Ville Tiensuu - ville.tiensuu@ixonos.com
Kaj Wallin - kaj.wallin@ixonos.com
+ Henri Lampela - henri.lampela@ixonos.com
Situare is free software; you can redistribute it and/or
modify it under the terms of the GNU General Public License
USA.
*/
-#include <QtGui>
+#include <qjson/parser.h>
+
#include <QtDebug>
#include <QDateTime>
-#include "facebookauthentication.h"
-#include "facebookcommon.h"
+#include <QNetworkReply>
+#include <QSettings>
+#include <QStringList>
+#include <QVariantMap>
+#include <QWebView>
+
+#ifdef Q_WS_MAEMO_5
+#include <QMaemo5InformationBox>
+#endif // Q_WS_MAEMO_5
+
+#include "common.h"
+#include "../error.h"
+#include "network/networkcookiejar.h"
+#include "situareservice/situarecommon.h"
+#include "ui/mainwindow.h"
-FacebookAuthentication::FacebookAuthentication(QWidget *parent)
- : QMainWindow(parent)
-{
- qDebug() << __PRETTY_FUNCTION__;
-
- m_webView = new QWebView;
- m_mainlayout = new QHBoxLayout;
+#include "facebookauthentication.h"
- m_facebookLoginPage = formLoginPage(FACEBOOK_LOGINBASE, SITUARE_PUBLIC_FACEBOOKAPI_KEY,
- INTERVAL1, SITUARE_LOGIN_SUCCESS, INTERVAL2,
- SITUARE_LOGIN_FAILURE, FACEBOOK_LOGIN_ENDING);
+const QString FB_LOGIN_SUCCESS_URL = "http://www.facebook.com/connect/login_success.html";
+const QString FB_LOGIN_URL = "https://www.facebook.com/login.php";
- connect(m_webView, SIGNAL(urlChanged(const QUrl &)),
- this, SLOT(updateCredentials(const QUrl &)));
+const QString URL_SESSION_PARAMETER_BEGIN("session={");
- readCredentials(m_loginCredentials);
+FacebookAuthentication::FacebookAuthentication(MainWindow *mainWindow, QObject *parent)
+ : QObject(parent),
+ m_loggedIn(false),
+ m_browser(0),
+ m_mainWindow(mainWindow)
+{
+ qDebug() << __PRETTY_FUNCTION__;
}
-FacebookAuthentication::~FacebookAuthentication()
+void FacebookAuthentication::browserDestroyed()
{
qDebug() << __PRETTY_FUNCTION__;
- delete m_webView;
- delete m_mainlayout;
+
+ m_mainWindow->toggleProgressIndicator(false);
+ m_browser = 0;
}
-void FacebookAuthentication::start()
+void FacebookAuthentication::clearAccountInformation(bool clearUserInformation)
{
- qDebug() << __PRETTY_FUNCTION__;
- if (!verifyCredentials(m_loginCredentials)){
- m_webView->setZoomFactor(FACEBOOK_LOGINPAGE_FONT_SIZE);
- m_webView->load(m_facebookLoginPage);
- setCentralWidget(m_webView);
- this->show();
+ /// @todo Parameter not needed
+ qDebug() << __PRETTY_FUNCTION__ << "clearUserInformation:" << clearUserInformation;
+
+ if (clearUserInformation) {
+ NetworkCookieJar::clearCookiesSetting();
+ QSettings settings(SETTINGS_ORGANIZATION_NAME, SETTINGS_APPLICATION_NAME);
+ settings.remove(SETTINGS_AUTOMATIC_UPDATE_ENABLED);
+ settings.remove(SETTINGS_AUTOMATIC_UPDATE_INTERVAL);
}
- else
- emit credentialsReady(m_loginCredentials);
}
-
-bool FacebookAuthentication::updateCredentials(const QUrl &url)
-{
+void FacebookAuthentication::destroyLogin()
+{
qDebug() << __PRETTY_FUNCTION__;
- bool foundSessionKey = FALSE;
- bool foundUserID = FALSE;
- bool foundExpires = FALSE;
- bool foundSessionSecret = FALSE;
- bool foundSig = FALSE;
-
- if (url.isValid()){
- qDebug() << "url is valid" << endl;
-
- QString callbackUrl = url.toString();
- QString urlEdit(callbackUrl);
- qDebug() << "callbackUrl: " << endl << callbackUrl.toAscii() << endl;
-
- if ( callbackUrl.indexOf(LOGIN_SUCCESS_REPLY) == 0 ){
- qDebug() << "login success" << endl;
-
- // let's find out session key
- int indexOfCredential = callbackUrl.indexOf(SESSION_KEY);
-
- if (indexOfCredential != -1){
- foundSessionKey = TRUE;
-
- indexOfCredential += 14; //lenght of SESSION_KEY
- urlEdit.remove(0,indexOfCredential);
- indexOfCredential = urlEdit.indexOf(USER_ID);
- urlEdit.remove(indexOfCredential, urlEdit.length());
- urlEdit.remove("\",\"");
-
- qDebug() << "Session Key" << endl << urlEdit.toAscii() << endl;
- m_loginCredentials.setSessionKey(urlEdit);
- }
-
- // let's find out uid
- urlEdit = callbackUrl;
- indexOfCredential = callbackUrl.indexOf(USER_ID);
+ m_mainWindow->destroyLoginDialog();
+ m_browser->deleteLater();
+}
- if (indexOfCredential != -1){
- foundUserID = TRUE;
+bool FacebookAuthentication::isLoggedIn() const
+{
+ qDebug() << __PRETTY_FUNCTION__;
- indexOfCredential += 5; //length of USER_ID:
- urlEdit.remove(0,indexOfCredential);
- indexOfCredential = urlEdit.indexOf(EXPIRES);
- urlEdit.remove(indexOfCredential, urlEdit.length());
- urlEdit.remove(",\"");
+ return m_loggedIn;
+}
- qDebug() << "userID" << endl << urlEdit.toAscii() << endl;
- m_loginCredentials.setUserID(urlEdit);
- }
+void FacebookAuthentication::login()
+{
+ qDebug() << __PRETTY_FUNCTION__;
- // let's find out expires
- urlEdit = callbackUrl;
- indexOfCredential = callbackUrl.indexOf(EXPIRES);
+ if (!m_browser) {
+ m_browser = new QWebView(m_mainWindow);
- if (indexOfCredential != -1){
- foundExpires = TRUE;
+ if (m_browser) {
+ m_browser->page()->networkAccessManager()->setCookieJar(new NetworkCookieJar());
- indexOfCredential += 9; //length of EXPIRES
- urlEdit.remove(0,indexOfCredential);
- indexOfCredential = urlEdit.indexOf(SESSION_SECRET);
- urlEdit.remove(indexOfCredential, urlEdit.length());
- urlEdit.remove(",\"");
+ connect(m_browser, SIGNAL(urlChanged(QUrl)),
+ this, SLOT(urlChanged(QUrl)));
- qDebug() << "Expires" << endl << urlEdit.toAscii() << endl;
- m_loginCredentials.setExpires(urlEdit);
- }
+ connect(m_browser, SIGNAL(destroyed(QObject*)),
+ this, SLOT(browserDestroyed()));
- // let's find out sessionsecret
- urlEdit = callbackUrl;
- indexOfCredential = callbackUrl.indexOf(SESSION_SECRET);
+ connect(m_browser->page()->networkAccessManager(),
+ SIGNAL(sslErrors(QNetworkReply*, QList<QSslError>)),
+ this, SLOT(sslErrors(QNetworkReply*, QList<QSslError>)));
- if (indexOfCredential != -1){
- foundSessionSecret = TRUE;
+ connect(m_browser->page()->networkAccessManager(), SIGNAL(finished(QNetworkReply*)),
+ this, SLOT(networkReplyHandler(QNetworkReply*)));
+ }
+ }
- indexOfCredential += 9; //" length of SESSION_SECRET
- urlEdit.remove(0,indexOfCredential);
- indexOfCredential = urlEdit.indexOf(SIGNATURE);
- urlEdit.remove(indexOfCredential, urlEdit.length());
- urlEdit.remove("\",\"");
+ if (m_browser) {
+ QString url = FB_LOGIN_URL + "?";
+ url.append("api_key=" + API_KEY +"&");
+ url.append("display=touch&");
+ url.append("fbconnect=1&");
+ url.append("next=" + FB_LOGIN_SUCCESS_URL + "&");
+ url.append("return_session=1&");
+ url.append("session_version=3&");
+ url.append("v=1.0&");
+ url.append("req_perms=publish_stream");
- qDebug() << "Session Secret" << endl << urlEdit.toAscii() << endl;
- m_loginCredentials.setSessionSecret(urlEdit);
- }
+ m_browser->load(QUrl(url));
- // let's find out sig
- urlEdit = callbackUrl;
- indexOfCredential = callbackUrl.indexOf(SIGNATURE);
+ m_mainWindow->toggleProgressIndicator(true);
+ }
+}
- if (indexOfCredential != -1){
- foundSig = TRUE;
+void FacebookAuthentication::logOut(bool clearUserInformation)
+{
+ qDebug() << __PRETTY_FUNCTION__;
- indexOfCredential += 6; //" length of SIGNATURE
- urlEdit.remove(0,indexOfCredential);
- urlEdit.remove("\"}");
+ clearAccountInformation(clearUserInformation);
+ m_loggedIn = false;
+ emit loggedOut();
+}
- qDebug() << "Signature" << endl << urlEdit.toAscii() << endl;
- m_loginCredentials.setSig(urlEdit);
- }
+void FacebookAuthentication::networkReplyHandler(QNetworkReply *reply)
+{
+ qDebug() <<__PRETTY_FUNCTION__;
- m_webView->hide();
- writeCredentials(m_loginCredentials);
- emit credentialsReady(m_loginCredentials);
- }
+ if ((reply->error() != QNetworkReply::NoError)
+ && (reply->error() != QNetworkReply::OperationCanceledError)) {
- else if ( callbackUrl.indexOf(LOGIN_FAILURE_REPLY) == 0){
- qWarning() << "login failure" << endl;
- emit loginFailure();
- }
+ qCritical() << __PRETTY_FUNCTION__ << "error:" << reply->error() << reply->errorString();
+ emit error(ErrorContext::NETWORK, reply->error());
+ destroyLogin();
+ }
+}
- else if ( callbackUrl.indexOf(LOGIN_PAGE) == 0){
- qDebug() << "correct loginPage";
- }
+QString FacebookAuthentication::parseSession(const QUrl &url)
+{
+ qDebug() << __PRETTY_FUNCTION__;
- else {
- qDebug() << "totally wrong webPage";
- emit loginFailure();
- start();
- }
- }
+ const QString END("}");
- else {
- qDebug() << " Loading of page failed invalid URL" << endl;
- emit loginFailure();
- return FALSE;
- }
+ QString urlString = url.toString();
+ int begin = urlString.indexOf(URL_SESSION_PARAMETER_BEGIN);
+ int end = urlString.indexOf(END, begin);
- return (foundSessionKey && foundUserID && foundExpires && foundSessionSecret && foundSig);
+ if ((begin > -1) && (end > -1))
+ return urlString.mid(begin, end - begin + 1);
+ else
+ return QString();
}
-void FacebookAuthentication::writeCredentials(const FacebookCredentials &credentials)
+void FacebookAuthentication::sslErrors(QNetworkReply *reply, const QList<QSslError> &errors)
{
qDebug() << __PRETTY_FUNCTION__;
- QSettings settings(DIRECTORY_NAME, FILE_NAME);
- settings.setValue("Session Key", credentials.sessionKey());
- settings.setValue("User ID", credentials.userID());
- settings.setValue("Expires", credentials.expires());
- settings.setValue("Session Secret", credentials.sessionSecret());
- settings.setValue("Sig", credentials.sig());
+ Q_UNUSED(errors);
+ reply->ignoreSslErrors();
}
-void FacebookAuthentication::readCredentials(FacebookCredentials &credentialsFromFile)
+void FacebookAuthentication::urlChanged(const QUrl &url)
{
- qDebug() << __PRETTY_FUNCTION__;
-
- QSettings settings(DIRECTORY_NAME, FILE_NAME);
-
- credentialsFromFile.setSessionKey(settings.value("Session Key", "Error").toString());
- credentialsFromFile.setUserID(settings.value("User ID", "Error").toString());
- credentialsFromFile.setExpires(settings.value("Expires", "Error").toString());
- credentialsFromFile.setSessionSecret(settings.value("Session Secret", "Error").toString());
- credentialsFromFile.setSig(settings.value("Sig", "Error").toString());
+ qDebug() << __PRETTY_FUNCTION__ << url.toString();
+
+ const QString WALL_POST_PERMISSION = "publish_stream";
+
+ /*
+ URL changes in different use cases:
+ * Login with cookie failed:
+ 1) http://m.facebook.com/login.php?api_key=cf77865a5070f2c2ba3b52cbf3371579&cancel_url=http://www.facebook.com/connect/login_failure.html&display=touch&fbconnect=1&next=http://www.facebook.com/connect/uiserver.php?app_id=286811277465&next=http%3A%2F%2Fwww.facebook.com%2Fconnect%2Flogin_success.html&display=touch&cancel_url=http%3A%2F%2Fwww.facebook.com%2Fconnect%2Flogin_failure.html&perms=publish_stream&return_session=1&session_version=3&fbconnect=1&canvas=0&legacy_return=1&method=permissions.request&return_session=1&session_version=3&v=1.0&req_perms=publish_stream&app_id=286811277465&refsrc=http://www.facebook.com/login.php&fbb=ra985c5e9
+
+ * Login without cookie, not allowed to publish:
+ 1) http://m.facebook.com/login.php?api_key=cf77865a5070f2c2ba3b52cbf3371579&display=touch&fbconnect=1&next=http://www.facebook.com/connect/uiserver.php?app_id=286811277465&next=http%3A%2F%2Fwww.facebook.com%2Fconnect%2Flogin_success.html&display=touch&perms=publish_stream&return_session=1&session_version=3&fbconnect=1&canvas=0&legacy_return=1&method=permissions.request&return_session=1&session_version=3&v=1.0&req_perms=publish_stream&app_id=286811277465&refsrc=http://www.facebook.com/login.php&fbb=r03cdf104"
+ --> browser dialog is invoked, user enters correct username and password
+ 2) http://www.facebook.com/connect/uiserver.php?app_id=286811277465&next=http://www.facebook.com/connect/login_success.html&display=touch&perms=publish_stream&return_session=1&session_version=3&fbconnect=1&canvas=0&legacy_return=1&method=permissions.request&session={"session_key":"2.isKv9bMtGmylvP1N6Il3IQ__.3600.1289394000-100001006647973","uid":100001006647973,"expires":1289394000,"secret":"PWiqZ9_aJjfKKJT4hJMTqA__","sig":"8f054aeca3c4d81e7efce3b90fb17d7e"}&installed=1&refsrc=http://www.facebook.com/login.php&fbb=rff1cc1be&refid=9&m_sess=sozzGNi5-SOBSb3AU
+ --> click allow
+ 3) http://www.facebook.com/connect/uiserver.php
+ 4) http://www.facebook.com/connect/login_success.html?perms=publish_stream&selected_profiles=100001006647973&session={"session_key":"2.isKv9bMtGmylvP1N6Il3IQ__.3600.1289394000-100001006647973","uid":"100001006647973","expires":1289394000,"secret":"PWiqZ9_aJjfKKJT4hJMTqA__","access_token":"286811277465|2.isKv9bMtGmylvP1N6Il3IQ__.3600.1289394000-100001006647973|bo9YniMczKY7PwlUEy9f40w3v5I","sig":"6b80d6928cf8f61b4c0c59d33d3127b6"}
+
+ * Login without cookie, not allowed to publish:
+ 1) http://m.facebook.com/login.php?api_key=cf77865a5070f2c2ba3b52cbf3371579&display=touch&fbconnect=1&next=http://www.facebook.com/connect/uiserver.php?app_id=286811277465&next=http%3A%2F%2Fwww.facebook.com%2Fconnect%2Flogin_success.html&display=touch&perms=publish_stream&return_session=1&session_version=3&fbconnect=1&canvas=0&legacy_return=1&method=permissions.request&return_session=1&session_version=3&v=1.0&req_perms=publish_stream&app_id=286811277465&refsrc=http://www.facebook.com/login.php&fbb=r3fa0d31d
+ --> browser dialog is invoked, user enters correct username and password
+ 2) http://www.facebook.com/connect/uiserver.php?app_id=286811277465&next=http://www.facebook.com/connect/login_success.html&display=touch&perms=publish_stream&return_session=1&session_version=3&fbconnect=1&canvas=0&legacy_return=1&method=permissions.request&session={"session_key":"2.isKv9bMtGmylvP1N6Il3IQ__.3600.1289394000-100001006647973","uid":100001006647973,"expires":1289394000,"secret":"PWiqZ9_aJjfKKJT4hJMTqA__","sig":"8f054aeca3c4d81e7efce3b90fb17d7e"}&installed=1&refsrc=http://www.facebook.com/login.php&fbb=r29076109&refid=9&m_sess=sozzGNi5-SOBSb3AU
+ --> click deny
+ 3) http://www.facebook.com/connect/uiserver.php
+ 4) http://www.facebook.com/connect/login_success.html?perms&selected_profiles=100001006647973&session={"session_key":"2.isKv9bMtGmylvP1N6Il3IQ__.3600.1289394000-100001006647973","uid":"100001006647973","expires":1289394000,"secret":"PWiqZ9_aJjfKKJT4hJMTqA__","access_token":"286811277465|2.isKv9bMtGmylvP1N6Il3IQ__.3600.1289394000-100001006647973|bo9YniMczKY7PwlUEy9f40w3v5I","sig":"6b80d6928cf8f61b4c0c59d33d3127b6"}
+
+ * Login with cookie succeeded, already allowed to publish:
+ 1) http://www.facebook.com/connect/uiserver.php?app_id=286811277465&next=http://www.facebook.com/connect/login_success.html&display=touch&cancel_url=http://www.facebook.com/connect/login_failure.html&perms=publish_stream&return_session=1&session_version=3&fbconnect=1&canvas=0&legacy_return=1&method=permissions.request&session={"session_key":"2.iHXi5fLKlHktva2R71xSAw__.3600.1289228400-100001006647973","uid":100001006647973,"expires":1289228400,"secret":"q4_Hn5qRdxnVT_qh3ztv5w__","sig":"c9d29ca857bacec48b952e7d2826a3ca"}&fbb=rb28f24e5
+ 2) http://www.facebook.com/connect/login_success.html?perms=publish_stream&selected_profiles=100001006647973&session={"session_key":"2.iHXi5fLKlHktva2R71xSAw__.3600.1289228400-100001006647973","uid":"100001006647973","expires":1289228400,"secret":"q4_Hn5qRdxnVT_qh3ztv5w__","access_token":"286811277465|2.iHXi5fLKlHktva2R71xSAw__.3600.1289228400-100001006647973|LVTHGW82A98SGvv6Fl43DlCrFT0","sig":"8edd8d611047bcd162abbe9983b25a56"}
+ */
+
+ const QString urlString = url.toString();
+ if (!urlString.contains(URL_SESSION_PARAMETER_BEGIN)) {
+ // login page url doesn't contain session
+ /// @todo INVOKE DIALOG ALSO WHEN STOPPED TO PERMISSION PAGE
+ /// @todo case: set cookie, remove situare app, re-login, 1 extra allow page before permissions, redirect from extra page when denying?
+ m_mainWindow->buildLoginDialog(m_browser);
+ } else if (urlString.startsWith(FB_LOGIN_SUCCESS_URL)) {
+ // login succeeded, permissions granted/declined
+ const QString session = parseSession(url);
+ qDebug() << __PRETTY_FUNCTION__ << "login finished, parsed session:" << session;
+ if (!session.isEmpty()) {
+ destroyLogin();
+ m_loggedIn = true;
+ emit loggedIn(session, urlString.contains(WALL_POST_PERMISSION));
+ }
+ }
+ else {
+ qCritical() << __PRETTY_FUNCTION__ << "new url was not recognised, url:" << urlString;
+ }
}
-
- FacebookCredentials FacebookAuthentication::loginCredentials() const
- {
- qDebug() << __PRETTY_FUNCTION__;
- return m_loginCredentials;
- }
-
- bool FacebookAuthentication::verifyCredentials(const FacebookCredentials &credentials) const
- {
- qDebug() << __PRETTY_FUNCTION__;
-
- // if expires value is 0, then credentials are valid forever
- if(credentials.expires() == "0") {
- return true;
- }
- else {
- QString expires = credentials.expires();
- QDateTime expireTime;
- expireTime.setTime_t(expires.toInt());
- QString expiresString = expireTime.toString("dd.MM.yyyy hh:mm:ss");
- qDebug() << expiresString.toAscii();
-
- QDateTime currentTime;
- currentTime = QDateTime::currentDateTime();
- QString currentTimeString = currentTime.toString("dd.MM.yyyy hh:mm:ss");
- qDebug() << currentTimeString.toAscii();
-
- return currentTime < expireTime;
- }
- }
-
- QString FacebookAuthentication::formLoginPage(const QString & part1, const QString & part2,
- const QString & part3, const QString & part4,
- const QString & part5, const QString & part6,
- const QString & part7) const
- {
- QString loginPage;
- loginPage.append(part1);
- loginPage.append(part2);
- loginPage.append(part3);
- loginPage.append(part4);
- loginPage.append(part5);
- loginPage.append(part5);
- loginPage.append(part6);
- loginPage.append(part7);
-
- return loginPage;
- }