3 * This program is free software; you can redistribute it and/or modify
4 * it under the terms of the GNU General Public License as published by
5 * the Free Software Foundation; either version 2 of the License, or
6 * (at your option) any later version.
8 * This program is distributed in the hope that it will be useful,
9 * but WITHOUT ANY WARRANTY; without even the implied warranty of
10 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 * GNU General Public License for more details.
13 * You should have received a copy of the GNU General Public License along
14 * with this program; if not, write to the Free Software Foundation, Inc.,
15 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
16 * http://www.gnu.org/copyleft/gpl.html
22 namespace MediaWiki\Auth
;
25 use MediaWiki\Block\DatabaseBlock
;
29 * Check if the user is blocked, and prevent authentication if so.
34 class CheckBlocksSecondaryAuthenticationProvider
extends AbstractSecondaryAuthenticationProvider
{
37 protected $blockDisablesLogin = null;
40 * @param array $params
41 * - blockDisablesLogin: (bool) Whether blocked accounts can log in,
42 * defaults to $wgBlockDisablesLogin
44 public function __construct( $params = [] ) {
45 if ( isset( $params['blockDisablesLogin'] ) ) {
46 $this->blockDisablesLogin
= (bool)$params['blockDisablesLogin'];
50 public function setConfig( Config
$config ) {
51 parent
::setConfig( $config );
53 if ( $this->blockDisablesLogin
=== null ) {
54 $this->blockDisablesLogin
= $this->config
->get( 'BlockDisablesLogin' );
58 public function getAuthenticationRequests( $action, array $options ) {
62 public function beginSecondaryAuthentication( $user, array $reqs ) {
63 // @TODO Partial blocks should not prevent the user from logging in.
64 // see: https://phabricator.wikimedia.org/T208895
65 if ( !$this->blockDisablesLogin
) {
66 return AuthenticationResponse
::newAbstain();
67 } elseif ( $user->getBlock() ) {
68 return AuthenticationResponse
::newFail(
69 new \
Message( 'login-userblocked', [ $user->getName() ] )
72 return AuthenticationResponse
::newPass();
76 public function beginSecondaryAccountCreation( $user, $creator, array $reqs ) {
77 return AuthenticationResponse
::newAbstain();
80 public function testUserForCreation( $user, $autocreate, array $options = [] ) {
81 $block = $user->isBlockedFromCreateAccount();
83 if ( $block->getReason() ) {
84 $reason = $block->getReason();
86 $msg = \Message
::newFromKey( 'blockednoreason' );
87 if ( !\RequestContext
::getMain()->getUser()->isSafeToLoad() ) {
88 $msg->inContentLanguage();
90 $reason = $msg->text();
99 if ( $block->getType() === DatabaseBlock
::TYPE_RANGE
) {
100 $errorMessage = 'cantcreateaccount-range-text';
101 $errorParams[] = $this->manager
->getRequest()->getIP();
103 $errorMessage = 'cantcreateaccount-text';
106 return StatusValue
::newFatal(
107 new \
Message( $errorMessage, $errorParams )
110 return StatusValue
::newGood();