#!/bin/bash
#
# Copyright 2006 Apple Computer, Inc.  All rights reserved.
# 
# iTunes U Sample Code License
# IMPORTANT:  This Apple software is supplied to you by Apple Computer, Inc. ("Apple") 
# in consideration of your agreement to the following terms, and your use, 
# installation, modification or distribution of this Apple software constitutes 
# acceptance of these terms.  If you do not agree with these terms, please do not use, 
# install, modify or distribute this Apple software.
# 
# In consideration of your agreement to abide by the following terms and subject to
# these terms, Apple grants you a personal, non-exclusive, non-transferable license, 
# under Apples copyrights in this original Apple software (the Apple Software): 
# 
# (a) to internally use, reproduce, modify and internally distribute the Apple 
# Software, with or without modifications, in source and binary forms, within your 
# educational organization or internal campus network for the sole purpose of 
# integrating Apple's iTunes U software with your internal campus network systems; and 
# 
# (b) to redistribute the Apple Software to other universities or educational 
# organizations, with or without modifications, in source and binary forms, for the 
# sole purpose of integrating Apple's iTunes U software with their internal campus 
# network systems; provided that the following conditions are met:
# 
# 	-  If you redistribute the Apple Software in its entirety and without 
#     modifications, you must retain the above copyright notice, this entire license 
#     and the disclaimer provisions in all such redistributions of the Apple Software.
# 	-  If you modify and redistribute the Apple Software, you must indicate that you
#     have made changes to the Apple Software, and you must retain the above
#     copyright notice, this entire license and the disclaimer provisions in all
#     such redistributions of the Apple Software and/or derivatives thereof created
#     by you.
#     -  Neither the name, trademarks, service marks or logos of Apple may be used to 
#     endorse or promote products derived from the Apple Software without specific 
#     prior written permission from Apple.  
# 
# Except as expressly stated above, no other rights or licenses, express or implied, 
# are granted by Apple herein, including but not limited to any patent rights that may
# be infringed by your derivative works or by other works in which the Apple Software 
# may be incorporated.  THE APPLE SOFTWARE IS PROVIDED BY APPLE ON AN "AS IS" BASIS.  
# APPLE MAKES NO WARRANTIES, EXPRESS OR IMPLIED, AND HEREBY DISCLAIMS ALL WARRANTIES, 
# INCLUDING WITHOUT LIMITATION THE IMPLIED WARRANTIES OF NON-INFRINGEMENT, 
# MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE, REGARDING THE APPLE SOFTWARE 
# OR ITS USE AND OPERATION ALONE OR IN COMBINATION WITH YOUR PRODUCTS OR SYSTEMS.  
# APPLE IS NOT OBLIGATED TO PROVIDE ANY MAINTENANCE, TECHNICAL OR OTHER SUPPORT FOR 
# THE APPLE SOFTWARE, OR TO PROVIDE ANY UPDATES TO THE APPLE SOFTWARE.  IN NO EVENT 
# SHALL APPLE BE LIABLE FOR ANY DIRECT, SPECIAL, INDIRECT, INCIDENTAL OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE 
# GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 
# ARISING IN ANY WAY OUT OF THE USE, REPRODUCTION, MODIFICATION AND/OR DISTRIBUTION 
# OF THE APPLE SOFTWARE, HOWEVER CAUSED AND WHETHER UNDER THEORY OF CONTRACT, TORT 
# (INCLUDING NEGLIGENCE), STRICT LIABILITY OR OTHERWISE, EVEN IF APPLE HAS BEEN 
# ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.         
# 
# Rev.  120806												
#

#
# This CGI script permits the secure transmission of
# user credentials and identity between Shibboleth
# (<http://shibboleth.internet2.edu/>) and iTunes U.
#

#
# Define paths for iTunes U utilities used by these scripts. The
# ANSI C source code for these can be found in the "C" folder of the
# iTunes U sample code. Compile this source and place the resulting
# executables in the locations defined below, or modify the values
# here to point to where those utilities or are on your system.
#
  HMAC_SHA256=/usr/local/bin/hmac-sha256
  TIME_IN_SECONDS=/usr/local/bin/seconds
  URL_ENCODE=/usr/local/bin/urlencode

#
# Define the path for the cURL utility on the local system. This script
# depends on that utility. If your system does not have it installed, you
# can get it pre-compiled for most platforms, or get its source code, from
# <http://curl.haxx.se/>. If you want to use another equivalent utility, make
# the appropriate changes to the code in this script that refers to $CURL.
# 
  CURL=/usr/bin/curl

#
# Define site parameters. Replace these
# values with ones appropriate for your site.
#
  SITE_URL="https://deimos.apple.com/WebObjects/Core.woa/Browse/example.edu"
  DEBUG_SUFFIX="/abc123"
  SHARED_SECRET="STRINGOFTHIRTYTWOLETTERSORDIGITS"
  ADMIN_CREDENTIAL="Administrator@urn:mace:itunesu.com:sites:example.edu"

#
# Obtain the current user's information from Shibboleth.
#
  CREDENTIALS="${HTTP_SHIB_EDUCOURSEMEMBER}"
  DISPLAY_NAME="${HTTP_SHIB_DISPLAYNAME}"
  EMAIL_ADDRESS="${HTTP_SHIB_MAIL}"
  USERNAME="${REMOTE_USER%% *}"
  USER_IDENTIFIER=""

#
# Define the iTunes U page to browse. Use the domain name that
# uniquely identifies your site in iTunes U to browse to that site's
# root page; use a destination string extracted from an iTunes U URL
# to browse to another iTunes U page; or use a destination string
# supplied as the "destination" parameter if this program is being
# invoked as a part of the login web service for your iTunes U site.
#
  DOMAIN="${SITE_URL##*/}"
  if [ "/${QUERY_STRING#destination=}/" != "/${QUERY_STRING}/" ]; then
      DESTINATION="${QUERY_STRING#destination=}"
  else
      DESTINATION="${DOMAIN}"
  fi

#
# Append your site's debug suffix to the destination if you want
# to receive an HTML page providing information about the
# transmission of credentials and identity between this program
# and iTunes U. Uncomment the following line for testing only.
#
  #DESTINATION="${DESTINATION}${DEBUG_SUFFIX}"

#
# Format the identity string, which includes the different components
# of the identity, appropriately delimited, and with any occurence
# of the delimiters in each component appropriately escaped.
#
  IDENTITY=""
  DISPLAY_NAME="${DISPLAY_NAME//\\\\/\\\\}"
  DISPLAY_NAME="${DISPLAY_NAME//\"/\\\"}"
  [ -n "${DISPLAY_NAME}" ] && IDENTITY="\"${DISPLAY_NAME}\""
  EMAIL_ADDRESS="${EMAIL_ADDRESS//\\\\/\\\\}"
  EMAIL_ADDRESS="${EMAIL_ADDRESS//>/\\>}"
  [ -n "${EMAIL_ADDRESS}" ] && IDENTITY="${IDENTITY} <${EMAIL_ADDRESS}>"
  USERNAME="${USERNAME//\\\\/\\\\}"
  USERNAME="${USERNAME//)/\\)}"
  [ -n "${USERNAME}" ] && IDENTITY="${IDENTITY} (${USERNAME})"
  USER_IDENTIFIER="${USER_IDENTIFIER//\\\\/\\\\}"
  USER_IDENTIFIER="${USER_IDENTIFIER//]/\\]}"
  [ -n "${USER_IDENTIFIER}" ] && IDENTITY="${IDENTITY} [${USER_IDENTIFIER}]"

#
# Encode the credentials and identity strings and
# use them to generate an authentication token.
#
  CREDENTIALS="$(printf '%s' "${CREDENTIALS}" | ${URL_ENCODE})"
  IDENTITY="$(printf '%s' "${IDENTITY}" | ${URL_ENCODE})"
  NOW="$(${TIME_IN_SECONDS})"
  DATA="credentials=${CREDENTIALS}&identity=${IDENTITY}&time=${NOW}"
  SIGNATURE="$(printf '%s\n%s' "${SHARED_SECRET}" "${DATA}" | ${HMAC_SHA256})"
  TOKEN="${DATA}&signature=${SIGNATURE}"

#
# Use the authorization token to connect to iTunes U and obtain from
# it the HTML that needs to be returned to a user's web browser to
# have a particular page or item in your iTunes U site displayed
# to that user in iTunes. Replace "/Browse/" in the code below with
# "/API/GetBrowseURL/" if you instead want to return the URL that would
# need to be opened to have that page or item displayed in iTunes.
#
  PREFIX="${SITE_URL%%.woa/*}.woa"
  URL="${PREFIX}/Browse/${DESTINATION}"
  printf 'Content-Type: text/html\n\n'
  printf '%s' "${TOKEN}" | ${CURL} -s -d @- "${URL}"
