source: code/trunk/downstream.go@ 731

Last change on this file since 731 was 729, checked in by contact, 4 years ago

Add support for draft/account-registration proxying

This adds support for the draft/account-registration extension [1].
This allows downstreams to register on upstream networks.

[1]: https://ircv3.net/specs/extensions/account-registration

File size: 73.3 KB
Line 
1package soju
2
3import (
4 "context"
5 "crypto/tls"
6 "encoding/base64"
7 "errors"
8 "fmt"
9 "io"
10 "net"
11 "strconv"
12 "strings"
13 "time"
14
15 "github.com/emersion/go-sasl"
16 "golang.org/x/crypto/bcrypt"
17 "gopkg.in/irc.v3"
18)
19
20type ircError struct {
21 Message *irc.Message
22}
23
24func (err ircError) Error() string {
25 return err.Message.String()
26}
27
28func newUnknownCommandError(cmd string) ircError {
29 return ircError{&irc.Message{
30 Command: irc.ERR_UNKNOWNCOMMAND,
31 Params: []string{
32 "*",
33 cmd,
34 "Unknown command",
35 },
36 }}
37}
38
39func newNeedMoreParamsError(cmd string) ircError {
40 return ircError{&irc.Message{
41 Command: irc.ERR_NEEDMOREPARAMS,
42 Params: []string{
43 "*",
44 cmd,
45 "Not enough parameters",
46 },
47 }}
48}
49
50func newChatHistoryError(subcommand string, target string) ircError {
51 return ircError{&irc.Message{
52 Command: "FAIL",
53 Params: []string{"CHATHISTORY", "MESSAGE_ERROR", subcommand, target, "Messages could not be retrieved"},
54 }}
55}
56
57// authError is an authentication error.
58type authError struct {
59 // Internal error cause. This will not be revealed to the user.
60 err error
61 // Error cause which can safely be sent to the user without compromising
62 // security.
63 reason string
64}
65
66func (err *authError) Error() string {
67 return err.err.Error()
68}
69
70func (err *authError) Unwrap() error {
71 return err.err
72}
73
74// authErrorReason returns the user-friendly reason of an authentication
75// failure.
76func authErrorReason(err error) string {
77 if authErr, ok := err.(*authError); ok {
78 return authErr.reason
79 } else {
80 return "Authentication failed"
81 }
82}
83
84func newInvalidUsernameOrPasswordError(err error) error {
85 return &authError{
86 err: err,
87 reason: "Invalid username or password",
88 }
89}
90
91func parseBouncerNetID(subcommand, s string) (int64, error) {
92 id, err := strconv.ParseInt(s, 10, 64)
93 if err != nil {
94 return 0, ircError{&irc.Message{
95 Command: "FAIL",
96 Params: []string{"BOUNCER", "INVALID_NETID", subcommand, s, "Invalid network ID"},
97 }}
98 }
99 return id, nil
100}
101
102func fillNetworkAddrAttrs(attrs irc.Tags, network *Network) {
103 u, err := network.URL()
104 if err != nil {
105 return
106 }
107
108 hasHostPort := true
109 switch u.Scheme {
110 case "ircs":
111 attrs["tls"] = irc.TagValue("1")
112 case "irc+insecure":
113 attrs["tls"] = irc.TagValue("0")
114 default: // e.g. unix://
115 hasHostPort = false
116 }
117 if host, port, err := net.SplitHostPort(u.Host); err == nil && hasHostPort {
118 attrs["host"] = irc.TagValue(host)
119 attrs["port"] = irc.TagValue(port)
120 } else if hasHostPort {
121 attrs["host"] = irc.TagValue(u.Host)
122 }
123}
124
125func getNetworkAttrs(network *network) irc.Tags {
126 state := "disconnected"
127 if uc := network.conn; uc != nil {
128 state = "connected"
129 }
130
131 attrs := irc.Tags{
132 "name": irc.TagValue(network.GetName()),
133 "state": irc.TagValue(state),
134 "nickname": irc.TagValue(GetNick(&network.user.User, &network.Network)),
135 }
136
137 if network.Username != "" {
138 attrs["username"] = irc.TagValue(network.Username)
139 }
140 if realname := GetRealname(&network.user.User, &network.Network); realname != "" {
141 attrs["realname"] = irc.TagValue(realname)
142 }
143
144 fillNetworkAddrAttrs(attrs, &network.Network)
145
146 return attrs
147}
148
149func networkAddrFromAttrs(attrs irc.Tags) string {
150 host, ok := attrs.GetTag("host")
151 if !ok {
152 return ""
153 }
154
155 addr := host
156 if port, ok := attrs.GetTag("port"); ok {
157 addr += ":" + port
158 }
159
160 if tlsStr, ok := attrs.GetTag("tls"); ok && tlsStr == "0" {
161 addr = "irc+insecure://" + tlsStr
162 }
163
164 return addr
165}
166
167func updateNetworkAttrs(record *Network, attrs irc.Tags, subcommand string) error {
168 addrAttrs := irc.Tags{}
169 fillNetworkAddrAttrs(addrAttrs, record)
170
171 updateAddr := false
172 for k, v := range attrs {
173 s := string(v)
174 switch k {
175 case "host", "port", "tls":
176 updateAddr = true
177 addrAttrs[k] = v
178 case "name":
179 record.Name = s
180 case "nickname":
181 record.Nick = s
182 case "username":
183 record.Username = s
184 case "realname":
185 record.Realname = s
186 case "pass":
187 record.Pass = s
188 default:
189 return ircError{&irc.Message{
190 Command: "FAIL",
191 Params: []string{"BOUNCER", "UNKNOWN_ATTRIBUTE", subcommand, k, "Unknown attribute"},
192 }}
193 }
194 }
195
196 if updateAddr {
197 record.Addr = networkAddrFromAttrs(addrAttrs)
198 if record.Addr == "" {
199 return ircError{&irc.Message{
200 Command: "FAIL",
201 Params: []string{"BOUNCER", "NEED_ATTRIBUTE", subcommand, "host", "Missing required host attribute"},
202 }}
203 }
204 }
205
206 return nil
207}
208
209// ' ' and ':' break the IRC message wire format, '@' and '!' break prefixes,
210// '*' and '?' break masks, '$' breaks server masks in PRIVMSG/NOTICE,
211// "*" is the reserved nickname for registration
212const illegalNickChars = " :@!*?$"
213
214// permanentDownstreamCaps is the list of always-supported downstream
215// capabilities.
216var permanentDownstreamCaps = map[string]string{
217 "batch": "",
218 "cap-notify": "",
219 "echo-message": "",
220 "invite-notify": "",
221 "message-tags": "",
222 "server-time": "",
223 "setname": "",
224
225 "soju.im/bouncer-networks": "",
226 "soju.im/bouncer-networks-notify": "",
227}
228
229// needAllDownstreamCaps is the list of downstream capabilities that
230// require support from all upstreams to be enabled
231var needAllDownstreamCaps = map[string]string{
232 "account-notify": "",
233 "account-tag": "",
234 "away-notify": "",
235 "extended-join": "",
236 "multi-prefix": "",
237
238 "draft/extended-monitor": "",
239}
240
241// passthroughIsupport is the set of ISUPPORT tokens that are directly passed
242// through from the upstream server to downstream clients.
243//
244// This is only effective in single-upstream mode.
245var passthroughIsupport = map[string]bool{
246 "AWAYLEN": true,
247 "BOT": true,
248 "CHANLIMIT": true,
249 "CHANMODES": true,
250 "CHANNELLEN": true,
251 "CHANTYPES": true,
252 "CLIENTTAGDENY": true,
253 "ELIST": true,
254 "EXCEPTS": true,
255 "EXTBAN": true,
256 "HOSTLEN": true,
257 "INVEX": true,
258 "KICKLEN": true,
259 "MAXLIST": true,
260 "MAXTARGETS": true,
261 "MODES": true,
262 "MONITOR": true,
263 "NAMELEN": true,
264 "NETWORK": true,
265 "NICKLEN": true,
266 "PREFIX": true,
267 "SAFELIST": true,
268 "TARGMAX": true,
269 "TOPICLEN": true,
270 "USERLEN": true,
271 "UTF8ONLY": true,
272 "WHOX": true,
273}
274
275type downstreamSASL struct {
276 server sasl.Server
277 plainUsername, plainPassword string
278}
279
280type downstreamConn struct {
281 conn
282
283 id uint64
284
285 registered bool
286 user *user
287 nick string
288 nickCM string
289 rawUsername string
290 networkName string
291 clientName string
292 realname string
293 hostname string
294 account string // RPL_LOGGEDIN/OUT state
295 password string // empty after authentication
296 network *network // can be nil
297 isMultiUpstream bool
298
299 negotiatingCaps bool
300 capVersion int
301 supportedCaps map[string]string
302 caps map[string]bool
303 sasl *downstreamSASL
304
305 lastBatchRef uint64
306
307 monitored casemapMap
308}
309
310func newDownstreamConn(srv *Server, ic ircConn, id uint64) *downstreamConn {
311 remoteAddr := ic.RemoteAddr().String()
312 logger := &prefixLogger{srv.Logger, fmt.Sprintf("downstream %q: ", remoteAddr)}
313 options := connOptions{Logger: logger}
314 dc := &downstreamConn{
315 conn: *newConn(srv, ic, &options),
316 id: id,
317 nick: "*",
318 nickCM: "*",
319 supportedCaps: make(map[string]string),
320 caps: make(map[string]bool),
321 monitored: newCasemapMap(0),
322 }
323 dc.hostname = remoteAddr
324 if host, _, err := net.SplitHostPort(dc.hostname); err == nil {
325 dc.hostname = host
326 }
327 for k, v := range permanentDownstreamCaps {
328 dc.supportedCaps[k] = v
329 }
330 dc.supportedCaps["sasl"] = "PLAIN"
331 // TODO: this is racy, we should only enable chathistory after
332 // authentication and then check that user.msgStore implements
333 // chatHistoryMessageStore
334 if srv.Config().LogPath != "" {
335 dc.supportedCaps["draft/chathistory"] = ""
336 }
337 return dc
338}
339
340func (dc *downstreamConn) prefix() *irc.Prefix {
341 return &irc.Prefix{
342 Name: dc.nick,
343 User: dc.user.Username,
344 Host: dc.hostname,
345 }
346}
347
348func (dc *downstreamConn) forEachNetwork(f func(*network)) {
349 if dc.network != nil {
350 f(dc.network)
351 } else if dc.isMultiUpstream {
352 dc.user.forEachNetwork(f)
353 }
354}
355
356func (dc *downstreamConn) forEachUpstream(f func(*upstreamConn)) {
357 if dc.network == nil && !dc.isMultiUpstream {
358 return
359 }
360 dc.user.forEachUpstream(func(uc *upstreamConn) {
361 if dc.network != nil && uc.network != dc.network {
362 return
363 }
364 f(uc)
365 })
366}
367
368// upstream returns the upstream connection, if any. If there are zero or if
369// there are multiple upstream connections, it returns nil.
370func (dc *downstreamConn) upstream() *upstreamConn {
371 if dc.network == nil {
372 return nil
373 }
374 return dc.network.conn
375}
376
377func isOurNick(net *network, nick string) bool {
378 // TODO: this doesn't account for nick changes
379 if net.conn != nil {
380 return net.casemap(nick) == net.conn.nickCM
381 }
382 // We're not currently connected to the upstream connection, so we don't
383 // know whether this name is our nickname. Best-effort: use the network's
384 // configured nickname and hope it was the one being used when we were
385 // connected.
386 return net.casemap(nick) == net.casemap(GetNick(&net.user.User, &net.Network))
387}
388
389// marshalEntity converts an upstream entity name (ie. channel or nick) into a
390// downstream entity name.
391//
392// This involves adding a "/<network>" suffix if the entity isn't the current
393// user.
394func (dc *downstreamConn) marshalEntity(net *network, name string) string {
395 if isOurNick(net, name) {
396 return dc.nick
397 }
398 name = partialCasemap(net.casemap, name)
399 if dc.network != nil {
400 if dc.network != net {
401 panic("soju: tried to marshal an entity for another network")
402 }
403 return name
404 }
405 return name + "/" + net.GetName()
406}
407
408func (dc *downstreamConn) marshalUserPrefix(net *network, prefix *irc.Prefix) *irc.Prefix {
409 if isOurNick(net, prefix.Name) {
410 return dc.prefix()
411 }
412 prefix.Name = partialCasemap(net.casemap, prefix.Name)
413 if dc.network != nil {
414 if dc.network != net {
415 panic("soju: tried to marshal a user prefix for another network")
416 }
417 return prefix
418 }
419 return &irc.Prefix{
420 Name: prefix.Name + "/" + net.GetName(),
421 User: prefix.User,
422 Host: prefix.Host,
423 }
424}
425
426// unmarshalEntityNetwork converts a downstream entity name (ie. channel or
427// nick) into an upstream entity name.
428//
429// This involves removing the "/<network>" suffix.
430func (dc *downstreamConn) unmarshalEntityNetwork(name string) (*network, string, error) {
431 if dc.network != nil {
432 return dc.network, name, nil
433 }
434 if !dc.isMultiUpstream {
435 return nil, "", ircError{&irc.Message{
436 Command: irc.ERR_NOSUCHCHANNEL,
437 Params: []string{dc.nick, name, "Cannot interact with channels and users on the bouncer connection. Did you mean to use a specific network?"},
438 }}
439 }
440
441 var net *network
442 if i := strings.LastIndexByte(name, '/'); i >= 0 {
443 network := name[i+1:]
444 name = name[:i]
445
446 for _, n := range dc.user.networks {
447 if network == n.GetName() {
448 net = n
449 break
450 }
451 }
452 }
453
454 if net == nil {
455 return nil, "", ircError{&irc.Message{
456 Command: irc.ERR_NOSUCHCHANNEL,
457 Params: []string{dc.nick, name, "Missing network suffix in name"},
458 }}
459 }
460
461 return net, name, nil
462}
463
464// unmarshalEntity is the same as unmarshalEntityNetwork, but returns the
465// upstream connection and fails if the upstream is disconnected.
466func (dc *downstreamConn) unmarshalEntity(name string) (*upstreamConn, string, error) {
467 net, name, err := dc.unmarshalEntityNetwork(name)
468 if err != nil {
469 return nil, "", err
470 }
471
472 if net.conn == nil {
473 return nil, "", ircError{&irc.Message{
474 Command: irc.ERR_NOSUCHCHANNEL,
475 Params: []string{dc.nick, name, "Disconnected from upstream network"},
476 }}
477 }
478
479 return net.conn, name, nil
480}
481
482func (dc *downstreamConn) unmarshalText(uc *upstreamConn, text string) string {
483 if dc.upstream() != nil {
484 return text
485 }
486 // TODO: smarter parsing that ignores URLs
487 return strings.ReplaceAll(text, "/"+uc.network.GetName(), "")
488}
489
490func (dc *downstreamConn) ReadMessage() (*irc.Message, error) {
491 msg, err := dc.conn.ReadMessage()
492 if err != nil {
493 return nil, err
494 }
495 dc.srv.metrics.downstreamInMessagesTotal.Inc()
496 return msg, nil
497}
498
499func (dc *downstreamConn) readMessages(ch chan<- event) error {
500 for {
501 msg, err := dc.ReadMessage()
502 if errors.Is(err, io.EOF) {
503 break
504 } else if err != nil {
505 return fmt.Errorf("failed to read IRC command: %v", err)
506 }
507
508 ch <- eventDownstreamMessage{msg, dc}
509 }
510
511 return nil
512}
513
514// SendMessage sends an outgoing message.
515//
516// This can only called from the user goroutine.
517func (dc *downstreamConn) SendMessage(msg *irc.Message) {
518 if !dc.caps["message-tags"] {
519 if msg.Command == "TAGMSG" {
520 return
521 }
522 msg = msg.Copy()
523 for name := range msg.Tags {
524 supported := false
525 switch name {
526 case "time":
527 supported = dc.caps["server-time"]
528 case "account":
529 supported = dc.caps["account"]
530 }
531 if !supported {
532 delete(msg.Tags, name)
533 }
534 }
535 }
536 if !dc.caps["batch"] && msg.Tags["batch"] != "" {
537 msg = msg.Copy()
538 delete(msg.Tags, "batch")
539 }
540 if msg.Command == "JOIN" && !dc.caps["extended-join"] {
541 msg.Params = msg.Params[:1]
542 }
543 if msg.Command == "SETNAME" && !dc.caps["setname"] {
544 return
545 }
546 if msg.Command == "AWAY" && !dc.caps["away-notify"] {
547 return
548 }
549 if msg.Command == "ACCOUNT" && !dc.caps["account-notify"] {
550 return
551 }
552
553 dc.srv.metrics.downstreamOutMessagesTotal.Inc()
554 dc.conn.SendMessage(msg)
555}
556
557func (dc *downstreamConn) SendBatch(typ string, params []string, tags irc.Tags, f func(batchRef irc.TagValue)) {
558 dc.lastBatchRef++
559 ref := fmt.Sprintf("%v", dc.lastBatchRef)
560
561 if dc.caps["batch"] {
562 dc.SendMessage(&irc.Message{
563 Tags: tags,
564 Prefix: dc.srv.prefix(),
565 Command: "BATCH",
566 Params: append([]string{"+" + ref, typ}, params...),
567 })
568 }
569
570 f(irc.TagValue(ref))
571
572 if dc.caps["batch"] {
573 dc.SendMessage(&irc.Message{
574 Prefix: dc.srv.prefix(),
575 Command: "BATCH",
576 Params: []string{"-" + ref},
577 })
578 }
579}
580
581// sendMessageWithID sends an outgoing message with the specified internal ID.
582func (dc *downstreamConn) sendMessageWithID(msg *irc.Message, id string) {
583 dc.SendMessage(msg)
584
585 if id == "" || !dc.messageSupportsBacklog(msg) {
586 return
587 }
588
589 dc.sendPing(id)
590}
591
592// advanceMessageWithID advances history to the specified message ID without
593// sending a message. This is useful e.g. for self-messages when echo-message
594// isn't enabled.
595func (dc *downstreamConn) advanceMessageWithID(msg *irc.Message, id string) {
596 if id == "" || !dc.messageSupportsBacklog(msg) {
597 return
598 }
599
600 dc.sendPing(id)
601}
602
603// ackMsgID acknowledges that a message has been received.
604func (dc *downstreamConn) ackMsgID(id string) {
605 netID, entity, err := parseMsgID(id, nil)
606 if err != nil {
607 dc.logger.Printf("failed to ACK message ID %q: %v", id, err)
608 return
609 }
610
611 network := dc.user.getNetworkByID(netID)
612 if network == nil {
613 return
614 }
615
616 network.delivered.StoreID(entity, dc.clientName, id)
617}
618
619func (dc *downstreamConn) sendPing(msgID string) {
620 token := "soju-msgid-" + msgID
621 dc.SendMessage(&irc.Message{
622 Command: "PING",
623 Params: []string{token},
624 })
625}
626
627func (dc *downstreamConn) handlePong(token string) {
628 if !strings.HasPrefix(token, "soju-msgid-") {
629 dc.logger.Printf("received unrecognized PONG token %q", token)
630 return
631 }
632 msgID := strings.TrimPrefix(token, "soju-msgid-")
633 dc.ackMsgID(msgID)
634}
635
636// marshalMessage re-formats a message coming from an upstream connection so
637// that it's suitable for being sent on this downstream connection. Only
638// messages that may appear in logs are supported, except MODE messages which
639// may only appear in single-upstream mode.
640func (dc *downstreamConn) marshalMessage(msg *irc.Message, net *network) *irc.Message {
641 msg = msg.Copy()
642 msg.Prefix = dc.marshalUserPrefix(net, msg.Prefix)
643
644 if dc.network != nil {
645 return msg
646 }
647
648 switch msg.Command {
649 case "PRIVMSG", "NOTICE", "TAGMSG":
650 msg.Params[0] = dc.marshalEntity(net, msg.Params[0])
651 case "NICK":
652 // Nick change for another user
653 msg.Params[0] = dc.marshalEntity(net, msg.Params[0])
654 case "JOIN", "PART":
655 msg.Params[0] = dc.marshalEntity(net, msg.Params[0])
656 case "KICK":
657 msg.Params[0] = dc.marshalEntity(net, msg.Params[0])
658 msg.Params[1] = dc.marshalEntity(net, msg.Params[1])
659 case "TOPIC":
660 msg.Params[0] = dc.marshalEntity(net, msg.Params[0])
661 case "QUIT", "SETNAME":
662 // This space is intentionally left blank
663 default:
664 panic(fmt.Sprintf("unexpected %q message", msg.Command))
665 }
666
667 return msg
668}
669
670func (dc *downstreamConn) handleMessage(ctx context.Context, msg *irc.Message) error {
671 ctx, cancel := dc.conn.NewContext(ctx)
672 defer cancel()
673
674 ctx, cancel = context.WithTimeout(ctx, handleDownstreamMessageTimeout)
675 defer cancel()
676
677 switch msg.Command {
678 case "QUIT":
679 return dc.Close()
680 default:
681 if dc.registered {
682 return dc.handleMessageRegistered(ctx, msg)
683 } else {
684 return dc.handleMessageUnregistered(ctx, msg)
685 }
686 }
687}
688
689func (dc *downstreamConn) handleMessageUnregistered(ctx context.Context, msg *irc.Message) error {
690 switch msg.Command {
691 case "NICK":
692 var nick string
693 if err := parseMessageParams(msg, &nick); err != nil {
694 return err
695 }
696 if nick == "" || strings.ContainsAny(nick, illegalNickChars) {
697 return ircError{&irc.Message{
698 Command: irc.ERR_ERRONEUSNICKNAME,
699 Params: []string{dc.nick, nick, "contains illegal characters"},
700 }}
701 }
702 nickCM := casemapASCII(nick)
703 if nickCM == serviceNickCM {
704 return ircError{&irc.Message{
705 Command: irc.ERR_NICKNAMEINUSE,
706 Params: []string{dc.nick, nick, "Nickname reserved for bouncer service"},
707 }}
708 }
709 dc.nick = nick
710 dc.nickCM = nickCM
711 case "USER":
712 if err := parseMessageParams(msg, &dc.rawUsername, nil, nil, &dc.realname); err != nil {
713 return err
714 }
715 case "PASS":
716 if err := parseMessageParams(msg, &dc.password); err != nil {
717 return err
718 }
719 case "CAP":
720 var subCmd string
721 if err := parseMessageParams(msg, &subCmd); err != nil {
722 return err
723 }
724 if err := dc.handleCapCommand(subCmd, msg.Params[1:]); err != nil {
725 return err
726 }
727 case "AUTHENTICATE":
728 credentials, err := dc.handleAuthenticateCommand(msg)
729 if err != nil {
730 return err
731 } else if credentials == nil {
732 break
733 }
734
735 if err := dc.authenticate(ctx, credentials.plainUsername, credentials.plainPassword); err != nil {
736 dc.logger.Printf("SASL authentication error for user %q: %v", credentials.plainUsername, err)
737 dc.endSASL(&irc.Message{
738 Prefix: dc.srv.prefix(),
739 Command: irc.ERR_SASLFAIL,
740 Params: []string{dc.nick, authErrorReason(err)},
741 })
742 break
743 }
744
745 // Technically we should send RPL_LOGGEDIN here. However we use
746 // RPL_LOGGEDIN to mirror the upstream connection status. Let's
747 // see how many clients that breaks. See:
748 // https://github.com/ircv3/ircv3-specifications/pull/476
749 dc.endSASL(nil)
750 case "BOUNCER":
751 var subcommand string
752 if err := parseMessageParams(msg, &subcommand); err != nil {
753 return err
754 }
755
756 switch strings.ToUpper(subcommand) {
757 case "BIND":
758 var idStr string
759 if err := parseMessageParams(msg, nil, &idStr); err != nil {
760 return err
761 }
762
763 if dc.user == nil {
764 return ircError{&irc.Message{
765 Command: "FAIL",
766 Params: []string{"BOUNCER", "ACCOUNT_REQUIRED", "BIND", "Authentication needed to bind to bouncer network"},
767 }}
768 }
769
770 id, err := parseBouncerNetID(subcommand, idStr)
771 if err != nil {
772 return err
773 }
774
775 var match *network
776 dc.user.forEachNetwork(func(net *network) {
777 if net.ID == id {
778 match = net
779 }
780 })
781 if match == nil {
782 return ircError{&irc.Message{
783 Command: "FAIL",
784 Params: []string{"BOUNCER", "INVALID_NETID", idStr, "Unknown network ID"},
785 }}
786 }
787
788 dc.networkName = match.GetName()
789 }
790 default:
791 dc.logger.Printf("unhandled message: %v", msg)
792 return newUnknownCommandError(msg.Command)
793 }
794 if dc.rawUsername != "" && dc.nick != "*" && !dc.negotiatingCaps {
795 return dc.register(ctx)
796 }
797 return nil
798}
799
800func (dc *downstreamConn) handleCapCommand(cmd string, args []string) error {
801 cmd = strings.ToUpper(cmd)
802
803 switch cmd {
804 case "LS":
805 if len(args) > 0 {
806 var err error
807 if dc.capVersion, err = strconv.Atoi(args[0]); err != nil {
808 return err
809 }
810 }
811 if !dc.registered && dc.capVersion >= 302 {
812 // Let downstream show everything it supports, and trim
813 // down the available capabilities when upstreams are
814 // known.
815 for k, v := range needAllDownstreamCaps {
816 dc.supportedCaps[k] = v
817 }
818 }
819
820 caps := make([]string, 0, len(dc.supportedCaps))
821 for k, v := range dc.supportedCaps {
822 if dc.capVersion >= 302 && v != "" {
823 caps = append(caps, k+"="+v)
824 } else {
825 caps = append(caps, k)
826 }
827 }
828
829 // TODO: multi-line replies
830 dc.SendMessage(&irc.Message{
831 Prefix: dc.srv.prefix(),
832 Command: "CAP",
833 Params: []string{dc.nick, "LS", strings.Join(caps, " ")},
834 })
835
836 if dc.capVersion >= 302 {
837 // CAP version 302 implicitly enables cap-notify
838 dc.caps["cap-notify"] = true
839 }
840
841 if !dc.registered {
842 dc.negotiatingCaps = true
843 }
844 case "LIST":
845 var caps []string
846 for name, enabled := range dc.caps {
847 if enabled {
848 caps = append(caps, name)
849 }
850 }
851
852 // TODO: multi-line replies
853 dc.SendMessage(&irc.Message{
854 Prefix: dc.srv.prefix(),
855 Command: "CAP",
856 Params: []string{dc.nick, "LIST", strings.Join(caps, " ")},
857 })
858 case "REQ":
859 if len(args) == 0 {
860 return ircError{&irc.Message{
861 Command: err_invalidcapcmd,
862 Params: []string{dc.nick, cmd, "Missing argument in CAP REQ command"},
863 }}
864 }
865
866 // TODO: atomically ack/nak the whole capability set
867 caps := strings.Fields(args[0])
868 ack := true
869 for _, name := range caps {
870 name = strings.ToLower(name)
871 enable := !strings.HasPrefix(name, "-")
872 if !enable {
873 name = strings.TrimPrefix(name, "-")
874 }
875
876 if enable == dc.caps[name] {
877 continue
878 }
879
880 _, ok := dc.supportedCaps[name]
881 if !ok {
882 ack = false
883 break
884 }
885
886 if name == "cap-notify" && dc.capVersion >= 302 && !enable {
887 // cap-notify cannot be disabled with CAP version 302
888 ack = false
889 break
890 }
891
892 dc.caps[name] = enable
893 }
894
895 reply := "NAK"
896 if ack {
897 reply = "ACK"
898 }
899 dc.SendMessage(&irc.Message{
900 Prefix: dc.srv.prefix(),
901 Command: "CAP",
902 Params: []string{dc.nick, reply, args[0]},
903 })
904
905 if !dc.registered {
906 dc.negotiatingCaps = true
907 }
908 case "END":
909 dc.negotiatingCaps = false
910 default:
911 return ircError{&irc.Message{
912 Command: err_invalidcapcmd,
913 Params: []string{dc.nick, cmd, "Unknown CAP command"},
914 }}
915 }
916 return nil
917}
918
919func (dc *downstreamConn) handleAuthenticateCommand(msg *irc.Message) (result *downstreamSASL, err error) {
920 defer func() {
921 if err != nil {
922 dc.sasl = nil
923 }
924 }()
925
926 if !dc.caps["sasl"] {
927 return nil, ircError{&irc.Message{
928 Prefix: dc.srv.prefix(),
929 Command: irc.ERR_SASLFAIL,
930 Params: []string{"*", "AUTHENTICATE requires the \"sasl\" capability to be enabled"},
931 }}
932 }
933 if len(msg.Params) == 0 {
934 return nil, ircError{&irc.Message{
935 Prefix: dc.srv.prefix(),
936 Command: irc.ERR_SASLFAIL,
937 Params: []string{"*", "Missing AUTHENTICATE argument"},
938 }}
939 }
940 if msg.Params[0] == "*" {
941 return nil, ircError{&irc.Message{
942 Prefix: dc.srv.prefix(),
943 Command: irc.ERR_SASLABORTED,
944 Params: []string{"*", "SASL authentication aborted"},
945 }}
946 }
947
948 var resp []byte
949 if dc.sasl == nil {
950 mech := strings.ToUpper(msg.Params[0])
951 var server sasl.Server
952 switch mech {
953 case "PLAIN":
954 server = sasl.NewPlainServer(sasl.PlainAuthenticator(func(identity, username, password string) error {
955 dc.sasl.plainUsername = username
956 dc.sasl.plainPassword = password
957 return nil
958 }))
959 default:
960 return nil, ircError{&irc.Message{
961 Prefix: dc.srv.prefix(),
962 Command: irc.ERR_SASLFAIL,
963 Params: []string{"*", fmt.Sprintf("Unsupported SASL mechanism %q", mech)},
964 }}
965 }
966
967 dc.sasl = &downstreamSASL{server: server}
968 } else {
969 // TODO: multi-line messages
970 if msg.Params[0] == "+" {
971 resp = nil
972 } else if resp, err = base64.StdEncoding.DecodeString(msg.Params[0]); err != nil {
973 return nil, ircError{&irc.Message{
974 Prefix: dc.srv.prefix(),
975 Command: irc.ERR_SASLFAIL,
976 Params: []string{"*", "Invalid base64-encoded response"},
977 }}
978 }
979 }
980
981 challenge, done, err := dc.sasl.server.Next(resp)
982 if err != nil {
983 return nil, err
984 } else if done {
985 return dc.sasl, nil
986 } else {
987 challengeStr := "+"
988 if len(challenge) > 0 {
989 challengeStr = base64.StdEncoding.EncodeToString(challenge)
990 }
991
992 // TODO: multi-line messages
993 dc.SendMessage(&irc.Message{
994 Prefix: dc.srv.prefix(),
995 Command: "AUTHENTICATE",
996 Params: []string{challengeStr},
997 })
998 return nil, nil
999 }
1000}
1001
1002func (dc *downstreamConn) endSASL(msg *irc.Message) {
1003 if dc.sasl == nil {
1004 return
1005 }
1006
1007 dc.sasl = nil
1008
1009 if msg != nil {
1010 dc.SendMessage(msg)
1011 } else {
1012 dc.SendMessage(&irc.Message{
1013 Prefix: dc.srv.prefix(),
1014 Command: irc.RPL_SASLSUCCESS,
1015 Params: []string{dc.nick, "SASL authentication successful"},
1016 })
1017 }
1018}
1019
1020func (dc *downstreamConn) setSupportedCap(name, value string) {
1021 prevValue, hasPrev := dc.supportedCaps[name]
1022 changed := !hasPrev || prevValue != value
1023 dc.supportedCaps[name] = value
1024
1025 if !dc.caps["cap-notify"] || !changed {
1026 return
1027 }
1028
1029 cap := name
1030 if value != "" && dc.capVersion >= 302 {
1031 cap = name + "=" + value
1032 }
1033
1034 dc.SendMessage(&irc.Message{
1035 Prefix: dc.srv.prefix(),
1036 Command: "CAP",
1037 Params: []string{dc.nick, "NEW", cap},
1038 })
1039}
1040
1041func (dc *downstreamConn) unsetSupportedCap(name string) {
1042 _, hasPrev := dc.supportedCaps[name]
1043 delete(dc.supportedCaps, name)
1044 delete(dc.caps, name)
1045
1046 if !dc.caps["cap-notify"] || !hasPrev {
1047 return
1048 }
1049
1050 dc.SendMessage(&irc.Message{
1051 Prefix: dc.srv.prefix(),
1052 Command: "CAP",
1053 Params: []string{dc.nick, "DEL", name},
1054 })
1055}
1056
1057func (dc *downstreamConn) updateSupportedCaps() {
1058 supportedCaps := make(map[string]bool)
1059 for cap := range needAllDownstreamCaps {
1060 supportedCaps[cap] = true
1061 }
1062 dc.forEachUpstream(func(uc *upstreamConn) {
1063 for cap, supported := range supportedCaps {
1064 supportedCaps[cap] = supported && uc.caps[cap]
1065 }
1066 })
1067
1068 for cap, supported := range supportedCaps {
1069 if supported {
1070 dc.setSupportedCap(cap, needAllDownstreamCaps[cap])
1071 } else {
1072 dc.unsetSupportedCap(cap)
1073 }
1074 }
1075
1076 if uc := dc.upstream(); uc != nil && uc.supportsSASL("PLAIN") {
1077 dc.setSupportedCap("sasl", "PLAIN")
1078 } else if dc.network != nil {
1079 dc.unsetSupportedCap("sasl")
1080 }
1081
1082 if uc := dc.upstream(); uc != nil && uc.caps["draft/account-registration"] {
1083 // Strip "before-connect", because we require downstreams to be fully
1084 // connected before attempting account registration.
1085 values := strings.Split(uc.supportedCaps["draft/account-registration"], ",")
1086 for i, v := range values {
1087 if v == "before-connect" {
1088 values = append(values[:i], values[i+1:]...)
1089 break
1090 }
1091 }
1092 dc.setSupportedCap("draft/account-registration", strings.Join(values, ","))
1093 } else {
1094 dc.unsetSupportedCap("draft/account-registration")
1095 }
1096
1097 if _, ok := dc.user.msgStore.(chatHistoryMessageStore); ok && dc.network != nil {
1098 dc.setSupportedCap("draft/event-playback", "")
1099 } else {
1100 dc.unsetSupportedCap("draft/event-playback")
1101 }
1102}
1103
1104func (dc *downstreamConn) updateNick() {
1105 if uc := dc.upstream(); uc != nil && uc.nick != dc.nick {
1106 dc.SendMessage(&irc.Message{
1107 Prefix: dc.prefix(),
1108 Command: "NICK",
1109 Params: []string{uc.nick},
1110 })
1111 dc.nick = uc.nick
1112 dc.nickCM = casemapASCII(dc.nick)
1113 }
1114}
1115
1116func (dc *downstreamConn) updateRealname() {
1117 if uc := dc.upstream(); uc != nil && uc.realname != dc.realname && dc.caps["setname"] {
1118 dc.SendMessage(&irc.Message{
1119 Prefix: dc.prefix(),
1120 Command: "SETNAME",
1121 Params: []string{uc.realname},
1122 })
1123 dc.realname = uc.realname
1124 }
1125}
1126
1127func (dc *downstreamConn) updateAccount() {
1128 var account string
1129 if dc.network == nil {
1130 account = dc.user.Username
1131 } else if uc := dc.upstream(); uc != nil {
1132 account = uc.account
1133 } else {
1134 return
1135 }
1136
1137 if dc.account == account || !dc.caps["sasl"] {
1138 return
1139 }
1140
1141 if account != "" {
1142 dc.SendMessage(&irc.Message{
1143 Prefix: dc.srv.prefix(),
1144 Command: irc.RPL_LOGGEDIN,
1145 Params: []string{dc.nick, dc.prefix().String(), account, "You are logged in as " + account},
1146 })
1147 } else {
1148 dc.SendMessage(&irc.Message{
1149 Prefix: dc.srv.prefix(),
1150 Command: irc.RPL_LOGGEDOUT,
1151 Params: []string{dc.nick, dc.prefix().String(), "You are logged out"},
1152 })
1153 }
1154
1155 dc.account = account
1156}
1157
1158func sanityCheckServer(ctx context.Context, addr string) error {
1159 ctx, cancel := context.WithTimeout(ctx, 15*time.Second)
1160 defer cancel()
1161
1162 conn, err := new(tls.Dialer).DialContext(ctx, "tcp", addr)
1163 if err != nil {
1164 return err
1165 }
1166
1167 return conn.Close()
1168}
1169
1170func unmarshalUsername(rawUsername string) (username, client, network string) {
1171 username = rawUsername
1172
1173 i := strings.IndexAny(username, "/@")
1174 j := strings.LastIndexAny(username, "/@")
1175 if i >= 0 {
1176 username = rawUsername[:i]
1177 }
1178 if j >= 0 {
1179 if rawUsername[j] == '@' {
1180 client = rawUsername[j+1:]
1181 } else {
1182 network = rawUsername[j+1:]
1183 }
1184 }
1185 if i >= 0 && j >= 0 && i < j {
1186 if rawUsername[i] == '@' {
1187 client = rawUsername[i+1 : j]
1188 } else {
1189 network = rawUsername[i+1 : j]
1190 }
1191 }
1192
1193 return username, client, network
1194}
1195
1196func (dc *downstreamConn) authenticate(ctx context.Context, username, password string) error {
1197 username, clientName, networkName := unmarshalUsername(username)
1198
1199 u, err := dc.srv.db.GetUser(ctx, username)
1200 if err != nil {
1201 return newInvalidUsernameOrPasswordError(fmt.Errorf("user not found: %w", err))
1202 }
1203
1204 // Password auth disabled
1205 if u.Password == "" {
1206 return newInvalidUsernameOrPasswordError(fmt.Errorf("password auth disabled"))
1207 }
1208
1209 err = bcrypt.CompareHashAndPassword([]byte(u.Password), []byte(password))
1210 if err != nil {
1211 return newInvalidUsernameOrPasswordError(fmt.Errorf("wrong password"))
1212 }
1213
1214 dc.user = dc.srv.getUser(username)
1215 if dc.user == nil {
1216 return fmt.Errorf("user not active")
1217 }
1218 dc.clientName = clientName
1219 dc.networkName = networkName
1220 return nil
1221}
1222
1223func (dc *downstreamConn) register(ctx context.Context) error {
1224 if dc.registered {
1225 return fmt.Errorf("tried to register twice")
1226 }
1227
1228 if dc.sasl != nil {
1229 dc.endSASL(&irc.Message{
1230 Prefix: dc.srv.prefix(),
1231 Command: irc.ERR_SASLABORTED,
1232 Params: []string{"*", "SASL authentication aborted"},
1233 })
1234 }
1235
1236 password := dc.password
1237 dc.password = ""
1238 if dc.user == nil {
1239 if err := dc.authenticate(ctx, dc.rawUsername, password); err != nil {
1240 dc.logger.Printf("PASS authentication error for user %q: %v", dc.rawUsername, err)
1241 return ircError{&irc.Message{
1242 Command: irc.ERR_PASSWDMISMATCH,
1243 Params: []string{"*", authErrorReason(err)},
1244 }}
1245 }
1246 }
1247
1248 if dc.clientName == "" && dc.networkName == "" {
1249 _, dc.clientName, dc.networkName = unmarshalUsername(dc.rawUsername)
1250 }
1251
1252 dc.registered = true
1253 dc.logger.Printf("registration complete for user %q", dc.user.Username)
1254 return nil
1255}
1256
1257func (dc *downstreamConn) loadNetwork(ctx context.Context) error {
1258 if dc.networkName == "" {
1259 return nil
1260 }
1261
1262 network := dc.user.getNetwork(dc.networkName)
1263 if network == nil {
1264 addr := dc.networkName
1265 if !strings.ContainsRune(addr, ':') {
1266 addr = addr + ":6697"
1267 }
1268
1269 dc.logger.Printf("trying to connect to new network %q", addr)
1270 if err := sanityCheckServer(ctx, addr); err != nil {
1271 dc.logger.Printf("failed to connect to %q: %v", addr, err)
1272 return ircError{&irc.Message{
1273 Command: irc.ERR_PASSWDMISMATCH,
1274 Params: []string{"*", fmt.Sprintf("Failed to connect to %q", dc.networkName)},
1275 }}
1276 }
1277
1278 // Some clients only allow specifying the nickname (and use the
1279 // nickname as a username too). Strip the network name from the
1280 // nickname when auto-saving networks.
1281 nick, _, _ := unmarshalUsername(dc.nick)
1282
1283 dc.logger.Printf("auto-saving network %q", dc.networkName)
1284 var err error
1285 network, err = dc.user.createNetwork(ctx, &Network{
1286 Addr: dc.networkName,
1287 Nick: nick,
1288 Enabled: true,
1289 })
1290 if err != nil {
1291 return err
1292 }
1293 }
1294
1295 dc.network = network
1296 return nil
1297}
1298
1299func (dc *downstreamConn) welcome(ctx context.Context) error {
1300 if dc.user == nil || !dc.registered {
1301 panic("tried to welcome an unregistered connection")
1302 }
1303
1304 // TODO: doing this might take some time. We should do it in dc.register
1305 // instead, but we'll potentially be adding a new network and this must be
1306 // done in the user goroutine.
1307 if err := dc.loadNetwork(ctx); err != nil {
1308 return err
1309 }
1310
1311 if dc.network == nil && !dc.caps["soju.im/bouncer-networks"] && dc.srv.Config().MultiUpstream {
1312 dc.isMultiUpstream = true
1313 }
1314
1315 dc.updateSupportedCaps()
1316
1317 isupport := []string{
1318 fmt.Sprintf("CHATHISTORY=%v", chatHistoryLimit),
1319 "CASEMAPPING=ascii",
1320 }
1321
1322 if dc.network != nil {
1323 isupport = append(isupport, fmt.Sprintf("BOUNCER_NETID=%v", dc.network.ID))
1324 }
1325 if title := dc.srv.Config().Title; dc.network == nil && title != "" {
1326 isupport = append(isupport, "NETWORK="+encodeISUPPORT(title))
1327 }
1328 if dc.network == nil && !dc.isMultiUpstream {
1329 isupport = append(isupport, "WHOX")
1330 }
1331
1332 if uc := dc.upstream(); uc != nil {
1333 for k := range passthroughIsupport {
1334 v, ok := uc.isupport[k]
1335 if !ok {
1336 continue
1337 }
1338 if v != nil {
1339 isupport = append(isupport, fmt.Sprintf("%v=%v", k, *v))
1340 } else {
1341 isupport = append(isupport, k)
1342 }
1343 }
1344 }
1345
1346 dc.SendMessage(&irc.Message{
1347 Prefix: dc.srv.prefix(),
1348 Command: irc.RPL_WELCOME,
1349 Params: []string{dc.nick, "Welcome to soju, " + dc.nick},
1350 })
1351 dc.SendMessage(&irc.Message{
1352 Prefix: dc.srv.prefix(),
1353 Command: irc.RPL_YOURHOST,
1354 Params: []string{dc.nick, "Your host is " + dc.srv.Config().Hostname},
1355 })
1356 dc.SendMessage(&irc.Message{
1357 Prefix: dc.srv.prefix(),
1358 Command: irc.RPL_MYINFO,
1359 Params: []string{dc.nick, dc.srv.Config().Hostname, "soju", "aiwroO", "OovaimnqpsrtklbeI"},
1360 })
1361 for _, msg := range generateIsupport(dc.srv.prefix(), dc.nick, isupport) {
1362 dc.SendMessage(msg)
1363 }
1364 if uc := dc.upstream(); uc != nil {
1365 dc.SendMessage(&irc.Message{
1366 Prefix: dc.srv.prefix(),
1367 Command: irc.RPL_UMODEIS,
1368 Params: []string{dc.nick, "+" + string(uc.modes)},
1369 })
1370 }
1371 if dc.network == nil && !dc.isMultiUpstream && dc.user.Admin {
1372 dc.SendMessage(&irc.Message{
1373 Prefix: dc.srv.prefix(),
1374 Command: irc.RPL_UMODEIS,
1375 Params: []string{dc.nick, "+o"},
1376 })
1377 }
1378
1379 dc.updateNick()
1380 dc.updateRealname()
1381 dc.updateAccount()
1382
1383 if motd := dc.user.srv.Config().MOTD; motd != "" && dc.network == nil {
1384 for _, msg := range generateMOTD(dc.srv.prefix(), dc.nick, motd) {
1385 dc.SendMessage(msg)
1386 }
1387 } else {
1388 motdHint := "No MOTD"
1389 if dc.network != nil {
1390 motdHint = "Use /motd to read the message of the day"
1391 }
1392 dc.SendMessage(&irc.Message{
1393 Prefix: dc.srv.prefix(),
1394 Command: irc.ERR_NOMOTD,
1395 Params: []string{dc.nick, motdHint},
1396 })
1397 }
1398
1399 if dc.caps["soju.im/bouncer-networks-notify"] {
1400 dc.SendBatch("soju.im/bouncer-networks", nil, nil, func(batchRef irc.TagValue) {
1401 dc.user.forEachNetwork(func(network *network) {
1402 idStr := fmt.Sprintf("%v", network.ID)
1403 attrs := getNetworkAttrs(network)
1404 dc.SendMessage(&irc.Message{
1405 Tags: irc.Tags{"batch": batchRef},
1406 Prefix: dc.srv.prefix(),
1407 Command: "BOUNCER",
1408 Params: []string{"NETWORK", idStr, attrs.String()},
1409 })
1410 })
1411 })
1412 }
1413
1414 dc.forEachUpstream(func(uc *upstreamConn) {
1415 for _, entry := range uc.channels.innerMap {
1416 ch := entry.value.(*upstreamChannel)
1417 if !ch.complete {
1418 continue
1419 }
1420 record := uc.network.channels.Value(ch.Name)
1421 if record != nil && record.Detached {
1422 continue
1423 }
1424
1425 dc.SendMessage(&irc.Message{
1426 Prefix: dc.prefix(),
1427 Command: "JOIN",
1428 Params: []string{dc.marshalEntity(ch.conn.network, ch.Name)},
1429 })
1430
1431 forwardChannel(dc, ch)
1432 }
1433 })
1434
1435 dc.forEachNetwork(func(net *network) {
1436 if dc.caps["draft/chathistory"] || dc.user.msgStore == nil {
1437 return
1438 }
1439
1440 // Only send history if we're the first connected client with that name
1441 // for the network
1442 firstClient := true
1443 dc.user.forEachDownstream(func(c *downstreamConn) {
1444 if c != dc && c.clientName == dc.clientName && c.network == dc.network {
1445 firstClient = false
1446 }
1447 })
1448 if firstClient {
1449 net.delivered.ForEachTarget(func(target string) {
1450 lastDelivered := net.delivered.LoadID(target, dc.clientName)
1451 if lastDelivered == "" {
1452 return
1453 }
1454
1455 dc.sendTargetBacklog(ctx, net, target, lastDelivered)
1456
1457 // Fast-forward history to last message
1458 targetCM := net.casemap(target)
1459 lastID, err := dc.user.msgStore.LastMsgID(&net.Network, targetCM, time.Now())
1460 if err != nil {
1461 dc.logger.Printf("failed to get last message ID: %v", err)
1462 return
1463 }
1464 net.delivered.StoreID(target, dc.clientName, lastID)
1465 })
1466 }
1467 })
1468
1469 return nil
1470}
1471
1472// messageSupportsBacklog checks whether the provided message can be sent as
1473// part of an history batch.
1474func (dc *downstreamConn) messageSupportsBacklog(msg *irc.Message) bool {
1475 // Don't replay all messages, because that would mess up client
1476 // state. For instance we just sent the list of users, sending
1477 // PART messages for one of these users would be incorrect.
1478 switch msg.Command {
1479 case "PRIVMSG", "NOTICE":
1480 return true
1481 }
1482 return false
1483}
1484
1485func (dc *downstreamConn) sendTargetBacklog(ctx context.Context, net *network, target, msgID string) {
1486 if dc.caps["draft/chathistory"] || dc.user.msgStore == nil {
1487 return
1488 }
1489
1490 ch := net.channels.Value(target)
1491
1492 ctx, cancel := context.WithTimeout(ctx, backlogTimeout)
1493 defer cancel()
1494
1495 targetCM := net.casemap(target)
1496 history, err := dc.user.msgStore.LoadLatestID(ctx, &net.Network, targetCM, msgID, backlogLimit)
1497 if err != nil {
1498 dc.logger.Printf("failed to send backlog for %q: %v", target, err)
1499 return
1500 }
1501
1502 dc.SendBatch("chathistory", []string{dc.marshalEntity(net, target)}, nil, func(batchRef irc.TagValue) {
1503 for _, msg := range history {
1504 if ch != nil && ch.Detached {
1505 if net.detachedMessageNeedsRelay(ch, msg) {
1506 dc.relayDetachedMessage(net, msg)
1507 }
1508 } else {
1509 msg.Tags["batch"] = batchRef
1510 dc.SendMessage(dc.marshalMessage(msg, net))
1511 }
1512 }
1513 })
1514}
1515
1516func (dc *downstreamConn) relayDetachedMessage(net *network, msg *irc.Message) {
1517 if msg.Command != "PRIVMSG" && msg.Command != "NOTICE" {
1518 return
1519 }
1520
1521 sender := msg.Prefix.Name
1522 target, text := msg.Params[0], msg.Params[1]
1523 if net.isHighlight(msg) {
1524 sendServiceNOTICE(dc, fmt.Sprintf("highlight in %v: <%v> %v", dc.marshalEntity(net, target), sender, text))
1525 } else {
1526 sendServiceNOTICE(dc, fmt.Sprintf("message in %v: <%v> %v", dc.marshalEntity(net, target), sender, text))
1527 }
1528}
1529
1530func (dc *downstreamConn) runUntilRegistered() error {
1531 ctx, cancel := context.WithTimeout(context.TODO(), downstreamRegisterTimeout)
1532 defer cancel()
1533
1534 // Close the connection with an error if the deadline is exceeded
1535 go func() {
1536 <-ctx.Done()
1537 if err := ctx.Err(); err == context.DeadlineExceeded {
1538 dc.SendMessage(&irc.Message{
1539 Prefix: dc.srv.prefix(),
1540 Command: "ERROR",
1541 Params: []string{"Connection registration timed out"},
1542 })
1543 dc.Close()
1544 }
1545 }()
1546
1547 for !dc.registered {
1548 msg, err := dc.ReadMessage()
1549 if err != nil {
1550 return fmt.Errorf("failed to read IRC command: %w", err)
1551 }
1552
1553 err = dc.handleMessage(ctx, msg)
1554 if ircErr, ok := err.(ircError); ok {
1555 ircErr.Message.Prefix = dc.srv.prefix()
1556 dc.SendMessage(ircErr.Message)
1557 } else if err != nil {
1558 return fmt.Errorf("failed to handle IRC command %q: %v", msg, err)
1559 }
1560 }
1561
1562 return nil
1563}
1564
1565func (dc *downstreamConn) handleMessageRegistered(ctx context.Context, msg *irc.Message) error {
1566 switch msg.Command {
1567 case "CAP":
1568 var subCmd string
1569 if err := parseMessageParams(msg, &subCmd); err != nil {
1570 return err
1571 }
1572 if err := dc.handleCapCommand(subCmd, msg.Params[1:]); err != nil {
1573 return err
1574 }
1575 case "PING":
1576 var source, destination string
1577 if err := parseMessageParams(msg, &source); err != nil {
1578 return err
1579 }
1580 if len(msg.Params) > 1 {
1581 destination = msg.Params[1]
1582 }
1583 hostname := dc.srv.Config().Hostname
1584 if destination != "" && destination != hostname {
1585 return ircError{&irc.Message{
1586 Command: irc.ERR_NOSUCHSERVER,
1587 Params: []string{dc.nick, destination, "No such server"},
1588 }}
1589 }
1590 dc.SendMessage(&irc.Message{
1591 Prefix: dc.srv.prefix(),
1592 Command: "PONG",
1593 Params: []string{hostname, source},
1594 })
1595 return nil
1596 case "PONG":
1597 if len(msg.Params) == 0 {
1598 return newNeedMoreParamsError(msg.Command)
1599 }
1600 token := msg.Params[len(msg.Params)-1]
1601 dc.handlePong(token)
1602 case "USER":
1603 return ircError{&irc.Message{
1604 Command: irc.ERR_ALREADYREGISTERED,
1605 Params: []string{dc.nick, "You may not reregister"},
1606 }}
1607 case "NICK":
1608 var rawNick string
1609 if err := parseMessageParams(msg, &rawNick); err != nil {
1610 return err
1611 }
1612
1613 nick := rawNick
1614 var upstream *upstreamConn
1615 if dc.upstream() == nil {
1616 uc, unmarshaledNick, err := dc.unmarshalEntity(nick)
1617 if err == nil { // NICK nick/network: NICK only on a specific upstream
1618 upstream = uc
1619 nick = unmarshaledNick
1620 }
1621 }
1622
1623 if nick == "" || strings.ContainsAny(nick, illegalNickChars) {
1624 return ircError{&irc.Message{
1625 Command: irc.ERR_ERRONEUSNICKNAME,
1626 Params: []string{dc.nick, rawNick, "contains illegal characters"},
1627 }}
1628 }
1629 if casemapASCII(nick) == serviceNickCM {
1630 return ircError{&irc.Message{
1631 Command: irc.ERR_NICKNAMEINUSE,
1632 Params: []string{dc.nick, rawNick, "Nickname reserved for bouncer service"},
1633 }}
1634 }
1635
1636 var err error
1637 dc.forEachNetwork(func(n *network) {
1638 if err != nil || (upstream != nil && upstream.network != n) {
1639 return
1640 }
1641 n.Nick = nick
1642 err = dc.srv.db.StoreNetwork(ctx, dc.user.ID, &n.Network)
1643 })
1644 if err != nil {
1645 return err
1646 }
1647
1648 dc.forEachUpstream(func(uc *upstreamConn) {
1649 if upstream != nil && upstream != uc {
1650 return
1651 }
1652 uc.SendMessageLabeled(dc.id, &irc.Message{
1653 Command: "NICK",
1654 Params: []string{nick},
1655 })
1656 })
1657
1658 if dc.upstream() == nil && upstream == nil && dc.nick != nick {
1659 dc.SendMessage(&irc.Message{
1660 Prefix: dc.prefix(),
1661 Command: "NICK",
1662 Params: []string{nick},
1663 })
1664 dc.nick = nick
1665 dc.nickCM = casemapASCII(dc.nick)
1666 }
1667 case "SETNAME":
1668 var realname string
1669 if err := parseMessageParams(msg, &realname); err != nil {
1670 return err
1671 }
1672
1673 // If the client just resets to the default, just wipe the per-network
1674 // preference
1675 storeRealname := realname
1676 if realname == dc.user.Realname {
1677 storeRealname = ""
1678 }
1679
1680 var storeErr error
1681 var needUpdate []Network
1682 dc.forEachNetwork(func(n *network) {
1683 // We only need to call updateNetwork for upstreams that don't
1684 // support setname
1685 if uc := n.conn; uc != nil && uc.caps["setname"] {
1686 uc.SendMessageLabeled(dc.id, &irc.Message{
1687 Command: "SETNAME",
1688 Params: []string{realname},
1689 })
1690
1691 n.Realname = storeRealname
1692 if err := dc.srv.db.StoreNetwork(ctx, dc.user.ID, &n.Network); err != nil {
1693 dc.logger.Printf("failed to store network realname: %v", err)
1694 storeErr = err
1695 }
1696 return
1697 }
1698
1699 record := n.Network // copy network record because we'll mutate it
1700 record.Realname = storeRealname
1701 needUpdate = append(needUpdate, record)
1702 })
1703
1704 // Walk the network list as a second step, because updateNetwork
1705 // mutates the original list
1706 for _, record := range needUpdate {
1707 if _, err := dc.user.updateNetwork(ctx, &record); err != nil {
1708 dc.logger.Printf("failed to update network realname: %v", err)
1709 storeErr = err
1710 }
1711 }
1712 if storeErr != nil {
1713 return ircError{&irc.Message{
1714 Command: "FAIL",
1715 Params: []string{"SETNAME", "CANNOT_CHANGE_REALNAME", "Failed to update realname"},
1716 }}
1717 }
1718
1719 if dc.upstream() == nil {
1720 dc.SendMessage(&irc.Message{
1721 Prefix: dc.prefix(),
1722 Command: "SETNAME",
1723 Params: []string{realname},
1724 })
1725 }
1726 case "JOIN":
1727 var namesStr string
1728 if err := parseMessageParams(msg, &namesStr); err != nil {
1729 return err
1730 }
1731
1732 var keys []string
1733 if len(msg.Params) > 1 {
1734 keys = strings.Split(msg.Params[1], ",")
1735 }
1736
1737 for i, name := range strings.Split(namesStr, ",") {
1738 uc, upstreamName, err := dc.unmarshalEntity(name)
1739 if err != nil {
1740 return err
1741 }
1742
1743 var key string
1744 if len(keys) > i {
1745 key = keys[i]
1746 }
1747
1748 if !uc.isChannel(upstreamName) {
1749 dc.SendMessage(&irc.Message{
1750 Prefix: dc.srv.prefix(),
1751 Command: irc.ERR_NOSUCHCHANNEL,
1752 Params: []string{name, "Not a channel name"},
1753 })
1754 continue
1755 }
1756
1757 params := []string{upstreamName}
1758 if key != "" {
1759 params = append(params, key)
1760 }
1761 uc.SendMessageLabeled(dc.id, &irc.Message{
1762 Command: "JOIN",
1763 Params: params,
1764 })
1765
1766 ch := uc.network.channels.Value(upstreamName)
1767 if ch != nil {
1768 // Don't clear the channel key if there's one set
1769 // TODO: add a way to unset the channel key
1770 if key != "" {
1771 ch.Key = key
1772 }
1773 uc.network.attach(ch)
1774 } else {
1775 ch = &Channel{
1776 Name: upstreamName,
1777 Key: key,
1778 }
1779 uc.network.channels.SetValue(upstreamName, ch)
1780 }
1781 if err := dc.srv.db.StoreChannel(ctx, uc.network.ID, ch); err != nil {
1782 dc.logger.Printf("failed to create or update channel %q: %v", upstreamName, err)
1783 }
1784 }
1785 case "PART":
1786 var namesStr string
1787 if err := parseMessageParams(msg, &namesStr); err != nil {
1788 return err
1789 }
1790
1791 var reason string
1792 if len(msg.Params) > 1 {
1793 reason = msg.Params[1]
1794 }
1795
1796 for _, name := range strings.Split(namesStr, ",") {
1797 uc, upstreamName, err := dc.unmarshalEntity(name)
1798 if err != nil {
1799 return err
1800 }
1801
1802 if strings.EqualFold(reason, "detach") {
1803 ch := uc.network.channels.Value(upstreamName)
1804 if ch != nil {
1805 uc.network.detach(ch)
1806 } else {
1807 ch = &Channel{
1808 Name: name,
1809 Detached: true,
1810 }
1811 uc.network.channels.SetValue(upstreamName, ch)
1812 }
1813 if err := dc.srv.db.StoreChannel(ctx, uc.network.ID, ch); err != nil {
1814 dc.logger.Printf("failed to create or update channel %q: %v", upstreamName, err)
1815 }
1816 } else {
1817 params := []string{upstreamName}
1818 if reason != "" {
1819 params = append(params, reason)
1820 }
1821 uc.SendMessageLabeled(dc.id, &irc.Message{
1822 Command: "PART",
1823 Params: params,
1824 })
1825
1826 if err := uc.network.deleteChannel(ctx, upstreamName); err != nil {
1827 dc.logger.Printf("failed to delete channel %q: %v", upstreamName, err)
1828 }
1829 }
1830 }
1831 case "KICK":
1832 var channelStr, userStr string
1833 if err := parseMessageParams(msg, &channelStr, &userStr); err != nil {
1834 return err
1835 }
1836
1837 channels := strings.Split(channelStr, ",")
1838 users := strings.Split(userStr, ",")
1839
1840 var reason string
1841 if len(msg.Params) > 2 {
1842 reason = msg.Params[2]
1843 }
1844
1845 if len(channels) != 1 && len(channels) != len(users) {
1846 return ircError{&irc.Message{
1847 Command: irc.ERR_BADCHANMASK,
1848 Params: []string{dc.nick, channelStr, "Bad channel mask"},
1849 }}
1850 }
1851
1852 for i, user := range users {
1853 var channel string
1854 if len(channels) == 1 {
1855 channel = channels[0]
1856 } else {
1857 channel = channels[i]
1858 }
1859
1860 ucChannel, upstreamChannel, err := dc.unmarshalEntity(channel)
1861 if err != nil {
1862 return err
1863 }
1864
1865 ucUser, upstreamUser, err := dc.unmarshalEntity(user)
1866 if err != nil {
1867 return err
1868 }
1869
1870 if ucChannel != ucUser {
1871 return ircError{&irc.Message{
1872 Command: irc.ERR_USERNOTINCHANNEL,
1873 Params: []string{dc.nick, user, channel, "They are on another network"},
1874 }}
1875 }
1876 uc := ucChannel
1877
1878 params := []string{upstreamChannel, upstreamUser}
1879 if reason != "" {
1880 params = append(params, reason)
1881 }
1882 uc.SendMessageLabeled(dc.id, &irc.Message{
1883 Command: "KICK",
1884 Params: params,
1885 })
1886 }
1887 case "MODE":
1888 var name string
1889 if err := parseMessageParams(msg, &name); err != nil {
1890 return err
1891 }
1892
1893 var modeStr string
1894 if len(msg.Params) > 1 {
1895 modeStr = msg.Params[1]
1896 }
1897
1898 if casemapASCII(name) == dc.nickCM {
1899 if modeStr != "" {
1900 if uc := dc.upstream(); uc != nil {
1901 uc.SendMessageLabeled(dc.id, &irc.Message{
1902 Command: "MODE",
1903 Params: []string{uc.nick, modeStr},
1904 })
1905 } else {
1906 dc.SendMessage(&irc.Message{
1907 Prefix: dc.srv.prefix(),
1908 Command: irc.ERR_UMODEUNKNOWNFLAG,
1909 Params: []string{dc.nick, "Cannot change user mode in multi-upstream mode"},
1910 })
1911 }
1912 } else {
1913 var userMode string
1914 if uc := dc.upstream(); uc != nil {
1915 userMode = string(uc.modes)
1916 }
1917
1918 dc.SendMessage(&irc.Message{
1919 Prefix: dc.srv.prefix(),
1920 Command: irc.RPL_UMODEIS,
1921 Params: []string{dc.nick, "+" + userMode},
1922 })
1923 }
1924 return nil
1925 }
1926
1927 uc, upstreamName, err := dc.unmarshalEntity(name)
1928 if err != nil {
1929 return err
1930 }
1931
1932 if !uc.isChannel(upstreamName) {
1933 return ircError{&irc.Message{
1934 Command: irc.ERR_USERSDONTMATCH,
1935 Params: []string{dc.nick, "Cannot change mode for other users"},
1936 }}
1937 }
1938
1939 if modeStr != "" {
1940 params := []string{upstreamName, modeStr}
1941 params = append(params, msg.Params[2:]...)
1942 uc.SendMessageLabeled(dc.id, &irc.Message{
1943 Command: "MODE",
1944 Params: params,
1945 })
1946 } else {
1947 ch := uc.channels.Value(upstreamName)
1948 if ch == nil {
1949 return ircError{&irc.Message{
1950 Command: irc.ERR_NOSUCHCHANNEL,
1951 Params: []string{dc.nick, name, "No such channel"},
1952 }}
1953 }
1954
1955 if ch.modes == nil {
1956 // we haven't received the initial RPL_CHANNELMODEIS yet
1957 // ignore the request, we will broadcast the modes later when we receive RPL_CHANNELMODEIS
1958 return nil
1959 }
1960
1961 modeStr, modeParams := ch.modes.Format()
1962 params := []string{dc.nick, name, modeStr}
1963 params = append(params, modeParams...)
1964
1965 dc.SendMessage(&irc.Message{
1966 Prefix: dc.srv.prefix(),
1967 Command: irc.RPL_CHANNELMODEIS,
1968 Params: params,
1969 })
1970 if ch.creationTime != "" {
1971 dc.SendMessage(&irc.Message{
1972 Prefix: dc.srv.prefix(),
1973 Command: rpl_creationtime,
1974 Params: []string{dc.nick, name, ch.creationTime},
1975 })
1976 }
1977 }
1978 case "TOPIC":
1979 var channel string
1980 if err := parseMessageParams(msg, &channel); err != nil {
1981 return err
1982 }
1983
1984 uc, upstreamName, err := dc.unmarshalEntity(channel)
1985 if err != nil {
1986 return err
1987 }
1988
1989 if len(msg.Params) > 1 { // setting topic
1990 topic := msg.Params[1]
1991 uc.SendMessageLabeled(dc.id, &irc.Message{
1992 Command: "TOPIC",
1993 Params: []string{upstreamName, topic},
1994 })
1995 } else { // getting topic
1996 ch := uc.channels.Value(upstreamName)
1997 if ch == nil {
1998 return ircError{&irc.Message{
1999 Command: irc.ERR_NOSUCHCHANNEL,
2000 Params: []string{dc.nick, upstreamName, "No such channel"},
2001 }}
2002 }
2003 sendTopic(dc, ch)
2004 }
2005 case "LIST":
2006 network := dc.network
2007 if network == nil && len(msg.Params) > 0 {
2008 var err error
2009 network, msg.Params[0], err = dc.unmarshalEntityNetwork(msg.Params[0])
2010 if err != nil {
2011 return err
2012 }
2013 }
2014 if network == nil {
2015 dc.SendMessage(&irc.Message{
2016 Prefix: dc.srv.prefix(),
2017 Command: irc.RPL_LISTEND,
2018 Params: []string{dc.nick, "LIST without a network suffix is not supported in multi-upstream mode"},
2019 })
2020 return nil
2021 }
2022
2023 uc := network.conn
2024 if uc == nil {
2025 dc.SendMessage(&irc.Message{
2026 Prefix: dc.srv.prefix(),
2027 Command: irc.RPL_LISTEND,
2028 Params: []string{dc.nick, "Disconnected from upstream server"},
2029 })
2030 return nil
2031 }
2032
2033 uc.enqueueCommand(dc, msg)
2034 case "NAMES":
2035 if len(msg.Params) == 0 {
2036 dc.SendMessage(&irc.Message{
2037 Prefix: dc.srv.prefix(),
2038 Command: irc.RPL_ENDOFNAMES,
2039 Params: []string{dc.nick, "*", "End of /NAMES list"},
2040 })
2041 return nil
2042 }
2043
2044 channels := strings.Split(msg.Params[0], ",")
2045 for _, channel := range channels {
2046 uc, upstreamName, err := dc.unmarshalEntity(channel)
2047 if err != nil {
2048 return err
2049 }
2050
2051 ch := uc.channels.Value(upstreamName)
2052 if ch != nil {
2053 sendNames(dc, ch)
2054 } else {
2055 // NAMES on a channel we have not joined, ask upstream
2056 uc.SendMessageLabeled(dc.id, &irc.Message{
2057 Command: "NAMES",
2058 Params: []string{upstreamName},
2059 })
2060 }
2061 }
2062 // For WHOX docs, see:
2063 // - http://faerion.sourceforge.net/doc/irc/whox.var
2064 // - https://github.com/quakenet/snircd/blob/master/doc/readme.who
2065 // Note, many features aren't widely implemented, such as flags and mask2
2066 case "WHO":
2067 if len(msg.Params) == 0 {
2068 // TODO: support WHO without parameters
2069 dc.SendMessage(&irc.Message{
2070 Prefix: dc.srv.prefix(),
2071 Command: irc.RPL_ENDOFWHO,
2072 Params: []string{dc.nick, "*", "End of /WHO list"},
2073 })
2074 return nil
2075 }
2076
2077 // Clients will use the first mask to match RPL_ENDOFWHO
2078 endOfWhoToken := msg.Params[0]
2079
2080 // TODO: add support for WHOX mask2
2081 mask := msg.Params[0]
2082 var options string
2083 if len(msg.Params) > 1 {
2084 options = msg.Params[1]
2085 }
2086
2087 optionsParts := strings.SplitN(options, "%", 2)
2088 // TODO: add support for WHOX flags in optionsParts[0]
2089 var fields, whoxToken string
2090 if len(optionsParts) == 2 {
2091 optionsParts := strings.SplitN(optionsParts[1], ",", 2)
2092 fields = strings.ToLower(optionsParts[0])
2093 if len(optionsParts) == 2 && strings.Contains(fields, "t") {
2094 whoxToken = optionsParts[1]
2095 }
2096 }
2097
2098 // TODO: support mixed bouncer/upstream WHO queries
2099 maskCM := casemapASCII(mask)
2100 if dc.network == nil && maskCM == dc.nickCM {
2101 // TODO: support AWAY (H/G) in self WHO reply
2102 flags := "H"
2103 if dc.user.Admin {
2104 flags += "*"
2105 }
2106 info := whoxInfo{
2107 Token: whoxToken,
2108 Username: dc.user.Username,
2109 Hostname: dc.hostname,
2110 Server: dc.srv.Config().Hostname,
2111 Nickname: dc.nick,
2112 Flags: flags,
2113 Account: dc.user.Username,
2114 Realname: dc.realname,
2115 }
2116 dc.SendMessage(generateWHOXReply(dc.srv.prefix(), dc.nick, fields, &info))
2117 dc.SendMessage(&irc.Message{
2118 Prefix: dc.srv.prefix(),
2119 Command: irc.RPL_ENDOFWHO,
2120 Params: []string{dc.nick, endOfWhoToken, "End of /WHO list"},
2121 })
2122 return nil
2123 }
2124 if maskCM == serviceNickCM {
2125 info := whoxInfo{
2126 Token: whoxToken,
2127 Username: servicePrefix.User,
2128 Hostname: servicePrefix.Host,
2129 Server: dc.srv.Config().Hostname,
2130 Nickname: serviceNick,
2131 Flags: "H*",
2132 Account: serviceNick,
2133 Realname: serviceRealname,
2134 }
2135 dc.SendMessage(generateWHOXReply(dc.srv.prefix(), dc.nick, fields, &info))
2136 dc.SendMessage(&irc.Message{
2137 Prefix: dc.srv.prefix(),
2138 Command: irc.RPL_ENDOFWHO,
2139 Params: []string{dc.nick, endOfWhoToken, "End of /WHO list"},
2140 })
2141 return nil
2142 }
2143
2144 // TODO: properly support WHO masks
2145 uc, upstreamMask, err := dc.unmarshalEntity(mask)
2146 if err != nil {
2147 return err
2148 }
2149
2150 params := []string{upstreamMask}
2151 if options != "" {
2152 params = append(params, options)
2153 }
2154
2155 uc.enqueueCommand(dc, &irc.Message{
2156 Command: "WHO",
2157 Params: params,
2158 })
2159 case "WHOIS":
2160 if len(msg.Params) == 0 {
2161 return ircError{&irc.Message{
2162 Command: irc.ERR_NONICKNAMEGIVEN,
2163 Params: []string{dc.nick, "No nickname given"},
2164 }}
2165 }
2166
2167 var target, mask string
2168 if len(msg.Params) == 1 {
2169 target = ""
2170 mask = msg.Params[0]
2171 } else {
2172 target = msg.Params[0]
2173 mask = msg.Params[1]
2174 }
2175 // TODO: support multiple WHOIS users
2176 if i := strings.IndexByte(mask, ','); i >= 0 {
2177 mask = mask[:i]
2178 }
2179
2180 if dc.network == nil && casemapASCII(mask) == dc.nickCM {
2181 dc.SendMessage(&irc.Message{
2182 Prefix: dc.srv.prefix(),
2183 Command: irc.RPL_WHOISUSER,
2184 Params: []string{dc.nick, dc.nick, dc.user.Username, dc.hostname, "*", dc.realname},
2185 })
2186 dc.SendMessage(&irc.Message{
2187 Prefix: dc.srv.prefix(),
2188 Command: irc.RPL_WHOISSERVER,
2189 Params: []string{dc.nick, dc.nick, dc.srv.Config().Hostname, "soju"},
2190 })
2191 if dc.user.Admin {
2192 dc.SendMessage(&irc.Message{
2193 Prefix: dc.srv.prefix(),
2194 Command: irc.RPL_WHOISOPERATOR,
2195 Params: []string{dc.nick, dc.nick, "is a bouncer administrator"},
2196 })
2197 }
2198 dc.SendMessage(&irc.Message{
2199 Prefix: dc.srv.prefix(),
2200 Command: rpl_whoisaccount,
2201 Params: []string{dc.nick, dc.nick, dc.user.Username, "is logged in as"},
2202 })
2203 dc.SendMessage(&irc.Message{
2204 Prefix: dc.srv.prefix(),
2205 Command: irc.RPL_ENDOFWHOIS,
2206 Params: []string{dc.nick, dc.nick, "End of /WHOIS list"},
2207 })
2208 return nil
2209 }
2210 if casemapASCII(mask) == serviceNickCM {
2211 dc.SendMessage(&irc.Message{
2212 Prefix: dc.srv.prefix(),
2213 Command: irc.RPL_WHOISUSER,
2214 Params: []string{dc.nick, serviceNick, servicePrefix.User, servicePrefix.Host, "*", serviceRealname},
2215 })
2216 dc.SendMessage(&irc.Message{
2217 Prefix: dc.srv.prefix(),
2218 Command: irc.RPL_WHOISSERVER,
2219 Params: []string{dc.nick, serviceNick, dc.srv.Config().Hostname, "soju"},
2220 })
2221 dc.SendMessage(&irc.Message{
2222 Prefix: dc.srv.prefix(),
2223 Command: irc.RPL_WHOISOPERATOR,
2224 Params: []string{dc.nick, serviceNick, "is the bouncer service"},
2225 })
2226 dc.SendMessage(&irc.Message{
2227 Prefix: dc.srv.prefix(),
2228 Command: rpl_whoisaccount,
2229 Params: []string{dc.nick, serviceNick, serviceNick, "is logged in as"},
2230 })
2231 dc.SendMessage(&irc.Message{
2232 Prefix: dc.srv.prefix(),
2233 Command: irc.RPL_ENDOFWHOIS,
2234 Params: []string{dc.nick, serviceNick, "End of /WHOIS list"},
2235 })
2236 return nil
2237 }
2238
2239 // TODO: support WHOIS masks
2240 uc, upstreamNick, err := dc.unmarshalEntity(mask)
2241 if err != nil {
2242 return err
2243 }
2244
2245 var params []string
2246 if target != "" {
2247 if target == mask { // WHOIS nick nick
2248 params = []string{upstreamNick, upstreamNick}
2249 } else {
2250 params = []string{target, upstreamNick}
2251 }
2252 } else {
2253 params = []string{upstreamNick}
2254 }
2255
2256 uc.SendMessageLabeled(dc.id, &irc.Message{
2257 Command: "WHOIS",
2258 Params: params,
2259 })
2260 case "PRIVMSG", "NOTICE":
2261 var targetsStr, text string
2262 if err := parseMessageParams(msg, &targetsStr, &text); err != nil {
2263 return err
2264 }
2265 tags := copyClientTags(msg.Tags)
2266
2267 for _, name := range strings.Split(targetsStr, ",") {
2268 if name == "$"+dc.srv.Config().Hostname || (name == "$*" && dc.network == nil) {
2269 // "$" means a server mask follows. If it's the bouncer's
2270 // hostname, broadcast the message to all bouncer users.
2271 if !dc.user.Admin {
2272 return ircError{&irc.Message{
2273 Prefix: dc.srv.prefix(),
2274 Command: irc.ERR_BADMASK,
2275 Params: []string{dc.nick, name, "Permission denied to broadcast message to all bouncer users"},
2276 }}
2277 }
2278
2279 dc.logger.Printf("broadcasting bouncer-wide %v: %v", msg.Command, text)
2280
2281 broadcastTags := tags.Copy()
2282 broadcastTags["time"] = irc.TagValue(time.Now().UTC().Format(serverTimeLayout))
2283 broadcastMsg := &irc.Message{
2284 Tags: broadcastTags,
2285 Prefix: servicePrefix,
2286 Command: msg.Command,
2287 Params: []string{name, text},
2288 }
2289 dc.srv.forEachUser(func(u *user) {
2290 u.events <- eventBroadcast{broadcastMsg}
2291 })
2292 continue
2293 }
2294
2295 if dc.network == nil && casemapASCII(name) == dc.nickCM {
2296 dc.SendMessage(&irc.Message{
2297 Tags: msg.Tags.Copy(),
2298 Prefix: dc.prefix(),
2299 Command: msg.Command,
2300 Params: []string{name, text},
2301 })
2302 continue
2303 }
2304
2305 if msg.Command == "PRIVMSG" && casemapASCII(name) == serviceNickCM {
2306 if dc.caps["echo-message"] {
2307 echoTags := tags.Copy()
2308 echoTags["time"] = irc.TagValue(time.Now().UTC().Format(serverTimeLayout))
2309 dc.SendMessage(&irc.Message{
2310 Tags: echoTags,
2311 Prefix: dc.prefix(),
2312 Command: msg.Command,
2313 Params: []string{name, text},
2314 })
2315 }
2316 handleServicePRIVMSG(ctx, dc, text)
2317 continue
2318 }
2319
2320 uc, upstreamName, err := dc.unmarshalEntity(name)
2321 if err != nil {
2322 return err
2323 }
2324
2325 if msg.Command == "PRIVMSG" && uc.network.casemap(upstreamName) == "nickserv" {
2326 dc.handleNickServPRIVMSG(ctx, uc, text)
2327 }
2328
2329 unmarshaledText := text
2330 if uc.isChannel(upstreamName) {
2331 unmarshaledText = dc.unmarshalText(uc, text)
2332 }
2333 uc.SendMessageLabeled(dc.id, &irc.Message{
2334 Tags: tags,
2335 Command: msg.Command,
2336 Params: []string{upstreamName, unmarshaledText},
2337 })
2338
2339 echoTags := tags.Copy()
2340 echoTags["time"] = irc.TagValue(time.Now().UTC().Format(serverTimeLayout))
2341 if uc.account != "" {
2342 echoTags["account"] = irc.TagValue(uc.account)
2343 }
2344 echoMsg := &irc.Message{
2345 Tags: echoTags,
2346 Prefix: &irc.Prefix{Name: uc.nick},
2347 Command: msg.Command,
2348 Params: []string{upstreamName, text},
2349 }
2350 uc.produce(upstreamName, echoMsg, dc)
2351
2352 uc.updateChannelAutoDetach(upstreamName)
2353 }
2354 case "TAGMSG":
2355 var targetsStr string
2356 if err := parseMessageParams(msg, &targetsStr); err != nil {
2357 return err
2358 }
2359 tags := copyClientTags(msg.Tags)
2360
2361 for _, name := range strings.Split(targetsStr, ",") {
2362 if dc.network == nil && casemapASCII(name) == dc.nickCM {
2363 dc.SendMessage(&irc.Message{
2364 Tags: msg.Tags.Copy(),
2365 Prefix: dc.prefix(),
2366 Command: "TAGMSG",
2367 Params: []string{name},
2368 })
2369 continue
2370 }
2371
2372 if casemapASCII(name) == serviceNickCM {
2373 continue
2374 }
2375
2376 uc, upstreamName, err := dc.unmarshalEntity(name)
2377 if err != nil {
2378 return err
2379 }
2380 if _, ok := uc.caps["message-tags"]; !ok {
2381 continue
2382 }
2383
2384 uc.SendMessageLabeled(dc.id, &irc.Message{
2385 Tags: tags,
2386 Command: "TAGMSG",
2387 Params: []string{upstreamName},
2388 })
2389
2390 uc.updateChannelAutoDetach(upstreamName)
2391 }
2392 case "INVITE":
2393 var user, channel string
2394 if err := parseMessageParams(msg, &user, &channel); err != nil {
2395 return err
2396 }
2397
2398 ucChannel, upstreamChannel, err := dc.unmarshalEntity(channel)
2399 if err != nil {
2400 return err
2401 }
2402
2403 ucUser, upstreamUser, err := dc.unmarshalEntity(user)
2404 if err != nil {
2405 return err
2406 }
2407
2408 if ucChannel != ucUser {
2409 return ircError{&irc.Message{
2410 Command: irc.ERR_USERNOTINCHANNEL,
2411 Params: []string{dc.nick, user, channel, "They are on another network"},
2412 }}
2413 }
2414 uc := ucChannel
2415
2416 uc.SendMessageLabeled(dc.id, &irc.Message{
2417 Command: "INVITE",
2418 Params: []string{upstreamUser, upstreamChannel},
2419 })
2420 case "AUTHENTICATE":
2421 // Post-connection-registration AUTHENTICATE is unsupported in
2422 // multi-upstream mode, or if the upstream doesn't support SASL
2423 uc := dc.upstream()
2424 if uc == nil || !uc.caps["sasl"] {
2425 return ircError{&irc.Message{
2426 Command: irc.ERR_SASLFAIL,
2427 Params: []string{dc.nick, "Upstream network authentication not supported"},
2428 }}
2429 }
2430
2431 credentials, err := dc.handleAuthenticateCommand(msg)
2432 if err != nil {
2433 return err
2434 }
2435
2436 if credentials != nil {
2437 if uc.saslClient != nil {
2438 dc.endSASL(&irc.Message{
2439 Prefix: dc.srv.prefix(),
2440 Command: irc.ERR_SASLFAIL,
2441 Params: []string{dc.nick, "Another authentication attempt is already in progress"},
2442 })
2443 return nil
2444 }
2445
2446 uc.logger.Printf("starting post-registration SASL PLAIN authentication with username %q", credentials.plainUsername)
2447 uc.saslClient = sasl.NewPlainClient("", credentials.plainUsername, credentials.plainPassword)
2448 uc.enqueueCommand(dc, &irc.Message{
2449 Command: "AUTHENTICATE",
2450 Params: []string{"PLAIN"},
2451 })
2452 }
2453 case "REGISTER", "VERIFY":
2454 // Check number of params here, since we'll use that to save the
2455 // credentials on command success
2456 if (msg.Command == "REGISTER" && len(msg.Params) < 3) || (msg.Command == "VERIFY" && len(msg.Params) < 2) {
2457 return newNeedMoreParamsError(msg.Command)
2458 }
2459
2460 uc := dc.upstream()
2461 if uc == nil || !uc.caps["draft/account-registration"] {
2462 return ircError{&irc.Message{
2463 Command: "FAIL",
2464 Params: []string{msg.Command, "TEMPORARILY_UNAVAILABLE", "*", "Upstream network account registration not supported"},
2465 }}
2466 }
2467
2468 uc.logger.Printf("starting %v with account name %v", msg.Command, msg.Params[0])
2469 uc.enqueueCommand(dc, msg)
2470 case "MONITOR":
2471 // MONITOR is unsupported in multi-upstream mode
2472 uc := dc.upstream()
2473 if uc == nil {
2474 return newUnknownCommandError(msg.Command)
2475 }
2476
2477 var subcommand string
2478 if err := parseMessageParams(msg, &subcommand); err != nil {
2479 return err
2480 }
2481
2482 switch strings.ToUpper(subcommand) {
2483 case "+", "-":
2484 var targets string
2485 if err := parseMessageParams(msg, nil, &targets); err != nil {
2486 return err
2487 }
2488 for _, target := range strings.Split(targets, ",") {
2489 if subcommand == "+" {
2490 // Hard limit, just to avoid having downstreams fill our map
2491 if len(dc.monitored.innerMap) >= 1000 {
2492 dc.SendMessage(&irc.Message{
2493 Prefix: dc.srv.prefix(),
2494 Command: irc.ERR_MONLISTFULL,
2495 Params: []string{dc.nick, "1000", target, "Bouncer monitor list is full"},
2496 })
2497 continue
2498 }
2499
2500 dc.monitored.SetValue(target, nil)
2501
2502 if uc.monitored.Has(target) {
2503 cmd := irc.RPL_MONOFFLINE
2504 if online := uc.monitored.Value(target); online {
2505 cmd = irc.RPL_MONONLINE
2506 }
2507
2508 dc.SendMessage(&irc.Message{
2509 Prefix: dc.srv.prefix(),
2510 Command: cmd,
2511 Params: []string{dc.nick, target},
2512 })
2513 }
2514 } else {
2515 dc.monitored.Delete(target)
2516 }
2517 }
2518 uc.updateMonitor()
2519 case "C": // clear
2520 dc.monitored = newCasemapMap(0)
2521 uc.updateMonitor()
2522 case "L": // list
2523 // TODO: be less lazy and pack the list
2524 for _, entry := range dc.monitored.innerMap {
2525 dc.SendMessage(&irc.Message{
2526 Prefix: dc.srv.prefix(),
2527 Command: irc.RPL_MONLIST,
2528 Params: []string{dc.nick, entry.originalKey},
2529 })
2530 }
2531 dc.SendMessage(&irc.Message{
2532 Prefix: dc.srv.prefix(),
2533 Command: irc.RPL_ENDOFMONLIST,
2534 Params: []string{dc.nick, "End of MONITOR list"},
2535 })
2536 case "S": // status
2537 // TODO: be less lazy and pack the lists
2538 for _, entry := range dc.monitored.innerMap {
2539 target := entry.originalKey
2540
2541 cmd := irc.RPL_MONOFFLINE
2542 if online := uc.monitored.Value(target); online {
2543 cmd = irc.RPL_MONONLINE
2544 }
2545
2546 dc.SendMessage(&irc.Message{
2547 Prefix: dc.srv.prefix(),
2548 Command: cmd,
2549 Params: []string{dc.nick, target},
2550 })
2551 }
2552 }
2553 case "CHATHISTORY":
2554 var subcommand string
2555 if err := parseMessageParams(msg, &subcommand); err != nil {
2556 return err
2557 }
2558 var target, limitStr string
2559 var boundsStr [2]string
2560 switch subcommand {
2561 case "AFTER", "BEFORE", "LATEST":
2562 if err := parseMessageParams(msg, nil, &target, &boundsStr[0], &limitStr); err != nil {
2563 return err
2564 }
2565 case "BETWEEN":
2566 if err := parseMessageParams(msg, nil, &target, &boundsStr[0], &boundsStr[1], &limitStr); err != nil {
2567 return err
2568 }
2569 case "TARGETS":
2570 if dc.network == nil {
2571 // Either an unbound bouncer network, in which case we should return no targets,
2572 // or a multi-upstream downstream, but we don't support CHATHISTORY TARGETS for those yet.
2573 dc.SendBatch("draft/chathistory-targets", nil, nil, func(batchRef irc.TagValue) {})
2574 return nil
2575 }
2576 if err := parseMessageParams(msg, nil, &boundsStr[0], &boundsStr[1], &limitStr); err != nil {
2577 return err
2578 }
2579 default:
2580 // TODO: support AROUND
2581 return ircError{&irc.Message{
2582 Command: "FAIL",
2583 Params: []string{"CHATHISTORY", "INVALID_PARAMS", subcommand, "Unknown command"},
2584 }}
2585 }
2586
2587 // We don't save history for our service
2588 if casemapASCII(target) == serviceNickCM {
2589 dc.SendBatch("chathistory", []string{target}, nil, func(batchRef irc.TagValue) {})
2590 return nil
2591 }
2592
2593 store, ok := dc.user.msgStore.(chatHistoryMessageStore)
2594 if !ok {
2595 return ircError{&irc.Message{
2596 Command: irc.ERR_UNKNOWNCOMMAND,
2597 Params: []string{dc.nick, "CHATHISTORY", "Unknown command"},
2598 }}
2599 }
2600
2601 network, entity, err := dc.unmarshalEntityNetwork(target)
2602 if err != nil {
2603 return err
2604 }
2605 entity = network.casemap(entity)
2606
2607 // TODO: support msgid criteria
2608 var bounds [2]time.Time
2609 bounds[0] = parseChatHistoryBound(boundsStr[0])
2610 if subcommand == "LATEST" && boundsStr[0] == "*" {
2611 bounds[0] = time.Now()
2612 } else if bounds[0].IsZero() {
2613 return ircError{&irc.Message{
2614 Command: "FAIL",
2615 Params: []string{"CHATHISTORY", "INVALID_PARAMS", subcommand, boundsStr[0], "Invalid first bound"},
2616 }}
2617 }
2618
2619 if boundsStr[1] != "" {
2620 bounds[1] = parseChatHistoryBound(boundsStr[1])
2621 if bounds[1].IsZero() {
2622 return ircError{&irc.Message{
2623 Command: "FAIL",
2624 Params: []string{"CHATHISTORY", "INVALID_PARAMS", subcommand, boundsStr[1], "Invalid second bound"},
2625 }}
2626 }
2627 }
2628
2629 limit, err := strconv.Atoi(limitStr)
2630 if err != nil || limit < 0 || limit > chatHistoryLimit {
2631 return ircError{&irc.Message{
2632 Command: "FAIL",
2633 Params: []string{"CHATHISTORY", "INVALID_PARAMS", subcommand, limitStr, "Invalid limit"},
2634 }}
2635 }
2636
2637 eventPlayback := dc.caps["draft/event-playback"]
2638
2639 var history []*irc.Message
2640 switch subcommand {
2641 case "BEFORE", "LATEST":
2642 history, err = store.LoadBeforeTime(ctx, &network.Network, entity, bounds[0], time.Time{}, limit, eventPlayback)
2643 case "AFTER":
2644 history, err = store.LoadAfterTime(ctx, &network.Network, entity, bounds[0], time.Now(), limit, eventPlayback)
2645 case "BETWEEN":
2646 if bounds[0].Before(bounds[1]) {
2647 history, err = store.LoadAfterTime(ctx, &network.Network, entity, bounds[0], bounds[1], limit, eventPlayback)
2648 } else {
2649 history, err = store.LoadBeforeTime(ctx, &network.Network, entity, bounds[0], bounds[1], limit, eventPlayback)
2650 }
2651 case "TARGETS":
2652 // TODO: support TARGETS in multi-upstream mode
2653 targets, err := store.ListTargets(ctx, &network.Network, bounds[0], bounds[1], limit, eventPlayback)
2654 if err != nil {
2655 dc.logger.Printf("failed fetching targets for chathistory: %v", err)
2656 return ircError{&irc.Message{
2657 Command: "FAIL",
2658 Params: []string{"CHATHISTORY", "MESSAGE_ERROR", subcommand, "Failed to retrieve targets"},
2659 }}
2660 }
2661
2662 dc.SendBatch("draft/chathistory-targets", nil, nil, func(batchRef irc.TagValue) {
2663 for _, target := range targets {
2664 if ch := network.channels.Value(target.Name); ch != nil && ch.Detached {
2665 continue
2666 }
2667
2668 dc.SendMessage(&irc.Message{
2669 Tags: irc.Tags{"batch": batchRef},
2670 Prefix: dc.srv.prefix(),
2671 Command: "CHATHISTORY",
2672 Params: []string{"TARGETS", target.Name, target.LatestMessage.UTC().Format(serverTimeLayout)},
2673 })
2674 }
2675 })
2676
2677 return nil
2678 }
2679 if err != nil {
2680 dc.logger.Printf("failed fetching %q messages for chathistory: %v", target, err)
2681 return newChatHistoryError(subcommand, target)
2682 }
2683
2684 dc.SendBatch("chathistory", []string{target}, nil, func(batchRef irc.TagValue) {
2685 for _, msg := range history {
2686 msg.Tags["batch"] = batchRef
2687 dc.SendMessage(dc.marshalMessage(msg, network))
2688 }
2689 })
2690 case "BOUNCER":
2691 var subcommand string
2692 if err := parseMessageParams(msg, &subcommand); err != nil {
2693 return err
2694 }
2695
2696 switch strings.ToUpper(subcommand) {
2697 case "BIND":
2698 return ircError{&irc.Message{
2699 Command: "FAIL",
2700 Params: []string{"BOUNCER", "REGISTRATION_IS_COMPLETED", "BIND", "Cannot bind to a network after registration"},
2701 }}
2702 case "LISTNETWORKS":
2703 dc.SendBatch("soju.im/bouncer-networks", nil, nil, func(batchRef irc.TagValue) {
2704 dc.user.forEachNetwork(func(network *network) {
2705 idStr := fmt.Sprintf("%v", network.ID)
2706 attrs := getNetworkAttrs(network)
2707 dc.SendMessage(&irc.Message{
2708 Tags: irc.Tags{"batch": batchRef},
2709 Prefix: dc.srv.prefix(),
2710 Command: "BOUNCER",
2711 Params: []string{"NETWORK", idStr, attrs.String()},
2712 })
2713 })
2714 })
2715 case "ADDNETWORK":
2716 var attrsStr string
2717 if err := parseMessageParams(msg, nil, &attrsStr); err != nil {
2718 return err
2719 }
2720 attrs := irc.ParseTags(attrsStr)
2721
2722 record := &Network{Nick: dc.nick, Enabled: true}
2723 if err := updateNetworkAttrs(record, attrs, subcommand); err != nil {
2724 return err
2725 }
2726
2727 if record.Nick == dc.user.Username {
2728 record.Nick = ""
2729 }
2730 if record.Realname == dc.user.Realname {
2731 record.Realname = ""
2732 }
2733
2734 network, err := dc.user.createNetwork(ctx, record)
2735 if err != nil {
2736 return ircError{&irc.Message{
2737 Command: "FAIL",
2738 Params: []string{"BOUNCER", "UNKNOWN_ERROR", subcommand, fmt.Sprintf("Failed to create network: %v", err)},
2739 }}
2740 }
2741
2742 dc.SendMessage(&irc.Message{
2743 Prefix: dc.srv.prefix(),
2744 Command: "BOUNCER",
2745 Params: []string{"ADDNETWORK", fmt.Sprintf("%v", network.ID)},
2746 })
2747 case "CHANGENETWORK":
2748 var idStr, attrsStr string
2749 if err := parseMessageParams(msg, nil, &idStr, &attrsStr); err != nil {
2750 return err
2751 }
2752 id, err := parseBouncerNetID(subcommand, idStr)
2753 if err != nil {
2754 return err
2755 }
2756 attrs := irc.ParseTags(attrsStr)
2757
2758 net := dc.user.getNetworkByID(id)
2759 if net == nil {
2760 return ircError{&irc.Message{
2761 Command: "FAIL",
2762 Params: []string{"BOUNCER", "INVALID_NETID", subcommand, idStr, "Invalid network ID"},
2763 }}
2764 }
2765
2766 record := net.Network // copy network record because we'll mutate it
2767 if err := updateNetworkAttrs(&record, attrs, subcommand); err != nil {
2768 return err
2769 }
2770
2771 if record.Nick == dc.user.Username {
2772 record.Nick = ""
2773 }
2774 if record.Realname == dc.user.Realname {
2775 record.Realname = ""
2776 }
2777
2778 _, err = dc.user.updateNetwork(ctx, &record)
2779 if err != nil {
2780 return ircError{&irc.Message{
2781 Command: "FAIL",
2782 Params: []string{"BOUNCER", "UNKNOWN_ERROR", subcommand, fmt.Sprintf("Failed to update network: %v", err)},
2783 }}
2784 }
2785
2786 dc.SendMessage(&irc.Message{
2787 Prefix: dc.srv.prefix(),
2788 Command: "BOUNCER",
2789 Params: []string{"CHANGENETWORK", idStr},
2790 })
2791 case "DELNETWORK":
2792 var idStr string
2793 if err := parseMessageParams(msg, nil, &idStr); err != nil {
2794 return err
2795 }
2796 id, err := parseBouncerNetID(subcommand, idStr)
2797 if err != nil {
2798 return err
2799 }
2800
2801 net := dc.user.getNetworkByID(id)
2802 if net == nil {
2803 return ircError{&irc.Message{
2804 Command: "FAIL",
2805 Params: []string{"BOUNCER", "INVALID_NETID", subcommand, idStr, "Invalid network ID"},
2806 }}
2807 }
2808
2809 if err := dc.user.deleteNetwork(ctx, net.ID); err != nil {
2810 return err
2811 }
2812
2813 dc.SendMessage(&irc.Message{
2814 Prefix: dc.srv.prefix(),
2815 Command: "BOUNCER",
2816 Params: []string{"DELNETWORK", idStr},
2817 })
2818 default:
2819 return ircError{&irc.Message{
2820 Command: "FAIL",
2821 Params: []string{"BOUNCER", "UNKNOWN_COMMAND", subcommand, "Unknown subcommand"},
2822 }}
2823 }
2824 default:
2825 dc.logger.Printf("unhandled message: %v", msg)
2826
2827 // Only forward unknown commands in single-upstream mode
2828 uc := dc.upstream()
2829 if uc == nil {
2830 return newUnknownCommandError(msg.Command)
2831 }
2832
2833 uc.SendMessageLabeled(dc.id, msg)
2834 }
2835 return nil
2836}
2837
2838func (dc *downstreamConn) handleNickServPRIVMSG(ctx context.Context, uc *upstreamConn, text string) {
2839 username, password, ok := parseNickServCredentials(text, uc.nick)
2840 if ok {
2841 uc.network.autoSaveSASLPlain(ctx, username, password)
2842 }
2843}
2844
2845func parseNickServCredentials(text, nick string) (username, password string, ok bool) {
2846 fields := strings.Fields(text)
2847 if len(fields) < 2 {
2848 return "", "", false
2849 }
2850 cmd := strings.ToUpper(fields[0])
2851 params := fields[1:]
2852 switch cmd {
2853 case "REGISTER":
2854 username = nick
2855 password = params[0]
2856 case "IDENTIFY":
2857 if len(params) == 1 {
2858 username = nick
2859 password = params[0]
2860 } else {
2861 username = params[0]
2862 password = params[1]
2863 }
2864 case "SET":
2865 if len(params) == 2 && strings.EqualFold(params[0], "PASSWORD") {
2866 username = nick
2867 password = params[1]
2868 }
2869 default:
2870 return "", "", false
2871 }
2872 return username, password, true
2873}
Note: See TracBrowser for help on using the repository browser.