source: code/trunk/service.go@ 795

Last change on this file since 795 was 772, checked in by contact, 3 years ago

service: make name arg optional for network commands

Makes commands less verbose.

File size: 27.8 KB
RevLine 
[117]1package soju
2
3import (
[652]4 "context"
[307]5 "crypto/sha1"
6 "crypto/sha256"
[575]7 "crypto/sha512"
[307]8 "encoding/hex"
[120]9 "flag"
[117]10 "fmt"
[120]11 "io/ioutil"
[339]12 "sort"
[542]13 "strconv"
[117]14 "strings"
[307]15 "time"
[566]16 "unicode"
[117]17
[252]18 "golang.org/x/crypto/bcrypt"
[117]19 "gopkg.in/irc.v3"
20)
21
22const serviceNick = "BouncerServ"
[478]23const serviceNickCM = "bouncerserv"
[343]24const serviceRealname = "soju bouncer service"
[117]25
[606]26// maxRSABits is the maximum number of RSA key bits used when generating a new
27// private key.
28const maxRSABits = 8192
29
[220]30var servicePrefix = &irc.Prefix{
31 Name: serviceNick,
32 User: serviceNick,
33 Host: serviceNick,
34}
35
[150]36type serviceCommandSet map[string]*serviceCommand
37
[117]38type serviceCommand struct {
[150]39 usage string
40 desc string
[677]41 handle func(ctx context.Context, dc *downstreamConn, params []string) error
[150]42 children serviceCommandSet
[328]43 admin bool
[117]44}
45
[218]46func sendServiceNOTICE(dc *downstreamConn, text string) {
47 dc.SendMessage(&irc.Message{
[220]48 Prefix: servicePrefix,
[218]49 Command: "NOTICE",
50 Params: []string{dc.nick, text},
51 })
52}
53
[117]54func sendServicePRIVMSG(dc *downstreamConn, text string) {
55 dc.SendMessage(&irc.Message{
[220]56 Prefix: servicePrefix,
[117]57 Command: "PRIVMSG",
58 Params: []string{dc.nick, text},
59 })
60}
61
[566]62func splitWords(s string) ([]string, error) {
63 var words []string
64 var lastWord strings.Builder
65 escape := false
66 prev := ' '
67 wordDelim := ' '
68
69 for _, r := range s {
70 if escape {
71 // last char was a backslash, write the byte as-is.
72 lastWord.WriteRune(r)
73 escape = false
74 } else if r == '\\' {
75 escape = true
76 } else if wordDelim == ' ' && unicode.IsSpace(r) {
77 // end of last word
78 if !unicode.IsSpace(prev) {
79 words = append(words, lastWord.String())
80 lastWord.Reset()
81 }
82 } else if r == wordDelim {
83 // wordDelim is either " or ', switch back to
84 // space-delimited words.
85 wordDelim = ' '
86 } else if r == '"' || r == '\'' {
87 if wordDelim == ' ' {
88 // start of (double-)quoted word
89 wordDelim = r
90 } else {
91 // either wordDelim is " and r is ' or vice-versa
92 lastWord.WriteRune(r)
93 }
94 } else {
95 lastWord.WriteRune(r)
96 }
97
98 prev = r
99 }
100
101 if !unicode.IsSpace(prev) {
102 words = append(words, lastWord.String())
103 }
104
105 if wordDelim != ' ' {
106 return nil, fmt.Errorf("unterminated quoted string")
107 }
108 if escape {
109 return nil, fmt.Errorf("unterminated backslash sequence")
110 }
111
112 return words, nil
113}
114
[677]115func handleServicePRIVMSG(ctx context.Context, dc *downstreamConn, text string) {
[566]116 words, err := splitWords(text)
[117]117 if err != nil {
[566]118 sendServicePRIVMSG(dc, fmt.Sprintf(`error: failed to parse command: %v`, err))
[117]119 return
120 }
121
[150]122 cmd, params, err := serviceCommands.Get(words)
123 if err != nil {
124 sendServicePRIVMSG(dc, fmt.Sprintf(`error: %v (type "help" for a list of commands)`, err))
[117]125 return
126 }
[328]127 if cmd.admin && !dc.user.Admin {
[625]128 sendServicePRIVMSG(dc, "error: you must be an admin to use this command")
[328]129 return
130 }
[117]131
[334]132 if cmd.handle == nil {
133 if len(cmd.children) > 0 {
134 var l []string
[335]135 appendServiceCommandSetHelp(cmd.children, words, dc.user.Admin, &l)
[334]136 sendServicePRIVMSG(dc, "available commands: "+strings.Join(l, ", "))
137 } else {
138 // Pretend the command does not exist if it has neither children nor handler.
139 // This is obviously a bug but it is better to not die anyway.
140 dc.logger.Printf("command without handler and subcommands invoked:", words[0])
141 sendServicePRIVMSG(dc, fmt.Sprintf("command %q not found", words[0]))
142 }
143 return
144 }
145
[677]146 if err := cmd.handle(ctx, dc, params); err != nil {
[117]147 sendServicePRIVMSG(dc, fmt.Sprintf("error: %v", err))
148 }
149}
150
[150]151func (cmds serviceCommandSet) Get(params []string) (*serviceCommand, []string, error) {
152 if len(params) == 0 {
153 return nil, nil, fmt.Errorf("no command specified")
154 }
[117]155
[150]156 name := params[0]
157 params = params[1:]
158
159 cmd, ok := cmds[name]
160 if !ok {
161 for k := range cmds {
162 if !strings.HasPrefix(k, name) {
163 continue
164 }
165 if cmd != nil {
166 return nil, params, fmt.Errorf("command %q is ambiguous", name)
167 }
168 cmd = cmds[k]
169 }
170 }
171 if cmd == nil {
172 return nil, params, fmt.Errorf("command %q not found", name)
173 }
174
175 if len(params) == 0 || len(cmd.children) == 0 {
176 return cmd, params, nil
177 }
178 return cmd.children.Get(params)
179}
180
[339]181func (cmds serviceCommandSet) Names() []string {
182 l := make([]string, 0, len(cmds))
183 for name := range cmds {
184 l = append(l, name)
185 }
186 sort.Strings(l)
187 return l
188}
189
[150]190var serviceCommands serviceCommandSet
191
[117]192func init() {
[150]193 serviceCommands = serviceCommandSet{
[117]194 "help": {
195 usage: "[command]",
196 desc: "print help message",
197 handle: handleServiceHelp,
198 },
[150]199 "network": {
200 children: serviceCommandSet{
201 "create": {
[542]202 usage: "-addr <addr> [-name name] [-username username] [-pass pass] [-realname realname] [-nick nick] [-enabled enabled] [-connect-command command]...",
[150]203 desc: "add a new network",
[325]204 handle: handleServiceNetworkCreate,
[150]205 },
[151]206 "status": {
207 desc: "show a list of saved networks and their current status",
208 handle: handleServiceNetworkStatus,
209 },
[313]210 "update": {
[772]211 usage: "[name] [-addr addr] [-name name] [-username username] [-pass pass] [-realname realname] [-nick nick] [-enabled enabled] [-connect-command command]...",
[315]212 desc: "update a network",
[313]213 handle: handleServiceNetworkUpdate,
214 },
[202]215 "delete": {
[772]216 usage: "[name]",
[202]217 desc: "delete a network",
218 handle: handleServiceNetworkDelete,
219 },
[577]220 "quote": {
[772]221 usage: "[name] <command>",
[577]222 desc: "send a raw line to a network",
223 handle: handleServiceNetworkQuote,
224 },
[150]225 },
[120]226 },
[307]227 "certfp": {
228 children: serviceCommandSet{
229 "generate": {
[771]230 usage: "[-key-type rsa|ecdsa|ed25519] [-bits N] [-network name]",
[307]231 desc: "generate a new self-signed certificate, defaults to using RSA-3072 key",
[614]232 handle: handleServiceCertFPGenerate,
[307]233 },
234 "fingerprint": {
[771]235 usage: "[-network name]",
236 desc: "show fingerprints of certificate",
[614]237 handle: handleServiceCertFPFingerprints,
[307]238 },
239 },
240 },
[363]241 "sasl": {
242 children: serviceCommandSet{
[730]243 "status": {
[771]244 usage: "[-network name]",
[730]245 desc: "show SASL status",
[770]246 handle: handleServiceSASLStatus,
[730]247 },
[363]248 "set-plain": {
[771]249 usage: "[-network name] <username> <password>",
[363]250 desc: "set SASL PLAIN credentials",
251 handle: handleServiceSASLSetPlain,
252 },
[364]253 "reset": {
[771]254 usage: "[-network name]",
[364]255 desc: "disable SASL authentication and remove stored credentials",
256 handle: handleServiceSASLReset,
257 },
[363]258 },
259 },
[329]260 "user": {
261 children: serviceCommandSet{
262 "create": {
[568]263 usage: "-username <username> -password <password> [-realname <realname>] [-admin]",
[329]264 desc: "create a new soju user",
265 handle: handleUserCreate,
266 admin: true,
267 },
[568]268 "update": {
[570]269 usage: "[-password <password>] [-realname <realname>]",
[568]270 desc: "update the current user",
271 handle: handleUserUpdate,
272 },
[379]273 "delete": {
274 usage: "<username>",
275 desc: "delete a user",
276 handle: handleUserDelete,
277 admin: true,
278 },
[329]279 },
280 },
[436]281 "channel": {
282 children: serviceCommandSet{
[539]283 "status": {
284 usage: "[-network name]",
285 desc: "show a list of saved channels and their current status",
286 handle: handleServiceChannelStatus,
287 },
[436]288 "update": {
289 usage: "<name> [-relay-detached <default|none|highlight|message>] [-reattach-on <default|none|highlight|message>] [-detach-after <duration>] [-detach-on <default|none|highlight|message>]",
290 desc: "update a channel",
291 handle: handleServiceChannelUpdate,
292 },
293 },
294 },
[605]295 "server": {
296 children: serviceCommandSet{
297 "status": {
298 desc: "show server statistics",
299 handle: handleServiceServerStatus,
300 admin: true,
301 },
[615]302 "notice": {
303 desc: "broadcast a notice to all connected bouncer users",
304 handle: handleServiceServerNotice,
305 admin: true,
306 },
[605]307 },
308 admin: true,
309 },
[117]310 }
311}
312
[328]313func appendServiceCommandSetHelp(cmds serviceCommandSet, prefix []string, admin bool, l *[]string) {
[339]314 for _, name := range cmds.Names() {
315 cmd := cmds[name]
[328]316 if cmd.admin && !admin {
317 continue
318 }
[150]319 words := append(prefix, name)
320 if len(cmd.children) == 0 {
321 s := strings.Join(words, " ")
322 *l = append(*l, s)
323 } else {
[328]324 appendServiceCommandSetHelp(cmd.children, words, admin, l)
[150]325 }
326 }
327}
328
[677]329func handleServiceHelp(ctx context.Context, dc *downstreamConn, params []string) error {
[117]330 if len(params) > 0 {
[150]331 cmd, rest, err := serviceCommands.Get(params)
332 if err != nil {
333 return err
[117]334 }
[150]335 words := params[:len(params)-len(rest)]
[117]336
[150]337 if len(cmd.children) > 0 {
338 var l []string
[328]339 appendServiceCommandSetHelp(cmd.children, words, dc.user.Admin, &l)
[150]340 sendServicePRIVMSG(dc, "available commands: "+strings.Join(l, ", "))
341 } else {
342 text := strings.Join(words, " ")
343 if cmd.usage != "" {
344 text += " " + cmd.usage
345 }
346 text += ": " + cmd.desc
347
348 sendServicePRIVMSG(dc, text)
[117]349 }
350 } else {
351 var l []string
[328]352 appendServiceCommandSetHelp(serviceCommands, nil, dc.user.Admin, &l)
[117]353 sendServicePRIVMSG(dc, "available commands: "+strings.Join(l, ", "))
354 }
355 return nil
356}
[120]357
[202]358func newFlagSet() *flag.FlagSet {
[120]359 fs := flag.NewFlagSet("", flag.ContinueOnError)
360 fs.SetOutput(ioutil.Discard)
[202]361 return fs
362}
363
[313]364type stringSliceFlag []string
[263]365
[313]366func (v *stringSliceFlag) String() string {
[263]367 return fmt.Sprint([]string(*v))
368}
369
[313]370func (v *stringSliceFlag) Set(s string) error {
[263]371 *v = append(*v, s)
372 return nil
373}
374
[313]375// stringPtrFlag is a flag value populating a string pointer. This allows to
376// disambiguate between a flag that hasn't been set and a flag that has been
377// set to an empty string.
378type stringPtrFlag struct {
379 ptr **string
380}
381
382func (f stringPtrFlag) String() string {
[333]383 if f.ptr == nil || *f.ptr == nil {
[313]384 return ""
385 }
386 return **f.ptr
387}
388
389func (f stringPtrFlag) Set(s string) error {
390 *f.ptr = &s
391 return nil
392}
393
[542]394type boolPtrFlag struct {
395 ptr **bool
396}
397
398func (f boolPtrFlag) String() string {
399 if f.ptr == nil || *f.ptr == nil {
400 return "<nil>"
401 }
402 return strconv.FormatBool(**f.ptr)
403}
404
405func (f boolPtrFlag) Set(s string) error {
406 v, err := strconv.ParseBool(s)
407 if err != nil {
408 return err
409 }
410 *f.ptr = &v
411 return nil
412}
413
[772]414func getNetworkFromArg(dc *downstreamConn, params []string) (*network, []string, error) {
415 name, params := popArg(params)
416 if name == "" {
417 if dc.network == nil {
418 return nil, params, fmt.Errorf("no network selected, a name argument is required")
419 }
420 return dc.network, params, nil
421 } else {
422 net := dc.user.getNetwork(name)
423 if net == nil {
424 return nil, params, fmt.Errorf("unknown network %q", name)
425 }
426 return net, params, nil
427 }
428}
429
[313]430type networkFlagSet struct {
431 *flag.FlagSet
432 Addr, Name, Nick, Username, Pass, Realname *string
[542]433 Enabled *bool
[315]434 ConnectCommands []string
[313]435}
436
437func newNetworkFlagSet() *networkFlagSet {
438 fs := &networkFlagSet{FlagSet: newFlagSet()}
439 fs.Var(stringPtrFlag{&fs.Addr}, "addr", "")
440 fs.Var(stringPtrFlag{&fs.Name}, "name", "")
441 fs.Var(stringPtrFlag{&fs.Nick}, "nick", "")
442 fs.Var(stringPtrFlag{&fs.Username}, "username", "")
443 fs.Var(stringPtrFlag{&fs.Pass}, "pass", "")
444 fs.Var(stringPtrFlag{&fs.Realname}, "realname", "")
[542]445 fs.Var(boolPtrFlag{&fs.Enabled}, "enabled", "")
[313]446 fs.Var((*stringSliceFlag)(&fs.ConnectCommands), "connect-command", "")
447 return fs
448}
449
450func (fs *networkFlagSet) update(network *Network) error {
451 if fs.Addr != nil {
452 if addrParts := strings.SplitN(*fs.Addr, "://", 2); len(addrParts) == 2 {
453 scheme := addrParts[0]
454 switch scheme {
[358]455 case "ircs", "irc+insecure", "unix":
[313]456 default:
[358]457 return fmt.Errorf("unknown scheme %q (supported schemes: ircs, irc+insecure, unix)", scheme)
[313]458 }
459 }
460 network.Addr = *fs.Addr
461 }
462 if fs.Name != nil {
463 network.Name = *fs.Name
464 }
465 if fs.Nick != nil {
466 network.Nick = *fs.Nick
467 }
468 if fs.Username != nil {
469 network.Username = *fs.Username
470 }
471 if fs.Pass != nil {
472 network.Pass = *fs.Pass
473 }
474 if fs.Realname != nil {
475 network.Realname = *fs.Realname
476 }
[542]477 if fs.Enabled != nil {
478 network.Enabled = *fs.Enabled
479 }
[313]480 if fs.ConnectCommands != nil {
481 if len(fs.ConnectCommands) == 1 && fs.ConnectCommands[0] == "" {
482 network.ConnectCommands = nil
483 } else {
484 for _, command := range fs.ConnectCommands {
485 _, err := irc.ParseMessage(command)
486 if err != nil {
487 return fmt.Errorf("flag -connect-command must be a valid raw irc command string: %q: %v", command, err)
488 }
489 }
490 network.ConnectCommands = fs.ConnectCommands
491 }
492 }
493 return nil
494}
495
[677]496func handleServiceNetworkCreate(ctx context.Context, dc *downstreamConn, params []string) error {
[313]497 fs := newNetworkFlagSet()
[120]498 if err := fs.Parse(params); err != nil {
499 return err
500 }
[313]501 if fs.Addr == nil {
[150]502 return fmt.Errorf("flag -addr is required")
[120]503 }
504
[313]505 record := &Network{
[542]506 Addr: *fs.Addr,
507 Enabled: true,
[269]508 }
[313]509 if err := fs.update(record); err != nil {
510 return err
[263]511 }
512
[677]513 network, err := dc.user.createNetwork(ctx, record)
[120]514 if err != nil {
515 return fmt.Errorf("could not create network: %v", err)
516 }
517
[202]518 sendServicePRIVMSG(dc, fmt.Sprintf("created network %q", network.GetName()))
[120]519 return nil
520}
[151]521
[677]522func handleServiceNetworkStatus(ctx context.Context, dc *downstreamConn, params []string) error {
[546]523 n := 0
[768]524 for _, net := range dc.user.networks {
[151]525 var statuses []string
526 var details string
[279]527 if uc := net.conn; uc != nil {
[271]528 if dc.nick != uc.nick {
529 statuses = append(statuses, "connected as "+uc.nick)
530 } else {
531 statuses = append(statuses, "connected")
532 }
[478]533 details = fmt.Sprintf("%v channels", uc.channels.Len())
[542]534 } else if !net.Enabled {
535 statuses = append(statuses, "disabled")
[151]536 } else {
537 statuses = append(statuses, "disconnected")
[219]538 if net.lastError != nil {
539 details = net.lastError.Error()
540 }
[151]541 }
542
543 if net == dc.network {
544 statuses = append(statuses, "current")
545 }
546
[224]547 name := net.GetName()
548 if name != net.Addr {
549 name = fmt.Sprintf("%v (%v)", name, net.Addr)
550 }
551
552 s := fmt.Sprintf("%v [%v]", name, strings.Join(statuses, ", "))
[151]553 if details != "" {
554 s += ": " + details
555 }
556 sendServicePRIVMSG(dc, s)
[546]557
558 n++
[768]559 }
[546]560
561 if n == 0 {
562 sendServicePRIVMSG(dc, `No network configured, add one with "network create".`)
563 }
564
[151]565 return nil
566}
[202]567
[677]568func handleServiceNetworkUpdate(ctx context.Context, dc *downstreamConn, params []string) error {
[772]569 net, params, err := getNetworkFromArg(dc, params)
570 if err != nil {
571 return err
[313]572 }
573
574 fs := newNetworkFlagSet()
[772]575 if err := fs.Parse(params); err != nil {
[313]576 return err
577 }
578
579 record := net.Network // copy network record because we'll mutate it
580 if err := fs.update(&record); err != nil {
581 return err
582 }
583
[677]584 network, err := dc.user.updateNetwork(ctx, &record)
[313]585 if err != nil {
586 return fmt.Errorf("could not update network: %v", err)
587 }
588
589 sendServicePRIVMSG(dc, fmt.Sprintf("updated network %q", network.GetName()))
590 return nil
591}
592
[677]593func handleServiceNetworkDelete(ctx context.Context, dc *downstreamConn, params []string) error {
[772]594 net, params, err := getNetworkFromArg(dc, params)
595 if err != nil {
596 return err
[202]597 }
598
[677]599 if err := dc.user.deleteNetwork(ctx, net.ID); err != nil {
[202]600 return err
601 }
602
603 sendServicePRIVMSG(dc, fmt.Sprintf("deleted network %q", net.GetName()))
604 return nil
605}
[252]606
[677]607func handleServiceNetworkQuote(ctx context.Context, dc *downstreamConn, params []string) error {
[772]608 if len(params) != 1 && len(params) != 2 {
609 return fmt.Errorf("expected one or two arguments")
[577]610 }
611
[772]612 raw := params[len(params)-1]
613 params = params[:len(params)-1]
614
615 net, params, err := getNetworkFromArg(dc, params)
616 if err != nil {
617 return err
[577]618 }
619
620 uc := net.conn
621 if uc == nil {
[772]622 return fmt.Errorf("network %q is not currently connected", net.GetName())
[577]623 }
624
[772]625 m, err := irc.ParseMessage(raw)
[577]626 if err != nil {
[772]627 return fmt.Errorf("failed to parse command %q: %v", raw, err)
[577]628 }
[757]629 uc.SendMessage(ctx, m)
[577]630
631 sendServicePRIVMSG(dc, fmt.Sprintf("sent command to %q", net.GetName()))
632 return nil
633}
634
[614]635func sendCertfpFingerprints(dc *downstreamConn, cert []byte) {
636 sha1Sum := sha1.Sum(cert)
637 sendServicePRIVMSG(dc, "SHA-1 fingerprint: "+hex.EncodeToString(sha1Sum[:]))
638 sha256Sum := sha256.Sum256(cert)
639 sendServicePRIVMSG(dc, "SHA-256 fingerprint: "+hex.EncodeToString(sha256Sum[:]))
640 sha512Sum := sha512.Sum512(cert)
641 sendServicePRIVMSG(dc, "SHA-512 fingerprint: "+hex.EncodeToString(sha512Sum[:]))
642}
643
[771]644func getNetworkFromFlag(dc *downstreamConn, name string) (*network, error) {
645 if name == "" {
646 if dc.network == nil {
647 return nil, fmt.Errorf("no network selected, -network is required")
648 }
649 return dc.network, nil
650 } else {
651 net := dc.user.getNetwork(name)
652 if net == nil {
653 return nil, fmt.Errorf("unknown network %q", name)
654 }
655 return net, nil
656 }
657}
658
[677]659func handleServiceCertFPGenerate(ctx context.Context, dc *downstreamConn, params []string) error {
[325]660 fs := newFlagSet()
[771]661 netName := fs.String("network", "", "select a network")
[325]662 keyType := fs.String("key-type", "rsa", "key type to generate (rsa, ecdsa, ed25519)")
663 bits := fs.Int("bits", 3072, "size of key to generate, meaningful only for RSA")
664
665 if err := fs.Parse(params); err != nil {
666 return err
667 }
668
[771]669 if *bits <= 0 || *bits > maxRSABits {
670 return fmt.Errorf("invalid value for -bits")
[325]671 }
672
[771]673 net, err := getNetworkFromFlag(dc, *netName)
674 if err != nil {
675 return err
[325]676 }
677
[614]678 privKey, cert, err := generateCertFP(*keyType, *bits)
[325]679 if err != nil {
680 return err
681 }
682
[614]683 net.SASL.External.CertBlob = cert
684 net.SASL.External.PrivKeyBlob = privKey
[325]685 net.SASL.Mechanism = "EXTERNAL"
686
[677]687 if err := dc.srv.db.StoreNetwork(ctx, dc.user.ID, &net.Network); err != nil {
[325]688 return err
689 }
690
691 sendServicePRIVMSG(dc, "certificate generated")
[614]692 sendCertfpFingerprints(dc, cert)
[325]693 return nil
694}
695
[677]696func handleServiceCertFPFingerprints(ctx context.Context, dc *downstreamConn, params []string) error {
[771]697 fs := newFlagSet()
698 netName := fs.String("network", "", "select a network")
699
700 if err := fs.Parse(params); err != nil {
701 return err
[325]702 }
703
[771]704 net, err := getNetworkFromFlag(dc, *netName)
705 if err != nil {
706 return err
[325]707 }
708
[614]709 if net.SASL.Mechanism != "EXTERNAL" {
710 return fmt.Errorf("CertFP not set up")
711 }
712
713 sendCertfpFingerprints(dc, net.SASL.External.CertBlob)
[325]714 return nil
715}
716
[770]717func handleServiceSASLStatus(ctx context.Context, dc *downstreamConn, params []string) error {
[771]718 fs := newFlagSet()
719 netName := fs.String("network", "", "select a network")
720
721 if err := fs.Parse(params); err != nil {
722 return err
[730]723 }
724
[771]725 net, err := getNetworkFromFlag(dc, *netName)
726 if err != nil {
727 return err
[730]728 }
729
730 switch net.SASL.Mechanism {
731 case "PLAIN":
732 sendServicePRIVMSG(dc, fmt.Sprintf("SASL PLAIN enabled with username %q", net.SASL.Plain.Username))
733 case "EXTERNAL":
734 sendServicePRIVMSG(dc, "SASL EXTERNAL (CertFP) enabled")
735 case "":
736 sendServicePRIVMSG(dc, "SASL is disabled")
737 }
738
739 if uc := net.conn; uc != nil {
740 if uc.account != "" {
741 sendServicePRIVMSG(dc, fmt.Sprintf("Authenticated on upstream network with account %q", uc.account))
742 } else {
743 sendServicePRIVMSG(dc, "Unauthenticated on upstream network")
744 }
745 } else {
746 sendServicePRIVMSG(dc, "Disconnected from upstream network")
747 }
748
749 return nil
750}
751
[677]752func handleServiceSASLSetPlain(ctx context.Context, dc *downstreamConn, params []string) error {
[771]753 fs := newFlagSet()
754 netName := fs.String("network", "", "select a network")
755
756 if err := fs.Parse(params); err != nil {
757 return err
[325]758 }
759
[771]760 if len(fs.Args()) != 2 {
761 return fmt.Errorf("expected exactly 2 arguments")
[325]762 }
763
[771]764 net, err := getNetworkFromFlag(dc, *netName)
765 if err != nil {
766 return err
767 }
768
769 net.SASL.Plain.Username = fs.Arg(0)
770 net.SASL.Plain.Password = fs.Arg(1)
[364]771 net.SASL.Mechanism = "PLAIN"
[325]772
[677]773 if err := dc.srv.db.StoreNetwork(ctx, dc.user.ID, &net.Network); err != nil {
[325]774 return err
775 }
776
[364]777 sendServicePRIVMSG(dc, "credentials saved")
[325]778 return nil
779}
780
[677]781func handleServiceSASLReset(ctx context.Context, dc *downstreamConn, params []string) error {
[771]782 fs := newFlagSet()
783 netName := fs.String("network", "", "select a network")
784
785 if err := fs.Parse(params); err != nil {
786 return err
[363]787 }
788
[771]789 net, err := getNetworkFromFlag(dc, *netName)
790 if err != nil {
791 return err
[363]792 }
793
[364]794 net.SASL.Plain.Username = ""
795 net.SASL.Plain.Password = ""
796 net.SASL.External.CertBlob = nil
797 net.SASL.External.PrivKeyBlob = nil
798 net.SASL.Mechanism = ""
[363]799
[677]800 if err := dc.srv.db.StoreNetwork(ctx, dc.user.ID, &net.Network); err != nil {
[363]801 return err
802 }
803
[364]804 sendServicePRIVMSG(dc, "credentials reset")
[363]805 return nil
806}
807
[677]808func handleUserCreate(ctx context.Context, dc *downstreamConn, params []string) error {
[329]809 fs := newFlagSet()
810 username := fs.String("username", "", "")
811 password := fs.String("password", "", "")
[568]812 realname := fs.String("realname", "", "")
[329]813 admin := fs.Bool("admin", false, "")
814
815 if err := fs.Parse(params); err != nil {
816 return err
817 }
818 if *username == "" {
819 return fmt.Errorf("flag -username is required")
820 }
821 if *password == "" {
822 return fmt.Errorf("flag -password is required")
823 }
824
825 hashed, err := bcrypt.GenerateFromPassword([]byte(*password), bcrypt.DefaultCost)
826 if err != nil {
827 return fmt.Errorf("failed to hash password: %v", err)
828 }
829
830 user := &User{
831 Username: *username,
832 Password: string(hashed),
[568]833 Realname: *realname,
[329]834 Admin: *admin,
835 }
[680]836 if _, err := dc.srv.createUser(ctx, user); err != nil {
[329]837 return fmt.Errorf("could not create user: %v", err)
838 }
839
840 sendServicePRIVMSG(dc, fmt.Sprintf("created user %q", *username))
841 return nil
842}
[379]843
[625]844func popArg(params []string) (string, []string) {
845 if len(params) > 0 && !strings.HasPrefix(params[0], "-") {
846 return params[0], params[1:]
847 }
848 return "", params
849}
850
[677]851func handleUserUpdate(ctx context.Context, dc *downstreamConn, params []string) error {
[570]852 var password, realname *string
[625]853 var admin *bool
[568]854 fs := newFlagSet()
[570]855 fs.Var(stringPtrFlag{&password}, "password", "")
[569]856 fs.Var(stringPtrFlag{&realname}, "realname", "")
[625]857 fs.Var(boolPtrFlag{&admin}, "admin", "")
[568]858
[625]859 username, params := popArg(params)
[568]860 if err := fs.Parse(params); err != nil {
861 return err
862 }
[625]863 if len(fs.Args()) > 0 {
864 return fmt.Errorf("unexpected argument")
865 }
[568]866
[625]867 var hashed *string
[570]868 if password != nil {
[625]869 hashedBytes, err := bcrypt.GenerateFromPassword([]byte(*password), bcrypt.DefaultCost)
[570]870 if err != nil {
871 return fmt.Errorf("failed to hash password: %v", err)
872 }
[625]873 hashedStr := string(hashedBytes)
874 hashed = &hashedStr
[570]875 }
[568]876
[625]877 if username != "" && username != dc.user.Username {
878 if !dc.user.Admin {
879 return fmt.Errorf("you must be an admin to update other users")
880 }
881 if realname != nil {
882 return fmt.Errorf("cannot update -realname of other user")
883 }
884
885 u := dc.srv.getUser(username)
886 if u == nil {
887 return fmt.Errorf("unknown username %q", username)
888 }
889
890 done := make(chan error, 1)
[679]891 event := eventUserUpdate{
[625]892 password: hashed,
893 admin: admin,
894 done: done,
895 }
[679]896 select {
897 case <-ctx.Done():
898 return ctx.Err()
899 case u.events <- event:
900 }
901 // TODO: send context to the other side
[625]902 if err := <-done; err != nil {
903 return err
904 }
905
906 sendServicePRIVMSG(dc, fmt.Sprintf("updated user %q", username))
907 } else {
908 // copy the user record because we'll mutate it
909 record := dc.user.User
910
911 if hashed != nil {
912 record.Password = *hashed
913 }
914 if realname != nil {
915 record.Realname = *realname
916 }
917 if admin != nil {
918 return fmt.Errorf("cannot update -admin of own user")
919 }
920
[677]921 if err := dc.user.updateUser(ctx, &record); err != nil {
[625]922 return err
923 }
924
925 sendServicePRIVMSG(dc, fmt.Sprintf("updated user %q", dc.user.Username))
[572]926 }
927
[568]928 return nil
929}
930
[677]931func handleUserDelete(ctx context.Context, dc *downstreamConn, params []string) error {
[379]932 if len(params) != 1 {
933 return fmt.Errorf("expected exactly one argument")
934 }
935 username := params[0]
936
937 u := dc.srv.getUser(username)
938 if u == nil {
939 return fmt.Errorf("unknown username %q", username)
940 }
941
942 u.stop()
943
[677]944 if err := dc.srv.db.DeleteUser(ctx, u.ID); err != nil {
[379]945 return fmt.Errorf("failed to delete user: %v", err)
946 }
947
948 sendServicePRIVMSG(dc, fmt.Sprintf("deleted user %q", username))
949 return nil
950}
[436]951
[677]952func handleServiceChannelStatus(ctx context.Context, dc *downstreamConn, params []string) error {
[539]953 var defaultNetworkName string
954 if dc.network != nil {
955 defaultNetworkName = dc.network.GetName()
956 }
957
958 fs := newFlagSet()
959 networkName := fs.String("network", defaultNetworkName, "")
960
961 if err := fs.Parse(params); err != nil {
962 return err
963 }
964
[546]965 n := 0
966
[539]967 sendNetwork := func(net *network) {
[573]968 var channels []*Channel
[539]969 for _, entry := range net.channels.innerMap {
[573]970 channels = append(channels, entry.value.(*Channel))
971 }
[539]972
[573]973 sort.Slice(channels, func(i, j int) bool {
974 return strings.ReplaceAll(channels[i].Name, "#", "") <
975 strings.ReplaceAll(channels[j].Name, "#", "")
976 })
977
978 for _, ch := range channels {
[539]979 var uch *upstreamChannel
980 if net.conn != nil {
981 uch = net.conn.channels.Value(ch.Name)
982 }
983
984 name := ch.Name
985 if *networkName == "" {
986 name += "/" + net.GetName()
987 }
988
989 var status string
990 if uch != nil {
991 status = "joined"
992 } else if net.conn != nil {
993 status = "parted"
994 } else {
995 status = "disconnected"
996 }
997
998 if ch.Detached {
999 status += ", detached"
1000 }
1001
1002 s := fmt.Sprintf("%v [%v]", name, status)
1003 sendServicePRIVMSG(dc, s)
[546]1004
1005 n++
[539]1006 }
1007 }
1008
1009 if *networkName == "" {
[768]1010 for _, net := range dc.user.networks {
1011 sendNetwork(net)
1012 }
[539]1013 } else {
1014 net := dc.user.getNetwork(*networkName)
1015 if net == nil {
1016 return fmt.Errorf("unknown network %q", *networkName)
1017 }
1018 sendNetwork(net)
1019 }
1020
[546]1021 if n == 0 {
1022 sendServicePRIVMSG(dc, "No channel configured.")
1023 }
1024
[539]1025 return nil
1026}
1027
[436]1028type channelFlagSet struct {
1029 *flag.FlagSet
1030 RelayDetached, ReattachOn, DetachAfter, DetachOn *string
1031}
1032
1033func newChannelFlagSet() *channelFlagSet {
1034 fs := &channelFlagSet{FlagSet: newFlagSet()}
1035 fs.Var(stringPtrFlag{&fs.RelayDetached}, "relay-detached", "")
1036 fs.Var(stringPtrFlag{&fs.ReattachOn}, "reattach-on", "")
1037 fs.Var(stringPtrFlag{&fs.DetachAfter}, "detach-after", "")
1038 fs.Var(stringPtrFlag{&fs.DetachOn}, "detach-on", "")
1039 return fs
1040}
1041
1042func (fs *channelFlagSet) update(channel *Channel) error {
1043 if fs.RelayDetached != nil {
1044 filter, err := parseFilter(*fs.RelayDetached)
1045 if err != nil {
1046 return err
1047 }
1048 channel.RelayDetached = filter
1049 }
1050 if fs.ReattachOn != nil {
1051 filter, err := parseFilter(*fs.ReattachOn)
1052 if err != nil {
1053 return err
1054 }
1055 channel.ReattachOn = filter
1056 }
1057 if fs.DetachAfter != nil {
1058 dur, err := time.ParseDuration(*fs.DetachAfter)
1059 if err != nil || dur < 0 {
1060 return fmt.Errorf("unknown duration for -detach-after %q (duration format: 0, 300s, 22h30m, ...)", *fs.DetachAfter)
1061 }
1062 channel.DetachAfter = dur
1063 }
1064 if fs.DetachOn != nil {
1065 filter, err := parseFilter(*fs.DetachOn)
1066 if err != nil {
1067 return err
1068 }
1069 channel.DetachOn = filter
1070 }
1071 return nil
1072}
1073
[677]1074func handleServiceChannelUpdate(ctx context.Context, dc *downstreamConn, params []string) error {
[436]1075 if len(params) < 1 {
1076 return fmt.Errorf("expected at least one argument")
1077 }
1078 name := params[0]
1079
1080 fs := newChannelFlagSet()
1081 if err := fs.Parse(params[1:]); err != nil {
1082 return err
1083 }
1084
1085 uc, upstreamName, err := dc.unmarshalEntity(name)
1086 if err != nil {
1087 return fmt.Errorf("unknown channel %q", name)
1088 }
1089
[478]1090 ch := uc.network.channels.Value(upstreamName)
1091 if ch == nil {
[436]1092 return fmt.Errorf("unknown channel %q", name)
1093 }
1094
1095 if err := fs.update(ch); err != nil {
1096 return err
1097 }
1098
1099 uc.updateChannelAutoDetach(upstreamName)
1100
[677]1101 if err := dc.srv.db.StoreChannel(ctx, uc.network.ID, ch); err != nil {
[436]1102 return fmt.Errorf("failed to update channel: %v", err)
1103 }
1104
1105 sendServicePRIVMSG(dc, fmt.Sprintf("updated channel %q", name))
1106 return nil
1107}
[605]1108
[677]1109func handleServiceServerStatus(ctx context.Context, dc *downstreamConn, params []string) error {
1110 dbStats, err := dc.user.srv.db.Stats(ctx)
[607]1111 if err != nil {
1112 return err
1113 }
1114 serverStats := dc.user.srv.Stats()
[710]1115 sendServicePRIVMSG(dc, fmt.Sprintf("%v/%v users, %v downstreams, %v upstreams, %v networks, %v channels", serverStats.Users, dbStats.Users, serverStats.Downstreams, serverStats.Upstreams, dbStats.Networks, dbStats.Channels))
[605]1116 return nil
1117}
[615]1118
[677]1119func handleServiceServerNotice(ctx context.Context, dc *downstreamConn, params []string) error {
[615]1120 if len(params) != 1 {
1121 return fmt.Errorf("expected exactly one argument")
1122 }
1123 text := params[0]
1124
1125 dc.logger.Printf("broadcasting bouncer-wide NOTICE: %v", text)
1126
1127 broadcastMsg := &irc.Message{
1128 Prefix: servicePrefix,
1129 Command: "NOTICE",
[691]1130 Params: []string{"$" + dc.srv.Config().Hostname, text},
[615]1131 }
[678]1132 var err error
[755]1133 sent := 0
1134 total := 0
[615]1135 dc.srv.forEachUser(func(u *user) {
[755]1136 total++
[678]1137 select {
1138 case <-ctx.Done():
1139 err = ctx.Err()
1140 case u.events <- eventBroadcast{broadcastMsg}:
[755]1141 sent++
[678]1142 }
[615]1143 })
[755]1144
1145 dc.logger.Printf("broadcast bouncer-wide NOTICE to %v/%v downstreams", sent, total)
1146 sendServicePRIVMSG(dc, fmt.Sprintf("sent to %v/%v downstream connections", sent, total))
1147
[678]1148 return err
[615]1149}
Note: See TracBrowser for help on using the repository browser.