source: code/trunk/service.go@ 771

Last change on this file since 771 was 771, checked in by contact, 3 years ago

service: switch to -network flag for certfp and sasl commands

Instead of always requiring users to explicitly specify the network
name, guess it from the downstream connection.

Network commands are left as-is because it's not yet clear how to
handle them.

File size: 27.5 KB
Line 
1package soju
2
3import (
4 "context"
5 "crypto/sha1"
6 "crypto/sha256"
7 "crypto/sha512"
8 "encoding/hex"
9 "flag"
10 "fmt"
11 "io/ioutil"
12 "sort"
13 "strconv"
14 "strings"
15 "time"
16 "unicode"
17
18 "golang.org/x/crypto/bcrypt"
19 "gopkg.in/irc.v3"
20)
21
22const serviceNick = "BouncerServ"
23const serviceNickCM = "bouncerserv"
24const serviceRealname = "soju bouncer service"
25
26// maxRSABits is the maximum number of RSA key bits used when generating a new
27// private key.
28const maxRSABits = 8192
29
30var servicePrefix = &irc.Prefix{
31 Name: serviceNick,
32 User: serviceNick,
33 Host: serviceNick,
34}
35
36type serviceCommandSet map[string]*serviceCommand
37
38type serviceCommand struct {
39 usage string
40 desc string
41 handle func(ctx context.Context, dc *downstreamConn, params []string) error
42 children serviceCommandSet
43 admin bool
44}
45
46func sendServiceNOTICE(dc *downstreamConn, text string) {
47 dc.SendMessage(&irc.Message{
48 Prefix: servicePrefix,
49 Command: "NOTICE",
50 Params: []string{dc.nick, text},
51 })
52}
53
54func sendServicePRIVMSG(dc *downstreamConn, text string) {
55 dc.SendMessage(&irc.Message{
56 Prefix: servicePrefix,
57 Command: "PRIVMSG",
58 Params: []string{dc.nick, text},
59 })
60}
61
62func splitWords(s string) ([]string, error) {
63 var words []string
64 var lastWord strings.Builder
65 escape := false
66 prev := ' '
67 wordDelim := ' '
68
69 for _, r := range s {
70 if escape {
71 // last char was a backslash, write the byte as-is.
72 lastWord.WriteRune(r)
73 escape = false
74 } else if r == '\\' {
75 escape = true
76 } else if wordDelim == ' ' && unicode.IsSpace(r) {
77 // end of last word
78 if !unicode.IsSpace(prev) {
79 words = append(words, lastWord.String())
80 lastWord.Reset()
81 }
82 } else if r == wordDelim {
83 // wordDelim is either " or ', switch back to
84 // space-delimited words.
85 wordDelim = ' '
86 } else if r == '"' || r == '\'' {
87 if wordDelim == ' ' {
88 // start of (double-)quoted word
89 wordDelim = r
90 } else {
91 // either wordDelim is " and r is ' or vice-versa
92 lastWord.WriteRune(r)
93 }
94 } else {
95 lastWord.WriteRune(r)
96 }
97
98 prev = r
99 }
100
101 if !unicode.IsSpace(prev) {
102 words = append(words, lastWord.String())
103 }
104
105 if wordDelim != ' ' {
106 return nil, fmt.Errorf("unterminated quoted string")
107 }
108 if escape {
109 return nil, fmt.Errorf("unterminated backslash sequence")
110 }
111
112 return words, nil
113}
114
115func handleServicePRIVMSG(ctx context.Context, dc *downstreamConn, text string) {
116 words, err := splitWords(text)
117 if err != nil {
118 sendServicePRIVMSG(dc, fmt.Sprintf(`error: failed to parse command: %v`, err))
119 return
120 }
121
122 cmd, params, err := serviceCommands.Get(words)
123 if err != nil {
124 sendServicePRIVMSG(dc, fmt.Sprintf(`error: %v (type "help" for a list of commands)`, err))
125 return
126 }
127 if cmd.admin && !dc.user.Admin {
128 sendServicePRIVMSG(dc, "error: you must be an admin to use this command")
129 return
130 }
131
132 if cmd.handle == nil {
133 if len(cmd.children) > 0 {
134 var l []string
135 appendServiceCommandSetHelp(cmd.children, words, dc.user.Admin, &l)
136 sendServicePRIVMSG(dc, "available commands: "+strings.Join(l, ", "))
137 } else {
138 // Pretend the command does not exist if it has neither children nor handler.
139 // This is obviously a bug but it is better to not die anyway.
140 dc.logger.Printf("command without handler and subcommands invoked:", words[0])
141 sendServicePRIVMSG(dc, fmt.Sprintf("command %q not found", words[0]))
142 }
143 return
144 }
145
146 if err := cmd.handle(ctx, dc, params); err != nil {
147 sendServicePRIVMSG(dc, fmt.Sprintf("error: %v", err))
148 }
149}
150
151func (cmds serviceCommandSet) Get(params []string) (*serviceCommand, []string, error) {
152 if len(params) == 0 {
153 return nil, nil, fmt.Errorf("no command specified")
154 }
155
156 name := params[0]
157 params = params[1:]
158
159 cmd, ok := cmds[name]
160 if !ok {
161 for k := range cmds {
162 if !strings.HasPrefix(k, name) {
163 continue
164 }
165 if cmd != nil {
166 return nil, params, fmt.Errorf("command %q is ambiguous", name)
167 }
168 cmd = cmds[k]
169 }
170 }
171 if cmd == nil {
172 return nil, params, fmt.Errorf("command %q not found", name)
173 }
174
175 if len(params) == 0 || len(cmd.children) == 0 {
176 return cmd, params, nil
177 }
178 return cmd.children.Get(params)
179}
180
181func (cmds serviceCommandSet) Names() []string {
182 l := make([]string, 0, len(cmds))
183 for name := range cmds {
184 l = append(l, name)
185 }
186 sort.Strings(l)
187 return l
188}
189
190var serviceCommands serviceCommandSet
191
192func init() {
193 serviceCommands = serviceCommandSet{
194 "help": {
195 usage: "[command]",
196 desc: "print help message",
197 handle: handleServiceHelp,
198 },
199 "network": {
200 children: serviceCommandSet{
201 "create": {
202 usage: "-addr <addr> [-name name] [-username username] [-pass pass] [-realname realname] [-nick nick] [-enabled enabled] [-connect-command command]...",
203 desc: "add a new network",
204 handle: handleServiceNetworkCreate,
205 },
206 "status": {
207 desc: "show a list of saved networks and their current status",
208 handle: handleServiceNetworkStatus,
209 },
210 "update": {
211 usage: "<name> [-addr addr] [-name name] [-username username] [-pass pass] [-realname realname] [-nick nick] [-enabled enabled] [-connect-command command]...",
212 desc: "update a network",
213 handle: handleServiceNetworkUpdate,
214 },
215 "delete": {
216 usage: "<name>",
217 desc: "delete a network",
218 handle: handleServiceNetworkDelete,
219 },
220 "quote": {
221 usage: "<name> <command>",
222 desc: "send a raw line to a network",
223 handle: handleServiceNetworkQuote,
224 },
225 },
226 },
227 "certfp": {
228 children: serviceCommandSet{
229 "generate": {
230 usage: "[-key-type rsa|ecdsa|ed25519] [-bits N] [-network name]",
231 desc: "generate a new self-signed certificate, defaults to using RSA-3072 key",
232 handle: handleServiceCertFPGenerate,
233 },
234 "fingerprint": {
235 usage: "[-network name]",
236 desc: "show fingerprints of certificate",
237 handle: handleServiceCertFPFingerprints,
238 },
239 },
240 },
241 "sasl": {
242 children: serviceCommandSet{
243 "status": {
244 usage: "[-network name]",
245 desc: "show SASL status",
246 handle: handleServiceSASLStatus,
247 },
248 "set-plain": {
249 usage: "[-network name] <username> <password>",
250 desc: "set SASL PLAIN credentials",
251 handle: handleServiceSASLSetPlain,
252 },
253 "reset": {
254 usage: "[-network name]",
255 desc: "disable SASL authentication and remove stored credentials",
256 handle: handleServiceSASLReset,
257 },
258 },
259 },
260 "user": {
261 children: serviceCommandSet{
262 "create": {
263 usage: "-username <username> -password <password> [-realname <realname>] [-admin]",
264 desc: "create a new soju user",
265 handle: handleUserCreate,
266 admin: true,
267 },
268 "update": {
269 usage: "[-password <password>] [-realname <realname>]",
270 desc: "update the current user",
271 handle: handleUserUpdate,
272 },
273 "delete": {
274 usage: "<username>",
275 desc: "delete a user",
276 handle: handleUserDelete,
277 admin: true,
278 },
279 },
280 },
281 "channel": {
282 children: serviceCommandSet{
283 "status": {
284 usage: "[-network name]",
285 desc: "show a list of saved channels and their current status",
286 handle: handleServiceChannelStatus,
287 },
288 "update": {
289 usage: "<name> [-relay-detached <default|none|highlight|message>] [-reattach-on <default|none|highlight|message>] [-detach-after <duration>] [-detach-on <default|none|highlight|message>]",
290 desc: "update a channel",
291 handle: handleServiceChannelUpdate,
292 },
293 },
294 },
295 "server": {
296 children: serviceCommandSet{
297 "status": {
298 desc: "show server statistics",
299 handle: handleServiceServerStatus,
300 admin: true,
301 },
302 "notice": {
303 desc: "broadcast a notice to all connected bouncer users",
304 handle: handleServiceServerNotice,
305 admin: true,
306 },
307 },
308 admin: true,
309 },
310 }
311}
312
313func appendServiceCommandSetHelp(cmds serviceCommandSet, prefix []string, admin bool, l *[]string) {
314 for _, name := range cmds.Names() {
315 cmd := cmds[name]
316 if cmd.admin && !admin {
317 continue
318 }
319 words := append(prefix, name)
320 if len(cmd.children) == 0 {
321 s := strings.Join(words, " ")
322 *l = append(*l, s)
323 } else {
324 appendServiceCommandSetHelp(cmd.children, words, admin, l)
325 }
326 }
327}
328
329func handleServiceHelp(ctx context.Context, dc *downstreamConn, params []string) error {
330 if len(params) > 0 {
331 cmd, rest, err := serviceCommands.Get(params)
332 if err != nil {
333 return err
334 }
335 words := params[:len(params)-len(rest)]
336
337 if len(cmd.children) > 0 {
338 var l []string
339 appendServiceCommandSetHelp(cmd.children, words, dc.user.Admin, &l)
340 sendServicePRIVMSG(dc, "available commands: "+strings.Join(l, ", "))
341 } else {
342 text := strings.Join(words, " ")
343 if cmd.usage != "" {
344 text += " " + cmd.usage
345 }
346 text += ": " + cmd.desc
347
348 sendServicePRIVMSG(dc, text)
349 }
350 } else {
351 var l []string
352 appendServiceCommandSetHelp(serviceCommands, nil, dc.user.Admin, &l)
353 sendServicePRIVMSG(dc, "available commands: "+strings.Join(l, ", "))
354 }
355 return nil
356}
357
358func newFlagSet() *flag.FlagSet {
359 fs := flag.NewFlagSet("", flag.ContinueOnError)
360 fs.SetOutput(ioutil.Discard)
361 return fs
362}
363
364type stringSliceFlag []string
365
366func (v *stringSliceFlag) String() string {
367 return fmt.Sprint([]string(*v))
368}
369
370func (v *stringSliceFlag) Set(s string) error {
371 *v = append(*v, s)
372 return nil
373}
374
375// stringPtrFlag is a flag value populating a string pointer. This allows to
376// disambiguate between a flag that hasn't been set and a flag that has been
377// set to an empty string.
378type stringPtrFlag struct {
379 ptr **string
380}
381
382func (f stringPtrFlag) String() string {
383 if f.ptr == nil || *f.ptr == nil {
384 return ""
385 }
386 return **f.ptr
387}
388
389func (f stringPtrFlag) Set(s string) error {
390 *f.ptr = &s
391 return nil
392}
393
394type boolPtrFlag struct {
395 ptr **bool
396}
397
398func (f boolPtrFlag) String() string {
399 if f.ptr == nil || *f.ptr == nil {
400 return "<nil>"
401 }
402 return strconv.FormatBool(**f.ptr)
403}
404
405func (f boolPtrFlag) Set(s string) error {
406 v, err := strconv.ParseBool(s)
407 if err != nil {
408 return err
409 }
410 *f.ptr = &v
411 return nil
412}
413
414type networkFlagSet struct {
415 *flag.FlagSet
416 Addr, Name, Nick, Username, Pass, Realname *string
417 Enabled *bool
418 ConnectCommands []string
419}
420
421func newNetworkFlagSet() *networkFlagSet {
422 fs := &networkFlagSet{FlagSet: newFlagSet()}
423 fs.Var(stringPtrFlag{&fs.Addr}, "addr", "")
424 fs.Var(stringPtrFlag{&fs.Name}, "name", "")
425 fs.Var(stringPtrFlag{&fs.Nick}, "nick", "")
426 fs.Var(stringPtrFlag{&fs.Username}, "username", "")
427 fs.Var(stringPtrFlag{&fs.Pass}, "pass", "")
428 fs.Var(stringPtrFlag{&fs.Realname}, "realname", "")
429 fs.Var(boolPtrFlag{&fs.Enabled}, "enabled", "")
430 fs.Var((*stringSliceFlag)(&fs.ConnectCommands), "connect-command", "")
431 return fs
432}
433
434func (fs *networkFlagSet) update(network *Network) error {
435 if fs.Addr != nil {
436 if addrParts := strings.SplitN(*fs.Addr, "://", 2); len(addrParts) == 2 {
437 scheme := addrParts[0]
438 switch scheme {
439 case "ircs", "irc+insecure", "unix":
440 default:
441 return fmt.Errorf("unknown scheme %q (supported schemes: ircs, irc+insecure, unix)", scheme)
442 }
443 }
444 network.Addr = *fs.Addr
445 }
446 if fs.Name != nil {
447 network.Name = *fs.Name
448 }
449 if fs.Nick != nil {
450 network.Nick = *fs.Nick
451 }
452 if fs.Username != nil {
453 network.Username = *fs.Username
454 }
455 if fs.Pass != nil {
456 network.Pass = *fs.Pass
457 }
458 if fs.Realname != nil {
459 network.Realname = *fs.Realname
460 }
461 if fs.Enabled != nil {
462 network.Enabled = *fs.Enabled
463 }
464 if fs.ConnectCommands != nil {
465 if len(fs.ConnectCommands) == 1 && fs.ConnectCommands[0] == "" {
466 network.ConnectCommands = nil
467 } else {
468 for _, command := range fs.ConnectCommands {
469 _, err := irc.ParseMessage(command)
470 if err != nil {
471 return fmt.Errorf("flag -connect-command must be a valid raw irc command string: %q: %v", command, err)
472 }
473 }
474 network.ConnectCommands = fs.ConnectCommands
475 }
476 }
477 return nil
478}
479
480func handleServiceNetworkCreate(ctx context.Context, dc *downstreamConn, params []string) error {
481 fs := newNetworkFlagSet()
482 if err := fs.Parse(params); err != nil {
483 return err
484 }
485 if fs.Addr == nil {
486 return fmt.Errorf("flag -addr is required")
487 }
488
489 record := &Network{
490 Addr: *fs.Addr,
491 Enabled: true,
492 }
493 if err := fs.update(record); err != nil {
494 return err
495 }
496
497 network, err := dc.user.createNetwork(ctx, record)
498 if err != nil {
499 return fmt.Errorf("could not create network: %v", err)
500 }
501
502 sendServicePRIVMSG(dc, fmt.Sprintf("created network %q", network.GetName()))
503 return nil
504}
505
506func handleServiceNetworkStatus(ctx context.Context, dc *downstreamConn, params []string) error {
507 n := 0
508 for _, net := range dc.user.networks {
509 var statuses []string
510 var details string
511 if uc := net.conn; uc != nil {
512 if dc.nick != uc.nick {
513 statuses = append(statuses, "connected as "+uc.nick)
514 } else {
515 statuses = append(statuses, "connected")
516 }
517 details = fmt.Sprintf("%v channels", uc.channels.Len())
518 } else if !net.Enabled {
519 statuses = append(statuses, "disabled")
520 } else {
521 statuses = append(statuses, "disconnected")
522 if net.lastError != nil {
523 details = net.lastError.Error()
524 }
525 }
526
527 if net == dc.network {
528 statuses = append(statuses, "current")
529 }
530
531 name := net.GetName()
532 if name != net.Addr {
533 name = fmt.Sprintf("%v (%v)", name, net.Addr)
534 }
535
536 s := fmt.Sprintf("%v [%v]", name, strings.Join(statuses, ", "))
537 if details != "" {
538 s += ": " + details
539 }
540 sendServicePRIVMSG(dc, s)
541
542 n++
543 }
544
545 if n == 0 {
546 sendServicePRIVMSG(dc, `No network configured, add one with "network create".`)
547 }
548
549 return nil
550}
551
552func handleServiceNetworkUpdate(ctx context.Context, dc *downstreamConn, params []string) error {
553 if len(params) < 1 {
554 return fmt.Errorf("expected at least one argument")
555 }
556
557 fs := newNetworkFlagSet()
558 if err := fs.Parse(params[1:]); err != nil {
559 return err
560 }
561
562 net := dc.user.getNetwork(params[0])
563 if net == nil {
564 return fmt.Errorf("unknown network %q", params[0])
565 }
566
567 record := net.Network // copy network record because we'll mutate it
568 if err := fs.update(&record); err != nil {
569 return err
570 }
571
572 network, err := dc.user.updateNetwork(ctx, &record)
573 if err != nil {
574 return fmt.Errorf("could not update network: %v", err)
575 }
576
577 sendServicePRIVMSG(dc, fmt.Sprintf("updated network %q", network.GetName()))
578 return nil
579}
580
581func handleServiceNetworkDelete(ctx context.Context, dc *downstreamConn, params []string) error {
582 if len(params) != 1 {
583 return fmt.Errorf("expected exactly one argument")
584 }
585
586 net := dc.user.getNetwork(params[0])
587 if net == nil {
588 return fmt.Errorf("unknown network %q", params[0])
589 }
590
591 if err := dc.user.deleteNetwork(ctx, net.ID); err != nil {
592 return err
593 }
594
595 sendServicePRIVMSG(dc, fmt.Sprintf("deleted network %q", net.GetName()))
596 return nil
597}
598
599func handleServiceNetworkQuote(ctx context.Context, dc *downstreamConn, params []string) error {
600 if len(params) != 2 {
601 return fmt.Errorf("expected exactly two arguments")
602 }
603
604 net := dc.user.getNetwork(params[0])
605 if net == nil {
606 return fmt.Errorf("unknown network %q", params[0])
607 }
608
609 uc := net.conn
610 if uc == nil {
611 return fmt.Errorf("network %q is not currently connected", params[0])
612 }
613
614 m, err := irc.ParseMessage(params[1])
615 if err != nil {
616 return fmt.Errorf("failed to parse command %q: %v", params[1], err)
617 }
618 uc.SendMessage(ctx, m)
619
620 sendServicePRIVMSG(dc, fmt.Sprintf("sent command to %q", net.GetName()))
621 return nil
622}
623
624func sendCertfpFingerprints(dc *downstreamConn, cert []byte) {
625 sha1Sum := sha1.Sum(cert)
626 sendServicePRIVMSG(dc, "SHA-1 fingerprint: "+hex.EncodeToString(sha1Sum[:]))
627 sha256Sum := sha256.Sum256(cert)
628 sendServicePRIVMSG(dc, "SHA-256 fingerprint: "+hex.EncodeToString(sha256Sum[:]))
629 sha512Sum := sha512.Sum512(cert)
630 sendServicePRIVMSG(dc, "SHA-512 fingerprint: "+hex.EncodeToString(sha512Sum[:]))
631}
632
633func getNetworkFromFlag(dc *downstreamConn, name string) (*network, error) {
634 if name == "" {
635 if dc.network == nil {
636 return nil, fmt.Errorf("no network selected, -network is required")
637 }
638 return dc.network, nil
639 } else {
640 net := dc.user.getNetwork(name)
641 if net == nil {
642 return nil, fmt.Errorf("unknown network %q", name)
643 }
644 return net, nil
645 }
646}
647
648func handleServiceCertFPGenerate(ctx context.Context, dc *downstreamConn, params []string) error {
649 fs := newFlagSet()
650 netName := fs.String("network", "", "select a network")
651 keyType := fs.String("key-type", "rsa", "key type to generate (rsa, ecdsa, ed25519)")
652 bits := fs.Int("bits", 3072, "size of key to generate, meaningful only for RSA")
653
654 if err := fs.Parse(params); err != nil {
655 return err
656 }
657
658 if *bits <= 0 || *bits > maxRSABits {
659 return fmt.Errorf("invalid value for -bits")
660 }
661
662 net, err := getNetworkFromFlag(dc, *netName)
663 if err != nil {
664 return err
665 }
666
667 privKey, cert, err := generateCertFP(*keyType, *bits)
668 if err != nil {
669 return err
670 }
671
672 net.SASL.External.CertBlob = cert
673 net.SASL.External.PrivKeyBlob = privKey
674 net.SASL.Mechanism = "EXTERNAL"
675
676 if err := dc.srv.db.StoreNetwork(ctx, dc.user.ID, &net.Network); err != nil {
677 return err
678 }
679
680 sendServicePRIVMSG(dc, "certificate generated")
681 sendCertfpFingerprints(dc, cert)
682 return nil
683}
684
685func handleServiceCertFPFingerprints(ctx context.Context, dc *downstreamConn, params []string) error {
686 fs := newFlagSet()
687 netName := fs.String("network", "", "select a network")
688
689 if err := fs.Parse(params); err != nil {
690 return err
691 }
692
693 net, err := getNetworkFromFlag(dc, *netName)
694 if err != nil {
695 return err
696 }
697
698 if net.SASL.Mechanism != "EXTERNAL" {
699 return fmt.Errorf("CertFP not set up")
700 }
701
702 sendCertfpFingerprints(dc, net.SASL.External.CertBlob)
703 return nil
704}
705
706func handleServiceSASLStatus(ctx context.Context, dc *downstreamConn, params []string) error {
707 fs := newFlagSet()
708 netName := fs.String("network", "", "select a network")
709
710 if err := fs.Parse(params); err != nil {
711 return err
712 }
713
714 net, err := getNetworkFromFlag(dc, *netName)
715 if err != nil {
716 return err
717 }
718
719 switch net.SASL.Mechanism {
720 case "PLAIN":
721 sendServicePRIVMSG(dc, fmt.Sprintf("SASL PLAIN enabled with username %q", net.SASL.Plain.Username))
722 case "EXTERNAL":
723 sendServicePRIVMSG(dc, "SASL EXTERNAL (CertFP) enabled")
724 case "":
725 sendServicePRIVMSG(dc, "SASL is disabled")
726 }
727
728 if uc := net.conn; uc != nil {
729 if uc.account != "" {
730 sendServicePRIVMSG(dc, fmt.Sprintf("Authenticated on upstream network with account %q", uc.account))
731 } else {
732 sendServicePRIVMSG(dc, "Unauthenticated on upstream network")
733 }
734 } else {
735 sendServicePRIVMSG(dc, "Disconnected from upstream network")
736 }
737
738 return nil
739}
740
741func handleServiceSASLSetPlain(ctx context.Context, dc *downstreamConn, params []string) error {
742 fs := newFlagSet()
743 netName := fs.String("network", "", "select a network")
744
745 if err := fs.Parse(params); err != nil {
746 return err
747 }
748
749 if len(fs.Args()) != 2 {
750 return fmt.Errorf("expected exactly 2 arguments")
751 }
752
753 net, err := getNetworkFromFlag(dc, *netName)
754 if err != nil {
755 return err
756 }
757
758 net.SASL.Plain.Username = fs.Arg(0)
759 net.SASL.Plain.Password = fs.Arg(1)
760 net.SASL.Mechanism = "PLAIN"
761
762 if err := dc.srv.db.StoreNetwork(ctx, dc.user.ID, &net.Network); err != nil {
763 return err
764 }
765
766 sendServicePRIVMSG(dc, "credentials saved")
767 return nil
768}
769
770func handleServiceSASLReset(ctx context.Context, dc *downstreamConn, params []string) error {
771 fs := newFlagSet()
772 netName := fs.String("network", "", "select a network")
773
774 if err := fs.Parse(params); err != nil {
775 return err
776 }
777
778 net, err := getNetworkFromFlag(dc, *netName)
779 if err != nil {
780 return err
781 }
782
783 net.SASL.Plain.Username = ""
784 net.SASL.Plain.Password = ""
785 net.SASL.External.CertBlob = nil
786 net.SASL.External.PrivKeyBlob = nil
787 net.SASL.Mechanism = ""
788
789 if err := dc.srv.db.StoreNetwork(ctx, dc.user.ID, &net.Network); err != nil {
790 return err
791 }
792
793 sendServicePRIVMSG(dc, "credentials reset")
794 return nil
795}
796
797func handleUserCreate(ctx context.Context, dc *downstreamConn, params []string) error {
798 fs := newFlagSet()
799 username := fs.String("username", "", "")
800 password := fs.String("password", "", "")
801 realname := fs.String("realname", "", "")
802 admin := fs.Bool("admin", false, "")
803
804 if err := fs.Parse(params); err != nil {
805 return err
806 }
807 if *username == "" {
808 return fmt.Errorf("flag -username is required")
809 }
810 if *password == "" {
811 return fmt.Errorf("flag -password is required")
812 }
813
814 hashed, err := bcrypt.GenerateFromPassword([]byte(*password), bcrypt.DefaultCost)
815 if err != nil {
816 return fmt.Errorf("failed to hash password: %v", err)
817 }
818
819 user := &User{
820 Username: *username,
821 Password: string(hashed),
822 Realname: *realname,
823 Admin: *admin,
824 }
825 if _, err := dc.srv.createUser(ctx, user); err != nil {
826 return fmt.Errorf("could not create user: %v", err)
827 }
828
829 sendServicePRIVMSG(dc, fmt.Sprintf("created user %q", *username))
830 return nil
831}
832
833func popArg(params []string) (string, []string) {
834 if len(params) > 0 && !strings.HasPrefix(params[0], "-") {
835 return params[0], params[1:]
836 }
837 return "", params
838}
839
840func handleUserUpdate(ctx context.Context, dc *downstreamConn, params []string) error {
841 var password, realname *string
842 var admin *bool
843 fs := newFlagSet()
844 fs.Var(stringPtrFlag{&password}, "password", "")
845 fs.Var(stringPtrFlag{&realname}, "realname", "")
846 fs.Var(boolPtrFlag{&admin}, "admin", "")
847
848 username, params := popArg(params)
849 if err := fs.Parse(params); err != nil {
850 return err
851 }
852 if len(fs.Args()) > 0 {
853 return fmt.Errorf("unexpected argument")
854 }
855
856 var hashed *string
857 if password != nil {
858 hashedBytes, err := bcrypt.GenerateFromPassword([]byte(*password), bcrypt.DefaultCost)
859 if err != nil {
860 return fmt.Errorf("failed to hash password: %v", err)
861 }
862 hashedStr := string(hashedBytes)
863 hashed = &hashedStr
864 }
865
866 if username != "" && username != dc.user.Username {
867 if !dc.user.Admin {
868 return fmt.Errorf("you must be an admin to update other users")
869 }
870 if realname != nil {
871 return fmt.Errorf("cannot update -realname of other user")
872 }
873
874 u := dc.srv.getUser(username)
875 if u == nil {
876 return fmt.Errorf("unknown username %q", username)
877 }
878
879 done := make(chan error, 1)
880 event := eventUserUpdate{
881 password: hashed,
882 admin: admin,
883 done: done,
884 }
885 select {
886 case <-ctx.Done():
887 return ctx.Err()
888 case u.events <- event:
889 }
890 // TODO: send context to the other side
891 if err := <-done; err != nil {
892 return err
893 }
894
895 sendServicePRIVMSG(dc, fmt.Sprintf("updated user %q", username))
896 } else {
897 // copy the user record because we'll mutate it
898 record := dc.user.User
899
900 if hashed != nil {
901 record.Password = *hashed
902 }
903 if realname != nil {
904 record.Realname = *realname
905 }
906 if admin != nil {
907 return fmt.Errorf("cannot update -admin of own user")
908 }
909
910 if err := dc.user.updateUser(ctx, &record); err != nil {
911 return err
912 }
913
914 sendServicePRIVMSG(dc, fmt.Sprintf("updated user %q", dc.user.Username))
915 }
916
917 return nil
918}
919
920func handleUserDelete(ctx context.Context, dc *downstreamConn, params []string) error {
921 if len(params) != 1 {
922 return fmt.Errorf("expected exactly one argument")
923 }
924 username := params[0]
925
926 u := dc.srv.getUser(username)
927 if u == nil {
928 return fmt.Errorf("unknown username %q", username)
929 }
930
931 u.stop()
932
933 if err := dc.srv.db.DeleteUser(ctx, u.ID); err != nil {
934 return fmt.Errorf("failed to delete user: %v", err)
935 }
936
937 sendServicePRIVMSG(dc, fmt.Sprintf("deleted user %q", username))
938 return nil
939}
940
941func handleServiceChannelStatus(ctx context.Context, dc *downstreamConn, params []string) error {
942 var defaultNetworkName string
943 if dc.network != nil {
944 defaultNetworkName = dc.network.GetName()
945 }
946
947 fs := newFlagSet()
948 networkName := fs.String("network", defaultNetworkName, "")
949
950 if err := fs.Parse(params); err != nil {
951 return err
952 }
953
954 n := 0
955
956 sendNetwork := func(net *network) {
957 var channels []*Channel
958 for _, entry := range net.channels.innerMap {
959 channels = append(channels, entry.value.(*Channel))
960 }
961
962 sort.Slice(channels, func(i, j int) bool {
963 return strings.ReplaceAll(channels[i].Name, "#", "") <
964 strings.ReplaceAll(channels[j].Name, "#", "")
965 })
966
967 for _, ch := range channels {
968 var uch *upstreamChannel
969 if net.conn != nil {
970 uch = net.conn.channels.Value(ch.Name)
971 }
972
973 name := ch.Name
974 if *networkName == "" {
975 name += "/" + net.GetName()
976 }
977
978 var status string
979 if uch != nil {
980 status = "joined"
981 } else if net.conn != nil {
982 status = "parted"
983 } else {
984 status = "disconnected"
985 }
986
987 if ch.Detached {
988 status += ", detached"
989 }
990
991 s := fmt.Sprintf("%v [%v]", name, status)
992 sendServicePRIVMSG(dc, s)
993
994 n++
995 }
996 }
997
998 if *networkName == "" {
999 for _, net := range dc.user.networks {
1000 sendNetwork(net)
1001 }
1002 } else {
1003 net := dc.user.getNetwork(*networkName)
1004 if net == nil {
1005 return fmt.Errorf("unknown network %q", *networkName)
1006 }
1007 sendNetwork(net)
1008 }
1009
1010 if n == 0 {
1011 sendServicePRIVMSG(dc, "No channel configured.")
1012 }
1013
1014 return nil
1015}
1016
1017type channelFlagSet struct {
1018 *flag.FlagSet
1019 RelayDetached, ReattachOn, DetachAfter, DetachOn *string
1020}
1021
1022func newChannelFlagSet() *channelFlagSet {
1023 fs := &channelFlagSet{FlagSet: newFlagSet()}
1024 fs.Var(stringPtrFlag{&fs.RelayDetached}, "relay-detached", "")
1025 fs.Var(stringPtrFlag{&fs.ReattachOn}, "reattach-on", "")
1026 fs.Var(stringPtrFlag{&fs.DetachAfter}, "detach-after", "")
1027 fs.Var(stringPtrFlag{&fs.DetachOn}, "detach-on", "")
1028 return fs
1029}
1030
1031func (fs *channelFlagSet) update(channel *Channel) error {
1032 if fs.RelayDetached != nil {
1033 filter, err := parseFilter(*fs.RelayDetached)
1034 if err != nil {
1035 return err
1036 }
1037 channel.RelayDetached = filter
1038 }
1039 if fs.ReattachOn != nil {
1040 filter, err := parseFilter(*fs.ReattachOn)
1041 if err != nil {
1042 return err
1043 }
1044 channel.ReattachOn = filter
1045 }
1046 if fs.DetachAfter != nil {
1047 dur, err := time.ParseDuration(*fs.DetachAfter)
1048 if err != nil || dur < 0 {
1049 return fmt.Errorf("unknown duration for -detach-after %q (duration format: 0, 300s, 22h30m, ...)", *fs.DetachAfter)
1050 }
1051 channel.DetachAfter = dur
1052 }
1053 if fs.DetachOn != nil {
1054 filter, err := parseFilter(*fs.DetachOn)
1055 if err != nil {
1056 return err
1057 }
1058 channel.DetachOn = filter
1059 }
1060 return nil
1061}
1062
1063func handleServiceChannelUpdate(ctx context.Context, dc *downstreamConn, params []string) error {
1064 if len(params) < 1 {
1065 return fmt.Errorf("expected at least one argument")
1066 }
1067 name := params[0]
1068
1069 fs := newChannelFlagSet()
1070 if err := fs.Parse(params[1:]); err != nil {
1071 return err
1072 }
1073
1074 uc, upstreamName, err := dc.unmarshalEntity(name)
1075 if err != nil {
1076 return fmt.Errorf("unknown channel %q", name)
1077 }
1078
1079 ch := uc.network.channels.Value(upstreamName)
1080 if ch == nil {
1081 return fmt.Errorf("unknown channel %q", name)
1082 }
1083
1084 if err := fs.update(ch); err != nil {
1085 return err
1086 }
1087
1088 uc.updateChannelAutoDetach(upstreamName)
1089
1090 if err := dc.srv.db.StoreChannel(ctx, uc.network.ID, ch); err != nil {
1091 return fmt.Errorf("failed to update channel: %v", err)
1092 }
1093
1094 sendServicePRIVMSG(dc, fmt.Sprintf("updated channel %q", name))
1095 return nil
1096}
1097
1098func handleServiceServerStatus(ctx context.Context, dc *downstreamConn, params []string) error {
1099 dbStats, err := dc.user.srv.db.Stats(ctx)
1100 if err != nil {
1101 return err
1102 }
1103 serverStats := dc.user.srv.Stats()
1104 sendServicePRIVMSG(dc, fmt.Sprintf("%v/%v users, %v downstreams, %v upstreams, %v networks, %v channels", serverStats.Users, dbStats.Users, serverStats.Downstreams, serverStats.Upstreams, dbStats.Networks, dbStats.Channels))
1105 return nil
1106}
1107
1108func handleServiceServerNotice(ctx context.Context, dc *downstreamConn, params []string) error {
1109 if len(params) != 1 {
1110 return fmt.Errorf("expected exactly one argument")
1111 }
1112 text := params[0]
1113
1114 dc.logger.Printf("broadcasting bouncer-wide NOTICE: %v", text)
1115
1116 broadcastMsg := &irc.Message{
1117 Prefix: servicePrefix,
1118 Command: "NOTICE",
1119 Params: []string{"$" + dc.srv.Config().Hostname, text},
1120 }
1121 var err error
1122 sent := 0
1123 total := 0
1124 dc.srv.forEachUser(func(u *user) {
1125 total++
1126 select {
1127 case <-ctx.Done():
1128 err = ctx.Err()
1129 case u.events <- eventBroadcast{broadcastMsg}:
1130 sent++
1131 }
1132 })
1133
1134 dc.logger.Printf("broadcast bouncer-wide NOTICE to %v/%v downstreams", sent, total)
1135 sendServicePRIVMSG(dc, fmt.Sprintf("sent to %v/%v downstream connections", sent, total))
1136
1137 return err
1138}
Note: See TracBrowser for help on using the repository browser.