source: code/trunk/service.go@ 313

Last change on this file since 313 was 313, checked in by contact, 5 years ago

Add network update command

The user.updateNetwork function is a bit involved because we need to
make sure that the upstream connection is closed before re-connecting
(would otherwise cause "Nick already used" errors) and that the
downstream connections' state is kept in sync.

References: https://todo.sr.ht/~emersion/soju/17

File size: 13.6 KB
Line 
1package soju
2
3import (
4 "crypto"
5 "crypto/ecdsa"
6 "crypto/ed25519"
7 "crypto/elliptic"
8 "crypto/rand"
9 "crypto/rsa"
10 "crypto/sha1"
11 "crypto/sha256"
12 "crypto/x509"
13 "crypto/x509/pkix"
14 "encoding/hex"
15 "errors"
16 "flag"
17 "fmt"
18 "io/ioutil"
19 "math/big"
20 "strings"
21 "time"
22
23 "github.com/google/shlex"
24 "golang.org/x/crypto/bcrypt"
25 "gopkg.in/irc.v3"
26)
27
28const serviceNick = "BouncerServ"
29
30var servicePrefix = &irc.Prefix{
31 Name: serviceNick,
32 User: serviceNick,
33 Host: serviceNick,
34}
35
36type serviceCommandSet map[string]*serviceCommand
37
38type serviceCommand struct {
39 usage string
40 desc string
41 handle func(dc *downstreamConn, params []string) error
42 children serviceCommandSet
43}
44
45func sendServiceNOTICE(dc *downstreamConn, text string) {
46 dc.SendMessage(&irc.Message{
47 Prefix: servicePrefix,
48 Command: "NOTICE",
49 Params: []string{dc.nick, text},
50 })
51}
52
53func sendServicePRIVMSG(dc *downstreamConn, text string) {
54 dc.SendMessage(&irc.Message{
55 Prefix: servicePrefix,
56 Command: "PRIVMSG",
57 Params: []string{dc.nick, text},
58 })
59}
60
61func handleServicePRIVMSG(dc *downstreamConn, text string) {
62 words, err := shlex.Split(text)
63 if err != nil {
64 sendServicePRIVMSG(dc, fmt.Sprintf("error: failed to parse command: %v", err))
65 return
66 }
67
68 cmd, params, err := serviceCommands.Get(words)
69 if err != nil {
70 sendServicePRIVMSG(dc, fmt.Sprintf(`error: %v (type "help" for a list of commands)`, err))
71 return
72 }
73
74 if err := cmd.handle(dc, params); err != nil {
75 sendServicePRIVMSG(dc, fmt.Sprintf("error: %v", err))
76 }
77}
78
79func (cmds serviceCommandSet) Get(params []string) (*serviceCommand, []string, error) {
80 if len(params) == 0 {
81 return nil, nil, fmt.Errorf("no command specified")
82 }
83
84 name := params[0]
85 params = params[1:]
86
87 cmd, ok := cmds[name]
88 if !ok {
89 for k := range cmds {
90 if !strings.HasPrefix(k, name) {
91 continue
92 }
93 if cmd != nil {
94 return nil, params, fmt.Errorf("command %q is ambiguous", name)
95 }
96 cmd = cmds[k]
97 }
98 }
99 if cmd == nil {
100 return nil, params, fmt.Errorf("command %q not found", name)
101 }
102
103 if len(params) == 0 || len(cmd.children) == 0 {
104 return cmd, params, nil
105 }
106 return cmd.children.Get(params)
107}
108
109var serviceCommands serviceCommandSet
110
111func init() {
112 serviceCommands = serviceCommandSet{
113 "help": {
114 usage: "[command]",
115 desc: "print help message",
116 handle: handleServiceHelp,
117 },
118 "network": {
119 children: serviceCommandSet{
120 "create": {
121 usage: "-addr <addr> [-name name] [-username username] [-pass pass] [-realname realname] [-nick nick] [-connect-command command]...",
122 desc: "add a new network",
123 handle: handleServiceCreateNetwork,
124 },
125 "status": {
126 desc: "show a list of saved networks and their current status",
127 handle: handleServiceNetworkStatus,
128 },
129 "update": {
130 usage: "[-addr addr] [-name name] [-username username] [-pass pass] [-realname realname] [-nick nick] [-connect-command command]...",
131 desc: "update a network",
132 handle: handleServiceNetworkUpdate,
133 },
134 "delete": {
135 usage: "<name>",
136 desc: "delete a network",
137 handle: handleServiceNetworkDelete,
138 },
139 },
140 },
141 "certfp": {
142 children: serviceCommandSet{
143 "generate": {
144 usage: "[-key-type rsa|ecdsa|ed25519] [-bits N] <network name>",
145 desc: "generate a new self-signed certificate, defaults to using RSA-3072 key",
146 handle: handleServiceCertfpGenerate,
147 },
148 "fingerprint": {
149 usage: "<network name>",
150 desc: "show fingerprints of certificate associated with the network",
151 handle: handleServiceCertfpFingerprints,
152 },
153 "reset": {
154 usage: "<network name>",
155 desc: "disable SASL EXTERNAL authentication and remove stored certificate",
156 handle: handleServiceCertfpReset,
157 },
158 },
159 },
160 "change-password": {
161 usage: "<new password>",
162 desc: "change your password",
163 handle: handlePasswordChange,
164 },
165 }
166}
167
168func handleServiceCertfpGenerate(dc *downstreamConn, params []string) error {
169 fs := newFlagSet()
170 keyType := fs.String("key-type", "rsa", "key type to generate (rsa, ecdsa, ed25519)")
171 bits := fs.Int("bits", 3072, "size of key to generate, meaningful only for RSA")
172
173 if err := fs.Parse(params); err != nil {
174 return err
175 }
176
177 if len(fs.Args()) != 1 {
178 return errors.New("exactly one argument is required")
179 }
180
181 net := dc.user.getNetwork(fs.Arg(0))
182 if net == nil {
183 return fmt.Errorf("unknown network %q", fs.Arg(0))
184 }
185
186 var (
187 privKey crypto.PrivateKey
188 pubKey crypto.PublicKey
189 )
190 switch *keyType {
191 case "rsa":
192 key, err := rsa.GenerateKey(rand.Reader, *bits)
193 if err != nil {
194 return err
195 }
196 privKey = key
197 pubKey = key.Public()
198 case "ecdsa":
199 key, err := ecdsa.GenerateKey(elliptic.P521(), rand.Reader)
200 if err != nil {
201 return err
202 }
203 privKey = key
204 pubKey = key.Public()
205 case "ed25519":
206 var err error
207 pubKey, privKey, err = ed25519.GenerateKey(rand.Reader)
208 if err != nil {
209 return err
210 }
211 }
212
213 // Using PKCS#8 allows easier extension for new key types.
214 privKeyBytes, err := x509.MarshalPKCS8PrivateKey(privKey)
215 if err != nil {
216 return err
217 }
218
219 notBefore := time.Now()
220 // Lets make a fair assumption nobody will use the same cert for more than 20 years...
221 notAfter := notBefore.Add(24 * time.Hour * 365 * 20)
222 serialNumberLimit := new(big.Int).Lsh(big.NewInt(1), 128)
223 serialNumber, err := rand.Int(rand.Reader, serialNumberLimit)
224 if err != nil {
225 return err
226 }
227 cert := &x509.Certificate{
228 SerialNumber: serialNumber,
229 Subject: pkix.Name{CommonName: "soju auto-generated certificate"},
230 NotBefore: notBefore,
231 NotAfter: notAfter,
232 KeyUsage: x509.KeyUsageKeyEncipherment | x509.KeyUsageDigitalSignature,
233 ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageClientAuth},
234 }
235 derBytes, err := x509.CreateCertificate(rand.Reader, cert, cert, pubKey, privKey)
236 if err != nil {
237 return err
238 }
239
240 net.SASL.External.CertBlob = derBytes
241 net.SASL.External.PrivKeyBlob = privKeyBytes
242 net.SASL.Mechanism = "EXTERNAL"
243
244 if err := dc.srv.db.StoreNetwork(net.Username, &net.Network); err != nil {
245 return err
246 }
247
248 sendServicePRIVMSG(dc, "certificate generated")
249
250 sha1Sum := sha1.Sum(derBytes)
251 sendServicePRIVMSG(dc, "SHA-1 fingerprint: "+hex.EncodeToString(sha1Sum[:]))
252 sha256Sum := sha256.Sum256(derBytes)
253 sendServicePRIVMSG(dc, "SHA-256 fingerprint: "+hex.EncodeToString(sha256Sum[:]))
254
255 return nil
256}
257
258func handleServiceCertfpFingerprints(dc *downstreamConn, params []string) error {
259 if len(params) != 1 {
260 return fmt.Errorf("expected exactly one argument")
261 }
262
263 net := dc.user.getNetwork(params[0])
264 if net == nil {
265 return fmt.Errorf("unknown network %q", params[0])
266 }
267
268 sha1Sum := sha1.Sum(net.SASL.External.CertBlob)
269 sendServicePRIVMSG(dc, "SHA-1 fingerprint: "+hex.EncodeToString(sha1Sum[:]))
270 sha256Sum := sha256.Sum256(net.SASL.External.CertBlob)
271 sendServicePRIVMSG(dc, "SHA-256 fingerprint: "+hex.EncodeToString(sha256Sum[:]))
272 return nil
273}
274
275func handleServiceCertfpReset(dc *downstreamConn, params []string) error {
276 if len(params) != 1 {
277 return fmt.Errorf("expected exactly one argument")
278 }
279
280 net := dc.user.getNetwork(params[0])
281 if net == nil {
282 return fmt.Errorf("unknown network %q", params[0])
283 }
284
285 net.SASL.External.CertBlob = nil
286 net.SASL.External.PrivKeyBlob = nil
287
288 if net.SASL.Mechanism == "EXTERNAL" {
289 net.SASL.Mechanism = ""
290 }
291 if err := dc.srv.db.StoreNetwork(dc.user.Username, &net.Network); err != nil {
292 return err
293 }
294
295 sendServicePRIVMSG(dc, "certificate reset")
296 return nil
297}
298
299func appendServiceCommandSetHelp(cmds serviceCommandSet, prefix []string, l *[]string) {
300 for name, cmd := range cmds {
301 words := append(prefix, name)
302 if len(cmd.children) == 0 {
303 s := strings.Join(words, " ")
304 *l = append(*l, s)
305 } else {
306 appendServiceCommandSetHelp(cmd.children, words, l)
307 }
308 }
309}
310
311func handleServiceHelp(dc *downstreamConn, params []string) error {
312 if len(params) > 0 {
313 cmd, rest, err := serviceCommands.Get(params)
314 if err != nil {
315 return err
316 }
317 words := params[:len(params)-len(rest)]
318
319 if len(cmd.children) > 0 {
320 var l []string
321 appendServiceCommandSetHelp(cmd.children, words, &l)
322 sendServicePRIVMSG(dc, "available commands: "+strings.Join(l, ", "))
323 } else {
324 text := strings.Join(words, " ")
325 if cmd.usage != "" {
326 text += " " + cmd.usage
327 }
328 text += ": " + cmd.desc
329
330 sendServicePRIVMSG(dc, text)
331 }
332 } else {
333 var l []string
334 appendServiceCommandSetHelp(serviceCommands, nil, &l)
335 sendServicePRIVMSG(dc, "available commands: "+strings.Join(l, ", "))
336 }
337 return nil
338}
339
340func newFlagSet() *flag.FlagSet {
341 fs := flag.NewFlagSet("", flag.ContinueOnError)
342 fs.SetOutput(ioutil.Discard)
343 return fs
344}
345
346type stringSliceFlag []string
347
348func (v *stringSliceFlag) String() string {
349 return fmt.Sprint([]string(*v))
350}
351
352func (v *stringSliceFlag) Set(s string) error {
353 *v = append(*v, s)
354 return nil
355}
356
357// stringPtrFlag is a flag value populating a string pointer. This allows to
358// disambiguate between a flag that hasn't been set and a flag that has been
359// set to an empty string.
360type stringPtrFlag struct {
361 ptr **string
362}
363
364func (f stringPtrFlag) String() string {
365 if *f.ptr == nil {
366 return ""
367 }
368 return **f.ptr
369}
370
371func (f stringPtrFlag) Set(s string) error {
372 *f.ptr = &s
373 return nil
374}
375
376type networkFlagSet struct {
377 *flag.FlagSet
378 Addr, Name, Nick, Username, Pass, Realname *string
379 ConnectCommands []string
380}
381
382func newNetworkFlagSet() *networkFlagSet {
383 fs := &networkFlagSet{FlagSet: newFlagSet()}
384 fs.Var(stringPtrFlag{&fs.Addr}, "addr", "")
385 fs.Var(stringPtrFlag{&fs.Name}, "name", "")
386 fs.Var(stringPtrFlag{&fs.Nick}, "nick", "")
387 fs.Var(stringPtrFlag{&fs.Username}, "username", "")
388 fs.Var(stringPtrFlag{&fs.Pass}, "pass", "")
389 fs.Var(stringPtrFlag{&fs.Realname}, "realname", "")
390 fs.Var((*stringSliceFlag)(&fs.ConnectCommands), "connect-command", "")
391 return fs
392}
393
394func (fs *networkFlagSet) update(network *Network) error {
395 if fs.Addr != nil {
396 if addrParts := strings.SplitN(*fs.Addr, "://", 2); len(addrParts) == 2 {
397 scheme := addrParts[0]
398 switch scheme {
399 case "ircs", "irc+insecure":
400 default:
401 return fmt.Errorf("unknown scheme %q (supported schemes: ircs, irc+insecure)", scheme)
402 }
403 }
404 network.Addr = *fs.Addr
405 }
406 if fs.Name != nil {
407 network.Name = *fs.Name
408 }
409 if fs.Nick != nil {
410 network.Nick = *fs.Nick
411 }
412 if fs.Username != nil {
413 network.Username = *fs.Username
414 }
415 if fs.Pass != nil {
416 network.Pass = *fs.Pass
417 }
418 if fs.Realname != nil {
419 network.Realname = *fs.Realname
420 }
421 if fs.ConnectCommands != nil {
422 if len(fs.ConnectCommands) == 1 && fs.ConnectCommands[0] == "" {
423 network.ConnectCommands = nil
424 } else {
425 for _, command := range fs.ConnectCommands {
426 _, err := irc.ParseMessage(command)
427 if err != nil {
428 return fmt.Errorf("flag -connect-command must be a valid raw irc command string: %q: %v", command, err)
429 }
430 }
431 network.ConnectCommands = fs.ConnectCommands
432 }
433 }
434 return nil
435}
436
437func handleServiceCreateNetwork(dc *downstreamConn, params []string) error {
438 fs := newNetworkFlagSet()
439 if err := fs.Parse(params); err != nil {
440 return err
441 }
442 if fs.Addr == nil {
443 return fmt.Errorf("flag -addr is required")
444 }
445
446 record := &Network{
447 Addr: *fs.Addr,
448 Nick: dc.nick,
449 }
450 if err := fs.update(record); err != nil {
451 return err
452 }
453
454 network, err := dc.user.createNetwork(record)
455 if err != nil {
456 return fmt.Errorf("could not create network: %v", err)
457 }
458
459 sendServicePRIVMSG(dc, fmt.Sprintf("created network %q", network.GetName()))
460 return nil
461}
462
463func handleServiceNetworkStatus(dc *downstreamConn, params []string) error {
464 dc.user.forEachNetwork(func(net *network) {
465 var statuses []string
466 var details string
467 if uc := net.conn; uc != nil {
468 if dc.nick != uc.nick {
469 statuses = append(statuses, "connected as "+uc.nick)
470 } else {
471 statuses = append(statuses, "connected")
472 }
473 details = fmt.Sprintf("%v channels", len(uc.channels))
474 } else {
475 statuses = append(statuses, "disconnected")
476 if net.lastError != nil {
477 details = net.lastError.Error()
478 }
479 }
480
481 if net == dc.network {
482 statuses = append(statuses, "current")
483 }
484
485 name := net.GetName()
486 if name != net.Addr {
487 name = fmt.Sprintf("%v (%v)", name, net.Addr)
488 }
489
490 s := fmt.Sprintf("%v [%v]", name, strings.Join(statuses, ", "))
491 if details != "" {
492 s += ": " + details
493 }
494 sendServicePRIVMSG(dc, s)
495 })
496 return nil
497}
498
499func handleServiceNetworkUpdate(dc *downstreamConn, params []string) error {
500 if len(params) < 1 {
501 return fmt.Errorf("expected exactly one argument")
502 }
503
504 fs := newNetworkFlagSet()
505 if err := fs.Parse(params[1:]); err != nil {
506 return err
507 }
508
509 net := dc.user.getNetwork(params[0])
510 if net == nil {
511 return fmt.Errorf("unknown network %q", params[0])
512 }
513
514 record := net.Network // copy network record because we'll mutate it
515 if err := fs.update(&record); err != nil {
516 return err
517 }
518
519 network, err := dc.user.updateNetwork(&record)
520 if err != nil {
521 return fmt.Errorf("could not update network: %v", err)
522 }
523
524 sendServicePRIVMSG(dc, fmt.Sprintf("updated network %q", network.GetName()))
525 return nil
526}
527
528func handleServiceNetworkDelete(dc *downstreamConn, params []string) error {
529 if len(params) != 1 {
530 return fmt.Errorf("expected exactly one argument")
531 }
532
533 net := dc.user.getNetwork(params[0])
534 if net == nil {
535 return fmt.Errorf("unknown network %q", params[0])
536 }
537
538 if err := dc.user.deleteNetwork(net.ID); err != nil {
539 return err
540 }
541
542 sendServicePRIVMSG(dc, fmt.Sprintf("deleted network %q", net.GetName()))
543 return nil
544}
545
546func handlePasswordChange(dc *downstreamConn, params []string) error {
547 if len(params) != 1 {
548 return fmt.Errorf("expected exactly one argument")
549 }
550
551 hashed, err := bcrypt.GenerateFromPassword([]byte(params[0]), bcrypt.DefaultCost)
552 if err != nil {
553 return fmt.Errorf("failed to hash password: %v", err)
554 }
555 if err := dc.user.updatePassword(string(hashed)); err != nil {
556 return err
557 }
558
559 sendServicePRIVMSG(dc, "password updated")
560 return nil
561}
Note: See TracBrowser for help on using the repository browser.