summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAdam <adam@sigterm.info>2016-09-13 17:46:12 -0400
committerGitHub <noreply@github.com>2016-09-13 17:46:12 -0400
commita6b14a9fb6afc5e16874ed7e4c0a135a4f5bfa53 (patch)
treedcb6ec77e491bfe3934bd171c66add711d199670
parentc4ebf02bce968e4846a0be72dfa7b104f21f5166 (diff)
parentae334addd024c11bb063704640d04cfd5f32bdce (diff)
Merge pull request #157 from SaberUK/master+require-encryption
Prevent using enc_none as the main encryption module.
-rw-r--r--data/anope.example.conf9
-rw-r--r--data/nickserv.example.conf16
-rw-r--r--include/anope.h8
-rw-r--r--include/event.h9
-rw-r--r--modules/encryption/none.cpp15
-rw-r--r--modules/nickserv/getpass.cpp82
-rw-r--r--modules/nickserv/register.cpp4
-rw-r--r--modules/nickserv/set.cpp10
-rw-r--r--src/misc.cpp17
9 files changed, 11 insertions, 159 deletions
diff --git a/data/anope.example.conf b/data/anope.example.conf
index 7724c8125..1d5dca213 100644
--- a/data/anope.example.conf
+++ b/data/anope.example.conf
@@ -731,7 +731,7 @@ log
log
{
target = "globops"
- admin = "global/* operserv/mode operserv/kick operserv/akill operserv/s*line operserv/noop operserv/jupe operserv/oline operserv/set operserv/svsnick operserv/svsjoin operserv/svspart nickserv/getpass */drop"
+ admin = "global/* operserv/mode operserv/kick operserv/akill operserv/s*line operserv/noop operserv/jupe operserv/oline operserv/set operserv/svsnick operserv/svsjoin operserv/svspart */drop"
servers = "squit"
users = "oper"
other = "expire/* bados akill/*"
@@ -787,8 +787,7 @@ log
*
* memoserv/sendall memoserv/staff
*
- * nickserv/getpass nickserv/getemail nickserv/suspend nickserv/ajoin
- * nickserv/list
+ * nickserv/getemail nickserv/suspend nickserv/ajoin nickserv/list
*
* nickserv/saset/autoop nickserv/saset/email nickserv/saset/greet nickserv/saset/password
* nickserv/saset/display nickserv/saset/kill nickserv/saset/language nickserv/saset/message
@@ -1167,7 +1166,9 @@ module
module { name = "encryption/sha256" }
/*
- * [DEPRECATED] Deprecated encryption modules.
+ * [DEPRECATED] Deprecated encryption modules. You can only use these for compatibility with
+ * old databases and will need to load one of the above modules as your primary encryption
+ * module.
*/
#module { name = "encryption/md5" }
#module { name = "encryption/sha1" }
diff --git a/data/nickserv.example.conf b/data/nickserv.example.conf
index bc5dac89e..fcd37db71 100644
--- a/data/nickserv.example.conf
+++ b/data/nickserv.example.conf
@@ -118,8 +118,8 @@ module
expire = 21d
/*
- * Prevents the use of the ACCESS and CERT (excluding their LIST subcommand), DROP, FORBID, SUSPEND,
- * GETPASS and SET PASSWORD commands by services operators on other services operators.
+ * Prevents the use of the ACCESS and CERT (excluding their LIST subcommand), DROP, FORBID, SUSPEND
+ * and SET PASSWORD commands by services operators on other services operators.
*
* This directive is optional, but recommended.
*/
@@ -323,18 +323,6 @@ module { name = "nickserv/getemail" }
command { service = "NickServ"; name = "GETEMAIL"; command = "nickserv/getemail"; permission = "nickserv/getemail"; group = "nickserv/admin"; }
/*
- * nickserv/getpass
- *
- * Provides the command nickserv/getpass.
- *
- * Used for getting users passwords.
- *
- * Requires no encryption is being used.
- */
-#module { name = "nickserv/getpass" }
-#command { service = "NickServ"; name = "GETPASS"; command = "nickserv/getpass"; permission = "nickserv/getpass"; }
-
-/*
* nickserv/group
*
* Provides the commands nickserv/group, nickserv/glist, and nickserv/ungroup.
diff --git a/include/anope.h b/include/anope.h
index c298d5d86..f3f05cb15 100644
--- a/include/anope.h
+++ b/include/anope.h
@@ -474,14 +474,6 @@ namespace Anope
*/
extern CoreExport void Encrypt(const Anope::string &src, Anope::string &dest);
- /** Decrypts what is in 'src' to 'dest'.
- * @param src The source string to decrypt
- * @param dest The destination where the decrypted string is placed
- * @return true if decryption was successful. This is usually not the case
- * as most encryption methods we use are one way.
- */
- extern CoreExport bool Decrypt(const Anope::string &src, Anope::string &dest);
-
/** Returns a sequence of data formatted as the format argument specifies.
** After the format parameter, the function expects at least as many
** additional arguments as specified in format.
diff --git a/include/event.h b/include/event.h
index 7705e44e3..b71eef738 100644
--- a/include/event.h
+++ b/include/event.h
@@ -327,15 +327,6 @@ namespace Event
virtual EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) anope_abstract;
};
- struct CoreExport Decrypt : Events
- {
- static constexpr const char *NAME = "decrypt";
-
- using Events::Events;
-
- virtual EventReturn OnDecrypt(const Anope::string &hashm, const Anope::string &src, Anope::string &dest) anope_abstract;
- };
-
struct CoreExport CreateBot : Events
{
static constexpr const char *NAME = "createbot";
diff --git a/modules/encryption/none.cpp b/modules/encryption/none.cpp
index 317abb132..3b1f49d33 100644
--- a/modules/encryption/none.cpp
+++ b/modules/encryption/none.cpp
@@ -21,16 +21,15 @@
class ENone : public Module
, public EventHook<Event::Encrypt>
- , public EventHook<Event::Decrypt>
, public EventHook<Event::CheckAuthentication>
{
public:
ENone(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator, ENCRYPTION | VENDOR)
, EventHook<Event::Encrypt>(this)
- , EventHook<Event::Decrypt>(this)
, EventHook<Event::CheckAuthentication>(this)
{
-
+ if (ModuleManager::FindFirstOf(ENCRYPTION) == this)
+ throw ModuleException("enc_none is deprecated and can not be used as a primary encryption method");
}
EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) override
@@ -44,16 +43,6 @@ class ENone : public Module
return EVENT_ALLOW;
}
- EventReturn OnDecrypt(const Anope::string &hashm, const Anope::string &src, Anope::string &dest) override
- {
- if (!hashm.equals_cs("plain"))
- return EVENT_CONTINUE;
- size_t pos = src.find(':');
- Anope::string buf = src.substr(pos + 1);
- Anope::B64Decode(buf, dest);
- return EVENT_ALLOW;
- }
-
void OnCheckAuthentication(User *, NickServ::IdentifyRequest *req) override
{
NickServ::Nick *na = NickServ::FindNick(req->GetAccount());
diff --git a/modules/nickserv/getpass.cpp b/modules/nickserv/getpass.cpp
deleted file mode 100644
index b8f746ccc..000000000
--- a/modules/nickserv/getpass.cpp
+++ /dev/null
@@ -1,82 +0,0 @@
-/*
- * Anope IRC Services
- *
- * Copyright (C) 2003-2016 Anope Team <team@anope.org>
- *
- * This file is part of Anope. Anope is free software; you can
- * redistribute it and/or modify it under the terms of the GNU
- * General Public License as published by the Free Software
- * Foundation, version 2.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU General Public License for more details.
- *
- * You should have received a copy of the GNU General Public License
- * along with this program; if not, see see <http://www.gnu.org/licenses/>.
- */
-
-#include "module.h"
-
-class CommandNSGetPass : public Command
-{
- public:
- CommandNSGetPass(Module *creator) : Command(creator, "nickserv/getpass", 1, 1)
- {
- this->SetDesc(_("Retrieve the password for a nickname"));
- this->SetSyntax(_("\037account\037"));
- }
-
- void Execute(CommandSource &source, const std::vector<Anope::string> &params) override
- {
- const Anope::string &nick = params[0];
- Anope::string tmp_pass;
- NickServ::Nick *na = NickServ::FindNick(nick);
-
- if (!na)
- {
- source.Reply(_("\002{0}\002 isn't registered."), nick);
- return;
- }
-
- if (Config->GetModule("nickserv")->Get<bool>("secureadmins", "yes") && na->GetAccount()->IsServicesOper())
- {
- source.Reply(_("You may not get the password of other Services Operators."));
- return;
- }
-
- if (!Anope::Decrypt(na->GetAccount()->GetPassword(), tmp_pass))
- {
- source.Reply(_("The \002{0}\002 command is unavailable because encryption is in use."), source.command);
- return;
- }
-
- Log(LOG_ADMIN, source, this) << "for " << na->GetNick();
- source.Reply(_("Password of \002{0}\02 is \002%s\002."), na->GetNick(), tmp_pass);
- }
-
- bool OnHelp(CommandSource &source, const Anope::string &subcommand) override
- {
- source.Reply(_("Returns the password for the given account. This command may not be available if password encryption is in use."));
- return true;
- }
-};
-
-class NSGetPass : public Module
-{
- CommandNSGetPass commandnsgetpass;
-
- public:
- NSGetPass(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator, VENDOR)
- , commandnsgetpass(this)
- {
-
- Anope::string tmp_pass = "plain:tmp";
- if (!Anope::Decrypt(tmp_pass, tmp_pass))
- throw ModuleException("Incompatible with the encryption module being used");
-
- }
-};
-
-MODULE_INIT(NSGetPass)
diff --git a/modules/nickserv/register.cpp b/modules/nickserv/register.cpp
index 41c0e716b..f7e93c9a1 100644
--- a/modules/nickserv/register.cpp
+++ b/modules/nickserv/register.cpp
@@ -244,10 +244,6 @@ class CommandNSRegister : public Command
source.Reply(_("\002{0}\002 has been registered."), u_nick);
- Anope::string tmp_pass;
- if (Anope::Decrypt(na->GetAccount()->GetPassword(), tmp_pass))
- source.Reply(_("Your password is \002{0}\002 - remember this for later use."), tmp_pass);
-
if (nsregister.equals_ci("admin"))
{
nc->SetS<bool>("UNCONFIRMED", true);
diff --git a/modules/nickserv/set.cpp b/modules/nickserv/set.cpp
index c733f93d2..12086e801 100644
--- a/modules/nickserv/set.cpp
+++ b/modules/nickserv/set.cpp
@@ -160,10 +160,7 @@ class CommandNSSetPassword : public Command
Anope::Encrypt(param, tmp_pass);
source.nc->SetPassword(tmp_pass);
- if (Anope::Decrypt(source.nc->GetPassword(), tmp_pass))
- source.Reply(_("Password for \002{0}\002 changed to \002{1]\002."), source.nc->GetDisplay(), tmp_pass);
- else
- source.Reply(_("Password for \002{0}\002 changed."), source.nc->GetDisplay());
+ source.Reply(_("Password for \002{0}\002 changed."), source.nc->GetDisplay());
}
bool OnHelp(CommandSource &source, const Anope::string &) override
@@ -223,10 +220,7 @@ class CommandNSSASetPassword : public Command
Anope::string tmp_pass;
Anope::Encrypt(params[1], tmp_pass);
nc->SetPassword(tmp_pass);
- if (Anope::Decrypt(nc->GetPassword(), tmp_pass) == 1)
- source.Reply(_("Password for \002{0}\002 changed to \002{1}\002."), nc->GetDisplay(), tmp_pass);
- else
- source.Reply(_("Password for \002{0}\002 changed."), nc->GetDisplay());
+ source.Reply(_("Password for \002{0}\002 changed."), nc->GetDisplay());
}
bool OnHelp(CommandSource &source, const Anope::string &) override
diff --git a/src/misc.cpp b/src/misc.cpp
index f5e610133..dc8d68f43 100644
--- a/src/misc.cpp
+++ b/src/misc.cpp
@@ -492,23 +492,6 @@ void Anope::Encrypt(const Anope::string &src, Anope::string &dest)
static_cast<void>(MOD_RESULT);
}
-bool Anope::Decrypt(const Anope::string &src, Anope::string &dest)
-{
- size_t pos = src.find(':');
- if (pos == Anope::string::npos)
- {
- Log() << "Error: Anope::Decrypt() called with invalid password string (" << src << ")";
- return false;
- }
- Anope::string hashm(src.begin(), src.begin() + pos);
-
- EventReturn MOD_RESULT = EventManager::Get()->Dispatch(&Event::Decrypt::OnDecrypt, hashm, src, dest);
- if (MOD_RESULT == EVENT_ALLOW)
- return true;
-
- return false;
-}
-
Anope::string Anope::printf(const char *fmt, ...)
{
va_list args;