diff options
| author | Adam <Adam@anope.org> | 2011-04-03 18:07:58 -0400 |
|---|---|---|
| committer | Adam <Adam@anope.org> | 2011-04-03 18:07:58 -0400 |
| commit | 905207093b89a3c71ee3732d051555870c4d39f5 (patch) | |
| tree | f940bf01272cae4a118a30e0701200e0f55a68fd /modules/core | |
| parent | d1328d876a988329b3bdeb94999cfd696e6aa7a5 (diff) | |
Made LDAP support recover, release, resetpass, etc.
Diffstat (limited to 'modules/core')
| -rw-r--r-- | modules/core/enc_md5.cpp | 28 | ||||
| -rw-r--r-- | modules/core/enc_none.cpp | 28 | ||||
| -rw-r--r-- | modules/core/enc_old.cpp | 28 | ||||
| -rw-r--r-- | modules/core/enc_sha1.cpp | 29 | ||||
| -rw-r--r-- | modules/core/enc_sha256.cpp | 31 | ||||
| -rw-r--r-- | modules/core/ns_ghost.cpp | 56 | ||||
| -rw-r--r-- | modules/core/ns_group.cpp | 23 | ||||
| -rw-r--r-- | modules/core/ns_identify.cpp | 24 | ||||
| -rw-r--r-- | modules/core/ns_recover.cpp | 18 | ||||
| -rw-r--r-- | modules/core/ns_release.cpp | 17 |
10 files changed, 177 insertions, 105 deletions
diff --git a/modules/core/enc_md5.cpp b/modules/core/enc_md5.cpp index a57ed86ad..0cf38e4fb 100644 --- a/modules/core/enc_md5.cpp +++ b/modules/core/enc_md5.cpp @@ -320,9 +320,8 @@ class EMD5 : public Module this->SetAuthor("Anope"); this->SetType(ENCRYPTION); - ModuleManager::Attach(I_OnEncrypt, this); - ModuleManager::Attach(I_OnDecrypt, this); - ModuleManager::Attach(I_OnCheckPassword, this); + Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication }; + ModuleManager::Attach(i, this, 3); } EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) @@ -348,22 +347,33 @@ class EMD5 : public Module return EVENT_STOP; } - EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password) + EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> ¶ms, const Anope::string &account, const Anope::string &password) { - if (!hashm.equals_cs("md5")) + NickAlias *na = findnick(account); + NickCore *nc = na ? na->nc : NULL; + if (na == NULL) + return EVENT_CONTINUE; + + size_t pos = nc->pass.find(':'); + if (pos == Anope::string::npos) + return EVENT_CONTINUE; + Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos); + if (!hash_method.equals_cs("md5")) return EVENT_CONTINUE; + Anope::string buf; - this->OnEncrypt(plaintext, buf); - if (password.equals_cs(buf)) + this->OnEncrypt(password, buf); + if (nc->pass.equals_cs(buf)) { /* if we are NOT the first module in the list, * we want to re-encrypt the pass with the new encryption */ if (!this->name.equals_ci(Config->EncModuleList.front())) - enc_encrypt(plaintext, password); + enc_encrypt(password, nc->pass); return EVENT_ALLOW; } - return EVENT_STOP; + + return EVENT_CONTINUE; } }; diff --git a/modules/core/enc_none.cpp b/modules/core/enc_none.cpp index 79c047c3f..c1b403235 100644 --- a/modules/core/enc_none.cpp +++ b/modules/core/enc_none.cpp @@ -17,9 +17,8 @@ class ENone : public Module this->SetAuthor("Anope"); this->SetType(ENCRYPTION); - ModuleManager::Attach(I_OnEncrypt, this); - ModuleManager::Attach(I_OnDecrypt, this); - ModuleManager::Attach(I_OnCheckPassword, this); + Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication }; + ModuleManager::Attach(i, this, 3); } EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) @@ -43,22 +42,33 @@ class ENone : public Module return EVENT_ALLOW; } - EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password) + EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> ¶ms, const Anope::string &account, const Anope::string &password) { - if (!hashm.equals_cs("plain")) + NickAlias *na = findnick(account); + NickCore *nc = na ? na->nc : NULL; + if (na == NULL) + return EVENT_CONTINUE; + + size_t pos = nc->pass.find(':'); + if (pos == Anope::string::npos) return EVENT_CONTINUE; + Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos); + if (!hash_method.equals_cs("plain")) + return EVENT_CONTINUE; + Anope::string buf; - this->OnEncrypt(plaintext, buf); - if (password.equals_cs(buf)) + this->OnEncrypt(password, buf); + if (nc->pass.equals_cs(buf)) { /* if we are NOT the first module in the list, * we want to re-encrypt the pass with the new encryption */ if (!this->name.equals_ci(Config->EncModuleList.front())) - enc_encrypt(plaintext, password); + enc_encrypt(password, nc->pass); return EVENT_ALLOW; } - return EVENT_STOP; + + return EVENT_CONTINUE; } }; diff --git a/modules/core/enc_old.cpp b/modules/core/enc_old.cpp index 52ba4734c..5fb863110 100644 --- a/modules/core/enc_old.cpp +++ b/modules/core/enc_old.cpp @@ -325,9 +325,8 @@ class EOld : public Module this->SetAuthor("Anope"); this->SetType(ENCRYPTION); - ModuleManager::Attach(I_OnEncrypt, this); - ModuleManager::Attach(I_OnDecrypt, this); - ModuleManager::Attach(I_OnCheckPassword, this); + Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication }; + ModuleManager::Attach(i, this, 3); } EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) @@ -358,22 +357,33 @@ class EOld : public Module return EVENT_STOP; } - EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password) + EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> ¶ms, const Anope::string &account, const Anope::string &password) { - if (!hashm.equals_cs("oldmd5")) + NickAlias *na = findnick(account); + NickCore *nc = na ? na->nc : NULL; + if (na == NULL) + return EVENT_CONTINUE; + + size_t pos = nc->pass.find(':'); + if (pos == Anope::string::npos) + return EVENT_CONTINUE; + Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos); + if (!hash_method.equals_cs("oldmd5")) return EVENT_CONTINUE; + Anope::string buf; - this->OnEncrypt(plaintext, buf); - if (password.equals_cs(buf)) + this->OnEncrypt(password, buf); + if (nc->pass.equals_cs(buf)) { /* if we are NOT the first module in the list, * we want to re-encrypt the pass with the new encryption */ if (!this->name.equals_ci(Config->EncModuleList.front())) - enc_encrypt(plaintext, password); + enc_encrypt(password, nc->pass); return EVENT_ALLOW; } - return EVENT_STOP; + + return EVENT_CONTINUE; } }; diff --git a/modules/core/enc_sha1.cpp b/modules/core/enc_sha1.cpp index 8dc3b57ab..8ec387d0d 100644 --- a/modules/core/enc_sha1.cpp +++ b/modules/core/enc_sha1.cpp @@ -173,10 +173,8 @@ class ESHA1 : public Module this->SetAuthor("Anope"); this->SetType(ENCRYPTION); - ModuleManager::Attach(I_OnEncrypt, this); - ModuleManager::Attach(I_OnEncryptCheckLen, this); - ModuleManager::Attach(I_OnDecrypt, this); - ModuleManager::Attach(I_OnCheckPassword, this); + Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication }; + ModuleManager::Attach(i, this, 3); } EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) @@ -202,22 +200,33 @@ class ESHA1 : public Module return EVENT_STOP; } - EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password) + EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> ¶ms, const Anope::string &account, const Anope::string &password) { - if (!hashm.equals_cs("sha1")) + NickAlias *na = findnick(account); + NickCore *nc = na ? na->nc : NULL; + if (na == NULL) + return EVENT_CONTINUE; + + size_t pos = nc->pass.find(':'); + if (pos == Anope::string::npos) + return EVENT_CONTINUE; + Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos); + if (!hash_method.equals_cs("sha1")) return EVENT_CONTINUE; + Anope::string buf; - this->OnEncrypt(plaintext, buf); - if (password.equals_cs(buf)) + this->OnEncrypt(password, buf); + if (nc->pass.equals_cs(buf)) { /* when we are NOT the first module in the list, * we want to re-encrypt the pass with the new encryption */ if (!this->name.equals_ci(Config->EncModuleList.front())) - enc_encrypt(plaintext, password); + enc_encrypt(password, nc->pass); return EVENT_ALLOW; } - return EVENT_STOP; + + return EVENT_CONTINUE; } }; diff --git a/modules/core/enc_sha256.cpp b/modules/core/enc_sha256.cpp index 45fc3433c..06154ada0 100644 --- a/modules/core/enc_sha256.cpp +++ b/modules/core/enc_sha256.cpp @@ -252,9 +252,8 @@ class ESHA256 : public Module this->SetAuthor("Anope"); this->SetType(ENCRYPTION); - ModuleManager::Attach(I_OnEncrypt, this); - ModuleManager::Attach(I_OnDecrypt, this); - ModuleManager::Attach(I_OnCheckPassword, this); + Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication }; + ModuleManager::Attach(i, this, 3); use_iv = false; } @@ -287,26 +286,36 @@ class ESHA256 : public Module return EVENT_STOP; } - EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password) + EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> ¶ms, const Anope::string &account, const Anope::string &password) { - if (!hashm.equals_cs("sha256")) + NickAlias *na = findnick(account); + NickCore *nc = na ? na->nc : NULL; + if (na == NULL) + return EVENT_CONTINUE; + + size_t pos = nc->pass.find(':'); + if (pos == Anope::string::npos) + return EVENT_CONTINUE; + Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos); + if (!hash_method.equals_cs("sha256")) return EVENT_CONTINUE; - Anope::string buf; - GetIVFromPass(password); + GetIVFromPass(nc->pass); use_iv = true; - this->OnEncrypt(plaintext, buf); + Anope::string buf; + this->OnEncrypt(password, buf); - if (password.equals_cs(buf)) + if (nc->pass.equals_cs(buf)) { /* if we are NOT the first module in the list, * we want to re-encrypt the pass with the new encryption */ if (!this->name.equals_ci(Config->EncModuleList.front())) - enc_encrypt(plaintext, password); + enc_encrypt(password, nc->pass); return EVENT_ALLOW; } - return EVENT_STOP; + + return EVENT_CONTINUE; } }; diff --git a/modules/core/ns_ghost.cpp b/modules/core/ns_ghost.cpp index dbc11e5f6..d8e0faf64 100644 --- a/modules/core/ns_ghost.cpp +++ b/modules/core/ns_ghost.cpp @@ -25,7 +25,7 @@ class CommandNSGhost : public Command CommandReturn Execute(CommandSource &source, const std::vector<Anope::string> ¶ms) { const Anope::string &nick = params[0]; - Anope::string pass = params.size() > 1 ? params[1] : ""; + const Anope::string &pass = params.size() > 1 ? params[1] : ""; User *u = source.u; User *user = finduser(nick); @@ -41,28 +41,46 @@ class CommandNSGhost : public Command source.Reply(_(NICK_X_SUSPENDED), na->nick.c_str()); else if (nick.equals_ci(u->nick)) source.Reply(_("You can't ghost yourself!")); - else if ((u->Account() == na->nc || (!na->nc->HasFlag(NI_SECURE) && is_on_access(u, na->nc))) || - (!pass.empty() && enc_check_password(pass, na->nc->pass) == 1) || - (!u->fingerprint.empty() && na->nc->FindCert(u->fingerprint))) + else { - if (!user->IsIdentified() && FindCommand(NickServ, "RECOVER")) - source.Reply(_("You may not ghost an unidentified user, use RECOVER instead.")); - else + bool ok = false; + if (u->Account() == na->nc) + ok = true; + else if (!na->nc->HasFlag(NI_SECURE) && is_on_access(u, na->nc)) + ok = true; + else if (!u->fingerprint.empty() && na->nc->FindCert(u->fingerprint)) + ok = true; + else if (!pass.empty()) { - Log(LOG_COMMAND, u, this) << "for " << nick; - Anope::string buf = "GHOST command used by " + u->nick; - kill_user(Config->s_NickServ, user, buf); - source.Reply(_("Ghost with your nick has been killed."), nick.c_str()); + EventReturn MOD_RESULT; + FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, na->nc->display, pass)); + if (MOD_RESULT == EVENT_STOP) + return MOD_CONT; + else if (MOD_RESULT == EVENT_ALLOW) + ok = true; } - } - else - { - source.Reply(_(ACCESS_DENIED)); - if (!pass.empty()) + + if (ok) + { + if (!user->IsIdentified() && FindCommand(NickServ, "RECOVER")) + source.Reply(_("You may not ghost an unidentified user, use RECOVER instead.")); + else + { + Log(LOG_COMMAND, u, this) << "for " << nick; + Anope::string buf = "GHOST command used by " + u->nick; + kill_user(Config->s_NickServ, user, buf); + source.Reply(_("Ghost with your nick has been killed."), nick.c_str()); + } + } + else { - Log(LOG_COMMAND, u, this) << "with an invalid password for " << nick; - if (bad_password(u)) - return MOD_STOP; + source.Reply(_(ACCESS_DENIED)); + if (!pass.empty()) + { + Log(LOG_COMMAND, u, this) << "with an invalid password for " << nick; + if (bad_password(u)) + return MOD_STOP; + } } } diff --git a/modules/core/ns_group.cpp b/modules/core/ns_group.cpp index 4b0fda4c4..463d36be6 100644 --- a/modules/core/ns_group.cpp +++ b/modules/core/ns_group.cpp @@ -27,7 +27,7 @@ class CommandNSGroup : public Command User *u = source.u; const Anope::string &nick = params[0]; - Anope::string pass = params.size() > 1 ? params[1] : ""; + const Anope::string &pass = params.size() > 1 ? params[1] : ""; if (readonly) { @@ -82,8 +82,19 @@ class CommandNSGroup : public Command "for more information."), target->nick.c_str(), Config->UseStrictPrivMsgString.c_str(), Config->s_NickServ.c_str(), Config->UseStrictPrivMsgString.c_str(), Config->s_NickServ.c_str()); else { - if ((!pass.empty() && enc_check_password(pass, target->nc->pass)) || - (!u->fingerprint.empty() && target->nc->FindCert(u->fingerprint))) + bool ok = false; + if (!u->fingerprint.empty() && target->nc->FindCert(u->fingerprint)) + ok = true; + else if (!pass.empty()) + { + EventReturn MOD_RESULT; + FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, target->nc->display, pass)); + if (MOD_RESULT == EVENT_STOP) + return MOD_CONT; + else if (MOD_RESULT == EVENT_ALLOW) + ok = true; + } + if (ok) { /* If the nick is already registered, drop it. * If not, check that it is valid. @@ -122,13 +133,9 @@ class CommandNSGroup : public Command check_memos(u); } - else if (pass.empty()) - { - this->OnSyntaxError(source, ""); - } else { - Log(LOG_COMMAND, u, this) << "failed group for " << target->nick << " (invalid password)"; + Log(LOG_COMMAND, u, this) << "failed group for " << target->nick; source.Reply(_(PASSWORD_INCORRECT)); if (bad_password(u)) return MOD_STOP; diff --git a/modules/core/ns_identify.cpp b/modules/core/ns_identify.cpp index 742fe986a..15f2ade94 100644 --- a/modules/core/ns_identify.cpp +++ b/modules/core/ns_identify.cpp @@ -30,30 +30,28 @@ class CommandNSIdentify : public Command Anope::string pass = params[params.size() - 1]; NickAlias *na = findnick(nick); - if (!na) - source.Reply(_(NICK_NOT_REGISTERED)); - else if (na->HasFlag(NS_FORBIDDEN)) + if (na && na->HasFlag(NS_FORBIDDEN)) source.Reply(_(NICK_X_FORBIDDEN), na->nick.c_str()); - else if (na->nc->HasFlag(NI_SUSPENDED)) + else if (na && na->nc->HasFlag(NI_SUSPENDED)) source.Reply(_(NICK_X_SUSPENDED), na->nick.c_str()); - /* You can now identify for other nicks without logging out first, - * however you can not identify again for the group you're already - * identified as - */ - else if (u->Account() && u->Account() == na->nc) + else if (u->Account() && na && u->Account() == na->nc) source.Reply(_("You are already identified.")); else { - int res = enc_check_password(pass, na->nc->pass); - if (!res) + EventReturn MOD_RESULT; + FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, nick, pass)); + if (MOD_RESULT == EVENT_STOP) + return MOD_CONT; + + if (!na) + source.Reply(_(NICK_X_NOT_REGISTERED), nick.c_str()); + else if (MOD_RESULT != EVENT_ALLOW) { Log(LOG_COMMAND, u, this) << "and failed to identify"; source.Reply(_(PASSWORD_INCORRECT)); if (bad_password(u)) return MOD_STOP; } - else if (res == -1) - source.Reply(_("Sorry, identification failed.")); else { if (u->IsIdentified()) diff --git a/modules/core/ns_recover.cpp b/modules/core/ns_recover.cpp index 416b0e184..d78955f51 100644 --- a/modules/core/ns_recover.cpp +++ b/modules/core/ns_recover.cpp @@ -27,7 +27,7 @@ class CommandNSRecover : public Command User *u = source.u; const Anope::string &nick = params[0]; - Anope::string pass = params.size() > 1 ? params[1] : ""; + const Anope::string &pass = params.size() > 1 ? params[1] : ""; NickAlias *na; User *u2; @@ -43,9 +43,12 @@ class CommandNSRecover : public Command source.Reply(_("You can't recover yourself!")); else if (!pass.empty()) { - int res = enc_check_password(pass, na->nc->pass); + EventReturn MOD_RESULT; + FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, na->nc->display, pass)); + if (MOD_RESULT == EVENT_STOP) + return MOD_CONT; - if (res == 1) + if (MOD_RESULT == EVENT_ALLOW) { u2->SendMessage(NickServ, _(FORCENICKCHANGE_NOW)); u2->Collide(na); @@ -58,12 +61,9 @@ class CommandNSRecover : public Command else { source.Reply(_(ACCESS_DENIED)); - if (!res) - { - Log(LOG_COMMAND, u, this) << "with invalid password for " << nick; - if (bad_password(u)) - return MOD_STOP; - } + Log(LOG_COMMAND, u, this) << "with invalid password for " << nick; + if (bad_password(u)) + return MOD_STOP; } } else diff --git a/modules/core/ns_release.cpp b/modules/core/ns_release.cpp index 94a778218..94126eef8 100644 --- a/modules/core/ns_release.cpp +++ b/modules/core/ns_release.cpp @@ -39,8 +39,12 @@ class CommandNSRelease : public Command source.Reply(_("Nick \002%s\002 isn't being held."), nick.c_str()); else if (!pass.empty()) { - int res = enc_check_password(pass, na->nc->pass); - if (res == 1) + EventReturn MOD_RESULT; + FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, na->nc->display, pass)); + if (MOD_RESULT == EVENT_STOP) + return MOD_CONT; + + if (MOD_RESULT == EVENT_ALLOW) { Log(LOG_COMMAND, u, this) << "released " << na->nick; na->Release(); @@ -49,12 +53,9 @@ class CommandNSRelease : public Command else { source.Reply(_(ACCESS_DENIED)); - if (!res) - { - Log(LOG_COMMAND, u, this) << "invalid password for " << nick; - if (bad_password(u)) - return MOD_STOP; - } + Log(LOG_COMMAND, u, this) << "invalid password for " << nick; + if (bad_password(u)) + return MOD_STOP; } } else |
