summaryrefslogtreecommitdiff
path: root/modules/core
diff options
context:
space:
mode:
authorAdam <Adam@anope.org>2011-04-03 18:07:58 -0400
committerAdam <Adam@anope.org>2011-04-03 18:07:58 -0400
commit905207093b89a3c71ee3732d051555870c4d39f5 (patch)
treef940bf01272cae4a118a30e0701200e0f55a68fd /modules/core
parentd1328d876a988329b3bdeb94999cfd696e6aa7a5 (diff)
Made LDAP support recover, release, resetpass, etc.
Diffstat (limited to 'modules/core')
-rw-r--r--modules/core/enc_md5.cpp28
-rw-r--r--modules/core/enc_none.cpp28
-rw-r--r--modules/core/enc_old.cpp28
-rw-r--r--modules/core/enc_sha1.cpp29
-rw-r--r--modules/core/enc_sha256.cpp31
-rw-r--r--modules/core/ns_ghost.cpp56
-rw-r--r--modules/core/ns_group.cpp23
-rw-r--r--modules/core/ns_identify.cpp24
-rw-r--r--modules/core/ns_recover.cpp18
-rw-r--r--modules/core/ns_release.cpp17
10 files changed, 177 insertions, 105 deletions
diff --git a/modules/core/enc_md5.cpp b/modules/core/enc_md5.cpp
index a57ed86ad..0cf38e4fb 100644
--- a/modules/core/enc_md5.cpp
+++ b/modules/core/enc_md5.cpp
@@ -320,9 +320,8 @@ class EMD5 : public Module
this->SetAuthor("Anope");
this->SetType(ENCRYPTION);
- ModuleManager::Attach(I_OnEncrypt, this);
- ModuleManager::Attach(I_OnDecrypt, this);
- ModuleManager::Attach(I_OnCheckPassword, this);
+ Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication };
+ ModuleManager::Attach(i, this, 3);
}
EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest)
@@ -348,22 +347,33 @@ class EMD5 : public Module
return EVENT_STOP;
}
- EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password)
+ EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> &params, const Anope::string &account, const Anope::string &password)
{
- if (!hashm.equals_cs("md5"))
+ NickAlias *na = findnick(account);
+ NickCore *nc = na ? na->nc : NULL;
+ if (na == NULL)
+ return EVENT_CONTINUE;
+
+ size_t pos = nc->pass.find(':');
+ if (pos == Anope::string::npos)
+ return EVENT_CONTINUE;
+ Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos);
+ if (!hash_method.equals_cs("md5"))
return EVENT_CONTINUE;
+
Anope::string buf;
- this->OnEncrypt(plaintext, buf);
- if (password.equals_cs(buf))
+ this->OnEncrypt(password, buf);
+ if (nc->pass.equals_cs(buf))
{
/* if we are NOT the first module in the list,
* we want to re-encrypt the pass with the new encryption
*/
if (!this->name.equals_ci(Config->EncModuleList.front()))
- enc_encrypt(plaintext, password);
+ enc_encrypt(password, nc->pass);
return EVENT_ALLOW;
}
- return EVENT_STOP;
+
+ return EVENT_CONTINUE;
}
};
diff --git a/modules/core/enc_none.cpp b/modules/core/enc_none.cpp
index 79c047c3f..c1b403235 100644
--- a/modules/core/enc_none.cpp
+++ b/modules/core/enc_none.cpp
@@ -17,9 +17,8 @@ class ENone : public Module
this->SetAuthor("Anope");
this->SetType(ENCRYPTION);
- ModuleManager::Attach(I_OnEncrypt, this);
- ModuleManager::Attach(I_OnDecrypt, this);
- ModuleManager::Attach(I_OnCheckPassword, this);
+ Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication };
+ ModuleManager::Attach(i, this, 3);
}
EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest)
@@ -43,22 +42,33 @@ class ENone : public Module
return EVENT_ALLOW;
}
- EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password)
+ EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> &params, const Anope::string &account, const Anope::string &password)
{
- if (!hashm.equals_cs("plain"))
+ NickAlias *na = findnick(account);
+ NickCore *nc = na ? na->nc : NULL;
+ if (na == NULL)
+ return EVENT_CONTINUE;
+
+ size_t pos = nc->pass.find(':');
+ if (pos == Anope::string::npos)
return EVENT_CONTINUE;
+ Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos);
+ if (!hash_method.equals_cs("plain"))
+ return EVENT_CONTINUE;
+
Anope::string buf;
- this->OnEncrypt(plaintext, buf);
- if (password.equals_cs(buf))
+ this->OnEncrypt(password, buf);
+ if (nc->pass.equals_cs(buf))
{
/* if we are NOT the first module in the list,
* we want to re-encrypt the pass with the new encryption
*/
if (!this->name.equals_ci(Config->EncModuleList.front()))
- enc_encrypt(plaintext, password);
+ enc_encrypt(password, nc->pass);
return EVENT_ALLOW;
}
- return EVENT_STOP;
+
+ return EVENT_CONTINUE;
}
};
diff --git a/modules/core/enc_old.cpp b/modules/core/enc_old.cpp
index 52ba4734c..5fb863110 100644
--- a/modules/core/enc_old.cpp
+++ b/modules/core/enc_old.cpp
@@ -325,9 +325,8 @@ class EOld : public Module
this->SetAuthor("Anope");
this->SetType(ENCRYPTION);
- ModuleManager::Attach(I_OnEncrypt, this);
- ModuleManager::Attach(I_OnDecrypt, this);
- ModuleManager::Attach(I_OnCheckPassword, this);
+ Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication };
+ ModuleManager::Attach(i, this, 3);
}
EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest)
@@ -358,22 +357,33 @@ class EOld : public Module
return EVENT_STOP;
}
- EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password)
+ EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> &params, const Anope::string &account, const Anope::string &password)
{
- if (!hashm.equals_cs("oldmd5"))
+ NickAlias *na = findnick(account);
+ NickCore *nc = na ? na->nc : NULL;
+ if (na == NULL)
+ return EVENT_CONTINUE;
+
+ size_t pos = nc->pass.find(':');
+ if (pos == Anope::string::npos)
+ return EVENT_CONTINUE;
+ Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos);
+ if (!hash_method.equals_cs("oldmd5"))
return EVENT_CONTINUE;
+
Anope::string buf;
- this->OnEncrypt(plaintext, buf);
- if (password.equals_cs(buf))
+ this->OnEncrypt(password, buf);
+ if (nc->pass.equals_cs(buf))
{
/* if we are NOT the first module in the list,
* we want to re-encrypt the pass with the new encryption
*/
if (!this->name.equals_ci(Config->EncModuleList.front()))
- enc_encrypt(plaintext, password);
+ enc_encrypt(password, nc->pass);
return EVENT_ALLOW;
}
- return EVENT_STOP;
+
+ return EVENT_CONTINUE;
}
};
diff --git a/modules/core/enc_sha1.cpp b/modules/core/enc_sha1.cpp
index 8dc3b57ab..8ec387d0d 100644
--- a/modules/core/enc_sha1.cpp
+++ b/modules/core/enc_sha1.cpp
@@ -173,10 +173,8 @@ class ESHA1 : public Module
this->SetAuthor("Anope");
this->SetType(ENCRYPTION);
- ModuleManager::Attach(I_OnEncrypt, this);
- ModuleManager::Attach(I_OnEncryptCheckLen, this);
- ModuleManager::Attach(I_OnDecrypt, this);
- ModuleManager::Attach(I_OnCheckPassword, this);
+ Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication };
+ ModuleManager::Attach(i, this, 3);
}
EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest)
@@ -202,22 +200,33 @@ class ESHA1 : public Module
return EVENT_STOP;
}
- EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password)
+ EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> &params, const Anope::string &account, const Anope::string &password)
{
- if (!hashm.equals_cs("sha1"))
+ NickAlias *na = findnick(account);
+ NickCore *nc = na ? na->nc : NULL;
+ if (na == NULL)
+ return EVENT_CONTINUE;
+
+ size_t pos = nc->pass.find(':');
+ if (pos == Anope::string::npos)
+ return EVENT_CONTINUE;
+ Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos);
+ if (!hash_method.equals_cs("sha1"))
return EVENT_CONTINUE;
+
Anope::string buf;
- this->OnEncrypt(plaintext, buf);
- if (password.equals_cs(buf))
+ this->OnEncrypt(password, buf);
+ if (nc->pass.equals_cs(buf))
{
/* when we are NOT the first module in the list,
* we want to re-encrypt the pass with the new encryption
*/
if (!this->name.equals_ci(Config->EncModuleList.front()))
- enc_encrypt(plaintext, password);
+ enc_encrypt(password, nc->pass);
return EVENT_ALLOW;
}
- return EVENT_STOP;
+
+ return EVENT_CONTINUE;
}
};
diff --git a/modules/core/enc_sha256.cpp b/modules/core/enc_sha256.cpp
index 45fc3433c..06154ada0 100644
--- a/modules/core/enc_sha256.cpp
+++ b/modules/core/enc_sha256.cpp
@@ -252,9 +252,8 @@ class ESHA256 : public Module
this->SetAuthor("Anope");
this->SetType(ENCRYPTION);
- ModuleManager::Attach(I_OnEncrypt, this);
- ModuleManager::Attach(I_OnDecrypt, this);
- ModuleManager::Attach(I_OnCheckPassword, this);
+ Implementation i[] = { I_OnEncrypt, I_OnDecrypt, I_OnCheckAuthentication };
+ ModuleManager::Attach(i, this, 3);
use_iv = false;
}
@@ -287,26 +286,36 @@ class ESHA256 : public Module
return EVENT_STOP;
}
- EventReturn OnCheckPassword(const Anope::string &hashm, Anope::string &plaintext, Anope::string &password)
+ EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> &params, const Anope::string &account, const Anope::string &password)
{
- if (!hashm.equals_cs("sha256"))
+ NickAlias *na = findnick(account);
+ NickCore *nc = na ? na->nc : NULL;
+ if (na == NULL)
+ return EVENT_CONTINUE;
+
+ size_t pos = nc->pass.find(':');
+ if (pos == Anope::string::npos)
+ return EVENT_CONTINUE;
+ Anope::string hash_method(nc->pass.begin(), nc->pass.begin() + pos);
+ if (!hash_method.equals_cs("sha256"))
return EVENT_CONTINUE;
- Anope::string buf;
- GetIVFromPass(password);
+ GetIVFromPass(nc->pass);
use_iv = true;
- this->OnEncrypt(plaintext, buf);
+ Anope::string buf;
+ this->OnEncrypt(password, buf);
- if (password.equals_cs(buf))
+ if (nc->pass.equals_cs(buf))
{
/* if we are NOT the first module in the list,
* we want to re-encrypt the pass with the new encryption
*/
if (!this->name.equals_ci(Config->EncModuleList.front()))
- enc_encrypt(plaintext, password);
+ enc_encrypt(password, nc->pass);
return EVENT_ALLOW;
}
- return EVENT_STOP;
+
+ return EVENT_CONTINUE;
}
};
diff --git a/modules/core/ns_ghost.cpp b/modules/core/ns_ghost.cpp
index dbc11e5f6..d8e0faf64 100644
--- a/modules/core/ns_ghost.cpp
+++ b/modules/core/ns_ghost.cpp
@@ -25,7 +25,7 @@ class CommandNSGhost : public Command
CommandReturn Execute(CommandSource &source, const std::vector<Anope::string> &params)
{
const Anope::string &nick = params[0];
- Anope::string pass = params.size() > 1 ? params[1] : "";
+ const Anope::string &pass = params.size() > 1 ? params[1] : "";
User *u = source.u;
User *user = finduser(nick);
@@ -41,28 +41,46 @@ class CommandNSGhost : public Command
source.Reply(_(NICK_X_SUSPENDED), na->nick.c_str());
else if (nick.equals_ci(u->nick))
source.Reply(_("You can't ghost yourself!"));
- else if ((u->Account() == na->nc || (!na->nc->HasFlag(NI_SECURE) && is_on_access(u, na->nc))) ||
- (!pass.empty() && enc_check_password(pass, na->nc->pass) == 1) ||
- (!u->fingerprint.empty() && na->nc->FindCert(u->fingerprint)))
+ else
{
- if (!user->IsIdentified() && FindCommand(NickServ, "RECOVER"))
- source.Reply(_("You may not ghost an unidentified user, use RECOVER instead."));
- else
+ bool ok = false;
+ if (u->Account() == na->nc)
+ ok = true;
+ else if (!na->nc->HasFlag(NI_SECURE) && is_on_access(u, na->nc))
+ ok = true;
+ else if (!u->fingerprint.empty() && na->nc->FindCert(u->fingerprint))
+ ok = true;
+ else if (!pass.empty())
{
- Log(LOG_COMMAND, u, this) << "for " << nick;
- Anope::string buf = "GHOST command used by " + u->nick;
- kill_user(Config->s_NickServ, user, buf);
- source.Reply(_("Ghost with your nick has been killed."), nick.c_str());
+ EventReturn MOD_RESULT;
+ FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, na->nc->display, pass));
+ if (MOD_RESULT == EVENT_STOP)
+ return MOD_CONT;
+ else if (MOD_RESULT == EVENT_ALLOW)
+ ok = true;
}
- }
- else
- {
- source.Reply(_(ACCESS_DENIED));
- if (!pass.empty())
+
+ if (ok)
+ {
+ if (!user->IsIdentified() && FindCommand(NickServ, "RECOVER"))
+ source.Reply(_("You may not ghost an unidentified user, use RECOVER instead."));
+ else
+ {
+ Log(LOG_COMMAND, u, this) << "for " << nick;
+ Anope::string buf = "GHOST command used by " + u->nick;
+ kill_user(Config->s_NickServ, user, buf);
+ source.Reply(_("Ghost with your nick has been killed."), nick.c_str());
+ }
+ }
+ else
{
- Log(LOG_COMMAND, u, this) << "with an invalid password for " << nick;
- if (bad_password(u))
- return MOD_STOP;
+ source.Reply(_(ACCESS_DENIED));
+ if (!pass.empty())
+ {
+ Log(LOG_COMMAND, u, this) << "with an invalid password for " << nick;
+ if (bad_password(u))
+ return MOD_STOP;
+ }
}
}
diff --git a/modules/core/ns_group.cpp b/modules/core/ns_group.cpp
index 4b0fda4c4..463d36be6 100644
--- a/modules/core/ns_group.cpp
+++ b/modules/core/ns_group.cpp
@@ -27,7 +27,7 @@ class CommandNSGroup : public Command
User *u = source.u;
const Anope::string &nick = params[0];
- Anope::string pass = params.size() > 1 ? params[1] : "";
+ const Anope::string &pass = params.size() > 1 ? params[1] : "";
if (readonly)
{
@@ -82,8 +82,19 @@ class CommandNSGroup : public Command
"for more information."), target->nick.c_str(), Config->UseStrictPrivMsgString.c_str(), Config->s_NickServ.c_str(), Config->UseStrictPrivMsgString.c_str(), Config->s_NickServ.c_str());
else
{
- if ((!pass.empty() && enc_check_password(pass, target->nc->pass)) ||
- (!u->fingerprint.empty() && target->nc->FindCert(u->fingerprint)))
+ bool ok = false;
+ if (!u->fingerprint.empty() && target->nc->FindCert(u->fingerprint))
+ ok = true;
+ else if (!pass.empty())
+ {
+ EventReturn MOD_RESULT;
+ FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, target->nc->display, pass));
+ if (MOD_RESULT == EVENT_STOP)
+ return MOD_CONT;
+ else if (MOD_RESULT == EVENT_ALLOW)
+ ok = true;
+ }
+ if (ok)
{
/* If the nick is already registered, drop it.
* If not, check that it is valid.
@@ -122,13 +133,9 @@ class CommandNSGroup : public Command
check_memos(u);
}
- else if (pass.empty())
- {
- this->OnSyntaxError(source, "");
- }
else
{
- Log(LOG_COMMAND, u, this) << "failed group for " << target->nick << " (invalid password)";
+ Log(LOG_COMMAND, u, this) << "failed group for " << target->nick;
source.Reply(_(PASSWORD_INCORRECT));
if (bad_password(u))
return MOD_STOP;
diff --git a/modules/core/ns_identify.cpp b/modules/core/ns_identify.cpp
index 742fe986a..15f2ade94 100644
--- a/modules/core/ns_identify.cpp
+++ b/modules/core/ns_identify.cpp
@@ -30,30 +30,28 @@ class CommandNSIdentify : public Command
Anope::string pass = params[params.size() - 1];
NickAlias *na = findnick(nick);
- if (!na)
- source.Reply(_(NICK_NOT_REGISTERED));
- else if (na->HasFlag(NS_FORBIDDEN))
+ if (na && na->HasFlag(NS_FORBIDDEN))
source.Reply(_(NICK_X_FORBIDDEN), na->nick.c_str());
- else if (na->nc->HasFlag(NI_SUSPENDED))
+ else if (na && na->nc->HasFlag(NI_SUSPENDED))
source.Reply(_(NICK_X_SUSPENDED), na->nick.c_str());
- /* You can now identify for other nicks without logging out first,
- * however you can not identify again for the group you're already
- * identified as
- */
- else if (u->Account() && u->Account() == na->nc)
+ else if (u->Account() && na && u->Account() == na->nc)
source.Reply(_("You are already identified."));
else
{
- int res = enc_check_password(pass, na->nc->pass);
- if (!res)
+ EventReturn MOD_RESULT;
+ FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, nick, pass));
+ if (MOD_RESULT == EVENT_STOP)
+ return MOD_CONT;
+
+ if (!na)
+ source.Reply(_(NICK_X_NOT_REGISTERED), nick.c_str());
+ else if (MOD_RESULT != EVENT_ALLOW)
{
Log(LOG_COMMAND, u, this) << "and failed to identify";
source.Reply(_(PASSWORD_INCORRECT));
if (bad_password(u))
return MOD_STOP;
}
- else if (res == -1)
- source.Reply(_("Sorry, identification failed."));
else
{
if (u->IsIdentified())
diff --git a/modules/core/ns_recover.cpp b/modules/core/ns_recover.cpp
index 416b0e184..d78955f51 100644
--- a/modules/core/ns_recover.cpp
+++ b/modules/core/ns_recover.cpp
@@ -27,7 +27,7 @@ class CommandNSRecover : public Command
User *u = source.u;
const Anope::string &nick = params[0];
- Anope::string pass = params.size() > 1 ? params[1] : "";
+ const Anope::string &pass = params.size() > 1 ? params[1] : "";
NickAlias *na;
User *u2;
@@ -43,9 +43,12 @@ class CommandNSRecover : public Command
source.Reply(_("You can't recover yourself!"));
else if (!pass.empty())
{
- int res = enc_check_password(pass, na->nc->pass);
+ EventReturn MOD_RESULT;
+ FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, na->nc->display, pass));
+ if (MOD_RESULT == EVENT_STOP)
+ return MOD_CONT;
- if (res == 1)
+ if (MOD_RESULT == EVENT_ALLOW)
{
u2->SendMessage(NickServ, _(FORCENICKCHANGE_NOW));
u2->Collide(na);
@@ -58,12 +61,9 @@ class CommandNSRecover : public Command
else
{
source.Reply(_(ACCESS_DENIED));
- if (!res)
- {
- Log(LOG_COMMAND, u, this) << "with invalid password for " << nick;
- if (bad_password(u))
- return MOD_STOP;
- }
+ Log(LOG_COMMAND, u, this) << "with invalid password for " << nick;
+ if (bad_password(u))
+ return MOD_STOP;
}
}
else
diff --git a/modules/core/ns_release.cpp b/modules/core/ns_release.cpp
index 94a778218..94126eef8 100644
--- a/modules/core/ns_release.cpp
+++ b/modules/core/ns_release.cpp
@@ -39,8 +39,12 @@ class CommandNSRelease : public Command
source.Reply(_("Nick \002%s\002 isn't being held."), nick.c_str());
else if (!pass.empty())
{
- int res = enc_check_password(pass, na->nc->pass);
- if (res == 1)
+ EventReturn MOD_RESULT;
+ FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(u, this, params, na->nc->display, pass));
+ if (MOD_RESULT == EVENT_STOP)
+ return MOD_CONT;
+
+ if (MOD_RESULT == EVENT_ALLOW)
{
Log(LOG_COMMAND, u, this) << "released " << na->nick;
na->Release();
@@ -49,12 +53,9 @@ class CommandNSRelease : public Command
else
{
source.Reply(_(ACCESS_DENIED));
- if (!res)
- {
- Log(LOG_COMMAND, u, this) << "invalid password for " << nick;
- if (bad_password(u))
- return MOD_STOP;
- }
+ Log(LOG_COMMAND, u, this) << "invalid password for " << nick;
+ if (bad_password(u))
+ return MOD_STOP;
}
}
else