summaryrefslogtreecommitdiff
path: root/modules/extra
diff options
context:
space:
mode:
authorAdam <Adam@anope.org>2011-04-03 18:07:58 -0400
committerAdam <Adam@anope.org>2011-04-03 18:07:58 -0400
commit905207093b89a3c71ee3732d051555870c4d39f5 (patch)
treef940bf01272cae4a118a30e0701200e0f55a68fd /modules/extra
parentd1328d876a988329b3bdeb94999cfd696e6aa7a5 (diff)
Made LDAP support recover, release, resetpass, etc.
Diffstat (limited to 'modules/extra')
-rw-r--r--modules/extra/m_ldap_authentication.cpp (renamed from modules/extra/ns_identify_ldap.cpp)154
-rw-r--r--modules/extra/m_xmlrpc_main.cpp15
2 files changed, 91 insertions, 78 deletions
diff --git a/modules/extra/ns_identify_ldap.cpp b/modules/extra/m_ldap_authentication.cpp
index 8a65c5438..fa60247e5 100644
--- a/modules/extra/ns_identify_ldap.cpp
+++ b/modules/extra/m_ldap_authentication.cpp
@@ -6,24 +6,21 @@ static Anope::string email_attribute;
struct IdentifyInfo
{
dynamic_reference<User> user;
+ dynamic_reference<Command> command;
+ std::vector<Anope::string> params;
Anope::string account;
Anope::string pass;
- IdentifyInfo(User *u, const Anope::string &a, const Anope::string &p) : user(u), account(a), pass(p) { }
+ IdentifyInfo(User *u, Command *c, const std::vector<Anope::string> &pa, const Anope::string &a, const Anope::string &p) : user(u), command(c), params(pa), account(a), pass(p) { }
};
-class IdentifyInterface : public LDAPInterface, public Command
+class IdentifyInterface : public LDAPInterface
{
std::map<LDAPQuery, IdentifyInfo *> requests;
public:
- IdentifyInterface(Module *m) : LDAPInterface(m), Command("IDENTIFY", 0, 0)
- {
- this->service = NickServ;
- }
-
- CommandReturn Execute(CommandSource &, const std::vector<Anope::string> &) { return MOD_STOP; }
+ IdentifyInterface(Module *m) : LDAPInterface(m) { }
void Add(LDAPQuery id, IdentifyInfo *ii)
{
@@ -41,28 +38,34 @@ class IdentifyInterface : public LDAPInterface, public Command
IdentifyInfo *ii = it->second;
this->requests.erase(it);
+ if (!ii->user || !ii->command)
+ {
+ delete this;
+ return;
+ }
+
User *u = *ii->user;
- NickAlias *na = findnick(ii->account);
+ Command *c = *ii->command;
+
+ u->Extend("m_ldap_authentication_authenticated");
- if (!na)
+ NickAlias *na = findnick(ii->account);
+ if (na == NULL)
{
na = new NickAlias(ii->account, new NickCore(ii->account));
- enc_encrypt(ii->pass, na->nc->pass);
-
- Anope::string last_usermask = u->GetIdent() + "@" + u->GetDisplayedHost();
- na->last_usermask = last_usermask;
- na->last_realname = u->realname;
if (Config->NSAddAccessOnReg)
na->nc->AddAccess(create_mask(u));
- u->SendMessage(NickServ, _("Your account \002%s\002 has been successfully created."), ii->account.c_str());
+ u->SendMessage(NickServ, _("Your account \002%s\002 has been successfully created."), na->nick.c_str());
}
- if (u->Account())
- Log(LOG_COMMAND, u, this) << "to log out of account " << u->Account()->display;
- Log(LOG_COMMAND, u, this) << "and identified for account " << na->nc->display << " using LDAP";
- u->SendMessage(NickServ, _("Password accepted - you are now recognized."));
- u->Identify(na);
+ enc_encrypt(ii->pass, na->nc->pass);
+
+ Anope::string params;
+ for (unsigned i = 0; i < ii->params.size(); ++i)
+ params += ii->params[i] + " ";
+ mod_run_cmd(c->service, u, NULL, c, c->name, params);
+
delete ii;
}
@@ -74,17 +77,22 @@ class IdentifyInterface : public LDAPInterface, public Command
IdentifyInfo *ii = it->second;
this->requests.erase(it);
- if (!ii->user)
+ if (!ii->user || !ii->command)
{
- delete this;
+ delete ii;
return;
}
User *u = *ii->user;
+ Command *c = *ii->command;
+
+ u->Extend("m_ldap_authentication_error");
+
+ Anope::string params;
+ for (unsigned i = 0; i < ii->params.size(); ++i)
+ params += ii->params[i] + " ";
+ mod_run_cmd(c->service, u, NULL, c, c->name, params);
- Log(LOG_COMMAND, u, this) << "and failed to identify for account " << ii->account << ". LDAP error: " << r.getError();
- u->SendMessage(NickServ, _(PASSWORD_INCORRECT));
- bad_password(u);
delete ii;
}
};
@@ -121,19 +129,19 @@ class OnIdentifyInterface : public LDAPInterface
{
u->Account()->email = email;
u->SendMessage(NickServ, _("Your email has been updated to \002%s\002"), email.c_str());
- Log() << "ns_identify_ldap: Updated email address for " << u->nick << " (" << u->Account()->display << ") to " << email;
+ Log() << "m_ldap_authentication: Updated email address for " << u->nick << " (" << u->Account()->display << ") to " << email;
}
}
catch (const LDAPException &ex)
{
- Log() << "ns_identify_ldap: " << ex.GetReason();
+ Log() << "m_ldap_authentication: " << ex.GetReason();
}
}
void OnError(const LDAPResult &r)
{
this->requests.erase(r.id);
- Log() << "ns_identify_ldap: " << r.error;
+ Log() << "m_ldap_authentication: " << r.error;
}
};
@@ -154,8 +162,9 @@ class NSIdentifyLDAP : public Module
this->SetAuthor("Anope");
this->SetType(SUPPORTED);
- Implementation i[] = { I_OnReload, I_OnPreCommand, I_OnNickIdentify };
- ModuleManager::Attach(i, this, 3);
+ Implementation i[] = { I_OnReload, I_OnPreCommand, I_OnCheckAuthentication, I_OnNickIdentify };
+ ModuleManager::Attach(i, this, 4);
+ ModuleManager::SetPriority(this, PRIORITY_FIRST);
OnReload(false);
}
@@ -164,57 +173,56 @@ class NSIdentifyLDAP : public Module
{
ConfigReader config;
- this->binddn = config.ReadValue("ns_identify_ldap", "binddn", "", 0);
- this->username_attribute = config.ReadValue("ns_identify_ldap", "username_attribute", "", 0);
- email_attribute = config.ReadValue("ns_identify_ldap", "email_attribute", "", 0);
- this->disable_register = config.ReadFlag("ns_identify_ldap", "disable_ns_register", "false", 0);
- this->disable_reason = config.ReadValue("ns_identify_ldap", "disable_reason", "", 0);
+ this->binddn = config.ReadValue("m_ldap_authentication", "binddn", "", 0);
+ this->username_attribute = config.ReadValue("m_ldap_authentication", "username_attribute", "", 0);
+ email_attribute = config.ReadValue("m_ldap_authentication", "email_attribute", "", 0);
+ this->disable_register = config.ReadFlag("m_ldap_authentication", "disable_ns_register", "false", 0);
+ this->disable_reason = config.ReadValue("m_ldap_authentication", "disable_reason", "", 0);
}
EventReturn OnPreCommand(CommandSource &source, Command *command, const std::vector<Anope::string> &params)
{
- if (command->service == NickServ)
+ if (this->disable_register && command->service == NickServ && command->name == "REGISTER")
{
- if (this->disable_register && command->name == "REGISTER")
- {
- source.Reply(_(this->disable_reason.c_str()));
- return EVENT_STOP;
- }
- else if (command->name == "IDENTIFY" && !params.empty() && this->ldap)
- {
- Anope::string account = params.size() > 1 ? params[0] : source.u->nick;
- Anope::string pass = params.size() > 1 ? params[1] : params[0];
-
- NickAlias *na = findnick(account);
- if (na)
- {
- account = na->nc->display;
-
- if (na->HasFlag(NS_FORBIDDEN) || na->nc->HasFlag(NI_SUSPENDED) || source.u->Account() == na->nc)
- return EVENT_CONTINUE;
- }
-
- IdentifyInfo *ii = new IdentifyInfo(source.u, account, pass);
- try
- {
- Anope::string full_binddn = this->username_attribute + "=" + account + "," + this->binddn;
- LDAPQuery id = this->ldap->Bind(&this->iinterface, full_binddn, pass);
- this->iinterface.Add(id, ii);
- }
- catch (const LDAPException &ex)
- {
- delete ii;
- Log() << "ns_identify_ldap: " << ex.GetReason();
- return EVENT_CONTINUE;
- }
-
- return EVENT_STOP;
- }
+ source.Reply(_(this->disable_reason.c_str()));
+ return EVENT_STOP;
}
return EVENT_CONTINUE;
}
+ EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> &params, const Anope::string &account, const Anope::string &password)
+ {
+ if (u == NULL || c == NULL || !this->ldap)
+ return EVENT_CONTINUE;
+ else if (u->GetExt("m_ldap_authentication_authenticated"))
+ {
+ u->Shrink("m_ldap_authentication_authenticated");
+ return EVENT_ALLOW;
+ }
+ else if (u->GetExt("m_ldap_authentication_error"))
+ {
+ u->Shrink("m_ldap_authentication_error");
+ return EVENT_CONTINUE;;
+ }
+
+ IdentifyInfo *ii = new IdentifyInfo(u, c, params, account, password);
+ try
+ {
+ Anope::string full_binddn = this->username_attribute + "=" + account + "," + this->binddn;
+ LDAPQuery id = this->ldap->Bind(&this->iinterface, full_binddn, password);
+ this->iinterface.Add(id, ii);
+ }
+ catch (const LDAPException &ex)
+ {
+ delete ii;
+ Log() << "ns_identify_ldap: " << ex.GetReason();
+ return EVENT_CONTINUE;
+ }
+
+ return EVENT_STOP;
+ }
+
void OnNickIdentify(User *u)
{
if (email_attribute.empty() || !this->ldap)
@@ -227,7 +235,7 @@ class NSIdentifyLDAP : public Module
}
catch (const LDAPException &ex)
{
- Log() << "ns_identify_ldap: " << ex.GetReason();
+ Log() << "m_ldap_authentication: " << ex.GetReason();
}
}
};
diff --git a/modules/extra/m_xmlrpc_main.cpp b/modules/extra/m_xmlrpc_main.cpp
index 33cf3818c..593aba6ef 100644
--- a/modules/extra/m_xmlrpc_main.cpp
+++ b/modules/extra/m_xmlrpc_main.cpp
@@ -113,13 +113,18 @@ class MyXMLRPCEvent : public XMLRPCEvent
if (!na)
request->reply("error", "Invalid account");
- else if (enc_check_password(password, na->nc->pass) == 1)
+ else
{
- request->reply("result", "Success");
- request->reply("account", na->nc->display);
+ EventReturn MOD_RESULT;
+ FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(NULL, NULL, std::vector<Anope::string>(), na->nc->display, password));
+ if (MOD_RESULT == EVENT_ALLOW)
+ {
+ request->reply("result", "Success");
+ request->reply("account", na->nc->display);
+ }
+ else
+ request->reply("error", "Invalid password");
}
- else
- request->reply("error", "Invalid password");
}
}