diff options
| author | Adam <Adam@anope.org> | 2011-04-03 18:07:58 -0400 |
|---|---|---|
| committer | Adam <Adam@anope.org> | 2011-04-03 18:07:58 -0400 |
| commit | 905207093b89a3c71ee3732d051555870c4d39f5 (patch) | |
| tree | f940bf01272cae4a118a30e0701200e0f55a68fd /modules/extra | |
| parent | d1328d876a988329b3bdeb94999cfd696e6aa7a5 (diff) | |
Made LDAP support recover, release, resetpass, etc.
Diffstat (limited to 'modules/extra')
| -rw-r--r-- | modules/extra/m_ldap_authentication.cpp (renamed from modules/extra/ns_identify_ldap.cpp) | 154 | ||||
| -rw-r--r-- | modules/extra/m_xmlrpc_main.cpp | 15 |
2 files changed, 91 insertions, 78 deletions
diff --git a/modules/extra/ns_identify_ldap.cpp b/modules/extra/m_ldap_authentication.cpp index 8a65c5438..fa60247e5 100644 --- a/modules/extra/ns_identify_ldap.cpp +++ b/modules/extra/m_ldap_authentication.cpp @@ -6,24 +6,21 @@ static Anope::string email_attribute; struct IdentifyInfo { dynamic_reference<User> user; + dynamic_reference<Command> command; + std::vector<Anope::string> params; Anope::string account; Anope::string pass; - IdentifyInfo(User *u, const Anope::string &a, const Anope::string &p) : user(u), account(a), pass(p) { } + IdentifyInfo(User *u, Command *c, const std::vector<Anope::string> &pa, const Anope::string &a, const Anope::string &p) : user(u), command(c), params(pa), account(a), pass(p) { } }; -class IdentifyInterface : public LDAPInterface, public Command +class IdentifyInterface : public LDAPInterface { std::map<LDAPQuery, IdentifyInfo *> requests; public: - IdentifyInterface(Module *m) : LDAPInterface(m), Command("IDENTIFY", 0, 0) - { - this->service = NickServ; - } - - CommandReturn Execute(CommandSource &, const std::vector<Anope::string> &) { return MOD_STOP; } + IdentifyInterface(Module *m) : LDAPInterface(m) { } void Add(LDAPQuery id, IdentifyInfo *ii) { @@ -41,28 +38,34 @@ class IdentifyInterface : public LDAPInterface, public Command IdentifyInfo *ii = it->second; this->requests.erase(it); + if (!ii->user || !ii->command) + { + delete this; + return; + } + User *u = *ii->user; - NickAlias *na = findnick(ii->account); + Command *c = *ii->command; + + u->Extend("m_ldap_authentication_authenticated"); - if (!na) + NickAlias *na = findnick(ii->account); + if (na == NULL) { na = new NickAlias(ii->account, new NickCore(ii->account)); - enc_encrypt(ii->pass, na->nc->pass); - - Anope::string last_usermask = u->GetIdent() + "@" + u->GetDisplayedHost(); - na->last_usermask = last_usermask; - na->last_realname = u->realname; if (Config->NSAddAccessOnReg) na->nc->AddAccess(create_mask(u)); - u->SendMessage(NickServ, _("Your account \002%s\002 has been successfully created."), ii->account.c_str()); + u->SendMessage(NickServ, _("Your account \002%s\002 has been successfully created."), na->nick.c_str()); } - if (u->Account()) - Log(LOG_COMMAND, u, this) << "to log out of account " << u->Account()->display; - Log(LOG_COMMAND, u, this) << "and identified for account " << na->nc->display << " using LDAP"; - u->SendMessage(NickServ, _("Password accepted - you are now recognized.")); - u->Identify(na); + enc_encrypt(ii->pass, na->nc->pass); + + Anope::string params; + for (unsigned i = 0; i < ii->params.size(); ++i) + params += ii->params[i] + " "; + mod_run_cmd(c->service, u, NULL, c, c->name, params); + delete ii; } @@ -74,17 +77,22 @@ class IdentifyInterface : public LDAPInterface, public Command IdentifyInfo *ii = it->second; this->requests.erase(it); - if (!ii->user) + if (!ii->user || !ii->command) { - delete this; + delete ii; return; } User *u = *ii->user; + Command *c = *ii->command; + + u->Extend("m_ldap_authentication_error"); + + Anope::string params; + for (unsigned i = 0; i < ii->params.size(); ++i) + params += ii->params[i] + " "; + mod_run_cmd(c->service, u, NULL, c, c->name, params); - Log(LOG_COMMAND, u, this) << "and failed to identify for account " << ii->account << ". LDAP error: " << r.getError(); - u->SendMessage(NickServ, _(PASSWORD_INCORRECT)); - bad_password(u); delete ii; } }; @@ -121,19 +129,19 @@ class OnIdentifyInterface : public LDAPInterface { u->Account()->email = email; u->SendMessage(NickServ, _("Your email has been updated to \002%s\002"), email.c_str()); - Log() << "ns_identify_ldap: Updated email address for " << u->nick << " (" << u->Account()->display << ") to " << email; + Log() << "m_ldap_authentication: Updated email address for " << u->nick << " (" << u->Account()->display << ") to " << email; } } catch (const LDAPException &ex) { - Log() << "ns_identify_ldap: " << ex.GetReason(); + Log() << "m_ldap_authentication: " << ex.GetReason(); } } void OnError(const LDAPResult &r) { this->requests.erase(r.id); - Log() << "ns_identify_ldap: " << r.error; + Log() << "m_ldap_authentication: " << r.error; } }; @@ -154,8 +162,9 @@ class NSIdentifyLDAP : public Module this->SetAuthor("Anope"); this->SetType(SUPPORTED); - Implementation i[] = { I_OnReload, I_OnPreCommand, I_OnNickIdentify }; - ModuleManager::Attach(i, this, 3); + Implementation i[] = { I_OnReload, I_OnPreCommand, I_OnCheckAuthentication, I_OnNickIdentify }; + ModuleManager::Attach(i, this, 4); + ModuleManager::SetPriority(this, PRIORITY_FIRST); OnReload(false); } @@ -164,57 +173,56 @@ class NSIdentifyLDAP : public Module { ConfigReader config; - this->binddn = config.ReadValue("ns_identify_ldap", "binddn", "", 0); - this->username_attribute = config.ReadValue("ns_identify_ldap", "username_attribute", "", 0); - email_attribute = config.ReadValue("ns_identify_ldap", "email_attribute", "", 0); - this->disable_register = config.ReadFlag("ns_identify_ldap", "disable_ns_register", "false", 0); - this->disable_reason = config.ReadValue("ns_identify_ldap", "disable_reason", "", 0); + this->binddn = config.ReadValue("m_ldap_authentication", "binddn", "", 0); + this->username_attribute = config.ReadValue("m_ldap_authentication", "username_attribute", "", 0); + email_attribute = config.ReadValue("m_ldap_authentication", "email_attribute", "", 0); + this->disable_register = config.ReadFlag("m_ldap_authentication", "disable_ns_register", "false", 0); + this->disable_reason = config.ReadValue("m_ldap_authentication", "disable_reason", "", 0); } EventReturn OnPreCommand(CommandSource &source, Command *command, const std::vector<Anope::string> ¶ms) { - if (command->service == NickServ) + if (this->disable_register && command->service == NickServ && command->name == "REGISTER") { - if (this->disable_register && command->name == "REGISTER") - { - source.Reply(_(this->disable_reason.c_str())); - return EVENT_STOP; - } - else if (command->name == "IDENTIFY" && !params.empty() && this->ldap) - { - Anope::string account = params.size() > 1 ? params[0] : source.u->nick; - Anope::string pass = params.size() > 1 ? params[1] : params[0]; - - NickAlias *na = findnick(account); - if (na) - { - account = na->nc->display; - - if (na->HasFlag(NS_FORBIDDEN) || na->nc->HasFlag(NI_SUSPENDED) || source.u->Account() == na->nc) - return EVENT_CONTINUE; - } - - IdentifyInfo *ii = new IdentifyInfo(source.u, account, pass); - try - { - Anope::string full_binddn = this->username_attribute + "=" + account + "," + this->binddn; - LDAPQuery id = this->ldap->Bind(&this->iinterface, full_binddn, pass); - this->iinterface.Add(id, ii); - } - catch (const LDAPException &ex) - { - delete ii; - Log() << "ns_identify_ldap: " << ex.GetReason(); - return EVENT_CONTINUE; - } - - return EVENT_STOP; - } + source.Reply(_(this->disable_reason.c_str())); + return EVENT_STOP; } return EVENT_CONTINUE; } + EventReturn OnCheckAuthentication(User *u, Command *c, const std::vector<Anope::string> ¶ms, const Anope::string &account, const Anope::string &password) + { + if (u == NULL || c == NULL || !this->ldap) + return EVENT_CONTINUE; + else if (u->GetExt("m_ldap_authentication_authenticated")) + { + u->Shrink("m_ldap_authentication_authenticated"); + return EVENT_ALLOW; + } + else if (u->GetExt("m_ldap_authentication_error")) + { + u->Shrink("m_ldap_authentication_error"); + return EVENT_CONTINUE;; + } + + IdentifyInfo *ii = new IdentifyInfo(u, c, params, account, password); + try + { + Anope::string full_binddn = this->username_attribute + "=" + account + "," + this->binddn; + LDAPQuery id = this->ldap->Bind(&this->iinterface, full_binddn, password); + this->iinterface.Add(id, ii); + } + catch (const LDAPException &ex) + { + delete ii; + Log() << "ns_identify_ldap: " << ex.GetReason(); + return EVENT_CONTINUE; + } + + return EVENT_STOP; + } + void OnNickIdentify(User *u) { if (email_attribute.empty() || !this->ldap) @@ -227,7 +235,7 @@ class NSIdentifyLDAP : public Module } catch (const LDAPException &ex) { - Log() << "ns_identify_ldap: " << ex.GetReason(); + Log() << "m_ldap_authentication: " << ex.GetReason(); } } }; diff --git a/modules/extra/m_xmlrpc_main.cpp b/modules/extra/m_xmlrpc_main.cpp index 33cf3818c..593aba6ef 100644 --- a/modules/extra/m_xmlrpc_main.cpp +++ b/modules/extra/m_xmlrpc_main.cpp @@ -113,13 +113,18 @@ class MyXMLRPCEvent : public XMLRPCEvent if (!na) request->reply("error", "Invalid account"); - else if (enc_check_password(password, na->nc->pass) == 1) + else { - request->reply("result", "Success"); - request->reply("account", na->nc->display); + EventReturn MOD_RESULT; + FOREACH_RESULT(I_OnCheckAuthentication, OnCheckAuthentication(NULL, NULL, std::vector<Anope::string>(), na->nc->display, password)); + if (MOD_RESULT == EVENT_ALLOW) + { + request->reply("result", "Success"); + request->reply("account", na->nc->display); + } + else + request->reply("error", "Invalid password"); } - else - request->reply("error", "Invalid password"); } } |
