diff options
| author | Sadie Powell <sadie@witchery.services> | 2024-02-29 14:49:39 +0000 |
|---|---|---|
| committer | Sadie Powell <sadie@witchery.services> | 2024-02-29 16:14:15 +0000 |
| commit | 579af3c44200a8325bd2eec9e6ff0ec28fa7125b (patch) | |
| tree | 455dbad4bdc231ea4b2b9297e0dfa0a53446d640 /modules/nickserv | |
| parent | 25bdcfcbc472b8e348aa338d8ebb0a18fd006fff (diff) | |
Rip out ns_access and related code.
This is wildly insecure and has been disabled by default for at
least a decade.
Diffstat (limited to 'modules/nickserv')
| -rw-r--r-- | modules/nickserv/nickserv.cpp | 26 | ||||
| -rw-r--r-- | modules/nickserv/ns_access.cpp | 208 | ||||
| -rw-r--r-- | modules/nickserv/ns_cert.cpp | 2 | ||||
| -rw-r--r-- | modules/nickserv/ns_recover.cpp | 6 | ||||
| -rw-r--r-- | modules/nickserv/ns_register.cpp | 6 | ||||
| -rw-r--r-- | modules/nickserv/ns_set.cpp | 107 | ||||
| -rw-r--r-- | modules/nickserv/ns_status.cpp | 89 |
7 files changed, 12 insertions, 432 deletions
diff --git a/modules/nickserv/nickserv.cpp b/modules/nickserv/nickserv.cpp index 673400e92..47d2cf30d 100644 --- a/modules/nickserv/nickserv.cpp +++ b/modules/nickserv/nickserv.cpp @@ -190,27 +190,14 @@ public: else if (MOD_RESULT == EVENT_ALLOW) return; - if (!na->nc->HasExt("NS_SECURE") && u->IsRecognized()) - { - na->last_seen = Anope::CurTime; - na->last_usermask = u->GetIdent() + "@" + u->GetDisplayedHost(); - na->last_realname = u->realname; - return; - } - if (Config->GetModule("nickserv")->Get<bool>("nonicknameownership")) return; - bool on_access = u->IsRecognized(false); - - if (on_access || !na->nc->HasExt("KILL_IMMED")) + if (!na->nc->HasExt("KILL_IMMED")) { - if (na->nc->HasExt("NS_SECURE")) - u->SendMessage(NickServ, NICK_IS_SECURE, Config->StrictPrivmsg.c_str(), NickServ->nick.c_str()); - else - u->SendMessage(NickServ, NICK_IS_REGISTERED, Config->StrictPrivmsg.c_str(), NickServ->nick.c_str()); + u->SendMessage(NickServ, NICK_IS_SECURE, Config->StrictPrivmsg.c_str(), NickServ->nick.c_str()); } - if (na->nc->HasExt("KILLPROTECT") && !on_access) + if (na->nc->HasExt("KILLPROTECT")) { if (na->nc->HasExt("KILL_IMMED")) { @@ -310,10 +297,9 @@ public: NickServ = bi; - spacesepstream(conf->GetModule(this)->Get<const Anope::string>("defaults", "ns_secure memo_signon memo_receive")).GetTokens(defaults); + spacesepstream(conf->GetModule(this)->Get<const Anope::string>("defaults", "memo_signon memo_receive")).GetTokens(defaults); if (defaults.empty()) { - defaults.emplace_back("NS_SECURE"); defaults.emplace_back("MEMO_SIGNON"); defaults.emplace_back("MEMO_RECEIVE"); } @@ -523,7 +509,7 @@ public: /* Update last quit and last seen for the user */ NickAlias *na = NickAlias::Find(u->nick); - if (na && !na->nc->HasExt("NS_SUSPENDED") && (u->IsRecognized() || u->IsIdentified(true))) + if (na && !na->nc->HasExt("NS_SUSPENDED") && u->IsIdentified(true)) { na->last_seen = Anope::CurTime; na->last_quit = msg; @@ -543,7 +529,7 @@ public: ++it; User *u = User::Find(na->nick, true); - if (u && (u->IsIdentified(true) || u->IsRecognized())) + if (u && u->IsIdentified(true)) na->last_seen = Anope::CurTime; bool expire = false; diff --git a/modules/nickserv/ns_access.cpp b/modules/nickserv/ns_access.cpp deleted file mode 100644 index c8d391751..000000000 --- a/modules/nickserv/ns_access.cpp +++ /dev/null @@ -1,208 +0,0 @@ -/* NickServ core functions - * - * (C) 2003-2024 Anope Team - * Contact us at team@anope.org - * - * Please read COPYING and README for further details. - * - * Based on the original code of Epona by Lara. - * Based on the original code of Services by Andy Church. - */ - -#include "module.h" - -class CommandNSAccess final - : public Command -{ -private: - void DoAdd(CommandSource &source, NickCore *nc, const Anope::string &mask) - { - if (mask.empty()) - { - this->OnSyntaxError(source, "ADD"); - return; - } - - if (Anope::ReadOnly) - { - source.Reply(READ_ONLY_MODE); - return; - } - - if (nc->access.size() >= Config->GetModule(this->owner)->Get<unsigned>("accessmax", "32")) - { - source.Reply(_("Sorry, the maximum of %d access entries has been reached."), Config->GetModule(this->owner)->Get<unsigned>("accessmax")); - return; - } - - if (nc->FindAccess(mask)) - { - source.Reply(_("Mask \002%s\002 already present on %s's access list."), mask.c_str(), nc->display.c_str()); - return; - } - - nc->AddAccess(mask); - Log(nc == source.GetAccount() ? LOG_COMMAND : LOG_ADMIN, source, this) << "to ADD mask " << mask << " to " << nc->display; - source.Reply(_("\002%s\002 added to %s's access list."), mask.c_str(), nc->display.c_str()); - - return; - } - - void DoDel(CommandSource &source, NickCore *nc, const Anope::string &mask) - { - if (mask.empty()) - { - this->OnSyntaxError(source, "DEL"); - return; - } - - if (Anope::ReadOnly) - { - source.Reply(READ_ONLY_MODE); - return; - } - - if (!nc->FindAccess(mask)) - { - source.Reply(_("\002%s\002 not found on %s's access list."), mask.c_str(), nc->display.c_str()); - return; - } - - nc->EraseAccess(mask); - Log(nc == source.GetAccount() ? LOG_COMMAND : LOG_ADMIN, source, this) << "to DELETE mask " << mask << " from " << nc->display; - source.Reply(_("\002%s\002 deleted from %s's access list."), mask.c_str(), nc->display.c_str()); - - return; - } - - static void DoList(CommandSource &source, NickCore *nc, const Anope::string &mask) - { - unsigned i, end; - - if (nc->access.empty()) - { - source.Reply(_("%s's access list is empty."), nc->display.c_str()); - return; - } - - source.Reply(_("Access list for %s:"), nc->display.c_str()); - for (i = 0, end = nc->access.size(); i < end; ++i) - { - Anope::string access = nc->GetAccess(i); - if (!mask.empty() && !Anope::Match(access, mask)) - continue; - source.Reply(" %s", access.c_str()); - } - - return; - } -public: - CommandNSAccess(Module *creator) : Command(creator, "nickserv/access", 1, 3) - { - this->SetDesc(_("Modify the list of authorized addresses")); - this->SetSyntax(_("ADD [\037nickname\037] \037mask\037")); - this->SetSyntax(_("DEL [\037nickname\037] \037mask\037")); - this->SetSyntax(_("LIST [\037nickname\037]")); - } - - void Execute(CommandSource &source, const std::vector<Anope::string> ¶ms) override - { - const Anope::string &cmd = params[0]; - Anope::string nick, mask; - - if (cmd.equals_ci("LIST")) - nick = params.size() > 1 ? params[1] : ""; - else - { - nick = params.size() == 3 ? params[1] : ""; - mask = params.size() > 1 ? params[params.size() - 1] : ""; - } - - NickCore *nc; - if (!nick.empty()) - { - const NickAlias *na = NickAlias::Find(nick); - if (na == NULL) - { - source.Reply(NICK_X_NOT_REGISTERED, nick.c_str()); - return; - } - else if (na->nc != source.GetAccount() && !source.HasPriv("nickserv/access")) - { - source.Reply(ACCESS_DENIED); - return; - } - else if (Config->GetModule("nickserv")->Get<bool>("secureadmins", "yes") && source.GetAccount() != na->nc && na->nc->IsServicesOper() && !cmd.equals_ci("LIST")) - { - source.Reply(_("You may view but not modify the access list of other Services Operators.")); - return; - } - - nc = na->nc; - } - else - nc = source.nc; - - if (!mask.empty() && (mask.find('@') == Anope::string::npos || mask.find('!') != Anope::string::npos)) - { - source.Reply(BAD_USERHOST_MASK); - source.Reply(MORE_INFO, Config->StrictPrivmsg.c_str(), source.service->nick.c_str(), source.command.c_str()); - } - else if (cmd.equals_ci("LIST")) - return this->DoList(source, nc, mask); - else if (nc->HasExt("NS_SUSPENDED")) - source.Reply(NICK_X_SUSPENDED, nc->display.c_str()); - else if (cmd.equals_ci("ADD")) - return this->DoAdd(source, nc, mask); - else if (cmd.equals_ci("DEL")) - return this->DoDel(source, nc, mask); - else - this->OnSyntaxError(source, ""); - } - - bool OnHelp(CommandSource &source, const Anope::string &subcommand) override - { - this->SendSyntax(source); - source.Reply(" "); - source.Reply(_("Modifies or displays the access list for your nick. This\n" - "is the list of addresses which will be automatically\n" - "recognized by %s as allowed to use the nick. If\n" - "you want to use the nick from a different address, you\n" - "need to send an \002IDENTIFY\002 command to make %s\n" - "recognize you. Services Operators may provide a nick\n" - "to modify other users' access lists.\n" - " \n" - "Examples:\n" - " \n" - " \002ACCESS ADD anyone@*.bepeg.com\002\n" - " Allows access to user \002anyone\002 from any machine in\n" - " the \002bepeg.com\002 domain.\n" - " \n" - " \002ACCESS DEL anyone@*.bepeg.com\002\n" - " Reverses the previous command.\n" - " \n" - " \002ACCESS LIST\002\n" - " Displays the current access list."), source.service->nick.c_str(), source.service->nick.c_str()); - return true; - } -}; - -class NSAccess final - : public Module -{ - CommandNSAccess commandnsaccess; - -public: - NSAccess(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator, VENDOR), - commandnsaccess(this) - { - } - - void OnNickRegister(User *u, NickAlias *na, const Anope::string &) override - { - if (u && Config->GetModule(this)->Get<bool>("addaccessonreg")) - na->nc->AddAccess(u->Mask()); - } -}; - -MODULE_INIT(NSAccess) diff --git a/modules/nickserv/ns_cert.cpp b/modules/nickserv/ns_cert.cpp index 88ff1ecaa..0eeb5f68b 100644 --- a/modules/nickserv/ns_cert.cpp +++ b/modules/nickserv/ns_cert.cpp @@ -299,7 +299,7 @@ public: source.Reply(NICK_X_NOT_REGISTERED, nick.c_str()); return; } - else if (na->nc != source.GetAccount() && !source.HasPriv("nickserv/access")) + else if (na->nc != source.GetAccount() && !source.HasPriv("nickserv/cert")) { source.Reply(ACCESS_DENIED); return; diff --git a/modules/nickserv/ns_recover.cpp b/modules/nickserv/ns_recover.cpp index f12929f3a..d77dbc898 100644 --- a/modules/nickserv/ns_recover.cpp +++ b/modules/nickserv/ns_recover.cpp @@ -59,7 +59,7 @@ public: // same person that is executing the command, so kill them off (old GHOST command). else if (u->Account() == na->nc) { - if (!source.GetAccount() && na->nc->HasExt("NS_SECURE")) + if (!source.GetAccount()) { source.GetUser()->Login(u->Account()); Log(LOG_COMMAND, source, cmd) << "and was automatically identified to " << u->Account()->display; @@ -90,7 +90,7 @@ public: /* User is not identified or not identified to the same account as the person using this command */ else { - if (!source.GetAccount() && na->nc->HasExt("NS_SECURE")) + if (!source.GetAccount()) { source.GetUser()->Login(na->nc); // Identify the user using the command if they arent identified Log(LOG_COMMAND, source, cmd) << "and was automatically identified to " << na->nick << " (" << na->nc->display << ")"; @@ -182,8 +182,6 @@ public: bool ok = false; if (source.GetAccount() == na->nc) ok = true; - else if (!na->nc->HasExt("NS_SECURE") && source.GetUser() && na->nc->IsOnAccess(source.GetUser())) - ok = true; NSCertList *cl = na->nc->GetExt<NSCertList>("certificates"); if (source.GetUser() && !source.GetUser()->fingerprint.empty() && cl && cl->FindCert(source.GetUser()->fingerprint)) diff --git a/modules/nickserv/ns_register.cpp b/modules/nickserv/ns_register.cpp index 34a76d973..d73d74c6b 100644 --- a/modules/nickserv/ns_register.cpp +++ b/modules/nickserv/ns_register.cpp @@ -233,11 +233,7 @@ public: Log(LOG_COMMAND, source, this) << "to register " << na->nick << " (email: " << (!na->nc->email.empty() ? na->nc->email : "none") << ")"; - if (na->nc->GetAccessCount()) - source.Reply(_("Nickname \002%s\002 registered under your user@host-mask: %s"), u_nick.c_str(), na->nc->GetAccess(0).c_str()); - else - source.Reply(_("Nickname \002%s\002 registered."), u_nick.c_str()); - + source.Reply(_("Nickname \002%s\002 registered."), u_nick.c_str()); if (nsregister.equals_ci("admin")) { nc->Extend<bool>("UNCONFIRMED"); diff --git a/modules/nickserv/ns_set.cpp b/modules/nickserv/ns_set.cpp index 9e79beb64..31547840b 100644 --- a/modules/nickserv/ns_set.cpp +++ b/modules/nickserv/ns_set.cpp @@ -1105,103 +1105,6 @@ public: } }; -class CommandNSSetSecure - : public Command -{ -public: - CommandNSSetSecure(Module *creator, const Anope::string &sname = "nickserv/set/secure", size_t min = 1) : Command(creator, sname, min, min + 1) - { - this->SetDesc(_("Turn nickname security on or off")); - this->SetSyntax("{ON | OFF}"); - } - - void Run(CommandSource &source, const Anope::string &user, const Anope::string ¶m) - { - if (Anope::ReadOnly) - { - source.Reply(READ_ONLY_MODE); - return; - } - - const NickAlias *na = NickAlias::Find(user); - if (!na) - { - source.Reply(NICK_X_NOT_REGISTERED, user.c_str()); - return; - } - NickCore *nc = na->nc; - - EventReturn MOD_RESULT; - FOREACH_RESULT(OnSetNickOption, MOD_RESULT, (source, this, nc, param)); - if (MOD_RESULT == EVENT_STOP) - return; - - if (param.equals_ci("ON")) - { - Log(nc == source.GetAccount() ? LOG_COMMAND : LOG_ADMIN, source, this) << "to enable secure for " << nc->display; - nc->Extend<bool>("NS_SECURE"); - source.Reply(_("Secure option is now \002on\002 for \002%s\002."), nc->display.c_str()); - } - else if (param.equals_ci("OFF")) - { - Log(nc == source.GetAccount() ? LOG_COMMAND : LOG_ADMIN, source, this) << "to disable secure for " << nc->display; - nc->Shrink<bool>("NS_SECURE"); - source.Reply(_("Secure option is now \002off\002 for \002%s\002."), nc->display.c_str()); - } - else - this->OnSyntaxError(source, "SECURE"); - } - - void Execute(CommandSource &source, const std::vector<Anope::string> ¶ms) override - { - this->Run(source, source.nc->display, params[0]); - } - - bool OnHelp(CommandSource &source, const Anope::string &) override - { - this->SendSyntax(source); - source.Reply(" "); - source.Reply(_("Turns %s's security features on or off for your\n" - "nick. With \002SECURE\002 set, you must enter your password\n" - "before you will be recognized as the owner of the nick,\n" - "regardless of whether your address is on the access\n" - "list. However, if you are on the access list, %s\n" - "will not auto-kill you regardless of the setting of the\n" - "\002KILL\002 option."), source.service->nick.c_str(), source.service->nick.c_str()); - return true; - } -}; - -class CommandNSSASetSecure final - : public CommandNSSetSecure -{ -public: - CommandNSSASetSecure(Module *creator) : CommandNSSetSecure(creator, "nickserv/saset/secure", 2) - { - this->ClearSyntax(); - this->SetSyntax(_("\037nickname\037 {ON | OFF}")); - } - - void Execute(CommandSource &source, const std::vector<Anope::string> ¶ms) override - { - this->Run(source, params[0], params[1]); - } - - bool OnHelp(CommandSource &source, const Anope::string &) override - { - this->SendSyntax(source); - source.Reply(" "); - source.Reply(_("Turns %s's security features on or off for your\n" - "nick. With \002SECURE\002 set, you must enter your password\n" - "before you will be recognized as the owner of the nick,\n" - "regardless of whether your address is on the access\n" - "list. However, if you are on the access list, %s\n" - "will not auto-kill you regardless of the setting of the\n" - "\002KILL\002 option."), source.service->nick.c_str(), source.service->nick.c_str()); - return true; - } -}; - class CommandNSSASetNoexpire final : public Command { @@ -1288,13 +1191,10 @@ class NSSet final CommandNSSetPassword commandnssetpassword; CommandNSSASetPassword commandnssasetpassword; - CommandNSSetSecure commandnssetsecure; - CommandNSSASetSecure commandnssasetsecure; - CommandNSSASetNoexpire commandnssasetnoexpire; SerializableExtensibleItem<bool> autoop, neverop, killprotect, kill_quick, kill_immed, - message, secure, noexpire; + message, noexpire; struct KeepModes final : SerializableExtensibleItem<bool> @@ -1358,13 +1258,12 @@ public: commandnssetlanguage(this), commandnssasetlanguage(this), commandnssetmessage(this), commandnssasetmessage(this), commandnssetpassword(this), commandnssasetpassword(this), - commandnssetsecure(this), commandnssasetsecure(this), commandnssasetnoexpire(this), autoop(this, "AUTOOP"), neverop(this, "NEVEROP"), killprotect(this, "KILLPROTECT"), kill_quick(this, "KILL_QUICK"), kill_immed(this, "KILL_IMMED"), message(this, "MSG"), - secure(this, "NS_SECURE"), noexpire(this, "NS_NO_EXPIRE"), + noexpire(this, "NS_NO_EXPIRE"), keep_modes(this, "NS_KEEP_MODES"), ns_set_email(this, "ns_set_email") { @@ -1420,8 +1319,6 @@ public: info.AddOption(_("Quick protection")); else if (killprotect.HasExt(na->nc)) info.AddOption(_("Protection")); - if (secure.HasExt(na->nc)) - info.AddOption(_("Security")); if (message.HasExt(na->nc)) info.AddOption(_("Message mode")); if (autoop.HasExt(na->nc)) diff --git a/modules/nickserv/ns_status.cpp b/modules/nickserv/ns_status.cpp deleted file mode 100644 index 7b4154ce6..000000000 --- a/modules/nickserv/ns_status.cpp +++ /dev/null @@ -1,89 +0,0 @@ -/* NickServ core functions - * - * (C) 2003-2024 Anope Team - * Contact us at team@anope.org - * - * Please read COPYING and README for further details. - * - * Based on the original code of Epona by Lara. - * Based on the original code of Services by Andy Church. - */ - -#include "module.h" - -class CommandNSStatus final - : public Command -{ -public: - CommandNSStatus(Module *creator) : Command(creator, "nickserv/status", 0, 16) - { - this->SetDesc(_("Returns the owner status of the given nickname")); - this->SetSyntax(_("[\037nickname\037]")); - this->AllowUnregistered(true); - } - - void Execute(CommandSource &source, const std::vector<Anope::string> ¶ms) override - { - const Anope::string &nick = !params.empty() ? params[0] : source.GetNick(); - const NickAlias *na = NickAlias::Find(nick); - spacesepstream sep(nick); - Anope::string nickbuf; - - while (sep.GetToken(nickbuf)) - { - User *u2 = User::Find(nickbuf, true); - if (!u2) /* Nick is not online */ - source.Reply("STATUS %s %d %s", nickbuf.c_str(), 0, ""); - else if (u2->IsIdentified() && na && na->nc == u2->Account()) /* Nick is identified */ - source.Reply("STATUS %s %d %s", nickbuf.c_str(), 3, u2->Account()->display.c_str()); - else if (u2->IsRecognized()) /* Nick is recognised, but NOT identified */ - source.Reply("STATUS %s %d %s", nickbuf.c_str(), 2, u2->Account() ? u2->Account()->display.c_str() : ""); - else if (!na) /* Nick is online, but NOT a registered */ - source.Reply("STATUS %s %d %s", nickbuf.c_str(), 0, ""); - else - /* Nick is not identified for the nick, but they could be logged into an account, - * so we tell the user about it - */ - source.Reply("STATUS %s %d %s", nickbuf.c_str(), 1, u2->Account() ? u2->Account()->display.c_str() : ""); - } - return; - } - - bool OnHelp(CommandSource &source, const Anope::string &subcommand) override - { - this->SendSyntax(source); - source.Reply(" "); - source.Reply(_("Returns whether the user using the given nickname is\n" - "recognized as the owner of the nickname. The response has\n" - "this format:\n" - " \n" - " \037nickname\037 \037status-code\037 \037account\037\n" - " \n" - "where \037nickname\037 is the nickname sent with the command,\n" - "\037status-code\037 is one of the following, and \037account\037\n" - "is the account they are logged in as.\n" - " \n" - " 0 - no such user online \002or\002 nickname not registered\n" - " 1 - user not recognized as nickname's owner\n" - " 2 - user recognized as owner via access list only\n" - " 3 - user recognized as owner via password identification\n" - " \n" - "If no nickname is given, your status will be returned.")); - return true; - } -}; - -class NSStatus final - : public Module -{ - CommandNSStatus commandnsstatus; - -public: - NSStatus(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator, VENDOR), - commandnsstatus(this) - { - - } -}; - -MODULE_INIT(NSStatus) |
