X-Git-Url: https://jfr.im/git/solanum.git/blobdiff_plain/0f021a8c1d618a1ca0997bb1b76bf255ba0a653f..6cac5cce0fedf3f0ed0de91d51539c8b8629fd9f:/extensions/m_webirc.c diff --git a/extensions/m_webirc.c b/extensions/m_webirc.c index 36a83894..04f59c96 100644 --- a/extensions/m_webirc.c +++ b/extensions/m_webirc.c @@ -20,8 +20,6 @@ * along with this program; if not, write to the Free Software * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 * USA - * - * $Id: m_webirc.c 3458 2007-05-18 19:51:22Z jilles $ */ /* Usage: * auth { @@ -32,10 +30,9 @@ * }; * Possible flags: * encrypted - password is encrypted (recommended) - * kline_exempt - k/g lines on the cgiirc ip are ignored - * gline_exempt - glines on the cgiirc ip are ignored + * kline_exempt - klines on the cgiirc ip are ignored * dlines are checked on the cgiirc ip (of course). - * k/d/g/x lines, auth blocks, user limits, etc are checked using the + * k/d/x lines, auth blocks, user limits, etc are checked using the * real host/ip. * The password should be specified unencrypted in webirc_password in * cgiirc.config @@ -43,7 +40,7 @@ #include "stdinc.h" #include "client.h" /* client struct */ -#include "irc_string.h" +#include "match.h" #include "hostmask.h" #include "send.h" /* sendto_one */ #include "numeric.h" /* ERR_xxx */ @@ -56,90 +53,134 @@ #include "s_conf.h" #include "reject.h" -static int mr_webirc(struct Client *, struct Client *, int, const char **); +static const char webirc_desc[] = "Adds support for the WebIRC system"; + +static void mr_webirc(struct MsgBuf *msgbuf_p, struct Client *, struct Client *, int, const char **); struct Message webirc_msgtab = { - "WEBIRC", 0, 0, 0, MFLG_SLOW | MFLG_UNREG, + "WEBIRC", 0, 0, 0, 0, {{mr_webirc, 5}, mg_reg, mg_ignore, mg_ignore, mg_ignore, mg_reg} }; mapi_clist_av1 webirc_clist[] = { &webirc_msgtab, NULL }; -DECLARE_MODULE_AV1(webirc, NULL, NULL, webirc_clist, NULL, NULL, "$Revision: 20702 $"); + +static void new_local_user(void *data); +mapi_hfn_list_av1 webirc_hfnlist[] = { + { "new_local_user", (hookfn) new_local_user }, + { NULL, NULL } +}; + +DECLARE_MODULE_AV2(webirc, NULL, NULL, webirc_clist, NULL, webirc_hfnlist, NULL, NULL, webirc_desc); /* * mr_webirc - webirc message handler - * parv[0] = sender prefix * parv[1] = password * parv[2] = fake username (we ignore this) - * parv[3] = fake hostname + * parv[3] = fake hostname * parv[4] = fake ip */ -static int -mr_webirc(struct Client *client_p, struct Client *source_p, int parc, const char *parv[]) +static void +mr_webirc(struct MsgBuf *msgbuf_p, struct Client *client_p, struct Client *source_p, int parc, const char *parv[]) { struct ConfItem *aconf; const char *encr; + struct rb_sockaddr_storage addr; - if (!strchr(parv[4], '.') && !strchr(parv[4], ':')) - { - sendto_one(source_p, "NOTICE * :Invalid IP"); - return 0; - } + int secure = 0; - aconf = find_address_conf(client_p->host, client_p->sockhost, + aconf = find_address_conf(client_p->host, client_p->sockhost, IsGotId(client_p) ? client_p->username : "webirc", IsGotId(client_p) ? client_p->username : "webirc", (struct sockaddr *) &client_p->localClient->ip, - client_p->localClient->ip.ss_family); + GET_SS_FAMILY(&client_p->localClient->ip), NULL); if (aconf == NULL || !(aconf->status & CONF_CLIENT)) - return 0; - if (!IsConfDoSpoofIp(aconf) || irccmp(aconf->name, "webirc.")) + return; + if (!IsConfDoSpoofIp(aconf) || irccmp(aconf->info.name, "webirc.")) { /* XXX */ sendto_one(source_p, "NOTICE * :Not a CGI:IRC auth block"); - return 0; + return; } if (EmptyString(aconf->passwd)) { sendto_one(source_p, "NOTICE * :CGI:IRC auth blocks must have a password"); - return 0; + return; + } + if (!IsSSL(source_p) && aconf->flags & CONF_FLAGS_NEED_SSL) + { + sendto_one(source_p, "NOTICE * :Your CGI:IRC block requires TLS"); + return; } if (EmptyString(parv[1])) encr = ""; else if (IsConfEncrypted(aconf)) - encr = crypt(parv[1], aconf->passwd); + encr = rb_crypt(parv[1], aconf->passwd); else encr = parv[1]; - if (strcmp(encr, aconf->passwd)) + if (encr == NULL || strcmp(encr, aconf->passwd)) { sendto_one(source_p, "NOTICE * :CGI:IRC password incorrect"); - return 0; + return; + } + + if (rb_inet_pton_sock(parv[4], &addr) <= 0) + { + sendto_one(source_p, "NOTICE * :Invalid IP"); + return; + } + + source_p->localClient->ip = addr; + + if (parc >= 6) + { + const char *s; + for (s = parv[5]; s != NULL; (s = strchr(s, ' ')) && s++) + { + if (!ircncmp(s, "secure", 6) && (s[6] == '=' || s[6] == ' ' || s[6] == '\0')) + secure = 1; + } } + if (secure && !IsSSL(source_p)) + { + sendto_one(source_p, "NOTICE * :CGI:IRC is not connected securely; marking you as insecure"); + secure = 0; + } - strlcpy(source_p->sockhost, parv[4], sizeof(source_p->sockhost)); + if (!secure) + { + SetInsecure(source_p); + } + + rb_inet_ntop_sock((struct sockaddr *)&source_p->localClient->ip, source_p->sockhost, sizeof(source_p->sockhost)); if(strlen(parv[3]) <= HOSTLEN) - strlcpy(source_p->host, parv[3], sizeof(source_p->host)); + rb_strlcpy(source_p->host, parv[3], sizeof(source_p->host)); else - strlcpy(source_p->host, source_p->sockhost, sizeof(source_p->host)); - - del_unknown_ip(source_p); - inetpton_sock(parv[4], (struct sockaddr *)&source_p->localClient->ip); - - /* Check dlines now, k/glines will be checked on registration */ - if((aconf = find_dline((struct sockaddr *)&source_p->localClient->ip, - source_p->localClient->ip.ss_family))) + rb_strlcpy(source_p->host, source_p->sockhost, sizeof(source_p->host)); + + /* Check dlines now, klines will be checked on registration */ + if((aconf = find_dline((struct sockaddr *)&source_p->localClient->ip, + GET_SS_FAMILY(&source_p->localClient->ip)))) { if(!(aconf->status & CONF_EXEMPTDLINE)) { exit_client(client_p, source_p, &me, "D-lined"); - return 0; + return; } } sendto_one(source_p, "NOTICE * :CGI:IRC host/IP set to %s %s", parv[3], parv[4]); - return 0; +} + +static void +new_local_user(void *data) +{ + struct Client *source_p = data; + struct ConfItem *aconf = source_p->localClient->att_conf; + + if (!irccmp(aconf->info.name, "webirc.")) + exit_client(source_p, source_p, &me, "Cannot log in using a WEBIRC block"); }