/
imapauth.cpp
167 lines (134 loc) · 4.04 KB
/
imapauth.cpp
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
/*
* Copyright (C) 2004-2014 ZNC, see the NOTICE file for details.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
#include <znc/znc.h>
using std::map;
class CIMAPAuthMod;
class CIMAPSock : public CSocket {
public:
CIMAPSock(CIMAPAuthMod* pModule, CSmartPtr<CAuthBase> Auth)
: CSocket((CModule*) pModule), m_spAuth(Auth) {
m_pIMAPMod = pModule;
m_bSentReply = false;
m_bSentLogin = false;
EnableReadLine();
}
virtual ~CIMAPSock() {
if (!m_bSentReply) {
m_spAuth->RefuseLogin("IMAP server is down, please try again later");
}
}
virtual void ReadLine(const CString& sLine);
private:
protected:
CIMAPAuthMod* m_pIMAPMod;
bool m_bSentLogin;
bool m_bSentReply;
CSmartPtr<CAuthBase> m_spAuth;
};
class CIMAPAuthMod : public CModule {
public:
MODCONSTRUCTOR(CIMAPAuthMod) {
m_Cache.SetTTL(60000);
m_sServer = "localhost";
m_uPort = 143;
m_bSSL = false;
}
virtual ~CIMAPAuthMod() {}
virtual bool OnBoot() {
return true;
}
virtual bool OnLoad(const CString& sArgs, CString& sMessage) {
if (sArgs.Trim_n().empty()) {
return true; // use defaults
}
m_sServer = sArgs.Token(0);
CString sPort = sArgs.Token(1);
m_sUserFormat = sArgs.Token(2);
if (sPort.Left(1) == "+") {
m_bSSL = true;
sPort.LeftChomp();
}
unsigned short uPort = sPort.ToUShort();
if (uPort) {
m_uPort = uPort;
}
return true;
}
virtual EModRet OnLoginAttempt(CSmartPtr<CAuthBase> Auth) {
CUser* pUser = CZNC::Get().FindUser(Auth->GetUsername());
if (!pUser) { // @todo Will want to do some sort of && !m_bAllowCreate in the future
Auth->RefuseLogin("Invalid User - Halting IMAP Lookup");
return HALT;
}
if (pUser && m_Cache.HasItem(CString(Auth->GetUsername() + ":" + Auth->GetPassword()).MD5())) {
DEBUG("+++ Found in cache");
Auth->AcceptLogin(*pUser);
return HALT;
}
CIMAPSock* pSock = new CIMAPSock(this, Auth);
pSock->Connect(m_sServer, m_uPort, m_bSSL, 20);
return HALT;
}
virtual void OnModCommand(const CString& sLine) {
}
void CacheLogin(const CString& sLogin) {
m_Cache.AddItem(sLogin);
}
// Getters
const CString& GetUserFormat() const { return m_sUserFormat; }
// !Getters
private:
// Settings
CString m_sServer;
unsigned short m_uPort;
bool m_bSSL;
CString m_sUserFormat;
// !Settings
TCacheMap<CString> m_Cache;
};
void CIMAPSock::ReadLine(const CString& sLine) {
if (!m_bSentLogin) {
CString sUsername = m_spAuth->GetUsername();
m_bSentLogin = true;
const CString& sFormat = m_pIMAPMod->GetUserFormat();
if (!sFormat.empty()) {
if (sFormat.find('%') != CString::npos) {
sUsername = sFormat.Replace_n("%", sUsername);
} else {
sUsername += sFormat;
}
}
Write("AUTH LOGIN " + sUsername + " " + m_spAuth->GetPassword() + "\r\n");
} else if (sLine.Left(5) == "AUTH ") {
CUser* pUser = CZNC::Get().FindUser(m_spAuth->GetUsername());
if (pUser && sLine.Equals("AUTH OK", false, 7)) {
m_spAuth->AcceptLogin(*pUser);
m_pIMAPMod->CacheLogin(CString(m_spAuth->GetUsername() + ":" + m_spAuth->GetPassword()).MD5()); // Use MD5 so passes don't sit in memory in plain text
DEBUG("+++ Successful IMAP lookup");
} else {
m_spAuth->RefuseLogin("Invalid Password");
DEBUG("--- FAILED IMAP lookup");
}
m_bSentReply = true;
Close();
}
}
template<> void TModInfo<CIMAPAuthMod>(CModInfo& Info) {
Info.SetWikiPage("imapauth");
Info.SetHasArgs(true);
Info.SetArgsHelpText("[ server [+]port [ UserFormatString ] ]");
}
GLOBALMODULEDEFS(CIMAPAuthMod, "Allow users to authenticate via imap")