]> git.netwichtig.de Git - user/henk/code/inspircd.git/blob - src/modules/m_dccallow.cpp
m_dccallow Validate tokens before use
[user/henk/code/inspircd.git] / src / modules / m_dccallow.cpp
1 /*
2  * InspIRCd -- Internet Relay Chat Daemon
3  *
4  *   Copyright (C) 2009 Daniel De Graaf <danieldg@inspircd.org>
5  *   Copyright (C) 2008 John Brooks <john.brooks@dereferenced.net>
6  *   Copyright (C) 2008 Pippijn van Steenhoven <pip88nl@gmail.com>
7  *   Copyright (C) 2006-2008 Craig Edwards <craigedwards@brainbox.cc>
8  *   Copyright (C) 2007-2008 Robin Burchell <robin+git@viroteck.net>
9  *   Copyright (C) 2007 Dennis Friis <peavey@inspircd.org>
10  *   Copyright (C) 2006 Jamie ??? <???@???>
11  *
12  * This file is part of InspIRCd.  InspIRCd is free software: you can
13  * redistribute it and/or modify it under the terms of the GNU General Public
14  * License as published by the Free Software Foundation, version 2.
15  *
16  * This program is distributed in the hope that it will be useful, but WITHOUT
17  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
18  * FOR A PARTICULAR PURPOSE.  See the GNU General Public License for more
19  * details.
20  *
21  * You should have received a copy of the GNU General Public License
22  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
23  */
24
25
26 #include "inspircd.h"
27
28 /* $ModDesc: Provides support for the /DCCALLOW command */
29
30 class BannedFileList
31 {
32  public:
33         std::string filemask;
34         std::string action;
35 };
36
37 class DCCAllow
38 {
39  public:
40         std::string nickname;
41         std::string hostmask;
42         time_t set_on;
43         long length;
44
45         DCCAllow() { }
46
47         DCCAllow(const std::string &nick, const std::string &hm, const time_t so, const long ln) : nickname(nick), hostmask(hm), set_on(so), length(ln) { }
48 };
49
50 typedef std::vector<User *> userlist;
51 userlist ul;
52 typedef std::vector<DCCAllow> dccallowlist;
53 dccallowlist* dl;
54 typedef std::vector<BannedFileList> bannedfilelist;
55 bannedfilelist bfl;
56 SimpleExtItem<dccallowlist>* ext;
57
58 class CommandDccallow : public Command
59 {
60  public:
61         CommandDccallow(Module* parent) : Command(parent, "DCCALLOW", 0)
62         {
63                 syntax = "[(+|-)<nick> [<time>]]|[LIST|HELP]";
64                 /* XXX we need to fix this so it can work with translation stuff (i.e. move +- into a seperate param */
65         }
66
67         CmdResult Handle(const std::vector<std::string> &parameters, User *user)
68         {
69                 /* syntax: DCCALLOW [+|-]<nick> (<time>) */
70                 if (!parameters.size())
71                 {
72                         // display current DCCALLOW list
73                         DisplayDCCAllowList(user);
74                         return CMD_FAILURE;
75                 }
76                 else if (parameters.size() > 0)
77                 {
78                         char action = *parameters[0].c_str();
79
80                         // if they didn't specify an action, this is probably a command
81                         if (action != '+' && action != '-')
82                         {
83                                 if (!strcasecmp(parameters[0].c_str(), "LIST"))
84                                 {
85                                         // list current DCCALLOW list
86                                         DisplayDCCAllowList(user);
87                                         return CMD_FAILURE;
88                                 }
89                                 else if (!strcasecmp(parameters[0].c_str(), "HELP"))
90                                 {
91                                         // display help
92                                         DisplayHelp(user);
93                                         return CMD_FAILURE;
94                                 }
95                                 else
96                                 {
97                                         user->WriteNumeric(998, "%s :DCCALLOW command not understood. For help on DCCALLOW, type /DCCALLOW HELP", user->nick.c_str());
98                                         return CMD_FAILURE;
99                                 }
100                         }
101
102                         std::string nick = parameters[0].substr(1);
103                         User *target = ServerInstance->FindNickOnly(nick);
104
105                         if ((target) && (!IS_SERVER(target)) && (!target->quitting) && (target->registered == REG_ALL))
106                         {
107
108                                 if (action == '-')
109                                 {
110                                         // check if it contains any entries
111                                         dl = ext->get(user);
112                                         if (dl)
113                                         {
114                                                 for (dccallowlist::iterator i = dl->begin(); i != dl->end(); ++i)
115                                                 {
116                                                         // search through list
117                                                         if (i->nickname == target->nick)
118                                                         {
119                                                                 dl->erase(i);
120                                                                 user->WriteNumeric(995, "%s %s :Removed %s from your DCCALLOW list", user->nick.c_str(), user->nick.c_str(), target->nick.c_str());
121                                                                 break;
122                                                         }
123                                                 }
124                                         }
125                                 }
126                                 else if (action == '+')
127                                 {
128                                         if (target == user)
129                                         {
130                                                 user->WriteNumeric(996, "%s %s :You cannot add yourself to your own DCCALLOW list!", user->nick.c_str(), user->nick.c_str());
131                                                 return CMD_FAILURE;
132                                         }
133
134                                         dl = ext->get(user);
135                                         if (!dl)
136                                         {
137                                                 dl = new dccallowlist;
138                                                 ext->set(user, dl);
139                                                 // add this user to the userlist
140                                                 ul.push_back(user);
141                                         }
142
143                                         for (dccallowlist::const_iterator k = dl->begin(); k != dl->end(); ++k)
144                                         {
145                                                 if (k->nickname == target->nick)
146                                                 {
147                                                         user->WriteNumeric(996, "%s %s :%s is already on your DCCALLOW list", user->nick.c_str(), user->nick.c_str(), target->nick.c_str());
148                                                         return CMD_FAILURE;
149                                                 }
150                                         }
151
152                                         std::string mask = target->nick+"!"+target->ident+"@"+target->dhost;
153                                         std::string default_length = ServerInstance->Config->ConfValue("dccallow")->getString("length");
154
155                                         long length;
156                                         if (parameters.size() < 2)
157                                         {
158                                                 length = ServerInstance->Duration(default_length);
159                                         }
160                                         else if (!atoi(parameters[1].c_str()))
161                                         {
162                                                 length = 0;
163                                         }
164                                         else
165                                         {
166                                                 length = ServerInstance->Duration(parameters[1]);
167                                         }
168
169                                         if (!ServerInstance->IsValidMask(mask))
170                                         {
171                                                 return CMD_FAILURE;
172                                         }
173
174                                         dl->push_back(DCCAllow(target->nick, mask, ServerInstance->Time(), length));
175
176                                         if (length > 0)
177                                         {
178                                                 user->WriteNumeric(993, "%s %s :Added %s to DCCALLOW list for %ld seconds", user->nick.c_str(), user->nick.c_str(), target->nick.c_str(), length);
179                                         }
180                                         else
181                                         {
182                                                 user->WriteNumeric(994, "%s %s :Added %s to DCCALLOW list for this session", user->nick.c_str(), user->nick.c_str(), target->nick.c_str());
183                                         }
184
185                                         /* route it. */
186                                         return CMD_SUCCESS;
187                                 }
188                         }
189                         else
190                         {
191                                 // nick doesn't exist
192                                 user->WriteNumeric(401, "%s %s :No such nick/channel", user->nick.c_str(), nick.c_str());
193                                 return CMD_FAILURE;
194                         }
195                 }
196                 return CMD_FAILURE;
197         }
198
199         RouteDescriptor GetRouting(User* user, const std::vector<std::string>& parameters)
200         {
201                 return ROUTE_BROADCAST;
202         }
203
204         void DisplayHelp(User* user)
205         {
206                 user->WriteNumeric(998, "%s :DCCALLOW [(+|-)<nick> [<time>]]|[LIST|HELP]", user->nick.c_str());
207                 user->WriteNumeric(998, "%s :You may allow DCCs from specific users by specifying a", user->nick.c_str());
208                 user->WriteNumeric(998, "%s :DCC allow for the user you want to receive DCCs from.", user->nick.c_str());
209                 user->WriteNumeric(998, "%s :For example, to allow the user Brain to send you inspircd.exe", user->nick.c_str());
210                 user->WriteNumeric(998, "%s :you would type:", user->nick.c_str());
211                 user->WriteNumeric(998, "%s :/DCCALLOW +Brain", user->nick.c_str());
212                 user->WriteNumeric(998, "%s :Brain would then be able to send you files. They would have to", user->nick.c_str());
213                 user->WriteNumeric(998, "%s :resend the file again if the server gave them an error message", user->nick.c_str());
214                 user->WriteNumeric(998, "%s :before you added them to your DCCALLOW list.", user->nick.c_str());
215                 user->WriteNumeric(998, "%s :DCCALLOW entries will be temporary by default, if you want to add", user->nick.c_str());
216                 user->WriteNumeric(998, "%s :them to your DCCALLOW list until you leave IRC, type:", user->nick.c_str());
217                 user->WriteNumeric(998, "%s :/DCCALLOW +Brain 0", user->nick.c_str());
218                 user->WriteNumeric(998, "%s :To remove the user from your DCCALLOW list, type:", user->nick.c_str());
219                 user->WriteNumeric(998, "%s :/DCCALLOW -Brain", user->nick.c_str());
220                 user->WriteNumeric(998, "%s :To see the users in your DCCALLOW list, type:", user->nick.c_str());
221                 user->WriteNumeric(998, "%s :/DCCALLOW LIST", user->nick.c_str());
222                 user->WriteNumeric(998, "%s :NOTE: If the user leaves IRC or changes their nickname", user->nick.c_str());
223                 user->WriteNumeric(998, "%s :  they will be removed from your DCCALLOW list.", user->nick.c_str());
224                 user->WriteNumeric(998, "%s :  your DCCALLOW list will be deleted when you leave IRC.", user->nick.c_str());
225                 user->WriteNumeric(999, "%s :End of DCCALLOW HELP", user->nick.c_str());
226
227                 LocalUser* localuser = IS_LOCAL(user);
228                 if (localuser)
229                         localuser->CommandFloodPenalty += 4000;
230         }
231
232         void DisplayDCCAllowList(User* user)
233         {
234                  // display current DCCALLOW list
235                 user->WriteNumeric(990, "%s :Users on your DCCALLOW list:", user->nick.c_str());
236
237                 dl = ext->get(user);
238                 if (dl)
239                 {
240                         for (dccallowlist::const_iterator c = dl->begin(); c != dl->end(); ++c)
241                         {
242                                 user->WriteNumeric(991, "%s %s :%s (%s)", user->nick.c_str(), user->nick.c_str(), c->nickname.c_str(), c->hostmask.c_str());
243                         }
244                 }
245
246                 user->WriteNumeric(992, "%s :End of DCCALLOW list", user->nick.c_str());
247         }
248
249 };
250
251 class ModuleDCCAllow : public Module
252 {
253         CommandDccallow cmd;
254  public:
255
256         ModuleDCCAllow()
257                 : cmd(this)
258         {
259                 ext = NULL;
260         }
261
262         void init()
263         {
264                 ext = new SimpleExtItem<dccallowlist>("dccallow", this);
265                 ServerInstance->Modules->AddService(*ext);
266                 ServerInstance->Modules->AddService(cmd);
267                 ReadFileConf();
268                 Implementation eventlist[] = { I_OnUserPreMessage, I_OnUserPreNotice, I_OnUserQuit, I_OnUserPostNick, I_OnRehash };
269                 ServerInstance->Modules->Attach(eventlist, this, sizeof(eventlist)/sizeof(Implementation));
270         }
271
272         virtual void OnRehash(User* user)
273         {
274                 ReadFileConf();
275         }
276
277         virtual void OnUserQuit(User* user, const std::string &reason, const std::string &oper_message)
278         {
279                 dccallowlist* udl = ext->get(user);
280
281                 // remove their DCCALLOW list if they have one
282                 if (udl)
283                 {
284                         userlist::iterator it = std::find(ul.begin(), ul.end(), user);
285                         if (it != ul.end())
286                                 ul.erase(it);
287                 }
288
289                 // remove them from any DCCALLOW lists
290                 // they are currently on
291                 RemoveNick(user);
292         }
293
294         virtual void OnUserPostNick(User* user, const std::string &oldnick)
295         {
296                 RemoveNick(user);
297         }
298
299         virtual ModResult OnUserPreMessage(User* user, void* dest, int target_type, std::string &text, char status, CUList &exempt_list)
300         {
301                 return OnUserPreNotice(user, dest, target_type, text, status, exempt_list);
302         }
303
304         virtual ModResult OnUserPreNotice(User* user, void* dest, int target_type, std::string &text, char status, CUList &exempt_list)
305         {
306                 if (!IS_LOCAL(user))
307                         return MOD_RES_PASSTHRU;
308
309                 if (target_type == TYPE_USER)
310                 {
311                         User* u = (User*)dest;
312
313                         /* Always allow a user to dcc themselves (although... why?) */
314                         if (user == u)
315                                 return MOD_RES_PASSTHRU;
316
317                         if ((text.length()) && (text[0] == '\1'))
318                         {
319                                 Expire();
320
321                                 // :jamie!jamie@test-D4457903BA652E0F.silverdream.org PRIVMSG eimaj :DCC SEND m_dnsbl.cpp 3232235786 52650 9676
322                                 // :jamie!jamie@test-D4457903BA652E0F.silverdream.org PRIVMSG eimaj :VERSION
323
324                                 if (strncmp(text.c_str(), "\1DCC ", 5) == 0)
325                                 {
326                                         dl = ext->get(u);
327                                         if (dl && dl->size())
328                                         {
329                                                 for (dccallowlist::const_iterator iter = dl->begin(); iter != dl->end(); ++iter)
330                                                         if (InspIRCd::Match(user->GetFullHost(), iter->hostmask))
331                                                                 return MOD_RES_PASSTHRU;
332                                         }
333
334                                         // tokenize
335                                         std::stringstream ss(text);
336                                         std::string buf;
337                                         std::vector<std::string> tokens;
338
339                                         while (ss >> buf)
340                                                 tokens.push_back(buf);
341
342                                         if (tokens.size() < 2)
343                                                 return MOD_RES_PASSTHRU;
344
345                                         irc::string type = tokens[1].c_str();
346
347                                         ConfigTag* conftag = ServerInstance->Config->ConfValue("dccallow");
348                                         bool blockchat = conftag->getBool("blockchat");
349
350                                         if (type == "SEND")
351                                         {
352                                                 if (tokens.size() < 3)
353                                                         return MOD_RES_PASSTHRU;
354
355                                                 std::string defaultaction = conftag->getString("action");
356                                                 std::string filename = tokens[2];
357
358                                                 bool found = false;
359                                                 for (unsigned int i = 0; i < bfl.size(); i++)
360                                                 {
361                                                         if (InspIRCd::Match(filename, bfl[i].filemask, ascii_case_insensitive_map))
362                                                         {
363                                                                 /* We have a matching badfile entry, override whatever the default action is */
364                                                                 if (bfl[i].action == "allow")
365                                                                         return MOD_RES_PASSTHRU;
366                                                                 else
367                                                                 {
368                                                                         found = true;
369                                                                         break;
370                                                                 }
371                                                         }
372                                                 }
373
374                                                 /* only follow the default action if no badfile matches were found above */
375                                                 if ((!found) && (defaultaction == "allow"))
376                                                         return MOD_RES_PASSTHRU;
377
378                                                 user->WriteServ("NOTICE %s :The user %s is not accepting DCC SENDs from you. Your file %s was not sent.", user->nick.c_str(), u->nick.c_str(), filename.c_str());
379                                                 u->WriteServ("NOTICE %s :%s (%s@%s) attempted to send you a file named %s, which was blocked.", u->nick.c_str(), user->nick.c_str(), user->ident.c_str(), user->dhost.c_str(), filename.c_str());
380                                                 u->WriteServ("NOTICE %s :If you trust %s and were expecting this, you can type /DCCALLOW HELP for information on the DCCALLOW system.", u->nick.c_str(), user->nick.c_str());
381                                                 return MOD_RES_DENY;
382                                         }
383                                         else if ((type == "CHAT") && (blockchat))
384                                         {
385                                                 user->WriteServ("NOTICE %s :The user %s is not accepting DCC CHAT requests from you.", user->nick.c_str(), u->nick.c_str());
386                                                 u->WriteServ("NOTICE %s :%s (%s@%s) attempted to initiate a DCC CHAT session, which was blocked.", u->nick.c_str(), user->nick.c_str(), user->ident.c_str(), user->dhost.c_str());
387                                                 u->WriteServ("NOTICE %s :If you trust %s and were expecting this, you can type /DCCALLOW HELP for information on the DCCALLOW system.", u->nick.c_str(), user->nick.c_str());
388                                                 return MOD_RES_DENY;
389                                         }
390                                 }
391                         }
392                 }
393                 return MOD_RES_PASSTHRU;
394         }
395
396         void Expire()
397         {
398                 for (userlist::iterator iter = ul.begin(); iter != ul.end();)
399                 {
400                         User* u = (User*)(*iter);
401                         dl = ext->get(u);
402                         if (dl)
403                         {
404                                 if (dl->size())
405                                 {
406                                         dccallowlist::iterator iter2 = dl->begin();
407                                         while (iter2 != dl->end())
408                                         {
409                                                 if (iter2->length != 0 && (iter2->set_on + iter2->length) <= ServerInstance->Time())
410                                                 {
411                                                         u->WriteNumeric(997, "%s %s :DCCALLOW entry for %s has expired", u->nick.c_str(), u->nick.c_str(), iter2->nickname.c_str());
412                                                         iter2 = dl->erase(iter2);
413                                                 }
414                                                 else
415                                                 {
416                                                         ++iter2;
417                                                 }
418                                         }
419                                 }
420                                 ++iter;
421                         }
422                         else
423                         {
424                                 iter = ul.erase(iter);
425                         }
426                 }
427         }
428
429         void RemoveNick(User* user)
430         {
431                 /* Iterate through all DCCALLOW lists and remove user */
432                 for (userlist::iterator iter = ul.begin(); iter != ul.end();)
433                 {
434                         User *u = (User*)(*iter);
435                         dl = ext->get(u);
436                         if (dl)
437                         {
438                                 if (dl->size())
439                                 {
440                                         for (dccallowlist::iterator i = dl->begin(); i != dl->end(); ++i)
441                                         {
442                                                 if (i->nickname == user->nick)
443                                                 {
444
445                                                         u->WriteServ("NOTICE %s :%s left the network or changed their nickname and has been removed from your DCCALLOW list", u->nick.c_str(), i->nickname.c_str());
446                                                         u->WriteNumeric(995, "%s %s :Removed %s from your DCCALLOW list", u->nick.c_str(), u->nick.c_str(), i->nickname.c_str());
447                                                         dl->erase(i);
448                                                         break;
449                                                 }
450                                         }
451                                 }
452                                 ++iter;
453                         }
454                         else
455                         {
456                                 iter = ul.erase(iter);
457                         }
458                 }
459         }
460
461         void RemoveFromUserlist(User *user)
462         {
463                 // remove user from userlist
464                 for (userlist::iterator j = ul.begin(); j != ul.end(); ++j)
465                 {
466                         User* u = (User*)(*j);
467                         if (u == user)
468                         {
469                                 ul.erase(j);
470                                 break;
471                         }
472                 }
473         }
474
475         void ReadFileConf()
476         {
477                 bfl.clear();
478                 ConfigTagList tags = ServerInstance->Config->ConfTags("banfile");
479                 for (ConfigIter i = tags.first; i != tags.second; ++i)
480                 {
481                         BannedFileList bf;
482                         bf.filemask = i->second->getString("pattern");
483                         bf.action = i->second->getString("action");
484                         bfl.push_back(bf);
485                 }
486         }
487
488         virtual ~ModuleDCCAllow()
489         {
490                 delete ext;
491         }
492
493         virtual Version GetVersion()
494         {
495                 return Version("Provides support for the /DCCALLOW command", VF_COMMON | VF_VENDOR);
496         }
497 };
498
499 MODULE_INIT(ModuleDCCAllow)