2016-08-25 09:45:05 +02:00
|
|
|
"""
|
|
|
|
permissions.py - Permissions Abstraction for PyLink IRC Services.
|
|
|
|
"""
|
|
|
|
|
|
|
|
from collections import defaultdict
|
|
|
|
import threading
|
|
|
|
|
|
|
|
# Global variables: these store mappings of hostmasks/exttargets to lists of permissions each target has.
|
|
|
|
default_permissions = defaultdict(set)
|
2016-08-31 22:32:21 +02:00
|
|
|
permissions = defaultdict(set)
|
2016-08-25 09:45:05 +02:00
|
|
|
|
|
|
|
# Only allow one thread to change the permissions index at once.
|
|
|
|
permissions_lock = threading.Lock()
|
|
|
|
|
|
|
|
from pylinkirc import conf, utils
|
|
|
|
from pylinkirc.log import log
|
|
|
|
|
|
|
|
def resetPermissions():
|
|
|
|
"""
|
|
|
|
Loads the permissions specified in the permissions: block of the PyLink configuration,
|
|
|
|
if such a block exists. Otherwise, fallback to the default permissions specified by plugins.
|
|
|
|
"""
|
|
|
|
with permissions_lock:
|
|
|
|
global permissions
|
|
|
|
log.debug('permissions.resetPermissions: old perm list: %s', permissions)
|
2016-08-25 20:41:37 +02:00
|
|
|
|
2016-08-25 21:07:55 +02:00
|
|
|
new_permissions = default_permissions.copy()
|
|
|
|
log.debug('permissions.resetPermissions: new_permissions %s', new_permissions)
|
2016-08-25 20:41:37 +02:00
|
|
|
if not conf.conf.get('permissions_merge_defaults', True):
|
|
|
|
log.debug('permissions.resetPermissions: clearing perm list due to permissions_merge_defaults set False.')
|
2016-08-25 21:07:55 +02:00
|
|
|
new_permissions.clear()
|
2016-08-25 20:41:37 +02:00
|
|
|
|
2016-08-25 21:07:55 +02:00
|
|
|
# Convert all perm lists to sets.
|
|
|
|
for k, v in conf.conf.get('permissions', {}).items():
|
|
|
|
new_permissions[k] |= set(v)
|
|
|
|
|
|
|
|
log.debug('permissions.resetPermissions: new_permissions %s', new_permissions)
|
|
|
|
permissions.clear()
|
|
|
|
permissions.update(new_permissions)
|
2016-08-25 09:45:05 +02:00
|
|
|
log.debug('permissions.resetPermissions: new perm list: %s', permissions)
|
|
|
|
|
|
|
|
def addDefaultPermissions(perms):
|
|
|
|
"""Adds default permissions to the index."""
|
|
|
|
with permissions_lock:
|
2016-08-25 21:07:36 +02:00
|
|
|
global default_permissions
|
2016-08-25 09:45:05 +02:00
|
|
|
for target, permlist in perms.items():
|
2016-08-25 21:07:36 +02:00
|
|
|
default_permissions[target] |= set(permlist)
|
2016-08-25 09:45:05 +02:00
|
|
|
|
|
|
|
def removeDefaultPermissions(perms):
|
|
|
|
"""Remove default permissions from the index."""
|
|
|
|
with permissions_lock:
|
2016-08-25 21:07:36 +02:00
|
|
|
global default_permissions
|
2016-08-25 09:45:05 +02:00
|
|
|
for target, permlist in perms.items():
|
2016-08-25 21:07:36 +02:00
|
|
|
default_permissions[target] -= set(permlist)
|
2016-08-25 09:45:05 +02:00
|
|
|
|
2016-08-25 20:41:37 +02:00
|
|
|
def checkPermissions(irc, uid, perms, also_show=[]):
|
2016-08-25 09:45:05 +02:00
|
|
|
"""
|
|
|
|
Checks permissions of the caller. If the caller has any of the permissions listed in perms,
|
|
|
|
this function returns True. Otherwise, NotAuthorizedError is raised.
|
|
|
|
"""
|
2016-12-10 05:51:04 +01:00
|
|
|
# For old (< 1.1 login blocks):
|
2016-08-31 22:32:21 +02:00
|
|
|
# If the user is logged in, they automatically have all permissions.
|
2017-06-30 08:01:39 +02:00
|
|
|
if irc.match_host('$pylinkacc', uid) and conf.conf['login'].get('user'):
|
2016-12-10 05:51:04 +01:00
|
|
|
log.debug('permissions: overriding permissions check for old-style admin user %s',
|
2017-06-30 08:01:39 +02:00
|
|
|
irc.get_hostmask(uid))
|
2016-08-31 22:32:21 +02:00
|
|
|
return True
|
|
|
|
|
2016-08-25 09:45:05 +02:00
|
|
|
# Iterate over all hostmask->permission list mappings.
|
|
|
|
for host, permlist in permissions.copy().items():
|
2016-08-25 09:56:13 +02:00
|
|
|
log.debug('permissions: permlist for %s: %s', host, permlist)
|
2017-06-30 08:01:39 +02:00
|
|
|
if irc.match_host(host, uid):
|
2016-08-25 09:45:05 +02:00
|
|
|
# Now, iterate over all the perms we are looking for.
|
2016-08-25 09:56:13 +02:00
|
|
|
for perm in permlist:
|
2017-06-30 08:01:39 +02:00
|
|
|
# Use irc.match_host to expand globs in an IRC-case insensitive and wildcard
|
2016-08-25 09:45:05 +02:00
|
|
|
# friendly way. e.g. 'xyz.*.#Channel\' will match 'xyz.manage.#channel|' on IRCds
|
|
|
|
# using the RFC1459 casemapping.
|
2016-08-25 09:56:13 +02:00
|
|
|
log.debug('permissions: checking if %s glob matches anything in %s', perm, permlist)
|
2017-06-30 08:01:39 +02:00
|
|
|
if any(irc.match_host(perm, p) for p in perms):
|
2016-08-25 09:45:05 +02:00
|
|
|
return True
|
|
|
|
raise utils.NotAuthorizedError("You are missing one of the following permissions: %s" %
|
2016-08-25 20:41:37 +02:00
|
|
|
(', '.join(perms+also_show)))
|