Compare commits

..

2 Commits

Author SHA1 Message Date
1c75877f87
template info 2022-04-16 20:46:43 +05:30
c9275c10c6
uwsginginx deploy docs 2022-04-16 20:40:47 +05:30
5 changed files with 95 additions and 53 deletions

40
DEPLOY.md Normal file
View File

@ -0,0 +1,40 @@
# Deploying
Deploy using nginx + uwsgi with an init system.
## Resources
* [flask-docs](https://flask.palletsprojects.com/en/2.1.x/deploying/uwsgi/)
## Procedure
### templates
* Update the templates for `/register` and `/verify` paths.
### uwsgi commands and notes
* `$ uwsgi -s /tmp/yourapplication.sock --manage-script-name --mount /yourapplication=myapp:app`
* If you want to deploy your flask application inside of a virtual environment, you need to also add --virtualenv /path/to/virtual/environment. You might also need to add --plugin python or --plugin python3 depending on which python version you use for your project.
### Nginx Config
The Usual - This configuration binds the application to /yourapplication.
```location = /yourapplication { rewrite ^ /yourapplication/; }
location /yourapplication { try_files $uri @yourapplication; }
location @yourapplication {
include uwsgi_params;
uwsgi_pass unix:/tmp/yourapplication.sock;
}
```
If you want to have it in the URL root its a bit simpler:
```location / { try_files $uri @yourapplication; }
location @yourapplication {
include uwsgi_params;
uwsgi_pass unix:/tmp/yourapplication.sock;
}
```

13
LICENSE
View File

@ -1,13 +0,0 @@
Copyright (c) 2021-2022 Pratyush Desai and others
All rights reserved.
Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
Redistributions of source code must retain the above copyright notice, this list of conditions, and the following disclaimer.
Redistributions in binary form must reproduce the above copyright notice, this list of conditions, and the following disclaimer in the documentation and/or other materials provided with the distribution.
Neither the name of the author of this software nor the name of contributors to this software may be used to endorse or promote products derived from this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Portions of the included source code are copyright by its original author(s) and remain subject to its associated license.

View File

@ -1,21 +1,12 @@
# IRC Web Registration
## Version 1
The v1 of this concept can be referenced in the [old and *not updated* README](https://git.com.de/LibertaCasa/webreg/src/branch/master/README.old.md)
The v1.1 enhancements added by [Georg Pfuetzenreuter](https://git.com.de/Georg) implements support for additional SSO integration to our KeyCloak setup.
It also works-in SSL support.
This webform available [here](https://liberta.casa/register) is purely demonstrative and does not successfully `POST` user data
## Introduction
This is a basic still WIP overhaul framework for registering an account on an ircd using a webform that is referenced above.
This is a basic still WIP framework for registering an account on an ircd using a webform.
## Features
- It relies on the draft IRCv3 spec [draft/account-registration](https://ircv3.net/specs/extensions/account-registration.html)
- It relies on the WIP IRCv3.2 spec [draft/account-registration](https://github.com/ProgVal/ircv3-specifications/blob/register/extensions/account-registration.md)
- It utilizes the flask framework and `WEBIRC` to relay remote host ip address.
- Can be tweaked to allow registration attempts from exit-nodes and other unsavory hosts allowing them to securely work with the `require-sasl` constraint if needed.
@ -33,10 +24,8 @@ It is recommended to work within a virtual environment.
## Installation and Setup
Todo! Refer to the issues and the __Milestones__ and __Projects__
for more
Todo!
### Note
Only works with setups not requiring verification at this moment as stated in #4
Only works with setups not requiring verification at this moment.

View File

@ -5,55 +5,72 @@ import os
webircpass = os.getenv("WEBIRC_PASS")
def ircregister(userip, username, password, email="*"):
d = irctokens.StatefulDecoder()
e = irctokens.StatefulEncoder()
s = socket.socket()
# Here we assume using this only on localhost i.e. loopback
s.connect(("127.0.0.1", 6667))
# define the send function
def _send(line):
print(f"> {line.format()}")
e.push(line)
while e.pending():
e.pop(s.send(e.pending()))
# Registering connection
# WEBIRC
_send(irctokens.build("WEBIRC", [ webircpass, "WebregGateway", userip, userip, "secure"]))
# Check for "ERROR :Invalid WebIRC password"
# Should all of this this be under a try except block?
lines = d.push(s.recv(1024))
if lines == None:
print("!disconnected")
return "disconnected"
elif lines.command == "ERROR" and lines.params == "Invalid WebIRC password":
return "WebIRC bad password"
# Inform the server that we support
# CAP 3.2
_send(irctokens.build("CAP", ["LS", "302"]))
while True:
lines = d.push(s.recv(1024))
if lines == None:
print("! disconnected")
break
for line in lines:
print(f"< {line.format()}")
# REGISTER can be attempted before-connect if server supports
# but if the server responds with the corresponding FAIL we
# need to try again. We can also handle email-required using
# the same keys. How to access these key-value pairs?
# reference: https://ircv3.net/specs/extensions/account-registration.html
# do we handle if email-req but not before-connect
# also how about when `custom-account-name` may be a value
if 'draft/account-registration=before-connect' in line.params:
# reference: https://github.com/ProgVal/ircv3-specifications/blob/register/extensions/account-registration.md#commands
# NICK and USER
_send(irctokens.build("USER", ["u", "0", "*", username]))
_send(irctokens.build("NICK", [username]))
# go through all cases
while True:
for line in lines:
print(f"< {line.format()}")
if line.command == "432":
return "ERR_ERRONEUSNICKNAME"
elif line.command == "433":
return "ERR_NICKNAMEINUSE"
_send(irctokens.build("CAP", ["REQ", "draft/account-registration"]))
if line.command == "CAP" and ("NAK" in line.params):
return "CAP_REFUSED"
elif line.command == "CAP" and ("ACK" in line.params):
_send(irctokens.build("CAP", ["END"]))
_send(irctokens.build("USER", ["u", "0", "*", username]))
_send(irctokens.build("NICK", [username]))
if line.command == "432":
return "ERR_ERRONEUSNICKNAME"
if line.command == "433":
return "ERR_NICKNAMEINUSE"
_send(irctokens.build("REGISTER", [username, "*", password]))
to_send = irctokens.build("CAP", ["END"])
_send(to_send)
if line.command == "PING":
to_send = irctokens.build("PONG", [line.params[0]])
_send(to_send)
if line.command == "001":
# assuming no verif reqd.
to_send = irctokens.build("REGISTER", ["*", email, password])
_send(to_send)
if line.command == "REGISTER" and ("SUCCESS" in line.params):
_send(irctokens.build("QUIT"))
to_send = irctokens.build("QUIT")
_send(to_send)
return "SUCCESS"

9
requirements.txt Normal file
View File

@ -0,0 +1,9 @@
click==8.0.1
Flask==2.0.1
Flask-WTF==0.15.1
irctokens==2.0.0
itsdangerous==2.0.1
Jinja2==3.0.1
MarkupSafe==2.0.1
Werkzeug==2.0.1
WTForms==2.3.3