Compare commits

..

11 Commits

Author SHA1 Message Date
a126b9732d Merge pull request 'Include ref to old version and misc updates' (#8) from update/readme into master
Reviewed-on: pratyush/ircWebRegistration#8
2023-03-20 09:07:25 +01:00
acf4dce66f
Include ref to old version and misc
Signed-off-by: Pratyush Desai <pratyush.desai@liberta.casa>
2023-03-20 13:28:58 +05:30
12297a3de8 Merge pull request 'Fixing the logic for draft/account-registration=before-connect' (#7) from before-connect into master
Reviewed-on: pratyush/ircWebRegistration#7
2023-03-20 08:10:59 +01:00
c004701edf
Rewrite the logic for 'before-connect' key
Signed-off-by: Pratyush Desai <pratyush.desai@liberta.casa>
2023-03-20 12:28:01 +05:30
c4c53ea5df
merge conflict 2022-08-31 19:38:42 +05:30
6ad857ed29
try before connect logic 2022-08-31 17:34:32 +05:30
242acac3f1 Upload LICENSE 2022-08-25 19:03:28 +02:00
bce189246c Merge pull request 'minor fixes qol' (#6) from devel into master
Reviewed-on: pratyush/ircWebRegistration#6
2022-04-16 15:58:19 +02:00
a6a94d1602
minor fixes qol 2022-04-16 19:18:20 +05:30
95430ca9da Merge pull request 'Update link to the draft/account-registration spec' (#3) from val/ircWebRegistration:update-spec-link into master
Reviewed-on: pratyush/ircWebRegistration#3
2022-04-01 20:57:26 +02:00
Valentin Lorentz
981306668a Update link to the draft/account-registration spec 2022-04-01 18:24:44 +02:00
6 changed files with 58 additions and 57 deletions

13
LICENSE Normal file
View File

@ -0,0 +1,13 @@
Copyright (c) 2021-2022 Pratyush Desai and others
All rights reserved.
Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
Redistributions of source code must retain the above copyright notice, this list of conditions, and the following disclaimer.
Redistributions in binary form must reproduce the above copyright notice, this list of conditions, and the following disclaimer in the documentation and/or other materials provided with the distribution.
Neither the name of the author of this software nor the name of contributors to this software may be used to endorse or promote products derived from this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Portions of the included source code are copyright by its original author(s) and remain subject to its associated license.

View File

@ -1,12 +1,21 @@
# IRC Web Registration
## Version 1
The v1 of this concept can be referenced in the [old and *not updated* README](https://git.com.de/LibertaCasa/webreg/src/branch/master/README.old.md)
The v1.1 enhancements added by [Georg Pfuetzenreuter](https://git.com.de/Georg) implements support for additional SSO integration to our KeyCloak setup.
It also works-in SSL support.
This webform available [here](https://liberta.casa/register) is purely demonstrative and does not successfully `POST` user data
## Introduction
This is a basic still WIP framework for registering an account on an ircd using a webform.
This is a basic still WIP overhaul framework for registering an account on an ircd using a webform that is referenced above.
## Features
- It relies on the WIP IRCv3.2 spec [draft/account-registration](https://github.com/ProgVal/ircv3-specifications/blob/register/extensions/account-registration.md)
- It relies on the draft IRCv3 spec [draft/account-registration](https://ircv3.net/specs/extensions/account-registration.html)
- It utilizes the flask framework and `WEBIRC` to relay remote host ip address.
- Can be tweaked to allow registration attempts from exit-nodes and other unsavory hosts allowing them to securely work with the `require-sasl` constraint if needed.
@ -24,8 +33,10 @@ It is recommended to work within a virtual environment.
## Installation and Setup
Todo!
Todo! Refer to the issues and the __Milestones__ and __Projects__
for more
### Note
Only works with setups not requiring verification at this moment.
Only works with setups not requiring verification at this moment as stated in #4

View File

@ -33,6 +33,9 @@ def register():
flash("Illegal Character in Username. Please choose a different one one.")
elif response == "ERR_NICKNAMEINUSE":
flash("Username already taken. Please choose a different one!")
elif response == "CAP_REFUSED":
flash("This IRCd doesn't support the draft/account-registration capability")
return redirect(webchat_url)
elif response == "SUCCESS":
return redirect(webchat_url)
else:

View File

@ -4,6 +4,7 @@ from wtforms.validators import DataRequired, Length, EqualTo
class RegistrationForm(FlaskForm):
# clarify that it conforms with casemapping on ircd.
username = StringField('Username', validators=[DataRequired(), Length(min=1, max=32)])
password = PasswordField('Password', validators=[DataRequired()])
confirm_password = PasswordField('Confirm Password', validators=[DataRequired(), EqualTo('password')])

View File

@ -5,72 +5,55 @@ import os
webircpass = os.getenv("WEBIRC_PASS")
def ircregister(userip, username, password, email="*"):
d = irctokens.StatefulDecoder()
e = irctokens.StatefulEncoder()
s = socket.socket()
# Here we assume using this only on localhost i.e. loopback
s.connect(("127.0.0.1", 6667))
# define the send function
def _send(line):
print(f"> {line.format()}")
e.push(line)
while e.pending():
e.pop(s.send(e.pending()))
# Registering connection
# WEBIRC
_send(irctokens.build("WEBIRC", [ webircpass, "WebregGateway", userip, userip, "secure"]))
# Check for "ERROR :Invalid WebIRC password"
# Should all of this this be under a try except block?
lines = d.push(s.recv(1024))
if lines == None:
print("!disconnected")
return "disconnected"
elif lines.command == "ERROR" and lines.params == "Invalid WebIRC password":
return "WebIRC bad password"
# Inform the server that we support
# CAP 3.2
_send(irctokens.build("CAP", ["LS", "302"]))
# REGISTER can be attempted before-connect if server supports
# but if the server responds with the corresponding FAIL we
# need to try again. We can also handle email-required using
# the same keys. How to access these key-value pairs?
# reference: https://github.com/ProgVal/ircv3-specifications/blob/register/extensions/account-registration.md#commands
# NICK and USER
_send(irctokens.build("USER", ["u", "0", "*", username]))
_send(irctokens.build("NICK", [username]))
# go through all cases
while True:
lines = d.push(s.recv(1024))
if lines == None:
print("! disconnected")
break
for line in lines:
print(f"< {line.format()}")
if line.command == "432":
return "ERR_ERRONEUSNICKNAME"
elif line.command == "433":
return "ERR_NICKNAMEINUSE"
_send(irctokens.build("CAP", ["REQ", "draft/account-registration"]))
# REGISTER can be attempted before-connect if server supports
# but if the server responds with the corresponding FAIL we
# need to try again. We can also handle email-required using
# the same keys. How to access these key-value pairs?
# reference: https://ircv3.net/specs/extensions/account-registration.html
# do we handle if email-req but not before-connect
# also how about when `custom-account-name` may be a value
if 'draft/account-registration=before-connect' in line.params:
_send(irctokens.build("CAP", ["REQ", "draft/account-registration"]))
if line.command == "CAP" and ("NAK" in line.params):
return "cap refused"
return "CAP_REFUSED"
elif line.command == "CAP" and ("ACK" in line.params):
to_send = irctokens.build("CAP", ["END"])
_send(to_send)
if line.command == "PING":
to_send = irctokens.build("PONG", [line.params[0]])
_send(to_send)
if line.command == "001":
# assuming no verif reqd.
to_send = irctokens.build("REGISTER", ["*", email, password])
_send(to_send)
_send(irctokens.build("CAP", ["END"]))
_send(irctokens.build("USER", ["u", "0", "*", username]))
_send(irctokens.build("NICK", [username]))
if line.command == "432":
return "ERR_ERRONEUSNICKNAME"
if line.command == "433":
return "ERR_NICKNAMEINUSE"
_send(irctokens.build("REGISTER", [username, "*", password]))
if line.command == "REGISTER" and ("SUCCESS" in line.params):
to_send = irctokens.build("QUIT")
_send(to_send)
_send(irctokens.build("QUIT"))
return "SUCCESS"

View File

@ -1,10 +0,0 @@
click==8.0.1
Flask==2.0.1
Flask-WTF==0.15.1
gunicorn==20.1.0
irctokens==2.0.0
itsdangerous==2.0.1
Jinja2==3.0.1
MarkupSafe==2.0.1
Werkzeug==2.0.1
WTForms==2.3.3