]> code.citadel.org Git - citadel.git/blob - citadel/user_ops.c
chainsaw tendencies
[citadel.git] / citadel / user_ops.c
1 /* $Id$ */
2
3 /* needed to properly enable crypt() stuff on some systems */
4 #define _XOPEN_SOURCE
5 /* needed for str[n]casecmp() on some systems if the above is defined */
6 #define _XOPEN_SOURCE_EXTENDED
7 /* needed to enable threads on some systems if the above are defined */
8 #define _POSIX_C_SOURCE 199506L
9
10 #include <stdlib.h>
11 #include <unistd.h>
12 #include <stdio.h>
13 #include <fcntl.h>
14 #include <signal.h>
15 #include <pwd.h>
16 #include <sys/types.h>
17 #include <sys/time.h>
18 #include <string.h>
19 #include <syslog.h>
20 #include <limits.h>
21 #include <pthread.h>
22 #include "citadel.h"
23 #include "server.h"
24 #include "database.h"
25 #include "user_ops.h"
26 #include "sysdep_decls.h"
27 #include "support.h"
28 #include "room_ops.h"
29 #include "logging.h"
30 #include "file_ops.h"
31 #include "control.h"
32 #include "msgbase.h"
33 #include "config.h"
34 #include "dynloader.h"
35 #include "sysdep.h"
36
37
38 /*
39  * getuser()  -  retrieve named user into supplied buffer.
40  *               returns 0 on success
41  */
42 int getuser(struct usersupp *usbuf, char name[]) {
43
44         char lowercase_name[32];
45         int a;
46         struct cdbdata *cdbus;
47
48         bzero(usbuf, sizeof(struct usersupp));
49         for (a=0; a<=strlen(name); ++a) {
50                 lowercase_name[a] = tolower(name[a]);
51                 }
52
53         cdbus = cdb_fetch(CDB_USERSUPP, lowercase_name, strlen(lowercase_name));
54         if (cdbus == NULL) {
55                 return(1);      /* user not found */
56                 }
57
58         memcpy(usbuf, cdbus->ptr,
59                 ( (cdbus->len > sizeof(struct usersupp)) ?
60                 sizeof(struct usersupp) : cdbus->len) );
61         cdb_free(cdbus);
62         return(0);
63         }
64
65
66 /*
67  * lgetuser()  -  same as getuser() but locks the record
68  */
69 int lgetuser(struct usersupp *usbuf, char *name)
70 {
71         int retcode;
72
73         retcode = getuser(usbuf,name);
74         if (retcode == 0) {
75                 begin_critical_section(S_USERSUPP);
76                 }
77         return(retcode);
78         }
79
80
81 /*
82  * putuser()  -  write user buffer into the correct place on disk
83  */
84 void putuser(struct usersupp *usbuf, char *name)
85 {
86         char lowercase_name[32];
87         int a;
88
89         for (a=0; a<=strlen(name); ++a) {
90                 lowercase_name[a] = tolower(name[a]);
91                 }
92
93         cdb_store(CDB_USERSUPP,
94                 lowercase_name, strlen(lowercase_name),
95                 usbuf, sizeof(struct usersupp));
96
97         }
98
99
100 /*
101  * lputuser()  -  same as putuser() but locks the record
102  */
103 void lputuser(struct usersupp *usbuf, char *name) {
104         putuser(usbuf,name);
105         end_critical_section(S_USERSUPP);
106         }
107
108 /*
109  * Index-generating function used by Ctdl[Get|Set]Relationship
110  */
111 int GenerateRelationshipIndex(  char *IndexBuf,
112                                 struct usersupp *rel_user,
113                                 struct quickroom *rel_room) {
114
115         struct {
116                 long RoomID;
117                 long RoomGen;
118                 long UserID;
119                 } TheIndex;
120
121         TheIndex.RoomID = rel_room->QRnumber;
122         TheIndex.RoomGen = rel_room->QRgen;
123         TheIndex.UserID = rel_user->usernum;
124
125         memcpy(IndexBuf, &TheIndex, sizeof(TheIndex));
126         return(sizeof(TheIndex));
127         }
128
129 /*
130  * Define a relationship between a user and a room
131  */
132 void CtdlSetRelationship(struct visit *newvisit,
133                         struct usersupp *rel_user,
134                         struct quickroom *rel_room) {
135
136         char IndexBuf[32];
137         int IndexLen;
138
139         /* We don't use these in Citadel because they're implicit by the
140          * index, but they must be present if the database is exported.
141          */
142         newvisit->v_roomnum = rel_room->QRnumber;
143         newvisit->v_roomgen = rel_room->QRgen;
144         newvisit->v_usernum = rel_user->usernum;
145
146         /* Generate an index */
147         IndexLen = GenerateRelationshipIndex(IndexBuf, rel_user, rel_room);
148
149         /* Store the record */
150         cdb_store(CDB_VISIT, IndexBuf, IndexLen,
151                 newvisit, sizeof(struct visit)
152                 );
153         }
154
155 /*
156  * Locate a relationship between a user and a room
157  */
158 void CtdlGetRelationship(struct visit *vbuf,
159                         struct usersupp *rel_user,
160                         struct quickroom *rel_room) {
161
162         char IndexBuf[32];
163         int IndexLen;
164         struct cdbdata *cdbvisit;
165
166         /* Generate an index */
167         IndexLen = GenerateRelationshipIndex(IndexBuf, rel_user, rel_room);
168
169         /* Clear out the buffer */
170         bzero(vbuf, sizeof(struct visit));
171
172         cdbvisit = cdb_fetch(CDB_VISIT, IndexBuf, IndexLen);
173         if (cdbvisit != NULL) {
174                 memcpy(vbuf, cdbvisit->ptr,
175                         ( (cdbvisit->len > sizeof(struct visit)) ?
176                         sizeof(struct visit) : cdbvisit->len) );
177                 cdb_free(cdbvisit);
178                 return;
179                 }
180         }
181
182
183 void PurgeStaleRelationships(void) {
184
185         /********* REWRITE THIS FOR GLOBAL USE AND MOVE IT TO THE PURGE MODULE
186         struct cdbdata *cdbvisit;
187         struct visit *visits;
188         struct quickroom qrbuf;
189         int num_visits;
190         int a, purge;
191
192         cdbvisit = cdb_fetch(CDB_VISIT, &CC->usersupp.usernum, sizeof(long));
193         if (cdbvisit != NULL) {
194                 if ((num_visits = cdbvisit->len / sizeof(struct visit)) == 0) {
195                         cdb_free(cdbvisit);
196                         return;
197                         }
198                 visits = (struct visit *)
199                         malloc(num_visits * sizeof(struct visit));
200                 memcpy(visits, cdbvisit->ptr,
201                         (num_visits * sizeof(struct visit)));
202                 cdb_free(cdbvisit);
203                 }
204         else return;
205
206         for (a=0; a<num_visits; ++a) {
207                 if (getroom(&qrbuf, visits[a].v_roomname)!=0) {
208                         purge = 1;
209                         }
210                 else if (qrbuf.QRgen != visits[a].v_generation) {
211                         purge = 1;
212                         }
213                 else {
214                         purge = 0;
215                         }
216
217                 if (purge) {
218                         memcpy(&visits[a], &visits[a+1],
219                                 (((num_visits-a)-1) * sizeof(struct visit)) );
220                         --num_visits;
221                         }
222
223                 }
224         
225         cdb_store(CDB_VISIT, &CC->usersupp.usernum, sizeof(long),
226                         visits, (num_visits * sizeof(struct visit)));
227         free(visits);
228         **************/
229         }
230
231
232
233 void MailboxName(char *buf, struct usersupp *who, char *prefix) {
234         sprintf(buf, "%010ld.%s", who->usernum, prefix);
235         }
236
237         
238 /*
239  * Is the user currently logged in an Aide?
240  */
241 int is_aide(void) {
242         if (CC->usersupp.axlevel >= 6) return(1);
243         else return(0);
244         }
245
246
247 /*
248  * Is the user currently logged in an Aide *or* the room aide for this room?
249  */
250 int is_room_aide(void) {
251         if ( (CC->usersupp.axlevel >= 6)
252            || (CC->quickroom.QRroomaide == CC->usersupp.usernum) ) {
253                 return(1);
254                 }
255         else {
256                 return(0);
257                 }
258         }
259
260 /*
261  * getuserbynumber()  -  get user by number
262  *                       returns 0 if user was found
263  */
264 int getuserbynumber(struct usersupp *usbuf, long int number)
265 {
266         struct cdbdata *cdbus;
267
268         cdb_rewind(CDB_USERSUPP);
269
270         while(cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
271                 bzero(usbuf, sizeof(struct usersupp));
272                 memcpy(usbuf, cdbus->ptr,
273                         ( (cdbus->len > sizeof(struct usersupp)) ?
274                         sizeof(struct usersupp) : cdbus->len) );
275                 cdb_free(cdbus);
276                 if (usbuf->usernum == number) {
277                         return(0);
278                         }
279                 }
280         return(-1);
281         }
282
283
284 /*
285  * USER cmd
286  */
287 void cmd_user(char *cmdbuf)
288 {
289         char username[256];
290         char autoname[256];
291         int found_user = 0;
292         struct passwd *p;
293         int a;
294
295         extract(username,cmdbuf,0);
296         username[25] = 0;
297         strproc(username);
298
299         if ((CC->logged_in)) {
300                 cprintf("%d Already logged in.\n",ERROR);
301                 return;
302                 }
303
304         found_user = getuser(&CC->usersupp,username);
305         if (found_user != 0) {
306                 p = (struct passwd *)getpwnam(username);
307                 if (p!=NULL) {
308                         strcpy(autoname,p->pw_gecos);
309                         for (a=0; a<strlen(autoname); ++a)
310                                 if (autoname[a]==',') autoname[a]=0;
311                         found_user = getuser(&CC->usersupp,autoname);
312                         }
313                 }
314         if (found_user == 0) {
315                 if (((CC->nologin)) && (CC->usersupp.axlevel < 6)) {
316                         cprintf("%d %s: Too many users are already online (maximum is %d)\n",
317                         ERROR+MAX_SESSIONS_EXCEEDED,
318                         config.c_nodename,config.c_maxsessions);
319                         }
320                 else {
321                         strcpy(CC->curr_user,CC->usersupp.fullname);
322                         cprintf("%d Password required for %s\n",
323                                 MORE_DATA,CC->curr_user);
324                         }
325                 }
326         else {
327                 cprintf("%d %s not found.\n",ERROR,username);
328                 }
329         }
330
331
332
333 /*
334  * session startup code which is common to both cmd_pass() and cmd_newu()
335  */
336 void session_startup(void) {
337         syslog(LOG_NOTICE,"user <%s> logged in",CC->curr_user);
338
339         lgetuser(&CC->usersupp,CC->curr_user);
340         ++(CC->usersupp.timescalled);
341         CC->fake_username[0] = '\0';
342         CC->fake_postname[0] = '\0';
343         CC->fake_hostname[0] = '\0';
344         CC->fake_roomname[0] = '\0';
345         CC->last_pager[0] = '\0';
346         time(&CC->usersupp.lastcall);
347
348         /* If this user's name is the name of the system administrator
349          * (as specified in setup), automatically assign access level 6.
350          */
351         if (!strcasecmp(CC->usersupp.fullname, config.c_sysadm)) {
352                 CC->usersupp.axlevel = 6;
353                 }
354
355         lputuser(&CC->usersupp,CC->curr_user);
356
357         /* Run any cleanup routines registered by loadable modules */
358         PerformSessionHooks(EVT_LOGIN);
359
360         cprintf("%d %s|%d|%d|%d|%u|%ld\n",OK,CC->usersupp.fullname,CC->usersupp.axlevel,
361                 CC->usersupp.timescalled,CC->usersupp.posted,CC->usersupp.flags,
362                 CC->usersupp.usernum);
363         usergoto(BASEROOM,0);           /* Enter the lobby */   
364         rec_log(CL_LOGIN,CC->curr_user);
365         }
366
367
368 /* 
369  * misc things to be taken care of when a user is logged out
370  */
371 void logout(struct CitContext *who)
372 {
373         who->logged_in = 0;
374         if (who->download_fp != NULL) {
375                 fclose(who->download_fp);
376                 who->download_fp = NULL;
377                 }
378         if (who->upload_fp != NULL) {
379                 abort_upl(who);
380                 }
381
382         /* Do modular stuff... */
383         PerformSessionHooks(EVT_LOGOUT);
384         }
385
386
387 void cmd_pass(char *buf)
388 {
389         char password[256];
390         int code;
391         struct passwd *p;
392
393         extract(password,buf,0);
394
395         if ((CC->logged_in)) {
396                 cprintf("%d Already logged in.\n",ERROR);
397                 return;
398                 }
399         if (!strcmp(CC->curr_user,"")) {
400                 cprintf("%d You must send a name with USER first.\n",ERROR);
401                 return;
402                 }
403         if (getuser(&CC->usersupp,CC->curr_user)) {
404                 cprintf("%d Can't find user record!\n",ERROR+INTERNAL_ERROR);
405                 return;
406                 }
407
408         code = (-1);
409         if (CC->usersupp.USuid == BBSUID) {
410                 strproc(password);
411                 strproc(CC->usersupp.password);
412                 code = strcasecmp(CC->usersupp.password,password);
413                 }
414         else {
415                 p = (struct passwd *)getpwuid(CC->usersupp.USuid);
416 #ifdef ENABLE_AUTOLOGIN
417                 if (p!=NULL) {
418                         if (!strcmp(p->pw_passwd,
419                            (char *)crypt(password,p->pw_passwd))) {
420                                 code = 0;
421                                 lgetuser(&CC->usersupp, CC->curr_user);
422                                 strcpy(CC->usersupp.password, password);
423                                 lputuser(&CC->usersupp, CC->curr_user);
424                                 }
425                         }
426 #endif
427                 }
428
429         if (!code) {
430                 (CC->logged_in) = 1;
431                 session_startup();
432                 }
433         else {
434                 cprintf("%d Wrong password.\n",ERROR);
435                 rec_log(CL_BADPW,CC->curr_user);
436                 }
437         }
438
439
440 /*
441  * Delete a user record *and* all of its related resources.
442  */
443 int purge_user(char pname[]) {
444         char filename[64];
445         char mailboxname[ROOMNAMELEN];
446         struct usersupp usbuf;
447         struct quickroom qrbuf;
448         char lowercase_name[32];
449         int a;
450
451         for (a=0; a<=strlen(pname); ++a) {
452                 lowercase_name[a] = tolower(pname[a]);
453                 }
454
455         if (getuser(&usbuf, pname) != 0) {
456                 lprintf(5, "Cannot purge user <%s> - not found\n", pname);
457                 return(ERROR+NO_SUCH_USER);
458                 }
459
460         lprintf(5, "Deleting user <%s>\n", pname);
461
462         /* FIX   Don't delete a user who is currently logged in. */
463
464         /* Perform any purge functions registered by server extensions */
465         PerformUserHooks(usbuf.fullname, usbuf.usernum, EVT_PURGEUSER);
466
467         /* delete any existing user/room relationships */
468         cdb_delete(CDB_VISIT, &usbuf.usernum, sizeof(long));
469
470         /* Delete the user's mailbox and its contents */
471         MailboxName(mailboxname, &usbuf, MAILROOM);
472         if (getroom(&qrbuf, mailboxname)==0) {
473                 delete_room(&qrbuf);
474                 }
475
476         /* delete the userlog entry */
477         cdb_delete(CDB_USERSUPP, lowercase_name, strlen(lowercase_name));
478
479         /* remove the user's bio file */        
480         sprintf(filename, "./bio/%ld", usbuf.usernum);
481         unlink(filename);
482
483         /* remove the user's picture */
484         sprintf(filename, "./userpics/%ld.gif", usbuf.usernum);
485         unlink(filename);
486
487         return(0);
488         }
489
490
491 /*
492  * create_user()  -  back end processing to create a new user
493  */
494 int create_user(char *newusername)
495 {
496         struct usersupp usbuf;
497         int a;
498         struct passwd *p = NULL;
499         char username[64];
500         char mailboxname[ROOMNAMELEN];
501
502         strcpy(username, newusername);
503         strproc(username);
504
505 #ifdef ENABLE_AUTOLOGIN
506         p = (struct passwd *)getpwnam(username);
507 #endif
508         if (p != NULL) {
509                 strcpy(username, p->pw_gecos);
510                 for (a=0; a<strlen(username); ++a) {
511                         if (username[a] == ',') username[a] = 0;
512                         }
513                 CC->usersupp.USuid = p->pw_uid;
514                 }
515         else {
516                 CC->usersupp.USuid = BBSUID;
517                 }
518
519         if (!getuser(&usbuf,username)) {
520                 return(ERROR+ALREADY_EXISTS);
521                 }
522
523         strcpy(CC->curr_user,username);
524         strcpy(CC->usersupp.fullname,username);
525         strcpy(CC->usersupp.password,"");
526         (CC->logged_in) = 1;
527
528         /* These are the default flags on new accounts */
529         CC->usersupp.flags =
530                 US_NEEDVALID|US_LASTOLD|US_DISAPPEAR|US_PAGINATOR|US_FLOORS;
531
532         CC->usersupp.timescalled = 0;
533         CC->usersupp.posted = 0;
534         CC->usersupp.axlevel = config.c_initax;
535         CC->usersupp.USscreenwidth = 80;
536         CC->usersupp.USscreenheight = 24;
537         time(&CC->usersupp.lastcall);
538         strcpy(CC->usersupp.USname, "");
539         strcpy(CC->usersupp.USaddr, "");
540         strcpy(CC->usersupp.UScity, "");
541         strcpy(CC->usersupp.USstate, "");
542         strcpy(CC->usersupp.USzip, "");
543         strcpy(CC->usersupp.USphone, "");
544
545         /* fetch a new user number */
546         CC->usersupp.usernum = get_new_user_number();
547
548         if (CC->usersupp.usernum == 1L) {
549                 CC->usersupp.axlevel = 6;
550                 }
551
552         /* add user to userlog */
553         putuser(&CC->usersupp,CC->curr_user);
554         if (getuser(&CC->usersupp,CC->curr_user)) {
555                 return(ERROR+INTERNAL_ERROR);
556                 }
557
558         /* give the user a private mailbox */
559         MailboxName(mailboxname, &CC->usersupp, MAILROOM);
560         create_room(mailboxname, 4, "", 0);
561
562         rec_log(CL_NEWUSER,CC->curr_user);
563         return(0);
564         }
565
566
567
568
569 /*
570  * cmd_newu()  -  create a new user account
571  */
572 void cmd_newu(char *cmdbuf)
573 {
574         int a;
575         char username[256];
576
577         if ((CC->logged_in)) {
578                 cprintf("%d Already logged in.\n",ERROR);
579                 return;
580                 }
581
582         if ((CC->nologin)) {
583                 cprintf("%d %s: Too many users are already online (maximum is %d)\n",
584                 ERROR+MAX_SESSIONS_EXCEEDED,
585                 config.c_nodename,config.c_maxsessions);
586                 }
587
588         extract(username,cmdbuf,0);
589         username[25] = 0;
590         strproc(username);
591
592         if (strlen(username)==0) {
593                 cprintf("%d You must supply a user name.\n",ERROR);
594                 return;
595                 }
596
597         a = create_user(username);
598         if ((!strcasecmp(username, "bbs")) ||
599             (!strcasecmp(username, "new")) ||
600             (!strcasecmp(username, ".")))
601         {
602            cprintf("%d '%s' is an invalid login name.\n", ERROR);
603            return;
604         }
605         if (a==ERROR+ALREADY_EXISTS) {
606                 cprintf("%d '%s' already exists.\n",
607                         ERROR+ALREADY_EXISTS,username);
608                 return;
609                 }
610         else if (a==ERROR+INTERNAL_ERROR) {
611                 cprintf("%d Internal error - user record disappeared?\n",
612                         ERROR+INTERNAL_ERROR);
613                 return;
614                 }
615         else if (a==0) {
616                 session_startup();
617                 }
618         else {
619                 cprintf("%d unknown error\n",ERROR);
620                 }
621         rec_log(CL_NEWUSER,CC->curr_user);
622         }
623
624
625
626 /*
627  * set password
628  */
629 void cmd_setp(char *new_pw)
630 {
631         if (!(CC->logged_in)) {
632                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
633                 return;
634                 }
635         if (CC->usersupp.USuid != BBSUID) {
636                 cprintf("%d Not allowed.  Use the 'passwd' command.\n",ERROR);
637                 return;
638                 }
639         strproc(new_pw);
640         if (strlen(new_pw)==0) {
641                 cprintf("%d Password unchanged.\n",OK);
642                 return;
643                 }
644         lgetuser(&CC->usersupp,CC->curr_user);
645         strcpy(CC->usersupp.password,new_pw);
646         lputuser(&CC->usersupp,CC->curr_user);
647         cprintf("%d Password changed.\n",OK);
648         rec_log(CL_PWCHANGE,CC->curr_user);
649         PerformSessionHooks(EVT_SETPASS);
650         }
651
652 /*
653  * get user parameters
654  */
655 void cmd_getu(void) {
656         if (!(CC->logged_in)) {
657                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
658                 return;
659                 }
660         getuser(&CC->usersupp,CC->curr_user);
661         cprintf("%d %d|%d|%d\n",
662                 OK,
663                 CC->usersupp.USscreenwidth,
664                 CC->usersupp.USscreenheight,
665                 (CC->usersupp.flags & US_USER_SET)
666                 );
667         }
668
669 /*
670  * set user parameters
671  */
672 void cmd_setu(char *new_parms)
673 {
674
675         if (num_parms(new_parms)!=3) {
676                 cprintf("%d Usage error.\n",ERROR);
677                 return;
678                 }       
679         if (!(CC->logged_in)) {
680                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
681                 return;
682                 }
683         lgetuser(&CC->usersupp,CC->curr_user);
684         CC->usersupp.USscreenwidth = extract_int(new_parms,0);
685         CC->usersupp.USscreenheight = extract_int(new_parms,1);
686         CC->usersupp.flags = CC->usersupp.flags & (~US_USER_SET);
687         CC->usersupp.flags = CC->usersupp.flags | 
688                 (extract_int(new_parms,2) & US_USER_SET);
689         lputuser(&CC->usersupp,CC->curr_user);
690         cprintf("%d Ok\n",OK);
691         }
692
693 /*
694  * set last read pointer
695  */
696 void cmd_slrp(char *new_ptr)
697 {
698         long newlr;
699         struct visit vbuf;
700
701         if (!(CC->logged_in)) {
702                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
703                 return;
704                 }
705
706         if (!strncasecmp(new_ptr,"highest",7)) {
707                 newlr = CC->quickroom.QRhighest;
708                 }
709         else {
710                 newlr = atol(new_ptr);
711                 }
712
713         lgetuser(&CC->usersupp, CC->curr_user);
714
715         CtdlGetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
716         vbuf.v_lastseen = newlr;
717         CtdlSetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
718
719         lputuser(&CC->usersupp, CC->curr_user);
720         cprintf("%d %ld\n",OK,newlr);
721         }
722
723
724 /*
725  * INVT and KICK commands
726  */
727 void cmd_invt_kick(char *iuser, int op)
728                         /* user name */
729         {               /* 1 = invite, 0 = kick out */
730         struct usersupp USscratch;
731         char bbb[256];
732         struct visit vbuf;
733
734         if (!(CC->logged_in)) {
735                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
736                 return;
737                 }
738
739         if (is_room_aide()==0) {
740                 cprintf("%d Higher access required.\n",
741                         ERROR+HIGHER_ACCESS_REQUIRED);
742                 return;
743                 }
744
745         if (lgetuser(&USscratch,iuser)!=0) {
746                 cprintf("%d No such user.\n",ERROR);
747                 return;
748                 }
749
750         CtdlGetRelationship(&vbuf, &USscratch, &CC->quickroom);
751
752         if (op==1) {
753                 vbuf.v_flags = vbuf.v_flags & ~V_FORGET & ~V_LOCKOUT;
754                 vbuf.v_flags = vbuf.v_flags | V_ACCESS;
755                 }
756
757         if (op==0) {
758                 vbuf.v_flags = vbuf.v_flags & ~V_ACCESS;
759                 vbuf.v_flags = vbuf.v_flags | V_FORGET | V_LOCKOUT;
760                 }
761
762         CtdlSetRelationship(&vbuf, &USscratch, &CC->quickroom);
763
764         lputuser(&USscratch,iuser);
765
766         /* post a message in Aide> saying what we just did */
767         sprintf(bbb,"%s %s %s> by %s",
768                 iuser,
769                 ((op == 1) ? "invited to" : "kicked out of"),
770                 CC->quickroom.QRname,
771                 CC->usersupp.fullname);
772         aide_message(bbb);
773
774         cprintf("%d %s %s %s.\n",
775                 OK, iuser,
776                 ((op == 1) ? "invited to" : "kicked out of"),
777                 CC->quickroom.QRname);
778         return;
779         }
780
781
782 /*
783  * forget (Zap) the current room
784  */
785 void cmd_forg(void) {
786         struct visit vbuf;
787
788         if (!(CC->logged_in)) {
789                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
790                 return;
791                 }
792
793         if (is_aide()) {
794                 cprintf("%d Aides cannot forget rooms.\n",ERROR);
795                 return;
796                 }
797
798         lgetuser(&CC->usersupp,CC->curr_user);
799         CtdlGetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
800
801         vbuf.v_flags = vbuf.v_flags | V_FORGET;
802
803         CtdlSetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
804         lputuser(&CC->usersupp,CC->curr_user);
805         cprintf("%d Ok\n",OK);
806         usergoto(BASEROOM, 0);
807         }
808
809 /*
810  * Get Next Unregistered User
811  */
812 void cmd_gnur(void) {
813         struct cdbdata *cdbus;
814         struct usersupp usbuf;
815
816         if (!(CC->logged_in)) {
817                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
818                 return;
819                 }
820
821         if (CC->usersupp.axlevel < 6) {
822                 cprintf("%d Higher access required.\n",
823                         ERROR+HIGHER_ACCESS_REQUIRED);
824                 return;
825                 }
826
827         if ((CitControl.MMflags&MM_VALID)==0) {
828                 cprintf("%d There are no unvalidated users.\n",OK);
829                 return;
830                 }
831
832         /* There are unvalidated users.  Traverse the usersupp database,
833          * and return the first user we find that needs validation.
834          */
835         cdb_rewind(CDB_USERSUPP);
836         while (cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
837                 bzero(&usbuf, sizeof(struct usersupp));
838                 memcpy(&usbuf, cdbus->ptr,
839                         ( (cdbus->len > sizeof(struct usersupp)) ?
840                         sizeof(struct usersupp) : cdbus->len) );
841                 cdb_free(cdbus);
842                 if ((usbuf.flags & US_NEEDVALID)
843                    &&(usbuf.axlevel > 0)) {
844                         cprintf("%d %s\n",MORE_DATA,usbuf.fullname);
845                         return;
846                         }
847                 } 
848
849         /* If we get to this point, there are no more unvalidated users.
850          * Therefore we clear the "users need validation" flag.
851          */
852
853         begin_critical_section(S_CONTROL);
854         get_control();
855         CitControl.MMflags = CitControl.MMflags&(~MM_VALID);
856         put_control();
857         end_critical_section(S_CONTROL);
858         cprintf("%d *** End of registration.\n",OK);
859
860
861         }
862
863
864 /*
865  * get registration info for a user
866  */
867 void cmd_greg(char *who)
868 {
869         struct usersupp usbuf;
870         int a,b;
871         char pbuf[32];
872
873         if (!(CC->logged_in)) {
874                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
875                 return;
876                 }
877
878         if (!strcasecmp(who,"_SELF_")) strcpy(who,CC->curr_user);
879
880         if ((CC->usersupp.axlevel < 6) && (strcasecmp(who,CC->curr_user))) {
881                 cprintf("%d Higher access required.\n",
882                         ERROR+HIGHER_ACCESS_REQUIRED);
883                 return;
884                 }
885
886         if (getuser(&usbuf,who) != 0) {
887                 cprintf("%d '%s' not found.\n",ERROR+NO_SUCH_USER,who);
888                 return;
889                 }
890
891         cprintf("%d %s\n",LISTING_FOLLOWS,usbuf.fullname);
892         cprintf("%ld\n",usbuf.usernum);
893         cprintf("%s\n",usbuf.password);
894         cprintf("%s\n",usbuf.USname);
895         cprintf("%s\n",usbuf.USaddr);
896         cprintf("%s\n%s\n%s\n",
897                 usbuf.UScity,usbuf.USstate,usbuf.USzip);
898         strcpy(pbuf,usbuf.USphone);
899         usbuf.USphone[0]=0;
900         for (a=0; a<strlen(pbuf); ++a) {
901                 if ((pbuf[a]>='0')&&(pbuf[a]<='9')) {
902                         b=strlen(usbuf.USphone);
903                         usbuf.USphone[b]=pbuf[a];
904                         usbuf.USphone[b+1]=0;
905                         }
906                 }
907         while(strlen(usbuf.USphone)<10) {
908                 strcpy(pbuf,usbuf.USphone);
909                 strcpy(usbuf.USphone," ");
910                 strcat(usbuf.USphone,pbuf);
911                 }
912
913         cprintf("(%c%c%c) %c%c%c-%c%c%c%c\n",
914                 usbuf.USphone[0],usbuf.USphone[1],
915                 usbuf.USphone[2],usbuf.USphone[3],
916                 usbuf.USphone[4],usbuf.USphone[5],
917                 usbuf.USphone[6],usbuf.USphone[7],
918                 usbuf.USphone[8],usbuf.USphone[9]);
919
920         cprintf("%d\n",usbuf.axlevel);
921         cprintf("%s\n",usbuf.USemail);
922         cprintf("000\n");
923         }
924
925 /*
926  * validate a user
927  */
928 void cmd_vali(char *v_args)
929 {
930         char user[256];
931         int newax;
932         struct usersupp userbuf;
933
934         extract(user,v_args,0);
935         newax = extract_int(v_args,1);
936
937         if (!(CC->logged_in)) {
938                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
939                 return;
940                 }
941
942         if (CC->usersupp.axlevel < 6) {
943                 cprintf("%d Higher access required.\n",
944                         ERROR+HIGHER_ACCESS_REQUIRED);
945                 return;
946                 }
947
948         if (lgetuser(&userbuf,user)!=0) {
949                 cprintf("%d '%s' not found.\n",ERROR+NO_SUCH_USER,user);
950                 return;
951                 }
952
953         userbuf.axlevel = newax;
954         userbuf.flags = (userbuf.flags & ~US_NEEDVALID);
955
956         lputuser(&userbuf,user);
957
958         /* If the access level was set to zero, delete the user */
959         if (newax == 0) {
960                 if (purge_user(user)==0) {
961                         cprintf("%d %s Deleted.\n", OK, userbuf.fullname);
962                         return;
963                         }
964                 }
965
966         cprintf("%d ok\n",OK);
967         }
968
969
970
971 /* 
972  *  Traverse the user file...
973  */
974 void ForEachUser(void (*CallBack)(struct usersupp *EachUser)) {
975         struct usersupp usbuf;
976         struct cdbdata *cdbus;
977
978         cdb_rewind(CDB_USERSUPP);
979
980         while(cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
981                 bzero(&usbuf, sizeof(struct usersupp));
982                 memcpy(&usbuf, cdbus->ptr,
983                         ( (cdbus->len > sizeof(struct usersupp)) ?
984                         sizeof(struct usersupp) : cdbus->len) );
985                 cdb_free(cdbus);
986                 (*CallBack)(&usbuf);
987                 }
988         }
989
990
991 /*
992  * List one user (this works with cmd_list)
993  */
994 void ListThisUser(struct usersupp *usbuf) {
995         if (usbuf->axlevel > 0) {
996                 if ((CC->usersupp.axlevel>=6)
997                    ||((usbuf->flags&US_UNLISTED)==0)
998                    ||((CC->internal_pgm))) {
999                         cprintf("%s|%d|%ld|%ld|%d|%d|",
1000                                 usbuf->fullname,
1001                                 usbuf->axlevel,
1002                                 usbuf->usernum,
1003                                 usbuf->lastcall,
1004                                 usbuf->timescalled,
1005                                 usbuf->posted);
1006                         if (CC->usersupp.axlevel >= 6)
1007                                 cprintf("%s",usbuf->password);
1008                         cprintf("\n");
1009                         }
1010                 }
1011         }
1012
1013 /* 
1014  *  List users
1015  */
1016 void cmd_list(void) {
1017         cprintf("%d \n",LISTING_FOLLOWS);
1018         ForEachUser(ListThisUser);
1019         cprintf("000\n");
1020         }
1021
1022
1023 /*
1024  * enter registration info
1025  */
1026 void cmd_regi(void) {
1027         int a,b,c;
1028         char buf[256];
1029
1030         char tmpname[256];
1031         char tmpaddr[256];
1032         char tmpcity[256];
1033         char tmpstate[256];
1034         char tmpzip[256];
1035         char tmpphone[256];
1036         char tmpemail[256];
1037
1038         if (!(CC->logged_in)) {
1039                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
1040                 return;
1041                 }
1042
1043         strcpy(tmpname,"");
1044         strcpy(tmpaddr,"");
1045         strcpy(tmpcity,"");
1046         strcpy(tmpstate,"");
1047         strcpy(tmpzip,"");
1048         strcpy(tmpphone,"");
1049         strcpy(tmpemail,"");
1050
1051         cprintf("%d Send registration...\n",SEND_LISTING);
1052         a=0;
1053         while (client_gets(buf), strcmp(buf,"000")) {
1054                 if (a==0) strcpy(tmpname,buf);
1055                 if (a==1) strcpy(tmpaddr,buf);
1056                 if (a==2) strcpy(tmpcity,buf);
1057                 if (a==3) strcpy(tmpstate,buf);
1058                 if (a==4) {
1059                         for (c=0; c<strlen(buf); ++c) {
1060                                 if ((buf[c]>='0')&&(buf[c]<='9')) {
1061                                         b=strlen(tmpzip);
1062                                         tmpzip[b]=buf[c];
1063                                         tmpzip[b+1]=0;
1064                                         }
1065                                 }
1066                         }
1067                 if (a==5) {
1068                         for (c=0; c<strlen(buf); ++c) {
1069                                 if ((buf[c]>='0')&&(buf[c]<='9')) {
1070                                         b=strlen(tmpphone);
1071                                         tmpphone[b]=buf[c];
1072                                         tmpphone[b+1]=0;
1073                                         }
1074                                 }
1075                         }
1076                 if (a==6) strncpy(tmpemail,buf,31);
1077                 ++a;
1078                 }
1079
1080         tmpname[29]=0;
1081         tmpaddr[24]=0;
1082         tmpcity[14]=0;
1083         tmpstate[2]=0;
1084         tmpzip[9]=0;
1085         tmpphone[10]=0;
1086         tmpemail[31]=0;
1087
1088         lgetuser(&CC->usersupp,CC->curr_user);
1089         strcpy(CC->usersupp.USname,tmpname);
1090         strcpy(CC->usersupp.USaddr,tmpaddr);
1091         strcpy(CC->usersupp.UScity,tmpcity);
1092         strcpy(CC->usersupp.USstate,tmpstate);
1093         strcpy(CC->usersupp.USzip,tmpzip);
1094         strcpy(CC->usersupp.USphone,tmpphone);
1095         strcpy(CC->usersupp.USemail,tmpemail);
1096         CC->usersupp.flags=(CC->usersupp.flags|US_REGIS|US_NEEDVALID);
1097         lputuser(&CC->usersupp,CC->curr_user);
1098
1099         /* set global flag calling for validation */
1100         begin_critical_section(S_CONTROL);
1101         get_control();
1102         CitControl.MMflags = CitControl.MMflags | MM_VALID ;
1103         put_control();
1104         end_critical_section(S_CONTROL);
1105         cprintf("%d *** End of registration.\n",OK);
1106         }
1107
1108
1109 /*
1110  * assorted info we need to check at login
1111  */
1112 void cmd_chek(void) {
1113         int mail = 0;
1114         int regis = 0;
1115         int vali = 0;
1116         
1117         if (!(CC->logged_in)) {
1118                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
1119                 return;
1120                 }
1121
1122         getuser(&CC->usersupp,CC->curr_user); /* no lock is needed here */
1123         if ((REGISCALL!=0)&&((CC->usersupp.flags&US_REGIS)==0)) regis = 1;
1124
1125         if (CC->usersupp.axlevel >= 6) {
1126                 get_control();
1127                 if (CitControl.MMflags&MM_VALID) vali = 1;
1128                 }
1129
1130
1131         /* check for mail */
1132         mail = NewMailCount();
1133
1134         cprintf("%d %d|%d|%d\n",OK,mail,regis,vali);
1135         }
1136
1137
1138 /*
1139  * check to see if a user exists
1140  */
1141 void cmd_qusr(char *who)
1142 {
1143         struct usersupp usbuf;
1144
1145         if (getuser(&usbuf,who) == 0) {
1146                 cprintf("%d %s\n",OK,usbuf.fullname);
1147                 }
1148         else {
1149                 cprintf("%d No such user.\n",ERROR+NO_SUCH_USER);
1150                 }
1151         }
1152
1153
1154 /*
1155  * enter user bio
1156  */
1157 void cmd_ebio(void) {
1158         char buf[256];
1159         FILE *fp;
1160
1161         if (!(CC->logged_in)) {
1162                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
1163                 return;
1164                 }
1165
1166         sprintf(buf,"./bio/%ld",CC->usersupp.usernum);
1167         fp = fopen(buf,"w");
1168         if (fp == NULL) {
1169                 cprintf("%d Cannot create file\n",ERROR);
1170                 return;
1171                 }
1172         cprintf("%d  \n",SEND_LISTING);
1173         while(client_gets(buf), strcmp(buf,"000")) {
1174                 fprintf(fp,"%s\n",buf);
1175                 }
1176         fclose(fp);
1177         }
1178
1179 /*
1180  * read user bio
1181  */
1182 void cmd_rbio(char *cmdbuf)
1183 {
1184         struct usersupp ruser;
1185         char buf[256];
1186         FILE *fp;
1187
1188         extract(buf,cmdbuf,0);
1189         if (getuser(&ruser,buf)!=0) {
1190                 cprintf("%d No such user.\n",ERROR+NO_SUCH_USER);
1191                 return;
1192                 }
1193         sprintf(buf,"./bio/%ld",ruser.usernum);
1194         
1195         fp = fopen(buf,"r");
1196         if (fp == NULL) {
1197                 cprintf("%d %s has no bio on file.\n",
1198                         ERROR+FILE_NOT_FOUND,ruser.fullname);
1199                 return;
1200                 }
1201         cprintf("%d  \n",LISTING_FOLLOWS);
1202         while (fgets(buf,256,fp)!=NULL) cprintf("%s",buf);
1203         fclose(fp);
1204         cprintf("000\n");
1205         }
1206
1207 /*
1208  * list of users who have entered bios
1209  */
1210 void cmd_lbio(void) {
1211         char buf[256];
1212         FILE *ls;
1213         struct usersupp usbuf;
1214
1215         ls=popen("cd ./bio; ls","r");
1216         if (ls==NULL) {
1217                 cprintf("%d Cannot open listing.\n",ERROR+FILE_NOT_FOUND);
1218                 return;
1219                 }
1220
1221         cprintf("%d\n",LISTING_FOLLOWS);
1222         while (fgets(buf,255,ls)!=NULL)
1223                 if (getuserbynumber(&usbuf,atol(buf))==0)
1224                         cprintf("%s\n",usbuf.fullname);
1225         pclose(ls);
1226         cprintf("000\n");
1227         }
1228
1229
1230 /*
1231  * Administrative Get User Parameters
1232  */
1233 void cmd_agup(char *cmdbuf) {
1234         struct usersupp usbuf;
1235         char requested_user[256];
1236
1237         if ( (CC->internal_pgm==0)
1238            && ( (CC->logged_in == 0) || (is_aide()==0) ) ) {
1239                 cprintf("%d Higher access required.\n", 
1240                         ERROR + HIGHER_ACCESS_REQUIRED);
1241                 return;
1242                 }
1243
1244         extract(requested_user, cmdbuf, 0);
1245         if (getuser(&usbuf, requested_user) != 0) {
1246                 cprintf("%d No such user.\n", ERROR + NO_SUCH_USER);
1247                 return;
1248                 }
1249
1250         cprintf("%d %s|%s|%u|%d|%d|%d|%ld|%ld|%d\n", 
1251                 OK,
1252                 usbuf.fullname,
1253                 usbuf.password,
1254                 usbuf.flags,
1255                 usbuf.timescalled,
1256                 usbuf.posted,
1257                 (int)usbuf.axlevel,
1258                 usbuf.usernum,
1259                 usbuf.lastcall,
1260                 usbuf.USuserpurge);
1261         }
1262
1263
1264
1265 /*
1266  * Administrative Set User Parameters
1267  */
1268 void cmd_asup(char *cmdbuf) {
1269         struct usersupp usbuf;
1270         char requested_user[256];
1271         int np;
1272         int newax;
1273         
1274         if ( (CC->internal_pgm==0)
1275            && ( (CC->logged_in == 0) || (is_aide()==0) ) ) {
1276                 cprintf("%d Higher access required.\n", 
1277                         ERROR + HIGHER_ACCESS_REQUIRED);
1278                 return;
1279                 }
1280
1281         extract(requested_user, cmdbuf, 0);
1282         if (lgetuser(&usbuf, requested_user) != 0) {
1283                 cprintf("%d No such user.\n", ERROR + NO_SUCH_USER);
1284                 return;
1285                 }
1286
1287         np = num_parms(cmdbuf);
1288         if (np > 1) extract(usbuf.password, cmdbuf, 1);
1289         if (np > 2) usbuf.flags = extract_int(cmdbuf, 2);
1290         if (np > 3) usbuf.timescalled = extract_int(cmdbuf, 3);
1291         if (np > 4) usbuf.posted = extract_int(cmdbuf, 4);
1292         if (np > 5) {
1293                 newax = extract_int(cmdbuf, 5);
1294                 if ((newax >=0) && (newax <= 6)) {
1295                         usbuf.axlevel = extract_int(cmdbuf, 5);
1296                         }
1297                 }
1298         if (np > 7) {
1299                 usbuf.lastcall = extract_long(cmdbuf, 7);
1300                 }
1301         if (np > 8) {
1302                 usbuf.USuserpurge = extract_int(cmdbuf, 8);
1303                 }
1304
1305         lputuser(&usbuf, requested_user);
1306         if (usbuf.axlevel == 0) {
1307                 if (purge_user(requested_user)==0) {
1308                         cprintf("%d %s deleted.\n", OK, requested_user);
1309                         }
1310                 }
1311         cprintf("%d Ok\n", OK);
1312         }
1313
1314
1315 /*
1316  * Count the number of new mail messages the user has
1317  */
1318 int NewMailCount() {
1319         int num_newmsgs = 0;
1320         int a;
1321         char mailboxname[32];
1322         struct quickroom mailbox;
1323         struct visit vbuf;
1324
1325         MailboxName(mailboxname, &CC->usersupp, MAILROOM);
1326         if (getroom(&mailbox, mailboxname)!=0) return(0);
1327         CtdlGetRelationship(&vbuf, &CC->usersupp, &mailbox);
1328
1329         get_msglist(&mailbox);
1330         for (a=0; a<CC->num_msgs; ++a) {
1331                 if (MessageFromList(a)>0L) {
1332                         if (MessageFromList(a) > vbuf.v_lastseen) {
1333                                 ++num_newmsgs;
1334                                 }
1335                         }
1336                 }
1337
1338         return(num_newmsgs);
1339         }