/* $Id$ */
-/* needed to properly enable crypt() stuff on some systems */
-#define _XOPEN_SOURCE
-/* needed for str[n]casecmp() on some systems if the above is defined */
-#define _XOPEN_SOURCE_EXTENDED
-/* needed to enable threads on some systems if the above are defined */
-#define _POSIX_C_SOURCE 199506L
-
+#include "sysdep.h"
+#include <errno.h>
#include <stdlib.h>
#include <unistd.h>
#include <stdio.h>
#include <signal.h>
#include <pwd.h>
#include <sys/types.h>
+#include <sys/wait.h>
#include <sys/time.h>
#include <string.h>
#include <syslog.h>
#include <limits.h>
+#ifdef HAVE_PTHREAD_H
#include <pthread.h>
+#endif
+#ifndef ENABLE_CHKPWD
+#include "auth.h"
+#endif
#include "citadel.h"
#include "server.h"
#include "database.h"
#include "msgbase.h"
#include "config.h"
#include "dynloader.h"
-#include "sysdep.h"
#include "tools.h"
int a;
struct cdbdata *cdbus;
- bzero(usbuf, sizeof(struct usersupp));
+ memset(usbuf, 0, sizeof(struct usersupp));
for (a=0; a<=strlen(name); ++a) {
- lowercase_name[a] = tolower(name[a]);
+ if (a < sizeof(lowercase_name))
+ lowercase_name[a] = tolower(name[a]);
}
+ lowercase_name[sizeof(lowercase_name)-1] = 0;
cdbus = cdb_fetch(CDB_USERSUPP, lowercase_name, strlen(lowercase_name));
if (cdbus == NULL) {
/*
* putuser() - write user buffer into the correct place on disk
*/
-void putuser(struct usersupp *usbuf, char *name)
+void putuser(struct usersupp *usbuf)
{
char lowercase_name[32];
int a;
- for (a=0; a<=strlen(name); ++a) {
- lowercase_name[a] = tolower(name[a]);
+ for (a=0; a<=strlen(usbuf->fullname); ++a) {
+ if (a < sizeof(lowercase_name))
+ lowercase_name[a] = tolower(usbuf->fullname[a]);
}
+ lowercase_name[sizeof(lowercase_name)-1] = 0;
cdb_store(CDB_USERSUPP,
lowercase_name, strlen(lowercase_name),
/*
* lputuser() - same as putuser() but locks the record
*/
-void lputuser(struct usersupp *usbuf, char *name) {
- putuser(usbuf,name);
+void lputuser(struct usersupp *usbuf) {
+ putuser(usbuf);
end_critical_section(S_USERSUPP);
}
rel_user->usernum);
/* Clear out the buffer */
- bzero(vbuf, sizeof(struct visit));
+ memset(vbuf, 0, sizeof(struct visit));
cdbvisit = cdb_fetch(CDB_VISIT, IndexBuf, IndexLen);
if (cdbvisit != NULL) {
cdb_rewind(CDB_USERSUPP);
while(cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
- bzero(usbuf, sizeof(struct usersupp));
+ memset(usbuf, 0, sizeof(struct usersupp));
memcpy(usbuf, cdbus->ptr,
( (cdbus->len > sizeof(struct usersupp)) ?
sizeof(struct usersupp) : cdbus->len) );
CC->fake_postname[0] = '\0';
CC->fake_hostname[0] = '\0';
CC->fake_roomname[0] = '\0';
- CC->last_pager[0] = '\0';
time(&CC->usersupp.lastcall);
/* If this user's name is the name of the system administrator
CC->usersupp.axlevel = 6;
}
- lputuser(&CC->usersupp,CC->curr_user);
+ lputuser(&CC->usersupp);
/* Run any cleanup routines registered by loadable modules */
PerformSessionHooks(EVT_LOGIN);
PerformSessionHooks(EVT_LOGOUT);
}
+#ifdef ENABLE_CHKPWD
+/*
+ * an alternate version of validpw() which executes `chkpwd' instead of
+ * verifying the password directly
+ */
+static int validpw(uid_t uid, const char *pass)
+{
+ pid_t pid;
+ int status, pipev[2];
+ char buf[24];
+
+ if (pipe(pipev)) {
+ lprintf(1, "pipe failed (%s): denying autologin access for "
+ "uid %u\n", strerror(errno), uid);
+ return 0;
+ }
+
+ switch (pid = fork()) {
+ case -1:
+ lprintf(1, "fork failed (%s): denying autologin access for "
+ "uid %u\n", strerror(errno), uid);
+ close(pipev[0]);
+ close(pipev[1]);
+ return 0;
+
+ case 0:
+ close(pipev[1]);
+ if (dup2(pipev[0], 0) == -1) {
+ perror("dup2");
+ exit(1);
+ }
+ close(pipev[0]);
+
+ execl(BBSDIR "/chkpwd", BBSDIR "/chkpwd", NULL);
+ perror(BBSDIR "/chkpwd");
+ exit(1);
+ }
+
+ close(pipev[0]);
+ write(pipev[1], buf, sprintf(buf, "%u\n", uid));
+ write(pipev[1], pass, strlen(pass));
+ write(pipev[1], "\n", 1);
+ close(pipev[1]);
+
+ while (waitpid(pid, &status, 0) == -1)
+ if (errno != EINTR) {
+ lprintf(1, "waitpid failed (%s): denying autologin "
+ "access for uid %u\n",
+ strerror(errno), uid);
+ return 0;
+ }
+
+ if (WIFEXITED(status) && !WEXITSTATUS(status))
+ return 1;
+
+ return 0;
+ }
+#endif
void cmd_pass(char *buf)
{
char password[256];
int code;
- struct passwd *p;
extract(password,buf,0);
strproc(CC->usersupp.password);
code = strcasecmp(CC->usersupp.password,password);
}
- else {
- p = (struct passwd *)getpwuid(CC->usersupp.USuid);
#ifdef ENABLE_AUTOLOGIN
- if (p!=NULL) {
- if (!strcmp(p->pw_passwd,
- (char *)crypt(password,p->pw_passwd))) {
- code = 0;
- lgetuser(&CC->usersupp, CC->curr_user);
- strcpy(CC->usersupp.password, password);
- lputuser(&CC->usersupp, CC->curr_user);
- }
+ else {
+ if (validpw(CC->usersupp.USuid, password)) {
+ code = 0;
+ lgetuser(&CC->usersupp, CC->curr_user);
+ safestrncpy(CC->usersupp.password, password,
+ sizeof CC->usersupp.password);
+ lputuser(&CC->usersupp);
}
-#endif
}
+#endif
if (!code) {
(CC->logged_in) = 1;
*/
int purge_user(char pname[]) {
char filename[64];
- char mailboxname[ROOMNAMELEN];
struct usersupp usbuf;
- struct quickroom qrbuf;
char lowercase_name[32];
int a;
struct CitContext *ccptr;
if (user_is_logged_in == 1) {
lprintf(5, "User <%s> is logged in; not deleting.\n", pname);
usbuf.axlevel = 0;
- putuser(&usbuf, pname);
+ putuser(&usbuf);
return(1);
}
/* delete any existing user/room relationships */
cdb_delete(CDB_VISIT, &usbuf.usernum, sizeof(long));
- /* Delete the user's mailbox and its contents */
- MailboxName(mailboxname, &usbuf, MAILROOM);
- if (getroom(&qrbuf, mailboxname)==0) {
- delete_room(&qrbuf);
- }
-
/* delete the userlog entry */
cdb_delete(CDB_USERSUPP, lowercase_name, strlen(lowercase_name));
}
/* add user to userlog */
- putuser(&CC->usersupp,CC->curr_user);
+ putuser(&CC->usersupp);
if (getuser(&CC->usersupp,CC->curr_user)) {
return(ERROR+INTERNAL_ERROR);
}
}
lgetuser(&CC->usersupp,CC->curr_user);
strcpy(CC->usersupp.password,new_pw);
- lputuser(&CC->usersupp,CC->curr_user);
+ lputuser(&CC->usersupp);
cprintf("%d Password changed.\n",OK);
rec_log(CL_PWCHANGE,CC->curr_user);
PerformSessionHooks(EVT_SETPASS);
CC->usersupp.flags = CC->usersupp.flags & (~US_USER_SET);
CC->usersupp.flags = CC->usersupp.flags |
(extract_int(new_parms,2) & US_USER_SET);
- lputuser(&CC->usersupp,CC->curr_user);
+ lputuser(&CC->usersupp);
cprintf("%d Ok\n",OK);
}
vbuf.v_lastseen = newlr;
CtdlSetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
- lputuser(&CC->usersupp, CC->curr_user);
+ lputuser(&CC->usersupp);
cprintf("%d %ld\n",OK,newlr);
}
CtdlSetRelationship(&vbuf, &USscratch, &CC->quickroom);
- lputuser(&USscratch,iuser);
+ lputuser(&USscratch);
/* post a message in Aide> saying what we just did */
- sprintf(bbb,"%s %s %s> by %s",
+ sprintf(bbb,"%s %s %s> by %s\n",
iuser,
((op == 1) ? "invited to" : "kicked out of"),
CC->quickroom.QRname,
vbuf.v_flags = vbuf.v_flags & ~V_ACCESS;
CtdlSetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
- lputuser(&CC->usersupp,CC->curr_user);
+ lputuser(&CC->usersupp);
cprintf("%d Ok\n",OK);
usergoto(BASEROOM, 0);
}
*/
cdb_rewind(CDB_USERSUPP);
while (cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
- bzero(&usbuf, sizeof(struct usersupp));
+ memset(&usbuf, 0, sizeof(struct usersupp));
memcpy(&usbuf, cdbus->ptr,
( (cdbus->len > sizeof(struct usersupp)) ?
sizeof(struct usersupp) : cdbus->len) );
userbuf.axlevel = newax;
userbuf.flags = (userbuf.flags & ~US_NEEDVALID);
- lputuser(&userbuf,user);
+ lputuser(&userbuf);
/* If the access level was set to zero, delete the user */
if (newax == 0) {
cdb_rewind(CDB_USERSUPP);
while(cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
- bzero(&usbuf, sizeof(struct usersupp));
+ memset(&usbuf, 0, sizeof(struct usersupp));
memcpy(&usbuf, cdbus->ptr,
( (cdbus->len > sizeof(struct usersupp)) ?
sizeof(struct usersupp) : cdbus->len) );
strcpy(CC->usersupp.USphone,tmpphone);
strcpy(CC->usersupp.USemail,tmpemail);
CC->usersupp.flags=(CC->usersupp.flags|US_REGIS|US_NEEDVALID);
- lputuser(&CC->usersupp,CC->curr_user);
+ lputuser(&CC->usersupp);
/* set global flag calling for validation */
begin_critical_section(S_CONTROL);
usbuf.USuserpurge = extract_int(cmdbuf, 8);
}
- lputuser(&usbuf, requested_user);
+ lputuser(&usbuf);
if (usbuf.axlevel == 0) {
if (purge_user(requested_user)==0) {
cprintf("%d %s deleted.\n", OK, requested_user);
int NewMailCount() {
int num_newmsgs = 0;
int a;
- char mailboxname[32];
+ char mailboxname[ROOMNAMELEN];
struct quickroom mailbox;
struct visit vbuf;
+ struct cdbdata *cdbfr;
+ long *msglist = NULL;
+ int num_msgs = 0;
MailboxName(mailboxname, &CC->usersupp, MAILROOM);
if (getroom(&mailbox, mailboxname)!=0) return(0);
CtdlGetRelationship(&vbuf, &CC->usersupp, &mailbox);
- get_msglist(&mailbox);
- for (a=0; a<CC->num_msgs; ++a) {
- if (MessageFromList(a)>0L) {
- if (MessageFromList(a) > vbuf.v_lastseen) {
+ cdbfr = cdb_fetch(CDB_MSGLISTS, &mailbox.QRnumber, sizeof(long));
+
+ if (cdbfr != NULL) {
+ msglist = mallok(cdbfr->len);
+ memcpy(msglist, cdbfr->ptr, cdbfr->len);
+ num_msgs = cdbfr->len / sizeof(long);
+ cdb_free(cdbfr);
+ }
+
+ if (num_msgs > 0) for (a=0; a<num_msgs; ++a) {
+ if (msglist[a]>0L) {
+ if (msglist[a] > vbuf.v_lastseen) {
++num_newmsgs;
}
}
}
+ if (msglist != NULL) phree(msglist);
+
return(num_newmsgs);
}