Minor mods
[citadel.git] / citadel / user_ops.c
1 /* $Id$ */
2
3 /* needed to properly enable crypt() stuff on some systems */
4 #define _XOPEN_SOURCE
5 /* needed for str[n]casecmp() on some systems if the above is defined */
6 #define _XOPEN_SOURCE_EXTENDED
7 /* needed to enable threads on some systems if the above are defined */
8 #define _POSIX_C_SOURCE 199506L
9
10 #include <stdlib.h>
11 #include <unistd.h>
12 #include <stdio.h>
13 #include <fcntl.h>
14 #include <signal.h>
15 #include <pwd.h>
16 #include <sys/types.h>
17 #include <sys/time.h>
18 #include <string.h>
19 #include <syslog.h>
20 #include <limits.h>
21 #include <pthread.h>
22 #include "citadel.h"
23 #include "server.h"
24 #include "database.h"
25 #include "user_ops.h"
26 #include "sysdep_decls.h"
27 #include "support.h"
28 #include "room_ops.h"
29 #include "logging.h"
30 #include "file_ops.h"
31 #include "control.h"
32 #include "msgbase.h"
33 #include "config.h"
34 #include "dynloader.h"
35 #include "sysdep.h"
36
37
38 /*
39  * getuser()  -  retrieve named user into supplied buffer.
40  *               returns 0 on success
41  */
42 int getuser(struct usersupp *usbuf, char name[]) {
43
44         char lowercase_name[32];
45         int a;
46         struct cdbdata *cdbus;
47
48         bzero(usbuf, sizeof(struct usersupp));
49         for (a=0; a<=strlen(name); ++a) {
50                 lowercase_name[a] = tolower(name[a]);
51                 }
52
53         cdbus = cdb_fetch(CDB_USERSUPP, lowercase_name, strlen(lowercase_name));
54         if (cdbus == NULL) {
55                 return(1);      /* user not found */
56                 }
57
58         memcpy(usbuf, cdbus->ptr,
59                 ( (cdbus->len > sizeof(struct usersupp)) ?
60                 sizeof(struct usersupp) : cdbus->len) );
61         cdb_free(cdbus);
62         return(0);
63         }
64
65
66 /*
67  * lgetuser()  -  same as getuser() but locks the record
68  */
69 int lgetuser(struct usersupp *usbuf, char *name)
70 {
71         int retcode;
72
73         retcode = getuser(usbuf,name);
74         if (retcode == 0) {
75                 begin_critical_section(S_USERSUPP);
76                 }
77         return(retcode);
78         }
79
80
81 /*
82  * putuser()  -  write user buffer into the correct place on disk
83  */
84 void putuser(struct usersupp *usbuf, char *name)
85 {
86         char lowercase_name[32];
87         int a;
88
89         for (a=0; a<=strlen(name); ++a) {
90                 lowercase_name[a] = tolower(name[a]);
91                 }
92
93         cdb_store(CDB_USERSUPP,
94                 lowercase_name, strlen(lowercase_name),
95                 usbuf, sizeof(struct usersupp));
96
97         }
98
99
100 /*
101  * lputuser()  -  same as putuser() but locks the record
102  */
103 void lputuser(struct usersupp *usbuf, char *name) {
104         putuser(usbuf,name);
105         end_critical_section(S_USERSUPP);
106         }
107
108 /*
109  * Index-generating function used by Ctdl[Get|Set]Relationship
110  */
111 int GenerateRelationshipIndex(  char *IndexBuf,
112                                 long RoomID,
113                                 long RoomGen,
114                                 long UserID) {
115
116         struct {
117                 long iRoomID;
118                 long iRoomGen;
119                 long iUserID;
120                 } TheIndex;
121
122         TheIndex.iRoomID = RoomID;
123         TheIndex.iRoomGen = RoomGen;
124         TheIndex.iUserID = UserID;
125
126         memcpy(IndexBuf, &TheIndex, sizeof(TheIndex));
127         return(sizeof(TheIndex));
128         }
129
130 /*
131  * Define a relationship between a user and a room
132  */
133 void CtdlSetRelationship(struct visit *newvisit,
134                         struct usersupp *rel_user,
135                         struct quickroom *rel_room) {
136
137         char IndexBuf[32];
138         int IndexLen;
139
140         /* We don't use these in Citadel because they're implicit by the
141          * index, but they must be present if the database is exported.
142          */
143         newvisit->v_roomnum = rel_room->QRnumber;
144         newvisit->v_roomgen = rel_room->QRgen;
145         newvisit->v_usernum = rel_user->usernum;
146
147         /* Generate an index */
148         IndexLen = GenerateRelationshipIndex(IndexBuf,
149                 rel_room->QRnumber,
150                 rel_room->QRgen,
151                 rel_user->usernum);
152
153         /* Store the record */
154         cdb_store(CDB_VISIT, IndexBuf, IndexLen,
155                 newvisit, sizeof(struct visit)
156                 );
157         }
158
159 /*
160  * Locate a relationship between a user and a room
161  */
162 void CtdlGetRelationship(struct visit *vbuf,
163                         struct usersupp *rel_user,
164                         struct quickroom *rel_room) {
165
166         char IndexBuf[32];
167         int IndexLen;
168         struct cdbdata *cdbvisit;
169
170         /* Generate an index */
171         IndexLen = GenerateRelationshipIndex(IndexBuf,
172                 rel_room->QRnumber,
173                 rel_room->QRgen,
174                 rel_user->usernum);
175
176         /* Clear out the buffer */
177         bzero(vbuf, sizeof(struct visit));
178
179         cdbvisit = cdb_fetch(CDB_VISIT, IndexBuf, IndexLen);
180         if (cdbvisit != NULL) {
181                 memcpy(vbuf, cdbvisit->ptr,
182                         ( (cdbvisit->len > sizeof(struct visit)) ?
183                         sizeof(struct visit) : cdbvisit->len) );
184                 cdb_free(cdbvisit);
185                 return;
186                 }
187         }
188
189
190 void MailboxName(char *buf, struct usersupp *who, char *prefix) {
191         sprintf(buf, "%010ld.%s", who->usernum, prefix);
192         }
193
194         
195 /*
196  * Is the user currently logged in an Aide?
197  */
198 int is_aide(void) {
199         if (CC->usersupp.axlevel >= 6) return(1);
200         else return(0);
201         }
202
203
204 /*
205  * Is the user currently logged in an Aide *or* the room aide for this room?
206  */
207 int is_room_aide(void) {
208         if ( (CC->usersupp.axlevel >= 6)
209            || (CC->quickroom.QRroomaide == CC->usersupp.usernum) ) {
210                 return(1);
211                 }
212         else {
213                 return(0);
214                 }
215         }
216
217 /*
218  * getuserbynumber()  -  get user by number
219  *                       returns 0 if user was found
220  */
221 int getuserbynumber(struct usersupp *usbuf, long int number)
222 {
223         struct cdbdata *cdbus;
224
225         cdb_rewind(CDB_USERSUPP);
226
227         while(cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
228                 bzero(usbuf, sizeof(struct usersupp));
229                 memcpy(usbuf, cdbus->ptr,
230                         ( (cdbus->len > sizeof(struct usersupp)) ?
231                         sizeof(struct usersupp) : cdbus->len) );
232                 cdb_free(cdbus);
233                 if (usbuf->usernum == number) {
234                         return(0);
235                         }
236                 }
237         return(-1);
238         }
239
240
241 /*
242  * USER cmd
243  */
244 void cmd_user(char *cmdbuf)
245 {
246         char username[256];
247         char autoname[256];
248         int found_user = 0;
249         struct passwd *p;
250         int a;
251
252         extract(username,cmdbuf,0);
253         username[25] = 0;
254         strproc(username);
255
256         if ((CC->logged_in)) {
257                 cprintf("%d Already logged in.\n",ERROR);
258                 return;
259                 }
260
261         found_user = getuser(&CC->usersupp,username);
262         if (found_user != 0) {
263                 p = (struct passwd *)getpwnam(username);
264                 if (p!=NULL) {
265                         strcpy(autoname,p->pw_gecos);
266                         for (a=0; a<strlen(autoname); ++a)
267                                 if (autoname[a]==',') autoname[a]=0;
268                         found_user = getuser(&CC->usersupp,autoname);
269                         }
270                 }
271         if (found_user == 0) {
272                 if (((CC->nologin)) && (CC->usersupp.axlevel < 6)) {
273                         cprintf("%d %s: Too many users are already online (maximum is %d)\n",
274                         ERROR+MAX_SESSIONS_EXCEEDED,
275                         config.c_nodename,config.c_maxsessions);
276                         }
277                 else {
278                         strcpy(CC->curr_user,CC->usersupp.fullname);
279                         cprintf("%d Password required for %s\n",
280                                 MORE_DATA,CC->curr_user);
281                         }
282                 }
283         else {
284                 cprintf("%d %s not found.\n",ERROR,username);
285                 }
286         }
287
288
289
290 /*
291  * session startup code which is common to both cmd_pass() and cmd_newu()
292  */
293 void session_startup(void) {
294         syslog(LOG_NOTICE,"user <%s> logged in",CC->curr_user);
295
296         lgetuser(&CC->usersupp,CC->curr_user);
297         ++(CC->usersupp.timescalled);
298         CC->fake_username[0] = '\0';
299         CC->fake_postname[0] = '\0';
300         CC->fake_hostname[0] = '\0';
301         CC->fake_roomname[0] = '\0';
302         CC->last_pager[0] = '\0';
303         time(&CC->usersupp.lastcall);
304
305         /* If this user's name is the name of the system administrator
306          * (as specified in setup), automatically assign access level 6.
307          */
308         if (!strcasecmp(CC->usersupp.fullname, config.c_sysadm)) {
309                 CC->usersupp.axlevel = 6;
310                 }
311
312         lputuser(&CC->usersupp,CC->curr_user);
313
314         /* Run any cleanup routines registered by loadable modules */
315         PerformSessionHooks(EVT_LOGIN);
316
317         cprintf("%d %s|%d|%d|%d|%u|%ld\n",OK,CC->usersupp.fullname,CC->usersupp.axlevel,
318                 CC->usersupp.timescalled,CC->usersupp.posted,CC->usersupp.flags,
319                 CC->usersupp.usernum);
320         usergoto(BASEROOM,0);           /* Enter the lobby */   
321         rec_log(CL_LOGIN,CC->curr_user);
322         }
323
324
325 /* 
326  * misc things to be taken care of when a user is logged out
327  */
328 void logout(struct CitContext *who)
329 {
330         who->logged_in = 0;
331         if (who->download_fp != NULL) {
332                 fclose(who->download_fp);
333                 who->download_fp = NULL;
334                 }
335         if (who->upload_fp != NULL) {
336                 abort_upl(who);
337                 }
338
339         /* Do modular stuff... */
340         PerformSessionHooks(EVT_LOGOUT);
341         }
342
343
344 void cmd_pass(char *buf)
345 {
346         char password[256];
347         int code;
348         struct passwd *p;
349
350         extract(password,buf,0);
351
352         if ((CC->logged_in)) {
353                 cprintf("%d Already logged in.\n",ERROR);
354                 return;
355                 }
356         if (!strcmp(CC->curr_user,"")) {
357                 cprintf("%d You must send a name with USER first.\n",ERROR);
358                 return;
359                 }
360         if (getuser(&CC->usersupp,CC->curr_user)) {
361                 cprintf("%d Can't find user record!\n",ERROR+INTERNAL_ERROR);
362                 return;
363                 }
364
365         code = (-1);
366         if (CC->usersupp.USuid == BBSUID) {
367                 strproc(password);
368                 strproc(CC->usersupp.password);
369                 code = strcasecmp(CC->usersupp.password,password);
370                 }
371         else {
372                 p = (struct passwd *)getpwuid(CC->usersupp.USuid);
373 #ifdef ENABLE_AUTOLOGIN
374                 if (p!=NULL) {
375                         if (!strcmp(p->pw_passwd,
376                            (char *)crypt(password,p->pw_passwd))) {
377                                 code = 0;
378                                 lgetuser(&CC->usersupp, CC->curr_user);
379                                 strcpy(CC->usersupp.password, password);
380                                 lputuser(&CC->usersupp, CC->curr_user);
381                                 }
382                         }
383 #endif
384                 }
385
386         if (!code) {
387                 (CC->logged_in) = 1;
388                 session_startup();
389                 }
390         else {
391                 cprintf("%d Wrong password.\n",ERROR);
392                 rec_log(CL_BADPW,CC->curr_user);
393                 }
394         }
395
396
397 /*
398  * Delete a user record *and* all of its related resources.
399  */
400 int purge_user(char pname[]) {
401         char filename[64];
402         char mailboxname[ROOMNAMELEN];
403         struct usersupp usbuf;
404         struct quickroom qrbuf;
405         char lowercase_name[32];
406         int a;
407         struct CitContext *ccptr;
408         int user_is_logged_in = 0;
409
410         for (a=0; a<=strlen(pname); ++a) {
411                 lowercase_name[a] = tolower(pname[a]);
412                 }
413
414         if (getuser(&usbuf, pname) != 0) {
415                 lprintf(5, "Cannot purge user <%s> - not found\n", pname);
416                 return(ERROR+NO_SUCH_USER);
417                 }
418
419         /* Don't delete a user who is currently logged in.  Instead, just
420          * set the access level to 0, and let the account get swept up
421          * during the next purge.
422          */
423         user_is_logged_in = 0;
424         begin_critical_section(S_SESSION_TABLE);
425         for (ccptr=ContextList; ccptr!=NULL; ccptr=ccptr->next) {
426                 if (ccptr->usersupp.usernum == usbuf.usernum) {
427                         user_is_logged_in = 1;
428                         }
429                 }
430         end_critical_section(S_SESSION_TABLE);
431         if (user_is_logged_in == 1) {
432                 lprintf(5, "User <%s> is logged in; not deleting.\n", pname);
433                 usbuf.axlevel = 0;
434                 putuser(&usbuf, pname);
435                 return(1);
436                 }
437
438         lprintf(5, "Deleting user <%s>\n", pname);
439
440         /* Perform any purge functions registered by server extensions */
441         PerformUserHooks(usbuf.fullname, usbuf.usernum, EVT_PURGEUSER);
442
443         /* delete any existing user/room relationships */
444         cdb_delete(CDB_VISIT, &usbuf.usernum, sizeof(long));
445
446         /* Delete the user's mailbox and its contents */
447         MailboxName(mailboxname, &usbuf, MAILROOM);
448         if (getroom(&qrbuf, mailboxname)==0) {
449                 delete_room(&qrbuf);
450                 }
451
452         /* delete the userlog entry */
453         cdb_delete(CDB_USERSUPP, lowercase_name, strlen(lowercase_name));
454
455         /* remove the user's bio file */        
456         sprintf(filename, "./bio/%ld", usbuf.usernum);
457         unlink(filename);
458
459         /* remove the user's picture */
460         sprintf(filename, "./userpics/%ld.gif", usbuf.usernum);
461         unlink(filename);
462
463         return(0);
464         }
465
466
467 /*
468  * create_user()  -  back end processing to create a new user
469  */
470 int create_user(char *newusername)
471 {
472         struct usersupp usbuf;
473         int a;
474         struct passwd *p = NULL;
475         char username[64];
476         char mailboxname[ROOMNAMELEN];
477
478         strcpy(username, newusername);
479         strproc(username);
480
481 #ifdef ENABLE_AUTOLOGIN
482         p = (struct passwd *)getpwnam(username);
483 #endif
484         if (p != NULL) {
485                 strcpy(username, p->pw_gecos);
486                 for (a=0; a<strlen(username); ++a) {
487                         if (username[a] == ',') username[a] = 0;
488                         }
489                 CC->usersupp.USuid = p->pw_uid;
490                 }
491         else {
492                 CC->usersupp.USuid = BBSUID;
493                 }
494
495         if (!getuser(&usbuf,username)) {
496                 return(ERROR+ALREADY_EXISTS);
497                 }
498
499         strcpy(CC->curr_user,username);
500         strcpy(CC->usersupp.fullname,username);
501         strcpy(CC->usersupp.password,"");
502         (CC->logged_in) = 1;
503
504         /* These are the default flags on new accounts */
505         CC->usersupp.flags =
506                 US_NEEDVALID|US_LASTOLD|US_DISAPPEAR|US_PAGINATOR|US_FLOORS;
507
508         CC->usersupp.timescalled = 0;
509         CC->usersupp.posted = 0;
510         CC->usersupp.axlevel = config.c_initax;
511         CC->usersupp.USscreenwidth = 80;
512         CC->usersupp.USscreenheight = 24;
513         time(&CC->usersupp.lastcall);
514         strcpy(CC->usersupp.USname, "");
515         strcpy(CC->usersupp.USaddr, "");
516         strcpy(CC->usersupp.UScity, "");
517         strcpy(CC->usersupp.USstate, "");
518         strcpy(CC->usersupp.USzip, "");
519         strcpy(CC->usersupp.USphone, "");
520
521         /* fetch a new user number */
522         CC->usersupp.usernum = get_new_user_number();
523
524         if (CC->usersupp.usernum == 1L) {
525                 CC->usersupp.axlevel = 6;
526                 }
527
528         /* add user to userlog */
529         putuser(&CC->usersupp,CC->curr_user);
530         if (getuser(&CC->usersupp,CC->curr_user)) {
531                 return(ERROR+INTERNAL_ERROR);
532                 }
533
534         /* give the user a private mailbox */
535         MailboxName(mailboxname, &CC->usersupp, MAILROOM);
536         create_room(mailboxname, 4, "", 0);
537
538         rec_log(CL_NEWUSER,CC->curr_user);
539         return(0);
540         }
541
542
543
544
545 /*
546  * cmd_newu()  -  create a new user account
547  */
548 void cmd_newu(char *cmdbuf)
549 {
550         int a;
551         char username[256];
552
553         if ((CC->logged_in)) {
554                 cprintf("%d Already logged in.\n",ERROR);
555                 return;
556                 }
557
558         if ((CC->nologin)) {
559                 cprintf("%d %s: Too many users are already online (maximum is %d)\n",
560                 ERROR+MAX_SESSIONS_EXCEEDED,
561                 config.c_nodename,config.c_maxsessions);
562                 }
563
564         extract(username,cmdbuf,0);
565         username[25] = 0;
566         strproc(username);
567
568         if (strlen(username)==0) {
569                 cprintf("%d You must supply a user name.\n",ERROR);
570                 return;
571                 }
572
573         a = create_user(username);
574         if ((!strcasecmp(username, "bbs")) ||
575             (!strcasecmp(username, "new")) ||
576             (!strcasecmp(username, ".")))
577         {
578            cprintf("%d '%s' is an invalid login name.\n", ERROR);
579            return;
580         }
581         if (a==ERROR+ALREADY_EXISTS) {
582                 cprintf("%d '%s' already exists.\n",
583                         ERROR+ALREADY_EXISTS,username);
584                 return;
585                 }
586         else if (a==ERROR+INTERNAL_ERROR) {
587                 cprintf("%d Internal error - user record disappeared?\n",
588                         ERROR+INTERNAL_ERROR);
589                 return;
590                 }
591         else if (a==0) {
592                 session_startup();
593                 }
594         else {
595                 cprintf("%d unknown error\n",ERROR);
596                 }
597         rec_log(CL_NEWUSER,CC->curr_user);
598         }
599
600
601
602 /*
603  * set password
604  */
605 void cmd_setp(char *new_pw)
606 {
607         if (!(CC->logged_in)) {
608                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
609                 return;
610                 }
611         if (CC->usersupp.USuid != BBSUID) {
612                 cprintf("%d Not allowed.  Use the 'passwd' command.\n",ERROR);
613                 return;
614                 }
615         strproc(new_pw);
616         if (strlen(new_pw)==0) {
617                 cprintf("%d Password unchanged.\n",OK);
618                 return;
619                 }
620         lgetuser(&CC->usersupp,CC->curr_user);
621         strcpy(CC->usersupp.password,new_pw);
622         lputuser(&CC->usersupp,CC->curr_user);
623         cprintf("%d Password changed.\n",OK);
624         rec_log(CL_PWCHANGE,CC->curr_user);
625         PerformSessionHooks(EVT_SETPASS);
626         }
627
628 /*
629  * get user parameters
630  */
631 void cmd_getu(void) {
632         if (!(CC->logged_in)) {
633                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
634                 return;
635                 }
636         getuser(&CC->usersupp,CC->curr_user);
637         cprintf("%d %d|%d|%d\n",
638                 OK,
639                 CC->usersupp.USscreenwidth,
640                 CC->usersupp.USscreenheight,
641                 (CC->usersupp.flags & US_USER_SET)
642                 );
643         }
644
645 /*
646  * set user parameters
647  */
648 void cmd_setu(char *new_parms)
649 {
650
651         if (num_parms(new_parms)!=3) {
652                 cprintf("%d Usage error.\n",ERROR);
653                 return;
654                 }       
655         if (!(CC->logged_in)) {
656                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
657                 return;
658                 }
659         lgetuser(&CC->usersupp,CC->curr_user);
660         CC->usersupp.USscreenwidth = extract_int(new_parms,0);
661         CC->usersupp.USscreenheight = extract_int(new_parms,1);
662         CC->usersupp.flags = CC->usersupp.flags & (~US_USER_SET);
663         CC->usersupp.flags = CC->usersupp.flags | 
664                 (extract_int(new_parms,2) & US_USER_SET);
665         lputuser(&CC->usersupp,CC->curr_user);
666         cprintf("%d Ok\n",OK);
667         }
668
669 /*
670  * set last read pointer
671  */
672 void cmd_slrp(char *new_ptr)
673 {
674         long newlr;
675         struct visit vbuf;
676
677         if (!(CC->logged_in)) {
678                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
679                 return;
680                 }
681
682         if (!strncasecmp(new_ptr,"highest",7)) {
683                 newlr = CC->quickroom.QRhighest;
684                 }
685         else {
686                 newlr = atol(new_ptr);
687                 }
688
689         lgetuser(&CC->usersupp, CC->curr_user);
690
691         CtdlGetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
692         vbuf.v_lastseen = newlr;
693         CtdlSetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
694
695         lputuser(&CC->usersupp, CC->curr_user);
696         cprintf("%d %ld\n",OK,newlr);
697         }
698
699
700 /*
701  * INVT and KICK commands
702  */
703 void cmd_invt_kick(char *iuser, int op)
704                         /* user name */
705         {               /* 1 = invite, 0 = kick out */
706         struct usersupp USscratch;
707         char bbb[256];
708         struct visit vbuf;
709
710         if (!(CC->logged_in)) {
711                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
712                 return;
713                 }
714
715         if (is_room_aide()==0) {
716                 cprintf("%d Higher access required.\n",
717                         ERROR+HIGHER_ACCESS_REQUIRED);
718                 return;
719                 }
720
721         if (lgetuser(&USscratch,iuser)!=0) {
722                 cprintf("%d No such user.\n",ERROR);
723                 return;
724                 }
725
726         CtdlGetRelationship(&vbuf, &USscratch, &CC->quickroom);
727
728         if (op==1) {
729                 vbuf.v_flags = vbuf.v_flags & ~V_FORGET & ~V_LOCKOUT;
730                 vbuf.v_flags = vbuf.v_flags | V_ACCESS;
731                 }
732
733         if (op==0) {
734                 vbuf.v_flags = vbuf.v_flags & ~V_ACCESS;
735                 vbuf.v_flags = vbuf.v_flags | V_FORGET | V_LOCKOUT;
736                 }
737
738         CtdlSetRelationship(&vbuf, &USscratch, &CC->quickroom);
739
740         lputuser(&USscratch,iuser);
741
742         /* post a message in Aide> saying what we just did */
743         sprintf(bbb,"%s %s %s> by %s",
744                 iuser,
745                 ((op == 1) ? "invited to" : "kicked out of"),
746                 CC->quickroom.QRname,
747                 CC->usersupp.fullname);
748         aide_message(bbb);
749
750         cprintf("%d %s %s %s.\n",
751                 OK, iuser,
752                 ((op == 1) ? "invited to" : "kicked out of"),
753                 CC->quickroom.QRname);
754         return;
755         }
756
757
758 /*
759  * forget (Zap) the current room
760  */
761 void cmd_forg(void) {
762         struct visit vbuf;
763
764         if (!(CC->logged_in)) {
765                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
766                 return;
767                 }
768
769         if (is_aide()) {
770                 cprintf("%d Aides cannot forget rooms.\n",ERROR);
771                 return;
772                 }
773
774         lgetuser(&CC->usersupp,CC->curr_user);
775         CtdlGetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
776
777         vbuf.v_flags = vbuf.v_flags | V_FORGET;
778
779         CtdlSetRelationship(&vbuf, &CC->usersupp, &CC->quickroom);
780         lputuser(&CC->usersupp,CC->curr_user);
781         cprintf("%d Ok\n",OK);
782         usergoto(BASEROOM, 0);
783         }
784
785 /*
786  * Get Next Unregistered User
787  */
788 void cmd_gnur(void) {
789         struct cdbdata *cdbus;
790         struct usersupp usbuf;
791
792         if (!(CC->logged_in)) {
793                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
794                 return;
795                 }
796
797         if (CC->usersupp.axlevel < 6) {
798                 cprintf("%d Higher access required.\n",
799                         ERROR+HIGHER_ACCESS_REQUIRED);
800                 return;
801                 }
802
803         if ((CitControl.MMflags&MM_VALID)==0) {
804                 cprintf("%d There are no unvalidated users.\n",OK);
805                 return;
806                 }
807
808         /* There are unvalidated users.  Traverse the usersupp database,
809          * and return the first user we find that needs validation.
810          */
811         cdb_rewind(CDB_USERSUPP);
812         while (cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
813                 bzero(&usbuf, sizeof(struct usersupp));
814                 memcpy(&usbuf, cdbus->ptr,
815                         ( (cdbus->len > sizeof(struct usersupp)) ?
816                         sizeof(struct usersupp) : cdbus->len) );
817                 cdb_free(cdbus);
818                 if ((usbuf.flags & US_NEEDVALID)
819                    &&(usbuf.axlevel > 0)) {
820                         cprintf("%d %s\n",MORE_DATA,usbuf.fullname);
821                         return;
822                         }
823                 } 
824
825         /* If we get to this point, there are no more unvalidated users.
826          * Therefore we clear the "users need validation" flag.
827          */
828
829         begin_critical_section(S_CONTROL);
830         get_control();
831         CitControl.MMflags = CitControl.MMflags&(~MM_VALID);
832         put_control();
833         end_critical_section(S_CONTROL);
834         cprintf("%d *** End of registration.\n",OK);
835
836
837         }
838
839
840 /*
841  * get registration info for a user
842  */
843 void cmd_greg(char *who)
844 {
845         struct usersupp usbuf;
846         int a,b;
847         char pbuf[32];
848
849         if (!(CC->logged_in)) {
850                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
851                 return;
852                 }
853
854         if (!strcasecmp(who,"_SELF_")) strcpy(who,CC->curr_user);
855
856         if ((CC->usersupp.axlevel < 6) && (strcasecmp(who,CC->curr_user))) {
857                 cprintf("%d Higher access required.\n",
858                         ERROR+HIGHER_ACCESS_REQUIRED);
859                 return;
860                 }
861
862         if (getuser(&usbuf,who) != 0) {
863                 cprintf("%d '%s' not found.\n",ERROR+NO_SUCH_USER,who);
864                 return;
865                 }
866
867         cprintf("%d %s\n",LISTING_FOLLOWS,usbuf.fullname);
868         cprintf("%ld\n",usbuf.usernum);
869         cprintf("%s\n",usbuf.password);
870         cprintf("%s\n",usbuf.USname);
871         cprintf("%s\n",usbuf.USaddr);
872         cprintf("%s\n%s\n%s\n",
873                 usbuf.UScity,usbuf.USstate,usbuf.USzip);
874         strcpy(pbuf,usbuf.USphone);
875         usbuf.USphone[0]=0;
876         for (a=0; a<strlen(pbuf); ++a) {
877                 if ((pbuf[a]>='0')&&(pbuf[a]<='9')) {
878                         b=strlen(usbuf.USphone);
879                         usbuf.USphone[b]=pbuf[a];
880                         usbuf.USphone[b+1]=0;
881                         }
882                 }
883         while(strlen(usbuf.USphone)<10) {
884                 strcpy(pbuf,usbuf.USphone);
885                 strcpy(usbuf.USphone," ");
886                 strcat(usbuf.USphone,pbuf);
887                 }
888
889         cprintf("(%c%c%c) %c%c%c-%c%c%c%c\n",
890                 usbuf.USphone[0],usbuf.USphone[1],
891                 usbuf.USphone[2],usbuf.USphone[3],
892                 usbuf.USphone[4],usbuf.USphone[5],
893                 usbuf.USphone[6],usbuf.USphone[7],
894                 usbuf.USphone[8],usbuf.USphone[9]);
895
896         cprintf("%d\n",usbuf.axlevel);
897         cprintf("%s\n",usbuf.USemail);
898         cprintf("000\n");
899         }
900
901 /*
902  * validate a user
903  */
904 void cmd_vali(char *v_args)
905 {
906         char user[256];
907         int newax;
908         struct usersupp userbuf;
909
910         extract(user,v_args,0);
911         newax = extract_int(v_args,1);
912
913         if (!(CC->logged_in)) {
914                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
915                 return;
916                 }
917
918         if (CC->usersupp.axlevel < 6) {
919                 cprintf("%d Higher access required.\n",
920                         ERROR+HIGHER_ACCESS_REQUIRED);
921                 return;
922                 }
923
924         if (lgetuser(&userbuf,user)!=0) {
925                 cprintf("%d '%s' not found.\n",ERROR+NO_SUCH_USER,user);
926                 return;
927                 }
928
929         userbuf.axlevel = newax;
930         userbuf.flags = (userbuf.flags & ~US_NEEDVALID);
931
932         lputuser(&userbuf,user);
933
934         /* If the access level was set to zero, delete the user */
935         if (newax == 0) {
936                 if (purge_user(user)==0) {
937                         cprintf("%d %s Deleted.\n", OK, userbuf.fullname);
938                         return;
939                         }
940                 }
941
942         cprintf("%d ok\n",OK);
943         }
944
945
946
947 /* 
948  *  Traverse the user file...
949  */
950 void ForEachUser(void (*CallBack)(struct usersupp *EachUser)) {
951         struct usersupp usbuf;
952         struct cdbdata *cdbus;
953
954         cdb_rewind(CDB_USERSUPP);
955
956         while(cdbus = cdb_next_item(CDB_USERSUPP), cdbus != NULL) {
957                 bzero(&usbuf, sizeof(struct usersupp));
958                 memcpy(&usbuf, cdbus->ptr,
959                         ( (cdbus->len > sizeof(struct usersupp)) ?
960                         sizeof(struct usersupp) : cdbus->len) );
961                 cdb_free(cdbus);
962                 (*CallBack)(&usbuf);
963                 }
964         }
965
966
967 /*
968  * List one user (this works with cmd_list)
969  */
970 void ListThisUser(struct usersupp *usbuf) {
971         if (usbuf->axlevel > 0) {
972                 if ((CC->usersupp.axlevel>=6)
973                    ||((usbuf->flags&US_UNLISTED)==0)
974                    ||((CC->internal_pgm))) {
975                         cprintf("%s|%d|%ld|%ld|%d|%d|",
976                                 usbuf->fullname,
977                                 usbuf->axlevel,
978                                 usbuf->usernum,
979                                 usbuf->lastcall,
980                                 usbuf->timescalled,
981                                 usbuf->posted);
982                         if (CC->usersupp.axlevel >= 6)
983                                 cprintf("%s",usbuf->password);
984                         cprintf("\n");
985                         }
986                 }
987         }
988
989 /* 
990  *  List users
991  */
992 void cmd_list(void) {
993         cprintf("%d \n",LISTING_FOLLOWS);
994         ForEachUser(ListThisUser);
995         cprintf("000\n");
996         }
997
998
999 /*
1000  * enter registration info
1001  */
1002 void cmd_regi(void) {
1003         int a,b,c;
1004         char buf[256];
1005
1006         char tmpname[256];
1007         char tmpaddr[256];
1008         char tmpcity[256];
1009         char tmpstate[256];
1010         char tmpzip[256];
1011         char tmpphone[256];
1012         char tmpemail[256];
1013
1014         if (!(CC->logged_in)) {
1015                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
1016                 return;
1017                 }
1018
1019         strcpy(tmpname,"");
1020         strcpy(tmpaddr,"");
1021         strcpy(tmpcity,"");
1022         strcpy(tmpstate,"");
1023         strcpy(tmpzip,"");
1024         strcpy(tmpphone,"");
1025         strcpy(tmpemail,"");
1026
1027         cprintf("%d Send registration...\n",SEND_LISTING);
1028         a=0;
1029         while (client_gets(buf), strcmp(buf,"000")) {
1030                 if (a==0) strcpy(tmpname,buf);
1031                 if (a==1) strcpy(tmpaddr,buf);
1032                 if (a==2) strcpy(tmpcity,buf);
1033                 if (a==3) strcpy(tmpstate,buf);
1034                 if (a==4) {
1035                         for (c=0; c<strlen(buf); ++c) {
1036                                 if ((buf[c]>='0')&&(buf[c]<='9')) {
1037                                         b=strlen(tmpzip);
1038                                         tmpzip[b]=buf[c];
1039                                         tmpzip[b+1]=0;
1040                                         }
1041                                 }
1042                         }
1043                 if (a==5) {
1044                         for (c=0; c<strlen(buf); ++c) {
1045                                 if ((buf[c]>='0')&&(buf[c]<='9')) {
1046                                         b=strlen(tmpphone);
1047                                         tmpphone[b]=buf[c];
1048                                         tmpphone[b+1]=0;
1049                                         }
1050                                 }
1051                         }
1052                 if (a==6) strncpy(tmpemail,buf,31);
1053                 ++a;
1054                 }
1055
1056         tmpname[29]=0;
1057         tmpaddr[24]=0;
1058         tmpcity[14]=0;
1059         tmpstate[2]=0;
1060         tmpzip[9]=0;
1061         tmpphone[10]=0;
1062         tmpemail[31]=0;
1063
1064         lgetuser(&CC->usersupp,CC->curr_user);
1065         strcpy(CC->usersupp.USname,tmpname);
1066         strcpy(CC->usersupp.USaddr,tmpaddr);
1067         strcpy(CC->usersupp.UScity,tmpcity);
1068         strcpy(CC->usersupp.USstate,tmpstate);
1069         strcpy(CC->usersupp.USzip,tmpzip);
1070         strcpy(CC->usersupp.USphone,tmpphone);
1071         strcpy(CC->usersupp.USemail,tmpemail);
1072         CC->usersupp.flags=(CC->usersupp.flags|US_REGIS|US_NEEDVALID);
1073         lputuser(&CC->usersupp,CC->curr_user);
1074
1075         /* set global flag calling for validation */
1076         begin_critical_section(S_CONTROL);
1077         get_control();
1078         CitControl.MMflags = CitControl.MMflags | MM_VALID ;
1079         put_control();
1080         end_critical_section(S_CONTROL);
1081         cprintf("%d *** End of registration.\n",OK);
1082         }
1083
1084
1085 /*
1086  * assorted info we need to check at login
1087  */
1088 void cmd_chek(void) {
1089         int mail = 0;
1090         int regis = 0;
1091         int vali = 0;
1092         
1093         if (!(CC->logged_in)) {
1094                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
1095                 return;
1096                 }
1097
1098         getuser(&CC->usersupp,CC->curr_user); /* no lock is needed here */
1099         if ((REGISCALL!=0)&&((CC->usersupp.flags&US_REGIS)==0)) regis = 1;
1100
1101         if (CC->usersupp.axlevel >= 6) {
1102                 get_control();
1103                 if (CitControl.MMflags&MM_VALID) vali = 1;
1104                 }
1105
1106
1107         /* check for mail */
1108         mail = NewMailCount();
1109
1110         cprintf("%d %d|%d|%d\n",OK,mail,regis,vali);
1111         }
1112
1113
1114 /*
1115  * check to see if a user exists
1116  */
1117 void cmd_qusr(char *who)
1118 {
1119         struct usersupp usbuf;
1120
1121         if (getuser(&usbuf,who) == 0) {
1122                 cprintf("%d %s\n",OK,usbuf.fullname);
1123                 }
1124         else {
1125                 cprintf("%d No such user.\n",ERROR+NO_SUCH_USER);
1126                 }
1127         }
1128
1129
1130 /*
1131  * enter user bio
1132  */
1133 void cmd_ebio(void) {
1134         char buf[256];
1135         FILE *fp;
1136
1137         if (!(CC->logged_in)) {
1138                 cprintf("%d Not logged in.\n",ERROR+NOT_LOGGED_IN);
1139                 return;
1140                 }
1141
1142         sprintf(buf,"./bio/%ld",CC->usersupp.usernum);
1143         fp = fopen(buf,"w");
1144         if (fp == NULL) {
1145                 cprintf("%d Cannot create file\n",ERROR);
1146                 return;
1147                 }
1148         cprintf("%d  \n",SEND_LISTING);
1149         while(client_gets(buf), strcmp(buf,"000")) {
1150                 fprintf(fp,"%s\n",buf);
1151                 }
1152         fclose(fp);
1153         }
1154
1155 /*
1156  * read user bio
1157  */
1158 void cmd_rbio(char *cmdbuf)
1159 {
1160         struct usersupp ruser;
1161         char buf[256];
1162         FILE *fp;
1163
1164         extract(buf,cmdbuf,0);
1165         if (getuser(&ruser,buf)!=0) {
1166                 cprintf("%d No such user.\n",ERROR+NO_SUCH_USER);
1167                 return;
1168                 }
1169         sprintf(buf,"./bio/%ld",ruser.usernum);
1170         
1171         fp = fopen(buf,"r");
1172         if (fp == NULL) {
1173                 cprintf("%d %s has no bio on file.\n",
1174                         ERROR+FILE_NOT_FOUND,ruser.fullname);
1175                 return;
1176                 }
1177         cprintf("%d  \n",LISTING_FOLLOWS);
1178         while (fgets(buf,256,fp)!=NULL) cprintf("%s",buf);
1179         fclose(fp);
1180         cprintf("000\n");
1181         }
1182
1183 /*
1184  * list of users who have entered bios
1185  */
1186 void cmd_lbio(void) {
1187         char buf[256];
1188         FILE *ls;
1189         struct usersupp usbuf;
1190
1191         ls=popen("cd ./bio; ls","r");
1192         if (ls==NULL) {
1193                 cprintf("%d Cannot open listing.\n",ERROR+FILE_NOT_FOUND);
1194                 return;
1195                 }
1196
1197         cprintf("%d\n",LISTING_FOLLOWS);
1198         while (fgets(buf,255,ls)!=NULL)
1199                 if (getuserbynumber(&usbuf,atol(buf))==0)
1200                         cprintf("%s\n",usbuf.fullname);
1201         pclose(ls);
1202         cprintf("000\n");
1203         }
1204
1205
1206 /*
1207  * Administrative Get User Parameters
1208  */
1209 void cmd_agup(char *cmdbuf) {
1210         struct usersupp usbuf;
1211         char requested_user[256];
1212
1213         if ( (CC->internal_pgm==0)
1214            && ( (CC->logged_in == 0) || (is_aide()==0) ) ) {
1215                 cprintf("%d Higher access required.\n", 
1216                         ERROR + HIGHER_ACCESS_REQUIRED);
1217                 return;
1218                 }
1219
1220         extract(requested_user, cmdbuf, 0);
1221         if (getuser(&usbuf, requested_user) != 0) {
1222                 cprintf("%d No such user.\n", ERROR + NO_SUCH_USER);
1223                 return;
1224                 }
1225
1226         cprintf("%d %s|%s|%u|%d|%d|%d|%ld|%ld|%d\n", 
1227                 OK,
1228                 usbuf.fullname,
1229                 usbuf.password,
1230                 usbuf.flags,
1231                 usbuf.timescalled,
1232                 usbuf.posted,
1233                 (int)usbuf.axlevel,
1234                 usbuf.usernum,
1235                 usbuf.lastcall,
1236                 usbuf.USuserpurge);
1237         }
1238
1239
1240
1241 /*
1242  * Administrative Set User Parameters
1243  */
1244 void cmd_asup(char *cmdbuf) {
1245         struct usersupp usbuf;
1246         char requested_user[256];
1247         int np;
1248         int newax;
1249         
1250         if ( (CC->internal_pgm==0)
1251            && ( (CC->logged_in == 0) || (is_aide()==0) ) ) {
1252                 cprintf("%d Higher access required.\n", 
1253                         ERROR + HIGHER_ACCESS_REQUIRED);
1254                 return;
1255                 }
1256
1257         extract(requested_user, cmdbuf, 0);
1258         if (lgetuser(&usbuf, requested_user) != 0) {
1259                 cprintf("%d No such user.\n", ERROR + NO_SUCH_USER);
1260                 return;
1261                 }
1262
1263         np = num_parms(cmdbuf);
1264         if (np > 1) extract(usbuf.password, cmdbuf, 1);
1265         if (np > 2) usbuf.flags = extract_int(cmdbuf, 2);
1266         if (np > 3) usbuf.timescalled = extract_int(cmdbuf, 3);
1267         if (np > 4) usbuf.posted = extract_int(cmdbuf, 4);
1268         if (np > 5) {
1269                 newax = extract_int(cmdbuf, 5);
1270                 if ((newax >=0) && (newax <= 6)) {
1271                         usbuf.axlevel = extract_int(cmdbuf, 5);
1272                         }
1273                 }
1274         if (np > 7) {
1275                 usbuf.lastcall = extract_long(cmdbuf, 7);
1276                 }
1277         if (np > 8) {
1278                 usbuf.USuserpurge = extract_int(cmdbuf, 8);
1279                 }
1280
1281         lputuser(&usbuf, requested_user);
1282         if (usbuf.axlevel == 0) {
1283                 if (purge_user(requested_user)==0) {
1284                         cprintf("%d %s deleted.\n", OK, requested_user);
1285                         }
1286                 }
1287         cprintf("%d Ok\n", OK);
1288         }
1289
1290
1291 /*
1292  * Count the number of new mail messages the user has
1293  */
1294 int NewMailCount() {
1295         int num_newmsgs = 0;
1296         int a;
1297         char mailboxname[32];
1298         struct quickroom mailbox;
1299         struct visit vbuf;
1300
1301         MailboxName(mailboxname, &CC->usersupp, MAILROOM);
1302         if (getroom(&mailbox, mailboxname)!=0) return(0);
1303         CtdlGetRelationship(&vbuf, &CC->usersupp, &mailbox);
1304
1305         get_msglist(&mailbox);
1306         for (a=0; a<CC->num_msgs; ++a) {
1307                 if (MessageFromList(a)>0L) {
1308                         if (MessageFromList(a) > vbuf.v_lastseen) {
1309                                 ++num_newmsgs;
1310                                 }
1311                         }
1312                 }
1313
1314         return(num_newmsgs);
1315         }