/*
* Implements the message store.
*
- * Copyright (c) 1987-2010 by the citadel.org team
+ * Copyright (c) 1987-2011 by the citadel.org team
*
- * This program is free software; you can redistribute it and/or modify
+ * This program is open source software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 3 of the License, or
* (at your option) any later version.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
+ * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
*/
#include "sysdep.h"
/* Load the message list */
cdbfr = cdb_fetch(CDB_MSGLISTS, &CC->room.QRnumber, sizeof(long));
- if (cdbfr != NULL) {
- msglist = (long *) cdbfr->ptr;
- num_msgs = cdbfr->len / sizeof(long);
- } else {
+ if (cdbfr == NULL) {
if (need_to_free_re) regfree(&re);
return 0; /* No messages at all? No further action. */
}
+ msglist = (long *) cdbfr->ptr;
+ num_msgs = cdbfr->len / sizeof(long);
+
+ cdbfr->ptr = NULL; /* clear this so that cdb_free() doesn't free it */
+ cdb_free(cdbfr); /* we own this memory now */
+
+ /*
+ * We cache the most recent msglist in order to do security checks later
+ */
+ if (CC->client_socket > 0) {
+ if (CC->cached_msglist != NULL) {
+ free(CC->cached_msglist);
+ }
+
+ CC->cached_msglist = msglist;
+ CC->cached_num_msgs = num_msgs;
+ }
/*
* Now begin the traversal.
++num_processed;
}
}
- cdb_free(cdbfr); /* Clean up */
if (need_to_free_re) regfree(&re);
+ if (CC->client_socket <= 0) free(msglist);
return num_processed;
}
}
}
-#ifdef MESSAGE_IN_ROOM
-/*
- * Check if a message is in the current room.
- * This is used by CtdlFetchMessage to prevent random picking
- * of messages from users private rooms
- *
- * The message list should probably be cached against the CC->room
- */
-int CtdlMessageInRoom(long msgnum)
-{
- visit vbuf;
- struct cdbdata *cdbfr;
-
- /* Learn about the user and room in question */
- CtdlGetUser(&CC->user, CC->curr_user);
- CtdlGetRelationship(&vbuf, &CC->user, &CC->room);
-
- /* Load the message list */
- cdbfr = cdb_fetch(CDB_MSGLISTS, &CC->room.QRnumber, sizeof(long));
- if (cdbfr != NULL) {
- long *msglist = NULL;
- int num_msgs = 0;
- int i;
- int r = 0;
-
- msglist = (long *) cdbfr->ptr;
- num_msgs = cdbfr->len / sizeof(long);
-
- /* search for message msgnum */
- for (i=0; i<num_msgs; i++) {
- if (msglist[i] == msgnum) {
- r = 1;
- break;
- }
- }
-
- cdb_free(cdbfr);
- return r;
- } else {
- return 0;
- }
-}
-#endif
/*
* Load a message from disk into memory.
cit_uint8_t field_header;
syslog(LOG_DEBUG, "CtdlFetchMessage(%ld, %d)\n", msgnum, with_body);
-
-#ifdef MESSAGE_IN_ROOM
- if (!CtdlMessageInRoom(msgnum)) {
- syslog(LOG_DEBUG, "Message %ld not in current room\n", msgnum);
- return NULL;
- }
-#endif
-
dmsgtext = cdb_fetch(CDB_MSGMAIN, &msgnum, sizeof(long));
if (dmsgtext == NULL) {
return NULL;
}
+/*
+ * Determine whether the specified message exists in the cached_msglist
+ * (This is a security check)
+ */
+int check_cached_msglist(long msgnum) {
+
+ /* cases in which we skip the check */
+ if (!CC) return om_ok; /* not a session */
+ if (CC->client_socket <= 0) return om_ok; /* not a client session */
+ if (CC->cached_msglist == NULL) return om_access_denied; /* no msglist fetched */
+ if (CC->cached_num_msgs == 0) return om_access_denied; /* nothing to check */
+
+
+ /* FIXME FIXME SLOW SEARCH DO NOT LET THIS GO INTO PRODUCTION */
+ int i;
+ for (i=0; i < CC->cached_num_msgs ; ++i) {
+ if (CC->cached_msglist[i] == msgnum) return om_ok;
+ }
+
+ return om_access_denied;
+}
+
+
/*
* Determine whether the currently logged in session has permission to read
* messages in the current room.
return(r);
}
-#ifdef MESSAGE_IN_ROOM
- if (!CtdlMessageInRoom(msg_num)) {
- syslog(LOG_DEBUG, "Message %ld not in current room\n", msg_num);
- if (do_proto) cprintf("%d Can't locate msg %ld in room\n",
- ERROR + MESSAGE_NOT_FOUND, msg_num);
- return(om_no_such_msg);
+ r = check_cached_msglist(msg_num);
+ if (r == om_ok) {
+ syslog(LOG_DEBUG, "\033[32m PASS \033[0m\n");
}
-#endif
+ else {
+ syslog(LOG_DEBUG, "\033[31m FAIL \033[0m\n");
+ }
+ /* FIXME after testing, this is where we deny access */
/*
* Fetch the message from disk. If we're in HEADERS_FAST mode,