Project

General

Profile

Download (6.98 KB) Statistics
| Branch: | Tag: | Revision:
55a68712 Marc Dequenes
#!/usr/bin/ruby -Ku

# http://www.ruby-doc.org/stdlib/libdoc/net/imap/rdoc/index.html
# http://tmail.rubyforge.org/reference/index.html
# http://tools.ietf.org/html/rfc3156

$: << "./lib"

require 'net/imap'
require 'tmail'
2891e0c2 Marc Dequenes
require 'tmail_extra'
55a68712 Marc Dequenes
#require 'socket'
#require 'fileutils'
#require 'tempfile'
require 'gpgme'
require 'active_ldap'
require 'shellwords'
require 'cyborghood/base'

3f7a1eee Marc Dequenes
class LdapPerson < ActiveLdap::Base
55a68712 Marc Dequenes
ldap_mapping :dn_attribute => 'uid', :prefix => '', :classes => ['person', 'extInetOrgPerson']
end

591ec1a2 Marc Dequenes
class Person < Delegator
attr_reader :ldap

def self.find_by_fingerprint(fingerprint)
list = LdapPerson.find(:all, :attribute => 'keyFingerPrint', :value => fingerprint)
case list.size
when 0
nil
when 1
person = allocate
person.instance_variable_set("@ldap", list.first)
person
else
logger.warn "Multiple users match in database, so i guess there is a mistake. It is safer to skip..."
nil
end
end

def __getobj__
@ldap
end
end

3f7a1eee Marc Dequenes
class LdapDnsDomain < ActiveLdap::Base
55a68712 Marc Dequenes
ldap_mapping :dn_attribute => 'cn', :prefix => '', :classes => ['genericDomain']

def managers
list = self.manager
return [] if list.nil?
return list.collect{|dn| dn.to_s } if list.is_a? Array
return [list.to_s]
end
end

3f7a1eee Marc Dequenes
class DnsDomain < Delegator
591ec1a2 Marc Dequenes
attr_reader :ldap, :name
3f7a1eee Marc Dequenes
def initialize(name)
591ec1a2 Marc Dequenes
@name = name
raise "invalid zone name" unless self.is_valid?
3f7a1eee Marc Dequenes
# may not exist (if creating a new one)
begin
@ldap = LdapDnsDomain.find(name)
rescue
@ldap = nil
end
end

def self.is_valid?(name)
name =~ /^[a-z0-9.-]+\.[a-z]{2,4}$/
end

591ec1a2 Marc Dequenes
def is_valid?
self.class.is_valid?(@name)
3f7a1eee Marc Dequenes
end

591ec1a2 Marc Dequenes
def hosted?
3f7a1eee Marc Dequenes
not @ldap.nil?
end

591ec1a2 Marc Dequenes
def managed_by?(user)
@ldap.managers.include? user.ldap.dn
end

3f7a1eee Marc Dequenes
def __getobj__
@ldap
end
591ec1a2 Marc Dequenes
def self.find_by_manager(user)
list = LdapDnsDomain.find(:all, :attribute => 'manager', :value => user.ldap.dn)
list.collect do |l_dom|
domain = allocate
domain.instance_variable_set("@ldap", l_dom)
end
end
3f7a1eee Marc Dequenes
end

55a68712 Marc Dequenes
#Socket.gethostname

#
# TODO:
# - should be able to handle encrypted messages for user to send sensitive data (postman would need a GPG key too)
#

class CommandParser
df41472b Marc Dequenes
def self.run(user, txt, refs)
55a68712 Marc Dequenes
txt.each_line do |line|
line.chomp!
sline = line.strip
# skip empty lines and comments
next if sline == "" or sline[0, 1] == "#"
# stop processing when detecting message signature
break if line == "-- "

3f7a1eee Marc Dequenes
logger.info "Executing command: #{sline}"
begin
execute_cmd(user, sline)
rescue
logger.info "Command failed: " + $!
end
55a68712 Marc Dequenes
end
end

private

def self.execute_cmd(user, cmdstr)
cmdline = Shellwords.shellwords(cmdstr)
subsys = cmdline.shift

ok = true
case subsys.upcase
when "DNS"
case cmdline.shift.upcase
when "INFO"
591ec1a2 Marc Dequenes
if cmdline.empty?
list = DnsDomain.find_by_manager(user)
logger.info "User is manager of the following zones: " + list.collect{|z| z.cn }.sort.join(", ")
else
ok = false
end
55a68712 Marc Dequenes
when "GET"
case cmdline.shift.upcase
when "ZONE"
zone = cmdline.shift.downcase
591ec1a2 Marc Dequenes
dom = DnsDomain.new(zone)
logger.info "User requesting zone content for '#{zone}'"
if dom.hosted?
if dom.managed_by? user
logger.info "User is manager of the zone"
else
logger.info "User is not allowed to manage the zone"
end
else
logger.info "Zone not hosted"
end
else
ok = false
end
55a68712 Marc Dequenes
when "SET"
else
ok = false
end
else
ok = false
end

if not ok
3f7a1eee Marc Dequenes
logger.info "Command not recognized: #{cmdstr}"
55a68712 Marc Dequenes
end
end
end

module CyborgHood
# not yet ready to be a real Cyborg
class Postman #< Cyborg
def initialize
# load config
Config.load(self.human_name.downcase)
@config = Config.instance

0af9cada Marc Dequenes
ldap_config = @config.ldap
ldap_config.logger = logger
ActiveLdap::Base.establish_connection(ldap_config.marshal_dump)

55a68712 Marc Dequenes
# setup logs
unless @config.log.nil?
logger.output_level(@config.log.console_level) unless @config.log.console_level.nil?
logger.log_to_file(@config.log.file) unless @config.log.file.nil?
end

logger.info "Bot '#{self.human_name}' loaded"
end

def run
# using SSL because TLS does not work in the NET::IMAP library
#imap = Net::IMAP.new('imap.duckcorp.org', 993, true, "/etc/ssl/certs/duckcorp.crt", true)
imap = Net::IMAP.new('localhost')
logger.debug "Connected to IMAP server"
2891e0c2 Marc Dequenes
logger.debug "IMAP Capabilities: " + imap.capability.join(", ")
55a68712 Marc Dequenes
imap.authenticate('LOGIN', @config.imap.login, @config.imap.passwd)
logger.debug "Logged into IMAP account"
#p imap.getquotaroot("INBOX")
imap.select('INBOX')
imap.search(["ALL"], "UTF-8").each do |message_id|
msg = imap.fetch(message_id, "RFC822")[0].attr["RFC822"]
# unquote headers and transform into TMail object
mail = TMail::Mail.parse(TMail::Unquoter.unquote_and_convert_to(msg, "UTF-8"))

591ec1a2 Marc Dequenes
logger.set_prefix()
55a68712 Marc Dequenes
logger.debug "######################################"
591ec1a2 Marc Dequenes
logger.set_prefix("[#{mail.message_id}] ")
55a68712 Marc Dequenes
logger.info "#{mail.from_addrs} -> #{mail.to_addrs}: #{mail.subject}"
# ignore mails not signed
591ec1a2 Marc Dequenes
unless mail.is_pgp_signed?
logger.info "Mail not signed or not RFC3156 compliant"
55a68712 Marc Dequenes
next
591ec1a2 Marc Dequenes
end
55a68712 Marc Dequenes
logger.debug "Proper signed content detected"
591ec1a2 Marc Dequenes
sig_check = mail.verify_pgp_signature()
2891e0c2 Marc Dequenes
if sig_check.status == 0
logger.info "Mail content was properly signed by key #{sig_check.fingerprint}"
591ec1a2 Marc Dequenes
user = Person.find_by_fingerprint(sig_check.fingerprint)
if user.nil?
logger.info "Mail is from an unknown person"
else
logger.info "Mail is from user #{user.uid} (#{user.cn})"
df41472b Marc Dequenes
signed_content = mail.pgp_signed_part()
591ec1a2 Marc Dequenes
if signed_content.multipart?
if signed_content.parts[0].content_type == "text/plain"
command_txt = signed_content.parts[0].body
command_refs = signed_content.parts.collect{|p| p.dup }
end
else
command_txt = signed_content.body if signed_content.content_type == "text/plain"
command_refs = []
end

if command_txt
CommandParser.run(user, command_txt, command_refs)
else
logger.info "Mail does not contain a proper MIME part for commands"
end
end
2891e0c2 Marc Dequenes
else
logger.info "Mail content tampered or badly signed: " + sig_check.to_s
55a68712 Marc Dequenes
end
end
imap.logout
end

def ask_to_stop
end
end
end

bot = CyborgHood::Postman.new

trap('INT') do
bot.ask_to_stop
end
trap('TERM') do
bot.ask_to_stop
end

bot.run