Note further package dependencies required for build
[tpg/opendispense2.git] / src / server / server.c
1 /*
2  * OpenDispense 2 
3  * UCC (University [of WA] Computer Club) Electronic Accounting System
4  *
5  * server.c - Client Server Code
6  *
7  * This file is licenced under the 3-clause BSD Licence. See the file
8  * COPYING for full details.
9  */
10 #include <stdio.h>
11 #include <stdlib.h>
12 #include "common.h"
13 #include <sys/socket.h>
14 #include <netinet/in.h>
15 #include <arpa/inet.h>
16 #include <unistd.h>
17 #include <fcntl.h>      // O_*
18 #include <string.h>
19 #include <limits.h>
20 #include <stdarg.h>
21 #include <signal.h>     // Signal handling
22 #include <ident.h>      // AUTHIDENT
23 #include <time.h>       // time(2)
24 #include <ctype.h>
25
26 #define DEBUG_TRACE_CLIENT      0
27 #define HACK_NO_REFUNDS 1
28
29 #define PIDFILE "/var/run/dispsrv.pid"
30
31 // Statistics
32 #define MAX_CONNECTION_QUEUE    5
33 #define INPUT_BUFFER_SIZE       256
34 #define CLIENT_TIMEOUT  10      // Seconds
35
36 #define HASH_TYPE       SHA1
37 #define HASH_LENGTH     20
38
39 #define MSG_STR_TOO_LONG        "499 Command too long (limit "EXPSTR(INPUT_BUFFER_SIZE)")\n"
40
41 #define IDENT_TRUSTED_NETWORK 0x825F0D00
42 #define IDENT_TRUSTED_NETMASK 0xFFFFFFC0
43
44 // === TYPES ===
45 typedef struct sClient
46 {
47          int    Socket; // Client socket ID
48          int    ID;     // Client ID
49          
50          int    bTrustedHost;
51          int    bCanAutoAuth;   // Is the connection from a trusted host/port
52         
53         char    *Username;
54         char    Salt[9];
55         
56          int    UID;
57          int    EffectiveUID;
58          int    bIsAuthed;
59 }       tClient;
60
61 // === PROTOTYPES ===
62 void    Server_Start(void);
63 void    Server_Cleanup(void);
64 void    Server_HandleClient(int Socket, int bTrustedHost, int bRootPort);
65 void    Server_ParseClientCommand(tClient *Client, char *CommandString);
66 // --- Commands ---
67 void    Server_Cmd_USER(tClient *Client, char *Args);
68 void    Server_Cmd_PASS(tClient *Client, char *Args);
69 void    Server_Cmd_AUTOAUTH(tClient *Client, char *Args);
70 void    Server_Cmd_AUTHIDENT(tClient *Client, char *Args);
71 void    Server_Cmd_SETEUSER(tClient *Client, char *Args);
72 void    Server_Cmd_ENUMITEMS(tClient *Client, char *Args);
73 void    Server_Cmd_ITEMINFO(tClient *Client, char *Args);
74 void    Server_Cmd_DISPENSE(tClient *Client, char *Args);
75 void    Server_Cmd_REFUND(tClient *Client, char *Args);
76 void    Server_Cmd_GIVE(tClient *Client, char *Args);
77 void    Server_Cmd_DONATE(tClient *Client, char *Args);
78 void    Server_Cmd_ADD(tClient *Client, char *Args);
79 void    Server_Cmd_SET(tClient *Client, char *Args);
80 void    Server_Cmd_ENUMUSERS(tClient *Client, char *Args);
81 void    Server_Cmd_USERINFO(tClient *Client, char *Args);
82 void    _SendUserInfo(tClient *Client, int UserID);
83 void    Server_Cmd_USERADD(tClient *Client, char *Args);
84 void    Server_Cmd_USERFLAGS(tClient *Client, char *Args);
85 void    Server_Cmd_UPDATEITEM(tClient *Client, char *Args);
86 void    Server_Cmd_PINCHECK(tClient *Client, char *Args);
87 void    Server_Cmd_PINSET(tClient *Client, char *Args);
88 // --- Helpers ---
89 void    Debug(tClient *Client, const char *Format, ...);
90  int    sendf(int Socket, const char *Format, ...);
91  int    Server_int_ParseArgs(int bUseLongArg, char *ArgStr, ...);
92  int    Server_int_ParseFlags(tClient *Client, const char *Str, int *Mask, int *Value);
93
94 // === CONSTANTS ===
95 // - Commands
96 const struct sClientCommand {
97         const char      *Name;
98         void    (*Function)(tClient *Client, char *Arguments);
99 }       gaServer_Commands[] = {
100         {"USER", Server_Cmd_USER},
101         {"PASS", Server_Cmd_PASS},
102         {"AUTOAUTH", Server_Cmd_AUTOAUTH},
103         {"AUTHIDENT", Server_Cmd_AUTHIDENT},
104         {"SETEUSER", Server_Cmd_SETEUSER},
105         {"ENUM_ITEMS", Server_Cmd_ENUMITEMS},
106         {"ITEM_INFO", Server_Cmd_ITEMINFO},
107         {"DISPENSE", Server_Cmd_DISPENSE},
108         {"REFUND", Server_Cmd_REFUND},
109         {"GIVE", Server_Cmd_GIVE},
110         {"DONATE", Server_Cmd_DONATE},
111         {"ADD", Server_Cmd_ADD},
112         {"SET", Server_Cmd_SET},
113         {"ENUM_USERS", Server_Cmd_ENUMUSERS},
114         {"USER_INFO", Server_Cmd_USERINFO},
115         {"USER_ADD", Server_Cmd_USERADD},
116         {"USER_FLAGS", Server_Cmd_USERFLAGS},
117         {"UPDATE_ITEM", Server_Cmd_UPDATEITEM},
118         {"PIN_CHECK", Server_Cmd_PINCHECK},
119         {"PIN_SET", Server_Cmd_PINSET}
120 };
121 #define NUM_COMMANDS    ((int)(sizeof(gaServer_Commands)/sizeof(gaServer_Commands[0])))
122
123 // === GLOBALS ===
124 // - Configuration
125  int    giServer_Port = 11020;
126  int    gbServer_RunInBackground = 0;
127 char    *gsServer_LogFile = "/var/log/dispsrv.log";
128 char    *gsServer_ErrorLog = "/var/log/dispsrv.err";
129  int    giServer_NumTrustedHosts;
130 struct in_addr  *gaServer_TrustedHosts;
131 // - State variables
132  int    giServer_Socket;        // Server socket
133  int    giServer_NextClientID = 1;      // Debug client ID
134  
135
136 // === CODE ===
137 /**
138  * \brief Open listenting socket and serve connections
139  */
140 void Server_Start(void)
141 {
142          int    client_socket;
143         struct sockaddr_in      server_addr, client_addr;
144
145         // Parse trusted hosts list
146         giServer_NumTrustedHosts = Config_GetValueCount("trusted_host");
147         gaServer_TrustedHosts = malloc(giServer_NumTrustedHosts * sizeof(*gaServer_TrustedHosts));
148         for( int i = 0; i < giServer_NumTrustedHosts; i ++ )
149         {
150                 const char      *addr = Config_GetValue("trusted_host", i);
151                 
152                 if( inet_aton(addr, &gaServer_TrustedHosts[i]) == 0 ) {
153                         fprintf(stderr, "Invalid IP address '%s'\n", addr);
154                         continue ;
155                 }
156         }
157
158         // Ignore SIGPIPE (stops crashes when the client exits early)
159         signal(SIGPIPE, SIG_IGN);
160
161         // Create Server
162         giServer_Socket = socket(PF_INET, SOCK_STREAM, IPPROTO_TCP);
163         if( giServer_Socket < 0 ) {
164                 fprintf(stderr, "ERROR: Unable to create server socket\n");
165                 return ;
166         }
167         
168         // Make listen address
169         memset(&server_addr, 0, sizeof(server_addr));
170         server_addr.sin_family = AF_INET;       // Internet Socket
171         server_addr.sin_addr.s_addr = htonl(INADDR_ANY);        // Listen on all interfaces
172         server_addr.sin_port = htons(giServer_Port);    // Port
173
174         // Bind
175         if( bind(giServer_Socket, (struct sockaddr *) &server_addr, sizeof(server_addr)) < 0 ) {
176                 fprintf(stderr, "ERROR: Unable to bind to 0.0.0.0:%i\n", giServer_Port);
177                 perror("Binding");
178                 close(giServer_Socket);
179                 return ;
180         }
181
182         // Fork into background
183         if( gbServer_RunInBackground )
184         {
185                 int pid = fork();
186                 if( pid == -1 ) {
187                         fprintf(stderr, "ERROR: Unable to fork\n");
188                         perror("fork background");
189                         exit(-1);
190                 }
191                 if( pid != 0 ) {
192                         // Parent, quit
193                         Debug_Notice("Forked child server as PID %i\n", pid);
194                         exit(0);
195                 }
196                 // In child
197                 // - Sort out stdin/stdout
198                 #if 0
199                 dup2( open("/dev/null", O_RDONLY, 0644), STDIN_FILENO );
200                 dup2( open(gsServer_LogFile, O_CREAT|O_APPEND, 0644), STDOUT_FILENO );
201                 dup2( open(gsServer_ErrorLog, O_CREAT|O_APPEND, 0644), STDERR_FILENO );
202                 #else
203                 freopen("/dev/null", "r", stdin);
204                 freopen(gsServer_LogFile, "a", stdout);
205                 freopen(gsServer_ErrorLog, "a", stderr);
206                 fprintf(stdout, "OpenDispense 2 Server Started at %lld\n", (long long)time(NULL));
207                 fprintf(stderr, "OpenDispense 2 Server Started at %lld\n", (long long)time(NULL));
208                 #endif
209         }
210         atexit(Server_Cleanup);
211
212         // Start the helper thread
213         StartPeriodicThread();
214         
215         // Listen
216         if( listen(giServer_Socket, MAX_CONNECTION_QUEUE) < 0 ) {
217                 fprintf(stderr, "ERROR: Unable to listen to socket\n");
218                 perror("Listen");
219                 return ;
220         }
221         
222         Debug_Notice("Listening on 0.0.0.0:%i", giServer_Port);
223         
224         // write pidfile
225         {
226                 FILE *fp = fopen(PIDFILE, "w");
227                 if( fp ) {
228                         fprintf(fp, "%i", getpid());
229                         fclose(fp);
230                 }
231         }
232
233         for(;;)
234         {
235                 uint    len = sizeof(client_addr);
236                  int    bTrusted = 0;
237                  int    bRootPort = 0;
238                 
239                 // Accept a connection
240                 client_socket = accept(giServer_Socket, (struct sockaddr *) &client_addr, &len);
241                 if(client_socket < 0) {
242                         fprintf(stderr, "ERROR: Unable to accept client connection\n");
243                         return ;
244                 }
245                 
246                 // Set a timeout on the user conneciton
247                 {
248                         struct timeval tv;
249                         tv.tv_sec = CLIENT_TIMEOUT;
250                         tv.tv_usec = 0;
251                         if( setsockopt(client_socket, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv)) )
252                         {
253                                 perror("setsockopt");
254                                 return ;
255                         }
256                 }
257                 
258                 // Debug: Print the connection string
259                 if(giDebugLevel >= 2) {
260                         char    ipstr[INET_ADDRSTRLEN];
261                         inet_ntop(AF_INET, &client_addr.sin_addr, ipstr, INET_ADDRSTRLEN);
262                         Debug_Debug("Client connection from %s:%i",
263                                 ipstr, ntohs(client_addr.sin_port));
264                 }
265                 
266                 // Doesn't matter what, localhost is trusted
267                 if( ntohl( client_addr.sin_addr.s_addr ) == 0x7F000001 )
268                         bTrusted = 1;
269         
270                 // Check if the host is on the trusted list     
271                 for( int i = 0; i < giServer_NumTrustedHosts; i ++ )
272                 {
273                         if( memcmp(&client_addr.sin_addr, &gaServer_TrustedHosts[i], sizeof(struct in_addr)) == 0 )
274                         {
275                                 bTrusted = 1;
276                                 break;
277                         }
278                 }
279
280                 // Root port (can AUTOAUTH if also a trusted machine
281                 if( ntohs(client_addr.sin_port) < 1024 )
282                         bRootPort = 1;
283                 
284                 #if 0
285                 {
286                         // TODO: Make this runtime configurable
287                         switch( ntohl( client_addr.sin_addr.s_addr ) )
288                         {
289                         case 0x7F000001:        // 127.0.0.1    localhost
290                 //      case 0x825F0D00:        // 130.95.13.0
291                         case 0x825F0D04:        // 130.95.13.4  merlo
292                 //      case 0x825F0D05:        // 130.95.13.5  heathred (MR)
293                         case 0x825F0D07:        // 130.95.13.7  motsugo
294                         case 0x825F0D11:        // 130.95.13.17 mermaid
295                         case 0x825F0D12:        // 130.95.13.18 mussel
296                         case 0x825F0D17:        // 130.95.13.23 martello
297                         case 0x825F0D2A:        // 130.95.13.42 meersau
298                 //      case 0x825F0D42:        // 130.95.13.66 heathred (Clubroom)
299                                 bTrusted = 1;
300                                 break;
301                         default:
302                                 break;
303                         }
304                 }
305                 #endif
306                 
307                 // TODO: Multithread this?
308                 Server_HandleClient(client_socket, bTrusted, bRootPort);
309                 
310                 close(client_socket);
311         }
312 }
313
314 void Server_Cleanup(void)
315 {
316         Debug_Debug("Close(%i)", giServer_Socket);
317         close(giServer_Socket);
318         unlink(PIDFILE);
319 }
320
321 /**
322  * \brief Reads from a client socket and parses the command strings
323  * \param Socket        Client socket number/handle
324  * \param bTrusted      Is the client trusted?
325  */
326 void Server_HandleClient(int Socket, int bTrusted, int bRootPort)
327 {
328         char    inbuf[INPUT_BUFFER_SIZE];
329         char    *buf = inbuf;
330          int    remspace = INPUT_BUFFER_SIZE-1;
331          int    bytes = -1;
332         tClient clientInfo;
333         
334         memset(&clientInfo, 0, sizeof(clientInfo));
335         
336         // Initialise Client info
337         clientInfo.Socket = Socket;
338         clientInfo.ID = giServer_NextClientID ++;
339         clientInfo.bTrustedHost = bTrusted;
340         clientInfo.bCanAutoAuth = bTrusted && bRootPort;
341         clientInfo.EffectiveUID = -1;
342         
343         // Read from client
344         /*
345          * Notes:
346          * - The `buf` and `remspace` variables allow a line to span several
347          *   calls to recv(), if a line is not completed in one recv() call
348          *   it is saved to the beginning of `inbuf` and `buf` is updated to
349          *   the end of it.
350          */
351         // TODO: Use select() instead (to give a timeout)
352         while( (bytes = recv(Socket, buf, remspace, 0)) > 0 )
353         {
354                 char    *eol, *start;
355                 buf[bytes] = '\0';      // Allow us to use stdlib string functions on it
356                 
357                 // Split by lines
358                 start = inbuf;
359                 while( (eol = strchr(start, '\n')) )
360                 {
361                         *eol = '\0';
362                         
363                         Server_ParseClientCommand(&clientInfo, start);
364                         
365                         start = eol + 1;
366                 }
367                 
368                 // Check if there was an incomplete line
369                 if( *start != '\0' ) {
370                          int    tailBytes = bytes - (start-buf);
371                         // Roll back in buffer
372                         memcpy(inbuf, start, tailBytes);
373                         remspace -= tailBytes;
374                         if(remspace == 0) {
375                                 send(Socket, MSG_STR_TOO_LONG, sizeof(MSG_STR_TOO_LONG), 0);
376                                 buf = inbuf;
377                                 remspace = INPUT_BUFFER_SIZE - 1;
378                         }
379                 }
380                 else {
381                         buf = inbuf;
382                         remspace = INPUT_BUFFER_SIZE - 1;
383                 }
384         }
385         
386         // Check for errors
387         if( bytes < 0 ) {
388                 fprintf(stderr, "ERROR: Unable to recieve from client on socket %i\n", Socket);
389                 return ;
390         }
391         
392         if(giDebugLevel >= 2) {
393                 printf("Client %i: Disconnected\n", clientInfo.ID);
394         }
395 }
396
397 /**
398  * \brief Parses a client command and calls the required helper function
399  * \param Client        Pointer to client state structure
400  * \param CommandString Command from client (single line of the command)
401  * \return Heap String to return to the client
402  */
403 void Server_ParseClientCommand(tClient *Client, char *CommandString)
404 {
405         char    *command, *args;
406          int    i;
407         
408         if( giDebugLevel >= 2 )
409                 Debug(Client, "Server_ParseClientCommand: (CommandString = '%s')", CommandString);
410         
411         if( Server_int_ParseArgs(1, CommandString, &command, &args, NULL) )
412         {
413                 if( command == NULL )   return ;
414                 // Is this an error? (just ignore for now)
415         }
416         
417         
418         // Find command
419         for( i = 0; i < NUM_COMMANDS; i++ )
420         {
421                 if(strcmp(command, gaServer_Commands[i].Name) == 0) {
422                         if( giDebugLevel >= 2 )
423                                 Debug(Client, "CMD %s - \"%s\"", command, args);
424                         gaServer_Commands[i].Function(Client, args);
425                         return ;
426                 }
427         }
428         
429         sendf(Client->Socket, "400 Unknown Command\n");
430 }
431
432 // ---
433 // Commands
434 // ---
435 /**
436  * \brief Set client username
437  * 
438  * Usage: USER <username>
439  */
440 void Server_Cmd_USER(tClient *Client, char *Args)
441 {
442         char    *username;
443         
444         if( Server_int_ParseArgs(0, Args, &username, NULL) )
445         {
446                 sendf(Client->Socket, "407 USER takes 1 argument\n");
447                 return ;
448         }
449         
450         // Debug!
451         if( giDebugLevel )
452                 Debug(Client, "Authenticating as '%s'", username);
453         
454         // Save username
455         if(Client->Username)
456                 free(Client->Username);
457         Client->Username = strdup(username);
458         
459         #if USE_SALT
460         // Create a salt (that changes if the username is changed)
461         // Yes, I know, I'm a little paranoid, but who isn't?
462         Client->Salt[0] = 0x21 + (rand()&0x3F);
463         Client->Salt[1] = 0x21 + (rand()&0x3F);
464         Client->Salt[2] = 0x21 + (rand()&0x3F);
465         Client->Salt[3] = 0x21 + (rand()&0x3F);
466         Client->Salt[4] = 0x21 + (rand()&0x3F);
467         Client->Salt[5] = 0x21 + (rand()&0x3F);
468         Client->Salt[6] = 0x21 + (rand()&0x3F);
469         Client->Salt[7] = 0x21 + (rand()&0x3F);
470         
471         // TODO: Also send hash type to use, (SHA1 or crypt according to [DAA])
472         sendf(Client->Socket, "100 SALT %s\n", Client->Salt);
473         #else
474         sendf(Client->Socket, "100 User Set\n");
475         #endif
476 }
477
478 /**
479  * \brief Authenticate as a user
480  * 
481  * Usage: PASS <hash>
482  */
483 void Server_Cmd_PASS(tClient *Client, char *Args)
484 {
485         char    *passhash;
486          int    flags;
487
488         if( Server_int_ParseArgs(0, Args, &passhash, NULL) )
489         {
490                 sendf(Client->Socket, "407 PASS takes 1 argument\n");
491                 return ;
492         }
493         
494         // Pass on to cokebank
495         Client->UID = Bank_GetUserAuth(Client->Salt, Client->Username, passhash);
496
497         if( Client->UID == -1 ) {
498                 sendf(Client->Socket, "401 Auth Failure\n");
499                 return ;
500         }
501
502         flags = Bank_GetFlags(Client->UID);
503         if( flags & USER_FLAG_DISABLED ) {
504                 Client->UID = -1;
505                 sendf(Client->Socket, "403 Account Disabled\n");
506                 return ;
507         }
508         if( flags & USER_FLAG_INTERNAL ) {
509                 Client->UID = -1;
510                 sendf(Client->Socket, "403 Internal account\n");
511                 return ;
512         }
513         
514         Client->bIsAuthed = 1;
515         sendf(Client->Socket, "200 Auth OK\n");
516 }
517
518 /**
519  * \brief Authenticate as a user without a password
520  * 
521  * Usage: AUTOAUTH <user>
522  */
523 void Server_Cmd_AUTOAUTH(tClient *Client, char *Args)
524 {
525         char    *username;
526          int    userflags;
527         
528         if( Server_int_ParseArgs(0, Args, &username, NULL) )
529         {
530                 sendf(Client->Socket, "407 AUTOAUTH takes 1 argument\n");
531                 return ;
532         }
533         
534         // Check if trusted
535         if( !Client->bCanAutoAuth ) {
536                 if(giDebugLevel)
537                         Debug(Client, "Untrusted client attempting to AUTOAUTH");
538                 sendf(Client->Socket, "401 Untrusted\n");
539                 return ;
540         }
541         
542         // Get UID
543         Client->UID = Bank_GetAcctByName( username, 0 );        
544         if( Client->UID < 0 ) {
545                 if(giDebugLevel)
546                         Debug(Client, "Unknown user '%s'", username);
547                 sendf(Client->Socket, "403 Auth Failure\n");
548                 return ;
549         }
550         
551         userflags = Bank_GetFlags(Client->UID);
552         // You can't be an internal account
553         if( userflags & USER_FLAG_INTERNAL ) {
554                 if(giDebugLevel)
555                         Debug(Client, "Autoauth as '%s', not allowed", username);
556                 Client->UID = -1;
557                 sendf(Client->Socket, "403 Account is internal\n");
558                 return ;
559         }
560
561         // Disabled accounts
562         if( userflags & USER_FLAG_DISABLED ) {
563                 Client->UID = -1;
564                 sendf(Client->Socket, "403 Account disabled\n");
565                 return ;
566         }
567
568         // Save username
569         if(Client->Username)
570                 free(Client->Username);
571         Client->Username = strdup(username);
572
573         Client->bIsAuthed = 1;
574         
575         if(giDebugLevel)
576                 Debug(Client, "Auto authenticated as '%s' (%i)", username, Client->UID);
577         
578         sendf(Client->Socket, "200 Auth OK\n");
579 }
580
581 /**
582  * \brief Authenticate as a user using the IDENT protocol
583  *
584  * Usage: AUTHIDENT
585  */
586 void Server_Cmd_AUTHIDENT(tClient *Client, char *Args)
587 {
588         char    *username;
589          int    userflags;
590         const int ident_timeout = 5;
591
592         if( Args != NULL && strlen(Args) ) {
593                 sendf(Client->Socket, "407 AUTHIDENT takes no arguments\n");
594                 return ;
595         }
596
597         // Check if trusted
598         if( !Client->bTrustedHost ) {
599                 if(giDebugLevel)
600                         Debug(Client, "Untrusted client attempting to AUTHIDENT");
601                 sendf(Client->Socket, "401 Untrusted\n");
602                 return ;
603         }
604
605         // Get username via IDENT
606         username = ident_id(Client->Socket, ident_timeout);
607         if( !username ) {
608                 perror("AUTHIDENT - IDENT timed out");
609                 sendf(Client->Socket, "403 Authentication failure: IDENT auth timed out\n");
610                 return ;
611         }
612
613         // Get UID
614         Client->UID = Bank_GetAcctByName( username, 0 );
615         if( Client->UID < 0 ) {
616                 if(giDebugLevel)
617                         Debug(Client, "Unknown user '%s'", username);
618                 sendf(Client->Socket, "403 Authentication failure: unknown account\n");
619                 free(username);
620                 return ;
621         }
622
623         userflags = Bank_GetFlags(Client->UID);
624         // You can't be an internal account
625         if( userflags & USER_FLAG_INTERNAL ) {
626                 if(giDebugLevel)
627                         Debug(Client, "IDENT auth as '%s', not allowed", username);
628                 Client->UID = -1;
629                 sendf(Client->Socket, "403 Authentication failure: that account is internal\n");
630                 free(username);
631                 return ;
632         }
633
634         // Disabled accounts
635         if( userflags & USER_FLAG_DISABLED ) {
636                 Client->UID = -1;
637                 sendf(Client->Socket, "403 Authentication failure: account disabled\n");
638                 free(username);
639                 return ;
640         }
641
642         // Save username
643         if(Client->Username)
644                 free(Client->Username);
645         Client->Username = strdup(username);
646
647         Client->bIsAuthed = 1;
648
649         if(giDebugLevel)
650                 Debug(Client, "IDENT authenticated as '%s' (%i)", username, Client->UID);
651         free(username);
652
653         sendf(Client->Socket, "200 Auth OK\n");
654 }
655
656 /**
657  * \brief Set effective user
658  */
659 void Server_Cmd_SETEUSER(tClient *Client, char *Args)
660 {
661         char    *username;
662          int    eUserFlags, userFlags;
663         
664         if( Server_int_ParseArgs(0, Args, &username, NULL) )
665         {
666                 sendf(Client->Socket, "407 SETEUSER takes 1 argument\n");
667                 return ;
668         }
669         
670         if( !strlen(Args) ) {
671                 sendf(Client->Socket, "407 SETEUSER expects an argument\n");
672                 return ;
673         }
674         
675         // Check authentication
676         if( !Client->bIsAuthed ) {
677                 sendf(Client->Socket, "401 Not Authenticated\n");
678                 return ;
679         }
680
681         // Check user permissions
682         userFlags = Bank_GetFlags(Client->UID);
683         if( !(userFlags & (USER_FLAG_COKE|USER_FLAG_ADMIN)) ) {
684                 sendf(Client->Socket, "403 Not in coke\n");
685                 return ;
686         }
687         
688         // Set id
689         Client->EffectiveUID = Bank_GetAcctByName(username, 0);
690         if( Client->EffectiveUID == -1 ) {
691                 sendf(Client->Socket, "404 User not found\n");
692                 return ;
693         }
694         // You can't be an internal account (unless you're an admin)
695         if( !(userFlags & USER_FLAG_ADMIN) )
696         {
697                 eUserFlags = Bank_GetFlags(Client->EffectiveUID);
698                 if( eUserFlags & USER_FLAG_INTERNAL ) {
699                         Client->EffectiveUID = -1;
700                         sendf(Client->Socket, "404 User not found\n");
701                         return ;
702                 }
703         }
704
705         // Disabled accounts
706         // - If disabled and the actual user is not an admin (and not root)
707         //   return 403
708         if( (eUserFlags & USER_FLAG_DISABLED) && (Client->UID == 0 || !(userFlags & USER_FLAG_ADMIN)) ) {
709                 Client->EffectiveUID = -1;
710                 sendf(Client->Socket, "403 Account disabled\n");
711                 return ;
712         }
713         
714         sendf(Client->Socket, "200 User set\n");
715 }
716
717 /**
718  * \brief Send an item status to the client
719  * \param Client        Who to?
720  * \param Item  Item to send
721  */
722 void Server_int_SendItem(tClient *Client, tItem *Item)
723 {
724         char    *status = "avail";
725         
726         if( Item->Handler->CanDispense )
727         {
728                 switch(Item->Handler->CanDispense(Client->UID, Item->ID))
729                 {
730                 case  0:        status = "avail";       break;
731                 case  1:        status = "sold";        break;
732                 default:
733                 case -1:        status = "error";       break;
734                 }
735         }
736         
737         if( !gbNoCostMode && Item->Price == 0 )
738                 status = "error";
739         // KNOWN HACK: Naming a slot 'dead' disables it
740         if( strcmp(Item->Name, "dead") == 0 )
741                 status = "sold";        // Another status?
742         
743         sendf(Client->Socket,
744                 "202 Item %s:%i %s %i %s\n",
745                 Item->Handler->Name, Item->ID, status, Item->Price, Item->Name
746                 );
747 }
748
749 /**
750  * \brief Enumerate the items that the server knows about
751  */
752 void Server_Cmd_ENUMITEMS(tClient *Client, char *Args)
753 {
754          int    i, count;
755
756         if( Args != NULL && strlen(Args) ) {
757                 sendf(Client->Socket, "407 ENUM_ITEMS takes no arguments\n");
758                 return ;
759         }
760         
761         // Count shown items
762         count = 0;
763         for( i = 0; i < giNumItems; i ++ ) {
764                 if( gaItems[i].bHidden )        continue;
765                 count ++;
766         }
767
768         sendf(Client->Socket, "201 Items %i\n", count);
769
770         for( i = 0; i < giNumItems; i ++ ) {
771                 if( gaItems[i].bHidden )        continue;
772                 Server_int_SendItem( Client, &gaItems[i] );
773         }
774
775         sendf(Client->Socket, "200 List end\n");
776 }
777
778 tItem *_GetItemFromString(char *String)
779 {
780         tHandler        *handler;
781         char    *type = String;
782         char    *colon = strchr(String, ':');
783          int    num, i;
784         
785         if( !colon ) {
786                 return NULL;
787         }
788
789         num = atoi(colon+1);
790         *colon = '\0';
791
792         // Find handler
793         handler = NULL;
794         for( i = 0; i < giNumHandlers; i ++ )
795         {
796                 if( strcmp(gaHandlers[i]->Name, type) == 0) {
797                         handler = gaHandlers[i];
798                         break;
799                 }
800         }
801         if( !handler ) {
802                 return NULL;
803         }
804
805         // Find item
806         for( i = 0; i < giNumItems; i ++ )
807         {
808                 if( gaItems[i].Handler != handler )     continue;
809                 if( gaItems[i].ID != num )      continue;
810                 return &gaItems[i];
811         }
812         return NULL;
813 }
814
815 /**
816  * \brief Fetch information on a specific item
817  *
818  * Usage: ITEMINFO <item ID>
819  */
820 void Server_Cmd_ITEMINFO(tClient *Client, char *Args)
821 {
822         tItem   *item;
823         char    *itemname;
824         
825         if( Server_int_ParseArgs(0, Args, &itemname, NULL) ) {
826                 sendf(Client->Socket, "407 ITEMINFO takes 1 argument\n");
827                 return ;
828         }
829         item = _GetItemFromString(Args);
830         
831         if( !item ) {
832                 sendf(Client->Socket, "406 Bad Item ID\n");
833                 return ;
834         }
835         
836         Server_int_SendItem( Client, item );
837 }
838
839 /**
840  * \brief Dispense an item
841  *
842  * Usage: DISPENSE <Item ID>
843  */
844 void Server_Cmd_DISPENSE(tClient *Client, char *Args)
845 {
846         tItem   *item;
847          int    ret;
848          int    uid;
849         char    *itemname;
850         
851         if( Server_int_ParseArgs(0, Args, &itemname, NULL) ) {
852                 sendf(Client->Socket, "407 DISPENSE takes only 1 argument\n");
853                 return ;
854         }
855          
856         if( !Client->bIsAuthed ) {
857                 sendf(Client->Socket, "401 Not Authenticated\n");
858                 return ;
859         }
860
861         item = _GetItemFromString(itemname);
862         if( !item ) {
863                 sendf(Client->Socket, "406 Bad Item ID\n");
864                 return ;
865         }
866         
867         if( Client->EffectiveUID != -1 ) {
868                 uid = Client->EffectiveUID;
869         }
870         else {
871                 uid = Client->UID;
872         }
873
874 //      if( Bank_GetFlags(Client->UID) & USER_FLAG_DISABLED  ) {
875 //      }
876
877         switch( ret = DispenseItem( Client->UID, uid, item ) )
878         {
879         case 0: sendf(Client->Socket, "200 Dispense OK\n");     return ;
880         case 1: sendf(Client->Socket, "501 Unable to dispense\n");      return ;
881         case 2: sendf(Client->Socket, "402 Poor You\n");        return ;
882         default:
883                 sendf(Client->Socket, "500 Dispense Error (%i)\n", ret);
884                 return ;
885         }
886 }
887
888 /**
889  * \brief Refund an item to a user
890  *
891  * Usage: REFUND <user> <item id> [<price>]
892  */
893 void Server_Cmd_REFUND(tClient *Client, char *Args)
894 {
895         tItem   *item;
896          int    uid, price_override = 0;
897         char    *username, *itemname, *price_str;
898
899         if( Server_int_ParseArgs(0, Args, &username, &itemname, &price_str, NULL) ) {
900                 if( !itemname || price_str ) {
901                         sendf(Client->Socket, "407 REFUND takes 2 or 3 arguments\n");
902                         return ;
903                 }
904         }
905
906         if( !Client->bIsAuthed ) {
907                 sendf(Client->Socket, "401 Not Authenticated\n");
908                 return ;
909         }
910
911         // Check user permissions
912         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
913                 sendf(Client->Socket, "403 Not in coke\n");
914                 return ;
915         }
916
917         uid = Bank_GetAcctByName(username, 0);
918         if( uid == -1 ) {
919                 sendf(Client->Socket, "404 Unknown user\n");
920                 return ;
921         }
922         
923         item = _GetItemFromString(itemname);
924         if( !item ) {
925                 sendf(Client->Socket, "406 Bad Item ID\n");
926                 return ;
927         }
928
929         if( price_str )
930                 price_override = atoi(price_str);
931
932         switch( DispenseRefund( Client->UID, uid, item, price_override ) )
933         {
934         case 0: sendf(Client->Socket, "200 Item Refunded\n");   return ;
935         default:
936                 sendf(Client->Socket, "500 Dispense Error\n");
937                 return;
938         }
939 }
940
941 /**
942  * \brief Transfer money to another account
943  *
944  * Usage: GIVE <dest> <ammount> <reason...>
945  */
946 void Server_Cmd_GIVE(tClient *Client, char *Args)
947 {
948         char    *recipient, *ammount, *reason;
949          int    uid, iAmmount;
950          int    thisUid;
951         
952         // Parse arguments
953         if( Server_int_ParseArgs(1, Args, &recipient, &ammount, &reason, NULL) ) {
954                 sendf(Client->Socket, "407 GIVE takes only 3 arguments\n");
955                 return ;
956         }
957         
958         // Check for authed
959         if( !Client->bIsAuthed ) {
960                 sendf(Client->Socket, "401 Not Authenticated\n");
961                 return ;
962         }
963
964         // Get recipient
965         uid = Bank_GetAcctByName(recipient, 0);
966         if( uid == -1 ) {
967                 sendf(Client->Socket, "404 Invalid target user\n");
968                 return ;
969         }
970         
971         // You can't alter an internal account
972 //      if( Bank_GetFlags(uid) & USER_FLAG_INTERNAL ) {
973 //              sendf(Client->Socket, "404 Invalid target user\n");
974 //              return ;
975 //      }
976
977         // Parse ammount
978         iAmmount = atoi(ammount);
979         if( iAmmount <= 0 ) {
980                 sendf(Client->Socket, "407 Invalid Argument, ammount must be > zero\n");
981                 return ;
982         }
983         
984         if( Client->EffectiveUID != -1 ) {
985                 thisUid = Client->EffectiveUID;
986         }
987         else {
988                 thisUid = Client->UID;
989         }
990
991         // Do give
992         switch( DispenseGive(Client->UID, thisUid, uid, iAmmount, reason) )
993         {
994         case 0:
995                 sendf(Client->Socket, "200 Give OK\n");
996                 return ;
997         case 2:
998                 sendf(Client->Socket, "402 Poor You\n");
999                 return ;
1000         default:
1001                 sendf(Client->Socket, "500 Unknown error\n");
1002                 return ;
1003         }
1004 }
1005
1006 void Server_Cmd_DONATE(tClient *Client, char *Args)
1007 {
1008         char    *ammount, *reason;
1009          int    iAmmount;
1010          int    thisUid;
1011         
1012         // Parse arguments
1013         if( Server_int_ParseArgs(1, Args, &ammount, &reason, NULL) ) {
1014                 sendf(Client->Socket, "407 DONATE takes 2 arguments\n");
1015                 return ;
1016         }
1017         
1018         if( !Client->bIsAuthed ) {
1019                 sendf(Client->Socket, "401 Not Authenticated\n");
1020                 return ;
1021         }
1022
1023         // Parse ammount
1024         iAmmount = atoi(ammount);
1025         if( iAmmount <= 0 ) {
1026                 sendf(Client->Socket, "407 Invalid Argument, ammount must be > zero\n");
1027                 return ;
1028         }
1029         
1030         // Handle effective users
1031         if( Client->EffectiveUID != -1 ) {
1032                 thisUid = Client->EffectiveUID;
1033         }
1034         else {
1035                 thisUid = Client->UID;
1036         }
1037
1038         // Do give
1039         switch( DispenseDonate(Client->UID, thisUid, iAmmount, reason) )
1040         {
1041         case 0:
1042                 sendf(Client->Socket, "200 Give OK\n");
1043                 return ;
1044         case 2:
1045                 sendf(Client->Socket, "402 Poor You\n");
1046                 return ;
1047         default:
1048                 sendf(Client->Socket, "500 Unknown error\n");
1049                 return ;
1050         }
1051 }
1052
1053 void Server_Cmd_ADD(tClient *Client, char *Args)
1054 {
1055         char    *user, *ammount, *reason;
1056          int    uid, iAmmount;
1057         
1058         // Parse arguments
1059         if( Server_int_ParseArgs(1, Args, &user, &ammount, &reason, NULL) ) {
1060                 sendf(Client->Socket, "407 ADD takes 3 arguments\n");
1061                 return ;
1062         }
1063         
1064         if( !Client->bIsAuthed ) {
1065                 sendf(Client->Socket, "401 Not Authenticated\n");
1066                 return ;
1067         }
1068
1069         // Check user permissions
1070         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1071                 sendf(Client->Socket, "403 Not in coke\n");
1072                 return ;
1073         }
1074
1075         #if !ROOT_CAN_ADD
1076         if( strcmp( Client->Username, "root" ) == 0 ) {
1077                 // Allow adding for new users
1078                 if( strcmp(reason, "treasurer: new user") != 0 ) {
1079                         sendf(Client->Socket, "403 Root may not add\n");
1080                         return ;
1081                 }
1082         }
1083         #endif
1084
1085         #if HACK_NO_REFUNDS
1086         if( strstr(reason, "refund") != NULL || strstr(reason, "misdispense") != NULL )
1087         {
1088                 sendf(Client->Socket, "499 Don't use `dispense acct` for refunds, use `dispense refund` (and `dispense -G` to get item IDs)\n");
1089                 return ;
1090         }
1091         #endif
1092
1093         // Get recipient
1094         uid = Bank_GetAcctByName(user, 0);
1095         if( uid == -1 ) {
1096                 sendf(Client->Socket, "404 Invalid user\n");
1097                 return ;
1098         }
1099         
1100         // You can't alter an internal account
1101         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) )
1102         {
1103                 if( Bank_GetFlags(uid) & USER_FLAG_INTERNAL ) {
1104                         sendf(Client->Socket, "403 Admin only\n");
1105                         return ;
1106                 }
1107                 // TODO: Maybe disallow changes to disabled?
1108         }
1109
1110         // Parse ammount
1111         iAmmount = atoi(ammount);
1112         if( iAmmount == 0 && ammount[0] != '0' ) {
1113                 sendf(Client->Socket, "407 Invalid Argument\n");
1114                 return ;
1115         }
1116
1117         // Do give
1118         switch( DispenseAdd(Client->UID, uid, iAmmount, reason) )
1119         {
1120         case 0:
1121                 sendf(Client->Socket, "200 Add OK\n");
1122                 return ;
1123         case 2:
1124                 sendf(Client->Socket, "402 Poor Guy\n");
1125                 return ;
1126         default:
1127                 sendf(Client->Socket, "500 Unknown error\n");
1128                 return ;
1129         }
1130 }
1131
1132 void Server_Cmd_SET(tClient *Client, char *Args)
1133 {
1134         char    *user, *ammount, *reason;
1135          int    uid, iAmmount;
1136         
1137         // Parse arguments
1138         if( Server_int_ParseArgs(1, Args, &user, &ammount, &reason, NULL) ) {
1139                 sendf(Client->Socket, "407 SET takes 3 arguments\n");
1140                 return ;
1141         }
1142         
1143         if( !Client->bIsAuthed ) {
1144                 sendf(Client->Socket, "401 Not Authenticated\n");
1145                 return ;
1146         }
1147
1148         // Check user permissions
1149         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN)  ) {
1150                 sendf(Client->Socket, "403 Not an admin\n");
1151                 return ;
1152         }
1153
1154         // Get recipient
1155         uid = Bank_GetAcctByName(user, 0);
1156         if( uid == -1 ) {
1157                 sendf(Client->Socket, "404 Invalid user\n");
1158                 return ;
1159         }
1160
1161         // Parse ammount
1162         iAmmount = atoi(ammount);
1163         if( iAmmount == 0 && ammount[0] != '0' ) {
1164                 sendf(Client->Socket, "407 Invalid Argument\n");
1165                 return ;
1166         }
1167
1168         int origBalance, rv;
1169         // Do give
1170         switch( rv = DispenseSet(Client->UID, uid, iAmmount, reason, &origBalance) )
1171         {
1172         case 0:
1173                 sendf(Client->Socket, "200 Add OK (%i)\n", origBalance);
1174                 return ;
1175         default:
1176                 sendf(Client->Socket, "500 Unknown error (%i)\n", rv);
1177                 return ;
1178         }
1179 }
1180
1181 void Server_Cmd_ENUMUSERS(tClient *Client, char *Args)
1182 {
1183          int    i, numRet = 0;
1184         tAcctIterator   *it;
1185          int    maxBal = INT_MAX, minBal = INT_MIN;
1186          int    flagMask = 0, flagVal = 0;
1187          int    sort = BANK_ITFLAG_SORT_NAME;
1188         time_t  lastSeenAfter=0, lastSeenBefore=0;
1189         
1190          int    flags;  // Iterator flags
1191          int    balValue;       // Balance value for iterator
1192         time_t  timeValue;      // Time value for iterator
1193         
1194         // Parse arguments
1195         if( Args && strlen(Args) )
1196         {
1197                 char    *space = Args, *type, *val;
1198                 do
1199                 {
1200                         type = space;
1201                         while(*type == ' ')     type ++;
1202                         // Get next space
1203                         space = strchr(space, ' ');
1204                         if(space)       *space = '\0';
1205                         
1206                         // Get type
1207                         val = strchr(type, ':');
1208                         if( val ) {
1209                                 *val = '\0';
1210                                 val ++;
1211                                 
1212                                 // Types
1213                                 // - Minium Balance
1214                                 if( strcmp(type, "min_balance") == 0 ) {
1215                                         minBal = atoi(val);
1216                                 }
1217                                 // - Maximum Balance
1218                                 else if( strcmp(type, "max_balance") == 0 ) {
1219                                         maxBal = atoi(val);
1220                                 }
1221                                 // - Flags
1222                                 else if( strcmp(type, "flags") == 0 ) {
1223                                         if( Server_int_ParseFlags(Client, val, &flagMask, &flagVal) )
1224                                                 return ;
1225                                 }
1226                                 // - Last seen before timestamp
1227                                 else if( strcmp(type, "last_seen_before") == 0 ) {
1228                                         lastSeenAfter = atoll(val);
1229                                 }
1230                                 // - Last seen after timestamp
1231                                 else if( strcmp(type, "last_seen_after") == 0 ) {
1232                                         lastSeenAfter = atoll(val);
1233                                 }
1234                                 // - Sorting 
1235                                 else if( strcmp(type, "sort") == 0 ) {
1236                                         char    *dash = strchr(val, '-');
1237                                         if( dash ) {
1238                                                 *dash = '\0';
1239                                                 dash ++;
1240                                         }
1241                                         if( strcmp(val, "name") == 0 ) {
1242                                                 sort = BANK_ITFLAG_SORT_NAME;
1243                                         }
1244                                         else if( strcmp(val, "balance") == 0 ) {
1245                                                 sort = BANK_ITFLAG_SORT_BAL;
1246                                         }
1247                                         else if( strcmp(val, "lastseen") == 0 ) {
1248                                                 sort = BANK_ITFLAG_SORT_LASTSEEN;
1249                                         }
1250                                         else {
1251                                                 sendf(Client->Socket, "407 Unknown sort field ('%s')\n", val);
1252                                                 return ;
1253                                         }
1254                                         // Handle sort direction
1255                                         if( dash ) {
1256                                                 if( strcmp(dash, "desc") == 0 ) {
1257                                                         sort |= BANK_ITFLAG_REVSORT;
1258                                                 }
1259                                                 else {
1260                                                         sendf(Client->Socket, "407 Unknown sort direction '%s'\n", dash);
1261                                                         return ;
1262                                                 }
1263                                                 dash[-1] = '-';
1264                                         }
1265                                 }
1266                                 else {
1267                                         sendf(Client->Socket, "407 Unknown argument to ENUM_USERS '%s:%s'\n", type, val);
1268                                         return ;
1269                                 }
1270                                 
1271                                 val[-1] = ':';
1272                         }
1273                         else {
1274                                 sendf(Client->Socket, "407 Unknown argument to ENUM_USERS '%s'\n", type);
1275                                 return ;
1276                         }
1277                         
1278                         // Eat whitespace
1279                         if( space ) {
1280                                 *space = ' ';   // Repair (to be nice)
1281                                 space ++;
1282                                 while(*space == ' ')    space ++;
1283                         }
1284                 }       while(space);
1285         }
1286         
1287         // Create iterator
1288         if( maxBal != INT_MAX ) {
1289                 flags = sort|BANK_ITFLAG_MAXBALANCE;
1290                 balValue = maxBal;
1291         }
1292         else if( minBal != INT_MIN ) {
1293                 flags = sort|BANK_ITFLAG_MINBALANCE;
1294                 balValue = minBal;
1295         }
1296         else {
1297                 flags = sort;
1298                 balValue = 0;
1299         }
1300         if( lastSeenBefore ) {
1301                 timeValue = lastSeenBefore;
1302                 flags |= BANK_ITFLAG_SEENBEFORE;
1303         }
1304         else if( lastSeenAfter ) {
1305                 timeValue = lastSeenAfter;
1306                 flags |= BANK_ITFLAG_SEENAFTER;
1307         }
1308         else {
1309                 timeValue = 0;
1310         }
1311         it = Bank_Iterator(flagMask, flagVal, flags, balValue, timeValue);
1312         
1313         // Get return number
1314         while( (i = Bank_IteratorNext(it)) != -1 )
1315         {
1316                 int bal = Bank_GetBalance(i);
1317                 
1318                 if( bal == INT_MIN )    continue;
1319                 
1320                 if( bal < minBal )      continue;
1321                 if( bal > maxBal )      continue;
1322                 
1323                 numRet ++;
1324         }
1325         
1326         Bank_DelIterator(it);
1327         
1328         // Send count
1329         sendf(Client->Socket, "201 Users %i\n", numRet);
1330         
1331         
1332         // Create iterator
1333         it = Bank_Iterator(flagMask, flagVal, flags, balValue, timeValue);
1334         
1335         while( (i = Bank_IteratorNext(it)) != -1 )
1336         {
1337                 int bal = Bank_GetBalance(i);
1338                 
1339                 if( bal == INT_MIN )    continue;
1340                 
1341                 if( bal < minBal )      continue;
1342                 if( bal > maxBal )      continue;
1343                 
1344                 _SendUserInfo(Client, i);
1345         }
1346         
1347         Bank_DelIterator(it);
1348         
1349         sendf(Client->Socket, "200 List End\n");
1350 }
1351
1352 void Server_Cmd_USERINFO(tClient *Client, char *Args)
1353 {
1354          int    uid;
1355         char    *user;
1356         
1357         // Parse arguments
1358         if( Server_int_ParseArgs(0, Args, &user, NULL) ) {
1359                 sendf(Client->Socket, "407 USER_INFO takes 1 argument\n");
1360                 return ;
1361         }
1362         
1363         if( giDebugLevel )      Debug(Client, "User Info '%s'", user);
1364         
1365         // Get recipient
1366         uid = Bank_GetAcctByName(user, 0);
1367         
1368         if( giDebugLevel >= 2 ) Debug(Client, "uid = %i", uid);
1369         if( uid == -1 ) {
1370                 sendf(Client->Socket, "404 Invalid user\n");
1371                 return ;
1372         }
1373         
1374         _SendUserInfo(Client, uid);
1375 }
1376
1377 void _SendUserInfo(tClient *Client, int UserID)
1378 {
1379         char    *type, *disabled="", *door="";
1380          int    flags = Bank_GetFlags(UserID);
1381         
1382         if( flags & USER_FLAG_INTERNAL ) {
1383                 type = "internal";
1384         }
1385         else if( flags & USER_FLAG_COKE ) {
1386                 if( flags & USER_FLAG_ADMIN )
1387                         type = "coke,admin";
1388                 else
1389                         type = "coke";
1390         }
1391         else if( flags & USER_FLAG_ADMIN ) {
1392                 type = "admin";
1393         }
1394         else {
1395                 type = "user";
1396         }
1397         
1398         if( flags & USER_FLAG_DISABLED )
1399                 disabled = ",disabled";
1400         if( flags & USER_FLAG_DOORGROUP )
1401                 door = ",door";
1402         
1403         // TODO: User flags/type
1404         sendf(
1405                 Client->Socket, "202 User %s %i %s%s%s\n",
1406                 Bank_GetAcctName(UserID), Bank_GetBalance(UserID),
1407                 type, disabled, door
1408                 );
1409 }
1410
1411 void Server_Cmd_USERADD(tClient *Client, char *Args)
1412 {
1413         char    *username;
1414         
1415         // Parse arguments
1416         if( Server_int_ParseArgs(0, Args, &username, NULL) ) {
1417                 sendf(Client->Socket, "407 USER_ADD takes 1 argument\n");
1418                 return ;
1419         }
1420         
1421         // Check authentication
1422         if( !Client->bIsAuthed ) {
1423                 sendf(Client->Socket, "401 Not Authenticated\n");
1424                 return ;
1425         }
1426         
1427         // Check permissions
1428         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) ) {
1429                 sendf(Client->Socket, "403 Not a coke admin\n");
1430                 return ;
1431         }
1432         
1433         // Try to create user
1434         if( Bank_CreateAcct(username) == -1 ) {
1435                 sendf(Client->Socket, "404 User exists\n");
1436                 return ;
1437         }
1438         
1439         {
1440                 char    *thisName = Bank_GetAcctName(Client->UID);
1441                 Log_Info("Account '%s' created by '%s'", username, thisName);
1442                 free(thisName);
1443         }
1444         
1445         sendf(Client->Socket, "200 User Added\n");
1446 }
1447
1448 void Server_Cmd_USERFLAGS(tClient *Client, char *Args)
1449 {
1450         char    *username, *flags, *reason=NULL;
1451          int    mask=0, value=0;
1452          int    uid;
1453         
1454         // Parse arguments
1455         if( Server_int_ParseArgs(1, Args, &username, &flags, &reason, NULL) ) {
1456                 if( !flags ) {
1457                         sendf(Client->Socket, "407 USER_FLAGS takes at least 2 arguments\n");
1458                         return ;
1459                 }
1460                 reason = "";
1461         }
1462         
1463         // Check authentication
1464         if( !Client->bIsAuthed ) {
1465                 sendf(Client->Socket, "401 Not Authenticated\n");
1466                 return ;
1467         }
1468         
1469         // Check permissions
1470         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) ) {
1471                 sendf(Client->Socket, "403 Not a coke admin\n");
1472                 return ;
1473         }
1474         
1475         // Get UID
1476         uid = Bank_GetAcctByName(username, 0);
1477         if( uid == -1 ) {
1478                 sendf(Client->Socket, "404 User '%s' not found\n", username);
1479                 return ;
1480         }
1481         
1482         // Parse flags
1483         if( Server_int_ParseFlags(Client, flags, &mask, &value) )
1484                 return ;
1485         
1486         if( giDebugLevel )
1487                 Debug(Client, "Set %i(%s) flags to %x (masked %x)\n",
1488                         uid, username, mask, value);
1489         
1490         // Apply flags
1491         Bank_SetFlags(uid, mask, value);
1492
1493         // Log the change
1494         Log_Info("Updated '%s' with flag set '%s' by '%s' - Reason: %s",
1495                 username, flags, Client->Username, reason);
1496         
1497         // Return OK
1498         sendf(Client->Socket, "200 User Updated\n");
1499 }
1500
1501 void Server_Cmd_UPDATEITEM(tClient *Client, char *Args)
1502 {
1503         char    *itemname, *price_str, *description;
1504          int    price;
1505         tItem   *item;
1506         
1507         if( Server_int_ParseArgs(1, Args, &itemname, &price_str, &description, NULL) ) {
1508                 sendf(Client->Socket, "407 UPDATE_ITEM takes 3 arguments\n");
1509                 return ;
1510         }
1511         
1512         if( !Client->bIsAuthed ) {
1513                 sendf(Client->Socket, "401 Not Authenticated\n");
1514                 return ;
1515         }
1516
1517         // Check user permissions
1518         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1519                 sendf(Client->Socket, "403 Not in coke\n");
1520                 return ;
1521         }
1522         
1523         item = _GetItemFromString(itemname);
1524         if( !item ) {
1525                 // TODO: Create item?
1526                 sendf(Client->Socket, "406 Bad Item ID\n");
1527                 return ;
1528         }
1529         
1530         price = atoi(price_str);
1531         if( price <= 0 && price_str[0] != '0' ) {
1532                 sendf(Client->Socket, "407 Invalid price set\n");
1533         }
1534         
1535         switch( DispenseUpdateItem( Client->UID, item, description, price ) )
1536         {
1537         case 0:
1538                 // Return OK
1539                 sendf(Client->Socket, "200 Item updated\n");
1540                 break;
1541         default:
1542                 break;
1543         }
1544 }
1545
1546 void Server_Cmd_PINCHECK(tClient *Client, char *Args)
1547 {
1548         char    *username, *pinstr;
1549          int    pin;
1550
1551         if( Server_int_ParseArgs(0, Args, &username, &pinstr, NULL) ) {
1552                 sendf(Client->Socket, "407 PIN_CHECK takes 2 arguments\n");
1553                 return ;
1554         }
1555         
1556         if( !isdigit(pinstr[0]) || !isdigit(pinstr[1]) || !isdigit(pinstr[2]) || !isdigit(pinstr[3]) || pinstr[4] != '\0' ) {
1557                 sendf(Client->Socket, "407 PIN should be four digits\n");
1558                 return ;
1559         }
1560         pin = atoi(pinstr);
1561
1562         // Not authenticated? go away!
1563         if( !Client->bIsAuthed ) {
1564                 sendf(Client->Socket, "401 Not Authenticated\n");
1565                 return ;
1566         }
1567         
1568         // Get user
1569         int uid = Bank_GetAcctByName(username, 0);
1570         if( uid == -1 ) {
1571                 sendf(Client->Socket, "404 User '%s' not found\n", username);
1572                 return ;
1573         }
1574         
1575         // Check user permissions
1576         if( uid != Client->UID && !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1577                 sendf(Client->Socket, "403 Not in coke\n");
1578                 return ;
1579         }
1580         
1581         // Get the pin
1582         static time_t   last_wrong_pin_time;
1583         static int      backoff = 1;
1584         if( time(NULL) - last_wrong_pin_time < backoff ) {
1585                 sendf(Client->Socket, "407 Rate limited (%i seconds remaining)\n",
1586                         backoff - (time(NULL) - last_wrong_pin_time));
1587                 return ;
1588         }       
1589         last_wrong_pin_time = time(NULL);
1590         if( !Bank_IsPinValid(uid, pin) )
1591         {
1592                 sendf(Client->Socket, "201 Pin incorrect\n");
1593                 struct sockaddr_storage addr;
1594                 socklen_t len = sizeof(addr);
1595                 char ipstr[INET6_ADDRSTRLEN];
1596                 getpeername(Client->Socket, (void*)&addr, &len);
1597                 struct sockaddr_in *s = (struct sockaddr_in *)&addr;
1598                 inet_ntop(addr.ss_family, &s->sin_addr, ipstr, sizeof(ipstr));
1599                 Debug_Notice("Bad pin from %s for %s by %i", ipstr, username, Client->UID);
1600                 if( backoff < 5)
1601                         backoff ++;
1602                 return ;
1603         }
1604
1605         last_wrong_pin_time = 0;
1606         backoff = 1;
1607         sendf(Client->Socket, "200 Pin correct\n");
1608         return ;
1609 }
1610 void Server_Cmd_PINSET(tClient *Client, char *Args)
1611 {
1612         char    *pinstr;
1613          int    pin;
1614         
1615
1616         if( Server_int_ParseArgs(0, Args, &pinstr, NULL) ) {
1617                 sendf(Client->Socket, "407 PIN_SET takes 1 argument\n");
1618                 return ;
1619         }
1620         
1621         if( !isdigit(pinstr[0]) || !isdigit(pinstr[1]) || !isdigit(pinstr[2]) || !isdigit(pinstr[3]) || pinstr[4] != '\0' ) {
1622                 sendf(Client->Socket, "407 PIN should be four digits\n");
1623                 return ;
1624         }
1625         pin = atoi(pinstr);
1626
1627         if( !Client->bIsAuthed ) {
1628                 sendf(Client->Socket, "401 Not Authenticated\n");
1629                 return ;
1630         }
1631         
1632         int uid = Client->EffectiveUID;
1633         if(uid == -1)
1634                 uid = Client->UID;
1635         // Can only pinset yourself (well, the effective user)
1636         Bank_SetPin(uid, pin);
1637         sendf(Client->Socket, "200 Pin updated\n");
1638         return ;
1639 }
1640
1641 // --- INTERNAL HELPERS ---
1642 void Debug(tClient *Client, const char *Format, ...)
1643 {
1644         va_list args;
1645         //printf("%010i [%i] ", (int)time(NULL), Client->ID);
1646         printf("[%i] ", Client->ID);
1647         va_start(args, Format);
1648         vprintf(Format, args);
1649         va_end(args);
1650         printf("\n");
1651 }
1652
1653 int sendf(int Socket, const char *Format, ...)
1654 {
1655         va_list args;
1656          int    len;
1657         
1658         va_start(args, Format);
1659         len = vsnprintf(NULL, 0, Format, args);
1660         va_end(args);
1661         
1662         {
1663                 char    buf[len+1];
1664                 va_start(args, Format);
1665                 vsnprintf(buf, len+1, Format, args);
1666                 va_end(args);
1667                 
1668                 #if DEBUG_TRACE_CLIENT
1669                 printf("sendf: %s", buf);
1670                 #endif
1671                 
1672                 return send(Socket, buf, len, 0);
1673         }
1674 }
1675
1676 // Takes a series of char *'s in
1677 /**
1678  * \brief Parse space-separated entries into 
1679  */
1680 int Server_int_ParseArgs(int bUseLongLast, char *ArgStr, ...)
1681 {
1682         va_list args;
1683         char    savedChar;
1684         char    **dest;
1685         va_start(args, ArgStr);
1686
1687         // Check for null
1688         if( !ArgStr )
1689         {
1690                 while( (dest = va_arg(args, char **)) )
1691                         *dest = NULL;
1692                 va_end(args);
1693                 return 1;
1694         }
1695
1696         savedChar = *ArgStr;
1697         
1698         while( (dest = va_arg(args, char **)) )
1699         {
1700                 // Trim leading spaces
1701                 while( *ArgStr == ' ' || *ArgStr == '\t' )
1702                         ArgStr ++;
1703                 
1704                 // ... oops, not enough arguments
1705                 if( *ArgStr == '\0' )
1706                 {
1707                         // NULL unset arguments
1708                         do {
1709                                 *dest = NULL;
1710                         }       while( (dest = va_arg(args, char **)) );
1711                 va_end(args);
1712                         return -1;
1713                 }
1714                 
1715                 if( *ArgStr == '"' )
1716                 {
1717                         ArgStr ++;
1718                         *dest = ArgStr;
1719                         // Read until quote
1720                         while( *ArgStr && *ArgStr != '"' )
1721                                 ArgStr ++;
1722                 }
1723                 else
1724                 {
1725                         // Set destination
1726                         *dest = ArgStr;
1727                         // Read until a space
1728                         while( *ArgStr && *ArgStr != ' ' && *ArgStr != '\t' )
1729                                 ArgStr ++;
1730                 }
1731                 savedChar = *ArgStr;    // savedChar is used to un-mangle the last string
1732                 *ArgStr = '\0';
1733                 ArgStr ++;
1734         }
1735         va_end(args);
1736         
1737         // Oops, extra arguments, and greedy not set
1738         if( (savedChar == ' ' || savedChar == '\t') && !bUseLongLast ) {
1739                 return -1;
1740         }
1741         
1742         // Un-mangle last
1743         if(bUseLongLast) {
1744                 ArgStr --;
1745                 *ArgStr = savedChar;
1746         }
1747         
1748         return 0;       // Success!
1749 }
1750
1751 int Server_int_ParseFlags(tClient *Client, const char *Str, int *Mask, int *Value)
1752 {
1753         struct {
1754                 const char      *Name;
1755                  int    Mask;
1756                  int    Value;
1757         }       cFLAGS[] = {
1758                  {"disabled", USER_FLAG_DISABLED, USER_FLAG_DISABLED}
1759                 ,{"door", USER_FLAG_DOORGROUP, USER_FLAG_DOORGROUP}
1760                 ,{"coke", USER_FLAG_COKE, USER_FLAG_COKE}
1761                 ,{"admin", USER_FLAG_ADMIN, USER_FLAG_ADMIN}
1762                 ,{"internal", USER_FLAG_INTERNAL, USER_FLAG_INTERNAL}
1763         };
1764         const int       ciNumFlags = sizeof(cFLAGS)/sizeof(cFLAGS[0]);
1765         
1766         char    *space;
1767         
1768         *Mask = 0;
1769         *Value = 0;
1770         
1771         do {
1772                  int    bRemove = 0;
1773                  int    i;
1774                  int    len;
1775                 
1776                 while( *Str == ' ' )    Str ++; // Eat whitespace
1777                 space = strchr(Str, ',');       // Find the end of the flag
1778                 if(space)
1779                         len = space - Str;
1780                 else
1781                         len = strlen(Str);
1782                 
1783                 // Check for inversion/removal
1784                 if( *Str == '!' || *Str == '-' ) {
1785                         bRemove = 1;
1786                         Str ++;
1787                 }
1788                 else if( *Str == '+' ) {
1789                         Str ++;
1790                 }
1791                 
1792                 // Check flag values
1793                 for( i = 0; i < ciNumFlags; i ++ )
1794                 {
1795                         if( strncmp(Str, cFLAGS[i].Name, len) == 0 ) {
1796                                 *Mask |= cFLAGS[i].Mask;
1797                                 *Value &= ~cFLAGS[i].Mask;
1798                                 if( !bRemove )
1799                                         *Value |= cFLAGS[i].Value;
1800                                 break;
1801                         }
1802                 }
1803                 
1804                 // Error check
1805                 if( i == ciNumFlags ) {
1806                         char    val[len+1];
1807                         strncpy(val, Str, len+1);
1808                         sendf(Client->Socket, "407 Unknown flag value '%s'\n", val);
1809                         return -1;
1810                 }
1811                 
1812                 Str = space + 1;
1813         } while(space);
1814         
1815         return 0;
1816 }
1817

UCC git Repository :: git.ucc.asn.au