Server - Fixed leaked file handles in both itemdb and modbus
[tpg/opendispense2.git] / src / server / server.c
1 /*
2  * OpenDispense 2 
3  * UCC (University [of WA] Computer Club) Electronic Accounting System
4  *
5  * server.c - Client Server Code
6  *
7  * This file is licenced under the 3-clause BSD Licence. See the file
8  * COPYING for full details.
9  */
10 #include <stdio.h>
11 #include <stdlib.h>
12 #include "common.h"
13 #include <sys/socket.h>
14 #include <netinet/in.h>
15 #include <arpa/inet.h>
16 #include <unistd.h>
17 #include <fcntl.h>      // O_*
18 #include <string.h>
19 #include <limits.h>
20 #include <stdarg.h>
21 #include <signal.h>     // Signal handling
22 #include <ident.h>      // AUTHIDENT
23 #include <time.h>       // time(2)
24 #include <ctype.h>
25
26 #define DEBUG_TRACE_CLIENT      0
27 #define HACK_NO_REFUNDS 1
28
29 #define PIDFILE "/var/run/dispsrv.pid"
30
31 // Statistics
32 #define MAX_CONNECTION_QUEUE    5
33 #define INPUT_BUFFER_SIZE       256
34 #define CLIENT_TIMEOUT  10      // Seconds
35
36 #define HASH_TYPE       SHA1
37 #define HASH_LENGTH     20
38
39 #define MSG_STR_TOO_LONG        "499 Command too long (limit "EXPSTR(INPUT_BUFFER_SIZE)")\n"
40
41 #define IDENT_TRUSTED_NETWORK 0x825F0D00
42 #define IDENT_TRUSTED_NETMASK 0xFFFFFFC0
43
44 // === TYPES ===
45 typedef struct sClient
46 {
47          int    Socket; // Client socket ID
48          int    ID;     // Client ID
49          
50          int    bTrustedHost;
51          int    bCanAutoAuth;   // Is the connection from a trusted host/port
52         
53         char    *Username;
54         char    Salt[9];
55         
56          int    UID;
57          int    EffectiveUID;
58          int    bIsAuthed;
59 }       tClient;
60
61 // === PROTOTYPES ===
62 void    Server_Start(void);
63 void    Server_Cleanup(void);
64 void    Server_HandleClient(int Socket, int bTrustedHost, int bRootPort);
65 void    Server_ParseClientCommand(tClient *Client, char *CommandString);
66 // --- Commands ---
67 void    Server_Cmd_USER(tClient *Client, char *Args);
68 void    Server_Cmd_PASS(tClient *Client, char *Args);
69 void    Server_Cmd_AUTOAUTH(tClient *Client, char *Args);
70 void    Server_Cmd_AUTHIDENT(tClient *Client, char *Args);
71 void    Server_Cmd_SETEUSER(tClient *Client, char *Args);
72 void    Server_Cmd_ENUMITEMS(tClient *Client, char *Args);
73 void    Server_Cmd_ITEMINFO(tClient *Client, char *Args);
74 void    Server_Cmd_DISPENSE(tClient *Client, char *Args);
75 void    Server_Cmd_REFUND(tClient *Client, char *Args);
76 void    Server_Cmd_GIVE(tClient *Client, char *Args);
77 void    Server_Cmd_DONATE(tClient *Client, char *Args);
78 void    Server_Cmd_ADD(tClient *Client, char *Args);
79 void    Server_Cmd_SET(tClient *Client, char *Args);
80 void    Server_Cmd_ENUMUSERS(tClient *Client, char *Args);
81 void    Server_Cmd_USERINFO(tClient *Client, char *Args);
82 void    _SendUserInfo(tClient *Client, int UserID);
83 void    Server_Cmd_USERADD(tClient *Client, char *Args);
84 void    Server_Cmd_USERFLAGS(tClient *Client, char *Args);
85 void    Server_Cmd_UPDATEITEM(tClient *Client, char *Args);
86 void    Server_Cmd_PINCHECK(tClient *Client, char *Args);
87 void    Server_Cmd_PINSET(tClient *Client, char *Args);
88 // --- Helpers ---
89 void    Debug(tClient *Client, const char *Format, ...);
90  int    sendf(int Socket, const char *Format, ...);
91  int    Server_int_ParseArgs(int bUseLongArg, char *ArgStr, ...);
92  int    Server_int_ParseFlags(tClient *Client, const char *Str, int *Mask, int *Value);
93
94 // === CONSTANTS ===
95 // - Commands
96 const struct sClientCommand {
97         const char      *Name;
98         void    (*Function)(tClient *Client, char *Arguments);
99 }       gaServer_Commands[] = {
100         {"USER", Server_Cmd_USER},
101         {"PASS", Server_Cmd_PASS},
102         {"AUTOAUTH", Server_Cmd_AUTOAUTH},
103         {"AUTHIDENT", Server_Cmd_AUTHIDENT},
104         {"SETEUSER", Server_Cmd_SETEUSER},
105         {"ENUM_ITEMS", Server_Cmd_ENUMITEMS},
106         {"ITEM_INFO", Server_Cmd_ITEMINFO},
107         {"DISPENSE", Server_Cmd_DISPENSE},
108         {"REFUND", Server_Cmd_REFUND},
109         {"GIVE", Server_Cmd_GIVE},
110         {"DONATE", Server_Cmd_DONATE},
111         {"ADD", Server_Cmd_ADD},
112         {"SET", Server_Cmd_SET},
113         {"ENUM_USERS", Server_Cmd_ENUMUSERS},
114         {"USER_INFO", Server_Cmd_USERINFO},
115         {"USER_ADD", Server_Cmd_USERADD},
116         {"USER_FLAGS", Server_Cmd_USERFLAGS},
117         {"UPDATE_ITEM", Server_Cmd_UPDATEITEM},
118         {"PIN_CHECK", Server_Cmd_PINCHECK},
119         {"PIN_SET", Server_Cmd_PINSET}
120 };
121 #define NUM_COMMANDS    ((int)(sizeof(gaServer_Commands)/sizeof(gaServer_Commands[0])))
122
123 // === GLOBALS ===
124 // - Configuration
125  int    giServer_Port = 11020;
126  int    gbServer_RunInBackground = 0;
127 char    *gsServer_LogFile = "/var/log/dispsrv.log";
128 char    *gsServer_ErrorLog = "/var/log/dispsrv.err";
129  int    giServer_NumTrustedHosts;
130 struct in_addr  *gaServer_TrustedHosts;
131 // - State variables
132  int    giServer_Socket;        // Server socket
133  int    giServer_NextClientID = 1;      // Debug client ID
134  
135
136 // === CODE ===
137 /**
138  * \brief Open listenting socket and serve connections
139  */
140 void Server_Start(void)
141 {
142          int    client_socket;
143         struct sockaddr_in      server_addr, client_addr;
144
145         // Parse trusted hosts list
146         giServer_NumTrustedHosts = Config_GetValueCount("trusted_host");
147         gaServer_TrustedHosts = malloc(giServer_NumTrustedHosts * sizeof(*gaServer_TrustedHosts));
148         for( int i = 0; i < giServer_NumTrustedHosts; i ++ )
149         {
150                 const char      *addr = Config_GetValue("trusted_host", i);
151                 
152                 if( inet_aton(addr, &gaServer_TrustedHosts[i]) == 0 ) {
153                         fprintf(stderr, "Invalid IP address '%s'\n", addr);
154                         continue ;
155                 }
156         }
157
158         // Ignore SIGPIPE (stops crashes when the client exits early)
159         signal(SIGPIPE, SIG_IGN);
160
161         // Create Server
162         giServer_Socket = socket(PF_INET, SOCK_STREAM, IPPROTO_TCP);
163         if( giServer_Socket < 0 ) {
164                 fprintf(stderr, "ERROR: Unable to create server socket\n");
165                 return ;
166         }
167         
168         // Make listen address
169         memset(&server_addr, 0, sizeof(server_addr));
170         server_addr.sin_family = AF_INET;       // Internet Socket
171         server_addr.sin_addr.s_addr = htonl(INADDR_ANY);        // Listen on all interfaces
172         server_addr.sin_port = htons(giServer_Port);    // Port
173
174         // Bind
175         if( bind(giServer_Socket, (struct sockaddr *) &server_addr, sizeof(server_addr)) < 0 ) {
176                 fprintf(stderr, "ERROR: Unable to bind to 0.0.0.0:%i\n", giServer_Port);
177                 perror("Binding");
178                 close(giServer_Socket);
179                 return ;
180         }
181
182         // Fork into background
183         if( gbServer_RunInBackground )
184         {
185                 int pid = fork();
186                 if( pid == -1 ) {
187                         fprintf(stderr, "ERROR: Unable to fork\n");
188                         perror("fork background");
189                         exit(-1);
190                 }
191                 if( pid != 0 ) {
192                         // Parent, quit
193                         Debug_Notice("Forked child server as PID %i\n", pid);
194                         exit(0);
195                 }
196                 // In child
197                 // - Sort out stdin/stdout
198                 #if 0
199                 dup2( open("/dev/null", O_RDONLY, 0644), STDIN_FILENO );
200                 dup2( open(gsServer_LogFile, O_CREAT|O_APPEND, 0644), STDOUT_FILENO );
201                 dup2( open(gsServer_ErrorLog, O_CREAT|O_APPEND, 0644), STDERR_FILENO );
202                 #else
203                 freopen("/dev/null", "r", stdin);
204                 freopen(gsServer_LogFile, "a", stdout);
205                 freopen(gsServer_ErrorLog, "a", stderr);
206                 fprintf(stdout, "OpenDispense 2 Server Started at %lld\n", (long long)time(NULL));
207                 fprintf(stderr, "OpenDispense 2 Server Started at %lld\n", (long long)time(NULL));
208                 #endif
209         }
210         atexit(Server_Cleanup);
211
212         // Start the helper thread
213         StartPeriodicThread();
214         
215         // Listen
216         if( listen(giServer_Socket, MAX_CONNECTION_QUEUE) < 0 ) {
217                 fprintf(stderr, "ERROR: Unable to listen to socket\n");
218                 perror("Listen");
219                 return ;
220         }
221         
222         Debug_Notice("Listening on 0.0.0.0:%i", giServer_Port);
223         
224         // write pidfile
225         {
226                 FILE *fp = fopen(PIDFILE, "w");
227                 if( fp ) {
228                         fprintf(fp, "%i", getpid());
229                         fclose(fp);
230                 }
231         }
232
233         for(;;)
234         {
235                 uint    len = sizeof(client_addr);
236                  int    bTrusted = 0;
237                  int    bRootPort = 0;
238                 
239                 // Accept a connection
240                 client_socket = accept(giServer_Socket, (struct sockaddr *) &client_addr, &len);
241                 if(client_socket < 0) {
242                         fprintf(stderr, "ERROR: Unable to accept client connection\n");
243                         return ;
244                 }
245                 
246                 // Set a timeout on the user conneciton
247                 {
248                         struct timeval tv;
249                         tv.tv_sec = CLIENT_TIMEOUT;
250                         tv.tv_usec = 0;
251                         if( setsockopt(client_socket, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv)) )
252                         {
253                                 perror("setsockopt");
254                                 return ;
255                         }
256                 }
257                 
258                 // Debug: Print the connection string
259                 if(giDebugLevel >= 2) {
260                         char    ipstr[INET_ADDRSTRLEN];
261                         inet_ntop(AF_INET, &client_addr.sin_addr, ipstr, INET_ADDRSTRLEN);
262                         Debug_Debug("Client connection from %s:%i",
263                                 ipstr, ntohs(client_addr.sin_port));
264                 }
265                 
266                 // Doesn't matter what, localhost is trusted
267                 if( ntohl( client_addr.sin_addr.s_addr ) == 0x7F000001 )
268                         bTrusted = 1;
269         
270                 // Check if the host is on the trusted list     
271                 for( int i = 0; i < giServer_NumTrustedHosts; i ++ )
272                 {
273                         if( memcmp(&client_addr.sin_addr, &gaServer_TrustedHosts[i], sizeof(struct in_addr)) == 0 )
274                         {
275                                 bTrusted = 1;
276                                 break;
277                         }
278                 }
279
280                 // Root port (can AUTOAUTH if also a trusted machine
281                 if( ntohs(client_addr.sin_port) < 1024 )
282                         bRootPort = 1;
283                 
284                 #if 0
285                 {
286                         // TODO: Make this runtime configurable
287                         switch( ntohl( client_addr.sin_addr.s_addr ) )
288                         {
289                         case 0x7F000001:        // 127.0.0.1    localhost
290                 //      case 0x825F0D00:        // 130.95.13.0
291                         case 0x825F0D04:        // 130.95.13.4  merlo
292                 //      case 0x825F0D05:        // 130.95.13.5  heathred (MR)
293                         case 0x825F0D07:        // 130.95.13.7  motsugo
294                         case 0x825F0D11:        // 130.95.13.17 mermaid
295                         case 0x825F0D12:        // 130.95.13.18 mussel
296                         case 0x825F0D17:        // 130.95.13.23 martello
297                         case 0x825F0D2A:        // 130.95.13.42 meersau
298                 //      case 0x825F0D42:        // 130.95.13.66 heathred (Clubroom)
299                                 bTrusted = 1;
300                                 break;
301                         default:
302                                 break;
303                         }
304                 }
305                 #endif
306                 
307                 // TODO: Multithread this?
308                 Server_HandleClient(client_socket, bTrusted, bRootPort);
309                 
310                 close(client_socket);
311         }
312 }
313
314 void Server_Cleanup(void)
315 {
316         Debug_Debug("Close(%i)", giServer_Socket);
317         close(giServer_Socket);
318         unlink(PIDFILE);
319 }
320
321 /**
322  * \brief Reads from a client socket and parses the command strings
323  * \param Socket        Client socket number/handle
324  * \param bTrusted      Is the client trusted?
325  */
326 void Server_HandleClient(int Socket, int bTrusted, int bRootPort)
327 {
328         char    inbuf[INPUT_BUFFER_SIZE];
329         char    *buf = inbuf;
330          int    remspace = INPUT_BUFFER_SIZE-1;
331          int    bytes = -1;
332         tClient clientInfo;
333         
334         memset(&clientInfo, 0, sizeof(clientInfo));
335         
336         // Initialise Client info
337         clientInfo.Socket = Socket;
338         clientInfo.ID = giServer_NextClientID ++;
339         clientInfo.bTrustedHost = bTrusted;
340         clientInfo.bCanAutoAuth = bTrusted && bRootPort;
341         clientInfo.EffectiveUID = -1;
342         
343         // Read from client
344         /*
345          * Notes:
346          * - The `buf` and `remspace` variables allow a line to span several
347          *   calls to recv(), if a line is not completed in one recv() call
348          *   it is saved to the beginning of `inbuf` and `buf` is updated to
349          *   the end of it.
350          */
351         // TODO: Use select() instead (to give a timeout)
352         while( (bytes = recv(Socket, buf, remspace, 0)) > 0 )
353         {
354                 char    *eol, *start;
355                 buf[bytes] = '\0';      // Allow us to use stdlib string functions on it
356                 
357                 // Split by lines
358                 start = inbuf;
359                 while( (eol = strchr(start, '\n')) )
360                 {
361                         *eol = '\0';
362                         
363                         Server_ParseClientCommand(&clientInfo, start);
364                         
365                         start = eol + 1;
366                 }
367                 
368                 // Check if there was an incomplete line
369                 if( *start != '\0' ) {
370                          int    tailBytes = bytes - (start-buf);
371                         // Roll back in buffer
372                         memcpy(inbuf, start, tailBytes);
373                         remspace -= tailBytes;
374                         if(remspace == 0) {
375                                 send(Socket, MSG_STR_TOO_LONG, sizeof(MSG_STR_TOO_LONG), 0);
376                                 buf = inbuf;
377                                 remspace = INPUT_BUFFER_SIZE - 1;
378                         }
379                 }
380                 else {
381                         buf = inbuf;
382                         remspace = INPUT_BUFFER_SIZE - 1;
383                 }
384         }
385         
386         // Check for errors
387         if( bytes < 0 ) {
388                 fprintf(stderr, "ERROR: Unable to recieve from client on socket %i\n", Socket);
389                 return ;
390         }
391         
392         if(giDebugLevel >= 2) {
393                 printf("Client %i: Disconnected\n", clientInfo.ID);
394         }
395 }
396
397 /**
398  * \brief Parses a client command and calls the required helper function
399  * \param Client        Pointer to client state structure
400  * \param CommandString Command from client (single line of the command)
401  * \return Heap String to return to the client
402  */
403 void Server_ParseClientCommand(tClient *Client, char *CommandString)
404 {
405         char    *command, *args;
406          int    i;
407         
408         if( giDebugLevel >= 2 )
409                 Debug(Client, "Server_ParseClientCommand: (CommandString = '%s')", CommandString);
410         
411         if( Server_int_ParseArgs(1, CommandString, &command, &args, NULL) )
412         {
413                 if( command == NULL )   return ;
414                 // Is this an error? (just ignore for now)
415         }
416         
417         
418         // Find command
419         for( i = 0; i < NUM_COMMANDS; i++ )
420         {
421                 if(strcmp(command, gaServer_Commands[i].Name) == 0) {
422                         if( giDebugLevel >= 2 )
423                                 Debug(Client, "CMD %s - \"%s\"", command, args);
424                         gaServer_Commands[i].Function(Client, args);
425                         return ;
426                 }
427         }
428         
429         sendf(Client->Socket, "400 Unknown Command\n");
430 }
431
432 // ---
433 // Commands
434 // ---
435 /**
436  * \brief Set client username
437  * 
438  * Usage: USER <username>
439  */
440 void Server_Cmd_USER(tClient *Client, char *Args)
441 {
442         char    *username;
443         
444         if( Server_int_ParseArgs(0, Args, &username, NULL) )
445         {
446                 sendf(Client->Socket, "407 USER takes 1 argument\n");
447                 return ;
448         }
449         
450         // Debug!
451         if( giDebugLevel )
452                 Debug(Client, "Authenticating as '%s'", username);
453         
454         // Save username
455         if(Client->Username)
456                 free(Client->Username);
457         Client->Username = strdup(username);
458         
459         #if USE_SALT
460         // Create a salt (that changes if the username is changed)
461         // Yes, I know, I'm a little paranoid, but who isn't?
462         Client->Salt[0] = 0x21 + (rand()&0x3F);
463         Client->Salt[1] = 0x21 + (rand()&0x3F);
464         Client->Salt[2] = 0x21 + (rand()&0x3F);
465         Client->Salt[3] = 0x21 + (rand()&0x3F);
466         Client->Salt[4] = 0x21 + (rand()&0x3F);
467         Client->Salt[5] = 0x21 + (rand()&0x3F);
468         Client->Salt[6] = 0x21 + (rand()&0x3F);
469         Client->Salt[7] = 0x21 + (rand()&0x3F);
470         
471         // TODO: Also send hash type to use, (SHA1 or crypt according to [DAA])
472         sendf(Client->Socket, "100 SALT %s\n", Client->Salt);
473         #else
474         sendf(Client->Socket, "100 User Set\n");
475         #endif
476 }
477
478 /**
479  * \brief Authenticate as a user
480  * 
481  * Usage: PASS <hash>
482  */
483 void Server_Cmd_PASS(tClient *Client, char *Args)
484 {
485         char    *passhash;
486          int    flags;
487
488         if( Server_int_ParseArgs(0, Args, &passhash, NULL) )
489         {
490                 sendf(Client->Socket, "407 PASS takes 1 argument\n");
491                 return ;
492         }
493         
494         // Pass on to cokebank
495         Client->UID = Bank_GetUserAuth(Client->Salt, Client->Username, passhash);
496
497         if( Client->UID == -1 ) {
498                 sendf(Client->Socket, "401 Auth Failure\n");
499                 return ;
500         }
501
502         flags = Bank_GetFlags(Client->UID);
503         if( flags & USER_FLAG_DISABLED ) {
504                 Client->UID = -1;
505                 sendf(Client->Socket, "403 Account Disabled\n");
506                 return ;
507         }
508         if( flags & USER_FLAG_INTERNAL ) {
509                 Client->UID = -1;
510                 sendf(Client->Socket, "403 Internal account\n");
511                 return ;
512         }
513         
514         Client->bIsAuthed = 1;
515         sendf(Client->Socket, "200 Auth OK\n");
516 }
517
518 /**
519  * \brief Authenticate as a user without a password
520  * 
521  * Usage: AUTOAUTH <user>
522  */
523 void Server_Cmd_AUTOAUTH(tClient *Client, char *Args)
524 {
525         char    *username;
526          int    userflags;
527         
528         if( Server_int_ParseArgs(0, Args, &username, NULL) )
529         {
530                 sendf(Client->Socket, "407 AUTOAUTH takes 1 argument\n");
531                 return ;
532         }
533         
534         // Check if trusted
535         if( !Client->bCanAutoAuth ) {
536                 if(giDebugLevel)
537                         Debug(Client, "Untrusted client attempting to AUTOAUTH");
538                 sendf(Client->Socket, "401 Untrusted\n");
539                 return ;
540         }
541         
542         // Get UID
543         Client->UID = Bank_GetAcctByName( username, 0 );        
544         if( Client->UID < 0 ) {
545                 if(giDebugLevel)
546                         Debug(Client, "Unknown user '%s'", username);
547                 sendf(Client->Socket, "403 Auth Failure\n");
548                 return ;
549         }
550         
551         userflags = Bank_GetFlags(Client->UID);
552         // You can't be an internal account
553         if( userflags & USER_FLAG_INTERNAL ) {
554                 if(giDebugLevel)
555                         Debug(Client, "Autoauth as '%s', not allowed", username);
556                 Client->UID = -1;
557                 sendf(Client->Socket, "403 Account is internal\n");
558                 return ;
559         }
560
561         // Disabled accounts
562         if( userflags & USER_FLAG_DISABLED ) {
563                 Client->UID = -1;
564                 sendf(Client->Socket, "403 Account disabled\n");
565                 return ;
566         }
567
568         // Save username
569         if(Client->Username)
570                 free(Client->Username);
571         Client->Username = strdup(username);
572
573         Client->bIsAuthed = 1;
574         
575         if(giDebugLevel)
576                 Debug(Client, "Auto authenticated as '%s' (%i)", username, Client->UID);
577         
578         sendf(Client->Socket, "200 Auth OK\n");
579 }
580
581 /**
582  * \brief Authenticate as a user using the IDENT protocol
583  *
584  * Usage: AUTHIDENT
585  */
586 void Server_Cmd_AUTHIDENT(tClient *Client, char *Args)
587 {
588         char    *username;
589          int    userflags;
590         const int ident_timeout = 5;
591
592         if( Args != NULL && strlen(Args) ) {
593                 sendf(Client->Socket, "407 AUTHIDENT takes no arguments\n");
594                 return ;
595         }
596
597         // Check if trusted
598         if( !Client->bTrustedHost ) {
599                 if(giDebugLevel)
600                         Debug(Client, "Untrusted client attempting to AUTHIDENT");
601                 sendf(Client->Socket, "401 Untrusted\n");
602                 return ;
603         }
604
605         // Get username via IDENT
606         username = ident_id(Client->Socket, ident_timeout);
607         if( !username ) {
608                 perror("AUTHIDENT - IDENT timed out");
609                 sendf(Client->Socket, "403 Authentication failure: IDENT auth timed out\n");
610                 return ;
611         }
612
613         // Get UID
614         Client->UID = Bank_GetAcctByName( username, 0 );
615         if( Client->UID < 0 ) {
616                 if(giDebugLevel)
617                         Debug(Client, "Unknown user '%s'", username);
618                 sendf(Client->Socket, "403 Authentication failure: unknown account\n");
619                 free(username);
620                 return ;
621         }
622
623         userflags = Bank_GetFlags(Client->UID);
624         // You can't be an internal account
625         if( userflags & USER_FLAG_INTERNAL ) {
626                 if(giDebugLevel)
627                         Debug(Client, "IDENT auth as '%s', not allowed", username);
628                 Client->UID = -1;
629                 sendf(Client->Socket, "403 Authentication failure: that account is internal\n");
630                 free(username);
631                 return ;
632         }
633
634         // Disabled accounts
635         if( userflags & USER_FLAG_DISABLED ) {
636                 Client->UID = -1;
637                 sendf(Client->Socket, "403 Authentication failure: account disabled\n");
638                 free(username);
639                 return ;
640         }
641
642         // Save username
643         if(Client->Username)
644                 free(Client->Username);
645         Client->Username = strdup(username);
646
647         Client->bIsAuthed = 1;
648
649         if(giDebugLevel)
650                 Debug(Client, "IDENT authenticated as '%s' (%i)", username, Client->UID);
651         free(username);
652
653         sendf(Client->Socket, "200 Auth OK\n");
654 }
655
656 /**
657  * \brief Set effective user
658  */
659 void Server_Cmd_SETEUSER(tClient *Client, char *Args)
660 {
661         char    *username;
662          int    eUserFlags, userFlags;
663         
664         if( Server_int_ParseArgs(0, Args, &username, NULL) )
665         {
666                 sendf(Client->Socket, "407 SETEUSER takes 1 argument\n");
667                 return ;
668         }
669         
670         if( !strlen(Args) ) {
671                 sendf(Client->Socket, "407 SETEUSER expects an argument\n");
672                 return ;
673         }
674         
675         // Check authentication
676         if( !Client->bIsAuthed ) {
677                 sendf(Client->Socket, "401 Not Authenticated\n");
678                 return ;
679         }
680
681         // Check user permissions
682         userFlags = Bank_GetFlags(Client->UID);
683         if( !(userFlags & (USER_FLAG_COKE|USER_FLAG_ADMIN)) ) {
684                 sendf(Client->Socket, "403 Not in coke\n");
685                 return ;
686         }
687         
688         // Set id
689         Client->EffectiveUID = Bank_GetAcctByName(username, 0);
690         if( Client->EffectiveUID == -1 ) {
691                 sendf(Client->Socket, "404 User not found\n");
692                 return ;
693         }
694         // You can't be an internal account (unless you're an admin)
695         if( !(userFlags & USER_FLAG_ADMIN) )
696         {
697                 eUserFlags = Bank_GetFlags(Client->EffectiveUID);
698                 if( eUserFlags & USER_FLAG_INTERNAL ) {
699                         Client->EffectiveUID = -1;
700                         sendf(Client->Socket, "404 User not found\n");
701                         return ;
702                 }
703         }
704
705         // Disabled accounts
706         // - If disabled and the actual user is not an admin (and not root)
707         //   return 403
708         if( (eUserFlags & USER_FLAG_DISABLED) && (Client->UID == 0 || !(userFlags & USER_FLAG_ADMIN)) ) {
709                 Client->EffectiveUID = -1;
710                 sendf(Client->Socket, "403 Account disabled\n");
711                 return ;
712         }
713         
714         sendf(Client->Socket, "200 User set\n");
715 }
716
717 /**
718  * \brief Send an item status to the client
719  * \param Client        Who to?
720  * \param Item  Item to send
721  */
722 void Server_int_SendItem(tClient *Client, tItem *Item)
723 {
724         char    *status = "avail";
725         
726         if( Item->Handler->CanDispense )
727         {
728                 switch(Item->Handler->CanDispense(Client->UID, Item->ID))
729                 {
730                 case  0:        status = "avail";       break;
731                 case  1:        status = "sold";        break;
732                 default:
733                 case -1:        status = "error";       break;
734                 }
735         }
736         
737         if( !gbNoCostMode && Item->Price == 0 )
738                 status = "error";
739         // KNOWN HACK: Naming a slot 'dead' disables it
740         if( strcmp(Item->Name, "dead") == 0 )
741                 status = "sold";        // Another status?
742         
743         sendf(Client->Socket,
744                 "202 Item %s:%i %s %i %s\n",
745                 Item->Handler->Name, Item->ID, status, Item->Price, Item->Name
746                 );
747 }
748
749 /**
750  * \brief Enumerate the items that the server knows about
751  */
752 void Server_Cmd_ENUMITEMS(tClient *Client, char *Args)
753 {
754          int    i, count;
755
756         if( Args != NULL && strlen(Args) ) {
757                 sendf(Client->Socket, "407 ENUM_ITEMS takes no arguments\n");
758                 return ;
759         }
760         
761         // Count shown items
762         count = 0;
763         for( i = 0; i < giNumItems; i ++ ) {
764                 if( gaItems[i].bHidden )        continue;
765                 count ++;
766         }
767
768         sendf(Client->Socket, "201 Items %i\n", count);
769
770         for( i = 0; i < giNumItems; i ++ ) {
771                 if( gaItems[i].bHidden )        continue;
772                 Server_int_SendItem( Client, &gaItems[i] );
773         }
774
775         sendf(Client->Socket, "200 List end\n");
776 }
777
778 tItem *_GetItemFromString(char *String)
779 {
780         tHandler        *handler;
781         char    *type = String;
782         char    *colon = strchr(String, ':');
783          int    num, i;
784         
785         if( !colon ) {
786                 return NULL;
787         }
788
789         num = atoi(colon+1);
790         *colon = '\0';
791
792         // Find handler
793         handler = NULL;
794         for( i = 0; i < giNumHandlers; i ++ )
795         {
796                 if( strcmp(gaHandlers[i]->Name, type) == 0) {
797                         handler = gaHandlers[i];
798                         break;
799                 }
800         }
801         if( !handler ) {
802                 return NULL;
803         }
804
805         // Find item
806         for( i = 0; i < giNumItems; i ++ )
807         {
808                 if( gaItems[i].Handler != handler )     continue;
809                 if( gaItems[i].ID != num )      continue;
810                 return &gaItems[i];
811         }
812         return NULL;
813 }
814
815 /**
816  * \brief Fetch information on a specific item
817  *
818  * Usage: ITEMINFO <item ID>
819  */
820 void Server_Cmd_ITEMINFO(tClient *Client, char *Args)
821 {
822         tItem   *item;
823         char    *itemname;
824         
825         if( Server_int_ParseArgs(0, Args, &itemname, NULL) ) {
826                 sendf(Client->Socket, "407 ITEMINFO takes 1 argument\n");
827                 return ;
828         }
829         item = _GetItemFromString(Args);
830         
831         if( !item ) {
832                 sendf(Client->Socket, "406 Bad Item ID\n");
833                 return ;
834         }
835         
836         Server_int_SendItem( Client, item );
837 }
838
839 /**
840  * \brief Dispense an item
841  *
842  * Usage: DISPENSE <Item ID>
843  */
844 void Server_Cmd_DISPENSE(tClient *Client, char *Args)
845 {
846         tItem   *item;
847          int    ret;
848          int    uid;
849         char    *itemname;
850         
851         if( Server_int_ParseArgs(0, Args, &itemname, NULL) ) {
852                 sendf(Client->Socket, "407 DISPENSE takes only 1 argument\n");
853                 return ;
854         }
855          
856         if( !Client->bIsAuthed ) {
857                 sendf(Client->Socket, "401 Not Authenticated\n");
858                 return ;
859         }
860
861         item = _GetItemFromString(itemname);
862         if( !item ) {
863                 sendf(Client->Socket, "406 Bad Item ID\n");
864                 return ;
865         }
866         
867         if( Client->EffectiveUID != -1 ) {
868                 uid = Client->EffectiveUID;
869         }
870         else {
871                 uid = Client->UID;
872         }
873
874 //      if( Bank_GetFlags(Client->UID) & USER_FLAG_DISABLED  ) {
875 //      }
876
877         switch( ret = DispenseItem( Client->UID, uid, item ) )
878         {
879         case 0: sendf(Client->Socket, "200 Dispense OK\n");     return ;
880         case 1: sendf(Client->Socket, "501 Unable to dispense\n");      return ;
881         case 2: sendf(Client->Socket, "402 Poor You\n");        return ;
882         default:
883                 sendf(Client->Socket, "500 Dispense Error (%i)\n", ret);
884                 return ;
885         }
886 }
887
888 /**
889  * \brief Refund an item to a user
890  *
891  * Usage: REFUND <user> <item id> [<price>]
892  */
893 void Server_Cmd_REFUND(tClient *Client, char *Args)
894 {
895         tItem   *item;
896          int    uid, price_override = 0;
897         char    *username, *itemname, *price_str;
898
899         if( Server_int_ParseArgs(0, Args, &username, &itemname, &price_str, NULL) ) {
900                 if( !itemname || price_str ) {
901                         sendf(Client->Socket, "407 REFUND takes 2 or 3 arguments\n");
902                         return ;
903                 }
904         }
905
906         if( !Client->bIsAuthed ) {
907                 sendf(Client->Socket, "401 Not Authenticated\n");
908                 return ;
909         }
910
911         // Check user permissions
912         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
913                 sendf(Client->Socket, "403 Not in coke\n");
914                 return ;
915         }
916
917         uid = Bank_GetAcctByName(username, 0);
918         if( uid == -1 ) {
919                 sendf(Client->Socket, "404 Unknown user\n");
920                 return ;
921         }
922         
923         item = _GetItemFromString(itemname);
924         if( !item ) {
925                 sendf(Client->Socket, "406 Bad Item ID\n");
926                 return ;
927         }
928
929         if( price_str )
930                 price_override = atoi(price_str);
931
932         switch( DispenseRefund( Client->UID, uid, item, price_override ) )
933         {
934         case 0: sendf(Client->Socket, "200 Item Refunded\n");   return ;
935         default:
936                 sendf(Client->Socket, "500 Dispense Error\n");
937                 return;
938         }
939 }
940
941 /**
942  * \brief Transfer money to another account
943  *
944  * Usage: GIVE <dest> <ammount> <reason...>
945  */
946 void Server_Cmd_GIVE(tClient *Client, char *Args)
947 {
948         char    *recipient, *ammount, *reason;
949          int    uid, iAmmount;
950          int    thisUid;
951         
952         // Parse arguments
953         if( Server_int_ParseArgs(1, Args, &recipient, &ammount, &reason, NULL) ) {
954                 sendf(Client->Socket, "407 GIVE takes only 3 arguments\n");
955                 return ;
956         }
957         
958         // Check for authed
959         if( !Client->bIsAuthed ) {
960                 sendf(Client->Socket, "401 Not Authenticated\n");
961                 return ;
962         }
963
964         // Get recipient
965         uid = Bank_GetAcctByName(recipient, 0);
966         if( uid == -1 ) {
967                 sendf(Client->Socket, "404 Invalid target user\n");
968                 return ;
969         }
970         
971         // You can't alter an internal account
972 //      if( Bank_GetFlags(uid) & USER_FLAG_INTERNAL ) {
973 //              sendf(Client->Socket, "404 Invalid target user\n");
974 //              return ;
975 //      }
976
977         // Parse ammount
978         iAmmount = atoi(ammount);
979         if( iAmmount <= 0 ) {
980                 sendf(Client->Socket, "407 Invalid Argument, ammount must be > zero\n");
981                 return ;
982         }
983         
984         if( Client->EffectiveUID != -1 ) {
985                 thisUid = Client->EffectiveUID;
986         }
987         else {
988                 thisUid = Client->UID;
989         }
990
991         // Do give
992         switch( DispenseGive(Client->UID, thisUid, uid, iAmmount, reason) )
993         {
994         case 0:
995                 sendf(Client->Socket, "200 Give OK\n");
996                 return ;
997         case 2:
998                 sendf(Client->Socket, "402 Poor You\n");
999                 return ;
1000         default:
1001                 sendf(Client->Socket, "500 Unknown error\n");
1002                 return ;
1003         }
1004 }
1005
1006 void Server_Cmd_DONATE(tClient *Client, char *Args)
1007 {
1008         char    *ammount, *reason;
1009          int    iAmmount;
1010          int    thisUid;
1011         
1012         // Parse arguments
1013         if( Server_int_ParseArgs(1, Args, &ammount, &reason, NULL) ) {
1014                 sendf(Client->Socket, "407 DONATE takes 2 arguments\n");
1015                 return ;
1016         }
1017         
1018         if( !Client->bIsAuthed ) {
1019                 sendf(Client->Socket, "401 Not Authenticated\n");
1020                 return ;
1021         }
1022
1023         // Parse ammount
1024         iAmmount = atoi(ammount);
1025         if( iAmmount <= 0 ) {
1026                 sendf(Client->Socket, "407 Invalid Argument, ammount must be > zero\n");
1027                 return ;
1028         }
1029         
1030         // Handle effective users
1031         if( Client->EffectiveUID != -1 ) {
1032                 thisUid = Client->EffectiveUID;
1033         }
1034         else {
1035                 thisUid = Client->UID;
1036         }
1037
1038         // Do give
1039         switch( DispenseDonate(Client->UID, thisUid, iAmmount, reason) )
1040         {
1041         case 0:
1042                 sendf(Client->Socket, "200 Give OK\n");
1043                 return ;
1044         case 2:
1045                 sendf(Client->Socket, "402 Poor You\n");
1046                 return ;
1047         default:
1048                 sendf(Client->Socket, "500 Unknown error\n");
1049                 return ;
1050         }
1051 }
1052
1053 void Server_Cmd_ADD(tClient *Client, char *Args)
1054 {
1055         char    *user, *ammount, *reason;
1056          int    uid, iAmmount;
1057         
1058         // Parse arguments
1059         if( Server_int_ParseArgs(1, Args, &user, &ammount, &reason, NULL) ) {
1060                 sendf(Client->Socket, "407 ADD takes 3 arguments\n");
1061                 return ;
1062         }
1063         
1064         if( !Client->bIsAuthed ) {
1065                 sendf(Client->Socket, "401 Not Authenticated\n");
1066                 return ;
1067         }
1068
1069         // Check user permissions
1070         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1071                 sendf(Client->Socket, "403 Not in coke\n");
1072                 return ;
1073         }
1074
1075         #if !ROOT_CAN_ADD
1076         if( strcmp( Client->Username, "root" ) == 0 ) {
1077                 // Allow adding for new users
1078                 if( strcmp(reason, "treasurer: new user") != 0 ) {
1079                         sendf(Client->Socket, "403 Root may not add\n");
1080                         return ;
1081                 }
1082         }
1083         #endif
1084
1085         #if HACK_NO_REFUNDS
1086         if( strstr(reason, "refund") != NULL || strstr(reason, "misdispense") != NULL )
1087         {
1088                 sendf(Client->Socket, "499 Don't use `dispense acct` for refunds, use `dispense refund` (and `dispense -G` to get item IDs)\n");
1089                 return ;
1090         }
1091         #endif
1092
1093         // Get recipient
1094         uid = Bank_GetAcctByName(user, 0);
1095         if( uid == -1 ) {
1096                 sendf(Client->Socket, "404 Invalid user\n");
1097                 return ;
1098         }
1099         
1100         // You can't alter an internal account
1101         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) )
1102         {
1103                 if( Bank_GetFlags(uid) & USER_FLAG_INTERNAL ) {
1104                         sendf(Client->Socket, "403 Admin only\n");
1105                         return ;
1106                 }
1107                 // TODO: Maybe disallow changes to disabled?
1108         }
1109
1110         // Parse ammount
1111         iAmmount = atoi(ammount);
1112         if( iAmmount == 0 && ammount[0] != '0' ) {
1113                 sendf(Client->Socket, "407 Invalid Argument\n");
1114                 return ;
1115         }
1116
1117         // Do give
1118         switch( DispenseAdd(Client->UID, uid, iAmmount, reason) )
1119         {
1120         case 0:
1121                 sendf(Client->Socket, "200 Add OK\n");
1122                 return ;
1123         case 2:
1124                 sendf(Client->Socket, "402 Poor Guy\n");
1125                 return ;
1126         default:
1127                 sendf(Client->Socket, "500 Unknown error\n");
1128                 return ;
1129         }
1130 }
1131
1132 void Server_Cmd_SET(tClient *Client, char *Args)
1133 {
1134         char    *user, *ammount, *reason;
1135          int    uid, iAmmount;
1136         
1137         // Parse arguments
1138         if( Server_int_ParseArgs(1, Args, &user, &ammount, &reason, NULL) ) {
1139                 sendf(Client->Socket, "407 SET takes 3 arguments\n");
1140                 return ;
1141         }
1142         
1143         if( !Client->bIsAuthed ) {
1144                 sendf(Client->Socket, "401 Not Authenticated\n");
1145                 return ;
1146         }
1147
1148         // Check user permissions
1149         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN)  ) {
1150                 sendf(Client->Socket, "403 Not an admin\n");
1151                 return ;
1152         }
1153
1154         // Get recipient
1155         uid = Bank_GetAcctByName(user, 0);
1156         if( uid == -1 ) {
1157                 sendf(Client->Socket, "404 Invalid user\n");
1158                 return ;
1159         }
1160
1161         // Parse ammount
1162         iAmmount = atoi(ammount);
1163         if( iAmmount == 0 && ammount[0] != '0' ) {
1164                 sendf(Client->Socket, "407 Invalid Argument\n");
1165                 return ;
1166         }
1167
1168         // Do give
1169         switch( DispenseSet(Client->UID, uid, iAmmount, reason) )
1170         {
1171         case 0:
1172                 sendf(Client->Socket, "200 Add OK\n");
1173                 return ;
1174         case 2:
1175                 sendf(Client->Socket, "402 Poor Guy\n");
1176                 return ;
1177         default:
1178                 sendf(Client->Socket, "500 Unknown error\n");
1179                 return ;
1180         }
1181 }
1182
1183 void Server_Cmd_ENUMUSERS(tClient *Client, char *Args)
1184 {
1185          int    i, numRet = 0;
1186         tAcctIterator   *it;
1187          int    maxBal = INT_MAX, minBal = INT_MIN;
1188          int    flagMask = 0, flagVal = 0;
1189          int    sort = BANK_ITFLAG_SORT_NAME;
1190         time_t  lastSeenAfter=0, lastSeenBefore=0;
1191         
1192          int    flags;  // Iterator flags
1193          int    balValue;       // Balance value for iterator
1194         time_t  timeValue;      // Time value for iterator
1195         
1196         // Parse arguments
1197         if( Args && strlen(Args) )
1198         {
1199                 char    *space = Args, *type, *val;
1200                 do
1201                 {
1202                         type = space;
1203                         while(*type == ' ')     type ++;
1204                         // Get next space
1205                         space = strchr(space, ' ');
1206                         if(space)       *space = '\0';
1207                         
1208                         // Get type
1209                         val = strchr(type, ':');
1210                         if( val ) {
1211                                 *val = '\0';
1212                                 val ++;
1213                                 
1214                                 // Types
1215                                 // - Minium Balance
1216                                 if( strcmp(type, "min_balance") == 0 ) {
1217                                         minBal = atoi(val);
1218                                 }
1219                                 // - Maximum Balance
1220                                 else if( strcmp(type, "max_balance") == 0 ) {
1221                                         maxBal = atoi(val);
1222                                 }
1223                                 // - Flags
1224                                 else if( strcmp(type, "flags") == 0 ) {
1225                                         if( Server_int_ParseFlags(Client, val, &flagMask, &flagVal) )
1226                                                 return ;
1227                                 }
1228                                 // - Last seen before timestamp
1229                                 else if( strcmp(type, "last_seen_before") == 0 ) {
1230                                         lastSeenAfter = atoll(val);
1231                                 }
1232                                 // - Last seen after timestamp
1233                                 else if( strcmp(type, "last_seen_after") == 0 ) {
1234                                         lastSeenAfter = atoll(val);
1235                                 }
1236                                 // - Sorting 
1237                                 else if( strcmp(type, "sort") == 0 ) {
1238                                         char    *dash = strchr(val, '-');
1239                                         if( dash ) {
1240                                                 *dash = '\0';
1241                                                 dash ++;
1242                                         }
1243                                         if( strcmp(val, "name") == 0 ) {
1244                                                 sort = BANK_ITFLAG_SORT_NAME;
1245                                         }
1246                                         else if( strcmp(val, "balance") == 0 ) {
1247                                                 sort = BANK_ITFLAG_SORT_BAL;
1248                                         }
1249                                         else if( strcmp(val, "lastseen") == 0 ) {
1250                                                 sort = BANK_ITFLAG_SORT_LASTSEEN;
1251                                         }
1252                                         else {
1253                                                 sendf(Client->Socket, "407 Unknown sort field ('%s')\n", val);
1254                                                 return ;
1255                                         }
1256                                         // Handle sort direction
1257                                         if( dash ) {
1258                                                 if( strcmp(dash, "desc") == 0 ) {
1259                                                         sort |= BANK_ITFLAG_REVSORT;
1260                                                 }
1261                                                 else {
1262                                                         sendf(Client->Socket, "407 Unknown sort direction '%s'\n", dash);
1263                                                         return ;
1264                                                 }
1265                                                 dash[-1] = '-';
1266                                         }
1267                                 }
1268                                 else {
1269                                         sendf(Client->Socket, "407 Unknown argument to ENUM_USERS '%s:%s'\n", type, val);
1270                                         return ;
1271                                 }
1272                                 
1273                                 val[-1] = ':';
1274                         }
1275                         else {
1276                                 sendf(Client->Socket, "407 Unknown argument to ENUM_USERS '%s'\n", type);
1277                                 return ;
1278                         }
1279                         
1280                         // Eat whitespace
1281                         if( space ) {
1282                                 *space = ' ';   // Repair (to be nice)
1283                                 space ++;
1284                                 while(*space == ' ')    space ++;
1285                         }
1286                 }       while(space);
1287         }
1288         
1289         // Create iterator
1290         if( maxBal != INT_MAX ) {
1291                 flags = sort|BANK_ITFLAG_MAXBALANCE;
1292                 balValue = maxBal;
1293         }
1294         else if( minBal != INT_MIN ) {
1295                 flags = sort|BANK_ITFLAG_MINBALANCE;
1296                 balValue = minBal;
1297         }
1298         else {
1299                 flags = sort;
1300                 balValue = 0;
1301         }
1302         if( lastSeenBefore ) {
1303                 timeValue = lastSeenBefore;
1304                 flags |= BANK_ITFLAG_SEENBEFORE;
1305         }
1306         else if( lastSeenAfter ) {
1307                 timeValue = lastSeenAfter;
1308                 flags |= BANK_ITFLAG_SEENAFTER;
1309         }
1310         else {
1311                 timeValue = 0;
1312         }
1313         it = Bank_Iterator(flagMask, flagVal, flags, balValue, timeValue);
1314         
1315         // Get return number
1316         while( (i = Bank_IteratorNext(it)) != -1 )
1317         {
1318                 int bal = Bank_GetBalance(i);
1319                 
1320                 if( bal == INT_MIN )    continue;
1321                 
1322                 if( bal < minBal )      continue;
1323                 if( bal > maxBal )      continue;
1324                 
1325                 numRet ++;
1326         }
1327         
1328         Bank_DelIterator(it);
1329         
1330         // Send count
1331         sendf(Client->Socket, "201 Users %i\n", numRet);
1332         
1333         
1334         // Create iterator
1335         it = Bank_Iterator(flagMask, flagVal, flags, balValue, timeValue);
1336         
1337         while( (i = Bank_IteratorNext(it)) != -1 )
1338         {
1339                 int bal = Bank_GetBalance(i);
1340                 
1341                 if( bal == INT_MIN )    continue;
1342                 
1343                 if( bal < minBal )      continue;
1344                 if( bal > maxBal )      continue;
1345                 
1346                 _SendUserInfo(Client, i);
1347         }
1348         
1349         Bank_DelIterator(it);
1350         
1351         sendf(Client->Socket, "200 List End\n");
1352 }
1353
1354 void Server_Cmd_USERINFO(tClient *Client, char *Args)
1355 {
1356          int    uid;
1357         char    *user;
1358         
1359         // Parse arguments
1360         if( Server_int_ParseArgs(0, Args, &user, NULL) ) {
1361                 sendf(Client->Socket, "407 USER_INFO takes 1 argument\n");
1362                 return ;
1363         }
1364         
1365         if( giDebugLevel )      Debug(Client, "User Info '%s'", user);
1366         
1367         // Get recipient
1368         uid = Bank_GetAcctByName(user, 0);
1369         
1370         if( giDebugLevel >= 2 ) Debug(Client, "uid = %i", uid);
1371         if( uid == -1 ) {
1372                 sendf(Client->Socket, "404 Invalid user\n");
1373                 return ;
1374         }
1375         
1376         _SendUserInfo(Client, uid);
1377 }
1378
1379 void _SendUserInfo(tClient *Client, int UserID)
1380 {
1381         char    *type, *disabled="", *door="";
1382          int    flags = Bank_GetFlags(UserID);
1383         
1384         if( flags & USER_FLAG_INTERNAL ) {
1385                 type = "internal";
1386         }
1387         else if( flags & USER_FLAG_COKE ) {
1388                 if( flags & USER_FLAG_ADMIN )
1389                         type = "coke,admin";
1390                 else
1391                         type = "coke";
1392         }
1393         else if( flags & USER_FLAG_ADMIN ) {
1394                 type = "admin";
1395         }
1396         else {
1397                 type = "user";
1398         }
1399         
1400         if( flags & USER_FLAG_DISABLED )
1401                 disabled = ",disabled";
1402         if( flags & USER_FLAG_DOORGROUP )
1403                 door = ",door";
1404         
1405         // TODO: User flags/type
1406         sendf(
1407                 Client->Socket, "202 User %s %i %s%s%s\n",
1408                 Bank_GetAcctName(UserID), Bank_GetBalance(UserID),
1409                 type, disabled, door
1410                 );
1411 }
1412
1413 void Server_Cmd_USERADD(tClient *Client, char *Args)
1414 {
1415         char    *username;
1416         
1417         // Parse arguments
1418         if( Server_int_ParseArgs(0, Args, &username, NULL) ) {
1419                 sendf(Client->Socket, "407 USER_ADD takes 1 argument\n");
1420                 return ;
1421         }
1422         
1423         // Check authentication
1424         if( !Client->bIsAuthed ) {
1425                 sendf(Client->Socket, "401 Not Authenticated\n");
1426                 return ;
1427         }
1428         
1429         // Check permissions
1430         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) ) {
1431                 sendf(Client->Socket, "403 Not a coke admin\n");
1432                 return ;
1433         }
1434         
1435         // Try to create user
1436         if( Bank_CreateAcct(username) == -1 ) {
1437                 sendf(Client->Socket, "404 User exists\n");
1438                 return ;
1439         }
1440         
1441         {
1442                 char    *thisName = Bank_GetAcctName(Client->UID);
1443                 Log_Info("Account '%s' created by '%s'", username, thisName);
1444                 free(thisName);
1445         }
1446         
1447         sendf(Client->Socket, "200 User Added\n");
1448 }
1449
1450 void Server_Cmd_USERFLAGS(tClient *Client, char *Args)
1451 {
1452         char    *username, *flags, *reason=NULL;
1453          int    mask=0, value=0;
1454          int    uid;
1455         
1456         // Parse arguments
1457         if( Server_int_ParseArgs(1, Args, &username, &flags, &reason, NULL) ) {
1458                 if( !flags ) {
1459                         sendf(Client->Socket, "407 USER_FLAGS takes at least 2 arguments\n");
1460                         return ;
1461                 }
1462                 reason = "";
1463         }
1464         
1465         // Check authentication
1466         if( !Client->bIsAuthed ) {
1467                 sendf(Client->Socket, "401 Not Authenticated\n");
1468                 return ;
1469         }
1470         
1471         // Check permissions
1472         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) ) {
1473                 sendf(Client->Socket, "403 Not a coke admin\n");
1474                 return ;
1475         }
1476         
1477         // Get UID
1478         uid = Bank_GetAcctByName(username, 0);
1479         if( uid == -1 ) {
1480                 sendf(Client->Socket, "404 User '%s' not found\n", username);
1481                 return ;
1482         }
1483         
1484         // Parse flags
1485         if( Server_int_ParseFlags(Client, flags, &mask, &value) )
1486                 return ;
1487         
1488         if( giDebugLevel )
1489                 Debug(Client, "Set %i(%s) flags to %x (masked %x)\n",
1490                         uid, username, mask, value);
1491         
1492         // Apply flags
1493         Bank_SetFlags(uid, mask, value);
1494
1495         // Log the change
1496         Log_Info("Updated '%s' with flag set '%s' by '%s' - Reason: %s",
1497                 username, flags, Client->Username, reason);
1498         
1499         // Return OK
1500         sendf(Client->Socket, "200 User Updated\n");
1501 }
1502
1503 void Server_Cmd_UPDATEITEM(tClient *Client, char *Args)
1504 {
1505         char    *itemname, *price_str, *description;
1506          int    price;
1507         tItem   *item;
1508         
1509         if( Server_int_ParseArgs(1, Args, &itemname, &price_str, &description, NULL) ) {
1510                 sendf(Client->Socket, "407 UPDATE_ITEM takes 3 arguments\n");
1511                 return ;
1512         }
1513         
1514         if( !Client->bIsAuthed ) {
1515                 sendf(Client->Socket, "401 Not Authenticated\n");
1516                 return ;
1517         }
1518
1519         // Check user permissions
1520         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1521                 sendf(Client->Socket, "403 Not in coke\n");
1522                 return ;
1523         }
1524         
1525         item = _GetItemFromString(itemname);
1526         if( !item ) {
1527                 // TODO: Create item?
1528                 sendf(Client->Socket, "406 Bad Item ID\n");
1529                 return ;
1530         }
1531         
1532         price = atoi(price_str);
1533         if( price <= 0 && price_str[0] != '0' ) {
1534                 sendf(Client->Socket, "407 Invalid price set\n");
1535         }
1536         
1537         switch( DispenseUpdateItem( Client->UID, item, description, price ) )
1538         {
1539         case 0:
1540                 // Return OK
1541                 sendf(Client->Socket, "200 Item updated\n");
1542                 break;
1543         default:
1544                 break;
1545         }
1546 }
1547
1548 void Server_Cmd_PINCHECK(tClient *Client, char *Args)
1549 {
1550         char    *username, *pinstr;
1551          int    pin;
1552
1553         if( Server_int_ParseArgs(0, Args, &username, &pinstr, NULL) ) {
1554                 sendf(Client->Socket, "407 PIN_CHECK takes 2 arguments\n");
1555                 return ;
1556         }
1557         
1558         if( !isdigit(pinstr[0]) || !isdigit(pinstr[1]) || !isdigit(pinstr[2]) || !isdigit(pinstr[3]) || pinstr[4] != '\0' ) {
1559                 sendf(Client->Socket, "407 PIN should be four digits\n");
1560                 return ;
1561         }
1562         pin = atoi(pinstr);
1563
1564         // Not authenticated? go away!
1565         if( !Client->bIsAuthed ) {
1566                 sendf(Client->Socket, "401 Not Authenticated\n");
1567                 return ;
1568         }
1569         
1570         // Get user
1571         int uid = Bank_GetAcctByName(username, 0);
1572         if( uid == -1 ) {
1573                 sendf(Client->Socket, "404 User '%s' not found\n", username);
1574                 return ;
1575         }
1576         
1577         // Check user permissions
1578         if( uid != Client->UID && !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1579                 sendf(Client->Socket, "403 Not in coke\n");
1580                 return ;
1581         }
1582         
1583         // Get the pin
1584         static time_t   last_wrong_pin_time;
1585         static int      backoff = 1;
1586         if( time(NULL) - last_wrong_pin_time < backoff ) {
1587                 sendf(Client->Socket, "407 Rate limited (%i seconds remaining)\n",
1588                         backoff - (time(NULL) - last_wrong_pin_time));
1589                 return ;
1590         }       
1591         last_wrong_pin_time = time(NULL);
1592         if( !Bank_IsPinValid(uid, pin) )
1593         {
1594                 sendf(Client->Socket, "201 Pin incorrect\n");
1595                 struct sockaddr_storage addr;
1596                 socklen_t len = sizeof(addr);
1597                 char ipstr[INET6_ADDRSTRLEN];
1598                 getpeername(Client->Socket, (void*)&addr, &len);
1599                 struct sockaddr_in *s = (struct sockaddr_in *)&addr;
1600                 inet_ntop(addr.ss_family, &s->sin_addr, ipstr, sizeof(ipstr));
1601                 Debug_Notice("Bad pin from %s for %s by %i", ipstr, username, Client->UID);
1602                 if( backoff < 5)
1603                         backoff ++;
1604                 return ;
1605         }
1606
1607         last_wrong_pin_time = 0;
1608         backoff = 1;
1609         sendf(Client->Socket, "200 Pin correct\n");
1610         return ;
1611 }
1612 void Server_Cmd_PINSET(tClient *Client, char *Args)
1613 {
1614         char    *pinstr;
1615          int    pin;
1616         
1617
1618         if( Server_int_ParseArgs(0, Args, &pinstr, NULL) ) {
1619                 sendf(Client->Socket, "407 PIN_SET takes 1 argument\n");
1620                 return ;
1621         }
1622         
1623         if( !isdigit(pinstr[0]) || !isdigit(pinstr[1]) || !isdigit(pinstr[2]) || !isdigit(pinstr[3]) || pinstr[4] != '\0' ) {
1624                 sendf(Client->Socket, "407 PIN should be four digits\n");
1625                 return ;
1626         }
1627         pin = atoi(pinstr);
1628
1629         if( !Client->bIsAuthed ) {
1630                 sendf(Client->Socket, "401 Not Authenticated\n");
1631                 return ;
1632         }
1633         
1634         int uid = Client->EffectiveUID;
1635         if(uid == -1)
1636                 uid = Client->UID;
1637         // Can only pinset yourself (well, the effective user)
1638         Bank_SetPin(uid, pin);
1639         sendf(Client->Socket, "200 Pin updated\n");
1640         return ;
1641 }
1642
1643 // --- INTERNAL HELPERS ---
1644 void Debug(tClient *Client, const char *Format, ...)
1645 {
1646         va_list args;
1647         //printf("%010i [%i] ", (int)time(NULL), Client->ID);
1648         printf("[%i] ", Client->ID);
1649         va_start(args, Format);
1650         vprintf(Format, args);
1651         va_end(args);
1652         printf("\n");
1653 }
1654
1655 int sendf(int Socket, const char *Format, ...)
1656 {
1657         va_list args;
1658          int    len;
1659         
1660         va_start(args, Format);
1661         len = vsnprintf(NULL, 0, Format, args);
1662         va_end(args);
1663         
1664         {
1665                 char    buf[len+1];
1666                 va_start(args, Format);
1667                 vsnprintf(buf, len+1, Format, args);
1668                 va_end(args);
1669                 
1670                 #if DEBUG_TRACE_CLIENT
1671                 printf("sendf: %s", buf);
1672                 #endif
1673                 
1674                 return send(Socket, buf, len, 0);
1675         }
1676 }
1677
1678 // Takes a series of char *'s in
1679 /**
1680  * \brief Parse space-separated entries into 
1681  */
1682 int Server_int_ParseArgs(int bUseLongLast, char *ArgStr, ...)
1683 {
1684         va_list args;
1685         char    savedChar;
1686         char    **dest;
1687         va_start(args, ArgStr);
1688
1689         // Check for null
1690         if( !ArgStr )
1691         {
1692                 while( (dest = va_arg(args, char **)) )
1693                         *dest = NULL;
1694                 va_end(args);
1695                 return 1;
1696         }
1697
1698         savedChar = *ArgStr;
1699         
1700         while( (dest = va_arg(args, char **)) )
1701         {
1702                 // Trim leading spaces
1703                 while( *ArgStr == ' ' || *ArgStr == '\t' )
1704                         ArgStr ++;
1705                 
1706                 // ... oops, not enough arguments
1707                 if( *ArgStr == '\0' )
1708                 {
1709                         // NULL unset arguments
1710                         do {
1711                                 *dest = NULL;
1712                         }       while( (dest = va_arg(args, char **)) );
1713                 va_end(args);
1714                         return -1;
1715                 }
1716                 
1717                 if( *ArgStr == '"' )
1718                 {
1719                         ArgStr ++;
1720                         *dest = ArgStr;
1721                         // Read until quote
1722                         while( *ArgStr && *ArgStr != '"' )
1723                                 ArgStr ++;
1724                 }
1725                 else
1726                 {
1727                         // Set destination
1728                         *dest = ArgStr;
1729                         // Read until a space
1730                         while( *ArgStr && *ArgStr != ' ' && *ArgStr != '\t' )
1731                                 ArgStr ++;
1732                 }
1733                 savedChar = *ArgStr;    // savedChar is used to un-mangle the last string
1734                 *ArgStr = '\0';
1735                 ArgStr ++;
1736         }
1737         va_end(args);
1738         
1739         // Oops, extra arguments, and greedy not set
1740         if( (savedChar == ' ' || savedChar == '\t') && !bUseLongLast ) {
1741                 return -1;
1742         }
1743         
1744         // Un-mangle last
1745         if(bUseLongLast) {
1746                 ArgStr --;
1747                 *ArgStr = savedChar;
1748         }
1749         
1750         return 0;       // Success!
1751 }
1752
1753 int Server_int_ParseFlags(tClient *Client, const char *Str, int *Mask, int *Value)
1754 {
1755         struct {
1756                 const char      *Name;
1757                  int    Mask;
1758                  int    Value;
1759         }       cFLAGS[] = {
1760                  {"disabled", USER_FLAG_DISABLED, USER_FLAG_DISABLED}
1761                 ,{"door", USER_FLAG_DOORGROUP, USER_FLAG_DOORGROUP}
1762                 ,{"coke", USER_FLAG_COKE, USER_FLAG_COKE}
1763                 ,{"admin", USER_FLAG_ADMIN, USER_FLAG_ADMIN}
1764                 ,{"internal", USER_FLAG_INTERNAL, USER_FLAG_INTERNAL}
1765         };
1766         const int       ciNumFlags = sizeof(cFLAGS)/sizeof(cFLAGS[0]);
1767         
1768         char    *space;
1769         
1770         *Mask = 0;
1771         *Value = 0;
1772         
1773         do {
1774                  int    bRemove = 0;
1775                  int    i;
1776                  int    len;
1777                 
1778                 while( *Str == ' ' )    Str ++; // Eat whitespace
1779                 space = strchr(Str, ',');       // Find the end of the flag
1780                 if(space)
1781                         len = space - Str;
1782                 else
1783                         len = strlen(Str);
1784                 
1785                 // Check for inversion/removal
1786                 if( *Str == '!' || *Str == '-' ) {
1787                         bRemove = 1;
1788                         Str ++;
1789                 }
1790                 else if( *Str == '+' ) {
1791                         Str ++;
1792                 }
1793                 
1794                 // Check flag values
1795                 for( i = 0; i < ciNumFlags; i ++ )
1796                 {
1797                         if( strncmp(Str, cFLAGS[i].Name, len) == 0 ) {
1798                                 *Mask |= cFLAGS[i].Mask;
1799                                 *Value &= ~cFLAGS[i].Mask;
1800                                 if( !bRemove )
1801                                         *Value |= cFLAGS[i].Value;
1802                                 break;
1803                         }
1804                 }
1805                 
1806                 // Error check
1807                 if( i == ciNumFlags ) {
1808                         char    val[len+1];
1809                         strncpy(val, Str, len+1);
1810                         sendf(Client->Socket, "407 Unknown flag value '%s'\n", val);
1811                         return -1;
1812                 }
1813                 
1814                 Str = space + 1;
1815         } while(space);
1816         
1817         return 0;
1818 }
1819

UCC git Repository :: git.ucc.asn.au