Pin checks and disabled account behavior
[tpg/opendispense2.git] / src / server / server.c
1 /*
2  * OpenDispense 2 
3  * UCC (University [of WA] Computer Club) Electronic Accounting System
4  *
5  * server.c - Client Server Code
6  *
7  * This file is licenced under the 3-clause BSD Licence. See the file
8  * COPYING for full details.
9  */
10 #include <stdio.h>
11 #include <stdlib.h>
12 #include "common.h"
13 #include <sys/socket.h>
14 #include <netinet/in.h>
15 #include <arpa/inet.h>
16 #include <unistd.h>
17 #include <fcntl.h>      // O_*
18 #include <string.h>
19 #include <limits.h>
20 #include <stdarg.h>
21 #include <signal.h>     // Signal handling
22 #include <ident.h>      // AUTHIDENT
23 #include <time.h>       // time(2)
24 #include <ctype.h>
25
26 #define DEBUG_TRACE_CLIENT      0
27 #define HACK_NO_REFUNDS 1
28
29 #define PIDFILE "/var/run/dispsrv.pid"
30
31 // Statistics
32 #define MAX_CONNECTION_QUEUE    5
33 #define INPUT_BUFFER_SIZE       256
34 #define CLIENT_TIMEOUT  10      // Seconds
35
36 #define HASH_TYPE       SHA1
37 #define HASH_LENGTH     20
38
39 #define MSG_STR_TOO_LONG        "499 Command too long (limit "EXPSTR(INPUT_BUFFER_SIZE)")\n"
40
41 #define IDENT_TRUSTED_NETWORK 0x825F0D00
42 #define IDENT_TRUSTED_NETMASK 0xFFFFFFC0
43
44 // === TYPES ===
45 typedef struct sClient
46 {
47          int    Socket; // Client socket ID
48          int    ID;     // Client ID
49          
50          int    bTrustedHost;
51          int    bCanAutoAuth;   // Is the connection from a trusted host/port
52         
53         char    *Username;
54         char    Salt[9];
55         
56          int    UID;
57          int    EffectiveUID;
58          int    bIsAuthed;
59 }       tClient;
60
61 // === PROTOTYPES ===
62 void    Server_Start(void);
63 void    Server_Cleanup(void);
64 void    Server_HandleClient(int Socket, int bTrustedHost, int bRootPort);
65 void    Server_ParseClientCommand(tClient *Client, char *CommandString);
66 // --- Commands ---
67 void    Server_Cmd_USER(tClient *Client, char *Args);
68 void    Server_Cmd_PASS(tClient *Client, char *Args);
69 void    Server_Cmd_AUTOAUTH(tClient *Client, char *Args);
70 void    Server_Cmd_AUTHIDENT(tClient *Client, char *Args);
71 void    Server_Cmd_SETEUSER(tClient *Client, char *Args);
72 void    Server_Cmd_ENUMITEMS(tClient *Client, char *Args);
73 void    Server_Cmd_ITEMINFO(tClient *Client, char *Args);
74 void    Server_Cmd_DISPENSE(tClient *Client, char *Args);
75 void    Server_Cmd_REFUND(tClient *Client, char *Args);
76 void    Server_Cmd_GIVE(tClient *Client, char *Args);
77 void    Server_Cmd_DONATE(tClient *Client, char *Args);
78 void    Server_Cmd_ADD(tClient *Client, char *Args);
79 void    Server_Cmd_SET(tClient *Client, char *Args);
80 void    Server_Cmd_ENUMUSERS(tClient *Client, char *Args);
81 void    Server_Cmd_USERINFO(tClient *Client, char *Args);
82 void    _SendUserInfo(tClient *Client, int UserID);
83 void    Server_Cmd_USERADD(tClient *Client, char *Args);
84 void    Server_Cmd_USERFLAGS(tClient *Client, char *Args);
85 void    Server_Cmd_UPDATEITEM(tClient *Client, char *Args);
86 void    Server_Cmd_PINCHECK(tClient *Client, char *Args);
87 void    Server_Cmd_PINSET(tClient *Client, char *Args);
88 // --- Helpers ---
89 void    Debug(tClient *Client, const char *Format, ...);
90  int    sendf(int Socket, const char *Format, ...);
91  int    Server_int_ParseArgs(int bUseLongArg, char *ArgStr, ...);
92  int    Server_int_ParseFlags(tClient *Client, const char *Str, int *Mask, int *Value);
93
94 // === CONSTANTS ===
95 // - Commands
96 const struct sClientCommand {
97         const char      *Name;
98         void    (*Function)(tClient *Client, char *Arguments);
99 }       gaServer_Commands[] = {
100         {"USER", Server_Cmd_USER},
101         {"PASS", Server_Cmd_PASS},
102         {"AUTOAUTH", Server_Cmd_AUTOAUTH},
103         {"AUTHIDENT", Server_Cmd_AUTHIDENT},
104         {"SETEUSER", Server_Cmd_SETEUSER},
105         {"ENUM_ITEMS", Server_Cmd_ENUMITEMS},
106         {"ITEM_INFO", Server_Cmd_ITEMINFO},
107         {"DISPENSE", Server_Cmd_DISPENSE},
108         {"REFUND", Server_Cmd_REFUND},
109         {"GIVE", Server_Cmd_GIVE},
110         {"DONATE", Server_Cmd_DONATE},
111         {"ADD", Server_Cmd_ADD},
112         {"SET", Server_Cmd_SET},
113         {"ENUM_USERS", Server_Cmd_ENUMUSERS},
114         {"USER_INFO", Server_Cmd_USERINFO},
115         {"USER_ADD", Server_Cmd_USERADD},
116         {"USER_FLAGS", Server_Cmd_USERFLAGS},
117         {"UPDATE_ITEM", Server_Cmd_UPDATEITEM},
118         {"PIN_CHECK", Server_Cmd_PINCHECK},
119         {"PIN_SET", Server_Cmd_PINSET}
120 };
121 #define NUM_COMMANDS    ((int)(sizeof(gaServer_Commands)/sizeof(gaServer_Commands[0])))
122
123 // === GLOBALS ===
124 // - Configuration
125  int    giServer_Port = 11020;
126  int    gbServer_RunInBackground = 0;
127 char    *gsServer_LogFile = "/var/log/dispsrv.log";
128 char    *gsServer_ErrorLog = "/var/log/dispsrv.err";
129  int    giServer_NumTrustedHosts;
130 struct in_addr  *gaServer_TrustedHosts;
131 // - State variables
132  int    giServer_Socket;        // Server socket
133  int    giServer_NextClientID = 1;      // Debug client ID
134  
135
136 // === CODE ===
137 /**
138  * \brief Open listenting socket and serve connections
139  */
140 void Server_Start(void)
141 {
142          int    client_socket;
143         struct sockaddr_in      server_addr, client_addr;
144
145         // Parse trusted hosts list
146         giServer_NumTrustedHosts = Config_GetValueCount("trusted_host");
147         gaServer_TrustedHosts = malloc(giServer_NumTrustedHosts * sizeof(*gaServer_TrustedHosts));
148         for( int i = 0; i < giServer_NumTrustedHosts; i ++ )
149         {
150                 const char      *addr = Config_GetValue("trusted_host", i);
151                 
152                 if( inet_aton(addr, &gaServer_TrustedHosts[i]) == 0 ) {
153                         fprintf(stderr, "Invalid IP address '%s'\n", addr);
154                         continue ;
155                 }
156         }
157
158         atexit(Server_Cleanup);
159         // Ignore SIGPIPE (stops crashes when the client exits early)
160         signal(SIGPIPE, SIG_IGN);
161
162         // Create Server
163         giServer_Socket = socket(PF_INET, SOCK_STREAM, IPPROTO_TCP);
164         if( giServer_Socket < 0 ) {
165                 fprintf(stderr, "ERROR: Unable to create server socket\n");
166                 return ;
167         }
168         
169         // Make listen address
170         memset(&server_addr, 0, sizeof(server_addr));
171         server_addr.sin_family = AF_INET;       // Internet Socket
172         server_addr.sin_addr.s_addr = htonl(INADDR_ANY);        // Listen on all interfaces
173         server_addr.sin_port = htons(giServer_Port);    // Port
174
175         // Bind
176         if( bind(giServer_Socket, (struct sockaddr *) &server_addr, sizeof(server_addr)) < 0 ) {
177                 fprintf(stderr, "ERROR: Unable to bind to 0.0.0.0:%i\n", giServer_Port);
178                 perror("Binding");
179                 return ;
180         }
181
182         // Fork into background
183         if( gbServer_RunInBackground )
184         {
185                 int pid = fork();
186                 if( pid == -1 ) {
187                         fprintf(stderr, "ERROR: Unable to fork\n");
188                         perror("fork background");
189                         exit(-1);
190                 }
191                 if( pid != 0 ) {
192                         // Parent, quit
193                         printf("Forked child %i\n", pid);
194                         exit(0);
195                 }
196                 // In child
197                 // - Sort out stdin/stdout
198                 #if 0
199                 dup2( open("/dev/null", O_RDONLY, 0644), STDIN_FILENO );
200                 dup2( open(gsServer_LogFile, O_CREAT|O_APPEND, 0644), STDOUT_FILENO );
201                 dup2( open(gsServer_ErrorLog, O_CREAT|O_APPEND, 0644), STDERR_FILENO );
202                 #else
203                 freopen("/dev/null", "r", stdin);
204                 freopen(gsServer_LogFile, "a", stdout);
205                 freopen(gsServer_ErrorLog, "a", stderr);
206                 fprintf(stdout, "OpenDispense 2 Server Started at %lld\n", (long long)time(NULL));
207                 fprintf(stderr, "OpenDispense 2 Server Started at %lld\n", (long long)time(NULL));
208                 #endif
209         }
210
211         // Start the helper thread
212         StartPeriodicThread();
213         
214         // Listen
215         if( listen(giServer_Socket, MAX_CONNECTION_QUEUE) < 0 ) {
216                 fprintf(stderr, "ERROR: Unable to listen to socket\n");
217                 perror("Listen");
218                 return ;
219         }
220         
221         printf("Listening on 0.0.0.0:%i\n", giServer_Port);
222         
223         // write pidfile
224         {
225                 FILE *fp = fopen(PIDFILE, "w");
226                 if( fp ) {
227                         fprintf(fp, "%i", getpid());
228                         fclose(fp);
229                 }
230         }
231
232         for(;;)
233         {
234                 uint    len = sizeof(client_addr);
235                  int    bTrusted = 0;
236                  int    bRootPort = 0;
237                 
238                 // Accept a connection
239                 client_socket = accept(giServer_Socket, (struct sockaddr *) &client_addr, &len);
240                 if(client_socket < 0) {
241                         fprintf(stderr, "ERROR: Unable to accept client connection\n");
242                         return ;
243                 }
244                 
245                 // Set a timeout on the user conneciton
246                 {
247                         struct timeval tv;
248                         tv.tv_sec = CLIENT_TIMEOUT;
249                         tv.tv_usec = 0;
250                         if( setsockopt(client_socket, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv)) )
251                         {
252                                 perror("setsockopt");
253                                 return ;
254                         }
255                 }
256                 
257                 // Debug: Print the connection string
258                 if(giDebugLevel >= 2) {
259                         char    ipstr[INET_ADDRSTRLEN];
260                         inet_ntop(AF_INET, &client_addr.sin_addr, ipstr, INET_ADDRSTRLEN);
261                         printf("Client connection from %s:%i\n",
262                                 ipstr, ntohs(client_addr.sin_port));
263                 }
264                 
265                 // Doesn't matter what, localhost is trusted
266                 if( ntohl( client_addr.sin_addr.s_addr ) == 0x7F000001 )
267                         bTrusted = 1;
268         
269                 // Check if the host is on the trusted list     
270                 for( int i = 0; i < giServer_NumTrustedHosts; i ++ )
271                 {
272                         if( memcmp(&client_addr.sin_addr, &gaServer_TrustedHosts[i], sizeof(struct in_addr)) == 0 )
273                         {
274                                 bTrusted = 1;
275                                 break;
276                         }
277                 }
278
279                 // Root port (can AUTOAUTH if also a trusted machine
280                 if( ntohs(client_addr.sin_port) < 1024 )
281                         bRootPort = 1;
282                 
283                 #if 0
284                 {
285                         // TODO: Make this runtime configurable
286                         switch( ntohl( client_addr.sin_addr.s_addr ) )
287                         {
288                         case 0x7F000001:        // 127.0.0.1    localhost
289                 //      case 0x825F0D00:        // 130.95.13.0
290                         case 0x825F0D04:        // 130.95.13.4  merlo
291                 //      case 0x825F0D05:        // 130.95.13.5  heathred (MR)
292                         case 0x825F0D07:        // 130.95.13.7  motsugo
293                         case 0x825F0D11:        // 130.95.13.17 mermaid
294                         case 0x825F0D12:        // 130.95.13.18 mussel
295                         case 0x825F0D17:        // 130.95.13.23 martello
296                         case 0x825F0D2A:        // 130.95.13.42 meersau
297                 //      case 0x825F0D42:        // 130.95.13.66 heathred (Clubroom)
298                                 bTrusted = 1;
299                                 break;
300                         default:
301                                 break;
302                         }
303                 }
304                 #endif
305                 
306                 // TODO: Multithread this?
307                 Server_HandleClient(client_socket, bTrusted, bRootPort);
308                 
309                 close(client_socket);
310         }
311 }
312
313 void Server_Cleanup(void)
314 {
315         printf("\nClose(%i)\n", giServer_Socket);
316         close(giServer_Socket);
317         unlink(PIDFILE);
318 }
319
320 /**
321  * \brief Reads from a client socket and parses the command strings
322  * \param Socket        Client socket number/handle
323  * \param bTrusted      Is the client trusted?
324  */
325 void Server_HandleClient(int Socket, int bTrusted, int bRootPort)
326 {
327         char    inbuf[INPUT_BUFFER_SIZE];
328         char    *buf = inbuf;
329          int    remspace = INPUT_BUFFER_SIZE-1;
330          int    bytes = -1;
331         tClient clientInfo;
332         
333         memset(&clientInfo, 0, sizeof(clientInfo));
334         
335         // Initialise Client info
336         clientInfo.Socket = Socket;
337         clientInfo.ID = giServer_NextClientID ++;
338         clientInfo.bTrustedHost = bTrusted;
339         clientInfo.bCanAutoAuth = bTrusted && bRootPort;
340         clientInfo.EffectiveUID = -1;
341         
342         // Read from client
343         /*
344          * Notes:
345          * - The `buf` and `remspace` variables allow a line to span several
346          *   calls to recv(), if a line is not completed in one recv() call
347          *   it is saved to the beginning of `inbuf` and `buf` is updated to
348          *   the end of it.
349          */
350         // TODO: Use select() instead (to give a timeout)
351         while( (bytes = recv(Socket, buf, remspace, 0)) > 0 )
352         {
353                 char    *eol, *start;
354                 buf[bytes] = '\0';      // Allow us to use stdlib string functions on it
355                 
356                 // Split by lines
357                 start = inbuf;
358                 while( (eol = strchr(start, '\n')) )
359                 {
360                         *eol = '\0';
361                         
362                         Server_ParseClientCommand(&clientInfo, start);
363                         
364                         start = eol + 1;
365                 }
366                 
367                 // Check if there was an incomplete line
368                 if( *start != '\0' ) {
369                          int    tailBytes = bytes - (start-buf);
370                         // Roll back in buffer
371                         memcpy(inbuf, start, tailBytes);
372                         remspace -= tailBytes;
373                         if(remspace == 0) {
374                                 send(Socket, MSG_STR_TOO_LONG, sizeof(MSG_STR_TOO_LONG), 0);
375                                 buf = inbuf;
376                                 remspace = INPUT_BUFFER_SIZE - 1;
377                         }
378                 }
379                 else {
380                         buf = inbuf;
381                         remspace = INPUT_BUFFER_SIZE - 1;
382                 }
383         }
384         
385         // Check for errors
386         if( bytes < 0 ) {
387                 fprintf(stderr, "ERROR: Unable to recieve from client on socket %i\n", Socket);
388                 return ;
389         }
390         
391         if(giDebugLevel >= 2) {
392                 printf("Client %i: Disconnected\n", clientInfo.ID);
393         }
394 }
395
396 /**
397  * \brief Parses a client command and calls the required helper function
398  * \param Client        Pointer to client state structure
399  * \param CommandString Command from client (single line of the command)
400  * \return Heap String to return to the client
401  */
402 void Server_ParseClientCommand(tClient *Client, char *CommandString)
403 {
404         char    *command, *args;
405          int    i;
406         
407         if( giDebugLevel >= 2 )
408                 Debug(Client, "Server_ParseClientCommand: (CommandString = '%s')", CommandString);
409         
410         if( Server_int_ParseArgs(1, CommandString, &command, &args, NULL) )
411         {
412                 if( command == NULL )   return ;
413                 // Is this an error? (just ignore for now)
414         }
415         
416         
417         // Find command
418         for( i = 0; i < NUM_COMMANDS; i++ )
419         {
420                 if(strcmp(command, gaServer_Commands[i].Name) == 0) {
421                         if( giDebugLevel >= 2 )
422                                 Debug(Client, "CMD %s - \"%s\"", command, args);
423                         gaServer_Commands[i].Function(Client, args);
424                         return ;
425                 }
426         }
427         
428         sendf(Client->Socket, "400 Unknown Command\n");
429 }
430
431 // ---
432 // Commands
433 // ---
434 /**
435  * \brief Set client username
436  * 
437  * Usage: USER <username>
438  */
439 void Server_Cmd_USER(tClient *Client, char *Args)
440 {
441         char    *username;
442         
443         if( Server_int_ParseArgs(0, Args, &username, NULL) )
444         {
445                 sendf(Client->Socket, "407 USER takes 1 argument\n");
446                 return ;
447         }
448         
449         // Debug!
450         if( giDebugLevel )
451                 Debug(Client, "Authenticating as '%s'", username);
452         
453         // Save username
454         if(Client->Username)
455                 free(Client->Username);
456         Client->Username = strdup(username);
457         
458         #if USE_SALT
459         // Create a salt (that changes if the username is changed)
460         // Yes, I know, I'm a little paranoid, but who isn't?
461         Client->Salt[0] = 0x21 + (rand()&0x3F);
462         Client->Salt[1] = 0x21 + (rand()&0x3F);
463         Client->Salt[2] = 0x21 + (rand()&0x3F);
464         Client->Salt[3] = 0x21 + (rand()&0x3F);
465         Client->Salt[4] = 0x21 + (rand()&0x3F);
466         Client->Salt[5] = 0x21 + (rand()&0x3F);
467         Client->Salt[6] = 0x21 + (rand()&0x3F);
468         Client->Salt[7] = 0x21 + (rand()&0x3F);
469         
470         // TODO: Also send hash type to use, (SHA1 or crypt according to [DAA])
471         sendf(Client->Socket, "100 SALT %s\n", Client->Salt);
472         #else
473         sendf(Client->Socket, "100 User Set\n");
474         #endif
475 }
476
477 /**
478  * \brief Authenticate as a user
479  * 
480  * Usage: PASS <hash>
481  */
482 void Server_Cmd_PASS(tClient *Client, char *Args)
483 {
484         char    *passhash;
485          int    flags;
486
487         if( Server_int_ParseArgs(0, Args, &passhash, NULL) )
488         {
489                 sendf(Client->Socket, "407 PASS takes 1 argument\n");
490                 return ;
491         }
492         
493         // Pass on to cokebank
494         Client->UID = Bank_GetUserAuth(Client->Salt, Client->Username, passhash);
495
496         if( Client->UID == -1 ) {
497                 sendf(Client->Socket, "401 Auth Failure\n");
498                 return ;
499         }
500
501         flags = Bank_GetFlags(Client->UID);
502         if( flags & USER_FLAG_DISABLED ) {
503                 Client->UID = -1;
504                 sendf(Client->Socket, "403 Account Disabled\n");
505                 return ;
506         }
507         if( flags & USER_FLAG_INTERNAL ) {
508                 Client->UID = -1;
509                 sendf(Client->Socket, "403 Internal account\n");
510                 return ;
511         }
512         
513         Client->bIsAuthed = 1;
514         sendf(Client->Socket, "200 Auth OK\n");
515 }
516
517 /**
518  * \brief Authenticate as a user without a password
519  * 
520  * Usage: AUTOAUTH <user>
521  */
522 void Server_Cmd_AUTOAUTH(tClient *Client, char *Args)
523 {
524         char    *username;
525          int    userflags;
526         
527         if( Server_int_ParseArgs(0, Args, &username, NULL) )
528         {
529                 sendf(Client->Socket, "407 AUTOAUTH takes 1 argument\n");
530                 return ;
531         }
532         
533         // Check if trusted
534         if( !Client->bCanAutoAuth ) {
535                 if(giDebugLevel)
536                         Debug(Client, "Untrusted client attempting to AUTOAUTH");
537                 sendf(Client->Socket, "401 Untrusted\n");
538                 return ;
539         }
540         
541         // Get UID
542         Client->UID = Bank_GetAcctByName( username, 0 );        
543         if( Client->UID < 0 ) {
544                 if(giDebugLevel)
545                         Debug(Client, "Unknown user '%s'", username);
546                 sendf(Client->Socket, "403 Auth Failure\n");
547                 return ;
548         }
549         
550         userflags = Bank_GetFlags(Client->UID);
551         // You can't be an internal account
552         if( userflags & USER_FLAG_INTERNAL ) {
553                 if(giDebugLevel)
554                         Debug(Client, "Autoauth as '%s', not allowed", username);
555                 Client->UID = -1;
556                 sendf(Client->Socket, "403 Account is internal\n");
557                 return ;
558         }
559
560         // Disabled accounts
561         if( userflags & USER_FLAG_DISABLED ) {
562                 Client->UID = -1;
563                 sendf(Client->Socket, "403 Account disabled\n");
564                 return ;
565         }
566
567         // Save username
568         if(Client->Username)
569                 free(Client->Username);
570         Client->Username = strdup(username);
571
572         Client->bIsAuthed = 1;
573         
574         if(giDebugLevel)
575                 Debug(Client, "Auto authenticated as '%s' (%i)", username, Client->UID);
576         
577         sendf(Client->Socket, "200 Auth OK\n");
578 }
579
580 /**
581  * \brief Authenticate as a user using the IDENT protocol
582  *
583  * Usage: AUTHIDENT
584  */
585 void Server_Cmd_AUTHIDENT(tClient *Client, char *Args)
586 {
587         char    *username;
588          int    userflags;
589         const int ident_timeout = 5;
590
591         if( Args != NULL && strlen(Args) ) {
592                 sendf(Client->Socket, "407 AUTHIDENT takes no arguments\n");
593                 return ;
594         }
595
596         // Check if trusted
597         if( !Client->bTrustedHost ) {
598                 if(giDebugLevel)
599                         Debug(Client, "Untrusted client attempting to AUTHIDENT");
600                 sendf(Client->Socket, "401 Untrusted\n");
601                 return ;
602         }
603
604         // Get username via IDENT
605         username = ident_id(Client->Socket, ident_timeout);
606         if( !username ) {
607                 perror("AUTHIDENT - IDENT timed out");
608                 sendf(Client->Socket, "403 Authentication failure: IDENT auth timed out\n");
609                 return ;
610         }
611
612         // Get UID
613         Client->UID = Bank_GetAcctByName( username, 0 );
614         if( Client->UID < 0 ) {
615                 if(giDebugLevel)
616                         Debug(Client, "Unknown user '%s'", username);
617                 sendf(Client->Socket, "403 Authentication failure: unknown account\n");
618                 free(username);
619                 return ;
620         }
621
622         userflags = Bank_GetFlags(Client->UID);
623         // You can't be an internal account
624         if( userflags & USER_FLAG_INTERNAL ) {
625                 if(giDebugLevel)
626                         Debug(Client, "IDENT auth as '%s', not allowed", username);
627                 Client->UID = -1;
628                 sendf(Client->Socket, "403 Authentication failure: that account is internal\n");
629                 free(username);
630                 return ;
631         }
632
633         // Disabled accounts
634         if( userflags & USER_FLAG_DISABLED ) {
635                 Client->UID = -1;
636                 sendf(Client->Socket, "403 Authentication failure: account disabled\n");
637                 free(username);
638                 return ;
639         }
640
641         // Save username
642         if(Client->Username)
643                 free(Client->Username);
644         Client->Username = strdup(username);
645
646         Client->bIsAuthed = 1;
647
648         if(giDebugLevel)
649                 Debug(Client, "IDENT authenticated as '%s' (%i)", username, Client->UID);
650         free(username);
651
652         sendf(Client->Socket, "200 Auth OK\n");
653 }
654
655 /**
656  * \brief Set effective user
657  */
658 void Server_Cmd_SETEUSER(tClient *Client, char *Args)
659 {
660         char    *username;
661          int    eUserFlags, userFlags;
662         
663         if( Server_int_ParseArgs(0, Args, &username, NULL) )
664         {
665                 sendf(Client->Socket, "407 SETEUSER takes 1 argument\n");
666                 return ;
667         }
668         
669         if( !strlen(Args) ) {
670                 sendf(Client->Socket, "407 SETEUSER expects an argument\n");
671                 return ;
672         }
673         
674         // Check authentication
675         if( !Client->bIsAuthed ) {
676                 sendf(Client->Socket, "401 Not Authenticated\n");
677                 return ;
678         }
679
680         // Check user permissions
681         userFlags = Bank_GetFlags(Client->UID);
682         if( !(userFlags & (USER_FLAG_COKE|USER_FLAG_ADMIN)) ) {
683                 sendf(Client->Socket, "403 Not in coke\n");
684                 return ;
685         }
686         
687         // Set id
688         Client->EffectiveUID = Bank_GetAcctByName(username, 0);
689         if( Client->EffectiveUID == -1 ) {
690                 sendf(Client->Socket, "404 User not found\n");
691                 return ;
692         }
693         // You can't be an internal account (unless you're an admin)
694         if( !(userFlags & USER_FLAG_ADMIN) )
695         {
696                 eUserFlags = Bank_GetFlags(Client->EffectiveUID);
697                 if( eUserFlags & USER_FLAG_INTERNAL ) {
698                         Client->EffectiveUID = -1;
699                         sendf(Client->Socket, "404 User not found\n");
700                         return ;
701                 }
702         }
703
704         // Disabled accounts
705         // - If disabled and the actual user is not an admin (and not root)
706         //   return 403
707         if( (eUserFlags & USER_FLAG_DISABLED) && (Client->UID == 0 || !(userFlags & USER_FLAG_ADMIN)) ) {
708                 Client->EffectiveUID = -1;
709                 sendf(Client->Socket, "403 Account disabled\n");
710                 return ;
711         }
712         
713         sendf(Client->Socket, "200 User set\n");
714 }
715
716 /**
717  * \brief Send an item status to the client
718  * \param Client        Who to?
719  * \param Item  Item to send
720  */
721 void Server_int_SendItem(tClient *Client, tItem *Item)
722 {
723         char    *status = "avail";
724         
725         if( Item->Handler->CanDispense )
726         {
727                 switch(Item->Handler->CanDispense(Client->UID, Item->ID))
728                 {
729                 case  0:        status = "avail";       break;
730                 case  1:        status = "sold";        break;
731                 default:
732                 case -1:        status = "error";       break;
733                 }
734         }
735         
736         if( !gbNoCostMode && Item->Price == 0 )
737                 status = "error";
738         // KNOWN HACK: Naming a slot 'dead' disables it
739         if( strcmp(Item->Name, "dead") == 0 )
740                 status = "sold";        // Another status?
741         
742         sendf(Client->Socket,
743                 "202 Item %s:%i %s %i %s\n",
744                 Item->Handler->Name, Item->ID, status, Item->Price, Item->Name
745                 );
746 }
747
748 /**
749  * \brief Enumerate the items that the server knows about
750  */
751 void Server_Cmd_ENUMITEMS(tClient *Client, char *Args)
752 {
753          int    i, count;
754
755         if( Args != NULL && strlen(Args) ) {
756                 sendf(Client->Socket, "407 ENUM_ITEMS takes no arguments\n");
757                 return ;
758         }
759         
760         // Count shown items
761         count = 0;
762         for( i = 0; i < giNumItems; i ++ ) {
763                 if( gaItems[i].bHidden )        continue;
764                 count ++;
765         }
766
767         sendf(Client->Socket, "201 Items %i\n", count);
768
769         for( i = 0; i < giNumItems; i ++ ) {
770                 if( gaItems[i].bHidden )        continue;
771                 Server_int_SendItem( Client, &gaItems[i] );
772         }
773
774         sendf(Client->Socket, "200 List end\n");
775 }
776
777 tItem *_GetItemFromString(char *String)
778 {
779         tHandler        *handler;
780         char    *type = String;
781         char    *colon = strchr(String, ':');
782          int    num, i;
783         
784         if( !colon ) {
785                 return NULL;
786         }
787
788         num = atoi(colon+1);
789         *colon = '\0';
790
791         // Find handler
792         handler = NULL;
793         for( i = 0; i < giNumHandlers; i ++ )
794         {
795                 if( strcmp(gaHandlers[i]->Name, type) == 0) {
796                         handler = gaHandlers[i];
797                         break;
798                 }
799         }
800         if( !handler ) {
801                 return NULL;
802         }
803
804         // Find item
805         for( i = 0; i < giNumItems; i ++ )
806         {
807                 if( gaItems[i].Handler != handler )     continue;
808                 if( gaItems[i].ID != num )      continue;
809                 return &gaItems[i];
810         }
811         return NULL;
812 }
813
814 /**
815  * \brief Fetch information on a specific item
816  *
817  * Usage: ITEMINFO <item ID>
818  */
819 void Server_Cmd_ITEMINFO(tClient *Client, char *Args)
820 {
821         tItem   *item;
822         char    *itemname;
823         
824         if( Server_int_ParseArgs(0, Args, &itemname, NULL) ) {
825                 sendf(Client->Socket, "407 ITEMINFO takes 1 argument\n");
826                 return ;
827         }
828         item = _GetItemFromString(Args);
829         
830         if( !item ) {
831                 sendf(Client->Socket, "406 Bad Item ID\n");
832                 return ;
833         }
834         
835         Server_int_SendItem( Client, item );
836 }
837
838 /**
839  * \brief Dispense an item
840  *
841  * Usage: DISPENSE <Item ID>
842  */
843 void Server_Cmd_DISPENSE(tClient *Client, char *Args)
844 {
845         tItem   *item;
846          int    ret;
847          int    uid;
848         char    *itemname;
849         
850         if( Server_int_ParseArgs(0, Args, &itemname, NULL) ) {
851                 sendf(Client->Socket, "407 DISPENSE takes only 1 argument\n");
852                 return ;
853         }
854          
855         if( !Client->bIsAuthed ) {
856                 sendf(Client->Socket, "401 Not Authenticated\n");
857                 return ;
858         }
859
860         item = _GetItemFromString(itemname);
861         if( !item ) {
862                 sendf(Client->Socket, "406 Bad Item ID\n");
863                 return ;
864         }
865         
866         if( Client->EffectiveUID != -1 ) {
867                 uid = Client->EffectiveUID;
868         }
869         else {
870                 uid = Client->UID;
871         }
872
873 //      if( Bank_GetFlags(Client->UID) & USER_FLAG_DISABLED  ) {
874 //      }
875
876         switch( ret = DispenseItem( Client->UID, uid, item ) )
877         {
878         case 0: sendf(Client->Socket, "200 Dispense OK\n");     return ;
879         case 1: sendf(Client->Socket, "501 Unable to dispense\n");      return ;
880         case 2: sendf(Client->Socket, "402 Poor You\n");        return ;
881         default:
882                 sendf(Client->Socket, "500 Dispense Error (%i)\n", ret);
883                 return ;
884         }
885 }
886
887 /**
888  * \brief Refund an item to a user
889  *
890  * Usage: REFUND <user> <item id> [<price>]
891  */
892 void Server_Cmd_REFUND(tClient *Client, char *Args)
893 {
894         tItem   *item;
895          int    uid, price_override = 0;
896         char    *username, *itemname, *price_str;
897
898         if( Server_int_ParseArgs(0, Args, &username, &itemname, &price_str, NULL) ) {
899                 if( !itemname || price_str ) {
900                         sendf(Client->Socket, "407 REFUND takes 2 or 3 arguments\n");
901                         return ;
902                 }
903         }
904
905         if( !Client->bIsAuthed ) {
906                 sendf(Client->Socket, "401 Not Authenticated\n");
907                 return ;
908         }
909
910         // Check user permissions
911         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
912                 sendf(Client->Socket, "403 Not in coke\n");
913                 return ;
914         }
915
916         uid = Bank_GetAcctByName(username, 0);
917         if( uid == -1 ) {
918                 sendf(Client->Socket, "404 Unknown user\n");
919                 return ;
920         }
921         
922         item = _GetItemFromString(itemname);
923         if( !item ) {
924                 sendf(Client->Socket, "406 Bad Item ID\n");
925                 return ;
926         }
927
928         if( price_str )
929                 price_override = atoi(price_str);
930
931         switch( DispenseRefund( Client->UID, uid, item, price_override ) )
932         {
933         case 0: sendf(Client->Socket, "200 Item Refunded\n");   return ;
934         default:
935                 sendf(Client->Socket, "500 Dispense Error\n");
936                 return;
937         }
938 }
939
940 /**
941  * \brief Transfer money to another account
942  *
943  * Usage: GIVE <dest> <ammount> <reason...>
944  */
945 void Server_Cmd_GIVE(tClient *Client, char *Args)
946 {
947         char    *recipient, *ammount, *reason;
948          int    uid, iAmmount;
949          int    thisUid;
950         
951         // Parse arguments
952         if( Server_int_ParseArgs(1, Args, &recipient, &ammount, &reason, NULL) ) {
953                 sendf(Client->Socket, "407 GIVE takes only 3 arguments\n");
954                 return ;
955         }
956         
957         // Check for authed
958         if( !Client->bIsAuthed ) {
959                 sendf(Client->Socket, "401 Not Authenticated\n");
960                 return ;
961         }
962
963         // Get recipient
964         uid = Bank_GetAcctByName(recipient, 0);
965         if( uid == -1 ) {
966                 sendf(Client->Socket, "404 Invalid target user\n");
967                 return ;
968         }
969         
970         // You can't alter an internal account
971 //      if( Bank_GetFlags(uid) & USER_FLAG_INTERNAL ) {
972 //              sendf(Client->Socket, "404 Invalid target user\n");
973 //              return ;
974 //      }
975
976         // Parse ammount
977         iAmmount = atoi(ammount);
978         if( iAmmount <= 0 ) {
979                 sendf(Client->Socket, "407 Invalid Argument, ammount must be > zero\n");
980                 return ;
981         }
982         
983         if( Client->EffectiveUID != -1 ) {
984                 thisUid = Client->EffectiveUID;
985         }
986         else {
987                 thisUid = Client->UID;
988         }
989
990         // Do give
991         switch( DispenseGive(Client->UID, thisUid, uid, iAmmount, reason) )
992         {
993         case 0:
994                 sendf(Client->Socket, "200 Give OK\n");
995                 return ;
996         case 2:
997                 sendf(Client->Socket, "402 Poor You\n");
998                 return ;
999         default:
1000                 sendf(Client->Socket, "500 Unknown error\n");
1001                 return ;
1002         }
1003 }
1004
1005 void Server_Cmd_DONATE(tClient *Client, char *Args)
1006 {
1007         char    *ammount, *reason;
1008          int    iAmmount;
1009          int    thisUid;
1010         
1011         // Parse arguments
1012         if( Server_int_ParseArgs(1, Args, &ammount, &reason, NULL) ) {
1013                 sendf(Client->Socket, "407 DONATE takes 2 arguments\n");
1014                 return ;
1015         }
1016         
1017         if( !Client->bIsAuthed ) {
1018                 sendf(Client->Socket, "401 Not Authenticated\n");
1019                 return ;
1020         }
1021
1022         // Parse ammount
1023         iAmmount = atoi(ammount);
1024         if( iAmmount <= 0 ) {
1025                 sendf(Client->Socket, "407 Invalid Argument, ammount must be > zero\n");
1026                 return ;
1027         }
1028         
1029         // Handle effective users
1030         if( Client->EffectiveUID != -1 ) {
1031                 thisUid = Client->EffectiveUID;
1032         }
1033         else {
1034                 thisUid = Client->UID;
1035         }
1036
1037         // Do give
1038         switch( DispenseDonate(Client->UID, thisUid, iAmmount, reason) )
1039         {
1040         case 0:
1041                 sendf(Client->Socket, "200 Give OK\n");
1042                 return ;
1043         case 2:
1044                 sendf(Client->Socket, "402 Poor You\n");
1045                 return ;
1046         default:
1047                 sendf(Client->Socket, "500 Unknown error\n");
1048                 return ;
1049         }
1050 }
1051
1052 void Server_Cmd_ADD(tClient *Client, char *Args)
1053 {
1054         char    *user, *ammount, *reason;
1055          int    uid, iAmmount;
1056         
1057         // Parse arguments
1058         if( Server_int_ParseArgs(1, Args, &user, &ammount, &reason, NULL) ) {
1059                 sendf(Client->Socket, "407 ADD takes 3 arguments\n");
1060                 return ;
1061         }
1062         
1063         if( !Client->bIsAuthed ) {
1064                 sendf(Client->Socket, "401 Not Authenticated\n");
1065                 return ;
1066         }
1067
1068         // Check user permissions
1069         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1070                 sendf(Client->Socket, "403 Not in coke\n");
1071                 return ;
1072         }
1073
1074         #if !ROOT_CAN_ADD
1075         if( strcmp( Client->Username, "root" ) == 0 ) {
1076                 // Allow adding for new users
1077                 if( strcmp(reason, "treasurer: new user") != 0 ) {
1078                         sendf(Client->Socket, "403 Root may not add\n");
1079                         return ;
1080                 }
1081         }
1082         #endif
1083
1084         #if HACK_NO_REFUNDS
1085         if( strstr(reason, "refund") != NULL || strstr(reason, "misdispense") != NULL )
1086         {
1087                 sendf(Client->Socket, "499 Don't use `dispense acct` for refunds, use `dispense refund` (and `dispense -G` to get item IDs)\n");
1088                 return ;
1089         }
1090         #endif
1091
1092         // Get recipient
1093         uid = Bank_GetAcctByName(user, 0);
1094         if( uid == -1 ) {
1095                 sendf(Client->Socket, "404 Invalid user\n");
1096                 return ;
1097         }
1098         
1099         // You can't alter an internal account
1100         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) )
1101         {
1102                 if( Bank_GetFlags(uid) & USER_FLAG_INTERNAL ) {
1103                         sendf(Client->Socket, "404 Invalid user\n");
1104                         return ;
1105                 }
1106                 // TODO: Maybe disallow changes to disabled?
1107         }
1108
1109         // Parse ammount
1110         iAmmount = atoi(ammount);
1111         if( iAmmount == 0 && ammount[0] != '0' ) {
1112                 sendf(Client->Socket, "407 Invalid Argument\n");
1113                 return ;
1114         }
1115
1116         // Do give
1117         switch( DispenseAdd(Client->UID, uid, iAmmount, reason) )
1118         {
1119         case 0:
1120                 sendf(Client->Socket, "200 Add OK\n");
1121                 return ;
1122         case 2:
1123                 sendf(Client->Socket, "402 Poor Guy\n");
1124                 return ;
1125         default:
1126                 sendf(Client->Socket, "500 Unknown error\n");
1127                 return ;
1128         }
1129 }
1130
1131 void Server_Cmd_SET(tClient *Client, char *Args)
1132 {
1133         char    *user, *ammount, *reason;
1134          int    uid, iAmmount;
1135         
1136         // Parse arguments
1137         if( Server_int_ParseArgs(1, Args, &user, &ammount, &reason, NULL) ) {
1138                 sendf(Client->Socket, "407 SET takes 3 arguments\n");
1139                 return ;
1140         }
1141         
1142         if( !Client->bIsAuthed ) {
1143                 sendf(Client->Socket, "401 Not Authenticated\n");
1144                 return ;
1145         }
1146
1147         // Check user permissions
1148         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN)  ) {
1149                 sendf(Client->Socket, "403 Not an admin\n");
1150                 return ;
1151         }
1152
1153         // Get recipient
1154         uid = Bank_GetAcctByName(user, 0);
1155         if( uid == -1 ) {
1156                 sendf(Client->Socket, "404 Invalid user\n");
1157                 return ;
1158         }
1159
1160         // Parse ammount
1161         iAmmount = atoi(ammount);
1162         if( iAmmount == 0 && ammount[0] != '0' ) {
1163                 sendf(Client->Socket, "407 Invalid Argument\n");
1164                 return ;
1165         }
1166
1167         // Do give
1168         switch( DispenseSet(Client->UID, uid, iAmmount, reason) )
1169         {
1170         case 0:
1171                 sendf(Client->Socket, "200 Add OK\n");
1172                 return ;
1173         case 2:
1174                 sendf(Client->Socket, "402 Poor Guy\n");
1175                 return ;
1176         default:
1177                 sendf(Client->Socket, "500 Unknown error\n");
1178                 return ;
1179         }
1180 }
1181
1182 void Server_Cmd_ENUMUSERS(tClient *Client, char *Args)
1183 {
1184          int    i, numRet = 0;
1185         tAcctIterator   *it;
1186          int    maxBal = INT_MAX, minBal = INT_MIN;
1187          int    flagMask = 0, flagVal = 0;
1188          int    sort = BANK_ITFLAG_SORT_NAME;
1189         time_t  lastSeenAfter=0, lastSeenBefore=0;
1190         
1191          int    flags;  // Iterator flags
1192          int    balValue;       // Balance value for iterator
1193         time_t  timeValue;      // Time value for iterator
1194         
1195         // Parse arguments
1196         if( Args && strlen(Args) )
1197         {
1198                 char    *space = Args, *type, *val;
1199                 do
1200                 {
1201                         type = space;
1202                         while(*type == ' ')     type ++;
1203                         // Get next space
1204                         space = strchr(space, ' ');
1205                         if(space)       *space = '\0';
1206                         
1207                         // Get type
1208                         val = strchr(type, ':');
1209                         if( val ) {
1210                                 *val = '\0';
1211                                 val ++;
1212                                 
1213                                 // Types
1214                                 // - Minium Balance
1215                                 if( strcmp(type, "min_balance") == 0 ) {
1216                                         minBal = atoi(val);
1217                                 }
1218                                 // - Maximum Balance
1219                                 else if( strcmp(type, "max_balance") == 0 ) {
1220                                         maxBal = atoi(val);
1221                                 }
1222                                 // - Flags
1223                                 else if( strcmp(type, "flags") == 0 ) {
1224                                         if( Server_int_ParseFlags(Client, val, &flagMask, &flagVal) )
1225                                                 return ;
1226                                 }
1227                                 // - Last seen before timestamp
1228                                 else if( strcmp(type, "last_seen_before") == 0 ) {
1229                                         lastSeenAfter = atoll(val);
1230                                 }
1231                                 // - Last seen after timestamp
1232                                 else if( strcmp(type, "last_seen_after") == 0 ) {
1233                                         lastSeenAfter = atoll(val);
1234                                 }
1235                                 // - Sorting 
1236                                 else if( strcmp(type, "sort") == 0 ) {
1237                                         char    *dash = strchr(val, '-');
1238                                         if( dash ) {
1239                                                 *dash = '\0';
1240                                                 dash ++;
1241                                         }
1242                                         if( strcmp(val, "name") == 0 ) {
1243                                                 sort = BANK_ITFLAG_SORT_NAME;
1244                                         }
1245                                         else if( strcmp(val, "balance") == 0 ) {
1246                                                 sort = BANK_ITFLAG_SORT_BAL;
1247                                         }
1248                                         else if( strcmp(val, "lastseen") == 0 ) {
1249                                                 sort = BANK_ITFLAG_SORT_LASTSEEN;
1250                                         }
1251                                         else {
1252                                                 sendf(Client->Socket, "407 Unknown sort field ('%s')\n", val);
1253                                                 return ;
1254                                         }
1255                                         // Handle sort direction
1256                                         if( dash ) {
1257                                                 if( strcmp(dash, "desc") == 0 ) {
1258                                                         sort |= BANK_ITFLAG_REVSORT;
1259                                                 }
1260                                                 else {
1261                                                         sendf(Client->Socket, "407 Unknown sort direction '%s'\n", dash);
1262                                                         return ;
1263                                                 }
1264                                                 dash[-1] = '-';
1265                                         }
1266                                 }
1267                                 else {
1268                                         sendf(Client->Socket, "407 Unknown argument to ENUM_USERS '%s:%s'\n", type, val);
1269                                         return ;
1270                                 }
1271                                 
1272                                 val[-1] = ':';
1273                         }
1274                         else {
1275                                 sendf(Client->Socket, "407 Unknown argument to ENUM_USERS '%s'\n", type);
1276                                 return ;
1277                         }
1278                         
1279                         // Eat whitespace
1280                         if( space ) {
1281                                 *space = ' ';   // Repair (to be nice)
1282                                 space ++;
1283                                 while(*space == ' ')    space ++;
1284                         }
1285                 }       while(space);
1286         }
1287         
1288         // Create iterator
1289         if( maxBal != INT_MAX ) {
1290                 flags = sort|BANK_ITFLAG_MAXBALANCE;
1291                 balValue = maxBal;
1292         }
1293         else if( minBal != INT_MIN ) {
1294                 flags = sort|BANK_ITFLAG_MINBALANCE;
1295                 balValue = minBal;
1296         }
1297         else {
1298                 flags = sort;
1299                 balValue = 0;
1300         }
1301         if( lastSeenBefore ) {
1302                 timeValue = lastSeenBefore;
1303                 flags |= BANK_ITFLAG_SEENBEFORE;
1304         }
1305         else if( lastSeenAfter ) {
1306                 timeValue = lastSeenAfter;
1307                 flags |= BANK_ITFLAG_SEENAFTER;
1308         }
1309         else {
1310                 timeValue = 0;
1311         }
1312         it = Bank_Iterator(flagMask, flagVal, flags, balValue, timeValue);
1313         
1314         // Get return number
1315         while( (i = Bank_IteratorNext(it)) != -1 )
1316         {
1317                 int bal = Bank_GetBalance(i);
1318                 
1319                 if( bal == INT_MIN )    continue;
1320                 
1321                 if( bal < minBal )      continue;
1322                 if( bal > maxBal )      continue;
1323                 
1324                 numRet ++;
1325         }
1326         
1327         Bank_DelIterator(it);
1328         
1329         // Send count
1330         sendf(Client->Socket, "201 Users %i\n", numRet);
1331         
1332         
1333         // Create iterator
1334         it = Bank_Iterator(flagMask, flagVal, flags, balValue, timeValue);
1335         
1336         while( (i = Bank_IteratorNext(it)) != -1 )
1337         {
1338                 int bal = Bank_GetBalance(i);
1339                 
1340                 if( bal == INT_MIN )    continue;
1341                 
1342                 if( bal < minBal )      continue;
1343                 if( bal > maxBal )      continue;
1344                 
1345                 _SendUserInfo(Client, i);
1346         }
1347         
1348         Bank_DelIterator(it);
1349         
1350         sendf(Client->Socket, "200 List End\n");
1351 }
1352
1353 void Server_Cmd_USERINFO(tClient *Client, char *Args)
1354 {
1355          int    uid;
1356         char    *user;
1357         
1358         // Parse arguments
1359         if( Server_int_ParseArgs(0, Args, &user, NULL) ) {
1360                 sendf(Client->Socket, "407 USER_INFO takes 1 argument\n");
1361                 return ;
1362         }
1363         
1364         if( giDebugLevel )      Debug(Client, "User Info '%s'", user);
1365         
1366         // Get recipient
1367         uid = Bank_GetAcctByName(user, 0);
1368         
1369         if( giDebugLevel >= 2 ) Debug(Client, "uid = %i", uid);
1370         if( uid == -1 ) {
1371                 sendf(Client->Socket, "404 Invalid user\n");
1372                 return ;
1373         }
1374         
1375         _SendUserInfo(Client, uid);
1376 }
1377
1378 void _SendUserInfo(tClient *Client, int UserID)
1379 {
1380         char    *type, *disabled="", *door="";
1381          int    flags = Bank_GetFlags(UserID);
1382         
1383         if( flags & USER_FLAG_INTERNAL ) {
1384                 type = "internal";
1385         }
1386         else if( flags & USER_FLAG_COKE ) {
1387                 if( flags & USER_FLAG_ADMIN )
1388                         type = "coke,admin";
1389                 else
1390                         type = "coke";
1391         }
1392         else if( flags & USER_FLAG_ADMIN ) {
1393                 type = "admin";
1394         }
1395         else {
1396                 type = "user";
1397         }
1398         
1399         if( flags & USER_FLAG_DISABLED )
1400                 disabled = ",disabled";
1401         if( flags & USER_FLAG_DOORGROUP )
1402                 door = ",door";
1403         
1404         // TODO: User flags/type
1405         sendf(
1406                 Client->Socket, "202 User %s %i %s%s%s\n",
1407                 Bank_GetAcctName(UserID), Bank_GetBalance(UserID),
1408                 type, disabled, door
1409                 );
1410 }
1411
1412 void Server_Cmd_USERADD(tClient *Client, char *Args)
1413 {
1414         char    *username;
1415         
1416         // Parse arguments
1417         if( Server_int_ParseArgs(0, Args, &username, NULL) ) {
1418                 sendf(Client->Socket, "407 USER_ADD takes 1 argument\n");
1419                 return ;
1420         }
1421         
1422         // Check authentication
1423         if( !Client->bIsAuthed ) {
1424                 sendf(Client->Socket, "401 Not Authenticated\n");
1425                 return ;
1426         }
1427         
1428         // Check permissions
1429         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) ) {
1430                 sendf(Client->Socket, "403 Not a coke admin\n");
1431                 return ;
1432         }
1433         
1434         // Try to create user
1435         if( Bank_CreateAcct(username) == -1 ) {
1436                 sendf(Client->Socket, "404 User exists\n");
1437                 return ;
1438         }
1439         
1440         {
1441                 char    *thisName = Bank_GetAcctName(Client->UID);
1442                 Log_Info("Account '%s' created by '%s'", username, thisName);
1443                 free(thisName);
1444         }
1445         
1446         sendf(Client->Socket, "200 User Added\n");
1447 }
1448
1449 void Server_Cmd_USERFLAGS(tClient *Client, char *Args)
1450 {
1451         char    *username, *flags, *reason=NULL;
1452          int    mask=0, value=0;
1453          int    uid;
1454         
1455         // Parse arguments
1456         if( Server_int_ParseArgs(1, Args, &username, &flags, &reason, NULL) ) {
1457                 if( !flags ) {
1458                         sendf(Client->Socket, "407 USER_FLAGS takes at least 2 arguments\n");
1459                         return ;
1460                 }
1461                 reason = "";
1462         }
1463         
1464         // Check authentication
1465         if( !Client->bIsAuthed ) {
1466                 sendf(Client->Socket, "401 Not Authenticated\n");
1467                 return ;
1468         }
1469         
1470         // Check permissions
1471         if( !(Bank_GetFlags(Client->UID) & USER_FLAG_ADMIN) ) {
1472                 sendf(Client->Socket, "403 Not a coke admin\n");
1473                 return ;
1474         }
1475         
1476         // Get UID
1477         uid = Bank_GetAcctByName(username, 0);
1478         if( uid == -1 ) {
1479                 sendf(Client->Socket, "404 User '%s' not found\n", username);
1480                 return ;
1481         }
1482         
1483         // Parse flags
1484         if( Server_int_ParseFlags(Client, flags, &mask, &value) )
1485                 return ;
1486         
1487         if( giDebugLevel )
1488                 Debug(Client, "Set %i(%s) flags to %x (masked %x)\n",
1489                         uid, username, mask, value);
1490         
1491         // Apply flags
1492         Bank_SetFlags(uid, mask, value);
1493
1494         // Log the change
1495         Log_Info("Updated '%s' with flag set '%s' by '%s' - Reason: %s",
1496                 username, flags, Client->Username, reason);
1497         
1498         // Return OK
1499         sendf(Client->Socket, "200 User Updated\n");
1500 }
1501
1502 void Server_Cmd_UPDATEITEM(tClient *Client, char *Args)
1503 {
1504         char    *itemname, *price_str, *description;
1505          int    price;
1506         tItem   *item;
1507         
1508         if( Server_int_ParseArgs(1, Args, &itemname, &price_str, &description, NULL) ) {
1509                 sendf(Client->Socket, "407 UPDATE_ITEM takes 3 arguments\n");
1510                 return ;
1511         }
1512         
1513         if( !Client->bIsAuthed ) {
1514                 sendf(Client->Socket, "401 Not Authenticated\n");
1515                 return ;
1516         }
1517
1518         // Check user permissions
1519         if( !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1520                 sendf(Client->Socket, "403 Not in coke\n");
1521                 return ;
1522         }
1523         
1524         item = _GetItemFromString(itemname);
1525         if( !item ) {
1526                 // TODO: Create item?
1527                 sendf(Client->Socket, "406 Bad Item ID\n");
1528                 return ;
1529         }
1530         
1531         price = atoi(price_str);
1532         if( price <= 0 && price_str[0] != '0' ) {
1533                 sendf(Client->Socket, "407 Invalid price set\n");
1534         }
1535         
1536         switch( DispenseUpdateItem( Client->UID, item, description, price ) )
1537         {
1538         case 0:
1539                 // Return OK
1540                 sendf(Client->Socket, "200 Item updated\n");
1541                 break;
1542         default:
1543                 break;
1544         }
1545 }
1546
1547 void Server_Cmd_PINCHECK(tClient *Client, char *Args)
1548 {
1549         char    *username, *pinstr;
1550          int    pin;
1551
1552         if( Server_int_ParseArgs(0, Args, &username, &pinstr, NULL) ) {
1553                 sendf(Client->Socket, "407 PIN_CHECK takes 2 arguments\n");
1554                 return ;
1555         }
1556         
1557         if( !isdigit(pinstr[0]) || !isdigit(pinstr[1]) || !isdigit(pinstr[2]) || !isdigit(pinstr[3]) || pinstr[4] != '\0' ) {
1558                 sendf(Client->Socket, "407 PIN should be four digits\n");
1559                 return ;
1560         }
1561         pin = atoi(pinstr);
1562
1563         // Not strictly needed, but ensures that randoms don't do brute forcing
1564         if( !Client->bIsAuthed ) {
1565                 sendf(Client->Socket, "401 Not Authenticated\n");
1566                 return ;
1567         }
1568         
1569         // Get user
1570         int uid = Bank_GetAcctByName(username, 0);
1571         if( uid == -1 ) {
1572                 sendf(Client->Socket, "404 User '%s' not found\n", username);
1573                 return ;
1574         }
1575         
1576         // Check user permissions
1577         if( uid != Client->UID && !(Bank_GetFlags(Client->UID) & (USER_FLAG_COKE|USER_FLAG_ADMIN))  ) {
1578                 sendf(Client->Socket, "403 Not in coke\n");
1579                 return ;
1580         }
1581         
1582         // Get the pin
1583         static time_t   last_wrong_pin_time;
1584         static int      backoff = 1;
1585         if( time(NULL) - last_wrong_pin_time < backoff ) {
1586                 sendf(Client->Socket, "407 Rate limited (%i seconds remaining)\n",
1587                         backoff - (time(NULL) - last_wrong_pin_time));
1588                 return ;
1589         }       
1590         last_wrong_pin_time = time(NULL);
1591         if( !Bank_IsPinValid(uid, pin) )
1592         {
1593                 sendf(Client->Socket, "201 Pin incorrect\n");
1594                 if( backoff < 5)
1595                         backoff ++;
1596                 return ;
1597         }
1598
1599         last_wrong_pin_time = 0;
1600         backoff = 1;
1601         sendf(Client->Socket, "200 Pin correct\n");
1602         return ;
1603 }
1604 void Server_Cmd_PINSET(tClient *Client, char *Args)
1605 {
1606         char    *pinstr;
1607          int    pin;
1608         
1609
1610         if( Server_int_ParseArgs(0, Args, &pinstr, NULL) ) {
1611                 sendf(Client->Socket, "407 PIN_SET takes 2 arguments\n");
1612                 return ;
1613         }
1614         
1615         if( !isdigit(pinstr[0]) || !isdigit(pinstr[1]) || !isdigit(pinstr[2]) || !isdigit(pinstr[3]) || pinstr[4] != '\0' ) {
1616                 sendf(Client->Socket, "407 PIN should be four digits\n");
1617                 return ;
1618         }
1619         pin = atoi(pinstr);
1620
1621         // Not strictly needed, but ensures that randoms don't do brute forcing
1622         if( !Client->bIsAuthed ) {
1623                 sendf(Client->Socket, "401 Not Authenticated\n");
1624                 return ;
1625         }
1626         
1627         int uid = Client->EffectiveUID;
1628         if(uid == -1)
1629                 uid = Client->UID;
1630         // Can only pinset yourself (well, the effective user)
1631         Bank_SetPin(uid, pin);
1632         sendf(Client->Socket, "200 Pin updated\n");
1633         return ;
1634 }
1635
1636 // --- INTERNAL HELPERS ---
1637 void Debug(tClient *Client, const char *Format, ...)
1638 {
1639         va_list args;
1640         //printf("%010i [%i] ", (int)time(NULL), Client->ID);
1641         printf("[%i] ", Client->ID);
1642         va_start(args, Format);
1643         vprintf(Format, args);
1644         va_end(args);
1645         printf("\n");
1646 }
1647
1648 int sendf(int Socket, const char *Format, ...)
1649 {
1650         va_list args;
1651          int    len;
1652         
1653         va_start(args, Format);
1654         len = vsnprintf(NULL, 0, Format, args);
1655         va_end(args);
1656         
1657         {
1658                 char    buf[len+1];
1659                 va_start(args, Format);
1660                 vsnprintf(buf, len+1, Format, args);
1661                 va_end(args);
1662                 
1663                 #if DEBUG_TRACE_CLIENT
1664                 printf("sendf: %s", buf);
1665                 #endif
1666                 
1667                 return send(Socket, buf, len, 0);
1668         }
1669 }
1670
1671 // Takes a series of char *'s in
1672 /**
1673  * \brief Parse space-separated entries into 
1674  */
1675 int Server_int_ParseArgs(int bUseLongLast, char *ArgStr, ...)
1676 {
1677         va_list args;
1678         char    savedChar;
1679         char    **dest;
1680         va_start(args, ArgStr);
1681
1682         // Check for null
1683         if( !ArgStr )
1684         {
1685                 while( (dest = va_arg(args, char **)) )
1686                         *dest = NULL;
1687                 va_end(args);
1688                 return 1;
1689         }
1690
1691         savedChar = *ArgStr;
1692         
1693         while( (dest = va_arg(args, char **)) )
1694         {
1695                 // Trim leading spaces
1696                 while( *ArgStr == ' ' || *ArgStr == '\t' )
1697                         ArgStr ++;
1698                 
1699                 // ... oops, not enough arguments
1700                 if( *ArgStr == '\0' )
1701                 {
1702                         // NULL unset arguments
1703                         do {
1704                                 *dest = NULL;
1705                         }       while( (dest = va_arg(args, char **)) );
1706                 va_end(args);
1707                         return -1;
1708                 }
1709                 
1710                 if( *ArgStr == '"' )
1711                 {
1712                         ArgStr ++;
1713                         *dest = ArgStr;
1714                         // Read until quote
1715                         while( *ArgStr && *ArgStr != '"' )
1716                                 ArgStr ++;
1717                 }
1718                 else
1719                 {
1720                         // Set destination
1721                         *dest = ArgStr;
1722                         // Read until a space
1723                         while( *ArgStr && *ArgStr != ' ' && *ArgStr != '\t' )
1724                                 ArgStr ++;
1725                 }
1726                 savedChar = *ArgStr;    // savedChar is used to un-mangle the last string
1727                 *ArgStr = '\0';
1728                 ArgStr ++;
1729         }
1730         va_end(args);
1731         
1732         // Oops, extra arguments, and greedy not set
1733         if( (savedChar == ' ' || savedChar == '\t') && !bUseLongLast ) {
1734                 return -1;
1735         }
1736         
1737         // Un-mangle last
1738         if(bUseLongLast) {
1739                 ArgStr --;
1740                 *ArgStr = savedChar;
1741         }
1742         
1743         return 0;       // Success!
1744 }
1745
1746 int Server_int_ParseFlags(tClient *Client, const char *Str, int *Mask, int *Value)
1747 {
1748         struct {
1749                 const char      *Name;
1750                  int    Mask;
1751                  int    Value;
1752         }       cFLAGS[] = {
1753                  {"disabled", USER_FLAG_DISABLED, USER_FLAG_DISABLED}
1754                 ,{"door", USER_FLAG_DOORGROUP, USER_FLAG_DOORGROUP}
1755                 ,{"coke", USER_FLAG_COKE, USER_FLAG_COKE}
1756                 ,{"admin", USER_FLAG_ADMIN, USER_FLAG_ADMIN}
1757                 ,{"internal", USER_FLAG_INTERNAL, USER_FLAG_INTERNAL}
1758         };
1759         const int       ciNumFlags = sizeof(cFLAGS)/sizeof(cFLAGS[0]);
1760         
1761         char    *space;
1762         
1763         *Mask = 0;
1764         *Value = 0;
1765         
1766         do {
1767                  int    bRemove = 0;
1768                  int    i;
1769                  int    len;
1770                 
1771                 while( *Str == ' ' )    Str ++; // Eat whitespace
1772                 space = strchr(Str, ',');       // Find the end of the flag
1773                 if(space)
1774                         len = space - Str;
1775                 else
1776                         len = strlen(Str);
1777                 
1778                 // Check for inversion/removal
1779                 if( *Str == '!' || *Str == '-' ) {
1780                         bRemove = 1;
1781                         Str ++;
1782                 }
1783                 else if( *Str == '+' ) {
1784                         Str ++;
1785                 }
1786                 
1787                 // Check flag values
1788                 for( i = 0; i < ciNumFlags; i ++ )
1789                 {
1790                         if( strncmp(Str, cFLAGS[i].Name, len) == 0 ) {
1791                                 *Mask |= cFLAGS[i].Mask;
1792                                 *Value &= ~cFLAGS[i].Mask;
1793                                 if( !bRemove )
1794                                         *Value |= cFLAGS[i].Value;
1795                                 break;
1796                         }
1797                 }
1798                 
1799                 // Error check
1800                 if( i == ciNumFlags ) {
1801                         char    val[len+1];
1802                         strncpy(val, Str, len+1);
1803                         sendf(Client->Socket, "407 Unknown flag value '%s'\n", val);
1804                         return -1;
1805                 }
1806                 
1807                 Str = space + 1;
1808         } while(space);
1809         
1810         return 0;
1811 }
1812

UCC git Repository :: git.ucc.asn.au