/***************************************************************************
- * Copyright (C) 2005-2015 by the Quassel Project *
+ * Copyright (C) 2005-2018 by the Quassel Project *
* devel@quassel-irc.org *
* *
* This program is free software; you can redistribute it and/or modify *
#endif
#include "core.h"
-#include "logger.h"
+#include "logmessage.h"
using namespace Protocol;
}
// read the list of protocols supported by the client
- while (socket()->bytesAvailable() >= 4) {
+ while (socket()->bytesAvailable() >= 4 && _supportedProtos.size() < 16) { // sanity check
quint32 data;
socket()->read((char*)&data, 4);
data = qFromBigEndian<quint32>(data);
level = Compressor::NoCompression;
RemotePeer *peer = PeerFactory::createPeer(_supportedProtos, this, socket(), level, this);
+ if (!peer) {
+ qWarning() << "Received invalid handshake data from client" << socket()->peerAddress().toString();
+ close();
+ return;
+ }
+
if (peer->protocol() == Protocol::LegacyProtocol) {
_legacy = true;
connect(peer, SIGNAL(protocolVersionMismatch(int,int)), SLOT(onProtocolVersionMismatch(int,int)));
else
useSsl = _connectionFeatures & Protocol::Encryption;
- if (Quassel::isOptionSet("require-ssl") && !useSsl) {
+ if (Quassel::isOptionSet("require-ssl") && !useSsl && !_peer->isLocal()) {
+ quInfo() << qPrintable(tr("SSL required but non-SSL connection attempt from %1").arg(socket()->peerAddress().toString()));
_peer->dispatch(ClientDenied(tr("<b>SSL is required!</b><br>You need to use SSL in order to connect to this core.")));
_peer->close();
return;
}
+ _peer->setFeatures(std::move(msg.features));
+ _peer->setBuildDate(msg.buildDate);
+ _peer->setClientVersion(msg.clientVersion);
+
QVariantList backends;
+ QVariantList authenticators;
bool configured = Core::isConfigured();
- if (!configured)
+ if (!configured) {
backends = Core::backendInfo();
+ if (_peer->hasFeature(Quassel::Feature::Authenticators)) {
+ authenticators = Core::authenticatorInfo();
+ }
+ }
- int uptime = Core::instance()->startTime().secsTo(QDateTime::currentDateTime().toUTC());
- int updays = uptime / 86400; uptime %= 86400;
- int uphours = uptime / 3600; uptime %= 3600;
- int upmins = uptime / 60;
- QString coreInfo = tr("<b>Quassel Core Version %1</b><br>"
- "Built: %2<br>"
- "Up %3d%4h%5m (since %6)").arg(Quassel::buildInfo().fancyVersionString)
- .arg(Quassel::buildInfo().buildDate)
- .arg(updays).arg(uphours, 2, 10, QChar('0')).arg(upmins, 2, 10, QChar('0')).arg(Core::instance()->startTime().toString(Qt::TextDate));
-
- // useSsl and coreInfo are only used for the legacy protocol
- _peer->dispatch(ClientRegistered(Quassel::features(), configured, backends, useSsl, coreInfo));
+ _peer->dispatch(ClientRegistered(Quassel::Features{}, configured, backends, authenticators, useSsl));
+ // useSsl is only used for the legacy protocol
if (_legacy && useSsl)
startSsl();
if (!checkClientRegistered())
return;
- QString result = Core::setup(msg.adminUser, msg.adminPassword, msg.backend, msg.setupData);
+ // The default parameter to authenticator is Database.
+ // Maybe this should be hardcoded elsewhere, i.e. as a define.
+ QString authenticator = msg.authenticator;
+ quInfo() << "[" << authenticator << "]";
+ if (authenticator.trimmed().isEmpty()) {
+ authenticator = QString("Database");
+ }
+
+ QString result = Core::setup(msg.adminUser, msg.adminPassword, msg.backend, msg.setupData, authenticator, msg.authSetupData);
if (!result.isEmpty())
_peer->dispatch(SetupFailed(result));
else
if (!checkClientRegistered())
return;
+ if (!Core::isConfigured()) {
+ qWarning() << qPrintable(tr("Client")) << qPrintable(socket()->peerAddress().toString()) << qPrintable(tr("attempted to login before the core was configured, rejecting."));
+ _peer->dispatch(ClientDenied(tr("<b>Attempted to login before core was configured!</b><br>The core must be configured before attempting to login.")));
+ return;
+ }
+
+ // First attempt local auth using the real username and password.
+ // If that fails, move onto the auth provider.
UserId uid = Core::validateUser(msg.user, msg.password);
if (uid == 0) {
+ uid = Core::authenticateUser(msg.user, msg.password);
+ }
+
+ if (uid == 0) {
+ quInfo() << qPrintable(tr("Invalid login attempt from %1 as \"%2\"").arg(socket()->peerAddress().toString(), msg.user));
_peer->dispatch(LoginFailed(tr("<b>Invalid username or password!</b><br>The username/password combination you supplied could not be found in the database.")));
return;
}
quInfo() << qPrintable(tr("Client %1 initialized and authenticated successfully as \"%2\" (UserId: %3).").arg(socket()->peerAddress().toString(), msg.user, QString::number(uid.toInt())));
+ const auto &clientFeatures = _peer->features();
+ auto unsupported = clientFeatures.toStringList(false);
+ if (!unsupported.isEmpty()) {
+ if (unsupported.contains("NoFeatures"))
+ quInfo() << qPrintable(tr("Client does not support extended features."));
+ else
+ quInfo() << qPrintable(tr("Client does not support the following features: %1").arg(unsupported.join(", ")));
+ }
+
+ if (!clientFeatures.unknownFeatures().isEmpty()) {
+ quInfo() << qPrintable(tr("Client supports unknown features: %1").arg(clientFeatures.unknownFeatures().join(", ")));
+ }
+
disconnect(socket(), 0, this, 0);
disconnect(_peer, 0, this, 0);
_peer->setParent(0); // Core needs to take care of this one now!