Annotate

plugins/mod_auth_cyrus.lua @ 6492:0d07fdc07d8c

mod_saslauth: Make it possible to disable certain mechanisms
author Kim Alvefur <zash@zash.se>
date Tue, 21 Oct 2014 14:38:40 +0200
parent 5117:2c7e1ce8f482
child 8054:0ba461b7d9af
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
1 -- Prosody IM
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
2 -- Copyright (C) 2008-2010 Matthew Wild
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
3 -- Copyright (C) 2008-2010 Waqas Hussain
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
4 --
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
5 -- This project is MIT/X11 licensed. Please see the
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
6 -- COPYING file in the source package for more information.
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
7 --
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
8
3271
1b6c2984c1f4 mod_auth_cyrus: Log as "auth_cyrus", not as "usermanager".
Waqas Hussain <waqas20@gmail.com>
parents: 3192
diff changeset
9 local log = require "util.logger".init("auth_cyrus");
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
10
3468
d50e2c937717 mod_saslauth, mod_auth_cyrus, util.sasl_cyrus: Moved cyrus account provisioning check out of mod_saslauth.
Waqas Hussain <waqas20@gmail.com>
parents: 3425
diff changeset
11 local usermanager_user_exists = require "core.usermanager".user_exists;
d50e2c937717 mod_saslauth, mod_auth_cyrus, util.sasl_cyrus: Moved cyrus account provisioning check out of mod_saslauth.
Waqas Hussain <waqas20@gmail.com>
parents: 3425
diff changeset
12
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
13 local cyrus_service_realm = module:get_option("cyrus_service_realm");
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
14 local cyrus_service_name = module:get_option("cyrus_service_name");
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
15 local cyrus_application_name = module:get_option("cyrus_application_name");
3468
d50e2c937717 mod_saslauth, mod_auth_cyrus, util.sasl_cyrus: Moved cyrus account provisioning check out of mod_saslauth.
Waqas Hussain <waqas20@gmail.com>
parents: 3425
diff changeset
16 local require_provisioning = module:get_option("cyrus_require_provisioning") or false;
5000
58c9519dc461 mod_auth_cyrus, util.sasl_cyrus: Add new option 'cyrus_server_fqdn' to override the hostname passed to Cyrus (and used in e.g. GSSAPI/Kerberos) - fixes #295
Matthew Wild <mwild1@gmail.com>
parents: 4160
diff changeset
17 local host_fqdn = module:get_option("cyrus_server_fqdn");
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
18
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
19 prosody.unlock_globals(); --FIXME: Figure out why this is needed and
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
20 -- why cyrussasl isn't caught by the sandbox
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
21 local cyrus_new = require "util.sasl_cyrus".new;
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
22 prosody.lock_globals();
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
23 local new_sasl = function(realm)
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
24 return cyrus_new(
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
25 cyrus_service_realm or realm,
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
26 cyrus_service_name or "xmpp",
5000
58c9519dc461 mod_auth_cyrus, util.sasl_cyrus: Add new option 'cyrus_server_fqdn' to override the hostname passed to Cyrus (and used in e.g. GSSAPI/Kerberos) - fixes #295
Matthew Wild <mwild1@gmail.com>
parents: 4160
diff changeset
27 cyrus_application_name or "prosody",
58c9519dc461 mod_auth_cyrus, util.sasl_cyrus: Add new option 'cyrus_server_fqdn' to override the hostname passed to Cyrus (and used in e.g. GSSAPI/Kerberos) - fixes #295
Matthew Wild <mwild1@gmail.com>
parents: 4160
diff changeset
28 host_fqdn
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
29 );
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
30 end
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
31
4159
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
32 do -- diagnostic
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
33 local list;
4160
f08f649b898b mod_auth_*: Get rid of undocumented and broken 'sasl_realm' config option.
Waqas Hussain <waqas20@gmail.com>
parents: 4159
diff changeset
34 for mechanism in pairs(new_sasl(module.host):mechanisms()) do
4159
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
35 list = (not(list) and mechanism) or (list..", "..mechanism);
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
36 end
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
37 if not list then
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
38 module:log("error", "No Cyrus SASL mechanisms available");
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
39 else
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
40 module:log("debug", "Available Cyrus SASL mechanisms: %s", list);
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
41 end
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
42 end
52eaa2590bfb mod_auth_cyrus: Print some diagnostic log messages about the available mechanisms.
Waqas Hussain <waqas20@gmail.com>
parents: 3468
diff changeset
43
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
44 local host = module.host;
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
45
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
46 -- define auth provider
5117
2c7e1ce8f482 mod_auth_*: Use module:provides().
Waqas Hussain <waqas20@gmail.com>
parents: 5115
diff changeset
47 local provider = {};
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
48 log("debug", "initializing default authentication provider for host '%s'", host);
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
49
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
50 function provider.test_password(username, password)
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
51 return nil, "Legacy auth not supported with Cyrus SASL.";
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
52 end
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
53
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
54 function provider.get_password(username)
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
55 return nil, "Passwords unavailable for Cyrus SASL.";
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
56 end
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
57
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
58 function provider.set_password(username, password)
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
59 return nil, "Passwords unavailable for Cyrus SASL.";
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
60 end
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
61
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
62 function provider.user_exists(username)
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
63 if require_provisioning then
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
64 return usermanager_user_exists(username, host);
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
65 end
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
66 return true;
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
67 end
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
68
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
69 function provider.create_user(username, password)
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
70 return nil, "Account creation/modification not available with Cyrus SASL.";
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
71 end
3192
8ad50989d79e mod_auth_cyrus: Auth provider with support for Cyrus SASL.
Waqas Hussain <waqas20@gmail.com>
parents:
diff changeset
72
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
73 function provider.get_sasl_handler()
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
74 local handler = new_sasl(host);
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
75 if require_provisioning then
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
76 function handler.require_provisioning(username)
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
77 return usermanager_user_exists(username, host);
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
78 end
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
79 end
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
80 return handler;
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
81 end
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
82
5117
2c7e1ce8f482 mod_auth_*: Use module:provides().
Waqas Hussain <waqas20@gmail.com>
parents: 5115
diff changeset
83 module:provides("auth", provider);
5115
3939960b3c07 mod_auth_{internal_plain,cyrus,anonymous}: Get rid of useless wrapper function new_default_provider.
Waqas Hussain <waqas20@gmail.com>
parents: 5000
diff changeset
84