From 053f8cf83202fee080408f7aa1725b7371a81737 Mon Sep 17 00:00:00 2001 From: Jean Date: Thu, 16 Jul 2026 02:33:55 +0000 Subject: [PATCH] NickServ: add SET HIDE STATUS for last-seen privacy Lets an account keep its last-seen/online line in INFO visible only to itself and to opers. Default stays public (Anope's default). Accepts STATUS (with USERMASK as an alias) per Anope's SET HIDE grammar. --- api/src/lib.rs | 5 +++++ modules/nickserv/src/info.rs | 21 ++++++++++++--------- modules/nickserv/src/lib.rs | 2 +- modules/nickserv/src/set.rs | 22 +++++++++++++++++++++- src/engine/db/account.rs | 20 ++++++++++++++++++-- src/engine/db/event.rs | 7 +++++++ src/engine/db/mod.rs | 5 +++++ src/engine/db/store.rs | 9 ++++++++- src/engine/db/tests.rs | 4 ++-- src/engine/mod.rs | 2 +- src/engine/tests.rs | 35 ++++++++++++++++++++++++++++++++++- src/grpc.rs | 3 ++- 12 files changed, 116 insertions(+), 19 deletions(-) diff --git a/api/src/lib.rs b/api/src/lib.rs index cff8b31..690319a 100644 --- a/api/src/lib.rs +++ b/api/src/lib.rs @@ -466,6 +466,8 @@ pub struct AccountView { pub greet: String, // Unix time this account was last active (coalesced); never below `ts`. pub last_seen: u64, + // Whether the last-seen/online line is hidden from non-owner, non-oper viewers. + pub hide_status: bool, } // One channel access-list entry (account -> level). `level` is either a legacy @@ -922,6 +924,9 @@ pub trait Store { // NickServ SET KILL: whether this account's nicks are enforcer-protected. fn set_account_kill(&mut self, account: &str, on: bool) -> Result<(), RegError>; fn account_wants_protect(&self, account: &str) -> bool; + // NickServ SET HIDE STATUS: whether this account hides its last-seen line. + fn set_account_hide_status(&mut self, account: &str, on: bool) -> Result<(), RegError>; + fn account_hides_status(&self, account: &str) -> bool; // HostServ vhosts. fn set_vhost(&mut self, account: &str, host: &str, setter: &str, ttl: Option) -> Result<(), RegError>; fn del_vhost(&mut self, account: &str) -> Result; diff --git a/modules/nickserv/src/info.rs b/modules/nickserv/src/info.rs index c5594d5..0015b5f 100644 --- a/modules/nickserv/src/info.rs +++ b/modules/nickserv/src/info.rs @@ -10,21 +10,24 @@ pub fn handle(me: &str, from: &Sender, args: &[&str], ctx: &mut ServiceCtx, net: ctx.notice(me, from.uid, format!("\x02{name}\x02 isn't registered.")); return; }; + let is_owner = from.account == Some(acct.name.as_str()); + let privileged = is_owner || from.privs.has(Priv::Auspex); ctx.notice(me, from.uid, format!("Information for \x02{}\x02:", acct.name)); ctx.notice(me, from.uid, format!(" Registered : {}", human_time(acct.ts))); - // Last-seen is public (Anope shows it by default); a live session reads as online. - let last_seen = if net.uids_logged_into(&acct.name).is_empty() { - human_time(acct.last_seen) - } else { - "now (online)".to_string() - }; - ctx.notice(me, from.uid, format!(" Last seen : {last_seen}")); + // Last-seen is public by default; SET HIDE STATUS keeps it to owner and opers. + if privileged || !acct.hide_status { + let last_seen = if net.uids_logged_into(&acct.name).is_empty() { + human_time(acct.last_seen) + } else { + "now (online)".to_string() + }; + ctx.notice(me, from.uid, format!(" Last seen : {last_seen}")); + } // A greet is public — the bot shows it in-channel to everyone anyway. if !acct.greet.is_empty() { ctx.notice(me, from.uid, format!(" Greet : {}", acct.greet)); } - let is_owner = from.account == Some(acct.name.as_str()); - if is_owner || from.privs.has(Priv::Auspex) { + if privileged { if let Some(s) = db.suspension(&acct.name) { ctx.notice(me, from.uid, format!(" Suspended : by \x02{}\x02 — {}", s.by, s.reason)); } diff --git a/modules/nickserv/src/lib.rs b/modules/nickserv/src/lib.rs index ac44780..b33f03d 100644 --- a/modules/nickserv/src/lib.rs +++ b/modules/nickserv/src/lib.rs @@ -54,7 +54,7 @@ const TOPICS: &[HelpEntry] = &[ HelpEntry { cmd: "LOGOUT", summary: "log out to a guest nick", detail: "Syntax: \x02LOGOUT\x02\nLogs you out and moves you to a guest nick. Also \x02LOGOFF\x02." }, HelpEntry { cmd: "INFO", summary: "show account information", detail: "Syntax: \x02INFO [account]\x02\nShows account information. The email is shown only to the owner." }, HelpEntry { cmd: "ALIST", summary: "list channels you have access on", detail: "Syntax: \x02ALIST\x02\nLists the channels you hold access on." }, - HelpEntry { cmd: "SET", summary: "change password, email, or preferences", detail: "Syntax: \x02SET PASSWORD \x02, \x02SET EMAIL
\x02, \x02SET GREET [message]\x02, \x02SET AUTOOP {ON|OFF}\x02, or \x02SET KILL {ON|OFF}\x02\nChanges your password, email, greet, auto-op, or nick-protection preference." }, + HelpEntry { cmd: "SET", summary: "change password, email, or preferences", detail: "Syntax: \x02SET PASSWORD \x02, \x02SET EMAIL
\x02, \x02SET GREET [message]\x02, \x02SET AUTOOP {ON|OFF}\x02, \x02SET KILL {ON|OFF}\x02, or \x02SET HIDE STATUS {ON|OFF}\x02\nChanges your password, email, greet, auto-op, nick-protection, or last-seen privacy." }, HelpEntry { cmd: "SASET", summary: "change another account's settings (operator)", detail: "Syntax: \x02SASET PASSWORD \x02, \x02EMAIL [address]\x02, or \x02GREET [message]\x02\nEdits another account's settings. Operators only." }, HelpEntry { cmd: "GROUP", summary: "link this nick to an account", detail: "Syntax: \x02GROUP \x02\nLinks your current nick to an account as an alias, so identifying under it logs into that account." }, HelpEntry { cmd: "GLIST", summary: "list your grouped nicks", detail: "Syntax: \x02GLIST\x02\nLists the nicks grouped to your account." }, diff --git a/modules/nickserv/src/set.rs b/modules/nickserv/src/set.rs index 4771c62..937593b 100644 --- a/modules/nickserv/src/set.rs +++ b/modules/nickserv/src/set.rs @@ -35,6 +35,26 @@ pub fn handle(me: &str, from: &Sender, args: &[&str], ctx: &mut ServiceCtx, db: Err(_) => ctx.notice(me, from.uid, "Sorry, that didn't work. Please try again in a moment."), } } + Some("HIDE") => { + // Anope grammar is SET HIDE {ON|OFF}. The only field that is + // public here is the last-seen/online line (STATUS); USERMASK is an + // accepted alias for it. + match args.get(2).map(|s| s.to_ascii_uppercase()).as_deref() { + Some("STATUS") | Some("USERMASK") => { + let Some(on) = args.get(3).and_then(|s| parse_toggle(s)) else { + let state = if db.account_hides_status(account) { "ON" } else { "OFF" }; + ctx.notice(me, from.uid, format!("HIDE STATUS is \x02{state}\x02. Syntax: SET HIDE STATUS {{ON|OFF}}")); + return; + }; + match db.set_account_hide_status(account, on) { + Ok(()) if on => ctx.notice(me, from.uid, "Your last-seen and online status are now hidden from other users."), + Ok(()) => ctx.notice(me, from.uid, "Your last-seen and online status are visible to everyone again."), + Err(_) => ctx.notice(me, from.uid, "Sorry, that didn't work. Please try again in a moment."), + } + } + _ => ctx.notice(me, from.uid, "Syntax: SET HIDE STATUS {ON|OFF}"), + } + } Some("KILL") => { // Anope accepts ON/QUICK/IMMED/OFF; grace here is a fixed interval, so // the finer variants simply enable protection like ON. @@ -76,7 +96,7 @@ pub fn handle(me: &str, from: &Sender, args: &[&str], ctx: &mut ServiceCtx, db: Err(_) => ctx.notice(me, from.uid, "Sorry, that didn't work. Please try again in a moment."), } } - _ => ctx.notice(me, from.uid, "Syntax: SET PASSWORD | SET EMAIL [address] | SET GREET [message] | SET AUTOOP {ON|OFF} | SET KILL {ON|OFF}"), + _ => ctx.notice(me, from.uid, "Syntax: SET PASSWORD | SET EMAIL [address] | SET GREET [message] | SET AUTOOP {ON|OFF} | SET KILL {ON|OFF} | SET HIDE STATUS {ON|OFF}"), } } diff --git a/src/engine/db/account.rs b/src/engine/db/account.rs index 1a285cc..6812f29 100644 --- a/src/engine/db/account.rs +++ b/src/engine/db/account.rs @@ -21,7 +21,7 @@ impl Db { ajoin: Vec::new(), suspension: None, memos: Vec::new(), memo_ignore: Vec::new(), memo_notify: true, memo_limit: None, - greet: String::new(), no_autoop: false, no_protect: false, + greet: String::new(), no_autoop: false, no_protect: false, hide_status: false, vhost: None, vhost_request: None, last_seen: now(), @@ -60,7 +60,7 @@ impl Db { ajoin: Vec::new(), suspension: None, memos: Vec::new(), memo_ignore: Vec::new(), memo_notify: true, memo_limit: None, - greet: String::new(), no_autoop: false, no_protect: false, + greet: String::new(), no_autoop: false, no_protect: false, hide_status: false, vhost: None, vhost_request: None, last_seen: now(), @@ -450,6 +450,22 @@ impl Db { self.accounts.get(&key(account)).is_none_or(|a| !a.no_protect) } + /// Set whether `account` hides its last-seen/online line from other users. + pub fn set_account_hide_status(&mut self, account: &str, on: bool) -> Result<(), RegError> { + let k = key(account); + if !self.accounts.contains_key(&k) { + return Err(RegError::Internal); + } + self.log.append(Event::AccountHideStatusSet { account: account.to_string(), on }).map_err(|_| RegError::Internal)?; + self.accounts.get_mut(&k).unwrap().hide_status = on; + Ok(()) + } + + /// Whether `account` hides its last-seen/online line from others (default false). + pub fn account_hides_status(&self, account: &str) -> bool { + self.accounts.get(&key(account)).is_some_and(|a| a.hide_status) + } + /// Replace `account`'s password with freshly derived credentials. pub fn set_credentials(&mut self, account: &str, creds: Credentials) -> Result<(), RegError> { let k = key(account); diff --git a/src/engine/db/event.rs b/src/engine/db/event.rs index 4afd6de..68af1a6 100644 --- a/src/engine/db/event.rs +++ b/src/engine/db/event.rs @@ -17,6 +17,7 @@ pub enum Event { AccountGreetSet { account: String, greet: String }, AccountAutoOpSet { account: String, on: bool }, AccountKillSet { account: String, on: bool }, + AccountHideStatusSet { account: String, on: bool }, AccountPasswordSet { account: String, scram256: String, scram512: String }, AccountDropped { account: String }, AccountVerified { account: String }, @@ -151,6 +152,7 @@ impl Event { | Event::AccountGreetSet { .. } | Event::AccountAutoOpSet { .. } | Event::AccountKillSet { .. } + | Event::AccountHideStatusSet { .. } | Event::AccountPasswordSet { .. } | Event::AccountDropped { .. } | Event::AccountVerified { .. } @@ -287,6 +289,11 @@ pub(crate) fn apply(accounts: &mut HashMap, channels: &mut Hash a.no_protect = !on; } } + Event::AccountHideStatusSet { account, on } => { + if let Some(a) = accounts.get_mut(&key(&account)) { + a.hide_status = on; + } + } Event::AccountPasswordSet { account, scram256, scram512 } => { if let Some(a) = accounts.get_mut(&key(&account)) { a.scram256 = Some(scram256); diff --git a/src/engine/db/mod.rs b/src/engine/db/mod.rs index 30c38fb..53a6b29 100644 --- a/src/engine/db/mod.rs +++ b/src/engine/db/mod.rs @@ -101,6 +101,11 @@ pub struct Account { // inverted so the default (protection enabled) is the zero value. #[serde(default)] pub no_protect: bool, + // NickServ SET HIDE STATUS: when set, the last-seen / online line in INFO is + // shown only to the account's owner and to opers, not to other users. Default + // (visible) is the zero value. + #[serde(default)] + pub hide_status: bool, // Assigned vhost (HostServ), applied to the displayed host on identify. #[serde(default)] pub vhost: Option, diff --git a/src/engine/db/store.rs b/src/engine/db/store.rs index f46da07..80a8531 100644 --- a/src/engine/db/store.rs +++ b/src/engine/db/store.rs @@ -12,6 +12,7 @@ impl Store for Db { verified: a.verified, greet: a.greet.clone(), last_seen: a.last_seen, + hide_status: a.hide_status, }) } fn resolve_account(&self, name: &str) -> Option<&str> { @@ -20,7 +21,7 @@ impl Store for Db { fn accounts_matching(&self, pattern: &str) -> Vec { self.accounts() .filter(|a| super::glob_match(pattern, &a.name)) - .map(|a| AccountView { name: a.name.clone(), email: a.email.clone(), ts: a.ts, verified: a.verified, greet: a.greet.clone(), last_seen: a.last_seen }) + .map(|a| AccountView { name: a.name.clone(), email: a.email.clone(), ts: a.ts, verified: a.verified, greet: a.greet.clone(), last_seen: a.last_seen, hide_status: a.hide_status }) .collect() } fn accounts_by_email(&self, pattern: &str) -> Vec { @@ -95,6 +96,12 @@ impl Store for Db { fn account_wants_protect(&self, account: &str) -> bool { Db::account_wants_protect(self, account) } + fn set_account_hide_status(&mut self, account: &str, on: bool) -> Result<(), RegError> { + Db::set_account_hide_status(self, account, on) + } + fn account_hides_status(&self, account: &str) -> bool { + Db::account_hides_status(self, account) + } fn set_vhost(&mut self, account: &str, host: &str, setter: &str, ttl: Option) -> Result<(), RegError> { Db::set_vhost(self, account, host, setter, ttl) } diff --git a/src/engine/db/tests.rs b/src/engine/db/tests.rs index c33ff08..ddd0372 100644 --- a/src/engine/db/tests.rs +++ b/src/engine/db/tests.rs @@ -32,7 +32,7 @@ // which of the two competing registrations we're looking at. let alice = |tag: &str, ts: u64, home: &str| Account { name: "alice".into(), email: Some(tag.into()), - ts, home: home.into(), scram256: None, scram512: None, certfps: vec![], verified: true, ajoin: vec![], suspension: None, memos: vec![], memo_ignore: vec![], memo_notify: true, memo_limit: None, greet: String::new(), no_autoop: false, no_protect: false, vhost: None, vhost_request: None, last_seen: ts, noexpire: false, expiry_warned: false, oper_note: None, + ts, home: home.into(), scram256: None, scram512: None, certfps: vec![], verified: true, ajoin: vec![], suspension: None, memos: vec![], memo_ignore: vec![], memo_notify: true, memo_limit: None, greet: String::new(), no_autoop: false, no_protect: false, hide_status: false, vhost: None, vhost_request: None, last_seen: ts, noexpire: false, expiry_warned: false, oper_note: None, }; let converge = |first: &Account, second: &Account| { let (mut acc, mut ch, mut gr, mut bo, mut hc, mut nd) = (HashMap::new(), HashMap::new(), HashMap::new(), HashMap::new(), HostConfig::default(), NetData::default()); @@ -329,7 +329,7 @@ db.register("alice", "pw", None).unwrap(); let bob = Account { name: "bob".into(), email: None, - ts: 0, home: "peer".into(), scram256: None, scram512: None, certfps: vec![], verified: true, ajoin: vec![], suspension: None, memos: vec![], memo_ignore: vec![], memo_notify: true, memo_limit: None, greet: String::new(), no_autoop: false, no_protect: false, vhost: None, vhost_request: None, last_seen: 0, noexpire: false, expiry_warned: false, oper_note: None, + ts: 0, home: "peer".into(), scram256: None, scram512: None, certfps: vec![], verified: true, ajoin: vec![], suspension: None, memos: vec![], memo_ignore: vec![], memo_notify: true, memo_limit: None, greet: String::new(), no_autoop: false, no_protect: false, hide_status: false, vhost: None, vhost_request: None, last_seen: 0, noexpire: false, expiry_warned: false, oper_note: None, }; let entry = LogEntry { origin: "peer".into(), seq: 0, lamport: 1, event: Event::AccountRegistered(Box::new(bob)) }; db.ingest(entry).unwrap(); diff --git a/src/engine/mod.rs b/src/engine/mod.rs index ede65dc..bb18131 100644 --- a/src/engine/mod.rs +++ b/src/engine/mod.rs @@ -1183,7 +1183,7 @@ fn audit_summary(event: &db::Event) -> Option { format!("{verb} channel \x02{channel}\x02 against expiry") } // Private, self-service, or cosmetic — not surfaced. - AjoinAdded { .. } | AjoinRemoved { .. } | AccountGreetSet { .. } | AccountAutoOpSet { .. } | AccountKillSet { .. } | VhostRequested { .. } + AjoinAdded { .. } | AjoinRemoved { .. } | AccountGreetSet { .. } | AccountAutoOpSet { .. } | AccountKillSet { .. } | AccountHideStatusSet { .. } | VhostRequested { .. } | VhostRequestCleared { .. } | MemoSent { .. } | MemoRead { .. } | MemoDeleted { .. } | MemoIgnoreAdd { .. } | MemoIgnoreDel { .. } | MemoPrefsSet { .. } | ChannelMlock { .. } | ChannelDescSet { .. } | ChannelEntryMsgSet { .. } | ChannelSettingsSet { .. } diff --git a/src/engine/tests.rs b/src/engine/tests.rs index 9c418cd..bc33741 100644 --- a/src/engine/tests.rs +++ b/src/engine/tests.rs @@ -411,7 +411,7 @@ // An earlier claim from another node wins and takes the name over. let winner = db::Account { name: "alice".into(), email: None, - ts: 0, home: "peer".into(), scram256: None, scram512: None, certfps: vec![], verified: true, ajoin: vec![], suspension: None, memos: vec![], memo_ignore: vec![], memo_notify: true, memo_limit: None, greet: String::new(), no_autoop: false, no_protect: false, vhost: None, vhost_request: None, last_seen: 0, noexpire: false, expiry_warned: false, oper_note: None, + ts: 0, home: "peer".into(), scram256: None, scram512: None, certfps: vec![], verified: true, ajoin: vec![], suspension: None, memos: vec![], memo_ignore: vec![], memo_notify: true, memo_limit: None, greet: String::new(), no_autoop: false, no_protect: false, hide_status: false, vhost: None, vhost_request: None, last_seen: 0, noexpire: false, expiry_warned: false, oper_note: None, }; let entry = LogEntry::for_test("peer", 0, 1, db::Event::AccountRegistered(Box::new(winner))); e.gossip_ingest(entry).unwrap(); @@ -473,6 +473,39 @@ assert!(notice(&to_ns(&mut e, "ALIST"), "#a")); } + // SET HIDE STATUS keeps the last-seen/online line to the owner and opers. + #[test] + fn nickserv_set_hide_status() { + let path = std::env::temp_dir().join("echo-nshide.jsonl"); + let _ = std::fs::remove_file(&path); + let mut db = Db::open(&path, "test"); + db.scram_iterations = 4096; + db.register("alice", "sesame", None).unwrap(); + db.register("bob", "hunter2", None).unwrap(); + let ns = NickServ { uid: "42SAAAAAA".into(), guest_nick: "Guest".into(), guest_seq: 0 }; + let mut e = Engine::new(vec![Box::new(ns)], db); + let send = |e: &mut Engine, uid: &str, text: &str| e.handle(NetEvent::Privmsg { from: uid.into(), to: "42SAAAAAA".into(), text: text.into() }); + let notice = |out: &[NetAction], needle: &str| out.iter().any(|a| matches!(a, NetAction::Notice { text, .. } if text.contains(needle))); + e.handle(NetEvent::UserConnect { uid: "000AAAAAA".into(), nick: "alice".into(), host: "h".into(), ip: "0.0.0.0".into() }); + send(&mut e, "000AAAAAA", "IDENTIFY sesame"); + e.handle(NetEvent::UserConnect { uid: "000AAAAAB".into(), nick: "bob".into(), host: "h".into(), ip: "0.0.0.0".into() }); + send(&mut e, "000AAAAAB", "IDENTIFY hunter2"); + + // Default: a stranger (bob) sees alice's last-seen line. + assert!(notice(&send(&mut e, "000AAAAAB", "INFO alice"), "Last seen"), "last-seen public by default"); + + // alice hides it: strangers lose the line, owner keeps it. + assert!(notice(&send(&mut e, "000AAAAAA", "SET HIDE STATUS ON"), "hidden"), "hide confirmed"); + let stranger = send(&mut e, "000AAAAAB", "INFO alice"); + assert!(notice(&stranger, "Registered"), "stranger still sees registration: {stranger:?}"); + assert!(!notice(&stranger, "Last seen"), "stranger no longer sees last-seen: {stranger:?}"); + assert!(notice(&send(&mut e, "000AAAAAA", "INFO"), "Last seen"), "owner still sees their own last-seen"); + + // Turn it off: public again. + assert!(notice(&send(&mut e, "000AAAAAA", "SET HIDE STATUS OFF"), "visible"), "unhide confirmed"); + assert!(notice(&send(&mut e, "000AAAAAB", "INFO alice"), "Last seen"), "last-seen public again"); + } + // SET EMAIL stores an email; SET PASSWORD defers derivation, and once // completed the new password authenticates and the old one no longer does. #[test] diff --git a/src/grpc.rs b/src/grpc.rs index c679dff..cbeda38 100644 --- a/src/grpc.rs +++ b/src/grpc.rs @@ -130,6 +130,7 @@ fn to_wire(entry: &LogEntry) -> Option { | Event::AccountGreetSet { .. } | Event::AccountAutoOpSet { .. } | Event::AccountKillSet { .. } + | Event::AccountHideStatusSet { .. } | Event::AjoinAdded { .. } | Event::AjoinRemoved { .. } | Event::VhostSet { .. } @@ -463,7 +464,7 @@ mod tests { memo_ignore: vec![], memo_notify: true, memo_limit: None, - greet: String::new(), no_autoop: false, no_protect: false, + greet: String::new(), no_autoop: false, no_protect: false, hide_status: false, vhost: None, vhost_request: None, last_seen: 111,