HostServ: forbidden-vhost patterns + auto-vhost template
FORBID <regex> / FORBIDLIST / FORBIDDEL let operators block impersonating user requests (e.g. (?i)(admin|staff)); REQUEST refuses a matching host. Matching reuses the linear-time RegexSet, so untrusted patterns are safe. TEMPLATE <$account...> sets a network auto-vhost pattern; DEFAULT gives a user $account.users.example with their sanitised account name. HostServ's node config (offers/forbidden/template) is consolidated into one HostConfig threaded through the log replay.
This commit is contained in:
parent
2c32dcdc63
commit
6a8e02f004
9 changed files with 302 additions and 22 deletions
32
hostserv/src/default.rs
Normal file
32
hostserv/src/default.rs
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
use fedserv_api::{Sender, ServiceCtx, Store};
|
||||
|
||||
// DEFAULT: give yourself the auto-vhost from the network template, with your
|
||||
// account name substituted for $account.
|
||||
pub fn handle(me: &str, from: &Sender, ctx: &mut ServiceCtx, db: &mut dyn Store) {
|
||||
let Some(account) = from.account else {
|
||||
ctx.notice(me, from.uid, "You need to identify to NickServ first.");
|
||||
return;
|
||||
};
|
||||
let Some(template) = db.vhost_template() else {
|
||||
ctx.notice(me, from.uid, "This network has no auto-vhost template.");
|
||||
return;
|
||||
};
|
||||
// Sanitise the account into a host-safe label (lowercase, alphanumerics only).
|
||||
let label: String = account.to_ascii_lowercase().chars().filter(|c| c.is_ascii_alphanumeric()).collect();
|
||||
if label.is_empty() {
|
||||
ctx.notice(me, from.uid, "Your account name has no usable characters for a vhost.");
|
||||
return;
|
||||
}
|
||||
let host = template.replace("$account", &label);
|
||||
if !super::valid_vhost(&host) || db.vhost_is_forbidden(&host) {
|
||||
ctx.notice(me, from.uid, "Sorry, a vhost couldn't be generated for your account.");
|
||||
return;
|
||||
}
|
||||
match db.set_vhost(account, &host, "template") {
|
||||
Ok(()) => {
|
||||
ctx.apply_vhost(from.uid, &host);
|
||||
ctx.notice(me, from.uid, format!("You now have the vhost \x02{host}\x02."));
|
||||
}
|
||||
Err(_) => ctx.notice(me, from.uid, "Sorry, that didn't work. Please try again in a moment."),
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue