Compare commits

...

5 Commits

Author SHA1 Message Date
missytake
0bea4fad3f plan: persistence is achieved 2023-10-14 00:22:47 +02:00
missytake
446bb3483b dovecot: run auth-worker as vmail user 2023-10-14 00:11:03 +02:00
missytake
cb5c5de154 doveauth: adjust pytest for persistent database 2023-10-14 00:07:00 +02:00
missytake
6be51aa4df doveauth: integrate sqlite database 2023-10-14 00:04:57 +02:00
missytake
f76ddf0e22 doveauth: add sqlite database to persist accounts 2023-10-14 00:04:27 +02:00
5 changed files with 184 additions and 26 deletions

View File

@@ -88,7 +88,7 @@ service auth {
service auth-worker { service auth-worker {
# Default is root. # Default is root.
# Drop privileges we don't need. # Drop privileges we don't need.
user = $default_internal_user user = vmail
} }
ssl = required ssl = required

View File

@@ -0,0 +1,153 @@
import sqlite3
import contextlib
import time
from pathlib import Path
class DBError(Exception):
"""error during an operation on the database."""
class Connection:
def __init__(self, sqlconn, write):
self._sqlconn = sqlconn
self._write = write
def close(self):
self._sqlconn.close()
def commit(self):
self._sqlconn.commit()
def rollback(self):
self._sqlconn.rollback()
def execute(self, query, params=()):
cur = self.cursor()
try:
cur.execute(query, params)
except sqlite3.IntegrityError as e:
raise DBError(e)
return cur
def cursor(self):
return self._sqlconn.cursor()
def create_user(self, addr: str, password: str):
"""Create a row in the users table."""
self.execute("PRAGMA foreign_keys=on;")
q = """INSERT INTO users (addr, password, last_login)
VALUES (?, ?, ?)"""
self.execute(q, (addr, password, int(time.time())))
def get_user(self, addr: str) -> {}:
"""Get a row from the users table."""
q = "SELECT addr, password, last_login from users WHERE addr = ?"
row = self._sqlconn.execute(q, (addr,)).fetchone()
result = {}
if row:
result = dict(
user=row[0],
password=row[1],
last_login=row[2],
)
return result
def set_config(self, name: str, value: str) -> str:
ok = [
"dbversion",
]
assert name in ok, name
q = "INSERT OR REPLACE INTO config (key, value) VALUES (?, ?)"
self.cursor().execute(q, (name, value)).fetchone()
return value
def get_config(self, key: str) -> str:
q = "SELECT key, value from config WHERE name = ?"
c = self._sqlconn.cursor()
try:
return c.execute(q, key).fetchone()
except sqlite3.OperationalError:
return None
class Database:
def __init__(self, path: str):
self.path = Path(path)
self.ensure_tables()
def _get_connection(self, write=False, transaction=False, closing=False) -> Connection:
# we let the database serialize all writers at connection time
# to play it very safe (we don't have massive amounts of writes).
mode = "ro"
if write:
mode = "rw"
if not self.path.exists():
mode = "rwc"
uri = "file:%s?mode=%s" % (self.path, mode)
sqlconn = sqlite3.connect(
uri,
timeout=60,
isolation_level=None if transaction else "DEFERRED",
uri=True,
)
# Enable Write-Ahead Logging to avoid readers blocking writers and vice versa.
if write:
sqlconn.execute("PRAGMA journal_mode=wal")
if transaction:
start_time = time.time()
while 1:
try:
sqlconn.execute("begin immediate")
break
except sqlite3.OperationalError:
# another thread may be writing, give it a chance to finish
time.sleep(0.1)
if time.time() - start_time > 5:
# if it takes this long, something is wrong
raise
conn = Connection(sqlconn, write=write)
if closing:
conn = contextlib.closing(conn)
return conn
@contextlib.contextmanager
def write_transaction(self):
conn = self._get_connection(closing=False, write=True, transaction=True)
try:
yield conn
except Exception:
conn.rollback()
conn.close()
raise
else:
conn.commit()
conn.close()
def read_connection(self, closing=True) -> Connection:
return self._get_connection(closing=closing, write=False)
CURRENT_DBVERSION = 1
def ensure_tables(self):
with self.write_transaction() as conn:
conn.execute(
"""
CREATE TABLE IF NOT EXISTS users (
addr TEXT PRIMARY KEY,
password TEXT,
last_login INTEGER
)
""",
)
conn.execute(
"""
CREATE TABLE IF NOT EXISTS config (
key TEXT PRIMARY KEY,
value TEXT
)
""",
)
conn.set_config("dbversion", self.CURRENT_DBVERSION)

View File

@@ -2,37 +2,40 @@
import base64 import base64
import sys import sys
from .database import Database
def get_user_data(user):
if user.startswith("link2xt@"):
return dict(
uid="vmail",
gid="vmail",
password="Ahyei6ie",
)
return {}
def create_user(user, password): def get_user_data(db, user):
with db.read_connection() as conn:
result = conn.get_user(user)
if result:
result['uid'] = "vmail"
result['gid'] = "vmail"
return result
def create_user(db, user, password):
with db.write_transaction() as conn:
conn.create_user(user, password)
return dict(home=f"/home/vmail/{user}", uid="vmail", gid="vmail", password=password) return dict(home=f"/home/vmail/{user}", uid="vmail", gid="vmail", password=password)
def verify_user(user, password): def verify_user(db, user, password):
userdata = get_user_data(user) userdata = get_user_data(db, user)
if userdata: if userdata:
if userdata.get("password") == password: if userdata.get("password") == password:
userdata["status"] = "ok" userdata["status"] = "ok"
else: else:
userdata["status"] = "fail" userdata["status"] = "fail"
else: else:
userdata = create_user(user, password) userdata = create_user(db, user, password)
userdata["status"] = "ok" userdata["status"] = "ok"
return userdata return userdata
def lookup_user(user): def lookup_user(db, user):
userdata = get_user_data(user) userdata = get_user_data(db, user)
if userdata: if userdata:
userdata["status"] = "ok" userdata["status"] = "ok"
else: else:
@@ -46,14 +49,15 @@ def dump_result(res):
def main(): def main():
db = Database("/home/vmail/passdb.sqlite")
if sys.argv[1] == "hexauth": if sys.argv[1] == "hexauth":
login = base64.b16decode(sys.argv[2]).decode() login = base64.b16decode(sys.argv[2]).decode()
password = base64.b16decode(sys.argv[3]).decode() password = base64.b16decode(sys.argv[3]).decode()
res = verify_user(login, password) res = verify_user(db, login, password)
dump_result(res) dump_result(res)
elif sys.argv[1] == "hexlookup": elif sys.argv[1] == "hexlookup":
login = base64.b16decode(sys.argv[2]).decode() login = base64.b16decode(sys.argv[2]).decode()
res = lookup_user(login) res = lookup_user(db, login)
dump_result(res) dump_result(res)

View File

@@ -1,19 +1,21 @@
import subprocess import subprocess
import pytest import pytest
from doveauth.doveauth import get_user_data, verify_user from doveauth.doveauth import get_user_data, verify_user, Database
def test_basic(): def test_basic(tmpdir):
data = get_user_data("link2xt@c1.testrun.org") db = Database(tmpdir / "passdb.sqlite")
verify_user(db, "link2xt@c1.testrun.org", "asdf")
data = get_user_data(db, "link2xt@c1.testrun.org")
assert data assert data
@pytest.mark.xfail(reason="no persistence yet") def test_verify_or_create(tmpdir):
def test_verify_or_create(): db = Database(tmpdir / "passdb.sqlite")
res = verify_user("newuser1@something.org", "kajdlkajsldk12l3kj1983") res = verify_user(db, "newuser1@something.org", "kajdlkajsldk12l3kj1983")
assert res["status"] == "ok" assert res["status"] == "ok"
res = verify_user("newuser1@something.org", "kajdlqweqwe") res = verify_user(db, "newuser1@something.org", "kajdlqweqwe")
assert res["status"] == "fail" assert res["status"] == "fail"

View File

@@ -3,7 +3,6 @@
## Dovecot goals/steps ## Dovecot goals/steps
1. create-user-on-login ("doveauth") 1. create-user-on-login ("doveauth")
- persistence of accounts
2. per-user quota (adaptive) 2. per-user quota (adaptive)