author | Paul Crowley <paul@lshift.net> |
Mon, 12 Oct 2009 16:04:07 +0100 | |
changeset 106 | 0519745e7a57 |
parent 86 | 78777f509303 |
child 107 | 84e9e33d866b |
permissions | -rw-r--r-- |
74
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
1 |
# Copyright 2008-2009 LShift Ltd |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
2 |
|
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
3 |
# WARNING |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
4 |
# This hook completely destroys your ~/.ssh/authorized_keys |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
5 |
# file every time it is run |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
6 |
# WARNING |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
7 |
|
106
0519745e7a57
Much less strict about most things
Paul Crowley <paul@lshift.net>
parents:
86
diff
changeset
|
8 |
import re |
74
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
9 |
import os |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
10 |
import os.path |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
11 |
import pwd |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
12 |
import subprocess |
106
0519745e7a57
Much less strict about most things
Paul Crowley <paul@lshift.net>
parents:
86
diff
changeset
|
13 |
from mercurialserver import paths |
0519745e7a57
Much less strict about most things
Paul Crowley <paul@lshift.net>
parents:
86
diff
changeset
|
14 |
|
0519745e7a57
Much less strict about most things
Paul Crowley <paul@lshift.net>
parents:
86
diff
changeset
|
15 |
goodkey = re.compile("[A-Za-z0-9._-]+$") |
74
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
16 |
|
86
78777f509303
Move check for hg user where it belongs
Paul Crowley <paul@lshift.net>
parents:
85
diff
changeset
|
17 |
def refreshAuth(pw_dir): |
78777f509303
Move check for hg user where it belongs
Paul Crowley <paul@lshift.net>
parents:
85
diff
changeset
|
18 |
akeyfile = pw_dir + "/.ssh/authorized_keys" |
79 | 19 |
wrappercommand = paths.getExePath() + "/hg-ssh" |
86
78777f509303
Move check for hg user where it belongs
Paul Crowley <paul@lshift.net>
parents:
85
diff
changeset
|
20 |
keydirs = [paths.getEtcPath() + "/keys", pw_dir + "/repos/hgadmin/keys"] |
74
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
21 |
prefix='no-pty,no-port-forwarding,no-X11-forwarding,no-agent-forwarding,command=' |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
22 |
|
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
23 |
if os.path.exists(akeyfile): |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
24 |
f = open(akeyfile) |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
25 |
try: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
26 |
for l in f: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
27 |
if not l.startswith(prefix): |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
28 |
raise Exception("Safety check failed, delete %s to continue" % akeyfile) |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
29 |
finally: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
30 |
f.close() |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
31 |
|
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
32 |
akeys = open(akeyfile + "_new", "w") |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
33 |
for keyroot in keydirs: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
34 |
kr = keyroot + "/" |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
35 |
#print "Processing keyroot", keyroot |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
36 |
for root, dirs, files in os.walk(keyroot): |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
37 |
for fn in files: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
38 |
ffn = os.path.join(root, fn) |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
39 |
if not ffn.startswith(kr): |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
40 |
raise Exception("Inconsistent behaviour in os.walk, bailing") |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
41 |
#print "Processing file", ffn |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
42 |
keyname = ffn[len(kr):] |
106
0519745e7a57
Much less strict about most things
Paul Crowley <paul@lshift.net>
parents:
86
diff
changeset
|
43 |
# FIXME: still too strict |
0519745e7a57
Much less strict about most things
Paul Crowley <paul@lshift.net>
parents:
86
diff
changeset
|
44 |
if not goodkey.match(keyname) |
74
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
45 |
# ignore any path that contains dodgy characters |
106
0519745e7a57
Much less strict about most things
Paul Crowley <paul@lshift.net>
parents:
86
diff
changeset
|
46 |
print "Ignoring key that contains banned character:", ffn |
74
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
47 |
continue |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
48 |
p = subprocess.Popen(("ssh-keygen", "-i", "-f", ffn), |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
49 |
stdout=subprocess.PIPE, stderr=subprocess.PIPE) |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
50 |
newkey = p.communicate()[0] |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
51 |
if p.wait() == 0: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
52 |
klines = [l.strip() for l in newkey.split("\n")] |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
53 |
else: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
54 |
# Conversion failed, read it directly. |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
55 |
kf = open(ffn) |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
56 |
try: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
57 |
klines = [l.strip() for l in kf] |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
58 |
finally: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
59 |
kf.close() |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
60 |
for l in klines: |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
61 |
if len(l): |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
62 |
akeys.write('%s"%s %s" %s\n' % (prefix, wrappercommand, keyname, l)) |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
63 |
akeys.close() |
9d2ae2841bf2
Move meat of do-refresh-auth into a module
Paul Crowley <paul@lshift.net>
parents:
diff
changeset
|
64 |
os.rename(akeyfile + "_new", akeyfile) |
75
5af89523a9d3
give refreshauth.py a hook and call that in hgadmin hgrc
Paul Crowley <paul@lshift.net>
parents:
74
diff
changeset
|
65 |
|
5af89523a9d3
give refreshauth.py a hook and call that in hgadmin hgrc
Paul Crowley <paul@lshift.net>
parents:
74
diff
changeset
|
66 |
def hook(ui, repo, hooktype, node=None, source=None, **kwargs): |
86
78777f509303
Move check for hg user where it belongs
Paul Crowley <paul@lshift.net>
parents:
85
diff
changeset
|
67 |
pentry = pwd.getpwuid(os.geteuid()) |
78777f509303
Move check for hg user where it belongs
Paul Crowley <paul@lshift.net>
parents:
85
diff
changeset
|
68 |
refreshAuth(pentry.pw_dir) |
75
5af89523a9d3
give refreshauth.py a hook and call that in hgadmin hgrc
Paul Crowley <paul@lshift.net>
parents:
74
diff
changeset
|
69 |