Home | History | Annotate | Line # | Download | only in pam_ftpusers
pam_ftpusers.c revision 1.1
      1  1.1  christos /*-
      2  1.1  christos  * Copyright (c) 2001 Networks Associates Technology, Inc.
      3  1.1  christos  * All rights reserved.
      4  1.1  christos  *
      5  1.1  christos  * This software was developed for the FreeBSD Project by ThinkSec AS and
      6  1.1  christos  * NAI Labs, the Security Research Division of Network Associates, Inc.
      7  1.1  christos  * under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"), as part of the
      8  1.1  christos  * DARPA CHATS research program.
      9  1.1  christos  *
     10  1.1  christos  * Redistribution and use in source and binary forms, with or without
     11  1.1  christos  * modification, are permitted provided that the following conditions
     12  1.1  christos  * are met:
     13  1.1  christos  * 1. Redistributions of source code must retain the above copyright
     14  1.1  christos  *    notice, this list of conditions and the following disclaimer.
     15  1.1  christos  * 2. Redistributions in binary form must reproduce the above copyright
     16  1.1  christos  *    notice, this list of conditions and the following disclaimer in the
     17  1.1  christos  *    documentation and/or other materials provided with the distribution.
     18  1.1  christos  * 3. The name of the author may not be used to endorse or promote
     19  1.1  christos  *    products derived from this software without specific prior written
     20  1.1  christos  *    permission.
     21  1.1  christos  *
     22  1.1  christos  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
     23  1.1  christos  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     24  1.1  christos  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     25  1.1  christos  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
     26  1.1  christos  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     27  1.1  christos  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     28  1.1  christos  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     29  1.1  christos  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     30  1.1  christos  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     31  1.1  christos  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     32  1.1  christos  * SUCH DAMAGE.
     33  1.1  christos  */
     34  1.1  christos 
     35  1.1  christos #include <sys/cdefs.h>
     36  1.1  christos __FBSDID("$FreeBSD: src/lib/libpam/modules/pam_ftpusers/pam_ftpusers.c,v 1.1 2002/05/08 00:30:10 des Exp $");
     37  1.1  christos 
     38  1.1  christos #include <ctype.h>
     39  1.1  christos #include <grp.h>
     40  1.1  christos #include <paths.h>
     41  1.1  christos #include <pwd.h>
     42  1.1  christos #include <stdio.h>
     43  1.1  christos #include <stdlib.h>
     44  1.1  christos #include <string.h>
     45  1.1  christos 
     46  1.1  christos #define PAM_SM_ACCOUNT
     47  1.1  christos 
     48  1.1  christos #include <security/pam_appl.h>
     49  1.1  christos #include <security/pam_modules.h>
     50  1.1  christos #include <security/pam_mod_misc.h>
     51  1.1  christos #include <security/openpam.h>
     52  1.1  christos 
     53  1.1  christos PAM_EXTERN int
     54  1.1  christos pam_sm_acct_mgmt(pam_handle_t *pamh, int flags __unused,
     55  1.1  christos     int argc __unused, const char *argv[] __unused)
     56  1.1  christos {
     57  1.1  christos 	struct passwd *pwd;
     58  1.1  christos 	struct group *grp;
     59  1.1  christos 	const char *user;
     60  1.1  christos 	int pam_err, found, allow;
     61  1.1  christos 	char *line, *name, **mem;
     62  1.1  christos 	size_t len, ulen;
     63  1.1  christos 	FILE *f;
     64  1.1  christos 
     65  1.1  christos 	pam_err = pam_get_user(pamh, &user, NULL);
     66  1.1  christos 	if (pam_err != PAM_SUCCESS)
     67  1.1  christos 		return (pam_err);
     68  1.1  christos 	if (user == NULL || (pwd = getpwnam(user)) == NULL)
     69  1.1  christos 		return (PAM_SERVICE_ERR);
     70  1.1  christos 
     71  1.1  christos 	found = 0;
     72  1.1  christos 	ulen = strlen(user);
     73  1.1  christos 	if ((f = fopen(_PATH_FTPUSERS, "r")) == NULL) {
     74  1.1  christos 		PAM_LOG("%s: %m", _PATH_FTPUSERS);
     75  1.1  christos 		goto done;
     76  1.1  christos 	}
     77  1.1  christos 	while (!found && (line = fgetln(f, &len)) != NULL) {
     78  1.1  christos 		if (*line == '#')
     79  1.1  christos 			continue;
     80  1.1  christos 		while (len > 0 && isspace(line[len - 1]))
     81  1.1  christos 			--len;
     82  1.1  christos 		if (len == 0)
     83  1.1  christos 			continue;
     84  1.1  christos 		/* simple case first */
     85  1.1  christos 		if (*line != '@') {
     86  1.1  christos 			if (len == ulen && strncmp(user, line, len) == 0)
     87  1.1  christos 				found = 1;
     88  1.1  christos 			continue;
     89  1.1  christos 		}
     90  1.1  christos 		/* member of specified group? */
     91  1.1  christos 		asprintf(&name, "%.*s", (int)len - 1, line + 1);
     92  1.1  christos 		if (name == NULL) {
     93  1.1  christos 			fclose(f);
     94  1.1  christos 			return (PAM_BUF_ERR);
     95  1.1  christos 		}
     96  1.1  christos 		grp = getgrnam(name);
     97  1.1  christos 		free(name);
     98  1.1  christos 		if (grp == NULL)
     99  1.1  christos 			continue;
    100  1.1  christos 		for (mem = grp->gr_mem; mem && *mem && !found; ++mem)
    101  1.1  christos 			if (strcmp(user, *mem) == 0)
    102  1.1  christos 				found = 1;
    103  1.1  christos 	}
    104  1.1  christos  done:
    105  1.1  christos 	allow = (openpam_get_option(pamh, "disallow") == NULL);
    106  1.1  christos 	if (found)
    107  1.1  christos 		pam_err = allow ? PAM_SUCCESS : PAM_AUTH_ERR;
    108  1.1  christos 	else
    109  1.1  christos 		pam_err = allow ? PAM_AUTH_ERR : PAM_SUCCESS;
    110  1.1  christos 	if (f != NULL)
    111  1.1  christos 		fclose(f);
    112  1.1  christos 	return (pam_err);
    113  1.1  christos }
    114  1.1  christos 
    115  1.1  christos PAM_MODULE_ENTRY("pam_ftpusers");
    116