aboutsummaryrefslogtreecommitdiffstats
path: root/fripost-adduser
blob: fc37489fd018da9aa76c2aecfe57f7da4f99d500 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
#!/usr/bin/perl

use 5.010_000;
use strict;
use warnings;
use utf8;

=head1 NAME

fripost-adduser - Add a new mailbox to the system

=head1 SYNOPSIS

B<fripost-adduser> [B<--verbose>] [B<--debug>] [B<--pretend>] [I<username>]
[B<--password=>I<password>]

=head1 DESCRIPTION

B<fripost-adduser> adds a new virtual mailbox to the system, unless
B<--pretend> is set.
If I<username> or I<password> are not given, the user is prompted for
them.
If I<username> is not fully qualified, C<fripost.org> is appended.
If I<username> is already an existing username or alias,
B<fripost-adduser> raises an error.

=head1 OPTIONS

=over 8

=item B<--pretend>

Only simulates the insertion. (But still query the LDAP server to ensure
that I<username> is not already in the database.)

=item B<--password=>I<password>

By default, the user is prompted for his/her new password, which is
hashed, salted and then added to the LDAP entry.
By using B<--password>, I<password> is inserted RAW in the database.
This can be useful if the user does not want to give the clear copy but
only a hash, for example.
Using this option disables the sending of credentials.

=item B<--server_host=>I<host>

The LDAP URI to connect to.
The default value is read from the configuration file, see B<CONFIGURATION>.

=item B<--bind_dn=>I<binddn>

The Distinguished Name (DN) to bind to the LDAP directory.
(If not set, B<fripost-adduser> binds anonymously.)
The default value is read from the configuration file, see B<CONFIGURATION>.

=item B<--bind_pw=>I<password>

The password to to bind with.
The default value is read from the configuration file, see B<CONFIGURATION>.

=item B<--base_dn=>I<basedn>

The root DN for everything done by B<fripost-adduser>.
The default value is read from the configuration file, see B<CONFIGURATION>.

=item B<-v>, B<--verbose>

Verbose mode.

=item B<--debug>

Debug mode.

=back

=head1 CONFIGURATION

The configuration is read from the file C<$HOME/.fripost.yml>.
Valid keys include:

=over 4

=item I<server_host>

The LDAP URI to connect to. Defaults to C<ldap://127.0.0.1:389>.

=item I<admin_email>

The I<From:> e-mail address to use. Defaults to C<admin@fripost.org>.

=item I<bind_dn>

The Distinguished Name (DN) to bind to the LDAP directory.
(If not set, B<fripost-adduser> binds anonymously.)

=item I<bind_pw>

The password to to bind with.

=item I<base_dn>

The root DN for everything done by B<fripost-adduser>.

=back

=cut

use FindBin qw($Bin);
use lib "$Bin/lib";

use Env qw /HOME/;
use File::Spec::Functions;

use Data::Dumper;
use Encode qw(encode);
use File::Slurp qw(slurp);
use Fripost::Password;
use Fripost::Prompt;
use Fripost::Schema;
use Getopt::Long qw /:config noauto_abbrev no_ignore_case
                             gnu_compat bundling permute nogetopt_compat
                             auto_version auto_help/;
use Pod::Usage;
use MIME::Lite;
use MIME::QuotedPrint;
use Template;
use YAML::Syck;


## Get command line options
our $conf = LoadFile( catfile ($HOME, '.fripost.yml') );

GetOptions(
    'server_host=s' => \$conf->{server_host},
    'base_dn=s'     => \$conf->{base_dn},
    'bind_dn=s'     => \$conf->{bind_dn},
    'bind_pw=s'     => \$conf->{bind_pw},
    'pretend'       => \$conf->{pretend},
    'debug'         => \$conf->{debug},
    'v|verbose'     => \$conf->{verbose},
    'password=s'    => \$conf->{password},
    'man'           => sub { pod2usage(-exitstatus => 0,
                                       -verbose => 2) }
) or pod2usage(2);

sub dsay { say STDERR @_ if $conf->{debug}; }
sub vsay { say STDERR @_ if $conf->{verbose} || $conf->{debug}; }


# Connect to the LDAP server
my $ldap = Fripost::Schema->new( $conf );


# Define the new user
my $user;
my ($domain, $login);
{
    my $username;
    if (defined $ARGV[0]) {
        $username = fix_username ($ARGV[0]);
        Email::Valid->address($username)
            or die "Error: $username is not a valid e-mail.\n";
    }
    else {
        $username = prompt_email("New username: ", 'is_user');
    }
    ($login, $domain) = split /\@/, $username, 2;
    my $isActive     = 'TRUE';
    my ($userPassword, $clearPassword);
    if ( defined $conf->{password} ) {
        $userPassword  = $conf->{password};
    }
    else {
        $clearPassword = prompt_password();
        $userPassword  = hash( $clearPassword );
    }

    $user = {
        username      => $username,
        isActive      => $isActive,
        userPassword  => $userPassword,
    };
    $user->{clearPassword} = $clearPassword unless defined $conf->{password};

    say "User name: $user->{username}";
    say "Password:  (hidden)";

    confirm_or_abort();
}


{
    # Error if the domain is unknown.
    die "Error: Unknown domain `" .$domain. "'.\n"
        unless $ldap->domain->search({ domain => $domain })->count;

    # Ensure that the username doesn't already exist.
    die "Error: User `" .$user->{username}. "' already exists.\n"
        if $ldap->user->search({ username => $user->{username} })->count;

    # Ensure that the username doesn't correspond to an existing alias.
    my $res = $ldap->alias->search({ address => $user->{username} });
    if ($res->count) {
        print STDERR "Error: Alias $user->{username} already exists. ";
        print STDERR "(Targetting to ";
        print STDERR (join ', ', map { $_->{goto} } $res->entries);
        say STDERR ".)";
        exit 1;
    }
}


## Insert the new user
if ($conf->{pretend}) {
    vsay "Did not create user since we are pretending.";
}
else {
    my %user = %$user;
    delete $user{clearPassword};
    $ldap->user->add(\%user);
    say "New account $user{username} added.";
}

$ldap->unbind();



### Prepare sending emails

my $tt = Template->new({
    INCLUDE_PATH => "$Bin/templ",
    INTERPOLATE  => 1,
}) || die "$Template::ERROR\n";

my $admin_email = $conf->{admin_email};
$admin_email  //= 'admin@fripost.org';
my $msg = MIME::Lite->new(

    From    => encode('MIME-Q', 'Friposts administratörer') . ' <' .$admin_email. '>',
    Subject => encode('MIME-Q', 'Välkommen till Fripost!'),
    Encoding => 'quoted-printable',
);

$msg->attr('content-type.charset' => 'utf-8');

### Send welcome email to new user
{
    my ($vars, $data);
    $vars = {};

    $tt->process('new_user_mail.tt', $vars, \$data)
        || die $tt->error(), '\n';
    $msg->data($data);

    $msg->replace(To => $user->{username});

    unless ($conf->{pretend}) {
        $msg->send() unless $conf->{pretend};
        say "Sent welcome message.";
    }
    dsay "-----------------------------------";
    dsay "| Welcome mail                    |";
    dsay "-----------------------------------";
    dsay decode_qp($msg->as_string);
    dsay "-----------------------------------";
}

### Subscribe user to announce-list
if (confirm("Subscribe user to announce mailing list? ")) {
    $msg->replace(From => $user->{username});
    $msg->replace(To => 'announce-subscribe@lists.fripost.org');
    $msg->replace(Subject => '');
    $msg->replace(Data => '');
    $msg->send();
}

### Send login credentials to new user
if (exists $user->{clearPassword}) {
    my ($vars, $data);
    $vars = {
        user => $user->{username},
        pass => $user->{clearPassword},
    };

    $tt->process('user_info.tt', $vars, \$data)
        || die $tt->error(), '\n';
    $msg->data($data);

    dsay "-----------------------------------";
    dsay "| Login credentials mail          |";
    dsay "-----------------------------------";
    dsay decode_qp($msg->as_string);
    dsay "-----------------------------------";

    confirm_or_abort("Send email with login information? ");
    my $to = prompt_email("Where should the email be sent? ");
    $msg->replace(To => $to);

    if (!$conf->{pretend}) {
        $msg->send;
        say "Credentials sent.";
    }
    else {
        say "Pretending, will not send credentials.";
    }
}

=head1 AUTHOR

Stefan Kangas C<< <skangas at skangas.se> >>

Guilhem Moulin C<< <guilhem at fripost.org> >>

=head1 COPYRIGHT

Copyright 2010,2011 Stefan Kangas.

Copyright 2012 Guilhem Moulin.

=head1 LICENSE

This program is free software; you can redistribute it and/or modify it
under the same terms as perl itself.

=cut