additional optimizations and permission handling

Optimizations for handling XMPP data and commands

Basic permission handling - Add fuid users to bot
- Ozmo has ACLs and an "owner", if bot comes from eco to bumper the fuid_user won't have permissions
- Bumper will add the fuid_ user to bot ACLs and grant full
  - This can be used later when bumper adds proper auth to allow/block users
This commit is contained in:
Brian Martin 2019-02-27 09:05:23 -05:00
parent af29f69a99
commit a7ce14eb9c
2 changed files with 249 additions and 214 deletions

View file

@ -652,7 +652,9 @@ class ConfServer:
json_body = json.loads(await request.text())
randomid = "".join(random.sample(string.ascii_letters, 6))
bots = self.bumper_bots.get()
if "toId" in json_body: #Its a command
for bot in bots:
if bot.company == 'eco-ng':
if bot.did == json_body["toId"] and bot.mqtt_connection == True:
retcmd = await self.helperbot.send_command(json_body, randomid)
body = retcmd
@ -660,7 +662,8 @@ class ConfServer:
"\r\n POST: {} \r\n Response: {}".format(json_body, body)
)
return web.json_response(body)
else:
#No response, send error back
confserverlog.error(
"No bots with DID: {} connected to MQTT".format(
json_body["toId"]
@ -668,6 +671,13 @@ class ConfServer:
)
body = {"id": randomid, "errno": bumper.ERR_COMMON, "ret": "fail"}
return web.json_response(body)
else:
if "td" in json_body: #Seen when doing initial wifi config
if json_body["td"] == "PollSCResult":
body = {
"ret": "ok"
}
return web.json_response(body)
except Exception as e:
confserverlog.exception("{}".format(e))

View file

@ -11,8 +11,7 @@ xmppserverlog = logging.getLogger("xmppserver")
class XMPPServer:
server_id = "bumper"
bot_id = "bumpy"
server_id = "ecouser.net"
client_id = None
clients = []
exit_flag = False
@ -218,7 +217,7 @@ class Client(threading.Thread):
except BrokenPipeError as e:
xmppserverlog.error("{}".format(e))
# self._set_state('DISCONNECT')
self._set_state('DISCONNECT')
except ConnectionResetError as e:
xmppserverlog.error("{}".format(e))
@ -282,7 +281,7 @@ class Client(threading.Thread):
def _handle_ctl(self, xml, data):
try:
if data.decode("utf-8").find("roster") > -1:
if "roster" in data:
# Return not-implemented for roster
self.send(
'<iq type="error" id="{}"><error type="cancel" code="501"><feature-not-implemented xmlns="urn:ietf:params:xml:ns:xmpp-stanzas"/></error></iq>'.format(
@ -293,7 +292,7 @@ class Client(threading.Thread):
if xml.get("type") == "set":
if (
data.decode("utf-8").find("com:sf") > -1
"com:sf" in data
and xml.get("to") == "rl.ecorobot.net"
): # Android bind? Not sure what this does yet.
self.send(
@ -305,11 +304,6 @@ class Client(threading.Thread):
)
)
#else:
# xmppserverlog.debug(
# "Unknown set type: {}".format(data.decode("utf-8"))
# )
if xml[0][0]:
ctl = xml[0][0]
if ctl.get("admin") and self.type == self.BOT:
@ -322,11 +316,8 @@ class Client(threading.Thread):
# forward
for client in XMPPServer.clients:
if client.bumper_jid != self.bumper_jid and client.state == client.READY:
#if client.address != self.address and client.state == client.READY:
ctl_to = xml.get("to")
#xml.attrib["from"] = self.bumper_jid#.replace("@{}".format(XMPPServer.server_id),"@ecouser.net")
xml.attrib["from"] = "{}@ecouser.net".format(self.uid)
xml.attrib["from"] = "{}".format(self.bumper_jid)
rxmlstring = ET.tostring(xml).decode("utf-8")
#clean up string to remove namespaces added by ET
rxmlstring = rxmlstring.replace("xmlns:ns0=", "xmlns=")
@ -338,20 +329,7 @@ class Client(threading.Thread):
if client.uid.lower() in ctl_to.lower():
xmppserverlog.info("Sending ctl to bot: {}".format(rxmlstring))
client.send(rxmlstring)
#client.send(data.decode("utf-8"))
# data = data.decode("utf-8")
# id_index = data.find("id")
# if id_index > -1:
# data = (
# data[:id_index]
# + 'from="'
# + XMPPServer.client_id
# + '" '
# + data[id_index:]
# )
# data = data.encode()
# client.send(data.decode("utf-8"))
except Exception as e:
xmppserverlog.exception("{}".format(e))
@ -391,51 +369,75 @@ class Client(threading.Thread):
xmppserverlog.exception("{}".format(e))
def _handle_result(self, xml, data):
# forward
try:
ctl_to = xml.get("to")
xml.attrib["from"] = self.bumper_jid
if "errno='103' error='permission denied," in data: #No permissions, usually if bot was last on Ecovac network
if self.type == self.BOT:
xquery = xml.getchildren()
ctl = xquery[0].getchildren()
ctlerr = ctl[0].attrib["error"]
adminuser = ctlerr.replace("permission denied, please contact ","")
adminuser = adminuser.replace(" ","")
if not (adminuser.startswith("fuid_") or bumper.use_auth): #if not fuid_ then its ecovacs OR ignore bumper auth
#TODO: Implement auth later, should this user have access to bot?
#Add user jid to bot
newuser = ctl_to.split("/")[0]
adduser = '<iq type="set" id="{}" from="{}" to="{}"><query xmlns="com:ctl"><ctl td="AddUser" id="0000" jid="{}" /></query></iq>'.format(
uuid.uuid4(), adminuser, self.bumper_jid, newuser)
xmppserverlog.debug("Add User: {}".format(adduser))
self.send(adduser)
#Add user ACs - Manage users, settings, and clean (full access)
adduseracs = '<iq type="set" id="{}" from="{}" to="{}"><query xmlns="com:ctl"><ctl td="SetAC" id="1111" jid="{}"><acs><ac name="userman" allow="1"/><ac name="setting" allow="1"/><ac name="clean" allow="1"/></acs></ctl></query></iq>'.format(
uuid.uuid4(), adminuser, self.bumper_jid, newuser)
xmppserverlog.debug("Add User ACs: {}".format(adduseracs))
self.send(adduseracs)
#GetUserInfo - Just to confirm it set correctly
self.send(
'<iq type="set" id="{}" from="{}" to="{}"><query xmlns="com:ctl"><ctl td="GetUserInfo" id="4444" /><UserInfos/></query></iq>'.format(
uuid.uuid4(), adminuser, self.bumper_jid)
)
else:
rxmlstring = ET.tostring(xml).decode("utf-8")
#clean up string to remove namespaces added by ET
rxmlstring = rxmlstring.replace("xmlns:ns0=", "xmlns=")
rxmlstring = rxmlstring.replace("ns0:", "")
rxmlstring = rxmlstring.replace('iq xmlns="com:ctl"', "iq")
rxmlstring = rxmlstring.replace('<query','<query xmlns="com:ctl"')
if self.type == self.BOT:
if ctl_to == "de.ecorobot.net": #Send to all clients
xmppserverlog.info("Sending to all clients because of de: {}".format(rxmlstring))
xmppserverlog.debug("Sending to all clients because of de: {}".format(rxmlstring))
for client in XMPPServer.clients:
client.send(rxmlstring)
else:
if xml.get("to").find("@") == -1: #No to address
ctl_to = xml.get("to")
else:
ctl_to = "{}@ecouser.net".format(ctl_to.split("@")[0])
for client in XMPPServer.clients:
if client.bumper_jid != self.bumper_jid and client.state == client.READY:
if ctl_to:
if client.uid.lower() in ctl_to.lower():
#if ctl_to == client.bumper_jid:
xmppserverlog.info("Sending from {} to client {}: {}".format(self.uid, client.uid, rxmlstring))
client.send(rxmlstring)
#xmppserverlog.info("Sending to client: {}".format(data.decode("utf-8")))
#client.send(data.decode("utf-8"))
else: #no send to
#xmppserverlog.info("Sending to all clients: {}".format(rxmlstring))
if not "@" in ctl_to: #No user@, send to all clients?
#TODO: Revisit later, this may be wrong
client.send(rxmlstring)
#if client.address != self.address and client.state == client.READY:
#client.send(data.decode("utf-8"))
elif client.uid.lower() in ctl_to.lower(): #If client matches TO=
xmppserverlog.debug("Sending from {} to client {}: {}".format(self.uid, client.uid, rxmlstring))
client.send(rxmlstring)
except Exception as e:
xmppserverlog.exception("{}".format(e))
def _handle_connect(self, data):
def _handle_connect(self, data, xml=None):
try:
if self.state == self.CONNECT:
if xml == None:
# Client first connecting, send our features
if data.decode("utf-8").find("jabber:client") > -1:
sc = data.decode("utf-8").find("to=")
ec = data.decode("utf-8").find(".ecorobot.net")
@ -457,15 +459,19 @@ class Client(threading.Thread):
)
# self.send('<stream:features><auth xmlns="http://jabber.org/features/iq-auth"/></stream:features>')
elif data.decode("utf-8").find("jabber:iq:auth") > -1: # Handle iq-auth
self._handle_iq_auth(data)
else:
self.send("</stream>")
elif (
data.decode("utf-8").find("urn:ietf:params:xml:ns:xmpp-sasl") > -1
): # Handle SASL auth
self._handle_sasl_auth(data)
else:
if "jabber:iq:auth" in xml.tag: # Handle iq-auth
self._handle_iq_auth(xml)
elif "urn:ietf:params:xml:ns:xmpp-sasl" in xml.tag: #Handle SASL Auth
self._handle_sasl_auth(xml)
else:
xmppserverlog.error("Couldn't handle: {}".format(xml))
elif self.state == self.INIT:
if xml == None:
# Client getting session after authentication
if data.decode("utf-8").find("jabber:client") > -1:
# ack jabbr:client
@ -481,7 +487,6 @@ class Client(threading.Thread):
)
else: # Handle init bind
xml = ET.fromstring(data.decode("utf-8"))
if len(xml):
child = self._tag_strip_uri(xml[0].tag)
else:
@ -490,6 +495,10 @@ class Client(threading.Thread):
if xml.tag == "iq":
if child == "bind":
self._handle_bind(xml)
else:
xmppserverlog.error("Couldn't handle: {}".format(xml))
except Exception as e:
xmppserverlog.exception("{}".format(e))
@ -573,7 +582,7 @@ class Client(threading.Thread):
except ET.ParseError as e:
if "no element found" in e.msg:
xmppserverlog.debug(
"xml parse error - {} - {} - this is common with ecovac protocol".format(
"xml parse error - {} - {}".format(
data.decode("utf-8"), e
)
)
@ -589,9 +598,9 @@ class Client(threading.Thread):
except Exception as e:
xmppserverlog.exception("{}".format(e))
def _handle_sasl_auth(self, data):
def _handle_sasl_auth(self, xml):
try:
xml = ET.fromstring(data.decode("utf-8"))
saslauth = base64.b64decode(xml.text).decode("utf-8").split("/")
username = saslauth[0]
username = saslauth[0].split("\x00")[1]
@ -609,6 +618,7 @@ class Client(threading.Thread):
if not self.uid.startswith("fuid"):
# Need sample data to see details here
bumper.add_bot(self.uid, self.uid, self.devclass, "atom","eco-legacy")
self.type = self.BOT
xmppserverlog.info("bot authenticated {}".format(self.uid))
# Send response
self.send(
@ -626,6 +636,7 @@ class Client(threading.Thread):
auth = True
if auth:
self.type = self.CONTROLLER
bumper.add_client(self.uid, "bumper", self.clientresource)
xmppserverlog.debug("client authenticated {}".format(self.uid))
@ -643,22 +654,6 @@ class Client(threading.Thread):
'<response xmlns="urn:ietf:params:xml:ns:xmpp-sasl"/>'
) # Fail
except ET.ParseError as e:
if "no element found" in e.msg:
xmppserverlog.debug(
"xml parse error - {} - {} - this is common with ecovac protocol".format(
data.decode("utf-8"), e
)
)
elif "not well-formed (invalid token)" in e.msg:
xmppserverlog.debug(
"xml parse error - {} - {}".format(data.decode("utf-8"), e)
)
else:
xmppserverlog.debug(
"xml parse error - {} - {}".format(data.decode("utf-8"), e)
)
except Exception as e:
xmppserverlog.exception("{}".format(e))
@ -725,103 +720,148 @@ class Client(threading.Thread):
def _handle_presence(self, xml):
try:
if len(xml) and xml[0].tag == "status":
# bot announcing arrival
self.type = self.BOT
xmppserverlog.debug(
"{} type set to BOT (based on presence tag)".format(self.address)
"bot presence {} ".format(ET.tostring(xml, encoding="utf-8"))
)
# send a command from an unknown user - the response will contain the correct admin username
#Most likely a bot, possibly hello world in text
#Send dummy return
self.send(
'<presence to="{}"> dummy </presence>'.format(
self.bumper_jid
)
)
# self.send(
# '<iq type="set" id="14" to="{}@{}.{}/atom"><query xmlns="com:ctl"><ctl td="GetDeviceInfo"/></query></iq>'.format(
# self.uid, self.devclass, XMPPServer.server_id
# )
# )
#If it is a BOT, send extras
if self.type == self.BOT:
#get device info
self.send(
'<iq type="set" id="{}" from="{}" to="{}"><query xmlns="com:ctl"><ctl td="GetCleanState" /></query></iq>'.format(
uuid.uuid4(), "unknown@ecouser.net", XMPPServer.server_id
'<iq type="set" id="14" to="{}" from="{}"><query xmlns="com:ctl"><ctl td="GetDeviceInfo"/></query></iq>'.format(
self.bumper_jid, XMPPServer.server_id
)
)
else:
self.type = self.CONTROLLER
xmppserverlog.debug(
"{} type set to CONTROLLER (based on presence tag)".format(
self.address
"client presence - {} ".format(ET.tostring(xml, encoding="utf-8"))
)
if xml.get("type") == "available":
xmppserverlog.debug(
"client presence available - {} ".format(ET.tostring(xml, encoding="utf-8"))
)
#Send dummy return
self.send(
'<presence to="{}@{}/{}"> dummy </presence>'.format(
self.uid, XMPPServer.server_id, self.clientresource
'<presence to="{}"> dummy </presence>'.format(
self.bumper_jid
)
)
elif xml.get("type") == "unavailable":
xmppserverlog.debug(
"client presence unavailable (DISCONNECT) - {} ".format(ET.tostring(xml, encoding="utf-8"))
)
self._set_state("DISCONNECT")
else:
#Sometimes the android app sends these
xmppserverlog.debug(
"client presence (UNKNOWN) - {} ".format(ET.tostring(xml, encoding="utf-8"))
)
#Send dummy return
self.send(
'<presence to="{}"> dummy </presence>'.format(
self.bumper_jid
)
)
except Exception as e:
xmppserverlog.exception("{}".format(e))
def _parse_data(self, data):
if self.log_incoming_data:
xmppserverlog.debug(
"from {} - {}".format(self.address, data.decode("utf-8"))
)
if data.decode("utf-8").startswith("<?xml"): #Strip <?xml and add artificial root
newdata = re.sub(r"(<\?xml[^>]+\?>)", r"<root>",data.decode("utf-8")) + "</root>"
else:
newdata = "<root>{}</root>".format(data.decode("utf-8")) #Add artificial root
try:
xml = ET.fromstring(data.decode("utf-8"))
self._handle_xml(xml, data)
root = ET.fromstring(newdata)
for item in root.iter():
if item.tag != "root":
if item.tag == "iq":
if self.log_incoming_data:
xmppserverlog.debug(
"from {} - {}".format(self.address, str(ET.tostring(item, encoding="utf-8").decode("utf-8")).replace("ns0:",""))
)
self._handle_iq(item, newdata)
item.clear()
elif "auth" in item.tag:
if "urn:ietf:params:xml:ns:xmpp-sasl" in item.tag: #SASL Auth
self._handle_sasl_auth(item)
item.clear()
elif "presence" in item.tag:
self._handle_presence(item)
item.clear()
else:
if self.log_incoming_data:
xmppserverlog.debug(
"Unparsed Item - {}".format(str(ET.tostring(item, encoding="utf-8").decode("utf-8")).replace("ns0:",""))
)
print("e")
except ET.ParseError as e:
if (
"no element found" in e.msg
): # Element not closed or not all bytes received
# Happens wth connect stream often
if "<stream:stream " in data.decode("utf-8"):
if "<stream:stream " in newdata:
if self.state == self.CONNECT or self.state == self.INIT:
self._handle_connect(data)
self._handle_connect(newdata.encode("utf-8"))
else:
if not (data.decode("utf-8") == "" or data.decode("utf-8") == " "):
if not (newdata == "" or newdata == " "):
xmppserverlog.error(
"xml parse error - {} - {}".format(data.decode("utf-8"), e)
"xml parse error - {} - {}".format(newdata, e)
)
elif "not well-formed (invalid token)" in e.msg:
# If a lone </stream:stream> - client is signalling end of session/disconnect
if not "</stream:stream>" in data.decode("utf-8"):
if not "</stream:stream>" in newdata:
xmppserverlog.error(
"xml parse error - {} - {}".format(data.decode("utf-8"), e)
"xml parse error - {} - {}".format(newdata, e)
)
else:
self.send("</stream:stream>") # Close stream
elif (
"junk after document element" in e.msg
): # More than one xml doc in data
# try to split it
data0 = data.decode("utf-8")
data1 = data0[e.position[1] :]
data0 = data0[: e.position[1]]
# xmppserverlog.debug('xml parse error - {} - {} - split0: {} - split1: {}'.format(data.decode('utf-8'), e, data0, data1))
self._parse_data(data0.encode("utf-8"))
self._parse_data(data1.encode("utf-8"))
else:
if "<stream:stream" in newdata: #Handle start stream and connect
if self.state == self.CONNECT or self.state == self.INIT:
xmppserverlog.debug(
"xml parse error - {} - {}".format(data.decode("utf-8"), e)
"Handling connect data - {}".format(newdata)
)
self._handle_connect(newdata.encode("utf-8"))
else:
if not "</stream:stream>" in newdata:
xmppserverlog.error(
"xml parse error - {} - {}".format(newdata, e)
)
else:
self.send("</stream:stream>") # Close stream
self._set_state("DISCONNECT")
except Exception as e:
xmppserverlog.exception("{}".format(e))
def _handle_xml(self, xml, data):
def _handle_iq(self, xml, data):
try:
if self.state == self.CONNECT or self.state == self.INIT:
self._handle_connect(data)
if len(xml):
child = self._tag_strip_uri(xml[0].tag)
else:
@ -850,25 +890,20 @@ class Client(threading.Thread):
else:
self._handle_result(xml, data)
if xml.tag == "presence":
self._handle_presence(xml)
except Exception as e:
xmppserverlog.exception("{}".format(e))
def run(self):
# xmppserverlog.info('client connected - {}'.format(self.address))
self._set_state("CONNECT")
while not self.state == self.DISCONNECT and not self.connection._closed:
data = b""
time.sleep(0.2)
time.sleep(0.1)
if not self.connection._closed:
try:
#data = self.connection.recv(4096)
data = self.connection.recv(8192)
data = self.connection.recv(4096)
if data != b"":
self._parse_data(data)
except ConnectionResetError as e:
xmppserverlog.error("{}".format(e))
except OSError as e:
@ -876,15 +911,5 @@ class Client(threading.Thread):
except Exception as e:
xmppserverlog.exception("{}".format(e))
if data != b"":
splitdata = data.decode("utf-8")
splitdata = splitdata.split("<iq")
if len(splitdata) > 1:
for s in splitdata:
if not s.startswith("<iq") and s:
self._parse_data("<iq {}".format(s).encode("utf-8"))
else:
self._parse_data(s.encode("utf-8"))
else:
self._parse_data(data)