ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/deliantra/server/ext/login.ext
(Generate patch)

Comparing deliantra/server/ext/login.ext (file contents):
Revision 1.111 by root, Sun May 9 22:51:13 2010 UTC vs.
Revision 1.126 by root, Sat Nov 17 11:13:54 2012 UTC

2 2
3# login handling 3# login handling
4 4
5use Fcntl; 5use Fcntl;
6use Coro::AIO; 6use Coro::AIO;
7use Deliantra::Util ();
7 8
8our $MAX_DISCONNECT_TIME = $cf::CFG{max_disconnect_time} || 3600; 9CONF MAX_DISCONNECT_TIME = 3600;
9 10
10# paranoia function to overwrite a string-in-place 11our $VALID_LOGIN = qr<^[a-zA-Z0-9][a-zA-Z0-9\-_]{2,19}\z>;
11sub nuke_str {
12 substr $_[0], 0, (length $_[0]), "x" x length $_[0]
13}
14 12
15sub query { 13sub query {
16 my ($ns, $flags, $text) = @_; 14 my ($ns, $flags, $text) = @_;
17 15
18 $ns->query ($flags, $text, Coro::rouse_cb); 16 $ns->query ($flags, $text, Coro::rouse_cb);
59 my $m = $ob->map 57 my $m = $ob->map
60 or return; 58 or return;
61 my $x = $ob->x; 59 my $x = $ob->x;
62 my $y = $ob->y; 60 my $y = $ob->y;
63 61
64# return 0;#d# 62 # never happens normally, but helps when shell users make mistakes
65# warn join ":", $m->at ($x, $y);#d# 63 $m->linkable
66# warn "FOO$m { ".scalar ($m->at ($x, $y))." }\n"; 64 or return 1;
67# return 0;
68 65
69 scalar grep $_->type == cf::SAVEBED, $m->at ($x, $y) 66 scalar grep $_->type == cf::SAVEBED, $m->at ($x, $y)
70} 67}
71 68
72sub enter_map { 69sub enter_map {
127 124
128 $ob->goto ($map, $x, $y); 125 $ob->goto ($map, $x, $y);
129} 126}
130 127
131sub encode_password($) { 128sub encode_password($) {
132# crypt $_[0],
133# join '',
134# ('.', '/', 0..9, 'A'..'Z', 'a'..'z')[(cf::rndm 64), (cf::rndm 64)]
135 "!" . unpack "H*", $_[0] 129 "!" . unpack "H*", $_[0]
136} 130}
137 131
138sub compare_password($$) { 132sub compare_password($$) {
139 my ($pass, $token) = @_; 133 my ($pass, $token) = @_;
140 134
141 if ($token =~ /\!(.*)/) { 135 if ($token =~ /!!(.*)/) {
136 return +(substr $pass, 0, 8) eq pack "H*", $1;
137 } elsif ($token =~ /!(.*)/) {
142 return $pass eq pack "H*", $1; 138 return $pass eq pack "H*", $1;
143 } else { 139 } else {
144 return $token eq crypt $pass, $token; 140 return $token eq crypt $pass, $token;
145 } 141 }
146} 142}
154 my $temp = "$PLAYERDIR/~$Coro::current~deleting~"; 150 my $temp = "$PLAYERDIR/~$Coro::current~deleting~";
155 aio_rename "$PLAYERDIR/$user", $temp; 151 aio_rename "$PLAYERDIR/$user", $temp;
156 IO::AIO::aio_rmtree $temp; 152 IO::AIO::aio_rmtree $temp;
157} 153}
158 154
155sub login {
156 my ($pl) = @_;
157
158 # handle character creation, if neccessary
159 # the rest of this function is character creation
160
161 my $ns = $pl->ns;
162 my $ob = $pl->ob;
163
164 $Coro::current->{desc} = "addme(" . $ob->name . ") login";
165
166 delete $pl->{deny_save}; # set by new
167
168 if ($pl->{chargen} eq "init") {
169 # create the playerdir, if necessary, as chargen_race_done did it before
170 # presumably because of unique maps
171 aio_mkdir playerdir $pl, 0770;
172 $pl->save;
173
174 $ob->goto ($pl->maplevel, $ob->x, $ob->y);
175
176 $pl->{chargen} = "stats";
177 }
178
179 if ($pl->{chargen} eq "stats") {
180 while () {
181 $ob->update_stats;
182 $pl->save_stats;
183
184 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
185 "[y] to roll new stats [n] to use stats\n[1-7] [1-7] to swap stats.\nRoll again (y/n/1-7)?";
186
187 if ($res =~ /^[Nn]/) {
188 last;
189 } elsif ($res > 0 && $res <= 7) {
190 my $swap = query $ns, cf::CS_QUERY_SINGLECHAR, "Swap stat with (will not roll new stats) [1-7]?";
191
192 if ($swap > 0 && $swap <= 7) {
193 $ob->swap_stats ($res - 1, $swap - 1);
194 }
195 } else {
196 $ob->roll_stats;
197 }
198
199 Coro::Timer::sleep 0.05;
200 }
201
202 $ob->set_animation (2);
203 $ob->add_statbonus;
204
205 $pl->{chargen} = "race";
206 }
207
208 if ($pl->{chargen} eq "race") {
209 while () {
210 $ns->send_msg ("chargen-race-title", ucfirst $pl->title, -1);
211 my $msg = $ob->msg;
212 $msg =~ s/(?<=\S)\n(?=\S)/ /g;
213 $ns->send_msg ("chargen-race-description", $msg, cf::NDI_BLUE);
214
215 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
216 "Now choose a character.\nPress any key to change outlook.\nPress `d' when you're pleased.\n";
217
218 last if $res =~ /[dD]/;
219
220 $pl->chargen_race_next;
221 Coro::Timer::sleep 0.05;
222 }
223
224 $pl->chargen_race_done;
225 $pl->{chargen} = "gender";
226 }
227
228 if ($pl->{chargen} eq "race") {
229 while () {
230 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
231 "Now choose a gender.\nPress 'f' to become female, and 'm' to become male.\n";
232
233 if ($res =~ /^[fF]/) {
234 $pl->gender (1);
235 last;
236 } elsif ($res =~ /^[mM]/) {
237 $pl->gender (0);
238 last;
239 }
240 Coro::Timer::sleep 0.05;
241 }
242 $pl->{chargen} = "done";
243 }
244
245 $ns->state (cf::ST_PLAYING);
246
247 if ($pl->{chargen} eq "done") {
248 # XXX: Workaround for delayed client ext protocol handshake
249 $pl->esrv_new_player;
250
251 $pl->{chargen} = "done";
252 }
253
254 $ob->reply (undef, "Welcome to Deliantra!");
255
256 if (0 < Coro::AIO::aio_load "$cf::CONFDIR/motd", my $motd) {
257 $pl->ns->send_msg ("c/motd" => $motd, cf::NDI_CLEAR);
258 }
259}
260
261sub chargen {
262 my ($ns, $user, $hasah) = @_;
263
264 # lock again, too lazy to make this nicer
265 local $cf::LOGIN_LOCK{$user} = 1;
266
267 # just to make sure nothing is left over
268 # normally, nothing is there.
269 nuke_playerdir $user;
270
271 my $pl = cf::player::new $user;
272 $pl->password (encode_password $pass);
273 $pl->connect ($ns);
274
275 $pl->{chargen} = "init";
276
277 login $pl;
278}
279
159cf::client->attach (on_addme => sub { 280cf::client->attach (on_addme => sub {
160 my ($ns) = @_; 281 my ($ns) = @_;
161 282
162 $ns->pl and return $ns->destroy; 283 $ns->{addme}++ and return $ns->destroy;
163 284
164 $ns->async (sub { 285 $ns->async (sub {
165 $Coro::current->{desc} = "addme init"; 286 $Coro::current->{desc} = "addme init";
166 287
167 my ($user, $pass); 288 my ($user, $pass);
184 $ns->send_drawinfo ( 305 $ns->send_drawinfo (
185 "That username is currently used in another login session. " 306 "That username is currently used in another login session. "
186 . "Chose another, or wait till the other session has ended.", 307 . "Chose another, or wait till the other session has ended.",
187 cf::NDI_RED 308 cf::NDI_RED
188 ); 309 );
189 } elsif ($user =~ /^[a-zA-Z0-9][a-zA-Z0-9\-_]{2,19}\z/) { 310 } elsif ($user =~ $VALID_LOGIN) {
190 last; 311 last;
191 } else { 312 } else {
192 $ns->send_drawinfo ( 313 $ns->send_drawinfo (
193 "Your username contains illegal characters " 314 "Your username contains illegal characters "
194 . "(only a-z, A-Z and 0-9 are allowed), " 315 . "(only a-z, A-Z and 0-9 are allowed), "
242 aio_stat $pl->path and next; 363 aio_stat $pl->path and next;
243 my $mtime = (stat _)[9]; 364 my $mtime = (stat _)[9];
244 my $token = $pl->password; 365 my $token = $pl->password;
245 366
246 if ($cf::CFG{ext_login_nocheck} or compare_password $pass, $token) { 367 if ($cf::CFG{ext_login_nocheck} or compare_password $pass, $token) {
247 $pl->password (encode_password $pass); # make sure we store the new encoding #d# 368 # player exists and passwords match - we can proceed
248 nuke_str $pass; 369
249 # password matches, wonderful 370 # password matches, wonderful
250 my $pl = cf::player::find $user or next; 371 my $pl = cf::player::find $user or next;
251 $pl->connect ($ns); 372 $pl->connect ($ns);
252 enter_map $pl; 373 enter_map $pl;
374 login $pl;
253 last; 375 return;
254 } elsif (can_cleanup $pl, $mtime) { 376 } elsif (can_cleanup $pl, $mtime) {
255 Coro::Timer::sleep 1; 377 Coro::Timer::sleep 1;
256 378
257 $ns->send_drawinfo ( 379 $ns->send_drawinfo (
258 "Player exists, but password does not match. If this is your account, " 380 "Player exists, but password does not match. If this is your account, "
259 . "please try again. If not, you can now decide to take over this account " 381 . "please try again. If not, you can now decide to take over this account "
260 . "because it has not been in-use for some time.", 382 . "because it has not been in-use for some time.",
261 cf::NDI_RED 383 cf::NDI_RED
262 ); 384 );
263 385
264 #TODO: nuke_str
265 (query $ns, cf::CS_QUERY_SINGLECHAR, "Delete existing account and create a new one (Y/N)?") =~ /^[yY]/ 386 (query $ns, cf::CS_QUERY_SINGLECHAR, "Delete existing account and create a new one (Y/N)?") =~ /^[yY]/
266 or next; 387 or next;
267 388
268 # check if the file hasn't changed 389 # check if the file hasn't changed
269 aio_stat cf::player::path $user and next; 390 aio_stat cf::player::path $user and next;
271 392
272 $pl->quit_character; 393 $pl->quit_character;
273 394
274 # fall through to creation 395 # fall through to creation
275 } else { 396 } else {
276 nuke_str $pass;
277
278 Coro::Timer::sleep 1; 397 Coro::Timer::sleep 1;
279 398
280 $ns->send_drawinfo ( 399 $ns->send_drawinfo (
281 "Wrong username or password. Please try again " 400 "Wrong username or password. Please try again "
282 . "(check for Numlock and other semi-obvious error sources).", 401 . "(check for Numlock and other semi-obvious error sources).",
284 ); 403 );
285 next; 404 next;
286 } 405 }
287 } else { 406 } else {
288 # unable to load the playerfile: 407 # unable to load the playerfile:
289 # check wether the player dir exists, which means the file is corrupted or 408 # check whether the player dir exists, which means the file is corrupted or
290 # something very similar. 409 # something very similar.
291 if (!aio_stat cf::player::playerdir $user) { 410 if (!aio_stat cf::player::playerdir $user) {
292 $ns->send_drawinfo ( 411 $ns->send_drawinfo (
293 "Unable to retrieve this player. It might be a locked or broken account. " 412 "Unable to retrieve this player. It might be a locked or broken account. "
294 . "If this is your account, ask a dungeon master for assistance. " 413 . "If this is your account, ask a dungeon master for assistance. "
297 ); 416 );
298 next; 417 next;
299 } 418 }
300 } 419 }
301 420
302 # the rest of this function is character creation
303 $Coro::current->{desc} = "addme($user) chargen";
304
305 # just to make sure nothing is left over
306 # normally, nothing is there.
307 nuke_playerdir $user;
308
309 my $pass2 = query $ns, cf::CS_QUERY_HIDEINPUT, "Please type your password again."; 421 my $pass2 = query $ns, cf::CS_QUERY_HIDEINPUT, "Please type your password again.";
310 422
311 if ($pass2 ne $pass) { 423 if ($pass2 ne $pass) {
312 nuke_str $pass;
313 nuke_str $pass2;
314 $ns->send_drawinfo ( 424 $ns->send_drawinfo (
315 "The passwords do not match, please try again.", 425 "The passwords do not match, please try again.",
316 cf::NDI_RED 426 cf::NDI_RED
317 ); 427 );
318 Coro::Timer::sleep 0.5; 428 Coro::Timer::sleep 0.5;
319 next; 429 next;
320 } 430 }
321 431
322 nuke_str $pass2;
323
324 my $pl = cf::player::new $user;
325 $pl->password (encode_password $pass);
326 nuke_str $pass;
327 $pl->connect ($ns);
328 my $ob = $pl->ob;
329
330 $ob->goto ($pl->maplevel, $ob->x, $ob->y);
331
332 while () {
333 $ob->update_stats;
334 $pl->save_stats;
335
336 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
337 "[y] to roll new stats [n] to use stats\n[1-7] [1-7] to swap stats.\nRoll again (y/n/1-7)?";
338
339 if ($res =~ /^[Nn]/) {
340 last;
341 } elsif ($res > 0 && $res <= 7) {
342 my $swap = query $ns, cf::CS_QUERY_SINGLECHAR, "Swap stat with (will not roll new stats) [1-7]?";
343
344 if ($swap > 0 && $swap <= 7) {
345 $ob->swap_stats ($res - 1, $swap - 1);
346 }
347 } else {
348 $ob->roll_stats;
349 }
350
351 Coro::Timer::sleep 0.05;
352 }
353
354 $ob->set_animation (2);
355 $ob->add_statbonus;
356
357 while () {
358 $ns->send_msg ("chargen-race-title", ucfirst $pl->title, -1);
359 my $msg = $ob->msg;
360 $msg =~ s/(?<=\S)\n(?=\S)/ /g;
361 $ns->send_msg ("chargen-race-description", $msg, cf::NDI_BLUE);
362
363 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
364 "Now choose a character.\nPress any key to change outlook.\nPress `d' when you're pleased.\n";
365
366 last if $res =~ /[dD]/;
367
368 $pl->chargen_race_next;
369 Coro::Timer::sleep 0.05;
370 }
371
372 # create the playerdir, if necessary, as chargen_race_done did it before
373 # presumably because of unique maps
374 aio_mkdir playerdir $pl, 0770;
375 $pl->chargen_race_done;
376
377 while () {
378 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
379 "Now choose a gender.\nPress 'f' to become female, and 'm' to become male.\n";
380
381 if ($res =~ /^[fF]/) {
382 $pl->gender (1);
383 last;
384 } elsif ($res =~ /^[mM]/) {
385 $pl->gender (0);
386 last;
387 }
388 Coro::Timer::sleep 0.05;
389 }
390
391 $ob->reply (undef, "Welcome to Deliantra!");
392
393 # XXX: Workaround for delayed client ext protocol handshake
394 $pl->esrv_new_player;
395
396 delete $pl->{deny_save};
397
398 last; 432 last;
399 } 433 }
400 434
401 if (0 < Coro::AIO::aio_load "$cf::CONFDIR/motd", my $motd) { 435 chargen $ns, $user, Deliantra::Util::hash_pw $pass;
402 $ns->send_msg ("c/motd" => $motd, cf::NDI_CLEAR);
403 }
404 }); 436 });
405}); 437});
406 438
439cf::client->attach (
440 on_version => sub {
441 my ($ns, $arg) = @_;
442
443 # perl probably uses lrand48, which is not secure at all
444 # maybe require linux and use /dev/urandom.
445 $ns->{nonces} = [map { join "", map { chr rand 256 } 0..63 } 1..2];
446 $ns->ext_msg (nonces => @{ $ns->{nonces} });
447 },
448);
449
450cf::register_async_exticmd create_login => sub {
451 my ($ns, $reply, $user, $pass) = @_;
452
453 $ns->{addme}++ and return $ns->destroy;
454
455 $ns->async (sub {
456 my $fail = sub {
457 $reply->(0, $_[0]);
458 $ns->flush; # does not ensure that the data reaches the client - TODO
459 # need to do this in another thread, as this one gets canceled
460 Coro::async_pool {
461 Coro::AnyEvent::sleep 0.1; # TODO, see above, extra hack
462 $ns->destroy if $ns->valid;
463 };
464 Coro::schedule; # do the destroy, should not return
465 };
466
467 $user =~ $VALID_LOGIN
468 or return $fail (
469 "Your username contains illegal characters (only a-z, A-Z and 0-9 are allowed), "
470 . "or is not between 3 and 20 characters in length."
471 );
472
473 cf::player::find $user
474 and return $fail->("User '$user' already exists - choose another login name.");
475
476 chargen $ns, $user, Deliantra::Util::hash_pw $pass;
477 });
478};
479
480cf::register_async_exticmd login => sub {
481 my ($ns, $reply, $user, $hash) = @_;
482
483 $ns->{addme}++ and return $ns->destroy;
484
485 $ns->async (sub {
486 local $cf::LOGIN_LOCK{$user} = 1;
487
488 $Coro::current->{desc} = "login($user) check";
489
490 my $fail = sub {
491 $reply->(0, $_[0]);
492 $ns->flush; # does not ensure that the data reaches the client - TODO
493 # need to do this in another thread, as this one gets canceled
494 Coro::async_pool {
495 Coro::AnyEvent::sleep 0.1; # TODO, see above, extra hack
496 $ns->destroy if $ns->valid;
497 };
498 Coro::schedule; # do the destroy, should not return
499 };
500
501 # try to read the user file and check the password
502 my $pl = cf::player::find $user
503 or return $fail->("User '$user' does not exist - wrong spelling?");
504
505 aio_stat $pl->path
506 and return $ns->destroy;
507
508 my $mtime = (stat _)[9];
509 my $token = $pl->password;
510
511 $token = $token =~ /^!/
512 ? Deliantra::Util::hash_pw pack "H*", substr $token, 1
513 : pack "H*", $token;
514
515 $token = Deliantra::Util::auth_pw $token, $ns->{nonces}[0], $ns->{nonces}[1];
516
517 $token eq $hash
518 or $cf::CFG{ext_login_nocheck}
519 or return $fail->("User exists, but the password doesn't match - check your spelling, NumLock/CapsLock etc.");
520
521 # player exists and passwords match - we can proceed
522
523 $reply->(1, "Success");
524
525 $pl->connect ($ns);
526 enter_map $pl;
527 login $pl;
528 });
529};
530
407cf::register_command password => sub { 531cf::register_command password => sub {
408 my ($pl, $arg) = @_; 532 my ($pl, $arg) = @_;
409 533
534 unless ($pl->flag (cf::FLAG_WIZ)) {
535 $pl->message (
536 "The password can currently only changed by a DM.",
537 cf::NDI_UNIQUE | cf::NDI_REPLY);
538 return;
539 }
540
541 $pl->message (#d#
542 "Passwords cannot currently be changed.",#d#
543 cf::NDI_UNIQUE | cf::NDI_REPLY);#d#
544 return;#d#
545
410 my (@args) = split /\s+/, $arg; 546 my (@args) = split /\s+/, $arg;
411
412 my ($new_pw, $player);
413
414 if ($pl->flag (cf::FLAG_WIZ)) {
415 ($player, $new_pw) = @args; 547 my ($player, $new_pw) = @args;
416 } else {
417 $new_pw = $args[0];
418 }
419 548
420 if ($pl->flag (cf::FLAG_WIZ) && $player eq '') { 549 if ($pl->flag (cf::FLAG_WIZ) && $player eq '') {
421 $pl->message ( 550 $pl->message (
422 "Usage: password <player> [<new password>]", 551 "Usage: password <player> [<new password>]",
423 cf::NDI_UNIQUE | cf::NDI_REPLY); 552 cf::NDI_UNIQUE | cf::NDI_REPLY);
424 return; 553 return;
425 } elsif (!$pl->flag (cf::FLAG_WIZ) && $new_pw eq '') {
426 $pl->message (
427 "Usage: password <new password>",
428 cf::NDI_UNIQUE | cf::NDI_REPLY);
429 return;
430 } 554 }
431 555
432 if ($player ne '' && $pl->flag (cf::FLAG_WIZ)) {
433 unless ($new_pw ne '') { 556 if ($new_pw eq '') {
434 $new_pw = 557 $new_pw =
435 join '', 558 join '',
436 map { ('.', '/', 0..9, 'A'..'Z', 'a'..'z')[(cf::rndm 64)] } 559 map { ('.', '/', 0..9, 'A'..'Z', 'a'..'z')[(cf::rndm 64)] }
437 1..9; 560 1..9;
438 } 561 }
439 562
440 cf::async { 563 cf::async {
441 my $plc = cf::player::find $player; 564 my $plc = cf::player::find $player;
442 if ($plc) { 565 if ($plc) {
443 $plc->password (encode_password $new_pw); 566 $plc->password (encode_password $new_pw);
444 $pl->message (
445 "Ok, changed password of '$player' to '$new_pw'!",
446 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
447 } else {
448 $pl->message (
449 "Fail! Couldn't set password for '$player', "
450 . "he doesn't seem to exist!",
451 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
452 }
453 };
454 } else {
455 my $change = delete $pl->{password_change};
456
457 if ($change && (time - $change->[0]) < 60) {
458 $pl->message ( 567 $pl->message (
459 "Ok, changed your password!", 568 "Ok, changed password of '$player' to '$new_pw'!",
460 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY); 569 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
461 $pl->contr->password (encode_password $new_pw);
462
463 } else { 570 } else {
464 $pl->message ( 571 $pl->message (
465 "Ok, please confirm your new password by sending " 572 "Fail! Couldn't set password for '$player', "
466 . "the command again within one minute!", 573 . "he doesn't seem to exist!",
467 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY); 574 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
468 $pl->{password_change} = [time, $new_pw];
469 } 575 }
470 } 576 };
471}; 577};
472 578
473cf::register_command quit => sub { 579cf::register_command quit => sub {
474 my ($ob, $arg) = @_; 580 my ($ob, $arg) = @_;
475 581
514 620
515 $pl->save; 621 $pl->save;
516 622
517 $ob->send_msg ($cf::SAY_CHANNEL => "In the future, you will wake up here when you die.", cf::NDI_DEF | cf::NDI_REPLY); 623 $ob->send_msg ($cf::SAY_CHANNEL => "In the future, you will wake up here when you die.", cf::NDI_DEF | cf::NDI_REPLY);
518 624
625 my $ns = $pl->ns
626 or return;
627
519 $pl->ns->query (cf::CS_QUERY_SINGLECHAR, "Do you want to continue playing (y/n)?", sub { 628 $ns->query (cf::CS_QUERY_SINGLECHAR, "Do you want to continue playing (y/n)?", sub {
520 if ($_[0] !~ /^[yY]/) { 629 if ($_[0] !~ /^[yY]/) {
521 $pl->invoke (cf::EVENT_PLAYER_LOGOUT, 1); 630 $pl->invoke (cf::EVENT_PLAYER_LOGOUT, 1);
522 $pl->deactivate; 631 $pl->deactivate;
523 $pl->ns->destroy; 632 $pl->ns->destroy;
524 } 633 }

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines