ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/deliantra/server/ext/login.ext
Revision: 1.129
Committed: Sun Nov 18 09:53:46 2012 UTC (11 years, 6 months ago) by root
Branch: MAIN
Changes since 1.128: +40 -48 lines
Log Message:
better locking. maybe

File Contents

# Content
1 #! perl # mandatory depends=highscore
2
3 # login handling
4
5 use Fcntl;
6 use Coro::AIO;
7 use Deliantra::Util ();
8
9 CONF MAX_DISCONNECT_TIME = 3600;
10
11 our $VALID_LOGIN = qr<^[a-zA-Z0-9][a-zA-Z0-9\-_]{2,19}\z>;
12 our %LOGIN_LOCK;
13
14 # HACK: remove when done
15 sub cf::client::send_drawinfo {
16 my ($self, $text, $flags) = @_;
17
18 utf8::encode $text;
19 $self->send_packet (sprintf "msg %d log %s", $flags || cf::NDI_BLACK, $text);
20 }
21
22 sub query {
23 my ($ns, $flags, $text) = @_;
24
25 $ns->query ($flags, $text, Coro::rouse_cb);
26 Coro::rouse_wait
27 }
28
29 sub can_cleanup {
30 my ($pl, $mtime) = @_;
31
32 my $age = time - $mtime;
33 my $level = $pl->ob->level;
34
35 ($level <= 3 && $age > 7 * 86400) # 7 days for level 0..3
36 || ($level <= 9 && $age > 90 * 86400) # 3 months for level 4..9
37 || ($level <= 20 && $age > 180 * 86400) # 6 months for level 10..20
38 || $age > 700 * 86400 # 2 years for everybody else
39 }
40
41 # return a guard object for a lock on the given username, if available
42 sub login_guard {
43 my ($user) = @_;
44
45 exists $LOGIN_LOCK{$user}
46 and return undef;
47
48 cf::player::find_active $user
49 and return undef;
50
51 undef $LOGIN_LOCK{$user};
52 Guard::guard { delete $LOGIN_LOCK{$user} }
53 }
54
55 sub safe_spot($) {
56 my ($pl) = @_;
57
58 my $ob = $pl->ob;
59
60 my $m = $ob->map
61 or return;
62 my $x = $ob->x;
63 my $y = $ob->y;
64
65 # never happens normally, but helps when shell users make mistakes
66 $m->linkable
67 or return 1;
68
69 scalar grep $_->type == cf::SAVEBED, $m->at ($x, $y)
70 }
71
72 sub enter_map {
73 my ($pl) = @_;
74
75 my $ob = $pl->ob;
76
77 my ($map, $x, $y)
78 = $ob->{_link_pos}
79 ? @{delete $ob->{_link_pos}}
80 : ($pl->maplevel, $ob->x, $ob->y);
81
82 $ob->enter_link;
83
84 my $m = cf::map::find $map;
85 my $time = delete $pl->{unclean_save};
86
87 if ($time && $m) {
88 if ($time < $m->{instantiate_time}) {
89 # the map was reset in the meantime
90 my $age = $cf::RUNTIME - $time;
91
92 cf::info $ob->name, " map reset after logout, logout age $age (>= $MAX_DISCONNECT_TIME)\n";#d#
93
94 if ($age >= $MAX_DISCONNECT_TIME) {
95 $ob->message (
96 "You didn't use a bed to reality to leave this realm, leaving your body in great danger. "
97 . "Unfortunately, nobody was near to help you when the monsters arrived to eat you. "
98 . "Maybe you can find comfort in the thought that your body was quite satisfying in taste... "
99 . "H<You disconnected too long without having used a savebed.>",
100 cf::NDI_RED
101 );
102 # kill them.
103 # reminds me of the famous badness 10000 syndrome...
104 $ob->stats->hp (-10000); #] if they survive this they deserved to live
105 my $killer = cf::arch::get "killer_login"; $pl->killer ($killer); $killer->destroy;
106 } else {
107 ($map, $x, $y) = $pl->savebed;
108
109 $ob->message (
110 "You didn't use a bed to reality to leave this realm, leaving your body in great danger. "
111 . "Fortunately, some friendly dwellers found you, checked your passport, and brought you to safety. "
112 . "Better use a savebed next time, much worse things could have happened... "
113 . "H<You disconnected without having used a savebed. When you do that for too long, you might die.>",
114 cf::NDI_RED
115 );
116 }
117 } else {
118 $ob->message (
119 "You didn't use a bed to reality to leave this realm. This is very dangerous, "
120 . "as lots of things could happen when you leave by other means, such as cave-ins, "
121 . "or monsters suddenly snapping your body. Better use a savebed next time. "
122 . "H<Always apply a bed of reality to disconnect from the server.>",
123 cf::NDI_RED
124 );
125 }
126 }
127
128 $ob->goto ($map, $x, $y);
129 }
130
131 sub encode_password($) {
132 unpack "H*", Deliantra::Util::hash_pw $_[0]
133 }
134
135 sub compare_password($$) {
136 my ($pass, $token) = @_;
137
138 if ($token =~ /!!(.*)/) {
139 return +(substr $pass, 0, 8) eq pack "H*", $1;
140 } elsif ($token =~ /!(.*)/) {
141 return $pass eq pack "H*", $1;
142 } else {
143 return $token eq crypt $pass, $token;
144 }
145 }
146
147 # delete a player directory
148 sub nuke_playerdir {
149 my ($user) = @_;
150
151 my $lock = cf::lock_acquire "ext::login::nuke_playerdir";
152
153 my $temp = "$PLAYERDIR/~$Coro::current~deleting~";
154 aio_rename "$PLAYERDIR/$user", $temp;
155 IO::AIO::aio_rmtree $temp;
156 }
157
158 sub login {
159 my ($pl) = @_;
160
161 # handle character creation, if neccessary
162 # the rest of this function is character creation
163
164 my $ns = $pl->ns;
165 my $ob = $pl->ob;
166
167 if ($pl->{chargen} eq "init") {
168 $ob->goto ($pl->maplevel, $ob->x, $ob->y);
169
170 # create the playerdir, if necessary, as chargen_race_done did it before
171 # presumably because of unique maps
172 aio_mkdir playerdir $pl, 0770;
173 delete $pl->{deny_save}; # set by new
174 $pl->save;
175
176 $pl->{chargen} = "stats";
177 }
178
179 if ($pl->{chargen} eq "stats") {
180 while () {
181 $ob->update_stats;
182 $pl->save_stats;
183
184 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
185 "[y] to roll new stats [n] to use stats\n[1-7] [1-7] to swap stats.\nRoll again (y/n/1-7)?";
186
187 if ($res =~ /^[Nn]/) {
188 last;
189 } elsif ($res > 0 && $res <= 7) {
190 my $swap = query $ns, cf::CS_QUERY_SINGLECHAR, "Swap stat with (will not roll new stats) [1-7]?";
191
192 if ($swap > 0 && $swap <= 7) {
193 $ob->swap_stats ($res - 1, $swap - 1);
194 }
195 } else {
196 $ob->roll_stats;
197 }
198
199 Coro::Timer::sleep 0.05;
200 }
201
202 $ob->set_animation (2);
203 $ob->add_statbonus;
204
205 $pl->{chargen} = "race";
206 }
207
208 if ($pl->{chargen} eq "race") {
209 while () {
210 $ns->send_msg ("chargen-race-title", ucfirst $pl->title, -1);
211 my $msg = $ob->msg;
212 $msg =~ s/(?<=\S)\n(?=\S)/ /g;
213 $ns->send_msg ("chargen-race-description", $msg, cf::NDI_BLUE);
214
215 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
216 "Now choose a character.\nPress any key to change outlook.\nPress `d' when you're pleased.\n";
217
218 last if $res =~ /[dD]/;
219
220 $pl->chargen_race_next;
221 Coro::Timer::sleep 0.05;
222 }
223
224 $pl->chargen_race_done;
225 $pl->{chargen} = "gender";
226 }
227
228 if ($pl->{chargen} eq "race") {
229 while () {
230 my $res = query $ns, cf::CS_QUERY_SINGLECHAR,
231 "Now choose a gender.\nPress 'f' to become female, and 'm' to become male.\n";
232
233 if ($res =~ /^[fF]/) {
234 $pl->gender (1);
235 last;
236 } elsif ($res =~ /^[mM]/) {
237 $pl->gender (0);
238 last;
239 }
240 Coro::Timer::sleep 0.05;
241 }
242 $pl->{chargen} = "done";
243 }
244
245 $ns->state (cf::ST_PLAYING);
246
247 if ($pl->{chargen} eq "done") {
248 # XXX: Workaround for delayed client ext protocol handshake
249 $pl->esrv_new_player;
250
251 $pl->{chargen} = "done";
252 }
253
254 $ob->reply (undef, "Welcome to Deliantra!");
255
256 if (0 < Coro::AIO::aio_load "$cf::CONFDIR/motd", my $motd) {
257 $pl->ns->send_msg ("c/motd" => $motd, cf::NDI_CLEAR);
258 }
259 }
260
261 sub chargen {
262 my ($ns, $user, $hash) = @_;
263
264 # just to make sure nothing is left over
265 # normally, nothing is there.
266 nuke_playerdir $user;
267
268 my $pl = cf::player::new $user;
269 $pl->password (unpack "H*", $hash);
270 $pl->connect ($ns);
271
272 $pl->{chargen} = "init";
273
274 login $pl;
275 }
276
277 cf::client->attach (on_addme => sub {
278 my ($ns) = @_;
279
280 $ns->{addme}++ and return $ns->destroy;
281
282 $ns->async (sub {
283 $Coro::current->{desc} = "addme init";
284
285 my ($user, $pass);
286
287 $ns->send_packet ("addme_success");
288
289 for (;;) {
290 delete $ns->{login_guard};
291
292 $ns->send_drawinfo (
293 "Please enter your username now. If you are a new user, "
294 . "make one up that describes your character best. "
295 . "Only letters and digits are allowed, though.",
296 cf::NDI_BLUE
297 );
298
299 # read username
300 while () {
301 $user = query $ns, 0, "What is your name? (login names are case-sensitive)\n:";
302
303 if ($user =~ $VALID_LOGIN) {
304 last;
305 } else {
306 $ns->send_drawinfo (
307 "Your username contains illegal characters "
308 . "(only a-z, A-Z and 0-9 are allowed), "
309 . "or is not between 3 and 20 characters in length.",
310 cf::NDI_RED
311 );
312 }
313 Coro::Timer::sleep 0.4;
314 }
315
316 $Coro::current->{desc} = "addme($user)";
317
318 $ns->send_drawinfo (
319 "Welcome $user, please enter your password now. "
320 . "New users should now choose a password. "
321 . "Anything your client lets you enter is fine.",
322 cf::NDI_BLUE
323 );
324
325 # read password
326 while () {
327 $pass = query $ns, cf::CS_QUERY_HIDEINPUT, "What is your password?\n:";
328 last if $pass =~ /.../;
329 $ns->send_drawinfo (
330 "Try to use at least three characters as your password please, "
331 . "that cannot be too much to ask for :)",
332 cf::NDI_RED
333 );
334 Coro::Timer::sleep 0.4;
335 }
336
337 $ns->{login_guard} = login_guard $user
338 or do {
339 $ns->send_drawinfo (
340 "That user is already logged in (or is logging in)."
341 . "Chose another, or wait till the other session has ended.",
342 cf::NDI_RED
343 );
344 next;
345 };
346
347 # try to read the user file and check the password
348 if (my $pl = cf::player::find $user) {
349 aio_stat $pl->path and next;
350 my $mtime = (stat _)[9];
351 my $token = $pl->password;
352
353 if ($cf::CFG{ext_login_nocheck} or compare_password $pass, $token) {
354 # player exists and passwords match - we can proceed
355
356 # password matches, wonderful
357 my $pl = cf::player::find $user or next;
358 $pl->connect ($ns);
359 enter_map $pl;
360 login $pl;
361 return;
362 } elsif (can_cleanup $pl, $mtime) {
363 Coro::Timer::sleep 1;
364
365 $ns->send_drawinfo (
366 "Player exists, but password does not match. If this is your account, "
367 . "please try again. If not, you can now decide to take over this account "
368 . "because it has not been in-use for some time.",
369 cf::NDI_RED
370 );
371
372 (query $ns, cf::CS_QUERY_SINGLECHAR, "Delete existing account and create a new one (Y/N)?") =~ /^[yY]/
373 or next;
374
375 # check if the file hasn't changed
376 aio_stat cf::player::path $user and next;
377 $mtime == (stat _)[9] or next;
378
379 $pl->quit_character;
380
381 # fall through to creation
382 } else {
383 Coro::Timer::sleep 1;
384
385 $ns->send_drawinfo (
386 "Wrong username or password. Please try again "
387 . "(check for Numlock and other semi-obvious error sources).",
388 cf::NDI_RED
389 );
390 next;
391 }
392 } else {
393 # unable to load the playerfile:
394 # check whether the player dir exists, which means the file is corrupted or
395 # something very similar.
396 if (!aio_stat cf::player::playerdir $user) {
397 $ns->send_drawinfo (
398 "Unable to retrieve this player. It might be a locked or broken account. "
399 . "If this is your account, ask a dungeon master for assistance. "
400 . "Otherwise choose a different login name.",
401 cf::NDI_RED
402 );
403 next;
404 }
405 }
406
407 my $pass2 = query $ns, cf::CS_QUERY_HIDEINPUT, "Please type your password again.";
408
409 if ($pass2 ne $pass) {
410 $ns->send_drawinfo (
411 "The passwords do not match, please try again.",
412 cf::NDI_RED
413 );
414 Coro::Timer::sleep 0.5;
415 next;
416 }
417
418 last;
419 }
420
421 chargen $ns, $user, Deliantra::Util::hash_pw $pass;
422 });
423 });
424
425 cf::client->attach (
426 on_version => sub {
427 my ($ns, $arg) = @_;
428
429 # perl probably uses lrand48, which is not secure at all
430 # maybe require linux and use /dev/urandom.
431 $ns->{nonces} = [map { join "", map { chr rand 256 } 0..63 } 1..2];
432 $ns->ext_msg (nonces => @{ $ns->{nonces} });
433 },
434 );
435
436 cf::register_async_exticmd create_login => sub {
437 my ($ns, $reply, $user, $pass) = @_;
438
439 $ns->{addme}++ and return $ns->destroy;
440
441 $ns->async (sub {
442 my $fail = sub {
443 $reply->(0, $_[0]);
444 $ns->flush; # does not ensure that the data reaches the client - TODO
445 # need to do this in another thread, as this one gets canceled
446 Coro::async_pool {
447 Coro::AnyEvent::sleep 0.1; # TODO, see above, extra hack
448 $ns->destroy if $ns->valid;
449 };
450 Coro::schedule; # do the destroy, should not return
451 };
452
453 $user =~ $VALID_LOGIN
454 or return $fail (
455 "Your username contains illegal characters (only a-z, A-Z and 0-9 are allowed), "
456 . "or is not between 3 and 20 characters in length."
457 );
458
459 $ns->{login_guard} = login_guard $user
460 or return $fail->("User name '$user' is in use - try another login name.");
461
462 cf::player::find $user
463 and return $fail->("User name '$user' is already registered - choose another login name.");
464
465 $reply->(1, "Account Created");
466
467 chargen $ns, $user, $pass;
468 });
469 };
470
471 cf::register_async_exticmd login => sub {
472 my ($ns, $reply, $user, $hash) = @_;
473
474 $ns->{addme}++ and return $ns->destroy;
475
476 $ns->async (sub {
477 $Coro::current->{desc} = "login($user)";
478
479 my $fail = sub {
480 $reply->(0, $_[0]);
481 $ns->flush; # does not ensure that the data reaches the client - TODO
482 # need to do this in another thread, as this one gets canceled
483 Coro::async_pool {
484 Coro::AnyEvent::sleep 0.1; # TODO, see above, extra hack
485 $ns->destroy if $ns->valid;
486 };
487 Coro::schedule; # do the destroy, should not return
488 };
489
490 $ns->{login_guard} = login_guard $user
491 or return $fail->("User '$user' is currently playing or logging in in another session. If that is your "
492 . "user name, make sure you are not running two clients. When in doubt, reboot.");
493
494 # try to read the user file and check the password
495 my $pl = cf::player::find $user
496 or return $fail->("User '$user' does not exist - wrong spelling?");
497
498 aio_stat $pl->path
499 and return $ns->destroy;
500
501 my $mtime = (stat _)[9];
502 my $token = $pl->password;
503
504 $token = $token =~ /^!/
505 ? Deliantra::Util::hash_pw pack "H*", substr $token, 1
506 : pack "H*", $token;
507
508 $token = Deliantra::Util::auth_pw $token, $ns->{nonces}[0], $ns->{nonces}[1];
509
510 $token eq $hash
511 or $cf::CFG{ext_login_nocheck}
512 or return $fail->("User exists, but the password doesn't match - check your spelling, NumLock/CapsLock etc.");
513
514 # player exists and passwords match - we can proceed
515
516 $reply->(1, "Success");
517
518 $pl->connect ($ns);
519 enter_map $pl;
520 login $pl;
521 });
522 };
523
524 cf::register_command password => sub {
525 my ($pl, $arg) = @_;
526
527 unless ($pl->flag (cf::FLAG_WIZ)) {
528 $pl->message (
529 "The password can currently only changed by a DM.",
530 cf::NDI_UNIQUE | cf::NDI_REPLY);
531 return;
532 }
533
534 $pl->message (#d#
535 "Passwords cannot currently be changed.",#d#
536 cf::NDI_UNIQUE | cf::NDI_REPLY);#d#
537 return;#d#
538
539 my (@args) = split /\s+/, $arg;
540 my ($player, $new_pw) = @args;
541
542 if ($pl->flag (cf::FLAG_WIZ) && $player eq '') {
543 $pl->message (
544 "Usage: password <player> [<new password>]",
545 cf::NDI_UNIQUE | cf::NDI_REPLY);
546 return;
547 }
548
549 if ($new_pw eq '') {
550 $new_pw =
551 join '',
552 map { ('.', '/', 0..9, 'A'..'Z', 'a'..'z')[(cf::rndm 64)] }
553 1..9;
554 }
555
556 cf::async {
557 my $plc = cf::player::find $player;
558 if ($plc) {
559 $plc->password (encode_password $new_pw);
560 $pl->message (
561 "Ok, changed password of '$player' to '$new_pw'!",
562 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
563 } else {
564 $pl->message (
565 "Fail! Couldn't set password for '$player', "
566 . "he doesn't seem to exist!",
567 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
568 }
569 };
570 };
571
572 cf::register_command quit => sub {
573 my ($ob, $arg) = @_;
574
575 $ob->send_msg (undef,
576 "Quitting will delete your character PERMANENTLY: It will be gone forever and any progress will be lost. "
577 . "If you are sure you want to do this, then use the quit_character command instead of quit.",
578 cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
579 };
580
581 cf::register_command quit_character => sub {
582 my ($ob, $arg) = @_;
583
584 my $pl = $ob->contr;
585
586 $pl->ns->query (cf::CS_QUERY_SINGLECHAR, "Do you want to PERMANENTLY delete your character and all associated data (y/n)?", sub {
587 if ($_[0] !~ /^[yY]/) {
588 $ob->send_msg (undef, "Ok, not not quitting then.", cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
589 } else {
590 $ob->send_msg (undef, "Ok, quitting, hope to see you again.", cf::NDI_UNIQUE | cf::NDI_RED | cf::NDI_REPLY);
591 cf::async {
592 $pl->quit_character;
593 };
594 }
595 });
596 };
597
598 cf::object->attach (
599 type => cf::SAVEBED,
600 on_apply => sub {
601 my ($bed, $ob) = @_;
602
603 return cf::override 0 unless $ob->type == cf::PLAYER;
604
605 my $pl = $ob->contr;
606
607 # update respawn position
608 $pl->savebed ($bed->map->path, $bed->x, $bed->y);
609
610 cf::async {
611 my $killer = cf::arch::get "killer_logout"; $pl->killer ($killer); $killer->destroy;
612 ext::highscore::check $ob;
613
614 $pl->save;
615
616 $ob->send_msg ($cf::SAY_CHANNEL => "In the future, you will wake up here when you die.", cf::NDI_DEF | cf::NDI_REPLY);
617
618 my $ns = $pl->ns
619 or return;
620
621 $ns->query (cf::CS_QUERY_SINGLECHAR, "Do you want to continue playing (y/n)?", sub {
622 if ($_[0] !~ /^[yY]/) {
623 $pl->invoke (cf::EVENT_PLAYER_LOGOUT, 1);
624 $pl->deactivate;
625 $pl->ns->destroy;
626 }
627 });
628 };
629 },
630 );
631
632 cf::player->attach (
633 on_login => sub {
634 my ($pl) = @_;
635 my $name = $pl->ob->name;
636
637 $_->ob->message ("$name has entered the game.", cf::NDI_DK_ORANGE | cf::NDI_UNIQUE) for cf::player::list;
638 },
639 on_logout => sub {
640 my ($pl, $cleanly) = @_;
641 my $name = $pl->ob->name;
642
643 if ($cleanly) {
644 $_->ob->message ("$name left the game.", cf::NDI_DK_ORANGE | cf::NDI_UNIQUE) for cf::player::list;
645 } else {
646 $_->ob->message ("$name uncerimoniously disconnected.", cf::NDI_DK_ORANGE | cf::NDI_UNIQUE) for cf::player::list;
647 $pl->{unclean_save} = $cf::RUNTIME
648 unless safe_spot $pl;
649 }
650 },
651 );
652