paul@6 | 1 | # -*- coding: iso-8859-1 -*- |
paul@6 | 2 | """ |
paul@6 | 3 | MoinMoin - MoinMessage library |
paul@6 | 4 | |
paul@6 | 5 | @copyright: 2012 by Paul Boddie <paul@boddie.org.uk> |
paul@6 | 6 | @license: GNU GPL (v2 or later), see COPYING.txt for details. |
paul@6 | 7 | """ |
paul@6 | 8 | |
paul@6 | 9 | from email import message_from_string |
paul@6 | 10 | from email.encoders import encode_noop |
paul@6 | 11 | from email.mime.multipart import MIMEMultipart |
paul@6 | 12 | from email.mime.application import MIMEApplication |
paul@6 | 13 | from email.mime.base import MIMEBase |
paul@6 | 14 | from email.mime.text import MIMEText |
paul@6 | 15 | from subprocess import Popen, PIPE |
paul@8 | 16 | from tempfile import mkstemp |
paul@12 | 17 | from urlparse import urlsplit |
paul@6 | 18 | import httplib |
paul@8 | 19 | import os |
paul@6 | 20 | |
paul@6 | 21 | class Message: |
paul@6 | 22 | |
paul@6 | 23 | "An update message." |
paul@6 | 24 | |
paul@6 | 25 | def __init__(self): |
paul@6 | 26 | self.updates = [] |
paul@6 | 27 | |
paul@6 | 28 | def add_update(self, alternatives): |
paul@6 | 29 | if len(alternatives) > 1: |
paul@6 | 30 | part = MIMEMultipart() |
paul@6 | 31 | for alternative in alternatives: |
paul@6 | 32 | part.attach(alternative) |
paul@6 | 33 | self.updates.append(part) |
paul@6 | 34 | else: |
paul@6 | 35 | self.updates.append(alternatives[0]) |
paul@6 | 36 | |
paul@6 | 37 | def get_payload(self): |
paul@6 | 38 | if len(self.updates) == 1: |
paul@6 | 39 | message = self.updates[0] |
paul@6 | 40 | else: |
paul@6 | 41 | message = MIMEMultipart() |
paul@6 | 42 | message.add_header("Update-Type", "collection") |
paul@6 | 43 | for update in self.updates: |
paul@6 | 44 | message.attach(update) |
paul@6 | 45 | |
paul@6 | 46 | return message |
paul@6 | 47 | |
paul@6 | 48 | class MoinMessageError(Exception): |
paul@6 | 49 | pass |
paul@6 | 50 | |
paul@8 | 51 | class GPG: |
paul@8 | 52 | |
paul@8 | 53 | "A wrapper around the gpg command using a particular configuration." |
paul@6 | 54 | |
paul@8 | 55 | def __init__(self, homedir=None): |
paul@8 | 56 | self.conf_args = [] |
paul@6 | 57 | |
paul@8 | 58 | if homedir: |
paul@8 | 59 | self.conf_args += ["--homedir", homedir] |
paul@8 | 60 | |
paul@8 | 61 | self.errors = None |
paul@6 | 62 | |
paul@8 | 63 | def run(self, args, text=None): |
paul@6 | 64 | |
paul@8 | 65 | """ |
paul@8 | 66 | Invoke gpg with the given 'args', supplying the given 'text' to the |
paul@8 | 67 | command directly or, if 'text' is omitted, using a file provided as part |
paul@8 | 68 | of the 'args' if appropriate. |
paul@6 | 69 | |
paul@8 | 70 | Failure to complete the operation will result in a MoinMessageError |
paul@8 | 71 | being raised. |
paul@8 | 72 | """ |
paul@8 | 73 | |
paul@8 | 74 | cmd = Popen(["gpg"] + self.conf_args + list(args), stdin=PIPE, stdout=PIPE, stderr=PIPE) |
paul@6 | 75 | |
paul@11 | 76 | try: |
paul@11 | 77 | # Attempt to write input to the command and to read output from the |
paul@11 | 78 | # command. |
paul@11 | 79 | |
paul@11 | 80 | try: |
paul@11 | 81 | if text: |
paul@11 | 82 | cmd.stdin.write(text) |
paul@11 | 83 | cmd.stdin.close() |
paul@6 | 84 | |
paul@11 | 85 | text = cmd.stdout.read() |
paul@11 | 86 | |
paul@11 | 87 | # I/O errors can indicate the failure of the command. |
paul@8 | 88 | |
paul@11 | 89 | except IOError: |
paul@11 | 90 | pass |
paul@11 | 91 | |
paul@11 | 92 | self.errors = cmd.stderr.read() |
paul@8 | 93 | |
paul@8 | 94 | # Test for a zero result. |
paul@6 | 95 | |
paul@8 | 96 | if not cmd.wait(): |
paul@8 | 97 | return text |
paul@8 | 98 | else: |
paul@10 | 99 | raise MoinMessageError, self.errors |
paul@8 | 100 | |
paul@8 | 101 | finally: |
paul@8 | 102 | cmd.stdout.close() |
paul@8 | 103 | cmd.stderr.close() |
paul@6 | 104 | |
paul@8 | 105 | def verifyMessage(self, signature, content): |
paul@8 | 106 | |
paul@8 | 107 | "Using the given 'signature', verify the given message 'content'." |
paul@6 | 108 | |
paul@8 | 109 | # Write the detached signature and content to files. |
paul@8 | 110 | |
paul@8 | 111 | signature_fd, signature_filename = mkstemp() |
paul@8 | 112 | content_fd, content_filename = mkstemp() |
paul@6 | 113 | |
paul@8 | 114 | try: |
paul@8 | 115 | signature_fp = os.fdopen(signature_fd, "w") |
paul@8 | 116 | content_fp = os.fdopen(content_fd, "w") |
paul@8 | 117 | try: |
paul@8 | 118 | signature_fp.write(signature) |
paul@8 | 119 | content_fp.write(content) |
paul@8 | 120 | finally: |
paul@8 | 121 | signature_fp.close() |
paul@8 | 122 | content_fp.close() |
paul@6 | 123 | |
paul@8 | 124 | # Verify the message text. |
paul@6 | 125 | |
paul@10 | 126 | text = self.run(["--status-fd", "1", "--verify", signature_filename, content_filename]) |
paul@10 | 127 | |
paul@10 | 128 | # Return the details of the signing key. |
paul@10 | 129 | |
paul@11 | 130 | identity = None |
paul@11 | 131 | fingerprint = None |
paul@11 | 132 | |
paul@10 | 133 | for line in text.split("\n"): |
paul@10 | 134 | try: |
paul@11 | 135 | prefix, msgtype, digest, details = line.strip().split(" ", 3) |
paul@10 | 136 | except ValueError: |
paul@10 | 137 | continue |
paul@10 | 138 | |
paul@10 | 139 | # Return the fingerprint and identity details. |
paul@10 | 140 | |
paul@10 | 141 | if msgtype == "GOODSIG": |
paul@11 | 142 | identity = details |
paul@11 | 143 | elif msgtype == "VALIDSIG": |
paul@11 | 144 | fingerprint = digest |
paul@11 | 145 | |
paul@11 | 146 | if identity and fingerprint: |
paul@11 | 147 | return fingerprint, identity |
paul@10 | 148 | |
paul@10 | 149 | return None |
paul@6 | 150 | |
paul@8 | 151 | finally: |
paul@8 | 152 | os.remove(signature_filename) |
paul@8 | 153 | os.remove(content_filename) |
paul@8 | 154 | |
paul@8 | 155 | def signMessage(self, message, keyid): |
paul@6 | 156 | |
paul@8 | 157 | """ |
paul@8 | 158 | Return a signed version of 'message' using the given 'keyid'. |
paul@8 | 159 | """ |
paul@6 | 160 | |
paul@8 | 161 | text = message.as_string() |
paul@8 | 162 | signature = self.run(["--armor", "-u", keyid, "--detach-sig"], text) |
paul@8 | 163 | |
paul@8 | 164 | # Make the container for the message. |
paul@8 | 165 | |
paul@8 | 166 | signed_message = MIMEMultipart("signed", protocol="application/pgp-signature") |
paul@8 | 167 | signed_message.attach(message) |
paul@6 | 168 | |
paul@8 | 169 | signature_part = MIMEBase("application", "pgp-signature") |
paul@8 | 170 | signature_part.set_payload(signature) |
paul@8 | 171 | signed_message.attach(signature_part) |
paul@8 | 172 | |
paul@8 | 173 | return signed_message |
paul@8 | 174 | |
paul@8 | 175 | def decryptMessage(self, message): |
paul@6 | 176 | |
paul@8 | 177 | "Return a decrypted version of 'message'." |
paul@8 | 178 | |
paul@8 | 179 | return self.run(["--decrypt"], message) |
paul@6 | 180 | |
paul@8 | 181 | def encryptMessage(self, message, keyid): |
paul@6 | 182 | |
paul@8 | 183 | """ |
paul@8 | 184 | Return an encrypted version of 'message' using the given 'keyid'. |
paul@8 | 185 | """ |
paul@6 | 186 | |
paul@8 | 187 | text = message.as_string() |
paul@8 | 188 | encrypted = self.run(["--armor", "-r", keyid, "--encrypt", "--trust-model", "always"], text) |
paul@8 | 189 | |
paul@8 | 190 | # Make the container for the message. |
paul@8 | 191 | |
paul@8 | 192 | encrypted_message = MIMEMultipart("encrypted", protocol="application/pgp-encrypted") |
paul@8 | 193 | |
paul@8 | 194 | # For encrypted content, add the declaration and content. |
paul@6 | 195 | |
paul@8 | 196 | declaration = MIMEBase("application", "pgp-encrypted") |
paul@8 | 197 | declaration.set_payload("Version: 1") |
paul@8 | 198 | encrypted_message.attach(declaration) |
paul@6 | 199 | |
paul@8 | 200 | content = MIMEApplication(encrypted, "octet-stream", encode_noop) |
paul@8 | 201 | encrypted_message.attach(content) |
paul@6 | 202 | |
paul@8 | 203 | return encrypted_message |
paul@8 | 204 | |
paul@8 | 205 | # Communications functions. |
paul@6 | 206 | |
paul@12 | 207 | def sendMessage(message, url): |
paul@6 | 208 | |
paul@12 | 209 | "Send 'message' to the given 'url." |
paul@6 | 210 | |
paul@12 | 211 | scheme, host, port, path = parseURL(url) |
paul@6 | 212 | text = message.as_string() |
paul@6 | 213 | |
paul@12 | 214 | if scheme == "http": |
paul@12 | 215 | cls = httplib.HTTPConnection |
paul@12 | 216 | elif scheme == "https": |
paul@12 | 217 | cls = httplib.HTTPSConnection |
paul@12 | 218 | else: |
paul@12 | 219 | raise MoinMessageError, "Communications protocol not supported: %s" % scheme |
paul@12 | 220 | |
paul@12 | 221 | req = cls(host, port) |
paul@12 | 222 | req.request("PUT", path, text) |
paul@6 | 223 | resp = req.getresponse() |
paul@6 | 224 | return resp.read() |
paul@6 | 225 | |
paul@12 | 226 | def parseURL(url): |
paul@12 | 227 | |
paul@12 | 228 | "Return the scheme, host, port and path for the given 'url'." |
paul@12 | 229 | |
paul@12 | 230 | scheme, host_port, path, query, fragment = urlsplit(url) |
paul@12 | 231 | host_port = host_port.split(":") |
paul@12 | 232 | |
paul@12 | 233 | if query: |
paul@12 | 234 | path += "?" + query |
paul@12 | 235 | |
paul@12 | 236 | if len(host_port) > 1: |
paul@12 | 237 | host = host_port[0] |
paul@12 | 238 | port = int(host_port[1]) |
paul@12 | 239 | else: |
paul@12 | 240 | host = host_port[0] |
paul@12 | 241 | port = 80 |
paul@12 | 242 | |
paul@12 | 243 | return scheme, host, port, path |
paul@12 | 244 | |
paul@6 | 245 | # vim: tabstop=4 expandtab shiftwidth=4 |