paul@6 | 1 | # -*- coding: iso-8859-1 -*- |
paul@6 | 2 | """ |
paul@6 | 3 | MoinMoin - MoinMessage library |
paul@6 | 4 | |
paul@16 | 5 | @copyright: 2012, 2013 by Paul Boddie <paul@boddie.org.uk> |
paul@6 | 6 | @license: GNU GPL (v2 or later), see COPYING.txt for details. |
paul@6 | 7 | """ |
paul@6 | 8 | |
paul@6 | 9 | from email import message_from_string |
paul@6 | 10 | from email.encoders import encode_noop |
paul@6 | 11 | from email.mime.multipart import MIMEMultipart |
paul@6 | 12 | from email.mime.application import MIMEApplication |
paul@6 | 13 | from email.mime.base import MIMEBase |
paul@20 | 14 | from email.utils import formatdate, parsedate |
paul@6 | 15 | from subprocess import Popen, PIPE |
paul@8 | 16 | from tempfile import mkstemp |
paul@12 | 17 | from urlparse import urlsplit |
paul@6 | 18 | import httplib |
paul@8 | 19 | import os |
paul@6 | 20 | |
paul@15 | 21 | def is_collection(message): |
paul@15 | 22 | return message.get("Update-Type") == "collection" |
paul@15 | 23 | |
paul@29 | 24 | def to_replace(message): |
paul@29 | 25 | return message.get("Update-Action") == "replace" |
paul@29 | 26 | |
paul@29 | 27 | def to_store(message): |
paul@29 | 28 | return message.get("Update-Action") == "store" |
paul@29 | 29 | |
paul@6 | 30 | class Message: |
paul@6 | 31 | |
paul@6 | 32 | "An update message." |
paul@6 | 33 | |
paul@15 | 34 | def __init__(self, text=None): |
paul@20 | 35 | self.date = None |
paul@6 | 36 | self.updates = [] |
paul@15 | 37 | if text: |
paul@15 | 38 | self.parse_text(text) |
paul@15 | 39 | |
paul@20 | 40 | def init_date(self, message): |
paul@20 | 41 | |
paul@20 | 42 | "Obtain the date of the given 'message'." |
paul@20 | 43 | |
paul@20 | 44 | if message.has_key("Date"): |
paul@20 | 45 | self.date = parsedate(message["Date"]) |
paul@20 | 46 | else: |
paul@20 | 47 | self.date = None |
paul@20 | 48 | |
paul@15 | 49 | def parse_text(self, text): |
paul@15 | 50 | |
paul@15 | 51 | "Parse the given 'text' as a message." |
paul@15 | 52 | |
paul@15 | 53 | self.handle_message(message_from_string(text)) |
paul@15 | 54 | |
paul@15 | 55 | def handle_message(self, message): |
paul@15 | 56 | |
paul@15 | 57 | "Handle the given 'message', recording the separate updates." |
paul@15 | 58 | |
paul@20 | 59 | self.init_date(message) |
paul@20 | 60 | |
paul@15 | 61 | # The message either consists of a collection of updates. |
paul@15 | 62 | |
paul@15 | 63 | if message.is_multipart() and is_collection(message): |
paul@15 | 64 | for part in message.get_payload(): |
paul@15 | 65 | self.updates.append(part) |
paul@15 | 66 | |
paul@15 | 67 | # Or the message is a single update. |
paul@15 | 68 | |
paul@15 | 69 | else: |
paul@15 | 70 | self.updates.append(message) |
paul@6 | 71 | |
paul@16 | 72 | def add_updates(self, parts): |
paul@13 | 73 | |
paul@13 | 74 | """ |
paul@16 | 75 | Add the given 'parts' to a message. |
paul@13 | 76 | """ |
paul@13 | 77 | |
paul@16 | 78 | for part in updates: |
paul@16 | 79 | self.add_update(part) |
paul@16 | 80 | |
paul@16 | 81 | def add_update(self, part): |
paul@16 | 82 | |
paul@16 | 83 | """ |
paul@16 | 84 | Add an update 'part' to a message. |
paul@16 | 85 | """ |
paul@16 | 86 | |
paul@16 | 87 | self.updates.append(part) |
paul@16 | 88 | |
paul@16 | 89 | def get_update(self, alternatives): |
paul@16 | 90 | |
paul@16 | 91 | """ |
paul@16 | 92 | Return a suitable multipart object containing the supplied |
paul@16 | 93 | 'alternatives'. |
paul@16 | 94 | """ |
paul@16 | 95 | |
paul@16 | 96 | part = MIMEMultipart() |
paul@16 | 97 | for alternative in alternatives: |
paul@16 | 98 | part.attach(alternative) |
paul@16 | 99 | return part |
paul@6 | 100 | |
paul@20 | 101 | def get_payload(self, timestamped=True): |
paul@13 | 102 | |
paul@20 | 103 | """ |
paul@20 | 104 | Get the multipart payload for the message. If the 'timestamped' |
paul@20 | 105 | parameter is omitted or set to a true value, the payload will be given a |
paul@20 | 106 | date header set to the current date and time that can be used to assess |
paul@20 | 107 | the validity of a message and to determine whether it has already been |
paul@20 | 108 | received by a recipient. |
paul@20 | 109 | """ |
paul@13 | 110 | |
paul@6 | 111 | if len(self.updates) == 1: |
paul@6 | 112 | message = self.updates[0] |
paul@6 | 113 | else: |
paul@6 | 114 | message = MIMEMultipart() |
paul@6 | 115 | message.add_header("Update-Type", "collection") |
paul@6 | 116 | for update in self.updates: |
paul@6 | 117 | message.attach(update) |
paul@6 | 118 | |
paul@20 | 119 | if timestamped: |
paul@20 | 120 | timestamp(message) |
paul@20 | 121 | self.init_date(message) |
paul@20 | 122 | |
paul@6 | 123 | return message |
paul@6 | 124 | |
paul@15 | 125 | class Mailbox: |
paul@15 | 126 | |
paul@15 | 127 | "A collection of messages within a multipart message." |
paul@15 | 128 | |
paul@15 | 129 | def __init__(self, text=None): |
paul@15 | 130 | self.messages = [] |
paul@15 | 131 | if text: |
paul@15 | 132 | self.parse_text(text) |
paul@15 | 133 | |
paul@15 | 134 | def parse_text(self, text): |
paul@15 | 135 | |
paul@15 | 136 | "Parse the given 'text' as a mailbox." |
paul@15 | 137 | |
paul@15 | 138 | message = message_from_string(text) |
paul@15 | 139 | |
paul@15 | 140 | if message.is_multipart(): |
paul@15 | 141 | for part in message.get_payload(): |
paul@15 | 142 | self.messages.append(part) |
paul@15 | 143 | else: |
paul@15 | 144 | self.messages.append(message) |
paul@15 | 145 | |
paul@15 | 146 | def add_message(self, message): |
paul@15 | 147 | |
paul@15 | 148 | "Add the given 'message' to the mailbox." |
paul@15 | 149 | |
paul@15 | 150 | self.messages.append(message) |
paul@15 | 151 | |
paul@15 | 152 | def get_payload(self): |
paul@15 | 153 | |
paul@15 | 154 | "Get the multipart payload for the mailbox." |
paul@15 | 155 | |
paul@15 | 156 | mailbox = MIMEMultipart() |
paul@15 | 157 | for message in self.messages: |
paul@15 | 158 | mailbox.attach(message) |
paul@15 | 159 | |
paul@15 | 160 | return mailbox |
paul@15 | 161 | |
paul@6 | 162 | class MoinMessageError(Exception): |
paul@6 | 163 | pass |
paul@6 | 164 | |
paul@33 | 165 | class MoinMessageDecodingError(Exception): |
paul@33 | 166 | pass |
paul@33 | 167 | |
paul@33 | 168 | class MoinMessageMissingPart(MoinMessageDecodingError): |
paul@33 | 169 | pass |
paul@33 | 170 | |
paul@33 | 171 | class MoinMessageBadContent(MoinMessageDecodingError): |
paul@33 | 172 | pass |
paul@33 | 173 | |
paul@8 | 174 | class GPG: |
paul@8 | 175 | |
paul@8 | 176 | "A wrapper around the gpg command using a particular configuration." |
paul@6 | 177 | |
paul@8 | 178 | def __init__(self, homedir=None): |
paul@8 | 179 | self.conf_args = [] |
paul@6 | 180 | |
paul@8 | 181 | if homedir: |
paul@8 | 182 | self.conf_args += ["--homedir", homedir] |
paul@8 | 183 | |
paul@8 | 184 | self.errors = None |
paul@6 | 185 | |
paul@8 | 186 | def run(self, args, text=None): |
paul@6 | 187 | |
paul@8 | 188 | """ |
paul@8 | 189 | Invoke gpg with the given 'args', supplying the given 'text' to the |
paul@8 | 190 | command directly or, if 'text' is omitted, using a file provided as part |
paul@8 | 191 | of the 'args' if appropriate. |
paul@6 | 192 | |
paul@8 | 193 | Failure to complete the operation will result in a MoinMessageError |
paul@8 | 194 | being raised. |
paul@8 | 195 | """ |
paul@8 | 196 | |
paul@8 | 197 | cmd = Popen(["gpg"] + self.conf_args + list(args), stdin=PIPE, stdout=PIPE, stderr=PIPE) |
paul@6 | 198 | |
paul@58 | 199 | # Attempt to write input to the command and to read output from the |
paul@58 | 200 | # command. |
paul@11 | 201 | |
paul@58 | 202 | text, self.errors = cmd.communicate(text) |
paul@8 | 203 | |
paul@58 | 204 | # Test for a zero result. |
paul@6 | 205 | |
paul@58 | 206 | if not cmd.returncode: |
paul@58 | 207 | return text |
paul@58 | 208 | else: |
paul@58 | 209 | raise MoinMessageError, self.errors |
paul@6 | 210 | |
paul@33 | 211 | def verifyMessageText(self, signature, content): |
paul@8 | 212 | |
paul@8 | 213 | "Using the given 'signature', verify the given message 'content'." |
paul@6 | 214 | |
paul@8 | 215 | # Write the detached signature and content to files. |
paul@8 | 216 | |
paul@8 | 217 | signature_fd, signature_filename = mkstemp() |
paul@8 | 218 | content_fd, content_filename = mkstemp() |
paul@6 | 219 | |
paul@8 | 220 | try: |
paul@8 | 221 | signature_fp = os.fdopen(signature_fd, "w") |
paul@8 | 222 | content_fp = os.fdopen(content_fd, "w") |
paul@8 | 223 | try: |
paul@8 | 224 | signature_fp.write(signature) |
paul@8 | 225 | content_fp.write(content) |
paul@8 | 226 | finally: |
paul@8 | 227 | signature_fp.close() |
paul@8 | 228 | content_fp.close() |
paul@6 | 229 | |
paul@8 | 230 | # Verify the message text. |
paul@6 | 231 | |
paul@10 | 232 | text = self.run(["--status-fd", "1", "--verify", signature_filename, content_filename]) |
paul@10 | 233 | |
paul@10 | 234 | # Return the details of the signing key. |
paul@10 | 235 | |
paul@11 | 236 | identity = None |
paul@11 | 237 | fingerprint = None |
paul@11 | 238 | |
paul@10 | 239 | for line in text.split("\n"): |
paul@10 | 240 | try: |
paul@11 | 241 | prefix, msgtype, digest, details = line.strip().split(" ", 3) |
paul@10 | 242 | except ValueError: |
paul@10 | 243 | continue |
paul@10 | 244 | |
paul@10 | 245 | # Return the fingerprint and identity details. |
paul@10 | 246 | |
paul@10 | 247 | if msgtype == "GOODSIG": |
paul@11 | 248 | identity = details |
paul@11 | 249 | elif msgtype == "VALIDSIG": |
paul@11 | 250 | fingerprint = digest |
paul@11 | 251 | |
paul@11 | 252 | if identity and fingerprint: |
paul@11 | 253 | return fingerprint, identity |
paul@10 | 254 | |
paul@10 | 255 | return None |
paul@6 | 256 | |
paul@8 | 257 | finally: |
paul@8 | 258 | os.remove(signature_filename) |
paul@8 | 259 | os.remove(content_filename) |
paul@8 | 260 | |
paul@33 | 261 | def verifyMessage(self, message): |
paul@33 | 262 | |
paul@33 | 263 | """ |
paul@33 | 264 | Verify the given RFC 3156 'message', returning a tuple of the form |
paul@33 | 265 | (fingerprint, identity, content). |
paul@33 | 266 | """ |
paul@33 | 267 | |
paul@36 | 268 | content, signature = getContentAndSignature(message) |
paul@33 | 269 | |
paul@33 | 270 | # Verify the message format. |
paul@33 | 271 | |
paul@33 | 272 | if signature.get_content_type() != "application/pgp-signature": |
paul@33 | 273 | raise MoinMessageBadContent |
paul@33 | 274 | |
paul@33 | 275 | # Verify the message. |
paul@33 | 276 | |
paul@33 | 277 | fingerprint, identity = self.verifyMessageText(signature.get_payload(), content.as_string()) |
paul@33 | 278 | return fingerprint, identity, content |
paul@33 | 279 | |
paul@8 | 280 | def signMessage(self, message, keyid): |
paul@6 | 281 | |
paul@8 | 282 | """ |
paul@8 | 283 | Return a signed version of 'message' using the given 'keyid'. |
paul@8 | 284 | """ |
paul@6 | 285 | |
paul@8 | 286 | text = message.as_string() |
paul@8 | 287 | signature = self.run(["--armor", "-u", keyid, "--detach-sig"], text) |
paul@8 | 288 | |
paul@8 | 289 | # Make the container for the message. |
paul@8 | 290 | |
paul@8 | 291 | signed_message = MIMEMultipart("signed", protocol="application/pgp-signature") |
paul@8 | 292 | signed_message.attach(message) |
paul@6 | 293 | |
paul@8 | 294 | signature_part = MIMEBase("application", "pgp-signature") |
paul@8 | 295 | signature_part.set_payload(signature) |
paul@8 | 296 | signed_message.attach(signature_part) |
paul@8 | 297 | |
paul@8 | 298 | return signed_message |
paul@8 | 299 | |
paul@33 | 300 | def decryptMessageText(self, message): |
paul@6 | 301 | |
paul@8 | 302 | "Return a decrypted version of 'message'." |
paul@8 | 303 | |
paul@8 | 304 | return self.run(["--decrypt"], message) |
paul@6 | 305 | |
paul@33 | 306 | def decryptMessage(self, message): |
paul@33 | 307 | |
paul@33 | 308 | """ |
paul@33 | 309 | Decrypt the given RFC 3156 'message', returning the message text. |
paul@33 | 310 | """ |
paul@33 | 311 | |
paul@33 | 312 | try: |
paul@33 | 313 | declaration, content = message.get_payload() |
paul@33 | 314 | except ValueError: |
paul@33 | 315 | raise MoinMessageMissingPart |
paul@33 | 316 | |
paul@33 | 317 | # Verify the message format. |
paul@33 | 318 | |
paul@33 | 319 | if content.get_content_type() != "application/octet-stream": |
paul@33 | 320 | raise MoinMessageBadContent |
paul@33 | 321 | |
paul@33 | 322 | # Return the decrypted message text. |
paul@33 | 323 | |
paul@33 | 324 | return self.decryptMessageText(content.get_payload()) |
paul@33 | 325 | |
paul@8 | 326 | def encryptMessage(self, message, keyid): |
paul@6 | 327 | |
paul@8 | 328 | """ |
paul@8 | 329 | Return an encrypted version of 'message' using the given 'keyid'. |
paul@8 | 330 | """ |
paul@6 | 331 | |
paul@8 | 332 | text = message.as_string() |
paul@8 | 333 | encrypted = self.run(["--armor", "-r", keyid, "--encrypt", "--trust-model", "always"], text) |
paul@8 | 334 | |
paul@8 | 335 | # Make the container for the message. |
paul@8 | 336 | |
paul@8 | 337 | encrypted_message = MIMEMultipart("encrypted", protocol="application/pgp-encrypted") |
paul@8 | 338 | |
paul@8 | 339 | # For encrypted content, add the declaration and content. |
paul@6 | 340 | |
paul@8 | 341 | declaration = MIMEBase("application", "pgp-encrypted") |
paul@8 | 342 | declaration.set_payload("Version: 1") |
paul@8 | 343 | encrypted_message.attach(declaration) |
paul@6 | 344 | |
paul@8 | 345 | content = MIMEApplication(encrypted, "octet-stream", encode_noop) |
paul@8 | 346 | encrypted_message.attach(content) |
paul@6 | 347 | |
paul@8 | 348 | return encrypted_message |
paul@8 | 349 | |
paul@33 | 350 | # Message decoding functions. |
paul@33 | 351 | |
paul@33 | 352 | # Detect PGP/GPG-encoded payloads. |
paul@33 | 353 | # See: http://tools.ietf.org/html/rfc3156 |
paul@33 | 354 | |
paul@33 | 355 | def is_signed(message): |
paul@33 | 356 | mimetype = message.get_content_type() |
paul@33 | 357 | encoding = message.get_content_charset() |
paul@33 | 358 | |
paul@33 | 359 | return mimetype == "multipart/signed" and \ |
paul@33 | 360 | message.get_param("protocol") == "application/pgp-signature" |
paul@33 | 361 | |
paul@33 | 362 | def is_encrypted(message): |
paul@33 | 363 | mimetype = message.get_content_type() |
paul@33 | 364 | encoding = message.get_content_charset() |
paul@33 | 365 | |
paul@33 | 366 | return mimetype == "multipart/encrypted" and \ |
paul@33 | 367 | message.get_param("protocol") == "application/pgp-encrypted" |
paul@33 | 368 | |
paul@36 | 369 | def getContentAndSignature(message): |
paul@36 | 370 | |
paul@36 | 371 | """ |
paul@36 | 372 | Return the content and signature parts of the given RFC 3156 'message'. |
paul@36 | 373 | |
paul@36 | 374 | NOTE: RFC 3156 states that signed messages should employ a detached |
paul@36 | 375 | NOTE: signature but then shows "BEGIN PGP MESSAGE" for signatures |
paul@36 | 376 | NOTE: instead of "BEGIN PGP SIGNATURE". |
paul@36 | 377 | NOTE: The "micalg" parameter is currently not supported. |
paul@36 | 378 | """ |
paul@36 | 379 | |
paul@36 | 380 | try: |
paul@36 | 381 | content, signature = message.get_payload() |
paul@36 | 382 | return content, signature |
paul@36 | 383 | except ValueError: |
paul@36 | 384 | raise MoinMessageMissingPart |
paul@36 | 385 | |
paul@8 | 386 | # Communications functions. |
paul@6 | 387 | |
paul@20 | 388 | def timestamp(message): |
paul@20 | 389 | |
paul@20 | 390 | """ |
paul@20 | 391 | Timestamp the given 'message' so that its validity can be assessed by the |
paul@20 | 392 | recipient. |
paul@20 | 393 | """ |
paul@20 | 394 | |
paul@20 | 395 | datestr = formatdate() |
paul@20 | 396 | |
paul@20 | 397 | if not message.has_key("Date"): |
paul@20 | 398 | message.add_header("Date", datestr) |
paul@20 | 399 | else: |
paul@20 | 400 | message["Date"] = datestr |
paul@20 | 401 | |
paul@44 | 402 | def sendMessage(message, url, method="PUT"): |
paul@6 | 403 | |
paul@44 | 404 | """ |
paul@44 | 405 | Send 'message' to the given 'url' using the given 'method' (using PUT as the |
paul@44 | 406 | default if omitted). |
paul@44 | 407 | """ |
paul@6 | 408 | |
paul@12 | 409 | scheme, host, port, path = parseURL(url) |
paul@6 | 410 | text = message.as_string() |
paul@6 | 411 | |
paul@12 | 412 | if scheme == "http": |
paul@12 | 413 | cls = httplib.HTTPConnection |
paul@12 | 414 | elif scheme == "https": |
paul@12 | 415 | cls = httplib.HTTPSConnection |
paul@12 | 416 | else: |
paul@12 | 417 | raise MoinMessageError, "Communications protocol not supported: %s" % scheme |
paul@12 | 418 | |
paul@12 | 419 | req = cls(host, port) |
paul@44 | 420 | req.request(method, path, text) |
paul@6 | 421 | resp = req.getresponse() |
paul@39 | 422 | |
paul@39 | 423 | if resp.status >= 400: |
paul@39 | 424 | raise MoinMessageError, "Message sending failed: %s" % resp.status |
paul@39 | 425 | |
paul@6 | 426 | return resp.read() |
paul@6 | 427 | |
paul@12 | 428 | def parseURL(url): |
paul@12 | 429 | |
paul@12 | 430 | "Return the scheme, host, port and path for the given 'url'." |
paul@12 | 431 | |
paul@12 | 432 | scheme, host_port, path, query, fragment = urlsplit(url) |
paul@12 | 433 | host_port = host_port.split(":") |
paul@12 | 434 | |
paul@12 | 435 | if query: |
paul@12 | 436 | path += "?" + query |
paul@12 | 437 | |
paul@12 | 438 | if len(host_port) > 1: |
paul@12 | 439 | host = host_port[0] |
paul@12 | 440 | port = int(host_port[1]) |
paul@12 | 441 | else: |
paul@12 | 442 | host = host_port[0] |
paul@12 | 443 | port = 80 |
paul@12 | 444 | |
paul@12 | 445 | return scheme, host, port, path |
paul@12 | 446 | |
paul@6 | 447 | # vim: tabstop=4 expandtab shiftwidth=4 |