paul@6 | 1 | # -*- coding: iso-8859-1 -*- |
paul@6 | 2 | """ |
paul@6 | 3 | MoinMoin - MoinMessage library |
paul@6 | 4 | |
paul@6 | 5 | @copyright: 2012 by Paul Boddie <paul@boddie.org.uk> |
paul@6 | 6 | @license: GNU GPL (v2 or later), see COPYING.txt for details. |
paul@6 | 7 | """ |
paul@6 | 8 | |
paul@6 | 9 | from email import message_from_string |
paul@6 | 10 | from email.encoders import encode_noop |
paul@6 | 11 | from email.mime.multipart import MIMEMultipart |
paul@6 | 12 | from email.mime.application import MIMEApplication |
paul@6 | 13 | from email.mime.base import MIMEBase |
paul@6 | 14 | from email.mime.text import MIMEText |
paul@6 | 15 | from subprocess import Popen, PIPE |
paul@8 | 16 | from tempfile import mkstemp |
paul@6 | 17 | import httplib |
paul@8 | 18 | import os |
paul@6 | 19 | |
paul@6 | 20 | class Message: |
paul@6 | 21 | |
paul@6 | 22 | "An update message." |
paul@6 | 23 | |
paul@6 | 24 | def __init__(self): |
paul@6 | 25 | self.updates = [] |
paul@6 | 26 | |
paul@6 | 27 | def add_update(self, alternatives): |
paul@6 | 28 | if len(alternatives) > 1: |
paul@6 | 29 | part = MIMEMultipart() |
paul@6 | 30 | for alternative in alternatives: |
paul@6 | 31 | part.attach(alternative) |
paul@6 | 32 | self.updates.append(part) |
paul@6 | 33 | else: |
paul@6 | 34 | self.updates.append(alternatives[0]) |
paul@6 | 35 | |
paul@6 | 36 | def get_payload(self): |
paul@6 | 37 | if len(self.updates) == 1: |
paul@6 | 38 | message = self.updates[0] |
paul@6 | 39 | else: |
paul@6 | 40 | message = MIMEMultipart() |
paul@6 | 41 | message.add_header("Update-Type", "collection") |
paul@6 | 42 | for update in self.updates: |
paul@6 | 43 | message.attach(update) |
paul@6 | 44 | |
paul@6 | 45 | return message |
paul@6 | 46 | |
paul@6 | 47 | class MoinMessageError(Exception): |
paul@6 | 48 | pass |
paul@6 | 49 | |
paul@8 | 50 | class GPG: |
paul@8 | 51 | |
paul@8 | 52 | "A wrapper around the gpg command using a particular configuration." |
paul@6 | 53 | |
paul@8 | 54 | def __init__(self, homedir=None): |
paul@8 | 55 | self.conf_args = [] |
paul@6 | 56 | |
paul@8 | 57 | if homedir: |
paul@8 | 58 | self.conf_args += ["--homedir", homedir] |
paul@8 | 59 | |
paul@8 | 60 | self.errors = None |
paul@6 | 61 | |
paul@8 | 62 | def run(self, args, text=None): |
paul@6 | 63 | |
paul@8 | 64 | """ |
paul@8 | 65 | Invoke gpg with the given 'args', supplying the given 'text' to the |
paul@8 | 66 | command directly or, if 'text' is omitted, using a file provided as part |
paul@8 | 67 | of the 'args' if appropriate. |
paul@6 | 68 | |
paul@8 | 69 | Failure to complete the operation will result in a MoinMessageError |
paul@8 | 70 | being raised. |
paul@8 | 71 | """ |
paul@8 | 72 | |
paul@8 | 73 | cmd = Popen(["gpg"] + self.conf_args + list(args), stdin=PIPE, stdout=PIPE, stderr=PIPE) |
paul@6 | 74 | |
paul@11 | 75 | try: |
paul@11 | 76 | # Attempt to write input to the command and to read output from the |
paul@11 | 77 | # command. |
paul@11 | 78 | |
paul@11 | 79 | try: |
paul@11 | 80 | if text: |
paul@11 | 81 | cmd.stdin.write(text) |
paul@11 | 82 | cmd.stdin.close() |
paul@6 | 83 | |
paul@11 | 84 | text = cmd.stdout.read() |
paul@11 | 85 | |
paul@11 | 86 | # I/O errors can indicate the failure of the command. |
paul@8 | 87 | |
paul@11 | 88 | except IOError: |
paul@11 | 89 | pass |
paul@11 | 90 | |
paul@11 | 91 | self.errors = cmd.stderr.read() |
paul@8 | 92 | |
paul@8 | 93 | # Test for a zero result. |
paul@6 | 94 | |
paul@8 | 95 | if not cmd.wait(): |
paul@8 | 96 | return text |
paul@8 | 97 | else: |
paul@10 | 98 | raise MoinMessageError, self.errors |
paul@8 | 99 | |
paul@8 | 100 | finally: |
paul@8 | 101 | cmd.stdout.close() |
paul@8 | 102 | cmd.stderr.close() |
paul@6 | 103 | |
paul@8 | 104 | def verifyMessage(self, signature, content): |
paul@8 | 105 | |
paul@8 | 106 | "Using the given 'signature', verify the given message 'content'." |
paul@6 | 107 | |
paul@8 | 108 | # Write the detached signature and content to files. |
paul@8 | 109 | |
paul@8 | 110 | signature_fd, signature_filename = mkstemp() |
paul@8 | 111 | content_fd, content_filename = mkstemp() |
paul@6 | 112 | |
paul@8 | 113 | try: |
paul@8 | 114 | signature_fp = os.fdopen(signature_fd, "w") |
paul@8 | 115 | content_fp = os.fdopen(content_fd, "w") |
paul@8 | 116 | try: |
paul@8 | 117 | signature_fp.write(signature) |
paul@8 | 118 | content_fp.write(content) |
paul@8 | 119 | finally: |
paul@8 | 120 | signature_fp.close() |
paul@8 | 121 | content_fp.close() |
paul@6 | 122 | |
paul@8 | 123 | # Verify the message text. |
paul@6 | 124 | |
paul@10 | 125 | text = self.run(["--status-fd", "1", "--verify", signature_filename, content_filename]) |
paul@10 | 126 | |
paul@10 | 127 | # Return the details of the signing key. |
paul@10 | 128 | |
paul@11 | 129 | identity = None |
paul@11 | 130 | fingerprint = None |
paul@11 | 131 | |
paul@10 | 132 | for line in text.split("\n"): |
paul@10 | 133 | try: |
paul@11 | 134 | prefix, msgtype, digest, details = line.strip().split(" ", 3) |
paul@10 | 135 | except ValueError: |
paul@10 | 136 | continue |
paul@10 | 137 | |
paul@10 | 138 | # Return the fingerprint and identity details. |
paul@10 | 139 | |
paul@10 | 140 | if msgtype == "GOODSIG": |
paul@11 | 141 | identity = details |
paul@11 | 142 | elif msgtype == "VALIDSIG": |
paul@11 | 143 | fingerprint = digest |
paul@11 | 144 | |
paul@11 | 145 | if identity and fingerprint: |
paul@11 | 146 | return fingerprint, identity |
paul@10 | 147 | |
paul@10 | 148 | return None |
paul@6 | 149 | |
paul@8 | 150 | finally: |
paul@8 | 151 | os.remove(signature_filename) |
paul@8 | 152 | os.remove(content_filename) |
paul@8 | 153 | |
paul@8 | 154 | def signMessage(self, message, keyid): |
paul@6 | 155 | |
paul@8 | 156 | """ |
paul@8 | 157 | Return a signed version of 'message' using the given 'keyid'. |
paul@8 | 158 | """ |
paul@6 | 159 | |
paul@8 | 160 | text = message.as_string() |
paul@8 | 161 | signature = self.run(["--armor", "-u", keyid, "--detach-sig"], text) |
paul@8 | 162 | |
paul@8 | 163 | # Make the container for the message. |
paul@8 | 164 | |
paul@8 | 165 | signed_message = MIMEMultipart("signed", protocol="application/pgp-signature") |
paul@8 | 166 | signed_message.attach(message) |
paul@6 | 167 | |
paul@8 | 168 | signature_part = MIMEBase("application", "pgp-signature") |
paul@8 | 169 | signature_part.set_payload(signature) |
paul@8 | 170 | signed_message.attach(signature_part) |
paul@8 | 171 | |
paul@8 | 172 | return signed_message |
paul@8 | 173 | |
paul@8 | 174 | def decryptMessage(self, message): |
paul@6 | 175 | |
paul@8 | 176 | "Return a decrypted version of 'message'." |
paul@8 | 177 | |
paul@8 | 178 | return self.run(["--decrypt"], message) |
paul@6 | 179 | |
paul@8 | 180 | def encryptMessage(self, message, keyid): |
paul@6 | 181 | |
paul@8 | 182 | """ |
paul@8 | 183 | Return an encrypted version of 'message' using the given 'keyid'. |
paul@8 | 184 | """ |
paul@6 | 185 | |
paul@8 | 186 | text = message.as_string() |
paul@8 | 187 | encrypted = self.run(["--armor", "-r", keyid, "--encrypt", "--trust-model", "always"], text) |
paul@8 | 188 | |
paul@8 | 189 | # Make the container for the message. |
paul@8 | 190 | |
paul@8 | 191 | encrypted_message = MIMEMultipart("encrypted", protocol="application/pgp-encrypted") |
paul@8 | 192 | |
paul@8 | 193 | # For encrypted content, add the declaration and content. |
paul@6 | 194 | |
paul@8 | 195 | declaration = MIMEBase("application", "pgp-encrypted") |
paul@8 | 196 | declaration.set_payload("Version: 1") |
paul@8 | 197 | encrypted_message.attach(declaration) |
paul@6 | 198 | |
paul@8 | 199 | content = MIMEApplication(encrypted, "octet-stream", encode_noop) |
paul@8 | 200 | encrypted_message.attach(content) |
paul@6 | 201 | |
paul@8 | 202 | return encrypted_message |
paul@8 | 203 | |
paul@8 | 204 | # Communications functions. |
paul@6 | 205 | |
paul@6 | 206 | def sendMessage(message, host, path): |
paul@6 | 207 | |
paul@6 | 208 | "Send 'message' to the given 'host' using the specified URL 'path'." |
paul@6 | 209 | |
paul@6 | 210 | text = message.as_string() |
paul@6 | 211 | |
paul@6 | 212 | req = httplib.HTTPConnection(host) |
paul@6 | 213 | req.request("PUT", path, text) # {"Content-Length" : len(text)} |
paul@6 | 214 | resp = req.getresponse() |
paul@6 | 215 | return resp.read() |
paul@6 | 216 | |
paul@6 | 217 | # vim: tabstop=4 expandtab shiftwidth=4 |