GatekeeperService.cs 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520
  1. /*
  2. * Copyright (c) Contributors, http://opensimulator.org/
  3. * See CONTRIBUTORS.TXT for a full list of copyright holders.
  4. *
  5. * Redistribution and use in source and binary forms, with or without
  6. * modification, are permitted provided that the following conditions are met:
  7. * * Redistributions of source code must retain the above copyright
  8. * notice, this list of conditions and the following disclaimer.
  9. * * Redistributions in binary form must reproduce the above copyright
  10. * notice, this list of conditions and the following disclaimer in the
  11. * documentation and/or other materials provided with the distribution.
  12. * * Neither the name of the OpenSimulator Project nor the
  13. * names of its contributors may be used to endorse or promote products
  14. * derived from this software without specific prior written permission.
  15. *
  16. * THIS SOFTWARE IS PROVIDED BY THE DEVELOPERS ``AS IS'' AND ANY
  17. * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
  18. * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  19. * DISCLAIMED. IN NO EVENT SHALL THE CONTRIBUTORS BE LIABLE FOR ANY
  20. * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
  21. * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  22. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
  23. * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
  24. * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
  25. * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  26. */
  27. using System;
  28. using System.Collections.Generic;
  29. using System.Net;
  30. using System.Reflection;
  31. using System.Text.RegularExpressions;
  32. using OpenSim.Framework;
  33. using OpenSim.Services.Interfaces;
  34. using GridRegion = OpenSim.Services.Interfaces.GridRegion;
  35. using OpenSim.Server.Base;
  36. using OpenSim.Services.Connectors.Hypergrid;
  37. using OpenMetaverse;
  38. using Nini.Config;
  39. using log4net;
  40. namespace OpenSim.Services.HypergridService
  41. {
  42. public class GatekeeperService : IGatekeeperService
  43. {
  44. private static readonly ILog m_log =
  45. LogManager.GetLogger(
  46. MethodBase.GetCurrentMethod().DeclaringType);
  47. private static bool m_Initialized = false;
  48. private static IGridService m_GridService;
  49. private static IPresenceService m_PresenceService;
  50. private static IUserAccountService m_UserAccountService;
  51. private static IUserAgentService m_UserAgentService;
  52. private static ISimulationService m_SimulationService;
  53. private static IGridUserService m_GridUserService;
  54. private static IBansService m_BansService;
  55. private static string m_AllowedClients = string.Empty;
  56. private static string m_DeniedClients = string.Empty;
  57. private static bool m_ForeignAgentsAllowed = true;
  58. private static List<string> m_ForeignsAllowedExceptions = new List<string>();
  59. private static List<string> m_ForeignsDisallowedExceptions = new List<string>();
  60. private static UUID m_ScopeID;
  61. private static bool m_AllowTeleportsToAnyRegion;
  62. private static string m_ExternalName;
  63. private static Uri m_Uri;
  64. private static GridRegion m_DefaultGatewayRegion;
  65. public GatekeeperService(IConfigSource config, ISimulationService simService)
  66. {
  67. if (!m_Initialized)
  68. {
  69. m_Initialized = true;
  70. IConfig serverConfig = config.Configs["GatekeeperService"];
  71. if (serverConfig == null)
  72. throw new Exception(String.Format("No section GatekeeperService in config file"));
  73. string accountService = serverConfig.GetString("UserAccountService", String.Empty);
  74. string homeUsersService = serverConfig.GetString("UserAgentService", string.Empty);
  75. string gridService = serverConfig.GetString("GridService", String.Empty);
  76. string presenceService = serverConfig.GetString("PresenceService", String.Empty);
  77. string simulationService = serverConfig.GetString("SimulationService", String.Empty);
  78. string gridUserService = serverConfig.GetString("GridUserService", String.Empty);
  79. string bansService = serverConfig.GetString("BansService", String.Empty);
  80. // These are mandatory, the others aren't
  81. if (gridService == string.Empty || presenceService == string.Empty)
  82. throw new Exception("Incomplete specifications, Gatekeeper Service cannot function.");
  83. string scope = serverConfig.GetString("ScopeID", UUID.Zero.ToString());
  84. UUID.TryParse(scope, out m_ScopeID);
  85. //m_WelcomeMessage = serverConfig.GetString("WelcomeMessage", "Welcome to OpenSim!");
  86. m_AllowTeleportsToAnyRegion = serverConfig.GetBoolean("AllowTeleportsToAnyRegion", true);
  87. m_ExternalName = Util.GetConfigVarFromSections<string>(config, "GatekeeperURI",
  88. new string[] { "Startup", "Hypergrid", "GatekeeperService" }, String.Empty);
  89. m_ExternalName = serverConfig.GetString("ExternalName", m_ExternalName);
  90. if (m_ExternalName != string.Empty && !m_ExternalName.EndsWith("/"))
  91. m_ExternalName = m_ExternalName + "/";
  92. try
  93. {
  94. m_Uri = new Uri(m_ExternalName);
  95. }
  96. catch
  97. {
  98. m_log.WarnFormat("[GATEKEEPER SERVICE]: Malformed gatekeeper address {0}", m_ExternalName);
  99. }
  100. Object[] args = new Object[] { config };
  101. m_GridService = ServerUtils.LoadPlugin<IGridService>(gridService, args);
  102. m_PresenceService = ServerUtils.LoadPlugin<IPresenceService>(presenceService, args);
  103. if (accountService != string.Empty)
  104. m_UserAccountService = ServerUtils.LoadPlugin<IUserAccountService>(accountService, args);
  105. if (homeUsersService != string.Empty)
  106. m_UserAgentService = ServerUtils.LoadPlugin<IUserAgentService>(homeUsersService, args);
  107. if (gridUserService != string.Empty)
  108. m_GridUserService = ServerUtils.LoadPlugin<IGridUserService>(gridUserService, args);
  109. if (bansService != string.Empty)
  110. m_BansService = ServerUtils.LoadPlugin<IBansService>(bansService, args);
  111. if (simService != null)
  112. m_SimulationService = simService;
  113. else if (simulationService != string.Empty)
  114. m_SimulationService = ServerUtils.LoadPlugin<ISimulationService>(simulationService, args);
  115. m_AllowedClients = serverConfig.GetString("AllowedClients", string.Empty);
  116. m_DeniedClients = serverConfig.GetString("DeniedClients", string.Empty);
  117. m_ForeignAgentsAllowed = serverConfig.GetBoolean("ForeignAgentsAllowed", true);
  118. LoadDomainExceptionsFromConfig(serverConfig, "AllowExcept", m_ForeignsAllowedExceptions);
  119. LoadDomainExceptionsFromConfig(serverConfig, "DisallowExcept", m_ForeignsDisallowedExceptions);
  120. if (m_GridService == null || m_PresenceService == null || m_SimulationService == null)
  121. throw new Exception("Unable to load a required plugin, Gatekeeper Service cannot function.");
  122. m_log.Debug("[GATEKEEPER SERVICE]: Starting...");
  123. }
  124. }
  125. public GatekeeperService(IConfigSource config)
  126. : this(config, null)
  127. {
  128. }
  129. protected void LoadDomainExceptionsFromConfig(IConfig config, string variable, List<string> exceptions)
  130. {
  131. string value = config.GetString(variable, string.Empty);
  132. string[] parts = value.Split(new char[] { ',' }, StringSplitOptions.RemoveEmptyEntries);
  133. foreach (string s in parts)
  134. exceptions.Add(s.Trim());
  135. }
  136. public bool LinkRegion(string regionName, out UUID regionID, out ulong regionHandle, out string externalName, out string imageURL, out string reason)
  137. {
  138. regionID = UUID.Zero;
  139. regionHandle = 0;
  140. externalName = m_ExternalName + ((regionName != string.Empty) ? " " + regionName : "");
  141. imageURL = string.Empty;
  142. reason = string.Empty;
  143. GridRegion region = null;
  144. m_log.DebugFormat("[GATEKEEPER SERVICE]: Request to link to {0}", (regionName == string.Empty)? "default region" : regionName);
  145. if (!m_AllowTeleportsToAnyRegion || regionName == string.Empty)
  146. {
  147. List<GridRegion> defs = m_GridService.GetDefaultHypergridRegions(m_ScopeID);
  148. if (defs != null && defs.Count > 0)
  149. {
  150. region = defs[0];
  151. m_DefaultGatewayRegion = region;
  152. }
  153. else
  154. {
  155. reason = "Grid setup problem. Try specifying a particular region here.";
  156. m_log.DebugFormat("[GATEKEEPER SERVICE]: Unable to send information. Please specify a default region for this grid!");
  157. return false;
  158. }
  159. }
  160. else
  161. {
  162. region = m_GridService.GetRegionByName(m_ScopeID, regionName);
  163. if (region == null)
  164. {
  165. reason = "Region not found";
  166. return false;
  167. }
  168. }
  169. regionID = region.RegionID;
  170. regionHandle = region.RegionHandle;
  171. string regionimage = "regionImage" + regionID.ToString();
  172. regionimage = regionimage.Replace("-", "");
  173. imageURL = region.ServerURI + "index.php?method=" + regionimage;
  174. return true;
  175. }
  176. public GridRegion GetHyperlinkRegion(UUID regionID)
  177. {
  178. m_log.DebugFormat("[GATEKEEPER SERVICE]: Request to get hyperlink region {0}", regionID);
  179. if (!m_AllowTeleportsToAnyRegion)
  180. // Don't even check the given regionID
  181. return m_DefaultGatewayRegion;
  182. GridRegion region = m_GridService.GetRegionByUUID(m_ScopeID, regionID);
  183. return region;
  184. }
  185. #region Login Agent
  186. public bool LoginAgent(AgentCircuitData aCircuit, GridRegion destination, out string reason)
  187. {
  188. reason = string.Empty;
  189. string authURL = string.Empty;
  190. if (aCircuit.ServiceURLs.ContainsKey("HomeURI"))
  191. authURL = aCircuit.ServiceURLs["HomeURI"].ToString();
  192. m_log.InfoFormat("[GATEKEEPER SERVICE]: Login request for {0} {1} @ {2} ({3}) at {4} using viewer {5}, channel {6}, IP {7}, Mac {8}, Id0 {9} Teleport Flags {10}",
  193. aCircuit.firstname, aCircuit.lastname, authURL, aCircuit.AgentID, destination.RegionName,
  194. aCircuit.Viewer, aCircuit.Channel, aCircuit.IPAddress, aCircuit.Mac, aCircuit.Id0, aCircuit.teleportFlags.ToString());
  195. string curViewer = Util.GetViewerName(aCircuit);
  196. //
  197. // Check client
  198. //
  199. if (m_AllowedClients != string.Empty)
  200. {
  201. Regex arx = new Regex(m_AllowedClients);
  202. Match am = arx.Match(curViewer);
  203. if (!am.Success)
  204. {
  205. m_log.InfoFormat("[GATEKEEPER SERVICE]: Login failed, reason: client {0} is not allowed", curViewer);
  206. return false;
  207. }
  208. }
  209. if (m_DeniedClients != string.Empty)
  210. {
  211. Regex drx = new Regex(m_DeniedClients);
  212. Match dm = drx.Match(curViewer);
  213. if (dm.Success)
  214. {
  215. m_log.InfoFormat("[GATEKEEPER SERVICE]: Login failed, reason: client {0} is denied", curViewer);
  216. return false;
  217. }
  218. }
  219. //
  220. // Authenticate the user
  221. //
  222. if (!Authenticate(aCircuit))
  223. {
  224. reason = "Unable to verify identity";
  225. m_log.InfoFormat("[GATEKEEPER SERVICE]: Unable to verify identity of agent {0} {1}. Refusing service.", aCircuit.firstname, aCircuit.lastname);
  226. return false;
  227. }
  228. m_log.DebugFormat("[GATEKEEPER SERVICE]: Identity verified for {0} {1} @ {2}", aCircuit.firstname, aCircuit.lastname, authURL);
  229. //
  230. // Check for impersonations
  231. //
  232. UserAccount account = null;
  233. if (m_UserAccountService != null)
  234. {
  235. // Check to see if we have a local user with that UUID
  236. account = m_UserAccountService.GetUserAccount(m_ScopeID, aCircuit.AgentID);
  237. if (account != null)
  238. {
  239. // Make sure this is the user coming home, and not a foreign user with same UUID as a local user
  240. if (m_UserAgentService != null)
  241. {
  242. if (!m_UserAgentService.IsAgentComingHome(aCircuit.SessionID, m_ExternalName))
  243. {
  244. // Can't do, sorry
  245. reason = "Unauthorized";
  246. m_log.InfoFormat("[GATEKEEPER SERVICE]: Foreign agent {0} {1} has same ID as local user. Refusing service.",
  247. aCircuit.firstname, aCircuit.lastname);
  248. return false;
  249. }
  250. }
  251. }
  252. }
  253. //
  254. // Foreign agents allowed? Exceptions?
  255. //
  256. if (account == null)
  257. {
  258. bool allowed = m_ForeignAgentsAllowed;
  259. if (m_ForeignAgentsAllowed && IsException(aCircuit, m_ForeignsAllowedExceptions))
  260. allowed = false;
  261. if (!m_ForeignAgentsAllowed && IsException(aCircuit, m_ForeignsDisallowedExceptions))
  262. allowed = true;
  263. if (!allowed)
  264. {
  265. reason = "Destination does not allow visitors from your world";
  266. m_log.InfoFormat("[GATEKEEPER SERVICE]: Foreign agents are not permitted {0} {1} @ {2}. Refusing service.",
  267. aCircuit.firstname, aCircuit.lastname, aCircuit.ServiceURLs["HomeURI"]);
  268. return false;
  269. }
  270. }
  271. //
  272. // Is the user banned?
  273. // This uses a Ban service that's more powerful than the configs
  274. //
  275. string uui = (account != null ? aCircuit.AgentID.ToString() : Util.ProduceUserUniversalIdentifier(aCircuit));
  276. if (m_BansService != null && m_BansService.IsBanned(uui, aCircuit.IPAddress, aCircuit.Id0, authURL))
  277. {
  278. reason = "You are banned from this world";
  279. m_log.InfoFormat("[GATEKEEPER SERVICE]: Login failed, reason: user {0} is banned", uui);
  280. return false;
  281. }
  282. m_log.DebugFormat("[GATEKEEPER SERVICE]: User {0} is ok", aCircuit.Name);
  283. bool isFirstLogin = false;
  284. //
  285. // Login the presence, if it's not there yet (by the login service)
  286. //
  287. PresenceInfo presence = m_PresenceService.GetAgent(aCircuit.SessionID);
  288. if (presence != null) // it has been placed there by the login service
  289. isFirstLogin = true;
  290. else
  291. {
  292. if (!m_PresenceService.LoginAgent(aCircuit.AgentID.ToString(), aCircuit.SessionID, aCircuit.SecureSessionID))
  293. {
  294. reason = "Unable to login presence";
  295. m_log.InfoFormat("[GATEKEEPER SERVICE]: Presence login failed for foreign agent {0} {1}. Refusing service.",
  296. aCircuit.firstname, aCircuit.lastname);
  297. return false;
  298. }
  299. m_log.DebugFormat("[GATEKEEPER SERVICE]: Login presence {0} is ok", aCircuit.Name);
  300. // Also login foreigners with GridUser service
  301. if (m_GridUserService != null && account == null)
  302. {
  303. string userId = aCircuit.AgentID.ToString();
  304. string first = aCircuit.firstname, last = aCircuit.lastname;
  305. if (last.StartsWith("@"))
  306. {
  307. string[] parts = aCircuit.firstname.Split('.');
  308. if (parts.Length >= 2)
  309. {
  310. first = parts[0];
  311. last = parts[1];
  312. }
  313. }
  314. userId += ";" + aCircuit.ServiceURLs["HomeURI"] + ";" + first + " " + last;
  315. m_GridUserService.LoggedIn(userId);
  316. }
  317. }
  318. //
  319. // Get the region
  320. //
  321. destination = m_GridService.GetRegionByUUID(m_ScopeID, destination.RegionID);
  322. if (destination == null)
  323. {
  324. reason = "Destination region not found";
  325. return false;
  326. }
  327. m_log.DebugFormat(
  328. "[GATEKEEPER SERVICE]: Destination {0} is ok for {1}", destination.RegionName, aCircuit.Name);
  329. //
  330. // Adjust the visible name
  331. //
  332. if (account != null)
  333. {
  334. aCircuit.firstname = account.FirstName;
  335. aCircuit.lastname = account.LastName;
  336. }
  337. if (account == null)
  338. {
  339. if (!aCircuit.lastname.StartsWith("@"))
  340. aCircuit.firstname = aCircuit.firstname + "." + aCircuit.lastname;
  341. try
  342. {
  343. Uri uri = new Uri(aCircuit.ServiceURLs["HomeURI"].ToString());
  344. aCircuit.lastname = "@" + uri.Host; // + ":" + uri.Port;
  345. }
  346. catch
  347. {
  348. m_log.WarnFormat("[GATEKEEPER SERVICE]: Malformed HomeURI (this should never happen): {0}", aCircuit.ServiceURLs["HomeURI"]);
  349. aCircuit.lastname = "@" + aCircuit.ServiceURLs["HomeURI"].ToString();
  350. }
  351. }
  352. //
  353. // Finally launch the agent at the destination
  354. //
  355. Constants.TeleportFlags loginFlag = isFirstLogin ? Constants.TeleportFlags.ViaLogin : Constants.TeleportFlags.ViaHGLogin;
  356. // Preserve our TeleportFlags we have gathered so-far
  357. loginFlag |= (Constants.TeleportFlags) aCircuit.teleportFlags;
  358. m_log.DebugFormat("[GATEKEEPER SERVICE]: Launching {0} {1}", aCircuit.Name, loginFlag);
  359. return m_SimulationService.CreateAgent(destination, aCircuit, (uint)loginFlag, out reason);
  360. }
  361. protected bool Authenticate(AgentCircuitData aCircuit)
  362. {
  363. if (!CheckAddress(aCircuit.ServiceSessionID))
  364. return false;
  365. if (string.IsNullOrEmpty(aCircuit.IPAddress))
  366. {
  367. m_log.DebugFormat("[GATEKEEPER SERVICE]: Agent did not provide a client IP address.");
  368. return false;
  369. }
  370. string userURL = string.Empty;
  371. if (aCircuit.ServiceURLs.ContainsKey("HomeURI"))
  372. userURL = aCircuit.ServiceURLs["HomeURI"].ToString();
  373. if (userURL == string.Empty)
  374. {
  375. m_log.DebugFormat("[GATEKEEPER SERVICE]: Agent did not provide an authentication server URL");
  376. return false;
  377. }
  378. if (userURL == m_ExternalName)
  379. {
  380. return m_UserAgentService.VerifyAgent(aCircuit.SessionID, aCircuit.ServiceSessionID);
  381. }
  382. else
  383. {
  384. IUserAgentService userAgentService = new UserAgentServiceConnector(userURL);
  385. try
  386. {
  387. return userAgentService.VerifyAgent(aCircuit.SessionID, aCircuit.ServiceSessionID);
  388. }
  389. catch
  390. {
  391. m_log.DebugFormat("[GATEKEEPER SERVICE]: Unable to contact authentication service at {0}", userURL);
  392. return false;
  393. }
  394. }
  395. }
  396. // Check that the service token was generated for *this* grid.
  397. // If it wasn't then that's a fake agent.
  398. protected bool CheckAddress(string serviceToken)
  399. {
  400. string[] parts = serviceToken.Split(new char[] { ';' });
  401. if (parts.Length < 2)
  402. return false;
  403. char[] trailing_slash = new char[] { '/' };
  404. string addressee = parts[0].TrimEnd(trailing_slash);
  405. string externalname = m_ExternalName.TrimEnd(trailing_slash);
  406. m_log.DebugFormat("[GATEKEEPER SERVICE]: Verifying {0} against {1}", addressee, externalname);
  407. Uri uri;
  408. try
  409. {
  410. uri = new Uri(addressee);
  411. }
  412. catch
  413. {
  414. m_log.DebugFormat("[GATEKEEPER SERVICE]: Visitor provided malformed service address {0}", addressee);
  415. return false;
  416. }
  417. return string.Equals(uri.GetLeftPart(UriPartial.Authority), m_Uri.GetLeftPart(UriPartial.Authority), StringComparison.OrdinalIgnoreCase) ;
  418. }
  419. #endregion
  420. #region Misc
  421. private bool IsException(AgentCircuitData aCircuit, List<string> exceptions)
  422. {
  423. bool exception = false;
  424. if (exceptions.Count > 0) // we have exceptions
  425. {
  426. // Retrieve the visitor's origin
  427. string userURL = aCircuit.ServiceURLs["HomeURI"].ToString();
  428. if (!userURL.EndsWith("/"))
  429. userURL += "/";
  430. if (exceptions.Find(delegate(string s)
  431. {
  432. if (!s.EndsWith("/"))
  433. s += "/";
  434. return s == userURL;
  435. }) != null)
  436. exception = true;
  437. }
  438. return exception;
  439. }
  440. #endregion
  441. }
  442. }