g1mp/plugins/services/permissions.py

178 lines
6.1 KiB
Python
Raw Normal View History

2025-02-14 19:02:13 +00:00
# permissions.py
# -*- coding: utf-8 -*-
2025-02-14 23:15:37 +00:00
"""A plugin for irc3 that provides a permission system using TinyDB."""
2025-02-14 19:02:13 +00:00
2025-02-14 21:48:23 +00:00
import irc3
2025-02-14 19:02:13 +00:00
from irc3.plugins.command import command
2025-02-14 23:15:37 +00:00
from tinydb import Query, TinyDB
2025-02-14 19:02:13 +00:00
import fnmatch
2025-02-14 21:48:23 +00:00
from ircstyle import style
2025-02-14 19:02:13 +00:00
2025-02-14 21:48:23 +00:00
@irc3.plugin
2025-02-14 19:02:13 +00:00
class TinyDBPermissions:
2025-02-14 23:15:37 +00:00
"""Main permission system plugin handling storage and commands."""
2025-02-14 19:02:13 +00:00
def __init__(self, bot):
self.bot = bot
self.permission_db = TinyDB('permissions.json')
self.bot.permission_db = self.permission_db
2025-02-14 21:48:23 +00:00
self.User = Query()
2025-02-14 19:02:13 +00:00
self.bot.log.info("TinyDB permissions plugin initialized")
2025-02-14 21:48:23 +00:00
@command(permission='admin')
def perm(self, mask, target, args):
2025-02-14 23:15:37 +00:00
"""Manage permissions through command interface.
2025-02-14 21:48:23 +00:00
Usage:
%%perm --add <mask> <permission>
%%perm --del <mask> <permission>
%%perm --list [<mask>]
"""
if args['--add']:
self._add_permission(target, args['<mask>'], args['<permission>'])
elif args['--del']:
self._del_permission(target, args['<mask>'], args['<permission>'])
elif args['--list']:
self._list_permissions(target, args['<mask>'])
else:
error_msg = style(
"Invalid syntax. Use --add, --del, or --list.",
fg='red', bold=True
)
self.bot.privmsg(target, error_msg)
2025-02-14 23:15:37 +00:00
@command(permission='admin')
def ignore(self, mask, target, args):
"""Manage user ignore list.
Usage:
%%ignore --add <nick>
%%ignore --del <nick>
"""
nick = args['<nick>']
user_mask = f"{nick}!*@*"
if args['--add']:
if self.permission_db.contains(
(self.User.mask == user_mask) &
(self.User.permission == 'ignore')
):
msg = style(f"{nick} already ignored", fg='yellow', bold=True)
else:
self.permission_db.insert({'mask': user_mask, 'permission': 'ignore'})
msg = style(f"Ignored {nick}", fg='green', bold=True)
elif args['--del']:
removed = self.permission_db.remove(
(self.User.mask == user_mask) &
(self.User.permission == 'ignore')
)
msg = style(f"Unignored {nick} ({len(removed)} entries)", fg='green', bold=True)
else:
msg = style("Invalid syntax", fg='red', bold=True)
self.bot.privmsg(target, msg)
2025-02-14 21:48:23 +00:00
def _add_permission(self, target, user_mask, perm):
2025-02-14 23:15:37 +00:00
"""Add a permission to the database."""
2025-02-14 21:48:23 +00:00
existing = self.permission_db.search(
(self.User.mask == user_mask) &
(self.User.permission == perm)
)
if existing:
msg = style(
f"Permission '{perm}' already exists for {user_mask}",
fg='yellow', bold=True
)
else:
self.permission_db.insert({'mask': user_mask, 'permission': perm})
msg = style(
f"Added permission '{perm}' for {user_mask}",
fg='green', bold=True
)
self.bot.privmsg(target, msg)
def _del_permission(self, target, user_mask, perm):
2025-02-14 23:15:37 +00:00
"""Remove a permission from the database."""
2025-02-14 21:48:23 +00:00
removed = self.permission_db.remove(
(self.User.mask == user_mask) &
(self.User.permission == perm)
)
if removed:
msg = style(
f"Removed {len(removed)} '{perm}' permission(s) for {user_mask}",
fg='green', bold=True
)
else:
msg = style(
f"No '{perm}' permissions found for {user_mask}",
fg='red', bold=True
)
self.bot.privmsg(target, msg)
def _list_permissions(self, target, mask_filter):
2025-02-14 23:15:37 +00:00
"""List permissions matching a filter pattern."""
2025-02-14 21:48:23 +00:00
mask_filter = mask_filter or '*'
regex = fnmatch.translate(mask_filter).split('(?ms)')[0].rstrip('\\Z')
2025-02-14 23:15:37 +00:00
entries = self.permission_db.search(
self.User.mask.matches(regex)
)
2025-02-14 21:48:23 +00:00
if not entries:
msg = style("No permissions found", fg='red', bold=True)
self.bot.privmsg(target, msg)
return
for entry in entries:
msg = style(
f"{entry['mask']}: {entry['permission']}",
fg='blue', bold=True
)
self.bot.privmsg(target, msg)
class TinyDBPolicy:
2025-02-14 23:15:37 +00:00
"""Authorization system for command access control."""
2025-02-14 21:48:23 +00:00
def __init__(self, bot):
2025-02-14 19:02:13 +00:00
self.bot = bot
2025-02-14 21:48:23 +00:00
self.User = Query()
2025-02-14 19:02:13 +00:00
def has_permission(self, client_mask, permission):
2025-02-14 23:15:37 +00:00
"""Check if a client has required permissions."""
# Check ignore list first
ignored = self.bot.permission_db.search(
2025-02-14 21:48:23 +00:00
self.User.permission == 'ignore'
)
2025-02-14 23:15:37 +00:00
for entry in ignored:
2025-02-14 21:48:23 +00:00
if fnmatch.fnmatch(client_mask, entry['mask']):
return False
2025-02-14 19:02:13 +00:00
2025-02-14 21:48:23 +00:00
# Check permissions if not ignored
2025-02-14 19:02:13 +00:00
if permission is None:
return True
2025-02-14 23:15:37 +00:00
# Check for matching permissions using fnmatch
entries = self.bot.permission_db.search(
self.User.permission.test(lambda p: p in (permission, 'all_permissions'))
2025-02-14 21:48:23 +00:00
)
2025-02-14 23:15:37 +00:00
for entry in entries:
2025-02-14 19:02:13 +00:00
if fnmatch.fnmatch(client_mask, entry['mask']):
return True
2025-02-14 23:15:37 +00:00
2025-02-14 19:02:13 +00:00
return False
2025-02-14 21:48:23 +00:00
def __call__(self, predicates, meth, client, target, args):
2025-02-14 23:15:37 +00:00
"""Enforce command permissions."""
2025-02-14 19:02:13 +00:00
cmd_name = predicates.get('name', meth.__name__)
2025-02-14 21:48:23 +00:00
client_hostmask = str(client)
if self.has_permission(client_hostmask, predicates.get('permission')):
2025-02-14 19:02:13 +00:00
return meth(client, target, args)
2025-02-14 21:48:23 +00:00
error_msg = style(
f"Access denied for '{cmd_name}' command",
2025-02-14 19:02:13 +00:00
fg='red', bold=True
)
2025-02-14 21:48:23 +00:00
self.bot.privmsg(client.nick, error_msg)