paul@6 | 1 | # -*- coding: iso-8859-1 -*- |
paul@6 | 2 | """ |
paul@6 | 3 | MoinMoin - MoinMessage library |
paul@6 | 4 | |
paul@6 | 5 | @copyright: 2012 by Paul Boddie <paul@boddie.org.uk> |
paul@6 | 6 | @license: GNU GPL (v2 or later), see COPYING.txt for details. |
paul@6 | 7 | """ |
paul@6 | 8 | |
paul@6 | 9 | from email import message_from_string |
paul@6 | 10 | from email.encoders import encode_noop |
paul@6 | 11 | from email.mime.multipart import MIMEMultipart |
paul@6 | 12 | from email.mime.application import MIMEApplication |
paul@6 | 13 | from email.mime.base import MIMEBase |
paul@6 | 14 | from subprocess import Popen, PIPE |
paul@8 | 15 | from tempfile import mkstemp |
paul@12 | 16 | from urlparse import urlsplit |
paul@6 | 17 | import httplib |
paul@8 | 18 | import os |
paul@6 | 19 | |
paul@6 | 20 | class Message: |
paul@6 | 21 | |
paul@6 | 22 | "An update message." |
paul@6 | 23 | |
paul@6 | 24 | def __init__(self): |
paul@6 | 25 | self.updates = [] |
paul@6 | 26 | |
paul@6 | 27 | def add_update(self, alternatives): |
paul@13 | 28 | |
paul@13 | 29 | """ |
paul@13 | 30 | Add an update fragment to a message, providing alternative forms of the |
paul@13 | 31 | update content in the given 'alternatives': a list of MIME message |
paul@13 | 32 | parts, each encoding the content according to different MIME types. |
paul@13 | 33 | """ |
paul@13 | 34 | |
paul@6 | 35 | if len(alternatives) > 1: |
paul@6 | 36 | part = MIMEMultipart() |
paul@6 | 37 | for alternative in alternatives: |
paul@6 | 38 | part.attach(alternative) |
paul@6 | 39 | self.updates.append(part) |
paul@6 | 40 | else: |
paul@6 | 41 | self.updates.append(alternatives[0]) |
paul@6 | 42 | |
paul@6 | 43 | def get_payload(self): |
paul@13 | 44 | |
paul@13 | 45 | "Get the multipart payload for the message." |
paul@13 | 46 | |
paul@6 | 47 | if len(self.updates) == 1: |
paul@6 | 48 | message = self.updates[0] |
paul@6 | 49 | else: |
paul@6 | 50 | message = MIMEMultipart() |
paul@6 | 51 | message.add_header("Update-Type", "collection") |
paul@6 | 52 | for update in self.updates: |
paul@6 | 53 | message.attach(update) |
paul@6 | 54 | |
paul@6 | 55 | return message |
paul@6 | 56 | |
paul@6 | 57 | class MoinMessageError(Exception): |
paul@6 | 58 | pass |
paul@6 | 59 | |
paul@8 | 60 | class GPG: |
paul@8 | 61 | |
paul@8 | 62 | "A wrapper around the gpg command using a particular configuration." |
paul@6 | 63 | |
paul@8 | 64 | def __init__(self, homedir=None): |
paul@8 | 65 | self.conf_args = [] |
paul@6 | 66 | |
paul@8 | 67 | if homedir: |
paul@8 | 68 | self.conf_args += ["--homedir", homedir] |
paul@8 | 69 | |
paul@8 | 70 | self.errors = None |
paul@6 | 71 | |
paul@8 | 72 | def run(self, args, text=None): |
paul@6 | 73 | |
paul@8 | 74 | """ |
paul@8 | 75 | Invoke gpg with the given 'args', supplying the given 'text' to the |
paul@8 | 76 | command directly or, if 'text' is omitted, using a file provided as part |
paul@8 | 77 | of the 'args' if appropriate. |
paul@6 | 78 | |
paul@8 | 79 | Failure to complete the operation will result in a MoinMessageError |
paul@8 | 80 | being raised. |
paul@8 | 81 | """ |
paul@8 | 82 | |
paul@8 | 83 | cmd = Popen(["gpg"] + self.conf_args + list(args), stdin=PIPE, stdout=PIPE, stderr=PIPE) |
paul@6 | 84 | |
paul@11 | 85 | try: |
paul@11 | 86 | # Attempt to write input to the command and to read output from the |
paul@11 | 87 | # command. |
paul@11 | 88 | |
paul@11 | 89 | try: |
paul@11 | 90 | if text: |
paul@11 | 91 | cmd.stdin.write(text) |
paul@11 | 92 | cmd.stdin.close() |
paul@6 | 93 | |
paul@11 | 94 | text = cmd.stdout.read() |
paul@11 | 95 | |
paul@11 | 96 | # I/O errors can indicate the failure of the command. |
paul@8 | 97 | |
paul@11 | 98 | except IOError: |
paul@11 | 99 | pass |
paul@11 | 100 | |
paul@11 | 101 | self.errors = cmd.stderr.read() |
paul@8 | 102 | |
paul@8 | 103 | # Test for a zero result. |
paul@6 | 104 | |
paul@8 | 105 | if not cmd.wait(): |
paul@8 | 106 | return text |
paul@8 | 107 | else: |
paul@10 | 108 | raise MoinMessageError, self.errors |
paul@8 | 109 | |
paul@8 | 110 | finally: |
paul@8 | 111 | cmd.stdout.close() |
paul@8 | 112 | cmd.stderr.close() |
paul@6 | 113 | |
paul@8 | 114 | def verifyMessage(self, signature, content): |
paul@8 | 115 | |
paul@8 | 116 | "Using the given 'signature', verify the given message 'content'." |
paul@6 | 117 | |
paul@8 | 118 | # Write the detached signature and content to files. |
paul@8 | 119 | |
paul@8 | 120 | signature_fd, signature_filename = mkstemp() |
paul@8 | 121 | content_fd, content_filename = mkstemp() |
paul@6 | 122 | |
paul@8 | 123 | try: |
paul@8 | 124 | signature_fp = os.fdopen(signature_fd, "w") |
paul@8 | 125 | content_fp = os.fdopen(content_fd, "w") |
paul@8 | 126 | try: |
paul@8 | 127 | signature_fp.write(signature) |
paul@8 | 128 | content_fp.write(content) |
paul@8 | 129 | finally: |
paul@8 | 130 | signature_fp.close() |
paul@8 | 131 | content_fp.close() |
paul@6 | 132 | |
paul@8 | 133 | # Verify the message text. |
paul@6 | 134 | |
paul@10 | 135 | text = self.run(["--status-fd", "1", "--verify", signature_filename, content_filename]) |
paul@10 | 136 | |
paul@10 | 137 | # Return the details of the signing key. |
paul@10 | 138 | |
paul@11 | 139 | identity = None |
paul@11 | 140 | fingerprint = None |
paul@11 | 141 | |
paul@10 | 142 | for line in text.split("\n"): |
paul@10 | 143 | try: |
paul@11 | 144 | prefix, msgtype, digest, details = line.strip().split(" ", 3) |
paul@10 | 145 | except ValueError: |
paul@10 | 146 | continue |
paul@10 | 147 | |
paul@10 | 148 | # Return the fingerprint and identity details. |
paul@10 | 149 | |
paul@10 | 150 | if msgtype == "GOODSIG": |
paul@11 | 151 | identity = details |
paul@11 | 152 | elif msgtype == "VALIDSIG": |
paul@11 | 153 | fingerprint = digest |
paul@11 | 154 | |
paul@11 | 155 | if identity and fingerprint: |
paul@11 | 156 | return fingerprint, identity |
paul@10 | 157 | |
paul@10 | 158 | return None |
paul@6 | 159 | |
paul@8 | 160 | finally: |
paul@8 | 161 | os.remove(signature_filename) |
paul@8 | 162 | os.remove(content_filename) |
paul@8 | 163 | |
paul@8 | 164 | def signMessage(self, message, keyid): |
paul@6 | 165 | |
paul@8 | 166 | """ |
paul@8 | 167 | Return a signed version of 'message' using the given 'keyid'. |
paul@8 | 168 | """ |
paul@6 | 169 | |
paul@8 | 170 | text = message.as_string() |
paul@8 | 171 | signature = self.run(["--armor", "-u", keyid, "--detach-sig"], text) |
paul@8 | 172 | |
paul@8 | 173 | # Make the container for the message. |
paul@8 | 174 | |
paul@8 | 175 | signed_message = MIMEMultipart("signed", protocol="application/pgp-signature") |
paul@8 | 176 | signed_message.attach(message) |
paul@6 | 177 | |
paul@8 | 178 | signature_part = MIMEBase("application", "pgp-signature") |
paul@8 | 179 | signature_part.set_payload(signature) |
paul@8 | 180 | signed_message.attach(signature_part) |
paul@8 | 181 | |
paul@8 | 182 | return signed_message |
paul@8 | 183 | |
paul@8 | 184 | def decryptMessage(self, message): |
paul@6 | 185 | |
paul@8 | 186 | "Return a decrypted version of 'message'." |
paul@8 | 187 | |
paul@8 | 188 | return self.run(["--decrypt"], message) |
paul@6 | 189 | |
paul@8 | 190 | def encryptMessage(self, message, keyid): |
paul@6 | 191 | |
paul@8 | 192 | """ |
paul@8 | 193 | Return an encrypted version of 'message' using the given 'keyid'. |
paul@8 | 194 | """ |
paul@6 | 195 | |
paul@8 | 196 | text = message.as_string() |
paul@8 | 197 | encrypted = self.run(["--armor", "-r", keyid, "--encrypt", "--trust-model", "always"], text) |
paul@8 | 198 | |
paul@8 | 199 | # Make the container for the message. |
paul@8 | 200 | |
paul@8 | 201 | encrypted_message = MIMEMultipart("encrypted", protocol="application/pgp-encrypted") |
paul@8 | 202 | |
paul@8 | 203 | # For encrypted content, add the declaration and content. |
paul@6 | 204 | |
paul@8 | 205 | declaration = MIMEBase("application", "pgp-encrypted") |
paul@8 | 206 | declaration.set_payload("Version: 1") |
paul@8 | 207 | encrypted_message.attach(declaration) |
paul@6 | 208 | |
paul@8 | 209 | content = MIMEApplication(encrypted, "octet-stream", encode_noop) |
paul@8 | 210 | encrypted_message.attach(content) |
paul@6 | 211 | |
paul@8 | 212 | return encrypted_message |
paul@8 | 213 | |
paul@8 | 214 | # Communications functions. |
paul@6 | 215 | |
paul@12 | 216 | def sendMessage(message, url): |
paul@6 | 217 | |
paul@12 | 218 | "Send 'message' to the given 'url." |
paul@6 | 219 | |
paul@12 | 220 | scheme, host, port, path = parseURL(url) |
paul@6 | 221 | text = message.as_string() |
paul@6 | 222 | |
paul@12 | 223 | if scheme == "http": |
paul@12 | 224 | cls = httplib.HTTPConnection |
paul@12 | 225 | elif scheme == "https": |
paul@12 | 226 | cls = httplib.HTTPSConnection |
paul@12 | 227 | else: |
paul@12 | 228 | raise MoinMessageError, "Communications protocol not supported: %s" % scheme |
paul@12 | 229 | |
paul@12 | 230 | req = cls(host, port) |
paul@12 | 231 | req.request("PUT", path, text) |
paul@6 | 232 | resp = req.getresponse() |
paul@6 | 233 | return resp.read() |
paul@6 | 234 | |
paul@12 | 235 | def parseURL(url): |
paul@12 | 236 | |
paul@12 | 237 | "Return the scheme, host, port and path for the given 'url'." |
paul@12 | 238 | |
paul@12 | 239 | scheme, host_port, path, query, fragment = urlsplit(url) |
paul@12 | 240 | host_port = host_port.split(":") |
paul@12 | 241 | |
paul@12 | 242 | if query: |
paul@12 | 243 | path += "?" + query |
paul@12 | 244 | |
paul@12 | 245 | if len(host_port) > 1: |
paul@12 | 246 | host = host_port[0] |
paul@12 | 247 | port = int(host_port[1]) |
paul@12 | 248 | else: |
paul@12 | 249 | host = host_port[0] |
paul@12 | 250 | port = 80 |
paul@12 | 251 | |
paul@12 | 252 | return scheme, host, port, path |
paul@12 | 253 | |
paul@6 | 254 | # vim: tabstop=4 expandtab shiftwidth=4 |