MUC: Prevent admins from being given affiliatons other than owner
[prosody.git] / plugins / muc / mod_muc.lua
index 94d8263c18598c4f3a8efc8c1dc9fea557b268d0..acc2da0d7c040beb1c66ec3b7aa2c11ba3aa4c3e 100644 (file)
@@ -22,26 +22,39 @@ if restrict_room_creation then
                restrict_room_creation = nil;
        end
 end
-local muc_new_room = module:require "muc".new_room;
+local muclib = module:require "muc";
+local muc_new_room = muclib.new_room;
 local jid_split = require "util.jid".split;
 local jid_bare = require "util.jid".bare;
 local st = require "util.stanza";
 local uuid_gen = require "util.uuid".generate;
-local datamanager = require "util.datamanager";
 local um_is_admin = require "core.usermanager".is_admin;
-local hosts = hosts;
+local hosts = prosody.hosts;
 
 rooms = {};
 local rooms = rooms;
-local persistent_rooms = datamanager.load(nil, muc_host, "persistent") or {};
+local persistent_rooms_storage = module:open_store("persistent");
+local persistent_rooms = persistent_rooms_storage:get() or {};
+local room_configs = module:open_store("config");
 
 -- Configurable options
-local max_history_messages = module:get_option_number("max_history_messages");
+muclib.set_max_history_length(module:get_option_number("max_history_messages"));
 
 local function is_admin(jid)
        return um_is_admin(jid, module.host);
 end
 
+local _set_affiliation = muc_new_room.room_mt.set_affiliation;
+local _get_affiliation = muc_new_room.room_mt.get_affiliation;
+function muclib.room_mt:get_affiliation(jid)
+       if is_admin(jid) then return "owner"; end
+       return _get_affiliation(self, jid);
+end
+function muclib.room_mt:set_affiliation(actor, jid, affiliation, callback, reason)
+       if affiliation ~= "owner" and is_admin(jid) then return nil, "modify", "not-acceptable"; end
+       return _set_affiliation(self, actor, jid, affiliation, callback, reason);
+end
+
 local function room_route_stanza(room, stanza) module:send(stanza); end
 local function room_save(room, forced)
        local node = jid_split(room.jid);
@@ -54,42 +67,43 @@ local function room_save(room, forced)
                        _data = room._data;
                        _affiliations = room._affiliations;
                };
-               datamanager.store(node, muc_host, "config", data);
+               room_configs:set(node, data);
                room._data.history = history;
        elseif forced then
-               datamanager.store(node, muc_host, "config", nil);
+               room_configs:set(node, nil);
                if not next(room._occupants) then -- Room empty
                        rooms[room.jid] = nil;
                end
        end
-       if forced then datamanager.store(nil, muc_host, "persistent", persistent_rooms); end
+       if forced then persistent_rooms_storage:set(nil, persistent_rooms); end
+end
+
+function create_room(jid)
+       local room = muc_new_room(jid);
+       room.route_stanza = room_route_stanza;
+       room.save = room_save;
+       rooms[jid] = room;
+       module:fire_event("muc-room-created", { room = room });
+       return room;
 end
 
 local persistent_errors = false;
 for jid in pairs(persistent_rooms) do
        local node = jid_split(jid);
-       local data = datamanager.load(node, muc_host, "config");
+       local data = room_configs:get(node);
        if data then
-               local room = muc_new_room(jid, {
-                       max_history_length = max_history_messages;
-               });
+               local room = create_room(jid);
                room._data = data._data;
-               room._data.max_history_length = max_history_messages; -- Overwrite old max_history_length in data with current settings
                room._affiliations = data._affiliations;
-               room.route_stanza = room_route_stanza;
-               room.save = room_save;
-               rooms[jid] = room;
        else -- missing room data
                persistent_rooms[jid] = nil;
                module:log("error", "Missing data for room '%s', removing from persistent room list", jid);
                persistent_errors = true;
        end
 end
-if persistent_errors then datamanager.store(nil, muc_host, "persistent", persistent_rooms); end
+if persistent_errors then persistent_rooms_storage:set(nil, persistent_rooms); end
 
-local host_room = muc_new_room(muc_host, {
-       max_history_length = max_history_messages;
-});
+local host_room = muc_new_room(muc_host);
 host_room.route_stanza = room_route_stanza;
 host_room.save = room_save;
 
@@ -114,9 +128,10 @@ local function handle_to_domain(event)
        if type == "error" or type == "result" then return; end
        if stanza.name == "iq" and type == "get" then
                local xmlns = stanza.tags[1].attr.xmlns;
-               if xmlns == "http://jabber.org/protocol/disco#info" then
+               local node = stanza.tags[1].attr.node;
+               if xmlns == "http://jabber.org/protocol/disco#info" and not node then
                        origin.send(get_disco_info(stanza));
-               elseif xmlns == "http://jabber.org/protocol/disco#items" then
+               elseif xmlns == "http://jabber.org/protocol/disco#items" and not node then
                        origin.send(get_disco_items(stanza));
                elseif xmlns == "http://jabber.org/protocol/muc#unique" then
                        origin.send(st.reply(stanza):tag("unique", {xmlns = xmlns}):text(uuid_gen())); -- FIXME Random UUIDs can theoretically have collisions
@@ -140,19 +155,15 @@ function stanza_handler(event)
                        return true;
                end
                if not(restrict_room_creation) or
-                 (restrict_room_creation == "admin" and is_admin(stanza.attr.from)) or
+                 is_admin(stanza.attr.from) or
                  (restrict_room_creation == "local" and select(2, jid_split(stanza.attr.from)) == module.host:gsub("^[^%.]+%.", "")) then
-                       room = muc_new_room(bare, {
-                               max_history_length = max_history_messages;
-                       });
-                       room.route_stanza = room_route_stanza;
-                       room.save = room_save;
-                       rooms[bare] = room;
+                       room = create_room(bare);
                end
        end
        if room then
                room:handle_stanza(origin, stanza);
                if not next(room._occupants) and not persistent_rooms[room.jid] then -- empty, non-persistent room
+                       module:fire_event("muc-room-destroyed", { room = room });
                        rooms[bare] = nil; -- discard room
                end
        else
@@ -185,14 +196,11 @@ module.save = function()
 end
 module.restore = function(data)
        for jid, oldroom in pairs(data.rooms or {}) do
-               local room = muc_new_room(jid);
+               local room = create_room(jid);
                room._jid_nick = oldroom._jid_nick;
                room._occupants = oldroom._occupants;
                room._data = oldroom._data;
                room._affiliations = oldroom._affiliations;
-               room.route_stanza = room_route_stanza;
-               room.save = room_save;
-               rooms[jid] = room;
        end
        hosts[module:get_host()].muc = { rooms = rooms };
 end