Permission.cs 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347
  1. /*
  2. Technitium DNS Server
  3. Copyright (C) 2024 Shreyas Zare (shreyas@technitium.com)
  4. This program is free software: you can redistribute it and/or modify
  5. it under the terms of the GNU General Public License as published by
  6. the Free Software Foundation, either version 3 of the License, or
  7. (at your option) any later version.
  8. This program is distributed in the hope that it will be useful,
  9. but WITHOUT ANY WARRANTY; without even the implied warranty of
  10. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  11. GNU General Public License for more details.
  12. You should have received a copy of the GNU General Public License
  13. along with this program. If not, see <http://www.gnu.org/licenses/>.
  14. */
  15. using System;
  16. using System.Collections.Concurrent;
  17. using System.Collections.Generic;
  18. using System.IO;
  19. using TechnitiumLibrary.IO;
  20. namespace DnsServerCore.Auth
  21. {
  22. enum PermissionSection : byte
  23. {
  24. Unknown = 0,
  25. Dashboard = 1,
  26. Zones = 2,
  27. Cache = 3,
  28. Allowed = 4,
  29. Blocked = 5,
  30. Apps = 6,
  31. DnsClient = 7,
  32. Settings = 8,
  33. DhcpServer = 9,
  34. Administration = 10,
  35. Logs = 11
  36. }
  37. [Flags]
  38. enum PermissionFlag : byte
  39. {
  40. None = 0,
  41. View = 1,
  42. Modify = 2,
  43. Delete = 4,
  44. ViewModify = 3,
  45. ViewModifyDelete = 7
  46. }
  47. class Permission : IComparable<Permission>
  48. {
  49. #region variables
  50. readonly PermissionSection _section;
  51. readonly string _subItemName;
  52. readonly ConcurrentDictionary<User, PermissionFlag> _userPermissions;
  53. readonly ConcurrentDictionary<Group, PermissionFlag> _groupPermissions;
  54. readonly ConcurrentDictionary<string, Permission> _subItemPermissions;
  55. #endregion
  56. #region constructor
  57. public Permission(PermissionSection section, string subItemName = null)
  58. {
  59. _section = section;
  60. _subItemName = subItemName;
  61. _userPermissions = new ConcurrentDictionary<User, PermissionFlag>(1, 1);
  62. _groupPermissions = new ConcurrentDictionary<Group, PermissionFlag>(1, 1);
  63. _subItemPermissions = new ConcurrentDictionary<string, Permission>(1, 1);
  64. }
  65. public Permission(BinaryReader bR, AuthManager authManager)
  66. {
  67. byte version = bR.ReadByte();
  68. switch (version)
  69. {
  70. case 1:
  71. case 2:
  72. _section = (PermissionSection)bR.ReadByte();
  73. {
  74. int count = bR.ReadByte();
  75. _userPermissions = new ConcurrentDictionary<User, PermissionFlag>(1, count);
  76. for (int i = 0; i < count; i++)
  77. {
  78. User user = authManager.GetUser(bR.ReadShortString());
  79. PermissionFlag flag = (PermissionFlag)bR.ReadByte();
  80. if (user is not null)
  81. _userPermissions.TryAdd(user, flag);
  82. }
  83. }
  84. {
  85. int count = bR.ReadByte();
  86. _groupPermissions = new ConcurrentDictionary<Group, PermissionFlag>(1, count);
  87. for (int i = 0; i < count; i++)
  88. {
  89. Group group = authManager.GetGroup(bR.ReadShortString());
  90. PermissionFlag flag = (PermissionFlag)bR.ReadByte();
  91. if (group is not null)
  92. _groupPermissions.TryAdd(group, flag);
  93. }
  94. }
  95. {
  96. int count;
  97. if (version >= 2)
  98. count = bR.ReadInt32();
  99. else
  100. count = bR.ReadByte();
  101. _subItemPermissions = new ConcurrentDictionary<string, Permission>(1, count);
  102. for (int i = 0; i < count; i++)
  103. {
  104. string subItemName = bR.ReadShortString();
  105. Permission subItemPermission = new Permission(bR, authManager);
  106. _subItemPermissions.TryAdd(subItemName.ToLowerInvariant(), subItemPermission);
  107. }
  108. }
  109. break;
  110. default:
  111. throw new InvalidDataException("Invalid data or version not supported.");
  112. }
  113. }
  114. #endregion
  115. #region public
  116. public void SetPermission(User user, PermissionFlag flags)
  117. {
  118. _userPermissions[user] = flags;
  119. }
  120. public void SyncPermissions(IReadOnlyDictionary<User, PermissionFlag> userPermissions)
  121. {
  122. //remove non-existent permissions
  123. foreach (KeyValuePair<User, PermissionFlag> userPermission in _userPermissions)
  124. {
  125. if (!userPermissions.ContainsKey(userPermission.Key))
  126. _userPermissions.TryRemove(userPermission.Key, out _);
  127. }
  128. //set new permissions
  129. foreach (KeyValuePair<User, PermissionFlag> userPermission in userPermissions)
  130. _userPermissions[userPermission.Key] = userPermission.Value;
  131. }
  132. public void SetSubItemPermission(string subItemName, User user, PermissionFlag flags)
  133. {
  134. Permission subItemPermission = _subItemPermissions.GetOrAdd(subItemName.ToLowerInvariant(), delegate (string key)
  135. {
  136. return new Permission(_section, key);
  137. });
  138. subItemPermission.SetPermission(user, flags);
  139. }
  140. public void SetPermission(Group group, PermissionFlag flags)
  141. {
  142. _groupPermissions[group] = flags;
  143. }
  144. public void SyncPermissions(IReadOnlyDictionary<Group, PermissionFlag> groupPermissions)
  145. {
  146. //remove non-existent permissions
  147. foreach (KeyValuePair<Group, PermissionFlag> groupPermission in _groupPermissions)
  148. {
  149. if (!groupPermissions.ContainsKey(groupPermission.Key))
  150. _groupPermissions.TryRemove(groupPermission.Key, out _);
  151. }
  152. //set new permissions
  153. foreach (KeyValuePair<Group, PermissionFlag> groupPermission in groupPermissions)
  154. _groupPermissions[groupPermission.Key] = groupPermission.Value;
  155. }
  156. public void SetSubItemPermission(string subItemName, Group group, PermissionFlag flags)
  157. {
  158. Permission subItemPermission = _subItemPermissions.GetOrAdd(subItemName.ToLowerInvariant(), delegate (string key)
  159. {
  160. return new Permission(_section, key);
  161. });
  162. subItemPermission.SetPermission(group, flags);
  163. }
  164. public bool RemovePermission(User user)
  165. {
  166. return _userPermissions.TryRemove(user, out _);
  167. }
  168. public bool RemoveSubItemPermission(string subItemName, User user)
  169. {
  170. return _subItemPermissions.TryGetValue(subItemName.ToLowerInvariant(), out Permission subItemPermission) && subItemPermission.RemovePermission(user);
  171. }
  172. public bool RemovePermission(Group group)
  173. {
  174. return _groupPermissions.TryRemove(group, out _);
  175. }
  176. public bool RemoveSubItemPermission(string subItemName, Group group)
  177. {
  178. return _subItemPermissions.TryGetValue(subItemName.ToLowerInvariant(), out Permission subItemPermission) && subItemPermission.RemovePermission(group);
  179. }
  180. public bool RemoveAllSubItemPermissions(User user)
  181. {
  182. bool removed = false;
  183. foreach (KeyValuePair<string, Permission> subItemPermission in _subItemPermissions)
  184. {
  185. if (subItemPermission.Value.RemovePermission(user))
  186. removed = true;
  187. }
  188. return removed;
  189. }
  190. public bool RemoveAllSubItemPermissions(Group group)
  191. {
  192. bool removed = false;
  193. foreach (KeyValuePair<string, Permission> subItemPermission in _subItemPermissions)
  194. {
  195. if (subItemPermission.Value.RemovePermission(group))
  196. removed = true;
  197. }
  198. return removed;
  199. }
  200. public bool RemoveAllSubItemPermissions(string subItemName)
  201. {
  202. return _subItemPermissions.TryRemove(subItemName, out _);
  203. }
  204. public Permission GetSubItemPermission(string subItemName)
  205. {
  206. if (_subItemPermissions.TryGetValue(subItemName.ToLowerInvariant(), out Permission subItemPermission))
  207. return subItemPermission;
  208. return null;
  209. }
  210. public bool IsPermitted(User user, PermissionFlag flag)
  211. {
  212. if (_userPermissions.TryGetValue(user, out PermissionFlag userPermissions) && userPermissions.HasFlag(flag))
  213. return true;
  214. foreach (Group group in user.MemberOfGroups)
  215. {
  216. if (_groupPermissions.TryGetValue(group, out PermissionFlag groupPermissions) && groupPermissions.HasFlag(flag))
  217. return true;
  218. }
  219. return false;
  220. }
  221. public bool IsSubItemPermitted(string subItemName, User user, PermissionFlag flag)
  222. {
  223. return _subItemPermissions.TryGetValue(subItemName.ToLowerInvariant(), out Permission subItemPermission) && subItemPermission.IsPermitted(user, flag);
  224. }
  225. public void WriteTo(BinaryWriter bW)
  226. {
  227. bW.Write((byte)2);
  228. bW.Write((byte)_section);
  229. {
  230. bW.Write(Convert.ToByte(_userPermissions.Count));
  231. foreach (KeyValuePair<User, PermissionFlag> userPermission in _userPermissions)
  232. {
  233. bW.WriteShortString(userPermission.Key.Username);
  234. bW.Write((byte)userPermission.Value);
  235. }
  236. }
  237. {
  238. bW.Write(Convert.ToByte(_groupPermissions.Count));
  239. foreach (KeyValuePair<Group, PermissionFlag> groupPermission in _groupPermissions)
  240. {
  241. bW.WriteShortString(groupPermission.Key.Name);
  242. bW.Write((byte)groupPermission.Value);
  243. }
  244. }
  245. {
  246. bW.Write(_subItemPermissions.Count);
  247. foreach (KeyValuePair<string, Permission> subItemPermission in _subItemPermissions)
  248. {
  249. bW.WriteShortString(subItemPermission.Key);
  250. subItemPermission.Value.WriteTo(bW);
  251. }
  252. }
  253. }
  254. public int CompareTo(Permission other)
  255. {
  256. return _section.CompareTo(other._section);
  257. }
  258. #endregion
  259. #region properties
  260. public PermissionSection Section
  261. { get { return _section; } }
  262. public string SubItemName
  263. { get { return _subItemName; } }
  264. public IReadOnlyDictionary<User, PermissionFlag> UserPermissions
  265. { get { return _userPermissions; } }
  266. public IReadOnlyDictionary<Group, PermissionFlag> GroupPermissions
  267. { get { return _groupPermissions; } }
  268. public IReadOnlyDictionary<string, Permission> SubItemPermissions
  269. { get { return _subItemPermissions; } }
  270. #endregion
  271. }
  272. }