30
32
from ivle import util
32
def url_to_local(config, urlpath):
34
# Make a Subversion client object (for published)
35
svnclient = pysvn.Client()
37
def url_to_local(urlpath):
33
38
"""Given a URL path (part of a URL query string, see below), returns a
35
40
* the username of the student whose directory is being browsed
47
52
Returns (None, None) if the path is empty.
49
>>> stubconfig = {'paths': {'jails': {'mounts': '/jails'}}}
51
>>> url_to_local(stubconfig, 'joe/foo/bar/baz')
52
('joe', '/jails/joe/home/joe/foo/bar/baz')
53
>>> url_to_local(stubconfig, 'joe')
54
('joe', '/jails/joe/home/joe')
55
>>> url_to_local(stubconfig, 'joe/')
56
('joe', '/jails/joe/home/joe')
58
We have some protection from various potential attacks. An empty,
59
absolute, or ..-prefixed path yields a special result.
61
>>> url_to_local(stubconfig, '')
63
>>> url_to_local(stubconfig, '/foo')
65
>>> url_to_local(stubconfig, '../bar')
54
See also: ivle.conf.jail_base
69
56
# First normalise the path
70
57
urlpath = os.path.normpath(urlpath)
71
58
# Now if it begins with ".." or separator, then it's illegal
81
68
# accordance with our directory scheme.
82
69
# (The first time is the name of the jail, the second is the user's home
83
70
# directory within the jail).
84
path = os.path.join(config['paths']['jails']['mounts'],
85
user, 'home', urlpath)
71
path = os.path.join(ivle.conf.jail_base, user, 'home', urlpath)
87
73
return (user, path)
89
def url_to_jailpaths(config, urlpath):
75
def url_to_jailpaths(urlpath):
90
76
"""Given a URL path (part of a URL query string), returns a tuple of
91
77
* the username of the student whose directory is being browsed
92
78
* the absolute path where the jail will be located.
95
81
urlpath: See urlpath in url_to_local.
97
>>> stubconfig = {'paths': {'jails': {'mounts': '/jails'}}}
83
>>> url_to_jailpaths("joe/mydir/myfile")
84
('joe', '/var/lib/ivle/jailmounts/joe', '/home/joe/mydir/myfile')
99
>>> url_to_jailpaths(stubconfig, "joe/mydir//myfile/.././myfile")
100
('joe', '/jails/joe', '/home/joe/mydir/myfile')
101
>>> url_to_jailpaths(stubconfig, "")
103
>>> url_to_jailpaths(stubconfig, "../foo")
105
>>> url_to_jailpaths(stubconfig, "/foo")
86
>>> url_to_jailpaths("")
106
87
(None, None, None)
108
89
# First normalise the path
109
90
urlpath = os.path.normpath(urlpath)
110
# Now if it begins with "..", or is absolute, then it's illegal
111
if urlpath.startswith("..") or os.path.isabs(urlpath):
91
# Now if it begins with ".." then it's illegal
92
if urlpath.startswith(".."):
112
93
return (None, None, None)
113
94
# Note: User can be a group name. There is absolutely no difference in our
114
95
# current directory scheme.
115
96
(user, subpath) = util.split_path(urlpath)
116
97
if user is None: return (None, None, None)
118
jail = os.path.join(config['paths']['jails']['mounts'], user)
119
path = to_home_path(urlpath)
99
jail = os.path.join(ivle.conf.jail_base, user)
100
path = os.path.join('/home', urlpath)
121
102
return (user, jail, path)
123
def to_home_path(urlpath):
124
"""Given a URL path (eg. joe/foo/bar/baz), returns a path within the home.
126
>>> to_home_path('joe/foo/bar/baz')
127
'/home/joe/foo/bar/baz'
128
>>> to_home_path('joe/foo//bar/baz/../../')
130
>>> to_home_path('joe/foo//bar/baz/../../../../../') is None
134
urlpath = os.path.normpath(urlpath)
135
# If it begins with '..', it's illegal.
136
if urlpath.startswith(".."):
139
return os.path.join('/home', urlpath)
104
def svnpublished(path):
105
"""Given a path on the LOCAL file system, determines whether the path has
106
its "ivle:published" property active (in subversion). Returns True
108
# Read SVN properties for this path
110
props = svnclient.propget("ivle:published", path, recurse=False)
111
except pysvn.ClientError:
112
# Not under version control? Then it isn't published.
114
return len(props) > 0
141
116
def published(path):
142
117
"""Given a path on the LOCAL file system, determines whether the path has a
170
145
urlpath = os.path.normpath(req.path)
171
146
# Now if it begins with ".." or separator, then it's illegal
172
147
if urlpath.startswith("..") or urlpath.startswith(os.sep):
148
req.throw_error(req.HTTP_FORBIDDEN)
175
150
(owner, _) = util.split_path(urlpath)
176
if user.login != owner:
151
if req.user.login != owner:
152
req.throw_error(req.HTTP_FORBIDDEN)
180
154
def authorize_public(req):
181
155
"""A different kind of authorization. Rather than making sure the
187
161
Same interface as "authorize" - None on success, HTTP_FORBIDDEN exception
188
162
raised on failure.
190
_, path = url_to_local(req.config, req.path)
192
# Walk up the tree, and find the deepest directory.
193
while not os.path.isdir(path):
194
path = os.path.dirname(path)
196
if not (worldreadable(path) and published(path)):
164
_, path = url_to_local(req.path)
165
dirpath, _ = os.path.split(path)
166
if not (worldreadable(dirpath) and published(dirpath)):
167
req.throw_error(req.HTTP_FORBIDDEN)