Account.h 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293
  1. /*
  2. * Copyright (c) 2020, Peter Elliott <pelliott@serenityos.org>
  3. *
  4. * SPDX-License-Identifier: BSD-2-Clause
  5. */
  6. #pragma once
  7. #include <AK/DeprecatedString.h>
  8. #include <AK/Types.h>
  9. #include <AK/Vector.h>
  10. #include <LibCore/SecretString.h>
  11. #include <pwd.h>
  12. #ifndef AK_OS_BSD_GENERIC
  13. # include <shadow.h>
  14. #endif
  15. #include <sys/types.h>
  16. namespace Core {
  17. #ifdef AK_OS_BSD_GENERIC
  18. struct spwd {
  19. char* sp_namp;
  20. char* sp_pwdp;
  21. };
  22. #endif
  23. class Account {
  24. public:
  25. enum class Read {
  26. All,
  27. PasswdOnly
  28. };
  29. static ErrorOr<Account> self(Read options = Read::All);
  30. static ErrorOr<Account> from_name(StringView username, Read options = Read::All);
  31. static ErrorOr<Account> from_uid(uid_t uid, Read options = Read::All);
  32. static ErrorOr<Vector<Account>> all(Read options = Read::All);
  33. bool authenticate(SecretString const& password) const;
  34. ErrorOr<void> login() const;
  35. DeprecatedString username() const { return m_username; }
  36. DeprecatedString password_hash() const { return m_password_hash; }
  37. // Setters only affect in-memory copy of password.
  38. // You must call sync to apply changes.
  39. void set_password(SecretString const& password);
  40. void set_password_enabled(bool enabled);
  41. void set_home_directory(StringView home_directory) { m_home_directory = home_directory; }
  42. void set_uid(uid_t uid) { m_uid = uid; }
  43. void set_gid(gid_t gid) { m_gid = gid; }
  44. void set_shell(StringView shell) { m_shell = shell; }
  45. void set_gecos(StringView gecos) { m_gecos = gecos; }
  46. void set_deleted() { m_deleted = true; };
  47. void delete_password();
  48. // A null password means that this account was missing from /etc/shadow.
  49. // It's considered to have a password in that case, and authentication will always fail.
  50. bool has_password() const { return !m_password_hash.is_empty() || m_password_hash.is_null(); }
  51. uid_t uid() const { return m_uid; }
  52. gid_t gid() const { return m_gid; }
  53. DeprecatedString const& gecos() const { return m_gecos; }
  54. DeprecatedString const& home_directory() const { return m_home_directory; }
  55. DeprecatedString const& shell() const { return m_shell; }
  56. Vector<gid_t> const& extra_gids() const { return m_extra_gids; }
  57. ErrorOr<void> sync();
  58. private:
  59. static ErrorOr<Account> from_passwd(passwd const&, spwd const&);
  60. Account(passwd const& pwd, spwd const& spwd, Vector<gid_t> extra_gids);
  61. ErrorOr<DeprecatedString> generate_passwd_file() const;
  62. #ifndef AK_OS_BSD_GENERIC
  63. ErrorOr<DeprecatedString> generate_shadow_file() const;
  64. #endif
  65. DeprecatedString m_username;
  66. DeprecatedString m_password_hash;
  67. uid_t m_uid { 0 };
  68. gid_t m_gid { 0 };
  69. DeprecatedString m_gecos;
  70. DeprecatedString m_home_directory;
  71. DeprecatedString m_shell;
  72. Vector<gid_t> m_extra_gids;
  73. bool m_deleted { false };
  74. };
  75. }