sftpgo_api_cli.py 40 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823
  1. #!/usr/bin/env python
  2. import argparse
  3. import base64
  4. from datetime import datetime
  5. import json
  6. import platform
  7. import sys
  8. import time
  9. import requests
  10. try:
  11. import urllib.parse as urlparse
  12. except ImportError:
  13. import urlparse
  14. try:
  15. import pygments
  16. from pygments.lexers import JsonLexer
  17. from pygments.formatters import TerminalFormatter
  18. except ImportError:
  19. pygments = None
  20. try:
  21. import pwd
  22. import spwd
  23. except ImportError:
  24. pwd = None
  25. class SFTPGoApiRequests:
  26. def __init__(self, debug, baseUrl, authType, authUser, authPassword, secure, no_color):
  27. self.userPath = urlparse.urljoin(baseUrl, '/api/v1/user')
  28. self.folderPath = urlparse.urljoin(baseUrl, '/api/v1/folder')
  29. self.quotaScanPath = urlparse.urljoin(baseUrl, '/api/v1/quota_scan')
  30. self.folderQuotaScanPath = urlparse.urljoin(baseUrl, '/api/v1/folder_quota_scan')
  31. self.activeConnectionsPath = urlparse.urljoin(baseUrl, '/api/v1/connection')
  32. self.versionPath = urlparse.urljoin(baseUrl, '/api/v1/version')
  33. self.providerStatusPath = urlparse.urljoin(baseUrl, '/api/v1/providerstatus')
  34. self.dumpDataPath = urlparse.urljoin(baseUrl, '/api/v1/dumpdata')
  35. self.loadDataPath = urlparse.urljoin(baseUrl, '/api/v1/loaddata')
  36. self.updateUsedQuotaPath = urlparse.urljoin(baseUrl, "/api/v1/quota_update")
  37. self.updateFolderUsedQuotaPath = urlparse.urljoin(baseUrl, "/api/v1/folder_quota_update")
  38. self.debug = debug
  39. if authType == 'basic':
  40. self.auth = requests.auth.HTTPBasicAuth(authUser, authPassword)
  41. elif authType == 'digest':
  42. self.auth = requests.auth.HTTPDigestAuth(authUser, authPassword)
  43. else:
  44. self.auth = None
  45. self.verify = secure
  46. self.no_color = no_color
  47. def formatAsJSON(self, text):
  48. if not text:
  49. return ''
  50. json_string = json.dumps(json.loads(text), sort_keys=True, indent=2)
  51. if not self.no_color and pygments:
  52. return pygments.highlight(json_string, JsonLexer(), TerminalFormatter())
  53. return json_string
  54. def printResponse(self, r):
  55. if 'content-type' in r.headers and 'application/json' in r.headers['content-type']:
  56. if self.debug:
  57. if pygments is None:
  58. print('')
  59. print('Response color highlight is not available: you need pygments 1.5 or above.')
  60. print('')
  61. print('Executed request: {} {} - request body: {}'.format(
  62. r.request.method, r.url, self.formatAsJSON(r.request.body)))
  63. print('')
  64. print('Got response, status code: {} body:'.format(r.status_code))
  65. print(self.formatAsJSON(r.text))
  66. else:
  67. print(r.text)
  68. def buildUserObject(self, user_id=0, username='', password='', public_keys=[], home_dir='', uid=0, gid=0,
  69. max_sessions=0, quota_size=0, quota_files=0, permissions={}, upload_bandwidth=0, download_bandwidth=0,
  70. status=1, expiration_date=0, allowed_ip=[], denied_ip=[], fs_provider='local', s3_bucket='',
  71. s3_region='', s3_access_key='', s3_access_secret='', s3_endpoint='', s3_storage_class='',
  72. s3_key_prefix='', gcs_bucket='', gcs_key_prefix='', gcs_storage_class='', gcs_credentials_file='',
  73. gcs_automatic_credentials='automatic', denied_login_methods=[], virtual_folders=[],
  74. denied_extensions=[], allowed_extensions=[], s3_upload_part_size=0, s3_upload_concurrency=0,
  75. max_upload_file_size=0, denied_protocols=[]):
  76. user = {'id':user_id, 'username':username, 'uid':uid, 'gid':gid,
  77. 'max_sessions':max_sessions, 'quota_size':quota_size, 'quota_files':quota_files,
  78. 'upload_bandwidth':upload_bandwidth, 'download_bandwidth':download_bandwidth,
  79. 'status':status, 'expiration_date':expiration_date}
  80. if password is not None:
  81. user.update({'password':password})
  82. if public_keys:
  83. if len(public_keys) == 1 and not public_keys[0]:
  84. user.update({'public_keys':[]})
  85. else:
  86. user.update({'public_keys':public_keys})
  87. if home_dir:
  88. user.update({'home_dir':home_dir})
  89. if permissions:
  90. user.update({'permissions':permissions})
  91. if virtual_folders:
  92. user.update({'virtual_folders':self.buildVirtualFolders(virtual_folders)})
  93. user.update({'filters':self.buildFilters(allowed_ip, denied_ip, denied_login_methods, denied_extensions,
  94. allowed_extensions, max_upload_file_size, denied_protocols)})
  95. user.update({'filesystem':self.buildFsConfig(fs_provider, s3_bucket, s3_region, s3_access_key, s3_access_secret,
  96. s3_endpoint, s3_storage_class, s3_key_prefix, gcs_bucket,
  97. gcs_key_prefix, gcs_storage_class, gcs_credentials_file,
  98. gcs_automatic_credentials, s3_upload_part_size, s3_upload_concurrency)})
  99. return user
  100. def buildVirtualFolders(self, vfolders):
  101. result = []
  102. for f in vfolders:
  103. if '::' in f:
  104. vpath = ''
  105. mapped_path = ''
  106. quota_files = 0
  107. quota_size = 0
  108. values = f.split('::')
  109. if len(values) > 1:
  110. vpath = values[0]
  111. mapped_path = values[1]
  112. if len(values) > 2:
  113. try:
  114. quota_files = int(values[2])
  115. except:
  116. pass
  117. if len(values) > 3:
  118. try:
  119. quota_size = int(values[3])
  120. except:
  121. pass
  122. if vpath and mapped_path:
  123. result.append({"virtual_path":vpath, "mapped_path":mapped_path,
  124. "quota_files":quota_files, "quota_size":quota_size})
  125. return result
  126. def buildPermissions(self, root_perms, subdirs_perms):
  127. permissions = {}
  128. if root_perms:
  129. permissions.update({'/':root_perms})
  130. for p in subdirs_perms:
  131. if '::' in p:
  132. directory = None
  133. values = []
  134. for value in p.split('::'):
  135. if directory is None:
  136. directory = value
  137. else:
  138. values = [v.strip() for v in value.split(',') if v.strip()]
  139. if directory:
  140. permissions.update({directory:values})
  141. return permissions
  142. def buildFilters(self, allowed_ip, denied_ip, denied_login_methods, denied_extensions, allowed_extensions,
  143. max_upload_file_size, denied_protocols):
  144. filters = {"max_upload_file_size":max_upload_file_size}
  145. if allowed_ip:
  146. if len(allowed_ip) == 1 and not allowed_ip[0]:
  147. filters.update({'allowed_ip':[]})
  148. else:
  149. filters.update({'allowed_ip':allowed_ip})
  150. if denied_ip:
  151. if len(denied_ip) == 1 and not denied_ip[0]:
  152. filters.update({'denied_ip':[]})
  153. else:
  154. filters.update({'denied_ip':denied_ip})
  155. if denied_login_methods:
  156. if len(denied_login_methods) == 1 and not denied_login_methods[0]:
  157. filters.update({'denied_login_methods':[]})
  158. else:
  159. filters.update({'denied_login_methods':denied_login_methods})
  160. if denied_protocols:
  161. if len(denied_protocols) == 1 and not denied_protocols[0]:
  162. filters.update({'denied_protocols':[]})
  163. else:
  164. filters.update({'denied_protocols':denied_protocols})
  165. extensions_filter = []
  166. extensions_denied = []
  167. extensions_allowed = []
  168. if denied_extensions:
  169. for e in denied_extensions:
  170. if '::' in e:
  171. directory = None
  172. values = []
  173. for value in e.split('::'):
  174. if directory is None:
  175. directory = value
  176. else:
  177. values = [v.strip() for v in value.split(',') if v.strip()]
  178. if directory:
  179. extensions_denied.append({'path':directory, 'denied_extensions':values,
  180. 'allowed_extensions':[]})
  181. if allowed_extensions:
  182. for e in allowed_extensions:
  183. if '::' in e:
  184. directory = None
  185. values = []
  186. for value in e.split('::'):
  187. if directory is None:
  188. directory = value
  189. else:
  190. values = [v.strip() for v in value.split(',') if v.strip()]
  191. if directory:
  192. extensions_allowed.append({'path':directory, 'allowed_extensions':values,
  193. 'denied_extensions':[]})
  194. if extensions_allowed and extensions_denied:
  195. for allowed in extensions_allowed:
  196. for denied in extensions_denied:
  197. if allowed.get('path') == denied.get('path'):
  198. allowed.update({'denied_extensions':denied.get('denied_extensions')})
  199. extensions_filter.append(allowed)
  200. for denied in extensions_denied:
  201. found = False
  202. for allowed in extensions_allowed:
  203. if allowed.get('path') == denied.get('path'):
  204. found = True
  205. if not found:
  206. extensions_filter.append(denied)
  207. elif extensions_allowed:
  208. extensions_filter = extensions_allowed
  209. elif extensions_denied:
  210. extensions_filter = extensions_denied
  211. if allowed_extensions or denied_extensions:
  212. filters.update({'file_extensions':extensions_filter})
  213. return filters
  214. def buildFsConfig(self, fs_provider, s3_bucket, s3_region, s3_access_key, s3_access_secret, s3_endpoint,
  215. s3_storage_class, s3_key_prefix, gcs_bucket, gcs_key_prefix, gcs_storage_class,
  216. gcs_credentials_file, gcs_automatic_credentials, s3_upload_part_size, s3_upload_concurrency):
  217. fs_config = {'provider':0}
  218. if fs_provider == 'S3':
  219. s3config = {'bucket':s3_bucket, 'region':s3_region, 'access_key':s3_access_key, 'access_secret':
  220. s3_access_secret, 'endpoint':s3_endpoint, 'storage_class':s3_storage_class, 'key_prefix':
  221. s3_key_prefix, 'upload_part_size':s3_upload_part_size, 'upload_concurrency':s3_upload_concurrency}
  222. fs_config.update({'provider':1, 's3config':s3config})
  223. elif fs_provider == 'GCS':
  224. gcsconfig = {'bucket':gcs_bucket, 'key_prefix':gcs_key_prefix, 'storage_class':gcs_storage_class}
  225. if gcs_automatic_credentials == "automatic":
  226. gcsconfig.update({'automatic_credentials':1})
  227. else:
  228. gcsconfig.update({'automatic_credentials':0})
  229. if gcs_credentials_file:
  230. with open(gcs_credentials_file) as creds:
  231. gcsconfig.update({'credentials':base64.b64encode(creds.read().encode('UTF-8')).decode('UTF-8'),
  232. 'automatic_credentials':0})
  233. fs_config.update({'provider':2, 'gcsconfig':gcsconfig})
  234. return fs_config
  235. def getUsers(self, limit=100, offset=0, order='ASC', username=''):
  236. r = requests.get(self.userPath, params={'limit':limit, 'offset':offset, 'order':order,
  237. 'username':username}, auth=self.auth, verify=self.verify)
  238. self.printResponse(r)
  239. def getUserByID(self, user_id):
  240. r = requests.get(urlparse.urljoin(self.userPath, 'user/' + str(user_id)), auth=self.auth, verify=self.verify)
  241. self.printResponse(r)
  242. def addUser(self, username='', password='', public_keys='', home_dir='', uid=0, gid=0, max_sessions=0, quota_size=0,
  243. quota_files=0, perms=[], upload_bandwidth=0, download_bandwidth=0, status=1, expiration_date=0,
  244. subdirs_permissions=[], allowed_ip=[], denied_ip=[], fs_provider='local', s3_bucket='', s3_region='',
  245. s3_access_key='', s3_access_secret='', s3_endpoint='', s3_storage_class='', s3_key_prefix='', gcs_bucket='',
  246. gcs_key_prefix='', gcs_storage_class='', gcs_credentials_file='', gcs_automatic_credentials='automatic',
  247. denied_login_methods=[], virtual_folders=[], denied_extensions=[], allowed_extensions=[],
  248. s3_upload_part_size=0, s3_upload_concurrency=0, max_upload_file_size=0, denied_protocols=[]):
  249. u = self.buildUserObject(0, username, password, public_keys, home_dir, uid, gid, max_sessions,
  250. quota_size, quota_files, self.buildPermissions(perms, subdirs_permissions), upload_bandwidth, download_bandwidth,
  251. status, expiration_date, allowed_ip, denied_ip, fs_provider, s3_bucket, s3_region, s3_access_key,
  252. s3_access_secret, s3_endpoint, s3_storage_class, s3_key_prefix, gcs_bucket, gcs_key_prefix, gcs_storage_class,
  253. gcs_credentials_file, gcs_automatic_credentials, denied_login_methods, virtual_folders, denied_extensions,
  254. allowed_extensions, s3_upload_part_size, s3_upload_concurrency, max_upload_file_size, denied_protocols)
  255. r = requests.post(self.userPath, json=u, auth=self.auth, verify=self.verify)
  256. self.printResponse(r)
  257. def updateUser(self, user_id, username='', password='', public_keys='', home_dir='', uid=0, gid=0, max_sessions=0,
  258. quota_size=0, quota_files=0, perms=[], upload_bandwidth=0, download_bandwidth=0, status=1,
  259. expiration_date=0, subdirs_permissions=[], allowed_ip=[], denied_ip=[], fs_provider='local',
  260. s3_bucket='', s3_region='', s3_access_key='', s3_access_secret='', s3_endpoint='', s3_storage_class='',
  261. s3_key_prefix='', gcs_bucket='', gcs_key_prefix='', gcs_storage_class='', gcs_credentials_file='',
  262. gcs_automatic_credentials='automatic', denied_login_methods=[], virtual_folders=[], denied_extensions=[],
  263. allowed_extensions=[], s3_upload_part_size=0, s3_upload_concurrency=0, max_upload_file_size=0,
  264. denied_protocols=[], disconnect=0):
  265. u = self.buildUserObject(user_id, username, password, public_keys, home_dir, uid, gid, max_sessions,
  266. quota_size, quota_files, self.buildPermissions(perms, subdirs_permissions), upload_bandwidth, download_bandwidth,
  267. status, expiration_date, allowed_ip, denied_ip, fs_provider, s3_bucket, s3_region, s3_access_key,
  268. s3_access_secret, s3_endpoint, s3_storage_class, s3_key_prefix, gcs_bucket, gcs_key_prefix, gcs_storage_class,
  269. gcs_credentials_file, gcs_automatic_credentials, denied_login_methods, virtual_folders, denied_extensions,
  270. allowed_extensions, s3_upload_part_size, s3_upload_concurrency, max_upload_file_size, denied_protocols)
  271. r = requests.put(urlparse.urljoin(self.userPath, 'user/' + str(user_id)), params={'disconnect':disconnect},
  272. json=u, auth=self.auth, verify=self.verify)
  273. self.printResponse(r)
  274. def deleteUser(self, user_id):
  275. r = requests.delete(urlparse.urljoin(self.userPath, 'user/' + str(user_id)), auth=self.auth, verify=self.verify)
  276. self.printResponse(r)
  277. def updateQuotaUsage(self, username, used_quota_size, used_quota_files, mode):
  278. req = {"username":username, "used_quota_files":used_quota_files, "used_quota_size":used_quota_size}
  279. r = requests.put(self.updateUsedQuotaPath, params={'mode':mode}, json=req, auth=self.auth, verify=self.verify)
  280. self.printResponse(r)
  281. def updateFolderQuotaUsage(self, mapped_path, used_quota_size, used_quota_files, mode):
  282. req = {"mapped_path":mapped_path, "used_quota_files":used_quota_files, "used_quota_size":used_quota_size}
  283. r = requests.put(self.updateFolderUsedQuotaPath, params={'mode':mode}, json=req, auth=self.auth, verify=self.verify)
  284. self.printResponse(r)
  285. def getConnections(self):
  286. r = requests.get(self.activeConnectionsPath, auth=self.auth, verify=self.verify)
  287. self.printResponse(r)
  288. def closeConnection(self, connectionID):
  289. r = requests.delete(urlparse.urljoin(self.activeConnectionsPath, 'connection/' + str(connectionID)), auth=self.auth)
  290. self.printResponse(r)
  291. def getQuotaScans(self):
  292. r = requests.get(self.quotaScanPath, auth=self.auth, verify=self.verify)
  293. self.printResponse(r)
  294. def startQuotaScan(self, username):
  295. u = self.buildUserObject(0, username)
  296. r = requests.post(self.quotaScanPath, json=u, auth=self.auth, verify=self.verify)
  297. self.printResponse(r)
  298. def getFoldersQuotaScans(self):
  299. r = requests.get(self.folderQuotaScanPath, auth=self.auth, verify=self.verify)
  300. self.printResponse(r)
  301. def startFolderQuotaScan(self, mapped_path):
  302. f = {"mapped_path":mapped_path}
  303. r = requests.post(self.folderQuotaScanPath, json=f, auth=self.auth, verify=self.verify)
  304. self.printResponse(r)
  305. def addFolder(self, mapped_path):
  306. f = {"mapped_path":mapped_path}
  307. r = requests.post(self.folderPath, json=f, auth=self.auth, verify=self.verify)
  308. self.printResponse(r)
  309. def deleteFolder(self, mapped_path):
  310. r = requests.delete(self.folderPath, params={'folder_path':mapped_path}, auth=self.auth, verify=self.verify)
  311. self.printResponse(r)
  312. def getFolders(self, limit=100, offset=0, order='ASC', mapped_path=''):
  313. r = requests.get(self.folderPath, params={'limit':limit, 'offset':offset, 'order':order,
  314. 'folder_path':mapped_path}, auth=self.auth, verify=self.verify)
  315. self.printResponse(r)
  316. def getVersion(self):
  317. r = requests.get(self.versionPath, auth=self.auth, verify=self.verify)
  318. self.printResponse(r)
  319. def getProviderStatus(self):
  320. r = requests.get(self.providerStatusPath, auth=self.auth, verify=self.verify)
  321. self.printResponse(r)
  322. def dumpData(self, output_file, indent):
  323. r = requests.get(self.dumpDataPath, params={'output_file':output_file, 'indent':indent},
  324. auth=self.auth, verify=self.verify)
  325. self.printResponse(r)
  326. def loadData(self, input_file, scan_quota, mode):
  327. r = requests.get(self.loadDataPath, params={'input_file':input_file, 'scan_quota':scan_quota,
  328. 'mode':mode},
  329. auth=self.auth, verify=self.verify)
  330. self.printResponse(r)
  331. class ConvertUsers:
  332. def __init__(self, input_file, users_format, output_file, min_uid, max_uid, usernames, force_uid, force_gid):
  333. self.input_file = input_file
  334. self.users_format = users_format
  335. self.output_file = output_file
  336. self.min_uid = min_uid
  337. self.max_uid = max_uid
  338. self.usernames = usernames
  339. self.force_uid = force_uid
  340. self.force_gid = force_gid
  341. self.SFTPGoUsers = []
  342. def setSFTPGoRestApi(self, api):
  343. self.SFTPGoRestAPI = api
  344. def addUser(self, user):
  345. user['id'] = len(self.SFTPGoUsers) + 1
  346. print('')
  347. print('New user imported: {}'.format(user))
  348. print('')
  349. self.SFTPGoUsers.append(user)
  350. def saveUsers(self):
  351. if self.SFTPGoUsers:
  352. data = {'users':self.SFTPGoUsers}
  353. jsonData = json.dumps(data)
  354. with open(self.output_file, 'w') as f:
  355. f.write(jsonData)
  356. print()
  357. print('Number of users saved to "{}": {}. You can import them using loaddata'.format(self.output_file,
  358. len(self.SFTPGoUsers)))
  359. print()
  360. sys.exit(0)
  361. else:
  362. print('No user imported')
  363. sys.exit(1)
  364. def convert(self):
  365. if self.users_format == 'unix-passwd':
  366. self.convertFromUnixPasswd()
  367. elif self.users_format == 'pure-ftpd':
  368. self.convertFromPureFTPD()
  369. else:
  370. self.convertFromProFTPD()
  371. self.saveUsers()
  372. def isUserValid(self, username, uid):
  373. if self.usernames and not username in self.usernames:
  374. return False
  375. if self.min_uid >= 0 and uid < self.min_uid:
  376. return False
  377. if self.max_uid >= 0 and uid > self.max_uid:
  378. return False
  379. return True
  380. def convertFromUnixPasswd(self):
  381. days_from_epoch_time = time.time() / 86400
  382. for user in pwd.getpwall():
  383. username = user.pw_name
  384. password = user.pw_passwd
  385. uid = user.pw_uid
  386. gid = user.pw_gid
  387. home_dir = user.pw_dir
  388. status = 1
  389. expiration_date = 0
  390. if not self.isUserValid(username, uid):
  391. continue
  392. if self.force_uid >= 0:
  393. uid = self.force_uid
  394. if self.force_gid >= 0:
  395. gid = self.force_gid
  396. # FIXME: if the passwords aren't in /etc/shadow they are probably DES encrypted and we don't support them
  397. if password == 'x' or password == '*':
  398. user_info = spwd.getspnam(username)
  399. password = user_info.sp_pwdp
  400. if not password or password == '!!':
  401. print('cannot import user "{}" without a password'.format(username))
  402. continue
  403. if user_info.sp_inact > 0:
  404. last_pwd_change_diff = days_from_epoch_time - user_info.sp_lstchg
  405. if last_pwd_change_diff > user_info.sp_inact:
  406. status = 0
  407. if user_info.sp_expire > 0:
  408. expiration_date = user_info.sp_expire * 86400
  409. permissions = self.SFTPGoRestAPI.buildPermissions(['*'], [])
  410. self.addUser(self.SFTPGoRestAPI.buildUserObject(0, username, password, [], home_dir, uid, gid, 0, 0, 0,
  411. permissions, 0, 0, status, expiration_date))
  412. def convertFromProFTPD(self):
  413. with open(self.input_file, 'r') as f:
  414. for line in f:
  415. fields = line.split(':')
  416. if len(fields) > 6:
  417. username = fields[0]
  418. password = fields[1]
  419. uid = int(fields[2])
  420. gid = int(fields[3])
  421. home_dir = fields[5]
  422. if not self.isUserValid(username, uid, gid):
  423. continue
  424. if self.force_uid >= 0:
  425. uid = self.force_uid
  426. if self.force_gid >= 0:
  427. gid = self.force_gid
  428. permissions = self.SFTPGoRestAPI.buildPermissions(['*'], [])
  429. self.addUser(self.SFTPGoRestAPI.buildUserObject(0, username, password, [], home_dir, uid, gid, 0, 0,
  430. 0, permissions, 0, 0, 1, 0))
  431. def convertPureFTPDIP(self, fields):
  432. result = []
  433. if not fields:
  434. return result
  435. for v in fields.split(','):
  436. ip_mask = v.strip()
  437. if not ip_mask:
  438. continue
  439. if ip_mask.count('.') < 3 and ip_mask.count(':') < 3:
  440. print('cannot import pure-ftpd IP: {}'.format(ip_mask))
  441. continue
  442. if '/' not in ip_mask:
  443. ip_mask += '/32'
  444. result.append(ip_mask)
  445. return result
  446. def convertFromPureFTPD(self):
  447. with open(self.input_file, 'r') as f:
  448. for line in f:
  449. fields = line.split(':')
  450. if len(fields) > 16:
  451. username = fields[0]
  452. password = fields[1]
  453. uid = int(fields[2])
  454. gid = int(fields[3])
  455. home_dir = fields[5]
  456. upload_bandwidth = 0
  457. if fields[6]:
  458. upload_bandwidth = int(int(fields[6]) / 1024)
  459. download_bandwidth = 0
  460. if fields[7]:
  461. download_bandwidth = int(int(fields[7]) / 1024)
  462. max_sessions = 0
  463. if fields[10]:
  464. max_sessions = int(fields[10])
  465. quota_files = 0
  466. if fields[11]:
  467. quota_files = int(fields[11])
  468. quota_size = 0
  469. if fields[12]:
  470. quota_size = int(fields[12])
  471. allowed_ip = self.convertPureFTPDIP(fields[15])
  472. denied_ip = self.convertPureFTPDIP(fields[16])
  473. if not self.isUserValid(username, uid, gid):
  474. continue
  475. if self.force_uid >= 0:
  476. uid = self.force_uid
  477. if self.force_gid >= 0:
  478. gid = self.force_gid
  479. permissions = self.SFTPGoRestAPI.buildPermissions(['*'], [])
  480. self.addUser(self.SFTPGoRestAPI.buildUserObject(0, username, password, [], home_dir, uid, gid,
  481. max_sessions, quota_size, quota_files, permissions,
  482. upload_bandwidth, download_bandwidth, 1, 0, allowed_ip,
  483. denied_ip))
  484. def validDate(s):
  485. if not s:
  486. return datetime.fromtimestamp(0)
  487. try:
  488. return datetime.strptime(s, '%Y-%m-%d')
  489. except ValueError:
  490. msg = 'Not a valid date: "{0}".'.format(s)
  491. raise argparse.ArgumentTypeError(msg)
  492. def getDatetimeAsMillisSinceEpoch(dt):
  493. epoch = datetime.fromtimestamp(0)
  494. return int((dt - epoch).total_seconds() * 1000)
  495. def addCommonUserArguments(parser):
  496. parser.add_argument('username', type=str)
  497. parser.add_argument('-P', '--password', type=str, default=None, help='Default: %(default)s')
  498. parser.add_argument('-K', '--public-keys', type=str, nargs='+', default=[], help='Public keys or SSH user certificates. ' +
  499. 'Default: %(default)s')
  500. parser.add_argument('-H', '--home-dir', type=str, default='', help='Default: %(default)s')
  501. parser.add_argument('--uid', type=int, default=0, help='Default: %(default)s')
  502. parser.add_argument('--gid', type=int, default=0, help='Default: %(default)s')
  503. parser.add_argument('-C', '--max-sessions', type=int, default=0,
  504. help='Maximum concurrent sessions. 0 means unlimited. Default: %(default)s')
  505. parser.add_argument('-S', '--quota-size', type=int, default=0,
  506. help='Maximum size allowed as bytes. 0 means unlimited. Default: %(default)s')
  507. parser.add_argument('-F', '--quota-files', type=int, default=0, help='default: %(default)s')
  508. parser.add_argument('-G', '--permissions', type=str, nargs='+', default=[],
  509. choices=['*', 'list', 'download', 'upload', 'overwrite', 'delete', 'rename', 'create_dirs',
  510. 'create_symlinks', 'chmod', 'chown', 'chtimes'], help='Permissions for the root directory '
  511. +'(/). Default: %(default)s')
  512. parser.add_argument('-L', '--denied-login-methods', type=str, nargs='+', default=[],
  513. choices=['', 'publickey', 'password', 'keyboard-interactive', 'publickey+password',
  514. 'publickey+keyboard-interactive'], help='Default: %(default)s')
  515. parser.add_argument('--denied-protocols', type=str, nargs='+', default=[],
  516. choices=['', 'SSH', 'FTP', 'DAV'], help='Default: %(default)s')
  517. parser.add_argument('--subdirs-permissions', type=str, nargs='*', default=[], help='Permissions for subdirs. '
  518. +'For example: "/somedir::list,download" "/otherdir/subdir::*" Default: %(default)s')
  519. parser.add_argument('--virtual-folders', type=str, nargs='*', default=[], help='Virtual folder mapping. For example: '
  520. +'"/vpath::/home/adir" "/vpath::C:\adir::[quota_file]::[quota_size]". Quota parameters -1 means '
  521. +'included inside user quota, 0 means unlimited. Ignored for non local filesystems. Default: %(default)s')
  522. parser.add_argument('-U', '--upload-bandwidth', type=int, default=0,
  523. help='Maximum upload bandwidth as KB/s, 0 means unlimited. Default: %(default)s')
  524. parser.add_argument('-D', '--download-bandwidth', type=int, default=0,
  525. help='Maximum download bandwidth as KB/s, 0 means unlimited. Default: %(default)s')
  526. parser.add_argument('--status', type=int, choices=[0, 1], default=1,
  527. help='User\'s status. 1 enabled, 0 disabled. Default: %(default)s')
  528. parser.add_argument('--max-upload-file-size', type=int, default=0,
  529. help='Maximum allowed size, as bytes, for a single file upload, 0 means unlimited. Default: %(default)s')
  530. parser.add_argument('-E', '--expiration-date', type=validDate, default='',
  531. help='Expiration date as YYYY-MM-DD, empty string means no expiration. Default: %(default)s')
  532. parser.add_argument('-Y', '--allowed-ip', type=str, nargs='+', default=[],
  533. help='Allowed IP/Mask in CIDR notation. For example "192.168.2.0/24" or "2001:db8::/32". Default: %(default)s')
  534. parser.add_argument('-N', '--denied-ip', type=str, nargs='+', default=[],
  535. help='Denied IP/Mask in CIDR notation. For example "192.168.2.0/24" or "2001:db8::/32". Default: %(default)s')
  536. parser.add_argument('--denied-extensions', type=str, nargs='*', default=[], help='Denied file extensions case insensitive. '
  537. +'The format is /dir::ext1,ext2. For example: "/somedir::.jpg,.png" "/otherdir/subdir::.zip,.rar". ' +
  538. 'You have to set both denied and allowed extensions to update existing values or none to preserve them.' +
  539. ' If you only set allowed or denied extensions the missing one is assumed to be an empty list. Default: %(default)s')
  540. parser.add_argument('--allowed-extensions', type=str, nargs='*', default=[], help='Allowed file extensions case insensitive. '
  541. +'The format is /dir::ext1,ext2. For example: "/somedir::.jpg,.png" "/otherdir/subdir::.zip,.rar". ' +
  542. 'Default: %(default)s')
  543. parser.add_argument('--fs', type=str, default='local', choices=['local', 'S3', 'GCS'],
  544. help='Filesystem provider. Default: %(default)s')
  545. parser.add_argument('--s3-bucket', type=str, default='', help='Default: %(default)s')
  546. parser.add_argument('--s3-key-prefix', type=str, default='', help='Virtual root directory. If non empty only this ' +
  547. 'directory and its contents will be available. Cannot start with "/". For example "folder/subfolder/".' +
  548. ' Default: %(default)s')
  549. parser.add_argument('--s3-region', type=str, default='', help='Default: %(default)s')
  550. parser.add_argument('--s3-access-key', type=str, default='', help='Default: %(default)s')
  551. parser.add_argument('--s3-access-secret', type=str, default='', help='Default: %(default)s')
  552. parser.add_argument('--s3-endpoint', type=str, default='', help='Default: %(default)s')
  553. parser.add_argument('--s3-storage-class', type=str, default='', help='Default: %(default)s')
  554. parser.add_argument('--s3-upload-part-size', type=int, default=0, help='The buffer size for multipart uploads (MB). ' +
  555. 'Zero means the default (5 MB). Minimum is 5. Default: %(default)s')
  556. parser.add_argument('--s3-upload-concurrency', type=int, default=0, help='How many parts are uploaded in parallel. ' +
  557. 'Zero means the default (2). Default: %(default)s')
  558. parser.add_argument('--gcs-bucket', type=str, default='', help='Default: %(default)s')
  559. parser.add_argument('--gcs-key-prefix', type=str, default='', help='Virtual root directory. If non empty only this ' +
  560. 'directory and its contents will be available. Cannot start with "/". For example "folder/subfolder/".' +
  561. ' Default: %(default)s')
  562. parser.add_argument('--gcs-storage-class', type=str, default='', help='Default: %(default)s')
  563. parser.add_argument('--gcs-credentials-file', type=str, default='', help='Default: %(default)s')
  564. parser.add_argument('--gcs-automatic-credentials', type=str, default='automatic', choices=['explicit', 'automatic'],
  565. help='If you provide a credentials file this argument will be setted to "explicit". Default: %(default)s')
  566. if __name__ == '__main__':
  567. parser = argparse.ArgumentParser(formatter_class=argparse.ArgumentDefaultsHelpFormatter)
  568. parser.add_argument('-b', '--base-url', type=str, default='http://127.0.0.1:8080',
  569. help='Base URL for SFTPGo REST API. Default: %(default)s')
  570. parser.add_argument('-a', '--auth-type', type=str, default=None, choices=['basic', 'digest'],
  571. help='HTTP authentication type. Default: %(default)s')
  572. parser.add_argument('-u', '--auth-user', type=str, default='',
  573. help='User for HTTP authentication. Default: %(default)s')
  574. parser.add_argument('-p', '--auth-password', type=str, default='',
  575. help='Password for HTTP authentication. Default: %(default)s')
  576. parser.add_argument('-d', '--debug', dest='debug', action='store_true')
  577. parser.set_defaults(debug=False)
  578. parser.add_argument('-i', '--insecure', dest='secure', action='store_false',
  579. help='Set to false to ignore verifying the SSL certificate')
  580. parser.set_defaults(secure=True)
  581. has_colors_default = pygments is not None and platform.system() != 'Windows'
  582. group = parser.add_mutually_exclusive_group(required=False)
  583. group.add_argument('-t', '--no-color', dest='no_color', action='store_true', default=(not has_colors_default),
  584. help='Disable color highlight for JSON responses. You need python pygments module 1.5 or above to have highlighted output')
  585. group.add_argument('-c', '--color', dest='no_color', action='store_false', default=has_colors_default,
  586. help='Enable color highlight for JSON responses. You need python pygments module 1.5 or above to have highlighted output')
  587. parser.add_argument_group(group)
  588. subparsers = parser.add_subparsers(dest='command', help='sub-command --help')
  589. subparsers.required = True
  590. parserAddUser = subparsers.add_parser('add-user', help='Add a new SFTP user')
  591. addCommonUserArguments(parserAddUser)
  592. parserUpdateUser = subparsers.add_parser('update-user', help='Update an existing user')
  593. parserUpdateUser.add_argument('id', type=int, help='User\'s ID to update')
  594. parserUpdateUser.add_argument('--disconnect', type=int, choices=[0, 1], default=0,
  595. help='0 means the user will not be disconnected and it will continue to use the old ' +
  596. 'configuration until connected. 1 means the user will be disconnected after a successful ' +
  597. 'update. It must login again and so it will be forced to use the new configuration. ' +
  598. 'Default: %(default)s')
  599. addCommonUserArguments(parserUpdateUser)
  600. parserDeleteUser = subparsers.add_parser('delete-user', help='Delete an existing user')
  601. parserDeleteUser.add_argument('id', type=int, help='User\'s ID to delete')
  602. parserGetUsers = subparsers.add_parser('get-users', help='Returns an array with one or more SFTP users')
  603. parserGetUsers.add_argument('-L', '--limit', type=int, default=100, choices=range(1, 501),
  604. help='Maximum allowed value is 500. Default: %(default)s', metavar='[1...500]')
  605. parserGetUsers.add_argument('-O', '--offset', type=int, default=0, help='Default: %(default)s')
  606. parserGetUsers.add_argument('-U', '--username', type=str, default='', help='Default: %(default)s')
  607. parserGetUsers.add_argument('-S', '--order', type=str, choices=['ASC', 'DESC'], default='ASC',
  608. help='default: %(default)s')
  609. parserGetUserByID = subparsers.add_parser('get-user-by-id', help='Find user by ID')
  610. parserGetUserByID.add_argument('id', type=int)
  611. parserGetConnections = subparsers.add_parser('get-connections',
  612. help='Get the active users and info about their uploads/downloads')
  613. parserCloseConnection = subparsers.add_parser('close-connection', help='Terminate an active SFTP/SCP connection')
  614. parserCloseConnection.add_argument('connectionID', type=str)
  615. parserGetQuotaScans = subparsers.add_parser('get-quota-scans', help='Get the active quota scans for users home directories')
  616. parserStartQuotaScan = subparsers.add_parser('start-quota-scan', help='Start a new user quota scan')
  617. addCommonUserArguments(parserStartQuotaScan)
  618. parserGetFolderQuotaScans = subparsers.add_parser('get-folders-quota-scans', help='Get the active quota scans for folders')
  619. parserStartFolderQuotaScan = subparsers.add_parser('start-folder-quota-scan', help='Start a new folder quota scan')
  620. parserStartFolderQuotaScan.add_argument('folder_path', type=str)
  621. parserGetFolders = subparsers.add_parser('get-folders', help='Returns an array with one or more folders')
  622. parserGetFolders.add_argument('-L', '--limit', type=int, default=100, choices=range(1, 501),
  623. help='Maximum allowed value is 500. Default: %(default)s', metavar='[1...500]')
  624. parserGetFolders.add_argument('-O', '--offset', type=int, default=0, help='Default: %(default)s')
  625. parserGetFolders.add_argument('-P', '--folder-path', type=str, default='', help='Default: %(default)s')
  626. parserGetFolders.add_argument('-S', '--order', type=str, choices=['ASC', 'DESC'], default='ASC',
  627. help='default: %(default)s')
  628. parserAddFolder = subparsers.add_parser('add-folder', help='Add a new folder')
  629. parserAddFolder.add_argument('folder_path', type=str)
  630. parserDeleteFolder = subparsers.add_parser('delete-folder', help='Delete an existing folder')
  631. parserDeleteFolder.add_argument('folder_path', type=str)
  632. parserGetVersion = subparsers.add_parser('get-version', help='Get version details')
  633. parserGetProviderStatus = subparsers.add_parser('get-provider-status', help='Get data provider status')
  634. parserDumpData = subparsers.add_parser('dumpdata', help='Backup SFTPGo data serializing them as JSON')
  635. parserDumpData.add_argument('output_file', type=str)
  636. parserDumpData.add_argument('-I', '--indent', type=int, choices=[0, 1], default=0,
  637. help='0 means no indentation. 1 means format the output JSON. Default: %(default)s')
  638. parserLoadData = subparsers.add_parser('loaddata', help='Restore SFTPGo data from a JSON backup')
  639. parserLoadData.add_argument('input_file', type=str)
  640. parserLoadData.add_argument('-Q', '--scan-quota', type=int, choices=[0, 1, 2], default=0,
  641. help='0 means no quota scan after a user is added/updated. 1 means always scan quota. 2 ' +
  642. 'means scan quota if the user has quota restrictions. Default: %(default)s')
  643. parserLoadData.add_argument('-M', '--mode', type=int, choices=[0, 1, 2], default=0,
  644. help='0 means new users are added, existing users are updated. 1 means new users are added,' +
  645. ' existing users are not modified. 2 is the same as 0 but if an updated user is connected ' +
  646. 'it will be disconnected and so forced to use the new configuration Default: %(default)s')
  647. parserUpdateQuotaUsage = subparsers.add_parser('update-quota-usage', help='Update the user used quota limits')
  648. parserUpdateQuotaUsage.add_argument('username', type=str)
  649. parserUpdateQuotaUsage.add_argument('-M', '--mode', type=str, choices=["add", "reset"], default="reset",
  650. help='the update mode specifies if the given quota usage values should be added or ' +
  651. 'replace the current ones. Default: %(default)s')
  652. parserUpdateQuotaUsage.add_argument('-S', '--used_quota_size', type=int, default=0, help='Default: %(default)s')
  653. parserUpdateQuotaUsage.add_argument('-F', '--used_quota_files', type=int, default=0, help='Default: %(default)s')
  654. parserUpdateFolderQuotaUsage = subparsers.add_parser('update-folder-quota-usage', help='Update the folder used quota limits')
  655. parserUpdateFolderQuotaUsage.add_argument('folder_path', type=str)
  656. parserUpdateFolderQuotaUsage.add_argument('-M', '--mode', type=str, choices=["add", "reset"], default="reset",
  657. help='the update mode specifies if the given quota usage values should be added or ' +
  658. 'replace the current ones. Default: %(default)s')
  659. parserUpdateFolderQuotaUsage.add_argument('-S', '--used_quota_size', type=int, default=0, help='Default: %(default)s')
  660. parserUpdateFolderQuotaUsage.add_argument('-F', '--used_quota_files', type=int, default=0, help='Default: %(default)s')
  661. parserConvertUsers = subparsers.add_parser('convert-users', help='Convert users to a JSON format suitable to use ' +
  662. 'with loadddata')
  663. supportedUsersFormats = []
  664. help_text = ''
  665. if pwd is not None:
  666. supportedUsersFormats.append('unix-passwd')
  667. help_text = 'To import from unix-passwd format you need the permission to read /etc/shadow that is typically granted to the root user only'
  668. supportedUsersFormats.append('pure-ftpd')
  669. supportedUsersFormats.append('proftpd')
  670. parserConvertUsers.add_argument('input_file', type=str)
  671. parserConvertUsers.add_argument('users_format', type=str, choices=supportedUsersFormats, help=help_text)
  672. parserConvertUsers.add_argument('output_file', type=str)
  673. parserConvertUsers.add_argument('--min-uid', type=int, default=-1, help='if >= 0 only import users with UID greater ' +
  674. 'or equal to this value. Default: %(default)s')
  675. parserConvertUsers.add_argument('--max-uid', type=int, default=-1, help='if >= 0 only import users with UID lesser ' +
  676. 'or equal to this value. Default: %(default)s')
  677. parserConvertUsers.add_argument('--usernames', type=str, nargs='+', default=[], help='Only import users with these ' +
  678. 'usernames. Default: %(default)s')
  679. parserConvertUsers.add_argument('--force-uid', type=int, default=-1, help='if >= 0 the imported users will have this UID in SFTPGo. Default: %(default)s')
  680. parserConvertUsers.add_argument('--force-gid', type=int, default=-1, help='if >= 0 the imported users will have this GID in SFTPGp. Default: %(default)s')
  681. args = parser.parse_args()
  682. api = SFTPGoApiRequests(args.debug, args.base_url, args.auth_type, args.auth_user, args.auth_password, args.secure,
  683. args.no_color)
  684. if args.command == 'add-user':
  685. api.addUser(args.username, args.password, args.public_keys, args.home_dir, args.uid, args.gid, args.max_sessions,
  686. args.quota_size, args.quota_files, args.permissions, args.upload_bandwidth, args.download_bandwidth,
  687. args.status, getDatetimeAsMillisSinceEpoch(args.expiration_date), args.subdirs_permissions, args.allowed_ip,
  688. args.denied_ip, args.fs, args.s3_bucket, args.s3_region, args.s3_access_key, args.s3_access_secret,
  689. args.s3_endpoint, args.s3_storage_class, args.s3_key_prefix, args.gcs_bucket, args.gcs_key_prefix,
  690. args.gcs_storage_class, args.gcs_credentials_file, args.gcs_automatic_credentials,
  691. args.denied_login_methods, args.virtual_folders, args.denied_extensions, args.allowed_extensions,
  692. args.s3_upload_part_size, args.s3_upload_concurrency, args.max_upload_file_size, args.denied_protocols)
  693. elif args.command == 'update-user':
  694. api.updateUser(args.id, args.username, args.password, args.public_keys, args.home_dir, args.uid, args.gid,
  695. args.max_sessions, args.quota_size, args.quota_files, args.permissions, args.upload_bandwidth,
  696. args.download_bandwidth, args.status, getDatetimeAsMillisSinceEpoch(args.expiration_date),
  697. args.subdirs_permissions, args.allowed_ip, args.denied_ip, args.fs, args.s3_bucket, args.s3_region,
  698. args.s3_access_key, args.s3_access_secret, args.s3_endpoint, args.s3_storage_class,
  699. args.s3_key_prefix, args.gcs_bucket, args.gcs_key_prefix, args.gcs_storage_class,
  700. args.gcs_credentials_file, args.gcs_automatic_credentials, args.denied_login_methods,
  701. args.virtual_folders, args.denied_extensions, args.allowed_extensions, args.s3_upload_part_size,
  702. args.s3_upload_concurrency, args.max_upload_file_size, args.denied_protocols, args.disconnect)
  703. elif args.command == 'delete-user':
  704. api.deleteUser(args.id)
  705. elif args.command == 'get-users':
  706. api.getUsers(args.limit, args.offset, args.order, args.username)
  707. elif args.command == 'get-user-by-id':
  708. api.getUserByID(args.id)
  709. elif args.command == 'get-connections':
  710. api.getConnections()
  711. elif args.command == 'close-connection':
  712. api.closeConnection(args.connectionID)
  713. elif args.command == 'get-quota-scans':
  714. api.getQuotaScans()
  715. elif args.command == 'start-quota-scan':
  716. api.startQuotaScan(args.username)
  717. elif args.command == 'get-folders':
  718. api.getFolders(args.limit, args.offset, args.order, args.folder_path)
  719. elif args.command == 'add-folder':
  720. api.addFolder(args.folder_path)
  721. elif args.command == 'delete-folder':
  722. api.deleteFolder(args.folder_path)
  723. elif args.command == 'get-folders-quota-scans':
  724. api.getFoldersQuotaScans()
  725. elif args.command == 'start-folder-quota-scan':
  726. api.startFolderQuotaScan(args.folder_path)
  727. elif args.command == 'get-version':
  728. api.getVersion()
  729. elif args.command == 'get-provider-status':
  730. api.getProviderStatus()
  731. elif args.command == 'dumpdata':
  732. api.dumpData(args.output_file, args.indent)
  733. elif args.command == 'loaddata':
  734. api.loadData(args.input_file, args.scan_quota, args.mode)
  735. elif args.command == 'update-quota-usage':
  736. api.updateQuotaUsage(args.username, args.used_quota_size, args.used_quota_files, args.mode)
  737. elif args.command == 'update-folder-quota-usage':
  738. api.updateFolderQuotaUsage(args.folder_path, args.used_quota_size, args.used_quota_files, args.mode)
  739. elif args.command == 'convert-users':
  740. convertUsers = ConvertUsers(args.input_file, args.users_format, args.output_file, args.min_uid, args.max_uid,
  741. args.usernames, args.force_uid, args.force_gid)
  742. convertUsers.setSFTPGoRestApi(api)
  743. convertUsers.convert()