|
|
@ -10,38 +10,45 @@ using NetFwTypeLib;
|
|
|
|
|
|
|
|
|
|
|
|
namespace NzbDrone.Common
|
|
|
|
namespace NzbDrone.Common
|
|
|
|
{
|
|
|
|
{
|
|
|
|
public class SecurityProvider
|
|
|
|
public interface ISecurityProvider
|
|
|
|
{
|
|
|
|
{
|
|
|
|
private static readonly Logger Logger = LogManager.GetCurrentClassLogger ();
|
|
|
|
void MakeAccessible();
|
|
|
|
|
|
|
|
bool IsCurrentUserAdmin();
|
|
|
|
|
|
|
|
bool IsNzbDronePortOpen();
|
|
|
|
|
|
|
|
bool IsNzbDroneUrlRegistered();
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
public class SecurityProvider : ISecurityProvider
|
|
|
|
|
|
|
|
{
|
|
|
|
private readonly ConfigFileProvider _configFileProvider;
|
|
|
|
private readonly ConfigFileProvider _configFileProvider;
|
|
|
|
private readonly EnvironmentProvider _environmentProvider;
|
|
|
|
private readonly EnvironmentProvider _environmentProvider;
|
|
|
|
private readonly ProcessProvider _processProvider;
|
|
|
|
private readonly ProcessProvider _processProvider;
|
|
|
|
|
|
|
|
private readonly Logger _logger;
|
|
|
|
|
|
|
|
|
|
|
|
public SecurityProvider (ConfigFileProvider configFileProvider, EnvironmentProvider environmentProvider,
|
|
|
|
public SecurityProvider(ConfigFileProvider configFileProvider, EnvironmentProvider environmentProvider,
|
|
|
|
ProcessProvider processProvider)
|
|
|
|
ProcessProvider processProvider, Logger logger)
|
|
|
|
{
|
|
|
|
{
|
|
|
|
_configFileProvider = configFileProvider;
|
|
|
|
_configFileProvider = configFileProvider;
|
|
|
|
_environmentProvider = environmentProvider;
|
|
|
|
_environmentProvider = environmentProvider;
|
|
|
|
_processProvider = processProvider;
|
|
|
|
_processProvider = processProvider;
|
|
|
|
|
|
|
|
_logger = logger;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
public SecurityProvider ()
|
|
|
|
public void MakeAccessible()
|
|
|
|
{
|
|
|
|
{
|
|
|
|
}
|
|
|
|
if (!IsCurrentUserAdmin ())
|
|
|
|
|
|
|
|
|
|
|
|
public virtual void MakeAccessible ()
|
|
|
|
|
|
|
|
{
|
|
|
|
{
|
|
|
|
if (!IsCurrentUserAdmin ()) {
|
|
|
|
_logger.Trace ("User is not an admin, skipping.");
|
|
|
|
Logger.Trace ("User is not an admin, skipping.");
|
|
|
|
|
|
|
|
return;
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int port = 0;
|
|
|
|
int port = 0;
|
|
|
|
|
|
|
|
|
|
|
|
if (IsFirewallEnabled ()) {
|
|
|
|
if (IsFirewallEnabled ())
|
|
|
|
if (IsNzbDronePortOpen ()) {
|
|
|
|
{
|
|
|
|
Logger.Trace ("NzbDrone port is already open, skipping.");
|
|
|
|
if (IsNzbDronePortOpen ())
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
_logger.Trace ("NzbDrone port is already open, skipping.");
|
|
|
|
return;
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
@ -58,24 +65,24 @@ namespace NzbDrone.Common
|
|
|
|
|
|
|
|
|
|
|
|
//Unregister Url (if port != 0)
|
|
|
|
//Unregister Url (if port != 0)
|
|
|
|
if (port != 0)
|
|
|
|
if (port != 0)
|
|
|
|
UnregisterUrl (port);
|
|
|
|
UnregisterUrl(port);
|
|
|
|
|
|
|
|
|
|
|
|
//Register Url
|
|
|
|
//Register Url
|
|
|
|
RegisterUrl (_configFileProvider.Port);
|
|
|
|
RegisterUrl(_configFileProvider.Port);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
public virtual bool IsCurrentUserAdmin ()
|
|
|
|
public bool IsCurrentUserAdmin()
|
|
|
|
{
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
try {
|
|
|
|
var principal = new WindowsPrincipal (WindowsIdentity.GetCurrent ());
|
|
|
|
var principal = new WindowsPrincipal (WindowsIdentity.GetCurrent ());
|
|
|
|
return principal.IsInRole (WindowsBuiltInRole.Administrator);
|
|
|
|
return principal.IsInRole (WindowsBuiltInRole.Administrator);
|
|
|
|
} catch (Exception ex) {
|
|
|
|
} catch (Exception ex) {
|
|
|
|
Logger.WarnException ("Error checking if the current user is an administrator.", ex);
|
|
|
|
_logger.WarnException ("Error checking if the current user is an administrator.", ex);
|
|
|
|
return false;
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
public virtual bool IsNzbDronePortOpen ()
|
|
|
|
public bool IsNzbDronePortOpen()
|
|
|
|
{
|
|
|
|
{
|
|
|
|
#if __MonoCS__
|
|
|
|
#if __MonoCS__
|
|
|
|
#else
|
|
|
|
#else
|
|
|
@ -83,7 +90,6 @@ namespace NzbDrone.Common
|
|
|
|
try {
|
|
|
|
try {
|
|
|
|
var netFwMgrType = Type.GetTypeFromProgID ("HNetCfg.FwMgr", false);
|
|
|
|
var netFwMgrType = Type.GetTypeFromProgID ("HNetCfg.FwMgr", false);
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
var mgr = (INetFwMgr)Activator.CreateInstance (netFwMgrType);
|
|
|
|
var mgr = (INetFwMgr)Activator.CreateInstance (netFwMgrType);
|
|
|
|
|
|
|
|
|
|
|
|
if (!mgr.LocalPolicy.CurrentProfile.FirewallEnabled)
|
|
|
|
if (!mgr.LocalPolicy.CurrentProfile.FirewallEnabled)
|
|
|
@ -95,14 +101,20 @@ namespace NzbDrone.Common
|
|
|
|
if (p.Port == _configFileProvider.Port)
|
|
|
|
if (p.Port == _configFileProvider.Port)
|
|
|
|
return true;
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
} catch (Exception ex) {
|
|
|
|
}
|
|
|
|
Logger.WarnException ("Failed to check for open port in firewall", ex);
|
|
|
|
catch (Exception ex) {
|
|
|
|
|
|
|
|
_logger.WarnException ("Failed to check for open port in firewall", ex);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
return false;
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
private bool OpenFirewallPort (int portNumber)
|
|
|
|
public bool IsNzbDroneUrlRegistered()
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
return CheckIfUrlIsRegisteredUrl(_configFileProvider.Port);
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
private void OpenFirewallPort(int portNumber)
|
|
|
|
{
|
|
|
|
{
|
|
|
|
#if __MonoCS__
|
|
|
|
#if __MonoCS__
|
|
|
|
return true;
|
|
|
|
return true;
|
|
|
@ -121,15 +133,14 @@ namespace NzbDrone.Common
|
|
|
|
var ports = mgr.LocalPolicy.CurrentProfile.GloballyOpenPorts;
|
|
|
|
var ports = mgr.LocalPolicy.CurrentProfile.GloballyOpenPorts;
|
|
|
|
|
|
|
|
|
|
|
|
ports.Add (port);
|
|
|
|
ports.Add (port);
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
} catch (Exception ex) {
|
|
|
|
catch (Exception ex) {
|
|
|
|
Logger.WarnException ("Failed to open port in firewall for NzbDrone " + portNumber, ex);
|
|
|
|
_logger.WarnException ("Failed to open port in firewall for NzbDrone " + portNumber, ex);
|
|
|
|
return false;
|
|
|
|
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
private int CloseFirewallPort ()
|
|
|
|
private int CloseFirewallPort()
|
|
|
|
{
|
|
|
|
{
|
|
|
|
|
|
|
|
|
|
|
|
#if __MonoCS__
|
|
|
|
#if __MonoCS__
|
|
|
@ -149,18 +160,21 @@ namespace NzbDrone.Common
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
if (portNumber != _configFileProvider.Port) {
|
|
|
|
if (portNumber != _configFileProvider.Port)
|
|
|
|
|
|
|
|
{
|
|
|
|
ports.Remove (portNumber, NET_FW_IP_PROTOCOL_.NET_FW_IP_PROTOCOL_TCP);
|
|
|
|
ports.Remove (portNumber, NET_FW_IP_PROTOCOL_.NET_FW_IP_PROTOCOL_TCP);
|
|
|
|
return portNumber;
|
|
|
|
return portNumber;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
} catch (Exception ex) {
|
|
|
|
}
|
|
|
|
Logger.WarnException ("Failed to close port in firewall for NzbDrone", ex);
|
|
|
|
catch (Exception ex)
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
_logger.WarnException ("Failed to close port in firewall for NzbDrone", ex);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
return 0;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
private bool IsFirewallEnabled ()
|
|
|
|
private bool IsFirewallEnabled()
|
|
|
|
{
|
|
|
|
{
|
|
|
|
#if __MonoCS__
|
|
|
|
#if __MonoCS__
|
|
|
|
return true;
|
|
|
|
return true;
|
|
|
@ -170,49 +184,70 @@ namespace NzbDrone.Common
|
|
|
|
var netFwMgrType = Type.GetTypeFromProgID ("HNetCfg.FwMgr", false);
|
|
|
|
var netFwMgrType = Type.GetTypeFromProgID ("HNetCfg.FwMgr", false);
|
|
|
|
var mgr = (INetFwMgr)Activator.CreateInstance (netFwMgrType);
|
|
|
|
var mgr = (INetFwMgr)Activator.CreateInstance (netFwMgrType);
|
|
|
|
return mgr.LocalPolicy.CurrentProfile.FirewallEnabled;
|
|
|
|
return mgr.LocalPolicy.CurrentProfile.FirewallEnabled;
|
|
|
|
} catch (Exception ex) {
|
|
|
|
}
|
|
|
|
Logger.WarnException ("Failed to check if the firewall is enabled", ex);
|
|
|
|
catch (Exception ex)
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
_logger.WarnException ("Failed to check if the firewall is enabled", ex);
|
|
|
|
return false;
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
private bool RegisterUrl (int portNumber)
|
|
|
|
private void RegisterUrl(int portNumber)
|
|
|
|
{
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
var arguments = String.Format("http add urlacl http://+:{0}/ user=EVERYONE", portNumber);
|
|
|
|
var startInfo = new ProcessStartInfo ()
|
|
|
|
RunNetsh(arguments);
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
private void UnregisterUrl(int portNumber)
|
|
|
|
{
|
|
|
|
{
|
|
|
|
FileName = "netsh.exe",
|
|
|
|
var arguments = String.Format("http delete urlacl http://+:{0}/", portNumber);
|
|
|
|
Arguments = string.Format("http add urlacl http://*:{0}/ user=EVERYONE", portNumber)
|
|
|
|
RunNetsh(arguments);
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
var process = _processProvider.Start (startInfo);
|
|
|
|
private bool CheckIfUrlIsRegisteredUrl(int portNumber)
|
|
|
|
process.WaitForExit (5000);
|
|
|
|
{
|
|
|
|
return true;
|
|
|
|
var url = String.Format("http://+:{0}/", portNumber);
|
|
|
|
} catch (Exception ex) {
|
|
|
|
var arguments = String.Format("http show urlacl url=\"{0}\"", url);
|
|
|
|
Logger.WarnException ("Error registering URL", ex);
|
|
|
|
var output = RunNetsh(arguments);
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
if(String.IsNullOrWhiteSpace(output))
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
_logger.Error("netsh output is invalid for arguments: {0}", arguments);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
if(!output.Contains(url))
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
_logger.Trace("Url has not already been registered");
|
|
|
|
return false;
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
private bool UnregisterUrl (int portNumber)
|
|
|
|
_logger.Trace("Url has already been registered!");
|
|
|
|
|
|
|
|
return true;
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
private string RunNetsh(string arguments)
|
|
|
|
{
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
try
|
|
|
|
var startInfo = new ProcessStartInfo ()
|
|
|
|
{
|
|
|
|
|
|
|
|
var startInfo = new ProcessStartInfo()
|
|
|
|
{
|
|
|
|
{
|
|
|
|
|
|
|
|
RedirectStandardOutput = true,
|
|
|
|
|
|
|
|
UseShellExecute = false,
|
|
|
|
FileName = "netsh.exe",
|
|
|
|
FileName = "netsh.exe",
|
|
|
|
Arguments = string.Format("http delete urlacl http://*:{0}/", portNumber)
|
|
|
|
Arguments = arguments
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
var process = _processProvider.Start (startInfo);
|
|
|
|
var process = _processProvider.Start(startInfo);
|
|
|
|
process.WaitForExit (5000);
|
|
|
|
process.WaitForExit(5000);
|
|
|
|
return true;
|
|
|
|
return process.StandardOutput.ReadToEnd();
|
|
|
|
} catch (Exception ex) {
|
|
|
|
}
|
|
|
|
Logger.WarnException ("Error registering URL", ex);
|
|
|
|
catch (Exception ex)
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
_logger.WarnException("Error executing netsh with arguments: " + arguments, ex);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
return false;
|
|
|
|
return null;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|