Fix slice range panics in the POP3 USER and PASS commands.
[mailpopbox.git] / pop3 / conn.go
1 package pop3
2
3 import (
4 "fmt"
5 "io"
6 "net"
7 "net/textproto"
8 "strings"
9
10 "github.com/uber-go/zap"
11 )
12
13 type state int
14
15 const (
16 stateAuth state = iota
17 stateTxn
18 stateUpdate
19 )
20
21 const (
22 errStateAuth = "not in AUTHORIZATION"
23 errStateTxn = "not in TRANSACTION"
24 errSyntax = "syntax error"
25 errDeletedMsg = "no such message - deleted"
26 )
27
28 type connection struct {
29 po PostOffice
30 mb Mailbox
31
32 tp *textproto.Conn
33 remoteAddr net.Addr
34
35 log zap.Logger
36
37 state
38 line string
39
40 user string
41 }
42
43 func AcceptConnection(netConn net.Conn, po PostOffice, log zap.Logger) {
44 log = log.With(zap.Stringer("client", netConn.RemoteAddr()))
45 conn := connection{
46 po: po,
47 tp: textproto.NewConn(netConn),
48 state: stateAuth,
49 log: log,
50 }
51
52 conn.log.Info("accepted connection")
53 conn.ok(fmt.Sprintf("POP3 (mailpopbox) server %s", po.Name()))
54
55 var err error
56
57 for {
58 conn.line, err = conn.tp.ReadLine()
59 if err != nil {
60 conn.log.Error("ReadLine()", zap.Error(err))
61 conn.tp.Close()
62 return
63 }
64
65 var cmd string
66 if _, err := fmt.Sscanf(conn.line, "%s", &cmd); err != nil {
67 conn.err("invalid command")
68 continue
69 }
70
71 conn.log = log.With(zap.String("command", cmd))
72
73 switch strings.ToUpper(cmd) {
74 case "QUIT":
75 conn.doQUIT()
76 return
77 case "USER":
78 conn.doUSER()
79 case "PASS":
80 conn.doPASS()
81 case "STAT":
82 conn.doSTAT()
83 case "LIST":
84 conn.doLIST()
85 case "RETR":
86 conn.doRETR()
87 case "DELE":
88 conn.doDELE()
89 case "NOOP":
90 conn.ok("")
91 case "RSET":
92 conn.doRSET()
93 case "UIDL":
94 conn.doUIDL()
95 default:
96 conn.log.Error("unknown command")
97 conn.err("unknown command")
98 }
99 }
100 }
101
102 func (conn *connection) ok(msg string) {
103 if len(msg) > 0 {
104 msg = " " + msg
105 }
106 conn.tp.PrintfLine("+OK%s", msg)
107 }
108
109 func (conn *connection) err(msg string) {
110 conn.log.Error("error", zap.String("message", msg))
111 if len(msg) > 0 {
112 msg = " " + msg
113 conn.tp.PrintfLine("-ERR%s", msg)
114 }
115 }
116
117 func (conn *connection) doQUIT() {
118 defer conn.tp.Close()
119
120 if conn.mb != nil {
121 err := conn.mb.Close()
122 if err != nil {
123 conn.err("failed to remove some messages")
124 return
125 }
126 }
127 conn.ok("goodbye")
128 }
129
130 func (conn *connection) doUSER() {
131 if conn.state != stateAuth {
132 conn.err(errStateAuth)
133 return
134 }
135
136 cmd := len("USER ")
137 if len(conn.line) < cmd {
138 conn.err("invalid user")
139 return
140 }
141
142 conn.user = conn.line[cmd:]
143 conn.ok("")
144 }
145
146 func (conn *connection) doPASS() {
147 if conn.state != stateAuth {
148 conn.err(errStateAuth)
149 return
150 }
151
152 if len(conn.user) == 0 {
153 conn.err("no USER")
154 return
155 }
156
157 cmd := len("PASS ")
158 if len(conn.line) < cmd {
159 conn.err("invalid pass")
160 return
161 }
162
163 pass := conn.line[cmd:]
164 if mbox, err := conn.po.OpenMailbox(conn.user, pass); err == nil {
165 conn.log.Info("authenticated", zap.String("user", conn.user))
166 conn.state = stateTxn
167 conn.mb = mbox
168 conn.ok("")
169 } else {
170 conn.log.Error("failed to open mailbox", zap.Error(err))
171 conn.err(err.Error())
172 }
173 }
174
175 func (conn *connection) doSTAT() {
176 if conn.state != stateTxn {
177 conn.err(errStateTxn)
178 return
179 }
180
181 msgs, err := conn.mb.ListMessages()
182 if err != nil {
183 conn.log.Error("failed to list messages", zap.Error(err))
184 conn.err(err.Error())
185 return
186 }
187
188 size := 0
189 num := 0
190 for _, msg := range msgs {
191 if msg.Deleted() {
192 continue
193 }
194 size += msg.Size()
195 num++
196 }
197
198 conn.ok(fmt.Sprintf("%d %d", num, size))
199 }
200
201 func (conn *connection) doLIST() {
202 if conn.state != stateTxn {
203 conn.err(errStateTxn)
204 return
205 }
206
207 msgs, err := conn.mb.ListMessages()
208 if err != nil {
209 conn.log.Error("failed to list messages", zap.Error(err))
210 conn.err(err.Error())
211 return
212 }
213
214 conn.ok("scan listing")
215 for _, msg := range msgs {
216 conn.tp.PrintfLine("%d %d", msg.ID(), msg.Size())
217 }
218 conn.tp.PrintfLine(".")
219 }
220
221 func (conn *connection) doRETR() {
222 if conn.state != stateTxn {
223 conn.err(errStateTxn)
224 return
225 }
226
227 msg := conn.getRequestedMessage()
228 if msg == nil {
229 return
230 }
231
232 if msg.Deleted() {
233 conn.err(errDeletedMsg)
234 return
235 }
236
237 rc, err := conn.mb.Retrieve(msg)
238 if err != nil {
239 conn.log.Error("failed to retrieve messages", zap.Error(err))
240 conn.err(err.Error())
241 return
242 }
243
244 conn.ok(fmt.Sprintf("%d", msg.Size()))
245
246 w := conn.tp.DotWriter()
247 io.Copy(w, rc)
248 w.Close()
249 }
250
251 func (conn *connection) doDELE() {
252 if conn.state != stateTxn {
253 conn.err(errStateTxn)
254 return
255 }
256
257 msg := conn.getRequestedMessage()
258 if msg == nil {
259 return
260 }
261
262 if msg.Deleted() {
263 conn.err(errDeletedMsg)
264 return
265 }
266
267 if err := conn.mb.Delete(msg); err != nil {
268 conn.log.Error("failed to delete message", zap.Error(err))
269 conn.err(err.Error())
270 } else {
271 conn.ok("")
272 }
273 }
274
275 func (conn *connection) doRSET() {
276 if conn.state != stateTxn {
277 conn.err(errStateTxn)
278 return
279 }
280 conn.mb.Reset()
281 conn.ok("")
282 }
283
284 func (conn *connection) doUIDL() {
285 if conn.state != stateTxn {
286 conn.err(errStateTxn)
287 return
288 }
289
290 msgs, err := conn.mb.ListMessages()
291 if err != nil {
292 conn.log.Error("failed to list messages", zap.Error(err))
293 conn.err(err.Error())
294 return
295 }
296
297 conn.ok("unique-id listing")
298 for _, msg := range msgs {
299 if msg.Deleted() {
300 continue
301 }
302 conn.tp.PrintfLine("%d %s", msg.ID(), msg.UniqueID())
303 }
304 conn.tp.PrintfLine(".")
305 }
306
307 func (conn *connection) getRequestedMessage() Message {
308 var cmd string
309 var idx int
310 if _, err := fmt.Sscanf(conn.line, "%s %d", &cmd, &idx); err != nil {
311 conn.err(errSyntax)
312 return nil
313 }
314
315 if idx < 1 {
316 conn.err("invalid message-number")
317 return nil
318 }
319
320 msg := conn.mb.GetMessage(idx)
321 if msg == nil {
322 conn.err("no such message")
323 return nil
324 }
325 return msg
326 }