sieve-manage.el (sieve-manage-open-server): Don't quote lambda; Use plist-get rather...
[gnus] / lisp / sieve-manage.el
1 ;;; sieve-manage.el --- Implementation of the managesieve protocol in elisp
2
3 ;; Copyright (C) 2001-2013 Free Software Foundation, Inc.
4
5 ;; Author: Simon Josefsson <simon@josefsson.org>
6 ;;         Albert Krewinkel <tarleb@moltkeplatz.de>
7
8 ;; This file is part of GNU Emacs.
9
10 ;; GNU Emacs is free software: you can redistribute it and/or modify
11 ;; it under the terms of the GNU General Public License as published by
12 ;; the Free Software Foundation, either version 3 of the License, or
13 ;; (at your option) any later version.
14
15 ;; GNU Emacs is distributed in the hope that it will be useful,
16 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
17 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
18 ;; GNU General Public License for more details.
19
20 ;; You should have received a copy of the GNU General Public License
21 ;; along with GNU Emacs.  If not, see <http://www.gnu.org/licenses/>.
22
23 ;;; Commentary:
24
25 ;; This library provides an elisp API for the managesieve network
26 ;; protocol.
27 ;;
28 ;; It uses the SASL library for authentication, which means it
29 ;; supports DIGEST-MD5, CRAM-MD5, SCRAM-MD5, NTLM, PLAIN and LOGIN
30 ;; methods.  STARTTLS is not well tested, but should be easy to get to
31 ;; work if someone wants.
32 ;;
33 ;; The API should be fairly obvious for anyone familiar with the
34 ;; managesieve protocol, interface functions include:
35 ;;
36 ;; `sieve-manage-open'
37 ;; open connection to managesieve server, returning a buffer to be
38 ;; used by all other API functions.
39 ;;
40 ;; `sieve-manage-opened'
41 ;; check if a server is open or not
42 ;;
43 ;; `sieve-manage-close'
44 ;; close a server connection.
45 ;;
46 ;; `sieve-manage-listscripts'
47 ;; `sieve-manage-deletescript'
48 ;; `sieve-manage-getscript'
49 ;; performs managesieve protocol actions
50 ;;
51 ;; and that's it.  Example of a managesieve session in *scratch*:
52 ;;
53 ;; (with-current-buffer (sieve-manage-open "mail.example.com")
54 ;;   (sieve-manage-authenticate)
55 ;;   (sieve-manage-listscripts))
56 ;;
57 ;; => ((active . "main") "vacation")
58 ;;
59 ;; References:
60 ;;
61 ;; draft-martin-managesieve-02.txt,
62 ;; "A Protocol for Remotely Managing Sieve Scripts",
63 ;; by Tim Martin.
64 ;;
65 ;; Release history:
66 ;;
67 ;; 2001-10-31 Committed to Oort Gnus.
68 ;; 2002-07-27 Added DELETESCRIPT.  Suggested by Ned Ludd.
69 ;; 2002-08-03 Use SASL library.
70 ;; 2013-06-05 Enabled STARTTLS support, fixed bit rot.
71
72 ;;; Code:
73
74 ;; For Emacs <22.2 and XEmacs.
75 (eval-and-compile
76   (unless (fboundp 'declare-function) (defmacro declare-function (&rest r))))
77
78 (if (locate-library "password-cache")
79     (require 'password-cache)
80   (require 'password))
81
82 (eval-when-compile
83   (require 'cl)                         ; caddr
84   (require 'sasl)
85   (require 'starttls))
86 (autoload 'sasl-find-mechanism "sasl")
87 (autoload 'auth-source-search "auth-source")
88
89 ;; User customizable variables:
90
91 (defgroup sieve-manage nil
92   "Low-level Managesieve protocol issues."
93   :group 'mail
94   :prefix "sieve-")
95
96 (defcustom sieve-manage-log "*sieve-manage-log*"
97   "Name of buffer for managesieve session trace."
98   :type 'string
99   :group 'sieve-manage)
100
101 (defcustom sieve-manage-server-eol "\r\n"
102   "The EOL string sent from the server."
103   :type 'string
104   :group 'sieve-manage)
105
106 (defcustom sieve-manage-client-eol "\r\n"
107   "The EOL string we send to the server."
108   :type 'string
109   :group 'sieve-manage)
110
111 (defcustom sieve-manage-authenticators '(digest-md5
112                                          cram-md5
113                                          scram-md5
114                                          ntlm
115                                          plain
116                                          login)
117   "Priority of authenticators to consider when authenticating to server."
118   :group 'sieve-manage)
119
120 (defcustom sieve-manage-authenticator-alist
121   '((cram-md5   sieve-manage-cram-md5-p       sieve-manage-cram-md5-auth)
122     (digest-md5 sieve-manage-digest-md5-p     sieve-manage-digest-md5-auth)
123     (scram-md5  sieve-manage-scram-md5-p      sieve-manage-scram-md5-auth)
124     (ntlm       sieve-manage-ntlm-p           sieve-manage-ntlm-auth)
125     (plain      sieve-manage-plain-p          sieve-manage-plain-auth)
126     (login      sieve-manage-login-p          sieve-manage-login-auth))
127   "Definition of authenticators.
128
129 \(NAME CHECK AUTHENTICATE)
130
131 NAME names the authenticator.  CHECK is a function returning non-nil if
132 the server support the authenticator and AUTHENTICATE is a function
133 for doing the actual authentication."
134   :group 'sieve-manage)
135
136 (defcustom sieve-manage-default-port "sieve"
137   "Default port number or service name for managesieve protocol."
138   :type '(choice integer string)
139   :version "24.4"
140   :group 'sieve-manage)
141
142 (defcustom sieve-manage-default-stream 'network
143   "Default stream type to use for `sieve-manage'."
144   :version "24.1"
145   :type 'symbol
146   :group 'sieve-manage)
147
148 ;; Internal variables:
149
150 (defconst sieve-manage-local-variables '(sieve-manage-server
151                                          sieve-manage-port
152                                          sieve-manage-auth
153                                          sieve-manage-stream
154                                          sieve-manage-process
155                                          sieve-manage-client-eol
156                                          sieve-manage-server-eol
157                                          sieve-manage-capability))
158 (defconst sieve-manage-coding-system-for-read 'binary)
159 (defconst sieve-manage-coding-system-for-write 'binary)
160 (defvar sieve-manage-stream nil)
161 (defvar sieve-manage-auth nil)
162 (defvar sieve-manage-server nil)
163 (defvar sieve-manage-port nil)
164 (defvar sieve-manage-state 'closed
165   "Managesieve state.
166 Valid states are `closed', `initial', `nonauth', and `auth'.")
167 (defvar sieve-manage-process nil)
168 (defvar sieve-manage-capability nil)
169
170 ;; Internal utility functions
171 (defun sieve-manage-make-process-buffer ()
172   (with-current-buffer
173       (generate-new-buffer (format " *sieve %s:%s*"
174                                    sieve-manage-server
175                                    sieve-manage-port))
176     (mapc 'make-local-variable sieve-manage-local-variables)
177     (mm-enable-multibyte)
178     (buffer-disable-undo)
179     (current-buffer)))
180
181 (defun sieve-manage-erase (&optional p buffer)
182   (let ((buffer (or buffer (current-buffer))))
183     (and sieve-manage-log
184          (with-current-buffer (get-buffer-create sieve-manage-log)
185            (mm-enable-multibyte)
186            (buffer-disable-undo)
187            (goto-char (point-max))
188            (insert-buffer-substring buffer (with-current-buffer buffer
189                                              (point-min))
190                                     (or p (with-current-buffer buffer
191                                             (point-max)))))))
192   (delete-region (point-min) (or p (point-max))))
193
194 (defun sieve-manage-open-server (server port &optional stream buffer)
195   "Open network connection to SERVER on PORT.
196 Return the buffer associated with the connection."
197   (with-current-buffer buffer
198     (sieve-manage-erase)
199     (setq sieve-manage-state 'initial)
200     (destructuring-bind (proc . props)
201         (open-protocol-stream
202          "SIEVE" buffer server port
203          :type stream
204          :capability-command "CAPABILITY\r\n"
205          :end-of-command "^\\(OK\\|NO\\).*\n"
206          :success "^OK.*\n"
207          :return-list t
208          :starttls-function
209          (lambda (capabilities)
210            (when (string-match "\\bSTARTTLS\\b" capabilities)
211              "STARTTLS\r\n")))
212       (setq sieve-manage-process proc)
213       (setq sieve-manage-capability
214             (sieve-manage-parse-capability (plist-get props :capabilities)))
215       ;; Ignore new capabilities issues after successful STARTTLS
216       (when (and (memq stream '(nil network starttls))
217                  (eq (plist-get props :type) 'tls))
218         (sieve-manage-drop-next-answer))
219       (current-buffer))))
220
221 ;; Authenticators
222 (defun sieve-sasl-auth (buffer mech)
223   "Login to server using the SASL MECH method."
224   (message "sieve: Authenticating using %s..." mech)
225   (with-current-buffer buffer
226     (let* ((auth-info (auth-source-search :host sieve-manage-server
227                                           :port "sieve"
228                                           :max 1
229                                           :create t))
230            (user-name (or (plist-get (nth 0 auth-info) :user) ""))
231            (user-password (or (plist-get (nth 0 auth-info) :secret) ""))
232            (user-password (if (functionp user-password)
233                               (funcall user-password)
234                             user-password))
235            (client (sasl-make-client (sasl-find-mechanism (list mech))
236                                      user-name "sieve" sieve-manage-server))
237            (sasl-read-passphrase
238             ;; We *need* to copy the password, because sasl will modify it
239             ;; somehow.
240             `(lambda (prompt) ,(copy-sequence user-password)))
241            (step (sasl-next-step client nil))
242            (tag (sieve-manage-send
243                  (concat
244                   "AUTHENTICATE \""
245                   mech
246                   "\""
247                   (and (sasl-step-data step)
248                        (concat
249                         " \""
250                         (base64-encode-string
251                          (sasl-step-data step)
252                          'no-line-break)
253                         "\"")))))
254            data rsp)
255       (catch 'done
256         (while t
257           (setq rsp nil)
258           (goto-char (point-min))
259           (while (null (or (progn
260                              (setq rsp (sieve-manage-is-string))
261                              (if (not (and rsp (looking-at
262                                                 sieve-manage-server-eol)))
263                                  (setq rsp nil)
264                                (goto-char (match-end 0))
265                                rsp))
266                            (setq rsp (sieve-manage-is-okno))))
267             (accept-process-output sieve-manage-process 1)
268             (goto-char (point-min)))
269           (sieve-manage-erase)
270           (when (sieve-manage-ok-p rsp)
271             (when (and (cadr rsp)
272                        (string-match "^SASL \"\\([^\"]+\\)\"" (cadr rsp)))
273               (sasl-step-set-data
274                step (base64-decode-string (match-string 1 (cadr rsp)))))
275             (if (and (setq step (sasl-next-step client step))
276                      (setq data (sasl-step-data step)))
277                 ;; We got data for server but it's finished
278                 (error "Server not ready for SASL data: %s" data)
279               ;; The authentication process is finished.
280               (throw 'done t)))
281           (unless (stringp rsp)
282             (error "Server aborted SASL authentication: %s" (caddr rsp)))
283           (sasl-step-set-data step (base64-decode-string rsp))
284           (setq step (sasl-next-step client step))
285           (sieve-manage-send
286            (if (sasl-step-data step)
287                (concat "\""
288                        (base64-encode-string (sasl-step-data step)
289                                              'no-line-break)
290                        "\"")
291              ""))))
292       (message "sieve: Login using %s...done" mech))))
293
294 (defun sieve-manage-cram-md5-p (buffer)
295   (sieve-manage-capability "SASL" "CRAM-MD5" buffer))
296
297 (defun sieve-manage-cram-md5-auth (buffer)
298   "Login to managesieve server using the CRAM-MD5 SASL method."
299   (sieve-sasl-auth buffer "CRAM-MD5"))
300
301 (defun sieve-manage-digest-md5-p (buffer)
302   (sieve-manage-capability "SASL" "DIGEST-MD5" buffer))
303
304 (defun sieve-manage-digest-md5-auth (buffer)
305   "Login to managesieve server using the DIGEST-MD5 SASL method."
306   (sieve-sasl-auth buffer "DIGEST-MD5"))
307
308 (defun sieve-manage-scram-md5-p (buffer)
309   (sieve-manage-capability "SASL" "SCRAM-MD5" buffer))
310
311 (defun sieve-manage-scram-md5-auth (buffer)
312   "Login to managesieve server using the SCRAM-MD5 SASL method."
313   (sieve-sasl-auth buffer "SCRAM-MD5"))
314
315 (defun sieve-manage-ntlm-p (buffer)
316   (sieve-manage-capability "SASL" "NTLM" buffer))
317
318 (defun sieve-manage-ntlm-auth (buffer)
319   "Login to managesieve server using the NTLM SASL method."
320   (sieve-sasl-auth buffer "NTLM"))
321
322 (defun sieve-manage-plain-p (buffer)
323   (sieve-manage-capability "SASL" "PLAIN" buffer))
324
325 (defun sieve-manage-plain-auth (buffer)
326   "Login to managesieve server using the PLAIN SASL method."
327   (sieve-sasl-auth buffer "PLAIN"))
328
329 (defun sieve-manage-login-p (buffer)
330   (sieve-manage-capability "SASL" "LOGIN" buffer))
331
332 (defun sieve-manage-login-auth (buffer)
333   "Login to managesieve server using the LOGIN SASL method."
334   (sieve-sasl-auth buffer "LOGIN"))
335
336 ;; Managesieve API
337
338 (defun sieve-manage-open (server &optional port stream auth buffer)
339   "Open a network connection to a managesieve SERVER (string).
340 Optional argument PORT is port number (integer) on remote server.
341 Optional argument STREAM is any of `sieve-manage-streams' (a symbol).
342 Optional argument AUTH indicates authenticator to use, see
343 `sieve-manage-authenticators' for available authenticators.
344 If nil, chooses the best stream the server is capable of.
345 Optional argument BUFFER is buffer (buffer, or string naming buffer)
346 to work in."
347   (setq sieve-manage-port (or port sieve-manage-default-port))
348   (with-current-buffer (or buffer (sieve-manage-make-process-buffer))
349     (setq sieve-manage-server (or server
350                                   sieve-manage-server)
351           sieve-manage-stream (or stream
352                                   sieve-manage-stream
353                                   sieve-manage-default-stream)
354           sieve-manage-auth   (or auth
355                                   sieve-manage-auth))
356     (message "sieve: Connecting to %s..." sieve-manage-server)
357     (sieve-manage-open-server sieve-manage-server
358                               sieve-manage-port
359                               sieve-manage-stream
360                               (current-buffer))
361     (when (sieve-manage-opened (current-buffer))
362       ;; Choose authenticator
363       (when (and (null sieve-manage-auth)
364                  (not (eq sieve-manage-state 'auth)))
365         (dolist (auth sieve-manage-authenticators)
366           (when (funcall (nth 1 (assq auth sieve-manage-authenticator-alist))
367                        buffer)
368             (setq sieve-manage-auth auth)
369             (return)))
370         (unless sieve-manage-auth
371           (error "Couldn't figure out authenticator for server")))
372       (sieve-manage-erase)
373       (current-buffer))))
374
375 (defun sieve-manage-authenticate (&optional buffer)
376   "Authenticate on server in BUFFER.
377 Return `sieve-manage-state' value."
378   (with-current-buffer (or buffer (current-buffer))
379     (if (eq sieve-manage-state 'nonauth)
380         (when (funcall (nth 2 (assq sieve-manage-auth
381                                     sieve-manage-authenticator-alist))
382                        (current-buffer))
383           (setq sieve-manage-state 'auth))
384       sieve-manage-state)))
385
386 (defun sieve-manage-opened (&optional buffer)
387   "Return non-nil if connection to managesieve server in BUFFER is open.
388 If BUFFER is nil then the current buffer is used."
389   (and (setq buffer (get-buffer (or buffer (current-buffer))))
390        (buffer-live-p buffer)
391        (with-current-buffer buffer
392          (and sieve-manage-process
393               (memq (process-status sieve-manage-process) '(open run))))))
394
395 (defun sieve-manage-close (&optional buffer)
396   "Close connection to managesieve server in BUFFER.
397 If BUFFER is nil, the current buffer is used."
398   (with-current-buffer (or buffer (current-buffer))
399     (when (sieve-manage-opened)
400       (sieve-manage-send "LOGOUT")
401       (sit-for 1))
402     (when (and sieve-manage-process
403                (memq (process-status sieve-manage-process) '(open run)))
404       (delete-process sieve-manage-process))
405     (setq sieve-manage-process nil)
406     (sieve-manage-erase)
407     t))
408
409 (defun sieve-manage-capability (&optional name value buffer)
410   "Check if capability NAME of server BUFFER match VALUE.
411 If it does, return the server value of NAME. If not returns nil.
412 If VALUE is nil, do not check VALUE and return server value.
413 If NAME is nil, return the full server list of capabilities."
414   (with-current-buffer (or buffer (current-buffer))
415     (if (null name)
416         sieve-manage-capability
417       (let ((server-value (cadr (assoc name sieve-manage-capability))))
418         (when (or (null value)
419                   (and server-value
420                        (string-match value server-value)))
421           server-value)))))
422
423 (defun sieve-manage-listscripts (&optional buffer)
424   (with-current-buffer (or buffer (current-buffer))
425     (sieve-manage-send "LISTSCRIPTS")
426     (sieve-manage-parse-listscripts)))
427
428 (defun sieve-manage-havespace (name size &optional buffer)
429   (with-current-buffer (or buffer (current-buffer))
430     (sieve-manage-send (format "HAVESPACE \"%s\" %s" name size))
431     (sieve-manage-parse-okno)))
432
433 (defun sieve-manage-putscript (name content &optional buffer)
434   (with-current-buffer (or buffer (current-buffer))
435     (sieve-manage-send (format "PUTSCRIPT \"%s\" {%d+}%s%s" name
436                                ;; Here we assume that the coding-system will
437                                ;; replace each char with a single byte.
438                                ;; This is always the case if `content' is
439                                ;; a unibyte string.
440                                (length content)
441                                sieve-manage-client-eol content))
442     (sieve-manage-parse-okno)))
443
444 (defun sieve-manage-deletescript (name &optional buffer)
445   (with-current-buffer (or buffer (current-buffer))
446     (sieve-manage-send (format "DELETESCRIPT \"%s\"" name))
447     (sieve-manage-parse-okno)))
448
449 (defun sieve-manage-getscript (name output-buffer &optional buffer)
450   (with-current-buffer (or buffer (current-buffer))
451     (sieve-manage-send (format "GETSCRIPT \"%s\"" name))
452     (let ((script (sieve-manage-parse-string)))
453       (sieve-manage-parse-crlf)
454       (with-current-buffer output-buffer
455         (insert script))
456       (sieve-manage-parse-okno))))
457
458 (defun sieve-manage-setactive (name &optional buffer)
459   (with-current-buffer (or buffer (current-buffer))
460     (sieve-manage-send (format "SETACTIVE \"%s\"" name))
461     (sieve-manage-parse-okno)))
462
463 ;; Protocol parsing routines
464
465 (defun sieve-manage-wait-for-answer ()
466   (let ((pattern "^\\(OK\\|NO\\).*\n")
467         pos)
468     (while (not pos)
469       (setq pos (search-forward-regexp pattern nil t))
470       (goto-char (point-min))
471       (sleep-for 0 50))
472     pos))
473
474 (defun sieve-manage-drop-next-answer ()
475   (sieve-manage-wait-for-answer)
476   (sieve-manage-erase))
477
478 (defun sieve-manage-ok-p (rsp)
479   (string= (downcase (or (car-safe rsp) "")) "ok"))
480
481 (defun sieve-manage-is-okno ()
482   (when (looking-at (concat
483                      "^\\(OK\\|NO\\)\\( (\\([^)]+\\))\\)?\\( \\(.*\\)\\)?"
484                      sieve-manage-server-eol))
485     (let ((status (match-string 1))
486           (resp-code (match-string 3))
487           (response (match-string 5)))
488       (when response
489         (goto-char (match-beginning 5))
490         (setq response (sieve-manage-is-string)))
491       (list status resp-code response))))
492
493 (defun sieve-manage-parse-okno ()
494   (let (rsp)
495     (while (null rsp)
496       (accept-process-output (get-buffer-process (current-buffer)) 1)
497       (goto-char (point-min))
498       (setq rsp (sieve-manage-is-okno)))
499     (sieve-manage-erase)
500     rsp))
501
502 (defun sieve-manage-parse-capability (str)
503   "Parse managesieve capability string `STR'.
504 Set variable `sieve-manage-capability' to "
505   (let ((capas (delq nil
506                      (mapcar #'split-string-and-unquote
507                              (split-string str "\n")))))
508     (when (string= "OK" (caar (last capas)))
509       (setq sieve-manage-state 'nonauth))
510     capas))
511
512 (defun sieve-manage-is-string ()
513   (cond ((looking-at "\"\\([^\"]+\\)\"")
514          (prog1
515              (match-string 1)
516            (goto-char (match-end 0))))
517         ((looking-at (concat "{\\([0-9]+\\+?\\)}" sieve-manage-server-eol))
518          (let ((pos (match-end 0))
519                (len (string-to-number (match-string 1))))
520            (if (< (point-max) (+ pos len))
521                nil
522              (goto-char (+ pos len))
523              (buffer-substring pos (+ pos len)))))))
524
525 (defun sieve-manage-parse-string ()
526   (let (rsp)
527     (while (null rsp)
528       (accept-process-output (get-buffer-process (current-buffer)) 1)
529       (goto-char (point-min))
530       (setq rsp (sieve-manage-is-string)))
531     (sieve-manage-erase (point))
532     rsp))
533
534 (defun sieve-manage-parse-crlf ()
535   (when (looking-at sieve-manage-server-eol)
536     (sieve-manage-erase (match-end 0))))
537
538 (defun sieve-manage-parse-listscripts ()
539   (let (tmp rsp data)
540     (while (null rsp)
541       (while (null (or (setq rsp (sieve-manage-is-okno))
542                        (setq tmp (sieve-manage-is-string))))
543         (accept-process-output (get-buffer-process (current-buffer)) 1)
544         (goto-char (point-min)))
545       (when tmp
546         (while (not (looking-at (concat "\\( ACTIVE\\)?"
547                                         sieve-manage-server-eol)))
548           (accept-process-output (get-buffer-process (current-buffer)) 1)
549           (goto-char (point-min)))
550         (if (match-string 1)
551             (push (cons 'active tmp) data)
552           (push tmp data))
553         (goto-char (match-end 0))
554         (setq tmp nil)))
555     (sieve-manage-erase)
556     (if (sieve-manage-ok-p rsp)
557         data
558       rsp)))
559
560 (defun sieve-manage-send (cmdstr)
561   (setq cmdstr (concat cmdstr sieve-manage-client-eol))
562   (and sieve-manage-log
563        (with-current-buffer (get-buffer-create sieve-manage-log)
564          (mm-enable-multibyte)
565          (buffer-disable-undo)
566          (goto-char (point-max))
567          (insert cmdstr)))
568   (process-send-string sieve-manage-process cmdstr))
569
570 (provide 'sieve-manage)
571
572 ;; sieve-manage.el ends here