| 1 | #!/usr/bin/perl | 
|---|
| 2 |  | 
|---|
| 3 | use strict; | 
|---|
| 4 | use warnings; | 
|---|
| 5 |  | 
|---|
| 6 | use Net::LDAP; | 
|---|
| 7 | use Net::LDAP::Filter; | 
|---|
| 8 |  | 
|---|
| 9 | my $url = $ARGV[0]; | 
|---|
| 10 | my ($proto, $hostname, $path) = $url =~ m|^(.*?)://([^/]*)(.*)| or die "Could not match URL"; | 
|---|
| 11 | my $mesg; | 
|---|
| 12 |  | 
|---|
| 13 | my $vhostName = $hostname; | 
|---|
| 14 |  | 
|---|
| 15 | vhost: | 
|---|
| 16 | # oh my gosh Net::LDAP::Filter SUCKS | 
|---|
| 17 | my $filter = bless({and => | 
|---|
| 18 | [{equalityMatch => {attributeDesc  => 'objectClass', | 
|---|
| 19 | assertionValue => 'scriptsVhost'}}, | 
|---|
| 20 | {or => | 
|---|
| 21 | [{equalityMatch => {attributeDesc  => 'scriptsVhostName', | 
|---|
| 22 | assertionValue => $vhostName}}, | 
|---|
| 23 | {equalityMatch => {attributeDesc  => 'scriptsVhostAlias', | 
|---|
| 24 | assertionValue => $vhostName}}]}]}, | 
|---|
| 25 | 'Net::LDAP::Filter'); | 
|---|
| 26 |  | 
|---|
| 27 | my $ldap = Net::LDAP->new("ldapi://%2fvar%2frun%2fslapd-scripts.socket/"); | 
|---|
| 28 | $mesg = $ldap->bind(); | 
|---|
| 29 | $mesg->code && die $mesg->error; | 
|---|
| 30 |  | 
|---|
| 31 | $mesg = $ldap->search(base => "ou=VirtualHosts,dc=scripts,dc=mit,dc=edu", | 
|---|
| 32 | filter => $filter); | 
|---|
| 33 | $mesg->code && die $mesg->error; | 
|---|
| 34 |  | 
|---|
| 35 | my $vhostEntry = $mesg->pop_entry; | 
|---|
| 36 | if (!defined $vhostEntry) { | 
|---|
| 37 | $vhostName ne '*' or die 'No vhost for *'; | 
|---|
| 38 | $vhostName =~ s/^(?:\*\.)?[^.]*/*/;  # Try next wildcard | 
|---|
| 39 | goto vhost; | 
|---|
| 40 | } | 
|---|
| 41 |  | 
|---|
| 42 | my $vhostDirectory = $vhostEntry->get_value('scriptsVhostDirectory'); | 
|---|
| 43 |  | 
|---|
| 44 | $mesg = $ldap->search(base => $vhostEntry->get_value('scriptsVhostAccount'), | 
|---|
| 45 | scope => 'base', filter => 'objectClass=posixAccount'); | 
|---|
| 46 | $mesg->code && die $mesg->error; | 
|---|
| 47 |  | 
|---|
| 48 | my $userEntry = $mesg->pop_entry; | 
|---|
| 49 | my ($homeDirectory, $uidNumber, $gidNumber) = | 
|---|
| 50 | map { $userEntry->get_value($_) } qw(homeDirectory uidNumber gidNumber); | 
|---|
| 51 | (my $scriptsdir = $homeDirectory) =~ s{(?:/Scripts)?$}{/Scripts}; | 
|---|
| 52 |  | 
|---|
| 53 | if ($proto eq 'svn') { | 
|---|
| 54 | chdir '/usr/libexec/scripts-trusted'; | 
|---|
| 55 | exec('/usr/sbin/suexec', $uidNumber, $gidNumber, '/usr/libexec/scripts-trusted/svn', "$scriptsdir/svn/$vhostDirectory"); | 
|---|
| 56 | } elsif ($proto eq 'git') { | 
|---|
| 57 | if ($vhostEntry->get_value('scriptsVhostName') eq 'notfound.example.com') { | 
|---|
| 58 | # git-daemon doesn’t report useful errors yet | 
|---|
| 59 | my $msg = "ERR No such host $hostname\n"; | 
|---|
| 60 | printf '%04x%s', length($msg) + 4, $msg; | 
|---|
| 61 | exit; | 
|---|
| 62 | } | 
|---|
| 63 | chdir '/usr/libexec/scripts-trusted'; | 
|---|
| 64 | exec('/usr/sbin/suexec', $uidNumber, $gidNumber, '/usr/libexec/scripts-trusted/git', "$scriptsdir/git/$vhostDirectory"); | 
|---|
| 65 | } elsif ($proto eq 'http') { | 
|---|
| 66 | print "suexec $uidNumber $gidNumber $scriptsdir/web/$vhostDirectory/$path\n"; | 
|---|
| 67 | } else { | 
|---|
| 68 | die "Unknown protocol\n"; | 
|---|
| 69 | } | 
|---|