propellor/Property/User.hs

62 lines
1.8 KiB
Haskell
Raw Normal View History

module Property.User where
import System.Posix
2014-03-30 19:31:57 +00:00
import Common
2014-03-30 20:53:31 +00:00
data Eep = YesReallyDeleteHome
2014-03-30 19:53:35 +00:00
sshAccountFor :: UserName -> Property
sshAccountFor user = check (isNothing <$> homedir user) $ cmdProperty "adduser"
[ Param "--disabled-password"
, Param "--gecos", Param ""
, Param user
]
2014-03-30 19:53:35 +00:00
`describe` ("ssh account " ++ user)
2014-03-30 04:17:44 +00:00
{- Removes user home directory!! Use with caution. -}
2014-03-30 20:53:31 +00:00
nuked :: UserName -> Eep -> Property
nuked user _ = check (isJust <$> homedir user) $ cmdProperty "userdel"
2014-03-30 04:17:44 +00:00
[ Param "-r"
, Param user
]
2014-03-30 19:53:35 +00:00
`describe` ("nuked user " ++ user)
2014-03-30 04:17:44 +00:00
2014-03-31 00:18:45 +00:00
{- Only ensures that the user has some password set. It may or may
- not be the password from the PrivData. -}
hasSomePassword :: UserName -> Property
hasSomePassword user = check ((/= HasPassword) <$> getPasswordStatus user) $
hasPassword user
2014-03-30 23:22:10 +00:00
hasPassword :: UserName -> Property
hasPassword user = Property (user ++ " has password") $
2014-03-30 23:10:32 +00:00
withPrivData (Password user) $ \password -> makeChange $
withHandle StdinHandle createProcessSuccess
(proc "chpasswd" []) $ \h -> do
hPutStrLn h $ user ++ ":" ++ password
hClose h
2014-03-30 04:17:44 +00:00
lockedPassword :: UserName -> Property
lockedPassword user = check (not <$> isLockedPassword user) $ cmdProperty "passwd"
2014-03-30 04:17:44 +00:00
[ Param "--lock"
, Param user
]
2014-03-30 19:53:35 +00:00
`describe` ("locked " ++ user ++ " password")
2014-03-30 04:17:44 +00:00
2014-03-31 00:18:45 +00:00
data PasswordStatus = NoPassword | LockedPassword | HasPassword
deriving (Eq)
getPasswordStatus :: UserName -> IO PasswordStatus
getPasswordStatus user = parse . words <$> readProcess "passwd" ["-S", user]
where
2014-03-31 00:18:45 +00:00
parse (_:"L":_) = LockedPassword
parse (_:"NP":_) = NoPassword
parse (_:"P":_) = HasPassword
parse _ = NoPassword
isLockedPassword :: UserName -> IO Bool
isLockedPassword user = (== LockedPassword) <$> getPasswordStatus user
homedir :: UserName -> IO (Maybe FilePath)
homedir user = catchMaybeIO $ homeDirectory <$> getUserEntryForName user