2014-03-31 03:37:54 +00:00
|
|
|
module Propellor.Property.User where
|
2014-03-30 03:10:52 +00:00
|
|
|
|
|
|
|
import System.Posix
|
|
|
|
|
2014-03-31 03:55:59 +00:00
|
|
|
import Propellor
|
2014-03-30 03:10:52 +00:00
|
|
|
|
2014-03-30 20:53:31 +00:00
|
|
|
data Eep = YesReallyDeleteHome
|
|
|
|
|
2014-04-01 20:58:11 +00:00
|
|
|
accountFor :: UserName -> Property
|
|
|
|
accountFor user = check (isNothing <$> homedir user) $ cmdProperty "adduser"
|
2014-03-31 03:55:59 +00:00
|
|
|
[ "--disabled-password"
|
|
|
|
, "--gecos", ""
|
|
|
|
, user
|
2014-03-30 03:10:52 +00:00
|
|
|
]
|
2014-03-30 19:53:35 +00:00
|
|
|
`describe` ("ssh account " ++ user)
|
2014-03-30 03:10:52 +00:00
|
|
|
|
2014-04-01 20:58:11 +00:00
|
|
|
-- | Removes user home directory!! Use with caution.
|
2014-03-30 20:53:31 +00:00
|
|
|
nuked :: UserName -> Eep -> Property
|
|
|
|
nuked user _ = check (isJust <$> homedir user) $ cmdProperty "userdel"
|
2014-03-31 03:55:59 +00:00
|
|
|
[ "-r"
|
|
|
|
, user
|
2014-03-30 04:17:44 +00:00
|
|
|
]
|
2014-03-30 19:53:35 +00:00
|
|
|
`describe` ("nuked user " ++ user)
|
2014-03-30 04:17:44 +00:00
|
|
|
|
2014-04-01 20:58:11 +00:00
|
|
|
-- | Only ensures that the user has some password set. It may or may
|
|
|
|
-- not be the password from the PrivData.
|
2014-03-31 00:18:45 +00:00
|
|
|
hasSomePassword :: UserName -> Property
|
|
|
|
hasSomePassword user = check ((/= HasPassword) <$> getPasswordStatus user) $
|
|
|
|
hasPassword user
|
|
|
|
|
2014-03-30 23:22:10 +00:00
|
|
|
hasPassword :: UserName -> Property
|
|
|
|
hasPassword user = Property (user ++ " has password") $
|
2014-03-30 23:10:32 +00:00
|
|
|
withPrivData (Password user) $ \password -> makeChange $
|
|
|
|
withHandle StdinHandle createProcessSuccess
|
|
|
|
(proc "chpasswd" []) $ \h -> do
|
|
|
|
hPutStrLn h $ user ++ ":" ++ password
|
|
|
|
hClose h
|
|
|
|
|
2014-03-30 04:17:44 +00:00
|
|
|
lockedPassword :: UserName -> Property
|
2014-03-30 05:57:10 +00:00
|
|
|
lockedPassword user = check (not <$> isLockedPassword user) $ cmdProperty "passwd"
|
2014-03-31 03:55:59 +00:00
|
|
|
[ "--lock"
|
|
|
|
, user
|
2014-03-30 04:17:44 +00:00
|
|
|
]
|
2014-03-30 19:53:35 +00:00
|
|
|
`describe` ("locked " ++ user ++ " password")
|
2014-03-30 04:17:44 +00:00
|
|
|
|
2014-03-31 00:18:45 +00:00
|
|
|
data PasswordStatus = NoPassword | LockedPassword | HasPassword
|
|
|
|
deriving (Eq)
|
|
|
|
|
|
|
|
getPasswordStatus :: UserName -> IO PasswordStatus
|
|
|
|
getPasswordStatus user = parse . words <$> readProcess "passwd" ["-S", user]
|
2014-03-30 05:57:10 +00:00
|
|
|
where
|
2014-03-31 00:18:45 +00:00
|
|
|
parse (_:"L":_) = LockedPassword
|
|
|
|
parse (_:"NP":_) = NoPassword
|
|
|
|
parse (_:"P":_) = HasPassword
|
|
|
|
parse _ = NoPassword
|
|
|
|
|
|
|
|
isLockedPassword :: UserName -> IO Bool
|
|
|
|
isLockedPassword user = (== LockedPassword) <$> getPasswordStatus user
|
2014-03-30 05:57:10 +00:00
|
|
|
|
2014-03-30 03:10:52 +00:00
|
|
|
homedir :: UserName -> IO (Maybe FilePath)
|
|
|
|
homedir user = catchMaybeIO $ homeDirectory <$> getUserEntryForName user
|