Document reserved keys
[emacs.git] / lisp / net / sieve-manage.el
blobe6a1e8401d2a254983004106e833966ff9687440
1 ;;; sieve-manage.el --- Implementation of the managesieve protocol in elisp
3 ;; Copyright (C) 2001-2018 Free Software Foundation, Inc.
5 ;; Author: Simon Josefsson <simon@josefsson.org>
6 ;; Albert Krewinkel <tarleb@moltkeplatz.de>
8 ;; This file is part of GNU Emacs.
10 ;; GNU Emacs is free software: you can redistribute it and/or modify
11 ;; it under the terms of the GNU General Public License as published by
12 ;; the Free Software Foundation, either version 3 of the License, or
13 ;; (at your option) any later version.
15 ;; GNU Emacs is distributed in the hope that it will be useful,
16 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
17 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 ;; GNU General Public License for more details.
20 ;; You should have received a copy of the GNU General Public License
21 ;; along with GNU Emacs. If not, see <https://www.gnu.org/licenses/>.
23 ;;; Commentary:
25 ;; This library provides an elisp API for the managesieve network
26 ;; protocol.
28 ;; It uses the SASL library for authentication, which means it
29 ;; supports DIGEST-MD5, CRAM-MD5, SCRAM-MD5, NTLM, PLAIN and LOGIN
30 ;; methods. STARTTLS is not well tested, but should be easy to get to
31 ;; work if someone wants.
33 ;; The API should be fairly obvious for anyone familiar with the
34 ;; managesieve protocol, interface functions include:
36 ;; `sieve-manage-open'
37 ;; open connection to managesieve server, returning a buffer to be
38 ;; used by all other API functions.
40 ;; `sieve-manage-opened'
41 ;; check if a server is open or not
43 ;; `sieve-manage-close'
44 ;; close a server connection.
46 ;; `sieve-manage-listscripts'
47 ;; `sieve-manage-deletescript'
48 ;; `sieve-manage-getscript'
49 ;; performs managesieve protocol actions
51 ;; and that's it. Example of a managesieve session in *scratch*:
53 ;; (with-current-buffer (sieve-manage-open "mail.example.com")
54 ;; (sieve-manage-authenticate)
55 ;; (sieve-manage-listscripts))
57 ;; => ((active . "main") "vacation")
59 ;; References:
61 ;; draft-martin-managesieve-02.txt,
62 ;; "A Protocol for Remotely Managing Sieve Scripts",
63 ;; by Tim Martin.
65 ;; Release history:
67 ;; 2001-10-31 Committed to Oort Gnus.
68 ;; 2002-07-27 Added DELETESCRIPT. Suggested by Ned Ludd.
69 ;; 2002-08-03 Use SASL library.
70 ;; 2013-06-05 Enabled STARTTLS support, fixed bit rot.
72 ;;; Code:
74 (if (locate-library "password-cache")
75 (require 'password-cache)
76 (require 'password))
78 (eval-when-compile (require 'cl))
79 (require 'sasl)
80 (require 'starttls)
81 (autoload 'sasl-find-mechanism "sasl")
82 (autoload 'auth-source-search "auth-source")
84 ;; User customizable variables:
86 (defgroup sieve-manage nil
87 "Low-level Managesieve protocol issues."
88 :group 'mail
89 :prefix "sieve-")
91 (defcustom sieve-manage-log "*sieve-manage-log*"
92 "Name of buffer for managesieve session trace."
93 :type 'string
94 :group 'sieve-manage)
96 (defcustom sieve-manage-server-eol "\r\n"
97 "The EOL string sent from the server."
98 :type 'string
99 :group 'sieve-manage)
101 (defcustom sieve-manage-client-eol "\r\n"
102 "The EOL string we send to the server."
103 :type 'string
104 :group 'sieve-manage)
106 (defcustom sieve-manage-authenticators '(digest-md5
107 cram-md5
108 scram-md5
109 ntlm
110 plain
111 login)
112 "Priority of authenticators to consider when authenticating to server."
113 ;; FIXME Improve this. It's not `set'.
114 ;; It's like (repeat (choice (const ...))), where each choice can
115 ;; only appear once.
116 :type '(repeat symbol)
117 :group 'sieve-manage)
119 (defcustom sieve-manage-authenticator-alist
120 '((cram-md5 sieve-manage-cram-md5-p sieve-manage-cram-md5-auth)
121 (digest-md5 sieve-manage-digest-md5-p sieve-manage-digest-md5-auth)
122 (scram-md5 sieve-manage-scram-md5-p sieve-manage-scram-md5-auth)
123 (ntlm sieve-manage-ntlm-p sieve-manage-ntlm-auth)
124 (plain sieve-manage-plain-p sieve-manage-plain-auth)
125 (login sieve-manage-login-p sieve-manage-login-auth))
126 "Definition of authenticators.
128 \(NAME CHECK AUTHENTICATE)
130 NAME names the authenticator. CHECK is a function returning non-nil if
131 the server support the authenticator and AUTHENTICATE is a function
132 for doing the actual authentication."
133 :type '(repeat (list (symbol :tag "Name") (function :tag "Check function")
134 (function :tag "Authentication function")))
135 :group 'sieve-manage)
137 (defcustom sieve-manage-default-port "sieve"
138 "Default port number or service name for managesieve protocol."
139 :type '(choice integer string)
140 :version "24.4"
141 :group 'sieve-manage)
143 (defcustom sieve-manage-default-stream 'network
144 "Default stream type to use for `sieve-manage'."
145 :version "24.1"
146 :type 'symbol
147 :group 'sieve-manage)
149 (defcustom sieve-manage-ignore-starttls nil
150 "Ignore STARTTLS even if STARTTLS capability is provided."
151 :version "26.1"
152 :type 'boolean
153 :group 'sieve-manage)
155 ;; Internal variables:
157 (defconst sieve-manage-local-variables '(sieve-manage-server
158 sieve-manage-port
159 sieve-manage-auth
160 sieve-manage-stream
161 sieve-manage-process
162 sieve-manage-client-eol
163 sieve-manage-server-eol
164 sieve-manage-capability))
165 (defconst sieve-manage-coding-system-for-read 'binary)
166 (defconst sieve-manage-coding-system-for-write 'binary)
167 (defvar sieve-manage-stream nil)
168 (defvar sieve-manage-auth nil)
169 (defvar sieve-manage-server nil)
170 (defvar sieve-manage-port nil)
171 (defvar sieve-manage-state 'closed
172 "Managesieve state.
173 Valid states are `closed', `initial', `nonauth', and `auth'.")
174 (defvar sieve-manage-process nil)
175 (defvar sieve-manage-capability nil)
177 ;; Internal utility functions
178 (autoload 'mm-enable-multibyte "mm-util")
180 (defun sieve-manage-make-process-buffer ()
181 (with-current-buffer
182 (generate-new-buffer (format " *sieve %s:%s*"
183 sieve-manage-server
184 sieve-manage-port))
185 (mapc 'make-local-variable sieve-manage-local-variables)
186 (mm-enable-multibyte)
187 (buffer-disable-undo)
188 (current-buffer)))
190 (defun sieve-manage-erase (&optional p buffer)
191 (let ((buffer (or buffer (current-buffer))))
192 (and sieve-manage-log
193 (with-current-buffer (get-buffer-create sieve-manage-log)
194 (mm-enable-multibyte)
195 (buffer-disable-undo)
196 (goto-char (point-max))
197 (insert-buffer-substring buffer (with-current-buffer buffer
198 (point-min))
199 (or p (with-current-buffer buffer
200 (point-max)))))))
201 (delete-region (point-min) (or p (point-max))))
203 (defun sieve-manage-open-server (server port &optional stream buffer)
204 "Open network connection to SERVER on PORT.
205 Return the buffer associated with the connection."
206 (with-current-buffer buffer
207 (sieve-manage-erase)
208 (setq sieve-manage-state 'initial)
209 (destructuring-bind (proc . props)
210 (open-network-stream
211 "SIEVE" buffer server port
212 :type stream
213 :capability-command "CAPABILITY\r\n"
214 :end-of-command "^\\(OK\\|NO\\).*\n"
215 :success "^OK.*\n"
216 :return-list t
217 :starttls-function
218 (lambda (capabilities)
219 (when (and (not sieve-manage-ignore-starttls)
220 (string-match "\\bSTARTTLS\\b" capabilities))
221 "STARTTLS\r\n")))
222 (setq sieve-manage-process proc)
223 (setq sieve-manage-capability
224 (sieve-manage-parse-capability (plist-get props :capabilities)))
225 ;; Ignore new capabilities issues after successful STARTTLS
226 (when (or sieve-manage-ignore-starttls
227 (and (memq stream '(nil network starttls))
228 (eq (plist-get props :type) 'tls)))
229 (sieve-manage-drop-next-answer))
230 (current-buffer))))
232 ;; Authenticators
233 (defun sieve-sasl-auth (buffer mech)
234 "Login to server using the SASL MECH method."
235 (message "sieve: Authenticating using %s..." mech)
236 (with-current-buffer buffer
237 (let* ((auth-info (auth-source-search :host sieve-manage-server
238 :port "sieve"
239 :max 1
240 :create t))
241 (user-name (or (plist-get (nth 0 auth-info) :user) ""))
242 (user-password (or (plist-get (nth 0 auth-info) :secret) ""))
243 (user-password (if (functionp user-password)
244 (funcall user-password)
245 user-password))
246 (client (sasl-make-client (sasl-find-mechanism (list mech))
247 user-name "sieve" sieve-manage-server))
248 (sasl-read-passphrase
249 ;; We *need* to copy the password, because sasl will modify it
250 ;; somehow.
251 `(lambda (prompt) ,(copy-sequence user-password)))
252 (step (sasl-next-step client nil))
253 (tag (sieve-manage-send
254 (concat
255 "AUTHENTICATE \""
256 mech
257 "\""
258 (and (sasl-step-data step)
259 (concat
260 " \""
261 (base64-encode-string
262 (sasl-step-data step)
263 'no-line-break)
264 "\"")))))
265 data rsp)
266 (catch 'done
267 (while t
268 (setq rsp nil)
269 (goto-char (point-min))
270 (while (null (or (progn
271 (setq rsp (sieve-manage-is-string))
272 (if (not (and rsp (looking-at
273 sieve-manage-server-eol)))
274 (setq rsp nil)
275 (goto-char (match-end 0))
276 rsp))
277 (setq rsp (sieve-manage-is-okno))))
278 (accept-process-output sieve-manage-process 1)
279 (goto-char (point-min)))
280 (sieve-manage-erase)
281 (when (sieve-manage-ok-p rsp)
282 (when (and (cadr rsp)
283 (string-match "^SASL \"\\([^\"]+\\)\"" (cadr rsp)))
284 (sasl-step-set-data
285 step (base64-decode-string (match-string 1 (cadr rsp)))))
286 (if (and (setq step (sasl-next-step client step))
287 (setq data (sasl-step-data step)))
288 ;; We got data for server but it's finished
289 (error "Server not ready for SASL data: %s" data)
290 ;; The authentication process is finished.
291 (throw 'done t)))
292 (unless (stringp rsp)
293 (error "Server aborted SASL authentication: %s" (caddr rsp)))
294 (sasl-step-set-data step (base64-decode-string rsp))
295 (setq step (sasl-next-step client step))
296 (sieve-manage-send
297 (if (sasl-step-data step)
298 (concat "\""
299 (base64-encode-string (sasl-step-data step)
300 'no-line-break)
301 "\"")
302 ""))))
303 (message "sieve: Login using %s...done" mech))))
305 (defun sieve-manage-cram-md5-p (buffer)
306 (sieve-manage-capability "SASL" "CRAM-MD5" buffer))
308 (defun sieve-manage-cram-md5-auth (buffer)
309 "Login to managesieve server using the CRAM-MD5 SASL method."
310 (sieve-sasl-auth buffer "CRAM-MD5"))
312 (defun sieve-manage-digest-md5-p (buffer)
313 (sieve-manage-capability "SASL" "DIGEST-MD5" buffer))
315 (defun sieve-manage-digest-md5-auth (buffer)
316 "Login to managesieve server using the DIGEST-MD5 SASL method."
317 (sieve-sasl-auth buffer "DIGEST-MD5"))
319 (defun sieve-manage-scram-md5-p (buffer)
320 (sieve-manage-capability "SASL" "SCRAM-MD5" buffer))
322 (defun sieve-manage-scram-md5-auth (buffer)
323 "Login to managesieve server using the SCRAM-MD5 SASL method."
324 (sieve-sasl-auth buffer "SCRAM-MD5"))
326 (defun sieve-manage-ntlm-p (buffer)
327 (sieve-manage-capability "SASL" "NTLM" buffer))
329 (defun sieve-manage-ntlm-auth (buffer)
330 "Login to managesieve server using the NTLM SASL method."
331 (sieve-sasl-auth buffer "NTLM"))
333 (defun sieve-manage-plain-p (buffer)
334 (sieve-manage-capability "SASL" "PLAIN" buffer))
336 (defun sieve-manage-plain-auth (buffer)
337 "Login to managesieve server using the PLAIN SASL method."
338 (sieve-sasl-auth buffer "PLAIN"))
340 (defun sieve-manage-login-p (buffer)
341 (sieve-manage-capability "SASL" "LOGIN" buffer))
343 (defun sieve-manage-login-auth (buffer)
344 "Login to managesieve server using the LOGIN SASL method."
345 (sieve-sasl-auth buffer "LOGIN"))
347 ;; Managesieve API
349 (defun sieve-manage-open (server &optional port stream auth buffer)
350 "Open a network connection to a managesieve SERVER (string).
351 Optional argument PORT is port number (integer) on remote server.
352 Optional argument STREAM is any of `sieve-manage-streams' (a symbol).
353 Optional argument AUTH indicates authenticator to use, see
354 `sieve-manage-authenticators' for available authenticators.
355 If nil, chooses the best stream the server is capable of.
356 Optional argument BUFFER is buffer (buffer, or string naming buffer)
357 to work in."
358 (setq sieve-manage-port (or port sieve-manage-default-port))
359 (with-current-buffer (or buffer (sieve-manage-make-process-buffer))
360 (setq sieve-manage-server (or server
361 sieve-manage-server)
362 sieve-manage-stream (or stream
363 sieve-manage-stream
364 sieve-manage-default-stream)
365 sieve-manage-auth (or auth
366 sieve-manage-auth))
367 (message "sieve: Connecting to %s..." sieve-manage-server)
368 (sieve-manage-open-server sieve-manage-server
369 sieve-manage-port
370 sieve-manage-stream
371 (current-buffer))
372 (when (sieve-manage-opened (current-buffer))
373 ;; Choose authenticator
374 (when (and (null sieve-manage-auth)
375 (not (eq sieve-manage-state 'auth)))
376 (dolist (auth sieve-manage-authenticators)
377 (when (funcall (nth 1 (assq auth sieve-manage-authenticator-alist))
378 buffer)
379 (setq sieve-manage-auth auth)
380 (return)))
381 (unless sieve-manage-auth
382 (error "Couldn't figure out authenticator for server")))
383 (sieve-manage-erase)
384 (current-buffer))))
386 (defun sieve-manage-authenticate (&optional buffer)
387 "Authenticate on server in BUFFER.
388 Return `sieve-manage-state' value."
389 (with-current-buffer (or buffer (current-buffer))
390 (if (eq sieve-manage-state 'nonauth)
391 (when (funcall (nth 2 (assq sieve-manage-auth
392 sieve-manage-authenticator-alist))
393 (current-buffer))
394 (setq sieve-manage-state 'auth))
395 sieve-manage-state)))
397 (defun sieve-manage-opened (&optional buffer)
398 "Return non-nil if connection to managesieve server in BUFFER is open.
399 If BUFFER is nil then the current buffer is used."
400 (and (setq buffer (get-buffer (or buffer (current-buffer))))
401 (buffer-live-p buffer)
402 (with-current-buffer buffer
403 (and sieve-manage-process
404 (memq (process-status sieve-manage-process) '(open run))))))
406 (defun sieve-manage-close (&optional buffer)
407 "Close connection to managesieve server in BUFFER.
408 If BUFFER is nil, the current buffer is used."
409 (with-current-buffer (or buffer (current-buffer))
410 (when (sieve-manage-opened)
411 (sieve-manage-send "LOGOUT")
412 (sit-for 1))
413 (when (and sieve-manage-process
414 (memq (process-status sieve-manage-process) '(open run)))
415 (delete-process sieve-manage-process))
416 (setq sieve-manage-process nil)
417 (sieve-manage-erase)
420 (defun sieve-manage-capability (&optional name value buffer)
421 "Check if capability NAME of server BUFFER match VALUE.
422 If it does, return the server value of NAME. If not returns nil.
423 If VALUE is nil, do not check VALUE and return server value.
424 If NAME is nil, return the full server list of capabilities."
425 (with-current-buffer (or buffer (current-buffer))
426 (if (null name)
427 sieve-manage-capability
428 (let ((server-value (cadr (assoc name sieve-manage-capability))))
429 (when (or (null value)
430 (and server-value
431 (string-match value server-value)))
432 server-value)))))
434 (defun sieve-manage-listscripts (&optional buffer)
435 (with-current-buffer (or buffer (current-buffer))
436 (sieve-manage-send "LISTSCRIPTS")
437 (sieve-manage-parse-listscripts)))
439 (defun sieve-manage-havespace (name size &optional buffer)
440 (with-current-buffer (or buffer (current-buffer))
441 (sieve-manage-send (format "HAVESPACE \"%s\" %s" name size))
442 (sieve-manage-parse-okno)))
444 (defun sieve-manage-putscript (name content &optional buffer)
445 (with-current-buffer (or buffer (current-buffer))
446 (sieve-manage-send (format "PUTSCRIPT \"%s\" {%d+}%s%s" name
447 ;; Here we assume that the coding-system will
448 ;; replace each char with a single byte.
449 ;; This is always the case if `content' is
450 ;; a unibyte string.
451 (length content)
452 sieve-manage-client-eol content))
453 (sieve-manage-parse-okno)))
455 (defun sieve-manage-deletescript (name &optional buffer)
456 (with-current-buffer (or buffer (current-buffer))
457 (sieve-manage-send (format "DELETESCRIPT \"%s\"" name))
458 (sieve-manage-parse-okno)))
460 (defun sieve-manage-getscript (name output-buffer &optional buffer)
461 (with-current-buffer (or buffer (current-buffer))
462 (sieve-manage-send (format "GETSCRIPT \"%s\"" name))
463 (let ((script (sieve-manage-parse-string)))
464 (sieve-manage-parse-crlf)
465 (with-current-buffer output-buffer
466 (insert script))
467 (sieve-manage-parse-okno))))
469 (defun sieve-manage-setactive (name &optional buffer)
470 (with-current-buffer (or buffer (current-buffer))
471 (sieve-manage-send (format "SETACTIVE \"%s\"" name))
472 (sieve-manage-parse-okno)))
474 ;; Protocol parsing routines
476 (defun sieve-manage-wait-for-answer ()
477 (let ((pattern "^\\(OK\\|NO\\).*\n")
478 pos)
479 (while (not pos)
480 (setq pos (search-forward-regexp pattern nil t))
481 (goto-char (point-min))
482 (sleep-for 0 50))
483 pos))
485 (defun sieve-manage-drop-next-answer ()
486 (sieve-manage-wait-for-answer)
487 (sieve-manage-erase))
489 (defun sieve-manage-ok-p (rsp)
490 (string= (downcase (or (car-safe rsp) "")) "ok"))
492 (defun sieve-manage-is-okno ()
493 (when (looking-at (concat
494 "^\\(OK\\|NO\\)\\( (\\([^)]+\\))\\)?\\( \\(.*\\)\\)?"
495 sieve-manage-server-eol))
496 (let ((status (match-string 1))
497 (resp-code (match-string 3))
498 (response (match-string 5)))
499 (when response
500 (goto-char (match-beginning 5))
501 (setq response (sieve-manage-is-string)))
502 (list status resp-code response))))
504 (defun sieve-manage-parse-okno ()
505 (let (rsp)
506 (while (null rsp)
507 (accept-process-output (get-buffer-process (current-buffer)) 1)
508 (goto-char (point-min))
509 (setq rsp (sieve-manage-is-okno)))
510 (sieve-manage-erase)
511 rsp))
513 (defun sieve-manage-parse-capability (str)
514 "Parse managesieve capability string `STR'.
515 Set variable `sieve-manage-capability' to "
516 (let ((capas (delq nil
517 (mapcar #'split-string-and-unquote
518 (split-string str "\n")))))
519 (when (string= "OK" (caar (last capas)))
520 (setq sieve-manage-state 'nonauth))
521 capas))
523 (defun sieve-manage-is-string ()
524 (cond ((looking-at "\"\\([^\"]+\\)\"")
525 (prog1
526 (match-string 1)
527 (goto-char (match-end 0))))
528 ((looking-at (concat "{\\([0-9]+\\+?\\)}" sieve-manage-server-eol))
529 (let ((pos (match-end 0))
530 (len (string-to-number (match-string 1))))
531 (if (< (point-max) (+ pos len))
533 (goto-char (+ pos len))
534 (buffer-substring pos (+ pos len)))))))
536 (defun sieve-manage-parse-string ()
537 (let (rsp)
538 (while (null rsp)
539 (accept-process-output (get-buffer-process (current-buffer)) 1)
540 (goto-char (point-min))
541 (setq rsp (sieve-manage-is-string)))
542 (sieve-manage-erase (point))
543 rsp))
545 (defun sieve-manage-parse-crlf ()
546 (when (looking-at sieve-manage-server-eol)
547 (sieve-manage-erase (match-end 0))))
549 (defun sieve-manage-parse-listscripts ()
550 (let (tmp rsp data)
551 (while (null rsp)
552 (while (null (or (setq rsp (sieve-manage-is-okno))
553 (setq tmp (sieve-manage-is-string))))
554 (accept-process-output (get-buffer-process (current-buffer)) 1)
555 (goto-char (point-min)))
556 (when tmp
557 (while (not (looking-at (concat "\\( ACTIVE\\)?"
558 sieve-manage-server-eol)))
559 (accept-process-output (get-buffer-process (current-buffer)) 1)
560 (goto-char (point-min)))
561 (if (match-string 1)
562 (push (cons 'active tmp) data)
563 (push tmp data))
564 (goto-char (match-end 0))
565 (setq tmp nil)))
566 (sieve-manage-erase)
567 (if (sieve-manage-ok-p rsp)
568 data
569 rsp)))
571 (defun sieve-manage-send (cmdstr)
572 (setq cmdstr (concat cmdstr sieve-manage-client-eol))
573 (and sieve-manage-log
574 (with-current-buffer (get-buffer-create sieve-manage-log)
575 (mm-enable-multibyte)
576 (buffer-disable-undo)
577 (goto-char (point-max))
578 (insert cmdstr)))
579 (process-send-string sieve-manage-process cmdstr))
581 (provide 'sieve-manage)
583 ;; sieve-manage.el ends here