/[winpt]/trunk/Src/wptPassphraseCB.cpp
ViewVC logotype

Annotation of /trunk/Src/wptPassphraseCB.cpp

Parent Directory Parent Directory | Revision Log Revision Log


Revision 271 - (hide annotations)
Sun Nov 5 08:57:45 2006 UTC (18 years, 3 months ago) by twoaday
File size: 14294 byte(s)


1 werner 36 /* wptPassphraseCB.cpp - GPGME Passphrase Callback
2 twoaday 255 * Copyright (C) 2001, 2002-2006 Timo Schulz
3 werner 36 * Copyright (C) 2005 g10 Code GmbH
4     *
5     * This file is part of WinPT.
6     *
7     * WinPT is free software; you can redistribute it and/or
8     * modify it under the terms of the GNU General Public License
9     * as published by the Free Software Foundation; either version 2
10     * of the License, or (at your option) any later version.
11     *
12     * WinPT is distributed in the hope that it will be useful,
13     * but WITHOUT ANY WARRANTY; without even the implied warranty of
14     * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15     * General Public License for more details.
16     *
17     * You should have received a copy of the GNU General Public License
18     * along with WinPT; if not, write to the Free Software Foundation,
19     * Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
20     */
21    
22     #ifdef HAVE_CONFIG_H
23     #include <config.h>
24     #endif
25    
26     #include <windows.h>
27     #include <ctype.h>
28    
29 werner 47 #include "resource.h"
30 werner 36 #include "wptNLS.h"
31     #include "wptW32API.h"
32     #include "wptVersion.h"
33     #include "wptGPG.h"
34     #include "wptCommonCtl.h"
35     #include "wptContext.h"
36     #include "wptDlgs.h"
37     #include "wptErrors.h"
38     #include "wptTypes.h"
39 werner 48 #include "wptKeylist.h"
40 werner 36 #include "wptAgent.h"
41     #include "wptRegistry.h"
42 twoaday 205 #include "wptUTF8.h"
43 werner 36
44    
45 twoaday 255 /* Return the control ID dependent on the mode (sign or decrypt). */
46 twoaday 181 #define item_ctrl_id(cmd) \
47 werner 36 ((cmd) == GPG_CMD_DECRYPT? IDC_DECRYPT_PWD : IDC_DECRYPT_SIGN_PWD)
48    
49     #define item_ctrl_id2(cmd) \
50     ((cmd) == GPG_CMD_DECRYPT? IDC_DECRYPT_HIDE : IDC_DECRYPT_SIGN_HIDE)
51    
52 twoaday 255 const char* get_symkey_algo (int algo);
53 twoaday 204 void ListBox_AddString_utf8 (HWND lb, const char *txt);
54    
55 twoaday 255
56 werner 36 /* Overwrite passphrase and free memory. */
57     static void
58     burn_passphrase (char **pwd)
59     {
60     char *pass = *pwd;
61 twoaday 271
62 werner 36 wipememory (pass, strlen (pass));
63     delete []pass;
64     *pwd = NULL;
65     }
66    
67    
68     /* Dialog procedure for the passphrase callback. */
69     static BOOL CALLBACK
70     passphrase_callback_proc (HWND dlg, UINT msg, WPARAM wparam, LPARAM lparam)
71     {
72 twoaday 77 static passphrase_cb_s *c;
73     gpgme_decrypt_result_t res=NULL;
74     gpgme_sign_result_t res_sig=NULL;
75 twoaday 69 gpgme_recipient_t recip=NULL, r;
76 twoaday 217 winpt_key_s key;
77 twoaday 69 void *item;
78 werner 36 const char *id;
79     char *info;
80     int n;
81    
82     switch (msg) {
83 twoaday 181 case WM_ACTIVATE:
84     safe_edit_control_init (dlg, item_ctrl_id (c->gpg_cmd));
85     break;
86    
87     case WM_DESTROY:
88     safe_edit_control_free (dlg, item_ctrl_id (c->gpg_cmd));
89     break;
90    
91 werner 36 case WM_INITDIALOG:
92     c = (passphrase_cb_s *)lparam;
93     if (!c)
94     BUG (0);
95 twoaday 105 SetDlgItemText (dlg, IDCANCEL, _("&Cancel"));
96 werner 36 SetWindowText (dlg, c->title);
97     if (c->gpg_cmd == GPG_CMD_DECRYPT) {
98 twoaday 214 SetDlgItemText (dlg, IDC_DECRYPT_HIDE, _("&Hide Typing"));
99 werner 36 SetDlgItemText (dlg, IDC_DECRYPT_LISTINF,
100     _("Encrypted with the following public key(s)"));
101     CheckDlgButton (dlg, IDC_DECRYPT_HIDE, BST_CHECKED);
102     }
103 twoaday 95 else if (c->gpg_cmd == GPG_CMD_SIGN) {
104     SetDlgItemText (dlg, IDC_DECRYPT_SIGN_HIDE, _("&Hide Typing"));
105 werner 36 CheckDlgButton (dlg, IDC_DECRYPT_SIGN_HIDE, BST_CHECKED);
106 twoaday 95 }
107 twoaday 179 /* Because it depends on the order the keys are stored in the
108     keyring whether res->recipients is complete or not, we also
109     support that the recipients were externally extracted and then
110     we use this list. */
111 werner 36 if (c->recipients)
112     recip = c->recipients; /* recipients were already extracted. */
113     else {
114     res = gpgme_op_decrypt_result (c->gpg);
115     if (res && res->recipients)
116     recip = res->recipients;
117     }
118     if (recip != NULL && c->gpg_cmd == GPG_CMD_DECRYPT) {
119 twoaday 179 for (r = recip; r; r = r->next) {
120 twoaday 217 memset (&key, 0, sizeof (key));
121     if (!winpt_get_pubkey (r->keyid, &key)) {
122     gpgme_user_id_t u = key.ctx->uids;
123 twoaday 160
124     id = u->name;
125 werner 36 if (!id)
126     id = _("Invalid User ID");
127 twoaday 204 n = 32+strlen (id)+1+4+strlen (r->keyid)+1;
128 twoaday 160 if (u->email)
129     n += strlen (u->email)+1;
130     info = new char [n+1];
131 werner 36 if (!info)
132     BUG (NULL);
133 twoaday 160 if (!u->email || strlen (u->email) < 1)
134 twoaday 204 sprintf (info, "%s (%s, 0x%s)", id,
135 twoaday 160 get_key_pubalgo (r->pubkey_algo), r->keyid+8);
136     else
137 twoaday 204 sprintf (info, "%s <%s> (%s, 0x%s)", id, u->email,
138 twoaday 160 get_key_pubalgo (r->pubkey_algo), r->keyid+8);
139 werner 36 }
140     else {
141     info = new char [32 + strlen (r->keyid)+1 + 4];
142     if (!info)
143     BUG (NULL);
144     sprintf (info, _("Unknown key ID (%s, 0x%s)"),
145     get_key_pubalgo (r->pubkey_algo), r->keyid+8);
146     }
147 twoaday 204 ListBox_AddString_utf8 (GetDlgItem (dlg, IDC_DECRYPT_LIST), info);
148 werner 36 free_if_alloc (info);
149 twoaday 217 winpt_release_pubkey (&key);
150 werner 36 }
151     }
152     else if (c->gpg_cmd == GPG_CMD_DECRYPT)
153     EnableWindow (GetDlgItem (dlg, IDC_DECRYPT_LIST), FALSE);
154     SetDlgItemText (dlg, c->gpg_cmd == GPG_CMD_DECRYPT?
155     IDC_DECRYPT_PWDINFO : IDC_DECRYPT_SIGN_PWDINFO,
156     c->bad_pwd? _("Bad passphrase; Enter passphrase again") :
157     _("Please enter your passphrase"));
158     if (c->gpg_cmd == GPG_CMD_DECRYPT) {
159     SetFocus (GetDlgItem (dlg, IDC_DECRYPT_PWD));
160     if (res && !res->recipients) {
161     const char *s = _("Symmetric encryption.\n"
162     "%s encrypted data.");
163     const char *alg = get_symkey_algo (c->sym.sym_algo);
164     info = new char[strlen (s) + strlen (alg) + 2];
165     if (!info)
166     BUG (NULL);
167     sprintf (info, s, alg);
168     SetDlgItemText (dlg, IDC_DECRYPT_MSG, info);
169     free_if_alloc (info);
170     }
171     else
172 twoaday 205 SetDlgItemText (dlg, IDC_DECRYPT_MSG, c->info);
173 werner 36 }
174     else {
175 twoaday 204 SetFocus (GetDlgItem (dlg, IDC_DECRYPT_SIGN_PWD));
176 twoaday 205 SetDlgItemText (dlg, IDC_DECRYPT_SIGN_MSG, c->info);
177 werner 36 }
178     center_window (dlg, NULL);
179     SetForegroundWindow (dlg);
180     return FALSE;
181    
182     case WM_COMMAND:
183     switch (HIWORD (wparam)) {
184     case BN_CLICKED:
185     if (LOWORD (wparam) == IDC_DECRYPT_HIDE
186     || LOWORD (wparam) == IDC_DECRYPT_SIGN_HIDE) {
187     HWND hwnd;
188     int hide = IsDlgButtonChecked (dlg, item_ctrl_id2 (c->gpg_cmd));
189     hwnd = GetDlgItem (dlg, item_ctrl_id (c->gpg_cmd));
190     SendMessage (hwnd, EM_SETPASSWORDCHAR, hide? '*' : 0, 0);
191     SetFocus (hwnd);
192     }
193     }
194    
195     switch (LOWORD (wparam)) {
196     case IDOK:
197     /* XXX: the item is even cached when the passphrase is not
198     correct, which means that the user needs to delete all
199     cached entries to continue. */
200     if (c->pwd)
201     burn_passphrase (&c->pwd);
202     n = item_get_text_length (dlg, item_ctrl_id (c->gpg_cmd));
203     if (!n) {
204     c->pwd = new char[2];
205     if (!c->pwd)
206     BUG (NULL);
207     strcpy (c->pwd, "");
208     }
209     else {
210 twoaday 229 char *p = new char[n+2];
211     if (!p)
212 werner 36 BUG (NULL);
213 twoaday 229 /* Get the passphrase and convert it utf8.
214     This does not just the us-ascii charset. */
215     SafeGetDlgItemText (dlg, item_ctrl_id (c->gpg_cmd), p, n+1);
216     c->pwd = native_to_utf8 (p);
217     sfree_if_alloc (p);
218 werner 36 }
219     res = gpgme_op_decrypt_result (c->gpg);
220     if (!res)
221 twoaday 271 res_sig = gpgme_op_sign_result (c->gpg);
222 twoaday 255 if (!c->is_card && reg_prefs.cache_time > 0 &&
223 twoaday 77 (res || res_sig)) {
224 twoaday 255 if (agent_get_cache (c->keyid, &item))
225 werner 36 agent_unlock_cache_entry (&item);
226 twoaday 77 else
227 werner 36 agent_put_cache (c->keyid, c->pwd, reg_prefs.cache_time);
228     }
229     c->cancel = 0;
230     EndDialog (dlg, TRUE);
231     return TRUE;
232    
233     case IDCANCEL:
234     SetDlgItemText (dlg, item_ctrl_id (c->gpg_cmd), "");
235     c->cancel = 1;
236     EndDialog (dlg, FALSE);
237 twoaday 271 return TRUE;
238 werner 36 }
239     break;
240     }
241    
242     return FALSE;
243     }
244    
245    
246     /* Extract the main keyid from @pass_info.
247     Return value: long main keyid or NULL for an error. */
248     static const char*
249     parse_gpg_keyid (const char *pass_info)
250     {
251     static char keyid[16+1];
252    
253     /* XXX: check for leading alpha-chars? */
254 twoaday 77 if (strlen (pass_info) < 16) {
255     log_debug ("parse_gpg_keyid: error '%s'\r\n", pass_info);
256 werner 36 return NULL;
257 twoaday 77 }
258 werner 36 /* the format of the desc buffer looks like this:
259     request_keyid[16] main_keyid[16] keytype[1] keylength[4]
260     we use the main keyid to use only one cache entry. */
261     strncpy (keyid, pass_info+17, 16);
262     keyid[16] = 0;
263     return keyid;
264     }
265    
266    
267     /* Parse the information in @uid_hint and @pass_info to generate
268     a input message for the user in @desc. */
269     static int
270     parse_gpg_description (const char *uid_hint, const char *pass_info,
271     char *desc, int size)
272     {
273     gpgme_pubkey_algo_t algo;
274     char usedkey[16+1];
275     char mainkey[16+1];
276 twoaday 205 char *p, *uid;
277 werner 36 int n=0;
278    
279 twoaday 69 algo = (gpgme_pubkey_algo_t)0;
280 werner 36 /* Each uid_hint contains a long key-ID so it is at least 16 bytes. */
281     if (strlen (uid_hint) < 17) {
282     *desc = 0;
283 twoaday 77 log_debug ("parse_gpg_description: error '%s'\r\n", uid_hint);
284 werner 36 return -1;
285     }
286    
287     while (p = strsep ((char**)&pass_info, " ")) {
288     switch (n++) {
289     case 0: strncpy (mainkey, p, 16); mainkey[16] = 0; break;
290     case 1: strncpy (usedkey, p, 16); usedkey[16] = 0; break;
291     case 2: algo = (gpgme_pubkey_algo_t)atol (p); break;
292     }
293     }
294     uid_hint += 16; /* skip keyid */
295     uid_hint += 1; /* space */
296    
297 twoaday 205 uid = utf8_to_native (uid_hint);
298 werner 36 if (strcmp (usedkey, mainkey))
299     _snprintf (desc, size-1,
300 twoaday 255 _("You need a passphrase to unlock the secret key for user:\n"
301     "\"%s\"\n"
302     "%s key, ID 0x%s (main key ID 0x%s)\n"),
303 twoaday 205 uid, get_key_pubalgo (algo), usedkey+8, mainkey+8);
304 werner 36 else if (!strcmp (usedkey, mainkey))
305     _snprintf (desc, size-1,
306 twoaday 255 _("You need a passphrase to unlock the secret key for user:\n"
307     "\"%s\"\n"
308     "%s key, ID 0x%s\n"),
309 twoaday 205 uid, get_key_pubalgo (algo), usedkey+8);
310     safe_free (uid);
311 werner 36 return 0;
312     }
313    
314    
315     /* Extract the serial number from the card ID @id and return it. */
316     const char*
317     extract_serial_no (const char *id)
318     {
319     static char buf[8];
320     char *p;
321    
322     p = strchr (id, '/');
323 twoaday 77 if (!p) {
324     log_debug ("extract_serial_no: error '%s'\r\n", id);
325 twoaday 260 return "";
326 twoaday 77 }
327 twoaday 260 memset (buf, 0, sizeof (buf));
328 werner 36 strncpy (buf, id+(p-id)-6, 6);
329     return buf;
330     }
331    
332    
333     /* Passphrase callback with the ability to support caching. */
334     gpgme_error_t
335     passphrase_cb (void *hook, const char *uid_hint,
336     const char *passphrase_info,
337     int prev_was_bad, int fd)
338     {
339     passphrase_cb_s *c = (passphrase_cb_s*)hook;
340     HANDLE hd = (HANDLE)fd;
341     void *item;
342 twoaday 69 const char *keyid=NULL, *pass;
343 werner 36 DWORD n;
344 twoaday 77 int rc = 0;
345 werner 36
346 twoaday 77 if (!c) {
347 twoaday 271 log_debug ("passphrase_cb: error no valid callback\r\n");
348 werner 36 return gpg_error (GPG_ERR_INV_ARG);
349 twoaday 77 }
350 werner 36 c->bad_pwd = prev_was_bad? 1 : 0;
351     if (prev_was_bad && !c->cancel) {
352     if (c->pwd)
353     burn_passphrase (&c->pwd);
354     agent_del_cache (c->keyid);
355     c->pwd_init = 1;
356     }
357    
358     if (passphrase_info) {
359     if (strlen (passphrase_info) < 16 &&
360     !strstr (passphrase_info, "OPENPGP")) {
361     /* assume symetric encryption. */
362 twoaday 69 int pos=2;
363 werner 36 c->sym.sym_algo = atoi (passphrase_info);
364     if (c->sym.sym_algo > 9)
365 twoaday 69 pos++;
366 werner 36 /* XXX: be more strict. */
367 twoaday 69 c->sym.s2k_mode = atoi (passphrase_info+pos);
368     c->sym.s2k_hash = atoi (passphrase_info+pos+2);
369 werner 36 }
370    
371     keyid = parse_gpg_keyid (passphrase_info);
372 twoaday 77 pass = agent_get_cache (keyid+8, &item);
373 werner 36 if (pass) {
374     agent_unlock_cache_entry (&item);
375     c->pwd_init = 0;
376     if (!WriteFile (hd, pass, strlen (pass), &n, NULL))
377     log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
378     if (!WriteFile (hd, "\n", 1, &n, NULL))
379     log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
380     return 0;
381     }
382     }
383    
384     if (c->pwd_init) {
385     if (keyid && strlen (keyid) == 16)
386     strcpy (c->keyid, keyid+8);
387    
388     /* if @passphrase_info contains 'OPENPGP' we assume a smart card
389     has been used. */
390     if (strstr (passphrase_info, "OPENPGP")) {
391     const char *s=passphrase_info;
392     while (s && *s && *s != 'D')
393     s++;
394     _snprintf (c->info, sizeof c->info-1,
395     _("Please enter the PIN to unlock your secret card key\n"
396     "Card: %s"), extract_serial_no (s));
397     c->is_card = 1;
398     }
399     else if (uid_hint)
400     parse_gpg_description (uid_hint, passphrase_info,
401 twoaday 181 c->info, sizeof (c->info) - 1);
402 werner 36 if (c->gpg_cmd == GPG_CMD_DECRYPT) {
403     rc = DialogBoxParam (glob_hinst, (LPCSTR)IDD_WINPT_DECRYPT,
404     (HWND)c->hwnd, passphrase_callback_proc,
405     (LPARAM)c);
406     }
407     else if (c->gpg_cmd == GPG_CMD_SIGN) {
408     rc = DialogBoxParam (glob_hinst, (LPCSTR)IDD_WINPT_DECRYPT_SIGN,
409     (HWND)c->hwnd, passphrase_callback_proc,
410     (LPARAM)c);
411     }
412     if (rc == -1) {
413     if (!WriteFile (hd, "\n", 1, &n, NULL))
414     log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
415 twoaday 271 log_debug ("passphrase_cb: could not create dialog box\n");
416 werner 36 return 0;
417     }
418     c->pwd_init = 0;
419     }
420 twoaday 214 if (c->cancel || !c->pwd) {
421 werner 36 if (!WriteFile (hd, "\n", 1, &n, NULL))
422     log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
423     return 0;
424     }
425    
426 twoaday 77 if (!WriteFile (hd, c->pwd, strlen (c->pwd), &n, NULL))
427     log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
428     if (!WriteFile (hd, "\n", 1, &n, NULL))
429     log_debug ("passphrase_cb: WriteFile() failed ec=%d\n", w32_errno);
430 werner 36 return 0;
431     }
432    
433    
434     /* Initialize the given passphrase callback @cb with the
435     used gpgme context @ctx, the command @cmd and a title
436     @title for the dialog. */
437     void
438     set_gpg_passphrase_cb (passphrase_cb_s *cb, gpgme_ctx_t ctx,
439     int cmd, HWND hwnd, const char *title)
440     {
441     memset (cb, 0, sizeof *cb);
442     cb->gpg_cmd = cmd;
443     cb->bad_pwd = 0;
444     cb->is_card = 0;
445     cb->cancel = 0;
446     cb->hwnd = hwnd;
447     cb->pwd_init = 1;
448     free_if_alloc (cb->title);
449     cb->title = m_strdup (title);
450     gpgme_set_passphrase_cb (ctx, passphrase_cb, cb);
451     cb->gpg = ctx;
452     }
453    
454    
455 twoaday 214 /* Release the gpg recipient list. */
456 werner 36 void
457 twoaday 214 release_gpg_recipients (gpgme_recipient_t *recipients)
458 werner 36 {
459     gpgme_recipient_t r, n;
460    
461 twoaday 214 r = *recipients;
462     while (r != NULL) {
463 werner 36 n = r->next;
464     safe_free (r->keyid);
465     safe_free (r);
466     r = n;
467     }
468 twoaday 214 *recipients = NULL;
469 werner 36 }
470    
471    
472 twoaday 214
473     /* Release a passphrase callback @ctx. */
474     void
475     release_gpg_passphrase_cb (passphrase_cb_s *ctx)
476     {
477     if (!ctx)
478     return;
479     sfree_if_alloc (ctx->pwd);
480     free_if_alloc (ctx->title);
481     release_gpg_recipients (&ctx->recipients);
482     }
483    
484    
485 twoaday 271 /* _Simple_ check to measure passphrase (@pass) quality.
486 werner 36 Return value: 0 on success. */
487     int
488     check_passwd_quality (const char *pass, int strict)
489     {
490     int i, nd=0, nc=0, n;
491    
492 twoaday 271 /* A good passphrase should be at least 8 characters. */
493 werner 36 n = strlen (pass);
494     if (n < 8)
495     return -1;
496    
497     for (i=0; i < n; i++) {
498 twoaday 271 if (isdigit (pass[i]))
499 werner 36 nd++;
500 twoaday 271 if (isalpha (pass[i]))
501 werner 36 nc++;
502     }
503    
504 twoaday 271 /* Check that the passphrase contains letters and numbers. */
505 werner 36 if (nd == n || nc == n)
506     return -1;
507    
508     return 0;
509     }

Properties

Name Value
svn:eol-style native

[email protected]
ViewVC Help
Powered by ViewVC 1.1.26