1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
|
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
# vim:fenc=utf-8 et ts=4 sts=4 sw=4
#
# Copyright © 2019 Maxime “pep” Buquet <pep@bouah.net>
#
# Distributed under terms of the zlib license. See COPYING file.
"""
Interface for E2EE (End-to-end Encryption) plugins.
"""
from typing import Callable, Dict, Optional, Union
from slixmpp import InvalidJID, JID, Message
from poezio.tabs import ConversationTab, DynamicConversationTab, PrivateTab, MucTab
from poezio.plugin import BasePlugin
import logging
log = logging.getLogger(__name__)
ChatTabs = Union[
MucTab,
DynamicConversationTab,
PrivateTab,
]
EME_NS = 'urn:xmpp:eme:0'
EME_TAG = 'encryption'
JCLIENT_NS = 'jabber:client'
HINTS_NS = 'urn:xmpp:hints'
class E2EEPlugin(BasePlugin):
"""Interface for E2EE plugins"""
# Specifies that the encryption mechanism does more than encrypting
# <body/>.
stanza_encryption = False
# Whitelist applied to messages when `stanza_encryption` is False.
# This might need to be changed depending on the encryption mechanism.
# Some encrypt directly content in <body/> for example, some use a
# different element like <payload/> and thus <body/> is a generic EME
# message.
tag_whitelist = list(map(lambda x: '{%s}%s' % (x[0], x[1]), [
(JCLIENT_NS, 'body'),
(EME_NS, EME_TAG),
(HINTS_NS, 'store'),
(HINTS_NS, 'no-copy'),
(HINTS_NS, 'no-store'),
(HINTS_NS, 'no-permanent-store'),
]))
# At least one of encryption_name and encryption_short_name must be set
encryption_name = None # type: Optional[str]
encryption_short_name = None # type: Optional[str]
# Required.
eme_ns = None # type: Optional[str]
# Static map, to be able to limit to one encryption mechanism per tab at a
# time
_enabled_tabs = {} # type: Dict[JID, Callable]
def init(self):
if self.encryption_name is None and self.encryption_short_name is None:
raise NotImplementedError
if self.eme_ns is None:
raise NotImplementedError
if self.encryption_name is None:
self.encryption_name = self.encryption_short_name
if self.encryption_short_name is None:
self.encryption_short_name = self.encryption_name
# Ensure decryption is done before everything, so that other handlers
# don't have to know about the encryption mechanism.
self.api.add_event_handler('muc_msg', self._decrypt, priority=0)
self.api.add_event_handler('conversation_msg', self._decrypt, priority=0)
self.api.add_event_handler('private_msg', self._decrypt, priority=0)
# Ensure encryption is done after everything, so that whatever can be
# encrypted is encrypted, and no plain element slips in.
self.api.add_event_handler('muc_say', self._encrypt, priority=100)
self.api.add_event_handler('conversation_say', self._encrypt, priority=100)
self.api.add_event_handler('private_say', self._encrypt, priority=100)
for tab_t in (DynamicConversationTab, PrivateTab, MucTab):
self.api.add_tab_command(
tab_t,
self.encryption_short_name,
self._toggle_tab,
usage='',
short='Toggle {} encryption for tab.'.format(self.encryption_name),
help='Toggle automatic {} encryption for tab.'.format(self.encryption_name),
)
ConversationTab.add_information_element(
self.encryption_short_name,
self._display_encryption_status,
)
MucTab.add_information_element(
self.encryption_short_name,
self._display_encryption_status,
)
PrivateTab.add_information_element(
self.encryption_short_name,
self._display_encryption_status,
)
def cleanup(self):
ConversationTab.remove_information_element(self.encryption_short_name)
MucTab.remove_information_element(self.encryption_short_name)
PrivateTab.remove_information_element(self.encryption_short_name)
def _display_encryption_status(self, jid_s: str) -> str:
"""
Return information to display in the infobar if encryption is
enabled for the JID.
"""
try:
jid = JID(jid_s)
except InvalidJID:
return ""
if self._encryption_enabled(jid):
return " " + self.encryption_short_name
return ""
def _toggle_tab(self, _input: str) -> None:
jid = self.api.current_tab().jid # type: JID
if self._encryption_enabled(jid):
del self._enabled_tabs[jid]
self.api.information(
'{} encryption disabled for {}'.format(self.encryption_name, jid),
'Info',
)
else:
self._enabled_tabs[jid] = self.encrypt
self.api.information(
'{} encryption enabled for {}'.format(self.encryption_name, jid),
'Info',
)
def _encryption_enabled(self, jid: JID) -> bool:
return jid in self._enabled_tabs and self._enabled_tabs[jid] == self.encrypt
def _decrypt(self, message: Message, tab: ChatTabs) -> None:
if message.xml.find('{%s}%s' % (EME_NS, EME_TAG)) is None:
return None
if message['eme']['namespace'] != self.eme_ns:
return None
log.debug('Received %s message: %r', self.encryption_name, message['body'])
self.decrypt(message, tab)
log.debug('Decrypted %s message: %r', self.encryption_name, message['body'])
return None
def _encrypt(self, message: Message, tab: ChatTabs):
jid = tab.jid
if not self._encryption_enabled(jid):
return None
log.debug('Sending %s message: %r', self.encryption_name, message['body'])
message['eme']['namespace'] = self.eme_ns
message['eme']['name'] = self.encryption_name
# Call the enabled encrypt method
self._enabled_tabs[jid](message, tab)
# Filter stanza with the whitelist if we don't do stanza encryption
if not self.stanza_encryption:
for elem in message.xml[:]:
if elem.tag not in self.tag_whitelist:
message.xml.remove(elem)
log.debug('Decrypted %s message: %r', self.encryption_name, message['body'])
return None
def decrypt(self, _message: Message, tab: ChatTabs):
"""Decryption method"""
raise NotImplementedError
def encrypt(self, _message: Message, tab: ChatTabs):
"""Encryption method"""
raise NotImplementedError
|