forked from Narcissus/pylibmeshctrl
Compare commits
2 Commits
feat/webso
...
fix/list-d
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bc5f2fda4b | ||
|
|
271f9fac23 |
@@ -2,34 +2,7 @@
|
|||||||
Changelog
|
Changelog
|
||||||
=========
|
=========
|
||||||
|
|
||||||
version 1.1.2
|
|
||||||
=============
|
|
||||||
Bugs:
|
|
||||||
* Fixed semver for requirements. New version of websockets broke this library.
|
|
||||||
|
|
||||||
Security:
|
|
||||||
* Updated cryptogaphy to ~44.0.1 to fix ssl vulnerability.
|
|
||||||
|
|
||||||
Version 1.1.1
|
|
||||||
=============
|
|
||||||
Bugs:
|
|
||||||
* Fixed bug when running device_info when user has access to multiple meshes
|
|
||||||
|
|
||||||
Version 1.1.0
|
|
||||||
=============
|
|
||||||
Features:
|
|
||||||
* Added overrides for meshcentral files for testing purposes
|
|
||||||
* Added `users` field to `device` object
|
|
||||||
|
|
||||||
Bugs:
|
|
||||||
* Fixed connection errors not raising immediately
|
|
||||||
* Fixed run_commands parsing return from multiple devices incorrectly
|
|
||||||
* Fixed listening to raw not removing its listener correctly
|
|
||||||
* Fixed javascript timecodes not being handled in gnu environments
|
|
||||||
* Changed some fstring formatting that locked the library into python >3.13
|
|
||||||
|
|
||||||
|
|
||||||
Version 1.0.0
|
Version 1.0.0
|
||||||
=============
|
===========
|
||||||
|
|
||||||
First release
|
First release
|
||||||
|
|||||||
@@ -5,8 +5,8 @@ sphinx>=3.2.1
|
|||||||
sphinx-jinja2-compat>=0.1.1
|
sphinx-jinja2-compat>=0.1.1
|
||||||
sphinx-toolbox>=2.16.0
|
sphinx-toolbox>=2.16.0
|
||||||
# sphinx_rtd_theme
|
# sphinx_rtd_theme
|
||||||
cffi~=1.17.1
|
cffi==1.17.1
|
||||||
cryptography~=44.0.1
|
cryptography==43.0.3
|
||||||
pycparser~=2.22
|
pycparser==2.22
|
||||||
websockets~=15.0.0
|
websockets==13.1
|
||||||
enum_tools
|
enum_tools
|
||||||
BIN
requirements.txt
BIN
requirements.txt
Binary file not shown.
@@ -44,9 +44,9 @@ python_requires = >=3.8
|
|||||||
# For more information, check out https://semver.org/.
|
# For more information, check out https://semver.org/.
|
||||||
install_requires =
|
install_requires =
|
||||||
importlib-metadata
|
importlib-metadata
|
||||||
cryptography~=44.0.1
|
cryptography>=43.0.3
|
||||||
websockets~=15.0.0
|
websockets>=13.1
|
||||||
python-socks[asyncio]~=2.5.3
|
python-socks[asyncio]
|
||||||
|
|
||||||
|
|
||||||
[options.packages.find]
|
[options.packages.find]
|
||||||
|
|||||||
@@ -2,9 +2,7 @@ class MeshCtrlError(Exception):
|
|||||||
"""
|
"""
|
||||||
Base class for Meshctrl errors
|
Base class for Meshctrl errors
|
||||||
"""
|
"""
|
||||||
def __init__(self, message, *args, **kwargs):
|
pass
|
||||||
self.message = message
|
|
||||||
super().__init__(message, *args, **kwargs)
|
|
||||||
|
|
||||||
class ServerError(MeshCtrlError):
|
class ServerError(MeshCtrlError):
|
||||||
"""
|
"""
|
||||||
@@ -27,7 +25,6 @@ class FileTransferError(MeshCtrlError):
|
|||||||
"""
|
"""
|
||||||
def __init__(self, message, stats):
|
def __init__(self, message, stats):
|
||||||
self.stats = stats
|
self.stats = stats
|
||||||
super().__init__(message)
|
|
||||||
|
|
||||||
class FileTransferCancelled(FileTransferError):
|
class FileTransferCancelled(FileTransferError):
|
||||||
"""
|
"""
|
||||||
|
|||||||
@@ -144,7 +144,7 @@ class Session(object):
|
|||||||
|
|
||||||
|
|
||||||
options["additional_headers"] = headers
|
options["additional_headers"] = headers
|
||||||
async for websocket in websockets.asyncio.client.connect(self.url, proxy=self._proxy, process_exception=util._process_websocket_exception, **options):
|
async for websocket in util.proxy_connect(self.url, proxy_url=self._proxy, process_exception=util._process_websocket_exception, **options):
|
||||||
self.alive = True
|
self.alive = True
|
||||||
self._socket_open.set()
|
self._socket_open.set()
|
||||||
try:
|
try:
|
||||||
@@ -533,7 +533,7 @@ class Session(object):
|
|||||||
data = await event_queue.get()
|
data = await event_queue.get()
|
||||||
yield data
|
yield data
|
||||||
finally:
|
finally:
|
||||||
self._eventer.off("raw", _)
|
self._eventer.off("server_event", _)
|
||||||
|
|
||||||
async def events(self, filter=None):
|
async def events(self, filter=None):
|
||||||
'''
|
'''
|
||||||
@@ -1363,10 +1363,10 @@ class Session(object):
|
|||||||
node["meshid"] = meshid
|
node["meshid"] = meshid
|
||||||
if _mesh is not None:
|
if _mesh is not None:
|
||||||
node["mesh"] = _mesh
|
node["mesh"] = _mesh
|
||||||
break
|
sysinfo["node"] = node
|
||||||
else:
|
sysinfo["nodeid"] = nodeid
|
||||||
continue
|
del sysinfo["result"]
|
||||||
break
|
del sysinfo["noinfo"]
|
||||||
if node is None:
|
if node is None:
|
||||||
raise ValueError("Invalid device id")
|
raise ValueError("Invalid device id")
|
||||||
if lastconnect is not None:
|
if lastconnect is not None:
|
||||||
@@ -1463,7 +1463,6 @@ class Session(object):
|
|||||||
result.setdefault(node, {})["complete"] = True
|
result.setdefault(node, {})["complete"] = True
|
||||||
if all(_["complete"] for key, _ in result.items()):
|
if all(_["complete"] for key, _ in result.items()):
|
||||||
break
|
break
|
||||||
continue
|
|
||||||
elif (event["value"].startswith("Run commands")):
|
elif (event["value"].startswith("Run commands")):
|
||||||
continue
|
continue
|
||||||
result[node]["result"].append(event["value"])
|
result[node]["result"].append(event["value"])
|
||||||
|
|||||||
@@ -67,7 +67,7 @@ class Tunnel(object):
|
|||||||
self.url = self._session.url.replace('/control.ashx', '/meshrelay.ashx?browser=1&p=' + str(self._protocol) + '&nodeid=' + self.node_id + '&id=' + self._tunnel_id + '&auth=' + self._authcookie["cookie"])
|
self.url = self._session.url.replace('/control.ashx', '/meshrelay.ashx?browser=1&p=' + str(self._protocol) + '&nodeid=' + self.node_id + '&id=' + self._tunnel_id + '&auth=' + self._authcookie["cookie"])
|
||||||
|
|
||||||
|
|
||||||
async for websocket in websockets.asyncio.client.connect(self.url, proxy=self._session._proxy, process_exception=util._process_websocket_exception, **options):
|
async for websocket in util.proxy_connect(self.url, proxy_url=self._session._proxy, process_exception=util._process_websocket_exception, **options):
|
||||||
self.alive = True
|
self.alive = True
|
||||||
self._socket_open.set()
|
self._socket_open.set()
|
||||||
try:
|
try:
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import ssl
|
|||||||
import functools
|
import functools
|
||||||
import urllib
|
import urllib
|
||||||
import python_socks
|
import python_socks
|
||||||
|
from python_socks.async_.asyncio import Proxy
|
||||||
from . import exceptions
|
from . import exceptions
|
||||||
|
|
||||||
def _encode_cookie(o, key):
|
def _encode_cookie(o, key):
|
||||||
@@ -139,20 +140,17 @@ def compare_dict(dict1, dict2):
|
|||||||
return False
|
return False
|
||||||
|
|
||||||
def _check_socket(f):
|
def _check_socket(f):
|
||||||
async def _check_errs(self):
|
@functools.wraps(f)
|
||||||
|
async def wrapper(self, *args, **kwargs):
|
||||||
|
try:
|
||||||
|
async with asyncio.TaskGroup() as tg:
|
||||||
|
tg.create_task(asyncio.wait_for(self.initialized.wait(), 10))
|
||||||
|
tg.create_task(asyncio.wait_for(self._socket_open.wait(), 10))
|
||||||
|
finally:
|
||||||
if not self.alive and self._main_loop_error is not None:
|
if not self.alive and self._main_loop_error is not None:
|
||||||
raise self._main_loop_error
|
raise self._main_loop_error
|
||||||
elif not self.alive and self.initialized.is_set():
|
elif not self.alive and self.initialized.is_set():
|
||||||
raise exceptions.SocketError("Socket Closed")
|
raise exceptions.SocketError("Socket Closed")
|
||||||
|
|
||||||
@functools.wraps(f)
|
|
||||||
async def wrapper(self, *args, **kwargs):
|
|
||||||
try:
|
|
||||||
await asyncio.wait_for(self.initialized.wait(), 10)
|
|
||||||
await _check_errs(self)
|
|
||||||
await asyncio.wait_for(self._socket_open.wait(), 10)
|
|
||||||
finally:
|
|
||||||
await _check_errs(self)
|
|
||||||
return await f(self, *args, **kwargs)
|
return await f(self, *args, **kwargs)
|
||||||
return wrapper
|
return wrapper
|
||||||
|
|
||||||
@@ -163,7 +161,17 @@ def _process_websocket_exception(exc):
|
|||||||
return exc
|
return exc
|
||||||
if isinstance(exc, python_socks._errors.ProxyError):
|
if isinstance(exc, python_socks._errors.ProxyError):
|
||||||
return None
|
return None
|
||||||
# Proxy errors show up like this now, and it's default to error out. Handle explicitly.
|
|
||||||
if isinstance(exc, websockets.exceptions.InvalidProxyMessage):
|
|
||||||
return None
|
|
||||||
return tmp
|
return tmp
|
||||||
|
|
||||||
|
class proxy_connect(websockets.asyncio.client.connect):
|
||||||
|
def __init__(self,*args, proxy_url=None, **kwargs):
|
||||||
|
self.proxy = None
|
||||||
|
if proxy_url is not None:
|
||||||
|
self.proxy = Proxy.from_url(proxy_url)
|
||||||
|
super().__init__(*args, **kwargs)
|
||||||
|
|
||||||
|
async def create_connection(self, *args, **kwargs):
|
||||||
|
if self.proxy is not None:
|
||||||
|
parsed = urllib.parse.urlparse(self.uri)
|
||||||
|
self.connection_kwargs["sock"] = await self.proxy.connect(dest_host=parsed.hostname, dest_port=parsed.port)
|
||||||
|
return await super().create_connection(*args, **kwargs)
|
||||||
@@ -62,7 +62,7 @@ class TestEnvironment(object):
|
|||||||
return self
|
return self
|
||||||
# Destroy the env in case it wasn't killed correctly last time.
|
# Destroy the env in case it wasn't killed correctly last time.
|
||||||
subprocess.check_call(["docker", "compose", "down"], stdout=subprocess.DEVNULL, cwd=thisdir)
|
subprocess.check_call(["docker", "compose", "down"], stdout=subprocess.DEVNULL, cwd=thisdir)
|
||||||
self._subp = _docker_process = subprocess.Popen(["docker", "compose", "up", "--build", "--force-recreate", "--no-deps"], cwd=thisdir)
|
self._subp = _docker_process = subprocess.Popen(["docker", "compose", "up", "--build", "--force-recreate", "--no-deps"], stdout=subprocess.DEVNULL, cwd=thisdir)
|
||||||
if not self._wait_for_meshcentral():
|
if not self._wait_for_meshcentral():
|
||||||
self.__exit__(None, None, None)
|
self.__exit__(None, None, None)
|
||||||
raise Exception("Failed to create docker instance")
|
raise Exception("Failed to create docker instance")
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
# Ignore everything in this directory
|
|
||||||
*
|
|
||||||
# Except this file
|
|
||||||
!.gitignore
|
|
||||||
@@ -4,5 +4,4 @@ RUN apk add python3
|
|||||||
WORKDIR /opt/meshcentral/
|
WORKDIR /opt/meshcentral/
|
||||||
COPY ./scripts/meshcentral ./scripts
|
COPY ./scripts/meshcentral ./scripts
|
||||||
COPY ./config/meshcentral/data /opt/meshcentral/meshcentral-data
|
COPY ./config/meshcentral/data /opt/meshcentral/meshcentral-data
|
||||||
COPY ./config/meshcentral/overrides /opt/meshcentral/meshcentral
|
|
||||||
CMD ["python3", "/opt/meshcentral/scripts/create_users.py"]
|
CMD ["python3", "/opt/meshcentral/scripts/create_users.py"]
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
requests
|
requests
|
||||||
pytest-asyncio
|
pytest-asyncio
|
||||||
cffi==1.17.1
|
cffi==1.17.1
|
||||||
cryptography~=44.0.1
|
cryptography==43.0.3
|
||||||
pycparser==2.22
|
pycparser==2.22
|
||||||
websockets~=15.0.0
|
websockets==13.1
|
||||||
@@ -5,8 +5,6 @@ import meshctrl
|
|||||||
import requests
|
import requests
|
||||||
import random
|
import random
|
||||||
import io
|
import io
|
||||||
import traceback
|
|
||||||
import time
|
|
||||||
thisdir = os.path.dirname(os.path.realpath(__file__))
|
thisdir = os.path.dirname(os.path.realpath(__file__))
|
||||||
|
|
||||||
async def test_admin(env):
|
async def test_admin(env):
|
||||||
@@ -46,10 +44,8 @@ async def test_auto_reconnect(env):
|
|||||||
for i in range(3):
|
for i in range(3):
|
||||||
try:
|
try:
|
||||||
await admin_session.ping(timeout=10)
|
await admin_session.ping(timeout=10)
|
||||||
except* Exception as e:
|
except:
|
||||||
print("".join(traceback.format_exception(e)))
|
continue
|
||||||
pass
|
|
||||||
else:
|
|
||||||
break
|
break
|
||||||
else:
|
else:
|
||||||
raise Exception("Failed to reconnect")
|
raise Exception("Failed to reconnect")
|
||||||
@@ -59,7 +55,6 @@ async def test_auto_reconnect(env):
|
|||||||
try:
|
try:
|
||||||
await admin_session.ping(timeout=10)
|
await admin_session.ping(timeout=10)
|
||||||
except* Exception as e:
|
except* Exception as e:
|
||||||
print("".join(traceback.format_exception(e)))
|
|
||||||
pass
|
pass
|
||||||
else:
|
else:
|
||||||
break
|
break
|
||||||
@@ -82,17 +77,6 @@ async def test_users(env):
|
|||||||
pass
|
pass
|
||||||
else:
|
else:
|
||||||
raise Exception("Connected with no password")
|
raise Exception("Connected with no password")
|
||||||
|
|
||||||
start = time.time()
|
|
||||||
try:
|
|
||||||
async with meshctrl.Session(env.mcurl, user="admin", password="The wrong password", ignore_ssl=True) as admin_session:
|
|
||||||
pass
|
|
||||||
except* meshctrl.exceptions.ServerError as eg:
|
|
||||||
assert str(eg.exceptions[0]) == "Invalid Auth" or eg.exceptions[0].message == "Invalid Auth", "Didn't get invalid auth message"
|
|
||||||
assert time.time() - start < 10, "Invalid auth wasn't raised until after timeout"
|
|
||||||
pass
|
|
||||||
else:
|
|
||||||
raise Exception("Connected with bad password")
|
|
||||||
async with meshctrl.Session(env.mcurl+"/", user="admin", password=env.users["admin"], ignore_ssl=True) as admin_session,\
|
async with meshctrl.Session(env.mcurl+"/", user="admin", password=env.users["admin"], ignore_ssl=True) as admin_session,\
|
||||||
meshctrl.Session(env.mcurl, user="privileged", password=env.users["privileged"], ignore_ssl=True) as privileged_session,\
|
meshctrl.Session(env.mcurl, user="privileged", password=env.users["privileged"], ignore_ssl=True) as privileged_session,\
|
||||||
meshctrl.Session(env.mcurl, user="unprivileged", password=env.users["unprivileged"], ignore_ssl=True) as unprivileged_session:
|
meshctrl.Session(env.mcurl, user="unprivileged", password=env.users["unprivileged"], ignore_ssl=True) as unprivileged_session:
|
||||||
@@ -203,52 +187,56 @@ async def test_mesh_device(env):
|
|||||||
|
|
||||||
assert r[0].description == "New description", "Description either failed to change, or was changed by a user without permission to do so"
|
assert r[0].description == "New description", "Description either failed to change, or was changed by a user without permission to do so"
|
||||||
|
|
||||||
# There once was a bug that occured whenever running run_commands with multiple meshes. We need to add devices to both meshes to be sure that bug is squashed.
|
with env.create_agent(mesh.short_meshid) as agent:
|
||||||
with env.create_agent(mesh.short_meshid) as agent,\
|
|
||||||
env.create_agent(mesh.short_meshid) as agent2,\
|
|
||||||
env.create_agent(mesh2.short_meshid) as agent3:
|
|
||||||
# Test agent added to device group being propagated correctly
|
# Test agent added to device group being propagated correctly
|
||||||
# Create agent isn't so good at waiting for the agent to show in the sessions. Give it a couple seconds to appear.
|
# Create agent isn't so good at waiting for the agent to show in the sessions. Give it a couple seconds to appear.
|
||||||
for i in range(3):
|
for i in range(3):
|
||||||
try:
|
try:
|
||||||
r = await admin_session.list_devices(timeout=10)
|
r = await admin_session.list_devices(timeout=10)
|
||||||
print("\ninfo list_devices: {}\n".format(r))
|
print("\ninfo list_devices: {}\n".format(r))
|
||||||
assert len(r) == 3, "Incorrect number of agents connected"
|
assert len(r) == 1, "Incorrect number of agents connected"
|
||||||
except:
|
except:
|
||||||
if i == 2:
|
if i == 2:
|
||||||
raise
|
raise
|
||||||
await asyncio.sleep(1)
|
await asyncio.sleep(1)
|
||||||
else:
|
else:
|
||||||
break
|
break
|
||||||
assert len(await privileged_session.list_devices(timeout=10)) == 2, "Incorrect number of agents connected"
|
assert len(await privileged_session.list_devices(timeout=10)) == 1, "Incorrect number of agents connected"
|
||||||
assert len(await unprivileged_session.list_devices(timeout=10)) == 0, "Unprivileged account has access to agent it should not"
|
assert len(await unprivileged_session.list_devices(timeout=10)) == 0, "Unprivileged account has access to agent it should not"
|
||||||
|
|
||||||
r = await admin_session.list_devices(details=True, timeout=10)
|
r = await admin_session.list_devices(details=True, timeout=10)
|
||||||
print("\ninfo list_devices_details: {}\n".format(r))
|
print("\ninfo list_devices_details: {}\n".format(r))
|
||||||
|
assert len(r), "No devices found"
|
||||||
|
assert r[0].mesh is not None, "No mesh found"
|
||||||
|
assert r[0].mesh.name is not None, "Mesh details not filled correctly"
|
||||||
|
|
||||||
r = await admin_session.list_devices(group=mesh.name, timeout=10)
|
r = await admin_session.list_devices(group=mesh.name, timeout=10)
|
||||||
print("\ninfo list_devices_group: {}\n".format(r))
|
print("\ninfo list_devices_group: {}\n".format(r))
|
||||||
|
assert len(r), "No devices found"
|
||||||
|
assert r[0].mesh is not None, "No mesh found"
|
||||||
|
assert r[0].mesh.name is not None, "Mesh details not filled correctly"
|
||||||
|
|
||||||
r = await admin_session.list_devices(meshid=mesh.meshid, timeout=10)
|
r = await admin_session.list_devices(meshid=mesh.meshid, timeout=10)
|
||||||
print("\ninfo list_devices_meshid: {}\n".format(r))
|
print("\ninfo list_devices_meshid: {}\n".format(r))
|
||||||
|
assert len(r), "No devices found"
|
||||||
r = await admin_session.device_info(agent.nodeid, timeout=10)
|
assert r[0].mesh is not None, "No mesh found"
|
||||||
print("\ninfo admin_device_info: {}\n".format(r))
|
assert r[0].mesh.name is not None, "Mesh details not filled correctly"
|
||||||
|
|
||||||
# Test editing device info propagating correctly
|
# Test editing device info propagating correctly
|
||||||
assert await admin_session.edit_device(agent.nodeid, name="new_name", description="New Description", tags="device", consent=meshctrl.constants.ConsentFlags.all, timeout=10), "Failed to edit device info"
|
assert await admin_session.edit_device(agent.nodeid, name="new_name", description="New Description", tags="device", consent=meshctrl.constants.ConsentFlags.all, timeout=10), "Failed to edit device info"
|
||||||
|
|
||||||
assert (await privileged_session.device_info(agent.nodeid, timeout=10)).name == "new_name", "New name did not propagate to other sessions"
|
r = await privileged_session.device_info(agent.nodeid, timeout=10)
|
||||||
|
print("\ninfo privileged_device_info: {}\n".format(r))
|
||||||
|
assert r.name == "new_name", "New name did not propagate to other sessions"
|
||||||
|
assert r.mesh is not None, "No mesh found"
|
||||||
|
assert r.mesh.name is not None, "Mesh details not filled correctly"
|
||||||
|
|
||||||
assert await admin_session.edit_device(agent.nodeid, consent=meshctrl.constants.ConsentFlags.none, timeout=10), "Failed to edit device info"
|
assert await admin_session.edit_device(agent.nodeid, consent=meshctrl.constants.ConsentFlags.none, timeout=10), "Failed to edit device info"
|
||||||
|
|
||||||
# Test run_commands
|
# Test run_commands
|
||||||
r = await admin_session.run_command([agent.nodeid, agent2.nodeid], "ls", timeout=10)
|
r = await admin_session.run_command(agent.nodeid, "ls", timeout=10)
|
||||||
print("\ninfo run_command: {}\n".format(r))
|
print("\ninfo run_command: {}\n".format(r))
|
||||||
assert "meshagent" in r[agent.nodeid]["result"], "ls gave incorrect data"
|
assert "meshagent" in r[agent.nodeid]["result"], "ls gave incorrect data"
|
||||||
assert "meshagent" in r[agent2.nodeid]["result"], "ls gave incorrect data"
|
|
||||||
assert "Run commands completed." not in r[agent.nodeid]["result"], "Didn't parse run command ending correctly"
|
|
||||||
assert "Run commands completed." not in r[agent2.nodeid]["result"], "Didn't parse run command ending correctly"
|
|
||||||
assert "meshagent" in (await privileged_session.run_command(agent.nodeid, "ls", timeout=10))[agent.nodeid]["result"], "ls gave incorrect data"
|
assert "meshagent" in (await privileged_session.run_command(agent.nodeid, "ls", timeout=10))[agent.nodeid]["result"], "ls gave incorrect data"
|
||||||
|
|
||||||
# Test run commands with ndividual device permissions
|
# Test run commands with ndividual device permissions
|
||||||
@@ -278,6 +266,7 @@ async def test_mesh_device(env):
|
|||||||
# Test getting individual device info
|
# Test getting individual device info
|
||||||
r = await unprivileged_session.device_info(agent.nodeid, timeout=10)
|
r = await unprivileged_session.device_info(agent.nodeid, timeout=10)
|
||||||
print("\ninfo unprivileged_device_info: {}\n".format(r))
|
print("\ninfo unprivileged_device_info: {}\n".format(r))
|
||||||
|
assert r.mesh is None or r.mesh.name is None, "Unprivileged user can see mesh"
|
||||||
|
|
||||||
# This device info includes the mesh ID of the device, even though the user doesn't have acces to that mesh. That's odd.
|
# This device info includes the mesh ID of the device, even though the user doesn't have acces to that mesh. That's odd.
|
||||||
# assert r.meshid is None, "Individual device is exposing its meshid"
|
# assert r.meshid is None, "Individual device is exposing its meshid"
|
||||||
|
|||||||
Reference in New Issue
Block a user