345 lines
16 KiB
Bash
345 lines
16 KiB
Bash
#!/bin/bash
|
|
|
|
AUTHORIZED_SERVERS_PATH="opt/public/servers"
|
|
AUTHORIZED_SERVERS_FILE="/${AUTHORIZED_SERVERS_PATH}/authorized_servers.txt"
|
|
CONNECTED_USER="$(whoami)"
|
|
|
|
USER_SERVERS=$(awk -v user="${CONNECTED_USER}" '
|
|
{
|
|
split($5, users, ",");
|
|
for (i in users) {
|
|
if (users[i] == user) {
|
|
print $0;
|
|
}
|
|
}
|
|
}' "${AUTHORIZED_SERVERS_FILE}")
|
|
|
|
if [[ -z ${USER_SERVERS} ]]; then
|
|
echo "Vous n'avez pas l'autorisation de vous connecter à un serveur."
|
|
exit 1
|
|
fi
|
|
|
|
TRANSFER_DIR="/opt/public/transfer"
|
|
TRANSFER_LOG="/var/log/monosphere/transfers.log"
|
|
TRANSFER_RIGHTS_FILE="/opt/public/rights/transfer_rights.txt"
|
|
|
|
mkdir -p "$(dirname "${TRANSFER_LOG}")" 2>/dev/null
|
|
touch "${TRANSFER_LOG}" 2>/dev/null
|
|
chmod 666 "${TRANSFER_LOG}" 2>/dev/null
|
|
|
|
if [[ -n ${SSH_ORIGINAL_COMMAND} ]]; then
|
|
case "${SSH_ORIGINAL_COMMAND}" in
|
|
"stage_file "*)
|
|
filename="${SSH_ORIGINAL_COMMAND#stage_file }"
|
|
if [[ -z ${filename} ]] || [[ ${filename} =~ [/] ]] || [[ ${filename} == ".." ]] || [[ ${filename} == "." ]]; then
|
|
echo "Usage: stage_file <filename> (chemin simple, sans /)"
|
|
exit 1
|
|
fi
|
|
mkdir -p "${TRANSFER_DIR}"
|
|
cat > "${TRANSFER_DIR}/${filename}"
|
|
size=$(stat -c %s "${TRANSFER_DIR}/${filename}" 2>/dev/null || stat -f %z "${TRANSFER_DIR}/${filename}" 2>/dev/null)
|
|
echo "$(date '+%Y-%m-%d %H:%M:%S') USER=${CONNECTED_USER} ACTION=stage FILE=${filename} SIZE=${size:-0} STATUS=success" >> "${TRANSFER_LOG}"
|
|
exit 0
|
|
;;
|
|
"retrieve_file "*)
|
|
args="${SSH_ORIGINAL_COMMAND#retrieve_file }"
|
|
server_name=$(echo "${args}" | cut -d ' ' -f 1)
|
|
remote_path=$(echo "${args}" | cut -d ' ' -f 2-)
|
|
if [[ -z ${server_name} ]] || [[ -z ${remote_path} ]]; then
|
|
echo "Usage: retrieve_file <server_name> <remote_path>"
|
|
exit 1
|
|
fi
|
|
server_line=$(echo "${USER_SERVERS}" | awk -v name="${server_name}" '$3 == name {print; exit}')
|
|
if [[ -z ${server_line} ]]; then
|
|
echo "Serveur \"${server_name}\" non trouve ou non autorise."
|
|
exit 1
|
|
fi
|
|
srv_ip=$(echo "${server_line}" | cut -d ' ' -f 1)
|
|
srv_port=$(echo "${server_line}" | cut -d ' ' -f 2)
|
|
srv_user=$(echo "${server_line}" | cut -d ' ' -f 4)
|
|
srv_authmethod=$(echo "${server_line}" | cut -d ' ' -f 6)
|
|
srv_authfile=$(echo "${server_line}" | cut -d ' ' -f 7)
|
|
if [[ -z ${srv_authmethod} ]]; then
|
|
ssh -T -o StrictHostKeyChecking=accept-new -p "${srv_port}" "${srv_user}@${srv_ip}" "cat '${remote_path}'" < /dev/null
|
|
elif [[ ${srv_authmethod} == "key" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
|
|
ssh -T -o StrictHostKeyChecking=accept-new -i "/${AUTHORIZED_SERVERS_PATH}/${srv_authfile}" -p "${srv_port}" "${srv_user}@${srv_ip}" "cat '${remote_path}'" < /dev/null
|
|
elif [[ ${srv_authmethod} == "password" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
|
|
sshpass -p "$(cat /${AUTHORIZED_SERVERS_PATH}/${srv_authfile})" ssh -T -o StrictHostKeyChecking=accept-new -p "${srv_port}" "${srv_user}@${srv_ip}" "cat '${remote_path}'" < /dev/null
|
|
else
|
|
echo "Erreur d'authentification pour le serveur ${server_name}."
|
|
exit 1
|
|
fi
|
|
exit_code=$?
|
|
if [[ ${exit_code} -eq 0 ]]; then
|
|
echo "$(date '+%Y-%m-%d %H:%M:%S') USER=${CONNECTED_USER} ACTION=retrieve SERVER=${server_name} FILE=${remote_path} STATUS=success" >> "${TRANSFER_LOG}"
|
|
else
|
|
echo "$(date '+%Y-%m-%d %H:%M:%S') USER=${CONNECTED_USER} ACTION=retrieve SERVER=${server_name} FILE=${remote_path} STATUS=failed" >> "${TRANSFER_LOG}"
|
|
fi
|
|
exit ${exit_code}
|
|
;;
|
|
*)
|
|
echo "Commande non reconnue: ${SSH_ORIGINAL_COMMAND}"
|
|
echo "Commandes supportees: stage_file <filename>, retrieve_file <server_name> <remote_path>"
|
|
exit 1
|
|
;;
|
|
esac
|
|
fi
|
|
|
|
log_transfer() {
|
|
local action="$1" server="$2" path="$3" size="$4" status="$5"
|
|
echo "$(date '+%Y-%m-%d %H:%M:%S') USER=${CONNECTED_USER} ACTION=${action} SERVER=${server} FILE=${path} SIZE=${size} STATUS=${status}" >> "${TRANSFER_LOG}"
|
|
}
|
|
|
|
file_transfer_menu() {
|
|
local choice action srv_line srv_name srv_ip srv_port srv_user selected_server
|
|
|
|
mkdir -p "${TRANSFER_DIR}"
|
|
echo ""
|
|
echo "=============================================="
|
|
echo " Transfert de fichiers"
|
|
echo "=============================================="
|
|
echo "Repertoire de staging (deposez vos fichiers) :"
|
|
echo " ${TRANSFER_DIR}"
|
|
echo ""
|
|
|
|
echo "Serveurs disponibles :"
|
|
local counter=0
|
|
declare -A srv_map
|
|
while read -r line; do
|
|
srv_ip=$(echo "${line}" | cut -d ' ' -f 1)
|
|
srv_port=$(echo "${line}" | cut -d ' ' -f 2)
|
|
srv_name=$(echo "${line}" | cut -d ' ' -f 3)
|
|
srv_user=$(echo "${line}" | cut -d ' ' -f 4)
|
|
srv_authmethod=$(echo "${line}" | cut -d ' ' -f 6)
|
|
srv_authfile=$(echo "${line}" | cut -d ' ' -f 7)
|
|
srv_map[${counter}]="${srv_ip} ${srv_port} ${srv_user} ${srv_authmethod} ${srv_authfile} ${srv_name}"
|
|
echo " ${counter}) ${srv_name} - ${srv_user}@${srv_ip}:${srv_port}"
|
|
counter=$((counter + 1))
|
|
done <<< "${USER_SERVERS}"
|
|
|
|
echo ""
|
|
read -r -p "Selectionnez un serveur (0-$((counter-1))) ou 'q' pour quitter : " choice
|
|
if [[ ${choice} == "q" ]]; then
|
|
return
|
|
fi
|
|
if [[ -z ${srv_map[${choice}]} ]]; then
|
|
echo "Selection invalide."
|
|
read -r -p "Appuyez sur Entree pour continuer..."
|
|
return
|
|
fi
|
|
|
|
selected_server="${srv_map[${choice}]}"
|
|
srv_ip=$(echo "${selected_server}" | cut -d ' ' -f 1)
|
|
srv_port=$(echo "${selected_server}" | cut -d ' ' -f 2)
|
|
srv_user=$(echo "${selected_server}" | cut -d ' ' -f 3)
|
|
srv_authmethod=$(echo "${selected_server}" | cut -d ' ' -f 4)
|
|
srv_authfile=$(echo "${selected_server}" | cut -d ' ' -f 5)
|
|
srv_name=$(echo "${selected_server}" | cut -d ' ' -f 6)
|
|
|
|
if [[ -f ${TRANSFER_RIGHTS_FILE} ]] && [[ -s ${TRANSFER_RIGHTS_FILE} ]]; then
|
|
user_allowed=$(awk -v server="${srv_name}" -v user="${CONNECTED_USER}" '
|
|
$1 == server {
|
|
split($2, ulist, ",");
|
|
for (i in ulist) {
|
|
if (ulist[i] == user || ulist[i] == "*") { print "yes"; exit; }
|
|
}
|
|
}
|
|
' "${TRANSFER_RIGHTS_FILE}")
|
|
if [[ -z ${user_allowed} ]]; then
|
|
echo "Vous n'avez pas le droit de transferer des fichiers vers ${srv_name}."
|
|
read -r -p "Appuyez sur Entree pour continuer..."
|
|
return
|
|
fi
|
|
fi
|
|
|
|
echo ""
|
|
echo "1) Upload (bastion -> ${srv_name})"
|
|
echo "2) Download (${srv_name} -> bastion)"
|
|
read -r -p "Choix : " action
|
|
|
|
case "${action}" in
|
|
"1")
|
|
clear
|
|
echo "===== Upload vers ${srv_name} ====="
|
|
echo ""
|
|
echo "Fichiers dans ${TRANSFER_DIR} :"
|
|
ls -la "${TRANSFER_DIR}" 2>/dev/null || echo " (repertoire vide)"
|
|
echo ""
|
|
read -r -p "Chemin source (sur le bastion) : " source_path
|
|
if [[ ! -f ${source_path} ]]; then
|
|
echo "Erreur : le fichier source n'existe pas."
|
|
read -r -p "Appuyez sur Entree pour continuer..."
|
|
return
|
|
fi
|
|
read -r -p "Chemin de destination (sur ${srv_name}) : " dest_path
|
|
if [[ -z ${dest_path} ]]; then
|
|
echo "Erreur : chemin de destination vide."
|
|
read -r -p "Appuyez sur Entree pour continuer..."
|
|
return
|
|
fi
|
|
|
|
local file_size file_name
|
|
file_size=$(stat -c %s "${source_path}" 2>/dev/null || stat -f %z "${source_path}" 2>/dev/null)
|
|
file_name=$(basename "${source_path}")
|
|
|
|
echo ""
|
|
echo "Transfert en cours..."
|
|
if [[ -z ${srv_authmethod} ]]; then
|
|
scp -o StrictHostKeyChecking=accept-new -P "${srv_port}" "${source_path}" "${srv_user}@${srv_ip}:\"${dest_path}\"" 2>&1
|
|
elif [[ ${srv_authmethod} == "key" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
|
|
scp -o StrictHostKeyChecking=accept-new -i "/${AUTHORIZED_SERVERS_PATH}/${srv_authfile}" -P "${srv_port}" "${source_path}" "${srv_user}@${srv_ip}:\"${dest_path}\"" 2>&1
|
|
elif [[ ${srv_authmethod} == "password" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
|
|
sshpass -p "$(cat /${AUTHORIZED_SERVERS_PATH}/${srv_authfile})" scp -o StrictHostKeyChecking=accept-new -P "${srv_port}" "${source_path}" "${srv_user}@${srv_ip}:\"${dest_path}\"" 2>&1
|
|
else
|
|
echo "Erreur d'authentification pour ${srv_name}."
|
|
return
|
|
fi
|
|
if [[ $? -eq 0 ]]; then
|
|
echo ""
|
|
echo "Transfert reussi."
|
|
log_transfer "upload" "${srv_name}" "${dest_path}/${file_name}" "${file_size:-0}" "success"
|
|
else
|
|
echo ""
|
|
echo "Echec du transfert."
|
|
log_transfer "upload" "${srv_name}" "${dest_path}/${file_name}" "${file_size:-0}" "failed"
|
|
fi
|
|
;;
|
|
"2")
|
|
clear
|
|
echo "===== Download depuis ${srv_name} ====="
|
|
echo ""
|
|
|
|
read -r -p "Chemin source (sur ${srv_name}) : " source_path
|
|
if [[ -z ${source_path} ]]; then
|
|
echo "Erreur : chemin source vide."
|
|
read -r -p "Appuyez sur Entree pour continuer..."
|
|
return
|
|
fi
|
|
|
|
echo ""
|
|
echo "Fichiers dans ${TRANSFER_DIR} :"
|
|
ls -la "${TRANSFER_DIR}" 2>/dev/null || echo " (repertoire vide)"
|
|
echo ""
|
|
read -r -p "Nom de destination (dans ${TRANSFER_DIR}) : " dest_name
|
|
if [[ -z ${dest_name} ]]; then
|
|
dest_name=$(basename "${source_path}")
|
|
fi
|
|
dest_name=$(basename "${dest_name}")
|
|
if [[ -z ${dest_name} ]]; then
|
|
echo "Erreur : nom de destination invalide."
|
|
return
|
|
fi
|
|
|
|
local dest_path="${TRANSFER_DIR}/${dest_name}"
|
|
echo ""
|
|
echo "Transfert en cours..."
|
|
if [[ -z ${srv_authmethod} ]]; then
|
|
scp -o StrictHostKeyChecking=accept-new -P "${srv_port}" "${srv_user}@${srv_ip}:\"${source_path}\"" "${dest_path}" 2>&1
|
|
elif [[ ${srv_authmethod} == "key" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
|
|
scp -o StrictHostKeyChecking=accept-new -i "/${AUTHORIZED_SERVERS_PATH}/${srv_authfile}" -P "${srv_port}" "${srv_user}@${srv_ip}:\"${source_path}\"" "${dest_path}" 2>&1
|
|
elif [[ ${srv_authmethod} == "password" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
|
|
sshpass -p "$(cat /${AUTHORIZED_SERVERS_PATH}/${srv_authfile})" scp -o StrictHostKeyChecking=accept-new -P "${srv_port}" "${srv_user}@${srv_ip}:\"${source_path}\"" "${dest_path}" 2>&1
|
|
else
|
|
echo "Erreur d'authentification pour ${srv_name}."
|
|
return
|
|
fi
|
|
if [[ $? -eq 0 ]]; then
|
|
local file_size
|
|
file_size=$(stat -c %s "${dest_path}" 2>/dev/null || stat -f %z "${dest_path}" 2>/dev/null)
|
|
echo ""
|
|
echo "Transfert reussi."
|
|
log_transfer "download" "${srv_name}" "${source_path}" "${file_size:-0}" "success"
|
|
else
|
|
echo ""
|
|
echo "Echec du transfert."
|
|
log_transfer "download" "${srv_name}" "${source_path}" "0" "failed"
|
|
fi
|
|
;;
|
|
*)
|
|
echo "Action invalide."
|
|
;;
|
|
esac
|
|
|
|
read -r -p "Appuyez sur Entree pour continuer..."
|
|
}
|
|
|
|
function main_menu() {
|
|
if [[ -z $choice ]] || [[ ${choice} == "null" ]]; then
|
|
echo "Veuillez sélectionner un serveur auquel vous connecter :"
|
|
fi
|
|
|
|
counter=0
|
|
declare -A server_map
|
|
while read -r line; do
|
|
ip=$(echo "${line}" | cut -d ' ' -f 1)
|
|
port=$(echo "${line}" | cut -d ' ' -f 2)
|
|
custom_name=$(echo "${line}" | cut -d ' ' -f 3)
|
|
server_user=$(echo "${line}" | cut -d ' ' -f 4)
|
|
server_authmethod=$(echo "${line}" | cut -d ' ' -f 6)
|
|
server_auth=$(echo "${line}" | cut -d ' ' -f 7)
|
|
server_map[${counter}]="${ip} ${port} ${server_user} ${server_authmethod} ${server_auth} ${custom_name}"
|
|
if [[ -z $choice ]] || [[ ${choice} == "null" ]]; then
|
|
echo "${counter}) ${custom_name} - ${server_user} ${ip}:${port}"
|
|
fi
|
|
counter=$((counter + 1))
|
|
done <<<"${USER_SERVERS}"
|
|
|
|
if [[ -z $choice ]] || [[ ${choice} == "null" ]]; then
|
|
echo "${counter}) Tapez 'quit' ou ${counter} pour vous déconnecter."
|
|
echo "f) Tapez 'f'<nom de l'hote> pour filtrer les entrées."
|
|
echo "t) Tapez 't' pour transferer des fichiers."
|
|
|
|
read -r -p "Votre choix (0-${counter}) : " choice
|
|
fi
|
|
|
|
if [[ ${choice} == "quit" ]] || [[ ${choice} == "${counter}" ]]; then
|
|
echo "Déconnexion du bastion."
|
|
exit 0
|
|
elif [[ $(echo "${choice}" | cut -c1-1) == "f" ]]; then
|
|
filter=$(echo "${choice}" | cut -c2-)
|
|
find_counter=0
|
|
echo "=====Résultats du filtre====="
|
|
for host in $(printf '%s\n' "${server_map[@]}" | tac | cut -d " " -f 6); do
|
|
if [[ $(echo "${host}" | awk '{print $(NF)}' | grep -m 1 -o "${filter}" | head -1) == $(echo "${filter}") ]]; then
|
|
echo "${find_counter}) $(echo ${server_map[${find_counter}]} | awk '{print $(NF)}') - $(echo ${server_map[${find_counter}]} | cut -d ' ' -f 3) $(echo ${server_map[${find_counter}]} | cut -d ' ' -f 1):$(echo ${server_map[${find_counter}]} | cut -d ' ' -f 2)"
|
|
fi
|
|
find_counter=$((find_counter + 1))
|
|
done
|
|
read -r -p "Votre choix (0-${counter}) : " choice
|
|
elif [[ ${choice} == "t" ]]; then
|
|
clear
|
|
file_transfer_menu
|
|
choice="null"
|
|
elif [[ -z ${choice} ]] || [[ -z ${server_map[${choice}]} ]]; then
|
|
echo "Sélection invalide."
|
|
choice="null"
|
|
else
|
|
clear
|
|
local selected_server
|
|
selected_server="${server_map[${choice}]}"
|
|
echo "Connexion à $(echo "${selected_server}" | cut -d " " -f -3)..."
|
|
if [[ -z "$(echo "${selected_server}" | cut -d ' ' -f 4)" ]]; then
|
|
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
|
|
elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "key" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then
|
|
eval "$(ssh-agent)" >/dev/null
|
|
trap 'kill $SSH_AGENT_PID' EXIT
|
|
cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" | ssh-add - >/dev/null
|
|
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
|
|
ssh-add -D >/dev/null
|
|
elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "password" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then
|
|
local ssh_password
|
|
ssh_password=$(cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)")
|
|
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- sshpass -p "${ssh_password}" ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
|
|
unset ssh_password
|
|
else
|
|
echo -e "Un problème de configuration a été détecté sur \nles options de connexion à l'hôte selectionné.\nVeuillez contacter votre administrateur."
|
|
fi
|
|
choice="null"
|
|
fi
|
|
}
|
|
|
|
while true; do
|
|
main_menu
|
|
clear
|
|
done
|