monosphere-bastion/server_menu.sh
2026-07-05 13:27:54 +02:00

345 lines
16 KiB
Bash

#!/bin/bash
AUTHORIZED_SERVERS_PATH="opt/public/servers"
AUTHORIZED_SERVERS_FILE="/${AUTHORIZED_SERVERS_PATH}/authorized_servers.txt"
CONNECTED_USER="$(whoami)"
USER_SERVERS=$(awk -v user="${CONNECTED_USER}" '
{
split($5, users, ",");
for (i in users) {
if (users[i] == user) {
print $0;
}
}
}' "${AUTHORIZED_SERVERS_FILE}")
if [[ -z ${USER_SERVERS} ]]; then
echo "Vous n'avez pas l'autorisation de vous connecter à un serveur."
exit 1
fi
TRANSFER_DIR="/opt/public/transfer"
TRANSFER_LOG="/var/log/monosphere/transfers.log"
TRANSFER_RIGHTS_FILE="/opt/public/rights/transfer_rights.txt"
mkdir -p "$(dirname "${TRANSFER_LOG}")" 2>/dev/null
touch "${TRANSFER_LOG}" 2>/dev/null
chmod 666 "${TRANSFER_LOG}" 2>/dev/null
if [[ -n ${SSH_ORIGINAL_COMMAND} ]]; then
case "${SSH_ORIGINAL_COMMAND}" in
"stage_file "*)
filename="${SSH_ORIGINAL_COMMAND#stage_file }"
if [[ -z ${filename} ]] || [[ ${filename} =~ [/] ]] || [[ ${filename} == ".." ]] || [[ ${filename} == "." ]]; then
echo "Usage: stage_file <filename> (chemin simple, sans /)"
exit 1
fi
mkdir -p "${TRANSFER_DIR}"
cat > "${TRANSFER_DIR}/${filename}"
size=$(stat -c %s "${TRANSFER_DIR}/${filename}" 2>/dev/null || stat -f %z "${TRANSFER_DIR}/${filename}" 2>/dev/null)
echo "$(date '+%Y-%m-%d %H:%M:%S') USER=${CONNECTED_USER} ACTION=stage FILE=${filename} SIZE=${size:-0} STATUS=success" >> "${TRANSFER_LOG}"
exit 0
;;
"retrieve_file "*)
args="${SSH_ORIGINAL_COMMAND#retrieve_file }"
server_name=$(echo "${args}" | cut -d ' ' -f 1)
remote_path=$(echo "${args}" | cut -d ' ' -f 2-)
if [[ -z ${server_name} ]] || [[ -z ${remote_path} ]]; then
echo "Usage: retrieve_file <server_name> <remote_path>"
exit 1
fi
server_line=$(echo "${USER_SERVERS}" | awk -v name="${server_name}" '$3 == name {print; exit}')
if [[ -z ${server_line} ]]; then
echo "Serveur \"${server_name}\" non trouve ou non autorise."
exit 1
fi
srv_ip=$(echo "${server_line}" | cut -d ' ' -f 1)
srv_port=$(echo "${server_line}" | cut -d ' ' -f 2)
srv_user=$(echo "${server_line}" | cut -d ' ' -f 4)
srv_authmethod=$(echo "${server_line}" | cut -d ' ' -f 6)
srv_authfile=$(echo "${server_line}" | cut -d ' ' -f 7)
if [[ -z ${srv_authmethod} ]]; then
ssh -T -o StrictHostKeyChecking=accept-new -p "${srv_port}" "${srv_user}@${srv_ip}" "cat '${remote_path}'" < /dev/null
elif [[ ${srv_authmethod} == "key" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
ssh -T -o StrictHostKeyChecking=accept-new -i "/${AUTHORIZED_SERVERS_PATH}/${srv_authfile}" -p "${srv_port}" "${srv_user}@${srv_ip}" "cat '${remote_path}'" < /dev/null
elif [[ ${srv_authmethod} == "password" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
sshpass -p "$(cat /${AUTHORIZED_SERVERS_PATH}/${srv_authfile})" ssh -T -o StrictHostKeyChecking=accept-new -p "${srv_port}" "${srv_user}@${srv_ip}" "cat '${remote_path}'" < /dev/null
else
echo "Erreur d'authentification pour le serveur ${server_name}."
exit 1
fi
exit_code=$?
if [[ ${exit_code} -eq 0 ]]; then
echo "$(date '+%Y-%m-%d %H:%M:%S') USER=${CONNECTED_USER} ACTION=retrieve SERVER=${server_name} FILE=${remote_path} STATUS=success" >> "${TRANSFER_LOG}"
else
echo "$(date '+%Y-%m-%d %H:%M:%S') USER=${CONNECTED_USER} ACTION=retrieve SERVER=${server_name} FILE=${remote_path} STATUS=failed" >> "${TRANSFER_LOG}"
fi
exit ${exit_code}
;;
*)
echo "Commande non reconnue: ${SSH_ORIGINAL_COMMAND}"
echo "Commandes supportees: stage_file <filename>, retrieve_file <server_name> <remote_path>"
exit 1
;;
esac
fi
log_transfer() {
local action="$1" server="$2" path="$3" size="$4" status="$5"
echo "$(date '+%Y-%m-%d %H:%M:%S') USER=${CONNECTED_USER} ACTION=${action} SERVER=${server} FILE=${path} SIZE=${size} STATUS=${status}" >> "${TRANSFER_LOG}"
}
file_transfer_menu() {
local choice action srv_line srv_name srv_ip srv_port srv_user selected_server
mkdir -p "${TRANSFER_DIR}"
echo ""
echo "=============================================="
echo " Transfert de fichiers"
echo "=============================================="
echo "Repertoire de staging (deposez vos fichiers) :"
echo " ${TRANSFER_DIR}"
echo ""
echo "Serveurs disponibles :"
local counter=0
declare -A srv_map
while read -r line; do
srv_ip=$(echo "${line}" | cut -d ' ' -f 1)
srv_port=$(echo "${line}" | cut -d ' ' -f 2)
srv_name=$(echo "${line}" | cut -d ' ' -f 3)
srv_user=$(echo "${line}" | cut -d ' ' -f 4)
srv_authmethod=$(echo "${line}" | cut -d ' ' -f 6)
srv_authfile=$(echo "${line}" | cut -d ' ' -f 7)
srv_map[${counter}]="${srv_ip} ${srv_port} ${srv_user} ${srv_authmethod} ${srv_authfile} ${srv_name}"
echo " ${counter}) ${srv_name} - ${srv_user}@${srv_ip}:${srv_port}"
counter=$((counter + 1))
done <<< "${USER_SERVERS}"
echo ""
read -r -p "Selectionnez un serveur (0-$((counter-1))) ou 'q' pour quitter : " choice
if [[ ${choice} == "q" ]]; then
return
fi
if [[ -z ${srv_map[${choice}]} ]]; then
echo "Selection invalide."
read -r -p "Appuyez sur Entree pour continuer..."
return
fi
selected_server="${srv_map[${choice}]}"
srv_ip=$(echo "${selected_server}" | cut -d ' ' -f 1)
srv_port=$(echo "${selected_server}" | cut -d ' ' -f 2)
srv_user=$(echo "${selected_server}" | cut -d ' ' -f 3)
srv_authmethod=$(echo "${selected_server}" | cut -d ' ' -f 4)
srv_authfile=$(echo "${selected_server}" | cut -d ' ' -f 5)
srv_name=$(echo "${selected_server}" | cut -d ' ' -f 6)
if [[ -f ${TRANSFER_RIGHTS_FILE} ]] && [[ -s ${TRANSFER_RIGHTS_FILE} ]]; then
user_allowed=$(awk -v server="${srv_name}" -v user="${CONNECTED_USER}" '
$1 == server {
split($2, ulist, ",");
for (i in ulist) {
if (ulist[i] == user || ulist[i] == "*") { print "yes"; exit; }
}
}
' "${TRANSFER_RIGHTS_FILE}")
if [[ -z ${user_allowed} ]]; then
echo "Vous n'avez pas le droit de transferer des fichiers vers ${srv_name}."
read -r -p "Appuyez sur Entree pour continuer..."
return
fi
fi
echo ""
echo "1) Upload (bastion -> ${srv_name})"
echo "2) Download (${srv_name} -> bastion)"
read -r -p "Choix : " action
case "${action}" in
"1")
clear
echo "===== Upload vers ${srv_name} ====="
echo ""
echo "Fichiers dans ${TRANSFER_DIR} :"
ls -la "${TRANSFER_DIR}" 2>/dev/null || echo " (repertoire vide)"
echo ""
read -r -p "Chemin source (sur le bastion) : " source_path
if [[ ! -f ${source_path} ]]; then
echo "Erreur : le fichier source n'existe pas."
read -r -p "Appuyez sur Entree pour continuer..."
return
fi
read -r -p "Chemin de destination (sur ${srv_name}) : " dest_path
if [[ -z ${dest_path} ]]; then
echo "Erreur : chemin de destination vide."
read -r -p "Appuyez sur Entree pour continuer..."
return
fi
local file_size file_name
file_size=$(stat -c %s "${source_path}" 2>/dev/null || stat -f %z "${source_path}" 2>/dev/null)
file_name=$(basename "${source_path}")
echo ""
echo "Transfert en cours..."
if [[ -z ${srv_authmethod} ]]; then
scp -o StrictHostKeyChecking=accept-new -P "${srv_port}" "${source_path}" "${srv_user}@${srv_ip}:\"${dest_path}\"" 2>&1
elif [[ ${srv_authmethod} == "key" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
scp -o StrictHostKeyChecking=accept-new -i "/${AUTHORIZED_SERVERS_PATH}/${srv_authfile}" -P "${srv_port}" "${source_path}" "${srv_user}@${srv_ip}:\"${dest_path}\"" 2>&1
elif [[ ${srv_authmethod} == "password" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
sshpass -p "$(cat /${AUTHORIZED_SERVERS_PATH}/${srv_authfile})" scp -o StrictHostKeyChecking=accept-new -P "${srv_port}" "${source_path}" "${srv_user}@${srv_ip}:\"${dest_path}\"" 2>&1
else
echo "Erreur d'authentification pour ${srv_name}."
return
fi
if [[ $? -eq 0 ]]; then
echo ""
echo "Transfert reussi."
log_transfer "upload" "${srv_name}" "${dest_path}/${file_name}" "${file_size:-0}" "success"
else
echo ""
echo "Echec du transfert."
log_transfer "upload" "${srv_name}" "${dest_path}/${file_name}" "${file_size:-0}" "failed"
fi
;;
"2")
clear
echo "===== Download depuis ${srv_name} ====="
echo ""
read -r -p "Chemin source (sur ${srv_name}) : " source_path
if [[ -z ${source_path} ]]; then
echo "Erreur : chemin source vide."
read -r -p "Appuyez sur Entree pour continuer..."
return
fi
echo ""
echo "Fichiers dans ${TRANSFER_DIR} :"
ls -la "${TRANSFER_DIR}" 2>/dev/null || echo " (repertoire vide)"
echo ""
read -r -p "Nom de destination (dans ${TRANSFER_DIR}) : " dest_name
if [[ -z ${dest_name} ]]; then
dest_name=$(basename "${source_path}")
fi
dest_name=$(basename "${dest_name}")
if [[ -z ${dest_name} ]]; then
echo "Erreur : nom de destination invalide."
return
fi
local dest_path="${TRANSFER_DIR}/${dest_name}"
echo ""
echo "Transfert en cours..."
if [[ -z ${srv_authmethod} ]]; then
scp -o StrictHostKeyChecking=accept-new -P "${srv_port}" "${srv_user}@${srv_ip}:\"${source_path}\"" "${dest_path}" 2>&1
elif [[ ${srv_authmethod} == "key" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
scp -o StrictHostKeyChecking=accept-new -i "/${AUTHORIZED_SERVERS_PATH}/${srv_authfile}" -P "${srv_port}" "${srv_user}@${srv_ip}:\"${source_path}\"" "${dest_path}" 2>&1
elif [[ ${srv_authmethod} == "password" ]] && [[ -f /${AUTHORIZED_SERVERS_PATH}/${srv_authfile} ]]; then
sshpass -p "$(cat /${AUTHORIZED_SERVERS_PATH}/${srv_authfile})" scp -o StrictHostKeyChecking=accept-new -P "${srv_port}" "${srv_user}@${srv_ip}:\"${source_path}\"" "${dest_path}" 2>&1
else
echo "Erreur d'authentification pour ${srv_name}."
return
fi
if [[ $? -eq 0 ]]; then
local file_size
file_size=$(stat -c %s "${dest_path}" 2>/dev/null || stat -f %z "${dest_path}" 2>/dev/null)
echo ""
echo "Transfert reussi."
log_transfer "download" "${srv_name}" "${source_path}" "${file_size:-0}" "success"
else
echo ""
echo "Echec du transfert."
log_transfer "download" "${srv_name}" "${source_path}" "0" "failed"
fi
;;
*)
echo "Action invalide."
;;
esac
read -r -p "Appuyez sur Entree pour continuer..."
}
function main_menu() {
if [[ -z $choice ]] || [[ ${choice} == "null" ]]; then
echo "Veuillez sélectionner un serveur auquel vous connecter :"
fi
counter=0
declare -A server_map
while read -r line; do
ip=$(echo "${line}" | cut -d ' ' -f 1)
port=$(echo "${line}" | cut -d ' ' -f 2)
custom_name=$(echo "${line}" | cut -d ' ' -f 3)
server_user=$(echo "${line}" | cut -d ' ' -f 4)
server_authmethod=$(echo "${line}" | cut -d ' ' -f 6)
server_auth=$(echo "${line}" | cut -d ' ' -f 7)
server_map[${counter}]="${ip} ${port} ${server_user} ${server_authmethod} ${server_auth} ${custom_name}"
if [[ -z $choice ]] || [[ ${choice} == "null" ]]; then
echo "${counter}) ${custom_name} - ${server_user} ${ip}:${port}"
fi
counter=$((counter + 1))
done <<<"${USER_SERVERS}"
if [[ -z $choice ]] || [[ ${choice} == "null" ]]; then
echo "${counter}) Tapez 'quit' ou ${counter} pour vous déconnecter."
echo "f) Tapez 'f'<nom de l'hote> pour filtrer les entrées."
echo "t) Tapez 't' pour transferer des fichiers."
read -r -p "Votre choix (0-${counter}) : " choice
fi
if [[ ${choice} == "quit" ]] || [[ ${choice} == "${counter}" ]]; then
echo "Déconnexion du bastion."
exit 0
elif [[ $(echo "${choice}" | cut -c1-1) == "f" ]]; then
filter=$(echo "${choice}" | cut -c2-)
find_counter=0
echo "=====Résultats du filtre====="
for host in $(printf '%s\n' "${server_map[@]}" | tac | cut -d " " -f 6); do
if [[ $(echo "${host}" | awk '{print $(NF)}' | grep -m 1 -o "${filter}" | head -1) == $(echo "${filter}") ]]; then
echo "${find_counter}) $(echo ${server_map[${find_counter}]} | awk '{print $(NF)}') - $(echo ${server_map[${find_counter}]} | cut -d ' ' -f 3) $(echo ${server_map[${find_counter}]} | cut -d ' ' -f 1):$(echo ${server_map[${find_counter}]} | cut -d ' ' -f 2)"
fi
find_counter=$((find_counter + 1))
done
read -r -p "Votre choix (0-${counter}) : " choice
elif [[ ${choice} == "t" ]]; then
clear
file_transfer_menu
choice="null"
elif [[ -z ${choice} ]] || [[ -z ${server_map[${choice}]} ]]; then
echo "Sélection invalide."
choice="null"
else
clear
local selected_server
selected_server="${server_map[${choice}]}"
echo "Connexion à $(echo "${selected_server}" | cut -d " " -f -3)..."
if [[ -z "$(echo "${selected_server}" | cut -d ' ' -f 4)" ]]; then
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "key" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then
eval "$(ssh-agent)" >/dev/null
trap 'kill $SSH_AGENT_PID' EXIT
cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" | ssh-add - >/dev/null
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
ssh-add -D >/dev/null
elif [[ "$(echo "${selected_server}" | cut -d ' ' -f 4)" == "password" ]] && [[ -f /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)" ]]; then
local ssh_password
ssh_password=$(cat /"${AUTHORIZED_SERVERS_PATH}"/"$(echo "${selected_server}" | cut -d ' ' -f 5)")
ttyrec -z --"$(echo "${selected_server}" | cut -d ' ' -f 1)"-"$(echo "${selected_server}" | cut -d ' ' -f 3)"-- -k 300 --warn-before-kill 60 -- sshpass -p "${ssh_password}" ssh -o StrictHostKeyChecking=accept-new -p "$(echo "${selected_server}" | cut -d ' ' -f 2)" "$(echo "${selected_server}" | cut -d ' ' -f 3)"@"$(echo "${selected_server}" | cut -d ' ' -f 1)"
unset ssh_password
else
echo -e "Un problème de configuration a été détecté sur \nles options de connexion à l'hôte selectionné.\nVeuillez contacter votre administrateur."
fi
choice="null"
fi
}
while true; do
main_menu
clear
done