Application.php 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272
  1. <?php
  2. declare(strict_types=1);
  3. /**
  4. * SPDX-FileCopyrightText: 2017 Nextcloud GmbH and Nextcloud contributors
  5. * SPDX-License-Identifier: AGPL-3.0-or-later
  6. */
  7. namespace OCA\AdminAudit\AppInfo;
  8. use OC\Group\Manager as GroupManager;
  9. use OC\User\Session as UserSession;
  10. use OCA\AdminAudit\Actions\AppManagement;
  11. use OCA\AdminAudit\Actions\Auth;
  12. use OCA\AdminAudit\Actions\Console;
  13. use OCA\AdminAudit\Actions\Files;
  14. use OCA\AdminAudit\Actions\GroupManagement;
  15. use OCA\AdminAudit\Actions\Security;
  16. use OCA\AdminAudit\Actions\Sharing;
  17. use OCA\AdminAudit\Actions\TagManagement;
  18. use OCA\AdminAudit\Actions\Trashbin;
  19. use OCA\AdminAudit\Actions\UserManagement;
  20. use OCA\AdminAudit\Actions\Versions;
  21. use OCA\AdminAudit\AuditLogger;
  22. use OCA\AdminAudit\IAuditLogger;
  23. use OCA\AdminAudit\Listener\CriticalActionPerformedEventListener;
  24. use OCP\App\ManagerEvent;
  25. use OCP\AppFramework\App;
  26. use OCP\AppFramework\Bootstrap\IBootContext;
  27. use OCP\AppFramework\Bootstrap\IBootstrap;
  28. use OCP\AppFramework\Bootstrap\IRegistrationContext;
  29. use OCP\Authentication\TwoFactorAuth\TwoFactorProviderChallengeFailed;
  30. use OCP\Authentication\TwoFactorAuth\TwoFactorProviderChallengePassed;
  31. use OCP\Console\ConsoleEvent;
  32. use OCP\EventDispatcher\IEventDispatcher;
  33. use OCP\Files\Events\Node\BeforeNodeReadEvent;
  34. use OCP\Files\Events\Node\BeforeNodeRenamedEvent;
  35. use OCP\Files\Events\Node\BeforeNodeWrittenEvent;
  36. use OCP\Files\Events\Node\NodeCopiedEvent;
  37. use OCP\Files\Events\Node\NodeCreatedEvent;
  38. use OCP\Files\Events\Node\NodeDeletedEvent;
  39. use OCP\Files\Events\Node\NodeRenamedEvent;
  40. use OCP\Files\Events\Node\NodeWrittenEvent;
  41. use OCP\IConfig;
  42. use OCP\IGroupManager;
  43. use OCP\IUserSession;
  44. use OCP\Log\Audit\CriticalActionPerformedEvent;
  45. use OCP\Log\ILogFactory;
  46. use OCP\Preview\BeforePreviewFetchedEvent;
  47. use OCP\Share;
  48. use OCP\Util;
  49. use Psr\Container\ContainerInterface;
  50. use Psr\Log\LoggerInterface;
  51. class Application extends App implements IBootstrap {
  52. /** @var LoggerInterface */
  53. protected $logger;
  54. public function __construct() {
  55. parent::__construct('admin_audit');
  56. }
  57. public function register(IRegistrationContext $context): void {
  58. $context->registerService(IAuditLogger::class, function (ContainerInterface $c) {
  59. return new AuditLogger($c->get(ILogFactory::class), $c->get(IConfig::class));
  60. });
  61. $context->registerEventListener(CriticalActionPerformedEvent::class, CriticalActionPerformedEventListener::class);
  62. }
  63. public function boot(IBootContext $context): void {
  64. /** @var IAuditLogger $logger */
  65. $logger = $context->getAppContainer()->get(IAuditLogger::class);
  66. /*
  67. * TODO: once the hooks are migrated to lazy events, this should be done
  68. * in \OCA\AdminAudit\AppInfo\Application::register
  69. */
  70. $this->registerHooks($logger, $context->getServerContainer());
  71. }
  72. /**
  73. * Register hooks in order to log them
  74. */
  75. private function registerHooks(IAuditLogger $logger,
  76. ContainerInterface $serverContainer): void {
  77. $this->userManagementHooks($logger, $serverContainer->get(IUserSession::class));
  78. $this->groupHooks($logger, $serverContainer->get(IGroupManager::class));
  79. $this->authHooks($logger);
  80. /** @var IEventDispatcher $eventDispatcher */
  81. $eventDispatcher = $serverContainer->get(IEventDispatcher::class);
  82. $this->consoleHooks($logger, $eventDispatcher);
  83. $this->appHooks($logger, $eventDispatcher);
  84. $this->sharingHooks($logger);
  85. $this->fileHooks($logger, $eventDispatcher);
  86. $this->trashbinHooks($logger);
  87. $this->versionsHooks($logger);
  88. $this->securityHooks($logger, $eventDispatcher);
  89. $this->tagHooks($logger, $eventDispatcher);
  90. }
  91. private function userManagementHooks(IAuditLogger $logger,
  92. IUserSession $userSession): void {
  93. $userActions = new UserManagement($logger);
  94. Util::connectHook('OC_User', 'post_createUser', $userActions, 'create');
  95. Util::connectHook('OC_User', 'post_deleteUser', $userActions, 'delete');
  96. Util::connectHook('OC_User', 'changeUser', $userActions, 'change');
  97. assert($userSession instanceof UserSession);
  98. $userSession->listen('\OC\User', 'postSetPassword', [$userActions, 'setPassword']);
  99. $userSession->listen('\OC\User', 'assignedUserId', [$userActions, 'assign']);
  100. $userSession->listen('\OC\User', 'postUnassignedUserId', [$userActions, 'unassign']);
  101. }
  102. private function groupHooks(IAuditLogger $logger,
  103. IGroupManager $groupManager): void {
  104. $groupActions = new GroupManagement($logger);
  105. assert($groupManager instanceof GroupManager);
  106. $groupManager->listen('\OC\Group', 'postRemoveUser', [$groupActions, 'removeUser']);
  107. $groupManager->listen('\OC\Group', 'postAddUser', [$groupActions, 'addUser']);
  108. $groupManager->listen('\OC\Group', 'postDelete', [$groupActions, 'deleteGroup']);
  109. $groupManager->listen('\OC\Group', 'postCreate', [$groupActions, 'createGroup']);
  110. }
  111. private function sharingHooks(IAuditLogger $logger): void {
  112. $shareActions = new Sharing($logger);
  113. Util::connectHook(Share::class, 'post_shared', $shareActions, 'shared');
  114. Util::connectHook(Share::class, 'post_unshare', $shareActions, 'unshare');
  115. Util::connectHook(Share::class, 'post_unshareFromSelf', $shareActions, 'unshare');
  116. Util::connectHook(Share::class, 'post_update_permissions', $shareActions, 'updatePermissions');
  117. Util::connectHook(Share::class, 'post_update_password', $shareActions, 'updatePassword');
  118. Util::connectHook(Share::class, 'post_set_expiration_date', $shareActions, 'updateExpirationDate');
  119. Util::connectHook(Share::class, 'share_link_access', $shareActions, 'shareAccessed');
  120. }
  121. private function authHooks(IAuditLogger $logger): void {
  122. $authActions = new Auth($logger);
  123. Util::connectHook('OC_User', 'pre_login', $authActions, 'loginAttempt');
  124. Util::connectHook('OC_User', 'post_login', $authActions, 'loginSuccessful');
  125. Util::connectHook('OC_User', 'logout', $authActions, 'logout');
  126. }
  127. private function appHooks(IAuditLogger $logger,
  128. IEventDispatcher $eventDispatcher): void {
  129. $eventDispatcher->addListener(ManagerEvent::EVENT_APP_ENABLE, function (ManagerEvent $event) use ($logger) {
  130. $appActions = new AppManagement($logger);
  131. $appActions->enableApp($event->getAppID());
  132. });
  133. $eventDispatcher->addListener(ManagerEvent::EVENT_APP_ENABLE_FOR_GROUPS, function (ManagerEvent $event) use ($logger) {
  134. $appActions = new AppManagement($logger);
  135. $appActions->enableAppForGroups($event->getAppID(), $event->getGroups());
  136. });
  137. $eventDispatcher->addListener(ManagerEvent::EVENT_APP_DISABLE, function (ManagerEvent $event) use ($logger) {
  138. $appActions = new AppManagement($logger);
  139. $appActions->disableApp($event->getAppID());
  140. });
  141. }
  142. private function consoleHooks(IAuditLogger $logger,
  143. IEventDispatcher $eventDispatcher): void {
  144. $eventDispatcher->addListener(ConsoleEvent::class, function (ConsoleEvent $event) use ($logger) {
  145. $appActions = new Console($logger);
  146. $appActions->runCommand($event->getArguments());
  147. });
  148. }
  149. private function tagHooks(IAuditLogger $logger,
  150. IEventDispatcher $eventDispatcher): void {
  151. $eventDispatcher->addListener(\OCP\SystemTag\ManagerEvent::EVENT_CREATE, function (\OCP\SystemTag\ManagerEvent $event) use ($logger) {
  152. $tagActions = new TagManagement($logger);
  153. $tagActions->createTag($event->getTag());
  154. });
  155. }
  156. private function fileHooks(IAuditLogger $logger,
  157. IEventDispatcher $eventDispatcher): void {
  158. $fileActions = new Files($logger);
  159. $eventDispatcher->addListener(
  160. BeforePreviewFetchedEvent::class,
  161. function (BeforePreviewFetchedEvent $event) use ($fileActions) {
  162. $fileActions->preview($event);
  163. }
  164. );
  165. $eventDispatcher->addListener(
  166. BeforeNodeRenamedEvent::class,
  167. function (BeforeNodeRenamedEvent $event) use ($fileActions) {
  168. $fileActions->beforeRename($event);
  169. }
  170. );
  171. $eventDispatcher->addListener(
  172. NodeRenamedEvent::class,
  173. function (NodeRenamedEvent $event) use ($fileActions) {
  174. $fileActions->afterRename($event);
  175. }
  176. );
  177. $eventDispatcher->addListener(
  178. NodeCreatedEvent::class,
  179. function (NodeCreatedEvent $event) use ($fileActions) {
  180. $fileActions->create($event);
  181. }
  182. );
  183. $eventDispatcher->addListener(
  184. NodeCopiedEvent::class,
  185. function (NodeCopiedEvent $event) use ($fileActions) {
  186. $fileActions->copy($event);
  187. }
  188. );
  189. $eventDispatcher->addListener(
  190. BeforeNodeWrittenEvent::class,
  191. function (BeforeNodeWrittenEvent $event) use ($fileActions) {
  192. $fileActions->write($event);
  193. }
  194. );
  195. $eventDispatcher->addListener(
  196. NodeWrittenEvent::class,
  197. function (NodeWrittenEvent $event) use ($fileActions) {
  198. $fileActions->update($event);
  199. }
  200. );
  201. $eventDispatcher->addListener(
  202. BeforeNodeReadEvent::class,
  203. function (BeforeNodeReadEvent $event) use ($fileActions) {
  204. $fileActions->read($event);
  205. }
  206. );
  207. $eventDispatcher->addListener(
  208. NodeDeletedEvent::class,
  209. function (NodeDeletedEvent $event) use ($fileActions) {
  210. $fileActions->delete($event);
  211. }
  212. );
  213. }
  214. private function versionsHooks(IAuditLogger $logger): void {
  215. $versionsActions = new Versions($logger);
  216. Util::connectHook('\OCP\Versions', 'rollback', $versionsActions, 'rollback');
  217. Util::connectHook('\OCP\Versions', 'delete', $versionsActions, 'delete');
  218. }
  219. private function trashbinHooks(IAuditLogger $logger): void {
  220. $trashActions = new Trashbin($logger);
  221. Util::connectHook('\OCP\Trashbin', 'preDelete', $trashActions, 'delete');
  222. Util::connectHook('\OCA\Files_Trashbin\Trashbin', 'post_restore', $trashActions, 'restore');
  223. }
  224. private function securityHooks(IAuditLogger $logger,
  225. IEventDispatcher $eventDispatcher): void {
  226. $eventDispatcher->addListener(TwoFactorProviderChallengePassed::class, function (TwoFactorProviderChallengePassed $event) use ($logger) {
  227. $security = new Security($logger);
  228. $security->twofactorSuccess($event->getUser(), $event->getProvider());
  229. });
  230. $eventDispatcher->addListener(TwoFactorProviderChallengeFailed::class, function (TwoFactorProviderChallengeFailed $event) use ($logger) {
  231. $security = new Security($logger);
  232. $security->twofactorFailed($event->getUser(), $event->getProvider());
  233. });
  234. }
  235. }