Application.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285
  1. <?php
  2. declare(strict_types=1);
  3. /**
  4. * @copyright Copyright (c) 2017 Joas Schilling <coding@schilljs.com>
  5. *
  6. * @author Arthur Schiwon <blizzz@arthur-schiwon.de>
  7. * @author Bjoern Schiessle <bjoern@schiessle.org>
  8. * @author Christoph Wurst <christoph@winzerhof-wurst.at>
  9. * @author Daniel Kesselberg <mail@danielkesselberg.de>
  10. * @author GrayFix <grayfix@gmail.com>
  11. * @author Joas Schilling <coding@schilljs.com>
  12. * @author Morris Jobke <hey@morrisjobke.de>
  13. * @author Roeland Jago Douma <roeland@famdouma.nl>
  14. * @author Tiago Flores <tiago.flores@yahoo.com.br>
  15. *
  16. * @license GNU AGPL version 3 or any later version
  17. *
  18. * This program is free software: you can redistribute it and/or modify
  19. * it under the terms of the GNU Affero General Public License as
  20. * published by the Free Software Foundation, either version 3 of the
  21. * License, or (at your option) any later version.
  22. *
  23. * This program is distributed in the hope that it will be useful,
  24. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  25. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  26. * GNU Affero General Public License for more details.
  27. *
  28. * You should have received a copy of the GNU Affero General Public License
  29. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  30. *
  31. */
  32. namespace OCA\AdminAudit\AppInfo;
  33. use OC\Files\Filesystem;
  34. use OC\Group\Manager as GroupManager;
  35. use OC\User\Session as UserSession;
  36. use OCA\AdminAudit\Actions\AppManagement;
  37. use OCA\AdminAudit\Actions\Auth;
  38. use OCA\AdminAudit\Actions\Console;
  39. use OCA\AdminAudit\Actions\Files;
  40. use OCA\AdminAudit\Actions\GroupManagement;
  41. use OCA\AdminAudit\Actions\Security;
  42. use OCA\AdminAudit\Actions\Sharing;
  43. use OCA\AdminAudit\Actions\Trashbin;
  44. use OCA\AdminAudit\Actions\UserManagement;
  45. use OCA\AdminAudit\Actions\Versions;
  46. use OCA\AdminAudit\AuditLogger;
  47. use OCA\AdminAudit\IAuditLogger;
  48. use OCA\AdminAudit\Listener\CriticalActionPerformedEventListener;
  49. use OCP\App\ManagerEvent;
  50. use OCP\AppFramework\App;
  51. use OCP\AppFramework\Bootstrap\IBootContext;
  52. use OCP\AppFramework\Bootstrap\IBootstrap;
  53. use OCP\AppFramework\Bootstrap\IRegistrationContext;
  54. use OCP\Authentication\TwoFactorAuth\TwoFactorProviderChallengeFailed;
  55. use OCP\Authentication\TwoFactorAuth\TwoFactorProviderChallengePassed;
  56. use OCP\Console\ConsoleEvent;
  57. use OCP\EventDispatcher\IEventDispatcher;
  58. use OCP\IConfig;
  59. use OCP\IGroupManager;
  60. use OCP\IUserSession;
  61. use OCP\Log\Audit\CriticalActionPerformedEvent;
  62. use OCP\Log\ILogFactory;
  63. use OCP\Preview\BeforePreviewFetchedEvent;
  64. use OCP\Share;
  65. use OCP\Util;
  66. use Psr\Container\ContainerInterface;
  67. use Psr\Log\LoggerInterface;
  68. class Application extends App implements IBootstrap {
  69. /** @var LoggerInterface */
  70. protected $logger;
  71. public function __construct() {
  72. parent::__construct('admin_audit');
  73. }
  74. public function register(IRegistrationContext $context): void {
  75. $context->registerService(IAuditLogger::class, function (ContainerInterface $c) {
  76. return new AuditLogger($c->get(ILogFactory::class), $c->get(IConfig::class));
  77. });
  78. $context->registerEventListener(CriticalActionPerformedEvent::class, CriticalActionPerformedEventListener::class);
  79. }
  80. public function boot(IBootContext $context): void {
  81. /** @var IAuditLogger $logger */
  82. $logger = $context->getAppContainer()->get(IAuditLogger::class);
  83. /*
  84. * TODO: once the hooks are migrated to lazy events, this should be done
  85. * in \OCA\AdminAudit\AppInfo\Application::register
  86. */
  87. $this->registerHooks($logger, $context->getServerContainer());
  88. }
  89. /**
  90. * Register hooks in order to log them
  91. */
  92. private function registerHooks(IAuditLogger $logger,
  93. ContainerInterface $serverContainer): void {
  94. $this->userManagementHooks($logger, $serverContainer->get(IUserSession::class));
  95. $this->groupHooks($logger, $serverContainer->get(IGroupManager::class));
  96. $this->authHooks($logger);
  97. /** @var IEventDispatcher $eventDispatcher */
  98. $eventDispatcher = $serverContainer->get(IEventDispatcher::class);
  99. $this->consoleHooks($logger, $eventDispatcher);
  100. $this->appHooks($logger, $eventDispatcher);
  101. $this->sharingHooks($logger);
  102. $this->fileHooks($logger, $eventDispatcher);
  103. $this->trashbinHooks($logger);
  104. $this->versionsHooks($logger);
  105. $this->securityHooks($logger, $eventDispatcher);
  106. $this->tagHooks($logger, $eventDispatcher);
  107. }
  108. private function userManagementHooks(IAuditLogger $logger,
  109. IUserSession $userSession): void {
  110. $userActions = new UserManagement($logger);
  111. Util::connectHook('OC_User', 'post_createUser', $userActions, 'create');
  112. Util::connectHook('OC_User', 'post_deleteUser', $userActions, 'delete');
  113. Util::connectHook('OC_User', 'changeUser', $userActions, 'change');
  114. assert($userSession instanceof UserSession);
  115. $userSession->listen('\OC\User', 'postSetPassword', [$userActions, 'setPassword']);
  116. $userSession->listen('\OC\User', 'assignedUserId', [$userActions, 'assign']);
  117. $userSession->listen('\OC\User', 'postUnassignedUserId', [$userActions, 'unassign']);
  118. }
  119. private function groupHooks(IAuditLogger $logger,
  120. IGroupManager $groupManager): void {
  121. $groupActions = new GroupManagement($logger);
  122. assert($groupManager instanceof GroupManager);
  123. $groupManager->listen('\OC\Group', 'postRemoveUser', [$groupActions, 'removeUser']);
  124. $groupManager->listen('\OC\Group', 'postAddUser', [$groupActions, 'addUser']);
  125. $groupManager->listen('\OC\Group', 'postDelete', [$groupActions, 'deleteGroup']);
  126. $groupManager->listen('\OC\Group', 'postCreate', [$groupActions, 'createGroup']);
  127. }
  128. private function sharingHooks(IAuditLogger $logger): void {
  129. $shareActions = new Sharing($logger);
  130. Util::connectHook(Share::class, 'post_shared', $shareActions, 'shared');
  131. Util::connectHook(Share::class, 'post_unshare', $shareActions, 'unshare');
  132. Util::connectHook(Share::class, 'post_unshareFromSelf', $shareActions, 'unshare');
  133. Util::connectHook(Share::class, 'post_update_permissions', $shareActions, 'updatePermissions');
  134. Util::connectHook(Share::class, 'post_update_password', $shareActions, 'updatePassword');
  135. Util::connectHook(Share::class, 'post_set_expiration_date', $shareActions, 'updateExpirationDate');
  136. Util::connectHook(Share::class, 'share_link_access', $shareActions, 'shareAccessed');
  137. }
  138. private function authHooks(IAuditLogger $logger): void {
  139. $authActions = new Auth($logger);
  140. Util::connectHook('OC_User', 'pre_login', $authActions, 'loginAttempt');
  141. Util::connectHook('OC_User', 'post_login', $authActions, 'loginSuccessful');
  142. Util::connectHook('OC_User', 'logout', $authActions, 'logout');
  143. }
  144. private function appHooks(IAuditLogger $logger,
  145. IEventDispatcher $eventDispatcher): void {
  146. $eventDispatcher->addListener(ManagerEvent::EVENT_APP_ENABLE, function (ManagerEvent $event) use ($logger) {
  147. $appActions = new AppManagement($logger);
  148. $appActions->enableApp($event->getAppID());
  149. });
  150. $eventDispatcher->addListener(ManagerEvent::EVENT_APP_ENABLE_FOR_GROUPS, function (ManagerEvent $event) use ($logger) {
  151. $appActions = new AppManagement($logger);
  152. $appActions->enableAppForGroups($event->getAppID(), $event->getGroups());
  153. });
  154. $eventDispatcher->addListener(ManagerEvent::EVENT_APP_DISABLE, function (ManagerEvent $event) use ($logger) {
  155. $appActions = new AppManagement($logger);
  156. $appActions->disableApp($event->getAppID());
  157. });
  158. }
  159. private function consoleHooks(IAuditLogger $logger,
  160. IEventDispatcher $eventDispatcher): void {
  161. $eventDispatcher->addListener(ConsoleEvent::class, function (ConsoleEvent $event) use ($logger) {
  162. $appActions = new Console($logger);
  163. $appActions->runCommand($event->getArguments());
  164. });
  165. }
  166. private function tagHooks(IAuditLogger $logger,
  167. IEventDispatcher $eventDispatcher): void {
  168. $eventDispatcher->addListener(\OCP\SystemTag\ManagerEvent::EVENT_CREATE, function (\OCP\SystemTag\ManagerEvent $event) use ($logger) {
  169. $appActions = new Console($logger);
  170. $appActions->runCommand([$event->getTag()->getName()]);
  171. });
  172. }
  173. private function fileHooks(IAuditLogger $logger,
  174. IEventDispatcher $eventDispatcher): void {
  175. $fileActions = new Files($logger);
  176. $eventDispatcher->addListener(
  177. BeforePreviewFetchedEvent::class,
  178. function (BeforePreviewFetchedEvent $event) use ($fileActions) {
  179. $file = $event->getNode();
  180. $fileActions->preview([
  181. 'path' => mb_substr($file->getInternalPath(), 5),
  182. 'width' => $event->getWidth(),
  183. 'height' => $event->getHeight(),
  184. 'crop' => $event->isCrop(),
  185. 'mode' => $event->getMode()
  186. ]);
  187. }
  188. );
  189. Util::connectHook(
  190. Filesystem::CLASSNAME,
  191. Filesystem::signal_post_rename,
  192. $fileActions,
  193. 'rename'
  194. );
  195. Util::connectHook(
  196. Filesystem::CLASSNAME,
  197. Filesystem::signal_post_create,
  198. $fileActions,
  199. 'create'
  200. );
  201. Util::connectHook(
  202. Filesystem::CLASSNAME,
  203. Filesystem::signal_post_copy,
  204. $fileActions,
  205. 'copy'
  206. );
  207. Util::connectHook(
  208. Filesystem::CLASSNAME,
  209. Filesystem::signal_post_write,
  210. $fileActions,
  211. 'write'
  212. );
  213. Util::connectHook(
  214. Filesystem::CLASSNAME,
  215. Filesystem::signal_post_update,
  216. $fileActions,
  217. 'update'
  218. );
  219. Util::connectHook(
  220. Filesystem::CLASSNAME,
  221. Filesystem::signal_read,
  222. $fileActions,
  223. 'read'
  224. );
  225. Util::connectHook(
  226. Filesystem::CLASSNAME,
  227. Filesystem::signal_delete,
  228. $fileActions,
  229. 'delete'
  230. );
  231. }
  232. private function versionsHooks(IAuditLogger $logger): void {
  233. $versionsActions = new Versions($logger);
  234. Util::connectHook('\OCP\Versions', 'rollback', $versionsActions, 'rollback');
  235. Util::connectHook('\OCP\Versions', 'delete', $versionsActions, 'delete');
  236. }
  237. private function trashbinHooks(IAuditLogger $logger): void {
  238. $trashActions = new Trashbin($logger);
  239. Util::connectHook('\OCP\Trashbin', 'preDelete', $trashActions, 'delete');
  240. Util::connectHook('\OCA\Files_Trashbin\Trashbin', 'post_restore', $trashActions, 'restore');
  241. }
  242. private function securityHooks(IAuditLogger $logger,
  243. IEventDispatcher $eventDispatcher): void {
  244. $eventDispatcher->addListener(TwoFactorProviderChallengePassed::class, function (TwoFactorProviderChallengePassed $event) use ($logger) {
  245. $security = new Security($logger);
  246. $security->twofactorSuccess($event->getUser(), $event->getProvider());
  247. });
  248. $eventDispatcher->addListener(TwoFactorProviderChallengeFailed::class, function (TwoFactorProviderChallengeFailed $event) use ($logger) {
  249. $security = new Security($logger);
  250. $security->twofactorFailed($event->getUser(), $event->getProvider());
  251. });
  252. }
  253. }