182 lines
5.8 KiB
Bash
182 lines
5.8 KiB
Bash
wx-login(){
|
|
ORG=$1
|
|
|
|
if [[ -z "$HOSTNAME" || ${#HOSTNAME} -lt 5 ]]
|
|
then
|
|
echo " >> Login << "
|
|
echo "------------------------------"
|
|
|
|
echo -n "Status: Hostname Required"
|
|
wx-stop
|
|
fi
|
|
|
|
if [[ ! -z $1 ]]
|
|
then
|
|
ORG=$1
|
|
elif [[ $(hostname -d) = *"devices.waren.io" ]]
|
|
then
|
|
ORG=warengroup
|
|
elif [[ $(hostname -d) = *"devices.cwinfo.net" ]]
|
|
then
|
|
ORG=cwinfo
|
|
elif [[ $(hostname -d) = *"devices.christerwaren.fi" ]]
|
|
then
|
|
ORG=cwchristerw
|
|
else
|
|
echo " >> Login << "
|
|
echo "------------------------------"
|
|
|
|
echo -n "Status: Organization Required"
|
|
wx-stop
|
|
fi
|
|
|
|
if [[ $ORG == "warengroup" ]]
|
|
then
|
|
DOMAIN=waren.io
|
|
elif [[ $ORG == "cwinfo" ]]
|
|
then
|
|
DOMAIN=cwinfo.net
|
|
elif [[ $ORG == "cwchristerw" ]]
|
|
then
|
|
DOMAIN=christerwaren.fi
|
|
else
|
|
echo " >> Login << "
|
|
echo "------------------------------"
|
|
|
|
echo -n "Status: Organization Unsupported"
|
|
wx-stop
|
|
fi
|
|
|
|
FOLDER=$ORG
|
|
DEVICE_DOMAIN="devices.$DOMAIN"
|
|
IDM_DOMAIN="idm.$DOMAIN"
|
|
VAULT_DOMAIN="vault.cwinfo.net"
|
|
|
|
if [[ ! -z $2 ]]
|
|
then
|
|
HOSTNAME="$2.$DEVICE_DOMAIN"
|
|
elif [[ $(hostname -d) ]]
|
|
then
|
|
HOSTNAME=$(hostname --fqdn)
|
|
else
|
|
echo " >> Login << "
|
|
echo "------------------------------"
|
|
|
|
echo -n "Status: Hostname Required"
|
|
wx-stop
|
|
fi
|
|
|
|
if [[ -z $USER || $USER == "root" || $USER == "local" ]]
|
|
then
|
|
if [[ -z $SUDO_USER ]]
|
|
then
|
|
if [[ -z LOGNAME ]]
|
|
then
|
|
echo " >> Login << "
|
|
echo "------------------------------"
|
|
|
|
echo -n "Status: Username Required"
|
|
wx-stop
|
|
else
|
|
USER=$LOGNAME
|
|
fi
|
|
else
|
|
USER=$SUDO_USER
|
|
fi
|
|
fi
|
|
|
|
VAULT_STATUS=$(curl -s -o /dev/null -w "%{http_code}" https://$VAULT_DOMAIN/v1/sys/health)
|
|
if [[ $VAULT_STATUS -eq 200 ]]
|
|
then
|
|
if [[ -f "$HOME/.config/warengroup/config.json" ]]
|
|
then
|
|
TOKEN="$(cat $HOME/.config/warengroup/config.json | jq -r .login.$ORG)"
|
|
fi
|
|
|
|
VAULT_LOGIN=$(curl https://$VAULT_DOMAIN/v1/auth/token/renew -X POST --header "X-Vault-Token: $TOKEN" -d '{ "token": "'$TOKEN'" }' -s | jq -r '.auth.client_token')
|
|
if [[ ! -z $VAULT_LOGIN && ${#VAULT_LOGIN} == 95 ]]
|
|
then
|
|
config["login",${ORG}]=$VAULT_LOGIN
|
|
jq '.login.'$ORG' = "'$VAULT_LOGIN'"' $HOME/.config/warengroup/config.json &> $HOME/.config/warengroup/config.json.tmp
|
|
mv $HOME/.config/warengroup/config.json.tmp $HOME/.config/warengroup/config.json &> /dev/null
|
|
else
|
|
IDM_STATUS=$(curl -s -o /dev/null -w "%{http_code}" https://$IDM_DOMAIN)
|
|
if [[ $IDM_STATUS -eq 301 ]]
|
|
then
|
|
echo " >> Login << "
|
|
echo "------------------------------"
|
|
|
|
echo $wxBold$ORG$wxNormal
|
|
|
|
if [[ -z $USER || $USER == "root" || $USER == "local" ]]
|
|
then
|
|
echo -n "Username: "
|
|
read USERNAME
|
|
else
|
|
echo "Username: $USER"
|
|
USERNAME=$USER
|
|
fi
|
|
|
|
echo -n "Password: "
|
|
read -s PASSWORD
|
|
echo "****************"
|
|
|
|
if [[ -z $USERNAME || -z $PASSWORD ]]
|
|
then
|
|
echo -n "Status: Username & Password Required"
|
|
wx-stop
|
|
else
|
|
VAULT_LOGIN=$(curl https://$VAULT_DOMAIN/v1/auth/ldap/login/$USERNAME -X POST -d '{ "password": "'$PASSWORD'" }' -s | jq -r '.auth.client_token')
|
|
if [[ -z $VAULT_LOGIN || ${#VAULT_LOGIN} -lt 95 || ${#VAULT_LOGIN} -gt 95 ]]
|
|
then
|
|
echo -n "Status: Login Failed"
|
|
wx-stop
|
|
fi
|
|
|
|
config["login",${ORG}]=$VAULT_LOGIN
|
|
jq '.login.'$ORG' = "'$VAULT_LOGIN'"' $HOME/.config/warengroup/config.json &> $HOME/.config/warengroup/config.json.tmp
|
|
mv $HOME/.config/warengroup/config.json.tmp $HOME/.config/warengroup/config.json &> /dev/null
|
|
|
|
wx-start
|
|
fi
|
|
else
|
|
echo " >> Login << "
|
|
echo "------------------------------"
|
|
|
|
echo $wxBold$ORG$wxNormal
|
|
|
|
echo -n "Token: "
|
|
read -s TOKEN
|
|
echo "****************"
|
|
|
|
if [[ -z $TOKEN || ${#TOKEN} -lt 95 || ${#TOKEN} -gt 95 ]]
|
|
then
|
|
echo -n "Status: Vault Token Required"
|
|
wx-stop
|
|
fi
|
|
|
|
VAULT_LOGIN=$(curl https://$VAULT_DOMAIN/v1/auth/token/renew -X POST --header "X-Vault-Token: $TOKEN" -d '{ "token": "'$TOKEN'" }' -s | jq -r '.auth.client_token')
|
|
if [[ -z $VAULT_LOGIN || ${#VAULT_LOGIN} -lt 95 || ${#VAULT_LOGIN} -gt 95 ]]
|
|
then
|
|
echo -n "Status: Login Failed"
|
|
wx-stop
|
|
fi
|
|
|
|
config["login",${ORG}]=$VAULT_LOGIN
|
|
jq '.login.'$ORG' = "'$VAULT_LOGIN'"' $HOME/.config/warengroup/config.json &> $HOME/.config/warengroup/config.json.tmp
|
|
mv $HOME/.config/warengroup/config.json.tmp $HOME/.config/warengroup/config.json &> /dev/null
|
|
|
|
wx-start
|
|
fi
|
|
fi
|
|
else
|
|
echo " >> Login << "
|
|
echo "------------------------------"
|
|
|
|
echo $wxBold$ORG$wxNormal
|
|
|
|
echo -n "Status: Vault Offline"
|
|
wx-stop
|
|
fi
|
|
}
|