aboutsummaryrefslogtreecommitdiff
#!/bin/sh
# estampa-ssh: forced command for the upload account in ~/.ssh/authorized_keys.
#
# Usage in authorized_keys:
#   command="/usr/local/bin/estampa-ssh /srv/estampa",no-pty,no-agent-forwarding,no-port-forwarding,no-X11-forwarding ssh-ed25519 AAAA... uploader
#
# On every incoming SSH session this:
#   1. prunes pastes older than one week from $1 (best-effort, never blocks),
#   2. then exec's the original scp/sftp command the client wanted to run.
# Any other command is rejected.

set -eu

# New uploads land mode 644 (rw-r--r--) so the nginx user can read them,
# regardless of the upload account's default umask.
umask 022

PASTE_DIR="${1:?usage: estampa-ssh <paste-dir>}"

estampa --run "$PASTE_DIR" >/dev/null 2>&1 || true

case "${SSH_ORIGINAL_COMMAND:-}" in
    "scp -t "*|"scp -f "*)
        # Legacy scp protocol (`scp -O ...` on the client).
        exec $SSH_ORIGINAL_COMMAND
        ;;
    */sftp-server|*/sftp-server\ *)
        # Modern scp uses SFTP; sshd sets SSH_ORIGINAL_COMMAND to the
        # subsystem path defined by `Subsystem sftp ...` in sshd_config.
        exec $SSH_ORIGINAL_COMMAND
        ;;
    internal-sftp|"internal-sftp "*)
        # `Subsystem sftp internal-sftp` runs in-process inside sshd,
        # but here we're outside sshd so we need a real binary.
        for sftp in \
            /usr/lib/ssh/sftp-server \
            /usr/lib/openssh/sftp-server \
            /usr/libexec/sftp-server \
            /usr/libexec/openssh/sftp-server
        do
            [ -x "$sftp" ] && exec "$sftp"
        done
        echo "estampa-ssh: no sftp-server binary found" >&2
        exit 1
        ;;
    *)
        echo "estampa-ssh: only scp/sftp uploads are allowed" >&2
        exit 1
        ;;
esac