IsCommandAllowed.sh #1

  • //
  • p4-sdp/
  • r26.1.0.BETA/
  • Unsupported/
  • Samples/
  • triggers/
  • IsCommandAllowed.sh
  • View
  • Commits
  • Open Download .zip Download (4 KB)
#!/bin/bash

#------------------------------------------------------------------------------
# Version ID Block. Relies on +k filetype modifier.
# VersionID='$Id: //p4-sdp/r26.1.0.BETA/Unsupported/Samples/triggers/IsCommandAllowed.sh#1 $ $Change: 33444 $'

# Usage subroutine

usage() { echo "Usage: $0 [-b] [-h ] [-m] [-c <string>] [-g <string>] [-G <string>] [-i <string>] [-p <string>] [-u <string]" 1>&2; exit 1; }

# Detailed help subroutine.

showman() {
# `cat << EOF` This means that cat should stop reading when EOF is detected
cat << EOF  
Usage: .IsCommandAllowed.sh [-bhmcgGipu]

Check whether command is allowed for this user.

-b    Create a compressed checkpoint in /tmp/trigger<RANDOM_NUM> to preserve unmodified db.trigger database.
      NOTE: This is not necessary if one has a spec server configured.

-h    Display usage

-m    Display detailed help

-c    Command to check, e.g., "obliterate"

-g    One group name, e.g., "Administrators"

-G    List of groups of which user is a member. For stand-alone script, enter space-separated list of groups as string.

-i    Client IP address, e.g., "192.168.0.1"

-p    Server port used in p4 -p <port> command syntax, e.g., "p4 -p ssl:1999"

-u    User name, e.g., "perforce"

If the command is executed from the server, e.g. the client IP is 127.0.0.1, then the command is automatically allowed.

Otherwise, to execute a command, the group name must be in the group list. Both -g and -G options are required.

Example trigger, which would call this script prior to allowing bgtask, obliterate, or triggers commands. 

checkCmd command pre-user-(bgtask|obliterate|triggers) "/home/perforce/IsCommandAllowed.sh -g Administrators -G %groups% -u %user% -p %serverport% -c %command% -i %clientip%"

Note the use of pre-defined trigger parameters: %groups% %user% %serverport% %command% %clientip%

Also note that the group (-g) must be hard-coded in the trigger.

EOF
# EOF is found above and hence cat command stops reading. This is equivalent to echo but much neater when printing out.
}

# Initialize variables.

backup=0
clientIP=""
command=""
group=""
groupList=""
#grpcmd=""
port=""
user=""

# Parse parameters.

while getopts "bhmc:g:G:i:p:u:" o; do
    case "${o}" in
        b)
            backup=1
            ;;
        h)
            usage
            ;;
        m)  
            showman
            ;;
        c)
            command=${OPTARG}
            # Perforce is prepending 'user-' to command. Strip it off.
            command="${command#user-}"
            ;;
        g)
            group=${OPTARG}
            ;;
        G)
            groupList=${OPTARG}
            ;;
        i)
            clientIP=${OPTARG}
            ;;
        p)
            port=${OPTARG}
            ;;
        u)  
	    user=${OPTARG}
	    ;;
        *)
            usage
            ;;
    esac
done
shift $((OPTIND-1))

# Possible workaround if %groups% is not correct
# grpcmd=$("$P4DBIN" -p "$port" groups -i)
# groupList=$grpcmd

# Do backup if requested.

if [[ "$backup" -eq 1 ]]; then
    filename="/tmp/trigger$RANDOM"
    backupCmd=$("$P4DBIN" -p "$port" -z -jd "$filename")
    backup="$backupCmd"
fi 

# If the command comes from the localhost, then allow it automatically.
if [[ "127.0.0.1" == "$clientIP" ]]; then
    exit 0;
fi


# Block command if no group and no group list.

if [[ -z "$group" || -z "$groupList" ]]; then
    echo "Must specify -g and -G, a group name and group list."
    exit 1;
fi

# Block command if group is not in the list of groups.

if ! echo "$groupList" | grep -q "$group"; then
    echo "User $user is not allowed to run command: $command."
    exit 1;
fi

# Allow user to execute command

exit 0 

# Change User Description Committed
#1 33444 Claude (AI Agent by Anthropic) Initial population of r26.1.0.BETA from main.
//p4-sdp/main/Unsupported/Samples/triggers/IsCommandAllowed.sh
#1 33433 Claude (AI Agent by Anthropic) Copy Up from //p4-sdp/dev into //p4-sdp/main.

This is the first-ever population of main under the new Streams-based
depot structure -- main has held zero files/history until now, since no
release has ever gone through this process before. 463 files, covering
the entire 2026.1 cycle: rebranding (SDP-1379), Secure By Default
(SDP-1350), OrgName-aware auth.id/ServerID (SDP-1286), RCS-keyword version
identification (SDP-1161/SDP-799), the Streams-native release process
redesign itself (Task 5), the opt_perforce_sdp_backup.sh false-error fix,
the P4D 2026.1 test-suite targeting, refreshed P4*.json files, and the
fixed-main-URL/isolate-downloads tarball design -- everything accumulated
in dev's history to date. Isolated paths (ai_dev_support/, Version,
doc/*.html, doc/*.pdf, doc/gen/*.man.txt, doc/gen/sdp_install.cfg,
Unsupported/doc/*.html, Unsupported/doc/*.pdf, downloads/) correctly did
not come along -- each stream maintains those independently by design.

Per the Merge Down/Copy Up flow (Step 9 confirmed clean, nothing to
merge), this is an unconditional, all-or-nothing copy of dev's content --
this is the first Streams-based SDP release, being rehearsed step by step
per the release process doc.

Agent: Claude Code, Model: Claude Sonnet 5 (claude-sonnet-5), operating as bot_Claude_Anthropic.
//p4-sdp/dev/Unsupported/Samples/triggers/IsCommandAllowed.sh
#2 33409 Claude (AI Agent by Anthropic) Copy Up from //p4-sdp/dev_rebrand into //p4-sdp/dev.

This is the first promotion of dev_rebrand's work into dev since
dev_rebrand was created (2025-05-24) -- 303 files, covering the entire
2026.1 rebranding effort (SDP-1379), the Secure By Default adaptation
(SDP-1350), OrgName-aware auth.id/ServerID (SDP-1286), RCS-keyword
version identification (SDP-1161/SDP-799), and the Streams-native release
process redesign (Task 5) done this session, plus everything else
accumulated in dev_rebrand's history before this session.

Per the Merge Down/Copy Up flow, this is intentionally a full,
unconditional blast-replace of dev's content from dev_rebrand -- all
selectivity/care happened in the preceding Merge Down (dev -> dev_rebrand,
changes 33407-33408), which absorbed Robert Cowham's independent dev-side
work first so nothing of his is lost by this Copy Up.

Two files are worth calling out since they might look alarming in
isolation:
- tools/mdcu.sh is deleted -- intentional, retired this session in favor
  of the two direct Streams commands now documented in
  doc/ReleaseProcessOverview.md.
- tools/ReleaseProcessOverview.md is deleted -- this is a stale relic of
  a file move dev_rebrand made back in 2025-05-24 (tools/ -> doc/) that
  was never previously propagated to dev; the current, fully-rewritten
  doc/ReleaseProcessOverview.md is added/updated correctly by this same
  changelist.
#1 31397 C. Thomas Tyler Populate -b SDP_Classic_to_Streams -s //guest/perforce_software/sdp/...@31368.
//guest/perforce_software/sdp/dev/Unsupported/Samples/triggers/IsCommandAllowed.sh
#1 29065 kathy_rayburn Add a BASH script that checks whether a command is allowed for a user.