bugfix in command "oset"
[srvx.git] / src / mod-hostserv.c
index a2e50d30aa8ee1c860ae8d0d9b2215198a8361d5..5e30ed9f929e6ae1b08205da09a3ee41b4c33641 100644 (file)
@@ -29,6 +29,8 @@
  *         "manager_can_del_toplevel" "0"; //managers of a toplevel group may delete the whole group
  *         "manager_can_rename_secondlevel" "0"; //managers of a secondlevel group may rename the whole group
  *         "manager_can_del_secondlevel" "0"; //managers of a secondlevel group may delete the whole group
+ *         "manager_toplevel_can_oset" "0"; //managers of a toplevel group can set other user's fakehosts
+ *         "manager_secondlevel_can_oset" "0"; //managers of a secondlevel group can set other user's fakehosts
  *     };
  *  };
  *
 #define KEY_ASSIGNMENTS "Assignments"
 #define KEY_ACTIVE "active"
 
+#define HS_FAKEHOST_SPECIAL_CHARS "_-:;" /* alphanum already included */
+
 #define HS_ASSIGNMENTSTATE_AUTO -1
 #define HS_ASSIGNMENTSTATE_OFF  0
 #define HS_ASSIGNMENTSTATE_ON   1
 
+#define HS_FHPARSE_SUCCESS 0
+#define HS_FHPARSE_INVALID 1
+#define HS_FHPARSE_UNKNOWN 2
+
 static const struct message_entry msgtab[] = {
     { "HSMSG_ACCESS_DENIED", "Access denied." },
     { "HSMSG_ASSIGNED_FAKEHOSTS", "Assigned Fakehosts for User $b%s$b:" },
@@ -106,6 +114,8 @@ static struct {
     int manager_can_del_secondlevel : 1;
     int manager_can_rename_toplevel : 1;
     int manager_can_rename_secondlevel : 1;
+    int manager_toplevel_can_oset : 1;
+    int manager_secondlevel_can_oset : 1;
 } hostserv_conf;
 
 const char *hostserv_module_deps[] = { NULL };
@@ -157,6 +167,16 @@ struct hs_user {
     struct hs_user *next;
 };
 
+/* temporary structs */
+struct hs_fakehost_info {
+    unsigned int parse_state : 4;
+    unsigned int have_secondlevel : 1;
+    char *tlfh_name;
+    char *slfh_name;
+    struct hs_toplevel *tlfh;
+    struct hs_secondlevel *slfh;
+};
+
 /* MANAGEMENT FUNCTIONS for FAKEHOST STRUCTS */
 static void hs_del_secondlevel(struct hs_secondlevel *slfh, int remove_from_tlfh);
 static void hs_del_manager(struct hs_manager *manager, int remove_from_object);
@@ -551,6 +571,65 @@ static int check_management_access(struct handle_info *hi, struct hs_toplevel *t
     return 0;
 }
 
+struct hs_fakehost_info parse_fakehost_info(char *fakehost, int fix_name_case) {
+    struct hs_fakehost_info fhinfo;
+    int i;
+    memset(&fhinfo, 0, sizeof(fhinfo));
+    for(i = strlen(fakehost)-1; i >= 0; i--) {
+        if(!isalnum(fakehost[i]) && fakehost[i] != '.' && !(fakehost[i] == '*' && i == 0) && !strchr(HS_FAKEHOST_SPECIAL_CHARS, fakehost[i])) {
+            fhinfo.parse_state = HS_FHPARSE_INVALID;
+            return fhinfo;
+        }
+    }
+    fhinfo.slfh_name = fakehost;
+    fhinfo.tlfh_name = strchr(fakehost, '.');
+    if(!fhinfo.tlfh_name) {
+        fhinfo.parse_state = HS_FHPARSE_INVALID;
+        return fhinfo;
+    }
+    fhinfo.tlfh_name[0] = '\0';
+    fhinfo.tlfh_name++;
+    if(strchr(fhinfo.tlfh_name, '.')) {
+        fhinfo.parse_state = HS_FHPARSE_INVALID;
+        fhinfo.tlfh_name--;
+        fhinfo.tlfh_name[0] = '\0';
+        return fhinfo;
+    }
+    if(irccasecmp(fhinfo.slfh_name, "*"))
+        fhinfo.have_secondlevel = 1;
+    struct hs_toplevel *tlfh;
+    struct hs_secondlevel *slfh;
+    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
+        if(!irccasecmp(tlfh->fakehost, fhinfo.tlfh_name)) break;
+    }
+    fhinfo.tlfh = tlfh;
+    if(!tlfh) {
+        fhinfo.slfh = NULL;
+        fhinfo.parse_state = HS_FHPARSE_UNKNOWN;
+        return fhinfo;
+    }
+    if(fhinfo.have_secondlevel) {
+        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
+            if(!irccasecmp(slfh->fakehost, fhinfo.slfh_name)) break;
+        }
+        fhinfo.slfh = slfh;
+        if(!slfh) {
+            fhinfo.parse_state = HS_FHPARSE_UNKNOWN;
+            return fhinfo;
+        }
+    } else
+        fhinfo.slfh = NULL;
+    if(fix_name_case) {
+        //simply copy the stored fakehosts over the given ones
+        strcpy(fhinfo.tlfh_name, fhinfo.tlfh->fakehost);
+        if(fhinfo.slfh)
+            strcpy(fhinfo.slfh_name, fhinfo.slfh->fakehost);
+    }
+    fhinfo.parse_state = HS_FHPARSE_SUCCESS;
+    return fhinfo;
+}
+
+
 
 static void cmd_view_toplevel_information(UNUSED_ARG(struct userNode *user), UNUSED_ARG(struct svccmd *cmd), struct hs_toplevel *tlfh) {
     reply("HSMSG_TOPLEVEL_FAKEHOSTS", tlfh->fakehost);
@@ -621,43 +700,27 @@ static MODCMD_FUNC(cmd_view) {
             reply("NSMSG_MUST_AUTH");
             return 0;
         }
-        char *slfh_name = argv[1];
-        char *tlfh_name = strchr(argv[1], '.');
-        if(!tlfh_name) {
-            reply("HSMSG_TOPLEVEL_INVALID", slfh_name);
+        struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 0);
+        if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+            reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
             return 0;
-        }
-        *tlfh_name = '\0';
-        tlfh_name++;
-        if(strchr(tlfh_name, '.')) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+            reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
-        struct hs_toplevel *tlfh;
-        for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-            if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-        }
-        if(!tlfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-            return 0;
-        }
-        if(!irccasecmp(slfh_name, "*")) {
-            if(!check_management_access(hi, tlfh, NULL)) {
-                reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        if(!fhinfo.slfh) {
+            if(!check_management_access(hi, fhinfo.tlfh, NULL)) {
+                reply("HSMSG_ACCESS_DENIED");
                 return 0;
             }
-            cmd_view_toplevel_information(user, cmd, tlfh);
+            cmd_view_toplevel_information(user, cmd, fhinfo.tlfh);
             return 1;
         } else {
-            struct hs_secondlevel *slfh;
-            for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-                if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-            }
-            if(!slfh || !check_management_access(hi, tlfh, slfh)) {
-                reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+            if(!check_management_access(hi, fhinfo.tlfh, fhinfo.slfh)) {
+                reply("HSMSG_ACCESS_DENIED");
                 return 0;
             }
-            cmd_view_secondlevel_information(user, cmd, slfh);
+            cmd_view_secondlevel_information(user, cmd, fhinfo.slfh);
             return 1;
         }
     } else {
@@ -711,13 +774,13 @@ static MODCMD_FUNC(cmd_view) {
                 reply("HSMSG_MANAGED_TOPLEVEL", tlfh->fakehost, slfhs, assignments);
             }
         }
-        for(manager = huser->managements; manager; manager = manager->next) {
+        for(manager = huser->managements; manager; manager = manager->unext) {
             if(manager->type == 2) {
                 struct hs_secondlevel *slfh = manager->object;
                 struct hs_toplevel *tlfh = slfh->toplevel;
                 //check if the user is already a manager of the tlfh
                 struct hs_manager *cmanager;
-                for(cmanager = tlfh->managers; cmanager; cmanager = cmanager->next) {
+                for(cmanager = tlfh->managers; cmanager; cmanager = cmanager->unext) {
                     if(cmanager->user == huser) break;
                 }
                 if(cmanager) continue;
@@ -736,63 +799,41 @@ static MODCMD_FUNC(cmd_view) {
 
 static MODCMD_FUNC(cmd_addhost) {
     struct handle_info *hi;
-    struct hs_toplevel *tlfh;
-    struct hs_secondlevel *slfh;
     if (!(hi = user->handle_info)) {
         reply("NSMSG_MUST_AUTH");
         return 0;
     }
-    char *slfh_name = argv[1];
-    char *tlfh_name = strchr(argv[1], '.');
-    if(!tlfh_name) {
-        reply("HSMSG_TOPLEVEL_INVALID", slfh_name);
-        return 0;
-    }
-    *tlfh_name = '\0';
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
         return 0;
     }
-    if(!irccasecmp(slfh_name, "*")) {
+    if(!fhinfo.have_secondlevel) {
         if(!check_management_access(hi, NULL, NULL)) {
             reply("HSMSG_ACCESS_DENIED");
             return 0;
         }
-        for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-            if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-        }
-        if(tlfh) {
-            reply("HSMSG_FAKEHOST_TOPLEVEL_ALREADY_EXISTS", slfh_name, tlfh_name);
+        if(fhinfo.parse_state != HS_FHPARSE_UNKNOWN) {
+            reply("HSMSG_FAKEHOST_TOPLEVEL_ALREADY_EXISTS", fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
-        if(irccasecmp(tlfh_name, "*")) {
-                   reply("HSMSG_ACCESS_DENIED");
-                   return 0;   
-        }
-        hs_add_toplevel(tlfh_name);
-        reply("HSMSG_FAKEHOST_TOPLEVEL_ADDED", tlfh_name);
+        hs_add_toplevel(fhinfo.tlfh_name);
+        reply("HSMSG_FAKEHOST_TOPLEVEL_ADDED", fhinfo.tlfh_name);
     } else {
-        for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-            if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-        }
-        if(!tlfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        if(!fhinfo.tlfh) {
+            reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
-        if(!check_management_access(hi, tlfh, NULL)) {
+        if(!check_management_access(hi, fhinfo.tlfh, NULL)) {
             reply("HSMSG_ACCESS_DENIED");
             return 0;
         }
-        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-            if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-        }
-        if(slfh) {
-            reply("HSMSG_FAKEHOST_SECONDLEVEL_ALREADY_EXISTS", slfh_name, tlfh_name);
+        if(fhinfo.parse_state != HS_FHPARSE_UNKNOWN) {
+            reply("HSMSG_FAKEHOST_SECONDLEVEL_ALREADY_EXISTS", fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
-        hs_add_secondlevel(tlfh, slfh_name);
-        reply("HSMSG_FAKEHOST_SECONDLEVEL_ADDED", slfh_name, tlfh_name);
+        hs_add_secondlevel(fhinfo.tlfh, fhinfo.slfh_name);
+        reply("HSMSG_FAKEHOST_SECONDLEVEL_ADDED", fhinfo.slfh_name, fhinfo.tlfh_name);
     }
     return 1;
 }
@@ -803,44 +844,28 @@ static MODCMD_FUNC(cmd_delhost) {
         reply("NSMSG_MUST_AUTH");
         return 0;
     }
-    char *slfh_name = argv[1];
-    char *tlfh_name = strchr(argv[1], '.');
-    *tlfh_name = '\0';
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
         return 0;
-    }
-    struct hs_toplevel *tlfh;
-    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-        if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-    }
-    if(!tlfh) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
-    if(!irccasecmp(slfh_name, "*")) {
-        if(!check_management_access(hi, (hostserv_conf.manager_can_del_toplevel ? tlfh : NULL), NULL)) { /* manager access is enough to delete whole toplevel? */
+    if(!fhinfo.slfh) {
+        if(!check_management_access(hi, (hostserv_conf.manager_can_del_toplevel ? fhinfo.tlfh : NULL), NULL)) { /* manager access is enough to delete whole toplevel? */
             reply("HSMSG_ACCESS_DENIED");
             return 0;
         }
-        hs_del_toplevel(tlfh);
-        reply("HSMSG_FAKEHOST_TOPLEVEL_DELETED", tlfh_name);
+        hs_del_toplevel(fhinfo.tlfh);
+        reply("HSMSG_FAKEHOST_TOPLEVEL_DELETED", fhinfo.tlfh_name);
     } else {
-        struct hs_secondlevel *slfh;
-        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-            if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-        }
-        if(!slfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-            return 0;
-        }
-        if(!check_management_access(hi, tlfh, (hostserv_conf.manager_can_del_secondlevel ? slfh : NULL))) {
+        if(!check_management_access(hi, fhinfo.tlfh, (hostserv_conf.manager_can_del_secondlevel ? fhinfo.slfh : NULL))) {
             reply("HSMSG_ACCESS_DENIED");
             return 0;
         }
-        hs_del_secondlevel(slfh, 1);
-        reply("HSMSG_FAKEHOST_SECONDLEVEL_DELETED", slfh_name, tlfh_name);
+        hs_del_secondlevel(fhinfo.slfh, 1);
+        reply("HSMSG_FAKEHOST_SECONDLEVEL_DELETED", fhinfo.slfh_name, fhinfo.tlfh_name);
     }
     return 1;
 }
@@ -852,98 +877,54 @@ static MODCMD_FUNC(cmd_renamehost) {
         return 0;
     }
     //old fakehost name
-    char *slfh_name = argv[1];
-    char *tlfh_name = strchr(argv[1], '.');
-    if(!tlfh_name) {
-        reply("HSMSG_TOPLEVEL_INVALID", slfh_name);
-        return 0;
-    }
-    *tlfh_name = '\0';
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
         return 0;
-    }
-    struct hs_toplevel *tlfh;
-    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-        if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-    }
-    if(!tlfh) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
     //new fakehost name
-    char *new_slfh_name = argv[2];
-    char *new_tlfh_name = strchr(argv[2], '.');
-    if(!new_tlfh_name) {
-        reply("HSMSG_TOPLEVEL_INVALID", new_slfh_name);
+    struct hs_fakehost_info new_fhinfo = parse_fakehost_info(argv[2], 0);
+    if(new_fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
         return 0;
-    }
-    *new_tlfh_name = '\0';
-    new_tlfh_name++;
-    if(strchr(new_tlfh_name, '.')) {
-        new_tlfh_name--;
-        *new_tlfh_name = '.';
-        reply("HSMSG_TOPLEVEL_INVALID", new_slfh_name);
+    } else if(new_fhinfo.parse_state != HS_FHPARSE_UNKNOWN && (irccasecmp(fhinfo.tlfh_name, new_fhinfo.tlfh_name) || (new_fhinfo.slfh && irccasecmp(fhinfo.slfh_name, new_fhinfo.slfh_name)))) {
+        reply("HSMSG_FAKEHOST_TOPLEVEL_ALREADY_EXISTS", new_fhinfo.slfh_name, new_fhinfo.tlfh_name);
         return 0;
     }
-    if(!irccasecmp(slfh_name, "*")) {
-        if(!check_management_access(hi, (hostserv_conf.manager_can_rename_toplevel ? tlfh : NULL), NULL)) { /* manager access is enough to delete whole toplevel? */
+    
+    if(!fhinfo.slfh) {
+        if(!check_management_access(hi, (hostserv_conf.manager_can_rename_toplevel ? fhinfo.tlfh : NULL), NULL)) { /* manager access is enough to delete whole toplevel? */
             reply("HSMSG_ACCESS_DENIED");
             return 0;
         }
-        if(irccasecmp(new_slfh_name, "*")) {
+        if(fhinfo.have_secondlevel) {
             //can't rename toplevel into secondlevel fakehost!
-            new_tlfh_name--;
-            *new_tlfh_name = '.';
-            reply("HSMSG_TOPLEVEL_INVALID", new_slfh_name);
+            new_fhinfo.tlfh_name--;
+            new_fhinfo.tlfh_name[0] = '.';
+            reply("HSMSG_TOPLEVEL_INVALID", new_fhinfo.slfh_name);
             return 0;
         }
-        struct hs_toplevel *ctlfh;
-        for(ctlfh = toplevels; ctlfh; ctlfh = ctlfh->next) {
-            if(!irccasecmp(ctlfh->fakehost, new_tlfh_name)) break;
-        }
-        if(ctlfh) {
-            reply("HSMSG_FAKEHOST_TOPLEVEL_ALREADY_EXISTS", new_slfh_name, new_tlfh_name);
-            return 0;
-        }
-               if(irccasecmp(new_tlfh_name, "*")) {
-                   reply("HSMSG_ACCESS_DENIED");
-                   return 0;   
-        }
-        if(strcmp(new_tlfh_name, tlfh->fakehost))
-            hs_rename_toplevel(tlfh, new_tlfh_name);
-        reply("HSMSG_FAKEHOST_RENAMED", slfh_name, tlfh_name, new_slfh_name, new_tlfh_name);
+        if(strcmp(new_fhinfo.tlfh_name, fhinfo.tlfh->fakehost))
+            hs_rename_toplevel(fhinfo.tlfh, new_fhinfo.tlfh_name);
+        reply("HSMSG_FAKEHOST_RENAMED", fhinfo.slfh_name, fhinfo.tlfh_name, new_fhinfo.slfh_name, new_fhinfo.tlfh_name);
     } else {
-        struct hs_secondlevel *slfh;
-        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-            if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-        }
-        if(!slfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-            return 0;
-        }
-        if(!check_management_access(hi, tlfh, (hostserv_conf.manager_can_rename_secondlevel ? slfh : NULL))) {
+        if(!check_management_access(hi, fhinfo.tlfh, (hostserv_conf.manager_can_rename_secondlevel ? fhinfo.slfh : NULL))) {
             reply("HSMSG_ACCESS_DENIED");
             return 0;
         }
-        if(irccasecmp(new_tlfh_name, tlfh_name)) {
+        if(irccasecmp(new_fhinfo.tlfh_name, fhinfo.tlfh_name)) {
             //can't rename toplevel and secondlevel fakehost with one command!
-            new_tlfh_name--;
-            *new_tlfh_name = '.';
-            reply("HSMSG_TOPLEVEL_INVALID", new_slfh_name);
-        }
-        struct hs_secondlevel *cslfh;
-        for(cslfh = tlfh->secondlevel; cslfh; cslfh = cslfh->next) {
-            if(!irccasecmp(cslfh->fakehost, new_slfh_name)) break;
-        }
-        if(cslfh) {
-            reply("HSMSG_FAKEHOST_SECONDLEVEL_ALREADY_EXISTS", new_slfh_name, new_tlfh_name);
+            new_fhinfo.tlfh_name--;
+            new_fhinfo.tlfh_name[0] = '.';
+            reply("HSMSG_TOPLEVEL_INVALID", new_fhinfo.slfh_name);
             return 0;
         }
-        if(strcmp(new_slfh_name, slfh->fakehost))
-            hs_rename_secondlevel(slfh, new_slfh_name);
-        reply("HSMSG_FAKEHOST_RENAMED", slfh_name, tlfh_name, new_slfh_name, new_tlfh_name);
+        if(strcmp(new_fhinfo.slfh_name, fhinfo.slfh->fakehost))
+            hs_rename_secondlevel(fhinfo.slfh, new_fhinfo.slfh_name);
+        reply("HSMSG_FAKEHOST_RENAMED", fhinfo.slfh_name, fhinfo.tlfh_name, new_fhinfo.slfh_name, new_fhinfo.tlfh_name);
     }
     return 1;
 }
@@ -951,79 +932,61 @@ static MODCMD_FUNC(cmd_renamehost) {
 static MODCMD_FUNC(cmd_addmanager) {
     struct handle_info *hi;
     char *fakehost;
-    if(argc >= 3) {
-        if(!strchr(argv[1], '.')) {
-            if (!(hi = modcmd_get_handle_info(user, argv[1])))
-                return 0;
-            fakehost = argv[2];
-        } else {
-            if (!(hi = modcmd_get_handle_info(user, argv[2])))
-                return 0;
-            fakehost = argv[1];
-        }
-        char *slfh_name = fakehost;
-        char *tlfh_name = strchr(fakehost, '.');
-        if(!tlfh_name) {
-            reply("HSMSG_TOPLEVEL_INVALID", slfh_name);
-            return 0;
-        }
-        *tlfh_name = '\0';
-        tlfh_name++;
-        if(strchr(tlfh_name, '.')) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    if(!strchr(argv[1], '.')) {
+        if (!(hi = modcmd_get_handle_info(user, argv[1])))
             return 0;
-        }
-        struct hs_toplevel *tlfh;
-        struct hs_secondlevel *slfh = NULL;
-        for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-            if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-        }
-        if(!tlfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        fakehost = argv[2];
+    } else {
+        if (!(hi = modcmd_get_handle_info(user, argv[2])))
             return 0;
-        }
-        if(!irccasecmp(slfh_name, "*")) {
-            if(!check_management_access(user->handle_info, tlfh, NULL)) {
-                reply("HSMSG_ACCESS_DENIED");
-                return 0;
-            }
-        } else {
-            for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-                if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-            }
-            if(!slfh) {
-                reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-                return 0;
-            }
-            if(!check_management_access(user->handle_info, tlfh, slfh)) {
-                reply("HSMSG_ACCESS_DENIED");
+        fakehost = argv[1];
+    }
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", fakehost);
+        return 0;
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
+    }
+    if(!check_management_access(user->handle_info, fhinfo.tlfh, fhinfo.slfh)) {
+        reply("HSMSG_ACCESS_DENIED");
+        return 0;
+    }
+    struct hs_user *huser = hs_get_user(hi, 1);
+    struct hs_manager *manager;
+    if(fhinfo.slfh) {
+        for(manager = huser->managements; manager; manager = manager->next) {
+            if(manager->type == 2 && manager->object == fhinfo.slfh) {
+                reply("HSMSG_MANAGER_ALREADY", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
                 return 0;
             }
         }
-        struct hs_user *huser = hs_get_user(hi, 1);
-        struct hs_manager *manager;
-        if(slfh) {
-            for(manager = huser->managements; manager; manager = manager->next) {
-                if(manager->type == 2 && manager->object == slfh) {
-                    reply("HSMSG_MANAGER_ALREADY", hi->handle, slfh_name, tlfh_name);
-                    return 0;
-                }
-            }
+    }
+    for(manager = huser->managements; manager; manager = manager->next) {
+        if(manager->type == 1 && manager->object == fhinfo.tlfh) {
+            reply("HSMSG_MANAGER_ALREADY", hi->handle, "*", fhinfo.tlfh_name);
+            return 0;
         }
-        for(manager = huser->managements; manager; manager = manager->next) {
-            if(manager->type == 1 && manager->object == tlfh) {
-                reply("HSMSG_MANAGER_ALREADY", hi->handle, "*", tlfh_name);
-                return 0;
+    }
+    if(fhinfo.slfh)
+        hs_add_manager_secondlevel(fhinfo.slfh, huser);
+    else {
+        hs_add_manager_toplevel(fhinfo.tlfh, huser);
+        //remove from all slfh's
+        struct hs_manager *next_manager;
+        struct hs_secondlevel *slfh;
+        for(manager = huser->managements; manager; manager = next_manager) {
+            next_manager = manager->next;
+            if(manager->type == 2) {
+                slfh = manager->object;
+                if(slfh->toplevel == fhinfo.tlfh)
+                    hs_del_manager(manager, 1);
             }
         }
-        if(slfh)
-            hs_add_manager_secondlevel(slfh, huser);
-        else
-            hs_add_manager_toplevel(tlfh, huser);
-        reply("HSMSG_MANAGER_ADDED", hi->handle, slfh_name, tlfh_name);
-        return 1;
     }
-    return 0;
+    reply("HSMSG_MANAGER_ADDED", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
+    return 1;
 }
 
 static MODCMD_FUNC(cmd_delmanager) {
@@ -1038,71 +1001,45 @@ static MODCMD_FUNC(cmd_delmanager) {
             return 0;
         fakehost = argv[1];
     }
-    char *slfh_name = fakehost;
-    char *tlfh_name = strchr(fakehost, '.');
-    if(!tlfh_name) {
-        reply("HSMSG_TOPLEVEL_INVALID", slfh_name);
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", fakehost);
         return 0;
-    }
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
-    struct hs_toplevel *tlfh;
-    struct hs_secondlevel *slfh = NULL;
-    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-        if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-    }
-    if(!tlfh) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    if(!check_management_access(user->handle_info, fhinfo.tlfh, fhinfo.slfh)) {
+        reply("HSMSG_ACCESS_DENIED");
         return 0;
     }
-    if(!irccasecmp(slfh_name, "*")) {
-        if(!check_management_access(user->handle_info, tlfh, NULL)) {
-            reply("HSMSG_ACCESS_DENIED");
-            return 0;
-        }
-    } else {
-        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-            if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-        }
-        if(!slfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-            return 0;
-        }
-        if(!check_management_access(user->handle_info, tlfh, slfh)) {
-            reply("HSMSG_ACCESS_DENIED");
-            return 0;
-        }
-    }
     struct hs_user *huser = hs_get_user(hi, 0);
     struct hs_manager *manager;
     if(!huser) {
-        reply("HSMSG_MANAGER_NOT", hi->handle, slfh_name, tlfh_name);
+        reply("HSMSG_MANAGER_NOT", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
-    if(slfh) {
-        for(manager = huser->managements; manager; manager = manager->next) {
-            if(manager->type == 2 && manager->object == slfh) 
+    if(fhinfo.slfh) {
+        for(manager = huser->managements; manager; manager = manager->unext) {
+            if(manager->type == 2 && manager->object == fhinfo.slfh) 
                 break;
         }
         if(!manager) {
-            reply("HSMSG_MANAGER_NOT", hi->handle, slfh_name, tlfh_name);
+            reply("HSMSG_MANAGER_NOT", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
     } else {
-        for(manager = huser->managements; manager; manager = manager->next) {
-            if(manager->type == 1 && manager->object == tlfh) 
+        for(manager = huser->managements; manager; manager = manager->unext) {
+            if(manager->type == 1 && manager->object == fhinfo.tlfh) 
                 break;
         }
         if(!manager) {
-            reply("HSMSG_MANAGER_NOT", hi->handle, "*", tlfh_name);
+            reply("HSMSG_MANAGER_NOT", hi->handle, "*", fhinfo.tlfh_name);
             return 0;
         }
     }
     hs_del_manager(manager, 1);
-    reply("HSMSG_MANAGER_DELETED", hi->handle, slfh_name, tlfh_name);
+    reply("HSMSG_MANAGER_DELETED", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
     return 1;
 }
 
@@ -1112,7 +1049,6 @@ static MODCMD_FUNC(cmd_set) {
     struct hs_assignment *assignment;
     struct hs_toplevel *tlfh;
     struct hs_secondlevel *slfh;
-    char *fakehost;
     
     if (!(hi = user->handle_info)) {
         reply("NSMSG_MUST_AUTH");
@@ -1125,27 +1061,24 @@ static MODCMD_FUNC(cmd_set) {
         hs_activate_assignment(hs_user, NULL);
         return 1;
     } else {
-        fakehost = argv[1];
-        char *slfh_name = fakehost;
-        char *tlfh_name = strchr(fakehost, '.');
-        if(tlfh_name) {
-            *tlfh_name = '\0';
-            tlfh_name++;
-        }
-        if(!tlfh_name || strchr(tlfh_name, '.')) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, (tlfh_name ? tlfh_name : ""));
+        struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 1);
+        if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+            reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
+            return 0;
+        } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+            reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
         for(assignment = hs_user->assignments; assignment; assignment = assignment->unext) {
             slfh = assignment->secondlevel;
             tlfh = slfh->toplevel;
-            if(!irccasecmp(tlfh_name, tlfh->fakehost) && !irccasecmp(slfh_name, slfh->fakehost)) {
+            if(tlfh == fhinfo.tlfh && slfh == fhinfo.slfh) {
                 hs_activate_assignment(hs_user, assignment);
                 reply("HSMSG_FAKEHOST_SET_SUCCESS", slfh->fakehost, tlfh->fakehost);
                 return 1;
             }
         }
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
 }
@@ -1166,41 +1099,26 @@ static MODCMD_FUNC(cmd_assign) {
         reply("NSMSG_MUST_AUTH");
         return 0;
     }
-    char *slfh_name = fakehost;
-    char *tlfh_name = strchr(fakehost, '.');
-    if(!tlfh_name) {
-        reply("HSMSG_TOPLEVEL_INVALID", slfh_name);
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", fakehost);
         return 0;
-    }
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN || !fhinfo.slfh) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
-    struct hs_toplevel *tlfh;
-    struct hs_secondlevel *slfh;
     struct hs_user *hs_user = hs_get_user(hi, 1);
-    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-        if(!irccasecmp(tlfh_name, tlfh->fakehost)) {
-            for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-                if(!irccasecmp(slfh_name, slfh->fakehost)) {
-                    if(!check_management_access(user->handle_info, tlfh, slfh)) {
-                        reply("HSMSG_ACCESS_DENIED");
-                        return 0;
-                    }
-                    if(hs_get_assignment(slfh, hs_user)) {
-                        reply("HSMSG_FAKEHOST_ASSIGNED", slfh_name, tlfh_name);
-                        return 0;
-                    }
-                    hs_add_assignment(slfh, hs_user, HS_ASSIGNMENTSTATE_AUTO);
-                    reply("HSMSG_FAKEHOST_ASSIGN_SUCCESS", slfh_name, tlfh_name);
-                    return 1;
-                }
-            }
-        }
+    if(!check_management_access(user->handle_info, fhinfo.tlfh, fhinfo.slfh)) {
+        reply("HSMSG_ACCESS_DENIED");
+        return 0;
     }
-    reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-    return 0;
+    if(hs_get_assignment(fhinfo.slfh, hs_user)) {
+        reply("HSMSG_FAKEHOST_ASSIGNED", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
+    }
+    hs_add_assignment(fhinfo.slfh, hs_user, HS_ASSIGNMENTSTATE_AUTO);
+    reply("HSMSG_FAKEHOST_ASSIGN_SUCCESS", fhinfo.slfh_name, fhinfo.tlfh_name);
+    return 1;
 }
 
 static MODCMD_FUNC(cmd_unassign) {
@@ -1219,38 +1137,91 @@ static MODCMD_FUNC(cmd_unassign) {
         reply("NSMSG_MUST_AUTH");
         return 0;
     }
-    char *slfh_name = fakehost;
-    char *tlfh_name = strchr(fakehost, '.');
-    if(!tlfh_name) {
-        reply("HSMSG_TOPLEVEL_INVALID", slfh_name);
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", fakehost);
         return 0;
-    }
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN || !fhinfo.slfh) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
     struct hs_assignment *assignment;
     struct hs_user *hs_user = hs_get_user(hi, 0);
     if(!hs_user) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
+    }
+    if(!check_management_access(user->handle_info, fhinfo.tlfh, fhinfo.slfh)) {
+        reply("HSMSG_ACCESS_DENIED");
+        return 0;
+    }
+    if(!(assignment = hs_get_assignment(fhinfo.slfh, hs_user))) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
+    }
+    hs_del_assignment(assignment, 1);
+    reply("HSMSG_FAKEHOST_UNASSIGN_SUCCESS", fhinfo.slfh_name, fhinfo.tlfh_name);
+    return 1;
+}
+
+static MODCMD_FUNC(cmd_oset) {
+    struct handle_info *hi;
+    char *fakehost;
+    struct hs_assignment *assignment;
+    if(!strchr(argv[1], '.')) {
+        if (!(hi = modcmd_get_handle_info(user, argv[1])))
+            return 0;
+        fakehost = argv[2];
+    } else {
+        if (!(hi = modcmd_get_handle_info(user, argv[2])))
+            return 0;
+        fakehost = argv[1];
+    }
+    if (!user->handle_info) {
+        reply("NSMSG_MUST_AUTH");
         return 0;
     }
+    struct hs_user *hs_user = hs_get_user(hi, 1);
     for(assignment = hs_user->assignments; assignment; assignment = assignment->unext) {
-        if(!irccasecmp(slfh_name, assignment->secondlevel->fakehost)) {
-            if(!irccasecmp(tlfh_name, assignment->secondlevel->toplevel->fakehost)) {
-                if(!check_management_access(user->handle_info, assignment->secondlevel->toplevel, assignment->secondlevel)) {
-                    reply("HSMSG_ACCESS_DENIED");
-                    return 0;
-                }
-                hs_del_assignment(assignment, 1);
-                reply("HSMSG_FAKEHOST_UNASSIGN_SUCCESS", slfh_name, tlfh_name);
+        if(assignment->active)
+            break;
+    }
+    if(assignment && !check_management_access(user->handle_info, (hostserv_conf.manager_toplevel_can_oset ? assignment->secondlevel->toplevel : NULL), (hostserv_conf.manager_secondlevel_can_oset ? assignment->secondlevel : NULL))) {
+        reply("HSMSG_ACCESS_DENIED");
+        return 0;
+    }
+    if(!strcmp(fakehost, "*")) {
+        if(!assignment)
+            return 0; //simply ignore (there is no assignment in use)
+        hs_activate_assignment(hs_user, NULL);
+        return 1;
+    } else {
+        struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+        if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+            reply("HSMSG_TOPLEVEL_INVALID", fakehost);
+            return 0;
+        } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN || !fhinfo.slfh) {
+            reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+            return 0;
+        }
+        if(!check_management_access(user->handle_info, (hostserv_conf.manager_toplevel_can_oset ? fhinfo.tlfh : NULL), (hostserv_conf.manager_secondlevel_can_oset ? fhinfo.slfh : NULL))) {
+            reply("HSMSG_ACCESS_DENIED");
+            return 0;
+        }
+        struct hs_toplevel *tlfh;
+        struct hs_secondlevel *slfh;
+        for(assignment = hs_user->assignments; assignment; assignment = assignment->unext) {
+            slfh = assignment->secondlevel;
+            tlfh = slfh->toplevel;
+            if(tlfh == fhinfo.tlfh && slfh == fhinfo.slfh) {
+                hs_activate_assignment(hs_user, assignment);
+                reply("HSMSG_FAKEHOST_SET_SUCCESS", slfh->fakehost, tlfh->fakehost);
                 return 1;
             }
         }
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
     }
-    reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-    return 0;
 }
 
 static void hostserv_conf_read(void) {
@@ -1273,26 +1244,29 @@ static void hostserv_conf_read(void) {
     hostserv_conf.modes = (str ? str : NULL);
     
     str = database_get_data(conf_node, "toplevel_access", RECDB_QSTRING);
-    unsigned int toplevel_access = atoi(str);
+    unsigned int toplevel_access = (str ? atoi(str) : 0);
     hostserv_conf.toplevel_access = (toplevel_access ? toplevel_access : 600);
     
     str = database_get_data(conf_node, "fallback_other_assignment", RECDB_QSTRING);
-    hostserv_conf.fallback_other_assignment = (atoi(str) ? 1 : 0);
+    hostserv_conf.fallback_other_assignment = (str && atoi(str) ? 1 : 0);
     
     str = database_get_data(conf_node, "manager_can_del_toplevel", RECDB_QSTRING);
-    hostserv_conf.manager_can_del_toplevel = (atoi(str) ? 1 : 0);
+    hostserv_conf.manager_can_del_toplevel = (str && atoi(str) ? 1 : 0);
     
     str = database_get_data(conf_node, "manager_can_del_secondlevel", RECDB_QSTRING);
-    hostserv_conf.manager_can_del_secondlevel = (atoi(str) ? 1 : 0);
+    hostserv_conf.manager_can_del_secondlevel = (str && atoi(str) ? 1 : 0);
     
     str = database_get_data(conf_node, "manager_can_rename_toplevel", RECDB_QSTRING);
-    hostserv_conf.manager_can_rename_toplevel = (atoi(str) ? 1 : 0);
+    hostserv_conf.manager_can_rename_toplevel = (str && atoi(str) ? 1 : 0);
     
     str = database_get_data(conf_node, "manager_can_rename_secondlevel", RECDB_QSTRING);
-    hostserv_conf.manager_can_rename_secondlevel = (atoi(str) ? 1 : 0);
+    hostserv_conf.manager_can_rename_secondlevel = (str && atoi(str) ? 1 : 0);
+    
+    str = database_get_data(conf_node, "manager_toplevel_can_oset", RECDB_QSTRING);
+    hostserv_conf.manager_toplevel_can_oset = (str && atoi(str) ? 1 : 0);
     
-    /*str = database_get_data(conf_node, "description", RECDB_QSTRING);
-    hostserv_conf.description = (str ? str : NULL);*/
+    str = database_get_data(conf_node, "manager_secondlevel_can_oset", RECDB_QSTRING);
+    hostserv_conf.manager_secondlevel_can_oset = (str && atoi(str) ? 1 : 0);
 }
 
 static int hostserv_saxdb_read_secondlevel(const char *name, void *data, UNUSED_ARG(void *extra));
@@ -1478,6 +1452,7 @@ int hostserv_init() {
     modcmd_register(hostserv_module, "addhost", cmd_addhost, 2, MODCMD_REQUIRE_AUTHED, NULL);
     modcmd_register(hostserv_module, "delhost", cmd_delhost, 2, MODCMD_REQUIRE_AUTHED, NULL);
     modcmd_register(hostserv_module, "renamehost", cmd_renamehost, 3, MODCMD_REQUIRE_AUTHED, NULL);
+    modcmd_register(hostserv_module, "oset", cmd_oset, 3, MODCMD_REQUIRE_AUTHED, NULL);
     message_register_table(msgtab);
     return 1;
 }