bugfix:
[srvx.git] / src / mod-hostserv.c
index da02cbb6c431afd111b882124a78e2ea5fc33d17..8829c66403fffca7938529633402923f4d20b642 100644 (file)
  *     "hostserv" {
  *         "nick" "HostServ";
  *         "modes" "+iok";
-           "toplevel_access" "600";
+ *         "toplevel_access" "600";
+ *         "fallback_other_assignment" "1"; //fall back to another assignment when active assignment gets removed
+ *         "manager_can_rename_toplevel" "0"; //managers of a toplevel group may rename the whole group
+ *         "manager_can_del_toplevel" "0"; //managers of a toplevel group may delete the whole group
+ *         "manager_can_rename_secondlevel" "0"; //managers of a secondlevel group may rename the whole group
+ *         "manager_can_del_secondlevel" "0"; //managers of a secondlevel group may delete the whole group
+ *         "manager_toplevel_can_oset" "0"; //managers of a toplevel group can set other user's fakehosts
+ *         "manager_secondlevel_can_oset" "0"; //managers of a secondlevel group can set other user's fakehosts
  *     };
  *  };
  *
+ * After you started srvx make the bot active:
+ /msg opserv bind hostserv * hostserv.*
+ /msg opserv bind hostserv help *modcmd.help
  */
 
 #include "chanserv.h"
 #include "modcmd.h"
 #include "saxdb.h"
 #include "timeq.h"
-#include "gline.h"
 
 #define KEY_TOPLEVEL "TopLevel"
 #define KEY_SECONDLEVEL "SecondLevel"
 #define KEY_MANAGERS "Manager"
 #define KEY_ASSIGNMENTS "Assignments"
 #define KEY_ACTIVE "active"
-#define KEY_TITLEHOST_SUFFIX "title_suffix"
+
+#define HS_FAKEHOST_SPECIAL_CHARS "_-:;" /* alphanum already included */
+
+#define HS_ASSIGNMENTSTATE_AUTO -1
+#define HS_ASSIGNMENTSTATE_OFF  0
+#define HS_ASSIGNMENTSTATE_ON   1
+
+#define HS_FHPARSE_SUCCESS 0
+#define HS_FHPARSE_INVALID 1
+#define HS_FHPARSE_UNKNOWN 2
 
 static const struct message_entry msgtab[] = {
+    { "HSMSG_ACCESS_DENIED", "Access denied." },
     { "HSMSG_ASSIGNED_FAKEHOSTS", "Assigned Fakehosts for User $b%s$b:" },
     { "HSMSG_ASSIGNED_FAKEHOST", "  $b%s.%s$b" },
     { "HSMSG_ASSIGNED_FAKEHOST_ACTTIVE", "  $b%s.%s$b (active)" },
@@ -58,7 +77,6 @@ static const struct message_entry msgtab[] = {
     { "HSMSG_MANAGED_FAKEHOST", "  $b%s.%s$b   assignments: %d" },
     { "HSMSG_MANAGE_HOWTO", "Use $bview xxx.yyy$b to view more information about a fakehost group." },
     { "HSMSG_UNKNOWN_FAKEHOST", "Fakehost $b%s.%s$b is unknown or you have no access to manage it." },
-    { "HSMSG_UNKNOWN_FAKEHOST_TOPLEVEL", "Fakehost $b%s$b is unknown or you have no access to manage it." },
     { "HSMSG_TOPLEVEL_FAKEHOSTS", "Fakehosts in group $b*.%s$b:" },
     { "HSMSG_TOPLEVEL_FAKEHOST", "  $b%s.%s$b   assignments: %d   managers: %d" },
     { "HSMSG_TOPLEVEL_INVALID", "The name of the group you entered is invalid ($b%s$b)" },
@@ -75,12 +93,14 @@ static const struct message_entry msgtab[] = {
     { "HSMSG_FAKEHOST_SECONDLEVEL_ADDED", "Group $b%s.%s$b successfully added." },
     { "HSMSG_FAKEHOST_SECONDLEVEL_ALREADY_EXISTS", "Group $b%s.%s$b already exists." },
     { "HSMSG_FAKEHOST_SECONDLEVEL_DELETED", "Group $b%s.%s$b successfully deleted." },
+    { "HSMSG_FAKEHOST_RENAMED", "Group $b%s.%s$b renamed to $b%s.%s$b." },
     { "HSMSG_MANAGER_ALREADY", "$b%s$b is already a manager of %s.%s" },
     { "HSMSG_MANAGER_ADDED", "$b%s$b is now a manager of %s.%s" },
     { "HSMSG_MANAGER_NOT", "$b%s$b is not a manager of %s.%s" },
     { "HSMSG_MANAGER_DELETED", "$b%s$b is no longer a manager of %s.%s" },
     { "HSMSG_FAKEHOST_ASSIGN_SUCCESS", "Group $b%s.%s$b was assigned successfully." },
-    { "HSMSG_FAKEHOST_REVOKE_SUCCESS", "Group $b%s.%s$b was revoked successfully." },
+    { "HSMSG_FAKEHOST_ASSIGNED", "Group $b%s.%s$b is already assigned to the user." },
+    { "HSMSG_FAKEHOST_UNASSIGN_SUCCESS", "Group $b%s.%s$b was unassigned successfully." },
     
     { NULL, NULL }
 };
@@ -89,6 +109,13 @@ static struct {
     const char *nick;
     const char *modes;
     int toplevel_access;
+    int fallback_other_assignment : 1;
+    int manager_can_del_toplevel : 1;
+    int manager_can_del_secondlevel : 1;
+    int manager_can_rename_toplevel : 1;
+    int manager_can_rename_secondlevel : 1;
+    int manager_toplevel_can_oset : 1;
+    int manager_secondlevel_can_oset : 1;
 } hostserv_conf;
 
 const char *hostserv_module_deps[] = { NULL };
@@ -99,7 +126,6 @@ static struct service *hostserv_service;
 static struct log_type *HS_LOG;
 static struct hs_toplevel *toplevels = NULL;
 static struct hs_user *hostserv_users = NULL;
-const char *title_suffix = NULL;
 
 /* FAKEHOST STRUCTS */
 struct hs_toplevel {
@@ -141,72 +167,22 @@ struct hs_user {
     struct hs_user *next;
 };
 
+/* temporary structs */
+struct hs_fakehost_info {
+    unsigned int parse_state : 4;
+    unsigned int have_secondlevel : 1;
+    char *tlfh_name;
+    char *slfh_name;
+    struct hs_toplevel *tlfh;
+    struct hs_secondlevel *slfh;
+};
+
 /* MANAGEMENT FUNCTIONS for FAKEHOST STRUCTS */
 static void hs_del_secondlevel(struct hs_secondlevel *slfh, int remove_from_tlfh);
 static void hs_del_manager(struct hs_manager *manager, int remove_from_object);
 static void hs_del_assignment(struct hs_assignment *assignment, int remove_from_slfh);
 static void hs_del_user(struct hs_user *user);
-
-static void apply_fakehost(struct handle_info *handle, struct userNode *user);
-
-static char *
-generate_fakehost(struct handle_info *handle)
-{
-    extern const char *hidden_host_suffix;
-    static char buffer[HOSTLEN+1];
-
-    if (!handle->fakehost) {
-        snprintf(buffer, sizeof(buffer), "%s.%s", handle->handle, hidden_host_suffix);
-        return buffer;
-    } else if (handle->fakehost[0] == '.') {
-        /* A leading dot indicates the stored value is actually a title. */
-        snprintf(buffer, sizeof(buffer), "%s.%s.%s", handle->handle, handle->fakehost+1, title_suffix);
-        return buffer;
-    } else if (handle->fakehost[0] == '$') {
-        /* A leading $ indicates the stored value begins with the user handle. */
-        snprintf(buffer, sizeof(buffer), "%s%s", handle->handle, handle->fakehost+1);
-        return buffer;
-    }
-    return handle->fakehost;
-}
-
-static char *
-generate_fakeident(struct handle_info *handle, struct userNode *user)
-{
-    static char buffer[USERLEN+1];
-
-    if (!handle->fakeident) {
-        if (!user)
-            return NULL;
-        safestrncpy(buffer, user->ident, sizeof(buffer));
-        return buffer;
-    }
-    return handle->fakeident;
-}
-
-static void
-apply_fakehost(struct handle_info *handle, struct userNode *user)
-{
-    struct userNode *target;
-    char *fakehost, *fakeident;
-
-    if (!handle->users)
-        return;
-
-    fakehost = generate_fakehost(handle);
-
-    if (user) {
-        fakeident = generate_fakeident(handle, user);
-        assign_fakehost(user, fakehost, fakeident, 0, 1);
-        return;
-    }
-
-    for (target = handle->users; target; target = target->next_authed) {
-        fakeident = generate_fakeident(handle, target);
-        assign_fakehost(target, fakehost, fakeident, 0, 1);
-    }
-    return;
-}
+static void hs_activate_assignment(struct hs_user *user, struct hs_assignment *assignment);
 
 static void hs_free_all() {
     struct hs_toplevel *tlfh, *next_tlfh;
@@ -222,7 +198,7 @@ static void hs_free_all() {
         }
         for(slfh = tlfh->secondlevel; slfh; slfh = next_slfh) {
             next_slfh = slfh->next;
-            for(manager = tlfh->managers; manager; manager = next_manager) {
+            for(manager = slfh->managers; manager; manager = next_manager) {
                 next_manager = manager->next;
                 free(manager);
             }
@@ -279,6 +255,23 @@ static void hs_del_toplevel(struct hs_toplevel *tlfh) {
     free(tlfh);
 }
 
+static void hs_rename_toplevel(struct hs_toplevel *tlfh, const char *name) {
+    struct hs_secondlevel *slfh;
+    struct hs_assignment *assng;
+    
+    free(tlfh->fakehost);
+    tlfh->fakehost = strdup(name);
+    
+    //trigger rename for all assignments
+    for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
+        for(assng = slfh->assignments; assng; assng = assng->next) {
+            if(assng->active) {
+                hs_activate_assignment(assng->user, assng);
+            }
+        }
+    }
+}
+
 static struct hs_secondlevel *hs_add_secondlevel(struct hs_toplevel *tlfh, const char *name) {
     struct hs_secondlevel *slfh = calloc(1, sizeof(*slfh));
     slfh->toplevel = tlfh;
@@ -316,6 +309,20 @@ static void hs_del_secondlevel(struct hs_secondlevel *slfh, int remove_from_tlfh
     free(slfh);
 }
 
+static void hs_rename_secondlevel(struct hs_secondlevel *slfh, const char *name) {
+    struct hs_assignment *assng;
+    
+    free(slfh->fakehost);
+    slfh->fakehost = strdup(name);
+    
+    //trigger rename for all assignments
+    for(assng = slfh->assignments; assng; assng = assng->next) {
+        if(assng->active) {
+            hs_activate_assignment(assng->user, assng);
+        }
+    }
+}
+
 static struct hs_manager *hs_add_manager_toplevel(struct hs_toplevel *tlfh, struct hs_user *user) {
     struct hs_manager *manager = calloc(1, sizeof(*manager));
     manager->user = user;
@@ -387,40 +394,49 @@ static void hs_del_manager(struct hs_manager *manager, int remove_from_object) {
     free(manager);
 }
 
-static void activateAssignment(struct hs_assignment *assignment) {
+static void hs_activate_assignment(struct hs_user *user, struct hs_assignment *assignment) {
     struct hs_toplevel *tlfh;
     struct hs_secondlevel *slfh;
-    struct hs_user *hs_user;
     struct hs_assignment *assgn;
-    char fakehost[140];
-    char *prefix = "$";
+    char fakehost[HOSTLEN];
     
-    hs_user = assignment->user;
-    if(hs_user->assignments) {
-        for(assgn = hs_user->assignments; assgn; assgn = assgn->unext) {
+    assert((!assignment || (assignment->user == user)));
+    
+    if(user->assignments) {
+        for(assgn = user->assignments; assgn; assgn = assgn->unext)
             assgn->active = 0;
-        }
     }
-    slfh = assignment->secondlevel;
-    tlfh = slfh->toplevel;
-    sprintf(fakehost, "%s.%s.%s", prefix, slfh->fakehost, tlfh->fakehost);
-    hs_user->hi->fakehost = strdup(fakehost);
-    apply_fakehost(hs_user->hi, NULL);
-    assignment->active = 1;
+    
+    if(user->hi->fakehost) {
+        free(user->hi->fakehost);
+        user->hi->fakehost = NULL;
+    }
+    
+    if(assignment) {
+        slfh = assignment->secondlevel;
+        tlfh = slfh->toplevel;
+        snprintf(fakehost, sizeof(fakehost), "$.%s.%s", slfh->fakehost, tlfh->fakehost);
+        user->hi->fakehost = strdup(fakehost);
+        assignment->active = 1;
+    }
+    
+    apply_fakehost(user->hi, NULL);
 }
 
-static struct hs_assignment *hs_add_assignment(struct hs_secondlevel *slfh, struct hs_user *user) {
+static struct hs_assignment *hs_add_assignment(struct hs_secondlevel *slfh, struct hs_user *user, int active) {
     struct hs_assignment *assignment = calloc(1, sizeof(*assignment));
     assignment->secondlevel = slfh;
     assignment->user = user;
-    if(user->assignments == NULL)
-        assignment->active = 1;
+    if(active == HS_ASSIGNMENTSTATE_AUTO)
+        assignment->active = (user->assignments == NULL ? 1 : 0);
+    else
+        assignment->active = (active == HS_ASSIGNMENTSTATE_ON ? 1 : 0);
     assignment->next = slfh->assignments;
     slfh->assignments = assignment;
     assignment->unext = user->assignments;
     user->assignments = assignment;
     if(assignment->active) {
-        activateAssignment(assignment);
+        hs_activate_assignment(user, assignment);
     }
     return assignment;
 }
@@ -452,20 +468,38 @@ static void hs_del_assignment(struct hs_assignment *assignment, int remove_from_
             } else
                 prev_assignment = cassignment;
         }
-        if(assignment->user->managements == NULL && assignment->user->assignments == NULL)
-            hs_del_user(assignment->user);
         
         if(assignment->active) {
-            struct handle_info *hi;
-            
-            hi = assignment->user->hi;
-            hi->fakehost = NULL;
-            apply_fakehost(hi, NULL);
+            /* use another assignment - or fall back to default user host? */
+            cassignment = NULL;
+            if(hostserv_conf.fallback_other_assignment && assignment->user->assignments) {
+                /* try to find another assignment from same slfh first */
+                for(cassignment = assignment->secondlevel->assignments; cassignment; cassignment = cassignment->next) {
+                    if(cassignment != assignment && cassignment->user == assignment->user)
+                        break;
+                }
+                /* use another tlfh assignment */
+                if(!cassignment)
+                    cassignment = assignment->user->assignments;
+            }
+            hs_activate_assignment(assignment->user, cassignment);
         }
+        
+        if(assignment->user->managements == NULL && assignment->user->assignments == NULL)
+            hs_del_user(assignment->user);
     }
     free(assignment);
 }
 
+static struct hs_assignment *hs_get_assignment(struct hs_secondlevel *slfh, struct hs_user *user) {
+    struct hs_assignment *cassignment;
+    for(cassignment = slfh->assignments; cassignment; cassignment = cassignment->next) {
+        if(cassignment->user == user)
+            return cassignment;
+    }
+    return NULL;
+}
+
 static struct hs_user *hs_get_user(struct handle_info *hi, int create) {
     struct hs_user *cuser;
     for(cuser = hostserv_users; cuser; cuser = cuser->next) {
@@ -537,6 +571,65 @@ static int check_management_access(struct handle_info *hi, struct hs_toplevel *t
     return 0;
 }
 
+struct hs_fakehost_info parse_fakehost_info(char *fakehost, int fix_name_case) {
+    struct hs_fakehost_info fhinfo;
+    int i;
+    memset(&fhinfo, 0, sizeof(fhinfo));
+    for(i = strlen(fakehost)-1; i >= 0; i--) {
+        if(!isalnum(fakehost[i]) && fakehost[i] != '.' && !(fakehost[i] == '*' && i == 0) && !strchr(HS_FAKEHOST_SPECIAL_CHARS, fakehost[i])) {
+            fhinfo.parse_state = HS_FHPARSE_INVALID;
+            return fhinfo;
+        }
+    }
+    fhinfo.slfh_name = fakehost;
+    fhinfo.tlfh_name = strchr(fakehost, '.');
+    if(!fhinfo.tlfh_name) {
+        fhinfo.parse_state = HS_FHPARSE_INVALID;
+        return fhinfo;
+    }
+    fhinfo.tlfh_name[0] = '\0';
+    fhinfo.tlfh_name++;
+    if(strchr(fhinfo.tlfh_name, '.')) {
+        fhinfo.parse_state = HS_FHPARSE_INVALID;
+        fhinfo.tlfh_name--;
+        fhinfo.tlfh_name[0] = '\0';
+        return fhinfo;
+    }
+    if(irccasecmp(fhinfo.slfh_name, "*"))
+        fhinfo.have_secondlevel = 1;
+    struct hs_toplevel *tlfh;
+    struct hs_secondlevel *slfh;
+    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
+        if(!irccasecmp(tlfh->fakehost, fhinfo.tlfh_name)) break;
+    }
+    fhinfo.tlfh = tlfh;
+    if(!tlfh) {
+        fhinfo.slfh = NULL;
+        fhinfo.parse_state = HS_FHPARSE_UNKNOWN;
+        return fhinfo;
+    }
+    if(fhinfo.have_secondlevel) {
+        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
+            if(!irccasecmp(slfh->fakehost, fhinfo.slfh_name)) break;
+        }
+        fhinfo.slfh = slfh;
+        if(!slfh) {
+            fhinfo.parse_state = HS_FHPARSE_UNKNOWN;
+            return fhinfo;
+        }
+    } else
+        fhinfo.slfh = NULL;
+    if(fix_name_case) {
+        //simply copy the stored fakehosts over the given ones
+        strcpy(fhinfo.tlfh_name, fhinfo.tlfh->fakehost);
+        if(fhinfo.slfh)
+            strcpy(fhinfo.slfh_name, fhinfo.slfh->fakehost);
+    }
+    fhinfo.parse_state = HS_FHPARSE_SUCCESS;
+    return fhinfo;
+}
+
+
 
 static void cmd_view_toplevel_information(UNUSED_ARG(struct userNode *user), UNUSED_ARG(struct svccmd *cmd), struct hs_toplevel *tlfh) {
     reply("HSMSG_TOPLEVEL_FAKEHOSTS", tlfh->fakehost);
@@ -597,112 +690,6 @@ static void cmd_view_secondlevel_information(UNUSED_ARG(struct userNode *user),
     }
 }
 
-static MODCMD_FUNC(cmd_addhost) {
-    struct handle_info *hi;
-    if (!(hi = user->handle_info)) {
-        reply("NSMSG_MUST_AUTH");
-        return 0;
-    }
-    char *slfh_name = argv[1];
-    char *tlfh_name = strchr(argv[1], '.');
-    if(!tlfh_name) {
-        reply("HSMSG_TOPLEVEL_INVALID", slfh_name);
-        return 0;
-    }
-    *tlfh_name = '\0';
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-        return 0;
-    }
-    if(!irccasecmp(slfh_name, "*")) {
-        if(hi->opserv_level >= hostserv_conf.toplevel_access) {
-            struct hs_toplevel *tlfh;
-            for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-                if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-            }
-            if(tlfh) {
-                reply("HSMSG_FAKEHOST_TOPLEVEL_ALREADY_EXISTS", slfh_name, tlfh_name);
-                return 0;
-            }
-            hs_add_toplevel(tlfh_name);
-            reply("HSMSG_FAKEHOST_TOPLEVEL_ADDED", tlfh_name);
-            return 1;
-        }
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-        return 0;
-    } else {
-        struct hs_secondlevel *slfh;
-        struct hs_toplevel *tlfh;
-        for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-            if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-        }
-        if(!tlfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-            return 0;
-        }
-        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-            if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-        }
-        if(slfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-            return 0;
-        }
-        if(!check_management_access(hi, tlfh, NULL)) {
-            reply("HSMSG_FAKEHOST_SECONDLEVEL_ALREADY_EXISTS", slfh_name, tlfh_name);
-            return 0;
-        }
-        hs_add_secondlevel(tlfh, slfh_name);
-        reply("HSMSG_FAKEHOST_SECONDLEVEL_ADDED", slfh_name, tlfh_name);
-    }
-    return 0;
-}
-
-static MODCMD_FUNC(cmd_delhost) {
-    struct handle_info *hi;
-    if (!(hi = user->handle_info)) {
-        reply("NSMSG_MUST_AUTH");
-        return 0;
-    }
-    char *slfh_name = argv[1];
-    char *tlfh_name = strchr(argv[1], '.');
-    *tlfh_name = '\0';
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-        return 0;
-    }
-    struct hs_toplevel *tlfh;
-    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-        if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-    }
-    if(!tlfh) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-        return 0;
-    }
-    if(!irccasecmp(slfh_name, "*")) {
-        if(hi->opserv_level < hostserv_conf.toplevel_access) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-            return 0;
-        }
-        hs_del_toplevel(tlfh);
-        reply("HSMSG_FAKEHOST_TOPLEVEL_DELETED", tlfh_name);
-        return 1;
-    } else {
-        struct hs_secondlevel *slfh;
-        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-            if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-        }
-        if(!slfh || !check_management_access(hi, tlfh, NULL)) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-            return 0;
-        }
-        hs_del_secondlevel(slfh, 1);
-        reply("HSMSG_FAKEHOST_SECONDLEVEL_DELETED", slfh_name, tlfh_name);
-    }
-    return 0;
-}
-
 static MODCMD_FUNC(cmd_view) {
     struct handle_info *hi;
     if(argc >= 2 && !strchr(argv[1], '.')) {
@@ -713,39 +700,27 @@ static MODCMD_FUNC(cmd_view) {
             reply("NSMSG_MUST_AUTH");
             return 0;
         }
-        char *slfh_name = argv[1];
-        char *tlfh_name = strchr(argv[1], '.');
-        *tlfh_name = '\0';
-        tlfh_name++;
-        if(strchr(tlfh_name, '.')) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 0);
+        if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+            reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
             return 0;
-        }
-        struct hs_toplevel *tlfh;
-        for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-            if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-        }
-        if(!tlfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+            reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
-        if(!irccasecmp(slfh_name, "*")) {
-            if(!check_management_access(hi, tlfh, NULL)) {
-                reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        if(!fhinfo.slfh) {
+            if(!check_management_access(hi, fhinfo.tlfh, NULL)) {
+                reply("HSMSG_ACCESS_DENIED");
                 return 0;
             }
-            cmd_view_toplevel_information(user, cmd, tlfh);
+            cmd_view_toplevel_information(user, cmd, fhinfo.tlfh);
             return 1;
         } else {
-            struct hs_secondlevel *slfh;
-            for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-                if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-            }
-            if(!slfh || !check_management_access(hi, tlfh, slfh)) {
-                reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+            if(!check_management_access(hi, fhinfo.tlfh, fhinfo.slfh)) {
+                reply("HSMSG_ACCESS_DENIED");
                 return 0;
             }
-            cmd_view_secondlevel_information(user, cmd, slfh);
+            cmd_view_secondlevel_information(user, cmd, fhinfo.slfh);
             return 1;
         }
     } else {
@@ -799,7 +774,7 @@ static MODCMD_FUNC(cmd_view) {
                 reply("HSMSG_MANAGED_TOPLEVEL", tlfh->fakehost, slfhs, assignments);
             }
         }
-        for(manager = huser->managements; manager; manager = manager->next) {
+        for(manager = huser->managements; manager; manager = manager->unext) {
             if(manager->type == 2) {
                 struct hs_secondlevel *slfh = manager->object;
                 struct hs_toplevel *tlfh = slfh->toplevel;
@@ -822,77 +797,139 @@ static MODCMD_FUNC(cmd_view) {
     return 1;
 }
 
-static MODCMD_FUNC(cmd_addmanager) {
+static MODCMD_FUNC(cmd_addhost) {
     struct handle_info *hi;
-    char *fakehost;
-    if(argc >= 3) {
-        if(!strchr(argv[1], '.')) {
-            if (!(hi = modcmd_get_handle_info(user, argv[1])))
-                return 0;
-            fakehost = argv[2];
-        } else {
-            if (!(hi = modcmd_get_handle_info(user, argv[2])))
-                return 0;
-            fakehost = argv[1];
+    if (!(hi = user->handle_info)) {
+        reply("NSMSG_MUST_AUTH");
+        return 0;
+    }
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
+        return 0;
+    }
+    if(!fhinfo.have_secondlevel) {
+        if(!check_management_access(hi, NULL, NULL)) {
+            reply("HSMSG_ACCESS_DENIED");
+            return 0;
         }
-        char *slfh_name = fakehost;
-        char *tlfh_name = strchr(fakehost, '.');
-        *tlfh_name = '\0';
-        tlfh_name++;
-        if(strchr(tlfh_name, '.')) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        if(fhinfo.parse_state != HS_FHPARSE_UNKNOWN) {
+            reply("HSMSG_FAKEHOST_TOPLEVEL_ALREADY_EXISTS", fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
-        struct hs_toplevel *tlfh;
-        struct hs_secondlevel *slfh = NULL;
-        for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-            if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
+        hs_add_toplevel(fhinfo.tlfh_name);
+        reply("HSMSG_FAKEHOST_TOPLEVEL_ADDED", fhinfo.tlfh_name);
+    } else {
+        if(!fhinfo.tlfh) {
+            reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+            return 0;
         }
-        if(!tlfh) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        if(!check_management_access(hi, fhinfo.tlfh, NULL)) {
+            reply("HSMSG_ACCESS_DENIED");
             return 0;
         }
-        if(!irccasecmp(slfh_name, "*")) {
-            if(!check_management_access(user->handle_info, tlfh, NULL)) {
-                reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-                return 0;
-            }
-        } else {
-            for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-                if(!irccasecmp(slfh->fakehost, slfh_name)) break;
-            }
-            if(!slfh || !check_management_access(user->handle_info, tlfh, slfh)) {
-                reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-                return 0;
-            }
+        if(fhinfo.parse_state != HS_FHPARSE_UNKNOWN) {
+            reply("HSMSG_FAKEHOST_SECONDLEVEL_ALREADY_EXISTS", fhinfo.slfh_name, fhinfo.tlfh_name);
+            return 0;
         }
-        struct hs_user *huser = hs_get_user(hi, 1);
-        struct hs_manager *manager;
-        if(slfh) {
-            for(manager = huser->managements; manager; manager = manager->next) {
-                if(manager->type == 2 && manager->object == slfh) {
-                    reply("HSMSG_MANAGER_ALREADY", hi->handle, slfh_name, tlfh_name);
-                    return 0;
-                }
-            }
+        hs_add_secondlevel(fhinfo.tlfh, fhinfo.slfh_name);
+        reply("HSMSG_FAKEHOST_SECONDLEVEL_ADDED", fhinfo.slfh_name, fhinfo.tlfh_name);
+    }
+    return 1;
+}
+
+static MODCMD_FUNC(cmd_delhost) {
+    struct handle_info *hi;
+    if (!(hi = user->handle_info)) {
+        reply("NSMSG_MUST_AUTH");
+        return 0;
+    }
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
+        return 0;
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
+    }
+    if(!fhinfo.slfh) {
+        if(!check_management_access(hi, (hostserv_conf.manager_can_del_toplevel ? fhinfo.tlfh : NULL), NULL)) { /* manager access is enough to delete whole toplevel? */
+            reply("HSMSG_ACCESS_DENIED");
+            return 0;
         }
-        for(manager = huser->managements; manager; manager = manager->next) {
-            if(manager->type == 1 && manager->object == tlfh) {
-                reply("HSMSG_MANAGER_ALREADY", hi->handle, "*", tlfh_name);
-                return 0;
-            }
+        hs_del_toplevel(fhinfo.tlfh);
+        reply("HSMSG_FAKEHOST_TOPLEVEL_DELETED", fhinfo.tlfh_name);
+    } else {
+        if(!check_management_access(hi, fhinfo.tlfh, (hostserv_conf.manager_can_del_secondlevel ? fhinfo.slfh : NULL))) {
+            reply("HSMSG_ACCESS_DENIED");
+            return 0;
         }
-        if(slfh)
-            hs_add_manager_secondlevel(slfh, huser);
-        else
-            hs_add_manager_toplevel(tlfh, huser);
-        reply("HSMSG_MANAGER_ADDED", hi->handle, slfh_name, tlfh_name);
-        return 1;
+        hs_del_secondlevel(fhinfo.slfh, 1);
+        reply("HSMSG_FAKEHOST_SECONDLEVEL_DELETED", fhinfo.slfh_name, fhinfo.tlfh_name);
     }
-    return 0;
+    return 1;
 }
 
-static MODCMD_FUNC(cmd_delmanager) {
+static MODCMD_FUNC(cmd_renamehost) {
+    struct handle_info *hi;
+    if (!(hi = user->handle_info)) {
+        reply("NSMSG_MUST_AUTH");
+        return 0;
+    }
+    //old fakehost name
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
+        return 0;
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
+    }
+    //new fakehost name
+    struct hs_fakehost_info new_fhinfo = parse_fakehost_info(argv[2], 0);
+    if(new_fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
+        return 0;
+    } else if(new_fhinfo.parse_state != HS_FHPARSE_UNKNOWN && (irccasecmp(fhinfo.tlfh_name, new_fhinfo.tlfh_name) || (new_fhinfo.slfh && irccasecmp(fhinfo.slfh_name, new_fhinfo.slfh_name)))) {
+        reply("HSMSG_FAKEHOST_TOPLEVEL_ALREADY_EXISTS", new_fhinfo.slfh_name, new_fhinfo.tlfh_name);
+        return 0;
+    }
+    
+    if(!fhinfo.slfh) {
+        if(!check_management_access(hi, (hostserv_conf.manager_can_rename_toplevel ? fhinfo.tlfh : NULL), NULL)) { /* manager access is enough to delete whole toplevel? */
+            reply("HSMSG_ACCESS_DENIED");
+            return 0;
+        }
+        if(fhinfo.have_secondlevel) {
+            //can't rename toplevel into secondlevel fakehost!
+            new_fhinfo.tlfh_name--;
+            new_fhinfo.tlfh_name[0] = '.';
+            reply("HSMSG_TOPLEVEL_INVALID", new_fhinfo.slfh_name);
+            return 0;
+        }
+        if(strcmp(new_fhinfo.tlfh_name, fhinfo.tlfh->fakehost))
+            hs_rename_toplevel(fhinfo.tlfh, new_fhinfo.tlfh_name);
+        reply("HSMSG_FAKEHOST_RENAMED", fhinfo.slfh_name, fhinfo.tlfh_name, new_fhinfo.slfh_name, new_fhinfo.tlfh_name);
+    } else {
+        if(!check_management_access(hi, fhinfo.tlfh, (hostserv_conf.manager_can_rename_secondlevel ? fhinfo.slfh : NULL))) {
+            reply("HSMSG_ACCESS_DENIED");
+            return 0;
+        }
+        if(irccasecmp(new_fhinfo.tlfh_name, fhinfo.tlfh_name)) {
+            //can't rename toplevel and secondlevel fakehost with one command!
+            new_fhinfo.tlfh_name--;
+            new_fhinfo.tlfh_name[0] = '.';
+            reply("HSMSG_TOPLEVEL_INVALID", new_fhinfo.slfh_name);
+            return 0;
+        }
+        if(strcmp(new_fhinfo.slfh_name, fhinfo.slfh->fakehost))
+            hs_rename_secondlevel(fhinfo.slfh, new_fhinfo.slfh_name);
+        reply("HSMSG_FAKEHOST_RENAMED", fhinfo.slfh_name, fhinfo.tlfh_name, new_fhinfo.slfh_name, new_fhinfo.tlfh_name);
+    }
+    return 1;
+}
+
+static MODCMD_FUNC(cmd_addmanager) {
     struct handle_info *hi;
     char *fakehost;
     if(!strchr(argv[1], '.')) {
@@ -904,73 +941,105 @@ static MODCMD_FUNC(cmd_delmanager) {
             return 0;
         fakehost = argv[1];
     }
-    if(!fakehost) {
-        reply("HSMSG_ASSIGNED_NONE");
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", fakehost);
         return 0;
-    }
-    char *slfh_name = fakehost;
-    char *tlfh_name = strchr(fakehost, '.');
-    if(tlfh_name) {
-        *tlfh_name = '\0';
-    } else {
-        reply("HSMSG_ASSIGNED_NONE");
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    if(!check_management_access(user->handle_info, fhinfo.tlfh, fhinfo.slfh)) {
+        reply("HSMSG_ACCESS_DENIED");
         return 0;
     }
-    struct hs_toplevel *tlfh;
-    struct hs_secondlevel *slfh = NULL;
-    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-        if(!irccasecmp(tlfh->fakehost, tlfh_name)) break;
-    }
-    if(!tlfh) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-        return 0;
+    struct hs_user *huser = hs_get_user(hi, 1);
+    struct hs_manager *manager;
+    if(fhinfo.slfh) {
+        for(manager = huser->managements; manager; manager = manager->next) {
+            if(manager->type == 2 && manager->object == fhinfo.slfh) {
+                reply("HSMSG_MANAGER_ALREADY", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
+                return 0;
+            }
+        }
     }
-    if(!irccasecmp(slfh_name, "*")) {
-        if(!check_management_access(user->handle_info, tlfh, NULL)) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    for(manager = huser->managements; manager; manager = manager->next) {
+        if(manager->type == 1 && manager->object == fhinfo.tlfh) {
+            reply("HSMSG_MANAGER_ALREADY", hi->handle, "*", fhinfo.tlfh_name);
             return 0;
         }
-    } else {
-        for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-            if(!irccasecmp(slfh->fakehost, slfh_name)) break;
+    }
+    if(fhinfo.slfh)
+        hs_add_manager_secondlevel(fhinfo.slfh, huser);
+    else {
+        hs_add_manager_toplevel(fhinfo.tlfh, huser);
+        //remove from all slfh's
+        struct hs_manager *next_manager;
+        struct hs_secondlevel *slfh;
+        for(manager = huser->managements; manager; manager = next_manager) {
+            next_manager = manager->next;
+            if(manager->type == 2) {
+                slfh = manager->object;
+                if(slfh->toplevel == fhinfo.tlfh)
+                    hs_del_manager(manager, 1);
+            }
         }
-        if(!slfh || !check_management_access(user->handle_info, tlfh, slfh)) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    }
+    reply("HSMSG_MANAGER_ADDED", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
+    return 1;
+}
+
+static MODCMD_FUNC(cmd_delmanager) {
+    struct handle_info *hi;
+    char *fakehost;
+    if(!strchr(argv[1], '.')) {
+        if (!(hi = modcmd_get_handle_info(user, argv[1])))
             return 0;
-        }
+        fakehost = argv[2];
+    } else {
+        if (!(hi = modcmd_get_handle_info(user, argv[2])))
+            return 0;
+        fakehost = argv[1];
+    }
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", fakehost);
+        return 0;
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
+    }
+    if(!check_management_access(user->handle_info, fhinfo.tlfh, fhinfo.slfh)) {
+        reply("HSMSG_ACCESS_DENIED");
+        return 0;
     }
     struct hs_user *huser = hs_get_user(hi, 0);
     struct hs_manager *manager;
     if(!huser) {
-        reply("HSMSG_MANAGER_NOT", hi->handle, slfh_name, tlfh_name);
+        reply("HSMSG_MANAGER_NOT", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
-    if(slfh) {
-        for(manager = huser->managements; manager; manager = manager->next) {
-            if(manager->type == 2 && manager->object == slfh) 
+    if(fhinfo.slfh) {
+        for(manager = huser->managements; manager; manager = manager->unext) {
+            if(manager->type == 2 && manager->object == fhinfo.slfh) 
                 break;
         }
         if(!manager) {
-            reply("HSMSG_MANAGER_NOT", hi->handle, slfh_name, tlfh_name);
+            reply("HSMSG_MANAGER_NOT", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
     } else {
-        for(manager = huser->managements; manager; manager = manager->next) {
-            if(manager->type == 1 && manager->object == tlfh) 
+        for(manager = huser->managements; manager; manager = manager->unext) {
+            if(manager->type == 1 && manager->object == fhinfo.tlfh) 
                 break;
         }
         if(!manager) {
-            reply("HSMSG_MANAGER_NOT", hi->handle, "*", tlfh_name);
+            reply("HSMSG_MANAGER_NOT", hi->handle, "*", fhinfo.tlfh_name);
             return 0;
         }
     }
     hs_del_manager(manager, 1);
-    reply("HSMSG_MANAGER_DELETED", hi->handle, slfh_name, tlfh_name);
+    reply("HSMSG_MANAGER_DELETED", hi->handle, fhinfo.slfh_name, fhinfo.tlfh_name);
     return 1;
 }
 
@@ -978,57 +1047,44 @@ static MODCMD_FUNC(cmd_set) {
     struct handle_info *hi;
     struct hs_user *hs_user;
     struct hs_assignment *assignment;
-    struct hs_assignment *assgn;
     struct hs_toplevel *tlfh;
     struct hs_secondlevel *slfh;
-    char *fakehost;
     
     if (!(hi = user->handle_info)) {
         reply("NSMSG_MUST_AUTH");
         return 0;
     }
     hs_user = hs_get_user(hi, 0);
+    if(!hs_user)
+        return 0; //nothing to do here
     if(!strcmp(argv[1], "*")) {
-        hi->fakehost = NULL;
-        apply_fakehost(hi, NULL);
-        if(hs_user->assignments) {
-            for(assgn = hs_user->assignments; assgn; assgn = assgn->unext) {
-                assgn->active = 0;
-            }
-        }
+        hs_activate_assignment(hs_user, NULL);
         return 1;
     } else {
-        if(!strchr(argv[1], '.')) {
+        struct hs_fakehost_info fhinfo = parse_fakehost_info(argv[1], 1);
+        if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+            reply("HSMSG_TOPLEVEL_INVALID", argv[1]);
             return 0;
-        }
-        fakehost = argv[1];
-        char *slfh_name = fakehost;
-        char *tlfh_name = strchr(fakehost, '.');
-        *tlfh_name = '\0';
-        tlfh_name++;
-        if(strchr(tlfh_name, '.')) {
-            reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN) {
+            reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
             return 0;
         }
         for(assignment = hs_user->assignments; assignment; assignment = assignment->unext) {
             slfh = assignment->secondlevel;
             tlfh = slfh->toplevel;
-            if(!irccasecmp(slfh_name, slfh->fakehost)) {
-                if(!irccasecmp(tlfh_name, tlfh->fakehost)) {
-                    activateAssignment(assignment);
-                    reply("HSMSG_FAKEHOST_SET_SUCCESS", slfh->fakehost, tlfh->fakehost);
-                    return 1;
-                }
+            if(tlfh == fhinfo.tlfh && slfh == fhinfo.slfh) {
+                hs_activate_assignment(hs_user, assignment);
+                reply("HSMSG_FAKEHOST_SET_SUCCESS", slfh->fakehost, tlfh->fakehost);
+                return 1;
             }
         }
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
 }
 
 static MODCMD_FUNC(cmd_assign) {
     struct handle_info *hi;
-    struct handle_info *hiuser;
     char *fakehost;
     if(!strchr(argv[1], '.')) {
         if (!(hi = modcmd_get_handle_info(user, argv[1])))
@@ -1039,52 +1095,34 @@ static MODCMD_FUNC(cmd_assign) {
             return 0;
         fakehost = argv[1];
     }
-    if (!(hiuser = user->handle_info)) {
+    if (!user->handle_info) {
         reply("NSMSG_MUST_AUTH");
         return 0;
     }
-    if(!fakehost) {
-        reply("HSMSG_ASSIGNED_NONE");
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", fakehost);
         return 0;
-    }
-    char *slfh_name = fakehost;
-    char *tlfh_name = strchr(fakehost, '.');
-    if(tlfh_name) {
-        *tlfh_name = '\0';
-    } else {
-        reply("HSMSG_ASSIGNED_NONE");
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN || !fhinfo.slfh) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    struct hs_user *hs_user = hs_get_user(hi, 1);
+    if(!check_management_access(user->handle_info, fhinfo.tlfh, fhinfo.slfh)) {
+        reply("HSMSG_ACCESS_DENIED");
         return 0;
     }
-    struct hs_toplevel *tlfh;;
-    struct hs_secondlevel *slfh;
-    struct hs_user *hs_user = hs_get_user(hi, 1);
-    for(tlfh = toplevels; tlfh; tlfh = tlfh->next) {
-        if(!irccasecmp(tlfh_name, tlfh->fakehost)) {
-            for(slfh = tlfh->secondlevel; slfh; slfh = slfh->next) {
-                if(!irccasecmp(slfh_name, slfh->fakehost)) {
-                    if(check_management_access(hiuser, tlfh, slfh)) {
-                        hs_add_assignment(slfh, hs_user);
-                        reply("HSMSG_FAKEHOST_ASSIGN_SUCCESS", slfh_name, tlfh_name);
-                        return 1;
-                    }
-                    reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-                    return 0;
-                }
-            }
-        }
+    if(hs_get_assignment(fhinfo.slfh, hs_user)) {
+        reply("HSMSG_FAKEHOST_ASSIGNED", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
     }
-    reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-    return 0;
+    hs_add_assignment(fhinfo.slfh, hs_user, HS_ASSIGNMENTSTATE_AUTO);
+    reply("HSMSG_FAKEHOST_ASSIGN_SUCCESS", fhinfo.slfh_name, fhinfo.tlfh_name);
+    return 1;
 }
 
-static MODCMD_FUNC(cmd_revoke) {
+static MODCMD_FUNC(cmd_unassign) {
     struct handle_info *hi;
-    struct handle_info *hiuser;
     char *fakehost;
     if(!strchr(argv[1], '.')) {
         if (!(hi = modcmd_get_handle_info(user, argv[1])))
@@ -1095,48 +1133,98 @@ static MODCMD_FUNC(cmd_revoke) {
             return 0;
         fakehost = argv[1];
     }
-    if (!(hiuser = user->handle_info)) {
+    if (!user->handle_info) {
         reply("NSMSG_MUST_AUTH");
         return 0;
     }
-    if(!fakehost) {
-        reply("HSMSG_ASSIGNED_NONE");
+    struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+    if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+        reply("HSMSG_TOPLEVEL_INVALID", fakehost);
+        return 0;
+    } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN || !fhinfo.slfh) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
-    char *slfh_name = fakehost;
-    char *tlfh_name = strchr(fakehost, '.');
-    if(tlfh_name) {
-        *tlfh_name = '\0';
-    } else {
-        reply("HSMSG_ASSIGNED_NONE");
+    struct hs_assignment *assignment;
+    struct hs_user *hs_user = hs_get_user(hi, 0);
+    if(!hs_user) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
+    }
+    if(!check_management_access(user->handle_info, fhinfo.tlfh, fhinfo.slfh)) {
+        reply("HSMSG_ACCESS_DENIED");
         return 0;
     }
-    tlfh_name++;
-    if(strchr(tlfh_name, '.')) {
-        reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
+    if(!(assignment = hs_get_assignment(fhinfo.slfh, hs_user))) {
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
         return 0;
     }
+    hs_del_assignment(assignment, 1);
+    reply("HSMSG_FAKEHOST_UNASSIGN_SUCCESS", fhinfo.slfh_name, fhinfo.tlfh_name);
+    return 1;
+}
+
+static MODCMD_FUNC(cmd_oset) {
+    struct handle_info *hi;
+    char *fakehost;
     struct hs_assignment *assignment;
-    struct hs_user *hs_user = hs_get_user(hi, 0);
+    if(!strchr(argv[1], '.')) {
+        if (!(hi = modcmd_get_handle_info(user, argv[1])))
+            return 0;
+        fakehost = argv[2];
+    } else {
+        if (!(hi = modcmd_get_handle_info(user, argv[2])))
+            return 0;
+        fakehost = argv[1];
+    }
+    if (!user->handle_info) {
+        reply("NSMSG_MUST_AUTH");
+        return 0;
+    }
+    struct hs_user *hs_user = hs_get_user(hi, 1);
     for(assignment = hs_user->assignments; assignment; assignment = assignment->unext) {
-        if(!irccasecmp(slfh_name, assignment->secondlevel->fakehost)) {
-            if(!irccasecmp(tlfh_name, assignment->secondlevel->toplevel->fakehost)) {
-                if(check_management_access(hi, assignment->secondlevel->toplevel, assignment->secondlevel)) {
-                    hs_del_assignment(assignment, 1);
-                    reply("HSMSG_FAKEHOST_REVOKE_SUCCESS", slfh_name, tlfh_name);
-                    return 1;
-                }
-                reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-                return 0;
+        if(assignment->active)
+            break;
+    }
+    if(assignment && !check_management_access(user->handle_info, (hostserv_conf.manager_toplevel_can_oset ? assignment->secondlevel->toplevel : NULL), (hostserv_conf.manager_secondlevel_can_oset ? assignment->secondlevel : NULL))) {
+        reply("HSMSG_ACCESS_DENIED");
+        return 0;
+    }
+    if(!strcmp(argv[1], "*")) {
+        if(!assignment)
+            return 0; //simply ignore (there is no assignment in use)
+        hs_activate_assignment(hs_user, NULL);
+        return 1;
+    } else {
+        struct hs_fakehost_info fhinfo = parse_fakehost_info(fakehost, 1);
+        if(fhinfo.parse_state == HS_FHPARSE_INVALID) {
+            reply("HSMSG_TOPLEVEL_INVALID", fakehost);
+            return 0;
+        } else if(fhinfo.parse_state == HS_FHPARSE_UNKNOWN || !fhinfo.slfh) {
+            reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+            return 0;
+        }
+        if(!check_management_access(user->handle_info, (hostserv_conf.manager_toplevel_can_oset ? fhinfo.tlfh : NULL), (hostserv_conf.manager_secondlevel_can_oset ? fhinfo.slfh : NULL))) {
+            reply("HSMSG_ACCESS_DENIED");
+            return 0;
+        }
+        struct hs_toplevel *tlfh;
+        struct hs_secondlevel *slfh;
+        for(assignment = hs_user->assignments; assignment; assignment = assignment->unext) {
+            slfh = assignment->secondlevel;
+            tlfh = slfh->toplevel;
+            if(tlfh == fhinfo.tlfh && slfh == fhinfo.slfh) {
+                hs_activate_assignment(hs_user, assignment);
+                reply("HSMSG_FAKEHOST_SET_SUCCESS", slfh->fakehost, tlfh->fakehost);
+                return 1;
             }
         }
+        reply("HSMSG_UNKNOWN_FAKEHOST", fhinfo.slfh_name, fhinfo.tlfh_name);
+        return 0;
     }
-    reply("HSMSG_UNKNOWN_FAKEHOST", slfh_name, tlfh_name);
-    return 0;
 }
 
-static void hostserv_conf_read(void)
-{
+static void hostserv_conf_read(void) {
     dict_t conf_node;
     const char *str;
 
@@ -1159,10 +1247,26 @@ static void hostserv_conf_read(void)
     unsigned int toplevel_access = atoi(str);
     hostserv_conf.toplevel_access = (toplevel_access ? toplevel_access : 600);
     
-    /*str = database_get_data(conf_node, "description", RECDB_QSTRING);
-    hostserv_conf.description = (str ? str : NULL);*/
-    str = database_get_data(conf_node, KEY_TITLEHOST_SUFFIX, RECDB_QSTRING);
-    title_suffix = str ? str : "example.net";
+    str = database_get_data(conf_node, "fallback_other_assignment", RECDB_QSTRING);
+    hostserv_conf.fallback_other_assignment = (atoi(str) ? 1 : 0);
+    
+    str = database_get_data(conf_node, "manager_can_del_toplevel", RECDB_QSTRING);
+    hostserv_conf.manager_can_del_toplevel = (atoi(str) ? 1 : 0);
+    
+    str = database_get_data(conf_node, "manager_can_del_secondlevel", RECDB_QSTRING);
+    hostserv_conf.manager_can_del_secondlevel = (atoi(str) ? 1 : 0);
+    
+    str = database_get_data(conf_node, "manager_can_rename_toplevel", RECDB_QSTRING);
+    hostserv_conf.manager_can_rename_toplevel = (atoi(str) ? 1 : 0);
+    
+    str = database_get_data(conf_node, "manager_can_rename_secondlevel", RECDB_QSTRING);
+    hostserv_conf.manager_can_rename_secondlevel = (atoi(str) ? 1 : 0);
+    
+    str = database_get_data(conf_node, "manager_toplevel_can_oset", RECDB_QSTRING);
+    hostserv_conf.manager_toplevel_can_oset = (atoi(str) ? 1 : 0);
+    
+    str = database_get_data(conf_node, "manager_secondlevel_can_oset", RECDB_QSTRING);
+    hostserv_conf.manager_secondlevel_can_oset = (atoi(str) ? 1 : 0);
 }
 
 static int hostserv_saxdb_read_secondlevel(const char *name, void *data, UNUSED_ARG(void *extra));
@@ -1237,18 +1341,15 @@ static int hostserv_saxdb_read_assignments(const char *name, void *data, UNUSED_
     struct record_data *rd = data;
     struct hs_secondlevel *slfh = extra;
     struct hs_user *user;
-    struct hs_assignment *assng;
+    int active;
     
     if (rd->type == RECDB_OBJECT) {
         dict_t db = GET_RECORD_OBJECT(rd);
         
         user = hs_get_user(get_handle_info(name), 1);
-        assng = hs_add_assignment(slfh, user);
+        active = (database_get_data(db, KEY_ACTIVE, RECDB_QSTRING) ? HS_ASSIGNMENTSTATE_ON : HS_ASSIGNMENTSTATE_OFF);
         
-        if (database_get_data(db, KEY_ACTIVE, RECDB_QSTRING))
-            assng->active = 1;
-        else
-            assng->active = 0;
+        hs_add_assignment(slfh, user, active);
     }
     
     return 0;
@@ -1347,9 +1448,11 @@ int hostserv_init() {
     modcmd_register(hostserv_module, "delmanager", cmd_delmanager, 3, MODCMD_REQUIRE_AUTHED, NULL);
     modcmd_register(hostserv_module, "set", cmd_set, 2, MODCMD_REQUIRE_AUTHED, NULL);
     modcmd_register(hostserv_module, "assign", cmd_assign, 3, MODCMD_REQUIRE_AUTHED, NULL);
-    modcmd_register(hostserv_module, "revoke", cmd_revoke, 3, MODCMD_REQUIRE_AUTHED, NULL);
+    modcmd_register(hostserv_module, "unassign", cmd_unassign, 3, MODCMD_REQUIRE_AUTHED, NULL);
     modcmd_register(hostserv_module, "addhost", cmd_addhost, 2, MODCMD_REQUIRE_AUTHED, NULL);
     modcmd_register(hostserv_module, "delhost", cmd_delhost, 2, MODCMD_REQUIRE_AUTHED, NULL);
+    modcmd_register(hostserv_module, "renamehost", cmd_renamehost, 3, MODCMD_REQUIRE_AUTHED, NULL);
+    modcmd_register(hostserv_module, "oset", cmd_oset, 3, MODCMD_REQUIRE_AUTHED, NULL);
     message_register_table(msgtab);
     return 1;
 }