16 Commits
  • Update netcup DNS API to support new API (#7214)
    * dns_netcup: add support for the new netcup REST API
    
    Domains managed by the new DNS backend can be handled through the new
    REST API at api.netcup.com. The API is selected by the length of
    NC_Apikey: new REST API keys are 64 characters long, legacy CCP API
    keys are 50.
    
    With a REST API key the domain is looked up via GET /v1/domain and the
    challenge record is managed through the dedicated ACME challenge
    endpoints. After adding a record, the script waits 20 seconds and then
    polls until the record reports the deployed status.
    
    Domains whose DNS cannot be managed via the REST API yet fall back to
    the legacy CCP API when NC_Apikey_Legacy, NC_Apipw and NC_CID are
    configured.
    
    * dns_netcup: treat non-challenge records as a no-op on the REST API
    
    The REST API can only manage _acme-challenge records, records with
    other names cannot exist behind it. The DNS-API-Test adds and removes
    a TXT record outside _acme-challenge and expects both calls to
    succeed, so treat such records as a successful no-op with an info
    message instead of failing.
    
    * dns_netcup: address review feedback for the REST API support
    
    - Only skip the synthetic DNS-API-Test record: real records without
      the _acme-challenge prefix (e.g. a challenge alias in the "=" form)
      now fail loudly, or use the legacy CCP API when legacy credentials
      are configured. The zone walk starts at the full name for them, so
      an apex alias is found.
    - Blank _H2..._H5 for REST API calls and clear all header slots before
      legacy CCP API calls so no auth headers leak between endpoints or
      dns hooks.
    - Stop walking the zone lookup when the API reports success:false and
      surface the response instead of a misleading "no zone found".
    - Split the response before extracting id/isDnsManaged so the egrep
      and sed implementations of _egrep_o cannot pick different matches.
    - Fall back to the legacy CCP API only on a literal isDnsManaged
      false; error distinctly on an unparsable value.
    - Poll the deploy status right away and sleep between retries instead
      of an unconditional 20 second sleep.
    - Use ${#NC_Apikey} for the key length and rename internal state to
      _nc_apikey/_nc_endrest.
    
    * dns_netcup: walk on when the REST API reports resourceDoesNotExist
    
    Querying /domain?fqdn= for a name that is not a domain of the account
    does not return an empty result: the API answers with success:false
    and the error code resourceDoesNotExist. Treat exactly that as "not
    found" during the zone walk and keep failing hard on everything else,
    e.g. an invalid API key.
  • Fix dns_netcup reporting a bogus 4013 instead of the real zone error
    The zone lookup walked the challenge name from the right and ended up
    asking netcup for the full "_acme-challenge.<domain>" as a zone name.
    That can never be a zone, so netcup answered 4013 "Validation Error",
    which replaced the real 5028 "The zone <domain> could not be found" as
    the error shown to the user.
    
    Stop one label short of the full name, and fail explicitly when no zone
    matched, reporting the last API response plus what to check. Before, a
    run where every candidate returned 5028 fell through to logout and
    returned success.
  • DNS provider API: structured description
    Instead of using comments declare info in a special variable.
    Then the variable can be used to print the DNS API provider usage.
    The usage can be parsed on UI and show all needed inputs for options.
    
    The info is stored in plain string that it's both human-readable and easy to parse:
    
        dns_example_info='API name
         An extended description.
         Multiline.
        Domains: list of alternative domains to find
        Site: the dns provider website e.g. example.com
        Docs: Link to ACME.sh wiki for the provider
        Options:
         VARIABLE1 Title for the option1.
         VARIABLE2 Title for the option2. Default "default value".
         VARIABLE3 Title for the option3. Description to show on UI. Optional.
        Issues: Link to a support ticket on https://github.com/acmesh-official/acme.sh
        Author: First Lastname <authoremail@example.com>, Another Author <https://github.com/example>;
        '
    
    Here:
    VARIABLE1 will be required.
    VARIABLE2 will be required too but will be populated with a "default value".
    VARIABLE3 is optional and can be empty.
    
    A DNS provider may have alternative options like CloudFlare may use API KEY or API Token.
    You can use a second section OptionsAlt: section.
    
    Some providers may have alternative names or domains e.g. Aliyun and AlibabaCloud.
    Add them to Domains: section.
    
    Signed-off-by: Sergey Ponomarev <stokito@gmail.com>
  • Fix variable name
    Wrong variable name was used in login() and logout(), preventing operation.
  • sync (#2297)
    * Create LICENSE.md
    
    * remove _hostingde_parse_no_strip_whitespace function as this breaks API requests
    
    * Fix sessionid parsing on BSD
    
    * Make travis happy. (SC2020)
    
    * fix for https://github.com/Neilpang/acme.sh/issues/2286
    
    * Notify mail update (#2293)
    
    * feat: disable e-mail validation if MAIL_NOVALIDATE is set
    
    * fix: expose _MAIL_BIN variable
    
    * fix: call _mail_body and _mail_cmnd directly to make sure that all used variables are exposed
    
    * fix: update notify/mail.sh
    
    Co-Authored-By: Matej Mihevc <zuexo@users.noreply.github.com>
    
    * fix: remove useless echo, quote eval