#!/usr/bin/env bash

APP_ROOT=`dirname $0`
CONFIG_FILE="$APP_ROOT/mo-ssh.conf"
LOG_FILE="$APP_ROOT/mo-ssh.log";
AUTH_STATUS_TIMEOUT=4
AUTH_STATUS_END=0
TRANSACTION_ID=0
MO_RESPONSE_MESSAGE=""
MO_HOST="https://login.xecurify.com/moas"
DEBUG=1

OK=0
FAIL=1

function debug() {    
	time=$(date +"%d-%m-%y :: %H:%M:%S")
	echo "[$time] $*" >> $LOG_FILE
	echo ">>> $*"
}

function escape_input() {
  sed "s/[;\`\"\$\' ]//g" <<<$*
}

function escape_number() {
  sed 's/[^0-9]*//g' <<< $*
}

function read_input() {
  read input
  echo "$(escape_input $input)"
}

function run_shell()
{
	if [[ "$SSH_ORIGINAL_COMMAND" != "" ]] # when user runs: ssh server <command>
    then
        debug "running command: $SSH_ORIGINAL_COMMAND"
        exec /bin/bash -c "${SSH_ORIGINAL_COMMAND}"
    elif [ $SHELL ] # when user runs: ssh server
    then
        debug "running shell: $SHELL"
        exec -l $SHELL
    fi

    exit $?
}

function check_config_file() {
    debug "Checking config file at $CONFIG_FILE"
    dir=`dirname ${CONFIG_FILE}`
    if [[ ! -r $dir ]]
    then
        debug "ERROR: ${dir} cannot be written by $USER"
        return $FAIL
    fi

    if [[ ! -f $CONFIG_FILE ]]
    then
        debug "miniOrange ssh module has not been configured yet." # FIXME: add more info
        return $FAIL
    fi

    if [[ $1 == "writable" && ! -w $CONFIG_FILE ]]
    then
        debug "$CONFIG_FILE is not writable. Please try again using sudo"
        exit $FAIL
    fi

    chmod 644 "$CONFIG_FILE" 2>/dev/null
    return $OK
}

function find_sshd_config() {
    debug "Trying to find sshd_config file"
    if [[ -f /etc/sshd_config ]]
    then
        SSHD_CONFIG="/etc/sshd_config"
    elif [[ -f /etc/ssh/sshd_config ]]
    then
        SSHD_CONFIG="/etc/ssh/sshd_config"
    else
        debug "Cannot find sshd_config in your server. miniOrange SSH module will be enabled when you add the ForceCommand to it"
    fi
}

function check_sshd_config_file() {
  debug "Checking the validity of $SSHD_CONFIG file..."

  sshd -t

  if [ $? -ne 0 ]
  then
    debug "sshd_config file is invalid. MAKE SURE YOU DO NOT RESTART THE SSH SERVER UNTIL YOU FIX IT."
    exit $FAIL
  fi

}

function add_force_command() {
    debug "Trying to add force command to $SSHD_CONFIG"
    find_sshd_config
    mo_ssh_command="$1"

    if [[ -w $SSHD_CONFIG ]]
    then
      debug "Adding 'ForceCommand ${mo_ssh_command} login' to ${SSHD_CONFIG}"     

      echo -e "\nForceCommand ${mo_ssh_command} login" >> ${SSHD_CONFIG}
      echo ""

      check_sshd_config_file

      debug "MAKE SURE YOU DO NOT MOVE/REMOVE ${mo_ssh_command} BEFORE UNINSTALLING miniOrange SSH module."
      sleep 5
    fi
}

function read_config() {
    key="$1"

    if [[ -f $CONFIG_FILE ]]
    then
        KEYFOUND=$FAIL
        while IFS='=' read -r ckey value
        do
            if [[ $ckey == $key ]]
            then
                echo $value # don't stop the loop so we can read repeated keys				
                KEYFOUND=$OK
            fi
        done < $CONFIG_FILE
        return $KEYFOUND
    fi

    debug "ERROR: $config_file couldn't be found"
    return $FAIL
}

function uninstall_miniorange() {
    find_sshd_config

    if [[ $1 != "quiet" ]]
    then
      debug "Uninstalling miniOrange SSH module from $SSHD_CONFIG..."
    fi

    if [[ -w $SSHD_CONFIG ]]
    then
        sed -ie '/^ForceCommand.*mo-ssh.*/d' $SSHD_CONFIG
    fi

    if [[ $1 != "quiet" ]]
    then
        debug "miniOrange SSH module was uninstalled."
        debug "Now restart the ssh server to apply changes and then remove ${APP_ROOT}/mo-ssh and $CONFIG_FILE"
    fi
}

function install_miniorange() {
    source="$1"
    dest="$2/mo-ssh"

	
	
    if [[ ! $2 ]]
    then
      dest="/usr/local/bin/mo-ssh" # defaults to /usr/local/bin
    fi
    config_file="${dest}.conf"
    log_file="${dest}.log"
	touch $log_file

    #
    # Ensure our target directory is present
    #
    set -e
    mkdir -p `dirname "${dest}"`
    set +e

    if [[ ! -r `dirname "${dest}"` ]]
    then
      debug "${dest} is not writable. Try again using sudo"
      return $FAIL
    fi

    debug "Copying ${source} to ${dest}..."
    cp "${source}" "${dest}"

    debug "Setting up permissions..."
    chmod 755 $dest
    chmod 766 $log_file
	
	 if [[ ! -f ${config_file} ]]
     then
       echo -n "Enter the miniOrange account email: "
       read  mo_email_address
	   echo -n "Enter the miniOrange account password: "
	   read -s mo_email_password
	   echo -e "\n\nVerifying your miniOrange account.\n"	
	  url="$MO_HOST/rest/customer/key"
	  
	  CURL_HEADERS=(
             '-H' "Authorization: Basic"             
             '-H' 'Content-Type: application/json'
             '-H' 'charset: UTF - 8'
)
	  post_data='{"email":"'$mo_email_address'","password":"'$mo_email_password'"}'		
	mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`	
	IFS='|' mo_response_body1=($mo_response)
	
	transaction_status=$(echo $mo_response_body1 | jq '.status')
		if [ $transaction_status == '"SUCCESS"' ]
		then
			customer_api_key=$(echo $mo_response_body1 | jq -r '.apiKey')
	customer_id=$(echo $mo_response_body1 | jq '.id')	
		echo "message=Logged in successfully" > "${config_file}"
		debug "${mo_email_address} verfied successfully."		
      echo "customer_api_key=${customer_api_key}" >> "${config_file}"
      echo "customer_id=${customer_id}" >> "${config_file}"
	  add_force_command "${dest}"
		else
			debug "Invalid Email or Password."
		fi
	      
     else
       debug "A config file was found on ${config_file}. Edit it manually if you want to change the customer details"
	   add_force_command "${dest}"
     fi
     chmod 644 ${config_file}	 
    
}

function require_curl() {
    which curl 2>&1 > /dev/null
    if [ $? -eq 0 ]
    then
      return $OK
    fi

    # if `which` is not installed this check is ran
    curl --help 2>&1 > /dev/null

    return $FAIL
}

function require_jq() {
	which jq 2>&1 > /dev/null
    if [ $? -eq 0 ]
    then
      return $OK
    fi

    # if `which` is not installed this check is ran
    jq --help 2>&1 > /dev/null

    return $FAIL
}

function hash_value_function()
{
python - <<END
import os
import hashlib
string_to_hash = os.environ['STRING_TO_HASH']
hash_object = hashlib.sha512(string_to_hash.encode())
hex_dig = hash_object.hexdigest()
print(hex_dig)
END
}


function request_sms() {

	mo_email_address="$1"	
	mo_auth_type="$2"
	
	url="$MO_HOST/api/auth/challenge"
	customer_key="$(read_config customer_id)"	
	customer_api_key="$(read_config customer_api_key)"	
	current_time_in_miliseconds="$(date +%s%N | cut -b1-13)"
	export STRING_TO_HASH="$customer_key$current_time_in_miliseconds$customer_api_key"	
	HV="$(hash_value_function)"	

	CURL_HEADERS=(
             '-H' "Authorization: ${HV}"
             '-H' "Customer-Key: ${customer_key}"
             '-H' "Timestamp: ${current_time_in_miliseconds}"
             '-H' 'Content-Type: application/json'
)

	post_data='{"customerKey":'$customer_key',"username":"'$mo_email_address'","authType":"'$mo_auth_type'","transactionName":"2FA over SSH"}'
			
	mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`		
	IFS='|' mo_response_body1=($mo_response)
	status=$(echo $mo_response_body1 | jq '.status')	
	if [[ $status == '"SUCCESS"' ]]
	then
		sms_status=$(echo $mo_response_body1 | jq -r '.phoneDelivery.sendStatus')
		email_status=$(echo $mo_response_body1 | jq -r .'emailDelivery.sendStatus')
		MO_RESPONSE_MESSAGE=$(echo $mo_response_body1 | jq '.message')
		case $mo_auth_type in
		("SMS" | "OUT OF BAND SMS")
			if [[ $sms_status == 'SUCCESS' ]]
			then
				TRANSACTION_ID=$(echo $mo_response_body1 | jq '.txId')
				return $OK
			else 
				return $FAIL
			fi	
		;;
		("EMAIL" | "OUT OF BAND EMAIL")
			if [[ $email_status == 'SUCCESS' ]]
			then
				TRANSACTION_ID=$(echo $mo_response_body1 | jq '.txId')
				return $OK
			else 
				return $FAIL
			fi		
		;;
		("SMS AND EMAIL")
			if [[ $sms_status == 'SUCCESS' && $email_status == 'SUCCESS' ]]
			then
				TRANSACTION_ID=$(echo $mo_response_body1 | jq '.txId')
				return $OK
			else 
				return $FAIL
			fi		
		;;
		*)
		esac	
	else
		return $FAIL
	fi
			 
}

function request_push_notification() {
	mo_email_address="$1"	
	mo_auth_type="$2"
	
	url="$MO_HOST/api/auth/challenge"
	customer_key="$(read_config customer_id)"	
	customer_api_key="$(read_config customer_api_key)"	
	current_time_in_miliseconds="$(date +%s%N | cut -b1-13)"
	export STRING_TO_HASH="$customer_key$current_time_in_miliseconds$customer_api_key"	
	HV="$(hash_value_function)"	

	CURL_HEADERS=(
             '-H' "Authorization: ${HV}"
             '-H' "Customer-Key: ${customer_key}"
             '-H' "Timestamp: ${current_time_in_miliseconds}"
             '-H' 'Content-Type: application/json'
)

	post_data='{"customerKey":'$customer_key',"username":"'$mo_email_address'","authType":"'$mo_auth_type'","transactionName":"2FA over SSH"}'
	
	mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`	
	IFS='|' mo_response_body1=($mo_response)
	status=$(echo $mo_response_body1 | jq '.status')
	if [[ $status == '"SUCCESS"' ]]
	then
		TRANSACTION_ID=$(echo $mo_response_body1 | jq '.txId')
		MO_RESPONSE_MESSAGE=$(echo $mo_response_body1 | jq '.message')
		return $OK
	else
		return $FAIL
	fi	
}

function get_auth_status(){
	 url="$MO_HOST/api/auth/auth-status"
	 customer_key="$(read_config customer_id)"	 
	 customer_api_key="$(read_config customer_api_key)"
	 current_time_in_miliseconds="$(date +%s%N | cut -b1-13)"
	 export STRING_TO_HASH="$customer_key$current_time_in_miliseconds$customer_api_key"	 
	 HV="$(hash_value_function)"	 

	 CURL_HEADERS=(
             '-H' "Authorization: ${HV}"
             '-H' "Customer-Key: ${customer_key}"
             '-H' "Timestamp: ${current_time_in_miliseconds}"
             '-H' 'Content-Type: application/json'
)


	 post_data='{"txId":'$TRANSACTION_ID'}'
	 mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`	 
	IFS='|' mo_response_body1=($mo_response)	 
	 status=$(echo $mo_response_body1 | jq '.status')
	 if [[ $status == '"IN_PROGRESS"' ]] 
	 then
		echo "Validation in progress"
		sleep $AUTH_STATUS_TIMEOUT
		if [ $AUTH_STATUS_END -ne 180 ]
		then
		AUTH_STATUS_END=$(( $AUTH_STATUS_END + $AUTH_STATUS_TIMEOUT ))		
		get_auth_status
		else
		echo "Timeout in Validation"
		return $FAIL
		fi
	 elif [[ $status == '"SUCCESS"' ]]
	 then
		return $OK
	 else
		return $FAIL
	fi	
}

function validate_token() {

	 mo_token="$1"	 
	 url="$MO_HOST/api/auth/validate"
	 customer_key="$(read_config customer_id)"	 
	 customer_api_key="$(read_config customer_api_key)"
	 current_time_in_miliseconds="$(date +%s%N | cut -b1-13)"
	 export STRING_TO_HASH="$customer_key$current_time_in_miliseconds$customer_api_key"	 
	 HV="$(hash_value_function)"	 

	 CURL_HEADERS=(
             '-H' "Authorization: ${HV}"
             '-H' "Customer-Key: ${customer_key}"
             '-H' "Timestamp: ${current_time_in_miliseconds}"
             '-H' 'Content-Type: application/json'
)

	 post_data='{"txId":'$TRANSACTION_ID',"token":"'$mo_token'"}'	
	 mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`
	IFS='|' mo_response_body1=($mo_response)	 
	 status=$(echo $mo_response_body1 | jq '.status')
	 status_message=$(echo $mo_response_body1 | jq '.message')	 
	if [[ $status == '"SUCCESS"' ]]
	then		
		return $OK
	else		
		return $FAIL
	fi	
}

function validate_soft_token() {
	mo_user_email="$1"
	mo_soft_token="$2"
	mo_auth_type="$3"
	 
	 url="$MO_HOST/api/auth/validate"
	 customer_key="$(read_config customer_id)"	 
	 customer_api_key="$(read_config customer_api_key)"
	 current_time_in_miliseconds="$(date +%s%N | cut -b1-13)"
	 export STRING_TO_HASH="$customer_key$current_time_in_miliseconds$customer_api_key"	 
	 HV="$(hash_value_function)"	 

	 CURL_HEADERS=(
             '-H' "Authorization: ${HV}"
             '-H' "Customer-Key: ${customer_key}"
             '-H' "Timestamp: ${current_time_in_miliseconds}"
             '-H' 'Content-Type: application/json'
)

	 post_data='{"customerKey":'$customer_key',"username":"'$mo_user_email'","token":"'$mo_soft_token'","authType":"'$mo_auth_type'"}'	
	 mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`
	IFS='|' mo_response_body1=($mo_response)	 
	 status=$(echo $mo_response_body1 | jq '.status')
	 status_message=$(echo $mo_response_body1 | jq '.message')	 
	if [[ $status == '"SUCCESS"' ]]
	then		
		return $OK
	else		
		return $FAIL
	fi
}
function ask_token_and_login() {
	mo_email_address="$1"	
	mo_auth_type="$2"
	is_test_flow="$3"
	times=3
	mo_token=""
	mo_2fa_method=""
	case $mo_auth_type in
		("SMS" | "EMAIL" | "SMS AND EMAIL" | "OUT OF BAND SMS" | "OUT OF BAND EMAIL")
		request_sms "$mo_email_address" "$mo_auth_type"
			if [[ $? -eq 0 ]]
				then
				debug "${MO_RESPONSE_MESSAGE}"								
				else 
					debug "Error in sending token"
				exit $FAIL
				fi
		;;	
		("PUSH NOTIFICATIONS")
		request_push_notification "$mo_email_address" "$mo_auth_type"
			if [[ $? -eq 0 ]]
				then
				debug "{MO_RESPONSE_MESSAGE}"									
				else 
					debug "Error in sending push notification"
				exit $FAIL
				fi
		;;	
		*)			
		;;
	esac
		
		case $mo_auth_type in
		("SMS" | "EMAIL" | "SMS AND EMAIL")
			echo -n "Enter the OTP:"
			mo_token="$(read_input)"
			if [ $? -ne 0 ]
			then
            debug "Timeout on Token read."
            exit $?
			fi
			if [[ $mo_token == "" ]]
			then
				debug "Empty token"
				exit $?
			else	
			validate_token "$mo_token"			
				if [[ $? -eq 0 ]]
				then
				debug "OTP Validation successful"
				if [[ $is_test_flow != "true" ]]
				then
				run_shell				
				fi
				else 
					debug "OTP Validation failed"
				exit $FAIL
				fi
			fi	
		;;
		("SOFT TOKEN" | "GOOGLE AUTHENTICATOR")
			echo -n "Enter the soft/google token:"
			mo_soft_token="$(read_input)"
			
			if [ $? -ne 0 ]
			then
            debug "Timeout on Token read."
            exit $?
			fi
			if [[ $mo_soft_token == "" ]]
			 then
				 debug "Empty token"
				 exit $?
			else
			validate_soft_token "$mo_email_address" "$mo_soft_token" "$mo_auth_type"			
				if [[ $? -eq 0 ]]
				then
					debug "Validation successful"
					if [[ $is_test_flow != "true" ]]
					then
					run_shell
					fi	
				else 
					debug "Validation failed"
				exit $FAIL
				fi				
			fi	
		;;
		("OUT OF BAND SMS" | "OUT OF BAND EMAIL" | "PUSH NOTIFICATIONS")
				get_auth_status
				if [[ $? -eq 0 ]]
				then
				debug "Validation successful"
				if [[ $is_test_flow != "true" ]]
				then
				run_shell
				fi		
				else 
					debug "Validation failed"
				exit $FAIL
				fi
		;;
		("HARDWARE TOKEN")
		echo "1. Insert your miniOrange Authenticator into a USB port."
		echo "2. Touch the miniOrange Authenticator button."
		echo -n "Reading Hardware token:"
			mo_hardware_token="$(read_input)"
			if [ $? -ne 0 ]
			then
            debug "Timeout on Token read."
            exit $?
			fi
			if [[ $mo_hardware_token == "" ]]
			then
				debug "Empty Hardware token"
				exit $?
			else	
			validate_soft_token "$mo_email_address" "$mo_hardware_token" "$mo_auth_type"			
				if [[ $? -eq 0 ]]
				then
				debug "Validation successful"
				if [[ $is_test_flow != "true" ]]
				then
				run_shell
				fi	
				else 
					debug "Validation failed"
				exit $FAIL
				fi
			fi
		;;
		*)
		;;
		esac	
}

function check_user_exist() {
	email="$(escape_input "$1")"
	url="$MO_HOST/api/admin/users/search"
	customer_key="$(read_config customer_id)"	
	customer_api_key="$(read_config customer_api_key)"
	current_time_in_miliseconds="$(date +%s%N | cut -b1-13)"
	
	export STRING_TO_HASH="$customer_key$current_time_in_miliseconds$customer_api_key"	
	HV="$(hash_value_function)"	

	CURL_HEADERS=(
             '-H' "Authorization: ${HV}"
             '-H' "Customer-Key: ${customer_key}"
             '-H' "Timestamp: ${current_time_in_miliseconds}"
             '-H' 'Content-Type: application/json'
)

post_data='{"customerKey":'$customer_key',"username":"'$email'"}'
	mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`
			
	user_status=$(echo $mo_response | jq '.status')	
	if [[ $user_status == '"USER_FOUND"' ]]
	then		
		return $OK
	else		
		return $FAIL
	fi

}

function register_user() {
	local_user="$1"
	mo_user_email="$2"	
	check_user_exist "$2"		
	
	if [[ $? -eq 0 ]]
	then
	debug "User found in miniOrange. Registering the User."						
	else 
	debug "User not found in miniOrange."
	exit $FAIL
	fi
	
	check_mo_user_exist "$1"
	
	if [[ $? -eq 0 ]]
	then
		debug "User already registered"
	else 	
		create_user_if_not_exist "$local_user"
		echo "user=$local_user:$mo_user_email" >> $CONFIG_FILE
		debug "User was registered"
	fi
}

function create_user_if_not_exist() {
	local_user="$1"
	getent passwd $local_user > /dev/null 2&>1

	if [[ $? -eq 0 ]]
	then
		debug "User exists on local machine."
	else
		create_local_user $local_user
	fi
}

function create_local_user() {
	local_user="$1"
	useradd -c "Created by mo-ssh" -s "$(which bash)" $local_user
	debug "User '$local_user' created. Set a new local password:"
	passwd $local_user
	# todo add user to groups
	debug "You must add the user to relevant groups manually."
}

function check_mo_user_exist() {
username="$1"

for user in `read_config user`
    do
        IFS=":"; declare -a mo_user=($user)
        if [[ ${mo_user[0]} == $username ]]
        then            
            return $OK
        fi
    done

    return $FAIL
}
function find_mo_user() {
    for user in `read_config user`
    do
        IFS=":"; declare -a mo_user=($user)
        if [[ ${mo_user[0]} == $1 ]]
        then
            echo $(escape_input ${mo_user[1]})
            return $OK
        fi
    done

    return $FAIL
}

function login_miniorange() {	
	
	url="$MO_HOST/api/admin/users/get"
	current_username="$(find_mo_user $USER)"
	
	if [[ $? -ne 0 ]] 
	then
		debug "2FA is not enabled for the ${USER} user"
		run_shell
	fi	
	customer_key="$(read_config customer_id)"	
	customer_api_key="$(read_config customer_api_key)"
	current_time_in_miliseconds="$(date +%s%N | cut -b1-13)"
	
	export STRING_TO_HASH="$customer_key$current_time_in_miliseconds$customer_api_key"	
	HV="$(hash_value_function)"	

	CURL_HEADERS=(
             '-H' "Authorization: ${HV}"
             '-H' "Customer-Key: ${customer_key}"
             '-H' "Timestamp: ${current_time_in_miliseconds}"
             '-H' 'Content-Type: application/json'
)

post_data='{"customerKey":'$customer_key',"username":"'$current_username'"}'

	mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`
	IFS='|' mo_response_body1=($mo_response)
	status=$(echo $mo_response_body1 | jq '.status')
	if [[ $status == '"SUCCESS"' ]]
	then 
	auth_type=$(echo $mo_response_body1 | jq -r '.authType')	
	ask_token_and_login "$current_username" "$auth_type" "false"
	else 
	debug "Error in fetching user information"
	fi
}

function test2fa_miniorange() {	
	
	url="$MO_HOST/api/admin/users/get"
	current_username="$(find_mo_user $1)"
	
	check_mo_user_exist "$1"
		
	if [[ $? -ne 0 ]] 
	then
		debug "2FA is not enabled for the ${current_username} user"
		exit $FAIL
	fi	
	
	customer_key="$(read_config customer_id)"	
	customer_api_key="$(read_config customer_api_key)"
	current_time_in_miliseconds="$(date +%s%N | cut -b1-13)"
	
	export STRING_TO_HASH="$customer_key$current_time_in_miliseconds$customer_api_key"	
	HV="$(hash_value_function)"	

	CURL_HEADERS=(
             '-H' "Authorization: ${HV}"
             '-H' "Customer-Key: ${customer_key}"
             '-H' "Timestamp: ${current_time_in_miliseconds}"
             '-H' 'Content-Type: application/json'
)

post_data='{"customerKey":'$customer_key',"username":"'$current_username'"}'

	mo_response=`curl --silent --connect-timeout 20 "${CURL_HEADERS[@]}" -k -d "${post_data}" "${url}"`
	IFS='|' mo_response_body1=($mo_response)
	status=$(echo $mo_response_body1 | jq '.status')
	if [[ $status == '"SUCCESS"' ]]
	then 
	auth_type=$(echo $mo_response_body1 | jq -r '.authType')	
	ask_token_and_login "$current_username" "$auth_type" "true"
	else 
	debug "Error in fetching user information"
	fi
}

require_curl
require_jq

# get the absolute path to the command
cd `dirname $0`
COMMAND="$PWD/`basename $0`"
cd - >/dev/null

case $1 in
	install)        
        install_miniorange "$0" "$2"
        ;;
	uninstall)
		uninstall_miniorange
		;;
	test2fa)
		test2fa_miniorange "$2"
		;;
	login)		
		login_miniorange
		;;
	enable)
		register_user "$2" "$3"
		;;
    *)
        cat <<__EOF__
Usage: mo-ssh <command> <arguments>

Available commands:

    install
        installs miniOrange SSH in the given directory. This command needs sudo if the directory is not writable.

        sudo $0 install /usr/local/bin

    uninstall
        uninstalls miniOrange SSH from sshd_config

        sudo $0 uninstall    

    enable
        receives a list of arguments needed to register/enable 2FA for a user. usage:

        sudo $0 enable [local-user] [email]

        Example: sudo $0 enable myuser myuser@example.com

    test2fa
		receives a username as argument and provide test environment to test 2Fa for a user.
        
		sudo $0 test2fa [local-username]
		
		Example: sudo $0 test2fa myuser

__EOF__
        ;;
esac
