Diffstat (limited to 'filters/simple-authentication.lua')
| -rw-r--r-- | filters/simple-authentication.lua | 122 |
1 files changed, 40 insertions, 82 deletions
diff --git a/filters/simple-authentication.lua b/filters/simple-authentication.lua index 23d3457..cc86b7e 100644 --- a/filters/simple-authentication.lua +++ b/filters/simple-authentication.lua @@ -1,15 +1,10 @@ -- This script may be used with the auth-filter. Be sure to configure it as you wish. -- -- Requirements: --- luaossl --- <http://25thandclement.com/~william/projects/luaossl.html> --- luaposix --- <https://github.com/luaposix/luaposix> +-- luacrypto >= 0.3 +-- <http://mkottman.github.io/luacrypto/> -- -local sysstat = require("posix.sys.stat") -local unistd = require("posix.unistd") -local rand = require("openssl.rand") -local hmac = require("openssl.hmac") + -- -- @@ -23,16 +18,24 @@ local protected_repos = { qt = { jason = true, bob = true } } --- A list of users and hashes, generated with `mkpasswd -m sha-512 -R 300000`. +-- Please note that, in production, you'll want to replace this simple lookup +-- table with either a table of salted and hashed passwords (using something +-- smart like scrypt), or replace this table lookup with an external support, +-- such as consulting your system's pam / shadow system, or an external +-- database, or an external validating web service. For testing, or for +-- extremely low-security usage, you may be able, however, to get away with +-- compromising on hardcoding the passwords in cleartext, as we have done here. local users = { - jason = "$6$rounds=300000$YYJct3n/o.ruYK$HhpSeuCuW1fJkpvMZOZzVizeLsBKcGA/aF2UPuV5v60JyH2MVSG6P511UMTj2F3H75.IT2HIlnvXzNb60FcZH1", - laurent = "$6$rounds=300000$dP0KNHwYb3JKigT$pN/LG7rWxQ4HniFtx5wKyJXBJUKP7R01zTNZ0qSK/aivw8ywGAOdfYiIQFqFhZFtVGvr11/7an.nesvm8iJUi.", - bob = "$6$rounds=300000$jCLCCt6LUpTz$PI1vvd1yaVYcCzqH8QAJFcJ60b6W/6sjcOsU7mAkNo7IE8FRGW1vkjF8I/T5jt/auv5ODLb1L4S2s.CAyZyUC" + jason = "secretpassword", + laurent = "s3cr3t", + bob = "ilikelua" } --- Set this to a path this script can write to for storing a persistent --- cookie secret, which should be guarded. -local secret_filename = "/var/cache/cgit/auth-secret" +-- All cookies will be authenticated based on this secret. Make it something +-- totally random and impossible to guess. It should be large. +local secret = "BE SURE TO CUSTOMIZE THIS STRING TO SOMETHING BIG AND RANDOM" + + -- -- @@ -42,8 +45,8 @@ local secret_filename = "/var/cache/cgit/auth-secret" -- Sets HTTP cookie headers based on post and sets up redirection. function authenticate_post() - local hash = users[post["username"]] - local redirect = validate_value("redirect", post["redirect"]) + local password = users[post["username"]] + local redirect = validate_value(post["redirect"]) if redirect == nil then not_found() @@ -52,11 +55,12 @@ function authenticate_post() redirect_to(redirect) - if hash == nil or hash ~= unistd.crypt(post["password"], hash) then + -- Lua hashes strings, so these comparisons are time invariant. + if password == nil or password ~= post["password"] then set_cookie("cgitauth", "") else -- One week expiration time - local username = secure_value("username", post["username"], os.time() + 604800) + local username = secure_value(post["username"], os.time() + 604800) set_cookie("cgitauth", username) end @@ -73,7 +77,7 @@ function authenticate_cookie() return 1 end - local username = validate_value("username", get_cookie(http["cookie"], "cgitauth")) + local username = validate_value(get_cookie(http["cookie"], "cgitauth")) if username == nil or not accepted_users[username:lower()] then return 0 else @@ -88,7 +92,7 @@ function body() html_attr(cgit["login"]) html("'>") html("<input type='hidden' name='redirect' value='") - html_attr(secure_value("redirect", cgit["url"], 0)) + html_attr(secure_value(cgit["url"], 0)) html("' />") html("<table>") html("<tr><td><label for='username'>Username:</label></td><td><input id='username' name='username' autofocus /></td></tr>") @@ -180,13 +184,6 @@ function get_cookie(cookies, name) return url_decode(string.match(cookies, ";" .. name .. "=(.-);")) end -function tohex(b) - local x = "" - for i = 1, #b do - x = x .. string.format("%.2x", string.byte(b, i)) - end - return x -end -- -- @@ -194,47 +191,15 @@ end -- -- -local secret = nil - --- Loads a secret from a file, creates a secret, or returns one from memory. -function get_secret() - if secret ~= nil then - return secret - end - local secret_file = io.open(secret_filename, "r") - if secret_file == nil then - local old_umask = sysstat.umask(63) - local temporary_filename = secret_filename .. ".tmp." .. tohex(rand.bytes(16)) - local temporary_file = io.open(temporary_filename, "w") - if temporary_file == nil then - os.exit(177) - end - temporary_file:write(tohex(rand.bytes(32))) - temporary_file:close() - unistd.link(temporary_filename, secret_filename) -- Intentionally fails in the case that another process is doing the same. - unistd.unlink(temporary_filename) - sysstat.umask(old_umask) - secret_file = io.open(secret_filename, "r") - end - if secret_file == nil then - os.exit(177) - end - secret = secret_file:read() - secret_file:close() - if secret:len() ~= 64 then - os.exit(177) - end - return secret -end +local crypto = require("crypto") -- Returns value of cookie if cookie is valid. Otherwise returns nil. -function validate_value(expected_field, cookie) +function validate_value(cookie) local i = 0 local value = "" - local field = "" local expiration = 0 local salt = "" - local chmac = "" + local hmac = "" if cookie == nil or cookie:len() < 3 or cookie:sub(1, 1) == "|" then return nil @@ -242,55 +207,48 @@ function validate_value(expected_field, cookie) for component in string.gmatch(cookie, "[^|]+") do if i == 0 then - field = component - elseif i == 1 then value = component - elseif i == 2 then + elseif i == 1 then expiration = tonumber(component) if expiration == nil then - expiration = -1 + expiration = 0 end - elseif i == 3 then + elseif i == 2 then salt = component - elseif i == 4 then - chmac = component + elseif i == 3 then + hmac = component else break end i = i + 1 end - if chmac == nil or chmac:len() == 0 then + if hmac == nil or hmac:len() == 0 then return nil end -- Lua hashes strings, so these comparisons are time invariant. - if chmac ~= tohex(hmac.new(get_secret(), "sha256"):final(field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt)) then - return nil - end - - if expiration == -1 or (expiration ~= 0 and expiration <= os.time()) then + if hmac ~= crypto.hmac.digest("sha1", value .. "|" .. tostring(expiration) .. "|" .. salt, secret) then return nil end - if url_decode(field) ~= expected_field then + if expiration ~= 0 and expiration <= os.time() then return nil end return url_decode(value) end -function secure_value(field, value, expiration) +function secure_value(value, expiration) if value == nil or value:len() <= 0 then return "" end local authstr = "" - local salt = tohex(rand.bytes(16)) + local salt = crypto.hex(crypto.rand.bytes(16)) value = url_encode(value) - field = url_encode(field) - authstr = field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt - authstr = authstr .. "|" .. tohex(hmac.new(get_secret(), "sha256"):final(authstr)) + authstr = value .. "|" .. tostring(expiration) .. "|" .. salt + authstr = authstr .. "|" .. crypto.hmac.digest("sha1", authstr, secret) return authstr end |