Refactor ExAuth for DICE

This commit is contained in:
Philipp Holzer 2019-07-28 00:14:39 +02:00 committed by Hypolite Petovan
parent ee02be3d48
commit 8565617ea1
3 changed files with 75 additions and 41 deletions

View file

@ -80,6 +80,7 @@ $dice = $dice->addRule(LoggerInterface::class,['constructParams' => ['auth_ejabb
$appMode = $dice->create(Mode::class); $appMode = $dice->create(Mode::class);
if ($appMode->isNormal()) { if ($appMode->isNormal()) {
$oAuth = new ExAuth(); /** @var ExAuth $oAuth */
$oAuth = $dice->create(ExAuth::class);
$oAuth->readStdin(); $oAuth->readStdin();
} }

View file

@ -321,7 +321,8 @@ class User
* @param string $password * @param string $password
* @param bool $third_party * @param bool $third_party
* @return int User Id if authentication is successful * @return int User Id if authentication is successful
* @throws Exception * @throws HTTPException\ForbiddenException
* @throws HTTPException\NotFoundException
*/ */
public static function getIdFromPasswordAuthentication($user_info, $password, $third_party = false) public static function getIdFromPasswordAuthentication($user_info, $password, $third_party = false)
{ {
@ -356,7 +357,7 @@ class User
return $user['uid']; return $user['uid'];
} }
throw new Exception(DI::l10n()->t('Login failed')); throw new HTTPException\ForbiddenException(DI::l10n()->t('Login failed'));
} }
/** /**
@ -370,7 +371,7 @@ class User
* *
* @param mixed $user_info * @param mixed $user_info
* @return array * @return array
* @throws Exception * @throws HTTPException\NotFoundException
*/ */
private static function getAuthenticationInfo($user_info) private static function getAuthenticationInfo($user_info)
{ {
@ -414,7 +415,7 @@ class User
} }
if (!DBA::isResult($user)) { if (!DBA::isResult($user)) {
throw new Exception(DI::l10n()->t('User not found')); throw new HTTPException\NotFoundException(DI::l10n()->t('User not found'));
} }
} }

View file

@ -34,9 +34,13 @@
namespace Friendica\Util; namespace Friendica\Util;
use Friendica\Database\DBA; use Exception;
use Friendica\DI; use Friendica\App;
use Friendica\Core\Config\IConfig;
use Friendica\Core\PConfig\IPConfig;
use Friendica\Database\Database;
use Friendica\Model\User; use Friendica\Model\User;
use Friendica\Network\HTTPException;
class ExAuth class ExAuth
{ {
@ -44,12 +48,43 @@ class ExAuth
private $host; private $host;
/** /**
* Create the class * @var App\Mode
*
*/ */
public function __construct() private $appMode;
/**
* @var IConfig
*/
private $config;
/**
* @var IPConfig
*/
private $pConfig;
/**
* @var Database
*/
private $dba;
/**
* @var App\BaseURL
*/
private $baseURL;
/**
* @param App\Mode $appMode
* @param IConfig $config
* @param IPConfig $pConfig
* @param Database $dba
* @param App\BaseURL $baseURL
* @throws Exception
*/
public function __construct(App\Mode $appMode, IConfig $config, IPConfig $pConfig, Database $dba, App\BaseURL $baseURL)
{ {
$this->bDebug = (int) DI::config()->get('jabber', 'debug'); $this->appMode = $appMode;
$this->config = $config;
$this->pConfig = $pConfig;
$this->dba = $dba;
$this->baseURL = $baseURL;
$this->bDebug = (int)$config->get('jabber', 'debug');
openlog('auth_ejabberd', LOG_PID, LOG_USER); openlog('auth_ejabberd', LOG_PID, LOG_USER);
@ -60,14 +95,18 @@ class ExAuth
* Standard input reading function, executes the auth with the provided * Standard input reading function, executes the auth with the provided
* parameters * parameters
* *
* @return null * @throws HTTPException\InternalServerErrorException
* @throws \Friendica\Network\HTTPException\InternalServerErrorException
*/ */
public function readStdin() public function readStdin()
{ {
if (!$this->appMode->isNormal()) {
$this->writeLog(LOG_ERR, 'The node isn\'t ready.');
return;
}
while (!feof(STDIN)) { while (!feof(STDIN)) {
// Quit if the database connection went down // Quit if the database connection went down
if (!DBA::connected()) { if (!$this->dba->isConnected()) {
$this->writeLog(LOG_ERR, 'the database connection went down'); $this->writeLog(LOG_ERR, 'the database connection went down');
return; return;
} }
@ -123,7 +162,7 @@ class ExAuth
* Check if the given username exists * Check if the given username exists
* *
* @param array $aCommand The command array * @param array $aCommand The command array
* @throws \Friendica\Network\HTTPException\InternalServerErrorException * @throws HTTPException\InternalServerErrorException
*/ */
private function isUser(array $aCommand) private function isUser(array $aCommand)
{ {
@ -142,9 +181,9 @@ class ExAuth
$sUser = str_replace(['%20', '(a)'], [' ', '@'], $aCommand[1]); $sUser = str_replace(['%20', '(a)'], [' ', '@'], $aCommand[1]);
// Does the hostname match? So we try directly // Does the hostname match? So we try directly
if (DI::baseUrl()->getHostname() == $aCommand[2]) { if ($this->baseURL->getHostname() == $aCommand[2]) {
$this->writeLog(LOG_INFO, 'internal user check for ' . $sUser . '@' . $aCommand[2]); $this->writeLog(LOG_INFO, 'internal user check for ' . $sUser . '@' . $aCommand[2]);
$found = DBA::exists('user', ['nickname' => $sUser]); $found = $this->dba->exists('user', ['nickname' => $sUser]);
} else { } else {
$found = false; $found = false;
} }
@ -173,7 +212,7 @@ class ExAuth
* @param boolean $ssl Should the check be done via SSL? * @param boolean $ssl Should the check be done via SSL?
* *
* @return boolean Was the user found? * @return boolean Was the user found?
* @throws \Friendica\Network\HTTPException\InternalServerErrorException * @throws HTTPException\InternalServerErrorException
*/ */
private function checkUser($host, $user, $ssl) private function checkUser($host, $user, $ssl)
{ {
@ -203,7 +242,7 @@ class ExAuth
* Authenticate the given user and password * Authenticate the given user and password
* *
* @param array $aCommand The command array * @param array $aCommand The command array
* @throws \Friendica\Network\HTTPException\InternalServerErrorException * @throws Exception
*/ */
private function auth(array $aCommand) private function auth(array $aCommand)
{ {
@ -221,35 +260,29 @@ class ExAuth
// We now check if the password match // We now check if the password match
$sUser = str_replace(['%20', '(a)'], [' ', '@'], $aCommand[1]); $sUser = str_replace(['%20', '(a)'], [' ', '@'], $aCommand[1]);
$Error = false;
// Does the hostname match? So we try directly // Does the hostname match? So we try directly
if (DI::baseUrl()->getHostname() == $aCommand[2]) { if ($this->baseURL->getHostname() == $aCommand[2]) {
$this->writeLog(LOG_INFO, 'internal auth for ' . $sUser . '@' . $aCommand[2]); try {
$this->writeLog(LOG_INFO, 'internal auth for ' . $sUser . '@' . $aCommand[2]);
$aUser = DBA::selectFirst('user', ['uid', 'password', 'legacy_password'], ['nickname' => $sUser]); User::getIdFromPasswordAuthentication($sUser, $aCommand[3], true);
if (DBA::isResult($aUser)) { } catch (HTTPException\ForbiddenException $ex) {
$uid = $aUser['uid']; // User exists, authentication failed
$success = User::authenticate($aUser, $aCommand[3], true);
$Error = $success === false;
} else {
$this->writeLog(LOG_WARNING, 'user not found: ' . $sUser);
$Error = true;
$uid = -1;
}
if ($Error) {
$this->writeLog(LOG_INFO, 'check against alternate password for ' . $sUser . '@' . $aCommand[2]); $this->writeLog(LOG_INFO, 'check against alternate password for ' . $sUser . '@' . $aCommand[2]);
$sPassword = DI::pConfig()->get($uid, 'xmpp', 'password', null, true); $aUser = User::getByNickname($sUser, ['uid']);
$sPassword = $this->pConfig->get($aUser['uid'], 'xmpp', 'password', null, true);
$Error = ($aCommand[3] != $sPassword); $Error = ($aCommand[3] != $sPassword);
} catch (\Throwable $ex) {
// User doesn't exist and any other failure case
$this->writeLog(LOG_WARNING, $ex->getMessage() . ': ' . $sUser);
$Error = true;
} }
} else { } else {
$Error = true; $Error = true;
} }
// If the hostnames doesn't match or there is some failure, we try to check remotely // If the hostnames doesn't match or there is some failure, we try to check remotely
if ($Error) { if ($Error && !$this->checkCredentials($aCommand[2], $aCommand[1], $aCommand[3], true)) {
$Error = !$this->checkCredentials($aCommand[2], $aCommand[1], $aCommand[3], true);
}
if ($Error) {
$this->writeLog(LOG_WARNING, 'authentification failed for user ' . $sUser . '@' . $aCommand[2]); $this->writeLog(LOG_WARNING, 'authentification failed for user ' . $sUser . '@' . $aCommand[2]);
fwrite(STDOUT, pack('nn', 2, 0)); fwrite(STDOUT, pack('nn', 2, 0));
} else { } else {
@ -297,7 +330,6 @@ class ExAuth
* Set the hostname for this process * Set the hostname for this process
* *
* @param string $host The hostname * @param string $host The hostname
* @throws \Friendica\Network\HTTPException\InternalServerErrorException
*/ */
private function setHost($host) private function setHost($host)
{ {
@ -309,7 +341,7 @@ class ExAuth
$this->host = $host; $this->host = $host;
$lockpath = DI::config()->get('jabber', 'lockpath'); $lockpath = $this->config->get('jabber', 'lockpath');
if (is_null($lockpath)) { if (is_null($lockpath)) {
$this->writeLog(LOG_INFO, 'No lockpath defined.'); $this->writeLog(LOG_INFO, 'No lockpath defined.');
return; return;