Then you must feed it newline-separated records in following format:
@example
-username:hashed-password
+username:hashed-password[:ro]
@end example
Where @code{hashed-password} is in one of following algorithms:
@end table
+Optional @code{:ro} flag forbids user to upload packages, but allows
+read-only access if @option{-auth-required} is enabled.
+
To add or update password entry:
@example
)
const (
- Version = "4.1.0"
+ Version = "4.2.0"
UserAgent = "GoCheese/" + Version
)
PasswdPath = flag.String("passwd", "", "")
PasswdListPath = flag.String("passwd-list", "", "")
PasswdCheck = flag.Bool("passwd-check", false, "")
+ AuthRequired = flag.Bool("auth-required", false, "")
LogTimestamped = flag.Bool("log-timestamped", false, "")
FSCK = flag.Bool("fsck", false, "")
ReadTimeout: time.Minute,
WriteTimeout: time.Minute,
}
- http.HandleFunc("/", serveHRRoot)
- http.HandleFunc("/hr/", serveHRPkg)
- http.HandleFunc(*JSONURLPath, serveJSON)
- http.HandleFunc(*NoRefreshURLPath, handler)
- http.HandleFunc(*RefreshURLPath, handler)
+ http.HandleFunc("/", checkAuth(serveHRRoot))
+ http.HandleFunc("/hr/", checkAuth(serveHRPkg))
+ http.HandleFunc(*JSONURLPath, checkAuth(serveJSON))
+ http.HandleFunc(*NoRefreshURLPath, checkAuth(handler))
+ http.HandleFunc(*RefreshURLPath, checkAuth(handler))
if *DoUCSPI {
server.SetKeepAlivesEnabled(false)
import (
"bufio"
+ "context"
"errors"
"log"
+ "net/http"
"os"
"strings"
"sync"
)
var (
- Passwords map[string]Auther = make(map[string]Auther)
+ Passwords map[string]*User = make(map[string]*User)
PasswordsM sync.RWMutex
)
+type CtxUserKeyType struct{}
+
+var CtxUserKey CtxUserKeyType
+
type Auther interface {
Auth(password string) bool
}
+type User struct {
+ name string
+ ro bool
+ auther Auther
+}
+
func strToAuther(verifier string) (string, Auther, error) {
st := strings.SplitN(verifier, "$", 3)
if len(st) != 3 || st[0] != "" {
continue
}
splitted := strings.Split(t, ":")
- if len(splitted) != 2 {
- log.Println("wrong login:password format:", t)
+ if len(splitted) < 2 {
+ log.Println("wrong login:password[:ro] format:", t)
isGood = false
continue
}
isGood = false
continue
}
+ var ro bool
+ if len(splitted) > 2 {
+ switch splitted[2] {
+ case "ro":
+ ro = true
+ default:
+ log.Println("wrong format of optional field:", t)
+ isGood = false
+ continue
+ }
+ }
log.Println("adding password for:", login)
PasswordsM.Lock()
- Passwords[login] = auther
+ Passwords[login] = &User{name: login, ro: ro, auther: auther}
PasswordsM.Unlock()
}
return isGood
fd.WriteString(login + "\n")
}
}
+
+func checkAuth(handler http.HandlerFunc) http.HandlerFunc {
+ return func(w http.ResponseWriter, r *http.Request) {
+ username, password, gotAuth := r.BasicAuth()
+ var user *User
+ if gotAuth {
+ PasswordsM.RLock()
+ user = Passwords[username]
+ PasswordsM.RUnlock()
+ }
+ var passwordValid bool
+ if gotAuth && user != nil {
+ passwordValid = user.auther.Auth(password)
+ }
+ if (gotAuth && user == nil) ||
+ (user != nil && !passwordValid) ||
+ (*AuthRequired && !gotAuth) {
+ log.Println(r.RemoteAddr, "unauthenticated", username)
+ http.Error(w, "unauthenticated", http.StatusUnauthorized)
+ return
+ }
+ handler(w, r.WithContext(context.WithValue(r.Context(), CtxUserKey, user)))
+ }
+}
var NormalizationRe = regexp.MustCompilePOSIX("[-_.]+")
func serveUpload(w http.ResponseWriter, r *http.Request) {
- // Authentication
- username, password, ok := r.BasicAuth()
- if !ok {
- log.Println(r.RemoteAddr, "unauthenticated", username)
- http.Error(w, "unauthenticated", http.StatusUnauthorized)
+ user := r.Context().Value(CtxUserKey).(*User)
+ if user == nil {
+ log.Println(r.RemoteAddr, "unauthorised")
+ http.Error(w, "unauthorised", http.StatusUnauthorized)
return
}
- PasswordsM.RLock()
- auther, ok := Passwords[username]
- PasswordsM.RUnlock()
- if !ok || !auther.Auth(password) {
- log.Println(r.RemoteAddr, "unauthenticated", username)
- http.Error(w, "unauthenticated", http.StatusUnauthorized)
+ if user.ro {
+ log.Println(r.RemoteAddr, "ro user", user.name)
+ http.Error(w, "unauthorised", http.StatusUnauthorized)
return
}
for _, file := range r.MultipartForm.File["content"] {
filename := file.Filename
- log.Println(r.RemoteAddr, "put", filename, "by", username)
+ log.Println(r.RemoteAddr, "put", filename, "by", user.name)
path := filepath.Join(dirPath, filename)
if _, err = os.Stat(path); err == nil {
log.Println(r.RemoteAddr, filename, "already exists")
-passwd PATH -- Path to readable FIFO for loading passwords
-passwd-list PATH -- Path to writeable FIFO for listing logins
-passwd-check -- Verify passwords format from stdin, then exit
+ -auth-required -- Require authorisation even for read-only endpoints
Other options:
-log-timestamped -- Prepend timestamp to log messages