clean pam auth version
This commit is contained in:
+19
-91
@@ -194,86 +194,6 @@ static int absec_handler_first(request_rec *r)
|
||||
//ap_rprintf(r, "User/Pass: %s/%s \n<br/>", user, pass);
|
||||
|
||||
////////
|
||||
// Validate user/pass against unix cred
|
||||
|
||||
////////
|
||||
// Get UID, GIDs for the user
|
||||
/* Working example, but just UID not PW */
|
||||
/*
|
||||
apr_status_t ret;
|
||||
apr_uid_t i;
|
||||
apr_gid_t g;
|
||||
ret = apr_uid_get ( &i, &g, user, r->pool );
|
||||
ap_rprintf(r, "Result2: G:%d, I:%d \n<br/>", g,i);
|
||||
*/
|
||||
|
||||
////////
|
||||
/* Retrieve PW (user details) from /etc/passwd */
|
||||
/* Should include <pwd.h> */
|
||||
struct passwd *pw;
|
||||
if((pw = getpwnam(user)) == NULL)
|
||||
{
|
||||
ap_rprintf(r, "NULL \n<br/>");
|
||||
apr_table_setn(r->err_headers_out,
|
||||
(PROXYREQ_PROXY == r->proxyreq) ? "Proxy-Authenticate"
|
||||
: "WWW-Authenticate",
|
||||
apr_pstrcat(r->pool, "Basic realm=\"USER INCONNU ", ap_auth_name(r),
|
||||
"\"", NULL));
|
||||
// User cannot be found, unauthorized
|
||||
return HTTP_UNAUTHORIZED;
|
||||
}
|
||||
|
||||
////////
|
||||
/* Retrieve PW from /etc/shadow */
|
||||
/* Should include <shadow.h> */
|
||||
/* struct spwd *spw;
|
||||
errno = 0;
|
||||
if((spw = getspnam(user)) == NULL)
|
||||
{
|
||||
ap_rprintf(r, "NULL %d\n<br/>", errno);
|
||||
apr_table_setn(r->err_headers_out,
|
||||
(PROXYREQ_PROXY == r->proxyreq) ? "Proxy-Authenticate"
|
||||
: "WWW-Authenticate",
|
||||
apr_pstrcat(r->pool, "Basic realm=\"", ap_auth_name(r),
|
||||
"\"", NULL));
|
||||
return HTTP_UNAUTHORIZED;
|
||||
}
|
||||
else
|
||||
{
|
||||
ap_rprintf(r, "Shadow PW : %s \n<br/>", spw->sp_pwdp);
|
||||
}
|
||||
|
||||
if (spw->sp_pwdp[0] == 'x' || spw->sp_pwdp[0] == '*' || spw->sp_pwdp[0] == '!') {
|
||||
apr_table_setn(r->err_headers_out,
|
||||
(PROXYREQ_PROXY == r->proxyreq) ? "Proxy-Authenticate"
|
||||
: "WWW-Authenticate",
|
||||
apr_pstrcat(r->pool, "Basic realm=\"", ap_auth_name(r),
|
||||
"\"", NULL));
|
||||
return HTTP_UNAUTHORIZED;
|
||||
}*/
|
||||
|
||||
////////
|
||||
/* Encrypt and compare shadow password */
|
||||
// TODO : Valider qu'on a un user
|
||||
// TODO : Valider qu'il y a un password (pas * ! rien)
|
||||
/* char *encrypted;
|
||||
const char *correct;
|
||||
int rrr;
|
||||
encrypted = crypt(pass, spw->sp_pwdp);
|
||||
rrr = strcmp(encrypted, spw->sp_pwdp);
|
||||
ap_rprintf(r, "compare pw : %s \n<br/>", encrypted);;
|
||||
ap_rprintf(r, "compare : %d \n<br/>", rrr);
|
||||
if (rrr!=0) {
|
||||
apr_table_setn(r->err_headers_out,
|
||||
(PROXYREQ_PROXY == r->proxyreq) ? "Proxy-Authenticate"
|
||||
: "WWW-Authenticate",
|
||||
apr_pstrcat(r->pool, "Basic realm=\"", ap_auth_name(r),
|
||||
"\"", NULL));
|
||||
return HTTP_UNAUTHORIZED;
|
||||
}
|
||||
*/
|
||||
|
||||
////////
|
||||
// Connect to PAM to auth user
|
||||
pam_handle_t * pamh = NULL;
|
||||
int rret;
|
||||
@@ -294,7 +214,7 @@ static int absec_handler_first(request_rec *r)
|
||||
apr_table_setn(r->err_headers_out,
|
||||
(PROXYREQ_PROXY == r->proxyreq) ? "Proxy-Authenticate"
|
||||
: "WWW-Authenticate",
|
||||
apr_pstrcat(r->pool, "Basic realm=\"PASSWORD INVALIDE ", ap_auth_name(r),
|
||||
apr_pstrcat(r->pool, "Basic realm=\"USER/PASS INVALIDE ", ap_auth_name(r),
|
||||
"\"", NULL));
|
||||
return HTTP_UNAUTHORIZED;
|
||||
printf("User auth failed\n");
|
||||
@@ -311,6 +231,23 @@ static int absec_handler_first(request_rec *r)
|
||||
////////
|
||||
// Continue checking permission
|
||||
|
||||
////////
|
||||
/* Retrieve user details from /etc/passwd to get uid and primary group */
|
||||
/* Should include <pwd.h> */
|
||||
struct passwd *pw;
|
||||
if((pw = getpwnam(user)) == NULL)
|
||||
{
|
||||
// Should never happend as already verified with PAM
|
||||
ap_rprintf(r, "NULL \n<br/>");
|
||||
apr_table_setn(r->err_headers_out,
|
||||
(PROXYREQ_PROXY == r->proxyreq) ? "Proxy-Authenticate"
|
||||
: "WWW-Authenticate",
|
||||
apr_pstrcat(r->pool, "Basic realm=\"USER INCONNU ", ap_auth_name(r),
|
||||
"\"", NULL));
|
||||
// User cannot be found, unauthorized
|
||||
return HTTP_UNAUTHORIZED;
|
||||
}
|
||||
|
||||
// If file is user readable and user match return content
|
||||
if ((fperm.st_uid==pw->pw_uid) && (fperm.st_mode & 0700 & permmask)) {
|
||||
ap_rprintf(r, "Fichier propriétaire<br/>\r\n");
|
||||
@@ -341,16 +278,7 @@ static int absec_handler_first(request_rec *r)
|
||||
return (DECLINED);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
/* ap_rprintf(r, "Erreur pas de groupe supplementaires? (code %d)<br/>\r\n", groupreturn);
|
||||
r->content_type = "text/html";
|
||||
apr_table_setn(r->err_headers_out,
|
||||
(PROXYREQ_PROXY == r->proxyreq) ? "Proxy-Authenticate"
|
||||
: "WWW-Authenticate",
|
||||
apr_pstrcat(r->pool, "Basic realm=\"", ap_auth_name(r),
|
||||
"\"", NULL));
|
||||
return HTTP_UNAUTHORIZED;
|
||||
*/ }
|
||||
}
|
||||
|
||||
// else decline request
|
||||
ap_rprintf(r, "Aucuns droits de voir le fichier<br/>\r\n");
|
||||
|
||||
Reference in New Issue
Block a user