Commit 5fc9ce547c4b06bf9f63e15b15a6522ff999abcf
1 parent
e7553ea2
added a first basic athentication system with ldap binding. Now login depends on…
… the existens of a valid ldap account
Showing
24 changed files
with
439 additions
and
32 deletions
@@ -21,7 +21,11 @@ | @@ -21,7 +21,11 @@ | ||
21 | </div> | 21 | </div> |
22 | <div id="login" class="hide"> | 22 | <div id="login" class="hide"> |
23 | <form> | 23 | <form> |
24 | - <input type="text" name="username" /> | 24 | + <label for="username">username</label> |
25 | + <input type="text" name="username" /><br /> | ||
26 | + <label for="password">password</label> | ||
27 | + <input type="password" name="password" /><br /> | ||
28 | + <input type="submit" /> | ||
25 | </form> | 29 | </form> |
26 | </div> | 30 | </div> |
27 | <div id="randval" class="hide"> | 31 | <div id="randval" class="hide"> |
include/auth.h
0 → 100644
1 | +/** | ||
2 | + * \file | ||
3 | + * Authenticatio module factory | ||
4 | + * | ||
5 | + * A factory to get a specific authentication module. | ||
6 | + * An authentication module is a class that implement the Auth interface. | ||
7 | + * | ||
8 | + * \author Georg Hopp | ||
9 | + * | ||
10 | + * \copyright | ||
11 | + * Copyright © 2012 Georg Hopp | ||
12 | + * | ||
13 | + * This program is free software: you can redistribute it and/or modify | ||
14 | + * it under the terms of the GNU General Public License as published by | ||
15 | + * the Free Software Foundation, either version 3 of the License, or | ||
16 | + * (at your option) any later version. | ||
17 | + * | ||
18 | + * This program is distributed in the hope that it will be useful, | ||
19 | + * but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
20 | + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
21 | + * GNU General Public License for more details. | ||
22 | + * | ||
23 | + * You should have received a copy of the GNU General Public License | ||
24 | + * along with this program. If not, see <http://www.gnu.org/licenses/>. | ||
25 | + */ | ||
26 | + | ||
27 | +#ifndef __AUTH_H__ | ||
28 | +#define __AUTH_H__ | ||
29 | + | ||
30 | +#include "class.h" | ||
31 | +#include "auth/ldap.h" | ||
32 | + | ||
33 | +typedef enum e_AuthModule { | ||
34 | + AUTH_LDAP = 0 | ||
35 | +} AuthModule; | ||
36 | + | ||
37 | +CLASS(Auth) { | ||
38 | +}; | ||
39 | + | ||
40 | +void * authCreateById(Auth, int); | ||
41 | +AuthLdap authCreateLdap(Auth); | ||
42 | + | ||
43 | +#endif // __AUTH_H__ | ||
44 | + | ||
45 | +// vim: set ts=4 sw=4: |
include/auth/ldap.h
0 → 100644
1 | +#ifndef __AUTH_LDAP_H__ | ||
2 | +#define __AUTH_LDAP_H__ | ||
3 | + | ||
4 | +#include <ldap.h> | ||
5 | +#include <sys/types.h> | ||
6 | + | ||
7 | +#include "class.h" | ||
8 | + | ||
9 | +CLASS(AuthLdap) { | ||
10 | + LDAP * ldap; | ||
11 | + char * url; | ||
12 | + char * base_dn; | ||
13 | + int version; | ||
14 | + size_t nbase_dn; | ||
15 | +}; | ||
16 | + | ||
17 | +#endif // __AUTH_LDAP_H__ | ||
18 | + | ||
19 | +// vim: set ts=4 sw=4: |
@@ -5,6 +5,14 @@ | @@ -5,6 +5,14 @@ | ||
5 | #define TRUE 1 | 5 | #define TRUE 1 |
6 | #define FALSE 0 | 6 | #define FALSE 0 |
7 | 7 | ||
8 | +#ifndef MAX | ||
9 | +# define MAX(a,b) ((a)>(b)? (a) : (b)) | ||
10 | +#endif | ||
11 | + | ||
12 | +#ifndef MIN | ||
13 | +# define MIN(a,b) ((a)<(b)? (a) : (b)) | ||
14 | +#endif | ||
15 | + | ||
8 | #define SWAP_FUN(a, b) ((a)^=(b),(b)^=(a),(a)^=(b)) | 16 | #define SWAP_FUN(a, b) ((a)^=(b),(b)^=(a),(a)^=(b)) |
9 | 17 | ||
10 | #define SWAP(type, a, b) do { \ | 18 | #define SWAP(type, a, b) do { \ |
include/credential.h
0 → 100644
1 | +#ifndef __CREDENTIAL_H__ | ||
2 | +#define __CREDENTIAL_H__ | ||
3 | + | ||
4 | +#include <sys/types.h> | ||
5 | + | ||
6 | +#include "class.h" | ||
7 | + | ||
8 | +#define CRED_PWD(c) (((c)->cred).pwd) | ||
9 | + | ||
10 | +typedef enum e_CredentialType { | ||
11 | + CRED_PASSWORD = 0 | ||
12 | +} CredentialType; | ||
13 | + | ||
14 | + | ||
15 | +CLASS(Credential) { | ||
16 | + CredentialType type; | ||
17 | + | ||
18 | + union { | ||
19 | + | ||
20 | + struct { | ||
21 | + char * user; | ||
22 | + size_t nuser; | ||
23 | + char * pass; | ||
24 | + size_t npass; | ||
25 | + } pwd; | ||
26 | + | ||
27 | + } cred; | ||
28 | +}; | ||
29 | + | ||
30 | +#endif // __CREDENTIAL_H__ | ||
31 | + | ||
32 | +// vim: set ts=4 sw=4: |
@@ -58,6 +58,7 @@ CLASS(HttpParser) { | @@ -58,6 +58,7 @@ CLASS(HttpParser) { | ||
58 | }; | 58 | }; |
59 | 59 | ||
60 | ssize_t httpParserParse(void *, Stream); | 60 | ssize_t httpParserParse(void *, Stream); |
61 | +void httpParserRequestVars(HttpParser); | ||
61 | void httpParserHeader(HttpParser, const char *, const char *); | 62 | void httpParserHeader(HttpParser, const char *, const char *); |
62 | void httpParserNewMessage(HttpParser, const char *, const char * lend); | 63 | void httpParserNewMessage(HttpParser, const char *, const char * lend); |
63 | size_t httpParserBody(HttpParser, const char *, size_t); | 64 | size_t httpParserBody(HttpParser, const char *, size_t); |
@@ -52,6 +52,8 @@ CLASS(HttpWorker) { | @@ -52,6 +52,8 @@ CLASS(HttpWorker) { | ||
52 | HttpWriter writer; | 52 | HttpWriter writer; |
53 | Session session; | 53 | Session session; |
54 | Session * sroot; | 54 | Session * sroot; |
55 | + | ||
56 | + void * auth; | ||
55 | }; | 57 | }; |
56 | 58 | ||
57 | #endif // __HTTP_WORKER_H__ | 59 | #endif // __HTTP_WORKER_H__ |
include/interface/auth.h
0 → 100644
1 | +/** | ||
2 | + * \file | ||
3 | + * The authentication interface. | ||
4 | + * | ||
5 | + * This is the authentication interface. It's only pupose is to | ||
6 | + * authenticate someone or somewhat. It is called AUTH. | ||
7 | + * The concrete access rights are managed within a class called ACL. | ||
8 | + * | ||
9 | + * \author Georg Hopp | ||
10 | + * | ||
11 | + * \copyright | ||
12 | + * Copyright © 2012 Georg Hopp | ||
13 | + * | ||
14 | + * This program is free software: you can redistribute it and/or modify | ||
15 | + * it under the terms of the GNU General Public License as published by | ||
16 | + * the Free Software Foundation, either version 3 of the License, or | ||
17 | + * (at your option) any later version. | ||
18 | + * | ||
19 | + * This program is distributed in the hope that it will be useful, | ||
20 | + * but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
21 | + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
22 | + * GNU General Public License for more details. | ||
23 | + * | ||
24 | + * You should have received a copy of the GNU General Public License | ||
25 | + * along with this program. If not, see <http://www.gnu.org/licenses/>. | ||
26 | + */ | ||
27 | + | ||
28 | +#ifndef __INTERFACE_AUTH_H__ | ||
29 | +#define __INTERFACE_AUTH_H__ | ||
30 | + | ||
31 | +#include <stdarg.h> | ||
32 | + | ||
33 | +#include "interface.h" | ||
34 | +#include "credential.h" | ||
35 | + | ||
36 | +typedef int (* fptr_authenticate)(void *, Credential); | ||
37 | + | ||
38 | +extern const struct interface i_Auth; | ||
39 | + | ||
40 | +struct i_Auth { | ||
41 | + const struct interface * const _; | ||
42 | + fptr_authenticate authenticate; | ||
43 | +}; | ||
44 | + | ||
45 | +extern int authenticate(void *, Credential); | ||
46 | + | ||
47 | +#endif // __INTERFACE_AUTH_H__ | ||
48 | + | ||
49 | +// vim: set ts=4 sw=4: |
@@ -6,13 +6,8 @@ IFACE = interface/class.c interface/stream_reader.c interface/logger.c \ | @@ -6,13 +6,8 @@ IFACE = interface/class.c interface/stream_reader.c interface/logger.c \ | ||
6 | interface/subject.c interface/observer.c interface.c | 6 | interface/subject.c interface/observer.c interface.c |
7 | SOCKET = socket.c socket/accept.c socket/connect.c socket/listen.c | 7 | SOCKET = socket.c socket/accept.c socket/connect.c socket/listen.c |
8 | STREAM = stream.c stream/read.c stream/write.c | 8 | STREAM = stream.c stream/read.c stream/write.c |
9 | -HASH = hash.c \ | ||
10 | - hash/add.c \ | ||
11 | - hash/get.c \ | ||
12 | - hash/delete.c \ | ||
13 | - hash/each.c \ | ||
14 | - interface/hashable.c \ | ||
15 | - hash_value.c | 9 | +HASH = hash.c hash/add.c hash/get.c hash/delete.c \ |
10 | + hash/each.c interface/hashable.c hash_value.c | ||
16 | SERVER = server.c server/run.c server/close_conn.c server/poll.c \ | 11 | SERVER = server.c server/run.c server/close_conn.c server/poll.c \ |
17 | server/handle_accept.c server/read.c server/write.c | 12 | server/handle_accept.c server/read.c server/write.c |
18 | LOGGER = logger.c logger/stderr.c logger/syslog.c | 13 | LOGGER = logger.c logger/stderr.c logger/syslog.c |
@@ -61,6 +56,7 @@ UTILS = utils/hash.c \ | @@ -61,6 +56,7 @@ UTILS = utils/hash.c \ | ||
61 | utils/http.c \ | 56 | utils/http.c \ |
62 | utils/daemonize.c \ | 57 | utils/daemonize.c \ |
63 | utils/signalHandling.c | 58 | utils/signalHandling.c |
59 | +AUTH = interface/auth.c auth/ldap.c credential.c | ||
64 | 60 | ||
65 | 61 | ||
66 | AM_CFLAGS = -Wall -I ../include/ | 62 | AM_CFLAGS = -Wall -I ../include/ |
@@ -70,6 +66,6 @@ bin_PROGRAMS = webgameserver | @@ -70,6 +66,6 @@ bin_PROGRAMS = webgameserver | ||
70 | webgameserver_SOURCES = webgameserver.c \ | 66 | webgameserver_SOURCES = webgameserver.c \ |
71 | $(IFACE) $(SOCKET) $(SERVER) $(LOGGER) $(MSG) $(REQ) \ | 67 | $(IFACE) $(SOCKET) $(SERVER) $(LOGGER) $(MSG) $(REQ) \ |
72 | $(WRITER) $(RESP) $(HEADER) $(PARSER) $(WORKER) $(CB) \ | 68 | $(WRITER) $(RESP) $(HEADER) $(PARSER) $(WORKER) $(CB) \ |
73 | - $(UTILS) $(MSGQ) $(SESSION) $(STREAM) $(HASH) | 69 | + $(UTILS) $(MSGQ) $(SESSION) $(STREAM) $(HASH) $(AUTH) |
74 | webgameserver_CFLAGS = -Wall -I ../include/ | 70 | webgameserver_CFLAGS = -Wall -I ../include/ |
75 | -webgameserver_LDFLAGS = -lrt -lssl | 71 | +webgameserver_LDFLAGS = -lrt -lssl -lldap |
src/auth/ldap.c
0 → 100644
1 | +#include <stdarg.h> | ||
2 | +#include <stdlib.h> | ||
3 | +#include <string.h> | ||
4 | +#include <stdio.h> | ||
5 | +#include <ldap.h> | ||
6 | + | ||
7 | +#include "auth/ldap.h" | ||
8 | +#include "class.h" | ||
9 | +#include "credential.h" | ||
10 | +#include "interface/class.h" | ||
11 | +#include "interface/auth.h" | ||
12 | + | ||
13 | +#include "utils/memory.h" | ||
14 | +#include "commons.h" | ||
15 | + | ||
16 | +static | ||
17 | +int | ||
18 | +authLdapCtor(void * _this, va_list * params) | ||
19 | +{ | ||
20 | + AuthLdap this = _this; | ||
21 | + char * url = va_arg(*params, char*); | ||
22 | + char * base_dn; | ||
23 | + | ||
24 | + this->url = malloc(strlen(url) + 1); | ||
25 | + strcpy(this->url, url); | ||
26 | + | ||
27 | + this->version = 3; | ||
28 | + | ||
29 | + base_dn = va_arg(* params, char *); | ||
30 | + this->nbase_dn = va_arg(* params, size_t); | ||
31 | + | ||
32 | + this->base_dn = malloc(this->nbase_dn + 1); | ||
33 | + this->base_dn[this->nbase_dn] = 0; | ||
34 | + memcpy(this->base_dn, base_dn, this->nbase_dn); | ||
35 | + | ||
36 | + return 0; | ||
37 | +} | ||
38 | + | ||
39 | +static | ||
40 | +void | ||
41 | +authLdapDtor(void * _this) | ||
42 | +{ | ||
43 | + AuthLdap this = _this; | ||
44 | + | ||
45 | + FREE(this->base_dn); | ||
46 | + FREE(this->url); | ||
47 | +} | ||
48 | + | ||
49 | +static | ||
50 | +int | ||
51 | +authLdapAuthenticate(void * _this, Credential cred) | ||
52 | +{ | ||
53 | + AuthLdap this = _this; | ||
54 | + char who[256]; | ||
55 | + char * who_ptr = who; | ||
56 | + int ldap_err; | ||
57 | + | ||
58 | + if (CRED_PASSWORD != cred->type) { | ||
59 | + return FALSE; | ||
60 | + } | ||
61 | + | ||
62 | + ldap_initialize(&(this->ldap), this->url); | ||
63 | + ldap_set_option(this->ldap, LDAP_OPT_PROTOCOL_VERSION, &(this->version)); | ||
64 | + | ||
65 | + memcpy(who_ptr, "cn=", sizeof("cn=") - 1); | ||
66 | + who_ptr += sizeof("cn=") - 1; | ||
67 | + memcpy(who_ptr, CRED_PWD(cred).user, CRED_PWD(cred).nuser); | ||
68 | + who_ptr += CRED_PWD(cred).nuser; | ||
69 | + *who_ptr++ = ','; | ||
70 | + memcpy(who_ptr, this->base_dn, this->nbase_dn); | ||
71 | + who_ptr[this->nbase_dn] = 0; | ||
72 | + | ||
73 | + ldap_err = ldap_simple_bind_s(this->ldap, who, CRED_PWD(cred).pass); | ||
74 | + if (0 == ldap_err) { | ||
75 | + ldap_unbind_s(this->ldap); | ||
76 | + //! \todo here we need to get and return the user id | ||
77 | + return TRUE; | ||
78 | + } | ||
79 | + | ||
80 | + fprintf(stderr, "%s\n", ldap_err2string(ldap_err)); | ||
81 | + return FALSE; | ||
82 | +} | ||
83 | + | ||
84 | +INIT_IFACE(Class, authLdapCtor, authLdapDtor, NULL); | ||
85 | +INIT_IFACE(Auth, authLdapAuthenticate); | ||
86 | +CREATE_CLASS(AuthLdap, NULL, IFACE(Class), IFACE(Auth)); | ||
87 | + | ||
88 | +// vim: set ts=4 sw=4: |
src/credential.c
0 → 100644
1 | +#include <stdarg.h> | ||
2 | +#include <sys/types.h> | ||
3 | +#include <stdlib.h> | ||
4 | +#include <string.h> | ||
5 | + | ||
6 | +#include "credential.h" | ||
7 | +#include "class.h" | ||
8 | +#include "interface/class.h" | ||
9 | + | ||
10 | +#include "utils/memory.h" | ||
11 | + | ||
12 | +static | ||
13 | +int | ||
14 | +credentialCtor(void * _this, va_list * params) | ||
15 | +{ | ||
16 | + Credential this = _this; | ||
17 | + | ||
18 | + this->type = va_arg(* params, CredentialType); | ||
19 | + | ||
20 | + switch(this->type) { | ||
21 | + case CRED_PASSWORD: | ||
22 | + { | ||
23 | + char * user, *pass; | ||
24 | + | ||
25 | + user = va_arg(* params, char*); | ||
26 | + CRED_PWD(this).nuser = va_arg(* params, size_t); | ||
27 | + pass = va_arg(* params, char*); | ||
28 | + CRED_PWD(this).npass = va_arg(* params, size_t); | ||
29 | + | ||
30 | + CRED_PWD(this).user = malloc(CRED_PWD(this).nuser + 1); | ||
31 | + CRED_PWD(this).user[CRED_PWD(this).nuser] = 0; | ||
32 | + memcpy(CRED_PWD(this).user, user, CRED_PWD(this).nuser); | ||
33 | + | ||
34 | + CRED_PWD(this).pass = malloc(CRED_PWD(this).npass + 1); | ||
35 | + CRED_PWD(this).pass[CRED_PWD(this).npass] = 0; | ||
36 | + memcpy(CRED_PWD(this).pass, pass, CRED_PWD(this).npass); | ||
37 | + } | ||
38 | + break; | ||
39 | + | ||
40 | + default: | ||
41 | + return -1; | ||
42 | + } | ||
43 | + | ||
44 | + return 0; | ||
45 | +} | ||
46 | + | ||
47 | +static | ||
48 | +void | ||
49 | +credentialDtor(void * _this) | ||
50 | +{ | ||
51 | + Credential this = _this; | ||
52 | + | ||
53 | + switch(this->type) { | ||
54 | + case CRED_PASSWORD: | ||
55 | + FREE(CRED_PWD(this).user); | ||
56 | + FREE(CRED_PWD(this).pass); | ||
57 | + break; | ||
58 | + } | ||
59 | +} | ||
60 | + | ||
61 | +INIT_IFACE(Class, credentialCtor, credentialDtor, NULL); | ||
62 | +CREATE_CLASS(Credential, NULL, IFACE(Class)); | ||
63 | + | ||
64 | +// vim: set ts=4 sw=4: |
@@ -47,7 +47,8 @@ httpMessageCtor(void * _this, va_list * params) | @@ -47,7 +47,8 @@ httpMessageCtor(void * _this, va_list * params) | ||
47 | this->version = calloc(1, strlen(version)+1); | 47 | this->version = calloc(1, strlen(version)+1); |
48 | strcpy(this->version, version); | 48 | strcpy(this->version, version); |
49 | 49 | ||
50 | - this->header = new(Hash); | 50 | + this->header = new(Hash); |
51 | + this->cookies = new(Hash); | ||
51 | 52 | ||
52 | return 0; | 53 | return 0; |
53 | } | 54 | } |
@@ -59,6 +60,8 @@ httpMessageDtor(void * _this) | @@ -59,6 +60,8 @@ httpMessageDtor(void * _this) | ||
59 | HttpMessage this = _this; | 60 | HttpMessage this = _this; |
60 | 61 | ||
61 | delete(this->header); | 62 | delete(this->header); |
63 | + delete(this->cookies); | ||
64 | + | ||
62 | FREE(this->version); | 65 | FREE(this->version); |
63 | 66 | ||
64 | switch (this->type) { | 67 | switch (this->type) { |
@@ -28,7 +28,7 @@ | @@ -28,7 +28,7 @@ | ||
28 | #include "http/parser.h" | 28 | #include "http/parser.h" |
29 | #include "cbuf.h" | 29 | #include "cbuf.h" |
30 | 30 | ||
31 | -#define MIN(a,b) (((a) < (b))? (a) : (b)) | 31 | +#include "commons.h" |
32 | 32 | ||
33 | size_t | 33 | size_t |
34 | httpParserBody(HttpParser this, const char * buf, size_t nbuf) | 34 | httpParserBody(HttpParser this, const char * buf, size_t nbuf) |
@@ -71,8 +71,8 @@ httpParserHeader( | @@ -71,8 +71,8 @@ httpParserHeader( | ||
71 | 71 | ||
72 | if (0 == strncasecmp("cookie", name, nname-1)) { | 72 | if (0 == strncasecmp("cookie", name, nname-1)) { |
73 | HttpRequest request = (HttpRequest)this->current; | 73 | HttpRequest request = (HttpRequest)this->current; |
74 | - char * pair = value; | ||
75 | - size_t togo = lend - value; | 74 | + char * pair = value; |
75 | + ssize_t togo = lend - value; | ||
76 | 76 | ||
77 | while(NULL != pair && 0 < togo) { | 77 | while(NULL != pair && 0 < togo) { |
78 | char * key = pair; | 78 | char * key = pair; |
@@ -100,8 +100,8 @@ httpParserHeader( | @@ -100,8 +100,8 @@ httpParserHeader( | ||
100 | hashAdd(request->cookies, | 100 | hashAdd(request->cookies, |
101 | new(HashValue, key, eqsign-key, val, nval)); | 101 | new(HashValue, key, eqsign-key, val, nval)); |
102 | 102 | ||
103 | - togo -= (pair - eqsign); | ||
104 | pair++; | 103 | pair++; |
104 | + togo -= (pair - eqsign); | ||
105 | } | 105 | } |
106 | } | 106 | } |
107 | 107 |
@@ -17,7 +17,7 @@ httpParserPostVars(HttpParser this) | @@ -17,7 +17,7 @@ httpParserPostVars(HttpParser this) | ||
17 | { | 17 | { |
18 | HttpRequest request = (HttpRequest)this->current; | 18 | HttpRequest request = (HttpRequest)this->current; |
19 | char * pair = this->current->body; | 19 | char * pair = this->current->body; |
20 | - size_t togo = this->current->nbody; | 20 | + ssize_t togo = this->current->nbody; |
21 | 21 | ||
22 | while(NULL != pair && 0 < togo) { | 22 | while(NULL != pair && 0 < togo) { |
23 | char * key = pair; | 23 | char * key = pair; |
@@ -42,8 +42,8 @@ httpParserPostVars(HttpParser this) | @@ -42,8 +42,8 @@ httpParserPostVars(HttpParser this) | ||
42 | hashAdd(request->post, | 42 | hashAdd(request->post, |
43 | new(HashValue, key, eqsign-key, value, nvalue)); | 43 | new(HashValue, key, eqsign-key, value, nvalue)); |
44 | 44 | ||
45 | - togo -= (pair - eqsign); | ||
46 | pair++; | 45 | pair++; |
46 | + togo -= (pair - eqsign); | ||
47 | } | 47 | } |
48 | } | 48 | } |
49 | 49 |
@@ -64,6 +64,8 @@ httpWorkerCtor(void * _this, va_list * params) | @@ -64,6 +64,8 @@ httpWorkerCtor(void * _this, va_list * params) | ||
64 | 64 | ||
65 | this->sroot = &(this->session); | 65 | this->sroot = &(this->session); |
66 | 66 | ||
67 | + this->auth = va_arg(* params, void *); | ||
68 | + | ||
67 | return 0; | 69 | return 0; |
68 | } | 70 | } |
69 | 71 | ||
@@ -106,6 +108,7 @@ httpWorkerClone(void * _this, void * _base) | @@ -106,6 +108,7 @@ httpWorkerClone(void * _this, void * _base) | ||
106 | this->writer = new(HttpWriter, base->wbuf); | 108 | this->writer = new(HttpWriter, base->wbuf); |
107 | 109 | ||
108 | this->sroot = &(base->session); | 110 | this->sroot = &(base->session); |
111 | + this->auth = base->auth; | ||
109 | } | 112 | } |
110 | 113 | ||
111 | ssize_t httpWorkerProcess(void *, Stream); | 114 | ssize_t httpWorkerProcess(void *, Stream); |
@@ -28,6 +28,7 @@ | @@ -28,6 +28,7 @@ | ||
28 | 28 | ||
29 | #include "class.h" | 29 | #include "class.h" |
30 | #include "interface/class.h" | 30 | #include "interface/class.h" |
31 | +#include "interface/auth.h" | ||
31 | 32 | ||
32 | #include "http/worker.h" | 33 | #include "http/worker.h" |
33 | #include "http/header.h" | 34 | #include "http/header.h" |
@@ -40,13 +41,17 @@ | @@ -40,13 +41,17 @@ | ||
40 | #include "stream.h" | 41 | #include "stream.h" |
41 | #include "hash_value.h" | 42 | #include "hash_value.h" |
42 | #include "hash.h" | 43 | #include "hash.h" |
44 | +#include "credential.h" | ||
43 | 45 | ||
44 | #include "utils/memory.h" | 46 | #include "utils/memory.h" |
45 | #include "hash.h" | 47 | #include "hash.h" |
48 | +#include "commons.h" | ||
49 | + | ||
46 | 50 | ||
47 | HttpMessage httpWorkerGetAsset(HttpRequest, const char *, const char *, size_t); | 51 | HttpMessage httpWorkerGetAsset(HttpRequest, const char *, const char *, size_t); |
48 | void httpWorkerAddCommonHeader(HttpMessage, HttpMessage); | 52 | void httpWorkerAddCommonHeader(HttpMessage, HttpMessage); |
49 | 53 | ||
54 | + | ||
50 | ssize_t | 55 | ssize_t |
51 | httpWorkerProcess(HttpWorker this, Stream st) | 56 | httpWorkerProcess(HttpWorker this, Stream st) |
52 | { | 57 | { |
@@ -96,16 +101,50 @@ httpWorkerProcess(HttpWorker this, Stream st) | @@ -96,16 +101,50 @@ httpWorkerProcess(HttpWorker this, Stream st) | ||
96 | size_t nbuf; | 101 | size_t nbuf; |
97 | 102 | ||
98 | HashValue username = hashGet(request->post, CSTRA("username")); | 103 | HashValue username = hashGet(request->post, CSTRA("username")); |
104 | + HashValue password = hashGet(request->post, CSTRA("password")); | ||
105 | + | ||
106 | + /** | ||
107 | + * \todo This is an application authorization not an HTTP | ||
108 | + * authorization...anyway think about sending HTTP 401 | ||
109 | + * messages if authorization is required and think about | ||
110 | + * sending the credentials via header as described in the | ||
111 | + * HTTP protocol. Most likely this will lead to hacky thing | ||
112 | + * with javascript as i am not sure how far this is implemented | ||
113 | + * within browsers. | ||
114 | + * Anyway, for now we simply ignore a failed login within the | ||
115 | + * response except that no session is initialized. We send | ||
116 | + * an empty 200 OK | ||
117 | + */ | ||
118 | + if (NULL == password || NULL == username) { | ||
119 | + response = new(HttpResponse, "HTTP/1.1", 200, "OK"); | ||
120 | + } | ||
99 | 121 | ||
100 | - this->session = sessionAdd( | ||
101 | - this->sroot, | ||
102 | - new(Session, username->value, username->nvalue)); | ||
103 | - nbuf = sprintf(buffer, "sid=%lu;Path=/", this->session->id); | ||
104 | - | ||
105 | - response = (HttpMessage)httpResponseSession(this->session); | ||
106 | - | ||
107 | - hashAdd(response->header, | ||
108 | - new(HttpHeader, CSTRA("Set-Cookie"), buffer, nbuf)); | 122 | + if (NULL == response) { |
123 | + Credential cred = new(Credential, | ||
124 | + CRED_PASSWORD, | ||
125 | + (char*)(username->value), username->nvalue, | ||
126 | + (char*)(password->value), password->nvalue); | ||
127 | + | ||
128 | + if (!authenticate(this->auth, cred)) { | ||
129 | + response = new(HttpResponse, "HTTP/1.1", 200, "OK"); | ||
130 | + } else { | ||
131 | + this->session = sessionAdd( | ||
132 | + this->sroot, | ||
133 | + new(Session, username->value, username->nvalue)); | ||
134 | + nbuf = sprintf(buffer, | ||
135 | + "sid=%lu;Path=/", | ||
136 | + this->session->id); | ||
137 | + | ||
138 | + response = (HttpMessage)httpResponseSession( | ||
139 | + this->session); | ||
140 | + | ||
141 | + hashAdd(response->header, | ||
142 | + new(HttpHeader, | ||
143 | + CSTRA("Set-Cookie"), | ||
144 | + buffer, nbuf)); | ||
145 | + } | ||
146 | + delete(cred); | ||
147 | + } | ||
109 | } | 148 | } |
110 | } | 149 | } |
111 | 150 |
@@ -30,8 +30,8 @@ | @@ -30,8 +30,8 @@ | ||
30 | #include "cbuf.h" | 30 | #include "cbuf.h" |
31 | #include "stream.h" | 31 | #include "stream.h" |
32 | 32 | ||
33 | -#define MIN(x,y) ((x) < (y) ? (x) : (y)) | ||
34 | -#define MAX(x,y) ((x) > (y) ? (x) : (y)) | 33 | +#include "commons.h" |
34 | + | ||
35 | 35 | ||
36 | ssize_t | 36 | ssize_t |
37 | httpWriterWrite(void * _this, Stream st) | 37 | httpWriterWrite(void * _this, Stream st) |
src/interface/auth.c
0 → 100644
1 | +/** | ||
2 | + * \file | ||
3 | + * | ||
4 | + * \author Georg Hopp | ||
5 | + * | ||
6 | + * \copyright | ||
7 | + * Copyright © 2012 Georg Hopp | ||
8 | + * | ||
9 | + * This program is free software: you can redistribute it and/or modify | ||
10 | + * it under the terms of the GNU General Public License as published by | ||
11 | + * the Free Software Foundation, either version 3 of the License, or | ||
12 | + * (at your option) any later version. | ||
13 | + * | ||
14 | + * This program is distributed in the hope that it will be useful, | ||
15 | + * but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
16 | + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
17 | + * GNU General Public License for more details. | ||
18 | + * | ||
19 | + * You should have received a copy of the GNU General Public License | ||
20 | + * along with this program. If not, see <http://www.gnu.org/licenses/>. | ||
21 | + */ | ||
22 | + | ||
23 | +#include "auth.h" | ||
24 | +#include "credential.h" | ||
25 | +#include "interface/auth.h" | ||
26 | + | ||
27 | +const struct interface i_Auth = { | ||
28 | + "auth", | ||
29 | + 1 | ||
30 | +}; | ||
31 | + | ||
32 | +int | ||
33 | +authenticate(void * auth, Credential cred) | ||
34 | +{ | ||
35 | + int ret; | ||
36 | + | ||
37 | + RETCALL(auth, Auth, authenticate, ret, cred); | ||
38 | + | ||
39 | + return ret; | ||
40 | +} | ||
41 | + | ||
42 | +// vim: set ts=4 sw=4: |
@@ -4,7 +4,7 @@ | @@ -4,7 +4,7 @@ | ||
4 | * \author Georg Hopp | 4 | * \author Georg Hopp |
5 | * | 5 | * |
6 | * \copyright | 6 | * \copyright |
7 | - * Copyright (C) 2012 Georg Hopp | 7 | + * Copyright © 2012 Georg Hopp |
8 | * | 8 | * |
9 | * This program is free software: you can redistribute it and/or modify | 9 | * This program is free software: you can redistribute it and/or modify |
10 | * it under the terms of the GNU General Public License as published by | 10 | * it under the terms of the GNU General Public License as published by |
@@ -4,7 +4,7 @@ | @@ -4,7 +4,7 @@ | ||
4 | * \author Georg Hopp | 4 | * \author Georg Hopp |
5 | * | 5 | * |
6 | * \copyright | 6 | * \copyright |
7 | - * Copyright (C) 2012 Georg Hopp | 7 | + * Copyright © 2012 Georg Hopp |
8 | * | 8 | * |
9 | * This program is free software: you can redistribute it and/or modify | 9 | * This program is free software: you can redistribute it and/or modify |
10 | * it under the terms of the GNU General Public License as published by | 10 | * it under the terms of the GNU General Public License as published by |
@@ -38,11 +38,13 @@ | @@ -38,11 +38,13 @@ | ||
38 | #include "server.h" | 38 | #include "server.h" |
39 | #include "logger.h" | 39 | #include "logger.h" |
40 | #include "http/worker.h" | 40 | #include "http/worker.h" |
41 | +#include "auth/ldap.h" | ||
41 | 42 | ||
42 | #include "interface/class.h" | 43 | #include "interface/class.h" |
43 | #include "interface/logger.h" | 44 | #include "interface/logger.h" |
44 | 45 | ||
45 | #include "utils/signalHandling.h" | 46 | #include "utils/signalHandling.h" |
47 | +#include "utils/memory.h" | ||
46 | 48 | ||
47 | #define DEFAULT_SECS 10 | 49 | #define DEFAULT_SECS 10 |
48 | //#define DEFAULT_USECS (1000000 / HZ * 2) | 50 | //#define DEFAULT_USECS (1000000 / HZ * 2) |
@@ -126,6 +128,7 @@ main() | @@ -126,6 +128,7 @@ main() | ||
126 | default: | 128 | default: |
127 | { | 129 | { |
128 | Logger logger; | 130 | Logger logger; |
131 | + AuthLdap auth; | ||
129 | HttpWorker worker; | 132 | HttpWorker worker; |
130 | Server server; | 133 | Server server; |
131 | 134 | ||
@@ -136,7 +139,10 @@ main() | @@ -136,7 +139,10 @@ main() | ||
136 | close(shm); | 139 | close(shm); |
137 | 140 | ||
138 | logger = new(LoggerSyslog, LOGGER_ERR); | 141 | logger = new(LoggerSyslog, LOGGER_ERR); |
139 | - worker = new(HttpWorker, "testserver", value); | 142 | + auth = new(AuthLdap, |
143 | + "ldap://localhost/", | ||
144 | + CSTRA("ou=user,dc=yabrog,dc=weird-web-workers,dc=org")); | ||
145 | + worker = new(HttpWorker, "testserver", value, auth); | ||
140 | server = new(Server, logger, worker, 11212, SOMAXCONN); | 146 | server = new(Server, logger, worker, 11212, SOMAXCONN); |
141 | 147 | ||
142 | //daemonize(); | 148 | //daemonize(); |
@@ -184,6 +190,7 @@ main() | @@ -184,6 +190,7 @@ main() | ||
184 | 190 | ||
185 | if (NULL != server) delete(server); | 191 | if (NULL != server) delete(server); |
186 | if (NULL != worker) delete(worker); | 192 | if (NULL != worker) delete(worker); |
193 | + if (NULL != auth) delete(auth); | ||
187 | if (NULL != logger) delete(logger); | 194 | if (NULL != logger) delete(logger); |
188 | } | 195 | } |
189 | 196 |
Please
register
or
login
to post a comment