mirror of
https://codeberg.org/forgejo/forgejo.git
synced 2025-10-24 11:02:42 +00:00
user, topic, project, label, milestone, repository, pull_request, release, asset, comment, reaction, review providers Signed-off-by: Earl Warren <contact@earl-warren.org> Preserve file size when creating attachments Introduced inc6f5029708repoList.LoadAttributes has a ctx argument now Rename `repo.GetOwner` to `repo.LoadOwner`bd66fa586aupgrade to the latest gof3 (cherry picked from commitc770713656) [F3] ID remapping logic is in place, remove workaround (cherry picked from commitd0fee30167) [F3] it is experimental, do not enable by default (cherry picked from commitde325b21d0) (cherry picked from commit547e7b3c40) (cherry picked from commit820df3a56b) (cherry picked from commiteaba87689b) (cherry picked from commit1b86896b3b) (cherry picked from commit0046aac1c6) (cherry picked from commitf14220df8f) (cherry picked from commit559b731001) (cherry picked from commit801f7d600d) (cherry picked from commit6aa76e9bcf) (cherry picked from commita8757dcb07) [F3] promote F3 users to matching OAuth2 users on first sign-in (cherry picked from commitbd7fef7496) (cherry picked from commit07412698e8) (cherry picked from commitd143e5b2a3) [F3] upgrade to gof3 50a6e740ac04 Add new methods GetIDString() & SetIDString() & ToFormatInterface() Change the prototype of the fixture function (cherry picked from commitd7b263ff8b) (cherry picked from commitb3eaf2249d) (cherry picked from commitd492ddd9bb) [F3] add GetLocalMatchingRemote with a default implementation (cherry picked from commit0a22015039) (cherry picked from commitf1310c38fb) (cherry picked from commitdeb68552f2) [F3] GetLocalMatchingRemote for user (cherry picked from commite73cb837f5) (cherry picked from commita24bc0b85e) (cherry picked from commit846a522ecc) [F3] GetAdminUser now has a ctx argument (cherry picked from commit37357a92af) (cherry picked from commit660bc1673c) (cherry picked from commit72d692a767) [F3] introduce UserTypeF3 To avoid conflicts should UserTypeRemoteUser be used differently by Gitea (cherry picked from commit6de2701bb3) [F3] user.Put: idempotency (cherry picked from commit821e38573c) (cherry picked from commitf7638f5414) [F3] upgrade to urfave v2 (cherry picked from commitcc3dbdfd1d) [F3] update gof3 (cherry picked from commit2eee960751) [F3] move f3 under forgejo-cli * simplify the tests by re-using the forgejo-cli helpers to capture the output * unify CmdF3 to be structured in the same way CmdActions is (cherry picked from commit4c9fe58b74) [F3] replace f3 with forgejo-cli f3 (cherry picked from commit7ba7ceef1b) [F3] s/ListOptions/Paginator/ [F3] user: add unit tests [F3] user comparison of F3 managed users is on content [F3] issue: add unit tests [F3] gof3 now has one more argument to Put() [F3] re-use gof3 unit tests for the driver (cherry picked from commitaf7ee6200c) Conflicts: tests/integration/integration_test.go because of some code removed in forgejo-development, trivial context conflict resolution [F3] more idempotent tests (#1275) Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/1275 Co-authored-by: Loïc Dachary <loic@dachary.org> Co-committed-by: Loïc Dachary <loic@dachary.org> [F3] tests: do SQL update if nothing changes [F3] tests comment idempotence [F3] tests milestone idempotence [F3] tests pull_request idempotence [F3] tests release idempotence [F3] tests asset idempotence [F3] tests project idempotence [F3] tests review idempotence
434 lines
11 KiB
Go
434 lines
11 KiB
Go
// Copyright 2014 The Gogs Authors. All rights reserved.
|
|
// Copyright 2019 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package auth
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"reflect"
|
|
|
|
"code.gitea.io/gitea/models/db"
|
|
"code.gitea.io/gitea/modules/log"
|
|
"code.gitea.io/gitea/modules/timeutil"
|
|
"code.gitea.io/gitea/modules/util"
|
|
|
|
"xorm.io/xorm"
|
|
"xorm.io/xorm/convert"
|
|
)
|
|
|
|
// Type represents an login type.
|
|
type Type int
|
|
|
|
// Note: new type must append to the end of list to maintain compatibility.
|
|
const (
|
|
NoType Type = iota
|
|
Plain // 1
|
|
LDAP // 2
|
|
SMTP // 3
|
|
PAM // 4
|
|
DLDAP // 5
|
|
OAuth2 // 6
|
|
SSPI // 7
|
|
)
|
|
|
|
// This should be in the above list of types but is separated to avoid conflicts with Gitea changes
|
|
const F3 Type = 129
|
|
|
|
// String returns the string name of the LoginType
|
|
func (typ Type) String() string {
|
|
return Names[typ]
|
|
}
|
|
|
|
// Int returns the int value of the LoginType
|
|
func (typ Type) Int() int {
|
|
return int(typ)
|
|
}
|
|
|
|
// Names contains the name of LoginType values.
|
|
var Names = map[Type]string{
|
|
LDAP: "LDAP (via BindDN)",
|
|
DLDAP: "LDAP (simple auth)", // Via direct bind
|
|
SMTP: "SMTP",
|
|
PAM: "PAM",
|
|
OAuth2: "OAuth2",
|
|
SSPI: "SPNEGO with SSPI",
|
|
F3: "F3",
|
|
}
|
|
|
|
// Config represents login config as far as the db is concerned
|
|
type Config interface {
|
|
convert.Conversion
|
|
}
|
|
|
|
// SkipVerifiable configurations provide a IsSkipVerify to check if SkipVerify is set
|
|
type SkipVerifiable interface {
|
|
IsSkipVerify() bool
|
|
}
|
|
|
|
// HasTLSer configurations provide a HasTLS to check if TLS can be enabled
|
|
type HasTLSer interface {
|
|
HasTLS() bool
|
|
}
|
|
|
|
// UseTLSer configurations provide a HasTLS to check if TLS is enabled
|
|
type UseTLSer interface {
|
|
UseTLS() bool
|
|
}
|
|
|
|
// SSHKeyProvider configurations provide ProvidesSSHKeys to check if they provide SSHKeys
|
|
type SSHKeyProvider interface {
|
|
ProvidesSSHKeys() bool
|
|
}
|
|
|
|
// RegisterableSource configurations provide RegisterSource which needs to be run on creation
|
|
type RegisterableSource interface {
|
|
RegisterSource() error
|
|
UnregisterSource() error
|
|
}
|
|
|
|
var registeredConfigs = map[Type]func() Config{}
|
|
|
|
// RegisterTypeConfig register a config for a provided type
|
|
func RegisterTypeConfig(typ Type, exemplar Config) {
|
|
if reflect.TypeOf(exemplar).Kind() == reflect.Ptr {
|
|
// Pointer:
|
|
registeredConfigs[typ] = func() Config {
|
|
return reflect.New(reflect.ValueOf(exemplar).Elem().Type()).Interface().(Config)
|
|
}
|
|
return
|
|
}
|
|
|
|
// Not a Pointer
|
|
registeredConfigs[typ] = func() Config {
|
|
return reflect.New(reflect.TypeOf(exemplar)).Elem().Interface().(Config)
|
|
}
|
|
}
|
|
|
|
// SourceSettable configurations can have their authSource set on them
|
|
type SourceSettable interface {
|
|
SetAuthSource(*Source)
|
|
}
|
|
|
|
// Source represents an external way for authorizing users.
|
|
type Source struct {
|
|
ID int64 `xorm:"pk autoincr"`
|
|
Type Type
|
|
Name string `xorm:"UNIQUE"`
|
|
IsActive bool `xorm:"INDEX NOT NULL DEFAULT false"`
|
|
IsSyncEnabled bool `xorm:"INDEX NOT NULL DEFAULT false"`
|
|
Cfg convert.Conversion `xorm:"TEXT"`
|
|
|
|
CreatedUnix timeutil.TimeStamp `xorm:"INDEX created"`
|
|
UpdatedUnix timeutil.TimeStamp `xorm:"INDEX updated"`
|
|
}
|
|
|
|
// TableName xorm will read the table name from this method
|
|
func (Source) TableName() string {
|
|
return "login_source"
|
|
}
|
|
|
|
func init() {
|
|
db.RegisterModel(new(Source))
|
|
}
|
|
|
|
// BeforeSet is invoked from XORM before setting the value of a field of this object.
|
|
func (source *Source) BeforeSet(colName string, val xorm.Cell) {
|
|
if colName == "type" {
|
|
typ := Type(db.Cell2Int64(val))
|
|
constructor, ok := registeredConfigs[typ]
|
|
if !ok {
|
|
return
|
|
}
|
|
source.Cfg = constructor()
|
|
if settable, ok := source.Cfg.(SourceSettable); ok {
|
|
settable.SetAuthSource(source)
|
|
}
|
|
}
|
|
}
|
|
|
|
// TypeName return name of this login source type.
|
|
func (source *Source) TypeName() string {
|
|
return Names[source.Type]
|
|
}
|
|
|
|
// IsLDAP returns true of this source is of the LDAP type.
|
|
func (source *Source) IsLDAP() bool {
|
|
return source.Type == LDAP
|
|
}
|
|
|
|
// IsDLDAP returns true of this source is of the DLDAP type.
|
|
func (source *Source) IsDLDAP() bool {
|
|
return source.Type == DLDAP
|
|
}
|
|
|
|
// IsSMTP returns true of this source is of the SMTP type.
|
|
func (source *Source) IsSMTP() bool {
|
|
return source.Type == SMTP
|
|
}
|
|
|
|
// IsPAM returns true of this source is of the PAM type.
|
|
func (source *Source) IsPAM() bool {
|
|
return source.Type == PAM
|
|
}
|
|
|
|
// IsOAuth2 returns true of this source is of the OAuth2 type.
|
|
func (source *Source) IsOAuth2() bool {
|
|
return source.Type == OAuth2
|
|
}
|
|
|
|
// IsSSPI returns true of this source is of the SSPI type.
|
|
func (source *Source) IsSSPI() bool {
|
|
return source.Type == SSPI
|
|
}
|
|
|
|
func (source *Source) IsF3() bool {
|
|
return source.Type == F3
|
|
}
|
|
|
|
// HasTLS returns true of this source supports TLS.
|
|
func (source *Source) HasTLS() bool {
|
|
hasTLSer, ok := source.Cfg.(HasTLSer)
|
|
return ok && hasTLSer.HasTLS()
|
|
}
|
|
|
|
// UseTLS returns true of this source is configured to use TLS.
|
|
func (source *Source) UseTLS() bool {
|
|
useTLSer, ok := source.Cfg.(UseTLSer)
|
|
return ok && useTLSer.UseTLS()
|
|
}
|
|
|
|
// SkipVerify returns true if this source is configured to skip SSL
|
|
// verification.
|
|
func (source *Source) SkipVerify() bool {
|
|
skipVerifiable, ok := source.Cfg.(SkipVerifiable)
|
|
return ok && skipVerifiable.IsSkipVerify()
|
|
}
|
|
|
|
// CreateSource inserts a AuthSource in the DB if not already
|
|
// existing with the given name.
|
|
func CreateSource(source *Source) error {
|
|
has, err := db.GetEngine(db.DefaultContext).Where("name=?", source.Name).Exist(new(Source))
|
|
if err != nil {
|
|
return err
|
|
} else if has {
|
|
return ErrSourceAlreadyExist{source.Name}
|
|
}
|
|
// Synchronization is only available with LDAP for now
|
|
if !source.IsLDAP() {
|
|
source.IsSyncEnabled = false
|
|
}
|
|
|
|
_, err = db.GetEngine(db.DefaultContext).Insert(source)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
if !source.IsActive {
|
|
return nil
|
|
}
|
|
|
|
if settable, ok := source.Cfg.(SourceSettable); ok {
|
|
settable.SetAuthSource(source)
|
|
}
|
|
|
|
registerableSource, ok := source.Cfg.(RegisterableSource)
|
|
if !ok {
|
|
return nil
|
|
}
|
|
|
|
err = registerableSource.RegisterSource()
|
|
if err != nil {
|
|
// remove the AuthSource in case of errors while registering configuration
|
|
if _, err := db.GetEngine(db.DefaultContext).Delete(source); err != nil {
|
|
log.Error("CreateSource: Error while wrapOpenIDConnectInitializeError: %v", err)
|
|
}
|
|
}
|
|
return err
|
|
}
|
|
|
|
// Sources returns a slice of all login sources found in DB.
|
|
func Sources() ([]*Source, error) {
|
|
auths := make([]*Source, 0, 6)
|
|
return auths, db.GetEngine(db.DefaultContext).Find(&auths)
|
|
}
|
|
|
|
// SourcesByType returns all sources of the specified type
|
|
func SourcesByType(loginType Type) ([]*Source, error) {
|
|
sources := make([]*Source, 0, 1)
|
|
if err := db.GetEngine(db.DefaultContext).Where("type = ?", loginType).Find(&sources); err != nil {
|
|
return nil, err
|
|
}
|
|
return sources, nil
|
|
}
|
|
|
|
// AllActiveSources returns all active sources
|
|
func AllActiveSources() ([]*Source, error) {
|
|
sources := make([]*Source, 0, 5)
|
|
if err := db.GetEngine(db.DefaultContext).Where("is_active = ?", true).Find(&sources); err != nil {
|
|
return nil, err
|
|
}
|
|
return sources, nil
|
|
}
|
|
|
|
// ActiveSources returns all active sources of the specified type
|
|
func ActiveSources(tp Type) ([]*Source, error) {
|
|
sources := make([]*Source, 0, 1)
|
|
if err := db.GetEngine(db.DefaultContext).Where("is_active = ? and type = ?", true, tp).Find(&sources); err != nil {
|
|
return nil, err
|
|
}
|
|
return sources, nil
|
|
}
|
|
|
|
// IsSSPIEnabled returns true if there is at least one activated login
|
|
// source of type LoginSSPI
|
|
func IsSSPIEnabled() bool {
|
|
if !db.HasEngine {
|
|
return false
|
|
}
|
|
sources, err := ActiveSources(SSPI)
|
|
if err != nil {
|
|
log.Error("ActiveSources: %v", err)
|
|
return false
|
|
}
|
|
return len(sources) > 0
|
|
}
|
|
|
|
// GetSourceByID returns login source by given ID.
|
|
func GetSourceByID(id int64) (*Source, error) {
|
|
source := new(Source)
|
|
if id == 0 {
|
|
source.Cfg = registeredConfigs[NoType]()
|
|
// Set this source to active
|
|
// FIXME: allow disabling of db based password authentication in future
|
|
source.IsActive = true
|
|
return source, nil
|
|
}
|
|
|
|
has, err := db.GetEngine(db.DefaultContext).ID(id).Get(source)
|
|
if err != nil {
|
|
return nil, err
|
|
} else if !has {
|
|
return nil, ErrSourceNotExist{id}
|
|
}
|
|
return source, nil
|
|
}
|
|
|
|
func GetSourceByName(ctx context.Context, name string) (*Source, error) {
|
|
source := &Source{}
|
|
has, err := db.GetEngine(ctx).Where("name = ?", name).Get(source)
|
|
if err != nil {
|
|
return nil, err
|
|
} else if !has {
|
|
return nil, ErrSourceNotExist{}
|
|
}
|
|
return source, nil
|
|
}
|
|
|
|
// UpdateSource updates a Source record in DB.
|
|
func UpdateSource(source *Source) error {
|
|
var originalSource *Source
|
|
if source.IsOAuth2() {
|
|
// keep track of the original values so we can restore in case of errors while registering OAuth2 providers
|
|
var err error
|
|
if originalSource, err = GetSourceByID(source.ID); err != nil {
|
|
return err
|
|
}
|
|
}
|
|
|
|
has, err := db.GetEngine(db.DefaultContext).Where("name=? AND id!=?", source.Name, source.ID).Exist(new(Source))
|
|
if err != nil {
|
|
return err
|
|
} else if has {
|
|
return ErrSourceAlreadyExist{source.Name}
|
|
}
|
|
|
|
_, err = db.GetEngine(db.DefaultContext).ID(source.ID).AllCols().Update(source)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
if !source.IsActive {
|
|
return nil
|
|
}
|
|
|
|
if settable, ok := source.Cfg.(SourceSettable); ok {
|
|
settable.SetAuthSource(source)
|
|
}
|
|
|
|
registerableSource, ok := source.Cfg.(RegisterableSource)
|
|
if !ok {
|
|
return nil
|
|
}
|
|
|
|
err = registerableSource.RegisterSource()
|
|
if err != nil {
|
|
// restore original values since we cannot update the provider it self
|
|
if _, err := db.GetEngine(db.DefaultContext).ID(source.ID).AllCols().Update(originalSource); err != nil {
|
|
log.Error("UpdateSource: Error while wrapOpenIDConnectInitializeError: %v", err)
|
|
}
|
|
}
|
|
return err
|
|
}
|
|
|
|
// CountSources returns number of login sources.
|
|
func CountSources() int64 {
|
|
count, _ := db.GetEngine(db.DefaultContext).Count(new(Source))
|
|
return count
|
|
}
|
|
|
|
// ErrSourceNotExist represents a "SourceNotExist" kind of error.
|
|
type ErrSourceNotExist struct {
|
|
ID int64
|
|
}
|
|
|
|
// IsErrSourceNotExist checks if an error is a ErrSourceNotExist.
|
|
func IsErrSourceNotExist(err error) bool {
|
|
_, ok := err.(ErrSourceNotExist)
|
|
return ok
|
|
}
|
|
|
|
func (err ErrSourceNotExist) Error() string {
|
|
return fmt.Sprintf("login source does not exist [id: %d]", err.ID)
|
|
}
|
|
|
|
// Unwrap unwraps this as a ErrNotExist err
|
|
func (err ErrSourceNotExist) Unwrap() error {
|
|
return util.ErrNotExist
|
|
}
|
|
|
|
// ErrSourceAlreadyExist represents a "SourceAlreadyExist" kind of error.
|
|
type ErrSourceAlreadyExist struct {
|
|
Name string
|
|
}
|
|
|
|
// IsErrSourceAlreadyExist checks if an error is a ErrSourceAlreadyExist.
|
|
func IsErrSourceAlreadyExist(err error) bool {
|
|
_, ok := err.(ErrSourceAlreadyExist)
|
|
return ok
|
|
}
|
|
|
|
func (err ErrSourceAlreadyExist) Error() string {
|
|
return fmt.Sprintf("login source already exists [name: %s]", err.Name)
|
|
}
|
|
|
|
// Unwrap unwraps this as a ErrExist err
|
|
func (err ErrSourceAlreadyExist) Unwrap() error {
|
|
return util.ErrAlreadyExist
|
|
}
|
|
|
|
// ErrSourceInUse represents a "SourceInUse" kind of error.
|
|
type ErrSourceInUse struct {
|
|
ID int64
|
|
}
|
|
|
|
// IsErrSourceInUse checks if an error is a ErrSourceInUse.
|
|
func IsErrSourceInUse(err error) bool {
|
|
_, ok := err.(ErrSourceInUse)
|
|
return ok
|
|
}
|
|
|
|
func (err ErrSourceInUse) Error() string {
|
|
return fmt.Sprintf("login source is still used by some users [id: %d]", err.ID)
|
|
}
|