Browse Source
Add tests for password and keyboard-interactive authentication. Implement password authentication; the default provided by sshd is non-interactive, which is not useful for JGit. Make sure the CredentialsProvider gets reset on successive password retrieval attempts. Otherwise it might always return the same non- accepted password from a secure storage. (That one was discovered by actually trying this via EGit; the JGit tests don't catch this.) Change the default order of authentication mechanisms to prefer password over keyboard-interactive. This is a mitigation for upstream bug SSHD-866.[1] Also include a fix for upstream bug SSHD-867.[2] [1] https://issues.apache.org/jira/projects/SSHD/issues/SSHD-866 [2] https://issues.apache.org/jira/projects/SSHD/issues/SSHD-867 Bug: 520927 Change-Id: I423e548f06d3b51531016cf08938c8bd7acaa2a9 Signed-off-by: Thomas Wolf <thomas.wolf@paranor.ch>stable-5.2
Thomas Wolf
6 years ago
committed by
Matthias Sohn
11 changed files with 431 additions and 26 deletions
@ -0,0 +1,66 @@
|
||||
/* |
||||
* Copyright (C) 2018, Thomas Wolf <thomas.wolf@paranor.ch> |
||||
* and other copyright owners as documented in the project's IP log. |
||||
* |
||||
* This program and the accompanying materials are made available |
||||
* under the terms of the Eclipse Distribution License v1.0 which |
||||
* accompanies this distribution, is reproduced below, and is |
||||
* available at http://www.eclipse.org/org/documents/edl-v10.php
|
||||
* |
||||
* All rights reserved. |
||||
* |
||||
* Redistribution and use in source and binary forms, with or |
||||
* without modification, are permitted provided that the following |
||||
* conditions are met: |
||||
* |
||||
* - Redistributions of source code must retain the above copyright |
||||
* notice, this list of conditions and the following disclaimer. |
||||
* |
||||
* - Redistributions in binary form must reproduce the above |
||||
* copyright notice, this list of conditions and the following |
||||
* disclaimer in the documentation and/or other materials provided |
||||
* with the distribution. |
||||
* |
||||
* - Neither the name of the Eclipse Foundation, Inc. nor the |
||||
* names of its contributors may be used to endorse or promote |
||||
* products derived from this software without specific prior |
||||
* written permission. |
||||
* |
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND |
||||
* CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, |
||||
* INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES |
||||
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
||||
* ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR |
||||
* CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT |
||||
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; |
||||
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER |
||||
* CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, |
||||
* STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) |
||||
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF |
||||
* ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||
*/ |
||||
package org.eclipse.jgit.internal.transport.sshd; |
||||
|
||||
import org.apache.sshd.client.auth.AbstractUserAuthFactory; |
||||
import org.apache.sshd.client.auth.UserAuth; |
||||
import org.apache.sshd.client.auth.password.UserAuthPasswordFactory; |
||||
|
||||
/** |
||||
* A customized {@link UserAuthPasswordFactory} that creates instance of |
||||
* {@link JGitPasswordAuthentication}. |
||||
*/ |
||||
public class JGitPasswordAuthFactory extends AbstractUserAuthFactory { |
||||
|
||||
/** The singleton {@link JGitPasswordAuthFactory}. */ |
||||
public static final JGitPasswordAuthFactory INSTANCE = new JGitPasswordAuthFactory(); |
||||
|
||||
private JGitPasswordAuthFactory() { |
||||
super(UserAuthPasswordFactory.NAME); |
||||
} |
||||
|
||||
@Override |
||||
public UserAuth create() { |
||||
return new JGitPasswordAuthentication(); |
||||
} |
||||
} |
@ -0,0 +1,100 @@
|
||||
/* |
||||
* Copyright (C) 2018, Thomas Wolf <thomas.wolf@paranor.ch> |
||||
* and other copyright owners as documented in the project's IP log. |
||||
* |
||||
* This program and the accompanying materials are made available |
||||
* under the terms of the Eclipse Distribution License v1.0 which |
||||
* accompanies this distribution, is reproduced below, and is |
||||
* available at http://www.eclipse.org/org/documents/edl-v10.php
|
||||
* |
||||
* All rights reserved. |
||||
* |
||||
* Redistribution and use in source and binary forms, with or |
||||
* without modification, are permitted provided that the following |
||||
* conditions are met: |
||||
* |
||||
* - Redistributions of source code must retain the above copyright |
||||
* notice, this list of conditions and the following disclaimer. |
||||
* |
||||
* - Redistributions in binary form must reproduce the above |
||||
* copyright notice, this list of conditions and the following |
||||
* disclaimer in the documentation and/or other materials provided |
||||
* with the distribution. |
||||
* |
||||
* - Neither the name of the Eclipse Foundation, Inc. nor the |
||||
* names of its contributors may be used to endorse or promote |
||||
* products derived from this software without specific prior |
||||
* written permission. |
||||
* |
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND |
||||
* CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, |
||||
* INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES |
||||
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
||||
* ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR |
||||
* CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT |
||||
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; |
||||
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER |
||||
* CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, |
||||
* STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) |
||||
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF |
||||
* ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||
*/ |
||||
package org.eclipse.jgit.internal.transport.sshd; |
||||
|
||||
import java.util.concurrent.CancellationException; |
||||
|
||||
import org.apache.sshd.client.ClientAuthenticationManager; |
||||
import org.apache.sshd.client.auth.keyboard.UserInteraction; |
||||
import org.apache.sshd.client.auth.password.UserAuthPassword; |
||||
import org.apache.sshd.client.session.ClientSession; |
||||
|
||||
/** |
||||
* A password authentication handler that uses the {@link JGitUserInteraction} |
||||
* to ask the user for the password. It also respects the |
||||
* {@code NumberOfPasswordPrompts} ssh config. |
||||
*/ |
||||
public class JGitPasswordAuthentication extends UserAuthPassword { |
||||
|
||||
private int maxAttempts; |
||||
|
||||
private int attempts; |
||||
|
||||
@Override |
||||
public void init(ClientSession session, String service) throws Exception { |
||||
super.init(session, service); |
||||
maxAttempts = Math.max(1, |
||||
session.getIntProperty( |
||||
ClientAuthenticationManager.PASSWORD_PROMPTS, |
||||
ClientAuthenticationManager.DEFAULT_PASSWORD_PROMPTS)); |
||||
attempts = 0; |
||||
} |
||||
|
||||
@Override |
||||
protected boolean sendAuthDataRequest(ClientSession session, String service) |
||||
throws Exception { |
||||
if (++attempts > maxAttempts) { |
||||
return false; |
||||
} |
||||
UserInteraction interaction = session.getUserInteraction(); |
||||
if (!interaction.isInteractionAllowed(session)) { |
||||
return false; |
||||
} |
||||
String password = getPassword(session, interaction); |
||||
if (password == null) { |
||||
throw new CancellationException(); |
||||
} |
||||
// sendPassword takes a buffer as first argument, but actually doesn't
|
||||
// use it and creates its own buffer...
|
||||
sendPassword(null, session, password, password); |
||||
return true; |
||||
} |
||||
|
||||
private String getPassword(ClientSession session, |
||||
UserInteraction interaction) { |
||||
String[] results = interaction.interactive(session, null, null, "", //$NON-NLS-1$
|
||||
new String[] { SshdText.get().passwordPrompt }, |
||||
new boolean[] { false }); |
||||
return (results == null || results.length == 0) ? null : results[0]; |
||||
} |
||||
} |
Loading…
Reference in new issue