Browse Source
Add tests for password and keyboard-interactive authentication. Implement password authentication; the default provided by sshd is non-interactive, which is not useful for JGit. Make sure the CredentialsProvider gets reset on successive password retrieval attempts. Otherwise it might always return the same non- accepted password from a secure storage. (That one was discovered by actually trying this via EGit; the JGit tests don't catch this.) Change the default order of authentication mechanisms to prefer password over keyboard-interactive. This is a mitigation for upstream bug SSHD-866.[1] Also include a fix for upstream bug SSHD-867.[2] [1] https://issues.apache.org/jira/projects/SSHD/issues/SSHD-866 [2] https://issues.apache.org/jira/projects/SSHD/issues/SSHD-867 Bug: 520927 Change-Id: I423e548f06d3b51531016cf08938c8bd7acaa2a9 Signed-off-by: Thomas Wolf <thomas.wolf@paranor.ch>stable-5.2
Thomas Wolf
6 years ago
committed by
Matthias Sohn
11 changed files with 431 additions and 26 deletions
@ -0,0 +1,66 @@ |
|||||||
|
/* |
||||||
|
* Copyright (C) 2018, Thomas Wolf <thomas.wolf@paranor.ch> |
||||||
|
* and other copyright owners as documented in the project's IP log. |
||||||
|
* |
||||||
|
* This program and the accompanying materials are made available |
||||||
|
* under the terms of the Eclipse Distribution License v1.0 which |
||||||
|
* accompanies this distribution, is reproduced below, and is |
||||||
|
* available at http://www.eclipse.org/org/documents/edl-v10.php
|
||||||
|
* |
||||||
|
* All rights reserved. |
||||||
|
* |
||||||
|
* Redistribution and use in source and binary forms, with or |
||||||
|
* without modification, are permitted provided that the following |
||||||
|
* conditions are met: |
||||||
|
* |
||||||
|
* - Redistributions of source code must retain the above copyright |
||||||
|
* notice, this list of conditions and the following disclaimer. |
||||||
|
* |
||||||
|
* - Redistributions in binary form must reproduce the above |
||||||
|
* copyright notice, this list of conditions and the following |
||||||
|
* disclaimer in the documentation and/or other materials provided |
||||||
|
* with the distribution. |
||||||
|
* |
||||||
|
* - Neither the name of the Eclipse Foundation, Inc. nor the |
||||||
|
* names of its contributors may be used to endorse or promote |
||||||
|
* products derived from this software without specific prior |
||||||
|
* written permission. |
||||||
|
* |
||||||
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND |
||||||
|
* CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, |
||||||
|
* INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES |
||||||
|
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
||||||
|
* ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR |
||||||
|
* CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT |
||||||
|
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; |
||||||
|
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER |
||||||
|
* CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, |
||||||
|
* STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) |
||||||
|
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF |
||||||
|
* ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
*/ |
||||||
|
package org.eclipse.jgit.internal.transport.sshd; |
||||||
|
|
||||||
|
import org.apache.sshd.client.auth.AbstractUserAuthFactory; |
||||||
|
import org.apache.sshd.client.auth.UserAuth; |
||||||
|
import org.apache.sshd.client.auth.password.UserAuthPasswordFactory; |
||||||
|
|
||||||
|
/** |
||||||
|
* A customized {@link UserAuthPasswordFactory} that creates instance of |
||||||
|
* {@link JGitPasswordAuthentication}. |
||||||
|
*/ |
||||||
|
public class JGitPasswordAuthFactory extends AbstractUserAuthFactory { |
||||||
|
|
||||||
|
/** The singleton {@link JGitPasswordAuthFactory}. */ |
||||||
|
public static final JGitPasswordAuthFactory INSTANCE = new JGitPasswordAuthFactory(); |
||||||
|
|
||||||
|
private JGitPasswordAuthFactory() { |
||||||
|
super(UserAuthPasswordFactory.NAME); |
||||||
|
} |
||||||
|
|
||||||
|
@Override |
||||||
|
public UserAuth create() { |
||||||
|
return new JGitPasswordAuthentication(); |
||||||
|
} |
||||||
|
} |
@ -0,0 +1,100 @@ |
|||||||
|
/* |
||||||
|
* Copyright (C) 2018, Thomas Wolf <thomas.wolf@paranor.ch> |
||||||
|
* and other copyright owners as documented in the project's IP log. |
||||||
|
* |
||||||
|
* This program and the accompanying materials are made available |
||||||
|
* under the terms of the Eclipse Distribution License v1.0 which |
||||||
|
* accompanies this distribution, is reproduced below, and is |
||||||
|
* available at http://www.eclipse.org/org/documents/edl-v10.php
|
||||||
|
* |
||||||
|
* All rights reserved. |
||||||
|
* |
||||||
|
* Redistribution and use in source and binary forms, with or |
||||||
|
* without modification, are permitted provided that the following |
||||||
|
* conditions are met: |
||||||
|
* |
||||||
|
* - Redistributions of source code must retain the above copyright |
||||||
|
* notice, this list of conditions and the following disclaimer. |
||||||
|
* |
||||||
|
* - Redistributions in binary form must reproduce the above |
||||||
|
* copyright notice, this list of conditions and the following |
||||||
|
* disclaimer in the documentation and/or other materials provided |
||||||
|
* with the distribution. |
||||||
|
* |
||||||
|
* - Neither the name of the Eclipse Foundation, Inc. nor the |
||||||
|
* names of its contributors may be used to endorse or promote |
||||||
|
* products derived from this software without specific prior |
||||||
|
* written permission. |
||||||
|
* |
||||||
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND |
||||||
|
* CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, |
||||||
|
* INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES |
||||||
|
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
||||||
|
* ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR |
||||||
|
* CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
||||||
|
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT |
||||||
|
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; |
||||||
|
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER |
||||||
|
* CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, |
||||||
|
* STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) |
||||||
|
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF |
||||||
|
* ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
||||||
|
*/ |
||||||
|
package org.eclipse.jgit.internal.transport.sshd; |
||||||
|
|
||||||
|
import java.util.concurrent.CancellationException; |
||||||
|
|
||||||
|
import org.apache.sshd.client.ClientAuthenticationManager; |
||||||
|
import org.apache.sshd.client.auth.keyboard.UserInteraction; |
||||||
|
import org.apache.sshd.client.auth.password.UserAuthPassword; |
||||||
|
import org.apache.sshd.client.session.ClientSession; |
||||||
|
|
||||||
|
/** |
||||||
|
* A password authentication handler that uses the {@link JGitUserInteraction} |
||||||
|
* to ask the user for the password. It also respects the |
||||||
|
* {@code NumberOfPasswordPrompts} ssh config. |
||||||
|
*/ |
||||||
|
public class JGitPasswordAuthentication extends UserAuthPassword { |
||||||
|
|
||||||
|
private int maxAttempts; |
||||||
|
|
||||||
|
private int attempts; |
||||||
|
|
||||||
|
@Override |
||||||
|
public void init(ClientSession session, String service) throws Exception { |
||||||
|
super.init(session, service); |
||||||
|
maxAttempts = Math.max(1, |
||||||
|
session.getIntProperty( |
||||||
|
ClientAuthenticationManager.PASSWORD_PROMPTS, |
||||||
|
ClientAuthenticationManager.DEFAULT_PASSWORD_PROMPTS)); |
||||||
|
attempts = 0; |
||||||
|
} |
||||||
|
|
||||||
|
@Override |
||||||
|
protected boolean sendAuthDataRequest(ClientSession session, String service) |
||||||
|
throws Exception { |
||||||
|
if (++attempts > maxAttempts) { |
||||||
|
return false; |
||||||
|
} |
||||||
|
UserInteraction interaction = session.getUserInteraction(); |
||||||
|
if (!interaction.isInteractionAllowed(session)) { |
||||||
|
return false; |
||||||
|
} |
||||||
|
String password = getPassword(session, interaction); |
||||||
|
if (password == null) { |
||||||
|
throw new CancellationException(); |
||||||
|
} |
||||||
|
// sendPassword takes a buffer as first argument, but actually doesn't
|
||||||
|
// use it and creates its own buffer...
|
||||||
|
sendPassword(null, session, password, password); |
||||||
|
return true; |
||||||
|
} |
||||||
|
|
||||||
|
private String getPassword(ClientSession session, |
||||||
|
UserInteraction interaction) { |
||||||
|
String[] results = interaction.interactive(session, null, null, "", //$NON-NLS-1$
|
||||||
|
new String[] { SshdText.get().passwordPrompt }, |
||||||
|
new boolean[] { false }); |
||||||
|
return (results == null || results.length == 0) ? null : results[0]; |
||||||
|
} |
||||||
|
} |
Loading…
Reference in new issue