Commit e5b88306 authored by Jan Koester's avatar Jan Koester
Browse files

test

parent 3991453f
Loading
Loading
Loading
Loading
+5 −0
Original line number Diff line number Diff line
@@ -268,8 +268,13 @@ void blogi::Auth::Apilogin(const int tid,const char *username,const char *passwo
}

bool blogi::Auth::isLoggedIn(const int tid,const uuid::uuid &authid){
      // Plugin-only sources (loginEligible=false) never grant blogi backend
      // access, even if the session happens to authenticate against one --
      // otherwise adding one for a plugin's own domain checks would quietly
      // open up blogi's own /settings to anyone from that source.
      for(size_t i = 0; i < _config.getAuthSourceCount(); ++i){
          const AuthSource &src = _config.getAuthSource(i);
          if(!src.loginEligible) continue;
          try {
              authdb::client::ClientConnection authcon;
              authcon.setUrl(src.url);
+12 −1
Original line number Diff line number Diff line
@@ -362,10 +362,15 @@ const blogi::AuthSource *blogi::Config::findAuthSource(const std::string &domain
}

std::vector<const blogi::AuthSource*> blogi::Config::findAuthSources(const std::string &domain) const {
    // Login routing only -- plugin-only sources (loginEligible=false) must
    // never be reachable through blogi's own login/session gate. Plugins
    // that want to see them too use getAuthSourceCount()/getAuthSource()
    // directly, which this deliberately doesn't touch.
    std::vector<const AuthSource*> out;
    std::string searchDomain = domain;
    for (auto &c : searchDomain) c = std::tolower(c);
    for (const auto &src : _AuthSources) {
        if (!src.loginEligible) continue;
        std::string srcDomain = src.domain;
        for (auto &c : srcDomain) c = std::tolower(c);
        if (srcDomain == searchDomain) out.push_back(&src);
@@ -376,7 +381,9 @@ std::vector<const blogi::AuthSource*> blogi::Config::findAuthSources(const std::
        // findAuthSource()'s single-source shortcut, generalized to a
        // failover chain. Matters for the common case where every entry is
        // tagged with the site's own domain name rather than "".
        for (const auto &src : _AuthSources) out.push_back(&src);
        for (const auto &src : _AuthSources) {
            if (src.loginEligible) out.push_back(&src);
        }
    }
    return out;
}
@@ -449,6 +456,7 @@ std::string serializeAuthSources(const std::vector<blogi::AuthSource> &srcs) {
        json_object_object_add(jo, "client_secret", json_object_new_string(s.clientSecret.c_str()));
        json_object_object_add(jo, "domain", json_object_new_string(s.domain.c_str()));
        json_object_object_add(jo, "tls_verify", json_object_new_boolean(s.tlsVerify));
        json_object_object_add(jo, "login_eligible", json_object_new_boolean(s.loginEligible));
        json_object_array_add(jarr, jo);
    }
    std::string out = json_object_to_json_string_ext(jarr, JSON_C_TO_STRING_PLAIN);
@@ -473,6 +481,9 @@ std::vector<blogi::AuthSource> parseAuthSources(const std::string &json) {
        if (json_object_object_get_ex(jo, "client_secret", &jv)) s.clientSecret = json_object_get_string(jv);
        if (json_object_object_get_ex(jo, "domain", &jv)) s.domain = json_object_get_string(jv);
        if (json_object_object_get_ex(jo, "tls_verify", &jv)) s.tlsVerify = json_object_get_boolean(jv);
        // Missing key (rows written before this flag existed) keeps the
        // struct's default of true -- those sources stay blogi-login-eligible.
        if (json_object_object_get_ex(jo, "login_eligible", &jv)) s.loginEligible = json_object_get_boolean(jv);
        out.push_back(std::move(s));
    }
    json_object_put(jarr);
+10 −0
Original line number Diff line number Diff line
@@ -46,6 +46,16 @@ namespace blogi {
        std::string domain;
        // See DomainConfig::authTlsVerify.
        bool tlsVerify = true;
        // false = plugin-only source: usable by plugins that iterate
        // getAuthSourceCount()/getAuthSource() for their own domain/GPO
        // checks (e.g. schimmeldoc's admin-/moderator-domain), but invisible
        // to blogi's own login/session gate -- Auth::login/Apilogin and
        // Auth::isLoggedIn skip these entirely, so adding one can never let
        // someone log into the blogi backend or pass its "Allow Login" GPO
        // check. Defaults to true so every pre-existing source (loaded from
        // config.yaml, or added before this flag existed) keeps working as
        // a normal blogi login source.
        bool loginEligible = true;
    };

    struct MediaSource {