From fea7c52e9584ff117be8529b431b40590deef0ca Mon Sep 17 00:00:00 2001
From: James Moger <james.moger@gitblit.com>
Date: Thu, 10 Apr 2014 18:58:08 -0400
Subject: [PATCH] Renamed SshContext->SshCommandContext for clarity of purpose
---
src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java | 144 +++++++++++++++++++++---------------------------
1 files changed, 63 insertions(+), 81 deletions(-)
diff --git a/src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java b/src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java
index 4ab20f3..3631922 100644
--- a/src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java
+++ b/src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java
@@ -15,25 +15,23 @@
*/
package com.gitblit.transport.ssh;
-import java.io.File;
-import java.io.IOException;
import java.security.PublicKey;
+import java.util.List;
import java.util.Locale;
import java.util.concurrent.ExecutionException;
+import java.util.concurrent.TimeUnit;
-import org.apache.commons.codec.binary.Base64;
-import org.apache.sshd.common.util.Buffer;
import org.apache.sshd.server.PublickeyAuthenticator;
import org.apache.sshd.server.session.ServerSession;
-import org.eclipse.jgit.lib.Constants;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
-import com.gitblit.manager.IGitblit;
-import com.google.common.base.Charsets;
+import com.gitblit.manager.IAuthenticationManager;
+import com.gitblit.models.UserModel;
+import com.google.common.cache.Cache;
import com.google.common.cache.CacheBuilder;
import com.google.common.cache.CacheLoader;
import com.google.common.cache.LoadingCache;
-import com.google.common.cache.Weigher;
-import com.google.common.io.Files;
/**
*
@@ -42,84 +40,68 @@
*/
public class SshKeyAuthenticator implements PublickeyAuthenticator {
- protected final IGitblit gitblit;
+ protected final Logger log = LoggerFactory.getLogger(getClass());
- LoadingCache<String, SshKeyCacheEntry> sshKeyCache = CacheBuilder
- .newBuilder().maximumWeight(2 << 20).weigher(new SshKeyCacheWeigher())
- .build(new CacheLoader<String, SshKeyCacheEntry>() {
- public SshKeyCacheEntry load(String key) throws Exception {
- return loadKey(key);
- }
+ protected final IKeyManager keyManager;
- private SshKeyCacheEntry loadKey(String key) {
- try {
- // TODO(davido): retrieve absolute path to public key directory:
- //String dir = gitblit.getSettings().getString("public_key_dir", "data/ssh");
- String dir = "/tmp/";
- // Expect public key file name in form: <username.pub> in
- File file = new File(dir + key + ".pub");
- String str = Files.toString(file, Charsets.ISO_8859_1);
- final String[] parts = str.split(" ");
- final byte[] bin =
- Base64.decodeBase64(Constants.encodeASCII(parts[1]));
- return new SshKeyCacheEntry(key, new Buffer(bin).getRawPublicKey());
- } catch (IOException e) {
- throw new RuntimeException("Canot read public key", e);
- }
- }
- });
+ protected final IAuthenticationManager authManager;
- public SshKeyAuthenticator(IGitblit gitblit) {
- this.gitblit = gitblit;
- }
+ LoadingCache<String, List<PublicKey>> sshKeyCache = CacheBuilder
+ .newBuilder().
+ expireAfterAccess(15, TimeUnit.MINUTES).
+ maximumSize(100)
+ .build(new CacheLoader<String, List<PublicKey>>() {
+ @Override
+ public List<PublicKey> load(String username) {
+ return keyManager.getKeys(username);
+ }
+ });
- @Override
- public boolean authenticate(String username, final PublicKey suppliedKey,
- final ServerSession session) {
- final SshSession sd = session.getAttribute(SshSession.KEY);
+ public SshKeyAuthenticator(IKeyManager keyManager, IAuthenticationManager authManager) {
+ this.keyManager = keyManager;
+ this.authManager = authManager;
+ }
- // if (config.getBoolean("auth", "userNameToLowerCase", false)) {
- username = username.toLowerCase(Locale.US);
- // }
- try {
- // TODO: allow multiple public keys per user
- SshKeyCacheEntry key = sshKeyCache.get(username);
- if (key == null) {
- sd.authenticationError(username, "no-matching-key");
- return false;
- }
+ @Override
+ public boolean authenticate(String username, final PublicKey suppliedKey,
+ final ServerSession session) {
+ final SshDaemonClient client = session.getAttribute(SshDaemonClient.KEY);
- if (key.match(suppliedKey)) {
- return success(username, session, sd);
- }
- return false;
- } catch (ExecutionException e) {
- sd.authenticationError(username, "user-not-found");
- return false;
- }
- }
+ if (client.getUser() != null) {
+ // TODO why do we re-authenticate?
+ log.info("{} has already authenticated!", username);
+ return true;
+ }
- boolean success(String username, ServerSession session, SshSession sd) {
- sd.authenticationSuccess(username);
- /*
- * sshLog.onLogin();
- *
- * GerritServerSession s = (GerritServerSession) session;
- * s.addCloseSessionListener( new SshFutureListener<CloseFuture>() {
- *
- * @Override public void operationComplete(CloseFuture future) { final
- * Context ctx = sshScope.newContext(null, sd, null); final Context old =
- * sshScope.set(ctx); try { sshLog.onLogout(); } finally {
- * sshScope.set(old); } } }); }
- */
- return true;
- }
+ username = username.toLowerCase(Locale.US);
+ try {
+ List<PublicKey> keys = sshKeyCache.get(username);
+ if (keys == null || keys.isEmpty()) {
+ log.info("{} has not added any public keys for ssh authentication", username);
+ return false;
+ }
- private static class SshKeyCacheWeigher implements
- Weigher<String, SshKeyCacheEntry> {
- @Override
- public int weigh(String key, SshKeyCacheEntry value) {
- return key.length() + value.weigh();
- }
- }
+ for (PublicKey key : keys) {
+ if (key.equals(suppliedKey)) {
+ UserModel user = authManager.authenticate(username, key);
+ if (user != null) {
+ client.setUser(user);
+ return true;
+ }
+ }
+ }
+ } catch (ExecutionException e) {
+ }
+
+ log.warn("could not authenticate {} for SSH using the supplied public key", username);
+ return false;
+ }
+
+ public IKeyManager getKeyManager() {
+ return keyManager;
+ }
+
+ public Cache<String, List<PublicKey>> getKeyCache() {
+ return sshKeyCache;
+ }
}
--
Gitblit v1.9.1