From fea7c52e9584ff117be8529b431b40590deef0ca Mon Sep 17 00:00:00 2001
From: James Moger <james.moger@gitblit.com>
Date: Thu, 10 Apr 2014 18:58:08 -0400
Subject: [PATCH] Renamed SshContext->SshCommandContext for clarity of purpose
---
src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java | 47 ++++++++++++++++++++++++++++++-----------------
1 files changed, 30 insertions(+), 17 deletions(-)
diff --git a/src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java b/src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java
index d41afdd..3631922 100644
--- a/src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java
+++ b/src/main/java/com/gitblit/transport/ssh/SshKeyAuthenticator.java
@@ -23,9 +23,12 @@
import org.apache.sshd.server.PublickeyAuthenticator;
import org.apache.sshd.server.session.ServerSession;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
import com.gitblit.manager.IAuthenticationManager;
import com.gitblit.models.UserModel;
+import com.google.common.cache.Cache;
import com.google.common.cache.CacheBuilder;
import com.google.common.cache.CacheLoader;
import com.google.common.cache.LoadingCache;
@@ -37,8 +40,10 @@
*/
public class SshKeyAuthenticator implements PublickeyAuthenticator {
+ protected final Logger log = LoggerFactory.getLogger(getClass());
+
protected final IKeyManager keyManager;
-
+
protected final IAuthenticationManager authManager;
LoadingCache<String, List<PublicKey>> sshKeyCache = CacheBuilder
@@ -46,6 +51,7 @@
expireAfterAccess(15, TimeUnit.MINUTES).
maximumSize(100)
.build(new CacheLoader<String, List<PublicKey>>() {
+ @Override
public List<PublicKey> load(String username) {
return keyManager.getKeys(username);
}
@@ -59,36 +65,43 @@
@Override
public boolean authenticate(String username, final PublicKey suppliedKey,
final ServerSession session) {
- final SshSession sd = session.getAttribute(SshSession.KEY);
+ final SshDaemonClient client = session.getAttribute(SshDaemonClient.KEY);
+
+ if (client.getUser() != null) {
+ // TODO why do we re-authenticate?
+ log.info("{} has already authenticated!", username);
+ return true;
+ }
username = username.toLowerCase(Locale.US);
try {
List<PublicKey> keys = sshKeyCache.get(username);
if (keys == null || keys.isEmpty()) {
- sd.authenticationError(username, "no-matching-key");
+ log.info("{} has not added any public keys for ssh authentication", username);
return false;
}
+
for (PublicKey key : keys) {
if (key.equals(suppliedKey)) {
- return validate(username, sd);
+ UserModel user = authManager.authenticate(username, key);
+ if (user != null) {
+ client.setUser(user);
+ return true;
+ }
}
}
- return false;
} catch (ExecutionException e) {
- sd.authenticationError(username, "user-not-found");
- return false;
}
+
+ log.warn("could not authenticate {} for SSH using the supplied public key", username);
+ return false;
}
- boolean validate(String username, SshSession sd) {
- // now that the key has been validated, check with the authentication
- // manager to ensure that this user exists and can authenticate
- sd.authenticationSuccess(username);
- UserModel user = authManager.authenticate(sd);
- if (user != null) {
- return true;
- }
- sd.authenticationError(username, "user-not-found");
- return false;
+ public IKeyManager getKeyManager() {
+ return keyManager;
+ }
+
+ public Cache<String, List<PublicKey>> getKeyCache() {
+ return sshKeyCache;
}
}
--
Gitblit v1.9.1