73edc31341103ed5f51750b3687833f4a11dbb34

Author
Toby Padilla <toby@charm.sh>
Committer
Toby Padilla <toby@charm.sh>
Date

Message

Auth against users in config.yaml

Diff

This diff is truncated to protect this page.

  1diff --git a/config/auth.go b/config/auth.go
  2index 78f6b2d6e27a5def15e9947b4d861c3f94e1c21b..1a772e27c27384e692d40d6be48cd147f9e62c09 100644
  3--- a/config/auth.go
  4+++ b/config/auth.go
  5@@ -1,13 +1,14 @@
  6 package config
  7 
  8 import (
  9+	"log"
 10+
 11 	gm "github.com/charmbracelet/wish/git"
 12 	"github.com/gliderlabs/ssh"
 13 )
 14 
 15 func (cfg *Config) AuthRepo(repo string, pk ssh.PublicKey) gm.AccessLevel {
 16-	// TODO: check yaml for access rules
 17-	return gm.ReadWriteAccess
 18+	return cfg.accessForKey(repo, pk)
 19 }
 20 
 21 func (cfg *Config) PasswordHandler(ctx ssh.Context, password string) bool {
 22@@ -15,6 +16,39 @@ func (cfg *Config) PasswordHandler(ctx ssh.Context, password string) bool {
 23 }
 24 
 25 func (cfg *Config) PublicKeyHandler(ctx ssh.Context, pk ssh.PublicKey) bool {
 26-	// TODO: check yaml for access rules
 27+	if cfg.accessForKey("", pk) == gm.NoAccess {
 28+		return false
 29+	}
 30 	return true
 31 }
 32+
 33+func (cfg *Config) accessForKey(repo string, pk ssh.PublicKey) gm.AccessLevel {
 34+	for _, u := range cfg.Users {
 35+		apk, _, _, _, err := ssh.ParseAuthorizedKey([]byte(u.PublicKey))
 36+		if err != nil {
 37+			log.Printf("error: malformed authorized key: '%s'", u.PublicKey)
 38+			return gm.NoAccess
 39+		}
 40+		if ssh.KeysEqual(pk, apk) {
 41+			if u.Admin {
 42+				return gm.AdminAccess
 43+			}
 44+			for _, r := range u.CollabRepos {
 45+				if repo == r {
 46+					return gm.ReadWriteAccess
 47+				}
 48+			}
 49+			return gm.ReadOnlyAccess
 50+		}
 51+	}
 52+	switch cfg.AnonAccess {
 53+	case "no-access":
 54+		return gm.NoAccess
 55+	case "read-only":
 56+		return gm.ReadOnlyAccess
 57+	case "read-write":
 58+		return gm.ReadWriteAccess
 59+	default:
 60+		return gm.NoAccess
 61+	}
 62+}
 63diff --git a/config/config.go b/config/config.go
 64index 46f7ba7ea87f014db60c0b07ecab34639e7b448c..17c97d0e96a93acac5a4dc4bfb19672957fd2070 100644
 65--- a/config/config.go
 66+++ b/config/config.go
 67@@ -29,7 +29,7 @@ type Config struct {
 68 type User struct {
 69 	Name        string   `yaml:"name"`
 70 	Admin       bool     `yaml:"admin"`
 71-	PublicKey   string   `yaml:"pk"`
 72+	PublicKey   string   `yaml:"public-key"`
 73 	CollabRepos []string `yaml:"collab_repos"`
 74 }
 75 
 76@@ -72,13 +72,13 @@ func NewConfig(host string, port int, pk string, rs *git.RepoSource) (*Config, e
 77 }
 78 
 79 func (cfg *Config) Pushed(repo string, pk ssh.PublicKey) {
 80-	err := cfg.Reload()
 81+	err := cfg.reload()
 82 	if err != nil {
 83 		log.Printf("error reloading after push: %s", err)
 84 	}
 85 }
 86 
 87-func (cfg *Config) Reload() error {
 88+func (cfg *Config) reload() error {
 89 	err := cfg.Source.LoadRepos()
 90 	if err != nil {
 91 		return err
 92@@ -157,12 +157,11 @@ func (cfg *Config) createDefaultConfigRepo(yaml string) error {
 93 		if err != nil {
 94 			return err
 95 		}
 96-		err = rs.LoadRepos()
 97 		if err != nil {
 98 			return err
 99 		}
100 	} else if err != nil {
101 		return err
102 	}
103-	return nil
104+	return cfg.reload()
105 }
106diff --git a/config/defaults.go b/config/defaults.go
107index 49b1235b6ec8289c28d1e623be783f6702b0476b..a7053c290fe619dbdf3ad174ec44620d0f43f42f 100644
108--- a/config/defaults.go
109+++ b/config/defaults.go
110@@ -2,8 +2,7 @@ package config
111