f851adb2faa6eb6281fbf55bb004294ace85a50a

Author
Ayman Bagabas <ayman.bagabas@gmail.com>
Committer
Ayman Bagabas <ayman.bagabas@gmail.com>
Date

Message

fix(ssh): restrict publickey auth

only accept readwrite access using pubkey auth. Keyboard-interactive
auth will be used after all keys authentication has failed

Diff

 1diff --git a/server/ssh/ssh.go b/server/ssh/ssh.go
 2index a962721d67d19636d31477aa7fb009097c001b45..6e727fbd2431fa2d81631f44f025266e4808215f 100644
 3--- a/server/ssh/ssh.go
 4+++ b/server/ssh/ssh.go
 5@@ -163,7 +163,7 @@ func (s *SSHServer) Shutdown(ctx context.Context) error {
 6 // PublicKeyAuthHandler handles public key authentication.
 7 func (s *SSHServer) PublicKeyHandler(ctx ssh.Context, pk ssh.PublicKey) (allowed bool) {
 8 	if pk == nil {
 9-		return s.cfg.Backend.AllowKeyless()
10+		return false
11 	}
12 
13 	ak := backend.MarshalAuthorizedKey(pk)
14@@ -173,11 +173,12 @@ func (s *SSHServer) PublicKeyHandler(ctx ssh.Context, pk ssh.PublicKey) (allowed
15 
16 	ac := s.cfg.Backend.AccessLevelByPublicKey("", pk)
17 	s.logger.Debugf("access level for %q: %s", ak, ac)
18-	allowed = ac >= backend.ReadOnlyAccess
19+	allowed = ac >= backend.ReadWriteAccess
20 	return
21 }
22 
23 // KeyboardInteractiveHandler handles keyboard interactive authentication.
24+// This is used after all public key authentication has failed.
25 func (s *SSHServer) KeyboardInteractiveHandler(ctx ssh.Context, _ gossh.KeyboardInteractiveChallenge) bool {
26 	ac := s.cfg.Backend.AllowKeyless()
27 	keyboardInteractiveCounter.WithLabelValues(ctx.User(), strconv.FormatBool(ac)).Inc()