Compare commits

...
6 Commits
Author SHA1 Message Date
Henrique Dias b645ac51eb Merge pull request #3 from fzoske/master
Add Support For BCrypt Storage of Passwords
2018-03-31 15:32:19 +01:00
Fabian Zoske 62aea27486 Add Support For BCrypt Storage of Passwords 2018-03-31 12:01:00 +02:00
Henrique Dias 541defc796 Update .travis.yml 2017-12-21 17:07:12 +00:00
Henrique Dias d2f2b1ccde Update Travis 2017-12-21 17:02:37 +00:00
Henrique Dias 6c10c35efe Merge pull request #2 from c35sys/master
Add *address* config option
2017-12-21 17:01:18 +00:00
Christophe Le Guern 8271975046 Add *address* config option 2017-12-21 17:50:03 +01:00
3 changed files with 37 additions and 20 deletions
+1 -4
View File
@@ -9,10 +9,7 @@ install:
- go get ./... - go get ./...
# Install gometalinter and certain linters # Install gometalinter and certain linters
- go get github.com/alecthomas/gometalinter - go get github.com/alecthomas/gometalinter
- go get github.com/client9/misspell/cmd/misspell - gometalinter --install
- go get github.com/gordonklaus/ineffassign
- go get golang.org/x/tools/cmd/goimports
- go get github.com/tsenart/deadcode
script: script:
- gometalinter --disable-all -E vet -E gofmt -E misspell -E ineffassign -E goimports -E deadcode --tests ./... - gometalinter --disable-all -E vet -E gofmt -E misspell -E ineffassign -E goimports -E deadcode --tests ./...
+32 -15
View File
@@ -11,8 +11,10 @@ import (
"os" "os"
"path/filepath" "path/filepath"
"regexp" "regexp"
"strings"
"github.com/hacdias/webdav" "github.com/hacdias/webdav"
"golang.org/x/crypto/bcrypt"
wd "golang.org/x/net/webdav" wd "golang.org/x/net/webdav"
yaml "gopkg.in/yaml.v2" yaml "gopkg.in/yaml.v2"
) )
@@ -133,24 +135,27 @@ func getConfig() []byte {
} }
type cfg struct { type cfg struct {
webdav *webdav.Config webdav *webdav.Config
port string address string
auth map[string]string port string
auth map[string]string
} }
func parseConfig() *cfg { func parseConfig() *cfg {
file := getConfig() file := getConfig()
data := struct { data := struct {
Port string `json:"port" yaml:"port"` Address string `json:"address" yaml:"address"`
Scope string `json:"scope" yaml:"scope"` Port string `json:"port" yaml:"port"`
Modify bool `json:"modify" yaml:"modify"` Scope string `json:"scope" yaml:"scope"`
Rules []map[string]interface{} `json:"rules" yaml:"rules"` Modify bool `json:"modify" yaml:"modify"`
Users []map[string]interface{} `json:"users" yaml:"users"` Rules []map[string]interface{} `json:"rules" yaml:"rules"`
Users []map[string]interface{} `json:"users" yaml:"users"`
}{ }{
Port: "0", Address: "0.0.0.0",
Scope: "./", Port: "0",
Modify: true, Scope: "./",
Modify: true,
} }
var err error var err error
@@ -165,8 +170,9 @@ func parseConfig() *cfg {
} }
config := &cfg{ config := &cfg{
port: data.Port, address: data.Address,
auth: map[string]string{}, port: data.Port,
auth: map[string]string{},
webdav: &webdav.Config{ webdav: &webdav.Config{
User: &webdav.User{ User: &webdav.User{
Scope: data.Scope, Scope: data.Scope,
@@ -209,7 +215,8 @@ func basicAuth(c *cfg) http.Handler {
return return
} }
if password != p { if !checkPassword(p, password) {
log.Println("Wrong Password for user", username)
http.Error(w, "Not authorized", 401) http.Error(w, "Not authorized", 401)
return return
} }
@@ -218,13 +225,23 @@ func basicAuth(c *cfg) http.Handler {
}) })
} }
func checkPassword(saved, input string) bool {
if strings.HasPrefix(saved, "{bcrypt}") {
savedPassword := strings.TrimPrefix(saved, "{bcrypt}")
return bcrypt.CompareHashAndPassword([]byte(savedPassword), []byte(input)) == nil
}
return saved == input
}
func main() { func main() {
flag.Parse() flag.Parse()
cfg := parseConfig() cfg := parseConfig()
handler := basicAuth(cfg) handler := basicAuth(cfg)
// Builds the address and a listener. // Builds the address and a listener.
laddr := ":" + cfg.port laddr := cfg.address + ":" + cfg.port
listener, err := net.Listen("tcp", laddr) listener, err := net.Listen("tcp", laddr)
if err != nil { if err != nil {
log.Fatal(err) log.Fatal(err)
+4 -1
View File
@@ -7,10 +7,13 @@
```yaml ```yaml
scope: /path/to/files scope: /path/to/files
address: 0.0.0.0
port: 8080 port: 8080
users: users:
- username: admin - username: admin
password: admin password: admin
- username: encrypted
password: "{bcrypt}$2y$10$zEP6oofmXFeHaeMfBNLnP.DO8m.H.Mwhd24/TOX2MWLxAExXi4qgi"
- username: basic - username: basic
password: basic password: basic
modify: false modify: false
@@ -22,4 +25,4 @@ users:
You can specify the path to the configuration file using the `--config` flag. By default, it will search for a `config.{yaml,json}` file on your current working directory. You can specify the path to the configuration file using the `--config` flag. By default, it will search for a `config.{yaml,json}` file on your current working directory.
Download it [here](https://github.com/hacdias/webdav/releases). Download it [here](https://github.com/hacdias/webdav/releases).