Project homepage Mailing List  Warmcat.com  API Docs  Github Mirror 
    npro  
 Modern all-safe Rust Network Protocol library supporting h1, h2, h3, ws, wt sans-IO and with socket IO + tls
git clone https://npro.rs/repo/npro
 
root / scripts / sai-web.service
Author[]Andy Green <andy@warmcat.com> 2026-04-02 15:04 UTC
Committer[]Andy Green <andy@warmcat.com> 2026-04-03 05:55 UTC
Tree4dbad7fca6a2b44c3c68c2bebefbe77a75e6f754   Raw Patch
 
auth: switch to oauth
auth: switch to oauth
diff --git a/assets/index.html b/assets/index.html index 9ce4186..4381ffd 100644 --- a/assets/index.html +++ b/assets/index.html @@ -4,6 +4,7 @@ <link rel="stylesheet" type="text/css" href="sai.css"/> <link rel="icon" href="sai-icon.svg" sizes="any" type="image/svg+xml"/> <script type='text/javascript' src='sai.js'></script> + <script type='text/javascript' src='lws-login.js'></script> <script type='text/javascript' src="lws-common.js"></script> <title>Sai</title> </head> @@ -11,26 +12,13 @@ <div class="overlay"></div> <div class="main-container"> <div class="left-pane"> - <div class="logo"> - <img class="logo" src="sai.svg"><br> - <span class="logo"><a href="https://warmcat.com/git/sai">Sai git</a></span> - <span class="logo" id="apirev"></span> - </div> - <div id="login" class="login"> - <div id="creds" class="creds hide"> - <form class="login"> - <label for="lname">Name:</label> - <input class="crin" type="text" id="lname" name="lname" autocomplete="username"><br> - <label for="lpass">Password:</label> - <input class="crin" type="password" id="lpass" name="lpass" autocomplete="current-password"><br> - <input class="crinb" type="button" value="Login" id="login-button"> - <input type="hidden" id="success_redir" name="success_redir" value=""> - </form> - </div> - <div id="logout" class="creds hide"> - <div id="remauth"></div> - <input class="crin" type="button" id="logout-button" value="Logout"> + <div style="display: flex; align-items: center; margin-bottom: 12px; flex-wrap: nowrap;"> + <div class="logo"> + <img class="logo" src="sai.svg"><br> + <span class="logo"><a href="https://warmcat.com/git/sai">Sai git</a></span> + <span class="logo" id="apirev"></span> </div> + <div id="lws-login-status-container" style="margin-left: 10px; margin-top: 4px;"></div> </div> <div id="sai_builders"></div> </div> diff --git a/assets/sai.js b/assets/sai.js index 3ea092c..f0430d6 100644 --- a/assets/sai.js +++ b/assets/sai.js @@ -1874,30 +1874,6 @@ function ws_open_sai() */ s = "<table>"; - authd = jso.authorized; - if (jso.authorized === 0) { - if (document.getElementById("creds")) - document.getElementById("creds").classList.remove("hide"); - if (document.getElementById("logout")) - document.getElementById("logout").classList.add("hide"); - } - if (jso.authorized === 1) { - if (document.getElementById("creds")) - document.getElementById("creds").classList.add("hide"); - if (document.getElementById("logout")) - document.getElementById("logout").classList.remove("hide"); - if (jso.auth_user) - auth_user = jso.auth_user; - if (jso.auth_secs) { - var now_ut = Math.round((new Date().getTime() / 1000)); - clearTimeout(exptimer); - exptimer = window.setTimeout(expiry, 1000 * jso.auth_secs); - if (document.getElementById("remauth")) - document.getElementById("remauth").innerHTML = - san(auth_user) + " " + agify(now_ut, now_ut + jso.auth_secs); - } - } - /* * Update existing? */ @@ -2004,30 +1980,6 @@ function ws_open_sai() if (!jso.t) break; - authd = jso.authorized; - if (jso.authorized === 0) { - if (document.getElementById("creds")) - document.getElementById("creds").classList.remove("hide"); - if (document.getElementById("logout")) - document.getElementById("logout").classList.add("hide"); - } - if (jso.authorized === 1) { - if (document.getElementById("creds")) - document.getElementById("creds").classList.add("hide"); - if (document.getElementById("logout")) - document.getElementById("logout").classList.remove("hide"); - if (jso.auth_user) - auth_user = jso.auth_user; - if (jso.auth_secs) { - var now_ut = Math.round((new Date().getTime() / 1000)); - clearTimeout(exptimer); - exptimer = window.setTimeout(expiry, 1000 * jso.auth_secs); - if (document.getElementById("remauth")) - document.getElementById("remauth").innerHTML = - san(auth_user) + " " + agify(now_ut, now_ut + jso.auth_secs); - } - } - /* * We get told about changes to any task state, * it's up to us to figure out if the page we @@ -2381,44 +2333,6 @@ function ws_open_sai() } } -function post_login_form() -{ - var xhr = new XMLHttpRequest(), s ="", q = window.location.pathname; - - s = "----boundo\x0d\x0acontent-disposition: form-data; name=\"lname\"\x0d\x0a\x0d\x0a" + - document.getElementById("lname").value + - "\x0d\x0a----boundo\x0d\x0acontent-disposition: form-data; name=\"lpass\"\x0d\x0a\x0d\x0a" + - document.getElementById("lpass").value + - "\x0d\x0a----boundo\x0d\x0acontent-disposition: form-data; name=\"success_redir\"\x0d\x0a\x0d\x0a" + - document.getElementById("success_redir").value + - "\x0d\x0a----boundo--"; - - if (q.length > 10 && q.substring(q.length - 10) == "index.html") - q = q.substring(0, q.length - 10); - xhr.open("POST", q + "login", true); - xhr.setRequestHeader( 'content-type', "multipart/form-data; boundary=--boundo"); - - console.log(s.length +" " + s); - - xhr.onload = function (e) { - if (xhr.readyState === 4) { - if (xhr.status === 200 || xhr.status == 303) { - console.log(xhr.responseText); - location.reload(); - } else { - console.error(xhr.statusText); - } - } - }; - xhr.onerror = function (e) { - console.error(xhr.statusText); - }; - - xhr.send(s); - - return false; -} - /* stuff that has to be delayed until all the page assets are loaded */ window.addEventListener("load", function() { @@ -2451,18 +2365,23 @@ window.addEventListener("load", function() { if (document.getElementById("noscript")) document.getElementById("noscript").display = "none"; - /* login form hidden success redirect */ - if (document.getElementById("success_redir")) - document.getElementById("success_redir").value = - window.location.href; + /* LWS Login hook */ + if (window.renderLwsLoginStatus) + window.renderLwsLoginStatus('lws-login-status-container'); + + fetch('.lws-login-status') + .then(function(res) { return res.json(); }) + .then(function(data) { + if (data.logged_in && data.has_grant) + authd = 1; + }) + .catch(function(err) { + console.log('lws-login auth fetch failed: ', err); + }); + ws_open_sai(); aging(); - if (document.getElementById("login-button")) { - document.getElementById("login-button").addEventListener("click", post_login_form); - document.getElementById("logout-button").addEventListener("click", post_login_form); - } - setInterval(function() { update_task_activities(); diff --git a/etc-sai-EXAMPLE/web/conf.d/unixskt b/etc-sai-EXAMPLE/web/conf.d/unixskt index e14702e..2c8b305 100644 --- a/etc-sai-EXAMPLE/web/conf.d/unixskt +++ b/etc-sai-EXAMPLE/web/conf.d/unixskt @@ -64,16 +64,6 @@ "database": "/srv/sai/sai-master", - # auth jwk path - # You can generate a suitable key like this - # - # lws-crypto-jwk -t EC -b512 -vP-521 --alg ES512 > mykey.jwk - # - "jwt-auth-alg": "ES512", - "jwt-auth-jwk-path": "/etc/sai/web/auth.jwk", - - "jwt-iss": "com.warmcat", - "jwt-aud": "https://mydomain.com/sai", # template HTML to use for this vhost. You'd normally # copy this to gitohashi-vhostname.html and modify it diff --git a/src/server/s-task.c b/src/server/s-task.c index 6f72e9e..901fa09 100644 --- a/src/server/s-task.c +++ b/src/server/s-task.c @@ -819,7 +819,8 @@ sais_create_and_offer_task_step(struct vhd *vhd, const char *task_uuid) /* * Make a copy of the lws_struct allocation in the lwsac, - * then drop the lwsac + * but we must retain the lwsac because the copied task_template + * still contains pointers into it! */ temp_task = malloc(sizeof(sai_task_t)); @@ -831,7 +832,7 @@ sais_create_and_offer_task_step(struct vhd *vhd, const char *task_uuid) memset(temp_task, 0, sizeof(*temp_task)); *temp_task = *task_template; - lwsac_free(&ac); + temp_task->ac_task_container = ac; sais_get_task_metrics_estimates(vhd, temp_task); diff --git a/src/web/w-comms.c b/src/web/w-comms.c index bc0931f..7911db5 100644 --- a/src/web/w-comms.c +++ b/src/web/w-comms.c @@ -40,24 +40,7 @@ const lws_struct_map_t lsm_schema_map_ta[] = { LSM_SCHEMA (sai_task_t, NULL, lsm_task, "com-warmcat-sai-ta"), }; -typedef struct sai_auth { - lws_dll2_t list; - char name[33]; - char passphrase[65]; - unsigned long since; - unsigned long last_updated; -} sai_auth_t; - -const lws_struct_map_t lsm_auth[] = { - LSM_CARRAY (sai_auth_t, name, "name"), - LSM_CARRAY (sai_auth_t, passphrase, "passphrase"), - LSM_UNSIGNED (sai_auth_t, since, "since"), - LSM_UNSIGNED (sai_auth_t, last_updated, "last_updated"), -}; -const lws_struct_map_t lsm_schema_sq3_map_auth[] = { - LSM_SCHEMA_DLL2 (sai_auth_t, list, NULL, lsm_auth, "auth"), -}; extern const lws_struct_map_t lsm_schema_sq3_map_event[]; @@ -119,19 +102,7 @@ sai_get_head_status(struct vhd *vhd, const char *projname) } -static int -sai_login_cb(void *data, const char *name, const char *filename, - char *buf, int len, enum lws_spa_fileupload_states state) -{ - lwsl_notice("%s: name '%s'\n", __func__, name); - return 0; -} -static const char * const auth_param_names[] = { - "lname", - "lpass", - "success_redir", -}; enum enum_param_names { EPN_LNAME, @@ -166,12 +137,10 @@ w_callback_ws(struct lws *wsi, enum lws_callback_reasons reason, void *user, uint8_t buf[LWS_PRE + 8192], *start = &buf[LWS_PRE], *p = start, *end = &buf[sizeof(buf) - LWS_PRE - 1]; struct pss *pss = (struct pss *)user; - struct lws_jwt_sign_set_cookie ck; sai_http_murl_t mu = SHMUT_NONE; char projname[64]; int n, resp, r; const char *cp; - size_t cml; (void)end; (void)p; @@ -214,84 +183,7 @@ w_callback_ws(struct lws *wsi, enum lws_callback_reasons reason, void *user, return -1; } - /* auth database */ - lws_snprintf((char *)buf, sizeof(buf), "%s-auth.sqlite3", - vhd->sqlite3_path_lhs); - - if (lws_struct_sq3_open(vhd->context, (char *)buf, 1, - &vhd->pdb_auth)) { - lwsl_err("%s: Unable to open auth db %s: %s\n", - __func__, vhd->sqlite3_path_lhs, sqlite3_errmsg( - vhd->pdb_auth)); - - return -1; - } - - if (lws_struct_sq3_create_table(vhd->pdb_auth, - lsm_schema_sq3_map_auth)) { - lwsl_err("%s: unable to create auth table\n", __func__); - return -1; - } - - /* - * jwt-iss - */ - - if (lws_pvo_get_str(in, "jwt-iss", &vhd->jwt_issuer)) { - lwsl_err("%s: jwt-iss required\n", __func__); - return -1; - } - - /* - * jwt-aud - */ - - if (lws_pvo_get_str(in, "jwt-aud", &vhd->jwt_audience)) { - lwsl_err("%s: jwt-aud required\n", __func__); - return -1; - } - - /* - * auth-alg - */ - - if (lws_pvo_get_str(in, "jwt-auth-alg", &cp)) { - lwsl_err("%s: jwt-auth-alg required\n", __func__); - return -1; - } - - lws_strncpy(vhd->jwt_auth_alg, cp, sizeof(vhd->jwt_auth_alg)); - - /* - * auth-jwk-path - */ - - if (lws_pvo_get_str(in, "jwt-auth-jwk-path", &cp)) { - lwsl_err("%s: jwt-auth-jwk-path required\n", __func__); - return -1; - } - - n = open(cp, LWS_O_RDONLY); - if (n < 0) { - lwsl_err("%s: can't open auth JWK %s\n", __func__, cp); - return -1; - } - r = (int)read(n, buf, sizeof(buf)); - close(n); - if (r < 0) { - lwsl_err("%s: can't read auth JWK %s\n", __func__, cp); - return -1; - } - - if (lws_jwk_import(&vhd->jwt_jwk_auth, NULL, NULL, - (const char *)buf, (unsigned int)r)) { - lwsl_notice("%s: Failed to parse JWK key\n", __func__); - return -1; - } - - lwsl_notice("%s: Auth JWK type %d\n", __func__, - vhd->jwt_jwk_auth.kty); /* * Reach out to the sai-server part over the SS ws websrv link @@ -319,8 +211,6 @@ w_callback_ws(struct lws *wsi, enum lws_callback_reasons reason, void *user, case LWS_CALLBACK_PROTOCOL_DESTROY: saiw_event_db_close_all_now(vhd); lws_struct_sq3_close(&vhd->pdb); - lws_struct_sq3_close(&vhd->pdb_auth); - lws_jwk_destroy(&vhd->jwt_jwk_auth); goto passthru; /* @@ -339,33 +229,6 @@ w_callback_ws(struct lws *wsi, enum lws_callback_reasons reason, void *user, resp = HTTP_STATUS_FORBIDDEN; pss->vhd = vhd; - /* - * What's the situation with a JWT cookie? Normal users won't - * have any, but privileged users will have one, and we should - * try to confirm it and set the pss auth level accordingly - */ - - memset(&ck, 0, sizeof(ck)); - ck.jwk = &vhd->jwt_jwk_auth; - ck.alg = vhd->jwt_auth_alg; - ck.iss = vhd->jwt_issuer; - ck.aud = vhd->jwt_audience; - ck.cookie_name = "__Host-sai_jwt"; - - cml = sizeof(buf); - if (!lws_jwt_get_http_cookie_validate_jwt(wsi, &ck, - (char *)buf, &cml) && - ck.extra_json && - !lws_json_simple_strcmp(ck.extra_json, ck.extra_json_len, - "\"authorized\":", "1")) { - /* the token allows him to manage us */ - pss->authorized = 1; - pss->expiry_unix_time = ck.expiry_unix_time; - lws_strncpy(pss->auth_user, ck.sub, - sizeof(pss->auth_user)); - } else - lwsl_info("%s: cookie rejected\n", __func__); - for (n = 0; n < (int)LWS_ARRAY_SIZE(well_known); n++) if (!strncmp((const char *)in, well_known[n], strlen(well_known[n]))) { @@ -414,11 +277,6 @@ w_callback_ws(struct lws *wsi, enum lws_callback_reasons reason, void *user, goto passthru; - case SHMUT_LOGIN: - pss->login_form = 1; - lwsl_notice("LWS_CALLBACK_HTTP: sees login\n"); - return 0; - case SHMUT_ARTIFACTS: /* * HTTP Bulk GET interface for artifact download @@ -510,43 +368,13 @@ http_resp: case LWS_CALLBACK_HTTP_BODY: // lwsl_notice("%s: HTTP_BODY\n", __func__); - - if (pss->login_form) { - - if (!pss->spa) { - pss->spa = lws_spa_create(wsi, auth_param_names, - LWS_ARRAY_SIZE(auth_param_names), - 1024, sai_login_cb, pss); - if (!pss->spa) { - lwsl_err("failed to create spa\n"); - return -1; - } - } - - /* let it parse the POST data */ - - lwsl_hexdump_notice(in, len); - - if (!pss->spa_failed && - lws_spa_process(pss->spa, in, (int)len)) { - - lwsl_notice("%s: spa failed\n", __func__); - - /* - * mark it as failed, and continue taking body until - * completion, and return error there - */ - pss->spa_failed = 1; - } - } - break; case LWS_CALLBACK_HTTP_BODY_COMPLETION: lwsl_user("%s: LWS_CALLBACK_HTTP_BODY_COMPLETION: %d\n", __func__, (int)len); - if (!pss->our_form && !pss->login_form) { + if (!pss->our_form) { lwsl_user("%s: no sai form\n", __func__); goto passthru; } @@ -555,155 +383,6 @@ http_resp: if (pss->spa) lws_spa_finalize(pss->spa); - if (pss->login_form) { - const char *un, *pw, *sr; - lws_dll2_owner_t o; - struct lwsac *ac = NULL; - - if (lws_add_http_header_status(wsi, - HTTP_STATUS_SEE_OTHER, &p, end)) - goto clean_spa; - if (lws_add_http_header_content_length(wsi, 0, &p, end)) - goto clean_spa; - - if (pss->spa_failed) - goto final; - - if (pss->authorized) { - - char temp[128]; - /* - * It means, logout then - */ - - n = lws_snprintf(temp, sizeof(temp), - "__Host-sai_jwt=deleted;" - "HttpOnly;" - "Secure;" - "SameSite=strict;" - "Path=/;" - "expires=Sun, 06 Nov 1994 08:49:37 GMT;"); - - sr = "x/.."; - - if (lws_add_http_header_by_token(wsi, - WSI_TOKEN_HTTP_SET_COOKIE, - (uint8_t *)temp, n, &p, end)) { - lwsl_err("%s: failed to add JWT cookie header\n", __func__); - return 1; - } - - goto back; - } - - un = lws_spa_get_string(pss->spa, EPN_LNAME); - pw = lws_spa_get_string(pss->spa, EPN_LPASS); - sr = lws_spa_get_string(pss->spa, EPN_SUCCESS_REDIR); - - if (!un || !pw || !sr) { - lwsl_notice("%s: missing form args %p %p %p\n", - __func__, un, pw, sr); - pss->spa_failed = 1; - goto final; - } - - // lwsl_notice("%s: login attempt %s %s %s\n", __func__, - // un, pw, sr); - - /* - * Try to look up his credentials - */ - - lws_sql_purify((char *)buf + 512, un, 34); - lws_sql_purify((char *)buf + 768, pw, 66); - lws_snprintf((char *)buf + 256, 256, - " and name='%s' and passphrase='%s'", - (const char *)buf + 512, - (const char *)buf + 768); - lws_dll2_owner_clear(&o); - n = lws_struct_sq3_deserialize(pss->vhd->pdb_auth, - (const char *)buf + 256, - NULL, - lsm_schema_sq3_map_auth, - &o, &ac, 0, 1); - if (n < 0 || !o.head) { - /* no results, failed */ - // lwsl_notice("%s: login attempt %s failed %d\n", - // __func__, (const char *)buf, n); - lwsac_free(&ac); - pss->spa_failed = 1; - goto final; - } - - /* any result in o means a successful match */ - - lwsac_free(&ac); - - /* - * Produce a signed JWT allowing managing this Sai - * instance for a short time, and redirect ourselves - * back to the page we were on - */ - - - - lwsl_notice("%s: setting cookie\n", __func__); - /* un is invalidated by destroying the spa */ - memset(&ck, 0, sizeof(ck)); - lws_strncpy(ck.sub, un, sizeof(ck.sub)); - ck.jwk = &vhd->jwt_jwk_auth; - ck.alg = vhd->jwt_auth_alg; - ck.iss = vhd->jwt_issuer; - ck.aud = vhd->jwt_audience; - ck.cookie_name = "sai_jwt"; - ck.extra_json = "\"authorized\": 1"; - ck.expiry_unix_time = 2 * 24 * 60 * 60; /* 2 days */ - - if (lws_jwt_sign_token_set_http_cookie(wsi, &ck, &p, end)) - goto clean_spa; - -back: - /* - * Auth succeeded, go to the page the form was on - */ - - if (lws_add_http_header_by_token(wsi, - WSI_TOKEN_HTTP_LOCATION, - (unsigned char *)sr, - (int)strlen((const char *)sr), - &p, end)) { - goto clean_spa; - } - - if (pss->spa) { - lws_spa_destroy(pss->spa); - pss->spa = NULL; - } - - if (lws_finalize_write_http_header(wsi, start, &p, end)) - goto bail; - - lwsl_notice("%s: set / delete cookie OK\n", __func__); - // lwsl_hexdump_notice(start, lws_ptr_diff(p, start)); - return 0; - -final: - lwsl_notice("%s: auth failed, login_form %d\n", - __func__, pss->login_form); - /* - * Auth failed, go back to / - */ - if (lws_add_http_header_by_token(wsi, - WSI_TOKEN_HTTP_LOCATION, - (unsigned char *)"/", 1, - &p, end)) { - goto clean_spa; - } - if (lws_finalize_write_http_header(wsi, start, &p, end)) - goto bail; - return 0; - } - if (pss->spa) { lws_spa_destroy(pss->spa); pss->spa = NULL; @@ -719,14 +398,6 @@ final: return -1; break; -clean_spa: - if (pss->spa) { - lws_spa_destroy(pss->spa); - pss->spa = NULL; - } - pss->spa_failed = 1; - goto final; - /* * ws connections from builders and browsers */ @@ -757,32 +428,6 @@ clean_spa: return -1; } - /* - * What's the situation with a JWT cookie? Normal users won't - * have any, but privileged users will have one, and we should - * try to confirm it and set the pss auth level accordingly - */ - - memset(&ck, 0, sizeof(ck)); - ck.jwk = &vhd->jwt_jwk_auth; - ck.alg = vhd->jwt_auth_alg; - ck.iss = vhd->jwt_issuer; - ck.aud = vhd->jwt_audience; - ck.cookie_name = "__Host-sai_jwt"; - - cml = sizeof(buf); - if (!lws_jwt_get_http_cookie_validate_jwt(wsi, &ck, - (char *)buf, &cml) && - ck.extra_json && - !lws_json_simple_strcmp(ck.extra_json, ck.extra_json_len, - "\"authorized\":", "1")) { - /* the token allows him to manage us */ - pss->authorized = 1; - pss->expiry_unix_time = ck.expiry_unix_time; - lws_strncpy(pss->auth_user, ck.sub, - sizeof(pss->auth_user)); - } else - lwsl_info("%s: cookie rejected\n", __func__); pss->wsi = wsi; pss->vhd = vhd; pss->alang[0] = '\0'; diff --git a/src/web/w-private.h b/src/web/w-private.h index 25a47f9..54b1b00 100644 --- a/src/web/w-private.h +++ b/src/web/w-private.h @@ -75,7 +75,6 @@ struct pss { char specific_ref[65]; char specific_task[65]; char specific_project[96]; - char auth_user[33]; sqlite3 *pdb_artifact; sqlite3_blob *blob_artifact; @@ -96,19 +95,15 @@ struct pss { int log_cache_index; int log_cache_size; - int authorized; int specificity; int segment_flags; unsigned int js_api_version; - unsigned long expiry_unix_time; /* notification hmac information */ char notification_sig[128]; char alang[128]; - struct lws_genhmac_ctx hmac; enum lws_genhmac_types hmac_type; char our_form; - char login_form; uint64_t first_log_timestamp; uint64_t initial_log_timestamp; @@ -138,16 +133,9 @@ struct vhd { struct lws_dll2_owner pcons_owner; struct lwsac *pcons; - /* our keys */ - struct lws_jwk jwt_jwk_auth; - char jwt_auth_alg[16]; - const char *jwt_issuer; - const char *jwt_audience; - lws_dll2_owner_t web_to_srv_owner; lws_dll2_owner_t subs_owner; sqlite3 *pdb; - sqlite3 *pdb_auth; struct lws_ss_handle *h_ss_websrv; /* client */ diff --git a/src/web/w-ws-browser.c b/src/web/w-ws-browser.c index 570679a..2a8b30e 100644 --- a/src/web/w-ws-browser.c +++ b/src/web/w-ws-browser.c @@ -117,9 +117,6 @@ enum { typedef struct sai_browse_taskreply { const sai_event_t *event; const sai_task_t *task; - char auth_user[33]; - int authorized; - int auth_secs; } sai_browse_taskreply_t; static lws_struct_map_t lsm_taskreply[] = { @@ -127,9 +124,6 @@ static lws_struct_map_t lsm_taskreply[] = { lsm_event, "e"), LSM_CHILD_PTR (sai_browse_taskreply_t, task, sai_task_t, NULL, lsm_task, "t"), - LSM_CARRAY (sai_browse_taskreply_t, auth_user, "auth_user"), - LSM_UNSIGNED (sai_browse_taskreply_t, authorized, "authorized"), - LSM_UNSIGNED (sai_browse_taskreply_t, auth_secs, "auth_secs"), }; const lws_struct_map_t lsm_schema_json_map_taskreply[] = { @@ -190,18 +184,7 @@ sai_sql3_get_uint64_cb(void *user, int cols, char **values, char **name) return 0; } -/* 1 == authorized */ -static int -sais_conn_auth(struct pss *pss) -{ - if (!pss->authorized) - return 0; - if (pss->expiry_unix_time < (unsigned long)lws_now_secs()) - return 0; - - return 1; -} /* * Ask for writeable cb on all browser connections subscribed to a particular @@ -344,8 +327,6 @@ saiw_pss_schedule_taskinfo(struct pss *pss, const char *task_uuid, int logsub) lws_sql_purify(esc2, pss->specific_project, sizeof(esc2)); m += lws_snprintf(qu + m, sizeof(qu) - (unsigned int)m, " and repo_name='%s'", esc2); } - if (!pss->authorized) - m += lws_snprintf(qu + m, sizeof(qu) - (unsigned int)m, " and sec=0"); if (pss->specific_ref[0] && pss->specificity != SAIM_SPECIFIC_TASK) { lws_sql_purify(esc2, pss->specific_ref, sizeof(esc2)); @@ -391,9 +372,6 @@ saiw_pss_schedule_taskinfo(struct pss *pss, const char *task_uuid, int logsub) one_task->state == SAIES_CANCELLED) && (lws_now_secs() - (one_task->started + (one_task->duration / 1000000)) < 24 * 3600); - task_reply.auth_secs = (int)(pss->authorized ? pss->expiry_unix_time - lws_now_secs() : 0); - task_reply.authorized = pss->authorized; - lws_strncpy(task_reply.auth_user, pss->auth_user, sizeof(task_reply.auth_user)); js = lws_struct_json_serialize_create(lsm_schema_json_map_taskreply, LWS_ARRAY_SIZE(lsm_schema_json_map_taskreply), @@ -656,9 +634,6 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, case SAIM_WS_BROWSER_RX_TASKRESET: - if (!sais_conn_auth(pss)) - goto auth_error; - /* * User is asking us to reset / rebuild this task */ @@ -667,11 +642,6 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, break; case SAIM_WS_BROWSER_RX_STAY: - if (!sais_conn_auth(pss)) { - lwsl_err("%s: stay didn't like auth\n", __func__); - goto auth_error; - } - lwsl_notice("%s: web: received stay req\n", __func__); /* @@ -680,10 +650,6 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, break; case SAIM_WS_BROWSER_RX_PCON_CONTROL: - if (!sais_conn_auth(pss)) { - lwsl_err("%s: pcon control didn't like auth\n", __func__); - goto auth_error; - } lwsl_warn("%s: web: received pcon control req (len %d)\n", __func__, (int)bl); /* Forward to sai-server via websrv link */ @@ -697,8 +663,6 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, goto ok; case SAIM_WS_BROWSER_RX_TASKREBUILDLASTSTEP: - if (!sais_conn_auth(pss)) - goto auth_error; /* * User is asking us to rebuild the last step of this task @@ -709,9 +673,6 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, case SAIM_WS_BROWSER_RX_EVENTRESET: - if (!sais_conn_auth(pss)) - goto auth_error; - /* * User is asking us to reset / rebuild every task in the event */ @@ -727,9 +688,6 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, * User is asking us to delete the whole event */ - if (!sais_conn_auth(pss)) - goto auth_error; - ei = (sai_browse_rx_evinfo_t *)a.dest; lwsl_notice("%s: received request to delete event %s\n", @@ -739,9 +697,6 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, case SAIM_WS_BROWSER_RX_TASKCANCEL: - if (!sais_conn_auth(pss)) - goto auth_error; - /* * Browser is informing us of task's STOP button clicked, we * need to inform any builder that might be building it @@ -755,18 +710,12 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, goto ok; case SAIM_WS_BROWSER_RX_REBUILD: - if (!sais_conn_auth(pss)) - goto auth_error; - /* * User is asking us to rebuild a builder */ break; case SAIM_WS_BROWSER_RX_PLATRESET: - if (!sais_conn_auth(pss)) - goto auth_error; - /* * User is asking us to reset / rebuild a whole platform */ @@ -784,25 +733,11 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, ok: ret = 0; +soft_error: bail: lwsac_free(&a.ac); return ret; - -auth_error: - { - uint8_t buf[LWS_PRE + 128]; - int n; - - n = lws_snprintf((char *)buf + LWS_PRE, sizeof(buf) - LWS_PRE, - "{\"schema\":\"com.warmcat.sai.unauthorized\"}"); - lws_write(pss->wsi, buf + LWS_PRE, (size_t)n, LWS_WRITE_TEXT); - } - -soft_error: - lwsac_free(&a.ac); - - return 0; } static void @@ -933,7 +868,7 @@ saiw_browser_queue_overview(struct vhd *vhd, struct pss *pss) { char buf[4096 + LWS_PRE], *start = buf + LWS_PRE, *p = start, *end = buf + sizeof(buf); - char esc[256], esc1[33], filt[128], subsequent; + char esc[256], filt[128], subsequent; struct lwsac *task_ac = NULL, *ac = NULL; lws_dll2_owner_t task_owner, owner; unsigned int task_index = 0; @@ -941,7 +876,7 @@ saiw_browser_queue_overview(struct vhd *vhd, struct pss *pss) sqlite3 *pdb = NULL; lws_dll2_t *walk; sai_task_t *t; - int n, iu; + int n; size_t w; filt[0] = '\0'; @@ -953,8 +888,6 @@ saiw_browser_queue_overview(struct vhd *vhd, struct pss *pss) lws_snprintf(filt, sizeof(filt), " and repo_name=\"%s\"", esc); n = -1; } - if (!pss->authorized) - lws_snprintf(filt + strlen(filt), sizeof(filt) - strlen(filt), " and sec=0"); pss->wants_event_updates = 1; if (lws_struct_sq3_deserialize(vhd->pdb, filt[0] ? filt : NULL, @@ -974,13 +907,8 @@ saiw_browser_queue_overview(struct vhd *vhd, struct pss *pss) "{\"schema\":\"sai.warmcat.com.overview\"," " \"api_version\":%u," " \"alang\":\"%s\"," - " \"authorized\": %d," - " \"auth_secs\": %ld," - " \"auth_user\": \"%s\"," "\"overview\":[", SAIW_API_VERSION, - lws_json_purify(esc, pss->alang, sizeof(esc) - 1, &iu), - pss->authorized, pss->authorized ? pss->expiry_unix_time - lws_now_secs() : 0, - lws_json_purify(esc1, pss->auth_user, sizeof(esc1) - 1, &iu) + lws_json_purify(esc, pss->alang, sizeof(esc) - 1, NULL) ); saiw_ws_browser_queue_REQUIRES_LWS_PRE(pss, start, @@ -990,13 +918,7 @@ saiw_browser_queue_overview(struct vhd *vhd, struct pss *pss) /* - * "authorized" here is used to decide whether to render the - * additional controls clientside. The events the controls - * cause if used are separately checked for coming from an - * authorized pss when they are received. - * - * If you're not authorized, you're only going to see events - * that have sec=0. Otherwise you can see all events. + * Walk through events */ if (pss->specificity) @@ -1260,22 +1182,16 @@ saiw_browser_broadcast_queue_builders(struct vhd *vhd, struct pss *pss) char buf[4096 + LWS_PRE], *start = buf + LWS_PRE, *p = start, *end = buf + sizeof(buf); lws_struct_serialize_t *js; - char esc[256], esc1[33]; + char esc[256]; lws_dll2_t *walk = NULL; char fi = 1, subsequent; size_t w; - int iu; p += lws_snprintf((char *)p, lws_ptr_diff_size_t(end, p), "{\"schema\":\"com.warmcat.sai.builders\"," " \"alang\":\"%s\"," - " \"authorized\":%d," - " \"auth_secs\":%ld," - " \"auth_user\": \"%s\"," " \"builders\":[", - lws_sql_purify(esc, pss->alang, sizeof(esc) - 1), - pss->authorized, pss->authorized ? pss->expiry_unix_time - lws_now_secs() : 0, - lws_json_purify(esc1, pss->auth_user, sizeof(esc1) - 1, &iu)); + lws_sql_purify(esc, pss->alang, sizeof(esc) - 1)); if (vhd && vhd->builders) walk = lws_dll2_get_head(&vhd->builders_owner);
Page fetched 0s ago, creation time: 8ms (vhost etag hits: 0%, cache hits: 0%)