mirror of
https://github.com/Buriburizaem0n/nezha_domains.git
synced 2026-09-22 03:00:12 +00:00
fix(auth): accept hyphenated agent metadata (#1197)
This commit is contained in:
+11
-8
@@ -39,10 +39,7 @@ func (a *authHandler) check(ctx context.Context) (uint64, error) {
|
|||||||
return 0, status.Errorf(codes.Unauthenticated, "获取 metaData 失败")
|
return 0, status.Errorf(codes.Unauthenticated, "获取 metaData 失败")
|
||||||
}
|
}
|
||||||
|
|
||||||
var clientSecret string
|
clientSecret := firstMetadataValue(md, "client-secret", "client_secret")
|
||||||
if value, ok := md["client_secret"]; ok {
|
|
||||||
clientSecret = strings.TrimSpace(value[0])
|
|
||||||
}
|
|
||||||
|
|
||||||
if clientSecret == "" {
|
if clientSecret == "" {
|
||||||
return 0, status.Error(codes.Unauthenticated, "客户端认证失败")
|
return 0, status.Error(codes.Unauthenticated, "客户端认证失败")
|
||||||
@@ -50,10 +47,7 @@ func (a *authHandler) check(ctx context.Context) (uint64, error) {
|
|||||||
|
|
||||||
ip, _ := ctx.Value(model.CtxKeyRealIP{}).(string)
|
ip, _ := ctx.Value(model.CtxKeyRealIP{}).(string)
|
||||||
|
|
||||||
var clientUUID string
|
clientUUID := firstMetadataValue(md, "client-uuid", "client_uuid")
|
||||||
if value, ok := md["client_uuid"]; ok {
|
|
||||||
clientUUID = value[0]
|
|
||||||
}
|
|
||||||
|
|
||||||
if _, err := uuid.ParseUUID(clientUUID); err != nil {
|
if _, err := uuid.ParseUUID(clientUUID); err != nil {
|
||||||
// Keep this counter on the same trigger surface as the
|
// Keep this counter on the same trigger surface as the
|
||||||
@@ -183,6 +177,15 @@ func (a *authHandler) check(ctx context.Context) (uint64, error) {
|
|||||||
return clientID, nil
|
return clientID, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func firstMetadataValue(md metadata.MD, keys ...string) string {
|
||||||
|
for _, key := range keys {
|
||||||
|
if value, ok := md[key]; ok && len(value) > 0 {
|
||||||
|
return strings.TrimSpace(value[0])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
// authorizeAgentForUUID resolves a client UUID to the dashboard's internal
|
// authorizeAgentForUUID resolves a client UUID to the dashboard's internal
|
||||||
// server ID, ensuring the resolved server is actually owned by the agent
|
// server ID, ensuring the resolved server is actually owned by the agent
|
||||||
// secret's owner. Previously Check returned the resolved server ID without
|
// secret's owner. Previously Check returned the resolved server ID without
|
||||||
|
|||||||
@@ -25,6 +25,14 @@ func authCheckWithSecret(secret, uuid string) (uint64, error) {
|
|||||||
return (&authHandler{}).Check(ctx)
|
return (&authHandler{}).Check(ctx)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func authCheckWithHyphenatedSecret(secret, uuid string) (uint64, error) {
|
||||||
|
ctx := metadata.NewIncomingContext(context.Background(), metadata.Pairs(
|
||||||
|
"client-secret", secret,
|
||||||
|
"client-uuid", uuid,
|
||||||
|
))
|
||||||
|
return (&authHandler{}).Check(ctx)
|
||||||
|
}
|
||||||
|
|
||||||
// authHandshakeUUID is RFC4122-shaped so it survives the uuid.ParseUUID gate
|
// authHandshakeUUID is RFC4122-shaped so it survives the uuid.ParseUUID gate
|
||||||
// at the top of check(); setupAuthAgentFixture's "uuid-alice" / "uuid-bob"
|
// at the top of check(); setupAuthAgentFixture's "uuid-alice" / "uuid-bob"
|
||||||
// only work for callers that bypass check() and exercise the inner helpers.
|
// only work for callers that bypass check() and exercise the inner helpers.
|
||||||
@@ -88,6 +96,18 @@ func setupAuthHandshakeFixture(t *testing.T) func() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestAuthCheckAcceptsHyphenatedMetadata(t *testing.T) {
|
||||||
|
defer setupAuthHandshakeFixture(t)()
|
||||||
|
|
||||||
|
cid, err := authCheckWithHyphenatedSecret("alice-global", authHandshakeUUID)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("hyphenated metadata must authenticate: %v", err)
|
||||||
|
}
|
||||||
|
if cid != 11 {
|
||||||
|
t.Fatalf("expected server ID 11, got %d", cid)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// setupAuthAgentFixture seeds an in-memory DB and ServerShared with two
|
// setupAuthAgentFixture seeds an in-memory DB and ServerShared with two
|
||||||
// servers belonging to different users so we can assert that a secret bound
|
// servers belonging to different users so we can assert that a secret bound
|
||||||
// to user A cannot resolve a server UUID owned by user B.
|
// to user A cannot resolve a server UUID owned by user B.
|
||||||
|
|||||||
Reference in New Issue
Block a user