diff options
| author | KunoiSayami <[email protected]> | 2026-02-09 20:59:33 +0800 |
|---|---|---|
| committer | KunoiSayami <[email protected]> | 2026-02-09 20:59:33 +0800 |
| commit | 735612ccfba150978d174fcc7d95b2ea3013ab9e (patch) | |
| tree | 24eff0b3bdbb4cd70246b90cf3eeec86acb62762 /src/datastructures.rs | |
| parent | 2d3d384f2c32562df304d027c30e6986bd94c157 (diff) | |
refactor: Remove pam authentication method
Signed-off-by: KunoiSayami <[email protected]>
Diffstat (limited to 'src/datastructures.rs')
| -rw-r--r-- | src/datastructures.rs | 112 |
1 files changed, 0 insertions, 112 deletions
diff --git a/src/datastructures.rs b/src/datastructures.rs index 1494257..c312f8f 100644 --- a/src/datastructures.rs +++ b/src/datastructures.rs @@ -21,14 +21,10 @@ use argon2::{ password_hash::{PasswordHash, PasswordHasher, PasswordVerifier, SaltString, rand_core::OsRng}, }; use base64::Engine; -#[cfg(feature = "pam")] -pub use ds_pam::*; use log::error; use rand::RngExt; use serde::{Deserialize, Serialize}; use sqlx::ConnectOptions; -#[cfg(feature = "pam")] -use std::borrow::BorrowMut; use std::borrow::Cow; use std::fmt::{Debug, Formatter}; use std::fs::read_to_string; @@ -77,71 +73,12 @@ pub(crate) trait TestSuite { fn generate_test_config() -> Self; } -#[cfg(feature = "pam")] -pub mod ds_pam { - - #[derive(Debug, Clone)] - pub struct PAMConfig { - use_pam: bool, - provider: String, - } - - impl From<&str> for PAMConfig { - fn from(s: &str) -> Self { - let use_pam = !s.to_lowercase().eq("false"); - Self { - use_pam, - provider: s.to_string(), - } - } - } - - impl PAMConfig { - pub fn get_enabled(&self) -> bool { - self.use_pam - } - - pub fn get_provider(&self) -> &String { - &self.provider - } - } - - impl Default for PAMConfig { - fn default() -> Self { - Self { - use_pam: false, - provider: "system-auth".to_string(), - } - } - } - - #[derive(Debug, Clone)] - pub struct PAMAuthorizer { - provider: String, - } - - impl PAMAuthorizer { - pub fn provider(&self) -> &str { - &self.provider - } - } - - impl From<&PAMConfig> for PAMAuthorizer { - fn from(cfg: &PAMConfig) -> Self { - Self { - provider: cfg.get_provider().clone(), - } - } - } -} #[derive(Debug, Clone)] pub struct Config { pub cookie_ttl: u64, database: String, pub bypass_root: bool, - #[cfg(feature = "pam")] - pam_config: PAMConfig, pub(crate) test: bool, protect_config: ProtectSettings, } @@ -152,8 +89,6 @@ impl Default for Config { cookie_ttl: DEFAULT_COOKIE_TTL, database: DEFAULT_DATABASE_LOCATION.to_string(), bypass_root: false, - #[cfg(feature = "pam")] - pam_config: Default::default(), test: false, protect_config: Default::default(), } @@ -173,8 +108,6 @@ impl Config { let mut bypass_root: bool = false; let mut protect_enabled: bool = true; let mut protect_white_list_mode: bool = true; - #[cfg(feature = "pam")] - let mut use_pam: &str = "false"; //let mut skip_user_access_check: bool = false; for line in file.lines() { @@ -194,8 +127,6 @@ impl Config { "cookie-ttl" => cookie_ttl = value.parse().unwrap_or(DEFAULT_COOKIE_TTL), "database" => database = value, "bypass-root" => bypass_root = value.to_lowercase().eq("true"), - #[cfg(feature = "pam")] - "use-pam" => use_pam = value, "protect" => match value.to_lowercase().as_str() { "full" => { protect_enabled = true; @@ -219,8 +150,6 @@ impl Config { database: database.to_string(), bypass_root, - #[cfg(feature = "pam")] - pam_config: PAMConfig::from(use_pam), test: false, protect_config: ProtectSettings::from_path( protect_enabled, @@ -307,11 +236,6 @@ impl Config { self.protect_config.query_is_all_protected() } - #[cfg(feature = "pam")] - fn get_pam_config(&self) -> &PAMConfig { - &self.pam_config - } - pub fn get_test_status(&self) -> bool { self.test } @@ -323,8 +247,6 @@ impl TestSuite for Config { database: "test/tmp.db".to_string(), bypass_root: false, cookie_ttl: DEFAULT_COOKIE_TTL, - #[cfg(feature = "pam")] - pam_config: Default::default(), test: true, protect_config: ProtectSettings::generate_test_config(), } @@ -651,8 +573,6 @@ impl std::fmt::Display for Cookie { #[derive(Debug, Clone)] pub enum AuthorizerType { - #[cfg(feature = "pam")] - PAM, Password, } @@ -662,8 +582,6 @@ impl std::fmt::Display for AuthorizerType { f, "{}", match self { - #[cfg(feature = "pam")] - AuthorizerType::PAM => "PAM", AuthorizerType::Password => "PASSWORD", } ) @@ -698,7 +616,6 @@ pub struct WrapConfigure { } impl From<Config> for WrapConfigure { - #[cfg(not(feature = "pam"))] fn from(cfg: Config) -> Self { let authorizer = Box::new(SQLAuthorizer::from(&cfg)); Self { @@ -706,37 +623,8 @@ impl From<Config> for WrapConfigure { authorizer, } } - #[cfg(feature = "pam")] - fn from(cfg: Config) -> Self { - let authorizer: Box<dyn Authorizer> = if cfg.get_pam_config().get_enabled() { - Box::new(PAMAuthorizer::from(cfg.get_pam_config())) - } else { - Box::new(SQLAuthorizer::from(&cfg)) - }; - Self { - config: cfg, - authorizer, - } - } } -#[cfg(feature = "pam")] -#[async_trait::async_trait] -impl Authorizer for PAMAuthorizer { - fn method(&self) -> AuthorizerType { - AuthorizerType::PAM - } - - async fn verify(&self, user: &str, password: &str) -> Result<bool> { - let service = self.provider(); - - let mut auth = pam::Client::with_password(service).unwrap(); - auth.conversation_mut() - .borrow_mut() - .set_credentials(user, password); - Ok(auth.authenticate().is_ok() && auth.open_session().is_ok()) - } -} #[derive(Debug, Clone)] struct SQLAuthorizer { |
