added auth method

This commit is contained in:
ston1th 2021-02-10 23:54:31 +01:00
commit a735b9cc5e
8 changed files with 270 additions and 12 deletions

113
pkg/api/v1/server/auth.go Normal file
View file

@ -0,0 +1,113 @@
package server
import (
"git.gitfish.de/ston1th/haproxy-lb/pkg/config"
"golang.org/x/crypto/bcrypt"
weakrand "math/rand"
"net/http"
"sync"
"time"
)
var cacheSize = 100
func init() {
weakrand.Seed(time.Now().UnixNano())
}
type cache struct {
cache map[string]bool
mtx sync.Mutex
}
func newCache() *cache {
return &cache{
cache: make(map[string]bool),
}
}
func (c *cache) get(key string) (bool, bool) {
c.mtx.Lock()
defer c.mtx.Unlock()
v, ok := c.cache[key]
return v, ok
}
func (c *cache) set(key string, value bool) {
c.mtx.Lock()
defer c.mtx.Unlock()
c.makeRoom()
c.cache[key] = value
}
func (c *cache) makeRoom() {
if len(c.cache) < cacheSize {
return
}
numToDelete := len(c.cache) / 10
if numToDelete < 1 {
numToDelete = 1
}
for deleted := 0; deleted <= numToDelete; deleted++ {
rnd := weakrand.Intn(len(c.cache))
i := 0
for key := range c.cache {
if i == rnd {
delete(c.cache, key)
break
}
i++
}
}
}
type auth struct {
users map[string]*creds
cache *cache
// bcryptMtx is there to ensure that bcrypt.CompareHashAndPassword is run
// only once in parallel as this is CPU intensive.
bcryptMtx sync.Mutex
}
func (a *auth) Auth(user, pass, path string) bool {
creds, valid := a.users[user]
hash := creds.Hash
if !valid {
// The user is not found. Use a fixed password hash to
// prevent user enumeration by timing requests.
// This is a bcrypt-hashed version of "fakepassword".
hash = "$2y$10$QOauhQNbBCuQDKes6eFzPeMqBSjb7Mr5DUmpZ/VcEd00UAV/LDeSi"
}
cacheKey := hex.EncodeToString(append(append([]byte(user), []byte(hash)...), []byte(pass)...))
authOk, ok := a.cache.get(cacheKey)
if !ok {
// This user, hashedPassword, password is not cached.
a.bcryptMtx.Lock()
err := bcrypt.CompareHashAndPassword([]byte(hash), []byte(pass))
a.bcryptMtx.Unlock()
authOk = err == nil
u.cache.set(cacheKey, authOk)
}
return authOk && valid && strings.HasPrefix(path, creds.Prefix)
}
type creds struct {
Hash string
Prefix string
}
func newAuth(conf config.Config) (a *auth) {
a = &auth{
users: make(map[string]creds),
cache: newCache(),
}
for _, u := range conf.BasicAuth {
a.users[u.User] = &creds{u.Hash, u.Prefix}
}
return
}

View file

@ -1,6 +1,7 @@
package server
import (
//"golang.org/x/crypto/bcrypt"
"net/http"
)
@ -15,10 +16,14 @@ func (nf *notFoundHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
func authHandler(h ctxHandler) ctxHandler {
return func(ctx *Context) {
// TODO
// test:123456
// test:$2b$10$zNfGTAQ94vifj2wtGsv1W.yZRe4/rDBzQixpB6FbrTed4BnHuNqBS
//bcrypt.CompareHashAndPassword(hash, pw)
h(ctx)
}
}
func healthzHandler(ctx *Context) {
// TODO maybe report etcd/raft stats
ctx.OK()
}

View file

@ -2,10 +2,10 @@ package server
import (
"git.giftfish.de/ston1th/haproxy-lb/pkg/api"
"git.giftfish.de/ston1th/haproxy-lb/pkg/api/v1/schema"
schemav1 "git.giftfish.de/ston1th/haproxy-lb/pkg/api/v1/schema"
)
const version = "/" + schema.Version
const v1 = "/" + schemav1.Version
var routes = []api.Route{
{
@ -14,8 +14,13 @@ var routes = []api.Route{
[]string{"GET"},
},
{
version + "/alloc",
authHandler(allocHandler),
[]string{"POST"},
v1 + "/lb",
authHandler(lbListHandler),
[]string{"GET"},
},
{
v1 + "/lb/{cluster:[a-zA-Z0-9-]+}/{name:[a-zA-Z0-9-]+$}",
authHandler(lbHandler),
[]string{"GET", "POST", "DELETE"},
},
}

View file

@ -34,7 +34,7 @@ type Server struct {
func NewServer(log logr.Logger) *Server {
s := &Server{
mux: mux.NewRouter(),
log: log,
log: log.WithName("api"),
stop: make(chan struct{}),
stopKeyReset: make(chan struct{}),