diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Trim the lua headers and fix the Scintillua notes
Diffstat (limited to 'custom/extensions/auth-file.lua')
-rw-r--r--custom/extensions/auth-file.lua31
1 file changed, 2 insertions, 29 deletions
diff --git a/custom/extensions/auth-file.lua b/custom/extensions/auth-file.lua
index 9c9c2ee..d003092 100644
--- a/custom/extensions/auth-file.lua
+++ b/custom/extensions/auth-file.lua
@@ -3,7 +3,7 @@
--
-- This is the FILE-BACKED variant. The user accounts, the groups, and the
-- per-repository access lists are read from files on disk, whose paths are set
--- in the CONFIGURATION block below. Edit those files without touching this
+-- among the configuration values below. Edit those files without touching this
-- script. This suits larger or externally managed user sets.
--
-- The companion auth-inline.lua behaves identically but keeps its accounts and
@@ -71,11 +71,8 @@ local unistd = require("posix.unistd")
local rand = require("openssl.rand")
local hmac = require("openssl.hmac")
---
--- ========================= CONFIGURATION =========================
--- Edit the values in this block. Nothing below it needs changing for
+-- Configuration, edit these values. Nothing below them needs changing for
-- ordinary use.
---
-- Accounts, one per line, as username:hash. Generate a hash with
-- mkpasswd -m sha-512 -R 300000
@@ -110,10 +107,6 @@ local cookie_path = "/"
-- HTTPS note in the header.
local cookie_insecure = false
---
--- =================================================================
---
-
-- A throwaway hash of the documented shape, used only to spend the same work
-- on a missing account as on a present one, so a failed login does not reveal
-- by timing whether the username exists.
@@ -122,12 +115,8 @@ local dummy_hash = "$6$rounds=300000$0000000000000000$"
-- Module state shared across the open, write and close calls of one request.
local action, http, cgit, post
---
---
-- Account and access-list storage. This is the ONLY part that differs from
-- auth-inline.lua. Swap these two functions to change where accounts live.
---
---
local function trim(s)
return (string.gsub(s, "^%s*(.-)%s*$", "%1"))
@@ -203,11 +192,7 @@ function repo_userset(repo)
return users
end
---
---
-- Utility functions based on keplerproject/wsapi.
---
---
function url_decode(str)
if not str then
@@ -265,11 +250,7 @@ function tohex(b)
return x
end
---
---
-- Cookie construction and validation helpers.
---
---
local secret = nil
@@ -446,11 +427,7 @@ function not_found()
html("Cache-Control: no-cache, no-store\n\n")
end
---
---
-- Authentication actions. Identical to auth-inline.lua from here down.
---
---
-- Sets HTTP cookie headers based on post and sets up redirection.
function authenticate_post()
@@ -524,12 +501,8 @@ function body()
return 0
end
---
---
-- Wrapper around the filter API, exposing the http, cgit and post tables to
-- the functions above.
---
---
local actions = {}
actions["authenticate-post"] = authenticate_post