diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Trim the lua headers and fix the Scintillua notes
Diffstat (limited to '')
-rw-r--r--custom/extensions/auth-inline.lua33
1 file changed, 3 insertions, 30 deletions
diff --git a/custom/extensions/auth-inline.lua b/custom/extensions/auth-inline.lua
index 0cd9da9..faa3bdc 100644
--- a/custom/extensions/auth-inline.lua
+++ b/custom/extensions/auth-inline.lua
@@ -2,8 +2,8 @@
-- session cookie.
--
-- This is the INLINE variant. The user accounts and the per-repository access
--- lists are written directly in this script, in the two tables in the
--- CONFIGURATION block below. Edit them here and reload. This suits a small
+-- lists are written directly in this script, in the two tables among the
+-- configuration values below. Edit them here and reload. This suits a small
-- fixed set of users that rarely changes.
--
-- The companion auth-file.lua behaves identically but reads its accounts and
@@ -71,11 +71,8 @@ local unistd = require("posix.unistd")
local rand = require("openssl.rand")
local hmac = require("openssl.hmac")
---
--- ========================= CONFIGURATION =========================
--- Edit the values in this block. Nothing below it needs changing for
+-- Configuration, edit these values. Nothing below them needs changing for
-- ordinary use.
---
-- Protected repositories and the users allowed into each. A repository listed
-- here is protected. One not listed is public. Keys and user names are matched
@@ -116,10 +113,6 @@ local cookie_path = "/"
-- HTTPS note in the header.
local cookie_insecure = false
---
--- =================================================================
---
-
-- A throwaway hash of the documented shape, used only to spend the same work
-- on a missing account as on a present one, so a failed login does not reveal
-- by timing whether the username exists.
@@ -128,12 +121,8 @@ local dummy_hash = "$6$rounds=300000$0000000000000000$"
-- Module state shared across the open, write and close calls of one request.
local action, http, cgit, post
---
---
-- Account and access-list storage. This is the ONLY part that differs from
-- auth-file.lua. Swap these two functions to change where accounts live.
---
---
-- Fold the configured tables to lowercased user names once, so lookups match
-- case-insensitively the same way auth-file.lua does. Repository names keep
@@ -170,11 +159,7 @@ function repo_userset(repo)
return protected_repos[repo]
end
---
---
-- Utility functions based on keplerproject/wsapi.
---
---
function url_decode(str)
if not str then
@@ -232,11 +217,7 @@ function tohex(b)
return x
end
---
---
-- Cookie construction and validation helpers.
---
---
local secret = nil
@@ -413,11 +394,7 @@ function not_found()
html("Cache-Control: no-cache, no-store\n\n")
end
---
---
-- Authentication actions. Identical to auth-inline.lua from here down.
---
---
-- Sets HTTP cookie headers based on post and sets up redirection.
function authenticate_post()
@@ -491,12 +468,8 @@ function body()
return 0
end
---
---
-- Wrapper around the filter API, exposing the http, cgit and post tables to
-- the functions above.
---
---
local actions = {}
actions["authenticate-post"] = authenticate_post