diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Clean up the whole tree
Diffstat (limited to '')
-rw-r--r--custom/extensions/auth-inline.lua33
1 file changed, 11 insertions, 22 deletions
diff --git a/custom/extensions/auth-inline.lua b/custom/extensions/auth-inline.lua
index e26fa57..0ae2cb8 100644
--- a/custom/extensions/auth-inline.lua
+++ b/custom/extensions/auth-inline.lua
@@ -203,21 +203,18 @@ function get_secret()
-- created readable by anyone but the user cgit runs as, and
-- the old mask goes back on every way out.
local old_umask = sysstat.umask(63)
- local temporary_filename = secret_filename .. ".tmp." ..
- tohex(rand.bytes(16))
+ local temporary_filename = secret_filename .. ".tmp." .. tohex(rand.bytes(16))
local temporary_file = io.open(temporary_filename, "w")
if temporary_file == nil then
sysstat.umask(old_umask)
- error("cgit auth: cannot create secret file " ..
- secret_filename)
+ error("cgit auth: cannot create secret file " .. secret_filename)
end
local wrote = temporary_file:write(tohex(rand.bytes(32)))
local closed = temporary_file:close()
if not wrote or not closed then
os.remove(temporary_filename)
sysstat.umask(old_umask)
- error("cgit auth: failed writing secret file " ..
- secret_filename)
+ error("cgit auth: failed writing secret file " .. secret_filename)
end
-- The link is meant to fail when another worker won the race,
-- which leaves that worker's secret in place rather than
@@ -234,8 +231,7 @@ function get_secret()
secret_file:close()
if secret == nil or secret:len() ~= 64 then
secret = nil
- error("cgit auth: secret file " .. secret_filename ..
- " is malformed, expected 64 hex characters")
+ error("cgit auth: secret file " .. secret_filename .. " is malformed, expected 64 hex characters")
end
return secret
end
@@ -295,10 +291,8 @@ function validate_value(expected_field, cookie)
return nil
end
- local payload = field .. "|" .. value .. "|" ..
- tostring(expiration) .. "|" .. salt
- local expected_signature =
- tohex(hmac.new(get_secret(), "sha256"):final(payload))
+ local payload = field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt
+ local expected_signature = tohex(hmac.new(get_secret(), "sha256"):final(payload))
if not constant_equals(signature, expected_signature) then
return nil
end
@@ -331,8 +325,7 @@ function secure_value(field, value, expiration)
local salt = tohex(rand.bytes(16))
value = url_encode(value)
field = url_encode(field)
- local payload = field .. "|" .. value .. "|" ..
- tostring(expiration) .. "|" .. salt
+ local payload = field .. "|" .. value .. "|" .. tostring(expiration) .. "|" .. salt
local signature = tohex(hmac.new(get_secret(), "sha256"):final(payload))
return payload .. "|" .. signature
end
@@ -367,11 +360,9 @@ function set_cookie(cookie, value)
if value == "" then
attributes = attributes .. "; Max-Age=0"
elseif session_seconds > 0 then
- attributes = attributes ..
- "; Max-Age=" .. tostring(session_seconds)
+ attributes = attributes .. "; Max-Age=" .. tostring(session_seconds)
end
- html("Set-Cookie: " .. cookie .. "=" ..
- strip_controls(value) .. attributes .. "\n")
+ html("Set-Cookie: " .. cookie .. "=" .. strip_controls(value) .. attributes .. "\n")
end
function redirect_to(url)
@@ -415,8 +406,7 @@ function authenticate_post()
end
if ok then
- set_cookie(cookie_name, secure_value("username", username,
- os.time() + session_seconds))
+ set_cookie(cookie_name, secure_value("username", username, os.time() + session_seconds))
else
set_cookie(cookie_name, "")
end
@@ -434,8 +424,7 @@ function authenticate_cookie()
return 1
end
- local username = validate_value("username",
- get_cookie(http["cookie"], cookie_name))
+ local username = validate_value("username", get_cookie(http["cookie"], cookie_name))
if username == nil or not accepted_users[username:lower()] then
return 0
end