diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Trim the lua headers and fix the Scintillua notes
Diffstat (limited to 'custom/extensions/auth-inline.lua')
| -rw-r--r-- | custom/extensions/auth-inline.lua | 33 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 3 insertions, 30 deletions
diff --git a/custom/extensions/auth-inline.lua b/custom/extensions/auth-inline.lua index 0cd9da9..faa3bdc 100644 --- a/custom/extensions/auth-inline.lua +++ b/custom/extensions/auth-inline.lua @@ -2,8 +2,8 @@ -- session cookie. -- -- This is the INLINE variant. The user accounts and the per-repository access --- lists are written directly in this script, in the two tables in the --- CONFIGURATION block below. Edit them here and reload. This suits a small +-- lists are written directly in this script, in the two tables among the +-- configuration values below. Edit them here and reload. This suits a small -- fixed set of users that rarely changes. -- -- The companion auth-file.lua behaves identically but reads its accounts and @@ -71,11 +71,8 @@ local unistd = require("posix.unistd") local rand = require("openssl.rand") local hmac = require("openssl.hmac") --- --- ========================= CONFIGURATION ========================= --- Edit the values in this block. Nothing below it needs changing for +-- Configuration, edit these values. Nothing below them needs changing for -- ordinary use. --- -- Protected repositories and the users allowed into each. A repository listed -- here is protected. One not listed is public. Keys and user names are matched @@ -116,10 +113,6 @@ local cookie_path = "/" -- HTTPS note in the header. local cookie_insecure = false --- --- ================================================================= --- - -- A throwaway hash of the documented shape, used only to spend the same work -- on a missing account as on a present one, so a failed login does not reveal -- by timing whether the username exists. @@ -128,12 +121,8 @@ local dummy_hash = "$6$rounds=300000$0000000000000000$" -- Module state shared across the open, write and close calls of one request. local action, http, cgit, post --- --- -- Account and access-list storage. This is the ONLY part that differs from -- auth-file.lua. Swap these two functions to change where accounts live. --- --- -- Fold the configured tables to lowercased user names once, so lookups match -- case-insensitively the same way auth-file.lua does. Repository names keep @@ -170,11 +159,7 @@ function repo_userset(repo) return protected_repos[repo] end --- --- -- Utility functions based on keplerproject/wsapi. --- --- function url_decode(str) if not str then @@ -232,11 +217,7 @@ function tohex(b) return x end --- --- -- Cookie construction and validation helpers. --- --- local secret = nil @@ -413,11 +394,7 @@ function not_found() html("Cache-Control: no-cache, no-store\n\n") end --- --- -- Authentication actions. Identical to auth-inline.lua from here down. --- --- -- Sets HTTP cookie headers based on post and sets up redirection. function authenticate_post() @@ -491,12 +468,8 @@ function body() return 0 end --- --- -- Wrapper around the filter API, exposing the http, cgit and post tables to -- the functions above. --- --- local actions = {} actions["authenticate-post"] = authenticate_post |
