initial public commit
This commit is contained in:
201
system/auth/basic-auth/htpasswd/LICENSE.txt
Normal file
201
system/auth/basic-auth/htpasswd/LICENSE.txt
Normal file
@ -0,0 +1,201 @@
|
||||
Apache License
|
||||
Version 2.0, January 2004
|
||||
http://www.apache.org/licenses/
|
||||
|
||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
||||
|
||||
1. Definitions.
|
||||
|
||||
"License" shall mean the terms and conditions for use, reproduction,
|
||||
and distribution as defined by Sections 1 through 9 of this document.
|
||||
|
||||
"Licensor" shall mean the copyright owner or entity authorized by
|
||||
the copyright owner that is granting the License.
|
||||
|
||||
"Legal Entity" shall mean the union of the acting entity and all
|
||||
other entities that control, are controlled by, or are under common
|
||||
control with that entity. For the purposes of this definition,
|
||||
"control" means (i) the power, direct or indirect, to cause the
|
||||
direction or management of such entity, whether by contract or
|
||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
||||
|
||||
"You" (or "Your") shall mean an individual or Legal Entity
|
||||
exercising permissions granted by this License.
|
||||
|
||||
"Source" form shall mean the preferred form for making modifications,
|
||||
including but not limited to software source code, documentation
|
||||
source, and configuration files.
|
||||
|
||||
"Object" form shall mean any form resulting from mechanical
|
||||
transformation or translation of a Source form, including but
|
||||
not limited to compiled object code, generated documentation,
|
||||
and conversions to other media types.
|
||||
|
||||
"Work" shall mean the work of authorship, whether in Source or
|
||||
Object form, made available under the License, as indicated by a
|
||||
copyright notice that is included in or attached to the work
|
||||
(an example is provided in the Appendix below).
|
||||
|
||||
"Derivative Works" shall mean any work, whether in Source or Object
|
||||
form, that is based on (or derived from) the Work and for which the
|
||||
editorial revisions, annotations, elaborations, or other modifications
|
||||
represent, as a whole, an original work of authorship. For the purposes
|
||||
of this License, Derivative Works shall not include works that remain
|
||||
separable from, or merely link (or bind by name) to the interfaces of,
|
||||
the Work and Derivative Works thereof.
|
||||
|
||||
"Contribution" shall mean any work of authorship, including
|
||||
the original version of the Work and any modifications or additions
|
||||
to that Work or Derivative Works thereof, that is intentionally
|
||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
||||
or by an individual or Legal Entity authorized to submit on behalf of
|
||||
the copyright owner. For the purposes of this definition, "submitted"
|
||||
means any form of electronic, verbal, or written communication sent
|
||||
to the Licensor or its representatives, including but not limited to
|
||||
communication on electronic mailing lists, source code control systems,
|
||||
and issue tracking systems that are managed by, or on behalf of, the
|
||||
Licensor for the purpose of discussing and improving the Work, but
|
||||
excluding communication that is conspicuously marked or otherwise
|
||||
designated in writing by the copyright owner as "Not a Contribution."
|
||||
|
||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
||||
on behalf of whom a Contribution has been received by Licensor and
|
||||
subsequently incorporated within the Work.
|
||||
|
||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
copyright license to reproduce, prepare Derivative Works of,
|
||||
publicly display, publicly perform, sublicense, and distribute the
|
||||
Work and such Derivative Works in Source or Object form.
|
||||
|
||||
3. Grant of Patent License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
(except as stated in this section) patent license to make, have made,
|
||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
||||
where such license applies only to those patent claims licensable
|
||||
by such Contributor that are necessarily infringed by their
|
||||
Contribution(s) alone or by combination of their Contribution(s)
|
||||
with the Work to which such Contribution(s) was submitted. If You
|
||||
institute patent litigation against any entity (including a
|
||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
||||
or a Contribution incorporated within the Work constitutes direct
|
||||
or contributory patent infringement, then any patent licenses
|
||||
granted to You under this License for that Work shall terminate
|
||||
as of the date such litigation is filed.
|
||||
|
||||
4. Redistribution. You may reproduce and distribute copies of the
|
||||
Work or Derivative Works thereof in any medium, with or without
|
||||
modifications, and in Source or Object form, provided that You
|
||||
meet the following conditions:
|
||||
|
||||
(a) You must give any other recipients of the Work or
|
||||
Derivative Works a copy of this License; and
|
||||
|
||||
(b) You must cause any modified files to carry prominent notices
|
||||
stating that You changed the files; and
|
||||
|
||||
(c) You must retain, in the Source form of any Derivative Works
|
||||
that You distribute, all copyright, patent, trademark, and
|
||||
attribution notices from the Source form of the Work,
|
||||
excluding those notices that do not pertain to any part of
|
||||
the Derivative Works; and
|
||||
|
||||
(d) If the Work includes a "NOTICE" text file as part of its
|
||||
distribution, then any Derivative Works that You distribute must
|
||||
include a readable copy of the attribution notices contained
|
||||
within such NOTICE file, excluding those notices that do not
|
||||
pertain to any part of the Derivative Works, in at least one
|
||||
of the following places: within a NOTICE text file distributed
|
||||
as part of the Derivative Works; within the Source form or
|
||||
documentation, if provided along with the Derivative Works; or,
|
||||
within a display generated by the Derivative Works, if and
|
||||
wherever such third-party notices normally appear. The contents
|
||||
of the NOTICE file are for informational purposes only and
|
||||
do not modify the License. You may add Your own attribution
|
||||
notices within Derivative Works that You distribute, alongside
|
||||
or as an addendum to the NOTICE text from the Work, provided
|
||||
that such additional attribution notices cannot be construed
|
||||
as modifying the License.
|
||||
|
||||
You may add Your own copyright statement to Your modifications and
|
||||
may provide additional or different license terms and conditions
|
||||
for use, reproduction, or distribution of Your modifications, or
|
||||
for any such Derivative Works as a whole, provided Your use,
|
||||
reproduction, and distribution of the Work otherwise complies with
|
||||
the conditions stated in this License.
|
||||
|
||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
||||
any Contribution intentionally submitted for inclusion in the Work
|
||||
by You to the Licensor shall be under the terms and conditions of
|
||||
this License, without any additional terms or conditions.
|
||||
Notwithstanding the above, nothing herein shall supersede or modify
|
||||
the terms of any separate license agreement you may have executed
|
||||
with Licensor regarding such Contributions.
|
||||
|
||||
6. Trademarks. This License does not grant permission to use the trade
|
||||
names, trademarks, service marks, or product names of the Licensor,
|
||||
except as required for reasonable and customary use in describing the
|
||||
origin of the Work and reproducing the content of the NOTICE file.
|
||||
|
||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
||||
agreed to in writing, Licensor provides the Work (and each
|
||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
||||
implied, including, without limitation, any warranties or conditions
|
||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
||||
appropriateness of using or redistributing the Work and assume any
|
||||
risks associated with Your exercise of permissions under this License.
|
||||
|
||||
8. Limitation of Liability. In no event and under no legal theory,
|
||||
whether in tort (including negligence), contract, or otherwise,
|
||||
unless required by applicable law (such as deliberate and grossly
|
||||
negligent acts) or agreed to in writing, shall any Contributor be
|
||||
liable to You for damages, including any direct, indirect, special,
|
||||
incidental, or consequential damages of any character arising as a
|
||||
result of this License or out of the use or inability to use the
|
||||
Work (including but not limited to damages for loss of goodwill,
|
||||
work stoppage, computer failure or malfunction, or any and all
|
||||
other commercial damages or losses), even if such Contributor
|
||||
has been advised of the possibility of such damages.
|
||||
|
||||
9. Accepting Warranty or Additional Liability. While redistributing
|
||||
the Work or Derivative Works thereof, You may choose to offer,
|
||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
||||
or other liability obligations and/or rights consistent with this
|
||||
License. However, in accepting such obligations, You may act only
|
||||
on Your own behalf and on Your sole responsibility, not on behalf
|
||||
of any other Contributor, and only if You agree to indemnify,
|
||||
defend, and hold each Contributor harmless for any liability
|
||||
incurred by, or claims asserted against, such Contributor by reason
|
||||
of your accepting any such warranty or additional liability.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
APPENDIX: How to apply the Apache License to your work.
|
||||
|
||||
To apply the Apache License to your work, attach the following
|
||||
boilerplate notice, with the fields enclosed by brackets "[]"
|
||||
replaced with your own identifying information. (Don't include
|
||||
the brackets!) The text should be enclosed in the appropriate
|
||||
comment syntax for the file format. We also recommend that a
|
||||
file or class name and description of purpose be included on the
|
||||
same "printed page" as the copyright notice for easier
|
||||
identification within third-party archives.
|
||||
|
||||
Copyright [yyyy] [name of copyright owner]
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
78
system/auth/basic-auth/htpasswd/README.md
Normal file
78
system/auth/basic-auth/htpasswd/README.md
Normal file
@ -0,0 +1,78 @@
|
||||
# SYSTEM :: ENTAXY :: BASIC AUTH :: HTPASSWD
|
||||
|
||||
Генерация htpasswd файла, сервис выдачи файла и checksum
|
||||
Работает с nginX шифрования MD5 и SHA-1
|
||||
|
||||
Описание данного подхода аутентификации:
|
||||
1. Nginx по умолчанию собран с модулем
|
||||
ngx_http_auth_basic_module, который проводит
|
||||
базовую аутентификацию через файлы htpasswd.
|
||||
2. Файл passwd периодически или по событиям
|
||||
синхронизируется между нодами при помощи скрипта синхронизации,
|
||||
который вызывает Rest сервис
|
||||
шины. (Rsync использовать нельзя, так как порты
|
||||
закрыты.)
|
||||
3. Аутентификация делается только на Nginx без доп.
|
||||
нагрузки на шину
|
||||
4. Файл хранится на сервере nginx и аутентификация
|
||||
будет работать всегда
|
||||
5. Подход рассчитан на балансировщики реализующие basic аутентификацию
|
||||
с использованием htpasswd
|
||||
|
||||
|
||||
## Сборка
|
||||
|
||||
Сборка осуществляется командой
|
||||
|
||||
```
|
||||
mvn clean install
|
||||
```
|
||||
|
||||
Файл конфигурации модуля ru.entaxy.esb.system.basic_auth.htpasswd.cfg хранится в SYSTEM :: ENTAXY :: Features
|
||||
|
||||
## Сервис Htpasswd
|
||||
|
||||
**Настраивается свойствами**
|
||||
|
||||
htpasswd.service.host по умолчанию 0.0.0.0
|
||||
|
||||
htpasswd.service.port по умолчанию 9091
|
||||
|
||||
htpasswd.service.root.path по умолчанию /htpasswd
|
||||
|
||||
**Методы:**
|
||||
|
||||
GET http://localhost:9091/htpasswd - получение содержимого файла htpasswd
|
||||
|
||||
GET http://localhost:9091/htpasswd/checksum - получение checksum текущего htpasswd
|
||||
|
||||
**Кластер:**
|
||||
|
||||
Для избежания рассинхронизации файлов htpasswd на разных серверах требуется настроить шару между карафами и установить адрес этой папки в свойство
|
||||
|
||||
htpasswd.file.directory=/mnt/share
|
||||
|
||||
## Скрипт сихронизации htpasswd для nginX
|
||||
|
||||
Расположен в папке resources/script/htpasswd-checker.sh
|
||||
|
||||
Запускается из любой папки расположенной на сервере.
|
||||
|
||||
Перед запуском проверить и при необходимости поправить переменные в скрипте
|
||||
|
||||
* KARAF_HOST_NAMES=("http://192.168.122.93:9091" "http://192.168.122.94:9091") - караф сервера с запущеным сервисом htpasswd
|
||||
* HTPASSWD_STORAGE=/etc/nginx/htpasswd - адрес файла htpasswd, на который настроен nginX
|
||||
|
||||
Добавить запуск скрипта через cron
|
||||
sudo crontab -e
|
||||
|
||||
```
|
||||
раз в минут
|
||||
*/5 * * * * <path_to_script>
|
||||
|
||||
либо раз в минуту
|
||||
*/1 * * * * <path_to_script>
|
||||
```
|
||||
|
||||
|
||||
|
57
system/auth/basic-auth/htpasswd/pom.xml
Normal file
57
system/auth/basic-auth/htpasswd/pom.xml
Normal file
@ -0,0 +1,57 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
<parent>
|
||||
<groupId>ru.entaxy.esb.system.auth.basic</groupId>
|
||||
<artifactId>basic-auth</artifactId>
|
||||
<version>1.8.0</version>
|
||||
</parent>
|
||||
|
||||
<groupId>ru.entaxy.esb.system.auth.basic.htpasswd</groupId>
|
||||
<artifactId>htpasswd</artifactId>
|
||||
<packaging>bundle</packaging>
|
||||
|
||||
<name>SYSTEM :: ENTAXY :: BASIC AUTH :: HTPASSWD</name>
|
||||
<description>SYSTEM :: ENTAXY :: BASIC AUTH :: HTPASSWD</description>
|
||||
|
||||
<properties>
|
||||
<bundle.osgi.export.pkg>
|
||||
ru.entaxy.esb.system.auth.basic.htpasswd,
|
||||
</bundle.osgi.export.pkg>
|
||||
<bundle.osgi.import.pkg>
|
||||
ru.entaxy.esb.system.auth.basic.jpa.api,
|
||||
ru.entaxy.esb.system.auth.basic.jpa.api.entity,
|
||||
ru.entaxy.esb.system.auth.basic.jpa.api.entity.field,
|
||||
org.apache.cxf.jaxrs.impl,
|
||||
org.apache.camel.component.cxf.jaxrs.blueprint,
|
||||
org.apache.camel.component.cxf.blueprint,
|
||||
org.apache.commons.codec.binary,
|
||||
*
|
||||
</bundle.osgi.import.pkg>
|
||||
</properties>
|
||||
|
||||
<dependencies>
|
||||
<dependency>
|
||||
<groupId>ru.entaxy.esb.system.auth.basic.api</groupId>
|
||||
<artifactId>basic-auth-api</artifactId>
|
||||
<version>${project.version}</version>
|
||||
</dependency>
|
||||
<dependency>
|
||||
<groupId>commons-codec</groupId>
|
||||
<artifactId>commons-codec</artifactId>
|
||||
<version>${commons-codec.version}</version>
|
||||
</dependency>
|
||||
<dependency>
|
||||
<groupId>org.apache.camel</groupId>
|
||||
<artifactId>camel-cxf</artifactId>
|
||||
<version>${camel.version}</version>
|
||||
</dependency>
|
||||
<dependency>
|
||||
<groupId>org.apache.camel.karaf</groupId>
|
||||
<artifactId>camel-cxf-blueprint</artifactId>
|
||||
<version>${camel.version}</version>
|
||||
</dependency>
|
||||
</dependencies>
|
||||
</project>
|
@ -0,0 +1,93 @@
|
||||
/*-
|
||||
* ~~~~~~licensing~~~~~~
|
||||
* htpasswd
|
||||
* ==========
|
||||
* Copyright (C) 2020 - 2021 EmDev LLC
|
||||
* ==========
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
* ~~~~~~/licensing~~~~~~
|
||||
*/
|
||||
package ru.entaxy.esb.system.auth.basic.htpasswd;
|
||||
|
||||
import org.apache.commons.codec.digest.DigestUtils;
|
||||
import org.apache.commons.logging.Log;
|
||||
import org.apache.commons.logging.LogFactory;
|
||||
import ru.entaxy.esb.system.auth.basic.htpasswd.entity.Htpasswd;
|
||||
import ru.entaxy.esb.system.auth.basic.jpa.api.entity.BasicAuthAccount;
|
||||
|
||||
import java.io.File;
|
||||
import java.io.IOException;
|
||||
import java.io.InputStream;
|
||||
import java.nio.file.Files;
|
||||
import java.nio.file.Path;
|
||||
import java.nio.file.Paths;
|
||||
import java.security.NoSuchAlgorithmException;
|
||||
import java.util.List;
|
||||
|
||||
public class HtpasswdGenerator {
|
||||
|
||||
private static final Log LOG = LogFactory.getLog(HtpasswdGenerator.class);
|
||||
|
||||
private String checkSumFileName;
|
||||
|
||||
public Htpasswd htpasswd;
|
||||
|
||||
public void generateHtpasswd(List<BasicAuthAccount> accounts, String salt) throws IOException, NoSuchAlgorithmException {
|
||||
htpasswd.setMasterSalt(salt);
|
||||
htpasswd.prepare(accounts);
|
||||
createFile();
|
||||
}
|
||||
|
||||
private void createFile() throws IOException {
|
||||
String content = htpasswd.toString();
|
||||
LOG.trace("HTTPASSWD " + content);
|
||||
String storeFolder = htpasswd.getDirectory();
|
||||
File folder = new File(storeFolder);
|
||||
folder.mkdirs();
|
||||
|
||||
File htpasswdFile = new File(folder.getAbsolutePath() + File.separator + htpasswd.getFileName());
|
||||
|
||||
Path path = Paths.get(htpasswdFile.getAbsolutePath());
|
||||
Files.write(path, content.getBytes());
|
||||
|
||||
String checkSum = calculateCheckSum(path);
|
||||
File checkSumFile = new File(folder.getAbsolutePath() + File.separator + checkSumFileName);
|
||||
path = Paths.get(checkSumFile.getAbsolutePath());
|
||||
Files.write(path, checkSum.getBytes());
|
||||
}
|
||||
|
||||
private String calculateCheckSum(Path path) throws IOException {
|
||||
String md5;
|
||||
try (InputStream is = Files.newInputStream(path)) {
|
||||
md5 = DigestUtils.md5Hex(is);
|
||||
}
|
||||
return md5;
|
||||
}
|
||||
|
||||
public Htpasswd getHtpasswd() {
|
||||
return htpasswd;
|
||||
}
|
||||
|
||||
public void setHtpasswd(Htpasswd htpasswd) {
|
||||
this.htpasswd = htpasswd;
|
||||
}
|
||||
|
||||
public String getCheckSumFileName() {
|
||||
return checkSumFileName;
|
||||
}
|
||||
|
||||
public void setCheckSumFileName(String checkSumFileName) {
|
||||
this.checkSumFileName = checkSumFileName;
|
||||
}
|
||||
|
||||
}
|
@ -0,0 +1,98 @@
|
||||
/*-
|
||||
* ~~~~~~licensing~~~~~~
|
||||
* htpasswd
|
||||
* ==========
|
||||
* Copyright (C) 2020 - 2021 EmDev LLC
|
||||
* ==========
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
* ~~~~~~/licensing~~~~~~
|
||||
*/
|
||||
package ru.entaxy.esb.system.auth.basic.htpasswd.entity;
|
||||
|
||||
import org.apache.commons.logging.Log;
|
||||
import org.apache.commons.logging.LogFactory;
|
||||
import ru.entaxy.esb.system.auth.basic.jpa.api.entity.BasicAuthAccount;
|
||||
|
||||
import java.security.NoSuchAlgorithmException;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
|
||||
public class Htpasswd {
|
||||
|
||||
private static final Log LOG = LogFactory.getLog(Htpasswd.class);
|
||||
private String directory;
|
||||
private String fileName;
|
||||
private String masterSalt = null;
|
||||
private final List<HtpasswdEntry> entries = new ArrayList<>();
|
||||
|
||||
public Htpasswd() {
|
||||
}
|
||||
|
||||
public void prepare(List<BasicAuthAccount> accounts) throws NoSuchAlgorithmException {
|
||||
if (masterSalt == null || masterSalt.isEmpty()) {
|
||||
throw new IllegalArgumentException("masterSalt not setted!");
|
||||
}
|
||||
if (accounts != null && accounts.size() > 0) {
|
||||
entries.clear();
|
||||
for (BasicAuthAccount account : accounts) {
|
||||
entries.add(new HtpasswdEntry(
|
||||
account.getLogin(),
|
||||
account.getPasswordHash(),
|
||||
masterSalt,
|
||||
account.getEncryptionAlgorithm().getAlgorithmName()));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
public void addString(String login, String passwordHash, String encryptionAlgorithm) throws NoSuchAlgorithmException {
|
||||
entries.add(new HtpasswdEntry(
|
||||
login,
|
||||
passwordHash,
|
||||
masterSalt,
|
||||
encryptionAlgorithm));
|
||||
}
|
||||
|
||||
public String getDirectory() {
|
||||
return directory;
|
||||
}
|
||||
|
||||
public void setDirectory(String directory) {
|
||||
this.directory = directory;
|
||||
}
|
||||
|
||||
public String getFileName() {
|
||||
return fileName;
|
||||
}
|
||||
|
||||
public void setFileName(String fileName) {
|
||||
this.fileName = fileName;
|
||||
}
|
||||
|
||||
public String getMasterSalt() {
|
||||
return masterSalt;
|
||||
}
|
||||
|
||||
public void setMasterSalt(String masterSalt) {
|
||||
this.masterSalt = masterSalt;
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
StringBuilder builder = new StringBuilder();
|
||||
for (HtpasswdEntry entry : entries) {
|
||||
builder.append(entry.toString());
|
||||
}
|
||||
return builder.toString();
|
||||
}
|
||||
|
||||
}
|
@ -0,0 +1,86 @@
|
||||
/*-
|
||||
* ~~~~~~licensing~~~~~~
|
||||
* htpasswd
|
||||
* ==========
|
||||
* Copyright (C) 2020 - 2021 EmDev LLC
|
||||
* ==========
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
* ~~~~~~/licensing~~~~~~
|
||||
*/
|
||||
package ru.entaxy.esb.system.auth.basic.htpasswd.entity;
|
||||
|
||||
import org.apache.commons.codec.binary.Base64;
|
||||
import ru.entaxy.esb.system.auth.basic.jpa.api.entity.field.EncryptionAlgorithm;
|
||||
|
||||
import java.nio.charset.StandardCharsets;
|
||||
import java.security.NoSuchAlgorithmException;
|
||||
|
||||
public class HtpasswdEntry {
|
||||
|
||||
private static final String APR1_PREFIX = "$apr1$";
|
||||
private static final String SHA512_PREFIX = "$6$";
|
||||
private static final String SALTED_SHA1_PREFIX = "{SSHA}";
|
||||
private static final String PLAIN_PREFIX = "{PLAIN}";
|
||||
|
||||
private static final String COLON = ":";
|
||||
private final String resultLine;
|
||||
|
||||
public HtpasswdEntry(String login, String passwordHash, String salt, String encryptionAlgorithm) throws NoSuchAlgorithmException {
|
||||
this(login, passwordHash, salt, encryptionAlgorithm, true);
|
||||
}
|
||||
|
||||
public HtpasswdEntry(String login, String passwordHash, String salt, String encryptionAlgorithm, boolean addLineSeparator) throws NoSuchAlgorithmException {
|
||||
StringBuilder content = new StringBuilder();
|
||||
content.append(login).append(COLON);
|
||||
|
||||
if (EncryptionAlgorithm.MD5.equalsName(encryptionAlgorithm)) {
|
||||
content
|
||||
.append(APR1_PREFIX)
|
||||
.append(salt)
|
||||
.append("$")
|
||||
.append(passwordHash);
|
||||
} else if (EncryptionAlgorithm.SHA1.equalsName(encryptionAlgorithm)) {
|
||||
content.append(SALTED_SHA1_PREFIX);
|
||||
byte[] digest = Base64.decodeBase64(passwordHash);
|
||||
byte[] saltBytes = salt.getBytes(StandardCharsets.UTF_8);
|
||||
|
||||
int l1 = digest.length;
|
||||
int l2 = saltBytes.length;
|
||||
byte[] resultArr = new byte[l1 + l2];
|
||||
System.arraycopy(digest, 0, resultArr, 0, l1);
|
||||
System.arraycopy(saltBytes, 0, resultArr, l1, l2);
|
||||
|
||||
content.append(Base64.encodeBase64String(resultArr));
|
||||
} else if (EncryptionAlgorithm.SHA512.equalsName(encryptionAlgorithm)) {
|
||||
content
|
||||
.append(SHA512_PREFIX)
|
||||
.append(salt)
|
||||
.append("$")
|
||||
.append(passwordHash);
|
||||
} else if (EncryptionAlgorithm.PLAIN.equalsName(encryptionAlgorithm)) {
|
||||
content
|
||||
.append(PLAIN_PREFIX)
|
||||
.append(passwordHash);
|
||||
} else {
|
||||
content.append(passwordHash);
|
||||
}
|
||||
content.append(System.lineSeparator());
|
||||
|
||||
this.resultLine = content.toString();
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return resultLine;
|
||||
}
|
||||
}
|
@ -0,0 +1,43 @@
|
||||
/*-
|
||||
* ~~~~~~licensing~~~~~~
|
||||
* htpasswd
|
||||
* ==========
|
||||
* Copyright (C) 2020 - 2021 EmDev LLC
|
||||
* ==========
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
* ~~~~~~/licensing~~~~~~
|
||||
*/
|
||||
package ru.entaxy.esb.system.auth.basic.htpasswd.rest;
|
||||
|
||||
import javax.ws.rs.GET;
|
||||
import javax.ws.rs.Path;
|
||||
import javax.ws.rs.Produces;
|
||||
import java.io.File;
|
||||
|
||||
@Path("/")
|
||||
public class HtpasswdService {
|
||||
|
||||
@GET
|
||||
@Produces("application/octet-stream")
|
||||
public File getFile() {
|
||||
return null;
|
||||
}
|
||||
|
||||
@GET
|
||||
@Path("/checksum")
|
||||
@Produces("plain/text")
|
||||
public String getCheckSum() {
|
||||
return null;
|
||||
}
|
||||
|
||||
}
|
@ -0,0 +1,95 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
~~~~~~licensing~~~~~~
|
||||
htpasswd
|
||||
==========
|
||||
Copyright (C) 2020 - 2021 EmDev LLC
|
||||
==========
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
~~~~~~/licensing~~~~~~
|
||||
-->
|
||||
|
||||
<blueprint xmlns="http://www.osgi.org/xmlns/blueprint/v1.0.0"
|
||||
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||
xmlns:cm="http://aries.apache.org/blueprint/xmlns/blueprint-cm/v1.1.0"
|
||||
xmlns:camelcxf="http://camel.apache.org/schema/blueprint/cxf"
|
||||
xsi:schemaLocation="http://www.osgi.org/xmlns/blueprint/v1.0.0 https://www.osgi.org/xmlns/blueprint/v1.0.0/blueprint.xsd">
|
||||
|
||||
<cm:property-placeholder persistent-id="ru.entaxy.esb.system.basic_auth.htpasswd" update-strategy="reload">
|
||||
<cm:default-properties>
|
||||
<cm:property name="htpasswd.file.directory" value="securityTest"/>
|
||||
<cm:property name="htpasswd.file.name" value="htpasswd"/>
|
||||
<cm:property name="htpasswd.file.checksum" value="MD5.md5"/>
|
||||
|
||||
<cm:property name="htpasswd.service.host" value="http://localhost"/>
|
||||
<cm:property name="htpasswd.service.port" value="9091"/>
|
||||
<cm:property name="htpasswd.service.root.path" value="/htpasswd"/>
|
||||
|
||||
</cm:default-properties>
|
||||
</cm:property-placeholder>
|
||||
|
||||
<bean id="htpasswd" class="ru.entaxy.esb.system.auth.basic.htpasswd.entity.Htpasswd">
|
||||
<property name="fileName" value="${htpasswd.file.name}"/>
|
||||
<property name="directory" value="${htpasswd.file.directory}"/>
|
||||
</bean>
|
||||
|
||||
<service ref="htpasswdGenerator" interface="ru.entaxy.esb.system.auth.basic.htpasswd.HtpasswdGenerator"/>
|
||||
<bean id="htpasswdGenerator" class="ru.entaxy.esb.system.auth.basic.htpasswd.HtpasswdGenerator">
|
||||
<property name="htpasswd" ref="htpasswd"/>
|
||||
<property name="checkSumFileName" value="${htpasswd.file.checksum}"/>
|
||||
</bean>
|
||||
|
||||
<!-- <reference id="phaseInterceptor" -->
|
||||
<!-- interface="org.apache.cxf.phase.PhaseInterceptor" -->
|
||||
<!-- filter="(type=system)" -->
|
||||
<!-- timeout="30000" -->
|
||||
<!-- availability="optional"/> -->
|
||||
|
||||
<!-- <cxf:bus id="entaxy"> -->
|
||||
<!-- <cxf:inInterceptors> -->
|
||||
<!-- <ref component-id="phaseInterceptor"/> -->
|
||||
<!-- </cxf:inInterceptors> -->
|
||||
<!-- </cxf:bus> -->
|
||||
|
||||
<camelcxf:rsServer id="rsServer"
|
||||
address="${htpasswd.service.host}:${htpasswd.service.port}${htpasswd.service.root.path}"
|
||||
serviceClass="ru.entaxy.esb.system.auth.basic.htpasswd.rest.HtpasswdService"
|
||||
loggingFeatureEnabled="false" loggingSizeLimit="20"/>
|
||||
|
||||
<camelContext id="htpasswd-camel-context" xmlns="http://camel.apache.org/schema/blueprint">
|
||||
|
||||
<route id="htpasswdServiceRouter">
|
||||
<from uri="cxfrs:bean:rsServer?bindingStyle=SimpleConsumer"/>
|
||||
<log message="Htpassed service operation ${header.operationName}" loggingLevel="DEBUG"/>
|
||||
<toD uri="direct:${header.operationName}"/>
|
||||
</route>
|
||||
|
||||
<route id="file">
|
||||
<from uri="direct:getFile"/>
|
||||
<log message="Request direct:getFile: type=${header.type}, active=${header.active}, customerData=${body}"/>
|
||||
<pollEnrich timeout="0">
|
||||
<simple>file:${properties:htpasswd.file.directory}?noop=true&fileName=${properties:htpasswd.file.name}&idempotent=false</simple>
|
||||
</pollEnrich>
|
||||
<convertBodyTo type="String"/>
|
||||
</route>
|
||||
|
||||
<route id="checkSum">
|
||||
<from uri="direct:getCheckSum"/>
|
||||
<log message="Request direct:getCheckSum: type=${header.type}, active=${header.active}, customerData=${body}"/>
|
||||
<pollEnrich timeout="0">
|
||||
<simple>file:${properties:htpasswd.file.directory}?noop=true&fileName=${properties:htpasswd.file.checksum}&idempotent=false</simple>
|
||||
</pollEnrich>
|
||||
<convertBodyTo type="String"/>
|
||||
</route>
|
||||
</camelContext>
|
||||
</blueprint>
|
@ -0,0 +1,67 @@
|
||||
###
|
||||
# ~~~~~~licensing~~~~~~
|
||||
# htpasswd
|
||||
# ==========
|
||||
# Copyright (C) 2020 - 2021 EmDev LLC
|
||||
# ==========
|
||||
# Licensed under the Apache License, Version 2.0 (the "License");
|
||||
# you may not use this file except in compliance with the License.
|
||||
# You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
# ~~~~~~/licensing~~~~~~
|
||||
###
|
||||
# !/bin/sh
|
||||
KARAF_HOST_NAMES=("http://192.168.122.93:9091" "http://192.168.122.94:9091")
|
||||
HTPASSWD_PATH=/htpasswd
|
||||
CHECKSUM_PATH=$HTPASSWD_PATH/checksum
|
||||
HTPASSWD_STORAGE=/etc/nginx/htpasswd
|
||||
LOGFILE="htpasswd-sync.log"
|
||||
TIMESTAMP=`date "+%Y-%m-%d %H:%M:%S"`
|
||||
|
||||
currentChecksum=`md5sum $HTPASSWD_STORAGE | awk '{ print $1 }'`
|
||||
|
||||
log(){
|
||||
echo "$TIMESTAMP $1" >> $LOGFILE
|
||||
}
|
||||
|
||||
#download actual checksum from karaf
|
||||
for actualHost in ${KARAF_HOST_NAMES[*]}; do
|
||||
wget -O checksum $actualHost$CHECKSUM_PATH
|
||||
newChecksum=`cat checksum`
|
||||
rm checksum
|
||||
if [[ -n $newChecksum ]]
|
||||
then
|
||||
log "checksum received from host $actualHost"
|
||||
break
|
||||
else
|
||||
log "host $actualHost did not give checksum data"
|
||||
fi
|
||||
done
|
||||
|
||||
log "newChecksum $newChecksum"
|
||||
log "currentChecksum $currentChecksum"
|
||||
|
||||
if [[ -n $newChecksum ]] && { [[ -z $currentChecksum ]] || [ $currentChecksum != $newChecksum ]; };
|
||||
then
|
||||
wget -O htpasswd $actualHost$HTPASSWD_PATH
|
||||
sudo mv htpasswd $HTPASSWD_STORAGE
|
||||
sudo chmod 644 $HTPASSWD_STORAGE
|
||||
sudo chown root:root $HTPASSWD_STORAGE
|
||||
sudo systemctl reload nginx
|
||||
log ">>>>>>>>>>>>>>>>> Htpasswd updated"
|
||||
else
|
||||
if [[ -n $newChecksum ]]
|
||||
then
|
||||
log ">>>>>>>>>>>>>>>>> Htpasswd is up to date"
|
||||
else
|
||||
log ">>>>>>>>>>>>>>>>> Script finished with error: new checksum not received!"
|
||||
#error action
|
||||
fi
|
||||
fi
|
Reference in New Issue
Block a user