reuse VerifyHostKeyFromKnownHosts (#143)

This commit is contained in:
Boshi Lian 2023-02-28 17:11:17 -08:00 committed by GitHub
parent 841350fadb
commit e7b276d6a5
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
4 changed files with 26 additions and 50 deletions

View file

@ -4,7 +4,6 @@ import (
"bufio"
"bytes"
"fmt"
"net"
"os"
"path"
"regexp"
@ -12,7 +11,6 @@ import (
"github.com/tg123/sshpiper/libplugin"
"golang.org/x/crypto/ssh"
"golang.org/x/crypto/ssh/knownhosts"
log "github.com/sirupsen/logrus"
)
@ -96,22 +94,13 @@ func (w *Workingdir) VerifyHostKey(hostname, netaddr string, key []byte) error {
return nil
}
hostKeyCallback, err := knownhosts.New(w.fullpath(userKnownHosts))
f, err := os.Open(w.fullpath(userKnownHosts))
if err != nil {
return err
}
defer f.Close()
pub, err := ssh.ParsePublicKey(key)
if err != nil {
return err
}
addr, err := net.ResolveTCPAddr("tcp", netaddr)
if err != nil {
return err
}
return hostKeyCallback(hostname, addr, pub)
return libplugin.VerifyHostKeyFromKnownHosts(f, hostname, netaddr, key)
}
func (w *Workingdir) checkPerm(file string) error {

View file

@ -5,7 +5,6 @@ import (
"context"
"encoding/base64"
"fmt"
"net"
"regexp"
"time"
@ -15,7 +14,6 @@ import (
sshpiper "github.com/tg123/sshpiper/plugin/kubernetes/generated/clientset/versioned"
piperlister "github.com/tg123/sshpiper/plugin/kubernetes/generated/listers/sshpiper/v1beta1"
"golang.org/x/crypto/ssh"
"golang.org/x/crypto/ssh/knownhosts"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/apimachinery/pkg/fields"
"k8s.io/apimachinery/pkg/labels"
@ -125,22 +123,7 @@ func (p *plugin) verifyHostKey(conn libplugin.ConnMetadata, hostname, netaddr st
return err
}
hostKeyCallback, err := knownhosts.NewFromReader(bytes.NewBuffer(data))
if err != nil {
return err
}
pub, err := ssh.ParsePublicKey(key)
if err != nil {
return err
}
addr, err := net.ResolveTCPAddr("tcp", netaddr)
if err != nil {
return err
}
return hostKeyCallback(hostname, addr, pub)
return libplugin.VerifyHostKeyFromKnownHosts(bytes.NewBuffer(data), hostname, netaddr, key)
}
func (p *plugin) createUpstream(conn libplugin.ConnMetadata, pipe *piperv1beta1.Pipe, originPassword string) (*libplugin.Upstream, error) {

View file

@ -6,7 +6,6 @@ import (
"bytes"
"encoding/base64"
"fmt"
"net"
"os"
"path/filepath"
"regexp"
@ -15,7 +14,6 @@ import (
"github.com/patrickmn/go-cache"
"github.com/tg123/sshpiper/libplugin"
"golang.org/x/crypto/ssh"
"golang.org/x/crypto/ssh/knownhosts"
"gopkg.in/yaml.v3"
)
@ -173,22 +171,7 @@ func (p *plugin) verifyHostKey(conn libplugin.ConnMetadata, hostname, netaddr st
return err
}
hostKeyCallback, err := knownhosts.NewFromReader(bytes.NewBuffer(data))
if err != nil {
return err
}
pub, err := ssh.ParsePublicKey(key)
if err != nil {
return err
}
addr, err := net.ResolveTCPAddr("tcp", netaddr)
if err != nil {
return err
}
return hostKeyCallback(hostname, addr, pub)
return libplugin.VerifyHostKeyFromKnownHosts(bytes.NewBuffer(data), hostname, netaddr, key)
}
func (p *plugin) createUpstream(conn libplugin.ConnMetadata, to pipeConfigTo, originPassword string) (*libplugin.Upstream, error) {