feat(vcs clients filtering): added changes related to vcs client filtering needed for EE. Fixes: RCCE-41
This commit is contained in:
parent
50822a3304
commit
d174103b5d
9 changed files with 188 additions and 8 deletions
|
|
@ -49,22 +49,31 @@ def admin_routes(config):
|
|||
|
||||
config.add_route(
|
||||
'admin_security',
|
||||
pattern=ADMIN_PREFIX + '/security')
|
||||
pattern='/security')
|
||||
config.add_view(
|
||||
AdminSecurityView,
|
||||
attr='security' ,
|
||||
attr='security',
|
||||
route_name='admin_security', request_method='GET',
|
||||
renderer='rhodecode:templates/admin/security/security.mako')
|
||||
|
||||
config.add_route(
|
||||
name='admin_security_update',
|
||||
pattern=ADMIN_PREFIX + '/security/update')
|
||||
pattern='/security/update')
|
||||
config.add_view(
|
||||
AdminSecurityView,
|
||||
attr='security_update',
|
||||
route_name='admin_security_update', request_method='POST',
|
||||
renderer='rhodecode:templates/admin/security/security.mako')
|
||||
|
||||
config.add_route(
|
||||
name='admin_security_modify_allowed_vcs_client_versions',
|
||||
pattern='/security/modify/allowed_vcs_client_versions')
|
||||
config.add_view(
|
||||
AdminSecurityView,
|
||||
attr='vcs_whitelisted_client_versions_edit',
|
||||
route_name='admin_security_modify_allowed_vcs_client_versions', request_method=('GET', 'POST'),
|
||||
renderer='rhodecode:templates/admin/security/edit_allowed_vcs_client_versions.mako')
|
||||
|
||||
|
||||
config.add_route(
|
||||
name='admin_audit_logs',
|
||||
|
|
|
|||
|
|
@ -17,8 +17,13 @@
|
|||
# and proprietary license terms, please see https://rhodecode.com/licenses/
|
||||
|
||||
import logging
|
||||
import formencode
|
||||
|
||||
from rhodecode import BACKENDS
|
||||
from rhodecode.apps._base import BaseAppView
|
||||
from rhodecode.model.meta import Session
|
||||
from rhodecode.model.settings import SettingsModel
|
||||
from rhodecode.model.forms import WhitelistedVcsClientsForm
|
||||
from rhodecode.lib.auth import LoginRequired, HasPermissionAllDecorator
|
||||
|
||||
log = logging.getLogger(__name__)
|
||||
|
|
@ -37,3 +42,31 @@ class AdminSecurityView(BaseAppView):
|
|||
c.active = 'security'
|
||||
return self._get_template_context(c)
|
||||
|
||||
@LoginRequired()
|
||||
@HasPermissionAllDecorator('hg.admin')
|
||||
def vcs_whitelisted_client_versions_edit(self):
|
||||
_ = self.request.translate
|
||||
c = self.load_default_context()
|
||||
render_ctx = {}
|
||||
settings = SettingsModel()
|
||||
form = WhitelistedVcsClientsForm(_, )()
|
||||
if self.request.method == 'POST':
|
||||
try:
|
||||
result = form.to_python(self.request.POST)
|
||||
for k, v in result.items():
|
||||
if v:
|
||||
setting = settings.create_or_update_setting(name=f'{k}_allowed_clients', val=v)
|
||||
Session().add(setting)
|
||||
Session().commit()
|
||||
|
||||
except formencode.Invalid as errors:
|
||||
render_ctx.update({
|
||||
'errors': errors.error_dict
|
||||
})
|
||||
for key in BACKENDS.keys():
|
||||
verbose_name = f"initial_{key}"
|
||||
if existing := settings.get_setting_by_name(name=f'{key}_allowed_clients'):
|
||||
render_ctx[verbose_name] = existing.app_settings_value
|
||||
else:
|
||||
render_ctx[verbose_name] = '*'
|
||||
return self._get_template_context(c, **render_ctx)
|
||||
|
|
|
|||
|
|
@ -102,6 +102,11 @@ class HTTPRequirementError(HTTPClientError):
|
|||
self.args = (message, )
|
||||
|
||||
|
||||
class ClientNotSupportedError(HTTPRequirementError):
|
||||
title = explanation = 'Client Not Supported'
|
||||
reason = None
|
||||
|
||||
|
||||
class HTTPLockedRC(HTTPClientError):
|
||||
"""
|
||||
Special Exception For locked Repos in RhodeCode, the return code can
|
||||
|
|
|
|||
|
|
@ -30,7 +30,7 @@ from rhodecode.lib import helpers as h
|
|||
from rhodecode.lib import audit_logger
|
||||
from rhodecode.lib.utils2 import safe_str, user_agent_normalizer
|
||||
from rhodecode.lib.exceptions import (
|
||||
HTTPLockedRC, HTTPBranchProtected, UserCreationError)
|
||||
HTTPLockedRC, HTTPBranchProtected, UserCreationError, ClientNotSupportedError)
|
||||
from rhodecode.model.db import Repository, User
|
||||
from rhodecode.lib.statsd_client import StatsdClient
|
||||
|
||||
|
|
@ -64,6 +64,18 @@ def is_shadow_repo(extras):
|
|||
return extras['is_shadow_repo']
|
||||
|
||||
|
||||
def check_vcs_client(extras):
|
||||
"""
|
||||
Checks if vcs client is allowed (Only works in enterprise edition)
|
||||
"""
|
||||
try:
|
||||
from rc_ee.lib.security.utils import is_vcs_client_whitelisted
|
||||
except ModuleNotFoundError:
|
||||
is_vcs_client_whitelisted = lambda *x: True
|
||||
backend = extras.get('scm')
|
||||
if not is_vcs_client_whitelisted(extras.get('user_agent'), backend):
|
||||
raise ClientNotSupportedError(f"Your {backend} client is forbidden")
|
||||
|
||||
def _get_scm_size(alias, root_path):
|
||||
|
||||
if not alias.startswith('.'):
|
||||
|
|
@ -108,6 +120,7 @@ def pre_push(extras):
|
|||
It bans pushing when the repository is locked.
|
||||
"""
|
||||
|
||||
check_vcs_client(extras)
|
||||
user = User.get_by_username(extras.username)
|
||||
output = ''
|
||||
if extras.locked_by[0] and user.user_id != int(extras.locked_by[0]):
|
||||
|
|
@ -180,6 +193,7 @@ def pre_pull(extras):
|
|||
It bans pulling when the repository is locked.
|
||||
"""
|
||||
|
||||
check_vcs_client(extras)
|
||||
output = ''
|
||||
if extras.locked_by[0]:
|
||||
locked_by = User.get(extras.locked_by[0]).username
|
||||
|
|
|
|||
|
|
@ -84,8 +84,11 @@ def adopt_for_celery(func):
|
|||
@wraps(func)
|
||||
def wrapper(extras):
|
||||
extras = AttributeDict(extras)
|
||||
# HooksResponse implements to_json method which must be used there.
|
||||
return func(extras).to_json()
|
||||
try:
|
||||
# HooksResponse implements to_json method which must be used there.
|
||||
return func(extras).to_json()
|
||||
except Exception as e:
|
||||
return {'status': 128, 'exception': type(e).__name__, 'exception_args': e.args}
|
||||
return wrapper
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -129,6 +129,20 @@ def TOTPForm(localizer, user, allow_recovery_code_use=False):
|
|||
return _TOTPForm
|
||||
|
||||
|
||||
def WhitelistedVcsClientsForm(localizer):
|
||||
_ = localizer
|
||||
|
||||
class _WhitelistedVcsClientsForm(formencode.Schema):
|
||||
regexp = r'^(?:\s*[<>=~^!]*\s*\d{1,2}\.\d{1,2}(?:\.\d{1,2})?\s*|\*)\s*(?:,\s*[<>=~^!]*\s*\d{1,2}\.\d{1,2}(?:\.\d{1,2})?\s*|\s*\*\s*)*$'
|
||||
allow_extra_fields = True
|
||||
filter_extra_fields = True
|
||||
git = v.Regex(regexp)
|
||||
hg = v.Regex(regexp)
|
||||
svn = v.Regex(regexp)
|
||||
|
||||
return _WhitelistedVcsClientsForm
|
||||
|
||||
|
||||
def UserForm(localizer, edit=False, available_languages=None, old_data=None):
|
||||
old_data = old_data or {}
|
||||
available_languages = available_languages or []
|
||||
|
|
|
|||
|
|
@ -86,6 +86,7 @@ function registerRCRoutes() {
|
|||
pyroutes.register('admin_settings_vcs_update', '/_admin/settings/vcs/update', []);
|
||||
pyroutes.register('admin_settings_visual', '/_admin/settings/visual', []);
|
||||
pyroutes.register('admin_settings_visual_update', '/_admin/settings/visual/update', []);
|
||||
pyroutes.register('admin_security_modify_allowed_vcs_client_versions', '/_admin/security/modify/allowed_vcs_client_versions', []);
|
||||
pyroutes.register('apiv2', '/_admin/api', []);
|
||||
pyroutes.register('atom_feed_home', '/%(repo_name)s/feed-atom', ['repo_name']);
|
||||
pyroutes.register('atom_feed_home_old', '/%(repo_name)s/feed/atom', ['repo_name']);
|
||||
|
|
|
|||
|
|
@ -0,0 +1,62 @@
|
|||
<style>
|
||||
.form-group {
|
||||
margin-bottom: 15px;
|
||||
}
|
||||
|
||||
.form-group label {
|
||||
display: flex;
|
||||
align-items: left;
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.form-control {
|
||||
width: 60%;
|
||||
padding: 10px;
|
||||
font-size: 1rem;
|
||||
line-height: 1.5;
|
||||
border: 1px solid #ced4da;
|
||||
border-radius: 4px;
|
||||
box-sizing: border-box;
|
||||
}
|
||||
|
||||
.btn-primary {
|
||||
background-color: #007bff;
|
||||
border: none;
|
||||
padding: 10px 20px;
|
||||
color: white;
|
||||
font-size: 1rem;
|
||||
border-radius: 4px;
|
||||
cursor: pointer;
|
||||
}
|
||||
|
||||
.btn-primary:hover {
|
||||
background-color: #0056b3;
|
||||
}
|
||||
.form-group .help_block {
|
||||
display: block;
|
||||
width: 100%;
|
||||
margin-top: 10px;
|
||||
text-align: left;
|
||||
font-size: 0.875rem;
|
||||
}
|
||||
</style>
|
||||
|
||||
<div>
|
||||
<div class="form-group">
|
||||
${h.secure_form(h.route_path('check_2fa'), request=request, id='allowed_clients_form')}
|
||||
<p><label for="git">${_('git')}:</label>
|
||||
${h.text('git', class_="form-control", value=initial_git)}</p>
|
||||
<p><label for="hg">${_('hg')}:</label>
|
||||
${h.text('hg', class_="form-control", value=initial_hg)}</p>
|
||||
<p><label for="svn">${_('svn')}:</label>
|
||||
${h.text('svn', class_="form-control", value=initial_svn)}</p>
|
||||
%for k, v in errors.items():
|
||||
<span class="error-message">${k}: ${v}</span>
|
||||
<br />
|
||||
%endfor
|
||||
<p class="help_block">${_('Set rules for allowed git, hg or svn client versions. You can set exact version (for example 2.0.9) or use comparison operators to set earliest or latest version (>=2.6.0)')}</p>
|
||||
|
||||
${h.submit('send', _('Save'), class_="btn btn-primary")}
|
||||
${h.end_form()}
|
||||
</div>
|
||||
</div>
|
||||
|
|
@ -28,13 +28,52 @@
|
|||
<div class="panel-body">
|
||||
<h4>${_('This feature is available in RhodeCode EE edition only. Contact {sales_email} to obtain a trial license.').format(sales_email='<a href="mailto:sales@rhodecode.com">sales@rhodecode.com</a>')|n}</h4>
|
||||
<p>
|
||||
You can scan your repositories for exposed secrets, passwords, etc
|
||||
${_('You can scan your repositories for exposed secrets, passwords, etc')}
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="panel panel-default">
|
||||
<div class="panel-heading">
|
||||
<h3 class="panel-title">${_('Allowed client versions')}</h3>
|
||||
</div>
|
||||
<div class="panel-body">
|
||||
%if c.rhodecode_edition_id != 'EE':
|
||||
<h4>${_('This feature is available in RhodeCode EE edition only. Contact {sales_email} to obtain a trial license.').format(sales_email='<a href="mailto:sales@rhodecode.com">sales@rhodecode.com</a>')|n}</h4>
|
||||
<p>
|
||||
${_('Some outdated client versions may have security vulnerabilities. This section have rules for whitelisting versions of clients for Git, Mercurial and SVN.')}
|
||||
</p>
|
||||
%else:
|
||||
<div class="inner form" id="container">
|
||||
</div>
|
||||
%endif
|
||||
</div>
|
||||
|
||||
</div>
|
||||
|
||||
<script>
|
||||
$(document).ready(function() {
|
||||
$.ajax({
|
||||
url: pyroutes.url('admin_security_modify_allowed_vcs_client_versions'),
|
||||
type: 'GET',
|
||||
success: function(response) {
|
||||
$('#container').html(response);
|
||||
},
|
||||
});
|
||||
$(document).on('submit', '#allowed_clients_form', function(event) {
|
||||
event.preventDefault();
|
||||
var formData = $(this).serialize();
|
||||
|
||||
$.ajax({
|
||||
url: pyroutes.url('admin_security_modify_allowed_vcs_client_versions'),
|
||||
type: 'POST',
|
||||
data: formData,
|
||||
success: function(response) {
|
||||
$('#container').html(response);
|
||||
},
|
||||
});
|
||||
});
|
||||
});
|
||||
</script>
|
||||
|
||||
</%def>
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue