Replace password reset with email OTP verification flow. Add auth_otp module, OTP templates, and email delivery. Expand styleguide CSS with full component library. Rework login, register, and admin views for cookie sessions. Remove legacy 2FA templates and password reset flow. Update SSH wrappers, forms, validators, and middleware.
111 lines
4.2 KiB
Python
111 lines
4.2 KiB
Python
# Copyright (C) 2016-2024 RhodeCode GmbH
|
|
#
|
|
# This program is free software: you can redistribute it and/or modify
|
|
# it under the terms of the GNU Affero General Public License, version 3
|
|
# (only), as published by the Free Software Foundation.
|
|
#
|
|
# This program is distributed in the hope that it will be useful,
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
# GNU General Public License for more details.
|
|
#
|
|
# You should have received a copy of the GNU Affero General Public License
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
#
|
|
# This program is dual-licensed. If you wish to learn more about the
|
|
# RhodeCode Enterprise Edition, including its added features, Support services,
|
|
# and proprietary license terms, please see https://rhodecode.com/licenses/
|
|
|
|
"""
|
|
WARNING: be really carefully with changing ANY imports in this file
|
|
# This script is to mean as really fast executable, doing some imports here that would yield an import chain change
|
|
# can affect execution times...
|
|
# This can be easily debugged using such command::
|
|
# time PYTHONPROFILEIMPORTTIME=1 rc-ssh-wrapper-v2 --debug --mode=test .dev/dev.ini
|
|
"""
|
|
|
|
import warnings
|
|
|
|
warnings.filterwarnings("ignore", message="pkg_resources is deprecated as an API.*", category=UserWarning)
|
|
warnings.filterwarnings("ignore", message="pkg_resources is deprecated as an API.*", category=DeprecationWarning)
|
|
|
|
import os
|
|
import sys
|
|
import time
|
|
import logging
|
|
|
|
import click
|
|
|
|
from rhodecode.config.config_maker import sanitize_settings_and_apply_defaults
|
|
|
|
from rhodecode.lib.request import Request
|
|
from rhodecode.lib.utils2 import AttributeDict
|
|
from rhodecode.lib.statsd_client import StatsdClient
|
|
from rhodecode.lib.config_utils import get_app_config_lightweight
|
|
|
|
from .utils import setup_custom_logging
|
|
from .backends import SshWrapperStandalone
|
|
|
|
log = logging.getLogger(__name__)
|
|
|
|
|
|
@click.command()
|
|
@click.argument("ini_path", type=click.Path(exists=True))
|
|
@click.option(
|
|
"--mode",
|
|
"-m",
|
|
required=False,
|
|
default="auto",
|
|
type=click.Choice(["auto", "vcs", "git", "hg", "svn", "test"]),
|
|
help="mode of operation",
|
|
)
|
|
@click.option("--user", help="Username for which the command will be executed")
|
|
@click.option("--user-id", help="User ID for which the command will be executed")
|
|
@click.option("--key-id", help="ID of the key from the database")
|
|
@click.option("--shell", "-s", is_flag=True, help="Allow Shell")
|
|
@click.option("--debug", is_flag=True, help="Enabled detailed output logging")
|
|
def main(ini_path, mode, user, user_id, key_id, shell, debug):
|
|
time_start = time.time()
|
|
setup_custom_logging(ini_path, debug)
|
|
|
|
command = os.environ.get("SSH_ORIGINAL_COMMAND", "")
|
|
if not command and mode not in ["test"]:
|
|
raise ValueError(
|
|
"Unable to fetch SSH_ORIGINAL_COMMAND from environment."
|
|
"Please make sure this is set and available during execution "
|
|
"of this script."
|
|
)
|
|
|
|
# initialize settings and get defaults
|
|
settings = get_app_config_lightweight(ini_path)
|
|
settings = sanitize_settings_and_apply_defaults({"__file__": ini_path}, settings)
|
|
|
|
# init and bootstrap StatsdClient
|
|
StatsdClient.setup(settings)
|
|
statsd = StatsdClient.statsd
|
|
|
|
try:
|
|
connection_info = os.environ.get("SSH_CONNECTION", "")
|
|
request = Request.blank("/", base_url=settings["app.base_url"])
|
|
request.user = AttributeDict(
|
|
{
|
|
"username": user,
|
|
"user_id": user_id,
|
|
"ip_addr": connection_info.split(" ")[0] if connection_info else None,
|
|
}
|
|
)
|
|
env = {"RC_CMD_SSH_WRAPPER": "1", "request": request}
|
|
ssh_wrapper = SshWrapperStandalone(
|
|
command, connection_info, mode, user, user_id, key_id, shell, ini_path, settings, env
|
|
)
|
|
except Exception:
|
|
log.exception("Failed to execute SshWrapper")
|
|
sys.exit(-5)
|
|
|
|
return_code = ssh_wrapper.wrap()
|
|
operation_took = time.time() - time_start
|
|
if statsd:
|
|
operation_took_ms = round(1000.0 * operation_took)
|
|
statsd.timing("rhodecode_ssh_wrapper_timing.histogram", operation_took_ms, use_decimals=False)
|
|
|
|
sys.exit(return_code)
|