unrhodecode/rhodecode/apps/ssh_support/lib/ssh_wrapper_v2.py
russell@unturf.com 722c3bd369 Prototype: OTP auth, styleguide overhaul, login/session rework
Replace password reset with email OTP verification flow.
Add auth_otp module, OTP templates, and email delivery.
Expand styleguide CSS with full component library.
Rework login, register, and admin views for cookie sessions.
Remove legacy 2FA templates and password reset flow.
Update SSH wrappers, forms, validators, and middleware.
2026-03-04 16:44:40 -05:00

111 lines
4.2 KiB
Python

# Copyright (C) 2016-2024 RhodeCode GmbH
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License, version 3
# (only), as published by the Free Software Foundation.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
#
# This program is dual-licensed. If you wish to learn more about the
# RhodeCode Enterprise Edition, including its added features, Support services,
# and proprietary license terms, please see https://rhodecode.com/licenses/
"""
WARNING: be really carefully with changing ANY imports in this file
# This script is to mean as really fast executable, doing some imports here that would yield an import chain change
# can affect execution times...
# This can be easily debugged using such command::
# time PYTHONPROFILEIMPORTTIME=1 rc-ssh-wrapper-v2 --debug --mode=test .dev/dev.ini
"""
import warnings
warnings.filterwarnings("ignore", message="pkg_resources is deprecated as an API.*", category=UserWarning)
warnings.filterwarnings("ignore", message="pkg_resources is deprecated as an API.*", category=DeprecationWarning)
import os
import sys
import time
import logging
import click
from rhodecode.config.config_maker import sanitize_settings_and_apply_defaults
from rhodecode.lib.request import Request
from rhodecode.lib.utils2 import AttributeDict
from rhodecode.lib.statsd_client import StatsdClient
from rhodecode.lib.config_utils import get_app_config_lightweight
from .utils import setup_custom_logging
from .backends import SshWrapperStandalone
log = logging.getLogger(__name__)
@click.command()
@click.argument("ini_path", type=click.Path(exists=True))
@click.option(
"--mode",
"-m",
required=False,
default="auto",
type=click.Choice(["auto", "vcs", "git", "hg", "svn", "test"]),
help="mode of operation",
)
@click.option("--user", help="Username for which the command will be executed")
@click.option("--user-id", help="User ID for which the command will be executed")
@click.option("--key-id", help="ID of the key from the database")
@click.option("--shell", "-s", is_flag=True, help="Allow Shell")
@click.option("--debug", is_flag=True, help="Enabled detailed output logging")
def main(ini_path, mode, user, user_id, key_id, shell, debug):
time_start = time.time()
setup_custom_logging(ini_path, debug)
command = os.environ.get("SSH_ORIGINAL_COMMAND", "")
if not command and mode not in ["test"]:
raise ValueError(
"Unable to fetch SSH_ORIGINAL_COMMAND from environment."
"Please make sure this is set and available during execution "
"of this script."
)
# initialize settings and get defaults
settings = get_app_config_lightweight(ini_path)
settings = sanitize_settings_and_apply_defaults({"__file__": ini_path}, settings)
# init and bootstrap StatsdClient
StatsdClient.setup(settings)
statsd = StatsdClient.statsd
try:
connection_info = os.environ.get("SSH_CONNECTION", "")
request = Request.blank("/", base_url=settings["app.base_url"])
request.user = AttributeDict(
{
"username": user,
"user_id": user_id,
"ip_addr": connection_info.split(" ")[0] if connection_info else None,
}
)
env = {"RC_CMD_SSH_WRAPPER": "1", "request": request}
ssh_wrapper = SshWrapperStandalone(
command, connection_info, mode, user, user_id, key_id, shell, ini_path, settings, env
)
except Exception:
log.exception("Failed to execute SshWrapper")
sys.exit(-5)
return_code = ssh_wrapper.wrap()
operation_took = time.time() - time_start
if statsd:
operation_took_ms = round(1000.0 * operation_took)
statsd.timing("rhodecode_ssh_wrapper_timing.histogram", operation_took_ms, use_decimals=False)
sys.exit(return_code)