authController.php 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243
  1. <?php
  2. /**
  3. * This controller handles action about authentication.
  4. */
  5. class FreshRSS_auth_Controller extends FreshRSS_ActionController {
  6. /**
  7. * This action handles authentication management page.
  8. *
  9. * Parameters are:
  10. * - token (default: current token)
  11. * - anon_access (default: false)
  12. * - anon_refresh (default: false)
  13. * - auth_type (default: none)
  14. * - unsafe_autologin (default: false)
  15. * - api_enabled (default: false)
  16. *
  17. * @todo move unsafe_autologin in an extension.
  18. */
  19. public function indexAction() {
  20. if (!FreshRSS_Auth::hasAccess('admin')) {
  21. Minz_Error::error(403);
  22. }
  23. FreshRSS_View::prependTitle(_t('admin.auth.title') . ' · ');
  24. if (Minz_Request::isPost()) {
  25. $ok = true;
  26. $anon = Minz_Request::param('anon_access', false);
  27. $anon = ((bool)$anon) && ($anon !== 'no');
  28. $anon_refresh = Minz_Request::param('anon_refresh', false);
  29. $anon_refresh = ((bool)$anon_refresh) && ($anon_refresh !== 'no');
  30. $auth_type = Minz_Request::param('auth_type', 'none');
  31. $unsafe_autologin = Minz_Request::param('unsafe_autologin', false);
  32. $api_enabled = Minz_Request::param('api_enabled', false);
  33. if ($anon != FreshRSS_Context::$system_conf->allow_anonymous ||
  34. $auth_type != FreshRSS_Context::$system_conf->auth_type ||
  35. $anon_refresh != FreshRSS_Context::$system_conf->allow_anonymous_refresh ||
  36. $unsafe_autologin != FreshRSS_Context::$system_conf->unsafe_autologin_enabled ||
  37. $api_enabled != FreshRSS_Context::$system_conf->api_enabled) {
  38. // TODO: test values from form
  39. FreshRSS_Context::$system_conf->auth_type = $auth_type;
  40. FreshRSS_Context::$system_conf->allow_anonymous = $anon;
  41. FreshRSS_Context::$system_conf->allow_anonymous_refresh = $anon_refresh;
  42. FreshRSS_Context::$system_conf->unsafe_autologin_enabled = $unsafe_autologin;
  43. FreshRSS_Context::$system_conf->api_enabled = $api_enabled;
  44. $ok &= FreshRSS_Context::$system_conf->save();
  45. }
  46. invalidateHttpCache();
  47. if ($ok) {
  48. Minz_Request::good(_t('feedback.conf.updated'), [ 'c' => 'auth', 'a' => 'index' ]);
  49. } else {
  50. Minz_Request::bad(_t('feedback.conf.error'), [ 'c' => 'auth', 'a' => 'index' ]);
  51. }
  52. }
  53. }
  54. /**
  55. * This action handles the login page.
  56. *
  57. * It forwards to the correct login page (form) or main page if
  58. * the user is already connected.
  59. */
  60. public function loginAction() {
  61. if (FreshRSS_Auth::hasAccess() && Minz_Request::param('u', '') == '') {
  62. Minz_Request::forward(array('c' => 'index', 'a' => 'index'), true);
  63. }
  64. $auth_type = FreshRSS_Context::$system_conf->auth_type;
  65. FreshRSS_Context::initUser('_', false);
  66. switch ($auth_type) {
  67. case 'form':
  68. Minz_Request::forward(array('c' => 'auth', 'a' => 'formLogin'));
  69. break;
  70. case 'http_auth':
  71. Minz_Error::error(403, array('error' => array(_t('feedback.access.denied'),
  72. ' [HTTP Remote-User=' . htmlspecialchars(httpAuthUser(), ENT_NOQUOTES, 'UTF-8') . ']'
  73. )), false);
  74. break;
  75. case 'none':
  76. // It should not happen!
  77. Minz_Error::error(404);
  78. default:
  79. // TODO load plugin instead
  80. Minz_Error::error(404);
  81. }
  82. }
  83. /**
  84. * This action handles form login page.
  85. *
  86. * If this action is reached through a POST request, username and password
  87. * are compared to login the current user.
  88. *
  89. * Parameters are:
  90. * - nonce (default: false)
  91. * - username (default: '')
  92. * - challenge (default: '')
  93. * - keep_logged_in (default: false)
  94. *
  95. * @todo move unsafe autologin in an extension.
  96. */
  97. public function formLoginAction() {
  98. invalidateHttpCache();
  99. FreshRSS_View::prependTitle(_t('gen.auth.login') . ' · ');
  100. FreshRSS_View::appendScript(Minz_Url::display('/scripts/bcrypt.min.js?' . @filemtime(PUBLIC_PATH . '/scripts/bcrypt.min.js')));
  101. $limits = FreshRSS_Context::$system_conf->limits;
  102. $this->view->cookie_days = round($limits['cookie_duration'] / 86400, 1);
  103. $isPOST = Minz_Request::isPost() && !Minz_Session::param('POST_to_GET');
  104. Minz_Session::_param('POST_to_GET');
  105. if ($isPOST) {
  106. $nonce = Minz_Session::param('nonce', '');
  107. $username = Minz_Request::param('username', '');
  108. $challenge = Minz_Request::param('challenge', '');
  109. usleep(rand(100, 10000)); //Primitive mitigation of timing attacks, in μs
  110. FreshRSS_Context::initUser($username);
  111. if (FreshRSS_Context::$user_conf == null) {
  112. // Initialise the default user to be able to display the error page
  113. FreshRSS_Context::initUser(FreshRSS_Context::$system_conf->default_user);
  114. Minz_Error::error(403, array(_t('feedback.auth.login.invalid')), false);
  115. return;
  116. }
  117. if (!FreshRSS_Context::$user_conf->enabled || FreshRSS_Context::$user_conf->passwordHash == '') {
  118. usleep(rand(100, 5000)); //Primitive mitigation of timing attacks, in μs
  119. Minz_Error::error(403, array(_t('feedback.auth.login.invalid')), false);
  120. return;
  121. }
  122. $ok = FreshRSS_FormAuth::checkCredentials(
  123. $username, FreshRSS_Context::$user_conf->passwordHash, $nonce, $challenge
  124. );
  125. if ($ok) {
  126. // Set session parameter to give access to the user.
  127. Minz_Session::_params([
  128. 'currentUser' => $username,
  129. 'passwordHash' => FreshRSS_Context::$user_conf->passwordHash,
  130. 'csrf' => false,
  131. ]);
  132. FreshRSS_Auth::giveAccess();
  133. // Set cookie parameter if needed.
  134. if (Minz_Request::param('keep_logged_in')) {
  135. FreshRSS_FormAuth::makeCookie($username, FreshRSS_Context::$user_conf->passwordHash);
  136. } else {
  137. FreshRSS_FormAuth::deleteCookie();
  138. }
  139. Minz_Translate::init(FreshRSS_Context::$user_conf->language);
  140. // All is good, go back to the index.
  141. Minz_Request::good(_t('feedback.auth.login.success'), [ 'c' => 'index', 'a' => 'index' ]);
  142. } else {
  143. Minz_Log::warning("Password mismatch for user={$username}, nonce={$nonce}, c={$challenge}");
  144. header('HTTP/1.1 403 Forbidden');
  145. Minz_Session::_param('POST_to_GET', true); //Prevent infinite internal redirect
  146. Minz_Request::setBadNotification(_t('feedback.auth.login.invalid'));
  147. Minz_Request::forward(['c' => 'auth', 'a' => 'login'], false);
  148. return;
  149. }
  150. } elseif (FreshRSS_Context::$system_conf->unsafe_autologin_enabled) {
  151. $username = Minz_Request::param('u', '');
  152. $password = Minz_Request::param('p', '');
  153. Minz_Request::_param('p');
  154. if (!$username) {
  155. return;
  156. }
  157. FreshRSS_FormAuth::deleteCookie();
  158. FreshRSS_Context::initUser($username);
  159. if (FreshRSS_Context::$user_conf == null) {
  160. return;
  161. }
  162. $s = FreshRSS_Context::$user_conf->passwordHash;
  163. $ok = password_verify($password, $s);
  164. unset($password);
  165. if ($ok) {
  166. Minz_Session::_params([
  167. 'currentUser' => $username,
  168. 'passwordHash' => $s,
  169. 'csrf' => false,
  170. ]);
  171. FreshRSS_Auth::giveAccess();
  172. Minz_Translate::init(FreshRSS_Context::$user_conf->language);
  173. Minz_Request::good(_t('feedback.auth.login.success'), [ 'c' => 'index', 'a' => 'index' ]);
  174. } else {
  175. Minz_Log::warning('Unsafe password mismatch for user ' . $username);
  176. Minz_Request::bad(
  177. _t('feedback.auth.login.invalid'),
  178. array('c' => 'auth', 'a' => 'login')
  179. );
  180. }
  181. }
  182. }
  183. /**
  184. * This action removes all accesses of the current user.
  185. */
  186. public function logoutAction() {
  187. invalidateHttpCache();
  188. FreshRSS_Auth::removeAccess();
  189. Minz_Request::good(_t('feedback.auth.logout.success'), [ 'c' => 'index', 'a' => 'index' ]);
  190. }
  191. /**
  192. * This action gives possibility to a user to create an account.
  193. *
  194. * The user is redirected to the home when logged in.
  195. *
  196. * A 403 is sent if max number of registrations is reached.
  197. */
  198. public function registerAction() {
  199. if (FreshRSS_Auth::hasAccess()) {
  200. Minz_Request::forward(array('c' => 'index', 'a' => 'index'), true);
  201. }
  202. if (max_registrations_reached()) {
  203. Minz_Error::error(403);
  204. }
  205. $this->view->show_tos_checkbox = file_exists(join_path(DATA_PATH, 'tos.html'));
  206. $this->view->show_email_field = FreshRSS_Context::$system_conf->force_email_validation;
  207. $this->view->preferred_language = Minz_Translate::getLanguage(null, Minz_Request::getPreferredLanguages(), FreshRSS_Context::$system_conf->language);
  208. FreshRSS_View::prependTitle(_t('gen.auth.registration.title') . ' · ');
  209. }
  210. }