]> source.dussan.org Git - nextcloud-server.git/commitdiff
Allow SSO authentication to provide a user secret 27929/head
authorMichaIng <micha@dietpi.com>
Mon, 12 Jul 2021 17:22:04 +0000 (19:22 +0200)
committerMichaIng <micha@dietpi.com>
Tue, 12 Jul 2022 17:19:00 +0000 (19:19 +0200)
Implementing PR #24837 from immerda

Signed-off-by: MichaIng <micha@dietpi.com>
lib/composer/composer/autoload_classmap.php
lib/composer/composer/autoload_static.php
lib/private/legacy/OC_User.php
lib/public/Authentication/IProvideUserSecretBackend.php [new file with mode: 0644]

index e3572aa833cfcdf647392933ec09c728335df791..6215ec92fcc84e737c93754a06b1e4c9482402db 100644 (file)
@@ -90,6 +90,7 @@ return array(
     'OCP\\Authentication\\Exceptions\\PasswordUnavailableException' => $baseDir . '/lib/public/Authentication/Exceptions/PasswordUnavailableException.php',
     'OCP\\Authentication\\IAlternativeLogin' => $baseDir . '/lib/public/Authentication/IAlternativeLogin.php',
     'OCP\\Authentication\\IApacheBackend' => $baseDir . '/lib/public/Authentication/IApacheBackend.php',
+    'OCP\\Authentication\\IProvideUserSecretBackend' => $baseDir . '/lib/public/Authentication/IProvideUserSecretBackend.php',
     'OCP\\Authentication\\LoginCredentials\\ICredentials' => $baseDir . '/lib/public/Authentication/LoginCredentials/ICredentials.php',
     'OCP\\Authentication\\LoginCredentials\\IStore' => $baseDir . '/lib/public/Authentication/LoginCredentials/IStore.php',
     'OCP\\Authentication\\TwoFactorAuth\\ALoginSetupController' => $baseDir . '/lib/public/Authentication/TwoFactorAuth/ALoginSetupController.php',
index 658f2cdfe2d2625af229ca7806c3cb67f1704436..84f4c83512049d051958d9714f09cba6f9926bac 100644 (file)
@@ -123,6 +123,7 @@ class ComposerStaticInit749170dad3f5e7f9ca158f5a9f04f6a2
         'OCP\\Authentication\\Exceptions\\PasswordUnavailableException' => __DIR__ . '/../../..' . '/lib/public/Authentication/Exceptions/PasswordUnavailableException.php',
         'OCP\\Authentication\\IAlternativeLogin' => __DIR__ . '/../../..' . '/lib/public/Authentication/IAlternativeLogin.php',
         'OCP\\Authentication\\IApacheBackend' => __DIR__ . '/../../..' . '/lib/public/Authentication/IApacheBackend.php',
+        'OCP\\Authentication\\IProvideUserSecretBackend' => __DIR__ . '/../../..' . '/lib/public/Authentication/IProvideUserSecretBackend.php',
         'OCP\\Authentication\\LoginCredentials\\ICredentials' => __DIR__ . '/../../..' . '/lib/public/Authentication/LoginCredentials/ICredentials.php',
         'OCP\\Authentication\\LoginCredentials\\IStore' => __DIR__ . '/../../..' . '/lib/public/Authentication/LoginCredentials/IStore.php',
         'OCP\\Authentication\\TwoFactorAuth\\ALoginSetupController' => __DIR__ . '/../../..' . '/lib/public/Authentication/TwoFactorAuth/ALoginSetupController.php',
index b7547be5e82b71f671741150c9ebbc2294aeaa06..de066e143b40539e578208d6eb2ccd9c806041b2 100644 (file)
@@ -178,7 +178,11 @@ class OC_User {
                                }
                                $userSession->setLoginName($uid);
                                $request = OC::$server->getRequest();
-                               $userSession->createSessionToken($request, $uid, $uid);
+                               $password = null;
+                               if ($backend instanceof \OCP\Authentication\IProvideUserSecretBackend) {
+                                       $password = $backend->getCurrentUserSecret();
+                               }
+                               $userSession->createSessionToken($request, $uid, $uid, $password);
                                $userSession->createRememberMeToken($userSession->getUser());
                                // setup the filesystem
                                OC_Util::setupFS($uid);
@@ -191,7 +195,7 @@ class OC_User {
                                        'post_login',
                                        [
                                                'uid' => $uid,
-                                               'password' => null,
+                                               'password' => $password,
                                                'isTokenLogin' => false,
                                        ]
                                );
diff --git a/lib/public/Authentication/IProvideUserSecretBackend.php b/lib/public/Authentication/IProvideUserSecretBackend.php
new file mode 100644 (file)
index 0000000..08f4043
--- /dev/null
@@ -0,0 +1,41 @@
+<?php
+/**
+ * @copyright Copyright (c) 2021, MichaIng <micha@dietpi.com>
+ *
+ * @author MichaIng <micha@dietpi.com>
+ *
+ * @license AGPL-3.0
+ *
+ * This code is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License, version 3,
+ * as published by the Free Software Foundation.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License, version 3,
+ * along with this program. If not, see <http://www.gnu.org/licenses/>
+ *
+ */
+// use OCP namespace for all classes that are considered public.
+// This means that they should be used by apps instead of the internal ownCloud classes
+
+namespace OCP\Authentication;
+
+/**
+ * Interface IProvideUserSecretBackend
+ *
+ * @since 23.0.0
+ */
+interface IProvideUserSecretBackend {
+
+       /**
+        * Optionally returns a stable per-user secret. This secret is for
+        * instance used to secure file encryption keys.
+        * @return string
+        * @since 23.0.0
+        */
+       public function getCurrentUserSecret(): string;
+}