You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

keys.go 8.9KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271
  1. // Copyright 2014 The Gogs Authors. All rights reserved.
  2. // Copyright 2018 The Gitea Authors. All rights reserved.
  3. // Use of this source code is governed by a MIT-style
  4. // license that can be found in the LICENSE file.
  5. package setting
  6. import (
  7. "net/http"
  8. asymkey_model "code.gitea.io/gitea/models/asymkey"
  9. "code.gitea.io/gitea/models/db"
  10. "code.gitea.io/gitea/modules/base"
  11. "code.gitea.io/gitea/modules/context"
  12. "code.gitea.io/gitea/modules/setting"
  13. "code.gitea.io/gitea/modules/web"
  14. asymkey_service "code.gitea.io/gitea/services/asymkey"
  15. "code.gitea.io/gitea/services/forms"
  16. )
  17. const (
  18. tplSettingsKeys base.TplName = "user/settings/keys"
  19. )
  20. // Keys render user's SSH/GPG public keys page
  21. func Keys(ctx *context.Context) {
  22. ctx.Data["Title"] = ctx.Tr("settings")
  23. ctx.Data["PageIsSettingsKeys"] = true
  24. ctx.Data["DisableSSH"] = setting.SSH.Disabled
  25. ctx.Data["BuiltinSSH"] = setting.SSH.StartBuiltinServer
  26. ctx.Data["AllowPrincipals"] = setting.SSH.AuthorizedPrincipalsEnabled
  27. loadKeysData(ctx)
  28. ctx.HTML(http.StatusOK, tplSettingsKeys)
  29. }
  30. // KeysPost response for change user's SSH/GPG keys
  31. func KeysPost(ctx *context.Context) {
  32. form := web.GetForm(ctx).(*forms.AddKeyForm)
  33. ctx.Data["Title"] = ctx.Tr("settings")
  34. ctx.Data["PageIsSettingsKeys"] = true
  35. ctx.Data["DisableSSH"] = setting.SSH.Disabled
  36. ctx.Data["BuiltinSSH"] = setting.SSH.StartBuiltinServer
  37. ctx.Data["AllowPrincipals"] = setting.SSH.AuthorizedPrincipalsEnabled
  38. if ctx.HasError() {
  39. loadKeysData(ctx)
  40. ctx.HTML(http.StatusOK, tplSettingsKeys)
  41. return
  42. }
  43. switch form.Type {
  44. case "principal":
  45. content, err := asymkey_model.CheckPrincipalKeyString(ctx.User, form.Content)
  46. if err != nil {
  47. if db.IsErrSSHDisabled(err) {
  48. ctx.Flash.Info(ctx.Tr("settings.ssh_disabled"))
  49. } else {
  50. ctx.Flash.Error(ctx.Tr("form.invalid_ssh_principal", err.Error()))
  51. }
  52. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  53. return
  54. }
  55. if _, err = asymkey_model.AddPrincipalKey(ctx.User.ID, content, 0); err != nil {
  56. ctx.Data["HasPrincipalError"] = true
  57. switch {
  58. case asymkey_model.IsErrKeyAlreadyExist(err), asymkey_model.IsErrKeyNameAlreadyUsed(err):
  59. loadKeysData(ctx)
  60. ctx.Data["Err_Content"] = true
  61. ctx.RenderWithErr(ctx.Tr("settings.ssh_principal_been_used"), tplSettingsKeys, &form)
  62. default:
  63. ctx.ServerError("AddPrincipalKey", err)
  64. }
  65. return
  66. }
  67. ctx.Flash.Success(ctx.Tr("settings.add_principal_success", form.Content))
  68. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  69. case "gpg":
  70. token := asymkey_model.VerificationToken(ctx.User, 1)
  71. lastToken := asymkey_model.VerificationToken(ctx.User, 0)
  72. keys, err := asymkey_model.AddGPGKey(ctx.User.ID, form.Content, token, form.Signature)
  73. if err != nil && asymkey_model.IsErrGPGInvalidTokenSignature(err) {
  74. keys, err = asymkey_model.AddGPGKey(ctx.User.ID, form.Content, lastToken, form.Signature)
  75. }
  76. if err != nil {
  77. ctx.Data["HasGPGError"] = true
  78. switch {
  79. case asymkey_model.IsErrGPGKeyParsing(err):
  80. ctx.Flash.Error(ctx.Tr("form.invalid_gpg_key", err.Error()))
  81. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  82. case asymkey_model.IsErrGPGKeyIDAlreadyUsed(err):
  83. loadKeysData(ctx)
  84. ctx.Data["Err_Content"] = true
  85. ctx.RenderWithErr(ctx.Tr("settings.gpg_key_id_used"), tplSettingsKeys, &form)
  86. case asymkey_model.IsErrGPGInvalidTokenSignature(err):
  87. loadKeysData(ctx)
  88. ctx.Data["Err_Content"] = true
  89. ctx.Data["Err_Signature"] = true
  90. ctx.Data["KeyID"] = err.(asymkey_model.ErrGPGInvalidTokenSignature).ID
  91. ctx.RenderWithErr(ctx.Tr("settings.gpg_invalid_token_signature"), tplSettingsKeys, &form)
  92. case asymkey_model.IsErrGPGNoEmailFound(err):
  93. loadKeysData(ctx)
  94. ctx.Data["Err_Content"] = true
  95. ctx.Data["Err_Signature"] = true
  96. ctx.Data["KeyID"] = err.(asymkey_model.ErrGPGNoEmailFound).ID
  97. ctx.RenderWithErr(ctx.Tr("settings.gpg_no_key_email_found"), tplSettingsKeys, &form)
  98. default:
  99. ctx.ServerError("AddPublicKey", err)
  100. }
  101. return
  102. }
  103. keyIDs := ""
  104. for _, key := range keys {
  105. keyIDs += key.KeyID
  106. keyIDs += ", "
  107. }
  108. if len(keyIDs) > 0 {
  109. keyIDs = keyIDs[:len(keyIDs)-2]
  110. }
  111. ctx.Flash.Success(ctx.Tr("settings.add_gpg_key_success", keyIDs))
  112. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  113. case "verify_gpg":
  114. token := asymkey_model.VerificationToken(ctx.User, 1)
  115. lastToken := asymkey_model.VerificationToken(ctx.User, 0)
  116. keyID, err := asymkey_model.VerifyGPGKey(ctx.User.ID, form.KeyID, token, form.Signature)
  117. if err != nil && asymkey_model.IsErrGPGInvalidTokenSignature(err) {
  118. keyID, err = asymkey_model.VerifyGPGKey(ctx.User.ID, form.KeyID, lastToken, form.Signature)
  119. }
  120. if err != nil {
  121. ctx.Data["HasGPGVerifyError"] = true
  122. switch {
  123. case asymkey_model.IsErrGPGInvalidTokenSignature(err):
  124. loadKeysData(ctx)
  125. ctx.Data["VerifyingID"] = form.KeyID
  126. ctx.Data["Err_Signature"] = true
  127. ctx.Data["KeyID"] = err.(asymkey_model.ErrGPGInvalidTokenSignature).ID
  128. ctx.RenderWithErr(ctx.Tr("settings.gpg_invalid_token_signature"), tplSettingsKeys, &form)
  129. default:
  130. ctx.ServerError("VerifyGPG", err)
  131. }
  132. }
  133. ctx.Flash.Success(ctx.Tr("settings.verify_gpg_key_success", keyID))
  134. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  135. case "ssh":
  136. content, err := asymkey_model.CheckPublicKeyString(form.Content)
  137. if err != nil {
  138. if db.IsErrSSHDisabled(err) {
  139. ctx.Flash.Info(ctx.Tr("settings.ssh_disabled"))
  140. } else if asymkey_model.IsErrKeyUnableVerify(err) {
  141. ctx.Flash.Info(ctx.Tr("form.unable_verify_ssh_key"))
  142. } else {
  143. ctx.Flash.Error(ctx.Tr("form.invalid_ssh_key", err.Error()))
  144. }
  145. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  146. return
  147. }
  148. if _, err = asymkey_model.AddPublicKey(ctx.User.ID, form.Title, content, 0); err != nil {
  149. ctx.Data["HasSSHError"] = true
  150. switch {
  151. case asymkey_model.IsErrKeyAlreadyExist(err):
  152. loadKeysData(ctx)
  153. ctx.Data["Err_Content"] = true
  154. ctx.RenderWithErr(ctx.Tr("settings.ssh_key_been_used"), tplSettingsKeys, &form)
  155. case asymkey_model.IsErrKeyNameAlreadyUsed(err):
  156. loadKeysData(ctx)
  157. ctx.Data["Err_Title"] = true
  158. ctx.RenderWithErr(ctx.Tr("settings.ssh_key_name_used"), tplSettingsKeys, &form)
  159. case asymkey_model.IsErrKeyUnableVerify(err):
  160. ctx.Flash.Info(ctx.Tr("form.unable_verify_ssh_key"))
  161. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  162. default:
  163. ctx.ServerError("AddPublicKey", err)
  164. }
  165. return
  166. }
  167. ctx.Flash.Success(ctx.Tr("settings.add_key_success", form.Title))
  168. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  169. default:
  170. ctx.Flash.Warning("Function not implemented")
  171. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  172. }
  173. }
  174. // DeleteKey response for delete user's SSH/GPG key
  175. func DeleteKey(ctx *context.Context) {
  176. switch ctx.FormString("type") {
  177. case "gpg":
  178. if err := asymkey_model.DeleteGPGKey(ctx.User, ctx.FormInt64("id")); err != nil {
  179. ctx.Flash.Error("DeleteGPGKey: " + err.Error())
  180. } else {
  181. ctx.Flash.Success(ctx.Tr("settings.gpg_key_deletion_success"))
  182. }
  183. case "ssh":
  184. keyID := ctx.FormInt64("id")
  185. external, err := asymkey_model.PublicKeyIsExternallyManaged(keyID)
  186. if err != nil {
  187. ctx.ServerError("sshKeysExternalManaged", err)
  188. return
  189. }
  190. if external {
  191. ctx.Flash.Error(ctx.Tr("settings.ssh_externally_managed"))
  192. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  193. return
  194. }
  195. if err := asymkey_service.DeletePublicKey(ctx.User, keyID); err != nil {
  196. ctx.Flash.Error("DeletePublicKey: " + err.Error())
  197. } else {
  198. ctx.Flash.Success(ctx.Tr("settings.ssh_key_deletion_success"))
  199. }
  200. case "principal":
  201. if err := asymkey_service.DeletePublicKey(ctx.User, ctx.FormInt64("id")); err != nil {
  202. ctx.Flash.Error("DeletePublicKey: " + err.Error())
  203. } else {
  204. ctx.Flash.Success(ctx.Tr("settings.ssh_principal_deletion_success"))
  205. }
  206. default:
  207. ctx.Flash.Warning("Function not implemented")
  208. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  209. }
  210. ctx.JSON(http.StatusOK, map[string]interface{}{
  211. "redirect": setting.AppSubURL + "/user/settings/keys",
  212. })
  213. }
  214. func loadKeysData(ctx *context.Context) {
  215. keys, err := asymkey_model.ListPublicKeys(ctx.User.ID, db.ListOptions{})
  216. if err != nil {
  217. ctx.ServerError("ListPublicKeys", err)
  218. return
  219. }
  220. ctx.Data["Keys"] = keys
  221. externalKeys, err := asymkey_model.PublicKeysAreExternallyManaged(keys)
  222. if err != nil {
  223. ctx.ServerError("ListPublicKeys", err)
  224. return
  225. }
  226. ctx.Data["ExternalKeys"] = externalKeys
  227. gpgkeys, err := asymkey_model.ListGPGKeys(db.DefaultContext, ctx.User.ID, db.ListOptions{})
  228. if err != nil {
  229. ctx.ServerError("ListGPGKeys", err)
  230. return
  231. }
  232. ctx.Data["GPGKeys"] = gpgkeys
  233. tokenToSign := asymkey_model.VerificationToken(ctx.User, 1)
  234. // generate a new aes cipher using the csrfToken
  235. ctx.Data["TokenToSign"] = tokenToSign
  236. principals, err := asymkey_model.ListPrincipalKeys(ctx.User.ID, db.ListOptions{})
  237. if err != nil {
  238. ctx.ServerError("ListPrincipalKeys", err)
  239. return
  240. }
  241. ctx.Data["Principals"] = principals
  242. ctx.Data["VerifyingID"] = ctx.FormString("verify_gpg")
  243. }