You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

keys.go 12KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337
  1. // Copyright 2014 The Gogs Authors. All rights reserved.
  2. // Copyright 2018 The Gitea Authors. All rights reserved.
  3. // SPDX-License-Identifier: MIT
  4. package setting
  5. import (
  6. "fmt"
  7. "net/http"
  8. asymkey_model "code.gitea.io/gitea/models/asymkey"
  9. "code.gitea.io/gitea/models/db"
  10. "code.gitea.io/gitea/modules/base"
  11. "code.gitea.io/gitea/modules/setting"
  12. "code.gitea.io/gitea/modules/web"
  13. asymkey_service "code.gitea.io/gitea/services/asymkey"
  14. "code.gitea.io/gitea/services/context"
  15. "code.gitea.io/gitea/services/forms"
  16. )
  17. const (
  18. tplSettingsKeys base.TplName = "user/settings/keys"
  19. )
  20. // Keys render user's SSH/GPG public keys page
  21. func Keys(ctx *context.Context) {
  22. ctx.Data["Title"] = ctx.Tr("settings.ssh_gpg_keys")
  23. ctx.Data["PageIsSettingsKeys"] = true
  24. ctx.Data["DisableSSH"] = setting.SSH.Disabled
  25. ctx.Data["BuiltinSSH"] = setting.SSH.StartBuiltinServer
  26. ctx.Data["AllowPrincipals"] = setting.SSH.AuthorizedPrincipalsEnabled
  27. loadKeysData(ctx)
  28. ctx.HTML(http.StatusOK, tplSettingsKeys)
  29. }
  30. // KeysPost response for change user's SSH/GPG keys
  31. func KeysPost(ctx *context.Context) {
  32. form := web.GetForm(ctx).(*forms.AddKeyForm)
  33. ctx.Data["Title"] = ctx.Tr("settings")
  34. ctx.Data["PageIsSettingsKeys"] = true
  35. ctx.Data["DisableSSH"] = setting.SSH.Disabled
  36. ctx.Data["BuiltinSSH"] = setting.SSH.StartBuiltinServer
  37. ctx.Data["AllowPrincipals"] = setting.SSH.AuthorizedPrincipalsEnabled
  38. if ctx.HasError() {
  39. loadKeysData(ctx)
  40. ctx.HTML(http.StatusOK, tplSettingsKeys)
  41. return
  42. }
  43. switch form.Type {
  44. case "principal":
  45. content, err := asymkey_model.CheckPrincipalKeyString(ctx, ctx.Doer, form.Content)
  46. if err != nil {
  47. if db.IsErrSSHDisabled(err) {
  48. ctx.Flash.Info(ctx.Tr("settings.ssh_disabled"))
  49. } else {
  50. ctx.Flash.Error(ctx.Tr("form.invalid_ssh_principal", err.Error()))
  51. }
  52. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  53. return
  54. }
  55. if _, err = asymkey_service.AddPrincipalKey(ctx, ctx.Doer.ID, content, 0); err != nil {
  56. ctx.Data["HasPrincipalError"] = true
  57. switch {
  58. case asymkey_model.IsErrKeyAlreadyExist(err), asymkey_model.IsErrKeyNameAlreadyUsed(err):
  59. loadKeysData(ctx)
  60. ctx.Data["Err_Content"] = true
  61. ctx.RenderWithErr(ctx.Tr("settings.ssh_principal_been_used"), tplSettingsKeys, &form)
  62. default:
  63. ctx.ServerError("AddPrincipalKey", err)
  64. }
  65. return
  66. }
  67. ctx.Flash.Success(ctx.Tr("settings.add_principal_success", form.Content))
  68. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  69. case "gpg":
  70. if setting.Admin.UserDisabledFeatures.Contains(setting.UserFeatureManageGPGKeys) {
  71. ctx.NotFound("Not Found", fmt.Errorf("gpg keys setting is not allowed to be visited"))
  72. return
  73. }
  74. token := asymkey_model.VerificationToken(ctx.Doer, 1)
  75. lastToken := asymkey_model.VerificationToken(ctx.Doer, 0)
  76. keys, err := asymkey_model.AddGPGKey(ctx, ctx.Doer.ID, form.Content, token, form.Signature)
  77. if err != nil && asymkey_model.IsErrGPGInvalidTokenSignature(err) {
  78. keys, err = asymkey_model.AddGPGKey(ctx, ctx.Doer.ID, form.Content, lastToken, form.Signature)
  79. }
  80. if err != nil {
  81. ctx.Data["HasGPGError"] = true
  82. switch {
  83. case asymkey_model.IsErrGPGKeyParsing(err):
  84. ctx.Flash.Error(ctx.Tr("form.invalid_gpg_key", err.Error()))
  85. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  86. case asymkey_model.IsErrGPGKeyIDAlreadyUsed(err):
  87. loadKeysData(ctx)
  88. ctx.Data["Err_Content"] = true
  89. ctx.RenderWithErr(ctx.Tr("settings.gpg_key_id_used"), tplSettingsKeys, &form)
  90. case asymkey_model.IsErrGPGInvalidTokenSignature(err):
  91. loadKeysData(ctx)
  92. ctx.Data["Err_Content"] = true
  93. ctx.Data["Err_Signature"] = true
  94. keyID := err.(asymkey_model.ErrGPGInvalidTokenSignature).ID
  95. ctx.Data["KeyID"] = keyID
  96. ctx.Data["PaddedKeyID"] = asymkey_model.PaddedKeyID(keyID)
  97. ctx.RenderWithErr(ctx.Tr("settings.gpg_invalid_token_signature"), tplSettingsKeys, &form)
  98. case asymkey_model.IsErrGPGNoEmailFound(err):
  99. loadKeysData(ctx)
  100. ctx.Data["Err_Content"] = true
  101. ctx.Data["Err_Signature"] = true
  102. keyID := err.(asymkey_model.ErrGPGNoEmailFound).ID
  103. ctx.Data["KeyID"] = keyID
  104. ctx.Data["PaddedKeyID"] = asymkey_model.PaddedKeyID(keyID)
  105. ctx.RenderWithErr(ctx.Tr("settings.gpg_no_key_email_found"), tplSettingsKeys, &form)
  106. default:
  107. ctx.ServerError("AddPublicKey", err)
  108. }
  109. return
  110. }
  111. keyIDs := ""
  112. for _, key := range keys {
  113. keyIDs += key.KeyID
  114. keyIDs += ", "
  115. }
  116. if len(keyIDs) > 0 {
  117. keyIDs = keyIDs[:len(keyIDs)-2]
  118. }
  119. ctx.Flash.Success(ctx.Tr("settings.add_gpg_key_success", keyIDs))
  120. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  121. case "verify_gpg":
  122. token := asymkey_model.VerificationToken(ctx.Doer, 1)
  123. lastToken := asymkey_model.VerificationToken(ctx.Doer, 0)
  124. keyID, err := asymkey_model.VerifyGPGKey(ctx, ctx.Doer.ID, form.KeyID, token, form.Signature)
  125. if err != nil && asymkey_model.IsErrGPGInvalidTokenSignature(err) {
  126. keyID, err = asymkey_model.VerifyGPGKey(ctx, ctx.Doer.ID, form.KeyID, lastToken, form.Signature)
  127. }
  128. if err != nil {
  129. ctx.Data["HasGPGVerifyError"] = true
  130. switch {
  131. case asymkey_model.IsErrGPGInvalidTokenSignature(err):
  132. loadKeysData(ctx)
  133. ctx.Data["VerifyingID"] = form.KeyID
  134. ctx.Data["Err_Signature"] = true
  135. keyID := err.(asymkey_model.ErrGPGInvalidTokenSignature).ID
  136. ctx.Data["KeyID"] = keyID
  137. ctx.Data["PaddedKeyID"] = asymkey_model.PaddedKeyID(keyID)
  138. ctx.RenderWithErr(ctx.Tr("settings.gpg_invalid_token_signature"), tplSettingsKeys, &form)
  139. default:
  140. ctx.ServerError("VerifyGPG", err)
  141. }
  142. }
  143. ctx.Flash.Success(ctx.Tr("settings.verify_gpg_key_success", keyID))
  144. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  145. case "ssh":
  146. if setting.Admin.UserDisabledFeatures.Contains(setting.UserFeatureManageSSHKeys) {
  147. ctx.NotFound("Not Found", fmt.Errorf("ssh keys setting is not allowed to be visited"))
  148. return
  149. }
  150. content, err := asymkey_model.CheckPublicKeyString(form.Content)
  151. if err != nil {
  152. if db.IsErrSSHDisabled(err) {
  153. ctx.Flash.Info(ctx.Tr("settings.ssh_disabled"))
  154. } else if asymkey_model.IsErrKeyUnableVerify(err) {
  155. ctx.Flash.Info(ctx.Tr("form.unable_verify_ssh_key"))
  156. } else if err == asymkey_model.ErrKeyIsPrivate {
  157. ctx.Flash.Error(ctx.Tr("form.must_use_public_key"))
  158. } else {
  159. ctx.Flash.Error(ctx.Tr("form.invalid_ssh_key", err.Error()))
  160. }
  161. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  162. return
  163. }
  164. if _, err = asymkey_model.AddPublicKey(ctx, ctx.Doer.ID, form.Title, content, 0); err != nil {
  165. ctx.Data["HasSSHError"] = true
  166. switch {
  167. case asymkey_model.IsErrKeyAlreadyExist(err):
  168. loadKeysData(ctx)
  169. ctx.Data["Err_Content"] = true
  170. ctx.RenderWithErr(ctx.Tr("settings.ssh_key_been_used"), tplSettingsKeys, &form)
  171. case asymkey_model.IsErrKeyNameAlreadyUsed(err):
  172. loadKeysData(ctx)
  173. ctx.Data["Err_Title"] = true
  174. ctx.RenderWithErr(ctx.Tr("settings.ssh_key_name_used"), tplSettingsKeys, &form)
  175. case asymkey_model.IsErrKeyUnableVerify(err):
  176. ctx.Flash.Info(ctx.Tr("form.unable_verify_ssh_key"))
  177. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  178. default:
  179. ctx.ServerError("AddPublicKey", err)
  180. }
  181. return
  182. }
  183. ctx.Flash.Success(ctx.Tr("settings.add_key_success", form.Title))
  184. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  185. case "verify_ssh":
  186. if setting.Admin.UserDisabledFeatures.Contains(setting.UserFeatureManageSSHKeys) {
  187. ctx.NotFound("Not Found", fmt.Errorf("ssh keys setting is not allowed to be visited"))
  188. return
  189. }
  190. token := asymkey_model.VerificationToken(ctx.Doer, 1)
  191. lastToken := asymkey_model.VerificationToken(ctx.Doer, 0)
  192. fingerprint, err := asymkey_model.VerifySSHKey(ctx, ctx.Doer.ID, form.Fingerprint, token, form.Signature)
  193. if err != nil && asymkey_model.IsErrSSHInvalidTokenSignature(err) {
  194. fingerprint, err = asymkey_model.VerifySSHKey(ctx, ctx.Doer.ID, form.Fingerprint, lastToken, form.Signature)
  195. }
  196. if err != nil {
  197. ctx.Data["HasSSHVerifyError"] = true
  198. switch {
  199. case asymkey_model.IsErrSSHInvalidTokenSignature(err):
  200. loadKeysData(ctx)
  201. ctx.Data["Err_Signature"] = true
  202. ctx.Data["Fingerprint"] = err.(asymkey_model.ErrSSHInvalidTokenSignature).Fingerprint
  203. ctx.RenderWithErr(ctx.Tr("settings.ssh_invalid_token_signature"), tplSettingsKeys, &form)
  204. default:
  205. ctx.ServerError("VerifySSH", err)
  206. }
  207. }
  208. ctx.Flash.Success(ctx.Tr("settings.verify_ssh_key_success", fingerprint))
  209. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  210. default:
  211. ctx.Flash.Warning("Function not implemented")
  212. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  213. }
  214. }
  215. // DeleteKey response for delete user's SSH/GPG key
  216. func DeleteKey(ctx *context.Context) {
  217. switch ctx.FormString("type") {
  218. case "gpg":
  219. if setting.Admin.UserDisabledFeatures.Contains(setting.UserFeatureManageGPGKeys) {
  220. ctx.NotFound("Not Found", fmt.Errorf("gpg keys setting is not allowed to be visited"))
  221. return
  222. }
  223. if err := asymkey_model.DeleteGPGKey(ctx, ctx.Doer, ctx.FormInt64("id")); err != nil {
  224. ctx.Flash.Error("DeleteGPGKey: " + err.Error())
  225. } else {
  226. ctx.Flash.Success(ctx.Tr("settings.gpg_key_deletion_success"))
  227. }
  228. case "ssh":
  229. if setting.Admin.UserDisabledFeatures.Contains(setting.UserFeatureManageSSHKeys) {
  230. ctx.NotFound("Not Found", fmt.Errorf("ssh keys setting is not allowed to be visited"))
  231. return
  232. }
  233. keyID := ctx.FormInt64("id")
  234. external, err := asymkey_model.PublicKeyIsExternallyManaged(ctx, keyID)
  235. if err != nil {
  236. ctx.ServerError("sshKeysExternalManaged", err)
  237. return
  238. }
  239. if external {
  240. ctx.Flash.Error(ctx.Tr("settings.ssh_externally_managed"))
  241. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  242. return
  243. }
  244. if err := asymkey_service.DeletePublicKey(ctx, ctx.Doer, keyID); err != nil {
  245. ctx.Flash.Error("DeletePublicKey: " + err.Error())
  246. } else {
  247. ctx.Flash.Success(ctx.Tr("settings.ssh_key_deletion_success"))
  248. }
  249. case "principal":
  250. if err := asymkey_service.DeletePublicKey(ctx, ctx.Doer, ctx.FormInt64("id")); err != nil {
  251. ctx.Flash.Error("DeletePublicKey: " + err.Error())
  252. } else {
  253. ctx.Flash.Success(ctx.Tr("settings.ssh_principal_deletion_success"))
  254. }
  255. default:
  256. ctx.Flash.Warning("Function not implemented")
  257. ctx.Redirect(setting.AppSubURL + "/user/settings/keys")
  258. }
  259. ctx.JSONRedirect(setting.AppSubURL + "/user/settings/keys")
  260. }
  261. func loadKeysData(ctx *context.Context) {
  262. keys, err := db.Find[asymkey_model.PublicKey](ctx, asymkey_model.FindPublicKeyOptions{
  263. OwnerID: ctx.Doer.ID,
  264. NotKeytype: asymkey_model.KeyTypePrincipal,
  265. })
  266. if err != nil {
  267. ctx.ServerError("ListPublicKeys", err)
  268. return
  269. }
  270. ctx.Data["Keys"] = keys
  271. externalKeys, err := asymkey_model.PublicKeysAreExternallyManaged(ctx, keys)
  272. if err != nil {
  273. ctx.ServerError("ListPublicKeys", err)
  274. return
  275. }
  276. ctx.Data["ExternalKeys"] = externalKeys
  277. gpgkeys, err := db.Find[asymkey_model.GPGKey](ctx, asymkey_model.FindGPGKeyOptions{
  278. ListOptions: db.ListOptionsAll,
  279. OwnerID: ctx.Doer.ID,
  280. })
  281. if err != nil {
  282. ctx.ServerError("ListGPGKeys", err)
  283. return
  284. }
  285. if err := asymkey_model.GPGKeyList(gpgkeys).LoadSubKeys(ctx); err != nil {
  286. ctx.ServerError("LoadSubKeys", err)
  287. return
  288. }
  289. ctx.Data["GPGKeys"] = gpgkeys
  290. tokenToSign := asymkey_model.VerificationToken(ctx.Doer, 1)
  291. // generate a new aes cipher using the csrfToken
  292. ctx.Data["TokenToSign"] = tokenToSign
  293. principals, err := db.Find[asymkey_model.PublicKey](ctx, asymkey_model.FindPublicKeyOptions{
  294. ListOptions: db.ListOptionsAll,
  295. OwnerID: ctx.Doer.ID,
  296. KeyTypes: []asymkey_model.KeyType{asymkey_model.KeyTypePrincipal},
  297. })
  298. if err != nil {
  299. ctx.ServerError("ListPrincipalKeys", err)
  300. return
  301. }
  302. ctx.Data["Principals"] = principals
  303. ctx.Data["VerifyingID"] = ctx.FormString("verify_gpg")
  304. ctx.Data["VerifyingFingerprint"] = ctx.FormString("verify_ssh")
  305. ctx.Data["UserDisabledFeatures"] = &setting.Admin.UserDisabledFeatures
  306. }