Merge pull request #9205 from ioito/hotfix/qx-passord-validate

fix(region): validate invalid character for password
This commit is contained in:
Zexi Li
2020-12-07 10:52:03 +08:00
committed by GitHub
15 changed files with 5142 additions and 3549 deletions
+3206 -2835
View File
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+3 -2
View File
@@ -445,8 +445,9 @@ func (manager *SClouduserManager) ValidateCreateData(ctx context.Context, userCr
}
if len(input.Password) > 0 {
if !seclib2.MeetComplxity(input.Password) {
return input, httperrors.NewWeakPasswordError()
err = seclib2.ValidatePassword(input.Password)
if err != nil {
return input, err
}
}
+6 -4
View File
@@ -303,8 +303,9 @@ func (manager *SDBInstanceAccountManager) FilterByUniqValues(q *sqlchemy.SQuery,
func (manager *SDBInstanceAccountManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, input api.DBInstanceAccountCreateInput) (*jsonutils.JSONDict, error) {
if len(input.Password) > 0 {
if !seclib2.MeetComplxity(input.Password) {
return nil, httperrors.NewWeakPasswordError()
err := seclib2.ValidatePassword(input.Password)
if err != nil {
return nil, err
}
} else {
input.Password = seclib2.RandomPassword2(12)
@@ -569,8 +570,9 @@ func (self *SDBInstanceAccount) PerformResetPassword(ctx context.Context, userCr
}
passwdStr, _ := data.GetString("password")
if len(passwdStr) > 0 {
if !seclib2.MeetComplxity(passwdStr) {
return nil, httperrors.NewWeakPasswordError()
err = seclib2.ValidatePassword(passwdStr)
if err != nil {
return nil, err
}
}
err = instance.GetRegion().GetDriver().ValidateResetDBInstancePassword(ctx, userCred, instance, self.Name)
+3 -2
View File
@@ -308,8 +308,9 @@ func (man *SDBInstanceManager) ValidateCreateData(ctx context.Context, userCred
}
if len(input.Password) > 0 {
if !seclib2.MeetComplxity(input.Password) {
return input, httperrors.NewWeakPasswordError()
err := seclib2.ValidatePassword(input.Password)
if err != nil {
return input, err
}
}
var vpc *SVpc
+6 -3
View File
@@ -473,9 +473,12 @@ func (self *SElasticcacheAccount) ValidatorResetPasswordData(ctx context.Context
}
}
passwd, err := data.GetString("password")
if err == nil && !seclib2.MeetComplxity(passwd) {
return nil, httperrors.NewWeakPasswordError()
passwd, _ := data.GetString("password")
if len(passwd) > 0 {
err := seclib2.ValidatePassword(passwd)
if err != nil {
return nil, err
}
}
privilegeV := validators.NewStringChoicesValidator("account_privilege", choices.NewChoices(api.ELASTIC_CACHE_ACCOUNT_PRIVILEGE_READ, api.ELASTIC_CACHE_ACCOUNT_PRIVILEGE_WRITE, api.ELASTIC_CACHE_ACCOUNT_PRIVILEGE_REPL)).Optional(true)
+3 -2
View File
@@ -1314,8 +1314,9 @@ func (self *SElasticcache) ValidatorResetPasswordData(ctx context.Context, userC
if password, err := data.GetString("password"); err != nil || len(password) == 0 {
return nil, httperrors.NewMissingParameterError("password")
} else {
if !seclib2.MeetComplxity(password) {
return nil, httperrors.NewWeakPasswordError()
err := seclib2.ValidatePassword(password)
if err != nil {
return nil, err
}
}
+6 -4
View File
@@ -613,8 +613,9 @@ func (self *SGuest) PerformDeploy(ctx context.Context, userCred mcclient.TokenCr
var resetPasswd bool
passwdStr, _ := kwargs.GetString("password")
if len(passwdStr) > 0 {
if !seclib2.MeetComplxity(passwdStr) {
return nil, httperrors.NewWeakPasswordError()
err := seclib2.ValidatePassword(passwdStr)
if err != nil {
return nil, err
}
resetPasswd = true
} else {
@@ -1484,8 +1485,9 @@ func (self *SGuest) PerformRebuildRoot(ctx context.Context, userCred mcclient.To
}
passwd := input.Password
if len(passwd) > 0 {
if !seclib2.MeetComplxity(passwd) {
return nil, httperrors.NewWeakPasswordError()
err = seclib2.ValidatePassword(passwd)
if err != nil {
return nil, err
}
}
+3 -2
View File
@@ -1118,8 +1118,9 @@ func (manager *SGuestManager) validateCreateData(
passwd := input.Password
if len(passwd) > 0 {
if !seclib2.MeetComplxity(passwd) {
return nil, httperrors.NewWeakPasswordError()
err = seclib2.ValidatePassword(passwd)
if err != nil {
return nil, err
}
resetPassword = true
input.ResetPassword = &resetPassword
+5 -3
View File
@@ -1197,8 +1197,9 @@ func (self *SAliyunRegionDriver) ValidateCreateElasticcacheData(ctx context.Cont
// validate password
if password, _ := data.GetString("password"); len(password) > 0 {
if !seclib2.MeetComplxity(password) {
return nil, httperrors.NewWeakPasswordError()
err := seclib2.ValidatePassword(password)
if err != nil {
return nil, err
}
}
@@ -1361,7 +1362,8 @@ func (self *SAliyunRegionDriver) ValidateCreateElasticcacheAccountData(ctx conte
}
passwd, _ := data.GetString("password")
if !seclib2.MeetComplxity(passwd) {
err := seclib2.ValidatePassword(passwd)
if err != nil {
return nil, httperrors.NewWeakPasswordError()
}
+3 -2
View File
@@ -2406,8 +2406,9 @@ func (self *SHuaWeiRegionDriver) ValidateCreateElasticcacheData(ctx context.Cont
// validate password
if password, _ := data.GetString("password"); len(password) > 0 {
if !seclib2.MeetComplxity(password) {
return nil, httperrors.NewWeakPasswordError()
err := seclib2.ValidatePassword(password)
if err != nil {
return nil, err
}
}
+6 -4
View File
@@ -1477,8 +1477,9 @@ func (self *SQcloudRegionDriver) ValidateCreateElasticcacheData(ctx context.Cont
// validate password
if password, _ := data.GetString("password"); len(password) > 0 {
if !seclib2.MeetComplxity(password) {
return nil, httperrors.NewWeakPasswordError()
err := seclib2.ValidatePassword(password)
if err != nil {
return nil, err
}
}
@@ -1700,8 +1701,9 @@ func (self *SQcloudRegionDriver) ValidateCreateElasticcacheAccountData(ctx conte
}
passwd, _ := data.GetString("password")
if !seclib2.MeetComplxity(passwd) {
return nil, httperrors.NewWeakPasswordError()
err := seclib2.ValidatePassword(passwd)
if err != nil {
return nil, err
}
return self.SManagedVirtualizationRegionDriver.ValidateCreateElasticcacheAccountData(ctx, userCred, ownerId, data)
+1 -1
View File
@@ -85,7 +85,7 @@ func NewInputParameterError(msg string, params ...interface{}) *httputils.JSONCl
}
func NewWeakPasswordError() *httputils.JSONClientError {
msg := ("password must be 12 chars of at least one digit, letter, uppercase letter and punctuate")
msg := ("password must be 12 chars of at least one digit, letter, uppercase letter and punctuate of @^-+=")
return httputils.NewJsonClientError(httpErrorCode[ErrWeakPassword], string(ErrWeakPassword), msg)
}
+17 -1
View File
@@ -21,6 +21,8 @@ import (
"strings"
"yunion.io/x/pkg/utils"
"yunion.io/x/onecloud/pkg/httperrors"
)
const (
@@ -40,6 +42,7 @@ type PasswordStrength struct {
Lowercases int
Uppercases int
Punctuats int
Invalid []byte
}
var WEAK_PASSWORDS []string = []string{
@@ -92,7 +95,7 @@ func randomPassword2(width int) string {
}
func AnalyzePasswordStrenth(passwd string) PasswordStrength {
ps := PasswordStrength{}
ps := PasswordStrength{Invalid: []byte{}}
for i := 0; i < len(passwd); i += 1 {
if strings.IndexByte(ALL_DIGITS, passwd[i]) >= 0 {
@@ -103,6 +106,8 @@ func AnalyzePasswordStrenth(passwd string) PasswordStrength {
ps.Uppercases += 1
} else if strings.IndexByte(PUNC, passwd[i]) >= 0 {
ps.Punctuats += 1
} else {
ps.Invalid = append(ps.Invalid, passwd[i])
}
}
return ps
@@ -120,6 +125,17 @@ func (ps PasswordStrength) MeetComplexity() bool {
}
}
func ValidatePassword(passwd string) error {
ps := AnalyzePasswordStrenth(passwd)
if len(ps.Invalid) > 0 {
return httperrors.NewInputParameterError("invalid characters %s", string(ps.Invalid))
}
if utils.IsInStringArray(passwd, WEAK_PASSWORDS) || !ps.MeetComplexity() {
return httperrors.NewWeakPasswordError()
}
return nil
}
func MeetComplxity(passwd string) bool {
if utils.IsInStringArray(passwd, WEAK_PASSWORDS) {
return false
+32
View File
@@ -18,6 +18,9 @@ import (
"math/rand"
"testing"
"time"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/util/httputils"
)
func TestRandomPassword2(t *testing.T) {
@@ -40,3 +43,32 @@ func TestMeetComplxity(t *testing.T) {
}
}
}
func TestPassword(t *testing.T) {
cases := []struct {
in string
valid bool
errClass string
invalidCharacters []byte
}{
{in: "123456", valid: false, errClass: httperrors.ErrWeakPassword.Error()},
{in: "123abcABC!@#", valid: false, invalidCharacters: []byte{'!', '#'}, errClass: httperrors.ErrInputParameter.Error()},
{in: "123abcABC-@=", valid: true},
}
for _, c := range cases {
ap := AnalyzePasswordStrenth(c.in)
if string(ap.Invalid) != string(c.invalidCharacters) {
t.Fatalf("%s invalid character %s != %s", c.in, string(ap.Invalid), string(c.invalidCharacters))
}
err := ValidatePassword(c.in)
if err != nil {
t.Logf("%s -> %v", c.in, err)
e := err.(*httputils.JSONClientError)
if e.Class != c.errClass {
t.Fatalf("%s invalid error class %s != %s", c.in, e.Class, c.errClass)
}
} else if !c.valid {
t.Fatalf("%s should be invalid", c.in)
}
}
}