mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #9205 from ioito/hotfix/qx-passord-validate
fix(region): validate invalid character for password
This commit is contained in:
+3206
-2835
File diff suppressed because it is too large
Load Diff
+1842
-684
File diff suppressed because it is too large
Load Diff
@@ -445,8 +445,9 @@ func (manager *SClouduserManager) ValidateCreateData(ctx context.Context, userCr
|
||||
}
|
||||
|
||||
if len(input.Password) > 0 {
|
||||
if !seclib2.MeetComplxity(input.Password) {
|
||||
return input, httperrors.NewWeakPasswordError()
|
||||
err = seclib2.ValidatePassword(input.Password)
|
||||
if err != nil {
|
||||
return input, err
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -303,8 +303,9 @@ func (manager *SDBInstanceAccountManager) FilterByUniqValues(q *sqlchemy.SQuery,
|
||||
|
||||
func (manager *SDBInstanceAccountManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, input api.DBInstanceAccountCreateInput) (*jsonutils.JSONDict, error) {
|
||||
if len(input.Password) > 0 {
|
||||
if !seclib2.MeetComplxity(input.Password) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err := seclib2.ValidatePassword(input.Password)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
} else {
|
||||
input.Password = seclib2.RandomPassword2(12)
|
||||
@@ -569,8 +570,9 @@ func (self *SDBInstanceAccount) PerformResetPassword(ctx context.Context, userCr
|
||||
}
|
||||
passwdStr, _ := data.GetString("password")
|
||||
if len(passwdStr) > 0 {
|
||||
if !seclib2.MeetComplxity(passwdStr) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err = seclib2.ValidatePassword(passwdStr)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
err = instance.GetRegion().GetDriver().ValidateResetDBInstancePassword(ctx, userCred, instance, self.Name)
|
||||
|
||||
@@ -308,8 +308,9 @@ func (man *SDBInstanceManager) ValidateCreateData(ctx context.Context, userCred
|
||||
}
|
||||
|
||||
if len(input.Password) > 0 {
|
||||
if !seclib2.MeetComplxity(input.Password) {
|
||||
return input, httperrors.NewWeakPasswordError()
|
||||
err := seclib2.ValidatePassword(input.Password)
|
||||
if err != nil {
|
||||
return input, err
|
||||
}
|
||||
}
|
||||
var vpc *SVpc
|
||||
|
||||
@@ -473,9 +473,12 @@ func (self *SElasticcacheAccount) ValidatorResetPasswordData(ctx context.Context
|
||||
}
|
||||
}
|
||||
|
||||
passwd, err := data.GetString("password")
|
||||
if err == nil && !seclib2.MeetComplxity(passwd) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
passwd, _ := data.GetString("password")
|
||||
if len(passwd) > 0 {
|
||||
err := seclib2.ValidatePassword(passwd)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
privilegeV := validators.NewStringChoicesValidator("account_privilege", choices.NewChoices(api.ELASTIC_CACHE_ACCOUNT_PRIVILEGE_READ, api.ELASTIC_CACHE_ACCOUNT_PRIVILEGE_WRITE, api.ELASTIC_CACHE_ACCOUNT_PRIVILEGE_REPL)).Optional(true)
|
||||
|
||||
@@ -1314,8 +1314,9 @@ func (self *SElasticcache) ValidatorResetPasswordData(ctx context.Context, userC
|
||||
if password, err := data.GetString("password"); err != nil || len(password) == 0 {
|
||||
return nil, httperrors.NewMissingParameterError("password")
|
||||
} else {
|
||||
if !seclib2.MeetComplxity(password) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err := seclib2.ValidatePassword(password)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -613,8 +613,9 @@ func (self *SGuest) PerformDeploy(ctx context.Context, userCred mcclient.TokenCr
|
||||
var resetPasswd bool
|
||||
passwdStr, _ := kwargs.GetString("password")
|
||||
if len(passwdStr) > 0 {
|
||||
if !seclib2.MeetComplxity(passwdStr) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err := seclib2.ValidatePassword(passwdStr)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
resetPasswd = true
|
||||
} else {
|
||||
@@ -1484,8 +1485,9 @@ func (self *SGuest) PerformRebuildRoot(ctx context.Context, userCred mcclient.To
|
||||
}
|
||||
passwd := input.Password
|
||||
if len(passwd) > 0 {
|
||||
if !seclib2.MeetComplxity(passwd) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err = seclib2.ValidatePassword(passwd)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -1118,8 +1118,9 @@ func (manager *SGuestManager) validateCreateData(
|
||||
|
||||
passwd := input.Password
|
||||
if len(passwd) > 0 {
|
||||
if !seclib2.MeetComplxity(passwd) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err = seclib2.ValidatePassword(passwd)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
resetPassword = true
|
||||
input.ResetPassword = &resetPassword
|
||||
|
||||
@@ -1197,8 +1197,9 @@ func (self *SAliyunRegionDriver) ValidateCreateElasticcacheData(ctx context.Cont
|
||||
|
||||
// validate password
|
||||
if password, _ := data.GetString("password"); len(password) > 0 {
|
||||
if !seclib2.MeetComplxity(password) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err := seclib2.ValidatePassword(password)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1361,7 +1362,8 @@ func (self *SAliyunRegionDriver) ValidateCreateElasticcacheAccountData(ctx conte
|
||||
}
|
||||
|
||||
passwd, _ := data.GetString("password")
|
||||
if !seclib2.MeetComplxity(passwd) {
|
||||
err := seclib2.ValidatePassword(passwd)
|
||||
if err != nil {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
}
|
||||
|
||||
|
||||
@@ -2406,8 +2406,9 @@ func (self *SHuaWeiRegionDriver) ValidateCreateElasticcacheData(ctx context.Cont
|
||||
|
||||
// validate password
|
||||
if password, _ := data.GetString("password"); len(password) > 0 {
|
||||
if !seclib2.MeetComplxity(password) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err := seclib2.ValidatePassword(password)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -1477,8 +1477,9 @@ func (self *SQcloudRegionDriver) ValidateCreateElasticcacheData(ctx context.Cont
|
||||
|
||||
// validate password
|
||||
if password, _ := data.GetString("password"); len(password) > 0 {
|
||||
if !seclib2.MeetComplxity(password) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err := seclib2.ValidatePassword(password)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1700,8 +1701,9 @@ func (self *SQcloudRegionDriver) ValidateCreateElasticcacheAccountData(ctx conte
|
||||
}
|
||||
|
||||
passwd, _ := data.GetString("password")
|
||||
if !seclib2.MeetComplxity(passwd) {
|
||||
return nil, httperrors.NewWeakPasswordError()
|
||||
err := seclib2.ValidatePassword(passwd)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return self.SManagedVirtualizationRegionDriver.ValidateCreateElasticcacheAccountData(ctx, userCred, ownerId, data)
|
||||
|
||||
@@ -85,7 +85,7 @@ func NewInputParameterError(msg string, params ...interface{}) *httputils.JSONCl
|
||||
}
|
||||
|
||||
func NewWeakPasswordError() *httputils.JSONClientError {
|
||||
msg := ("password must be 12 chars of at least one digit, letter, uppercase letter and punctuate")
|
||||
msg := ("password must be 12 chars of at least one digit, letter, uppercase letter and punctuate of @^-+=")
|
||||
return httputils.NewJsonClientError(httpErrorCode[ErrWeakPassword], string(ErrWeakPassword), msg)
|
||||
}
|
||||
|
||||
|
||||
@@ -21,6 +21,8 @@ import (
|
||||
"strings"
|
||||
|
||||
"yunion.io/x/pkg/utils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -40,6 +42,7 @@ type PasswordStrength struct {
|
||||
Lowercases int
|
||||
Uppercases int
|
||||
Punctuats int
|
||||
Invalid []byte
|
||||
}
|
||||
|
||||
var WEAK_PASSWORDS []string = []string{
|
||||
@@ -92,7 +95,7 @@ func randomPassword2(width int) string {
|
||||
}
|
||||
|
||||
func AnalyzePasswordStrenth(passwd string) PasswordStrength {
|
||||
ps := PasswordStrength{}
|
||||
ps := PasswordStrength{Invalid: []byte{}}
|
||||
|
||||
for i := 0; i < len(passwd); i += 1 {
|
||||
if strings.IndexByte(ALL_DIGITS, passwd[i]) >= 0 {
|
||||
@@ -103,6 +106,8 @@ func AnalyzePasswordStrenth(passwd string) PasswordStrength {
|
||||
ps.Uppercases += 1
|
||||
} else if strings.IndexByte(PUNC, passwd[i]) >= 0 {
|
||||
ps.Punctuats += 1
|
||||
} else {
|
||||
ps.Invalid = append(ps.Invalid, passwd[i])
|
||||
}
|
||||
}
|
||||
return ps
|
||||
@@ -120,6 +125,17 @@ func (ps PasswordStrength) MeetComplexity() bool {
|
||||
}
|
||||
}
|
||||
|
||||
func ValidatePassword(passwd string) error {
|
||||
ps := AnalyzePasswordStrenth(passwd)
|
||||
if len(ps.Invalid) > 0 {
|
||||
return httperrors.NewInputParameterError("invalid characters %s", string(ps.Invalid))
|
||||
}
|
||||
if utils.IsInStringArray(passwd, WEAK_PASSWORDS) || !ps.MeetComplexity() {
|
||||
return httperrors.NewWeakPasswordError()
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func MeetComplxity(passwd string) bool {
|
||||
if utils.IsInStringArray(passwd, WEAK_PASSWORDS) {
|
||||
return false
|
||||
|
||||
@@ -18,6 +18,9 @@ import (
|
||||
"math/rand"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/util/httputils"
|
||||
)
|
||||
|
||||
func TestRandomPassword2(t *testing.T) {
|
||||
@@ -40,3 +43,32 @@ func TestMeetComplxity(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestPassword(t *testing.T) {
|
||||
cases := []struct {
|
||||
in string
|
||||
valid bool
|
||||
errClass string
|
||||
invalidCharacters []byte
|
||||
}{
|
||||
{in: "123456", valid: false, errClass: httperrors.ErrWeakPassword.Error()},
|
||||
{in: "123abcABC!@#", valid: false, invalidCharacters: []byte{'!', '#'}, errClass: httperrors.ErrInputParameter.Error()},
|
||||
{in: "123abcABC-@=", valid: true},
|
||||
}
|
||||
for _, c := range cases {
|
||||
ap := AnalyzePasswordStrenth(c.in)
|
||||
if string(ap.Invalid) != string(c.invalidCharacters) {
|
||||
t.Fatalf("%s invalid character %s != %s", c.in, string(ap.Invalid), string(c.invalidCharacters))
|
||||
}
|
||||
err := ValidatePassword(c.in)
|
||||
if err != nil {
|
||||
t.Logf("%s -> %v", c.in, err)
|
||||
e := err.(*httputils.JSONClientError)
|
||||
if e.Class != c.errClass {
|
||||
t.Fatalf("%s invalid error class %s != %s", c.in, e.Class, c.errClass)
|
||||
}
|
||||
} else if !c.valid {
|
||||
t.Fatalf("%s should be invalid", c.in)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user