From 80ba1c07bf614f8d116249ed904f61cd43bbaa35 Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Mon, 13 Nov 2017 12:18:47 +0000 Subject: [PATCH] Fix allow-register option in auth module config/auth_conf.xml.sample specifies that the possible values are True, False and Challenge. Broken in commit b3174efa8e2996dc8e05e85d563e546cc66e2848 . Also remove _get_bool(d, k, o) function in favour of the more explicit `string_as_bool(d.get(k, o))` . --- lib/galaxy/auth/__init__.py | 27 +++++++++++---------------- lib/galaxy/auth/providers/ldap_ad.py | 5 ++--- lib/galaxy/auth/providers/pam_auth.py | 9 ++++----- 3 files changed, 17 insertions(+), 24 deletions(-) diff --git a/lib/galaxy/auth/__init__.py b/lib/galaxy/auth/__init__.py index d8587fe0b18..c751be8afd3 100644 --- a/lib/galaxy/auth/__init__.py +++ b/lib/galaxy/auth/__init__.py @@ -7,7 +7,7 @@ import xml.etree.ElementTree from collections import namedtuple from galaxy.security.validate_user_input import validate_publicname -from galaxy.util import plugin_config, string_as_bool, string_as_bool_or_none +from galaxy.util import plugin_config, string_as_bool log = logging.getLogger(__name__) @@ -55,8 +55,8 @@ class AuthManager(object): message = '' status = 'done' for provider, options in self.active_authenticators(email, username, password): - allow_reg = _get_tri_state(options, 'allow-register', True) - if allow_reg is None: # i.e. challenge + allow_reg = _get_allow_register(options) + if allow_reg == 'challenge': auth_result, msg = provider.authenticate(email, username, password, options) if auth_result is True: break @@ -102,7 +102,7 @@ class AuthManager(object): else: break # end for loop if we can't make a unique username log.debug("Email: %s, auto-register with username: %s" % (auto_email, auto_username)) - return (_get_bool(options, 'auto-register', False), auto_email, auto_username) + return (string_as_bool(options.get('auto-register', False)), auto_email, auto_username) elif auth_result is None: log.debug("Email: %s, Username %s, stopping due to failed non-continue" % (auto_email, auto_username)) break # end authentication (skip rest) @@ -131,7 +131,7 @@ class AuthManager(object): else: auth_result = provider.authenticate_user(user, current_password, options) if auth_result is True: - if _get_bool(options, "allow-password-change", False): + if string_as_bool(options.get("allow-password-change", False)): return (True, '') # accept user else: return (False, 'Password change not supported.') @@ -160,15 +160,10 @@ class AuthManager(object): Authenticator = namedtuple('Authenticator', ['plugin', 'filter_template', 'options']) -def _get_bool(d, k, o): - if k in d: - return string_as_bool(d[k]) +def _get_allow_register(d): + s = d.get('allow-register', True) + lower_s = str(s).lower() + if lower_s == 'challenge': + return lower_s else: - return o - - -def _get_tri_state(d, k, o): - if k in d: - return string_as_bool_or_none(d[k]) - else: - return o + return string_as_bool(s) diff --git a/lib/galaxy/auth/providers/ldap_ad.py b/lib/galaxy/auth/providers/ldap_ad.py index 1d0d2ecd691..7917225d2ab 100644 --- a/lib/galaxy/auth/providers/ldap_ad.py +++ b/lib/galaxy/auth/providers/ldap_ad.py @@ -6,9 +6,8 @@ Created on 15/07/2014 import logging -from galaxy.auth import _get_bool from galaxy.exceptions import ConfigurationError - +from galaxy.util import string_as_bool from ..providers import AuthProvider log = logging.getLogger(__name__) @@ -84,7 +83,7 @@ class LDAP(AuthProvider): if options.get('continue-on-failure', 'False') == 'False': failure_mode = None # reject and do not continue - if _get_bool(options, 'login-use-username', False): + if string_as_bool(options.get('login-use-username', False)): if username is None: log.debug('LDAP authenticate: username must be used to login, cannot be None') return (failure_mode, '', '') diff --git a/lib/galaxy/auth/providers/pam_auth.py b/lib/galaxy/auth/providers/pam_auth.py index 8763a181933..3a103fa124e 100644 --- a/lib/galaxy/auth/providers/pam_auth.py +++ b/lib/galaxy/auth/providers/pam_auth.py @@ -7,8 +7,7 @@ import logging import shlex from subprocess import PIPE, Popen -from galaxy.auth import _get_bool - +from galaxy.util import string_as_bool from ..providers import AuthProvider log = logging.getLogger(__name__) @@ -65,7 +64,7 @@ class PAM(AuthProvider): log.debug("use username: {} use email {} email {} username {}".format(options.get('login-use-username'), options.get('login-use-email', False), email, username)) # check email based login first because if email exists in Galaxy DB # we will be given the "public name" as username - if _get_bool(options, 'login-use-email', False) and email is not None: + if string_as_bool(options.get('login-use-email', False)) and email is not None: if '@' in email: (email_user, email_domain) = email.split('@') pam_username = email_user @@ -82,7 +81,7 @@ class PAM(AuthProvider): else: log.debug('PAM authenticate: email must be used to login, but no valid email found') force_fail = True - elif _get_bool(options, 'login-use-username', False): + elif string_as_bool(options.get('login-use-username', False)): # if we get here via authenticate_user then # user will be "public name" and # email address will be as per registered user @@ -106,7 +105,7 @@ class PAM(AuthProvider): return None, '', '' pam_service = options.get('pam-service', 'galaxy') - use_helper = _get_bool(options, 'use-external-helper', False) + use_helper = string_as_bool(options.get('use-external-helper', False)) log.debug("PAM auth: will use external helper: {}".format(use_helper)) authenticated = False if use_helper: