From 95113b9c8473a6d33010e27910771299c25d35e0 Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Thu, 18 Aug 2016 16:02:20 +0100 Subject: [PATCH 1/6] Skip whoami check for LDAP servers not supporting it Fix #2805. --- lib/galaxy/auth/providers/ldap_ad.py | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/lib/galaxy/auth/providers/ldap_ad.py b/lib/galaxy/auth/providers/ldap_ad.py index 095bf0179ac..93650ee394e 100644 --- a/lib/galaxy/auth/providers/ldap_ad.py +++ b/lib/galaxy/auth/providers/ldap_ad.py @@ -162,12 +162,20 @@ class LDAP(AuthProvider): l = ldap.initialize(_get_subs(options, 'server', params)) l.protocol_version = 3 + bind_password = _get_subs(options, 'bind-password', params) + if not bind_password: + raise RuntimeError('LDAP authenticate: empty password') l.simple_bind_s(_get_subs( - options, 'bind-user', params), _get_subs(options, 'bind-password', params)) - whoami = l.whoami_s() - log.debug("LDAP authenticate: whoami is %s", whoami) - if whoami is None: - raise RuntimeError('LDAP authenticate: anonymous bind') + options, 'bind-user', params), bind_password) + try: + whoami = l.whoami_s() + except ldap.PROTOCOL_ERROR: + # The "Who am I?" extended operation is not supported by this LDAP server + pass + else: + log.debug("LDAP authenticate: whoami is %s", whoami) + if whoami is None: + raise RuntimeError('LDAP authenticate: anonymous bind') except Exception: log.warning('LDAP authenticate: bind exception', exc_info=True) return (failure_mode, '', '') From a2f0bdbded8a0ae84567ed12107fb6b4fd294d48 Mon Sep 17 00:00:00 2001 From: Martin Cech Date: Mon, 22 Aug 2016 13:34:18 -0400 Subject: [PATCH 2/6] disable conda_auto_init --- config/galaxy.ini.sample | 2 +- lib/galaxy/tools/deps/__init__.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/config/galaxy.ini.sample b/config/galaxy.ini.sample index f8b80f362ef..b590b8a589c 100644 --- a/config/galaxy.ini.sample +++ b/config/galaxy.ini.sample @@ -206,7 +206,7 @@ paste.app_factory = galaxy.web.buildapp:app_factory #conda_verbose_install_check=False # Set to True to instruct Galaxy to install Conda from the web automatically # if it cannot find a local copy and conda_exec is not configured. -#conda_auto_init = True +#conda_auto_init = False # File containing the Galaxy Tool Sheds that should be made available to # install from in the admin interface (.sample used if default does not exist). diff --git a/lib/galaxy/tools/deps/__init__.py b/lib/galaxy/tools/deps/__init__.py index 65971dfc825..f7afa8e8a65 100644 --- a/lib/galaxy/tools/deps/__init__.py +++ b/lib/galaxy/tools/deps/__init__.py @@ -22,7 +22,7 @@ EXTRA_CONFIG_KWDS = { 'conda_debug': None, 'conda_ensure_channels': 'r,bioconda,iuc', 'conda_auto_install': False, - 'conda_auto_init': True, + 'conda_auto_init': False, } CONFIG_VAL_NOT_FOUND = object() From 0cf4f7277e62f5f1318a0a6bba1afeacbce4ee10 Mon Sep 17 00:00:00 2001 From: John Chilton Date: Mon, 22 Aug 2016 14:30:13 -0400 Subject: [PATCH 3/6] Fix Galaxy for if pyuwsgi is install in .venv. --- lib/galaxy/util/postfork.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/galaxy/util/postfork.py b/lib/galaxy/util/postfork.py index 31b5cce271c..8cb7c86adec 100644 --- a/lib/galaxy/util/postfork.py +++ b/lib/galaxy/util/postfork.py @@ -7,8 +7,10 @@ Handle postfork functions under uWSGI # uwsgi-managed process. try: import uwsgi - if uwsgi.numproc: + if hasattr(uwsgi, "numproc"): process_is_uwsgi = True + else: + process_is_uwsgi = False except ImportError: # This is not a uwsgi process, or something went horribly wrong. process_is_uwsgi = False From 56914b2d203c0bb1b3835c533e7ff36ec0894721 Mon Sep 17 00:00:00 2001 From: Martin Cech Date: Mon, 22 Aug 2016 16:55:29 -0400 Subject: [PATCH 4/6] filter mail blacklist on the first domain level --- lib/galaxy/security/validate_user_input.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/lib/galaxy/security/validate_user_input.py b/lib/galaxy/security/validate_user_input.py index 101239adc3f..88c73d66642 100644 --- a/lib/galaxy/security/validate_user_input.py +++ b/lib/galaxy/security/validate_user_input.py @@ -34,7 +34,10 @@ def validate_email( trans, email, user=None, check_dup=True ): message = "User with that email already exists." # If the blacklist is not empty filter out the disposable domains. elif trans.app.config.blacklist_content is not None: - if email.split('@')[1] in trans.app.config.blacklist_content: + domain = email.split('@')[1] + if len( domain.split('.') ) > 2: + domain = ('.').join( domain.split('.')[-2:] ) + if domain in trans.app.config.blacklist_content: message = "Please enter your permanent email address." return message From bf43b2735e4aaf8becf776a3b99bb5f27694fecf Mon Sep 17 00:00:00 2001 From: John Chilton Date: Tue, 23 Aug 2016 09:34:09 -0400 Subject: [PATCH 5/6] Remove beaker session options from reports and shed. These were removed from Galaxy's config a while ago. --- config/reports.ini.sample | 7 ------- config/tool_shed.ini.sample | 7 ------- 2 files changed, 14 deletions(-) diff --git a/config/reports.ini.sample b/config/reports.ini.sample index 1b9a28a150b..545f9c99841 100644 --- a/config/reports.ini.sample +++ b/config/reports.ini.sample @@ -55,13 +55,6 @@ log_level = DEBUG # used for the cache #template_cache_path = database/compiled_templates/reports -# Session support (beaker) -use_beaker_session = True -session_type = memory -session_data_dir = %(here)s/database/beaker_sessions -session_key = galaxysessions -session_secret = changethisinproduction - # Configuration for debugging middleware #debug = False diff --git a/config/tool_shed.ini.sample b/config/tool_shed.ini.sample index cf017220d36..0f961fe1a25 100644 --- a/config/tool_shed.ini.sample +++ b/config/tool_shed.ini.sample @@ -53,13 +53,6 @@ new_file_path = database/tmp # standard). #pretty_datetime_format = $locale (UTC) -# Session support (beaker) -use_beaker_session = True -session_type = memory -session_data_dir = %(here)s/database/beaker_sessions -session_key = galaxysessions -session_secret = changethisinproduction - # -- Repository and Tool search # Using the script located at scripts/build_ts_whoosh_index.py # you can generate search index and allow full text API searching over From 55d4f13d75382ad1d6186d78e2e18de1bdd3322f Mon Sep 17 00:00:00 2001 From: John Chilton Date: Tue, 23 Aug 2016 09:42:48 -0400 Subject: [PATCH 6/6] Synchronize and update documentation for reports and shed. --- config/reports.ini.sample | 12 ++++++---- config/tool_shed.ini.sample | 31 +++++++++++++++++--------- lib/galaxy/webapps/tool_shed/config.py | 2 +- 3 files changed, 29 insertions(+), 16 deletions(-) diff --git a/config/reports.ini.sample b/config/reports.ini.sample index 545f9c99841..d9227d0366a 100644 --- a/config/reports.ini.sample +++ b/config/reports.ini.sample @@ -39,12 +39,16 @@ prefix = /reports # Specifies the factory for the universe WSGI application paste.app_factory = galaxy.webapps.reports.buildapp:app_factory -log_level = DEBUG + +# Verbosity of console log messages. Acceptable values can be found here: +# https://docs.python.org/2/library/logging.html#logging-levels +#log_level = DEBUG # Database connection -# Galaxy reports are intended for production Galaxy instances, so sqlite is not supported. -# You may use a SQLAlchemy connection string to specify an external database. -#database_connection = postgres:///galaxy_test?user=postgres&password=postgres +# Galaxy reports are intended for production Galaxy instances, so sqlite (and the default value +# below) is not supported. An SQLAlchemy connection string should be used specify an external +# database. +#database_connection = sqlite:///./database/universe.sqlite?isolation_level=IMMEDIATE # Where dataset files are saved #file_path = database/files diff --git a/config/tool_shed.ini.sample b/config/tool_shed.ini.sample index 0f961fe1a25..b8e498248d0 100644 --- a/config/tool_shed.ini.sample +++ b/config/tool_shed.ini.sample @@ -23,23 +23,27 @@ threadpool_kill_thread_limit = 10800 # Specifies the factory for the universe WSGI application paste.app_factory = galaxy.webapps.tool_shed.buildapp:app_factory + +# Verbosity of console log messages. Acceptable values can be found here: +# https://docs.python.org/2/library/logging.html#logging-levels #log_level = DEBUG -# Database connection -database_file = database/community.sqlite -# You may use a SQLAlchemy connection string to specify -# an external database instead -#database_connection = postgres:///community_test?host=/var/run/postgresql +# By default, the Tool Shed uses a SQLite database at 'database/community.sqlite'. You +# may use a SQLAlchemy connection string to specify an external database +# instead. This string takes many options which are explained in detail in the +# config file documentation. +#database_connection = sqlite:///./database/community.sqlite?isolation_level=IMMEDIATE # Where the hgweb.config file is stored. # The default is the Galaxy installation directory. #hgweb_config_dir = None # Where tool shed repositories are stored. -file_path = database/community_files +#file_path = database/community_files + # Temporary storage for additional datasets, # this should be shared through the cluster -new_file_path = database/tmp +#new_file_path = database/tmp # File containing old-style genome builds #builds_file_path = tool-data/shared/ucsc/builds.txt @@ -87,12 +91,14 @@ new_file_path = database/tmp # -- Users and Security -# Galaxy encodes various internal values when these values will be output in +# The Tool Shed encodes various internal values when these values will be output in # some format (for example, in a URL or cookie). You should set a key to be # used by the algorithm that encodes and decodes these values. It can be any # string. If left unchanged, anyone could construct a cookie that would grant # them access to others' sessions. -id_secret = changethisinproductiontoo +# One simple way to generate a value for this is with the shell command: +# python -c 'import time; print time.time()' | md5sum | cut -f 1 -d ' ' +#id_secret = changethisinproductiontoo # User authentication can be delegated to an upstream proxy server (usually # Apache). The upstream proxy should set a REMOTE_USER header in the request. @@ -119,8 +125,11 @@ id_secret = changethisinproductiontoo # NEVER enable this on a public site (even test or QA) #use_interactive = true -# this should be a comma-separated list of valid Galaxy users -#admin_users = user1@example.org,user2@example.org +# Administrative users - set this to a comma-separated list of valid Tool Shed +# users (email addresses). These users will have access to the Admin section +# of the server, and will have access to create users, groups, roles, +# libraries, and more. +#admin_users = None # Force everyone to log in (disable anonymous access) #require_login = False diff --git a/lib/galaxy/webapps/tool_shed/config.py b/lib/galaxy/webapps/tool_shed/config.py index 9d75231ebcf..6973c26a541 100644 --- a/lib/galaxy/webapps/tool_shed/config.py +++ b/lib/galaxy/webapps/tool_shed/config.py @@ -66,7 +66,7 @@ class Configuration( object ): self.new_file_path = resolve_path( kwargs.get( "new_file_path", "database/tmp" ), self.root ) self.cookie_path = kwargs.get( "cookie_path", "/" ) self.enable_quotas = string_as_bool( kwargs.get( 'enable_quotas', False ) ) - self.id_secret = kwargs.get( "id_secret", "USING THE DEFAULT IS NOT SECURE!" ) + self.id_secret = kwargs.get( "id_secret", "changethisinproductiontoo") # Tool stuff self.tool_path = resolve_path( kwargs.get( "tool_path", "tools" ), self.root ) self.tool_secret = kwargs.get( "tool_secret", "" )