Files
teleport/lib/web/mfa_codec.go
T
Alan Parra bac0ccdc99 Remove U2F support (#10476)
Follows up on #10466 by removing remaining U2F references, including proto/gRPC
surface and the lib/auth/u2f package itself.

#10375

* Remove U2F from lib/auth/ (1)
* Remove U2F from lib/auth/ (2)
* Remove U2F from lib/auth/ (3)
* Remove U2F from lib/services/
* Remove U2F from tsh mfa add suggestions
* Remove U2F protos
* Update generated protos
* Cleanup a few stragglers
* Remove lib/auth/u2f package
* Fix references to auth.MFAAuthenticateChallenge
* Revert needless lib/auth/password.go change
* Update e/ to ad8fd4a (U2F cleanup)
* Fix stragglers from latest master rebase
* Fix lint and compile failures
2022-02-24 19:54:28 +00:00

98 lines
3.1 KiB
Go

/*
Copyright 2022 Gravitational, Inc.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package web
import (
"bytes"
"encoding/json"
proto "github.com/gogo/protobuf/proto"
authproto "github.com/gravitational/teleport/api/client/proto"
"github.com/gravitational/teleport/lib/client"
"github.com/gravitational/teleport/lib/defaults"
"github.com/gravitational/teleport/lib/srv/desktop/tdp"
"github.com/gravitational/teleport/lib/web/mfajson"
"github.com/gravitational/trace"
)
// mfaCodec converts MFA challenges/responses between their native types and a format
// suitable for being sent over a network connection.
type mfaCodec interface {
// encode converts an MFA challenge to wire format
encode(chal *client.MFAAuthenticateChallenge, envelopeType string) ([]byte, error)
// decode parses an MFA authentication response
decode(bytes []byte, envelopeType string) (*authproto.MFAAuthenticateResponse, error)
}
// protobufMFACodec converts MFA challenges and responses to the protobuf
// format used by SSH web sessions
type protobufMFACodec struct{}
func (protobufMFACodec) encode(chal *client.MFAAuthenticateChallenge, envelopeType string) ([]byte, error) {
jsonBytes, err := json.Marshal(chal)
if err != nil {
return nil, trace.Wrap(err)
}
envelope := &Envelope{
Version: defaults.WebsocketVersion,
Type: envelopeType,
Payload: string(jsonBytes),
}
protoBytes, err := proto.Marshal(envelope)
if err != nil {
return nil, trace.Wrap(err)
}
return protoBytes, nil
}
func (protobufMFACodec) decode(bytes []byte, envelopeType string) (*authproto.MFAAuthenticateResponse, error) {
envelope := &Envelope{}
if err := proto.Unmarshal(bytes, envelope); err != nil {
return nil, trace.Wrap(err)
}
return mfajson.Decode([]byte(envelope.Payload), envelopeType)
}
// tdpMFACodec converts MFA challenges and responses to Teleport Desktop
// Protocol (TDP) messages used by Desktop Access web sessions
type tdpMFACodec struct{}
func (tdpMFACodec) encode(chal *client.MFAAuthenticateChallenge, envelopeType string) ([]byte, error) {
switch envelopeType {
case defaults.WebsocketWebauthnChallenge:
default:
return nil, trace.BadParameter(
"received envelope type %v, expected %v (WebAuthn)", envelopeType, defaults.WebsocketWebauthnChallenge)
}
tdpMsg := tdp.MFA{
Type: envelopeType[0],
MFAAuthenticateChallenge: chal,
}
return tdpMsg.Encode()
}
func (tdpMFACodec) decode(buf []byte, envelopeType string) (*authproto.MFAAuthenticateResponse, error) {
msg, err := tdp.DecodeMFA(bytes.NewReader(buf))
if err != nil {
return nil, trace.Wrap(err)
}
return msg.MFAAuthenticateResponse, nil
}