2015-04-23 04:58:57 -07:00
|
|
|
// Copyright 2014 The Gogs Authors. All rights reserved.
|
2022-11-27 11:20:29 -07:00
|
|
|
// SPDX-License-Identifier: MIT
|
2015-04-23 04:58:57 -07:00
|
|
|
|
2021-08-24 09:47:09 -07:00
|
|
|
//go:build pam
|
|
|
|
|
2015-04-23 04:58:57 -07:00
|
|
|
package pam
|
|
|
|
|
|
|
|
import (
|
|
|
|
"errors"
|
|
|
|
|
|
|
|
"github.com/msteinert/pam"
|
|
|
|
)
|
|
|
|
|
2020-10-23 03:10:29 -07:00
|
|
|
// Supported is true when built with PAM
|
|
|
|
var Supported = true
|
|
|
|
|
2016-11-26 23:03:59 -07:00
|
|
|
// Auth pam auth service
|
2020-02-23 12:52:05 -07:00
|
|
|
func Auth(serviceName, userName, passwd string) (string, error) {
|
2015-04-23 04:58:57 -07:00
|
|
|
t, err := pam.StartFunc(serviceName, userName, func(s pam.Style, msg string) (string, error) {
|
|
|
|
switch s {
|
|
|
|
case pam.PromptEchoOff:
|
|
|
|
return passwd, nil
|
|
|
|
case pam.PromptEchoOn, pam.ErrorMsg, pam.TextInfo:
|
|
|
|
return "", nil
|
|
|
|
}
|
|
|
|
return "", errors.New("Unrecognized PAM message style")
|
|
|
|
})
|
|
|
|
if err != nil {
|
2020-02-23 12:52:05 -07:00
|
|
|
return "", err
|
2015-04-23 04:58:57 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
if err = t.Authenticate(0); err != nil {
|
2020-02-23 12:52:05 -07:00
|
|
|
return "", err
|
2015-04-23 04:58:57 -07:00
|
|
|
}
|
2022-03-13 09:40:47 -07:00
|
|
|
|
2022-03-09 19:00:05 -07:00
|
|
|
if err = t.AcctMgmt(0); err != nil {
|
2022-03-13 09:40:47 -07:00
|
|
|
return "", err
|
|
|
|
}
|
2015-04-23 04:58:57 -07:00
|
|
|
|
2020-02-23 12:52:05 -07:00
|
|
|
// PAM login names might suffer transformations in the PAM stack.
|
|
|
|
// We should take whatever the PAM stack returns for it.
|
|
|
|
return t.GetItem(pam.User)
|
2015-04-23 04:58:57 -07:00
|
|
|
}
|