Bug 1175643 - Rewrite auth delegation to use a server-side POST instead of a…

Bug 1175643 - Rewrite auth delegation to use a server-side POST instead of a client-side GET to delegate API Key r/a=dkl
parent 5fd2b62a
...@@ -23,6 +23,8 @@ use Bugzilla::Mailer qw(MessageToMTA); ...@@ -23,6 +23,8 @@ use Bugzilla::Mailer qw(MessageToMTA);
use URI; use URI;
use URI::QueryParam; use URI::QueryParam;
use Digest::SHA qw(sha256_hex); use Digest::SHA qw(sha256_hex);
use LWP::UserAgent ();
use JSON qw(decode_json encode_json);
Bugzilla->login(LOGIN_REQUIRED); Bugzilla->login(LOGIN_REQUIRED);
...@@ -88,10 +90,39 @@ if ($confirmed || $skip_confirmation) { ...@@ -88,10 +90,39 @@ if ($confirmed || $skip_confirmation) {
MessageToMTA($message); MessageToMTA($message);
} }
$callback_uri->query_param(client_api_key => $api_key->api_key); my $ua = LWP::UserAgent->new();
$callback_uri->query_param(client_api_login => $user->login); $ua->timeout(2);
$ua->protocols_allowed(['http', 'https']);
print $cgi->redirect($callback_uri); # If the URL of the proxy is given, use it, else get this information
# from the environment variable.
my $proxy_url = Bugzilla->params->{'proxy_url'};
if ($proxy_url) {
$ua->proxy(['http', 'https'], $proxy_url);
}
else {
$ua->env_proxy;
}
my $content = encode_json({ client_api_key => $api_key->api_key,
client_api_login => $user->login });
my $resp = $ua->post($callback_uri,
'Content-Type' => 'application/json',
Content => $content);
if ($resp->code == 200) {
$callback_uri->query_param(client_api_login => $user->login);
eval {
my $data = decode_json($resp->content);
$callback_uri->query_param(callback_result => $data->{result});
};
if ($@) {
ThrowUserError('auth_delegation_json_error', { json_text => $resp->content });
}
else {
print $cgi->redirect($callback_uri);
}
}
else {
ThrowUserError('auth_delegation_post_error', { code => $resp->code });
}
} }
else { else {
$args{token} = issue_auth_delegation_token($callback); $args{token} = issue_auth_delegation_token($callback);
......
...@@ -140,6 +140,15 @@ ...@@ -140,6 +140,15 @@
[% title = "Auth delegation can't be confirmed" %] [% title = "Auth delegation can't be confirmed" %]
Auth delegation cannot be confirmed due to missing or invalid token. Auth delegation cannot be confirmed due to missing or invalid token.
[% ELSIF error == "auth_delegation_json_error" %]
[% title = "Auth delegation received invalid JSON" %]
Auth delegation received an invalid JSON response from auth consumer:
<pre>[% json_text FILTER html %]</pre>
[% ELSIF error == "auth_delegation_post_error" %]
[% title = "Auth delegation received invalid status code" %]
Auth delegation received an HTTP response other than 200 OK from auth consumer. Code: [% code FILTER html %]
[% ELSIF error == "auth_failure" %] [% ELSIF error == "auth_failure" %]
[% title = "Authorization Required" %] [% title = "Authorization Required" %]
[% admindocslinks = {'groups.html' => 'Group Security'} %] [% admindocslinks = {'groups.html' => 'Group Security'} %]
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment