Commit 3db657e0 authored by Frédéric Buclin's avatar Frédéric Buclin

Bug 1185241: Logging out when or after impersonating a user doesn't delete…

Bug 1185241: Logging out when or after impersonating a user doesn't delete cookies from the logincookies table correctly r=dkl
parent a72defcf
...@@ -94,7 +94,7 @@ sub logout { ...@@ -94,7 +94,7 @@ sub logout {
my $cgi = Bugzilla->cgi; my $cgi = Bugzilla->cgi;
my $input = Bugzilla->input_params; my $input = Bugzilla->input_params;
$param = {} unless $param; $param = {} unless $param;
my $user = $param->{user} || Bugzilla->user; my $user = $param->{user} || Bugzilla->sudoer || Bugzilla->user;
my $type = $param->{type} || LOGOUT_ALL; my $type = $param->{type} || LOGOUT_ALL;
if ($type == LOGOUT_ALL) { if ($type == LOGOUT_ALL) {
......
...@@ -54,22 +54,6 @@ elsif ($action eq 'prepare-sudo') { ...@@ -54,22 +54,6 @@ elsif ($action eq 'prepare-sudo') {
# Keep a temporary record of the user visiting this page # Keep a temporary record of the user visiting this page
$vars->{'token'} = issue_session_token('sudo_prepared'); $vars->{'token'} = issue_session_token('sudo_prepared');
if ($user->authorizer->can_login) {
my $value = generate_random_password();
my %args;
$args{'-secure'} = 1 if Bugzilla->params->{ssl_redirect};
$cgi->send_cookie(-name => 'Bugzilla_login_request_cookie',
-value => $value,
-httponly => 1,
%args);
# The user ID must not be set when generating the token, because
# that information will not be available when validating it.
local Bugzilla->user->{userid} = 0;
$vars->{'login_request_token'} = issue_hash_token(['login_request', $value]);
}
# Show the sudo page # Show the sudo page
$vars->{'target_login_default'} = $cgi->param('target_login'); $vars->{'target_login_default'} = $cgi->param('target_login');
$vars->{'reason_default'} = $cgi->param('reason'); $vars->{'reason_default'} = $cgi->param('reason');
...@@ -77,32 +61,16 @@ elsif ($action eq 'prepare-sudo') { ...@@ -77,32 +61,16 @@ elsif ($action eq 'prepare-sudo') {
} }
# begin-sudo: Confirm login and start sudo session # begin-sudo: Confirm login and start sudo session
elsif ($action eq 'begin-sudo') { elsif ($action eq 'begin-sudo') {
# We must be sure that the user is authenticating by providing a login
# and password.
# We only need to do this for authentication methods that involve Bugzilla
# directly obtaining a login (i.e. normal CGI login), as opposed to other
# methods (like Environment vars login).
# First, record if Bugzilla_login and Bugzilla_password were provided
my $credentials_provided;
if (defined($cgi->param('Bugzilla_login'))
&& defined($cgi->param('Bugzilla_password')))
{
$credentials_provided = 1;
}
# Next, log in the user
my $user = Bugzilla->login(LOGIN_REQUIRED); my $user = Bugzilla->login(LOGIN_REQUIRED);
my $target_login = $cgi->param('target_login'); my $target_login = $cgi->param('target_login');
my $reason = $cgi->param('reason') || ''; my $reason = $cgi->param('reason') || '';
# At this point, the user is logged in. However, if they used a method if ($user->authorizer->can_login) {
# where they could have provided a username/password (i.e. CGI), but they my $password = $cgi->param('password')
# did not provide a username/password, then throw an error. or ThrowUserError('sudo_password_required',
if ($user->authorizer->can_login && !$credentials_provided) { { target_login => $target_login, reason => $reason });
ThrowUserError('sudo_password_required', $user->check_current_password($password);
{ target_login => $target_login, reason => $reason });
} }
# The user must be in the 'bz_sudoers' group # The user must be in the 'bz_sudoers' group
...@@ -112,12 +80,25 @@ elsif ($action eq 'begin-sudo') { ...@@ -112,12 +80,25 @@ elsif ($action eq 'begin-sudo') {
object => 'sudo_session' } object => 'sudo_session' }
); );
} }
# Do not try to start a new session if one is already in progress! # Do not try to start a new session if one is already in progress!
if (defined(Bugzilla->sudoer)) { if (defined(Bugzilla->sudoer)) {
ThrowUserError('sudo_in_progress', { target => $user->login }); ThrowUserError('sudo_in_progress', { target => $user->login });
} }
# Get & verify the target user (the user who we will be impersonating)
my $target_user = new Bugzilla::User({ name => $target_login });
unless (defined($target_user)
&& $target_user->id
&& $user->can_see_user($target_user))
{
ThrowUserError('user_match_failed', { name => $target_login });
}
if ($target_user->in_group('bz_sudo_protect')) {
ThrowUserError('sudo_protected', { login => $target_user->login });
}
# Did the user actually go trough the 'sudo-prepare' action? Do some # Did the user actually go trough the 'sudo-prepare' action? Do some
# checks on the token the action should have left. # checks on the token the action should have left.
my ($token_user, $token_timestamp, $token_data) = my ($token_user, $token_timestamp, $token_data) =
...@@ -132,18 +113,6 @@ elsif ($action eq 'begin-sudo') { ...@@ -132,18 +113,6 @@ elsif ($action eq 'begin-sudo') {
} }
delete_token($cgi->param('token')); delete_token($cgi->param('token'));
# Get & verify the target user (the user who we will be impersonating)
my $target_user = new Bugzilla::User({ name => $target_login });
unless (defined($target_user)
&& $target_user->id
&& $user->can_see_user($target_user))
{
ThrowUserError('user_match_failed', { name => $target_login });
}
if ($target_user->in_group('bz_sudo_protect')) {
ThrowUserError('sudo_protected', { login => $target_user->login });
}
# Calculate the session expiry time (T + 6 hours) # Calculate the session expiry time (T + 6 hours)
my $time_string = time2str('%a, %d-%b-%Y %T %Z', time + MAX_SUDO_TOKEN_AGE, 'GMT'); my $time_string = time2str('%a, %d-%b-%Y %T %Z', time + MAX_SUDO_TOKEN_AGE, 'GMT');
......
...@@ -17,9 +17,9 @@ ...@@ -17,9 +17,9 @@
<p> <p>
The <b>sudo</b> feature of Bugzilla allows you to impersonate a The <b>sudo</b> feature of Bugzilla allows you to impersonate a
user for a short time While an sudo session is in progress, every action you user for a short time. While a sudo session is in progress, every action you
perform will be taking place as if you had logged in as the user whom will be perform will be taking place as if you had logged in as the user who will be
impersonating. impersonated.
</p> </p>
<p class="areyoureallyreallysure"> <p class="areyoureallyreallysure">
...@@ -67,12 +67,8 @@ ...@@ -67,12 +67,8 @@
[% IF user.authorizer.can_login %] [% IF user.authorizer.can_login %]
<p> <p>
Finally, enter <label for="Bugzilla_password">your [% terms.Bugzilla %] Finally, enter <label for="password">your [% terms.Bugzilla %] password</label>:
password</label>: <input type="password" id="password" name="password" size="20" required>
<input type="hidden" name="Bugzilla_login" value="[% user.login FILTER html %]">
<input type="password" id="Bugzilla_password" name="Bugzilla_password" size="20" required>
<input type="hidden" name="Bugzilla_login_token"
value="[% login_request_token FILTER html %]">
<br> <br>
This is done for two reasons. First of all, it is done to reduce This is done for two reasons. First of all, it is done to reduce
the chances of someone doing large amounts of damage using your the chances of someone doing large amounts of damage using your
...@@ -80,9 +76,8 @@ ...@@ -80,9 +76,8 @@
time to consider if you really need to use this feature. time to consider if you really need to use this feature.
</p> </p>
[% END %] [% END %]
<p> <p>
Click the button to begin the session:
<input type="submit" id="begin_sudo" value="Begin Session"> <input type="submit" id="begin_sudo" value="Begin Session">
<input type="hidden" name="action" value="begin-sudo"> <input type="hidden" name="action" value="begin-sudo">
<input type="hidden" name="token" value="[% token FILTER html %]"> <input type="hidden" name="token" value="[% token FILTER html %]">
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment