Merge pull request #145 from oaydogmus/master

added IP&token auth
pull/147/head
Piero Toffanin 2021-02-18 15:32:07 -05:00 zatwierdzone przez GitHub
commit 425487ea5a
Nie znaleziono w bazie danych klucza dla tego podpisu
ID klucza GPG: 4AEE18F83AFDEB23
4 zmienionych plików z 77 dodań i 7 usunięć

Wyświetl plik

@ -17,5 +17,6 @@
"testSkipOrthophotos": false,
"testSkipDems": false,
"token": "",
"authorizedIps": [],
"maxImages": ""
}

Wyświetl plik

@ -107,6 +107,7 @@ config.testFailTasks = argv.test_fail_tasks || fromConfigFile("testFailTasks", f
config.testSeconds = parseInt(argv.test_seconds || fromConfigFile("testSeconds", 0));
config.powercycle = argv.powercycle || fromConfigFile("powercycle", false);
config.token = argv.token || fromConfigFile("token", "");
config.authorizedIps = fromConfigFile("authorizedIps", []);
config.maxImages = parseInt(argv.max_images || fromConfigFile("maxImages", "")) || null;
config.webhook = argv.webhook || fromConfigFile("webhook", "");
config.s3Endpoint = argv.s3_endpoint || fromConfigFile("s3Endpoint", "");

Wyświetl plik

@ -0,0 +1,65 @@
/*
Node-OpenDroneMap Node.js App and REST API to access OpenDroneMap.
Copyright (C) 2018 Node-OpenDroneMap Contributors
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
const TokenAuthBase = require("./TokenAuthBase");
module.exports = class TokenIpAuth extends TokenAuthBase {
// @param token {String} token to use for authentication
// @param authorizedIps {Array} authorizedIps to use for authentication
constructor(token, authorizedIps) {
super(token);
this.token = token;
this.authorizedIps = authorizedIps;
}
validateToken(token, cb) {
if (this.token === token) {
return cb(null, true);
} else {
cb(new Error("token does not match."), false);
}
}
validateIp(ip, cb) {
if (this.authorizedIps.indexOf(ip) !== -1) return cb(null, true)
else cb(new Error('IP is not one of authorized IPs.', false))
}
getMiddleware() {
return (req, res, next) => {
this.validateToken(req.query.token, (err, valid) => {
if (valid) {
this.validateIp(req.connection.remoteAddress, (err, valid) => {
if (valid) next();
else {
res.json({
error: "Invalid authentication IP: " + err.message,
});
}
});
}
else {
res.json({
error: "Invalid authentication token: " + err.message,
});
}
});
};
}
};

Wyświetl plik

@ -1,12 +1,15 @@
const NoTokenRequiredAuth = require('./NoTokenRequiredAuth');
const SimpleTokenAuth = require('./SimpleTokenAuth');
const NoTokenRequiredAuth = require("./NoTokenRequiredAuth");
const TokenIpAuth = require("./TokenIpAuth");
const SimpleTokenAuth = require("./SimpleTokenAuth");
module.exports = {
fromConfig: function(config){
if (config.token){
fromConfig: function (config) {
if (config.token && config.authorizedIps && config.authorizedIps.length) {
return new TokenIpAuth(config.token, config.authorizedIps);
} else if (config.token) {
return new SimpleTokenAuth(config.token);
}else{
} else {
return new NoTokenRequiredAuth();
}
}
}
},
};