-
-
Notifications
You must be signed in to change notification settings - Fork 102
Expand file tree
/
Copy pathcommand_credentials.go
More file actions
342 lines (330 loc) 路 13 KB
/
Copy pathcommand_credentials.go
File metadata and controls
342 lines (330 loc) 路 13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
// Copyright 2022 Paul Greenberg greenpau@outlook.com
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package security
import (
"context"
"crypto/rand"
"encoding/json"
"errors"
"fmt"
"io"
"math/big"
"os"
"os/signal"
"strings"
"syscall"
"time"
"unicode"
"unicode/utf8"
"github.com/greenpau/go-authcrunch/pkg/identity"
passwordparser "github.com/greenpau/go-authcrunch/pkg/identity/password/parser"
cfgutil "github.com/greenpau/go-authcrunch/pkg/util/cfg"
"github.com/spf13/cobra"
"golang.org/x/crypto/bcrypt"
"golang.org/x/term"
"golang.org/x/text/transform"
)
var errSecurityTerminalEncoding = errors.New("terminal input contains invalid UTF-8 or a replacement character; use a private config or password file")
// x/term's line editor treats utf8.RuneError as an incomplete key and can
// discard it. Validate the stream first, including sequences split across
// reads. Literal U+FFFD is rejected here too; file input preserves it exactly.
type securityTerminalUTF8 struct{ transform.NopResetter }
// Transform preserves complete UTF-8 sequences and rejects input the editor would discard.
func (securityTerminalUTF8) Transform(dst, src []byte, atEOF bool) (nDst, nSrc int, err error) {
for nSrc < len(src) {
if !atEOF && !utf8.FullRune(src[nSrc:]) {
return nDst, nSrc, transform.ErrShortSrc
}
value, size := utf8.DecodeRune(src[nSrc:])
if value == utf8.RuneError {
return nDst, nSrc, errSecurityTerminalEncoding
}
if len(dst)-nDst < size {
return nDst, nSrc, transform.ErrShortDst
}
copy(dst[nDst:], src[nSrc:nSrc+size])
nDst += size
nSrc += size
}
return nDst, nSrc, nil
}
func addSecurityCredentialCommands(parent *cobra.Command) {
generate := securityCommandGroup(parent, "generate", "Generate credentials offline")
password := securityCommandGroup(generate, "password", "Generate password hashes")
api := securityCommandGroup(generate, "api", "Generate API credentials")
for _, action := range []struct {
parent *cobra.Command
name string
api bool
}{
{password, "hash", false}, {api, "key", true},
} {
cmd := &cobra.Command{Use: action.name, Args: securityNoArgs}
cmd.Flags().Int("cost", 10, "Bcrypt cost (8-31)")
if action.api {
cmd.Short = "Generate an API key and its Caddyfile hash"
cmd.Long = "Generate a random 72-character API key and a bcrypt hash. Output includes the plaintext secret and an api key Caddyfile directive with its 24-character prefix. Protect stdout. No server or database is accessed."
} else {
cmd.Short = "Generate a Caddyfile password hash"
cmd.Long = "Read a password without terminal echo and print a password Caddyfile directive. Bcrypt is the default; --algorithm argon2 selects Argon2id. Argon2 options are --memory (KiB), --iterations and --parallelism; --cost is bcrypt-only. For automation use --password-file, or --password-file - for stdin. One final LF or CRLF is removed; other whitespace is never silently trimmed. An optional --db-path reads password policy without modifying the database."
cmd.Flags().String("password-file", "", "Owner-only password file, or - to read stdin")
cmd.Flags().String("db-path", "", "Existing local database to read password policy from")
cmd.Flags().String("algorithm", "bcrypt", "Password algorithm: bcrypt or argon2 (Argon2id)")
cmd.Flags().Int("memory", 65536, "Argon2 memory in KiB")
cmd.Flags().Int("iterations", 3, "Argon2 passes")
cmd.Flags().Int("parallelism", 4, "Argon2 lanes")
}
cmd.RunE = func(cmd *cobra.Command, _ []string) error { return runSecurityCredential(cmd, action.api) }
action.parent.AddCommand(cmd)
}
}
// Collect explicit options once. The shared parser owns defaults, algorithm
// compatibility and resource bounds; parsing must finish before reading input.
func securityPasswordHashConfig(cmd *cobra.Command) (*identity.PasswordHashConfig, error) {
var directives []string
for _, name := range []string{"algorithm", "cost", "memory", "iterations", "parallelism"} {
if cmd.Flags().Changed(name) {
value := cmd.Flags().Lookup(name).Value.String()
if name == "algorithm" {
// EncodeArgs trims unquoted trailing tabs and Unicode whitespace.
// Preserve this string exactly so the shared parser rejects invalid
// algorithm names before any password input or hashing work.
directives = append(directives, `algorithm "`+strings.ReplaceAll(value, `"`, `""`)+`"`)
continue
}
directives = append(directives, cfgutil.EncodeArgs([]string{name, value}))
}
}
return passwordparser.NewPasswordHashConfigFromDirectives(directives)
}
// The caller owns terminal state so cancellation restores echo immediately.
// A pending terminal read may remain until this CLI process exits; it never owns
// terminal restoration and therefore cannot put the terminal back in raw mode.
func readSecuritySecret(ctx context.Context, input io.Reader, output io.Writer, prompt string) (string, error) {
if err := ctx.Err(); err != nil {
return "", err
}
f, ok := input.(*os.File)
if !ok || !term.IsTerminal(int(f.Fd())) {
return "", fmt.Errorf("terminal input required; configure credentials or use --password-file for hashing")
}
fd := int(f.Fd())
state, err := term.MakeRaw(fd)
if err != nil {
return "", fmt.Errorf("cannot read terminal input")
}
defer term.Restore(fd, state)
if _, err := fmt.Fprint(output, prompt); err != nil {
return "", err
}
type result struct {
text string
err error
}
results := make(chan result, 1)
terminal := term.NewTerminal(struct {
io.Reader
io.Writer
}{transform.NewReader(input, securityTerminalUTF8{}), io.Discard}, "")
go func() { value, err := terminal.ReadPassword(""); results <- result{value, err} }()
select {
case value := <-results:
if _, err := fmt.Fprint(output, "\r\n"); err != nil {
return "", err
}
if value.err != nil {
if errors.Is(value.err, errSecurityTerminalEncoding) {
return "", errSecurityTerminalEncoding
}
return "", fmt.Errorf("cannot read terminal input")
}
return value.text, nil
case <-ctx.Done():
return "", ctx.Err()
}
}
func runSecurityCredential(cmd *cobra.Command, api bool) error {
cost, _ := cmd.Flags().GetInt("cost")
if api && (cost < 8 || cost > bcrypt.MaxCost) {
return fmt.Errorf("bcrypt cost must be between 8 and 31")
}
var config *identity.PasswordHashConfig
if !api {
var err error
config, err = securityPasswordHashConfig(cmd)
if err != nil {
return err
}
cost = config.Cost
}
var secret string
if api {
// Authcrunch requires 64-72 alphanumeric bytes and indexes the first 24.
const alphabet = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789"
var value [72]byte
for i := range value {
n, err := rand.Int(rand.Reader, big.NewInt(int64(len(alphabet))))
if err != nil {
return fmt.Errorf("cannot generate API key")
}
value[i] = alphabet[n.Int64()]
}
secret = string(value[:])
} else {
path, _ := cmd.Flags().GetString("db-path")
policy, err := securityPasswordPolicy(cmd.Context(), path)
if err != nil {
return err
}
passwordFile, _ := cmd.Flags().GetString("password-file")
if cmd.Flags().Changed("password-file") && passwordFile == "" {
return fmt.Errorf("password file must not be empty")
}
if passwordFile == "" {
secret, err = func() (string, error) {
ctx, stop := signal.NotifyContext(cmd.Context(), os.Interrupt, syscall.SIGTERM)
defer stop()
ctx, cancel := context.WithTimeout(ctx, 30*time.Second)
defer cancel()
return readSecuritySecret(ctx, cmd.InOrStdin(), cmd.ErrOrStderr(), "Password: ")
}()
// Release the interrupt handler before hashing, which cannot observe
// context cancellation. Ctrl-C must still stop an expensive hash.
} else {
limit := int64(policy.MaxLength)
if config.Algorithm == identity.PasswordAlgorithmBcrypt && limit > 72 {
limit = 72
}
// Include one optional CRLF and one byte to detect oversized input.
// Avoid overflow even with an operator-supplied policy length.
if limit > (1<<63)-4 {
return fmt.Errorf("invalid database password length policy")
}
var data []byte
if passwordFile == "-" {
data, err = io.ReadAll(io.LimitReader(cmd.InOrStdin(), limit+3))
} else {
data, err = readSecurityLocalFile(cmd.Context(), passwordFile, limit+2, true)
}
if err != nil {
return fmt.Errorf("cannot read password input")
}
secret = strings.TrimSuffix(string(data), "\n")
if len(secret) < len(data) {
secret = strings.TrimSuffix(secret, "\r")
}
}
if err != nil {
return err
}
if err := validateSecurityPassword(secret, policy, config.Algorithm); err != nil {
return err
}
if config.Algorithm == identity.PasswordAlgorithmArgon2 {
// This command generates from plaintext. Do not let the constructor's
// trusted import path bypass policy or override the requested options.
if identity.IsPasswordHashImport(secret) {
return fmt.Errorf("argon2 generation requires plaintext without a reserved password hash prefix")
}
password, err := identity.NewPasswordWithConfig(secret, "generic", config)
if err != nil {
return fmt.Errorf("cannot generate password hash")
}
_, err = fmt.Fprintf(cmd.OutOrStdout(), "password %q\n", password.EncodedHash())
return err
}
}
// Hash plaintext directly: the upstream constructor interprets bcrypt:
// prefixes as already-hashed input and silently trims password whitespace.
hash, err := bcrypt.GenerateFromPassword([]byte(secret), cost)
if err != nil {
return fmt.Errorf("cannot generate bcrypt hash")
}
if api {
_, err = fmt.Fprintf(cmd.OutOrStdout(), "secret: %s\napi key %s \"bcrypt:%d:%s\"\n", secret, secret[:24], cost, hash)
} else {
_, err = fmt.Fprintf(cmd.OutOrStdout(), "password \"bcrypt:%d:%s\"\n", cost, hash)
}
return err
}
func securityPasswordPolicy(ctx context.Context, path string) (identity.PasswordPolicy, error) {
if err := ctx.Err(); err != nil {
return identity.PasswordPolicy{}, err
}
// Obtain upstream defaults in memory. NewDatabase(path) can create or rewrite
// files while applying defaults, even for a supposedly read-only hash command.
db, err := identity.NewDatabase(":memory:")
if err != nil {
return identity.PasswordPolicy{}, fmt.Errorf("cannot initialize password policy")
}
policy := db.Policy.Password
if path == "" || path == ":memory:" {
return policy, nil
}
data, err := readSecurityLocalFile(ctx, path, 64<<20, false)
if err != nil {
return policy, fmt.Errorf("read database policy: %w", err)
}
var record *struct {
Policy struct {
Password identity.PasswordPolicy `json:"password"`
} `json:"policy"`
}
if json.Unmarshal(data, &record) != nil || record == nil {
return policy, fmt.Errorf("invalid database policy JSON")
}
loaded := record.Policy.Password
if loaded.MinLength == 0 {
loaded.MinLength = policy.MinLength
}
if loaded.MaxLength == 0 {
loaded.MaxLength = policy.MaxLength
}
if loaded.MinLength < 0 || loaded.MaxLength < loaded.MinLength {
return policy, fmt.Errorf("invalid database password length policy")
}
return loaded, nil
}
func validateSecurityPassword(secret string, policy identity.PasswordPolicy, algorithm string) error {
if !utf8.ValidString(secret) || strings.ContainsAny(secret, "\r\n\x00") || strings.TrimSpace(secret) != secret {
return fmt.Errorf("password must be valid UTF-8 without line breaks, NUL, or surrounding whitespace")
}
if algorithm == identity.PasswordAlgorithmBcrypt && (len(secret) == 0 || len(secret) > 72) {
return fmt.Errorf("bcrypt password must contain 1-72 bytes")
}
// Consult the password-only library API, never a synthetic username. Retain
// the existing bcrypt generator's literal-prefix and character-class checks;
// the library treats prefixes as imports and checks only plaintext length.
if identity.IsPasswordHashImport(secret) {
if len(secret) < policy.MinLength || len(secret) > policy.MaxLength {
return fmt.Errorf("password does not satisfy database length policy")
}
} else {
db := identity.Database{Policy: identity.Policy{Password: policy}}
if err := db.CheckPasswordPolicyCompliance(secret); err != nil {
return fmt.Errorf("password does not satisfy database length policy")
}
}
var upper, lower, number, special bool
for _, c := range secret {
upper = upper || unicode.IsUpper(c)
lower = lower || unicode.IsLower(c)
number = number || unicode.IsDigit(c)
special = special || (!unicode.IsLetter(c) && !unicode.IsDigit(c))
}
if (policy.RequireUppercase && !upper) || (policy.RequireLowercase && !lower) || (policy.RequireNumber && !number) || (policy.RequireNonAlphaNumeric && !special) {
return fmt.Errorf("password does not satisfy database character requirements")
}
return nil
}