Skip to content

Commit 9174d61

Browse files
committed
Implemented authentication for websocket connection
1 parent b316765 commit 9174d61

File tree

5 files changed

+67
-32
lines changed

5 files changed

+67
-32
lines changed

src/http.c

Lines changed: 34 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -18,11 +18,11 @@ check_auth(struct lws *wsi) {
1818
if (strlen(token) == 0)
1919
continue;
2020
if (i++ == 2) {
21-
b64_text = strdup(token);
21+
b64_text = token;
2222
break;
2323
}
2424
}
25-
if (b64_text != NULL && strcmp(b64_text, server->credential) == 0)
25+
if (b64_text != NULL && !strcmp(b64_text, server->credential))
2626
return 0;
2727
}
2828

@@ -51,26 +51,20 @@ int
5151
callback_http(struct lws *wsi, enum lws_callback_reasons reason, void *user, void *in, size_t len) {
5252
unsigned char buffer[4096 + LWS_PRE], *p, *end;
5353
char buf[256];
54-
int n;
5554

5655
switch (reason) {
5756
case LWS_CALLBACK_HTTP:
58-
lwsl_notice("lws_http_serve: %s\n", in);
59-
6057
{
6158
char name[100], rip[50];
62-
lws_get_peer_addresses(wsi, lws_get_socket_fd(wsi), name,
63-
sizeof(name), rip, sizeof(rip));
64-
sprintf(buf, "%s (%s)", name, rip);
65-
lwsl_notice("HTTP connect from %s\n", buf);
59+
lws_get_peer_addresses(wsi, lws_get_socket_fd(wsi), name, sizeof(name), rip, sizeof(rip));
60+
lwsl_notice("HTTP connect from %s (%s), path: %s\n", name, rip, in);
6661
}
6762

6863
if (len < 1) {
6964
lws_return_http_status(wsi, HTTP_STATUS_BAD_REQUEST, NULL);
7065
goto try_to_reuse;
7166
}
7267

73-
// TODO: this doesn't work for websocket
7468
switch (check_auth(wsi)) {
7569
case 0:
7670
break;
@@ -85,37 +79,54 @@ callback_http(struct lws *wsi, enum lws_callback_reasons reason, void *user, voi
8579
if (lws_hdr_total_length(wsi, WSI_TOKEN_POST_URI))
8680
return 0;
8781

88-
if (strcmp((const char *) in, "/")) {
89-
lws_return_http_status(wsi, HTTP_STATUS_NOT_FOUND, NULL);
82+
p = buffer + LWS_PRE;
83+
end = p + sizeof(buffer) - LWS_PRE;
84+
85+
if (!strncmp((const char *)in, "/auth_token.js", 14)) {
86+
size_t n = server->credential != NULL ? sprintf(buf, "var tty_auth_token = '%s';", server->credential) : 0;
87+
88+
if (lws_add_http_header_status(wsi, HTTP_STATUS_OK, &p, end))
89+
return 1;
90+
if (lws_add_http_header_by_token(wsi,
91+
WSI_TOKEN_HTTP_CONTENT_TYPE,
92+
(unsigned char *) "application/javascript",
93+
22, &p, end))
94+
return 1;
95+
if (lws_add_http_header_content_length(wsi, (unsigned long) n, &p, end))
96+
return 1;
97+
if (lws_finalize_http_header(wsi, &p, end))
98+
return 1;
99+
if (lws_write(wsi, buffer + LWS_PRE, p - (buffer + LWS_PRE), LWS_WRITE_HTTP_HEADERS) < 0)
100+
return 1;
101+
if (n > 0 && lws_write_http(wsi, buf, n) < 0) {
102+
return 1;
103+
}
90104
goto try_to_reuse;
91105
}
92106

93-
p = buffer + LWS_PRE;
94-
end = p + sizeof(buffer) - LWS_PRE;
107+
if (strncmp((const char *) in, "/", 1)) {
108+
lws_return_http_status(wsi, HTTP_STATUS_NOT_FOUND, NULL);
109+
goto try_to_reuse;
110+
}
95111

96-
if (lws_add_http_header_status(wsi, 200, &p, end))
112+
if (lws_add_http_header_status(wsi, HTTP_STATUS_OK, &p, end))
97113
return 1;
98114
if (lws_add_http_header_by_token(wsi,
99115
WSI_TOKEN_HTTP_CONTENT_TYPE,
100116
(unsigned char *) "text/html",
101117
9, &p, end))
102118
return 1;
103-
if (lws_add_http_header_content_length(wsi, index_html_len, &p, end))
119+
if (lws_add_http_header_content_length(wsi, (unsigned long) index_html_len, &p, end))
104120
return 1;
105121
if (lws_finalize_http_header(wsi, &p, end))
106122
return 1;
107-
n = lws_write(wsi, buffer + LWS_PRE, p - (buffer + LWS_PRE), LWS_WRITE_HTTP_HEADERS);
108-
if (n < 0) {
123+
if (lws_write(wsi, buffer + LWS_PRE, p - (buffer + LWS_PRE), LWS_WRITE_HTTP_HEADERS) < 0) {
109124
return 1;
110125
}
111126

112-
n = lws_write_http(wsi, index_html, index_html_len);
113-
if (n < 0)
127+
if (lws_write_http(wsi, index_html, index_html_len) < 0)
114128
return 1;
115129
goto try_to_reuse;
116-
case LWS_CALLBACK_HTTP_WRITEABLE:
117-
lwsl_info("LWS_CALLBACK_HTTP_WRITEABLE\n");
118-
break;
119130
default:
120131
break;
121132
}

src/index.html

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -571,6 +571,7 @@
571571
"Ch6PdwAAAGyWjFW4yScjaWa2mGcofHxWxewKALglWBpLUvwwk+UOh5eNGyUOs1/EF+pZr+ud5Ozo"+"GwYdAABg2p52LiSgAY/ZVlOmilEgHn6G3OcwYjzI7vOj1t6xsx4S3lBY96EUQBF6AIBAmPYH4PoG"+"YCoJAADWe+OZJZi7/x76/yH7Lzf9M5XzRKnFPmveMsilQHwVAAAAAKB3LQD8PCIAAADga0QujBLy"+"wzeJ4a6Z/ERVBAUlAEDqvoM7BQBAuAguzFqILtmjH3Kd4wfKobnOhA3z85qWoRPm9hwoOHoDAAlC"+"bwDAA56FHAuXflHo3fe2ttG9XUDeA9YmYCBQ0oPr/1QC8IvuCwAAApbUAQCK22MmE3O78VAbHQT9"+"PIPNoT9zNc3l2Oe7TAVLANBufT8MAQAAAGzT4PS8AQAAoELGHb2uaCwwEv1EWhFriUkbAaAZ27/f"+"VZnTZXbWz3BwWpjUaMZKRj7dZ0J//gUeTdpVEwAAZOFsNxKAjQSgA+ABPoY8Jj5y2wje81jsXc/1"+
572572
"TOQWTDYZBmAkNDiqVwuA2NJ9AQAAEBKAt9Vrsfs/2N19MO91S9rd8EHTZHnzC5MYmfQEACy/FBcA"+"AADA5c4gi4z8RANs/m6FNXVo9DV46JG1BBDukqlw/Va5G7QbuGVSI+2aZaoLXJrdVj2zlC9Z5QEA"+"EFz/5QzgVZwAAAAA/oXcxyC6WfTu+09Ve/c766J4VTAGUFmA51+VANKi/QPoPwYgYAkA715OH4S0"+"s5KDHvj99MMq8TPFc3roKZnGOoT1bmIhVgc7XAMBAAAAAMAW1VbQw3gapzOpJd+Kd2fc4iSO62fJ"+"v9+movui1wUNPAj059N3OVxzk4gV73PmE8FIA2F5mRq37Evc76vLXfF4rD5UJJAw46hW6LZCb5sN"+"Ldx+kzMCAAB+hfy95+965ZCLP7B3/VlTHCvDEKtQhTm4KiCgAEAbrfbWTPssAAAAXpee1tVrozYY"+"n41wD1aeYtkKfswN5/SXPO0JDnhO/4laUortv/s412fybe/nONdncoCHnBVliu0CQGBWlPY/5Kwo"+
573573
"m2L/kruPM6Q7oz4tvDQy+bZ3HzOi+gNHA4DZEgA="+"");lib.resource.add("hterm/concat/date","text/plain","Sat, 10 Sep 2016 08:51:57 +0000"+"");lib.resource.add("hterm/changelog/version","text/plain","1.58"+"");lib.resource.add("hterm/changelog/date","text/plain","2016-07-12"+"");lib.resource.add("hterm/git/HEAD","text/plain","49f8641dd055afaad9eadcd8553804eff0dd2637"+"");</script>
574+
<script src="auth_token.js"></script>
574575
<script type="text/javascript">
575576
(function() {
576577
var httpsEnabled = window.location.protocol == "https:";
@@ -580,12 +581,12 @@
580581

581582
var openWs = function() {
582583
var ws = new WebSocket(url, protocols);
583-
584-
var term;
585-
586-
var pingTimer;
584+
var term, pingTimer;
587585

588586
ws.onopen = function(event) {
587+
if (typeof tty_auth_token !== 'undefined') {
588+
ws.send(JSON.stringify({AuthToken: tty_auth_token}));
589+
}
589590
pingTimer = setInterval(sendPing, 30 * 1000, ws);
590591

591592
hterm.defaultStorage = new lib.Storage.Local();

src/protocol.c

Lines changed: 26 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
#define INPUT '0'
55
#define PING '1'
66
#define RESIZE_TERMINAL '2'
7+
#define JSON_DATA '{'
78

89
// server message
910
#define OUTPUT '0'
@@ -158,14 +159,15 @@ callback_tty(struct lws *wsi, enum lws_callback_reasons reason,
158159
case LWS_CALLBACK_ESTABLISHED:
159160
client->exit = false;
160161
client->initialized = false;
162+
client->authenticated = false;
161163
client->wsi = wsi;
162164
lws_get_peer_addresses(wsi, lws_get_socket_fd(wsi),
163165
client->hostname, sizeof(client->hostname),
164166
client->address, sizeof(client->address));
165167
STAILQ_INIT(&client->queue);
166168
if (pthread_create(&client->thread, NULL, thread_run_command, client) != 0) {
167169
lwsl_err("pthread_create\n");
168-
return 1;
170+
return -1;
169171
}
170172

171173
pthread_mutex_lock(&server->lock);
@@ -222,6 +224,13 @@ callback_tty(struct lws *wsi, enum lws_callback_reasons reason,
222224
case LWS_CALLBACK_RECEIVE:
223225
data = (char *) in;
224226
char command = data[0];
227+
228+
// check auth
229+
if (server->credential != NULL && !client->authenticated && command != JSON_DATA) {
230+
lwsl_notice("websocket authentication failed\n");
231+
return -1;
232+
}
233+
225234
switch (command) {
226235
case INPUT:
227236
if (write(client->pty, data + 1, len - 1) < len - 1) {
@@ -247,6 +256,22 @@ callback_tty(struct lws *wsi, enum lws_callback_reasons reason,
247256
t_free(size);
248257
}
249258
break;
259+
case JSON_DATA:
260+
if (server->credential == NULL)
261+
break;
262+
{
263+
json_object *obj = json_tokener_parse(data);
264+
struct json_object *o = NULL;
265+
if (json_object_object_get_ex(obj, "AuthToken", &o)) {
266+
const char *token = json_object_get_string(o);
267+
if (strcmp(token, server->credential)) {
268+
lwsl_notice("websocket authentication failed with token: %s\n", token);
269+
return -1;
270+
}
271+
}
272+
client->authenticated = true;
273+
}
274+
break;
250275
default:
251276
lwsl_notice("unknown message type: %c\n", command);
252277
break;

src/server.h

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,7 @@
1818
#include <assert.h>
1919

2020
#ifdef __APPLE__
21-
2221
#include <util.h>
23-
2422
#else
2523
#include <pty.h>
2624
#endif
@@ -43,6 +41,7 @@ struct pty_data {
4341
struct tty_client {
4442
bool exit;
4543
bool initialized;
44+
bool authenticated;
4645
char hostname[100];
4746
char address[50];
4847

src/utils.c

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,8 +36,7 @@ t_malloc(size_t size) {
3636
}
3737

3838
void t_free(void *p) {
39-
if (p)
40-
free(p);
39+
free(p);
4140
}
4241

4342
void *

0 commit comments

Comments
 (0)