XRootD
Loading...
Searching...
No Matches
XrdMacaroonsAuthz.cc
Go to the documentation of this file.
3
4#include "XrdOuc/XrdOucEnv.hh"
9
10#include <ctime>
11#include <sstream>
12#include <stdexcept>
13
14#include <macaroons.h>
15
16using namespace Macaroons;
17
18namespace {
19
20class AuthzCheck
21{
22public:
23 AuthzCheck(const char *req_path, const Access_Operation req_oper, ssize_t max_duration, XrdSysError &log);
24
25 const std::string &GetSecName() const {return m_sec_name;}
26 const std::string &GetErrorMessage() const {return m_emsg;}
27
28 static int verify_before_s(void *authz_ptr,
29 const unsigned char *pred,
30 size_t pred_sz);
31
32 static int verify_activity_s(void *authz_ptr,
33 const unsigned char *pred,
34 size_t pred_sz);
35
36 static int verify_path_s(void *authz_ptr,
37 const unsigned char *pred,
38 size_t pred_sz);
39
40 static int verify_name_s(void *authz_ptr,
41 const unsigned char *pred,
42 size_t pred_sz);
43
44private:
45 int verify_before(const unsigned char *pred, size_t pred_sz);
46 int verify_activity(const unsigned char *pred, size_t pred_sz);
47 int verify_path(const unsigned char *pred, size_t pred_sz);
48 int verify_name(const unsigned char *pred, size_t pred_sz);
49
50 ssize_t m_max_duration;
51 XrdSysError &m_log;
52 std::string m_emsg;
53 const std::string m_path;
54 std::string m_desired_activity;
55 std::string m_sec_name;
56 Access_Operation m_oper;
57 time_t m_now;
58};
59
60static XrdAccPrivs AddPriv(Access_Operation op, XrdAccPrivs privs)
61{
62 int new_privs = privs;
63 switch (op) {
64 case AOP_Any:
65 break;
66 case AOP_Chmod:
67 new_privs |= static_cast<int>(XrdAccPriv_Chmod);
68 break;
69 case AOP_Chown:
70 new_privs |= static_cast<int>(XrdAccPriv_Chown);
71 break;
72 case AOP_Excl_Create: // fallthrough
73 case AOP_Create:
74 new_privs |= static_cast<int>(XrdAccPriv_Create);
75 break;
76 case AOP_Delete:
77 new_privs |= static_cast<int>(XrdAccPriv_Delete);
78 break;
79 case AOP_Excl_Insert: // fallthrough
80 case AOP_Insert:
81 new_privs |= static_cast<int>(XrdAccPriv_Insert);
82 break;
83 case AOP_Lock:
84 new_privs |= static_cast<int>(XrdAccPriv_Lock);
85 break;
86 case AOP_Mkdir:
87 new_privs |= static_cast<int>(XrdAccPriv_Mkdir);
88 break;
89 case AOP_Read:
90 new_privs |= static_cast<int>(XrdAccPriv_Read);
91 break;
92 case AOP_Readdir:
93 new_privs |= static_cast<int>(XrdAccPriv_Readdir);
94 break;
95 case AOP_Rename:
96 new_privs |= static_cast<int>(XrdAccPriv_Rename);
97 break;
98 case AOP_Stat:
99 new_privs |= static_cast<int>(XrdAccPriv_Lookup);
100 break;
101 case AOP_Update:
102 new_privs |= static_cast<int>(XrdAccPriv_Update);
103 break;
104 case AOP_Stage:
105 new_privs |= static_cast<int>(XrdAccPriv_Stage);
106 break;
107 case AOP_Poll:
108 new_privs |= static_cast<int>(XrdAccPriv_Poll);
109 break;
110 };
111 return static_cast<XrdAccPrivs>(new_privs);
112}
113
114// Accept any value of the path, name, or activity caveats
115int validate_verify_empty(void *emsg_ptr,
116 const unsigned char *pred,
117 size_t pred_sz)
118{
119 if ((pred_sz >= 5) && (!memcmp(reinterpret_cast<const char *>(pred), "path:", 5) ||
120 !memcmp(reinterpret_cast<const char *>(pred), "name:", 5)))
121 {
122 return 0;
123 }
124 if ((pred_sz >= 9) && (!memcmp(reinterpret_cast<const char *>(pred), "activity:", 9)))
125 {
126 return 0;
127 }
128 return 1;
129}
130
131} // unnamed namespace
132
133Authz::Authz(XrdSysLogger *log, char const *config, XrdAccAuthorize *chain)
134 : m_max_duration(86400),
135 m_chain(chain),
136 m_log(log, "macarons_"),
137 m_authz_behavior(static_cast<int>(Handler::AuthzBehavior::PASSTHROUGH))
138{
140 XrdOucEnv env;
141 if (!Handler::Config(config, &env, &m_log, m_location, m_secret, m_max_duration, behavior))
142 {
143 throw std::runtime_error("Macaroon authorization config failed.");
144 }
145 m_authz_behavior = static_cast<int>(behavior);
146}
147
149Authz::OnMissing(const XrdSecEntity *Entity, const char *path,
150 const Access_Operation oper, XrdOucEnv *env)
151{
152 switch (m_authz_behavior) {
154 return m_chain ? m_chain->Access(Entity, path, oper, env) : XrdAccPriv_None;
156 return AddPriv(oper, XrdAccPriv_None);;
158 return XrdAccPriv_None;
159 }
160 // Code should be unreachable.
161 return XrdAccPriv_None;
162}
163
165Authz::Access(const XrdSecEntity *Entity, const char *path,
166 const Access_Operation oper, XrdOucEnv *env)
167{
168 // We don't allow any testing to occur in this authz module, preventing
169 // a macaroon to be used to receive further macaroons.
170 if (oper == AOP_Any)
171 {
172 return m_chain ? m_chain->Access(Entity, path, oper, env) : XrdAccPriv_None;
173 }
174
175 const char *authz = env ? env->Get("authz") : nullptr;
176 if (authz && !strncmp(authz, "Bearer%20", 9))
177 {
178 authz += 9;
179 }
180
181 // If there's no request-specific token, check for a ZTN session token
182 if (!authz && Entity && !strcmp("ztn", Entity->prot) && Entity->creds &&
183 Entity->credslen && Entity->creds[Entity->credslen] == '\0')
184 {
185 authz = Entity->creds;
186 }
187
188 if (!authz) {
189 return OnMissing(Entity, path, oper, env);
190 }
191
192 macaroon_returncode mac_err = MACAROON_SUCCESS;
193 struct macaroon* macaroon = macaroon_deserialize(
194 authz,
195 &mac_err);
196 if (!macaroon)
197 {
198 // Do not log - might be other token type!
199 //m_log.Emsg("Access", "Failed to parse the macaroon");
200 return OnMissing(Entity, path, oper, env);
201 }
202
203 struct macaroon_verifier *verifier = macaroon_verifier_create();
204 if (!verifier)
205 {
206 m_log.Emsg("Access", "Failed to create a new macaroon verifier");
207 return XrdAccPriv_None;
208 }
209 if (!path)
210 {
211 m_log.Emsg("Access", "Request with no provided path.");
212 macaroon_verifier_destroy(verifier);
213 return XrdAccPriv_None;
214 }
215
216 AuthzCheck check_helper(path, oper, m_max_duration, m_log);
217
218 if (macaroon_verifier_satisfy_general(verifier, AuthzCheck::verify_before_s, &check_helper, &mac_err) ||
219 macaroon_verifier_satisfy_general(verifier, AuthzCheck::verify_activity_s, &check_helper, &mac_err) ||
220 macaroon_verifier_satisfy_general(verifier, AuthzCheck::verify_name_s, &check_helper, &mac_err) ||
221 macaroon_verifier_satisfy_general(verifier, AuthzCheck::verify_path_s, &check_helper, &mac_err))
222 {
223 m_log.Emsg("Access", "Failed to configure caveat verifier:");
224 macaroon_verifier_destroy(verifier);
225 return XrdAccPriv_None;
226 }
227
228 const unsigned char *macaroon_loc;
229 size_t location_sz;
230 macaroon_location(macaroon, &macaroon_loc, &location_sz);
231 if (strncmp(reinterpret_cast<const char *>(macaroon_loc), m_location.c_str(), location_sz))
232 {
233 std::string location_str(reinterpret_cast<const char *>(macaroon_loc), location_sz);
234 m_log.Emsg("Access", "Macaroon is for incorrect location", location_str.c_str());
235 macaroon_verifier_destroy(verifier);
236 macaroon_destroy(macaroon);
237 return m_chain ? m_chain->Access(Entity, path, oper, env) : XrdAccPriv_None;
238 }
239
240 if (macaroon_verify(verifier, macaroon,
241 reinterpret_cast<const unsigned char *>(m_secret.c_str()),
242 m_secret.size(),
243 nullptr, 0, // discharge macaroons
244 &mac_err))
245 {
246 m_log.Log(LogMask::Debug, "Access", "Macaroon verification failed");
247 macaroon_verifier_destroy(verifier);
248 macaroon_destroy(macaroon);
249 // This token is from our server (location matched) but caveats or HMAC
250 // failed. Falling through to the chain would let a path-restricted
251 // macaroon bypass its own restrictions. Deny unconditionally.
252 return XrdAccPriv_None;
253 }
254 macaroon_verifier_destroy(verifier);
255
256 const unsigned char *macaroon_id;
257 size_t id_sz;
258 macaroon_identifier(macaroon, &macaroon_id, &id_sz);
259
260 std::string macaroon_id_str(reinterpret_cast<const char *>(macaroon_id), id_sz);
261 m_log.Log(LogMask::Info, "Access", "Macaroon verification successful; ID", macaroon_id_str.c_str());
262 macaroon_destroy(macaroon);
263
264 // Copy the name, if present into the macaroon, into the credential object.
265 if (Entity && check_helper.GetSecName().size()) {
266 const std::string &username = check_helper.GetSecName();
267 m_log.Log(LogMask::Debug, "Access", "Setting the request name to", username.c_str());
268 Entity->eaAPI->Add("request.name", username,true);
269 }
270
271 // We passed verification - give the correct privilege.
272 return AddPriv(oper, XrdAccPriv_None);
273}
274
275bool Authz::Validate(const char *token,
276 std::string &emsg,
277 long long *expT,
278 XrdSecEntity *entP)
279{
280 macaroon_returncode mac_err = MACAROON_SUCCESS;
281 std::unique_ptr<struct macaroon, decltype(&macaroon_destroy)> macaroon(
282 macaroon_deserialize(token, &mac_err),
283 &macaroon_destroy);
284
285 if (!macaroon)
286 {
287 emsg = "Failed to deserialize the token as a macaroon";
288 // Purposely log at debug level in case if this validation is ever
289 // chained so we don't have overly-chatty logs.
290 m_log.Log(LogMask::Debug, "Validate", emsg.c_str());
291 return false;
292 }
293
294 std::unique_ptr<struct macaroon_verifier, decltype(&macaroon_verifier_destroy)> verifier(
295 macaroon_verifier_create(), &macaroon_verifier_destroy);
296 if (!verifier)
297 {
298 emsg = "Internal error: failed to create a verifier.";
299 m_log.Log(LogMask::Error, "Validate", emsg.c_str());
300 return false;
301 }
302
303 // Note the path and operation here are ignored as we won't use those validators
304 AuthzCheck check_helper("/", AOP_Read, m_max_duration, m_log);
305
306 if (macaroon_verifier_satisfy_general(verifier.get(), AuthzCheck::verify_before_s, &check_helper, &mac_err) ||
307 macaroon_verifier_satisfy_general(verifier.get(), validate_verify_empty, nullptr, &mac_err))
308 {
309 emsg = "Failed to configure the verifier";
310 m_log.Log(LogMask::Error, "Validate", emsg.c_str());
311 return false;
312 }
313
314 const unsigned char *macaroon_loc;
315 size_t location_sz;
316 macaroon_location(macaroon.get(), &macaroon_loc, &location_sz);
317 if (strncmp(reinterpret_cast<const char *>(macaroon_loc), m_location.c_str(), location_sz))
318 {
319 emsg = "Macaroon contains incorrect location: " +
320 std::string(reinterpret_cast<const char *>(macaroon_loc), location_sz);
321 m_log.Log(LogMask::Warning, "Validate", emsg.c_str(), ("all.sitename is " + m_location).c_str());
322 return false;
323 }
324
325 if (macaroon_verify(verifier.get(), macaroon.get(),
326 reinterpret_cast<const unsigned char *>(m_secret.c_str()),
327 m_secret.size(),
328 nullptr, 0,
329 &mac_err))
330 {
331 emsg = "Macaroon verification error" + (check_helper.GetErrorMessage().size() ?
332 (", " + check_helper.GetErrorMessage()) : "");
333 m_log.Log(LogMask::Warning, "Validate", emsg.c_str());
334 return false;
335 }
336
337 const unsigned char *macaroon_id;
338 size_t id_sz;
339 macaroon_identifier(macaroon.get(), &macaroon_id, &id_sz);
340 m_log.Log(LogMask::Info, "Validate", ("Macaroon verification successful; ID " +
341 std::string(reinterpret_cast<const char *>(macaroon_id), id_sz)).c_str());
342
343 return true;
344}
345
346AuthzCheck::AuthzCheck(const char *req_path, const Access_Operation req_oper, ssize_t max_duration, XrdSysError &log)
347 : m_max_duration(max_duration),
348 m_log(log),
349 m_path(XrdOucUtils::NormalizePath(req_path)),
350 m_oper(req_oper),
351 m_now(time(nullptr))
352{
353 switch (m_oper)
354 {
355 case AOP_Any:
356 break;
357 case AOP_Chmod:
358 case AOP_Chown:
359 m_desired_activity = "UPDATE_METADATA";
360 break;
361 case AOP_Insert:
362 case AOP_Lock:
363 case AOP_Mkdir:
364 case AOP_Update:
365 case AOP_Create:
366 m_desired_activity = "MANAGE";
367 break;
368 case AOP_Rename:
369 case AOP_Excl_Create:
370 case AOP_Excl_Insert:
371 m_desired_activity = "UPLOAD";
372 break;
373 case AOP_Delete:
374 m_desired_activity = "DELETE";
375 break;
376 case AOP_Read:
377 m_desired_activity = "DOWNLOAD";
378 break;
379 case AOP_Readdir:
380 m_desired_activity = "LIST";
381 break;
382 case AOP_Stat:
383 m_desired_activity = "READ_METADATA";
384 break;
385 case AOP_Stage:
386 case AOP_Poll:
387 break;
388 };
389}
390
391int
392AuthzCheck::verify_before_s(void *authz_ptr,
393 const unsigned char *pred,
394 size_t pred_sz)
395{
396 return static_cast<AuthzCheck*>(authz_ptr)->verify_before(pred, pred_sz);
397}
398
399int
400AuthzCheck::verify_activity_s(void *authz_ptr,
401 const unsigned char *pred,
402 size_t pred_sz)
403{
404 return static_cast<AuthzCheck*>(authz_ptr)->verify_activity(pred, pred_sz);
405}
406
407int
408AuthzCheck::verify_path_s(void *authz_ptr,
409 const unsigned char *pred,
410 size_t pred_sz)
411{
412 return static_cast<AuthzCheck*>(authz_ptr)->verify_path(pred, pred_sz);
413}
414
415int
416AuthzCheck::verify_name_s(void *authz_ptr,
417 const unsigned char *pred,
418 size_t pred_sz)
419{
420 return static_cast<AuthzCheck*>(authz_ptr)->verify_name(pred, pred_sz);
421}
422
423int
424AuthzCheck::verify_before(const unsigned char * pred, size_t pred_sz)
425{
426 std::string pred_str(reinterpret_cast<const char *>(pred), pred_sz);
427 if (strncmp("before:", pred_str.c_str(), 7))
428 {
429 return 1;
430 }
431 m_log.Log(LogMask::Debug, "AuthzCheck", "Checking macaroon for expiration; caveat:", pred_str.c_str());
432
433 struct tm caveat_tm;
434 if (strptime(&pred_str[7], "%Y-%m-%dT%H:%M:%SZ", &caveat_tm) == nullptr)
435 {
436 m_emsg = "Failed to parse time string: " + pred_str.substr(7);
437 m_log.Log(LogMask::Warning, "AuthzCheck", m_emsg.c_str());
438 return 1;
439 }
440 caveat_tm.tm_isdst = -1;
441
442 time_t caveat_time = timegm(&caveat_tm);
443 if (-1 == caveat_time)
444 {
445 m_emsg = "Failed to generate unix time: " + pred_str.substr(7);
446 m_log.Log(LogMask::Warning, "AuthzCheck", m_emsg.c_str());
447 return 1;
448 }
449 if ((m_max_duration > 0) && (caveat_time > m_now + m_max_duration))
450 {
451 m_emsg = "Max token age is greater than configured max duration; rejecting";
452 m_log.Log(LogMask::Warning, "AuthzCheck", m_emsg.c_str());
453 return 1;
454 }
455
456 int result = (m_now >= caveat_time);
457 if (!result)
458 {
459 m_log.Log(LogMask::Debug, "AuthzCheck", "Macaroon has not expired.");
460 }
461 else
462 {
463 m_emsg = "Macaroon expired at " + pred_str.substr(7);
464 m_log.Log(LogMask::Debug, "AuthzCheck", m_emsg.c_str());
465 }
466 return result;
467}
468
469int
470AuthzCheck::verify_activity(const unsigned char * pred, size_t pred_sz)
471{
472 if (!m_desired_activity.size()) {return 1;}
473 std::string pred_str(reinterpret_cast<const char *>(pred), pred_sz);
474 if (strncmp("activity:", pred_str.c_str(), 9)) {return 1;}
475 m_log.Log(LogMask::Debug, "AuthzCheck", "running verify activity", pred_str.c_str());
476
477 std::stringstream ss(pred_str.substr(9));
478 for (std::string activity; std::getline(ss, activity, ','); )
479 {
480 // Any allowed activity also implies "READ_METADATA"
481 if (m_desired_activity == "READ_METADATA") {return 0;}
482 if ((activity == m_desired_activity) || ((m_desired_activity == "UPLOAD") && (activity == "MANAGE")))
483 {
484 m_log.Log(LogMask::Debug, "AuthzCheck", "macaroon has desired activity", activity.c_str());
485 return 0;
486 }
487 }
488 m_log.Log(LogMask::Info, "AuthzCheck", "macaroon does NOT have desired activity", m_desired_activity.c_str());
489 return 1;
490}
491
492int
493AuthzCheck::verify_path(const unsigned char * pred, size_t pred_sz)
494{
495 std::string pred_str_raw(reinterpret_cast<const char *>(pred), pred_sz);
496 if (strncmp("path:", pred_str_raw.c_str(), 5)) {return 1;}
497 std::string pred_str = XrdOucUtils::NormalizePath(pred_str_raw.substr(5));
498 m_log.Log(LogMask::Debug, "AuthzCheck", "running verify path", pred_str.c_str());
499
500 if ((m_path.find("/./") != std::string::npos) ||
501 (m_path.find("/../") != std::string::npos))
502 {
503 m_log.Log(LogMask::Info, "AuthzCheck", "invalid requested path", m_path.c_str());
504 return 1;
505 }
506
507 // Allow operations under subdirectories and not substrings
508 // For e.g. pred_str = "/data/sudir/mydir"
509 // Allows m_path = /data/subdir/mydir/newdir
510 // But rejects, m_path = /data/subdir/mydirmycoolname/newdir
511 int is_subdir = is_subdirectory(pred_str, m_path);
512 if (is_subdir)
513 {
514 m_log.Log(LogMask::Debug, "AuthzCheck", "path request verified for", m_path.c_str());
515 }
516
517 // READ_METADATA (i.e AOP_Stat) permission for /foo/bar automatically implies permission
518 // to READ_METADATA for /foo.
519 // Similarly, MKDIR Pemissions for a parent path is implied.
520 else if (m_oper == AOP_Stat || m_oper == AOP_Mkdir)
521 {
522 is_subdir = is_subdirectory(m_path, pred_str);
523 const char *opName = (m_oper == AOP_Stat) ? "READ_METADATA" : "MKDIR";
524 m_log.Log(LogMask::Debug, "AuthzCheck",
525 (std::string(opName) + (is_subdir? " Path request verified for" : " Path request NOT allowed for")).c_str(),
526 m_path.c_str());
527 }
528 else
529 {
530 m_log.Log(LogMask::Debug, "AuthzCheck", "path request NOT allowed", m_path.c_str());
531 }
532
533 return !is_subdir;
534}
535
536int
537AuthzCheck::verify_name(const unsigned char * pred, size_t pred_sz)
538{
539 std::string pred_str(reinterpret_cast<const char *>(pred), pred_sz);
540 if (strncmp("name:", pred_str.c_str(), 5)) {return 1;}
541 if (pred_str.size() < 6) {return 1;}
542 m_log.Log(LogMask::Debug, "AuthzCheck", "Verifying macaroon with", pred_str.c_str());
543
544 // Make a copy of the name for the XrdSecEntity; this will be used later.
545 m_sec_name = pred_str.substr(5);
546
547 return 0;
548}
Access_Operation
The following are supported operations.
@ AOP_Delete
rm() or rmdir()
@ AOP_Mkdir
mkdir()
@ AOP_Update
open() r/w or append
@ AOP_Create
open() with create
@ AOP_Readdir
opendir()
@ AOP_Chmod
chmod()
@ AOP_Any
Special for getting privs.
@ AOP_Stat
exists(), stat()
@ AOP_Poll
stage polling operations
@ AOP_Rename
mv() for source
@ AOP_Read
open() r/o, prepare()
@ AOP_Excl_Create
open() with O_EXCL|O_CREAT
@ AOP_Insert
mv() for target
@ AOP_Lock
n/a
@ AOP_Chown
chown()
@ AOP_Stage
stage and or read data, plus related operations
@ AOP_Excl_Insert
mv() where destination doesn't exist.
XrdAccPrivs
@ XrdAccPriv_Mkdir
@ XrdAccPriv_Chown
@ XrdAccPriv_Insert
@ XrdAccPriv_Lookup
@ XrdAccPriv_Rename
@ XrdAccPriv_Poll
@ XrdAccPriv_Update
@ XrdAccPriv_Read
@ XrdAccPriv_Lock
@ XrdAccPriv_None
@ XrdAccPriv_Stage
@ XrdAccPriv_Delete
@ XrdAccPriv_Create
@ XrdAccPriv_Readdir
@ XrdAccPriv_Chmod
int emsg(int rc, char *msg)
virtual bool Validate(const char *token, std::string &emsg, long long *expT, XrdSecEntity *entP) override
Authz(XrdSysLogger *lp, const char *parms, XrdAccAuthorize *chain)
virtual XrdAccPrivs Access(const XrdSecEntity *Entity, const char *path, const Access_Operation oper, XrdOucEnv *env) override
static bool Config(const char *config, XrdOucEnv *env, XrdSysError *log, std::string &location, std::string &secret, ssize_t &max_duration, AuthzBehavior &behavior)
XrdAccAuthorize()
Constructor.
virtual XrdAccPrivs Access(const XrdSecEntity *Entity, const char *path, const Access_Operation oper, XrdOucEnv *Env=0)=0
char * Get(const char *varname)
Definition XrdOucEnv.hh:69
static std::string NormalizePath(const std::string &path)
bool Add(XrdSecAttr &attr)
int credslen
Length of the 'creds' data.
XrdSecEntityAttr * eaAPI
non-const API to attributes
char prot[XrdSecPROTOIDSIZE]
Auth protocol used (e.g. krb5).
char * creds
Raw entity credentials or cert.