auth proxy: add VFS options parameter for use for default VFS

This is for use from the RC API.
This commit is contained in:
Nick Craig-Wood
2025-04-09 11:12:07 +01:00
parent df457f5802
commit 028316ba5d
7 changed files with 13 additions and 8 deletions
+1 -1
View File
@@ -175,7 +175,7 @@ func newServer(ctx context.Context, f fs.Fs, opt *Options) (*driver, error) {
opt: *opt, opt: *opt,
} }
if proxyflags.Opt.AuthProxy != "" { if proxyflags.Opt.AuthProxy != "" {
d.proxy = proxy.New(ctx, &proxyflags.Opt) d.proxy = proxy.New(ctx, &proxyflags.Opt, &vfscommon.Opt)
d.userPass = make(map[string]string, 16) d.userPass = make(map[string]string, 16)
} else { } else {
d.globalVFS = vfs.New(f, &vfscommon.Opt) d.globalVFS = vfs.New(f, &vfscommon.Opt)
+1 -1
View File
@@ -146,7 +146,7 @@ func run(ctx context.Context, f fs.Fs, opt Options) (s *HTTP, err error) {
} }
if proxyflags.Opt.AuthProxy != "" { if proxyflags.Opt.AuthProxy != "" {
s.proxy = proxy.New(ctx, &proxyflags.Opt) s.proxy = proxy.New(ctx, &proxyflags.Opt, &vfscommon.Opt)
// override auth // override auth
s.opt.Auth.CustomAuthFn = s.auth s.opt.Auth.CustomAuthFn = s.auth
} else { } else {
+6 -2
View File
@@ -122,6 +122,7 @@ type Proxy struct {
vfsCache *libcache.Cache vfsCache *libcache.Cache
ctx context.Context // for global config ctx context.Context // for global config
Opt Options Opt Options
vfsOpt vfscommon.Options
} }
// cacheEntry is what is stored in the vfsCache // cacheEntry is what is stored in the vfsCache
@@ -131,12 +132,15 @@ type cacheEntry struct {
} }
// New creates a new proxy with the Options passed in // New creates a new proxy with the Options passed in
func New(ctx context.Context, opt *Options) *Proxy { //
// Any VFS are created with the vfsOpt passed in.
func New(ctx context.Context, opt *Options, vfsOpt *vfscommon.Options) *Proxy {
return &Proxy{ return &Proxy{
ctx: ctx, ctx: ctx,
Opt: *opt, Opt: *opt,
cmdLine: strings.Fields(opt.AuthProxy), cmdLine: strings.Fields(opt.AuthProxy),
vfsCache: libcache.New(), vfsCache: libcache.New(),
vfsOpt: *vfsOpt,
} }
} }
@@ -242,7 +246,7 @@ func (p *Proxy) call(user, auth string, isPublicKey bool) (value any, err error)
// need to in memory. An attacker would find it easier to go // need to in memory. An attacker would find it easier to go
// after the unencrypted password in memory most likely. // after the unencrypted password in memory most likely.
entry := cacheEntry{ entry := cacheEntry{
vfs: vfs.New(f, &vfscommon.Opt), vfs: vfs.New(f, &p.vfsOpt),
pwHash: sha256.Sum256([]byte(auth)), pwHash: sha256.Sum256([]byte(auth)),
} }
return entry, true, nil return entry, true, nil
+2 -1
View File
@@ -13,6 +13,7 @@ import (
"github.com/rclone/rclone/fs" "github.com/rclone/rclone/fs"
"github.com/rclone/rclone/fs/config/configmap" "github.com/rclone/rclone/fs/config/configmap"
"github.com/rclone/rclone/fs/config/obscure" "github.com/rclone/rclone/fs/config/obscure"
"github.com/rclone/rclone/vfs/vfscommon"
"github.com/stretchr/testify/assert" "github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require" "github.com/stretchr/testify/require"
"golang.org/x/crypto/ssh" "golang.org/x/crypto/ssh"
@@ -22,7 +23,7 @@ func TestRun(t *testing.T) {
opt := DefaultOpt opt := DefaultOpt
cmd := "go run proxy_code.go" cmd := "go run proxy_code.go"
opt.AuthProxy = cmd opt.AuthProxy = cmd
p := New(context.Background(), &opt) p := New(context.Background(), &opt, &vfscommon.Opt)
t.Run("Normal", func(t *testing.T) { t.Run("Normal", func(t *testing.T) {
config, err := p.run(map[string]string{ config, err := p.run(map[string]string{
+1 -1
View File
@@ -81,7 +81,7 @@ func newServer(ctx context.Context, f fs.Fs, opt *Options) (s *Server, err error
w.handler = w.faker.Server() w.handler = w.faker.Server()
if proxyflags.Opt.AuthProxy != "" { if proxyflags.Opt.AuthProxy != "" {
w.proxy = proxy.New(ctx, &proxyflags.Opt) w.proxy = proxy.New(ctx, &proxyflags.Opt, &vfscommon.Opt)
// proxy auth middleware // proxy auth middleware
w.handler = proxyAuthMiddleware(w.handler, w) w.handler = proxyAuthMiddleware(w.handler, w)
w.handler = authPairMiddleware(w.handler, w) w.handler = authPairMiddleware(w.handler, w)
+1 -1
View File
@@ -53,7 +53,7 @@ func newServer(ctx context.Context, f fs.Fs, opt *Options) *server {
waitChan: make(chan struct{}), waitChan: make(chan struct{}),
} }
if proxyflags.Opt.AuthProxy != "" { if proxyflags.Opt.AuthProxy != "" {
s.proxy = proxy.New(ctx, &proxyflags.Opt) s.proxy = proxy.New(ctx, &proxyflags.Opt, &vfscommon.Opt)
} else { } else {
s.vfs = vfs.New(f, &vfscommon.Opt) s.vfs = vfs.New(f, &vfscommon.Opt)
} }
+1 -1
View File
@@ -205,7 +205,7 @@ func newWebDAV(ctx context.Context, f fs.Fs, opt *Options) (w *WebDAV, err error
opt: *opt, opt: *opt,
} }
if proxyflags.Opt.AuthProxy != "" { if proxyflags.Opt.AuthProxy != "" {
w.proxy = proxy.New(ctx, &proxyflags.Opt) w.proxy = proxy.New(ctx, &proxyflags.Opt, &vfscommon.Opt)
// override auth // override auth
w.opt.Auth.CustomAuthFn = w.auth w.opt.Auth.CustomAuthFn = w.auth
} else { } else {