Force HTTPS for backend connections in old-style configurations.

Prevents clients from sending a HTTP auth URL to trigger an insecure
connection from the signaling server to Nextcloud.
This commit is contained in:
Joachim Bauch
2021-07-07 09:16:59 +02:00
parent 2662d49017
commit ec71f29fee
5 changed files with 66 additions and 1 deletions
+24
View File
@@ -41,6 +41,8 @@ type Backend struct {
secret []byte
compat bool
allowHttp bool
maxStreamBitrate int
maxScreenBitrate int
@@ -61,6 +63,17 @@ func (b *Backend) IsCompat() bool {
return b.compat
}
func (b *Backend) IsUrlAllowed(u *url.URL) bool {
switch u.Scheme {
case "https":
return true
case "http":
return b.allowHttp
default:
return false
}
}
func (b *Backend) AddSession(session Session) error {
if session.ClientType() == HelloClientTypeInternal || session.ClientType() == HelloClientTypeVirtual {
// Internal and virtual sessions are not counting to the limit.
@@ -102,6 +115,7 @@ type BackendConfiguration struct {
func NewBackendConfiguration(config *goconf.ConfigFile) (*BackendConfiguration, error) {
allowAll, _ := config.GetBool("backend", "allowall")
allowHttp, _ := config.GetBool("backend", "allowhttp")
commonSecret, _ := config.GetString("backend", "secret")
sessionLimit, err := config.GetInt("backend", "sessionlimit")
if err != nil || sessionLimit < 0 {
@@ -116,6 +130,8 @@ func NewBackendConfiguration(config *goconf.ConfigFile) (*BackendConfiguration,
secret: []byte(commonSecret),
compat: true,
allowHttp: allowHttp,
sessionLimit: uint64(sessionLimit),
}
if sessionLimit > 0 {
@@ -150,6 +166,8 @@ func NewBackendConfiguration(config *goconf.ConfigFile) (*BackendConfiguration,
secret: []byte(commonSecret),
compat: true,
allowHttp: allowHttp,
sessionLimit: uint64(sessionLimit),
}
hosts := make([]string, 0, len(allowMap))
@@ -286,6 +304,8 @@ func getConfiguredHosts(backendIds string, config *goconf.ConfigFile) (hosts map
url: u,
secret: []byte(secret),
allowHttp: parsed.Scheme == "http",
maxStreamBitrate: maxStreamBitrate,
maxScreenBitrate: maxScreenBitrate,
@@ -341,6 +361,10 @@ func (b *BackendConfiguration) GetBackend(u *url.URL) *Backend {
s += "/"
}
for _, entry := range entries {
if !entry.IsUrlAllowed(u) {
continue
}
if entry.url == "" {
// Old-style configuration, only hosts are configured.
return entry