cmd/strelaysrv: Add optional auth token (fixes #3987) (#8561)

* implement authentication via token for relaysrv

Make replaysrv check for a token before allowing clients to
join. The token can be set via the replay-uri.

* fix formatting

* key composite literal

* do not error out if auth material is provided but not needed

* remove unused method receiver

* clean up unused parameter in functions

* cleaner token handling, disable joining the pool if token is set.

* Keep backwards compatibility with older clients.

In prior versions of the protocol JoinRelayRequest did not have a
token field. Trying to unmarshal such a request will result in
an error. Return an empty JoinRelayRequest, that is a request
without token, instead.

Co-authored-by: entity0xfe <entity0xfe@my.domain>
This commit is contained in:
entity0xfe
2022-10-01 20:41:02 +01:00
committed by GitHub
co-authored by entity0xfe
parent 0935886045
commit ad986f372d
6 changed files with 88 additions and 41 deletions
+9
View File
@@ -17,6 +17,7 @@ var (
ResponseSuccess = Response{0, "success"}
ResponseNotFound = Response{1, "not found"}
ResponseAlreadyConnected = Response{2, "already connected"}
ResponseWrongToken = Response{3, "wrong token"}
ResponseUnexpectedMessage = Response{100, "unexpected message"}
)
@@ -107,6 +108,14 @@ func ReadMessage(r io.Reader) (interface{}, error) {
return msg, err
case messageTypeJoinRelayRequest:
var msg JoinRelayRequest
// In prior versions of the protocol JoinRelayRequest did not have a
// token field. Trying to unmarshal such a request will result in
// an error, return msg with an empty token instead.
if header.messageLength == 0 {
return msg, nil
}
err := msg.UnmarshalXDR(buf)
return msg, err
case messageTypeJoinSessionRequest: