mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-09-30 03:31:27 +02:00
Address gosec findings
Mostly handling unhandled errors appropriately. If logging to STDERR fails, we panic. Added #nosec comments to findings we are OK with.
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
package basic
|
||||
|
||||
import (
|
||||
"crypto/sha1"
|
||||
"crypto/sha1" // #nosec G505
|
||||
"encoding/base64"
|
||||
"encoding/csv"
|
||||
"fmt"
|
||||
@@ -29,11 +29,16 @@ type sha1Pass string
|
||||
// NewHTPasswdValidator constructs an httpasswd based validator from the file
|
||||
// at the path given.
|
||||
func NewHTPasswdValidator(path string) (Validator, error) {
|
||||
r, err := os.Open(path)
|
||||
r, err := os.Open(path) // #nosec G304
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("could not open htpasswd file: %v", err)
|
||||
}
|
||||
defer r.Close()
|
||||
defer func(c io.Closer) {
|
||||
cerr := c.Close()
|
||||
if cerr != nil {
|
||||
logger.Fatalf("error closing the htpasswd file: %v", cerr)
|
||||
}
|
||||
}(r)
|
||||
return newHtpasswd(r)
|
||||
}
|
||||
|
||||
@@ -83,13 +88,16 @@ func (h *htpasswdMap) Validate(user string, password string) bool {
|
||||
return false
|
||||
}
|
||||
|
||||
switch real := realPassword.(type) {
|
||||
switch rp := realPassword.(type) {
|
||||
case sha1Pass:
|
||||
d := sha1.New()
|
||||
d.Write([]byte(password))
|
||||
return string(real) == base64.StdEncoding.EncodeToString(d.Sum(nil))
|
||||
d := sha1.New() // #nosec G401
|
||||
_, err := d.Write([]byte(password))
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
return string(rp) == base64.StdEncoding.EncodeToString(d.Sum(nil))
|
||||
case bcryptPass:
|
||||
return bcrypt.CompareHashAndPassword([]byte(real), []byte(password)) == nil
|
||||
return bcrypt.CompareHashAndPassword([]byte(rp), []byte(password)) == nil
|
||||
default:
|
||||
return false
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user