Dont expose any information about the user status on login failure (#10925)
Этот коммит содержится в:
коммит произвёл
Christopher Speller
родитель
9dc14d63b7
Коммит
f3801d7db5
@@ -1240,10 +1240,13 @@ func sendPasswordReset(c *Context, w http.ResponseWriter, r *http.Request) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func login(c *Context, w http.ResponseWriter, r *http.Request) {
|
func login(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||||
// For hardened mode, translate all login errors to generic. MFA error being an exception, since it's required for
|
// Translate all login errors to generic. MFA error being an exception, since it's required for the login flow itself
|
||||||
// the login flow itself.
|
|
||||||
defer func() {
|
defer func() {
|
||||||
if *c.App.Config().ServiceSettings.ExperimentalEnableHardenedMode && c.Err != nil && c.Err.Id != "mfa.validate_token.authenticate.app_error" {
|
if c.Err != nil &&
|
||||||
|
c.Err.Id != "mfa.validate_token.authenticate.app_error" &&
|
||||||
|
c.Err.Id != "api.user.login.blank_pwd.app_error" &&
|
||||||
|
c.Err.Id != "api.user.login.bot_login_forbidden.app_error" &&
|
||||||
|
c.Err.Id != "api.user.login.client_side_cert.certificate.app_error" {
|
||||||
c.Err = model.NewAppError("login", "api.user.login.invalid_credentials", nil, "", http.StatusUnauthorized)
|
c.Err = model.NewAppError("login", "api.user.login.invalid_credentials", nil, "", http.StatusUnauthorized)
|
||||||
}
|
}
|
||||||
}()
|
}()
|
||||||
|
|||||||
@@ -2655,7 +2655,7 @@ func TestLogin(t *testing.T) {
|
|||||||
|
|
||||||
t.Run("unknown user", func(t *testing.T) {
|
t.Run("unknown user", func(t *testing.T) {
|
||||||
_, resp := th.Client.Login("unknown", th.BasicUser.Password)
|
_, resp := th.Client.Login("unknown", th.BasicUser.Password)
|
||||||
CheckErrorMessage(t, resp, "store.sql_user.get_for_login.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
})
|
})
|
||||||
|
|
||||||
t.Run("valid login", func(t *testing.T) {
|
t.Run("valid login", func(t *testing.T) {
|
||||||
@@ -2764,7 +2764,7 @@ func TestCBALogin(t *testing.T) {
|
|||||||
th.Client.Logout()
|
th.Client.Logout()
|
||||||
th.Client.HttpHeader["X-SSL-Client-Cert-Subject-DN"] = "C=US, ST=Maryland, L=Pasadena, O=Brent Baccala, OU=FreeSoft, CN=www.freesoft.org/emailAddress=mis_match" + th.BasicUser.Email
|
th.Client.HttpHeader["X-SSL-Client-Cert-Subject-DN"] = "C=US, ST=Maryland, L=Pasadena, O=Brent Baccala, OU=FreeSoft, CN=www.freesoft.org/emailAddress=mis_match" + th.BasicUser.Email
|
||||||
_, resp := th.Client.Login(th.BasicUser.Email, "")
|
_, resp := th.Client.Login(th.BasicUser.Email, "")
|
||||||
CheckBadRequestStatus(t, resp)
|
CheckUnauthorizedStatus(t, resp)
|
||||||
})
|
})
|
||||||
|
|
||||||
t.Run("successful cba login", func(t *testing.T) {
|
t.Run("successful cba login", func(t *testing.T) {
|
||||||
@@ -4114,28 +4114,41 @@ func TestLoginLockout(t *testing.T) {
|
|||||||
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.ServiceSettings.EnableMultifactorAuthentication = true })
|
th.App.UpdateConfig(func(cfg *model.Config) { *cfg.ServiceSettings.EnableMultifactorAuthentication = true })
|
||||||
|
|
||||||
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_password.invalid.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_password.invalid.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_password.invalid.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
_, resp = th.Client.Login(th.BasicUser.Email, "wrong")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
|
|
||||||
|
//Check if lock is active
|
||||||
|
_, resp = th.Client.Login(th.BasicUser.Email, th.BasicUser.Password)
|
||||||
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
|
|
||||||
// Fake user has MFA enabled
|
// Fake user has MFA enabled
|
||||||
if result := <-th.Server.Store.User().UpdateMfaActive(th.BasicUser2.Id, true); result.Err != nil {
|
if result := <-th.Server.Store.User().UpdateMfaActive(th.BasicUser2.Id, true); result.Err != nil {
|
||||||
t.Fatal(result.Err)
|
t.Fatal(result.Err)
|
||||||
}
|
}
|
||||||
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_mfa.bad_code.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_mfa.bad_code.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_mfa.bad_code.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
_, resp = th.Client.LoginWithMFA(th.BasicUser2.Email, th.BasicUser2.Password, "000000")
|
||||||
CheckErrorMessage(t, resp, "api.user.check_user_login_attempts.too_many.app_error")
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
|
|
||||||
|
// Fake user has MFA disabled
|
||||||
|
if result := <-th.Server.Store.User().UpdateMfaActive(th.BasicUser2.Id, false); result.Err != nil {
|
||||||
|
t.Fatal(result.Err)
|
||||||
|
}
|
||||||
|
|
||||||
|
//Check if lock is active
|
||||||
|
_, resp = th.Client.Login(th.BasicUser2.Email, th.BasicUser2.Password)
|
||||||
|
CheckErrorMessage(t, resp, "api.user.login.invalid_credentials")
|
||||||
}
|
}
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user