Recettes Nginx : autorisation LDAP avec captcha

Pour effectuer l'authentification avec CAPTCHA, nous avons besoin de ceci nginx et de ses plugins session-encryptée, input-formulaire, ctpp2, echo, ldap, headers-plus, demande-auth, set-misc. (J'ai donné des liens vers mes forks, car j'ai fait certaines modifications qui n'ont pas encore pu être intégrées dans les dépôts originaux. Vous pouvez également utiliser une méthode prête à l'emploi.)

Pour commencer, définissons

clé_session_encryptée "abcdefghijklmnopqrstuvwxyz123456";

Ensuite, au cas où, désactivons l'en-tête d'authentification

more_clear_input_headers Authorization;

Maintenant, protégeons tout par authentification

demande-auth /auth;
location =/auth {
    interne;
    accès_sous-requête_phase on; # autoriser la phase d'authentification dans la sous-requête
    demande-auth off; # ne pas utiliser l'authentification
    set_decode_base64 $auth_decode $cookie_auth; # décodez le cookie d'authentification
    set_decrypt_session $auth_decrypt $auth_decode; # déchiffrez l'authentification
    if ($auth_decrypt = "") { return 401 NON AUTORISÉ; } # si le déchiffrement échoue, l'utilisateur n'est pas authentifié
    more_set_input_headers "Authorization: Basic $auth_decrypt"; # remplacez l'authentification par basic (pour utiliser la variable $remote_user)
    auth_basic_ldap_realm Auth; # activez l'authentification ldap
    auth_basic_ldap_url ldap://ldap.server.com; # définissez l'adresse
    auth_basic_ldap_bind_dn dn.server.com; # définissez le suffixe
    echo -n OK; # utilisateur authentifié
}

Pour les utilisateurs authentifiés, affichons le contenu de leur dossier

location / {
    alias html/$remote_user/;
}

Et en l'absence d'authentification, affichons le formulaire d'authentification avec CAPTCHA

error_page 401 = @error401;
location @error401 {
    set_escape_uri $request_uri_escape $request_uri; # encode the request
    return 303 /login?request_uri=$request_uri_escape; # redirect to the authorization form with captcha, preserving the request
}
location =/login {
    default_type "text/html; charset=utf-8"; # set type
    if ($request_method = GET) { # if only show the authorization form with captcha
        template login.html.ct2; # set template
        ctpp2 on; # enable templating
        set_secure_random_alphanum $csrf_random 32; # set random csrf
        encrypted_session_expires 300; # set csrf lifetime to 5 minutes (5 * 60 = 300)
        set_encrypt_session $csrf_encrypt $csrf_random; # encrypt the random csrf
        set_encode_base64 $csrf_encode $csrf_encrypt; # encode the encrypted csrf
        add_header Set-Cookie "CSRF=$csrf_encode; Max-Age=300"; # place the encrypted csrf in the cookie for 5 minutes (5 * 60 = 300)
        return 200 "{"csrf":"$csrf_random"}"; # return json for the templater
    } # otherwise, process the authorization form with captcha
    set_form_input $csrf_form csrf; # get csrf from the form
    set_unescape_uri $csrf_unescape $csrf_form; # unescape csrf from the form
    set_decode_base64 $csrf_decode $cookie_csrf; # decode csrf from the cookie
    set_decrypt_session $csrf_decrypt $csrf_decode; # decrypt csrf from the cookie
    if ($csrf_decrypt != $csrf_unescape) { return 303 $request_uri; } # if csrf from the form does not match csrf from the cookie, redirect to show the form again
    set_form_input $captcha_form captcha; # get captcha from the form
    set_unescape_uri $captcha_unescape $captcha_form; # unescape captcha from the form
    set_md5 $captcha_md5 "secret${captcha_unescape}${csrf_decrypt}"; # calculate md5
    if ($captcha_md5 != $cookie_captcha) { return 303 $request_uri; } # if md5 does not match the captcha from the cookie, redirect to show the form again
    set_form_input $username_form username; # get login from the form
    set_form_input $password_form password; # get password from the form
    set_unescape_uri $username_unescape $username_form; # unescape login from the form
    set_unescape_uri $password_unescape $password_form; # unescape password from the form
    encrypted_session_expires 2592000; # set session lifetime to 30 days (30 * 24 * 60 * 60 = 2592000)
    set $username_password "$username_unescape:$password_unescape"; # set basic authorization
    set_encode_base64 $username_password_encode $username_password; # encode basic authorization
    set_encrypt_session $auth_encrypt $username_password_encode; # encrypt basic authorization
    set_encode_base64 $auth_encode $auth_encrypt; # encode the encrypted basic authorization
    add_header Set-Cookie "Auth=$auth_encode; Max-Age=2592000"; # place the encrypted basic authorization in the authorization cookie for 30 days (30 * 24 * 60 * 60 = 2592000)
    set $arg_request_uri_or_slash $arg_request_uri; # copy request from the argument
    set_if_empty $arg_request_uri_or_slash "/"; # if the argument is not specified, then start
    set_unescape_uri $request_uri_unescape $arg_request_uri_or_slash; # unescape request
    return 303 $request_uri_unescape; # redirect to the saved request
}

login.html

<html>
    <body>
        <form method="post" action="">
            <input type="hidden" name="csrf" value="<TMPL_var csrf>" />
            nom d'utilisateur : <input type="text" name="username" placeholder="Entrez le nom d&#039;utilisateur..." /><br />
            mot de passe : <input type="password" name="password" /><br />
            captcha : <img src="/captcha?csrf=<TMPL_var csrf>"/><input type="text" name="captcha" autocomplete="off" /><br />
            <input type="submit" name="submit" value="soumettre" />
        <input type="hidden" name="trp-form-language" value="fr"/></form>
    </body>
</html>

Source : habr.com

Acheter un hébergement fiable pour les sites avec protection DDoS, serveurs VPS VDS 🔥 Acheter un hébergement fiable pour les sites avec protection DDoS, serveurs VPS VDS | ProHoster