Pour effectuer l'authentification avec CAPTCHA, nous avons besoin de ceci et de ses plugins , , , , , , , . (J'ai donné des liens vers mes forks, car j'ai fait certaines modifications qui n'ont pas encore pu être intégrées dans les dépôts originaux. Vous pouvez également utiliser .)
Pour commencer, définissons
clé_session_encryptée "abcdefghijklmnopqrstuvwxyz123456";Ensuite, au cas où, désactivons l'en-tête d'authentification
more_clear_input_headers Authorization;Maintenant, protégeons tout par authentification
demande-auth /auth;
location =/auth {
interne;
accès_sous-requête_phase on; # autoriser la phase d'authentification dans la sous-requête
demande-auth off; # ne pas utiliser l'authentification
set_decode_base64 $auth_decode $cookie_auth; # décodez le cookie d'authentification
set_decrypt_session $auth_decrypt $auth_decode; # déchiffrez l'authentification
if ($auth_decrypt = "") { return 401 NON AUTORISÉ; } # si le déchiffrement échoue, l'utilisateur n'est pas authentifié
more_set_input_headers "Authorization: Basic $auth_decrypt"; # remplacez l'authentification par basic (pour utiliser la variable $remote_user)
auth_basic_ldap_realm Auth; # activez l'authentification ldap
auth_basic_ldap_url ldap://ldap.server.com; # définissez l'adresse
auth_basic_ldap_bind_dn dn.server.com; # définissez le suffixe
echo -n OK; # utilisateur authentifié
}Pour les utilisateurs authentifiés, affichons le contenu de leur dossier
location / {
alias html/$remote_user/;
}Et en l'absence d'authentification, affichons le formulaire d'authentification avec CAPTCHA
error_page 401 = @error401;
location @error401 {
set_escape_uri $request_uri_escape $request_uri; # encode the request
return 303 /login?request_uri=$request_uri_escape; # redirect to the authorization form with captcha, preserving the request
}
location =/login {
default_type "text/html; charset=utf-8"; # set type
if ($request_method = GET) { # if only show the authorization form with captcha
template login.html.ct2; # set template
ctpp2 on; # enable templating
set_secure_random_alphanum $csrf_random 32; # set random csrf
encrypted_session_expires 300; # set csrf lifetime to 5 minutes (5 * 60 = 300)
set_encrypt_session $csrf_encrypt $csrf_random; # encrypt the random csrf
set_encode_base64 $csrf_encode $csrf_encrypt; # encode the encrypted csrf
add_header Set-Cookie "CSRF=$csrf_encode; Max-Age=300"; # place the encrypted csrf in the cookie for 5 minutes (5 * 60 = 300)
return 200 "{"csrf":"$csrf_random"}"; # return json for the templater
} # otherwise, process the authorization form with captcha
set_form_input $csrf_form csrf; # get csrf from the form
set_unescape_uri $csrf_unescape $csrf_form; # unescape csrf from the form
set_decode_base64 $csrf_decode $cookie_csrf; # decode csrf from the cookie
set_decrypt_session $csrf_decrypt $csrf_decode; # decrypt csrf from the cookie
if ($csrf_decrypt != $csrf_unescape) { return 303 $request_uri; } # if csrf from the form does not match csrf from the cookie, redirect to show the form again
set_form_input $captcha_form captcha; # get captcha from the form
set_unescape_uri $captcha_unescape $captcha_form; # unescape captcha from the form
set_md5 $captcha_md5 "secret${captcha_unescape}${csrf_decrypt}"; # calculate md5
if ($captcha_md5 != $cookie_captcha) { return 303 $request_uri; } # if md5 does not match the captcha from the cookie, redirect to show the form again
set_form_input $username_form username; # get login from the form
set_form_input $password_form password; # get password from the form
set_unescape_uri $username_unescape $username_form; # unescape login from the form
set_unescape_uri $password_unescape $password_form; # unescape password from the form
encrypted_session_expires 2592000; # set session lifetime to 30 days (30 * 24 * 60 * 60 = 2592000)
set $username_password "$username_unescape:$password_unescape"; # set basic authorization
set_encode_base64 $username_password_encode $username_password; # encode basic authorization
set_encrypt_session $auth_encrypt $username_password_encode; # encrypt basic authorization
set_encode_base64 $auth_encode $auth_encrypt; # encode the encrypted basic authorization
add_header Set-Cookie "Auth=$auth_encode; Max-Age=2592000"; # place the encrypted basic authorization in the authorization cookie for 30 days (30 * 24 * 60 * 60 = 2592000)
set $arg_request_uri_or_slash $arg_request_uri; # copy request from the argument
set_if_empty $arg_request_uri_or_slash "/"; # if the argument is not specified, then start
set_unescape_uri $request_uri_unescape $arg_request_uri_or_slash; # unescape request
return 303 $request_uri_unescape; # redirect to the saved request
}login.html
<html>
<body>
<form method="post" action="">
<input type="hidden" name="csrf" value="<TMPL_var csrf>" />
nom d'utilisateur : <input type="text" name="username" placeholder="Entrez le nom d'utilisateur..." /><br />
mot de passe : <input type="password" name="password" /><br />
captcha : <img src="/captcha?csrf=<TMPL_var csrf>"/><input type="text" name="captcha" autocomplete="off" /><br />
<input type="submit" name="submit" value="soumettre" />
<input type="hidden" name="trp-form-language" value="fr"/></form>
</body>
</html>Source : habr.com
