Nginx-recepten: basisautorisatie met CAPTCHA

Voor het instellen van autorisatie met CAPTCHA hebben we het volgende nodig met alles wat daarin al aanwezig is, en de inhoud van de map en zijn plugins encrypted-session, form-input, ctpp2, echo, headers-more, auth_request, auth_basic, set-misc. (Ik heb links naar mijn forks gegeven, omdat ik enkele wijzigingen heb aangebracht die ik nog niet in de originele repositories heb kunnen doorvoeren. Je kunt ook gebruikmaken van een kant-en-klare versie.)

Laten we eerst instellen

encrypted_session_key "abcdefghijklmnopqrstuvwxyz123456";

Vervolgens schakelen we, voor de zekerheid, de autorisatie-header uit

more_clear_input_headers Authorization;

Nu beveiligen we alles met autorisatie

auth_request \/auth;
location =\/auth {
    internal;
    subrequest_access_phase on; # staat de autorisatiefase toe in de subaanroep
    auth_request off; # gebruik geen autorisatie
    set_decode_base64 $auth_decode $cookie_auth; # decodeer het autorisatiecookie
    set_decrypt_session $auth_decrypt $auth_decode; # decrypt het autorisatiecookie
    if ($auth_decrypt = "") { return 401 UNAUTHORIZED; } # als decryptie mislukt, is de gebruiker niet geautoriseerd
    more_set_input_headers "Authorization: Basic $auth_decrypt"; # vervang de autorisatie door basis (om de variabele $remote_user te gebruiken)
    auth_basic_user_file \/data\/nginx\/.htaccess; # stel het bestand voor basisautorisatie in
    auth_basic Auth; # zet basisautorisatie aan
    echo -n OK; # de gebruiker is geautoriseerd
}

Voor geautoriseerde gebruikers tonen we de inhoud uit hun map

location \/ {
    alias html\/$remote_user\/;
}

Als er geen autorisatie is, tonen we het autorisatieformulier met CAPTCHA

error_page 401 = @error401;
location @error401 {
    set_escape_uri $request_uri_escape $request_uri; # encode the request
    return 303 /login?request_uri=$request_uri_escape; # redirect to the login form with captcha, preserving the request
}
location =/login {
    default_type "text/html; charset=utf-8"; # set type
    if ($request_method = GET) { # if only to show the login form with captcha
        template login.html.ct2; # set template
        ctpp2 on; # enable templating
        set_secure_random_alphanum $csrf_random 32; # set random csrf
        encrypted_session_expires 300; # set csrf lifetime to 5 minutes (5 * 60 = 300)
        set_encrypt_session $csrf_encrypt $csrf_random; # encrypt random csrf
        set_encode_base64 $csrf_encode $csrf_encrypt; # encode encrypted csrf
        add_header Set-Cookie "CSRF=$csrf_encode; Max-Age=300"; # place encrypted csrf in cookie for 5 minutes (5 * 60 = 300)
        return 200 "{"csrf":"$csrf_random"}"; # return json for the templater
    } # otherwise - process the login form with captcha
    set_form_input $csrf_form csrf; # get csrf from the form
    set_unescape_uri $csrf_unescape $csrf_form; # decode csrf from the form
    set_decode_base64 $csrf_decode $cookie_csrf; # decode csrf from cookie
    set_decrypt_session $csrf_decrypt $csrf_decode; # decrypt csrf from cookie
    if ($csrf_decrypt != $csrf_unescape) { return 303 $request_uri; } # if csrf from the form does not match csrf from the cookie, redirect to show the form again
    set_form_input $captcha_form captcha; # get captcha from the form
    set_unescape_uri $captcha_unescape $captcha_form; # decode captcha from the form
    set_md5 $captcha_md5 "secret${captcha_unescape}${csrf_decrypt}"; # calculate md5
    if ($captcha_md5 != $cookie_captcha) { return 303 $request_uri; } # if md5 does not match the captcha from the cookie, redirect to show the form again
    set_form_input $username_form username; # get username from the form
    set_form_input $password_form password; # get password from the form
    set_unescape_uri $username_unescape $username_form; # decode username from the form
    set_unescape_uri $password_unescape $password_form; # decode password from the form
    encrypted_session_expires 2592000; # set session lifetime to 30 days (30 * 24 * 60 * 60 = 2592000)
    set $username_password "$username_unescape:$password_unescape"; # set basic auth
    set_encode_base64 $username_password_encode $username_password; # encode basic auth
    set_encrypt_session $auth_encrypt $username_password_encode; # encrypt basic auth
    set_encode_base64 $auth_encode $auth_encrypt; # encode encrypted basic auth
    add_header Set-Cookie "Auth=$auth_encode; Max-Age=2592000"; # place encrypted basic auth in the auth cookie for 30 days (30 * 24 * 60 * 60 = 2592000)
    set $arg_request_uri_or_slash $arg_request_uri; # copy request from argument
    set_if_empty $arg_request_uri_or_slash "/"; # if the argument is not set, then start
    set_unescape_uri $request_uri_unescape $arg_request_uri_or_slash; # decode request
    return 303 $request_uri_unescape; # redirect to the saved request
}

login.html

<html>
    <body>
        <form method="post" action="">
            <input type="hidden" name="csrf" value="<TMPL_var csrf>" />
            gebruikersnaam: <input type="text" name="username" placeholder="Voer gebruikersnaam in..." /><br />
            password: <input type="password" name="password" /><br />
            captcha: <img src="/captcha?csrf=<TMPL_var csrf>"/><input type="text" name="captcha" autocomplete="off" /><br />
            <input type="submit" name="submit" value="indienen" />
        <input type="hidden" name="trp-form-language" value="nl"/></form>
    </body>
</html>

Bron: habr.com

Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers šŸ”„ Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers | ProHoster