Voor het instellen van autorisatie met CAPTCHA hebben we het volgende nodig en zijn plugins , , , , , , , . (Ik heb links naar mijn forks gegeven, omdat ik enkele wijzigingen heb aangebracht die ik nog niet in de originele repositories heb kunnen doorvoeren. Je kunt ook gebruikmaken van .)
Laten we eerst instellen
encrypted_session_key "abcdefghijklmnopqrstuvwxyz123456";Vervolgens schakelen we, voor de zekerheid, de autorisatie-header uit
more_clear_input_headers Authorization;Nu beveiligen we alles met autorisatie
auth_request \/auth;
location =\/auth {
internal;
subrequest_access_phase on; # staat de autorisatiefase toe in de subaanroep
auth_request off; # gebruik geen autorisatie
set_decode_base64 $auth_decode $cookie_auth; # decodeer het autorisatiecookie
set_decrypt_session $auth_decrypt $auth_decode; # decrypt het autorisatiecookie
if ($auth_decrypt = "") { return 401 UNAUTHORIZED; } # als decryptie mislukt, is de gebruiker niet geautoriseerd
more_set_input_headers "Authorization: Basic $auth_decrypt"; # vervang de autorisatie door basis (om de variabele $remote_user te gebruiken)
auth_basic_user_file \/data\/nginx\/.htaccess; # stel het bestand voor basisautorisatie in
auth_basic Auth; # zet basisautorisatie aan
echo -n OK; # de gebruiker is geautoriseerd
}Voor geautoriseerde gebruikers tonen we de inhoud uit hun map
location \/ {
alias html\/$remote_user\/;
}Als er geen autorisatie is, tonen we het autorisatieformulier met CAPTCHA
error_page 401 = @error401;
location @error401 {
set_escape_uri $request_uri_escape $request_uri; # encode the request
return 303 /login?request_uri=$request_uri_escape; # redirect to the login form with captcha, preserving the request
}
location =/login {
default_type "text/html; charset=utf-8"; # set type
if ($request_method = GET) { # if only to show the login form with captcha
template login.html.ct2; # set template
ctpp2 on; # enable templating
set_secure_random_alphanum $csrf_random 32; # set random csrf
encrypted_session_expires 300; # set csrf lifetime to 5 minutes (5 * 60 = 300)
set_encrypt_session $csrf_encrypt $csrf_random; # encrypt random csrf
set_encode_base64 $csrf_encode $csrf_encrypt; # encode encrypted csrf
add_header Set-Cookie "CSRF=$csrf_encode; Max-Age=300"; # place encrypted csrf in cookie for 5 minutes (5 * 60 = 300)
return 200 "{"csrf":"$csrf_random"}"; # return json for the templater
} # otherwise - process the login form with captcha
set_form_input $csrf_form csrf; # get csrf from the form
set_unescape_uri $csrf_unescape $csrf_form; # decode csrf from the form
set_decode_base64 $csrf_decode $cookie_csrf; # decode csrf from cookie
set_decrypt_session $csrf_decrypt $csrf_decode; # decrypt csrf from cookie
if ($csrf_decrypt != $csrf_unescape) { return 303 $request_uri; } # if csrf from the form does not match csrf from the cookie, redirect to show the form again
set_form_input $captcha_form captcha; # get captcha from the form
set_unescape_uri $captcha_unescape $captcha_form; # decode captcha from the form
set_md5 $captcha_md5 "secret${captcha_unescape}${csrf_decrypt}"; # calculate md5
if ($captcha_md5 != $cookie_captcha) { return 303 $request_uri; } # if md5 does not match the captcha from the cookie, redirect to show the form again
set_form_input $username_form username; # get username from the form
set_form_input $password_form password; # get password from the form
set_unescape_uri $username_unescape $username_form; # decode username from the form
set_unescape_uri $password_unescape $password_form; # decode password from the form
encrypted_session_expires 2592000; # set session lifetime to 30 days (30 * 24 * 60 * 60 = 2592000)
set $username_password "$username_unescape:$password_unescape"; # set basic auth
set_encode_base64 $username_password_encode $username_password; # encode basic auth
set_encrypt_session $auth_encrypt $username_password_encode; # encrypt basic auth
set_encode_base64 $auth_encode $auth_encrypt; # encode encrypted basic auth
add_header Set-Cookie "Auth=$auth_encode; Max-Age=2592000"; # place encrypted basic auth in the auth cookie for 30 days (30 * 24 * 60 * 60 = 2592000)
set $arg_request_uri_or_slash $arg_request_uri; # copy request from argument
set_if_empty $arg_request_uri_or_slash "/"; # if the argument is not set, then start
set_unescape_uri $request_uri_unescape $arg_request_uri_or_slash; # decode request
return 303 $request_uri_unescape; # redirect to the saved request
}login.html
<html>
<body>
<form method="post" action="">
<input type="hidden" name="csrf" value="<TMPL_var csrf>" />
gebruikersnaam: <input type="text" name="username" placeholder="Voer gebruikersnaam in..." /><br />
password: <input type="password" name="password" /><br />
captcha: <img src="/captcha?csrf=<TMPL_var csrf>"/><input type="text" name="captcha" autocomplete="off" /><br />
<input type="submit" name="submit" value="indienen" />
<input type="hidden" name="trp-form-language" value="nl"/></form>
</body>
</html>Bron: habr.com
