Linux anchor 4.4.0-210-generic #242-Ubuntu SMP Fri Apr 16 09:57:56 UTC 2021 x86_64
Apache/2.4.18 (Ubuntu)
Server IP : 10.10.100.4 & Your IP : 216.73.217.150
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
var /
www /
owncloud-prm /
lib /
private /
User /
Delete
Unzip
Name
Size
Permission
Date
Action
Sync
[ DIR ]
drwxr-xr-x
2018-04-19 18:15
Account.php
2.76
KB
-rw-r--r--
2018-04-19 18:15
AccountMapper.php
8.03
KB
-rw-r--r--
2018-04-19 18:15
AccountTerm.php
1.17
KB
-rw-r--r--
2018-04-19 18:15
AccountTermMapper.php
2.22
KB
-rw-r--r--
2018-04-19 18:15
Backend.php
4.07
KB
-rw-r--r--
2018-04-19 18:15
BasicAuthModule.php
4
KB
-rw-r--r--
2018-04-19 18:15
Database.php
9.91
KB
-rw-r--r--
2018-04-19 18:15
LoginException.php
862
B
-rw-r--r--
2018-04-19 18:15
Manager.php
13.18
KB
-rw-r--r--
2018-04-19 18:15
NoUserException.php
818
B
-rw-r--r--
2018-04-19 18:15
RemoteUser.php
3.29
KB
-rw-r--r--
2018-04-19 18:15
Session.php
30.16
KB
-rw-r--r--
2018-04-19 18:15
SyncService.php
12.19
KB
-rw-r--r--
2018-04-19 18:15
TokenAuthModule.php
3.53
KB
-rw-r--r--
2018-04-19 18:15
User.php
12.83
KB
-rw-r--r--
2018-04-19 18:15
Save
Rename
<?php /** * @author Thomas Müller <thomas.mueller@tmit.eu> * * @copyright Copyright (c) 2018, ownCloud GmbH * @license AGPL-3.0 * * This code is free software: you can redistribute it and/or modify * it under the terms of the GNU Affero General Public License, version 3, * as published by the Free Software Foundation. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU Affero General Public License for more details. * * You should have received a copy of the GNU Affero General Public License, version 3, * along with this program. If not, see <http://www.gnu.org/licenses/> * */ namespace OC\User; use OC\Authentication\Exceptions\InvalidTokenException; use OC\Authentication\Exceptions\PasswordlessTokenException; use OC\Authentication\Token\IProvider; use OC\Authentication\Token\IToken; use OCP\Authentication\IAuthModule; use OCP\IRequest; use OCP\ISession; use OCP\IUser; use OCP\IUserManager; use OCP\Session\Exceptions\SessionNotAvailableException; class TokenAuthModule implements IAuthModule { /** @var ISession */ private $session; /** @var IProvider */ private $tokenProvider; /** @var IUserManager */ private $manager; /** @var string */ private $password = ''; public function __construct(ISession $session, IProvider $tokenProvider, IUserManager $manager) { $this->session = $session; $this->tokenProvider = $tokenProvider; $this->manager = $manager; } /** * @inheritdoc */ public function auth(IRequest $request) { $dbToken = $this->getTokenForAppPassword($request, $token); if ($dbToken === null) { $dbToken = $this->getToken($request, $token); } if ($dbToken === null) { return null; } // When logging in with token, the password must be decrypted first before passing to login hook try { $this->password = $this->tokenProvider->getPassword($dbToken, $token); } catch (PasswordlessTokenException $ex) { // Ignore and use empty string instead } $uid = $dbToken->getUID(); return $this->manager->get($uid); } /** * @inheritdoc */ public function getUserPassword(IRequest $request) { return $this->password; } /** * @param IRequest $request * @return null|IToken */ private function getTokenForAppPassword(IRequest $request, &$token) { if (!isset($request->server['PHP_AUTH_USER'], $request->server['PHP_AUTH_PW'])) { return null; } try { $token = $request->server['PHP_AUTH_PW']; $dbToken = $this->tokenProvider->getToken($token); if ($dbToken->getUID() !== $request->server['PHP_AUTH_USER']) { throw new \Exception('Invalid credentials'); } return $dbToken; } catch (InvalidTokenException $ex) { // invalid app passwords do NOT throw an exception because basic // auth headers can be evaluated properly in the basic auth module $token = null; return null; } } /** * @param IRequest $request * @return null|IToken * @throws \Exception */ private function getToken(IRequest $request, &$token) { $authHeader = $request->getHeader('Authorization'); if ($authHeader === null || strpos($authHeader, 'token ') === false) { // No auth header, let's try session id try { $token = $this->session->getId(); } catch (SessionNotAvailableException $ex) { return null; } } else { $token = substr($authHeader, 6); } try { return $this->tokenProvider->getToken($token); } catch (InvalidTokenException $ex) { $token = null; return null; } } }