FastCGI Authorizers and Apache 2.2
Aredridel <[email protected]>
| Newsgroups | gmane.comp.web.fastcgi.devel |
|---|---|
| Message-ID | <1135592114.22686.11.camel@localhost> |
The Apache 2.2 API changes for AAA modules breaks FastCGI Authorizers, Authenticators and Access checkers. The attached patch begins to provide a migration path. The module has to be compiled with -DAPACHE22, as I haven't worked out the kinks of detecting when the module is compiled against Apache 2.2 yet. In this patch, only authenticators are ported to the new API. I'll be working on the remaining parts over the next days, updates will appear at http://cvs.pld-linux.org/SOURCES/apache-mod_fastcgi-apache22.patch and feedback and additions are very welcome. Aria ___________________________________ fastcgi-developers mailing list http://fastcgi.com/fastcgi-developers/
apache-mod_fastcgi-apache22.patch
(text/x-patch, 2.6 KB)
diff -ur mod_fastcgi-2.4.2-o/mod_fastcgi.c mod_fastcgi-2.4.2/mod_fastcgi.c
--- mod_fastcgi-2.4.2-o/mod_fastcgi.c 2005-12-25 02:45:12.000000000 -0700
+++ mod_fastcgi-2.4.2/mod_fastcgi.c 2005-12-26 02:58:58.000000000 -0700
@@ -82,6 +82,10 @@
#include "unixd.h"
+#ifdef APACHE22
+#include "mod_auth.h"
+#endif
+
#endif
#endif
@@ -2657,10 +2661,15 @@
r->status_line = NULL;
}
+#ifdef APACHE22
+static authn_status check_user_authentication(request_rec *r, const char *user, const char *password)
+{
+#else /* !APACHE22 */
static int check_user_authentication(request_rec *r)
{
- int res, authenticated = 0;
const char *password;
+#endif
+ int res, authenticated = 0;
fcgi_request *fr;
const fcgi_dir_config * const dir_config =
(const fcgi_dir_config *)ap_get_module_config(r->per_dir_config, &fastcgi_module);
@@ -2668,9 +2677,11 @@
if (dir_config->authenticator == NULL)
return DECLINED;
- /* Get the user password */
+#ifndef APACHE22
+ /* Get the user password */
if ((res = ap_get_basic_auth_pw(r, &password)) != OK)
return res;
+#endif /* APACHE22 */
res = create_fcgi_request(r, dir_config->authenticator, &fr);
if (res)
@@ -2704,6 +2715,20 @@
goto AuthenticationFailed;
}
+#ifdef APACHE22
+ if (authenticated)
+ return AUTH_GRANTED;
+
+AuthenticationFailed:
+ /* @@@ Probably should support custom_responses */
+ ap_note_basic_auth_failure(r);
+ ap_log_rerror(FCGI_LOG_ERR_NOERRNO, r,
+ "FastCGI: authentication failed for user \"%s\": %s",
+ r->user, r->uri);
+
+ return (res == OK) ? AUTH_DENIED : AUTH_GRANTED;
+
+#else /* !APACHE22 */
if (authenticated)
return OK;
@@ -2722,6 +2747,7 @@
#endif
return (res == OK) ? HTTP_UNAUTHORIZED : res;
+#endif /* !APACHE22 */
}
static int check_user_authorization(request_rec *r)
@@ -2913,6 +2939,15 @@
#ifdef APACHE2
+#ifdef APACHE22
+static const authn_provider authn_fastcgi_provider =
+{
+ &check_user_authentication,
+ NULL,
+};
+#endif /* APACHE22 */
+
+
static void register_hooks(apr_pool_t * p)
{
/* ap_hook_pre_config(x_pre_config, NULL, NULL, APR_HOOK_MIDDLE); */
@@ -2923,6 +2958,11 @@
ap_hook_access_checker(check_access, NULL, NULL, APR_HOOK_MIDDLE);
ap_hook_auth_checker(check_user_authorization, NULL, NULL, APR_HOOK_MIDDLE);
ap_hook_fixups(fixups, NULL, NULL, APR_HOOK_MIDDLE);
+#ifdef APACHE22
+ ap_register_provider(p, AUTHN_PROVIDER_GROUP, "fastcgi", "0",
+ &authn_fastcgi_provider);
+#endif /* APACHE22 */
+
}
module AP_MODULE_DECLARE_DATA fastcgi_module =