FastCGI Authorizers and Apache 2.2

Aredridel <[email protected]>
Newsgroups gmane.comp.web.fastcgi.devel
Message-ID <1135592114.22686.11.camel@localhost>
The Apache 2.2 API changes for AAA modules breaks FastCGI Authorizers,
Authenticators and Access checkers.

The attached patch begins to provide a migration path. The module has to
be compiled with -DAPACHE22, as I haven't worked out the kinks of
detecting when the module is compiled against Apache 2.2 yet.

In this patch, only authenticators are ported to the new API. I'll be
working on the remaining parts over the next days, updates will appear
at http://cvs.pld-linux.org/SOURCES/apache-mod_fastcgi-apache22.patch
and feedback and additions are very welcome.

Aria

___________________________________
fastcgi-developers mailing list
http://fastcgi.com/fastcgi-developers/
apache-mod_fastcgi-apache22.patch (text/x-patch, 2.6 KB)
diff -ur mod_fastcgi-2.4.2-o/mod_fastcgi.c mod_fastcgi-2.4.2/mod_fastcgi.c
--- mod_fastcgi-2.4.2-o/mod_fastcgi.c	2005-12-25 02:45:12.000000000 -0700
+++ mod_fastcgi-2.4.2/mod_fastcgi.c	2005-12-26 02:58:58.000000000 -0700
@@ -82,6 +82,10 @@
 
 #include "unixd.h"
 
+#ifdef APACHE22
+#include "mod_auth.h"
+#endif
+
 #endif
 #endif
 
@@ -2657,10 +2661,15 @@
     r->status_line = NULL;
 }
 
+#ifdef APACHE22
+static authn_status check_user_authentication(request_rec *r, const char *user, const char *password)
+{
+#else /* !APACHE22 */
 static int check_user_authentication(request_rec *r)
 {
-    int res, authenticated = 0;
     const char *password;
+#endif
+    int res, authenticated = 0;
     fcgi_request *fr;
     const fcgi_dir_config * const dir_config =
         (const fcgi_dir_config *)ap_get_module_config(r->per_dir_config, &fastcgi_module);
@@ -2668,9 +2677,11 @@
     if (dir_config->authenticator == NULL)
         return DECLINED;
 
-    /* Get the user password */
+#ifndef APACHE22
+		/* Get the user password */
     if ((res = ap_get_basic_auth_pw(r, &password)) != OK)
         return res;
+#endif /* APACHE22 */
 
     res = create_fcgi_request(r, dir_config->authenticator, &fr);
     if (res)
@@ -2704,6 +2715,20 @@
         goto AuthenticationFailed;
     }
 
+#ifdef APACHE22
+    if (authenticated)
+        return AUTH_GRANTED;
+
+AuthenticationFailed:
+    /* @@@ Probably should support custom_responses */
+    ap_note_basic_auth_failure(r);
+    ap_log_rerror(FCGI_LOG_ERR_NOERRNO, r,
+        "FastCGI: authentication failed for user \"%s\": %s",
+        r->user, r->uri);
+
+		return (res == OK) ? AUTH_DENIED : AUTH_GRANTED;
+
+#else /* !APACHE22 */
     if (authenticated)
         return OK;
 
@@ -2722,6 +2747,7 @@
 #endif
 
         return (res == OK) ? HTTP_UNAUTHORIZED : res;
+#endif /* !APACHE22 */
 }
 
 static int check_user_authorization(request_rec *r)
@@ -2913,6 +2939,15 @@
 
 #ifdef APACHE2
 
+#ifdef APACHE22
+static const authn_provider authn_fastcgi_provider =
+{
+    &check_user_authentication,
+		NULL,
+};
+#endif /* APACHE22 */
+
+
 static void register_hooks(apr_pool_t * p)
 {
     /* ap_hook_pre_config(x_pre_config, NULL, NULL, APR_HOOK_MIDDLE); */
@@ -2923,6 +2958,11 @@
     ap_hook_access_checker(check_access, NULL, NULL, APR_HOOK_MIDDLE);
     ap_hook_auth_checker(check_user_authorization, NULL, NULL, APR_HOOK_MIDDLE);
     ap_hook_fixups(fixups, NULL, NULL, APR_HOOK_MIDDLE); 
+#ifdef APACHE22
+		ap_register_provider(p, AUTHN_PROVIDER_GROUP, "fastcgi", "0",
+			 &authn_fastcgi_provider);
+#endif /* APACHE22 */
+
 }
 
 module AP_MODULE_DECLARE_DATA fastcgi_module =
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.