2012-09-20 07:51:34 +04:00
|
|
|
/**
|
|
|
|
* xrdp: A Remote Desktop Protocol server.
|
|
|
|
*
|
2015-10-11 08:16:16 +03:00
|
|
|
* Copyright (C) Jay Sorg 2004-2015
|
2012-09-20 07:51:34 +04:00
|
|
|
*
|
|
|
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
* you may not use this file except in compliance with the License.
|
|
|
|
* You may obtain a copy of the License at
|
|
|
|
*
|
|
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
*
|
|
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
|
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
* See the License for the specific language governing permissions and
|
|
|
|
* limitations under the License.
|
|
|
|
*/
|
2006-05-26 17:10:14 +04:00
|
|
|
|
|
|
|
/**
|
|
|
|
*
|
|
|
|
* @file scp_v0.c
|
|
|
|
* @brief scp version 0 implementation
|
|
|
|
* @author Jay Sorg, Simone Fedele
|
2008-07-30 14:58:30 +04:00
|
|
|
*
|
2006-05-26 17:10:14 +04:00
|
|
|
*/
|
|
|
|
|
2017-03-03 07:33:23 +03:00
|
|
|
#if defined(HAVE_CONFIG_H)
|
|
|
|
#include <config_ac.h>
|
|
|
|
#endif
|
|
|
|
|
2006-05-26 17:10:14 +04:00
|
|
|
#include "sesman.h"
|
|
|
|
|
2012-09-20 07:51:34 +04:00
|
|
|
extern struct config_sesman *g_cfg; /* in sesman.c */
|
2008-02-21 01:02:24 +03:00
|
|
|
|
2006-05-26 17:10:14 +04:00
|
|
|
/******************************************************************************/
|
2017-03-12 19:35:00 +03:00
|
|
|
void
|
2012-09-20 07:51:34 +04:00
|
|
|
scp_v0_process(struct SCP_CONNECTION *c, struct SCP_SESSION *s)
|
2006-05-26 17:10:14 +04:00
|
|
|
{
|
2012-09-20 07:51:34 +04:00
|
|
|
int display = 0;
|
|
|
|
tbus data;
|
|
|
|
struct session_item *s_item;
|
2015-12-12 07:41:17 +03:00
|
|
|
int errorcode = 0;
|
2017-03-21 04:59:44 +03:00
|
|
|
bool_t do_auth_end = 1;
|
2007-02-01 09:03:46 +03:00
|
|
|
|
2015-12-12 07:41:17 +03:00
|
|
|
data = auth_userpass(s->username, s->password, &errorcode);
|
2012-09-20 07:51:34 +04:00
|
|
|
|
|
|
|
if (s->type == SCP_GW_AUTHENTICATION)
|
2006-05-26 17:10:14 +04:00
|
|
|
{
|
2012-09-20 07:51:34 +04:00
|
|
|
/* this is just authentication in a gateway situation */
|
|
|
|
/* g_writeln("SCP_GW_AUTHENTICATION message received"); */
|
|
|
|
if (data)
|
|
|
|
{
|
|
|
|
if (1 == access_login_allowed(s->username))
|
|
|
|
{
|
|
|
|
/* the user is member of the correct groups. */
|
2013-01-16 13:28:35 +04:00
|
|
|
scp_v0s_replyauthentication(c, errorcode);
|
2012-09-20 07:51:34 +04:00
|
|
|
log_message(LOG_LEVEL_INFO, "Access permitted for user: %s",
|
|
|
|
s->username);
|
|
|
|
/* g_writeln("Connection allowed"); */
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2015-10-11 08:16:16 +03:00
|
|
|
scp_v0s_replyauthentication(c, 32 + 3); /* all first 32 are reserved for PAM errors */
|
2012-09-20 07:51:34 +04:00
|
|
|
log_message(LOG_LEVEL_INFO, "Username okey but group problem for "
|
|
|
|
"user: %s", s->username);
|
|
|
|
/* g_writeln("user password ok, but group problem"); */
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
/* g_writeln("username or password error"); */
|
|
|
|
log_message(LOG_LEVEL_INFO, "Username or password error for user: %s",
|
|
|
|
s->username);
|
2013-01-16 13:28:35 +04:00
|
|
|
scp_v0s_replyauthentication(c, errorcode);
|
2012-09-20 07:51:34 +04:00
|
|
|
}
|
2006-10-15 17:08:08 +04:00
|
|
|
}
|
2012-09-20 07:51:34 +04:00
|
|
|
else if (data)
|
2006-10-15 17:08:08 +04:00
|
|
|
{
|
2012-09-20 07:51:34 +04:00
|
|
|
s_item = session_get_bydata(s->username, s->width, s->height,
|
2014-04-20 11:42:19 +04:00
|
|
|
s->bpp, s->type, s->client_ip);
|
2012-09-20 07:51:34 +04:00
|
|
|
|
|
|
|
if (s_item != 0)
|
2010-11-04 14:14:03 +03:00
|
|
|
{
|
2012-09-20 07:51:34 +04:00
|
|
|
display = s_item->display;
|
2016-12-05 04:20:01 +03:00
|
|
|
g_memcpy(s->guid, s_item->guid, 16);
|
2012-09-20 07:51:34 +04:00
|
|
|
if (0 != s->client_ip)
|
|
|
|
{
|
|
|
|
log_message( LOG_LEVEL_INFO, "++ reconnected session: username %s, "
|
|
|
|
"display :%d.0, session_pid %d, ip %s",
|
|
|
|
s->username, display, s_item->pid, s->client_ip);
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
log_message(LOG_LEVEL_INFO, "++ reconnected session: username %s, "
|
|
|
|
"display :%d.0, session_pid %d", s->username, display,
|
|
|
|
s_item->pid);
|
|
|
|
}
|
|
|
|
|
2018-05-31 12:30:11 +03:00
|
|
|
session_reconnect(display, s->username, data);
|
2010-11-04 14:14:03 +03:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2012-09-20 07:51:34 +04:00
|
|
|
LOG_DBG("pre auth");
|
|
|
|
|
|
|
|
if (1 == access_login_allowed(s->username))
|
|
|
|
{
|
2016-12-04 10:12:48 +03:00
|
|
|
tui8 guid[16];
|
|
|
|
|
|
|
|
g_random((char*)guid, 16);
|
|
|
|
scp_session_set_guid(s, guid);
|
|
|
|
|
2012-09-20 07:51:34 +04:00
|
|
|
if (0 != s->client_ip)
|
|
|
|
{
|
|
|
|
log_message(LOG_LEVEL_INFO, "++ created session (access granted): "
|
|
|
|
"username %s, ip %s", s->username, s->client_ip);
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
log_message(LOG_LEVEL_INFO, "++ created session (access granted): "
|
|
|
|
"username %s", s->username);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (SCP_SESSION_TYPE_XVNC == s->type)
|
|
|
|
{
|
|
|
|
log_message( LOG_LEVEL_INFO, "starting Xvnc session...");
|
2017-03-19 00:45:58 +03:00
|
|
|
display = session_start(data, SESMAN_SESSION_TYPE_XVNC, c, s);
|
2012-09-20 07:51:34 +04:00
|
|
|
}
|
2014-03-09 04:41:37 +04:00
|
|
|
else if (SCP_SESSION_TYPE_XRDP == s->type)
|
2012-09-20 07:51:34 +04:00
|
|
|
{
|
|
|
|
log_message(LOG_LEVEL_INFO, "starting X11rdp session...");
|
2017-03-19 00:45:58 +03:00
|
|
|
display = session_start(data, SESMAN_SESSION_TYPE_XRDP, c, s);
|
2015-10-11 08:16:16 +03:00
|
|
|
}
|
2014-03-22 15:36:33 +04:00
|
|
|
else if (SCP_SESSION_TYPE_XORG == s->type)
|
2014-03-09 04:41:37 +04:00
|
|
|
{
|
2015-10-11 08:16:16 +03:00
|
|
|
/* type is SCP_SESSION_TYPE_XORG */
|
2014-03-22 15:36:33 +04:00
|
|
|
log_message(LOG_LEVEL_INFO, "starting Xorg session...");
|
2017-03-19 00:45:58 +03:00
|
|
|
display = session_start(data, SESMAN_SESSION_TYPE_XORG, c, s);
|
2012-09-20 07:51:34 +04:00
|
|
|
}
|
2017-03-21 04:59:44 +03:00
|
|
|
/* if the session started up ok, auth_end will be called on
|
|
|
|
sig child */
|
|
|
|
do_auth_end = display == 0;
|
2012-09-20 07:51:34 +04:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
display = 0;
|
|
|
|
}
|
2010-11-04 14:14:03 +03:00
|
|
|
}
|
|
|
|
|
2012-09-20 07:51:34 +04:00
|
|
|
if (display == 0)
|
2006-05-26 17:10:14 +04:00
|
|
|
{
|
2012-09-20 07:51:34 +04:00
|
|
|
scp_v0s_deny_connection(c);
|
2006-05-26 17:10:14 +04:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2016-12-04 10:12:48 +03:00
|
|
|
scp_v0s_allow_connection(c, display, s->guid);
|
2006-05-26 17:10:14 +04:00
|
|
|
}
|
2006-10-15 17:08:08 +04:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2012-09-20 07:51:34 +04:00
|
|
|
scp_v0s_deny_connection(c);
|
2006-10-15 17:08:08 +04:00
|
|
|
}
|
2017-03-21 04:59:44 +03:00
|
|
|
if (do_auth_end)
|
|
|
|
{
|
|
|
|
auth_end(data);
|
|
|
|
}
|
2006-05-26 17:10:14 +04:00
|
|
|
}
|