Plugin delayed authentication.

This commit is contained in:
Roger A. Light
2021-05-19 16:54:26 +01:00
parent 9c9ca33d63
commit 0d3870585b
24 changed files with 481 additions and 11 deletions
+1
View File
@@ -5,4 +5,5 @@ endif()
add_subdirectory(auth-by-ip)
add_subdirectory(client-properties)
add_subdirectory(connection-state)
add_subdirectory(delayed-auth)
add_subdirectory(payload-modification)
+1
View File
@@ -3,6 +3,7 @@ DIRS= \
auth-by-ip \
client-properties \
connection-state \
delayed-auth \
message-timestamp \
payload-modification
@@ -0,0 +1,18 @@
add_library(mosquitto_delayed_auth SHARED
mosquitto_delayed_auth.c
)
target_include_directories(mosquitto_delayed_auth PRIVATE
"${STDBOOL_H_PATH}"
"${STDINT_H_PATH}"
"${mosquitto_SOURCE_DIR}"
"${mosquitto_SOURCE_DIR}/include"
)
set_target_properties(mosquitto_delayed_auth PROPERTIES
PREFIX ""
POSITION_INDEPENDENT_CODE 1
)
# Don't install, these are example plugins only.
#install(TARGETS mosquitto_delayed_auth RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}")
+28
View File
@@ -0,0 +1,28 @@
include ../../../config.mk
.PHONY : all binary check clean reallyclean test install uninstall
PLUGIN_NAME=mosquitto_delayed_auth
PLUGIN_CFLAGS+=-I../../../include -I../../../
all : binary
binary : ${PLUGIN_NAME}.so
${PLUGIN_NAME}.so : ${PLUGIN_NAME}.c
$(CROSS_COMPILE)$(CC) $(PLUGIN_CPPFLAGS) $(PLUGIN_CFLAGS) $(PLUGIN_LDFLAGS) -fPIC -shared $< -o $@
reallyclean : clean
clean:
-rm -f *.o ${PLUGIN_NAME}.so *.gcda *.gcno
check: test
test:
install: ${PLUGIN_NAME}.so
# Don't install, these are examples only.
#$(INSTALL) -d "${DESTDIR}$(libdir)"
#$(INSTALL) ${STRIP_OPTS} ${PLUGIN_NAME}.so "${DESTDIR}${libdir}/${PLUGIN_NAME}.so"
uninstall :
-rm -f "${DESTDIR}${libdir}/${PLUGIN_NAME}.so"
@@ -0,0 +1,176 @@
/*
Copyright (c) 2021 Roger Light <roger@atchoo.org>
All rights reserved. This program and the accompanying materials
are made available under the terms of the Eclipse Public License 2.0
and Eclipse Distribution License v1.0 which accompany this distribution.
The Eclipse Public License is available at
https://www.eclipse.org/legal/epl-2.0/
and the Eclipse Distribution License is available at
http://www.eclipse.org/org/documents/edl-v10.php.
SPDX-License-Identifier: EPL-2.0 OR EDL-1.0
Contributors:
Roger Light - initial implementation and documentation.
*/
/*
* This is an example plugin showing how to carry out delayed authentication.
* The "authentication" in this example makes no checks whatsoever, but delays
* the response by 5 seconds, and randomly chooses whether it should succeed.
*
* Compile with:
* gcc -I<path to mosquitto-repo/include> -fPIC -shared mosquitto_delayed_auth.c -o mosquitto_delayed_auth.so
*
* Use in config with:
*
* plugin /path/to/mosquitto_delayed_auth.so
*
* Note that this only works on Mosquitto 2.0 or later.
*/
#include <limits.h>
#include <stdbool.h>
#include <stdio.h>
#include <string.h>
#include <time.h>
#include <uthash.h>
#include "mosquitto_broker.h"
#include "mosquitto_plugin.h"
#include "mosquitto.h"
#include "mqtt_protocol.h"
#ifndef UNUSED
# define UNUSED(A) (void)(A)
#endif
struct client_list{
UT_hash_handle hh;
char *id;
time_t request_time;
};
static mosquitto_plugin_id_t *mosq_pid = NULL;
static struct client_list *clients = NULL;
static time_t last_check = 0;
bool authentication_check(struct client_list *client, time_t now)
{
time_t secs;
secs = now - client->request_time;
return secs > 5 ? true : false;
}
static int basic_auth_callback(int event, void *event_data, void *userdata)
{
struct mosquitto_evt_basic_auth *ed = event_data;
static struct client_list *client;
const char *id;
UNUSED(event);
UNUSED(userdata);
id = mosquitto_client_id(ed->client);
HASH_FIND(hh, clients, id, strlen(id), client);
if(client){
client->request_time = time(NULL);
}else{
client = mosquitto_malloc(sizeof(struct client_list));
if(client == NULL){
return MOSQ_ERR_NOMEM;
}
client->id = mosquitto_strdup(id);
if(client->id == NULL){
mosquitto_free(client);
return MOSQ_ERR_NOMEM;
}
client->request_time = time(NULL);
HASH_ADD_KEYPTR(hh, clients, client->id, strlen(client->id), client);
mosquitto_log_printf(MOSQ_LOG_DEBUG, "Starting auth for %s at %d", client->id, time(NULL));
}
return MOSQ_ERR_AUTH_DELAYED;
}
static int tick_callback(int event, void *event_data, void *userdata)
{
struct client_list *client, *client_tmp;
time_t now;
long r;
UNUSED(event);
UNUSED(event_data);
UNUSED(userdata);
now = time(NULL);
if(now > last_check){
HASH_ITER(hh, clients, client, client_tmp){
if(authentication_check(client, now)){
/* Deny access 1/4 of the time, yes it's biased number generation. */
r = random() % 1000;
if(r > 740){
mosquitto_complete_basic_auth(client->id, MOSQ_ERR_AUTH);
}else{
mosquitto_complete_basic_auth(client->id, MOSQ_ERR_SUCCESS);
}
mosquitto_log_printf(MOSQ_LOG_DEBUG, "Completing auth for %s at %d", client->id, now);
HASH_DELETE(hh, clients, client);
mosquitto_free(client->id);
mosquitto_free(client);
}
}
last_check = now;
}
return MOSQ_ERR_SUCCESS;
}
int mosquitto_plugin_version(int supported_version_count, const int *supported_versions)
{
int i;
for(i=0; i<supported_version_count; i++){
if(supported_versions[i] == 5){
return 5;
}
}
return -1;
}
int mosquitto_plugin_init(mosquitto_plugin_id_t *identifier, void **user_data, struct mosquitto_opt *opts, int opt_count)
{
int rc;
UNUSED(user_data);
UNUSED(opts);
UNUSED(opt_count);
mosq_pid = identifier;
rc = mosquitto_callback_register(mosq_pid, MOSQ_EVT_BASIC_AUTH, basic_auth_callback, NULL, NULL);
if(rc) return rc;
rc = mosquitto_callback_register(mosq_pid, MOSQ_EVT_TICK, tick_callback, NULL, NULL);
return rc;
}
int mosquitto_plugin_cleanup(void *user_data, struct mosquitto_opt *opts, int opt_count)
{
UNUSED(user_data);
UNUSED(opts);
UNUSED(opt_count);
mosquitto_callback_unregister(mosq_pid, MOSQ_EVT_BASIC_AUTH, basic_auth_callback, NULL);
mosquitto_callback_unregister(mosq_pid, MOSQ_EVT_TICK, tick_callback, NULL);
return 0;
}
+7
View File
@@ -0,0 +1,7 @@
listener 1883
plugin ./mosquitto_delayed_auth.so
sys_interval 1
log_timestamp_format %Y-%m-%dT%H:%M:%S
+3
View File
@@ -0,0 +1,3 @@
#!/bin/sh
../../src/mosquitto -c test.conf -v