/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
struct authz_section_conf { constchar *provider_name; constchar *provider_args; constvoid *provider_parsed_args; const authz_provider *provider;
apr_int64_t limited;
authz_logic_op op; int negate; /** true if this is not a real container but produced by AuthMerging;
* only used for logging */ int is_merged;
authz_section_conf *first;
authz_section_conf *next;
};
/* Only per-server directive we have is GLOBAL_ONLY */ staticvoid *merge_authz_core_svr_config(apr_pool_t *p, void *basev, void *newv)
{ return basev;
}
/* This is a fake authz provider that really merges various authz alias *configurationsandtheninvokesthem.
*/ static authz_status authz_alias_check_authorization(request_rec *r, constchar *require_args, constvoid *parsed_require_args)
{ constchar *provider_name;
/* Look up the provider alias in the alias list. *Getthedir_configandcallap_merge_per_dir_configs() *Calltherealprovider->check_authorization()function *Returntheresultoftheabovefunctioncall
*/
/* If we found the alias provider in the list, then merge the directory
configurations and call the real provider */ if (prvdraliasrec) {
ap_conf_vector_t *orig_dir_config = r->per_dir_config;
authz_status ret;
/* Pull the real provider name and the alias name from the block header */
provider_name = ap_getword_conf(cmd->pool, &args);
provider_alias = ap_getword_conf(cmd->pool, &args);
provider_args = ap_getword_conf(cmd->pool, &args);
extra_args = ap_getword_conf(cmd->pool, &args);
/* We only handle one "Require-Parameters" parameter. If several parameters
are needed, they must be enclosed between quotes */ if (extra_args && *extra_args) {
ap_log_error(APLOG_MARK, APLOG_WARNING, 0, cmd->server, APLOGNO(10142) "When several arguments (%s %s...) are passed to a %s directive, " "they must be enclosed in quotation marks. Otherwise, only the " "first one is taken into account",
provider_args, extra_args, cmd->cmd->name);
}
/* Walk the subsection configuration to get the per_dir config that we will *mergejustbeforetherealprovideriscalled.
*/
cmd->override = OR_AUTHCFG | ACCESS_CONF;
errmsg = ap_walk_config(cmd->directive->first_child, cmd,
new_authz_config);
cmd->override = old_overrides;
if (!errmsg) {
provider_alias_rec *prvdraliasrec;
authz_core_srv_conf *authcfg;
/* Save off the new directory config along with the original *providernameandfunctionpointerdata
*/
prvdraliasrec->provider_name = provider_name;
prvdraliasrec->provider_alias = provider_alias;
prvdraliasrec->provider_args = provider_args;
prvdraliasrec->sec_auth = new_authz_config;
prvdraliasrec->provider =
ap_lookup_provider(AUTHZ_PROVIDER_GROUP, provider_name,
AUTHZ_PROVIDER_VERSION);
/* by the time the config file is used, the provider should be loaded *andregisteredwithus.
*/ if (!prvdraliasrec->provider) { return apr_psprintf(cmd->pool, "Unknown Authz provider: %s",
provider_name);
} if (prvdraliasrec->provider->parse_require_line) {
err = prvdraliasrec->provider->parse_require_line(cmd,
provider_args, &prvdraliasrec->provider_parsed_args); if (err) return apr_psprintf(cmd->pool, "Can't parse 'Require %s %s': %s",
provider_name, provider_args, err);
}
/* Register the fake provider so that we get called first */
ap_register_auth_provider(cmd->pool, AUTHZ_PROVIDER_GROUP,
provider_alias, AUTHZ_PROVIDER_VERSION,
&authz_alias_provider,
AP_AUTH_INTERNAL_PER_CONF);
}
/* lookup and cache the actual provider now */
section->provider = ap_lookup_provider(AUTHZ_PROVIDER_GROUP,
section->provider_name,
AUTHZ_PROVIDER_VERSION);
/* by the time the config file is used, the provider should be loaded *andregisteredwithus.
*/ if (!section->provider) { return apr_psprintf(cmd->pool, "Unknown Authz provider: %s",
section->provider_name);
}
/* if the provider doesn't provide the appropriate function, reject it */ if (!section->provider->check_authorization) { return apr_psprintf(cmd->pool, "The '%s' Authz provider is not supported by any " "of the loaded authorization modules",
section->provider_name);
}
while (conf) { if (conf->section) { if (authz_core_check_section(p, s, conf->section, 1) != OK) { return !OK;
}
}
conf = conf->next;
}
return OK;
}
staticconst command_rec authz_cmds[] =
{
AP_INIT_RAW_ARGS("<AuthzProviderAlias", authz_require_alias_section,
NULL, RSRC_CONF, "container for grouping an authorization provider's " "directives under a provider alias"),
AP_INIT_RAW_ARGS("Require", add_authz_provider, NULL, OR_AUTHCFG, "specifies authorization directives " "which one must pass (or not) for a request to suceeed"),
AP_INIT_RAW_ARGS("<RequireAll", add_authz_section, NULL, OR_AUTHCFG, "container for grouping authorization directives " "of which none must fail and at least one must pass " "for a request to succeed"),
AP_INIT_RAW_ARGS("<RequireAny", add_authz_section, NULL, OR_AUTHCFG, "container for grouping authorization directives " "of which one must pass " "for a request to succeed"), #ifdef AUTHZ_EXTRA_CONFIGS
AP_INIT_RAW_ARGS("<RequireNotAll", add_authz_section, NULL, OR_AUTHCFG, "container for grouping authorization directives " "of which some must fail or none must pass " "for a request to succeed"), #endif
AP_INIT_RAW_ARGS("<RequireNone", add_authz_section, NULL, OR_AUTHCFG, "container for grouping authorization directives " "of which none must pass " "for a request to succeed"),
AP_INIT_TAKE1("AuthMerging", authz_merge_sections, NULL, OR_AUTHCFG, "controls how a <Directory>, <Location>, or similar " "directive's authorization directives are combined with " "those of its predecessor"),
AP_INIT_FLAG("AuthzSendForbiddenOnFailure", ap_set_flag_slot_char,
(void *)APR_OFFSETOF(authz_core_dir_conf, authz_forbidden_on_fail),
OR_AUTHCFG, "Controls if an authorization failure should result in a " "'403 FORBIDDEN' response instead of the HTTP-conforming " "'401 UNAUTHORIZED'"),
{NULL}
};
/* check to make sure that the request method requires authorization */ if (!(section->limited & (AP_METHOD_BIT << r->method_number))) {
auth_result =
(parent_op == AUTHZ_LOGIC_AND) ? AUTHZ_GRANTED : AUTHZ_NEUTRAL;
ap_log_rerror(APLOG_MARK, APLOG_DEBUG, APR_SUCCESS, r, APLOGNO(01625) "authorization result of %s: %s " "(directive limited to other methods)",
format_authz_command(r->pool, section),
format_authz_result(auth_result));
return auth_result;
}
if (section->provider) {
apr_table_setn(r->notes, AUTHZ_PROVIDER_NAME_NOTE,
section->provider_name);
if (section->negate) { if (auth_result == AUTHZ_GRANTED) {
auth_result = AUTHZ_DENIED;
} elseif (auth_result == AUTHZ_DENIED ||
auth_result == AUTHZ_DENIED_NO_USER) { /* For negated directives, if the original result was denied *thenthenewresultisneutralsincewecannotgrant *accesssimplybecauseauthorizationwasnotrejected.
*/
auth_result = AUTHZ_NEUTRAL;
}
}
ap_log_rerror(APLOG_MARK, APLOG_DEBUG, APR_SUCCESS, r, APLOGNO(01626) "authorization result of %s: %s",
format_authz_command(r->pool, section),
format_authz_result(auth_result));
return auth_result;
}
staticint authorize_user_core(request_rec *r, int after_authn)
{
authz_core_dir_conf *conf;
authz_status auth_result;
/* The 'env' provider will allow the configuration to specify a list of envvariablestocheckratherthanasinglevariable.Thisisdifferent
from the previous host based syntax. */
t = require_line; while ((w = ap_getword_conf(r->pool, &t)) && w[0]) { if (apr_table_get(r->subprocess_env, w)) { return AUTHZ_GRANTED;
}
}
AP_DECLARE_MODULE(authz_core) =
{
STANDARD20_MODULE_STUFF,
create_authz_core_dir_config, /* dir config creater */
merge_authz_core_dir_config, /* dir merger */
create_authz_core_svr_config, /* server config */
merge_authz_core_svr_config , /* merge server config */
authz_cmds,
register_hooks /* register hooks */
};
Messung V0.5 in Prozent
¤ Diese beiden folgenden Angebotsgruppen bietet das Unternehmen0.23Angebot
(Wie Sie bei der Firma Beratungs- und Dienstleistungen beauftragen können 2026-09-29)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.