diff options
author | Lukas Fleischer <lfleischer@archlinux.org> | 2015-06-01 23:36:14 +0200 |
---|---|---|
committer | Lukas Fleischer <lfleischer@archlinux.org> | 2015-06-02 10:34:34 +0200 |
commit | 10ecd3982decc31bda251ec73d00d6a903a75f9f (patch) | |
tree | acd7b8fb78ce116daae4efbfdb11582cbc35e51a /git-interface/git-auth.py | |
parent | 451e60d91d48d69ba6ae139794c5168804d59136 (diff) | |
download | aur-10ecd3982decc31bda251ec73d00d6a903a75f9f.tar.gz aur-10ecd3982decc31bda251ec73d00d6a903a75f9f.tar.xz |
Restructure scripts
* Move scripts/git-integration/ to git-interface/.
* Move scripts/aurblup/aurblup.py to scripts/aurblup.py.
Signed-off-by: Lukas Fleischer <lfleischer@archlinux.org>
Diffstat (limited to 'git-interface/git-auth.py')
-rwxr-xr-x | git-interface/git-auth.py | 44 |
1 files changed, 44 insertions, 0 deletions
diff --git a/git-interface/git-auth.py b/git-interface/git-auth.py new file mode 100755 index 00000000..c9e1f015 --- /dev/null +++ b/git-interface/git-auth.py @@ -0,0 +1,44 @@ +#!/usr/bin/python3 + +import configparser +import mysql.connector +import os +import re +import sys + +config = configparser.RawConfigParser() +config.read(os.path.dirname(os.path.realpath(__file__)) + "/../conf/config") + +aur_db_host = config.get('database', 'host') +aur_db_name = config.get('database', 'name') +aur_db_user = config.get('database', 'user') +aur_db_pass = config.get('database', 'password') +aur_db_socket = config.get('database', 'socket') + +valid_keytypes = config.get('auth', 'valid-keytypes').split() +username_regex = config.get('auth', 'username-regex') +git_serve_cmd = config.get('auth', 'git-serve-cmd') +ssh_opts = config.get('auth', 'ssh-options') + +keytype = sys.argv[1] +keytext = sys.argv[2] +if not keytype in valid_keytypes: + exit(1) + +db = mysql.connector.connect(host=aur_db_host, user=aur_db_user, + passwd=aur_db_pass, db=aur_db_name, + unix_socket=aur_db_socket, buffered=True) + +cur = db.cursor() +cur.execute("SELECT Username FROM Users WHERE SSHPubKey = %s " + + "AND Suspended = 0", (keytype + " " + keytext,)) + +if cur.rowcount != 1: + exit(1) + +user = cur.fetchone()[0] +if not re.match(username_regex, user): + exit(1) + +print('command="%s %s",%s %s' % (git_serve_cmd, user, ssh_opts, + keytype + " " + keytext)) |