Files
greptimedb/src/auth/common.rs.html
2026-05-19 06:04:59 +00:00

182 lines
21 KiB
HTML

<!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="generator" content="rustdoc"><meta name="description" content="Source of the Rust file `src/auth/src/common.rs`."><title>common.rs - source</title><script>if(window.location.protocol!=="file:")document.head.insertAdjacentHTML("beforeend","SourceSerif4-Regular-6b053e98.ttf.woff2,FiraSans-Italic-81dc35de.woff2,FiraSans-Regular-0fe48ade.woff2,FiraSans-MediumItalic-ccf7e434.woff2,FiraSans-Medium-e1aa3f0a.woff2,SourceCodePro-Regular-8badfe75.ttf.woff2,SourceCodePro-Semibold-aa29a496.ttf.woff2".split(",").map(f=>`<link rel="preload" as="font" type="font/woff2"href="../../static.files/${f}">`).join(""))</script><link rel="stylesheet" href="../../static.files/normalize-9960930a.css"><link rel="stylesheet" href="../../static.files/rustdoc-17e0aaed.css"><meta name="rustdoc-vars" data-root-path="../../" data-static-root-path="../../static.files/" data-current-crate="auth" data-themes="" data-resource-suffix="" data-rustdoc-version="1.96.0-nightly (ac7f9ec7d 2026-03-20)" data-channel="nightly" data-search-js="search-63369b7b.js" data-stringdex-js="stringdex-2da4960a.js" data-settings-js="settings-170eb4bf.js" ><script src="../../static.files/storage-41dd4d93.js"></script><script defer src="../../static.files/src-script-813739b1.js"></script><script defer src="../../src-files.js"></script><script defer src="../../static.files/main-5013f961.js"></script><noscript><link rel="stylesheet" href="../../static.files/noscript-f7c3ffd8.css"></noscript><link rel="alternate icon" type="image/png" href="../../static.files/favicon-32x32-eab170b8.png"><link rel="icon" type="image/svg+xml" href="../../static.files/favicon-044be391.svg"></head><body class="rustdoc src"><a class="skip-main-content" href="#main-content">Skip to main content</a><!--[if lte IE 11]><div class="warning">This old browser is unsupported and will most likely display funky things.</div><![endif]--><nav class="sidebar"><div class="src-sidebar-title"><h2>Files</h2></div></nav><div class="sidebar-resizer" title="Drag to resize sidebar"></div><main><section id="main-content" class="content" tabindex="-1"><div class="main-heading"><h1><div class="sub-heading">auth/</div>common.rs</h1><rustdoc-toolbar></rustdoc-toolbar></div><div class="example-wrap digits-3"><pre class="rust"><code><a href=#1 id=1 data-nosnippet>1</a><span class="comment">// Copyright 2023 Greptime Team
<a href=#2 id=2 data-nosnippet>2</a>//
<a href=#3 id=3 data-nosnippet>3</a>// Licensed under the Apache License, Version 2.0 (the "License");
<a href=#4 id=4 data-nosnippet>4</a>// you may not use this file except in compliance with the License.
<a href=#5 id=5 data-nosnippet>5</a>// You may obtain a copy of the License at
<a href=#6 id=6 data-nosnippet>6</a>//
<a href=#7 id=7 data-nosnippet>7</a>// http://www.apache.org/licenses/LICENSE-2.0
<a href=#8 id=8 data-nosnippet>8</a>//
<a href=#9 id=9 data-nosnippet>9</a>// Unless required by applicable law or agreed to in writing, software
<a href=#10 id=10 data-nosnippet>10</a>// distributed under the License is distributed on an "AS IS" BASIS,
<a href=#11 id=11 data-nosnippet>11</a>// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
<a href=#12 id=12 data-nosnippet>12</a>// See the License for the specific language governing permissions and
<a href=#13 id=13 data-nosnippet>13</a>// limitations under the License.
<a href=#14 id=14 data-nosnippet>14</a>
<a href=#15 id=15 data-nosnippet>15</a></span><span class="kw">use </span>std::sync::Arc;
<a href=#16 id=16 data-nosnippet>16</a>
<a href=#17 id=17 data-nosnippet>17</a><span class="kw">use </span>common_base::secrets::SecretString;
<a href=#18 id=18 data-nosnippet>18</a><span class="kw">use </span>digest::Digest;
<a href=#19 id=19 data-nosnippet>19</a><span class="kw">use </span>sha1::Sha1;
<a href=#20 id=20 data-nosnippet>20</a><span class="kw">use </span>snafu::{OptionExt, ensure};
<a href=#21 id=21 data-nosnippet>21</a>
<a href=#22 id=22 data-nosnippet>22</a><span class="kw">use </span><span class="kw">crate</span>::error::{IllegalParamSnafu, InvalidConfigSnafu, <span class="prelude-ty">Result</span>, UserPasswordMismatchSnafu};
<a href=#23 id=23 data-nosnippet>23</a><span class="kw">use </span><span class="kw">crate</span>::user_info::DefaultUserInfo;
<a href=#24 id=24 data-nosnippet>24</a><span class="kw">use </span><span class="kw">crate</span>::user_provider::static_user_provider::{STATIC_USER_PROVIDER, StaticUserProvider};
<a href=#25 id=25 data-nosnippet>25</a><span class="kw">use </span><span class="kw">crate</span>::user_provider::watch_file_user_provider::{
<a href=#26 id=26 data-nosnippet>26</a> WATCH_FILE_USER_PROVIDER, WatchFileUserProvider,
<a href=#27 id=27 data-nosnippet>27</a>};
<a href=#28 id=28 data-nosnippet>28</a><span class="kw">use </span>crate::{UserInfoRef, UserProviderRef};
<a href=#29 id=29 data-nosnippet>29</a>
<a href=#30 id=30 data-nosnippet>30</a><span class="kw">pub</span>(<span class="kw">crate</span>) <span class="kw">const </span>DEFAULT_USERNAME: <span class="kw-2">&amp;</span>str = <span class="string">"greptime"</span>;
<a href=#31 id=31 data-nosnippet>31</a>
<a href=#32 id=32 data-nosnippet>32</a><span class="doccomment">/// construct a [`UserInfo`](crate::user_info::UserInfo) impl with name
<a href=#33 id=33 data-nosnippet>33</a>/// use default username `greptime` if None is provided
<a href=#34 id=34 data-nosnippet>34</a></span><span class="kw">pub fn </span>userinfo_by_name(username: <span class="prelude-ty">Option</span>&lt;String&gt;) -&gt; UserInfoRef {
<a href=#35 id=35 data-nosnippet>35</a> DefaultUserInfo::with_name(username.unwrap_or_else(|| DEFAULT_USERNAME.to_string()))
<a href=#36 id=36 data-nosnippet>36</a>}
<a href=#37 id=37 data-nosnippet>37</a>
<a href=#38 id=38 data-nosnippet>38</a><span class="kw">pub fn </span>user_provider_from_option(opt: <span class="kw-2">&amp;</span>str) -&gt; <span class="prelude-ty">Result</span>&lt;UserProviderRef&gt; {
<a href=#39 id=39 data-nosnippet>39</a> <span class="kw">let </span>(name, content) = opt.split_once(<span class="string">':'</span>).with_context(|| InvalidConfigSnafu {
<a href=#40 id=40 data-nosnippet>40</a> value: opt.to_string(),
<a href=#41 id=41 data-nosnippet>41</a> msg: <span class="string">"UserProviderOption must be in format `&lt;option&gt;:&lt;value&gt;`"</span>,
<a href=#42 id=42 data-nosnippet>42</a> })<span class="question-mark">?</span>;
<a href=#43 id=43 data-nosnippet>43</a> <span class="kw">match </span>name {
<a href=#44 id=44 data-nosnippet>44</a> STATIC_USER_PROVIDER =&gt; {
<a href=#45 id=45 data-nosnippet>45</a> <span class="kw">let </span>provider =
<a href=#46 id=46 data-nosnippet>46</a> StaticUserProvider::new(content).map(|p| Arc::new(p) <span class="kw">as </span>UserProviderRef)<span class="question-mark">?</span>;
<a href=#47 id=47 data-nosnippet>47</a> <span class="prelude-val">Ok</span>(provider)
<a href=#48 id=48 data-nosnippet>48</a> }
<a href=#49 id=49 data-nosnippet>49</a> WATCH_FILE_USER_PROVIDER =&gt; {
<a href=#50 id=50 data-nosnippet>50</a> WatchFileUserProvider::new(content).map(|p| Arc::new(p) <span class="kw">as </span>UserProviderRef)
<a href=#51 id=51 data-nosnippet>51</a> }
<a href=#52 id=52 data-nosnippet>52</a> <span class="kw">_ </span>=&gt; InvalidConfigSnafu {
<a href=#53 id=53 data-nosnippet>53</a> value: name.to_string(),
<a href=#54 id=54 data-nosnippet>54</a> msg: <span class="string">"Invalid UserProviderOption"</span>,
<a href=#55 id=55 data-nosnippet>55</a> }
<a href=#56 id=56 data-nosnippet>56</a> .fail(),
<a href=#57 id=57 data-nosnippet>57</a> }
<a href=#58 id=58 data-nosnippet>58</a>}
<a href=#59 id=59 data-nosnippet>59</a>
<a href=#60 id=60 data-nosnippet>60</a><span class="kw">pub fn </span>static_user_provider_from_option(opt: <span class="kw-2">&amp;</span>str) -&gt; <span class="prelude-ty">Result</span>&lt;StaticUserProvider&gt; {
<a href=#61 id=61 data-nosnippet>61</a> <span class="kw">let </span>(name, content) = opt.split_once(<span class="string">':'</span>).with_context(|| InvalidConfigSnafu {
<a href=#62 id=62 data-nosnippet>62</a> value: opt.to_string(),
<a href=#63 id=63 data-nosnippet>63</a> msg: <span class="string">"UserProviderOption must be in format `&lt;option&gt;:&lt;value&gt;`"</span>,
<a href=#64 id=64 data-nosnippet>64</a> })<span class="question-mark">?</span>;
<a href=#65 id=65 data-nosnippet>65</a> <span class="kw">match </span>name {
<a href=#66 id=66 data-nosnippet>66</a> STATIC_USER_PROVIDER =&gt; {
<a href=#67 id=67 data-nosnippet>67</a> <span class="kw">let </span>provider = StaticUserProvider::new(content)<span class="question-mark">?</span>;
<a href=#68 id=68 data-nosnippet>68</a> <span class="prelude-val">Ok</span>(provider)
<a href=#69 id=69 data-nosnippet>69</a> }
<a href=#70 id=70 data-nosnippet>70</a> <span class="kw">_ </span>=&gt; InvalidConfigSnafu {
<a href=#71 id=71 data-nosnippet>71</a> value: name.to_string(),
<a href=#72 id=72 data-nosnippet>72</a> msg: <span class="macro">format!</span>(<span class="string">"Invalid UserProviderOption, expect only {STATIC_USER_PROVIDER}"</span>),
<a href=#73 id=73 data-nosnippet>73</a> }
<a href=#74 id=74 data-nosnippet>74</a> .fail(),
<a href=#75 id=75 data-nosnippet>75</a> }
<a href=#76 id=76 data-nosnippet>76</a>}
<a href=#77 id=77 data-nosnippet>77</a>
<a href=#78 id=78 data-nosnippet>78</a><span class="kw">type </span>Username&lt;<span class="lifetime">'a</span>&gt; = <span class="kw-2">&amp;</span><span class="lifetime">'a </span>str;
<a href=#79 id=79 data-nosnippet>79</a><span class="kw">type </span>HostOrIp&lt;<span class="lifetime">'a</span>&gt; = <span class="kw-2">&amp;</span><span class="lifetime">'a </span>str;
<a href=#80 id=80 data-nosnippet>80</a>
<a href=#81 id=81 data-nosnippet>81</a><span class="attr">#[derive(Debug, Clone)]
<a href=#82 id=82 data-nosnippet>82</a></span><span class="kw">pub enum </span>Identity&lt;<span class="lifetime">'a</span>&gt; {
<a href=#83 id=83 data-nosnippet>83</a> UserId(Username&lt;<span class="lifetime">'a</span>&gt;, <span class="prelude-ty">Option</span>&lt;HostOrIp&lt;<span class="lifetime">'a</span>&gt;&gt;),
<a href=#84 id=84 data-nosnippet>84</a>}
<a href=#85 id=85 data-nosnippet>85</a>
<a href=#86 id=86 data-nosnippet>86</a><span class="kw">pub type </span>HashedPassword&lt;<span class="lifetime">'a</span>&gt; = <span class="kw-2">&amp;</span><span class="lifetime">'a </span>[u8];
<a href=#87 id=87 data-nosnippet>87</a><span class="kw">pub type </span>Salt&lt;<span class="lifetime">'a</span>&gt; = <span class="kw-2">&amp;</span><span class="lifetime">'a </span>[u8];
<a href=#88 id=88 data-nosnippet>88</a>
<a href=#89 id=89 data-nosnippet>89</a><span class="doccomment">/// Authentication information sent by the client.
<a href=#90 id=90 data-nosnippet>90</a></span><span class="kw">pub enum </span>Password&lt;<span class="lifetime">'a</span>&gt; {
<a href=#91 id=91 data-nosnippet>91</a> PlainText(SecretString),
<a href=#92 id=92 data-nosnippet>92</a> MysqlNativePassword(HashedPassword&lt;<span class="lifetime">'a</span>&gt;, Salt&lt;<span class="lifetime">'a</span>&gt;),
<a href=#93 id=93 data-nosnippet>93</a> PgMD5(HashedPassword&lt;<span class="lifetime">'a</span>&gt;, Salt&lt;<span class="lifetime">'a</span>&gt;),
<a href=#94 id=94 data-nosnippet>94</a>}
<a href=#95 id=95 data-nosnippet>95</a>
<a href=#96 id=96 data-nosnippet>96</a><span class="kw">impl </span>Password&lt;<span class="lifetime">'_</span>&gt; {
<a href=#97 id=97 data-nosnippet>97</a> <span class="kw">pub fn </span>r#type(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; <span class="kw-2">&amp;</span>str {
<a href=#98 id=98 data-nosnippet>98</a> <span class="kw">match </span><span class="self">self </span>{
<a href=#99 id=99 data-nosnippet>99</a> Password::PlainText(<span class="kw">_</span>) =&gt; <span class="string">"plain_text"</span>,
<a href=#100 id=100 data-nosnippet>100</a> Password::MysqlNativePassword(<span class="kw">_</span>, <span class="kw">_</span>) =&gt; <span class="string">"mysql_native_password"</span>,
<a href=#101 id=101 data-nosnippet>101</a> Password::PgMD5(<span class="kw">_</span>, <span class="kw">_</span>) =&gt; <span class="string">"pg_md5"</span>,
<a href=#102 id=102 data-nosnippet>102</a> }
<a href=#103 id=103 data-nosnippet>103</a> }
<a href=#104 id=104 data-nosnippet>104</a>}
<a href=#105 id=105 data-nosnippet>105</a>
<a href=#106 id=106 data-nosnippet>106</a><span class="kw">pub fn </span>auth_mysql(
<a href=#107 id=107 data-nosnippet>107</a> auth_data: HashedPassword,
<a href=#108 id=108 data-nosnippet>108</a> salt: Salt,
<a href=#109 id=109 data-nosnippet>109</a> username: <span class="kw-2">&amp;</span>str,
<a href=#110 id=110 data-nosnippet>110</a> save_pwd: <span class="kw-2">&amp;</span>[u8],
<a href=#111 id=111 data-nosnippet>111</a>) -&gt; <span class="prelude-ty">Result</span>&lt;()&gt; {
<a href=#112 id=112 data-nosnippet>112</a> <span class="macro">ensure!</span>(
<a href=#113 id=113 data-nosnippet>113</a> auth_data.len() == <span class="number">20</span>,
<a href=#114 id=114 data-nosnippet>114</a> IllegalParamSnafu {
<a href=#115 id=115 data-nosnippet>115</a> msg: <span class="string">"Illegal mysql password length"
<a href=#116 id=116 data-nosnippet>116</a> </span>}
<a href=#117 id=117 data-nosnippet>117</a> );
<a href=#118 id=118 data-nosnippet>118</a> <span class="comment">// ref: https://github.com/mysql/mysql-server/blob/a246bad76b9271cb4333634e954040a970222e0a/sql/auth/password.cc#L62
<a href=#119 id=119 data-nosnippet>119</a> </span><span class="kw">let </span>hash_stage_2 = double_sha1(save_pwd);
<a href=#120 id=120 data-nosnippet>120</a> <span class="kw">let </span>tmp = sha1_two(salt, <span class="kw-2">&amp;</span>hash_stage_2);
<a href=#121 id=121 data-nosnippet>121</a> <span class="comment">// xor auth_data and tmp
<a href=#122 id=122 data-nosnippet>122</a> </span><span class="kw">let </span><span class="kw-2">mut </span>xor_result = [<span class="number">0u8</span>; <span class="number">20</span>];
<a href=#123 id=123 data-nosnippet>123</a> <span class="kw">for </span>i <span class="kw">in </span><span class="number">0</span>..<span class="number">20 </span>{
<a href=#124 id=124 data-nosnippet>124</a> xor_result[i] = auth_data[i] ^ tmp[i];
<a href=#125 id=125 data-nosnippet>125</a> }
<a href=#126 id=126 data-nosnippet>126</a> <span class="kw">let </span>candidate_stage_2 = sha1_one(<span class="kw-2">&amp;</span>xor_result);
<a href=#127 id=127 data-nosnippet>127</a> <span class="kw">if </span>candidate_stage_2 == hash_stage_2 {
<a href=#128 id=128 data-nosnippet>128</a> <span class="prelude-val">Ok</span>(())
<a href=#129 id=129 data-nosnippet>129</a> } <span class="kw">else </span>{
<a href=#130 id=130 data-nosnippet>130</a> UserPasswordMismatchSnafu {
<a href=#131 id=131 data-nosnippet>131</a> username: username.to_string(),
<a href=#132 id=132 data-nosnippet>132</a> }
<a href=#133 id=133 data-nosnippet>133</a> .fail()
<a href=#134 id=134 data-nosnippet>134</a> }
<a href=#135 id=135 data-nosnippet>135</a>}
<a href=#136 id=136 data-nosnippet>136</a>
<a href=#137 id=137 data-nosnippet>137</a><span class="kw">fn </span>sha1_two(input_1: <span class="kw-2">&amp;</span>[u8], input_2: <span class="kw-2">&amp;</span>[u8]) -&gt; Vec&lt;u8&gt; {
<a href=#138 id=138 data-nosnippet>138</a> <span class="kw">let </span><span class="kw-2">mut </span>hasher = Sha1::new();
<a href=#139 id=139 data-nosnippet>139</a> hasher.update(input_1);
<a href=#140 id=140 data-nosnippet>140</a> hasher.update(input_2);
<a href=#141 id=141 data-nosnippet>141</a> hasher.finalize().to_vec()
<a href=#142 id=142 data-nosnippet>142</a>}
<a href=#143 id=143 data-nosnippet>143</a>
<a href=#144 id=144 data-nosnippet>144</a><span class="kw">fn </span>sha1_one(data: <span class="kw-2">&amp;</span>[u8]) -&gt; Vec&lt;u8&gt; {
<a href=#145 id=145 data-nosnippet>145</a> <span class="kw">let </span><span class="kw-2">mut </span>hasher = Sha1::new();
<a href=#146 id=146 data-nosnippet>146</a> hasher.update(data);
<a href=#147 id=147 data-nosnippet>147</a> hasher.finalize().to_vec()
<a href=#148 id=148 data-nosnippet>148</a>}
<a href=#149 id=149 data-nosnippet>149</a>
<a href=#150 id=150 data-nosnippet>150</a><span class="kw">fn </span>double_sha1(data: <span class="kw-2">&amp;</span>[u8]) -&gt; Vec&lt;u8&gt; {
<a href=#151 id=151 data-nosnippet>151</a> sha1_one(<span class="kw-2">&amp;</span>sha1_one(data))
<a href=#152 id=152 data-nosnippet>152</a>}
<a href=#153 id=153 data-nosnippet>153</a>
<a href=#154 id=154 data-nosnippet>154</a><span class="attr">#[cfg(test)]
<a href=#155 id=155 data-nosnippet>155</a></span><span class="kw">mod </span>tests {
<a href=#156 id=156 data-nosnippet>156</a> <span class="kw">use </span>super::<span class="kw-2">*</span>;
<a href=#157 id=157 data-nosnippet>157</a>
<a href=#158 id=158 data-nosnippet>158</a> <span class="attr">#[test]
<a href=#159 id=159 data-nosnippet>159</a> </span><span class="kw">fn </span>test_sha() {
<a href=#160 id=160 data-nosnippet>160</a> <span class="kw">let </span>sha_1_answer: Vec&lt;u8&gt; = <span class="macro">vec!</span>[
<a href=#161 id=161 data-nosnippet>161</a> <span class="number">124</span>, <span class="number">74</span>, <span class="number">141</span>, <span class="number">9</span>, <span class="number">202</span>, <span class="number">55</span>, <span class="number">98</span>, <span class="number">175</span>, <span class="number">97</span>, <span class="number">229</span>, <span class="number">149</span>, <span class="number">32</span>, <span class="number">148</span>, <span class="number">61</span>, <span class="number">194</span>, <span class="number">100</span>, <span class="number">148</span>, <span class="number">248</span>, <span class="number">148</span>,
<a href=#162 id=162 data-nosnippet>162</a> <span class="number">27</span>,
<a href=#163 id=163 data-nosnippet>163</a> ];
<a href=#164 id=164 data-nosnippet>164</a> <span class="kw">let </span>sha_1 = sha1_one(<span class="string">"123456"</span>.as_bytes());
<a href=#165 id=165 data-nosnippet>165</a> <span class="macro">assert_eq!</span>(sha_1, sha_1_answer);
<a href=#166 id=166 data-nosnippet>166</a>
<a href=#167 id=167 data-nosnippet>167</a> <span class="kw">let </span>double_sha1_answer: Vec&lt;u8&gt; = <span class="macro">vec!</span>[
<a href=#168 id=168 data-nosnippet>168</a> <span class="number">107</span>, <span class="number">180</span>, <span class="number">131</span>, <span class="number">126</span>, <span class="number">183</span>, <span class="number">67</span>, <span class="number">41</span>, <span class="number">16</span>, <span class="number">94</span>, <span class="number">228</span>, <span class="number">86</span>, <span class="number">141</span>, <span class="number">218</span>, <span class="number">125</span>, <span class="number">198</span>, <span class="number">126</span>, <span class="number">210</span>, <span class="number">202</span>,
<a href=#169 id=169 data-nosnippet>169</a> <span class="number">42</span>, <span class="number">217</span>,
<a href=#170 id=170 data-nosnippet>170</a> ];
<a href=#171 id=171 data-nosnippet>171</a> <span class="kw">let </span>double_sha1 = double_sha1(<span class="string">"123456"</span>.as_bytes());
<a href=#172 id=172 data-nosnippet>172</a> <span class="macro">assert_eq!</span>(double_sha1, double_sha1_answer);
<a href=#173 id=173 data-nosnippet>173</a>
<a href=#174 id=174 data-nosnippet>174</a> <span class="kw">let </span>sha1_2_answer: Vec&lt;u8&gt; = <span class="macro">vec!</span>[
<a href=#175 id=175 data-nosnippet>175</a> <span class="number">132</span>, <span class="number">115</span>, <span class="number">215</span>, <span class="number">211</span>, <span class="number">99</span>, <span class="number">186</span>, <span class="number">164</span>, <span class="number">206</span>, <span class="number">168</span>, <span class="number">152</span>, <span class="number">217</span>, <span class="number">192</span>, <span class="number">117</span>, <span class="number">47</span>, <span class="number">240</span>, <span class="number">252</span>, <span class="number">142</span>, <span class="number">244</span>,
<a href=#176 id=176 data-nosnippet>176</a> <span class="number">37</span>, <span class="number">204</span>,
<a href=#177 id=177 data-nosnippet>177</a> ];
<a href=#178 id=178 data-nosnippet>178</a> <span class="kw">let </span>sha1_2 = sha1_two(<span class="string">"123456"</span>.as_bytes(), <span class="string">"654321"</span>.as_bytes());
<a href=#179 id=179 data-nosnippet>179</a> <span class="macro">assert_eq!</span>(sha1_2, sha1_2_answer);
<a href=#180 id=180 data-nosnippet>180</a> }
<a href=#181 id=181 data-nosnippet>181</a>}
</code></pre></div></section></main></body></html>