mirror of
https://github.com/inverse-inc/sogo.git
synced 2026-10-06 20:37:14 +00:00
(feat) added AngularJS's XSRF support (#3246)
This commit is contained in:
1 parent
2da7a04bac
commit
582baf2960
40 files changed
+224
-129
No files matched your search
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
Copyright (C) 2014 Inverse inc.
|
||||
Copyright (C) 2014-2016 Inverse inc.
|
||||
|
||||
This file is part of SOGo.
|
||||
|
||||
@@ -23,10 +23,11 @@
|
||||
#import <SOGo/SOGoCache.h>
|
||||
#import <SOGo/NSObject+Utilities.h>
|
||||
|
||||
#import <NGObjWeb/NSException+HTTP.h>
|
||||
#import <NGObjWeb/WOContext.h>
|
||||
#import <NGObjWeb/WODirectAction.h>
|
||||
#import <NGObjWeb/NSException+HTTP.h>
|
||||
#import <NGObjWeb/WOResponse.h>
|
||||
|
||||
#import <Common/WODirectAction+SOGo.h>
|
||||
#import <ActiveSync/SOGoActiveSyncDispatcher.h>
|
||||
|
||||
@interface SOGoMicrosoftActiveSyncActions : WODirectAction
|
||||
@@ -47,7 +48,9 @@
|
||||
Class clazz;
|
||||
|
||||
request = (WORequest *)[context request];
|
||||
response = [self responseWithStatus: 200];
|
||||
response = [context response];
|
||||
[response setStatus: 200];
|
||||
[response setHeader: @"text/plain; charset=utf-8" forKey: @"content-type"];
|
||||
|
||||
bundle = [NSBundle bundleForClass: NSClassFromString(@"ActiveSyncProduct")];
|
||||
clazz = [bundle classNamed: @"SOGoActiveSyncDispatcher"];
|
||||
|
||||
@@ -36,6 +36,7 @@
|
||||
|
||||
#import <Appointments/SOGoAppointmentFolders.h>
|
||||
|
||||
#import <SOGo/NSString+Crypto.h>
|
||||
#import <SOGo/NSString+Utilities.h>
|
||||
#import <SOGo/SOGoBuild.h>
|
||||
#import <SOGo/SOGoCache.h>
|
||||
@@ -170,14 +171,14 @@
|
||||
{
|
||||
WOResponse *response;
|
||||
WORequest *request;
|
||||
WOCookie *authCookie;
|
||||
WOCookie *authCookie, *xsrfCookie;
|
||||
SOGoWebAuthenticator *auth;
|
||||
SOGoAppointmentFolders *calendars;
|
||||
SOGoUserDefaults *ud;
|
||||
SOGoUser *loggedInUser;
|
||||
NSDictionary *params;
|
||||
NSString *username, *password, *language, *domain, *remoteHost;
|
||||
NSArray *supportedLanguages;
|
||||
NSArray *supportedLanguages, *creds;
|
||||
|
||||
SOGoPasswordPolicyError err;
|
||||
int expire, grace;
|
||||
@@ -232,6 +233,13 @@
|
||||
inContext: context];
|
||||
[response addCookie: authCookie];
|
||||
|
||||
// We prepare the XSRF protection cookie
|
||||
creds = [auth parseCredentials: [authCookie value]];
|
||||
xsrfCookie = [WOCookie cookieWithName: @"XSRF-TOKEN"
|
||||
value: [[SOGoSession valueForSessionKey: [creds lastObject]] asSHA1String]];
|
||||
[xsrfCookie setPath: [NSString stringWithFormat: @"/%@/", [[context request] applicationName]]];
|
||||
[response addCookie: xsrfCookie];
|
||||
|
||||
supportedLanguages = [[SOGoSystemDefaults sharedSystemDefaults]
|
||||
supportedLanguages];
|
||||
loggedInUser = [SOGoUser userWithLogin: username];
|
||||
@@ -540,8 +548,8 @@
|
||||
- (WOResponse *) changePasswordAction
|
||||
{
|
||||
NSString *username, *domain, *password, *newPassword, *value;
|
||||
WOCookie *authCookie, *xsrfCookie;
|
||||
NSDictionary *message;
|
||||
WOCookie *authCookie;
|
||||
NSArray *creds;
|
||||
SOGoUserManager *um;
|
||||
SOGoPasswordPolicyError error;
|
||||
@@ -592,6 +600,12 @@
|
||||
andPassword: newPassword
|
||||
inContext: context];
|
||||
[response addCookie: authCookie];
|
||||
|
||||
// We update the XSRF protection cookie
|
||||
creds = [auth parseCredentials: [authCookie value]];
|
||||
xsrfCookie = [WOCookie cookieWithName: @"XSRF-TOKEN"
|
||||
value: [[SOGoSession valueForSessionKey: [creds lastObject]] asSHA1String]];
|
||||
[response addCookie: xsrfCookie];
|
||||
}
|
||||
else
|
||||
response = [self _responseWithLDAPPolicyError: error];
|
||||
|
||||
@@ -455,8 +455,8 @@
|
||||
|
||||
- (id <WOActionResults>) logoffAction
|
||||
{
|
||||
SOGoWebAuthenticator *auth;
|
||||
NSString *userName, *value;
|
||||
SOGoWebAuthenticator *auth;
|
||||
WOResponse *response;
|
||||
NSCalendarDate *date;
|
||||
WOCookie *cookie;
|
||||
@@ -486,6 +486,12 @@
|
||||
if (cookie)
|
||||
[response addCookie: cookie];
|
||||
|
||||
// We remove the XSRF cookie
|
||||
cookie = [WOCookie cookieWithName: @"XSRF-TOKEN" value: @"discard"];
|
||||
[cookie setPath: [NSString stringWithFormat: @"/%@/", [[context request] applicationName]]];
|
||||
[cookie setExpires: [date yesterday]];
|
||||
[response addCookie: cookie];
|
||||
|
||||
[response setHeader: [date rfc822DateString] forKey: @"Last-Modified"];
|
||||
[response setHeader: @"no-store, no-cache, must-revalidate,"
|
||||
@" max-age=0, post-check=0, pre-check=0"
|
||||
|
||||
Reference in new issue
Block a user