Compare commits
3 Commits
1.0-Beta
...
feature/wh
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
cac1ed8697 | ||
|
|
f9a3ddec43 | ||
|
|
2326c7e2cb |
14
pom.xml
14
pom.xml
@@ -6,7 +6,7 @@
|
|||||||
|
|
||||||
<groupId>com.ryanmichela</groupId>
|
<groupId>com.ryanmichela</groupId>
|
||||||
<artifactId>SSHD</artifactId>
|
<artifactId>SSHD</artifactId>
|
||||||
<version>1.0</version>
|
<version>1.2</version>
|
||||||
<url>http://dev.bukkit.org/server-mods/sshd/</url>
|
<url>http://dev.bukkit.org/server-mods/sshd/</url>
|
||||||
|
|
||||||
<!-- Repositories -->
|
<!-- Repositories -->
|
||||||
@@ -30,7 +30,7 @@
|
|||||||
<dependency>
|
<dependency>
|
||||||
<groupId>org.bukkit</groupId>
|
<groupId>org.bukkit</groupId>
|
||||||
<artifactId>craftbukkit</artifactId>
|
<artifactId>craftbukkit</artifactId>
|
||||||
<version>1.6.4-R1.0</version>
|
<version>1.7.9-R0.2</version>
|
||||||
<scope>provided</scope>
|
<scope>provided</scope>
|
||||||
<type>jar</type>
|
<type>jar</type>
|
||||||
</dependency>
|
</dependency>
|
||||||
@@ -41,11 +41,6 @@
|
|||||||
<scope>compile</scope>
|
<scope>compile</scope>
|
||||||
<type>jar</type>
|
<type>jar</type>
|
||||||
</dependency>
|
</dependency>
|
||||||
<!--<dependency>-->
|
|
||||||
<!--<groupId>org.bouncycastle</groupId>-->
|
|
||||||
<!--<artifactId>bcprov-jdk16</artifactId>-->
|
|
||||||
<!--<version>1.46</version>-->
|
|
||||||
<!--</dependency>-->
|
|
||||||
</dependencies>
|
</dependencies>
|
||||||
|
|
||||||
<!-- Build -->
|
<!-- Build -->
|
||||||
@@ -75,6 +70,7 @@
|
|||||||
</excludes>
|
</excludes>
|
||||||
</filter>
|
</filter>
|
||||||
</filters>
|
</filters>
|
||||||
|
<minimizeJar>true</minimizeJar>
|
||||||
</configuration>
|
</configuration>
|
||||||
</plugin>
|
</plugin>
|
||||||
<!-- Compile plugin -->
|
<!-- Compile plugin -->
|
||||||
@@ -83,8 +79,8 @@
|
|||||||
<artifactId>maven-compiler-plugin</artifactId>
|
<artifactId>maven-compiler-plugin</artifactId>
|
||||||
<version>3.0</version>
|
<version>3.0</version>
|
||||||
<configuration>
|
<configuration>
|
||||||
<source>1.7</source>
|
<source>1.6</source>
|
||||||
<target>1.7</target>
|
<target>1.6</target>
|
||||||
<showDeprecation>true</showDeprecation>
|
<showDeprecation>true</showDeprecation>
|
||||||
</configuration>
|
</configuration>
|
||||||
</plugin>
|
</plugin>
|
||||||
|
|||||||
142
src/main/java/com/ryanmichela/sshd/CidrUtils.java
Normal file
142
src/main/java/com/ryanmichela/sshd/CidrUtils.java
Normal file
@@ -0,0 +1,142 @@
|
|||||||
|
/*
|
||||||
|
* The MIT License
|
||||||
|
*
|
||||||
|
* Copyright (c) 2013 Edin Dazdarevic (edin.dazdarevic@gmail.com)
|
||||||
|
|
||||||
|
* Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
|
* of this software and associated documentation files (the "Software"), to deal
|
||||||
|
* in the Software without restriction, including without limitation the rights
|
||||||
|
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||||
|
* copies of the Software, and to permit persons to whom the Software is
|
||||||
|
* furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
* The above copyright notice and this permission notice shall be included in
|
||||||
|
* all copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
|
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
|
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||||
|
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||||
|
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||||
|
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
|
||||||
|
* THE SOFTWARE.
|
||||||
|
*
|
||||||
|
* */
|
||||||
|
|
||||||
|
package com.ryanmichela.sshd;
|
||||||
|
|
||||||
|
import java.math.BigInteger;
|
||||||
|
import java.net.InetAddress;
|
||||||
|
import java.net.UnknownHostException;
|
||||||
|
import java.nio.ByteBuffer;
|
||||||
|
import java.util.ArrayList;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A class that enables to get an IP range from CIDR specification. It supports
|
||||||
|
* both IPv4 and IPv6.
|
||||||
|
*/
|
||||||
|
public class CIDRUtils {
|
||||||
|
private final String cidr;
|
||||||
|
|
||||||
|
private InetAddress inetAddress;
|
||||||
|
private InetAddress startAddress;
|
||||||
|
private InetAddress endAddress;
|
||||||
|
private final int prefixLength;
|
||||||
|
|
||||||
|
|
||||||
|
public CIDRUtils(String cidr) throws UnknownHostException {
|
||||||
|
|
||||||
|
this.cidr = cidr;
|
||||||
|
|
||||||
|
/* split CIDR to address and prefix part */
|
||||||
|
if (this.cidr.contains("/")) {
|
||||||
|
int index = this.cidr.indexOf("/");
|
||||||
|
String addressPart = this.cidr.substring(0, index);
|
||||||
|
String networkPart = this.cidr.substring(index + 1);
|
||||||
|
|
||||||
|
inetAddress = InetAddress.getByName(addressPart);
|
||||||
|
prefixLength = Integer.parseInt(networkPart);
|
||||||
|
|
||||||
|
calculate();
|
||||||
|
} else {
|
||||||
|
throw new IllegalArgumentException("not an valid CIDR format!");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
private void calculate() throws UnknownHostException {
|
||||||
|
|
||||||
|
ByteBuffer maskBuffer;
|
||||||
|
int targetSize;
|
||||||
|
if (inetAddress.getAddress().length == 4) {
|
||||||
|
maskBuffer =
|
||||||
|
ByteBuffer
|
||||||
|
.allocate(4)
|
||||||
|
.putInt(-1);
|
||||||
|
targetSize = 4;
|
||||||
|
} else {
|
||||||
|
maskBuffer = ByteBuffer.allocate(16)
|
||||||
|
.putLong(-1L)
|
||||||
|
.putLong(-1L);
|
||||||
|
targetSize = 16;
|
||||||
|
}
|
||||||
|
|
||||||
|
BigInteger mask = (new BigInteger(1, maskBuffer.array())).not().shiftRight(prefixLength);
|
||||||
|
|
||||||
|
ByteBuffer buffer = ByteBuffer.wrap(inetAddress.getAddress());
|
||||||
|
BigInteger ipVal = new BigInteger(1, buffer.array());
|
||||||
|
|
||||||
|
BigInteger startIp = ipVal.and(mask);
|
||||||
|
BigInteger endIp = startIp.add(mask.not());
|
||||||
|
|
||||||
|
byte[] startIpArr = toBytes(startIp.toByteArray(), targetSize);
|
||||||
|
byte[] endIpArr = toBytes(endIp.toByteArray(), targetSize);
|
||||||
|
|
||||||
|
this.startAddress = InetAddress.getByAddress(startIpArr);
|
||||||
|
this.endAddress = InetAddress.getByAddress(endIpArr);
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
private byte[] toBytes(byte[] array, int targetSize) {
|
||||||
|
int counter = 0;
|
||||||
|
List<Byte> newArr = new ArrayList<Byte>();
|
||||||
|
while (counter < targetSize && (array.length - 1 - counter >= 0)) {
|
||||||
|
newArr.add(0, array[array.length - 1 - counter]);
|
||||||
|
counter++;
|
||||||
|
}
|
||||||
|
|
||||||
|
int size = newArr.size();
|
||||||
|
for (int i = 0; i < (targetSize - size); i++) {
|
||||||
|
|
||||||
|
newArr.add(0, (byte) 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
byte[] ret = new byte[newArr.size()];
|
||||||
|
for (int i = 0; i < newArr.size(); i++) {
|
||||||
|
ret[i] = newArr.get(i);
|
||||||
|
}
|
||||||
|
return ret;
|
||||||
|
}
|
||||||
|
|
||||||
|
public String getNetworkAddress() {
|
||||||
|
|
||||||
|
return this.startAddress.getHostAddress();
|
||||||
|
}
|
||||||
|
|
||||||
|
public String getBroadcastAddress() {
|
||||||
|
return this.endAddress.getHostAddress();
|
||||||
|
}
|
||||||
|
|
||||||
|
public boolean isInRange(String ipAddress) throws UnknownHostException {
|
||||||
|
InetAddress address = InetAddress.getByName(ipAddress);
|
||||||
|
BigInteger start = new BigInteger(1, this.startAddress.getAddress());
|
||||||
|
BigInteger end = new BigInteger(1, this.endAddress.getAddress());
|
||||||
|
BigInteger target = new BigInteger(1, address.getAddress());
|
||||||
|
|
||||||
|
int st = start.compareTo(target);
|
||||||
|
int te = target.compareTo(end);
|
||||||
|
|
||||||
|
return (st == -1 || st == 0) && (te == -1 || te == 0);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -9,11 +9,13 @@ import java.util.Map;
|
|||||||
/**
|
/**
|
||||||
* Copyright 2013 Ryan Michela
|
* Copyright 2013 Ryan Michela
|
||||||
*/
|
*/
|
||||||
public class ConfigPasswordAuthenticator implements PasswordAuthenticator {
|
public class ConfigPasswordAuthenticator extends IpFilteredAuthenticator implements PasswordAuthenticator {
|
||||||
private Map<String, Integer> failCounts = new HashMap<String, Integer>();
|
private Map<String, Integer> failCounts = new HashMap<String, Integer>();
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public boolean authenticate(String username, String password, ServerSession serverSession) {
|
public boolean authenticate(String username, String password, ServerSession serverSession) {
|
||||||
|
if (!ipAddressIsApproved(serverSession)) return false;
|
||||||
|
|
||||||
if (SshdPlugin.instance.getConfig().getString("credentials." + username).equals(password)) {
|
if (SshdPlugin.instance.getConfig().getString("credentials." + username).equals(password)) {
|
||||||
failCounts.put(username, 0);
|
failCounts.put(username, 0);
|
||||||
return true;
|
return true;
|
||||||
|
|||||||
@@ -53,7 +53,7 @@ public class ConsoleCommandFactory implements CommandFactory {
|
|||||||
SshdPlugin.instance.getLogger().info("[U: " + environment.getEnv().get(Environment.ENV_USER) + "] " + command);
|
SshdPlugin.instance.getLogger().info("[U: " + environment.getEnv().get(Environment.ENV_USER) + "] " + command);
|
||||||
Bukkit.dispatchCommand(Bukkit.getConsoleSender(), command);
|
Bukkit.dispatchCommand(Bukkit.getConsoleSender(), command);
|
||||||
} catch (Exception e) {
|
} catch (Exception e) {
|
||||||
SshdPlugin.instance.getLogger().severe("Error processing command from SSH");
|
SshdPlugin.instance.getLogger().severe("Error processing command from SSH -" + e.getMessage());
|
||||||
} finally {
|
} finally {
|
||||||
callback.onExit(0);
|
callback.onExit(0);
|
||||||
}
|
}
|
||||||
|
|||||||
42
src/main/java/com/ryanmichela/sshd/ConsoleLogFormatter.java
Normal file
42
src/main/java/com/ryanmichela/sshd/ConsoleLogFormatter.java
Normal file
@@ -0,0 +1,42 @@
|
|||||||
|
package com.ryanmichela.sshd;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Copyright 2013 Ryan Michela
|
||||||
|
*/
|
||||||
|
|
||||||
|
import java.io.PrintWriter;
|
||||||
|
import java.io.StringWriter;
|
||||||
|
import java.text.SimpleDateFormat;
|
||||||
|
import java.util.logging.Formatter;
|
||||||
|
import java.util.logging.LogRecord;
|
||||||
|
|
||||||
|
public class ConsoleLogFormatter extends Formatter {
|
||||||
|
|
||||||
|
private SimpleDateFormat dateFormat;
|
||||||
|
|
||||||
|
public ConsoleLogFormatter() {
|
||||||
|
this.dateFormat = new SimpleDateFormat("HH:mm:ss");
|
||||||
|
}
|
||||||
|
|
||||||
|
public String format(LogRecord logrecord) {
|
||||||
|
StringBuilder stringbuilder = new StringBuilder();
|
||||||
|
|
||||||
|
stringbuilder.append(" [");
|
||||||
|
stringbuilder.append(this.dateFormat.format(Long.valueOf(logrecord.getMillis()))).append(" ");
|
||||||
|
|
||||||
|
stringbuilder.append(logrecord.getLevel().getName()).append("]: ");
|
||||||
|
stringbuilder.append(this.formatMessage(logrecord));
|
||||||
|
stringbuilder.append('\n');
|
||||||
|
Throwable throwable = logrecord.getThrown();
|
||||||
|
|
||||||
|
if (throwable != null) {
|
||||||
|
StringWriter stringwriter = new StringWriter();
|
||||||
|
|
||||||
|
throwable.printStackTrace(new PrintWriter(stringwriter));
|
||||||
|
stringbuilder.append(stringwriter.toString());
|
||||||
|
}
|
||||||
|
|
||||||
|
return stringbuilder.toString();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
@@ -1,5 +1,7 @@
|
|||||||
package com.ryanmichela.sshd;
|
package com.ryanmichela.sshd;
|
||||||
|
|
||||||
|
import org.apache.logging.log4j.LogManager;
|
||||||
|
import org.apache.logging.log4j.core.Logger;
|
||||||
import org.apache.sshd.common.Factory;
|
import org.apache.sshd.common.Factory;
|
||||||
import org.apache.sshd.server.Command;
|
import org.apache.sshd.server.Command;
|
||||||
import org.apache.sshd.server.Environment;
|
import org.apache.sshd.server.Environment;
|
||||||
@@ -10,8 +12,6 @@ import org.bukkit.craftbukkit.libs.jline.console.ConsoleReader;
|
|||||||
import java.io.IOException;
|
import java.io.IOException;
|
||||||
import java.io.InputStream;
|
import java.io.InputStream;
|
||||||
import java.io.OutputStream;
|
import java.io.OutputStream;
|
||||||
import java.util.logging.Formatter;
|
|
||||||
import java.util.logging.Logger;
|
|
||||||
import java.util.logging.StreamHandler;
|
import java.util.logging.StreamHandler;
|
||||||
|
|
||||||
public class ConsoleShellFactory implements Factory<Command> {
|
public class ConsoleShellFactory implements Factory<Command> {
|
||||||
@@ -29,7 +29,7 @@ public class ConsoleShellFactory implements Factory<Command> {
|
|||||||
private Environment environment;
|
private Environment environment;
|
||||||
private Thread thread;
|
private Thread thread;
|
||||||
|
|
||||||
StreamHandler streamHandler;
|
StreamHandlerAppender streamHandlerAppender;
|
||||||
ConsoleReader consoleReader;
|
ConsoleReader consoleReader;
|
||||||
|
|
||||||
public InputStream getIn() {
|
public InputStream getIn() {
|
||||||
@@ -66,19 +66,18 @@ public class ConsoleShellFactory implements Factory<Command> {
|
|||||||
|
|
||||||
public void start(Environment env) throws IOException {
|
public void start(Environment env) throws IOException {
|
||||||
|
|
||||||
Formatter bukkitFormatter = Bukkit.getLogger().getHandlers()[0].getFormatter();
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
consoleReader = new ConsoleReader(in, new FlushyOutputStream(out), new SshTerminal());
|
consoleReader = new ConsoleReader(in, new FlushyOutputStream(out), new SshTerminal());
|
||||||
consoleReader.setExpandEvents(true);
|
consoleReader.setExpandEvents(true);
|
||||||
consoleReader.addCompleter(new ConsoleCommandCompleter());
|
consoleReader.addCompleter(new ConsoleCommandCompleter());
|
||||||
|
|
||||||
streamHandler = new FlushyStreamHandler(out, bukkitFormatter, consoleReader);
|
StreamHandler streamHandler = new FlushyStreamHandler(out, new ConsoleLogFormatter(), consoleReader);
|
||||||
Bukkit.getLogger().addHandler(streamHandler);
|
streamHandlerAppender = new StreamHandlerAppender(streamHandler);
|
||||||
Logger.getLogger("").addHandler(streamHandler);
|
|
||||||
|
((Logger) LogManager.getRootLogger()).addAppender(streamHandlerAppender);
|
||||||
|
|
||||||
environment = env;
|
environment = env;
|
||||||
thread = new Thread(this, "EchoShell " + env.getEnv().get(Environment.ENV_USER));
|
thread = new Thread(this, "SSHD ConsoleShell " + env.getEnv().get(Environment.ENV_USER));
|
||||||
thread.start();
|
thread.start();
|
||||||
} catch (Exception e) {
|
} catch (Exception e) {
|
||||||
throw new IOException("Error starting shell", e);
|
throw new IOException("Error starting shell", e);
|
||||||
@@ -86,8 +85,7 @@ public class ConsoleShellFactory implements Factory<Command> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
public void destroy() {
|
public void destroy() {
|
||||||
Bukkit.getLogger().removeHandler(streamHandler);
|
((Logger) LogManager.getRootLogger()).removeAppender(streamHandlerAppender);
|
||||||
Logger.getLogger("").removeHandler(streamHandler);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public void run() {
|
public void run() {
|
||||||
@@ -100,7 +98,7 @@ public class ConsoleShellFactory implements Factory<Command> {
|
|||||||
if (command.equals("exit")) {
|
if (command.equals("exit")) {
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
SshdPlugin.instance.getLogger().info("[U: " + environment.getEnv().get(Environment.ENV_USER) + "] " + command);
|
SshdPlugin.instance.getLogger().info("<" + environment.getEnv().get(Environment.ENV_USER) + "> " + command);
|
||||||
Bukkit.dispatchCommand(Bukkit.getConsoleSender(), command);
|
Bukkit.dispatchCommand(Bukkit.getConsoleSender(), command);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,28 @@
|
|||||||
|
package com.ryanmichela.sshd;
|
||||||
|
|
||||||
|
import org.apache.sshd.server.session.ServerSession;
|
||||||
|
|
||||||
|
import java.net.InetSocketAddress;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Copyright 2014 Ryan Michela
|
||||||
|
*/
|
||||||
|
public class IpFilteredAuthenticator {
|
||||||
|
private NetworkAddressValidator addressValidator;
|
||||||
|
|
||||||
|
public IpFilteredAuthenticator() {
|
||||||
|
List<String> whitelist = SshdPlugin.instance.getConfig().getStringList("whitelist");
|
||||||
|
if (whitelist.size() > 0) {
|
||||||
|
addressValidator = new NetworkAddressValidator(whitelist);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public boolean ipAddressIsApproved(ServerSession serverSession) {
|
||||||
|
if (addressValidator != null) {
|
||||||
|
String ip = ((InetSocketAddress)serverSession.getIoSession().getRemoteAddress()).getAddress().getHostAddress();
|
||||||
|
return addressValidator.isApproved(ip);
|
||||||
|
}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
package com.ryanmichela.sshd;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Copyright 2014 Ryan Michela
|
||||||
|
*/
|
||||||
|
|
||||||
|
import java.net.UnknownHostException;
|
||||||
|
import java.util.List;
|
||||||
|
|
||||||
|
public class NetworkAddressValidator {
|
||||||
|
|
||||||
|
private CIDRUtils[] approvedAddressList = null;
|
||||||
|
|
||||||
|
public NetworkAddressValidator(List<String> approvedAddressList) {
|
||||||
|
this.approvedAddressList = new CIDRUtils[approvedAddressList.size()];
|
||||||
|
for (int i = 0; i < approvedAddressList.size(); i++) {
|
||||||
|
String whitelistEntry = approvedAddressList.get(i);
|
||||||
|
try {
|
||||||
|
if (approvedAddressList.get(i).indexOf("/") > 0) {
|
||||||
|
this.approvedAddressList[i] = new CIDRUtils(whitelistEntry);
|
||||||
|
} else {
|
||||||
|
this.approvedAddressList[i] = new CIDRUtils(whitelistEntry + "/32");
|
||||||
|
}
|
||||||
|
} catch (UnknownHostException e) {
|
||||||
|
SshdPlugin.instance.getLogger().severe(whitelistEntry + " is not a valid IPv4 or IPv6 address or CIDR formatted address.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public boolean isApproved(String ipAddress) {
|
||||||
|
try {
|
||||||
|
for (CIDRUtils approvedAddress : approvedAddressList) {
|
||||||
|
if (approvedAddress.isInRange(ipAddress)) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
} catch (UnknownHostException e) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
package com.ryanmichela.sshd;
|
package com.ryanmichela.sshd;
|
||||||
|
|
||||||
import org.apache.commons.lang3.ArrayUtils;
|
import org.apache.commons.lang.ArrayUtils;
|
||||||
import org.apache.sshd.server.PublickeyAuthenticator;
|
import org.apache.sshd.server.PublickeyAuthenticator;
|
||||||
import org.apache.sshd.server.session.ServerSession;
|
import org.apache.sshd.server.session.ServerSession;
|
||||||
|
|
||||||
@@ -11,7 +11,7 @@ import java.security.PublicKey;
|
|||||||
/**
|
/**
|
||||||
* Copyright 2013 Ryan Michela
|
* Copyright 2013 Ryan Michela
|
||||||
*/
|
*/
|
||||||
public class PublicKeyAuthenticator implements PublickeyAuthenticator {
|
public class PublicKeyAuthenticator extends IpFilteredAuthenticator implements PublickeyAuthenticator {
|
||||||
private File authorizedKeysDir;
|
private File authorizedKeysDir;
|
||||||
|
|
||||||
public PublicKeyAuthenticator(File authorizedKeysDir) {
|
public PublicKeyAuthenticator(File authorizedKeysDir) {
|
||||||
@@ -20,6 +20,8 @@ public class PublicKeyAuthenticator implements PublickeyAuthenticator {
|
|||||||
|
|
||||||
@Override
|
@Override
|
||||||
public boolean authenticate(String username, PublicKey key, ServerSession session) {
|
public boolean authenticate(String username, PublicKey key, ServerSession session) {
|
||||||
|
if (!ipAddressIsApproved(session)) return false;
|
||||||
|
|
||||||
byte[] keyBytes = key.getEncoded();
|
byte[] keyBytes = key.getEncoded();
|
||||||
File keyFile = new File(authorizedKeysDir, username);
|
File keyFile = new File(authorizedKeysDir, username);
|
||||||
|
|
||||||
|
|||||||
@@ -55,7 +55,7 @@ public class SshdPlugin extends JavaPlugin {
|
|||||||
public void onDisable() {
|
public void onDisable() {
|
||||||
try {
|
try {
|
||||||
sshd.stop();
|
sshd.stop();
|
||||||
} catch (InterruptedException e) {
|
} catch (Exception e) {
|
||||||
// do nothing
|
// do nothing
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,83 @@
|
|||||||
|
package com.ryanmichela.sshd;
|
||||||
|
|
||||||
|
import org.apache.logging.log4j.core.Appender;
|
||||||
|
import org.apache.logging.log4j.core.ErrorHandler;
|
||||||
|
import org.apache.logging.log4j.core.Layout;
|
||||||
|
import org.apache.logging.log4j.core.LogEvent;
|
||||||
|
|
||||||
|
import java.io.Serializable;
|
||||||
|
import java.util.UUID;
|
||||||
|
import java.util.logging.LogRecord;
|
||||||
|
import java.util.logging.StreamHandler;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Copyright 2014 Ryan Michela
|
||||||
|
*/
|
||||||
|
public class StreamHandlerAppender implements Appender {
|
||||||
|
private StreamHandler streamHandler;
|
||||||
|
private UUID uuid;
|
||||||
|
|
||||||
|
public StreamHandlerAppender(StreamHandler streamHandler) {
|
||||||
|
this.streamHandler = streamHandler;
|
||||||
|
uuid = UUID.randomUUID();
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public void append(LogEvent logEvent) {
|
||||||
|
java.util.logging.Level level;
|
||||||
|
switch (logEvent.getLevel())
|
||||||
|
{
|
||||||
|
case DEBUG: level = java.util.logging.Level.FINE; break;
|
||||||
|
case INFO: level = java.util.logging.Level.INFO; break;
|
||||||
|
case WARN: level = java.util.logging.Level.WARNING; break;
|
||||||
|
case ERROR: level = java.util.logging.Level.SEVERE; break;
|
||||||
|
default: level = java.util.logging.Level.INFO; break;
|
||||||
|
}
|
||||||
|
|
||||||
|
String message = logEvent.getMessage().getFormattedMessage();
|
||||||
|
|
||||||
|
|
||||||
|
LogRecord logRecord = new LogRecord(level, message);
|
||||||
|
streamHandler.publish(logRecord);
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public String getName() {
|
||||||
|
return "StreamHandlerAppender:" + uuid.toString();
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public Layout<? extends Serializable> getLayout() {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public boolean ignoreExceptions() {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public ErrorHandler getHandler() {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public void setHandler(ErrorHandler errorHandler) {
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public void start() {
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public void stop() {
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
@Override
|
||||||
|
public boolean isStarted() {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -10,3 +10,10 @@ port: 22
|
|||||||
credentials:
|
credentials:
|
||||||
# user1: password1
|
# user1: password1
|
||||||
# user2: password2
|
# user2: password2
|
||||||
|
|
||||||
|
# To enable the IP whitelist, add more lines below. Whitelist entries can be expressed
|
||||||
|
# in CIDR notation (ip address/mask) for whitelisting a range of IP addresses.
|
||||||
|
whitelist:
|
||||||
|
# - ::1/128
|
||||||
|
# - 127.0.0.0/8
|
||||||
|
# - 192.168.0.0/16
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
name: SSHD
|
name: SSHD
|
||||||
version: "1.0"
|
version: "1.2"
|
||||||
author: Ryan Michela
|
author: Ryan Michela
|
||||||
main: com.ryanmichela.sshd.SshdPlugin
|
main: com.ryanmichela.sshd.SshdPlugin
|
||||||
Reference in New Issue
Block a user