Diff

plugins/mod_auth_internal_plain.lua @ 10916:c7ed8f754033

Merge 0.11->trunk
author Kim Alvefur <zash@zash.se>
date Sat, 06 Jun 2020 00:54:28 +0200
parent 10914:0d7d71dee0a0
child 11544:c98aebe601f9
line wrap: on
line diff
--- a/plugins/mod_auth_internal_plain.lua	Sat Jun 06 00:49:48 2020 +0200
+++ b/plugins/mod_auth_internal_plain.lua	Sat Jun 06 00:54:28 2020 +0200
@@ -8,6 +8,7 @@
 
 local usermanager = require "core.usermanager";
 local new_sasl = require "util.sasl".new;
+local saslprep = require "util.encodings".stringprep.saslprep;
 
 local log = module._log;
 local host = module.host;
@@ -20,8 +21,12 @@
 function provider.test_password(username, password)
 	log("debug", "test password for user '%s'", username);
 	local credentials = accounts:get(username) or {};
+	password = saslprep(password);
+	if not password then
+		return nil, "Password fails SASLprep.";
+	end
 
-	if password == credentials.password then
+	if password == saslprep(credentials.password) then
 		return true;
 	else
 		return nil, "Auth failed. Invalid username or password.";
@@ -35,6 +40,10 @@
 
 function provider.set_password(username, password)
 	log("debug", "set_password for username '%s'", username);
+	password = saslprep(password);
+	if not password then
+		return nil, "Password fails SASLprep.";
+	end
 	local account = accounts:get(username);
 	if account then
 		account.password = password;
@@ -57,6 +66,10 @@
 end
 
 function provider.create_user(username, password)
+	password = saslprep(password);
+	if not password then
+		return nil, "Password fails SASLprep.";
+	end
 	return accounts:set(username, {password = password});
 end