fix: keep RDP creds out of tunnel URL/logs via single-use encrypted stash
This commit is contained in:
@@ -150,6 +150,56 @@ func GetConsoleSession(sessionID string) (*models.ConsoleSession, error) {
|
||||
return &s, nil
|
||||
}
|
||||
|
||||
// StashConsoleRDPCreds encrypts and stores single-use RDP credentials on the
|
||||
// session document. They are consumed (and cleared) when the tunnel opens.
|
||||
func StashConsoleRDPCreds(sessionID, username, password string) error {
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
defer cancel()
|
||||
u, err := encryptString(username)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
p, err := encryptString(password)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, err = db.Col("console_sessions").UpdateOne(ctx,
|
||||
bson.M{"session_id": sessionID},
|
||||
bson.M{"$set": bson.M{"rdp_user_enc": u, "rdp_pass_enc": p}},
|
||||
)
|
||||
return err
|
||||
}
|
||||
|
||||
// ConsumeConsoleRDPCreds decrypts and returns the stored RDP credentials, then
|
||||
// clears them from the session document (single-use). Returns empty strings if
|
||||
// none were stored.
|
||||
func ConsumeConsoleRDPCreds(sessionID string) (username, password string, err error) {
|
||||
s, err := GetConsoleSession(sessionID)
|
||||
if err != nil {
|
||||
return "", "", err
|
||||
}
|
||||
if s.RDPUserEnc == "" && s.RDPPassEnc == "" {
|
||||
return "", "", nil
|
||||
}
|
||||
if s.RDPUserEnc != "" {
|
||||
if username, err = decryptString(s.RDPUserEnc); err != nil {
|
||||
return "", "", err
|
||||
}
|
||||
}
|
||||
if s.RDPPassEnc != "" {
|
||||
if password, err = decryptString(s.RDPPassEnc); err != nil {
|
||||
return "", "", err
|
||||
}
|
||||
}
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
defer cancel()
|
||||
_, _ = db.Col("console_sessions").UpdateOne(ctx,
|
||||
bson.M{"session_id": sessionID},
|
||||
bson.M{"$unset": bson.M{"rdp_user_enc": "", "rdp_pass_enc": ""}},
|
||||
)
|
||||
return username, password, nil
|
||||
}
|
||||
|
||||
func EndConsoleSession(sessionID string) error {
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
defer cancel()
|
||||
|
||||
Reference in New Issue
Block a user