Password policy (#82268)

* add password service interface

* add password service implementation

* add tests for password service

* add password service wiring

* add feature toggle

* Rework from service interface to static function

* Replace previous password validations

* Add codeowners to password service

* add error logs

* update config files


---------

Co-authored-by: Karl Persson <kalle.persson@grafana.com>
This commit is contained in:
linoman
2024-02-16 04:58:05 -06:00
committed by GitHub
co-authored by Karl Persson
parent 846eadff63
commit ac84069071
27 changed files with 300 additions and 105 deletions
@@ -18,7 +18,7 @@ import (
const DefaultAdminUserId = 1
func resetPasswordCommand(c utils.CommandLine, runner server.Runner) error {
newPassword := ""
var newPassword user.Password
adminId := int64(c.Int("user-id"))
if c.Bool("password-from-stdin") {
@@ -31,9 +31,13 @@ func resetPasswordCommand(c utils.CommandLine, runner server.Runner) error {
}
return fmt.Errorf("can't read password from stdin")
}
newPassword = scanner.Text()
newPassword = user.Password(scanner.Text())
} else {
newPassword = c.Args().First()
newPassword = user.Password(c.Args().First())
}
if err := newPassword.Validate(runner.Cfg); err != nil {
return fmt.Errorf("the new password doesn't meet the password policy criteria")
}
err := resetPassword(adminId, newPassword, runner.UserService)
@@ -44,12 +48,7 @@ func resetPasswordCommand(c utils.CommandLine, runner server.Runner) error {
return err
}
func resetPassword(adminId int64, newPassword string, userSvc user.Service) error {
password := user.Password(newPassword)
if password.IsWeak() {
return fmt.Errorf("new password is too short")
}
func resetPassword(adminId int64, newPassword user.Password, userSvc user.Service) error {
userQuery := user.GetUserByIDQuery{ID: adminId}
usr, err := userSvc.GetByID(context.Background(), &userQuery)
if err != nil {
@@ -59,14 +58,14 @@ func resetPassword(adminId int64, newPassword string, userSvc user.Service) erro
return ErrMustBeAdmin
}
passwordHashed, err := util.EncodePassword(newPassword, usr.Salt)
passwordHashed, err := util.EncodePassword(string(newPassword), usr.Salt)
if err != nil {
return err
}
cmd := user.ChangeUserPasswordCommand{
UserID: adminId,
NewPassword: passwordHashed,
NewPassword: user.Password(passwordHashed),
}
if err := userSvc.ChangePassword(context.Background(), &cmd); err != nil {