pbs: move api-token detection into own local sub method
for better encapsulation. Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
This commit is contained in:
@ -701,13 +701,19 @@ my sub snapshot_files_encrypted {
|
|||||||
return $any && $all;
|
return $any && $all;
|
||||||
}
|
}
|
||||||
|
|
||||||
# NOTE: We cannot use the PVE token regexes as we're stricter in PVE, so some tokens that would be
|
my sub auth_id_is_api_token {
|
||||||
# valid for PBS would get rejected. Adapt over the PBS ones from proxmox-auth-api/src/types.rs:
|
my ($auth_id) = @_;
|
||||||
my $pbs_safe_id_regex = qr/(?:[A-Za-z0-9_][A-Za-z0-9\._\-]*)/;
|
|
||||||
my $pbs_token_name_regex = $pbs_safe_id_regex;
|
# NOTE: We cannot use the PVE token regexes as we're stricter in PVE, so some tokens that would
|
||||||
my $pbs_user_name_regex = qr/(?:[^\s:\/\p{PosixCntrl}]+)/;
|
# be valid for PBS would get rejected. Adapt over the PBS ones from proxmox-auth-api types
|
||||||
my $pbs_user_id_regex = qr/${pbs_user_name_regex}\@${pbs_safe_id_regex}/;
|
my $pbs_safe_id_regex = qr/(?:[A-Za-z0-9_][A-Za-z0-9\._\-]*)/;
|
||||||
my $pbs_apitoken_id_regex = qr/${pbs_user_id_regex}\!${pbs_token_name_regex}/;
|
my $pbs_token_name_regex = $pbs_safe_id_regex;
|
||||||
|
my $pbs_user_name_regex = qr/(?:[^\s:\/\p{PosixCntrl}]+)/;
|
||||||
|
my $pbs_user_id_regex = qr/${pbs_user_name_regex}\@${pbs_safe_id_regex}/;
|
||||||
|
my $pbs_apitoken_id_regex = qr/${pbs_user_id_regex}\!${pbs_token_name_regex}/;
|
||||||
|
|
||||||
|
return $auth_id =~ qr/^${pbs_apitoken_id_regex}$/;
|
||||||
|
}
|
||||||
|
|
||||||
# TODO: use a client with native rust/proxmox-backup bindings to profit from
|
# TODO: use a client with native rust/proxmox-backup bindings to profit from
|
||||||
# API schema checks and types
|
# API schema checks and types
|
||||||
@ -718,7 +724,7 @@ my sub pbs_api_connect {
|
|||||||
|
|
||||||
my $auth_id = $scfg->{username} // 'root@pam';
|
my $auth_id = $scfg->{username} // 'root@pam';
|
||||||
|
|
||||||
if ($auth_id =~ qr/^${pbs_apitoken_id_regex}$/) {
|
if (auth_id_is_api_token($auth_id)) {
|
||||||
$params->{apitoken} = "PBSAPIToken=${auth_id}:${password}";
|
$params->{apitoken} = "PBSAPIToken=${auth_id}:${password}";
|
||||||
} else {
|
} else {
|
||||||
$params->{password} = $password;
|
$params->{password} = $password;
|
||||||
|
|||||||
Reference in New Issue
Block a user