Allow username, password and TOTP to be entered ineractively.

This commit is contained in:
Andris Raugulis
2018-04-09 17:35:07 +03:00
parent 71fdf176dc
commit 49e76bd87f
+18 -6
View File
@@ -84,7 +84,7 @@ def parse_form(html):
def load_conf(cf): def load_conf(cf):
conf = {} conf = {}
keys = ['username', 'password', 'okta_url', 'vpn_url', 'totp_secret'] keys = ['vpn_url', 'username', 'password', 'okta_url']
with io.open(cf, 'r', encoding='utf-8') as fp: with io.open(cf, 'r', encoding='utf-8') as fp:
for rline in fp: for rline in fp:
line = rline.strip() line = rline.strip()
@@ -95,9 +95,16 @@ def load_conf(cf):
if re.match('^{0}.*{0}$'.format(q), v): if re.match('^{0}.*{0}$'.format(q), v):
v = v[1:-1] v = v[1:-1]
conf[k] = v conf[k] = v
if 'username' not in conf:
conf['username'] = raw_input('username: ').strip()
if 'password' not in conf:
conf['password'] = raw_input('password: ').strip()
for k in keys: for k in keys:
if k not in conf: if k not in conf:
err('missing configuration key: {0}'.format(k)) err('missing configuration key: {0}'.format(k))
else:
if len(conf[k].strip()) == 0:
err('empty configuration key: {0}'.format(k))
conf['debug'] = conf.get('debug', '').lower() in ['1', 'true'] conf['debug'] = conf.get('debug', '').lower() in ['1', 'true']
return conf return conf
@@ -174,9 +181,6 @@ def okta_auth(conf, s):
return session_token return session_token
def okta_mfa(conf, s, j): def okta_mfa(conf, s, j):
totp_secret = conf.get('totp_secret', '').strip()
if len(totp_secret) == 0:
err('totp_secret not defined')
state_token = j.get('stateToken', '').strip() state_token = j.get('stateToken', '').strip()
if len(state_token) == 0: if len(state_token) == 0:
err('empty state token') err('empty state token')
@@ -198,13 +202,21 @@ def okta_mfa(conf, s, j):
dbg(conf.get('debug'), 'factor', factor_id, factor_type, factor_url) dbg(conf.get('debug'), 'factor', factor_id, factor_type, factor_url)
if factor_type != 'token:software:totp': if factor_type != 'token:software:totp':
err('factor is not totp type') err('factor is not totp type')
totp_code = None
totp_secret = conf.get('totp_secret', '').strip()
if len(totp_secret) == 0:
totp_code = raw_input('TOTP: ').strip()
if len(totp_code) == 0:
err('empty totp')
if totp_code is None:
import pyotp import pyotp
totp = pyotp.TOTP(totp_secret) totp = pyotp.TOTP(totp_secret)
pass_code = totp.now() totp_code = totp.now()
data = { data = {
'factorId': factor_id, 'factorId': factor_id,
'stateToken': state_token, 'stateToken': state_token,
'passCode': pass_code, 'passCode': totp_code,
} }
log('mfa request') log('mfa request')
r = s.post(factor_url, headers=hdr_json(), data=json.dumps(data)) r = s.post(factor_url, headers=hdr_json(), data=json.dumps(data))