mirror of
https://github.com/os-mnemo/pan-globalprotect-okta
synced 2026-07-31 15:54:36 +02:00
Allow username, password and TOTP to be entered ineractively.
This commit is contained in:
+18
-6
@@ -84,7 +84,7 @@ def parse_form(html):
|
|||||||
|
|
||||||
def load_conf(cf):
|
def load_conf(cf):
|
||||||
conf = {}
|
conf = {}
|
||||||
keys = ['username', 'password', 'okta_url', 'vpn_url', 'totp_secret']
|
keys = ['vpn_url', 'username', 'password', 'okta_url']
|
||||||
with io.open(cf, 'r', encoding='utf-8') as fp:
|
with io.open(cf, 'r', encoding='utf-8') as fp:
|
||||||
for rline in fp:
|
for rline in fp:
|
||||||
line = rline.strip()
|
line = rline.strip()
|
||||||
@@ -95,9 +95,16 @@ def load_conf(cf):
|
|||||||
if re.match('^{0}.*{0}$'.format(q), v):
|
if re.match('^{0}.*{0}$'.format(q), v):
|
||||||
v = v[1:-1]
|
v = v[1:-1]
|
||||||
conf[k] = v
|
conf[k] = v
|
||||||
|
if 'username' not in conf:
|
||||||
|
conf['username'] = raw_input('username: ').strip()
|
||||||
|
if 'password' not in conf:
|
||||||
|
conf['password'] = raw_input('password: ').strip()
|
||||||
for k in keys:
|
for k in keys:
|
||||||
if k not in conf:
|
if k not in conf:
|
||||||
err('missing configuration key: {0}'.format(k))
|
err('missing configuration key: {0}'.format(k))
|
||||||
|
else:
|
||||||
|
if len(conf[k].strip()) == 0:
|
||||||
|
err('empty configuration key: {0}'.format(k))
|
||||||
conf['debug'] = conf.get('debug', '').lower() in ['1', 'true']
|
conf['debug'] = conf.get('debug', '').lower() in ['1', 'true']
|
||||||
return conf
|
return conf
|
||||||
|
|
||||||
@@ -174,9 +181,6 @@ def okta_auth(conf, s):
|
|||||||
return session_token
|
return session_token
|
||||||
|
|
||||||
def okta_mfa(conf, s, j):
|
def okta_mfa(conf, s, j):
|
||||||
totp_secret = conf.get('totp_secret', '').strip()
|
|
||||||
if len(totp_secret) == 0:
|
|
||||||
err('totp_secret not defined')
|
|
||||||
state_token = j.get('stateToken', '').strip()
|
state_token = j.get('stateToken', '').strip()
|
||||||
if len(state_token) == 0:
|
if len(state_token) == 0:
|
||||||
err('empty state token')
|
err('empty state token')
|
||||||
@@ -198,13 +202,21 @@ def okta_mfa(conf, s, j):
|
|||||||
dbg(conf.get('debug'), 'factor', factor_id, factor_type, factor_url)
|
dbg(conf.get('debug'), 'factor', factor_id, factor_type, factor_url)
|
||||||
if factor_type != 'token:software:totp':
|
if factor_type != 'token:software:totp':
|
||||||
err('factor is not totp type')
|
err('factor is not totp type')
|
||||||
|
|
||||||
|
totp_code = None
|
||||||
|
totp_secret = conf.get('totp_secret', '').strip()
|
||||||
|
if len(totp_secret) == 0:
|
||||||
|
totp_code = raw_input('TOTP: ').strip()
|
||||||
|
if len(totp_code) == 0:
|
||||||
|
err('empty totp')
|
||||||
|
if totp_code is None:
|
||||||
import pyotp
|
import pyotp
|
||||||
totp = pyotp.TOTP(totp_secret)
|
totp = pyotp.TOTP(totp_secret)
|
||||||
pass_code = totp.now()
|
totp_code = totp.now()
|
||||||
data = {
|
data = {
|
||||||
'factorId': factor_id,
|
'factorId': factor_id,
|
||||||
'stateToken': state_token,
|
'stateToken': state_token,
|
||||||
'passCode': pass_code,
|
'passCode': totp_code,
|
||||||
}
|
}
|
||||||
log('mfa request')
|
log('mfa request')
|
||||||
r = s.post(factor_url, headers=hdr_json(), data=json.dumps(data))
|
r = s.post(factor_url, headers=hdr_json(), data=json.dumps(data))
|
||||||
|
|||||||
Reference in New Issue
Block a user