fix: Fixes server access for owners (#916)

* Removes new password on reset option.
* Fixes a bug with the feature that would allow an exploit.
This commit is contained in:
Kamron Batman 2022-01-10 23:32:12 -08:00 • committed by GitHub
parent fc51b60cc1
commit 1989488638
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -5,6 +5,7 @@ using System.Text.Json.Serialization;
using Server.Accounting;
using Server.Json;
using Server.Logging;
using Server.Network;
namespace Server.Misc;
@ -67,33 +68,26 @@ public static class ServerAccess
return;
}
var account = Accounts.GetAccount(username);
if (account is not { Banned: true, AccessLevel: >= AccessLevel.Owner })
var acct = Accounts.GetAccount(username);
if (acct == null || !acct.Banned && acct.AccessLevel >= AccessLevel.Owner || !acct.CheckPassword(e.Password))
{
return;
}
account.Banned = false;
account.AccessLevel = AccessLevel.Owner;
acct.Banned = false;
acct.AccessLevel = AccessLevel.Owner;
logger.Warning("Protected account \"{0}\" has been reset.", username);
if (ServerAccessConfiguration.NewPasswordOnReset)
if (e.RejectReason is ALRReason.Blocked or ALRReason.BadPass or ALRReason.BadComm)
{
var password = Guid.NewGuid().ToString();
logger.Warning("Protected account \"{0}\" password reset to \"{1}\"", username, password);
account.SetPassword(password);
e.Accepted = true;
}
e.Accepted = true;
}
}
public record ServerAccessConfiguration
{
[JsonPropertyName("newPasswordOnReset")]
public bool NewPasswordOnReset { get; init; }
[JsonPropertyName("protectedAccounts")]
public HashSet<string> ProtectedAccounts { get; init; }
}