Add XAuthorityInSystemDir option
Add an option to allow XAUTHORITY to be moved away from $HOME. This is modelled on the lightm 'user-authority-in-system-dir' option, and also current GDM default behaviour.
This commit is contained in:
@@ -251,6 +251,14 @@ The number of login attempts that are allowed on terminal server. If set
|
||||
to \fI0\fR, unlimited attempts are allowed. If not specified, defaults to
|
||||
\fI3\fR.
|
||||
|
||||
.TP
|
||||
\fBXAuthorityInSystemDir\fR=\fI[no|yes]\fR
|
||||
If set to \fByes\fR, xrdp will set XAUTHORITY to be in a system directory
|
||||
(currently @socketdir@/\fI<uid>\fR) which is only accessible to the
|
||||
logged-in user.
|
||||
You may wish to use this if $HOME is NFS-mounted, or you are experiencing
|
||||
other applications overwriting the default file.
|
||||
|
||||
.TP
|
||||
\fBTerminalServerUsers\fR=\fIgroup\fR
|
||||
Only the users belonging to the specified group are allowed to login on
|
||||
|
||||
@@ -63,6 +63,7 @@
|
||||
*/
|
||||
#define SESMAN_CFG_SECURITY "Security"
|
||||
#define SESMAN_CFG_SEC_LOGIN_RETRY "MaxLoginRetry"
|
||||
#define SESMAN_CFG_XAUTH_IN_SYSDIR "XAuthorityInSystemDir"
|
||||
#define SESMAN_CFG_SEC_ALLOW_ROOT "AllowRootLogin"
|
||||
#define SESMAN_CFG_SEC_USR_GROUP "TerminalServerUsers"
|
||||
#define SESMAN_CFG_SEC_ADM_GROUP "TerminalServerAdmins"
|
||||
@@ -307,6 +308,7 @@ config_read_security(int file, struct config_security *sc,
|
||||
/* setting defaults */
|
||||
sc->allow_root = 0;
|
||||
sc->login_retry = 3;
|
||||
sc->xauth_in_sysdir = 0;
|
||||
sc->restrict_outbound_clipboard = 0;
|
||||
sc->restrict_inbound_clipboard = 0;
|
||||
sc->allow_alternate_shell = 1;
|
||||
@@ -330,6 +332,10 @@ config_read_security(int file, struct config_security *sc,
|
||||
{
|
||||
sc->login_retry = g_atoi(value);
|
||||
}
|
||||
else if (0 == g_strcasecmp(buf, SESMAN_CFG_XAUTH_IN_SYSDIR))
|
||||
{
|
||||
sc->xauth_in_sysdir = g_text2bool(value);
|
||||
}
|
||||
else if (0 == g_strcasecmp(buf, SESMAN_CFG_SEC_USR_GROUP))
|
||||
{
|
||||
g_free(sc->ts_users);
|
||||
@@ -672,6 +678,7 @@ config_dump(struct config_sesman *config)
|
||||
g_writeln("Security configuration:");
|
||||
g_writeln(" AllowRootLogin: %d", sc->allow_root);
|
||||
g_writeln(" MaxLoginRetry: %d", sc->login_retry);
|
||||
g_writeln(" XAuthorityInSystemDir: %d", sc->xauth_in_sysdir);
|
||||
g_writeln(" AlwaysGroupCheck: %d", sc->ts_always_group_check);
|
||||
g_writeln(" AllowAlternateShell: %d", sc->allow_alternate_shell);
|
||||
#ifdef HAVE_SYS_PRCTL_H
|
||||
|
||||
@@ -68,6 +68,12 @@ struct config_security
|
||||
* @brief maximum login attempts
|
||||
*/
|
||||
int login_retry;
|
||||
/**
|
||||
* @var x_authority_in_system_dir
|
||||
* @brief Move XAUTHORITY to a system directory
|
||||
*/
|
||||
int xauth_in_sysdir;
|
||||
|
||||
/**
|
||||
* @var ts_users
|
||||
* @brief Terminal Server Users group
|
||||
|
||||
@@ -162,6 +162,12 @@ env_set_user(int uid, char **passwd_file, int display,
|
||||
/* pulse source socket */
|
||||
g_snprintf(text, sizeof(text), CHANSRV_PORT_IN_BASE_STR, display);
|
||||
g_setenv("XRDP_PULSE_SOURCE_SOCKET", text, 1);
|
||||
if (g_cfg->sec.xauth_in_sysdir)
|
||||
{
|
||||
g_snprintf(text, sizeof(text), XRDP_SOCKET_PATH "/Xauthority",
|
||||
uid);
|
||||
g_setenv("XAUTHORITY", text, 1);
|
||||
}
|
||||
if ((env_names != 0) && (env_values != 0) &&
|
||||
(env_names->count == env_values->count))
|
||||
{
|
||||
|
||||
@@ -14,6 +14,7 @@ ReconnectScript=reconnectwm.sh
|
||||
[Security]
|
||||
AllowRootLogin=true
|
||||
MaxLoginRetry=4
|
||||
XAuthorityInSystemDir=no
|
||||
TerminalServerUsers=tsusers
|
||||
TerminalServerAdmins=tsadmins
|
||||
; When AlwaysGroupCheck=false access will be permitted
|
||||
|
||||
Reference in New Issue
Block a user