Add XAuthorityInSystemDir option

Add an option to allow XAUTHORITY to be moved away from $HOME.

This is modelled on the lightm 'user-authority-in-system-dir' option,
and also current GDM default behaviour.
This commit is contained in:
matt335672
2025-01-13 11:48:51 +00:00
parent b61dfb1096
commit d2e96fe2d2
5 changed files with 28 additions and 0 deletions
+8
View File
@@ -251,6 +251,14 @@ The number of login attempts that are allowed on terminal server. If set
to \fI0\fR, unlimited attempts are allowed. If not specified, defaults to
\fI3\fR.
.TP
\fBXAuthorityInSystemDir\fR=\fI[no|yes]\fR
If set to \fByes\fR, xrdp will set XAUTHORITY to be in a system directory
(currently @socketdir@/\fI<uid>\fR) which is only accessible to the
logged-in user.
You may wish to use this if $HOME is NFS-mounted, or you are experiencing
other applications overwriting the default file.
.TP
\fBTerminalServerUsers\fR=\fIgroup\fR
Only the users belonging to the specified group are allowed to login on
+7
View File
@@ -63,6 +63,7 @@
*/
#define SESMAN_CFG_SECURITY "Security"
#define SESMAN_CFG_SEC_LOGIN_RETRY "MaxLoginRetry"
#define SESMAN_CFG_XAUTH_IN_SYSDIR "XAuthorityInSystemDir"
#define SESMAN_CFG_SEC_ALLOW_ROOT "AllowRootLogin"
#define SESMAN_CFG_SEC_USR_GROUP "TerminalServerUsers"
#define SESMAN_CFG_SEC_ADM_GROUP "TerminalServerAdmins"
@@ -307,6 +308,7 @@ config_read_security(int file, struct config_security *sc,
/* setting defaults */
sc->allow_root = 0;
sc->login_retry = 3;
sc->xauth_in_sysdir = 0;
sc->restrict_outbound_clipboard = 0;
sc->restrict_inbound_clipboard = 0;
sc->allow_alternate_shell = 1;
@@ -330,6 +332,10 @@ config_read_security(int file, struct config_security *sc,
{
sc->login_retry = g_atoi(value);
}
else if (0 == g_strcasecmp(buf, SESMAN_CFG_XAUTH_IN_SYSDIR))
{
sc->xauth_in_sysdir = g_text2bool(value);
}
else if (0 == g_strcasecmp(buf, SESMAN_CFG_SEC_USR_GROUP))
{
g_free(sc->ts_users);
@@ -672,6 +678,7 @@ config_dump(struct config_sesman *config)
g_writeln("Security configuration:");
g_writeln(" AllowRootLogin: %d", sc->allow_root);
g_writeln(" MaxLoginRetry: %d", sc->login_retry);
g_writeln(" XAuthorityInSystemDir: %d", sc->xauth_in_sysdir);
g_writeln(" AlwaysGroupCheck: %d", sc->ts_always_group_check);
g_writeln(" AllowAlternateShell: %d", sc->allow_alternate_shell);
#ifdef HAVE_SYS_PRCTL_H
+6
View File
@@ -68,6 +68,12 @@ struct config_security
* @brief maximum login attempts
*/
int login_retry;
/**
* @var x_authority_in_system_dir
* @brief Move XAUTHORITY to a system directory
*/
int xauth_in_sysdir;
/**
* @var ts_users
* @brief Terminal Server Users group
+6
View File
@@ -162,6 +162,12 @@ env_set_user(int uid, char **passwd_file, int display,
/* pulse source socket */
g_snprintf(text, sizeof(text), CHANSRV_PORT_IN_BASE_STR, display);
g_setenv("XRDP_PULSE_SOURCE_SOCKET", text, 1);
if (g_cfg->sec.xauth_in_sysdir)
{
g_snprintf(text, sizeof(text), XRDP_SOCKET_PATH "/Xauthority",
uid);
g_setenv("XAUTHORITY", text, 1);
}
if ((env_names != 0) && (env_values != 0) &&
(env_names->count == env_values->count))
{
+1
View File
@@ -14,6 +14,7 @@ ReconnectScript=reconnectwm.sh
[Security]
AllowRootLogin=true
MaxLoginRetry=4
XAuthorityInSystemDir=no
TerminalServerUsers=tsusers
TerminalServerAdmins=tsadmins
; When AlwaysGroupCheck=false access will be permitted