mirror of
				https://github.com/go-gitea/gitea
				synced 2025-10-31 03:18:24 +00:00 
			
		
		
		
	Backport #28392 by @nekrondev Windows-based shells will add a CRLF when piping the token into ssh-keygen command resulting in verification error. This resolves #21527. Co-authored-by: nekrondev <heiko@noordsee.de> Co-authored-by: Heiko Besemann <heiko.besemann@qbeyond.de> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
		| @@ -29,10 +29,15 @@ func VerifySSHKey(ownerID int64, fingerprint, token, signature string) (string, | ||||
| 		return "", ErrKeyNotExist{} | ||||
| 	} | ||||
|  | ||||
| 	if err := sshsig.Verify(bytes.NewBuffer([]byte(token)), []byte(signature), []byte(key.Content), "gitea"); err != nil { | ||||
| 		log.Error("Unable to validate token signature. Error: %v", err) | ||||
| 		return "", ErrSSHInvalidTokenSignature{ | ||||
| 			Fingerprint: key.Fingerprint, | ||||
| 	err = sshsig.Verify(bytes.NewBuffer([]byte(token)), []byte(signature), []byte(key.Content), "gitea") | ||||
| 	if err != nil { | ||||
| 		// edge case for Windows based shells that will add CR LF if piped to ssh-keygen command | ||||
| 		// see https://github.com/PowerShell/PowerShell/issues/5974 | ||||
| 		if sshsig.Verify(bytes.NewBuffer([]byte(token+"\r\n")), []byte(signature), []byte(key.Content), "gitea") != nil { | ||||
| 			log.Error("Unable to validate token signature. Error: %v", err) | ||||
| 			return "", ErrSSHInvalidTokenSignature{ | ||||
| 				Fingerprint: key.Fingerprint, | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
|   | ||||
		Reference in New Issue
	
	Block a user