Github user necouchman commented on a diff in the pull request:

    
https://github.com/apache/incubator-guacamole-client/pull/111#discussion_r99333796
  
    --- Diff: 
extensions/guacamole-auth-http/src/main/java/org/apache/guacamole/auth/http/AuthenticationProviderService.java
 ---
    @@ -0,0 +1,89 @@
    +/*
    + * Licensed to the Apache Software Foundation (ASF) under one
    + * or more contributor license agreements.  See the NOTICE file
    + * distributed with this work for additional information
    + * regarding copyright ownership.  The ASF licenses this file
    + * to you under the Apache License, Version 2.0 (the
    + * "License"); you may not use this file except in compliance
    + * with the License.  You may obtain a copy of the License at
    + *
    + *   http://www.apache.org/licenses/LICENSE-2.0
    + *
    + * Unless required by applicable law or agreed to in writing,
    + * software distributed under the License is distributed on an
    + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
    + * KIND, either express or implied.  See the License for the
    + * specific language governing permissions and limitations
    + * under the License.
    + */
    +
    +package org.apache.guacamole.auth.http;
    +
    +import com.google.inject.Inject;
    +import com.google.inject.Provider;
    +import javax.servlet.http.HttpServletRequest;
    +import org.apache.guacamole.GuacamoleException;
    +import org.apache.guacamole.net.auth.Credentials;
    +import org.apache.guacamole.net.auth.credentials.CredentialsInfo;
    +import 
org.apache.guacamole.net.auth.credentials.GuacamoleInvalidCredentialsException;
    +import org.apache.guacamole.auth.http.user.AuthenticatedUser;
    +import java.security.Principal;
    +
    +/**
    + * Service providing convenience functions for the HTTP 
AuthenticationProvider
    + * implementation.
    + *
    + * @author Nick Couchman
    + */
    +public class AuthenticationProviderService {
    +
    +    /**
    +     * Service for retrieving header configuration information.
    +     */
    +    @Inject
    +    private ConfigurationService confService;
    +
    +    /**
    +     * Provider for AuthenticatedUser objects.
    +     */
    +    @Inject
    +    private Provider<AuthenticatedUser> authenticatedUserProvider;
    +
    +    /**
    +     * Returns an AuthenticatedUser representing the user authenticated by 
the
    +     * given credentials.
    +     *
    +     * @param credentials
    +     *     The credentials to use for authentication.
    +     *
    +     * @return
    +     *     An AuthenticatedUser representing the user authenticated by the
    +     *     given credentials.
    +     *
    +     * @throws GuacamoleException
    +     *     If an error occurs while authenticating the user, or if access 
is
    +     *     denied.
    +     */
    +    public AuthenticatedUser authenticateUser(Credentials credentials)
    +            throws GuacamoleException {
    +
    +        // Pull HTTP header from request if present
    +        HttpServletRequest request = credentials.getRequest();
    +        if (request != null) {
    +            String username = request.getRemoteUser();
    +            if(username == null)
    +                username = 
request.getHeader(confService.getHttpAuthHeader());
    --- End diff --
    
    So, Oracle's JavaEE documentation has this to say on the subject of 
HttpServletRequest getRemoteUser():
    
    > Returns the login of the user making this request, if the user has been 
authenticated, or null if the user has not been authenticated. Whether the user 
name is sent with each subsequent request depends on the browser and type of 
authentication. Same as the value of the CGI variable REMOTE_USER.
    
    This indicates to me that this function probably works off the REMOTE_USER 
header.
    
    That said, it may still be a little confusing for the operator to set 
something up in guacamole.properties for a custom header, and then run into a 
situation where a different username gets pulled from getRemoteUser() (because 
it's looking at the REMOTE_USER header) and whatever the operator has 
configured as their header.  So, I think the two options would be:
    1) Remove getRemoteUser() altogether and just work off the configured 
header, or default to REMOTE_USER if none is configured.
    2) Reverse the logic such that the configured header is checked, first, 
and, if nothing is found or nothing configured, revert to getRemoteUser().  
This may not be overly-useful though, and may not eliminate the confusion for 
the operator.
    
    Thoughts?


---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at [email protected] or file a JIRA ticket
with INFRA.
---

Reply via email to