www-servers/nginx: http_auth_pam: adjust loglevel for auth failures
authorThomas Deutschmann <whissi@gentoo.org>
Thu, 13 Dec 2018 15:37:16 +0000 (16:37 +0100)
committerThomas Deutschmann <whissi@gentoo.org>
Thu, 13 Dec 2018 15:39:29 +0000 (16:39 +0100)
Package-Manager: Portage-2.3.52, Repoman-2.3.12
Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>
www-servers/nginx/files/http_auth_pam-1.5.1-adjust-loglevel-for-authentication-failures.patch [new file with mode: 0644]
www-servers/nginx/nginx-1.14.2-r1.ebuild [moved from www-servers/nginx/nginx-1.14.2.ebuild with 99% similarity]
www-servers/nginx/nginx-1.15.7-r1.ebuild [moved from www-servers/nginx/nginx-1.15.7.ebuild with 99% similarity]

diff --git a/www-servers/nginx/files/http_auth_pam-1.5.1-adjust-loglevel-for-authentication-failures.patch b/www-servers/nginx/files/http_auth_pam-1.5.1-adjust-loglevel-for-authentication-failures.patch
new file mode 100644 (file)
index 0000000..632dcde
--- /dev/null
@@ -0,0 +1,22 @@
+https://github.com/sto/ngx_http_auth_pam_module/pull/18
+
+--- a/ngx_http_auth_pam_module.c
++++ b/ngx_http_auth_pam_module.c
+@@ -348,7 +348,7 @@ ngx_http_auth_pam_authenticate(ngx_http_request_t *r,
+     /* try to authenticate user, log error on failure */
+     if ((rc = pam_authenticate(pamh,
+                                PAM_DISALLOW_NULL_AUTHTOK)) != PAM_SUCCESS) {
+-        ngx_log_debug2(NGX_LOG_DEBUG_HTTP, r->connection->log, 0,
++        ngx_log_error(NGX_LOG_ERR, r->connection->log, 0,
+                       "PAM: user '%s' - not authenticated: %s",
+                       ainfo.username.data, pam_strerror(pamh, rc));
+         pam_end(pamh, PAM_SUCCESS);
+@@ -357,7 +357,7 @@ ngx_http_auth_pam_authenticate(ngx_http_request_t *r,
+ 
+     /* check that the account is healthy */
+     if ((rc = pam_acct_mgmt(pamh, PAM_DISALLOW_NULL_AUTHTOK)) != PAM_SUCCESS) {
+-        ngx_log_debug2(NGX_LOG_DEBUG_HTTP, r->connection->log, 0,
++        ngx_log_error(NGX_LOG_ERR, r->connection->log, 0,
+                       "PAM: user '%s'  - invalid account: %s",
+                       ainfo.username.data, pam_strerror(pamh, rc));
+         pam_end(pamh, PAM_SUCCESS);
similarity index 99%
rename from www-servers/nginx/nginx-1.14.2.ebuild
rename to www-servers/nginx/nginx-1.14.2-r1.ebuild
index 66b09925f1e0c31622a6b192541340c3831cf773..08100e45578752ad097f67fa0a7261cce5949aa8 100644 (file)
@@ -381,6 +381,12 @@ src_prepare() {
        eapply "${FILESDIR}/${PN}-1.4.1-fix-perl-install-path.patch"
        eapply "${FILESDIR}/${PN}-httpoxy-mitigation-r1.patch"
 
+       if use nginx_modules_http_auth_pam; then
+               cd "${HTTP_AUTH_PAM_MODULE_WD}" || die
+               eapply "${FILESDIR}"/http_auth_pam-1.5.1-adjust-loglevel-for-authentication-failures.patch
+               cd "${S}" || die
+       fi
+
        if use nginx_modules_http_brotli; then
                cd "${HTTP_BROTLI_MODULE_WD}" || die
                eapply "${FILESDIR}"/http_brotli-detect-brotli-r2.patch
similarity index 99%
rename from www-servers/nginx/nginx-1.15.7.ebuild
rename to www-servers/nginx/nginx-1.15.7-r1.ebuild
index e873f4b5416305136fdc6d2e0de7085391f0e09e..6fbcd2eaad4bd6db75c93b22978f5e58329970dd 100644 (file)
@@ -381,6 +381,12 @@ src_prepare() {
        eapply "${FILESDIR}/${PN}-1.4.1-fix-perl-install-path.patch"
        eapply "${FILESDIR}/${PN}-httpoxy-mitigation-r1.patch"
 
+       if use nginx_modules_http_auth_pam; then
+               cd "${HTTP_AUTH_PAM_MODULE_WD}" || die
+               eapply "${FILESDIR}"/http_auth_pam-1.5.1-adjust-loglevel-for-authentication-failures.patch
+               cd "${S}" || die
+       fi
+
        if use nginx_modules_http_brotli; then
                cd "${HTTP_BROTLI_MODULE_WD}" || die
                eapply "${FILESDIR}"/http_brotli-detect-brotli-r2.patch