author Mozilla Releng Treescript <release+treescript@mozilla.org>
Mon, 05 Dec 2022 15:31:08 +0000
changeset 713401 2f7d3460c20c4fd9544cb35924ee99ba8ee32bdf
parent 657487 c0d6eff2103b06d37dffe94f13fb7fe8f25e4863
permissions -rw-r--r--
No bug - tagging d49c937bc2e046430bb9468a57ad5151b49bd8ed with FIREFOX_RELEASE_108_BASE a=release DONTBUILD CLOSED TREE

/* vim:set ts=4 sw=2 et cindent: */
/* This Source Code Form is subject to the terms of the Mozilla Public
 * License, v. 2.0. If a copy of the MPL was not distributed with this
 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */

#ifndef nsAuthSambaNTLM_h__
#define nsAuthSambaNTLM_h__

#include "nsIAuthModule.h"
#include "nsString.h"
#include "nsCOMPtr.h"
#include "prio.h"
#include "prproces.h"
#include "mozilla/Attributes.h"

 * This is an implementation of NTLM authentication that does single-signon
 * by obtaining the user's Unix username, parsing it into DOMAIN\name format,
 * and then asking Samba's ntlm_auth tool to do the authentication for us
 * using the user's password cached in winbindd, if available. If the
 * password is not available then this component fails to instantiate so
 * nsHttpNTLMAuth will fall back to a different NTLM implementation.
 * NOTE: at time of writing, this requires patches to be added to the stock
 * Samba winbindd and ntlm_auth!
class nsAuthSambaNTLM final : public nsIAuthModule {


  // We spawn the ntlm_auth helper from the module constructor, because
  // that lets us fail to instantiate the module if ntlm_auth isn't
  // available, triggering fallback to the built-in NTLM support (which
  // doesn't support single signon, of course)
  nsresult SpawnNTLMAuthHelper();


  void Shutdown();

  uint8_t* mInitialMessage; /* free with free() */
  uint32_t mInitialMessageLen{};
  PRProcess* mChildPID;
  PRFileDesc* mFromChildFD;
  PRFileDesc* mToChildFD;

#endif /* nsAuthSambaNTLM_h__ */