Added loging to auth.log, removed sys.exit from pam handler causing err
This commit is contained in:
parent
a04b33d01b
commit
6e9169e87c
2 changed files with 19 additions and 6 deletions
20
src/pam.py
20
src/pam.py
|
|
@ -2,9 +2,9 @@
|
||||||
|
|
||||||
# Import required modules
|
# Import required modules
|
||||||
import subprocess
|
import subprocess
|
||||||
import sys
|
|
||||||
import os
|
import os
|
||||||
import glob
|
import glob
|
||||||
|
import syslog
|
||||||
|
|
||||||
# pam-python is running python 2, so we use the old module here
|
# pam-python is running python 2, so we use the old module here
|
||||||
import ConfigParser
|
import ConfigParser
|
||||||
|
|
@ -19,22 +19,24 @@ def doAuth(pamh):
|
||||||
|
|
||||||
# Abort is Howdy is disabled
|
# Abort is Howdy is disabled
|
||||||
if config.getboolean("core", "disabled"):
|
if config.getboolean("core", "disabled"):
|
||||||
sys.exit(0)
|
return pamh.PAM_AUTHINFO_UNAVAIL
|
||||||
|
|
||||||
# Abort if we're in a remote SSH env
|
# Abort if we're in a remote SSH env
|
||||||
if config.getboolean("core", "ignore_ssh"):
|
if config.getboolean("core", "ignore_ssh"):
|
||||||
if "SSH_CONNECTION" in os.environ or "SSH_CLIENT" in os.environ or "SSHD_OPTS" in os.environ:
|
if "SSH_CONNECTION" in os.environ or "SSH_CLIENT" in os.environ or "SSHD_OPTS" in os.environ:
|
||||||
sys.exit(0)
|
return pamh.PAM_AUTHINFO_UNAVAIL
|
||||||
|
|
||||||
# Abort if lid is closed
|
# Abort if lid is closed
|
||||||
if config.getboolean("core", "ignore_closed_lid"):
|
if config.getboolean("core", "ignore_closed_lid"):
|
||||||
if any("closed" in open(f).read() for f in glob.glob("/proc/acpi/button/lid/*/state")):
|
if any("closed" in open(f).read() for f in glob.glob("/proc/acpi/button/lid/*/state")):
|
||||||
sys.exit(0)
|
return pamh.PAM_AUTHINFO_UNAVAIL
|
||||||
|
|
||||||
# Alert the user that we are doing face detection
|
# Alert the user that we are doing face detection
|
||||||
if config.getboolean("core", "detection_notice"):
|
if config.getboolean("core", "detection_notice"):
|
||||||
pamh.conversation(pamh.Message(pamh.PAM_TEXT_INFO, "Attempting face detection"))
|
pamh.conversation(pamh.Message(pamh.PAM_TEXT_INFO, "Attempting face detection"))
|
||||||
|
|
||||||
|
syslog.syslog(syslog.LOG_AUTH, "[HOWDY] Attempting facial authentication for user " + pamh.get_user())
|
||||||
|
|
||||||
# Run compare as python3 subprocess to circumvent python version and import issues
|
# Run compare as python3 subprocess to circumvent python version and import issues
|
||||||
status = subprocess.call(["/usr/bin/python3", os.path.dirname(os.path.abspath(__file__)) + "/compare.py", pamh.get_user()])
|
status = subprocess.call(["/usr/bin/python3", os.path.dirname(os.path.abspath(__file__)) + "/compare.py", pamh.get_user()])
|
||||||
|
|
||||||
|
|
@ -42,16 +44,24 @@ def doAuth(pamh):
|
||||||
if status == 10:
|
if status == 10:
|
||||||
if not config.getboolean("core", "suppress_unknown"):
|
if not config.getboolean("core", "suppress_unknown"):
|
||||||
pamh.conversation(pamh.Message(pamh.PAM_ERROR_MSG, "No face model known"))
|
pamh.conversation(pamh.Message(pamh.PAM_ERROR_MSG, "No face model known"))
|
||||||
|
|
||||||
|
syslog.syslog(syslog.LOG_AUTH, "[HOWDY] Failure, no face model known")
|
||||||
return pamh.PAM_USER_UNKNOWN
|
return pamh.PAM_USER_UNKNOWN
|
||||||
|
|
||||||
# Status 11 means we exceded the maximum retry count
|
# Status 11 means we exceded the maximum retry count
|
||||||
elif status == 11:
|
elif status == 11:
|
||||||
pamh.conversation(pamh.Message(pamh.PAM_ERROR_MSG, "Face detection timeout reached"))
|
pamh.conversation(pamh.Message(pamh.PAM_ERROR_MSG, "Face detection timeout reached"))
|
||||||
|
syslog.syslog(syslog.LOG_AUTH, "[HOWDY] Failure, timeout reached")
|
||||||
return pamh.PAM_AUTH_ERR
|
return pamh.PAM_AUTH_ERR
|
||||||
|
|
||||||
# Status 12 means we aborted
|
# Status 12 means we aborted
|
||||||
elif status == 12:
|
elif status == 12:
|
||||||
|
syslog.syslog(syslog.LOG_AUTH, "[HOWDY] Failure, general abort")
|
||||||
return pamh.PAM_AUTH_ERR
|
return pamh.PAM_AUTH_ERR
|
||||||
|
|
||||||
# Status 13 means the image was too dark
|
# Status 13 means the image was too dark
|
||||||
elif status == 13:
|
elif status == 13:
|
||||||
|
syslog.syslog(syslog.LOG_AUTH, "[HOWDY] Failure, image too dark")
|
||||||
pamh.conversation(pamh.Message(pamh.PAM_ERROR_MSG, "Face detection image too dark"))
|
pamh.conversation(pamh.Message(pamh.PAM_ERROR_MSG, "Face detection image too dark"))
|
||||||
return pamh.PAM_AUTH_ERR
|
return pamh.PAM_AUTH_ERR
|
||||||
# Status 0 is a successful exit
|
# Status 0 is a successful exit
|
||||||
|
|
@ -60,10 +70,12 @@ def doAuth(pamh):
|
||||||
if not config.getboolean("core", "no_confirmation"):
|
if not config.getboolean("core", "no_confirmation"):
|
||||||
pamh.conversation(pamh.Message(pamh.PAM_TEXT_INFO, "Identified face as " + pamh.get_user()))
|
pamh.conversation(pamh.Message(pamh.PAM_TEXT_INFO, "Identified face as " + pamh.get_user()))
|
||||||
|
|
||||||
|
syslog.syslog(syslog.LOG_AUTH, "[HOWDY] Login approved")
|
||||||
return pamh.PAM_SUCCESS
|
return pamh.PAM_SUCCESS
|
||||||
|
|
||||||
# Otherwise, we can't discribe what happend but it wasn't successful
|
# Otherwise, we can't discribe what happend but it wasn't successful
|
||||||
pamh.conversation(pamh.Message(pamh.PAM_ERROR_MSG, "Unknown error: " + str(status)))
|
pamh.conversation(pamh.Message(pamh.PAM_ERROR_MSG, "Unknown error: " + str(status)))
|
||||||
|
syslog.syslog(syslog.LOG_AUTH, "[HOWDY] Failure, unknown error" + str(status))
|
||||||
return pamh.PAM_SYSTEM_ERR
|
return pamh.PAM_SYSTEM_ERR
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -15,7 +15,6 @@ import sys
|
||||||
|
|
||||||
|
|
||||||
class VideoCapture:
|
class VideoCapture:
|
||||||
|
|
||||||
def __init__(self, config):
|
def __init__(self, config):
|
||||||
"""
|
"""
|
||||||
Creates a new VideoCapture instance depending on the settings in the
|
Creates a new VideoCapture instance depending on the settings in the
|
||||||
|
|
@ -23,6 +22,8 @@ class VideoCapture:
|
||||||
|
|
||||||
Config can either be a string to the path, or a pre-setup configparser.
|
Config can either be a string to the path, or a pre-setup configparser.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
# Parse config from string if nedded
|
||||||
if isinstance(config, str):
|
if isinstance(config, str):
|
||||||
self.config = configparser.ConfigParser()
|
self.config = configparser.ConfigParser()
|
||||||
self.config.read(config)
|
self.config.read(config)
|
||||||
|
|
@ -30,7 +31,7 @@ class VideoCapture:
|
||||||
self.config = config
|
self.config = config
|
||||||
|
|
||||||
# Check device path
|
# Check device path
|
||||||
if not os.path.exists(config.get("video", "device_path")):
|
if not os.path.exists(self.config.get("video", "device_path")):
|
||||||
print("Camera path is not configured correctly, please edit the 'device_path' config value.")
|
print("Camera path is not configured correctly, please edit the 'device_path' config value.")
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue