drop userauth implementation

closes #1341
This commit is contained in:
Yasuhiro Matsumoto
2025-07-26 21:16:49 +09:00
committed by mattn
parent 8c283ed77e
commit d8fd268206

View File

@@ -16,53 +16,10 @@ package sqlite3
#else #else
#include <sqlite3.h> #include <sqlite3.h>
#endif #endif
#include <stdlib.h>
static int
_sqlite3_user_authenticate(sqlite3* db, const char* zUsername, const char* aPW, int nPW)
{
return sqlite3_user_authenticate(db, zUsername, aPW, nPW);
}
static int
_sqlite3_user_add(sqlite3* db, const char* zUsername, const char* aPW, int nPW, int isAdmin)
{
return sqlite3_user_add(db, zUsername, aPW, nPW, isAdmin);
}
static int
_sqlite3_user_change(sqlite3* db, const char* zUsername, const char* aPW, int nPW, int isAdmin)
{
return sqlite3_user_change(db, zUsername, aPW, nPW, isAdmin);
}
static int
_sqlite3_user_delete(sqlite3* db, const char* zUsername)
{
return sqlite3_user_delete(db, zUsername);
}
static int
_sqlite3_auth_enabled(sqlite3* db)
{
int exists = -1;
sqlite3_stmt *stmt;
sqlite3_prepare_v2(db, "select count(type) from sqlite_master WHERE type='table' and name='sqlite_user';", -1, &stmt, NULL);
while ( sqlite3_step(stmt) == SQLITE_ROW) {
exists = sqlite3_column_int(stmt, 0);
}
sqlite3_finalize(stmt);
return exists;
}
*/ */
import "C" import "C"
import ( import (
"errors" "errors"
"unsafe"
) )
const ( const (
@@ -88,15 +45,7 @@ var (
// If the SQLITE_USER table is not present in the database file, then // If the SQLITE_USER table is not present in the database file, then
// this interface is a harmless no-op returning SQLITE_OK. // this interface is a harmless no-op returning SQLITE_OK.
func (c *SQLiteConn) Authenticate(username, password string) error { func (c *SQLiteConn) Authenticate(username, password string) error {
rv := c.authenticate(username, password)
switch rv {
case C.SQLITE_ERROR, C.SQLITE_AUTH:
return ErrUnauthorized return ErrUnauthorized
case C.SQLITE_OK:
return nil
default:
return c.lastError()
}
} }
// authenticate provides the actual authentication to SQLite. // authenticate provides the actual authentication to SQLite.
@@ -109,17 +58,7 @@ func (c *SQLiteConn) Authenticate(username, password string) error {
// C.SQLITE_ERROR (1) // C.SQLITE_ERROR (1)
// C.SQLITE_AUTH (23) // C.SQLITE_AUTH (23)
func (c *SQLiteConn) authenticate(username, password string) int { func (c *SQLiteConn) authenticate(username, password string) int {
// Allocate C Variables return 1
cuser := C.CString(username)
cpass := C.CString(password)
// Free C Variables
defer func() {
C.free(unsafe.Pointer(cuser))
C.free(unsafe.Pointer(cpass))
}()
return int(C._sqlite3_user_authenticate(c.db, cuser, cpass, C.int(len(password))))
} }
// AuthUserAdd can be used (by an admin user only) // AuthUserAdd can be used (by an admin user only)
@@ -131,20 +70,7 @@ func (c *SQLiteConn) authenticate(username, password string) int {
// for any ATTACH-ed databases. Any call to AuthUserAdd by a // for any ATTACH-ed databases. Any call to AuthUserAdd by a
// non-admin user results in an error. // non-admin user results in an error.
func (c *SQLiteConn) AuthUserAdd(username, password string, admin bool) error { func (c *SQLiteConn) AuthUserAdd(username, password string, admin bool) error {
isAdmin := 0 return ErrUnauthorized
if admin {
isAdmin = 1
}
rv := c.authUserAdd(username, password, isAdmin)
switch rv {
case C.SQLITE_ERROR, C.SQLITE_AUTH:
return ErrAdminRequired
case C.SQLITE_OK:
return nil
default:
return c.lastError()
}
} }
// authUserAdd enables the User Authentication if not enabled. // authUserAdd enables the User Authentication if not enabled.
@@ -162,17 +88,7 @@ func (c *SQLiteConn) AuthUserAdd(username, password string, admin bool) error {
// C.SQLITE_ERROR (1) // C.SQLITE_ERROR (1)
// C.SQLITE_AUTH (23) // C.SQLITE_AUTH (23)
func (c *SQLiteConn) authUserAdd(username, password string, admin int) int { func (c *SQLiteConn) authUserAdd(username, password string, admin int) int {
// Allocate C Variables return 1
cuser := C.CString(username)
cpass := C.CString(password)
// Free C Variables
defer func() {
C.free(unsafe.Pointer(cuser))
C.free(unsafe.Pointer(cpass))
}()
return int(C._sqlite3_user_add(c.db, cuser, cpass, C.int(len(password)), C.int(admin)))
} }
// AuthUserChange can be used to change a users // AuthUserChange can be used to change a users
@@ -181,20 +97,7 @@ func (c *SQLiteConn) authUserAdd(username, password string, admin int) int {
// credentials or admin privilege setting. No user may change their own // credentials or admin privilege setting. No user may change their own
// admin privilege setting. // admin privilege setting.
func (c *SQLiteConn) AuthUserChange(username, password string, admin bool) error { func (c *SQLiteConn) AuthUserChange(username, password string, admin bool) error {
isAdmin := 0 return ErrUnauthorized
if admin {
isAdmin = 1
}
rv := c.authUserChange(username, password, isAdmin)
switch rv {
case C.SQLITE_ERROR, C.SQLITE_AUTH:
return ErrAdminRequired
case C.SQLITE_OK:
return nil
default:
return c.lastError()
}
} }
// authUserChange allows to modify a user. // authUserChange allows to modify a user.
@@ -215,17 +118,7 @@ func (c *SQLiteConn) AuthUserChange(username, password string, admin bool) error
// C.SQLITE_ERROR (1) // C.SQLITE_ERROR (1)
// C.SQLITE_AUTH (23) // C.SQLITE_AUTH (23)
func (c *SQLiteConn) authUserChange(username, password string, admin int) int { func (c *SQLiteConn) authUserChange(username, password string, admin int) int {
// Allocate C Variables return 1
cuser := C.CString(username)
cpass := C.CString(password)
// Free C Variables
defer func() {
C.free(unsafe.Pointer(cuser))
C.free(unsafe.Pointer(cpass))
}()
return int(C._sqlite3_user_change(c.db, cuser, cpass, C.int(len(password)), C.int(admin)))
} }
// AuthUserDelete can be used (by an admin user only) // AuthUserDelete can be used (by an admin user only)
@@ -234,15 +127,7 @@ func (c *SQLiteConn) authUserChange(username, password string, admin int) int {
// the database cannot be converted into a no-authentication-required // the database cannot be converted into a no-authentication-required
// database. // database.
func (c *SQLiteConn) AuthUserDelete(username string) error { func (c *SQLiteConn) AuthUserDelete(username string) error {
rv := c.authUserDelete(username) return ErrUnauthorized
switch rv {
case C.SQLITE_ERROR, C.SQLITE_AUTH:
return ErrAdminRequired
case C.SQLITE_OK:
return nil
default:
return c.lastError()
}
} }
// authUserDelete can be used to delete a user. // authUserDelete can be used to delete a user.
@@ -258,25 +143,12 @@ func (c *SQLiteConn) AuthUserDelete(username string) error {
// C.SQLITE_ERROR (1) // C.SQLITE_ERROR (1)
// C.SQLITE_AUTH (23) // C.SQLITE_AUTH (23)
func (c *SQLiteConn) authUserDelete(username string) int { func (c *SQLiteConn) authUserDelete(username string) int {
// Allocate C Variables return 1
cuser := C.CString(username)
// Free C Variables
defer func() {
C.free(unsafe.Pointer(cuser))
}()
return int(C._sqlite3_user_delete(c.db, cuser))
} }
// AuthEnabled checks if the database is protected by user authentication // AuthEnabled checks if the database is protected by user authentication
func (c *SQLiteConn) AuthEnabled() (exists bool) { func (c *SQLiteConn) AuthEnabled() (exists bool) {
rv := c.authEnabled() return false
if rv == 1 {
exists = true
}
return
} }
// authEnabled perform the actual check for user authentication. // authEnabled perform the actual check for user authentication.
@@ -289,7 +161,7 @@ func (c *SQLiteConn) AuthEnabled() (exists bool) {
// 0 - Disabled // 0 - Disabled
// 1 - Enabled // 1 - Enabled
func (c *SQLiteConn) authEnabled() int { func (c *SQLiteConn) authEnabled() int {
return int(C._sqlite3_auth_enabled(c.db)) return 1
} }
// EOF // EOF