From 6ca5d517829587785df88ca7c9326adef577c11d Mon Sep 17 00:00:00 2001 From: Steve Lee Date: Thu, 12 Oct 2017 10:19:18 -0700 Subject: [PATCH] [feature] removed code to show a GUI prompt for credentials as PSCore6 prompts in console --- .../msh/ConsoleHostUserInterfacePrompt.cs | 31 +--- .../msh/ConsoleHostUserInterfaceSecurity.cs | 148 +++++------------- 2 files changed, 47 insertions(+), 132 deletions(-) diff --git a/src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHostUserInterfacePrompt.cs b/src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHostUserInterfacePrompt.cs index c740be6c61..71d178ac76 100644 --- a/src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHostUserInterfacePrompt.cs +++ b/src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHostUserInterfacePrompt.cs @@ -315,31 +315,12 @@ namespace Microsoft.PowerShell { WriteLineToConsole(WrapToCurrentWindowWidth(fieldPrompt)); PSCredential credential = null; - // the earlier implementation contained null - // for caption and message in the call below - // Passing null is a potential security risk - // as any modifications made with security in - // mind is lost. This can lead to a malicious - // server prompting the user for a request - // which can appear to come from locally. - if (!PromptUsingConsole() && desc.ModifiedByRemotingProtocol) - { - credential = - PromptForCredential( - caption, - message, - null, - string.Empty); - } - else - { - credential = - PromptForCredential( - null, // caption already written - null, // message already written - null, - string.Empty); - } + credential = + PromptForCredential( + null, // caption already written + null, // message already written + null, + string.Empty); convertedObj = credential; cancelInput = (convertedObj == null); if ((credential != null) && (credential.Password.Length == 0) && listInput) diff --git a/src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHostUserInterfaceSecurity.cs b/src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHostUserInterfaceSecurity.cs index 10e6cacfca..d4235985c3 100644 --- a/src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHostUserInterfaceSecurity.cs +++ b/src/Microsoft.PowerShell.ConsoleHost/host/msh/ConsoleHostUserInterfaceSecurity.cs @@ -78,127 +78,61 @@ namespace Microsoft.PowerShell PSCredentialTypes allowedCredentialTypes, PSCredentialUIOptions options) { - if (!PromptUsingConsole()) + PSCredential cred = null; + SecureString password = null; + string userPrompt = null; + string passwordPrompt = null; + + if (!string.IsNullOrEmpty(caption)) { - IntPtr mainWindowHandle = GetMainWindowHandle(); - return HostUtilities.CredUIPromptForCredential(caption, message, userName, targetName, allowedCredentialTypes, options, mainWindowHandle); - } - else - { - PSCredential cred = null; - SecureString password = null; - string userPrompt = null; - string passwordPrompt = null; + // Should be a skin lookup - if (!string.IsNullOrEmpty(caption)) - { - // Should be a skin lookup - - WriteLineToConsole(); - WriteToConsole(PromptColor, RawUI.BackgroundColor, WrapToCurrentWindowWidth(caption)); - WriteLineToConsole(); - } - - if (!string.IsNullOrEmpty(message)) - { - WriteLineToConsole(WrapToCurrentWindowWidth(message)); - } - - if (string.IsNullOrEmpty(userName)) - { - userPrompt = ConsoleHostUserInterfaceSecurityResources.PromptForCredential_User; - - // - // need to prompt for user name first - // - do - { - WriteToConsole(userPrompt, true); - userName = ReadLine(); - if (userName == null) - { - return null; - } - } - while (userName.Length == 0); - } - - passwordPrompt = StringUtil.Format(ConsoleHostUserInterfaceSecurityResources.PromptForCredential_Password, userName - ); - - // - // now, prompt for the password - // - WriteToConsole(passwordPrompt, true); - password = ReadLineAsSecureString(); - if (password == null) - { - return null; - } WriteLineToConsole(); - - cred = new PSCredential(userName, password); - - return cred; + WriteToConsole(PromptColor, RawUI.BackgroundColor, WrapToCurrentWindowWidth(caption)); + WriteLineToConsole(); } - } - private IntPtr GetMainWindowHandle() - { -#if CORECLR // No System.Diagnostics.Process.MainWindowHandle on CoreCLR; - // Returned WindowHandle is used only in 1 case - prompting for credential using GUI dialog, which is not used on Nano, - // because on Nano we prompt for credential using console (different code path in 'PromptForCredential' function) - return IntPtr.Zero; -#else - System.Diagnostics.Process currentProcess = System.Diagnostics.Process.GetCurrentProcess(); - IntPtr mainWindowHandle = currentProcess.MainWindowHandle; - - while ((mainWindowHandle == IntPtr.Zero) && (currentProcess != null)) + if (!string.IsNullOrEmpty(message)) { - currentProcess = PsUtils.GetParentProcess(currentProcess); - if (currentProcess != null) + WriteLineToConsole(WrapToCurrentWindowWidth(message)); + } + + if (string.IsNullOrEmpty(userName)) + { + userPrompt = ConsoleHostUserInterfaceSecurityResources.PromptForCredential_User; + + // + // need to prompt for user name first + // + do { - mainWindowHandle = currentProcess.MainWindowHandle; + WriteToConsole(userPrompt, true); + userName = ReadLine(); + if (userName == null) + { + return null; + } } + while (userName.Length == 0); } - return mainWindowHandle; -#endif - } + passwordPrompt = StringUtil.Format(ConsoleHostUserInterfaceSecurityResources.PromptForCredential_Password, userName + ); - // Determines whether we should prompt using the Console prompting - // APIs - private bool PromptUsingConsole() - { -#if CORECLR - // on Nano there is no other way to prompt except by using console - return true; -#else - bool promptUsingConsole = false; - // Get the configuration setting - try + // + // now, prompt for the password + // + WriteToConsole(passwordPrompt, true); + password = ReadLineAsSecureString(); + if (password == null) { - promptUsingConsole = ConfigPropertyAccessor.Instance.GetConsolePrompting(); - } - catch (System.Security.SecurityException e) - { - s_tracer.TraceError("Could not read CredUI registry key: " + e.Message); - return promptUsingConsole; - } - catch (InvalidCastException e) - { - s_tracer.TraceError("Could not parse CredUI registry key: " + e.Message); - return promptUsingConsole; - } - catch (FormatException e) - { - s_tracer.TraceError("Could not parse CredUI registry key: " + e.Message); - return promptUsingConsole; + return null; } + WriteLineToConsole(); - s_tracer.WriteLine("DetermineCredUIPolicy: policy == {0}", promptUsingConsole); - return promptUsingConsole; -#endif + cred = new PSCredential(userName, password); + + return cred; } } }