commit | e9cc517271fe60b4e729bda002509efe482d5901 | [log] [tgz] |
---|---|---|
author | Ed Tanous <edtanous@google.com> | Wed Nov 03 14:13:19 2021 +0800 |
committer | Ed Tanous <ed@tanous.net> | Mon Nov 15 22:10:04 2021 +0000 |
tree | 86a72ac71be16608091ab1c9dfad9287d2835035 | |
parent | 03913171c748202e81021ed2520362fd2877879b [diff] |
Redfish: Repair the wrong change made by non-admin In Redfish spec, the Operator and Readonly group should only change their own passwd using patch in ManagerAccount. (because of their ConfigureSelf privilege) But now they can even modify their RoleId in the code. https://www.dmtf.org/sites/default/files/standards/documents/DSP2046_2021.2.pdf Test: the 'xiao' is a Operator ~ curl -k -H "X-Auth-Token: $token" -X PATCH -d '{"RoleId":"ReadOnly"}' https://${bmc}/redfish/v1/AccountService/Accounts/xiao { "error": { "@Message.ExtendedInfo": [ { "@odata.type": "#Message.v1_1_1.Message", "Message": "There are insufficient privileges for the account or credentials associated with the current session to perform the requested operation.", "MessageArgs": [], "MessageId": "Base.1.8.1.InsufficientPrivilege", "MessageSeverity": "Critical", "Resolution": "Either abandon the operation or change the associated access rights and resubmit the request if the operation failed." } ], "code": "Base.1.8.1.InsufficientPrivilege", "message": "There are insufficient privileges for the account or credentials associated with the current session to perform the requested operation." } }% Signed-off-by: Xiaochao Ma <maxiaochao@inspur.com> Signed-off-by: Ed Tanous <edtanous@google.com> Change-Id: I9befcd94ee3a0b55f1ae7af38eb40e5f92fc3264
This component attempts to be a "do everything" embedded webserver for openbmc.
At this time, the webserver implements a few interfaces:
BMCWeb is configured by setting -D
flags that correspond to options in bmcweb/meson_options.txt
and then compiling. For example, meson <builddir> -Dkvm=disabled ...
followed by ninja
in build directory. The option names become C++ preprocessor symbols that control which code is compiled into the program.
meson builddir ninja -C builddir
meson builddir -Dbuildtype=minsize -Db_lto=true -Dtests=disabled ninja -C buildir
If any of the dependencies are not found on the host system during configuration, meson automatically gets them via its wrap dependencies mentioned in bmcweb/subprojects
.
meson builddir -Dwrap_mode=nofallback ninja -C builddir
meson builddir -Dbuildtype=debug ninja -C builddir
meson builddir -Db_coverage=true -Dtests=enabled ninja coverage -C builddir test
When BMCWeb starts running, it reads persistent configuration data (such as UUID and session data) from a local file. If this is not usable, it generates a new configuration.
When BMCWeb SSL support is enabled and a usable certificate is not found, it will generate a self-sign a certificate before launching the server. The keys are generated by the secp384r1
algorithm. The certificate
C=US, O=OpenBMC, CN=testhost
,SHA-256
algorithm.