]> dgit.raspbian.org Git - nextcloud-desktop.git/commitdiff
Forbid trusting the untrusted certificate.
authoralex-z <blackslayer4@gmail.com>
Tue, 26 Oct 2021 11:27:22 +0000 (14:27 +0300)
committerallexzander (Rebase PR Action) <allexzander@users.noreply.github.com>
Wed, 27 Oct 2021 07:23:42 +0000 (07:23 +0000)
Signed-off-by: alex-z <blackslayer4@gmail.com>
NEXTCLOUD.cmake
config.h.in
src/gui/sslerrordialog.cpp
src/libsync/theme.cpp
src/libsync/theme.h

index 11f43aa1dbdc9055680b552facca3847ab17c487..ce246e8e8899ab0c77d8ebfb8c8dd05fae68c0b9 100644 (file)
@@ -12,6 +12,7 @@ set( APPLICATION_SERVER_URL_ENFORCE ON ) # If set and APPLICATION_SERVER_URL is
 set( APPLICATION_REV_DOMAIN "com.nextcloud.desktopclient" )
 set( APPLICATION_VIRTUALFILE_SUFFIX "nextcloud" CACHE STRING "Virtual file suffix (not including the .)")
 set( APPLICATION_OCSP_STAPLING_ENABLED OFF )
+set( APPLICATION_FORBID_BAD_SSL OFF )
 
 set( LINUX_PACKAGE_SHORTNAME "nextcloud" )
 set( LINUX_APPLICATION_ID "${APPLICATION_REV_DOMAIN}.${LINUX_PACKAGE_SHORTNAME}")
index 48236399c43df13f20ad3ef5970af04ee4f60021..1c7d921cd7ef114fa8a3f145aa687fdaf768cd41 100644 (file)
@@ -30,6 +30,7 @@
 #cmakedefine APPLICATION_WIZARD_USE_CUSTOM_LOGO "@APPLICATION_WIZARD_USE_CUSTOM_LOGO@"
 #cmakedefine APPLICATION_VIRTUALFILE_SUFFIX "@APPLICATION_VIRTUALFILE_SUFFIX@"
 #cmakedefine APPLICATION_OCSP_STAPLING_ENABLED "@APPLICATION_OCSP_STAPLING_ENABLED@"
+#cmakedefine APPLICATION_FORBID_BAD_SSL "@APPLICATION_FORBID_BAD_SSL@"
 #define APPLICATION_DOTVIRTUALFILE_SUFFIX "." APPLICATION_VIRTUALFILE_SUFFIX
 
 #cmakedefine ZLIB_FOUND @ZLIB_FOUND@
index 429f29b323c8bf2dab085f468588dccf4e8b5937..7b97a657a6c01dec0d26e94b09f0db54a01549de 100644 (file)
@@ -13,6 +13,7 @@
  */
 #include "configfile.h"
 #include "sslerrordialog.h"
+#include "theme.h"
 
 #include <QtGui>
 #include <QtNetwork>
@@ -68,6 +69,8 @@ SslErrorDialog::SslErrorDialog(AccountPtr account, QWidget *parent)
     QPushButton *cancelButton =
         _ui->_dialogButtonBox->button(QDialogButtonBox::Cancel);
     okButton->setEnabled(false);
+
+    _ui->_cbTrustConnect->setEnabled(!Theme::instance()->forbidBadSSL());
     connect(_ui->_cbTrustConnect, &QAbstractButton::clicked,
         okButton, &QWidget::setEnabled);
 
@@ -136,7 +139,6 @@ bool SslErrorDialog::checkFailingCertsKnown(const QList<QSslError> &errors)
     msg += QL("<h3>") + tr("Cannot connect securely to <i>%1</i>:").arg(host) + QL("</h3>");
     // loop over the unknown certs and line up their errors.
     msg += QL("<div id=\"ca_errors\">");
-
     foreach (const QSslCertificate &cert, _unknownCerts) {
         msg += QL("<div id=\"ca_error\">");
         // add the errors for this cert
@@ -153,7 +155,7 @@ bool SslErrorDialog::checkFailingCertsKnown(const QList<QSslError> &errors)
     }
 
     if (!additionalErrorStrings.isEmpty()) {
-        msg += QL("<h3>") + tr("Additional errors:") + QL("</h3>");
+        msg += QL("<h4>") + tr("Additional errors:") + QL("</h4>");
 
         for (const auto &errorString : additionalErrorStrings) {
             msg += QL("<div id=\"ca_error\">");
index 37eb4568a0ba4a506af4fb0e05ac32bd8f8ab290..8fd5b1a3fc808f8058bfbfc54041b42fd6d33ae2 100644 (file)
@@ -408,6 +408,15 @@ bool Theme::enableStaplingOCSP() const
 #endif
 }
 
+bool Theme::forbidBadSSL() const
+{
+#ifdef APPLICATION_FORBID_BAD_SSL
+    return true;
+#else
+    return false;
+#endif
+}
+
 QString Theme::forceConfigAuthType() const
 {
     return QString();
index 29db46414752b48cf3beaf74d457890c0180c529..f07c0de4a88a28d2a860ba46a915c6d4cd79b04d 100644 (file)
@@ -247,6 +247,13 @@ public:
      */
     virtual bool enableStaplingOCSP() const;
 
+    /**
+     * Enforce SSL validity
+     *
+     * When true, trusting the untrusted certificate is not allowed
+     */
+    virtual bool forbidBadSSL() const;
+
     /**
      * This is only usefull when previous version had a different overrideServerUrl
      * with a different auth type in that case You should then specify "http" or "shibboleth".