Files
rustfs/crates/protocols/Cargo.toml
T
Zhengchao An 3c3113619e fix(protocols): use constant-time secret comparison in FTPS and WebDAV auth (#4403)
The FTPS and WebDAV authentication handlers compared the client-supplied secret
key against the stored secret with `String::eq`, which short-circuits on the
first differing byte. A network attacker who knows (or enumerates) a valid
access key can recover the secret key byte-by-byte via response-timing analysis;
neither path is rate limited.

Switch both to a constant-time comparison using `subtle::ConstantTimeEq`, the
same primitive the SFTP handler and `rustfs/src/auth.rs::constant_time_eq`
already use. `subtle` is added to the `ftps` and `webdav` feature dependency
sets (it was previously gated on `sftp` only).

Addresses GHSA-3p3x-734c-h5vx.
2026-07-08 09:31:51 +08:00

139 lines
4.7 KiB
TOML

# Copyright 2024 RustFS Team
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
[package]
name = "rustfs-protocols"
version.workspace = true
authors.workspace = true
edition.workspace = true
rust-version.workspace = true
license.workspace = true
repository.workspace = true
homepage.workspace = true
description = "Protocol implementations for RustFS (FTPS, SFTP, etc.)"
keywords = ["ftp", "sftp", "protocol", "storage", "rustfs"]
categories = ["network-programming", "filesystem"]
[features]
default = []
ftps = ["dep:libunftp", "dep:unftp-core", "dep:rustls", "dep:rustfs-tls-runtime", "dep:subtle"]
swift = [
"dep:rustfs-keystone",
"dep:rustfs-ecstore",
"dep:rustfs-rio",
"dep:axum",
"dep:http",
"dep:tower",
"dep:regex",
"dep:percent-encoding",
"dep:sha2",
"dep:uuid",
"dep:futures",
"dep:http-body-util",
"dep:tokio-util",
"dep:serde",
"dep:urlencoding",
"dep:md5",
"dep:quick-xml",
"dep:hmac",
"dep:sha1",
"dep:hex",
"dep:astral-tokio-tar",
"dep:base64",
"dep:async-compression",
]
webdav = ["dep:dav-server", "dep:hyper", "dep:hyper-util", "dep:http-body-util", "dep:tokio-rustls", "dep:base64", "dep:rustls", "dep:percent-encoding", "dep:rustfs-tls-runtime", "dep:subtle"]
sftp = ["dep:russh", "dep:russh-sftp", "dep:uuid", "dep:subtle", "dep:tokio-util", "dep:socket2"]
[dependencies]
# Core RustFS dependencies
rustfs-iam = { workspace = true }
rustfs-credentials = { workspace = true }
rustfs-policy = { workspace = true }
rustfs-utils = { workspace = true }
rustfs-config = { workspace = true }
rustfs-storage-api = { workspace = true }
rustfs-tls-runtime = { workspace = true, optional = true }
# Async dependencies
tokio = { workspace = true, features = ["fs", "io-util", "sync", "time"] }
tracing = { workspace = true }
futures-util = { workspace = true }
# Error handling
thiserror = { workspace = true }
# Serialization
serde_json = { workspace = true }
# Utilities
async-trait = { workspace = true }
time = { workspace = true }
bytes = { workspace = true }
# S3 API dependencies
s3s = { workspace = true }
# FTPS specific dependencies (optional)
libunftp = { workspace = true, optional = true }
unftp-core = { workspace = true, optional = true }
rustls = { workspace = true, optional = true }
# Swift specific dependencies (optional)
rustfs-keystone = { workspace = true, optional = true }
rustfs-ecstore = { workspace = true, optional = true }
rustfs-rio = { workspace = true, optional = true }
axum = { workspace = true, optional = true }
http = { workspace = true, optional = true }
tower = { workspace = true, optional = true }
regex = { workspace = true, optional = true }
percent-encoding = { workspace = true, optional = true }
sha2 = { workspace = true, optional = true }
uuid = { workspace = true, optional = true }
futures = { workspace = true, optional = true }
http-body-util = { workspace = true, optional = true }
tokio-util = { workspace = true, optional = true, features = ["rt"] }
serde = { workspace = true, optional = true }
urlencoding = { workspace = true, optional = true }
md5 = { workspace = true, optional = true }
quick-xml = { workspace = true, optional = true, features = ["serialize"] }
hmac = { workspace = true, optional = true }
sha1 = { workspace = true, optional = true }
hex = { workspace = true, optional = true }
astral-tokio-tar = { workspace = true, optional = true }
base64 = { workspace = true, optional = true }
async-compression = { workspace = true, optional = true, features = ["tokio", "gzip", "bzip2"] }
# WebDAV specific dependencies (optional)
dav-server = { workspace = true, optional = true }
hyper = { workspace = true, optional = true }
hyper-util = { workspace = true, optional = true }
tokio-rustls = { workspace = true, optional = true }
# SFTP specific dependencies (optional)
russh = { workspace = true, optional = true }
russh-sftp = { workspace = true, optional = true }
subtle = { workspace = true, optional = true }
socket2 = { workspace = true, optional = true }
[dev-dependencies]
tempfile = { workspace = true }
proptest = "1"
tracing-subscriber = { workspace = true }
tokio = { workspace = true, features = ["test-util", "macros", "rt"] }
[package.metadata.docs.rs]
all-features = true
rustdoc-args = ["--cfg", "docsrs"]