BruteForceThrottler.php 2.4 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374
  1. <?php
  2. declare(strict_types=1);
  3. /**
  4. * @copyright Copyright (c) 2023 Côme Chilliet <come.chilliet@nextcloud.com>
  5. *
  6. * @author Côme Chilliet <come.chilliet@nextcloud.com>
  7. *
  8. * @license GNU AGPL version 3 or any later version
  9. *
  10. * This program is free software: you can redistribute it and/or modify
  11. * it under the terms of the GNU Affero General Public License as
  12. * published by the Free Software Foundation, either version 3 of the
  13. * License, or (at your option) any later version.
  14. *
  15. * This program is distributed in the hope that it will be useful,
  16. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  17. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  18. * GNU Affero General Public License for more details.
  19. *
  20. * You should have received a copy of the GNU Affero General Public License
  21. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  22. *
  23. */
  24. namespace OCA\Settings\SetupChecks;
  25. use OCP\IL10N;
  26. use OCP\IRequest;
  27. use OCP\IURLGenerator;
  28. use OCP\Security\Bruteforce\IThrottler;
  29. use OCP\SetupCheck\ISetupCheck;
  30. use OCP\SetupCheck\SetupResult;
  31. class BruteForceThrottler implements ISetupCheck {
  32. public function __construct(
  33. private IL10N $l10n,
  34. private IURLGenerator $urlGenerator,
  35. private IRequest $request,
  36. private IThrottler $throttler,
  37. ) {
  38. }
  39. public function getCategory(): string {
  40. return 'system';
  41. }
  42. public function getName(): string {
  43. return $this->l10n->t('Brute-force Throttle');
  44. }
  45. public function run(): SetupResult {
  46. $address = $this->request->getRemoteAddress();
  47. if ($address === '') {
  48. if (\OC::$CLI) {
  49. /* We were called from CLI */
  50. return SetupResult::info($this->l10n->t('Your remote address could not be determined.'));
  51. } else {
  52. /* Should never happen */
  53. return SetupResult::error($this->l10n->t('Your remote address could not be determined.'));
  54. }
  55. } elseif ($this->throttler->showBruteforceWarning($address)) {
  56. return SetupResult::error(
  57. $this->l10n->t('Your remote address was identified as "%s" and is brute-force throttled at the moment slowing down the performance of various requests. If the remote address is not your address this can be an indication that a proxy is not configured correctly.', [$address]),
  58. $this->urlGenerator->linkToDocs('admin-reverse-proxy')
  59. );
  60. } else {
  61. return SetupResult::success(
  62. $this->l10n->t('Your remote address "%s" is not brute-force throttled.', [$address])
  63. );
  64. }
  65. }
  66. }