diff options
author | Pilou <pierre-louis.bonicoli@libregerbil.fr> | 2021-08-26 01:58:42 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2021-08-26 09:58:42 +1000 |
commit | 3d7f2a1366a8060f4f7e8a63bc7937a56c13bf82 (patch) | |
tree | d441609c9857372b66eafba050982374ba33b1d2 /lib/ansible/utils | |
parent | baa20fba2f0c48049416e09b2999f7f1fb0e7213 (diff) | |
download | ansible-3d7f2a1366a8060f4f7e8a63bc7937a56c13bf82.tar.gz |
Fix an exception when passlib library is used with a wrapped algo (#75527)
* Test a passlib wrapped algo with a password lookup
* Fix error when passlib is used with a wrapped algo
The exception was:
An unhandled exception occurred while running the lookup plugin 'password'.
Error was a <class 'TypeError'>, original message: issubclass() arg 1 must be a class
and can be reproduced using the following command:
ansible localhost -i localhost, -mdebug -amsg="{{ lookup('password', '/dev/null encrypt=ldap_sha512_crypt') }}"
The concerned algo are: bsd_nthash, django_argon2, django_bcrypt, ldap_bcrypt,
ldap_bsdi_crypt, ldap_des_crypt, ldap_hex_md5, ldap_hex_sha1, ldap_md5_crypt,
ldap_pbkdf2_sha1, ldap_pbkdf2_sha256, ldap_pbkdf2_sha512, ldap_sha1_crypt,
ldap_sha256_crypt, ldap_sha512_crypt, roundup_plaintext
Diffstat (limited to 'lib/ansible/utils')
-rw-r--r-- | lib/ansible/utils/encrypt.py | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/lib/ansible/utils/encrypt.py b/lib/ansible/utils/encrypt.py index 1579f779f9..7139084323 100644 --- a/lib/ansible/utils/encrypt.py +++ b/lib/ansible/utils/encrypt.py @@ -23,7 +23,7 @@ HAS_CRYPT = PASSLIB_AVAILABLE = False try: import passlib import passlib.hash - from passlib.utils.handlers import HasRawSalt + from passlib.utils.handlers import HasRawSalt, PrefixWrapper try: from passlib.utils.binary import bcrypt64 except ImportError: @@ -194,7 +194,7 @@ class PasslibHash(BaseHash): def _clean_salt(self, salt): if not salt: return None - elif issubclass(self.crypt_algo, HasRawSalt): + elif issubclass(self.crypt_algo.wrapped if isinstance(self.crypt_algo, PrefixWrapper) else self.crypt_algo, HasRawSalt): ret = to_bytes(salt, encoding='ascii', errors='strict') else: ret = to_text(salt, encoding='ascii', errors='strict') |