login: add optional field for ticket_info and make password optional

tickets created through the new HttpOnly ticket endpoint won't return
a ticket in the password field. so this field will be left empty.
hence make it optional.

the endpoint does return a ticket_info parameter, though, that
includes the information when a ticket needs to be refreshed. so add
a new optional field for that too.

Signed-off-by: Shannon Sterz <s.sterz@proxmox.com>
This commit is contained in:
Shannon Sterz 2025-03-04 15:42:36 +01:00 committed by Wolfgang Bumiller
parent 1b9def4736
commit 9c6d6b8d2a
2 changed files with 10 additions and 3 deletions

View File

@ -21,7 +21,8 @@ pub struct CreateTicket {
pub otp: Option<String>,
/// The secret password. This can also be a valid ticket.
pub password: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub password: Option<String>,
/// Verify ticket, and check if user have access 'privs' on 'path'
#[serde(default, skip_serializing_if = "Option::is_none")]
@ -61,6 +62,12 @@ pub struct CreateTicketResponse {
#[serde(default, skip_serializing_if = "Option::is_none")]
pub ticket: Option<String>,
/// A purely informational ticket that can be used to gather information about when the actual
/// ticket needs to be refreshed.
#[serde(default, skip_serializing_if = "Option::is_none")]
#[serde(rename = "ticket-info")]
pub ticket_info: Option<String>,
/// The full userid with the `@realm` part.
pub username: String,
}

View File

@ -129,7 +129,7 @@ impl Login {
let request = api::CreateTicket {
new_format: self.pve_compat.then_some(true),
username: self.userid.clone(),
password: self.password.clone(),
password: Some(self.password.clone()),
..Default::default()
};
@ -279,7 +279,7 @@ impl SecondFactorChallenge {
let request = api::CreateTicket {
new_format: self.pve_compat.then_some(true),
username: self.userid.clone(),
password: data.to_string(),
password: Some(data.to_string()),
tfa_challenge: Some(self.ticket.clone()),
..Default::default()
};