mirror of
https://github.com/go-gitea/gitea.git
synced 2026-03-12 02:24:21 -05:00
U2F not working with Gitea 1.10.3 #4775
Closed
opened 2025-11-02 06:02:32 -06:00 by GiteaMirror
·
9 comments
No Branch/Tag Specified
main
release/v1.25
release/v1.24
release/v1.23
release/v1.22
release/v1.21
release/v1.20
release/v1.19
release/v1.18
release/v1.17
release/v1.16
release/v1.15
release/v1.14
release/v1.13
release/v1.12
release/v1.11
release/v1.10
release/v1.9
release/v1.8
v1.25.3
v1.25.2
v1.25.1
v1.25.0
v1.24.7
v1.25.0-rc0
v1.26.0-dev
v1.24.6
v1.24.5
v1.24.4
v1.24.3
v1.24.2
v1.24.1
v1.24.0
v1.23.8
v1.24.0-rc0
v1.25.0-dev
v1.23.7
v1.23.6
v1.23.5
v1.23.4
v1.23.3
v1.23.2
v1.23.1
v1.23.0
v1.23.0-rc0
v1.24.0-dev
v1.22.6
v1.22.5
v1.22.4
v1.22.3
v1.22.2
v1.22.1
v1.22.0
v1.23.0-dev
v1.22.0-rc1
v1.21.11
v1.22.0-rc0
v1.21.10
v1.21.9
v1.21.8
v1.21.7
v1.21.6
v1.21.5
v1.21.4
v1.21.3
v1.21.2
v1.20.6
v1.21.1
v1.21.0
v1.21.0-rc2
v1.21.0-rc1
v1.20.5
v1.22.0-dev
v1.21.0-rc0
v1.20.4
v1.20.3
v1.20.2
v1.20.1
v1.20.0
v1.19.4
v1.21.0-dev
v1.20.0-rc2
v1.20.0-rc1
v1.20.0-rc0
v1.19.3
v1.19.2
v1.19.1
v1.19.0
v1.19.0-rc1
v1.20.0-dev
v1.19.0-rc0
v1.18.5
v1.18.4
v1.18.3
v1.18.2
v1.18.1
v1.18.0
v1.17.4
v1.18.0-rc1
v1.19.0-dev
v1.18.0-rc0
v1.17.3
v1.17.2
v1.17.1
v1.17.0
v1.17.0-rc2
v1.16.9
v1.17.0-rc1
v1.18.0-dev
v1.16.8
v1.16.7
v1.16.6
v1.16.5
v1.16.4
v1.16.3
v1.16.2
v1.16.1
v1.16.0
v1.15.11
v1.17.0-dev
v1.16.0-rc1
v1.15.10
v1.15.9
v1.15.8
v1.15.7
v1.15.6
v1.15.5
v1.15.4
v1.15.3
v1.15.2
v1.15.1
v1.14.7
v1.15.0
v1.15.0-rc3
v1.14.6
v1.15.0-rc2
v1.14.5
v1.16.0-dev
v1.15.0-rc1
v1.14.4
v1.14.3
v1.14.2
v1.14.1
v1.14.0
v1.13.7
v1.14.0-rc2
v1.13.6
v1.13.5
v1.14.0-rc1
v1.15.0-dev
v1.13.4
v1.13.3
v1.13.2
v1.13.1
v1.13.0
v1.12.6
v1.13.0-rc2
v1.14.0-dev
v1.13.0-rc1
v1.12.5
v1.12.4
v1.12.3
v1.12.2
v1.12.1
v1.11.8
v1.12.0
v1.11.7
v1.12.0-rc2
v1.11.6
v1.12.0-rc1
v1.13.0-dev
v1.11.5
v1.11.4
v1.11.3
v1.10.6
v1.12.0-dev
v1.11.2
v1.10.5
v1.11.1
v1.10.4
v1.11.0
v1.11.0-rc2
v1.10.3
v1.11.0-rc1
v1.10.2
v1.10.1
v1.10.0
v1.9.6
v1.9.5
v1.10.0-rc2
v1.11.0-dev
v1.10.0-rc1
v1.9.4
v1.9.3
v1.9.2
v1.9.1
v1.9.0
v1.9.0-rc2
v1.10.0-dev
v1.9.0-rc1
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.8.0-rc3
v1.7.6
v1.8.0-rc2
v1.7.5
v1.8.0-rc1
v1.9.0-dev
v1.7.4
v1.7.3
v1.7.2
v1.7.1
v1.7.0
v1.7.0-rc3
v1.6.4
v1.7.0-rc2
v1.6.3
v1.7.0-rc1
v1.7.0-dev
v1.6.2
v1.6.1
v1.6.0
v1.6.0-rc2
v1.5.3
v1.6.0-rc1
v1.6.0-dev
v1.5.2
v1.5.1
v1.5.0
v1.5.0-rc2
v1.5.0-rc1
v1.5.0-dev
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.4.0-rc3
v1.4.0-rc2
v1.3.3
v1.4.0-rc1
v1.3.2
v1.3.1
v1.3.0
v1.3.0-rc2
v1.3.0-rc1
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.2.0-rc3
v1.2.0-rc2
v1.1.4
v1.2.0-rc1
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.99
Labels
Clear labels
$20
$250
$50
$500
backport/done
💎 Bounty
docs-update-needed
good first issue
hacktoberfest
issue/bounty
issue/confirmed
issue/critical
issue/duplicate
issue/needs-feedback
issue/not-a-bug
issue/regression
issue/stale
issue/workaround
lgtm/need 2
modifies/api
modifies/translation
outdated/backport/v1.18
outdated/theme/markdown
outdated/theme/timetracker
performance/bigrepo
performance/cpu
performance/memory
performance/speed
pr/breaking
proposal/accepted
proposal/rejected
pr/wip
pull-request
reviewed/wontfix
💰 Rewarded
skip-changelog
status/blocked
topic/accessibility
topic/api
topic/authentication
topic/build
topic/code-linting
topic/commit-signing
topic/content-rendering
topic/deployment
topic/distribution
topic/federation
topic/gitea-actions
topic/issues
topic/lfs
topic/mobile
topic/moderation
topic/packages
topic/pr
topic/projects
topic/repo
topic/repo-migration
topic/security
topic/theme
topic/ui
topic/ui-interaction
topic/ux
topic/webhooks
topic/wiki
type/bug
type/deprecation
type/docs
type/enhancement
type/feature
type/miscellaneous
type/proposal
type/question
type/refactoring
type/summary
type/testing
type/upstream
Mirrored from GitHub Pull Request
No Label
type/question
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/gitea#4775
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @0x6d61726b on GitHub (Feb 2, 2020).
Gitea version 1.10.3 built with GNU Make 4.1, go1.13.6 : bindata, sqlite, sqlite_unlock_notify
git version 2.20.1
Linux test 4.19.0-6-amd64 #1 SMP Debian 4.19.67-2+deb10u2 (2019-11-11) x86_64 GNU/Linux
[x]):2020/02/02 16:35:00 ...ce/gracehttp/http.go:142:Serve() [I] Serving [::]:3000 with pid 12342020/02/02 16:35:05 .../xorm/session_raw.go:76:queryRows() [I] [SQL] SELECT 'id', 'lower_name', 'name', 'full_name', 'email', 'keep_email_private', 'email_notifications_preference', 'passwd', 'passwd_hash_algo', 'must_change_password', 'login_type', 'login_source', 'login_name', 'type', 'location', 'website', 'rands', 'salt', 'language', 'description', 'created_unix', 'updated_unix', 'last_login_unix', 'last_repo_visibility', 'max_repo_creation', 'is_active', 'is_admin', 'allow_git_hook', 'allow_import_local', 'allow_create_organization', 'prohibit_login', 'avatar', 'avatar_email', 'use_custom_avatar', 'num_followers', 'num_following', 'num_stars', 'num_repos', 'num_teams', 'num_members', 'visibility', 'repo_admin_change_team_access', 'diff_view_style', 'theme' FROM 'user' WHERE 'id'=? LIMIT 1 []interface {}{1} - took: 102.363µs2020/02/02 16:35:05 ...s/context/context.go:330:func1() [D] Session ID: 1bbce208aa01b2cd2020/02/02 16:35:05 ...s/context/context.go:331:func1() [D] CSRF Token: 0-lR0jNh25DGmwImY3X7u9qOYoA6MTU4MDY1MTIwMTc1MTY2MjU2OQ2020/02/02 16:35:05 .../xorm/session_raw.go:76:queryRows() [I] [SQL] SELECT count(*) FROM 'notification' WHERE (user_id = ?) AND (status = ?) []interface {}{1, 0x1} - took: 49.808µs2020/02/02 16:35:05 .../xorm/session_raw.go:76:queryRows() [I] [SQL] SELECT 'id', 'name', 'user_id', 'raw', 'counter', 'created_unix', 'updated_unix' FROM 'u2f_registration' WHERE (user_id = ?) []interface {}{1} - took: 29.496µsDescription
I tried to add a yubikey security key/token to gitea and got the error message "Could not read your security key.". I used both Firefox 72.0.2 and Chrome 79.0.3945.130 but was unable to add the security key.
I already searched documentation and issues, but was not yet able to find a solution.
What can I do for further debugging? Unfortunately, the log does not output any error message.
Screenshots
@lunny commented on GitHub (Feb 3, 2020):
Are you visiting a localhost? That will not work with U2F.
@0x6d61726b commented on GitHub (Feb 3, 2020):
Hi @lunny,
thanks for your hint. I use a dyndns service to resolv to the public IP address of my ISP (to which also the SSL certificate was issued to by letsencrypt) which today resolves to 93.220.xxx.xxx. However gitea runs on the virtual machine with the IP address 192.168.1.6. Traffic is forwarded from the ISP router to the virtual machine with NAT.
Here is the tcpdump file that was captured during the "add security key" procedure:
tcpdump: verbose output suppressed, use -v or -vv for full protocol decodelistening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes08:09:55.741008 IP 93.220.xxx.xxx.49866 > 192.168.1.6.3000: Flags [P.], seq 4280327037:4280327716, ack 1741328768, win 1025, length 67908:09:55.741041 IP 192.168.1.6.3000 > 93.220.xxx.xxx.49866: Flags [.], ack 679, win 716, length 008:09:55.745807 IP 192.168.1.6.3000 > 93.220.xxx.xxx.49866: Flags [P.], seq 1:336, ack 679, win 716, length 33508:09:55.790815 IP 93.220.xxx.xxx.49866 > 192.168.1.6.3000: Flags [.], ack 336, win 1024, length 008:09:59.951388 IP 93.220.xxx.xxx.49933 > 192.168.1.6.3000: Flags [.], seq 3126526437:3126526438, ack 1943948608, win 1025, length 108:09:59.951428 IP 192.168.1.6.3000 > 93.220.xxx.xxx.49933: Flags [.], ack 1, win 246, options [nop,nop,sack 1 {0:1}], length 008:09:59.963152 IP 93.220.xxx.xxx.49937 > 192.168.1.6.3000: Flags [.], seq 3555876064:3555876065, ack 1335527715, win 1024, length 108:09:59.963225 IP 192.168.1.6.3000 > 93.220.xxx.xxx.49937: Flags [.], ack 1, win 266, options [nop,nop,sack 1 {0:1}], length 008:09:59.963170 IP 93.220.xxx.xxx.49936 > 192.168.1.6.3000: Flags [.], seq 2695486276:2695486277, ack 2730822703, win 1025, length 108:09:59.963243 IP 192.168.1.6.3000 > 93.220.xxx.xxx.49936: Flags [.], ack 1, win 247, options [nop,nop,sack 1 {0:1}], length 008:09:59.982799 IP 93.220.xxx.xxx.49935 > 192.168.1.6.3000: Flags [.], seq 3937215492:3937215493, ack 2161389577, win 1025, length 108:09:59.982863 IP 192.168.1.6.3000 > 93.220.xxx.xxx.49935: Flags [.], ack 1, win 246, options [nop,nop,sack 1 {0:1}], length 008:10:00.077591 IP 93.220.xxx.xxx.49934 > 192.168.1.6.3000: Flags [.], seq 2568963727:2568963728, ack 1579807665, win 1023, length 108:10:00.077637 IP 192.168.1.6.3000 > 93.220.xxx.xxx.49934: Flags [.], ack 1, win 265, options [nop,nop,sack 1 {0:1}], length 014 packets captured14 packets received by filter0 packets dropped by kernelDo you think this is the problem?
@lunny commented on GitHub (Feb 3, 2020):
And could you have any js error on your chrome console?
@0x6d61726b commented on GitHub (Feb 3, 2020):
I did not find any errors neither in Chrome nor in Firefox. I did update to the pre-Release (v1.11.0-rc2) just to see if that eliminates the issue, but that wasn't the case. This is also the reason why the error message looks different now. In addition I again tried using registration/login on webauthn.io which worked fine.
Can I do anything else to track-down this issue?
The log file still does not contain any further hints.
@0x6d61726b commented on GitHub (Feb 4, 2020):
I did further debugging with Firefox console today (which I am more familiar with) and found out that I had an incorrect
ROOT_URLentry in app.ini telling the wrong protocol and no port.Incorrect setting:
After I changed the ROOT_URL the authentication worked as expected:
Maybe additional information can be added to the manual?
Thanks again for your support.
@zeripath commented on GitHub (Feb 5, 2020):
I don't understand why you've even set the ROOT_URL there. There's no need to set it - you've just set it to the default value.
The docs state:
You're not the only person I've seen do this but I still don't understand where it is coming from.
@zeripath commented on GitHub (Feb 5, 2020):
Anyway as this was a configuration issue I'm going to close this.
@0x6d61726b commented on GitHub (Feb 5, 2020):
What I was doing was running the installation wizard on
http://\<ip-adress\>:3000/installwhich created the app.ini file that contains contains the following values in the server section (with SSH disabled):The
ROOT_URLfield value is set by the installation wizard and seems to get the value from theGitea Base URL *(required) field.So maybe thats an explanation why I am not the only person with that kind of non-recommended configuration?
@lunny commented on GitHub (Feb 7, 2020):
@0x6d61726b That's a good workaround. Maybe we should add a hint on FAQ.