auth.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483
  1. package auth
  2. /*
  3. author: tobychui
  4. */
  5. import (
  6. "crypto/rand"
  7. "crypto/sha512"
  8. "errors"
  9. "net/http"
  10. "net/mail"
  11. "strings"
  12. "encoding/hex"
  13. "github.com/gorilla/sessions"
  14. db "imuslab.com/zoraxy/mod/database"
  15. "imuslab.com/zoraxy/mod/info/logger"
  16. "imuslab.com/zoraxy/mod/utils"
  17. )
  18. type AuthAgent struct {
  19. //Session related
  20. SessionName string
  21. SessionStore *sessions.CookieStore
  22. Database *db.Database
  23. LoginRedirectionHandler func(http.ResponseWriter, *http.Request)
  24. Logger *logger.Logger
  25. }
  26. type AuthEndpoints struct {
  27. Login string
  28. Logout string
  29. Register string
  30. CheckLoggedIn string
  31. Autologin string
  32. }
  33. // Constructor
  34. func NewAuthenticationAgent(sessionName string, key []byte, sysdb *db.Database, allowReg bool, logger *logger.Logger, loginRedirectionHandler func(http.ResponseWriter, *http.Request)) *AuthAgent {
  35. store := sessions.NewCookieStore(key)
  36. err := sysdb.NewTable("auth")
  37. if err != nil {
  38. logger.Println("Failed to create auth database. Terminating.")
  39. panic(err)
  40. }
  41. //Create a new AuthAgent object
  42. newAuthAgent := AuthAgent{
  43. SessionName: sessionName,
  44. SessionStore: store,
  45. Database: sysdb,
  46. LoginRedirectionHandler: loginRedirectionHandler,
  47. }
  48. //Return the authAgent
  49. return &newAuthAgent
  50. }
  51. func GetSessionKey(sysdb *db.Database, logger *logger.Logger) (string, error) {
  52. sysdb.NewTable("auth")
  53. sessionKey := ""
  54. if !sysdb.KeyExists("auth", "sessionkey") {
  55. key := make([]byte, 32)
  56. rand.Read(key)
  57. sessionKey = string(key)
  58. sysdb.Write("auth", "sessionkey", sessionKey)
  59. logger.PrintAndLog("auth", "New authentication session key generated", nil)
  60. } else {
  61. logger.PrintAndLog("auth", "Authentication session key loaded from database", nil)
  62. err := sysdb.Read("auth", "sessionkey", &sessionKey)
  63. if err != nil {
  64. return "", errors.New("database read error. Is the database file corrupted?")
  65. }
  66. }
  67. return sessionKey, nil
  68. }
  69. // This function will handle an http request and redirect to the given login address if not logged in
  70. func (a *AuthAgent) HandleCheckAuth(w http.ResponseWriter, r *http.Request, handler func(http.ResponseWriter, *http.Request)) {
  71. if a.CheckAuth(r) {
  72. //User already logged in
  73. handler(w, r)
  74. } else {
  75. //User not logged in
  76. a.LoginRedirectionHandler(w, r)
  77. }
  78. }
  79. // Handle login request, require POST username and password
  80. func (a *AuthAgent) HandleLogin(w http.ResponseWriter, r *http.Request) {
  81. //Get username from request using POST mode
  82. username, err := utils.PostPara(r, "username")
  83. if err != nil {
  84. //Username not defined
  85. a.Logger.PrintAndLog("auth", r.RemoteAddr+" trying to login with username: "+username, nil)
  86. utils.SendErrorResponse(w, "Username not defined or empty.")
  87. return
  88. }
  89. //Get password from request using POST mode
  90. password, err := utils.PostPara(r, "password")
  91. if err != nil {
  92. //Password not defined
  93. utils.SendErrorResponse(w, "Password not defined or empty.")
  94. return
  95. }
  96. //Get rememberme settings
  97. rememberme := false
  98. rmbme, _ := utils.PostPara(r, "rmbme")
  99. if rmbme == "true" {
  100. rememberme = true
  101. }
  102. //Check the database and see if this user is in the database
  103. passwordCorrect, rejectionReason := a.ValidateUsernameAndPasswordWithReason(username, password)
  104. //The database contain this user information. Check its password if it is correct
  105. if passwordCorrect {
  106. //Password correct
  107. // Set user as authenticated
  108. a.LoginUserByRequest(w, r, username, rememberme)
  109. //Print the login message to console
  110. a.Logger.PrintAndLog("auth", username+" logged in.", nil)
  111. utils.SendOK(w)
  112. } else {
  113. //Password incorrect
  114. a.Logger.PrintAndLog("auth", username+" login request rejected: "+rejectionReason, nil)
  115. utils.SendErrorResponse(w, rejectionReason)
  116. return
  117. }
  118. }
  119. func (a *AuthAgent) ValidateUsernameAndPassword(username string, password string) bool {
  120. succ, _ := a.ValidateUsernameAndPasswordWithReason(username, password)
  121. return succ
  122. }
  123. // validate the username and password, return reasons if the auth failed
  124. func (a *AuthAgent) ValidateUsernameAndPasswordWithReason(username string, password string) (bool, string) {
  125. hashedPassword := Hash(password)
  126. var passwordInDB string
  127. err := a.Database.Read("auth", "passhash/"+username, &passwordInDB)
  128. if err != nil {
  129. //User not found or db exception
  130. a.Logger.PrintAndLog("auth", username+" login with incorrect password", nil)
  131. return false, "Invalid username or password"
  132. }
  133. if passwordInDB == hashedPassword {
  134. return true, ""
  135. } else {
  136. return false, "Invalid username or password"
  137. }
  138. }
  139. // Login the user by creating a valid session for this user
  140. func (a *AuthAgent) LoginUserByRequest(w http.ResponseWriter, r *http.Request, username string, rememberme bool) {
  141. session, _ := a.SessionStore.Get(r, a.SessionName)
  142. session.Values["authenticated"] = true
  143. session.Values["username"] = username
  144. session.Values["rememberMe"] = rememberme
  145. //Check if remember me is clicked. If yes, set the maxage to 1 week.
  146. if rememberme {
  147. session.Options = &sessions.Options{
  148. MaxAge: 3600 * 24 * 7, //One week
  149. Path: "/",
  150. }
  151. } else {
  152. session.Options = &sessions.Options{
  153. MaxAge: 3600 * 1, //One hour
  154. Path: "/",
  155. }
  156. }
  157. session.Save(r, w)
  158. }
  159. // Handle logout, reply OK after logged out. WILL NOT DO REDIRECTION
  160. func (a *AuthAgent) HandleLogout(w http.ResponseWriter, r *http.Request) {
  161. username, err := a.GetUserName(w, r)
  162. if err != nil {
  163. utils.SendErrorResponse(w, "user not logged in")
  164. return
  165. }
  166. if username != "" {
  167. a.Logger.PrintAndLog("auth", username+" logged out", nil)
  168. }
  169. // Revoke users authentication
  170. err = a.Logout(w, r)
  171. if err != nil {
  172. utils.SendErrorResponse(w, "Logout failed")
  173. return
  174. }
  175. utils.SendOK(w)
  176. }
  177. func (a *AuthAgent) Logout(w http.ResponseWriter, r *http.Request) error {
  178. session, err := a.SessionStore.Get(r, a.SessionName)
  179. if err != nil {
  180. return err
  181. }
  182. session.Values["authenticated"] = false
  183. session.Values["username"] = nil
  184. session.Save(r, w)
  185. return nil
  186. }
  187. // Get the current session username from request
  188. func (a *AuthAgent) GetUserName(w http.ResponseWriter, r *http.Request) (string, error) {
  189. if a.CheckAuth(r) {
  190. //This user has logged in.
  191. session, _ := a.SessionStore.Get(r, a.SessionName)
  192. return session.Values["username"].(string), nil
  193. } else {
  194. //This user has not logged in.
  195. return "", errors.New("user not logged in")
  196. }
  197. }
  198. // Get the current session user email from request
  199. func (a *AuthAgent) GetUserEmail(w http.ResponseWriter, r *http.Request) (string, error) {
  200. if a.CheckAuth(r) {
  201. //This user has logged in.
  202. session, _ := a.SessionStore.Get(r, a.SessionName)
  203. username := session.Values["username"].(string)
  204. userEmail := ""
  205. err := a.Database.Read("auth", "email/"+username, &userEmail)
  206. if err != nil {
  207. return "", err
  208. }
  209. return userEmail, nil
  210. } else {
  211. //This user has not logged in.
  212. return "", errors.New("user not logged in")
  213. }
  214. }
  215. // Check if the user has logged in, return true / false in JSON
  216. func (a *AuthAgent) CheckLogin(w http.ResponseWriter, r *http.Request) {
  217. if a.CheckAuth(r) {
  218. utils.SendJSONResponse(w, "true")
  219. } else {
  220. utils.SendJSONResponse(w, "false")
  221. }
  222. }
  223. // Handle new user register. Require POST username, password, group.
  224. func (a *AuthAgent) HandleRegister(w http.ResponseWriter, r *http.Request, callback func(string, string)) {
  225. //Get username from request
  226. newusername, err := utils.PostPara(r, "username")
  227. if err != nil {
  228. utils.SendErrorResponse(w, "Missing 'username' paramter")
  229. return
  230. }
  231. //Get password from request
  232. password, err := utils.PostPara(r, "password")
  233. if err != nil {
  234. utils.SendErrorResponse(w, "Missing 'password' paramter")
  235. return
  236. }
  237. //Get email from request
  238. email, err := utils.PostPara(r, "email")
  239. if err != nil {
  240. utils.SendErrorResponse(w, "Missing 'email' paramter")
  241. return
  242. }
  243. _, err = mail.ParseAddress(email)
  244. if err != nil {
  245. utils.SendErrorResponse(w, "Invalid or malformed email")
  246. return
  247. }
  248. //Ok to proceed create this user
  249. err = a.CreateUserAccount(newusername, password, email)
  250. if err != nil {
  251. utils.SendErrorResponse(w, err.Error())
  252. return
  253. }
  254. //Do callback if exists
  255. if callback != nil {
  256. callback(newusername, email)
  257. }
  258. //Return to the client with OK
  259. utils.SendOK(w)
  260. a.Logger.PrintAndLog("auth", "New user "+newusername+" added to system.", nil)
  261. }
  262. // Handle new user register without confirmation email. Require POST username, password, group.
  263. func (a *AuthAgent) HandleRegisterWithoutEmail(w http.ResponseWriter, r *http.Request, callback func(string, string)) {
  264. //Get username from request
  265. newusername, err := utils.PostPara(r, "username")
  266. if err != nil {
  267. utils.SendErrorResponse(w, "Missing 'username' paramter")
  268. return
  269. }
  270. //Get password from request
  271. password, err := utils.PostPara(r, "password")
  272. if err != nil {
  273. utils.SendErrorResponse(w, "Missing 'password' paramter")
  274. return
  275. }
  276. //Ok to proceed create this user
  277. err = a.CreateUserAccount(newusername, password, "")
  278. if err != nil {
  279. utils.SendErrorResponse(w, err.Error())
  280. return
  281. }
  282. //Do callback if exists
  283. if callback != nil {
  284. callback(newusername, "")
  285. }
  286. //Return to the client with OK
  287. utils.SendOK(w)
  288. a.Logger.PrintAndLog("auth", "Admin account created: "+newusername, nil)
  289. }
  290. // Check authentication from request header's session value
  291. func (a *AuthAgent) CheckAuth(r *http.Request) bool {
  292. session, err := a.SessionStore.Get(r, a.SessionName)
  293. if err != nil {
  294. return false
  295. }
  296. // Check if user is authenticated
  297. if auth, ok := session.Values["authenticated"].(bool); !ok || !auth {
  298. return false
  299. }
  300. return true
  301. }
  302. // Handle de-register of users. Require POST username.
  303. // THIS FUNCTION WILL NOT CHECK FOR PERMISSION. PLEASE USE WITH PERMISSION HANDLER
  304. func (a *AuthAgent) HandleUnregister(w http.ResponseWriter, r *http.Request) {
  305. //Check if the user is logged in
  306. if !a.CheckAuth(r) {
  307. //This user has not logged in
  308. utils.SendErrorResponse(w, "Login required to remove user from the system.")
  309. return
  310. }
  311. //Get username from request
  312. username, err := utils.PostPara(r, "username")
  313. if err != nil {
  314. utils.SendErrorResponse(w, "Missing 'username' paramter")
  315. return
  316. }
  317. err = a.UnregisterUser(username)
  318. if err != nil {
  319. utils.SendErrorResponse(w, err.Error())
  320. return
  321. }
  322. //Return to the client with OK
  323. utils.SendOK(w)
  324. a.Logger.PrintAndLog("auth", "User "+username+" has been removed from the system", nil)
  325. }
  326. func (a *AuthAgent) UnregisterUser(username string) error {
  327. //Check if the user exists in the system database.
  328. if !a.Database.KeyExists("auth", "passhash/"+username) {
  329. //This user do not exists.
  330. return errors.New("this user does not exists")
  331. }
  332. //OK! Remove the user from the database
  333. a.Database.Delete("auth", "passhash/"+username)
  334. a.Database.Delete("auth", "email/"+username)
  335. return nil
  336. }
  337. // Get the number of users in the system
  338. func (a *AuthAgent) GetUserCounts() int {
  339. entries, _ := a.Database.ListTable("auth")
  340. usercount := 0
  341. for _, keypairs := range entries {
  342. if strings.Contains(string(keypairs[0]), "passhash/") {
  343. //This is a user registry
  344. usercount++
  345. }
  346. }
  347. if usercount == 0 {
  348. a.Logger.PrintAndLog("auth", "There are no user in the database", nil)
  349. }
  350. return usercount
  351. }
  352. // List all username within the system
  353. func (a *AuthAgent) ListUsers() []string {
  354. entries, _ := a.Database.ListTable("auth")
  355. results := []string{}
  356. for _, keypairs := range entries {
  357. if strings.Contains(string(keypairs[0]), "passhash/") {
  358. username := strings.Split(string(keypairs[0]), "/")[1]
  359. results = append(results, username)
  360. }
  361. }
  362. return results
  363. }
  364. // Check if the given username exists
  365. func (a *AuthAgent) UserExists(username string) bool {
  366. userpasswordhash := ""
  367. err := a.Database.Read("auth", "passhash/"+username, &userpasswordhash)
  368. if err != nil || userpasswordhash == "" {
  369. return false
  370. }
  371. return true
  372. }
  373. // Update the session expire time given the request header.
  374. func (a *AuthAgent) UpdateSessionExpireTime(w http.ResponseWriter, r *http.Request) bool {
  375. session, _ := a.SessionStore.Get(r, a.SessionName)
  376. if session.Values["authenticated"].(bool) {
  377. //User authenticated. Extend its expire time
  378. rememberme := session.Values["rememberMe"].(bool)
  379. //Extend the session expire time
  380. if rememberme {
  381. session.Options = &sessions.Options{
  382. MaxAge: 3600 * 24 * 7, //One week
  383. Path: "/",
  384. }
  385. } else {
  386. session.Options = &sessions.Options{
  387. MaxAge: 3600 * 1, //One hour
  388. Path: "/",
  389. }
  390. }
  391. session.Save(r, w)
  392. return true
  393. } else {
  394. return false
  395. }
  396. }
  397. // Create user account
  398. func (a *AuthAgent) CreateUserAccount(newusername string, password string, email string) error {
  399. //Check user already exists
  400. if a.UserExists(newusername) {
  401. return errors.New("user with same name already exists")
  402. }
  403. key := newusername
  404. hashedPassword := Hash(password)
  405. err := a.Database.Write("auth", "passhash/"+key, hashedPassword)
  406. if err != nil {
  407. return err
  408. }
  409. if email != "" {
  410. err = a.Database.Write("auth", "email/"+key, email)
  411. if err != nil {
  412. return err
  413. }
  414. }
  415. return nil
  416. }
  417. // Hash the given raw string into sha512 hash
  418. func Hash(raw string) string {
  419. h := sha512.New()
  420. h.Write([]byte(raw))
  421. return hex.EncodeToString(h.Sum(nil))
  422. }