1
0

auth.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485
  1. package auth
  2. /*
  3. author: tobychui
  4. */
  5. import (
  6. "crypto/rand"
  7. "crypto/sha512"
  8. "errors"
  9. "net/http"
  10. "net/mail"
  11. "strings"
  12. "encoding/hex"
  13. "github.com/gorilla/sessions"
  14. db "imuslab.com/zoraxy/mod/database"
  15. "imuslab.com/zoraxy/mod/info/logger"
  16. "imuslab.com/zoraxy/mod/utils"
  17. )
  18. type AuthAgent struct {
  19. //Session related
  20. SessionName string
  21. SessionStore *sessions.CookieStore
  22. Database *db.Database
  23. LoginRedirectionHandler func(http.ResponseWriter, *http.Request)
  24. Logger *logger.Logger
  25. }
  26. type AuthEndpoints struct {
  27. Login string
  28. Logout string
  29. Register string
  30. CheckLoggedIn string
  31. Autologin string
  32. }
  33. // Constructor
  34. func NewAuthenticationAgent(sessionName string, key []byte, sysdb *db.Database, allowReg bool, systemLogger *logger.Logger, loginRedirectionHandler func(http.ResponseWriter, *http.Request)) *AuthAgent {
  35. store := sessions.NewCookieStore(key)
  36. err := sysdb.NewTable("auth")
  37. if err != nil {
  38. systemLogger.Println("Failed to create auth database. Terminating.")
  39. panic(err)
  40. }
  41. //Create a new AuthAgent object
  42. newAuthAgent := AuthAgent{
  43. SessionName: sessionName,
  44. SessionStore: store,
  45. Database: sysdb,
  46. LoginRedirectionHandler: loginRedirectionHandler,
  47. Logger: systemLogger,
  48. }
  49. //Return the authAgent
  50. return &newAuthAgent
  51. }
  52. func GetSessionKey(sysdb *db.Database, logger *logger.Logger) (string, error) {
  53. sysdb.NewTable("auth")
  54. sessionKey := ""
  55. if !sysdb.KeyExists("auth", "sessionkey") {
  56. key := make([]byte, 32)
  57. rand.Read(key)
  58. sessionKey = string(key)
  59. sysdb.Write("auth", "sessionkey", sessionKey)
  60. logger.PrintAndLog("auth", "New authentication session key generated", nil)
  61. } else {
  62. logger.PrintAndLog("auth", "Authentication session key loaded from database", nil)
  63. err := sysdb.Read("auth", "sessionkey", &sessionKey)
  64. if err != nil {
  65. return "", errors.New("database read error. Is the database file corrupted?")
  66. }
  67. }
  68. return sessionKey, nil
  69. }
  70. // This function will handle an http request and redirect to the given login address if not logged in
  71. func (a *AuthAgent) HandleCheckAuth(w http.ResponseWriter, r *http.Request, handler func(http.ResponseWriter, *http.Request)) {
  72. if a.CheckAuth(r) {
  73. //User already logged in
  74. handler(w, r)
  75. } else {
  76. //User not logged in
  77. a.LoginRedirectionHandler(w, r)
  78. }
  79. }
  80. // Handle login request, require POST username and password
  81. func (a *AuthAgent) HandleLogin(w http.ResponseWriter, r *http.Request) {
  82. //Get username from request using POST mode
  83. username, err := utils.PostPara(r, "username")
  84. if err != nil {
  85. //Username not defined
  86. a.Logger.PrintAndLog("auth", r.RemoteAddr+" trying to login with username: "+username, nil)
  87. utils.SendErrorResponse(w, "Username not defined or empty.")
  88. return
  89. }
  90. //Get password from request using POST mode
  91. password, err := utils.PostPara(r, "password")
  92. if err != nil {
  93. //Password not defined
  94. utils.SendErrorResponse(w, "Password not defined or empty.")
  95. return
  96. }
  97. //Get rememberme settings
  98. rememberme := false
  99. rmbme, _ := utils.PostPara(r, "rmbme")
  100. if rmbme == "true" {
  101. rememberme = true
  102. }
  103. //Check the database and see if this user is in the database
  104. passwordCorrect, rejectionReason := a.ValidateUsernameAndPasswordWithReason(username, password)
  105. //The database contain this user information. Check its password if it is correct
  106. if passwordCorrect {
  107. //Password correct
  108. // Set user as authenticated
  109. a.LoginUserByRequest(w, r, username, rememberme)
  110. //Print the login message to console
  111. a.Logger.PrintAndLog("auth", username+" logged in.", nil)
  112. utils.SendOK(w)
  113. } else {
  114. //Password incorrect
  115. a.Logger.PrintAndLog("auth", username+" login request rejected: "+rejectionReason, nil)
  116. utils.SendErrorResponse(w, rejectionReason)
  117. return
  118. }
  119. }
  120. func (a *AuthAgent) ValidateUsernameAndPassword(username string, password string) bool {
  121. succ, _ := a.ValidateUsernameAndPasswordWithReason(username, password)
  122. return succ
  123. }
  124. // validate the username and password, return reasons if the auth failed
  125. func (a *AuthAgent) ValidateUsernameAndPasswordWithReason(username string, password string) (bool, string) {
  126. hashedPassword := Hash(password)
  127. var passwordInDB string
  128. err := a.Database.Read("auth", "passhash/"+username, &passwordInDB)
  129. if err != nil {
  130. //User not found or db exception
  131. a.Logger.PrintAndLog("auth", username+" login with incorrect password", nil)
  132. return false, "Invalid username or password"
  133. }
  134. if passwordInDB == hashedPassword {
  135. return true, ""
  136. } else {
  137. return false, "Invalid username or password"
  138. }
  139. }
  140. // Login the user by creating a valid session for this user
  141. func (a *AuthAgent) LoginUserByRequest(w http.ResponseWriter, r *http.Request, username string, rememberme bool) {
  142. session, _ := a.SessionStore.Get(r, a.SessionName)
  143. session.Values["authenticated"] = true
  144. session.Values["username"] = username
  145. session.Values["rememberMe"] = rememberme
  146. //Check if remember me is clicked. If yes, set the maxage to 1 week.
  147. if rememberme {
  148. session.Options = &sessions.Options{
  149. MaxAge: 3600 * 24 * 7, //One week
  150. Path: "/",
  151. }
  152. } else {
  153. session.Options = &sessions.Options{
  154. MaxAge: 3600 * 1, //One hour
  155. Path: "/",
  156. }
  157. }
  158. session.Save(r, w)
  159. }
  160. // Handle logout, reply OK after logged out. WILL NOT DO REDIRECTION
  161. func (a *AuthAgent) HandleLogout(w http.ResponseWriter, r *http.Request) {
  162. username, err := a.GetUserName(w, r)
  163. if err != nil {
  164. utils.SendErrorResponse(w, "user not logged in")
  165. return
  166. }
  167. if username != "" {
  168. a.Logger.PrintAndLog("auth", username+" logged out", nil)
  169. }
  170. // Revoke users authentication
  171. err = a.Logout(w, r)
  172. if err != nil {
  173. utils.SendErrorResponse(w, "Logout failed")
  174. return
  175. }
  176. utils.SendOK(w)
  177. }
  178. func (a *AuthAgent) Logout(w http.ResponseWriter, r *http.Request) error {
  179. session, err := a.SessionStore.Get(r, a.SessionName)
  180. if err != nil {
  181. return err
  182. }
  183. session.Values["authenticated"] = false
  184. session.Values["username"] = nil
  185. session.Options.MaxAge = -1
  186. return session.Save(r, w)
  187. }
  188. // Get the current session username from request
  189. func (a *AuthAgent) GetUserName(w http.ResponseWriter, r *http.Request) (string, error) {
  190. if a.CheckAuth(r) {
  191. //This user has logged in.
  192. session, _ := a.SessionStore.Get(r, a.SessionName)
  193. return session.Values["username"].(string), nil
  194. } else {
  195. //This user has not logged in.
  196. return "", errors.New("user not logged in")
  197. }
  198. }
  199. // Get the current session user email from request
  200. func (a *AuthAgent) GetUserEmail(w http.ResponseWriter, r *http.Request) (string, error) {
  201. if a.CheckAuth(r) {
  202. //This user has logged in.
  203. session, _ := a.SessionStore.Get(r, a.SessionName)
  204. username := session.Values["username"].(string)
  205. userEmail := ""
  206. err := a.Database.Read("auth", "email/"+username, &userEmail)
  207. if err != nil {
  208. return "", err
  209. }
  210. return userEmail, nil
  211. } else {
  212. //This user has not logged in.
  213. return "", errors.New("user not logged in")
  214. }
  215. }
  216. // Check if the user has logged in, return true / false in JSON
  217. func (a *AuthAgent) CheckLogin(w http.ResponseWriter, r *http.Request) {
  218. if a.CheckAuth(r) {
  219. utils.SendJSONResponse(w, "true")
  220. } else {
  221. utils.SendJSONResponse(w, "false")
  222. }
  223. }
  224. // Handle new user register. Require POST username, password, group.
  225. func (a *AuthAgent) HandleRegister(w http.ResponseWriter, r *http.Request, callback func(string, string)) {
  226. //Get username from request
  227. newusername, err := utils.PostPara(r, "username")
  228. if err != nil {
  229. utils.SendErrorResponse(w, "Missing 'username' paramter")
  230. return
  231. }
  232. //Get password from request
  233. password, err := utils.PostPara(r, "password")
  234. if err != nil {
  235. utils.SendErrorResponse(w, "Missing 'password' paramter")
  236. return
  237. }
  238. //Get email from request
  239. email, err := utils.PostPara(r, "email")
  240. if err != nil {
  241. utils.SendErrorResponse(w, "Missing 'email' paramter")
  242. return
  243. }
  244. _, err = mail.ParseAddress(email)
  245. if err != nil {
  246. utils.SendErrorResponse(w, "Invalid or malformed email")
  247. return
  248. }
  249. //Ok to proceed create this user
  250. err = a.CreateUserAccount(newusername, password, email)
  251. if err != nil {
  252. utils.SendErrorResponse(w, err.Error())
  253. return
  254. }
  255. //Do callback if exists
  256. if callback != nil {
  257. callback(newusername, email)
  258. }
  259. //Return to the client with OK
  260. utils.SendOK(w)
  261. a.Logger.PrintAndLog("auth", "New user "+newusername+" added to system.", nil)
  262. }
  263. // Handle new user register without confirmation email. Require POST username, password, group.
  264. func (a *AuthAgent) HandleRegisterWithoutEmail(w http.ResponseWriter, r *http.Request, callback func(string, string)) {
  265. //Get username from request
  266. newusername, err := utils.PostPara(r, "username")
  267. if err != nil {
  268. utils.SendErrorResponse(w, "Missing 'username' paramter")
  269. return
  270. }
  271. //Get password from request
  272. password, err := utils.PostPara(r, "password")
  273. if err != nil {
  274. utils.SendErrorResponse(w, "Missing 'password' paramter")
  275. return
  276. }
  277. //Ok to proceed create this user
  278. err = a.CreateUserAccount(newusername, password, "")
  279. if err != nil {
  280. utils.SendErrorResponse(w, err.Error())
  281. return
  282. }
  283. //Do callback if exists
  284. if callback != nil {
  285. callback(newusername, "")
  286. }
  287. //Return to the client with OK
  288. utils.SendOK(w)
  289. a.Logger.PrintAndLog("auth", "Admin account created: "+newusername, nil)
  290. }
  291. // Check authentication from request header's session value
  292. func (a *AuthAgent) CheckAuth(r *http.Request) bool {
  293. session, err := a.SessionStore.Get(r, a.SessionName)
  294. if err != nil {
  295. return false
  296. }
  297. // Check if user is authenticated
  298. if auth, ok := session.Values["authenticated"].(bool); !ok || !auth {
  299. return false
  300. }
  301. return true
  302. }
  303. // Handle de-register of users. Require POST username.
  304. // THIS FUNCTION WILL NOT CHECK FOR PERMISSION. PLEASE USE WITH PERMISSION HANDLER
  305. func (a *AuthAgent) HandleUnregister(w http.ResponseWriter, r *http.Request) {
  306. //Check if the user is logged in
  307. if !a.CheckAuth(r) {
  308. //This user has not logged in
  309. utils.SendErrorResponse(w, "Login required to remove user from the system.")
  310. return
  311. }
  312. //Get username from request
  313. username, err := utils.PostPara(r, "username")
  314. if err != nil {
  315. utils.SendErrorResponse(w, "Missing 'username' paramter")
  316. return
  317. }
  318. err = a.UnregisterUser(username)
  319. if err != nil {
  320. utils.SendErrorResponse(w, err.Error())
  321. return
  322. }
  323. //Return to the client with OK
  324. utils.SendOK(w)
  325. a.Logger.PrintAndLog("auth", "User "+username+" has been removed from the system", nil)
  326. }
  327. func (a *AuthAgent) UnregisterUser(username string) error {
  328. //Check if the user exists in the system database.
  329. if !a.Database.KeyExists("auth", "passhash/"+username) {
  330. //This user do not exists.
  331. return errors.New("this user does not exists")
  332. }
  333. //OK! Remove the user from the database
  334. a.Database.Delete("auth", "passhash/"+username)
  335. a.Database.Delete("auth", "email/"+username)
  336. return nil
  337. }
  338. // Get the number of users in the system
  339. func (a *AuthAgent) GetUserCounts() int {
  340. entries, _ := a.Database.ListTable("auth")
  341. usercount := 0
  342. for _, keypairs := range entries {
  343. if strings.Contains(string(keypairs[0]), "passhash/") {
  344. //This is a user registry
  345. usercount++
  346. }
  347. }
  348. if usercount == 0 {
  349. a.Logger.PrintAndLog("auth", "There are no user in the database", nil)
  350. }
  351. return usercount
  352. }
  353. // List all username within the system
  354. func (a *AuthAgent) ListUsers() []string {
  355. entries, _ := a.Database.ListTable("auth")
  356. results := []string{}
  357. for _, keypairs := range entries {
  358. if strings.Contains(string(keypairs[0]), "passhash/") {
  359. username := strings.Split(string(keypairs[0]), "/")[1]
  360. results = append(results, username)
  361. }
  362. }
  363. return results
  364. }
  365. // Check if the given username exists
  366. func (a *AuthAgent) UserExists(username string) bool {
  367. userpasswordhash := ""
  368. err := a.Database.Read("auth", "passhash/"+username, &userpasswordhash)
  369. if err != nil || userpasswordhash == "" {
  370. return false
  371. }
  372. return true
  373. }
  374. // Update the session expire time given the request header.
  375. func (a *AuthAgent) UpdateSessionExpireTime(w http.ResponseWriter, r *http.Request) bool {
  376. session, _ := a.SessionStore.Get(r, a.SessionName)
  377. if session.Values["authenticated"].(bool) {
  378. //User authenticated. Extend its expire time
  379. rememberme := session.Values["rememberMe"].(bool)
  380. //Extend the session expire time
  381. if rememberme {
  382. session.Options = &sessions.Options{
  383. MaxAge: 3600 * 24 * 7, //One week
  384. Path: "/",
  385. }
  386. } else {
  387. session.Options = &sessions.Options{
  388. MaxAge: 3600 * 1, //One hour
  389. Path: "/",
  390. }
  391. }
  392. session.Save(r, w)
  393. return true
  394. } else {
  395. return false
  396. }
  397. }
  398. // Create user account
  399. func (a *AuthAgent) CreateUserAccount(newusername string, password string, email string) error {
  400. //Check user already exists
  401. if a.UserExists(newusername) {
  402. return errors.New("user with same name already exists")
  403. }
  404. key := newusername
  405. hashedPassword := Hash(password)
  406. err := a.Database.Write("auth", "passhash/"+key, hashedPassword)
  407. if err != nil {
  408. return err
  409. }
  410. if email != "" {
  411. err = a.Database.Write("auth", "email/"+key, email)
  412. if err != nil {
  413. return err
  414. }
  415. }
  416. return nil
  417. }
  418. // Hash the given raw string into sha512 hash
  419. func Hash(raw string) string {
  420. h := sha512.New()
  421. h.Write([]byte(raw))
  422. return hex.EncodeToString(h.Sum(nil))
  423. }