auth.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534
  1. package auth
  2. /*
  3. ArOZ Online Authentication Module
  4. author: tobychui
  5. This system make use of sessions (similar to PHP SESSION) to remember the user login.
  6. See https://gowebexamples.com/sessions/ for detail.
  7. Auth database are stored as the following key
  8. auth/login/{username}/passhash => hashed password
  9. auth/login/{username}/permission => permission level
  10. Other system variables related to auth
  11. auth/users/usercount => Number of users in the system
  12. Pre-requirement: imuslab.com/arozos/mod/database
  13. */
  14. import (
  15. "crypto/sha512"
  16. "errors"
  17. "net/http"
  18. "strings"
  19. "sync"
  20. "encoding/hex"
  21. "log"
  22. "time"
  23. "github.com/gorilla/sessions"
  24. "imuslab.com/arozos/mod/auth/accesscontrol/blacklist"
  25. "imuslab.com/arozos/mod/auth/accesscontrol/whitelist"
  26. "imuslab.com/arozos/mod/auth/authlogger"
  27. db "imuslab.com/arozos/mod/database"
  28. "imuslab.com/arozos/mod/network"
  29. )
  30. type AuthAgent struct {
  31. //Session related
  32. SessionName string
  33. SessionStore *sessions.CookieStore
  34. Database *db.Database
  35. LoginRedirectionHandler func(http.ResponseWriter, *http.Request)
  36. //Token related
  37. ExpireTime int64 //Set this to 0 to disable token access
  38. tokenStore sync.Map
  39. terminateTokenListener chan bool
  40. mutex *sync.Mutex
  41. //Autologin Related
  42. AllowAutoLogin bool
  43. autoLoginTokens []*AutoLoginToken
  44. //IPLists manager
  45. WhitelistManager *whitelist.WhiteList
  46. BlacklistManager *blacklist.BlackList
  47. //Logger
  48. Logger *authlogger.Logger
  49. }
  50. type AuthEndpoints struct {
  51. Login string
  52. Logout string
  53. Register string
  54. CheckLoggedIn string
  55. Autologin string
  56. }
  57. //Constructor
  58. func NewAuthenticationAgent(sessionName string, key []byte, sysdb *db.Database, allowReg bool, loginRedirectionHandler func(http.ResponseWriter, *http.Request)) *AuthAgent {
  59. store := sessions.NewCookieStore(key)
  60. err := sysdb.NewTable("auth")
  61. if err != nil {
  62. log.Println("Failed to create auth database. Terminating.")
  63. panic(err)
  64. }
  65. //Creat a ticker to clean out outdated token every 5 minutes
  66. ticker := time.NewTicker(300 * time.Second)
  67. done := make(chan bool)
  68. //Create a new whitelist manager
  69. thisWhitelistManager := whitelist.NewWhitelistManager(sysdb)
  70. //Create a new blacklist manager
  71. thisBlacklistManager := blacklist.NewBlacklistManager(sysdb)
  72. //Create a new logger for logging all login request
  73. newLogger, err := authlogger.NewLogger()
  74. if err != nil {
  75. panic(err)
  76. }
  77. //Create a new AuthAgent object
  78. newAuthAgent := AuthAgent{
  79. SessionName: sessionName,
  80. SessionStore: store,
  81. Database: sysdb,
  82. LoginRedirectionHandler: loginRedirectionHandler,
  83. tokenStore: sync.Map{},
  84. ExpireTime: 120,
  85. terminateTokenListener: done,
  86. mutex: &sync.Mutex{},
  87. //Auto login management
  88. AllowAutoLogin: false,
  89. autoLoginTokens: []*AutoLoginToken{},
  90. //Blacklist management
  91. WhitelistManager: thisWhitelistManager,
  92. BlacklistManager: thisBlacklistManager,
  93. Logger: newLogger,
  94. }
  95. //Create a timer to listen to its token storage
  96. go func(listeningAuthAgent *AuthAgent) {
  97. for {
  98. select {
  99. case <-done:
  100. return
  101. case <-ticker.C:
  102. listeningAuthAgent.ClearTokenStore()
  103. }
  104. }
  105. }(&newAuthAgent)
  106. //Return the authAgent
  107. return &newAuthAgent
  108. }
  109. //Close the authAgent listener
  110. func (a *AuthAgent) Close() {
  111. //Stop the token listening
  112. a.terminateTokenListener <- true
  113. //Close the auth logger database
  114. a.Logger.Close()
  115. }
  116. //This function will handle an http request and redirect to the given login address if not logged in
  117. func (a *AuthAgent) HandleCheckAuth(w http.ResponseWriter, r *http.Request, handler func(http.ResponseWriter, *http.Request)) {
  118. if a.CheckAuth(r) {
  119. //User already logged in
  120. handler(w, r)
  121. } else {
  122. //User not logged in
  123. a.LoginRedirectionHandler(w, r)
  124. }
  125. }
  126. //Handle login request, require POST username and password
  127. func (a *AuthAgent) HandleLogin(w http.ResponseWriter, r *http.Request) {
  128. //Get username from request using POST mode
  129. username, err := mv(r, "username", true)
  130. if err != nil {
  131. //Username not defined
  132. log.Println("[System Auth] Someone trying to login with username: " + username)
  133. //Write to log
  134. a.Logger.LogAuth(r, false)
  135. sendErrorResponse(w, "Username not defined or empty.")
  136. return
  137. }
  138. //Get password from request using POST mode
  139. password, err := mv(r, "password", true)
  140. if err != nil {
  141. //Password not defined
  142. a.Logger.LogAuth(r, false)
  143. sendErrorResponse(w, "Password not defined or empty.")
  144. return
  145. }
  146. //Get rememberme settings
  147. rememberme := false
  148. rmbme, _ := mv(r, "rmbme", true)
  149. if rmbme == "true" {
  150. rememberme = true
  151. }
  152. //Check the database and see if this user is in the database
  153. passwordCorrect, rejectionReason := a.ValidateUsernameAndPasswordWithReason(username, password)
  154. //The database contain this user information. Check its password if it is correct
  155. if passwordCorrect {
  156. //Password correct
  157. //Check if this request origin is allowed to access
  158. ok, reasons := a.ValidateLoginRequest(w, r)
  159. if !ok {
  160. sendErrorResponse(w, reasons.Error())
  161. return
  162. }
  163. // Set user as authenticated
  164. a.LoginUserByRequest(w, r, username, rememberme)
  165. //Print the login message to console
  166. log.Println(username + " logged in.")
  167. a.Logger.LogAuth(r, true)
  168. sendOK(w)
  169. } else {
  170. //Password incorrect
  171. log.Println(username + " login request rejected: " + rejectionReason)
  172. sendErrorResponse(w, rejectionReason)
  173. a.Logger.LogAuth(r, false)
  174. return
  175. }
  176. }
  177. func (a *AuthAgent) ValidateUsernameAndPassword(username string, password string) bool {
  178. succ, _ := a.ValidateUsernameAndPasswordWithReason(username, password)
  179. return succ
  180. }
  181. //validate the username and password, return reasons if the auth failed
  182. func (a *AuthAgent) ValidateUsernameAndPasswordWithReason(username string, password string) (bool, string) {
  183. hashedPassword := Hash(password)
  184. var passwordInDB string
  185. err := a.Database.Read("auth", "passhash/"+username, &passwordInDB)
  186. if err != nil {
  187. //User not found or db exception
  188. //log.Println("[System Auth] " + username + " login with incorrect password")
  189. return false, "Invalid username or password"
  190. }
  191. if passwordInDB == hashedPassword {
  192. return true, ""
  193. } else {
  194. return false, "Invalid username or password"
  195. }
  196. }
  197. //Validate the user request for login
  198. func (a *AuthAgent) ValidateLoginRequest(w http.ResponseWriter, r *http.Request) (bool, error) {
  199. //Get the ip address of the request
  200. clientIP, err := network.GetIpFromRequest(r)
  201. if err != nil {
  202. return false, nil
  203. }
  204. return a.ValidateLoginIpAccess(clientIP)
  205. }
  206. func (a *AuthAgent) ValidateLoginIpAccess(ipv4 string) (bool, error) {
  207. ipv4 = strings.ReplaceAll(ipv4, " ", "")
  208. //Check if the account is whitelisted
  209. if a.WhitelistManager.Enabled && !a.WhitelistManager.IsWhitelisted(ipv4) {
  210. //Whitelist enabled but this IP is not whitelisted
  211. return false, errors.New("Your IP is not whitelisted on this host")
  212. }
  213. //Check if the account is banned
  214. if a.BlacklistManager.Enabled && a.BlacklistManager.IsBanned(ipv4) {
  215. //This user is banned
  216. return false, errors.New("Your IP is banned by this host")
  217. }
  218. return true, nil
  219. }
  220. //Login the user by creating a valid session for this user
  221. func (a *AuthAgent) LoginUserByRequest(w http.ResponseWriter, r *http.Request, username string, rememberme bool) {
  222. session, _ := a.SessionStore.Get(r, a.SessionName)
  223. session.Values["authenticated"] = true
  224. session.Values["username"] = username
  225. session.Values["rememberMe"] = rememberme
  226. //Check if remember me is clicked. If yes, set the maxage to 1 week.
  227. if rememberme == true {
  228. session.Options = &sessions.Options{
  229. MaxAge: 3600 * 24 * 7, //One week
  230. Path: "/",
  231. }
  232. } else {
  233. session.Options = &sessions.Options{
  234. MaxAge: 3600 * 1, //One hour
  235. Path: "/",
  236. }
  237. }
  238. session.Save(r, w)
  239. }
  240. //Handle logout, reply OK after logged out. WILL NOT DO REDIRECTION
  241. func (a *AuthAgent) HandleLogout(w http.ResponseWriter, r *http.Request) {
  242. username, _ := a.GetUserName(w, r)
  243. if username != "" {
  244. log.Println(username + " logged out.")
  245. }
  246. // Revoke users authentication
  247. err := a.Logout(w, r)
  248. if err != nil {
  249. sendErrorResponse(w, "Logout failed")
  250. return
  251. }
  252. w.Write([]byte("OK"))
  253. }
  254. func (a *AuthAgent) Logout(w http.ResponseWriter, r *http.Request) error {
  255. session, err := a.SessionStore.Get(r, a.SessionName)
  256. if err != nil {
  257. return err
  258. }
  259. session.Values["authenticated"] = false
  260. session.Values["username"] = nil
  261. session.Save(r, w)
  262. return nil
  263. }
  264. //Get the current session username from request
  265. func (a *AuthAgent) GetUserName(w http.ResponseWriter, r *http.Request) (string, error) {
  266. if a.CheckAuth(r) {
  267. //This user has logged in.
  268. session, _ := a.SessionStore.Get(r, a.SessionName)
  269. return session.Values["username"].(string), nil
  270. } else {
  271. //This user has not logged in.
  272. return "", errors.New("User not logged in")
  273. }
  274. }
  275. //Check if the user has logged in, return true / false in JSON
  276. func (a *AuthAgent) CheckLogin(w http.ResponseWriter, r *http.Request) {
  277. if a.CheckAuth(r) != false {
  278. sendJSONResponse(w, "true")
  279. } else {
  280. sendJSONResponse(w, "false")
  281. }
  282. }
  283. //Handle new user register. Require POST username, password, group.
  284. func (a *AuthAgent) HandleRegister(w http.ResponseWriter, r *http.Request) {
  285. userCount := a.GetUserCounts()
  286. //Get username from request
  287. newusername, err := mv(r, "username", true)
  288. if err != nil {
  289. sendTextResponse(w, "Error. Missing 'username' paramter")
  290. return
  291. }
  292. //Get password from request
  293. password, err := mv(r, "password", true)
  294. if err != nil {
  295. sendTextResponse(w, "Error. Missing 'password' paramter")
  296. return
  297. }
  298. //Set permission group to default
  299. group, err := mv(r, "group", true)
  300. if err != nil {
  301. sendTextResponse(w, "Error. Missing 'group' paramter")
  302. return
  303. }
  304. //Check if the number of users in the system is == 0. If yes, there are no need to login before registering new user
  305. if userCount > 0 {
  306. //Require login to create new user
  307. if a.CheckAuth(r) == false {
  308. //System have more than one person and this user is not logged in
  309. sendErrorResponse(w, "Login is needed to create new user")
  310. return
  311. }
  312. }
  313. //Ok to proceed create this user
  314. err = a.CreateUserAccount(newusername, password, []string{group})
  315. if err != nil {
  316. sendErrorResponse(w, err.Error())
  317. return
  318. }
  319. //Return to the client with OK
  320. sendOK(w)
  321. log.Println("[System Auth] New user " + newusername + " added to system.")
  322. return
  323. }
  324. //Check authentication from request header's session value
  325. func (a *AuthAgent) CheckAuth(r *http.Request) bool {
  326. session, _ := a.SessionStore.Get(r, a.SessionName)
  327. // Check if user is authenticated
  328. if auth, ok := session.Values["authenticated"].(bool); !ok || !auth {
  329. return false
  330. }
  331. return true
  332. }
  333. //Handle de-register of users. Require POST username.
  334. //THIS FUNCTION WILL NOT CHECK FOR PERMISSION. PLEASE USE WITH PERMISSION HANDLER
  335. func (a *AuthAgent) HandleUnregister(w http.ResponseWriter, r *http.Request) {
  336. //Check if the user is logged in
  337. if a.CheckAuth(r) == false {
  338. //This user has not logged in
  339. sendErrorResponse(w, "Login required to remove user from the system.")
  340. return
  341. }
  342. //Check for permission of this user.
  343. /*
  344. if !system_permission_checkUserIsAdmin(w,r){
  345. //This user is not admin. No permission to access this function
  346. sendErrorResponse(w, "Permission denied")
  347. }
  348. */
  349. //Get username from request
  350. username, err := mv(r, "username", true)
  351. if err != nil {
  352. sendErrorResponse(w, "Missing 'username' paramter")
  353. return
  354. }
  355. err = a.UnregisterUser(username)
  356. if err != nil {
  357. sendErrorResponse(w, err.Error())
  358. return
  359. }
  360. //Return to the client with OK
  361. sendOK(w)
  362. log.Println("[system_auth] User " + username + " has been removed from the system.")
  363. return
  364. }
  365. func (a *AuthAgent) UnregisterUser(username string) error {
  366. //Check if the user exists in the system database.
  367. if !a.Database.KeyExists("auth", "passhash/"+username) {
  368. //This user do not exists.
  369. return errors.New("This user does not exists.")
  370. }
  371. //OK! Remove the user from the database
  372. a.Database.Delete("auth", "passhash/"+username)
  373. a.Database.Delete("auth", "group/"+username)
  374. a.Database.Delete("auth", "acstatus/"+username)
  375. a.Database.Delete("auth", "profilepic/"+username)
  376. //Remove the user's autologin tokens
  377. a.RemoveAutologinTokenByUsername(username)
  378. return nil
  379. }
  380. //Get the number of users in the system
  381. func (a *AuthAgent) GetUserCounts() int {
  382. entries, _ := a.Database.ListTable("auth")
  383. usercount := 0
  384. for _, keypairs := range entries {
  385. if strings.Contains(string(keypairs[0]), "passhash/") {
  386. //This is a user registry
  387. usercount++
  388. }
  389. }
  390. if usercount == 0 {
  391. log.Println("There are no user in the database.")
  392. }
  393. return usercount
  394. }
  395. //List all username within the system
  396. func (a *AuthAgent) ListUsers() []string {
  397. entries, _ := a.Database.ListTable("auth")
  398. results := []string{}
  399. for _, keypairs := range entries {
  400. if strings.Contains(string(keypairs[0]), "group/") {
  401. username := strings.Split(string(keypairs[0]), "/")[1]
  402. results = append(results, username)
  403. }
  404. }
  405. return results
  406. }
  407. //Check if the given username exists
  408. func (a *AuthAgent) UserExists(username string) bool {
  409. userpasswordhash := ""
  410. err := a.Database.Read("auth", "passhash/"+username, &userpasswordhash)
  411. if err != nil || userpasswordhash == "" {
  412. return false
  413. }
  414. return true
  415. }
  416. //Update the session expire time given the request header.
  417. func (a *AuthAgent) UpdateSessionExpireTime(w http.ResponseWriter, r *http.Request) bool {
  418. session, _ := a.SessionStore.Get(r, a.SessionName)
  419. if session.Values["authenticated"].(bool) == true {
  420. //User authenticated. Extend its expire time
  421. rememberme := session.Values["rememberMe"].(bool)
  422. //Extend the session expire time
  423. if rememberme == true {
  424. session.Options = &sessions.Options{
  425. MaxAge: 3600 * 24 * 7, //One week
  426. Path: "/",
  427. }
  428. } else {
  429. session.Options = &sessions.Options{
  430. MaxAge: 3600 * 1, //One hour
  431. Path: "/",
  432. }
  433. }
  434. session.Save(r, w)
  435. return true
  436. } else {
  437. return false
  438. }
  439. }
  440. //Create user account
  441. func (a *AuthAgent) CreateUserAccount(newusername string, password string, group []string) error {
  442. key := newusername
  443. hashedPassword := Hash(password)
  444. err := a.Database.Write("auth", "passhash/"+key, hashedPassword)
  445. if err != nil {
  446. return err
  447. }
  448. //Store this user's usergroup settings
  449. err = a.Database.Write("auth", "group/"+newusername, group)
  450. if err != nil {
  451. return err
  452. }
  453. return nil
  454. }
  455. //Hash the given raw string into sha512 hash
  456. func Hash(raw string) string {
  457. h := sha512.New()
  458. h.Write([]byte(raw))
  459. return hex.EncodeToString(h.Sum(nil))
  460. }