auth.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491
  1. package auth
  2. /*
  3. ArOZ Online Authentication Module
  4. author: tobychui
  5. This system make use of sessions (similar to PHP SESSION) to remember the user login.
  6. See https://gowebexamples.com/sessions/ for detail.
  7. Auth database are stored as the following key
  8. auth/login/{username}/passhash => hashed password
  9. auth/login/{username}/permission => permission level (wip)
  10. Other system variables related to auth
  11. auth/users/usercount => Number of users in the system
  12. Pre-requirement: imuslab.com/arozos/mod/database
  13. */
  14. import (
  15. "crypto/sha512"
  16. "errors"
  17. "net/http"
  18. "strings"
  19. "sync"
  20. //"encoding/json"
  21. "encoding/hex"
  22. "log"
  23. "time"
  24. "github.com/gorilla/sessions"
  25. "imuslab.com/arozos/mod/auth/authlogger"
  26. db "imuslab.com/arozos/mod/database"
  27. )
  28. type AuthAgent struct {
  29. //Session related
  30. SessionName string
  31. SessionStore *sessions.CookieStore
  32. Database *db.Database
  33. LoginRedirectionHandler func(http.ResponseWriter, *http.Request)
  34. //Token related
  35. ExpireTime int64 //Set this to 0 to disable token access
  36. tokenStore sync.Map
  37. terminateTokenListener chan bool
  38. mutex *sync.Mutex
  39. //Autologin Related
  40. AllowAutoLogin bool
  41. autoLoginTokens []*AutoLoginToken
  42. //Logger
  43. Logger *authlogger.Logger
  44. }
  45. type AuthEndpoints struct {
  46. Login string
  47. Logout string
  48. Register string
  49. CheckLoggedIn string
  50. Autologin string
  51. }
  52. //Constructor
  53. func NewAuthenticationAgent(sessionName string, key []byte, sysdb *db.Database, allowReg bool, loginRedirectionHandler func(http.ResponseWriter, *http.Request)) *AuthAgent {
  54. store := sessions.NewCookieStore(key)
  55. err := sysdb.NewTable("auth")
  56. if err != nil {
  57. log.Println("Failed to create auth database. Terminating.")
  58. panic(err)
  59. }
  60. //Creat a ticker to clean out outdated token every 5 minutes
  61. ticker := time.NewTicker(300 * time.Second)
  62. done := make(chan bool)
  63. //Create a new logger for logging all login request
  64. newLogger, err := authlogger.NewLogger()
  65. if err != nil {
  66. panic(err)
  67. }
  68. //Create a new AuthAgent object
  69. newAuthAgent := AuthAgent{
  70. SessionName: sessionName,
  71. SessionStore: store,
  72. Database: sysdb,
  73. LoginRedirectionHandler: loginRedirectionHandler,
  74. tokenStore: sync.Map{},
  75. ExpireTime: 120,
  76. terminateTokenListener: done,
  77. mutex: &sync.Mutex{},
  78. AllowAutoLogin: false,
  79. autoLoginTokens: []*AutoLoginToken{},
  80. Logger: newLogger,
  81. }
  82. //Create a timer to listen to its token storage
  83. go func(listeningAuthAgent *AuthAgent) {
  84. for {
  85. select {
  86. case <-done:
  87. return
  88. case <-ticker.C:
  89. listeningAuthAgent.ClearTokenStore()
  90. }
  91. }
  92. }(&newAuthAgent)
  93. //Return the authAgent
  94. return &newAuthAgent
  95. }
  96. //Close the authAgent listener
  97. func (a *AuthAgent) Close() {
  98. //Stop the token listening
  99. a.terminateTokenListener <- true
  100. //Close the auth logger database
  101. a.Logger.Close()
  102. }
  103. //This function will handle an http request and redirect to the given login address if not logged in
  104. func (a *AuthAgent) HandleCheckAuth(w http.ResponseWriter, r *http.Request, handler func(http.ResponseWriter, *http.Request)) {
  105. if a.CheckAuth(r) {
  106. //User already logged in
  107. handler(w, r)
  108. } else {
  109. //User not logged in
  110. a.LoginRedirectionHandler(w, r)
  111. }
  112. }
  113. //Register APIs that requires public access
  114. func (a *AuthAgent) RegisterPublicAPIs(ep AuthEndpoints) {
  115. http.HandleFunc(ep.Login, a.HandleLogin)
  116. http.HandleFunc(ep.Logout, a.HandleLogout)
  117. http.HandleFunc(ep.Register, a.HandleRegister)
  118. http.HandleFunc(ep.CheckLoggedIn, a.CheckLogin)
  119. http.HandleFunc(ep.Autologin, a.HandleAutologinTokenLogin)
  120. }
  121. //Handle login request, require POST username and password
  122. func (a *AuthAgent) HandleLogin(w http.ResponseWriter, r *http.Request) {
  123. //Get username from request using POST mode
  124. username, err := mv(r, "username", true)
  125. if err != nil {
  126. //Username not defined
  127. log.Println("[System Auth] Someone trying to login with username: " + username)
  128. //Write to log
  129. a.Logger.LogAuth(r, false)
  130. sendErrorResponse(w, "Username not defined or empty.")
  131. return
  132. }
  133. //Get password from request using POST mode
  134. password, err := mv(r, "password", true)
  135. if err != nil {
  136. //Password not defined
  137. a.Logger.LogAuth(r, false)
  138. sendErrorResponse(w, "Password not defined or empty.")
  139. return
  140. }
  141. //Get rememberme settings
  142. rememberme := false
  143. rmbme, _ := mv(r, "rmbme", true)
  144. if rmbme == "true" {
  145. rememberme = true
  146. }
  147. //Check the database and see if this user is in the database
  148. passwordCorrect, rejectionReason := a.ValidateUsernameAndPasswordWithReason(username, password)
  149. //The database contain this user information. Check its password if it is correct
  150. if passwordCorrect {
  151. //Password correct
  152. // Set user as authenticated
  153. a.LoginUserByRequest(w, r, username, rememberme)
  154. //Print the login message to console
  155. log.Println(username + " logged in.")
  156. a.Logger.LogAuth(r, true)
  157. sendOK(w)
  158. } else {
  159. //Password incorrect
  160. log.Println(username + " login request rejected: " + rejectionReason)
  161. sendErrorResponse(w, rejectionReason)
  162. a.Logger.LogAuth(r, false)
  163. return
  164. }
  165. }
  166. func (a *AuthAgent) ValidateUsernameAndPassword(username string, password string) bool {
  167. succ, _ := a.ValidateUsernameAndPasswordWithReason(username, password)
  168. return succ
  169. }
  170. //validate the username and password, return reasons if the auth failed
  171. func (a *AuthAgent) ValidateUsernameAndPasswordWithReason(username string, password string) (bool, string) {
  172. hashedPassword := Hash(password)
  173. var passwordInDB string
  174. err := a.Database.Read("auth", "passhash/"+username, &passwordInDB)
  175. if err != nil {
  176. //User not found or db exception
  177. //log.Println("[System Auth] " + username + " login with incorrect password")
  178. return false, "Invalid username or password"
  179. }
  180. if passwordInDB == hashedPassword {
  181. return true, ""
  182. } else {
  183. return false, "Invalid username or password"
  184. }
  185. }
  186. func (a *AuthAgent) LoginUserByRequest(w http.ResponseWriter, r *http.Request, username string, rememberme bool) {
  187. session, _ := a.SessionStore.Get(r, a.SessionName)
  188. session.Values["authenticated"] = true
  189. session.Values["username"] = username
  190. session.Values["rememberMe"] = rememberme
  191. //Check if remember me is clicked. If yes, set the maxage to 1 week.
  192. if rememberme == true {
  193. session.Options = &sessions.Options{
  194. MaxAge: 3600 * 24 * 7, //One week
  195. Path: "/",
  196. }
  197. } else {
  198. session.Options = &sessions.Options{
  199. MaxAge: 3600 * 1, //One hour
  200. Path: "/",
  201. }
  202. }
  203. session.Save(r, w)
  204. }
  205. //Handle logout, reply OK after logged out. WILL NOT DO REDIRECTION
  206. func (a *AuthAgent) HandleLogout(w http.ResponseWriter, r *http.Request) {
  207. username, _ := a.GetUserName(w, r)
  208. if username != "" {
  209. log.Println(username + " logged out.")
  210. }
  211. // Revoke users authentication
  212. err := a.Logout(w, r)
  213. if err != nil {
  214. sendErrorResponse(w, "Logout failed")
  215. return
  216. }
  217. w.Write([]byte("OK"))
  218. }
  219. func (a *AuthAgent) Logout(w http.ResponseWriter, r *http.Request) error {
  220. session, err := a.SessionStore.Get(r, a.SessionName)
  221. if err != nil {
  222. return err
  223. }
  224. session.Values["authenticated"] = false
  225. session.Values["username"] = nil
  226. session.Save(r, w)
  227. return nil
  228. }
  229. //Get the current session username from request
  230. func (a *AuthAgent) GetUserName(w http.ResponseWriter, r *http.Request) (string, error) {
  231. if a.CheckAuth(r) {
  232. //This user has logged in.
  233. session, _ := a.SessionStore.Get(r, a.SessionName)
  234. return session.Values["username"].(string), nil
  235. } else {
  236. //This user has not logged in.
  237. return "", errors.New("User not logged in")
  238. }
  239. }
  240. //Check if the user has logged in, return true / false in JSON
  241. func (a *AuthAgent) CheckLogin(w http.ResponseWriter, r *http.Request) {
  242. if a.CheckAuth(r) != false {
  243. sendJSONResponse(w, "true")
  244. } else {
  245. sendJSONResponse(w, "false")
  246. }
  247. }
  248. //Handle new user register. Require POST username, password, group.
  249. func (a *AuthAgent) HandleRegister(w http.ResponseWriter, r *http.Request) {
  250. userCount := a.GetUserCounts()
  251. //Get username from request
  252. newusername, err := mv(r, "username", true)
  253. if err != nil {
  254. sendTextResponse(w, "Error. Missing 'username' paramter")
  255. return
  256. }
  257. //Get password from request
  258. password, err := mv(r, "password", true)
  259. if err != nil {
  260. sendTextResponse(w, "Error. Missing 'password' paramter")
  261. return
  262. }
  263. //Set permission group to default
  264. group, err := mv(r, "group", true)
  265. if err != nil {
  266. sendTextResponse(w, "Error. Missing 'group' paramter")
  267. return
  268. }
  269. //Check if the number of users in the system is == 0. If yes, there are no need to login before registering new user
  270. if userCount > 0 {
  271. //Require login to create new user
  272. if a.CheckAuth(r) == false {
  273. //System have more than one person and this user is not logged in
  274. sendErrorResponse(w, "Login is needed to create new user")
  275. return
  276. }
  277. }
  278. //Ok to proceed create this user
  279. err = a.CreateUserAccount(newusername, password, []string{group})
  280. if err != nil {
  281. sendErrorResponse(w, err.Error())
  282. return
  283. }
  284. //Return to the client with OK
  285. sendOK(w)
  286. log.Println("[System Auth] New user " + newusername + " added to system.")
  287. return
  288. }
  289. //Check authentication from request header's session value
  290. func (a *AuthAgent) CheckAuth(r *http.Request) bool {
  291. session, _ := a.SessionStore.Get(r, a.SessionName)
  292. // Check if user is authenticated
  293. if auth, ok := session.Values["authenticated"].(bool); !ok || !auth {
  294. return false
  295. }
  296. return true
  297. }
  298. //Handle de-register of users. Require POST username.
  299. //THIS FUNCTION WILL NOT CHECK FOR PERMISSION. PLEASE USE WITH PERMISSION HANDLER
  300. func (a *AuthAgent) HandleUnregister(w http.ResponseWriter, r *http.Request) {
  301. //Check if the user is logged in
  302. if a.CheckAuth(r) == false {
  303. //This user has not logged in
  304. sendErrorResponse(w, "Login required to remove user from the system.")
  305. return
  306. }
  307. //Check for permission of this user.
  308. /*
  309. if !system_permission_checkUserIsAdmin(w,r){
  310. //This user is not admin. No permission to access this function
  311. sendErrorResponse(w, "Permission denied")
  312. }
  313. */
  314. //Get username from request
  315. username, err := mv(r, "username", true)
  316. if err != nil {
  317. sendErrorResponse(w, "Missing 'username' paramter")
  318. return
  319. }
  320. err = a.UnregisterUser(username)
  321. if err != nil {
  322. sendErrorResponse(w, err.Error())
  323. return
  324. }
  325. //Return to the client with OK
  326. sendOK(w)
  327. log.Println("[system_auth] User " + username + " has been removed from the system.")
  328. return
  329. }
  330. func (a *AuthAgent) UnregisterUser(username string) error {
  331. //Check if the user exists in the system database.
  332. if !a.Database.KeyExists("auth", "passhash/"+username) {
  333. //This user do not exists.
  334. return errors.New("This user does not exists.")
  335. }
  336. //OK! Remove the user from the database
  337. a.Database.Delete("auth", "passhash/"+username)
  338. a.Database.Delete("auth", "group/"+username)
  339. a.Database.Delete("auth", "acstatus/"+username)
  340. a.Database.Delete("auth", "profilepic/"+username)
  341. //Remove the user's autologin tokens
  342. a.RemoveAutologinTokenByUsername(username)
  343. return nil
  344. }
  345. //Get the number of users in the system
  346. func (a *AuthAgent) GetUserCounts() int {
  347. entries, _ := a.Database.ListTable("auth")
  348. usercount := 0
  349. for _, keypairs := range entries {
  350. if strings.Contains(string(keypairs[0]), "passhash/") {
  351. //This is a user registry
  352. usercount++
  353. }
  354. }
  355. if usercount == 0 {
  356. log.Println("There are no user in the database.")
  357. }
  358. return usercount
  359. }
  360. //List all username within the system
  361. func (a *AuthAgent) ListUsers() []string {
  362. entries, _ := a.Database.ListTable("auth")
  363. results := []string{}
  364. for _, keypairs := range entries {
  365. if strings.Contains(string(keypairs[0]), "group/") {
  366. username := strings.Split(string(keypairs[0]), "/")[1]
  367. results = append(results, username)
  368. }
  369. }
  370. return results
  371. }
  372. //Check if the given username exists
  373. func (a *AuthAgent) UserExists(username string) bool {
  374. userpasswordhash := ""
  375. err := a.Database.Read("auth", "passhash/"+username, &userpasswordhash)
  376. if err != nil || userpasswordhash == "" {
  377. return false
  378. }
  379. return true
  380. }
  381. //Update the session expire time given the request header.
  382. func (a *AuthAgent) UpdateSessionExpireTime(w http.ResponseWriter, r *http.Request) bool {
  383. session, _ := a.SessionStore.Get(r, a.SessionName)
  384. if session.Values["authenticated"].(bool) == true {
  385. //User authenticated. Extend its expire time
  386. rememberme := session.Values["rememberMe"].(bool)
  387. //Extend the session expire time
  388. if rememberme == true {
  389. session.Options = &sessions.Options{
  390. MaxAge: 3600 * 24 * 7, //One week
  391. Path: "/",
  392. }
  393. } else {
  394. session.Options = &sessions.Options{
  395. MaxAge: 3600 * 1, //One hour
  396. Path: "/",
  397. }
  398. }
  399. session.Save(r, w)
  400. return true
  401. } else {
  402. return false
  403. }
  404. }
  405. //Create user account
  406. func (a *AuthAgent) CreateUserAccount(newusername string, password string, group []string) error {
  407. key := newusername
  408. hashedPassword := Hash(password)
  409. err := a.Database.Write("auth", "passhash/"+key, hashedPassword)
  410. if err != nil {
  411. return err
  412. }
  413. //Store this user's usergroup settings
  414. err = a.Database.Write("auth", "group/"+newusername, group)
  415. if err != nil {
  416. return err
  417. }
  418. return nil
  419. }
  420. //Hash the given raw string into sha512 hash
  421. func Hash(raw string) string {
  422. h := sha512.New()
  423. h.Write([]byte(raw))
  424. return hex.EncodeToString(h.Sum(nil))
  425. }