auth.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510
  1. package auth
  2. /*
  3. ArOZ Online Authentication Module
  4. author: tobychui
  5. This system make use of sessions (similar to PHP SESSION) to remember the user login.
  6. See https://gowebexamples.com/sessions/ for detail.
  7. Auth database are stored as the following key
  8. auth/login/{username}/passhash => hashed password
  9. auth/login/{username}/permission => permission level
  10. Other system variables related to auth
  11. auth/users/usercount => Number of users in the system
  12. Pre-requirement: imuslab.com/arozos/mod/database
  13. */
  14. import (
  15. "crypto/sha512"
  16. "errors"
  17. "net/http"
  18. "strings"
  19. "sync"
  20. "encoding/hex"
  21. "log"
  22. "time"
  23. "github.com/gorilla/sessions"
  24. "imuslab.com/arozos/mod/auth/authlogger"
  25. "imuslab.com/arozos/mod/auth/blacklist"
  26. db "imuslab.com/arozos/mod/database"
  27. )
  28. type AuthAgent struct {
  29. //Session related
  30. SessionName string
  31. SessionStore *sessions.CookieStore
  32. Database *db.Database
  33. LoginRedirectionHandler func(http.ResponseWriter, *http.Request)
  34. //Token related
  35. ExpireTime int64 //Set this to 0 to disable token access
  36. tokenStore sync.Map
  37. terminateTokenListener chan bool
  38. mutex *sync.Mutex
  39. //Autologin Related
  40. AllowAutoLogin bool
  41. autoLoginTokens []*AutoLoginToken
  42. //IP Blacklist manager
  43. BlacklistManager *blacklist.BlackList
  44. //Logger
  45. Logger *authlogger.Logger
  46. }
  47. type AuthEndpoints struct {
  48. Login string
  49. Logout string
  50. Register string
  51. CheckLoggedIn string
  52. Autologin string
  53. }
  54. //Constructor
  55. func NewAuthenticationAgent(sessionName string, key []byte, sysdb *db.Database, allowReg bool, loginRedirectionHandler func(http.ResponseWriter, *http.Request)) *AuthAgent {
  56. store := sessions.NewCookieStore(key)
  57. err := sysdb.NewTable("auth")
  58. if err != nil {
  59. log.Println("Failed to create auth database. Terminating.")
  60. panic(err)
  61. }
  62. //Creat a ticker to clean out outdated token every 5 minutes
  63. ticker := time.NewTicker(300 * time.Second)
  64. done := make(chan bool)
  65. //Create a new blacklist manager
  66. thisBlacklistManager := blacklist.NewBlacklistManager(sysdb)
  67. //Create a new logger for logging all login request
  68. newLogger, err := authlogger.NewLogger()
  69. if err != nil {
  70. panic(err)
  71. }
  72. //Create a new AuthAgent object
  73. newAuthAgent := AuthAgent{
  74. SessionName: sessionName,
  75. SessionStore: store,
  76. Database: sysdb,
  77. LoginRedirectionHandler: loginRedirectionHandler,
  78. tokenStore: sync.Map{},
  79. ExpireTime: 120,
  80. terminateTokenListener: done,
  81. mutex: &sync.Mutex{},
  82. //Auto login management
  83. AllowAutoLogin: false,
  84. autoLoginTokens: []*AutoLoginToken{},
  85. //Blacklist management
  86. BlacklistManager: thisBlacklistManager,
  87. Logger: newLogger,
  88. }
  89. //Create a timer to listen to its token storage
  90. go func(listeningAuthAgent *AuthAgent) {
  91. for {
  92. select {
  93. case <-done:
  94. return
  95. case <-ticker.C:
  96. listeningAuthAgent.ClearTokenStore()
  97. }
  98. }
  99. }(&newAuthAgent)
  100. //Return the authAgent
  101. return &newAuthAgent
  102. }
  103. //Close the authAgent listener
  104. func (a *AuthAgent) Close() {
  105. //Stop the token listening
  106. a.terminateTokenListener <- true
  107. //Close the auth logger database
  108. a.Logger.Close()
  109. }
  110. //This function will handle an http request and redirect to the given login address if not logged in
  111. func (a *AuthAgent) HandleCheckAuth(w http.ResponseWriter, r *http.Request, handler func(http.ResponseWriter, *http.Request)) {
  112. if a.CheckAuth(r) {
  113. //User already logged in
  114. handler(w, r)
  115. } else {
  116. //User not logged in
  117. a.LoginRedirectionHandler(w, r)
  118. }
  119. }
  120. //Handle login request, require POST username and password
  121. func (a *AuthAgent) HandleLogin(w http.ResponseWriter, r *http.Request) {
  122. //Get username from request using POST mode
  123. username, err := mv(r, "username", true)
  124. if err != nil {
  125. //Username not defined
  126. log.Println("[System Auth] Someone trying to login with username: " + username)
  127. //Write to log
  128. a.Logger.LogAuth(r, false)
  129. sendErrorResponse(w, "Username not defined or empty.")
  130. return
  131. }
  132. //Get password from request using POST mode
  133. password, err := mv(r, "password", true)
  134. if err != nil {
  135. //Password not defined
  136. a.Logger.LogAuth(r, false)
  137. sendErrorResponse(w, "Password not defined or empty.")
  138. return
  139. }
  140. //Get rememberme settings
  141. rememberme := false
  142. rmbme, _ := mv(r, "rmbme", true)
  143. if rmbme == "true" {
  144. rememberme = true
  145. }
  146. //Check the database and see if this user is in the database
  147. passwordCorrect, rejectionReason := a.ValidateUsernameAndPasswordWithReason(username, password)
  148. //The database contain this user information. Check its password if it is correct
  149. if passwordCorrect {
  150. //Password correct
  151. //Check if this request origin is allowed to access
  152. ok, reasons := a.ValidateLoginRequest(w, r)
  153. if !ok {
  154. sendErrorResponse(w, reasons.Error())
  155. return
  156. }
  157. // Set user as authenticated
  158. a.LoginUserByRequest(w, r, username, rememberme)
  159. //Print the login message to console
  160. log.Println(username + " logged in.")
  161. a.Logger.LogAuth(r, true)
  162. sendOK(w)
  163. } else {
  164. //Password incorrect
  165. log.Println(username + " login request rejected: " + rejectionReason)
  166. sendErrorResponse(w, rejectionReason)
  167. a.Logger.LogAuth(r, false)
  168. return
  169. }
  170. }
  171. func (a *AuthAgent) ValidateUsernameAndPassword(username string, password string) bool {
  172. succ, _ := a.ValidateUsernameAndPasswordWithReason(username, password)
  173. return succ
  174. }
  175. //validate the username and password, return reasons if the auth failed
  176. func (a *AuthAgent) ValidateUsernameAndPasswordWithReason(username string, password string) (bool, string) {
  177. hashedPassword := Hash(password)
  178. var passwordInDB string
  179. err := a.Database.Read("auth", "passhash/"+username, &passwordInDB)
  180. if err != nil {
  181. //User not found or db exception
  182. //log.Println("[System Auth] " + username + " login with incorrect password")
  183. return false, "Invalid username or password"
  184. }
  185. if passwordInDB == hashedPassword {
  186. return true, ""
  187. } else {
  188. return false, "Invalid username or password"
  189. }
  190. }
  191. //Validate the user request for login
  192. func (a *AuthAgent) ValidateLoginRequest(w http.ResponseWriter, r *http.Request) (bool, error) {
  193. //Check if the account is banned
  194. if a.BlacklistManager.CheckIsBannedByRequest(r) {
  195. //This user is banned
  196. return false, errors.New("This IP is banned")
  197. }
  198. return true, nil
  199. }
  200. //Login the user by creating a valid session for this user
  201. func (a *AuthAgent) LoginUserByRequest(w http.ResponseWriter, r *http.Request, username string, rememberme bool) {
  202. session, _ := a.SessionStore.Get(r, a.SessionName)
  203. session.Values["authenticated"] = true
  204. session.Values["username"] = username
  205. session.Values["rememberMe"] = rememberme
  206. //Check if remember me is clicked. If yes, set the maxage to 1 week.
  207. if rememberme == true {
  208. session.Options = &sessions.Options{
  209. MaxAge: 3600 * 24 * 7, //One week
  210. Path: "/",
  211. }
  212. } else {
  213. session.Options = &sessions.Options{
  214. MaxAge: 3600 * 1, //One hour
  215. Path: "/",
  216. }
  217. }
  218. session.Save(r, w)
  219. }
  220. //Handle logout, reply OK after logged out. WILL NOT DO REDIRECTION
  221. func (a *AuthAgent) HandleLogout(w http.ResponseWriter, r *http.Request) {
  222. username, _ := a.GetUserName(w, r)
  223. if username != "" {
  224. log.Println(username + " logged out.")
  225. }
  226. // Revoke users authentication
  227. err := a.Logout(w, r)
  228. if err != nil {
  229. sendErrorResponse(w, "Logout failed")
  230. return
  231. }
  232. w.Write([]byte("OK"))
  233. }
  234. func (a *AuthAgent) Logout(w http.ResponseWriter, r *http.Request) error {
  235. session, err := a.SessionStore.Get(r, a.SessionName)
  236. if err != nil {
  237. return err
  238. }
  239. session.Values["authenticated"] = false
  240. session.Values["username"] = nil
  241. session.Save(r, w)
  242. return nil
  243. }
  244. //Get the current session username from request
  245. func (a *AuthAgent) GetUserName(w http.ResponseWriter, r *http.Request) (string, error) {
  246. if a.CheckAuth(r) {
  247. //This user has logged in.
  248. session, _ := a.SessionStore.Get(r, a.SessionName)
  249. return session.Values["username"].(string), nil
  250. } else {
  251. //This user has not logged in.
  252. return "", errors.New("User not logged in")
  253. }
  254. }
  255. //Check if the user has logged in, return true / false in JSON
  256. func (a *AuthAgent) CheckLogin(w http.ResponseWriter, r *http.Request) {
  257. if a.CheckAuth(r) != false {
  258. sendJSONResponse(w, "true")
  259. } else {
  260. sendJSONResponse(w, "false")
  261. }
  262. }
  263. //Handle new user register. Require POST username, password, group.
  264. func (a *AuthAgent) HandleRegister(w http.ResponseWriter, r *http.Request) {
  265. userCount := a.GetUserCounts()
  266. //Get username from request
  267. newusername, err := mv(r, "username", true)
  268. if err != nil {
  269. sendTextResponse(w, "Error. Missing 'username' paramter")
  270. return
  271. }
  272. //Get password from request
  273. password, err := mv(r, "password", true)
  274. if err != nil {
  275. sendTextResponse(w, "Error. Missing 'password' paramter")
  276. return
  277. }
  278. //Set permission group to default
  279. group, err := mv(r, "group", true)
  280. if err != nil {
  281. sendTextResponse(w, "Error. Missing 'group' paramter")
  282. return
  283. }
  284. //Check if the number of users in the system is == 0. If yes, there are no need to login before registering new user
  285. if userCount > 0 {
  286. //Require login to create new user
  287. if a.CheckAuth(r) == false {
  288. //System have more than one person and this user is not logged in
  289. sendErrorResponse(w, "Login is needed to create new user")
  290. return
  291. }
  292. }
  293. //Ok to proceed create this user
  294. err = a.CreateUserAccount(newusername, password, []string{group})
  295. if err != nil {
  296. sendErrorResponse(w, err.Error())
  297. return
  298. }
  299. //Return to the client with OK
  300. sendOK(w)
  301. log.Println("[System Auth] New user " + newusername + " added to system.")
  302. return
  303. }
  304. //Check authentication from request header's session value
  305. func (a *AuthAgent) CheckAuth(r *http.Request) bool {
  306. session, _ := a.SessionStore.Get(r, a.SessionName)
  307. // Check if user is authenticated
  308. if auth, ok := session.Values["authenticated"].(bool); !ok || !auth {
  309. return false
  310. }
  311. return true
  312. }
  313. //Handle de-register of users. Require POST username.
  314. //THIS FUNCTION WILL NOT CHECK FOR PERMISSION. PLEASE USE WITH PERMISSION HANDLER
  315. func (a *AuthAgent) HandleUnregister(w http.ResponseWriter, r *http.Request) {
  316. //Check if the user is logged in
  317. if a.CheckAuth(r) == false {
  318. //This user has not logged in
  319. sendErrorResponse(w, "Login required to remove user from the system.")
  320. return
  321. }
  322. //Check for permission of this user.
  323. /*
  324. if !system_permission_checkUserIsAdmin(w,r){
  325. //This user is not admin. No permission to access this function
  326. sendErrorResponse(w, "Permission denied")
  327. }
  328. */
  329. //Get username from request
  330. username, err := mv(r, "username", true)
  331. if err != nil {
  332. sendErrorResponse(w, "Missing 'username' paramter")
  333. return
  334. }
  335. err = a.UnregisterUser(username)
  336. if err != nil {
  337. sendErrorResponse(w, err.Error())
  338. return
  339. }
  340. //Return to the client with OK
  341. sendOK(w)
  342. log.Println("[system_auth] User " + username + " has been removed from the system.")
  343. return
  344. }
  345. func (a *AuthAgent) UnregisterUser(username string) error {
  346. //Check if the user exists in the system database.
  347. if !a.Database.KeyExists("auth", "passhash/"+username) {
  348. //This user do not exists.
  349. return errors.New("This user does not exists.")
  350. }
  351. //OK! Remove the user from the database
  352. a.Database.Delete("auth", "passhash/"+username)
  353. a.Database.Delete("auth", "group/"+username)
  354. a.Database.Delete("auth", "acstatus/"+username)
  355. a.Database.Delete("auth", "profilepic/"+username)
  356. //Remove the user's autologin tokens
  357. a.RemoveAutologinTokenByUsername(username)
  358. return nil
  359. }
  360. //Get the number of users in the system
  361. func (a *AuthAgent) GetUserCounts() int {
  362. entries, _ := a.Database.ListTable("auth")
  363. usercount := 0
  364. for _, keypairs := range entries {
  365. if strings.Contains(string(keypairs[0]), "passhash/") {
  366. //This is a user registry
  367. usercount++
  368. }
  369. }
  370. if usercount == 0 {
  371. log.Println("There are no user in the database.")
  372. }
  373. return usercount
  374. }
  375. //List all username within the system
  376. func (a *AuthAgent) ListUsers() []string {
  377. entries, _ := a.Database.ListTable("auth")
  378. results := []string{}
  379. for _, keypairs := range entries {
  380. if strings.Contains(string(keypairs[0]), "group/") {
  381. username := strings.Split(string(keypairs[0]), "/")[1]
  382. results = append(results, username)
  383. }
  384. }
  385. return results
  386. }
  387. //Check if the given username exists
  388. func (a *AuthAgent) UserExists(username string) bool {
  389. userpasswordhash := ""
  390. err := a.Database.Read("auth", "passhash/"+username, &userpasswordhash)
  391. if err != nil || userpasswordhash == "" {
  392. return false
  393. }
  394. return true
  395. }
  396. //Update the session expire time given the request header.
  397. func (a *AuthAgent) UpdateSessionExpireTime(w http.ResponseWriter, r *http.Request) bool {
  398. session, _ := a.SessionStore.Get(r, a.SessionName)
  399. if session.Values["authenticated"].(bool) == true {
  400. //User authenticated. Extend its expire time
  401. rememberme := session.Values["rememberMe"].(bool)
  402. //Extend the session expire time
  403. if rememberme == true {
  404. session.Options = &sessions.Options{
  405. MaxAge: 3600 * 24 * 7, //One week
  406. Path: "/",
  407. }
  408. } else {
  409. session.Options = &sessions.Options{
  410. MaxAge: 3600 * 1, //One hour
  411. Path: "/",
  412. }
  413. }
  414. session.Save(r, w)
  415. return true
  416. } else {
  417. return false
  418. }
  419. }
  420. //Create user account
  421. func (a *AuthAgent) CreateUserAccount(newusername string, password string, group []string) error {
  422. key := newusername
  423. hashedPassword := Hash(password)
  424. err := a.Database.Write("auth", "passhash/"+key, hashedPassword)
  425. if err != nil {
  426. return err
  427. }
  428. //Store this user's usergroup settings
  429. err = a.Database.Write("auth", "group/"+newusername, group)
  430. if err != nil {
  431. return err
  432. }
  433. return nil
  434. }
  435. //Hash the given raw string into sha512 hash
  436. func Hash(raw string) string {
  437. h := sha512.New()
  438. h.Write([]byte(raw))
  439. return hex.EncodeToString(h.Sum(nil))
  440. }