auth.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464
  1. package auth
  2. /*
  3. ArOZ Online Authentication Module
  4. author: tobychui
  5. This system make use of sessions (similar to PHP SESSION) to remember the user login.
  6. See https://gowebexamples.com/sessions/ for detail.
  7. Auth database are stored as the following key
  8. auth/login/{username}/passhash => hashed password
  9. auth/login/{username}/permission => permission level (wip)
  10. Other system variables related to auth
  11. auth/users/usercount => Number of users in the system
  12. Pre-requirement: imuslab.com/arozos/mod/database
  13. */
  14. import (
  15. "crypto/sha512"
  16. "errors"
  17. "net/http"
  18. "strings"
  19. "sync"
  20. //"encoding/json"
  21. "encoding/hex"
  22. "log"
  23. "time"
  24. "github.com/gorilla/sessions"
  25. db "imuslab.com/arozos/mod/database"
  26. )
  27. type AuthAgent struct {
  28. //Session related
  29. SessionName string
  30. SessionStore *sessions.CookieStore
  31. Database *db.Database
  32. LoginRedirectionHandler func(http.ResponseWriter, *http.Request)
  33. //Token related
  34. ExpireTime int64 //Set this to 0 to disable token access
  35. tokenStore sync.Map
  36. terminateTokenListener chan bool
  37. mutex *sync.Mutex
  38. //Autologin Related
  39. AllowAutoLogin bool
  40. autoLoginTokens []AutoLoginToken
  41. }
  42. type AuthEndpoints struct {
  43. Login string
  44. Logout string
  45. Register string
  46. CheckLoggedIn string
  47. Autologin string
  48. }
  49. //Constructor
  50. func NewAuthenticationAgent(sessionName string, key []byte, sysdb *db.Database, allowReg bool, loginRedirectionHandler func(http.ResponseWriter, *http.Request)) *AuthAgent {
  51. store := sessions.NewCookieStore(key)
  52. err := sysdb.NewTable("auth")
  53. if err != nil {
  54. log.Println("Failed to create auth database. Terminating.")
  55. panic(err)
  56. }
  57. //Creat a ticker to clean out outdated token every 5 minutes
  58. ticker := time.NewTicker(300 * time.Second)
  59. done := make(chan bool)
  60. //Create a new AuthAgent object
  61. newAuthAgent := AuthAgent{
  62. SessionName: sessionName,
  63. SessionStore: store,
  64. Database: sysdb,
  65. LoginRedirectionHandler: loginRedirectionHandler,
  66. tokenStore: sync.Map{},
  67. ExpireTime: 120,
  68. terminateTokenListener: done,
  69. mutex: &sync.Mutex{},
  70. AllowAutoLogin: false,
  71. autoLoginTokens: []AutoLoginToken{},
  72. }
  73. //Create a timer to listen to its token storage
  74. go func(listeningAuthAgent *AuthAgent) {
  75. for {
  76. select {
  77. case <-done:
  78. return
  79. case <-ticker.C:
  80. listeningAuthAgent.ClearTokenStore()
  81. }
  82. }
  83. }(&newAuthAgent)
  84. //Return the authAgent
  85. return &newAuthAgent
  86. }
  87. //Close the authAgent listener
  88. func (a *AuthAgent) Close() {
  89. a.terminateTokenListener <- true
  90. }
  91. //This function will handle an http request and redirect to the given login address if not logged in
  92. func (a *AuthAgent) HandleCheckAuth(w http.ResponseWriter, r *http.Request, handler func(http.ResponseWriter, *http.Request)) {
  93. if a.CheckAuth(r) {
  94. //User already logged in
  95. handler(w, r)
  96. } else {
  97. //User not logged in
  98. a.LoginRedirectionHandler(w, r)
  99. }
  100. }
  101. //Register APIs that requires public access
  102. func (a *AuthAgent) RegisterPublicAPIs(ep AuthEndpoints) {
  103. http.HandleFunc(ep.Login, a.HandleLogin)
  104. http.HandleFunc(ep.Logout, a.HandleLogout)
  105. http.HandleFunc(ep.Register, a.HandleRegister)
  106. http.HandleFunc(ep.CheckLoggedIn, a.CheckLogin)
  107. http.HandleFunc(ep.Autologin, a.HandleAutologinTokenLogin)
  108. }
  109. //Handle login request, require POST username and password
  110. func (a *AuthAgent) HandleLogin(w http.ResponseWriter, r *http.Request) {
  111. //Get username from request using POST mode
  112. username, err := mv(r, "username", true)
  113. if err != nil {
  114. //Username not defined
  115. log.Println("[System Auth] Someone trying to login with username: " + username)
  116. sendErrorResponse(w, "Username not defined or empty.")
  117. return
  118. }
  119. //Get password from request using POST mode
  120. password, err := mv(r, "password", true)
  121. if err != nil {
  122. //Password not defined
  123. sendErrorResponse(w, "Password not defined or empty.")
  124. return
  125. }
  126. //Get rememberme settings
  127. rememberme := false
  128. rmbme, _ := mv(r, "rmbme", true)
  129. if rmbme == "true" {
  130. rememberme = true
  131. }
  132. //Check the database and see if this user is in the database
  133. passwordCorrect := a.ValidateUsernameAndPassword(username, password)
  134. //The database contain this user information. Check its password if it is correct
  135. if passwordCorrect {
  136. //Password correct
  137. // Set user as authenticated
  138. a.LoginUserByRequest(w, r, username, rememberme)
  139. //Print the login message to console
  140. log.Println(username + " logged in.")
  141. sendOK(w)
  142. } else {
  143. //Password incorrect
  144. log.Println(username + " has entered an invalid username or password")
  145. sendErrorResponse(w, "Invalid username or password")
  146. return
  147. }
  148. }
  149. func (a *AuthAgent) ValidateUsernameAndPassword(username string, password string) bool {
  150. hashedPassword := Hash(password)
  151. var passwordInDB string
  152. err := a.Database.Read("auth", "passhash/"+username, &passwordInDB)
  153. if err != nil {
  154. //User not found or db exception
  155. //log.Println("[System Auth] " + username + " login with incorrect password")
  156. return false
  157. }
  158. if passwordInDB == hashedPassword {
  159. return true
  160. } else {
  161. return false
  162. }
  163. }
  164. func (a *AuthAgent) LoginUserByRequest(w http.ResponseWriter, r *http.Request, username string, rememberme bool) {
  165. session, _ := a.SessionStore.Get(r, a.SessionName)
  166. session.Values["authenticated"] = true
  167. session.Values["username"] = username
  168. session.Values["rememberMe"] = rememberme
  169. //Check if remember me is clicked. If yes, set the maxage to 1 week.
  170. if rememberme == true {
  171. session.Options = &sessions.Options{
  172. MaxAge: 3600 * 24 * 7, //One week
  173. Path: "/",
  174. }
  175. } else {
  176. session.Options = &sessions.Options{
  177. MaxAge: 3600 * 1, //One hour
  178. Path: "/",
  179. }
  180. }
  181. session.Save(r, w)
  182. }
  183. //Handle logout, reply OK after logged out. WILL NOT DO REDIRECTION
  184. func (a *AuthAgent) HandleLogout(w http.ResponseWriter, r *http.Request) {
  185. username, _ := a.GetUserName(w, r)
  186. if username != "" {
  187. log.Println(username + " logged out.")
  188. }
  189. // Revoke users authentication
  190. err := a.Logout(w, r)
  191. if err != nil {
  192. sendErrorResponse(w, "Logout failed")
  193. return
  194. }
  195. w.Write([]byte("OK"))
  196. }
  197. func (a *AuthAgent) Logout(w http.ResponseWriter, r *http.Request) error {
  198. session, err := a.SessionStore.Get(r, a.SessionName)
  199. if err != nil {
  200. return err
  201. }
  202. session.Values["authenticated"] = false
  203. session.Values["username"] = nil
  204. session.Save(r, w)
  205. return nil
  206. }
  207. //Get the current session username from request
  208. func (a *AuthAgent) GetUserName(w http.ResponseWriter, r *http.Request) (string, error) {
  209. if a.CheckAuth(r) {
  210. //This user has logged in.
  211. session, _ := a.SessionStore.Get(r, a.SessionName)
  212. return session.Values["username"].(string), nil
  213. } else {
  214. //This user has not logged in.
  215. return "", errors.New("User not logged in")
  216. }
  217. }
  218. //Check if the user has logged in, return true / false in JSON
  219. func (a *AuthAgent) CheckLogin(w http.ResponseWriter, r *http.Request) {
  220. if a.CheckAuth(r) != false {
  221. sendJSONResponse(w, "true")
  222. } else {
  223. sendJSONResponse(w, "false")
  224. }
  225. }
  226. //Handle new user register. Require POST username, password, group.
  227. func (a *AuthAgent) HandleRegister(w http.ResponseWriter, r *http.Request) {
  228. userCount := a.GetUserCounts()
  229. //Get username from request
  230. newusername, err := mv(r, "username", true)
  231. if err != nil {
  232. sendTextResponse(w, "Error. Missing 'username' paramter")
  233. return
  234. }
  235. //Get password from request
  236. password, err := mv(r, "password", true)
  237. if err != nil {
  238. sendTextResponse(w, "Error. Missing 'password' paramter")
  239. return
  240. }
  241. //Set permission group to default
  242. group, err := mv(r, "group", true)
  243. if err != nil {
  244. sendTextResponse(w, "Error. Missing 'group' paramter")
  245. return
  246. }
  247. //Check if the number of users in the system is == 0. If yes, there are no need to login before registering new user
  248. if userCount > 0 {
  249. //Require login to create new user
  250. if a.CheckAuth(r) == false {
  251. //System have more than one person and this user is not logged in
  252. sendErrorResponse(w, "Login is needed to create new user")
  253. return
  254. }
  255. }
  256. //Ok to proceed create this user
  257. err = a.CreateUserAccount(newusername, password, []string{group})
  258. if err != nil {
  259. sendErrorResponse(w, err.Error())
  260. return
  261. }
  262. //Return to the client with OK
  263. sendOK(w)
  264. log.Println("[System Auth] New user " + newusername + " added to system.")
  265. return
  266. }
  267. //Check authentication from request header's session value
  268. func (a *AuthAgent) CheckAuth(r *http.Request) bool {
  269. session, _ := a.SessionStore.Get(r, a.SessionName)
  270. // Check if user is authenticated
  271. if auth, ok := session.Values["authenticated"].(bool); !ok || !auth {
  272. return false
  273. }
  274. return true
  275. }
  276. //Handle de-register of users. Require POST username.
  277. //THIS FUNCTION WILL NOT CHECK FOR PERMISSION. PLEASE USE WITH PERMISSION HANDLER
  278. func (a *AuthAgent) HandleUnregister(w http.ResponseWriter, r *http.Request) {
  279. //Check if the user is logged in
  280. if a.CheckAuth(r) == false {
  281. //This user has not logged in
  282. sendErrorResponse(w, "Login required to remove user from the system.")
  283. return
  284. }
  285. //Check for permission of this user.
  286. /*
  287. if !system_permission_checkUserIsAdmin(w,r){
  288. //This user is not admin. No permission to access this function
  289. sendErrorResponse(w, "Permission denied")
  290. }
  291. */
  292. //Get username from request
  293. username, err := mv(r, "username", true)
  294. if err != nil {
  295. sendErrorResponse(w, "Missing 'username' paramter")
  296. return
  297. }
  298. err = a.UnregisterUser(username)
  299. if err != nil {
  300. sendErrorResponse(w, err.Error())
  301. return
  302. }
  303. //Return to the client with OK
  304. sendOK(w)
  305. log.Println("[system_auth] User " + username + " has been removed from the system.")
  306. return
  307. }
  308. func (a *AuthAgent) UnregisterUser(username string) error {
  309. //Check if the user exists in the system database.
  310. if !a.Database.KeyExists("auth", "passhash/"+username) {
  311. //This user do not exists.
  312. return errors.New("This user does not exists.")
  313. }
  314. //OK! Remove the user from the database
  315. a.Database.Delete("auth", "passhash/"+username)
  316. a.Database.Delete("auth", "group/"+username)
  317. a.Database.Delete("auth", "acstatus/"+username)
  318. a.Database.Delete("auth", "profilepic/"+username)
  319. //Remove the user's autologin tokens
  320. a.RemoveAutologinTokenByUsername(username)
  321. return nil
  322. }
  323. //Get the number of users in the system
  324. func (a *AuthAgent) GetUserCounts() int {
  325. entries, _ := a.Database.ListTable("auth")
  326. usercount := 0
  327. for _, keypairs := range entries {
  328. if strings.Contains(string(keypairs[0]), "passhash/") {
  329. //This is a user registry
  330. usercount++
  331. }
  332. }
  333. if usercount == 0 {
  334. log.Println("There are no user in the database.")
  335. }
  336. return usercount
  337. }
  338. //List all username within the system
  339. func (a *AuthAgent) ListUsers() []string {
  340. entries, _ := a.Database.ListTable("auth")
  341. results := []string{}
  342. for _, keypairs := range entries {
  343. if strings.Contains(string(keypairs[0]), "group/") {
  344. username := strings.Split(string(keypairs[0]), "/")[1]
  345. results = append(results, username)
  346. }
  347. }
  348. return results
  349. }
  350. //Check if the given username exists
  351. func (a *AuthAgent) UserExists(username string) bool {
  352. userpasswordhash := ""
  353. err := a.Database.Read("auth", "passhash/"+username, &userpasswordhash)
  354. if err != nil || userpasswordhash == "" {
  355. return false
  356. }
  357. return true
  358. }
  359. //Update the session expire time given the request header.
  360. func (a *AuthAgent) UpdateSessionExpireTime(w http.ResponseWriter, r *http.Request) bool {
  361. session, _ := a.SessionStore.Get(r, a.SessionName)
  362. if session.Values["authenticated"].(bool) == true {
  363. //User authenticated. Extend its expire time
  364. rememberme := session.Values["rememberMe"].(bool)
  365. //Extend the session expire time
  366. if rememberme == true {
  367. session.Options = &sessions.Options{
  368. MaxAge: 3600 * 24 * 7, //One week
  369. Path: "/",
  370. }
  371. } else {
  372. session.Options = &sessions.Options{
  373. MaxAge: 3600 * 1, //One hour
  374. Path: "/",
  375. }
  376. }
  377. session.Save(r, w)
  378. return true
  379. } else {
  380. return false
  381. }
  382. }
  383. //Create user account
  384. func (a *AuthAgent) CreateUserAccount(newusername string, password string, group []string) error {
  385. key := newusername
  386. hashedPassword := Hash(password)
  387. err := a.Database.Write("auth", "passhash/"+key, hashedPassword)
  388. if err != nil {
  389. return err
  390. }
  391. //Store this user's usergroup settings
  392. err = a.Database.Write("auth", "group/"+newusername, group)
  393. if err != nil {
  394. return err
  395. }
  396. return nil
  397. }
  398. //Hash the given raw string into sha512 hash
  399. func Hash(raw string) string {
  400. h := sha512.New()
  401. h.Write([]byte(raw))
  402. return hex.EncodeToString(h.Sum(nil))
  403. }