system.resetpw.go 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151
  1. package main
  2. import (
  3. "errors"
  4. "log"
  5. "net/http"
  6. auth "imuslab.com/arozos/mod/auth"
  7. "imuslab.com/arozos/mod/common"
  8. )
  9. /*
  10. Password Reset Module
  11. This module exists to serve the password restart page with security check
  12. */
  13. func system_resetpw_init() {
  14. http.HandleFunc("/system/reset/validateResetKey", system_resetpw_validateResetKeyHandler)
  15. http.HandleFunc("/system/reset/confirmPasswordReset", system_resetpw_confirmReset)
  16. }
  17. //Validate if the ysername and rkey is valid
  18. func system_resetpw_validateResetKeyHandler(w http.ResponseWriter, r *http.Request) {
  19. username, err := common.Mv(r, "username", true)
  20. if err != nil {
  21. common.SendErrorResponse(w, "Invalid username or key")
  22. return
  23. }
  24. rkey, err := common.Mv(r, "rkey", true)
  25. if err != nil {
  26. common.SendErrorResponse(w, "Invalid username or key")
  27. return
  28. }
  29. if username == "" || rkey == "" {
  30. common.SendErrorResponse(w, "Invalid username or rkey")
  31. return
  32. }
  33. //Check if the pair is valid
  34. err = system_resetpw_validateResetKey(username, rkey)
  35. if err != nil {
  36. common.SendErrorResponse(w, err.Error())
  37. return
  38. }
  39. common.SendOK(w)
  40. }
  41. func system_resetpw_confirmReset(w http.ResponseWriter, r *http.Request) {
  42. username, _ := common.Mv(r, "username", true)
  43. rkey, _ := common.Mv(r, "rkey", true)
  44. newpw, _ := common.Mv(r, "pw", true)
  45. if username == "" || rkey == "" || newpw == "" {
  46. common.SendErrorResponse(w, "Internal Server Error")
  47. return
  48. }
  49. //Check user exists
  50. if !authAgent.UserExists(username) {
  51. common.SendErrorResponse(w, "Username not exists")
  52. return
  53. }
  54. //Validate rkey
  55. err := system_resetpw_validateResetKey(username, rkey)
  56. if err != nil {
  57. common.SendErrorResponse(w, err.Error())
  58. return
  59. }
  60. //OK to procced
  61. newHashedPassword := auth.Hash(newpw)
  62. err = sysdb.Write("auth", "passhash/"+username, newHashedPassword)
  63. if err != nil {
  64. common.SendErrorResponse(w, err.Error())
  65. return
  66. }
  67. common.SendOK(w)
  68. }
  69. func system_resetpw_validateResetKey(username string, key string) error {
  70. //Get current password from db
  71. passwordInDB := ""
  72. err := sysdb.Read("auth", "passhash/"+username, &passwordInDB)
  73. if err != nil {
  74. return err
  75. }
  76. //Get hashed user key
  77. hashedKey := auth.Hash(key)
  78. if passwordInDB != hashedKey {
  79. return errors.New("Invalid Password Reset Key")
  80. }
  81. return nil
  82. }
  83. func system_resetpw_handlePasswordReset(w http.ResponseWriter, r *http.Request) {
  84. //Check if the user click on this link with reset password key string. If not, ask the user to input one
  85. acc, err := common.Mv(r, "acc", false)
  86. if err != nil || acc == "" {
  87. system_resetpw_serveIdEnterInterface(w, r)
  88. return
  89. }
  90. resetkey, err := common.Mv(r, "rkey", false)
  91. if err != nil || resetkey == "" {
  92. system_resetpw_serveIdEnterInterface(w, r)
  93. return
  94. }
  95. //Check if the code is valid
  96. err = system_resetpw_validateResetKey(acc, resetkey)
  97. if err != nil {
  98. common.SendErrorResponse(w, "Invalid username or resetKey")
  99. return
  100. }
  101. //OK. Create the New Password Entering UI
  102. imageBase64, _ := common.LoadImageAsBase64("./web/" + iconVendor)
  103. template, err := common.Templateload("system/reset/resetPasswordTemplate.html", map[string]interface{}{
  104. "vendor_logo": imageBase64,
  105. "host_name": *host_name,
  106. "username": acc,
  107. "rkey": resetkey,
  108. })
  109. if err != nil {
  110. log.Fatal(err)
  111. }
  112. w.Header().Set("Content-Type", "text/html; charset=UTF-8")
  113. w.Write([]byte(template))
  114. }
  115. func system_resetpw_serveIdEnterInterface(w http.ResponseWriter, r *http.Request) {
  116. //Reset Key or Username not found, Serve entering interface
  117. imageBase64, _ := common.LoadImageAsBase64("./web/" + iconVendor)
  118. template, err := common.Templateload("system/reset/resetCodeTemplate.html", map[string]interface{}{
  119. "vendor_logo": imageBase64,
  120. "host_name": *host_name,
  121. })
  122. if err != nil {
  123. log.Fatal(err)
  124. }
  125. w.Header().Set("Content-Type", "text/html; charset=UTF-8")
  126. w.Write([]byte(template))
  127. }