auth.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560
  1. package auth
  2. /*
  3. ArOZ Online Authentication Module
  4. author: tobychui
  5. This system make use of sessions (similar to PHP SESSION) to remember the user login.
  6. See https://gowebexamples.com/sessions/ for detail.
  7. Auth database are stored as the following key
  8. auth/login/{username}/passhash => hashed password
  9. auth/login/{username}/permission => permission level
  10. Other system variables related to auth
  11. auth/users/usercount => Number of users in the system
  12. Pre-requirement: imuslab.com/arozos/mod/database
  13. */
  14. import (
  15. "crypto/sha512"
  16. "errors"
  17. "net/http"
  18. "strconv"
  19. "strings"
  20. "sync"
  21. "encoding/hex"
  22. "log"
  23. "time"
  24. "github.com/gorilla/sessions"
  25. "imuslab.com/arozos/mod/auth/accesscontrol/blacklist"
  26. "imuslab.com/arozos/mod/auth/accesscontrol/whitelist"
  27. "imuslab.com/arozos/mod/auth/authlogger"
  28. "imuslab.com/arozos/mod/auth/explogin"
  29. db "imuslab.com/arozos/mod/database"
  30. "imuslab.com/arozos/mod/network"
  31. )
  32. type AuthAgent struct {
  33. //Session related
  34. SessionName string
  35. SessionStore *sessions.CookieStore
  36. Database *db.Database
  37. LoginRedirectionHandler func(http.ResponseWriter, *http.Request)
  38. //Token related
  39. ExpireTime int64 //Set this to 0 to disable token access
  40. tokenStore sync.Map
  41. terminateTokenListener chan bool
  42. mutex *sync.Mutex
  43. //Autologin Related
  44. AllowAutoLogin bool
  45. autoLoginTokens []*AutoLoginToken
  46. //Exponential Delay Retry Handler
  47. ExpDelayHandler *explogin.ExpLoginHandler
  48. //IPLists manager
  49. WhitelistManager *whitelist.WhiteList
  50. BlacklistManager *blacklist.BlackList
  51. //Logger
  52. Logger *authlogger.Logger
  53. }
  54. type AuthEndpoints struct {
  55. Login string
  56. Logout string
  57. Register string
  58. CheckLoggedIn string
  59. Autologin string
  60. }
  61. //Constructor
  62. func NewAuthenticationAgent(sessionName string, key []byte, sysdb *db.Database, allowReg bool, loginRedirectionHandler func(http.ResponseWriter, *http.Request)) *AuthAgent {
  63. store := sessions.NewCookieStore(key)
  64. err := sysdb.NewTable("auth")
  65. if err != nil {
  66. log.Println("Failed to create auth database. Terminating.")
  67. panic(err)
  68. }
  69. //Creat a ticker to clean out outdated token every 5 minutes
  70. ticker := time.NewTicker(300 * time.Second)
  71. done := make(chan bool)
  72. //Create a exponential login delay handler
  73. expLoginHandler := explogin.NewExponentialLoginHandler(2, 10800)
  74. //Create a new whitelist manager
  75. thisWhitelistManager := whitelist.NewWhitelistManager(sysdb)
  76. //Create a new blacklist manager
  77. thisBlacklistManager := blacklist.NewBlacklistManager(sysdb)
  78. //Create a new logger for logging all login request
  79. newLogger, err := authlogger.NewLogger()
  80. if err != nil {
  81. panic(err)
  82. }
  83. //Create a new AuthAgent object
  84. newAuthAgent := AuthAgent{
  85. SessionName: sessionName,
  86. SessionStore: store,
  87. Database: sysdb,
  88. LoginRedirectionHandler: loginRedirectionHandler,
  89. tokenStore: sync.Map{},
  90. ExpireTime: 120,
  91. terminateTokenListener: done,
  92. mutex: &sync.Mutex{},
  93. //Auto login management
  94. AllowAutoLogin: false,
  95. autoLoginTokens: []*AutoLoginToken{},
  96. //Blacklist management
  97. WhitelistManager: thisWhitelistManager,
  98. BlacklistManager: thisBlacklistManager,
  99. ExpDelayHandler: expLoginHandler,
  100. Logger: newLogger,
  101. }
  102. //Create a timer to listen to its token storage
  103. go func(listeningAuthAgent *AuthAgent) {
  104. for {
  105. select {
  106. case <-done:
  107. return
  108. case <-ticker.C:
  109. listeningAuthAgent.ClearTokenStore()
  110. }
  111. }
  112. }(&newAuthAgent)
  113. //Return the authAgent
  114. return &newAuthAgent
  115. }
  116. //Close the authAgent listener
  117. func (a *AuthAgent) Close() {
  118. //Stop the token listening
  119. a.terminateTokenListener <- true
  120. //Close the auth logger database
  121. a.Logger.Close()
  122. }
  123. //This function will handle an http request and redirect to the given login address if not logged in
  124. func (a *AuthAgent) HandleCheckAuth(w http.ResponseWriter, r *http.Request, handler func(http.ResponseWriter, *http.Request)) {
  125. if a.CheckAuth(r) {
  126. //User already logged in
  127. handler(w, r)
  128. } else {
  129. //User not logged in
  130. a.LoginRedirectionHandler(w, r)
  131. }
  132. }
  133. //Handle login request, require POST username and password
  134. func (a *AuthAgent) HandleLogin(w http.ResponseWriter, r *http.Request) {
  135. //Get username from request using POST mode
  136. username, err := mv(r, "username", true)
  137. if err != nil {
  138. //Username not defined
  139. log.Println("[System Auth] Someone trying to login with username: " + username)
  140. //Write to log
  141. a.Logger.LogAuth(r, false)
  142. sendErrorResponse(w, "Username not defined or empty.")
  143. return
  144. }
  145. //Get password from request using POST mode
  146. password, err := mv(r, "password", true)
  147. if err != nil {
  148. //Password not defined
  149. a.Logger.LogAuth(r, false)
  150. sendErrorResponse(w, "Password not defined or empty.")
  151. return
  152. }
  153. //Get rememberme settings
  154. rememberme := false
  155. rmbme, _ := mv(r, "rmbme", true)
  156. if rmbme == "true" {
  157. rememberme = true
  158. }
  159. //Check Exponential Login Handler
  160. ok, nextRetryIn := a.ExpDelayHandler.AllowImmediateAccess(username, r)
  161. if !ok {
  162. //Too many request! (maybe the account is under brute force attack?)
  163. a.ExpDelayHandler.AddUserRetrycount(username, r)
  164. sendErrorResponse(w, "Too many request! Next retry in "+strconv.Itoa(int(nextRetryIn))+" seconds")
  165. return
  166. }
  167. //Check the database and see if this user is in the database
  168. passwordCorrect, rejectionReason := a.ValidateUsernameAndPasswordWithReason(username, password)
  169. //The database contain this user information. Check its password if it is correct
  170. if passwordCorrect {
  171. //Password correct
  172. //Check if this request origin is allowed to access
  173. ok, reasons := a.ValidateLoginRequest(w, r)
  174. if !ok {
  175. sendErrorResponse(w, reasons.Error())
  176. return
  177. }
  178. // Set user as authenticated
  179. a.LoginUserByRequest(w, r, username, rememberme)
  180. //Reset user retry count if any
  181. a.ExpDelayHandler.ResetUserRetryCount(username, r)
  182. //Print the login message to console
  183. log.Println(username + " logged in.")
  184. a.Logger.LogAuth(r, true)
  185. sendOK(w)
  186. } else {
  187. //Password incorrect
  188. log.Println(username + " login request rejected: " + rejectionReason)
  189. //Add to retry count
  190. a.ExpDelayHandler.AddUserRetrycount(username, r)
  191. sendErrorResponse(w, rejectionReason)
  192. a.Logger.LogAuth(r, false)
  193. return
  194. }
  195. }
  196. func (a *AuthAgent) ValidateUsernameAndPassword(username string, password string) bool {
  197. succ, _ := a.ValidateUsernameAndPasswordWithReason(username, password)
  198. return succ
  199. }
  200. //validate the username and password, return reasons if the auth failed
  201. func (a *AuthAgent) ValidateUsernameAndPasswordWithReason(username string, password string) (bool, string) {
  202. hashedPassword := Hash(password)
  203. var passwordInDB string
  204. err := a.Database.Read("auth", "passhash/"+username, &passwordInDB)
  205. if err != nil {
  206. //User not found or db exception
  207. //log.Println("[System Auth] " + username + " login with incorrect password")
  208. return false, "Invalid username or password"
  209. }
  210. if passwordInDB == hashedPassword {
  211. return true, ""
  212. } else {
  213. return false, "Invalid username or password"
  214. }
  215. }
  216. //Validate the user request for login
  217. func (a *AuthAgent) ValidateLoginRequest(w http.ResponseWriter, r *http.Request) (bool, error) {
  218. //Get the ip address of the request
  219. clientIP, err := network.GetIpFromRequest(r)
  220. if err != nil {
  221. return false, nil
  222. }
  223. return a.ValidateLoginIpAccess(clientIP)
  224. }
  225. func (a *AuthAgent) ValidateLoginIpAccess(ipv4 string) (bool, error) {
  226. ipv4 = strings.ReplaceAll(ipv4, " ", "")
  227. //Check if the account is whitelisted
  228. if a.WhitelistManager.Enabled && !a.WhitelistManager.IsWhitelisted(ipv4) {
  229. //Whitelist enabled but this IP is not whitelisted
  230. return false, errors.New("Your IP is not whitelisted on this host")
  231. }
  232. //Check if the account is banned
  233. if a.BlacklistManager.Enabled && a.BlacklistManager.IsBanned(ipv4) {
  234. //This user is banned
  235. return false, errors.New("Your IP is banned by this host")
  236. }
  237. return true, nil
  238. }
  239. //Login the user by creating a valid session for this user
  240. func (a *AuthAgent) LoginUserByRequest(w http.ResponseWriter, r *http.Request, username string, rememberme bool) {
  241. session, _ := a.SessionStore.Get(r, a.SessionName)
  242. session.Values["authenticated"] = true
  243. session.Values["username"] = username
  244. session.Values["rememberMe"] = rememberme
  245. //Check if remember me is clicked. If yes, set the maxage to 1 week.
  246. if rememberme == true {
  247. session.Options = &sessions.Options{
  248. MaxAge: 3600 * 24 * 7, //One week
  249. Path: "/",
  250. }
  251. } else {
  252. session.Options = &sessions.Options{
  253. MaxAge: 3600 * 1, //One hour
  254. Path: "/",
  255. }
  256. }
  257. session.Save(r, w)
  258. }
  259. //Handle logout, reply OK after logged out. WILL NOT DO REDIRECTION
  260. func (a *AuthAgent) HandleLogout(w http.ResponseWriter, r *http.Request) {
  261. username, _ := a.GetUserName(w, r)
  262. if username != "" {
  263. log.Println(username + " logged out.")
  264. }
  265. // Revoke users authentication
  266. err := a.Logout(w, r)
  267. if err != nil {
  268. sendErrorResponse(w, "Logout failed")
  269. return
  270. }
  271. w.Write([]byte("OK"))
  272. }
  273. func (a *AuthAgent) Logout(w http.ResponseWriter, r *http.Request) error {
  274. session, err := a.SessionStore.Get(r, a.SessionName)
  275. if err != nil {
  276. return err
  277. }
  278. session.Values["authenticated"] = false
  279. session.Values["username"] = nil
  280. session.Save(r, w)
  281. return nil
  282. }
  283. //Get the current session username from request
  284. func (a *AuthAgent) GetUserName(w http.ResponseWriter, r *http.Request) (string, error) {
  285. if a.CheckAuth(r) {
  286. //This user has logged in.
  287. session, _ := a.SessionStore.Get(r, a.SessionName)
  288. return session.Values["username"].(string), nil
  289. } else {
  290. //This user has not logged in.
  291. return "", errors.New("User not logged in")
  292. }
  293. }
  294. //Check if the user has logged in, return true / false in JSON
  295. func (a *AuthAgent) CheckLogin(w http.ResponseWriter, r *http.Request) {
  296. if a.CheckAuth(r) != false {
  297. sendJSONResponse(w, "true")
  298. } else {
  299. sendJSONResponse(w, "false")
  300. }
  301. }
  302. //Handle new user register. Require POST username, password, group.
  303. func (a *AuthAgent) HandleRegister(w http.ResponseWriter, r *http.Request) {
  304. userCount := a.GetUserCounts()
  305. //Get username from request
  306. newusername, err := mv(r, "username", true)
  307. if err != nil {
  308. sendTextResponse(w, "Error. Missing 'username' paramter")
  309. return
  310. }
  311. //Get password from request
  312. password, err := mv(r, "password", true)
  313. if err != nil {
  314. sendTextResponse(w, "Error. Missing 'password' paramter")
  315. return
  316. }
  317. //Set permission group to default
  318. group, err := mv(r, "group", true)
  319. if err != nil {
  320. sendTextResponse(w, "Error. Missing 'group' paramter")
  321. return
  322. }
  323. //Check if the number of users in the system is == 0. If yes, there are no need to login before registering new user
  324. if userCount > 0 {
  325. //Require login to create new user
  326. if a.CheckAuth(r) == false {
  327. //System have more than one person and this user is not logged in
  328. sendErrorResponse(w, "Login is needed to create new user")
  329. return
  330. }
  331. }
  332. //Ok to proceed create this user
  333. err = a.CreateUserAccount(newusername, password, []string{group})
  334. if err != nil {
  335. sendErrorResponse(w, err.Error())
  336. return
  337. }
  338. //Return to the client with OK
  339. sendOK(w)
  340. log.Println("[System Auth] New user " + newusername + " added to system.")
  341. return
  342. }
  343. //Check authentication from request header's session value
  344. func (a *AuthAgent) CheckAuth(r *http.Request) bool {
  345. session, _ := a.SessionStore.Get(r, a.SessionName)
  346. // Check if user is authenticated
  347. if auth, ok := session.Values["authenticated"].(bool); !ok || !auth {
  348. return false
  349. }
  350. return true
  351. }
  352. //Handle de-register of users. Require POST username.
  353. //THIS FUNCTION WILL NOT CHECK FOR PERMISSION. PLEASE USE WITH PERMISSION HANDLER
  354. func (a *AuthAgent) HandleUnregister(w http.ResponseWriter, r *http.Request) {
  355. //Check if the user is logged in
  356. if a.CheckAuth(r) == false {
  357. //This user has not logged in
  358. sendErrorResponse(w, "Login required to remove user from the system.")
  359. return
  360. }
  361. //Check for permission of this user.
  362. /*
  363. if !system_permission_checkUserIsAdmin(w,r){
  364. //This user is not admin. No permission to access this function
  365. sendErrorResponse(w, "Permission denied")
  366. }
  367. */
  368. //Get username from request
  369. username, err := mv(r, "username", true)
  370. if err != nil {
  371. sendErrorResponse(w, "Missing 'username' paramter")
  372. return
  373. }
  374. err = a.UnregisterUser(username)
  375. if err != nil {
  376. sendErrorResponse(w, err.Error())
  377. return
  378. }
  379. //Return to the client with OK
  380. sendOK(w)
  381. log.Println("[system_auth] User " + username + " has been removed from the system.")
  382. return
  383. }
  384. func (a *AuthAgent) UnregisterUser(username string) error {
  385. //Check if the user exists in the system database.
  386. if !a.Database.KeyExists("auth", "passhash/"+username) {
  387. //This user do not exists.
  388. return errors.New("This user does not exists.")
  389. }
  390. //OK! Remove the user from the database
  391. a.Database.Delete("auth", "passhash/"+username)
  392. a.Database.Delete("auth", "group/"+username)
  393. a.Database.Delete("auth", "acstatus/"+username)
  394. a.Database.Delete("auth", "profilepic/"+username)
  395. //Remove the user's autologin tokens
  396. a.RemoveAutologinTokenByUsername(username)
  397. return nil
  398. }
  399. //Get the number of users in the system
  400. func (a *AuthAgent) GetUserCounts() int {
  401. entries, _ := a.Database.ListTable("auth")
  402. usercount := 0
  403. for _, keypairs := range entries {
  404. if strings.Contains(string(keypairs[0]), "passhash/") {
  405. //This is a user registry
  406. usercount++
  407. }
  408. }
  409. if usercount == 0 {
  410. log.Println("There are no user in the database.")
  411. }
  412. return usercount
  413. }
  414. //List all username within the system
  415. func (a *AuthAgent) ListUsers() []string {
  416. entries, _ := a.Database.ListTable("auth")
  417. results := []string{}
  418. for _, keypairs := range entries {
  419. if strings.Contains(string(keypairs[0]), "group/") {
  420. username := strings.Split(string(keypairs[0]), "/")[1]
  421. results = append(results, username)
  422. }
  423. }
  424. return results
  425. }
  426. //Check if the given username exists
  427. func (a *AuthAgent) UserExists(username string) bool {
  428. userpasswordhash := ""
  429. err := a.Database.Read("auth", "passhash/"+username, &userpasswordhash)
  430. if err != nil || userpasswordhash == "" {
  431. return false
  432. }
  433. return true
  434. }
  435. //Update the session expire time given the request header.
  436. func (a *AuthAgent) UpdateSessionExpireTime(w http.ResponseWriter, r *http.Request) bool {
  437. session, _ := a.SessionStore.Get(r, a.SessionName)
  438. if session.Values["authenticated"].(bool) == true {
  439. //User authenticated. Extend its expire time
  440. rememberme := session.Values["rememberMe"].(bool)
  441. //Extend the session expire time
  442. if rememberme == true {
  443. session.Options = &sessions.Options{
  444. MaxAge: 3600 * 24 * 7, //One week
  445. Path: "/",
  446. }
  447. } else {
  448. session.Options = &sessions.Options{
  449. MaxAge: 3600 * 1, //One hour
  450. Path: "/",
  451. }
  452. }
  453. session.Save(r, w)
  454. return true
  455. } else {
  456. return false
  457. }
  458. }
  459. //Create user account
  460. func (a *AuthAgent) CreateUserAccount(newusername string, password string, group []string) error {
  461. key := newusername
  462. hashedPassword := Hash(password)
  463. err := a.Database.Write("auth", "passhash/"+key, hashedPassword)
  464. if err != nil {
  465. return err
  466. }
  467. //Store this user's usergroup settings
  468. err = a.Database.Write("auth", "group/"+newusername, group)
  469. if err != nil {
  470. return err
  471. }
  472. return nil
  473. }
  474. //Hash the given raw string into sha512 hash
  475. func Hash(raw string) string {
  476. h := sha512.New()
  477. h.Write([]byte(raw))
  478. return hex.EncodeToString(h.Sum(nil))
  479. }