-
-
Notifications
You must be signed in to change notification settings - Fork 4.1k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
move verification token logic out of lost password controller
- to make it reusable - needed for local email verification Signed-off-by: Arthur Schiwon <[email protected]>
- Loading branch information
Showing
8 changed files
with
588 additions
and
340 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
111 changes: 111 additions & 0 deletions
111
lib/private/Security/VerificationToken/VerificationToken.php
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,111 @@ | ||
<?php | ||
|
||
declare(strict_types=1); | ||
|
||
/** | ||
* @copyright Copyright (c) 2021 Arthur Schiwon <blizzz@arthur-schiwon.de> | ||
* | ||
* @author Arthur Schiwon <blizzz@arthur-schiwon.de> | ||
* | ||
* @license GNU AGPL version 3 or any later version | ||
* | ||
* This program is free software: you can redistribute it and/or modify | ||
* it under the terms of the GNU Affero General Public License as | ||
* published by the Free Software Foundation, either version 3 of the | ||
* License, or (at your option) any later version. | ||
* | ||
* This program is distributed in the hope that it will be useful, | ||
* but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
* GNU Affero General Public License for more details. | ||
* | ||
* You should have received a copy of the GNU Affero General Public License | ||
* along with this program. If not, see <https://www.gnu.org/licenses/>. | ||
* | ||
*/ | ||
|
||
namespace OC\Security\VerificationToken; | ||
|
||
use OCP\AppFramework\Utility\ITimeFactory; | ||
use OCP\IConfig; | ||
use OCP\IUser; | ||
use OCP\Security\ICrypto; | ||
use OCP\Security\ISecureRandom; | ||
use OCP\Security\VerificationToken\InvalidTokenException; | ||
use OCP\Security\VerificationToken\IVerificationToken; | ||
|
||
class VerificationToken implements IVerificationToken { | ||
|
||
/** @var IConfig */ | ||
private $config; | ||
/** @var ICrypto */ | ||
private $crypto; | ||
/** @var ITimeFactory */ | ||
private $timeFactory; | ||
/** @var ISecureRandom */ | ||
private $secureRandom; | ||
|
||
public function __construct( | ||
IConfig $config, | ||
ICrypto $crypto, | ||
ITimeFactory $timeFactory, | ||
ISecureRandom $secureRandom | ||
) { | ||
$this->config = $config; | ||
$this->crypto = $crypto; | ||
$this->timeFactory = $timeFactory; | ||
$this->secureRandom = $secureRandom; | ||
} | ||
|
||
/** | ||
* @throws InvalidTokenException | ||
*/ | ||
protected function throwInvalidTokenException(int $code): void { | ||
throw new InvalidTokenException($code); | ||
} | ||
|
||
public function check(string $token, ?IUser $user, string $subject, string $passwordPrefix = ''): void { | ||
if ($user === null || !$user->isEnabled()) { | ||
$this->throwInvalidTokenException(InvalidTokenException::USER_UNKNOWN); | ||
} | ||
|
||
$encryptedToken = $this->config->getUserValue($user->getUID(), 'core', $subject, null); | ||
if ($encryptedToken === null) { | ||
$this->throwInvalidTokenException(InvalidTokenException::TOKEN_NOT_FOUND); | ||
} | ||
|
||
try { | ||
$decryptedToken = $this->crypto->decrypt($encryptedToken, $passwordPrefix.$this->config->getSystemValue('secret')); | ||
} catch (\Exception $e) { | ||
$this->throwInvalidTokenException(InvalidTokenException::TOKEN_DECRYPTION_ERROR); | ||
} | ||
|
||
$splitToken = explode(':', $decryptedToken ?? ''); | ||
if (count($splitToken) !== 2) { | ||
$this->throwInvalidTokenException(InvalidTokenException::TOKEN_INVALID_FORMAT); | ||
} | ||
|
||
if ($splitToken[0] < ($this->timeFactory->getTime() - 60 * 60 * 24 * 7) || | ||
$user->getLastLogin() > $splitToken[0]) { | ||
$this->throwInvalidTokenException(InvalidTokenException::TOKEN_EXPIRED); | ||
} | ||
|
||
if (!hash_equals($splitToken[1], $token)) { | ||
$this->throwInvalidTokenException(InvalidTokenException::TOKEN_MISMATCH); | ||
} | ||
} | ||
|
||
public function create(IUser $user, string $subject, string $passwordPrefix = ''): string { | ||
$token = $this->secureRandom->generate( | ||
21, | ||
ISecureRandom::CHAR_DIGITS. | ||
ISecureRandom::CHAR_LOWER. | ||
ISecureRandom::CHAR_UPPER | ||
); | ||
$tokenValue = $this->timeFactory->getTime() .':'. $token; | ||
$encryptedValue = $this->crypto->encrypt($tokenValue, $passwordPrefix . $this->config->getSystemValue('secret')); | ||
$this->config->setUserValue($user->getUID(), 'core', $subject, $encryptedValue); | ||
|
||
return $token; | ||
} | ||
} |
55 changes: 55 additions & 0 deletions
55
lib/public/Security/VerificationToken/IVerificationToken.php
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,55 @@ | ||
<?php | ||
|
||
declare(strict_types=1); | ||
|
||
/** | ||
* @copyright Copyright (c) 2021 Arthur Schiwon <blizzz@arthur-schiwon.de> | ||
* | ||
* @author Arthur Schiwon <blizzz@arthur-schiwon.de> | ||
* | ||
* @license GNU AGPL version 3 or any later version | ||
* | ||
* This program is free software: you can redistribute it and/or modify | ||
* it under the terms of the GNU Affero General Public License as | ||
* published by the Free Software Foundation, either version 3 of the | ||
* License, or (at your option) any later version. | ||
* | ||
* This program is distributed in the hope that it will be useful, | ||
* but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
* GNU Affero General Public License for more details. | ||
* | ||
* You should have received a copy of the GNU Affero General Public License | ||
* along with this program. If not, see <https://www.gnu.org/licenses/>. | ||
* | ||
*/ | ||
|
||
namespace OCP\Security\VerificationToken; | ||
|
||
use OCP\IUser; | ||
|
||
/** | ||
* @since 23.0.0 | ||
*/ | ||
interface IVerificationToken { | ||
|
||
/** | ||
* Checks whether the a provided tokent matches a stored token and its | ||
* constraints. An InvalidTokenException is thrown on issues, otherwise | ||
* the check is successful. | ||
* | ||
* null can be passed as $user, but mind that this is for conveniently | ||
* passing the return of IUserManager::getUser() to this method. When | ||
* $user is null, InvalidTokenException is thrown for all the issued | ||
* tokens are user related. | ||
* | ||
* @throws InvalidTokenException | ||
* @since 23.0.0 | ||
*/ | ||
public function check(string $token, ?IUser $user, string $subject, string $passwordPrefix = ''): void; | ||
|
||
/** | ||
* @since 23.0.0 | ||
*/ | ||
public function create(IUser $user, string $subject, string $passwordPrefix = ''): string; | ||
} |
Oops, something went wrong.