Now storing hashed auth tokens
This commit is contained in:
@@ -32,6 +32,8 @@
|
|||||||
|
|
||||||
namespace Auth {
|
namespace Auth {
|
||||||
|
|
||||||
|
static const Wt::Auth::SHA1HashFunction sha1Function;
|
||||||
|
|
||||||
AuthTokenService::AuthTokenService(std::size_t maxThrottlerEntries)
|
AuthTokenService::AuthTokenService(std::size_t maxThrottlerEntries)
|
||||||
: _loginThrottler {maxThrottlerEntries}
|
: _loginThrottler {maxThrottlerEntries}
|
||||||
{
|
{
|
||||||
@@ -40,7 +42,8 @@ AuthTokenService::AuthTokenService(std::size_t maxThrottlerEntries)
|
|||||||
std::string
|
std::string
|
||||||
AuthTokenService::createAuthToken(Database::Session& session, Database::IdType userId, const Wt::WDateTime& expiry)
|
AuthTokenService::createAuthToken(Database::Session& session, Database::IdType userId, const Wt::WDateTime& expiry)
|
||||||
{
|
{
|
||||||
const std::string secret {Wt::WRandom::generateId(64)};
|
const std::string secret {Wt::WRandom::generateId(32)};
|
||||||
|
const std::string secretHash {sha1Function.compute(secret, {})};
|
||||||
|
|
||||||
auto transaction {session.createUniqueTransaction()};
|
auto transaction {session.createUniqueTransaction()};
|
||||||
|
|
||||||
@@ -48,7 +51,7 @@ AuthTokenService::createAuthToken(Database::Session& session, Database::IdType u
|
|||||||
if (!user)
|
if (!user)
|
||||||
throw LmsException {"User deleted"};
|
throw LmsException {"User deleted"};
|
||||||
|
|
||||||
Database::AuthToken::pointer authToken {Database::AuthToken::create(session, secret, expiry, user)};
|
Database::AuthToken::pointer authToken {Database::AuthToken::create(session, secretHash, expiry, user)};
|
||||||
|
|
||||||
LMS_LOG(UI, DEBUG) << "Created auth token for user '" << user->getLoginName() << "', expiry = " << expiry.toString();
|
LMS_LOG(UI, DEBUG) << "Created auth token for user '" << user->getLoginName() << "', expiry = " << expiry.toString();
|
||||||
|
|
||||||
@@ -60,11 +63,13 @@ AuthTokenService::createAuthToken(Database::Session& session, Database::IdType u
|
|||||||
|
|
||||||
static
|
static
|
||||||
boost::optional<AuthTokenService::AuthTokenProcessResult::AuthTokenInfo>
|
boost::optional<AuthTokenService::AuthTokenProcessResult::AuthTokenInfo>
|
||||||
processAuthToken(Database::Session& session, const std::string& tokenValue)
|
processAuthToken(Database::Session& session, const std::string& secret)
|
||||||
{
|
{
|
||||||
|
const std::string secretHash {sha1Function.compute(secret, {})};
|
||||||
|
|
||||||
auto transaction {session.createUniqueTransaction()};
|
auto transaction {session.createUniqueTransaction()};
|
||||||
|
|
||||||
Database::AuthToken::pointer authToken {Database::AuthToken::getByValue(session, tokenValue)};
|
Database::AuthToken::pointer authToken {Database::AuthToken::getByValue(session, secretHash)};
|
||||||
if (!authToken)
|
if (!authToken)
|
||||||
return boost::none;
|
return boost::none;
|
||||||
|
|
||||||
|
|||||||
@@ -35,7 +35,7 @@
|
|||||||
|
|
||||||
namespace Database {
|
namespace Database {
|
||||||
|
|
||||||
#define LMS_DATABASE_VERSION 5
|
#define LMS_DATABASE_VERSION 6
|
||||||
|
|
||||||
using Version = std::size_t;
|
using Version = std::size_t;
|
||||||
|
|
||||||
@@ -98,6 +98,10 @@ Session::doDatabaseMigrationIfNeeded()
|
|||||||
|
|
||||||
switch (version)
|
switch (version)
|
||||||
{
|
{
|
||||||
|
case 5:
|
||||||
|
LMS_LOG(DB, INFO) << "Migrating database from version 5...";
|
||||||
|
_session.execute("DELETE FROM auth_token"); // format has changed
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
LMS_LOG(DB, ERROR) << "Database version " << version << " cannot be handled using migration";
|
LMS_LOG(DB, ERROR) << "Database version " << version << " cannot be handled using migration";
|
||||||
throw LmsException { LMS_DATABASE_VERSION > version ? outdatedMsg : "Server binary outdated, please upgrade it to handle this database"};
|
throw LmsException { LMS_DATABASE_VERSION > version ? outdatedMsg : "Server binary outdated, please upgrade it to handle this database"};
|
||||||
|
|||||||
Reference in New Issue
Block a user