Now storing hashed auth tokens

This commit is contained in:
emeric
2019-08-07 13:15:33 +02:00
parent f8cb16954b
commit 4d118221fb
2 changed files with 14 additions and 5 deletions
+9 -4
View File
@@ -32,6 +32,8 @@
namespace Auth { namespace Auth {
static const Wt::Auth::SHA1HashFunction sha1Function;
AuthTokenService::AuthTokenService(std::size_t maxThrottlerEntries) AuthTokenService::AuthTokenService(std::size_t maxThrottlerEntries)
: _loginThrottler {maxThrottlerEntries} : _loginThrottler {maxThrottlerEntries}
{ {
@@ -40,7 +42,8 @@ AuthTokenService::AuthTokenService(std::size_t maxThrottlerEntries)
std::string std::string
AuthTokenService::createAuthToken(Database::Session& session, Database::IdType userId, const Wt::WDateTime& expiry) AuthTokenService::createAuthToken(Database::Session& session, Database::IdType userId, const Wt::WDateTime& expiry)
{ {
const std::string secret {Wt::WRandom::generateId(64)}; const std::string secret {Wt::WRandom::generateId(32)};
const std::string secretHash {sha1Function.compute(secret, {})};
auto transaction {session.createUniqueTransaction()}; auto transaction {session.createUniqueTransaction()};
@@ -48,7 +51,7 @@ AuthTokenService::createAuthToken(Database::Session& session, Database::IdType u
if (!user) if (!user)
throw LmsException {"User deleted"}; throw LmsException {"User deleted"};
Database::AuthToken::pointer authToken {Database::AuthToken::create(session, secret, expiry, user)}; Database::AuthToken::pointer authToken {Database::AuthToken::create(session, secretHash, expiry, user)};
LMS_LOG(UI, DEBUG) << "Created auth token for user '" << user->getLoginName() << "', expiry = " << expiry.toString(); LMS_LOG(UI, DEBUG) << "Created auth token for user '" << user->getLoginName() << "', expiry = " << expiry.toString();
@@ -60,11 +63,13 @@ AuthTokenService::createAuthToken(Database::Session& session, Database::IdType u
static static
boost::optional<AuthTokenService::AuthTokenProcessResult::AuthTokenInfo> boost::optional<AuthTokenService::AuthTokenProcessResult::AuthTokenInfo>
processAuthToken(Database::Session& session, const std::string& tokenValue) processAuthToken(Database::Session& session, const std::string& secret)
{ {
const std::string secretHash {sha1Function.compute(secret, {})};
auto transaction {session.createUniqueTransaction()}; auto transaction {session.createUniqueTransaction()};
Database::AuthToken::pointer authToken {Database::AuthToken::getByValue(session, tokenValue)}; Database::AuthToken::pointer authToken {Database::AuthToken::getByValue(session, secretHash)};
if (!authToken) if (!authToken)
return boost::none; return boost::none;
+5 -1
View File
@@ -35,7 +35,7 @@
namespace Database { namespace Database {
#define LMS_DATABASE_VERSION 5 #define LMS_DATABASE_VERSION 6
using Version = std::size_t; using Version = std::size_t;
@@ -98,6 +98,10 @@ Session::doDatabaseMigrationIfNeeded()
switch (version) switch (version)
{ {
case 5:
LMS_LOG(DB, INFO) << "Migrating database from version 5...";
_session.execute("DELETE FROM auth_token"); // format has changed
break;
default: default:
LMS_LOG(DB, ERROR) << "Database version " << version << " cannot be handled using migration"; LMS_LOG(DB, ERROR) << "Database version " << version << " cannot be handled using migration";
throw LmsException { LMS_DATABASE_VERSION > version ? outdatedMsg : "Server binary outdated, please upgrade it to handle this database"}; throw LmsException { LMS_DATABASE_VERSION > version ? outdatedMsg : "Server binary outdated, please upgrade it to handle this database"};