Add U2F support

This commit is contained in:
Jonas Lochmann
2022-09-22 08:47:06 +02:00
parent 04aa2ce517
commit 613776cbf9
64 changed files with 2501 additions and 134 deletions
+52
View File
@@ -0,0 +1,52 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { ParentAction } from './basetypes'
import { throwOutOfRange } from './meta/util'
const actionType = 'AddParentU2fKey'
export class AddParentU2fKeyAction extends ParentAction {
readonly keyHandle: Buffer
readonly publicKey: Buffer
constructor ({ keyHandle, publicKey }: {
keyHandle: Buffer
publicKey: Buffer
}) {
super()
if (keyHandle.length > 2048) throwOutOfRange({ actionType, field: 'keyHandle', value: keyHandle.length })
if (publicKey.length > 2048) throwOutOfRange({ actionType, field: 'publicKey', value: publicKey.length })
this.keyHandle = keyHandle
this.publicKey = publicKey
}
static parse = ({ keyHandle, publicKey }: SerializedAddParentU2fKeyAction) => (
new AddParentU2fKeyAction({
keyHandle: Buffer.from(keyHandle, 'base64'),
publicKey: Buffer.from(publicKey, 'base64')
})
)
}
export interface SerializedAddParentU2fKeyAction {
type: 'ADD_PARENT_U2F'
keyHandle: string
publicKey: string
}
+3
View File
@@ -21,6 +21,7 @@ export { AddCategoryAppsAction } from './addcategoryapps'
export { AddCategoryNetworkIdAction } from './addcategorynetworkid'
export { AddUserAction } from './adduser'
export { AddInstalledAppsAction } from './addinstalledapps'
export { AddParentU2fKeyAction } from './addu2fkey'
export { AddUsedTimeAction } from './addusedtime'
export { AddUsedTimeActionVersion2 } from './addusedtime2'
export { ChangeParentPasswordAction } from './changeparentpassword'
@@ -36,10 +37,12 @@ export { IgnoreManipulationAction } from './ignoremanipulation'
export { IncrementCategoryExtraTimeAction } from './incrementcategoryextratime'
export { RemoveCategoryAppsAction } from './removecategoryapps'
export { RemoveInstalledAppsAction } from './removeinstalledapps'
export { RemoveParentU2fKeyAction } from './removeu2fkey'
export { RemoveUserAction } from './removeuser'
export { ResetCategoryNetworkIdsAction } from './resetcategorynetworkids'
export { RenameChildAction } from './renamechild'
export { ReplyToKeyRequestAction } from './replytokeyrequest'
export { ReportU2fLoginAction } from './reportu2flogin'
export { SetCategoryExtraTimeAction } from './setcategoryextratime'
export { SetCategoryForUnassignedAppsAction } from './setcategoryforunassignedapps'
export { SetChildPasswordAction } from './setchildpassword'
+52
View File
@@ -0,0 +1,52 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { ParentAction } from './basetypes'
import { throwOutOfRange } from './meta/util'
const actionType = 'RemoveParentU2FKey'
export class RemoveParentU2fKeyAction extends ParentAction {
readonly keyHandle: Buffer
readonly publicKey: Buffer
constructor ({ keyHandle, publicKey }: {
keyHandle: Buffer
publicKey: Buffer
}) {
super()
if (keyHandle.length > 2048) throwOutOfRange({ actionType, field: 'keyHandle', value: keyHandle.length })
if (publicKey.length > 2048) throwOutOfRange({ actionType, field: 'publicKey', value: publicKey.length })
this.keyHandle = keyHandle
this.publicKey = publicKey
}
static parse = ({ keyHandle, publicKey }: SerializedRemoveParentU2fKeyAction) => (
new RemoveParentU2fKeyAction({
keyHandle: Buffer.from(keyHandle, 'base64'),
publicKey: Buffer.from(publicKey, 'base64')
})
)
}
export interface SerializedRemoveParentU2fKeyAction {
type: 'REMOVE_PARENT_U2F'
keyHandle: string
publicKey: string
}
+30
View File
@@ -0,0 +1,30 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { ParentAction } from './basetypes'
export class ReportU2fLoginAction extends ParentAction {
static instance = new ReportU2fLoginAction()
private constructor () {
super()
}
}
export interface SerializedReportU2fLoginAction {
type: 'REPORT_U2F_LOGIN'
}
+13 -1
View File
@@ -1,6 +1,6 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2021 Jonas Lochmann
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
@@ -17,6 +17,7 @@
import { AddCategoryAppsAction, SerializedAddCategoryAppsAction } from '../addcategoryapps'
import { AddCategoryNetworkIdAction, SerializedAddCategoryNetworkIdAction } from '../addcategorynetworkid'
import { AddParentU2fKeyAction, SerializedAddParentU2fKeyAction } from '../addu2fkey'
import { AddUserAction, SerializedAddUserAction } from '../adduser'
import { ParentAction } from '../basetypes'
import { ChangeParentPasswordAction, SerializedChangeParentPasswordAction } from '../changeparentpassword'
@@ -27,8 +28,10 @@ import { DeleteChildTaskAction, SerializedDeleteChildTaskAction } from '../delet
import { DeleteTimeLimitRuleAction, SerializedDeleteTimeLimitRuleAction } from '../deletetimelimitrule'
import { IgnoreManipulationAction, SerializedIgnoreManipulationAction } from '../ignoremanipulation'
import { IncrementCategoryExtraTimeAction, SerializedIncrementCategoryExtraTimeAction } from '../incrementcategoryextratime'
import { ReportU2fLoginAction, SerializedReportU2fLoginAction } from '../reportu2flogin'
import { UnknownActionTypeException } from '../meta/exception'
import { RemoveCategoryAppsAction, SerializedRemoveCategoryAppsAction } from '../removecategoryapps'
import { RemoveParentU2fKeyAction, SerializedRemoveParentU2fKeyAction } from '../removeu2fkey'
import { RemoveUserAction, SerializedRemoveUserAction } from '../removeuser'
import { RenameChildAction, SerializedRenameChildAction } from '../renamechild'
import { ResetCategoryNetworkIdsAction, SerializeResetCategoryNetworkIdsAction } from '../resetcategorynetworkids'
@@ -68,6 +71,7 @@ import { SerializedUpdateUserLimitLoginPreBlockDuration, UpdateUserLimitLoginPre
export type SerializedParentAction =
SerializedAddCategoryAppsAction |
SerializedAddCategoryNetworkIdAction |
SerializedAddParentU2fKeyAction |
SerializedAddUserAction |
SerializedChangeParentPasswordAction |
SerializedCreateCategoryAction |
@@ -77,7 +81,9 @@ export type SerializedParentAction =
SerializedDeleteTimeLimitRuleAction |
SerializedIgnoreManipulationAction |
SerializedIncrementCategoryExtraTimeAction |
SerializedReportU2fLoginAction |
SerializedRemoveCategoryAppsAction |
SerializedRemoveParentU2fKeyAction |
SerializedRemoveUserAction |
SerializedRenameChildAction |
SerializeResetCategoryNetworkIdsAction |
@@ -119,6 +125,8 @@ export const parseParentAction = (action: SerializedParentAction): ParentAction
return AddCategoryAppsAction.parse(action)
} else if (action.type === 'ADD_CATEGORY_NETWORK_ID') {
return AddCategoryNetworkIdAction.parse(action)
} else if (action.type === 'ADD_PARENT_U2F') {
return AddParentU2fKeyAction.parse(action)
} else if (action.type === 'ADD_USER') {
return AddUserAction.parse(action)
} else if (action.type === 'CHANGE_PARENT_PASSWORD') {
@@ -137,8 +145,12 @@ export const parseParentAction = (action: SerializedParentAction): ParentAction
return IgnoreManipulationAction.parse(action)
} else if (action.type === 'INCREMENT_CATEGORY_EXTRATIME') {
return IncrementCategoryExtraTimeAction.parse(action)
} else if (action.type === 'REPORT_U2F_LOGIN') {
return ReportU2fLoginAction.instance
} else if (action.type === 'REMOVE_CATEGORY_APPS') {
return RemoveCategoryAppsAction.parse(action)
} else if (action.type === 'REMOVE_PARENT_U2F') {
return RemoveParentU2fKeyAction.parse(action)
} else if (action.type === 'REMOVE_USER') {
return RemoveUserAction.parse(action)
} else if (action.type === 'RENAME_CHILD') {
+52
View File
@@ -16,6 +16,7 @@
*/
import { json } from 'body-parser'
import { createHmac } from 'crypto'
import { Router } from 'express'
import { BadRequest, Forbidden, Unauthorized } from 'http-errors'
import { config } from '../config'
@@ -27,6 +28,7 @@ import { getStatusByMailToken } from '../function/parent/get-status-by-mail-addr
import { linkMailAddress } from '../function/parent/link-mail-address'
import { recoverParentPassword } from '../function/parent/recover-parent-password'
import { signInIntoFamily } from '../function/parent/sign-in-into-family'
import { validateU2fIntegrity, U2fValidationError } from '../function/u2f'
import { createIdentityToken, MissingSignSecretException } from '../util/identity-token'
import { WebsocketApi } from '../websocket'
import {
@@ -168,6 +170,56 @@ export const createParentRouter = ({ database, websocket }: {database: Database,
}
return { deviceEntry, parentEntry }
} else if (secondPasswordHash.startsWith('u2f:')) {
try {
const familyEntryUnsafe = await database.family.findOne({
where: {
familyId: deviceEntry.familyId
},
transaction,
attributes: ['hasFullVersion']
})
if (!familyEntryUnsafe) {
throw new Unauthorized()
}
const familyEntry = { hasFullVersion: familyEntryUnsafe.hasFullVersion }
const hasFullVersion = familyEntry.hasFullVersion || config.alwaysPro
const u2fResult = await validateU2fIntegrity({
integrity: secondPasswordHash,
hasFullVersion,
familyId: deviceEntry.familyId,
deviceId: deviceEntry.deviceId,
database,
transaction,
calculateHmac: (secret) => createHmac('sha256', secret)
.update('direct action')
.digest()
})
if (u2fResult.userId !== parentId) throw new Unauthorized()
const parentEntry = await database.user.findOne({
where: {
familyId: deviceEntry.familyId,
type: 'parent',
userId: u2fResult.userId
},
transaction
})
if (!parentEntry) {
throw new Unauthorized()
}
return { deviceEntry, parentEntry }
} catch (ex) {
if (ex instanceof U2fValidationError) throw new Unauthorized()
else throw ex
}
} else {
const parentEntry = await database.user.findOne({
where: {
+1
View File
@@ -132,6 +132,7 @@ export const createSyncRouter = ({ database, websocket, connectedDevicesManager,
if (serverStatus.krq) { eventHandler.countEvent('pullStatusRequest pendingKeyRequests') }
if (serverStatus.kr) { eventHandler.countEvent('pullStatusRequest keyResponses') }
if (serverStatus.dh) { eventHandler.countEvent('pullStatusRequest dh') }
if (serverStatus.u2f) { eventHandler.countEvent('pullStatusRequest u2f') }
res.json(serverStatus)
} catch (ex) {
+116
View File
@@ -75,6 +75,9 @@ const definitions = {
},
"dh": {
"type": "string"
},
"u2f": {
"type": "string"
}
},
"additionalProperties": false,
@@ -209,6 +212,29 @@ const definitions = {
"type"
]
},
"SerializedAddParentU2fKeyAction": {
"type": "object",
"properties": {
"type": {
"type": "string",
"enum": [
"ADD_PARENT_U2F"
]
},
"keyHandle": {
"type": "string"
},
"publicKey": {
"type": "string"
}
},
"additionalProperties": false,
"required": [
"keyHandle",
"publicKey",
"type"
]
},
"SerializedAddUserAction": {
"type": "object",
"properties": {
@@ -535,6 +561,21 @@ const definitions = {
"type"
]
},
"SerializedReportU2fLoginAction": {
"type": "object",
"properties": {
"type": {
"type": "string",
"enum": [
"REPORT_U2F_LOGIN"
]
}
},
"additionalProperties": false,
"required": [
"type"
]
},
"SerializedRemoveCategoryAppsAction": {
"type": "object",
"properties": {
@@ -561,6 +602,29 @@ const definitions = {
"type"
]
},
"SerializedRemoveParentU2fKeyAction": {
"type": "object",
"properties": {
"type": {
"type": "string",
"enum": [
"REMOVE_PARENT_U2F"
]
},
"keyHandle": {
"type": "string"
},
"publicKey": {
"type": "string"
}
},
"additionalProperties": false,
"required": [
"keyHandle",
"publicKey",
"type"
]
},
"SerializedRemoveUserAction": {
"type": "object",
"properties": {
@@ -2747,6 +2811,49 @@ const definitions = {
"k",
"v"
]
},
"U2fData": {
"type": "object",
"properties": {
"v": {
"type": "string"
},
"d": {
"type": "array",
"items": {
"$ref": "#/definitions/U2fItem"
}
}
},
"additionalProperties": false,
"required": [
"d",
"v"
]
},
"U2fItem": {
"type": "object",
"properties": {
"u": {
"type": "string"
},
"a": {
"type": "number"
},
"h": {
"type": "string"
},
"p": {
"type": "string"
}
},
"additionalProperties": false,
"required": [
"a",
"h",
"p",
"u"
]
}
}
@@ -2907,6 +3014,9 @@ export const isSerializedParentAction: (value: unknown) => value is SerializedPa
{
"$ref": "#/definitions/SerializedAddCategoryNetworkIdAction"
},
{
"$ref": "#/definitions/SerializedAddParentU2fKeyAction"
},
{
"$ref": "#/definitions/SerializedAddUserAction"
},
@@ -2934,9 +3044,15 @@ export const isSerializedParentAction: (value: unknown) => value is SerializedPa
{
"$ref": "#/definitions/SerializedIncrementCategoryExtraTimeAction"
},
{
"$ref": "#/definitions/SerializedReportU2fLoginAction"
},
{
"$ref": "#/definitions/SerializedRemoveCategoryAppsAction"
},
{
"$ref": "#/definitions/SerializedRemoveParentU2fKeyAction"
},
{
"$ref": "#/definitions/SerializedRemoveUserAction"
},
+15 -2
View File
@@ -33,7 +33,12 @@ export interface FamilyAttributesVersion2 {
nextServerKeyRequestSeq: string
}
export type FamilyAttributes = FamilyAttributesVersion1 & FamilyAttributesVersion2
export interface FamilyAttributesVersion3 {
u2fKeysVersion: string
}
export type FamilyAttributes = FamilyAttributesVersion1 &
FamilyAttributesVersion2 & FamilyAttributesVersion3
export type FamilyModel = Sequelize.Model<FamilyAttributes> & FamilyAttributes
export type FamilyModelStatic = typeof Sequelize.Model & {
@@ -64,9 +69,17 @@ export const attributesVersion2: SequelizeAttributes<FamilyAttributesVersion2> =
}
}
export const attributesVersion3: SequelizeAttributes<FamilyAttributesVersion3> = {
u2fKeysVersion: {
...versionColumn,
defaultValue: '0000'
}
}
export const attributes: SequelizeAttributes<FamilyAttributes> = {
...attributesVersion1,
...attributesVersion2
...attributesVersion2,
...attributesVersion3
}
export const createFamilyModel = (sequelize: Sequelize.Sequelize): FamilyModelStatic => sequelize.define('Family', attributes) as FamilyModelStatic
+3
View File
@@ -38,6 +38,7 @@ import { createOldDeviceModel, OldDeviceModelStatic } from './olddevice'
import { createPurchaseModel, PurchaseModelStatic } from './purchase'
import { createSessionDurationModel, SessionDurationModelStatic } from './sessionduration'
import { createTimelimitRuleModel, TimelimitRuleModelStatic } from './timelimitrule'
import { createU2fKeyModel, U2fKeyModelStatic } from './u2fkey'
import { createUsedTimeModel, UsedTimeModelStatic } from './usedtime'
import { createUserModel, UserModelStatic } from './user'
import { createUserLimitLoginCategoryModel, UserLimitLoginCategoryModelStatic } from './userlimitlogincategory'
@@ -66,6 +67,7 @@ export interface Database {
purchase: PurchaseModelStatic
sessionDuration: SessionDurationModelStatic
timelimitRule: TimelimitRuleModelStatic
u2fKey: U2fKeyModelStatic
usedTime: UsedTimeModelStatic
user: UserModelStatic
userLimitLoginCategory: UserLimitLoginCategoryModelStatic
@@ -95,6 +97,7 @@ const createDatabase = (sequelize: Sequelize.Sequelize): Database => ({
purchase: createPurchaseModel(sequelize),
sessionDuration: createSessionDurationModel(sequelize),
timelimitRule: createTimelimitRuleModel(sequelize),
u2fKey: createU2fKeyModel(sequelize),
usedTime: createUsedTimeModel(sequelize),
user: createUserModel(sequelize),
userLimitLoginCategory: createUserLimitLoginCategoryModel(sequelize),
@@ -0,0 +1,70 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { QueryInterface, Sequelize, Transaction } from 'sequelize'
export async function up (queryInterface: QueryInterface, sequelize: Sequelize) {
await sequelize.transaction({
type: Transaction.TYPES.EXCLUSIVE
}, async (transaction) => {
const dialect = sequelize.getDialect()
const isMysql = dialect === 'mysql' || dialect === 'mariadb'
const isPosgresql = dialect === 'postgres'
if (isMysql) {
await sequelize.query(
'CREATE TABLE `U2fKeys` ' +
'(`familyId` VARCHAR(10) NOT NULL,' +
'`keyId` VARCHAR(8) NOT NULL,' +
'`userId` VARCHAR(6) NOT NULL,' +
'`addedAt` BIGINT NOT NULL, ' +
'`keyHandle` BLOB NOT NULL, ' +
'`publicKey` BLOB NOT NULL, ' +
'`nextCounter` BIGINT NOT NULL, ' +
'PRIMARY KEY (`familyId`, `keyId`),' +
'FOREIGN KEY (`familyId`, `userId`) REFERENCES `Users` (`familyId`, `userId`) ON UPDATE CASCADE ON DELETE CASCADE' +
')',
{ transaction }
)
} else {
await sequelize.query(
'CREATE TABLE "U2fKeys" ' +
'("familyId" VARCHAR(10) NOT NULL,' +
'"keyId" VARCHAR(8) NOT NULL,' +
'"userId" VARCHAR(6) NOT NULL,' +
'"addedAt" ' + (isPosgresql ? 'BIGINT' : 'LONG') + ' NOT NULL, ' +
'"keyHandle" ' + (isPosgresql ? 'BYTEA' : 'BLOB') + ' NOT NULL, ' +
'"publicKey" ' + (isPosgresql ? 'BYTEA' : 'BLOB') + ' NOT NULL, ' +
'"nextCounter" ' + (isPosgresql ? 'BIGINT' : 'LONG') + ' NOT NULL, ' +
'PRIMARY KEY ("familyId", "keyId"),' +
'FOREIGN KEY ("familyId", "userId") REFERENCES "Users" ("familyId", "userId") ON UPDATE CASCADE ON DELETE CASCADE' +
')',
{ transaction }
)
}
await queryInterface.addIndex('U2fKeys', ['familyId', 'userId'], { transaction })
})
}
export async function down (queryInterface: QueryInterface, sequelize: Sequelize) {
await sequelize.transaction({
type: Transaction.TYPES.EXCLUSIVE
}, async (transaction) => {
await queryInterface.dropTable('U2fKeys', { transaction })
})
}
@@ -0,0 +1,39 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { QueryInterface, Sequelize, Transaction } from 'sequelize'
import { attributesVersion3 as familyAttributes } from '../../family'
export async function up (queryInterface: QueryInterface, sequelize: Sequelize) {
await sequelize.transaction({
type: Transaction.TYPES.EXCLUSIVE
}, async (transaction) => {
await queryInterface.addColumn('Families', 'u2fKeysVersion', {
...familyAttributes.u2fKeysVersion
}, {
transaction
})
})
}
export async function down (queryInterface: QueryInterface, sequelize: Sequelize) {
await sequelize.transaction({
type: Transaction.TYPES.EXCLUSIVE
}, async (transaction) => {
await queryInterface.removeColumn('Families', 'u2fKeysVersion', { transaction })
})
}
+82
View File
@@ -0,0 +1,82 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import * as Sequelize from 'sequelize'
import { createHash } from 'crypto'
import { familyIdColumn, idWithinFamilyColumn, timestampColumn } from './columns'
import { SequelizeAttributes } from './types'
import { intToBuffer } from '../util/binary-number'
export function getU2fKeyId({ keyHandle, publicKey }: {
keyHandle: Buffer
publicKey: Buffer
}) {
return createHash('sha256')
.update(intToBuffer(keyHandle.length))
.update(keyHandle)
.update(intToBuffer(publicKey.length))
.update(publicKey)
.digest()
.slice(0, 6)
.toString('base64')
}
export interface U2fKeyAttributes {
familyId: string
keyId: string
userId: string
addedAt: string
keyHandle: Buffer
publicKey: Buffer
nextCounter: string
}
export type U2fKeyModel = Sequelize.Model<U2fKeyAttributes> & U2fKeyAttributes
export type U2fKeyModelStatic = typeof Sequelize.Model & {
new (values?: object, options?: Sequelize.BuildOptions): U2fKeyModel;
}
export const attributes: SequelizeAttributes<U2fKeyAttributes> = {
familyId: {
...familyIdColumn,
primaryKey: true
},
keyId: {
type: Sequelize.STRING(8),
primaryKey: true
},
userId: {
...idWithinFamilyColumn
},
addedAt: {
...timestampColumn
},
keyHandle: {
type: Sequelize.BLOB,
allowNull: false
},
publicKey: {
type: Sequelize.BLOB,
allowNull: false
},
nextCounter: {
type: Sequelize.BIGINT,
allowNull: false
}
}
export const createU2fKeyModel = (sequelize: Sequelize.Sequelize): U2fKeyModelStatic => sequelize.define('U2fKey', attributes) as U2fKeyModelStatic
+14 -54
View File
@@ -16,10 +16,10 @@
*/
import * as Sequelize from 'sequelize'
import { createDecipheriv, createPrivateKey, createPublicKey, diffieHellman } from 'crypto'
import { createDecipheriv } from 'crypto'
import { Database } from '../../database'
import { calculateExpireTime } from '../../database/devicedhkey'
import { isVersionId } from '../../util/token'
import { getSharedSecret, SharedSecretException } from './shared-secret'
export async function decrypt({
database, transaction, familyId, deviceId, encryptedData, authData
@@ -43,61 +43,24 @@ export async function decrypt({
if (!isVersionId(keyId)) throw new KeyNotFoundDecryptException('invalid key id')
const databaseKeyEntry = await database.deviceDhKey.findOne({
where: {
familyId,
deviceId,
version: keyId
},
transaction
})
if (!databaseKeyEntry) throw new KeyNotFoundDecryptException('private key not found')
if (databaseKeyEntry.expireAt === null) {
databaseKeyEntry.expireAt = calculateExpireTime(BigInt(Date.now())).toString(10)
await databaseKeyEntry.save({ transaction })
} else {
if (BigInt(databaseKeyEntry.expireAt) < BigInt(Date.now())) throw new KeyExpiredDecryptException()
}
const privateKey = (() => {
const sharedSecret = await (async () => {
try {
return createPrivateKey({
key: databaseKeyEntry.privateKey,
format: 'der',
type: 'pkcs8'
return getSharedSecret({
database,
transaction,
familyId,
deviceId,
keyId,
otherPublicKey
})
} catch (ex) {
throw new MalformedPrivateKeyException()
}
})()
const decodedOtherPublicKey = (() => {
try {
return createPublicKey({
key: otherPublicKey,
format: 'der',
type: 'spki'
})
} catch (ex) {
throw new MalformedPublicKeyException()
}
})()
const sharedSecret = (() => {
try {
return diffieHellman({
privateKey,
publicKey: decodedOtherPublicKey
})
} catch (ex) {
throw new MalformedNoMatchingKeysException()
if (ex instanceof SharedSecretException) throw new SharedSecretDecryptException(ex)
throw ex
}
})()
try {
const decipher = createDecipheriv('aes-128-gcm', sharedSecret.slice(0, 16), ivAndEncrypted.slice(0, 12), {
const decipher = createDecipheriv('aes-128-gcm', sharedSecret.sharedSecret.slice(0, 16), ivAndEncrypted.slice(0, 12), {
authTagLength: 16
})
@@ -116,10 +79,7 @@ export async function decrypt({
}
export class DecryptException extends Error {}
class SharedSecretDecryptException extends DecryptException { constructor(cause: Error) { super(cause.message) } }
class MalformedDataDecryptException extends DecryptException { constructor(message: string) { super('malformed data: ' + message) } }
class MalformedPrivateKeyException extends DecryptException { constructor() { super('private key') } }
class MalformedPublicKeyException extends DecryptException { constructor() { super('public key') } }
class MalformedNoMatchingKeysException extends DecryptException { constructor() { super('no matching keys') } }
class MalformedAuthenticationException extends DecryptException { constructor() { super('authentication data') } }
class KeyExpiredDecryptException extends DecryptException { constructor() { super('key expired') } }
class KeyNotFoundDecryptException extends DecryptException { constructor(message: string) { super('key not found: ' + message) } }
+1
View File
@@ -18,3 +18,4 @@
export { decrypt } from './decrypt'
export { generateDhKeypair } from './genkey'
export { decryptParentPassword } from './parentpassword'
export { getSharedSecret, SharedSecretException } from './shared-secret'
+100
View File
@@ -0,0 +1,100 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import * as Sequelize from 'sequelize'
import { createPrivateKey, createPublicKey, diffieHellman } from 'crypto'
import { Database } from '../../database'
import { calculateExpireTime } from '../../database/devicedhkey'
import { isVersionId } from '../../util/token'
export async function getSharedSecret({
database, transaction, familyId, deviceId, keyId, otherPublicKey
}: {
database: Database
transaction: Sequelize.Transaction
familyId: string
deviceId: string
keyId: string
otherPublicKey: Buffer
}) {
if (!isVersionId(keyId)) throw new KeyNotFoundException('invalid key id')
const databaseKeyEntry = await database.deviceDhKey.findOne({
where: {
familyId,
deviceId,
version: keyId
},
transaction
})
if (!databaseKeyEntry) throw new KeyNotFoundException('private key not found')
if (databaseKeyEntry.expireAt === null) {
databaseKeyEntry.expireAt = calculateExpireTime(BigInt(Date.now())).toString(10)
await databaseKeyEntry.save({ transaction })
} else {
if (BigInt(databaseKeyEntry.expireAt) < BigInt(Date.now())) throw new KeyExpiredException()
}
const privateKey = (() => {
try {
return createPrivateKey({
key: databaseKeyEntry.privateKey,
format: 'der',
type: 'pkcs8'
})
} catch (ex) {
throw new MalformedPrivateKeyException()
}
})()
const decodedOtherPublicKey = (() => {
try {
return createPublicKey({
key: otherPublicKey,
format: 'der',
type: 'spki'
})
} catch (ex) {
throw new MalformedPublicKeyException()
}
})()
const sharedSecret = (() => {
try {
return diffieHellman({
privateKey,
publicKey: decodedOtherPublicKey
})
} catch (ex) {
throw new MalformedNoMatchingKeysException()
}
})()
return {
sharedSecret,
ownPublicKey: databaseKeyEntry.publicKey
}
}
export class SharedSecretException extends Error {}
class MalformedPrivateKeyException extends SharedSecretException { constructor() { super('private key') } }
class MalformedPublicKeyException extends SharedSecretException { constructor() { super('public key') } }
class MalformedNoMatchingKeysException extends SharedSecretException { constructor() { super('no matching keys') } }
class KeyExpiredException extends SharedSecretException { constructor() { super('key expired') } }
class KeyNotFoundException extends SharedSecretException { constructor(message: string) { super('key not found: ' + message) } }
+2 -1
View File
@@ -68,7 +68,8 @@ export const createFamily = async ({ database, mailAuthToken, firstParentDevice,
// 14 days demo version
fullVersionUntil: (Date.now() + 1000 * 60 * 60 * 24 * 14).toString(10),
hasFullVersion: true,
nextServerKeyRequestSeq: '1'
nextServerKeyRequestSeq: '1',
u2fKeysVersion: generateIdWithinFamily()
}, { transaction })
// create parent user
+14
View File
@@ -45,6 +45,7 @@ export class Cache {
invalidiateUserList = false
invalidiateDeviceList = false
invalidateU2fList = false
areChangesImportant = false
constructor ({ familyId, deviceId, hasFullVersion, database, transaction, connectedDevicesManager }: {
@@ -271,6 +272,19 @@ export class Cache {
this.invalidiateDeviceList = false
}
if (this.invalidateU2fList) {
await database.family.update({
u2fKeysVersion: generateVersionId()
}, {
where: {
familyId: this.familyId
},
transaction
})
this.invalidateU2fList = false
}
this.devicesWithModifiedShowDeviceConnected.forEach((showDeviceConnected, deviceId) => {
this.connectedDevicesManager.notifyShareConnectedChanged({
familyId: this.familyId,
@@ -1,6 +1,6 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2020 Jonas Lochmann
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
@@ -24,14 +24,18 @@ import { Cache } from '../cache'
import { dispatchParentAction as dispatchParentActionInternal } from '../dispatch-parent-action'
import { SourceDeviceNotFoundException } from '../exception/illegal-state'
import { SelfLimitNotPossibleException } from '../exception/self-limit'
import { AuthenticationMethod } from '../types'
import { dispatch } from './helper'
export async function dispatchParentAction ({ action, eventHandler, cache, isChildLimitAdding, deviceId }: {
export async function dispatchParentAction ({
action, eventHandler, cache, isChildLimitAdding, deviceId, authentication
}: {
action: ClientPushChangesRequestAction
cache: Cache
eventHandler: EventHandler
isChildLimitAdding: boolean
deviceId: string
authentication: AuthenticationMethod
}) {
return dispatch({
action,
@@ -90,7 +94,8 @@ export async function dispatchParentAction ({ action, eventHandler, cache, isChi
cache,
parentUserId: action.userId,
sourceDeviceId: deviceId,
fromChildSelfLimitAddChildUserId: deviceUserId
fromChildSelfLimitAddChildUserId: deviceUserId,
authentication
})
} else {
await dispatchParentActionInternal({
@@ -98,7 +103,8 @@ export async function dispatchParentAction ({ action, eventHandler, cache, isChi
cache,
parentUserId: action.userId,
sourceDeviceId: deviceId,
fromChildSelfLimitAddChildUserId: null
fromChildSelfLimitAddChildUserId: null,
authentication
})
}
}
@@ -0,0 +1,56 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { AddParentU2fKeyAction } from '../../../../action'
import { getU2fKeyId } from '../../../../database/u2fkey'
import { Cache } from '../cache'
import { ApplyActionUnacceptableAuthMethodException } from '../exception/auth'
import { LimitReachedException } from '../exception/limit'
import { AuthenticationMethod } from '../types'
export async function dispatchAddU2f ({ action, cache, parentUserId, authentication }: {
action: AddParentU2fKeyAction
cache: Cache
parentUserId: string
authentication: AuthenticationMethod
}) {
if (authentication === 'u2f') {
throw new ApplyActionUnacceptableAuthMethodException()
}
const counter = await cache.database.u2fKey.count({
where: {
familyId: cache.familyId
},
transaction: cache.transaction
})
if (counter >= 16) throw new LimitReachedException({ type: 'u2f keys' })
await cache.database.u2fKey.create({
familyId: cache.familyId,
keyId: getU2fKeyId({ keyHandle: action.keyHandle, publicKey: action.publicKey }),
userId: parentUserId,
addedAt: Date.now().toString(10),
keyHandle: action.keyHandle,
publicKey: action.publicKey,
nextCounter: '0'
}, { transaction: cache.transaction })
cache.invalidateU2fList = true
cache.areChangesImportant = true
}
@@ -1,6 +1,6 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2020 Jonas Lochmann
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
@@ -18,6 +18,7 @@
import {
AddCategoryAppsAction,
AddCategoryNetworkIdAction,
AddParentU2fKeyAction,
AddUserAction,
ChangeParentPasswordAction,
CreateCategoryAction,
@@ -29,7 +30,9 @@ import {
IncrementCategoryExtraTimeAction,
ParentAction,
RemoveCategoryAppsAction,
RemoveParentU2fKeyAction,
RemoveUserAction,
ReportU2fLoginAction,
RenameChildAction,
ResetCategoryNetworkIdsAction,
ReviewChildTaskAction,
@@ -68,8 +71,10 @@ import {
import { Cache } from '../cache'
import { ActionObjectTypeNotHandledException } from '../exception/illegal-state'
import { ActionNotSupportedBySelfLimitationException } from '../exception/self-limit'
import { AuthenticationMethod } from '../types'
import { dispatchAddCategoryApps } from './addcategoryapps'
import { dispatchAddCategoryNetworkId } from './addcategorynetworkid'
import { dispatchAddU2f } from './addu2fkey'
import { dispatchAddUser } from './adduser'
import { dispatchChangeParentPassword } from './changeparentpassword'
import { dispatchCreateCategory } from './createcategory'
@@ -80,7 +85,9 @@ import { dispatchDeleteTimeLimitRule } from './deletetimelimitrule'
import { dispatchIgnoreManipulation } from './ignoremanipulation'
import { dispatchIncrementCategoryExtraTime } from './incrementcategoryextratime'
import { dispatchRemoveCategoryApps } from './removecategoryapps'
import { dispatchRemoveU2f } from './removeu2fkey'
import { dispatchRemoveUser } from './removeuser'
import { dispatchReportU2fLogin } from './reportu2flogin'
import { dispatchRenameChild } from './renamechild'
import { dispatchResetCategoryNetworkIds } from './resetcategorynetworkids'
import { dispatchReviewChildTaskAction } from './reviewchildtaskaction'
@@ -116,12 +123,16 @@ import { dispatchUpdateUserFlagsAction } from './updateuserflags'
import { dispatchUpdateUserLimitLoginCategoryAction } from './updateuserlimitlogincategory'
import { dispatchUpdateUserLimitPreBlockDuration } from './updateuserlimitloginpreblockduration'
export const dispatchParentAction = async ({ action, cache, parentUserId, sourceDeviceId, fromChildSelfLimitAddChildUserId }: {
export const dispatchParentAction = async ({
action, cache, parentUserId, sourceDeviceId,
fromChildSelfLimitAddChildUserId, authentication
}: {
action: ParentAction
cache: Cache
parentUserId: string
sourceDeviceId: string | null
fromChildSelfLimitAddChildUserId: string | null
authentication: AuthenticationMethod
}) => {
if (action instanceof AddCategoryAppsAction) {
return dispatchAddCategoryApps({ action, cache, fromChildSelfLimitAddChildUserId })
@@ -146,10 +157,14 @@ export const dispatchParentAction = async ({ action, cache, parentUserId, source
} else {
if (action instanceof AddCategoryNetworkIdAction) {
return dispatchAddCategoryNetworkId({ action, cache })
} else if (action instanceof AddParentU2fKeyAction) {
return dispatchAddU2f({ action, cache, parentUserId, authentication })
} else if (action instanceof AddUserAction) {
return dispatchAddUser({ action, cache })
} else if (action instanceof RemoveCategoryAppsAction) {
return dispatchRemoveCategoryApps({ action, cache })
} else if (action instanceof RemoveParentU2fKeyAction) {
return dispatchRemoveU2f({ action, cache, parentUserId, authentication })
} else if (action instanceof DeleteCategoryAction) {
return dispatchDeleteCategory({ action, cache })
} else if (action instanceof UpdateCategoryTitleAction) {
@@ -200,6 +215,8 @@ export const dispatchParentAction = async ({ action, cache, parentUserId, source
return dispatchUpdateTimelimitRule({ action, cache })
} else if (action instanceof RemoveUserAction) {
return dispatchRemoveUser({ action, cache, parentUserId })
} else if (action instanceof ReportU2fLoginAction) {
return dispatchReportU2fLogin({ action, cache, authentication })
} else if (action instanceof ResetCategoryNetworkIdsAction) {
return dispatchResetCategoryNetworkIds({ action, cache })
} else if (action instanceof RenameChildAction) {
@@ -0,0 +1,47 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { RemoveParentU2fKeyAction } from '../../../../action'
import { getU2fKeyId } from '../../../../database/u2fkey'
import { Cache } from '../cache'
import { ApplyActionUnacceptableAuthMethodException } from '../exception/auth'
import { AuthenticationMethod } from '../types'
export async function dispatchRemoveU2f ({ action, cache, parentUserId, authentication }: {
action: RemoveParentU2fKeyAction
cache: Cache
parentUserId: string
authentication: AuthenticationMethod
}) {
if (authentication === 'u2f') {
throw new ApplyActionUnacceptableAuthMethodException()
}
await cache.database.u2fKey.destroy({
where: {
familyId: cache.familyId,
keyId: getU2fKeyId({ keyHandle: action.keyHandle, publicKey: action.publicKey }),
userId: parentUserId,
keyHandle: action.keyHandle,
publicKey: action.publicKey
},
transaction: cache.transaction
})
cache.invalidateU2fList = true
cache.areChangesImportant = true
}
@@ -0,0 +1,34 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { ReportU2fLoginAction } from '../../../../action'
import { Cache } from '../cache'
import { ApplyActionUnacceptableAuthMethodException } from '../exception/auth'
import { AuthenticationMethod } from '../types'
export async function dispatchReportU2fLogin ({ authentication }: {
action: ReportU2fLoginAction
cache: Cache
authentication: AuthenticationMethod
}) {
if (authentication !== 'u2f') {
throw new ApplyActionUnacceptableAuthMethodException()
}
// nothing to do; the goal was already reached by the authentication
// validation that expired the dh key
}
@@ -0,0 +1,22 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { ApplyActionException } from './index'
export class ApplyActionUnacceptableAuthMethodException extends ApplyActionException {
constructor() { super({ staticMessage: 'invalid auth method for the action' }) }
}
@@ -1,6 +1,6 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2020 Jonas Lochmann
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
@@ -27,6 +27,10 @@ export class InvalidParentActionIntegrityValue extends ApplyActionIntegrityExcep
constructor () { super({ staticMessage: 'invalid parent action integrity value' }) }
}
export class InvalidU2fIntegrityValue extends ApplyActionIntegrityException {
constructor (message: string) { super({ staticMessage: 'invalid parent action u2f integrity value: ' + message }) }
}
export class InvalidChildActionIntegrityValue extends ApplyActionIntegrityException {
constructor () { super({ staticMessage: 'invalid child action integrity value' }) }
}
@@ -0,0 +1,24 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { ApplyActionException } from './index'
export class LimitReachedException extends ApplyActionException {
constructor({type}: { type: string }) {
super({ staticMessage: 'limit reached: ' + type })
}
}
+14 -7
View File
@@ -71,12 +71,6 @@ export const applyActionsFromDevice = async ({ database, request, websocket, con
// update the next sequence number
nextSequenceNumber = action.sequenceNumber + 1
const { isChildLimitAdding } = await assertActionIntegrity({
deviceId: baseInfo.deviceId,
cache,
action
})
if (action.type === 'appLogic') {
await dispatchAppLogicAction({
action,
@@ -85,14 +79,27 @@ export const applyActionsFromDevice = async ({ database, request, websocket, con
eventHandler
})
} else if (action.type === 'parent') {
const { isChildLimitAdding, authentication } = await assertActionIntegrity({
deviceId: baseInfo.deviceId,
cache,
action
})
await dispatchParentAction({
action,
cache,
deviceId: baseInfo.deviceId,
eventHandler,
isChildLimitAdding
isChildLimitAdding,
authentication
})
} else if (action.type === 'child') {
await assertActionIntegrity({
deviceId: baseInfo.deviceId,
cache,
action
})
await dispatchChildAction({
action,
cache,
+103 -13
View File
@@ -1,6 +1,6 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2020 Jonas Lochmann
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
@@ -15,20 +15,26 @@
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { createHash } from 'crypto'
import { createHash, createHmac, timingSafeEqual } from 'crypto'
import { ClientPushChangesRequestAction } from '../../../api/schema'
import { intToBuffer, longToBuffer } from '../../../util/binary-number'
import { validateU2fIntegrity, U2fValidationError } from '../../u2f'
import { Cache } from './cache'
import {
InvalidChildActionIntegrityValue, InvalidParentActionIntegrityValue, ParentDeviceActionWithoutParentDeviceException
InvalidChildActionIntegrityValue, InvalidParentActionIntegrityValue,
ParentDeviceActionWithoutParentDeviceException, InvalidU2fIntegrityValue
} from './exception/integrity'
import { ActionObjectTypeNotHandledException } from './exception/illegal-state'
import { AuthenticationMethod } from './types'
export async function assertActionIntegrity ({ action, cache, deviceId }: {
action: ClientPushChangesRequestAction
cache: Cache
deviceId: string
}): Promise<{ isChildLimitAdding: boolean }> {
let isChildLimitAdding = false
}): Promise<{
isChildLimitAdding: boolean
authentication: AuthenticationMethod
}> {
if (action.type === 'parent') {
if (action.integrity === 'device') {
const deviceEntryUnsafe = await cache.database.device.findOne({
@@ -48,10 +54,69 @@ export async function assertActionIntegrity ({ action, cache, deviceId }: {
// this ensures that the parent exists
await cache.getSecondPasswordHashOfParent(action.userId)
return {
isChildLimitAdding: false,
authentication: 'device'
}
} else if (action.integrity === 'childDevice') {
// will be checked later
isChildLimitAdding = true
return {
isChildLimitAdding: true, // will be checked later
authentication: 'device'
}
} else if (action.integrity.startsWith('u2f:')) {
// this ensures that the parent exists
await cache.getSecondPasswordHashOfParent(action.userId)
try {
const checkResult = await validateU2fIntegrity({
integrity: action.integrity,
hasFullVersion: cache.hasFullVersion,
familyId: cache.familyId,
deviceId,
database: cache.database,
transaction: cache.transaction,
calculateHmac: (secret) => calculateActionHmac({
action,
deviceId,
secret
})
})
if (checkResult.userId !== action.userId) {
throw new InvalidParentActionIntegrityValue()
}
} catch (ex) {
if (ex instanceof U2fValidationError) throw new InvalidU2fIntegrityValue(ex.message)
else throw ex
}
return {
isChildLimitAdding: false,
authentication: 'u2f'
}
} else if (action.integrity.startsWith('password:')) {
// password method with hmac
const parentSecondHash = await cache.getSecondPasswordHashOfParent(action.userId)
const correctResponse = calculateActionHmac({
action,
deviceId,
secret: Buffer.from(parentSecondHash, 'utf8')
})
const providedResult = Buffer.from(action.integrity.substring(9), 'base64')
if (!timingSafeEqual(providedResult, correctResponse)) {
throw new InvalidParentActionIntegrityValue()
}
return {
isChildLimitAdding: false,
authentication: 'password'
}
} else {
// legacy password method
const parentSecondHash = await cache.getSecondPasswordHashOfParent(action.userId)
const integrityData = action.sequenceNumber.toString(10) +
@@ -64,10 +129,13 @@ export async function assertActionIntegrity ({ action, cache, deviceId }: {
if (action.integrity !== expectedIntegrityValue) {
throw new InvalidParentActionIntegrityValue()
}
}
}
if (action.type === 'child') {
return {
isChildLimitAdding: false,
authentication: 'password'
}
}
} else if (action.type === 'child') {
const childSecondHash = await cache.getSecondPasswordHashOfChild(action.userId)
const integrityData = action.sequenceNumber.toString(10) +
@@ -80,7 +148,29 @@ export async function assertActionIntegrity ({ action, cache, deviceId }: {
if (action.integrity !== expectedIntegrityValue) {
throw new InvalidChildActionIntegrityValue()
}
}
return { isChildLimitAdding }
return {
isChildLimitAdding: false,
authentication: 'password'
}
} else {
throw new ActionObjectTypeNotHandledException()
}
}
function calculateActionHmac({ action, deviceId, secret }: {
action: ClientPushChangesRequestAction
deviceId: string
secret: Buffer
}): Buffer {
const binaryDeviceId = Buffer.from(deviceId, 'utf8')
const binaryAction = Buffer.from(action.encodedAction, 'utf8')
return createHmac('sha256', secret)
.update(longToBuffer(BigInt(action.sequenceNumber)))
.update(intToBuffer(binaryDeviceId.length))
.update(binaryDeviceId)
.update(intToBuffer(binaryAction.length))
.update(binaryAction)
.digest()
}
+18
View File
@@ -0,0 +1,18 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
export type AuthenticationMethod = 'device' | 'password' | 'u2f'
@@ -1,6 +1,6 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2020 Jonas Lochmann
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
@@ -25,6 +25,7 @@ export interface FamilyEntry {
userListVersion: string
hasFullVersion: boolean
fullVersionUntil: string
u2fKeysVersion: string
}
export async function getFamilyEntry ({ database, familyId, transaction }: {
@@ -40,7 +41,8 @@ export async function getFamilyEntry ({ database, familyId, transaction }: {
'deviceListVersion',
'userListVersion',
'hasFullVersion',
'fullVersionUntil'
'fullVersionUntil',
'u2fKeysVersion'
],
transaction
})
@@ -54,6 +56,7 @@ export async function getFamilyEntry ({ database, familyId, transaction }: {
deviceListVersion: familyEntryUnsafe.deviceListVersion,
userListVersion: familyEntryUnsafe.userListVersion,
hasFullVersion: familyEntryUnsafe.hasFullVersion,
fullVersionUntil: familyEntryUnsafe.fullVersionUntil
fullVersionUntil: familyEntryUnsafe.fullVersionUntil,
u2fKeysVersion: familyEntryUnsafe.u2fKeysVersion
}
}
@@ -34,6 +34,7 @@ import { getFamilyEntry } from './family-entry'
import { getUserList } from './user-list'
import { getKeyRequests } from './key-requests'
import { getKeyResponses } from './key-responses'
import { getU2f } from './u2f'
export const generateServerDataStatus = async ({
database, clientStatus, familyId, deviceId, transaction, eventHandler
@@ -51,13 +52,14 @@ export const generateServerDataStatus = async ({
const doesClientSupportTasks = clientLevel >= 3
const doesClientSupportCryptoApps = clientLevel >= 4
const doesClientSupportDh = clientLevel >= 5
const doesClientSupportU2f = clientLevel >= 6
const result: ServerDataStatus = {
fullVersion: config.alwaysPro ? 1 : (
familyEntry.hasFullVersion ? parseInt(familyEntry.fullVersionUntil, 10) : 0
),
message: await getStatusMessage({ database, transaction }) || undefined,
apiLevel: 5
apiLevel: 6
}
if (familyEntry.deviceListVersion !== clientStatus.devices) {
@@ -152,5 +154,14 @@ export const generateServerDataStatus = async ({
}) || undefined
}
if (doesClientSupportU2f) {
result.u2f = await getU2f({
database,
transaction,
familyEntry,
lastVersionId: clientStatus.u2f || null
}) || undefined
}
return result
}
@@ -0,0 +1,49 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import * as Sequelize from 'sequelize'
import { Database } from '../../../database'
import { U2fData } from '../../../object/serverdatastatus'
import { FamilyEntry } from './family-entry'
export async function getU2f ({
database, transaction, familyEntry, lastVersionId
}: {
database: Database
transaction: Sequelize.Transaction
familyEntry: FamilyEntry
lastVersionId: string | null
}): Promise<U2fData | null> {
if (lastVersionId === familyEntry.u2fKeysVersion) return null
const savedData = await database.u2fKey.findAll({
where: {
familyId: familyEntry.familyId
},
transaction
})
return {
v: familyEntry.u2fKeysVersion,
d: savedData.map((item) => ({
u: item.userId,
a: parseInt(item.addedAt, 10),
h: item.keyHandle.toString('base64'),
p: item.publicKey.toString('base64')
}))
}
}
+148
View File
@@ -0,0 +1,148 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { createHash, timingSafeEqual } from 'crypto'
import * as Sequelize from 'sequelize'
import { getSharedSecret, SharedSecretException } from '../dh'
import { Database } from '../../database'
import { intToBuffer } from '../../util/binary-number'
import { isU2fSignatureValid, calculateApplicationId } from '../../util/u2fsignature'
export class U2fValidationError extends Error {}
class IntegrityMalformedException extends U2fValidationError { constructor() { super('integrity malformed') } }
class MissingPremiumException extends U2fValidationError { constructor() { super('missing premium') } }
class U2fSharedSecretException extends U2fValidationError { constructor(message: string) { super('shared secret: ' + message) } }
class HmacMismatchException extends U2fValidationError { constructor() { super('hmac mismatch') } }
class UnknownU2fKeyIdException extends U2fValidationError { constructor() { super('unknown u2f key id') } }
class InvalidU2fSignatureException extends U2fValidationError { constructor() { super('u2f signature invalid') } }
export async function validateU2fIntegrity({
integrity,
hasFullVersion,
familyId,
deviceId,
database,
transaction,
calculateHmac
}: {
integrity: string
hasFullVersion: boolean
familyId: string
deviceId: string
database: Database
transaction: Sequelize.Transaction
calculateHmac: (secret: Buffer) => Buffer
}) {
if (!integrity.startsWith('u2f:')) throw new IntegrityMalformedException()
const parts = integrity.substring(4).split('.')
if (parts.length !== 5) {
throw new IntegrityMalformedException()
}
if (!hasFullVersion) {
throw new MissingPremiumException()
}
const [dhKeyId, dhPublicKeyBase64, u2fKeyId, u2fResponseBase64, providedHmacResultBase64] = parts
const binaryDhKeyId = Buffer.from(dhKeyId, 'utf8')
const dhPublicKey = Buffer.from(dhPublicKeyBase64, 'base64')
const u2fResponse = Buffer.from(u2fResponseBase64, 'base64')
const providedHmacResult = Buffer.from(providedHmacResultBase64, 'base64')
const sharedSecret = await (async () => {
try {
return await getSharedSecret({
database,
transaction,
familyId,
deviceId,
keyId: dhKeyId,
otherPublicKey: dhPublicKey
})
} catch (ex) {
if (ex instanceof SharedSecretException) throw new U2fSharedSecretException(ex.message)
else throw ex
}
})()
const correctHmac = calculateHmac(sharedSecret.sharedSecret)
if (!timingSafeEqual(providedHmacResult, correctHmac)) {
throw new HmacMismatchException()
}
const keyDescriptorUnsafe = await database.u2fKey.findOne({
where: {
familyId,
keyId: u2fKeyId
},
transaction,
attributes: ['publicKey', 'userId']
})
if (keyDescriptorUnsafe === null) throw new UnknownU2fKeyIdException()
const keyDescriptor = {
publicKey: keyDescriptorUnsafe.publicKey,
userId: keyDescriptorUnsafe.userId
}
const dhPublicKeysHash = createHash('sha256')
.update(intToBuffer(binaryDhKeyId.length))
.update(binaryDhKeyId)
.update(intToBuffer(sharedSecret.ownPublicKey.length))
.update(sharedSecret.ownPublicKey)
.update(intToBuffer(dhPublicKey.length))
.update(dhPublicKey)
.digest()
if (
!isU2fSignatureValid({
u2fRawResponse: u2fResponse,
applicationId: calculateApplicationId('https://timelimit.io'),
challenge: dhPublicKeysHash,
publicKey: keyDescriptor.publicKey
})
) {
throw new InvalidU2fSignatureException()
}
const u2fCounter = u2fResponse.readUInt32BE(1)
// the counter is not checked at the server
// this happens because the offline usage can cause receiving actions
// out of order so it would be required to keep track of the used counter
// values; if this becomes necassary in the future, then it does not
// require any client modification to add it
await database.u2fKey.update({
nextCounter: (u2fCounter + 1).toString(10)
}, {
where: {
familyId,
keyId: u2fKeyId
},
transaction
})
return {
userId: keyDescriptor.userId
}
}
+1
View File
@@ -25,6 +25,7 @@ export interface ClientDataStatus {
kri?: number // last key request index
kr?: number // last key response index
dh?: string // last Diffie Hellman key version
u2f?: string // last u2f list version
}
export type ClientDataStatusApps = {[key: string]: string} // installedAppsVersionsByDeviceId
+13
View File
@@ -35,6 +35,7 @@ export interface ServerDataStatus {
krq?: Array<ServerKeyRequest> // pendingKeyRequests
kr?: Array<ServerKeyResponse> // keyResponses
dh?: ServerDhKey // Diffie Hellman
u2f?: U2fData
fullVersion: number // fullVersionUntil
message?: string
apiLevel: number
@@ -258,3 +259,15 @@ export interface ServerDhKey {
v: string // version
k: string // key, base64
}
export interface U2fData {
v: string // version
d: Array<U2fItem> // data
}
export interface U2fItem {
u: string // userId
a: number // addedAt
h: string // key handle, base64
p: string // public key, base64
}
+32
View File
@@ -0,0 +1,32 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
export function intToBuffer(input: number): Buffer {
const buffer = Buffer.alloc(4)
buffer.writeUInt32BE(input)
return buffer
}
export function longToBuffer(input: bigint): Buffer {
const buffer = Buffer.alloc(8)
buffer.writeBigUInt64BE(input)
return buffer
}
+52
View File
@@ -0,0 +1,52 @@
/*
* server component for the TimeLimit App
* Copyright (C) 2019 - 2022 Jonas Lochmann
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, version 3 of the License.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import { createVerify, createPublicKey, createHash } from 'crypto'
export function isU2fSignatureValid({
u2fRawResponse, applicationId, challenge, publicKey
}: {
u2fRawResponse: Buffer
applicationId: Buffer
challenge: Buffer
publicKey: Buffer
}): boolean {
if (u2fRawResponse.length < 5) return false
if (publicKey.length !== 65 || publicKey.readInt8(0) !== 4) return false
const publicKeyObject = createPublicKey({
key: Buffer.concat([
Buffer.from('MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgA=', 'base64'), publicKey
]),
format: 'der',
type: 'spki'
})
const verifier = createVerify('SHA256')
verifier.update(applicationId)
verifier.update(u2fRawResponse.slice(0, 5))
verifier.update(challenge)
return verifier.verify(publicKeyObject, u2fRawResponse.slice(5))
}
export function calculateApplicationId(url: string): Buffer {
return createHash('sha256')
.update(Buffer.from(url, 'utf8'))
.digest()
}