mirror of
https://codeberg.org/timelimit/timelimit-server.git
synced 2026-08-31 19:03:45 +02:00
Add support for encrypted second password hashes
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* server component for the TimeLimit App
|
||||
* Copyright (C) 2019 - 2020 Jonas Lochmann
|
||||
* Copyright (C) 2019 - 2022 Jonas Lochmann
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Affero General Public License as
|
||||
@@ -27,6 +27,7 @@ import { InvalidChildActionIntegrityValue } from './exception/integrity'
|
||||
|
||||
export class Cache {
|
||||
readonly familyId: string
|
||||
readonly deviceId: string
|
||||
readonly hasFullVersion: boolean
|
||||
transaction: Sequelize.Transaction
|
||||
readonly database: Database
|
||||
@@ -46,14 +47,16 @@ export class Cache {
|
||||
invalidiateDeviceList = false
|
||||
areChangesImportant = false
|
||||
|
||||
constructor ({ familyId, hasFullVersion, database, transaction, connectedDevicesManager }: {
|
||||
constructor ({ familyId, deviceId, hasFullVersion, database, transaction, connectedDevicesManager }: {
|
||||
familyId: string
|
||||
deviceId: string
|
||||
hasFullVersion: boolean
|
||||
database: Database
|
||||
transaction: Sequelize.Transaction
|
||||
connectedDevicesManager: VisibleConnectedDevicesManager
|
||||
}) {
|
||||
this.familyId = familyId
|
||||
this.deviceId = deviceId
|
||||
this.hasFullVersion = hasFullVersion || config.alwaysPro
|
||||
this.database = database
|
||||
this.transaction = transaction
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* server component for the TimeLimit App
|
||||
* Copyright (C) 2019 - 2021 Jonas Lochmann
|
||||
* Copyright (C) 2019 - 2022 Jonas Lochmann
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Affero General Public License as
|
||||
@@ -18,6 +18,7 @@
|
||||
import { ChildChangePasswordAction } from '../../../../action'
|
||||
import { Cache } from '../cache'
|
||||
import { SourceUserNotFoundException } from '../exception/illegal-state'
|
||||
import { decryptParentPassword } from '../../../dh'
|
||||
|
||||
export const dispatchChildChangePassword = async ({ action, childUserId, cache }: {
|
||||
action: ChildChangePasswordAction
|
||||
@@ -37,9 +38,11 @@ export const dispatchChildChangePassword = async ({ action, childUserId, cache }
|
||||
throw new SourceUserNotFoundException()
|
||||
}
|
||||
|
||||
childEntry.passwordHash = action.password.hash
|
||||
childEntry.secondPasswordSalt = action.password.secondSalt
|
||||
childEntry.secondPasswordHash = action.password.secondHash
|
||||
const newPassword = await decryptParentPassword({ cache, password: action.password })
|
||||
|
||||
childEntry.passwordHash = newPassword.hash
|
||||
childEntry.secondPasswordSalt = newPassword.secondSalt
|
||||
childEntry.secondPasswordHash = newPassword.secondHash
|
||||
|
||||
await childEntry.save({ transaction: cache.transaction })
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* server component for the TimeLimit App
|
||||
* Copyright (C) 2019 - 2020 Jonas Lochmann
|
||||
* Copyright (C) 2019 - 2022 Jonas Lochmann
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Affero General Public License as
|
||||
@@ -16,21 +16,27 @@
|
||||
*/
|
||||
|
||||
import { AddUserAction } from '../../../../action'
|
||||
import { decryptParentPassword } from '../../../dh'
|
||||
import { Cache } from '../cache'
|
||||
|
||||
export async function dispatchAddUser ({ action, cache }: {
|
||||
action: AddUserAction
|
||||
cache: Cache
|
||||
}) {
|
||||
const password =
|
||||
action.password ?
|
||||
await decryptParentPassword({ cache, password: action.password }) :
|
||||
null
|
||||
|
||||
await cache.database.user.create({
|
||||
familyId: cache.familyId,
|
||||
userId: action.userId,
|
||||
type: action.userType,
|
||||
name: action.name,
|
||||
timeZone: action.timeZone,
|
||||
passwordHash: action.password ? action.password.hash : '',
|
||||
secondPasswordHash: action.password ? action.password.secondHash : '',
|
||||
secondPasswordSalt: action.password ? action.password.secondSalt : '',
|
||||
passwordHash: password ? password.hash : '',
|
||||
secondPasswordHash: password ? password.secondHash : '',
|
||||
secondPasswordSalt: password ? password.secondSalt : '',
|
||||
mail: '',
|
||||
disableTimelimitsUntil: '0',
|
||||
currentDevice: '',
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* server component for the TimeLimit App
|
||||
* Copyright (C) 2019 - 2021 Jonas Lochmann
|
||||
* Copyright (C) 2019 - 2022 Jonas Lochmann
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Affero General Public License as
|
||||
@@ -18,6 +18,7 @@
|
||||
import { SetChildPasswordAction } from '../../../../action'
|
||||
import { Cache } from '../cache'
|
||||
import { MissingUserException } from '../exception/missing-item'
|
||||
import { decryptParentPassword } from '../../../dh'
|
||||
|
||||
export async function dispatchSetChildPassword ({ action, cache }: {
|
||||
action: SetChildPasswordAction
|
||||
@@ -36,9 +37,11 @@ export async function dispatchSetChildPassword ({ action, cache }: {
|
||||
throw new MissingUserException()
|
||||
}
|
||||
|
||||
childEntry.passwordHash = action.newPassword.hash
|
||||
childEntry.secondPasswordSalt = action.newPassword.secondSalt
|
||||
childEntry.secondPasswordHash = action.newPassword.secondHash
|
||||
const newPassword = await decryptParentPassword({ cache, password: action.newPassword })
|
||||
|
||||
childEntry.passwordHash = newPassword.hash
|
||||
childEntry.secondPasswordSalt = newPassword.secondSalt
|
||||
childEntry.secondPasswordHash = newPassword.secondHash
|
||||
|
||||
await childEntry.save({ transaction: cache.transaction })
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* server component for the TimeLimit App
|
||||
* Copyright (C) 2019 - 2020 Jonas Lochmann
|
||||
* Copyright (C) 2019 - 2022 Jonas Lochmann
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Affero General Public License as
|
||||
@@ -54,6 +54,7 @@ export const applyActionsFromDevice = async ({ database, request, websocket, con
|
||||
hasFullVersion: baseInfo.hasFullVersion,
|
||||
transaction,
|
||||
familyId: baseInfo.familyId,
|
||||
deviceId: baseInfo.deviceId,
|
||||
connectedDevicesManager
|
||||
})
|
||||
|
||||
|
||||
Reference in New Issue
Block a user