mirror of
https://codeberg.org/timelimit/timelimit-server.git
synced 2026-08-31 19:03:45 +02:00
Compare commits
24
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
63c23060f6 | ||
|
|
c3793f71a8 | ||
|
|
c693cfdbd4 | ||
|
|
d3675d484b | ||
|
|
053c59899b | ||
|
|
c1e2ea8c84 | ||
|
|
07ee3c268a | ||
|
|
0f92e6b1b7 | ||
|
|
b4a3862c1e | ||
|
|
24fa354f09 | ||
|
|
3d307bee6e | ||
|
|
d227f112e4 | ||
|
|
d83b8a2c26 | ||
|
|
333ac4a8a2 | ||
|
|
77e39752ed | ||
|
|
7c81f50ad2 | ||
|
|
44e7d16b5c | ||
|
|
473fbe80e9 | ||
|
|
1930dd0a27 | ||
|
|
a79fcf235e | ||
|
|
cb1347fffa | ||
|
|
48ecbd8ada | ||
|
|
e6cc08a292 | ||
|
|
120ea33547 |
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
FROM node:24-alpine
|
FROM node:16-alpine
|
||||||
|
|
||||||
# Create app directories
|
# Create app directories
|
||||||
RUN mkdir -p /usr/src/app
|
RUN mkdir -p /usr/src/app
|
||||||
|
|||||||
@@ -270,6 +270,14 @@
|
|||||||
|
|
||||||
* [Untitled object in ClientPullChangesRequest](./clientpullchangesrequest-definitions-clientdatastatus-properties-devicesdetail.md) – `https://timelimit.io/ClientPullChangesRequest#/definitions/ClientDataStatus/properties/devicesDetail`
|
* [Untitled object in ClientPullChangesRequest](./clientpullchangesrequest-definitions-clientdatastatus-properties-devicesdetail.md) – `https://timelimit.io/ClientPullChangesRequest#/definitions/ClientDataStatus/properties/devicesDetail`
|
||||||
|
|
||||||
|
* [Untitled object in ClientPullChangesRequest](./clientpullchangesrequest-definitions-clientdatastatus-properties-apps.md) – `https://timelimit.io/ClientPullChangesRequest#/definitions/ClientDataStatus/properties/apps`
|
||||||
|
|
||||||
|
* [Untitled object in ClientPullChangesRequest](./clientpullchangesrequest-definitions-clientdatastatus-properties-categories.md) – `https://timelimit.io/ClientPullChangesRequest#/definitions/ClientDataStatus/properties/categories`
|
||||||
|
|
||||||
|
* [Untitled object in ClientPullChangesRequest](./clientpullchangesrequest-definitions-clientdatastatus-properties-devicesdetail.md) – `https://timelimit.io/ClientPullChangesRequest#/definitions/ClientDataStatus/properties/devicesDetail`
|
||||||
|
|
||||||
|
* [Untitled object in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddusedtimeactionversion2-properties-i-items.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddUsedTimeActionVersion2/properties/i/items`
|
||||||
|
|
||||||
* [Untitled object in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddusedtimeactionversion2-properties-i-items.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddUsedTimeActionVersion2/properties/i/items`
|
* [Untitled object in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddusedtimeactionversion2-properties-i-items.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddUsedTimeActionVersion2/properties/i/items`
|
||||||
|
|
||||||
### Arrays
|
### Arrays
|
||||||
@@ -298,6 +306,32 @@
|
|||||||
|
|
||||||
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedupdateappactivitiesaction-properties-updatedoradded.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedUpdateAppActivitiesAction/properties/updatedOrAdded`
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedupdateappactivitiesaction-properties-updatedoradded.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedUpdateAppActivitiesAction/properties/updatedOrAdded`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddinstalledappsaction-properties-apps.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddInstalledAppsAction/properties/apps`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddusedtimeactionversion2-properties-i.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddUsedTimeActionVersion2/properties/i`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddusedtimeactionversion2-properties-i-items-properties-as.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddUsedTimeActionVersion2/properties/i/items/properties/as`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddusedtimeactionversion2-properties-i-items-properties-as-items.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddUsedTimeActionVersion2/properties/i/items/properties/as/items`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddusedtimeactionversion2-properties-i-items-properties-sdl.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddUsedTimeActionVersion2/properties/i/items/properties/sdl`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedaddusedtimeactionversion2-properties-i-items-properties-sdl-items.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedAddUsedTimeActionVersion2/properties/i/items/properties/sdl/items`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedremoveinstalledappsaction-properties-packagenames.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedRemoveInstalledAppsAction/properties/packageNames`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedupdateappactivitiesaction-properties-removed.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedUpdateAppActivitiesAction/properties/removed`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedupdateappactivitiesaction-properties-removed-items.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedUpdateAppActivitiesAction/properties/removed/items`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedAppLogicAction](./serializedapplogicaction-definitions-serializedupdateappactivitiesaction-properties-updatedoradded.md) – `https://timelimit.io/SerializedAppLogicAction#/definitions/SerializedUpdateAppActivitiesAction/properties/updatedOrAdded`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedParentAction](./serializedparentaction-definitions-serializedaddcategoryappsaction-properties-packagenames.md) – `https://timelimit.io/SerializedParentAction#/definitions/SerializedAddCategoryAppsAction/properties/packageNames`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedParentAction](./serializedparentaction-definitions-serializedremovecategoryappsaction-properties-packagenames.md) – `https://timelimit.io/SerializedParentAction#/definitions/SerializedRemoveCategoryAppsAction/properties/packageNames`
|
||||||
|
|
||||||
|
* [Untitled array in SerializedParentAction](./serializedparentaction-definitions-serializedupdatecategorysortingaction-properties-categoryids.md) – `https://timelimit.io/SerializedParentAction#/definitions/SerializedUpdateCategorySortingAction/properties/categoryIds`
|
||||||
|
|
||||||
* [Untitled array in SerializedParentAction](./serializedparentaction-definitions-serializedaddcategoryappsaction-properties-packagenames.md) – `https://timelimit.io/SerializedParentAction#/definitions/SerializedAddCategoryAppsAction/properties/packageNames`
|
* [Untitled array in SerializedParentAction](./serializedparentaction-definitions-serializedaddcategoryappsaction-properties-packagenames.md) – `https://timelimit.io/SerializedParentAction#/definitions/SerializedAddCategoryAppsAction/properties/packageNames`
|
||||||
|
|
||||||
* [Untitled array in SerializedParentAction](./serializedparentaction-definitions-serializedremovecategoryappsaction-properties-packagenames.md) – `https://timelimit.io/SerializedParentAction#/definitions/SerializedRemoveCategoryAppsAction/properties/packageNames`
|
* [Untitled array in SerializedParentAction](./serializedparentaction-definitions-serializedremovecategoryappsaction-properties-packagenames.md) – `https://timelimit.io/SerializedParentAction#/definitions/SerializedRemoveCategoryAppsAction/properties/packageNames`
|
||||||
@@ -348,6 +382,30 @@
|
|||||||
|
|
||||||
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-u2fdata-properties-d.md) – `https://timelimit.io/ServerDataStatus#/definitions/U2fData/properties/d`
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-u2fdata-properties-d.md) – `https://timelimit.io/ServerDataStatus#/definitions/U2fData/properties/d`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverdevicelist-properties-data.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerDeviceList/properties/data`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverinstalledappsdata-properties-apps.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerInstalledAppsData/properties/apps`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverinstalledappsdata-properties-activities.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerInstalledAppsData/properties/activities`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverupdatedcategorybasedata-properties-networks.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerUpdatedCategoryBaseData/properties/networks`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverupdatedcategorybasedata-properties-atw.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerUpdatedCategoryBaseData/properties/atw`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverupdatedcategoryassignedapps-properties-apps.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerUpdatedCategoryAssignedApps/properties/apps`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverupdatedcategoryusedtimes-properties-times.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerUpdatedCategoryUsedTimes/properties/times`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverupdatedcategoryusedtimes-properties-sessiondurations.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerUpdatedCategoryUsedTimes/properties/sessionDurations`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverupdatedtimelimitrules-properties-rules.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerUpdatedTimeLimitRules/properties/rules`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serverupdatedcategorytasks-properties-tasks.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerUpdatedCategoryTasks/properties/tasks`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-serveruserlist-properties-data.md) – `https://timelimit.io/ServerDataStatus#/definitions/ServerUserList/properties/data`
|
||||||
|
|
||||||
|
* [Untitled array in ServerDataStatus](./serverdatastatus-definitions-u2fdata-properties-d.md) – `https://timelimit.io/ServerDataStatus#/definitions/U2fData/properties/d`
|
||||||
|
|
||||||
## Version Note
|
## Version Note
|
||||||
|
|
||||||
The schemas linked above follow the JSON Schema Spec version: `http://json-schema.org/draft-07/schema#`
|
The schemas linked above follow the JSON Schema Spec version: `http://json-schema.org/draft-07/schema#`
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
# EncryptableParentPassword Schema
|
# EncryptableParentPassword Schema
|
||||||
|
|
||||||
```txt
|
```txt
|
||||||
https://timelimit.io/SerializedParentAction#/definitions/EncryptableParentPassword
|
https://timelimit.io/SerializedParentAction#/definitions/SerializedSetChildPasswordAction/properties/newPassword
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
@@ -10,11 +10,11 @@ https://timelimit.io/SerializedParentAction#/definitions/EncryptableParentPasswo
|
|||||||
| :------------------ | :--------- | :------------- | :----------- | :---------------- | :-------------------- | :------------------ | :------------------------------------------------------------------------------------------------ |
|
| :------------------ | :--------- | :------------- | :----------- | :---------------- | :-------------------- | :------------------ | :------------------------------------------------------------------------------------------------ |
|
||||||
| Can be instantiated | No | Unknown status | No | Forbidden | Forbidden | none | [SerializedParentAction.schema.json\*](SerializedParentAction.schema.json "open original schema") |
|
| Can be instantiated | No | Unknown status | No | Forbidden | Forbidden | none | [SerializedParentAction.schema.json\*](SerializedParentAction.schema.json "open original schema") |
|
||||||
|
|
||||||
## EncryptableParentPassword Type
|
## newPassword Type
|
||||||
|
|
||||||
`object` ([EncryptableParentPassword](serializedparentaction-definitions-encryptableparentpassword.md))
|
`object` ([EncryptableParentPassword](serializedparentaction-definitions-encryptableparentpassword.md))
|
||||||
|
|
||||||
# EncryptableParentPassword Properties
|
# newPassword Properties
|
||||||
|
|
||||||
| Property | Type | Required | Nullable | Defined by |
|
| Property | Type | Required | Nullable | Defined by |
|
||||||
| :------------------------ | :-------- | :------- | :------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
| :------------------------ | :-------- | :------- | :------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
|||||||
@@ -57,3 +57,5 @@
|
|||||||
- SIGN_SECRET
|
- SIGN_SECRET
|
||||||
- used for signing tokens
|
- used for signing tokens
|
||||||
- if not set or set to an empty string, then the features that depend on it are disabled
|
- if not set or set to an empty string, then the features that depend on it are disabled
|
||||||
|
- UA_MAIL_BLOCKLIST
|
||||||
|
- List of user agents, separated by comma, that are not allowed to trigger sign in mails
|
||||||
|
|||||||
Generated
+1550
-1598
File diff suppressed because it is too large
Load Diff
+2
-1
@@ -29,7 +29,7 @@
|
|||||||
},
|
},
|
||||||
"homepage": "https://gitlab.com/timelimit.io/timelimit-server-2018#README",
|
"homepage": "https://gitlab.com/timelimit.io/timelimit-server-2018#README",
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@adobe/jsonschema2md": "^8.0.8",
|
"@adobe/jsonschema2md": "^7.0.0",
|
||||||
"@types/basic-auth": "^1.1.3",
|
"@types/basic-auth": "^1.1.3",
|
||||||
"@types/body-parser": "^1.19.0",
|
"@types/body-parser": "^1.19.0",
|
||||||
"@types/ejs": "^3.1.0",
|
"@types/ejs": "^3.1.0",
|
||||||
@@ -59,6 +59,7 @@
|
|||||||
"nodemailer": "^7.0.9",
|
"nodemailer": "^7.0.9",
|
||||||
"pg": "^8.5.1",
|
"pg": "^8.5.1",
|
||||||
"pg-hstore": "^2.3.3",
|
"pg-hstore": "^2.3.3",
|
||||||
|
"pkijs": "^3.0.16",
|
||||||
"rate-limiter-flexible": "^2.1.15",
|
"rate-limiter-flexible": "^2.1.15",
|
||||||
"sequelize": "^6.25.5",
|
"sequelize": "^6.25.5",
|
||||||
"socket.io": "^4.0.1",
|
"socket.io": "^4.0.1",
|
||||||
|
|||||||
+13
-3
@@ -1,6 +1,6 @@
|
|||||||
/*
|
/*
|
||||||
* server component for the TimeLimit App
|
* server component for the TimeLimit App
|
||||||
* Copyright (C) 2019 - 2021 Jonas Lochmann
|
* Copyright (C) 2019 - 2024 Jonas Lochmann
|
||||||
*
|
*
|
||||||
* This program is free software: you can redistribute it and/or modify
|
* This program is free software: you can redistribute it and/or modify
|
||||||
* it under the terms of the GNU Affero General Public License as
|
* it under the terms of the GNU Affero General Public License as
|
||||||
@@ -17,7 +17,8 @@
|
|||||||
|
|
||||||
import { json } from 'body-parser'
|
import { json } from 'body-parser'
|
||||||
import { Router } from 'express'
|
import { Router } from 'express'
|
||||||
import { BadRequest } from 'http-errors'
|
import { BadRequest, Forbidden } from 'http-errors'
|
||||||
|
import { config } from '../config'
|
||||||
import { Database } from '../database'
|
import { Database } from '../database'
|
||||||
import { sendLoginCode, signInByMailCode } from '../function/authentication/login-by-mail'
|
import { sendLoginCode, signInByMailCode } from '../function/authentication/login-by-mail'
|
||||||
import { isMailAddressCoveredByWhitelist, isMailServerBlacklisted, sanitizeMailAddress } from '../util/mail'
|
import { isMailAddressCoveredByWhitelist, isMailServerBlacklisted, sanitizeMailAddress } from '../util/mail'
|
||||||
@@ -25,11 +26,17 @@ import {
|
|||||||
isSendMailLoginCodeRequest,
|
isSendMailLoginCodeRequest,
|
||||||
isSignInByMailCodeRequest
|
isSignInByMailCodeRequest
|
||||||
} from './validator'
|
} from './validator'
|
||||||
|
import { analyze } from './integrity'
|
||||||
|
|
||||||
export const createAuthRouter = (database: Database) => {
|
export const createAuthRouter = (database: Database) => {
|
||||||
const router = Router()
|
const router = Router()
|
||||||
|
|
||||||
router.post('/send-mail-login-code-v2', json(), async (req, res, next) => {
|
router.post('/send-mail-login-code-v2', json(), async (req, res, next) => {
|
||||||
|
const info = {
|
||||||
|
ua: req.headers['user-agent'],
|
||||||
|
cert: analyze(req),
|
||||||
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
if (!isSendMailLoginCodeRequest(req.body)) {
|
if (!isSendMailLoginCodeRequest(req.body)) {
|
||||||
throw new BadRequest()
|
throw new BadRequest()
|
||||||
@@ -45,12 +52,15 @@ export const createAuthRouter = (database: Database) => {
|
|||||||
res.json({ mailAddressNotWhitelisted: true })
|
res.json({ mailAddressNotWhitelisted: true })
|
||||||
} else if (isMailServerBlacklisted(mail)) {
|
} else if (isMailServerBlacklisted(mail)) {
|
||||||
res.json({ mailServerBlacklisted: true })
|
res.json({ mailServerBlacklisted: true })
|
||||||
|
} else if (config.uaMailBlocklist.indexOf(req.headers['user-agent'] || '') !== -1) {
|
||||||
|
throw new Forbidden()
|
||||||
} else {
|
} else {
|
||||||
const { mailLoginToken } = await sendLoginCode({
|
const { mailLoginToken } = await sendLoginCode({
|
||||||
mail,
|
mail,
|
||||||
deviceAuthToken: req.body.deviceAuthToken,
|
deviceAuthToken: req.body.deviceAuthToken,
|
||||||
locale: req.body.locale,
|
locale: req.body.locale,
|
||||||
database
|
database,
|
||||||
|
info: Buffer.from(JSON.stringify(info), 'utf8')
|
||||||
})
|
})
|
||||||
|
|
||||||
res.json({ mailLoginToken })
|
res.json({ mailLoginToken })
|
||||||
|
|||||||
@@ -0,0 +1,102 @@
|
|||||||
|
import { X509Certificate } from 'crypto'
|
||||||
|
import { Request } from 'express'
|
||||||
|
import { fromBER, Sequence, Integer, OctetString, Set } from 'asn1js'
|
||||||
|
import { Certificate } from 'pkijs'
|
||||||
|
|
||||||
|
export interface CertInfo {
|
||||||
|
applicationCerts: Array<string>
|
||||||
|
}
|
||||||
|
|
||||||
|
export function analyze(req: Request): CertInfo | null {
|
||||||
|
try {
|
||||||
|
const certStr = req.headers['clientcertificate']
|
||||||
|
|
||||||
|
if (typeof certStr !== 'string') return null
|
||||||
|
|
||||||
|
const nativeCert = new X509Certificate(decodeURIComponent(certStr))
|
||||||
|
|
||||||
|
const now = Date.now()
|
||||||
|
const from = Date.parse(nativeCert.validFrom)
|
||||||
|
const to = Date.parse(nativeCert.validTo)
|
||||||
|
|
||||||
|
if (from > now || to < now) return null
|
||||||
|
if (from > to || from + 1000 * 60 * 5 < to) return null
|
||||||
|
|
||||||
|
const cert1 = fromBER(nativeCert.raw)
|
||||||
|
|
||||||
|
if (cert1.offset === -1) return null
|
||||||
|
|
||||||
|
const cert2 = new Certificate({ schema: cert1.result })
|
||||||
|
const androidExtension = (cert2.extensions || []).find((item) => item.extnID === '1.3.6.1.4.1.11129.2.1.17')?.extnValue?.valueBlock?.valueHexView
|
||||||
|
|
||||||
|
if (!androidExtension) return null
|
||||||
|
|
||||||
|
const androidExtensionParsed = fromBER(androidExtension)
|
||||||
|
|
||||||
|
if (androidExtensionParsed.offset === -1) return null
|
||||||
|
|
||||||
|
const androidExtensionSequence = androidExtensionParsed.result
|
||||||
|
|
||||||
|
if (!(androidExtensionSequence instanceof Sequence)) return null
|
||||||
|
|
||||||
|
const versionInteger = androidExtensionSequence.valueBlock.value[0]
|
||||||
|
|
||||||
|
if (!(versionInteger instanceof Integer)) return null
|
||||||
|
|
||||||
|
const versionValue = versionInteger.valueBlock.valueDec
|
||||||
|
|
||||||
|
const authorizationLists = androidExtensionSequence.valueBlock.value.slice(6, 8)
|
||||||
|
|
||||||
|
let applicationId = null
|
||||||
|
|
||||||
|
for (const authList of authorizationLists) {
|
||||||
|
if (!(authList instanceof Sequence)) continue
|
||||||
|
|
||||||
|
for (const authListItem of authList.valueBlock.value) {
|
||||||
|
if (
|
||||||
|
// version 1 does not provide this data structure
|
||||||
|
versionValue !== 1 &&
|
||||||
|
authListItem.idBlock.tagNumber === 709
|
||||||
|
) {
|
||||||
|
if (!('value' in authListItem.valueBlock)) continue
|
||||||
|
|
||||||
|
const value = (authListItem.valueBlock as unknown as { value: object }).value
|
||||||
|
|
||||||
|
if (!Array.isArray(value) || value.length !== 1) continue
|
||||||
|
|
||||||
|
if (value[0] instanceof OctetString) applicationId = value[0]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!applicationId) return null
|
||||||
|
|
||||||
|
const parsedApplicationId = fromBER(applicationId.valueBlock.valueHexView)
|
||||||
|
|
||||||
|
if (parsedApplicationId.offset === -1) return null
|
||||||
|
|
||||||
|
if (!(parsedApplicationId.result instanceof Sequence)) return null
|
||||||
|
|
||||||
|
const parsedApplicationIdInfo = parsedApplicationId.result.valueBlock.value
|
||||||
|
|
||||||
|
if (parsedApplicationIdInfo.length !== 2) return null
|
||||||
|
|
||||||
|
const signatureDigests = parsedApplicationIdInfo[1]
|
||||||
|
|
||||||
|
if (!(signatureDigests instanceof Set)) return null
|
||||||
|
|
||||||
|
const applicationCerts = []
|
||||||
|
|
||||||
|
for (const cert of signatureDigests.valueBlock.value) {
|
||||||
|
if (cert instanceof OctetString) {
|
||||||
|
applicationCerts.push(Buffer.from(cert.valueBlock.valueHexView).toString('hex'))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
applicationCerts
|
||||||
|
}
|
||||||
|
} catch (ex) {
|
||||||
|
return null
|
||||||
|
}
|
||||||
|
}
|
||||||
+9
-3
@@ -1,6 +1,6 @@
|
|||||||
/*
|
/*
|
||||||
* server component for the TimeLimit App
|
* server component for the TimeLimit App
|
||||||
* Copyright (C) 2019 - 2022 Jonas Lochmann
|
* Copyright (C) 2019 - 2024 Jonas Lochmann
|
||||||
*
|
*
|
||||||
* This program is free software: you can redistribute it and/or modify
|
* This program is free software: you can redistribute it and/or modify
|
||||||
* it under the terms of the GNU Affero General Public License as
|
* it under the terms of the GNU Affero General Public License as
|
||||||
@@ -22,6 +22,7 @@ interface Config {
|
|||||||
pingInterval: number
|
pingInterval: number
|
||||||
alwaysPro: boolean
|
alwaysPro: boolean
|
||||||
signSecret: string
|
signSecret: string
|
||||||
|
uaMailBlocklist: Array<string>
|
||||||
}
|
}
|
||||||
|
|
||||||
function parseYesNo (value: string) {
|
function parseYesNo (value: string) {
|
||||||
@@ -34,12 +35,17 @@ function parseYesNo (value: string) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function parseList(list: string) {
|
||||||
|
return list.split(',').map((item) => item.trim()).filter((item) => item.length > 0)
|
||||||
|
}
|
||||||
|
|
||||||
class ParseYesNoException extends Error {}
|
class ParseYesNoException extends Error {}
|
||||||
|
|
||||||
export const config: Config = {
|
export const config: Config = {
|
||||||
mailWhitelist: (process.env.MAIL_WHITELIST || '').split(',').map((item) => item.trim()).filter((item) => item.length > 0),
|
mailWhitelist: parseList(process.env.MAIL_WHITELIST || ''),
|
||||||
disableSignup: parseYesNo(process.env.DISABLE_SIGNUP || 'no'),
|
disableSignup: parseYesNo(process.env.DISABLE_SIGNUP || 'no'),
|
||||||
pingInterval: parseInt(process.env.PING_INTERVAL_SEC || '25', 10) * 1000,
|
pingInterval: parseInt(process.env.PING_INTERVAL_SEC || '25', 10) * 1000,
|
||||||
alwaysPro: process.env.ALWAYS_PRO ? parseYesNo(process.env.ALWAYS_PRO) : false,
|
alwaysPro: process.env.ALWAYS_PRO ? parseYesNo(process.env.ALWAYS_PRO) : false,
|
||||||
signSecret: process.env.SIGN_SECRET || ''
|
signSecret: process.env.SIGN_SECRET || '',
|
||||||
|
uaMailBlocklist: parseList(process.env.UA_MAIL_BLOCKLIST || '')
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
/*
|
/*
|
||||||
* server component for the TimeLimit App
|
* server component for the TimeLimit App
|
||||||
* Copyright (C) 2019 - 2023 Jonas Lochmann
|
* Copyright (C) 2019 - 2024 Jonas Lochmann
|
||||||
*
|
*
|
||||||
* This program is free software: you can redistribute it and/or modify
|
* This program is free software: you can redistribute it and/or modify
|
||||||
* it under the terms of the GNU Affero General Public License as
|
* it under the terms of the GNU Affero General Public License as
|
||||||
@@ -23,11 +23,12 @@ import { checkMailSendLimit } from '../../util/ratelimit-authmail'
|
|||||||
import { generateAuthToken } from '../../util/token'
|
import { generateAuthToken } from '../../util/token'
|
||||||
import { createAuthTokenByMailAddress } from './index'
|
import { createAuthTokenByMailAddress } from './index'
|
||||||
|
|
||||||
export const sendLoginCode = async ({ mail, deviceAuthToken, locale, database }: {
|
export const sendLoginCode = async ({ mail, deviceAuthToken, locale, database, info }: {
|
||||||
mail: string
|
mail: string
|
||||||
deviceAuthToken?: string
|
deviceAuthToken?: string
|
||||||
locale: string
|
locale: string
|
||||||
database: Database
|
database: Database
|
||||||
|
info: Buffer
|
||||||
// no transaction here because this is directly called from an API endpoint
|
// no transaction here because this is directly called from an API endpoint
|
||||||
}): Promise<{ mailLoginToken: string }> => {
|
}): Promise<{ mailLoginToken: string }> => {
|
||||||
let deviceName = null
|
let deviceName = null
|
||||||
@@ -82,7 +83,8 @@ export const sendLoginCode = async ({ mail, deviceAuthToken, locale, database }:
|
|||||||
receiver: mail,
|
receiver: mail,
|
||||||
code,
|
code,
|
||||||
locale,
|
locale,
|
||||||
deviceName
|
deviceName,
|
||||||
|
info
|
||||||
})
|
})
|
||||||
|
|
||||||
await database.transaction(async (transaction) => {
|
await database.transaction(async (transaction) => {
|
||||||
|
|||||||
+16
-6
@@ -1,6 +1,6 @@
|
|||||||
/*
|
/*
|
||||||
* server component for the TimeLimit App
|
* server component for the TimeLimit App
|
||||||
* Copyright (C) 2019 - 2023 Jonas Lochmann
|
* Copyright (C) 2019 - 2024 Jonas Lochmann
|
||||||
*
|
*
|
||||||
* This program is free software: you can redistribute it and/or modify
|
* This program is free software: you can redistribute it and/or modify
|
||||||
* it under the terms of the GNU Affero General Public License as
|
* it under the terms of the GNU Affero General Public License as
|
||||||
@@ -45,9 +45,10 @@ function createMailTemplateSender (templateName: string) {
|
|||||||
const textTemplate = compileTemplate('text.ejs')
|
const textTemplate = compileTemplate('text.ejs')
|
||||||
const htmlTemplate = compileTemplate('html.ejs')
|
const htmlTemplate = compileTemplate('html.ejs')
|
||||||
|
|
||||||
const sendMail = async ({ receiver, params }: {
|
const sendMail = async ({ receiver, params, info }: {
|
||||||
receiver: string
|
receiver: string
|
||||||
params: object
|
params: object
|
||||||
|
info?: Buffer
|
||||||
}) => {
|
}) => {
|
||||||
if (!mailTransport) {
|
if (!mailTransport) {
|
||||||
throw new Error('can not send mails without mail config and without NODE_ENV=development')
|
throw new Error('can not send mails without mail config and without NODE_ENV=development')
|
||||||
@@ -56,6 +57,9 @@ function createMailTemplateSender (templateName: string) {
|
|||||||
const subject = subjectTemplate(params).replace(/\n/g, ' ')
|
const subject = subjectTemplate(params).replace(/\n/g, ' ')
|
||||||
const text = textTemplate(params)
|
const text = textTemplate(params)
|
||||||
const html = htmlTemplate(params)
|
const html = htmlTemplate(params)
|
||||||
|
const headers: {[key: string]: string} = info ? {
|
||||||
|
'X-TlInfo': info.toString('base64')
|
||||||
|
} : {}
|
||||||
|
|
||||||
await new Promise<void>((resolve, reject) => {
|
await new Promise<void>((resolve, reject) => {
|
||||||
mailTransport.sendMail({
|
mailTransport.sendMail({
|
||||||
@@ -63,7 +67,8 @@ function createMailTemplateSender (templateName: string) {
|
|||||||
to: receiver,
|
to: receiver,
|
||||||
subject,
|
subject,
|
||||||
text,
|
text,
|
||||||
html
|
html,
|
||||||
|
headers
|
||||||
}, (err, info) => {
|
}, (err, info) => {
|
||||||
if (err) {
|
if (err) {
|
||||||
reject(err)
|
reject(err)
|
||||||
@@ -90,9 +95,13 @@ function createMailTemplateSender (templateName: string) {
|
|||||||
const loginMailSender = createMailTemplateSender('login')
|
const loginMailSender = createMailTemplateSender('login')
|
||||||
|
|
||||||
export const sendAuthenticationMail = async ({
|
export const sendAuthenticationMail = async ({
|
||||||
receiver, code, locale, deviceName
|
receiver, code, locale, deviceName, info
|
||||||
}: {
|
}: {
|
||||||
receiver: string, code: string, locale: string, deviceName: string | null
|
receiver: string
|
||||||
|
code: string
|
||||||
|
locale: string
|
||||||
|
deviceName: string | null
|
||||||
|
info: Buffer
|
||||||
}) => {
|
}) => {
|
||||||
await loginMailSender.sendMail({
|
await loginMailSender.sendMail({
|
||||||
receiver,
|
receiver,
|
||||||
@@ -105,7 +114,8 @@ export const sendAuthenticationMail = async ({
|
|||||||
deviceName,
|
deviceName,
|
||||||
deviceNameIntro: locale === 'de' ? 'Die Anmeldung wurde am Gerät' : 'The login was attempted at the device',
|
deviceNameIntro: locale === 'de' ? 'Die Anmeldung wurde am Gerät' : 'The login was attempted at the device',
|
||||||
deviceNameOutro: locale === 'de' ? 'versucht.' : '.'
|
deviceNameOutro: locale === 'de' ? 'versucht.' : '.'
|
||||||
}
|
},
|
||||||
|
info
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user