2016-05-25 20:17:42 +02:00
|
|
|
///<reference path="../customtypings/ExtendedRequest.d.ts"/>
|
2018-03-30 15:30:30 -04:00
|
|
|
import {NextFunction, Request, Response} from 'express';
|
|
|
|
import {ErrorCodes, ErrorDTO} from '../../../common/entities/Error';
|
|
|
|
import {UserDTO, UserRoles} from '../../../common/entities/UserDTO';
|
2019-02-15 11:47:09 -05:00
|
|
|
import {ObjectManagers} from '../../model/ObjectManagers';
|
2018-03-30 15:30:30 -04:00
|
|
|
import {Config} from '../../../common/config/private/Config';
|
|
|
|
import {PasswordHelper} from '../../model/PasswordHelper';
|
|
|
|
import {Utils} from '../../../common/Utils';
|
2018-11-30 15:36:42 +01:00
|
|
|
import {QueryParams} from '../../../common/QueryParams';
|
2019-02-22 23:39:01 +01:00
|
|
|
import * as path from 'path';
|
2016-03-19 17:31:42 +01:00
|
|
|
|
2016-03-26 11:19:10 +01:00
|
|
|
export class AuthenticationMWs {
|
2016-03-19 17:31:42 +01:00
|
|
|
|
2017-07-13 23:39:09 +02:00
|
|
|
public static async tryAuthenticate(req: Request, res: Response, next: NextFunction) {
|
|
|
|
if (Config.Client.authenticationRequired === false) {
|
2018-12-04 22:08:13 +01:00
|
|
|
req.session.user = <UserDTO>{name: UserRoles[Config.Client.unAuthenticatedUserRole], role: Config.Client.unAuthenticatedUserRole};
|
2017-07-13 23:39:09 +02:00
|
|
|
return next();
|
|
|
|
}
|
|
|
|
try {
|
|
|
|
const user = await AuthenticationMWs.getSharingUser(req);
|
|
|
|
if (!!user) {
|
|
|
|
req.session.user = user;
|
|
|
|
return next();
|
|
|
|
}
|
|
|
|
} catch (err) {
|
|
|
|
}
|
|
|
|
|
|
|
|
return next();
|
|
|
|
|
|
|
|
}
|
2017-07-15 17:48:29 +02:00
|
|
|
|
2017-07-03 19:17:49 +02:00
|
|
|
public static async authenticate(req: Request, res: Response, next: NextFunction) {
|
|
|
|
|
|
|
|
if (Config.Client.authenticationRequired === false) {
|
2018-12-04 22:08:13 +01:00
|
|
|
req.session.user = <UserDTO>{name: UserRoles[Config.Client.unAuthenticatedUserRole], role: Config.Client.unAuthenticatedUserRole};
|
2017-07-03 19:17:49 +02:00
|
|
|
return next();
|
|
|
|
}
|
|
|
|
try {
|
|
|
|
const user = await AuthenticationMWs.getSharingUser(req);
|
|
|
|
if (!!user) {
|
|
|
|
req.session.user = user;
|
2016-03-19 17:31:42 +01:00
|
|
|
return next();
|
2017-07-03 19:17:49 +02:00
|
|
|
}
|
|
|
|
} catch (err) {
|
2017-07-15 12:47:11 +02:00
|
|
|
return next(new ErrorDTO(ErrorCodes.CREDENTIAL_NOT_FOUND, null, err));
|
2017-07-03 19:17:49 +02:00
|
|
|
}
|
|
|
|
if (typeof req.session.user === 'undefined') {
|
2017-07-15 12:47:11 +02:00
|
|
|
return next(new ErrorDTO(ErrorCodes.NOT_AUTHENTICATED));
|
2016-03-19 17:31:42 +01:00
|
|
|
}
|
2017-07-16 10:59:28 +02:00
|
|
|
if (req.session.rememberMe === true) {
|
|
|
|
req.sessionOptions.expires = new Date(Date.now() + Config.Server.sessionTimeout);
|
|
|
|
} else {
|
2018-11-30 15:36:42 +01:00
|
|
|
delete (req.sessionOptions.expires);
|
2017-07-16 10:59:28 +02:00
|
|
|
}
|
2017-07-03 19:17:49 +02:00
|
|
|
return next();
|
|
|
|
}
|
2016-05-09 17:04:56 +02:00
|
|
|
|
2018-03-30 15:30:30 -04:00
|
|
|
|
2019-02-22 23:39:01 +01:00
|
|
|
public static normalizePathParam(paramName: string) {
|
|
|
|
return (req: Request, res: Response, next: NextFunction) => {
|
|
|
|
req.params[paramName] = path.normalize(req.params[paramName] || path.sep).replace(/^(\.\.[\/\\])+/, '');
|
2018-03-30 15:30:30 -04:00
|
|
|
return next();
|
2019-02-22 23:39:01 +01:00
|
|
|
};
|
|
|
|
}
|
2018-03-30 15:30:30 -04:00
|
|
|
|
2019-02-22 23:39:01 +01:00
|
|
|
public static authorisePath(paramName: string, isDirectory: boolean) {
|
|
|
|
return (req: Request, res: Response, next: NextFunction) => {
|
|
|
|
let p: string = req.params[paramName];
|
|
|
|
if (!isDirectory) {
|
|
|
|
p = path.dirname(p);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!UserDTO.isDirectoryPathAvailable(p, req.session.user.permissions, path.sep)) {
|
|
|
|
return res.sendStatus(403);
|
|
|
|
}
|
|
|
|
|
|
|
|
return next();
|
|
|
|
};
|
2018-03-30 15:30:30 -04:00
|
|
|
}
|
|
|
|
|
2019-02-22 23:39:01 +01:00
|
|
|
|
2017-07-03 19:17:49 +02:00
|
|
|
public static authorise(role: UserRoles) {
|
|
|
|
return (req: Request, res: Response, next: NextFunction) => {
|
|
|
|
if (req.session.user.role < role) {
|
2017-07-15 12:47:11 +02:00
|
|
|
return next(new ErrorDTO(ErrorCodes.NOT_AUTHORISED));
|
2017-07-03 19:17:49 +02:00
|
|
|
}
|
|
|
|
return next();
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
2018-03-30 15:30:30 -04:00
|
|
|
public static async shareLogin(req: Request, res: Response, next: NextFunction) {
|
|
|
|
|
|
|
|
if (Config.Client.Sharing.enabled === false) {
|
2017-07-03 19:17:49 +02:00
|
|
|
return next();
|
|
|
|
}
|
2018-05-12 12:19:51 -04:00
|
|
|
// not enough parameter
|
2018-11-30 15:36:42 +01:00
|
|
|
if ((!req.query[QueryParams.gallery.sharingKey_short] && !req.params[QueryParams.gallery.sharingKey_long])) {
|
2018-03-30 15:30:30 -04:00
|
|
|
return next(new ErrorDTO(ErrorCodes.INPUT_ERROR, 'no sharing key provided'));
|
|
|
|
}
|
2016-05-16 23:15:03 +02:00
|
|
|
|
2018-03-30 15:30:30 -04:00
|
|
|
try {
|
|
|
|
const password = (req.body ? req.body.password : null) || null;
|
|
|
|
|
2019-02-15 11:47:09 -05:00
|
|
|
const sharing = await ObjectManagers.getInstance().SharingManager.findOne({
|
2018-11-30 15:36:42 +01:00
|
|
|
sharingKey: req.query[QueryParams.gallery.sharingKey_short] || req.params[QueryParams.gallery.sharingKey_long]
|
2018-03-30 15:30:30 -04:00
|
|
|
});
|
2018-05-16 17:47:32 -04:00
|
|
|
|
2018-03-30 15:30:30 -04:00
|
|
|
if (!sharing || sharing.expires < Date.now() ||
|
|
|
|
(Config.Client.Sharing.passwordProtected === true
|
2018-05-16 17:47:32 -04:00
|
|
|
&& (sharing.password)
|
|
|
|
&& !PasswordHelper.comparePassword(password, sharing.password))) {
|
2018-03-30 15:30:30 -04:00
|
|
|
return next(new ErrorDTO(ErrorCodes.CREDENTIAL_NOT_FOUND));
|
|
|
|
}
|
|
|
|
|
2019-02-22 23:39:01 +01:00
|
|
|
let sharingPath = sharing.path;
|
2018-05-12 12:19:51 -04:00
|
|
|
if (sharing.includeSubfolders === true) {
|
2019-02-22 23:39:01 +01:00
|
|
|
sharingPath += '*';
|
2018-03-30 15:30:30 -04:00
|
|
|
}
|
|
|
|
|
2019-02-22 23:39:01 +01:00
|
|
|
req.session.user = <UserDTO>{name: 'Guest', role: UserRoles.LimitedGuest, permissions: [sharingPath]};
|
2017-07-03 19:17:49 +02:00
|
|
|
return next();
|
2018-03-30 15:30:30 -04:00
|
|
|
|
|
|
|
} catch (err) {
|
|
|
|
return next(new ErrorDTO(ErrorCodes.GENERAL_ERROR, null, err));
|
2017-07-03 19:17:49 +02:00
|
|
|
}
|
2018-02-03 19:50:42 -05:00
|
|
|
|
2017-07-03 19:17:49 +02:00
|
|
|
}
|
2016-03-19 17:31:42 +01:00
|
|
|
|
2017-07-03 19:17:49 +02:00
|
|
|
public static inverseAuthenticate(req: Request, res: Response, next: NextFunction) {
|
|
|
|
if (typeof req.session.user !== 'undefined') {
|
2017-07-15 12:47:11 +02:00
|
|
|
return next(new ErrorDTO(ErrorCodes.ALREADY_AUTHENTICATED));
|
2017-07-03 19:17:49 +02:00
|
|
|
}
|
|
|
|
return next();
|
|
|
|
}
|
2016-03-19 17:31:42 +01:00
|
|
|
|
2017-07-03 19:17:49 +02:00
|
|
|
public static async login(req: Request, res: Response, next: NextFunction) {
|
|
|
|
|
2018-05-12 12:19:51 -04:00
|
|
|
// not enough parameter
|
|
|
|
if ((typeof req.body === 'undefined') ||
|
|
|
|
(typeof req.body.loginCredential === 'undefined') ||
|
|
|
|
(typeof req.body.loginCredential.username === 'undefined') ||
|
2017-07-03 19:17:49 +02:00
|
|
|
(typeof req.body.loginCredential.password === 'undefined')) {
|
2017-07-15 12:47:11 +02:00
|
|
|
return next(new ErrorDTO(ErrorCodes.INPUT_ERROR));
|
2016-03-19 17:31:42 +01:00
|
|
|
}
|
2017-07-03 19:17:49 +02:00
|
|
|
try {
|
2018-05-12 12:19:51 -04:00
|
|
|
// lets find the user
|
2019-02-15 11:47:09 -05:00
|
|
|
const user = Utils.clone(await ObjectManagers.getInstance().UserManager.findOne({
|
2017-07-03 19:17:49 +02:00
|
|
|
name: req.body.loginCredential.username,
|
|
|
|
password: req.body.loginCredential.password
|
2017-07-16 10:59:28 +02:00
|
|
|
}));
|
|
|
|
delete (user.password);
|
|
|
|
req.session.user = user;
|
|
|
|
if (req.body.loginCredential.rememberMe) {
|
|
|
|
req.sessionOptions.expires = new Date(Date.now() + Config.Server.sessionTimeout);
|
|
|
|
}
|
2017-07-03 19:17:49 +02:00
|
|
|
return next();
|
2016-03-19 17:31:42 +01:00
|
|
|
|
2017-07-03 19:17:49 +02:00
|
|
|
} catch (err) {
|
2017-07-15 12:47:11 +02:00
|
|
|
return next(new ErrorDTO(ErrorCodes.CREDENTIAL_NOT_FOUND));
|
2016-05-16 23:15:03 +02:00
|
|
|
}
|
2016-03-19 17:31:42 +01:00
|
|
|
|
2017-07-03 19:17:49 +02:00
|
|
|
|
|
|
|
}
|
|
|
|
|
2019-02-22 23:39:01 +01:00
|
|
|
public static logout(req: Request, res: Response, next: NextFunction) {
|
|
|
|
delete req.session.user;
|
|
|
|
delete req.session.rememberMe;
|
|
|
|
return next();
|
|
|
|
}
|
|
|
|
|
2018-03-30 15:30:30 -04:00
|
|
|
private static async getSharingUser(req: Request) {
|
|
|
|
if (Config.Client.Sharing.enabled === true &&
|
2018-11-30 15:36:42 +01:00
|
|
|
(!!req.params[QueryParams.gallery.sharingKey_short] || !!req.params[QueryParams.gallery.sharingKey_long])) {
|
2019-02-15 11:47:09 -05:00
|
|
|
const sharing = await ObjectManagers.getInstance().SharingManager.findOne({
|
2018-11-30 15:36:42 +01:00
|
|
|
sharingKey: req.query[QueryParams.gallery.sharingKey_short] || req.params[QueryParams.gallery.sharingKey_long],
|
2017-07-09 12:03:17 +02:00
|
|
|
});
|
2018-03-30 15:30:30 -04:00
|
|
|
if (!sharing || sharing.expires < Date.now()) {
|
|
|
|
return null;
|
|
|
|
}
|
|
|
|
|
2018-05-16 17:47:32 -04:00
|
|
|
if (Config.Client.Sharing.passwordProtected === true && (sharing.password)) {
|
2018-03-30 15:30:30 -04:00
|
|
|
return null;
|
2017-07-09 12:03:17 +02:00
|
|
|
}
|
|
|
|
|
2019-02-22 23:39:01 +01:00
|
|
|
let sharingPath = sharing.path;
|
2018-05-12 12:19:51 -04:00
|
|
|
if (sharing.includeSubfolders === true) {
|
2019-02-22 23:39:01 +01:00
|
|
|
sharingPath += '*';
|
2017-07-09 12:03:17 +02:00
|
|
|
}
|
2019-02-22 23:39:01 +01:00
|
|
|
return <UserDTO>{
|
|
|
|
name: 'Guest',
|
|
|
|
role: UserRoles.LimitedGuest,
|
|
|
|
permissions: [sharingPath],
|
|
|
|
usedSharingKey: sharing.sharingKey
|
|
|
|
};
|
2017-07-09 12:03:17 +02:00
|
|
|
|
|
|
|
}
|
2018-03-30 15:30:30 -04:00
|
|
|
return null;
|
2017-07-09 12:03:17 +02:00
|
|
|
}
|
|
|
|
|
2017-07-03 19:17:49 +02:00
|
|
|
}
|