api_mfa.go 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317
  1. // Copyright (C) 2019-2023 Nicola Murino
  2. //
  3. // This program is free software: you can redistribute it and/or modify
  4. // it under the terms of the GNU Affero General Public License as published
  5. // by the Free Software Foundation, version 3.
  6. //
  7. // This program is distributed in the hope that it will be useful,
  8. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  9. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  10. // GNU Affero General Public License for more details.
  11. //
  12. // You should have received a copy of the GNU Affero General Public License
  13. // along with this program. If not, see <https://www.gnu.org/licenses/>.
  14. package httpd
  15. import (
  16. "bytes"
  17. "errors"
  18. "fmt"
  19. "io"
  20. "net/http"
  21. "strconv"
  22. "strings"
  23. "github.com/go-chi/render"
  24. "github.com/drakkan/sftpgo/v2/internal/dataprovider"
  25. "github.com/drakkan/sftpgo/v2/internal/kms"
  26. "github.com/drakkan/sftpgo/v2/internal/mfa"
  27. "github.com/drakkan/sftpgo/v2/internal/util"
  28. )
  29. var (
  30. errRecoveryCodeForbidden = errors.New("recovery codes are not available with two-factor authentication disabled")
  31. )
  32. type generateTOTPRequest struct {
  33. ConfigName string `json:"config_name"`
  34. }
  35. type generateTOTPResponse struct {
  36. ConfigName string `json:"config_name"`
  37. Issuer string `json:"issuer"`
  38. Secret string `json:"secret"`
  39. URL string `json:"url"`
  40. QRCode []byte `json:"qr_code"`
  41. }
  42. type validateTOTPRequest struct {
  43. ConfigName string `json:"config_name"`
  44. Passcode string `json:"passcode"`
  45. Secret string `json:"secret"`
  46. }
  47. type recoveryCode struct {
  48. Code string `json:"code"`
  49. Used bool `json:"used"`
  50. }
  51. func getTOTPConfigs(w http.ResponseWriter, r *http.Request) {
  52. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  53. render.JSON(w, r, mfa.GetAvailableTOTPConfigs())
  54. }
  55. func generateTOTPSecret(w http.ResponseWriter, r *http.Request) {
  56. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  57. claims, err := getTokenClaims(r)
  58. if err != nil || claims.Username == "" {
  59. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  60. return
  61. }
  62. var accountName string
  63. if claims.hasUserAudience() {
  64. accountName = fmt.Sprintf("User %q", claims.Username)
  65. } else {
  66. accountName = fmt.Sprintf("Admin %q", claims.Username)
  67. }
  68. var req generateTOTPRequest
  69. err = render.DecodeJSON(r.Body, &req)
  70. if err != nil {
  71. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  72. return
  73. }
  74. configName, key, qrCode, err := mfa.GenerateTOTPSecret(req.ConfigName, accountName)
  75. if err != nil {
  76. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  77. return
  78. }
  79. render.JSON(w, r, generateTOTPResponse{
  80. ConfigName: configName,
  81. Issuer: key.Issuer(),
  82. Secret: key.Secret(),
  83. URL: key.URL(),
  84. QRCode: qrCode,
  85. })
  86. }
  87. func getQRCode(w http.ResponseWriter, r *http.Request) {
  88. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  89. img, err := mfa.GenerateQRCodeFromURL(r.URL.Query().Get("url"), 400, 400)
  90. if err != nil {
  91. sendAPIResponse(w, r, nil, "unable to generate qr code", http.StatusInternalServerError)
  92. return
  93. }
  94. imgSize := int64(len(img))
  95. w.Header().Set("Content-Length", strconv.FormatInt(imgSize, 10))
  96. w.Header().Set("Content-Type", "image/png")
  97. io.CopyN(w, bytes.NewBuffer(img), imgSize) //nolint:errcheck
  98. }
  99. func saveTOTPConfig(w http.ResponseWriter, r *http.Request) {
  100. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  101. claims, err := getTokenClaims(r)
  102. if err != nil || claims.Username == "" {
  103. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  104. return
  105. }
  106. recoveryCodes := make([]dataprovider.RecoveryCode, 0, 12)
  107. for i := 0; i < 12; i++ {
  108. code := getNewRecoveryCode()
  109. recoveryCodes = append(recoveryCodes, dataprovider.RecoveryCode{Secret: kms.NewPlainSecret(code)})
  110. }
  111. if claims.hasUserAudience() {
  112. if err := saveUserTOTPConfig(claims.Username, r, recoveryCodes); err != nil {
  113. sendAPIResponse(w, r, err, "", getRespStatus(err))
  114. return
  115. }
  116. if claims.MustSetTwoFactorAuth {
  117. // force logout
  118. defer func() {
  119. c := jwtTokenClaims{}
  120. c.removeCookie(w, r, webBaseClientPath)
  121. }()
  122. }
  123. } else {
  124. if err := saveAdminTOTPConfig(claims.Username, r, recoveryCodes); err != nil {
  125. sendAPIResponse(w, r, err, "", getRespStatus(err))
  126. return
  127. }
  128. }
  129. sendAPIResponse(w, r, nil, "TOTP configuration saved", http.StatusOK)
  130. }
  131. func validateTOTPPasscode(w http.ResponseWriter, r *http.Request) {
  132. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  133. var req validateTOTPRequest
  134. err := render.DecodeJSON(r.Body, &req)
  135. if err != nil {
  136. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  137. return
  138. }
  139. match, err := mfa.ValidateTOTPPasscode(req.ConfigName, req.Passcode, req.Secret)
  140. if !match || err != nil {
  141. sendAPIResponse(w, r, err, "Invalid passcode", http.StatusBadRequest)
  142. return
  143. }
  144. sendAPIResponse(w, r, nil, "Passcode successfully validated", http.StatusOK)
  145. }
  146. func getRecoveryCodes(w http.ResponseWriter, r *http.Request) {
  147. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  148. claims, err := getTokenClaims(r)
  149. if err != nil || claims.Username == "" {
  150. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  151. return
  152. }
  153. recoveryCodes := make([]recoveryCode, 0, 12)
  154. var accountRecoveryCodes []dataprovider.RecoveryCode
  155. if claims.hasUserAudience() {
  156. user, err := dataprovider.UserExists(claims.Username, "")
  157. if err != nil {
  158. sendAPIResponse(w, r, err, "", getRespStatus(err))
  159. return
  160. }
  161. if !user.Filters.TOTPConfig.Enabled {
  162. sendAPIResponse(w, r, errRecoveryCodeForbidden, "", http.StatusForbidden)
  163. return
  164. }
  165. accountRecoveryCodes = user.Filters.RecoveryCodes
  166. } else {
  167. admin, err := dataprovider.AdminExists(claims.Username)
  168. if err != nil {
  169. sendAPIResponse(w, r, err, "", getRespStatus(err))
  170. return
  171. }
  172. if !admin.Filters.TOTPConfig.Enabled {
  173. sendAPIResponse(w, r, errRecoveryCodeForbidden, "", http.StatusForbidden)
  174. return
  175. }
  176. accountRecoveryCodes = admin.Filters.RecoveryCodes
  177. }
  178. for _, code := range accountRecoveryCodes {
  179. if err := code.Secret.Decrypt(); err != nil {
  180. sendAPIResponse(w, r, err, "Unable to decrypt recovery codes", getRespStatus(err))
  181. return
  182. }
  183. recoveryCodes = append(recoveryCodes, recoveryCode{
  184. Code: code.Secret.GetPayload(),
  185. Used: code.Used,
  186. })
  187. }
  188. render.JSON(w, r, recoveryCodes)
  189. }
  190. func generateRecoveryCodes(w http.ResponseWriter, r *http.Request) {
  191. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  192. claims, err := getTokenClaims(r)
  193. if err != nil || claims.Username == "" {
  194. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  195. return
  196. }
  197. recoveryCodes := make([]string, 0, 12)
  198. accountRecoveryCodes := make([]dataprovider.RecoveryCode, 0, 12)
  199. for i := 0; i < 12; i++ {
  200. code := getNewRecoveryCode()
  201. recoveryCodes = append(recoveryCodes, code)
  202. accountRecoveryCodes = append(accountRecoveryCodes, dataprovider.RecoveryCode{Secret: kms.NewPlainSecret(code)})
  203. }
  204. if claims.hasUserAudience() {
  205. user, err := dataprovider.UserExists(claims.Username, "")
  206. if err != nil {
  207. sendAPIResponse(w, r, err, "", getRespStatus(err))
  208. return
  209. }
  210. if !user.Filters.TOTPConfig.Enabled {
  211. sendAPIResponse(w, r, errRecoveryCodeForbidden, "", http.StatusForbidden)
  212. return
  213. }
  214. user.Filters.RecoveryCodes = accountRecoveryCodes
  215. if err := dataprovider.UpdateUser(&user, dataprovider.ActionExecutorSelf, util.GetIPFromRemoteAddress(r.RemoteAddr), user.Role); err != nil {
  216. sendAPIResponse(w, r, err, "", getRespStatus(err))
  217. return
  218. }
  219. } else {
  220. admin, err := dataprovider.AdminExists(claims.Username)
  221. if err != nil {
  222. sendAPIResponse(w, r, err, "", getRespStatus(err))
  223. return
  224. }
  225. if !admin.Filters.TOTPConfig.Enabled {
  226. sendAPIResponse(w, r, errRecoveryCodeForbidden, "", http.StatusForbidden)
  227. return
  228. }
  229. admin.Filters.RecoveryCodes = accountRecoveryCodes
  230. if err := dataprovider.UpdateAdmin(&admin, dataprovider.ActionExecutorSelf, util.GetIPFromRemoteAddress(r.RemoteAddr), admin.Role); err != nil {
  231. sendAPIResponse(w, r, err, "", getRespStatus(err))
  232. return
  233. }
  234. }
  235. render.JSON(w, r, recoveryCodes)
  236. }
  237. func getNewRecoveryCode() string {
  238. return fmt.Sprintf("RC-%v", strings.ToUpper(util.GenerateUniqueID()))
  239. }
  240. func saveUserTOTPConfig(username string, r *http.Request, recoveryCodes []dataprovider.RecoveryCode) error {
  241. user, err := dataprovider.UserExists(username, "")
  242. if err != nil {
  243. return err
  244. }
  245. currentTOTPSecret := user.Filters.TOTPConfig.Secret
  246. user.Filters.TOTPConfig.Secret = nil
  247. err = render.DecodeJSON(r.Body, &user.Filters.TOTPConfig)
  248. if err != nil {
  249. return util.NewValidationError(fmt.Sprintf("unable to decode JSON body: %v", err))
  250. }
  251. if !user.Filters.TOTPConfig.Enabled && len(user.Filters.TwoFactorAuthProtocols) > 0 {
  252. return util.NewValidationError("two-factor authentication must be enabled")
  253. }
  254. for _, p := range user.Filters.TwoFactorAuthProtocols {
  255. if !util.Contains(user.Filters.TOTPConfig.Protocols, p) {
  256. return util.NewValidationError(fmt.Sprintf("totp: the following protocols are required: %q",
  257. strings.Join(user.Filters.TwoFactorAuthProtocols, ", ")))
  258. }
  259. }
  260. if user.Filters.TOTPConfig.Secret == nil || !user.Filters.TOTPConfig.Secret.IsPlain() {
  261. user.Filters.TOTPConfig.Secret = currentTOTPSecret
  262. }
  263. if user.Filters.TOTPConfig.Enabled {
  264. if user.CountUnusedRecoveryCodes() < 5 && user.Filters.TOTPConfig.Enabled {
  265. user.Filters.RecoveryCodes = recoveryCodes
  266. }
  267. } else {
  268. user.Filters.RecoveryCodes = nil
  269. }
  270. return dataprovider.UpdateUser(&user, dataprovider.ActionExecutorSelf, util.GetIPFromRemoteAddress(r.RemoteAddr), user.Role)
  271. }
  272. func saveAdminTOTPConfig(username string, r *http.Request, recoveryCodes []dataprovider.RecoveryCode) error {
  273. admin, err := dataprovider.AdminExists(username)
  274. if err != nil {
  275. return err
  276. }
  277. currentTOTPSecret := admin.Filters.TOTPConfig.Secret
  278. admin.Filters.TOTPConfig.Secret = nil
  279. err = render.DecodeJSON(r.Body, &admin.Filters.TOTPConfig)
  280. if err != nil {
  281. return util.NewValidationError(fmt.Sprintf("unable to decode JSON body: %v", err))
  282. }
  283. if admin.Filters.TOTPConfig.Enabled {
  284. if admin.CountUnusedRecoveryCodes() < 5 && admin.Filters.TOTPConfig.Enabled {
  285. admin.Filters.RecoveryCodes = recoveryCodes
  286. }
  287. } else {
  288. admin.Filters.RecoveryCodes = nil
  289. }
  290. if admin.Filters.TOTPConfig.Secret == nil || !admin.Filters.TOTPConfig.Secret.IsPlain() {
  291. admin.Filters.TOTPConfig.Secret = currentTOTPSecret
  292. }
  293. return dataprovider.UpdateAdmin(&admin, dataprovider.ActionExecutorSelf, util.GetIPFromRemoteAddress(r.RemoteAddr), admin.Role)
  294. }