api_mfa.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322
  1. // Copyright (C) 2019 Nicola Murino
  2. //
  3. // This program is free software: you can redistribute it and/or modify
  4. // it under the terms of the GNU Affero General Public License as published
  5. // by the Free Software Foundation, version 3.
  6. //
  7. // This program is distributed in the hope that it will be useful,
  8. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  9. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  10. // GNU Affero General Public License for more details.
  11. //
  12. // You should have received a copy of the GNU Affero General Public License
  13. // along with this program. If not, see <https://www.gnu.org/licenses/>.
  14. package httpd
  15. import (
  16. "bytes"
  17. "errors"
  18. "fmt"
  19. "io"
  20. "net/http"
  21. "strconv"
  22. "strings"
  23. "github.com/go-chi/render"
  24. "github.com/drakkan/sftpgo/v2/internal/dataprovider"
  25. "github.com/drakkan/sftpgo/v2/internal/kms"
  26. "github.com/drakkan/sftpgo/v2/internal/mfa"
  27. "github.com/drakkan/sftpgo/v2/internal/util"
  28. )
  29. var (
  30. errRecoveryCodeForbidden = errors.New("recovery codes are not available with two-factor authentication disabled")
  31. )
  32. type generateTOTPRequest struct {
  33. ConfigName string `json:"config_name"`
  34. }
  35. type generateTOTPResponse struct {
  36. ConfigName string `json:"config_name"`
  37. Issuer string `json:"issuer"`
  38. Secret string `json:"secret"`
  39. URL string `json:"url"`
  40. QRCode []byte `json:"qr_code"`
  41. }
  42. type validateTOTPRequest struct {
  43. ConfigName string `json:"config_name"`
  44. Passcode string `json:"passcode"`
  45. Secret string `json:"secret"`
  46. }
  47. type recoveryCode struct {
  48. Code string `json:"code"`
  49. Used bool `json:"used"`
  50. }
  51. func getTOTPConfigs(w http.ResponseWriter, r *http.Request) {
  52. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  53. render.JSON(w, r, mfa.GetAvailableTOTPConfigs())
  54. }
  55. func generateTOTPSecret(w http.ResponseWriter, r *http.Request) {
  56. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  57. claims, err := getTokenClaims(r)
  58. if err != nil || claims.Username == "" {
  59. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  60. return
  61. }
  62. var accountName string
  63. if claims.hasUserAudience() {
  64. accountName = fmt.Sprintf("User %q", claims.Username)
  65. } else {
  66. accountName = fmt.Sprintf("Admin %q", claims.Username)
  67. }
  68. var req generateTOTPRequest
  69. err = render.DecodeJSON(r.Body, &req)
  70. if err != nil {
  71. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  72. return
  73. }
  74. configName, key, qrCode, err := mfa.GenerateTOTPSecret(req.ConfigName, accountName)
  75. if err != nil {
  76. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  77. return
  78. }
  79. render.JSON(w, r, generateTOTPResponse{
  80. ConfigName: configName,
  81. Issuer: key.Issuer(),
  82. Secret: key.Secret(),
  83. URL: key.URL(),
  84. QRCode: qrCode,
  85. })
  86. }
  87. func getQRCode(w http.ResponseWriter, r *http.Request) {
  88. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  89. img, err := mfa.GenerateQRCodeFromURL(r.URL.Query().Get("url"), 400, 400)
  90. if err != nil {
  91. sendAPIResponse(w, r, nil, "unable to generate qr code", http.StatusInternalServerError)
  92. return
  93. }
  94. imgSize := int64(len(img))
  95. w.Header().Set("Content-Length", strconv.FormatInt(imgSize, 10))
  96. w.Header().Set("Content-Type", "image/png")
  97. io.CopyN(w, bytes.NewBuffer(img), imgSize) //nolint:errcheck
  98. }
  99. func saveTOTPConfig(w http.ResponseWriter, r *http.Request) {
  100. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  101. claims, err := getTokenClaims(r)
  102. if err != nil || claims.Username == "" {
  103. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  104. return
  105. }
  106. recoveryCodes := make([]dataprovider.RecoveryCode, 0, 12)
  107. for i := 0; i < 12; i++ {
  108. code := getNewRecoveryCode()
  109. recoveryCodes = append(recoveryCodes, dataprovider.RecoveryCode{Secret: kms.NewPlainSecret(code)})
  110. }
  111. baseURL := webBaseClientPath
  112. if claims.hasUserAudience() {
  113. if err := saveUserTOTPConfig(claims.Username, r, recoveryCodes); err != nil {
  114. sendAPIResponse(w, r, err, "", getRespStatus(err))
  115. return
  116. }
  117. } else {
  118. if err := saveAdminTOTPConfig(claims.Username, r, recoveryCodes); err != nil {
  119. sendAPIResponse(w, r, err, "", getRespStatus(err))
  120. return
  121. }
  122. baseURL = webBasePath
  123. }
  124. if claims.MustSetTwoFactorAuth {
  125. // force logout
  126. defer func() {
  127. c := jwtTokenClaims{}
  128. c.removeCookie(w, r, baseURL)
  129. }()
  130. }
  131. sendAPIResponse(w, r, nil, "TOTP configuration saved", http.StatusOK)
  132. }
  133. func validateTOTPPasscode(w http.ResponseWriter, r *http.Request) {
  134. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  135. var req validateTOTPRequest
  136. err := render.DecodeJSON(r.Body, &req)
  137. if err != nil {
  138. sendAPIResponse(w, r, err, "", http.StatusBadRequest)
  139. return
  140. }
  141. match, err := mfa.ValidateTOTPPasscode(req.ConfigName, req.Passcode, req.Secret)
  142. if !match || err != nil {
  143. sendAPIResponse(w, r, err, "Invalid passcode", http.StatusBadRequest)
  144. return
  145. }
  146. sendAPIResponse(w, r, nil, "Passcode successfully validated", http.StatusOK)
  147. }
  148. func getRecoveryCodes(w http.ResponseWriter, r *http.Request) {
  149. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  150. claims, err := getTokenClaims(r)
  151. if err != nil || claims.Username == "" {
  152. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  153. return
  154. }
  155. recoveryCodes := make([]recoveryCode, 0, 12)
  156. var accountRecoveryCodes []dataprovider.RecoveryCode
  157. if claims.hasUserAudience() {
  158. user, err := dataprovider.UserExists(claims.Username, "")
  159. if err != nil {
  160. sendAPIResponse(w, r, err, "", getRespStatus(err))
  161. return
  162. }
  163. if !user.Filters.TOTPConfig.Enabled {
  164. sendAPIResponse(w, r, errRecoveryCodeForbidden, "", http.StatusForbidden)
  165. return
  166. }
  167. accountRecoveryCodes = user.Filters.RecoveryCodes
  168. } else {
  169. admin, err := dataprovider.AdminExists(claims.Username)
  170. if err != nil {
  171. sendAPIResponse(w, r, err, "", getRespStatus(err))
  172. return
  173. }
  174. if !admin.Filters.TOTPConfig.Enabled {
  175. sendAPIResponse(w, r, errRecoveryCodeForbidden, "", http.StatusForbidden)
  176. return
  177. }
  178. accountRecoveryCodes = admin.Filters.RecoveryCodes
  179. }
  180. for _, code := range accountRecoveryCodes {
  181. if err := code.Secret.Decrypt(); err != nil {
  182. sendAPIResponse(w, r, err, "Unable to decrypt recovery codes", getRespStatus(err))
  183. return
  184. }
  185. recoveryCodes = append(recoveryCodes, recoveryCode{
  186. Code: code.Secret.GetPayload(),
  187. Used: code.Used,
  188. })
  189. }
  190. render.JSON(w, r, recoveryCodes)
  191. }
  192. func generateRecoveryCodes(w http.ResponseWriter, r *http.Request) {
  193. r.Body = http.MaxBytesReader(w, r.Body, maxRequestSize)
  194. claims, err := getTokenClaims(r)
  195. if err != nil || claims.Username == "" {
  196. sendAPIResponse(w, r, err, "Invalid token claims", http.StatusBadRequest)
  197. return
  198. }
  199. recoveryCodes := make([]string, 0, 12)
  200. accountRecoveryCodes := make([]dataprovider.RecoveryCode, 0, 12)
  201. for i := 0; i < 12; i++ {
  202. code := getNewRecoveryCode()
  203. recoveryCodes = append(recoveryCodes, code)
  204. accountRecoveryCodes = append(accountRecoveryCodes, dataprovider.RecoveryCode{Secret: kms.NewPlainSecret(code)})
  205. }
  206. if claims.hasUserAudience() {
  207. user, err := dataprovider.UserExists(claims.Username, "")
  208. if err != nil {
  209. sendAPIResponse(w, r, err, "", getRespStatus(err))
  210. return
  211. }
  212. if !user.Filters.TOTPConfig.Enabled {
  213. sendAPIResponse(w, r, errRecoveryCodeForbidden, "", http.StatusForbidden)
  214. return
  215. }
  216. user.Filters.RecoveryCodes = accountRecoveryCodes
  217. if err := dataprovider.UpdateUser(&user, dataprovider.ActionExecutorSelf, util.GetIPFromRemoteAddress(r.RemoteAddr), user.Role); err != nil {
  218. sendAPIResponse(w, r, err, "", getRespStatus(err))
  219. return
  220. }
  221. } else {
  222. admin, err := dataprovider.AdminExists(claims.Username)
  223. if err != nil {
  224. sendAPIResponse(w, r, err, "", getRespStatus(err))
  225. return
  226. }
  227. if !admin.Filters.TOTPConfig.Enabled {
  228. sendAPIResponse(w, r, errRecoveryCodeForbidden, "", http.StatusForbidden)
  229. return
  230. }
  231. admin.Filters.RecoveryCodes = accountRecoveryCodes
  232. if err := dataprovider.UpdateAdmin(&admin, dataprovider.ActionExecutorSelf, util.GetIPFromRemoteAddress(r.RemoteAddr), admin.Role); err != nil {
  233. sendAPIResponse(w, r, err, "", getRespStatus(err))
  234. return
  235. }
  236. }
  237. render.JSON(w, r, recoveryCodes)
  238. }
  239. func getNewRecoveryCode() string {
  240. return fmt.Sprintf("RC-%v", strings.ToUpper(util.GenerateUniqueID()))
  241. }
  242. func saveUserTOTPConfig(username string, r *http.Request, recoveryCodes []dataprovider.RecoveryCode) error {
  243. user, userMerged, err := dataprovider.GetUserVariants(username, "")
  244. if err != nil {
  245. return err
  246. }
  247. currentTOTPSecret := user.Filters.TOTPConfig.Secret
  248. user.Filters.TOTPConfig.Secret = nil
  249. err = render.DecodeJSON(r.Body, &user.Filters.TOTPConfig)
  250. if err != nil {
  251. return util.NewValidationError(fmt.Sprintf("unable to decode JSON body: %v", err))
  252. }
  253. if !user.Filters.TOTPConfig.Enabled && len(userMerged.Filters.TwoFactorAuthProtocols) > 0 {
  254. return util.NewValidationError("two-factor authentication must be enabled")
  255. }
  256. for _, p := range userMerged.Filters.TwoFactorAuthProtocols {
  257. if !util.Contains(user.Filters.TOTPConfig.Protocols, p) {
  258. return util.NewValidationError(fmt.Sprintf("totp: the following protocols are required: %q",
  259. strings.Join(userMerged.Filters.TwoFactorAuthProtocols, ", ")))
  260. }
  261. }
  262. if user.Filters.TOTPConfig.Secret == nil || !user.Filters.TOTPConfig.Secret.IsPlain() {
  263. user.Filters.TOTPConfig.Secret = currentTOTPSecret
  264. }
  265. if user.Filters.TOTPConfig.Enabled {
  266. if user.CountUnusedRecoveryCodes() < 5 && user.Filters.TOTPConfig.Enabled {
  267. user.Filters.RecoveryCodes = recoveryCodes
  268. }
  269. } else {
  270. user.Filters.RecoveryCodes = nil
  271. }
  272. return dataprovider.UpdateUser(&user, dataprovider.ActionExecutorSelf, util.GetIPFromRemoteAddress(r.RemoteAddr), user.Role)
  273. }
  274. func saveAdminTOTPConfig(username string, r *http.Request, recoveryCodes []dataprovider.RecoveryCode) error {
  275. admin, err := dataprovider.AdminExists(username)
  276. if err != nil {
  277. return err
  278. }
  279. currentTOTPSecret := admin.Filters.TOTPConfig.Secret
  280. admin.Filters.TOTPConfig.Secret = nil
  281. err = render.DecodeJSON(r.Body, &admin.Filters.TOTPConfig)
  282. if err != nil {
  283. return util.NewValidationError(fmt.Sprintf("unable to decode JSON body: %v", err))
  284. }
  285. if !admin.Filters.TOTPConfig.Enabled && admin.Filters.RequireTwoFactor {
  286. return util.NewValidationError("two-factor authentication must be enabled")
  287. }
  288. if admin.Filters.TOTPConfig.Enabled {
  289. if admin.CountUnusedRecoveryCodes() < 5 && admin.Filters.TOTPConfig.Enabled {
  290. admin.Filters.RecoveryCodes = recoveryCodes
  291. }
  292. } else {
  293. admin.Filters.RecoveryCodes = nil
  294. }
  295. if admin.Filters.TOTPConfig.Secret == nil || !admin.Filters.TOTPConfig.Secret.IsPlain() {
  296. admin.Filters.TOTPConfig.Secret = currentTOTPSecret
  297. }
  298. return dataprovider.UpdateAdmin(&admin, dataprovider.ActionExecutorSelf, util.GetIPFromRemoteAddress(r.RemoteAddr), admin.Role)
  299. }