2016-08-15 02:58:33 -05:00
|
|
|
class UserApiKeysController < ApplicationController
|
|
|
|
|
2016-08-16 00:10:32 -05:00
|
|
|
layout 'no_ember'
|
|
|
|
|
2019-04-01 12:18:53 -05:00
|
|
|
requires_login only: [:create, :create_otp, :revoke, :undo_revoke]
|
|
|
|
skip_before_action :redirect_to_login_if_required, only: [:new, :otp]
|
2017-08-30 23:06:56 -05:00
|
|
|
skip_before_action :check_xhr, :preload_json
|
2016-08-15 02:58:33 -05:00
|
|
|
|
2019-04-01 12:18:53 -05:00
|
|
|
AUTH_API_VERSION ||= 4
|
2016-08-16 18:58:19 -05:00
|
|
|
|
2016-08-15 02:58:33 -05:00
|
|
|
def new
|
2016-08-16 18:58:19 -05:00
|
|
|
|
|
|
|
if request.head?
|
|
|
|
head :ok, auth_api_version: AUTH_API_VERSION
|
|
|
|
return
|
|
|
|
end
|
|
|
|
|
2016-08-16 00:10:32 -05:00
|
|
|
require_params
|
2016-08-23 01:48:00 -05:00
|
|
|
validate_params
|
2016-08-16 00:10:32 -05:00
|
|
|
|
|
|
|
unless current_user
|
|
|
|
cookies[:destination_url] = request.fullpath
|
2016-09-15 22:48:50 -05:00
|
|
|
|
|
|
|
if SiteSetting.enable_sso?
|
|
|
|
redirect_to path('/session/sso')
|
|
|
|
else
|
|
|
|
redirect_to path('/login')
|
|
|
|
end
|
2016-08-16 00:10:32 -05:00
|
|
|
return
|
|
|
|
end
|
|
|
|
|
2016-09-12 00:42:06 -05:00
|
|
|
unless meets_tl?
|
2016-08-23 01:48:00 -05:00
|
|
|
@no_trust_level = true
|
|
|
|
return
|
|
|
|
end
|
|
|
|
|
2016-08-16 00:10:32 -05:00
|
|
|
@application_name = params[:application_name]
|
|
|
|
@public_key = params[:public_key]
|
|
|
|
@nonce = params[:nonce]
|
|
|
|
@client_id = params[:client_id]
|
|
|
|
@auth_redirect = params[:auth_redirect]
|
|
|
|
@push_url = params[:push_url]
|
2017-07-27 20:20:09 -05:00
|
|
|
@localized_scopes = params[:scopes].split(",").map { |s| I18n.t("user_api_key.scopes.#{s}") }
|
2016-10-14 00:05:27 -05:00
|
|
|
@scopes = params[:scopes]
|
2016-08-17 01:44:20 -05:00
|
|
|
|
2016-08-23 01:48:00 -05:00
|
|
|
rescue Discourse::InvalidAccess
|
|
|
|
@generic_error = true
|
2016-08-15 02:58:33 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
def create
|
|
|
|
|
2016-08-16 00:10:32 -05:00
|
|
|
require_params
|
|
|
|
|
2019-04-01 12:18:53 -05:00
|
|
|
if params.key?(:auth_redirect)
|
|
|
|
raise Discourse::InvalidAccess if UserApiKey.invalid_auth_redirect?(params[:auth_redirect])
|
2016-08-15 02:58:33 -05:00
|
|
|
end
|
|
|
|
|
2016-09-12 00:42:06 -05:00
|
|
|
raise Discourse::InvalidAccess unless meets_tl?
|
2016-08-15 02:58:33 -05:00
|
|
|
|
2016-08-16 00:10:32 -05:00
|
|
|
validate_params
|
2019-01-03 21:46:18 -06:00
|
|
|
@application_name = params[:application_name]
|
2019-04-01 12:18:53 -05:00
|
|
|
scopes = params[:scopes].split(",")
|
2016-08-15 02:58:33 -05:00
|
|
|
|
2016-08-16 02:06:33 -05:00
|
|
|
# destroy any old keys we had
|
|
|
|
UserApiKey.where(user_id: current_user.id, client_id: params[:client_id]).destroy_all
|
|
|
|
|
2016-08-15 02:58:33 -05:00
|
|
|
key = UserApiKey.create!(
|
2019-01-03 21:46:18 -06:00
|
|
|
application_name: @application_name,
|
2016-08-15 02:58:33 -05:00
|
|
|
client_id: params[:client_id],
|
|
|
|
user_id: current_user.id,
|
2016-10-14 00:05:27 -05:00
|
|
|
push_url: params[:push_url],
|
2016-08-15 02:58:33 -05:00
|
|
|
key: SecureRandom.hex,
|
2019-04-01 12:18:53 -05:00
|
|
|
scopes: scopes
|
2016-08-15 02:58:33 -05:00
|
|
|
)
|
|
|
|
|
|
|
|
# we keep the payload short so it encrypts easily with public key
|
|
|
|
# it is often restricted to 128 chars
|
2019-01-03 21:46:18 -06:00
|
|
|
@payload = {
|
2016-08-15 02:58:33 -05:00
|
|
|
key: key.key,
|
|
|
|
nonce: params[:nonce],
|
2016-10-14 00:05:27 -05:00
|
|
|
push: key.has_push?,
|
|
|
|
api: AUTH_API_VERSION
|
2016-08-15 02:58:33 -05:00
|
|
|
}.to_json
|
|
|
|
|
|
|
|
public_key = OpenSSL::PKey::RSA.new(params[:public_key])
|
2019-01-03 21:46:18 -06:00
|
|
|
@payload = Base64.encode64(public_key.public_encrypt(@payload))
|
|
|
|
|
2019-04-01 12:18:53 -05:00
|
|
|
if scopes.include?("one_time_password")
|
|
|
|
# encrypt one_time_password separately to bypass 128 chars encryption limit
|
|
|
|
otp_payload = one_time_password(public_key, current_user.username)
|
|
|
|
end
|
|
|
|
|
2019-01-03 21:46:18 -06:00
|
|
|
if params[:auth_redirect]
|
2019-04-01 12:18:53 -05:00
|
|
|
redirect_path = "#{params[:auth_redirect]}?payload=#{CGI.escape(@payload)}"
|
|
|
|
redirect_path << "&oneTimePassword=#{CGI.escape(otp_payload)}" if scopes.include?("one_time_password")
|
|
|
|
redirect_to(redirect_path)
|
2019-01-03 21:46:18 -06:00
|
|
|
else
|
|
|
|
respond_to do |format|
|
|
|
|
format.html { render :show }
|
|
|
|
format.json do
|
|
|
|
instructions = I18n.t("user_api_key.instructions", application_name: @application_name)
|
|
|
|
render json: { payload: @payload, instructions: instructions }
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2016-08-15 02:58:33 -05:00
|
|
|
end
|
|
|
|
|
2019-04-01 12:18:53 -05:00
|
|
|
def otp
|
|
|
|
require_params_otp
|
|
|
|
|
|
|
|
unless current_user
|
|
|
|
cookies[:destination_url] = request.fullpath
|
|
|
|
|
|
|
|
if SiteSetting.enable_sso?
|
|
|
|
redirect_to path('/session/sso')
|
|
|
|
else
|
|
|
|
redirect_to path('/login')
|
|
|
|
end
|
|
|
|
return
|
|
|
|
end
|
|
|
|
|
|
|
|
@application_name = params[:application_name]
|
|
|
|
@public_key = params[:public_key]
|
|
|
|
@auth_redirect = params[:auth_redirect]
|
|
|
|
end
|
|
|
|
|
|
|
|
def create_otp
|
|
|
|
require_params_otp
|
|
|
|
|
|
|
|
raise Discourse::InvalidAccess if UserApiKey.invalid_auth_redirect?(params[:auth_redirect])
|
|
|
|
raise Discourse::InvalidAccess unless meets_tl?
|
|
|
|
|
|
|
|
public_key = OpenSSL::PKey::RSA.new(params[:public_key])
|
|
|
|
otp_payload = one_time_password(public_key, current_user.username)
|
|
|
|
|
|
|
|
redirect_path = "#{params[:auth_redirect]}?oneTimePassword=#{CGI.escape(otp_payload)}"
|
|
|
|
redirect_to(redirect_path)
|
|
|
|
end
|
|
|
|
|
2016-08-16 02:06:33 -05:00
|
|
|
def revoke
|
2016-09-02 02:08:46 -05:00
|
|
|
revoke_key = find_key if params[:id]
|
|
|
|
|
2016-09-02 01:57:41 -05:00
|
|
|
if current_key = request.env['HTTP_USER_API_KEY']
|
|
|
|
request_key = UserApiKey.find_by(key: current_key)
|
2016-09-02 02:08:46 -05:00
|
|
|
revoke_key ||= request_key
|
2016-10-14 00:05:27 -05:00
|
|
|
if request_key && request_key.id != revoke_key.id && !request_key.scopes.include?("write")
|
2016-09-02 01:57:41 -05:00
|
|
|
raise Discourse::InvalidAccess
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2016-09-02 02:08:46 -05:00
|
|
|
raise Discourse::NotFound unless revoke_key
|
|
|
|
|
2016-09-02 01:57:41 -05:00
|
|
|
revoke_key.update_columns(revoked_at: Time.zone.now)
|
|
|
|
|
2016-08-16 02:06:33 -05:00
|
|
|
render json: success_json
|
|
|
|
end
|
|
|
|
|
|
|
|
def undo_revoke
|
|
|
|
find_key.update_columns(revoked_at: nil)
|
|
|
|
render json: success_json
|
|
|
|
end
|
|
|
|
|
|
|
|
def find_key
|
|
|
|
key = UserApiKey.find(params[:id])
|
|
|
|
raise Discourse::InvalidAccess unless current_user.admin || key.user_id = current_user.id
|
|
|
|
key
|
|
|
|
end
|
|
|
|
|
2016-08-16 00:10:32 -05:00
|
|
|
def require_params
|
|
|
|
[
|
|
|
|
:public_key,
|
|
|
|
:nonce,
|
2016-10-14 00:05:27 -05:00
|
|
|
:scopes,
|
2016-08-16 00:10:32 -05:00
|
|
|
:client_id,
|
|
|
|
:application_name
|
2017-07-27 20:20:09 -05:00
|
|
|
].each { |p| params.require(p) }
|
2016-08-16 00:10:32 -05:00
|
|
|
end
|
|
|
|
|
2016-08-25 22:23:06 -05:00
|
|
|
def validate_params
|
2016-10-14 00:05:27 -05:00
|
|
|
requested_scopes = Set.new(params[:scopes].split(","))
|
|
|
|
raise Discourse::InvalidAccess unless UserApiKey.allowed_scopes.superset?(requested_scopes)
|
2016-08-16 00:10:32 -05:00
|
|
|
|
|
|
|
# our pk has got to parse
|
|
|
|
OpenSSL::PKey::RSA.new(params[:public_key])
|
|
|
|
end
|
|
|
|
|
2019-04-01 12:18:53 -05:00
|
|
|
def require_params_otp
|
|
|
|
[
|
|
|
|
:public_key,
|
|
|
|
:auth_redirect,
|
|
|
|
:application_name
|
|
|
|
].each { |p| params.require(p) }
|
|
|
|
end
|
|
|
|
|
2016-09-12 00:42:06 -05:00
|
|
|
def meets_tl?
|
|
|
|
current_user.staff? || current_user.trust_level >= SiteSetting.min_trust_level_for_user_api_key
|
|
|
|
end
|
|
|
|
|
2019-04-01 12:18:53 -05:00
|
|
|
def one_time_password(public_key, username)
|
|
|
|
raise Discourse::InvalidAccess unless UserApiKey.allowed_scopes.superset?(Set.new(["one_time_password"]))
|
|
|
|
|
|
|
|
otp = SecureRandom.hex
|
|
|
|
$redis.setex "otp_#{otp}", 10.minutes, username
|
|
|
|
|
|
|
|
Base64.encode64(public_key.public_encrypt(otp))
|
|
|
|
end
|
2016-08-15 02:58:33 -05:00
|
|
|
end
|