cic-staff-client/src/app/_services/auth.service.ts

219 lines
7.1 KiB
TypeScript
Raw Normal View History

2021-05-10 18:15:25 +02:00
import { Injectable } from '@angular/core';
import { hobaParseChallengeHeader } from '@src/assets/js/hoba.js';
import { signChallenge } from '@src/assets/js/hoba-pgp.js';
import { environment } from '@src/environments/environment';
import { LoggingService } from '@app/_services/logging.service';
import { MutableKeyStore, MutablePgpKeyStore } from '@app/_pgp';
import { ErrorDialogService } from '@app/_services/error-dialog.service';
import { HttpClient } from '@angular/common/http';
2021-05-17 08:06:07 +02:00
import { HttpError, rejectBody } from '@app/_helpers/global-error-handler';
2020-12-28 10:09:11 +01:00
@Injectable({
2021-05-10 18:15:25 +02:00
providedIn: 'root',
2020-12-28 10:09:11 +01:00
})
export class AuthService {
2021-01-18 14:04:16 +01:00
sessionToken: any;
2021-04-29 07:29:54 +02:00
mutableKeyStore: MutableKeyStore;
2020-12-28 10:09:11 +01:00
constructor(
2021-03-19 17:05:15 +01:00
private httpClient: HttpClient,
private loggingService: LoggingService,
private errorDialogService: ErrorDialogService
) {
this.mutableKeyStore = new MutablePgpKeyStore();
}
2021-04-29 07:29:54 +02:00
async init(): Promise<void> {
await this.mutableKeyStore.loadKeyring();
// TODO setting these together should be atomic
2021-01-18 14:04:16 +01:00
if (sessionStorage.getItem(btoa('CICADA_SESSION_TOKEN'))) {
this.sessionToken = sessionStorage.getItem(btoa('CICADA_SESSION_TOKEN'));
}
if (localStorage.getItem(btoa('CICADA_PRIVATE_KEY'))) {
await this.mutableKeyStore.importPrivateKey(localStorage.getItem(btoa('CICADA_PRIVATE_KEY')));
2021-01-18 14:04:16 +01:00
}
}
2020-12-28 10:09:11 +01:00
setState(s): void {
document.getElementById('state').innerHTML = s;
2020-12-28 10:09:11 +01:00
}
2021-05-15 12:42:46 +02:00
getWithToken(): Promise<boolean> {
return new Promise((resolve, reject) => {
const headers = {
Authorization: 'Bearer ' + this.sessionToken,
'Content-Type': 'application/json;charset=utf-8',
'x-cic-automerge': 'none',
};
const options = {
headers,
};
fetch(environment.cicMetaUrl, options).then((response) => {
if (response.status === 401) {
2021-05-17 08:06:07 +02:00
return reject(rejectBody(response));
2021-05-15 12:42:46 +02:00
}
return resolve(true);
});
2020-12-28 10:09:11 +01:00
});
}
// TODO rename to send signed challenge and set session. Also separate these responsibilities
sendResponse(hobaResponseEncoded: any): Promise<boolean> {
2021-04-29 07:29:54 +02:00
return new Promise((resolve, reject) => {
2021-05-15 12:42:46 +02:00
const headers = {
Authorization: 'HOBA ' + hobaResponseEncoded,
'Content-Type': 'application/json;charset=utf-8',
'x-cic-automerge': 'none',
};
const options = {
headers,
};
fetch(environment.cicMetaUrl, options).then((response) => {
if (response.status === 401) {
2021-05-17 08:06:07 +02:00
return reject(rejectBody(response));
2021-04-29 07:29:54 +02:00
}
2021-05-15 12:42:46 +02:00
this.sessionToken = response.headers.get('Token');
2021-04-29 07:29:54 +02:00
sessionStorage.setItem(btoa('CICADA_SESSION_TOKEN'), this.sessionToken);
this.setState('Click button to log in');
return resolve(true);
});
});
2020-12-28 10:09:11 +01:00
}
2021-05-15 12:42:46 +02:00
getChallenge(): Promise<any> {
return new Promise((resolve, reject) => {
fetch(environment.cicMetaUrl).then(async (response) => {
if (response.status === 401) {
const authHeader: string = response.headers.get('WWW-Authenticate');
return resolve(hobaParseChallengeHeader(authHeader));
}
if (!response.ok) {
2021-05-17 08:06:07 +02:00
return reject(rejectBody(response));
2021-05-15 12:42:46 +02:00
}
});
});
2020-12-28 10:09:11 +01:00
}
2021-05-15 12:42:46 +02:00
async login(): Promise<boolean> {
2020-12-28 10:09:11 +01:00
if (this.sessionToken !== undefined) {
try {
2021-05-15 12:42:46 +02:00
const response: boolean = await this.getWithToken();
return response === true;
2020-12-28 10:09:11 +01:00
} catch (e) {
2021-05-10 18:15:25 +02:00
this.loggingService.sendErrorLevelMessage('Login token failed', this, { error: e });
2020-12-28 10:09:11 +01:00
}
} else {
try {
2021-05-15 12:42:46 +02:00
const o = await this.getChallenge();
const response: boolean = await this.loginResponse(o);
return response === true;
2020-12-28 10:09:11 +01:00
} catch (e) {
2021-05-10 18:15:25 +02:00
this.loggingService.sendErrorLevelMessage('Login challenge failed', this, { error: e });
2020-12-28 10:09:11 +01:00
}
}
return false;
}
2021-05-10 18:15:25 +02:00
async loginResponse(o: { challenge: string; realm: any }): Promise<any> {
return new Promise(async (resolve, reject) => {
2020-12-28 10:09:11 +01:00
try {
2021-05-10 18:15:25 +02:00
const r = await signChallenge(
o.challenge,
o.realm,
environment.cicMetaUrl,
this.mutableKeyStore
);
2021-05-15 12:42:46 +02:00
const response: boolean = await this.sendResponse(r);
resolve(response);
2021-04-29 07:29:54 +02:00
} catch (error) {
if (error instanceof HttpError) {
if (error.status === 403) {
2021-05-10 18:15:25 +02:00
this.errorDialogService.openDialog({
message: 'You are not authorized to use this system',
});
2021-05-15 12:42:46 +02:00
} else if (error.status === 401) {
this.errorDialogService.openDialog({
2021-05-10 18:15:25 +02:00
message:
'Unable to authenticate with the service. ' +
'Please speak with the staff at Grassroots ' +
'Economics for requesting access ' +
2021-05-10 18:15:25 +02:00
'staff@grassrootseconomics.net.',
});
2021-04-29 07:29:54 +02:00
}
2021-05-15 12:42:46 +02:00
} else {
// TODO define this error
this.errorDialogService.openDialog({ message: 'Incorrect key passphrase.' });
2021-04-29 07:29:54 +02:00
}
resolve(false);
2020-12-28 10:09:11 +01:00
}
2021-04-29 07:29:54 +02:00
});
2020-12-28 10:09:11 +01:00
}
loginView(): void {
document.getElementById('one').style.display = 'none';
document.getElementById('two').style.display = 'block';
this.setState('Click button to log in with PGP key ' + this.mutableKeyStore.getPrivateKeyId());
2020-12-28 10:09:11 +01:00
}
async setKey(privateKeyArmored): Promise<boolean> {
try {
const isValidKeyCheck = await this.mutableKeyStore.isValidKey(privateKeyArmored);
2021-03-21 03:23:50 +01:00
if (!isValidKeyCheck) {
2021-03-21 12:02:18 +01:00
throw Error('The private key is invalid');
2021-03-21 03:23:50 +01:00
}
2021-04-29 07:29:54 +02:00
// TODO leaving this out for now.
// const isEncryptedKeyCheck = await this.mutableKeyStore.isEncryptedPrivateKey(privateKeyArmored);
// if (!isEncryptedKeyCheck) {
// throw Error('The private key doesn\'t have a password!');
// }
2021-03-21 03:23:50 +01:00
const key = await this.mutableKeyStore.importPrivateKey(privateKeyArmored);
localStorage.setItem(btoa('CICADA_PRIVATE_KEY'), privateKeyArmored);
} catch (err) {
2021-05-10 18:15:25 +02:00
this.loggingService.sendErrorLevelMessage(
`Failed to set key: ${err.message || err.statusText}`,
this,
{ error: err }
);
this.errorDialogService.openDialog({
2021-03-21 03:23:50 +01:00
message: `Failed to set key: ${err.message || err.statusText}`,
});
2020-12-28 10:09:11 +01:00
return false;
}
this.loginView();
return true;
}
2021-01-18 14:04:16 +01:00
logout(): void {
sessionStorage.removeItem(btoa('CICADA_SESSION_TOKEN'));
2021-05-15 12:42:46 +02:00
localStorage.removeItem(btoa('CICADA_PRIVATE_KEY'));
2021-03-24 17:41:11 +01:00
this.sessionToken = undefined;
2021-05-10 18:15:25 +02:00
window.location.reload();
2021-01-18 14:04:16 +01:00
}
2021-03-16 18:13:48 +01:00
getTrustedUsers(): any {
const trustedUsers: Array<any> = [];
2021-05-10 18:15:25 +02:00
this.mutableKeyStore.getPublicKeys().forEach((key) => trustedUsers.push(key.users[0].userId));
2021-03-16 18:13:48 +01:00
return trustedUsers;
}
2021-04-29 07:29:54 +02:00
async getPublicKeys(): Promise<any> {
2021-05-17 08:06:07 +02:00
return new Promise((resolve, reject) => {
fetch(environment.publicKeysUrl).then((res) => {
if (!res.ok) {
// TODO does angular recommend an error interface?
return reject(rejectBody(res));
}
return resolve(res.text());
});
2021-05-10 18:15:25 +02:00
});
2021-03-21 03:23:50 +01:00
}
2021-04-29 07:29:54 +02:00
getPrivateKey(): any {
2021-05-10 18:15:25 +02:00
return this.mutableKeyStore.getPrivateKey();
}
getPrivateKeyInfo(): any {
return this.getPrivateKey().users[0].userId;
}
2020-12-28 10:09:11 +01:00
}