2015-03-15 08:06:08 -07:00
|
|
|
// Package confirm implements confirmation of user registration via e-mail
|
2015-02-07 04:27:12 -08:00
|
|
|
package confirm
|
|
|
|
|
|
|
|
import (
|
2017-02-23 16:13:25 -08:00
|
|
|
"context"
|
2015-02-07 04:27:12 -08:00
|
|
|
"crypto/rand"
|
2018-02-27 07:14:30 -08:00
|
|
|
"crypto/sha512"
|
2015-02-07 04:27:12 -08:00
|
|
|
"encoding/base64"
|
|
|
|
"fmt"
|
|
|
|
"net/http"
|
2015-02-10 00:43:45 -08:00
|
|
|
"net/url"
|
2015-02-26 22:01:53 -08:00
|
|
|
"path"
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2017-02-21 15:04:30 -08:00
|
|
|
"github.com/pkg/errors"
|
|
|
|
|
2017-07-30 19:39:33 -07:00
|
|
|
"github.com/volatiletech/authboss"
|
2015-02-07 04:27:12 -08:00
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
2018-02-27 07:14:30 -08:00
|
|
|
// PageConfirm is only really used for the BodyReader
|
|
|
|
PageConfirm = "confirm"
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// EmailConfirmHTML is the name of the html template for e-mails
|
|
|
|
EmailConfirmHTML = "confirm_html"
|
|
|
|
// EmailConfirmTxt is the name of the text template for e-mails
|
|
|
|
EmailConfirmTxt = "confirm_txt"
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// FormValueConfirm is the name of the form value for
|
|
|
|
FormValueConfirm = "cnf"
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// DataConfirmURL is the name of the e-mail template variable
|
|
|
|
// that gives the url to send to the user for confirmation.
|
|
|
|
DataConfirmURL = "url"
|
2015-02-07 04:27:12 -08:00
|
|
|
)
|
|
|
|
|
|
|
|
func init() {
|
2016-05-09 13:20:10 -04:00
|
|
|
authboss.RegisterModule("confirm", &Confirm{})
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
|
2015-03-16 14:42:45 -07:00
|
|
|
// Confirm module
|
2015-02-07 04:27:12 -08:00
|
|
|
type Confirm struct {
|
2015-03-31 15:27:47 -07:00
|
|
|
*authboss.Authboss
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// Init module
|
|
|
|
func (c *Confirm) Init(ab *authboss.Authboss) (err error) {
|
2015-03-31 15:27:47 -07:00
|
|
|
c.Authboss = ab
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
if err = c.Authboss.Config.Core.MailRenderer.Load(EmailConfirmHTML, EmailConfirmTxt); err != nil {
|
2015-09-21 20:53:51 -07:00
|
|
|
return err
|
2018-02-27 07:14:30 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
c.Authboss.Config.Core.Router.Get("/confirm", c.Authboss.Config.Core.ErrorHandler.Wrap(c.Get))
|
|
|
|
|
|
|
|
c.Events.Before(authboss.EventAuth, c.PreventAuth)
|
|
|
|
c.Events.After(authboss.EventRegister, c.StartConfirmationWeb)
|
2015-02-07 04:27:12 -08:00
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// PreventAuth stops the EventAuth from succeeding when a user is not confirmed
|
|
|
|
// This relies on the fact that the context holds the user at this point in time
|
|
|
|
// loaded by the auth module (or something else).
|
|
|
|
func (c *Confirm) PreventAuth(w http.ResponseWriter, r *http.Request, handled bool) (bool, error) {
|
|
|
|
logger := c.Authboss.RequestLogger(r)
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-03-07 16:41:58 -08:00
|
|
|
user, err := c.Authboss.CurrentUser(r)
|
2018-02-27 07:14:30 -08:00
|
|
|
if err != nil {
|
|
|
|
return false, err
|
|
|
|
}
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
cuser := authboss.MustBeConfirmable(user)
|
|
|
|
if cuser.GetConfirmed() {
|
|
|
|
logger.Infof("user %s was confirmed, allowing auth", user.GetPID())
|
|
|
|
return false, nil
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
2015-02-10 00:43:45 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
logger.Infof("user %s was not confirmed, preventing auth", user.GetPID())
|
|
|
|
ro := authboss.RedirectOptions{
|
|
|
|
Code: http.StatusTemporaryRedirect,
|
|
|
|
RedirectPath: c.Authboss.Config.Paths.ConfirmNotOK,
|
|
|
|
Failure: "Your account has not been confirmed, please check your e-mail.",
|
|
|
|
}
|
|
|
|
return true, c.Authboss.Config.Core.Redirector.Redirect(w, r, ro)
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// StartConfirmationWeb hijacks a request and forces a user to be confirmed first
|
|
|
|
// it's assumed that the current user is loaded into the request context.
|
|
|
|
func (c *Confirm) StartConfirmationWeb(w http.ResponseWriter, r *http.Request, handled bool) (bool, error) {
|
2018-03-07 16:41:58 -08:00
|
|
|
user, err := c.Authboss.CurrentUser(r)
|
2018-02-27 07:14:30 -08:00
|
|
|
if err != nil {
|
|
|
|
return false, err
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
cuser := authboss.MustBeConfirmable(user)
|
|
|
|
if err = c.StartConfirmation(r.Context(), cuser, true); err != nil {
|
|
|
|
return false, err
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
ro := authboss.RedirectOptions{
|
|
|
|
Code: http.StatusTemporaryRedirect,
|
|
|
|
RedirectPath: c.Authboss.Config.Paths.ConfirmNotOK,
|
|
|
|
Success: "Please verify your account, an e-mail has been sent to you.",
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
2018-02-27 07:14:30 -08:00
|
|
|
return true, c.Authboss.Config.Core.Redirector.Redirect(w, r, ro)
|
|
|
|
}
|
|
|
|
|
|
|
|
// StartConfirmation begins confirmation on a user by setting them to require confirmation
|
|
|
|
// via a created token, and optionally sending them an e-mail.
|
|
|
|
func (c *Confirm) StartConfirmation(ctx context.Context, user authboss.ConfirmableUser, sendEmail bool) error {
|
|
|
|
logger := c.Authboss.Logger(ctx)
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
hash, token, err := GenerateToken()
|
2015-02-22 00:09:52 -08:00
|
|
|
if err != nil {
|
|
|
|
return err
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
2015-02-22 00:09:52 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
user.PutConfirmed(false)
|
|
|
|
user.PutConfirmToken(hash)
|
|
|
|
|
|
|
|
logger.Infof("generated new confirm token for user: %s", user.GetPID())
|
|
|
|
if err := c.Authboss.Config.Storage.Server.Save(ctx, user); err != nil {
|
|
|
|
return errors.Wrap(err, "failed to save user during StartConfirmation, user data may be in weird state")
|
|
|
|
}
|
|
|
|
|
|
|
|
goConfirmEmail(c, ctx, user.GetEmail(), token)
|
2015-02-22 00:09:52 -08:00
|
|
|
|
|
|
|
return nil
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// This is here so it can be mocked out by a test
|
2017-02-23 16:13:25 -08:00
|
|
|
var goConfirmEmail = func(c *Confirm, ctx context.Context, to, token string) {
|
2018-02-27 07:14:30 -08:00
|
|
|
go c.SendConfirmEmail(ctx, to, token)
|
2015-02-10 00:43:45 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// SendConfirmEmail sends a confirmation e-mail to a user
|
|
|
|
func (c *Confirm) SendConfirmEmail(ctx context.Context, to, token string) {
|
|
|
|
logger := c.Authboss.Logger(ctx)
|
|
|
|
|
|
|
|
p := path.Join(c.Config.Paths.Mount, "confirm")
|
|
|
|
url := fmt.Sprintf("%s%s?%s=%s", c.Paths.RootURL, p, url.QueryEscape(FormValueConfirm), url.QueryEscape(token))
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2015-02-22 00:09:52 -08:00
|
|
|
email := authboss.Email{
|
|
|
|
To: []string{to},
|
2018-02-27 07:14:30 -08:00
|
|
|
From: c.Config.Mail.From,
|
|
|
|
Subject: c.Config.Mail.SubjectPrefix + "Confirm New Account",
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
logger.Infof("sending confirm e-mail to: %s", to)
|
|
|
|
|
|
|
|
ro := authboss.EmailResponseOptions{
|
|
|
|
Data: authboss.NewHTMLData(DataConfirmURL, url),
|
|
|
|
HTMLTemplate: EmailConfirmHTML,
|
|
|
|
TextTemplate: EmailConfirmTxt,
|
|
|
|
}
|
|
|
|
if err := c.Authboss.Email(ctx, email, ro); err != nil {
|
|
|
|
logger.Errorf("failed to send confirm e-mail to %s: %+v", to, err)
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// Get is a request that confirms a user with a valid token
|
|
|
|
func (c *Confirm) Get(w http.ResponseWriter, r *http.Request) error {
|
|
|
|
logger := c.RequestLogger(r)
|
|
|
|
|
|
|
|
validator, err := c.Authboss.Config.Core.BodyReader.Read(PageConfirm, r)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if errs := validator.Validate(); errs != nil {
|
|
|
|
logger.Infof("validation failed in Confirm.Get, this typically means a bad token: %+v", errs)
|
|
|
|
ro := authboss.RedirectOptions{
|
|
|
|
Code: http.StatusTemporaryRedirect,
|
|
|
|
Failure: "Invalid confirm token.",
|
|
|
|
RedirectPath: c.Authboss.Config.Paths.ConfirmNotOK,
|
|
|
|
}
|
|
|
|
return c.Authboss.Config.Core.Redirector.Redirect(w, r, ro)
|
2015-02-10 00:43:45 -08:00
|
|
|
}
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
values := authboss.MustHaveConfirmValues(validator)
|
|
|
|
|
|
|
|
toHash, err := base64.URLEncoding.DecodeString(values.GetToken())
|
2015-02-07 04:27:12 -08:00
|
|
|
if err != nil {
|
2018-02-27 07:14:30 -08:00
|
|
|
logger.Infof("error decoding token in Confirm.Get, this typically means a bad token: %s %+v", values.GetToken(), err)
|
|
|
|
ro := authboss.RedirectOptions{
|
|
|
|
Code: http.StatusTemporaryRedirect,
|
|
|
|
Failure: "Invalid confirm token.",
|
|
|
|
RedirectPath: c.Authboss.Config.Paths.ConfirmNotOK,
|
2015-02-22 00:09:52 -08:00
|
|
|
}
|
2018-02-27 07:14:30 -08:00
|
|
|
return c.Authboss.Config.Core.Redirector.Redirect(w, r, ro)
|
2015-02-10 00:43:45 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
sum := sha512.Sum512(toHash)
|
|
|
|
token := base64.StdEncoding.EncodeToString(sum[:])
|
2015-02-16 13:27:29 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
storer := authboss.EnsureCanConfirm(c.Authboss.Config.Storage.Server)
|
2018-03-05 17:47:11 -08:00
|
|
|
user, err := storer.LoadByConfirmToken(r.Context(), token)
|
2015-02-10 00:43:45 -08:00
|
|
|
if err == authboss.ErrUserNotFound {
|
2018-02-27 07:14:30 -08:00
|
|
|
logger.Infof("confirm token was not found in database: %s", token)
|
|
|
|
ro := authboss.RedirectOptions{
|
|
|
|
Code: http.StatusTemporaryRedirect,
|
|
|
|
Failure: "Invalid confirm token.",
|
|
|
|
RedirectPath: c.Authboss.Config.Paths.ConfirmNotOK,
|
|
|
|
}
|
|
|
|
return c.Authboss.Config.Core.Redirector.Redirect(w, r, ro)
|
2015-02-10 00:43:45 -08:00
|
|
|
} else if err != nil {
|
2015-02-22 00:09:52 -08:00
|
|
|
return err
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
user.PutConfirmToken("")
|
|
|
|
user.PutConfirmed(true)
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
logger.Infof("user %s confirmed their account", user.GetPID())
|
|
|
|
if err = c.Authboss.Config.Storage.Server.Save(r.Context(), user); err != nil {
|
2015-02-22 00:09:52 -08:00
|
|
|
return err
|
|
|
|
}
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
ro := authboss.RedirectOptions{
|
|
|
|
Code: http.StatusTemporaryRedirect,
|
|
|
|
Success: "You have successfully confirmed your account.",
|
|
|
|
RedirectPath: c.Authboss.Config.Paths.ConfirmOK,
|
2015-02-10 00:43:45 -08:00
|
|
|
}
|
2018-02-27 07:14:30 -08:00
|
|
|
return c.Authboss.Config.Core.Redirector.Redirect(w, r, ro)
|
|
|
|
}
|
2015-02-07 04:27:12 -08:00
|
|
|
|
2018-02-27 07:14:30 -08:00
|
|
|
// Middleware ensures that a user is confirmed, or else it will intercept the request
|
|
|
|
// and send them to the confirm page, this will load the user if he's not been loaded
|
|
|
|
// yet from the session.
|
|
|
|
//
|
|
|
|
// Panics if the user was not able to be loaded in order to allow a panic handler to show
|
|
|
|
// a nice error page, also panics if it failed to redirect for whatever reason.
|
2018-03-07 13:01:35 -08:00
|
|
|
func Middleware(ab *authboss.Authboss) func(http.Handler) http.Handler {
|
|
|
|
return func(next http.Handler) http.Handler {
|
|
|
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
2018-03-07 16:41:58 -08:00
|
|
|
user := ab.LoadCurrentUserP(&r)
|
2018-03-07 13:01:35 -08:00
|
|
|
|
|
|
|
cu := authboss.MustBeConfirmable(user)
|
|
|
|
if cu.GetConfirmed() {
|
|
|
|
next.ServeHTTP(w, r)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
logger := ab.RequestLogger(r)
|
|
|
|
logger.Infof("user %s prevented from accessing %s: not confirmed", user.GetPID(), r.URL.Path)
|
|
|
|
ro := authboss.RedirectOptions{
|
|
|
|
Code: http.StatusTemporaryRedirect,
|
|
|
|
Failure: "Your account has not been confirmed, please check your e-mail.",
|
|
|
|
RedirectPath: ab.Config.Paths.ConfirmNotOK,
|
|
|
|
}
|
|
|
|
ab.Config.Core.Redirector.Redirect(w, r, ro)
|
|
|
|
})
|
|
|
|
}
|
2018-02-27 07:14:30 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
// GenerateToken creates a random token that will be used to confirm the user.
|
|
|
|
func GenerateToken() (hash string, token string, err error) {
|
|
|
|
tok := make([]byte, 32)
|
|
|
|
if _, err := rand.Read(tok); err != nil {
|
|
|
|
return "", "", err
|
|
|
|
}
|
|
|
|
sum := sha512.Sum512(tok)
|
|
|
|
return base64.StdEncoding.EncodeToString(sum[:]), base64.URLEncoding.EncodeToString(tok[:]), nil
|
2015-02-07 04:27:12 -08:00
|
|
|
}
|