2018-02-15 00:53:11 +01:00
|
|
|
use chrono::{NaiveDateTime, Utc};
|
2018-10-10 20:40:39 +02:00
|
|
|
use serde_json::Value;
|
2018-02-10 01:00:55 +01:00
|
|
|
|
2018-12-07 02:05:45 +01:00
|
|
|
use crate::crypto;
|
|
|
|
use crate::CONFIG;
|
2018-02-10 01:00:55 +01:00
|
|
|
|
2018-02-15 00:40:34 +01:00
|
|
|
#[derive(Debug, Identifiable, Queryable, Insertable)]
|
2018-02-10 01:00:55 +01:00
|
|
|
#[table_name = "users"]
|
|
|
|
#[primary_key(uuid)]
|
|
|
|
pub struct User {
|
|
|
|
pub uuid: String,
|
|
|
|
pub created_at: NaiveDateTime,
|
|
|
|
pub updated_at: NaiveDateTime,
|
|
|
|
|
|
|
|
pub email: String,
|
|
|
|
pub name: String,
|
|
|
|
|
|
|
|
pub password_hash: Vec<u8>,
|
|
|
|
pub salt: Vec<u8>,
|
|
|
|
pub password_iterations: i32,
|
|
|
|
pub password_hint: Option<String>,
|
|
|
|
|
|
|
|
pub key: String,
|
|
|
|
pub private_key: Option<String>,
|
|
|
|
pub public_key: Option<String>,
|
2018-12-30 23:34:31 +01:00
|
|
|
|
2018-07-12 21:46:50 +02:00
|
|
|
#[column_name = "totp_secret"]
|
|
|
|
_totp_secret: Option<String>,
|
2018-02-10 01:00:55 +01:00
|
|
|
pub totp_recover: Option<String>,
|
2018-06-01 15:08:03 +02:00
|
|
|
|
2018-02-10 01:00:55 +01:00
|
|
|
pub security_stamp: String,
|
2018-02-15 00:40:34 +01:00
|
|
|
|
|
|
|
pub equivalent_domains: String,
|
|
|
|
pub excluded_globals: String,
|
2018-12-30 23:34:31 +01:00
|
|
|
|
2018-09-19 17:30:14 +02:00
|
|
|
pub client_kdf_type: i32,
|
|
|
|
pub client_kdf_iter: i32,
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
/// Local methods
|
|
|
|
impl User {
|
2018-09-19 17:30:14 +02:00
|
|
|
pub const CLIENT_KDF_TYPE_DEFAULT: i32 = 0; // PBKDF2: 0
|
|
|
|
pub const CLIENT_KDF_ITER_DEFAULT: i32 = 5_000;
|
|
|
|
|
2018-09-11 15:25:12 +02:00
|
|
|
pub fn new(mail: String) -> Self {
|
2018-02-10 01:00:55 +01:00
|
|
|
let now = Utc::now().naive_utc();
|
|
|
|
let email = mail.to_lowercase();
|
|
|
|
|
2018-02-15 00:40:34 +01:00
|
|
|
Self {
|
2018-12-07 14:32:40 +01:00
|
|
|
uuid: crate::util::get_uuid(),
|
2018-02-10 01:00:55 +01:00
|
|
|
created_at: now,
|
|
|
|
updated_at: now,
|
|
|
|
name: email.clone(),
|
|
|
|
email,
|
2018-09-11 15:25:12 +02:00
|
|
|
key: String::new(),
|
2018-02-10 01:00:55 +01:00
|
|
|
|
2018-09-11 15:25:12 +02:00
|
|
|
password_hash: Vec::new(),
|
2018-09-19 17:30:14 +02:00
|
|
|
salt: crypto::get_random_64(),
|
2019-01-25 18:23:51 +01:00
|
|
|
password_iterations: CONFIG.password_iterations(),
|
2018-02-10 01:00:55 +01:00
|
|
|
|
2018-12-07 14:32:40 +01:00
|
|
|
security_stamp: crate::util::get_uuid(),
|
2018-02-10 01:00:55 +01:00
|
|
|
|
|
|
|
password_hint: None,
|
|
|
|
private_key: None,
|
|
|
|
public_key: None,
|
2018-12-30 23:34:31 +01:00
|
|
|
|
2018-07-12 21:46:50 +02:00
|
|
|
_totp_secret: None,
|
2018-02-10 01:00:55 +01:00
|
|
|
totp_recover: None,
|
2018-02-15 00:40:34 +01:00
|
|
|
|
|
|
|
equivalent_domains: "[]".to_string(),
|
|
|
|
excluded_globals: "[]".to_string(),
|
2018-12-30 23:34:31 +01:00
|
|
|
|
2018-09-19 17:30:14 +02:00
|
|
|
client_kdf_type: Self::CLIENT_KDF_TYPE_DEFAULT,
|
|
|
|
client_kdf_iter: Self::CLIENT_KDF_ITER_DEFAULT,
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
pub fn check_valid_password(&self, password: &str) -> bool {
|
2018-12-30 23:34:31 +01:00
|
|
|
crypto::verify_password_hash(
|
|
|
|
password.as_bytes(),
|
|
|
|
&self.salt,
|
|
|
|
&self.password_hash,
|
|
|
|
self.password_iterations as u32,
|
|
|
|
)
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
|
|
|
|
2018-02-15 19:05:57 +01:00
|
|
|
pub fn check_valid_recovery_code(&self, recovery_code: &str) -> bool {
|
|
|
|
if let Some(ref totp_recover) = self.totp_recover {
|
|
|
|
recovery_code == totp_recover.to_lowercase()
|
|
|
|
} else {
|
|
|
|
false
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-02-10 01:00:55 +01:00
|
|
|
pub fn set_password(&mut self, password: &str) {
|
2018-12-30 23:34:31 +01:00
|
|
|
self.password_hash = crypto::hash_password(password.as_bytes(), &self.salt, self.password_iterations as u32);
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
pub fn reset_security_stamp(&mut self) {
|
2018-12-07 14:32:40 +01:00
|
|
|
self.security_stamp = crate::util::get_uuid();
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
2018-04-24 22:01:55 +02:00
|
|
|
}
|
|
|
|
|
2018-12-30 23:34:31 +01:00
|
|
|
use super::{Cipher, Device, Folder, TwoFactor, UserOrgType, UserOrganization};
|
|
|
|
use crate::db::schema::{invitations, users};
|
|
|
|
use crate::db::DbConn;
|
2018-04-24 22:01:55 +02:00
|
|
|
use diesel;
|
|
|
|
use diesel::prelude::*;
|
|
|
|
|
2018-12-19 21:52:53 +01:00
|
|
|
use crate::api::EmptyResult;
|
|
|
|
use crate::error::MapResult;
|
|
|
|
|
2018-04-24 22:01:55 +02:00
|
|
|
/// Database methods
|
|
|
|
impl User {
|
2018-10-10 20:40:39 +02:00
|
|
|
pub fn to_json(&self, conn: &DbConn) -> Value {
|
2018-12-30 23:34:31 +01:00
|
|
|
use super::{TwoFactor, UserOrganization};
|
2018-04-24 22:01:55 +02:00
|
|
|
|
2018-12-19 22:51:08 +01:00
|
|
|
let orgs = UserOrganization::find_by_user(&self.uuid, conn);
|
2018-10-10 20:40:39 +02:00
|
|
|
let orgs_json: Vec<Value> = orgs.iter().map(|c| c.to_json(&conn)).collect();
|
2018-09-13 21:55:23 +02:00
|
|
|
let twofactor_enabled = !TwoFactor::find_by_user(&self.uuid, conn).is_empty();
|
2018-07-12 21:46:50 +02:00
|
|
|
|
2018-02-10 01:00:55 +01:00
|
|
|
json!({
|
2019-01-26 19:28:54 +01:00
|
|
|
"_Enabled": !self.password_hash.is_empty(),
|
2018-02-10 01:00:55 +01:00
|
|
|
"Id": self.uuid,
|
|
|
|
"Name": self.name,
|
|
|
|
"Email": self.email,
|
|
|
|
"EmailVerified": true,
|
|
|
|
"Premium": true,
|
|
|
|
"MasterPasswordHint": self.password_hint,
|
|
|
|
"Culture": "en-US",
|
2018-07-12 21:46:50 +02:00
|
|
|
"TwoFactorEnabled": twofactor_enabled,
|
2018-02-10 01:00:55 +01:00
|
|
|
"Key": self.key,
|
|
|
|
"PrivateKey": self.private_key,
|
|
|
|
"SecurityStamp": self.security_stamp,
|
2018-04-24 22:01:55 +02:00
|
|
|
"Organizations": orgs_json,
|
2018-02-10 01:00:55 +01:00
|
|
|
"Object": "profile"
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2018-12-19 21:52:53 +01:00
|
|
|
pub fn save(&mut self, conn: &DbConn) -> EmptyResult {
|
2019-01-22 17:26:17 +01:00
|
|
|
if self.email.trim().is_empty() {
|
|
|
|
err!("User email can't be empty")
|
|
|
|
}
|
|
|
|
|
2018-02-15 01:07:57 +01:00
|
|
|
self.updated_at = Utc::now().naive_utc();
|
2018-02-10 01:00:55 +01:00
|
|
|
|
2018-10-14 19:32:43 +02:00
|
|
|
diesel::replace_into(users::table) // Insert or update
|
2018-12-30 23:34:31 +01:00
|
|
|
.values(&*self)
|
|
|
|
.execute(&**conn)
|
|
|
|
.map_res("Error saving user")
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
|
|
|
|
2018-12-19 21:52:53 +01:00
|
|
|
pub fn delete(self, conn: &DbConn) -> EmptyResult {
|
2018-10-12 16:20:10 +02:00
|
|
|
for user_org in UserOrganization::find_by_user(&self.uuid, &*conn) {
|
2018-11-12 18:13:25 +01:00
|
|
|
if user_org.type_ == UserOrgType::Owner {
|
2018-12-30 23:34:31 +01:00
|
|
|
let owner_type = UserOrgType::Owner as i32;
|
|
|
|
if UserOrganization::find_by_org_and_type(&user_org.org_uuid, owner_type, &conn).len() <= 1 {
|
2018-12-19 21:52:53 +01:00
|
|
|
err!("Can't delete last owner")
|
2018-10-12 16:20:10 +02:00
|
|
|
}
|
|
|
|
}
|
2018-02-15 19:05:57 +01:00
|
|
|
}
|
2018-10-12 16:20:10 +02:00
|
|
|
|
|
|
|
UserOrganization::delete_all_by_user(&self.uuid, &*conn)?;
|
|
|
|
Cipher::delete_all_by_user(&self.uuid, &*conn)?;
|
|
|
|
Folder::delete_all_by_user(&self.uuid, &*conn)?;
|
|
|
|
Device::delete_all_by_user(&self.uuid, &*conn)?;
|
2018-12-19 22:51:08 +01:00
|
|
|
TwoFactor::delete_all_by_user(&self.uuid, &*conn)?;
|
2018-10-12 16:20:10 +02:00
|
|
|
Invitation::take(&self.email, &*conn); // Delete invitation if any
|
|
|
|
|
2018-12-30 23:34:31 +01:00
|
|
|
diesel::delete(users::table.filter(users::uuid.eq(self.uuid)))
|
|
|
|
.execute(&**conn)
|
|
|
|
.map_res("Error deleting user")
|
2018-02-15 19:05:57 +01:00
|
|
|
}
|
|
|
|
|
2019-01-28 00:39:14 +01:00
|
|
|
pub fn update_uuid_revision(uuid: &str, conn: &DbConn) -> Vec<String> {
|
2018-08-21 13:20:55 +02:00
|
|
|
if let Some(mut user) = User::find_by_uuid(&uuid, conn) {
|
2018-12-30 23:34:31 +01:00
|
|
|
if user.update_revision(conn).is_err() {
|
2018-12-06 20:35:25 +01:00
|
|
|
warn!("Failed to update revision for {}", user.email);
|
2018-08-21 13:20:55 +02:00
|
|
|
};
|
|
|
|
};
|
2019-01-28 00:39:14 +01:00
|
|
|
|
|
|
|
vec![uuid.to_string()]
|
2018-08-21 13:20:55 +02:00
|
|
|
}
|
|
|
|
|
2018-12-19 21:52:53 +01:00
|
|
|
pub fn update_revision(&mut self, conn: &DbConn) -> EmptyResult {
|
2018-08-21 11:36:04 +02:00
|
|
|
self.updated_at = Utc::now().naive_utc();
|
2018-12-30 23:34:31 +01:00
|
|
|
diesel::update(users::table.filter(users::uuid.eq(&self.uuid)))
|
|
|
|
.set(users::updated_at.eq(&self.updated_at))
|
|
|
|
.execute(&**conn)
|
|
|
|
.map_res("Error updating user revision")
|
2018-08-13 11:58:39 +02:00
|
|
|
}
|
|
|
|
|
2018-02-15 00:40:34 +01:00
|
|
|
pub fn find_by_mail(mail: &str, conn: &DbConn) -> Option<Self> {
|
2018-02-10 01:00:55 +01:00
|
|
|
let lower_mail = mail.to_lowercase();
|
|
|
|
users::table
|
|
|
|
.filter(users::email.eq(lower_mail))
|
2018-12-30 23:34:31 +01:00
|
|
|
.first::<Self>(&**conn)
|
|
|
|
.ok()
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
|
|
|
|
2018-02-15 00:40:34 +01:00
|
|
|
pub fn find_by_uuid(uuid: &str, conn: &DbConn) -> Option<Self> {
|
2018-12-30 23:34:31 +01:00
|
|
|
users::table.filter(users::uuid.eq(uuid)).first::<Self>(&**conn).ok()
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
2018-10-12 16:20:10 +02:00
|
|
|
|
|
|
|
pub fn get_all(conn: &DbConn) -> Vec<Self> {
|
2018-12-30 23:34:31 +01:00
|
|
|
users::table.load::<Self>(&**conn).expect("Error loading users")
|
2018-10-12 16:20:10 +02:00
|
|
|
}
|
2018-02-10 01:00:55 +01:00
|
|
|
}
|
2018-09-10 15:51:40 +02:00
|
|
|
|
|
|
|
#[derive(Debug, Identifiable, Queryable, Insertable)]
|
|
|
|
#[table_name = "invitations"]
|
|
|
|
#[primary_key(email)]
|
|
|
|
pub struct Invitation {
|
|
|
|
pub email: String,
|
|
|
|
}
|
|
|
|
|
|
|
|
impl Invitation {
|
|
|
|
pub fn new(email: String) -> Self {
|
2018-12-30 23:34:31 +01:00
|
|
|
Self { email }
|
2018-09-10 15:51:40 +02:00
|
|
|
}
|
|
|
|
|
2018-12-19 21:52:53 +01:00
|
|
|
pub fn save(&mut self, conn: &DbConn) -> EmptyResult {
|
2019-01-22 17:26:17 +01:00
|
|
|
if self.email.trim().is_empty() {
|
|
|
|
err!("Invitation email can't be empty")
|
|
|
|
}
|
|
|
|
|
2018-09-10 15:51:40 +02:00
|
|
|
diesel::replace_into(invitations::table)
|
2018-12-30 23:34:31 +01:00
|
|
|
.values(&*self)
|
|
|
|
.execute(&**conn)
|
|
|
|
.map_res("Error saving invitation")
|
2018-09-10 15:51:40 +02:00
|
|
|
}
|
|
|
|
|
2018-12-19 21:52:53 +01:00
|
|
|
pub fn delete(self, conn: &DbConn) -> EmptyResult {
|
2018-12-30 23:34:31 +01:00
|
|
|
diesel::delete(invitations::table.filter(invitations::email.eq(self.email)))
|
|
|
|
.execute(&**conn)
|
|
|
|
.map_res("Error deleting invitation")
|
2018-09-10 15:51:40 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
pub fn find_by_mail(mail: &str, conn: &DbConn) -> Option<Self> {
|
|
|
|
let lower_mail = mail.to_lowercase();
|
|
|
|
invitations::table
|
|
|
|
.filter(invitations::email.eq(lower_mail))
|
2018-12-30 23:34:31 +01:00
|
|
|
.first::<Self>(&**conn)
|
|
|
|
.ok()
|
2018-09-10 15:51:40 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
pub fn take(mail: &str, conn: &DbConn) -> bool {
|
2019-01-25 18:23:51 +01:00
|
|
|
CONFIG.invitations_allowed()
|
2018-12-30 23:34:31 +01:00
|
|
|
&& match Self::find_by_mail(mail, &conn) {
|
|
|
|
Some(invitation) => invitation.delete(&conn).is_ok(),
|
|
|
|
None => false,
|
|
|
|
}
|
2018-09-10 15:51:40 +02:00
|
|
|
}
|
2018-12-30 23:34:31 +01:00
|
|
|
}
|