pw_reset.go 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299
  1. package user
  2. import (
  3. "fmt"
  4. "net/http"
  5. "net/url"
  6. "time"
  7. "github.com/porter-dev/porter/api/server/handlers"
  8. "github.com/porter-dev/porter/api/server/shared"
  9. "github.com/porter-dev/porter/api/server/shared/apierrors"
  10. "github.com/porter-dev/porter/api/types"
  11. "github.com/porter-dev/porter/internal/models"
  12. "github.com/porter-dev/porter/internal/notifier"
  13. "github.com/porter-dev/porter/internal/random"
  14. "github.com/porter-dev/porter/internal/repository"
  15. "golang.org/x/crypto/bcrypt"
  16. "gorm.io/gorm"
  17. )
  18. type UserPasswordInitiateResetHandler struct {
  19. handlers.PorterHandlerReader
  20. }
  21. func NewUserPasswordInitiateResetHandler(
  22. config *shared.Config,
  23. decoderValidator shared.RequestDecoderValidator,
  24. writer shared.ResultWriter,
  25. ) *UserPasswordInitiateResetHandler {
  26. return &UserPasswordInitiateResetHandler{
  27. PorterHandlerReader: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  28. }
  29. }
  30. func (c *UserPasswordInitiateResetHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  31. request := &types.InitiateResetUserPasswordRequest{}
  32. ok := c.DecodeAndValidate(w, r, request)
  33. if !ok {
  34. return
  35. }
  36. // check that the email exists; return 200 status code even if it doesn't
  37. user, err := c.Repo().User().ReadUserByEmail(request.Email)
  38. if err == gorm.ErrRecordNotFound {
  39. w.WriteHeader(http.StatusOK)
  40. return
  41. } else if err != nil {
  42. c.HandleAPIError(w, apierrors.NewErrInternal(err))
  43. return
  44. }
  45. // if the user is a Github user, send them a Github email
  46. if user.GithubUserID != 0 {
  47. err := c.Config().UserNotifier.SendGithubRelinkEmail(
  48. &notifier.SendGithubRelinkEmailOpts{
  49. Email: user.Email,
  50. URL: fmt.Sprintf("%s/api/oauth/login/github", c.Config().ServerConf.ServerURL),
  51. },
  52. )
  53. if err != nil {
  54. c.HandleAPIError(w, apierrors.NewErrInternal(err))
  55. return
  56. }
  57. w.WriteHeader(http.StatusOK)
  58. return
  59. }
  60. pwReset, rawToken, err := CreatePWResetTokenForEmail(c.Repo().PWResetToken(), c.HandleAPIError, w, request)
  61. if err != nil {
  62. return
  63. }
  64. queryVals := url.Values{
  65. "token": []string{rawToken},
  66. "email": []string{request.Email},
  67. "token_id": []string{fmt.Sprintf("%d", pwReset.ID)},
  68. }
  69. err = c.Config().UserNotifier.SendPasswordResetEmail(
  70. &notifier.SendPasswordResetEmailOpts{
  71. Email: user.Email,
  72. URL: fmt.Sprintf("%s/password/reset/finalize?%s", c.Config().ServerConf.ServerURL, queryVals.Encode()),
  73. },
  74. )
  75. if err != nil {
  76. c.HandleAPIError(w, apierrors.NewErrInternal(err))
  77. return
  78. }
  79. w.WriteHeader(http.StatusOK)
  80. return
  81. }
  82. type UserPasswordVerifyResetHandler struct {
  83. handlers.PorterHandlerReader
  84. }
  85. func NewUserPasswordVerifyResetHandler(
  86. config *shared.Config,
  87. decoderValidator shared.RequestDecoderValidator,
  88. writer shared.ResultWriter,
  89. ) *UserPasswordVerifyResetHandler {
  90. return &UserPasswordVerifyResetHandler{
  91. PorterHandlerReader: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  92. }
  93. }
  94. func (c *UserPasswordVerifyResetHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  95. request := &types.VerifyResetUserPasswordRequest{}
  96. ok := c.DecodeAndValidate(w, r, request)
  97. if !ok {
  98. return
  99. }
  100. VerifyToken(
  101. c.Repo().PWResetToken(),
  102. c.HandleAPIError,
  103. w,
  104. &request.VerifyTokenFinalizeRequest,
  105. request.Email,
  106. )
  107. }
  108. type UserPasswordFinalizeResetHandler struct {
  109. handlers.PorterHandlerReader
  110. }
  111. func NewUserPasswordFinalizeResetHandler(
  112. config *shared.Config,
  113. decoderValidator shared.RequestDecoderValidator,
  114. writer shared.ResultWriter,
  115. ) *UserPasswordFinalizeResetHandler {
  116. return &UserPasswordFinalizeResetHandler{
  117. PorterHandlerReader: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  118. }
  119. }
  120. func (c *UserPasswordFinalizeResetHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  121. request := &types.FinalizeResetUserPasswordRequest{}
  122. ok := c.DecodeAndValidate(w, r, request)
  123. if !ok {
  124. return
  125. }
  126. token, err := VerifyToken(
  127. c.Repo().PWResetToken(),
  128. c.HandleAPIError,
  129. w,
  130. &request.VerifyTokenFinalizeRequest,
  131. request.Email,
  132. )
  133. if err != nil {
  134. return
  135. }
  136. // check that the email exists
  137. user, err := c.Repo().User().ReadUserByEmail(request.Email)
  138. if err != nil {
  139. if err == gorm.ErrRecordNotFound {
  140. err = fmt.Errorf("finalize password reset failed: email does not exist")
  141. c.HandleAPIError(w, apierrors.NewErrForbidden(err))
  142. } else {
  143. c.HandleAPIError(w, apierrors.NewErrInternal(err))
  144. }
  145. return
  146. }
  147. hashedPW, err := bcrypt.GenerateFromPassword([]byte(request.NewPassword), 8)
  148. if err != nil {
  149. c.HandleAPIError(w, apierrors.NewErrInternal(err))
  150. return
  151. }
  152. user.Password = string(hashedPW)
  153. user, err = c.Repo().User().UpdateUser(user)
  154. if err != nil {
  155. c.HandleAPIError(w, apierrors.NewErrInternal(err))
  156. return
  157. }
  158. // invalidate the token
  159. token.IsValid = false
  160. _, err = c.Repo().PWResetToken().UpdatePWResetToken(token)
  161. if err != nil {
  162. c.HandleAPIError(w, apierrors.NewErrInternal(err))
  163. return
  164. }
  165. w.WriteHeader(http.StatusOK)
  166. return
  167. }
  168. func VerifyToken(
  169. pwResetRepo repository.PWResetTokenRepository,
  170. handleErr func(w http.ResponseWriter, apiErr apierrors.RequestError),
  171. w http.ResponseWriter,
  172. request *types.VerifyTokenFinalizeRequest,
  173. email string,
  174. ) (*models.PWResetToken, error) {
  175. token, err := pwResetRepo.ReadPWResetToken(request.TokenID)
  176. if err != nil {
  177. if err == gorm.ErrRecordNotFound {
  178. err = fmt.Errorf("verify token failed: token does not exist")
  179. handleErr(w, apierrors.NewErrForbidden(err))
  180. return nil, err
  181. } else {
  182. handleErr(w, apierrors.NewErrInternal(err))
  183. }
  184. return nil, err
  185. }
  186. // make sure the token is still valid and has not expired
  187. if !token.IsValid || token.IsExpired() {
  188. err = fmt.Errorf("verify token failed: expired %t, valid %t", token.IsExpired(), token.IsValid)
  189. handleErr(w, apierrors.NewErrForbidden(err))
  190. return nil, err
  191. }
  192. // check that the email matches
  193. if token.Email != email {
  194. err = fmt.Errorf("verify token failed: token email does not match request email")
  195. handleErr(w, apierrors.NewErrForbidden(err))
  196. return nil, err
  197. }
  198. // make sure the token is correct
  199. if err := bcrypt.CompareHashAndPassword([]byte(token.Token), []byte(request.Token)); err != nil {
  200. err = fmt.Errorf("verify token failed: %s", err)
  201. handleErr(w, apierrors.NewErrForbidden(err))
  202. return nil, err
  203. }
  204. return token, nil
  205. }
  206. func CreatePWResetTokenForEmail(
  207. pwResetRepo repository.PWResetTokenRepository,
  208. handleErr func(w http.ResponseWriter, apiErr apierrors.RequestError),
  209. w http.ResponseWriter,
  210. request *types.InitiateResetUserPasswordRequest,
  211. ) (*models.PWResetToken, string, error) {
  212. // convert the form to a project model
  213. expiry := time.Now().Add(30 * time.Minute)
  214. rawToken, err := random.StringWithCharset(32, "")
  215. if err != nil {
  216. handleErr(w, apierrors.NewErrInternal(err))
  217. return nil, "", err
  218. }
  219. hashedToken, err := bcrypt.GenerateFromPassword([]byte(rawToken), 8)
  220. if err != nil {
  221. handleErr(w, apierrors.NewErrInternal(err))
  222. return nil, "", err
  223. }
  224. pwReset := &models.PWResetToken{
  225. Email: request.Email,
  226. IsValid: true,
  227. Expiry: &expiry,
  228. Token: string(hashedToken),
  229. }
  230. // handle write to the database
  231. pwReset, err = pwResetRepo.CreatePWResetToken(pwReset)
  232. if err != nil {
  233. handleErr(w, apierrors.NewErrInternal(err))
  234. return nil, "", err
  235. }
  236. return pwReset, rawToken, nil
  237. }