2018-10-10 20:40:39 +02:00
|
|
|
use serde_json::Value;
|
2018-07-12 21:46:50 +02:00
|
|
|
|
2019-08-03 18:47:52 +02:00
|
|
|
use crate::api::EmptyResult;
|
2019-08-04 16:55:43 +02:00
|
|
|
use crate::db::DbConn;
|
2019-08-03 18:47:52 +02:00
|
|
|
use crate::error::MapResult;
|
|
|
|
|
2018-07-12 21:46:50 +02:00
|
|
|
use super::User;
|
|
|
|
|
2020-08-18 17:15:44 +02:00
|
|
|
db_object! {
|
|
|
|
#[derive(Debug, Identifiable, Queryable, Insertable, Associations, AsChangeset)]
|
|
|
|
#[table_name = "twofactor"]
|
|
|
|
#[belongs_to(User, foreign_key = "user_uuid")]
|
|
|
|
#[primary_key(uuid)]
|
|
|
|
pub struct TwoFactor {
|
|
|
|
pub uuid: String,
|
|
|
|
pub user_uuid: String,
|
|
|
|
pub atype: i32,
|
|
|
|
pub enabled: bool,
|
|
|
|
pub data: String,
|
|
|
|
pub last_used: i32,
|
|
|
|
}
|
2018-07-12 21:46:50 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
#[allow(dead_code)]
|
2020-05-03 17:24:51 +02:00
|
|
|
#[derive(num_derive::FromPrimitive)]
|
2018-07-12 21:46:50 +02:00
|
|
|
pub enum TwoFactorType {
|
|
|
|
Authenticator = 0,
|
|
|
|
Email = 1,
|
|
|
|
Duo = 2,
|
|
|
|
YubiKey = 3,
|
|
|
|
U2f = 4,
|
|
|
|
Remember = 5,
|
|
|
|
OrganizationDuo = 6,
|
|
|
|
|
|
|
|
// These are implementation details
|
|
|
|
U2fRegisterChallenge = 1000,
|
|
|
|
U2fLoginChallenge = 1001,
|
2019-08-03 18:47:52 +02:00
|
|
|
EmailVerificationChallenge = 1002,
|
2018-07-12 21:46:50 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
/// Local methods
|
|
|
|
impl TwoFactor {
|
2019-05-20 21:12:41 +02:00
|
|
|
pub fn new(user_uuid: String, atype: TwoFactorType, data: String) -> Self {
|
2018-07-12 21:46:50 +02:00
|
|
|
Self {
|
2018-12-07 14:32:40 +01:00
|
|
|
uuid: crate::util::get_uuid(),
|
2018-07-12 21:46:50 +02:00
|
|
|
user_uuid,
|
2019-05-20 21:12:41 +02:00
|
|
|
atype: atype as i32,
|
2018-07-12 21:46:50 +02:00
|
|
|
enabled: true,
|
|
|
|
data,
|
2019-10-10 17:32:20 +02:00
|
|
|
last_used: 0,
|
2018-07-12 21:46:50 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-10-10 20:40:39 +02:00
|
|
|
pub fn to_json(&self) -> Value {
|
2018-07-12 21:46:50 +02:00
|
|
|
json!({
|
|
|
|
"Enabled": self.enabled,
|
|
|
|
"Key": "", // This key and value vary
|
|
|
|
"Object": "twoFactorAuthenticator" // This value varies
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2020-05-08 19:36:35 +02:00
|
|
|
pub fn to_json_provider(&self) -> Value {
|
2018-07-12 21:46:50 +02:00
|
|
|
json!({
|
|
|
|
"Enabled": self.enabled,
|
2019-05-20 21:12:41 +02:00
|
|
|
"Type": self.atype,
|
2018-07-12 21:46:50 +02:00
|
|
|
"Object": "twoFactorProvider"
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/// Database methods
|
|
|
|
impl TwoFactor {
|
2019-09-12 22:12:22 +02:00
|
|
|
pub fn save(&self, conn: &DbConn) -> EmptyResult {
|
2020-08-18 17:15:44 +02:00
|
|
|
db_run! { conn:
|
|
|
|
sqlite, mysql {
|
|
|
|
diesel::replace_into(twofactor::table)
|
|
|
|
.values(TwoFactorDb::to_db(self))
|
|
|
|
.execute(conn)
|
|
|
|
.map_res("Error saving twofactor")
|
|
|
|
}
|
|
|
|
postgresql {
|
|
|
|
let value = TwoFactorDb::to_db(self);
|
|
|
|
// We need to make sure we're not going to violate the unique constraint on user_uuid and atype.
|
|
|
|
// This happens automatically on other DBMS backends due to replace_into(). PostgreSQL does
|
|
|
|
// not support multiple constraints on ON CONFLICT clauses.
|
|
|
|
diesel::delete(twofactor::table.filter(twofactor::user_uuid.eq(&self.user_uuid)).filter(twofactor::atype.eq(&self.atype)))
|
|
|
|
.execute(conn)
|
|
|
|
.map_res("Error deleting twofactor for insert")?;
|
2019-09-12 22:12:22 +02:00
|
|
|
|
2020-08-18 17:15:44 +02:00
|
|
|
diesel::insert_into(twofactor::table)
|
|
|
|
.values(&value)
|
|
|
|
.on_conflict(twofactor::uuid)
|
|
|
|
.do_update()
|
|
|
|
.set(&value)
|
|
|
|
.execute(conn)
|
|
|
|
.map_res("Error saving twofactor")
|
|
|
|
}
|
|
|
|
}
|
2018-07-12 21:46:50 +02:00
|
|
|
}
|
|
|
|
|
2018-12-19 21:52:53 +01:00
|
|
|
pub fn delete(self, conn: &DbConn) -> EmptyResult {
|
2020-08-18 17:15:44 +02:00
|
|
|
db_run! { conn: {
|
|
|
|
diesel::delete(twofactor::table.filter(twofactor::uuid.eq(self.uuid)))
|
|
|
|
.execute(conn)
|
|
|
|
.map_res("Error deleting twofactor")
|
|
|
|
}}
|
2018-07-12 21:46:50 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
pub fn find_by_user(user_uuid: &str, conn: &DbConn) -> Vec<Self> {
|
2020-08-18 17:15:44 +02:00
|
|
|
db_run! { conn: {
|
|
|
|
twofactor::table
|
|
|
|
.filter(twofactor::user_uuid.eq(user_uuid))
|
|
|
|
.filter(twofactor::atype.lt(1000)) // Filter implementation types
|
|
|
|
.load::<TwoFactorDb>(conn)
|
|
|
|
.expect("Error loading twofactor")
|
|
|
|
.from_db()
|
|
|
|
}}
|
2018-07-12 21:46:50 +02:00
|
|
|
}
|
|
|
|
|
2019-05-20 21:12:41 +02:00
|
|
|
pub fn find_by_user_and_type(user_uuid: &str, atype: i32, conn: &DbConn) -> Option<Self> {
|
2020-08-18 17:15:44 +02:00
|
|
|
db_run! { conn: {
|
|
|
|
twofactor::table
|
|
|
|
.filter(twofactor::user_uuid.eq(user_uuid))
|
|
|
|
.filter(twofactor::atype.eq(atype))
|
|
|
|
.first::<TwoFactorDb>(conn)
|
|
|
|
.ok()
|
|
|
|
.from_db()
|
|
|
|
}}
|
2018-07-12 21:46:50 +02:00
|
|
|
}
|
2018-12-30 23:34:31 +01:00
|
|
|
|
2018-12-19 21:52:53 +01:00
|
|
|
pub fn delete_all_by_user(user_uuid: &str, conn: &DbConn) -> EmptyResult {
|
2020-08-18 17:15:44 +02:00
|
|
|
db_run! { conn: {
|
|
|
|
diesel::delete(twofactor::table.filter(twofactor::user_uuid.eq(user_uuid)))
|
|
|
|
.execute(conn)
|
|
|
|
.map_res("Error deleting twofactors")
|
|
|
|
}}
|
2018-12-18 18:52:58 +01:00
|
|
|
}
|
|
|
|
}
|