Added in database authentication to access web interface

This commit is contained in:
Obique PSWG
2015-08-28 03:32:59 -05:00
parent 3e71418bf8
commit 2a59b799bf
6 changed files with 224 additions and 76 deletions
+61 -4
View File
@@ -6,10 +6,16 @@ import java.io.IOException;
import java.net.InetAddress;
import java.net.URL;
import java.net.UnknownHostException;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import java.sql.SQLException;
import java.util.HashMap;
import java.util.Map;
import java.util.concurrent.Executors;
import java.util.concurrent.ScheduledExecutorService;
import java.util.concurrent.TimeUnit;
import network.encryption.MD5;
import resources.config.ConfigFile;
import resources.control.Intent;
import resources.control.Service;
@@ -19,17 +25,19 @@ import services.admin.http.HttpServer;
import services.admin.http.HttpServer.HttpServerCallback;
import services.admin.http.HttpSocket;
import services.admin.http.HttpSocket.HttpRequest;
import services.admin.http.HttpStatusCode;
import services.admin.http.HttpSession;
import services.admin.http.HttpsServer;
import utilities.ThreadUtilities;
public class OnlineInterfaceService extends Service implements HttpServerCallback {
private static final String TAG = "OnlineInterfaceService";
private static final String GET_USER_SQL = "SELECT password, password_salt, banned FROM users WHERE username = ? AND password = ?";
private final WebserverData data;
private final WebserverHandler handler;
private final Runnable dataCollectionRunnable;
private final PreparedStatement getUser;
private ScheduledExecutorService executor;
private HttpsServer httpsServer;
private HttpServer httpServer;
@@ -39,6 +47,7 @@ public class OnlineInterfaceService extends Service implements HttpServerCallbac
data = new WebserverData();
handler = new WebserverHandler(data);
dataCollectionRunnable = () -> collectData();
getUser = getLocalDatabase().prepareStatement(GET_USER_SQL);
authorized = false;
}
@@ -99,9 +108,18 @@ public class OnlineInterfaceService extends Service implements HttpServerCallbac
@Override
public void onRequestReceived(HttpSocket socket, HttpRequest request) {
try {
if (!request.getType().equals("GET")) {
socket.send(HttpStatusCode.METHOD_NOT_ALLOWED);
return;
if (request.getType().equals("POST")) {
String [] variables = request.getBody().split("&");
if (variables.length == 2) {
Map<String, String> varMap = new HashMap<>();
for (String str : variables) {
String [] var = str.split("=");
if (var.length == 2)
varMap.put(var[0], var[1]);
}
if (varMap.containsKey("username") && varMap.containsKey("password"))
login(socket, varMap.get("username"), varMap.get("password"));
}
}
if (!socket.isSecure()) {
socket.redirect(new URL("https", httpsServer.getBindAddress().getHostName(), httpsServer.getBindPort(), request.getURI().getPath()).toString());
@@ -148,4 +166,43 @@ public class OnlineInterfaceService extends Service implements HttpServerCallbac
return null;
}
private void login(HttpSocket socket, String username, String password) {
HttpSession session = socket.getSession();
if (session == null)
return;
synchronized (getUser) {
try {
getUser.setString(1, username);
getUser.setString(2, password);
session.setAuthenticated(false);
try (ResultSet cursor = getUser.executeQuery()) {
session.setAuthenticated(cursor.next() && isUserValid(cursor, password));
if (session.isAuthenticated()) {
Log.i(TAG, "[%s] Successfully logged in to online interface", username);
} else {
Log.w(TAG, "[%s] Failed to login to online interface. Incorrect user/pass", username);
socket.redirect(new URL("https", httpsServer.getBindAddress().getHostName(), httpsServer.getBindPort(), "/").toString());
}
} catch (IOException e) {
e.printStackTrace();
}
} catch (SQLException e) {
e.printStackTrace();
}
}
}
private boolean isUserValid(ResultSet set, String password) throws SQLException {
if (password.isEmpty())
return false;
if (set.getBoolean("banned"))
return false;
String psqlPass = set.getString("password");
String psqlSalt = set.getString("password_salt");
if (psqlPass.length() != 32 && psqlSalt.length() == 0)
return psqlPass.equals(password);
password = MD5.digest(MD5.digest(psqlSalt) + MD5.digest(password));
return psqlPass.equals(password);
}
}