mirror of
https://github.com/ProjectSWGCore/Holocore.git
synced 2026-09-28 13:12:59 -04:00
Added in database authentication to access web interface
This commit is contained in:
@@ -6,10 +6,16 @@ import java.io.IOException;
|
||||
import java.net.InetAddress;
|
||||
import java.net.URL;
|
||||
import java.net.UnknownHostException;
|
||||
import java.sql.PreparedStatement;
|
||||
import java.sql.ResultSet;
|
||||
import java.sql.SQLException;
|
||||
import java.util.HashMap;
|
||||
import java.util.Map;
|
||||
import java.util.concurrent.Executors;
|
||||
import java.util.concurrent.ScheduledExecutorService;
|
||||
import java.util.concurrent.TimeUnit;
|
||||
|
||||
import network.encryption.MD5;
|
||||
import resources.config.ConfigFile;
|
||||
import resources.control.Intent;
|
||||
import resources.control.Service;
|
||||
@@ -19,17 +25,19 @@ import services.admin.http.HttpServer;
|
||||
import services.admin.http.HttpServer.HttpServerCallback;
|
||||
import services.admin.http.HttpSocket;
|
||||
import services.admin.http.HttpSocket.HttpRequest;
|
||||
import services.admin.http.HttpStatusCode;
|
||||
import services.admin.http.HttpSession;
|
||||
import services.admin.http.HttpsServer;
|
||||
import utilities.ThreadUtilities;
|
||||
|
||||
public class OnlineInterfaceService extends Service implements HttpServerCallback {
|
||||
|
||||
private static final String TAG = "OnlineInterfaceService";
|
||||
private static final String GET_USER_SQL = "SELECT password, password_salt, banned FROM users WHERE username = ? AND password = ?";
|
||||
|
||||
private final WebserverData data;
|
||||
private final WebserverHandler handler;
|
||||
private final Runnable dataCollectionRunnable;
|
||||
private final PreparedStatement getUser;
|
||||
private ScheduledExecutorService executor;
|
||||
private HttpsServer httpsServer;
|
||||
private HttpServer httpServer;
|
||||
@@ -39,6 +47,7 @@ public class OnlineInterfaceService extends Service implements HttpServerCallbac
|
||||
data = new WebserverData();
|
||||
handler = new WebserverHandler(data);
|
||||
dataCollectionRunnable = () -> collectData();
|
||||
getUser = getLocalDatabase().prepareStatement(GET_USER_SQL);
|
||||
authorized = false;
|
||||
}
|
||||
|
||||
@@ -99,9 +108,18 @@ public class OnlineInterfaceService extends Service implements HttpServerCallbac
|
||||
@Override
|
||||
public void onRequestReceived(HttpSocket socket, HttpRequest request) {
|
||||
try {
|
||||
if (!request.getType().equals("GET")) {
|
||||
socket.send(HttpStatusCode.METHOD_NOT_ALLOWED);
|
||||
return;
|
||||
if (request.getType().equals("POST")) {
|
||||
String [] variables = request.getBody().split("&");
|
||||
if (variables.length == 2) {
|
||||
Map<String, String> varMap = new HashMap<>();
|
||||
for (String str : variables) {
|
||||
String [] var = str.split("=");
|
||||
if (var.length == 2)
|
||||
varMap.put(var[0], var[1]);
|
||||
}
|
||||
if (varMap.containsKey("username") && varMap.containsKey("password"))
|
||||
login(socket, varMap.get("username"), varMap.get("password"));
|
||||
}
|
||||
}
|
||||
if (!socket.isSecure()) {
|
||||
socket.redirect(new URL("https", httpsServer.getBindAddress().getHostName(), httpsServer.getBindPort(), request.getURI().getPath()).toString());
|
||||
@@ -148,4 +166,43 @@ public class OnlineInterfaceService extends Service implements HttpServerCallbac
|
||||
return null;
|
||||
}
|
||||
|
||||
private void login(HttpSocket socket, String username, String password) {
|
||||
HttpSession session = socket.getSession();
|
||||
if (session == null)
|
||||
return;
|
||||
synchronized (getUser) {
|
||||
try {
|
||||
getUser.setString(1, username);
|
||||
getUser.setString(2, password);
|
||||
session.setAuthenticated(false);
|
||||
try (ResultSet cursor = getUser.executeQuery()) {
|
||||
session.setAuthenticated(cursor.next() && isUserValid(cursor, password));
|
||||
if (session.isAuthenticated()) {
|
||||
Log.i(TAG, "[%s] Successfully logged in to online interface", username);
|
||||
} else {
|
||||
Log.w(TAG, "[%s] Failed to login to online interface. Incorrect user/pass", username);
|
||||
socket.redirect(new URL("https", httpsServer.getBindAddress().getHostName(), httpsServer.getBindPort(), "/").toString());
|
||||
}
|
||||
} catch (IOException e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
} catch (SQLException e) {
|
||||
e.printStackTrace();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private boolean isUserValid(ResultSet set, String password) throws SQLException {
|
||||
if (password.isEmpty())
|
||||
return false;
|
||||
if (set.getBoolean("banned"))
|
||||
return false;
|
||||
String psqlPass = set.getString("password");
|
||||
String psqlSalt = set.getString("password_salt");
|
||||
if (psqlPass.length() != 32 && psqlSalt.length() == 0)
|
||||
return psqlPass.equals(password);
|
||||
password = MD5.digest(MD5.digest(psqlSalt) + MD5.digest(password));
|
||||
return psqlPass.equals(password);
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user