From 9b283b31f437aaf99ae09319cf6d443f091b1e0d Mon Sep 17 00:00:00 2001 From: Garritt McCune Date: Wed, 10 Mar 2021 21:52:52 -0600 Subject: [PATCH] Tweaked the SessionManager's IsSessionTokenValid function to accept a connection string to standardize the interfaces on all the SessionManager functions. --- .vs/SecureCore/v16/.suo | Bin 81408 -> 83456 bytes SecureCore/AppSettingsManager.cs | 2 +- SecureCore/Authentication/PasswordManager.cs | 2 ++ SecureCore/Authentication/SessionManager.cs | 4 +--- SecureCore/Controllers/AuthController.cs | 4 ++-- SecureCore/Controllers/EmployeeController.cs | 8 ++++++-- SecureCore/appsettings.json | 2 +- 7 files changed, 13 insertions(+), 9 deletions(-) diff --git a/.vs/SecureCore/v16/.suo b/.vs/SecureCore/v16/.suo index 455cb8190247cdf140077868448b065d0e27d840..db49d7eb4384388c8a0dee7f2b43a6dbcf078d22 100644 GIT binary patch delta 4637 zcmZqp!_v^hI>A7Zi2(`(7#Lg_7#LU>7#RNj|NkE(%FMvPAigp1HzT9`4Y zg(}u!U|^7EU|p`B1R}1_p+ziGk`O)eH;_wNSx21_p)(P@Mc> z3}BR>tjHwKw_(#iQev?lITk^7g0KWMK0v+$@j)0{yn^Bz7Ox;Ruy_UOgT*UI92Bph z_{9>hP9XXJu!sevPAn12K$Um}CE&puuR7S`6%;t2z-(e zun1rk=X2pmgk~yOUY%UR7r+6^m7p{X6WsiTkB@OOlTi_?86yM3?a7r!{w$z~fXPq( zVidpuasfXmg+X&Yqt4_~V?Ry?Sq26MP{M~PX47V5U|?dH{7di`W9#IvLiLPwlS_sD zI2l3d#tg{-)@nuu2A0V`#l1NU85qDZ3p0bUd~>P9ddAHvVs{uPr5v8@ED}3eLG-~S zNrA}%d?v(tO2B||vx>|e#zhKDlO6m`c|!8@bBgssG7F0JR!nX*NuSIm@1*D*(f2LR zJm}jKkHbx3bG#NDwJ|tRHm$sLqm}4M5uWA23=;!|Cx1{8ne3;;Cs?7Y7UKS4vfIiT ziVsu-t^To0zsSj`FHjo&z~3u7`rpl_$=gi=e%zWaz{OZF{SqIe8pw*x8A>yl2f_hL z(u^L{3ltfJHb-eJW1bWs!pJ`{P@7{Cw8)t35n#YMpMim40RscW!p(&`^^A-3m_W*e z2q>FmRl-<1xzwtjv1amDt9r(=$)(npC-=wdOfIo$U}T*9)ux__fpKz~Z557Qzurb!W)vC+LKh;5RH z2MefThk12#iAWFQq7Q31=Qh7XJaf1wpU$WtIZ$*6?nLdKs1RBeD_2WA^9 zxQyBSvz?u3Q548GEFj;2QsCy2svg!wO(2J0wSQ3$)1nHdO_Q9NCOh*Pva&HUFx;5@ zQ&gAHWU?ZY7p3bm*9ww79|K$w4 zJ^8>^naRCJT{mAj9LPBN*0QCH>!8Bg?8T|Y#hLkelN-((O}=z=*5m^p`4~|&v9K|? zU{x+67!1+to0ylFo?4`rT+FCFy^(`aYBEo*AQKXM^31Q!lLOZBu!GuHoD2+`&mXs8 zWCbM_&dG^u=TE+{jBE0l|6-FLY*3i|{$#oss3ZUtL<|gi2S6gJz3!Nhspg%ohL6}TmMj zb8V9wHXoQAuv~xg+AW(DK+R2v3bg~ERwKwwpjHPcKZ3+3=bf|WVAKds1#=FrQ36@O z^5EV7|C0?*sfyQtguz(vz%*z>)nz^7qB$&+8}^D!Zak$k`M_R7{>=Qmn1aOO;`02W zl-$I;#SOcdHXUeST(p2`ve8+m$+?$JHk;k+VqA2H5fQy6NrtA0CT5npmT4v_x+Z3c z2D%o8#wogKW@ctd29~B476z%qEqcW#H=J$Q?C_+4akAsG0BrF*X~O|nG%wo7xcIoetcT7(bW7L{_{uUo2!{qyC^!enR8S)v57*ZKR z7*ZLEH{0Ji$T+#-%{CEJ1``G&1~UdDhTHs*&JY{JUfWR74bO5jMH; z;l{~3f1Co9g_CgqS||7*jDS)xt%Wn|nuSzwvu%+k5@n3qzRHqu8RPN*c}Aw~0oIHgn6}w41|STY!nDnb SF@$+?SZm(ogw_-!oCE;dKs{*y delta 5109 zcmZqZVQu)sGQnW7!F)~$0R{$Z1_lNe1_p+I|NsAIU|?WiWME*B-Wd3sk&$__B9lCy zL(%HvN@CX;y%-o68WJW~F;y`(PX5YN&&W8rl-Zv{o`HeEjDdk+vV5%KWCJF4-ZlmX zh7d`RNem1!lNnjW>n#}=82H~>uFfi1EEeCP57#J8p?iGeAU}Iol5My9qV1@GCptJ!41A`_51A{381A{pO1A{XI z1A_$v1A{ID1A`G%jXjhGnG3>tP(COaL3|D3fgzcJfgy!~fguelZp^^Ipaf-SF)%P>GcYieK=~j`3X#}F3=9m# z3=9mV3=9l;3=9lqAP<%^FfddwFfddyFfi00DXvFiH!(0UOk(nZriB8RhsQ`r3-!op z0puhQmVw3|ETBMQpcH~Db%4|%rw)*MSn2?!0&J-Rq(%Z1^PrRo;^0XhI8z5ZG?j5kx6_mlU+m&CYSI9 zaDe=7h*UUi{=&z{IGKsh36BaX1IEcJLKhetCVv&GXRMuED(uGzE;c}k09MLyS203L zEs){=!#yXTkcim4AR>Wrkr>k?5f=_nQ2{C@VCosmHkXR5XWXn}cZYG243l7mu3Cuu zhska$XDB{U5w!ZpGC6UPzCda81AnjV=zlkxCT}+h_;G8SH6sh-bQT51HH+k!reES? zRGaQ4&FHi_Lum#x$wo}SB+ckCT|tFWXmgatGG<#)*nn^|0|P?~0|NseG}pB=Ffep5 zFfep7Ffep6Ffep8FfjBmFfjBoFfjBnFfjBpFfh!T7^uxT2dZK2=0+V*BnT|hV_M|F zG)bU@)s&He;oRg(0e==ynFmyakGQh0memsOc?GKf;xkIcTX}ZVXT>4YE;iyJ^8CqJ!9$QQsc`kpz;9b z$jK!p4U7zvznauD{b!h5W?Cov4_a%1Tu5qUf@0EQvxUP6#z__)ETCEjVUI-!3#fX6 z3w*I?VEj9|)UuiF3n=|DZ2srW#DWn9a+HUG4faH9)6KZZhY3^!F-#9+VYCs5I1h3# z1A}{NUTRTdN&e)X)dtfYxEZxYLGEJ)g$Jmt&o3=XPK_x_o!-FB*f2@KR3^2kI3_VA zH#0A$7$dxSd325NIm1l0(jl;WXdz_|eG z@qZf=>lqgXu}uoVjLPmwq5_)*sy;9-iecgamF8TG3=ESwoaXR=I3TP864>CR0G2fa zac(&M$OXxOa5*CbLj@xPLnR}mkpdEf;W|bJhI*(tC^LaDEJMwQx{cU`DGJX}&^8Fj zuzwp9n;ADHxiE5o8VR6A06b}wB=;wnzjNYRm}?43j4+i0bPx1T&N{ zBr+5+lrWSs6fo#91TmyCBr>EhI5Olhq%e3gd+FiIJhD zp;2;DvYCY$8^gTGfsef>$FG%{?DL3wvi}m@$xX{q^Ea(Kz%*HBwZo>32N);k ztWF2ZN;5DpcunU2=P|iq^MT2QOI0UZFXNm1d5P8J{4JY6D!4%X2R{Y|1{W01h$4HY zNH4j#rl#7_Y|$K+$$>?Nta{1Cj9QcDt&kFOsw_!`6{H|#5MdUO@ZyGDOdK$|$vvyx zLDo&yXX2QAU>XY}^W?LOBteDk|ji0uwsZ|DBb*j zAtR$csL}zafTU#eR3l@HRNX}LWD8xBRAUR>#Kc5X-BcqplSD&P%cL|*LpFxV6IU(W zd}nbWBO;bTX@H2B2I&OFEw+f8#R{t9g*W%Ea$^(&^`9Uyu6F>`LIxF!h!n9oV2v*0 z;)W+olP7#~o_t`f1Gd=a{}+IiB0+KKH)+Fx$^BatC*Rv5zi1=lR0I5@>5KGF~t0L3OOA`y{{Bkp;SRij6{1SrNq z?$9+&O-wVkG)YZ02K6u)rYo>AN`n%JBqBXBx>y-l8CX@Dnizr7#^i;oY$ojzne3PE9T?N_EaJN}b%W$6<5BjYh`Fjh6~|Ef^u4b5P0AG1+mi>+}XOMxM$3 zmu(p5AakWA_g>-?EM+KWNM$HuNMT3>7jDIq9UX)x8{Z0Lc41(cY0pnz++YXcNmWk$-WF{w;Waj6^oaAQ!^;{X)7`9Fhd|WqK@2kb+nk7Dy6T$gCm0_gC&Cn!#TKJyTB&vedV6KV5!k&zX$b<6Ot)L)dWZNwGua*&eAqi5IKKbEN+pY18hZ!e-dMmzJ@23hQBiHu%jEwskLFtJL zTt4D*v>eDSlMk#FntqCjF%U#d0cnC1s?+nC88=T>{31R%?)L()Ft{|`p3ls924Xfm zt%4eO*aKAvBliSN-tgH;5IL8C@)Sr^XL8{R$;tU!gs1zlFuui}XQ^Y86W(0P0n4S6 z5B?GZRTyYx10%!a#77!pm_Bp1iV2;5fRpk6pb_3ZS0k1V&8p?Fx2`6PTtmi89J; PKV!#e!8)DAhH(u55*#p7 diff --git a/SecureCore/AppSettingsManager.cs b/SecureCore/AppSettingsManager.cs index f2b236d..10c6a96 100644 --- a/SecureCore/AppSettingsManager.cs +++ b/SecureCore/AppSettingsManager.cs @@ -63,7 +63,7 @@ namespace SecureCore public static void InitializeSettings() { - if (Settings != null) throw new InvalidOperationException("The in memory JSON settings has already been loaded. Operation aborted."); + if (Settings != null) throw new InvalidOperationException("The in memory JSON settings have already been loaded. Operation aborted."); if (!File.Exists(AppSettingsPath)) throw new FileNotFoundException($"The app settings file '{AppSettingsPath}' couldn't be found."); try diff --git a/SecureCore/Authentication/PasswordManager.cs b/SecureCore/Authentication/PasswordManager.cs index d01ef31..22578f6 100644 --- a/SecureCore/Authentication/PasswordManager.cs +++ b/SecureCore/Authentication/PasswordManager.cs @@ -24,6 +24,8 @@ namespace SecureCore.Authentication public static void InitializeSettings() { + if (!string.IsNullOrEmpty(Pepper)) throw new InvalidOperationException("The PasswordManager's settings have already been initialized. Operation aborted."); + if (AppSettingsManager.TryGetSettingInt(SectionName, "MaxLength", out int maxPasswordLength)) { //As noted in this article https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#maximum-password-lengths diff --git a/SecureCore/Authentication/SessionManager.cs b/SecureCore/Authentication/SessionManager.cs index 8276aee..6b092db 100644 --- a/SecureCore/Authentication/SessionManager.cs +++ b/SecureCore/Authentication/SessionManager.cs @@ -34,10 +34,8 @@ namespace SecureCore.Authentication return Convert.ToBoolean(result); } - public static bool IsSessionTokenValid(HttpContext context) + public static bool IsSessionTokenValid(HttpContext context, string connectionString) { - AppSettingsManager.TryGetConnectionString("MainDataConnectionString", out string connectionString); - if (!context.Request.Cookies.ContainsKey(SessionCookieName)) return false; return IsSessionTokenValid(context.Request.Cookies[SessionCookieName], connectionString); diff --git a/SecureCore/Controllers/AuthController.cs b/SecureCore/Controllers/AuthController.cs index 7d6fcb2..173bcb4 100644 --- a/SecureCore/Controllers/AuthController.cs +++ b/SecureCore/Controllers/AuthController.cs @@ -22,7 +22,7 @@ namespace SecureCore.Controllers try { - if (SessionManager.IsSessionTokenValid(HttpContext)) + if (SessionManager.IsSessionTokenValid(HttpContext, connectionString)) return Ok("Logged in\n"); //Verify that the username provided is valid, i.e. no whitespace, special characters, etc. @@ -168,7 +168,7 @@ namespace SecureCore.Controllers PasswordManager.InsertPasswordResetRequest(email, token, DateTime.Now.AddHours(1), agent, ip, connectionString); token = HttpUtility.UrlEncode(token); - //TODO: Allow the admin to configure the address that this function creates when doing password resets. + //TODO: Email the link to the supplied email. return Ok($"192.168.255.200:5000/auth/ResetPassword?token={token}{Environment.NewLine}"); } catch(Exception e) diff --git a/SecureCore/Controllers/EmployeeController.cs b/SecureCore/Controllers/EmployeeController.cs index 8ecec09..56f5830 100644 --- a/SecureCore/Controllers/EmployeeController.cs +++ b/SecureCore/Controllers/EmployeeController.cs @@ -24,7 +24,9 @@ namespace SecureCore.Controllers [HttpGet] public IActionResult Get() { - if(SessionManager.IsSessionTokenValid(HttpContext)) + AppSettingsManager.TryGetConnectionString("MainDataConnectionString", out string connectionString); + + if (SessionManager.IsSessionTokenValid(HttpContext, connectionString)) return Ok(DataService.Get()); else return Unauthorized(); @@ -33,7 +35,9 @@ namespace SecureCore.Controllers [HttpGet("{id}", Name = "Get")] public IActionResult Get(int id) { - if (SessionManager.IsSessionTokenValid(HttpContext)) + AppSettingsManager.TryGetConnectionString("MainDataConnectionString", out string connectionString); + + if (SessionManager.IsSessionTokenValid(HttpContext, connectionString)) return Ok(DataService.GetById(id)); else return Unauthorized(); diff --git a/SecureCore/appsettings.json b/SecureCore/appsettings.json index 896460d..ab529bb 100644 --- a/SecureCore/appsettings.json +++ b/SecureCore/appsettings.json @@ -14,7 +14,7 @@ "doamin": "copyrightcrusader.org" }, "PasswordSettings": { - "Peppser": "rVk/OwQUw01qy76Q+5WimPk+NdqUMMghftMXyJzzckOj/+eFn056PDYzBD61E/ZNjRdgiMK6RhcHEcdfpJdbcw==", + "Pepper": "rVk/OwQUw01qy76Q+5WimPk+NdqUMMghftMXyJzzckOj/+eFn056PDYzBD61E/ZNjRdgiMK6RhcHEcdfpJdbcw==", "MaxLength": 128, "MinLength": 22 }