Tweaked the SessionManager's IsSessionTokenValid function to accept a connection string to standardize the interfaces on all the SessionManager functions.
This commit is contained in:
Binary file not shown.
@@ -63,7 +63,7 @@ namespace SecureCore
|
|||||||
|
|
||||||
public static void InitializeSettings()
|
public static void InitializeSettings()
|
||||||
{
|
{
|
||||||
if (Settings != null) throw new InvalidOperationException("The in memory JSON settings has already been loaded. Operation aborted.");
|
if (Settings != null) throw new InvalidOperationException("The in memory JSON settings have already been loaded. Operation aborted.");
|
||||||
if (!File.Exists(AppSettingsPath)) throw new FileNotFoundException($"The app settings file '{AppSettingsPath}' couldn't be found.");
|
if (!File.Exists(AppSettingsPath)) throw new FileNotFoundException($"The app settings file '{AppSettingsPath}' couldn't be found.");
|
||||||
|
|
||||||
try
|
try
|
||||||
|
|||||||
@@ -24,6 +24,8 @@ namespace SecureCore.Authentication
|
|||||||
|
|
||||||
public static void InitializeSettings()
|
public static void InitializeSettings()
|
||||||
{
|
{
|
||||||
|
if (!string.IsNullOrEmpty(Pepper)) throw new InvalidOperationException("The PasswordManager's settings have already been initialized. Operation aborted.");
|
||||||
|
|
||||||
if (AppSettingsManager.TryGetSettingInt(SectionName, "MaxLength", out int maxPasswordLength))
|
if (AppSettingsManager.TryGetSettingInt(SectionName, "MaxLength", out int maxPasswordLength))
|
||||||
{
|
{
|
||||||
//As noted in this article https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#maximum-password-lengths
|
//As noted in this article https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#maximum-password-lengths
|
||||||
|
|||||||
@@ -34,10 +34,8 @@ namespace SecureCore.Authentication
|
|||||||
return Convert.ToBoolean(result);
|
return Convert.ToBoolean(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
public static bool IsSessionTokenValid(HttpContext context)
|
public static bool IsSessionTokenValid(HttpContext context, string connectionString)
|
||||||
{
|
{
|
||||||
AppSettingsManager.TryGetConnectionString("MainDataConnectionString", out string connectionString);
|
|
||||||
|
|
||||||
if (!context.Request.Cookies.ContainsKey(SessionCookieName)) return false;
|
if (!context.Request.Cookies.ContainsKey(SessionCookieName)) return false;
|
||||||
|
|
||||||
return IsSessionTokenValid(context.Request.Cookies[SessionCookieName], connectionString);
|
return IsSessionTokenValid(context.Request.Cookies[SessionCookieName], connectionString);
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ namespace SecureCore.Controllers
|
|||||||
|
|
||||||
try
|
try
|
||||||
{
|
{
|
||||||
if (SessionManager.IsSessionTokenValid(HttpContext))
|
if (SessionManager.IsSessionTokenValid(HttpContext, connectionString))
|
||||||
return Ok("Logged in\n");
|
return Ok("Logged in\n");
|
||||||
|
|
||||||
//Verify that the username provided is valid, i.e. no whitespace, special characters, etc.
|
//Verify that the username provided is valid, i.e. no whitespace, special characters, etc.
|
||||||
@@ -168,7 +168,7 @@ namespace SecureCore.Controllers
|
|||||||
PasswordManager.InsertPasswordResetRequest(email, token, DateTime.Now.AddHours(1), agent, ip, connectionString);
|
PasswordManager.InsertPasswordResetRequest(email, token, DateTime.Now.AddHours(1), agent, ip, connectionString);
|
||||||
|
|
||||||
token = HttpUtility.UrlEncode(token);
|
token = HttpUtility.UrlEncode(token);
|
||||||
//TODO: Allow the admin to configure the address that this function creates when doing password resets.
|
//TODO: Email the link to the supplied email.
|
||||||
return Ok($"192.168.255.200:5000/auth/ResetPassword?token={token}{Environment.NewLine}");
|
return Ok($"192.168.255.200:5000/auth/ResetPassword?token={token}{Environment.NewLine}");
|
||||||
}
|
}
|
||||||
catch(Exception e)
|
catch(Exception e)
|
||||||
|
|||||||
@@ -24,7 +24,9 @@ namespace SecureCore.Controllers
|
|||||||
[HttpGet]
|
[HttpGet]
|
||||||
public IActionResult Get()
|
public IActionResult Get()
|
||||||
{
|
{
|
||||||
if(SessionManager.IsSessionTokenValid(HttpContext))
|
AppSettingsManager.TryGetConnectionString("MainDataConnectionString", out string connectionString);
|
||||||
|
|
||||||
|
if (SessionManager.IsSessionTokenValid(HttpContext, connectionString))
|
||||||
return Ok(DataService.Get());
|
return Ok(DataService.Get());
|
||||||
else
|
else
|
||||||
return Unauthorized();
|
return Unauthorized();
|
||||||
@@ -33,7 +35,9 @@ namespace SecureCore.Controllers
|
|||||||
[HttpGet("{id}", Name = "Get")]
|
[HttpGet("{id}", Name = "Get")]
|
||||||
public IActionResult Get(int id)
|
public IActionResult Get(int id)
|
||||||
{
|
{
|
||||||
if (SessionManager.IsSessionTokenValid(HttpContext))
|
AppSettingsManager.TryGetConnectionString("MainDataConnectionString", out string connectionString);
|
||||||
|
|
||||||
|
if (SessionManager.IsSessionTokenValid(HttpContext, connectionString))
|
||||||
return Ok(DataService.GetById(id));
|
return Ok(DataService.GetById(id));
|
||||||
else
|
else
|
||||||
return Unauthorized();
|
return Unauthorized();
|
||||||
|
|||||||
@@ -14,7 +14,7 @@
|
|||||||
"doamin": "copyrightcrusader.org"
|
"doamin": "copyrightcrusader.org"
|
||||||
},
|
},
|
||||||
"PasswordSettings": {
|
"PasswordSettings": {
|
||||||
"Peppser": "rVk/OwQUw01qy76Q+5WimPk+NdqUMMghftMXyJzzckOj/+eFn056PDYzBD61E/ZNjRdgiMK6RhcHEcdfpJdbcw==",
|
"Pepper": "rVk/OwQUw01qy76Q+5WimPk+NdqUMMghftMXyJzzckOj/+eFn056PDYzBD61E/ZNjRdgiMK6RhcHEcdfpJdbcw==",
|
||||||
"MaxLength": 128,
|
"MaxLength": 128,
|
||||||
"MinLength": 22
|
"MinLength": 22
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user