blob: e475b2445f97e3581ddd2b80bfaa792152d3e5ca [file] [log] [blame]
Zhiyi Zhangdefa9592017-02-21 10:56:22 -08001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
2/**
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -07003 * Copyright (c) 2017-2019, Regents of the University of California.
Zhiyi Zhangdefa9592017-02-21 10:56:22 -08004 *
5 * This file is part of ndncert, a certificate management system based on NDN.
6 *
7 * ndncert is free software: you can redistribute it and/or modify it under the terms
8 * of the GNU General Public License as published by the Free Software Foundation, either
9 * version 3 of the License, or (at your option) any later version.
10 *
11 * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License along with
16 * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
17 *
18 * See AUTHORS.md for complete list of ndncert authors and contributors.
19 */
20
21#include "challenge-email.hpp"
Zhiyi Zhang5f749a22019-06-12 17:02:33 -070022#include "../ca-module.hpp"
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080023#include "../logging.hpp"
Zhiyi Zhang8ce677b2018-07-13 14:44:06 -070024#include <regex>
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080025
26namespace ndn {
27namespace ndncert {
28
29_LOG_INIT(ndncert.ChallengeEmail);
30
31NDNCERT_REGISTER_CHALLENGE(ChallengeEmail, "Email");
32
33const std::string ChallengeEmail::NEED_CODE = "need-code";
34const std::string ChallengeEmail::WRONG_CODE = "wrong-code";
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080035const std::string ChallengeEmail::FAILURE_INVALID_EMAIL = "failure-invalid-email";
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080036const std::string ChallengeEmail::JSON_EMAIL = "email";
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080037const std::string ChallengeEmail::JSON_CODE = "code";
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080038
39ChallengeEmail::ChallengeEmail(const std::string& scriptPath,
40 const size_t& maxAttemptTimes,
41 const time::seconds secretLifetime)
Zhiyi Zhanga9bda732017-05-20 22:58:55 -070042 : ChallengeModule("Email")
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080043 , m_sendEmailScript(scriptPath)
44 , m_maxAttemptTimes(maxAttemptTimes)
45 , m_secretLifetime(secretLifetime)
46{
47}
48
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070049// For CA
50void
51ChallengeEmail::handleChallengeRequest(const JsonSection& params, CertificateRequest& request)
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080052{
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070053 if (request.m_challengeStatus == "") {
54 // for the first time, init the challenge
55 std::string emailAddress = params.get<std::string>(JSON_EMAIL);
56 if (!isValidEmailAddress(emailAddress)) {
57 request.m_status = STATUS_FAILURE;
58 request.m_challengeStatus = FAILURE_INVALID_EMAIL;
59 return;
60 }
Zhiyi Zhang5f749a22019-06-12 17:02:33 -070061 // check whether this email is the same as the one used in PROBE
62 if (request.m_probeToken != nullptr) {
63 const auto& content = request.m_probeToken->getContent();
64 const auto& json = CaModule::jsonFromBlock(content);
65 const auto& expectedEmail = json.get("email", "");
66 Name expectedPrefix(json.get(JSON_CA_NAME, ""));
67 if (expectedEmail != emailAddress || !expectedPrefix.isPrefixOf(request.m_cert.getName())) {
Zhiyi Zhang42e1cf32019-06-22 17:11:42 -070068 _LOG_ERROR("Cannot match with the PROBE token. Input email: " << emailAddress
69 << " Email in Token: " << expectedEmail
70 << " Requested Cert Name: " << request.m_cert.getName()
71 << " Identity Name got from Token: " << expectedPrefix);
Zhiyi Zhang5f749a22019-06-12 17:02:33 -070072 return;
73 }
74 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070075 request.m_status = STATUS_CHALLENGE;
76 request.m_challengeStatus = NEED_CODE;
77 request.m_challengeType = CHALLENGE_TYPE;
78 std::string emailCode = generateSecretCode();
79 JsonSection secretJson;
80 secretJson.add(JSON_CODE, emailCode);
81 request.m_challengeSecrets = secretJson;
82 request.m_challengeTp = time::toIsoString(time::system_clock::now());
83 request.m_remainingTime = m_secretLifetime.count();
84 request.m_remainingTries = m_maxAttemptTimes;
85 // send out the email
86 sendEmail(emailAddress, emailCode, request);
87 _LOG_TRACE("Secret for request " << request.m_requestId << " : " << emailCode);
88 return;
Zhiyi Zhangdefa9592017-02-21 10:56:22 -080089 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070090 else if (request.m_challengeStatus == NEED_CODE || request.m_challengeStatus == WRONG_CODE) {
91 _LOG_TRACE("Challenge Interest arrives. Challenge Status: " << request.m_challengeStatus);
92 // the incoming interest should bring the pin code
93 std::string givenCode = params.get<std::string>(JSON_CODE);
94 const auto realCode = request.m_challengeSecrets.get<std::string>(JSON_CODE);
95 if (time::system_clock::now() - time::fromIsoString(request.m_challengeTp) >= m_secretLifetime) {
96 // secret expires
97 request.m_status = STATUS_FAILURE;
98 request.m_challengeStatus = CHALLENGE_STATUS_FAILURE_TIMEOUT;
99 updateRequestOnChallengeEnd(request);
100 _LOG_TRACE("Secret expired. Challenge failed.");
101 return;
102 }
103 else if (givenCode == realCode) {
104 // the code is correct
105 request.m_status = STATUS_PENDING;
106 request.m_challengeStatus = CHALLENGE_STATUS_SUCCESS;
107 updateRequestOnChallengeEnd(request);
108 _LOG_TRACE("Secret code matched. Challenge succeeded.");
109 return;
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800110 }
111 else {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700112 // check rest attempt times
113 if (request.m_remainingTries > 1) {
114 request.m_challengeStatus = WRONG_CODE;
115 request.m_remainingTries = request.m_remainingTries - 1;
116 auto remainTime = m_secretLifetime - (time::system_clock::now() - time::fromIsoString(request.m_challengeTp));
117 request.m_remainingTime = remainTime.count();
118 _LOG_TRACE("Secret code didn't match. Remaining Tries - 1.");
119 return;
120 }
121 else {
122 // run out times
123 request.m_status = STATUS_FAILURE;
124 request.m_challengeStatus = CHALLENGE_STATUS_FAILURE_MAXRETRY;
125 updateRequestOnChallengeEnd(request);
126 _LOG_TRACE("Secret code didn't match. Ran out tires. Challenge failed.");
127 return;
128 }
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800129 }
130 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700131 else {
132 _LOG_ERROR("The challenge status is wrong");
133 request.m_status = STATUS_FAILURE;
134 return;
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800135 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700136}
137
138// For Client
139JsonSection
140ChallengeEmail::getRequirementForChallenge(int status, const std::string& challengeStatus)
141{
142 JsonSection result;
143 if (status == STATUS_BEFORE_CHALLENGE && challengeStatus == "") {
144 result.put(JSON_EMAIL, "Please_input_your_email_address");
145 }
146 else if (status == STATUS_CHALLENGE && challengeStatus == NEED_CODE) {
147 result.put(JSON_CODE, "Please_input_your_verification_code");
148 }
149 else if (status == STATUS_CHALLENGE && challengeStatus == WRONG_CODE) {
150 result.put(JSON_CODE, "Incorrect_code_please_try_again");
151 }
152 else {
153 _LOG_ERROR("CA's status and challenge status are wrong");
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800154 }
155 return result;
156}
157
158JsonSection
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700159ChallengeEmail::genChallengeRequestJson(int status, const std::string& challengeStatus, const JsonSection& params)
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800160{
161 JsonSection result;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700162 if (status == STATUS_BEFORE_CHALLENGE && challengeStatus == "") {
163 result.put(JSON_CLIENT_SELECTED_CHALLENGE, CHALLENGE_TYPE);
164 result.put(JSON_EMAIL, params.get<std::string>(JSON_EMAIL, ""));
165 }
166 else if (status == STATUS_CHALLENGE && challengeStatus == NEED_CODE) {
167 result.put(JSON_CLIENT_SELECTED_CHALLENGE, CHALLENGE_TYPE);
168 result.put(JSON_CODE, params.get<std::string>(JSON_CODE, ""));
169 }
170 else if (status == STATUS_CHALLENGE && challengeStatus == WRONG_CODE) {
171 result.put(JSON_CLIENT_SELECTED_CHALLENGE, CHALLENGE_TYPE);
172 result.put(JSON_CODE, params.get<std::string>(JSON_CODE, ""));
173 }
174 else {
175 _LOG_ERROR("Client's status and challenge status are wrong");
176 }
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800177 return result;
178}
179
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800180bool
181ChallengeEmail::isValidEmailAddress(const std::string& emailAddress)
182{
Zhiyi Zhang8ce677b2018-07-13 14:44:06 -0700183 const std::string pattern = R"_REGEX_((^[a-zA-Z0-9_.+-]+@[a-zA-Z0-9-]+.[a-zA-Z0-9\-\.]+$))_REGEX_";
184 static const std::regex emailPattern(pattern);
185 return std::regex_match(emailAddress, emailPattern);
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800186}
187
188void
Zhiyi Zhang576aad12017-10-03 15:41:53 -0700189ChallengeEmail::sendEmail(const std::string& emailAddress, const std::string& secret,
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700190 const CertificateRequest& request) const
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800191{
Zhiyi Zhang576aad12017-10-03 15:41:53 -0700192 std::string command = m_sendEmailScript;
Zhiyi Zhang70d74b42019-06-11 22:27:07 -0700193 command += " \"" + emailAddress + "\" \"" + secret + "\" \""
194 + request.m_caName.toUri() + "\" \"" + request.m_cert.getName().toUri() + "\"";
Zhiyi Zhang576aad12017-10-03 15:41:53 -0700195 int result = system(command.c_str());
196 if (result == -1) {
197 _LOG_TRACE("EmailSending Script " + m_sendEmailScript + " fails.");
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800198 }
Zhiyi Zhang576aad12017-10-03 15:41:53 -0700199 _LOG_TRACE("EmailSending Script " + m_sendEmailScript +
200 " was executed successfully with return value" + std::to_string(result) + ".");
Zhiyi Zhangdefa9592017-02-21 10:56:22 -0800201 return;
202}
203
204} // namespace ndncert
205} // namespace ndn