20 changed files with 583 additions and 330 deletions
@ -0,0 +1,124 @@ |
|||
/** |
|||
* Copyright © 2016-2022 The Thingsboard Authors |
|||
* |
|||
* Licensed under the Apache License, Version 2.0 (the "License"); |
|||
* you may not use this file except in compliance with the License. |
|||
* You may obtain a copy of the License at |
|||
* |
|||
* http://www.apache.org/licenses/LICENSE-2.0
|
|||
* |
|||
* Unless required by applicable law or agreed to in writing, software |
|||
* distributed under the License is distributed on an "AS IS" BASIS, |
|||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|||
* See the License for the specific language governing permissions and |
|||
* limitations under the License. |
|||
*/ |
|||
package org.thingsboard.server.controller; |
|||
|
|||
import com.google.zxing.BarcodeFormat; |
|||
import com.google.zxing.client.j2se.MatrixToImageWriter; |
|||
import com.google.zxing.common.BitMatrix; |
|||
import com.google.zxing.qrcode.QRCodeWriter; |
|||
import lombok.RequiredArgsConstructor; |
|||
import org.springframework.security.access.prepost.PreAuthorize; |
|||
import org.springframework.web.bind.annotation.DeleteMapping; |
|||
import org.springframework.web.bind.annotation.GetMapping; |
|||
import org.springframework.web.bind.annotation.PostMapping; |
|||
import org.springframework.web.bind.annotation.RequestBody; |
|||
import org.springframework.web.bind.annotation.RequestMapping; |
|||
import org.springframework.web.bind.annotation.RequestParam; |
|||
import org.springframework.web.bind.annotation.RestController; |
|||
import org.thingsboard.common.util.JacksonUtil; |
|||
import org.thingsboard.server.common.data.exception.ThingsboardErrorCode; |
|||
import org.thingsboard.server.common.data.exception.ThingsboardException; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthConfigManager; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthSettings; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.account.TotpTwoFactorAuthAccountConfig; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.account.TwoFactorAuthAccountConfig; |
|||
import org.thingsboard.server.service.security.auth.mfa.provider.TwoFactorAuthProviderType; |
|||
import org.thingsboard.server.service.security.auth.mfa.TwoFactorAuthService; |
|||
import org.thingsboard.server.service.security.model.SecurityUser; |
|||
|
|||
import javax.servlet.ServletOutputStream; |
|||
import javax.servlet.http.HttpServletResponse; |
|||
import javax.validation.Valid; |
|||
|
|||
@RestController |
|||
@RequestMapping("/api/2fa") |
|||
@RequiredArgsConstructor |
|||
public class TwoFactorAuthConfigController extends BaseController { |
|||
|
|||
private final TwoFactorAuthConfigManager twoFactorAuthConfigManager; |
|||
private final TwoFactorAuthService twoFactorAuthService; |
|||
|
|||
|
|||
@GetMapping("/account/config") |
|||
@PreAuthorize("isAuthenticated()") |
|||
public TwoFactorAuthAccountConfig getTwoFaAccountConfig() throws ThingsboardException { |
|||
SecurityUser user = getCurrentUser(); |
|||
return twoFactorAuthConfigManager.getTwoFaAccountConfig(user.getTenantId(), user.getId()).orElse(null); |
|||
} |
|||
|
|||
@PostMapping("/account/config/generate") |
|||
@PreAuthorize("isAuthenticated()") |
|||
public TwoFactorAuthAccountConfig generateTwoFaAccountConfig(@RequestParam TwoFactorAuthProviderType providerType) throws Exception { |
|||
SecurityUser user = getCurrentUser(); |
|||
return twoFactorAuthService.generateNewAccountConfig(user, providerType); |
|||
} |
|||
|
|||
/* TMP */ |
|||
@PostMapping("/account/config/generate/qr") |
|||
@PreAuthorize("isAuthenticated()") |
|||
public void generateTwoFaAccountConfigWithQr(@RequestParam TwoFactorAuthProviderType providerType, HttpServletResponse response) throws Exception { |
|||
TwoFactorAuthAccountConfig config = generateTwoFaAccountConfig(providerType); |
|||
if (providerType == TwoFactorAuthProviderType.TOTP) { |
|||
BitMatrix qr = new QRCodeWriter().encode(((TotpTwoFactorAuthAccountConfig) config).getAuthUrl(), BarcodeFormat.QR_CODE, 200, 200); |
|||
try (ServletOutputStream outputStream = response.getOutputStream()) { |
|||
MatrixToImageWriter.writeToStream(qr, "PNG", outputStream); |
|||
} |
|||
} |
|||
response.setHeader("config", JacksonUtil.toString(config)); |
|||
} |
|||
/* TMP */ |
|||
|
|||
@PostMapping("/account/config/submit") |
|||
@PreAuthorize("isAuthenticated()") |
|||
public void submitTwoFaAccountConfig(@Valid @RequestBody TwoFactorAuthAccountConfig accountConfig) throws Exception { |
|||
SecurityUser user = getCurrentUser(); |
|||
twoFactorAuthService.prepareVerificationCode(user, accountConfig, false); |
|||
} |
|||
|
|||
@PostMapping("/account/config") |
|||
@PreAuthorize("isAuthenticated()") |
|||
public void verifyAndSaveTwoFaAccountConfig(@Valid @RequestBody TwoFactorAuthAccountConfig accountConfig, |
|||
@RequestParam String verificationCode) throws Exception { |
|||
SecurityUser user = getCurrentUser(); |
|||
boolean verificationSuccess = twoFactorAuthService.checkVerificationCode(user, verificationCode, accountConfig, false); |
|||
if (verificationSuccess) { |
|||
twoFactorAuthConfigManager.saveTwoFaAccountConfig(user.getTenantId(), user.getId(), accountConfig); |
|||
} else { |
|||
throw new ThingsboardException("Verification code is incorrect", ThingsboardErrorCode.INVALID_ARGUMENTS); |
|||
} |
|||
} |
|||
|
|||
@DeleteMapping("/account/config") |
|||
@PreAuthorize("isAuthenticated()") |
|||
public void deleteTwoFactorAuthAccountConfig() throws ThingsboardException { |
|||
SecurityUser user = getCurrentUser(); |
|||
twoFactorAuthConfigManager.deleteTwoFaAccountConfig(user.getTenantId(), user.getId()); |
|||
} |
|||
|
|||
|
|||
@GetMapping("/settings") |
|||
@PreAuthorize("hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')") |
|||
public TwoFactorAuthSettings getTwoFactorAuthSettings() throws ThingsboardException { |
|||
return twoFactorAuthConfigManager.getTwoFaSettings(getTenantId()).orElse(null); |
|||
} |
|||
|
|||
@PostMapping("/settings") |
|||
@PreAuthorize("hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')") |
|||
public void saveTwoFactorAuthSettings(@RequestBody TwoFactorAuthSettings twoFactorAuthSettings) throws ThingsboardException { |
|||
twoFactorAuthConfigManager.saveTwoFaSettings(getTenantId(), twoFactorAuthSettings); |
|||
} |
|||
|
|||
} |
|||
@ -0,0 +1,151 @@ |
|||
/** |
|||
* Copyright © 2016-2022 The Thingsboard Authors |
|||
* |
|||
* Licensed under the Apache License, Version 2.0 (the "License"); |
|||
* you may not use this file except in compliance with the License. |
|||
* You may obtain a copy of the License at |
|||
* |
|||
* http://www.apache.org/licenses/LICENSE-2.0
|
|||
* |
|||
* Unless required by applicable law or agreed to in writing, software |
|||
* distributed under the License is distributed on an "AS IS" BASIS, |
|||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|||
* See the License for the specific language governing permissions and |
|||
* limitations under the License. |
|||
*/ |
|||
package org.thingsboard.server.service.security.auth.mfa; |
|||
|
|||
import lombok.RequiredArgsConstructor; |
|||
import org.springframework.beans.factory.annotation.Autowired; |
|||
import org.springframework.stereotype.Service; |
|||
import org.thingsboard.server.common.data.StringUtils; |
|||
import org.thingsboard.server.common.data.User; |
|||
import org.thingsboard.server.common.data.exception.ThingsboardErrorCode; |
|||
import org.thingsboard.server.common.data.exception.ThingsboardException; |
|||
import org.thingsboard.server.common.data.id.TenantId; |
|||
import org.thingsboard.server.common.msg.tools.TbRateLimits; |
|||
import org.thingsboard.server.dao.user.UserService; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthConfigManager; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthSettings; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.account.TwoFactorAuthAccountConfig; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.provider.TwoFactorAuthProviderConfig; |
|||
import org.thingsboard.server.service.security.auth.mfa.provider.TwoFactorAuthProvider; |
|||
import org.thingsboard.server.service.security.auth.mfa.provider.TwoFactorAuthProviderType; |
|||
import org.thingsboard.server.service.security.model.SecurityUser; |
|||
import org.thingsboard.server.service.security.system.SystemSecurityService; |
|||
|
|||
import java.util.Collection; |
|||
import java.util.EnumMap; |
|||
import java.util.Map; |
|||
import java.util.Optional; |
|||
import java.util.concurrent.ConcurrentHashMap; |
|||
import java.util.concurrent.ConcurrentMap; |
|||
|
|||
@Service |
|||
@RequiredArgsConstructor |
|||
public class DefaultTwoFactorAuthService implements TwoFactorAuthService { |
|||
|
|||
private final TwoFactorAuthConfigManager configManager; |
|||
private final SystemSecurityService systemSecurityService; |
|||
private final UserService userService; |
|||
private final Map<TwoFactorAuthProviderType, TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>> providers = new EnumMap<>(TwoFactorAuthProviderType.class); |
|||
|
|||
// FIXME [viacheslav]: remove from the map
|
|||
// TODO [viacheslav]: these rate limits are local, and will work bad in the cluster
|
|||
private final ConcurrentMap<String, TbRateLimits> verificationCodeSendingRateLimits = new ConcurrentHashMap<>(); |
|||
private final ConcurrentMap<String, TbRateLimits> verificationCodeCheckingRateLimits = new ConcurrentHashMap<>(); |
|||
|
|||
private static final ThingsboardException ACCOUNT_NOT_CONFIGURED = new ThingsboardException("2FA is not configured for account", ThingsboardErrorCode.BAD_REQUEST_PARAMS); |
|||
private static final ThingsboardException PROVIDER_NOT_CONFIGURED = new ThingsboardException("2FA provider is not configured", ThingsboardErrorCode.BAD_REQUEST_PARAMS); |
|||
private static final ThingsboardException PROVIDER_NOT_AVAILABLE = new ThingsboardException("2FA provider is not available", ThingsboardErrorCode.GENERAL); |
|||
|
|||
|
|||
@Override |
|||
public void prepareVerificationCode(SecurityUser securityUser, boolean rateLimit) throws Exception { |
|||
TwoFactorAuthAccountConfig accountConfig = configManager.getTwoFaAccountConfig(securityUser.getTenantId(), securityUser.getId()) |
|||
.orElseThrow(() -> ACCOUNT_NOT_CONFIGURED); |
|||
prepareVerificationCode(securityUser, accountConfig, rateLimit); |
|||
} |
|||
|
|||
@Override |
|||
public void prepareVerificationCode(SecurityUser securityUser, TwoFactorAuthAccountConfig accountConfig, boolean rateLimit) throws ThingsboardException { |
|||
TwoFactorAuthSettings twoFaSettings = configManager.getTwoFaSettings(securityUser.getTenantId()) |
|||
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
|||
if (rateLimit) { |
|||
if (StringUtils.isNotEmpty(twoFaSettings.getVerificationCodeSendRateLimit())) { |
|||
TbRateLimits rateLimits = verificationCodeSendingRateLimits.computeIfAbsent(securityUser.getSessionId(), sessionId -> { |
|||
return new TbRateLimits(twoFaSettings.getVerificationCodeSendRateLimit()); |
|||
}); |
|||
if (!rateLimits.tryConsume()) { |
|||
throw new ThingsboardException("Too many verification code sending requests", ThingsboardErrorCode.TOO_MANY_REQUESTS); |
|||
} |
|||
} |
|||
} |
|||
|
|||
TwoFactorAuthProviderConfig providerConfig = twoFaSettings.getProviderConfig(accountConfig.getProviderType()) |
|||
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
|||
getTwoFaProvider(accountConfig.getProviderType()).prepareVerificationCode(securityUser, providerConfig, accountConfig); |
|||
} |
|||
|
|||
@Override |
|||
public boolean checkVerificationCode(SecurityUser securityUser, String verificationCode, boolean rateLimit) throws ThingsboardException { |
|||
TwoFactorAuthAccountConfig accountConfig = configManager.getTwoFaAccountConfig(securityUser.getTenantId(), securityUser.getId()) |
|||
.orElseThrow(() -> ACCOUNT_NOT_CONFIGURED); |
|||
return checkVerificationCode(securityUser, verificationCode, accountConfig, rateLimit); |
|||
} |
|||
|
|||
@Override |
|||
public boolean checkVerificationCode(SecurityUser securityUser, String verificationCode, TwoFactorAuthAccountConfig accountConfig, boolean rateLimit) throws ThingsboardException { |
|||
if (!userService.findUserCredentialsByUserId(securityUser.getTenantId(), securityUser.getId()).isEnabled()) { |
|||
throw new ThingsboardException("User is disabled", ThingsboardErrorCode.AUTHENTICATION); |
|||
} |
|||
|
|||
TwoFactorAuthSettings twoFaSettings = configManager.getTwoFaSettings(securityUser.getTenantId()) |
|||
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
|||
if (rateLimit) { |
|||
if (StringUtils.isNotEmpty(twoFaSettings.getVerificationCodeCheckRateLimit())) { |
|||
TbRateLimits rateLimits = verificationCodeCheckingRateLimits.computeIfAbsent(securityUser.getSessionId(), sessionId -> { |
|||
return new TbRateLimits(twoFaSettings.getVerificationCodeCheckRateLimit()); |
|||
}); |
|||
if (!rateLimits.tryConsume()) { |
|||
throw new ThingsboardException("Too many verification code checking requests", ThingsboardErrorCode.TOO_MANY_REQUESTS); |
|||
} |
|||
} |
|||
} |
|||
|
|||
TwoFactorAuthProviderConfig providerConfig = twoFaSettings.getProviderConfig(accountConfig.getProviderType()) |
|||
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
|||
boolean verificationSuccess = getTwoFaProvider(accountConfig.getProviderType()).checkVerificationCode(securityUser, verificationCode, providerConfig, accountConfig); |
|||
if (rateLimit) { |
|||
systemSecurityService.validateTwoFaVerification(securityUser.getTenantId(), securityUser.getId(), verificationSuccess, twoFaSettings); |
|||
} |
|||
return verificationSuccess; |
|||
} |
|||
|
|||
@Override |
|||
public TwoFactorAuthAccountConfig generateNewAccountConfig(User user, TwoFactorAuthProviderType providerType) throws ThingsboardException { |
|||
TwoFactorAuthProviderConfig providerConfig = getTwoFaProviderConfig(user.getTenantId(), providerType); |
|||
return getTwoFaProvider(providerType).generateNewAccountConfig(user, providerConfig); |
|||
} |
|||
|
|||
|
|||
private TwoFactorAuthProviderConfig getTwoFaProviderConfig(TenantId tenantId, TwoFactorAuthProviderType providerType) throws ThingsboardException { |
|||
return configManager.getTwoFaSettings(tenantId) |
|||
.flatMap(twoFaSettings -> twoFaSettings.getProviderConfig(providerType)) |
|||
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
|||
} |
|||
|
|||
private TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig> getTwoFaProvider(TwoFactorAuthProviderType providerType) throws ThingsboardException { |
|||
return Optional.ofNullable(providers.get(providerType)) |
|||
.orElseThrow(() -> PROVIDER_NOT_AVAILABLE); |
|||
} |
|||
|
|||
@Autowired |
|||
private void setProviders(Collection<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>> providers) { |
|||
providers.forEach(provider -> { |
|||
this.providers.put(provider.getType(), provider); |
|||
}); |
|||
} |
|||
|
|||
} |
|||
|
|||
@ -0,0 +1,139 @@ |
|||
/** |
|||
* Copyright © 2016-2022 The Thingsboard Authors |
|||
* |
|||
* Licensed under the Apache License, Version 2.0 (the "License"); |
|||
* you may not use this file except in compliance with the License. |
|||
* You may obtain a copy of the License at |
|||
* |
|||
* http://www.apache.org/licenses/LICENSE-2.0
|
|||
* |
|||
* Unless required by applicable law or agreed to in writing, software |
|||
* distributed under the License is distributed on an "AS IS" BASIS, |
|||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|||
* See the License for the specific language governing permissions and |
|||
* limitations under the License. |
|||
*/ |
|||
package org.thingsboard.server.service.security.auth.mfa.config; |
|||
|
|||
import com.fasterxml.jackson.databind.node.ObjectNode; |
|||
import lombok.RequiredArgsConstructor; |
|||
import lombok.SneakyThrows; |
|||
import org.springframework.stereotype.Service; |
|||
import org.thingsboard.common.util.JacksonUtil; |
|||
import org.thingsboard.server.common.data.AdminSettings; |
|||
import org.thingsboard.server.common.data.DataConstants; |
|||
import org.thingsboard.server.common.data.User; |
|||
import org.thingsboard.server.common.data.exception.ThingsboardErrorCode; |
|||
import org.thingsboard.server.common.data.exception.ThingsboardException; |
|||
import org.thingsboard.server.common.data.id.TenantId; |
|||
import org.thingsboard.server.common.data.id.UserId; |
|||
import org.thingsboard.server.common.data.kv.BaseAttributeKvEntry; |
|||
import org.thingsboard.server.common.data.kv.JsonDataEntry; |
|||
import org.thingsboard.server.dao.attributes.AttributesService; |
|||
import org.thingsboard.server.dao.service.ConstraintValidator; |
|||
import org.thingsboard.server.dao.settings.AdminSettingsService; |
|||
import org.thingsboard.server.dao.user.UserService; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.account.TwoFactorAuthAccountConfig; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.provider.TwoFactorAuthProviderConfig; |
|||
import org.thingsboard.server.service.security.auth.mfa.provider.TwoFactorAuthProviderType; |
|||
|
|||
import java.util.Collections; |
|||
import java.util.Optional; |
|||
import java.util.concurrent.ExecutionException; |
|||
|
|||
@Service |
|||
@RequiredArgsConstructor |
|||
public class DefaultTwoFactorAuthConfigManager implements TwoFactorAuthConfigManager { |
|||
|
|||
private final UserService userService; |
|||
private final AdminSettingsService adminSettingsService; |
|||
private final AttributesService attributesService; |
|||
|
|||
protected static final String TWO_FACTOR_AUTH_ACCOUNT_CONFIG_KEY = "twoFaConfig"; |
|||
protected static final String TWO_FACTOR_AUTH_SETTINGS_KEY = "twoFaSettings"; |
|||
|
|||
|
|||
@Override |
|||
public boolean isTwoFaEnabled(User user) { |
|||
return getTwoFaAccountConfig(user.getTenantId(), user.getId()).isPresent(); |
|||
} |
|||
|
|||
@Override |
|||
public Optional<TwoFactorAuthAccountConfig> getTwoFaAccountConfig(TenantId tenantId, UserId userId) { |
|||
User user = userService.findUserById(tenantId, userId); |
|||
return Optional.ofNullable(user.getAdditionalInfo()) |
|||
.flatMap(additionalInfo -> Optional.ofNullable(additionalInfo.get(TWO_FACTOR_AUTH_ACCOUNT_CONFIG_KEY)).filter(jsonNode -> !jsonNode.isNull())) |
|||
.map(jsonNode -> JacksonUtil.treeToValue(jsonNode, TwoFactorAuthAccountConfig.class)) |
|||
.filter(twoFactorAuthAccountConfig -> { |
|||
return getTwoFaProviderConfig(tenantId, twoFactorAuthAccountConfig.getProviderType()).isPresent(); |
|||
}); |
|||
} |
|||
|
|||
@Override |
|||
public void saveTwoFaAccountConfig(TenantId tenantId, UserId userId, TwoFactorAuthAccountConfig accountConfig) throws ThingsboardException { |
|||
getTwoFaProviderConfig(tenantId, accountConfig.getProviderType()) |
|||
.orElseThrow(() -> new ThingsboardException("2FA provider is not configured", ThingsboardErrorCode.BAD_REQUEST_PARAMS)); |
|||
|
|||
User user = userService.findUserById(tenantId, userId); |
|||
ObjectNode additionalInfo = (ObjectNode) Optional.ofNullable(user.getAdditionalInfo()) |
|||
.orElseGet(JacksonUtil::newObjectNode); |
|||
additionalInfo.set(TWO_FACTOR_AUTH_ACCOUNT_CONFIG_KEY, JacksonUtil.valueToTree(accountConfig)); |
|||
user.setAdditionalInfo(additionalInfo); |
|||
|
|||
userService.saveUser(user); |
|||
} |
|||
|
|||
@Override |
|||
public void deleteTwoFaAccountConfig(TenantId tenantId, UserId userId) { |
|||
User user = userService.findUserById(tenantId, userId); |
|||
ObjectNode additionalInfo = (ObjectNode) Optional.ofNullable(user.getAdditionalInfo()) |
|||
.orElseGet(JacksonUtil::newObjectNode); |
|||
additionalInfo.remove(TWO_FACTOR_AUTH_ACCOUNT_CONFIG_KEY); |
|||
user.setAdditionalInfo(additionalInfo); |
|||
|
|||
userService.saveUser(user); |
|||
} |
|||
|
|||
|
|||
private Optional<TwoFactorAuthProviderConfig> getTwoFaProviderConfig(TenantId tenantId, TwoFactorAuthProviderType providerType) { |
|||
return getTwoFaSettings(tenantId) |
|||
.flatMap(twoFaSettings -> twoFaSettings.getProviderConfig(providerType)); |
|||
} |
|||
|
|||
@SneakyThrows({InterruptedException.class, ExecutionException.class}) |
|||
@Override |
|||
public Optional<TwoFactorAuthSettings> getTwoFaSettings(TenantId tenantId) { |
|||
if (tenantId.equals(TenantId.SYS_TENANT_ID)) { |
|||
return Optional.ofNullable(adminSettingsService.findAdminSettingsByKey(tenantId, TWO_FACTOR_AUTH_SETTINGS_KEY)) |
|||
.map(adminSettings -> JacksonUtil.treeToValue(adminSettings.getJsonValue(), TwoFactorAuthSettings.class)); |
|||
} else { |
|||
return attributesService.find(TenantId.SYS_TENANT_ID, tenantId, DataConstants.SERVER_SCOPE, TWO_FACTOR_AUTH_SETTINGS_KEY).get() |
|||
.map(adminSettingsAttribute -> JacksonUtil.fromString(adminSettingsAttribute.getJsonValue().get(), TwoFactorAuthSettings.class)) |
|||
.filter(tenantTwoFactorAuthSettings -> !tenantTwoFactorAuthSettings.isUseSystemTwoFactorAuthSettings()) |
|||
.or(() -> getTwoFaSettings(TenantId.SYS_TENANT_ID)); |
|||
} |
|||
} |
|||
|
|||
@SneakyThrows({InterruptedException.class, ExecutionException.class}) |
|||
@Override |
|||
public void saveTwoFaSettings(TenantId tenantId, TwoFactorAuthSettings twoFactorAuthSettings) { |
|||
if (tenantId.equals(TenantId.SYS_TENANT_ID) || !twoFactorAuthSettings.isUseSystemTwoFactorAuthSettings()) { |
|||
ConstraintValidator.validateFields(twoFactorAuthSettings); |
|||
} |
|||
if (tenantId.equals(TenantId.SYS_TENANT_ID)) { |
|||
AdminSettings settings = Optional.ofNullable(adminSettingsService.findAdminSettingsByKey(tenantId, TWO_FACTOR_AUTH_SETTINGS_KEY)) |
|||
.orElseGet(() -> { |
|||
AdminSettings newSettings = new AdminSettings(); |
|||
newSettings.setKey(TWO_FACTOR_AUTH_SETTINGS_KEY); |
|||
return newSettings; |
|||
}); |
|||
settings.setJsonValue(JacksonUtil.valueToTree(twoFactorAuthSettings)); |
|||
adminSettingsService.saveAdminSettings(tenantId, settings); |
|||
} else { |
|||
attributesService.save(TenantId.SYS_TENANT_ID, tenantId, DataConstants.SERVER_SCOPE, Collections.singletonList( |
|||
new BaseAttributeKvEntry(new JsonDataEntry(TWO_FACTOR_AUTH_SETTINGS_KEY, JacksonUtil.toString(twoFactorAuthSettings)), System.currentTimeMillis()) |
|||
)).get(); |
|||
} |
|||
} |
|||
|
|||
} |
|||
@ -0,0 +1,41 @@ |
|||
/** |
|||
* Copyright © 2016-2022 The Thingsboard Authors |
|||
* |
|||
* Licensed under the Apache License, Version 2.0 (the "License"); |
|||
* you may not use this file except in compliance with the License. |
|||
* You may obtain a copy of the License at |
|||
* |
|||
* http://www.apache.org/licenses/LICENSE-2.0
|
|||
* |
|||
* Unless required by applicable law or agreed to in writing, software |
|||
* distributed under the License is distributed on an "AS IS" BASIS, |
|||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
|||
* See the License for the specific language governing permissions and |
|||
* limitations under the License. |
|||
*/ |
|||
package org.thingsboard.server.service.security.auth.mfa.config; |
|||
|
|||
import org.thingsboard.server.common.data.User; |
|||
import org.thingsboard.server.common.data.exception.ThingsboardException; |
|||
import org.thingsboard.server.common.data.id.TenantId; |
|||
import org.thingsboard.server.common.data.id.UserId; |
|||
import org.thingsboard.server.service.security.auth.mfa.config.account.TwoFactorAuthAccountConfig; |
|||
|
|||
import java.util.Optional; |
|||
|
|||
public interface TwoFactorAuthConfigManager { |
|||
|
|||
boolean isTwoFaEnabled(User user); |
|||
|
|||
Optional<TwoFactorAuthAccountConfig> getTwoFaAccountConfig(TenantId tenantId, UserId userId); |
|||
|
|||
void saveTwoFaAccountConfig(TenantId tenantId, UserId userId, TwoFactorAuthAccountConfig accountConfig) throws ThingsboardException; |
|||
|
|||
void deleteTwoFaAccountConfig(TenantId tenantId, UserId userId); |
|||
|
|||
|
|||
Optional<TwoFactorAuthSettings> getTwoFaSettings(TenantId tenantId); |
|||
|
|||
void saveTwoFaSettings(TenantId tenantId, TwoFactorAuthSettings twoFactorAuthSettings); |
|||
|
|||
} |
|||
Loading…
Reference in new issue