20 changed files with 583 additions and 330 deletions
@ -0,0 +1,124 @@ |
|||||
|
/** |
||||
|
* Copyright © 2016-2022 The Thingsboard Authors |
||||
|
* |
||||
|
* Licensed under the Apache License, Version 2.0 (the "License"); |
||||
|
* you may not use this file except in compliance with the License. |
||||
|
* You may obtain a copy of the License at |
||||
|
* |
||||
|
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
* |
||||
|
* Unless required by applicable law or agreed to in writing, software |
||||
|
* distributed under the License is distributed on an "AS IS" BASIS, |
||||
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||||
|
* See the License for the specific language governing permissions and |
||||
|
* limitations under the License. |
||||
|
*/ |
||||
|
package org.thingsboard.server.controller; |
||||
|
|
||||
|
import com.google.zxing.BarcodeFormat; |
||||
|
import com.google.zxing.client.j2se.MatrixToImageWriter; |
||||
|
import com.google.zxing.common.BitMatrix; |
||||
|
import com.google.zxing.qrcode.QRCodeWriter; |
||||
|
import lombok.RequiredArgsConstructor; |
||||
|
import org.springframework.security.access.prepost.PreAuthorize; |
||||
|
import org.springframework.web.bind.annotation.DeleteMapping; |
||||
|
import org.springframework.web.bind.annotation.GetMapping; |
||||
|
import org.springframework.web.bind.annotation.PostMapping; |
||||
|
import org.springframework.web.bind.annotation.RequestBody; |
||||
|
import org.springframework.web.bind.annotation.RequestMapping; |
||||
|
import org.springframework.web.bind.annotation.RequestParam; |
||||
|
import org.springframework.web.bind.annotation.RestController; |
||||
|
import org.thingsboard.common.util.JacksonUtil; |
||||
|
import org.thingsboard.server.common.data.exception.ThingsboardErrorCode; |
||||
|
import org.thingsboard.server.common.data.exception.ThingsboardException; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthConfigManager; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthSettings; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.account.TotpTwoFactorAuthAccountConfig; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.account.TwoFactorAuthAccountConfig; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.provider.TwoFactorAuthProviderType; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.TwoFactorAuthService; |
||||
|
import org.thingsboard.server.service.security.model.SecurityUser; |
||||
|
|
||||
|
import javax.servlet.ServletOutputStream; |
||||
|
import javax.servlet.http.HttpServletResponse; |
||||
|
import javax.validation.Valid; |
||||
|
|
||||
|
@RestController |
||||
|
@RequestMapping("/api/2fa") |
||||
|
@RequiredArgsConstructor |
||||
|
public class TwoFactorAuthConfigController extends BaseController { |
||||
|
|
||||
|
private final TwoFactorAuthConfigManager twoFactorAuthConfigManager; |
||||
|
private final TwoFactorAuthService twoFactorAuthService; |
||||
|
|
||||
|
|
||||
|
@GetMapping("/account/config") |
||||
|
@PreAuthorize("isAuthenticated()") |
||||
|
public TwoFactorAuthAccountConfig getTwoFaAccountConfig() throws ThingsboardException { |
||||
|
SecurityUser user = getCurrentUser(); |
||||
|
return twoFactorAuthConfigManager.getTwoFaAccountConfig(user.getTenantId(), user.getId()).orElse(null); |
||||
|
} |
||||
|
|
||||
|
@PostMapping("/account/config/generate") |
||||
|
@PreAuthorize("isAuthenticated()") |
||||
|
public TwoFactorAuthAccountConfig generateTwoFaAccountConfig(@RequestParam TwoFactorAuthProviderType providerType) throws Exception { |
||||
|
SecurityUser user = getCurrentUser(); |
||||
|
return twoFactorAuthService.generateNewAccountConfig(user, providerType); |
||||
|
} |
||||
|
|
||||
|
/* TMP */ |
||||
|
@PostMapping("/account/config/generate/qr") |
||||
|
@PreAuthorize("isAuthenticated()") |
||||
|
public void generateTwoFaAccountConfigWithQr(@RequestParam TwoFactorAuthProviderType providerType, HttpServletResponse response) throws Exception { |
||||
|
TwoFactorAuthAccountConfig config = generateTwoFaAccountConfig(providerType); |
||||
|
if (providerType == TwoFactorAuthProviderType.TOTP) { |
||||
|
BitMatrix qr = new QRCodeWriter().encode(((TotpTwoFactorAuthAccountConfig) config).getAuthUrl(), BarcodeFormat.QR_CODE, 200, 200); |
||||
|
try (ServletOutputStream outputStream = response.getOutputStream()) { |
||||
|
MatrixToImageWriter.writeToStream(qr, "PNG", outputStream); |
||||
|
} |
||||
|
} |
||||
|
response.setHeader("config", JacksonUtil.toString(config)); |
||||
|
} |
||||
|
/* TMP */ |
||||
|
|
||||
|
@PostMapping("/account/config/submit") |
||||
|
@PreAuthorize("isAuthenticated()") |
||||
|
public void submitTwoFaAccountConfig(@Valid @RequestBody TwoFactorAuthAccountConfig accountConfig) throws Exception { |
||||
|
SecurityUser user = getCurrentUser(); |
||||
|
twoFactorAuthService.prepareVerificationCode(user, accountConfig, false); |
||||
|
} |
||||
|
|
||||
|
@PostMapping("/account/config") |
||||
|
@PreAuthorize("isAuthenticated()") |
||||
|
public void verifyAndSaveTwoFaAccountConfig(@Valid @RequestBody TwoFactorAuthAccountConfig accountConfig, |
||||
|
@RequestParam String verificationCode) throws Exception { |
||||
|
SecurityUser user = getCurrentUser(); |
||||
|
boolean verificationSuccess = twoFactorAuthService.checkVerificationCode(user, verificationCode, accountConfig, false); |
||||
|
if (verificationSuccess) { |
||||
|
twoFactorAuthConfigManager.saveTwoFaAccountConfig(user.getTenantId(), user.getId(), accountConfig); |
||||
|
} else { |
||||
|
throw new ThingsboardException("Verification code is incorrect", ThingsboardErrorCode.INVALID_ARGUMENTS); |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
@DeleteMapping("/account/config") |
||||
|
@PreAuthorize("isAuthenticated()") |
||||
|
public void deleteTwoFactorAuthAccountConfig() throws ThingsboardException { |
||||
|
SecurityUser user = getCurrentUser(); |
||||
|
twoFactorAuthConfigManager.deleteTwoFaAccountConfig(user.getTenantId(), user.getId()); |
||||
|
} |
||||
|
|
||||
|
|
||||
|
@GetMapping("/settings") |
||||
|
@PreAuthorize("hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')") |
||||
|
public TwoFactorAuthSettings getTwoFactorAuthSettings() throws ThingsboardException { |
||||
|
return twoFactorAuthConfigManager.getTwoFaSettings(getTenantId()).orElse(null); |
||||
|
} |
||||
|
|
||||
|
@PostMapping("/settings") |
||||
|
@PreAuthorize("hasAnyAuthority('SYS_ADMIN', 'TENANT_ADMIN')") |
||||
|
public void saveTwoFactorAuthSettings(@RequestBody TwoFactorAuthSettings twoFactorAuthSettings) throws ThingsboardException { |
||||
|
twoFactorAuthConfigManager.saveTwoFaSettings(getTenantId(), twoFactorAuthSettings); |
||||
|
} |
||||
|
|
||||
|
} |
||||
@ -0,0 +1,151 @@ |
|||||
|
/** |
||||
|
* Copyright © 2016-2022 The Thingsboard Authors |
||||
|
* |
||||
|
* Licensed under the Apache License, Version 2.0 (the "License"); |
||||
|
* you may not use this file except in compliance with the License. |
||||
|
* You may obtain a copy of the License at |
||||
|
* |
||||
|
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
* |
||||
|
* Unless required by applicable law or agreed to in writing, software |
||||
|
* distributed under the License is distributed on an "AS IS" BASIS, |
||||
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||||
|
* See the License for the specific language governing permissions and |
||||
|
* limitations under the License. |
||||
|
*/ |
||||
|
package org.thingsboard.server.service.security.auth.mfa; |
||||
|
|
||||
|
import lombok.RequiredArgsConstructor; |
||||
|
import org.springframework.beans.factory.annotation.Autowired; |
||||
|
import org.springframework.stereotype.Service; |
||||
|
import org.thingsboard.server.common.data.StringUtils; |
||||
|
import org.thingsboard.server.common.data.User; |
||||
|
import org.thingsboard.server.common.data.exception.ThingsboardErrorCode; |
||||
|
import org.thingsboard.server.common.data.exception.ThingsboardException; |
||||
|
import org.thingsboard.server.common.data.id.TenantId; |
||||
|
import org.thingsboard.server.common.msg.tools.TbRateLimits; |
||||
|
import org.thingsboard.server.dao.user.UserService; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthConfigManager; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.TwoFactorAuthSettings; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.account.TwoFactorAuthAccountConfig; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.provider.TwoFactorAuthProviderConfig; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.provider.TwoFactorAuthProvider; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.provider.TwoFactorAuthProviderType; |
||||
|
import org.thingsboard.server.service.security.model.SecurityUser; |
||||
|
import org.thingsboard.server.service.security.system.SystemSecurityService; |
||||
|
|
||||
|
import java.util.Collection; |
||||
|
import java.util.EnumMap; |
||||
|
import java.util.Map; |
||||
|
import java.util.Optional; |
||||
|
import java.util.concurrent.ConcurrentHashMap; |
||||
|
import java.util.concurrent.ConcurrentMap; |
||||
|
|
||||
|
@Service |
||||
|
@RequiredArgsConstructor |
||||
|
public class DefaultTwoFactorAuthService implements TwoFactorAuthService { |
||||
|
|
||||
|
private final TwoFactorAuthConfigManager configManager; |
||||
|
private final SystemSecurityService systemSecurityService; |
||||
|
private final UserService userService; |
||||
|
private final Map<TwoFactorAuthProviderType, TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>> providers = new EnumMap<>(TwoFactorAuthProviderType.class); |
||||
|
|
||||
|
// FIXME [viacheslav]: remove from the map
|
||||
|
// TODO [viacheslav]: these rate limits are local, and will work bad in the cluster
|
||||
|
private final ConcurrentMap<String, TbRateLimits> verificationCodeSendingRateLimits = new ConcurrentHashMap<>(); |
||||
|
private final ConcurrentMap<String, TbRateLimits> verificationCodeCheckingRateLimits = new ConcurrentHashMap<>(); |
||||
|
|
||||
|
private static final ThingsboardException ACCOUNT_NOT_CONFIGURED = new ThingsboardException("2FA is not configured for account", ThingsboardErrorCode.BAD_REQUEST_PARAMS); |
||||
|
private static final ThingsboardException PROVIDER_NOT_CONFIGURED = new ThingsboardException("2FA provider is not configured", ThingsboardErrorCode.BAD_REQUEST_PARAMS); |
||||
|
private static final ThingsboardException PROVIDER_NOT_AVAILABLE = new ThingsboardException("2FA provider is not available", ThingsboardErrorCode.GENERAL); |
||||
|
|
||||
|
|
||||
|
@Override |
||||
|
public void prepareVerificationCode(SecurityUser securityUser, boolean rateLimit) throws Exception { |
||||
|
TwoFactorAuthAccountConfig accountConfig = configManager.getTwoFaAccountConfig(securityUser.getTenantId(), securityUser.getId()) |
||||
|
.orElseThrow(() -> ACCOUNT_NOT_CONFIGURED); |
||||
|
prepareVerificationCode(securityUser, accountConfig, rateLimit); |
||||
|
} |
||||
|
|
||||
|
@Override |
||||
|
public void prepareVerificationCode(SecurityUser securityUser, TwoFactorAuthAccountConfig accountConfig, boolean rateLimit) throws ThingsboardException { |
||||
|
TwoFactorAuthSettings twoFaSettings = configManager.getTwoFaSettings(securityUser.getTenantId()) |
||||
|
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
||||
|
if (rateLimit) { |
||||
|
if (StringUtils.isNotEmpty(twoFaSettings.getVerificationCodeSendRateLimit())) { |
||||
|
TbRateLimits rateLimits = verificationCodeSendingRateLimits.computeIfAbsent(securityUser.getSessionId(), sessionId -> { |
||||
|
return new TbRateLimits(twoFaSettings.getVerificationCodeSendRateLimit()); |
||||
|
}); |
||||
|
if (!rateLimits.tryConsume()) { |
||||
|
throw new ThingsboardException("Too many verification code sending requests", ThingsboardErrorCode.TOO_MANY_REQUESTS); |
||||
|
} |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
TwoFactorAuthProviderConfig providerConfig = twoFaSettings.getProviderConfig(accountConfig.getProviderType()) |
||||
|
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
||||
|
getTwoFaProvider(accountConfig.getProviderType()).prepareVerificationCode(securityUser, providerConfig, accountConfig); |
||||
|
} |
||||
|
|
||||
|
@Override |
||||
|
public boolean checkVerificationCode(SecurityUser securityUser, String verificationCode, boolean rateLimit) throws ThingsboardException { |
||||
|
TwoFactorAuthAccountConfig accountConfig = configManager.getTwoFaAccountConfig(securityUser.getTenantId(), securityUser.getId()) |
||||
|
.orElseThrow(() -> ACCOUNT_NOT_CONFIGURED); |
||||
|
return checkVerificationCode(securityUser, verificationCode, accountConfig, rateLimit); |
||||
|
} |
||||
|
|
||||
|
@Override |
||||
|
public boolean checkVerificationCode(SecurityUser securityUser, String verificationCode, TwoFactorAuthAccountConfig accountConfig, boolean rateLimit) throws ThingsboardException { |
||||
|
if (!userService.findUserCredentialsByUserId(securityUser.getTenantId(), securityUser.getId()).isEnabled()) { |
||||
|
throw new ThingsboardException("User is disabled", ThingsboardErrorCode.AUTHENTICATION); |
||||
|
} |
||||
|
|
||||
|
TwoFactorAuthSettings twoFaSettings = configManager.getTwoFaSettings(securityUser.getTenantId()) |
||||
|
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
||||
|
if (rateLimit) { |
||||
|
if (StringUtils.isNotEmpty(twoFaSettings.getVerificationCodeCheckRateLimit())) { |
||||
|
TbRateLimits rateLimits = verificationCodeCheckingRateLimits.computeIfAbsent(securityUser.getSessionId(), sessionId -> { |
||||
|
return new TbRateLimits(twoFaSettings.getVerificationCodeCheckRateLimit()); |
||||
|
}); |
||||
|
if (!rateLimits.tryConsume()) { |
||||
|
throw new ThingsboardException("Too many verification code checking requests", ThingsboardErrorCode.TOO_MANY_REQUESTS); |
||||
|
} |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
TwoFactorAuthProviderConfig providerConfig = twoFaSettings.getProviderConfig(accountConfig.getProviderType()) |
||||
|
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
||||
|
boolean verificationSuccess = getTwoFaProvider(accountConfig.getProviderType()).checkVerificationCode(securityUser, verificationCode, providerConfig, accountConfig); |
||||
|
if (rateLimit) { |
||||
|
systemSecurityService.validateTwoFaVerification(securityUser.getTenantId(), securityUser.getId(), verificationSuccess, twoFaSettings); |
||||
|
} |
||||
|
return verificationSuccess; |
||||
|
} |
||||
|
|
||||
|
@Override |
||||
|
public TwoFactorAuthAccountConfig generateNewAccountConfig(User user, TwoFactorAuthProviderType providerType) throws ThingsboardException { |
||||
|
TwoFactorAuthProviderConfig providerConfig = getTwoFaProviderConfig(user.getTenantId(), providerType); |
||||
|
return getTwoFaProvider(providerType).generateNewAccountConfig(user, providerConfig); |
||||
|
} |
||||
|
|
||||
|
|
||||
|
private TwoFactorAuthProviderConfig getTwoFaProviderConfig(TenantId tenantId, TwoFactorAuthProviderType providerType) throws ThingsboardException { |
||||
|
return configManager.getTwoFaSettings(tenantId) |
||||
|
.flatMap(twoFaSettings -> twoFaSettings.getProviderConfig(providerType)) |
||||
|
.orElseThrow(() -> PROVIDER_NOT_CONFIGURED); |
||||
|
} |
||||
|
|
||||
|
private TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig> getTwoFaProvider(TwoFactorAuthProviderType providerType) throws ThingsboardException { |
||||
|
return Optional.ofNullable(providers.get(providerType)) |
||||
|
.orElseThrow(() -> PROVIDER_NOT_AVAILABLE); |
||||
|
} |
||||
|
|
||||
|
@Autowired |
||||
|
private void setProviders(Collection<TwoFactorAuthProvider<TwoFactorAuthProviderConfig, TwoFactorAuthAccountConfig>> providers) { |
||||
|
providers.forEach(provider -> { |
||||
|
this.providers.put(provider.getType(), provider); |
||||
|
}); |
||||
|
} |
||||
|
|
||||
|
} |
||||
|
|
||||
@ -0,0 +1,139 @@ |
|||||
|
/** |
||||
|
* Copyright © 2016-2022 The Thingsboard Authors |
||||
|
* |
||||
|
* Licensed under the Apache License, Version 2.0 (the "License"); |
||||
|
* you may not use this file except in compliance with the License. |
||||
|
* You may obtain a copy of the License at |
||||
|
* |
||||
|
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
* |
||||
|
* Unless required by applicable law or agreed to in writing, software |
||||
|
* distributed under the License is distributed on an "AS IS" BASIS, |
||||
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||||
|
* See the License for the specific language governing permissions and |
||||
|
* limitations under the License. |
||||
|
*/ |
||||
|
package org.thingsboard.server.service.security.auth.mfa.config; |
||||
|
|
||||
|
import com.fasterxml.jackson.databind.node.ObjectNode; |
||||
|
import lombok.RequiredArgsConstructor; |
||||
|
import lombok.SneakyThrows; |
||||
|
import org.springframework.stereotype.Service; |
||||
|
import org.thingsboard.common.util.JacksonUtil; |
||||
|
import org.thingsboard.server.common.data.AdminSettings; |
||||
|
import org.thingsboard.server.common.data.DataConstants; |
||||
|
import org.thingsboard.server.common.data.User; |
||||
|
import org.thingsboard.server.common.data.exception.ThingsboardErrorCode; |
||||
|
import org.thingsboard.server.common.data.exception.ThingsboardException; |
||||
|
import org.thingsboard.server.common.data.id.TenantId; |
||||
|
import org.thingsboard.server.common.data.id.UserId; |
||||
|
import org.thingsboard.server.common.data.kv.BaseAttributeKvEntry; |
||||
|
import org.thingsboard.server.common.data.kv.JsonDataEntry; |
||||
|
import org.thingsboard.server.dao.attributes.AttributesService; |
||||
|
import org.thingsboard.server.dao.service.ConstraintValidator; |
||||
|
import org.thingsboard.server.dao.settings.AdminSettingsService; |
||||
|
import org.thingsboard.server.dao.user.UserService; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.account.TwoFactorAuthAccountConfig; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.provider.TwoFactorAuthProviderConfig; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.provider.TwoFactorAuthProviderType; |
||||
|
|
||||
|
import java.util.Collections; |
||||
|
import java.util.Optional; |
||||
|
import java.util.concurrent.ExecutionException; |
||||
|
|
||||
|
@Service |
||||
|
@RequiredArgsConstructor |
||||
|
public class DefaultTwoFactorAuthConfigManager implements TwoFactorAuthConfigManager { |
||||
|
|
||||
|
private final UserService userService; |
||||
|
private final AdminSettingsService adminSettingsService; |
||||
|
private final AttributesService attributesService; |
||||
|
|
||||
|
protected static final String TWO_FACTOR_AUTH_ACCOUNT_CONFIG_KEY = "twoFaConfig"; |
||||
|
protected static final String TWO_FACTOR_AUTH_SETTINGS_KEY = "twoFaSettings"; |
||||
|
|
||||
|
|
||||
|
@Override |
||||
|
public boolean isTwoFaEnabled(User user) { |
||||
|
return getTwoFaAccountConfig(user.getTenantId(), user.getId()).isPresent(); |
||||
|
} |
||||
|
|
||||
|
@Override |
||||
|
public Optional<TwoFactorAuthAccountConfig> getTwoFaAccountConfig(TenantId tenantId, UserId userId) { |
||||
|
User user = userService.findUserById(tenantId, userId); |
||||
|
return Optional.ofNullable(user.getAdditionalInfo()) |
||||
|
.flatMap(additionalInfo -> Optional.ofNullable(additionalInfo.get(TWO_FACTOR_AUTH_ACCOUNT_CONFIG_KEY)).filter(jsonNode -> !jsonNode.isNull())) |
||||
|
.map(jsonNode -> JacksonUtil.treeToValue(jsonNode, TwoFactorAuthAccountConfig.class)) |
||||
|
.filter(twoFactorAuthAccountConfig -> { |
||||
|
return getTwoFaProviderConfig(tenantId, twoFactorAuthAccountConfig.getProviderType()).isPresent(); |
||||
|
}); |
||||
|
} |
||||
|
|
||||
|
@Override |
||||
|
public void saveTwoFaAccountConfig(TenantId tenantId, UserId userId, TwoFactorAuthAccountConfig accountConfig) throws ThingsboardException { |
||||
|
getTwoFaProviderConfig(tenantId, accountConfig.getProviderType()) |
||||
|
.orElseThrow(() -> new ThingsboardException("2FA provider is not configured", ThingsboardErrorCode.BAD_REQUEST_PARAMS)); |
||||
|
|
||||
|
User user = userService.findUserById(tenantId, userId); |
||||
|
ObjectNode additionalInfo = (ObjectNode) Optional.ofNullable(user.getAdditionalInfo()) |
||||
|
.orElseGet(JacksonUtil::newObjectNode); |
||||
|
additionalInfo.set(TWO_FACTOR_AUTH_ACCOUNT_CONFIG_KEY, JacksonUtil.valueToTree(accountConfig)); |
||||
|
user.setAdditionalInfo(additionalInfo); |
||||
|
|
||||
|
userService.saveUser(user); |
||||
|
} |
||||
|
|
||||
|
@Override |
||||
|
public void deleteTwoFaAccountConfig(TenantId tenantId, UserId userId) { |
||||
|
User user = userService.findUserById(tenantId, userId); |
||||
|
ObjectNode additionalInfo = (ObjectNode) Optional.ofNullable(user.getAdditionalInfo()) |
||||
|
.orElseGet(JacksonUtil::newObjectNode); |
||||
|
additionalInfo.remove(TWO_FACTOR_AUTH_ACCOUNT_CONFIG_KEY); |
||||
|
user.setAdditionalInfo(additionalInfo); |
||||
|
|
||||
|
userService.saveUser(user); |
||||
|
} |
||||
|
|
||||
|
|
||||
|
private Optional<TwoFactorAuthProviderConfig> getTwoFaProviderConfig(TenantId tenantId, TwoFactorAuthProviderType providerType) { |
||||
|
return getTwoFaSettings(tenantId) |
||||
|
.flatMap(twoFaSettings -> twoFaSettings.getProviderConfig(providerType)); |
||||
|
} |
||||
|
|
||||
|
@SneakyThrows({InterruptedException.class, ExecutionException.class}) |
||||
|
@Override |
||||
|
public Optional<TwoFactorAuthSettings> getTwoFaSettings(TenantId tenantId) { |
||||
|
if (tenantId.equals(TenantId.SYS_TENANT_ID)) { |
||||
|
return Optional.ofNullable(adminSettingsService.findAdminSettingsByKey(tenantId, TWO_FACTOR_AUTH_SETTINGS_KEY)) |
||||
|
.map(adminSettings -> JacksonUtil.treeToValue(adminSettings.getJsonValue(), TwoFactorAuthSettings.class)); |
||||
|
} else { |
||||
|
return attributesService.find(TenantId.SYS_TENANT_ID, tenantId, DataConstants.SERVER_SCOPE, TWO_FACTOR_AUTH_SETTINGS_KEY).get() |
||||
|
.map(adminSettingsAttribute -> JacksonUtil.fromString(adminSettingsAttribute.getJsonValue().get(), TwoFactorAuthSettings.class)) |
||||
|
.filter(tenantTwoFactorAuthSettings -> !tenantTwoFactorAuthSettings.isUseSystemTwoFactorAuthSettings()) |
||||
|
.or(() -> getTwoFaSettings(TenantId.SYS_TENANT_ID)); |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
@SneakyThrows({InterruptedException.class, ExecutionException.class}) |
||||
|
@Override |
||||
|
public void saveTwoFaSettings(TenantId tenantId, TwoFactorAuthSettings twoFactorAuthSettings) { |
||||
|
if (tenantId.equals(TenantId.SYS_TENANT_ID) || !twoFactorAuthSettings.isUseSystemTwoFactorAuthSettings()) { |
||||
|
ConstraintValidator.validateFields(twoFactorAuthSettings); |
||||
|
} |
||||
|
if (tenantId.equals(TenantId.SYS_TENANT_ID)) { |
||||
|
AdminSettings settings = Optional.ofNullable(adminSettingsService.findAdminSettingsByKey(tenantId, TWO_FACTOR_AUTH_SETTINGS_KEY)) |
||||
|
.orElseGet(() -> { |
||||
|
AdminSettings newSettings = new AdminSettings(); |
||||
|
newSettings.setKey(TWO_FACTOR_AUTH_SETTINGS_KEY); |
||||
|
return newSettings; |
||||
|
}); |
||||
|
settings.setJsonValue(JacksonUtil.valueToTree(twoFactorAuthSettings)); |
||||
|
adminSettingsService.saveAdminSettings(tenantId, settings); |
||||
|
} else { |
||||
|
attributesService.save(TenantId.SYS_TENANT_ID, tenantId, DataConstants.SERVER_SCOPE, Collections.singletonList( |
||||
|
new BaseAttributeKvEntry(new JsonDataEntry(TWO_FACTOR_AUTH_SETTINGS_KEY, JacksonUtil.toString(twoFactorAuthSettings)), System.currentTimeMillis()) |
||||
|
)).get(); |
||||
|
} |
||||
|
} |
||||
|
|
||||
|
} |
||||
@ -0,0 +1,41 @@ |
|||||
|
/** |
||||
|
* Copyright © 2016-2022 The Thingsboard Authors |
||||
|
* |
||||
|
* Licensed under the Apache License, Version 2.0 (the "License"); |
||||
|
* you may not use this file except in compliance with the License. |
||||
|
* You may obtain a copy of the License at |
||||
|
* |
||||
|
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
* |
||||
|
* Unless required by applicable law or agreed to in writing, software |
||||
|
* distributed under the License is distributed on an "AS IS" BASIS, |
||||
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||||
|
* See the License for the specific language governing permissions and |
||||
|
* limitations under the License. |
||||
|
*/ |
||||
|
package org.thingsboard.server.service.security.auth.mfa.config; |
||||
|
|
||||
|
import org.thingsboard.server.common.data.User; |
||||
|
import org.thingsboard.server.common.data.exception.ThingsboardException; |
||||
|
import org.thingsboard.server.common.data.id.TenantId; |
||||
|
import org.thingsboard.server.common.data.id.UserId; |
||||
|
import org.thingsboard.server.service.security.auth.mfa.config.account.TwoFactorAuthAccountConfig; |
||||
|
|
||||
|
import java.util.Optional; |
||||
|
|
||||
|
public interface TwoFactorAuthConfigManager { |
||||
|
|
||||
|
boolean isTwoFaEnabled(User user); |
||||
|
|
||||
|
Optional<TwoFactorAuthAccountConfig> getTwoFaAccountConfig(TenantId tenantId, UserId userId); |
||||
|
|
||||
|
void saveTwoFaAccountConfig(TenantId tenantId, UserId userId, TwoFactorAuthAccountConfig accountConfig) throws ThingsboardException; |
||||
|
|
||||
|
void deleteTwoFaAccountConfig(TenantId tenantId, UserId userId); |
||||
|
|
||||
|
|
||||
|
Optional<TwoFactorAuthSettings> getTwoFaSettings(TenantId tenantId); |
||||
|
|
||||
|
void saveTwoFaSettings(TenantId tenantId, TwoFactorAuthSettings twoFactorAuthSettings); |
||||
|
|
||||
|
} |
||||
Loading…
Reference in new issue