2017-10-21 21:10:33 -04:00
|
|
|
"use strict";
|
|
|
|
|
2017-10-15 19:47:05 -04:00
|
|
|
const utils = require('../services/utils');
|
2018-04-01 21:27:46 -04:00
|
|
|
const optionService = require('../services/options');
|
|
|
|
const myScryptService = require('../services/my_scrypt');
|
2021-04-19 21:41:29 +02:00
|
|
|
const log = require('../services/log');
|
2021-12-29 23:37:12 +01:00
|
|
|
const sqlInit = require("../services/sql_init.js");
|
|
|
|
const optionsInitService = require("../services/options_init.js");
|
2017-10-15 16:32:49 -04:00
|
|
|
|
2018-03-30 19:31:22 -04:00
|
|
|
function loginPage(req, res) {
|
|
|
|
res.render('login', { failedAuth: false });
|
|
|
|
}
|
2017-10-15 16:32:49 -04:00
|
|
|
|
2021-12-29 23:19:05 +01:00
|
|
|
function setPasswordPage(req, res) {
|
2021-12-29 23:37:12 +01:00
|
|
|
res.render('set_password', { error: false });
|
2021-12-29 23:19:05 +01:00
|
|
|
}
|
|
|
|
|
2021-12-29 23:37:12 +01:00
|
|
|
function setPassword(req, res) {
|
|
|
|
if (sqlInit.isPasswordSet()) {
|
|
|
|
return [400, "Password has been already set"];
|
|
|
|
}
|
|
|
|
|
|
|
|
let {password1, password2} = req.body;
|
|
|
|
password1 = password1.trim();
|
|
|
|
password2 = password2.trim();
|
|
|
|
|
|
|
|
let error;
|
|
|
|
|
|
|
|
if (password1 !== password2) {
|
|
|
|
error = "Entered passwords don't match.";
|
|
|
|
} else if (password1.length < 4) {
|
|
|
|
error = "Password must be at least 4 characters long.";
|
|
|
|
}
|
2017-10-15 16:32:49 -04:00
|
|
|
|
2021-12-29 23:37:12 +01:00
|
|
|
if (error) {
|
|
|
|
res.render('set_password', { error });
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
optionsInitService.initPassword(password1);
|
|
|
|
|
|
|
|
res.redirect('login');
|
|
|
|
}
|
|
|
|
|
|
|
|
function login(req, res) {
|
2017-10-15 16:32:49 -04:00
|
|
|
const guessedPassword = req.body.password;
|
|
|
|
|
2021-12-29 23:37:12 +01:00
|
|
|
if (verifyPassword(guessedPassword)) {
|
2017-10-16 19:14:15 -04:00
|
|
|
const rememberMe = req.body.remember_me;
|
2017-10-15 16:32:49 -04:00
|
|
|
|
2017-10-15 20:16:30 -04:00
|
|
|
req.session.regenerate(() => {
|
2017-10-16 19:14:15 -04:00
|
|
|
if (rememberMe) {
|
|
|
|
req.session.cookie.maxAge = 21 * 24 * 3600000; // 3 weeks
|
|
|
|
} else {
|
|
|
|
req.session.cookie.expires = false;
|
|
|
|
}
|
|
|
|
|
2017-10-15 20:16:30 -04:00
|
|
|
req.session.loggedIn = true;
|
2019-05-22 21:25:13 +02:00
|
|
|
res.redirect('.');
|
2017-10-15 20:16:30 -04:00
|
|
|
});
|
2017-10-15 16:32:49 -04:00
|
|
|
}
|
|
|
|
else {
|
2021-04-19 21:41:29 +02:00
|
|
|
// note that logged IP address is usually meaningless since the traffic should come from a reverse proxy
|
2021-12-29 23:37:12 +01:00
|
|
|
log.info(`WARNING: Wrong password from ${req.ip}, rejecting.`);
|
2021-04-19 21:41:29 +02:00
|
|
|
|
2017-10-15 16:32:49 -04:00
|
|
|
res.render('login', {'failedAuth': true});
|
|
|
|
}
|
2018-03-30 19:31:22 -04:00
|
|
|
}
|
2017-10-15 16:32:49 -04:00
|
|
|
|
2020-06-20 12:31:38 +02:00
|
|
|
function verifyPassword(guessedPassword) {
|
|
|
|
const hashed_password = utils.fromBase64(optionService.getOption('passwordVerificationHash'));
|
2017-10-15 16:32:49 -04:00
|
|
|
|
2020-06-20 12:31:38 +02:00
|
|
|
const guess_hashed = myScryptService.getVerificationHash(guessedPassword);
|
2017-10-15 16:32:49 -04:00
|
|
|
|
|
|
|
return guess_hashed.equals(hashed_password);
|
|
|
|
}
|
|
|
|
|
2018-03-30 19:31:22 -04:00
|
|
|
function logout(req, res) {
|
|
|
|
req.session.regenerate(() => {
|
|
|
|
req.session.loggedIn = false;
|
|
|
|
|
2019-04-11 22:04:36 +02:00
|
|
|
res.redirect('login');
|
2018-03-30 19:31:22 -04:00
|
|
|
});
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
module.exports = {
|
|
|
|
loginPage,
|
2021-12-29 23:19:05 +01:00
|
|
|
setPasswordPage,
|
2021-12-29 23:37:12 +01:00
|
|
|
setPassword,
|
2018-03-30 19:31:22 -04:00
|
|
|
login,
|
|
|
|
logout
|
|
|
|
};
|