diff --git a/src/auth/auth.cpp b/src/auth/auth.cpp index 85c4136..41f04df 100644 --- a/src/auth/auth.cpp +++ b/src/auth/auth.cpp @@ -1,11 +1,12 @@ #include "auth.hpp" +// function for authorization users void auth(const httplib::Request& request, httplib::Response& response) { - if (request.body == "") {response.set_content("{\"needed\":\"[uername,password]\"}", "application/json");return;} + if (request.body == "") {response.set_content("{\"needed\":\"[username,password]\"}", "application/json");return;} nlohmann::json json_body = nlohmann::json::parse(request.body); - if (json_body["username"] == nullptr) {response.set_content("{\"needed\":\"[uername,password]\"}", "application/json");return;} - if (json_body["password"] == nullptr) {response.set_content("{\"needed\":\"[uername,password]\"}", "application/json");return;} + if (json_body["username"] == nullptr) {response.set_content("{\"needed\":\"[username,password]\"}", "application/json");return;} + if (json_body["password"] == nullptr) {response.set_content("{\"needed\":\"[username,password]\"}", "application/json");return;} const std::string request_username = json_body["username"]; const std::string request_password = json_body["password"]; @@ -13,19 +14,20 @@ void auth(const httplib::Request& request, httplib::Response& response) { nlohmann::json all_users = nlohmann::json::parse(usersfile); usersfile.close(); - int userid = -1; + std::string userid = ""; for (int i = 0; i < all_users.size(); i++) { if ((all_users[i]["username"] == request_username) && (all_users[i]["password"] == request_password)) { userid = all_users[i]["id"]; + break; } } - if (userid == -1) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} auto token = jwt::create() .set_type("JWT") - // .set_issuer("auth0") - .set_payload_claim("userId", jwt::claim(std::to_string(userid))) + .set_issuer("auth0") + .set_payload_claim("userId", jwt::claim(userid)) .sign(jwt::algorithm::hs256{JWT_SECRET_KEY}); std::stringstream response_json; @@ -33,6 +35,25 @@ void auth(const httplib::Request& request, httplib::Response& response) { response.set_content(response_json.str(), "application/json"); } +// function for verify tokens bool verify_auth(const std::string token) { - return true; + try { + // parse token + const auto decoded = jwt::decode(token); + + // validate token + const auto verifier = jwt::verify() + .allow_algorithm(jwt::algorithm::hs256{JWT_SECRET_KEY}) + .with_issuer("auth0"); + + verifier.verify(decoded); + return true; + } + catch (const std::system_error& e) { + std::cout << "Verification error: " << e.what() << std::endl; + return false; + } + catch (...) { + return false; + } } diff --git a/src/auth/auth.hpp b/src/auth/auth.hpp index 422013a..a8a3429 100644 --- a/src/auth/auth.hpp +++ b/src/auth/auth.hpp @@ -9,7 +9,9 @@ #include "../includes.hpp" #include +// function for authorization users void auth(const httplib::Request& request, httplib::Response& response); +// function for verify tokens bool verify_auth(const std::string token); #endif // AUTH_HPP diff --git a/src/auth_service.cpp b/src/auth_service.cpp index 3e01d3a..de44dc8 100644 --- a/src/auth_service.cpp +++ b/src/auth_service.cpp @@ -5,18 +5,19 @@ #include #include "auth/auth.hpp" +#include "users/users.hpp" int main() { httplib::Server srv; srv.Post("/api/token", auth); - - srv.Get("/api/users", [](const httplib::Request& request, httplib::Response& response) { - std::ifstream usersfile("users.json"); - nlohmann::json usersdata = nlohmann::json::parse(usersfile); - usersfile.close(); - response.set_content(usersdata.dump(), "application/json"); - }); + srv.Post("/api/user", get_user); + srv.Post("/api/users/all", get_all_users); + // srv.Post("/api/adduser", add_user); + // srv.Post("/api/changepassword", change_password); + // srv.Post("/api/deluser", del_user); + // srv.Post("/api/deluserassuperuser", del_user_as_superuser); + srv.Post("/api/access", user_access); srv.listen("localhost", 43243); return 0; diff --git a/src/includes.hpp b/src/includes.hpp index 7e70284..1d48df6 100644 --- a/src/includes.hpp +++ b/src/includes.hpp @@ -1 +1,6 @@ -#define JWT_SECRET_KEY "secret" \ No newline at end of file +#ifndef INCLUDES_HPP +#define INCLUDES_HPP + +#define JWT_SECRET_KEY "secret" + +#endif // INCLUDES_HPP \ No newline at end of file diff --git a/src/users/users.cpp b/src/users/users.cpp new file mode 100644 index 0000000..5968465 --- /dev/null +++ b/src/users/users.cpp @@ -0,0 +1,73 @@ +#include "users.hpp" + +// function for get user data without password +void get_user(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + auto decoded_token = jwt::decode(json_body["token"]); + std::string userid = ""; + for (auto& e : decoded_token.get_payload_json()) { + if (e.first == "userId") { + userid = e.second.to_str(); + break; + } + } + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + std::ifstream usersfile("users.json"); + nlohmann::json all_users = nlohmann::json::parse(usersfile); + usersfile.close(); + nlohmann::json response_user_data = nullptr; + for (auto& user : all_users) { + if (user["id"] == userid) { + response_user_data = user; + break; + } + } + if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + response_user_data.erase("password"); + response.set_content(response_user_data.dump(), "application/json"); +} + +// function for get all users data without password +void get_all_users(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + auto decoded_token = jwt::decode(json_body["token"]); + std::string userid = ""; + for (auto& e : decoded_token.get_payload_json()) { + if (e.first == "userId") { + userid = e.second.to_str(); + break; + } + } + if (userid == "") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + std::ifstream usersfile("users.json"); + nlohmann::json all_users = nlohmann::json::parse(usersfile); + usersfile.close(); + nlohmann::json response_user_data = nullptr; + for (auto& user : all_users) { + if (user["id"] == userid) { + response_user_data = user; + } + user.erase("password"); + } + if (response_user_data == nullptr) {response.set_content("{\"status\":\"403\"}", "application/json");return;} + if (response_user_data["is_superuser"] != "1") {response.set_content("{\"status\":\"403\"}", "application/json");return;} + response.set_content(all_users.dump(), "application/json"); +} + +// function for access or reject authorization +void user_access(const httplib::Request& request, httplib::Response& response) { + if (request.body == "") {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;} + nlohmann::json json_body = nlohmann::json::parse(request.body); + + if (json_body["token"] == nullptr) {response.set_content("{\"needed\":\"[token]\"}", "application/json");return;} + if (!verify_auth(json_body["token"])) {response.set_content("{\"access\":\"reject\"}", "application/json");return;} + response.set_content("{\"access\":\"success\"}", "application/json"); +} diff --git a/src/users/users.hpp b/src/users/users.hpp new file mode 100644 index 0000000..517cbcb --- /dev/null +++ b/src/users/users.hpp @@ -0,0 +1,15 @@ +#ifndef USERS_HPP +#define USERS_HPP + +#include +#include +#include "../auth/auth.hpp" + +// function for get user data without password +void get_user(const httplib::Request& request, httplib::Response& response); +// function for get all users data without password +void get_all_users(const httplib::Request& request, httplib::Response& response); +// function for access or reject authorization +void user_access(const httplib::Request& request, httplib::Response& response); + +#endif // USERS_HPP