diff --git a/CMakeLists.txt b/CMakeLists.txt index 062756e..4e13cd1 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -3,7 +3,7 @@ project(auth_service LANGUAGES C) set(CMAKE_C_STANDARD 23) set(CMAKE_EXPORT_COMPILE_COMMANDS ON) -set(CMAKE_C_FLAGS "-ffunction-sections -fdata-sections") +set(CMAKE_C_FLAGS "-ffunction-sections -fdata-sections -DMG_TLS=MG_TLS_OPENSSL") if (APPLE) elseif (UNIX) set(CMAKE_EXE_LINKER_FLAGS "-Wl,--gc-sections") diff --git a/config.json b/config.json index 5559e65..791254d 100644 --- a/config.json +++ b/config.json @@ -1,5 +1,5 @@ { - "database": "asdf.json", + "database": "db.json", "database_type": "file", "address": "0.0.0.0:8222", "tls_address": "0.0.0.0:8223", @@ -7,5 +7,6 @@ "web": "./web", "tls_enabled": true, "tls_cert": "/home/tola/certs/localhost/localhost.crt", - "tls_key": "/home/tola/certs/localhost/localhost.key" + "tls_key": "/home/tola/certs/localhost/localhost.key", + "jwt_secret": "secret" } diff --git a/meson.build b/meson.build index 028b0d6..d17f551 100644 --- a/meson.build +++ b/meson.build @@ -1,7 +1,7 @@ project('auth_service', 'c', default_options: ['c_std=gnu2x']) include_dirs = include_directories('src', 'src/lib') deps = [dependency('openssl')] -extra_c_args = ['-ffunction-sections', '-fdata-sections'] +extra_c_args = ['-ffunction-sections', '-fdata-sections', '-DMG_TLS=MG_TLS_OPENSSL'] extra_c_link_args = [] system = host_machine.system() if system == 'linux' diff --git a/src/api/add_user.c b/src/api/add_user.c index 8a740cd..c5cf3d9 100644 --- a/src/api/add_user.c +++ b/src/api/add_user.c @@ -1,10 +1,18 @@ #include "security/jwt.h" #include "user.h" #include "utils/utils.h" +#include "config/config.h" void add_user(struct mg_connection *c, struct mg_http_message *hm) { request_with_token *requestdata = check_body(hm); - const bool valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret"); + bool valid = false; + if (jwt_secret) { + printf("jwt_secret is not null %s\n", jwt_secret); + valid = jwt_verifyJWT(requestdata->token, jwt_secret); + } else { + valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + } if (!valid) { mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"), MG_ESC("invalid token")); diff --git a/src/api/change_password.c b/src/api/change_password.c index e373fef..96db19b 100644 --- a/src/api/change_password.c +++ b/src/api/change_password.c @@ -2,6 +2,7 @@ #include "security/jwt.h" #include "user.h" #include "utils/utils.h" +#include "config/config.h" void change_password(struct mg_connection *c, struct mg_http_message *hm) { if (hm->body.len == 0) { @@ -15,7 +16,14 @@ void change_password(struct mg_connection *c, struct mg_http_message *hm) { MG_ESC(requestdata->error)); return; } - const bool valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret"); + bool valid = false; + if (jwt_secret) { + printf("jwt_secret is not null %s\n", jwt_secret); + valid = jwt_verifyJWT(requestdata->token, jwt_secret); + } else { + valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + } if (!valid) { mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"), MG_ESC("invalid token")); diff --git a/src/api/change_user.c b/src/api/change_user.c index 8fc57b4..ba35fde 100644 --- a/src/api/change_user.c +++ b/src/api/change_user.c @@ -1,6 +1,7 @@ #include "security/jwt.h" #include "user.h" #include "utils/utils.h" +#include "config/config.h" void change_user(struct mg_connection *c, struct mg_http_message *hm) { if (hm->body.len == 0) { @@ -14,7 +15,14 @@ void change_user(struct mg_connection *c, struct mg_http_message *hm) { MG_ESC(requestdata->error)); return; } - const bool valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret"); + bool valid = false; + if (jwt_secret) { + printf("jwt_secret is not null %s\n", jwt_secret); + valid = jwt_verifyJWT(requestdata->token, jwt_secret); + } else { + valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + } if (!valid) { mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"), MG_ESC("invalid token")); diff --git a/src/api/delete_user.c b/src/api/delete_user.c index 811ff38..2a1b805 100644 --- a/src/api/delete_user.c +++ b/src/api/delete_user.c @@ -1,6 +1,7 @@ #include "security/jwt.h" #include "user.h" #include "utils/utils.h" +#include "config/config.h" void delete_user(struct mg_connection *c, struct mg_http_message *hm) { if (hm->body.len == 0) { @@ -14,7 +15,14 @@ void delete_user(struct mg_connection *c, struct mg_http_message *hm) { MG_ESC(requestdata->error)); return; } - const bool valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret"); + bool valid = false; + if (jwt_secret) { + printf("jwt_secret is not null %s\n", jwt_secret); + valid = jwt_verifyJWT(requestdata->token, jwt_secret); + } else { + valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + } if (!valid) { mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"), MG_ESC("invalid token")); diff --git a/src/api/get_all_users.c b/src/api/get_all_users.c index f48c733..d648307 100644 --- a/src/api/get_all_users.c +++ b/src/api/get_all_users.c @@ -1,6 +1,7 @@ #include "security/jwt.h" #include "user.h" #include "utils/utils.h" +#include "config/config.h" void get_all_users(struct mg_connection *c, struct mg_http_message *hm) { request_with_token *data = check_body(hm); @@ -9,7 +10,15 @@ void get_all_users(struct mg_connection *c, struct mg_http_message *hm) { MG_ESC(data->error)); return; } - if (!jwt_verifyJWT(data->token, JWT_DEFAULT_SECRET)) { + char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret"); + bool valid = false; + if (jwt_secret) { + printf("jwt_secret is not null %s\n", jwt_secret); + valid = jwt_verifyJWT(data->token, jwt_secret); + } else { + valid = jwt_verifyJWT(data->token, JWT_DEFAULT_SECRET); + } + if (!valid) { mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"), MG_ESC("invalid token")); return; diff --git a/src/api/get_token.c b/src/api/get_token.c index 8a2a7b9..0a3893d 100644 --- a/src/api/get_token.c +++ b/src/api/get_token.c @@ -1,5 +1,7 @@ +#include "config/ConfigManager.h" #include "security/jwt.h" #include "user.h" +#include "config/config.h" void get_token(struct mg_connection *c, struct mg_http_message *hm) { if (hm->body.len == 0) { @@ -41,9 +43,17 @@ void get_token(struct mg_connection *c, struct mg_http_message *hm) { "\"%s\",\"is_superuser\": %s}", db_user->id, db_user->username, db_user->email, db_user->group, db_user->is_superuser ? "true" : "false"); - char *token = jwt_createJWT(header, payload, JWT_DEFAULT_SECRET); + char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret"); + char *token = nullptr; + if (jwt_secret) { + printf("jwt_secret is not null %s\n", jwt_secret); + token = jwt_createJWT(header, payload, jwt_secret); + } else { + token = jwt_createJWT(header, payload, JWT_DEFAULT_SECRET); + } mg_http_reply(c, 200, HTTP_HEADERS, "{%m:%m}", MG_ESC("token"), MG_ESC(token)); free_user(db_user); free(token); + free(jwt_secret); } diff --git a/src/api/get_user.c b/src/api/get_user.c index d2b3e18..85d6d8b 100644 --- a/src/api/get_user.c +++ b/src/api/get_user.c @@ -1,6 +1,7 @@ #include "security/jwt.h" #include "user.h" #include "utils/utils.h" +#include "config/config.h" void get_user(struct mg_connection *c, struct mg_http_message *hm) { if (hm->body.len == 0) { @@ -14,7 +15,15 @@ void get_user(struct mg_connection *c, struct mg_http_message *hm) { MG_ESC(requestdata->error)); return; } - if (!jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET)) { + char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret"); + bool valid = false; + if (jwt_secret) { + printf("jwt_secret is not null %s\n", jwt_secret); + valid = jwt_verifyJWT(requestdata->token, jwt_secret); + } else { + valid = jwt_verifyJWT(requestdata->token, JWT_DEFAULT_SECRET); + } + if (!valid) { free_request_with_token(requestdata); mg_http_reply(c, 403, HTTP_HEADERS, "{%m:%m}", MG_ESC("error"), MG_ESC("invalid token")); diff --git a/src/api/verify_token.c b/src/api/verify_token.c index e3920e4..356a1ee 100644 --- a/src/api/verify_token.c +++ b/src/api/verify_token.c @@ -1,3 +1,5 @@ +#include "config/ConfigManager.h" +#include "config/config.h" #include "security/jwt.h" #include "user.h" #include "utils/utils.h" @@ -8,7 +10,14 @@ void verify_token(struct mg_connection *c, struct mg_http_message *hm) { mg_http_reply(c, 403, HTTP_HEADERS, "{%m:false}", MG_ESC("valid")); return; } - const bool valid = jwt_verifyJWT(data->token, JWT_DEFAULT_SECRET); + char *jwt_secret = cm_get_parameter_as_string(config, "jwt_secret"); + bool valid = false; + if (jwt_secret) { + printf("jwt_secret is not null %s\n", jwt_secret); + valid = jwt_verifyJWT(data->token, jwt_secret); + } else { + valid = jwt_verifyJWT(data->token, JWT_DEFAULT_SECRET); + } if (!valid) { mg_http_reply(c, 403, HTTP_HEADERS, "{%m:false}", MG_ESC("valid")); free_request_with_token(data); @@ -35,4 +44,5 @@ void verify_token(struct mg_connection *c, struct mg_http_message *hm) { free_request_with_token(data); free(username); free_user(user); + free(jwt_secret); } diff --git a/src/security/jwt.c b/src/security/jwt.c index ca56b1d..00f916d 100644 --- a/src/security/jwt.c +++ b/src/security/jwt.c @@ -7,7 +7,7 @@ #include // Удаляет символы '=' в конце строки (падинг) -static void remove_padding(const char *str) { +static void remove_padding(char *str) { char *pos = strchr(str, '\0'); while (pos > str && *(pos - 1) == '=') { *(--pos) = '\0';