otp.go 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163
  1. package user
  2. import (
  3. "bytes"
  4. "crypto/sha1"
  5. "encoding/base64"
  6. "encoding/hex"
  7. "fmt"
  8. "github.com/0xJacky/Nginx-UI/api"
  9. "github.com/0xJacky/Nginx-UI/internal/crypto"
  10. "github.com/0xJacky/Nginx-UI/query"
  11. "github.com/0xJacky/Nginx-UI/settings"
  12. "github.com/gin-gonic/gin"
  13. "github.com/pquerna/otp"
  14. "github.com/pquerna/otp/totp"
  15. "image/jpeg"
  16. "net/http"
  17. "strings"
  18. )
  19. func GenerateTOTP(c *gin.Context) {
  20. user := api.CurrentUser(c)
  21. issuer := fmt.Sprintf("Nginx UI %s", settings.ServerSettings.Name)
  22. issuer = strings.TrimSpace(issuer)
  23. otpOpts := totp.GenerateOpts{
  24. Issuer: issuer,
  25. AccountName: user.Name,
  26. Period: 30, // seconds
  27. Digits: otp.DigitsSix,
  28. Algorithm: otp.AlgorithmSHA1,
  29. }
  30. otpKey, err := totp.Generate(otpOpts)
  31. if err != nil {
  32. api.ErrHandler(c, err)
  33. return
  34. }
  35. ciphertext, err := crypto.AesEncrypt([]byte(otpKey.Secret()))
  36. if err != nil {
  37. api.ErrHandler(c, err)
  38. return
  39. }
  40. qrCode, err := otpKey.Image(512, 512)
  41. if err != nil {
  42. api.ErrHandler(c, err)
  43. return
  44. }
  45. // Encode the image to a buffer
  46. var buf []byte
  47. buffer := bytes.NewBuffer(buf)
  48. err = jpeg.Encode(buffer, qrCode, nil)
  49. if err != nil {
  50. fmt.Println("Error encoding image:", err)
  51. return
  52. }
  53. // Convert the buffer to a base64 string
  54. base64Str := "data:image/jpeg;base64," + base64.StdEncoding.EncodeToString(buffer.Bytes())
  55. c.JSON(http.StatusOK, gin.H{
  56. "secret": base64.StdEncoding.EncodeToString(ciphertext),
  57. "qr_code": base64Str,
  58. })
  59. }
  60. func EnrollTOTP(c *gin.Context) {
  61. user := api.CurrentUser(c)
  62. if len(user.OTPSecret) > 0 {
  63. c.JSON(http.StatusBadRequest, gin.H{
  64. "message": "User already enrolled",
  65. })
  66. return
  67. }
  68. var json struct {
  69. Secret string `json:"secret" binding:"required"`
  70. Passcode string `json:"passcode" binding:"required"`
  71. }
  72. if !api.BindAndValid(c, &json) {
  73. return
  74. }
  75. secret, err := base64.StdEncoding.DecodeString(json.Secret)
  76. if err != nil {
  77. api.ErrHandler(c, err)
  78. return
  79. }
  80. decrypted, err := crypto.AesDecrypt(secret)
  81. if err != nil {
  82. api.ErrHandler(c, err)
  83. return
  84. }
  85. if ok := totp.Validate(json.Passcode, string(decrypted)); !ok {
  86. c.JSON(http.StatusNotAcceptable, gin.H{
  87. "message": "Invalid passcode",
  88. })
  89. return
  90. }
  91. ciphertext, err := crypto.AesEncrypt(decrypted)
  92. if err != nil {
  93. api.ErrHandler(c, err)
  94. return
  95. }
  96. u := query.Auth
  97. _, err = u.Where(u.ID.Eq(user.ID)).Update(u.OTPSecret, ciphertext)
  98. if err != nil {
  99. api.ErrHandler(c, err)
  100. return
  101. }
  102. recoveryCode := sha1.Sum(ciphertext)
  103. c.JSON(http.StatusOK, gin.H{
  104. "message": "ok",
  105. "recovery_code": hex.EncodeToString(recoveryCode[:]),
  106. })
  107. }
  108. func ResetOTP(c *gin.Context) {
  109. var json struct {
  110. RecoveryCode string `json:"recovery_code"`
  111. }
  112. if !api.BindAndValid(c, &json) {
  113. return
  114. }
  115. recoverCode, err := hex.DecodeString(json.RecoveryCode)
  116. if err != nil {
  117. api.ErrHandler(c, err)
  118. return
  119. }
  120. user := api.CurrentUser(c)
  121. k := sha1.Sum(user.OTPSecret)
  122. if !bytes.Equal(k[:], recoverCode) {
  123. c.JSON(http.StatusBadRequest, gin.H{
  124. "message": "Invalid recovery code",
  125. })
  126. return
  127. }
  128. u := query.Auth
  129. _, err = u.Where(u.ID.Eq(user.ID)).UpdateSimple(u.OTPSecret.Null())
  130. if err != nil {
  131. api.ErrHandler(c, err)
  132. return
  133. }
  134. c.JSON(http.StatusOK, gin.H{
  135. "message": "ok",
  136. })
  137. }
  138. func OTPStatus(c *gin.Context) {
  139. c.JSON(http.StatusOK, gin.H{
  140. "status": len(api.CurrentUser(c).OTPSecret) > 0,
  141. })
  142. }