2015-10-29 19:27:14 +03:00
|
|
|
<?php
|
|
|
|
/**
|
2016-07-21 17:49:16 +03:00
|
|
|
* @copyright Copyright (c) 2016, ownCloud, Inc.
|
|
|
|
*
|
2016-05-26 20:56:05 +03:00
|
|
|
* @author Björn Schießle <bjoern@schiessle.org>
|
2017-11-06 17:56:42 +03:00
|
|
|
* @author Joas Schilling <coding@schilljs.com>
|
2016-07-21 17:49:16 +03:00
|
|
|
* @author Morris Jobke <hey@morrisjobke.de>
|
2016-07-21 19:13:36 +03:00
|
|
|
* @author Robin Appelman <robin@icewind.nl>
|
2016-01-12 17:02:16 +03:00
|
|
|
* @author Thomas Müller <thomas.mueller@tmit.eu>
|
2015-10-29 19:27:14 +03:00
|
|
|
*
|
|
|
|
* @license AGPL-3.0
|
|
|
|
*
|
|
|
|
* This code is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU Affero General Public License, version 3,
|
|
|
|
* as published by the Free Software Foundation.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU Affero General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public License, version 3,
|
2019-12-03 21:57:53 +03:00
|
|
|
* along with this program. If not, see <http://www.gnu.org/licenses/>
|
2015-10-29 19:27:14 +03:00
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
namespace OCA\Federation;
|
|
|
|
|
|
|
|
|
2015-11-10 12:50:59 +03:00
|
|
|
use OC\Files\Filesystem;
|
2015-10-29 19:27:14 +03:00
|
|
|
use OC\HintException;
|
|
|
|
use OCP\IDBConnection;
|
|
|
|
use OCP\IL10N;
|
|
|
|
|
2015-11-10 12:50:59 +03:00
|
|
|
/**
|
|
|
|
* Class DbHandler
|
|
|
|
*
|
|
|
|
* handles all database calls for the federation app
|
|
|
|
*
|
|
|
|
* @group DB
|
|
|
|
* @package OCA\Federation
|
|
|
|
*/
|
2015-10-29 19:27:14 +03:00
|
|
|
class DbHandler {
|
|
|
|
|
|
|
|
/** @var IDBConnection */
|
|
|
|
private $connection;
|
|
|
|
|
|
|
|
/** @var IL10N */
|
2016-07-05 23:45:05 +03:00
|
|
|
private $IL10N;
|
2015-10-29 19:27:14 +03:00
|
|
|
|
|
|
|
/** @var string */
|
|
|
|
private $dbTable = 'trusted_servers';
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param IDBConnection $connection
|
|
|
|
* @param IL10N $il10n
|
|
|
|
*/
|
|
|
|
public function __construct(
|
|
|
|
IDBConnection $connection,
|
|
|
|
IL10N $il10n
|
|
|
|
) {
|
|
|
|
$this->connection = $connection;
|
|
|
|
$this->IL10N = $il10n;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2016-06-20 11:17:12 +03:00
|
|
|
* add server to the list of trusted servers
|
2015-10-29 19:27:14 +03:00
|
|
|
*
|
2015-11-10 12:50:59 +03:00
|
|
|
* @param string $url
|
2015-10-29 19:27:14 +03:00
|
|
|
* @return int
|
|
|
|
* @throws HintException
|
|
|
|
*/
|
2015-11-10 12:50:59 +03:00
|
|
|
public function addServer($url) {
|
|
|
|
$hash = $this->hash($url);
|
2015-11-24 15:07:40 +03:00
|
|
|
$url = rtrim($url, '/');
|
2015-10-29 19:27:14 +03:00
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->insert($this->dbTable)
|
|
|
|
->values(
|
|
|
|
[
|
|
|
|
'url' => $query->createParameter('url'),
|
|
|
|
'url_hash' => $query->createParameter('url_hash'),
|
|
|
|
]
|
|
|
|
)
|
|
|
|
->setParameter('url', $url)
|
|
|
|
->setParameter('url_hash', $hash);
|
|
|
|
|
|
|
|
$result = $query->execute();
|
|
|
|
|
|
|
|
if ($result) {
|
2015-11-19 19:49:43 +03:00
|
|
|
return (int)$this->connection->lastInsertId('*PREFIX*'.$this->dbTable);
|
2015-10-29 19:27:14 +03:00
|
|
|
}
|
2017-08-02 15:35:14 +03:00
|
|
|
|
|
|
|
$message = 'Internal failure, Could not add trusted server: ' . $url;
|
|
|
|
$message_t = $this->IL10N->t('Could not add server');
|
|
|
|
throw new HintException($message, $message_t);
|
2015-10-29 19:27:14 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2016-06-20 11:17:12 +03:00
|
|
|
* remove server from the list of trusted servers
|
2015-10-29 19:27:14 +03:00
|
|
|
*
|
|
|
|
* @param int $id
|
|
|
|
*/
|
2015-11-10 12:50:59 +03:00
|
|
|
public function removeServer($id) {
|
2015-10-29 19:27:14 +03:00
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->delete($this->dbTable)
|
|
|
|
->where($query->expr()->eq('id', $query->createParameter('id')))
|
|
|
|
->setParameter('id', $id);
|
|
|
|
$query->execute();
|
|
|
|
}
|
|
|
|
|
2016-02-26 18:59:53 +03:00
|
|
|
/**
|
|
|
|
* get trusted server with given ID
|
|
|
|
*
|
|
|
|
* @param int $id
|
|
|
|
* @return array
|
|
|
|
* @throws \Exception
|
|
|
|
*/
|
|
|
|
public function getServerById($id) {
|
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->select('*')->from($this->dbTable)
|
|
|
|
->where($query->expr()->eq('id', $query->createParameter('id')))
|
|
|
|
->setParameter('id', $id);
|
|
|
|
$query->execute();
|
|
|
|
$result = $query->execute()->fetchAll();
|
|
|
|
|
|
|
|
if (empty($result)) {
|
|
|
|
throw new \Exception('No Server found with ID: ' . $id);
|
|
|
|
}
|
|
|
|
|
|
|
|
return $result[0];
|
|
|
|
}
|
|
|
|
|
2015-10-29 19:27:14 +03:00
|
|
|
/**
|
|
|
|
* get all trusted servers
|
|
|
|
*
|
|
|
|
* @return array
|
|
|
|
*/
|
2015-11-10 12:50:59 +03:00
|
|
|
public function getAllServer() {
|
2015-10-29 19:27:14 +03:00
|
|
|
$query = $this->connection->getQueryBuilder();
|
2017-08-02 15:35:14 +03:00
|
|
|
$query->select(['url', 'url_hash', 'id', 'status', 'shared_secret', 'sync_token'])
|
|
|
|
->from($this->dbTable);
|
|
|
|
$statement = $query->execute();
|
|
|
|
$result = $statement->fetchAll();
|
|
|
|
$statement->closeCursor();
|
2015-10-29 19:27:14 +03:00
|
|
|
return $result;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* check if server already exists in the database table
|
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @return bool
|
|
|
|
*/
|
2015-11-10 12:50:59 +03:00
|
|
|
public function serverExists($url) {
|
|
|
|
$hash = $this->hash($url);
|
2015-10-29 19:27:14 +03:00
|
|
|
$query = $this->connection->getQueryBuilder();
|
2017-08-02 15:35:14 +03:00
|
|
|
$query->select('url')
|
|
|
|
->from($this->dbTable)
|
2015-10-29 19:27:14 +03:00
|
|
|
->where($query->expr()->eq('url_hash', $query->createParameter('url_hash')))
|
2015-11-10 12:50:59 +03:00
|
|
|
->setParameter('url_hash', $hash);
|
2017-08-02 15:35:14 +03:00
|
|
|
$statement = $query->execute();
|
|
|
|
$result = $statement->fetchAll();
|
|
|
|
$statement->closeCursor();
|
2015-10-29 19:27:14 +03:00
|
|
|
|
|
|
|
return !empty($result);
|
|
|
|
}
|
|
|
|
|
2015-11-10 12:50:59 +03:00
|
|
|
/**
|
|
|
|
* write token to database. Token is used to exchange the secret
|
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @param string $token
|
|
|
|
*/
|
|
|
|
public function addToken($url, $token) {
|
|
|
|
$hash = $this->hash($url);
|
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->update($this->dbTable)
|
|
|
|
->set('token', $query->createParameter('token'))
|
|
|
|
->where($query->expr()->eq('url_hash', $query->createParameter('url_hash')))
|
|
|
|
->setParameter('url_hash', $hash)
|
|
|
|
->setParameter('token', $token);
|
|
|
|
$query->execute();
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* get token stored in database
|
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @return string
|
2016-02-15 18:59:49 +03:00
|
|
|
* @throws \Exception
|
2015-11-10 12:50:59 +03:00
|
|
|
*/
|
|
|
|
public function getToken($url) {
|
|
|
|
$hash = $this->hash($url);
|
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->select('token')->from($this->dbTable)
|
|
|
|
->where($query->expr()->eq('url_hash', $query->createParameter('url_hash')))
|
|
|
|
->setParameter('url_hash', $hash);
|
|
|
|
|
2017-08-02 15:35:14 +03:00
|
|
|
$statement = $query->execute();
|
|
|
|
$result = $statement->fetch();
|
|
|
|
$statement->closeCursor();
|
2016-02-15 18:59:49 +03:00
|
|
|
|
|
|
|
if (!isset($result['token'])) {
|
|
|
|
throw new \Exception('No token found for: ' . $url);
|
|
|
|
}
|
|
|
|
|
2015-11-10 12:50:59 +03:00
|
|
|
return $result['token'];
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* add shared Secret to database
|
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @param string $sharedSecret
|
|
|
|
*/
|
|
|
|
public function addSharedSecret($url, $sharedSecret) {
|
|
|
|
$hash = $this->hash($url);
|
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->update($this->dbTable)
|
|
|
|
->set('shared_secret', $query->createParameter('sharedSecret'))
|
|
|
|
->where($query->expr()->eq('url_hash', $query->createParameter('url_hash')))
|
|
|
|
->setParameter('url_hash', $hash)
|
|
|
|
->setParameter('sharedSecret', $sharedSecret);
|
|
|
|
$query->execute();
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* get shared secret from database
|
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @return string
|
|
|
|
*/
|
|
|
|
public function getSharedSecret($url) {
|
|
|
|
$hash = $this->hash($url);
|
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->select('shared_secret')->from($this->dbTable)
|
|
|
|
->where($query->expr()->eq('url_hash', $query->createParameter('url_hash')))
|
|
|
|
->setParameter('url_hash', $hash);
|
|
|
|
|
2017-08-02 15:35:14 +03:00
|
|
|
$statement = $query->execute();
|
|
|
|
$result = $statement->fetch();
|
|
|
|
$statement->closeCursor();
|
2015-11-10 12:50:59 +03:00
|
|
|
return $result['shared_secret'];
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* set server status
|
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @param int $status
|
2015-12-07 17:28:06 +03:00
|
|
|
* @param string|null $token
|
2015-11-10 12:50:59 +03:00
|
|
|
*/
|
2015-12-04 15:38:32 +03:00
|
|
|
public function setServerStatus($url, $status, $token = null) {
|
2015-11-10 12:50:59 +03:00
|
|
|
$hash = $this->hash($url);
|
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->update($this->dbTable)
|
2015-12-04 15:38:32 +03:00
|
|
|
->set('status', $query->createNamedParameter($status))
|
|
|
|
->where($query->expr()->eq('url_hash', $query->createNamedParameter($hash)));
|
|
|
|
if (!is_null($token)) {
|
|
|
|
$query->set('sync_token', $query->createNamedParameter($token));
|
|
|
|
}
|
2015-11-10 12:50:59 +03:00
|
|
|
$query->execute();
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* get server status
|
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @return int
|
|
|
|
*/
|
|
|
|
public function getServerStatus($url) {
|
|
|
|
$hash = $this->hash($url);
|
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->select('status')->from($this->dbTable)
|
|
|
|
->where($query->expr()->eq('url_hash', $query->createParameter('url_hash')))
|
|
|
|
->setParameter('url_hash', $hash);
|
|
|
|
|
2017-08-02 15:35:14 +03:00
|
|
|
$statement = $query->execute();
|
|
|
|
$result = $statement->fetch();
|
|
|
|
$statement->closeCursor();
|
2015-11-19 19:49:43 +03:00
|
|
|
return (int)$result['status'];
|
2015-11-10 12:50:59 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* create hash from URL
|
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @return string
|
|
|
|
*/
|
|
|
|
protected function hash($url) {
|
|
|
|
$normalized = $this->normalizeUrl($url);
|
2016-02-26 19:02:13 +03:00
|
|
|
return sha1($normalized);
|
2015-11-10 12:50:59 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2016-02-26 19:02:13 +03:00
|
|
|
* normalize URL, used to create the sha1 hash
|
2015-11-10 12:50:59 +03:00
|
|
|
*
|
|
|
|
* @param string $url
|
|
|
|
* @return string
|
|
|
|
*/
|
|
|
|
protected function normalizeUrl($url) {
|
|
|
|
$normalized = $url;
|
|
|
|
|
|
|
|
if (strpos($url, 'https://') === 0) {
|
|
|
|
$normalized = substr($url, strlen('https://'));
|
|
|
|
} else if (strpos($url, 'http://') === 0) {
|
|
|
|
$normalized = substr($url, strlen('http://'));
|
|
|
|
}
|
|
|
|
|
|
|
|
$normalized = Filesystem::normalizePath($normalized);
|
|
|
|
$normalized = trim($normalized, '/');
|
|
|
|
|
|
|
|
return $normalized;
|
|
|
|
}
|
|
|
|
|
2015-12-03 18:22:18 +03:00
|
|
|
/**
|
|
|
|
* @param $username
|
|
|
|
* @param $password
|
|
|
|
* @return bool
|
|
|
|
*/
|
|
|
|
public function auth($username, $password) {
|
|
|
|
if ($username !== 'system') {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
$query = $this->connection->getQueryBuilder();
|
|
|
|
$query->select('url')->from($this->dbTable)
|
|
|
|
->where($query->expr()->eq('shared_secret', $query->createNamedParameter($password)));
|
|
|
|
|
2017-08-02 15:35:14 +03:00
|
|
|
$statement = $query->execute();
|
|
|
|
$result = $statement->fetch();
|
|
|
|
$statement->closeCursor();
|
2015-12-03 18:22:18 +03:00
|
|
|
return !empty($result);
|
|
|
|
}
|
|
|
|
|
2015-10-29 19:27:14 +03:00
|
|
|
}
|