diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..b5d7fe6 --- /dev/null +++ b/.gitignore @@ -0,0 +1,289 @@ +## Ignore Visual Studio temporary files, build results, and +## files generated by popular Visual Studio add-ons. +## +## Get latest from https://github.com/github/gitignore/blob/master/VisualStudio.gitignore + +# User-specific files +*.suo +*.user +*.userosscache +*.sln.docstates + +# User-specific files (MonoDevelop/Xamarin Studio) +*.userprefs + +# Build results +[Dd]ebug/ +[Dd]ebugPublic/ +[Rr]elease/ +x64/ +x86/ +bld/ +[Bb]in/ +[Oo]bj/ +[Ll]og/ + +# Visual Studio 2015 cache/options directory +.vs/ +# Uncomment if you have tasks that create the project's static files in wwwroot +#wwwroot/ + +# MSTest test Results +[Tt]est[Rr]esult*/ +[Bb]uild[Ll]og.* + +# NUNIT +*.VisualState.xml +TestResult.xml + +# Build Results of an ATL Project +[Dd]ebugPS/ +[Rr]eleasePS/ +dlldata.c + +# .NET Core +project.lock.json +project.fragment.lock.json +artifacts/ +**/Properties/launchSettings.json + +# VS Code +.vscode/ + +*_i.c +*_p.c +*_i.h +*.ilk +*.meta +*.obj +*.pch +*.pdb +*.pgc +*.pgd +*.rsp +*.sbr +*.tlb +*.tli +*.tlh +*.tmp +*.tmp_proj +*.log +*.vspscc +*.vssscc +.builds +*.pidb +*.svclog +*.scc + +# Chutzpah Test files +_Chutzpah* + +# Visual C++ cache files +ipch/ +*.aps +*.ncb +*.opendb +*.opensdf +*.sdf +*.cachefile +*.VC.db +*.VC.VC.opendb + +# Visual Studio profiler +*.psess +*.vsp +*.vspx +*.sap + +# TFS 2012 Local Workspace +$tf/ + +# Guidance Automation Toolkit +*.gpState + +# ReSharper is a .NET coding add-in +_ReSharper*/ +*.[Rr]e[Ss]harper +*.DotSettings.user + +# JustCode is a .NET coding add-in +.JustCode + +# TeamCity is a build add-in +_TeamCity* + +# DotCover is a Code Coverage Tool +*.dotCover + +# Visual Studio code coverage results +*.coverage +*.coveragexml + +# NCrunch +_NCrunch_* +.*crunch*.local.xml +nCrunchTemp_* + +# MightyMoose +*.mm.* +AutoTest.Net/ + +# Web workbench (sass) +.sass-cache/ + +# Installshield output folder +[Ee]xpress/ + +# DocProject is a documentation generator add-in +DocProject/buildhelp/ +DocProject/Help/*.HxT +DocProject/Help/*.HxC +DocProject/Help/*.hhc +DocProject/Help/*.hhk +DocProject/Help/*.hhp +DocProject/Help/Html2 +DocProject/Help/html + +# Click-Once directory +publish/ + +# Publish Web Output +*.[Pp]ublish.xml +*.azurePubxml +# TODO: Comment the next line if you want to checkin your web deploy settings +# but database connection strings (with potential passwords) will be unencrypted +*.pubxml +*.publishproj + +# Microsoft Azure Web App publish settings. Comment the next line if you want to +# checkin your Azure Web App publish settings, but sensitive information contained +# in these scripts will be unencrypted +PublishScripts/ + +# NuGet Packages +*.nupkg +# The packages folder can be ignored because of Package Restore +**/packages/* +# except build/, which is used as an MSBuild target. +!**/packages/build/ +# Uncomment if necessary however generally it will be regenerated when needed +#!**/packages/repositories.config +# NuGet v3's project.json files produces more ignorable files +*.nuget.props +*.nuget.targets + +# Microsoft Azure Build Output +csx/ +*.build.csdef + +# Microsoft Azure Emulator +ecf/ +rcf/ + +# Windows Store app package directories and files +AppPackages/ +BundleArtifacts/ +Package.StoreAssociation.xml +_pkginfo.txt + +# Visual Studio cache files +# files ending in .cache can be ignored +*.[Cc]ache +# but keep track of directories ending in .cache +!*.[Cc]ache/ + +# Others +ClientBin/ +~$* +*~ +*.dbmdl +*.dbproj.schemaview +*.jfm +*.pfx +*.publishsettings +orleans.codegen.cs + +# Since there are multiple workflows, uncomment next line to ignore bower_components +# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622) +#bower_components/ + +# RIA/Silverlight projects +Generated_Code/ + +# Backup & report files from converting an old project file +# to a newer Visual Studio version. Backup files are not needed, +# because we have git ;-) +_UpgradeReport_Files/ +Backup*/ +UpgradeLog*.XML +UpgradeLog*.htm + +# SQL Server files +*.mdf +*.ldf + +# Business Intelligence projects +*.rdl.data +*.bim.layout +*.bim_*.settings + +# Microsoft Fakes +FakesAssemblies/ + +# GhostDoc plugin setting file +*.GhostDoc.xml + +# Node.js Tools for Visual Studio +.ntvs_analysis.dat +node_modules/ + +# Typescript v1 declaration files +typings/ + +# Visual Studio 6 build log +*.plg + +# Visual Studio 6 workspace options file +*.opt + +# Visual Studio 6 auto-generated workspace file (contains which files were open etc.) +*.vbw + +# Visual Studio LightSwitch build output +**/*.HTMLClient/GeneratedArtifacts +**/*.DesktopClient/GeneratedArtifacts +**/*.DesktopClient/ModelManifest.xml +**/*.Server/GeneratedArtifacts +**/*.Server/ModelManifest.xml +_Pvt_Extensions + +# Paket dependency manager +.paket/paket.exe +paket-files/ + +# FAKE - F# Make +.fake/ + +# JetBrains Rider +.idea/ +*.sln.iml + +# CodeRush +.cr/ + +# Python Tools for Visual Studio (PTVS) +__pycache__/ +*.pyc + +# Cake - Uncomment if you are using it +# tools/** +# !tools/packages.config + +# Telerik's JustMock configuration file +*.jmconfig + +# BizTalk build output +*.btp.cs +*.btm.cs +*.odx.cs +*.xsd.cs diff --git a/RecRoomPhotonAuthenticationServer.sln b/RecRoomPhotonAuthenticationServer.sln new file mode 100644 index 0000000..3c480aa --- /dev/null +++ b/RecRoomPhotonAuthenticationServer.sln @@ -0,0 +1,16 @@ + +Microsoft Visual Studio Solution File, Format Version 12.00 +Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "RecRoomPhotonAuthenticationServer", "RecRoomPhotonAuthenticationServer\RecRoomPhotonAuthenticationServer.csproj", "{2ED2DAB8-7B21-467E-B5DE-81B03785B745}" +EndProject +Global + GlobalSection(SolutionConfigurationPlatforms) = preSolution + Debug|Any CPU = Debug|Any CPU + Release|Any CPU = Release|Any CPU + EndGlobalSection + GlobalSection(ProjectConfigurationPlatforms) = postSolution + {2ED2DAB8-7B21-467E-B5DE-81B03785B745}.Debug|Any CPU.ActiveCfg = Debug|Any CPU + {2ED2DAB8-7B21-467E-B5DE-81B03785B745}.Debug|Any CPU.Build.0 = Debug|Any CPU + {2ED2DAB8-7B21-467E-B5DE-81B03785B745}.Release|Any CPU.ActiveCfg = Release|Any CPU + {2ED2DAB8-7B21-467E-B5DE-81B03785B745}.Release|Any CPU.Build.0 = Release|Any CPU + EndGlobalSection +EndGlobal diff --git a/RecRoomPhotonAuthenticationServer/App.cs b/RecRoomPhotonAuthenticationServer/App.cs new file mode 100644 index 0000000..4c6b05a --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/App.cs @@ -0,0 +1,59 @@ +using Microsoft.AspNetCore.Builder; +using Microsoft.EntityFrameworkCore; +using Microsoft.Extensions.Configuration; +using Microsoft.Extensions.DependencyInjection; +using Npgsql; + +namespace RecRoomPhotonAuthenticationServer; + +public static class App +{ + public static string rsaPath; + public static string keyId; + + public static async Task Main(string[] args) + { + var builder = WebApplication.CreateBuilder(args); + + builder.WebHost.UseUrls("http://localhost:2374"); + builder.Services.AddControllers(); + builder.Services.AddEndpointsApiExplorer(); + builder.Services.AddSingleton(); + + // defaultconnection is in appsettings.json + if (builder.Configuration.GetConnectionString("DefaultConnection") == null) + { + throw new Exception("DefaultConnection is not set in appsettings.json"); + } + else + { + builder.Services.AddDbContext(options => + options.UseNpgsql( + builder.Configuration.GetConnectionString("DefaultConnection") + )); + } + + if (builder.Configuration.GetSection("RSAPubKeyPath").Value == null) + { + throw new Exception("RSAPubKeyPath is not set in appsettings.json"); + } + else + { + rsaPath = builder.Configuration.GetSection("RSAPubKeyPath").Value; + } + + if (builder.Configuration.GetSection("KeyId").Value == null) + { + throw new Exception("KeyId is not set in appsettings.json"); + } + else + { + keyId = builder.Configuration.GetSection("KeyId").Value; + } + + WebApplication app = builder.Build(); + app.MapControllers(); + + await app.RunAsync(); + } +} \ No newline at end of file diff --git a/RecRoomPhotonAuthenticationServer/Controllers/AuthController.cs b/RecRoomPhotonAuthenticationServer/Controllers/AuthController.cs new file mode 100644 index 0000000..99417d0 --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/Controllers/AuthController.cs @@ -0,0 +1,85 @@ +using System.Text.Json; +using Microsoft.AspNetCore.Http; +using Microsoft.AspNetCore.Mvc; +using Microsoft.EntityFrameworkCore; +using Npgsql; +using RecRoomPhotonAuthenticationServer.Models; + +namespace RecRoomPhotonAuthenticationServer.Controllers; + +[ApiController, Route("api/auth")] +public class AuthController : ControllerBase +{ + private readonly DBContext _db; + + public AuthController(DBContext db) + { + _db = db; + } + + [HttpPost("authenticate")] + [Consumes("text/plain", "application/json")] + public async Task Authentication([FromServices] JWTValidator jwtService) + { + using var reader = new StreamReader(Request.Body); + var body = await reader.ReadToEndAsync(); + + AuthenticationRequest? request; + + try + { + request = JsonSerializer.Deserialize( + body, + new JsonSerializerOptions + { + PropertyNameCaseInsensitive = true + }); + + if (request == null || string.IsNullOrWhiteSpace(request.accessToken)) + { + return Ok(new + { + ResultCode = 3, + Message = "Invalid parameters." + }); + } + + var accountIdString = jwtService.ValidateAndGetAccountId(request.accessToken); + var userId = int.TryParse(accountIdString, out var parsedUserId) ? parsedUserId : 0; + + var account = await _db.Accounts + .FirstOrDefaultAsync(a => a.AccountId == userId); + + if (account == null) + { + return BadRequest(new + { + ResultCode = 2, + Message = "Authentication failed. Wrong credentials." + }); + } + + return Ok(new + { + ResultCode = 1, + UserId = userId + }); + } + catch (JsonException) + { + return Ok(new + { + ResultCode = 3, + Message = "Invalid parameters." + }); + } + catch (Exception ex) + { + return BadRequest(new + { + ResultCode = 3, + Message = "Invalid parameters." + }); + } + } +} \ No newline at end of file diff --git a/RecRoomPhotonAuthenticationServer/DBContext.cs b/RecRoomPhotonAuthenticationServer/DBContext.cs new file mode 100644 index 0000000..2b5acb4 --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/DBContext.cs @@ -0,0 +1,25 @@ +using RecRoomPhotonAuthenticationServer.Models; + +namespace RecRoomPhotonAuthenticationServer; + +using Microsoft.EntityFrameworkCore; + +public class DBContext : DbContext +{ + public DBContext(DbContextOptions options) : base(options) { } + + public DbSet Accounts { get; set; } + + protected override void OnModelCreating(ModelBuilder modelBuilder) + { + base.OnModelCreating(modelBuilder); + + // accounts, you'll prob have to change the table name there + modelBuilder.Entity(entity => + { + entity.HasKey(e => e.AccountId); + entity.Property(e => e.AccountId).ValueGeneratedNever(); + entity.ToTable("accounts"); + }); + } +} \ No newline at end of file diff --git a/RecRoomPhotonAuthenticationServer/JWTValidator.cs b/RecRoomPhotonAuthenticationServer/JWTValidator.cs new file mode 100644 index 0000000..a57e354 --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/JWTValidator.cs @@ -0,0 +1,60 @@ +using System.IdentityModel.Tokens.Jwt; +using System.Security.Cryptography; +using System.Text; +using Microsoft.IdentityModel.Tokens; + +namespace RecRoomPhotonAuthenticationServer; + +public class JWTValidator +{ + private readonly RsaSecurityKey _securityKey; + + public JWTValidator() + { + var rsa = RSA.Create(); + + var pem = File.ReadAllText(App.rsaPath); + rsa.ImportFromPem(pem); + + _securityKey = new RsaSecurityKey(rsa) + { + KeyId = App.keyId + }; + } + + public string? ValidateAndGetAccountId(string token) + { + try + { + var handler = new JwtSecurityTokenHandler(); + handler.InboundClaimTypeMap.Clear(); + + // you probably have to change these + var parameters = new TokenValidationParameters + { + ValidateIssuerSigningKey = true, + IssuerSigningKey = _securityKey, + ValidateIssuer = true, + ValidIssuer = "https://auth.lapis.codes", + ValidateAudience = true, + ValidAudiences = + [ + "https://api.lapis.codes/resources", + "https://auth.lapis.codes/resources" + ], + ValidateLifetime = true, + ClockSkew = TimeSpan.Zero + }; + + var principal = handler.ValidateToken(token, parameters, out SecurityToken validatedToken); + + var accountIdClaim = principal.Claims.FirstOrDefault(c => c.Type == "sub"); + + return accountIdClaim?.Value; + } + catch (Exception ex) + { + return null; + } + } +} \ No newline at end of file diff --git a/RecRoomPhotonAuthenticationServer/Models/Account.cs b/RecRoomPhotonAuthenticationServer/Models/Account.cs new file mode 100644 index 0000000..aae9052 --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/Models/Account.cs @@ -0,0 +1,8 @@ +using System.Text.Json.Serialization; + +namespace RecRoomPhotonAuthenticationServer.Models; + +public class Account +{ + [JsonPropertyName("accountId")] public int? AccountId { get; set; } +} \ No newline at end of file diff --git a/RecRoomPhotonAuthenticationServer/Models/AuthenticationRequest.cs b/RecRoomPhotonAuthenticationServer/Models/AuthenticationRequest.cs new file mode 100644 index 0000000..4cd93c2 --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/Models/AuthenticationRequest.cs @@ -0,0 +1,8 @@ +namespace RecRoomPhotonAuthenticationServer.Models; + +public class AuthenticationRequest +{ + public string? accessToken { get; set; } + public string? accountId { get; set; } + public string? environment { get; set; } +} \ No newline at end of file diff --git a/RecRoomPhotonAuthenticationServer/RecRoomPhotonAuthenticationServer.csproj b/RecRoomPhotonAuthenticationServer/RecRoomPhotonAuthenticationServer.csproj new file mode 100644 index 0000000..10ebe86 --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/RecRoomPhotonAuthenticationServer.csproj @@ -0,0 +1,16 @@ + + + + net10.0 + Exe + enable + enable + + + + + + + + + diff --git a/RecRoomPhotonAuthenticationServer/appsettings.Production.json b/RecRoomPhotonAuthenticationServer/appsettings.Production.json new file mode 100644 index 0000000..cc8d58f --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/appsettings.Production.json @@ -0,0 +1,7 @@ +{ + "ConnectionStrings": { + "DefaultConnection": "Host=localhost;Port=5432;Database=database;Username=postgres;Password=postgres" + }, + "RSAPubKeyPath": "PathToPemHere", + "KeyId": "KeyHere" +} \ No newline at end of file diff --git a/RecRoomPhotonAuthenticationServer/appsettings.json b/RecRoomPhotonAuthenticationServer/appsettings.json new file mode 100644 index 0000000..cc8d58f --- /dev/null +++ b/RecRoomPhotonAuthenticationServer/appsettings.json @@ -0,0 +1,7 @@ +{ + "ConnectionStrings": { + "DefaultConnection": "Host=localhost;Port=5432;Database=database;Username=postgres;Password=postgres" + }, + "RSAPubKeyPath": "PathToPemHere", + "KeyId": "KeyHere" +} \ No newline at end of file