Add Meta authentication secret and SHA256 hashing

This commit is contained in:
Holden
2026-06-21 15:36:17 -05:00
parent e77e479493
commit 706c4f13d8
7 changed files with 242 additions and 8 deletions

View File

@@ -0,0 +1,19 @@
using System.Security.Cryptography;
using System.Text;
namespace RecNet.Application.Common.Security;
public static class Hashing
{
public static byte[] ComputeSha256(string input)
=> SHA256.HashData(Encoding.UTF8.GetBytes(input));
public static bool VerifySha256(string input, byte[] expectedHash)
{
var computedHash = ComputeSha256(input);
return CryptographicOperations.FixedTimeEquals(
computedHash,
expectedHash);
}
}

View File

@@ -1,5 +1,7 @@
using AutoMapper;
using RecNet.Application.Common.Interfaces;
using RecNet.Application.Common.Security;
using RecNet.Domain.Common;
using RecNet.Domain.GameVersions;
using RecNet.Domain.Profiles;
using ProfileEntity = RecNet.Domain.Profiles.Profile;
@@ -51,7 +53,7 @@ public class ProfileService(
);
await profileRepository.SaveChangesAsync(ct);
return mapper.Map<AvatarDTO>(profile.Avatar);
}
@@ -60,13 +62,13 @@ public class ProfileService(
CancellationToken ct = default)
{
var settings = await profileRepository.GetSettingsByProfileIdAsync(profileId, ct);
return mapper.Map<List<PlayerSettingDTO>>(settings);
}
public async Task<bool> UpdatePlayerSettingAsync(
Guid profileId,
UpdatePlayerSettingCommand command,
Guid profileId,
UpdatePlayerSettingCommand command,
CancellationToken ct = default)
{
var profile = await profileRepository.GetByIdWithSettingsAsync(profileId, ct);
@@ -130,9 +132,15 @@ public class ProfileService(
command.PlatformType,
command.PlatformId);
if (command.PlatformType == PlatformType.Meta)
profile.SetMetaAuthenticationSecret(Hashing.ComputeSha256(command.PlatformAuthentication));
await profileRepository.AddAsync(profile, ct);
}
if (command.PlatformType == PlatformType.Meta && !Hashing.VerifySha256(command.PlatformAuthentication, profile.MetaAuthenticationSecret))
return LoginProfileResult.Fail("Platform Auth Failed: Invalid authentication");
if (profile.IsBanned)
return LoginProfileResult.Fail("Profile is banned");
@@ -148,4 +156,4 @@ public class ProfileService(
expiresIn: token.ExpiresIn
);
}
}
}

View File

@@ -28,7 +28,8 @@ public class Profile
public PlatformType Platform { get; private set; }
public string PlatformId { get; private set; }
public List<string> DeviceIds { get; private set; } = [];
public byte[] MetaAuthenticationSecret { get; private set; } = [];
// EZ
public bool IsBanned { get; private set; }
public bool IsModerator { get; private set; }
@@ -63,6 +64,9 @@ public class Profile
DeviceIds.Add(deviceId);
}
public void SetMetaAuthenticationSecret(byte[] metaAuthenticationSecret)
=> MetaAuthenticationSecret = metaAuthenticationSecret;
public void RecordSuccessfulLogin(string deviceId, string? platformName)
{

View File

@@ -0,0 +1,168 @@
// <auto-generated />
using System;
using Microsoft.EntityFrameworkCore;
using Microsoft.EntityFrameworkCore.Infrastructure;
using Microsoft.EntityFrameworkCore.Migrations;
using Microsoft.EntityFrameworkCore.Storage.ValueConversion;
using Npgsql.EntityFrameworkCore.PostgreSQL.Metadata;
using RecNet.Infrastructure.Persistence;
#nullable disable
namespace RecNet.Infrastructure.Persistence.Migrations
{
[DbContext(typeof(DatabaseContext))]
[Migration("20260621202709_MetaAuthenticationSecret")]
partial class MetaAuthenticationSecret
{
/// <inheritdoc />
protected override void BuildTargetModel(ModelBuilder modelBuilder)
{
#pragma warning disable 612, 618
modelBuilder
.HasAnnotation("ProductVersion", "10.0.8")
.HasAnnotation("Relational:MaxIdentifierLength", 63);
NpgsqlModelBuilderExtensions.UseIdentityByDefaultColumns(modelBuilder);
modelBuilder.Entity("RecNet.Domain.Configuration.ServerConfig", b =>
{
b.Property<string>("Key")
.HasMaxLength(128)
.HasColumnType("character varying(128)");
b.Property<string>("Value")
.IsRequired()
.HasColumnType("jsonb");
b.HasKey("Key");
b.ToTable("ServerConfigs");
});
modelBuilder.Entity("RecNet.Domain.GameVersions.GameVersion", b =>
{
b.Property<string>("Version")
.HasMaxLength(32)
.HasColumnType("character varying(32)");
b.Property<bool>("IsValid")
.HasColumnType("boolean");
b.HasKey("Version");
b.ToTable("GameVersions");
});
modelBuilder.Entity("RecNet.Domain.Profiles.PlayerSetting", b =>
{
b.Property<Guid>("UserId")
.HasColumnType("uuid");
b.Property<string>("Key")
.HasMaxLength(100)
.HasColumnType("character varying(100)");
b.Property<string>("Value")
.IsRequired()
.HasColumnType("text");
b.HasKey("UserId", "Key");
b.ToTable("PlayerSettings");
});
modelBuilder.Entity("RecNet.Domain.Profiles.Profile", b =>
{
b.Property<Guid>("ProfileId")
.ValueGeneratedOnAdd()
.HasColumnType("uuid");
b.Property<DateTimeOffset>("CreatedAt")
.HasColumnType("timestamp with time zone");
b.PrimitiveCollection<string>("DeviceIds")
.IsRequired()
.HasColumnType("jsonb");
b.Property<bool>("IsBanned")
.HasColumnType("boolean");
b.Property<bool>("IsModerator")
.HasColumnType("boolean");
b.Property<byte[]>("MetaAuthenticationSecret")
.IsRequired()
.HasColumnType("bytea");
b.Property<string>("Name")
.IsRequired()
.HasMaxLength(32)
.HasColumnType("character varying(32)");
b.Property<string>("Platform")
.IsRequired()
.HasMaxLength(50)
.HasColumnType("character varying(50)");
b.Property<string>("PlatformId")
.IsRequired()
.HasMaxLength(50)
.HasColumnType("character varying(50)");
b.HasKey("ProfileId");
b.HasIndex("Platform", "PlatformId")
.IsUnique();
b.ToTable("Profiles");
});
modelBuilder.Entity("RecNet.Domain.Profiles.PlayerSetting", b =>
{
b.HasOne("RecNet.Domain.Profiles.Profile", null)
.WithMany("Settings")
.HasForeignKey("UserId")
.OnDelete(DeleteBehavior.Cascade)
.IsRequired();
});
modelBuilder.Entity("RecNet.Domain.Profiles.Profile", b =>
{
b.OwnsOne("RecNet.Domain.Profiles.Avatar", "Avatar", b1 =>
{
b1.Property<Guid>("ProfileId")
.HasColumnType("uuid");
b1.Property<string>("HairColor")
.IsRequired()
.HasColumnType("text");
b1.Property<string>("OutfitSelections")
.IsRequired()
.HasColumnType("text");
b1.Property<string>("SkinColor")
.IsRequired()
.HasColumnType("text");
b1.HasKey("ProfileId");
b1.ToTable("Profiles");
b1.WithOwner()
.HasForeignKey("ProfileId");
});
b.Navigation("Avatar")
.IsRequired();
});
modelBuilder.Entity("RecNet.Domain.Profiles.Profile", b =>
{
b.Navigation("Settings");
});
#pragma warning restore 612, 618
}
}
}

View File

@@ -0,0 +1,29 @@
using Microsoft.EntityFrameworkCore.Migrations;
#nullable disable
namespace RecNet.Infrastructure.Persistence.Migrations
{
/// <inheritdoc />
public partial class MetaAuthenticationSecret : Migration
{
/// <inheritdoc />
protected override void Up(MigrationBuilder migrationBuilder)
{
migrationBuilder.AddColumn<byte[]>(
name: "MetaAuthenticationSecret",
table: "Profiles",
type: "bytea",
nullable: false,
defaultValue: new byte[0]);
}
/// <inheritdoc />
protected override void Down(MigrationBuilder migrationBuilder)
{
migrationBuilder.DropColumn(
name: "MetaAuthenticationSecret",
table: "Profiles");
}
}
}

View File

@@ -88,6 +88,10 @@ namespace RecNet.Infrastructure.Persistence.Migrations
b.Property<bool>("IsModerator")
.HasColumnType("boolean");
b.Property<byte[]>("MetaAuthenticationSecret")
.IsRequired()
.HasColumnType("bytea");
b.Property<string>("Name")
.IsRequired()
.HasMaxLength(32)

View File

@@ -9,7 +9,9 @@ public class MetaAuthValidator : IPlatformAuthValidator
public PlatformType PlatformType
=> PlatformType.Meta;
public Task<PlatformAuthResult> ValidateAsync(string platformAuthentication, string platformId,
public Task<PlatformAuthResult> ValidateAsync(
string platformAuthentication,
string platformId,
CancellationToken ct = default)
=> Task.FromResult(PlatformAuthResult.Success(null)); // TODO: Implement
=> Task.FromResult(PlatformAuthResult.Success(null)); // We have a custom flow that utilizes platformAuthentication for Meta, so this gets skipped.
}