Add Meta authentication secret and SHA256 hashing
This commit is contained in:
19
src/RecNet.Application/Common/Security/Hashing.cs
Normal file
19
src/RecNet.Application/Common/Security/Hashing.cs
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
|
|
||||||
|
namespace RecNet.Application.Common.Security;
|
||||||
|
|
||||||
|
public static class Hashing
|
||||||
|
{
|
||||||
|
public static byte[] ComputeSha256(string input)
|
||||||
|
=> SHA256.HashData(Encoding.UTF8.GetBytes(input));
|
||||||
|
|
||||||
|
public static bool VerifySha256(string input, byte[] expectedHash)
|
||||||
|
{
|
||||||
|
var computedHash = ComputeSha256(input);
|
||||||
|
|
||||||
|
return CryptographicOperations.FixedTimeEquals(
|
||||||
|
computedHash,
|
||||||
|
expectedHash);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,5 +1,7 @@
|
|||||||
using AutoMapper;
|
using AutoMapper;
|
||||||
using RecNet.Application.Common.Interfaces;
|
using RecNet.Application.Common.Interfaces;
|
||||||
|
using RecNet.Application.Common.Security;
|
||||||
|
using RecNet.Domain.Common;
|
||||||
using RecNet.Domain.GameVersions;
|
using RecNet.Domain.GameVersions;
|
||||||
using RecNet.Domain.Profiles;
|
using RecNet.Domain.Profiles;
|
||||||
using ProfileEntity = RecNet.Domain.Profiles.Profile;
|
using ProfileEntity = RecNet.Domain.Profiles.Profile;
|
||||||
@@ -130,9 +132,15 @@ public class ProfileService(
|
|||||||
command.PlatformType,
|
command.PlatformType,
|
||||||
command.PlatformId);
|
command.PlatformId);
|
||||||
|
|
||||||
|
if (command.PlatformType == PlatformType.Meta)
|
||||||
|
profile.SetMetaAuthenticationSecret(Hashing.ComputeSha256(command.PlatformAuthentication));
|
||||||
|
|
||||||
await profileRepository.AddAsync(profile, ct);
|
await profileRepository.AddAsync(profile, ct);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (command.PlatformType == PlatformType.Meta && !Hashing.VerifySha256(command.PlatformAuthentication, profile.MetaAuthenticationSecret))
|
||||||
|
return LoginProfileResult.Fail("Platform Auth Failed: Invalid authentication");
|
||||||
|
|
||||||
if (profile.IsBanned)
|
if (profile.IsBanned)
|
||||||
return LoginProfileResult.Fail("Profile is banned");
|
return LoginProfileResult.Fail("Profile is banned");
|
||||||
|
|
||||||
|
|||||||
@@ -28,6 +28,7 @@ public class Profile
|
|||||||
public PlatformType Platform { get; private set; }
|
public PlatformType Platform { get; private set; }
|
||||||
public string PlatformId { get; private set; }
|
public string PlatformId { get; private set; }
|
||||||
public List<string> DeviceIds { get; private set; } = [];
|
public List<string> DeviceIds { get; private set; } = [];
|
||||||
|
public byte[] MetaAuthenticationSecret { get; private set; } = [];
|
||||||
|
|
||||||
// EZ
|
// EZ
|
||||||
public bool IsBanned { get; private set; }
|
public bool IsBanned { get; private set; }
|
||||||
@@ -64,6 +65,9 @@ public class Profile
|
|||||||
DeviceIds.Add(deviceId);
|
DeviceIds.Add(deviceId);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public void SetMetaAuthenticationSecret(byte[] metaAuthenticationSecret)
|
||||||
|
=> MetaAuthenticationSecret = metaAuthenticationSecret;
|
||||||
|
|
||||||
public void RecordSuccessfulLogin(string deviceId, string? platformName)
|
public void RecordSuccessfulLogin(string deviceId, string? platformName)
|
||||||
{
|
{
|
||||||
if (!string.IsNullOrWhiteSpace(platformName) && Name != platformName)
|
if (!string.IsNullOrWhiteSpace(platformName) && Name != platformName)
|
||||||
|
|||||||
168
src/RecNet.Infrastructure/Persistence/Migrations/20260621202709_MetaAuthenticationSecret.Designer.cs
generated
Normal file
168
src/RecNet.Infrastructure/Persistence/Migrations/20260621202709_MetaAuthenticationSecret.Designer.cs
generated
Normal file
@@ -0,0 +1,168 @@
|
|||||||
|
// <auto-generated />
|
||||||
|
using System;
|
||||||
|
using Microsoft.EntityFrameworkCore;
|
||||||
|
using Microsoft.EntityFrameworkCore.Infrastructure;
|
||||||
|
using Microsoft.EntityFrameworkCore.Migrations;
|
||||||
|
using Microsoft.EntityFrameworkCore.Storage.ValueConversion;
|
||||||
|
using Npgsql.EntityFrameworkCore.PostgreSQL.Metadata;
|
||||||
|
using RecNet.Infrastructure.Persistence;
|
||||||
|
|
||||||
|
#nullable disable
|
||||||
|
|
||||||
|
namespace RecNet.Infrastructure.Persistence.Migrations
|
||||||
|
{
|
||||||
|
[DbContext(typeof(DatabaseContext))]
|
||||||
|
[Migration("20260621202709_MetaAuthenticationSecret")]
|
||||||
|
partial class MetaAuthenticationSecret
|
||||||
|
{
|
||||||
|
/// <inheritdoc />
|
||||||
|
protected override void BuildTargetModel(ModelBuilder modelBuilder)
|
||||||
|
{
|
||||||
|
#pragma warning disable 612, 618
|
||||||
|
modelBuilder
|
||||||
|
.HasAnnotation("ProductVersion", "10.0.8")
|
||||||
|
.HasAnnotation("Relational:MaxIdentifierLength", 63);
|
||||||
|
|
||||||
|
NpgsqlModelBuilderExtensions.UseIdentityByDefaultColumns(modelBuilder);
|
||||||
|
|
||||||
|
modelBuilder.Entity("RecNet.Domain.Configuration.ServerConfig", b =>
|
||||||
|
{
|
||||||
|
b.Property<string>("Key")
|
||||||
|
.HasMaxLength(128)
|
||||||
|
.HasColumnType("character varying(128)");
|
||||||
|
|
||||||
|
b.Property<string>("Value")
|
||||||
|
.IsRequired()
|
||||||
|
.HasColumnType("jsonb");
|
||||||
|
|
||||||
|
b.HasKey("Key");
|
||||||
|
|
||||||
|
b.ToTable("ServerConfigs");
|
||||||
|
});
|
||||||
|
|
||||||
|
modelBuilder.Entity("RecNet.Domain.GameVersions.GameVersion", b =>
|
||||||
|
{
|
||||||
|
b.Property<string>("Version")
|
||||||
|
.HasMaxLength(32)
|
||||||
|
.HasColumnType("character varying(32)");
|
||||||
|
|
||||||
|
b.Property<bool>("IsValid")
|
||||||
|
.HasColumnType("boolean");
|
||||||
|
|
||||||
|
b.HasKey("Version");
|
||||||
|
|
||||||
|
b.ToTable("GameVersions");
|
||||||
|
});
|
||||||
|
|
||||||
|
modelBuilder.Entity("RecNet.Domain.Profiles.PlayerSetting", b =>
|
||||||
|
{
|
||||||
|
b.Property<Guid>("UserId")
|
||||||
|
.HasColumnType("uuid");
|
||||||
|
|
||||||
|
b.Property<string>("Key")
|
||||||
|
.HasMaxLength(100)
|
||||||
|
.HasColumnType("character varying(100)");
|
||||||
|
|
||||||
|
b.Property<string>("Value")
|
||||||
|
.IsRequired()
|
||||||
|
.HasColumnType("text");
|
||||||
|
|
||||||
|
b.HasKey("UserId", "Key");
|
||||||
|
|
||||||
|
b.ToTable("PlayerSettings");
|
||||||
|
});
|
||||||
|
|
||||||
|
modelBuilder.Entity("RecNet.Domain.Profiles.Profile", b =>
|
||||||
|
{
|
||||||
|
b.Property<Guid>("ProfileId")
|
||||||
|
.ValueGeneratedOnAdd()
|
||||||
|
.HasColumnType("uuid");
|
||||||
|
|
||||||
|
b.Property<DateTimeOffset>("CreatedAt")
|
||||||
|
.HasColumnType("timestamp with time zone");
|
||||||
|
|
||||||
|
b.PrimitiveCollection<string>("DeviceIds")
|
||||||
|
.IsRequired()
|
||||||
|
.HasColumnType("jsonb");
|
||||||
|
|
||||||
|
b.Property<bool>("IsBanned")
|
||||||
|
.HasColumnType("boolean");
|
||||||
|
|
||||||
|
b.Property<bool>("IsModerator")
|
||||||
|
.HasColumnType("boolean");
|
||||||
|
|
||||||
|
b.Property<byte[]>("MetaAuthenticationSecret")
|
||||||
|
.IsRequired()
|
||||||
|
.HasColumnType("bytea");
|
||||||
|
|
||||||
|
b.Property<string>("Name")
|
||||||
|
.IsRequired()
|
||||||
|
.HasMaxLength(32)
|
||||||
|
.HasColumnType("character varying(32)");
|
||||||
|
|
||||||
|
b.Property<string>("Platform")
|
||||||
|
.IsRequired()
|
||||||
|
.HasMaxLength(50)
|
||||||
|
.HasColumnType("character varying(50)");
|
||||||
|
|
||||||
|
b.Property<string>("PlatformId")
|
||||||
|
.IsRequired()
|
||||||
|
.HasMaxLength(50)
|
||||||
|
.HasColumnType("character varying(50)");
|
||||||
|
|
||||||
|
b.HasKey("ProfileId");
|
||||||
|
|
||||||
|
b.HasIndex("Platform", "PlatformId")
|
||||||
|
.IsUnique();
|
||||||
|
|
||||||
|
b.ToTable("Profiles");
|
||||||
|
});
|
||||||
|
|
||||||
|
modelBuilder.Entity("RecNet.Domain.Profiles.PlayerSetting", b =>
|
||||||
|
{
|
||||||
|
b.HasOne("RecNet.Domain.Profiles.Profile", null)
|
||||||
|
.WithMany("Settings")
|
||||||
|
.HasForeignKey("UserId")
|
||||||
|
.OnDelete(DeleteBehavior.Cascade)
|
||||||
|
.IsRequired();
|
||||||
|
});
|
||||||
|
|
||||||
|
modelBuilder.Entity("RecNet.Domain.Profiles.Profile", b =>
|
||||||
|
{
|
||||||
|
b.OwnsOne("RecNet.Domain.Profiles.Avatar", "Avatar", b1 =>
|
||||||
|
{
|
||||||
|
b1.Property<Guid>("ProfileId")
|
||||||
|
.HasColumnType("uuid");
|
||||||
|
|
||||||
|
b1.Property<string>("HairColor")
|
||||||
|
.IsRequired()
|
||||||
|
.HasColumnType("text");
|
||||||
|
|
||||||
|
b1.Property<string>("OutfitSelections")
|
||||||
|
.IsRequired()
|
||||||
|
.HasColumnType("text");
|
||||||
|
|
||||||
|
b1.Property<string>("SkinColor")
|
||||||
|
.IsRequired()
|
||||||
|
.HasColumnType("text");
|
||||||
|
|
||||||
|
b1.HasKey("ProfileId");
|
||||||
|
|
||||||
|
b1.ToTable("Profiles");
|
||||||
|
|
||||||
|
b1.WithOwner()
|
||||||
|
.HasForeignKey("ProfileId");
|
||||||
|
});
|
||||||
|
|
||||||
|
b.Navigation("Avatar")
|
||||||
|
.IsRequired();
|
||||||
|
});
|
||||||
|
|
||||||
|
modelBuilder.Entity("RecNet.Domain.Profiles.Profile", b =>
|
||||||
|
{
|
||||||
|
b.Navigation("Settings");
|
||||||
|
});
|
||||||
|
#pragma warning restore 612, 618
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
using Microsoft.EntityFrameworkCore.Migrations;
|
||||||
|
|
||||||
|
#nullable disable
|
||||||
|
|
||||||
|
namespace RecNet.Infrastructure.Persistence.Migrations
|
||||||
|
{
|
||||||
|
/// <inheritdoc />
|
||||||
|
public partial class MetaAuthenticationSecret : Migration
|
||||||
|
{
|
||||||
|
/// <inheritdoc />
|
||||||
|
protected override void Up(MigrationBuilder migrationBuilder)
|
||||||
|
{
|
||||||
|
migrationBuilder.AddColumn<byte[]>(
|
||||||
|
name: "MetaAuthenticationSecret",
|
||||||
|
table: "Profiles",
|
||||||
|
type: "bytea",
|
||||||
|
nullable: false,
|
||||||
|
defaultValue: new byte[0]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// <inheritdoc />
|
||||||
|
protected override void Down(MigrationBuilder migrationBuilder)
|
||||||
|
{
|
||||||
|
migrationBuilder.DropColumn(
|
||||||
|
name: "MetaAuthenticationSecret",
|
||||||
|
table: "Profiles");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -88,6 +88,10 @@ namespace RecNet.Infrastructure.Persistence.Migrations
|
|||||||
b.Property<bool>("IsModerator")
|
b.Property<bool>("IsModerator")
|
||||||
.HasColumnType("boolean");
|
.HasColumnType("boolean");
|
||||||
|
|
||||||
|
b.Property<byte[]>("MetaAuthenticationSecret")
|
||||||
|
.IsRequired()
|
||||||
|
.HasColumnType("bytea");
|
||||||
|
|
||||||
b.Property<string>("Name")
|
b.Property<string>("Name")
|
||||||
.IsRequired()
|
.IsRequired()
|
||||||
.HasMaxLength(32)
|
.HasMaxLength(32)
|
||||||
|
|||||||
@@ -9,7 +9,9 @@ public class MetaAuthValidator : IPlatformAuthValidator
|
|||||||
public PlatformType PlatformType
|
public PlatformType PlatformType
|
||||||
=> PlatformType.Meta;
|
=> PlatformType.Meta;
|
||||||
|
|
||||||
public Task<PlatformAuthResult> ValidateAsync(string platformAuthentication, string platformId,
|
public Task<PlatformAuthResult> ValidateAsync(
|
||||||
|
string platformAuthentication,
|
||||||
|
string platformId,
|
||||||
CancellationToken ct = default)
|
CancellationToken ct = default)
|
||||||
=> Task.FromResult(PlatformAuthResult.Success(null)); // TODO: Implement
|
=> Task.FromResult(PlatformAuthResult.Success(null)); // We have a custom flow that utilizes platformAuthentication for Meta, so this gets skipped.
|
||||||
}
|
}
|
||||||
Reference in New Issue
Block a user