2021-01-05 09:33:45 +01:00
|
|
|
package domain
|
|
|
|
|
|
|
|
import (
|
2021-01-15 09:32:59 +01:00
|
|
|
"github.com/pquerna/otp"
|
|
|
|
"github.com/pquerna/otp/totp"
|
2022-04-27 01:01:45 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/crypto"
|
|
|
|
caos_errs "github.com/zitadel/zitadel/internal/errors"
|
|
|
|
es_models "github.com/zitadel/zitadel/internal/eventstore/v1/models"
|
2021-01-05 09:33:45 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
type OTP struct {
|
|
|
|
es_models.ObjectRoot
|
|
|
|
|
|
|
|
Secret *crypto.CryptoValue
|
|
|
|
SecretString string
|
|
|
|
Url string
|
|
|
|
State MFAState
|
|
|
|
}
|
2021-01-07 16:06:45 +01:00
|
|
|
|
2023-06-22 12:06:32 +02:00
|
|
|
type TOTP struct {
|
2023-06-20 12:36:21 +02:00
|
|
|
*ObjectDetails
|
|
|
|
|
|
|
|
Secret string
|
|
|
|
URI string
|
|
|
|
}
|
|
|
|
|
2021-01-15 09:32:59 +01:00
|
|
|
func NewOTPKey(issuer, accountName string, cryptoAlg crypto.EncryptionAlgorithm) (*otp.Key, *crypto.CryptoValue, error) {
|
|
|
|
key, err := totp.Generate(totp.GenerateOpts{Issuer: issuer, AccountName: accountName})
|
|
|
|
if err != nil {
|
2023-06-20 12:36:21 +02:00
|
|
|
return nil, nil, caos_errs.ThrowInternal(err, "TOTP-ieY3o", "Errors.Internal")
|
2021-01-15 09:32:59 +01:00
|
|
|
}
|
|
|
|
encryptedSecret, err := crypto.Encrypt([]byte(key.Secret()), cryptoAlg)
|
|
|
|
if err != nil {
|
|
|
|
return nil, nil, err
|
|
|
|
}
|
|
|
|
return key, encryptedSecret, nil
|
|
|
|
}
|
2021-01-07 16:06:45 +01:00
|
|
|
|
2021-01-15 09:32:59 +01:00
|
|
|
func VerifyMFAOTP(code string, secret *crypto.CryptoValue, cryptoAlg crypto.EncryptionAlgorithm) error {
|
|
|
|
decrypt, err := crypto.DecryptString(secret, cryptoAlg)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2021-01-07 16:06:45 +01:00
|
|
|
|
2021-01-15 09:32:59 +01:00
|
|
|
valid := totp.Validate(code, decrypt)
|
|
|
|
if !valid {
|
2021-10-19 09:38:35 +02:00
|
|
|
return caos_errs.ThrowInvalidArgument(nil, "EVENT-8isk2", "Errors.User.MFA.OTP.InvalidCode")
|
2021-01-15 09:32:59 +01:00
|
|
|
}
|
|
|
|
return nil
|
2021-01-07 16:06:45 +01:00
|
|
|
}
|