2023-08-24 11:41:52 +02:00
|
|
|
package command
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"io"
|
|
|
|
|
|
|
|
"golang.org/x/text/language"
|
|
|
|
|
|
|
|
"github.com/zitadel/zitadel/internal/domain"
|
2024-05-31 00:08:48 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/eventstore"
|
2023-08-24 11:41:52 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/repository/session"
|
2024-05-31 00:08:48 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/repository/user"
|
2023-12-08 16:30:55 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/zerrors"
|
2023-08-24 11:41:52 +02:00
|
|
|
)
|
|
|
|
|
|
|
|
func (c *Commands) CreateOTPSMSChallengeReturnCode(dst *string) SessionCommand {
|
|
|
|
return c.createOTPSMSChallenge(true, dst)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) CreateOTPSMSChallenge() SessionCommand {
|
|
|
|
return c.createOTPSMSChallenge(false, nil)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) createOTPSMSChallenge(returnCode bool, dst *string) SessionCommand {
|
2024-05-31 00:08:48 +02:00
|
|
|
return func(ctx context.Context, cmd *SessionCommands) ([]eventstore.Command, error) {
|
2023-08-24 11:41:52 +02:00
|
|
|
if cmd.sessionWriteModel.UserID == "" {
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, zerrors.ThrowPreconditionFailed(nil, "COMMAND-JKL3g", "Errors.User.UserIDMissing")
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
writeModel := NewHumanOTPSMSWriteModel(cmd.sessionWriteModel.UserID, "")
|
|
|
|
if err := cmd.eventstore.FilterToQueryReducer(ctx, writeModel); err != nil {
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, err
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
if !writeModel.OTPAdded() {
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, zerrors.ThrowPreconditionFailed(nil, "COMMAND-BJ2g3", "Errors.User.MFA.OTP.NotReady")
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
code, err := cmd.createCode(ctx, cmd.eventstore.Filter, domain.SecretGeneratorTypeOTPSMS, cmd.otpAlg, c.defaultSecretGenerators.OTPSMS)
|
|
|
|
if err != nil {
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, err
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
if returnCode {
|
|
|
|
*dst = code.Plain
|
|
|
|
}
|
|
|
|
cmd.OTPSMSChallenged(ctx, code.Crypted, code.Expiry, returnCode)
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, nil
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) OTPSMSSent(ctx context.Context, sessionID, resourceOwner string) error {
|
|
|
|
sessionWriteModel := NewSessionWriteModel(sessionID, resourceOwner)
|
|
|
|
err := c.eventstore.FilterToQueryReducer(ctx, sessionWriteModel)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if sessionWriteModel.OTPSMSCodeChallenge == nil {
|
2023-12-08 16:30:55 +02:00
|
|
|
return zerrors.ThrowPreconditionFailed(nil, "COMMAND-G3t31", "Errors.User.Code.NotFound")
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
return c.pushAppendAndReduce(ctx, sessionWriteModel,
|
|
|
|
session.NewOTPSMSSentEvent(ctx, &session.NewAggregate(sessionID, sessionWriteModel.ResourceOwner).Aggregate),
|
|
|
|
)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) CreateOTPEmailChallengeURLTemplate(urlTmpl string) (SessionCommand, error) {
|
|
|
|
if err := domain.RenderOTPEmailURLTemplate(io.Discard, urlTmpl, "code", "userID", "loginName", "displayName", language.English); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return c.createOTPEmailChallenge(false, urlTmpl, nil), nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) CreateOTPEmailChallengeReturnCode(dst *string) SessionCommand {
|
|
|
|
return c.createOTPEmailChallenge(true, "", dst)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) CreateOTPEmailChallenge() SessionCommand {
|
|
|
|
return c.createOTPEmailChallenge(false, "", nil)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) createOTPEmailChallenge(returnCode bool, urlTmpl string, dst *string) SessionCommand {
|
2024-05-31 00:08:48 +02:00
|
|
|
return func(ctx context.Context, cmd *SessionCommands) ([]eventstore.Command, error) {
|
2023-08-24 11:41:52 +02:00
|
|
|
if cmd.sessionWriteModel.UserID == "" {
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, zerrors.ThrowPreconditionFailed(nil, "COMMAND-JK3gp", "Errors.User.UserIDMissing")
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
writeModel := NewHumanOTPEmailWriteModel(cmd.sessionWriteModel.UserID, "")
|
|
|
|
if err := cmd.eventstore.FilterToQueryReducer(ctx, writeModel); err != nil {
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, err
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
if !writeModel.OTPAdded() {
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, zerrors.ThrowPreconditionFailed(nil, "COMMAND-JKLJ3", "Errors.User.MFA.OTP.NotReady")
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
code, err := cmd.createCode(ctx, cmd.eventstore.Filter, domain.SecretGeneratorTypeOTPEmail, cmd.otpAlg, c.defaultSecretGenerators.OTPEmail)
|
|
|
|
if err != nil {
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, err
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
if returnCode {
|
|
|
|
*dst = code.Plain
|
|
|
|
}
|
|
|
|
cmd.OTPEmailChallenged(ctx, code.Crypted, code.Expiry, returnCode, urlTmpl)
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, nil
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) OTPEmailSent(ctx context.Context, sessionID, resourceOwner string) error {
|
|
|
|
sessionWriteModel := NewSessionWriteModel(sessionID, resourceOwner)
|
|
|
|
err := c.eventstore.FilterToQueryReducer(ctx, sessionWriteModel)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if sessionWriteModel.OTPEmailCodeChallenge == nil {
|
2023-12-08 16:30:55 +02:00
|
|
|
return zerrors.ThrowPreconditionFailed(nil, "COMMAND-SLr02", "Errors.User.Code.NotFound")
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
return c.pushAppendAndReduce(ctx, sessionWriteModel,
|
|
|
|
session.NewOTPEmailSentEvent(ctx, &session.NewAggregate(sessionID, sessionWriteModel.ResourceOwner).Aggregate),
|
|
|
|
)
|
|
|
|
}
|
|
|
|
|
|
|
|
func CheckOTPSMS(code string) SessionCommand {
|
2024-05-31 00:08:48 +02:00
|
|
|
return func(ctx context.Context, cmd *SessionCommands) (_ []eventstore.Command, err error) {
|
|
|
|
writeModel := func(ctx context.Context, userID string, resourceOwner string) (OTPCodeWriteModel, error) {
|
|
|
|
otpWriteModel := NewHumanOTPSMSCodeWriteModel(cmd.sessionWriteModel.UserID, "")
|
|
|
|
err := cmd.eventstore.FilterToQueryReducer(ctx, otpWriteModel)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
// explicitly set the challenge from the session write model since the code write model will only check user events
|
|
|
|
otpWriteModel.otpCode = cmd.sessionWriteModel.OTPSMSCodeChallenge
|
|
|
|
return otpWriteModel, nil
|
|
|
|
}
|
|
|
|
succeededEvent := func(ctx context.Context, aggregate *eventstore.Aggregate, info *user.AuthRequestInfo) eventstore.Command {
|
|
|
|
return user.NewHumanOTPSMSCheckSucceededEvent(ctx, aggregate, nil)
|
|
|
|
}
|
|
|
|
failedEvent := func(ctx context.Context, aggregate *eventstore.Aggregate, info *user.AuthRequestInfo) eventstore.Command {
|
|
|
|
return user.NewHumanOTPSMSCheckFailedEvent(ctx, aggregate, nil)
|
|
|
|
}
|
|
|
|
commands, err := checkOTP(ctx, cmd.sessionWriteModel.UserID, code, "", nil, writeModel, cmd.eventstore.FilterToQueryReducer, cmd.otpAlg, succeededEvent, failedEvent)
|
2023-08-24 11:41:52 +02:00
|
|
|
if err != nil {
|
2024-05-31 00:08:48 +02:00
|
|
|
return commands, err
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
2024-05-31 00:08:48 +02:00
|
|
|
cmd.eventCommands = append(cmd.eventCommands, commands...)
|
2023-08-24 11:41:52 +02:00
|
|
|
cmd.OTPSMSChecked(ctx, cmd.now())
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, nil
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func CheckOTPEmail(code string) SessionCommand {
|
2024-05-31 00:08:48 +02:00
|
|
|
return func(ctx context.Context, cmd *SessionCommands) (_ []eventstore.Command, err error) {
|
|
|
|
writeModel := func(ctx context.Context, userID string, resourceOwner string) (OTPCodeWriteModel, error) {
|
|
|
|
otpWriteModel := NewHumanOTPEmailCodeWriteModel(cmd.sessionWriteModel.UserID, "")
|
|
|
|
err := cmd.eventstore.FilterToQueryReducer(ctx, otpWriteModel)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
// explicitly set the challenge from the session write model since the code write model will only check user events
|
|
|
|
otpWriteModel.otpCode = cmd.sessionWriteModel.OTPEmailCodeChallenge
|
|
|
|
return otpWriteModel, nil
|
|
|
|
}
|
|
|
|
succeededEvent := func(ctx context.Context, aggregate *eventstore.Aggregate, info *user.AuthRequestInfo) eventstore.Command {
|
|
|
|
return user.NewHumanOTPEmailCheckSucceededEvent(ctx, aggregate, nil)
|
|
|
|
}
|
|
|
|
failedEvent := func(ctx context.Context, aggregate *eventstore.Aggregate, info *user.AuthRequestInfo) eventstore.Command {
|
|
|
|
return user.NewHumanOTPEmailCheckFailedEvent(ctx, aggregate, nil)
|
|
|
|
}
|
|
|
|
commands, err := checkOTP(ctx, cmd.sessionWriteModel.UserID, code, "", nil, writeModel, cmd.eventstore.FilterToQueryReducer, cmd.otpAlg, succeededEvent, failedEvent)
|
2023-08-24 11:41:52 +02:00
|
|
|
if err != nil {
|
2024-05-31 00:08:48 +02:00
|
|
|
return commands, err
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
2024-05-31 00:08:48 +02:00
|
|
|
cmd.eventCommands = append(cmd.eventCommands, commands...)
|
2023-08-24 11:41:52 +02:00
|
|
|
cmd.OTPEmailChecked(ctx, cmd.now())
|
2024-05-31 00:08:48 +02:00
|
|
|
return nil, nil
|
2023-08-24 11:41:52 +02:00
|
|
|
}
|
|
|
|
}
|