implements password hashing
This commit is contained in:
@@ -1,4 +1,4 @@
|
|||||||
CFLAGS := -ggdb -Wall -pedantic -lpq
|
CFLAGS := -ggdb -Wall -pedantic -lpq -lcrypto
|
||||||
|
|
||||||
SRC_DIR := src
|
SRC_DIR := src
|
||||||
OBJ_DIR := src/obj
|
OBJ_DIR := src/obj
|
||||||
|
|||||||
@@ -6,7 +6,7 @@
|
|||||||
- [x] Paging in the file list
|
- [x] Paging in the file list
|
||||||
- [x] Get files in FS by their hash
|
- [x] Get files in FS by their hash
|
||||||
- [x] Registration
|
- [x] Registration
|
||||||
- [ ] Encrypt passwords in DB
|
- [x] Encrypt passwords in DB
|
||||||
- [ ] Message to admin
|
- [ ] Message to admin
|
||||||
- [x] Advanced folder structure in the storage
|
- [x] Advanced folder structure in the storage
|
||||||
- [ ] File encryption
|
- [ ] File encryption
|
||||||
|
|||||||
@@ -1,17 +1,21 @@
|
|||||||
#include "db.h"
|
#include "db.h"
|
||||||
#include "main.h"
|
#include "main.h"
|
||||||
#include <endian.h>
|
#include <endian.h>
|
||||||
|
#include <fcntl.h>
|
||||||
#include <libpq-fe.h>
|
#include <libpq-fe.h>
|
||||||
#include <netinet/in.h>
|
#include <netinet/in.h>
|
||||||
|
#include <openssl/sha.h>
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
|
#include <unistd.h>
|
||||||
|
|
||||||
#define UNUSED(x) (void)(x)
|
#define UNUSED(x) (void)(x)
|
||||||
#define Q_LEN 128
|
#define Q_LEN 128
|
||||||
#define BIN 1
|
#define BIN 1
|
||||||
#define TEXT 0
|
#define TEXT 0
|
||||||
|
#define ENCR_SIZE 2048
|
||||||
|
|
||||||
static PGconn *conn = NULL;
|
static PGconn *conn = NULL;
|
||||||
static PGresult *res = NULL;
|
static PGresult *res = NULL;
|
||||||
@@ -93,9 +97,24 @@ int init_db_connection() {
|
|||||||
return exit_query(0);
|
return exit_query(0);
|
||||||
}
|
}
|
||||||
|
|
||||||
int32_t db_user_auth(i_auth_t *credentials, o_auth_t *response) {
|
void SHA256_raw_to_string(const unsigned char *passHashed, char *restrict out) {
|
||||||
|
int i;
|
||||||
|
for (i = 0; i < 4; i++) {
|
||||||
|
uint64_t *num_pointer = (uint64_t *)(passHashed + i * 8);
|
||||||
|
sprintf(out + 16 * i, "%016lx", htobe64(*num_pointer));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
void string_to_SHA256(const char *str, char *restrict out) {
|
||||||
|
unsigned char md[SHA256_DIGEST_LENGTH];
|
||||||
|
unsigned char *passHashed = SHA256((unsigned char *)str, strlen(str), md);
|
||||||
|
SHA256_raw_to_string(passHashed, out);
|
||||||
|
}
|
||||||
|
|
||||||
|
int32_t db_user_auth(i_auth_t *c, o_auth_t *r) {
|
||||||
const char *paramValues[1];
|
const char *paramValues[1];
|
||||||
paramValues[0] = credentials->name;
|
paramValues[0] = c->name;
|
||||||
|
char passHashed[SHA256_DIGEST_LENGTH * 2];
|
||||||
|
|
||||||
res = PQexecParams(conn,
|
res = PQexecParams(conn,
|
||||||
"SELECT id, username, password, privileges "
|
"SELECT id, username, password, privileges "
|
||||||
@@ -107,13 +126,13 @@ int32_t db_user_auth(i_auth_t *credentials, o_auth_t *response) {
|
|||||||
return exit_query(1);
|
return exit_query(1);
|
||||||
|
|
||||||
const char *pass = PQgetvalue(res, 0, 2);
|
const char *pass = PQgetvalue(res, 0, 2);
|
||||||
if (!strcmp(pass, credentials->pass)) {
|
string_to_SHA256( c->pass, passHashed);
|
||||||
response->privileges = PQgetvalue(res, 0, 3)[0];
|
if (!strcmp(passHashed, pass)) {
|
||||||
response->uid = atoi(PQgetvalue(res, 0, 0));
|
r->privileges = PQgetvalue(res, 0, 3)[0];
|
||||||
|
r->uid = atoi(PQgetvalue(res, 0, 0));
|
||||||
clearRes();
|
clearRes();
|
||||||
char u_buf[128];
|
char u_buf[128];
|
||||||
sprintf(u_buf, "UPDATE users SET last_login = NOW() WHERE id = %u",
|
sprintf(u_buf, "UPDATE users SET last_login = NOW() WHERE id = %u", r->uid);
|
||||||
response->uid);
|
|
||||||
res = PQexec(conn, u_buf);
|
res = PQexec(conn, u_buf);
|
||||||
if (PQresultStatus(res) != PGRES_TUPLES_OK && !PQntuples(res))
|
if (PQresultStatus(res) != PGRES_TUPLES_OK && !PQntuples(res))
|
||||||
return exit_query(3);
|
return exit_query(3);
|
||||||
@@ -124,16 +143,19 @@ int32_t db_user_auth(i_auth_t *credentials, o_auth_t *response) {
|
|||||||
|
|
||||||
int32_t db_user_create(i_db_user_create *args) {
|
int32_t db_user_create(i_db_user_create *args) {
|
||||||
const char *paramValues[3];
|
const char *paramValues[3];
|
||||||
|
char passHashed[SHA256_DIGEST_LENGTH * 2];
|
||||||
paramValues[0] = args->uname;
|
paramValues[0] = args->uname;
|
||||||
paramValues[1] = args->pass;
|
|
||||||
paramValues[2] = args->email;
|
paramValues[2] = args->email;
|
||||||
uint32_t ret_value;
|
uint32_t ret_value;
|
||||||
|
|
||||||
res = PQexecParams(
|
string_to_SHA256(args->pass, passHashed);
|
||||||
conn,
|
paramValues[1] = passHashed;
|
||||||
"INSERT INTO users (username, password, email, privileges, created_at, last_login)"
|
|
||||||
" VALUES ($1, $2, $3, 1, NOW(), NOW()) RETURNING id",
|
res = PQexecParams(conn,
|
||||||
3, NULL, paramValues, NULL, NULL, TEXT);
|
"INSERT INTO users (username, password, email, "
|
||||||
|
"privileges, created_at, last_login)"
|
||||||
|
" VALUES ($1, $2, $3, 1, NOW(), NOW()) RETURNING id",
|
||||||
|
3, NULL, paramValues, NULL, NULL, TEXT);
|
||||||
|
|
||||||
if (PQresultStatus(res) != PGRES_TUPLES_OK && !PQntuples(res))
|
if (PQresultStatus(res) != PGRES_TUPLES_OK && !PQntuples(res))
|
||||||
return exit_query(-1);
|
return exit_query(-1);
|
||||||
|
|||||||
Reference in New Issue
Block a user