Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7bc6086509 | ||
|
|
a03fafebcf |
@@ -1,5 +1,4 @@
|
||||
using SimpleHttpServer.Internal;
|
||||
using SimpleHttpServer.Types;
|
||||
|
||||
namespace SimpleHttpServer;
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
namespace SimpleHttpServer.Types;
|
||||
namespace SimpleHttpServer;
|
||||
|
||||
public enum HttpRequestType {
|
||||
GET,
|
||||
+23
-125
@@ -4,7 +4,6 @@ using SimpleHttpServer.Types.ParameterConverters;
|
||||
using System.Net;
|
||||
using System.Numerics;
|
||||
using System.Reflection;
|
||||
using System.Text;
|
||||
|
||||
namespace SimpleHttpServer;
|
||||
|
||||
@@ -14,8 +13,7 @@ public sealed class HttpServer {
|
||||
|
||||
private readonly HttpListener listener;
|
||||
private Task? listenerTask;
|
||||
private readonly Logger mainLogger;
|
||||
private readonly Logger requestLogger;
|
||||
private readonly Logger logger;
|
||||
private readonly SimpleHttpServerConfiguration conf;
|
||||
private bool shutdown = false;
|
||||
|
||||
@@ -24,20 +22,19 @@ public sealed class HttpServer {
|
||||
conf = configuration;
|
||||
listener = new HttpListener();
|
||||
listener.Prefixes.Add($"http://localhost:{port}/");
|
||||
mainLogger = new(LogOutputTopic.Main, conf);
|
||||
requestLogger = new(LogOutputTopic.Request, conf);
|
||||
logger = new(LogOutputTopic.Main, conf);
|
||||
}
|
||||
|
||||
public void Start() {
|
||||
mainLogger.Information($"Starting on port {Port}...");
|
||||
logger.Information($"Starting on port {Port}...");
|
||||
Assert(listenerTask == null, "Server was already started!");
|
||||
listener.Start();
|
||||
listenerTask = Task.Run(GetContextLoopAsync);
|
||||
mainLogger.Information($"Ready to handle requests!");
|
||||
logger.Information($"Ready to handle requests!");
|
||||
}
|
||||
|
||||
public async Task StopAsync(CancellationToken ctok) {
|
||||
mainLogger.Information("Stopping server...");
|
||||
logger.Information("Stopping server...");
|
||||
Assert(listenerTask != null, "Server was not started!");
|
||||
shutdown = true;
|
||||
listener.Stop();
|
||||
@@ -49,9 +46,8 @@ public sealed class HttpServer {
|
||||
try {
|
||||
var ctx = await listener.GetContextAsync();
|
||||
_ = ProcessRequestAsync(ctx);
|
||||
} catch (HttpListenerException ex) when (ex.ErrorCode == 995) { //The I/O operation has been aborted because of either a thread exit or an application request
|
||||
} catch (Exception ex) {
|
||||
mainLogger.Fatal($"Caught otherwise uncaught exception in GetContextLoop:\n{ex}");
|
||||
logger.Fatal($"Caught otherwise uncaught exception in GetContextLoop:\n{ex}");
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -60,7 +56,6 @@ public sealed class HttpServer {
|
||||
void RegisterConverter<T>() where T : IParsable<T> {
|
||||
stringToTypeParameterConverters.Add(typeof(T), new ParsableParameterConverter<T>());
|
||||
}
|
||||
stringToTypeParameterConverters.Add(typeof(string), new StringParameterConverter());
|
||||
|
||||
stringToTypeParameterConverters.Add(typeof(bool), new BoolParsableParameterConverter());
|
||||
RegisterConverter<char>();
|
||||
@@ -114,7 +109,7 @@ public sealed class HttpServer {
|
||||
var par = methodParams[i];
|
||||
var attr = par.GetCustomAttribute<ParameterAttribute>(false);
|
||||
qparams.Add((attr?.Name ?? par.Name ?? throw new ArgumentException($"C# variable name of parameter at index {i} of method {GetFancyMethodName()} is null!"),
|
||||
(par.ParameterType, attr?.IsOptional ?? false)));
|
||||
(par.GetType(), attr?.IsOptional ?? false)));
|
||||
|
||||
if (!stringToTypeParameterConverters.ContainsKey(par.ParameterType)) {
|
||||
throw new MissingParameterConverterException($"Parameter converter for type {par.ParameterType} has not been registered (yet)!");
|
||||
@@ -122,84 +117,30 @@ public sealed class HttpServer {
|
||||
}
|
||||
|
||||
foreach (var location in attrib.Locations) {
|
||||
var normLocation = NormalizeUrlPath(location);
|
||||
int idx = normLocation.IndexOf('{');
|
||||
int idx = location.IndexOf('{');
|
||||
if (idx >= 0) {
|
||||
// this path contains path parameters
|
||||
throw new NotImplementedException("Path parameters are not yet implemented!");
|
||||
}
|
||||
|
||||
var reqMethod = Enum.GetName(attrib.RequestMethod) ?? throw new ArgumentException("Request method was undefined");
|
||||
mainLogger.Information($"Registered endpoint: '{reqMethod} {normLocation}'");
|
||||
simpleEndpointMethodInfos.Add((normLocation, reqMethod), new EndpointInvocationInfo(mi, qparams));
|
||||
simpleEndpointMethodInfos.Add((location, reqMethod), new EndpointInvocationInfo(mi, qparams));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Serves all files located in <paramref name="filesystemDirectory"/> on a website path that is relative to <paramref name="requestPath"/>,
|
||||
/// while restricting requests to inside the local filesystem directory. Static serving has a lower priority than registering an endpoint.
|
||||
/// </summary>
|
||||
/// <param name="requestPath"></param>
|
||||
/// <param name="filesystemDirectory"></param>
|
||||
public void RegisterStaticServePath(string requestPath, string filesystemDirectory) {
|
||||
var absPath = Path.GetFullPath(filesystemDirectory);
|
||||
string npath = NormalizeUrlPath(requestPath);
|
||||
mainLogger.Information($"Registered static serve path: '{npath}' --> '{absPath}'");
|
||||
staticServePaths.Add(npath, absPath);
|
||||
}
|
||||
|
||||
private readonly Dictionary<string, string> staticServePaths = new Dictionary<string, string>();
|
||||
|
||||
private readonly Dictionary<Type, IParameterConverter> stringToTypeParameterConverters = new();
|
||||
|
||||
private static string NormalizeUrlPath(string url) {
|
||||
var fwdSlashUrl = url.Replace('\\', '/');
|
||||
|
||||
var segments = fwdSlashUrl.Trim('/').Split('/', StringSplitOptions.RemoveEmptyEntries).ToList();
|
||||
List<string> simplifiedSegmentsReversed = new List<string>();
|
||||
int doubleDotsEncountered = 0;
|
||||
for (int i = segments.Count - 1; i >= 0; i--) {
|
||||
var segment = segments[i];
|
||||
if (segment == ".") {
|
||||
continue; // remove single dot segments
|
||||
}
|
||||
if (segment == "..") {
|
||||
doubleDotsEncountered++; // if we encounter a doubledot, keep track of that and dont add it to the output yet
|
||||
continue;
|
||||
}
|
||||
// otherwise only keep the segment if doubleDotsEncountered > 0
|
||||
if (doubleDotsEncountered > 0) {
|
||||
doubleDotsEncountered--;
|
||||
continue;
|
||||
}
|
||||
simplifiedSegmentsReversed.Add(segment);
|
||||
}
|
||||
|
||||
var rv = new StringBuilder();
|
||||
for (int i = 0; i < doubleDotsEncountered; i++) {
|
||||
rv.Append("../");
|
||||
}
|
||||
rv.AppendJoin('/', simplifiedSegmentsReversed.Reverse<string>());
|
||||
|
||||
return '/' + (rv.ToString().TrimEnd('/') + (fwdSlashUrl.EndsWith('/') ? "/" : "")).TrimStart('/');
|
||||
}
|
||||
|
||||
private async Task ProcessRequestAsync(HttpListenerContext ctx) {
|
||||
using RequestContext rc = new RequestContext(ctx);
|
||||
|
||||
// TODO add path escape countermeasure-unittests
|
||||
var splitted = (ctx.Request.RawUrl ?? "").Split('?', 2, StringSplitOptions.None);
|
||||
var reqPath = NormalizeUrlPath(WebUtility.UrlDecode(splitted.First()));
|
||||
string requestMethod = ctx.Request.HttpMethod.ToUpperInvariant();
|
||||
bool wasStaticlyServed = false;
|
||||
|
||||
void LogRequest() {
|
||||
requestLogger.Information($"{rc.ListenerContext.Response.StatusCode} {(wasStaticlyServed ? "static" : "endpnt")} {requestMethod} {ctx.Request.Url}");
|
||||
}
|
||||
try {
|
||||
var decUri = WebUtility.UrlDecode(ctx.Request.RawUrl)!; // TODO add path escape countermeasures+unittests
|
||||
var splitted = decUri.Split('?', 2, StringSplitOptions.None);
|
||||
var path = WebUtility.UrlDecode(splitted.First());
|
||||
|
||||
if (simpleEndpointMethodInfos.TryGetValue((reqPath, requestMethod), out var endpointInvocationInfo)) {
|
||||
|
||||
using var rc = new RequestContext(ctx);
|
||||
if (simpleEndpointMethodInfos.TryGetValue((decUri, ctx.Request.HttpMethod.ToUpperInvariant()), out var endpointInvocationInfo)) {
|
||||
var mi = endpointInvocationInfo.methodInfo;
|
||||
var qparams = endpointInvocationInfo.queryParameters;
|
||||
var args = splitted.Length == 2 ? splitted[1] : null;
|
||||
@@ -214,11 +155,11 @@ public sealed class HttpServer {
|
||||
foreach (var queryKV in queryStringArgs) {
|
||||
var queryKVSplitted = queryKV.Split('=');
|
||||
if (queryKVSplitted.Length != 2) {
|
||||
await HandleDefaultErrorPageAsync(rc, HttpStatusCode.BadRequest, "Malformed request URL parameters");
|
||||
rc.SetStatusCodeAndDispose(HttpStatusCode.BadRequest, "Malformed request URL parameters");
|
||||
return;
|
||||
}
|
||||
if (!parsedQParams.TryAdd(WebUtility.UrlDecode(queryKVSplitted[0]), WebUtility.UrlDecode(queryKVSplitted[1]))) {
|
||||
await HandleDefaultErrorPageAsync(rc, HttpStatusCode.BadRequest, "Duplicate request URL parameters");
|
||||
rc.SetStatusCodeAndDispose(HttpStatusCode.BadRequest, "Duplicate request URL parameters");
|
||||
return;
|
||||
}
|
||||
}
|
||||
@@ -231,82 +172,39 @@ public sealed class HttpServer {
|
||||
if (stringToTypeParameterConverters[qparamInfo.type].TryConvertFromString(qparamValue, out object objRes)) {
|
||||
convertedQParamValues[i] = objRes;
|
||||
} else {
|
||||
await HandleDefaultErrorPageAsync(rc, HttpStatusCode.BadRequest);
|
||||
rc.SetStatusCodeAndDispose(HttpStatusCode.BadRequest);
|
||||
return;
|
||||
}
|
||||
} else {
|
||||
if (qparamInfo.isOptional) {
|
||||
convertedQParamValues[i] = null!;
|
||||
} else {
|
||||
await HandleDefaultErrorPageAsync(rc, HttpStatusCode.BadRequest, $"Missing required query parameter {qparamName}");
|
||||
rc.SetStatusCodeAndDispose(HttpStatusCode.BadRequest, $"Missing required query parameter {qparamName}");
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
convertedQParamValues[0] = rc;
|
||||
rc.ParsedParameters = parsedQParams.AsReadOnly();
|
||||
|
||||
await (Task) (mi.Invoke(null, convertedQParamValues) ?? throw new NullReferenceException("Website func returned null unexpectedly"));
|
||||
} else {
|
||||
if (requestMethod == "GET")
|
||||
foreach (var (k, v) in staticServePaths) {
|
||||
if (reqPath.StartsWith(k)) { // do a static serve
|
||||
wasStaticlyServed = true;
|
||||
var relativeStaticReqPath = reqPath[k.Length..];
|
||||
var staticResponsePath = Path.GetFullPath(Path.Join(v, relativeStaticReqPath.TrimStart('/')));
|
||||
|
||||
if (Path.GetRelativePath(v, staticResponsePath).Contains("..")) {
|
||||
requestLogger.Warning($"Blocked GET request to {reqPath} as somehow the target file does not lie inside the static serve folder? Are you using symlinks?");
|
||||
await HandleDefaultErrorPageAsync(rc, HttpStatusCode.NotFound);
|
||||
return;
|
||||
}
|
||||
|
||||
if (File.Exists(staticResponsePath)) {
|
||||
rc.SetStatusCode(HttpStatusCode.OK);
|
||||
if (staticResponsePath.EndsWith(".svg")) {
|
||||
rc.ListenerContext.Response.AddHeader("Content-Type", "image/svg+xml");
|
||||
}
|
||||
using var f = File.OpenRead(staticResponsePath);
|
||||
await f.CopyToAsync(rc.ListenerContext.Response.OutputStream);
|
||||
} else {
|
||||
await HandleDefaultErrorPageAsync(rc, HttpStatusCode.NotFound);
|
||||
}
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
// invoke 404
|
||||
await HandleDefaultErrorPageAsync(rc, 404);
|
||||
}
|
||||
|
||||
} catch (Exception ex) {
|
||||
await HandleDefaultErrorPageAsync(rc, 500);
|
||||
mainLogger.Fatal($"Caught otherwise uncaught exception while ProcessingRequest:\n{ex}");
|
||||
} finally {
|
||||
try { await rc.RespWriter.FlushAsync(); } catch (ObjectDisposedException) { }
|
||||
rc.ListenerContext.Response.Close();
|
||||
LogRequest();
|
||||
logger.Fatal($"Caught otherwise uncaught exception while ProcessingRequest:\n{ex}");
|
||||
}
|
||||
}
|
||||
|
||||
private static async Task HandleDefaultErrorPageAsync(RequestContext ctx, HttpStatusCode errorCode, string? statusDescription = null) => await HandleDefaultErrorPageAsync(ctx, (int) errorCode, statusDescription);
|
||||
|
||||
private static async Task HandleDefaultErrorPageAsync(RequestContext ctx, int errorCode, string? statusDescription = null) {
|
||||
ctx.SetStatusCode(errorCode);
|
||||
string desc = statusDescription != null ? $"\r\n{statusDescription}" : "";
|
||||
private static async Task HandleDefaultErrorPageAsync(RequestContext ctx, int errorCode) {
|
||||
await ctx.WriteLineToRespAsync($"""
|
||||
<body>
|
||||
<h1>Oh no, an error occurred!</h1>
|
||||
<p>Code: {errorCode}</p>{desc}
|
||||
<h1>Oh no, and error occurred!</h1>
|
||||
<p>Code: {errorCode}</p>
|
||||
</body>
|
||||
""");
|
||||
try {
|
||||
if (statusDescription == null) {
|
||||
await ctx.SetStatusCodeAndDisposeAsync(errorCode);
|
||||
} else {
|
||||
await ctx.SetStatusCodeAndDisposeAsync(errorCode, statusDescription);
|
||||
}
|
||||
} catch (ObjectDisposedException) { }
|
||||
}
|
||||
}
|
||||
@@ -1,81 +1,73 @@
|
||||
using Newtonsoft.Json;
|
||||
using System.Diagnostics.CodeAnalysis;
|
||||
using Konscious.Security.Cryptography;
|
||||
using Newtonsoft.Json;
|
||||
using System.Security.Cryptography;
|
||||
using System.Text;
|
||||
|
||||
namespace SimpleHttpServer.Login;
|
||||
|
||||
internal struct SerialLoginData {
|
||||
public string passwordSalt;
|
||||
public string extraDataSalt;
|
||||
public string salt;
|
||||
public string pwd;
|
||||
public string extraData;
|
||||
public string additionalData;
|
||||
|
||||
public LoginData ToPlainData() {
|
||||
public LoginData toPlainData() {
|
||||
return new LoginData {
|
||||
passwordSalt = Convert.FromBase64String(passwordSalt),
|
||||
extraDataSalt = Convert.FromBase64String(extraDataSalt)
|
||||
salt = Convert.FromBase64String(salt),
|
||||
password = Convert.FromBase64String(pwd)
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
internal struct LoginData {
|
||||
public byte[] passwordSalt;
|
||||
public byte[] extraDataSalt;
|
||||
public byte[] passwordHash;
|
||||
public byte[] encryptedExtraData;
|
||||
public byte[] salt;
|
||||
public byte[] password;
|
||||
public byte[] encryptedData;
|
||||
|
||||
public SerialLoginData ToSerial() {
|
||||
public SerialLoginData toSerial() {
|
||||
return new SerialLoginData {
|
||||
passwordSalt = Convert.ToBase64String(passwordSalt),
|
||||
extraDataSalt = Convert.ToBase64String(extraDataSalt),
|
||||
pwd = Convert.ToBase64String(passwordHash),
|
||||
extraData = Convert.ToBase64String(encryptedExtraData)
|
||||
salt = Convert.ToBase64String(salt),
|
||||
pwd = Convert.ToBase64String(password),
|
||||
additionalData = Convert.ToBase64String(encryptedData)
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
internal struct LoginDataProviderConfig {
|
||||
|
||||
/// <summary>
|
||||
/// Size of the password salt and the extradata salt. So each salt will be of size <see cref="SALT_SIZE"/>.
|
||||
/// </summary>
|
||||
public int SALT_SIZE = 32;
|
||||
public int KEY_LENGTH = 256 / 8;
|
||||
public int A2_ITERATIONS = 5;
|
||||
public int A2_MEMORY_SIZE = 500_000;
|
||||
public int A2_PARALLELISM = 8;
|
||||
public int A2_HASH_LENGTH = 256 / 8;
|
||||
public int A2_MAX_CONCURRENT = 4;
|
||||
public int PBKDF2_ITERATIONS = 600_000;
|
||||
|
||||
public LoginDataProviderConfig() { }
|
||||
}
|
||||
|
||||
public class LoginProvider<TExtraData> {
|
||||
public class LoginProvider<T> {
|
||||
|
||||
private static readonly Func<TExtraData, byte[]> JsonSerialize = t => Encoding.UTF8.GetBytes(JsonConvert.SerializeObject(t));
|
||||
private static readonly Func<byte[], TExtraData> JsonDeserialize = b => JsonConvert.DeserializeObject<TExtraData>(Encoding.UTF8.GetString(b))!;
|
||||
|
||||
[ThreadStatic]
|
||||
private static SHA256? _sha256PerThread;
|
||||
private static SHA256 Sha256PerThread { get => _sha256PerThread ??= SHA256.Create(); }
|
||||
private static readonly Func<T, byte[]> JsonSerialize = t => Encoding.UTF8.GetBytes(JsonConvert.SerializeObject(t));
|
||||
private static readonly Func<byte[], T> JsonDeserialize = b => JsonConvert.DeserializeObject<T>(Encoding.UTF8.GetString(b))!;
|
||||
|
||||
private readonly LoginDataProviderConfig config;
|
||||
private readonly ReaderWriterLockSlim ldLock = new ReaderWriterLockSlim(LockRecursionPolicy.SupportsRecursion);
|
||||
private readonly string ldPath;
|
||||
private readonly Dictionary<string, LoginData> loginDatas;
|
||||
|
||||
private Func<TExtraData, byte[]> DataSerializer = JsonSerialize;
|
||||
private Func<byte[], TExtraData> DataDeserializer = JsonDeserialize;
|
||||
public void SetDataSerializers(Func<TExtraData, byte[]> serializer, Func<byte[], TExtraData> deserializer) {
|
||||
DataSerializer = serializer ?? JsonSerialize;
|
||||
DataDeserializer = deserializer ?? JsonDeserialize;
|
||||
}
|
||||
private readonly Dictionary<string, LoginData> loginData;
|
||||
private readonly SemaphoreSlim argon2Limit;
|
||||
|
||||
private Func<T, byte[]> DataSerializer = JsonSerialize;
|
||||
private Func<byte[], T> DataDeserializer = JsonDeserialize;
|
||||
|
||||
public LoginProvider(string ldPath, string confPath) {
|
||||
this.ldPath = ldPath;
|
||||
loginDatas = LoadLoginDatas(ldPath);
|
||||
config = LoadLoginProviderConfig(confPath);
|
||||
loginData = LoadLoginData(ldPath);
|
||||
config = LoadArgon2Config(confPath);
|
||||
argon2Limit = new SemaphoreSlim(config.A2_MAX_CONCURRENT);
|
||||
}
|
||||
|
||||
private static Dictionary<string, LoginData> LoadLoginDatas(string path) {
|
||||
private static Dictionary<string, LoginData> LoadLoginData(string path) {
|
||||
Dictionary<string, SerialLoginData> tempData;
|
||||
if (!File.Exists(path)) {
|
||||
File.WriteAllText(path, "{}", Encoding.UTF8);
|
||||
@@ -87,26 +79,13 @@ public class LoginProvider<TExtraData> {
|
||||
}
|
||||
}
|
||||
var ld = new Dictionary<string, LoginData>();
|
||||
foreach (var pair in tempData) {
|
||||
ld.Add(pair.Key, pair.Value.ToPlainData());
|
||||
foreach (var pair in tempData!) {
|
||||
ld.Add(pair.Key, pair.Value.toPlainData());
|
||||
}
|
||||
return ld;
|
||||
}
|
||||
|
||||
private void SaveLoginData() {
|
||||
var serial = new Dictionary<string, SerialLoginData>();
|
||||
ldLock.EnterWriteLock();
|
||||
try {
|
||||
foreach (var pair in loginDatas) {
|
||||
serial.Add(pair.Key, pair.Value.ToSerial());
|
||||
}
|
||||
} finally {
|
||||
ldLock.ExitWriteLock();
|
||||
}
|
||||
File.WriteAllText(ldPath, JsonConvert.SerializeObject(serial));
|
||||
}
|
||||
|
||||
private static LoginDataProviderConfig LoadLoginProviderConfig(string path) {
|
||||
private static LoginDataProviderConfig LoadArgon2Config(string path) {
|
||||
if (!File.Exists(path)) {
|
||||
var conf = new LoginDataProviderConfig();
|
||||
File.WriteAllText(path, JsonConvert.SerializeObject(conf));
|
||||
@@ -115,22 +94,39 @@ public class LoginProvider<TExtraData> {
|
||||
return JsonConvert.DeserializeObject<LoginDataProviderConfig>(File.ReadAllText(path));
|
||||
}
|
||||
|
||||
public bool AddUser(string username, string password, TExtraData additional) {
|
||||
public void SetDataSerialization(Func<T, byte[]> serializer, Func<byte[], T> deserializer) {
|
||||
DataSerializer = serializer ?? JsonSerialize;
|
||||
DataDeserializer = deserializer ?? JsonDeserialize;
|
||||
}
|
||||
|
||||
private void StoreLoginData() {
|
||||
var serial = new Dictionary<string, SerialLoginData>();
|
||||
ldLock.EnterWriteLock();
|
||||
try {
|
||||
if (loginDatas.ContainsKey(username)) {
|
||||
foreach (var pair in loginData!) {
|
||||
serial.Add(pair.Key, pair.Value.toSerial());
|
||||
}
|
||||
} finally {
|
||||
ldLock.ExitWriteLock();
|
||||
}
|
||||
File.WriteAllText(ldPath, JsonConvert.SerializeObject(serial));
|
||||
}
|
||||
|
||||
public bool AddUser(string username, string password, T additional) {
|
||||
ldLock.EnterWriteLock();
|
||||
try {
|
||||
if (loginData.ContainsKey(username)) {
|
||||
return false;
|
||||
}
|
||||
var passwordSalt = RandomNumberGenerator.GetBytes(config.SALT_SIZE);
|
||||
var extraDataSalt = RandomNumberGenerator.GetBytes(config.SALT_SIZE);
|
||||
var salt = RandomNumberGenerator.GetBytes(config.SALT_SIZE);
|
||||
var pwdHash = HashPwd(password, salt);
|
||||
LoginData ld = new LoginData() {
|
||||
passwordSalt = passwordSalt,
|
||||
extraDataSalt = extraDataSalt,
|
||||
passwordHash = ComputeSaltedSha256Hash(password, passwordSalt),
|
||||
encryptedExtraData = EncryptExtraData(password, extraDataSalt, additional),
|
||||
salt = salt,
|
||||
password = pwdHash,
|
||||
encryptedData = EncryptAdditionalData(password, salt, additional)
|
||||
};
|
||||
loginDatas.Add(username, ld);
|
||||
SaveLoginData();
|
||||
loginData.Add(username, ld);
|
||||
StoreLoginData();
|
||||
} finally {
|
||||
ldLock.ExitWriteLock();
|
||||
}
|
||||
@@ -140,9 +136,9 @@ public class LoginProvider<TExtraData> {
|
||||
public bool RemoveUser(string username) {
|
||||
ldLock.EnterWriteLock();
|
||||
try {
|
||||
var removed = loginDatas.Remove(username);
|
||||
var removed = loginData.Remove(username);
|
||||
if (removed) {
|
||||
SaveLoginData();
|
||||
StoreLoginData();
|
||||
}
|
||||
return removed;
|
||||
} finally {
|
||||
@@ -150,62 +146,64 @@ public class LoginProvider<TExtraData> {
|
||||
}
|
||||
}
|
||||
|
||||
public bool ModifyUser(string username, string newPassword, TExtraData newExtraData) {
|
||||
public bool ModifyUser(string username, string newPassword, T newAdditional) {
|
||||
ldLock.EnterWriteLock();
|
||||
try {
|
||||
if (!loginDatas.ContainsKey(username)) {
|
||||
if (!loginData.ContainsKey(username)) {
|
||||
return false;
|
||||
}
|
||||
loginDatas.Remove(username, out var data);
|
||||
data.passwordHash = ComputeSaltedSha256Hash(newPassword, data.passwordSalt);
|
||||
data.encryptedExtraData = EncryptExtraData(newPassword, data.extraDataSalt, newExtraData);
|
||||
loginDatas.Add(username, data);
|
||||
SaveLoginData();
|
||||
loginData.Remove(username, out var data);
|
||||
data.password = HashPwd(newPassword, data.salt);
|
||||
data.encryptedData = EncryptAdditionalData(newPassword, data.salt, newAdditional);
|
||||
loginData.Add(username, data);
|
||||
StoreLoginData();
|
||||
} finally {
|
||||
ldLock.ExitWriteLock();
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
public bool TryAuthenticate(string username, string password, [MaybeNullWhen(false)] out TExtraData extraData) {
|
||||
public (bool, T) Authenticate(string username, string password) {
|
||||
LoginData data;
|
||||
ldLock.EnterReadLock();
|
||||
try {
|
||||
if (!loginDatas.TryGetValue(username, out data)) {
|
||||
extraData = default;
|
||||
return false;
|
||||
if (!loginData.TryGetValue(username, out data)) {
|
||||
return (false, default(T)!);
|
||||
}
|
||||
} finally {
|
||||
ldLock.ExitReadLock();
|
||||
}
|
||||
var hash = ComputeSaltedSha256Hash(password, data.passwordSalt);
|
||||
if (!hash.SequenceEqual(data.passwordHash)) {
|
||||
extraData = default;
|
||||
return false;
|
||||
var hash = HashPwd(password, data.salt);
|
||||
if (!hash.SequenceEqual(data.password)) {
|
||||
return (false, default(T)!);
|
||||
}
|
||||
extraData = DecryptExtraData(password, data.extraDataSalt, data.encryptedExtraData);
|
||||
return true;
|
||||
return (true, DecryptAdditionalData(password, data.salt, data.encryptedData));
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Threadsafe as the SHA256 instance (<see cref="Sha256PerThread"/>) is per thread.
|
||||
/// </summary>
|
||||
/// <param name="data"></param>
|
||||
/// <param name="salt"></param>
|
||||
/// <returns></returns>
|
||||
private static byte[] ComputeSaltedSha256Hash(string data, byte[] salt) {
|
||||
var dataBytes = Encoding.UTF8.GetBytes(data);
|
||||
var buf = new byte[data.Length + salt.Length];
|
||||
Buffer.BlockCopy(dataBytes, 0, buf, 0, dataBytes.Length);
|
||||
Buffer.BlockCopy(salt, 0, buf, dataBytes.Length, salt.Length);
|
||||
return Sha256PerThread.ComputeHash(buf);
|
||||
private byte[] HashPwd(string pwd, byte[] salt) {
|
||||
byte[] hash;
|
||||
argon2Limit.Wait();
|
||||
try {
|
||||
using (var argon2 = new Argon2id(Encoding.UTF8.GetBytes(pwd))) {
|
||||
argon2.Iterations = config.A2_ITERATIONS;
|
||||
argon2.MemorySize = config.A2_MEMORY_SIZE;
|
||||
argon2.DegreeOfParallelism = config.A2_PARALLELISM;
|
||||
argon2.Salt = salt;
|
||||
hash = argon2.GetBytes(config.A2_HASH_LENGTH);
|
||||
}
|
||||
// force collection to reduce sustained memory usage if many hashes are done in close time proximity to each other
|
||||
GC.Collect();
|
||||
} finally {
|
||||
argon2Limit.Release();
|
||||
}
|
||||
return hash;
|
||||
}
|
||||
|
||||
private byte[] EncryptExtraData(string pwd, byte[] salt, TExtraData extraData) {
|
||||
private byte[] EncryptAdditionalData(string pwd, byte[] salt, T data) {
|
||||
var pbkdf2 = new Rfc2898DeriveBytes(Encoding.UTF8.GetBytes(pwd), salt, config.PBKDF2_ITERATIONS, HashAlgorithmName.SHA256);
|
||||
var key = pbkdf2.GetBytes(config.KEY_LENGTH / 8);
|
||||
|
||||
var plainBytes = DataSerializer(extraData);
|
||||
var plainBytes = DataSerializer(data);
|
||||
using var aes = Aes.Create();
|
||||
aes.KeySize = config.KEY_LENGTH;
|
||||
aes.Key = key;
|
||||
@@ -221,7 +219,7 @@ public class LoginProvider<TExtraData> {
|
||||
return encryptedBytes;
|
||||
}
|
||||
|
||||
private TExtraData DecryptExtraData(string pwd, byte[] salt, byte[] encryptedData) {
|
||||
private T DecryptAdditionalData(string pwd, byte[] salt, byte[] encryptedData) {
|
||||
var pbkdf2 = new Rfc2898DeriveBytes(Encoding.UTF8.GetBytes(pwd), salt, config.PBKDF2_ITERATIONS, HashAlgorithmName.SHA256);
|
||||
var key = pbkdf2.GetBytes(config.KEY_LENGTH / 8);
|
||||
|
||||
|
||||
@@ -1,23 +1,15 @@
|
||||
using System.Collections.ObjectModel;
|
||||
using System.Net;
|
||||
using System.Net;
|
||||
|
||||
namespace SimpleHttpServer;
|
||||
public class RequestContext : IDisposable {
|
||||
|
||||
public HttpListenerContext ListenerContext { get; }
|
||||
public ReadOnlyDictionary<string, string> ParsedParameters { get; internal set; }
|
||||
|
||||
private TextReader? reqReader;
|
||||
/// <summary>
|
||||
/// THREADSAFE
|
||||
/// </summary>
|
||||
public TextReader ReqReader => reqReader ??= TextReader.Synchronized(new StreamReader(ListenerContext.Request.InputStream));
|
||||
private StreamReader? reqReader;
|
||||
public StreamReader ReqReader => reqReader ??= new(ListenerContext.Request.InputStream);
|
||||
|
||||
private TextWriter? respWriter;
|
||||
/// <summary>
|
||||
/// THREADSAFE
|
||||
/// </summary>
|
||||
public TextWriter RespWriter => respWriter ??= TextWriter.Synchronized(new StreamWriter(ListenerContext.Response.OutputStream) { NewLine = "\n" });
|
||||
private StreamWriter? respWriter;
|
||||
public StreamWriter RespWriter => respWriter ??= new(ListenerContext.Response.OutputStream) { NewLine = "\n" };
|
||||
|
||||
public RequestContext(HttpListenerContext listenerContext) {
|
||||
ListenerContext = listenerContext;
|
||||
@@ -33,40 +25,27 @@ public class RequestContext : IDisposable {
|
||||
|
||||
public void SetStatusCode(HttpStatusCode status) => SetStatusCode((int) status);
|
||||
|
||||
public async Task SetStatusCodeAndDisposeAsync(int status) {
|
||||
using (this) {
|
||||
public void SetStatusCodeAndDispose(int status) {
|
||||
using (this)
|
||||
SetStatusCode(status);
|
||||
await WriteToRespAsync("\n\n");
|
||||
await RespWriter.FlushAsync();
|
||||
}
|
||||
}
|
||||
|
||||
public async Task SetStatusCodeAndDisposeAsync(HttpStatusCode status) {
|
||||
using (this) {
|
||||
public void SetStatusCodeAndDispose(HttpStatusCode status) {
|
||||
using (this)
|
||||
SetStatusCode((int) status);
|
||||
await WriteToRespAsync("\n\n");
|
||||
await RespWriter.FlushAsync();
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
public async Task SetStatusCodeAndDisposeAsync(int status, string description) {
|
||||
public void SetStatusCodeAndDispose(int status, string description) {
|
||||
using (this) {
|
||||
ListenerContext.Response.StatusCode = status;
|
||||
ListenerContext.Response.StatusDescription = description;
|
||||
await WriteToRespAsync("\n\n");
|
||||
await RespWriter.FlushAsync();
|
||||
}
|
||||
}
|
||||
public async Task SetStatusCodeAndDisposeAsync(HttpStatusCode status, string description) => await SetStatusCodeAndDisposeAsync((int) status, description);
|
||||
public void SetStatusCodeAndDispose(HttpStatusCode status, string description) => SetStatusCodeAndDispose((int) status, description);
|
||||
|
||||
|
||||
public async Task WriteRedirect302AndDisposeAsync(string url) {
|
||||
ListenerContext.Response.AddHeader("Location", url);
|
||||
await SetStatusCodeAndDisposeAsync(HttpStatusCode.Redirect);
|
||||
}
|
||||
|
||||
public void Dispose() {
|
||||
void IDisposable.Dispose() {
|
||||
reqReader?.Dispose();
|
||||
respWriter?.Dispose();
|
||||
GC.SuppressFinalize(this);
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
</PropertyGroup>
|
||||
|
||||
<ItemGroup>
|
||||
<PackageReference Include="Konscious.Security.Cryptography.Argon2" Version="1.3.0" />
|
||||
<PackageReference Include="Newtonsoft.Json" Version="13.0.3" />
|
||||
</ItemGroup>
|
||||
|
||||
|
||||
@@ -1,7 +0,0 @@
|
||||
namespace SimpleHttpServer.Types.ParameterConverters;
|
||||
internal class StringParameterConverter : IParameterConverter {
|
||||
public bool TryConvertFromString(string value, out object result) {
|
||||
result = value;
|
||||
return true;
|
||||
}
|
||||
}
|
||||
@@ -1,6 +1,4 @@
|
||||
using SimpleHttpServer;
|
||||
using SimpleHttpServer.Types;
|
||||
using System.Net;
|
||||
|
||||
namespace SimpleHttpServerTest;
|
||||
|
||||
@@ -10,36 +8,19 @@ public class SimpleServerTest {
|
||||
const int PORT = 8833;
|
||||
|
||||
private HttpServer? activeServer = null;
|
||||
private HttpClient? activeHttpClient = null;
|
||||
private bool failOnLogError = true;
|
||||
private static string GetRequestPath(string url) => $"http://localhost:{PORT}/{url.TrimStart('/')}";
|
||||
private async Task RequestGetStringAsync(string path) => await activeHttpClient!.GetStringAsync(GetRequestPath(path));
|
||||
private async Task<HttpResponseMessage> AssertGetStatusCodeAsync(string path, HttpStatusCode statusCode) {
|
||||
var resp = await activeHttpClient!.GetAsync(GetRequestPath(path));
|
||||
Assert.AreEqual(statusCode, resp.StatusCode);
|
||||
return resp;
|
||||
}
|
||||
|
||||
[TestInitialize]
|
||||
public void Init() {
|
||||
var conf = new SimpleHttpServerConfiguration() {
|
||||
DisableLogMessagePrinting = false,
|
||||
LogMessageHandler = (LogOutputTopic topic, string message, LogOutputLevel logLevel) => {
|
||||
if (failOnLogError && logLevel is LogOutputLevel.Error or LogOutputLevel.Fatal)
|
||||
Assert.Fail($"An error was thrown in the log output:\n{topic} {message}");
|
||||
}
|
||||
};
|
||||
var conf = new SimpleHttpServerConfiguration();
|
||||
if (activeServer != null)
|
||||
throw new InvalidOperationException("Tried to create another httpserver instance when an existing one was already running.");
|
||||
|
||||
Console.WriteLine("Starting server...");
|
||||
failOnLogError = true;
|
||||
activeServer = new HttpServer(PORT, conf);
|
||||
activeServer.RegisterEndpointsFromType<TestEndpoints>();
|
||||
activeServer.Start();
|
||||
|
||||
activeHttpClient = new HttpClient();
|
||||
|
||||
Console.WriteLine("Server started.");
|
||||
}
|
||||
|
||||
@@ -52,87 +33,20 @@ public class SimpleServerTest {
|
||||
}
|
||||
await Console.Out.WriteLineAsync("Shutting down server...");
|
||||
await activeServer.StopAsync(ctokSrc.Token);
|
||||
activeHttpClient?.Dispose();
|
||||
activeHttpClient = null;
|
||||
await Console.Out.WriteLineAsync("Shutdown finished.");
|
||||
}
|
||||
|
||||
static string GetHttpPageContentFromPrefix(string page)
|
||||
=> $"It works!!!!!!56sg5sdf46a4sd65a412f31sdfgdf89h74g9f8h4as56d4f56as2as1f3d24f87g9d87{page}";
|
||||
|
||||
[TestMethod]
|
||||
public async Task CheckSimpleServe() {
|
||||
var resp = await AssertGetStatusCodeAsync("/", HttpStatusCode.OK);
|
||||
var str = await resp.Content.ReadAsStringAsync();
|
||||
Assert.AreEqual("It works!", str);
|
||||
}
|
||||
|
||||
[TestMethod]
|
||||
public async Task CheckMultiServe() {
|
||||
|
||||
foreach (var item in "index2.html;testpage;testpage2;testpage3".Split(';')) {
|
||||
await Console.Out.WriteLineAsync($"Checking page: /{item}");
|
||||
var resp = await AssertGetStatusCodeAsync(item, HttpStatusCode.OK);
|
||||
var str = await resp.Content.ReadAsStringAsync();
|
||||
Assert.AreEqual(GetHttpPageContentFromPrefix(item), str);
|
||||
}
|
||||
}
|
||||
|
||||
[TestMethod]
|
||||
public async Task CheckQueryArgs() {
|
||||
foreach (var a1 in "test1;longstring2;something else with a space".Split(';')) {
|
||||
foreach (var a2 in new[] { -10, 2, -2, 5, 0, 4 }) {
|
||||
foreach (var a3 in new[] { -1, 9, 2, -20, 0 }) {
|
||||
foreach (var a4 in new[] { -1, 9, 0 }) {
|
||||
foreach (var page in "returnqueries;returnqueries2".Split(';')) {
|
||||
var resp = await AssertGetStatusCodeAsync($"{page}?arg1={a1}&arg2={a2}&arg3={a3}&arg4={a4}", HttpStatusCode.OK);
|
||||
var str = await resp.Content.ReadAsStringAsync();
|
||||
Assert.AreEqual(TestEndpoints.GetReturnQueryPageResult(a1, a2, page == "returnqueries2" ? (a3 + a4) : a3), str);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
using var hc = new HttpClient();
|
||||
await hc.GetStringAsync(GetRequestPath("/"));
|
||||
}
|
||||
|
||||
public class TestEndpoints {
|
||||
[HttpEndpoint(HttpRequestType.GET, "/", "index.html")]
|
||||
|
||||
[HttpEndpoint(HttpRequestType.GET, "/", "index.html", "amogus.html")]
|
||||
public static async Task Index(RequestContext req) {
|
||||
await req.RespWriter.WriteAsync("It works!");
|
||||
}
|
||||
|
||||
[HttpEndpoint(HttpRequestType.GET, "index2.html")]
|
||||
public static async Task Index2(RequestContext req) {
|
||||
await req.RespWriter.WriteAsync(GetHttpPageContentFromPrefix("index2.html"));
|
||||
}
|
||||
|
||||
[HttpEndpoint(HttpRequestType.GET, "/testpage")]
|
||||
public static async Task TestPage(RequestContext req) {
|
||||
await req.RespWriter.WriteAsync(GetHttpPageContentFromPrefix("testpage"));
|
||||
}
|
||||
|
||||
[HttpEndpoint(HttpRequestType.GET, "testpage2")]
|
||||
public static async Task TestPage2(RequestContext req) {
|
||||
await req.RespWriter.WriteAsync(GetHttpPageContentFromPrefix("testpage2"));
|
||||
}
|
||||
[HttpEndpoint(HttpRequestType.GET, "/testpage3")]
|
||||
public static async Task TestPage3(RequestContext req) {
|
||||
await req.RespWriter.WriteAsync(GetHttpPageContentFromPrefix("testpage3"));
|
||||
}
|
||||
|
||||
|
||||
public static string GetReturnQueryPageResult(string arg1, int arg2, int arg3) => $"{arg1};{arg2 * 2 - arg3 * 5}";
|
||||
|
||||
[HttpEndpoint(HttpRequestType.GET, "/returnqueries")]
|
||||
public static async Task ReturnQueriesPage(RequestContext req, string arg1, int arg2, int arg3) {
|
||||
await req.RespWriter.WriteAsync(GetReturnQueryPageResult(arg1, arg2, arg3));
|
||||
}
|
||||
|
||||
[HttpEndpoint(HttpRequestType.GET, "/returnqueries2")]
|
||||
public static async Task ReturnQueriesPage2(RequestContext req,
|
||||
[Parameter("arg2")] int arg1, [Parameter("arg1")] string arg2, int arg3, [Parameter("arg4", true)] int arg4) {
|
||||
// arg4 should be equal to zero as it should get the deafult value because it is not passed to the server
|
||||
await req.RespWriter.WriteAsync(GetReturnQueryPageResult(arg2, arg1, arg3 + arg4));
|
||||
await req.RespWriter.WriteLineAsync("It works!");
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user