update_validation.c (6094B)
1 /* 2 This file is part of Challenger 3 Copyright (C) 2023 Taler Systems SA 4 5 Challenger is free software; you can redistribute it and/or modify it under the 6 terms of the GNU General Public License as published by the Free Software 7 Foundation; either version 3, or (at your option) any later version. 8 9 Challenger is distributed in the hope that it will be useful, but WITHOUT ANY 10 WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR 11 A PARTICULAR PURPOSE. See the GNU General Public License for more details. 12 13 You should have received a copy of the GNU General Public License along with 14 Challenger; see the file COPYING. If not, see <http://www.gnu.org/licenses/> 15 */ 16 /** 17 * @file src/challengerdb/update_validation.c 18 * @brief Implementation of the update_validation function for Postgres 19 * @author Christian Grothoff 20 * @author Bohdan Potuzhnyi 21 * @author Vlada Svirsh 22 */ 23 #include "platform.h" 24 #include <taler/taler_error_codes.h> 25 #include <taler/taler_dbevents.h> 26 #include <taler/taler_pq_lib.h> 27 #include "update_validation.h" 28 #include "pg_helper.h" 29 30 31 enum GNUNET_DB_QueryStatus 32 CHALLENGERDB_update_validation ( 33 struct CHALLENGERDB_PostgresContext *ctx, 34 const struct CHALLENGER_ValidationNonceP *nonce, 35 uint64_t client_id, 36 const char *client_scope, 37 const char *client_state, 38 const char *client_redirect_uri, 39 const char *code_challenge, 40 uint32_t code_challenge_method, 41 json_t **last_address, 42 uint32_t *address_attempts_left, 43 uint32_t *pin_transmissions_left, 44 uint32_t *auth_attempts_left, 45 bool *solved, 46 bool *failed, 47 char **final_redirect_uri, 48 struct GNUNET_TIME_Absolute *last_tx_time) 49 { 50 struct GNUNET_TIME_Absolute now 51 = GNUNET_TIME_absolute_get (); 52 struct GNUNET_PQ_QueryParam params[] = { 53 GNUNET_PQ_query_param_auto_from_type (nonce), 54 GNUNET_PQ_query_param_uint64 (&client_id), 55 NULL != client_scope 56 ? GNUNET_PQ_query_param_string (client_scope) 57 : GNUNET_PQ_query_param_null (), 58 NULL != client_state 59 ? GNUNET_PQ_query_param_string (client_state) 60 : GNUNET_PQ_query_param_null (), 61 NULL != client_redirect_uri 62 ? GNUNET_PQ_query_param_string (client_redirect_uri) 63 : GNUNET_PQ_query_param_null (), 64 NULL != code_challenge 65 ? GNUNET_PQ_query_param_string (code_challenge) 66 : GNUNET_PQ_query_param_null (), 67 GNUNET_PQ_query_param_uint32 (&code_challenge_method), 68 GNUNET_PQ_query_param_absolute_time (&now), 69 GNUNET_PQ_query_param_end 70 }; 71 struct GNUNET_PQ_ResultSpec rs[] = { 72 GNUNET_PQ_result_spec_allow_null ( 73 TALER_PQ_result_spec_json ("address", 74 last_address), 75 NULL), 76 GNUNET_PQ_result_spec_uint32 ("address_attempts_left", 77 address_attempts_left), 78 GNUNET_PQ_result_spec_uint32 ("pin_transmissions_left", 79 pin_transmissions_left), 80 GNUNET_PQ_result_spec_uint32 ("auth_attempts_left", 81 auth_attempts_left), 82 GNUNET_PQ_result_spec_bool ("solved", 83 solved), 84 GNUNET_PQ_result_spec_bool ("failed", 85 failed), 86 GNUNET_PQ_result_spec_string ("client_redirect_uri", 87 final_redirect_uri), 88 GNUNET_PQ_result_spec_absolute_time ("last_tx_time", 89 last_tx_time), 90 GNUNET_PQ_result_spec_end 91 }; 92 93 *last_address = NULL; 94 *final_redirect_uri = NULL; 95 /* A repeated /authorize must never *weaken* an existing PKCE binding 96 (RFC 7636): /authorize authenticates nobody (the client_id is a plain 97 query argument) and the nonce is recoverable from an issued code, so 98 replaying /authorize without a code_challenge would otherwise strip the 99 binding from a validation that already had one. Hence COALESCE, just 100 like for client_redirect_uri above. code_challenge_method must move 101 with the challenge it describes: the column is NOT NULL DEFAULT 0, so 102 writing it unconditionally would leave a retained challenge with the 103 method of the request that tried to drop it. 104 'failed' is updated here, too, as a validation can run out of options 105 without a /solve or /challenge noticing, e.g. if the transmission 106 helper failed on the last TAN; see do_challenge_address.sql for the 107 same condition. The WHERE clause guarantees that client_redirect_uri 108 is not NULL after the update. */ 109 PREPARE (ctx, 110 "update_validation", 111 "UPDATE validations SET" 112 " client_scope=$3" 113 " ,client_state=$4" 114 " ,client_redirect_uri=COALESCE($5::VARCHAR,client_redirect_uri)" 115 " ,code_challenge=COALESCE($6::VARCHAR,code_challenge)" 116 " ,code_challenge_method=CASE" 117 " WHEN $6::VARCHAR IS NULL" 118 " THEN code_challenge_method" 119 " ELSE $7" 120 " END" 121 " ,failed=failed" 122 " OR ( (auth_attempts_left=0)" 123 " AND (pin_transmissions_left=0)" 124 " AND ( (address_attempts_left=0)" 125 " OR COALESCE(address::JSONB->'read_only'" 126 " = 'true'::JSONB, FALSE) ) )" 127 " WHERE nonce=$1" 128 " AND client_serial_id=$2" 129 " AND expiration_time > $8" 130 " AND ( ($5::VARCHAR=client_redirect_uri)" 131 " OR ( ($5::VARCHAR IS NULL)" 132 " AND (client_redirect_uri IS NOT NULL) ) )" 133 " RETURNING" 134 " address" 135 " ,address_attempts_left" 136 " ,pin_transmissions_left" 137 " ,GREATEST(0, auth_attempts_left) AS auth_attempts_left" 138 " ,auth_attempts_left = -1 AS solved" 139 " ,failed" 140 " ,client_redirect_uri" 141 " ,last_tx_time;"); 142 return GNUNET_PQ_eval_prepared_singleton_select (ctx->conn, 143 "update_validation", 144 params, 145 rs); 146 }