challenger

OAuth 2.0-based authentication service that validates user can receive messages at a certain address
Log | Files | Refs | Submodules | README | LICENSE

update_validation.c (6094B)


      1 /*
      2    This file is part of Challenger
      3    Copyright (C) 2023 Taler Systems SA
      4 
      5    Challenger is free software; you can redistribute it and/or modify it under the
      6    terms of the GNU General Public License as published by the Free Software
      7    Foundation; either version 3, or (at your option) any later version.
      8 
      9    Challenger is distributed in the hope that it will be useful, but WITHOUT ANY
     10    WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
     11    A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
     12 
     13    You should have received a copy of the GNU General Public License along with
     14    Challenger; see the file COPYING.  If not, see <http://www.gnu.org/licenses/>
     15  */
     16 /**
     17  * @file src/challengerdb/update_validation.c
     18  * @brief Implementation of the update_validation function for Postgres
     19  * @author Christian Grothoff
     20  * @author Bohdan Potuzhnyi
     21  * @author Vlada Svirsh
     22  */
     23 #include "platform.h"
     24 #include <taler/taler_error_codes.h>
     25 #include <taler/taler_dbevents.h>
     26 #include <taler/taler_pq_lib.h>
     27 #include "update_validation.h"
     28 #include "pg_helper.h"
     29 
     30 
     31 enum GNUNET_DB_QueryStatus
     32 CHALLENGERDB_update_validation (
     33   struct CHALLENGERDB_PostgresContext *ctx,
     34   const struct CHALLENGER_ValidationNonceP *nonce,
     35   uint64_t client_id,
     36   const char *client_scope,
     37   const char *client_state,
     38   const char *client_redirect_uri,
     39   const char *code_challenge,
     40   uint32_t code_challenge_method,
     41   json_t **last_address,
     42   uint32_t *address_attempts_left,
     43   uint32_t *pin_transmissions_left,
     44   uint32_t *auth_attempts_left,
     45   bool *solved,
     46   bool *failed,
     47   char **final_redirect_uri,
     48   struct GNUNET_TIME_Absolute *last_tx_time)
     49 {
     50   struct GNUNET_TIME_Absolute now
     51     = GNUNET_TIME_absolute_get ();
     52   struct GNUNET_PQ_QueryParam params[] = {
     53     GNUNET_PQ_query_param_auto_from_type (nonce),
     54     GNUNET_PQ_query_param_uint64 (&client_id),
     55     NULL != client_scope
     56     ? GNUNET_PQ_query_param_string (client_scope)
     57     : GNUNET_PQ_query_param_null (),
     58     NULL != client_state
     59     ? GNUNET_PQ_query_param_string (client_state)
     60     : GNUNET_PQ_query_param_null (),
     61     NULL != client_redirect_uri
     62     ? GNUNET_PQ_query_param_string (client_redirect_uri)
     63     : GNUNET_PQ_query_param_null (),
     64     NULL != code_challenge
     65     ? GNUNET_PQ_query_param_string (code_challenge)
     66     : GNUNET_PQ_query_param_null (),
     67     GNUNET_PQ_query_param_uint32 (&code_challenge_method),
     68     GNUNET_PQ_query_param_absolute_time (&now),
     69     GNUNET_PQ_query_param_end
     70   };
     71   struct GNUNET_PQ_ResultSpec rs[] = {
     72     GNUNET_PQ_result_spec_allow_null (
     73       TALER_PQ_result_spec_json ("address",
     74                                  last_address),
     75       NULL),
     76     GNUNET_PQ_result_spec_uint32 ("address_attempts_left",
     77                                   address_attempts_left),
     78     GNUNET_PQ_result_spec_uint32 ("pin_transmissions_left",
     79                                   pin_transmissions_left),
     80     GNUNET_PQ_result_spec_uint32 ("auth_attempts_left",
     81                                   auth_attempts_left),
     82     GNUNET_PQ_result_spec_bool ("solved",
     83                                 solved),
     84     GNUNET_PQ_result_spec_bool ("failed",
     85                                 failed),
     86     GNUNET_PQ_result_spec_string ("client_redirect_uri",
     87                                   final_redirect_uri),
     88     GNUNET_PQ_result_spec_absolute_time ("last_tx_time",
     89                                          last_tx_time),
     90     GNUNET_PQ_result_spec_end
     91   };
     92 
     93   *last_address = NULL;
     94   *final_redirect_uri = NULL;
     95   /* A repeated /authorize must never *weaken* an existing PKCE binding
     96      (RFC 7636): /authorize authenticates nobody (the client_id is a plain
     97      query argument) and the nonce is recoverable from an issued code, so
     98      replaying /authorize without a code_challenge would otherwise strip the
     99      binding from a validation that already had one.  Hence COALESCE, just
    100      like for client_redirect_uri above.  code_challenge_method must move
    101      with the challenge it describes: the column is NOT NULL DEFAULT 0, so
    102      writing it unconditionally would leave a retained challenge with the
    103      method of the request that tried to drop it.
    104      'failed' is updated here, too, as a validation can run out of options
    105      without a /solve or /challenge noticing, e.g. if the transmission
    106      helper failed on the last TAN; see do_challenge_address.sql for the
    107      same condition.  The WHERE clause guarantees that client_redirect_uri
    108      is not NULL after the update. */
    109   PREPARE (ctx,
    110            "update_validation",
    111            "UPDATE validations SET"
    112            "  client_scope=$3"
    113            " ,client_state=$4"
    114            " ,client_redirect_uri=COALESCE($5::VARCHAR,client_redirect_uri)"
    115            " ,code_challenge=COALESCE($6::VARCHAR,code_challenge)"
    116            " ,code_challenge_method=CASE"
    117            "    WHEN $6::VARCHAR IS NULL"
    118            "    THEN code_challenge_method"
    119            "    ELSE $7"
    120            "  END"
    121            " ,failed=failed"
    122            "   OR ( (auth_attempts_left=0)"
    123            "    AND (pin_transmissions_left=0)"
    124            "    AND ( (address_attempts_left=0)"
    125            "       OR COALESCE(address::JSONB->'read_only'"
    126            "                   = 'true'::JSONB, FALSE) ) )"
    127            " WHERE nonce=$1"
    128            "   AND client_serial_id=$2"
    129            "   AND expiration_time > $8"
    130            "   AND ( ($5::VARCHAR=client_redirect_uri)"
    131            "      OR ( ($5::VARCHAR IS NULL)"
    132            "       AND (client_redirect_uri IS NOT NULL) ) )"
    133            " RETURNING"
    134            "   address"
    135            "  ,address_attempts_left"
    136            "  ,pin_transmissions_left"
    137            "  ,GREATEST(0, auth_attempts_left) AS auth_attempts_left"
    138            "  ,auth_attempts_left = -1 AS solved"
    139            "  ,failed"
    140            "  ,client_redirect_uri"
    141            "  ,last_tx_time;");
    142   return GNUNET_PQ_eval_prepared_singleton_select (ctx->conn,
    143                                                    "update_validation",
    144                                                    params,
    145                                                    rs);
    146 }