challenger

OAuth 2.0-based authentication service that validates user can receive messages at a certain address
Log | Files | Refs | Submodules | README | LICENSE

update_validation.h (4035B)


      1 /*
      2    This file is part of Challenger
      3    Copyright (C) 2023 Taler Systems SA
      4 
      5    Challenger is free software; you can redistribute it and/or modify it under the
      6    terms of the GNU General Public License as published by the Free Software
      7    Foundation; either version 3, or (at your option) any later version.
      8 
      9    Challenger is distributed in the hope that it will be useful, but WITHOUT ANY
     10    WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
     11    A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
     12 
     13    You should have received a copy of the GNU General Public License along with
     14    Challenger; see the file COPYING.  If not, see <http://www.gnu.org/licenses/>
     15  */
     16 /**
     17  * @file src/include/challenger-database/update_validation.h
     18  * @brief implementation of the update_validation function for Postgres
     19  * @author Christian Grothoff
     20  * @author Bohdan Potuzhnyi
     21  * @author Vlada Svirsh
     22  */
     23 #ifndef CHALLENGER_DATABASE_UPDATE_VALIDATION_H
     24 #define CHALLENGER_DATABASE_UPDATE_VALIDATION_H
     25 
     26 #include <taler/taler_util.h>
     27 #include <taler/taler_json_lib.h>
     28 #include "challenger_util.h"
     29 #include "challenger_database_lib.h"
     30 
     31 
     32 /**
     33  * Begin the authorization phase of a validation: record the client's OAuth2
     34  * scope, state, redirect URI and PKCE code challenge on the validation
     35  * identified by @a nonce, and return the current status (last address,
     36  * remaining attempt counters, whether it is already solved).  Succeeds only if
     37  * the supplied @a client_redirect_uri matches the one registered for the client.
     38  *
     39  * @param cls
     40  * @param nonce unique nonce to use to identify the validation
     41  * @param client_id client that initiated the validation
     42  * @param client_scope scope of the validation
     43  * @param client_state state of the client
     44  * @param client_redirect_uri where to redirect at the end, NULL to use a unique one registered for the client
     45  * @param code_challenge PKCE code challenge, NULL to keep the one already
     46  *        stored (a repeated authorization may add a code challenge, but it
     47  *        may never remove one)
     48  * @param code_challenge_method PKCE code challenge method enum; ignored if
     49  *        @a code_challenge is NULL
     50  * @param[out] last_address set to the last address used
     51  * @param[out] address_attempts_left set to number of address changing attempts left for this address
     52  * @param[out] pin_transmissions_left set to number of times the TAN can still be re-requested
     53  * @param[out] auth_attempts_left set to number of authentication attempts remaining
     54  * @param[out] solved set to true if the challenge is already solved
     55  * @param[out] failed set to true if the validation failed permanently: no
     56  *        address change, TAN transmission or TAN attempt is left
     57  * @param[out] final_redirect_uri set to the redirect URI now on file, which
     58  *        is the registered one if @a client_redirect_uri is NULL; the
     59  *        caller must free it
     60  * @param[out] last_tx_time set to the last time when we (presumably) send a TAN to @a last_address; 0 if never sent
     61  * @return transaction status:
     62  *   #GNUNET_DB_STATUS_SUCCESS_ONE_RESULT if the validation exists and the
     63  *     OAuth2 scope/state/redirect/PKCE parameters were recorded
     64  *   #GNUNET_DB_STATUS_SUCCESS_NO_RESULTS if no validation matches @a nonce and
     65  *     @a client_id, or the supplied @a client_redirect_uri does not match the
     66  *     redirect URI registered for the client
     67  *   #GNUNET_DB_STATUS_HARD_ERROR on failure
     68  */
     69 enum GNUNET_DB_QueryStatus
     70 CHALLENGERDB_update_validation (
     71   struct CHALLENGERDB_PostgresContext *ctx,
     72   const struct CHALLENGER_ValidationNonceP *nonce,
     73   uint64_t client_id,
     74   const char *client_scope,
     75   const char *client_state,
     76   const char *client_redirect_uri,
     77   const char *code_challenge,
     78   uint32_t code_challenge_method,
     79   json_t **last_address,
     80   uint32_t *address_attempts_left,
     81   uint32_t *pin_transmissions_left,
     82   uint32_t *auth_attempts_left,
     83   bool *solved,
     84   bool *failed,
     85   char **final_redirect_uri,
     86   struct GNUNET_TIME_Absolute *last_tx_time);
     87 
     88 
     89 #endif