Skip to content

Commit 6fbc79e

Browse files
Merge pull request #17581 from nextcloud/backport/17575/stable31
[stable31] fix(hostedhpb): Expect nonce on request
2 parents 1566f91 + 92aeb86 commit 6fbc79e

1 file changed

Lines changed: 24 additions & 8 deletions

File tree

‎lib/Controller/HostedSignalingServerController.php‎

Lines changed: 24 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@
1414
use OCA\Talk\Exceptions\HostedSignalingServerInputException;
1515
use OCA\Talk\Service\HostedSignalingServerService;
1616
use OCP\AppFramework\Http;
17+
use OCP\AppFramework\Http\Attribute\BruteForceProtection;
1718
use OCP\AppFramework\Http\Attribute\OpenAPI;
1819
use OCP\AppFramework\Http\Attribute\PublicPage;
1920
use OCP\AppFramework\Http\DataResponse;
@@ -41,25 +42,40 @@ public function __construct(
4142
/**
4243
* Get the authentication credentials
4344
*
44-
* @return DataResponse<Http::STATUS_OK, array{nonce: string}, array{}>|DataResponse<Http::STATUS_PRECONDITION_FAILED, null, array{}>
45+
* @return DataResponse<Http::STATUS_OK, array{nonce: string}, array{}>|DataResponse<Http::STATUS_FORBIDDEN|Http::STATUS_PRECONDITION_FAILED, null, array{}>
4546
*
4647
* 200: Authentication credentials returned
48+
* 403: Provided nonce is wrong
4749
* 412: Getting authentication credentials is not possible
4850
*/
4951
#[OpenAPI(scope: OpenAPI::SCOPE_IGNORE)]
5052
#[PublicPage]
53+
#[BruteForceProtection(action: 'hosted-hpb-nonce')]
5154
public function auth(): DataResponse {
55+
$sentNonce = $this->request->getHeader('x-account-service-nonce');
56+
if ($sentNonce === '') {
57+
$response = new DataResponse(null, Http::STATUS_FORBIDDEN);
58+
$response->throttle();
59+
return $response;
60+
}
61+
5262
$storedNonce = $this->config->getAppValue('spreed', 'hosted-signaling-server-nonce', '');
53-
// reset nonce after one request
54-
$this->config->deleteAppValue('spreed', 'hosted-signaling-server-nonce');
63+
if ($storedNonce === '') {
64+
return new DataResponse(null, Http::STATUS_PRECONDITION_FAILED);
65+
}
5566

56-
if ($storedNonce !== '') {
57-
return new DataResponse([
58-
'nonce' => $storedNonce,
59-
]);
67+
if (!hash_equals($storedNonce, $sentNonce)) {
68+
$response = new DataResponse(null, Http::STATUS_FORBIDDEN);
69+
$response->throttle();
70+
return $response;
6071
}
6172

62-
return new DataResponse(null, Http::STATUS_PRECONDITION_FAILED);
73+
// reset nonce after one request
74+
$this->config->deleteAppValue('spreed', 'hosted-signaling-server-nonce');
75+
76+
return new DataResponse([
77+
'nonce' => $storedNonce,
78+
]);
6379
}
6480

6581
/**

0 commit comments

Comments
 (0)