|
14 | 14 | use OCA\Talk\Exceptions\HostedSignalingServerInputException; |
15 | 15 | use OCA\Talk\Service\HostedSignalingServerService; |
16 | 16 | use OCP\AppFramework\Http; |
| 17 | +use OCP\AppFramework\Http\Attribute\BruteForceProtection; |
17 | 18 | use OCP\AppFramework\Http\Attribute\OpenAPI; |
18 | 19 | use OCP\AppFramework\Http\Attribute\PublicPage; |
19 | 20 | use OCP\AppFramework\Http\DataResponse; |
@@ -41,25 +42,40 @@ public function __construct( |
41 | 42 | /** |
42 | 43 | * Get the authentication credentials |
43 | 44 | * |
44 | | - * @return DataResponse<Http::STATUS_OK, array{nonce: string}, array{}>|DataResponse<Http::STATUS_PRECONDITION_FAILED, null, array{}> |
| 45 | + * @return DataResponse<Http::STATUS_OK, array{nonce: string}, array{}>|DataResponse<Http::STATUS_FORBIDDEN|Http::STATUS_PRECONDITION_FAILED, null, array{}> |
45 | 46 | * |
46 | 47 | * 200: Authentication credentials returned |
| 48 | + * 403: Provided nonce is wrong |
47 | 49 | * 412: Getting authentication credentials is not possible |
48 | 50 | */ |
49 | 51 | #[OpenAPI(scope: OpenAPI::SCOPE_IGNORE)] |
50 | 52 | #[PublicPage] |
| 53 | + #[BruteForceProtection(action: 'hosted-hpb-nonce')] |
51 | 54 | public function auth(): DataResponse { |
| 55 | + $sentNonce = $this->request->getHeader('x-account-service-nonce'); |
| 56 | + if ($sentNonce === '') { |
| 57 | + $response = new DataResponse(null, Http::STATUS_FORBIDDEN); |
| 58 | + $response->throttle(); |
| 59 | + return $response; |
| 60 | + } |
| 61 | + |
52 | 62 | $storedNonce = $this->config->getAppValue('spreed', 'hosted-signaling-server-nonce', ''); |
53 | | - // reset nonce after one request |
54 | | - $this->config->deleteAppValue('spreed', 'hosted-signaling-server-nonce'); |
| 63 | + if ($storedNonce === '') { |
| 64 | + return new DataResponse(null, Http::STATUS_PRECONDITION_FAILED); |
| 65 | + } |
55 | 66 |
|
56 | | - if ($storedNonce !== '') { |
57 | | - return new DataResponse([ |
58 | | - 'nonce' => $storedNonce, |
59 | | - ]); |
| 67 | + if (!hash_equals($storedNonce, $sentNonce)) { |
| 68 | + $response = new DataResponse(null, Http::STATUS_FORBIDDEN); |
| 69 | + $response->throttle(); |
| 70 | + return $response; |
60 | 71 | } |
61 | 72 |
|
62 | | - return new DataResponse(null, Http::STATUS_PRECONDITION_FAILED); |
| 73 | + // reset nonce after one request |
| 74 | + $this->config->deleteAppValue('spreed', 'hosted-signaling-server-nonce'); |
| 75 | + |
| 76 | + return new DataResponse([ |
| 77 | + 'nonce' => $storedNonce, |
| 78 | + ]); |
63 | 79 | } |
64 | 80 |
|
65 | 81 | /** |
|
0 commit comments