2026-10-01 08:05:56 +02:00
|
|
|
using MailKit.Net.Smtp;
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
using Microsoft.Extensions.Localization;
|
|
|
|
|
|
|
|
|
|
using MimeKit;
|
|
|
|
|
|
|
|
|
|
using MongoDB.Driver;
|
|
|
|
|
using MongoDB.Entities;
|
|
|
|
|
|
|
|
|
|
using PasswordGenerator;
|
|
|
|
|
|
2023-02-19 00:43:43 +01:00
|
|
|
using PrivaPub.ClientModels;
|
|
|
|
|
using PrivaPub.ClientModels.User;
|
|
|
|
|
using PrivaPub.Models;
|
|
|
|
|
using PrivaPub.Models.User;
|
|
|
|
|
using PrivaPub.Resources;
|
2026-10-04 03:16:59 +02:00
|
|
|
using PrivaPub.Infrastructure.Jobs;
|
|
|
|
|
using PrivaPub.Models.Jobs;
|
2023-02-19 00:43:43 +01:00
|
|
|
using PrivaPub.StaticServices;
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
using System.Globalization;
|
2026-10-04 03:16:59 +02:00
|
|
|
using System.Text.Json;
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
#pragma warning disable 8603
|
|
|
|
|
#pragma warning disable 8625
|
|
|
|
|
|
2023-02-19 00:43:43 +01:00
|
|
|
namespace PrivaPub.Services
|
2023-02-18 08:52:17 +01:00
|
|
|
{
|
|
|
|
|
public class RootUsersService : IRootUsersService
|
|
|
|
|
{
|
|
|
|
|
readonly DbEntities DbEntities;
|
|
|
|
|
readonly IPasswordHasher PasswordHasher;
|
|
|
|
|
readonly IStringLocalizer Localizer;
|
|
|
|
|
readonly ILogger<RootUsersService> Logger;
|
|
|
|
|
readonly AppConfigurationService AppConfigurationService;
|
|
|
|
|
readonly AuthTokenManager AuthTokenManager;
|
2026-10-04 03:16:59 +02:00
|
|
|
readonly IJobQueue Jobs;
|
|
|
|
|
readonly IRootSessions Sessions;
|
|
|
|
|
readonly IRootRemoval Removal;
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
public RootUsersService(
|
2026-10-04 03:16:59 +02:00
|
|
|
IJobQueue jobs,
|
|
|
|
|
IRootSessions sessions,
|
|
|
|
|
IRootRemoval removal,
|
2023-02-18 08:52:17 +01:00
|
|
|
IStringLocalizer<GenericRes> localizer,
|
|
|
|
|
ILogger<RootUsersService> logger,
|
|
|
|
|
IPasswordHasher passwordHasher,
|
|
|
|
|
DbEntities dbEntities,
|
|
|
|
|
AppConfigurationService appConfigurationService,
|
|
|
|
|
AuthTokenManager authTokenManager)
|
|
|
|
|
{
|
2026-10-04 03:16:59 +02:00
|
|
|
Jobs = jobs;
|
|
|
|
|
Sessions = sessions;
|
|
|
|
|
Removal = removal;
|
2023-02-18 08:52:17 +01:00
|
|
|
DbEntities = dbEntities;
|
|
|
|
|
AuthTokenManager = authTokenManager;
|
|
|
|
|
PasswordHasher = passwordHasher;
|
|
|
|
|
Localizer = localizer;
|
|
|
|
|
Logger = logger;
|
|
|
|
|
AppConfigurationService = appConfigurationService;
|
|
|
|
|
}
|
|
|
|
|
|
2026-10-04 03:16:59 +02:00
|
|
|
public const string NoMatch = "That username and password do not match.";
|
|
|
|
|
static string _decoy;
|
|
|
|
|
|
|
|
|
|
// a hash nobody's password matches, so an unknown login costs the same hashing as a wrong password
|
|
|
|
|
string Decoy => _decoy ??= PasswordHasher.Hash(Convert.ToHexString(System.Security.Cryptography.RandomNumberGenerator.GetBytes(16)));
|
|
|
|
|
|
2023-02-18 08:52:17 +01:00
|
|
|
public async Task<WebResult> SignUpAsync(LoginForm signUpForm, string invitationCode = default,
|
|
|
|
|
bool isPasswordRequired = false)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
signUpForm.UserName = signUpForm.UserName.ToLower();
|
|
|
|
|
if (await DbEntities.RootUsers.Match(u => u.UserName == signUpForm.UserName).ExecuteAnyAsync())
|
|
|
|
|
return result.Invalidate(Localizer["Username '{0}' already taken.", signUpForm.UserName]);
|
|
|
|
|
|
|
|
|
|
var signUpPasswordHashed = PasswordHasher.Hash(signUpForm.Password);
|
|
|
|
|
var newUser = new RootUser
|
|
|
|
|
{
|
|
|
|
|
UserName = signUpForm.UserName,
|
|
|
|
|
HashedPassword = signUpPasswordHashed
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
var cultureLanguage = CultureInfo.CurrentCulture.TwoLetterISOLanguageName;
|
|
|
|
|
var language = await DbEntities.Languages.Match(l => l.International2Code == cultureLanguage).ExecuteFirstAsync();
|
2026-10-01 08:05:56 +02:00
|
|
|
newUser.Settings = new RootUserSettings
|
2023-02-18 08:52:17 +01:00
|
|
|
{
|
|
|
|
|
LanguageCode = language?.International2Code ?? "en",
|
|
|
|
|
LightThemeIndexColour = signUpForm.LightThemeIndexColour,
|
|
|
|
|
DarkThemeIndexColour = signUpForm.DarkThemeIndexColour,
|
|
|
|
|
IconsThemeIndexColour = signUpForm.IconsThemeIndexColour,
|
|
|
|
|
ThemeIsDarkGray = signUpForm.ThemeIsDarkGray,
|
|
|
|
|
ThemeIsLightGray = signUpForm.ThemeIsLightGray,
|
|
|
|
|
PreferSystemTheming = signUpForm.PreferSystemTheming,
|
|
|
|
|
ThemeIsDarkMode = signUpForm.ThemeIsDarkMode
|
|
|
|
|
};
|
2026-10-01 08:05:56 +02:00
|
|
|
await DB.Default.SaveAsync(newUser);
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
//if (!string.IsNullOrEmpty(invitationCode))
|
|
|
|
|
//{
|
|
|
|
|
// if (isPasswordRequired)
|
|
|
|
|
// result = await DiscussionService.InviteUserToDiscussion(new PwDiscussionPreviewForm
|
|
|
|
|
// {
|
|
|
|
|
// InvitationCode = invitationCode,
|
|
|
|
|
// Password = signUpForm.InvitationPassword
|
|
|
|
|
// }, newUser.ID);
|
|
|
|
|
// else
|
|
|
|
|
// result = await DiscussionService.InviteUserToDiscussion(new NoPwDiscussionPreviewForm
|
|
|
|
|
// {
|
|
|
|
|
// InvitationCode = invitationCode,
|
|
|
|
|
// }, newUser.ID);
|
|
|
|
|
// if (!result.IsValid)
|
|
|
|
|
// return result;
|
|
|
|
|
//}
|
|
|
|
|
|
2026-10-01 08:05:56 +02:00
|
|
|
result.Data = (newUser, ToViewSettings(newUser.Settings));
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(SignUpAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public async Task<WebResult> LoginAsync(LoginForm loginForm, string invitationCode = default,
|
|
|
|
|
bool isPasswordRequired = false)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-04 03:16:59 +02:00
|
|
|
// One answer, after the same work, whether the login is unknown, deleted or the password wrong: sign-in must not
|
|
|
|
|
// tell anyone which logins exist. Only someone who knows the password learns the login is banned.
|
2023-02-18 08:52:17 +01:00
|
|
|
loginForm.UserName = loginForm.UserName.ToLower();
|
2026-10-04 03:16:59 +02:00
|
|
|
var user = await DbEntities.RootUsers.Match(u => u.UserName == loginForm.UserName && u.DeletedAt == null).ExecuteFirstAsync();
|
|
|
|
|
var (verified, needsUpgrade) = PasswordHasher.Check(user?.HashedPassword ?? Decoy, loginForm.Password);
|
|
|
|
|
if (user?.HashedPassword == default || !verified)
|
|
|
|
|
return result.Invalidate(Localizer[NoMatch]);
|
2023-02-18 08:52:17 +01:00
|
|
|
if (user.IsBanned)
|
|
|
|
|
return result.Invalidate(Localizer["User '{0}' banned.", user.UserName]);
|
|
|
|
|
|
|
|
|
|
if (needsUpgrade)
|
|
|
|
|
result.ErrorMessage = Localizer["Needs upgrade!"];
|
|
|
|
|
|
|
|
|
|
var userSettingsResult = await GetUserSettingsAsync(user.ID, loginForm);
|
2026-10-01 08:05:56 +02:00
|
|
|
var userSettings = (ViewUserSettings)userSettingsResult.Data;
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
//if (!string.IsNullOrEmpty(invitationCode))
|
|
|
|
|
//{
|
|
|
|
|
// if (isPasswordRequired)
|
|
|
|
|
// result = await DiscussionService.InviteUserToDiscussion(new PwDiscussionPreviewForm
|
|
|
|
|
// {
|
|
|
|
|
// InvitationCode = invitationCode,
|
|
|
|
|
// Password = loginForm.InvitationPassword
|
|
|
|
|
// }, user.ID);
|
|
|
|
|
// else
|
|
|
|
|
// result = await DiscussionService.InviteUserToDiscussion(new NoPwDiscussionPreviewForm
|
|
|
|
|
// {
|
|
|
|
|
// InvitationCode = invitationCode,
|
|
|
|
|
// }, user.ID);
|
|
|
|
|
// if (!result.IsValid)
|
|
|
|
|
// return result;
|
|
|
|
|
//}
|
|
|
|
|
|
|
|
|
|
result.Data = (user, userSettings);
|
|
|
|
|
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(LoginAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public async Task<WebResult> UpdateUserAsync(UserForm userForm, string userId)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
var currentUser = await DbEntities.RootUsers.Match(u => u.ID == userId).ExecuteFirstAsync();
|
|
|
|
|
if (!string.IsNullOrEmpty(userForm.Email) && currentUser.Email != userForm.Email)
|
|
|
|
|
{
|
|
|
|
|
var emailAlreadyUsed = await DbEntities.RootUsers.Match(u => u.Email == userForm.Email).ExecuteAnyAsync();
|
|
|
|
|
if (emailAlreadyUsed)
|
|
|
|
|
return result.Invalidate(Localizer["Email '{0}' already taken.", userForm.Email]);
|
|
|
|
|
}
|
|
|
|
|
|
2026-10-01 08:05:56 +02:00
|
|
|
await DB.Default.Update<RootUser>()
|
2023-02-18 08:52:17 +01:00
|
|
|
.Match(u => u.ID == userId)
|
|
|
|
|
.Modify(u => u.Email, userForm.Email)
|
|
|
|
|
.ExecuteAsync();
|
|
|
|
|
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(UpdateUserAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-10-01 08:05:56 +02:00
|
|
|
public async Task<WebResult> UpdateUserSettingsAsync(ViewUserSettings userSettings, string userId)
|
2023-02-18 08:52:17 +01:00
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
var isSupportedLanguage = AppConfigurationService.AppConfiguration.SupportedLanguages.Contains(userSettings.LanguageCode);
|
|
|
|
|
if (!isSupportedLanguage)
|
|
|
|
|
return result.Invalidate(Localizer["Language code '{0}' unsupported.", userSettings.LanguageCode]);
|
|
|
|
|
|
|
|
|
|
var languageCodeExists = await DbEntities.Languages
|
|
|
|
|
.Match(l => l.International2Code == userSettings.LanguageCode).ExecuteAnyAsync();
|
|
|
|
|
if (!languageCodeExists)
|
|
|
|
|
return result.Invalidate(Localizer["Language code '{0}' doesn't exist.", userSettings.LanguageCode]);
|
|
|
|
|
|
|
|
|
|
var language = await DbEntities.Languages.Match(l => l.International2Code == userSettings.LanguageCode)
|
|
|
|
|
.ExecuteFirstAsync();
|
2026-10-01 08:05:56 +02:00
|
|
|
_ = await DB.Default.Update<RootUser>()
|
|
|
|
|
.MatchID(userId)
|
|
|
|
|
.Modify(u => u.Settings.LanguageCode, language.International2Code)
|
|
|
|
|
.Modify(u => u.Settings.LightThemeIndexColour, userSettings.LightThemeIndexColour)
|
|
|
|
|
.Modify(u => u.Settings.DarkThemeIndexColour, userSettings.DarkThemeIndexColour)
|
|
|
|
|
.Modify(u => u.Settings.PreferSystemTheming, userSettings.PreferSystemTheming)
|
|
|
|
|
.Modify(u => u.Settings.ThemeIsDarkMode, userSettings.ThemeIsDarkMode)
|
|
|
|
|
.Modify(u => u.Settings.ThemeIsDarkGray, userSettings.ThemeIsDarkGray)
|
|
|
|
|
.Modify(u => u.Settings.ThemeIsLightGray, userSettings.ThemeIsLightGray)
|
|
|
|
|
.Modify(u => u.Settings.IconsThemeIndexColour, userSettings.IconsThemeIndexColour)
|
|
|
|
|
.Modify(u => u.UpdatedAt, DateTime.UtcNow)
|
2023-02-18 08:52:17 +01:00
|
|
|
.ExecuteAsync();
|
|
|
|
|
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(UpdateUserSettingsAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public async Task<WebResult> UpdateUserPasswordAsync(UserPasswordForm userPasswordForm, string userId)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-01 08:05:56 +02:00
|
|
|
var user = await DbEntities.RootUsers.Match(u => u.ID == userId && u.DeletedAt == null).ExecuteFirstAsync();
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
if (user == null)
|
|
|
|
|
return result.Invalidate(Localizer["Username '{0}' not found.", userId]);
|
|
|
|
|
|
|
|
|
|
var (verified, needsUpgrade) = PasswordHasher.Check(user.HashedPassword, userPasswordForm.OldPassword);
|
|
|
|
|
|
|
|
|
|
if (!verified)
|
|
|
|
|
return result.Invalidate(Localizer["Wrong password."]);
|
|
|
|
|
|
|
|
|
|
var newPasswordHashed = PasswordHasher.Hash(userPasswordForm.NewPassword);
|
|
|
|
|
user.HashedPassword = newPasswordHashed;
|
2026-10-01 08:05:56 +02:00
|
|
|
user.UpdatedAt = DateTime.UtcNow;
|
|
|
|
|
await DB.Default.SaveAsync(user);
|
2023-02-18 08:52:17 +01:00
|
|
|
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(UpdateUserPasswordAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public async Task<WebResult> RemoveUserAsync(UsersIds usersIds)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-04 03:16:59 +02:00
|
|
|
var removed = 0;
|
|
|
|
|
foreach (var id in usersIds.UserIdList.Distinct())
|
|
|
|
|
if (await Removal.Remove(id, CancellationToken.None))
|
|
|
|
|
removed++;
|
|
|
|
|
if (removed == 0)
|
2023-02-18 08:52:17 +01:00
|
|
|
return result.Invalidate(Localizer["User already deleted."]);
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(RemoveUserAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-10-04 03:16:59 +02:00
|
|
|
// A root deletes itself only with its password, so a stolen session cannot.
|
|
|
|
|
public async Task<WebResult> RemoveSelfAsync(string rootId, string password)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
var user = await DbEntities.RootUsers.MatchID(rootId).Match(u => u.DeletedAt == null).ExecuteFirstAsync();
|
|
|
|
|
var (verified, _) = PasswordHasher.Check(user?.HashedPassword ?? Decoy, password ?? string.Empty);
|
|
|
|
|
if (user?.HashedPassword == default || !verified)
|
|
|
|
|
return result.Invalidate(Localizer[NoMatch], StatusCodes.Status403Forbidden);
|
|
|
|
|
await Removal.Remove(user.ID, CancellationToken.None);
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(RemoveSelfAsync)}()");
|
|
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2023-02-18 08:52:17 +01:00
|
|
|
public async Task<WebResult> BanUserAsync(UsersIds usersIds)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-01 08:05:56 +02:00
|
|
|
await DB.Default.Update<RootUser>()
|
2023-02-18 08:52:17 +01:00
|
|
|
.Match(u => usersIds.UserIdList.Contains(u.ID))
|
|
|
|
|
.Modify(u => u.IsBanned, true)
|
|
|
|
|
.ExecuteAsync();
|
|
|
|
|
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(BanUserAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public async Task<WebResult> UnbanUserAsync(UsersIds usersIds)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-01 08:05:56 +02:00
|
|
|
await DB.Default.Update<RootUser>()
|
2023-02-18 08:52:17 +01:00
|
|
|
.Match(u => usersIds.UserIdList.Contains(u.ID))
|
|
|
|
|
.Modify(u => u.IsBanned, false)
|
|
|
|
|
.ExecuteAsync();
|
|
|
|
|
|
|
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(UnbanUserAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public async Task<WebResult> GetUserSettingsAsync(string userId, LoginForm loginForm = default)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-01 08:05:56 +02:00
|
|
|
var user = await DbEntities.RootUsers.MatchID(userId).ExecuteFirstAsync();
|
|
|
|
|
if (user == default)
|
|
|
|
|
return result.Invalidate(Localizer["User not found."], StatusCodes.Status404NotFound);
|
|
|
|
|
|
|
|
|
|
if (loginForm != default && loginForm.ThemeIsDarkMode != user.Settings.ThemeIsDarkMode)
|
2023-02-18 08:52:17 +01:00
|
|
|
{
|
2026-10-01 08:05:56 +02:00
|
|
|
user.Settings.ThemeIsDarkMode = loginForm.ThemeIsDarkMode;
|
|
|
|
|
await DB.Default.Update<RootUser>()
|
|
|
|
|
.MatchID(userId)
|
|
|
|
|
.Modify(u => u.Settings.ThemeIsDarkMode, loginForm.ThemeIsDarkMode)
|
|
|
|
|
.ExecuteAsync();
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
|
2026-10-01 08:05:56 +02:00
|
|
|
result.Data = ToViewSettings(user.Settings);
|
2023-02-18 08:52:17 +01:00
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(GetUserSettingsAsync)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-10-04 03:16:59 +02:00
|
|
|
public const string RecoverySent = "If that account has an email address, a recovery link is on its way. It works for one hour.";
|
|
|
|
|
|
|
|
|
|
// The same answer, after the same work, whether the account exists, has an email or can be written to: recovery must
|
|
|
|
|
// not tell anyone which logins or addresses exist. RecoveryJob does the rest, out of the request.
|
2023-02-18 08:52:17 +01:00
|
|
|
public async Task<WebResult> SetupAndSendRecoveryEmail(PasswordRecoveryForm passwordRecoveryForm, string host)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-04 03:16:59 +02:00
|
|
|
var userName = passwordRecoveryForm.UserName?.ToLowerInvariant();
|
|
|
|
|
var user = passwordRecoveryForm.IsEmailDisabled
|
|
|
|
|
? await DbEntities.RootUsers.Match(u => u.UserName == userName && u.DeletedAt == null).ExecuteFirstAsync()
|
|
|
|
|
: await DbEntities.RootUsers.Match(u => u.Email == passwordRecoveryForm.Email && u.DeletedAt == null).ExecuteFirstAsync();
|
|
|
|
|
await Jobs.Enqueue(JobKind.SendRecovery, JsonSerializer.Serialize(new RecoveryPayload(user?.ID, host)), RecoveryJob.Host,
|
|
|
|
|
dedupeKey: default, CancellationToken.None);
|
|
|
|
|
result.Data = Localizer[RecoverySent].Value;
|
2023-02-18 08:52:17 +01:00
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(SetupAndSendRecoveryEmail)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-10-04 03:16:59 +02:00
|
|
|
Task<EmailRecovery> LiveRecovery(string recoveryCode)
|
|
|
|
|
{
|
|
|
|
|
var hash = RecoveryJob.Hash(recoveryCode);
|
|
|
|
|
var now = DateTime.UtcNow;
|
|
|
|
|
return DbEntities.EmailRecoveries.Match(er => er.CodeHash == hash && er.ExpiresAt > now).ExecuteFirstAsync();
|
|
|
|
|
}
|
|
|
|
|
|
2023-02-18 08:52:17 +01:00
|
|
|
public async Task<WebResult> IsValidRecoveryCode(string recoveryCode)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-04 03:16:59 +02:00
|
|
|
result.Data = await LiveRecovery(recoveryCode) != default;
|
2023-02-18 08:52:17 +01:00
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-10-04 03:16:59 +02:00
|
|
|
// A recovered password ends every session the root had: whoever had them may be why it was recovered.
|
2023-02-18 08:52:17 +01:00
|
|
|
public async Task<WebResult> ChangePassword(NewPasswordForm newPasswordForm)
|
|
|
|
|
{
|
|
|
|
|
var result = new WebResult();
|
|
|
|
|
try
|
|
|
|
|
{
|
2026-10-04 03:16:59 +02:00
|
|
|
var recovery = await LiveRecovery(newPasswordForm.RecoveryCode);
|
|
|
|
|
var user = recovery == default ? default
|
|
|
|
|
: await DbEntities.RootUsers.MatchID(recovery.RootUserId).Match(u => u.DeletedAt == null && !u.IsBanned).ExecuteFirstAsync();
|
|
|
|
|
if (user == default)
|
2023-02-18 08:52:17 +01:00
|
|
|
return result.Invalidate(Localizer["Invalid recovery code."], StatusCodes.Status404NotFound);
|
|
|
|
|
|
2026-10-04 03:16:59 +02:00
|
|
|
await DB.Default.Update<RootUser>().MatchID(user.ID)
|
|
|
|
|
.Modify(u => u.HashedPassword, PasswordHasher.Hash(newPasswordForm.NewPassword))
|
|
|
|
|
.Modify(u => u.UpdatedAt, DateTime.UtcNow)
|
2023-02-18 08:52:17 +01:00
|
|
|
.ExecuteAsync();
|
2026-10-04 03:16:59 +02:00
|
|
|
await DB.Default.DeleteAsync<EmailRecovery>(er => er.RootUserId == user.ID);
|
|
|
|
|
await Sessions.Revoke(user.ID, CancellationToken.None);
|
2023-02-18 08:52:17 +01:00
|
|
|
return result;
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(ChangePassword)}()");
|
2026-10-01 10:58:39 +02:00
|
|
|
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-10-01 08:05:56 +02:00
|
|
|
static ViewUserSettings ToViewSettings(RootUserSettings settings) => new()
|
|
|
|
|
{
|
|
|
|
|
LanguageCode = settings.LanguageCode,
|
|
|
|
|
LightThemeIndexColour = settings.LightThemeIndexColour,
|
|
|
|
|
DarkThemeIndexColour = settings.DarkThemeIndexColour,
|
|
|
|
|
PreferSystemTheming = settings.PreferSystemTheming,
|
|
|
|
|
ThemeIsDarkMode = settings.ThemeIsDarkMode,
|
|
|
|
|
IconsThemeIndexColour = settings.IconsThemeIndexColour,
|
|
|
|
|
ThemeIsDarkGray = settings.ThemeIsDarkGray,
|
|
|
|
|
ThemeIsLightGray = settings.ThemeIsLightGray
|
|
|
|
|
};
|
2023-02-18 08:52:17 +01:00
|
|
|
}
|
2026-10-01 08:05:56 +02:00
|
|
|
}
|