UserSession.cs 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185
  1. /*
  2. Technitium DNS Server
  3. Copyright (C) 2023 Shreyas Zare (shreyas@technitium.com)
  4. This program is free software: you can redistribute it and/or modify
  5. it under the terms of the GNU General Public License as published by
  6. the Free Software Foundation, either version 3 of the License, or
  7. (at your option) any later version.
  8. This program is distributed in the hope that it will be useful,
  9. but WITHOUT ANY WARRANTY; without even the implied warranty of
  10. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  11. GNU General Public License for more details.
  12. You should have received a copy of the GNU General Public License
  13. along with this program. If not, see <http://www.gnu.org/licenses/>.
  14. */
  15. using System;
  16. using System.IO;
  17. using System.Net;
  18. using System.Security.Cryptography;
  19. using TechnitiumLibrary.IO;
  20. using TechnitiumLibrary.Net;
  21. namespace DnsServerCore.Auth
  22. {
  23. enum UserSessionType : byte
  24. {
  25. Unknown = 0,
  26. Standard = 1,
  27. ApiToken = 2
  28. }
  29. class UserSession : IComparable<UserSession>
  30. {
  31. #region variables
  32. static readonly RandomNumberGenerator _rng = RandomNumberGenerator.Create();
  33. readonly string _token;
  34. readonly UserSessionType _type;
  35. readonly string _tokenName;
  36. readonly User _user;
  37. DateTime _lastSeen;
  38. IPAddress _lastSeenRemoteAddress;
  39. string _lastSeenUserAgent;
  40. #endregion
  41. #region constructor
  42. public UserSession(UserSessionType type, string tokenName, User user, IPAddress remoteAddress, string lastSeenUserAgent)
  43. {
  44. if ((tokenName is not null) && (tokenName.Length > 255))
  45. throw new ArgumentOutOfRangeException(nameof(tokenName), "Token name length cannot exceed 255 characters.");
  46. if (remoteAddress.IsIPv4MappedToIPv6)
  47. remoteAddress = remoteAddress.MapToIPv4();
  48. byte[] tokenBytes = new byte[32];
  49. _rng.GetBytes(tokenBytes);
  50. _token = Convert.ToHexString(tokenBytes).ToLower();
  51. _type = type;
  52. _tokenName = tokenName;
  53. _user = user;
  54. _lastSeen = DateTime.UtcNow;
  55. _lastSeenRemoteAddress = remoteAddress;
  56. _lastSeenUserAgent = lastSeenUserAgent;
  57. if ((_lastSeenUserAgent is not null) && (_lastSeenUserAgent.Length > 255))
  58. _lastSeenUserAgent = _lastSeenUserAgent.Substring(0, 255);
  59. }
  60. public UserSession(BinaryReader bR, AuthManager authManager)
  61. {
  62. switch (bR.ReadByte())
  63. {
  64. case 1:
  65. _token = bR.ReadShortString();
  66. _type = (UserSessionType)bR.ReadByte();
  67. _tokenName = bR.ReadShortString();
  68. if (_tokenName.Length == 0)
  69. _tokenName = null;
  70. _user = authManager.GetUser(bR.ReadShortString());
  71. _lastSeen = bR.ReadDateTime();
  72. _lastSeenRemoteAddress = IPAddressExtensions.ReadFrom(bR);
  73. _lastSeenUserAgent = bR.ReadShortString();
  74. if (_lastSeenUserAgent.Length == 0)
  75. _lastSeenUserAgent = null;
  76. break;
  77. default:
  78. throw new InvalidDataException("Invalid data or version not supported.");
  79. }
  80. }
  81. #endregion
  82. #region public
  83. public void UpdateLastSeen(IPAddress remoteAddress, string lastSeenUserAgent)
  84. {
  85. if (remoteAddress.IsIPv4MappedToIPv6)
  86. remoteAddress = remoteAddress.MapToIPv4();
  87. _lastSeen = DateTime.UtcNow;
  88. _lastSeenRemoteAddress = remoteAddress;
  89. _lastSeenUserAgent = lastSeenUserAgent;
  90. if ((_lastSeenUserAgent is not null) && (_lastSeenUserAgent.Length > 255))
  91. _lastSeenUserAgent = _lastSeenUserAgent.Substring(0, 255);
  92. }
  93. public bool HasExpired()
  94. {
  95. if (_type == UserSessionType.ApiToken)
  96. return false;
  97. if (_user.SessionTimeoutSeconds == 0)
  98. return false;
  99. return _lastSeen.AddSeconds(_user.SessionTimeoutSeconds) < DateTime.UtcNow;
  100. }
  101. public void WriteTo(BinaryWriter bW)
  102. {
  103. bW.Write((byte)1);
  104. bW.WriteShortString(_token);
  105. bW.Write((byte)_type);
  106. if (_tokenName is null)
  107. bW.Write((byte)0);
  108. else
  109. bW.WriteShortString(_tokenName);
  110. bW.WriteShortString(_user.Username);
  111. bW.Write(_lastSeen);
  112. _lastSeenRemoteAddress.WriteTo(bW);
  113. if (_lastSeenUserAgent is null)
  114. bW.Write((byte)0);
  115. else
  116. bW.WriteShortString(_lastSeenUserAgent);
  117. }
  118. public int CompareTo(UserSession other)
  119. {
  120. return other._lastSeen.CompareTo(_lastSeen);
  121. }
  122. #endregion
  123. #region properties
  124. public string Token
  125. { get { return _token; } }
  126. public UserSessionType Type
  127. { get { return _type; } }
  128. public string TokenName
  129. { get { return _tokenName; } }
  130. public User User
  131. { get { return _user; } }
  132. public DateTime LastSeen
  133. { get { return _lastSeen; } }
  134. public IPAddress LastSeenRemoteAddress
  135. { get { return _lastSeenRemoteAddress; } }
  136. public string LastSeenUserAgent
  137. { get { return _lastSeenUserAgent; } }
  138. #endregion
  139. }
  140. }