|
| 1 | +import { promisify } from 'util' |
| 2 | +import crypto from 'crypto' |
| 3 | +import config from '../config/server' |
| 4 | +import { ValueOf } from 'type-fest' |
| 5 | +import { User } from '../database/users' |
| 6 | + |
| 7 | +const randomBytes = promisify(crypto.randomBytes) |
| 8 | +const tokenKey = Buffer.from(config.tokenKey, 'base64') |
| 9 | + |
| 10 | +export enum tokenKinds { |
| 11 | + auth = 0, |
| 12 | + team = 1, |
| 13 | + verify = 2, |
| 14 | + ctftimeAuth = 4 |
| 15 | +} |
| 16 | + |
| 17 | +export enum VerifyTokenKinds { |
| 18 | + update = 'update', |
| 19 | + register = 'register' |
| 20 | +} |
| 21 | + |
| 22 | +export type AuthTokenData = string |
| 23 | +export type TeamTokenData = string |
| 24 | +export interface VerifyTokenData { |
| 25 | + verifyId: string |
| 26 | + kind: VerifyTokenKinds |
| 27 | + userId: User['id'] |
| 28 | + email: User['email'] |
| 29 | + division: User['division'] |
| 30 | +} |
| 31 | +export type CtftimeAuthTokenData = string |
| 32 | + |
| 33 | +// Internal map of type definitions for typing purposes only - |
| 34 | +// this type does not describe a real data-structure |
| 35 | +type TokenDataTypes = { |
| 36 | + [tokenKinds.auth]: AuthTokenData; |
| 37 | + [tokenKinds.team]: TeamTokenData; |
| 38 | + [tokenKinds.verify]: VerifyTokenData; |
| 39 | + [tokenKinds.ctftimeAuth]: CtftimeAuthTokenData; |
| 40 | +} |
| 41 | + |
| 42 | +export type Token = string |
| 43 | + |
| 44 | +interface InternalTokenData<Kind extends tokenKinds> { |
| 45 | + k: Kind |
| 46 | + t: number |
| 47 | + d: TokenDataTypes[Kind] |
| 48 | +} |
| 49 | + |
| 50 | +const tokenExpiries: Record<ValueOf<typeof tokenKinds>, number> = { |
| 51 | + [tokenKinds.auth]: Infinity, |
| 52 | + [tokenKinds.team]: Infinity, |
| 53 | + [tokenKinds.verify]: config.loginTimeout, |
| 54 | + [tokenKinds.ctftimeAuth]: config.loginTimeout |
| 55 | +} |
| 56 | + |
| 57 | +const timeNow = () => Math.floor(Date.now() / 1000) |
| 58 | + |
| 59 | +const encryptToken = async <Kind extends tokenKinds>(content: InternalTokenData<Kind>): Promise<Token> => { |
| 60 | + const iv = await randomBytes(12) |
| 61 | + const cipher = crypto.createCipheriv('aes-256-gcm', tokenKey, iv) |
| 62 | + const cipherText = cipher.update(JSON.stringify(content)) |
| 63 | + cipher.final() |
| 64 | + const tokenContent = Buffer.concat([iv, cipherText, cipher.getAuthTag()]) |
| 65 | + return tokenContent.toString('base64') |
| 66 | +} |
| 67 | + |
| 68 | +const decryptToken = async <Kind extends tokenKinds>(token: Token): Promise<InternalTokenData<Kind> | null> => { |
| 69 | + try { |
| 70 | + const tokenContent = Buffer.from(token, 'base64') |
| 71 | + const iv = tokenContent.slice(0, 12) |
| 72 | + const authTag = tokenContent.slice(tokenContent.length - 16) |
| 73 | + const cipher = crypto.createDecipheriv('aes-256-gcm', tokenKey, iv) |
| 74 | + cipher.setAuthTag(authTag) |
| 75 | + const plainText = cipher.update(tokenContent.slice(12, tokenContent.length - 16)) |
| 76 | + cipher.final() |
| 77 | + return JSON.parse(plainText.toString()) as InternalTokenData<Kind> |
| 78 | + } catch (e) { |
| 79 | + return null |
| 80 | + } |
| 81 | +} |
| 82 | + |
| 83 | +export const getData = async <Kind extends tokenKinds>(expectedTokenKind: Kind, token: Token): Promise<TokenDataTypes[Kind] | null> => { |
| 84 | + const content = await decryptToken<Kind>(token) |
| 85 | + if (content === null) { |
| 86 | + return null |
| 87 | + } |
| 88 | + const { k: kind, t: createdAt, d: data } = content |
| 89 | + if (kind !== expectedTokenKind) { |
| 90 | + return null |
| 91 | + } |
| 92 | + if (createdAt + tokenExpiries[kind] < timeNow()) { |
| 93 | + return null |
| 94 | + } |
| 95 | + return data |
| 96 | +} |
| 97 | + |
| 98 | +export const getToken = async <Kind extends tokenKinds>(tokenKind: Kind, data: TokenDataTypes[Kind]): Promise<Token> => { |
| 99 | + const token = await encryptToken({ |
| 100 | + k: tokenKind, |
| 101 | + t: timeNow(), |
| 102 | + d: data |
| 103 | + }) |
| 104 | + return token |
| 105 | +} |
0 commit comments