passman/lib/Service/CredentialService.php

182 lines
5.3 KiB
PHP
Raw Normal View History

2016-09-12 01:45:20 +08:00
<?php
/**
* Nextcloud - passman
*
2016-10-19 23:44:19 +08:00
* @copyright Copyright (c) 2016, Sander Brand (brantje@gmail.com)
* @copyright Copyright (c) 2016, Marcos Zuriaga Miguel (wolfi@wolfi.es)
* @license GNU AGPL version 3 or any later version
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as
* published by the Free Software Foundation, either version 3 of the
* License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
2016-09-12 01:45:20 +08:00
*
*/
namespace OCA\Passman\Service;
2016-10-05 19:46:25 +08:00
use OCA\Passman\Db\Credential;
2016-10-23 18:14:43 +08:00
use OCA\Passman\Db\CredentialRevision;
use OCA\Passman\Db\SharingACL;
use OCA\Passman\Db\SharingACLMapper;
2016-09-12 01:45:20 +08:00
use OCP\IConfig;
use OCP\AppFramework\Db\DoesNotExistException;
use OCA\Passman\Db\CredentialMapper;
class CredentialService {
private $credentialMapper;
2017-01-02 22:25:41 +08:00
private $sharingACL;
private $encryptService;
private $server_key;
2016-09-12 01:45:20 +08:00
2017-01-02 22:25:41 +08:00
public function __construct(CredentialMapper $credentialMapper, SharingACLMapper $sharingACL, EncryptService $encryptService) {
2016-09-12 01:45:20 +08:00
$this->credentialMapper = $credentialMapper;
2017-01-02 22:25:41 +08:00
$this->sharingACL = $sharingACL;
$this->encryptService = $encryptService;
$this->server_key = \OC::$server->getConfig()->getSystemValue('passwordsalt', '');
2016-09-12 01:45:20 +08:00
}
2016-10-05 19:46:25 +08:00
/**
* Create a new credential
2017-01-02 22:25:41 +08:00
*
2017-01-03 05:06:55 +08:00
* @param array $credential
2016-10-05 19:46:25 +08:00
* @return Credential
*/
2016-09-12 01:45:20 +08:00
public function createCredential($credential) {
2017-01-02 22:25:41 +08:00
$credential = $this->encryptService->encryptCredential($credential);
2016-09-12 01:45:20 +08:00
return $this->credentialMapper->create($credential);
}
2016-09-12 02:47:29 +08:00
2016-10-23 18:14:43 +08:00
/**
* Update credential
2017-01-02 22:25:41 +08:00
*
* @param $credential array | Credential
* @param $useRawUser bool
2016-10-23 18:14:43 +08:00
* @return Credential
*/
public function updateCredential($credential, $useRawUser = false) {
2017-01-02 22:25:41 +08:00
$credential = $this->encryptService->encryptCredential($credential);
return $this->credentialMapper->updateCredential($credential, $useRawUser);
2016-09-24 00:17:47 +08:00
}
2016-10-23 18:14:43 +08:00
/**
* Update credential
2017-01-02 22:25:41 +08:00
*
2016-10-23 18:14:43 +08:00
* @param $credential Credential
2017-01-02 22:25:41 +08:00
* @return Credential
2016-10-23 18:14:43 +08:00
*/
public function upd(Credential $credential) {
2017-01-02 22:25:41 +08:00
$credential = $this->encryptService->encryptCredential($credential);
return $this->credentialMapper->updateCredential($credential);
2016-09-15 03:12:10 +08:00
}
2016-10-23 18:14:43 +08:00
/**
* Delete credential
2017-01-02 22:25:41 +08:00
*
2016-10-23 18:14:43 +08:00
* @param Credential $credential
* @return \OCP\AppFramework\Db\Entity
*/
2017-01-02 22:25:41 +08:00
public function deleteCredential(Credential $credential) {
return $this->credentialMapper->deleteCredential($credential);
}
2016-10-23 18:14:43 +08:00
/**
* Get credentials by vault id
2017-01-02 22:25:41 +08:00
*
2016-10-23 18:14:43 +08:00
* @param $vault_id
* @param $user_id
2017-01-02 22:25:41 +08:00
* @return \OCA\Passman\Db\Credential[]
2016-10-23 18:14:43 +08:00
*/
2016-09-23 22:52:41 +08:00
public function getCredentialsByVaultId($vault_id, $user_id) {
2017-01-02 22:25:41 +08:00
$credentials = $this->credentialMapper->getCredentialsByVaultId($vault_id, $user_id);
foreach ($credentials as $index => $credential) {
$credentials[$index] = $this->encryptService->decryptCredential($credential);
}
return $credentials;
2016-09-12 02:47:29 +08:00
}
2016-09-23 22:52:41 +08:00
2016-10-23 18:14:43 +08:00
/**
* Get a random credential from given vault
2017-01-02 22:25:41 +08:00
*
2016-10-23 18:14:43 +08:00
* @param $vault_id
* @param $user_id
* @return mixed
*/
2016-10-01 02:43:20 +08:00
public function getRandomCredentialByVaultId($vault_id, $user_id) {
$credentials = $this->credentialMapper->getRandomCredentialByVaultId($vault_id, $user_id);
2017-01-02 22:25:41 +08:00
foreach ($credentials as $index => $credential) {
$credentials[$index] = $this->encryptService->decryptCredential($credential);
}
return array_pop($credentials);
2016-10-01 02:43:20 +08:00
}
2016-10-23 18:14:43 +08:00
/**
* Get expired credentials.
2017-01-02 22:25:41 +08:00
*
2016-10-23 18:14:43 +08:00
* @param $timestamp
* @return \OCA\Passman\Db\Credential[]
*/
2016-09-23 22:52:41 +08:00
public function getExpiredCredentials($timestamp) {
2017-01-02 22:25:41 +08:00
$credentials = $this->credentialMapper->getExpiredCredentials($timestamp);
foreach ($credentials as $index => $credential) {
$credentials[$index] = $this->encryptService->decryptCredential($credential);
}
return $credentials;
}
2016-09-23 22:52:41 +08:00
2016-10-23 18:14:43 +08:00
/**
* Get a single credential.
2017-01-02 22:25:41 +08:00
*
2016-10-23 18:14:43 +08:00
* @param $credential_id
* @param $user_id
* @return Credential
* @throws DoesNotExistException
*/
2017-01-02 22:25:41 +08:00
public function getCredentialById($credential_id, $user_id) {
$credential = $this->credentialMapper->getCredentialById($credential_id);
if ($credential->getUserId() === $user_id) {
2017-08-13 20:23:23 +08:00
return $this->encryptService->decryptCredential($credential);
2017-01-02 22:25:41 +08:00
} else {
$acl = $this->sharingACL->getItemACL($user_id, $credential->getGuid());
if ($acl->hasPermission(SharingACL::READ)) {
return $this->encryptService->decryptCredential($credential);
2017-01-12 01:09:10 +08:00
} else {
throw new DoesNotExistException("Did expect one result but found none when executing");
2016-12-20 01:43:15 +08:00
}
2017-01-02 22:25:41 +08:00
}
2016-09-23 22:52:41 +08:00
}
2016-10-23 18:14:43 +08:00
/**
* Get credential label by credential id.
2017-01-02 22:25:41 +08:00
*
2016-10-23 18:14:43 +08:00
* @param $credential_id
* @return Credential
*/
2017-01-02 22:25:41 +08:00
public function getCredentialLabelById($credential_id) {
$credential = $this->credentialMapper->getCredentialLabelById($credential_id);
return $this->encryptService->decryptCredential($credential);
}
2016-10-23 18:14:43 +08:00
/**
* Get credential by guid
2017-01-02 22:25:41 +08:00
*
2016-10-23 18:14:43 +08:00
* @param $credential_guid
* @param null $user_id
* @return Credential
*/
2017-01-02 22:25:41 +08:00
public function getCredentialByGUID($credential_guid, $user_id = null) {
$credential = $this->credentialMapper->getCredentialByGUID($credential_guid, $user_id);
return $this->encryptService->decryptCredential($credential);
}
2016-09-12 01:45:20 +08:00
}