Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 1 | /* |
| 2 | // Copyright (c) 2018 Intel Corporation |
| 3 | // |
| 4 | // Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | // you may not use this file except in compliance with the License. |
| 6 | // You may obtain a copy of the License at |
| 7 | // |
| 8 | // http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | // |
| 10 | // Unless required by applicable law or agreed to in writing, software |
| 11 | // distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | // See the License for the specific language governing permissions and |
| 14 | // limitations under the License. |
| 15 | */ |
| 16 | #pragma once |
Borawski.Lukasz | 43a095a | 2018-02-19 15:39:01 +0100 | [diff] [blame] | 17 | |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 18 | #include "error_messages.hpp" |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 19 | #include "node.hpp" |
Borawski.Lukasz | 4b1b868 | 2018-04-04 12:50:16 +0200 | [diff] [blame] | 20 | #include "persistent_data_middleware.hpp" |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 21 | |
| 22 | namespace redfish { |
| 23 | |
| 24 | class SessionCollection; |
| 25 | |
| 26 | class Sessions : public Node { |
| 27 | public: |
Borawski.Lukasz | 43a095a | 2018-02-19 15:39:01 +0100 | [diff] [blame] | 28 | Sessions(CrowApp& app) |
Ed Tanous | 6c23301 | 2018-03-15 14:43:56 -0700 | [diff] [blame] | 29 | : Node(app, "/redfish/v1/SessionService/Sessions/<str>/", std::string()) { |
Borawski.Lukasz | c1a46bd | 2018-02-08 13:31:59 +0100 | [diff] [blame] | 30 | Node::json["@odata.type"] = "#Session.v1_0_2.Session"; |
| 31 | Node::json["@odata.context"] = "/redfish/v1/$metadata#Session.Session"; |
| 32 | Node::json["Name"] = "User Session"; |
| 33 | Node::json["Description"] = "Manager User Session"; |
Ed Tanous | 3ebd75f | 2018-03-05 18:20:01 -0800 | [diff] [blame] | 34 | |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 35 | entityPrivileges = { |
| 36 | {boost::beast::http::verb::get, {{"Login"}}}, |
| 37 | {boost::beast::http::verb::head, {{"Login"}}}, |
| 38 | {boost::beast::http::verb::patch, {{"ConfigureManager"}}}, |
| 39 | {boost::beast::http::verb::put, {{"ConfigureManager"}}}, |
| 40 | {boost::beast::http::verb::delete_, {{"ConfigureManager"}}}, |
| 41 | {boost::beast::http::verb::post, {{"ConfigureManager"}}}}; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 42 | } |
| 43 | |
| 44 | private: |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 45 | void doGet(crow::Response& res, const crow::Request& req, |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 46 | const std::vector<std::string>& params) override { |
| 47 | auto session = |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 48 | crow::persistent_data::SessionStore::getInstance().getSessionByUid( |
Borawski.Lukasz | 4b1b868 | 2018-04-04 12:50:16 +0200 | [diff] [blame] | 49 | params[0]); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 50 | |
| 51 | if (session == nullptr) { |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 52 | messages::addMessageToErrorJson( |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 53 | res.jsonValue, messages::resourceNotFound("Session", params[0])); |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 54 | |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 55 | res.result(boost::beast::http::status::not_found); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 56 | res.end(); |
| 57 | return; |
| 58 | } |
| 59 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 60 | Node::json["Id"] = session->uniqueId; |
Borawski.Lukasz | c1a46bd | 2018-02-08 13:31:59 +0100 | [diff] [blame] | 61 | Node::json["UserName"] = session->username; |
| 62 | Node::json["@odata.id"] = |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 63 | "/redfish/v1/SessionService/Sessions/" + session->uniqueId; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 64 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 65 | res.jsonValue = Node::json; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 66 | res.end(); |
| 67 | } |
| 68 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 69 | void doDelete(crow::Response& res, const crow::Request& req, |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 70 | const std::vector<std::string>& params) override { |
| 71 | // Need only 1 param which should be id of session to be deleted |
| 72 | if (params.size() != 1) { |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 73 | // This should be handled by crow and never happen |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 74 | BMCWEB_LOG_ERROR |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 75 | << "Session DELETE has been called with invalid number of params"; |
| 76 | |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 77 | res.result(boost::beast::http::status::bad_request); |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 78 | messages::addMessageToErrorJson(res.jsonValue, messages::generalError()); |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 79 | |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 80 | res.end(); |
| 81 | return; |
| 82 | } |
| 83 | |
| 84 | auto session = |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 85 | crow::persistent_data::SessionStore::getInstance().getSessionByUid( |
Borawski.Lukasz | 4b1b868 | 2018-04-04 12:50:16 +0200 | [diff] [blame] | 86 | params[0]); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 87 | |
| 88 | if (session == nullptr) { |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 89 | messages::addMessageToErrorJson( |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 90 | res.jsonValue, messages::resourceNotFound("Session", params[0])); |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 91 | |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 92 | res.result(boost::beast::http::status::not_found); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 93 | res.end(); |
| 94 | return; |
| 95 | } |
| 96 | |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 97 | // DELETE should return representation of object that will be removed |
| 98 | doGet(res, req, params); |
| 99 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 100 | crow::persistent_data::SessionStore::getInstance().removeSession(session); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 101 | } |
| 102 | |
| 103 | /** |
| 104 | * This allows SessionCollection to reuse this class' doGet method, to |
| 105 | * maintain consistency of returned data, as Collection's doPost should return |
| 106 | * data for created member which should match member's doGet result in 100% |
| 107 | */ |
| 108 | friend SessionCollection; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 109 | }; |
| 110 | |
| 111 | class SessionCollection : public Node { |
| 112 | public: |
Borawski.Lukasz | 43a095a | 2018-02-19 15:39:01 +0100 | [diff] [blame] | 113 | SessionCollection(CrowApp& app) |
Ed Tanous | 3ebd75f | 2018-03-05 18:20:01 -0800 | [diff] [blame] | 114 | : Node(app, "/redfish/v1/SessionService/Sessions/"), memberSession(app) { |
Borawski.Lukasz | c1a46bd | 2018-02-08 13:31:59 +0100 | [diff] [blame] | 115 | Node::json["@odata.type"] = "#SessionCollection.SessionCollection"; |
| 116 | Node::json["@odata.id"] = "/redfish/v1/SessionService/Sessions/"; |
| 117 | Node::json["@odata.context"] = |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 118 | "/redfish/v1/$metadata#SessionCollection.SessionCollection"; |
Borawski.Lukasz | c1a46bd | 2018-02-08 13:31:59 +0100 | [diff] [blame] | 119 | Node::json["Name"] = "Session Collection"; |
| 120 | Node::json["Description"] = "Session Collection"; |
| 121 | Node::json["Members@odata.count"] = 0; |
| 122 | Node::json["Members"] = nlohmann::json::array(); |
Ed Tanous | 3ebd75f | 2018-03-05 18:20:01 -0800 | [diff] [blame] | 123 | |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 124 | entityPrivileges = { |
| 125 | {boost::beast::http::verb::get, {{"Login"}}}, |
| 126 | {boost::beast::http::verb::head, {{"Login"}}}, |
| 127 | {boost::beast::http::verb::patch, {{"ConfigureManager"}}}, |
| 128 | {boost::beast::http::verb::put, {{"ConfigureManager"}}}, |
| 129 | {boost::beast::http::verb::delete_, {{"ConfigureManager"}}}, |
| 130 | {boost::beast::http::verb::post, {}}}; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 131 | } |
| 132 | |
| 133 | private: |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 134 | void doGet(crow::Response& res, const crow::Request& req, |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 135 | const std::vector<std::string>& params) override { |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 136 | std::vector<const std::string*> sessionIds = |
| 137 | crow::persistent_data::SessionStore::getInstance().getUniqueIds( |
| 138 | false, crow::persistent_data::PersistenceType::TIMEOUT); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 139 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 140 | Node::json["Members@odata.count"] = sessionIds.size(); |
Borawski.Lukasz | c1a46bd | 2018-02-08 13:31:59 +0100 | [diff] [blame] | 141 | Node::json["Members"] = nlohmann::json::array(); |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 142 | for (const std::string* uid : sessionIds) { |
Borawski.Lukasz | c1a46bd | 2018-02-08 13:31:59 +0100 | [diff] [blame] | 143 | Node::json["Members"].push_back( |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 144 | {{"@odata.id", "/redfish/v1/SessionService/Sessions/" + *uid}}); |
| 145 | } |
| 146 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 147 | res.jsonValue = Node::json; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 148 | res.end(); |
| 149 | } |
| 150 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 151 | void doPost(crow::Response& res, const crow::Request& req, |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 152 | const std::vector<std::string>& params) override { |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 153 | boost::beast::http::status status; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 154 | std::string username; |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 155 | bool userAuthSuccessful = |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 156 | authenticateUser(req, status, username, res.jsonValue); |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 157 | res.result(status); |
| 158 | |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 159 | if (!userAuthSuccessful) { |
| 160 | res.end(); |
| 161 | return; |
| 162 | } |
| 163 | |
| 164 | // User is authenticated - create session for him |
| 165 | auto session = |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 166 | crow::persistent_data::SessionStore::getInstance().generateUserSession( |
Borawski.Lukasz | 4b1b868 | 2018-04-04 12:50:16 +0200 | [diff] [blame] | 167 | username); |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 168 | res.addHeader("X-Auth-Token", session->sessionToken); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 169 | |
Ed Tanous | b9845d9 | 2018-07-24 14:38:06 -0700 | [diff] [blame] | 170 | res.addHeader("Location", |
| 171 | "/redfish/v1/SessionService/Sessions/" + session->uniqueId); |
| 172 | |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 173 | // Return data for created session |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 174 | memberSession.doGet(res, req, {session->uniqueId}); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 175 | |
| 176 | // No need for res.end(), as it is called by doGet() |
| 177 | } |
| 178 | |
| 179 | /** |
| 180 | * @brief Verifies data provided in request and tries to authenticate user |
| 181 | * |
| 182 | * @param[in] req Crow request containing authentication data |
| 183 | * @param[out] httpRespCode HTTP Code that should be returned in response |
| 184 | * @param[out] user Retrieved username - not filled on failure |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 185 | * @param[out] errJson JSON to which error messages will be written |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 186 | * |
| 187 | * @return true if authentication was successful, false otherwise |
| 188 | */ |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 189 | bool authenticateUser(const crow::Request& req, |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 190 | boost::beast::http::status& httpRespCode, |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 191 | std::string& user, nlohmann::json& errJson) { |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 192 | // We need only UserName and Password - nothing more, nothing less |
| 193 | static constexpr const unsigned int numberOfRequiredFieldsInReq = 2; |
| 194 | |
| 195 | // call with exceptions disabled |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 196 | auto loginCredentials = nlohmann::json::parse(req.body, nullptr, false); |
| 197 | if (loginCredentials.is_discarded()) { |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 198 | httpRespCode = boost::beast::http::status::bad_request; |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 199 | |
| 200 | messages::addMessageToErrorJson(errJson, messages::malformedJSON()); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 201 | |
| 202 | return false; |
| 203 | } |
| 204 | |
| 205 | // Check that there are only as many fields as there should be |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 206 | if (loginCredentials.size() != numberOfRequiredFieldsInReq) { |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 207 | httpRespCode = boost::beast::http::status::bad_request; |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 208 | |
| 209 | messages::addMessageToErrorJson(errJson, messages::malformedJSON()); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 210 | |
| 211 | return false; |
| 212 | } |
| 213 | |
| 214 | // Find fields that we need - UserName and Password |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 215 | auto userIt = loginCredentials.find("UserName"); |
| 216 | auto passIt = loginCredentials.find("Password"); |
| 217 | if (userIt == loginCredentials.end() || passIt == loginCredentials.end()) { |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 218 | httpRespCode = boost::beast::http::status::bad_request; |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 219 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 220 | if (userIt == loginCredentials.end()) { |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 221 | messages::addMessageToErrorJson(errJson, |
| 222 | messages::propertyMissing("UserName")); |
| 223 | } |
| 224 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 225 | if (passIt == loginCredentials.end()) { |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 226 | messages::addMessageToErrorJson(errJson, |
| 227 | messages::propertyMissing("Password")); |
| 228 | } |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 229 | |
| 230 | return false; |
| 231 | } |
| 232 | |
| 233 | // Check that given data is of valid type (string) |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 234 | if (!userIt->is_string() || !passIt->is_string()) { |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 235 | httpRespCode = boost::beast::http::status::bad_request; |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 236 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 237 | if (!userIt->is_string()) { |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 238 | messages::addMessageToErrorJson( |
| 239 | errJson, |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 240 | messages::propertyValueTypeError(userIt->dump(), "UserName")); |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 241 | } |
| 242 | |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 243 | if (!passIt->is_string()) { |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 244 | messages::addMessageToErrorJson( |
| 245 | errJson, |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 246 | messages::propertyValueTypeError(userIt->dump(), "Password")); |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 247 | } |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 248 | |
| 249 | return false; |
| 250 | } |
| 251 | |
| 252 | // Extract username and password |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 253 | std::string username = userIt->get<const std::string>(); |
| 254 | std::string password = passIt->get<const std::string>(); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 255 | |
| 256 | // Verify that required fields are not empty |
| 257 | if (username.empty() || password.empty()) { |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 258 | httpRespCode = boost::beast::http::status::bad_request; |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 259 | |
| 260 | if (username.empty()) { |
| 261 | messages::addMessageToErrorJson(errJson, |
| 262 | messages::propertyMissing("UserName")); |
| 263 | } |
| 264 | |
| 265 | if (password.empty()) { |
| 266 | messages::addMessageToErrorJson(errJson, |
| 267 | messages::propertyMissing("Password")); |
| 268 | } |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 269 | |
| 270 | return false; |
| 271 | } |
| 272 | |
| 273 | // Finally - try to authenticate user |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 274 | if (!pamAuthenticateUser(username, password)) { |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 275 | httpRespCode = boost::beast::http::status::unauthorized; |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 276 | |
| 277 | messages::addMessageToErrorJson( |
| 278 | errJson, messages::resourceAtUriUnauthorized( |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 279 | std::string(req.url), "Invalid username or password")); |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 280 | |
| 281 | return false; |
| 282 | } |
| 283 | |
| 284 | // User authenticated successfully |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 285 | httpRespCode = boost::beast::http::status::ok; |
Kowalski, Kamil | f4c4dcf | 2018-01-29 14:55:35 +0100 | [diff] [blame] | 286 | user = username; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 287 | |
| 288 | return true; |
| 289 | } |
| 290 | |
| 291 | /** |
| 292 | * Member session to ensure consistency between collection's doPost and |
| 293 | * member's doGet, as they should return 100% matching data |
| 294 | */ |
| 295 | Sessions memberSession; |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 296 | }; |
| 297 | |
Borawski.Lukasz | 5d27b85 | 2018-02-08 13:24:24 +0100 | [diff] [blame] | 298 | class SessionService : public Node { |
| 299 | public: |
Ed Tanous | 3ebd75f | 2018-03-05 18:20:01 -0800 | [diff] [blame] | 300 | SessionService(CrowApp& app) : Node(app, "/redfish/v1/SessionService/") { |
Borawski.Lukasz | 5d27b85 | 2018-02-08 13:24:24 +0100 | [diff] [blame] | 301 | Node::json["@odata.type"] = "#SessionService.v1_0_2.SessionService"; |
| 302 | Node::json["@odata.id"] = "/redfish/v1/SessionService/"; |
| 303 | Node::json["@odata.context"] = |
| 304 | "/redfish/v1/$metadata#SessionService.SessionService"; |
| 305 | Node::json["Name"] = "Session Service"; |
Ed Tanous | 6c23301 | 2018-03-15 14:43:56 -0700 | [diff] [blame] | 306 | Node::json["Id"] = "SessionService"; |
Borawski.Lukasz | 5d27b85 | 2018-02-08 13:24:24 +0100 | [diff] [blame] | 307 | Node::json["Description"] = "Session Service"; |
| 308 | Node::json["SessionTimeout"] = |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 309 | crow::persistent_data::SessionStore::getInstance() |
| 310 | .getTimeoutInSeconds(); |
Borawski.Lukasz | 5d27b85 | 2018-02-08 13:24:24 +0100 | [diff] [blame] | 311 | Node::json["ServiceEnabled"] = true; |
Ed Tanous | 3ebd75f | 2018-03-05 18:20:01 -0800 | [diff] [blame] | 312 | |
Ed Tanous | e0d918b | 2018-03-27 17:41:04 -0700 | [diff] [blame] | 313 | entityPrivileges = { |
| 314 | {boost::beast::http::verb::get, {{"Login"}}}, |
| 315 | {boost::beast::http::verb::head, {{"Login"}}}, |
| 316 | {boost::beast::http::verb::patch, {{"ConfigureManager"}}}, |
| 317 | {boost::beast::http::verb::put, {{"ConfigureManager"}}}, |
| 318 | {boost::beast::http::verb::delete_, {{"ConfigureManager"}}}, |
| 319 | {boost::beast::http::verb::post, {{"ConfigureManager"}}}}; |
Borawski.Lukasz | 5d27b85 | 2018-02-08 13:24:24 +0100 | [diff] [blame] | 320 | } |
| 321 | |
| 322 | private: |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 323 | void doGet(crow::Response& res, const crow::Request& req, |
Borawski.Lukasz | 5d27b85 | 2018-02-08 13:24:24 +0100 | [diff] [blame] | 324 | const std::vector<std::string>& params) override { |
Ed Tanous | 55c7b7a | 2018-05-22 15:27:24 -0700 | [diff] [blame] | 325 | res.jsonValue = Node::json; |
Borawski.Lukasz | 5d27b85 | 2018-02-08 13:24:24 +0100 | [diff] [blame] | 326 | res.end(); |
| 327 | } |
| 328 | }; |
| 329 | |
Kowalski, Kamil | 2b7981f | 2018-01-31 13:24:59 +0100 | [diff] [blame] | 330 | } // namespace redfish |