forked from ppy/osu-web
-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
14 changed files
with
193 additions
and
105 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,12 @@ | ||
<?php | ||
|
||
// Copyright (c) ppy Pty Ltd <[email protected]>. Licensed under the GNU Affero General Public License v3.0. | ||
// See the LICENCE file in the repository root for full licence text. | ||
|
||
declare(strict_types=1); | ||
|
||
namespace App\Exceptions; | ||
|
||
class ClientCheckParseTokenException extends \Exception | ||
{ | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -3,39 +3,101 @@ | |
// Copyright (c) ppy Pty Ltd <[email protected]>. Licensed under the GNU Affero General Public License v3.0. | ||
// See the LICENCE file in the repository root for full licence text. | ||
|
||
declare(strict_types=1); | ||
|
||
namespace App\Libraries; | ||
|
||
use App\Exceptions\ClientCheckParseTokenException; | ||
use App\Models\Build; | ||
use Illuminate\Http\Request; | ||
|
||
class ClientCheck | ||
{ | ||
public static function findBuild($user, $params): ?Build | ||
public static function parseToken(Request $request): array | ||
{ | ||
$assertValid = $GLOBALS['cfg']['osu']['client']['check_version'] && $user->findUserGroup(app('groups')->byIdentifier('admin'), true) === null; | ||
|
||
$clientHash = presence(get_string($params['version_hash'] ?? null)); | ||
if ($clientHash === null) { | ||
if ($assertValid) { | ||
abort(422, 'missing client version'); | ||
} else { | ||
return null; | ||
$token = $request->header('x-token'); | ||
$assertValid = $GLOBALS['cfg']['osu']['client']['check_version']; | ||
$ret = [ | ||
'buildId' => $GLOBALS['cfg']['osu']['client']['default_build_id'], | ||
'token' => null, | ||
]; | ||
|
||
try { | ||
if ($token === null) { | ||
throw new ClientCheckParseTokenException('missing token header'); | ||
} | ||
|
||
$input = static::splitToken($token); | ||
|
||
$build = Build::firstWhere([ | ||
'hash' => $input['clientHash'], | ||
'allow_ranking' => true, | ||
]); | ||
|
||
if ($build === null) { | ||
throw new ClientCheckParseTokenException('invalid client hash'); | ||
} | ||
|
||
$ret['buildId'] = $build->getKey(); | ||
|
||
$computed = hash_hmac( | ||
'sha1', | ||
$input['clientData'], | ||
static::getKey($build), | ||
true, | ||
); | ||
|
||
if (!hash_equals($computed, $input['expected'])) { | ||
throw new ClientCheckParseTokenException('invalid verification hash'); | ||
} | ||
} | ||
|
||
// temporary measure to allow android builds to submit without access to the underlying dll to hash | ||
if (strlen($clientHash) !== 32) { | ||
$clientHash = md5($clientHash); | ||
$now = time(); | ||
static $maxTime = 15 * 60; | ||
if (abs($now - $input['clientTime']) > $maxTime) { | ||
throw new ClientCheckParseTokenException('expired token'); | ||
} | ||
|
||
$ret['token'] = $token; | ||
} catch (ClientCheckParseTokenException $e) { | ||
abort_if($assertValid, 422, $e->getMessage()); | ||
} | ||
|
||
$build = Build::firstWhere([ | ||
'hash' => hex2bin($clientHash), | ||
'allow_ranking' => true, | ||
]); | ||
return $ret; | ||
} | ||
|
||
if ($build === null && $assertValid) { | ||
abort(422, 'invalid client hash'); | ||
public static function queueToken(?array $tokenData, int $scoreId): void | ||
{ | ||
if ($tokenData['token'] === null) { | ||
return; | ||
} | ||
|
||
return $build; | ||
\LaravelRedis::lpush($GLOBALS['cfg']['osu']['client']['token_queue'], json_encode([ | ||
'id' => $scoreId, | ||
'token' => $tokenData['token'], | ||
])); | ||
} | ||
|
||
private static function getKey(Build $build): string | ||
{ | ||
return $GLOBALS['cfg']['osu']['client']['token_keys'][$build->platform()] | ||
?? $GLOBALS['cfg']['osu']['client']['token_keys']['default'] | ||
?? ''; | ||
} | ||
|
||
private static function splitToken(string $token): array | ||
{ | ||
$data = substr($token, -82); | ||
$clientTimeHex = substr($data, 32, 8); | ||
$clientTime = strlen($clientTimeHex) === 8 | ||
? unpack('V', hex2bin($clientTimeHex))[1] | ||
: 0; | ||
|
||
return [ | ||
'clientData' => substr($data, 0, 40), | ||
'clientHash' => hex2bin(substr($data, 0, 32)), | ||
'clientTime' => $clientTime, | ||
'expected' => hex2bin(substr($data, 40, 40)), | ||
'version' => substr($data, 80, 2), | ||
]; | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.