fix crypt error in case of oidc and normal login both is enabled

This commit is contained in:
Avinash Gusain 2024-09-16 11:02:24 +05:30
parent ed41d8e45f
commit 23f4e52873

View file

@ -16,6 +16,29 @@ class MainAccount extends Account
{ {
$oStorage = \RainLoop\Api::Actions()->StorageProvider(); $oStorage = \RainLoop\Api::Actions()->StorageProvider();
$sKey = $oStorage->Get($this, StorageType::ROOT, '.cryptkey'); $sKey = $oStorage->Get($this, StorageType::ROOT, '.cryptkey');
// Get the AppManager from the server container
$appManager = \OC::$server->getAppManager();
// Check if the OIDC Login app is enabled
$isEnabled = $appManager->isEnabledForUser('oidc_login');
// If OIDC Login is enabled then we will assign $pwd instead of $this->IncPassword() and $pwd value is taken by following similar approach as https://github.com/the-djmaze/snappymail/blob/0db6c6ab5f9e05c46b13ebbdaf351341710438ac/plugins/login-gmail/index.php#L125
if ($isEnabled) {
$sUID = \OC::$server->getUserSession()->getUser()->getUID();
$pwd = new \SnappyMail\SensitiveString($sUID);
if ($sKey) {
$sKey = \SnappyMail\Crypt::DecryptFromJSON($sKey, $pwd);
if (!$sKey) {
throw new ClientException(Notifications::CryptKeyError);
}
$sKey = \SnappyMail\Crypt::EncryptToJSON($sKey, $pwd);
if ($sKey) {
$this->sCryptKey = null;
if (\RainLoop\Api::Actions()->StorageProvider()->Put($this, StorageType::ROOT, '.cryptkey', $sKey)) {
return true;
}
}
}
} else {
if ($sKey) { if ($sKey) {
$sKey = \SnappyMail\Crypt::DecryptFromJSON($sKey, $oOldPass); $sKey = \SnappyMail\Crypt::DecryptFromJSON($sKey, $oOldPass);
if (!$sKey) { if (!$sKey) {
@ -29,6 +52,7 @@ class MainAccount extends Account
} }
} }
} }
}
return false; return false;
} }
@ -39,6 +63,29 @@ class MainAccount extends Account
// can use the old password to re-seal the cryptkey // can use the old password to re-seal the cryptkey
$oStorage = \RainLoop\Api::Actions()->StorageProvider(); $oStorage = \RainLoop\Api::Actions()->StorageProvider();
$sKey = $oStorage->Get($this, StorageType::ROOT, '.cryptkey'); $sKey = $oStorage->Get($this, StorageType::ROOT, '.cryptkey');
// Get the AppManager from the server container
$appManager = \OC::$server->getAppManager();
// Check if the OIDC Login app is enabled
$isEnabled = $appManager->isEnabledForUser('oidc_login');
// If OIDC Login app is enabled then we will assign $pwd instead of $this->IncPassword() and $pwd value is taken by following similar approach as https://github.com/the-djmaze/snappymail/blob/0db6c6ab5f9e05c46b13ebbdaf351341710438ac/plugins/login-gmail/index.php#L125
if ($isEnabled) {
$sUID = \OC::$server->getUserSession()->getUser()->getUID();
$pwd = new \SnappyMail\SensitiveString($sUID);
if (!$sKey) {
$sKey = \SnappyMail\Crypt::EncryptToJSON(
\sha1($pwd . APP_SALT),
$pwd
);
$oStorage->Put($this, StorageType::ROOT, '.cryptkey', $sKey);
}
$sKey = \SnappyMail\Crypt::DecryptFromJSON($sKey, $pwd);
if (!$sKey) {
throw new ClientException(Notifications::CryptKeyError);
}
$this->sCryptKey = new SensitiveString(\hex2bin($sKey));
} else {
if (!$sKey) { if (!$sKey) {
$sKey = \SnappyMail\Crypt::EncryptToJSON( $sKey = \SnappyMail\Crypt::EncryptToJSON(
\sha1($this->IncPassword() . APP_SALT), \sha1($this->IncPassword() . APP_SALT),
@ -52,6 +99,8 @@ class MainAccount extends Account
} }
$this->sCryptKey = new SensitiveString(\hex2bin($sKey)); $this->sCryptKey = new SensitiveString(\hex2bin($sKey));
} }
}
return $this->sCryptKey; return $this->sCryptKey;
} }