Line data Source code
1 : /*
2 : This file is part of Challenger
3 : Copyright (C) 2023 Taler Systems SA
4 :
5 : Challenger is free software; you can redistribute it and/or modify it under the
6 : terms of the GNU General Public License as published by the Free Software
7 : Foundation; either version 3, or (at your option) any later version.
8 :
9 : Challenger is distributed in the hope that it will be useful, but WITHOUT ANY
10 : WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
11 : A PARTICULAR PURPOSE. See the GNU General Public License for more details.
12 :
13 : You should have received a copy of the GNU General Public License along with
14 : Challenger; see the file COPYING. If not, see <http://www.gnu.org/licenses/>
15 : */
16 : /**
17 : * @file src/challengerdb/do_challenge_address.c
18 : * @brief Implementation of the do_challenge_address function for Postgres
19 : * @author Christian Grothoff
20 : */
21 : #include "platform.h"
22 : #include <taler/taler_error_codes.h>
23 : #include <taler/taler_dbevents.h>
24 : #include <taler/taler_pq_lib.h>
25 : #include "do_challenge_address.h"
26 : #include "pg_helper.h"
27 :
28 :
29 : enum GNUNET_DB_QueryStatus
30 44 : CHALLENGERDB_do_challenge_address (
31 : struct CHALLENGERDB_PostgresContext *ctx,
32 : const struct CHALLENGER_ValidationNonceP *nonce,
33 : const json_t *address,
34 : struct GNUNET_TIME_Relative retransmission_frequency,
35 : uint32_t *tan,
36 : char **state,
37 : struct GNUNET_TIME_Absolute *last_tx_time,
38 : uint32_t *auth_attempts_left,
39 : uint32_t *pin_transmissions_left,
40 : bool *pin_transmit,
41 : char **client_redirect_uri,
42 : bool *address_refused,
43 : bool *solved)
44 : {
45 : struct GNUNET_TIME_Absolute now
46 44 : = GNUNET_TIME_absolute_get ();
47 : /* We must gate retransmission on
48 : last_tx_time + retransmission_frequency <= now
49 : but 'last_tx_time' is only read (under FOR UPDATE) inside the stored
50 : procedure, so we cannot form that sum here. We therefore pass the
51 : equivalent, inverted form: the *newest* 'last_tx_time' for which a
52 : retransmission is still due. The SQL then merely checks
53 : last_tx_time <= retransmit_cutoff.
54 : Note that this is deliberately a subtraction from 'now', not
55 : 'now + retransmission_frequency': the value is compared against a
56 : timestamp in the *past*. GNUNET_TIME_absolute_subtract() saturates at
57 : zero rather than underflowing, so a FOREVER frequency degrades to
58 : "never *re*transmit" (the initial TAN, sent when last_tx_time is still 0,
59 : is unaffected). */
60 : struct GNUNET_TIME_Absolute retransmit_cutoff
61 44 : = GNUNET_TIME_absolute_subtract (now,
62 : retransmission_frequency);
63 44 : struct GNUNET_PQ_QueryParam params[] = {
64 44 : GNUNET_PQ_query_param_auto_from_type (nonce),
65 44 : TALER_PQ_query_param_json (address),
66 44 : GNUNET_PQ_query_param_absolute_time (&retransmit_cutoff),
67 44 : GNUNET_PQ_query_param_absolute_time (&now),
68 44 : GNUNET_PQ_query_param_uint32 (tan),
69 : GNUNET_PQ_query_param_end
70 : };
71 : bool not_found;
72 : bool no_last_tan;
73 : uint32_t tan_out;
74 44 : struct GNUNET_PQ_ResultSpec rs[] = {
75 44 : GNUNET_PQ_result_spec_bool ("not_found",
76 : ¬_found),
77 44 : GNUNET_PQ_result_spec_absolute_time ("last_tx_time",
78 : last_tx_time),
79 44 : GNUNET_PQ_result_spec_allow_null (
80 : GNUNET_PQ_result_spec_uint32 ("last_pin",
81 : &tan_out),
82 : &no_last_tan),
83 44 : GNUNET_PQ_result_spec_bool ("pin_transmit",
84 : pin_transmit),
85 44 : GNUNET_PQ_result_spec_uint32 ("auth_attempts_left",
86 : auth_attempts_left),
87 44 : GNUNET_PQ_result_spec_uint32 ("pin_transmissions_left",
88 : pin_transmissions_left),
89 44 : GNUNET_PQ_result_spec_allow_null (
90 : GNUNET_PQ_result_spec_string ("client_redirect_uri",
91 : client_redirect_uri),
92 : NULL),
93 44 : GNUNET_PQ_result_spec_allow_null (
94 : GNUNET_PQ_result_spec_string ("state",
95 : state),
96 : NULL),
97 44 : GNUNET_PQ_result_spec_bool ("address_refused",
98 : address_refused),
99 44 : GNUNET_PQ_result_spec_bool ("solved",
100 : solved),
101 : GNUNET_PQ_result_spec_end
102 : };
103 : enum GNUNET_DB_QueryStatus qs;
104 :
105 44 : *client_redirect_uri = NULL;
106 44 : no_last_tan = true;
107 44 : PREPARE (ctx,
108 : "do_challenge_address",
109 : "SELECT "
110 : " out_not_found AS not_found"
111 : ",out_last_tx_time AS last_tx_time"
112 : ",out_pin_transmit AS pin_transmit"
113 : ",out_last_pin AS last_pin"
114 : ",out_state AS state"
115 : ",out_auth_attempts_left AS auth_attempts_left"
116 : ",out_pin_transmissions_left AS pin_transmissions_left"
117 : ",out_client_redirect_uri AS client_redirect_uri"
118 : ",out_address_refused AS address_refused"
119 : ",out_solved AS solved"
120 : " FROM challenger_do_challenge_set_address_and_pin"
121 : " ($1,$2,$3,$4,$5);");
122 44 : qs = GNUNET_PQ_eval_prepared_singleton_select (ctx->conn,
123 : "do_challenge_address",
124 : params,
125 : rs);
126 44 : if (qs <= 0)
127 0 : return qs;
128 44 : if (not_found)
129 0 : return GNUNET_DB_STATUS_SUCCESS_NO_RESULTS;
130 44 : if (! no_last_tan)
131 42 : *tan = tan_out;
132 44 : return qs;
133 : }
134 :
135 :
136 : enum GNUNET_DB_QueryStatus
137 33 : CHALLENGERDB_do_challenge_address_confirm_pin (
138 : struct CHALLENGERDB_PostgresContext *ctx,
139 : const struct CHALLENGER_ValidationNonceP *nonce,
140 : uint32_t *auth_attempts_left)
141 : {
142 33 : struct GNUNET_PQ_QueryParam params[] = {
143 33 : GNUNET_PQ_query_param_auto_from_type (nonce),
144 : GNUNET_PQ_query_param_end
145 : };
146 33 : struct GNUNET_PQ_ResultSpec rs[] = {
147 33 : GNUNET_PQ_result_spec_uint32 ("auth_attempts_left",
148 : auth_attempts_left),
149 : GNUNET_PQ_result_spec_end
150 : };
151 :
152 33 : PREPARE (ctx,
153 : "do_challenge_address_confirm_pin",
154 : "UPDATE validations SET"
155 : " last_pin=pending_pin"
156 : " ,pending_pin=NULL"
157 : " ,auth_attempts_left=3"
158 : " WHERE nonce=$1"
159 : /* nothing to promote if we did not just transmit a TAN */
160 : " AND pending_pin IS NOT NULL"
161 : /* never resurrect an already solved validation */
162 : " AND auth_attempts_left >= 0"
163 : " RETURNING auth_attempts_left;");
164 33 : return GNUNET_PQ_eval_prepared_singleton_select (
165 : ctx->conn,
166 : "do_challenge_address_confirm_pin",
167 : params,
168 : rs);
169 : }
|