123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491 |
- import 'dart:convert';
- import 'dart:io' as io;
- import 'dart:typed_data';
- import 'package:bip39/bip39.dart' as bip39;
- import 'package:ente_auth/core/constants.dart';
- import 'package:ente_auth/core/event_bus.dart';
- import 'package:ente_auth/events/signed_in_event.dart';
- import 'package:ente_auth/events/signed_out_event.dart';
- import 'package:ente_auth/models/key_attributes.dart';
- import 'package:ente_auth/models/key_gen_result.dart';
- import 'package:ente_auth/models/private_key_attributes.dart';
- import 'package:ente_auth/store/authenticator_db.dart';
- import 'package:ente_auth/utils/crypto_util.dart';
- import 'package:flutter_secure_storage/flutter_secure_storage.dart';
- import 'package:flutter_sodium/flutter_sodium.dart';
- import 'package:logging/logging.dart';
- import 'package:path_provider/path_provider.dart';
- import 'package:shared_preferences/shared_preferences.dart';
- import 'package:tuple/tuple.dart';
- class Configuration {
- Configuration._privateConstructor();
- static final Configuration instance = Configuration._privateConstructor();
- static const endpoint = String.fromEnvironment(
- "endpoint",
- defaultValue: kDefaultProductionEndpoint,
- );
- static const emailKey = "email";
- static const keyAttributesKey = "key_attributes";
- static const keyKey = "key";
- static const keyShouldShowLockScreen = "should_show_lock_screen";
- static const lastTempFolderClearTimeKey = "last_temp_folder_clear_time";
- static const secretKeyKey = "secret_key";
- static const authSecretKeyKey = "auth_secret_key";
- static const tokenKey = "token";
- static const encryptedTokenKey = "encrypted_token";
- static const userIDKey = "user_id";
- static const hasMigratedSecureStorageKey = "has_migrated_secure_storage";
- final kTempFolderDeletionTimeBuffer = const Duration(days: 1).inMicroseconds;
- static final _logger = Logger("Configuration");
- String? _cachedToken;
- late String _documentsDirectory;
- String? _key;
- late SharedPreferences _preferences;
- String? _secretKey;
- String? _authSecretKey;
- late FlutterSecureStorage _secureStorage;
- late String _tempDirectory;
- late String _thumbnailCacheDirectory;
- // 6th July 22: Remove this after 3 months. Hopefully, active users
- // will migrate to newer version of the app, where shared media is stored
- // on appSupport directory which OS won't clean up automatically
- late String _sharedTempMediaDirectory;
- late String _sharedDocumentsMediaDirectory;
- String? _volatilePassword;
- final _secureStorageOptionsIOS = const IOSOptions(
- accessibility: KeychainAccessibility.first_unlock_this_device,
- );
- // const IOSOptions(accessibility: IOSAccessibility.first_unlock);
- Future<void> init() async {
- _preferences = await SharedPreferences.getInstance();
- _secureStorage = const FlutterSecureStorage();
- _documentsDirectory = (await getApplicationDocumentsDirectory()).path;
- _tempDirectory = _documentsDirectory + "/temp/";
- final tempDirectory = io.Directory(_tempDirectory);
- try {
- final currentTime = DateTime.now().microsecondsSinceEpoch;
- if (tempDirectory.existsSync() &&
- (_preferences.getInt(lastTempFolderClearTimeKey) ?? 0) <
- (currentTime - kTempFolderDeletionTimeBuffer)) {
- await tempDirectory.delete(recursive: true);
- await _preferences.setInt(lastTempFolderClearTimeKey, currentTime);
- _logger.info("Cleared temp folder");
- } else {
- _logger.info("Skipping temp folder clear");
- }
- } catch (e) {
- _logger.warning(e);
- }
- tempDirectory.createSync(recursive: true);
- final tempDirectoryPath = (await getTemporaryDirectory()).path;
- _thumbnailCacheDirectory = tempDirectoryPath + "/thumbnail-cache";
- io.Directory(_thumbnailCacheDirectory).createSync(recursive: true);
- _sharedTempMediaDirectory = tempDirectoryPath + "/ente-shared-media";
- io.Directory(_sharedTempMediaDirectory).createSync(recursive: true);
- _sharedDocumentsMediaDirectory = _documentsDirectory + "/ente-shared-media";
- io.Directory(_sharedDocumentsMediaDirectory).createSync(recursive: true);
- if (!_preferences.containsKey(tokenKey)) {
- await _secureStorage.deleteAll(iOptions: _secureStorageOptionsIOS);
- } else {
- _key = await _secureStorage.read(
- key: keyKey,
- iOptions: _secureStorageOptionsIOS,
- );
- _secretKey = await _secureStorage.read(
- key: secretKeyKey,
- iOptions: _secureStorageOptionsIOS,
- );
- _authSecretKey = await _secureStorage.read(
- key: authSecretKeyKey,
- iOptions: _secureStorageOptionsIOS,
- );
- if (_key == null) {
- await logout(autoLogout: true);
- }
- await _migrateSecurityStorageToFirstUnlock();
- }
- }
- Future<void> logout({bool autoLogout = false}) async {
- await _preferences.clear();
- await _secureStorage.deleteAll(iOptions: _secureStorageOptionsIOS);
- await AuthenticatorDB.instance.clearTable();
- _key = null;
- _cachedToken = null;
- _secretKey = null;
- _authSecretKey = null;
- Bus.instance.fire(SignedOutEvent());
- }
- Future<KeyGenResult> generateKey(String password) async {
- // Create a master key
- final masterKey = CryptoUtil.generateKey();
- // Create a recovery key
- final recoveryKey = CryptoUtil.generateKey();
- // Encrypt master key and recovery key with each other
- final encryptedMasterKey = CryptoUtil.encryptSync(masterKey, recoveryKey);
- final encryptedRecoveryKey = CryptoUtil.encryptSync(recoveryKey, masterKey);
- // Derive a key from the password that will be used to encrypt and
- // decrypt the master key
- final kekSalt = CryptoUtil.getSaltToDeriveKey();
- final derivedKeyResult = await CryptoUtil.deriveSensitiveKey(
- utf8.encode(password) as Uint8List,
- kekSalt,
- );
- final loginKey = await CryptoUtil.deriveLoginKey(derivedKeyResult.key);
- // Encrypt the key with this derived key
- final encryptedKeyData =
- CryptoUtil.encryptSync(masterKey, derivedKeyResult.key);
- // Generate a public-private keypair and encrypt the latter
- final keyPair = await CryptoUtil.generateKeyPair();
- final encryptedSecretKeyData =
- CryptoUtil.encryptSync(keyPair.sk, masterKey);
- final attributes = KeyAttributes(
- Sodium.bin2base64(kekSalt),
- Sodium.bin2base64(encryptedKeyData.encryptedData!),
- Sodium.bin2base64(encryptedKeyData.nonce!),
- Sodium.bin2base64(keyPair.pk),
- Sodium.bin2base64(encryptedSecretKeyData.encryptedData!),
- Sodium.bin2base64(encryptedSecretKeyData.nonce!),
- derivedKeyResult.memLimit,
- derivedKeyResult.opsLimit,
- Sodium.bin2base64(encryptedMasterKey.encryptedData!),
- Sodium.bin2base64(encryptedMasterKey.nonce!),
- Sodium.bin2base64(encryptedRecoveryKey.encryptedData!),
- Sodium.bin2base64(encryptedRecoveryKey.nonce!),
- );
- final privateAttributes = PrivateKeyAttributes(
- Sodium.bin2base64(masterKey),
- Sodium.bin2hex(recoveryKey),
- Sodium.bin2base64(keyPair.sk),
- );
- return KeyGenResult(attributes, privateAttributes, loginKey);
- }
- Future<Tuple2<KeyAttributes, Uint8List>> getAttributesForNewPassword(String password) async {
- // Get master key
- final masterKey = getKey();
- // Derive a key from the password that will be used to encrypt and
- // decrypt the master key
- final kekSalt = CryptoUtil.getSaltToDeriveKey();
- final derivedKeyResult = await CryptoUtil.deriveSensitiveKey(
- utf8.encode(password) as Uint8List,
- kekSalt,
- );
- final loginKey = await CryptoUtil.deriveLoginKey(derivedKeyResult.key);
- // Encrypt the key with this derived key
- final encryptedKeyData =
- CryptoUtil.encryptSync(masterKey!, derivedKeyResult.key);
- final existingAttributes = getKeyAttributes();
- final updatedAttributes = existingAttributes!.copyWith(
- kekSalt: Sodium.bin2base64(kekSalt),
- encryptedKey: Sodium.bin2base64(encryptedKeyData.encryptedData!),
- keyDecryptionNonce: Sodium.bin2base64(encryptedKeyData.nonce!),
- memLimit: derivedKeyResult.memLimit,
- opsLimit: derivedKeyResult.opsLimit,
- );
- return Tuple2(updatedAttributes, loginKey);
- }
- // decryptSecretsAndGetLoginKey decrypts the master key and recovery key
- // with the given password and save them in local secure storage.
- // This method also returns the keyEncKey that can be used for performing
- // SRP setup for existing users.
- Future<Uint8List> decryptSecretsAndGetKeyEncKey(
- String password,
- KeyAttributes attributes,
- {
- Uint8List? keyEncryptionKey,
- }
- ) async {
- _logger.info('Start decryptAndSaveSecrets');
- keyEncryptionKey ??= await CryptoUtil.deriveKey(
- utf8.encode(password) as Uint8List,
- Sodium.base642bin(attributes.kekSalt),
- attributes.memLimit,
- attributes.opsLimit,
- );
- _logger.info('user-key done');
- Uint8List key;
- try {
- key = CryptoUtil.decryptSync(
- Sodium.base642bin(attributes.encryptedKey),
- keyEncryptionKey,
- Sodium.base642bin(attributes.keyDecryptionNonce),
- );
- } catch (e) {
- _logger.severe('master-key failed, incorrect password?', e);
- throw Exception("Incorrect password");
- }
- _logger.info("master-key done");
- await setKey(Sodium.bin2base64(key));
- final secretKey = CryptoUtil.decryptSync(
- Sodium.base642bin(attributes.encryptedSecretKey),
- key,
- Sodium.base642bin(attributes.secretKeyDecryptionNonce),
- );
- _logger.info("secret-key done");
- await setSecretKey(Sodium.bin2base64(secretKey));
- final token = CryptoUtil.openSealSync(
- Sodium.base642bin(getEncryptedToken()!),
- Sodium.base642bin(attributes.publicKey),
- secretKey,
- );
- _logger.info('appToken done');
- await setToken(
- Sodium.bin2base64(token, variant: Sodium.base64VariantUrlsafe),
- );
- return keyEncryptionKey;
- }
- Future<void> recover(String recoveryKey) async {
- // check if user has entered mnemonic code
- if (recoveryKey.contains(' ')) {
- if (recoveryKey.split(' ').length != mnemonicKeyWordCount) {
- throw AssertionError(
- 'recovery code should have $mnemonicKeyWordCount words',
- );
- }
- recoveryKey = bip39.mnemonicToEntropy(recoveryKey);
- }
- final attributes = getKeyAttributes();
- Uint8List masterKey;
- try {
- masterKey = await CryptoUtil.decrypt(
- Sodium.base642bin(attributes!.masterKeyEncryptedWithRecoveryKey),
- Sodium.hex2bin(recoveryKey),
- Sodium.base642bin(attributes.masterKeyDecryptionNonce),
- );
- } catch (e) {
- _logger.severe(e);
- rethrow;
- }
- await setKey(Sodium.bin2base64(masterKey));
- final secretKey = CryptoUtil.decryptSync(
- Sodium.base642bin(attributes.encryptedSecretKey),
- masterKey,
- Sodium.base642bin(attributes.secretKeyDecryptionNonce),
- );
- await setSecretKey(Sodium.bin2base64(secretKey));
- final token = CryptoUtil.openSealSync(
- Sodium.base642bin(getEncryptedToken()!),
- Sodium.base642bin(attributes.publicKey),
- secretKey,
- );
- await setToken(
- Sodium.bin2base64(token, variant: Sodium.base64VariantUrlsafe),
- );
- }
- String getHttpEndpoint() {
- return endpoint;
- }
- String? getToken() {
- _cachedToken ??= _preferences.getString(tokenKey);
- return _cachedToken;
- }
- bool isLoggedIn() {
- return getToken() != null;
- }
- Future<void> setToken(String token) async {
- _cachedToken = token;
- await _preferences.setString(tokenKey, token);
- Bus.instance.fire(SignedInEvent());
- }
- Future<void> setEncryptedToken(String encryptedToken) async {
- await _preferences.setString(encryptedTokenKey, encryptedToken);
- }
- String? getEncryptedToken() {
- return _preferences.getString(encryptedTokenKey);
- }
- String? getEmail() {
- return _preferences.getString(emailKey);
- }
- Future<void> setEmail(String email) async {
- await _preferences.setString(emailKey, email);
- }
- int? getUserID() {
- return _preferences.getInt(userIDKey);
- }
- Future<void> setUserID(int userID) async {
- await _preferences.setInt(userIDKey, userID);
- }
- Future<void> setKeyAttributes(KeyAttributes attributes) async {
- await _preferences.setString(keyAttributesKey, attributes.toJson());
- }
- KeyAttributes? getKeyAttributes() {
- final jsonValue = _preferences.getString(keyAttributesKey);
- if (jsonValue == null) {
- return null;
- } else {
- return KeyAttributes.fromJson(jsonValue);
- }
- }
- Future<void> setKey(String? key) async {
- _key = key;
- if (key == null) {
- await _secureStorage.delete(
- key: keyKey,
- iOptions: _secureStorageOptionsIOS,
- );
- } else {
- await _secureStorage.write(
- key: keyKey,
- value: key,
- iOptions: _secureStorageOptionsIOS,
- );
- }
- }
- Future<void> setSecretKey(String? secretKey) async {
- _secretKey = secretKey;
- if (secretKey == null) {
- await _secureStorage.delete(
- key: secretKeyKey,
- iOptions: _secureStorageOptionsIOS,
- );
- } else {
- await _secureStorage.write(
- key: secretKeyKey,
- value: secretKey,
- iOptions: _secureStorageOptionsIOS,
- );
- }
- }
- Future<void> setAuthSecretKey(String? authSecretKey) async {
- _authSecretKey = authSecretKey;
- if (authSecretKey == null) {
- await _secureStorage.delete(
- key: authSecretKeyKey,
- iOptions: _secureStorageOptionsIOS,
- );
- } else {
- await _secureStorage.write(
- key: authSecretKeyKey,
- value: authSecretKey,
- iOptions: _secureStorageOptionsIOS,
- );
- }
- }
- Uint8List? getKey() {
- return _key == null ? null : Sodium.base642bin(_key!);
- }
- Uint8List? getSecretKey() {
- return _secretKey == null ? null : Sodium.base642bin(_secretKey!);
- }
- Uint8List? getAuthSecretKey() {
- return _authSecretKey == null ? null : Sodium.base642bin(_authSecretKey!);
- }
- Uint8List getRecoveryKey() {
- final keyAttributes = getKeyAttributes()!;
- return CryptoUtil.decryptSync(
- Sodium.base642bin(keyAttributes.recoveryKeyEncryptedWithMasterKey),
- getKey()!,
- Sodium.base642bin(keyAttributes.recoveryKeyDecryptionNonce),
- );
- }
- // Caution: This directory is cleared on app start
- String getTempDirectory() {
- return _tempDirectory;
- }
- String getThumbnailCacheDirectory() {
- return _thumbnailCacheDirectory;
- }
- String getOldSharedMediaCacheDirectory() {
- return _sharedTempMediaDirectory;
- }
- String getSharedMediaDirectory() {
- return _sharedDocumentsMediaDirectory;
- }
- bool hasConfiguredAccount() {
- return getToken() != null && _key != null;
- }
- bool shouldShowLockScreen() {
- if (_preferences.containsKey(keyShouldShowLockScreen)) {
- return _preferences.getBool(keyShouldShowLockScreen)!;
- } else {
- return false;
- }
- }
- Future<void> setShouldShowLockScreen(bool value) {
- return _preferences.setBool(keyShouldShowLockScreen, value);
- }
- void setVolatilePassword(String? volatilePassword) {
- _volatilePassword = volatilePassword;
- }
- String? getVolatilePassword() {
- return _volatilePassword;
- }
- Future<void> _migrateSecurityStorageToFirstUnlock() async {
- final hasMigratedSecureStorageToFirstUnlock =
- _preferences.getBool(hasMigratedSecureStorageKey) ?? false;
- if (!hasMigratedSecureStorageToFirstUnlock &&
- _key != null &&
- _secretKey != null) {
- await _secureStorage.write(
- key: keyKey,
- value: _key,
- iOptions: _secureStorageOptionsIOS,
- );
- await _secureStorage.write(
- key: secretKeyKey,
- value: _secretKey,
- iOptions: _secureStorageOptionsIOS,
- );
- await _preferences.setBool(
- hasMigratedSecureStorageKey,
- true,
- );
- }
- }
- }
|