2014-10-19 23:30:44 -06:00
/* jslint node: true */
'use strict';
2014-10-23 22:18:38 -06:00
var userDb = require('./database.js').dbs.user;
2015-04-15 22:46:45 -06:00
var Config = require('./config.js').config;
2015-05-11 16:39:28 -06:00
var userGroup = require('./user_group.js');
2015-04-15 22:46:45 -06:00
2014-10-19 23:30:44 -06:00
var crypto = require('crypto');
2014-10-20 22:47:13 -06:00
var assert = require('assert');
2014-10-25 21:35:42 -06:00
var async = require('async');
2015-04-09 22:49:56 -06:00
var _ = require('lodash');
2015-07-22 16:37:11 -06:00
var moment = require('moment');
2014-10-19 23:30:44 -06:00
2014-10-23 22:18:38 -06:00
exports.User = User;
2015-04-06 00:18:08 -06:00
exports.getUserIdAndName = getUserIdAndName;
2015-08-02 18:27:05 -06:00
exports.getUserName = getUserName;
exports.loadProperties = loadProperties;
2015-11-27 22:26:00 -07:00
exports.getUserIdsWithProperty = getUserIdsWithProperty;
2015-10-18 11:48:08 -06:00
exports.getUserList = getUserList;
2014-10-20 22:47:13 -06:00
2016-08-29 21:03:48 -06:00
exports.isRootUserId = function(id) { return 1 === id; };
2014-10-19 23:30:44 -06:00
function User() {
var self = this;
2015-04-06 00:18:08 -06:00
this.userId = 0;
this.username = '';
2015-05-12 16:34:11 -06:00
this.properties = {}; // name:value
2015-08-20 22:29:16 -06:00
this.groups = []; // group membership(s)
2014-10-20 22:47:13 -06:00
2016-01-30 15:26:19 -07:00
this.isAuthenticated = function() {
return true === self.authenticated;
2016-08-29 21:03:48 -06:00
2016-01-30 15:26:19 -07:00
2014-10-23 22:18:38 -06:00
this.isValid = function() {
2015-05-12 23:04:22 -06:00
if(self.userId <= 0 || self.username.length < Config.users.usernameMin) {
2014-10-23 22:18:38 -06:00
return false;
2014-10-20 22:47:13 -06:00
2014-10-23 22:18:38 -06:00
return this.hasValidPassword();
2014-10-20 22:47:13 -06:00
2014-10-23 22:18:38 -06:00
this.hasValidPassword = function() {
if(!this.properties || !this.properties.pw_pbkdf2_salt || !this.properties.pw_pbkdf2_dk) {
return false;
2014-10-20 22:47:13 -06:00
2014-10-19 23:30:44 -06:00
2014-10-23 22:18:38 -06:00
return this.properties.pw_pbkdf2_salt.length === User.PBKDF2.saltLen * 2 &&
this.prop_name.pw_pbkdf2_dk.length === User.PBKDF2.keyLen * 2;
2014-10-19 23:30:44 -06:00
2014-10-23 22:18:38 -06:00
this.isRoot = function() {
2015-04-06 00:18:08 -06:00
return 1 === this.userId;
2014-10-23 22:18:38 -06:00
2014-10-20 22:47:13 -06:00
2014-10-23 22:18:38 -06:00
this.isSysOp = this.isRoot; // alias
2015-04-06 00:18:08 -06:00
2015-11-04 23:04:55 -07:00
this.isGroupMember = function(groupNames) {
if(_.isString(groupNames)) {
groupNames = [ groupNames ];
2016-08-31 22:06:49 -06:00
const isMember = groupNames.some(gn => (-1 !== self.groups.indexOf(gn)));
2016-01-30 15:26:19 -07:00
return isMember;
2015-06-29 23:14:17 -06:00
2015-05-12 16:34:11 -06:00
2015-08-03 23:11:17 -06:00
this.getLegacySecurityLevel = function() {
2015-08-04 22:35:59 -06:00
if(self.isRoot() || self.isGroupMember('sysops')) {
return 100;
2016-08-31 22:06:49 -06:00
if(self.isGroupMember('users')) {
2015-08-04 22:35:59 -06:00
return 30;
2016-08-31 22:06:49 -06:00
return 10; // :TODO: Is this what we want?
2015-08-03 23:11:17 -06:00
2014-10-23 22:18:38 -06:00
2014-10-19 23:30:44 -06:00
2014-10-23 22:18:38 -06:00
User.PBKDF2 = {
iterations : 1000,
keyLen : 128,
saltLen : 32,
2014-10-20 22:47:13 -06:00
2014-10-25 21:35:42 -06:00
User.StandardPropertyGroups = {
password : [ 'pw_pbkdf2_salt', 'pw_pbkdf2_dk' ],
2015-04-15 22:46:45 -06:00
User.AccountStatus = {
2015-11-14 12:22:21 -07:00
disabled : 0,
inactive : 1,
active : 2,
2015-04-15 22:46:45 -06:00
2015-08-02 18:27:05 -06:00
User.prototype.load = function(userId, cb) {
2015-04-06 00:18:08 -06:00
User.prototype.authenticate = function(username, password, cb) {
2016-08-29 21:03:48 -06:00
const self = this;
2015-04-06 00:18:08 -06:00
2016-08-29 21:03:48 -06:00
const cachedInfo = {};
2015-04-06 00:18:08 -06:00
function fetchUserId(callback) {
// get user ID
getUserIdAndName(username, function onUserId(err, uid, un) {
cachedInfo.userId = uid;
cachedInfo.username = un;
function getRequiredAuthProperties(callback) {
// fetch properties required for authentication
loadProperties( { userId : cachedInfo.userId, names : User.StandardPropertyGroups.password }, function onProps(err, props) {
callback(err, props);
function getDkWithSalt(props, callback) {
// get DK from stored salt and password provided
generatePasswordDerivedKey(password, props.pw_pbkdf2_salt, function onDk(err, dk) {
callback(err, dk, props.pw_pbkdf2_dk);
function validateAuth(passDk, propsDk, callback) {
// Use constant time comparison here for security feel-goods
var passDkBuf = new Buffer(passDk, 'hex');
var propsDkBuf = new Buffer(propsDk, 'hex');
if(passDkBuf.length !== propsDkBuf.length) {
callback(new Error('Invalid password'));
var c = 0;
for(var i = 0; i < passDkBuf.length; i++) {
c |= passDkBuf[i] ^ propsDkBuf[i];
callback(0 === c ? null : new Error('Invalid password'));
function initProps(callback) {
2015-05-12 16:34:11 -06:00
loadProperties( { userId : cachedInfo.userId }, function onProps(err, allProps) {
2015-04-06 00:18:08 -06:00
if(!err) {
cachedInfo.properties = allProps;
2015-05-11 16:39:28 -06:00
function initGroups(callback) {
userGroup.getGroupsForUser(cachedInfo.userId, function groupsLoaded(err, groups) {
if(!err) {
cachedInfo.groups = groups;
2015-04-06 00:18:08 -06:00
function complete(err) {
if(!err) {
2015-04-09 22:49:56 -06:00
self.userId = cachedInfo.userId;
self.username = cachedInfo.username;
self.properties = cachedInfo.properties;
2015-05-11 16:39:28 -06:00
self.groups = cachedInfo.groups;
2015-04-09 22:49:56 -06:00
self.authenticated = true;
2015-04-06 00:18:08 -06:00
2016-08-29 21:03:48 -06:00
return cb(err);
2015-04-06 00:18:08 -06:00
2015-04-09 22:49:56 -06:00
User.prototype.create = function(options, cb) {
assert(0 === this.userId);
assert(this.username.length > 0); // :TODO: Min username length? Max?
var self = this;
2015-04-15 22:46:45 -06:00
// :TODO: set various defaults, e.g. default activation status, etc.
self.properties.account_status = Config.users.requireActivation ? User.AccountStatus.inactive : User.AccountStatus.active;
2015-04-09 22:49:56 -06:00
function beginTransaction(callback) {
userDb.run('BEGIN;', function transBegin(err) {
function createUserRec(callback) {
'INSERT INTO user (user_name) ' +
'VALUES (?);',
[ self.username ],
function userInsert(err) {
if(err) {
} else {
self.userId = this.lastID;
2015-04-15 22:46:45 -06:00
2015-05-12 16:34:11 -06:00
// Do not require activation for userId 1 (root/admin)
2015-04-15 22:46:45 -06:00
if(1 === self.userId) {
self.properties.account_status = User.AccountStatus.active;
2015-08-20 22:51:00 -06:00
2015-04-09 22:49:56 -06:00
function genAuthCredentials(callback) {
2015-04-14 22:27:07 -06:00
generatePasswordDerivedKeyAndSalt(options.password, function dkAndSalt(err, info) {
2015-04-09 22:49:56 -06:00
if(err) {
} else {
self.properties.pw_pbkdf2_salt = info.salt;
self.properties.pw_pbkdf2_dk = info.dk;
2015-05-11 16:39:28 -06:00
function setInitialGroupMembership(callback) {
2015-08-20 22:29:16 -06:00
self.groups = Config.users.defaultGroups;
if(1 === self.userId) { // root/SysOp?
2015-05-12 16:34:11 -06:00
2015-08-20 22:29:16 -06:00
2015-05-12 16:34:11 -06:00
2015-04-09 22:49:56 -06:00
function saveAll(callback) {
2015-04-14 22:27:07 -06:00
self.persist(false, function persisted(err) {
2015-04-09 22:49:56 -06:00
function complete(err) {
if(err) {
var originalError = err;
userDb.run('ROLLBACK;', function rollback(err) {
} else {
userDb.run('COMMIT;', function commited(err) {
User.prototype.persist = function(useTransaction, cb) {
assert(this.userId > 0);
2015-04-14 22:27:07 -06:00
var self = this;
2015-04-09 22:49:56 -06:00
function beginTransaction(callback) {
if(useTransaction) {
userDb.run('BEGIN;', function transBegin(err) {
} else {
function saveProps(callback) {
2015-08-16 21:47:33 -06:00
self.persistAllProperties(function persisted(err) {
2015-04-09 22:49:56 -06:00
2015-05-11 16:39:28 -06:00
function saveGroups(callback) {
userGroup.addUserToGroups(self.userId, self.groups, function groupsSaved(err) {
2015-04-09 22:49:56 -06:00
function complete(err) {
if(err) {
if(useTransaction) {
userDb.run('ROLLBACK;', function rollback(err) {
} else {
} else {
if(useTransaction) {
userDb.run('COMMIT;', function commited(err) {
} else {
2015-07-26 00:20:07 -06:00
User.prototype.persistProperty = function(propName, propValue, cb) {
// update live props
this.properties[propName] = propValue;
'REPLACE INTO user_property (user_id, prop_name, prop_value) ' +
2015-08-17 21:45:11 -06:00
'VALUES (?, ?, ?);',
[ this.userId, propName, propValue ],
function ran(err) {
if(cb) {
2015-07-26 00:20:07 -06:00
2015-08-19 16:05:35 -06:00
2015-07-26 00:20:07 -06:00
2015-08-16 21:47:33 -06:00
User.prototype.persistProperties = function(properties, cb) {
var self = this;
2015-08-20 16:35:04 -06:00
// update live props
_.merge(this.properties, properties);
2015-08-16 21:47:33 -06:00
var stmt = userDb.prepare(
'REPLACE INTO user_property (user_id, prop_name, prop_value) ' +
'VALUES (?, ?, ?);');
async.each(Object.keys(properties), function property(propName, callback) {
stmt.run(self.userId, propName, properties[propName], function onRun(err) {
}, function complete(err) {
if(err) {
} else {
stmt.finalize(function finalized() {
User.prototype.persistAllProperties = function(cb) {
2015-04-14 22:27:07 -06:00
assert(this.userId > 0);
2015-08-16 21:47:33 -06:00
this.persistProperties(this.properties, cb);
2015-04-14 22:27:07 -06:00
2015-12-24 11:54:55 -07:00
User.prototype.setNewAuthCredentials = function(password, cb) {
var self = this;
generatePasswordDerivedKeyAndSalt(password, function dkAndSalt(err, info) {
if(err) {
} else {
var newProperties = {
pw_pbkdf2_salt : info.salt,
pw_pbkdf2_dk : info.dk,
self.persistProperties(newProperties, function persisted(err) {
2015-07-21 23:52:20 -06:00
User.prototype.getAge = function() {
2015-07-22 16:37:11 -06:00
if(_.has(this.properties, 'birthdate')) {
return moment().diff(this.properties.birthdate, 'years');
2015-07-21 23:52:20 -06:00
2015-05-12 16:34:11 -06:00
// Exported methods
function getUserIdAndName(username, cb) {
'SELECT id, user_name ' +
'FROM user ' +
'WHERE user_name LIKE ?;',
[ username ],
function onResults(err, row) {
2014-10-20 22:47:13 -06:00
if(err) {
2015-05-12 16:34:11 -06:00
2014-10-20 22:47:13 -06:00
} else {
2015-05-12 16:34:11 -06:00
if(row) {
cb(null, row.id, row.user_name);
} else {
cb(new Error('No matching username'));
2014-10-20 22:47:13 -06:00
2015-08-02 18:27:05 -06:00
function getUserName(userId, cb) {
'SELECT user_name ' +
'FROM user ' +
'WHERE id=?;', [ userId ],
function got(err, row) {
if(err) {
} else {
if(row) {
cb(null, row.user_name);
} else {
cb(new Error('No matching user ID'));
2015-05-12 16:34:11 -06:00
// Internal utility methods
2014-10-25 21:35:42 -06:00
function generatePasswordDerivedKeyAndSalt(password, cb) {
function getSalt(callback) {
generatePasswordDerivedKeySalt(function onSalt(err, salt) {
callback(err, salt);
function getDk(salt, callback) {
generatePasswordDerivedKey(password, salt, function onDk(err, dk) {
callback(err, salt, dk);
function onComplete(err, salt, dk) {
cb(err, { salt : salt, dk : dk });
function generatePasswordDerivedKeySalt(cb) {
crypto.randomBytes(User.PBKDF2.saltLen, function onRandSalt(err, salt) {
2014-10-20 22:47:13 -06:00
if(err) {
2014-10-25 21:35:42 -06:00
} else {
cb(null, salt.toString('hex'));
2014-10-20 22:47:13 -06:00
2014-10-25 21:35:42 -06:00
2014-10-20 22:47:13 -06:00
2014-10-25 21:35:42 -06:00
function generatePasswordDerivedKey(password, salt, cb) {
password = new Buffer(password).toString('hex');
crypto.pbkdf2(password, salt, User.PBKDF2.iterations, User.PBKDF2.keyLen, function onDerivedKey(err, dk) {
if(err) {
} else {
cb(null, dk.toString('hex'));
2014-10-19 23:30:44 -06:00
2014-10-23 22:18:38 -06:00
2014-10-19 23:30:44 -06:00
2015-04-06 00:18:08 -06:00
function loadProperties(options, cb) {
var sql =
'SELECT prop_name, prop_value ' +
'FROM user_property ' +
'WHERE user_id = ?';
if(options.names) {
sql +=' AND prop_name IN("' + options.names.join('","') + '");';
} else {
sql += ';';
var properties = {};
userDb.each(sql, [ options.userId ], function onRow(err, row) {
if(err) {
} else {
properties[row.prop_name] = row.prop_value;
}, function complete() {
cb(null, properties);
2015-10-18 11:48:08 -06:00
2015-11-27 22:26:00 -07:00
// :TODO: make this much more flexible - propValue should allow for case-insensitive compare, etc.
function getUserIdsWithProperty(propName, propValue, cb) {
var userIds = [];
'SELECT user_id ' +
'FROM user_property ' +
'WHERE prop_name = ? AND prop_value = ?;',
[ propName, propValue ],
function rowEntry(err, row) {
if(!err) {
function complete() {
cb(null, userIds);
2015-10-18 11:48:08 -06:00
function getUserList(options, cb) {
var userList = [];
var orderClause = 'ORDER BY ' + (options.order || 'user_name');
'SELECT id, user_name ' +
'FROM user ' +
orderClause + ';',
function userRow(err, row) {
userId : row.id,
userName : row.user_name,
function usersComplete(err) {
options.properties = options.properties || [];
async.map(userList, function iter(user, callback) {
'SELECT prop_name, prop_value ' +
'FROM user_property ' +
'WHERE user_id=? AND prop_name IN ("' + options.properties.join('","') + '");',
[ user.userId ],
function propRow(err, row) {
user[row.prop_name] = row.prop_value;
function complete(err) {
callback(err, user);
}, function propsComplete(err, transformed) {
cb(err, transformed);