Commit f4e97894 by Michael Brachmann

fix

parent a2573e3e
......@@ -188,7 +188,7 @@ var
cdJsonBytes, attObjBytes, credIdBytes: TBytes;
cdJsonText: string;
cdJson: TJSONObject;
typeVal, challengeVal: string;
typeVal, challengeVal, originVal, effectiveRpId: string;
authData: TBytes;
rpIdHash, credId, pubKeyX, pubKeyY: TBytes;
flags: Byte;
......@@ -229,7 +229,6 @@ begin
Exit;
end;
var originVal: string;
try
typeVal := cdJson.GetValue<string>('type', '');
challengeVal := cdJson.GetValue<string>('challenge', '');
......@@ -255,10 +254,10 @@ begin
// Derive effectiveRpId from the origin the browser reported.
// Falls back to ServerConfig.rpId only if origin is absent.
var effectiveRpId := ExtractOriginHostname(originVal);
effectiveRpId := ExtractOriginHostname(originVal);
if effectiveRpId = '' then
effectiveRpId := ServerConfig.rpId;
Logger.Log(3, 'CompleteRegistration - effectiveRpId: "' + effectiveRpId + '" (origin: "' + originVal + '")');
Logger.Log(2, 'CompleteRegistration - effectiveRpId: "' + effectiveRpId + '" origin: "' + originVal + '"');
// 3. Decode attestationObject and extract authData
......@@ -443,7 +442,7 @@ var
cdJsonBytes, authDataBytes, sigBytes: TBytes;
cdJsonText: string;
cdJson: TJSONObject;
typeVal, challengeVal: string;
typeVal, challengeVal, loginOriginVal, loginEffectiveRpId: string;
rpIdHash, expectedRpIdHash: TBytes;
flags: Byte;
signCount: Cardinal;
......@@ -494,11 +493,10 @@ begin
if not Assigned(cdJson) then
raise EXDataHttpUnauthorized.Create('clientDataJSON is not valid JSON.');
var loginOriginVal: string;
try
typeVal := cdJson.GetValue<string>('type', '');
challengeVal := cdJson.GetValue<string>('challenge', '');
loginOriginVal := cdJson.GetValue<string>('origin', '');
typeVal := cdJson.GetValue<string>('type', '');
challengeVal := cdJson.GetValue<string>('challenge', '');
loginOriginVal := cdJson.GetValue<string>('origin', '');
finally
cdJson.Free;
end;
......@@ -509,10 +507,10 @@ begin
if challengeVal <> challengeB64 then
raise EXDataHttpUnauthorized.Create('Challenge mismatch.');
var loginEffectiveRpId := ExtractOriginHostname(loginOriginVal);
loginEffectiveRpId := ExtractOriginHostname(loginOriginVal);
if loginEffectiveRpId = '' then
loginEffectiveRpId := ServerConfig.rpId;
Logger.Log(3, Format('AuthService.Login - effectiveRpId: "%s"', [loginEffectiveRpId]));
Logger.Log(2, Format('AuthService.Login - effectiveRpId: "%s" origin: "%s"', [loginEffectiveRpId, loginOriginVal]));
// 4. Load credential from DB
q := TUniQuery.Create(nil);
......@@ -550,13 +548,13 @@ begin
if Length(authDataBytes) < 37 then
raise EXDataHttpUnauthorized.Create('authenticatorData too short.');
// Verify rpIdHash (first 32 bytes of authData) against effective rpId from origin
// Verify rpIdHash (first 32 bytes of authData) against effective rpId from clientDataJSON origin
SetLength(rpIdHash, 32);
Move(authDataBytes[0], rpIdHash[0], 32);
expectedRpIdHash := SHA256Bytes(TEncoding.UTF8.GetBytes(loginEffectiveRpId));
if not CompareMem(@rpIdHash[0], @expectedRpIdHash[0], 32) then
raise EXDataHttpUnauthorized.Create(
Format('rpId mismatch (server derived "%s" from origin "%s").', [loginEffectiveRpId, loginOriginVal]));
Format('rpId mismatch — server used "%s" (from origin "%s")', [loginEffectiveRpId, loginOriginVal]));
// Check user-present flag
flags := authDataBytes[32];
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment