Commit f4e97894 by Michael Brachmann

fix

parent a2573e3e
...@@ -188,7 +188,7 @@ var ...@@ -188,7 +188,7 @@ var
cdJsonBytes, attObjBytes, credIdBytes: TBytes; cdJsonBytes, attObjBytes, credIdBytes: TBytes;
cdJsonText: string; cdJsonText: string;
cdJson: TJSONObject; cdJson: TJSONObject;
typeVal, challengeVal: string; typeVal, challengeVal, originVal, effectiveRpId: string;
authData: TBytes; authData: TBytes;
rpIdHash, credId, pubKeyX, pubKeyY: TBytes; rpIdHash, credId, pubKeyX, pubKeyY: TBytes;
flags: Byte; flags: Byte;
...@@ -229,7 +229,6 @@ begin ...@@ -229,7 +229,6 @@ begin
Exit; Exit;
end; end;
var originVal: string;
try try
typeVal := cdJson.GetValue<string>('type', ''); typeVal := cdJson.GetValue<string>('type', '');
challengeVal := cdJson.GetValue<string>('challenge', ''); challengeVal := cdJson.GetValue<string>('challenge', '');
...@@ -255,10 +254,10 @@ begin ...@@ -255,10 +254,10 @@ begin
// Derive effectiveRpId from the origin the browser reported. // Derive effectiveRpId from the origin the browser reported.
// Falls back to ServerConfig.rpId only if origin is absent. // Falls back to ServerConfig.rpId only if origin is absent.
var effectiveRpId := ExtractOriginHostname(originVal); effectiveRpId := ExtractOriginHostname(originVal);
if effectiveRpId = '' then if effectiveRpId = '' then
effectiveRpId := ServerConfig.rpId; effectiveRpId := ServerConfig.rpId;
Logger.Log(3, 'CompleteRegistration - effectiveRpId: "' + effectiveRpId + '" (origin: "' + originVal + '")'); Logger.Log(2, 'CompleteRegistration - effectiveRpId: "' + effectiveRpId + '" origin: "' + originVal + '"');
// 3. Decode attestationObject and extract authData // 3. Decode attestationObject and extract authData
...@@ -443,7 +442,7 @@ var ...@@ -443,7 +442,7 @@ var
cdJsonBytes, authDataBytes, sigBytes: TBytes; cdJsonBytes, authDataBytes, sigBytes: TBytes;
cdJsonText: string; cdJsonText: string;
cdJson: TJSONObject; cdJson: TJSONObject;
typeVal, challengeVal: string; typeVal, challengeVal, loginOriginVal, loginEffectiveRpId: string;
rpIdHash, expectedRpIdHash: TBytes; rpIdHash, expectedRpIdHash: TBytes;
flags: Byte; flags: Byte;
signCount: Cardinal; signCount: Cardinal;
...@@ -494,7 +493,6 @@ begin ...@@ -494,7 +493,6 @@ begin
if not Assigned(cdJson) then if not Assigned(cdJson) then
raise EXDataHttpUnauthorized.Create('clientDataJSON is not valid JSON.'); raise EXDataHttpUnauthorized.Create('clientDataJSON is not valid JSON.');
var loginOriginVal: string;
try try
typeVal := cdJson.GetValue<string>('type', ''); typeVal := cdJson.GetValue<string>('type', '');
challengeVal := cdJson.GetValue<string>('challenge', ''); challengeVal := cdJson.GetValue<string>('challenge', '');
...@@ -509,10 +507,10 @@ begin ...@@ -509,10 +507,10 @@ begin
if challengeVal <> challengeB64 then if challengeVal <> challengeB64 then
raise EXDataHttpUnauthorized.Create('Challenge mismatch.'); raise EXDataHttpUnauthorized.Create('Challenge mismatch.');
var loginEffectiveRpId := ExtractOriginHostname(loginOriginVal); loginEffectiveRpId := ExtractOriginHostname(loginOriginVal);
if loginEffectiveRpId = '' then if loginEffectiveRpId = '' then
loginEffectiveRpId := ServerConfig.rpId; loginEffectiveRpId := ServerConfig.rpId;
Logger.Log(3, Format('AuthService.Login - effectiveRpId: "%s"', [loginEffectiveRpId])); Logger.Log(2, Format('AuthService.Login - effectiveRpId: "%s" origin: "%s"', [loginEffectiveRpId, loginOriginVal]));
// 4. Load credential from DB // 4. Load credential from DB
q := TUniQuery.Create(nil); q := TUniQuery.Create(nil);
...@@ -550,13 +548,13 @@ begin ...@@ -550,13 +548,13 @@ begin
if Length(authDataBytes) < 37 then if Length(authDataBytes) < 37 then
raise EXDataHttpUnauthorized.Create('authenticatorData too short.'); raise EXDataHttpUnauthorized.Create('authenticatorData too short.');
// Verify rpIdHash (first 32 bytes of authData) against effective rpId from origin // Verify rpIdHash (first 32 bytes of authData) against effective rpId from clientDataJSON origin
SetLength(rpIdHash, 32); SetLength(rpIdHash, 32);
Move(authDataBytes[0], rpIdHash[0], 32); Move(authDataBytes[0], rpIdHash[0], 32);
expectedRpIdHash := SHA256Bytes(TEncoding.UTF8.GetBytes(loginEffectiveRpId)); expectedRpIdHash := SHA256Bytes(TEncoding.UTF8.GetBytes(loginEffectiveRpId));
if not CompareMem(@rpIdHash[0], @expectedRpIdHash[0], 32) then if not CompareMem(@rpIdHash[0], @expectedRpIdHash[0], 32) then
raise EXDataHttpUnauthorized.Create( raise EXDataHttpUnauthorized.Create(
Format('rpId mismatch (server derived "%s" from origin "%s").', [loginEffectiveRpId, loginOriginVal])); Format('rpId mismatch — server used "%s" (from origin "%s")', [loginEffectiveRpId, loginOriginVal]));
// Check user-present flag // Check user-present flag
flags := authDataBytes[32]; flags := authDataBytes[32];
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment