2012-07-25 15:51:48 +00:00
|
|
|
<?php
|
|
|
|
/***
|
2012-07-25 14:59:55 +00:00
|
|
|
* ownCloud
|
|
|
|
*
|
|
|
|
* @author Bjoern Schiessle
|
|
|
|
* @copyright 2012 Bjoern Schiessle <schiessle@owncloud.com>
|
|
|
|
*
|
|
|
|
* This library is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU AFFERO GENERAL PUBLIC LICENSE
|
|
|
|
* License as published by the Free Software Foundation; either
|
|
|
|
* version 3 of the License, or any later version.
|
|
|
|
*
|
|
|
|
* This library is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU AFFERO GENERAL PUBLIC LICENSE for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public
|
|
|
|
* License along with this library. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*
|
2012-07-25 15:51:48 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
namespace OCA_Encryption;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* This class provides basic operations to read/write encryption keys from/to the filesystem
|
|
|
|
*/
|
|
|
|
class Keymanager {
|
|
|
|
|
2012-08-01 13:11:41 +00:00
|
|
|
# TODO: make all dependencies (including static classes) explicit, such as ocfsview objects, by adding them as method arguments (dependency injection)
|
2012-08-08 12:20:29 +00:00
|
|
|
|
2012-07-25 15:51:48 +00:00
|
|
|
/**
|
|
|
|
* @brief retrieve private key from a user
|
|
|
|
*
|
|
|
|
* @return string private key or false
|
|
|
|
*/
|
2012-08-03 11:52:41 +00:00
|
|
|
public static function getPrivateKey() {
|
2012-08-10 09:44:38 +00:00
|
|
|
|
2012-08-09 13:45:34 +00:00
|
|
|
$user = \OCP\User::getUser();
|
2012-07-25 17:28:56 +00:00
|
|
|
$view = new \OC_FilesystemView( '/' . $user . '/' . 'files_encryption' );
|
2012-08-10 10:27:09 +00:00
|
|
|
return $view->file_get_contents( '/' . $user.'.private.key' );
|
|
|
|
|
2012-07-25 15:51:48 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2012-08-03 09:49:55 +00:00
|
|
|
* @brief retrieve a list of the public key from all users with access to the file
|
2012-07-25 14:59:55 +00:00
|
|
|
*
|
2012-08-03 09:49:55 +00:00
|
|
|
* @param string path to file
|
|
|
|
* @return array of public keys for the given file
|
2012-07-25 14:59:55 +00:00
|
|
|
*/
|
2012-08-03 09:49:55 +00:00
|
|
|
public static function getPublicKeys($path) {
|
|
|
|
$userId = \OCP\User::getUser();
|
|
|
|
$path = ltrim( $path, '/' );
|
|
|
|
$filepath = '/'.$userId.'/files/'.$path;
|
|
|
|
|
|
|
|
// check if file was shared with other users
|
|
|
|
$query = \OC_DB::prepare( "SELECT uid_owner, source, target, uid_shared_with FROM `*PREFIX*sharing` WHERE ( target = ? AND uid_shared_with = ? ) OR source = ? " );
|
|
|
|
$result = $query->execute( array ($filepath, $userId, $filepath));
|
|
|
|
$users = array();
|
|
|
|
if ($row = $result->fetchRow()){
|
|
|
|
$source = $row['source'];
|
|
|
|
$owner = $row['uid_owner'];
|
|
|
|
$users[] = $owner;
|
|
|
|
// get the uids of all user with access to the file
|
|
|
|
$query = \OC_DB::prepare( "SELECT source, uid_shared_with FROM `*PREFIX*sharing` WHERE source = ?" );
|
|
|
|
$result = $query->execute( array ($source));
|
|
|
|
while ( ($row = $result->fetchRow()) ) {
|
|
|
|
$users[] = $row['uid_shared_with'];
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
// check if it is a file owned by the user and not shared at all
|
|
|
|
$userview = new \OC_FilesystemView( '/'.$userId.'/files/' );
|
|
|
|
if ($userview->file_exists($path)) {
|
|
|
|
$users[] = $userId;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2012-07-26 11:49:22 +00:00
|
|
|
$view = new \OC_FilesystemView( '/public-keys/' );
|
2012-08-03 09:49:55 +00:00
|
|
|
|
|
|
|
$keylist = array();
|
|
|
|
$count = 0;
|
|
|
|
foreach ($users as $user) {
|
|
|
|
$keylist['key'.++$count] = $view->file_get_contents($user.'.public.key');
|
|
|
|
}
|
2012-08-09 13:45:34 +00:00
|
|
|
|
2012-08-03 09:49:55 +00:00
|
|
|
return $keylist;
|
|
|
|
|
2012-07-25 15:51:48 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2012-07-25 14:59:55 +00:00
|
|
|
* @brief retrieve file encryption key
|
|
|
|
*
|
2012-07-25 15:51:48 +00:00
|
|
|
* @param string file name
|
2012-07-25 14:59:55 +00:00
|
|
|
* @return string file key or false
|
|
|
|
*/
|
2012-08-03 11:52:41 +00:00
|
|
|
public static function getFileKey( $path ) {
|
2012-07-30 10:38:38 +00:00
|
|
|
|
2012-07-31 18:28:11 +00:00
|
|
|
$keypath = ltrim( $path, '/' );
|
2012-08-03 11:52:41 +00:00
|
|
|
$user = \OCP\User::getUser();
|
2012-07-30 10:38:38 +00:00
|
|
|
|
|
|
|
// update $keypath and $user if path point to a file shared by someone else
|
|
|
|
$query = \OC_DB::prepare( "SELECT uid_owner, source, target FROM `*PREFIX*sharing` WHERE target = ? AND uid_shared_with = ?" );
|
2012-08-03 11:52:41 +00:00
|
|
|
$result = $query->execute( array ('/'.$user.'/files/'.$keypath, $user));
|
2012-07-30 10:38:38 +00:00
|
|
|
if ($row = $result->fetchRow()){
|
|
|
|
$keypath = $row['source'];
|
|
|
|
$keypath_parts=explode('/',$keypath);
|
|
|
|
$user = $keypath_parts[1];
|
|
|
|
$keypath = str_replace('/'.$user.'/files/', '', $keypath);
|
|
|
|
}
|
|
|
|
|
2012-07-26 11:49:22 +00:00
|
|
|
$view = new \OC_FilesystemView('/'.$user.'/files_encryption/keyfiles/');
|
2012-08-10 10:27:09 +00:00
|
|
|
return $view->file_get_contents($keypath.'.key');
|
|
|
|
|
2012-07-25 15:51:48 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2012-08-03 11:52:41 +00:00
|
|
|
* @brief store private key from the user
|
2012-07-25 14:59:55 +00:00
|
|
|
*
|
|
|
|
* @param string key
|
|
|
|
* @return bool true/false
|
2012-07-25 15:51:48 +00:00
|
|
|
*/
|
2012-08-03 11:52:41 +00:00
|
|
|
public static function setPrivateKey($key) {
|
2012-07-26 15:19:55 +00:00
|
|
|
|
2012-08-03 11:52:41 +00:00
|
|
|
$user = \OCP\User::getUser();
|
2012-07-26 15:19:55 +00:00
|
|
|
$view = new \OC_FilesystemView('/'.$user.'/files_encryption');
|
|
|
|
if (!$view->file_exists('')) $view->mkdir('');
|
2012-08-10 10:27:09 +00:00
|
|
|
return $view->file_put_contents($user.'.private.key', $key);
|
2012-07-26 15:19:55 +00:00
|
|
|
|
2012-07-25 15:51:48 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
2012-08-03 11:52:41 +00:00
|
|
|
* @brief store public key of the user
|
2012-07-25 14:59:55 +00:00
|
|
|
*
|
|
|
|
* @param string key
|
|
|
|
* @return bool true/false
|
2012-07-25 15:51:48 +00:00
|
|
|
*/
|
2012-08-03 11:52:41 +00:00
|
|
|
public static function setPublicKey($key) {
|
2012-07-26 15:19:55 +00:00
|
|
|
|
|
|
|
$view = new \OC_FilesystemView('/public-keys');
|
|
|
|
if (!$view->file_exists('')) $view->mkdir('');
|
2012-08-10 10:27:09 +00:00
|
|
|
return $view->file_put_contents(\OCP\User::getUser().'.public.key', $key);
|
2012-07-26 15:19:55 +00:00
|
|
|
|
2012-07-25 14:59:55 +00:00
|
|
|
}
|
2012-07-25 15:51:48 +00:00
|
|
|
|
|
|
|
/**
|
2012-07-25 14:59:55 +00:00
|
|
|
* @brief store file encryption key
|
2012-07-25 15:51:48 +00:00
|
|
|
*
|
2012-07-25 17:28:56 +00:00
|
|
|
* @param string $path relative path of the file, including filename
|
|
|
|
* @param string $key
|
2012-07-25 14:59:55 +00:00
|
|
|
* @return bool true/false
|
2012-07-31 18:28:11 +00:00
|
|
|
*/
|
2012-08-10 09:44:38 +00:00
|
|
|
public static function setFileKey( $path, $key, $view = Null, $dbClassName = '\OC_DB') {
|
2012-07-30 10:38:38 +00:00
|
|
|
|
2012-07-31 18:28:11 +00:00
|
|
|
$targetpath = ltrim( $path, '/' );
|
2012-08-03 11:52:41 +00:00
|
|
|
$user = \OCP\User::getUser();
|
2012-07-30 10:38:38 +00:00
|
|
|
|
|
|
|
// update $keytarget and $user if key belongs to a file shared by someone else
|
2012-08-01 13:11:41 +00:00
|
|
|
$query = $dbClassName::prepare( "SELECT uid_owner, source, target FROM `*PREFIX*sharing` WHERE target = ? AND uid_shared_with = ?" );
|
2012-07-31 18:28:11 +00:00
|
|
|
|
2012-08-01 13:11:41 +00:00
|
|
|
$result = $query->execute( array ( '/'.$user.'/files/'.$targetpath, $user ) );
|
2012-07-31 18:28:11 +00:00
|
|
|
|
|
|
|
if ( $row = $result->fetchRow( ) ) {
|
2012-08-01 13:11:41 +00:00
|
|
|
|
2012-07-30 10:38:38 +00:00
|
|
|
$targetpath = $row['source'];
|
2012-08-01 13:11:41 +00:00
|
|
|
|
2012-07-31 18:28:11 +00:00
|
|
|
$targetpath_parts=explode( '/',$targetpath );
|
2012-08-01 13:11:41 +00:00
|
|
|
|
2012-07-30 10:38:38 +00:00
|
|
|
$user = $targetpath_parts[1];
|
2012-08-13 09:31:15 +00:00
|
|
|
|
|
|
|
$rootview = new \OC_FilesystemView( '/');
|
|
|
|
if (!$rootview->is_writable($targetpath)) {
|
|
|
|
\OC_Log::write( 'Encryption library', "File Key not updated because you don't have write access for the corresponding file" , \OC_Log::ERROR );
|
|
|
|
return false;
|
|
|
|
}
|
2012-08-01 13:11:41 +00:00
|
|
|
|
2012-07-31 18:28:11 +00:00
|
|
|
$targetpath = str_replace( '/'.$user.'/files/', '', $targetpath );
|
2012-08-01 13:11:41 +00:00
|
|
|
|
2012-07-30 10:43:17 +00:00
|
|
|
//TODO: check for write permission on shared file once the new sharing API is in place
|
2012-08-01 13:11:41 +00:00
|
|
|
|
2012-07-30 10:38:38 +00:00
|
|
|
}
|
|
|
|
|
2012-07-31 18:28:11 +00:00
|
|
|
$path_parts = pathinfo( $targetpath );
|
2012-08-08 12:15:35 +00:00
|
|
|
|
|
|
|
if (!$view) {
|
|
|
|
$view = new \OC_FilesystemView( '/' . $user . '/files_encryption/keyfiles' );
|
|
|
|
}
|
2012-07-31 18:28:11 +00:00
|
|
|
|
|
|
|
if ( !$view->file_exists( $path_parts['dirname'] ) ) $view->mkdir( $path_parts['dirname'] );
|
|
|
|
|
2012-08-10 10:27:09 +00:00
|
|
|
return $view->file_put_contents( '/' . $targetpath . '.key', $key );
|
2012-07-25 17:28:56 +00:00
|
|
|
|
2012-07-25 15:51:48 +00:00
|
|
|
}
|
|
|
|
|
2012-08-09 12:25:09 +00:00
|
|
|
/**
|
|
|
|
* @brief change password of private encryption key
|
|
|
|
*
|
|
|
|
* @param string $oldpasswd old password
|
|
|
|
* @param string $newpasswd new password
|
|
|
|
* @return bool true/false
|
|
|
|
*/
|
2012-08-09 10:19:51 +00:00
|
|
|
public static function changePasswd($oldpasswd, $newpasswd) {
|
2012-08-10 10:27:09 +00:00
|
|
|
|
2012-08-09 11:47:27 +00:00
|
|
|
if ( \OCP\User::checkPassword(\OCP\User::getUser(), $newpasswd) ) {
|
2012-08-09 13:45:34 +00:00
|
|
|
$key = Keymanager::getPrivateKey();
|
|
|
|
if ( ($key = Crypt::symmetricDecryptFileContent($key,$oldpasswd)) ) {
|
|
|
|
if ( ($key = Crypt::symmetricEncryptFileContent($key, $newpasswd)) ) {
|
|
|
|
Keymanager::setPrivateKey($key);
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
}
|
2012-08-09 11:47:27 +00:00
|
|
|
}
|
2012-08-09 13:45:34 +00:00
|
|
|
return false;
|
2012-08-10 10:27:09 +00:00
|
|
|
|
2012-08-09 10:19:51 +00:00
|
|
|
}
|
|
|
|
|
2012-07-25 14:59:55 +00:00
|
|
|
}
|