2014-08-12 10:10:52 -04:00
|
|
|
# -*- coding: utf-8 -*-
|
2014-09-03 12:29:13 -04:00
|
|
|
# Copyright 2014 OpenMarket Ltd
|
2014-08-12 10:10:52 -04:00
|
|
|
#
|
|
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
# you may not use this file except in compliance with the License.
|
|
|
|
# You may obtain a copy of the License at
|
|
|
|
#
|
|
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
#
|
|
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
# See the License for the specific language governing permissions and
|
|
|
|
# limitations under the License.
|
2014-08-12 22:14:34 -04:00
|
|
|
|
2014-08-12 10:10:52 -04:00
|
|
|
"""This module contains REST servlets to do with registration: /register"""
|
|
|
|
from twisted.internet import defer
|
|
|
|
|
2014-09-05 20:58:06 -04:00
|
|
|
from synapse.api.errors import SynapseError, Codes
|
2014-08-12 10:10:52 -04:00
|
|
|
from base import RestServlet, client_path_pattern
|
|
|
|
|
|
|
|
import json
|
|
|
|
import urllib
|
|
|
|
|
|
|
|
|
|
|
|
class RegisterRestServlet(RestServlet):
|
|
|
|
PATTERN = client_path_pattern("/register$")
|
|
|
|
|
|
|
|
@defer.inlineCallbacks
|
|
|
|
def on_POST(self, request):
|
|
|
|
desired_user_id = None
|
|
|
|
password = None
|
|
|
|
try:
|
|
|
|
register_json = json.loads(request.content.read())
|
|
|
|
if "password" in register_json:
|
2014-08-24 06:28:00 -04:00
|
|
|
password = register_json["password"].encode("utf-8")
|
2014-08-12 10:10:52 -04:00
|
|
|
|
|
|
|
if type(register_json["user_id"]) == unicode:
|
2014-08-24 06:28:00 -04:00
|
|
|
desired_user_id = register_json["user_id"].encode("utf-8")
|
2014-08-12 10:10:52 -04:00
|
|
|
if urllib.quote(desired_user_id) != desired_user_id:
|
|
|
|
raise SynapseError(
|
|
|
|
400,
|
|
|
|
"User ID must only contain characters which do not " +
|
|
|
|
"require URL encoding.")
|
|
|
|
except ValueError:
|
|
|
|
defer.returnValue((400, "No JSON object."))
|
|
|
|
except KeyError:
|
|
|
|
pass # user_id is optional
|
|
|
|
|
2014-09-03 13:22:27 -04:00
|
|
|
threepidCreds = None
|
|
|
|
if 'threepidCreds' in register_json:
|
|
|
|
threepidCreds = register_json['threepidCreds']
|
2014-09-05 20:58:06 -04:00
|
|
|
|
2014-09-05 22:18:23 -04:00
|
|
|
captcha = {}
|
2014-09-05 20:58:06 -04:00
|
|
|
if self.hs.config.enable_registration_captcha:
|
2014-09-05 22:18:23 -04:00
|
|
|
challenge = None
|
|
|
|
user_response = None
|
|
|
|
try:
|
|
|
|
captcha_type = register_json["captcha"]["type"]
|
|
|
|
if captcha_type != "m.login.recaptcha":
|
2014-09-06 01:55:29 -04:00
|
|
|
raise SynapseError(400, "Sorry, only m.login.recaptcha " +
|
|
|
|
"requests are supported.")
|
2014-09-05 22:18:23 -04:00
|
|
|
challenge = register_json["captcha"]["challenge"]
|
|
|
|
user_response = register_json["captcha"]["response"]
|
|
|
|
except KeyError:
|
2014-09-06 01:55:29 -04:00
|
|
|
raise SynapseError(400, "Captcha response is required",
|
|
|
|
errcode=Codes.CAPTCHA_NEEDED)
|
2014-09-05 22:18:23 -04:00
|
|
|
|
|
|
|
# TODO determine the source IP : May be an X-Forwarding-For header depending on config
|
|
|
|
ip_addr = request.getClientIP()
|
2014-09-06 01:51:11 -04:00
|
|
|
if self.hs.config.captcha_ip_origin_is_x_forwarded:
|
|
|
|
# use the header
|
|
|
|
if request.requestHeaders.hasHeader("X-Forwarded-For"):
|
|
|
|
ip_addr = request.requestHeaders.getRawHeaders(
|
|
|
|
"X-Forwarded-For")[0]
|
2014-09-05 22:18:23 -04:00
|
|
|
|
|
|
|
captcha = {
|
|
|
|
"ip": ip_addr,
|
|
|
|
"private_key": self.hs.config.recaptcha_private_key,
|
|
|
|
"challenge": challenge,
|
|
|
|
"response": user_response
|
|
|
|
}
|
|
|
|
|
2014-09-03 13:22:27 -04:00
|
|
|
|
2014-08-12 10:10:52 -04:00
|
|
|
handler = self.handlers.registration_handler
|
|
|
|
(user_id, token) = yield handler.register(
|
|
|
|
localpart=desired_user_id,
|
2014-09-03 13:22:27 -04:00
|
|
|
password=password,
|
2014-09-05 22:18:23 -04:00
|
|
|
threepidCreds=threepidCreds,
|
|
|
|
captcha_info=captcha)
|
2014-08-12 10:10:52 -04:00
|
|
|
|
|
|
|
result = {
|
|
|
|
"user_id": user_id,
|
|
|
|
"access_token": token,
|
|
|
|
"home_server": self.hs.hostname,
|
|
|
|
}
|
|
|
|
defer.returnValue(
|
|
|
|
(200, result)
|
|
|
|
)
|
|
|
|
|
|
|
|
def on_OPTIONS(self, request):
|
|
|
|
return (200, {})
|
|
|
|
|
|
|
|
|
|
|
|
def register_servlets(hs, http_server):
|
|
|
|
RegisterRestServlet(hs).register(http_server)
|