Generate smaller device IDs

This commit is contained in:
Erik Johnston 2017-10-06 13:47:40 +01:00
parent 3335918e0e
commit fd9947b87d
5 changed files with 41 additions and 20 deletions

View file

@ -40,6 +40,9 @@ var UnknownDeviceID = "unknown-device"
// 32 bytes => 256 bits
var tokenByteLength = 32
// The length of generated device IDs
var deviceIDByteLength = 8
// DeviceDatabase represents a device database.
type DeviceDatabase interface {
// Look up the device matching the given access token.
@ -89,7 +92,7 @@ func GenerateAccessToken() (string, error) {
// GenerateDeviceID creates a new device id. Returns an error if failed to generate
// random bytes.
func GenerateDeviceID() (string, error) {
b := make([]byte, tokenByteLength)
b := make([]byte, deviceIDByteLength)
_, err := rand.Read(b)
if err != nil {
return "", err

View file

@ -18,6 +18,7 @@ import (
"context"
"database/sql"
"github.com/matrix-org/dendrite/clientapi/auth"
"github.com/matrix-org/dendrite/clientapi/auth/authtypes"
"github.com/matrix-org/dendrite/common"
"github.com/matrix-org/gomatrixserverlib"
@ -55,20 +56,42 @@ func (d *Database) GetDeviceByAccessToken(
// If there is already a device with the same device ID for this user, that access token will be revoked
// and replaced with the given accessToken. If the given accessToken is already in use for another device,
// an error will be returned.
// If no device ID is given one is generated.
// Returns the device on success.
func (d *Database) CreateDevice(
ctx context.Context, localpart, deviceID, accessToken string,
ctx context.Context, localpart string, deviceID *string, accessToken string,
) (dev *authtypes.Device, returnErr error) {
returnErr = common.WithTransaction(d.db, func(txn *sql.Tx) error {
var err error
// Revoke existing token for this device
if err = d.devices.deleteDevice(ctx, txn, deviceID, localpart); err != nil {
return err
}
if deviceID != nil {
returnErr = common.WithTransaction(d.db, func(txn *sql.Tx) error {
var err error
// Revoke existing token for this device
if err = d.devices.deleteDevice(ctx, txn, *deviceID, localpart); err != nil {
return err
}
dev, err = d.devices.insertDevice(ctx, txn, deviceID, localpart, accessToken)
return err
})
dev, err = d.devices.insertDevice(ctx, txn, *deviceID, localpart, accessToken)
return err
})
} else {
// We generate device IDs in a loop in case its already taken.
// We cap this at going round 5 times to ensure we don't spin forever
var newDeviceID string
for i := 1; i <= 5; i++ {
newDeviceID, returnErr = auth.GenerateDeviceID()
if returnErr != nil {
return
}
returnErr = common.WithTransaction(d.db, func(txn *sql.Tx) error {
var err error
dev, err = d.devices.insertDevice(ctx, txn, newDeviceID, localpart, accessToken)
return err
})
if returnErr == nil {
return
}
}
}
return
}

View file

@ -117,14 +117,9 @@ func Login(
httputil.LogThenError(req, err)
}
deviceID, err := auth.GenerateDeviceID()
if err != nil {
httputil.LogThenError(req, err)
}
// TODO: Use the device ID in the request
dev, err := deviceDB.CreateDevice(
req.Context(), acc.Localpart, deviceID, token,
req.Context(), acc.Localpart, nil, token,
)
if err != nil {
return util.JSONResponse{
@ -139,7 +134,7 @@ func Login(
UserID: dev.UserID,
AccessToken: dev.AccessToken,
HomeServer: cfg.Matrix.ServerName,
DeviceID: deviceID,
DeviceID: dev.ID,
},
}
}

View file

@ -290,7 +290,7 @@ func completeRegistration(
}
// // TODO: Use the device ID in the request.
dev, err := deviceDB.CreateDevice(ctx, username, auth.UnknownDeviceID, token)
dev, err := deviceDB.CreateDevice(ctx, username, nil, token)
if err != nil {
return util.JSONResponse{
Code: 500,

View file

@ -87,7 +87,7 @@ func main() {
}
device, err := deviceDB.CreateDevice(
context.Background(), *username, "create-account-script", *accessToken,
context.Background(), *username, nil, *accessToken,
)
if err != nil {
fmt.Println(err.Error())