Delete block when deleting account

pull/1/head
yflory 4 years ago
parent 9d6cc55642
commit eb7f7aaa89

@ -232,17 +232,6 @@ define([
}; };
postMessage("MIGRATE_ANON_DRIVE", data, cb); postMessage("MIGRATE_ANON_DRIVE", data, cb);
}; };
// Settings
common.deleteAccount = function (cb) {
postMessage("DELETE_ACCOUNT", null, function (obj) {
if (obj.state) {
Feedback.send('DELETE_ACCOUNT_AUTOMATIC');
} else {
Feedback.send('DELETE_ACCOUNT_MANUAL');
}
cb(obj);
});
};
// Drive // Drive
common.userObjectCommand = function (data, cb) { common.userObjectCommand = function (data, cb) {
postMessage("DRIVE_USEROBJECT", data, cb); postMessage("DRIVE_USEROBJECT", data, cb);
@ -1674,30 +1663,16 @@ define([
}; };
common.changeUserPassword = function (Crypt, edPublic, data, cb) { var getBlockKeys = function (data, cb) {
if (!edPublic) {
return void cb({
error: 'E_NOT_LOGGED_IN'
});
}
var accountName = LocalStore.getAccountName(); var accountName = LocalStore.getAccountName();
var hash = LocalStore.getUserHash(); var password = data.password;
if (!hash) { var Cred, Block, Login;
return void cb({ var blockKeys;
error: 'E_NOT_LOGGED_IN'
});
}
var password = data.password; // To remove your old block
var newPassword = data.newPassword; // To create your new block
var secret = Hash.getSecrets('drive', hash);
var newHash, newHref, newSecret, blockKeys;
var oldIsOwned = false;
var hash = LocalStore.getUserHash();
if (!hash) { return void cb({ error: 'E_NOT_LOGGED_IN' }); }
var blockHash = LocalStore.getBlockHash(); var blockHash = LocalStore.getBlockHash();
var oldBlockKeys;
var Cred, Block, Login;
Nthen(function (waitFor) { Nthen(function (waitFor) {
require([ require([
'/common/common-credential.js', '/common/common-credential.js',
@ -1710,30 +1685,92 @@ define([
})); }));
}).nThen(function (waitFor) { }).nThen(function (waitFor) {
// confirm that the provided password is correct // confirm that the provided password is correct
Cred.deriveFromPassphrase(accountName, password, Login.requiredBytes, waitFor(function (bytes) { Cred.deriveFromPassphrase(accountName, password, Login.requiredBytes,
waitFor(function (bytes) {
var allocated = Login.allocateBytes(bytes); var allocated = Login.allocateBytes(bytes);
oldBlockKeys = allocated.blockKeys; blockKeys = allocated.blockKeys;
if (blockHash) { if (blockHash) {
if (blockHash !== allocated.blockHash) { if (blockHash !== allocated.blockHash) {
// incorrect password
console.log("provided password did not yield the correct blockHash"); console.log("provided password did not yield the correct blockHash");
// incorrect password probably
waitFor.abort(); waitFor.abort();
return void cb({ return void cb({ error: 'INVALID_PASSWORD', });
error: 'INVALID_PASSWORD',
});
} }
// the user has already created a block, so you should compare against that
} else { } else {
// otherwise they're a legacy user, and we should check against the User_hash // otherwise they're a legacy user, and we should check against the User_hash
if (hash !== allocated.userHash) { if (hash !== allocated.userHash) {
// incorrect password
console.log("provided password did not yield the correct userHash"); console.log("provided password did not yield the correct userHash");
waitFor.abort(); waitFor.abort();
return void cb({ return void cb({ error: 'INVALID_PASSWORD', });
error: 'INVALID_PASSWORD',
});
} }
} }
})); }));
}).nThen(function () {
cb({
Cred: Cred,
Block: Block,
Login: Login,
blockKeys: blockKeys
});
});
};
common.deleteAccount = function (data, cb) {
data = data || {};
// Confirm that the provided password is corrct and get the block keys
getBlockKeys(data, function (obj) {
if (obj && obj.error) { return void cb(obj); }
var blockKeys = obj.blockKeys;
var removeData = obj.Block.remove(blockKeys);
postMessage("DELETE_ACCOUNT", {
removeData: removeData
}, function (obj) {
if (obj.state) {
Feedback.send('DELETE_ACCOUNT_AUTOMATIC');
} else {
Feedback.send('DELETE_ACCOUNT_MANUAL');
}
cb(obj);
});
});
};
common.changeUserPassword = function (Crypt, edPublic, data, cb) {
if (!edPublic) {
return void cb({
error: 'E_NOT_LOGGED_IN'
});
}
var accountName = LocalStore.getAccountName();
var hash = LocalStore.getUserHash();
if (!hash) {
return void cb({
error: 'E_NOT_LOGGED_IN'
});
}
var password = data.password; // To remove your old block
var newPassword = data.newPassword; // To create your new block
var secret = Hash.getSecrets('drive', hash);
var newHash, newHref, newSecret, blockKeys;
var oldIsOwned = false;
var blockHash = LocalStore.getBlockHash();
var oldBlockKeys;
var Cred, Block, Login;
Nthen(function (waitFor) {
getBlockKeys(data, waitFor(function (obj) {
if (obj && obj.error) {
waitFor.abort();
return void cb(obj);
}
oldBlockKeys = obj.blockKeys;
Cred = obj.Cred;
Login = obj.Login;
Block = obj.Block;
}));
}).nThen(function (waitFor) { }).nThen(function (waitFor) {
// Check if our drive is already owned // Check if our drive is already owned
console.log("checking if old drive is owned"); console.log("checking if old drive is owned");

@ -741,6 +741,7 @@ define([
Store.deleteAccount = function (clientId, data, cb) { Store.deleteAccount = function (clientId, data, cb) {
var edPublic = store.proxy.edPublic; var edPublic = store.proxy.edPublic;
var removeData = data && data.removeData;
Store.anonRpcMsg(clientId, { Store.anonRpcMsg(clientId, {
msg: 'GET_METADATA', msg: 'GET_METADATA',
data: store.driveChannel data: store.driveChannel
@ -769,8 +770,11 @@ define([
channel: store.driveChannel, channel: store.driveChannel,
force: true force: true
}, waitFor()); }, waitFor());
}).nThen(function (waitFor) {
if (!removeData) { return; }
// Delete the block. Don't abort if it fails, it doesn't leak any data.
store.rpc.removeLoginBlock(removeData, waitFor());
}).nThen(function () { }).nThen(function () {
// TODO delete block
// Log out current worker // Log out current worker
postMessage(clientId, "DELETE_ACCOUNT", token, function () {}); postMessage(clientId, "DELETE_ACCOUNT", token, function () {});
store.network.disconnect(); store.network.disconnect();

@ -85,7 +85,7 @@
} }
} }
.cp-settings-change-password, .cp-settings-own-drive { .cp-settings-change-password, .cp-settings-own-drive, .cp-settings-delete {
[type="password"], [type="text"] { [type="password"], [type="text"] {
width: @sidebar_button-width; width: @sidebar_button-width;
flex: unset; flex: unset;

@ -469,63 +469,64 @@ define([
}); });
}, true); }, true);
create['delete'] = function() { makeBlock('delete', function(cb) { // Msg.settings_deleteHint, .settings_deleteTitle
if (!common.isLoggedIn()) { return; } if (!common.isLoggedIn()) { return cb(false); }
var $div = $('<div>', { 'class': 'cp-settings-delete cp-sidebarlayout-element' });
$('<span>', { 'class': 'label' }).text(Messages.settings_deleteTitle).appendTo($div);
$('<span>', { 'class': 'cp-sidebarlayout-description' })
.append(Messages.settings_deleteHint).appendTo($div);
var $ok = $('<span>', { 'class': 'fa fa-check', title: Messages.saved });
var $spinner = $('<span>', { 'class': 'fa fa-spinner fa-pulse' });
var $button = $('<button>', { 'id': 'cp-settings-delete', 'class': 'btn btn-danger' }) var button = h('button.btn.btn-danger', Messages.settings_deleteButton);
.text(Messages.settings_deleteButton).appendTo($div); var form = h('div', [
UI.passwordInput({
id: 'cp-settings-delete-account',
placeholder: Messages.settings_changePasswordCurrent
}, true),
button
]);
var $form = $(form);
var $button = $(button);
var spinner = UI.makeSpinner($form);
$button.click(function() { UI.confirmButton(button, {
$spinner.show(); classes: 'btn-danger'
UI.confirm(Messages.settings_deleteConfirm, function(yes) { }, function() {
if (!yes) { return void $spinner.hide(); } $button.prop('disabled', 'disabled');
sframeChan.query("Q_SETTINGS_DELETE_ACCOUNT", null, function(err, data) { spinner.spin();
// Owned drive var password = $form.find('#cp-settings-delete-account').val();
if (data.state === true) { if (!password) {
sframeChan.query('Q_SETTINGS_LOGOUT', null, function() {}); return void UI.warn(Messages.error);
UI.alert(Messages.settings_deleted, function() { }
common.gotoURL('/'); sframeChan.query("Q_SETTINGS_DELETE_ACCOUNT", {
}); password: password
$ok.show(); }, function(err, data) {
$spinner.hide(); if (data && data.error) {
return; spinner.hide();
$button.prop('disabled', '');
if (data.error === 'INVALID_PASSWORD') {
return void UI.warn(Messages.drive_sfPasswordError);
} }
// Not owned drive console.error(data.error);
var msg = h('div.cp-app-settings-delete-alert', [ return void UI.warn(Messages.error);
h('p', Messages.settings_deleteModal), }
h('pre', JSON.stringify(data, 0, 2)) // Owned drive
]); if (data.state === true) {
UI.alert(msg); sframeChan.query('Q_SETTINGS_LOGOUT', null, function() {});
$spinner.hide(); UI.alert(Messages.settings_deleted, function() {
}); common.gotoURL('/');
});
spinner.done();
return;
}
// Not owned drive
var msg = h('div.cp-app-settings-delete-alert', [
h('p', Messages.settings_deleteModal),
h('pre', JSON.stringify(data, 0, 2))
]);
UI.alert(msg);
spinner.done();
$button.prop('disabled', '');
}); });
// TODO
/*
UI.confirm("Are you sure?", function (yes) {
// Logout everywhere
// Disconnect other tabs
// Remove owned pads
// Remove owned drive
// Remove pinstore
// Alert: "Account deleted", press OK to be redirected to the home page
$spinner.hide();
});*/
}); });
$spinner.hide().appendTo($div); cb(form);
$ok.hide().appendTo($div); }, true);
return $div;
};
create['change-password'] = function() { create['change-password'] = function() {
if (!common.isLoggedIn()) { return; } if (!common.isLoggedIn()) { return; }

@ -67,7 +67,7 @@ define([
Cryptpad.mergeAnonDrive(cb); Cryptpad.mergeAnonDrive(cb);
}); });
sframeChan.on('Q_SETTINGS_DELETE_ACCOUNT', function (data, cb) { sframeChan.on('Q_SETTINGS_DELETE_ACCOUNT', function (data, cb) {
Cryptpad.deleteAccount(cb); Cryptpad.deleteAccount(data, cb);
}); });
sframeChan.on('Q_COLORTHEME_CHANGE', function (data, cb) { sframeChan.on('Q_COLORTHEME_CHANGE', function (data, cb) {
localStorage['CRYPTPAD_STORE|colortheme'] = data.theme; localStorage['CRYPTPAD_STORE|colortheme'] = data.theme;

Loading…
Cancel
Save