feat: complete Ancestor quote bot with production-ready Docker support
This commit is contained in:
167
node_modules/matrix-js-sdk/lib/interactive-auth.js
generated
vendored
167
node_modules/matrix-js-sdk/lib/interactive-auth.js
generated
vendored
@@ -1,4 +1,14 @@
|
||||
import _defineProperty from "@babel/runtime/helpers/defineProperty";
|
||||
"use strict";
|
||||
|
||||
var _interopRequireDefault = require("@babel/runtime/helpers/interopRequireDefault");
|
||||
Object.defineProperty(exports, "__esModule", {
|
||||
value: true
|
||||
});
|
||||
exports.NoAuthFlowFoundError = exports.InteractiveAuth = exports.AuthType = void 0;
|
||||
var _defineProperty2 = _interopRequireDefault(require("@babel/runtime/helpers/defineProperty"));
|
||||
var _logger = require("./logger");
|
||||
var _utils = require("./utils");
|
||||
var _httpApi = require("./http-api");
|
||||
/*
|
||||
Copyright 2016 OpenMarket Ltd
|
||||
Copyright 2017 Vector Creations Ltd
|
||||
@@ -17,8 +27,6 @@ See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
import { logger } from "./logger.js";
|
||||
import { MatrixError } from "./http-api/index.js";
|
||||
const EMAIL_STAGE_TYPE = "m.login.email.identity";
|
||||
const MSISDN_STAGE_TYPE = "m.login.msisdn";
|
||||
|
||||
@@ -27,8 +35,7 @@ const MSISDN_STAGE_TYPE = "m.login.msisdn";
|
||||
*
|
||||
* @see https://spec.matrix.org/v1.6/client-server-api/#user-interactive-api-in-the-rest-api
|
||||
*/
|
||||
|
||||
export let AuthType = /*#__PURE__*/function (AuthType) {
|
||||
let AuthType = /*#__PURE__*/function (AuthType) {
|
||||
AuthType["Password"] = "m.login.password";
|
||||
AuthType["Recaptcha"] = "m.login.recaptcha";
|
||||
AuthType["Terms"] = "m.login.terms";
|
||||
@@ -38,42 +45,35 @@ export let AuthType = /*#__PURE__*/function (AuthType) {
|
||||
AuthType["SsoUnstable"] = "org.matrix.login.sso";
|
||||
AuthType["Dummy"] = "m.login.dummy";
|
||||
AuthType["RegistrationToken"] = "m.login.registration_token";
|
||||
// For backwards compatability with servers that have not yet updated to
|
||||
// use the stable "m.login.registration_token" type.
|
||||
// The authentication flow is the same in both cases.
|
||||
AuthType["UnstableRegistrationToken"] = "org.matrix.msc3231.login.registration_token";
|
||||
/**
|
||||
* m.oauth stage introduced by MSC4312:
|
||||
* https://spec.matrix.org/v1.17/client-server-api/#oauth-authentication
|
||||
*/
|
||||
AuthType["OAuth"] = "m.oauth";
|
||||
return AuthType;
|
||||
}({});
|
||||
|
||||
/**
|
||||
* https://spec.matrix.org/v1.7/client-server-api/#password-based
|
||||
*/
|
||||
|
||||
/**
|
||||
* https://spec.matrix.org/v1.7/client-server-api/#google-recaptcha
|
||||
*/
|
||||
|
||||
/**
|
||||
* https://spec.matrix.org/v1.7/client-server-api/#email-based-identity--homeserver
|
||||
*/
|
||||
|
||||
/**
|
||||
* The parameters which are submitted as the `auth` dict in a UIA request
|
||||
*
|
||||
* @see https://spec.matrix.org/v1.6/client-server-api/#authentication-types
|
||||
*/
|
||||
|
||||
export class NoAuthFlowFoundError extends Error {
|
||||
/**
|
||||
* Backwards compatible export
|
||||
* @deprecated in favour of AuthDict
|
||||
*/
|
||||
exports.AuthType = AuthType;
|
||||
class NoAuthFlowFoundError extends Error {
|
||||
// eslint-disable-next-line @typescript-eslint/naming-convention, camelcase
|
||||
constructor(m, required_stages, flows) {
|
||||
super(m);
|
||||
_defineProperty(this, "name", "NoAuthFlowFoundError");
|
||||
this.required_stages = required_stages;
|
||||
this.flows = flows;
|
||||
(0, _defineProperty2.default)(this, "name", "NoAuthFlowFoundError");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -86,7 +86,7 @@ export class NoAuthFlowFoundError extends Error {
|
||||
*
|
||||
* The generic parameter `T` is the type of the response of the endpoint, once it is eventually successful.
|
||||
*/
|
||||
|
||||
exports.NoAuthFlowFoundError = NoAuthFlowFoundError;
|
||||
/**
|
||||
* Abstracts the logic used to drive the interactive auth process.
|
||||
*
|
||||
@@ -102,33 +102,33 @@ export class NoAuthFlowFoundError extends Error {
|
||||
* @param opts - options object
|
||||
* @typeParam T - the return type of the request when it is successful
|
||||
*/
|
||||
export class InteractiveAuth {
|
||||
class InteractiveAuth {
|
||||
constructor(opts) {
|
||||
_defineProperty(this, "matrixClient", void 0);
|
||||
_defineProperty(this, "inputs", void 0);
|
||||
_defineProperty(this, "clientSecret", void 0);
|
||||
_defineProperty(this, "requestCallback", void 0);
|
||||
_defineProperty(this, "busyChangedCallback", void 0);
|
||||
_defineProperty(this, "stateUpdatedCallback", void 0);
|
||||
_defineProperty(this, "requestEmailTokenCallback", void 0);
|
||||
_defineProperty(this, "supportedStages", void 0);
|
||||
(0, _defineProperty2.default)(this, "matrixClient", void 0);
|
||||
(0, _defineProperty2.default)(this, "inputs", void 0);
|
||||
(0, _defineProperty2.default)(this, "clientSecret", void 0);
|
||||
(0, _defineProperty2.default)(this, "requestCallback", void 0);
|
||||
(0, _defineProperty2.default)(this, "busyChangedCallback", void 0);
|
||||
(0, _defineProperty2.default)(this, "stateUpdatedCallback", void 0);
|
||||
(0, _defineProperty2.default)(this, "requestEmailTokenCallback", void 0);
|
||||
(0, _defineProperty2.default)(this, "supportedStages", void 0);
|
||||
// The current latest data or error received from the server during the user interactive auth flow.
|
||||
_defineProperty(this, "data", void 0);
|
||||
_defineProperty(this, "emailSid", void 0);
|
||||
_defineProperty(this, "requestingEmailToken", false);
|
||||
_defineProperty(this, "attemptAuthDeferred", null);
|
||||
_defineProperty(this, "chosenFlow", null);
|
||||
_defineProperty(this, "currentStage", null);
|
||||
_defineProperty(this, "emailAttempt", 1);
|
||||
(0, _defineProperty2.default)(this, "data", void 0);
|
||||
(0, _defineProperty2.default)(this, "emailSid", void 0);
|
||||
(0, _defineProperty2.default)(this, "requestingEmailToken", false);
|
||||
(0, _defineProperty2.default)(this, "attemptAuthDeferred", null);
|
||||
(0, _defineProperty2.default)(this, "chosenFlow", null);
|
||||
(0, _defineProperty2.default)(this, "currentStage", null);
|
||||
(0, _defineProperty2.default)(this, "emailAttempt", 1);
|
||||
// if we are currently trying to submit an auth dict (which includes polling)
|
||||
// the promise the will resolve/reject when it completes
|
||||
_defineProperty(this, "submitPromise", null);
|
||||
(0, _defineProperty2.default)(this, "submitPromise", null);
|
||||
/**
|
||||
* Requests a new email token and sets the email sid for the validation session
|
||||
*/
|
||||
_defineProperty(this, "requestEmailToken", async () => {
|
||||
(0, _defineProperty2.default)(this, "requestEmailToken", async () => {
|
||||
if (!this.requestingEmailToken) {
|
||||
logger.trace("Requesting email token. Attempt: " + this.emailAttempt);
|
||||
_logger.logger.trace("Requesting email token. Attempt: " + this.emailAttempt);
|
||||
// If we've picked a flow with email auth, we send the email
|
||||
// now because we want the request to fail as soon as possible
|
||||
// if the email address is not valid (ie. already taken or not
|
||||
@@ -137,12 +137,12 @@ export class InteractiveAuth {
|
||||
try {
|
||||
const requestTokenResult = await this.requestEmailTokenCallback(this.inputs.emailAddress, this.clientSecret, this.emailAttempt++, this.data.session);
|
||||
this.emailSid = requestTokenResult.sid;
|
||||
logger.trace("Email token request succeeded");
|
||||
_logger.logger.trace("Email token request succeeded");
|
||||
} finally {
|
||||
this.requestingEmailToken = false;
|
||||
}
|
||||
} else {
|
||||
logger.warn("Could not request email token: Already requesting");
|
||||
_logger.logger.warn("Could not request email token: Already requesting");
|
||||
}
|
||||
});
|
||||
this.matrixClient = opts.matrixClient;
|
||||
@@ -169,21 +169,24 @@ export class InteractiveAuth {
|
||||
* no suitable authentication flow can be found
|
||||
*/
|
||||
async attemptAuth() {
|
||||
var _this$data;
|
||||
// This promise will be quite long-lived and will resolve when the
|
||||
// request is authenticated and completes successfully.
|
||||
this.attemptAuthDeferred = Promise.withResolvers();
|
||||
this.attemptAuthDeferred = (0, _utils.defer)();
|
||||
// pluck the promise out now, as doRequest may clear before we return
|
||||
const promise = this.attemptAuthDeferred.promise;
|
||||
|
||||
// if we have no flows, try a request to acquire the flows
|
||||
if (!this.data?.flows?.length) {
|
||||
this.busyChangedCallback?.(true);
|
||||
if (!((_this$data = this.data) !== null && _this$data !== void 0 && (_this$data = _this$data.flows) !== null && _this$data !== void 0 && _this$data.length)) {
|
||||
var _this$busyChangedCall;
|
||||
(_this$busyChangedCall = this.busyChangedCallback) === null || _this$busyChangedCall === void 0 ? void 0 : _this$busyChangedCall.call(this, true);
|
||||
// use the existing sessionId, if one is present.
|
||||
const auth = this.data.session ? {
|
||||
session: this.data.session
|
||||
} : null;
|
||||
this.doRequest(auth).finally(() => {
|
||||
this.busyChangedCallback?.(false);
|
||||
var _this$busyChangedCall2;
|
||||
(_this$busyChangedCall2 = this.busyChangedCallback) === null || _this$busyChangedCall2 === void 0 ? void 0 : _this$busyChangedCall2.call(this, false);
|
||||
});
|
||||
} else {
|
||||
this.startNextAuthStage();
|
||||
@@ -212,13 +215,17 @@ export class InteractiveAuth {
|
||||
sid: this.emailSid,
|
||||
client_secret: this.clientSecret
|
||||
};
|
||||
const isUrl = this.matrixClient.getIdentityServerUrl();
|
||||
if (isUrl) {
|
||||
creds.id_server = new URL(isUrl).host;
|
||||
if (await this.matrixClient.doesServerRequireIdServerParam()) {
|
||||
const idServerParsedUrl = new URL(this.matrixClient.getIdentityServerUrl());
|
||||
creds.id_server = idServerParsedUrl.host;
|
||||
}
|
||||
authDict = {
|
||||
type: EMAIL_STAGE_TYPE,
|
||||
threepid_creds: creds
|
||||
// TODO: Remove `threepid_creds` once servers support proper UIA
|
||||
// See https://github.com/matrix-org/synapse/issues/5665
|
||||
// See https://github.com/matrix-org/matrix-doc/issues/2220
|
||||
threepid_creds: creds,
|
||||
threepidCreds: creds
|
||||
};
|
||||
}
|
||||
}
|
||||
@@ -231,7 +238,8 @@ export class InteractiveAuth {
|
||||
* @returns session id
|
||||
*/
|
||||
getSessionId() {
|
||||
return this.data?.session;
|
||||
var _this$data2;
|
||||
return (_this$data2 = this.data) === null || _this$data2 === void 0 ? void 0 : _this$data2.session;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -251,7 +259,8 @@ export class InteractiveAuth {
|
||||
* @returns any parameters from the server for this stage
|
||||
*/
|
||||
getStageParams(loginType) {
|
||||
return this.data?.params?.[loginType];
|
||||
var _this$data3;
|
||||
return (_this$data3 = this.data) === null || _this$data3 === void 0 || (_this$data3 = _this$data3.params) === null || _this$data3 === void 0 ? void 0 : _this$data3[loginType];
|
||||
}
|
||||
getChosenFlow() {
|
||||
return this.chosenFlow;
|
||||
@@ -270,31 +279,33 @@ export class InteractiveAuth {
|
||||
* for requests that just poll to see if auth has been completed elsewhere.
|
||||
*/
|
||||
async submitAuthDict(authData, background = false) {
|
||||
var _this$data4;
|
||||
if (!this.attemptAuthDeferred) {
|
||||
throw new Error("submitAuthDict() called before attemptAuth()");
|
||||
}
|
||||
if (!background) {
|
||||
this.busyChangedCallback?.(true);
|
||||
var _this$busyChangedCall3;
|
||||
(_this$busyChangedCall3 = this.busyChangedCallback) === null || _this$busyChangedCall3 === void 0 ? void 0 : _this$busyChangedCall3.call(this, true);
|
||||
}
|
||||
|
||||
// if we're currently trying a request, wait for it to finish
|
||||
// as otherwise we can get multiple 200 responses which can mean
|
||||
// things like multiple logins for register requests.
|
||||
// (but discard any exceptions as we only care when its done,
|
||||
// not whether it worked or not)
|
||||
while (this.submitPromise) {
|
||||
try {
|
||||
await this.submitPromise;
|
||||
} catch {
|
||||
// discard any exceptions as we only care when its done,
|
||||
// not whether it worked or not
|
||||
}
|
||||
} catch (e) {}
|
||||
}
|
||||
|
||||
// use the sessionid from the last request, if one is present.
|
||||
let auth;
|
||||
if (this.data?.session) {
|
||||
auth = Object.assign({
|
||||
if ((_this$data4 = this.data) !== null && _this$data4 !== void 0 && _this$data4.session) {
|
||||
auth = {
|
||||
session: this.data.session
|
||||
}, authData);
|
||||
};
|
||||
Object.assign(auth, authData);
|
||||
} else {
|
||||
auth = authData;
|
||||
}
|
||||
@@ -306,7 +317,8 @@ export class InteractiveAuth {
|
||||
} finally {
|
||||
this.submitPromise = null;
|
||||
if (!background) {
|
||||
this.busyChangedCallback?.(false);
|
||||
var _this$busyChangedCall4;
|
||||
(_this$busyChangedCall4 = this.busyChangedCallback) === null || _this$busyChangedCall4 === void 0 ? void 0 : _this$busyChangedCall4.call(this, false);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -349,20 +361,22 @@ export class InteractiveAuth {
|
||||
this.attemptAuthDeferred.resolve(result);
|
||||
this.attemptAuthDeferred = null;
|
||||
} catch (error) {
|
||||
const matrixError = error instanceof MatrixError ? error : null;
|
||||
var _matrixError$data$flo, _matrixError$data, _this$data5, _this$chosenFlow;
|
||||
const matrixError = error instanceof _httpApi.MatrixError ? error : null;
|
||||
|
||||
// sometimes UI auth errors don't come with flows
|
||||
const errorFlows = matrixError?.data?.flows ?? null;
|
||||
const haveFlows = this.data?.flows || Boolean(errorFlows);
|
||||
const errorFlows = (_matrixError$data$flo = matrixError === null || matrixError === void 0 || (_matrixError$data = matrixError.data) === null || _matrixError$data === void 0 ? void 0 : _matrixError$data.flows) !== null && _matrixError$data$flo !== void 0 ? _matrixError$data$flo : null;
|
||||
const haveFlows = ((_this$data5 = this.data) === null || _this$data5 === void 0 ? void 0 : _this$data5.flows) || Boolean(errorFlows);
|
||||
if (!matrixError || matrixError.httpStatus !== 401 || !matrixError.data || !haveFlows) {
|
||||
// doesn't look like an interactive-auth failure.
|
||||
if (!background) {
|
||||
this.attemptAuthDeferred?.reject(error);
|
||||
var _this$attemptAuthDefe;
|
||||
(_this$attemptAuthDefe = this.attemptAuthDeferred) === null || _this$attemptAuthDefe === void 0 ? void 0 : _this$attemptAuthDefe.reject(error);
|
||||
} else {
|
||||
// We ignore all failures here (even non-UI auth related ones)
|
||||
// since we don't want to suddenly fail if the internet connection
|
||||
// had a blip whilst we were polling
|
||||
logger.log("Background poll request failed doing UI auth: ignoring", error);
|
||||
_logger.logger.log("Background poll request failed doing UI auth: ignoring", error);
|
||||
}
|
||||
}
|
||||
if (matrixError && !matrixError.data) {
|
||||
@@ -388,7 +402,7 @@ export class InteractiveAuth {
|
||||
this.attemptAuthDeferred = null;
|
||||
return;
|
||||
}
|
||||
if (!this.emailSid && this.chosenFlow?.stages.includes(AuthType.Email)) {
|
||||
if (!this.emailSid && (_this$chosenFlow = this.chosenFlow) !== null && _this$chosenFlow !== void 0 && _this$chosenFlow.stages.includes(AuthType.Email)) {
|
||||
try {
|
||||
await this.requestEmailToken();
|
||||
// NB. promise is not resolved here - at some point, doRequest
|
||||
@@ -418,6 +432,7 @@ export class InteractiveAuth {
|
||||
* @throws {@link NoAuthFlowFoundError} If no suitable authentication flow can be found
|
||||
*/
|
||||
startNextAuthStage() {
|
||||
var _this$data6, _this$data7;
|
||||
const nextStage = this.chooseStage();
|
||||
if (!nextStage) {
|
||||
throw new Error("No incomplete flows from the server");
|
||||
@@ -429,10 +444,11 @@ export class InteractiveAuth {
|
||||
});
|
||||
return;
|
||||
}
|
||||
if (this.data?.errcode || this.data?.error) {
|
||||
if ((_this$data6 = this.data) !== null && _this$data6 !== void 0 && _this$data6.errcode || (_this$data7 = this.data) !== null && _this$data7 !== void 0 && _this$data7.error) {
|
||||
var _this$data8, _this$data9;
|
||||
this.stateUpdatedCallback(nextStage, {
|
||||
errcode: this.data?.errcode || "",
|
||||
error: this.data?.error || ""
|
||||
errcode: ((_this$data8 = this.data) === null || _this$data8 === void 0 ? void 0 : _this$data8.errcode) || "",
|
||||
error: ((_this$data9 = this.data) === null || _this$data9 === void 0 ? void 0 : _this$data9.error) || ""
|
||||
});
|
||||
return;
|
||||
}
|
||||
@@ -452,9 +468,9 @@ export class InteractiveAuth {
|
||||
if (this.chosenFlow === null) {
|
||||
this.chosenFlow = this.chooseFlow();
|
||||
}
|
||||
logger.log("Active flow => %s", JSON.stringify(this.chosenFlow));
|
||||
_logger.logger.log("Active flow => %s", JSON.stringify(this.chosenFlow));
|
||||
const nextStage = this.firstUncompletedStage(this.chosenFlow);
|
||||
logger.log("Next stage: %s", nextStage);
|
||||
_logger.logger.log("Next stage: %s", nextStage);
|
||||
return nextStage;
|
||||
}
|
||||
|
||||
@@ -485,7 +501,8 @@ export class InteractiveAuth {
|
||||
* @throws {@link NoAuthFlowFoundError} If no suitable authentication flow can be found
|
||||
*/
|
||||
chooseFlow() {
|
||||
const flows = this.data?.flows || [];
|
||||
var _this$data10;
|
||||
const flows = ((_this$data10 = this.data) === null || _this$data10 === void 0 ? void 0 : _this$data10.flows) || [];
|
||||
|
||||
// we've been given an email or we've already done an email part
|
||||
const haveEmail = Boolean(this.inputs.emailAddress) || Boolean(this.emailSid);
|
||||
@@ -523,8 +540,10 @@ export class InteractiveAuth {
|
||||
* @returns login type
|
||||
*/
|
||||
firstUncompletedStage(flow) {
|
||||
const completed = this.data?.completed || [];
|
||||
var _this$data11;
|
||||
const completed = ((_this$data11 = this.data) === null || _this$data11 === void 0 ? void 0 : _this$data11.completed) || [];
|
||||
return flow.stages.find(stageType => !completed.includes(stageType));
|
||||
}
|
||||
}
|
||||
exports.InteractiveAuth = InteractiveAuth;
|
||||
//# sourceMappingURL=interactive-auth.js.map
|
||||
Reference in New Issue
Block a user