Skip to content

Remote wipe support - #15104

Merged
rullzer merged 1 commit into
masterfrom
enh/remote_wipe
May 21, 2019
Merged

Remote wipe support#15104
rullzer merged 1 commit into
masterfrom
enh/remote_wipe

Conversation

@rullzer

@rullzer rullzer commented Apr 15, 2019

Copy link
Copy Markdown
Member

Todo:

  • Close dialog when clicking on wipe
  • Confirmation dialog password when wiping -> dialog will come later
  • Allow tokens to still be dleted when in wipe state
    • show dialog that this will kill the wipe
  • Docs - Remote wipe client api docs documentation#1453
  • Notifications
    • Once when the device fetches the wipe state
    • Once when device reports wipe complete
  • Activities
    • Once when the device fetches the wipe state
    • Once when device reports wipe complete
  • Tests

Future work:

  • Confirmation dialog (requires vue-components work)
  • Send mail
  • More tests

@rullzer rullzer added this to the Nextcloud 17 milestone Apr 15, 2019
@ChristophWurst

Copy link
Copy Markdown
Member
* Confirmation dialog when wiping

Is password confirmation sufficient?

@ChristophWurst

Copy link
Copy Markdown
Member

I've added a bit of visual distinction to the wiped tokens.

Bildschirmfoto von 2019-04-30 09-40-42

@rullzer

rullzer commented May 10, 2019

Copy link
Copy Markdown
Member Author
* Confirmation dialog when wiping

Is password confirmation sufficient?

Ah well. so yes there should be password confirmation. But since this is such a destructive feature and right next to 'delete token'. A separate popup would be helpfull IMO.

Of course if this is to much work then so be it for now and we create a ticket.

@ChristophWurst

Copy link
Copy Markdown
Member

Of course if this is to much work then so be it for now and we create a ticket.

I think we should look into creating a component for this in nextcloud-vue. There is also a need for this in Mail.

Comment thread core/Application.php
}, function() use ($server) {
}, function() {
return [
'id' => 'core',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

id already in use, same for the name

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also I have a problem with those notifications, since the to-be-wiped device can also delete them.
So basically they are useless. Please use an email instead.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rullzer opinions? I just added them because they were in this PR's todo.

So basically they are useless. Please use an email instead.

FYI there is a notification and an activity.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When the device fetches the wipe state it should not longer display notifications or allow other interaction I guess...

of course also sending a mail doesn't hurt.

@rullzer

rullzer commented May 16, 2019

Copy link
Copy Markdown
Member Author

So I would vote we make a list of things that are still needed but get this in soonish. Else it keeps doing the rebase and rebuild dance. And the basics should be solid already.

@rullzer

rullzer commented May 16, 2019

Copy link
Copy Markdown
Member Author
  • Revoking a token marked for wiping fails with a 404

@rullzer rullzer added 3. to review Waiting for reviews and removed 2. developing Work in progress labels May 16, 2019
@rullzer

rullzer commented May 16, 2019

Copy link
Copy Markdown
Member Author

So lets get this in so clients can do their thing and we can fix the remaining issues in small steps.

Comment thread core/Controller/WipeController.php Outdated
Comment thread core/Controller/WipeController.php Outdated
Comment thread lib/private/Authentication/Notifications/Notifier.php
@georgehrke

Copy link
Copy Markdown
Member

Probably something for later, but is it intended the you can remote wipe any token?

I guess this should only be available for our sync clients.

BECEB6DB-17F0-48BF-AA82-234DB6E865FB
You can also mark Thunderbird Lightning as remote wipe and i'm sure there are users that expect all the calendar data in lightning to be deleted, when they do that. But obviously lightning will just stop syncing, but not delete the calendar data from its cache.

@rullzer

rullzer commented May 16, 2019

Copy link
Copy Markdown
Member Author

Probably something for later, but is it intended the you can remote wipe any token?

I guess this should only be available for our sync clients.

BECEB6DB-17F0-48BF-AA82-234DB6E865FB
You can also mark Thunderbird Lightning as remote wipe and i'm sure there are users that expect all the calendar data in lightning to be deleted, when they do that. But obviously lightning will just stop syncing, but not delete the calendar data from its cache.

Yeah. Because you can rename tokens anyway.
But it should show in the dialog (that is to come) that not all devices are capable of remote wipe etc etc.

@georgehrke

georgehrke commented May 16, 2019

Copy link
Copy Markdown
Member

When using the curl command from the doc i just get an empty array.

Details SQL: ``` INSERT INTO `oc_authtoken` (`id`, `uid`, `login_name`, `password`, `name`, `token`, `type`, `remember`, `last_activity`, `last_check`, `scope`, `expires`, `private_key`, `public_key`, `version`, `password_invalid`) VALUES (134, X'61646D696E', X'61646D696E', X'344A79487A57454C65512F42464F482B4F505349354F385643762F312F686E38303563677970733969736C4257555553644E34426C6658664E5A306275422F796D7265532B7A51734468314A47394C5758396E70594C4C6C6F71496636736B445059364A7A53335772582B4E5955744C2B6143492B624D6363487A4C747A334C486268534A6A2F436B7A75304D4A7771586D74636B46516C374C3064643165387559726D72394753366E5054615A6266546E674C623645624B346249676644387A336235595831574736363943494941756F69414231427551586C397553356E6278634A424365432B466B6D4A6F73697157692F34626D51556B5454677766624732536F46482B544739323950315573493842506461434D4A50792F786767595467626E676271734E5968524244634868326449455256525676497A6C59774D7056714F654144764D726A6A39356F577676394B2B513D3D', X'636C692D74657374', X'6161383361666561616663313933643362376366633532313732613933653261656335373031343338336661613539383635666635633133323637376133326436363637633461333964316239316639306138313539356336393062353836333866626634656538626630333066393432633833396135626139326161373961', 2, 0, 1558000720, 1558000587, NULL, NULL, X'346132356330373938373063316564643861656430303762356438366137666331653736356337316166323033343033313836613833616437336333303961326636613361656432343437626431386330336237326163393830373263623532663165613061663866656262363461633964623336353637623531353465613763653266366565316664373335633563306631333261646661343335663463666366366262366136656263643438613861353032626532373465653262623531656533336139333662316265363964336337396361363138316263363362666639636433383737343962383031353265376437663331643032656236316432386566366563336265643430373361303631333531306233353931363435336636336231333063373332653163643535353763386131663339373932666465613835313363363266666638366461303235303630623935353361366536643734326335616130386133346639343661306163646333303534346136663964646138623934613636393965303530643533636564643465336563626139336130353264663138643834663138333966656535333233383533656634353266643730383233393438306461623531393366343330313638386137626561396138363165376362333030663961626362656639623933623263333430653665653462653735633630376462383565636630616664646363343537376362346432366564393965376662653664643034353761336266656436363132353865386665633731643934653965616435363039323132653466643834383365313338393339316364343464636164343236333966363135353439366265623263393365623836323237646464636566373062653165396562306535353664363231623462633038393039313634383532356264636233363530363662323230313038393738393364386562303636386264376534343933613031636631633434353934666635373835343634303163666334656239336233383163616533626539653330343039333037343932306532633763333930636636666434623638386665356132386635383263383236303135383163303638653632343630646130396637626439383537306466653238336435316133663662373661643766393938303539373961383636373434366661643361616530353833393665633437613563346637383639353861383965646462383335623034386630633562626536353636303362366364383365623139376566646164333033663636343334326338643161613937653565363631396361343664353334626639393466353437623962656362666234326336316565363534643565353139623338653138353434393838323031633661303462633139363631313133663261316566313135323831616466393162326539316565383661396430633937303566323562656331373532303764643863363435646361346465396532313965636562333430363161663938303663393936306361356434323832623333396666366132393464376436313061653861353662313164336362646664353464663932373334626633363361376665343132303834326132333734303763393939643162313134323335663537306432363061323964646663333465663734316137386334303362636564636461653666663430366133373561656431636366313732353866373335653337343735353736383534386131313730653630653933343763373733626230643765366535356434656461636662383932336263306362636436653138653137303462653234336266313861383735623865653133313536336139346131366133666466306331393866656339633235343865306135366337303761306363633030633133333764346439383933343766303031363762323934643132396665646135343935633765326362623436656539363666363330373335666537656266326234613236386637646365373839663065376663383139386364613762613630616434323063663030623639633831393631613033373232316330373337373638333931396666373939333161393339383164366466633931373263343038353462646264633632353262336362626238333262343932646437386362306135636437306134333265323537316564333763323035366233616534306439666462303838383462316637343361613639333632653137353537663262313831366666336133326261663330376631616136336462633634373338633864656366303862373932363864626534663862303362373966333835333039333531336131363365353031396464383634363233653432653737333866346430313866366132353563376364373834356264623634363332303366336239363131643031353135343362333430393933623537623965343436663563353663303362646232616332343539333932353832613963313365623238633230393337316161646333663638623562353632636232383935666365653463353632336662646131366632393433323761643762373830616264633638323063373136653236643237373832636534353762643234303535323737656639636266326238646433643832383137373534393265343631613361306139343665626236356131633934313631343565396632653662346237313962306464323530373361346236623763353865663834323036613637663136353631613533356338613666373839346266653034353234346161653264356163313635626431653066346361646234643735336438383631623433393232656137363462653066636335636363656366613431383763306632613865653634303161396338613033336435653361383439613964623631323734326132323463373937646566663734666631636539653633316438356366656466636130383530303932313134356664653530643266323032616361653737366666356162366232346635633632313233353231633431353565623632663639333136326632666639663865333562383830353564633839376434626661303863643331383764653261303165376662316534333566393934613235353832376437343533333137343137323136613238346261656563666465353937313837373664393531316436636634393862383933383562626534653831393931343137663635643939313839323533396233303665626533663431666337646563653335373333363336636338646635346134376339666438323431333639646636623964656536373235363661376364363830633335626534373835336530343865356566666165636461363732346333326662343266376464316537333131343931333064366439633466303363633334316535653732303838313438323064613333363261623534383434636639653834353338636262386335663935386232363735326534613733373436623166353861373036643836336334653735313035666137396164646637666564383333363230666338373736663833333761363635393731323031653138386463663831373532313932363236626332613436316466396433313739313864333236666431656234613738333761656161656563353935363864306261353739636263613464343736343063396566636263396464316337303334373838393966336564376266613730653335306336313934343234623061666134316563613766393131393864336433373264626237653935326564616634666138353234656634313663316230386362393365643939383237626464323032313365633639343735616462366431663532353133633365316436653666666363313839333530313566646138613465326234616366643437616230643239633431303362373336643461323865353036613465376530353434353462313561396638323963626563653966393733626236373838303930616462323537653662643334626538363732626436323830326536323634653263316435353831373937326365376366343038326633393161633337316465626565303635663339326432353236373930363635646262666334353766633535343934323366323335333230386332363634303332386566393436613236616162326463313663653530643434373439386163653836343066663363366139663231373964656466623837323736363331386431386130373733323462616433343233373635383764393738373137646131623133623465383734336537396266373630663165616331386463613739393738303234616433653836326233333064356661363838336464303433316264396163623862616138323435623965633136636664613063356536643362646639383863363466346136326261663837643035663534353139316434643634393836323062643161663239386634666439313461373762303633363561303932623165633533373335366434316532373130346334663562346565643939393564333334366239613536376435373466623734333232366233366133363162356435646438323965306131396235663333323837316637323339373737663937396635623237657C326A443556323777625536566F454F667C6334383530656230363033623034343133336237366263333736653935616530366537306431653939656561386339396365393765356134653436663161633934376135343632653335356535333838663265356431633764336637313636656662316266313535316433663630613861313132636335636438323666613835', X'2D2D2D2D2D424547494E205055424C4943204B45592D2D2D2D2D0A4D494942496A414E42676B71686B6947397730424151454641414F43415138414D49494243674B434151454135445959324E4959547358654B553648654E6E670A31454373616B344B6E486D366136554F556E764E4B5078386D736331716F66367778774553646A38776C5379576A35575A636B67504738546867734B394234650A342B3164696E434A3833754A364B626D697A7441784B554865434250742B3070564C324F4B37684E45506837763964642B6735364B4A4E724A4F636F6A4B596E0A6253516579494B34782F4179444F2F35455568727554304C3549344778364653722F504F656251715241446D747064675A674C4969626D592F30526F736F4F5A0A73435057597175745471664E7437427668794F75485761476934323954303765477049797A4B5A30624E4A504B446A474143733773675A424C725436426570510A47436D6431574167626B736A686D70525063503374726373626846643857754E64617763383356346B39744E716F4B593475544F434C4C7A37645169416C32530A4E514944415141420A2D2D2D2D2D454E44205055424C4943204B45592D2D2D2D2D0A', 2, 0); ```
curl -v http://nextcloud.local/index.php/core/wipe/check -X POST -d 'token=aa83afeaafc193d3b7cfc52172a93e2aec57014383faa59865ff5c132677a32d6667c4a39d1b91f90a81595c690b58638fbf4ee8bf030f942c839a5ba92aa79a'
Note: Unnecessary use of -X or --request, POST is already inferred.
*   Trying 127.0.0.1...
* TCP_NODELAY set
* Connected to nextcloud.local (127.0.0.1) port 80 (#0)
> POST /index.php/core/wipe/check HTTP/1.1
> Host: nextcloud.local
> User-Agent: curl/7.54.0
> Accept: */*
> Content-Length: 134
> Content-Type: application/x-www-form-urlencoded
>
* upload completely sent off: 134 out of 134 bytes
< HTTP/1.1 404 Not Found
< Date: Thu, 16 May 2019 10:11:21 GMT
< Server: Apache/2.4.37 (Unix)
< X-Powered-By: PHP/7.2.13
< Expires: Thu, 19 Nov 1981 08:52:00 GMT
< Pragma: no-cache
< X-Frame-Options: SAMEORIGIN
< Cache-Control: no-cache, no-store, must-revalidate
< Content-Security-Policy: default-src 'none';base-uri 'none';manifest-src 'self'
< Set-Cookie: XDEBUG_SESSION=www-data; expires=Thu, 16-May-2019 11:11:21 GMT; Max-Age=3600; path=/
< Set-Cookie: ockwx55s3hm3=2bdcebea6160cc2bc0791c19cd4a7200; path=/; HttpOnly
< Set-Cookie: oc_sessionPassphrase=VG4vJ3oH6p%2BzaurZyn7l3MPAur0YZd0gMpwwuh4S8VAuTjK5QVxp2CJEtIPsptrOabbMpGlgiB6cwJBBQYEhmuuyx%2BeNSosq92tlVVdwnAh3PXOjccOuIYJe%2FsC7K4S%2F; path=/; HttpOnly
< Set-Cookie: nc_sameSiteCookielax=true; path=/; httponly;expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=lax
< Set-Cookie: nc_sameSiteCookiestrict=true; path=/; httponly;expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=strict
< Content-Length: 2
< X-Content-Type-Options: nosniff
< X-XSS-Protection: 1; mode=block
< X-Robots-Tag: none
< X-Download-Options: noopen
< X-Permitted-Cross-Domain-Policies: none
< Referrer-Policy: no-referrer
< Content-Type: application/json; charset=utf-8
<
* Connection #0 to host nextcloud.local left intact
[]%

Looking at the SQL, the type is set to 2, so instead of an empty array it should return {wipe:true}, right?

@georgehrke georgehrke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Wipe check works properly.
Token is deleted after client signalised successful wipe.

Comment thread core/Controller/WipeController.php Outdated
Comment thread core/Controller/WipeController.php Outdated

@MorrisJobke MorrisJobke left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested (called the API manually) and it works 👍

@rullzer
rullzer force-pushed the enh/remote_wipe branch from 64222e6 to cddf3d2 Compare May 17, 2019 08:54
Comment thread core/Controller/WipeController.php Outdated
Comment thread core/Controller/WipeController.php Outdated
Comment thread lib/private/Authentication/Token/IProvider.php
This allows a user to mark a token for remote wipe.
Clients that support this can then wipe the device properly.

Signed-off-by: Roeland Jago Douma <roeland@famdouma.nl>
Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at>
@rullzer
rullzer force-pushed the enh/remote_wipe branch from cddf3d2 to f03eb7e Compare May 20, 2019 18:50
@MorrisJobke MorrisJobke added 4. to release Ready to be released and/or waiting for tests to finish and removed 3. to review Waiting for reviews labels May 20, 2019
@rullzer
rullzer merged commit 50dbdee into master May 21, 2019
@rullzer
rullzer deleted the enh/remote_wipe branch May 21, 2019 06:36
@marinofaggiana

Copy link
Copy Markdown
Member

@rullzer I call the endpoint core/wipe when I get an error 401 or 403, now If the core/wipe return with a 200 I read the wipe json and remove locally the user but if the session is only revoke I get an 404. The question is, is possible get an 401 or 403 for session revoked and the 404 for error on core/wipe ?

sound good for you ?

@rullzer

rullzer commented Oct 10, 2019

Copy link
Copy Markdown
Member Author

@marinofaggiana I'm not sure I follow what you mean.

If you do not get anything on the wipe endpoint you can assume your token is revoked right?

@marinofaggiana

Copy link
Copy Markdown
Member

@rullzer what you mean for "anything" ? error 404 ?

@rullzer

rullzer commented Oct 10, 2019

Copy link
Copy Markdown
Member Author

if you need to wipe you get a 200 on the endpoint. If not. your token is not marked for wipe. And you should follow the same steps you do right now if you get back a 403 ;)

@marinofaggiana

marinofaggiana commented Oct 10, 2019

Copy link
Copy Markdown
Member

Yes but, I repeat, endpoint with 200 ok, but if the session is revoked or exists an issue on server etc. return always 404. E.g. if the session is revoked will be a 401 or 403 and not a 404.

@rullzer

rullzer commented Oct 10, 2019

Copy link
Copy Markdown
Member Author

No if there is a sever issue you won't get a 404

@marinofaggiana

Copy link
Copy Markdown
Member

for me it would be more logical an 401/403 if is revoked ..

@rullzer

rullzer commented Oct 10, 2019

Copy link
Copy Markdown
Member Author

The problem is we do not know. The moment you revoke a token it gets removed. Meaning that actually searching for the token returns a token not found. Otherwise the token table would only every grow since we can then never throw away tokens.

@marinofaggiana

Copy link
Copy Markdown
Member

sorry but i don't understand but for the same reason when I call another endpoint with the same situation I get a 401 and not a 404. eg ocs/v2.php/apps/files_sharing/api/v1/shares

@rullzer

rullzer commented Oct 10, 2019

Copy link
Copy Markdown
Member Author

The endpoint itself it unauthenticated. We could also always return a 401 on the wipe endpoint. But the endpoint is there to ask if the device should be wiped or not. And if we don't know the token the only thing we can return is that the token is not found.

@georgehrke

Copy link
Copy Markdown
Member

It is all properly documented here: https://docs.nextcloud.com/server/17/developer_manual/client_apis/RemoteWipe/index.html#obtaining-wipe-status

Do your normal WebDAV requests. If you get a 401 or 403, call the wipe check endpoint. If that wipe check endpoint returns a status code 200 with the following body, then wipe

{
        "wipe":true
}

@marinofaggiana

Copy link
Copy Markdown
Member

@georgehrke, I make already exactly so, was only the number of response. But is not a big problem, I use the 404

@tobiasKaminsky

Copy link
Copy Markdown
Member

use the 404

No. You cannot rely on 404 here.
404 is a total different meaning, which might falsely trigger remote wipe.

As said by all the others, you have to follow exactly the API!
(If you have troubles, ping me on chat)

@marinofaggiana

Copy link
Copy Markdown
Member

which might falsely trigger remote wipe.

??? @tobiasKaminsky please ???

@tobiasKaminsky

Copy link
Copy Markdown
Member

(If you have troubles, ping me on chat)

@tobiasKaminsky

Copy link
Copy Markdown
Member

Indeed a bit confusing:
When I query an existing token (not marked as wipe), I do get 404.
But it should be 200, with value: wipe:false
or?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4. to release Ready to be released and/or waiting for tests to finish enhancement security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants