NCLoginWeb.swift 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352
  1. //
  2. // NCLoginWeb.swift
  3. // Nextcloud
  4. //
  5. // Created by Marino Faggiana on 21/08/2019.
  6. // Copyright © 2019 Marino Faggiana. All rights reserved.
  7. //
  8. // Author Marino Faggiana <marino.faggiana@nextcloud.com>
  9. //
  10. // This program is free software: you can redistribute it and/or modify
  11. // it under the terms of the GNU General Public License as published by
  12. // the Free Software Foundation, either version 3 of the License, or
  13. // (at your option) any later version.
  14. //
  15. // This program is distributed in the hope that it will be useful,
  16. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  17. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  18. // GNU General Public License for more details.
  19. //
  20. // You should have received a copy of the GNU General Public License
  21. // along with this program. If not, see <http://www.gnu.org/licenses/>.
  22. //
  23. import UIKit
  24. import WebKit
  25. import NextcloudKit
  26. import FloatingPanel
  27. class NCLoginWeb: UIViewController {
  28. var activityIndicator: UIActivityIndicatorView!
  29. var webView: WKWebView?
  30. let appDelegate = UIApplication.shared.delegate as! AppDelegate
  31. var titleView: String = ""
  32. var urlBase = ""
  33. var configServerUrl: String?
  34. var configUsername: String?
  35. var configPassword: String?
  36. var configAppPassword: String?
  37. var loginFlowV2Available = false
  38. var loginFlowV2Token = ""
  39. var loginFlowV2Endpoint = ""
  40. var loginFlowV2Login = ""
  41. // MARK: - View Life Cycle
  42. override func viewDidLoad() {
  43. super.viewDidLoad()
  44. let accountCount = NCManageDatabase.shared.getAccounts()?.count ?? 0
  45. if NCBrandOptions.shared.use_login_web_personalized && accountCount > 0 {
  46. navigationItem.leftBarButtonItem = UIBarButtonItem(barButtonSystemItem: .stop, target: self, action: #selector(self.closeView(sender:)))
  47. }
  48. if accountCount > 0 {
  49. navigationItem.rightBarButtonItem = UIBarButtonItem(image: UIImage(named: "users")!.image(color: .label, size: 35), style: .plain, target: self, action: #selector(self.changeUser(sender:)))
  50. }
  51. let config = WKWebViewConfiguration()
  52. config.websiteDataStore = WKWebsiteDataStore.nonPersistent()
  53. webView = WKWebView(frame: CGRect.zero, configuration: config)
  54. webView!.navigationDelegate = self
  55. view.addSubview(webView!)
  56. webView!.translatesAutoresizingMaskIntoConstraints = false
  57. webView!.leadingAnchor.constraint(equalTo: view.leadingAnchor, constant: 0).isActive = true
  58. webView!.rightAnchor.constraint(equalTo: view.rightAnchor, constant: 0).isActive = true
  59. webView!.topAnchor.constraint(equalTo: view.topAnchor, constant: 0).isActive = true
  60. webView!.bottomAnchor.constraint(equalTo: view.bottomAnchor, constant: 0).isActive = true
  61. activityIndicator = UIActivityIndicatorView(style: .medium)
  62. activityIndicator.center = self.view.center
  63. activityIndicator.startAnimating()
  64. self.view.addSubview(activityIndicator)
  65. // load AppConfig
  66. if let serverConfig = UserDefaults.standard.dictionary(forKey: "com.apple.configuration.managed") {
  67. if let serverUrl = serverConfig[NCGlobal.shared.configuration_serverUrl] as? String {
  68. self.configServerUrl = serverUrl
  69. }
  70. if let username = serverConfig[NCGlobal.shared.configuration_username] as? String, !username.isEmpty, username.lowercased() != "username" {
  71. self.configUsername = username
  72. }
  73. if let password = serverConfig[NCGlobal.shared.configuration_password] as? String, !password.isEmpty, password.lowercased() != "password" {
  74. self.configPassword = password
  75. }
  76. if let apppassword = serverConfig[NCGlobal.shared.configuration_apppassword] as? String, !apppassword.isEmpty, apppassword.lowercased() != "apppassword" {
  77. self.configAppPassword = apppassword
  78. }
  79. }
  80. if let serverUrl = configServerUrl {
  81. if let username = self.configUsername, let password = configAppPassword {
  82. activityIndicator.stopAnimating()
  83. createAccount(server: serverUrl, username: username, password: password)
  84. return
  85. } else if let username = self.configUsername, let password = configPassword {
  86. getAppPassword(serverUrl: serverUrl, username: username, password: password)
  87. return
  88. } else {
  89. urlBase = serverUrl
  90. }
  91. }
  92. // ADD end point for Web Flow
  93. if urlBase != NCBrandOptions.shared.linkloginPreferredProviders {
  94. if loginFlowV2Available {
  95. urlBase = loginFlowV2Login
  96. } else {
  97. urlBase += "/index.php/login/flow"
  98. }
  99. }
  100. if let url = URL(string: urlBase) {
  101. loadWebPage(webView: webView!, url: url)
  102. } else {
  103. let error = NKError(errorCode: NCGlobal.shared.errorInternalError, errorDescription: "_login_url_error_")
  104. NCContentPresenter.shared.showError(error: error, priority: .max)
  105. }
  106. // TITLE
  107. titleView = urlBase
  108. if let host = URL(string: urlBase)?.host {
  109. if let account = NCManageDatabase.shared.getActiveAccount(), CCUtility.getPassword(account.account).isEmpty {
  110. titleView = NSLocalizedString("_user_", comment: "") + " " + account.userId + " " + NSLocalizedString("_in_", comment: "") + " " + host
  111. }
  112. }
  113. self.title = titleView
  114. }
  115. override func viewDidAppear(_ animated: Bool) {
  116. super.viewDidAppear(animated)
  117. // Stop timer error network
  118. appDelegate.timerErrorNetworking?.invalidate()
  119. // ITMS-90076: Potential Loss of Keychain Access
  120. if appDelegate.errorITMS90076, !CCUtility.getPresentErrorITMS90076() {
  121. let message = "\n" + NSLocalizedString("_ITMS-90076_", comment: "")
  122. let alertController = UIAlertController(title: titleView, message: message, preferredStyle: .alert)
  123. alertController.addAction(UIAlertAction(title: NSLocalizedString("_ok_", comment: ""), style: .default, handler: { _ in }))
  124. present(alertController, animated: true, completion: {
  125. CCUtility.setPresentErrorITMS90076(true)
  126. })
  127. } else if let account = NCManageDatabase.shared.getActiveAccount(), CCUtility.getPassword(account.account).isEmpty {
  128. let message = "\n" + NSLocalizedString("_password_not_present_", comment: "")
  129. let alertController = UIAlertController(title: titleView, message: message, preferredStyle: .alert)
  130. alertController.addAction(UIAlertAction(title: NSLocalizedString("_ok_", comment: ""), style: .default, handler: { _ in }))
  131. present(alertController, animated: true)
  132. }
  133. }
  134. override func viewDidDisappear(_ animated: Bool) {
  135. super.viewDidDisappear(animated)
  136. // Start timer error network
  137. appDelegate.startTimerErrorNetworking()
  138. }
  139. func loadWebPage(webView: WKWebView, url: URL) {
  140. let language = NSLocale.preferredLanguages[0] as String
  141. var request = URLRequest(url: url)
  142. if let deviceName = "\(UIDevice.current.name) (\(NCBrandOptions.shared.brand) iOS)".cString(using: .utf8),
  143. let deviceUserAgent = String(cString: deviceName, encoding: .ascii) {
  144. webView.customUserAgent = deviceUserAgent
  145. } else {
  146. webView.customUserAgent = CCUtility.getUserAgent()
  147. }
  148. request.addValue("true", forHTTPHeaderField: "OCS-APIRequest")
  149. request.addValue(language, forHTTPHeaderField: "Accept-Language")
  150. webView.load(request)
  151. }
  152. func getAppPassword(serverUrl: String, username: String, password: String) {
  153. NextcloudKit.shared.getAppPassword(serverUrl: serverUrl, username: username, password: password) { token, data, error in
  154. self.activityIndicator.stopAnimating()
  155. if error == .success, let password = token {
  156. self.createAccount(server: serverUrl, username: username, password: password)
  157. } else {
  158. NCContentPresenter.shared.showError(error: error)
  159. self.dismiss(animated: true, completion: nil)
  160. }
  161. }
  162. }
  163. @objc func closeView(sender: UIBarButtonItem) {
  164. self.dismiss(animated: true, completion: nil)
  165. }
  166. @objc func changeUser(sender: UIBarButtonItem) {
  167. toggleMenu()
  168. }
  169. }
  170. extension NCLoginWeb: WKNavigationDelegate {
  171. func webView(_ webView: WKWebView, didReceiveServerRedirectForProvisionalNavigation navigation: WKNavigation!) {
  172. guard let url = webView.url else { return }
  173. let urlString: String = url.absoluteString.lowercased()
  174. // prevent http redirection
  175. if urlBase.lowercased().hasPrefix("https://") && urlString.lowercased().hasPrefix("http://") {
  176. let alertController = UIAlertController(title: NSLocalizedString("_error_", comment: ""), message: NSLocalizedString("_prevent_http_redirection_", comment: ""), preferredStyle: .alert)
  177. alertController.addAction(UIAlertAction(title: NSLocalizedString("_ok_", comment: ""), style: .default, handler: { _ in
  178. _ = self.navigationController?.popViewController(animated: true)
  179. }))
  180. self.present(alertController, animated: true)
  181. return
  182. }
  183. if urlString.hasPrefix(NCBrandOptions.shared.webLoginAutenticationProtocol) == true && urlString.contains("login") == true {
  184. var server: String = ""
  185. var user: String = ""
  186. var password: String = ""
  187. let keyValue = url.path.components(separatedBy: "&")
  188. for value in keyValue {
  189. if value.contains("server:") { server = value }
  190. if value.contains("user:") { user = value }
  191. if value.contains("password:") { password = value }
  192. }
  193. if server != "" && user != "" && password != "" {
  194. let server: String = server.replacingOccurrences(of: "/server:", with: "")
  195. let username: String = user.replacingOccurrences(of: "user:", with: "").replacingOccurrences(of: "+", with: " ")
  196. let password: String = password.replacingOccurrences(of: "password:", with: "")
  197. createAccount(server: server, username: username, password: password)
  198. }
  199. }
  200. }
  201. func webView(_ webView: WKWebView, didFailProvisionalNavigation navigation: WKNavigation!, withError error: Error) {
  202. var errorMessage = error.localizedDescription
  203. for (key, value) in (error as NSError).userInfo {
  204. let message = "\(key) \(value)\n"
  205. errorMessage += message
  206. }
  207. let alertController = UIAlertController(title: NSLocalizedString("_error_", comment: ""), message: errorMessage, preferredStyle: .alert)
  208. alertController.addAction(UIAlertAction(title: NSLocalizedString("_ok_", comment: ""), style: .default, handler: { _ in }))
  209. self.present(alertController, animated: true)
  210. }
  211. func webView(_ webView: WKWebView, didReceive challenge: URLAuthenticationChallenge, completionHandler: @escaping (URLSession.AuthChallengeDisposition, URLCredential?) -> Void) {
  212. if let serverTrust = challenge.protectionSpace.serverTrust {
  213. completionHandler(Foundation.URLSession.AuthChallengeDisposition.useCredential, URLCredential(trust: serverTrust))
  214. } else {
  215. completionHandler(URLSession.AuthChallengeDisposition.useCredential, nil)
  216. }
  217. }
  218. func webView(_ webView: WKWebView, decidePolicyFor navigationAction: WKNavigationAction, decisionHandler: @escaping (WKNavigationActionPolicy) -> Void) {
  219. decisionHandler(.allow)
  220. }
  221. func webView(_ webView: WKWebView, didStartProvisionalNavigation navigation: WKNavigation!) {
  222. print("didStartProvisionalNavigation")
  223. }
  224. func webView(_ webView: WKWebView, didFinish navigation: WKNavigation!) {
  225. activityIndicator.stopAnimating()
  226. print("didFinishProvisionalNavigation")
  227. if loginFlowV2Available {
  228. DispatchQueue.main.asyncAfter(deadline: .now() + 1) {
  229. NextcloudKit.shared.getLoginFlowV2Poll(token: self.loginFlowV2Token, endpoint: self.loginFlowV2Endpoint) { server, loginName, appPassword, data, error in
  230. if error == .success && server != nil && loginName != nil && appPassword != nil {
  231. self.createAccount(server: server!, username: loginName!, password: appPassword!)
  232. }
  233. }
  234. }
  235. }
  236. }
  237. // MARK: -
  238. func createAccount(server: String, username: String, password: String) {
  239. var urlBase = server
  240. // Normalized
  241. if urlBase.last == "/" {
  242. urlBase = String(urlBase.dropLast())
  243. }
  244. // Create account
  245. let account: String = "\(username) \(urlBase)"
  246. // NO account found, clear all
  247. if NCManageDatabase.shared.getAccounts() == nil {
  248. NCUtility.shared.removeAllSettings()
  249. }
  250. // Add new account
  251. NCManageDatabase.shared.deleteAccount(account)
  252. NCManageDatabase.shared.addAccount(account, urlBase: urlBase, user: username, password: password)
  253. guard let tableAccount = NCManageDatabase.shared.setAccountActive(account) else {
  254. self.dismiss(animated: true, completion: nil)
  255. return
  256. }
  257. appDelegate.settingAccount(account, urlBase: urlBase, user: username, userId: tableAccount.userId, password: password)
  258. if CCUtility.getIntro() {
  259. NotificationCenter.default.postOnMainThread(name: NCGlobal.shared.notificationCenterInitialize)
  260. self.dismiss(animated: true)
  261. } else {
  262. CCUtility.setIntro(true)
  263. if self.presentingViewController == nil {
  264. if let viewController = UIStoryboard(name: "Main", bundle: nil).instantiateInitialViewController() {
  265. viewController.modalPresentationStyle = .fullScreen
  266. NotificationCenter.default.postOnMainThread(name: NCGlobal.shared.notificationCenterInitialize)
  267. viewController.view.alpha = 0
  268. appDelegate.window?.rootViewController = viewController
  269. appDelegate.window?.makeKeyAndVisible()
  270. UIView.animate(withDuration: 0.5) {
  271. viewController.view.alpha = 1
  272. }
  273. }
  274. } else {
  275. NotificationCenter.default.postOnMainThread(name: NCGlobal.shared.notificationCenterInitialize)
  276. self.dismiss(animated: true)
  277. }
  278. }
  279. }
  280. }