bitwarden-estensione-browser/src/services/api.service.ts

489 lines
20 KiB
TypeScript
Raw Normal View History

2018-06-13 20:08:43 +02:00
import { DeviceType } from '../enums/deviceType';
2018-01-09 22:19:55 +01:00
import { ApiService as ApiServiceAbstraction } from '../abstractions/api.service';
import { PlatformUtilsService } from '../abstractions/platformUtils.service';
import { TokenService } from '../abstractions/token.service';
import { EnvironmentUrls } from '../models/domain/environmentUrls';
2018-06-12 23:12:27 +02:00
import { CipherBulkDeleteRequest } from '../models/request/cipherBulkDeleteRequest';
import { CipherBulkMoveRequest } from '../models/request/cipherBulkMoveRequest';
2018-06-13 06:02:15 +02:00
import { CipherBulkShareRequest } from '../models/request/cipherBulkShareRequest';
2018-06-12 19:07:06 +02:00
import { CipherCollectionsRequest } from '../models/request/cipherCollectionsRequest';
import { CipherRequest } from '../models/request/cipherRequest';
2018-06-12 17:45:02 +02:00
import { CipherShareRequest } from '../models/request/cipherShareRequest';
import { EmailRequest } from '../models/request/emailRequest';
import { EmailTokenRequest } from '../models/request/emailTokenRequest';
import { FolderRequest } from '../models/request/folderRequest';
2018-06-23 21:41:22 +02:00
import { ImportCiphersRequest } from '../models/request/importCiphersRequest';
import { ImportDirectoryRequest } from '../models/request/importDirectoryRequest';
2018-06-23 21:41:22 +02:00
import { ImportOrganizationCiphersRequest } from '../models/request/importOrganizationCiphersRequest';
import { PasswordHintRequest } from '../models/request/passwordHintRequest';
import { PasswordRequest } from '../models/request/passwordRequest';
2018-06-21 23:15:43 +02:00
import { PasswordVerificationRequest } from '../models/request/passwordVerificationRequest';
import { RegisterRequest } from '../models/request/registerRequest';
import { TokenRequest } from '../models/request/tokenRequest';
import { TwoFactorEmailRequest } from '../models/request/twoFactorEmailRequest';
2018-06-26 21:17:14 +02:00
import { TwoFactorProviderRequest } from '../models/request/twoFactorProviderRequest';
import { TwoFactorRecoveryRequest } from '../models/request/twoFactorRecoveryRequest';
2018-06-26 05:04:59 +02:00
import { UpdateDomainsRequest } from '../models/request/updateDomainsRequest';
2018-06-21 05:40:59 +02:00
import { UpdateProfileRequest } from '../models/request/updateProfileRequest';
2018-06-26 21:17:14 +02:00
import { UpdateTwoFactorAuthenticatorRequest } from '../models/request/updateTwoFactorAuthenticatorRequest';
import { UpdateTwoFactorDuoRequest } from '../models/request/updateTwoFactorDuoRequest';
import { UpdateTwoFactorEmailRequest } from '../models/request/updateTwoFactorEmailRequest';
import { UpdateTwoFactorU2fRequest } from '../models/request/updateTwoFactorU2fRequest';
import { UpdateTwoFactorYubioOtpRequest } from '../models/request/updateTwoFactorYubioOtpRequest';
import { CipherResponse } from '../models/response/cipherResponse';
2018-06-26 05:04:59 +02:00
import { DomainsResponse } from '../models/response/domainsResponse';
import { ErrorResponse } from '../models/response/errorResponse';
import { FolderResponse } from '../models/response/folderResponse';
import { IdentityTokenResponse } from '../models/response/identityTokenResponse';
import { IdentityTwoFactorResponse } from '../models/response/identityTwoFactorResponse';
2018-06-26 21:17:14 +02:00
import { ListResponse } from '../models/response/listResponse';
2018-05-03 18:46:49 +02:00
import { ProfileResponse } from '../models/response/profileResponse';
import { SyncResponse } from '../models/response/syncResponse';
2018-06-26 21:17:14 +02:00
import { TwoFactorAuthenticatorResponse } from '../models/response/twoFactorAuthenticatorResponse';
import { TwoFactorDuoResponse } from '../models/response/twoFactorDuoResponse';
import { TwoFactorEmailResponse } from '../models/response/twoFactorEmailResponse';
import { TwoFactorProviderResponse } from '../models/response/twoFactorProviderResponse';
import { TwoFactorRecoverResponse } from '../models/response/twoFactorRescoverResponse';
import { TwoFactorU2fResponse } from '../models/response/twoFactorU2fResponse';
import { TwoFactorYubiKeyResponse } from '../models/response/twoFactorYubiKeyResponse';
2018-01-09 22:19:55 +01:00
2018-01-31 20:27:11 +01:00
export class ApiService implements ApiServiceAbstraction {
2018-01-09 22:19:55 +01:00
urlsSet: boolean = false;
2018-06-14 04:12:23 +02:00
apiBaseUrl: string;
identityBaseUrl: string;
2018-06-14 04:09:47 +02:00
private deviceType: string;
private isWebClient = false;
private isDesktopClient = false;
2018-06-14 04:09:47 +02:00
private usingBaseUrl = false;
2018-01-09 22:19:55 +01:00
2018-03-21 16:19:05 +01:00
constructor(private tokenService: TokenService, private platformUtilsService: PlatformUtilsService,
2018-05-16 05:40:15 +02:00
private logoutCallback: (expired: boolean) => Promise<void>) {
2018-06-13 20:08:43 +02:00
const device = platformUtilsService.getDevice();
this.deviceType = device.toString();
this.isWebClient = device === DeviceType.Web;
this.isDesktopClient = device === DeviceType.Windows || device === DeviceType.MacOs ||
device === DeviceType.Linux;
2018-01-09 22:19:55 +01:00
}
2018-01-09 22:23:27 +01:00
setUrls(urls: EnvironmentUrls): void {
2018-01-09 22:19:55 +01:00
this.urlsSet = true;
if (urls.base != null) {
2018-06-05 21:45:19 +02:00
this.usingBaseUrl = true;
2018-06-14 04:09:47 +02:00
this.apiBaseUrl = urls.base + '/api';
2018-01-09 22:19:55 +01:00
this.identityBaseUrl = urls.base + '/identity';
return;
}
if (urls.api != null && urls.identity != null) {
2018-06-14 04:09:47 +02:00
this.apiBaseUrl = urls.api;
2018-01-09 22:19:55 +01:00
this.identityBaseUrl = urls.identity;
return;
}
/* tslint:disable */
2018-06-22 04:12:26 +02:00
// Local Dev
2018-06-14 04:09:47 +02:00
//this.apiBaseUrl = 'http://localhost:4000';
//this.identityBaseUrl = 'http://localhost:33656';
2018-01-09 22:19:55 +01:00
// Production
2018-06-22 04:12:26 +02:00
this.apiBaseUrl = 'https://api.bitwarden.com';
this.identityBaseUrl = 'https://identity.bitwarden.com';
2018-01-09 22:19:55 +01:00
/* tslint:enable */
}
// Auth APIs
2018-02-02 04:55:49 +01:00
async postIdentityToken(request: TokenRequest): Promise<IdentityTokenResponse | IdentityTwoFactorResponse> {
2018-01-09 22:19:55 +01:00
const response = await fetch(new Request(this.identityBaseUrl + '/connect/token', {
2018-03-21 16:19:05 +01:00
body: this.qsStringify(request.toIdentityToken(this.platformUtilsService.identityClientId)),
2018-06-05 21:45:19 +02:00
credentials: this.getCredentials(),
2018-01-09 22:19:55 +01:00
cache: 'no-cache',
headers: new Headers({
'Content-Type': 'application/x-www-form-urlencoded; charset=utf-8',
'Accept': 'application/json',
'Device-Type': this.deviceType,
}),
method: 'POST',
}));
let responseJson: any = null;
const typeHeader = response.headers.get('content-type');
if (typeHeader != null && typeHeader.indexOf('application/json') > -1) {
responseJson = await response.json();
}
if (responseJson != null) {
if (response.status === 200) {
return new IdentityTokenResponse(responseJson);
} else if (response.status === 400 && responseJson.TwoFactorProviders2 &&
Object.keys(responseJson.TwoFactorProviders2).length) {
await this.tokenService.clearTwoFactorToken(request.email);
2018-02-02 04:55:49 +01:00
return new IdentityTwoFactorResponse(responseJson);
2018-01-09 22:19:55 +01:00
}
}
return Promise.reject(new ErrorResponse(responseJson, response.status, true));
}
async refreshIdentityToken(): Promise<any> {
try {
await this.doRefreshToken();
} catch (e) {
return Promise.reject(null);
}
}
// Two Factor APIs
2018-06-26 04:42:57 +02:00
postTwoFactorEmail(request: TwoFactorEmailRequest): Promise<any> {
return this.send('POST', '/two-factor/send-email-login', request, false, false);
2018-01-09 22:19:55 +01:00
}
// Account APIs
2018-05-03 18:46:49 +02:00
async getProfile(): Promise<ProfileResponse> {
2018-06-26 04:42:57 +02:00
const r = await this.send('GET', '/accounts/profile', null, true, true);
return new ProfileResponse(r);
2018-05-03 18:46:49 +02:00
}
2018-06-21 05:40:59 +02:00
async putProfile(request: UpdateProfileRequest): Promise<ProfileResponse> {
2018-06-26 04:42:57 +02:00
const r = await this.send('PUT', '/accounts/profile', request, true, true);
return new ProfileResponse(r);
2018-06-21 05:40:59 +02:00
}
2018-06-26 04:42:57 +02:00
postEmailToken(request: EmailTokenRequest): Promise<any> {
return this.send('POST', '/accounts/email-token', request, true, false);
}
2018-06-26 04:42:57 +02:00
postEmail(request: EmailRequest): Promise<any> {
return this.send('POST', '/accounts/email', request, true, false);
}
2018-06-26 04:42:57 +02:00
postPassword(request: PasswordRequest): Promise<any> {
return this.send('POST', '/accounts/password', request, true, false);
}
2018-06-26 04:42:57 +02:00
postSecurityStamp(request: PasswordVerificationRequest): Promise<any> {
return this.send('POST', '/accounts/security-stamp', request, true, false);
2018-06-21 23:15:43 +02:00
}
2018-06-26 04:42:57 +02:00
postDeleteAccount(request: PasswordVerificationRequest): Promise<any> {
return this.send('POST', '/accounts/delete', request, true, false);
2018-06-21 23:15:43 +02:00
}
2018-01-09 22:19:55 +01:00
async getAccountRevisionDate(): Promise<number> {
2018-06-26 04:42:57 +02:00
const r = await this.send('GET', '/accounts/revision-date', null, true, true);
return r as number;
2018-01-09 22:19:55 +01:00
}
2018-06-26 04:42:57 +02:00
postPasswordHint(request: PasswordHintRequest): Promise<any> {
return this.send('POST', '/accounts/password-hint', request, false, false);
2018-01-09 22:19:55 +01:00
}
2018-06-26 04:42:57 +02:00
postRegister(request: RegisterRequest): Promise<any> {
return this.send('POST', '/accounts/register', request, false, false);
2018-01-09 22:19:55 +01:00
}
// Folder APIs
async postFolder(request: FolderRequest): Promise<FolderResponse> {
2018-06-26 04:42:57 +02:00
const r = await this.send('POST', '/folders', request, true, true);
return new FolderResponse(r);
2018-01-09 22:19:55 +01:00
}
async putFolder(id: string, request: FolderRequest): Promise<FolderResponse> {
2018-06-26 04:42:57 +02:00
const r = await this.send('PUT', '/folders/' + id, request, true, true);
return new FolderResponse(r);
2018-01-09 22:19:55 +01:00
}
2018-06-26 04:42:57 +02:00
deleteFolder(id: string): Promise<any> {
return this.send('DELETE', '/folders/' + id, null, true, false);
2018-01-09 22:19:55 +01:00
}
// Cipher APIs
async postCipher(request: CipherRequest): Promise<CipherResponse> {
2018-06-26 04:42:57 +02:00
const r = await this.send('POST', '/ciphers', request, true, true);
return new CipherResponse(r);
2018-01-09 22:19:55 +01:00
}
async putCipher(id: string, request: CipherRequest): Promise<CipherResponse> {
2018-06-26 04:42:57 +02:00
const r = await this.send('PUT', '/ciphers/' + id, request, true, true);
return new CipherResponse(r);
2018-01-09 22:19:55 +01:00
}
2018-06-26 04:42:57 +02:00
deleteCipher(id: string): Promise<any> {
return this.send('DELETE', '/ciphers/' + id, null, true, false);
2018-06-12 19:07:06 +02:00
}
2018-06-26 04:42:57 +02:00
deleteManyCiphers(request: CipherBulkDeleteRequest): Promise<any> {
return this.send('DELETE', '/ciphers', request, true, false);
2018-06-12 23:12:27 +02:00
}
2018-06-26 04:42:57 +02:00
putMoveCiphers(request: CipherBulkMoveRequest): Promise<any> {
return this.send('PUT', '/ciphers/move', request, true, false);
2018-06-12 23:12:27 +02:00
}
2018-06-26 04:42:57 +02:00
putShareCipher(id: string, request: CipherShareRequest): Promise<any> {
return this.send('PUT', '/ciphers/' + id + '/share', request, true, false);
2018-06-13 06:02:15 +02:00
}
2018-06-26 04:42:57 +02:00
putShareCiphers(request: CipherBulkShareRequest): Promise<any> {
return this.send('PUT', '/ciphers/share', request, true, false);
2018-06-12 17:45:02 +02:00
}
2018-06-26 04:42:57 +02:00
putCipherCollections(id: string, request: CipherCollectionsRequest): Promise<any> {
return this.send('PUT', '/ciphers/' + id + '/collections', request, true, false);
2018-01-09 22:19:55 +01:00
}
2018-06-26 04:42:57 +02:00
postPurgeCiphers(request: PasswordVerificationRequest): Promise<any> {
return this.send('POST', '/ciphers/purge', request, true, false);
2018-06-23 21:41:22 +02:00
}
2018-06-26 04:42:57 +02:00
postImportCiphers(request: ImportCiphersRequest): Promise<any> {
return this.send('POST', '/ciphers/import', request, true, false);
2018-06-23 21:41:22 +02:00
}
2018-06-26 04:42:57 +02:00
postImportOrganizationCiphers(request: ImportOrganizationCiphersRequest): Promise<any> {
return this.send('POST', '/ciphers/import-organization', request, true, false);
2018-06-21 23:15:43 +02:00
}
2018-01-09 22:19:55 +01:00
// Attachments APIs
async postCipherAttachment(id: string, data: FormData): Promise<CipherResponse> {
2018-06-26 04:42:57 +02:00
const r = await this.send('POST', '/ciphers/' + id + '/attachment', data, true, true);
return new CipherResponse(r);
2018-06-12 17:45:02 +02:00
}
2018-06-26 04:42:57 +02:00
deleteCipherAttachment(id: string, attachmentId: string): Promise<any> {
return this.send('DELETE', '/ciphers/' + id + '/attachment/' + attachmentId, null, true, false);
2018-06-12 19:07:06 +02:00
}
2018-06-26 04:42:57 +02:00
postShareCipherAttachment(id: string, attachmentId: string, data: FormData,
2018-06-12 17:45:02 +02:00
organizationId: string): Promise<any> {
2018-06-26 04:42:57 +02:00
return this.send('POST', '/ciphers/' + id + '/attachment/' +
attachmentId + '/share?organizationId=' + organizationId, data, true, false);
2018-01-09 22:19:55 +01:00
}
// Sync APIs
async getSync(): Promise<SyncResponse> {
const path = this.isDesktopClient || this.isWebClient ? '/sync?excludeDomains=true' : '/sync';
const r = await this.send('GET', path, null, true, true);
2018-06-26 04:42:57 +02:00
return new SyncResponse(r);
2018-01-09 22:19:55 +01:00
}
async postImportDirectory(organizationId: string, request: ImportDirectoryRequest): Promise<any> {
2018-06-26 04:42:57 +02:00
return this.send('POST', '/organizations/' + organizationId + '/import', request, true, false);
}
2018-06-26 05:04:59 +02:00
// Settings
async getSettingsDomains(): Promise<DomainsResponse> {
const r = await this.send('GET', '/settings/domains', null, true, true);
return new DomainsResponse(r);
}
async putSettingsDomains(request: UpdateDomainsRequest): Promise<DomainsResponse> {
const r = await this.send('PUT', '/settings/domains', request, true, true);
return new DomainsResponse(r);
}
2018-06-26 21:17:14 +02:00
// Two-factor
async getTwoFactorProviders(): Promise<ListResponse<TwoFactorProviderResponse>> {
const r = await this.send('GET', '/two-factor', null, true, true);
return new ListResponse(r, TwoFactorProviderResponse);
}
async getTwoFactorAuthenticator(request: PasswordVerificationRequest): Promise<TwoFactorAuthenticatorResponse> {
const r = await this.send('POST', '/two-factor/get-authenticator', request, true, true);
return new TwoFactorAuthenticatorResponse(r);
}
async getTwoFactorEmail(request: PasswordVerificationRequest): Promise<TwoFactorEmailResponse> {
const r = await this.send('POST', '/two-factor/get-email', request, true, true);
return new TwoFactorEmailResponse(r);
}
async getTwoFactorDuo(request: PasswordVerificationRequest): Promise<TwoFactorDuoResponse> {
const r = await this.send('POST', '/two-factor/get-duo', request, true, true);
return new TwoFactorDuoResponse(r);
}
async getTwoFactorYubiKey(request: PasswordVerificationRequest): Promise<TwoFactorYubiKeyResponse> {
const r = await this.send('POST', '/two-factor/get-yubikey', request, true, true);
return new TwoFactorYubiKeyResponse(r);
}
async getTwoFactorU2f(request: PasswordVerificationRequest): Promise<TwoFactorU2fResponse> {
const r = await this.send('POST', '/two-factor/get-u2f', request, true, true);
return new TwoFactorU2fResponse(r);
}
async getTwoFactorRecover(request: PasswordVerificationRequest): Promise<TwoFactorRecoverResponse> {
const r = await this.send('POST', '/two-factor/get-recover', request, true, true);
return new TwoFactorRecoverResponse(r);
}
async putTwoFactorAuthenticator(
request: UpdateTwoFactorAuthenticatorRequest): Promise<TwoFactorAuthenticatorResponse> {
const r = await this.send('PUT', '/two-factor/authenticator', request, true, true);
return new TwoFactorAuthenticatorResponse(r);
}
async putTwoFactorEmail(request: UpdateTwoFactorEmailRequest): Promise<TwoFactorEmailResponse> {
const r = await this.send('PUT', '/two-factor/email', request, true, true);
return new TwoFactorEmailResponse(r);
}
async putTwoFactorDuo(request: UpdateTwoFactorDuoRequest): Promise<TwoFactorDuoResponse> {
const r = await this.send('PUT', '/two-factor/duo', request, true, true);
return new TwoFactorDuoResponse(r);
}
async putTwoFactorYubiKey(request: UpdateTwoFactorYubioOtpRequest): Promise<TwoFactorYubiKeyResponse> {
const r = await this.send('PUT', '/two-factor/yubikey', request, true, true);
return new TwoFactorYubiKeyResponse(r);
}
async putTwoFactorU2f(request: UpdateTwoFactorU2fRequest): Promise<TwoFactorU2fResponse> {
const r = await this.send('PUT', '/two-factor/u2f', request, true, true);
return new TwoFactorU2fResponse(r);
}
async putTwoFactorDisable(request: TwoFactorProviderRequest): Promise<TwoFactorProviderResponse> {
const r = await this.send('PUT', '/two-factor/disable', request, true, true);
return new TwoFactorProviderResponse(r);
}
postTwoFactorRecover(request: TwoFactorRecoveryRequest): Promise<any> {
return this.send('POST', '/two-factor/recover', request, false, false);
}
2018-06-26 04:42:57 +02:00
// Helpers
private async send(method: 'GET' | 'POST' | 'PUT' | 'DELETE', path: string, body: any,
authed: boolean, hasResponse: boolean): Promise<any> {
const headers = new Headers({
'Device-Type': this.deviceType,
});
const requestInit: RequestInit = {
cache: 'no-cache',
2018-06-05 21:45:19 +02:00
credentials: this.getCredentials(),
2018-06-26 04:42:57 +02:00
method: method,
};
if (authed) {
const authHeader = await this.handleTokenState();
headers.set('Authorization', authHeader);
}
if (body != null) {
if (typeof body === 'string') {
requestInit.body = body;
headers.set('Content-Type', 'application/x-www-form-urlencoded; charset=utf-8');
} else if (typeof body === 'object') {
if (body instanceof FormData) {
requestInit.body = body;
} else {
headers.set('Content-Type', 'application/json; charset=utf-8');
requestInit.body = JSON.stringify(body);
}
}
}
if (hasResponse) {
headers.set('Accept', 'application/json');
}
requestInit.headers = headers;
const response = await fetch(new Request(this.apiBaseUrl + path, requestInit));
2018-06-26 04:42:57 +02:00
if (hasResponse && response.status === 200) {
const responseJson = await response.json();
return responseJson;
} else if (response.status !== 200) {
const error = await this.handleError(response, false);
return Promise.reject(error);
}
}
2018-01-09 22:19:55 +01:00
private async handleError(response: Response, tokenError: boolean): Promise<ErrorResponse> {
if ((tokenError && response.status === 400) || response.status === 401 || response.status === 403) {
2018-05-16 05:40:15 +02:00
await this.logoutCallback(true);
2018-01-09 22:19:55 +01:00
return null;
}
let responseJson: any = null;
const typeHeader = response.headers.get('content-type');
if (typeHeader != null && typeHeader.indexOf('application/json') > -1) {
responseJson = await response.json();
}
return new ErrorResponse(responseJson, response.status, tokenError);
}
private async handleTokenState(): Promise<string> {
2018-05-15 05:56:27 +02:00
let accessToken = await this.tokenService.getToken();
2018-01-09 22:19:55 +01:00
if (this.tokenService.tokenNeedsRefresh()) {
const tokenResponse = await this.doRefreshToken();
accessToken = tokenResponse.accessToken;
}
return 'Bearer ' + accessToken;
}
private async doRefreshToken(): Promise<IdentityTokenResponse> {
const refreshToken = await this.tokenService.getRefreshToken();
if (refreshToken == null || refreshToken === '') {
throw new Error();
}
2018-03-29 03:54:21 +02:00
const decodedToken = this.tokenService.decodeToken();
2018-01-09 22:19:55 +01:00
const response = await fetch(new Request(this.identityBaseUrl + '/connect/token', {
body: this.qsStringify({
grant_type: 'refresh_token',
2018-03-29 03:54:21 +02:00
client_id: decodedToken.client_id,
2018-01-09 22:19:55 +01:00
refresh_token: refreshToken,
}),
cache: 'no-cache',
2018-06-05 21:45:19 +02:00
credentials: this.getCredentials(),
2018-01-09 22:19:55 +01:00
headers: new Headers({
'Content-Type': 'application/x-www-form-urlencoded; charset=utf-8',
'Accept': 'application/json',
'Device-Type': this.deviceType,
}),
method: 'POST',
}));
if (response.status === 200) {
const responseJson = await response.json();
const tokenResponse = new IdentityTokenResponse(responseJson);
await this.tokenService.setTokens(tokenResponse.accessToken, tokenResponse.refreshToken);
return tokenResponse;
} else {
const error = await this.handleError(response, true);
return Promise.reject(error);
}
}
private qsStringify(params: any): string {
return Object.keys(params).map((key) => {
return encodeURIComponent(key) + '=' + encodeURIComponent(params[key]);
}).join('&');
}
2018-06-05 21:45:19 +02:00
private getCredentials(): RequestCredentials {
if (!this.isWebClient || this.usingBaseUrl) {
return 'include';
}
return undefined;
}
2018-01-09 22:19:55 +01:00
}