Web API for the bulk printing desktop application.

Client.cs 21KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518
  1. using ExtensionMethods;
  2. using MAX.Models;
  3. using Microsoft.Extensions.Logging;
  4. using System;
  5. using System.Net.Sockets;
  6. using System.Security.Cryptography;
  7. using System.Text;
  8. using System.Threading;
  9. using System.Threading.Tasks;
  10. using System.Xml;
  11. namespace MAX
  12. {
  13. public class Client : IDisposable
  14. {
  15. private ILogger _logger;
  16. private string _host;
  17. private int _port;
  18. private int _vendorId;
  19. private string _serialNumber;
  20. private int _userId;
  21. private string _username;
  22. private string _password;
  23. private bool _logResponses;
  24. private TcpClient _connection = null;
  25. private NetworkStream _connectionStream = null;
  26. private TripleDES _des = null;
  27. private bool _disposed = false;
  28. public Client(ILogger logger, bool logResponses, string host, int port, int vendorId, string serialNumber, int userId, string username, string password)
  29. {
  30. _logger = logger;
  31. _host = host;
  32. _port = port;
  33. _vendorId = vendorId;
  34. _serialNumber = serialNumber;
  35. _userId = userId;
  36. _username = username;
  37. _password = password;
  38. _logResponses = logResponses;
  39. ConnectTimeout = 10000;
  40. ReceiveTimeout = 10000;
  41. SendTimeout = 10000;
  42. }
  43. public Client(ILogger logger, bool logResponses, string host, int port, LoginCredentials credentials)
  44. : this(logger, logResponses, host, port, credentials.Vendor.Id, credentials.Vendor.SerialNumber,
  45. credentials.User.Id, credentials.User.Username, credentials.Password)
  46. {
  47. }
  48. public void Close()
  49. {
  50. Dispose(true);
  51. }
  52. public async Task<User> ConnectAsync()
  53. {
  54. if (_connection != null)
  55. throw new Exception("Already connected");
  56. _connection = new TcpClient(AddressFamily.InterNetwork);
  57. _connection.ReceiveTimeout = ReceiveTimeout;
  58. _connection.SendTimeout = SendTimeout;
  59. // Connect to the server
  60. try
  61. {
  62. using (var cancellationSource = new CancellationTokenSource(ConnectTimeout))
  63. {
  64. await _connection.ConnectAsync(_host, _port).WithCancellation(cancellationSource.Token).ConfigureAwait(false);
  65. }
  66. }
  67. catch (OperationCanceledException)
  68. {
  69. throw new Exception("Connect timeout");
  70. }
  71. _connectionStream = _connection.GetStream();
  72. // Device authentication
  73. await WriteMessageAsync(new MessageBuilder()
  74. .Append("Hi ")
  75. .Append(_serialNumber)
  76. .Append("|V")
  77. .Append(_vendorId)
  78. .Append("|123451234512345||||||")).ConfigureAwait(false);
  79. var response = ExpectResponse(await ReadMessageAsync().ConfigureAwait(false), "Hi");
  80. // Request server RSA key
  81. //
  82. // WARNING:
  83. //
  84. // The protocol does not do any form of server authentication so this step is
  85. // trivially vulnerable to a man-in-the-middle attack where an intermediary
  86. // intercepts this request and sends their own RSA key while keeping the server RSA
  87. // key to themselves.
  88. await WriteMessageAsync(new MessageBuilder().Append("PK")).ConfigureAwait(false);
  89. response = await ReadMessageAsync().ConfigureAwait(false);
  90. // Key exchange
  91. _des = TripleDES.Create();
  92. _des.IV = new byte[8];
  93. await WriteMessageAsync(new MessageBuilder()
  94. .Append("3D ")
  95. .Append(EncryptRSA(response, BitConverter.ToString(_des.Key).Replace("-", "")))).ConfigureAwait(false);
  96. response = ExpectResponse(await ReadMessageAsync().ConfigureAwait(false), "OK");
  97. // User authentication
  98. await WriteMessageAsync(new MessageBuilder()
  99. .Append("User ")
  100. .Append(Encrypt(new StringBuilder()
  101. .Append(_userId)
  102. .Append("|")
  103. .Append(_username)
  104. .Append("|")
  105. .Append(_password).ToString()))).ConfigureAwait(false);
  106. response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  107. var parts = response.Split('|');
  108. var user = new User()
  109. {
  110. Id = _userId,
  111. Username = _username,
  112. FirstName = parts[4],
  113. Surname = parts[3],
  114. Enabled = ParseBool(parts[6], "User.Enabled(6)", response),
  115. Level = (User.UserLevel)ParseInt(parts[1], "User.Level(1)", response),
  116. System = ParseInt(parts[2], "User.System(2)", response),
  117. LastLogin = ParseDateTime(parts[5], "User.LastLogin(5)", response)
  118. };
  119. if (user.Level == User.UserLevel.CustomUser)
  120. {
  121. user.CanPrintOffline = ParseBool(parts[7], "User.CanPrintOffline(7)", response);
  122. user.OfflinePrintValue = ParseDecimal(parts[8], "User.OfflinePrintValue(8)", response);
  123. user.CanPrintOnline = ParseBool(parts[9], "User.CanPrintOnline(9)", response);
  124. user.OnlinePrintValue = ParseDecimal(parts[10], "User.OnlinePrintValue(10)", response);
  125. user.CanReprintOffline = ParseBool(parts[11], "User.CanReprintOffline(11)", response);
  126. user.OfflineReprintValue = ParseDecimal(parts[12], "User.OfflineReprintValue(12)", response);
  127. user.CanReprintOnline = ParseBool(parts[13], "User.CanReprintOnline(13)", response);
  128. user.OnlineReprintValue = ParseDecimal(parts[14], "User.OnlineReprintValue(14)", response);
  129. user.BulkExport = ParseBool(parts[15], "User.BulkExport(15)", response);
  130. user.BulkExportMaxValue = ParseDecimal(parts[16], "User.BulkExportMaxValue(16)", response);
  131. user.BulkOrder = ParseBool(parts[17], "User.BulkOrder(17)", response);
  132. user.BulkOrderMaxValue = ParseDecimal(parts[18], "User.BulkOrderMaxValue(18)", response);
  133. user.BulkViewPins = ParseBool(parts[19], "User.BulkViewPins(19)", response);
  134. user.BulkReExport = ParseBool(parts[20], "User.BulkReExport(20)", response);
  135. }
  136. return user;
  137. }
  138. public int ConnectTimeout { get; set; }
  139. protected virtual void Dispose(bool disposing)
  140. {
  141. if (_disposed)
  142. return;
  143. _disposed = true;
  144. // No unmanaged resources are disposed so we don't need the full finalisation pattern.
  145. if (disposing)
  146. {
  147. if (_des != null)
  148. {
  149. _des.Dispose();
  150. _des = null;
  151. }
  152. if (_connectionStream != null)
  153. {
  154. _connectionStream.Dispose();
  155. _connectionStream = null;
  156. }
  157. if (_connection != null)
  158. {
  159. _connection.Dispose();
  160. _connection = null;
  161. }
  162. }
  163. }
  164. public void Dispose()
  165. {
  166. Dispose(true);
  167. }
  168. private string Decrypt(string cipherText)
  169. {
  170. var response = Utils.TripleDESDecrypt(cipherText, _des);
  171. if (_logResponses)
  172. {
  173. _logger.LogDebug("Decrypted response for {0}: {1}", LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), response);
  174. }
  175. return response;
  176. }
  177. private string Encrypt(string plainText)
  178. {
  179. return Utils.TripleDESEncrypt(plainText, _des);
  180. }
  181. private string EncryptRSA(string publicKey, string plainText)
  182. {
  183. RSAParameters parameters = new RSAParameters();
  184. var xml = new XmlDocument();
  185. xml.LoadXml(publicKey);
  186. if (! xml.DocumentElement.Name.Equals("RSAKeyValue"))
  187. throw new Exception("Invalid RSA key");
  188. foreach (XmlNode node in xml.DocumentElement.ChildNodes)
  189. {
  190. switch (node.Name)
  191. {
  192. case "Modulus": parameters.Modulus = Convert.FromBase64String(node.InnerText); break;
  193. case "Exponent": parameters.Exponent = Convert.FromBase64String(node.InnerText); break;
  194. case "P": parameters.P = Convert.FromBase64String(node.InnerText); break;
  195. case "Q": parameters.Q = Convert.FromBase64String(node.InnerText); break;
  196. case "DP": parameters.DP = Convert.FromBase64String(node.InnerText); break;
  197. case "DQ": parameters.DQ = Convert.FromBase64String(node.InnerText); break;
  198. case "InverseQ": parameters.InverseQ = Convert.FromBase64String(node.InnerText); break;
  199. case "D": parameters.D = Convert.FromBase64String(node.InnerText); break;
  200. }
  201. }
  202. using (var rsa = RSA.Create())
  203. {
  204. rsa.ImportParameters(parameters);
  205. var blockSize = rsa.KeySize / 8 - 42;
  206. var offset = 0;
  207. var input = Encoding.UTF32.GetBytes(plainText);
  208. StringBuilder output = new StringBuilder();
  209. while (offset < input.Length)
  210. {
  211. var length = input.Length - offset;
  212. if (length > blockSize)
  213. length = blockSize;
  214. var block = new byte[length];
  215. Array.Copy(input, offset, block, 0, length);
  216. var cipherText = rsa.Encrypt(block, RSAEncryptionPadding.OaepSHA1);
  217. Array.Reverse(cipherText);
  218. output.Append(Convert.ToBase64String(cipherText));
  219. offset += length;
  220. }
  221. return output.ToString();
  222. }
  223. }
  224. public async Task<Account> GetAccountAsync()
  225. {
  226. await WriteMessageAsync(new MessageBuilder().Append("Acc")).ConfigureAwait(false);
  227. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  228. var parts = response.Split('|');
  229. return new Account()
  230. {
  231. Id = ParseInt(parts[1], "Account.Id(1)", response),
  232. Name = parts[2],
  233. Balance = ParseDecimal(parts[3], "Account.Balance(3)", response),
  234. Status = (Account.AccountStatus)ParseInt(parts[4], "Account.AccountStatus(4)", response),
  235. Reference = parts[5],
  236. Warehouse = new Warehouse()
  237. {
  238. Id = ParseInt(parts[6], "Account.Warehouse.Id(6)", response),
  239. Name = parts[7]
  240. }
  241. };
  242. }
  243. public async Task<ProductCatalogue> GetProductCatalogueAsync(Account account)
  244. {
  245. var encryptedWarehouseName = Encrypt(account.Warehouse.Name);
  246. await WriteMessageAsync(new MessageBuilder()
  247. .Append("Pdt ")
  248. .Append(encryptedWarehouseName)).ConfigureAwait(false);
  249. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  250. var parts = response.Split('|');
  251. var count = ParseInt(parts[1], "Products.Count(1)", response);
  252. var catalogue = new ProductCatalogue();
  253. var listCommand = new MessageBuilder().Append("List ")
  254. .Append(encryptedWarehouseName).GetBytes();
  255. for (var i = 0; i < count; i++)
  256. {
  257. await _connectionStream.WriteAsync(listCommand, 0, listCommand.Length).ConfigureAwait(false);
  258. response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  259. parts = response.Split('|');
  260. int networkId = ParseInt(parts[4], "Product.NetworkId(4)", response);
  261. Network network;
  262. if (! catalogue.NetworkMap.TryGetValue(networkId, out network))
  263. {
  264. network = catalogue.AddNetwork(networkId, parts[5]);
  265. }
  266. catalogue.AddProduct(
  267. network: network,
  268. id: ParseInt(parts[1], "Product.Id(1)", response),
  269. faceValue: ParseDecimal(parts[2], "Product.FaceValue(2)", response),
  270. description: parts[3],
  271. voucherType: (Batch.Vouchertype)ParseInt(parts[6], "Product.VoucherType(6)", response),
  272. discountPercentage: ParseDecimal(parts[7], "Product.DiscountPercentage(7)", response)
  273. );
  274. }
  275. return catalogue;
  276. }
  277. private void ThrowParseError(string value, string valueName, string valueType, string fullResponse)
  278. {
  279. _logger.LogError(
  280. "Failed to parse value: valueType={0} valueName={1} value={2} fullResponse={3} {4}",
  281. valueType,
  282. valueName,
  283. value,
  284. fullResponse,
  285. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber)
  286. );
  287. throw new Exception(String.Format("Invalid value for {0}", valueName));
  288. }
  289. private bool ParseBool(string value, string valueName, string fullResponse)
  290. {
  291. bool ret;
  292. if (! bool.TryParse(value, out ret))
  293. {
  294. ThrowParseError(value, valueName, "bool", fullResponse);
  295. }
  296. return ret;
  297. }
  298. private DateTime ParseDateTime(string value, string valueName, string fullResponse)
  299. {
  300. DateTime ret;
  301. if (!DateTime.TryParse(value, out ret))
  302. {
  303. ThrowParseError(value, valueName, "DateTime", fullResponse);
  304. }
  305. return ret;
  306. }
  307. private decimal ParseDecimal(string value, string valueName, string fullResponse)
  308. {
  309. decimal ret;
  310. if (!decimal.TryParse(value, out ret))
  311. {
  312. double fallback;
  313. if (!double.TryParse(value, out fallback))
  314. {
  315. ThrowParseError(value, valueName, "decimal", fullResponse);
  316. }
  317. return (decimal)fallback;
  318. }
  319. return ret;
  320. }
  321. private int ParseInt(string value, string valueName, string fullResponse)
  322. {
  323. int ret;
  324. if (!int.TryParse(value, out ret))
  325. {
  326. ThrowParseError(value, valueName, "int", fullResponse);
  327. }
  328. return ret;
  329. }
  330. public async Task<OrderResponse> PlaceOrderAsync(int accountId, Product product, int quantity,
  331. string customerReference, string internalReference, Guid? orderGuid, byte[] key)
  332. {
  333. if (key.Length != 24)
  334. {
  335. throw new ArgumentException("24 byte key expected", nameof(key));
  336. }
  337. _logger.LogDebug(
  338. "Placing order for {0}: date={1} quantity={2} productId={3} productDescription={4} networkId={5} networkName={6} customerRef={7} internalRef={8}",
  339. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  340. DateTimeOffset.UtcNow,
  341. quantity,
  342. product.Id,
  343. product.Description,
  344. product.Network.Id,
  345. product.Network.Name,
  346. customerReference,
  347. internalReference
  348. );
  349. await WriteMessageAsync(new MessageBuilder()
  350. .Append("Order ")
  351. .Append(Encrypt(new StringBuilder()
  352. .Append(product.Id)
  353. .Append("|")
  354. .Append(quantity)
  355. .Append("|")
  356. .Append(customerReference)
  357. .Append("|2|") // EncType: 0:None, 1:DES, 2:Triple DES
  358. .Append(BitConverter.ToString(key, 0, 8).Replace("-", ""))
  359. .Append("|")
  360. .Append(BitConverter.ToString(key, 8, 8).Replace("-", ""))
  361. .Append("|")
  362. .Append(BitConverter.ToString(key, 16, 8).Replace("-", ""))
  363. .Append("|")
  364. .Append(internalReference)
  365. .ToString()))).ConfigureAwait(false);
  366. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  367. _logger.LogDebug("Order response for {0} customerRef={1} internalRef={2}: {3}",
  368. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  369. customerReference,
  370. internalReference,
  371. response
  372. );
  373. var parts = response.Split('|');
  374. return new OrderResponse()
  375. {
  376. Batch = new Batch()
  377. {
  378. Id = ParseInt(parts[1], "Batch.Id(1)", response),
  379. OrderReference = parts[2],
  380. RequestedQuantity = ParseInt(parts[3], "Batch.RequestQuantity(3)", response),
  381. DeliveredQuantity = ParseInt(parts[4], "Batch.DeliveredQuantity(4)", response),
  382. Cost = ParseDecimal(parts[5], "Batch.Cost(5)", response),
  383. InternalReference = internalReference,
  384. OrderGuid = orderGuid,
  385. AccountId = accountId,
  386. VendorId = _vendorId,
  387. ProductId = product.Id,
  388. ProductDescription = product.Description,
  389. VoucherType = product.VoucherType,
  390. FaceValue = product.FaceValue,
  391. DiscountPercentage = product.DiscountPercentage,
  392. NetworkId = product.Network.Id,
  393. NetworkName = product.Network.Name,
  394. OrderDate = DateTimeOffset.UtcNow,
  395. OrderedById = _userId,
  396. ReadyForDownload = false
  397. },
  398. RemainingBalance = ParseDecimal(parts[6], "Batch.RemainingBalance(6)", response)
  399. };
  400. }
  401. private async Task<byte[]> ReadBytesAsync(int count)
  402. {
  403. int totalBytesRead = 0;
  404. byte[] buffer = new byte[count];
  405. while (totalBytesRead < count)
  406. {
  407. int bytesRead = await _connectionStream.ReadAsync(buffer, totalBytesRead, count - totalBytesRead).ConfigureAwait(false);
  408. if (bytesRead == 0)
  409. throw new Exception("Connection closed unexpectedly");
  410. totalBytesRead += bytesRead;
  411. }
  412. return buffer;
  413. }
  414. private async Task<string> ReadMessageAsync()
  415. {
  416. byte[] buffer = await ReadBytesAsync(2).ConfigureAwait(false);
  417. int size = buffer[0] * 256 + buffer[1];
  418. if (size <= 0)
  419. {
  420. throw new Exception("Invalid message size");
  421. }
  422. var response = Encoding.ASCII.GetString(await ReadBytesAsync(size).ConfigureAwait(false));
  423. if (_logResponses)
  424. {
  425. _logger.LogDebug("Response for {0}: {1}", LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), response);
  426. }
  427. return response;
  428. }
  429. public int ReceiveTimeout { get; set; }
  430. public int SendTimeout { get; set; }
  431. private string ExpectResponse(string response, string prefix)
  432. {
  433. if (response.StartsWith("ER"))
  434. {
  435. var parts = response.Split('|');
  436. int errorCode;
  437. if ((parts.Length < 2) || ! int.TryParse(parts[1], out errorCode))
  438. {
  439. errorCode = -1;
  440. }
  441. var message = parts.Length >= 3 ? parts[2] : String.Format("Malformed server error: {0}", response);
  442. _logger.LogError("MAX Error for {0}: {1} (code {2})",
  443. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), message, errorCode);
  444. throw new MAXException(errorCode, message);
  445. }
  446. else if (! response.StartsWith(prefix))
  447. {
  448. _logger.LogError("Invalid MAX response for {0}: {1}",
  449. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  450. response);
  451. throw new Exception(String.Format("Invalid server response: {0}", response));
  452. }
  453. return response;
  454. }
  455. private async Task WriteMessageAsync(MessageBuilder message)
  456. {
  457. byte[] data = message.GetBytes();
  458. await _connectionStream.WriteAsync(data, 0, data.Length).ConfigureAwait(false);
  459. }
  460. }
  461. }