Web API for the bulk printing desktop application.

Client.cs 21KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532
  1. using ExtensionMethods;
  2. using MAX.Models;
  3. using Microsoft.Extensions.Logging;
  4. using System;
  5. using System.Net.Sockets;
  6. using System.Security.Cryptography;
  7. using System.Text;
  8. using System.Threading;
  9. using System.Threading.Tasks;
  10. using System.Xml;
  11. namespace MAX
  12. {
  13. public class Client : IDisposable
  14. {
  15. private ILogger _logger;
  16. private string _host;
  17. private int _port;
  18. private int _vendorId;
  19. private string _serialNumber;
  20. private int _userId;
  21. private string _username;
  22. private string _password;
  23. private bool _logResponses;
  24. private TcpClient _connection = null;
  25. private NetworkStream _connectionStream = null;
  26. private TripleDES _des = null;
  27. private bool _disposed = false;
  28. public Client(ILogger logger, bool logResponses, string host, int port, int vendorId, string serialNumber, int userId, string username, string password)
  29. {
  30. _logger = logger;
  31. _host = host;
  32. _port = port;
  33. _vendorId = vendorId;
  34. _serialNumber = serialNumber;
  35. _userId = userId;
  36. _username = username;
  37. _password = password;
  38. _logResponses = logResponses;
  39. ConnectTimeout = 10000;
  40. ReceiveTimeout = 10000;
  41. SendTimeout = 10000;
  42. }
  43. public Client(ILogger logger, bool logResponses, string host, int port, LoginCredentials credentials)
  44. : this(logger, logResponses, host, port, credentials.Vendor.Id, credentials.Vendor.SerialNumber,
  45. credentials.User.Id, credentials.User.Username, credentials.Password)
  46. {
  47. }
  48. public void Close()
  49. {
  50. Dispose(true);
  51. }
  52. public async Task<User> ConnectAsync()
  53. {
  54. if (_connection != null)
  55. throw new Exception("Already connected");
  56. _connection = new TcpClient(AddressFamily.InterNetwork);
  57. _connection.ReceiveTimeout = ReceiveTimeout;
  58. _connection.SendTimeout = SendTimeout;
  59. // Connect to the server
  60. try
  61. {
  62. using (var cancellationSource = new CancellationTokenSource(ConnectTimeout))
  63. {
  64. await _connection.ConnectAsync(_host, _port).WithCancellation(cancellationSource.Token).ConfigureAwait(false);
  65. }
  66. }
  67. catch (OperationCanceledException)
  68. {
  69. throw new Exception("Connect timeout");
  70. }
  71. _connectionStream = _connection.GetStream();
  72. // Device authentication
  73. await WriteMessageAsync(new MessageBuilder()
  74. .Append("Hi ")
  75. .Append(_serialNumber)
  76. .Append("|V")
  77. .Append(_vendorId)
  78. .Append("|123451234512345||||||")).ConfigureAwait(false);
  79. var response = ExpectResponse(await ReadMessageAsync().ConfigureAwait(false), "Hi");
  80. // Request server RSA key
  81. //
  82. // WARNING:
  83. //
  84. // The protocol does not do any form of server authentication so this step is
  85. // trivially vulnerable to a man-in-the-middle attack where an intermediary
  86. // intercepts this request and sends their own RSA key while keeping the server RSA
  87. // key to themselves.
  88. await WriteMessageAsync(new MessageBuilder().Append("PK")).ConfigureAwait(false);
  89. response = await ReadMessageAsync().ConfigureAwait(false);
  90. // Key exchange
  91. _des = TripleDES.Create();
  92. _des.IV = new byte[8];
  93. if (_logResponses)
  94. {
  95. _logger.LogDebug("Key for {0}: {1}",
  96. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  97. BitConverter.ToString(_des.Key).Replace("-", "")
  98. );
  99. }
  100. await WriteMessageAsync(new MessageBuilder()
  101. .Append("3D ")
  102. .Append(EncryptRSA(response, BitConverter.ToString(_des.Key).Replace("-", "")))).ConfigureAwait(false);
  103. response = ExpectResponse(await ReadMessageAsync().ConfigureAwait(false), "OK");
  104. // User authentication
  105. await WriteMessageAsync(new MessageBuilder()
  106. .Append("User ")
  107. .Append(Encrypt(new StringBuilder()
  108. .Append(_userId)
  109. .Append("|")
  110. .Append(_username)
  111. .Append("|")
  112. .Append(_password).ToString()))).ConfigureAwait(false);
  113. response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  114. var parts = response.Split('|');
  115. var user = new User()
  116. {
  117. Id = _userId,
  118. Username = _username,
  119. FirstName = parts[4],
  120. Surname = parts[3],
  121. Enabled = ParseBool(parts[6], "User.Enabled(6)", response),
  122. Level = (User.UserLevel)ParseInt(parts[1], "User.Level(1)", response),
  123. System = ParseInt(parts[2], "User.System(2)", response),
  124. LastLogin = ParseDateTime(parts[5], "User.LastLogin(5)", response)
  125. };
  126. if (user.Level == User.UserLevel.CustomUser)
  127. {
  128. user.CanPrintOffline = ParseBool(parts[7], "User.CanPrintOffline(7)", response);
  129. user.OfflinePrintValue = ParseDecimal(parts[8], "User.OfflinePrintValue(8)", response);
  130. user.CanPrintOnline = ParseBool(parts[9], "User.CanPrintOnline(9)", response);
  131. user.OnlinePrintValue = ParseDecimal(parts[10], "User.OnlinePrintValue(10)", response);
  132. user.CanReprintOffline = ParseBool(parts[11], "User.CanReprintOffline(11)", response);
  133. user.OfflineReprintValue = ParseDecimal(parts[12], "User.OfflineReprintValue(12)", response);
  134. user.CanReprintOnline = ParseBool(parts[13], "User.CanReprintOnline(13)", response);
  135. user.OnlineReprintValue = ParseDecimal(parts[14], "User.OnlineReprintValue(14)", response);
  136. user.BulkExport = ParseBool(parts[15], "User.BulkExport(15)", response);
  137. user.BulkExportMaxValue = ParseDecimal(parts[16], "User.BulkExportMaxValue(16)", response);
  138. user.BulkOrder = ParseBool(parts[17], "User.BulkOrder(17)", response);
  139. user.BulkOrderMaxValue = ParseDecimal(parts[18], "User.BulkOrderMaxValue(18)", response);
  140. user.BulkViewPins = ParseBool(parts[19], "User.BulkViewPins(19)", response);
  141. user.BulkReExport = ParseBool(parts[20], "User.BulkReExport(20)", response);
  142. }
  143. return user;
  144. }
  145. public int ConnectTimeout { get; set; }
  146. protected virtual void Dispose(bool disposing)
  147. {
  148. if (_disposed)
  149. return;
  150. _disposed = true;
  151. // No unmanaged resources are disposed so we don't need the full finalisation pattern.
  152. if (disposing)
  153. {
  154. if (_des != null)
  155. {
  156. _des.Dispose();
  157. _des = null;
  158. }
  159. if (_connectionStream != null)
  160. {
  161. _connectionStream.Dispose();
  162. _connectionStream = null;
  163. }
  164. if (_connection != null)
  165. {
  166. _connection.Dispose();
  167. _connection = null;
  168. }
  169. }
  170. }
  171. public void Dispose()
  172. {
  173. Dispose(true);
  174. }
  175. private string Decrypt(string cipherText)
  176. {
  177. var response = Utils.TripleDESDecrypt(cipherText, _des);
  178. if (_logResponses)
  179. {
  180. _logger.LogDebug("Decrypted response for {0}: {1}", LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), response);
  181. }
  182. return response;
  183. }
  184. private string Encrypt(string plainText)
  185. {
  186. return Utils.TripleDESEncrypt(plainText, _des);
  187. }
  188. private string EncryptRSA(string publicKey, string plainText)
  189. {
  190. RSAParameters parameters = new RSAParameters();
  191. var xml = new XmlDocument();
  192. xml.LoadXml(publicKey);
  193. if (! xml.DocumentElement.Name.Equals("RSAKeyValue"))
  194. throw new Exception("Invalid RSA key");
  195. foreach (XmlNode node in xml.DocumentElement.ChildNodes)
  196. {
  197. switch (node.Name)
  198. {
  199. case "Modulus": parameters.Modulus = Convert.FromBase64String(node.InnerText); break;
  200. case "Exponent": parameters.Exponent = Convert.FromBase64String(node.InnerText); break;
  201. case "P": parameters.P = Convert.FromBase64String(node.InnerText); break;
  202. case "Q": parameters.Q = Convert.FromBase64String(node.InnerText); break;
  203. case "DP": parameters.DP = Convert.FromBase64String(node.InnerText); break;
  204. case "DQ": parameters.DQ = Convert.FromBase64String(node.InnerText); break;
  205. case "InverseQ": parameters.InverseQ = Convert.FromBase64String(node.InnerText); break;
  206. case "D": parameters.D = Convert.FromBase64String(node.InnerText); break;
  207. }
  208. }
  209. using (var rsa = RSA.Create())
  210. {
  211. rsa.ImportParameters(parameters);
  212. var blockSize = rsa.KeySize / 8 - 42;
  213. var offset = 0;
  214. var input = Encoding.UTF32.GetBytes(plainText);
  215. StringBuilder output = new StringBuilder();
  216. while (offset < input.Length)
  217. {
  218. var length = input.Length - offset;
  219. if (length > blockSize)
  220. length = blockSize;
  221. var block = new byte[length];
  222. Array.Copy(input, offset, block, 0, length);
  223. var cipherText = rsa.Encrypt(block, RSAEncryptionPadding.OaepSHA1);
  224. Array.Reverse(cipherText);
  225. output.Append(Convert.ToBase64String(cipherText));
  226. offset += length;
  227. }
  228. return output.ToString();
  229. }
  230. }
  231. public async Task<Account> GetAccountAsync()
  232. {
  233. await WriteMessageAsync(new MessageBuilder().Append("Acc")).ConfigureAwait(false);
  234. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  235. var parts = response.Split('|');
  236. return new Account()
  237. {
  238. Id = ParseInt(parts[1], "Account.Id(1)", response),
  239. Name = parts[2],
  240. Balance = ParseDecimal(parts[3], "Account.Balance(3)", response),
  241. Status = (Account.AccountStatus)ParseInt(parts[4], "Account.AccountStatus(4)", response),
  242. Reference = parts[5],
  243. Warehouse = new Warehouse()
  244. {
  245. Id = ParseInt(parts[6], "Account.Warehouse.Id(6)", response),
  246. Name = parts[7]
  247. }
  248. };
  249. }
  250. public async Task<ProductCatalogue> GetProductCatalogueAsync(Account account)
  251. {
  252. var encryptedWarehouseName = Encrypt(account.Warehouse.Name);
  253. await WriteMessageAsync(new MessageBuilder()
  254. .Append("Pdt ")
  255. .Append(encryptedWarehouseName)).ConfigureAwait(false);
  256. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  257. var parts = response.Split('|');
  258. var count = ParseInt(parts[1], "Products.Count(1)", response);
  259. var catalogue = new ProductCatalogue();
  260. var listCommand = new MessageBuilder().Append("List ")
  261. .Append(encryptedWarehouseName).GetBytes();
  262. for (var i = 0; i < count; i++)
  263. {
  264. await _connectionStream.WriteAsync(listCommand, 0, listCommand.Length).ConfigureAwait(false);
  265. response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  266. parts = response.Split('|');
  267. int networkId = ParseInt(parts[4], "Product.NetworkId(4)", response);
  268. Network network;
  269. if (! catalogue.NetworkMap.TryGetValue(networkId, out network))
  270. {
  271. network = catalogue.AddNetwork(networkId, parts[5]);
  272. }
  273. catalogue.AddProduct(
  274. network: network,
  275. id: ParseInt(parts[1], "Product.Id(1)", response),
  276. faceValue: ParseDecimal(parts[2], "Product.FaceValue(2)", response),
  277. description: parts[3],
  278. voucherType: (Batch.Vouchertype)ParseInt(parts[6], "Product.VoucherType(6)", response),
  279. discountPercentage: ParseDecimal(parts[7], "Product.DiscountPercentage(7)", response)
  280. );
  281. }
  282. return catalogue;
  283. }
  284. private void ThrowParseError(string value, string valueName, string valueType, string fullResponse)
  285. {
  286. _logger.LogError(
  287. "Failed to parse value: valueType={0} valueName={1} value={2} fullResponse={3} {4}",
  288. valueType,
  289. valueName,
  290. value,
  291. fullResponse,
  292. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber)
  293. );
  294. throw new Exception(String.Format("Invalid value for {0}", valueName));
  295. }
  296. private bool ParseBool(string value, string valueName, string fullResponse)
  297. {
  298. bool ret;
  299. if (! bool.TryParse(value, out ret))
  300. {
  301. ThrowParseError(value, valueName, "bool", fullResponse);
  302. }
  303. return ret;
  304. }
  305. private DateTime ParseDateTime(string value, string valueName, string fullResponse)
  306. {
  307. DateTime ret;
  308. if (!DateTime.TryParse(value, out ret))
  309. {
  310. ThrowParseError(value, valueName, "DateTime", fullResponse);
  311. }
  312. return ret;
  313. }
  314. private decimal ParseDecimal(string value, string valueName, string fullResponse)
  315. {
  316. decimal ret;
  317. if (!decimal.TryParse(value, out ret))
  318. {
  319. double fallback;
  320. if (!double.TryParse(value, out fallback))
  321. {
  322. ThrowParseError(value, valueName, "decimal", fullResponse);
  323. }
  324. return (decimal)fallback;
  325. }
  326. return ret;
  327. }
  328. private int ParseInt(string value, string valueName, string fullResponse)
  329. {
  330. int ret;
  331. if (!int.TryParse(value, out ret))
  332. {
  333. ThrowParseError(value, valueName, "int", fullResponse);
  334. }
  335. return ret;
  336. }
  337. public async Task<OrderResponse> PlaceOrderAsync(int accountId, Product product, int quantity,
  338. string customerReference, string internalReference, Guid? orderGuid, byte[] key)
  339. {
  340. if (key.Length != 24)
  341. {
  342. throw new ArgumentException("24 byte key expected", nameof(key));
  343. }
  344. _logger.LogDebug(
  345. "Placing order for {0}: date={1} quantity={2} productId={3} productDescription={4} networkId={5} networkName={6} customerRef={7} internalRef={8}",
  346. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  347. DateTimeOffset.UtcNow,
  348. quantity,
  349. product.Id,
  350. product.Description,
  351. product.Network.Id,
  352. product.Network.Name,
  353. customerReference,
  354. internalReference
  355. );
  356. await WriteMessageAsync(new MessageBuilder()
  357. .Append("Order ")
  358. .Append(Encrypt(new StringBuilder()
  359. .Append(product.Id)
  360. .Append("|")
  361. .Append(quantity)
  362. .Append("|")
  363. .Append(customerReference)
  364. .Append("|2|") // EncType: 0:None, 1:DES, 2:Triple DES
  365. .Append(BitConverter.ToString(key, 0, 8).Replace("-", ""))
  366. .Append("|")
  367. .Append(BitConverter.ToString(key, 8, 8).Replace("-", ""))
  368. .Append("|")
  369. .Append(BitConverter.ToString(key, 16, 8).Replace("-", ""))
  370. .Append("|")
  371. .Append(internalReference)
  372. .ToString()))).ConfigureAwait(false);
  373. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  374. _logger.LogDebug("Order response for {0} customerRef={1} internalRef={2}: {3}",
  375. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  376. customerReference,
  377. internalReference,
  378. response
  379. );
  380. var parts = response.Split('|');
  381. return new OrderResponse()
  382. {
  383. Batch = new Batch()
  384. {
  385. Id = ParseInt(parts[1], "Batch.Id(1)", response),
  386. OrderReference = parts[2],
  387. RequestedQuantity = ParseInt(parts[3], "Batch.RequestQuantity(3)", response),
  388. DeliveredQuantity = ParseInt(parts[4], "Batch.DeliveredQuantity(4)", response),
  389. Cost = ParseDecimal(parts[5], "Batch.Cost(5)", response),
  390. InternalReference = internalReference,
  391. OrderGuid = orderGuid,
  392. AccountId = accountId,
  393. VendorId = _vendorId,
  394. ProductId = product.Id,
  395. ProductDescription = product.Description,
  396. VoucherType = product.VoucherType,
  397. FaceValue = product.FaceValue,
  398. DiscountPercentage = product.DiscountPercentage,
  399. NetworkId = product.Network.Id,
  400. NetworkName = product.Network.Name,
  401. OrderDate = DateTimeOffset.UtcNow,
  402. OrderedById = _userId,
  403. ReadyForDownload = false
  404. },
  405. RemainingBalance = ParseDecimal(parts[6], "Batch.RemainingBalance(6)", response)
  406. };
  407. }
  408. private async Task<byte[]> ReadBytesAsync(int count)
  409. {
  410. int totalBytesRead = 0;
  411. byte[] buffer = new byte[count];
  412. while (totalBytesRead < count)
  413. {
  414. int bytesRead = await _connectionStream.ReadAsync(buffer, totalBytesRead, count - totalBytesRead).ConfigureAwait(false);
  415. if (bytesRead == 0)
  416. throw new Exception("Connection closed unexpectedly");
  417. totalBytesRead += bytesRead;
  418. }
  419. return buffer;
  420. }
  421. private async Task<string> ReadMessageAsync()
  422. {
  423. byte[] buffer = await ReadBytesAsync(2).ConfigureAwait(false);
  424. int size = buffer[0] * 256 + buffer[1];
  425. if (size <= 0)
  426. {
  427. throw new Exception("Invalid message size");
  428. }
  429. var response = Encoding.ASCII.GetString(await ReadBytesAsync(size).ConfigureAwait(false));
  430. if (_logResponses)
  431. {
  432. _logger.LogDebug("Response for {0}: {1}", LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), response);
  433. }
  434. return response;
  435. }
  436. public int ReceiveTimeout { get; set; }
  437. public int SendTimeout { get; set; }
  438. private string ExpectResponse(string response, string prefix)
  439. {
  440. if (response.StartsWith("ER"))
  441. {
  442. var parts = response.Split('|');
  443. int errorCode;
  444. if ((parts.Length < 2) || ! int.TryParse(parts[1], out errorCode))
  445. {
  446. errorCode = -1;
  447. }
  448. var message = parts.Length >= 3 ? parts[2] : String.Format("Malformed server error: {0}", response);
  449. _logger.LogError("MAX Error for {0}: {1} (code {2})",
  450. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), message, errorCode);
  451. throw new MAXException(errorCode, message);
  452. }
  453. else if (! response.StartsWith(prefix))
  454. {
  455. _logger.LogError("Invalid MAX response for {0}: {1}",
  456. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  457. response);
  458. throw new Exception(String.Format("Invalid server response: {0}", response));
  459. }
  460. return response;
  461. }
  462. private async Task WriteMessageAsync(MessageBuilder message)
  463. {
  464. byte[] data = message.GetBytes();
  465. if (_logResponses)
  466. {
  467. _logger.LogDebug("Request for {0}: {1}",
  468. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  469. Encoding.ASCII.GetString(data, 2, data.Length - 2)
  470. );
  471. }
  472. await _connectionStream.WriteAsync(data, 0, data.Length).ConfigureAwait(false);
  473. }
  474. }
  475. }