Web API for the bulk printing desktop application.

Client.cs 22KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533
  1. using ExtensionMethods;
  2. using MAX.Models;
  3. using Microsoft.Extensions.Logging;
  4. using System;
  5. using System.Net.Sockets;
  6. using System.Security.Cryptography;
  7. using System.Text;
  8. using System.Threading;
  9. using System.Threading.Tasks;
  10. using System.Xml;
  11. namespace MAX
  12. {
  13. public class Client : IDisposable
  14. {
  15. private ILogger _logger;
  16. private string _host;
  17. private int _port;
  18. private int _vendorId;
  19. private string _serialNumber;
  20. private int _userId;
  21. private string _username;
  22. private string _password;
  23. private bool _logResponses;
  24. private TcpClient _connection = null;
  25. private NetworkStream _connectionStream = null;
  26. private TripleDES _des = null;
  27. private bool _disposed = false;
  28. public Client(ILogger logger, bool logResponses, string host, int port, int vendorId, string serialNumber, int userId, string username, string password)
  29. {
  30. _logger = logger;
  31. _host = host;
  32. _port = port;
  33. _vendorId = vendorId;
  34. _serialNumber = serialNumber;
  35. _userId = userId;
  36. _username = username;
  37. _password = password;
  38. _logResponses = logResponses;
  39. ConnectTimeout = 10000;
  40. ReceiveTimeout = 10000;
  41. SendTimeout = 10000;
  42. }
  43. public Client(ILogger logger, bool logResponses, string host, int port, LoginCredentials credentials)
  44. : this(logger, logResponses, host, port, credentials.Vendor.Id, credentials.Vendor.SerialNumber,
  45. credentials.User.Id, credentials.User.Username, credentials.Password)
  46. {
  47. }
  48. public void Close()
  49. {
  50. Dispose(true);
  51. }
  52. public async Task<User> ConnectAsync()
  53. {
  54. if (_connection != null)
  55. throw new Exception("Already connected");
  56. _connection = new TcpClient(AddressFamily.InterNetwork);
  57. _connection.ReceiveTimeout = ReceiveTimeout;
  58. _connection.SendTimeout = SendTimeout;
  59. // Connect to the server
  60. try
  61. {
  62. using (var cancellationSource = new CancellationTokenSource(ConnectTimeout))
  63. {
  64. await _connection.ConnectAsync(_host, _port).WithCancellation(cancellationSource.Token).ConfigureAwait(false);
  65. }
  66. }
  67. catch (OperationCanceledException)
  68. {
  69. throw new Exception("Connect timeout");
  70. }
  71. _connectionStream = _connection.GetStream();
  72. // Device authentication
  73. await WriteMessageAsync(new MessageBuilder()
  74. .Append("Hi ")
  75. .Append(_serialNumber)
  76. .Append("|V")
  77. .Append(_vendorId)
  78. .Append("|123451234512345||||||")).ConfigureAwait(false);
  79. var response = ExpectResponse(await ReadMessageAsync().ConfigureAwait(false), "Hi");
  80. // Request server RSA key
  81. //
  82. // WARNING:
  83. //
  84. // The protocol does not do any form of server authentication so this step is
  85. // vulnerable to a man-in-the-middle attack where an intermediary intercepts this
  86. // request and sends their own RSA key while keeping the server RSA key to themselves.
  87. // This is not really an issue here as this is server to server communication and
  88. // therefore less likely to be intercepted.
  89. await WriteMessageAsync(new MessageBuilder().Append("PK")).ConfigureAwait(false);
  90. response = await ReadMessageAsync().ConfigureAwait(false);
  91. // Key exchange
  92. _des = TripleDES.Create();
  93. _des.IV = new byte[8];
  94. if (_logResponses)
  95. {
  96. _logger.LogDebug("Key for {0}: {1}",
  97. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  98. BitConverter.ToString(_des.Key).Replace("-", "")
  99. );
  100. }
  101. await WriteMessageAsync(new MessageBuilder()
  102. .Append("3D ")
  103. .Append(EncryptRSA(response, BitConverter.ToString(_des.Key).Replace("-", "")))).ConfigureAwait(false);
  104. response = ExpectResponse(await ReadMessageAsync().ConfigureAwait(false), "OK");
  105. // User authentication
  106. await WriteMessageAsync(new MessageBuilder()
  107. .Append("User ")
  108. .Append(Encrypt(new StringBuilder()
  109. .Append(_userId)
  110. .Append("|")
  111. .Append(_username)
  112. .Append("|")
  113. .Append(_password).ToString()))).ConfigureAwait(false);
  114. response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  115. var parts = response.Split('|');
  116. var user = new User()
  117. {
  118. Id = _userId,
  119. Username = _username,
  120. FirstName = parts[4],
  121. Surname = parts[3],
  122. Enabled = ParseBool(parts[6], "User.Enabled(6)", response),
  123. Level = (User.UserLevel)ParseInt(parts[1], "User.Level(1)", response),
  124. System = ParseInt(parts[2], "User.System(2)", response),
  125. LastLogin = ParseDateTime(parts[5], "User.LastLogin(5)", response)
  126. };
  127. if (user.Level == User.UserLevel.CustomUser)
  128. {
  129. user.CanPrintOffline = ParseBool(parts[7], "User.CanPrintOffline(7)", response);
  130. user.OfflinePrintValue = ParseDecimal(parts[8], "User.OfflinePrintValue(8)", response);
  131. user.CanPrintOnline = ParseBool(parts[9], "User.CanPrintOnline(9)", response);
  132. user.OnlinePrintValue = ParseDecimal(parts[10], "User.OnlinePrintValue(10)", response);
  133. user.CanReprintOffline = ParseBool(parts[11], "User.CanReprintOffline(11)", response);
  134. user.OfflineReprintValue = ParseDecimal(parts[12], "User.OfflineReprintValue(12)", response);
  135. user.CanReprintOnline = ParseBool(parts[13], "User.CanReprintOnline(13)", response);
  136. user.OnlineReprintValue = ParseDecimal(parts[14], "User.OnlineReprintValue(14)", response);
  137. user.BulkExport = ParseBool(parts[15], "User.BulkExport(15)", response);
  138. user.BulkExportMaxValue = ParseDecimal(parts[16], "User.BulkExportMaxValue(16)", response);
  139. user.BulkOrder = ParseBool(parts[17], "User.BulkOrder(17)", response);
  140. user.BulkOrderMaxValue = ParseDecimal(parts[18], "User.BulkOrderMaxValue(18)", response);
  141. user.BulkViewPins = ParseBool(parts[19], "User.BulkViewPins(19)", response);
  142. user.BulkReExport = ParseBool(parts[20], "User.BulkReExport(20)", response);
  143. }
  144. return user;
  145. }
  146. public int ConnectTimeout { get; set; }
  147. protected virtual void Dispose(bool disposing)
  148. {
  149. if (_disposed)
  150. return;
  151. _disposed = true;
  152. // No unmanaged resources are disposed so we don't need the full finalisation pattern.
  153. if (disposing)
  154. {
  155. if (_des != null)
  156. {
  157. _des.Dispose();
  158. _des = null;
  159. }
  160. if (_connectionStream != null)
  161. {
  162. _connectionStream.Dispose();
  163. _connectionStream = null;
  164. }
  165. if (_connection != null)
  166. {
  167. _connection.Dispose();
  168. _connection = null;
  169. }
  170. }
  171. }
  172. public void Dispose()
  173. {
  174. Dispose(true);
  175. }
  176. private string Decrypt(string cipherText)
  177. {
  178. var response = Utils.TripleDESDecrypt(cipherText, _des);
  179. if (_logResponses)
  180. {
  181. _logger.LogDebug("Decrypted response for {0}: {1}", LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), response);
  182. }
  183. return response;
  184. }
  185. private string Encrypt(string plainText)
  186. {
  187. return Utils.TripleDESEncrypt(plainText, _des);
  188. }
  189. private string EncryptRSA(string publicKey, string plainText)
  190. {
  191. RSAParameters parameters = new RSAParameters();
  192. var xml = new XmlDocument();
  193. xml.LoadXml(publicKey);
  194. if (! xml.DocumentElement.Name.Equals("RSAKeyValue"))
  195. throw new Exception("Invalid RSA key");
  196. foreach (XmlNode node in xml.DocumentElement.ChildNodes)
  197. {
  198. switch (node.Name)
  199. {
  200. case "Modulus": parameters.Modulus = Convert.FromBase64String(node.InnerText); break;
  201. case "Exponent": parameters.Exponent = Convert.FromBase64String(node.InnerText); break;
  202. case "P": parameters.P = Convert.FromBase64String(node.InnerText); break;
  203. case "Q": parameters.Q = Convert.FromBase64String(node.InnerText); break;
  204. case "DP": parameters.DP = Convert.FromBase64String(node.InnerText); break;
  205. case "DQ": parameters.DQ = Convert.FromBase64String(node.InnerText); break;
  206. case "InverseQ": parameters.InverseQ = Convert.FromBase64String(node.InnerText); break;
  207. case "D": parameters.D = Convert.FromBase64String(node.InnerText); break;
  208. }
  209. }
  210. using (var rsa = RSA.Create())
  211. {
  212. rsa.ImportParameters(parameters);
  213. var blockSize = rsa.KeySize / 8 - 42;
  214. var offset = 0;
  215. var input = Encoding.UTF32.GetBytes(plainText);
  216. StringBuilder output = new StringBuilder();
  217. while (offset < input.Length)
  218. {
  219. var length = input.Length - offset;
  220. if (length > blockSize)
  221. length = blockSize;
  222. var block = new byte[length];
  223. Array.Copy(input, offset, block, 0, length);
  224. var cipherText = rsa.Encrypt(block, RSAEncryptionPadding.OaepSHA1);
  225. Array.Reverse(cipherText);
  226. output.Append(Convert.ToBase64String(cipherText));
  227. offset += length;
  228. }
  229. return output.ToString();
  230. }
  231. }
  232. public async Task<Account> GetAccountAsync()
  233. {
  234. await WriteMessageAsync(new MessageBuilder().Append("Acc")).ConfigureAwait(false);
  235. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  236. var parts = response.Split('|');
  237. return new Account()
  238. {
  239. Id = ParseInt(parts[1], "Account.Id(1)", response),
  240. Name = parts[2],
  241. Balance = ParseDecimal(parts[3], "Account.Balance(3)", response),
  242. Status = (Account.AccountStatus)ParseInt(parts[4], "Account.AccountStatus(4)", response),
  243. Reference = parts[5],
  244. Warehouse = new Warehouse()
  245. {
  246. Id = ParseInt(parts[6], "Account.Warehouse.Id(6)", response),
  247. Name = parts[7]
  248. }
  249. };
  250. }
  251. public async Task<ProductCatalogue> GetProductCatalogueAsync(Account account)
  252. {
  253. var encryptedWarehouseName = Encrypt(account.Warehouse.Name);
  254. await WriteMessageAsync(new MessageBuilder()
  255. .Append("Pdt ")
  256. .Append(encryptedWarehouseName)).ConfigureAwait(false);
  257. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  258. var parts = response.Split('|');
  259. var count = ParseInt(parts[1], "Products.Count(1)", response);
  260. var catalogue = new ProductCatalogue();
  261. var listCommand = new MessageBuilder().Append("List ")
  262. .Append(encryptedWarehouseName).GetBytes();
  263. for (var i = 0; i < count; i++)
  264. {
  265. await _connectionStream.WriteAsync(listCommand, 0, listCommand.Length).ConfigureAwait(false);
  266. response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  267. parts = response.Split('|');
  268. int networkId = ParseInt(parts[4], "Product.NetworkId(4)", response);
  269. Network network;
  270. if (! catalogue.NetworkMap.TryGetValue(networkId, out network))
  271. {
  272. network = catalogue.AddNetwork(networkId, parts[5]);
  273. }
  274. catalogue.AddProduct(
  275. network: network,
  276. id: ParseInt(parts[1], "Product.Id(1)", response),
  277. faceValue: ParseDecimal(parts[2], "Product.FaceValue(2)", response),
  278. description: parts[3],
  279. voucherType: (Batch.Vouchertype)ParseInt(parts[6], "Product.VoucherType(6)", response),
  280. discountPercentage: ParseDecimal(parts[7], "Product.DiscountPercentage(7)", response)
  281. );
  282. }
  283. return catalogue;
  284. }
  285. private void ThrowParseError(string value, string valueName, string valueType, string fullResponse)
  286. {
  287. _logger.LogError(
  288. "Failed to parse value: valueType={0} valueName={1} value={2} fullResponse={3} {4}",
  289. valueType,
  290. valueName,
  291. value,
  292. fullResponse,
  293. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber)
  294. );
  295. throw new Exception(String.Format("Invalid value for {0}", valueName));
  296. }
  297. private bool ParseBool(string value, string valueName, string fullResponse)
  298. {
  299. bool ret;
  300. if (! bool.TryParse(value, out ret))
  301. {
  302. ThrowParseError(value, valueName, "bool", fullResponse);
  303. }
  304. return ret;
  305. }
  306. private DateTime ParseDateTime(string value, string valueName, string fullResponse)
  307. {
  308. DateTime ret;
  309. if (!DateTime.TryParse(value, out ret))
  310. {
  311. ThrowParseError(value, valueName, "DateTime", fullResponse);
  312. }
  313. return ret;
  314. }
  315. private decimal ParseDecimal(string value, string valueName, string fullResponse)
  316. {
  317. decimal ret;
  318. if (!decimal.TryParse(value, out ret))
  319. {
  320. double fallback;
  321. if (!double.TryParse(value, out fallback))
  322. {
  323. ThrowParseError(value, valueName, "decimal", fullResponse);
  324. }
  325. return (decimal)fallback;
  326. }
  327. return ret;
  328. }
  329. private int ParseInt(string value, string valueName, string fullResponse)
  330. {
  331. int ret;
  332. if (!int.TryParse(value, out ret))
  333. {
  334. ThrowParseError(value, valueName, "int", fullResponse);
  335. }
  336. return ret;
  337. }
  338. public async Task<OrderResponse> PlaceOrderAsync(int accountId, Product product, int quantity,
  339. string customerReference, string internalReference, Guid? orderGuid, byte[] key)
  340. {
  341. if (key.Length != 24)
  342. {
  343. throw new ArgumentException("24 byte key expected", nameof(key));
  344. }
  345. _logger.LogDebug(
  346. "Placing order for {0}: date={1} quantity={2} productId={3} productDescription={4} networkId={5} networkName={6} customerRef={7} internalRef={8}",
  347. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  348. DateTimeOffset.UtcNow,
  349. quantity,
  350. product.Id,
  351. product.Description,
  352. product.Network.Id,
  353. product.Network.Name,
  354. customerReference,
  355. internalReference
  356. );
  357. await WriteMessageAsync(new MessageBuilder()
  358. .Append("Order ")
  359. .Append(Encrypt(new StringBuilder()
  360. .Append(product.Id)
  361. .Append("|")
  362. .Append(quantity)
  363. .Append("|")
  364. .Append(customerReference)
  365. .Append("|2|") // EncType: 0:None, 1:DES, 2:Triple DES
  366. .Append(BitConverter.ToString(key, 0, 8).Replace("-", ""))
  367. .Append("|")
  368. .Append(BitConverter.ToString(key, 8, 8).Replace("-", ""))
  369. .Append("|")
  370. .Append(BitConverter.ToString(key, 16, 8).Replace("-", ""))
  371. .Append("|")
  372. .Append(internalReference)
  373. .ToString()))).ConfigureAwait(false);
  374. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  375. _logger.LogDebug("Order response for {0} customerRef={1} internalRef={2}: {3}",
  376. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  377. customerReference,
  378. internalReference,
  379. response
  380. );
  381. var parts = response.Split('|');
  382. return new OrderResponse()
  383. {
  384. Batch = new Batch()
  385. {
  386. Id = ParseInt(parts[1], "Batch.Id(1)", response),
  387. OrderReference = parts[2],
  388. RequestedQuantity = ParseInt(parts[3], "Batch.RequestQuantity(3)", response),
  389. DeliveredQuantity = ParseInt(parts[4], "Batch.DeliveredQuantity(4)", response),
  390. Cost = ParseDecimal(parts[5], "Batch.Cost(5)", response),
  391. InternalReference = internalReference,
  392. OrderGuid = orderGuid,
  393. AccountId = accountId,
  394. VendorId = _vendorId,
  395. ProductId = product.Id,
  396. ProductDescription = product.Description,
  397. VoucherType = product.VoucherType,
  398. FaceValue = product.FaceValue,
  399. DiscountPercentage = product.DiscountPercentage,
  400. NetworkId = product.Network.Id,
  401. NetworkName = product.Network.Name,
  402. OrderDate = DateTimeOffset.UtcNow,
  403. OrderedById = _userId,
  404. ReadyForDownload = false
  405. },
  406. RemainingBalance = ParseDecimal(parts[6], "Batch.RemainingBalance(6)", response)
  407. };
  408. }
  409. private async Task<byte[]> ReadBytesAsync(int count)
  410. {
  411. int totalBytesRead = 0;
  412. byte[] buffer = new byte[count];
  413. while (totalBytesRead < count)
  414. {
  415. int bytesRead = await _connectionStream.ReadAsync(buffer, totalBytesRead, count - totalBytesRead).ConfigureAwait(false);
  416. if (bytesRead == 0)
  417. throw new Exception("Connection closed unexpectedly");
  418. totalBytesRead += bytesRead;
  419. }
  420. return buffer;
  421. }
  422. private async Task<string> ReadMessageAsync()
  423. {
  424. byte[] buffer = await ReadBytesAsync(2).ConfigureAwait(false);
  425. int size = buffer[0] * 256 + buffer[1];
  426. if (size <= 0)
  427. {
  428. throw new Exception("Invalid message size");
  429. }
  430. var response = Encoding.ASCII.GetString(await ReadBytesAsync(size).ConfigureAwait(false));
  431. if (_logResponses)
  432. {
  433. _logger.LogDebug("Response for {0}: {1}", LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), response);
  434. }
  435. return response;
  436. }
  437. public int ReceiveTimeout { get; set; }
  438. public int SendTimeout { get; set; }
  439. private string ExpectResponse(string response, string prefix)
  440. {
  441. if (response.StartsWith("ER"))
  442. {
  443. var parts = response.Split('|');
  444. int errorCode;
  445. if ((parts.Length < 2) || ! int.TryParse(parts[1], out errorCode))
  446. {
  447. errorCode = -1;
  448. }
  449. var message = parts.Length >= 3 ? parts[2] : String.Format("Malformed server error: {0}", response);
  450. _logger.LogError("MAX Error for {0}: {1} (code {2})",
  451. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), message, errorCode);
  452. throw new MAXException(errorCode, message);
  453. }
  454. else if (! response.StartsWith(prefix))
  455. {
  456. _logger.LogError("Invalid MAX response for {0}: {1}",
  457. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  458. response);
  459. throw new Exception(String.Format("Invalid server response: {0}", response));
  460. }
  461. return response;
  462. }
  463. private async Task WriteMessageAsync(MessageBuilder message)
  464. {
  465. byte[] data = message.GetBytes();
  466. if (_logResponses)
  467. {
  468. _logger.LogDebug("Request for {0}: {1}",
  469. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  470. Encoding.ASCII.GetString(data, 2, data.Length - 2)
  471. );
  472. }
  473. await _connectionStream.WriteAsync(data, 0, data.Length).ConfigureAwait(false);
  474. }
  475. }
  476. }