Web API for the bulk printing desktop application.

Client.cs 23KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558
  1. using ExtensionMethods;
  2. using MAX.Models;
  3. using Microsoft.Extensions.Logging;
  4. using System;
  5. using System.Net.Sockets;
  6. using System.Security.Cryptography;
  7. using System.Text;
  8. using System.Threading;
  9. using System.Threading.Tasks;
  10. using System.Xml;
  11. namespace MAX
  12. {
  13. public class Client : IDisposable
  14. {
  15. private ILogger _logger;
  16. private string _host;
  17. private int _port;
  18. private int _vendorId;
  19. private string _serialNumber;
  20. private int _userId;
  21. private string _username;
  22. private string _password;
  23. private bool _logResponses;
  24. private TcpClient _connection = null;
  25. private NetworkStream _connectionStream = null;
  26. private TripleDES _des = null;
  27. private bool _disposed = false;
  28. public Client(ILogger logger, bool logResponses, string host, int port, int vendorId, string serialNumber, int userId, string username, string password)
  29. {
  30. _logger = logger;
  31. _host = host;
  32. _port = port;
  33. _vendorId = vendorId;
  34. _serialNumber = serialNumber;
  35. _userId = userId;
  36. _username = username;
  37. _password = password;
  38. _logResponses = logResponses;
  39. ConnectTimeout = 10000;
  40. ReceiveTimeout = 10000;
  41. SendTimeout = 10000;
  42. }
  43. public Client(ILogger logger, bool logResponses, string host, int port, LoginCredentials credentials)
  44. : this(logger, logResponses, host, port, credentials.Vendor.Id, credentials.Vendor.SerialNumber,
  45. credentials.User.Id, credentials.User.Username, credentials.Password)
  46. {
  47. }
  48. public void Close()
  49. {
  50. Dispose(true);
  51. }
  52. public async Task<User> ConnectAsync()
  53. {
  54. if (_connection != null)
  55. throw new Exception("Already connected");
  56. _connection = new TcpClient(AddressFamily.InterNetwork);
  57. _connection.ReceiveTimeout = ReceiveTimeout;
  58. _connection.SendTimeout = SendTimeout;
  59. // Connect to the server
  60. try
  61. {
  62. using (var cancellationSource = new CancellationTokenSource(ConnectTimeout))
  63. {
  64. await _connection.ConnectAsync(_host, _port).WithCancellation(cancellationSource.Token).ConfigureAwait(false);
  65. }
  66. }
  67. catch (OperationCanceledException)
  68. {
  69. throw new Exception("Connect timeout");
  70. }
  71. _connectionStream = _connection.GetStream();
  72. // Device authentication
  73. await WriteMessageAsync(new MessageBuilder()
  74. .Append("Hi ")
  75. .Append(_serialNumber)
  76. .Append("|V")
  77. .Append(_vendorId)
  78. .Append("|123451234512345||||||")).ConfigureAwait(false);
  79. var response = ExpectResponse(await ReadMessageAsync().ConfigureAwait(false), "Hi");
  80. // Request server RSA key
  81. //
  82. // WARNING:
  83. //
  84. // The protocol does not do any form of server authentication so this step is
  85. // vulnerable to a man-in-the-middle attack where an intermediary intercepts this
  86. // request and sends their own RSA key while keeping the server RSA key to themselves.
  87. // This is not really an issue here as this is server to server communication and
  88. // therefore less likely to be intercepted.
  89. await WriteMessageAsync(new MessageBuilder().Append("PK")).ConfigureAwait(false);
  90. response = await ReadMessageAsync().ConfigureAwait(false);
  91. // Key exchange
  92. _des = TripleDES.Create();
  93. _des.IV = new byte[8];
  94. if (_logResponses)
  95. {
  96. _logger.LogDebug("Key for {0}: {1}",
  97. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  98. BitConverter.ToString(_des.Key).Replace("-", "")
  99. );
  100. }
  101. await WriteMessageAsync(new MessageBuilder()
  102. .Append("3D ")
  103. .Append(EncryptRSA(response, BitConverter.ToString(_des.Key).Replace("-", "")))).ConfigureAwait(false);
  104. response = ExpectResponse(await ReadMessageAsync().ConfigureAwait(false), "OK");
  105. // User authentication
  106. await WriteMessageAsync(new MessageBuilder()
  107. .Append("User ")
  108. .Append(Encrypt(new StringBuilder()
  109. .Append(_userId)
  110. .Append("|")
  111. .Append(_username)
  112. .Append("|")
  113. .Append(_password).ToString()))).ConfigureAwait(false);
  114. response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  115. var parts = response.Split('|');
  116. var user = new User()
  117. {
  118. Id = _userId,
  119. Username = _username,
  120. FirstName = parts[4],
  121. Surname = parts[3],
  122. Enabled = ParseBool(parts[6], "User.Enabled(6)", response),
  123. Level = (User.UserLevel)ParseInt(parts[1], "User.Level(1)", response),
  124. System = ParseInt(parts[2], "User.System(2)", response),
  125. LastLogin = ParseDateTime(parts[5], "User.LastLogin(5)", response)
  126. };
  127. if (user.Level == User.UserLevel.CustomUser)
  128. {
  129. user.CanPrintOffline = ParseBool(parts[7], "User.CanPrintOffline(7)", response);
  130. user.OfflinePrintValue = ParseDecimal(parts[8], "User.OfflinePrintValue(8)", response);
  131. user.CanPrintOnline = ParseBool(parts[9], "User.CanPrintOnline(9)", response);
  132. user.OnlinePrintValue = ParseDecimal(parts[10], "User.OnlinePrintValue(10)", response);
  133. user.CanReprintOffline = ParseBool(parts[11], "User.CanReprintOffline(11)", response);
  134. user.OfflineReprintValue = ParseDecimal(parts[12], "User.OfflineReprintValue(12)", response);
  135. user.CanReprintOnline = ParseBool(parts[13], "User.CanReprintOnline(13)", response);
  136. user.OnlineReprintValue = ParseDecimal(parts[14], "User.OnlineReprintValue(14)", response);
  137. user.BulkExport = ParseBool(parts[15], "User.BulkExport(15)", response);
  138. user.BulkExportMaxValue = ParseDecimal(parts[16], "User.BulkExportMaxValue(16)", response);
  139. user.BulkOrder = ParseBool(parts[17], "User.BulkOrder(17)", response);
  140. user.BulkOrderMaxValue = ParseDecimal(parts[18], "User.BulkOrderMaxValue(18)", response);
  141. user.BulkViewPins = ParseBool(parts[19], "User.BulkViewPins(19)", response);
  142. user.BulkReExport = ParseBool(parts[20], "User.BulkReExport(20)", response);
  143. }
  144. return user;
  145. }
  146. public int ConnectTimeout { get; set; }
  147. protected virtual void Dispose(bool disposing)
  148. {
  149. if (_disposed)
  150. return;
  151. _disposed = true;
  152. // No unmanaged resources are disposed so we don't need the full finalisation pattern.
  153. if (disposing)
  154. {
  155. if (_des != null)
  156. {
  157. _des.Dispose();
  158. _des = null;
  159. }
  160. if (_connectionStream != null)
  161. {
  162. _connectionStream.Dispose();
  163. _connectionStream = null;
  164. }
  165. if (_connection != null)
  166. {
  167. _connection.Dispose();
  168. _connection = null;
  169. }
  170. }
  171. }
  172. public void Dispose()
  173. {
  174. Dispose(true);
  175. }
  176. private string Decrypt(string cipherText)
  177. {
  178. var response = Utils.TripleDESDecrypt(cipherText, _des);
  179. if (_logResponses)
  180. {
  181. _logger.LogDebug("Decrypted response for {0}: {1}", LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), response);
  182. }
  183. return response;
  184. }
  185. private string Encrypt(string plainText)
  186. {
  187. return Utils.TripleDESEncrypt(plainText, _des);
  188. }
  189. private string EncryptRSA(string publicKey, string plainText)
  190. {
  191. RSAParameters parameters = new RSAParameters();
  192. var xml = new XmlDocument();
  193. xml.LoadXml(publicKey);
  194. if (! xml.DocumentElement.Name.Equals("RSAKeyValue"))
  195. throw new Exception("Invalid RSA key");
  196. foreach (XmlNode node in xml.DocumentElement.ChildNodes)
  197. {
  198. switch (node.Name)
  199. {
  200. case "Modulus": parameters.Modulus = Convert.FromBase64String(node.InnerText); break;
  201. case "Exponent": parameters.Exponent = Convert.FromBase64String(node.InnerText); break;
  202. case "P": parameters.P = Convert.FromBase64String(node.InnerText); break;
  203. case "Q": parameters.Q = Convert.FromBase64String(node.InnerText); break;
  204. case "DP": parameters.DP = Convert.FromBase64String(node.InnerText); break;
  205. case "DQ": parameters.DQ = Convert.FromBase64String(node.InnerText); break;
  206. case "InverseQ": parameters.InverseQ = Convert.FromBase64String(node.InnerText); break;
  207. case "D": parameters.D = Convert.FromBase64String(node.InnerText); break;
  208. }
  209. }
  210. using (var rsa = RSA.Create())
  211. {
  212. rsa.ImportParameters(parameters);
  213. var blockSize = rsa.KeySize / 8 - 42;
  214. var offset = 0;
  215. var input = Encoding.UTF32.GetBytes(plainText);
  216. StringBuilder output = new StringBuilder();
  217. while (offset < input.Length)
  218. {
  219. var length = input.Length - offset;
  220. if (length > blockSize)
  221. length = blockSize;
  222. var block = new byte[length];
  223. Array.Copy(input, offset, block, 0, length);
  224. var cipherText = rsa.Encrypt(block, RSAEncryptionPadding.OaepSHA1);
  225. Array.Reverse(cipherText);
  226. output.Append(Convert.ToBase64String(cipherText));
  227. offset += length;
  228. }
  229. return output.ToString();
  230. }
  231. }
  232. private string ExpectResponse(string response, string prefix)
  233. {
  234. if (response.StartsWith("ER"))
  235. {
  236. var parts = response.Split('|');
  237. int errorCode;
  238. if ((parts.Length < 2) || !int.TryParse(parts[1], out errorCode))
  239. {
  240. errorCode = -1;
  241. }
  242. var message = parts.Length >= 3 ? parts[2] : String.Format("Malformed server error: {0}", response);
  243. _logger.LogError("MAX Error for {0}: {1} (code {2})",
  244. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), message, errorCode);
  245. throw new MAXException(errorCode, message);
  246. }
  247. else if (!response.StartsWith(prefix))
  248. {
  249. _logger.LogError("Invalid MAX response for {0}: {1}",
  250. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  251. response);
  252. throw new Exception(String.Format("Invalid server response: {0}", response));
  253. }
  254. return response;
  255. }
  256. public async Task<Account> GetAccountAsync()
  257. {
  258. await WriteMessageAsync(new MessageBuilder().Append("Acc")).ConfigureAwait(false);
  259. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  260. var parts = response.Split('|');
  261. return new Account()
  262. {
  263. Id = ParseInt(parts[1], "Account.Id(1)", response),
  264. Name = parts[2],
  265. Balance = ParseDecimal(parts[3], "Account.Balance(3)", response),
  266. Status = (Account.AccountStatus)ParseInt(parts[4], "Account.AccountStatus(4)", response),
  267. Reference = parts[5],
  268. Warehouse = new Warehouse()
  269. {
  270. Id = ParseInt(parts[6], "Account.Warehouse.Id(6)", response),
  271. Name = parts[7]
  272. }
  273. };
  274. }
  275. public async Task<ProductCatalogue> GetProductCatalogueAsync(Account account)
  276. {
  277. var encryptedWarehouseName = Encrypt(account.Warehouse.Name);
  278. await WriteMessageAsync(new MessageBuilder()
  279. .Append("Pdt ")
  280. .Append(encryptedWarehouseName)).ConfigureAwait(false);
  281. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  282. var parts = response.Split('|');
  283. var count = ParseInt(parts[1], "Products.Count(1)", response);
  284. var catalogue = new ProductCatalogue();
  285. var listCommand = new MessageBuilder().Append("List ")
  286. .Append(encryptedWarehouseName).GetBytes();
  287. for (var i = 0; i < count; i++)
  288. {
  289. await _connectionStream.WriteAsync(listCommand, 0, listCommand.Length).ConfigureAwait(false);
  290. response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  291. parts = response.Split('|');
  292. int networkId = ParseInt(parts[4], "Product.NetworkId(4)", response);
  293. Network network;
  294. if (! catalogue.NetworkMap.TryGetValue(networkId, out network))
  295. {
  296. network = catalogue.AddNetwork(networkId, parts[5]);
  297. }
  298. catalogue.AddProduct(
  299. network: network,
  300. id: ParseInt(parts[1], "Product.Id(1)", response),
  301. faceValue: ParseDecimal(parts[2], "Product.FaceValue(2)", response),
  302. description: parts[3],
  303. voucherType: (Batch.Vouchertype)ParseInt(parts[6], "Product.VoucherType(6)", response),
  304. discountPercentage: ParseDecimal(parts[7], "Product.DiscountPercentage(7)", response)
  305. );
  306. }
  307. return catalogue;
  308. }
  309. private bool ParseBool(string value, string valueName, string fullResponse)
  310. {
  311. bool ret;
  312. if (! bool.TryParse(value, out ret))
  313. {
  314. ThrowParseError(value, valueName, "bool", fullResponse);
  315. }
  316. return ret;
  317. }
  318. private DateTime ParseDateTime(string value, string valueName, string fullResponse)
  319. {
  320. DateTime ret;
  321. if (!DateTime.TryParse(value, out ret))
  322. {
  323. ThrowParseError(value, valueName, "DateTime", fullResponse);
  324. }
  325. return ret;
  326. }
  327. private decimal ParseDecimal(string value, string valueName, string fullResponse)
  328. {
  329. decimal ret;
  330. if (!decimal.TryParse(value, out ret))
  331. {
  332. double fallback;
  333. if (!double.TryParse(value, out fallback))
  334. {
  335. ThrowParseError(value, valueName, "decimal", fullResponse);
  336. }
  337. return (decimal)fallback;
  338. }
  339. return ret;
  340. }
  341. private int ParseInt(string value, string valueName, string fullResponse)
  342. {
  343. int ret;
  344. if (!int.TryParse(value, out ret))
  345. {
  346. ThrowParseError(value, valueName, "int", fullResponse);
  347. }
  348. return ret;
  349. }
  350. public async Task<OrderResponse> PlaceOrderAsync(int accountId, Product product, int quantity,
  351. string customerReference, string internalReference, Guid? orderGuid, byte[] key)
  352. {
  353. if (key.Length != 24)
  354. {
  355. throw new ArgumentException("24 byte key expected", nameof(key));
  356. }
  357. _logger.LogDebug(
  358. "Placing order for {0}: date={1} quantity={2} productId={3} productDescription={4} networkId={5} networkName={6} customerRef={7} internalRef={8}",
  359. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  360. DateTimeOffset.UtcNow,
  361. quantity,
  362. product.Id,
  363. product.Description,
  364. product.Network.Id,
  365. product.Network.Name,
  366. customerReference,
  367. internalReference
  368. );
  369. await WriteMessageAsync(new MessageBuilder()
  370. .Append("Order ")
  371. .Append(Encrypt(new StringBuilder()
  372. .Append(product.Id)
  373. .Append("|")
  374. .Append(quantity)
  375. .Append("|")
  376. .Append(customerReference)
  377. .Append("|2|") // EncType: 0:None, 1:DES, 2:Triple DES
  378. .Append(BitConverter.ToString(key, 0, 8).Replace("-", ""))
  379. .Append("|")
  380. .Append(BitConverter.ToString(key, 8, 8).Replace("-", ""))
  381. .Append("|")
  382. .Append(BitConverter.ToString(key, 16, 8).Replace("-", ""))
  383. .Append("|")
  384. .Append(internalReference)
  385. .ToString()))).ConfigureAwait(false);
  386. var response = ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  387. _logger.LogDebug("Order response for {0} customerRef={1} internalRef={2}: {3}",
  388. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  389. customerReference,
  390. internalReference,
  391. response
  392. );
  393. var parts = response.Split('|');
  394. var deliveredQuantity = ParseInt(parts[4], "Batch.DeliveredQuantity(4)", response);
  395. return new OrderResponse()
  396. {
  397. Batch = new Batch()
  398. {
  399. Id = ParseInt(parts[1], "Batch.Id(1)", response),
  400. OrderReference = parts[2],
  401. RequestedQuantity = ParseInt(parts[3], "Batch.RequestQuantity(3)", response),
  402. DeliveredQuantity = deliveredQuantity,
  403. Cost = ParseDecimal(parts[5], "Batch.Cost(5)", response),
  404. InternalReference = internalReference,
  405. OrderGuid = orderGuid,
  406. AccountId = accountId,
  407. VendorId = _vendorId,
  408. ProductId = product.Id,
  409. ProductDescription = product.Description,
  410. VoucherType = product.VoucherType,
  411. FaceValue = product.FaceValue,
  412. DiscountPercentage = product.DiscountPercentage,
  413. NetworkId = product.Network.Id,
  414. NetworkName = product.Network.Name,
  415. OrderDate = DateTimeOffset.UtcNow,
  416. OrderedById = _userId,
  417. ReadyForDownload = deliveredQuantity == 0
  418. },
  419. RemainingBalance = ParseDecimal(parts[6], "Batch.RemainingBalance(6)", response)
  420. };
  421. }
  422. private async Task<byte[]> ReadBytesAsync(int count)
  423. {
  424. int totalBytesRead = 0;
  425. byte[] buffer = new byte[count];
  426. while (totalBytesRead < count)
  427. {
  428. int bytesRead = await _connectionStream.ReadAsync(buffer, totalBytesRead, count - totalBytesRead).ConfigureAwait(false);
  429. if (bytesRead == 0)
  430. throw new Exception("Connection closed unexpectedly");
  431. totalBytesRead += bytesRead;
  432. }
  433. return buffer;
  434. }
  435. private async Task<string> ReadMessageAsync()
  436. {
  437. byte[] buffer = await ReadBytesAsync(2).ConfigureAwait(false);
  438. int size = buffer[0] * 256 + buffer[1];
  439. if (size <= 0)
  440. {
  441. throw new Exception("Invalid message size");
  442. }
  443. var response = Encoding.ASCII.GetString(await ReadBytesAsync(size).ConfigureAwait(false));
  444. if (_logResponses)
  445. {
  446. _logger.LogDebug("Response for {0}: {1}", LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber), response);
  447. }
  448. return response;
  449. }
  450. public int ReceiveTimeout { get; set; }
  451. public async Task ReExportBatchAsync(int batchId, byte[] key)
  452. {
  453. if (key.Length != 24)
  454. {
  455. throw new ArgumentException("24 byte key expected", nameof(key));
  456. }
  457. await WriteMessageAsync(new MessageBuilder()
  458. .Append("ReExport ")
  459. .Append(Encrypt(new StringBuilder()
  460. .Append(batchId)
  461. .Append("|2|") // EncType: 0:None, 1:DES, 2:Triple DES
  462. .Append(BitConverter.ToString(key, 0, 8).Replace("-", ""))
  463. .Append("|")
  464. .Append(BitConverter.ToString(key, 8, 8).Replace("-", ""))
  465. .Append("|")
  466. .Append(BitConverter.ToString(key, 16, 8).Replace("-", ""))
  467. .ToString()))).ConfigureAwait(false);
  468. ExpectResponse(Decrypt(await ReadMessageAsync().ConfigureAwait(false)), "OK");
  469. }
  470. public int SendTimeout { get; set; }
  471. private void ThrowParseError(string value, string valueName, string valueType, string fullResponse)
  472. {
  473. _logger.LogError(
  474. "Failed to parse value: valueType={0} valueName={1} value={2} fullResponse={3} {4}",
  475. valueType,
  476. valueName,
  477. value,
  478. fullResponse,
  479. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber)
  480. );
  481. throw new Exception(String.Format("Invalid value for {0}", valueName));
  482. }
  483. private async Task WriteMessageAsync(MessageBuilder message)
  484. {
  485. byte[] data = message.GetBytes();
  486. if (_logResponses)
  487. {
  488. _logger.LogDebug("Request for {0}: {1}",
  489. LoginCredentials.Format(_userId, _username, _vendorId, _serialNumber),
  490. Encoding.ASCII.GetString(data, 2, data.Length - 2)
  491. );
  492. }
  493. await _connectionStream.WriteAsync(data, 0, data.Length).ConfigureAwait(false);
  494. }
  495. }
  496. }