BangleApps/apps/authentiwatch/app.js

273 lines
7.8 KiB
JavaScript
Raw Normal View History

2021-10-29 13:37:38 +00:00
const tokenentryheight = 46;
// Hash functions
const crypto = require("crypto");
2021-11-09 15:24:05 +00:00
const algos = {
"SHA512":{sha:crypto.SHA512,retsz:64,blksz:128},
"SHA256":{sha:crypto.SHA256,retsz:32,blksz:64 },
"SHA1" :{sha:crypto.SHA1 ,retsz:20,blksz:64 },
};
2021-10-29 13:37:38 +00:00
var tokens = require("Storage").readJSON("authentiwatch.json", true) || [
2021-10-29 13:37:38 +00:00
{algorithm:"SHA512",digits:8,period:60,secret:"aaaa aaaa aaaa aaaa",label:"AgAgAg"},
{algorithm:"SHA1",digits:6,period:30,secret:"bbbb bbbb bbbb bbbb",label:"BgBgBg"},
2021-11-13 04:04:30 +00:00
{algorithm:"SHA1",digits:8,period:-3,secret:"cccc cccc cccc cccc",label:"CgCgCg"},
2021-10-29 13:37:38 +00:00
{algorithm:"SHA1",digits:6,period:60,secret:"yyyy yyyy yyyy yyyy",label:"YgYgYg"},
{algorithm:"SHA1",digits:8,period:30,secret:"zzzz zzzz zzzz zzzz",label:"ZgZgZg"},
];
// QR Code Text
//
// Example:
//
// otpauth://totp/${url}:AA_${algorithm}_${digits}dig_${period}s@${url}?algorithm=${algorithm}&digits=${digits}&issuer=${url}&period=${period}&secret=${secret}
//
// ${algorithm} : one of SHA1 / SHA256 / SHA512
// ${digits} : one of 6 / 8
// ${period} : one of 30 / 60
// ${url} : a domain name "example.com"
// ${secret} : the seed code
function b32decode(seedstr) {
// RFC4648
var i, buf = 0, bitcount = 0, retstr = "";
for (i in seedstr) {
var c = "ABCDEFGHIJKLMNOPQRSTUVWXYZ234567".indexOf(seedstr.charAt(i).toUpperCase(), 0);
2021-10-29 13:37:38 +00:00
if (c != -1) {
buf <<= 5;
buf |= c;
bitcount += 5;
if (bitcount >= 8) {
retstr += String.fromCharCode(buf >> (bitcount - 8));
buf &= (0xFF >> (16 - bitcount));
bitcount -= 8;
}
}
}
if (bitcount > 0) {
retstr += String.fromCharCode(buf << (8 - bitcount));
}
var retbuf = new Uint8Array(retstr.length);
for (i in retstr) {
retbuf[i] = retstr.charCodeAt(i);
}
return retbuf;
}
function do_hmac(key, message, algo) {
2021-11-09 15:24:05 +00:00
var a = algos[algo];
2021-10-29 13:37:38 +00:00
// RFC2104
2021-11-09 15:24:05 +00:00
if (key.length > a.blksz) {
key = a.sha(key);
2021-10-29 13:37:38 +00:00
}
2021-11-09 15:24:05 +00:00
var istr = new Uint8Array(a.blksz + message.length);
var ostr = new Uint8Array(a.blksz + a.retsz);
for (var i = 0; i < a.blksz; ++i) {
var c = (i < key.length) ? key[i] : 0;
2021-10-29 13:37:38 +00:00
istr[i] = c ^ 0x36;
ostr[i] = c ^ 0x5C;
}
2021-11-09 15:24:05 +00:00
istr.set(message, a.blksz);
ostr.set(a.sha(istr), a.blksz);
var ret = a.sha(ostr);
2021-10-29 13:37:38 +00:00
// RFC4226 dynamic truncation
var v = new DataView(ret, ret[ret.length - 1] & 0x0F, 4);
return v.getUint32(0) & 0x7FFFFFFF;
}
2021-11-12 16:58:50 +00:00
function hotp(token) {
var tick;
2021-10-29 13:37:38 +00:00
var d = new Date();
2021-11-12 16:58:50 +00:00
if (token.period > 0) {
// RFC6238 - timed
var seconds = Math.floor(d.getTime() / 1000);
tick = Math.floor(seconds / token.period);
} else {
// RFC4226 - counter
tick = -token.period;
}
2021-10-29 13:37:38 +00:00
var msg = new Uint8Array(8);
var v = new DataView(msg.buffer);
v.setUint32(0, tick >> 16 >> 16);
v.setUint32(4, tick & 0xFFFFFFFF);
2021-11-12 16:58:50 +00:00
var hash = do_hmac(b32decode(token.secret), msg, token.algorithm.toUpperCase());
var ret = "" + hash % Math.pow(10, token.digits);
while (ret.length < token.digits) {
2021-10-29 13:37:38 +00:00
ret = "0" + ret;
}
2021-11-12 16:58:50 +00:00
return {hotp:ret, next:((token.period > 0) ? ((tick + 1) * token.period * 1000) : d.getTime() + 30000)};
2021-10-29 13:37:38 +00:00
}
var state = {
listy: 0,
curtoken:-1,
nextTime:0,
otp:"",
2021-11-12 16:58:50 +00:00
rem:0,
hide:0
2021-10-29 13:37:38 +00:00
};
function drawToken(id, r) {
var x1 = r.x;
var y1 = r.y;
var x2 = r.x + r.w - 1;
var y2 = r.y + r.h - 1;
2021-11-13 04:04:30 +00:00
var adj;
g.setClipRect(Math.max(x1, Bangle.appRect.x ), Math.max(y1, Bangle.appRect.y ),
Math.min(x2, Bangle.appRect.x2), Math.min(y2, Bangle.appRect.y2));
2021-10-29 13:37:38 +00:00
if (id == state.curtoken) {
// current token
g.setColor(g.theme.fgH);
g.setBgColor(g.theme.bgH);
2021-11-09 15:24:05 +00:00
g.setFont("Vector", 16);
2021-10-29 13:37:38 +00:00
// center just below top line
g.setFontAlign(0, -1, 0);
2021-11-13 04:04:30 +00:00
adj = y1;
2021-10-29 13:37:38 +00:00
} else {
g.setColor(g.theme.fg);
g.setBgColor(g.theme.bg);
2021-11-09 15:24:05 +00:00
g.setFont("Vector", 30);
2021-10-29 13:37:38 +00:00
// center in box
g.setFontAlign(0, 0, 0);
2021-11-13 04:04:30 +00:00
adj = (y1 + y2) / 2;
2021-10-29 13:37:38 +00:00
}
g.clearRect(x1, y1, x2, y2);
2021-11-13 04:04:30 +00:00
g.drawString(tokens[id].label, (x1 + x2) / 2, adj, false);
2021-10-29 13:37:38 +00:00
if (id == state.curtoken) {
2021-11-13 04:04:30 +00:00
if (tokens[id].period > 0) {
// timed - draw progress bar
let xr = Math.floor(Bangle.appRect.w * state.rem / tokens[id].period);
g.fillRect(x1, y2 - 4, xr, y2 - 1);
adj = 0;
} else {
// counter - draw triangle as swipe hint
let yc = (y1 + y2) / 2;
g.fillPoly([0, yc, 10, yc - 10, 10, yc + 10, 0, yc]);
adj = 5;
}
2021-10-29 13:37:38 +00:00
// digits just below label
2021-11-13 04:04:30 +00:00
g.setFont("Vector", (tokens[id].digits > 8) ? 26 : 30);
g.drawString(state.otp, (x1 + x2) / 2 + adj, y1 + 16, false);
2021-10-29 13:37:38 +00:00
}
// shaded lines top and bottom
2021-11-13 04:04:30 +00:00
g.setColor(0.5, 0.5, 0.5);
2021-10-29 13:37:38 +00:00
g.drawLine(x1, y1, x2, y1);
g.drawLine(x1, y2, x2, y2);
g.setClipRect(0, 0, g.getWidth(), g.getHeight());
2021-10-29 13:37:38 +00:00
}
function draw() {
2021-11-12 16:58:50 +00:00
var d = new Date();
2021-10-29 13:37:38 +00:00
if (state.curtoken != -1) {
var t = tokens[state.curtoken];
if (d.getTime() > state.nextTime) {
2021-11-12 16:58:50 +00:00
if (state.hide == 0) {
// auto-hide the current token
state.curtoken = -1;
2021-10-29 13:37:38 +00:00
state.nextTime = 0;
2021-11-12 16:58:50 +00:00
} else {
// time to generate a new token
try {
var r = hotp(t);
state.nextTime = r.next;
state.otp = r.hotp;
if (t.period <= 0) {
state.hide = 1;
}
} catch (err) {
state.nextTime = 0;
state.otp = "Not supported";
}
state.hide--;
2021-10-29 13:37:38 +00:00
}
}
state.rem = Math.max(0, Math.floor((state.nextTime - d.getTime()) / 1000));
}
if (tokens.length > 0) {
var drewcur = false;
var id = Math.floor(state.listy / tokenentryheight);
var y = id * tokenentryheight + Bangle.appRect.y - state.listy;
while (id < tokens.length && y < Bangle.appRect.y2) {
drawToken(id, {x:Bangle.appRect.x, y:y, w:Bangle.appRect.w, h:tokenentryheight});
2021-11-12 16:58:50 +00:00
if (id == state.curtoken && (tokens[id].period <= 0 || state.nextTime != 0)) {
2021-10-29 13:37:38 +00:00
drewcur = true;
}
id += 1;
y += tokenentryheight;
}
if (drewcur) {
2021-11-12 16:58:50 +00:00
// the current token has been drawn - draw it again in 1sec
2021-10-29 13:37:38 +00:00
if (state.drawtimer) {
clearTimeout(state.drawtimer);
}
2021-11-12 16:58:50 +00:00
state.drawtimer = setTimeout(draw, (tokens[state.curtoken].period > 0) ? 1000 : state.nexttime - d.getTime());
if (tokens[state.curtoken].period <= 0) {
state.hide = 0;
}
} else {
// de-select the current token if it is scrolled out of view
state.curtoken = -1;
state.nexttime = 0;
2021-10-29 13:37:38 +00:00
}
} else {
2021-11-09 15:24:05 +00:00
g.setFont("Vector", 30);
2021-10-29 13:37:38 +00:00
g.setFontAlign(0, 0, 0);
g.drawString("No tokens", Bangle.appRect.x + Bangle.appRect.w / 2,Bangle.appRect.y + Bangle.appRect.h / 2, false);
2021-10-29 13:37:38 +00:00
}
}
function onTouch(zone, e) {
var id = Math.floor((state.listy + (e.y - Bangle.appRect.y)) / tokenentryheight);
2021-10-29 13:37:38 +00:00
if (id == state.curtoken) {
id = -1;
}
if (state.curtoken != id) {
if (id != -1) {
var y = id * tokenentryheight - state.listy;
if (y < 0) {
state.listy += y;
y = 0;
}
y += tokenentryheight;
if (y > Bangle.appRect.h) {
state.listy += (y - Bangle.appRect.h);
2021-10-29 13:37:38 +00:00
}
}
state.nextTime = 0;
state.curtoken = id;
2021-11-12 16:58:50 +00:00
state.hide = 2;
2021-10-29 13:37:38 +00:00
draw();
}
}
function onDrag(e) {
if (e.x > g.getWidth() || e.y > g.getHeight()) return;
if (e.dx == 0 && e.dy == 0) return;
var newy = Math.min(state.listy - e.dy, tokens.length * tokenentryheight - Bangle.appRect.h);
newy = Math.max(0, newy);
2021-10-29 13:37:38 +00:00
if (newy != state.listy) {
state.listy = newy;
draw();
}
}
function onSwipe(e) {
if (e == 1) {
Bangle.showLauncher();
}
2021-11-12 16:58:50 +00:00
if (e == -1 && state.curtoken != -1 && tokens[state.curtoken].period <= 0) {
tokens[state.curtoken].period--;
require("Storage").writeJSON("authentiwatch.json", tokens);
state.nextTime = 0;
state.hide = 2;
draw();
}
2021-10-29 13:37:38 +00:00
}
Bangle.on('touch', onTouch);
Bangle.on('drag' , onDrag );
Bangle.on('swipe', onSwipe);
Bangle.loadWidgets();
2021-10-29 13:37:38 +00:00
// Clear the screen once, at startup
g.clear();
draw();
Bangle.drawWidgets();