1*ab19a69eSdjm /*
2*ab19a69eSdjm * Copyright (c) 2018-2022 Yubico AB. All rights reserved.
3*ab19a69eSdjm * Use of this source code is governed by a BSD-style
4*ab19a69eSdjm * license that can be found in the LICENSE file.
5*ab19a69eSdjm */
6*ab19a69eSdjm
7*ab19a69eSdjm #include <openssl/sha.h>
8*ab19a69eSdjm #include "fido.h"
9*ab19a69eSdjm
10*ab19a69eSdjm int
fido_dev_get_touch_begin(fido_dev_t * dev)11*ab19a69eSdjm fido_dev_get_touch_begin(fido_dev_t *dev)
12*ab19a69eSdjm {
13*ab19a69eSdjm fido_blob_t f;
14*ab19a69eSdjm cbor_item_t *argv[9];
15*ab19a69eSdjm const char *clientdata = FIDO_DUMMY_CLIENTDATA;
16*ab19a69eSdjm const uint8_t user_id = FIDO_DUMMY_USER_ID;
17*ab19a69eSdjm unsigned char cdh[SHA256_DIGEST_LENGTH];
18*ab19a69eSdjm fido_rp_t rp;
19*ab19a69eSdjm fido_user_t user;
20*ab19a69eSdjm int ms = dev->timeout_ms;
21*ab19a69eSdjm int r = FIDO_ERR_INTERNAL;
22*ab19a69eSdjm
23*ab19a69eSdjm memset(&f, 0, sizeof(f));
24*ab19a69eSdjm memset(argv, 0, sizeof(argv));
25*ab19a69eSdjm memset(cdh, 0, sizeof(cdh));
26*ab19a69eSdjm memset(&rp, 0, sizeof(rp));
27*ab19a69eSdjm memset(&user, 0, sizeof(user));
28*ab19a69eSdjm
29*ab19a69eSdjm if (fido_dev_is_fido2(dev) == false)
30*ab19a69eSdjm return (u2f_get_touch_begin(dev, &ms));
31*ab19a69eSdjm
32*ab19a69eSdjm if (SHA256((const void *)clientdata, strlen(clientdata), cdh) != cdh) {
33*ab19a69eSdjm fido_log_debug("%s: sha256", __func__);
34*ab19a69eSdjm return (FIDO_ERR_INTERNAL);
35*ab19a69eSdjm }
36*ab19a69eSdjm
37*ab19a69eSdjm if ((rp.id = strdup(FIDO_DUMMY_RP_ID)) == NULL ||
38*ab19a69eSdjm (user.name = strdup(FIDO_DUMMY_USER_NAME)) == NULL) {
39*ab19a69eSdjm fido_log_debug("%s: strdup", __func__);
40*ab19a69eSdjm goto fail;
41*ab19a69eSdjm }
42*ab19a69eSdjm
43*ab19a69eSdjm if (fido_blob_set(&user.id, &user_id, sizeof(user_id)) < 0) {
44*ab19a69eSdjm fido_log_debug("%s: fido_blob_set", __func__);
45*ab19a69eSdjm goto fail;
46*ab19a69eSdjm }
47*ab19a69eSdjm
48*ab19a69eSdjm if ((argv[0] = cbor_build_bytestring(cdh, sizeof(cdh))) == NULL ||
49*ab19a69eSdjm (argv[1] = cbor_encode_rp_entity(&rp)) == NULL ||
50*ab19a69eSdjm (argv[2] = cbor_encode_user_entity(&user)) == NULL ||
51*ab19a69eSdjm (argv[3] = cbor_encode_pubkey_param(COSE_ES256)) == NULL) {
52*ab19a69eSdjm fido_log_debug("%s: cbor encode", __func__);
53*ab19a69eSdjm goto fail;
54*ab19a69eSdjm }
55*ab19a69eSdjm
56*ab19a69eSdjm if (fido_dev_supports_pin(dev)) {
57*ab19a69eSdjm if ((argv[7] = cbor_new_definite_bytestring()) == NULL ||
58*ab19a69eSdjm (argv[8] = cbor_encode_pin_opt(dev)) == NULL) {
59*ab19a69eSdjm fido_log_debug("%s: cbor encode", __func__);
60*ab19a69eSdjm goto fail;
61*ab19a69eSdjm }
62*ab19a69eSdjm }
63*ab19a69eSdjm
64*ab19a69eSdjm if (cbor_build_frame(CTAP_CBOR_MAKECRED, argv, nitems(argv), &f) < 0 ||
65*ab19a69eSdjm fido_tx(dev, CTAP_CMD_CBOR, f.ptr, f.len, &ms) < 0) {
66*ab19a69eSdjm fido_log_debug("%s: fido_tx", __func__);
67*ab19a69eSdjm r = FIDO_ERR_TX;
68*ab19a69eSdjm goto fail;
69*ab19a69eSdjm }
70*ab19a69eSdjm
71*ab19a69eSdjm r = FIDO_OK;
72*ab19a69eSdjm fail:
73*ab19a69eSdjm cbor_vector_free(argv, nitems(argv));
74*ab19a69eSdjm free(f.ptr);
75*ab19a69eSdjm free(rp.id);
76*ab19a69eSdjm free(user.name);
77*ab19a69eSdjm free(user.id.ptr);
78*ab19a69eSdjm
79*ab19a69eSdjm return (r);
80*ab19a69eSdjm }
81*ab19a69eSdjm
82*ab19a69eSdjm int
fido_dev_get_touch_status(fido_dev_t * dev,int * touched,int ms)83*ab19a69eSdjm fido_dev_get_touch_status(fido_dev_t *dev, int *touched, int ms)
84*ab19a69eSdjm {
85*ab19a69eSdjm int r;
86*ab19a69eSdjm
87*ab19a69eSdjm *touched = 0;
88*ab19a69eSdjm
89*ab19a69eSdjm if (fido_dev_is_fido2(dev) == false)
90*ab19a69eSdjm return (u2f_get_touch_status(dev, touched, &ms));
91*ab19a69eSdjm
92*ab19a69eSdjm switch ((r = fido_rx_cbor_status(dev, &ms))) {
93*ab19a69eSdjm case FIDO_ERR_PIN_AUTH_INVALID:
94*ab19a69eSdjm case FIDO_ERR_PIN_INVALID:
95*ab19a69eSdjm case FIDO_ERR_PIN_NOT_SET:
96*ab19a69eSdjm case FIDO_ERR_SUCCESS:
97*ab19a69eSdjm *touched = 1;
98*ab19a69eSdjm break;
99*ab19a69eSdjm case FIDO_ERR_RX:
100*ab19a69eSdjm /* ignore */
101*ab19a69eSdjm break;
102*ab19a69eSdjm default:
103*ab19a69eSdjm fido_log_debug("%s: fido_rx_cbor_status", __func__);
104*ab19a69eSdjm return (r);
105*ab19a69eSdjm }
106*ab19a69eSdjm
107*ab19a69eSdjm return (FIDO_OK);
108*ab19a69eSdjm }
109