|DataResponse * * 200: Authentication credentials returned * 403: Provided nonce is wrong * 412: Getting authentication credentials is not possible */ #[OpenAPI(scope: OpenAPI::SCOPE_IGNORE)] #[PublicPage] #[BruteForceProtection(action: 'hosted-hpb-nonce')] #[RequestHeader(name: 'x-account-service-nonce', description: 'Random string provided to the hostedsignalingserver entity, so it can verify that it was requested')] public function auth(): DataResponse { $sentNonce = $this->request->getHeader('x-account-service-nonce'); if ($sentNonce === '') { $response = new DataResponse(null, Http::STATUS_FORBIDDEN); $response->throttle(); return $response; } $storedNonce = $this->config->getAppValue('spreed', 'hosted-signaling-server-nonce', ''); if ($storedNonce === '') { return new DataResponse(null, Http::STATUS_PRECONDITION_FAILED); } if (!hash_equals($storedNonce, $sentNonce)) { $response = new DataResponse(null, Http::STATUS_FORBIDDEN); $response->throttle(); return $response; } // reset nonce after one request $this->config->deleteAppValue('spreed', 'hosted-signaling-server-nonce'); return new DataResponse([ 'nonce' => $storedNonce, ]); } /** * Request a trial account * * @param string $url Server URL * @param string $name Display name of the user * @param string $email Email of the user * @param string $language Language of the user * @param string $country Country of the user * @return DataResponse, array{}>|DataResponse * * 200: Trial requested successfully * 400: Requesting trial is not possible */ public function requestTrial(string $url, string $name, string $email, string $language, string $country): DataResponse { try { $registerAccountData = new RegisterAccountData( $url, $name, $email, $language, $country ); $accountId = $this->hostedSignalingServerService->registerAccount($registerAccountData); $accountInfo = $this->hostedSignalingServerService->fetchAccountInfo($accountId); $this->config->setAppValue('spreed', 'hosted-signaling-server-account', json_encode($accountInfo)); } catch (HostedSignalingServerAPIException $e) { // API or connection issues return new DataResponse(['message' => $e->getMessage()], Http::STATUS_INTERNAL_SERVER_ERROR); } catch (HostedSignalingServerInputException $e) { // user solvable issues return new DataResponse(['message' => $e->getMessage()], Http::STATUS_BAD_REQUEST); } return new DataResponse($accountInfo); } /** * Delete the account * * @return DataResponse|DataResponse * * 204: Account deleted successfully * 400: Deleting account is not possible */ public function deleteAccount(): DataResponse { $accountId = $this->config->getAppValue('spreed', 'hosted-signaling-server-account-id'); if ($accountId === null) { return new DataResponse(['message' => $this->l10n->t('No account available to delete.')], Http::STATUS_BAD_REQUEST); } try { $this->hostedSignalingServerService->deleteAccount(new AccountId($accountId)); } catch (HostedSignalingServerAPIException $e) { if ($e->getCode() === Http::STATUS_NOT_FOUND) { // Account was deleted, so remove the information locally } else { // API or connection issues - do nothing and just try again later return new DataResponse(['message' => $e->getMessage()], Http::STATUS_INTERNAL_SERVER_ERROR); } } $this->config->deleteAppValue('spreed', 'hosted-signaling-server-account'); $this->config->deleteAppValue('spreed', 'hosted-signaling-server-account-id'); // remove signaling servers if account is not active anymore $this->config->deleteAppValue('spreed', 'signaling_mode'); $this->config->deleteAppValue('spreed', 'signaling_servers'); $this->logger->info('Deleted hosted signaling server account with ID ' . $accountId); return new DataResponse(null, Http::STATUS_NO_CONTENT); } }