Make sure the ID is not used when uploading a file

This commit is contained in:
yflory 2018-05-28 16:57:20 +02:00
parent 586193d6a1
commit 8aac7bad45

View File

@ -1,8 +1,9 @@
define([ define([
'/file/file-crypto.js', '/file/file-crypto.js',
'/common/common-hash.js', '/common/common-hash.js',
'/bower_components/nthen/index.js',
'/bower_components/tweetnacl/nacl-fast.min.js', '/bower_components/tweetnacl/nacl-fast.min.js',
], function (FileCrypto, Hash) { ], function (FileCrypto, Hash, nThen) {
var Nacl = window.nacl; var Nacl = window.nacl;
var module = {}; var module = {};
@ -14,89 +15,106 @@ define([
var path = file.path; var path = file.path;
var password = file.password; var password = file.password;
var hash = Hash.createRandomHash('file', password); var hash, secret, key, id, href;
var secret = Hash.getSecrets('file', hash, password);
var key = secret.keys.cryptKey;
var id = secret.channel;
// XXX check id here (getFileSize) var getNewHash = function () {
hash = Hash.createRandomHash('file', password);
secret = Hash.getSecrets('file', hash, password);
key = secret.keys.cryptKey;
id = secret.channel;
href = '/file/#' + hash;
};
var next = FileCrypto.encrypt(u8, metadata, key); var getValidHash = function (cb) {
getNewHash();
var estimate = FileCrypto.computeEncryptedSize(u8.length, metadata); common.getFileSize(href, password, function (err, size) {
if (err || typeof(size) !== "number") { throw new Error(err || "Invalid size!"); }
var sendChunk = function (box, cb) { if (size === 0) { return void cb(); }
var enc = Nacl.util.encodeBase64(box); getValidHash();
common.uploadChunk(enc, function (e, msg) {
cb(e, msg);
}); });
}; };
var actual = 0; nThen(function (waitFor) {
var again = function (err, box) { // Generate a hash and check if the resulting id is valid (not already used)
if (err) { throw new Error(err); } getValidHash(waitFor());
if (box) { }).nThen(function () {
actual += box.length; var next = FileCrypto.encrypt(u8, metadata, key);
var progressValue = (actual / estimate * 100);
updateProgress(progressValue);
return void sendChunk(box, function (e) { var estimate = FileCrypto.computeEncryptedSize(u8.length, metadata);
if (e) { return console.error(e); }
next(again); var sendChunk = function (box, cb) {
var enc = Nacl.util.encodeBase64(box);
common.uploadChunk(enc, function (e, msg) {
cb(e, msg);
}); });
} };
if (actual !== estimate) { var actual = 0;
console.error('Estimated size does not match actual size'); var again = function (err, box) {
} if (err) { throw new Error(err); }
if (box) {
actual += box.length;
var progressValue = (actual / estimate * 100);
updateProgress(progressValue);
// if not box then done return void sendChunk(box, function (e) {
common.uploadComplete(id, function (e) { if (e) { return console.error(e); }
if (e) { return void console.error(e); }
var uri = ['', 'blob', id.slice(0,2), id].join('/');
console.log("encrypted blob is now available as %s", uri);
var href = '/file/#' + hash;
var title = metadata.name;
if (noStore) { return void onComplete(href); }
var data = {
title: title || "",
href: href,
path: path,
password: password,
channel: id
};
common.setPadTitle(data, function (err) {
if (err) { return void console.error(err); }
onComplete(href);
common.setPadAttribute('fileType', metadata.type, null, href);
});
});
};
common.uploadStatus(estimate, function (e, pending) {
if (e) {
console.error(e);
onError(e);
return;
}
if (pending) {
return void onPending(function () {
// if the user wants to cancel the pending upload to execute that one
common.uploadCancel(estimate, function (e) {
if (e) {
return void console.error(e);
}
next(again); next(again);
}); });
}
if (actual !== estimate) {
console.error('Estimated size does not match actual size');
}
// if not box then done
common.uploadComplete(id, function (e) {
if (e) { return void console.error(e); }
var uri = ['', 'blob', id.slice(0,2), id].join('/');
console.log("encrypted blob is now available as %s", uri);
var title = metadata.name;
if (noStore) { return void onComplete(href); }
var data = {
title: title || "",
href: href,
path: path,
password: password,
channel: id
};
common.setPadTitle(data, function (err) {
if (err) { return void console.error(err); }
onComplete(href);
common.setPadAttribute('fileType', metadata.type, null, href);
});
}); });
} };
next(again);
common.uploadStatus(estimate, function (e, pending) {
if (e) {
console.error(e);
onError(e);
return;
}
if (pending) {
return void onPending(function () {
// if the user wants to cancel the pending upload to execute that one
common.uploadCancel(estimate, function (e) {
if (e) {
return void console.error(e);
}
next(again);
});
});
}
next(again);
});
}); });
}; };
return module; return module;
}); });