Compare commits

..
Author SHA1 Message Date
1576062160 Update Rust crate ecdsa to 0.17.0
Some checks failed
renovate/artifacts Artifact file update failure
Build and Test / account (push) Failing after 1m51s
2026-07-05 20:30:56 +00:00
2c7767124e switch to using nex-account for nex account management
All checks were successful
Build and Test / account (push) Successful in 23m46s
2026-07-05 22:13:51 +02:00
3c3b8bf91c Merge pull request 'Fix default account level' (#70) from fix-tester-bug into main
All checks were successful
Build and Test / account (push) Successful in 3m3s
Reviewed-on: #70
2026-07-05 11:14:07 +02:00
18da6e247b Fix default account level
All checks were successful
Build and Test / account (push) Successful in 3m3s
2026-07-05 01:47:37 +02:00
f7d6b3ebf0 sqlx prepare
All checks were successful
Build and Test / account (push) Successful in 2m52s
2026-07-04 20:52:24 +02:00
ea5f9d1c13 simple ban system for admins (to be replaced later)
Some checks failed
Build and Test / account (push) Failing after 1m15s
2026-07-04 19:26:28 +02:00
13 changed files with 1424 additions and 1136 deletions

View file

@ -1,2 +1,5 @@
[target.'cfg(target_arch = "x86_64")']
rustflags = ["-C", "target-feature=+aes,+sse2"]
[registries]
spbr = { index = "sparse+https://crates.spbr.net/api/v1/crates/" }

View file

@ -0,0 +1,15 @@
{
"db_name": "PostgreSQL",
"query": "UPDATE users SET account_level = $1 WHERE username = $2",
"describe": {
"columns": [],
"parameters": {
"Left": [
"Int4",
"Text"
]
},
"nullable": []
},
"hash": "9d41e04076235e9a8c857c58c6f5fe7b26cba4da50ce8527ba32128152a31ce6"
}

View file

@ -1,64 +0,0 @@
{
"db_name": "PostgreSQL",
"query": "SELECT game_server_id, maintenance_mode, address, port FROM nex_servers WHERE title_id = $1",
"describe": {
"columns": [
{
"ordinal": 0,
"name": "game_server_id",
"type_info": "Varchar",
"origin": {
"Table": {
"table": "nex_servers",
"name": "game_server_id"
}
}
},
{
"ordinal": 1,
"name": "maintenance_mode",
"type_info": "Bool",
"origin": {
"Table": {
"table": "nex_servers",
"name": "maintenance_mode"
}
}
},
{
"ordinal": 2,
"name": "address",
"type_info": "Inet",
"origin": {
"Table": {
"table": "nex_servers",
"name": "address"
}
}
},
{
"ordinal": 3,
"name": "port",
"type_info": "Int4",
"origin": {
"Table": {
"table": "nex_servers",
"name": "port"
}
}
}
],
"parameters": {
"Left": [
"Text"
]
},
"nullable": [
false,
false,
false,
false
]
},
"hash": "e3349c0e5ab82bbef359cf573caf454f23588f3cfa27299e58863dc9397d55de"
}

1992
Cargo.lock generated

File diff suppressed because it is too large Load diff

View file

@ -55,3 +55,4 @@ dsa = "0.6.3"
openssl = {version = "0.10.78", features = ["vendored"]}
time = "0.3.47"
hickory-resolver = { version = "0.24", features = ["tokio-runtime"] }
nex-account = { version = "0.2.3", registry = "spbr" }

View file

@ -0,0 +1,39 @@
use rocket::serde::json::Json;
use rocket::{post, FromForm, State};
use rocket::form::Form;
use rocket::futures::TryFutureExt;
use rocket::http::Status;
use crate::account::account::Auth;
use crate::json_api::oauth::generate_token::TokenRequest;
use crate::nnid::people::{build_oauth_profile, GetOwnOAuthProfileData};
use crate::Pool;
#[derive(FromForm)]
pub struct AdminRequest<'r> {
pub username: &'r str,
}
#[post("/api/v2/admin/ban", data = "<request>")]
pub async fn ban_user(pool: &State<Pool>, auth: Auth<true>, request: Form<AdminRequest<'_>>) -> Result<(), Status> {
if auth.account_level < 2 {
return Err(Status::Forbidden);
};
log::info!("banning user {:?} from moderator {:?}", request.username, auth.username);
let row = sqlx::query!(
"UPDATE users SET account_level = $1 WHERE username = $2",
-1,
request.username
)
.execute(pool.inner())
.await
.map_err(|e| {
log::error!("failed to execute query: {:?}", e);
return Err::<(), rocket::http::Status>(Status::InternalServerError);
});
log::info!("banned user {:?}", request.username);
Ok(())
}

View file

@ -0,0 +1 @@
pub mod bans;

View file

@ -1,2 +1,3 @@
pub mod oauth;
pub mod users;
pub mod admin;

View file

@ -41,10 +41,7 @@ pub fn verify_nintendo_password(pid: i32, text_password: &str, db_bcrypt_hash: &
sha.update(&[0x02, 0x65, 0x43, 0x46]);
sha.update(text_password.as_bytes());
let hashed_password_hex = hex::encode(sha.finalize());
match bcrypt::verify(hashed_password_hex, db_bcrypt_hash) {
Ok(valid) => valid,
Err(_) => false,
}
bcrypt::verify(hashed_password_hex, db_bcrypt_hash).unwrap_or_else(|_| false)
}
// dummy error responses

View file

@ -118,6 +118,7 @@ async fn launch() -> _ {
json_api::users::delete::delete_account,
json_api::oauth::authorize::authorize_page,
json_api::oauth::authorize::authorize_submit,
json_api::admin::bans::ban_user,
nnid::people::thing,
// graphql::graphiql,
// graphql::playground,

View file

@ -1,31 +1,30 @@
#![allow(unused)]
use chrono::{NaiveDate, NaiveDateTime};
use gxhash::{gxhash32, gxhash64};
use rocket::{get, post, put, State};
use rocket::serde::{Deserialize, Serialize};
use crate::Pool;
use crate::account::account::{Auth, User, generate_nex_password, generate_password};
use crate::dsresponse::Ds;
use crate::error::{Error, Errors};
use crate::nnid::pid_distribution::next_pid;
use crate::nnid::timezones::{OFFSET_FROM_TIMEZONE};
use crate::Pool;
use crate::xml::{Xml, YesNoVal};
use crate::email::send_verification_email;
use rand::prelude::*;
use crate::error::{Error, Errors};
use crate::mii_util::get_mii_img_url;
use crate::nnid::timezones::OFFSET_FROM_TIMEZONE;
use crate::xml::{Xml, YesNoVal};
use chrono::{NaiveDate, NaiveDateTime};
use gxhash::{gxhash32, gxhash64};
use nex_account::grpc::{ActStageInfo, ActStageReturn};
use nex_account::grpc_client;
use rand::prelude::*;
use rocket::serde::{Deserialize, Serialize};
use rocket::{State, get, post, put};
const DATABASE_ERROR: Errors = Errors {
error: &[
Error{
error: &[Error {
code: "9999",
message: "Internal server error"
}
]
message: "Internal server error",
}],
};
#[derive(Deserialize)]
pub struct Email {
address: Box<str>
address: Box<str>,
}
#[derive(Deserialize)]
@ -56,24 +55,38 @@ pub struct AccountCreationData{
gender: Box<str>,
marketing_flag: YesNoVal,
off_device_flag: YesNoVal,
region: i32
region: i32,
}
#[derive(Serialize)]
#[serde(rename(serialize = "person"))]
pub struct AccountCreationResponseData {
pid: i32
pid: i32,
}
#[post("/v1/api/people", data = "<data>")]
pub async fn create_account(database: &State<Pool>, data: Xml<AccountCreationData>) -> Result<Xml<AccountCreationResponseData>, Option<Errors<'_>>>{
pub async fn create_account(
database: &State<Pool>,
data: Xml<AccountCreationData>,
) -> Result<Xml<AccountCreationResponseData>, Option<Errors<'_>>> {
let database = database.inner();
let nex_password = generate_nex_password();
let mut client = grpc_client().await.expect("unable to connect to grpc");
let Ok(ret) = client
.stage_new_account(ActStageInfo {
password: nex_password.clone().into_bytes(),
})
.await
else {
return Err(Some(DATABASE_ERROR));
};
let ActStageReturn { pid, .. } = ret.into_inner();
// its fine to crash here if we cant get the next pid as that is in my opinion a dead state
// anyways as noone can register anymore, EVER
let pid = next_pid(database).await;
let verification_code: i32 = rand::rng().random_range(100_000..1_000_000);
let AccountCreationData {
@ -82,14 +95,8 @@ pub async fn create_account(database: &State<Pool>, data: Xml<AccountCreationDat
birth_date,
tz_name,
language,
email: Email{
address
},
mii: Mii{
name,
data,
..
},
email: Email { address },
mii: Mii { name, data, .. },
marketing_flag,
gender,
region,
@ -101,14 +108,13 @@ pub async fn create_account(database: &State<Pool>, data: Xml<AccountCreationDat
let account_level = if user_id.to_lowercase().contains("omey") {
-1
} else {
1
0
};
let password = generate_password(pid, &password).ok_or(None)?;
let nex_password = generate_nex_password();
sqlx::query!("
sqlx::query!(
"
INSERT INTO users (
pid,
username,
@ -146,19 +152,20 @@ pub async fn create_account(database: &State<Pool>, data: Xml<AccountCreationDat
verification_code,
account_level,
nex_password
).execute(database).await.unwrap();
)
.execute(database)
.await
.unwrap();
//generate_s3_images(pid, &data).await;
if let Err(e) = send_verification_email(address.as_ref(), verification_code, user_id.as_ref()).await {
if let Err(e) =
send_verification_email(address.as_ref(), verification_code, user_id.as_ref()).await
{
println!("Failed to send verification email: {e}");
}
Ok(
Xml(AccountCreationResponseData{
pid
})
)
Ok(Xml(AccountCreationResponseData { pid }))
}
// #[derive(Serialize)]
@ -177,7 +184,7 @@ struct EmailInfoOwnProfileData{
email_type: String,
updated_by: String,
validated: YesNoVal,
validated_date: Option<NaiveDateTime>
validated_date: Option<NaiveDateTime>,
}
#[derive(Serialize)]
@ -191,7 +198,7 @@ struct EmailInfoOwnOAuthProfileData{
email_type: String,
updated_by: String,
validated: bool,
validated_date: Option<NaiveDateTime>
validated_date: Option<NaiveDateTime>,
}
#[derive(Serialize)]
@ -200,13 +207,12 @@ struct MiiImage{
id: u32,
url: String,
#[serde(rename = "type")]
image_type: String
image_type: String,
}
#[derive(Serialize)]
struct MiiImages {
mii_image: MiiImage
mii_image: MiiImage,
}
#[derive(Serialize)]
@ -217,11 +223,9 @@ struct MiiDataOwnProfileData{
mii_hash: String,
mii_images: MiiImages,
name: String,
primary: YesNoVal
primary: YesNoVal,
}
#[derive(Serialize)]
#[serde(rename(serialize = "person"))]
pub struct GetOwnProfileData {
@ -314,7 +318,6 @@ pub fn build_profile(user: User) -> GetOwnProfileData {
.replace("\r", "")
.replace(" ", "");
GetOwnProfileData {
active_flag: YesNoVal(true),
pid,
@ -341,7 +344,7 @@ pub fn build_profile(user: User) -> GetOwnProfileData {
mii: MiiDataOwnProfileData {
id: gxhash32(mii_data.as_bytes(), 0),
mii_hash: hex::encode(bytemuck::bytes_of(
&(gxhash64(mii_data.as_bytes(), 1) & !(0x1000000000000000))
&(gxhash64(mii_data.as_bytes(), 1) & !(0x1000000000000000)),
)),
name: crate::mii_util::MiiData::read(&mii_data)
.map(|v| v.name)
@ -359,8 +362,8 @@ pub fn build_profile(user: User) -> GetOwnProfileData {
url: image_url.clone(),
cached_url: image_url,
}
}
}
},
},
},
off_device_flag: YesNoVal(off_device_allowed),
region,
@ -404,7 +407,6 @@ pub fn build_oauth_profile(user: User) -> GetOwnOAuthProfileData {
.replace("\r", "")
.replace(" ", "");
GetOwnOAuthProfileData {
id,
sub,
@ -434,7 +436,7 @@ pub fn build_oauth_profile(user: User) -> GetOwnOAuthProfileData {
mii: MiiDataOwnProfileData {
id: gxhash32(mii_data.as_bytes(), 0),
mii_hash: hex::encode(bytemuck::bytes_of(
&(gxhash64(mii_data.as_bytes(), 1) & !(0x1000000000000000))
&(gxhash64(mii_data.as_bytes(), 1) & !(0x1000000000000000)),
)),
name: crate::mii_util::MiiData::read(&mii_data)
.map(|v| v.name)
@ -452,8 +454,8 @@ pub fn build_oauth_profile(user: User) -> GetOwnOAuthProfileData {
url: image_url.clone(),
cached_url: image_url,
}
}
}
},
},
},
off_device_flag: off_device_allowed,
region,
@ -492,8 +494,5 @@ pub async fn change_mii(
Ok(())
}
#[post("/v1/api/people/@me/agreements")]
pub async fn thing(){
}
pub async fn thing() {}

View file

@ -1,5 +1,6 @@
#![deprecated = "handled by nex-account now"]
/*
use crate::Pool;
pub async fn next_pid(pool: &Pool) -> i32{
loop {
let next_pid = sqlx::query!("SELECT nextval('pid_counter') as pid")
@ -27,3 +28,4 @@ pub async fn next_pid(pool: &Pool) -> i32{
}
*/

View file

@ -1,51 +1,44 @@
use std::net::Ipv4Addr;
use rocket::{get, State};
use serde::Serialize;
use sqlx::types::ipnetwork::IpNetwork::V4;
use crate::Pool;
use crate::account::account::Auth;
use crate::error::{Error, Errors};
use crate::nnid::oauth::generate_token::{create_token};
use crate::nnid::oauth::generate_token::create_token;
use crate::nnid::oauth::generate_token::token_type::NEX_TOKEN;
use crate::Pool;
use crate::xml::Xml;
use nex_account::grpc::Pid;
use reqwest::header::SERVER;
use rocket::{State, get};
use serde::Serialize;
use sqlx::types::ipnetwork::IpNetwork::V4;
use std::net::Ipv4Addr;
const NO_IPV4_ERROR: Errors = Errors {
error: &[
Error{
error: &[Error {
code: "1022",
message: "Server is not a valid IPv4 address"
}
]
message: "Server is not a valid IPv4 address",
}],
};
const SERVER_ERROR: Errors = Errors {
error: &[
Error{
error: &[Error {
code: "9999",
message: "Internal Server Error"
}
]
message: "Internal Server Error",
}],
};
const NO_SERVER_ERROR: Errors = Errors {
error: &[
Error{
error: &[Error {
code: "1021",
message: "The requested game server was not found"
}
]
message: "The requested game server was not found",
}],
};
const MAINTENANCE_ERROR: Errors = Errors {
error: &[
Error{
error: &[Error {
code: "2002",
message: "The requested game server is under maintenance"
}
]
message: "The requested game server is under maintenance",
}],
};
#[derive(Serialize)]
#[serde(rename = "nex_token")]
pub struct NexToken {
@ -53,17 +46,20 @@ pub struct NexToken{
nex_password: String,
pid: i32,
port: u16,
token: String
token: Box<str>,
}
#[derive(Serialize)]
#[serde(rename = "service_token")]
pub struct ServiceToken {
token: String
token: String,
}
#[get("/v1/api/provider/service_token/@me")]
pub async fn get_service_token(pool: &State<Pool>, auth: Auth<true, false>) -> Result<Xml<ServiceToken>, Option<Errors<'static>>>{
pub async fn get_service_token(
pool: &State<Pool>,
auth: Auth<true, false>,
) -> Result<Xml<ServiceToken>, Option<Errors<'static>>> {
// just gonna put this here as a side note for the future:
// we could also be using key derivation to derive the nex token as if it were a key
// that way we could reduce the data the database needs to store and also reduce the transfer
@ -75,17 +71,15 @@ pub async fn get_service_token(pool: &State<Pool>, auth: Auth<true, false>) -> R
let token = create_token(pool, auth.pid, NEX_TOKEN, None).await;
Ok(
Xml(
ServiceToken{
token
}
)
)
Ok(Xml(ServiceToken { token }))
}
#[get("/v1/api/provider/nex_token/@me?<game_server_id>")]
pub async fn get_nex_token(pool: &State<Pool>, auth: Auth<true, false>, game_server_id: &str) -> Result<Xml<NexToken>, Option<Errors<'static>>>{
pub async fn get_nex_token(
pool: &State<Pool>,
auth: Auth<true, false>,
game_server_id: &str,
) -> Result<Xml<NexToken>, Option<Errors<'static>>> {
// just gonna put this here as a side note for the future:
// we could also be using key derivation to derive the nex token as if it were a key
// that way we could reduce the data the database needs to store and also reduce the transfer
@ -110,26 +104,35 @@ pub async fn get_nex_token(pool: &State<Pool>, auth: Auth<true, false>, game_ser
}; // only crash on db failure (not missing row)
if server.maintenance_mode {
return Err(Some(MAINTENANCE_ERROR))
return Err(Some(MAINTENANCE_ERROR));
}
let token = create_token(pool, auth.pid, NEX_TOKEN, None).await;
let V4(host) = server.address else {
return Err(Some(NO_IPV4_ERROR));
};
let host = host.ip();
Ok(
Xml(
NexToken{
let mut client = nex_account::grpc_client().await.unwrap();
let Ok(key) = client.get_nex_key_by_pid(Pid { pid: auth.pid }).await else {
println!("account does not exist on nex-account server");
return Err(Some(SERVER_ERROR));
};
let token = nex_account::gen_nexact_token(
auth.pid,
key.into_inner()
.key
.try_into()
.map_err(|_| Some(SERVER_ERROR))?,
)
.expect("NEX_ACCOUNT_KEYPAIR not set");
Ok(Xml(NexToken {
host,
port: server.port as u16,
nex_password: auth.nex_password.clone(),
pid: auth.pid,
token
}
)
)
token,
}))
}