|
1 |
| -window.addEventListener("message", receiveMessage, false); |
| 1 | +/** |
| 2 | + * bcrypt |
| 3 | + */ |
| 4 | + |
| 5 | +var bcrypt = dcodeIO.bcrypt; |
| 6 | + |
| 7 | + |
| 8 | +/** |
| 9 | + * Handle RP Message |
| 10 | + */ |
2 | 11 |
|
3 |
| -function receiveMessage(e){ // e has client_id and session_state |
| 12 | +function receiveMessage (e) { |
4 | 13 |
|
5 | 14 | // Validate message origin
|
6 |
| - client_id = e.data.split(' ')[0]; |
7 |
| - session_state = e.data.split(' ')[1]; |
8 |
| - var salt = session_state.split('.')[1]; |
| 15 | + var origin = e.origin; |
| 16 | + var parser = document.createElement('a'); |
| 17 | + parser.href = document.referrer; |
| 18 | + messenger = parser.protocol + '//' + parser.host; |
| 19 | + if (origin !== messenger) { |
| 20 | + return; // Ignore the message |
| 21 | + } |
| 22 | + |
| 23 | + // Validate message syntax |
| 24 | + var parts = e.data.split(' '); |
| 25 | + var client_id = parts[0]; |
| 26 | + var session_state = parts[1]; |
| 27 | + var salt = parts[2]; |
9 | 28 |
|
10 |
| - // if message syntactically invalid |
11 |
| - // postMessage('error', e.origin) and return |
| 29 | + if (parts.length !== 3) { |
| 30 | + e.source.postMessage('error', origin); |
| 31 | + } |
12 | 32 |
|
13 | 33 | // get_op_browser_state() is an OP defined function
|
14 | 34 | // that returns the browser's login status at the OP.
|
15 | 35 | // How it is done is entirely up to the OP.
|
16 |
| - var opbs = get_op_browser_state(); |
| 36 | + //var opbs = get_op_browser_state(); |
| 37 | + var opbs = 'authenticated'; |
17 | 38 |
|
18 | 39 | // Here, the session_state is calculated in this particular way,
|
19 | 40 | // but it is entirely up to the OP how to do it under the
|
20 | 41 | // requirements defined in this specification.
|
21 |
| - var ss = CryptoJS.SHA256(client_id + ' ' + e.origin + ' ' + |
22 |
| - opbs + [' ' + salt]) [+ "." + salt]; |
| 42 | + //var ss = CryptoJS.SHA256(client_id + ' ' + e.origin + ' ' + |
| 43 | + // opbs + [' ' + salt]) [+ "." + salt]; |
| 44 | + var value = [client_id, origin, opbs, salt].join(' ') |
| 45 | + var hash = bcrypt.hashSync(value, salt); |
23 | 46 |
|
24 |
| - if (e.session_state == ss) { |
25 |
| - stat = 'unchanged'; |
26 |
| - } else { |
27 |
| - stat = 'changed'; |
28 |
| - } |
29 |
| - |
30 |
| - e.source.postMessage(stat, e.origin); |
| 47 | + e.source.postMessage( |
| 48 | + (hash === session_state) ? 'unchanged' : 'changed' , origin |
| 49 | + ); |
31 | 50 | };
|
| 51 | + |
| 52 | + |
| 53 | +/** |
| 54 | + * Register Listener |
| 55 | + */ |
| 56 | + |
| 57 | +window.addEventListener("message", receiveMessage, false); |
0 commit comments