Made NEX accounts unique per-device type

This commit is contained in:
Jonathan Barrow
2022-09-28 18:28:02 -04:00
parent 27a78270cc
commit 5ffd6c5a9d
5 changed files with 30 additions and 27 deletions

View File

@@ -116,13 +116,14 @@ async function NASCMiddleware(request, response, next) {
try {
// Create new NEX account
const nexAccountResult = await NEXAccount.create([{
pid: 0,
password: '',
owning_pid: 0,
device_type: '3ds',
}], { session });
const nexAccount = nexAccountResult[0];
await nexAccount.generatePID();
await nexAccount.generatePassword();
pid = nexAccount.get('pid');
// Set password

View File

@@ -2,10 +2,15 @@ const { Schema, model } = require('mongoose');
const uniqueValidator = require('mongoose-unique-validator');
const NEXAccountSchema = new Schema({
pid: {
type: Number,
unique: true
device_type: {
type: String,
enum: [
// Only track the family here not the model
'wiiu',
'3ds',
]
},
pid: Number,
password: String,
owning_pid: Number,
access_level: {
@@ -18,6 +23,8 @@ const NEXAccountSchema = new Schema({
},
});
NEXAccountSchema.index({ device_type: 1, pid: 1 }, { unique: true })
NEXAccountSchema.plugin(uniqueValidator, { message: '{PATH} already in use.' });
/*
@@ -35,7 +42,8 @@ NEXAccountSchema.methods.generatePID = async function () {
let pid = Math.floor(Math.random() * (max - min + 1) + min);
const inuse = await NEXAccount.findOne({
pid
pid,
device_type: this.get('device_type')
});
pid = (inuse ? await NEXAccount.generatePID() : pid);
@@ -60,16 +68,6 @@ NEXAccountSchema.methods.generatePassword = function () {
this.set('password', output.join(''));
};
NEXAccountSchema.pre('save', async function (next) {
await this.generatePID();
if (this.get('password') === '') {
await this.generatePassword();
}
next();
});
const NEXAccount = model('NEXAccount', NEXAccountSchema);
module.exports = {

View File

@@ -136,7 +136,7 @@ PNIDSchema.methods.generateEmailValidationCode = async function() {
const inuse = await PNID.findOne({
'identification.email_code': code
});
code = (inuse ? await PNID.generateEmailValidationCode() : code);
this.set('identification.email_code', code);

View File

@@ -246,14 +246,17 @@ router.post('/', async (request, response) => {
await session.startTransaction();
try {
// * PNIDs can only be registered from a Wii U
// * So assume website users are WiiU NEX accounts
const nexAccountResult = await NEXAccount.create([{
pid: 0,
password: '',
owning_pid: 0,
device_type: 'wiiu',
}], { session });
nexAccount = nexAccountResult[0];
await nexAccount.generatePID();
await nexAccount.generatePassword();
const primaryPasswordHash = util.nintendoPasswordHash(password, nexAccount.get('pid'));
const passwordHash = await bcrypt.hash(primaryPasswordHash, 10);
@@ -295,7 +298,7 @@ router.post('/', async (request, response) => {
marketing: true, // TODO: Change this
off_device: true // TODO: Change this
},
validation: {
identification: {
email_code: 1, // will be overwritten before saving
email_token: '' // will be overwritten before saving
}
@@ -318,7 +321,7 @@ router.post('/', async (request, response) => {
await session.commitTransaction();
} catch (error) {
logger.error('[POST] /v1/api/people: ' + error);
logger.error('[POST] /v1/register: ' + error);
await session.abortTransaction();

View File

@@ -84,13 +84,14 @@ router.post('/', ratelimit, deviceCertificateMiddleware, async (request, respons
try {
const nexAccountResult = await NEXAccount.create([{
pid: 0,
password: '',
owning_pid: 0,
device_type: 'wiiu',
}], { session });
nexAccount = nexAccountResult[0];
await nexAccount.generatePID();
await nexAccount.generatePassword();
const primaryPasswordHash = util.nintendoPasswordHash(person.get('password'), nexAccount.get('pid'));
const passwordHash = await bcrypt.hash(primaryPasswordHash, 10);
@@ -132,7 +133,7 @@ router.post('/', ratelimit, deviceCertificateMiddleware, async (request, respons
marketing: person.get('marketing_flag') === 'Y',
off_device: person.get('off_device_flag') === 'Y'
},
validation: {
identification: {
email_code: 1, // will be overwritten before saving
email_token: '' // will be overwritten before saving
}