From 3e35cf6980e88c690f7b48989adfc4cbab64e72b Mon Sep 17 00:00:00 2001 From: igor Date: Mon, 9 Dec 2024 19:24:12 +0600 Subject: [PATCH] =?UTF-8?q?=D0=9F=D0=B5=D1=80=D0=B2=D1=8B=D0=B9?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .gitignore | 35 + .mvn/wrapper/maven-wrapper.jar | Bin 0 -> 62547 bytes .mvn/wrapper/maven-wrapper.properties | 2 + README.md | 248 +++ kg_gpti_transit_jwt.properties | 38 + kz_istransit_jwt.properties | 40 + kz_mcp_jwt.properties | 43 + mvnw | 308 ++++ mvnw.cmd | 205 +++ org_ccalm_jwt.properties | 38 + pom.xml | 135 ++ run.sh | 3 + .../java/org/ccalm/jwt/JwtApplication.java | 20 + .../java/org/ccalm/jwt/MainController.java | 1478 +++++++++++++++++ src/main/java/org/ccalm/jwt/Translation.java | 60 + .../java/org/ccalm/jwt/models/ActionName.java | 16 + .../java/org/ccalm/jwt/models/EmailModel.java | 14 + .../java/org/ccalm/jwt/models/ErrorModel.java | 19 + .../java/org/ccalm/jwt/models/LoginModel.java | 36 + .../org/ccalm/jwt/models/NewUserModel.java | 47 + .../org/ccalm/jwt/models/RestoreModel.java | 25 + .../org/ccalm/jwt/models/SettingModel.java | 28 + .../org/ccalm/jwt/models/UpdateModel.java | 42 + .../java/org/ccalm/jwt/models/UserModel.java | 96 ++ src/main/java/org/ccalm/jwt/tools/Cache.java | 63 + .../org/ccalm/jwt/tools/CustomException.java | 30 + .../java/org/ccalm/jwt/tools/DBTools.java | 40 + .../org/ccalm/jwt/tools/EmailUtility.java | 65 + .../java/org/ccalm/jwt/tools/Storage.java | 167 ++ src/main/java/org/ccalm/jwt/tools/Tools.java | 148 ++ src/main/resources/logback-spring.xml | 33 + .../com/geovizor/jwt/JwtApplicationTests.java | 13 + 32 files changed, 3535 insertions(+) create mode 100644 .gitignore create mode 100644 .mvn/wrapper/maven-wrapper.jar create mode 100644 .mvn/wrapper/maven-wrapper.properties create mode 100644 README.md create mode 100644 kg_gpti_transit_jwt.properties create mode 100644 kz_istransit_jwt.properties create mode 100644 kz_mcp_jwt.properties create mode 100644 mvnw create mode 100644 mvnw.cmd create mode 100644 org_ccalm_jwt.properties create mode 100644 pom.xml create mode 100644 run.sh create mode 100644 src/main/java/org/ccalm/jwt/JwtApplication.java create mode 100644 src/main/java/org/ccalm/jwt/MainController.java create mode 100644 src/main/java/org/ccalm/jwt/Translation.java create mode 100644 src/main/java/org/ccalm/jwt/models/ActionName.java create mode 100644 src/main/java/org/ccalm/jwt/models/EmailModel.java create mode 100644 src/main/java/org/ccalm/jwt/models/ErrorModel.java create mode 100644 src/main/java/org/ccalm/jwt/models/LoginModel.java create mode 100644 src/main/java/org/ccalm/jwt/models/NewUserModel.java create mode 100644 src/main/java/org/ccalm/jwt/models/RestoreModel.java create mode 100644 src/main/java/org/ccalm/jwt/models/SettingModel.java create mode 100644 src/main/java/org/ccalm/jwt/models/UpdateModel.java create mode 100644 src/main/java/org/ccalm/jwt/models/UserModel.java create mode 100644 src/main/java/org/ccalm/jwt/tools/Cache.java create mode 100644 src/main/java/org/ccalm/jwt/tools/CustomException.java create mode 100644 src/main/java/org/ccalm/jwt/tools/DBTools.java create mode 100644 src/main/java/org/ccalm/jwt/tools/EmailUtility.java create mode 100644 src/main/java/org/ccalm/jwt/tools/Storage.java create mode 100644 src/main/java/org/ccalm/jwt/tools/Tools.java create mode 100644 src/main/resources/logback-spring.xml create mode 100644 src/test/java/com/geovizor/jwt/JwtApplicationTests.java diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..28b9f53 --- /dev/null +++ b/.gitignore @@ -0,0 +1,35 @@ +HELP.md +target/ +!.mvn/wrapper/maven-wrapper.jar +!**/src/main/**/target/ +!**/src/test/**/target/ + +### STS ### +.apt_generated +.classpath +.factorypath +.project +.settings +.springBeans +.sts4-cache + +### IntelliJ IDEA ### +.idea +*.iws +*.iml +*.ipr + +### NetBeans ### +/nbproject/private/ +/nbbuild/ +/dist/ +/nbdist/ +/.nb-gradle/ +build/ +!**/src/main/**/build/ +!**/src/test/**/build/ + +### VS Code ### +.vscode/ +/logs +/temporary.sqlite diff --git a/.mvn/wrapper/maven-wrapper.jar b/.mvn/wrapper/maven-wrapper.jar new file mode 100644 index 0000000000000000000000000000000000000000..cb28b0e37c7d206feb564310fdeec0927af4123a GIT binary patch literal 62547 zcmb5V1CS=sk~Z9!wr$(CZEL#U=Co~N+O}=mwr$(Cds^S@-Tij=#=rmlVk@E|Dyp8$ z$UKz?`Q$l@GN3=8fq)=^fVx`E)Pern1@-q?PE1vZPD);!LGdpP^)C$aAFx&{CzjH` zpQV9;fd0PyFPNN=yp*_@iYmRFcvOrKbU!1a*o)t$0ex(~3z5?bw11HQYW_uDngyer za60w&wz^`W&Z!0XSH^cLNR&k>%)Vr|$}(wfBzmSbuK^)dy#xr@_NZVszJASn12dw; z-KbI5yz=2awY0>OUF)&crfPu&tVl|!>g*#ur@K=$@8N05<_Mldg}X`N6O<~3|Dpk3 zRWb!e7z<{Mr96 z^C{%ROigEIapRGbFA5g4XoQAe_Y1ii3Ci!KV`?$ zZ2Hy1VP#hVp>OOqe~m|lo@^276Ik<~*6eRSOe;$wn_0@St#cJy}qI#RP= zHVMXyFYYX%T_k3MNbtOX{<*_6Htq*o|7~MkS|A|A|8AqKl!%zTirAJGz;R<3&F7_N z)uC9$9K1M-)g0#}tnM(lO2k~W&4xT7gshgZ1-y2Yo-q9Li7%zguh7W#kGfnjo7Cl6 z!^wTtP392HU0aVB!$cPHjdK}yi7xNMp+KVZy3_u}+lBCloJ&C?#NE@y$_{Uv83*iV zhDOcv`=|CiyQ5)C4fghUmxmwBP0fvuR>aV`bZ3{Q4&6-(M@5sHt0M(}WetqItGB1C zCU-)_n-VD;(6T1%0(@6%U`UgUwgJCCdXvI#f%79Elbg4^yucgfW1^ zNF!|C39SaXsqU9kIimX0vZ`U29)>O|Kfs*hXBXC;Cs9_Zos3%8lu)JGm~c19+j8Va z)~kFfHouwMbfRHJ``%9mLj_bCx!<)O9XNq&uH(>(Q0V7-gom7$kxSpjpPiYGG{IT8 zKdjoDkkMTL9-|vXDuUL=B-K)nVaSFd5TsX0v1C$ETE1Ajnhe9ept?d;xVCWMc$MbR zL{-oP*vjp_3%f0b8h!Qija6rzq~E!#7X~8^ZUb#@rnF~sG0hx^Ok?G9dwmit494OT z_WQzm_sR_#%|I`jx5(6aJYTLv;3U#e@*^jms9#~U`eHOZZEB~yn=4UA(=_U#pYn5e zeeaDmq-$-)&)5Y}h1zDbftv>|?GjQ=)qUw*^CkcAG#o%I8i186AbS@;qrezPCQYWHe=q-5zF>xO*Kk|VTZD;t={XqrKfR|{itr~k71VS?cBc=9zgeFbpeQf*Wad-tAW7(o ze6RbNeu31Uebi}b0>|=7ZjH*J+zSj8fy|+T)+X{N8Vv^d+USG3arWZ?pz)WD)VW}P z0!D>}01W#e@VWTL8w1m|h`D(EnHc*C5#1WK4G|C5ViXO$YzKfJkda# z2c2*qXI-StLW*7_c-%Dws+D#Kkv^gL!_=GMn?Y^0J7*3le!!fTzSux%=1T$O8oy8j z%)PQ9!O+>+y+Dw*r`*}y4SpUa21pWJ$gEDXCZg8L+B!pYWd8X;jRBQkN_b=#tb6Nx zVodM4k?gF&R&P=s`B3d@M5Qvr;1;i_w1AI=*rH(G1kVRMC`_nohm~Ie5^YWYqZMV2<`J* z`i)p799U_mcUjKYn!^T&hu7`Lw$PkddV&W(ni)y|9f}rGr|i-7nnfH6nyB$Q{(*Nv zZz@~rzWM#V@sjT3ewv9c`pP@xM6D!StnV@qCdO${loe(4Gy00NDF5&@Ku;h2P+Vh7 z(X6De$cX5@V}DHXG?K^6mV>XiT768Ee^ye&Cs=2yefVcFn|G zBz$~J(ld&1j@%`sBK^^0Gs$I$q9{R}!HhVu|B@Bhb29PF(%U6#P|T|{ughrfjB@s- zZ)nWbT=6f6aVyk86h(0{NqFg#_d-&q^A@E2l0Iu0(C1@^s6Y-G0r32qll>aW3cHP# zyH`KWu&2?XrIGVB6LOgb+$1zrsW>c2!a(2Y!TnGSAg(|akb#ROpk$~$h}jiY&nWEz zmMxk4&H$8yk(6GKOLQCx$Ji-5H%$Oo4l7~@gbHzNj;iC%_g-+`hCf=YA>Z&F)I1sI z%?Mm27>#i5b5x*U%#QE0wgsN|L73Qf%Mq)QW@O+)a;#mQN?b8e#X%wHbZyA_F+`P%-1SZVnTPPMermk1Rpm#(;z^tMJqwt zDMHw=^c9%?#BcjyPGZFlGOC12RN(i`QAez>VM4#BK&Tm~MZ_!#U8PR->|l+38rIqk zap{3_ei_txm=KL<4p_ukI`9GAEZ+--)Z%)I+9LYO!c|rF=Da5DE@8%g-Zb*O-z8Tv zzbvTzeUcYFgy{b)8Q6+BPl*C}p~DiX%RHMlZf;NmCH;xy=D6Ii;tGU~ zM?k;9X_E?)-wP|VRChb4LrAL*?XD6R2L(MxRFolr6GJ$C>Ihr*nv#lBU>Yklt`-bQ zr;5c(o}R!m4PRz=CnYcQv}m?O=CA(PWBW0?)UY)5d4Kf;8-HU@=xMnA#uw{g`hK{U zB-EQG%T-7FMuUQ;r2xgBi1w69b-Jk8Kujr>`C#&kw-kx_R_GLRC}oum#c{je^h&x9 zoEe)8uUX|SahpME4SEog-5X^wQE0^I!YEHlwawJ|l^^0kD)z{o4^I$Eha$5tzD*A8 zR<*lss4U5N*JCYl;sxBaQkB3M8VT|gXibxFR-NH4Hsmw|{={*Xk)%!$IeqpW&($DQ zuf$~fL+;QIaK?EUfKSX;Gpbm8{<=v#$SrH~P-it--v1kL>3SbJS@>hAE2x_k1-iK# zRN~My-v@dGN3E#c!V1(nOH>vJ{rcOVCx$5s7B?7EKe%B`bbx(8}km#t2a z1A~COG(S4C7~h~k+3;NkxdA4gbB7bRVbm%$DXK0TSBI=Ph6f+PA@$t){_NrRLb`jp zn1u=O0C8%&`rdQgO3kEi#QqiBQcBcbG3wqPrJ8+0r<`L0Co-n8y-NbWbx;}DTq@FD z1b)B$b>Nwx^2;+oIcgW(4I`5DeLE$mWYYc7#tishbd;Y!oQLxI>?6_zq7Ej)92xAZ z!D0mfl|v4EC<3(06V8m+BS)Vx90b=xBSTwTznptIbt5u5KD54$vwl|kp#RpZuJ*k) z>jw52JS&x)9&g3RDXGV zElux37>A=`#5(UuRx&d4qxrV<38_w?#plbw03l9>Nz$Y zZS;fNq6>cGvoASa2y(D&qR9_{@tVrnvduek+riBR#VCG|4Ne^w@mf2Y;-k90%V zpA6dVw|naH;pM~VAwLcQZ|pyTEr;_S2GpkB?7)+?cW{0yE$G43`viTn+^}IPNlDo3 zmE`*)*tFe^=p+a{a5xR;H0r=&!u9y)kYUv@;NUKZ)`u-KFTv0S&FTEQc;D3d|KEKSxirI9TtAWe#hvOXV z>807~TWI~^rL?)WMmi!T!j-vjsw@f11?#jNTu^cmjp!+A1f__Dw!7oqF>&r$V7gc< z?6D92h~Y?faUD+I8V!w~8Z%ws5S{20(AkaTZc>=z`ZK=>ik1td7Op#vAnD;8S zh<>2tmEZiSm-nEjuaWVE)aUXp$BumSS;qw#Xy7-yeq)(<{2G#ap8z)+lTi( ziMb-iig6!==yk zb6{;1hs`#qO5OJQlcJ|62g!?fbI^6v-(`tAQ%Drjcm!`-$%Q#@yw3pf`mXjN>=BSH z(Nftnf50zUUTK;htPt0ONKJq1_d0!a^g>DeNCNpoyZhsnch+s|jXg1!NnEv%li2yw zL}Y=P3u`S%Fj)lhWv0vF4}R;rh4&}2YB8B!|7^}a{#Oac|%oFdMToRrWxEIEN<0CG@_j#R4%R4i0$*6xzzr}^`rI!#y9Xkr{+Rt9G$*@ zQ}XJ+_dl^9@(QYdlXLIMI_Q2uSl>N9g*YXMjddFvVouadTFwyNOT0uG$p!rGF5*`1 z&xsKPj&;t10m&pdPv+LpZd$pyI_v1IJnMD%kWn{vY=O3k1sJRYwPoDV1S4OfVz4FB z$^ygjgHCW=ySKSsoSA&wSlq83JB+O-)s>>e@a{_FjB{@=AlrX7wq>JE=n@}@fba(;n4EG| zge1i)?NE@M@DC5eEv4; z#R~0aNssmFHANL@-eDq2_jFn=MXE9y>1FZH4&v<}vEdB6Kz^l)X%%X@E#4)ahB(KY zx8RH+1*6b|o1$_lRqi^)qoLs;eV5zkKSN;HDwJIx#ceKS!A$ZJ-BpJSc*zl+D~EM2 zm@Kpq2M*kX`;gES_Dd1Y#UH`i!#1HdehqP^{DA-AW^dV(UPu|O@Hvr>?X3^~=1iaRa~AVXbj z-yGL<(5}*)su2Tj#oIt+c6Gh}$0|sUYGGDzNMX+$Oi$e&UJt3&kwu)HX+XP{es(S3 z%9C9y({_fu>^BKjI7k;mZ4DKrdqxw`IM#8{Sh?X(6WE4S6-9M}U0&e32fV$2w{`19 zd=9JfCaYm@J$;nSG3(|byYDqh>c%`JW)W*Y0&K~g6)W?AvVP&DsF_6!fG3i%j^Q>R zR_j5@NguaZB{&XjXF+~6m|utO*pxq$8?0GjW0J-e6Lnf0c@}hvom8KOnirhjOM7!n zP#Iv^0_BqJI?hR5+Dl}p!7X}^NvFOCGvh9y*hgik<&X)3UcEBCdUr$Dt8?0f&LSur ze*n!(V(7umZ%UCS>Hf(g=}39OcvGbf2+D;OZ089m_nUbdCE0PXJfnyrIlLXGh2D!m zK=C#{JmoHY1ws47L0zeWkxxV=A%V8a&E^w%;fBp`PN_ndicD@oN?p?Bu~20>;h;W` ztV=hI*Ts$6JXOwOY?sOk_1xjzNYA#40dD}|js#3V{SLhPEkn5>Ma+cGQi*#`g-*g56Q&@!dg)|1YpLai3Bu8a;l2fnD6&)MZ~hS%&J}k z2p-wG=S|5YGy*Rcnm<9VIVq%~`Q{g(Vq4V)CP257v06=M2W|8AgZO0CC_}HVQ>`VU zy;2LDlG1iwIeMj?l40_`21Qsm?d=1~6f4@_&`lp~pIeXnR)wF0z7FH&wu~L~mfmMr zY4_w6tc{ZP&sa&Ui@UxZ*!UovRT})(p!GtQh~+AMZ6wcqMXM*4r@EaUdt>;Qs2Nt8 zDCJi#^Rwx|T|j_kZi6K!X>Ir%%UxaH>m6I9Yp;Sr;DKJ@{)dz4hpG>jX?>iiXzVQ0 zR$IzL8q11KPvIWIT{hU`TrFyI0YQh`#>J4XE*3;v^07C004~FC7TlRVVC}<}LC4h_ zZjZ)2*#)JyXPHcwte!}{y%i_!{^KwF9qzIRst@oUu~4m;1J_qR;Pz1KSI{rXY5_I_ z%gWC*%bNsb;v?>+TbM$qT`_U8{-g@egY=7+SN#(?RE<2nfrWrOn2OXK!ek7v`aDrH zxCoFHyA&@^@m+#Y(*cohQ4B76me;)(t}{#7?E$_u#1fv)vUE5K;jmlgYI0$Mo!*EA zf?dx$4L(?nyFbv|AF1kB!$P_q)wk1*@L0>mSC(A8f4Rgmv1HG;QDWFj<(1oz)JHr+cP|EPET zSD~QW&W(W?1PF-iZ()b|UrnB(#wG^NR!*X}t~OS-21dpXq)h)YcdA(1A`2nzVFax9rx~WuN=SVt`OIR=eE@$^9&Gx_HCfN= zI(V`)Jn+tJPF~mS?ED7#InwS&6OfH;qDzI_8@t>In6nl zo}q{Ds*cTG*w3CH{Mw9*Zs|iDH^KqmhlLp_+wfwIS24G z{c@fdgqy^Y)RNpI7va^nYr9;18t|j=AYDMpj)j1oNE;8+QQ)ap8O??lv%jbrb*a;} z?OvnGXbtE9zt;TOyWc|$9BeSGQbfNZR`o_C!kMr|mzFvN+5;g2TgFo8DzgS2kkuw@ z=`Gq?xbAPzyf3MQ^ZXp>Gx4GwPD))qv<1EreWT!S@H-IpO{TPP1se8Yv8f@Xw>B}Y z@#;egDL_+0WDA)AuP5@5Dyefuu&0g;P>ro9Qr>@2-VDrb(-whYxmWgkRGE(KC2LwS z;ya>ASBlDMtcZCCD8h+Awq1%A|Hbx)rpn`REck#(J^SbjiHXe-jBp!?>~DC7Wb?mC z_AN+^nOt;3tPnaRZBEpB6s|hCcFouWlA{3QJHP!EPBq1``CIsgMCYD#80(bsKpvwO)0#)1{ zos6v&9c=%W0G-T@9sfSLxeGZvnHk$SnHw57+5X4!u1dvH0YwOvuZ7M^2YOKra0dqR zD`K@MTs(k@h>VeI5UYI%n7#3L_WXVnpu$Vr-g}gEE>Y8ZQQsj_wbl&t6nj{;ga4q8SN#Z6cBZepMoyv7MF-tnnZp*(8jq848yZ zsG_fP$Y-rtCAPPI7QC^nzQjlk;p3tk88!1dJuEFZ!BoB;c!T>L>xSD<#+4X%*;_IB z0bZ%-SLOi5DV7uo{z}YLKHsOHfFIYlu8h(?gRs9@bbzk&dkvw*CWnV;GTAKOZfbY9 z(nKOTQ?fRRs(pr@KsUDq@*P`YUk4j=m?FIoIr)pHUCSE84|Qcf6GucZBRt;6oq_8Z zP^R{LRMo?8>5oaye)Jgg9?H}q?%m@2bBI!XOOP1B0s$%htwA&XuR`=chDc2)ebgna zFWvevD|V882V)@vt|>eeB+@<-L0^6NN%B5BREi8K=GwHVh6X>kCN+R3l{%oJw5g>F zrj$rp$9 zhepggNYDlBLM;Q*CB&%w zW+aY{Mj{=;Rc0dkUw~k)SwgT$RVEn+1QV;%<*FZg!1OcfOcLiF@~k$`IG|E8J0?R2 zk?iDGLR*b|9#WhNLtavx0&=Nx2NII{!@1T78VEA*I#65C`b5)8cGclxKQoVFM$P({ zLwJKo9!9xN4Q8a2F`xL&_>KZfN zOK?5jP%CT{^m4_jZahnn4DrqgTr%(e_({|z2`C2NrR6=v9 z*|55wrjpExm3M&wQ^P?rQPmkI9Z9jlcB~4IfYuLaBV95OGm#E|YwBvj5Z}L~f`&wc zrFo!zLX*C{d2}OGE{YCxyPDNV(%RZ7;;6oM*5a>5LmLy~_NIuhXTy-*>*^oo1L;`o zlY#igc#sXmsfGHA{Vu$lCq$&Ok|9~pSl5Q3csNqZc-!a;O@R$G28a@Sg#&gnrYFsk z&OjZtfIdsr%RV)bh>{>f883aoWuYCPDP{_)%yQhVdYh;6(EOO=;ztX1>n-LcOvCIr zKPLkb`WG2;>r)LTp!~AlXjf-Oe3k`Chvw$l7SB2bA=x3s$;;VTFL0QcHliysKd^*n zg-SNbtPnMAIBX7uiwi&vS)`dunX$}x)f=iwHH;OS6jZ9dYJ^wQ=F#j9U{wJ9eGH^#vzm$HIm->xSO>WQ~nwLYQ8FS|?l!vWL<%j1~P<+07ZMKkTqE0F*Oy1FchM z2(Nx-db%$WC~|loN~e!U`A4)V4@A|gPZh`TA18`yO1{ z(?VA_M6SYp-A#%JEppNHsV~kgW+*Ez=?H?GV!<$F^nOd+SZX(f0IoC#@A=TDv4B2M z%G-laS}yqR0f+qnYW_e7E;5$Q!eO-%XWZML++hz$Xaq@c%2&ognqB2%k;Cs!WA6vl z{6s3fwj*0Q_odHNXd(8234^=Asmc0#8ChzaSyIeCkO(wxqC=R`cZY1|TSK)EYx{W9 z!YXa8GER#Hx<^$eY>{d;u8*+0ocvY0f#D-}KO!`zyDD$%z1*2KI>T+Xmp)%%7c$P< zvTF;ea#Zfzz51>&s<=tS74(t=Hm0dIncn~&zaxiohmQn>6x`R+%vT%~Dhc%RQ=Cj^ z&%gxxQo!zAsu6Z+Ud#P!%3is<%*dJXe!*wZ-yidw|zw|C`cR z`fiF^(yZt?p{ZX|8Ita)UC$=fg6wOve?w+8ww|^7OQ0d zN(3dmJ@mV8>74I$kQl8NM%aC+2l?ZQ2pqkMs{&q(|4hwNM z^xYnjj)q6uAK@m|H$g2ARS2($e9aqGYlEED9sT?~{isH3Sk}kjmZ05Atkgh^M6VNP zX7@!i@k$yRsDK8RA1iqi0}#Phs7y(bKYAQbO9y=~10?8cXtIC4@gF#xZS;y3mAI`h zZ^VmqwJ%W>kisQ!J6R?Zjcgar;Il%$jI*@y)B+fn^53jQd0`)=C~w%Lo?qw!q3fVi{~2arObUM{s=q)hgBn64~)W0tyi?(vlFb z>tCE=B1cbfyY=V38fUGN(#vmn1aY!@v_c70}pa(Lrle-(-SH8Nd!emQF zf3kz0cE~KzB%37B24|e=l4)L}g1AF@v%J*A;5F7li!>I0`lfO9TR+ak`xyqWnj5iwJ$>t_vp(bet2p(jRD;5Q9x2*`|FA4#5cfo8SF@cW zeO{H7C0_YJ*P@_BEvm2dB}pUDYXq@G1^Ee#NY9Q`l`$BUXb01#lmQk^{g3?aaP~(* zD;INgi#8TDZ&*@ZKhx$jA^H-H1Lp`%`O{Y{@_o!+7ST}{Ng^P;X>~Bci{|Qdf1{}p z_kK+zL;>D30r6~R?|h!5NKYOi6X&I5)|ME+NG>d9^`hxKpU^)KBOpZiU^ z;|SzGWtbaclC-%9(zR-|q}kB8H&($nsB1LPAkgcm+Qs@cAov{IXxo5PHrH(8DuEMb z3_R#>7^jjGeS7$!`}m8!8$z|)I~{dhd)SvoH9oR9#LjO{{8O&r7w{d9V1z^syn&E6 z{DG0vlQF_Yb3*|>RzVop^{$mWp|%NDYj@4{d*-@O^<(=L=DMFIQHEp-dtz@1Rumd; zadt^4B#(uUyM6aeUJkGl0GfaULpR!2Ql&q$nEV^+SiDptdPbuJ=VJ)`czZ@&HPUuj zc5dSRB&xk)dI~;6N?wkzI}}4K3i%I=EnlKGpPJ9hu?mNzH7|H0j(mN3(ubdaps3GM z1i+9gk=!$mH=L#LRDf4!mXw0;uxSUIXhl|#h*uK+fQPilJc8RCK9GNPt=X^8`*;3$ zBBo77gkGB5F8a8)*OR10nK&~8CEMPVQyhY>i`PS{L^-*WAz$ljtU%zlG1lm%%U4Zw zms0oZR8b|`>4U1X*9JLQQ>m9MF5%ppoafz^;`7DbmmIENrc$hucekkE4I83WhT%(9 zMaE;f7`g4B#vl(#tNP8$3q{$&oY*oa0HLX6D?xTW3M6f<^{%CK4OE1Pmfue`M6Dh= z&Z-zrq$^xhP%|hU&)(+2KSSpeHgX^0?gRZ5wA8@%%9~@|*Ylux1M{WQ4ekG(T+_b` zb6I)QRGp%fRF)^T?i^j&JDBhfNU9?>Sl6WVMM%S?7< ze|4gaDbPooB=F4Y=>~_+y~Q1{Ox@%q>v+_ZIOfnz5y+qy zhi+^!CE*Lv-}>g^%G=bGLqD(aTN;yHDBH#tOC=X02}QU~Xdme``Wn>N>6{VwgU~Z>g+0 zxv0`>>iSfu$baHMw8(^FL6QWe;}(U>@;8j)t)yHAOj?SdeH;evFx-kpU@nT>lsrUt zqhV}2pD^5bC4786guG1`5|fK@pE6xcT#ns)vR|^?A08G62teHaE&p`ZrCBj_Swt*~dVt=5*RK6Y{% zABqK$X59BnrK3r3u=wxklRnA1uh+q`?T0kE1YhvDWF4OY#<(+V|R@R%tdkq2huF(!Ip+EpZF3zr*|9pmKHPo)Cu z;H+^s&`Ql}u=Jt~ZWj`bAw|i-3#7(2WuRU3DU{BW8`?!O?YO1M$*MMTsaEM!5Jyp~ z!gp6yR4$O%wQ8%dyz43ZPeoJwy;o;yg=S0^Y}%|)to>=N^`!3VMf1~}OZ`Dl$q&|w z9$!i3!i1uAgPTuKSWdBrDr*N$g=E#mdqfj*h;Z}OG`{n245+g;IKfdn!&gF2OtHaD zyGDzj@@d2!P(_Ux)3v;1ABTj__{w*kaRF-1YVU`})Acgk?(T*1YqEve3=5)8bkZK* z!Tus*e$h@^u z>#zV0771Bix~r&h2FJ9)%N{>s>?2tk1$bId)1#G;OKgn-U8jUo^AK;Hu)hQEi}swD(264kAS-SBCD$R(Ro0rh8~Le zzRwxbz_JHDbD+hTX15AWmVw!#rC)-zeZahQQmo6FG1)ah3uuyIuTMof}RO!`Y3^Fxn_-G$23RDOh(@NU?r6`*S?#E50)w zpcsgDZ-iO{;EesgDQq9;p*C#QH(sp~2w^zAJWaUL%@yo)iIL6y8;e_}=dwQc%k%;H zFt5lenH*`}LWd+fPqi;exJeRZgl&nLR%|a!%1x0RQ54cgyWBYrL>sskcAtPxi&8c( zw_K?sI*3n%S;lKiYpveBN08{rgV&-B1NN5Jiu07~%n#%&f!(R(z1)xsxtRBkg#+Lv zh21zX?aYDd_f}qdA`Os*j!eC<5)iUJ&Twj7?*p%vEOGElGhpRZsccM!<k}DeC;TY;rULQs3e}lZyP#UVb=6 zB$Dkm2FaHWUXr7<{R&46sfZ)&(HXxB_=e`%LZci`s7L6c-L7iF&wdmTJz`*^=jD~* zpOZ@jcq8LezVkE^M6D9^QgZqnX&x*mr1_Cf#R9R3&{i3%v#}V$UZzGC;Or*=Dw5SXBC6NV|sGZp^#%RTimyaj@!ZuyJ z6C+r}O1TsAzV9PAa*Gd!9#FQMl)ZLHzTr99biAqA(dz-m9LeIeKny3YB=*+|#-Gq# zaErUR5Z*Wh^e<+wcm70eW;f-g=YTbMiDX)AznDM6B73)T4r%nq+*hKcKF?)#vbv?K zPMe=sFCuC*ZqsBPh-?g!m*O`}6<}Pfj}Y1n9|Y@cUdD5GX_)6Sx9pPfS7 zxkt?g6ZwJ+50C7qrh6dMFmr7qah`FskT_H=GC92vkVh$WfZa2%5L99_DxyM{$#6HQ zx$VR-Wwt!q9JL2{ybEGJr$^?!V4m_BqDqt!mbs=QjHf340+^a{)waVvP0+98(BA$M ztWr&sM=juyYgvf`(SC}+y@QtYgU>0ghJ6VbU}|kEraR&&W%#;!#KI?le%g`e>ZVPiDrneh#&1(Y?uiMo^f5qo@{JEr(p9>8GhDa+PC9yG;lX+D?hQ^fZB&Sdox219zUj_5;+n<0@Wi3@DK`MU8FM!OFJ z8*_mTA-u!Ab#95FRVWTIqAL#BVQGxE_s?>Ql|@0o9vos&r<_4d!+Q6(_270)6#lu$ zV!j$a?_V0I<(3Z=J7C-K0a^Kc1Go9p&T6yQeAD+)dG-$a&%Fo0AOte~_Z&_m2@ue~ z9cKFf-A41Dz31Ooj9FSR`l?H5UtdP?JS=UU$jF#znE1k@0g%K?KQuwZkfDI3Ai)(q z#x_Yo6WR_Y@#6I_02S&NpcP<%sw!!M_3#*8qa+*4rS@x=i{-2K#*Qr)*Q$-{<_(<| z0730e+rubnT38*m;|$-4!1r6u&Ua2kO_s-(7*NGgDTe##%I>_9uW;X__b_k)xlv$; zW%K2hsmr>5e^Z~`tS-eUgWmSF9}Yg8E}qydSVX0nYZMX_x94QK?tw2>^;raVTqstR zIrNAX2`X~|h->dTOb9IrA!i5INpLV}99ES|i0ldzC`;R$FBY5&7+TIy8%GO8SZ37_ zw=^Swk?z+j-&0-cTE|LU0q@IKRa&C6ZlXbSa2vN5r-)*f<3{wLV*uJUw980AFkWN7 zKh{?97GmVu-0rs9FB6ludy|n`gN5p~?y51aJzBg6#+-=0pWdZ2n4xTiQ=&3As-!-6 zFlb|ssAJEJL#s8(=odfz8^9b#@RrvNE4gjuEITzAd7R4+rq$yEJKXP?6D@yM7xZ&^ z@%jnE3}bteJo{p(l`hu`Yvzg9I#~>(T;>c;ufeLfc!m3D&RaQS=gAtEO-WbI+f_#| zaVpq-<%~=27U8*qlVCuI6z9@j)#R!z3{jc>&I(qT-8IBW57_$z5Qm3gVC1TcWJNc% zDk?H3%QHno@fu9nT%L^K)=#sRiRNg|=%M zR;8BE)QA4#Dsg^EakzttRg9pkfIrF3iVYVM#*_+#3X+~qeZc^WQJvEyVlO@9=0pl!ayNOh|{j0j^a z+zi_$_0QKhwArW)sJ$wji;A`?$ecbr?(4x5%2pLgh#wggbt)#T^2R3a9m+>GcrUxU z*u-WTgHAN*e!0;Wa%1k)J_P(Vdp>vwrROTVae@6Wn04q4JL-)g&bWO6PWGuN2Q*s9 zn47Q2bIn4=!P1k0jN_U#+`Ah59zRD??jY?s;U;k@%q87=dM*_yvLN0->qswJWb zImaj{Ah&`)C$u#E0mfZh;iyyWNyEg;w0v%QS5 zGXqad{`>!XZJ%+nT+DiVm;lahOGmZyeqJ-;D&!S3d%CQS4ZFM zkzq5U^O|vIsU_erz_^^$|D0E3(i*&fF-fN}8!k3ugsUmW1{&dgnk!|>z2At?h^^T@ zWN_|`?#UM!FwqmSAgD6Hw%VM|fEAlhIA~^S@d@o<`-sxtE(|<><#76_5^l)Xr|l}Q zd@7Fa8Bj1ICqcy2fKl1rD4TYd84)PG5Ee2W4Nt@NNmpJWvc3q@@*c;~%^Vasf2H`y z+~U-19wtFT?@yIFc4SE_ab?s@wEUfSkOED}+qVjjy>=eac2^S^+|_3%cjH%EUTJ&r znp9q?RbStJcT*Vi{3KDa^jr4>{5x+?!1)8c2SqiCEzE$TQ+`3KPQQnG8_Qk<^)y_o zt1Q^f{#yCUt!1e(3;E6y?>p+7sGAYLp`lA3c~Y`re9q&`c6>0?c0E2Ap5seFv92#X z1Vldj!7A8@8tWr&?%;EBQ_Fwd)8A3!wIx`V!~~h(!$pCy7=&*+*uIzG@*d%*{qG#4 zX0^}}sRN^N=p{w(+yjv%xwb!%lnVTE7l1l6gJwQmq_G83J&Y98$S!r*L8}IiIa2E= zE!0tbOuEDb*No0-KB{zjo1k#_4FHtr{!)>o+Y@bll}Sa6D^xktI0H&l{jKAK)A(iz zB-N00F?~Z}Y7tG+vp)-q*v71(C}65$-=uXx^|R$xx9zZip-V>Hqeyfd(wteM)+!!H z$s+>g4I@+`h2>C|J;PhvtOq)`xm4;CyF}R<)!ma3T{Vf_5|zo;D4YI4ZDBkE(vMeE zb#ZV;n}CgA0w8x!UC2&5Z(K)9bibj#?~>R(72lFx_Am~jS?;7mo~p+05~XGD+(wV4 zEVYnf0N5+-7O+Gc1L!sPGUHv<6=cV8}*m$m`kBs@z zy;goR(?J^JrB7uXXpD00+SD0luk!vK3wwp(N%|X!HmO{xC#OMYQ&a7Yqv-54iEUK4 zVH;)rY6)pUX~ESvQK^w|&}>J{I?YlvOhpMgt-JB}m5Br`Q9X+^8+Xa%S81hO<1t#h zbS+MljFP1J0GGNR1}KwE=cfey%;@n&@Kli+Z5d>daJjbvuO3dW{r$1FT0j zR$c9$t~P50P+NhG^krLH%k}wsQ%mm+@#c;-c9>rYy;8#(jZ|KA8RrmnN2~>w0ciU7 zGiLC?Q^{^Ox-9F()RE^>Xq(MAbGaT0^6jc>M5^*&uc@YGt5Iw4i{6_z5}H$oO`arY z4BT(POK%DnxbH>P$A;OWPb@gYS96F7`jTn6JO@hdM za>_p!1mf?ULJZb1w-+HamqN__2CtI%VK`k^(++Ga0%z*z@k0wYJDqT^)~%|4O299; zh1_iRtc7you(kOK8?Q$R7v-@Qk4+i=8GD2_zI0%{Ra`_prF{+UPW^m5MCA&4ZUpZb z2*!)KA8b--Upp~U%f+rsmCmV~!Y>Gzl#yVvZER2h;f&rkdx{r#9mc8DZMJaQXs?SL zCg3#>xR6ve8&YkP*`Z=lng|Ow+h@t*!Ial*XQg3P;VS8@E1C)VS`?L9N+rxlD7bxC z3@Ag)Vu?#ykY`ND+GvRYTUP&-KDMiqly$Z~uFXt^)4Jjk9RIs*&$?-UPM*d7&m${m zm12kaN3mV1J|c6f$>V+{lvHp~XVW3DU0;cBR>7|)4bo{xa1-ts-lYU-Q-b)_fVVl`EP5X}+J9EzT20x8XIv=m7witdu7!3Lh=KE#OyKpT1GWk{YAo^ny|fvZt<+jmsFs=l*%e& zmRkBt5ccv4O7!HAyv2~rsq*(FmMTm?@TX3&1`nu|7C^F{ad%GLuoX}Rl}6`)uHF_xlx^gVca+mGH4T8u8;q{S*x3=j;kelz^atO~)v!Q_BT z4H6%IA}bvfuk0_vweELeEl8N5w-Q1GF!@f{VKnbyYB2?}d&QvI-j}~RI_+9t9$tC2 z94m=3eLi=sQb^S5;fqP?3aaXc&`}`lq z&M8dOXvxx9Y1^u_ZQHhO+qP}nwkvJhwoz$Mp6Qcq^7M#eWm}!3U@s07hop` zW24|J{t$aB`W>uBTssEvYMyi$hkaOqWh+^(RV_1MYnE0XPgW?7sBDk=Cqs(;$qrPEflqa0ZE?A3cBfW%0RPA235Wb6@=R_d>Sez; z`spwa50bq?-zh+id~Q!T`AYn`$GHzs;jxIw(A1_Ql&f|qP}|bon#H;sjKmSDM!nyn z>bU8l%3DB3F+$}|J^da!!pN|DO!Ndc2J)wMk!+Rr1hes#V}5o(?(yQSphn|9_aU<- zn|nsDS{^x&tweP;Ft`2ur>Koo2IdXJDsr6IN)7vB41Yy-^Wbo9*2th2QA@C zE0-0Gk12YOO?d_Guu6b3&(PIL`d zh4{`k54hu9o%v1K3PGuccez-wdC<&2fp)>`qIIaf)R{5un7-vwm=>LD7ibnJ$|KyE zzw`X*tM0S|V(I3vf454PY{yA5lbE+36_<1kd=&0Xy4jfvUKZ0$Jq!AG4KS7DrE9rph;dK^6*#CIU9qu7 z?)6O`TN&MCWGmUVd1@E2ow2`vZ1A#nGo8_n!dmX77DCgAP1va*ILU+!a&$zdm6Pa6 z4#|*&3dM+r_RJb%!0}7X!An&T4a4@ejqNJ;=1YVQ{J6|oURuj8MBZ8i7l=zz%S4-; zL}=M^wU43lZVwNJgN|#xIfo$aZfY#odZ6~z?aNn=oR1@zDb=a(o3w`IGu&j>6lYxL z&MtqINe4Z>bdsHNkVIu$Dbq0wc#X-xev221e~L zbm8kJ(Xzij$gF4Ij0(yuR?H1hShSy@{WXsHyKtAedk4O!IdpR{E32Oqp{1TD{usJi zGG@{3A$x%R*pp8b$RQo4w&eDhN`&b~iZ2m3U>@9p1o5kXoEVmHX7I6Uw4dn((mFw` zilWrqFd=F5sH$&*(eJB52zaLwRe zz`sruIc=Ck75>v5P5kd>B2u=drvGPg6s&k5^W!%CDxtRO)V6_Y_QP{%7B>E~vyMLG zhrfn8kijyK&bX+rZsnSJ26!j$1x+V!Pyn|ph%sXWr9^f&lf|C;+I^Fi_4;`-LJI&F zr;5O@#4jZX=Yaw0`pUyfF4J8A9wE#7_9!X|_s8~YUzWu&#E^%4NxUA3*jK-F5R3LP2|msHBLmiMIzVpPAEX)2 zLKYjm3VI4r#7|nP^}-}rL+Q4?LqlmBnbL+R8P%8VmV{`wP0=~2)LptW_i682*sUR# z+EifOk_cWVKg-iWr^Qf4cs^3&@BFRC6n0vu{HqZzNqW1{m)3K@gi$i}O(hT`f#bT- z8PqCdSj~FncPNmMKl9i9QPH1OMhvd42zLL~qWVup#nIJRg_?7KQ-g3jGTt5ywN;Qx zwmz4dddJYIOsC8VqC2R%NQ>zm=PJH70kS|EsEB>2Otmtf-18`jUGA6kMZL3vEASDN zNX%?0+=vgsUz!dxZ@~)eU17m4pN3xGC0T;#a@b9Iu0g_v*a3|ck^s_DVA^%yH-wt= zm1)7&q6&Rq#)nc9PQ6DKD{NU=&ul10rTiIe!)x^PS~=K(wX9|?k&{Mv&S$iL9@H7= zG0w~UxKXLF003zJ-H%fGA4Db9{~#p&Bl7ki^SWwv2sfoAlrLMvza)uh;7Aa_@FL4b z4G>`j5Mn9e5JrrN#R$wiB(!6@lU@49(tawM&oma6lB$-^!Pmmo;&j57CDmKi)yesg~P;lJPy9D(!;n;^1ql)$5uYf~f z&GywSWx=ABov_%8pCx=g-gww_u26?5st=rdeExu?5dvj^C?ZZxDv@Si^nX~2qA&K= z2jr;{=L(x~9GLXrIGXs>dehU^D}_NMCMegdtNVWyx)8xHT6Qu!R>?%@RvADs9er;NMkweUBFNrBm1F5e0_>^%CwM6ui}K_MpRqLS0*@lAcj zB6TTCBv>w2qh)qU3*kN+6tPmMQx|5Z0A4n67U-nss90Ec_rDF}r)IR4PE{$8;BSt= zT%6|jyD^(w6a*A5>_|TkMqx~e$n@8{`q?|)Q&Y4UWcI!yP-8AwBQ#P`%M&ib;}pli z9KAPU_9txQ3zOM#(x}*lN8q$2(Tq1yT4RN0!t~|&RdQMXfm!81d0ZuyD}aG3r4+g` z8Aevs3E_ssRAMR+&*Q30M!J5&o%^(3$ZJ=PLZ9<@x^0nb>dm17;8EQJE>hLgR(Wc% zn_LXw|5=b$6%X zS~ClDAZ?wdQrtKcV9>_v1_IXqy)?<@cGGq#!H`DNOE1hb4*P_@tGbMy6r@iCN=NiA zL1jLwuMw&N-e9H(v7>HGwqegSgD{GSzZ@sZ?g5Y`fuZ^X2hL=qeFO(;u|QZl1|HmW zYv+kq#fq_Kzr_LaezT zqIkG6R+ve#k6!xy*}@Kz@jcRaG9g|~j5fAYegGOE0k8+qtF?EgI99h*W}Cw z7TP&T0tz4QxiW!r zF4?|!WiNo=$ZCyrom-ep7y}(MVWOWxL+9?AlhX<>p||=VzvX`lUX(EdR^e5m%Rp_q zim6JL6{>S%OKoX(0FS>c1zY|;&!%i-sSE>ybYX3&^>zb`NPj7?N^ydh=s=0fpyyz% zraFILQ17_9<ettJJt~I+sl=&CPHwz zC9dEb#QFQcY?bk11Y=tEl{t+2IG`QFmYS>ECl;kv=N6&_xJLQt>}ZQiFSf+!D*4Ar zGJ~LFB7e_2AQaxg*h{$!eJ6=smO(d2ZNmwzcy3OG@)kNymCWS44|>fP^7QkJHkE9JmLryhcxFASKb4GYkJ|u^Fj=VdF0%6kgKllkt zC|_ov2R4cJ2QjjYjT6jE#J1J<xaNC>Xm;0SX<`LuW*}*{yQ3c9{Zl=<9NP z^2g5rAdO!-b4XfeBrXa4f{M0&VDrq+ps&2C8FYl@S59?edhp~7ee>GR$zQI4r8ONi zP^OA+8zrTAxOMx5ZBS03RS@J_V`3{QsOxznx6Yt*$IuEd3%R|Ki&zZkjNvrxlPD$m z%K+rwM!`E&Z46ogXCu!3 z8use`FJJ?g_xi?~?MxZYXEu=F=XTC8P3{W*CbG3Wk)^31nD~W>*cJ@W4xg%Qqo7rq z`pUu8wL!6Cm~@niI*YmQ+NbldAlQRh?L!)upVZ)|1{2;0gh38FD&8h#V{7tR&&J}I zX1?;dBqK}5XVyv;l(%?@IVMYj3lL4r)Wx9$<99}{B92UthUfHW3DvGth^Q0-=kcJ1 z!*I9xYAc$5N$~rXV>_VzPVv`6CeX(A_j3*ZkeB~lor#8O-k+0OOYzTkri@PVRRpOP zmBV|NKlJT?y4Q82er)@lK&P%CeLbRw8f+ZC9R)twg5ayJ-Va!hbpPlhs?>297lC8 zvD*WtsmSS{t{}hMPS;JjNf)`_WzqoEt~Pd0T;+_0g*?p=dEQ0#Aemzg_czxPUspzI z^H5oelpi$Z{#zG$emQJ#$q#|K%a0_x5`|;7XGMuQ7lQB9zsnh6b75B9@>ZatHR_6c z0(k}`kfHic{V|@;ghTu>UOZ_jFClp>UT#piDniL(5ZNYXWeW0VRfBerxamg4su5<; z(}Ct2AhR@I-ro0}DdZLRtgI@dm+V`cRZjgV-H+aXm5|Mgz`aZX63i<|oHk-E)cABn z0$NR?(>fla7)Ong28FZSi9Yk0LtYl5lZw5wT!K5=fYT$avgkMKJWx~V#i@7~6_{dM zxDDPIW2l{O2Elv#i^cjYg~lGHRj(W*9gD`(FILKY$R`tL2qo&rtU*c;li!V`O$aV{ z!m|n!FAB2>MR_FVN*Ktv5+2dW4rr3YmfEheyD+48%USM#q6)w%#2}~=5yZE1LLcth zF%VtefH&#AcMx7)JNC$P>~OFuG6sK}F7V$D7m!{ixz&inpAVpFXiu^QruAw@Sc7Y2 z_A^V(2W_+KTGRp2aQSMAgyV#b3@{?5q@hPEP6oF3^}|@8GuD6iKbX;!LI!L=P#Za zL$Zuv#=x3fseRMZ()#SQcXv->xW`C|6quwqL1M&KByBj z2V`}(uL4JB-hUs6304@%QL~S6VF^6ZI=e-Nm9Tc^7gWLd*HM-^S&0d1NuObw-Y3e> zqSXR3>u^~aDQx>tHzn9x?XRk}+__h_LvS~3Fa`#+m*MB9qG(g(GY-^;wO|i#x^?CR zVsOitW{)5m7YV{kb&Z!eXmI}pxP_^kI{}#_ zgjaG)(y7RO*u`io)9E{kXo@kDHrbP;mO`v2Hei32u~HxyuS)acL!R(MUiOKsKCRtv z#H4&dEtrDz|MLy<&(dV!`Pr-J2RVuX1OUME@1%*GzLOchqoc94!9QF$QnrTrRzl`K zYz}h+XD4&p|5Pg33fh+ch;6#w*H5`@6xA;;S5)H>i$}ii2d*l_1qHxY`L3g=t? z!-H0J5>kDt$4DQ{@V3$htxCI;N+$d^K^ad8q~&)NCV6wa5(D${P!Y2w(XF!8d0GpJ zRa=xLRQ;=8`J2+A334};LOIhU`HQ*0v4Upn?w|sciL|{AJSrG_(%-(W9EZb%>EAGG zpDY?z1rQLps`nbCtzqJ#@wxU4}(j!ZQ{`g`g*SXlLah*W9 zyuh)UWoRCknQtd~Lk#BT_qjwj&Kw8U)w=owaJ;A5ae}3)y>{neYNS`|VHJdcSEBF# zBJ6a;T)u;^i#L~LVF-X7!E$SggILXMlsEy~v}K*DM2)f@U~g|Q6I-Pss@)`>fgFWx zsq&7pe!|VA-h;@=fBF{(mR1^{1>ukTYUdyF^#A+(|I_&nm{_xaKn3h4&yMyym2k-wMFg(s@ez=DPmuB%`| z6;e@HQKB(|!PU1sW)W6~x|=8m6rL~4dQ9LTk|RzL-_(_77B4I~ZG=q7K%qHiv!FD8 zmt;Vnhb{ymaydv2V;X-5p zTt2ln?kaB9&(dH_X70^@rrCfz)nwfa9LYTHXO(IPcTEf$QiEhTpl??L+`Eetyqof8 zzl=q)?KdYni!C_9b8Z3xm7r5<5ZG-0uA`u^7Dm7k4mAsQ(rkoWy*^DZJa~#y6+hNG zh?7{D9$a9LS`a@SvZ5?C{JUHovWU9KI}z8YV4pWftx21v*Q;MpU{+b@>Or(}pwO^fu0qA3_k_Bo2}lIxvmMhucG-o>O=+R6YxZ zjs!o%K1AA*q#&bs@~%YA@C;}?!7yIml1`%lT3Cvq4)%A)U0o1)7HM;mm4-ZZK2`Lj zLo?!Kq1G1y1lk>$U~_tOW=%XFoyIui^Cdk511&V}x#n4JeB7>bpQkYIkpGQRHxH$L z%tS=WHC~upIXSem>=TTv?BLsQ37AO88(X+L1bI<;Bt>eY!}wjYoBn#2RGEP49&ZH-Z_}R_JK_ z>o*_y!pOI6?Vf*{x-XT;^(_0}2twfk`*)_lLl0H-g|}BC?dm7CU|^-gNJ~rx z($>97WTKf71$?2|V$Ybpf~Aj@ZZOcb3#uRq51%4^ts-#RMrJhgm|K3QpCsPGW=2dZ zAr5-HYX!D*o#Q&2;jL%X?0{}yH}j*(JC4ck;u%=a_D6CrXyBIM&O#7QWgc?@7MCsY zfH6&xgQmG$U6Miu$iF(*6d8Mq3Z+en_Fi`6VFF=i6L8+;Hr6J zmT=k0A2T{9Ghh9@)|G5R-<3A|qe_a#ipsFs6Yd!}Lcdl8k)I22-)F^4O&GP&1ljl~ z!REpRoer@}YTSWM&mueNci|^H?GbJcfC_Y@?Y+e4Yw?Qoy@VLy_8u2d#0W~C6j(pe zyO6SqpGhB-;)%3lwMGseMkWH0EgErnd9a_pLaxbWJug8$meJoY@o-5kNv&A$MJZ=U z^fXPLqV6m3#x%4V*OYD zUPS&WHikdN<{#Yj|EFQ`UojD4`Zh*CZO4Cv`w^&*FfqBi`iXsWg%%a< zk@*c%j1+xib(4q^nHHO^y5d8iNkvczbqZ5;^ZVu%*PJ!O?X-CoNP*&tOU!5%bwUEw zQN?P*a=KKlu{`7GoA}DE=#nDibRgecw>-*da~7&wgow}|DyCJq!-Lp8a~(zR@tO1 zgu(4s4HptPGn(HmN2ayYs@g+yx1n`nU3KM{tQHhMHBw7f#gwru$=C()`aKZAl^dYc ze7fC)8EZEXOryk6AD&-4L+4cJ&M@3;;{R)mi4=`ti7IZByr^|_HNsjcNFu?mIE)jD za2j)FPwRY!R_YR-P?URm0Pti*e#5jmfK)6EvaKCT{h)kbJl{AGr1Ekt}pG?^e z*botRf-RsB8q10BTroj{ZP**)2zkXTF+{9<4@$aNDreO7%tttKkR3z`3ljd?heAJEe<0%4zYK?};Ur*!a>PbGYFFi(OF-%wyzbKeBdbkjv^i9mn@UocSS z4;J%-Q$l`zb&r*Pb`U;3@qkc=8QaPE9KwmlVwAf01sa*uI2*N`9U^3*1lLsM9dJ(4 zZBkU}os|5YT#Z;PD8xVv!yo$-n{-n4JM5ukjnTciniiT`(cZ6sD6~67e5_?8am%!w zeCLUxq~7x-!Xg#PgKV&caC@7mu<86am{WaXo(lAemt4~I$utSp(URWpYNo$RvU*$N z#%iiA+h`(E;BUg;=I!#EaxO89bUK3*v5Nc3GPmURC5TqzC|))DsFNtJICH6oBW6#q z+B(N{ey+^mk_{!@ z)VhAWXG=_0j|0f9iJ;c404PiIFqK)(AD05Xh`Fk`r$^b`v+>*g+_+h@r)e+ELJ45) z?20~u<}HQyQ5AsBz(teF9!!_GLXnm{5Z0e{Ki*@!=&3x4-RcjBn##DDzHJ|KSZ5(E z9=tFZ)p~-}x%9sCY27)2i>(E-^OiYT?_)a;yXAGR$y+E`myMd;xDA#_Q49t*E}&ql#H~|x z2J2R1_#2lt91NnF!uqW%_=HlbF?A{B{n>}9$g5QF!bh_a7LTU~Jyz}7>W5{_LAov{ zy2_dmGy)d)&7^bJyUjEw%3xj{cuG0Eo zwL*XQB*Oi=r&HIIecC1%lbE;Y-*5|cL955S+2@uR18JDL<0;;Uc2Q9JEyo1R!!sz_ z#BqnkGfbLP#oQJk3y}nwMd(3Tt^PVA#zXnYF7D0W1)#+`i?@cm}fBkKD z+Mpcuim53|v7;8Tv(KraEyOK`HvJq^;rlNzOjIbW&HJDFqW>doN&j7)`RDv#v|PQ+ z03WnB4Y4X@Fe-@%3;He*FjY1MFmkyv0>64Cp~FIDKQTwmFP~_CxZOf{8gPy}I<=JC zo%_bmue&$UU0|GG%%99eI!m#5Y1MD3AsJqG#gt3u{%sj5&tQ&xZpP%fcKdYPtr<3$ zAeqgZ=vdjA;Xi##r%!J+yhK)TDP3%C7Y#J|&N^))dRk&qJSU*b;1W%t1;j#2{l~#{ zo8QYEny2AY>N{z4S6|uBzYp>7nP_tqX#!DfgQfeY6CO7ZRJ10&$5Rc+BEPb{ns!Bi z`y;v{>LQheel`}&OniUiNtQv@;EQP5iR&MitbPCYvoZgL76Tqu#lruAI`#g9F#j!= z^FLRVg0?m$=BCaL`u{ZnNKV>N`O$SuDvY`AoyfIzL9~ zo|bs1ADoXMr{tRGL% zA#cLu%kuMrYQXJq8(&qS|UYUxdCla(;SJLYIdQp)1luCxniVg~duy zUTPo9%ev2~W}Vbm-*=!DKv$%TktO$2rF~7-W-{ODp{sL%yQY_tcupR@HlA0f#^1l8 zbi>MV~o zz)zl1a?sGv)E}kP$4v3CQgTjpSJo?s>_$e>s2i+M^D5EfrwjFAo(8E%(^ROV0vz0o z-cg0jIk24n!wxZainfH)+?MGu@kg$XgaMY-^H}z^vG~XC7z2;p2Kv`b^3S#b5ssMOJ7724v>S36dD zeypxJ<=E~sD4f5wX060RIF-AR0#{Z z=&y$r8A-e6q18lIF{@O9Mi%dYSYT6erw!@zrl=uj>o(3=M*Bg4E$#bLhNUPO+Mn}>+IVN-`>5gM7tT7jre|&*_t;Tpk%PJL z%$qScr*q7OJ6?p&;VjEZ&*A;wHv2GdJ+fE;d(Qj#pmf2WL5#s^ZrXYC8x7)>5vq_7 zMCL}T{jNMA5`}6P5#PaMJDB2~TVt;!yEP)WEDAoi9PUt89S2Cj?+E0V(=_sv4Vn6b z_kS6~X!G;PKK>vZF@gWpg8Zuh%YX^2UYPdCg7?EH#^gkdOWpy(%RnXyyrhmJT~UJw zAR;%Zgb6z(mS+o9MT|Sc6O({!i0pzk;s9?Dq)%tTW3*XdM3zhPn*`z45$Bg!P4xfy zD*{>30*JsSk?bQ-DgG62v>Vw-w`SA}{*Za7%N(d-mr@~xq5&OvPa*F2Q3Mqzzf%Oe z4N$`+<=;f5_$9nBd=PhPRU>9_2N8M`tT<-fcvc&!qkoAo4J{e3&;6(YoF8Wd&A+>; z|MSKXb~83~{=byCWHm57tRs{!AI<5papN(zKssb_p_WT@0kL0T0Z5#KLbz%zfk?f7 zR!vXBs36XaNcq5usS7<>skM_*P$e*^8y1ksiuokbsGFQ_{-8BAMfu!Z6G=88;>Fxt z|F-RU{=9i6obkTa0k~L#g;9ot8GCSxjAsyeN~1;^E=o5`m%u7dO1C*nn1gklHCBUw z;R(LgZ}sHld`c%&=S+Vx%;_I1*36P`WYx%&AboA1W@P;BvuFW+ng*wh?^aH4-b7So zG?9kFs_6ma85@wo!Z`L)B#zQAZz{Mc7S%d<*_4cKYaKRSY`#<{w?}4*Z>f2gvK`P1 zfT~v?LkvzaxnV|3^^P5UZa1I@u*4>TdXADYkent$d1q;jzE~%v?@rFYC~jB;IM5n_U0;r>5Xmdu{;2%zCwa&n>vnRC^&+dUZKy zt=@Lfsb$dsMP}Bn;3sb+u76jBKX(|0P-^P!&CUJ!;M?R?z7)$0DXkMG*ccBLj+xI) zYP=jIl88MY5Jyf@wKN--x@We~_^#kM2#Xg$0yD+2Tu^MZ1w%AIpCToT-qQbctHpc_ z>Z97ECB%ak;R<4hEt6bVqgYm(!~^Yx9?6_FUDqQQVk=HETyWpi!O^`EZ_5AoSv@VbUzsqusIZ;yX!4CsMiznO}S{4e>^0`c<)c~mC#*{90@+T@%EQ~>bovc8n_$bvqkOU7CrYe8uI5~{3O7EijeX`js z-$LNz4pJA7_V5~JA_Wl*uSrQYSh9Wm($%@jowv^fSPW<~kK&M*hAleywHd?7v{`;Y zBhL2+-O+7QK_)7XOJAbdTV-S`!I)t~GE8z+fV7y;wp#!wj75drv;R*UdSh(}u$%{VSd0gLeFp;h6FkiVz%g=EY3G#>RU;alRy;vQmk*| z@x-ba0XKE%IyL4OYw6IXzMiS(q^UDk=t(#XgkuF`{P?=k8k3r)rmhkv`vg@kiWd34 z-~t+1aV3SabTbG=nQYs>3~E<}{5@0g**LAWi*~SfRZhGcgP{e5T!0M7CU}`f@r8xI z0bx%sI!?5);-wG+Mx&S=NRfIi>V-wP(n&$X0Bhd)qI^ch%96s6&u7qpiK8ijA=X_R zk&|9f$GXf-;VgnrxV83Cp-Q!!sHH`5O^o~qZu!xny1t?(Au(EAn)D??v<1Uo;#m7-M@ovk|()C(`o>QMTp}F?> zakm3bHBKUjH-MHXDow7#Z|@wea1X9ePH;%YA)fCZ9-MD)p^(p!2E`aU9nmJlm;CXQ zkx~$WQ`Yq{1h5k>E>Ex{Z=P=)N*0b8_O({IeKg?vqQ)hk=JHe z5iqUKm!~mLP0fnRwkCO(xxTV@&p+o8wdSP$jZofYP}yEkvSc z5yD-^>04{zTP7X44q9Af&-wgt7k|XtncO&L@y-wFFR44RsPu57FRvIBaI^Pqy_*DV z@i13CsaR5@X@xH=NT3}T`_vsy!a02n80eQqya=-p7#YW`Jc0z!QglGg`1zeg6uXwI zsB~hlNMo)kFL(V3Q1<%8yoI6X7ncn-&&Uh3rL@S(6@wKAXt6Wr=a2ObI7}8$D-FoI z>AJA>WsBEMi5ba6JhJ%9EAi&ocd(ZsD|MsXwu@X;2h#|(bSWu@2{+c7soC`%uo{sMYq&Vyufb)?OI59ds)O+kyE8@G z@tlpNr0UO~}qd0HQve6njJ zda2+l$gdX7AvvGhxM6OToCuQ|Zw|9!g1)O+7>~{KNvASjp9#Cqce-or+y5xdzWL3gLWt2oa+T(I+{j(&bF1laUsJB{fOgE-B}qslaS>C z)TjzG8XecbS%a+?yT!0QmTex?E478;D|sL*oS4C-g0Tq(YoH|eyxJ#1j088C|U-w5id`%Sz7X_w#l+U9+)$|2no<}5J zRb_9@0esSr?n}HvVGbD5@$p$8k4?qOe-GNOk3-K^Mw>Xg+drCKi5@$GTeijpI;;IG ziD<&go`ptLC&^<0jw^l0aY?_pUUK+xp#0Bk66iQ29vpR)VBE{JOJ&OL^gKsN<&t<| zCMLTYMSDG5Ie9O>6Dl#T{@cscz%)}?tC#?rj>iwQ0!YUk~R z$rB-k=fa9x&631Z9Mfqj_GRoS1MzqSMEdaZ2!isP19Sr>qG8!yL(WWF)_&{F)r>KnJGSciSp!P0fqHr+G=fGO02Q#9gHK zpwz+yhpC4w*<9JO@#(MdkZcWbdCO5B!H`Z|nV?UtcBo96$BgX+7VYMwp@b-%;BrJu zMd*K!{1txv{kHKPDs9?WZrz_^o1Tq2P=+=|E=Oy4#WE{>9}*9(apqhmE`&AeBzQgQ zELFLCmb~q|6y0FCt|B}*uI*ayZ#6=$BpGtF{Jfye#Q>FZ?BPnk)*Qmd?rNG^tvFUU z_b&antYsZnUR6Q9tQUy81r$&ovT#fy;(Db4F&M*C=KxQgHDrRcVR#d+ z0(D|*9#u`w_%2o3faI{?dNd9$#5nj1PROHNq z7HJ(;7B1ThyM>a@Fo^lJb2ls2lD`}ocREH|5pKN;$>gFyM6k)kZG;lA;@kSJIqUhf zX%dhcN(Jtomz4(rNng&1br3Xx33EvCWz%o8s;SpRiKEUFd+KJ+u|gn|J85dZ)Exc&=V|Ns8Xs#P>qv6PX&VAJXJ(ILZO!WJd0 z`+|f5HrEj~isRN7?dBHotcPI7;6W48*%J(9 zftl1Tr`bKH*WNdFx+h;BZ+`p!qKl~|Zt5izh}#pU9FQKE97#$@*pf38Hr8A+`N+50U3$6h%^!4fBN zjh^cl#8qW5OZbvxCfYzKHuyeKLF4z^@~+oqlz9(Hx8vypIiUlt!(vs}_t#4@nh$s; z>FYERg*KD#Xs+W4q-V-IBQK!)M1)Aa+h+V+is)z!_=gEn&^ci7<DEEmYcoSh?WdXUsP7O4)&lQXA(BVM5jI8s6;mO}94AC0gG(`>|T)yuV1l~i-ejCCt zoejDhX0nrZDP|x9u4zp%S2UeDzV`o#pBGu1tZ-$<9TIbN=ALwhQ0=9S{8#}Uu8n-~ z5~xIvUhLSz@c@0|me$CdZCpZl(vQw@a0Y4^{T0w_>pOkwI^x4KkBf3qGmm)nG|Ps5 z_XTY~^b^mL&_*yjl~RRIi&eS(>y?y}O4-)nWyTEPpQAb#Xz8SnnfIL+nAcNL9nqV9 zRL|eyF)RKI5-kJO6}>Q89XmgY@b1&!JI>g3ryZ@jN2v3vm7O`AL!BTWNouJzV+$+Y zYY}u%i>K6=IYU2O$2TAyVjGt?wgF9xCj;?EK(8fWu!!~48`3u^W$eUlCh*91PLxu1 zRY(F7Q3s7h$Q-p&L$ucN}it*-9KR z_<wHu?!dav0$P+PI3{J8?{+l|n&2YMLV2 z+hRta$A5WpCXl1RNbYBsX8IGX{2v>U|8_I-JD56K|GexW>}F_e_g_1r?08v8Kz{V$ zT=6aGMk>ibvRO@Yrc@ezaD0%ydHkXGHrR{7>q~~tO7ChJflwa4-xL|@#YIJejC5VT zInU4CjQ9V0+lClQY=vh^s4MadwQmk7li{54Y;Ht}gkZOIh9(vfK?3kXLoD72!lHD# zwI-Jg|IhT=Y#s|tso1PWp;|aJ2}M?Y{ETyYG<86woO_b+WVRh<9eJu#i5jxKu(s~3 z4mz+@3=aNl^xt{E2_xewFIsHJfCzEkqQ0<7e|{vT>{;WlICA|DW4c@^A*osWudRAP zJut4A^wh@}XW4*&iFq|rOUqg*x%1F+hu3U6Am;CLXMF&({;q0uEWG2w2lZtg)prt` z=5@!oRH~lpncz1yO4+)?>NkO4NEgP4U~VPmfw~CEWo`!#AeTySp3qOE#{oUW>FwHkZ3rBaFeISHfiVSB7%}M) z=10EZ1Ec&l;4 zG98m5sU!pVqojGEFh8P{2|!ReQ&hfDEH2dmTVkrS;$dN~G2v-qnxn^A2VeHqY@;P} zudZD5vHtVvB*loIDF1M7AEEvS&h0;X`u}!1vj6S-NmdbeL=r{*T2J6^VA7F`S`CDd zY|=AA6|9Tu8>ND6fQhfK4;L3vAdJPBA}d6YOyKP&ZVi%z6{lbkE|VyB*p1_julR^k zqBwjkqmFK=u&e8MfArjW-(Ei8{rWso1vt5NhUdN|zpXqK{ylJ8@}wq-nV~L4bIjtt zt$&(1FTIs+aw}{&0SO4*sa0H2h&7g}VN5uYjfed5h7eGp$2Wu*@m9WIr0kxOc}fX9eOWh zFKfV>+SD$@kESKYm{F*J90XQjr$!<~v(J%&RMuQM+6CkmnYZDGlOUdq}%)VA& zl#acS%XE2KuX~7IamK`og@C`21~*cEEc#PZM6HT*Veb_l&Ej~j0zL7p0Eo`mMu(=X zJ$v;&Lya75I4C^saKROgfi(fdP0C$GM3WyZn%mm3yEI>|S&O(u{{S<}ihUp#`X&_z zmQBma;82#`C;dR5Sx09e07FvtJLhZ{9R~|$FCdU6TDNUwTc9kNct?8e@o2MpQDrkg zN?G+aYtTjiUPA=RX5o{4RYu}6;)ET>TcgL^VpfIpluJ|lQR(_)>6k%L^FZmoK-Wm- zR5qy0P)hm8yvqOL>>Z;k4U}!s?%1~7v7K~m+gh=0c9Ip_9UC3nwr$%^I>yU6`;2kV z-uJ%y-afzA7;BC7jc-=XnpHK+Kf*tcOS>f5ab2&J&5hIOfXzs=&cz|Qmrpu6Z);`R z0%3^dioK5x?o7t~SK7u5m{dyUZ#QUPqBHYn@jETeG>VU=ieZuJ;mm^j>dZM7))cw?a`w8R z%3M0R=kdOt^W^$Kq5Z%aJ(a$(*qFpy^W}Ij$h+Jnmc9eaP(vB@{@8t zz=RQ$x4XYC#enS$fxh@;cSZ|D%7ug;0z{C8I8h{KocN-cyv3UG_nk99UNS4ki^OFkYea`q`rs zG@qdMI;4ogcd5Tr`di1JBg4I*6CFvCID_2SN5&)DZG&wXW{|c+BdQ4)G9_{YGA@A* zaf}o^hQFJCFtzt&*ua~%3NylCjLtqWTfmA-@zw;@*?d&RE3O8G&d;AVC|rZrU}jx# zC-9SF`9;CbQ(?07o8Q9E12vi)EP@tOIYKEKnO@-o!ggkC)^#L-c40iZtb4Y-cS>$I zTn~+>rn*Ts>*y*z^b3-fAlne+M-*%ecrI^rmKAVv23cB`aWD?JDJ5NIafRvRr*~~C z)99Afs`BPK!5BFT)b_^8GyH*{22}yDq;be`GnPl=vW+ITnaqzl(uYOHhXi}S!P+QZ z4SwfEPuu&z4t#?6Zaw}bvN{;|80DfxCTuOdz-}iY%AO}SBj1nx1(*F%3A-zdxU0aj z`zzw9-l?C(2H7rtBA*_)*rea>G?SnBgv#L)17oe57KFyDgzE36&tlDunHKKW$?}ta ztJc>6h<^^#x1@iTYrc}__pe0yf1OnQmoTjWaCG`#Cbdb?g5kXaXd-7;tfx?>Y-gI| zt7_K}yT5WM-2?bD-}ym*?~sZ{FgkQ9tXFSF zls=QGy?fZ=+(@M>P3Y>@O{f44yU^fP>zNzIQ0(&O$JCd_!p?2;} zI6E1j@`DxzgJvqcE@zgapQ?tophO14`=14DUZ*#@%rRi``pi0lkNgidSsHGjXK8gO{drQoNqR&tRjM4>^DtW`)fiRFO4LE=Z+nCBS~|B3gZsh`Y?-$g z@8@Z$D7C!L9l=SWoE;(+*YirPLWvBd$5Ztn3J3EaGM+#pW#@{3%yksGqy(2Bt5PVE zf*fICtPp77%}5j#0G8<=v=)LR>-a3dxja8cy3m$=MZ2#$8mbLvxE%NptMd+L?mG`v zF1cANFv17DqP^P5)AYHDQWHk*s~HFq6OaJ3h#BUqUOMkh)~!(ptZ2WP!_$TBV}!@>Ta#eQS_{ffgpfiRbyw1f)X4S z_iU`lNuTy86;%!sF3yh?$5zjW4F?6E9Ts-TnA zDyx5p1h$Z3IsHv7b*Q{5(bkPc{f`2Wfxg*Z#IvQ;W_q9|GqXGj<@abo)FyPtzI~i25&o zC!cJR%0!}lLf^L2eAfZg7Z69wp{J?D6UhXr%vvAn?%)7Ngct4Hrs@LZqD9qFHYAWy z4l=2LI?ER&$He2n`RiG&nsfLv?8$Cl)&d8a-~-N`I|&EPa@Y=v@>0Gl?jlt>AUY;H z`**5bpS#VGhdp4pKbf3iEF*>-eXg_$bqt5Dc%q0+)R50>zd^l7sN5R5Z)Ut+oz-8_ zJ`Z9HE9(=wRTD)T=%GZTEi9K5naPzlfE$|3GYGLRCLsnqLi8Sc6y&iskqA&Z$#7Ng z7Q@C0)6k;J$TlQ+VKZ5)-Ff_BNoIMm+~!@Cv1yAUI-U!R)LHc@+nSUzo$GlRb+8W< zYPG%NFfr;!(RlnvBbN~~EpT6Xj5*^Z&73tdIQ$LZu`vkfzdTKa5|JJtQ_rm4g$9LO zKtgYVdW=b<2WGM3I_j|Rd8gZ3j;)S#AT(aP^d>9wrtQS_+K>pZDX^?mN!Z>f^jP@1 zlJ;i79_MgOAJa`%S9EdVn>ip{d!k6c5%zizdIoB9Nr!n`*X#%6xP1?vHKc6*6+vKx zmEt|f^02)S_u_wlW_<`7uLQU%{wdH0iojOf_=}2=(krE<*!~kn%==#0Zz`?8v@4gP zPB=-O-W=OO3tD19%eX>PZj3YfrCt0sEjgTd#b$buAgBri#)wW14x7QcHf2Cneuizz z368r7`zpf`YltXY9|2V{stf8VCHgKXVGjv$m!hdDf0gi`(Q!(Pyg~FO28Vr#!BYP| zI)qG2?Ho=1Us9dTml}-ZOR?g5Vk)f+r=dbCN*N1=qNfG>UCLeA8pd3Ub-pRx1b3FA zEn`CIMf`2Mt3>>#3RkE19o}aMzi^C`+Z>8iIPHSdTdmjCdJBtNmd9o0^LrJc9|U9c zD~=FUnSyghk7jScMWT|SHkP(&DK$Z=n&lGm+FDTpGxfoIyKV)H6^nY~INQ#=OtIT! zyB*J=(#oHf=S)MNOncW->!c0r0H#=2QzobO&f@x&Y8sYi-)Ld;83zO$9@nPPhD}yt z{P`*fT@Z(?YAmF{1)C;o?G@dfd2$c+=Av*|;P@Yz1KnclB-Z-fJQ-=+T*g>0B7!g# zQH{dHt_%wj=wlmT&m59)TQ~xK)gB6f^EY$=1zcbGf~Q>p_PzDCHR6lndGmqPY2)&w z$Th^K%1v@KeY-5DpLr4zeJcHqB`HqX0A$e)AIm(Y(hNQk5uqovcuch0v=`DU5YC3y z-5i&?5@i$icVgS3@YrU<+aBw+WUaTr5Ya9$)S>!<@Q?5PsQIz560=q4wGE3Ycs*vK z8@ys>cpbG8Ff74#oVzfy)S@LK27V5-0h|;_~=j1TTZ9_1LrbBUHb?)F4fc)&F7hX1v160!vJc!aRI>vp*bYK=CB(Qbtw7 zDr2O^J%%#zHa7M5hGBh#8(2IBAk}zdhAk$`=QYe^0P6Bb+j5X)Grmi$ z6YH?*kx9hX>KCI04iaM_wzSVD+%EWS)@DR&nWsSBc2VIZ>C(jX((ZiV0=cp}rtTO&|GMvbmE4FpBF5Rd z6ZG=>X&>N3?ZN2^11pXEP4L?XUo`qrwxgQm4X~RCttXmZAhnhu4KDK=VkKq?@@Q_Z za`*xyHrsAEsR zV(7)2+|h)%EHHLD3>Qg{>G|ns_%5g5aSzA#z91R zMDKNuIt@|t?PkPsjCxUy&fu^At*yUYdBV!R_KOyVb?DO&z$GLJh9~b|3ELsysL7U6 zp24`RH+;%C(!bWHtX&*bF!l-jEXsR_|K~XL+9c+$`<11IzZ4>se?JZh1Ds60y#7sW zoh+O!Tuqd}w)1VxzL>W?;A=$xf1Os={m;|NbvBxm+JC@H^Fj$J=?t2XqL|2KWl$3+ zz$K+#_-KW(t)MEg6zBSF8XqU$IUhHj+&VwsZqd7) ztjz$#CZrccfmFdi_1$#&wl~A*RisBaBy~)w|txu1QrvR1?)2mb&m2N$C(5MS%hSX)VJnb@ZGXB5^%(<#1L@ zL^>fBd+dEe`&hxXM<0A9tviIs^BDkByJdc~mtTYr!%F7Q1XnK2$%h$Ob30*hSP$Bt zDd#w{2Z%x^Wpv8!)hm>6u01mY!xmPgwZ#Q0148)SxJc3Udt!-&}eRO^LN ze26pQB!Jhg&Z>#FD>`C`sU44><=v>O>tJdLs!HPpV#AM32^J@Za-9J(CQjKxpzXao zQfRkWP%g9P8XV21MmoHfx{DICLSc*t4qVeQL9t}&Pz0rM}YTba@XsD=XMW@FxFM{QYQJHvM(JsUSa3mcTUl9^qcVA zBveO--fqw%{#QGR1vy;x88+qMcgzmcYc#8U`CPPt6bl?uj%w_`b~9JliftnOa|ziW z|6(q&STs_*0{KNa(Z79@{`X&JY1^+;Xa69b|Dd7D&H!hVf6&hh4NZ5v0pt&DEsMpo zMr0ak4U%PP5+e(ja@sKj)2IONU+B`cVR&53WbXAm5=K>~>@0Qh7kK*=iU^KaC~-ir zYFQA7@!SSrZyYEp95i%GCj*1WgtDId*icG=rKu~O#ZtEB2^+&4+s_Tv1;2OIjh~pG zcfHczxNp>;OeocnVoL-HyKU!i!v0vWF_jJs&O1zm%4%40S7_FVNX1;R4h^c1u9V@f z`YzP6l>w>%a#*jk(Y82xQ@`@L(*zD&H>NY`iH(iyEU5R$qwTKC5jm4>BikQGHp^)u z-RQ`UCa70hJaYQeA=HtU1;fyxkcB2oY&q&->r-G9pis)t$`508$?eDDueFdW=n5hJ z08lH$dKN$y#OEE@k{#|<%GYY=_c~fHfC@pD54KSP9{Ek@T47ez$;m$}iwR}3?)hbkwS$@p2iVH0IM$lB*XYA+#}-re|UNzCE)SOYwy z=Y!fkG4&I%3J(_H#UsV#SjHulRIVcpJ`utDTY{k&6?#fzt~@Om=L(vs6cxAJxkIWI z@H7)f2h%9!jl@C!lm+X4uu;TT6o0pd7 zteFQ(ND@djf#o2kTkjcgT=dHs7ukmP0&l8{f;o3JuHGd2Op*?p7?Ct=jA*tIg{MZk z$2Lsc0e8Tdcwrjx|_Ok?9uB3Il|^2FF%X#ck}WoIvrzQXN%kT$9NI{79Wm~gZ3`8I+O`)`n30feZ( zDO-fl6IG3c^8S;Y_M-)+^CmM0tT^g0?H#>H8!oC8W%oU!~3|DJ?)~LT9*&GAQG13zOGq6gs*={cu|(V7{R$y@{-iV*9q@AD(#Ktb}J&3&k|5Djs$)9WM7!6#EaJ_ilvbfUvyh8c?-{n zfuFrC0u6}UJZ7aj@(cNG_(CKgjQQTA-UK@-MVmick zot}6F%@jhq(*}!rVFp5d6?dg|G}M*moyLriI!PQDI;E1L1eOa6>F9E6&mdLD>^0jJ z09l?1PptuV65gm=)VYiv<5?*<+MH~*G|$~9Z3XEy@B1-M(}o&*Fr9Sv6NYAP#`h{p zbwbUE3xeJ;vD}QMqECN)!yvDHRwb7c1s6IRmW!094`?Fm!l~45w)0X`Hg+6Y0-xf# zSMemBdE)Q=e^58HR{kWrL5-H0X6pDu%o{0=#!KxGp0A;6{N5kI+EoY_eTE%2q|rwm zekNeLY-R?htk!YP2|@dbd8TWG4#G)=bXlE{^ZTb^Q$}Er zz)Fp)ul24tBtQFIegdI37`K$VR3tVdi<(fIsu{#QMx=$&CK9M8oN%3Mk;>ZPd-;Q- zn|sSKSnc-S0yrw#TlA$+p{J~u=u98s>IoL@cNLOxH=+1m?;t1bR$vR=M$US&Z8DO3 z_&zhQuId1$wVNsS=X?&s(ecIi#00o{kuPs6kpYkL$jMyGW8U7mlCVaZeEL=HsIxqm zFRLxWin8B>!Dc#9Z#t0RNQiR-@5J+=;tC7|1D*~rxcwHa5iIVD@99cCFE@BukUC-S z^iJdt?dwU)kH2VY9?|zVShMbZctzFRz5Q4tiXa^>@U%jDYq}$rSyc#p2wXr}mc0qq z^lT>$y)N(Qg0dwmEwTopneoU(y)>Mj+f{iHM0o|>ZtCg-itPj4addYz??aE)Rp&hk z_SI)%XeSf=SjZq18h!Cc>Xy&EynnxdHQ){(x@g|ZA%`3LU^KzX02c5N;F#tEk1)7v z(|V9tO3>?^X|kQ*rRBf4>mWW2$-Lx})|M7z125&VHcxsCqB!<$l1F$zCrJ+nm0f3Z z%Hq^=SKpHyV2@Y*Cu2x>fXC0SscnR*($zEB{KOniJcpn@e`PMH*_Q6*0Z^8RNCEvZ z+UU9!927p9YZ&g=bnUvQUZcdisyn;-4;ACXOe-Xor9K8Qbp{ldE17+G@VQT+9ZJQ*9dZoXfU2ue|mMhrrZk2R7&~YjFW4`BTq45UwVc6JORKU)wBCTanITh0GD}s$`C5pb(9{b9 znwee6j%?-UV)_7opOioCf5@C?@w^@g& z&68+oMmV;5JW@TT63&CSDrfYL2$L)pVseDtAwPwleEM3F^-Ufn3PpfxFmx6o zQ`Wq9x#d$e`VKn5LOXNsrqhGao7~|s(u~drPrZ+;aP!C%z4NskZstCbAibD}O%8Ij zb~C(taxco~WzJLxhL1T}3ctXMbV6}_z=IZN9L0|SxLSe`$X`<)BhM`$1&&)e_}fCh z=idVL<+u6Vn{&ksP*ZLlMo$fC`dtzF_?~L?4Rril2G4%v5^7sUa^&8aMtMX&mtapl zD(dW|cisM3fqMaB`8?QbkyiUl2g>hMB5EoS&IB8TdoC~)b$nT=`%GgU`k-)+8}`)F*~I~DXMaTP%kZftx11~?iALs5J+&Rom#p%Y z>dH}-euH4u=_V3hc6^*2WMtL!9%yRTJ93p}@aV0zdY*?xchFI>m+UivV=;aMFp0P~ zwB8P)wvV6D-GL?6hJ#g7Hy7=2i^&Od#S=j!;Rc_yjO!*4aN7{vqzg2t-R|Dav%_NDk z`H_FVlSi==(~f-#65VmQ{EE92x<03lwo5p)s=ZJ^L7PlS>132Whr zR6v~t(#I+(`usYLCoO;Rt8j&b^5g_xgs*98Gp|N}b>-`HtVm)MscD)71y?(K6DRCZV26RsHPHKk)EKKZA%C99t3$t^B0-k5@?E>A-YMbFe?>ms?J?_guHHNU(;id*>xH zTrtam+Aq?n@-y@uY@A?hy?1qX^eLu_RaH4Ave?A8NapgQF=C%XI7wlcCf4<6BRo_% zBXxxc*A6-3CruF?3i8HOdbc%>N=-iiOF+9HX|ht6SCkz;A^am&qi_I&qk1B(x<=(m z>QG)nswCOLl_1{SZ@_eE#m^qb6#6DoMsB*)`17ui+XvF%(}|J4G$z2G*;E!1ERnAH z@q%=#uV6kBddqy4=g>!VTV)9*1=i{wJ}Ep!I*?)uJdA(LwE?(!?;}_u=^M2NShWC_ z*7l4aBJ=!QVU2-iehgb`$vOI8zkm{W%QO~?xOD;NgI;Iqa3#^$^U5D&McReLe&qs# zR<^@QpR4#W~Laz+QBsPt@3L#KF`Yr8}jgHe;5(cfpQ=;Zjtbt;c%y^#-m=hqOT z;KAYakW+$w0&F}>K10&SiPcD9SrDOuczj@U#W})5jGU-_htU`U6Q%wdy((%?J}y+$ z=$4jw1N nJo)qTxG{D(`3*#8tY|67hJRF;)r6F|#I`Ar6I0aafRa=kr-Z0I^}9xf^u;G5iEQCbpv3b#S#%H|HYHsQaHK$! zU#3Fpz8*^pK%RRmX<_09eIVziB0jOgPgFnI-*QcwEBtBiO#v!>{W1cLNXyw3D9M|A z*oGy(u8BkDA1c;MsXmpK^-~pl=We^RYnhZ4bz*)Q)C2G+E3tgx9PzU0T>c|1ilS!T zyE=bz`=wskDiOi!@!l?Y))#%{FM`}7r~X)i1)1*c6_2Q!_1{)fp%cS|YF+Q-CB%d< z=zYus`Vt@Mx*a7V)=mpLS$-5viaKgNB=+zN657qy0qR94!cTtX-Z%KBCg4OKw7b=t zr=`7q5Ox=lJ%!G5WIyNQC1xpqYU0{!I$hyrk!6%De$gp<_*Gc?ES(OwY8U^)Kjgc{ zSlhpXDb|;{+y9`u{EuMz54rlky2~p6xX2>MV6BZ&k`$q%q7v(xYps2wr9e8^4<;CB zc)eAT~B^rjzO6<4BDDH;il6 zFsM8jL+agQ;zazW(uiQjM%fPf2N~_p{cy29XP11_lQFpt`t#9nlk}>fv((FZt-dBa zuMIc4HmPHW04n0TTG9ug9;&OV9euL$Ib|+M7}}L~z4e%%%b|r~6OQj(S2d7XfYn#xp8;KQ55UYu#gY*De5j6Cc z#R%?rqwpy7I1(kpU7B*Pq=etXeYUn04jg%ZPjYqQNa$==yTG=6KX+=;i2Xg+kjV2T*Gc!(ef z`Q4fR*TA=M5-}z+s%YO+!K{k}S**ic&>o4_Tmv$EQTOp7F6TXPCj-UTXy?OQ=%*y62Qajk{rXbR%jMCOFMiVE3KekQa4xR}B%=iPtd8BXo~q$OX_ zSp910{Ew;m|GATsq_XiJ3w@s(jrj^NDtr(Dp!`Ve!Oq?|EJ9=vY2>IfrV{rT%(jiY zi}W@jA2iqd=?q>s;3%?@oi7~Ndo3Ge-2!zX58j(w&zVlPuXm3rcHb7O0RsM|!Ys(b zh(=*&Aywo3vuJoWZnU!u2_4bNkDTc&&bCYc%T zM~~xYxS#3KXFzQ@OXdc%9QDOxqiTd_> zT;(DX9{5dIuC4pO_xy+3{Ov)1I7j!Z)6&nHUvTRP>VU5dm#849icG)cvl0QOPkCIzG^lOp4#UcNr`VhBp(Ha%8@KPlvT*5u!v_$b#b~%sn3K{mu zaxeD%Q~{;Lw03ZAq(Pc-IVj>n*h3l2{sqioCMGatQY0kx zi`1(WWDQ=;gmLSGptEQ%UFC)th@|71<8eiRtX&Mx@#1q#nMF_BMfQdS>!!Qkx2o}= zuqRi?`UOX5P3fP%M+71Q$ctH4Av}bXED#fQ`KR4!b~60nsAv^*M7c-x`|~B}XIuq% zlqIJOf>WvlhQ@Uw$du|14)tZ?; zPNZ|xZSwp1y+d4sut8E4*l2JWR|~o0A9vD-?zC-w zDc@=wE1YKb*OMSi_Kx}&w;#h3>sHp|8^hnA3w?-WK)X?@Z2dgV7`9Cupf-B2RE4x^ zwlw+~!V9C^tyb`J;m2}ksD`w}G9`yu(^--{SQ+wt^Fu4Li~Fft!3QO`upSkAU?o;# z(1Q%GUVWbbkTK-M=T+ULkk3s6Dc9`G4CO6|=&-S&D+rbJQ$`Y-xL~ol;kc(l)VbU>{&>bV+*?ua;$bnDc29RW+Ig16)Vf6=L|fMR_P2b7>6}0 zdlB#-gj|j*C~M=F^2=K*k~=tl6YM3SXXi&K-`EvEXnWz&4D-^hQRBJI3gKKDj^6|> z*WhHSim1qAffNt60Mve9lfw^+&0bx-AM0%j>QP3%W=S@(l=(nrJ678mRQ(#+sI@d{ zdb#5fo#T;hK7xJ=M58wZf|?DHwD%!OZ3JrTGV5#{cfQwuiMvz%!CQ}CubJ7`z?@rSF<+KHNV2goc)a6hP0oHB@3LLKSH2w{um&J*z1Ka2 zLIR>lvOvh>Oxe%?3A@v<_T|}${zf_&@C~^FCo#jB(W9VLO?DX{)n(BQ0(V0`mI|9Y z#U3WwxixJkU_NTvA>5q(A@r2dnEXJp#6B=pww$XGU}~1~c``UKqQb=^*2P|4Dq*_! zhY^i61Sy%T5$Td0O6^C>h(xVvT!}Y##WeT8+s+Uuz=7)~V$>!zU;%d>H)rm*6^IrsCma%|cifwDLk_ z!^W2voQ)D;I$=v2E>iSaBw!d7aD+|LWl2iD!cBw`Q5p1~fk_xGiPi8e^mY&#viTAk zmaKL8m;JQ4bY(n6uBZt02z#noMMxTfF-RzjKre-c+@B)#J3pN-Zv7F}JtAwNk3j?OkpVCL6W1)Q$FLAj zGI!tX;g`O{%pt=0|q54Jyj##w*4e*|_;Us2Tn?!#^R(>u}|FAw1G_ z#wQsagnj9$TAC`2B_XgB$wNq~Sxgl?#0+QWWcB{G`c6~&SosbtRt}Tukw`TQ!oG1= zYyL(y<;Wh+H24>=E}Gs=Hs2%fg;&Qdvr74{E!R?Bd zIRQ?{{xkLJ_44P@y3^#(Be%(pk%$liKbUUo76wSoVfJmt9iTKL3z{uW6L&?jYg>EY zsx{kRiW@q%<$VZvbS(TKKTO4{Ad6l^IeY(F^3}=mX9|FZmQ`~RErNxlBPl3ast}W$T4V?SW=6kIGn@-^`qJv| zZXwhK4Kl1a4E}nLI`rdOi?^pd6;LZ-|8G&INHgOeC5q{_#s+SXb0r(;5ryHFsoTJD zx$VtNDh=-Tx3t!NTlk=hgAaSM)#U}e>_-Ex(|JoX*hWmBPPdTIa-2(BIOUJ|Iddy| zwY*J%z%W$}*;uSoB!BIJB6N6UhQUIQE_yz_qzI>J^KBi}BY>=s6i!&Tc@qiz!=i?7 zxiX$U`wY+pL|g$eMs`>($`tgd_(wYg79#sL4Fo+aAXig?OQz2#X0Qak(8U8^&8==C z#-0^IygzQfJG4SWwS5vko2aaOJn*kM+f1-)aG{T43VJAgxdP(fJ4&U{XR90*#a)G8+clOwdF?hJ?D) zmxu>0>M|g_QRHe_7G|q6o`C>9x4xd$Gl7lAuR~+FtNid=%DRsnf}YI*yOToWO%xnP zY*1G5yDnTGv{{xg5FhWU65q3-|-(+-rJ2WCeSJn(7Az>ej4Jp9+l-GyZ_| zJ8}>iA4g|}q1AhEEv#uWR&$g&Uyht?fVU(qk(j?^D`))s>oG08pow!f>P1u71P%oL2)UC4GeS87&G?{)NE;D=my1Q9{~;y zJULE=bG6jXE28Y11YmoZoo945`MM*`v%5b=_02*0cwzDve#3(4M}NPt`)?SCa|7*q z-94ks(R6WH-l9fE4m4}10WSu&O`|;ZCIT%vL$_pbABY!}s33@~gIvZ0H4co|=_-T$ zF#lC7r`89_+RL9wYN=E3YwR?2{$^ki(KKd>smX(Wh*^VmQh|Ob5$n_%N{!{9xP~LJO0^=V?BK8AbCEFBhDd$^yih$>U z(o{RReCU{#zHSEavFNdc8Yt<%N9pd1flD{ZVSWQu*ea1t#$J5f6*6;tCx=&;EIN^S}*3s%=M#)`~=nz!&Q0&{EP|9nzWyS<#!QxP;!E8&3D}?QKh^ zqGum|+;xu9QE=F#fe2ws5+y1Igr&l`fLyLKry=1}(W+2W`waeOR`ZXlW1B{|;4sE3 zn^ZVlR11hiV~p<~TaSen8I~ay#7Ql=-_|U@$8yjZsZ=Vi+^`JV2+kn+oiSUi%omO_+7}saXnJ9 z5ETilbag(g#jZPopCgJu+n@(i7g}3EK2@N zd64$77H5a`i%b%a^iRjMaprwzWz(`=7E6QY)o)gek7H)yZ-BLw^6FAoHwTj9nJtWc ztKaytMlWGLg29W{?gr|rx&snb@XyvR_}x3fmC>d=-nQp5ab3*whTw}DfUcKlMDDx` z-%?ek^*|Kqooy#>2lfklZ|jN4X$&n6f)RNNPl(+0S>t(8xSeOGj~X0CGRrWmm(WXT z))DDW_t&y$D#2`9<-+JT0x1==26*gpWPV~IF=rePVF%e-I&y$@5eo~A+>yZ&z6&7> z*INESfBHGNegTWga&d@;n;FSCGyW?}e_Qw#GTLHo*fWxuuG@I~5VA!A1pOdRTiPA~ z^AGe(yo=9bwLJD}@oDf$d+34~=(vIuPtOKiP}obDc|?@hY}J*@V|UynBeAkYa?S{@ z_f$U=K+>deTAi&=a*xv>Ruyw$UsTWY=Yn=xjf;s)6NQu>_niQ_idmzIwuL`Scf)f= zyzK?D5a5)^D@H&qN%F6Zd0JeXX*Knbe~VLe^gi|?JK67&mB4jrapV-$`hCQT;C{%T z*pjxB+Y|~LD9bmMN%Iq}S$F$x1yWU7@GcR91V8h;!O2I5MN_rq*gRx(k8T!1WSDTp zr9eJO4$~H94aG^6k5p8k=kFJ>4lnY0q_Bsa$@vTRW6uY?slH|Qt)Yu6Yun&pfJ zBi!h;6x?FDs&79#PT*HSCEUsKws#s%TFy*=2PAfb`>gEPBn+D-WdfXA?MkB=<8kb_ z1+4D11mdHG0EcAyg4dneLtfJ8)RyHQl@6hWJNe(d_EjyCHf7%Xsd)S4A-4COz{G@% z5xQ!P>AS@H@;4Ws)N91)3A6PleMe2<& z!(zv#%Uc?N`(Xmm)OJPYt)BM`nRjoWA&P0Yxl@c9Y02zlPH1J5l$nhPrMwu=atkz4 z)a-1+OEL;d@ctx=s<<+3Sv1VYy0RYmiji|#hy$66#`5;u~BkH4^$EGZ-Y4xyZ=%3KuaeLYKAUr$xMtIh_5mga> zPz<#G0mQ7IxEw-yO}BueN}RaFlg$RwCDB)vLF$wDu%qZyLYsPKdcbHD23$qn9i#JFqIo#OK?u7db2-$GatzO!On87%}Br};~#}n zziVB;qf_4(K$u>Qyz$ln_kBGS!CD-t4Y}9oxL@7@Sx*?NOAzdeINUD>Hl#*V%pfA; zSA`==YatS*G*crJ3`3ll4)vKss&)UtY#7ZxiVoG%9(4<%`WWcjX2jV(^g7Yhj+h5J z$5=?S=tuCyEt74^6jo@6y|@~N>&cVfFNtaRl=)Gm!vR;Bc$3-;ySCI$%kdmjQ|si` z{$q_YCe6vjy6re9jGN|`43D``)1PODtz0)vhV4XV36nVpOnMx2uM%qZ<3TtcI%>BQ zf0(J`{JqPPJxw>k#&nIvoZ5e9Sno)B2r+E0G} z@&M|zf4E0Q$O*NBR2I;?i7N} z@2^Su#`%qeX}m3cbSojiLk#84kvW1fICNPS`OyT0SpUoA0(s^2m~J<^eKE!dhJx_N zG_T}0&(<*an>oF=@?6?55g&IxSgY3?7|@pmDRE6gJyJNPH6un~%0hZ@?h=hI6O$b^ z)29#<4$E)cE-5IFbRpk9JVrw$$966UDyw;Iym4OY4Fc!&s1ZH4BJ1-$9<)Zt1c)N- zU^&9hsk6z?3%<9kGKHW|6~k;&cghtWz`oz`_YjVuvy;B;T67=L2c6=8`7WyTBv*QH zNv*bo1#KOk{O&)@&pkd*?v+kcJ8tM>AGx$~WMhH{L40_N=bkrVg+^p!H)IqXCQf2_ z0fPig=8CEo>p4vE(nc^DKbZ|9_Xo}$i4zJ`jVh95; z5%aNP3@``=EJ=Vt9U`y+$YtX;%OPzgZ_3+;+mh{p#W&y4-%%Bf`LhOy-*kB0qnB^m z_nBTz_b?-`F$*ymByshU>D)za2g`0j^ioo;A#QeL@x3@|+_!=YXA5f6Xg(Ack&WOg zJ<2i|Fd6OmyH!@YSMVxb;=M)ZDhBt)4`5T*>cUXWPG#%@$&*>K&u3#|`fm2mj*FKVf?du{xZ}WKWETTFhq6_fO$PS5(ItF=3~pFp~*j z!ys1<4EL1)#{`mz@gW|t-FpPkd%pK)n_Rb)F;z7cQ6dym_>YI3&e!=!m006oS3Mjq{q ze%hNzW=G0jpfl2K(x`CDuZCsJV*hm9T~%5n7R_g}VFpk`G((D^MWVMAmRp--T{`P; zwMgD<;e`fm`g3|fPns|6qnd{|FCHY*YAguXH(?%sx%4+Gu|Y)_8mk4EljxmP+MP`* z`SUbI{TCIN2OV+$y#g->Jqv#$wL;}4xJmah#$0`v^ughM_XjTA$B}ux)JZuY5-GW4 zKy440I+w=ZtE-_i+0xImq}vyzD68?8;94-5L~_O6Ty>X3itdA-x?6P(c4jkr+f!H( zUDeqiG>3bn^Sf8(`_YwqPeJ9&-@OCQZm4X{FfRMeBtN4E9Ca@;GVpU*L>lVb;@=PH zTQvTr?^jKyCKh&ZVOI*<y%T*Aw(XCPrFC=39*y$A`FSzxBiQ#W+uW10d8&gYp4{teh;^p@anft+z$5!Hv&@h0X-@xJG>hbTCxjDwMiWK@1b%8wYL6BrV zT41m}tX8g-`P@vj4T!Mlk8F0S!MA`^J=SCy9-jdwDe^hVDa`WwyI^H@ryt=F5y6>b zT8&iI6&j8edAfX^ycgWbnMZQ26Q~`LmdEScKC8|~$Jgyw(>18NAQ$9AwCRmri!96L zp^)b0P2CR-9S%cG$#rU}MXnx21T#031o>2VrDs@sa-FpjfvgLPW>Q&LHUoNOtmkt# zoDZ=5OGp{^vO~=p29^`aXd8K?(+f-bW`N$U;-o;%f?RcR!k02Nod2h^^8ly%Z67#E zC3|IOuj~^YBO=Fklo@3mvd6I{Z*&FZ>iq* zxh|JuJoo2$p8MJ3zO@dQ;%1#~Mrm48 zB0053{1bDi_a@jo<4!@!`w4}B(&Qb`~IeSBh zu+_yIYl2Wgk+?x4pCmAM>x_SqBPUj#c`C`k>_fp@qPlAAwD$!zOxRkL7;=|nu(#ut zyF^;&hm-D_;ji{d6rOloACu5*NkF4IC3@rifMG(|^Skv$H&^YnYL*rpw=UCi;JOuz zN*NX(7wZXS4tF@6PIWAs%*j!$RoL*3sh)}iry%thDvN5AUM888q_(>|Tzt|Yea3AyMYBgm$H_`F^v2%)bux)3s znFIEBDK;-JS5SH|;1?afJb<*=c5puu=w%tv#ihn*R!^Hd$KWAp4$#`joJ*)$kNtZ z2Al6h>Z>(u?3tmzA4^d+jLKx{97!Pb4;CX&u;M||**7zXI7hO6nrdMx*Xa=|-`#1^ zBQ?Ha&7cd7hN=%y4yUp?zl8~Lo;%mQrDe8!ce-W_K94FFMN*g(w8q-_K5S+c0{o29X&PzpV;UJE^!xnFc%b@>kvW4m#xiOj-L*DadC&2N#0Us z;<-(m1WB7$=j6hjcPC6JB)D3T2#IC`ibu#yi!uK7W2!j|Z>~RaJ*&XXy#ytIk2DIp z5?Qd^s90_?ILjU#>ZWk5HXts}grg_!Gmgm!d?eLGR7xEP zvTCrslV~94ym5_i<5oqy(@@?wN}lIdtiY8=?|Ng!XeYnly`@9wCGx2S$3x|0x8T2h zz7A85Vb2>s44rKpI_4Y7_Pnd2^mYj2%^jM|Du>u4`^Psda^JIP%*DK6bo`Vf&f{!% zDTYCwF5Nhi=)QhU2$@eQv&ZzxsX+Hl+gP6kW|e!n9IU2>Vh~cioI{>4WvR}t*4Hpz z%5z?HjLGoka}Q3AbX9AkY|Yjf^M(>@tBAI9JO5pDCQu0R3Nns>)LC#vB2p96C*?K? zvX$un$sBDx$1=+NNj*@Oa@u*b@O*XBr_sg@8sCUq-|LK!MUmC)epklrv}5O_^<{NP zX16|c$9Wtbks3y7geI^tF5oRZJu;v zwkW8j+8Ccxo9stEDOT_Go&j%$KCgVO7pm+^%PKEPBZqbMw%s@732XS{cX+wCSjH1s z5)bc=g**<^NNsroY` z?}fHHlgu^B?2r{^^gQ&j zbF~T((>|Yg&C5WKL8DCnl1}Z3!YHFW2S1|;Xr0`Uz-;=FxEwYc4QpeAtnm7^f~uzX zl;xA!?>MLR?tL80Iudm;mi{!ewL91KhG7Hsa-XepKi<2mc6%zf0GwtbfJ1Zf-<@Xu z#|XWDzv|04t)&9Id!UxAAkN{t5qC%%8-WV3i;3duS19%m2||Y{!3pR1=g|zQYAMqc zff)_2nj-O4wfxy;UNM?|Uieo!^J$A*uDe>@V(NKH;KS;Y_dtE8${p>RdcrW;=2*fj4~d?OG0l-(g?ik}vz} z)5-wDppVts>K-=|@{=!53?=8)Jw#RGpS_FWpbwtn}{v!JEJ$q-sr7F6&OPBuI# zuVNFMPte79XgEu!P&qRq8u4J>r%$l-IQ00Lin90(_KtC)aR_de zxN=pY2<1b29_^AG2WJIGmmX4rv3$!`l15{e(H!1^+x9voZ6;882YAE12q7+lgy+>) zj|s0CyzI9=Mo!R}&LXB`&DYpZ7c?0r(&KNV+~TULd0y^e;G{KVR4nL0KvU9mr8&$^ zxrM-9P8zE`J?aZ(iB~Rz<{vvnk2HaZU#K$aVFfYnbAXVUOLU#As5JvS%+26 zi$sNuPY}dLGUS$0g&;oBqhzv2dY`l3@6Na403M!Sh${B|7(y|_cONa;6BrtUe@ZzV z7SThtHT8k?Rwc)(Z}@BP#H@JJHz&GR&M=E@P9KJ89yQKmRh&I~%vbL1L-K3E>7>CH z)Y!=jXVb1iPrAoAZZ3}3wU*5~nrV!ZjL5zqJ<@NwjHCZC>68Cc<{&E_#S;E*jOdjtg?uKN|l`P8sjz&Qf7a^z9 z;{3-8T+H4y99_zc;JYIvs!sk$G}` z??mt*Mm9Z@glCZb!X?!xXD-21sFDPEpZOK{sbQseQ$%6~b;n+*z0hRoR}0Pe>B|#t z$XrVcXv8M|q*Z8MY&r9J0A=d^1bHpjrUXu)qEj~$%%=gZp`^~%O*lzxUquG^p6;n; z^(3HL+hx4gRP?4N*b2p9!^|2~rcw3!9nQj$vmZusbXYz_x^AVc`3qBFm(jS9ueU5h z^AnNnbswfQ2Jq=W=T+p-V|nQco@bOAH$pLQZ+BKH8E$iM>IDz z3|wc?QP`yI=X5YTlp8h}%p6{Deq?S0QD$Ug>ih1SdPZg237Rl{S~=Ha4~-ckMoIWMn+X@@`V6 z#HHZj>MQbt$Qqp*9T(cjc^lxZ7UO(>PwzF-qEr(wo`vaulxdall|KP`7p4gd`23&Jy=#sAes*0diLB(U$Nx46VQvP)8idSs8^zaV91xw*O-JMH=)FoJshRob|_)O)ojtfP))WHCr(;*2;VMQ75^ zfN@a^f#o<|*9X;3IcGodLUz-3i~FAu+zI4c5h+nW^h_!^)b*B_xw-l4O$TB(ixaqW ziMoa%i=BeS<-F45kMO;Tw|FWa`G2c!SuOA3CbowPhF6csf1|&qqugUrj;UgGHm| z;j^yoH?MZhR;AYOW_XW2Lg2j%%ejL)B@*bUMD`g<#Z${1+fa57r7X82 zcqY-cfPnK%Y^3@szRner zt)bBToYCph6Jv*W+&t?&9FG4(Iu2w46 z4B#AcFy_^J@f*6<{>CN}Sj969*DYV*e7<61U>GoN{tz!Do90+jApFueVY_IW(MQF; zl?4yA_(MvMwN&pWKVyg{3uU_+y6RMdot2vu%mC?st=N0pf-~JZXE?3JFf)j<{1xsU z`2ephz)#HzsWEP!inHm2hI(V(~@W zY7gGU-lO52cHD&SY)>QHgy$=>^X%u0TQZfCizro!*weMyvZC=;MWOawdAx~`3C*W` z%^#^$uRP;gyqEE0<(i8xcQY$oc+6mY#z{-XFxsO1(cN8Y)>p;^q9|5bk`Z*p|c!?(rErw#y;yT(%@c7trQBv6cj)$3>pI z>tz+;IB?D=aQV=s(n)o63*yn8dX1m7#Z4G{%fF@K2o5n3jxR~mU?nzMi#;}8e#(>{ zy{Z4!AI)jZ8TY;nq1aq}tq;~=zzoTv)er06oeX3;9{uP{LWR*2%9cmE%S^`~!BW>X zn3PZFTf3g*dG68~^1*q@#^Ge(_8puPEFLD8OS|0b2a{5e=N4S%;~f3tC>F6UxK#v9 z)N-#Mv8=ePCh1KsUKD1A8jF_%$MPf|_yCN9oy%*@um6D{w*2|4GY zb}gafrSC+f=b*W{)!a!fqwZ9)K>fk=i4qf!4M?0v{CMNTo2A9}mQzV=%3UT&i{3{W z>ulG#M!K7%jPf6Mjff9BMslgQq3zIogY);Cv3v;&b#;^=sh#(Bn%W)H*bHNaLwdpq z85%fUTUJJNjYO_426T2TBj0D{6t zw&S_HZ|C?pI_2q(9Fas&@uJs6nVX;P*5K#6p|#)_(8PM-{L(;2wl`ma{ZAd5gA)?y z>0GSLoK<*FwW+G8@-M3vcffg7I(qm7lzF)n`Q9iCvp*mn7=|CjlpG{x z&r0n}XLWZ!>=lynUr7D`6n`7a_ZgT< zm!i;&?Fb0Q2QmqmCHfZ7ex=_tU~(7b)L?RIvPyEAU=gLIZ-VTAA~WR00yKyTXg^(G zqWLZJs!FnQYMOH3*fN&Tn(IKMLf{Ki?pRo8zZJ6YVyj)y0^)-sR}2-)%mI(Aw2AgT zbbp1T{qB(OSNJd0cVBH^tI>HR(q+#*lmi@LWe*rZz&M2h1L_=50uZ1e*n#E*`6?aw zj`ka&JpceRGe@}Ey1)Q~O}0qHRg4K_u>4e1arvJ7Q9!=t5AuzG`n=a-f0}{+lnCE#zu$`oVn44eS&T?N*wz~t~E&oQDBrB_MSg z_yVrQehWbD0xHX|v-hpselAu;O7s;P*!uAT`dr~}Lie=tknaGoiU?;*8Cwgala-65 zosOB4mATbdXJFujzgA4?UkCKE093A1KM?W&Pw>A?IACqg1z~IZYkdP70EeCfjii(n z3k%ax?4|rY(87N&_vhsyVK1zp@uils|B%`(V4e3%sj5f|i(eIhiSg-fHK1Pb0-mS^ zeh?WA7#{hhNci5e;?n*iVy|)iJiR>|8{TN3!=VBC2dN)~^ISSW_(g<^rHr$)nVrdA z39BMa5wl5q+5F@)4b%5-> zA^-P20l_e^S2PTa&HE2wf3jf)#)2ITVXzndeuMpPo8}kphQKhegB%QO+yBpDpgkcl z1nlPp14#+^bIA7__h16pMFECzKJ3p4`;Rf$gnr%{!5#oG42AH&X8hV8061%4W91ku z`OW_hyI+uBOqYXkVC&BqoKWmv;|{O|4d#Nay<)gkxBr^^N48(VDF7Sj#H1i3>9138 zkhxAU7;M)I18&d!Yw!V9zQA0tp(G4<8U5GX{YoYCQ?p56FxcD-2FwO5fqyx@__=$L zeK6Sg3>XQv)qz1?zW-k$_j`-)tf+yRU_%fXrenc>$^70d1Q-W?T#vy;6#Y-Q-<2)+ z5iTl6MA7j9m&oBhRXTKr*$3gec z3E;zX457RGZwUvD$l&8e42Qb^cbq>zYy@ive8`2N9vk=#6+AQlZZ7qk=?(ap1q0n0 z{B9Fte-{Gi-Tvax1)M+d1}Fyg@9X~sh1m|hsDcZuYOnxriBPN;z)q3<=-yBN2iM6V A?*IS* literal 0 HcmV?d00001 diff --git a/.mvn/wrapper/maven-wrapper.properties b/.mvn/wrapper/maven-wrapper.properties new file mode 100644 index 0000000..5f0536e --- /dev/null +++ b/.mvn/wrapper/maven-wrapper.properties @@ -0,0 +1,2 @@ +distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.5/apache-maven-3.9.5-bin.zip +wrapperUrl=https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.2.0/maven-wrapper-3.2.0.jar diff --git a/README.md b/README.md new file mode 100644 index 0000000..f876d23 --- /dev/null +++ b/README.md @@ -0,0 +1,248 @@ +# Описание функций авторизации +____ +#### Алгоритм +Refresh token токен действует 12 часов и за эти 12 часов не реже чем раз в 3 часа нужно обновить Refresh token ну и заодно Access token обновиться. +Аccess token действует 20 минут (позже уменьшу до 10 минут) и его можно обновить в любое время, если будет просрочен выдаст 401 ошибку. Чтобы время от времени по расписанию не запрашивать обновление токена, +можно сделать обвёртку для 2й отправки запроса, в случае выявления просрочки токена чтобы эта обвёртка отправляла запрос Refresh, а потом обратно в нужное место отправляла запрос. +____ +## Оглавление +1. [Получить список разрешений для пользователя по Access token](#получить-список-разрешений-для-пользователя-по-Access-token) +2. [Получить CAPTCHA с проверочным токеном](#получить-captcha-с-проверочным-токеном) +3. [Создать нового пользователя](#создать-нового-пользователя) +4. [Получить информацию о пользователе по его Access token ](#получить-информацию-о-пользователе-по-его-access-token ) +5. [Авторизоваться](#авторизоваться) +6. [Обновить токен доступа (а также обновить рефреш токен)](#обновить-токен-доступа-а-также-обновить-рефреш-токен) +7. [Ссылка для подтверждения смены пароля (переходят на неё из почты)](#ссылка-для-подтверждения-смены-пароля-переходят-на-неё-из-почты) +8. [Принять капчу и код для инициализации процедуры восстановления пароля](#принять-капчу-и-код-для-инициализации-процедуры-восстановления-пароля) +9. [Обновить пароль по логину и старому паролю](#обновить-пароль-по-логину-и-старому-паролю) +10. [Проверить валидность токена](#проверить-валидность-токена) + +____ + +### Получить список разрешений для пользователя по Access token +https://istransit.kz/api/authorization/v02/access/ + +Запрос может содержать параметры фильтрации для поиска частичного совпадения названия (действия), если параметров фильтрации нет или он равен null то вернёт все записи. + +Пример запроса: +```json +{ + "action_name":"arm_" +} +``` + +Пример ответа: +```json +{ + "error_code": 0, + "error_message": "", + "data": [ + "arm_accounting", + "arm_carrier", + "arm_hr"] +} +``` + +### Получить CAPTCHA с проверочным токеном +https://istransit.kz/api/authorization/v02/captcha/ + +Пример запроса: +```json +{ + "email":"test@mail.ru" +} +``` +Пример ответа: +```json +{ + "image":"тут gif в base64", + "token":"ZUROMC9xQVpRNjVGZGZBSWdrSGk5NHlPK2JXcHJMHVlbWVBPT0=.ywHb5zzI+ARK3XDRpgVkC1fdlqEQWWOXLuVIu\/rRMho=" +} +``` +Где "image" это рисунок в base64 + +А "token" это токен для последующей проверки введённого кода "code":"XXXXXX". + +По умолчанию токен captcha действует 10 минут. + +### Создать нового пользователя +https://istransit.kz/api/authorization/v02/create/ + +Письмо с паролем придёт на почту + +Пример запроса: +```json5 +{ + "country_id": "1", + "company_name": "ТОО 'Тестовая компания'", + "position": "Менеджер", + "name": "Берик", + "surname": "Султанов", + "patronymic": "Серикович", + "phone": "+7777123456", + "email": "test@test.kz", + "code":"11111", //Код с CAPTCHA + "token":"ZUROMC9xQVpRNjVGZGZBSdyc2JIV0ZueHdDMHVlbWVBPT0=.ywHb5zzI+ARK3XDRpgVkC1fdlqEQWWOXLuVIu\/rRMho=" //Токен с CAPTCHA +} +``` +Пример ответа: +```json +{ + "error_code": "0", + "error_message":"" +} +``` + +### Получить информацию о пользователе по его Access token +https://istransit.kz/api/authorization/v02/info/ + +Запрос: +``` +Cookie: jwt_a = Access token +``` +Пример ответа: +```json5 +{ + "error_code": "0", + "error_message": "", + "name": "Igor", + "surname": "M", + "patronymic": "I", + "roles": "Кассир, Кладовщик", + "time": "1703838784", //Время с сервера + "expiration": "1696924443", //Когда "протухнет" пароль + "appid": "postman", + "arm": "monitoring" +} +``` +### Авторизоваться +https://istransit.kz/api/authorization/v02/login/ + +Пример запроса: +```json +{ + "login" : "test@istt.kz", + "password" : "test", + "totp": "123456", + "appid" : "postman" +} +``` +В ответ: +```json5 +{ + "error_code": "0", + "error_message": "", + "name": "Igor", + "surname": "M", + "patronymic": "I", + "roles": "Кассир, Кладовщик", + "time": "1703838784", //Время с сервера + "expiration": "1696924443", //Когда протухает пароль + "appid": "postman", + "arm": "monitoring" +} +``` +Также в ответ Cookie: +``` +Cookie: jwt_a = Access token +Cookie: jwt_r = Refresh token +``` + +### Обновить токен доступа (а также обновить рефреш токен) +https://istransit.kz/api/authorization/v02/refresh/ + +В запросе Cookie: +``` +Cookie: jwt_a = Access token +Cookie: jwt_r = Refresh token +``` +Пример ответа: +```json +{ + "error_code": "0", + "error_message":"" +} +``` +Также в ответе Cookie: +``` +Cookie: jwt_a = Access token +Cookie: jwt_r = Refresh token +``` + +### Ссылка для подтверждения смены пароля (переходят на неё из почты) +https://istransit.kz/api/authorization/v02/reset/ + +Пример запроса: +```html +https://istransit.kz/api/authorization/v02/reset/?token=xxxxx&lng=1 +``` + +В ответ HTML страница с результатом на 7 секунд, с переходом на главную страницу: +```html + + + + + + + +

Описание результата

+ + +``` + +### Принять капчу и код для инициализации процедуры восстановления пароля +https://istransit.kz/api/authorization/v02/restore/ + +Пример запроса: +```json +{ + "code":"11111", + "token":"ZUROMC9xQVpRNjVGZGZBSdyc2JIV0ZueHdDMHVlbWVBPT0=.ywHb5zzI+ARK3XDRpgVkC1fdlqEQWWOXLuVIu\/rRMho=" +} +``` +Код и токен из captcha + +Пример ответа: +```json +{ + "error_code": "0", + "error_message":"" +} +``` + +### Обновить пароль по логину и старому паролю +https://istransit.kz/api/authorization/v02/update/ + +Для этой функции авторизация пользователя не обязательна, а значит пользователя можно не авторизовывать если у него просрочен пароль. + +В новом пароле должно быть цифра, большая латинская буква, маленькая латинская буква, один спец символ и длина не менее 6 символов. + +Пример запроса: +```json +{ + "login":"test@mail.ru", + "password":"12345", + "password_new":"54321" +} +``` +Пример ответа: +```json +{ + "error_code": "0", + "error_message":"" +} +``` + +### Проверить валидность токена +https://istransit.kz/api/authorization/v02/alive/ + +На вход Cookie с jwt_a токеном, на выход код ошибки. + +Пример ответа: +```json +{ + "error_code": "0", + "error_message":"" +} +``` \ No newline at end of file diff --git a/kg_gpti_transit_jwt.properties b/kg_gpti_transit_jwt.properties new file mode 100644 index 0000000..248390b --- /dev/null +++ b/kg_gpti_transit_jwt.properties @@ -0,0 +1,38 @@ +spring.application.name=kg_gpti_jwt +server.port=8082 +issuer.name=transit + +logging.level.com.zaxxer.hikari=DEBUG + +spring.datasource.url=jdbc:postgresql://192.168.6.25:5432/transit?ApplicationName=transit_jwt +spring.datasource.username=postgres +spring.datasource.password=lelPfAtgQWhHYfy1SsHk +spring.datasource.driver-class-name=org.postgresql.Driver + +spring.datasource.hikari.maximum-pool-size=10 +spring.datasource.hikari.minimum-idle=5 +spring.datasource.hikari.max-lifetime=1700000 +spring.datasource.hikari.idle-timeout=600000 +spring.datasource.hikari.connection-timeout=30000 +spring.datasource.hikari.connection-test-query=SELECT now() +spring.datasource.hikari.validation-timeout=60000 + +private.key=MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQD1GHVopvcvpJyU/ha7+R9IDC6EoZyZKZ14XBGu95ikEUSPkIoxE8n6TbF8Srj95OxrowHhOejtMrUhF+NBJNR59evR9ZT1JO2yo/QvvfA834wiDpNzCDFQbGO5emuN9KoinZIpFSyMtjGNlaj7zf01wYIglSqr3kzpTYlF3zlVlW/6oGECA3swKnz9eiNEMg7WEHCIZx+HureHySSJi4MZLizH4EzAW8geUB7Vi5rJLfg5fPcXkJfOcP6PoSnfHqXkSw2DFEoM+hz3vrS/rj05YlkmTTKarnr+GOAc4IhE36zbSx93BaZ4d59Hsk5CuS4qk/sI9dn7IQYJKuypKJiFAgMBAAECggEBAI2AwoBaLUofYpuOmveJm+rPxaejWrL+2MBdf4QhxMmsgoXUcERnZWwSoQ7eYTGMkoaORQ6QjY8sgHCLxxOcPOPw/GZqv8ZMvMMvb1KE+YdblR8whSabq0UAXw79w8zgXb3AdVsss1zF75QLvNUsFy2K/CLtnAZAQO1Na5yghQyIKjKd8YXSP8Ylk15Nz942jbo71h980Uk3mr8tV/PqJ1x7cs1Z5femhQHNFDsuJMRh6TpPDSqEir3ziZs9jVQMR4pAMm5bCvfcsnOPaltomRymUKOTdvHBVv1LCTWNipQgqNPMitmcWtJnC48j62M5ADtnF1p30VezMQnylLS+3kECgYEA+rXZQdbndKHaROTE1bDAmthxgrOBW5wrzZ7B9Z0zDnrsuOa8bk8Dc0WNGd8/mzKz1t4fAfA7W9c/748erhwUFhBlzpv8COOcEJwWSL4dV0mCLBqMuhmb4yJRYwv2kVEdFvbWPjKRhr7WcnIV7rrbc/jr3kdr/aKSXzxt7J0BaDUCgYEA+kRIb8/0XC6YJL84v8NlkpgaGx7BDGqIsjVYrWAfTWtS01HxT+39QG6T5tT6rgkIN1FBxkvSvvuz2/mwSpAvVktCuZyIHoAutJUuowwwT9yYy0zaLyrhX44zoXZiHmZAHObxo1oYogtH64yhiC3X+uLtScW0g5Z7SFxjDOTFmRECgYEAxVNnwjhhSB0z7FGa0w4hKj79aH/carxKhbZUtvqZeuYpd4az/KZX8txlKF3cdEy923pMMXxhW/HZMrYU0bjr3kndt3ZyMpTi+ve/WlW4RkFnIUtsQ/VwCp+yKyD5WnrbSH3TNnUasVF2+/DrblDH9UmQbA0O5DyWtDqd0kPpHZkCgYEAs95rqWDuoWojkxWUNc67q9aBvMgnu0K+KEbLCyCwnrXp+1NDekzz3WEcD6U23epD624NNfW86+J/bDRSjeR/AShqNnjYJAPAja1CrZDPEDbd4g/EKG5LOKA9X2h0MKEQpzUcqmjQl3ZAJH0Yg4VfW0PJg2IC0ShQRruPvO6XTeECgYA54eQya6sEIpE7aIKXwitRMV3VE8jMP5cQHTLK841pFPKiC2iMQDrgJqjYuMJUdhx2WRhoHQwy76XvLMWzLmD+k2U4DwzSq3APc6r+m4EesUdhsmt8/DFyR29OT0r7OuVVppQbQ+SPHrtNxVrAVuwhpnfW8rTdZRdbPHAnwgs/lg== +public.key=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9Rh1aKb3L6SclP4Wu/kfSAwuhKGcmSmdeFwRrveYpBFEj5CKMRPJ+k2xfEq4/eTsa6MB4Tno7TK1IRfjQSTUefXr0fWU9STtsqP0L73wPN+MIg6TcwgxUGxjuXprjfSqIp2SKRUsjLYxjZWo+839NcGCIJUqq95M6U2JRd85VZVv+qBhAgN7MCp8/XojRDIO1hBwiGcfh7q3h8kkiYuDGS4sx+BMwFvIHlAe1YuayS34OXz3F5CXznD+j6Ep3x6l5EsNgxRKDPoc9760v649OWJZJk0ymq56/hjgHOCIRN+s20sfdwWmeHefR7JOQrkuKpP7CPXZ+yEGCSrsqSiYhQIDAQAB +access.time=600 +refresh.time=43200 + +captcha.key=PPExpv36jk4Vzda3NpYnXLfuHCLYXqaNrxlOH/Jr/1M= +captcha.time=600 + +mail.host=mail.gpti.kg +mail.port=587 +mail.login=noreply@gpti.kg +mail.password=PasW#vc!a24 + +url.reset=https://transit.gpti.kg/api/authorization/v02/reset +url.main=https://transit.gpti.kg/ + +spring.redis.host=192.168.6.25 +spring.redis.port=6379 +spring.redis.password=9F3/NKWeOjd815vkadT2DcgVHf6fEpVQXw== diff --git a/kz_istransit_jwt.properties b/kz_istransit_jwt.properties new file mode 100644 index 0000000..530bfd3 --- /dev/null +++ b/kz_istransit_jwt.properties @@ -0,0 +1,40 @@ +spring.application.name=kz_istransit_jwt +server.port=8082 +issuer.name=istransit + +logging.level.com.zaxxer.hikari=DEBUG + +spring.datasource.url=jdbc:postgresql://10.101.1.6:5432/transit_2024_09_03?ApplicationName=kz_istransit_jwt +spring.datasource.username=postgres +spring.datasource.password=PasSecrKey1 +spring.datasource.driver-class-name=org.postgresql.Driver + +spring.datasource.hikari.maximum-pool-size=10 +spring.datasource.hikari.minimum-idle=5 +spring.datasource.hikari.max-lifetime=1700000 +spring.datasource.hikari.idle-timeout=600000 +spring.datasource.hikari.connection-timeout=30000 +spring.datasource.hikari.connection-test-query=SELECT now() +spring.datasource.hikari.validation-timeout=60000 + + +private.key=MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCsrV60WgOCbFDz7mrr5Ade4wSrKjgB4PX+Y2zzttc87FKILzZswpQv2XLRZXEbkgpAViV99BsKDSd0f46FTynTH3SqbAJ4KfhsVPqfMD2yNjJBJSRyLZ19QAFdyyveRI/b4oQ+dOl0ZhlAUQ5Hfg5G34cE/AyfoVaHRol2ZOpkf5XL90/dPKxPsAaWw+LwgD2PdqzINl1L17EspVUjNiRsclQqkodhzhP/brRhq5S03KKNtPnDhlZJsep67NX8cZQJgil8BnIzGHMqdFF+NBZoLPy/+r4U/Vr6O1oPZ7RK3ontY6fJPHY/bI17KxwQusk8C3tPJNwg2U3mhkJ3mF93AgMBAAECggEAE9nCX11RtfaZv9ESvZdzOXdDnCG4Wo7v+JSZe9LzH2/TdRBoY0xjGLUYu/W7cP3y6757hOVBDoDAnmXjjnOxTTH6iXTtO78nbdy/CvnSvd/5GwAYFoAj8Lgg8BVhL6YWG6MIrN1n0RfDo18uEw3suj0MGoiXMuqrNdXoC5JCV9cajVSDhABw761sNrwBgYCOxk28KrfTRLh6QsQGSf8stLDDwgfImWXJTLzKacFAemNRFuBqp+pQdVuBtorN9rYoGyiswVBTWIA06uUYZqK1uIRLh7wHf2cFARm5rREDwYmG8EHe8JXYeOU2JUF/Rd0V4EQVZHFB4VLwYYumwq2XUQKBgQDcyrmpaA7xjt7ilIV50CtzrY8hAJST2bbdnl/aMm7JI/ZjNFVXbTDHxUen0IvyHmpPS1Z3K8XJ2IR07L7vO3E96OJcYsU2dJ9/HZ5Vg+Q+f3TrscbNRc6Dn6knG9Vr/D/x3pJoyRR7VoWQXs6y87Df5eVtdjmzTTKtY/tmMhEyrQKBgQDINnvwg9vxhhaqflQmNCxGoAkImrYsyGBVlhOy3qbqnMVSQGW8ub/MChpNPrOBTNq6Nb7kK4dzYGSa7lK3vjX+9bc/8vUY69DpV9yZpp370UXTnrKkPUIgrVHiQfjfOXDXeHcpCNQD7E+cDM+DtPtgjtPV966HipFMSvOBmohDMwKBgQDY3Ro9ZeL/qpgLr1vnCOwVBA1ImhxVmIt/5FY7qDuevv778+Q7Khm2rnQyRamfl/ZNii8UgF8WYd/AROVJb3ZMG9lyauVQFn6uyXXCgviF1oUOGCCvcPhl2kW4DyOynCJmvHnMCG1gs9wesLCPnsJFOLb/rBcCoTm8iy7b8yNnRQKBgCeDSTaQb2ndMr/3KphXl51gnCfMkMOJ0ClT8xNMCdknk3HGL83tQsL8A3DXPQn5pvk0/jV9ub+1eGVzP3Pv4CwvRjkis+h1Mce7hVf1oBxAku1O1qa/SDu2uQBUUM+NQI3lwm6gxWb4zkVX6eRuZWYLCheiSBmL6V0LNb+QRfAtAoGBAJ4tM34ovk0Ag/fRjxgEYqo7FcMplBs3nymGV/zS9QQA4gorGq5mBiQX0n8wR68UpKz7u1NXNXc7hJGvP0uHK+/GCQd9i1Csow641TIdMv+4XhQl2/ZO0NuJb/NVB6qJ93WlnhWJP3s1a1zVlRyF3+Zn0D8nbBp+tkCbET0+XGuB +public.key=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArK1etFoDgmxQ8+5q6+QHXuMEqyo4AeD1/mNs87bXPOxSiC82bMKUL9ly0WVxG5IKQFYlffQbCg0ndH+OhU8p0x90qmwCeCn4bFT6nzA9sjYyQSUkci2dfUABXcsr3kSP2+KEPnTpdGYZQFEOR34ORt+HBPwMn6FWh0aJdmTqZH+Vy/dP3TysT7AGlsPi8IA9j3asyDZdS9exLKVVIzYkbHJUKpKHYc4T/260YauUtNyijbT5w4ZWSbHqeuzV/HGUCYIpfAZyMxhzKnRRfjQWaCz8v/q+FP1a+jtaD2e0St6J7WOnyTx2P2yNeyscELrJPAt7TyTcINlN5oZCd5hfdwIDAQAB +access.time=600 +refresh.time=43200 + + +captcha.key=PPExpv36jk4Vzda3NpYnXLfuHCLYXqaNrxlOH/Jr/1M= +captcha.time=600 + +mail.host=92.46.51.29 +mail.port=465 +mail.login=no-reply@istt.kz +mail.password=je6&HHCEmJ + +url.reset=http://127.0.0.1:8088/reset +url.main=http://127.0.0.1:8088/ + +spring.redis.host=10.101.1.6 +spring.redis.port=6379 +spring.redis.password=9F3/NKWeOjd815vkadT2DcgVHf6fEpVQXw== diff --git a/kz_mcp_jwt.properties b/kz_mcp_jwt.properties new file mode 100644 index 0000000..f630f17 --- /dev/null +++ b/kz_mcp_jwt.properties @@ -0,0 +1,43 @@ +spring.application.name=kz_mcp_jwt +server.port=8082 +issuer.name=geovizor + +logging.level.com.zaxxer.hikari=DEBUG + +#spring.datasource.url=jdbc:postgresql://geovizor.com:5432/monitoring_new +#spring.datasource.username=postgres +#spring.datasource.password=y7HMHi0ATxx1VC3UU5WG +#spring.datasource.driver-class-name=org.postgresql.Driver + +spring.datasource.url=jdbc:postgresql://mcp.kz:5432/mcp +spring.datasource.username=igor +spring.datasource.password=VnzbUdcePSLtg22ktz13 +spring.datasource.driver-class-name=org.postgresql.Driver + +spring.datasource.hikari.maximum-pool-size=10 +spring.datasource.hikari.minimum-idle=5 +spring.datasource.hikari.max-lifetime=600000 +spring.datasource.hikari.idle-timeout=60000 +spring.datasource.hikari.connection-timeout=30000 +spring.datasource.hikari.connection-test-query=SELECT 1 +spring.datasource.hikari.validation-timeout=30000 + +public.key=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA30j+pSoKFHSdSulIGzdFtg+z+ANJPOSVFJ6jvehj1sonOqQsI2rz539+FgIrsDZE8iydFAlQNxS8vqYtWiQSksAUId7aOY/eq7mFkGW+U5xIA2OPgIvN0uhW1Edm85jS7aAg/P/c+lLHnPzQIFdsgVrAh4esFvVS10Pj6TjJVprDj0jOraIw84GVt0gYXZTudcvZavWcmGV1mQJf0jDIHQsCRcMJAE2lzBIKpJGPPZke9xs25lm8feTFR0NNjDNvCG4dYAimyAH36UslXa/zIfRB/7r4AB9KPBFxGe8szK1EcXbJY+paq+TazZJ8Lo8nEmpehCdHUNdD9iWtiYRjNQIDAQAB +private.key=MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQDfSP6lKgoUdJ1K6UgbN0W2D7P4A0k85JUUnqO96GPWyic6pCwjavPnf34WAiuwNkTyLJ0UCVA3FLy+pi1aJBKSwBQh3to5j96ruYWQZb5TnEgDY4+Ai83S6FbUR2bzmNLtoCD8/9z6Usec/NAgV2yBWsCHh6wW9VLXQ+PpOMlWmsOPSM6tojDzgZW3SBhdlO51y9lq9ZyYZXWZAl/SMMgdCwJFwwkATaXMEgqkkY89mR73GzbmWbx95MVHQ02MM28Ibh1gCKbIAffpSyVdr/Mh9EH/uvgAH0o8EXEZ7yzMrURxdslj6lqr5NrNknwujycSal6EJ0dQ10P2Ja2JhGM1AgMBAAECggEAPWsLuIzOxv+owJFYpzvV7hV1sJPe0mQh6dEVQ0ioJc3naob8KSXjP1tfaFhigg77eg3xizBgozYOEPcO5IulnD4/i22MY2cCngPjDGwgJUmIuX3qXDaYgBouwCd/1yPDaV+xk0YiF60rgTA9Y5gInbBD40Pbf1kt106yY1WedDaMaogilC6nZwde7H6UQrjoxQ3fSyw9brH04Vma7awcaEYQ6C0NM4uMJFws9jnwDXkYh0QnPW5eIIf9gmr2a+FtKtqlQyZiCjrQOJuU2TQo9wgKiOkVRIfmivXbt5I1O7SkPPUl2mtQAjbZxtHqooLC6It9svO/4rRJY0egjvsGZQKBgQDwCTGhExOahz/UH0I58Ksq44Zz6c6wt7Pt8U2S9L4Sfgjt4Gxu5XcdgMchZHu+xQtONpd7HWO4d9zK1IIHgJ/4IBMA2Lcp7EglHsnuc9II31EU9uP6Ar3yD3UC3zP/lszQs7t3Tagpq3I0bUuSnKH+SMW+mKztg5Xiu4x72HeIGwKBgQDuIpryaOhCEuwN6VguTSStNJe6fxI1NlHLF0anacuT43MotsRXYWRKWdu2nkupB3SqY+Lxipibu8I5CkWoKV8pbGYSqW8YDSzxoSPocTrbkuai7mczMSBCtFZ3nDFx1J3O2IJZaBT4OA+HEVaj+rzeyEYrwACmtSAl+YBNXE4W7wKBgH4ohuIe0aXdQgnuJ/Ol74DKNueDUnQFCVedBOWhJqk3ft/vnW4nwpRKE98UHgnlLIz+Gl3F05ynuu8MBA+HZgyWZwaB4LrzCfQgm4dtbk3leYsoPCgx+r1XrGtG/uBt1NY4MOaCdUj5aDvv2dGD64xnmS8UtYbcKxIQ+sQ4wJJTAoGAVOcVo3Pvyw8ABn25qNhsSSzFJAMGNN6nDue/kxTPNm0Ts+Jl4lmg7jlXcqbBhwRXfiCa20901aF9v+R/rVMC0LwLMIAkUcjwyz2OleM4/uxDOrgRJ1lOjTnK0l5n6pPJp+PdpY7MWytxrdBquZA+Ipf5HMQZ91YAnkl0iyBr3xUCgYBNBIb0fVTlAf7KJ4urjOE+305oRmEU5eHK2KiAViPDj16BuPy/hE11BnZE5HT4AMfuAm6AmLdrdiyb2iROMrsEQ8AFsGaFsY/njXqV75nNWceLpqrMk1FcYmnAEv0X/RhvsPzv79RzEf9jyjZlQ1XMfBfuuwwjWaUTLBcQhGFOqQ== +access.time=600 +refresh.time=43200 + +captcha.key=PPExpv36jk4Vzda3NpYnXLfuHCLYXqaNrxlOH/Jr/1M= +captcha.time=600 + +mail.host=smtp.yandex.ru +mail.port=465 +mail.login=info@ccalm.org +mail.password=fu2lpsoGPGiq1xlRm8ag + +url.reset=https://mcp.test/api/authorization/login/reset +url.main=https://mcp.test/ + +spring.redis.host=127.0.0.1 +spring.redis.port=6379 +spring.redis.password=9F3/NKWeOjd815vkadT2DcgVHf6fEpVQXw== diff --git a/mvnw b/mvnw new file mode 100644 index 0000000..66df285 --- /dev/null +++ b/mvnw @@ -0,0 +1,308 @@ +#!/bin/sh +# ---------------------------------------------------------------------------- +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +# ---------------------------------------------------------------------------- + +# ---------------------------------------------------------------------------- +# Apache Maven Wrapper startup batch script, version 3.2.0 +# +# Required ENV vars: +# ------------------ +# JAVA_HOME - location of a JDK home dir +# +# Optional ENV vars +# ----------------- +# MAVEN_OPTS - parameters passed to the Java VM when running Maven +# e.g. to debug Maven itself, use +# set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 +# MAVEN_SKIP_RC - flag to disable loading of mavenrc files +# ---------------------------------------------------------------------------- + +if [ -z "$MAVEN_SKIP_RC" ] ; then + + if [ -f /usr/local/etc/mavenrc ] ; then + . /usr/local/etc/mavenrc + fi + + if [ -f /etc/mavenrc ] ; then + . /etc/mavenrc + fi + + if [ -f "$HOME/.mavenrc" ] ; then + . "$HOME/.mavenrc" + fi + +fi + +# OS specific support. $var _must_ be set to either true or false. +cygwin=false; +darwin=false; +mingw=false +case "$(uname)" in + CYGWIN*) cygwin=true ;; + MINGW*) mingw=true;; + Darwin*) darwin=true + # Use /usr/libexec/java_home if available, otherwise fall back to /Library/Java/Home + # See https://developer.apple.com/library/mac/qa/qa1170/_index.html + if [ -z "$JAVA_HOME" ]; then + if [ -x "/usr/libexec/java_home" ]; then + JAVA_HOME="$(/usr/libexec/java_home)"; export JAVA_HOME + else + JAVA_HOME="/Library/Java/Home"; export JAVA_HOME + fi + fi + ;; +esac + +if [ -z "$JAVA_HOME" ] ; then + if [ -r /etc/gentoo-release ] ; then + JAVA_HOME=$(java-config --jre-home) + fi +fi + +# For Cygwin, ensure paths are in UNIX format before anything is touched +if $cygwin ; then + [ -n "$JAVA_HOME" ] && + JAVA_HOME=$(cygpath --unix "$JAVA_HOME") + [ -n "$CLASSPATH" ] && + CLASSPATH=$(cygpath --path --unix "$CLASSPATH") +fi + +# For Mingw, ensure paths are in UNIX format before anything is touched +if $mingw ; then + [ -n "$JAVA_HOME" ] && [ -d "$JAVA_HOME" ] && + JAVA_HOME="$(cd "$JAVA_HOME" || (echo "cannot cd into $JAVA_HOME."; exit 1); pwd)" +fi + +if [ -z "$JAVA_HOME" ]; then + javaExecutable="$(which javac)" + if [ -n "$javaExecutable" ] && ! [ "$(expr "\"$javaExecutable\"" : '\([^ ]*\)')" = "no" ]; then + # readlink(1) is not available as standard on Solaris 10. + readLink=$(which readlink) + if [ ! "$(expr "$readLink" : '\([^ ]*\)')" = "no" ]; then + if $darwin ; then + javaHome="$(dirname "\"$javaExecutable\"")" + javaExecutable="$(cd "\"$javaHome\"" && pwd -P)/javac" + else + javaExecutable="$(readlink -f "\"$javaExecutable\"")" + fi + javaHome="$(dirname "\"$javaExecutable\"")" + javaHome=$(expr "$javaHome" : '\(.*\)/bin') + JAVA_HOME="$javaHome" + export JAVA_HOME + fi + fi +fi + +if [ -z "$JAVACMD" ] ; then + if [ -n "$JAVA_HOME" ] ; then + if [ -x "$JAVA_HOME/jre/sh/java" ] ; then + # IBM's JDK on AIX uses strange locations for the executables + JAVACMD="$JAVA_HOME/jre/sh/java" + else + JAVACMD="$JAVA_HOME/bin/java" + fi + else + JAVACMD="$(\unset -f command 2>/dev/null; \command -v java)" + fi +fi + +if [ ! -x "$JAVACMD" ] ; then + echo "Error: JAVA_HOME is not defined correctly." >&2 + echo " We cannot execute $JAVACMD" >&2 + exit 1 +fi + +if [ -z "$JAVA_HOME" ] ; then + echo "Warning: JAVA_HOME environment variable is not set." +fi + +# traverses directory structure from process work directory to filesystem root +# first directory with .mvn subdirectory is considered project base directory +find_maven_basedir() { + if [ -z "$1" ] + then + echo "Path not specified to find_maven_basedir" + return 1 + fi + + basedir="$1" + wdir="$1" + while [ "$wdir" != '/' ] ; do + if [ -d "$wdir"/.mvn ] ; then + basedir=$wdir + break + fi + # workaround for JBEAP-8937 (on Solaris 10/Sparc) + if [ -d "${wdir}" ]; then + wdir=$(cd "$wdir/.." || exit 1; pwd) + fi + # end of workaround + done + printf '%s' "$(cd "$basedir" || exit 1; pwd)" +} + +# concatenates all lines of a file +concat_lines() { + if [ -f "$1" ]; then + # Remove \r in case we run on Windows within Git Bash + # and check out the repository with auto CRLF management + # enabled. Otherwise, we may read lines that are delimited with + # \r\n and produce $'-Xarg\r' rather than -Xarg due to word + # splitting rules. + tr -s '\r\n' ' ' < "$1" + fi +} + +log() { + if [ "$MVNW_VERBOSE" = true ]; then + printf '%s\n' "$1" + fi +} + +BASE_DIR=$(find_maven_basedir "$(dirname "$0")") +if [ -z "$BASE_DIR" ]; then + exit 1; +fi + +MAVEN_PROJECTBASEDIR=${MAVEN_BASEDIR:-"$BASE_DIR"}; export MAVEN_PROJECTBASEDIR +log "$MAVEN_PROJECTBASEDIR" + +########################################################################################## +# Extension to allow automatically downloading the maven-wrapper.jar from Maven-central +# This allows using the maven wrapper in projects that prohibit checking in binary data. +########################################################################################## +wrapperJarPath="$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.jar" +if [ -r "$wrapperJarPath" ]; then + log "Found $wrapperJarPath" +else + log "Couldn't find $wrapperJarPath, downloading it ..." + + if [ -n "$MVNW_REPOURL" ]; then + wrapperUrl="$MVNW_REPOURL/org/apache/maven/wrapper/maven-wrapper/3.2.0/maven-wrapper-3.2.0.jar" + else + wrapperUrl="https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.2.0/maven-wrapper-3.2.0.jar" + fi + while IFS="=" read -r key value; do + # Remove '\r' from value to allow usage on windows as IFS does not consider '\r' as a separator ( considers space, tab, new line ('\n'), and custom '=' ) + safeValue=$(echo "$value" | tr -d '\r') + case "$key" in (wrapperUrl) wrapperUrl="$safeValue"; break ;; + esac + done < "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.properties" + log "Downloading from: $wrapperUrl" + + if $cygwin; then + wrapperJarPath=$(cygpath --path --windows "$wrapperJarPath") + fi + + if command -v wget > /dev/null; then + log "Found wget ... using wget" + [ "$MVNW_VERBOSE" = true ] && QUIET="" || QUIET="--quiet" + if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then + wget $QUIET "$wrapperUrl" -O "$wrapperJarPath" || rm -f "$wrapperJarPath" + else + wget $QUIET --http-user="$MVNW_USERNAME" --http-password="$MVNW_PASSWORD" "$wrapperUrl" -O "$wrapperJarPath" || rm -f "$wrapperJarPath" + fi + elif command -v curl > /dev/null; then + log "Found curl ... using curl" + [ "$MVNW_VERBOSE" = true ] && QUIET="" || QUIET="--silent" + if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then + curl $QUIET -o "$wrapperJarPath" "$wrapperUrl" -f -L || rm -f "$wrapperJarPath" + else + curl $QUIET --user "$MVNW_USERNAME:$MVNW_PASSWORD" -o "$wrapperJarPath" "$wrapperUrl" -f -L || rm -f "$wrapperJarPath" + fi + else + log "Falling back to using Java to download" + javaSource="$MAVEN_PROJECTBASEDIR/.mvn/wrapper/MavenWrapperDownloader.java" + javaClass="$MAVEN_PROJECTBASEDIR/.mvn/wrapper/MavenWrapperDownloader.class" + # For Cygwin, switch paths to Windows format before running javac + if $cygwin; then + javaSource=$(cygpath --path --windows "$javaSource") + javaClass=$(cygpath --path --windows "$javaClass") + fi + if [ -e "$javaSource" ]; then + if [ ! -e "$javaClass" ]; then + log " - Compiling MavenWrapperDownloader.java ..." + ("$JAVA_HOME/bin/javac" "$javaSource") + fi + if [ -e "$javaClass" ]; then + log " - Running MavenWrapperDownloader.java ..." + ("$JAVA_HOME/bin/java" -cp .mvn/wrapper MavenWrapperDownloader "$wrapperUrl" "$wrapperJarPath") || rm -f "$wrapperJarPath" + fi + fi + fi +fi +########################################################################################## +# End of extension +########################################################################################## + +# If specified, validate the SHA-256 sum of the Maven wrapper jar file +wrapperSha256Sum="" +while IFS="=" read -r key value; do + case "$key" in (wrapperSha256Sum) wrapperSha256Sum=$value; break ;; + esac +done < "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.properties" +if [ -n "$wrapperSha256Sum" ]; then + wrapperSha256Result=false + if command -v sha256sum > /dev/null; then + if echo "$wrapperSha256Sum $wrapperJarPath" | sha256sum -c > /dev/null 2>&1; then + wrapperSha256Result=true + fi + elif command -v shasum > /dev/null; then + if echo "$wrapperSha256Sum $wrapperJarPath" | shasum -a 256 -c > /dev/null 2>&1; then + wrapperSha256Result=true + fi + else + echo "Checksum validation was requested but neither 'sha256sum' or 'shasum' are available." + echo "Please install either command, or disable validation by removing 'wrapperSha256Sum' from your maven-wrapper.properties." + exit 1 + fi + if [ $wrapperSha256Result = false ]; then + echo "Error: Failed to validate Maven wrapper SHA-256, your Maven wrapper might be compromised." >&2 + echo "Investigate or delete $wrapperJarPath to attempt a clean download." >&2 + echo "If you updated your Maven version, you need to update the specified wrapperSha256Sum property." >&2 + exit 1 + fi +fi + +MAVEN_OPTS="$(concat_lines "$MAVEN_PROJECTBASEDIR/.mvn/jvm.config") $MAVEN_OPTS" + +# For Cygwin, switch paths to Windows format before running java +if $cygwin; then + [ -n "$JAVA_HOME" ] && + JAVA_HOME=$(cygpath --path --windows "$JAVA_HOME") + [ -n "$CLASSPATH" ] && + CLASSPATH=$(cygpath --path --windows "$CLASSPATH") + [ -n "$MAVEN_PROJECTBASEDIR" ] && + MAVEN_PROJECTBASEDIR=$(cygpath --path --windows "$MAVEN_PROJECTBASEDIR") +fi + +# Provide a "standardized" way to retrieve the CLI args that will +# work with both Windows and non-Windows executions. +MAVEN_CMD_LINE_ARGS="$MAVEN_CONFIG $*" +export MAVEN_CMD_LINE_ARGS + +WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain + +# shellcheck disable=SC2086 # safe args +exec "$JAVACMD" \ + $MAVEN_OPTS \ + $MAVEN_DEBUG_OPTS \ + -classpath "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.jar" \ + "-Dmaven.multiModuleProjectDirectory=${MAVEN_PROJECTBASEDIR}" \ + ${WRAPPER_LAUNCHER} $MAVEN_CONFIG "$@" diff --git a/mvnw.cmd b/mvnw.cmd new file mode 100644 index 0000000..95ba6f5 --- /dev/null +++ b/mvnw.cmd @@ -0,0 +1,205 @@ +@REM ---------------------------------------------------------------------------- +@REM Licensed to the Apache Software Foundation (ASF) under one +@REM or more contributor license agreements. See the NOTICE file +@REM distributed with this work for additional information +@REM regarding copyright ownership. The ASF licenses this file +@REM to you under the Apache License, Version 2.0 (the +@REM "License"); you may not use this file except in compliance +@REM with the License. You may obtain a copy of the License at +@REM +@REM https://www.apache.org/licenses/LICENSE-2.0 +@REM +@REM Unless required by applicable law or agreed to in writing, +@REM software distributed under the License is distributed on an +@REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +@REM KIND, either express or implied. See the License for the +@REM specific language governing permissions and limitations +@REM under the License. +@REM ---------------------------------------------------------------------------- + +@REM ---------------------------------------------------------------------------- +@REM Apache Maven Wrapper startup batch script, version 3.2.0 +@REM +@REM Required ENV vars: +@REM JAVA_HOME - location of a JDK home dir +@REM +@REM Optional ENV vars +@REM MAVEN_BATCH_ECHO - set to 'on' to enable the echoing of the batch commands +@REM MAVEN_BATCH_PAUSE - set to 'on' to wait for a keystroke before ending +@REM MAVEN_OPTS - parameters passed to the Java VM when running Maven +@REM e.g. to debug Maven itself, use +@REM set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 +@REM MAVEN_SKIP_RC - flag to disable loading of mavenrc files +@REM ---------------------------------------------------------------------------- + +@REM Begin all REM lines with '@' in case MAVEN_BATCH_ECHO is 'on' +@echo off +@REM set title of command window +title %0 +@REM enable echoing by setting MAVEN_BATCH_ECHO to 'on' +@if "%MAVEN_BATCH_ECHO%" == "on" echo %MAVEN_BATCH_ECHO% + +@REM set %HOME% to equivalent of $HOME +if "%HOME%" == "" (set "HOME=%HOMEDRIVE%%HOMEPATH%") + +@REM Execute a user defined script before this one +if not "%MAVEN_SKIP_RC%" == "" goto skipRcPre +@REM check for pre script, once with legacy .bat ending and once with .cmd ending +if exist "%USERPROFILE%\mavenrc_pre.bat" call "%USERPROFILE%\mavenrc_pre.bat" %* +if exist "%USERPROFILE%\mavenrc_pre.cmd" call "%USERPROFILE%\mavenrc_pre.cmd" %* +:skipRcPre + +@setlocal + +set ERROR_CODE=0 + +@REM To isolate internal variables from possible post scripts, we use another setlocal +@setlocal + +@REM ==== START VALIDATION ==== +if not "%JAVA_HOME%" == "" goto OkJHome + +echo. +echo Error: JAVA_HOME not found in your environment. >&2 +echo Please set the JAVA_HOME variable in your environment to match the >&2 +echo location of your Java installation. >&2 +echo. +goto error + +:OkJHome +if exist "%JAVA_HOME%\bin\java.exe" goto init + +echo. +echo Error: JAVA_HOME is set to an invalid directory. >&2 +echo JAVA_HOME = "%JAVA_HOME%" >&2 +echo Please set the JAVA_HOME variable in your environment to match the >&2 +echo location of your Java installation. >&2 +echo. +goto error + +@REM ==== END VALIDATION ==== + +:init + +@REM Find the project base dir, i.e. the directory that contains the folder ".mvn". +@REM Fallback to current working directory if not found. + +set MAVEN_PROJECTBASEDIR=%MAVEN_BASEDIR% +IF NOT "%MAVEN_PROJECTBASEDIR%"=="" goto endDetectBaseDir + +set EXEC_DIR=%CD% +set WDIR=%EXEC_DIR% +:findBaseDir +IF EXIST "%WDIR%"\.mvn goto baseDirFound +cd .. +IF "%WDIR%"=="%CD%" goto baseDirNotFound +set WDIR=%CD% +goto findBaseDir + +:baseDirFound +set MAVEN_PROJECTBASEDIR=%WDIR% +cd "%EXEC_DIR%" +goto endDetectBaseDir + +:baseDirNotFound +set MAVEN_PROJECTBASEDIR=%EXEC_DIR% +cd "%EXEC_DIR%" + +:endDetectBaseDir + +IF NOT EXIST "%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config" goto endReadAdditionalConfig + +@setlocal EnableExtensions EnableDelayedExpansion +for /F "usebackq delims=" %%a in ("%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config") do set JVM_CONFIG_MAVEN_PROPS=!JVM_CONFIG_MAVEN_PROPS! %%a +@endlocal & set JVM_CONFIG_MAVEN_PROPS=%JVM_CONFIG_MAVEN_PROPS% + +:endReadAdditionalConfig + +SET MAVEN_JAVA_EXE="%JAVA_HOME%\bin\java.exe" +set WRAPPER_JAR="%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.jar" +set WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain + +set WRAPPER_URL="https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.2.0/maven-wrapper-3.2.0.jar" + +FOR /F "usebackq tokens=1,2 delims==" %%A IN ("%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.properties") DO ( + IF "%%A"=="wrapperUrl" SET WRAPPER_URL=%%B +) + +@REM Extension to allow automatically downloading the maven-wrapper.jar from Maven-central +@REM This allows using the maven wrapper in projects that prohibit checking in binary data. +if exist %WRAPPER_JAR% ( + if "%MVNW_VERBOSE%" == "true" ( + echo Found %WRAPPER_JAR% + ) +) else ( + if not "%MVNW_REPOURL%" == "" ( + SET WRAPPER_URL="%MVNW_REPOURL%/org/apache/maven/wrapper/maven-wrapper/3.2.0/maven-wrapper-3.2.0.jar" + ) + if "%MVNW_VERBOSE%" == "true" ( + echo Couldn't find %WRAPPER_JAR%, downloading it ... + echo Downloading from: %WRAPPER_URL% + ) + + powershell -Command "&{"^ + "$webclient = new-object System.Net.WebClient;"^ + "if (-not ([string]::IsNullOrEmpty('%MVNW_USERNAME%') -and [string]::IsNullOrEmpty('%MVNW_PASSWORD%'))) {"^ + "$webclient.Credentials = new-object System.Net.NetworkCredential('%MVNW_USERNAME%', '%MVNW_PASSWORD%');"^ + "}"^ + "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; $webclient.DownloadFile('%WRAPPER_URL%', '%WRAPPER_JAR%')"^ + "}" + if "%MVNW_VERBOSE%" == "true" ( + echo Finished downloading %WRAPPER_JAR% + ) +) +@REM End of extension + +@REM If specified, validate the SHA-256 sum of the Maven wrapper jar file +SET WRAPPER_SHA_256_SUM="" +FOR /F "usebackq tokens=1,2 delims==" %%A IN ("%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.properties") DO ( + IF "%%A"=="wrapperSha256Sum" SET WRAPPER_SHA_256_SUM=%%B +) +IF NOT %WRAPPER_SHA_256_SUM%=="" ( + powershell -Command "&{"^ + "$hash = (Get-FileHash \"%WRAPPER_JAR%\" -Algorithm SHA256).Hash.ToLower();"^ + "If('%WRAPPER_SHA_256_SUM%' -ne $hash){"^ + " Write-Output 'Error: Failed to validate Maven wrapper SHA-256, your Maven wrapper might be compromised.';"^ + " Write-Output 'Investigate or delete %WRAPPER_JAR% to attempt a clean download.';"^ + " Write-Output 'If you updated your Maven version, you need to update the specified wrapperSha256Sum property.';"^ + " exit 1;"^ + "}"^ + "}" + if ERRORLEVEL 1 goto error +) + +@REM Provide a "standardized" way to retrieve the CLI args that will +@REM work with both Windows and non-Windows executions. +set MAVEN_CMD_LINE_ARGS=%* + +%MAVEN_JAVA_EXE% ^ + %JVM_CONFIG_MAVEN_PROPS% ^ + %MAVEN_OPTS% ^ + %MAVEN_DEBUG_OPTS% ^ + -classpath %WRAPPER_JAR% ^ + "-Dmaven.multiModuleProjectDirectory=%MAVEN_PROJECTBASEDIR%" ^ + %WRAPPER_LAUNCHER% %MAVEN_CONFIG% %* +if ERRORLEVEL 1 goto error +goto end + +:error +set ERROR_CODE=1 + +:end +@endlocal & set ERROR_CODE=%ERROR_CODE% + +if not "%MAVEN_SKIP_RC%"=="" goto skipRcPost +@REM check for post script, once with legacy .bat ending and once with .cmd ending +if exist "%USERPROFILE%\mavenrc_post.bat" call "%USERPROFILE%\mavenrc_post.bat" +if exist "%USERPROFILE%\mavenrc_post.cmd" call "%USERPROFILE%\mavenrc_post.cmd" +:skipRcPost + +@REM pause the script if MAVEN_BATCH_PAUSE is set to 'on' +if "%MAVEN_BATCH_PAUSE%"=="on" pause + +if "%MAVEN_TERMINATE_CMD%"=="on" exit %ERROR_CODE% + +cmd /C exit /B %ERROR_CODE% diff --git a/org_ccalm_jwt.properties b/org_ccalm_jwt.properties new file mode 100644 index 0000000..52e962c --- /dev/null +++ b/org_ccalm_jwt.properties @@ -0,0 +1,38 @@ +spring.application.name=org_ccalm_jwt +server.port=8082 +issuer.name=ccalm + +logging.level.com.zaxxer.hikari=DEBUG + +spring.datasource.url=jdbc:postgresql://91.201.214.156:5432/CCALM?ApplicationName=org_ccalm_jwt +spring.datasource.username=postgres +spring.datasource.password=PasSecrKey1 +spring.datasource.driver-class-name=org.postgresql.Driver + +spring.datasource.hikari.maximum-pool-size=10 +spring.datasource.hikari.minimum-idle=5 +spring.datasource.hikari.max-lifetime=1700000 +spring.datasource.hikari.idle-timeout=600000 +spring.datasource.hikari.connection-timeout=30000 +spring.datasource.hikari.connection-test-query=SELECT now() +spring.datasource.hikari.validation-timeout=60000 + +private.key=MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQDNgtaCfu5QlhWfU8bJAooLoX+bo/ARsvoWUJf5NodkGOivze5Lqtu5eq6ptT+gVKK+IEsjpmDsFPMCE2CW7xLZfgbtrWmTPd+fiRb2Z/fMudedo166H5WEgS3+TDWKt7WkLA/3kqvIqdBotuL4BENwZj6CIjGNdG01RNsCaDA/vxTkzx9njz6kfgAda/+wbdOJNwjNRgIb9AyedQT5OKvqRXequzrrOKD9wrm1O4nv8lA6WFg5YEMSW7T6WRIeArZsQr1aHv6qkiu47YreApfdFIWHxd9QinA9WrLPYdWXONr7+xyvqS4MHSJh9ZmCvMsc/HcF3RHJgEwgiC8E6hiZAgMBAAECggEAByZOICwaTmNqTSi0+blE5DKyJdAGQhdf6/bR0rG69BiJv9QCPk+rZUCHYxATLpjDMKoe8xaOuKfh7GiQK7AVj8t6ojouOhkk9n/mdJwZWt38Slesq/z9TqbP2tD769+ISjXeOFa58zk1Lu9t5gL/9aEY+54E607pnbjPhb3qL819/7absLbY1y3GKw2Cwd7RfP8nOWj0ViwnalFjfg6YZS1BL5c9NSg41FzZolwPruZ/bBGbc3nMW2khpuK7CtRk1pRJHUNYuVCsaBU4M4sf3tlZQPOdB6eYmQ3xmPtdnHYB13s588KialXKFlAuO4zG0CFa8DfIKsWDv6xTC1cMgQKBgQD6CjJuu715oKob7ohDTfrSppk4PY/kxWhUkKyKVW1Y1jXQOcd4BwVSyH6s7N8pCSWMwWmoF/t/l2kIcAWNZnsbzAQ8TYOhp1THstXMVb6c7JOL3SQC5RjbgW1RWCalh7/4QVE0xYeEL3qv5I2t9215zKR87Z6LIdJkxxAsHgMSbQKBgQDSaOp0kJZPkQH/75ltaI9exczyoaf+5U/OrnqT2lpRwa+5wqUTPWpTFTCDcJdu8OKCgrKPOQ6NACuX4PbIW/jR+70w7nbC46Tx3JdDYxBlm+6MuHUs5RXufFDJyGoN8lJzoPGax3uxY1kxWwSaSIB0sVXV/P3PIE31I5DbarWjXQKBgQCrRyLm4anYUCtWuN4UpK0lcUPR17Hi9ysRioz2sbAWw53XRk0SNlT6MSc9E4GGnaJgOflDUTJRY4lqYzoac1HvZ6CbIkoCCRq1NRbpQu8wlYo4q8JITWDqtE0LBMRsbYId77hN2uWKse9r37cBrVULsxgWD7uj+QYjTI0Se3iFPQJ/SSYwXFXn68F98Hxb2q1/KnOZzMBmpzcRh8kg1EYVIFc1wF7rBMVVMY0sUIXUH72fAcBuU1yCsoJcpXCQWxeeaWIbY+eDYj3CGlOWQtct3CVZyZJXKkR6W27cp0oFlNOp1okddbHkTsc7Ou1prDmIbwk3zi0mD9wrPg4fTijK/QKBgQDrYEWT77dQLPcN3RTVn3Ua2d9aj/IWwC330I4qZq2SFKOaB/olnPA6fLNYToTWO70A2ZlsMtVepdThIeYFidkA7Lj7lTVYFdQQzREsO5908A1YWE4sgMEEdMc7n5xKT85vpkPOjBOLZYQ6JjDeWBMDxnXR9/txwbau4bsq3/QFuQ== +public.key=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzYLWgn7uUJYVn1PGyQKKC6F/m6PwEbL6FlCX+TaHZBjor83uS6rbuXquqbU/oFSiviBLI6Zg7BTzAhNglu8S2X4G7a1pkz3fn4kW9mf3zLnXnaNeuh+VhIEt/kw1ire1pCwP95KryKnQaLbi+ARDcGY+giIxjXRtNUTbAmgwP78U5M8fZ48+pH4AHWv/sG3TiTcIzUYCG/QMnnUE+Tir6kV3qrs66zig/cK5tTuJ7/JQOlhYOWBDElu0+lkSHgK2bEK9Wh7+qpIruO2K3gKX3RSFh8XfUIpwPVqyz2HVlzja+/scr6kuDB0iYfWZgrzLHPx3Bd0RyYBMIIgvBOoYmQIDAQAB +access.time=600 +refresh.time=43200 + +captcha.key=PPExpv36jk4Vzda3NpYnXLfuHCLYXqaNrxlOH/Jr/1M= +captcha.time=600 + +mail.host=smtp.yandex.ru +mail.port=465 +mail.login=info@ccalm.org +mail.password=fu2lpsoGPGiq1xlRm8ag + +url.reset=https://ccalm.org/api/authorization/v02/reset +url.main=https://ccalm.org/ + +spring.redis.host=127.0.0.1 +spring.redis.port=6379 +spring.redis.password=9F3/NKWeOjd815vkadT2DcgVHf6fEpVQXw== diff --git a/pom.xml b/pom.xml new file mode 100644 index 0000000..dfcce3d --- /dev/null +++ b/pom.xml @@ -0,0 +1,135 @@ + + + 4.0.0 + + org.springframework.boot + spring-boot-starter-parent + 3.3.3 + + + org.ccalm + jwt + 0.0.1-SNAPSHOT + jwt + jwt + + 21 + + + + org.springframework.boot + spring-boot-starter-data-redis + 3.3.3 + + + org.springframework.boot + spring-boot-starter-web + 3.3.3 + + + org.springframework.boot + spring-boot-starter-test + test + 3.3.3 + + + org.springframework.boot + spring-boot-starter-data-jpa + 3.3.3 + + + org.postgresql + postgresql + 42.7.4 + runtime + + + org.json + json + 20231013 + + + io.jsonwebtoken + jjwt-api + 0.11.2 + + + io.jsonwebtoken + jjwt-impl + 0.11.2 + runtime + + + io.jsonwebtoken + jjwt-jackson + 0.11.2 + runtime + + + redis.clients + jedis + 3.7.0 + + + net.logicsquad + nanocaptcha + 2.1 + + + ch.qos.logback + logback-classic + 1.5.6 + + + net.logstash.logback + logstash-logback-encoder + 6.6 + + + javax.mail + mail + 1.4 + + + org.xerial + sqlite-jdbc + 3.36.0.1 + + + com.fasterxml.jackson.datatype + jackson-datatype-jsr310 + 2.18.0 + + + org.apache.commons + commons-text + 1.12.0 + + + com.warrenstrange + googleauth + 1.5.0 + + + + + + + org.springframework.boot + spring-boot-maven-plugin + + + org.apache.maven.plugins + maven-surefire-plugin + 2.22.2 + + + file:kz_mcp_jwt.properties + + + + + + + diff --git a/run.sh b/run.sh new file mode 100644 index 0000000..aa8f53b --- /dev/null +++ b/run.sh @@ -0,0 +1,3 @@ +#!/bin/bash +cd target +java -jar jwt-0.0.1-SNAPSHOT.jar \ No newline at end of file diff --git a/src/main/java/org/ccalm/jwt/JwtApplication.java b/src/main/java/org/ccalm/jwt/JwtApplication.java new file mode 100644 index 0000000..ef98f7d --- /dev/null +++ b/src/main/java/org/ccalm/jwt/JwtApplication.java @@ -0,0 +1,20 @@ +package org.ccalm.jwt; + +import org.apache.logging.log4j.LogManager; +import org.apache.logging.log4j.Logger; +import org.springframework.boot.SpringApplication; +import org.springframework.boot.autoconfigure.SpringBootApplication; +import org.springframework.context.annotation.ComponentScan; + +@SpringBootApplication +@ComponentScan(basePackages = {"org.ccalm.jwt"}) +public class JwtApplication { + + private static final Logger logger = LogManager.getLogger(JwtApplication.class); + + public static void main(String[] args) { + logger.info("Start JwtApplication"); + SpringApplication.run(JwtApplication.class, args); + } + +} diff --git a/src/main/java/org/ccalm/jwt/MainController.java b/src/main/java/org/ccalm/jwt/MainController.java new file mode 100644 index 0000000..1c76f3f --- /dev/null +++ b/src/main/java/org/ccalm/jwt/MainController.java @@ -0,0 +1,1478 @@ +package org.ccalm.jwt; + +import com.warrenstrange.googleauth.GoogleAuthenticator; +import com.warrenstrange.googleauth.GoogleAuthenticatorKey; +import org.ccalm.jwt.models.*; +import org.ccalm.jwt.tools.*; +import com.zaxxer.hikari.HikariDataSource; +import io.jsonwebtoken.*; +import io.jsonwebtoken.security.Keys; +import jakarta.servlet.ServletContext; +import jakarta.servlet.http.Cookie; +import jakarta.servlet.http.HttpServletRequest; +import jakarta.servlet.http.HttpServletResponse; +import net.logicsquad.nanocaptcha.content.LatinContentProducer; +import net.logicsquad.nanocaptcha.image.ImageCaptcha; +import net.logicsquad.nanocaptcha.image.backgrounds.GradiatedBackgroundProducer; +import net.logicsquad.nanocaptcha.image.noise.CurvedLineNoiseProducer; +import net.logicsquad.nanocaptcha.image.renderer.DefaultWordRenderer; +import org.json.JSONArray; +import org.json.JSONException; +import org.springframework.beans.factory.annotation.Autowired; +import org.springframework.beans.factory.annotation.Value; +import org.springframework.core.io.ClassPathResource; +import org.springframework.dao.DataAccessException; +import org.springframework.http.HttpHeaders; +import org.springframework.http.ResponseCookie; +import org.springframework.jdbc.BadSqlGrammarException; +import org.springframework.stereotype.Controller; +import org.springframework.lang.Nullable; +import org.springframework.ui.Model; +import org.springframework.web.bind.annotation.*; +import org.springframework.web.context.ServletContextAware; +import org.json.JSONObject; +import org.springframework.jdbc.core.namedparam.MapSqlParameterSource; +import org.springframework.jdbc.core.namedparam.NamedParameterJdbcTemplate; +import org.apache.logging.log4j.LogManager; +import org.apache.logging.log4j.Logger; +import org.apache.commons.text.RandomStringGenerator; +import redis.clients.jedis.Jedis; + +import java.net.URLEncoder; +import java.nio.charset.StandardCharsets; +import java.nio.file.Files; +import java.security.KeyFactory; +import java.security.PrivateKey; +import java.security.PublicKey; +import javax.crypto.SecretKey; +import javax.crypto.spec.SecretKeySpec; +import javax.imageio.ImageIO; +import javax.mail.MessagingException; +import java.awt.*; +import java.awt.image.BufferedImage; +import java.io.*; +import java.security.spec.PKCS8EncodedKeySpec; +import java.security.spec.X509EncodedKeySpec; +import java.sql.*; +import java.sql.Date; +import java.time.Duration; +import java.time.Instant; +import java.util.*; +import java.util.List; +import java.util.regex.Pattern; + +@Controller +public class MainController implements ServletContextAware { + + private static final Logger logger = LogManager.getLogger(MainController.class); + @Value("${spring.application.name}") + String application_name=""; + @Value("${issuer.name}") + String issuer_name=""; + @Value("${public.key}") + String public_key; + @Value("${private.key}") + String private_key; + @Value("${captcha.key}") + String captchaKey; + @Value("${access.time}") + int access_time=0; //На сколько секунд продлевать время Access токена + @Value("${refresh.time}") + int refresh_time=0; //На сколько секунд продлевать время Refresh токена + @Value("${mail.host}") + String mail_host = ""; + @Value("${mail.port}") + String mail_port = ""; + @Value("${mail.login}") + String mail_login = ""; + @Value("${mail.password}") + String mail_password; + + @Value("${url.reset}") + String url_reset = ""; + @Value("${url.main}") + String url_main = ""; + + @Value("${spring.redis.host}") + String redis_host; + @Value("${spring.redis.port}") + int redis_port; + @Value("${spring.redis.password}") + String redis_password; + + private ServletContext context; + private final NamedParameterJdbcTemplate jdbcTemplate; + private HikariDataSource dataSource; + public Storage storage=new Storage(); + + @Override + public void setServletContext(ServletContext servletContext) { + this.context=servletContext; + } + + @Autowired + public void DatabaseService(HikariDataSource dataSource) { + this.dataSource = dataSource; + } + + @Autowired + public MainController(NamedParameterJdbcTemplate jdbcTemplate) { + this.jdbcTemplate = jdbcTemplate; + } + + public String createStrJSONError(int code, String message,String marker) { + JSONObject json = new JSONObject(); + json.put("error_code",code); + json.put("error_message",message); + json.put("error_marker",marker); + return json.toString(); + } + public JSONObject createJSONError(int code, String message,String marker){ + JSONObject json = new JSONObject(); + json.put("error_code",code); + json.put("error_message",message); + json.put("error_marker",marker); + return json; + } + public String createHTMLError(int code,String message) + { + return ""; + } + + public static int countOccurrences(String str, char symbol) { + int count = 0; + for (int i = 0; i < str.length(); i++) { + if (str.charAt(i) == symbol) { + count++; + } + } + return count; + } + + public static String afterLast(String str, String sub) { + int pos = str.lastIndexOf(sub); + if (pos == -1) { + return null; + } + return str.substring(pos + sub.length()); + } + + public static String beforeFirst(String str, String ch) + { + int i=str.indexOf(ch); + if(i!=-1) + { + return str.substring(0,i); + } + return ""; + } + + private PrivateKey getPrivateKey(){ + try { + byte[] keyBytes = Base64.getDecoder().decode(private_key); + PKCS8EncodedKeySpec spec = new PKCS8EncodedKeySpec(keyBytes); + KeyFactory keyFactory = KeyFactory.getInstance("RSA"); + return keyFactory.generatePrivate(spec); + } catch (Exception e) { + logger.error(e); + } + return null; + } + + private PublicKey getPublicKey(){ + try { + byte[] keyBytes = Base64.getDecoder().decode(public_key); + X509EncodedKeySpec spec = new X509EncodedKeySpec(keyBytes); + KeyFactory keyFactory = KeyFactory.getInstance("RSA"); + PublicKey key = keyFactory.generatePublic(spec); + return key; + } catch (Exception e) { + logger.error(e); + } + return null; + } + + /** + * Create a Refresh Cookie + */ + public boolean setRefreshCookie(HttpServletResponse response, HttpServletRequest request, String jwt_r) { + // Получаем путь из заголовка X-Forwarded-Path + String forwardedPath = request.getHeader("x-forwarded-uri"); + if (forwardedPath == null || forwardedPath.isEmpty()) { + forwardedPath = request.getRequestURI(); + } + // Убираем последний уровень пути (обычно это версия API /v02/) + String newPath = forwardedPath.substring(0, forwardedPath.lastIndexOf('/') + 1); + String cookiePath = newPath.isEmpty() ? "/" : newPath; + + // Определяем продолжительность жизни куки + Duration maxAge; + if (jwt_r == null || jwt_r.isEmpty()) { + maxAge = Duration.ZERO; // Удаляем куки + } else { + maxAge = Duration.ofHours(12); // 12 часов + } + + // Создаем ResponseCookie с настройками + ResponseCookie cookie = ResponseCookie.from("jwt_r", jwt_r) + .path(cookiePath) + .httpOnly(true) + .secure(false) // если true то только по HTTPS (если сертификат просрочен то будет пустым, поэтому закомментировал) + .sameSite("Strict") // SameSite атрибут + .maxAge(maxAge) // Время жизни куки + .build(); + + // Добавляем куки в заголовок ответа + response.addHeader(HttpHeaders.SET_COOKIE, cookie.toString()); + + return true; + } + + + /** + * Create a Access Cookie + */ + public boolean setAccessCookie(HttpServletResponse response, String jwt_a) { + // Определяем продолжительность жизни куки + Duration maxAge; + if (jwt_a == null || jwt_a.isEmpty()) { + maxAge = Duration.ZERO; // Удаляем куки + } else { + maxAge = Duration.ofSeconds(access_time); //В 2 раза больше + } + // Создаем ResponseCookie с настройками + ResponseCookie cookie = ResponseCookie.from("jwt_a", jwt_a) + .path("/") // Путь для куки + .httpOnly(true) // HttpOnly для безопасности + .secure(false) // если true то только по HTTPS (если сертификат просрочен то будет пустым, поэтому закомментировал) + .sameSite("Strict") // SameSite атрибут + .maxAge(maxAge) // Время жизни куки + .build(); + // Добавляем куки в заголовок ответа + response.addHeader(HttpHeaders.SET_COOKIE, cookie.toString()); + return true; + } + + @RequestMapping(value = "/",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String index(Model model,@RequestParam(required=false,name="lng",defaultValue = "1") String language_id) { + JSONObject json = new JSONObject(); + json.put("error_code",0); + json.put("error_message","Application name: "+application_name); + json.put("error_marker",(String)null); + json.put("active_connections",dataSource.getHikariPoolMXBean().getActiveConnections()); + json.put("idle_connections",dataSource.getHikariPoolMXBean().getIdleConnections()); + return json.toString(); + } + /* + @RequestMapping(value = "/get_settings/",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String get_settings(Model model, @CookieValue(value = "jwt_a", defaultValue = "") String jwt_a,@RequestBody ActionName action_name, @CookieValue(value = "lng", defaultValue = "1") String language_id) { + */ + @RequestMapping(value = "/get_settings",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String get_settings(@CookieValue(value = "jwt_a", defaultValue = "") String jwt_a, @RequestParam(required=false,name="lng",defaultValue = "1") String language_id) { + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + //json.put("error_message",""); + //json.put("error_marker",(String)null); + try{ + if(jwt_a.equals("") || countOccurrences(jwt_a, '.')!=2) + { + throw new CustomException(10000, trt.trt("Please_send_a_valid_JWT_token"),null); + } + //Проверяю подпись токена + Jws claims = null; + try { + claims = Jwts.parserBuilder() + .setSigningKey(getPublicKey()) //.setSigningKey(key_a) + .build() + .parseClaimsJws(jwt_a); + } catch (Exception e) { + return createStrJSONError(10000, trt.trt("JWT_token_verification_error"),null); + } + String sql = """ + select + us.name, + us.value + from + main.Users_Settings us + where + us.del=false + and user_id=:user_id + """; + MapSqlParameterSource parameters = new MapSqlParameterSource(); + parameters.addValue("user_id", claims.getBody().get("user_id")); + List ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + JSONArray data = new JSONArray(); + for (int i = 0; i < ret.size(); i++) { + data.put((new JSONObject(ret.get(i))).getString("name")); + } + json.put("data",data); + + } catch (CustomException e) { + json = e.getJson(); + } catch (BadSqlGrammarException e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Error_executing_SQL_query")+" "+e.getMessage(), uuid); + } catch (Exception e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Internal_Server_Error")+" "+e.getMessage(), uuid); + } + return json.toString(); + } + + @RequestMapping(value = "/set_settings",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String set_settings(SettingModel setting, @CookieValue(value = "jwt_a", defaultValue = "") String jwt_a, @RequestParam(required=false,name="lng",defaultValue = "1") String language_id) { + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + //json.put("error_message",""); + //json.put("error_marker",(String)null); + try{ + if(jwt_a.equals("") || countOccurrences(jwt_a, '.')!=2) + { + throw new CustomException(10000, trt.trt("Please_send_a_valid_JWT_token"),null); + } + //Проверяю подпись токена + Jws claims = null; + try { + claims = Jwts.parserBuilder() + .setSigningKey(getPublicKey()) + .build() + .parseClaimsJws(jwt_a); + } catch (Exception e) { + throw new CustomException(10000, trt.trt("JWT_token_verification_error"),null); + } + //TODO проверить доступ для выполнения данной функции + //Выполняем функцию + String sql = """ + select id from main._users_settings where user_id=:user_id and identifier=:identifier limit 1 + """; + MapSqlParameterSource parameters = new MapSqlParameterSource(); + parameters.addValue("user_id", claims.getBody().get("user_id")); + parameters.addValue("identifier", setting.getIdentifier()); + List ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + long id=0; + for (int i = 0; i < ret.size(); i++) { + JSONObject obj = new JSONObject(ret.get(i)); + id=obj.getLong("id"); + } + if(id==0) { + sql = """ + insert into main._users_settings(user_id,identifier,value)values(:user_id,:identifier,:value) + """; + }else{ + sql = """ + update main._users_settings set + del=false, + user_id=:user_id, + identifier=:identifier, + value=:value + where + id=:id + """; + } + parameters = new MapSqlParameterSource(); + parameters.addValue("user_id", claims.getBody().get("user_id")); + parameters.addValue("identifier", setting.getIdentifier()); + parameters.addValue("value", setting.getValue()); + jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + + } catch (CustomException e) { + json = e.getJson(); + } catch (Exception e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Internal_Server_Error")+" "+e.getMessage(), uuid); + } + return json.toString(); + } + + @RequestMapping(value = "/access",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String access(Model model, @CookieValue(value = "jwt_a", defaultValue = "") String jwt_a,@Nullable @RequestBody ActionName action_name,@CookieValue(value = "lng",defaultValue = "1") String language_id) { + + Translation trt = new Translation(language_id,jdbcTemplate); + + String result=createStrJSONError(10000,trt.trt("Request_not_processed"),null); + if(jwt_a.equals("") || countOccurrences(jwt_a, '.')!=2) + { + result=createStrJSONError(10000,trt.trt("Please_send_a_valid_JWT_token"),null); + return result; + } + + //Connection conn = getConnection(); + //Проверяю подпись токена + Jws claims = null; + //SecretKey key_a = new SecretKeySpec(Base64.getDecoder().decode(key_a_txt), "HmacSHA256"); + try { + claims = Jwts.parserBuilder() + .setSigningKey(getPublicKey()) //.setSigningKey(key_a) + .build() + .parseClaimsJws(jwt_a); + } catch (Exception e) { + return createStrJSONError(10000, trt.trt("JWT_token_verification_error"),null); + } + String sql = """ + select + name + from + main.get_access_list(:user_id) + where + allow=true + and (:action_name::text is null or name ilike '%'|| :action_name::text ||'%') + order by name + """; + + + MapSqlParameterSource parameters = new MapSqlParameterSource(); + parameters.addValue("user_id", claims.getBody().get("user_id")); + if(action_name == null) + parameters.addValue("action_name", null); + else + parameters.addValue("action_name", action_name.getActionName()); + List ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + JSONObject json = new JSONObject(); + json.put("error_code",0); + //json.put("error_message",""); + //json.put("error_marker",(String)null); + JSONArray data = new JSONArray(); + for (int i = 0; i < ret.size(); i++) { + data.put((new JSONObject(ret.get(i))).getString("name")); + } + json.put("data",data); + result = json.toString(); + + return result; + } + + @RequestMapping(value = "/captcha",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String captcha(Model model, @RequestBody EmailModel email_model, @RequestParam(required=false,name="lng",defaultValue = "1") String language_id) { + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + json.put("error_message",""); + try{ + //Генерю Captcha + ImageCaptcha imageCaptcha = new ImageCaptcha.Builder(400, 100) + .addContent(new LatinContentProducer(7), + new DefaultWordRenderer.Builder() + .randomColor(Color.BLACK, Color.BLUE, Color.CYAN, Color.RED) + .build()) + .addBackground(new GradiatedBackgroundProducer()) + .addNoise(new CurvedLineNoiseProducer()) + .build(); + BufferedImage img = imageCaptcha.getImage(); + + json.put("code",imageCaptcha.getContent());//json.put("code",""); + try { + ByteArrayOutputStream baos = new ByteArrayOutputStream(); + ImageIO.write(img, "jpeg", baos); + byte[] bytes = baos.toByteArray(); + json.put("image",Base64.getEncoder().encodeToString(bytes)); + } catch (IOException e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + throw new CustomException(10000, trt.trt("Input_output_error"),uuid); + } + + //Формирую JSON токена и шифрую его + JSONObject jToken = new JSONObject(); + jToken.put("exp", Instant.now().getEpochSecond()+(60*10)); //+10 минут + jToken.put("code",imageCaptcha.getContent()); + jToken.put("email",email_model.getEmail()); + String sToken = jToken.toString(); + sToken = Tools.encryptText(captchaKey,sToken); + //Подпись для как бы токена + json.put("token",sToken+"."+Tools.generateSignature(captchaKey, sToken)); + + } catch (CustomException e) { + json = e.getJson(); + } catch (Exception e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Internal_Server_Error")+" "+e.getMessage(), uuid); + } + return json.toString(); + } + + @RequestMapping(value = "/create",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String create(@RequestBody NewUserModel newUserModel,@RequestParam(required=false,name="lng",defaultValue="1") String language_id) { + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + json.put("error_message",""); + try{ + if(newUserModel.getName().length()<3) { + throw new CustomException(10000, trt.trt("The_name_field_is_empty"),null); + } + if(newUserModel.getEmail().length()<6) { + throw new CustomException(10000, trt.trt("The_email_field_is_empty"),null); + } + if (!Tools.isValidEmail(newUserModel.getEmail())) { + throw new CustomException(10000, trt.trt("The_email_field_is_incorrect"),null); + } + if(newUserModel.getCode().length()<3) { + throw new CustomException(10000, trt.trt("The_code_field_is_empty"),null); + } + if(newUserModel.getToken().length()<3) { + throw new CustomException(10000, trt.trt("The_token_field_is_empty"),null); + } + + //Проверяю что подпись одинакова + String signature1 = afterLast(newUserModel.getToken(), "."); + String payload = beforeFirst(newUserModel.getToken(), "."); + + String signature2 = Tools.generateSignature(captchaKey, payload); + if (!signature1.equals(signature2)) { + throw new CustomException(10000, trt.trt("The_signature_did_not_match"),null); + } + //Расшифровываю + String sToken = Tools.decryptText(captchaKey,payload); + + JSONObject jToken = null; + try { + jToken = new JSONObject(sToken); + } catch (JSONException e) { + logger.error(e); + } + + if(jToken==null) { + throw new CustomException(10000, trt.trt("Please_send_a_valid_JSON_string_in_your_token"),null); + } + if (!newUserModel.getCode().equals(jToken.getString("code"))) { + throw new CustomException(10000, trt.trt("The_code_did_not_match_what_was_specified_in_the_captcha"),null); + } + if (jToken.getLong("exp") < (System.currentTimeMillis() / 1000L)) { + throw new CustomException(10000, trt.trt("Captcha_is_outdated"),null); + } + if (!Tools.isValidEmail(jToken.getString("email"))) { + throw new CustomException(10000, trt.trt("The_email_field_is_incorrect"),null); + } + if (!newUserModel.getEmail().equals(jToken.getString("email"))) { + throw new CustomException(10000, trt.trt("The_email_did_not_match_what_was_specified_in_the_captcha"),null); + } + + //Проверяю существование пользователя с таким email + String sql = """ + select * from main._users where email=:email; + """; + MapSqlParameterSource parameters = new MapSqlParameterSource(); + parameters.addValue("email", newUserModel.getEmail()); + List ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + throw new CustomException(10000, trt.trt("A_user_with_the_same_email_address_already_exists"),null); + } + + // Генерируем временный пароль + RandomStringGenerator generator = new RandomStringGenerator.Builder() + .withinRange('0', 'z') // диапазон символов (можно настроить) + .filteredBy(c -> Character.isLetterOrDigit(c)) + .get(); + String password = generator.generate(8); + + //Добавляем пользователя + sql = """ + insert into main._users( + _user_id, name, email, password, expiration + )values( + 1, :name, :email, crypt(:password, gen_salt('bf')), now()+interval '5 day' + ) RETURNING id; + """; + parameters = new MapSqlParameterSource(); + //parameters.addValue("country_id",); + //parameters.addValue("company_name",); + //parameters.addValue("position",); + parameters.addValue("name",newUserModel.getName()); + //parameters.addValue("surname",); + //parameters.addValue("patronymic",); + //parameters.addValue("phone",); + parameters.addValue("email",newUserModel.getEmail()); + parameters.addValue("password",password); + + ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + json = new JSONObject(ret.get(i)); + //Добавляю роль перевозчика пользователю + sql = """ + insert into main._usersgroups(user_id,group_id)values(:id,12) RETURNING id; + """; + parameters = new MapSqlParameterSource(); + parameters.addValue("id",json.getLong("id")); + jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + } + + //Отправляю пароль на почту с ссылкой на активацию этого пользователя + String html=""; + html += "" + trt.trt("Now_user") + ""; + html += "

" + trt.trt("To_activate_the_user_please_log_in") + ":

"; + html += "istransit.kz

"; + html += trt.trt("To_log_in_please_use_the_following_password") + ": \"" + password + "\""; + html += ""; + + try { + EmailUtility.sendEmail(mail_host, mail_port, mail_login, mail_password, newUserModel.getEmail(), trt.trt("Password"), html); + } catch (MessagingException e) { + throw new CustomException(10000, String.format(trt.trt("Failed_send_mail_to_s"), newUserModel.getEmail()),null); + } + + json.put("error_message",trt.trt("The_authorization_password_has_been_sent_to_your_email_address")); + + } catch (CustomException e) { + json = e.getJson(); + } catch (Exception e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Internal_Server_Error")+" "+e.getMessage(), uuid); + } + return json.toString(); + } + + @RequestMapping(value = "/info",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String info(Model model, @CookieValue(value = "jwt_a", defaultValue = "") String jwt_a, @CookieValue(value = "lng",defaultValue="1") String language_id) { + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + json.put("error_message",""); + try { + if(jwt_a.equals("") || countOccurrences(jwt_a, '.')!=2) + { + throw new CustomException(10000, trt.trt("Please_send_a_valid_JWT_token"),null); + } + //Проверяю подпись токена + Jws claims = null; + try { + claims = Jwts.parserBuilder() + .setSigningKey(getPublicKey()) + .build() + .parseClaimsJws(jwt_a); + } catch (Exception e) { + throw new CustomException(10000, trt.trt("JWT_token_verification_error"),null); + } + + //Выбираю данные о пользователе (TODO наверно стоит вызывать функцию get_user_info также и при логине) + String sql = "select * from main.get_user_info(1,:user_id);"; + + try { + MapSqlParameterSource parameters = new MapSqlParameterSource(); + parameters.addValue("user_id", claims.getBody().get("user_id")); + List ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + json = new JSONObject(ret.get(i)); + } + } catch (Exception ex) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid, ex); + throw new CustomException(10000, trt.trt("Error_executing_SQL_query"), uuid); + } + + if (json == null) { + throw new CustomException(10000, trt.trt("Invalid_username_and_or_password"), null); + } else { + if (json.has("block")) { + if (!json.isNull("block") && json.getBoolean("block")) + throw new CustomException(10006, trt.trt("The_user_account_is_blocked"), null); + json.remove("block"); + } + + String rolesString = json.getJSONObject("roles").getString("value"); + JSONArray rolesArray = new JSONArray(rolesString); + json.put("roles", rolesArray); + + json.put("error_code",0); + } + } catch (CustomException e) { + json = e.getJson(); + } + catch (Exception e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Internal_Server_Error")+" "+e.getMessage(), uuid); + } finally { + //try { if(conn!=null) conn.close(); } catch (SQLException e) { throw new RuntimeException(e); } + } + return json.toString(); + } + + @RequestMapping(value = "/login",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String login(HttpServletResponse response, HttpServletRequest request, @RequestBody LoginModel loginModel, @CookieValue(value = "lng", defaultValue = "1") String language_id) { + + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + json.put("error_message",""); + try { + if(loginModel.getLogin().isEmpty()) + throw new CustomException(10000,trt.trt("The_login_field_is_empty"),null); + if(!Tools.isValidEmail(loginModel.getLogin())) + throw new CustomException(10000,trt.trt("The_login_field_is_incorrect"),null); + if(loginModel.getPassword().isEmpty()) + throw new CustomException(10000,trt.trt("The_password_field_is_empty"),null); + if(loginModel.getPassword().length()<=3) + throw new CustomException(10000,trt.trt("The_password_field_is_short"),null); + if(loginModel.getAppid().isEmpty()) + throw new CustomException(10000,trt.trt("The_application_name_field_is_empty"),null); + + String ipAddress = request.getHeader("X-FORWARDED-FOR"); //Не беспокойся на регистр не обращает внимания + if (ipAddress == null) { + ipAddress = request.getRemoteAddr(); + } + + //I check that there are no more than 5 failed authorization errors in 5 minutes + String sql = ""; + int attempt_count=0, attempt_limit=0, attempt_duration=0; + MapSqlParameterSource parameters = null; + List ret = null; + try { + sql = "select * from main.user_is_blocked(:login,:ip)"; + parameters = new MapSqlParameterSource(); + parameters.addValue("login", loginModel.getLogin()); + parameters.addValue("ip", ipAddress); + ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + json = new JSONObject(ret.get(i)); + if (!json.has("result") || json.getBoolean("result")) { + if(json.getInt("count")==0) + { + throw new CustomException(10000, trt.trt("The_user_account_is_blocked"),null); + }else{ + throw new CustomException(10000, String.format(trt.trt("The_limit_of_authorization_attempts_has_been_exceeded_please_wait_s_minutes"), json.getInt("limit_duration")),null); + } + } + if(json.has("count") && json.has("limit_count") && json.has("limit_duration")) { + attempt_count = json.getInt("count"); + attempt_limit = json.getInt("limit_count"); + //attempt_duration = json.getInt("limit_duration"); + } + } + }catch (DataAccessException ex){ + String uuid = UUID.randomUUID().toString(); + logger.error("Функция main.user_is_blocked не вернула результата!", uuid, ex); + throw new CustomException(10000, trt.trt("Error_executing_SQL_query"),uuid); + } + + //I'm trying to log in + json = null; + try { + sql="select * from main.p__login(:user_id,:login,:password,:ip,:fingerprint);"; + parameters = new MapSqlParameterSource(); + parameters.addValue("user_id", 1); + parameters.addValue("login", loginModel.getLogin()); + parameters.addValue("password", loginModel.getPassword()); + parameters.addValue("ip", ipAddress); + parameters.addValue("fingerprint", null); + ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + json = new JSONObject(ret.get(i)); + } + }catch (DataAccessException ex){ + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,ex); + throw new CustomException(10000, trt.trt("Error_executing_SQL_query"),uuid); + } + if(json==null) { + String msg = trt.trt("Invalid_username_and_or_password"); + if(attempt_count>0){ + msg = msg + " " + String.format(trt.trt("Authorization_attempts_s_out_of_s"),attempt_count,attempt_limit); + } + throw new CustomException(10000, msg, null); + } + + if(json.has("block")) { + if(json.getBoolean("block")) + throw new CustomException(10006,trt.trt("The_user_account_is_blocked"),null); + json.remove("block"); + } + + //Если для пользователя настроено то что он обязательно должен авторизоваться используя TOTP а он не задан то генерю его ему + if(json.has("key_required") && !json.isNull("key_required") && json.getBoolean("key_required") && json.has("secret") && json.isNull("secret")) { + throw new CustomException(10010, trt.trt("You_need_to_get_a_new_TOTP_key"), null); + } + if(json.has("secret")) { + if(!json.isNull("secret")) { + if(!Tools.isInteger(loginModel.getTotp())) { + throw new CustomException(10000, trt.trt("The_TOTP_field_is_empty"), null); + } + //Проверяю на соответствие TOTP ключа TODO потом написать поверку в функции p__Login плагином + GoogleAuthenticator gAuth = new GoogleAuthenticator(); + boolean isCodeValid = gAuth.authorize(json.getString("secret"), Integer.parseInt(loginModel.getTotp())); + if(!isCodeValid){ + throw new CustomException(10000, trt.trt("TOTP_key_does_not_match"), null); + } + } + json.remove("secret"); + } + if(json.has("key_required")) { + json.remove("key_required"); + } + + //В каком ARM был в последний раз пользователь + try { + sql="SELECT value FROM main.users_settings where del=false and name='last_url' and user_id=:user_id;"; + parameters = new MapSqlParameterSource(); + parameters.addValue("user_id", json.getLong("user_id")); + ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + JSONObject obj = new JSONObject(ret.get(i)); + json.put("last_url", obj.getString("value")); + } + }catch (Exception ex){ + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,ex); + throw new CustomException(10000, trt.trt("Error_executing_SQL_query"),uuid); + } + + //SecretKey key_a = new SecretKeySpec(Base64.getDecoder().decode(key_a_txt), "HmacSHA256"); + String key_r_txt = Tools.genKey(); //SecretKey key_r = Keys.secretKeyFor(SignatureAlgorithm.HS256); //Генерю секретный ключ для рефреш токена + + JSONObject token = new JSONObject(); + token.put("iss",issuer_name); + token.put("iat", Instant.now().getEpochSecond()); //время, когда был выпущен JWT; + //token.put("nbf", Instant.now().getEpochSecond()); //время, начиная с которого может быть использован (не раньше, чем). + token.put("exp", Instant.now().getEpochSecond()+access_time); //дата истечения срока действия (в настройках 20 минут или 1200 секунд) + token.put("appid", loginModel.getAppid()); //Кто запросил токен + //token.put("jti", json.getString("000")); //Уникальный идентификатор токена (беру из таблицы лигинов ещё бы appid в логины записать) + token.put("data", + new JSONObject() + .put("id",json.getLong("user_id")) + .put("name",json.getString("name")) + .put("email",json.getString("email")) + ); + + // Время действия токена (например, 1 час) + Date expirationDate = new Date(System.currentTimeMillis() + refresh_time * 1000); + + Map claims = new HashMap<>(); + claims.put("user_id", json.getLong("user_id")); + claims.put("email", json.getString("email")); + + // Создание JWT с подписью + JwtBuilder jwt = Jwts.builder(); + jwt.setClaims(claims); + jwt.setIssuer(issuer_name); //iss издатель токена + //jwt.setAudience(issuer_name); //aud Аудитория + jwt.setId(String.valueOf(json.getLong("id"))); //jti Authorization ID (from login history) + + jwt.setSubject(json.getString("name")); //sub + //jwt.setIssuedAt(new Date(System.currentTimeMillis())); //время, когда был выпущен JWT; + //jwt.setNotBefore(new Date(System.currentTimeMillis())); //nbf время, начиная с которого может быть использован (не раньше, чем). + jwt.setExpiration(expirationDate); //exp дата истечения срока действия (в настройках 20 минут или 1200 секунд) + jwt.signWith(getPrivateKey()); //jwt.signWith(key_a); + String jwt_a = jwt.compact(); + + //System.out.println("Созданный JWT: " + jwt_a); + + setAccessCookie(response,jwt_a); + + //Создаю рефреш токен на 12 часов (доступный только по HTML и по пути /authorization/) + claims.put("sig", afterLast(jwt_a,".")); //В рефреш подпись из акцесс + jwt = Jwts.builder(); + jwt.setClaims(claims); + jwt.setIssuer(issuer_name); //iss издатель токена + //jwt.setAudience(issuer_name); //aud Аудитория + jwt.setId(String.valueOf(json.getLong("id"))); //jti Authorization ID (from login history) + jwt.setSubject(json.getString("name")); //sub + //jwt.setIssuedAt(new Date(System.currentTimeMillis())); //время, когда был выпущен JWT; + //jwt.setNotBefore(new Date(System.currentTimeMillis())); //nbf время, начиная с которого может быть использован (не раньше, чем). + jwt.setExpiration(expirationDate); //exp дата истечения срока действия (в настройках 20 минут или 1200 секунд) + jwt.signWith(getPrivateKey()); //jwt.signWith(new SecretKeySpec(Base64.getDecoder().decode(key_r_txt), "HmacSHA256")); + String jwt_r = jwt.compact(); + + setRefreshCookie(response, request, jwt_r); + + //Если старый access токен ещё активен, то помещаем подпись этого токена в Redis (для определения одновременной авторизации из различных браузеров) + JSONObject old=storage.getJWT(json.getString("email")); + if(!old.isNull("time_a") && old.getLong("time_a")>Instant.now().getEpochSecond()){ + try(Cache cache = new Cache(redis_host,redis_port,redis_password)){ + cache.open(); + cache.set(Tools.extractSignature(old.getString("jwt_a")), "repeat", access_time); + }catch (Exception e) { + logger.error("An error occurred", e); + } + } + + //Обновляю либо создаю Refresh токен в базе + storage.setJWT( + json.getString("email"), + key_r_txt, + jwt_r, + jwt_a, + (System.currentTimeMillis() + refresh_time * 1000)/1000, + (System.currentTimeMillis() + access_time * 1000)/1000 + ); + + if(json!=null) { + json.put("error_code",0); + //json.put("error_message",""); + //json.put("error_marker",(String)null); + json.put("ip",ipAddress); + + + String rolesString = json.getJSONObject("roles").getString("value"); + JSONArray rolesArray = new JSONArray(rolesString); + json.put("roles",rolesArray); + } + + } catch (CustomException e) { + json = e.getJson(); + } catch (Exception e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Internal_Server_Error"), uuid); + } finally { + //try { if(conn!=null) conn.close(); } catch (SQLException e) { throw new RuntimeException(e); } + } + return json.toString(); + } + + //Функция для генерации нового TOTP ключа (немного похожа на логин, но не логин). + //Если это первое получение TOTP, то старый TOTP не нужен если последующее, то нужен! + @RequestMapping(value = "/newtotp",method = {RequestMethod.POST},produces = "application/json;charset=utf-8") + @ResponseBody + public String newtotp(HttpServletRequest request, @RequestBody LoginModel loginModel, @RequestParam(required=false,name="lng",defaultValue="1") String language_id) { + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + json.put("error_message",""); + try { + if(loginModel.getLogin().isEmpty()) + throw new CustomException(10000,trt.trt("The_login_field_is_empty"),null); + if(!Tools.isValidEmail(loginModel.getLogin())) + throw new CustomException(10000,trt.trt("The_login_field_is_incorrect"),null); + if(loginModel.getPassword().isEmpty()) + throw new CustomException(10000,trt.trt("The_password_field_is_empty"),null); + if(loginModel.getPassword().length()<=3) + throw new CustomException(10000,trt.trt("The_password_field_is_short"),null); + if(loginModel.getAppid().isEmpty()) + throw new CustomException(10000,trt.trt("The_application_name_field_is_empty"),null); + + String ipAddress = request.getHeader("X-FORWARDED-FOR"); //Не беспокойся на регистр не обращает внимания + if (ipAddress == null) { + ipAddress = request.getRemoteAddr(); + } + + //I check that there are no more than 5 failed authorization errors in 5 minutes + String sql = ""; + int attempt_count=0, attempt_limit=0, attempt_duration=0; + MapSqlParameterSource parameters = null; + List ret = null; + try { + sql = "select * from main.user_is_blocked(:login,:ip)"; + parameters = new MapSqlParameterSource(); + parameters.addValue("login", loginModel.getLogin()); + parameters.addValue("ip", ipAddress); + ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + json = new JSONObject(ret.get(i)); + if (!json.has("result") || json.getBoolean("result")) { + if(json.getInt("count")==0) + { + throw new CustomException(10000, trt.trt("The_user_account_is_blocked"),null); + }else{ + throw new CustomException(10000, String.format(trt.trt("The_limit_of_authorization_attempts_has_been_exceeded_please_wait_s_minutes"), json.getInt("limit_duration")),null); + } + } + if(json.has("count") && json.has("limit_count") && json.has("limit_duration")) { + attempt_count = json.getInt("count"); + attempt_limit = json.getInt("limit_count"); + //attempt_duration = json.getInt("limit_duration"); + } + } + }catch (DataAccessException ex){ + String uuid = UUID.randomUUID().toString(); + logger.error("Функция main.user_is_blocked не вернула результата!", uuid, ex); + throw new CustomException(10000, trt.trt("Error_executing_SQL_query"),uuid); + } + + //I'm trying to log in + json = null; + try { + sql="select * from main.p__login(:user_id,:login,:password,:ip,:fingerprint);"; + parameters = new MapSqlParameterSource(); + parameters.addValue("user_id", 1); + parameters.addValue("login", loginModel.getLogin()); + parameters.addValue("password", loginModel.getPassword()); + parameters.addValue("ip", ipAddress); + parameters.addValue("fingerprint", null); + ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + json = new JSONObject(ret.get(i)); + } + }catch (DataAccessException ex){ + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,ex); + throw new CustomException(10000, trt.trt("Error_executing_SQL_query"),uuid); + } + if(json==null) { + String msg = trt.trt("Invalid_username_and_or_password"); + if(attempt_count>0){ + msg = msg + " " + String.format(trt.trt("Authorization_attempts_s_out_of_s"),attempt_count,attempt_limit); + } + throw new CustomException(10000, msg, null); + } + + if(json.has("block")) { + if(json.getBoolean("block")) + throw new CustomException(10006,trt.trt("The_user_account_is_blocked"),null); + json.remove("block"); + } + + //Если есть старый TOTP то проверяем его + if(json.has("secret")) { + if(!json.isNull("secret")) { + + if(!Tools.isInteger(loginModel.getTotp())) + throw new CustomException(10000,trt.trt("The_TOTP_field_is_empty"),null); + + //Проверяю на соответствие TOTP ключа TODO потом написать поверку в функции p__Login плагином + GoogleAuthenticator gAuth = new GoogleAuthenticator(); + boolean isCodeValid = gAuth.authorize(json.getString("secret"), Integer.valueOf(loginModel.getTotp())); + if(!isCodeValid){ + throw new CustomException(10000, trt.trt("TOTP_key_does_not_match"), null); + } + } + json.remove("secret"); + } + //Теперь новый TOTP ключ и далее отправляем его клиенту для сканирования при помощи QR кода + // Генерация TOTP ключа + GoogleAuthenticator gAuth = new GoogleAuthenticator(); + GoogleAuthenticatorKey key = gAuth.createCredentials(); + String secretKey = key.getKey(); + + //сохраняю ключ пользователю + try { + sql="update main._Users set key=:secret where id=:user_id"; + parameters = new MapSqlParameterSource(); + parameters.addValue("secret", secretKey); + parameters.addValue("user_id", json.getInt("user_id")); + int cnt = jdbcTemplate.update(sql, parameters); + }catch (DataAccessException ex){ + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,ex); + throw new CustomException(10000, trt.trt("Error_executing_SQL_query"),uuid); + } + + // Создание OTP URL + String otpauthUrl = "otpauth://totp/" + issuer_name + ":" + loginModel.getLogin() + + "?secret=" + secretKey + + "&issuer=" + issuer_name + + "&period=30"; + + // Формирование JSON ответа + json = new JSONObject(); + json.put("error_code", 0); + json.put("error_message", ""); + json.put("url", otpauthUrl); + + } catch (CustomException e) { + json = e.getJson(); + } catch (Exception e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Internal_Server_Error"), uuid); + } finally { + //try { if(conn!=null) conn.close(); } catch (SQLException e) { throw new RuntimeException(e); } + } + return json.toString(); + } + + @RequestMapping(value = "/logout",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String logout(HttpServletResponse response,HttpServletRequest request) { + + //Устанавливает куки + setAccessCookie(response,""); + + setRefreshCookie(response, request, ""); + + return createStrJSONError(0,"",null); + } + + //Update refresh token + @RequestMapping(value = "/refresh",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String refresh(HttpServletResponse response,HttpServletRequest request,@CookieValue(value = "jwt_a", defaultValue = "") String jwt_a,@CookieValue(value = "jwt_r", defaultValue = "") String jwt_r,@RequestParam(required=false,name="lng",defaultValue = "1") String language_id) { + + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + json.put("error_message",""); + try { + + if(jwt_a.equals("") || countOccurrences(jwt_a, '.')!=2 || jwt_r.equals("") || countOccurrences(jwt_r, '.')!=2 ) + { + logout(response,request); + throw new CustomException(10000, trt.trt("Please_send_a_valid_JWT_token"),null); + } + + //Разбираю токен без проверки, чтобы выбрать email + String email=""; + JSONObject token_a=Tools.extractToken(jwt_a); + if(token_a!=null && token_a.has("email") && !token_a.isNull("email")) { + email = token_a.getString("email"); + } + + //По email из jwt_a выбираю ключ из базы данных для проверки Refresh токена + String key_r_txt = storage.getKey(email); + + //Проверяю подпись рефреш токена + Jws token = null; + try { + token = Jwts.parserBuilder() + .setSigningKey(getPublicKey()) //.setSigningKey(key_r) + .build() + .parseClaimsJws(jwt_r); + } catch (Exception e) { + logout(response,request); + throw new CustomException(10000, trt.trt("JWT_token_verification_error"),null); + } + + //Для обнаружения попытки взлома проверяю чтобы подпись токена доступа совпадала с тем что записано в токете обновления + String token_aa_sig = Tools.extractSignature(jwt_a); //Текущая подпись токена доступа + String token_ar_sig = token.getBody().get("sig", String.class); //Она же но уже в токене обновления + if(token_aa_sig==null || !token_aa_sig.equals(token_ar_sig)){ + logout(response,request); //Удаляю куки чтобы эмулировать выход из приложения + return createStrJSONError(10000,trt.trt("Attempt_to_substitution_tokens"),null); + } + + //TODO проверить не заблокирован ли пользователь + //if(json.has("block")) { + // if(json.getBoolean("block")) + // throw new CustomException(10006,trt.trt("The_user_account_is_blocked"),null); + // json.remove("block"); + //} + + //Создаю новый JWT access токен + Date expirationDate = new Date(System.currentTimeMillis() + access_time * 1000); // Текущая дата + время из настроек (600 сек = 10 минут) + token.getBody().setExpiration(expirationDate); + // Создание нового токена на основе Claims токена обновления + jwt_a = Jwts.builder() + .setClaims(token.getBody()) //Переписываю значения из токена обновления + .signWith(getPrivateKey()) //.signWith(new SecretKeySpec(Base64.getDecoder().decode(key_a_txt), "HmacSHA256")) + .compact(); // Преобразование в строку + token_ar_sig = Tools.extractSignature(jwt_a); //Для записи подписи в новый jwt_r токен + setAccessCookie(response, jwt_a); + + //Создаю новый JWT refresh токен + key_r_txt = Tools.genKey(); + expirationDate = new Date(System.currentTimeMillis() + refresh_time * 1000); // Текущая дата + время из настроек (600 сек = 12 часов) + token.getBody().setExpiration(expirationDate); + token.getBody().put("sig", token_ar_sig); + jwt_r = Jwts.builder() + .setClaims(token.getBody()) + .signWith(getPrivateKey()) //.signWith(new SecretKeySpec(Base64.getDecoder().decode(key_r_txt), "HmacSHA256")) + .compact(); // Преобразование в строку + + setRefreshCookie(response, request, jwt_r); + + //Обновляю либо создаю Refresh токен в базе + storage.setJWT( + email, + key_r_txt, + jwt_r, + jwt_a, + (System.currentTimeMillis() + refresh_time * 1000)/1000, + (System.currentTimeMillis() + access_time * 1000)/1000 + ); + + } catch (CustomException e) { + json = e.getJson(); + } catch (Exception e) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid,e); + json = createJSONError(10000,trt.trt("Internal_Server_Error")+" "+e.getMessage(), uuid); + } finally { + + } + return json.toString(); + } + + @RequestMapping(value = "/reset",method = {RequestMethod.POST,RequestMethod.GET},produces = "text/html;charset=utf-8") + @ResponseBody + public String reset(@RequestParam(required=false,name="token",defaultValue = "") String token,@RequestParam(required=false,name="lng",defaultValue = "1") String language_id) { + + Translation trt = new Translation(language_id,jdbcTemplate); + String result=createHTMLError(1,trt.trt("Request_not_processed")); + + int index = token.indexOf("."); + if(index<0) + return createHTMLError(10000,trt.trt("Please_send_a_valid_token")); + + String payload = token.substring(0, index); + String signature1 = token.substring(index+1); + + String signature2 = Tools.generateSignature(captchaKey,payload); + if(! signature1.equals(signature2)) + { + return createHTMLError(1,trt.trt("The_signature_did_not_match")); + } + + //расшифровываю + JSONObject jToken = new JSONObject(Tools.decryptText(captchaKey,payload)); + if(jToken==null) + return createHTMLError(10000,trt.trt("Please_send_a_valid_JSON_string_in_your_token")); + if(jToken.getLong("exp") ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + id = (new JSONObject(ret.get(i))).getLong("id"); + } + if(id==0) + return createHTMLError(10000, trt.trt("The_password_update_request_has_expired")); + + //Теперь обновляем пароль в базе + sql = "update main._users set password=crypt(password_new, gen_salt('bf')),password_new = null,expiration='1970-01-01' where password_new is not null and email=:email"; + parameters = new MapSqlParameterSource(); + parameters.addValue("email", jToken.getString("email")); + int cnt = jdbcTemplate.update(sql, parameters); + + return createHTMLError(0,trt.trt("The_password_has_been_changed_and_you_will_be_redirected_to_the_main_page")); + } + + @RequestMapping(value = "/restore",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String restore(Model model, @RequestBody RestoreModel restore, @RequestParam(required=false,name="lng",defaultValue = "1") String language_id) { + + Translation trt = new Translation(language_id,jdbcTemplate); + + String result=createStrJSONError(10000,trt.trt("Request_not_processed"),null); + //Connection conn = getConnection(); + + int index = restore.getToken().indexOf("."); + String payload = restore.getToken().substring(0, index); + String signature1 = restore.getToken().substring(index+1); + + System.out.println("signature1: " + signature1); + System.out.println("payload: " + payload); + + String signature2 = Tools.generateSignature(captchaKey,payload); + if(! signature1.equals(signature2)) + { + result=createStrJSONError(10000,trt.trt("The_signature_did_not_match"),null); + } + + System.out.println("signature2: " + signature2); + + //расшифровываю + JSONObject token = new JSONObject(Tools.decryptText(captchaKey,payload)); + + if(token==null) + return createStrJSONError(10000,trt.trt("Please_send_a_valid_JSON_string_in_your_token"),null); + if(!restore.getCode().equals(token.getString("code"))){ + return createStrJSONError(10000,trt.trt("The_code_did_not_match"),null); + } + + if(token.getLong("exp") ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + for (int i = 0; i < ret.size(); i++) { + id = (new JSONObject(ret.get(i))).getLong("id"); + } + if(id==0) + return createStrJSONError(10000, trt.trt("User_with_this_email_was_not_found"),null); + + String password_new = Tools.generatePassword(6); + + sql = "update main._users set password_new=:password_new where email=:email"; + parameters = new MapSqlParameterSource(); + parameters.addValue("password_new", password_new); + parameters.addValue("email", token.getString("email")); + int cnt = jdbcTemplate.update(sql, parameters); + + //Создаю новый токен, кодирую, шифрую, подписываю и затем отправляю на почту + JSONObject jTokenNew = new JSONObject(); + jTokenNew.put("exp", Instant.now().getEpochSecond()+(60*60)); //+60 минут + jTokenNew.put("password",password_new); + jTokenNew.put("email",token.getString("email")); + String token_new = jTokenNew.toString(); + token_new = Tools.encryptText(captchaKey,token_new); + token_new = token_new+"."+Tools.generateSignature(captchaKey, token_new); //Подпись для как бы токена + + //token_new = token_new.replace("+", "-") + // .replace("/", "_") + // .replace("=", "^"); //Убираем спец символы для передачи через URL + try { + token_new = URLEncoder.encode(token_new, StandardCharsets.UTF_8.toString()); + } catch (UnsupportedEncodingException e) { + return createStrJSONError(10000, trt.trt("Internal_Server_Error"),null); + } + + //Формирую ссылку для отправки на почту для сброса пароля + String html = ""+trt.trt("Password_recovery")+""; + html += "

"+trt.trt("To_reset_your_password_click_on_the_link")+":

"; + html += ""+trt.trt("Reset_the_password")+"

"; + html += trt.trt("After_clicking_on_the_link_the_new_password_will_be")+": \"" + password_new + "\""; + html += ""; + try { + EmailUtility.sendEmail(mail_host, mail_port, mail_login, mail_password, token.getString("email"), trt.trt("Password_recovery"), html); + } catch (Exception ex) { + String uuid = UUID.randomUUID().toString(); + logger.error(uuid, ex); + return createStrJSONError(10000,String.format(trt.trt("Failed_send_mail_to_s"), token.getString("email")),uuid); + } + return createStrJSONError(0, trt.trt("A_recovery_link_has_been_sent_to_your_email"),(String)null); + } + + @RequestMapping(value = "/update",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String update(HttpServletRequest request, @RequestBody UpdateModel update, @RequestParam(required=false,name="lng",defaultValue="1") String language_id) { + + Translation trt = new Translation(language_id,jdbcTemplate); + JSONObject json = new JSONObject(); + json.put("error_code",0); + json.put("error_message",""); + try { + if(update==null) + throw new CustomException(10000,trt.trt("Please_send_a_valid_JSON_string_in_your_request"),null); + if(update.getLogin().equals("")) + throw new CustomException(10000,trt.trt("The_login_field_is_empty"),null); + if (!Tools.isValidEmail(update.getLogin())) + throw new CustomException(10000, trt.trt("The_email_field_is_incorrect"),null); + if(update.getPassword().equals("")) + throw new CustomException(10000,trt.trt("The_password_field_is_empty"),null); + if(update.getPasswordNew().equals("")) + throw new CustomException(10000,trt.trt("The_new_password_field_is_empty"),null); + + if(!Pattern.compile("[0-9]").matcher(update.getPasswordNew()).find()) + throw new CustomException(10000,trt.trt("The_password_is_missing_a_number"),null); + if(!Pattern.compile("[a-z]").matcher(update.getPasswordNew()).find()) + throw new CustomException(10000,trt.trt("The_password_is_missing_a_small_Latin_letter"),null); + if (!Pattern.compile("[A-Z]").matcher(update.getPasswordNew()).find()) + throw new CustomException(10000,trt.trt("The_password_is_missing_a_big_Latin_letter"),null); + if (!Pattern.compile("[_!@#$%^&*]").matcher(update.getPasswordNew()).find()) + throw new CustomException(10000,trt.trt("The_password_is_missing_a_special_letter"),null); + if (update.getPasswordNew().length() < 6) + throw new CustomException(10000,trt.trt("The_password_is_less_than_six_characters"),null); + + //Проверяем попытки смены пароля (сохраение попыток в функции логина) + String ipAddress = request.getHeader("X-FORWARDED-FOR"); + if (ipAddress == null) { + ipAddress = request.getRemoteAddr(); + } + //String sql = "select main.user_is_blocked(:login,:ip) as block"; + String sql = "select * from main.user_is_blocked(:login,:ip)"; + MapSqlParameterSource parameters = new MapSqlParameterSource(); + parameters.addValue("login", update.getLogin()); + parameters.addValue("ip", ipAddress); + List ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + JSONObject rows=null; + for (int i = 0; i < ret.size(); i++) { + rows = new JSONObject(ret.get(i)); + if(rows.getBoolean("result")) { + throw new CustomException(10000, String.format(trt.trt("The_limit_of_authorization_attempts_has_been_exceeded_please_wait_s_minutes"), 5),null); + } + } + if(rows==null) { + logger.error("Функция main.user_is_blocked не вернула результата!"); + throw new CustomException(10000, trt.trt("Error_executing_SQL_query"),null); + } + + //Получаю id пользователя + sql="select id from main._users where del=false and password=crypt(:password, password) and email=:email"; + parameters = new MapSqlParameterSource(); + parameters.addValue("email", update.getLogin()); + parameters.addValue("password", update.getPassword()); + ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + rows = null; + for (int i = 0; i < ret.size(); i++) { + rows = new JSONObject(ret.get(i)); + } + if(rows==null) + throw new CustomException(10000,trt.trt("Invalid_username_and_or_password"),null); + + //Обновляю пароль + sql = "update main._users set password=crypt(:password_new, gen_salt('bf')),password_new = null,expiration=now()+INTERVAL '1 year' where password=crypt(:password, password) and email=:email"; + parameters = new MapSqlParameterSource(); + parameters.addValue("password", update.getPassword()); + parameters.addValue("password_new", update.getPasswordNew()); + parameters.addValue("email", update.getLogin()); + int cnt = jdbcTemplate.update(sql, parameters); + + if(json!=null) { + json.put("error_code",0); + json.put("error_message",""); + json.put("error_marker",(String)null); + } + + } catch (CustomException e) { + json = e.getJson(); + } finally { + } + return json.toString(); + } + + @RequestMapping(value = "/alive",method = {RequestMethod.POST,RequestMethod.GET},produces = "application/json;charset=utf-8") + @ResponseBody + public String alive(HttpServletResponse response,HttpServletRequest request, @CookieValue(value = "jwt_a", defaultValue = "") String jwt_a, @CookieValue(value = "lng",defaultValue="1") String language_id) { + + Translation trt = new Translation(language_id,jdbcTemplate); + + if(jwt_a.equals("") || countOccurrences(jwt_a, '.')!=2) + { + return createStrJSONError(10000,trt.trt("Please_send_a_valid_JWT_token"),null); + } + //Connection conn = getConnection(); + //Checking the token signature + Jws claims = null; + //SecretKey key_a = new SecretKeySpec(Base64.getDecoder().decode(key_a_txt), "HmacSHA256"); + try { + claims = Jwts.parserBuilder() + .setSigningKey(getPublicKey()) //.setSigningKey(key_a) + .build() + .parseClaimsJws(jwt_a); + } catch (Exception e) { + return createStrJSONError(10000, trt.trt("JWT_token_verification_error"),null); + } + //If this is a repeat authorization, then we inform the client about it + String result=null; + try(Cache cache = new Cache(redis_host,redis_port,redis_password)) { + cache.open(); + String data = cache.get(claims.getSignature()); + if (data != null) { + if (data.equals("repeat")) + result = createStrJSONError(10000, trt.trt("Reauthorization_detected_if_it_is_not_you_please_change_your_password"),null); + else + result = createStrJSONError(10000, trt.trt("Your_authorization_token_is_not_valid"),null); + } + } catch (Exception e) { + logger.error("An error occurred", e); + e.printStackTrace(); + } + if(result!=null) + { + logout(response,request); + return result; + } + return createStrJSONError(0,"",null); + } +} diff --git a/src/main/java/org/ccalm/jwt/Translation.java b/src/main/java/org/ccalm/jwt/Translation.java new file mode 100644 index 0000000..ec4aa4d --- /dev/null +++ b/src/main/java/org/ccalm/jwt/Translation.java @@ -0,0 +1,60 @@ +package org.ccalm.jwt; + +import org.ccalm.jwt.tools.DBTools; +import org.json.JSONArray; +import org.json.JSONObject; +import org.springframework.jdbc.core.namedparam.MapSqlParameterSource; +import org.springframework.jdbc.core.namedparam.NamedParameterJdbcTemplate; + +import java.util.List; + +public class Translation { + public int language_id; + public NamedParameterJdbcTemplate jdbcTemplate; + Translation(String lng, NamedParameterJdbcTemplate jdbcTemplate){ + language_id=1; + switch (lng) { + case "kz": + case "kk": + language_id = 2; + break; + case "en": + language_id = 3; + break; + case "uz": + language_id = 4; + break; + case "ru": + default: + language_id = 1; + break; + } + this.jdbcTemplate = jdbcTemplate; + } + + String trt(String text){ + String sql = """ + select + translation + from + main._translations + where + del=false + and language_id=:language_id + and identifier=:identifier; + """; + MapSqlParameterSource parameters = new MapSqlParameterSource(); + parameters.addValue("language_id", language_id); + parameters.addValue("identifier", text); + List ret = jdbcTemplate.query(sql, parameters, new DBTools.JsonRowMapper()); + int i = 0; + for (i = 0; i < ret.size(); i++) { + JSONObject json = new JSONObject(ret.get(i)); + text = json.getString("translation"); + } + if(i==0){ + text = text.replace("_", " "); + } + return text; + } +} diff --git a/src/main/java/org/ccalm/jwt/models/ActionName.java b/src/main/java/org/ccalm/jwt/models/ActionName.java new file mode 100644 index 0000000..6e932af --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/ActionName.java @@ -0,0 +1,16 @@ +package org.ccalm.jwt.models; + +//import jakarta.persistence.Column; +import com.fasterxml.jackson.annotation.JsonProperty; + +public class ActionName { + //@Column(name = "action_name", nullable = true) + @JsonProperty("action_name") + private String action_name; + public String getActionName() { + return action_name; + } + public void setActionName(String action_name) { + this.action_name = action_name; + } +} \ No newline at end of file diff --git a/src/main/java/org/ccalm/jwt/models/EmailModel.java b/src/main/java/org/ccalm/jwt/models/EmailModel.java new file mode 100644 index 0000000..8126efe --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/EmailModel.java @@ -0,0 +1,14 @@ +package org.ccalm.jwt.models; + +import com.fasterxml.jackson.annotation.JsonProperty; + +public class EmailModel { + @JsonProperty("email") + String email; + public String getEmail() { + return email; + } + public void setEmail(String email) { + this.email = email; + } +} diff --git a/src/main/java/org/ccalm/jwt/models/ErrorModel.java b/src/main/java/org/ccalm/jwt/models/ErrorModel.java new file mode 100644 index 0000000..237d9fe --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/ErrorModel.java @@ -0,0 +1,19 @@ +package org.ccalm.jwt.models; + +import com.fasterxml.jackson.annotation.JsonProperty; + +public class ErrorModel { + @JsonProperty("timestamp") + private String timestamp; + + @JsonProperty("status") + private int status; + + @JsonProperty("error") + private String error; + + @JsonProperty("path") + private String path; + + // Конструктор, геттеры и сеттеры +} diff --git a/src/main/java/org/ccalm/jwt/models/LoginModel.java b/src/main/java/org/ccalm/jwt/models/LoginModel.java new file mode 100644 index 0000000..212ba3a --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/LoginModel.java @@ -0,0 +1,36 @@ +package org.ccalm.jwt.models; + +public class LoginModel { + //@JsonProperty("login") + private String login; + //@JsonProperty("password") + private String password; + //@JsonProperty("appid") + private String totp; + private String appid; + public String getLogin() { + return login; + } + public void setLogin(String login) { + this.login = login; + } + public String getPassword() { + return password; + } + public void setPassword(String password) { + this.password = password; + } + public String getTotp() { return totp; } + public void setTotp(String totp) { + this.totp = totp; + } + public String getAppid() { + return appid; + } + public void setAppid(String appid) { + this.appid = appid; + } + + + +} diff --git a/src/main/java/org/ccalm/jwt/models/NewUserModel.java b/src/main/java/org/ccalm/jwt/models/NewUserModel.java new file mode 100644 index 0000000..0b9ef09 --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/NewUserModel.java @@ -0,0 +1,47 @@ +package org.ccalm.jwt.models; + +import com.fasterxml.jackson.annotation.JsonProperty; + +public class NewUserModel { + + @JsonProperty("name") + private String name; + @JsonProperty("email") + private String email; + @JsonProperty("code") + private String code; + @JsonProperty("token") + private String token; + + public String getName() { + if(name==null) return ""; + else return name; + } + public void setName(String name) { + this.name = name; + } + + public String getEmail() { + if(email==null) return ""; + else return email; + } + public void setEmail(String email) { + this.email = email; + } + + public String getCode() { + if(code==null) return ""; + else return code; + } + public void setCode(String code) { + this.code = code; + } + + public String getToken() { + if(token==null) return ""; + else return token; + } + public void setToken(String token) { + this.token = token; + } +} diff --git a/src/main/java/org/ccalm/jwt/models/RestoreModel.java b/src/main/java/org/ccalm/jwt/models/RestoreModel.java new file mode 100644 index 0000000..86d71ee --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/RestoreModel.java @@ -0,0 +1,25 @@ +package org.ccalm.jwt.models; + +import com.fasterxml.jackson.annotation.JsonProperty; + +public class RestoreModel { + + @JsonProperty("code") + String code; + @JsonProperty("token") + String token; + + public String getCode() { + return code; + } + public void setCode(String code) { + this.code = code; + } + + public String getToken() { + return token; + } + public void setToken(String token) { + this.token = token; + } +} diff --git a/src/main/java/org/ccalm/jwt/models/SettingModel.java b/src/main/java/org/ccalm/jwt/models/SettingModel.java new file mode 100644 index 0000000..0419fc7 --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/SettingModel.java @@ -0,0 +1,28 @@ +package org.ccalm.jwt.models; + +import com.fasterxml.jackson.annotation.JsonProperty; + +public class SettingModel { + @JsonProperty("identifier") + private String identifier; + @JsonProperty("value") + private String value; + + public String getIdentifier() { + return identifier; + } + + public void setIdentifier(String identifier) { + this.identifier = identifier; + } + + public String getValue() { + return value; + } + + public void setValue(String value) { + this.value = value; + } + +} + diff --git a/src/main/java/org/ccalm/jwt/models/UpdateModel.java b/src/main/java/org/ccalm/jwt/models/UpdateModel.java new file mode 100644 index 0000000..e1bbf93 --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/UpdateModel.java @@ -0,0 +1,42 @@ +package org.ccalm.jwt.models; + +import com.fasterxml.jackson.annotation.JsonProperty; + +public class UpdateModel { + + @JsonProperty("login") + private String login; + @JsonProperty("password") + private String password; + @JsonProperty("password_new") + private String passwordNew; + + // Геттеры и сеттеры для полей + + public String getLogin() { + if(login==null) return ""; + else return login; + } + + public void setLogin(String login) { + this.login = login; + } + + public String getPassword() { + if(password==null) return ""; + else return password; + } + + public void setPassword(String password) { + this.password = password; + } + + public String getPasswordNew() { + if(passwordNew==null) return ""; + else return passwordNew; + } + + public void setPasswordNew(String passwordNew) { + this.passwordNew = passwordNew; + } +} diff --git a/src/main/java/org/ccalm/jwt/models/UserModel.java b/src/main/java/org/ccalm/jwt/models/UserModel.java new file mode 100644 index 0000000..0bae762 --- /dev/null +++ b/src/main/java/org/ccalm/jwt/models/UserModel.java @@ -0,0 +1,96 @@ +package org.ccalm.jwt.models; + +import com.fasterxml.jackson.annotation.JsonProperty; + +public class UserModel { + @JsonProperty("country_id") + private Long countryId; + @JsonProperty("company_name") + private String companyName; + @JsonProperty("position") + private String position; + @JsonProperty("name") + private String name; + @JsonProperty("surname") + private String surname; + @JsonProperty("patronymic") + private String patronymic; + @JsonProperty("phone") + private String phone; + @JsonProperty("email") + private String email; + @JsonProperty("password") + private String password; + + public Long getCountryId() { + return countryId; + } + + public void setCountryId(Long countryId) { + this.countryId = countryId; + } + + public String getCompanyName() { + return companyName; + } + + public void setCompanyName(String companyName) { + this.companyName = companyName; + } + + public String getPosition() { + return position; + } + + public void setPosition(String position) { + this.position = position; + } + + public String getName() { + return name; + } + + public void setName(String name) { + this.name = name; + } + + public String getSurname() { + return surname; + } + + public void setSurname(String surname) { + this.surname = surname; + } + + public String getPatronymic() { + return patronymic; + } + + public void setPatronymic(String patronymic) { + this.patronymic = patronymic; + } + + public String getPhone() { + return phone; + } + + public void setPhone(String phone) { + this.phone = phone; + } + + public String getEmail() { + return email; + } + + public void setEmail(String email) { + this.email = email; + } + + public String getPassword() { + return password; + } + + public void setPassword(String password) { + this.password = password; + } +} diff --git a/src/main/java/org/ccalm/jwt/tools/Cache.java b/src/main/java/org/ccalm/jwt/tools/Cache.java new file mode 100644 index 0000000..02df6ed --- /dev/null +++ b/src/main/java/org/ccalm/jwt/tools/Cache.java @@ -0,0 +1,63 @@ +package org.ccalm.jwt.tools; + +import org.ccalm.jwt.MainController; +import org.apache.logging.log4j.LogManager; +import org.apache.logging.log4j.Logger; +import org.springframework.beans.factory.annotation.Value; +import org.springframework.stereotype.Component; +import redis.clients.jedis.Jedis; + +import java.io.FileInputStream; +import java.io.IOException; +import java.io.InputStream; +import java.util.Properties; + + +public class Cache implements AutoCloseable { + + private static final Logger logger = LogManager.getLogger(Cache.class); + private Jedis jedis = null; + + String host = null; + int port = 0; + String password = null; + + public Cache(String host,int port,String password) { + this.host=host; + this.port=port; + this.password=password; + } + + public boolean open(){ + try { + jedis = new Jedis(host, port); + jedis.auth(password); + }catch (Exception e) + { + logger.error(e); + } + return true; + } + + @Override + public void close() throws Exception { + if(jedis!=null) + jedis.close(); + } + + public String get(String key) { + return jedis.get(key); + } + + public boolean set(String key,String data,int ttl){ + jedis.set(key, data); + long currentTimeMillis = System.currentTimeMillis(); + long expireTimeMillis = currentTimeMillis + ttl * 1000; + jedis.expireAt(key, expireTimeMillis / 1000); + return true; + } + + public void delete(String key) { + jedis.del(key.getBytes()); + } +} diff --git a/src/main/java/org/ccalm/jwt/tools/CustomException.java b/src/main/java/org/ccalm/jwt/tools/CustomException.java new file mode 100644 index 0000000..3ac21b0 --- /dev/null +++ b/src/main/java/org/ccalm/jwt/tools/CustomException.java @@ -0,0 +1,30 @@ +package org.ccalm.jwt.tools; + +import org.json.JSONObject; + +public class CustomException extends Exception { + private int errorCode; + private String marker; + + public CustomException(int errorCode,String message,String marker) { + super(message); + this.errorCode = errorCode; + this.marker = marker; + } + + public int getErrorCode() { + return errorCode; + } + + public String getErrorMarker() { + return marker; + } + + public JSONObject getJson() { + JSONObject json = new JSONObject(); + json.put("error_code", getErrorCode()); + json.put("error_message", getMessage()); + json.put("error_marker", getErrorMarker()); + return json; + } +} diff --git a/src/main/java/org/ccalm/jwt/tools/DBTools.java b/src/main/java/org/ccalm/jwt/tools/DBTools.java new file mode 100644 index 0000000..c31a792 --- /dev/null +++ b/src/main/java/org/ccalm/jwt/tools/DBTools.java @@ -0,0 +1,40 @@ +package org.ccalm.jwt.tools; + +import com.fasterxml.jackson.databind.ObjectMapper; +import org.springframework.jdbc.core.RowMapper; + +import java.sql.Connection; +import java.sql.PreparedStatement; +import java.sql.ResultSet; +import java.sql.SQLException; +import java.util.ArrayList; +import java.util.HashMap; +import java.util.List; +import java.util.Map; + +public class DBTools { + + public static class JsonRowMapper implements RowMapper { + + @Override + public String mapRow(ResultSet rs, int rowNum) throws SQLException { + ObjectMapper objectMapper = new ObjectMapper(); + Map resultMap = new HashMap<>(); + + // Получаем метаданные ResultSet для получения названий столбцов + int columnCount = rs.getMetaData().getColumnCount(); + for (int i = 1; i <= columnCount; i++) { + String columnName = rs.getMetaData().getColumnName(i); + Object columnValue = rs.getObject(i); + resultMap.put(columnName, columnValue); + } + + // Преобразовываем Map в JSON строку + try { + return objectMapper.writeValueAsString(resultMap); + } catch (Exception e) { + throw new RuntimeException("Failed to convert Map to JSON", e); + } + } + } +} diff --git a/src/main/java/org/ccalm/jwt/tools/EmailUtility.java b/src/main/java/org/ccalm/jwt/tools/EmailUtility.java new file mode 100644 index 0000000..5661312 --- /dev/null +++ b/src/main/java/org/ccalm/jwt/tools/EmailUtility.java @@ -0,0 +1,65 @@ +//From: http://www.codejava.net/java-ee/jsp/sending-e-mail-with-jsp-servlet-and-javamail +package org.ccalm.jwt.tools; + +import java.util.Date; +import java.util.Properties; + +import javax.mail.Authenticator; +import javax.mail.Message; +import javax.mail.MessagingException; +import javax.mail.PasswordAuthentication; +import javax.mail.Session; +import javax.mail.Transport; +import javax.mail.internet.AddressException; +import javax.mail.internet.InternetAddress; +import javax.mail.internet.MimeMessage; + +/** + * A utility class for sending e-mail messages + * @author www.codejava.net + * + */ +public class EmailUtility { + + public static void sendEmail(String host, String port, + final String userName, final String password, String toAddress, + String subject, String message) throws AddressException, + MessagingException + { + // sets SMTP server properties + Properties properties = new Properties(); + + properties.put("mail.smtp.host", host); + properties.put("mail.smtp.port", port); + properties.put("mail.smtp.auth", "true"); + //properties.put("mail.smtp.starttls.enable","true"); STARTTLS requested but already using SSL + properties.put("mail.smtp.EnableSSL.enable","true"); + properties.put("mail.smtp.socketFactory.port", port); + properties.put("mail.smtp.socketFactory.class","javax.net.ssl.SSLSocketFactory"); + //properties.put("mail.debug", "true"); + + + // creates a new session with an authenticator + Authenticator auth = new Authenticator() { + public PasswordAuthentication getPasswordAuthentication() { + return new PasswordAuthentication(userName, password); + } + }; + + Session session = Session.getInstance(properties, auth); + + //creates a new e-mail message + Message msg = new MimeMessage(session); + + msg.setFrom(new InternetAddress(userName)); + InternetAddress[] toAddresses = { new InternetAddress(toAddress) }; + msg.setRecipients(Message.RecipientType.TO, toAddresses); + msg.setSubject(subject); + msg.setSentDate(new Date()); + //msg.setText(message); + msg.setContent(message, "text/html; charset=utf-8"); + + // sends the e-mail + Transport.send(msg); + } +} \ No newline at end of file diff --git a/src/main/java/org/ccalm/jwt/tools/Storage.java b/src/main/java/org/ccalm/jwt/tools/Storage.java new file mode 100644 index 0000000..3019fcc --- /dev/null +++ b/src/main/java/org/ccalm/jwt/tools/Storage.java @@ -0,0 +1,167 @@ +package org.ccalm.jwt.tools; + +import org.ccalm.jwt.MainController; +import org.apache.logging.log4j.LogManager; +import org.apache.logging.log4j.Logger; +import org.json.JSONObject; + +import java.sql.*; + +public class Storage implements AutoCloseable { + + private static final Logger logger = LogManager.getLogger(Storage.class); + private Connection conn = null; + + public Storage(){ + String url = "jdbc:sqlite:temporary.sqlite"; + try { + conn = DriverManager.getConnection(url); + Statement stmt = conn.createStatement(); + String sql= """ + CREATE TABLE IF NOT EXISTS _users ( + id INTEGER PRIMARY KEY AUTOINCREMENT, + email TEXT NOT NULL, --Email пользователя + key TEXT NOT NULL, --Ключ для токена обновления (refresh token) + jwt_r TEXT NOT NULL, --Сам ключ обновления + jwt_a TEXT NOT NULL, --Сам ключ доступа + time_r INTEGER, --Unix time в секундах, когда заканчивается токен обновления + time_a INTEGER --Unix time в секундах, когда заканчивается токен доступа + ); + """; + stmt.execute(sql); + stmt.close(); + } catch (SQLException e) { + logger.error("Error connecting or executing SQL query in SQLite", e); + } + } + + //Для выполнения: try-with-resources + @Override + public void close() throws Exception { + if(conn!=null) { + try { + conn.close(); + conn=null; + } catch (SQLException e) { + logger.error("SQLite close error", e); + } + } + } + + // В коде не надеюсь на finalize, использую try-with-resources из AutoCloseable + @Override + protected void finalize() throws Throwable { + if(conn!=null) { + try { + conn.close(); + conn=null; + } catch (SQLException e) { + logger.error("SQLite close error", e); + } + } + super.finalize(); + } + + //Получаю поля из базы email пользователя + public JSONObject getJWT(String email){ + JSONObject result = new JSONObject(); + try { + PreparedStatement pstmt = conn.prepareStatement("SELECT * FROM _users WHERE email=?"); + pstmt.setString(1, email); + ResultSet rs = pstmt.executeQuery(); + if (rs.next()) { + result.put("id", rs.getInt("id")); + result.put("email", rs.getString("email")); + result.put("key", rs.getString("key")); + result.put("jwt_r", rs.getString("jwt_r")); + result.put("jwt_a", rs.getString("jwt_a")); + result.put("time_r", rs.getLong("time_r")); + result.put("time_a", rs.getLong("time_a")); + } + } catch (SQLException e) { + logger.error("An error occurred", e); + } + return result; + } + + //Сохранить либо обновить Refresh токен + public boolean setJWT(String email,String key,String jwt_r,String jwt_a,long time_r,long time_a){ + try { + // Проверка существует ли запись с данным email + PreparedStatement selectStmt = conn.prepareStatement("SELECT * FROM _users WHERE email=?"); + selectStmt.setString(1, email); + ResultSet rs = selectStmt.executeQuery(); + boolean exists = rs.next(); + selectStmt.close(); + if (exists) { + String updateSql = "UPDATE _users SET key=?, jwt_r=?, jwt_a=?, time_r=?, time_a=? WHERE email=?"; + PreparedStatement updateStmt = conn.prepareStatement(updateSql); + updateStmt.setString(1, key); + updateStmt.setString(2, jwt_r); + updateStmt.setString(3, jwt_a); + updateStmt.setLong(4, time_r); // Время в секундах + updateStmt.setLong(5, time_a); // Время в секундах + updateStmt.setString(6, email); + updateStmt.executeUpdate(); + updateStmt.close(); + } else { + String insertSql = "INSERT INTO _users(email, key, jwt_r, jwt_a, time_r, time_a) VALUES (?, ?, ?, ?, ?, ?)"; + PreparedStatement insertStmt = conn.prepareStatement(insertSql); + insertStmt.setString(1, email); + insertStmt.setString(2, key); + insertStmt.setString(3, jwt_r); + insertStmt.setString(4, jwt_a); + insertStmt.setLong(5, time_r); // Время в секундах + insertStmt.setLong(6, time_a); // Время в секундах + insertStmt.executeUpdate(); + insertStmt.close(); + } + return true; + } catch (SQLException e) { + logger.error("SQLite query execution error", e); + return false; + } + } + //Получаю пароль для токена обновления из базы + public String getKey(String email){ + String key=""; + try { + PreparedStatement pstmt = conn.prepareStatement("SELECT key FROM _users WHERE email=?"); + pstmt.setString(1, email); + ResultSet rs = pstmt.executeQuery(); + if (rs.next()) { + key = rs.getString("key"); + } + } catch (SQLException e) { + logger.error("SQLite query execution error", e); + } + return key; + } + //Получаю время когда Refresh token "протухнет" + public long getTime(String email){ + long time = 1; + try { + PreparedStatement pstmt = conn.prepareStatement("SELECT time_r FROM _users WHERE email=?"); + pstmt.setString(1, email); + ResultSet rs = pstmt.executeQuery(); + if (rs.next()) { + time = rs.getLong("time_r"); + } + } catch (SQLException e) { + logger.error("SQLite query execution error", e); + } + return time; + } + //Удалить токен обновления из базы данных + public boolean delToken(String email){ + try { + PreparedStatement pstmt = conn.prepareStatement("DELETE FROM _users WHERE email=?"); + pstmt.setString(1, email); + pstmt.executeUpdate(); + return true; + } catch (SQLException e) { + logger.error("SQLite query execution error", e); + return false; + } + } +} diff --git a/src/main/java/org/ccalm/jwt/tools/Tools.java b/src/main/java/org/ccalm/jwt/tools/Tools.java new file mode 100644 index 0000000..2ce5545 --- /dev/null +++ b/src/main/java/org/ccalm/jwt/tools/Tools.java @@ -0,0 +1,148 @@ +package org.ccalm.jwt.tools; + +import io.jsonwebtoken.SignatureAlgorithm; +import io.jsonwebtoken.security.Keys; +import org.json.JSONException; +import org.json.JSONObject; + +import javax.crypto.*; +import javax.crypto.spec.IvParameterSpec; +import javax.crypto.spec.SecretKeySpec; +import java.nio.charset.StandardCharsets; +import java.security.*; +import java.util.Base64; +import java.util.regex.Matcher; +import java.util.regex.Pattern; + +public class Tools { + + //Зашифровать + public static String encryptText(String pass,String data){ + String encryptedBase64=""; + String encryptionIV = "jazz_tyt_net_111"; // Ваш вектор инициализации + try { + Cipher cipher = Cipher.getInstance("AES/CTR/NoPadding"); + SecretKeySpec key = new SecretKeySpec(Base64.getDecoder().decode(pass), "AES"); + IvParameterSpec iv = new IvParameterSpec(encryptionIV.getBytes()); // Создание объекта IvParameterSpec для вектора инициализации + cipher.init(Cipher.ENCRYPT_MODE, key, iv); // Инициализация шифра с ключом и вектором инициализации + byte[] encrypted = cipher.doFinal(data.getBytes()); // Шифрование строки + encryptedBase64 = Base64.getEncoder().encodeToString(encrypted); // Преобразование зашифрованных данных в base64 + } catch (InvalidKeyException e) { + throw new RuntimeException(e); + } catch (InvalidAlgorithmParameterException e) { + throw new RuntimeException(e); + } catch (NoSuchPaddingException e) { + throw new RuntimeException(e); + } catch (IllegalBlockSizeException e) { + throw new RuntimeException(e); + } catch (NoSuchAlgorithmException e) { + throw new RuntimeException(e); + } catch (BadPaddingException e) { + throw new RuntimeException(e); + } + return encryptedBase64; + } + + public static String decryptText(String pass,String data){ + String encryptionIV = "jazz_tyt_net_111"; // Ваш вектор инициализации + String decryptedText= ""; + try { + Cipher cipher = Cipher.getInstance("AES/CTR/NoPadding"); + SecretKeySpec key = new SecretKeySpec(Base64.getDecoder().decode(pass), "AES"); + IvParameterSpec iv = new IvParameterSpec(encryptionIV.getBytes()); // Создание объекта IvParameterSpec для вектора инициализации + cipher.init(Cipher.DECRYPT_MODE, key, iv); // Инициализация шифра с ключом и вектором инициализации + + byte[] decrypted = cipher.doFinal(Base64.getDecoder().decode(data)); // Расшифровка данных + decryptedText = new String(decrypted); // Преобразование расшифрованных данных в строку + } catch (NoSuchAlgorithmException | NoSuchPaddingException | InvalidKeyException | + InvalidAlgorithmParameterException | IllegalBlockSizeException | BadPaddingException e) { + e.printStackTrace(); + } + return decryptedText; + } + + public static String generateSignature(String pass,String input) { + try { + SecretKey secretKey = new SecretKeySpec(Base64.getDecoder().decode(pass), "HmacSHA256"); + + MessageDigest digest = MessageDigest.getInstance("SHA-256"); + byte[] encodedInput = digest.digest(input.getBytes(StandardCharsets.UTF_8)); + byte[] encodedKey = secretKey.getEncoded(); + + // Создание HMAC-подписи + javax.crypto.spec.SecretKeySpec keySpec = new javax.crypto.spec.SecretKeySpec(encodedKey, "HmacSHA256"); + javax.crypto.Mac mac = javax.crypto.Mac.getInstance("HmacSHA256"); + mac.init(keySpec); + byte[] rawHmac = mac.doFinal(encodedInput); + + // Кодирование подписи в base64 + return Base64.getEncoder().encodeToString(rawHmac); + } catch (NoSuchAlgorithmException | java.security.InvalidKeyException e) { + e.printStackTrace(); + return null; + } + } + + public static boolean isValidEmail(String email) { + String EMAIL_REGEX = "^[a-zA-Z0-9_+&*-]+(?:\\.[a-zA-Z0-9_+&*-]+)*@(?:[a-zA-Z0-9-]+\\.)+[a-zA-Z]{2,7}$"; + Pattern pattern = Pattern.compile(EMAIL_REGEX); + Matcher matcher = pattern.matcher(email); + return matcher.matches(); + } + + public static boolean isInteger(String str) { + if (str == null || str.isEmpty()) { + return false; + } + try { + Integer.parseInt(str); + return true; + } catch (NumberFormatException e) { + return false; + } + } + + public static String genKey(){ + SecretKey key = Keys.secretKeyFor(SignatureAlgorithm.HS256); + byte[] keyBytes = key.getEncoded(); + return Base64.getEncoder().encodeToString(keyBytes); + } + + public static String generatePassword(int length) { + String CHARACTERS = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789"; + SecureRandom random = new SecureRandom(); + StringBuilder sb = new StringBuilder(length); + for (int i = 0; i < length; i++) { + int randomIndex = random.nextInt(CHARACTERS.length()); + sb.append(CHARACTERS.charAt(randomIndex)); + } + return sb.toString(); + } + + // Метод для извлечения подписи из JWT токена + public static String extractSignature(String jwtToken) { + String[] jwtParts = jwtToken.split("\\."); + if (jwtParts.length != 3) { + return null; + } + return jwtParts[2]; + } + + //Для извлечения содержимого токена + public static JSONObject extractToken(String jwtToken) { + String[] jwtParts = jwtToken.split("\\."); + if (jwtParts.length != 3) { + return null; + } + String payloadJson = new String(Base64.getUrlDecoder().decode(jwtParts[1])); + JSONObject payload=null; + try { + payload = new JSONObject(payloadJson); + } catch (JSONException e) { + return null; + } + return payload; + } + + +} diff --git a/src/main/resources/logback-spring.xml b/src/main/resources/logback-spring.xml new file mode 100644 index 0000000..99d4074 --- /dev/null +++ b/src/main/resources/logback-spring.xml @@ -0,0 +1,33 @@ + + + + + + + + + ${LOGS}/${appName}.log + + {"timestamp":"%d{yyyy-MM-dd'T'HH:mm:ss.SSS'Z'}","thread":"[%thread]","level":"%level","logger":"%logger{36}","marker":"%X{marker}","message":"%msg"}%n + + + ${LOGS}/${appName}.%d{yyyy-MM-dd}.%i.log + 30 + + 100MB + + + + + + + %d{yyyy-MM-dd'T'HH:mm:ss.SSS'Z'} | %level | %logger{36} | %X{marker} | %msg%n + + + + + + + + + diff --git a/src/test/java/com/geovizor/jwt/JwtApplicationTests.java b/src/test/java/com/geovizor/jwt/JwtApplicationTests.java new file mode 100644 index 0000000..4bcc0d9 --- /dev/null +++ b/src/test/java/com/geovizor/jwt/JwtApplicationTests.java @@ -0,0 +1,13 @@ +package org.ccalm.jwt; + +import org.junit.jupiter.api.Test; +import org.springframework.boot.test.context.SpringBootTest; + +@SpringBootTest +class JwtApplicationTests { + + @Test + void contextLoads() { + } + +}