commit fd9641db4bc91412ce6718c7fe91f8a93a5d18e7 Author: Vaclav VESELY Date: Sun Nov 28 19:58:00 2021 +0100 move from github to git.ictoi.io diff --git a/code.gs b/code.gs new file mode 100644 index 0000000..bc14d63 --- /dev/null +++ b/code.gs @@ -0,0 +1,624 @@ +function setTransferOwnership() { + // catch exception + try { + setDeleteAllTriggersOfHandlerFunction("setTransferOwnership"); + } catch(e) { + Flog("Can not delete triggers!" + e); + return false; + } + // catch exception + try { + Flog("Getting cache files."); + var startTime = new Date(), cacheWriteChunkSize = 20; + // get data from cache or init cache with all domain users + var cacheFileId = getCacheFileId(false, "dirScan"); + var resultFileId = getCacheFileId(false, "transResult"); + var fileCache = null, fileCacheTxt = null, fileResult = null, fileResultTxt = null; + fileCache = DriveApp.getFileById(cacheFileId), fileResult = DriveApp.getFileById(resultFileId); + fileCacheTxt = fileCache.getBlob().getDataAsString(), fileResultTxt = fileResult.getBlob().getDataAsString(); // FILE CACHE READ & FILE RESULT READ + Flog("Getting cache files. Done!"); + } catch(e) { + Flog("Can not get cache files! " + e); + return false; + } + // catch exception + try { + Flog("Parsing cache files."); + var inObj = {}, outObj = {}; + if (fileCacheTxt != "") { + inObj = JSON.parse(fileCacheTxt); + } else { + // blank cache file means terminate + Flog("Blank cache file. Run 'Scan dir to cache file' function first!"); + throw new Error("Blank cache file. Run scan dir first!"); // ERROR + } + //fileResult.setContent(""); // debug only + if (fileResultTxt === "") { + outObj["domainUsers"] = {}; + } + if (fileResultTxt !== "") { + outObj = JSON.parse(fileResultTxt); + } + Flog("Parsing cache files. Done!"); + } catch(e) { + Flog("Can not parse cache files! " + e); + return false; + } + // catch exception + try { + Flog("Work objects init."); + var cUserId = null, cUserObj = null, cUserFilesArr = [], doneFiles = [], todoFiles = []; + for (cUserId in inObj["domainUsers"]){ + if (inObj["domainUsers"][cUserId]["queryComplete"] === true && inObj["domainUsers"][cUserId]["userFiles"].length === 0) { + //Flog("No files for owner " + cUserId + ". Continue!"); + continue; + } + Flog("Set user " + cUserId + "."); + if (inObj["domainUsers"][cUserId]["queryComplete"] === true && inObj["domainUsers"][cUserId]["userFiles"].length !== 0) { + if (typeof outObj["domainUsers"][cUserId] === "undefined") { + outObj["domainUsers"][cUserId] = { + "ownerComplete" : false, + "todoFiles" : inObj["domainUsers"][cUserId]["userFiles"], + "doneFiles" : [] + }; + Flog("Set user " + cUserId + ". Done!"); + break; + } + if (outObj["domainUsers"][cUserId]["ownerComplete"] === true) { + Flog("Owner complete " + cUserId + ". Continue!"); + continue; + } + if (outObj["domainUsers"][cUserId]["ownerComplete"] !== true) { + doneFiles = outObj["domainUsers"][cUserId]["doneFiles"]; + break; + } + Flog("All users done. Success!"); + return true; // RETURN + } + Flog("All users done. Success!"); + return true; // RETURN + } + Flog("Work objects init. Done!"); + } catch(e) { + Flog("Can not set files to parse! " + e); + return false; + } + // catch exception + try { + // get impersonated token and transfer ownership + //Flog(JSON.stringify(outObj["domainUsers"][cUserId])); // debug only + todoFiles = outObj["domainUsers"][cUserId]["todoFiles"]; + var lenI = outObj["domainUsers"][cUserId]["todoFiles"].length; + Flog("Begin loop for " + cUserId + " length " + lenI + "."); + for (var i = 0; i < lenI; i++) { + ///Flog("Count: " + i); // debug only + //Utilities.sleep(1000); // debug only + if (todoFiles[i] === undefined) {break}; + try { + var impResult = setImpersonatedOwnership(todoFiles[i], cUserId, GVAR.TRANSFER_OWNERSHIP_TO); + } catch(e) { + Flog("Can not transfer ownership for actual file!"); + } + try { + DriveApp.removeFile(DriveApp.getFileById(todoFiles[i])); + } catch(e) { + Flog("Can not remove file from the root folder!"); + } + //var impResult = true; // debug only + if (impResult) { + var cItem = todoFiles.shift(); + doneFiles.push(cItem); + outObj["domainUsers"][cUserId]["doneFiles"] = doneFiles; + outObj["domainUsers"][cUserId]["todoFiles"] = todoFiles; + } else { + Flog("Error while transferring ownership of object id: " + todoFiles[i] + "!"); + break; + return false; + } + var timeElapsed = countdown(startTime, new Date(), countdown.DEFAULTS); + var timeElapsedValue = timeElapsed.value; + if (timeElapsedValue >= 242000) { // 4.04 minutes; 6 minutes max. but 5 minutes trigger run interval + // set continuation trigger + var contTrigger = ScriptApp.newTrigger("setTransferOwnership").timeBased().everyMinutes(1).create(); + //var contTriggerId = contTrigger.getUniqueId(); + //outObj["domainUsers"][cUserId]["contTriggerId"] = contTriggerId; + fileResult = fileResult.setContent(JSON.stringify(outObj)); // FILE CACHE WRITE + Flog("Timeout trigger set. Script will continue!"); + //throw new Error("Timeout"); + return false; // RETURN + } + // save in chunks + if (i % cacheWriteChunkSize === 0 && i > 0) { + fileResult = fileResult.setContent(JSON.stringify(outObj)); // FILE CACHE WRITE + var timeElapsedHuman = timeElapsed.toString(); + Flog("Chunk " + i + " in " + timeElapsedHuman + ". Done " + doneFiles.length + "; remains " + todoFiles.length + "."); + } + } + } catch(e) { + Flog("Can not loop files! " + e); + return false; + } + Flog("Transfer loop. Done!"); + outObj["domainUsers"][cUserId]["ownerComplete"] = true; + fileResult = fileResult.setContent(JSON.stringify(outObj)); + Flog("Chunk " + i + "." + " Done " + doneFiles.length + "; remains " + todoFiles.length + "."); + // recursive call + setTransferOwnership(); + //return true; + // set continuation trigger + /*var contTrigger = ScriptApp.newTrigger("setImpersonatedOwnershipDirScan").timeBased().everyMinutes(5).create(); + var contTriggerId = contTrigger.getUniqueId(); + outObj["contTriggerId"] = contTriggerId; + fileResult = fileResult.setContent(JSON.stringify(outObj));*/ +} + +function setDirScanToCacheFile() { + // catch exception + try { + setDeleteAllTriggersOfHandlerFunction("setDirScanToCacheFile"); + } catch(e) { + Flog("Can not delete triggers!" + e); + } + var startTime = new Date(); + // catch exception + try { + // get data from cache or init cache with all domain users + Flog("Get and parse cache file."); + var cacheFileId = getCacheFileId(false, "dirScan"); + var fileCache = null, fileCacheTxt = null, loopCount = 0; + fileCache = DriveApp.getFileById(cacheFileId); + //fileCache.setContent(""); // debug only + fileCacheTxt = fileCache.getBlob().getDataAsString(); // FILE CACHE READ + var masterObj = {}; + if (fileCacheTxt != "") { + masterObj = JSON.parse(fileCacheTxt); + } else { + // get all domain users + var allDomainUsersEmail = getAllDomainUsersEmail(); + masterObj = {"domainUserList" : allDomainUsersEmail, "domainUsers" : {}}; + fileCache = fileCache.setContent(JSON.stringify(masterObj)); // FILE CACHE WRITE + } + Flog("Get and parse cache file. Done!"); + } catch (e) { + Flog("Can not get domain users or parse cache file!"); + return false; + } + // loop all users and generate file list + Flog(masterObj["domainUserList"]); + if (typeof masterObj["domainUserList"] !== "undefined" && masterObj["domainUserList"].length > 0) { + for (var i = 0, lenI = masterObj["domainUserList"].length; i < lenI; i++) { + if (typeof masterObj["domainUsers"][masterObj["domainUserList"][i]] !== "undefined" + && masterObj["domainUsers"][masterObj["domainUserList"][i]]["queryComplete"] === true) { + Flog(masterObj["domainUserList"][i] + " item " + i + " of " + lenI + ". Done!"); // debug only + continue; + }; + Flog("Starting item " + i + " of " + lenI + ". Done!"); + //var actionResult = setAllOwnerFilesCacheFile("jan.hus@ictoi.com", false, cacheFileId, startTime, 20, GVAR.CACHE_FILE_LIFETIME); // debug only + //var actionResult = setAllOwnerFilesCacheFile(masterObj["domainUserList"][i], false, cacheFileId, startTime, 20, GVAR.CACHE_FILE_LIFETIME); // debug only + var actionResult = setAllOwnerFilesCacheFile(masterObj["domainUserList"][i], false, cacheFileId, startTime, 25, GVAR.CACHE_FILE_LIFETIME); // debug only + //var actionResult = setAllOwnerFilesCacheFile(masterObj["domainUserList"][i], false, cacheFileId, startTime, 30, GVAR.CACHE_FILE_LIFETIME); // debug only + //var actionResult = setAllOwnerFilesCacheFile(masterObj["domainUserList"][i], false, cacheFileId, startTime, 40, GVAR.CACHE_FILE_LIFETIME); // debug only + //var actionResult = setAllOwnerFilesCacheFile(masterObj["domainUserList"][i], false, cacheFileId, startTime, 2, GVAR.CACHE_FILE_LIFETIME); // debug only + if (!actionResult) { + Flog("Action result is false. Error!"); + return false + }; + } + } + Flog("Scan dir for all owners completed successfully. Done!"); + // prepare email variables and send transactional email + var mailVariablesObj = { + "~backgroundColor~" : "#738ffe", // #738ffe = Blue 400 + "~titleText~" : "Scan dir for all owners completed successfully", + "~headerMessage~" : "Scan dir for all owners completed successfully", + "~mainMessage~" : "Scan dir for ownership transfer completed successfully for all owners.", + "~buttonText~" : "See generated cache file", + "~buttonUrl~" : "https://drive.google.com/open?id=" + cacheFileId + "&authuser=0", + "~footerText~" : "Do not reply to this email." + }; + var mailSendResult = setSendTransactionalEmail(GVAR.TRANSFER_OWNERSHIP_TO, mailVariablesObj); +} + +function setAllOwnerFilesCacheFile(ownerEmail, returnNegatives, cacheFileId, startTime, cacheWriteChunkSize, queryLifeTimeHours) { + Flog("File init for " + ownerEmail + "."); + // catch exception + try { + // get lock + var userLock = LockService.getUserLock(); + userLock.waitLock(10000); + if (!userLock.hasLock()) { + Flog("Can not run second instance of the script."); + //throw new Error("Can not run second instance of the script."); // ERROR + return false; // RETURN + }; + } catch(e) { + Flog("Can not get user lock! " + e); + return false; + } + // catch exception + try { + // init cache + //Flog("Get and parse cache file."); + var fileCache = null, fileCacheTxt = null, loopCount = 0, cLifeTime = null; + fileCache = DriveApp.getFileById(cacheFileId); + //fileCache.setContent(""); // debug only + fileCacheTxt = fileCache.getBlob().getDataAsString(); // FILE CACHE READ + var masterObj = {}; + // check cache file blank and parse + if (fileCacheTxt != "") { + masterObj = JSON.parse(fileCacheTxt); + } + //Flog("Get and parse cache file. Done!"); + } catch(e) { + Flog("Can not get and parse cache file! " + e); + return false; + } + Flog("File init for " + ownerEmail + ". Done!"); + // catch exception + try { + // init domain users node + Flog("Check tasks for " + ownerEmail + "!"); + if (typeof masterObj["domainUsers"] === "undefined") {masterObj["domainUsers"] = {}}; + if (typeof masterObj["domainUsers"][ownerEmail] !== "undefined") { + // do not run query if already completed and lifetime is not reached + cLifeTime = Math.abs(new Date(masterObj["domainUsers"][ownerEmail]["queryFirstInitTime"]) - startTime) / 36e5; + if (masterObj["domainUsers"][ownerEmail]["queryComplete"] === true && (cLifeTime < queryLifeTimeHours)) { + Flog("Query complete. Done!"); + setDeleteTriggerById(masterObj["domainUsers"][ownerEmail]["contTriggerId"]); + // release lock + userLock.releaseLock(); + return true; // RETURN + } + if (masterObj["domainUsers"][ownerEmail]["queryComplete"] === true && (cLifeTime >= queryLifeTimeHours)) { + masterObj["domainUsers"][ownerEmail] = undefined, fileCacheTxt = ""; + } + Flog("Check tasks. Done!"); + } + // check cache file not blank or domain users node present or owner email node not present + if (fileCacheTxt == "" || typeof masterObj["domainUsers"][ownerEmail] === "undefined") { + Flog("Init user object."); + var filesOwnedByUser = null, contTokenObj = {}; + // init master object for non cached run or if new owner passed + masterObj["domainUsers"][ownerEmail] = { + "queryComplete" : false, + "queryFirstInitTime" : new Date(), + "queryEndSuccessTime" : null, + "queryElapsedTime" : null, + "filesAlreadyCached" : 0, // debug only + "chunksDone" : [], // debug only + //"lastChunkEndTime" : null, // debug only + //"lastChunkElapsedTime" : null, + "resumedRunCount" : 0, + "contToken" : null, + //"previousContToken" : null, // debug only + "contTokenCreationTime" : null, + "contTriggerId" : null, + "impToken" : null, + "userFiles" : [] + } + //fileCache = fileCache.setContent(JSON.stringify(masterObj)); // FILE CACHE WRITE + Flog("Init user object. Done!"); + } + } catch(e) { + Flog("Can not get and parse cache file! " + e); + return false; + } + // catch exception + try { + // get tokens for iterators + Flog("Run query."); + var userFilesIter = null, queryFirstInitTime = null; + var contTokenLifeTime = Math.abs(new Date(masterObj["domainUsers"][ownerEmail]["contTokenCreationTime"]) - startTime) / 36e5; + if (masterObj["domainUsers"][ownerEmail]["contToken"] === null || contTokenLifeTime >= 24) { + userFilesIter = DriveApp.searchFiles("trashed != true and not ('" + GVAR.TRANSFER_OWNERSHIP_TO + "' in owners) and '" + ownerEmail + "' in owners"); + /*userFilesIter = DriveApp.searchFiles("trashed != true and not ('" + GVAR.TRANSFER_OWNERSHIP_TO + "' in owners) and '" + ownerEmail + "' in owners " + + "and " + "(" + + "mimeType = 'application/vnd.google-apps.document'" + + " or " + + "mimeType = 'application/vnd.google-apps.drawing'" + + " or " + + "mimeType = 'application/vnd.google-apps.forms'" + + " or " + + "mimeType = 'application/vnd.google-apps.fusiontable'" + + " or " + + "mimeType = 'application/vnd.google-apps.presentation'" + + " or " + + "mimeType = 'application/vnd.google-apps.script'" + + " or " + + "mimeType = 'application/vnd.google-apps.sites'" + + " or " + + "mimeType = 'application/vnd.google-apps.spreadsheet'" + + ")" + ); // free domains only*/ + queryFirstInitTime = new Date(); + } else { + userFilesIter = DriveApp.continueFileIterator(masterObj["domainUsers"][ownerEmail]["contToken"]); + // delete continuation trigger + setDeleteTriggerById(masterObj["domainUsers"][ownerEmail]["contTriggerId"]); + queryFirstInitTime = masterObj["domainUsers"][ownerEmail]["queryFirstInitTime"]; + } + Flog("Run query. Done!"); + } catch(e) { + Flog("Can not initiate or call query! " + e); + return false; + } + // catch exception + try { + Flog("Loop objects."); + while (userFilesIter.hasNext()) { + // init vars + var fileObj = null, fileId = null, fileName = null; + loopCount++; + masterObj["domainUsers"][ownerEmail]["filesAlreadyCached"]++; + // iterate next + var fileObj = userFilesIter.next() + // get file basic info + fileId = fileObj.getId() + //fileName = fileObj.getName(); + var ancResult = false, fillArray = [], iterLevel = 0, ancArray = null, timeElapsed = null; + // get all drive object ancestors + //var timerA = new Date(); // debug only + ancResult = getFileHasAncestor(fileObj, fillArray, iterLevel); + //if (loopCount % cacheWriteChunkSize === 0) {Flog("Get ancestors" + "; count: " + loopCount + "; subtime elapsed: " + countdown(timerA, new Date(), countdown.DEFAULTS).toString())}; // debug only + //if (ancResult) {ancArray = fillArray} // debug only + fillArray = null; // null result array + // fill master object with search data + //masterObj["domainUsers"][ownerEmail]["userFiles"].push([fileId, fileName, ancResult, ancArray]); // debug only + if (ancResult || (returnNegatives && ancResult === null)) { + //masterObj["domainUsers"][ownerEmail]["userFiles"].push([fileId, fileName, ancResult]); // debug only + masterObj["domainUsers"][ownerEmail]["userFiles"].push(fileId); + } + //Utilities.sleep(4000); // debug only + // run in chunks + timeElapsed = countdown(startTime, new Date(), countdown.DEFAULTS).value; + if (loopCount % cacheWriteChunkSize === 0) { + // first run or first continuation run + if (loopCount / cacheWriteChunkSize === 1) {masterObj["domainUsers"][ownerEmail]["queryFirstInitTime"] = queryFirstInitTime}; + var timeElapsedHuman = countdown(startTime, new Date(), countdown.DEFAULTS).toString(); + //masterObj["domainUsers"][ownerEmail]["chunksDone"].push([loopCount, timeElapsed, timeElapsedHuman]); // debug only + masterObj["domainUsers"][ownerEmail]["chunksDone"].push([loopCount, timeElapsed]); // debug only + fileCache = fileCache.setContent(JSON.stringify(masterObj)); // FILE CACHE WRITE + Flog("Chunk " + loopCount + " done in " + timeElapsedHuman); + // cont token and previous cont token equal means failure + /*if (masterObj["domainUsers"][ownerEmail]["filesAlreadyCached"] > 10000) { + // prepare email variables and send transactional email + var mailVariablesObj = { + "~backgroundColor~" : "#ff7043", // #ff7043 = Deep Orange 400 + "~titleText~" : "Scan dir for " + ownerEmail + " exceeded limit file count", + "~headerMessage~" : "Scan dir for " + ownerEmail + " exceeded limit file count", + "~mainMessage~" : "This results in fatal error that may lead to infinite loop. If you see this email, contact your administrator!", + "~buttonText~" : "See generated cache file", + "~buttonUrl~" : "https://drive.google.com/open?id=" + cacheFileId + "&authuser=0", + "~footerText~" : "Do not reply to this email." + }; + var mailSendResult = setSendTransactionalEmail(GVAR.TRANSFER_OWNERSHIP_TO, mailVariablesObj); + var deleteResult = setDeleteAllTriggersOfHandlerFunction("setAllOwnerFilesCacheFile"); + return false; + break; + };*/ + } + // check max script time run and terminate with continuation token cache write + //if (timeElapsed >= 270000) { // 4.5 minutes; 6 minutes max. but 5 minutes trigger run interval + if (timeElapsed >= 252000) { // 4.2 minutes; 6 minutes max. but 5 minutes trigger run interval + //if (timeElapsed >= 242000) { // 4.04 minutes; 6 minutes max. but 5 minutes trigger run interval + //if (timeElapsed >= 235000) { // 3.92 minutes; 6 minutes max. but 5 minutes trigger run interval + //masterObj["domainUsers"][ownerEmail]["previousContToken"] = masterObj["domainUsers"][ownerEmail]["contToken"]; + var contToken = userFilesIter.getContinuationToken(); + masterObj["domainUsers"][ownerEmail]["contToken"] = contToken; + masterObj["domainUsers"][ownerEmail]["contTokenCreationTime"] = new Date(); + masterObj["domainUsers"][ownerEmail]["resumedRunCount"]++; + //masterObj["domainUsers"][ownerEmail]["filesAlreadyCached"] = loopCount; + // set continuation trigger + var contTrigger = ScriptApp.newTrigger("setDirScanToCacheFile").timeBased().everyMinutes(1).create(); + var contTriggerId = contTrigger.getUniqueId(); + masterObj["domainUsers"][ownerEmail]["contTriggerId"] = contTriggerId; + masterObj["domainUsers"][ownerEmail]["chunksDone"].push([masterObj["domainUsers"][ownerEmail]["contToken"], masterObj["domainUsers"][ownerEmail]["contTokenCreationTime"], cLifeTime]); // debug only + fileCache = fileCache.setContent(JSON.stringify(masterObj)); // FILE CACHE WRITE + Flog("Timeout trigger set. Script will continue!"); + // release lock + userLock.releaseLock(); + //throw new Error("Loop timeout but resume trigger has been set."); // ERROR + return false; // RETURN + } + } + Flog("Loop objects. Done!"); + } catch(e) { + Flog("Can not loop objects! " + e); + return false; + } + Flog("Finalize user section and inform."); + masterObj["domainUsers"][ownerEmail]["contTriggerId"] = null; + masterObj["domainUsers"][ownerEmail]["contToken"] = null; + masterObj["domainUsers"][ownerEmail]["contTokenCreationTime"] = null; + masterObj["domainUsers"][ownerEmail]["queryComplete"] = true; + masterObj["domainUsers"][ownerEmail]["queryEndSuccessTime"] = new Date(); + masterObj["domainUsers"][ownerEmail]["queryElapsedTime"] = countdown(new Date(masterObj["domainUsers"][ownerEmail]["queryFirstInitTime"]), masterObj["domainUsers"][ownerEmail]["queryEndSuccessTime"], countdown.DEFAULTS).toString(); + //masterObj["domainUsers"][ownerEmail]["lastChunkElapsedTime"] = countdown(new Date(masterObj["domainUsers"][ownerEmail]["lastChunkEndTime"]), new Date(), countdown.DEFAULTS).toString(); // debug only + fileCache = fileCache.setContent(JSON.stringify(masterObj)); // FILE CACHE WRITE + // prepare email variables and send transactional email + var mailVariablesObj = { + "~backgroundColor~" : "#ffb300", // #ffb300 = Amber 600 + "~titleText~" : "Scan dir for " + ownerEmail + " completed successfully", + "~headerMessage~" : "Scan dir for " + ownerEmail + " completed successfully", + "~mainMessage~" : "Scan dir for ownership transfer completed successfully in " + masterObj["domainUsers"][ownerEmail]["queryElapsedTime"] + " for actual owner " + ownerEmail + " with " + masterObj["domainUsers"][ownerEmail]["filesAlreadyCached"] + " cached files.", + "~buttonText~" : "See generated cache file", + "~buttonUrl~" : "https://drive.google.com/open?id=" + cacheFileId + "&authuser=0", + "~footerText~" : "Do not reply to this email." + }; + var mailSendResult = setSendTransactionalEmail(GVAR.TRANSFER_OWNERSHIP_TO, mailVariablesObj); // release lock + Flog("Finalize user section and inform. Done!"); + userLock.releaseLock(); + return true; // RETURN +} + +/** +* releases user lock if exists +* @returns {Bool} success +*/ +function setReleaseUserLock() { + var userLock = LockService.getUserLock(); + userLock.tryLock(10000); + if (!userLock.hasLock()) { + userLock.releaseLock(); + } + return true; +} + +/** +* sets ownership on given drive object (file, folder) via impersonization +* +* @param {String} driveObjectId drive object id (file, folder) +* @param {String} impersonatedUserEmail the email address of the user for which the application is requesting delegated access +* @param {String} transferOwnershipToEmail the email address to whom the ownership will be transfered +* @requires crypto (https://code.google.com/p/crypto-js/) +* @requires jsrsasign (http://kjur.github.io/jsrsasign/) +* @requires jwsjs (http://kjur.github.io/jsjws/) +* @requires countdownjs (http://countdownjs.org/) +* @returns {Bool} true if ownership transfered successfully +*/ +function setImpersonatedOwnership(driveObjectId, impersonatedUserEmail, transferOwnershipToEmail) { + // same ownership switch + if (impersonatedUserEmail === transferOwnershipToEmail) {return true}; + if (typeof driveObjectId === "undefined") {return false}; + // get impersonated oauth token + var oauthToken = getImpersonatedAccessToken(impersonatedUserEmail, GVAR.SERVICE_ACCOUNT_EMAIL, GVAR.SCOPES_SPACE_SEPARATED, GVAR.GOOGLE_DEV_CONSOLE_OAUTH_P12_BASE64, true); + // generate fetch data + var payloadObj = { + "role" : "owner", + "type" : "user", + "value" : transferOwnershipToEmail + }; + /*var payloadObj = {};*/ + //var payloadJson = encodeURIComponent(JSON.stringify(payloadObj)); // does not work + var payloadJson = JSON.stringify(payloadObj); + var fetchOpt = { + "method" : "post", + //"method" : "get", + "contentType" : "application/json", + "muteHttpExceptions" : false, + "headers" : { //http://en.wikipedia.org/wiki/List_of_HTTP_header_fields + "User-Agent" : "curl/7.38.0", // not documented but key element to get impersonization in google apps script to work + "Authorization" : "Bearer " + oauthToken + }, + "payload" : payloadJson + } + //var fetchUrl = "https://www.googleapis.com/drive/v2/permissionIds/" + transferOwnershipToEmail; // debug only + //var fetchUrl = "https://www.googleapis.com/drive/v2/files/" + driveObjectId + "/touch"; // debug only + var fetchUrl = "https://www.googleapis.com/drive/v2/files/" + driveObjectId + "/permissions"; + var fetchResponse = UrlFetchApp.fetch(fetchUrl, fetchOpt); + // parse response + if (fetchResponse.getResponseCode() == 200){ + //var responseContent = JSON.parse(fetchResponse.getContentText()); // debug only + return true; + } + if (fetchResponse.getResponseCode() == 500){ + Flog("Error 500 for drive object id: " + driveObjectId); + return false; + } + if (fetchResponse.getResponseCode() != 200 || fetchResponse.getResponseCode() != 500){ + throw new Error("Oops! Failed to parse response or invalid response code obtained."); + } +} + +/** +* returns impersonated oauth token +* +* @param {String} impersonatedUserEmail the email address of the user for which the application is requesting delegated access +* @param {String} serviceAccountEmail service account email address +* @param {String} scopesSpaceSeparated oauth scopes separated by space +* @param {String} oauthServiceAccountPrivateKeyBase64 service account p12 key generated from google developer console +* @param {Bool} cacheTokenFromToUserCache cache token from/to user cache switch +* @requires crypto (https://code.google.com/p/crypto-js/) +* @requires jsrsasign (http://kjur.github.io/jsrsasign/) +* @requires jwsjs (http://kjur.github.io/jsjws/) +* @requires countdownjs (http://countdownjs.org/) +* @returns {String|Bool} accessToken impersonated oauth access token or false if error +*/ +function getImpersonatedAccessToken(impersonatedUserEmail, serviceAccountEmail, scopesSpaceSeparated, oauthServiceAccountPrivateKeyBase64, cacheTokenFromToUserCache){ + // catch exception + try { + // get token from cache + var cacheHash = Utilities.computeDigest(Utilities.DigestAlgorithm.MD5, (serviceAccountEmail + "." + impersonatedUserEmail + "." + scopesSpaceSeparated), Utilities.Charset.US_ASCII); + var cachedToken = CacheService.getUserCache().get(cacheHash); + if (cachedToken && cacheTokenFromToUserCache) {return cachedToken;} + // log duration + //Flog("Time to check and get cache: " + countdown(startTime, new Date(), countdown.ALL).toString()); // debug only + } catch(e) { + Flog("Cano not get token from cache or cache token! " + e); + throw new Error("Oops! Failed to get token from cache or cache token."); + } + // catch exception + try { + // generate header + var jwtHeader = { + "alg" : "RS256", + "typ" : "JWT" + }; + var tStart = Math.floor((new Date().getTime()) / 1000); + var tStop = tStart + 3600; + // generate claim set payload + var jwtClaimSet = { + "iss" : serviceAccountEmail, + "sub" : impersonatedUserEmail, + "scope" : scopesSpaceSeparated, + "aud" : "https://accounts.google.com/o/oauth2/token", + "exp" : tStop, + "iat" : tStart + }; + var jwtHeaderBase64 = Utilities.base64Encode(JSON.stringify(jwtHeader)); + var jwtClaimBase64 = Utilities.base64Encode(JSON.stringify(jwtClaimSet)); + var jwtPemCert = Utilities.newBlob(Utilities.base64Decode(oauthServiceAccountPrivateKeyBase64, Utilities.Charset.UTF_8)).getDataAsString(); + } catch(e) { + Flog("Can not generate JWT variables! " + e); + throw new Error("Oops! Failed to generate JWT variables."); + } + // catch exception + try { + // generate jws + var jwsjsObj = new KJUR.jws.JWS(); + var rsaKey = new RSAKey(); + rsaKey.readPrivateKeyFromPEMString(jwtPemCert); + var jwsResult = rsaKey.signStringWithSHA256(jwtHeaderBase64 + "." + jwtClaimBase64); + var signedJwsResultBase64 = hex2b64(jwsResult); + // https://developers.google.com/accounts/docs/OAuth2ServiceAccount + var assertionStr = jwtHeaderBase64 + "." + jwtClaimBase64 + "." + signedJwsResultBase64; // {Base64url encoded header}.{Base64url encoded claim set}.{Base64url encoded signature} + // log duration + //Flog("Time to generate JWS: " + countdown(startTime, new Date(), countdown.ALL).toString()); // debug only + } catch(e) { + Flog("Can not generate JWS! " + e); + throw new Error("Oops! Failed to generate JWS."); + } + // catch exception + try { + // get token and parse response + var fetchOpt = { + "method" : "post", + "payload" : { + "grant_type" : "urn:ietf:params:oauth:grant-type:jwt-bearer", + //"access_type" : "offline", // not allowed for impersonization + "assertion" : assertionStr + }}; + var fetchResponse = UrlFetchApp.fetch("https://accounts.google.com/o/oauth2/token", fetchOpt); + // log duration + //Flog("Time to get token: " + countdown(startTime, new Date(), countdown.ALL).toString()); // debug only + } catch(e) { + Flog("Can not fetch oAuth 2.0 URL!" + e); + throw new Error("Oops! Failed to fetch oAuth 2.0 URL."); + } + // parse response + if(fetchResponse.getResponseCode() == 200){ + var responseContent = JSON.parse(fetchResponse.getContentText()); + } else { + throw new Error("Oops! Failed to parse response or invalid response code obtained."); + } + // catch exception + try { + // cache token + if (cacheTokenFromToUserCache) {CacheService.getUserCache().put(cacheHash, responseContent.access_token, 3550)}; + } catch(e) { + Flog("Can not put token to cache! " + e); + throw new Error("Oops! Failed to put token to cache."); + } + // return success + return responseContent.access_token; +} diff --git a/countdown.gs b/countdown.gs new file mode 100644 index 0000000..e728b25 --- /dev/null +++ b/countdown.gs @@ -0,0 +1,28 @@ +/* + countdown.js v2.3.4 http://countdownjs.org + Copyright (c)2006-2012 Stephen M. McKamey. + Licensed under The MIT License. +*/ +var module; +var countdown=function(module){var MILLISECONDS=1;var SECONDS=2;var MINUTES=4;var HOURS=8;var DAYS=16;var WEEKS=32;var MONTHS=64;var YEARS=128;var DECADES=256;var CENTURIES=512;var MILLENNIA=1024;var DEFAULTS=YEARS|MONTHS|DAYS|HOURS|MINUTES|SECONDS;var MILLISECONDS_PER_SECOND=1E3;var SECONDS_PER_MINUTE=60;var MINUTES_PER_HOUR=60;var HOURS_PER_DAY=24;var MILLISECONDS_PER_DAY=HOURS_PER_DAY*MINUTES_PER_HOUR*SECONDS_PER_MINUTE*MILLISECONDS_PER_SECOND;var DAYS_PER_WEEK=7;var MONTHS_PER_YEAR=12;var YEARS_PER_DECADE= +10;var DECADES_PER_CENTURY=10;var CENTURIES_PER_MILLENNIUM=10;var ceil=Math.ceil;var floor=Math.floor;function borrowMonths(ref,shift){var prevTime=ref.getTime();ref.setUTCMonth(ref.getUTCMonth()+shift);return Math.round((ref.getTime()-prevTime)/MILLISECONDS_PER_DAY)}function daysPerMonth(ref){var a=ref.getTime();var b=new Date(a);b.setUTCMonth(ref.getUTCMonth()+1);return Math.round((b.getTime()-a)/MILLISECONDS_PER_DAY)}function daysPerYear(ref){var a=ref.getTime();var b=new Date(a);b.setUTCFullYear(ref.getUTCFullYear()+ +1);return Math.round((b.getTime()-a)/MILLISECONDS_PER_DAY)}var LABEL_MILLISECONDS=0;var LABEL_SECONDS=1;var LABEL_MINUTES=2;var LABEL_HOURS=3;var LABEL_DAYS=4;var LABEL_WEEKS=5;var LABEL_MONTHS=6;var LABEL_YEARS=7;var LABEL_DECADES=8;var LABEL_CENTURIES=9;var LABEL_MILLENNIA=10;var LABELS_SINGLUAR;var LABELS_PLURAL;function plurality(value,unit){return value+" "+(value===1?LABELS_SINGLUAR[unit]:LABELS_PLURAL[unit])}var formatList;function Timespan(){}Timespan.prototype.toString=function(){var label= +formatList(this);var count=label.length;if(!count)return"";if(count>1)label[count-1]="and "+label[count-1];return label.join(", ")};Timespan.prototype.toHTML=function(tag){tag=tag||"span";var label=formatList(this);var count=label.length;if(!count)return"";for(var i=0;i"+label[i]+"";if(--count)label[count]="and "+label[count];return label.join(", ")};formatList=function(ts){var list=[];var value=ts.millennia;if(value)list.push(plurality(value,LABEL_MILLENNIA)); +value=ts.centuries;if(value)list.push(plurality(value,LABEL_CENTURIES));value=ts.decades;if(value)list.push(plurality(value,LABEL_DECADES));value=ts.years;if(value)list.push(plurality(value,LABEL_YEARS));value=ts.months;if(value)list.push(plurality(value,LABEL_MONTHS));value=ts.weeks;if(value)list.push(plurality(value,LABEL_WEEKS));value=ts.days;if(value)list.push(plurality(value,LABEL_DAYS));value=ts.hours;if(value)list.push(plurality(value,LABEL_HOURS));value=ts.minutes;if(value)list.push(plurality(value, +LABEL_MINUTES));value=ts.seconds;if(value)list.push(plurality(value,LABEL_SECONDS));value=ts.milliseconds;if(value)list.push(plurality(value,LABEL_MILLISECONDS));return list};function rippleRounded(ts,toUnit){switch(toUnit){case "seconds":if(ts.seconds!==SECONDS_PER_MINUTE||isNaN(ts.minutes))return;ts.minutes++;ts.seconds=0;case "minutes":if(ts.minutes!==MINUTES_PER_HOUR||isNaN(ts.hours))return;ts.hours++;ts.minutes=0;case "hours":if(ts.hours!==HOURS_PER_DAY||isNaN(ts.days))return;ts.days++;ts.hours= +0;case "days":if(ts.days!==DAYS_PER_WEEK||isNaN(ts.weeks))return;ts.weeks++;ts.days=0;case "weeks":if(ts.weeks!==daysPerMonth(ts.refMonth)/DAYS_PER_WEEK||isNaN(ts.months))return;ts.months++;ts.weeks=0;case "months":if(ts.months!==MONTHS_PER_YEAR||isNaN(ts.years))return;ts.years++;ts.months=0;case "years":if(ts.years!==YEARS_PER_DECADE||isNaN(ts.decades))return;ts.decades++;ts.years=0;case "decades":if(ts.decades!==DECADES_PER_CENTURY||isNaN(ts.centuries))return;ts.centuries++;ts.decades=0;case "centuries":if(ts.centuries!== +CENTURIES_PER_MILLENNIUM||isNaN(ts.millennia))return;ts.millennia++;ts.centuries=0}}function fraction(ts,frac,fromUnit,toUnit,conversion,digits){if(ts[fromUnit]>=0){frac+=ts[fromUnit];delete ts[fromUnit]}frac/=conversion;if(frac+1<=1)return 0;if(ts[toUnit]>=0){ts[toUnit]=+(ts[toUnit]+frac).toFixed(digits);rippleRounded(ts,toUnit);return 0}return frac}function fractional(ts,digits){var frac=fraction(ts,0,"milliseconds","seconds",MILLISECONDS_PER_SECOND,digits);if(!frac)return;frac=fraction(ts,frac, +"seconds","minutes",SECONDS_PER_MINUTE,digits);if(!frac)return;frac=fraction(ts,frac,"minutes","hours",MINUTES_PER_HOUR,digits);if(!frac)return;frac=fraction(ts,frac,"hours","days",HOURS_PER_DAY,digits);if(!frac)return;frac=fraction(ts,frac,"days","weeks",DAYS_PER_WEEK,digits);if(!frac)return;frac=fraction(ts,frac,"weeks","months",daysPerMonth(ts.refMonth)/DAYS_PER_WEEK,digits);if(!frac)return;frac=fraction(ts,frac,"months","years",daysPerYear(ts.refMonth)/daysPerMonth(ts.refMonth),digits);if(!frac)return; +frac=fraction(ts,frac,"years","decades",YEARS_PER_DECADE,digits);if(!frac)return;frac=fraction(ts,frac,"decades","centuries",DECADES_PER_CENTURY,digits);if(!frac)return;frac=fraction(ts,frac,"centuries","millennia",CENTURIES_PER_MILLENNIUM,digits);if(frac)throw new Error("Fractional unit overflow");}function ripple(ts){var x;if(ts.milliseconds<0){x=ceil(-ts.milliseconds/MILLISECONDS_PER_SECOND);ts.seconds-=x;ts.milliseconds+=x*MILLISECONDS_PER_SECOND}else if(ts.milliseconds>=MILLISECONDS_PER_SECOND){ts.seconds+= +floor(ts.milliseconds/MILLISECONDS_PER_SECOND);ts.milliseconds%=MILLISECONDS_PER_SECOND}if(ts.seconds<0){x=ceil(-ts.seconds/SECONDS_PER_MINUTE);ts.minutes-=x;ts.seconds+=x*SECONDS_PER_MINUTE}else if(ts.seconds>=SECONDS_PER_MINUTE){ts.minutes+=floor(ts.seconds/SECONDS_PER_MINUTE);ts.seconds%=SECONDS_PER_MINUTE}if(ts.minutes<0){x=ceil(-ts.minutes/MINUTES_PER_HOUR);ts.hours-=x;ts.minutes+=x*MINUTES_PER_HOUR}else if(ts.minutes>=MINUTES_PER_HOUR){ts.hours+=floor(ts.minutes/MINUTES_PER_HOUR);ts.minutes%= +MINUTES_PER_HOUR}if(ts.hours<0){x=ceil(-ts.hours/HOURS_PER_DAY);ts.days-=x;ts.hours+=x*HOURS_PER_DAY}else if(ts.hours>=HOURS_PER_DAY){ts.days+=floor(ts.hours/HOURS_PER_DAY);ts.hours%=HOURS_PER_DAY}while(ts.days<0){ts.months--;ts.days+=borrowMonths(ts.refMonth,1)}if(ts.days>=DAYS_PER_WEEK){ts.weeks+=floor(ts.days/DAYS_PER_WEEK);ts.days%=DAYS_PER_WEEK}if(ts.months<0){x=ceil(-ts.months/MONTHS_PER_YEAR);ts.years-=x;ts.months+=x*MONTHS_PER_YEAR}else if(ts.months>=MONTHS_PER_YEAR){ts.years+=floor(ts.months/ +MONTHS_PER_YEAR);ts.months%=MONTHS_PER_YEAR}if(ts.years>=YEARS_PER_DECADE){ts.decades+=floor(ts.years/YEARS_PER_DECADE);ts.years%=YEARS_PER_DECADE;if(ts.decades>=DECADES_PER_CENTURY){ts.centuries+=floor(ts.decades/DECADES_PER_CENTURY);ts.decades%=DECADES_PER_CENTURY;if(ts.centuries>=CENTURIES_PER_MILLENNIUM){ts.millennia+=floor(ts.centuries/CENTURIES_PER_MILLENNIUM);ts.centuries%=CENTURIES_PER_MILLENNIUM}}}}function pruneUnits(ts,units,max,digits){var count=0;if(!(units&MILLENNIA)||count>=max){ts.centuries+= +ts.millennia*CENTURIES_PER_MILLENNIUM;delete ts.millennia}else if(ts.millennia)count++;if(!(units&CENTURIES)||count>=max){ts.decades+=ts.centuries*DECADES_PER_CENTURY;delete ts.centuries}else if(ts.centuries)count++;if(!(units&DECADES)||count>=max){ts.years+=ts.decades*YEARS_PER_DECADE;delete ts.decades}else if(ts.decades)count++;if(!(units&YEARS)||count>=max){ts.months+=ts.years*MONTHS_PER_YEAR;delete ts.years}else if(ts.years)count++;if(!(units&MONTHS)||count>=max){if(ts.months)ts.days+=borrowMonths(ts.refMonth, +ts.months);delete ts.months;if(ts.days>=DAYS_PER_WEEK){ts.weeks+=floor(ts.days/DAYS_PER_WEEK);ts.days%=DAYS_PER_WEEK}}else if(ts.months)count++;if(!(units&WEEKS)||count>=max){ts.days+=ts.weeks*DAYS_PER_WEEK;delete ts.weeks}else if(ts.weeks)count++;if(!(units&DAYS)||count>=max){ts.hours+=ts.days*HOURS_PER_DAY;delete ts.days}else if(ts.days)count++;if(!(units&HOURS)||count>=max){ts.minutes+=ts.hours*MINUTES_PER_HOUR;delete ts.hours}else if(ts.hours)count++;if(!(units&MINUTES)||count>=max){ts.seconds+= +ts.minutes*SECONDS_PER_MINUTE;delete ts.minutes}else if(ts.minutes)count++;if(!(units&SECONDS)||count>=max){ts.milliseconds+=ts.seconds*MILLISECONDS_PER_SECOND;delete ts.seconds}else if(ts.seconds)count++;if(!(units&MILLISECONDS)||count>=max)fractional(ts,digits)}function populate(ts,start,end,units,max,digits){ts.start=start;ts.end=end;ts.units=units;ts.value=end.getTime()-start.getTime();if(ts.value<0){var temp=end;end=start;start=temp}ts.refMonth=new Date(start.getFullYear(),start.getMonth(),15); +try{ts.millennia=0;ts.centuries=0;ts.decades=0;ts.years=end.getUTCFullYear()-start.getUTCFullYear();ts.months=end.getUTCMonth()-start.getUTCMonth();ts.weeks=0;ts.days=end.getUTCDate()-start.getUTCDate();ts.hours=end.getUTCHours()-start.getUTCHours();ts.minutes=end.getUTCMinutes()-start.getUTCMinutes();ts.seconds=end.getUTCSeconds()-start.getUTCSeconds();ts.milliseconds=end.getUTCMilliseconds()-start.getUTCMilliseconds();ripple(ts);pruneUnits(ts,units,max,digits)}finally{delete ts.refMonth}return ts} +function getDelay(units){if(units&MILLISECONDS)return MILLISECONDS_PER_SECOND/30;if(units&SECONDS)return MILLISECONDS_PER_SECOND;if(units&MINUTES)return MILLISECONDS_PER_SECOND*SECONDS_PER_MINUTE;if(units&HOURS)return MILLISECONDS_PER_SECOND*SECONDS_PER_MINUTE*MINUTES_PER_HOUR;if(units&DAYS)return MILLISECONDS_PER_SECOND*SECONDS_PER_MINUTE*MINUTES_PER_HOUR*HOURS_PER_DAY;return MILLISECONDS_PER_SECOND*SECONDS_PER_MINUTE*MINUTES_PER_HOUR*HOURS_PER_DAY*DAYS_PER_WEEK}function countdown(start,end,units, +max,digits){var callback;units=+units||DEFAULTS;max=max>0?max:NaN;digits=digits>0?digits<20?Math.round(digits):20:0;if("function"===typeof start){callback=start;start=null}else if(!(start instanceof Date))start=start!==null&&isFinite(start)?new Date(start):null;if("function"===typeof end){callback=end;end=null}else if(!(end instanceof Date))end=end!==null&&isFinite(end)?new Date(end):null;if(!start&&!end)return new Timespan;if(!callback)return populate(new Timespan,(start||new Date),(end||new Date), +units,max,digits);var delay=getDelay(units),timerId,fn=function(){callback(populate(new Timespan,(start||new Date),(end||new Date),units,max,digits),timerId)};fn();return timerId=setInterval(fn,delay)}countdown.MILLISECONDS=MILLISECONDS;countdown.SECONDS=SECONDS;countdown.MINUTES=MINUTES;countdown.HOURS=HOURS;countdown.DAYS=DAYS;countdown.WEEKS=WEEKS;countdown.MONTHS=MONTHS;countdown.YEARS=YEARS;countdown.DECADES=DECADES;countdown.CENTURIES=CENTURIES;countdown.MILLENNIA=MILLENNIA;countdown.DEFAULTS= +DEFAULTS;countdown.ALL=MILLENNIA|CENTURIES|DECADES|YEARS|MONTHS|WEEKS|DAYS|HOURS|MINUTES|SECONDS|MILLISECONDS;var setLabels=countdown.setLabels=function(singular,plural){singular=singular||[];if(singular.split)singular=singular.split("|");plural=plural||[];if(plural.split)plural=plural.split("|");for(var i=LABEL_MILLISECONDS;i<=LABEL_MILLENNIA;i++){LABELS_SINGLUAR[i]=singular[i]||LABELS_SINGLUAR[i];LABELS_PLURAL[i]=plural[i]||LABELS_PLURAL[i]}};var resetLabels=countdown.resetLabels=function(){LABELS_SINGLUAR= +"millisecond|second|minute|hour|day|week|month|year|decade|century|millennium".split("|");LABELS_PLURAL="milliseconds|seconds|minutes|hours|days|weeks|months|years|decades|centuries|millennia".split("|")};resetLabels();return countdown}(module); diff --git a/crypto.gs b/crypto.gs new file mode 100644 index 0000000..f072f30 --- /dev/null +++ b/crypto.gs @@ -0,0 +1,57 @@ +/** @preserve +CryptoJS v3.1.2 +code.google.com/p/crypto-js +(c) 2009-2013 by Jeff Mott. All rights reserved. +code.google.com/p/crypto-js/wiki/License +*/ + +/** @preserve +(c) 2012 by Cedric Mesnil. All rights reserved. +Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: + - Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. + - Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +*/ + +// https://crypto-js.googlecode.com/svn-history/r668/branches/3.x/src/core.js +var CryptoJS=CryptoJS||function(Math,undefined){var C={};var C_lib=C.lib={};var Base=C_lib.Base=function(){function F(){}return{extend:function(overrides){F.prototype=this;var subtype=new F;if(overrides)subtype.mixIn(overrides);if(!subtype.hasOwnProperty("init"))subtype.init=function(){subtype.$super.init.apply(this,arguments)};subtype.init.prototype=subtype;subtype.$super=this;return subtype},create:function(){var instance=this.extend();instance.init.apply(instance,arguments);return instance},init:function(){}, +mixIn:function(properties){for(var propertyName in properties)if(properties.hasOwnProperty(propertyName))this[propertyName]=properties[propertyName];if(properties.hasOwnProperty("toString"))this.toString=properties.toString},clone:function(){return this.init.prototype.extend(this)}}}();var WordArray=C_lib.WordArray=Base.extend({init:function(words,sigBytes){words=this.words=words||[];if(sigBytes!=undefined)this.sigBytes=sigBytes;else this.sigBytes=words.length*4},toString:function(encoder){return(encoder|| +Hex).stringify(this)},concat:function(wordArray){var thisWords=this.words;var thatWords=wordArray.words;var thisSigBytes=this.sigBytes;var thatSigBytes=wordArray.sigBytes;this.clamp();if(thisSigBytes%4)for(var i=0;i>>2]>>>24-i%4*8&255;thisWords[thisSigBytes+i>>>2]|=thatByte<<24-(thisSigBytes+i)%4*8}else for(var i=0;i>>2]=thatWords[i>>>2];this.sigBytes+=thatSigBytes;return this},clamp:function(){var words=this.words; +var sigBytes=this.sigBytes;words[sigBytes>>>2]&=4294967295<<32-sigBytes%4*8;words.length=Math.ceil(sigBytes/4)},clone:function(){var clone=Base.clone.call(this);clone.words=this.words.slice(0);return clone},random:function(nBytes){var words=[];for(var i=0;i>>2]>>>24-i%4*8&255;hexChars.push((bite>>>4).toString(16));hexChars.push((bite&15).toString(16))}return hexChars.join("")},parse:function(hexStr){var hexStrLength=hexStr.length;var words=[];for(var i=0;i>>3]|=parseInt(hexStr.substr(i,2),16)<<24-i%8*4;return new WordArray.init(words,hexStrLength/2)}};var Latin1=C_enc.Latin1={stringify:function(wordArray){var words=wordArray.words;var sigBytes=wordArray.sigBytes;var latin1Chars=[];for(var i= +0;i>>2]>>>24-i%4*8&255;latin1Chars.push(String.fromCharCode(bite))}return latin1Chars.join("")},parse:function(latin1Str){var latin1StrLength=latin1Str.length;var words=[];for(var i=0;i>>2]|=(latin1Str.charCodeAt(i)&255)<<24-i%4*8;return new WordArray.init(words,latin1StrLength)}};var Utf8=C_enc.Utf8={stringify:function(wordArray){try{return decodeURIComponent(escape(Latin1.stringify(wordArray)))}catch(e){throw new Error("Malformed UTF-8 data"); +}},parse:function(utf8Str){return Latin1.parse(unescape(encodeURIComponent(utf8Str)))}};var BufferedBlockAlgorithm=C_lib.BufferedBlockAlgorithm=Base.extend({reset:function(){this._data=new WordArray.init;this._nDataBytes=0},_append:function(data){if(typeof data=="string")data=Utf8.parse(data);this._data.concat(data);this._nDataBytes+=data.sigBytes},_process:function(doFlush){var data=this._data;var dataWords=data.words;var dataSigBytes=data.sigBytes;var blockSize=this.blockSize;var blockSizeBytes= +blockSize*4;var nBlocksReady=dataSigBytes/blockSizeBytes;if(doFlush)nBlocksReady=Math.ceil(nBlocksReady);else nBlocksReady=Math.max((nBlocksReady|0)-this._minBufferSize,0);var nWordsReady=nBlocksReady*blockSize;var nBytesReady=Math.min(nWordsReady*4,dataSigBytes);if(nWordsReady){for(var offset=0;offset>>31}var t=(a<<5|a>>> +27)+e+W[i];if(i<20)t+=(b&c|~b&d)+1518500249;else if(i<40)t+=(b^c^d)+1859775393;else if(i<60)t+=(b&c|b&d|c&d)-1894007588;else t+=(b^c^d)-899497514;e=d;d=c;c=b<<30|b>>>2;b=a;a=t}H[0]=H[0]+a|0;H[1]=H[1]+b|0;H[2]=H[2]+c|0;H[3]=H[3]+d|0;H[4]=H[4]+e|0},_doFinalize:function(){var data=this._data;var dataWords=data.words;var nBitsTotal=this._nDataBytes*8;var nBitsLeft=data.sigBytes*8;dataWords[nBitsLeft>>>5]|=128<<24-nBitsLeft%32;dataWords[(nBitsLeft+64>>>9<<4)+14]=Math.floor(nBitsTotal/4294967296);dataWords[(nBitsLeft+ +64>>>9<<4)+15]=nBitsTotal;data.sigBytes=dataWords.length*4;this._process();return this._hash},clone:function(){var clone=Hasher.clone.call(this);clone._hash=this._hash.clone();return clone}});C.SHA1=Hasher._createHelper(SHA1);C.HmacSHA1=Hasher._createHmacHelper(SHA1)})(); + +// https://crypto-js.googlecode.com/svn-history/r668/branches/3.x/src/sha256.js +(function(Math){var C=CryptoJS;var C_lib=C.lib;var WordArray=C_lib.WordArray;var Hasher=C_lib.Hasher;var C_algo=C.algo;var H=[];var K=[];(function(){function isPrime(n){var sqrtN=Math.sqrt(n);for(var factor=2;factor<=sqrtN;factor++)if(!(n%factor))return false;return true}function getFractionalBits(n){return(n-(n|0))*4294967296|0}var n=2;var nPrime=0;while(nPrime<64){if(isPrime(n)){if(nPrime<8)H[nPrime]=getFractionalBits(Math.pow(n,1/2));K[nPrime]=getFractionalBits(Math.pow(n,1/3));nPrime++}n++}})(); +var W=[];var SHA256=C_algo.SHA256=Hasher.extend({_doReset:function(){this._hash=new WordArray.init(H.slice(0))},_doProcessBlock:function(M,offset){var H=this._hash.words;var a=H[0];var b=H[1];var c=H[2];var d=H[3];var e=H[4];var f=H[5];var g=H[6];var h=H[7];for(var i=0;i<64;i++){if(i<16)W[i]=M[offset+i]|0;else{var gamma0x=W[i-15];var gamma0=(gamma0x<<25|gamma0x>>>7)^(gamma0x<<14|gamma0x>>>18)^gamma0x>>>3;var gamma1x=W[i-2];var gamma1=(gamma1x<<15|gamma1x>>>17)^(gamma1x<<13|gamma1x>>>19)^gamma1x>>> +10;W[i]=gamma0+W[i-7]+gamma1+W[i-16]}var ch=e&f^~e&g;var maj=a&b^a&c^b&c;var sigma0=(a<<30|a>>>2)^(a<<19|a>>>13)^(a<<10|a>>>22);var sigma1=(e<<26|e>>>6)^(e<<21|e>>>11)^(e<<7|e>>>25);var t1=h+sigma1+ch+K[i]+W[i];var t2=sigma0+maj;h=g;g=f;f=e;e=d+t1|0;d=c;c=b;b=a;a=t1+t2|0}H[0]=H[0]+a|0;H[1]=H[1]+b|0;H[2]=H[2]+c|0;H[3]=H[3]+d|0;H[4]=H[4]+e|0;H[5]=H[5]+f|0;H[6]=H[6]+g|0;H[7]=H[7]+h|0},_doFinalize:function(){var data=this._data;var dataWords=data.words;var nBitsTotal=this._nDataBytes*8;var nBitsLeft= +data.sigBytes*8;dataWords[nBitsLeft>>>5]|=128<<24-nBitsLeft%32;dataWords[(nBitsLeft+64>>>9<<4)+14]=Math.floor(nBitsTotal/4294967296);dataWords[(nBitsLeft+64>>>9<<4)+15]=nBitsTotal;data.sigBytes=dataWords.length*4;this._process();return this._hash},clone:function(){var clone=Hasher.clone.call(this);clone._hash=this._hash.clone();return clone}});C.SHA256=Hasher._createHelper(SHA256);C.HmacSHA256=Hasher._createHmacHelper(SHA256)})(Math); + +// https://crypto-js.googlecode.com/svn-history/r668/branches/3.x/src/x64-core.js +(function(undefined){var C=CryptoJS;var C_lib=C.lib;var Base=C_lib.Base;var X32WordArray=C_lib.WordArray;var C_x64=C.x64={};var X64Word=C_x64.Word=Base.extend({init:function(high,low){this.high=high;this.low=low}});var X64WordArray=C_x64.WordArray=Base.extend({init:function(words,sigBytes){words=this.words=words||[];if(sigBytes!=undefined)this.sigBytes=sigBytes;else this.sigBytes=words.length*8},toX32:function(){var x64Words=this.words;var x64WordsLength=x64Words.length;var x32Words=[];for(var i= +0;i>>1|gamma0xl<<31)^(gamma0xh>>>8|gamma0xl<<24)^gamma0xh>>>7;var gamma0l=(gamma0xl>>>1|gamma0xh<< +31)^(gamma0xl>>>8|gamma0xh<<24)^(gamma0xl>>>7|gamma0xh<<25);var gamma1x=W[i-2];var gamma1xh=gamma1x.high;var gamma1xl=gamma1x.low;var gamma1h=(gamma1xh>>>19|gamma1xl<<13)^(gamma1xh<<3|gamma1xl>>>29)^gamma1xh>>>6;var gamma1l=(gamma1xl>>>19|gamma1xh<<13)^(gamma1xl<<3|gamma1xh>>>29)^(gamma1xl>>>6|gamma1xh<<26);var Wi7=W[i-7];var Wi7h=Wi7.high;var Wi7l=Wi7.low;var Wi16=W[i-16];var Wi16h=Wi16.high;var Wi16l=Wi16.low;var Wil=gamma0l+Wi7l;var Wih=gamma0h+Wi7h+(Wil>>>0>>0?1:0);var Wil=Wil+gamma1l; +var Wih=Wih+gamma1h+(Wil>>>0>>0?1:0);var Wil=Wil+Wi16l;var Wih=Wih+Wi16h+(Wil>>>0>>0?1:0);Wi.high=Wih;Wi.low=Wil}var chh=eh&fh^~eh&gh;var chl=el&fl^~el≷var majh=ah&bh^ah&ch^bh&ch;var majl=al&bl^al&cl^bl&cl;var sigma0h=(ah>>>28|al<<4)^(ah<<30|al>>>2)^(ah<<25|al>>>7);var sigma0l=(al>>>28|ah<<4)^(al<<30|ah>>>2)^(al<<25|ah>>>7);var sigma1h=(eh>>>14|el<<18)^(eh>>>18|el<<14)^(eh<<23|el>>>9);var sigma1l=(el>>>14|eh<<18)^(el>>>18|eh<<14)^(el<<23|eh>>>9);var Ki=K[i];var Kih=Ki.high;var Kil= +Ki.low;var t1l=hl+sigma1l;var t1h=hh+sigma1h+(t1l>>>0>>0?1:0);var t1l=t1l+chl;var t1h=t1h+chh+(t1l>>>0>>0?1:0);var t1l=t1l+Kil;var t1h=t1h+Kih+(t1l>>>0>>0?1:0);var t1l=t1l+Wil;var t1h=t1h+Wih+(t1l>>>0>>0?1:0);var t2l=sigma0l+majl;var t2h=sigma0h+majh+(t2l>>>0>>0?1:0);hh=gh;hl=gl;gh=fh;gl=fl;fh=eh;fl=el;el=dl+t1l|0;eh=dh+t1h+(el>>>0
>>0?1:0)|0;dh=ch;dl=cl;ch=bh;cl=bl;bh=ah;bl=al;al=t1l+t2l|0;ah=t1h+t2h+(al>>>0>>0?1:0)|0}H0l=H0.low=H0l+al;H0.high=H0h+ah+(H0l>>>0< +al>>>0?1:0);H1l=H1.low=H1l+bl;H1.high=H1h+bh+(H1l>>>0>>0?1:0);H2l=H2.low=H2l+cl;H2.high=H2h+ch+(H2l>>>0>>0?1:0);H3l=H3.low=H3l+dl;H3.high=H3h+dh+(H3l>>>0
>>0?1:0);H4l=H4.low=H4l+el;H4.high=H4h+eh+(H4l>>>0>>0?1:0);H5l=H5.low=H5l+fl;H5.high=H5h+fh+(H5l>>>0>>0?1:0);H6l=H6.low=H6l+gl;H6.high=H6h+gh+(H6l>>>0>>0?1:0);H7l=H7.low=H7l+hl;H7.high=H7h+hh+(H7l>>>0>>0?1:0)},_doFinalize:function(){var data=this._data;var dataWords=data.words;var nBitsTotal=this._nDataBytes*8;var nBitsLeft= +data.sigBytes*8;dataWords[nBitsLeft>>>5]|=128<<24-nBitsLeft%32;dataWords[(nBitsLeft+128>>>10<<5)+30]=Math.floor(nBitsTotal/4294967296);dataWords[(nBitsLeft+128>>>10<<5)+31]=nBitsTotal;data.sigBytes=dataWords.length*4;this._process();var hash=this._hash.toX32();return hash},clone:function(){var clone=Hasher.clone.call(this);clone._hash=this._hash.clone();return clone},blockSize:1024/32});C.SHA512=Hasher._createHelper(SHA512);C.HmacSHA512=Hasher._createHmacHelper(SHA512)})(); diff --git a/globals.gs b/globals.gs new file mode 100644 index 0000000..fe1cbd7 --- /dev/null +++ b/globals.gs @@ -0,0 +1,68 @@ +function setGlobalVariableToScriptProperties() { + var scriptProperties = PropertiesService.getScriptProperties(); + scriptProperties.setProperty("GVAR", JSON.stringify(GVAR)); +} + +function setDeleteAllScriptProperties() { + var scriptProperties = PropertiesService.getScriptProperties().deleteAllProperties(); +} + +/** +* global variable object contains all global variables +* @type {Object} +* @const +*/ +var GVAR = { + // script name for various use + "SCRIPT_NAME" : "Transfer Ownership", // used by frontend only + + // email address of the user for which the application is requesting delegated access + "IMPERSONATED_USER_EMAIL" : "user_name.surname@domain.tld", // debug only + + // id of the drive object for debug and testing + "IMPERSONATED_USER_DRIVE_OBJECT_ID" : "SOME_FILE_ID", // debug only + + // oauth scopes separated by space as in https://developers.google.com/drive/web/scopes for drive + // needs full access to all files in the user's drive + "SCOPES_SPACE_SEPARATED" : "https://www.googleapis.com/auth/drive", // change for production + + // service account email address generated from google developer console > apis & auth > credentials > oauth > create new client id > service account + "SERVICE_ACCOUNT_EMAIL" : "service_account_email@developer.gserviceaccount.com", // change for production + + // service account p12 key generated from google developer console > apis & auth > credentials > oauth > create new client id > service account + // transformed to base64 pem via "openssl pkcs12 -in ~/certfilename.p12 -nodes | openssl rsa | base64 > ~/certfilename.pem.b64" + "GOOGLE_DEV_CONSOLE_OAUTH_P12_BASE64" : "THIS_IS_JUST_TEMPLATE_fg4897gf98457gf984g7f8947gf984g75f8947g5f98475gf98475gf89347g5f893475gf98347gf93487gf8945gf73489gf74875fg984f7g9483gf89437gf98347gf8934gf798457gf8947gf9347gf89347gf8947g5f98743g5f89743g5f8934g75f897g4895fg734985f7g34895fgf93475gf49f7g94835gf4985f7g845gf48957gf4985gf7f49385gf794857gf4943758fg9345fg48975gf948375gf49857gf8347g5f934875gf4897g5f84957gf475gf894357gf89435gf49875gf48975gf4785gf938457gf934875gf934875gf8437g5f94785fg8934gf89437gf934857gf89437gf89473g5f9847g5f894375gf89475gf894375gf8947g5f8947gf83475gf983475gf893475gf8934f89437g5f893475gf98347g5f98437gf589437g5f89347g5f8947g5f8947g5f89437g5f9834gf89473gf89347g5f8934g7589f7g49875gf89347gf89437g5f9847gf589437g5f89734gf89734g985gf73489gf98347gf8943gf89475gf834g5f87g34985f7g43897gf89347gf89345gf8574gf983475gf98347f5g8934g7f8934gf89347g5f89347g5f98347g5f89473g5f89734g5f98g34589f7g4589f7g98457gf98347g5f89347gf893475gf89347gf89347g5ff34f7y94837yf89347yf98437y5f8734y5f89473y9f83y4895f7y34987yf8347y5f98347yf98347yf98347y5f8974y35f89y3498f7y893475yf98347yf893457yf984375yf98347y5f98743y59f87y4398fy34895f7y98457yf893457y98f7y345985f7y89347yf89347y598fy3498f7y34897y5f893477fyf98_THIS_IS_JUST_TEMPLATE=", // change for production + + // script url id + "SCRIPT_URL_ID" : "14t54yXwWL92IellyMjwhJtRgqPIznFn4q18XmLFWkPq-638cKaVkNn_6", // change for production + + // script project key + "SCRIPT_PROJECT_KEY" : "OfYRv8X9K-VuJTzw32qfU0xkPvQ8bevdh", // change for productions + + // script web service key + "WEB_SERVICE_KEY" : "C4A4E45C877B17AA97CCC642D98C406B", // change for production + + // email address of the user to whom transfer ownership + "TRANSFER_OWNERSHIP_TO" : "admin_name.surname@domain.tld", // change for production + + // domain of google apps to work with + "DOMAIN_OF_GOOGLE_APPS" : "domain.tld", // change for production + + // dir scan cache file lifetime in hours + "CACHE_FILE_LIFETIME" : 96, // change for production + + // root folder id for ownership transfer + "ROOT_FOLDER_ID" : "SOME_FOLDER_ID", // change for production + + // cache folder id to store script data as cache + "CACHE_FOLDER_ID" : "SOME_FOLDER_ID", // change for production + + // log file id + "LOG_FILE_ID" : "SOME_FILE_ID" // change for production + + // mail ui file name + "MAIL_UI_FILENAME" : "mailui.html", // change for production + + // webservice ui file name + "WEBSERVICE_UI_FILENAME" : "webui.html" // change for production +}; diff --git a/helpers.gs b/helpers.gs new file mode 100644 index 0000000..50e9503 --- /dev/null +++ b/helpers.gs @@ -0,0 +1,288 @@ +/** +* sends transactional email +* +* @param {String} recipientEmailAddress recipient email address +* @param {String} mailVariablesObj mail variables object +* @requires MailUi.html file +* @returns {Bool} success +*/ +function setSendTransactionalEmail(recipientEmailAddress, mailVariablesObj){ + recipientEmailAddress = (recipientEmailAddress || GVAR.TRANSFER_OWNERSHIP_TO); + // #2baf2b = Green 400, #738ffe = Blue 400, #ffb300 = Amber 600, #ff7043 = Deep Orange 400; always use black text - see http://www.google.com/design/spec/style/color.html#color-ui-color-palette + mailVariablesObj = (mailVariablesObj || { + "~backgroundColor~" : "#ff7043", // #ff7043 = Deep Orange 400 + "~titleText~" : "Fatal error", + "~headerMessage~" : "Fatal error", + "~mainMessage~" : "Fatal error", + "~buttonText~" : "Contact your administrator.", + "~buttonUrl~" : "https://drive.google.com/", + "~footerText~" : "Do not reply to this email." + }); + // get html temlpate + var aVar = null, htmlBody = null, plainBody = ""; + var htmlBody = HtmlService.createHtmlOutputFromFile(GVAR.MAIL_UI_FILENAME).getContent(); + // get all email variables and replace with data values + var mailVariables = htmlBody.match(/([~])(?:(?=(\\?))\2.)*?\1/g); + if (mailVariables !== null) { + for (var i = 0, lenI = mailVariables.length; i < lenI; i++) { + htmlBody = htmlBody.replace(mailVariables[i], mailVariablesObj[mailVariables[i]]); + plainBody = htmlBody.replace(mailVariables[i], mailVariablesObj[mailVariables[i]]); + } + } + // send email + var gmailAppObj = GmailApp.sendEmail(recipientEmailAddress, + mailVariablesObj["~titleText~"], + plainBody, { + htmlBody : htmlBody, + //bcc: "name.surname@domain.tld", // debug only + noReply : true}); + return true; +} + +/** +* gets total number of files shared to account +* +* @returns {Number} file count +*/ +function getUserSharedFileCount(ownerEmail) { + //ownerEmail = (ownerEmail || "name.surname@domain.tld"); // debug only + var fileIterator = null, file = null, i = 0, startTime = new Date(); + fileIterator = DriveApp.searchFiles("trashed != true and not ('" + GVAR.TRANSFER_OWNERSHIP_TO + "' in owners) and '" + ownerEmail + "' in owners"); + /*fileIterator = DriveApp.searchFiles("trashed != true and not ('" + GVAR.TRANSFER_OWNERSHIP_TO + "' in owners) and '" + ownerEmail + "' in owners " + + "and " + "(" + + "mimeType = 'application/vnd.google-apps.document'" + + " or " + + "mimeType = 'application/vnd.google-apps.drawing'" + + " or " + + "mimeType = 'application/vnd.google-apps.forms'" + + " or " + + "mimeType = 'application/vnd.google-apps.fusiontable'" + + " or " + + "mimeType = 'application/vnd.google-apps.presentation'" + + " or " + + "mimeType = 'application/vnd.google-apps.script'" + + " or " + + "mimeType = 'application/vnd.google-apps.sites'" + + " or " + + "mimeType = 'application/vnd.google-apps.spreadsheet'" + + ")" + ); // free domains only*/ + while (fileIterator.hasNext()) { + file = fileIterator.next(); + i++; + } + var elapsedTime = countdown(startTime, new Date(), countdown.DEFAULTS).toString(); + // prepare email variables and send transactional email + var mailVariablesObj = { + "~backgroundColor~" : "#738ffe", // #738ffe = Blue 400 + "~titleText~" : "File count " + ownerEmail + " " + i + " in " + elapsedTime, + "~headerMessage~" : "File count " + ownerEmail + " " + i + " in " + elapsedTime, + "~mainMessage~" : "File count " + ownerEmail + " " + i + " in " + elapsedTime, + "~buttonText~" : "Stay relaxed", + "~buttonUrl~" : "https://drive.google.com/", + "~footerText~" : "Do not reply to this email." + }; + var mailSendResult = setSendTransactionalEmail(GVAR.TRANSFER_OWNERSHIP_TO, mailVariablesObj); + return i; +} + +/** +* gets all drive object (file / folder) ancestors and results in true if root folder is ancestor +* @param {File|Folder} driveObj drive object id (file, folder) +* @param {Array} fillArray array to fill with ancestors +* @param {Number} iterLevel current iteration level +* @returns {Bool|Null} true if root folder found in ancestors | null if not present +*/ +function getFileHasAncestor(driveObj, fillArray, iterLevel){ + // process all parents + var parentIter = driveObj.getParents(); + while (parentIter.hasNext()) { + var parentFolder = parentIter.next(); + var parentFolderId = parentFolder.getId(); + fillArray.push([parentFolderId, iterLevel]); + // drive object has root folder in ancestors + if (parentFolderId === GVAR.ROOT_FOLDER_ID) {return true}; + // recursive call + if (getFileHasAncestor(parentFolder, fillArray, iterLevel)) {return true}; + } +} + +/** +* gets cache file id from script properties or settles new cache file and writes to script properties +* @param {Bool} settleNewCacheFile switch to settle new cache file +* @param {String} cacheFilePurpose cache file purpose switch +* @returns {String} cache file id +*/ +function getCacheFileId(settleNewCacheFile, cacheFilePurpose) { + // defaults + if (arguments.length === 0) {settleNewCacheFile = true, cacheFilePurpose = "dirScan"}; + // catch exception + try { + // set variables + var cacheFileId = null; + // prepopulate folder object with root folder + var scriptProperties = PropertiesService.getScriptProperties(); + //scriptProperties.deleteProperty("cacheFileId"); // debug only + if (scriptProperties.getProperty("cacheFileId" + "_" + cacheFilePurpose) !== null && settleNewCacheFile === false) { + cacheFileId = scriptProperties.getProperty("cacheFileId" + "_" + cacheFilePurpose); + } else { + var cacheFileName = "cache_" + Utilities.formatDate((new Date()), "Europe/Prague", "yyyy-MM-dd'T'HH:mm:ss.SSSXXX") + "_" + cacheFilePurpose + ".json"; + cacheFileId = DriveApp.getFolderById(GVAR.CACHE_FOLDER_ID).createFile(cacheFileName, "", MimeType.JSON).getId(); + scriptProperties.setProperty("cacheFileId" + "_" + cacheFilePurpose, cacheFileId); + } + } catch(e) { + Logger.log(e); + //Flog(e); + throw new Error("Oops! Can not get cache file or read from cache."); + } + // get folder structure file list + return cacheFileId; +} + +/** +* cleans cache file +* @requires getCacheFileId +* @returns {Bool} success +*/ +function setCleanCacheFile(cacheFilePurpose) { + cacheFilePurpose = (cacheFilePurpose || "transResult"); + var cacheFileId = getCacheFileId(false, cacheFilePurpose); + var fileCache = null; + fileCache = DriveApp.getFileById(cacheFileId); + fileCache.setContent(""); + return true; +} + +/** +* deletes all project triggers of given handler function +* @param {String} handlerFunction name of the handler function to be deleted +* @returns {Bool} success +*/ +function setDeleteAllTriggersOfHandlerFunction(handlerFunction) { + var allTriggers = ScriptApp.getProjectTriggers(); + for (var i = 0; i < allTriggers.length; i++) { + if (allTriggers[i].getHandlerFunction() === handlerFunction) { + ScriptApp.deleteTrigger(allTriggers[i]); + } + } + return true; +} + +/** +* deletes trigger by its id +* @returns {String} triggerId id of the trigger to be deleted +* @returns {Bool} success +*/ +function setDeleteTriggerById(triggerId) { + var allTriggers = ScriptApp.getProjectTriggers(); + for (var i = 0; i < allTriggers.length; i++) { + if (allTriggers[i].getUniqueId() == triggerId) { + ScriptApp.deleteTrigger(allTriggers[i]); + break; + } + } + return true; +} + +/** +* deletes all project triggers +* @returns {Bool} success +*/ +function setDeleteAllTriggers(){ + var allTriggers = ScriptApp.getProjectTriggers(); + for (var i = 0; i < allTriggers.length; i++) { + ScriptApp.deleteTrigger(allTriggers[i]); + } + return true; +} + +/** +* gets all domain user emails via admin sdk directory api +* @requires advanced google services Admin Directory API to be allowed and enabled in developer console +* @returns {Array} usersArray array of all domain users +*/ +function getAllDomainUsersEmail() { + var pageToken, page, usersArray = []; + do { + //https://developers.google.com/admin-sdk/directory/v1/reference/users/list + page = AdminDirectory.Users.list({ + domain: GVAR.DOMAIN_OF_GOOGLE_APPS, + orderBy: "email", + maxResults: 500, + pageToken: pageToken + }); + var users = page.users; + if (users) { + for (var i = 0, lenI = users.length; i < lenI; i++) { + var user = users[i]; + usersArray.push(user.primaryEmail); + } + } else { + Logger.log("No users found."); + return []; + } + pageToken = page.nextPageToken; + } while (pageToken); + return usersArray; +} + +/** +* returns all triggers as array +* @returns {Array} triggerArray user trigger array +*/ +function getScriptTriggersArray() { + var allTriggers = ScriptApp.getProjectTriggers(); + var triggerArray = []; + for (var i = 0; i < allTriggers.length; i++) { + triggerArray.push( + "Type: " + allTriggers[i].getEventType() + + "; function: " + allTriggers[i].getHandlerFunction() + + "; source: " + allTriggers[i].getTriggerSource() + + "; id: " + allTriggers[i].getUniqueId() + ) + } + return triggerArray; +} + +/** +* logs message to log file +* @returns {Bool} success +*/ +function Flog(logMessage, initFile){ + logMessage = (logMessage || new Date()); + var logFile = null, logFileTxt = null; + logFile = DriveApp.getFileById(GVAR.LOG_FILE_ID); + if (initFile) { + logFile.setContent("Begin log file."); + return true; + } + logFileTxt = logFile.getBlob().getDataAsString(); + logFileTxt = Utilities.formatDate((new Date()), "Europe/Prague", "yyyy-MM-dd'T'HH:mm:ss.SSSXXX") + " : " + logMessage + "\n" + logFileTxt; + logFile.setContent(logFileTxt); + return true; +} + +/** +* returns flog as array +* @returns {Array} logArray user log array +*/ +function getFlog() { + var logFile = null, logFileTxt = null; + logFile = DriveApp.getFileById(GVAR.LOG_FILE_ID); + logFileTxt = logFile.getBlob().getDataAsString(); + var logArray = logFileTxt.split("\n"); + return logArray; +} + +/** +* releases user lock if exists +* @returns {Bool} success +*/ +function setReleaseUserLock() { + var userLock = LockService.getUserLock(); + userLock.tryLock(10000); + if (!userLock.hasLock()) { + userLock.releaseLock(); + } + return true; +} diff --git a/jsrsasign.gs b/jsrsasign.gs new file mode 100644 index 0000000..bcc4bdf --- /dev/null +++ b/jsrsasign.gs @@ -0,0 +1,162 @@ +/** @preserve +The 'jsrsasign'(RSA-Sign JavaScript Library) License + +Copyright (c) 2010-2013 Kenji Urushima + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. +*/ + +// base64-min.js +var b64map="ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";var b64pad="=";function hex2b64(h){var i;var c;var ret="";for(i=0;i+3<=h.length;i+=3){c=parseInt(h.substring(i,i+3),16);ret+=b64map.charAt(c>>6)+b64map.charAt(c&63)}if(i+1==h.length){c=parseInt(h.substring(i,i+1),16);ret+=b64map.charAt(c<<2)}else if(i+2==h.length){c=parseInt(h.substring(i,i+2),16);ret+=b64map.charAt(c>>2)+b64map.charAt((c&3)<<4)}if(b64pad)while((ret.length&3)>0)ret+=b64pad;return ret} +function b64tohex(s){var ret="";var i;var k=0;var slop;var v;for(i=0;i>2);slop=v&3;k=1}else if(k==1){ret+=int2char(slop<<2|v>>4);slop=v&15;k=2}else if(k==2){ret+=int2char(slop);ret+=int2char(v>>2);slop=v&3;k=3}else{ret+=int2char(slop<<2|v>>4);ret+=int2char(v&15);k=0}}if(k==1)ret+=int2char(slop<<2);return ret} +function b64toBA(s){var h=b64tohex(s);var i;var a=new Array;for(i=0;2*i=0){var v=x*this[i++]+w[j]+c;c=Math.floor(v/67108864);w[j++]=v&67108863}return c} +function am2(i,x,w,j,c,n){var xl=x&32767,xh=x>>15;while(--n>=0){var l=this[i]&32767;var h=this[i++]>>15;var m=xh*l+h*xl;l=xl*l+((m&32767)<<15)+w[j]+(c&1073741823);c=(l>>>30)+(m>>>15)+xh*h+(c>>>30);w[j++]=l&1073741823}return c}function am3(i,x,w,j,c,n){var xl=x&16383,xh=x>>14;while(--n>=0){var l=this[i]&16383;var h=this[i++]>>14;var m=xh*l+h*xl;l=xl*l+((m&16383)<<14)+w[j]+c;c=(l>>28)+(m>>14)+xh*h;w[j++]=l&268435455}return c} +//if(j_lm&&navigator.appName=="Microsoft Internet Explorer"){BigInteger.prototype.am=am2;dbits=30}else if(j_lm&&navigator.appName!="Netscape"){BigInteger.prototype.am=am1;dbits=26}else{BigInteger.prototype.am=am3;dbits=28}BigInteger.prototype.DB=dbits;BigInteger.prototype.DM=(1<=0;--i)r[i]=this[i];r.t=this.t;r.s=this.s} +function bnpFromInt(x){this.t=1;this.s=x<0?-1:0;if(x>0)this[0]=x;else if(x<-1)this[0]=x+this.DV;else this.t=0}function nbv(i){var r=nbi();r.fromInt(i);return r} +function bnpFromString(s,b){var k;if(b==16)k=4;else if(b==8)k=3;else if(b==256)k=8;else if(b==2)k=1;else if(b==32)k=5;else if(b==4)k=2;else{this.fromRadix(s,b);return}this.t=0;this.s=0;var i=s.length,mi=false,sh=0;while(--i>=0){var x=k==8?s[i]&255:intAt(s,i);if(x<0){if(s.charAt(i)=="-")mi=true;continue}mi=false;if(sh==0)this[this.t++]=x;else if(sh+k>this.DB){this[this.t-1]|=(x&(1<>this.DB-sh}else this[this.t-1]|=x<=this.DB)sh-=this.DB}if(k==8&& +(s[0]&128)!=0){this.s=-1;if(sh>0)this[this.t-1]|=(1<0&&this[this.t-1]==c)--this.t} +function bnToString(b){if(this.s<0)return"-"+this.negate().toString(b);var k;if(b==16)k=4;else if(b==8)k=3;else if(b==2)k=1;else if(b==32)k=5;else if(b==4)k=2;else return this.toRadix(b);var km=(1<0){if(p>p)>0){m=true;r=int2char(d)}while(i>=0){if(p>(p+=this.DB-k)}else{d=this[i]>>(p-=k)&km;if(p<=0){p+=this.DB;--i}}if(d>0)m=true;if(m)r+=int2char(d)}}return m?r:"0"} +function bnNegate(){var r=nbi();BigInteger.ZERO.subTo(this,r);return r}function bnAbs(){return this.s<0?this.negate():this}function bnCompareTo(a){var r=this.s-a.s;if(r!=0)return r;var i=this.t;r=i-a.t;if(r!=0)return this.s<0?-r:r;while(--i>=0)if((r=this[i]-a[i])!=0)return r;return 0}function nbits(x){var r=1,t;if((t=x>>>16)!=0){x=t;r+=16}if((t=x>>8)!=0){x=t;r+=8}if((t=x>>4)!=0){x=t;r+=4}if((t=x>>2)!=0){x=t;r+=2}if((t=x>>1)!=0){x=t;r+=1}return r} +function bnBitLength(){if(this.t<=0)return 0;return this.DB*(this.t-1)+nbits(this[this.t-1]^this.s&this.DM)}function bnpDLShiftTo(n,r){var i;for(i=this.t-1;i>=0;--i)r[i+n]=this[i];for(i=n-1;i>=0;--i)r[i]=0;r.t=this.t+n;r.s=this.s}function bnpDRShiftTo(n,r){for(var i=n;i=0;--i){r[i+ds+1]=this[i]>>cbs|c;c=(this[i]&bm)<=0;--i)r[i]=0;r[ds]=c;r.t=this.t+ds+1;r.s=this.s;r.clamp()} +function bnpRShiftTo(n,r){r.s=this.s;var ds=Math.floor(n/this.DB);if(ds>=this.t){r.t=0;return}var bs=n%this.DB;var cbs=this.DB-bs;var bm=(1<>bs;for(var i=ds+1;i>bs}if(bs>0)r[this.t-ds-1]|=(this.s&bm)<>=this.DB}if(a.t>=this.DB}c+=this.s}else{c+=this.s;while(i>=this.DB}c-=a.s}r.s=c<0?-1:0;if(c<-1)r[i++]=this.DV+c;else if(c>0)r[i++]=c;r.t=i;r.clamp()} +function bnpMultiplyTo(a,r){var x=this.abs(),y=a.abs();var i=x.t;r.t=i+y.t;while(--i>=0)r[i]=0;for(i=0;i=0)r[i]=0;for(i=0;i=x.DV){r[i+x.t]-=x.DV;r[i+x.t+1]=1}}if(r.t>0)r[r.t-1]+=x.am(i,x[i],r,2*i,0,1);r.s=0;r.clamp()} +function bnpDivRemTo(m,q,r){var pm=m.abs();if(pm.t<=0)return;var pt=this.abs();if(pt.t0){pm.lShiftTo(nsh,y);pt.lShiftTo(nsh,r)}else{pm.copyTo(y);pt.copyTo(r)}var ys=y.t;var y0=y[ys-1];if(y0==0)return;var yt=y0*(1<1?y[ys-2]>>this.F2:0);var d1=this.FV/yt,d2=(1<=0){r[r.t++]=1;r.subTo(t,r)}BigInteger.ONE.dlShiftTo(ys,t);t.subTo(y,y);while(y.t=0){var qd=r[--i]==y0?this.DM:Math.floor(r[i]*d1+(r[i-1]+e)*d2);if((r[i]+=y.am(0,qd,r,j,0,ys))0)r.rShiftTo(nsh,r);if(ts<0)BigInteger.ZERO.subTo(r,r)} +function bnMod(a){var r=nbi();this.abs().divRemTo(a,null,r);if(this.s<0&&r.compareTo(BigInteger.ZERO)>0)a.subTo(r,r);return r}function Classic(m){this.m=m}function cConvert(x){if(x.s<0||x.compareTo(this.m)>=0)return x.mod(this.m);else return x}function cRevert(x){return x}function cReduce(x){x.divRemTo(this.m,null,x)}function cMulTo(x,y,r){x.multiplyTo(y,r);this.reduce(r)}function cSqrTo(x,r){x.squareTo(r);this.reduce(r)}Classic.prototype.convert=cConvert;Classic.prototype.revert=cRevert; +Classic.prototype.reduce=cReduce;Classic.prototype.mulTo=cMulTo;Classic.prototype.sqrTo=cSqrTo;function bnpInvDigit(){if(this.t<1)return 0;var x=this[0];if((x&1)==0)return 0;var y=x&3;y=y*(2-(x&15)*y)&15;y=y*(2-(x&255)*y)&255;y=y*(2-((x&65535)*y&65535))&65535;y=y*(2-x*y%this.DV)%this.DV;return y>0?this.DV-y:-y}function Montgomery(m){this.m=m;this.mp=m.invDigit();this.mpl=this.mp&32767;this.mph=this.mp>>15;this.um=(1<0)this.m.subTo(r,r);return r}function montRevert(x){var r=nbi();x.copyTo(r);this.reduce(r);return r} +function montReduce(x){while(x.t<=this.mt2)x[x.t++]=0;for(var i=0;i>15)*this.mpl&this.um)<<15)&x.DM;j=i+this.m.t;x[j]+=this.m.am(0,u0,x,i,0,this.m.t);while(x[j]>=x.DV){x[j]-=x.DV;x[++j]++}}x.clamp();x.drShiftTo(this.m.t,x);if(x.compareTo(this.m)>=0)x.subTo(this.m,x)}function montSqrTo(x,r){x.squareTo(r);this.reduce(r)}function montMulTo(x,y,r){x.multiplyTo(y,r);this.reduce(r)}Montgomery.prototype.convert=montConvert; +Montgomery.prototype.revert=montRevert;Montgomery.prototype.reduce=montReduce;Montgomery.prototype.mulTo=montMulTo;Montgomery.prototype.sqrTo=montSqrTo;function bnpIsEven(){return(this.t>0?this[0]&1:this.s)==0}function bnpExp(e,z){if(e>4294967295||e<1)return BigInteger.ONE;var r=nbi(),r2=nbi(),g=z.convert(this),i=nbits(e)-1;g.copyTo(r);while(--i>=0){z.sqrTo(r,r2);if((e&1<0)z.mulTo(r2,g,r);else{var t=r;r=r2;r2=t}}return z.revert(r)} +function bnModPowInt(e,m){var z;if(e<256||m.isEven())z=new Classic(m);else z=new Montgomery(m);return this.exp(e,z)}BigInteger.prototype.copyTo=bnpCopyTo;BigInteger.prototype.fromInt=bnpFromInt;BigInteger.prototype.fromString=bnpFromString;BigInteger.prototype.clamp=bnpClamp;BigInteger.prototype.dlShiftTo=bnpDLShiftTo;BigInteger.prototype.drShiftTo=bnpDRShiftTo;BigInteger.prototype.lShiftTo=bnpLShiftTo;BigInteger.prototype.rShiftTo=bnpRShiftTo;BigInteger.prototype.subTo=bnpSubTo; +BigInteger.prototype.multiplyTo=bnpMultiplyTo;BigInteger.prototype.squareTo=bnpSquareTo;BigInteger.prototype.divRemTo=bnpDivRemTo;BigInteger.prototype.invDigit=bnpInvDigit;BigInteger.prototype.isEven=bnpIsEven;BigInteger.prototype.exp=bnpExp;BigInteger.prototype.toString=bnToString;BigInteger.prototype.negate=bnNegate;BigInteger.prototype.abs=bnAbs;BigInteger.prototype.compareTo=bnCompareTo;BigInteger.prototype.bitLength=bnBitLength;BigInteger.prototype.mod=bnMod;BigInteger.prototype.modPowInt=bnModPowInt; +BigInteger.ZERO=nbv(0);BigInteger.ONE=nbv(1); + +// jsbn2.js +function bnClone(){var r=nbi();this.copyTo(r);return r}function bnIntValue(){if(this.s<0)if(this.t==1)return this[0]-this.DV;else{if(this.t==0)return-1}else if(this.t==1)return this[0];else if(this.t==0)return 0;return(this[1]&(1<<32-this.DB)-1)<>24}function bnShortValue(){return this.t==0?this.s:this[0]<<16>>16}function bnpChunkSize(r){return Math.floor(Math.LN2*this.DB/Math.log(r))} +function bnSigNum(){if(this.s<0)return-1;else if(this.t<=0||this.t==1&&this[0]<=0)return 0;else return 1}function bnpToRadix(b){if(b==null)b=10;if(this.signum()==0||b<2||b>36)return"0";var cs=this.chunkSize(b);var a=Math.pow(b,cs);var d=nbv(a),y=nbi(),z=nbi(),r="";this.divRemTo(d,y,z);while(y.signum()>0){r=(a+z.intValue()).toString(b).substr(1)+r;y.divRemTo(d,y,z)}return z.intValue().toString(b)+r} +function bnpFromRadix(s,b){this.fromInt(0);if(b==null)b=10;var cs=this.chunkSize(b);var d=Math.pow(b,cs),mi=false,j=0,w=0;for(var i=0;i=cs){this.dMultiply(d);this.dAddOffset(w,0);j=0;w=0}}if(j>0){this.dMultiply(Math.pow(b,j));this.dAddOffset(w,0)}if(mi)BigInteger.ZERO.subTo(this,this)} +function bnpFromNumber(a,b,c){if("number"==typeof b)if(a<2)this.fromInt(1);else{this.fromNumber(a,c);if(!this.testBit(a-1))this.bitwiseTo(BigInteger.ONE.shiftLeft(a-1),op_or,this);if(this.isEven())this.dAddOffset(1,0);while(!this.isProbablePrime(b)){this.dAddOffset(2,0);if(this.bitLength()>a)this.subTo(BigInteger.ONE.shiftLeft(a-1),this)}}else{var x=new Array,t=a&7;x.length=(a>>3)+1;b.nextBytes(x);if(t>0)x[0]&=(1<0){if(p>p)!=(this.s&this.DM)>>p)r[k++]=d|this.s<=0){if(p<8){d=(this[i]&(1<>(p+=this.DB-8)}else{d=this[i]>>(p-=8)&255;if(p<=0){p+=this.DB;--i}}if((d&128)!=0)d|=-256;if(k==0&&(this.s&128)!=(d&128))++k;if(k>0||d!=this.s)r[k++]=d}}return r}function bnEquals(a){return this.compareTo(a)==0} +function bnMin(a){return this.compareTo(a)<0?this:a}function bnMax(a){return this.compareTo(a)>0?this:a}function bnpBitwiseTo(a,op,r){var i,f,m=Math.min(a.t,this.t);for(i=0;i>=16;r+=16}if((x&255)==0){x>>=8;r+=8}if((x&15)==0){x>>=4;r+=4}if((x&3)==0){x>>=2;r+=2}if((x&1)==0)++r;return r} +function bnGetLowestSetBit(){for(var i=0;i=this.t)return this.s!=0;return(this[j]&1<>=this.DB}if(a.t>=this.DB}c+=this.s}else{c+=this.s;while(i>=this.DB}c+=a.s}r.s=c<0?-1:0;if(c>0)r[i++]=c;else if(c<-1)r[i++]=this.DV+c;r.t=i;r.clamp()}function bnAdd(a){var r=nbi();this.addTo(a,r);return r}function bnSubtract(a){var r=nbi();this.subTo(a,r);return r} +function bnMultiply(a){var r=nbi();this.multiplyTo(a,r);return r}function bnSquare(){var r=nbi();this.squareTo(r);return r}function bnDivide(a){var r=nbi();this.divRemTo(a,r,null);return r}function bnRemainder(a){var r=nbi();this.divRemTo(a,null,r);return r}function bnDivideAndRemainder(a){var q=nbi(),r=nbi();this.divRemTo(a,q,r);return new Array(q,r)}function bnpDMultiply(n){this[this.t]=this.am(0,n-1,this,0,0,this.t);++this.t;this.clamp()} +function bnpDAddOffset(n,w){if(n==0)return;while(this.t<=w)this[this.t++]=0;this[w]+=n;while(this[w]>=this.DV){this[w]-=this.DV;if(++w>=this.t)this[this.t++]=0;++this[w]}}function NullExp(){}function nNop(x){return x}function nMulTo(x,y,r){x.multiplyTo(y,r)}function nSqrTo(x,r){x.squareTo(r)}NullExp.prototype.convert=nNop;NullExp.prototype.revert=nNop;NullExp.prototype.mulTo=nMulTo;NullExp.prototype.sqrTo=nSqrTo;function bnPow(e){return this.exp(e,new NullExp)} +function bnpMultiplyLowerTo(a,n,r){var i=Math.min(this.t+a.t,n);r.s=0;r.t=i;while(i>0)r[--i]=0;var j;for(j=r.t-this.t;i=0)r[i]=0;for(i=Math.max(n-this.t,0);i2*this.m.t)return x.mod(this.m);else if(x.compareTo(this.m)<0)return x;else{var r=nbi();x.copyTo(r);this.reduce(r);return r}}function barrettRevert(x){return x} +function barrettReduce(x){x.drShiftTo(this.m.t-1,this.r2);if(x.t>this.m.t+1){x.t=this.m.t+1;x.clamp()}this.mu.multiplyUpperTo(this.r2,this.m.t+1,this.q3);this.m.multiplyLowerTo(this.q3,this.m.t+1,this.r2);while(x.compareTo(this.r2)<0)x.dAddOffset(1,this.m.t+1);x.subTo(this.r2,x);while(x.compareTo(this.m)>=0)x.subTo(this.m,x)}function barrettSqrTo(x,r){x.squareTo(r);this.reduce(r)}function barrettMulTo(x,y,r){x.multiplyTo(y,r);this.reduce(r)}Barrett.prototype.convert=barrettConvert; +Barrett.prototype.revert=barrettRevert;Barrett.prototype.reduce=barrettReduce;Barrett.prototype.mulTo=barrettMulTo;Barrett.prototype.sqrTo=barrettSqrTo; +function bnModPow(e,m){var i=e.bitLength(),k,r=nbv(1),z;if(i<=0)return r;else if(i<18)k=1;else if(i<48)k=3;else if(i<144)k=4;else if(i<768)k=5;else k=6;if(i<8)z=new Classic(m);else if(m.isEven())z=new Barrett(m);else z=new Montgomery(m);var g=new Array,n=3,k1=k-1,km=(1<1){var g2=nbi();z.sqrTo(g[1],g2);while(n<=km){g[n]=nbi();z.mulTo(g2,g[n-2],g[n]);n+=2}}var j=e.t-1,w,is1=true,r2=nbi(),t;i=nbits(e[j])-1;while(j>=0){if(i>=k1)w=e[j]>>i-k1&km;else{w=(e[j]&(1<0)w|=e[j-1]>>this.DB+i-k1}n=k;while((w&1)==0){w>>=1;--n}if((i-=n)<0){i+=this.DB;--j}if(is1){g[w].copyTo(r);is1=false}else{while(n>1){z.sqrTo(r,r2);z.sqrTo(r2,r);n-=2}if(n>0)z.sqrTo(r,r2);else{t=r;r=r2;r2=t}z.mulTo(r2,g[w],r)}while(j>=0&&(e[j]&1<0){x.rShiftTo(g,x);y.rShiftTo(g,y)}while(x.signum()>0){if((i=x.getLowestSetBit())>0)x.rShiftTo(i,x);if((i=y.getLowestSetBit())>0)y.rShiftTo(i,y);if(x.compareTo(y)>=0){x.subTo(y,x);x.rShiftTo(1,x)}else{y.subTo(x,y);y.rShiftTo(1,y)}}if(g>0)y.lShiftTo(g,y);return y} +function bnpModInt(n){if(n<=0)return 0;var d=this.DV%n,r=this.s<0?n-1:0;if(this.t>0)if(d==0)r=this[0]%n;else for(var i=this.t-1;i>=0;--i)r=(d*r+this[i])%n;return r} +function bnModInverse(m){var ac=m.isEven();if(this.isEven()&&ac||m.signum()==0)return BigInteger.ZERO;var u=m.clone(),v=this.clone();var a=nbv(1),b=nbv(0),c=nbv(0),d=nbv(1);while(u.signum()!=0){while(u.isEven()){u.rShiftTo(1,u);if(ac){if(!a.isEven()||!b.isEven()){a.addTo(this,a);b.subTo(m,b)}a.rShiftTo(1,a)}else if(!b.isEven())b.subTo(m,b);b.rShiftTo(1,b)}while(v.isEven()){v.rShiftTo(1,v);if(ac){if(!c.isEven()||!d.isEven()){c.addTo(this,c);d.subTo(m,d)}c.rShiftTo(1,c)}else if(!d.isEven())d.subTo(m, +d);d.rShiftTo(1,d)}if(u.compareTo(v)>=0){u.subTo(v,u);if(ac)a.subTo(c,a);b.subTo(d,b)}else{v.subTo(u,v);if(ac)c.subTo(a,c);d.subTo(b,d)}}if(v.compareTo(BigInteger.ONE)!=0)return BigInteger.ZERO;if(d.compareTo(m)>=0)return d.subtract(m);if(d.signum()<0)d.addTo(m,d);else return d;if(d.signum()<0)return d.add(m);else return d} +var lowprimes=[2,3,5,7,11,13,17,19,23,29,31,37,41,43,47,53,59,61,67,71,73,79,83,89,97,101,103,107,109,113,127,131,137,139,149,151,157,163,167,173,179,181,191,193,197,199,211,223,227,229,233,239,241,251,257,263,269,271,277,281,283,293,307,311,313,317,331,337,347,349,353,359,367,373,379,383,389,397,401,409,419,421,431,433,439,443,449,457,461,463,467,479,487,491,499,503,509,521,523,541,547,557,563,569,571,577,587,593,599,601,607,613,617,619,631,641,643,647,653,659,661,673,677,683,691,701,709,719,727, +733,739,743,751,757,761,769,773,787,797,809,811,821,823,827,829,839,853,857,859,863,877,881,883,887,907,911,919,929,937,941,947,953,967,971,977,983,991,997];var lplim=(1<<26)/lowprimes[lowprimes.length-1]; +function bnIsProbablePrime(t){var i,x=this.abs();if(x.t==1&&x[0]<=lowprimes[lowprimes.length-1]){for(i=0;i>1;if(t>lowprimes.length)t=lowprimes.length;var a=nbi();for(var i=0;i=0&&n>0){var c=s.charCodeAt(i--);if(c<128)ba[--n]=c;else if(c>127&&c<2048){ba[--n]=c&63|128;ba[--n]=c>>6|192}else{ba[--n]=c&63|128;ba[--n]=c>>6&63|128;ba[--n]=c>>12|224}}ba[--n]=0;var rng=new SecureRandom;var x=new Array;while(n>2){x[0]=0;while(x[0]==0)rng.nextBytes(x);ba[--n]=x[0]}ba[--n]=2;ba[--n]=0;return new BigInteger(ba)} +function oaep_mgf1_arr(seed,len,hash){var mask="",i=0;while(mask.length>24,(i&16711680)>>16,(i&65280)>>8,i&255])));i+=1}return mask}var SHA1_SIZE=20; +function oaep_pad(s,n,hash){if(s.length+2*SHA1_SIZE+2>n)throw"Message too long for RSA";var PS="",i;for(i=0;i0&&E.length>0){this.n=parseBigInt(N,16);this.e=parseInt(E,16)}else alert("Invalid RSA public key")} +function RSADoPublic(x){return x.modPowInt(this.e,this.n)}function RSAEncrypt(text){var m=pkcs1pad2(text,this.n.bitLength()+7>>3);if(m==null)return null;var c=this.doPublic(m);if(c==null)return null;var h=c.toString(16);if((h.length&1)==0)return h;else return"0"+h}function RSAEncryptOAEP(text,hash){var m=oaep_pad(text,this.n.bitLength()+7>>3,hash);if(m==null)return null;var c=this.doPublic(m);if(c==null)return null;var h=c.toString(16);if((h.length&1)==0)return h;else return"0"+h} +RSAKey.prototype.doPublic=RSADoPublic;RSAKey.prototype.setPublic=RSASetPublic;RSAKey.prototype.encrypt=RSAEncrypt;RSAKey.prototype.encryptOAEP=RSAEncryptOAEP;RSAKey.prototype.type="RSA"; + +// rsa2.js +function pkcs1unpad2(d,n){var b=d.toByteArray();var i=0;while(i=b.length)return null;var ret="";while(++i191&&c<224){ret+=String.fromCharCode((c&31)<<6|b[i+1]&63);++i}else{ret+=String.fromCharCode((c&15)<<12|(b[i+1]&63)<<6|b[i+2]&63);i+=2}}return ret} +function oaep_mgf1_str(seed,len,hash){var mask="",i=0;while(mask.length>24,(i&16711680)>>16,(i&65280)>>8,i&255]));i+=1}return mask}var SHA1_SIZE=20; +function oaep_unpad(d,n,hash){d=d.toByteArray();var i;for(i=0;i0&&E.length>0){this.n=parseBigInt(N,16);this.e=parseInt(E,16);this.d=parseBigInt(D,16)}else alert("Invalid RSA private key")} +function RSASetPrivateEx(N,E,D,P,Q,DP,DQ,C){this.isPrivate=true;if(N==null)throw"RSASetPrivateEx N == null";if(E==null)throw"RSASetPrivateEx E == null";if(N.length==0)throw"RSASetPrivateEx N.length == 0";if(E.length==0)throw"RSASetPrivateEx E.length == 0";if(N!=null&&E!=null&&N.length>0&&E.length>0){this.n=parseBigInt(N,16);this.e=parseInt(E,16);this.d=parseBigInt(D,16);this.p=parseBigInt(P,16);this.q=parseBigInt(Q,16);this.dmp1=parseBigInt(DP,16);this.dmq1=parseBigInt(DQ,16);this.coeff=parseBigInt(C, +16)}else alert("Invalid RSA private key in RSASetPrivateEx")} +function RSAGenerate(B,E){var rng=new SecureRandom;var qs=B>>1;this.e=parseInt(E,16);var ee=new BigInteger(E,16);for(;;){for(;;){this.p=new BigInteger(B-qs,1,rng);if(this.p.subtract(BigInteger.ONE).gcd(ee).compareTo(BigInteger.ONE)==0&&this.p.isProbablePrime(10))break}for(;;){this.q=new BigInteger(qs,1,rng);if(this.q.subtract(BigInteger.ONE).gcd(ee).compareTo(BigInteger.ONE)==0&&this.q.isProbablePrime(10))break}if(this.p.compareTo(this.q)<=0){var t=this.p;this.p=this.q;this.q=t}var p1=this.p.subtract(BigInteger.ONE); +var q1=this.q.subtract(BigInteger.ONE);var phi=p1.multiply(q1);if(phi.gcd(ee).compareTo(BigInteger.ONE)==0){this.n=this.p.multiply(this.q);this.d=ee.modInverse(phi);this.dmp1=this.d.mod(p1);this.dmq1=this.d.mod(q1);this.coeff=this.q.modInverse(this.p);break}}this.isPrivate=true} +function RSADoPrivate(x){if(this.p==null||this.q==null)return x.modPow(this.d,this.n);var xp=x.mod(this.p).modPow(this.dmp1,this.p);var xq=x.mod(this.q).modPow(this.dmq1,this.q);while(xp.compareTo(xq)<0)xp=xp.add(this.p);return xp.subtract(xq).multiply(this.coeff).mod(this.p).multiply(this.q).add(xq)}function RSADecrypt(ctext){var c=parseBigInt(ctext,16);var m=this.doPrivate(c);if(m==null)return null;return pkcs1unpad2(m,this.n.bitLength()+7>>3)} +function RSADecryptOAEP(ctext,hash){var c=parseBigInt(ctext,16);var m=this.doPrivate(c);if(m==null)return null;return oaep_unpad(m,this.n.bitLength()+7>>3,hash)}RSAKey.prototype.doPrivate=RSADoPrivate;RSAKey.prototype.setPrivate=RSASetPrivate;RSAKey.prototype.setPrivateEx=RSASetPrivateEx;RSAKey.prototype.generate=RSAGenerate;RSAKey.prototype.decrypt=RSADecrypt;RSAKey.prototype.decryptOAEP=RSADecryptOAEP; + +// rsapem-1.1.js +function _rsapem_pemToBase64(sPEMPrivateKey){var s=sPEMPrivateKey;s=s.replace("-----BEGIN RSA PRIVATE KEY-----","");s=s.replace("-----END RSA PRIVATE KEY-----","");s=s.replace(/[ \n]+/g,"");return s} +function _rsapem_getPosArrayOfChildrenFromHex(hPrivateKey){var a=new Array;var v1=ASN1HEX.getStartPosOfV_AtObj(hPrivateKey,0);var n1=ASN1HEX.getPosOfNextSibling_AtObj(hPrivateKey,v1);var e1=ASN1HEX.getPosOfNextSibling_AtObj(hPrivateKey,n1);var d1=ASN1HEX.getPosOfNextSibling_AtObj(hPrivateKey,e1);var p1=ASN1HEX.getPosOfNextSibling_AtObj(hPrivateKey,d1);var q1=ASN1HEX.getPosOfNextSibling_AtObj(hPrivateKey,p1);var dp1=ASN1HEX.getPosOfNextSibling_AtObj(hPrivateKey,q1);var dq1=ASN1HEX.getPosOfNextSibling_AtObj(hPrivateKey, +dp1);var co1=ASN1HEX.getPosOfNextSibling_AtObj(hPrivateKey,dq1);a.push(v1,n1,e1,d1,p1,q1,dp1,dq1,co1);return a} +function _rsapem_getHexValueArrayOfChildrenFromHex(hPrivateKey){var posArray=_rsapem_getPosArrayOfChildrenFromHex(hPrivateKey);var v=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[0]);var n=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[1]);var e=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[2]);var d=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[3]);var p=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[4]);var q=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[5]);var dp=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[6]); +var dq=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[7]);var co=ASN1HEX.getHexOfV_AtObj(hPrivateKey,posArray[8]);var a=new Array;a.push(v,n,e,d,p,q,dp,dq,co);return a}function _rsapem_readPrivateKeyFromASN1HexString(keyHex){var a=_rsapem_getHexValueArrayOfChildrenFromHex(keyHex);this.setPrivateEx(a[1],a[2],a[3],a[4],a[5],a[6],a[7],a[8])} +function _rsapem_readPrivateKeyFromPEMString(keyPEM){var keyB64=_rsapem_pemToBase64(keyPEM);var keyHex=b64tohex(keyB64);var a=_rsapem_getHexValueArrayOfChildrenFromHex(keyHex);this.setPrivateEx(a[1],a[2],a[3],a[4],a[5],a[6],a[7],a[8])}RSAKey.prototype.readPrivateKeyFromPEMString=_rsapem_readPrivateKeyFromPEMString;RSAKey.prototype.readPrivateKeyFromASN1HexString=_rsapem_readPrivateKeyFromASN1HexString; + +// rsasign-1.2.js +var _RE_HEXDECONLY=new RegExp("");_RE_HEXDECONLY.compile("[^0-9a-f]","gi");function _rsasign_getHexPaddedDigestInfoForString(s,keySize,hashAlg){var hashFunc=function(s){return KJUR.crypto.Util.hashString(s,hashAlg)};var sHashHex=hashFunc(s);return KJUR.crypto.Util.getPaddedDigestInfoHex(sHashHex,hashAlg,keySize)}function _zeroPaddingOfSignature(hex,bitLength){var s="";var nZero=bitLength/4-hex.length;for(var i=0;i>24,(i&16711680)>>16,(i&65280)>>8,i&255]))));i+=1}return mask}function _rsasign_signStringPSS(s,hashAlg,sLen){var hashFunc=function(sHex){return KJUR.crypto.Util.hashHex(sHex,hashAlg)};var hHash=hashFunc(rstrtohex(s));if(sLen===undefined)sLen=-1;return this.signWithMessageHashPSS(hHash,hashAlg,sLen)} +function _rsasign_signWithMessageHashPSS(hHash,hashAlg,sLen){var mHash=hextorstr(hHash);var hLen=mHash.length;var emBits=this.n.bitLength()-1;var emLen=Math.ceil(emBits/8);var i;var hashFunc=function(sHex){return KJUR.crypto.Util.hashHex(sHex,hashAlg)};if(sLen===-1||sLen===undefined)sLen=hLen;else if(sLen===-2)sLen=emLen-hLen-2;else if(sLen<-2)throw"invalid salt length";if(emLen0){salt=new Array(sLen);(new SecureRandom).nextBytes(salt);salt=String.fromCharCode.apply(String, +salt)}var H=hextorstr(hashFunc(rstrtohex("\x00\x00\x00\x00\x00\x00\x00\x00"+mHash+salt)));var PS=[];for(i=0;i>8*emLen-emBits&255;maskedDB[0]&=~mask;for(i=0;ithis.n.bitLength())return 0;var biDecryptedSig=this.doPublic(biSig);var hDigestInfo=biDecryptedSig.toString(16).replace(/^1f+00/,"");var digestInfoAry=_rsasign_getAlgNameAndHashFromHexDisgestInfo(hDigestInfo);if(digestInfoAry.length==0)return false;var algName=digestInfoAry[0];var diHashValue=digestInfoAry[1];var ff=function(s){return KJUR.crypto.Util.hashString(s, +algName)};var msgHashValue=ff(sMsg);return diHashValue==msgHashValue} +function _rsasign_verifyWithMessageHash(sHashHex,hSig){hSig=hSig.replace(_RE_HEXDECONLY,"");hSig=hSig.replace(/[ \n]+/g,"");var biSig=parseBigInt(hSig,16);if(biSig.bitLength()>this.n.bitLength())return 0;var biDecryptedSig=this.doPublic(biSig);var hDigestInfo=biDecryptedSig.toString(16).replace(/^1f+00/,"");var digestInfoAry=_rsasign_getAlgNameAndHashFromHexDisgestInfo(hDigestInfo);if(digestInfoAry.length==0)return false;var algName=digestInfoAry[0];var diHashValue=digestInfoAry[1];return diHashValue== +sHashHex}function _rsasign_verifyStringPSS(sMsg,hSig,hashAlg,sLen){var hashFunc=function(sHex){return KJUR.crypto.Util.hashHex(sHex,hashAlg)};var hHash=hashFunc(rstrtohex(sMsg));if(sLen===undefined)sLen=-1;return this.verifyWithMessageHashPSS(hHash,hSig,hashAlg,sLen)} +function _rsasign_verifyWithMessageHashPSS(hHash,hSig,hashAlg,sLen){var biSig=new BigInteger(hSig,16);if(biSig.bitLength()>this.n.bitLength())return false;var hashFunc=function(sHex){return KJUR.crypto.Util.hashHex(sHex,hashAlg)};var mHash=hextorstr(hHash);var hLen=mHash.length;var emBits=this.n.bitLength()-1;var emLen=Math.ceil(emBits/8);var i;if(sLen===-1||sLen===undefined)sLen=hLen;else if(sLen===-2)sLen=emLen-hLen-2;else if(sLen<-2)throw"invalid salt length";if(emLen>8*emLen-emBits&255;if((maskedDB.charCodeAt(0)&mask)!==0)throw"bits beyond keysize not zero";var dbMask=pss_mgf1_str(H,maskedDB.length,hashFunc);var DB=[];for(i=0;i=len*2)break;if(k>=200)break;a.push(pNext);p=pNext;k++}return a};this.getNthChildIndex_AtObj=function(h, +idx,nth){var a=this.getPosArrayOfChildren_AtObj(h,idx);return a[nth]};this.getDecendantIndexByNthList=function(h,currentIndex,nthList){if(nthList.length==0)return currentIndex;var firstNth=nthList.shift();var a=this.getPosArrayOfChildren_AtObj(h,currentIndex);return this.getDecendantIndexByNthList(h,a[firstNth],nthList)};this.getDecendantHexTLVByNthList=function(h,currentIndex,nthList){var idx=this.getDecendantIndexByNthList(h,currentIndex,nthList);return this.getHexOfTLV_AtObj(h,idx)};this.getDecendantHexVByNthList= +function(h,currentIndex,nthList){var idx=this.getDecendantIndexByNthList(h,currentIndex,nthList);return this.getHexOfV_AtObj(h,idx)}};ASN1HEX.getVbyList=function(h,currentIndex,nthList,checkingTag){var idx=this.getDecendantIndexByNthList(h,currentIndex,nthList);if(idx===undefined)throw"can't find nthList object";if(checkingTag!==undefined)if(h.substr(idx,2)!=checkingTag)throw"checking tag doesn't match: "+h.substr(idx,2)+"!="+checkingTag;return this.getHexOfV_AtObj(h,idx)}; +ASN1HEX.hextooidstr=function(hex){var zeroPadding=function(s,len){if(s.length>=len)return s;return(new Array(len-s.length+1)).join("0")+s};var a=[];var hex0=hex.substr(0,2);var i0=parseInt(hex0,16);a[0]=new String(Math.floor(i0/40));a[1]=new String(i0%40);var hex1=hex.substr(2);var b=[];for(var i=0;i0)s=s+"."+c.join(".");return s}; + +// x509-1.1.min.js +function X509(){this.subjectPublicKeyRSA=null;this.subjectPublicKeyRSA_hN=null;this.subjectPublicKeyRSA_hE=null;this.hex=null;this.getSerialNumberHex=function(){return ASN1HEX.getDecendantHexVByNthList(this.hex,0,[0,1])};this.getIssuerHex=function(){return ASN1HEX.getDecendantHexTLVByNthList(this.hex,0,[0,3])};this.getIssuerString=function(){return X509.hex2dn(ASN1HEX.getDecendantHexTLVByNthList(this.hex,0,[0,3]))};this.getSubjectHex=function(){return ASN1HEX.getDecendantHexTLVByNthList(this.hex,0,[0,5])};this.getSubjectString=function(){return X509.hex2dn(ASN1HEX.getDecendantHexTLVByNthList(this.hex,0,[0,5]))};this.getNotBefore=function(){var a=ASN1HEX.getDecendantHexVByNthList(this.hex,0,[0,4,0]);a=a.replace(/(..)/g,"%$1");a=decodeURIComponent(a);return a};this.getNotAfter=function(){var a=ASN1HEX.getDecendantHexVByNthList(this.hex,0,[0,4,1]);a=a.replace(/(..)/g,"%$1");a=decodeURIComponent(a);return a};this.readCertPEM=function(c){var e=X509.pemToHex(c);var b=X509.getPublicKeyHexArrayFromCertHex(e);var d=new RSAKey();d.setPublic(b[0],b[1]);this.subjectPublicKeyRSA=d;this.subjectPublicKeyRSA_hN=b[0];this.subjectPublicKeyRSA_hE=b[1];this.hex=e};this.readCertPEMWithoutRSAInit=function(c){var d=X509.pemToHex(c);var b=X509.getPublicKeyHexArrayFromCertHex(d);this.subjectPublicKeyRSA.setPublic(b[0],b[1]);this.subjectPublicKeyRSA_hN=b[0];this.subjectPublicKeyRSA_hE=b[1];this.hex=d}}X509.pemToBase64=function(a){var b=a;b=b.replace("-----BEGIN CERTIFICATE-----","");b=b.replace("-----END CERTIFICATE-----","");b=b.replace(/[ \n]+/g,"");return b};X509.pemToHex=function(a){var c=X509.pemToBase64(a);var b=b64tohex(c);return b};X509.getSubjectPublicKeyPosFromCertHex=function(f){var e=X509.getSubjectPublicKeyInfoPosFromCertHex(f);if(e==-1){return -1}var b=ASN1HEX.getPosArrayOfChildren_AtObj(f,e);if(b.length!=2){return -1}var d=b[1];if(f.substring(d,d+2)!="03"){return -1}var c=ASN1HEX.getStartPosOfV_AtObj(f,d);if(f.substring(c,c+2)!="00"){return -1}return c+2};X509.getSubjectPublicKeyInfoPosFromCertHex=function(d){var c=ASN1HEX.getStartPosOfV_AtObj(d,0);var b=ASN1HEX.getPosArrayOfChildren_AtObj(d,c);if(b.length<1){return -1}if(d.substring(b[0],b[0]+10)=="a003020102"){if(b.length<6){return -1}return b[6]}else{if(b.length<5){return -1}return b[5]}};X509.getPublicKeyHexArrayFromCertHex=function(f){var e=X509.getSubjectPublicKeyPosFromCertHex(f);var b=ASN1HEX.getPosArrayOfChildren_AtObj(f,e);if(b.length!=2){return[]}var d=ASN1HEX.getHexOfV_AtObj(f,b[0]);var c=ASN1HEX.getHexOfV_AtObj(f,b[1]);if(d!=null&&c!=null){return[d,c]}else{return[]}};X509.getHexTbsCertificateFromCert=function(b){var a=ASN1HEX.getStartPosOfV_AtObj(b,0);return a};X509.getPublicKeyHexArrayFromCertPEM=function(c){var d=X509.pemToHex(c);var b=X509.getPublicKeyHexArrayFromCertHex(d);return b};X509.hex2dn=function(e){var f="";var c=ASN1HEX.getPosArrayOfChildren_AtObj(e,0);for(var d=0;dd){throw"key is too short for SigAlg: keylen="+j+","+a}var b="0001";var k="00"+c;var g="";var l=d-b.length-k.length;for(var f=0;fMIT License + */ + +if (typeof KJUR == "undefined" || !KJUR) KJUR = {}; +if (typeof KJUR.jws == "undefined" || !KJUR.jws) KJUR.jws = {}; + +/** + * JSON Web Signature JSON Serialization (JWSJS) class.
+ * @class JSON Web Signature JSON Serialization (JWSJS) class + * @name KJUR.jws.JWSJS + * @property {array of String} aHeader array of Encoded JWS Headers + * @property {String} sPayload Encoded JWS payload + * @property {array of String} aSignature array of Encoded JWS signature value + * @author Kenji Urushima + * @version 1.0 (18 May 2012) + * @requires base64x.js, json-sans-eval.js, jws.js and jsrsasign library + * @see 'jwjws'(JWS JavaScript Library) home page http://kjur.github.com/jsjws/ + * @see 'jwrsasign'(RSA Sign JavaScript Library) home page http://kjur.github.com/jsrsasign/ + * @see IETF I-D JSON Web Signature JSON Serialization (JWS-JS) specification + */ +KJUR.jws.JWSJS = function() { + this.aHeader = []; + this.sPayload = ""; + this.aSignature = []; + + // == initialize =================================================================== + /** + * (re-)initialize this object.
+ * @name init + * @memberOf KJUR.jws.JWSJS + * @function + */ + this.init = function() { + this.aHeader = []; + this.sPayload = ""; + this.aSignature = []; + }; + + /** + * (re-)initialize and set first signature with JWS.
+ * @name initWithJWS + * @memberOf KJUR.jws.JWSJS + * @param {String} sJWS JWS signature to set + * @function + */ + this.initWithJWS = function(sJWS) { + this.init(); + + var jws = new KJUR.jws.JWS(); + jws.parseJWS(sJWS); + + this.aHeader.push(jws.parsedJWS.headB64U); + this.sPayload = jws.parsedJWS.payloadB64U; + this.aSignature.push(jws.parsedJWS.sigvalB64U); + }; + + // == add signature =================================================================== + /** + * add a signature to existing JWS-JS by Header and PKCS1 private key.
+ * @name addSignatureByHeaderKey + * @memberOf KJUR.jws.JWSJS + * @function + * @param {String} sHead JSON string of JWS Header for adding signature. + * @param {String} sPemPrvKey string of PKCS1 private key + */ + this.addSignatureByHeaderKey = function(sHead, sPemPrvKey) { + var sPayload = b64utoutf8(this.sPayload); + + var jws = new KJUR.jws.JWS(); + var sJWS = jws.generateJWSByP1PrvKey(sHead, sPayload, sPemPrvKey); + + this.aHeader.push(jws.parsedJWS.headB64U); + this.aSignature.push(jws.parsedJWS.sigvalB64U); + }; + + /** + * add a signature to existing JWS-JS by Header, Payload and PKCS1 private key.
+ * This is to add first signature to JWS-JS object. + * @name addSignatureByHeaderPayloadKey + * @memberOf KJUR.jws.JWSJS + * @function + * @param {String} sHead JSON string of JWS Header for adding signature. + * @param {String} sPayload string of JWS Payload for adding signature. + * @param {String} sPemPrvKey string of PKCS1 private key + */ + this.addSignatureByHeaderPayloadKey = function(sHead, sPayload, sPemPrvKey) { + var jws = new KJUR.jws.JWS(); + var sJWS = jws.generateJWSByP1PrvKey(sHead, sPayload, sPemPrvKey); + + this.aHeader.push(jws.parsedJWS.headB64U); + this.sPayload = jws.parsedJWS.payloadB64U; + this.aSignature.push(jws.parsedJWS.sigvalB64U); + }; + + // == verify signature =================================================================== + /** + * verify JWS-JS object with array of certificate string.
+ * @name verifyWithCerts + * @memberOf KJUR.jws.JWSJS + * @function + * @param {array of String} aCert array of string for X.509 PEM certificate. + * @return 1 if signature is valid. + * @throw if JWS-JS signature is invalid. + */ + this.verifyWithCerts = function(aCert) { + if (this.aHeader.length != aCert.length) + throw "num headers does not match with num certs"; + if (this.aSignature.length != aCert.length) + throw "num signatures does not match with num certs"; + + var payload = this.sPayload; + var errMsg = ""; + for (var i = 0; i < aCert.length; i++) { + var cert = aCert[i]; + var header = this.aHeader[i]; + var sig = this.aSignature[i]; + var sJWS = header + "." + payload + "." + sig; + + var jws = new KJUR.jws.JWS(); + try { + var result = jws.verifyJWSByPemX509Cert(sJWS, cert); + if (result != 1) { + errMsg += (i + 1) + "th signature unmatch. "; + } + } catch (ex) { + errMsg += (i + 1) + "th signature fail(" + ex + "). "; + } + } + + if (errMsg == "") { + return 1; + } else { + throw errMsg; + } + }; + + /** + * read JWS-JS string.
+ * @name raedJWSJS + * @memberOf KJUR.jws.JWSJS + * @function + * @param {String} string of JWS-JS to load. + * @throw if sJWSJS is malformed or not JSON string. + */ + this.readJWSJS = function(sJWSJS) { + var jws = new KJUR.jws.JWS(); + var oJWSJS = jws.readSafeJSONString(sJWSJS); + if (oJWSJS == null) throw "argument is not JSON string: " + sJWSJS; + + this.aHeader = oJWSJS.headers; + this.sPayload = oJWSJS.payload; + this.aSignature = oJWSJS.signatures; + }; + + // == utility =================================================================== + /** + * get JSON object for this JWS-JS object.
+ * @name getJSON + * @memberOf KJUR.jws.JWSJS + * @function + */ + this.getJSON = function() { + return { "headers": this.aHeader, + "payload": this.sPayload, + "signatures": this.aSignature }; + }; + + /** + * check if this JWS-JS object is empty.
+ * @name isEmpty + * @memberOf KJUR.jws.JWSJS + * @function + * @return 1 if there is no signatures in this object, otherwise 0. + */ + this.isEmpty = function() { + if (this.aHeader.length == 0) return 1; + return 0; + }; +}; + +/*! jws-2.0.3 (c) 2012 Kenji Urushima | kjur.github.com/jsjws/license + */ +/* + * jws.js - JSON Web Signature Class + * + * version: 2.0.3 (2013 Jul 30) + * + * Copyright (c) 2010-2013 Kenji Urushima (kenji.urushima@gmail.com) + * + * This software is licensed under the terms of the MIT License. + * http://kjur.github.com/jsjws/license/ + * + * The above copyright and license notice shall be + * included in all copies or substantial portions of the Software. + */ + +/** + * @fileOverview + * @name jws-2.0.js + * @author Kenji Urushima kenji.urushima@gmail.com + * @version 2.0.3 (2013-Jul-30) + * @since jsjws 1.0 + * @license MIT License + */ + +if (typeof KJUR == "undefined" || !KJUR) KJUR = {}; +if (typeof KJUR.jws == "undefined" || !KJUR.jws) KJUR.jws = {}; + +/** + * JSON Web Signature(JWS) class.
+ * @class JSON Web Signature(JWS) class + * @property {Dictionary} parsedJWS This property is set after JWS signature verification.
+ * Following "parsedJWS_*" properties can be accessed as "parsedJWS.*" because of + * JsDoc restriction. + * @property {String} parsedJWS_headB64U string of Encrypted JWS Header + * @property {String} parsedJWS_payloadB64U string of Encrypted JWS Payload + * @property {String} parsedJWS_sigvalB64U string of Encrypted JWS signature value + * @property {String} parsedJWS_si string of Signature Input + * @property {String} parsedJWS_sigvalH hexadecimal string of JWS signature value + * @property {String} parsedJWS_sigvalBI BigInteger(defined in jsbn.js) object of JWS signature value + * @property {String} parsedJWS_headS string of decoded JWS Header + * @property {String} parsedJWS_headS string of decoded JWS Payload + * @author Kenji Urushima + * @version 1.1 (07 May 2012) + * @requires base64x.js, json-sans-eval.js and jsrsasign library + * @see 'jwjws'(JWS JavaScript Library) home page http://kjur.github.com/jsjws/ + * @see 'jwrsasign'(RSA Sign JavaScript Library) home page http://kjur.github.com/jsrsasign/ + */ +KJUR.jws.JWS = function() { + + // === utility ============================================================= + /** + * check whether a String "s" is a safe JSON string or not.
+ * If a String "s" is a malformed JSON string or an other object type + * this returns 0, otherwise this returns 1. + * @name isSafeJSONString + * @memberOf KJUR.jws.JWS + * @function + * @param {String} s JSON string + * @return {Number} 1 or 0 + */ + this.isSafeJSONString = function(s, h, p) { + var o = null; + try { + o = jsonParse(s); + if (typeof o != "object") return 0; + if (o.constructor === Array) return 0; + if (h) h[p] = o; + return 1; + } catch (ex) { + return 0; + } + }; + + /** + * read a String "s" as JSON object if it is safe.
+ * If a String "s" is a malformed JSON string or not JSON string, + * this returns null, otherwise returns JSON object. + * @name readSafeJSONString + * @memberOf KJUR.jws.JWS + * @function + * @param {String} s JSON string + * @return {Object} JSON object or null + * @since 1.1.1 + */ + this.readSafeJSONString = function(s) { + var o = null; + try { + o = jsonParse(s); + if (typeof o != "object") return null; + if (o.constructor === Array) return null; + return o; + } catch (ex) { + return null; + } + }; + + /** + * get Encoed Signature Value from JWS string.
+ * @name getEncodedSignatureValueFromJWS + * @memberOf KJUR.jws.JWS + * @function + * @param {String} sJWS JWS signature string to be verified + * @return {String} string of Encoded Signature Value + * @throws if sJWS is not comma separated string such like "Header.Payload.Signature". + */ + this.getEncodedSignatureValueFromJWS = function(sJWS) { + if (sJWS.match(/^[^.]+\.[^.]+\.([^.]+)$/) == null) { + throw "JWS signature is not a form of 'Head.Payload.SigValue'."; + } + return RegExp.$1; + }; + + /** + * parse JWS string and set public property 'parsedJWS' dictionary.
+ * @name parseJWS + * @memberOf KJUR.jws.JWS + * @function + * @param {String} sJWS JWS signature string to be parsed. + * @throws if sJWS is not comma separated string such like "Header.Payload.Signature". + * @throws if JWS Header is a malformed JSON string. + * @since 1.1 + */ + this.parseJWS = function(sJWS, sigValNotNeeded) { + if ((this.parsedJWS !== undefined) && + (sigValNotNeeded || (this.parsedJWS.sigvalH !== undefined))) { + return; + } + if (sJWS.match(/^([^.]+)\.([^.]+)\.([^.]+)$/) == null) { + throw "JWS signature is not a form of 'Head.Payload.SigValue'."; + } + var b6Head = RegExp.$1; + var b6Payload = RegExp.$2; + var b6SigVal = RegExp.$3; + var sSI = b6Head + "." + b6Payload; + this.parsedJWS = {}; + this.parsedJWS.headB64U = b6Head; + this.parsedJWS.payloadB64U = b6Payload; + this.parsedJWS.sigvalB64U = b6SigVal; + this.parsedJWS.si = sSI; + + if (!sigValNotNeeded) { + var hSigVal = b64utohex(b6SigVal); + var biSigVal = parseBigInt(hSigVal, 16); + this.parsedJWS.sigvalH = hSigVal; + this.parsedJWS.sigvalBI = biSigVal; + } + + var sHead = b64utoutf8(b6Head); + var sPayload = b64utoutf8(b6Payload); + this.parsedJWS.headS = sHead; + this.parsedJWS.payloadS = sPayload; + + if (! this.isSafeJSONString(sHead, this.parsedJWS, 'headP')) + throw "malformed JSON string for JWS Head: " + sHead; + }; + + // ==== JWS Validation ========================================================= + function _getSignatureInputByString(sHead, sPayload) { + return utf8tob64u(sHead) + "." + utf8tob64u(sPayload); + }; + + function _getHashBySignatureInput(sSignatureInput, sHashAlg) { + var hashfunc = function(s) { return KJUR.crypto.Util.hashString(s, sHashAlg); }; + if (hashfunc == null) throw "hash function not defined in jsrsasign: " + sHashAlg; + return hashfunc(sSignatureInput); + }; + + function _jws_verifySignature(sHead, sPayload, hSig, hN, hE) { + var sSignatureInput = _getSignatureInputByString(sHead, sPayload); + var biSig = parseBigInt(hSig, 16); + return _rsasign_verifySignatureWithArgs(sSignatureInput, biSig, hN, hE); + }; + + /** + * verify JWS signature with naked RSA public key.
+ * This only supports "RS256" and "RS512" algorithm. + * @name verifyJWSByNE + * @memberOf KJUR.jws.JWS + * @function + * @param {String} sJWS JWS signature string to be verified + * @param {String} hN hexadecimal string for modulus of RSA public key + * @param {String} hE hexadecimal string for public exponent of RSA public key + * @return {String} returns 1 when JWS signature is valid, otherwise returns 0 + * @throws if sJWS is not comma separated string such like "Header.Payload.Signature". + * @throws if JWS Header is a malformed JSON string. + */ + this.verifyJWSByNE = function(sJWS, hN, hE) { + this.parseJWS(sJWS); + return _rsasign_verifySignatureWithArgs(this.parsedJWS.si, this.parsedJWS.sigvalBI, hN, hE); + }; + + /** + * verify JWS signature with RSA public key.
+ * This only supports "RS256", "RS512", "PS256" and "PS512" algorithms. + * @name verifyJWSByKey + * @memberOf KJUR.jws.JWS + * @function + * @param {String} sJWS JWS signature string to be verified + * @param {RSAKey} key RSA public key + * @return {Boolean} returns true when JWS signature is valid, otherwise returns false + * @throws if sJWS is not comma separated string such like "Header.Payload.Signature". + * @throws if JWS Header is a malformed JSON string. + */ + this.verifyJWSByKey = function(sJWS, key) { + this.parseJWS(sJWS); + var hashAlg = _jws_getHashAlgFromParsedHead(this.parsedJWS.headP); + var isPSS = this.parsedJWS.headP['alg'].substr(0, 2) == "PS"; + + if (key.hashAndVerify) { + return key.hashAndVerify(hashAlg, + new Buffer(this.parsedJWS.si, 'utf8').toString('base64'), + b64utob64(this.parsedJWS.sigvalB64U), + 'base64', + isPSS); + } else if (isPSS) { + return key.verifyStringPSS(this.parsedJWS.si, + this.parsedJWS.sigvalH, hashAlg); + } else { + return key.verifyString(this.parsedJWS.si, + this.parsedJWS.sigvalH); + } + }; + + /** + * verify JWS signature by PEM formatted X.509 certificate.
+ * This only supports "RS256" and "RS512" algorithm. + * @name verifyJWSByPemX509Cert + * @memberOf KJUR.jws.JWS + * @function + * @param {String} sJWS JWS signature string to be verified + * @param {String} sPemX509Cert string of PEM formatted X.509 certificate + * @return {String} returns 1 when JWS signature is valid, otherwise returns 0 + * @throws if sJWS is not comma separated string such like "Header.Payload.Signature". + * @throws if JWS Header is a malformed JSON string. + * @since 1.1 + */ + this.verifyJWSByPemX509Cert = function(sJWS, sPemX509Cert) { + this.parseJWS(sJWS); + var x509 = new X509(); + x509.readCertPEM(sPemX509Cert); + return x509.subjectPublicKeyRSA.verifyString(this.parsedJWS.si, this.parsedJWS.sigvalH); + }; + + // ==== JWS Generation ========================================================= + function _jws_getHashAlgFromParsedHead(head) { + var sigAlg = head["alg"]; + var hashAlg = ""; + + if (sigAlg != "RS256" && sigAlg != "RS512" && + sigAlg != "PS256" && sigAlg != "PS512") + throw "JWS signature algorithm not supported: " + sigAlg; + if (sigAlg.substr(2) == "256") hashAlg = "sha256"; + if (sigAlg.substr(2) == "512") hashAlg = "sha512"; + return hashAlg; + }; + + function _jws_getHashAlgFromHead(sHead) { + return _jws_getHashAlgFromParsedHead(jsonParse(sHead)); + }; + + function _jws_generateSignatureValueBySI_NED(sHead, sPayload, sSI, hN, hE, hD) { + var rsa = new RSAKey(); + rsa.setPrivate(hN, hE, hD); + + var hashAlg = _jws_getHashAlgFromHead(sHead); + var sigValue = rsa.signString(sSI, hashAlg); + return sigValue; + }; + + function _jws_generateSignatureValueBySI_Key(sHead, sPayload, sSI, key, head) { + var hashAlg = null; + if (typeof head == "undefined") { + hashAlg = _jws_getHashAlgFromHead(sHead); + } else { + hashAlg = _jws_getHashAlgFromParsedHead(head); + } + + var isPSS = head['alg'].substr(0, 2) == "PS"; + + if (key.hashAndSign) { + return b64tob64u(key.hashAndSign(hashAlg, sSI, 'binary', 'base64', isPSS)); + } else if (isPSS) { + return hextob64u(key.signStringPSS(sSI, hashAlg)); + } else { + return hextob64u(key.signString(sSI, hashAlg)); + } + }; + + function _jws_generateSignatureValueByNED(sHead, sPayload, hN, hE, hD) { + var sSI = _getSignatureInputByString(sHead, sPayload); + return _jws_generateSignatureValueBySI_NED(sHead, sPayload, sSI, hN, hE, hD); + }; + + /** + * generate JWS signature by Header, Payload and a naked RSA private key.
+ * This only supports "RS256" and "RS512" algorithm. + * @name generateJWSByNED + * @memberOf KJUR.jws.JWS + * @function + * @param {String} sHead string of JWS Header + * @param {String} sPayload string of JWS Payload + * @param {String} hN hexadecimal string for modulus of RSA public key + * @param {String} hE hexadecimal string for public exponent of RSA public key + * @param {String} hD hexadecimal string for private exponent of RSA private key + * @return {String} JWS signature string + * @throws if sHead is a malformed JSON string. + * @throws if supported signature algorithm was not specified in JSON Header. + */ + this.generateJWSByNED = function(sHead, sPayload, hN, hE, hD) { + if (! this.isSafeJSONString(sHead)) throw "JWS Head is not safe JSON string: " + sHead; + var sSI = _getSignatureInputByString(sHead, sPayload); + var hSigValue = _jws_generateSignatureValueBySI_NED(sHead, sPayload, sSI, hN, hE, hD); + var b64SigValue = hextob64u(hSigValue); + + this.parsedJWS = {}; + this.parsedJWS.headB64U = sSI.split(".")[0]; + this.parsedJWS.payloadB64U = sSI.split(".")[1]; + this.parsedJWS.sigvalB64U = b64SigValue; + + return sSI + "." + b64SigValue; + }; + + /** + * generate JWS signature by Header, Payload and a RSA private key.
+ * This only supports "RS256", "RS512", "PS256" and "PS512" algorithms. + * @name generateJWSByKey + * @memberOf KJUR.jws.JWS + * @function + * @param {String} sHead string of JWS Header + * @param {String} sPayload string of JWS Payload + * @param {RSAKey} RSA private key + * @return {String} JWS signature string + * @throws if sHead is a malformed JSON string. + * @throws if supported signature algorithm was not specified in JSON Header. + */ + this.generateJWSByKey = function(sHead, sPayload, key) { + var obj = {}; + if (!this.isSafeJSONString(sHead, obj, 'headP')) + throw "JWS Head is not safe JSON string: " + sHead; + var sSI = _getSignatureInputByString(sHead, sPayload); + var b64SigValue = _jws_generateSignatureValueBySI_Key(sHead, sPayload, sSI, key, obj.headP); + + this.parsedJWS = {}; + this.parsedJWS.headB64U = sSI.split(".")[0]; + this.parsedJWS.payloadB64U = sSI.split(".")[1]; + this.parsedJWS.sigvalB64U = b64SigValue; + + return sSI + "." + b64SigValue; + }; + + // === sign with PKCS#1 RSA private key ===================================================== + function _jws_generateSignatureValueBySI_PemPrvKey(sHead, sPayload, sSI, sPemPrvKey) { + var rsa = new RSAKey(); + rsa.readPrivateKeyFromPEMString(sPemPrvKey); + var hashAlg = _jws_getHashAlgFromHead(sHead); + var sigValue = rsa.signString(sSI, hashAlg); + return sigValue; + }; + + /** + * generate JWS signature by Header, Payload and a PEM formatted PKCS#1 RSA private key.
+ * This only supports "RS256" and "RS512" algorithm. + * @name generateJWSByP1PrvKey + * @memberOf KJUR.jws.JWS + * @function + * @param {String} sHead string of JWS Header + * @param {String} sPayload string of JWS Payload + * @param {String} string for sPemPrvKey PEM formatted PKCS#1 RSA private key
+ * Heading and trailing space characters in PEM key will be ignored. + * @return {String} JWS signature string + * @throws if sHead is a malformed JSON string. + * @throws if supported signature algorithm was not specified in JSON Header. + * @since 1.1 + */ + this.generateJWSByP1PrvKey = function(sHead, sPayload, sPemPrvKey) { + if (! this.isSafeJSONString(sHead)) throw "JWS Head is not safe JSON string: " + sHead; + var sSI = _getSignatureInputByString(sHead, sPayload); + var hSigValue = _jws_generateSignatureValueBySI_PemPrvKey(sHead, sPayload, sSI, sPemPrvKey); + var b64SigValue = hextob64u(hSigValue); + + this.parsedJWS = {}; + this.parsedJWS.headB64U = sSI.split(".")[0]; + this.parsedJWS.payloadB64U = sSI.split(".")[1]; + this.parsedJWS.sigvalB64U = b64SigValue; + + return sSI + "." + b64SigValue; + }; + +}; + +/*! Mike Samuel (c) 2009 | code.google.com/p/json-sans-eval + */ +// This source code is free for use in the public domain. +// NO WARRANTY EXPRESSED OR IMPLIED. USE AT YOUR OWN RISK. + +// http://code.google.com/p/json-sans-eval/ + +/** + * Parses a string of well-formed JSON text. + * + * If the input is not well-formed, then behavior is undefined, but it is + * deterministic and is guaranteed not to modify any object other than its + * return value. + * + * This does not use `eval` so is less likely to have obscure security bugs than + * json2.js. + * It is optimized for speed, so is much faster than json_parse.js. + * + * This library should be used whenever security is a concern (when JSON may + * come from an untrusted source), speed is a concern, and erroring on malformed + * JSON is *not* a concern. + * + * Pros Cons + * +-----------------------+-----------------------+ + * json_sans_eval.js | Fast, secure | Not validating | + * +-----------------------+-----------------------+ + * json_parse.js | Validating, secure | Slow | + * +-----------------------+-----------------------+ + * json2.js | Fast, some validation | Potentially insecure | + * +-----------------------+-----------------------+ + * + * json2.js is very fast, but potentially insecure since it calls `eval` to + * parse JSON data, so an attacker might be able to supply strange JS that + * looks like JSON, but that executes arbitrary javascript. + * If you do have to use json2.js with untrusted data, make sure you keep + * your version of json2.js up to date so that you get patches as they're + * released. + * + * @param {string} json per RFC 4627 + * @param {function (this:Object, string, *):*} opt_reviver optional function + * that reworks JSON objects post-parse per Chapter 15.12 of EcmaScript3.1. + * If supplied, the function is called with a string key, and a value. + * The value is the property of 'this'. The reviver should return + * the value to use in its place. So if dates were serialized as + * {@code { "type": "Date", "time": 1234 }}, then a reviver might look like + * {@code + * function (key, value) { + * if (value && typeof value === 'object' && 'Date' === value.type) { + * return new Date(value.time); + * } else { + * return value; + * } + * }}. + * If the reviver returns {@code undefined} then the property named by key + * will be deleted from its container. + * {@code this} is bound to the object containing the specified property. + * @return {Object|Array} + * @author Mike Samuel + */ +var jsonParse = (function () { + var number + = '(?:-?\\b(?:0|[1-9][0-9]*)(?:\\.[0-9]+)?(?:[eE][+-]?[0-9]+)?\\b)'; + var oneChar = '(?:[^\\0-\\x08\\x0a-\\x1f\"\\\\]' + + '|\\\\(?:[\"/\\\\bfnrt]|u[0-9A-Fa-f]{4}))'; + var string = '(?:\"' + oneChar + '*\")'; + + // Will match a value in a well-formed JSON file. + // If the input is not well-formed, may match strangely, but not in an unsafe + // way. + // Since this only matches value tokens, it does not match whitespace, colons, + // or commas. + var jsonToken = new RegExp( + '(?:false|true|null|[\\{\\}\\[\\]]' + + '|' + number + + '|' + string + + ')', 'g'); + + // Matches escape sequences in a string literal + var escapeSequence = new RegExp('\\\\(?:([^u])|u(.{4}))', 'g'); + + // Decodes escape sequences in object literals + var escapes = { + '"': '"', + '/': '/', + '\\': '\\', + 'b': '\b', + 'f': '\f', + 'n': '\n', + 'r': '\r', + 't': '\t' + }; + function unescapeOne(_, ch, hex) { + return ch ? escapes[ch] : String.fromCharCode(parseInt(hex, 16)); + } + + // A non-falsy value that coerces to the empty string when used as a key. + var EMPTY_STRING = new String(''); + var SLASH = '\\'; + + // Constructor to use based on an open token. + var firstTokenCtors = { '{': Object, '[': Array }; + + var hop = Object.hasOwnProperty; + + return function (json, opt_reviver) { + // Split into tokens + var toks = json.match(jsonToken); + // Construct the object to return + var result; + var tok = toks[0]; + var topLevelPrimitive = false; + if ('{' === tok) { + result = {}; + } else if ('[' === tok) { + result = []; + } else { + // The RFC only allows arrays or objects at the top level, but the JSON.parse + // defined by the EcmaScript 5 draft does allow strings, booleans, numbers, and null + // at the top level. + result = []; + topLevelPrimitive = true; + } + + // If undefined, the key in an object key/value record to use for the next + // value parsed. + var key; + // Loop over remaining tokens maintaining a stack of uncompleted objects and + // arrays. + var stack = [result]; + for (var i = 1 - topLevelPrimitive, n = toks.length; i < n; ++i) { + tok = toks[i]; + + var cont; + switch (tok.charCodeAt(0)) { + default: // sign or digit + cont = stack[0]; + cont[key || cont.length] = +(tok); + key = void 0; + break; + case 0x22: // '"' + tok = tok.substring(1, tok.length - 1); + if (tok.indexOf(SLASH) !== -1) { + tok = tok.replace(escapeSequence, unescapeOne); + } + cont = stack[0]; + if (!key) { + if (cont instanceof Array) { + key = cont.length; + } else { + key = tok || EMPTY_STRING; // Use as key for next value seen. + break; + } + } + cont[key] = tok; + key = void 0; + break; + case 0x5b: // '[' + cont = stack[0]; + stack.unshift(cont[key || cont.length] = []); + key = void 0; + break; + case 0x5d: // ']' + stack.shift(); + break; + case 0x66: // 'f' + cont = stack[0]; + cont[key || cont.length] = false; + key = void 0; + break; + case 0x6e: // 'n' + cont = stack[0]; + cont[key || cont.length] = null; + key = void 0; + break; + case 0x74: // 't' + cont = stack[0]; + cont[key || cont.length] = true; + key = void 0; + break; + case 0x7b: // '{' + cont = stack[0]; + stack.unshift(cont[key || cont.length] = {}); + key = void 0; + break; + case 0x7d: // '}' + stack.shift(); + break; + } + } + // Fail if we've got an uncompleted object. + if (topLevelPrimitive) { + if (stack.length !== 1) { throw new Error(); } + result = result[0]; + } else { + if (stack.length) { throw new Error(); } + } + + if (opt_reviver) { + // Based on walk as implemented in http://www.json.org/json2.js + var walk = function (holder, key) { + var value = holder[key]; + if (value && typeof value === 'object') { + var toDelete = null; + for (var k in value) { + if (hop.call(value, k) && value !== holder) { + // Recurse to properties first. This has the effect of causing + // the reviver to be called on the object graph depth-first. + + // Since 'this' is bound to the holder of the property, the + // reviver can access sibling properties of k including ones + // that have not yet been revived. + + // The value returned by the reviver is used in place of the + // current value of property k. + // If it returns undefined then the property is deleted. + var v = walk(value, k); + if (v !== void 0) { + value[k] = v; + } else { + // Deleting properties inside the loop has vaguely defined + // semantics in ES3 and ES3.1. + if (!toDelete) { toDelete = []; } + toDelete.push(k); + } + } + } + if (toDelete) { + for (var i = toDelete.length; --i >= 0;) { + delete value[toDelete[i]]; + } + } + } + return opt_reviver.call(holder, key, value); + }; + result = walk({ '': result }, ''); + } + + return result; + }; +})(); diff --git a/mailui.html b/mailui.html new file mode 100644 index 0000000..43759f6 --- /dev/null +++ b/mailui.html @@ -0,0 +1,174 @@ + + + + + + + ~titleText~ + + + + + + + + + + ~titleText~ + + + + + + + + + + +
+
+ + + + + + + +
+ ~headerMessage~ +
+ + + + + + + + + + +
+ ~mainMessage~ +
+ ~buttonText~ +
+ Thank you for using this script. +
+
+ +
+
+ + diff --git a/readme.gs b/readme.gs new file mode 100644 index 0000000..88c2e8b --- /dev/null +++ b/readme.gs @@ -0,0 +1,113 @@ +/* +* +* NAME: +* +* Transfer Ownership +* +* VERSION: +* +* 1.2.3.1 (2015-01-15) +* +* LICENSE: +* +* Copyright (C) 2015 Václav VESELÝ ⊂ ICTOI, s.r.o.; www.ictoi.com +* +* This program is free software: you can redistribute it and/or modify +* it under the terms of the GNU General Public License as published by +* the Free Software Foundation, either version 3 of the License, or +* (at your option) any later version. +* +* This program is distributed in the hope that it will be useful, +* but WITHOUT ANY WARRANTY; without even the implied warranty of +* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +* GNU General Public License for more details. +* +* You should have received a copy of the GNU General Public License +* along with this program. If not, see . +* +*/ + +/* Google Apps Domain-Wide Delegation of Authority help links +* +* https://developers.google.com/drive/web/delegation#delegate_domain-wide_authority_to_your_service_account +* https://developers.google.com/google-apps/documents-list/#using_google_apps_administrative_access_to_impersonate_other_domain_users +* https://developers.google.com/gmail/xoauth2_protocol +* https://developers.google.com/drive/web/push +* https://developers.google.com/accounts/docs/OAuth2ServiceAccount +* https://developers.google.com/console/help/ +* https://github.com/mcdanielgilbert/gas-oauth2-gae +* http://stackoverflow.com/questions/8999932/generating-rsa-sha1-signatures-with-javascript +* http://stackoverflow.com/questions/13652706/is-it-possible-to-impersonate-domains-users-with-google-drive-api-using-google +* http://stackoverflow.com/questions/25943631/how-can-i-create-google-apps-user-account-programatically/25950294#25950294 +* curl -H "Authorization: Bearer TOKEN" https://www.googleapis.com/drive/v2/files +*/ + +/* +* KNOWN LIMITS as on 2014-11-07 on Google Apps for Work +* +* https://developers.google.com/apps-script/guides/services/quotas +* +* Script runtime = 6 min / execution +* Triggers total runtime = 6 hr / day +* URL Fetch calls = 100,000 / day +* URL Fetch data received = 100MB / day +* Properties write = 500,000 / day +* Properties total storage = 500kB / property store +* Properties value size = 9kB / val +* One cache file size = 10MB +* Continuation tokens are generally valid for one week +* Does not work on Google Apps Free edition for files other than native as in https://support.google.com/drive/answer/2494892?hl=en +*/ + +/* +* PREREQUISITES +* +* script has to be run as a domain super administrator see https://support.google.com/a/answer/2405986 +*/ + +/* +* INSTALLATION +* +* login as domain super administrator +* open new tab +* browse to google developer console > https://console.developers.google.com/project +* create new project +* choose whatever name and project id +* navigate to "APIs & auth > Credentials > OAuth" and click "Create new Client ID" +* choose "Service account" +* copy EMAIL ADDRESS to script global variable SERVICE_ACCOUNT_EMAIL (replace the sample) +* copy CLIENT ID for later use to some text editor +* get openssl (don feed gluttons use Linux :], if on Windows try http://slproweb.com/products/Win32OpenSSL.html) +* transform your P12 key to base64 pem via terminal "openssl pkcs12 -in ~/certfilename.p12 -nodes | openssl rsa | base64 > ~/certfilename.pem.b64" (as password use 'notasecret' or whatever given by console) (adjust the command with your paths and system specifics) +* copy all text contained in openssl generated file via some text editor and remove all newlines so you have one long text string +* copy the long text string from previous step to script global variable GOOGLE_DEV_CONSOLE_OAUTH_P12_BASE64 (replace the sample) +* in the script replace all global variables in Globals.gs preferable ending with "// change for production" to whatever you want on your domain +* navigate to "APIs & auth > APIs > Browse APIs" an allow all APIs that you are going to use (in this example Drive API) +* open new tab +* browse to google apps admin console > https://admin.google.com/ +* navigate to "Security > Advanced settings (may be hidden under Show more) > Authentication > Manage API client access" +* copy CLIENT ID stored in previous step to "Authorized API clients" +* fill all scopes to "One or More API Scopes"; the scopes must be the same as in global variable SCOPES_SPACE_SEPARATED (see scopes here https://developers.google.com/drive/web/scopes) +* click Authorize +* open script tab +* do first dry run to authorize the script +*/ + +/* +* DEFAULT SCRIPT OAUTH SCOPES +* https://mail.google.com/ +* https://www.googleapis.com/auth/drive +* https://www.googleapis.com/auth/drive.apps.readonly +* https://www.googleapis.com/auth/script.external_request +*/ + +/* +* GENERATE DRIVE TEST STRUCTURE +* +* generate random dir structure with shell script and upload to drive +* http://stackoverflow.com/questions/13400312/linux-create-random-directory-file-hierarchy +* +* OUTDIR, ASCIIONLY, DIRDEPTH, MAXFIRSTLEVELDIRS, MAXDIRCHILDREN, MAXDIRNAMELEN, MAXFILECHILDREN, MAXFILENAMELEN, MAXFILESIZE +* ./rndtree.sh ./rndtree_b 1 6 8 50 8 1 8 1 // dynamic +* ./rndtree.sh ./rndtree_b 1 5 8 500 8 1 8 1 // steep +*/ diff --git a/webservice.gs b/webservice.gs new file mode 100644 index 0000000..e393610 --- /dev/null +++ b/webservice.gs @@ -0,0 +1,22 @@ +/** +* publishes control panel +* @param {Object} webservice parameters +* @return {HtmlOutput} html output +*/ +function doGet(request) { + if (request.parameters.hasOwnProperty("key")) { + // check request secret + if (request.parameters.key == GVAR.WEB_SERVICE_KEY) { + return HtmlService + .createTemplateFromFile(GVAR.WEBSERVICE_UI_FILENAME) + .evaluate() + .setTitle(GVAR.SCRIPT_NAME) + .setSandboxMode(HtmlService.SandboxMode.NATIVE); + //.setSandboxMode(HtmlService.SandboxMode.IFRAME); + } else { + return ContentService + .createTextOutput("Unauthorized access!") + .setMimeType(ContentService.MimeType.TEXT); + } + } +} diff --git a/webui.html b/webui.html new file mode 100644 index 0000000..f532847 --- /dev/null +++ b/webui.html @@ -0,0 +1,217 @@ + + + + + +Google Apps Script + + + + + + + + + + +
+

+

Control Panel

+
+
+
+
+
+ Main controls +
+ + + +
+
+ + + +
+
+ + + + +
+
+ + + + +
+
+ + + +
+
    +
  • Click 'Run' button to get triggers...
  • +
+
+ + + + +
+
+ + + +
+
+ + + + +
+
+ + >Open URL +
+
+
+
+
+ Global variables +
+ + > +
+
+ + > +
+
+ + > +
+
+ + > +
+
+ + > +
+
+ + > +
+ +
+
+
+
+ Actual variables and outputs +
+ + > +
+
+ + > +
+
+ + > +
+ +
+
+
+
+
+ + + + +
+
+ + + +
+
    +
  • Click 'Run' button to get file log...
  • +
+
+
+
+ + + + +