CUST: - FwUpdateBuilder: - catch wrong production password to avoid overwriting with new one - safe build denied

This commit is contained in:
Thomas Wiedebusch
2024-05-31 11:12:44 +02:00
parent 6d91ad17a8
commit 28ce4c7e57
@@ -9,6 +9,7 @@ using Newtonsoft.Json;
using Xylem.Common.CommonCore.Configuration;
using Xylem.Common.CommonCore.Consts;
using Xylem.Common.Cryptology.Security;
using Xylem.Common.Hardware.WaterMeter.Genesis.Applications.Properties;
using Xylem.Common.Hardware.WaterMeter.Genesis.GenesisCore;
using Xylem.Common.Hardware.WaterMeter.Genesis.GenesisFile;
using Xylem.Common.Hardware.WaterMeter.Genesis.GenesisPwd;
@@ -316,6 +317,10 @@ namespace Xylem.ServiceFwUpdate.Common.FwUpdateDb
/// - Used the <see cref="MeterPwdFile.BuildPwdFile"/> as common routine for password hash file generation out of
/// the raw text passwords. This routine verifies the password container.
/// </remarks>
/// <remarks date="2024-May-17" author="Thomas Wiedebusch">
/// - Avoid generation of password file if new generated Lvl8 password is not the Lvl8 production password,
/// if the password is the skeleton key the password file was never generated so go ahead.
/// </remarks>
public Boolean DownloadCordonelPwdFromDb(String pcbId, out PasswordContainer passwordContainer)
{
passwordContainer = new PasswordContainer();
@@ -333,6 +338,14 @@ namespace Xylem.ServiceFwUpdate.Common.FwUpdateDb
return false;
}
// Avoid generation of password file if new generated Lvl8 password is not the Lvl8 production password,
// if the password is the skeleton key the password file was never generated so go ahead
if (meterPwdDb.Password != meterPwdDb.Skeleton &&
meterPwdDb.Password != Encoding.UTF8.GetString(meterPwdDb.ListOfPasswords[MeterPwdDb.PwdLevel8Idx]))
{
throw new ApplicationException("Wrong production password");
}
DbIsConnected = true;
passwordContainer.PcbId = pcbId;
passwordContainer.SkeletonKey =
@@ -391,7 +404,7 @@ namespace Xylem.ServiceFwUpdate.Common.FwUpdateDb
catch (Exception ex)
{
DbIsConnected = false;
throw new ApplicationException(ex.Message + $" PcbId: {pcbId}");
throw new ApplicationException(ex.Message + $" - PcbId: {pcbId}");
}
}
/// <summary>