mirror of
https://github.com/sonr-io/sonr.git
synced 2026-08-03 18:01:39 +00:00
* **refactor: remove nebula static file serving** * **feat: Add login, register, and authorize sections** * **feat: implement registration form UI** * **refactor: abstract template rendering to ctx module** * **feat: add deployment target for Highway gateway** * **feat: migrate Highway gateway to Cloudflare Workers** * **feat: refactor nebula routes to components** * **chore(deps): remove unused dependencies** * **chore(deps): remove unused dependencies** * **feat: add user and relaying party entities** * **refactor: remove unused imports** * * **feat: add motion scale-in and opacity-in animations** * **refactor: move dwn and orm packages to internal** * **refactor: update imports to use relative paths** * **refactor: rename build targets for clarity** * **feat: add RelayingPartyEntity model** * **refactor: rename creds templates to credentials** * **refactor: remove unused entity model** * **refactor: move models to internal package** * **refactor: move models package to internal/orm** * **feat: implement broadcast channel context** * **feat: remove config upload step** * **feat: remove unused configuration files** * **feat: migrate authentication logic to workers** * **feat: remove cloudflared dependency** * **refactor: move client related routes to 'routes/client.go'** * **feat: implement macaroon middleware** * **refactor: move fetch package to cmd/motr** * **feat: remove auth and grant endpoints** * **docs: add conceptual descriptions to did module** <sub><a href="https://huly.app/guest/sonrhq?token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJsaW5rSWQiOiI2NzA4MTIyNmM3ZDZhNTZhOGY4ZGFjOTciLCJndWVzdCI6InRydWUiLCJlbWFpbCI6IiNndWVzdEBoYy5lbmdpbmVlcmluZyIsIndvcmtzcGFjZSI6InctcHJhZC1zb25yaHEtNjVlZjcyZDQtY2UyOGQ0ODJjNi00ZWY4ZDAifQ.j-w5jk5Ji-0vCkaxVaK8pDMIOhRsXmG7o6oZictoHYE">Huly®: <b>ENG-1057</b></a></sub>
96 lines
2.4 KiB
Go
96 lines
2.4 KiB
Go
package ctx
|
|
|
|
import (
|
|
"fmt"
|
|
"net/http"
|
|
"time"
|
|
|
|
"github.com/labstack/echo/v4"
|
|
"gopkg.in/macaroon.v2"
|
|
)
|
|
|
|
const (
|
|
OriginMacroonCaveat MacroonCaveat = "origin"
|
|
ScopesMacroonCaveat MacroonCaveat = "scopes"
|
|
SubjectMacroonCaveat MacroonCaveat = "subject"
|
|
ExpMacroonCaveat MacroonCaveat = "exp"
|
|
TokenMacroonCaveat MacroonCaveat = "token"
|
|
)
|
|
|
|
var MacroonCaveats = []MacroonCaveat{OriginMacroonCaveat, ScopesMacroonCaveat, SubjectMacroonCaveat, ExpMacroonCaveat, TokenMacroonCaveat}
|
|
|
|
type MacroonCaveat string
|
|
|
|
func (c MacroonCaveat) Equal(other string) bool {
|
|
return string(c) == other
|
|
}
|
|
|
|
func (c MacroonCaveat) String() string {
|
|
return string(c)
|
|
}
|
|
|
|
func (c MacroonCaveat) Verify(value string) error {
|
|
switch c {
|
|
case OriginMacroonCaveat:
|
|
return nil
|
|
case ScopesMacroonCaveat:
|
|
return nil
|
|
case SubjectMacroonCaveat:
|
|
return nil
|
|
case ExpMacroonCaveat:
|
|
// Check if the expiration time is still valid
|
|
exp, err := time.Parse(time.RFC3339, value)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
if time.Now().After(exp) {
|
|
return fmt.Errorf("expired")
|
|
}
|
|
return nil
|
|
case TokenMacroonCaveat:
|
|
return nil
|
|
default:
|
|
return fmt.Errorf("unknown caveat: %s", c)
|
|
}
|
|
}
|
|
|
|
func MacaroonMiddleware(secretKeyStr string, location string) echo.MiddlewareFunc {
|
|
secretKey := []byte(secretKeyStr)
|
|
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
|
return func(c echo.Context) error {
|
|
// Extract the macaroon from the Authorization header
|
|
auth := c.Request().Header.Get("Authorization")
|
|
if auth == "" {
|
|
return c.JSON(http.StatusUnauthorized, map[string]string{"error": "Missing Authorization header"})
|
|
}
|
|
|
|
// Decode the macaroon
|
|
mac, err := macaroon.Base64Decode([]byte(auth))
|
|
if err != nil {
|
|
return c.JSON(http.StatusBadRequest, map[string]string{"error": "Invalid macaroon encoding"})
|
|
}
|
|
|
|
token, err := macaroon.New(secretKey, mac, location, macaroon.LatestVersion)
|
|
if err != nil {
|
|
return c.JSON(http.StatusBadRequest, map[string]string{"error": "Invalid macaroon"})
|
|
}
|
|
|
|
// Verify the macaroon
|
|
err = token.Verify(secretKey, func(caveat string) error {
|
|
for _, c := range MacroonCaveats {
|
|
if c.String() == caveat {
|
|
return nil
|
|
}
|
|
}
|
|
return nil // Return nil if the caveat is valid
|
|
}, nil)
|
|
if err != nil {
|
|
return c.JSON(http.StatusUnauthorized, map[string]string{"error": "Invalid macaroon"})
|
|
}
|
|
|
|
// Macaroon is valid, proceed to the next handler
|
|
return next(c)
|
|
}
|
|
}
|
|
}
|