mirror of
https://github.com/sonr-io/sonr.git
synced 2026-08-03 09:51:39 +00:00
- **deps: remove tigerbeetle-go dependency** - **refactor: remove unused landing page components and models** - **feat: add pin and publish vault handlers** - **refactor: move payment and credential services to webui browser package** - **refactor: remove unused credentials management components** - **feat: add landing page components and middleware for credentials and payments** - **refactor: remove unused imports in vault config** - **refactor: remove unused bank, DID, and DWN gRPC clients** - **refactor: rename client files and improve code structure** - **feat: add session middleware helpers and landing page components** - **feat: add user profile registration flow** - **feat: Implement WebAuthn registration flow** - **feat: add error view for users without WebAuthn devices** - **chore: update htmx to include extensions** - **refactor: rename pin handler to claim handler and update routes** - **chore: update import paths after moving UI components and styles** - **fix: address potential server errors by handling and logging them properly** - **refactor: move vault config to gateway package and update related dependencies** - **style: simplify form styling and remove unnecessary components** - **feat: improve UI design for registration flow** - **feat: implement passkey-based authentication** - **refactor: migrate registration forms to use reusable form components** - **refactor: remove tailwindcss setup and use CDN instead** - **style: update submit button style to use outline variant** - **refactor: refactor server and IPFS client, remove MPC encryption** - **refactor: Abstract keyshare functionality and improve message encoding** - **refactor: improve keyset JSON marshaling and error handling** - **feat: add support for digital signatures using MPC keys** - **fix: Refactor MarshalJSON to use standard json.Marshal for Message serialization** - **fix: Encode messages before storing in keyshare structs** - **style: update form input styles for improved user experience** - **refactor: improve code structure in registration handlers** - **refactor: consolidate signer middleware and IPFS interaction** - **refactor: rename MPC signing and refresh protocol functions** - **refactor: update hway configuration loading mechanism** - **feat: integrate database support for sessions and users** - **refactor: remove devnet infrastructure and simplify build process** - **docs(guides): add Sonr DID module guide** - **feat: integrate progress bar into registration form** - **refactor: migrate WebAuthn dependencies to protocol package** - **feat: enhance user registration with passkey integration and improved form styling** - **refactor: move gateway view handlers to internal pages package** - **refactor: Move address package to MPC module** - **feat: integrate turnstile for registration** - **style: remove unnecessary size attribute from buttons** - **refactor: rename cookie package to session/cookie** - **refactor: remove unnecessary types.Session dependency** - **refactor: rename pkg/core to pkg/chain** - **refactor: simplify deployment process by removing testnet-specific Taskfile and devbox configuration** - **feat: add error redirect functionality and improve routes** - **feat: implement custom error handling for gateway** - **chore: update version number to 0.0.7 in template** - **feat: add IPFS client implementation** - **feat: Implement full IPFS client interface with comprehensive methods** - **refactor: improve IPFS client path handling** - **refactor: Move UCAN middleware to controller package** - **feat: add UCAN middleware to motr** - **refactor: update libp2p dependency** - **docs: add UCAN specification document** - **refactor: move UCAN controller logic to common package** - **refactor: rename exports.go to common.go** - **feat: add UCAN token support** - **refactor: migrate UCAN token parsing to dedicated package** - **refactor: improve CometBFT and app config initialization** - **refactor: improve deployment scripts and documentation** - **feat: integrate IPFS and producer middleware** - **refactor: rename agent directory to aider** - **fix: correct libp2p import path** - **refactor: remove redundant dependency** - **cleanup: remove unnecessary test files** - **refactor: move attention types to crypto/ucan package** - **feat: expand capabilities and resource types for UCANs** - **refactor: rename sonr.go to codec.go and update related imports** - **feat: add IPFS-based token store** - **feat: Implement IPFS-based token store with caching and UCAN integration** - **feat: Add dynamic attenuation constructor for UCAN presets** - **fix: Handle missing or invalid attenuation data with EmptyAttenuation** - **fix: Update UCAN attenuation tests with correct capability types** - **feat: integrate UCAN-based authorization into the producer middleware** - **refactor: remove unused dependency on go-ucan** - **refactor: Move address handling logic to DID module** - **feat: Add support for compressed and uncompressed Secp256k1 public keys in didkey** - **test: Add test for generating DID key from MPC keyshares** - **feat: Add methods for extracting compressed and uncompressed public keys in share types** - **feat: Add BaseKeyshare struct with public key conversion methods** - **refactor: Use compressed and uncompressed public keys in keyshare, fix public key usage in tests and verification** - **feat: add support for key generation policy type** - **fix: correct typo in VaultPermissions constant** - **refactor: move JWT related code to ucan package** - **refactor: move UCAN JWT and source code to spec package**
157 lines
4.8 KiB
Go
157 lines
4.8 KiB
Go
package session
|
|
|
|
import (
|
|
"regexp"
|
|
"strings"
|
|
|
|
"github.com/go-webauthn/webauthn/protocol"
|
|
"github.com/go-webauthn/webauthn/protocol/webauthncose"
|
|
"github.com/labstack/echo/v4"
|
|
"github.com/segmentio/ksuid"
|
|
|
|
"github.com/onsonr/sonr/pkg/common"
|
|
)
|
|
|
|
const kWebAuthnTimeout = 6000
|
|
|
|
// TODO: Returns fixed chain ID for testing.
|
|
func GetChainID(c echo.Context) string {
|
|
return "sonr-testnet-1"
|
|
}
|
|
|
|
// SetVaultAddress sets the address of the vault
|
|
func SetVaultAddress(c echo.Context, address string) error {
|
|
return common.WriteCookie(c, common.SonrAddress, address)
|
|
}
|
|
|
|
// SetVaultAuthorization sets the UCAN CID of the vault
|
|
func SetVaultAuthorization(c echo.Context, ucanCID string) error {
|
|
common.HeaderWrite(c, common.Authorization, formatAuth(ucanCID))
|
|
return nil
|
|
}
|
|
|
|
// ╭───────────────────────────────────────────────────────────╮
|
|
// │ Initialization │
|
|
// ╰───────────────────────────────────────────────────────────╯
|
|
|
|
func loadOrGenKsuid(c echo.Context) error {
|
|
var (
|
|
sessionID string
|
|
err error
|
|
)
|
|
|
|
// Setup genKsuid function
|
|
genKsuid := func() string {
|
|
return ksuid.New().String()
|
|
}
|
|
|
|
// Attempt to read the session ID from the "session" cookie
|
|
if ok := common.CookieExists(c, common.SessionID); !ok {
|
|
sessionID = genKsuid()
|
|
} else {
|
|
sessionID, err = common.ReadCookie(c, common.SessionID)
|
|
if err != nil {
|
|
sessionID = genKsuid()
|
|
}
|
|
}
|
|
common.WriteCookie(c, common.SessionID, sessionID)
|
|
return nil
|
|
}
|
|
|
|
// ╭───────────────────────────────────────────────────────────╮
|
|
// │ Extraction │
|
|
// ╰───────────────────────────────────────────────────────────╯
|
|
|
|
func extractPeerInfo(c echo.Context) (string, string) {
|
|
var chal protocol.URLEncodedBase64
|
|
id, _ := common.ReadCookie(c, common.SessionID)
|
|
chalRaw, _ := common.ReadCookieBytes(c, common.SessionChallenge)
|
|
chal.UnmarshalJSON(chalRaw)
|
|
|
|
return id, common.Base64Encode(chal)
|
|
}
|
|
|
|
func extractBrowserInfo(c echo.Context) (string, string) {
|
|
secCHUA := common.HeaderRead(c, common.UserAgent)
|
|
|
|
// If common.is empty, return empty BrowserInfo
|
|
if secCHUA == "" {
|
|
return "N/A", "-1"
|
|
}
|
|
|
|
// Split the common.into individual browser entries
|
|
var (
|
|
name string
|
|
ver string
|
|
)
|
|
entries := strings.Split(strings.TrimSpace(secCHUA), ",")
|
|
for _, entry := range entries {
|
|
// Remove leading/trailing spaces and quotes
|
|
entry = strings.TrimSpace(entry)
|
|
|
|
// Use regex to extract the browser name and version
|
|
re := regexp.MustCompile(`"([^"]+)";v="([^"]+)"`)
|
|
matches := re.FindStringSubmatch(entry)
|
|
|
|
if len(matches) == 3 {
|
|
browserName := matches[1]
|
|
version := matches[2]
|
|
|
|
// Skip "Not A;Brand"
|
|
if !validBrowser(browserName) {
|
|
continue
|
|
}
|
|
|
|
// Store the first valid browser info as fallback
|
|
name = browserName
|
|
ver = version
|
|
}
|
|
}
|
|
return name, ver
|
|
}
|
|
|
|
func validBrowser(name string) bool {
|
|
return name != common.BrowserNameUnknown.String() && name != common.BrowserNameChromium.String()
|
|
}
|
|
|
|
// ╭───────────────────────────────────────────────────────────╮
|
|
// │ Authentication │
|
|
// ╰───────────────────────────────────────────────────────────╯
|
|
|
|
func buildUserEntity(userID string) protocol.UserEntity {
|
|
return protocol.UserEntity{
|
|
ID: userID,
|
|
}
|
|
}
|
|
|
|
// returns the base options for registering a new user without challenge or user entity.
|
|
func baseRegisterOptions() *protocol.PublicKeyCredentialCreationOptions {
|
|
return &protocol.PublicKeyCredentialCreationOptions{
|
|
Timeout: kWebAuthnTimeout,
|
|
Attestation: protocol.PreferDirectAttestation,
|
|
AuthenticatorSelection: protocol.AuthenticatorSelection{
|
|
AuthenticatorAttachment: "platform",
|
|
ResidentKey: protocol.ResidentKeyRequirementPreferred,
|
|
UserVerification: "preferred",
|
|
},
|
|
Parameters: []protocol.CredentialParameter{
|
|
{
|
|
Type: "public-key",
|
|
Algorithm: webauthncose.AlgES256,
|
|
},
|
|
{
|
|
Type: "public-key",
|
|
Algorithm: webauthncose.AlgES256K,
|
|
},
|
|
{
|
|
Type: "public-key",
|
|
Algorithm: webauthncose.AlgEdDSA,
|
|
},
|
|
},
|
|
}
|
|
}
|
|
|
|
func formatAuth(ucanCID string) string {
|
|
return "Bearer " + ucanCID
|
|
}
|