Fix authenticated endpoints
parent: tbd commit: 1400b06
1 | use ; |
2 | |
3 | use Error; |
4 | use Future; |
5 | use |
6 | , |
7 | , | Instance
8 | , | User
9 | ; |
10 | use ; |
11 | use |
12 | , |
13 | , |
14 | , | Sha256
15 | , | Verifier
16 | RsaPublicKey, |
17 | ; |
18 | use ; |
19 | use Value; |
20 | |
21 | use crate ConnectionState; |
22 | |
23 | ; |
24 | |
25 | |
26 | type Target = ; |
27 | |
28 | |
29 | &self.0 |
30 | |
31 | |
32 | |
33 | ; |
34 | |
35 | |
36 | |
37 | |
38 | Missing, |
39 | // #[error("{0}")] |
40 | // InstanceAuthentication(#[from] Error), |
41 | |
42 | InvalidToken, |
43 | |
44 | Other, |
45 | |
46 | |
47 | ; |
48 | |
49 | |
50 | |
51 | &self.0 |
52 | |
53 | |
54 | |
55 | |
56 | |
57 | async ; |
58 | |
59 | |
60 | |
61 | |
62 | async |
63 | network_message: &NetworkMessage, |
64 | state: &ConnectionState, |
65 | |
66 | let message: AuthenticatedPayload = |
67 | map_err?; | from_slice .
68 | |
69 | let = message |
70 | .source |
71 | .iter |
72 | .filter_map |
73 | if let User = auth |
74 | Some |
75 | else |
76 | None |
77 | |
78 | |
79 | .next |
80 | .ok_or_else?; |
81 | |
82 | let authenticated_instance = |
83 | ?; | from_message .await
84 | |
85 | let public_key_raw = public_key .await?; |
86 | let verification_key = from_rsa_pem .unwrap; |
87 | |
88 | let data: = decode |
89 | auth_token.as_ref, |
90 | &verification_key, |
91 | & new, |
92 | |
93 | .unwrap; |
94 | |
95 | if data.claims.user != *auth_user |
96 | || data.claims.generated_for != *authenticated_instance.inner |
97 | |
98 | Err |
99 | else |
100 | Ok |
101 | |
102 | |
103 | |
104 | |
105 | |
106 | |
107 | async |
108 | network_message: &NetworkMessage, |
109 | state: &ConnectionState, |
110 | |
111 | let message: AuthenticatedPayload = |
112 | map_err?; | from_slice .
113 | |
114 | let = message |
115 | .source |
116 | .iter |
117 | .filter_map |
118 | if let Instance |
119 | instance, |
120 | signature, |
121 | = auth |
122 | |
123 | Some |
124 | else |
125 | None |
126 | |
127 | |
128 | .next |
129 | // TODO: Instance authentication error |
130 | .ok_or_else?; |
131 | |
132 | let public_key = |
133 | let cached_keys = state.cached_keys.read .await; |
134 | |
135 | if let Some = cached_keys.get |
136 | key.clone |
137 | else |
138 | drop; |
139 | let mut cached_keys = state.cached_keys.write .await; |
140 | let key = public_key .await?; |
141 | let public_key = from_pkcs1_pem .unwrap; |
142 | cached_keys.insert; |
143 | public_key |
144 | |
145 | ; |
146 | |
147 | let verifying_key: = new; |
148 | |
149 | verifying_key.verify |
150 | &message.payload, |
151 | & try_from .unwrap, |
152 | ?; |
153 | |
154 | Ok |
155 | |
156 | |
157 | |
158 | |
159 | |
160 | |
161 | T: , |
162 | S: Send + Sync + 'static, |
163 | |
164 | async |
165 | Ok |
166 | |
167 | |
168 | |
169 | |
170 | |
171 | async ; |
172 | |
173 | |
174 | |
175 | |
176 | T: FnOnce(T1) -> F + Clone + Send + 'static, |
177 | F: + Send, |
178 | T1: + Send, |
179 | S: Send + Sync, |
180 | E: Error + Send + Sync + 'static, |
181 | |
182 | async |
183 | let value = T1 from_message .await?; |
184 | self .await.map_err |
185 | |
186 | |
187 | |
188 | |
189 | |
190 | |
191 | T: FnOnce(T1, T2) -> F + Clone + Send + 'static, |
192 | F: + Send, |
193 | T1: + Send, |
194 | T2: + Send, |
195 | S: Send + Sync, |
196 | E: Error + Send + Sync + 'static, |
197 | |
198 | async |
199 | let value = T1 from_message .await?; |
200 | let value_2 = T2 from_message .await?; |
201 | self .await.map_err |
202 | |
203 | |
204 | |
205 | |
206 | |
207 | |
208 | T: FnOnce(T1, T2, T3) -> F + Clone + Send + 'static, |
209 | F: + Send, |
210 | T1: + Send, |
211 | T2: + Send, |
212 | T3: + Send, |
213 | S: Send + Sync, |
214 | E: Error + Send + Sync + 'static, |
215 | |
216 | async |
217 | let value = T1 from_message .await?; |
218 | let value_2 = T2 from_message .await?; |
219 | let value_3 = T3 from_message .await?; |
220 | |
221 | self |
222 | .await |
223 | .map_err |
224 | |
225 | |
226 | |
227 | ; |
228 | |
229 | |
230 | |
231 | |
232 | T: Clone + Send + Sync, |
233 | |
234 | async |
235 | Ok |
236 | |
237 | |
238 | |
239 | // Temp |
240 | |
241 | |
242 | |
243 | T: DeserializeOwned + Send + Sync + Serialize, |
244 | S: Clone + Send + Sync, |
245 | |
246 | async |
247 | let payload: AuthenticatedPayload = from_slice?; |
248 | Ok |
249 | |
250 | |
251 | |
252 | ; |
253 | |
254 | async |
255 | let key = get |
256 | .await? |
257 | .text |
258 | .await?; |
259 | |
260 | Ok |
261 | |
262 | |
263 | /// Handshake-specific message type. |
264 | /// |
265 | /// Uses basic serde_json-based deserialization to maintain the highest |
266 | /// level of compatibility across versions. |
267 | ; |
268 | |
269 | |
270 | |
271 | |
272 | T: DeserializeOwned + Send + Sync + Serialize, |
273 | S: Clone + Send + Sync, |
274 | |
275 | async |
276 | Ok |
277 | |
278 |