User Auth Early
parent: tbd commit: 8069fba
1 | use ; |
2 | |
3 | use ; |
4 | use |
5 | , |
6 | , |
7 | , | Sha256
8 | , |
9 | RsaPrivateKey, RsaPublicKey, |
10 | ; |
11 | use ; |
12 | |
13 | use crate:: |
14 | , | UserTokenMetadata
15 | , | HandshakeMessage
16 | , |
17 | ; |
18 | |
19 | use ; |
20 | |
21 | |
22 | |
23 | |
24 | |
25 | |
26 | |
27 | |
28 | Handshake, |
29 | Repository, |
30 | Authentication, |
31 | |
32 | |
33 | /// An authenticated message, where the instance is authenticating |
34 | /// a request it is making for itself. |
35 | |
36 | |
37 | message: T, |
38 | instance: Instance, |
39 | signature: , |
40 | |
41 | |
42 | |
43 | |
44 | T: Clone + Serialize, |
45 | |
46 | |
47 | Self |
48 | message: self.message.clone, |
49 | instance: self.instance.clone, |
50 | signature: self.signature.clone, |
51 | |
52 | |
53 | |
54 | |
55 | |
56 | |
57 | T: Debug + Serialize, |
58 | |
59 | |
60 | f.debug_struct |
61 | .field |
62 | .field |
63 | .field |
64 | .finish |
65 | |
66 | |
67 | |
68 | |
69 | |
70 | message: T, |
71 | instance: Instance, |
72 | private_key: String, |
73 | |
74 | let mut rng = thread_rng; |
75 | |
76 | let private_key = from_pkcs1_pem?; |
77 | let signing_key = new; |
78 | |
79 | let message_json = to_vec?; |
80 | |
81 | let signature = signing_key.sign_with_rng; |
82 | |
83 | Ok |
84 | message, |
85 | instance, |
86 | signature: signature.to_vec, |
87 | |
88 | |
89 | |
90 | pub async |
91 | &self.message |
92 | |
93 | |
94 | pub async |
95 | let public_key = public_key .await?; |
96 | let public_key = from_pkcs1_pem .unwrap; |
97 | |
98 | let verifying_key: = new; |
99 | |
100 | let message_json = to_vec .unwrap; |
101 | |
102 | verifying_key |
103 | .verify |
104 | &message_json, |
105 | & try_from .unwrap, |
106 | |
107 | .unwrap; |
108 | |
109 | Ok |
110 | |
111 | |
112 | |
113 | /// An authenticated message. |
114 | /// |
115 | /// Includes the message, with a digest generated with |
116 | /// our private key. |
117 | |
118 | |
119 | #[serde(flatten)] |
120 | message: T, |
121 | user: User, |
122 | |
123 | |
124 | |
125 | |
126 | T: Clone + Serialize, |
127 | |
128 | |
129 | Self |
130 | message: self.message.clone, |
131 | user: self.user.clone, |
132 | |
133 | |
134 | |
135 | |
136 | |
137 | |
138 | T: Debug + Serialize, |
139 | |
140 | |
141 | f.debug_struct |
142 | .field |
143 | .field |
144 | .finish |
145 | |
146 | |
147 | |
148 | |
149 | pub async |
150 | &self.message |
151 | |
152 | |
153 | pub async |
154 | &self.user |
155 | |
156 | |
157 | |
158 | /// An unvalidated authenticated message. |
159 | /// |
160 | /// Includes the message, with a digest generated with |
161 | /// our private key. |
162 | |
163 | |
164 | #[serde(flatten)] |
165 | message: T, |
166 | token: String, |
167 | digest: , |
168 | |
169 | |
170 | |
171 | |
172 | T: Clone + Serialize, |
173 | |
174 | |
175 | Self |
176 | message: self.message.clone, |
177 | token: self.token.clone, |
178 | digest: self.digest.clone, |
179 | |
180 | |
181 | |
182 | |
183 | |
184 | |
185 | T: Debug + Serialize, |
186 | |
187 | |
188 | f.debug_struct |
189 | .field |
190 | .field |
191 | .field |
192 | .finish |
193 | |
194 | |
195 | |
196 | |
197 | |
198 | let mut rng = thread_rng; |
199 | |
200 | let private_key = from_pkcs1_pem?; |
201 | let signing_key = new; |
202 | |
203 | let message_json = to_vec?; |
204 | |
205 | let signature = signing_key.sign_with_rng; |
206 | |
207 | Ok |
208 | message, |
209 | token, |
210 | digest: signature.to_vec, |
211 | |
212 | |
213 | |
214 | pub async |
215 | &self.message |
216 | |
217 | |
218 | pub async |
219 | let instance = |
220 | let mut validation = new; |
221 | validation.insecure_disable_signature_validation; |
222 | |
223 | let value: = |
224 | decode .unwrap; |
225 | |
226 | value.claims.generated_for.clone |
227 | ; |
228 | |
229 | let public_key_raw = public_key .await?; |
230 | let public_key = from_pkcs1_pem .unwrap; |
231 | |
232 | let verifying_key: = new; |
233 | |
234 | let message_json = to_vec .unwrap; |
235 | |
236 | verifying_key |
237 | .verify |
238 | &message_json, |
239 | & try_from .unwrap, |
240 | |
241 | .unwrap; |
242 | |
243 | let verification_key = from_rsa_pem .unwrap; |
244 | |
245 | let data: = decode |
246 | &self.token, |
247 | &verification_key, |
248 | & new, |
249 | |
250 | .unwrap; |
251 | |
252 | assert_eq!; |
253 | |
254 | Ok |
255 | message: self.message, |
256 | user: data.claims.user, |
257 | |
258 | |
259 | |
260 | |
261 | async |
262 | let key = get |
263 | .await? |
264 | .text |
265 | .await?; |
266 | |
267 | Ok |
268 | |
269 |