Add token extension
parent: tbd commit: 86d028f
1 | use ; |
2 | |
3 | use ; |
4 | use ; |
5 | use ; |
6 | use Table; |
7 | |
8 | use crate:: |
9 | |
10 | |
11 | AuthenticationTokenRequest, AuthenticationTokenResponse, TokenExtensionRequest, |
12 | TokenExtensionResponse, |
13 | , |
14 | InstanceAuthenticated, |
15 | , |
16 | , |
17 | ; |
18 | |
19 | |
20 | |
21 | user: User, |
22 | generated_for: Instance, |
23 | exp: u64, |
24 | |
25 | |
26 | |
27 | pub config: Table, |
28 | |
29 | |
30 | |
31 | pub async |
32 | &mut self, |
33 | request: AuthenticationTokenRequest, |
34 | |
35 | let secret_key = self.config |
36 | .as_str |
37 | .unwrap; |
38 | let private_key = |
39 | let mut file = open |
40 | .await |
41 | .unwrap; |
42 | |
43 | let mut key = vec!; |
44 | file.read_to_end .await.unwrap; |
45 | |
46 | key |
47 | ; |
48 | |
49 | if request.secret_key != secret_key |
50 | error!; |
51 | |
52 | panic! |
53 | |
54 | |
55 | let encoding_key = from_rsa_pem .unwrap; |
56 | |
57 | let claims = UserTokenMetadata |
58 | user: User |
59 | username: String from, |
60 | instance: Instance |
61 | url: String from, |
62 | , |
63 | , |
64 | generated_for: Instance |
65 | url: String from, |
66 | , |
67 | exp: |
68 | + from_secs |
69 | .as_secs, |
70 | ; |
71 | |
72 | let token = encode |
73 | & new, |
74 | &claims, |
75 | &encoding_key, |
76 | |
77 | .unwrap; |
78 | |
79 | Ok |
80 | |
81 | |
82 | pub async |
83 | &mut self, |
84 | raw_request: , |
85 | |
86 | let request = raw_request.inner .await; |
87 | |
88 | let server_public_key = |
89 | let mut file = open |
90 | .await |
91 | .unwrap; |
92 | |
93 | let mut key = vec!; |
94 | file.read_to_end .await.unwrap; |
95 | |
96 | key |
97 | ; |
98 | |
99 | let verification_key = from_rsa_pem .unwrap; |
100 | |
101 | let data: = decode |
102 | &request.token, |
103 | &verification_key, |
104 | & new, |
105 | |
106 | .unwrap; |
107 | |
108 | info!; |
109 | |
110 | let secret_key = self.config |
111 | .as_str |
112 | .unwrap; |
113 | |
114 | if request.secret_key != secret_key |
115 | error!; |
116 | |
117 | panic! |
118 | |
119 | |
120 | let requester_public_key = public_key .await.unwrap; |
121 | |
122 | // Validate request |
123 | raw_request.validate .await.unwrap; |
124 | info!; |
125 | |
126 | let private_key = |
127 | let mut file = open |
128 | .await |
129 | .unwrap; |
130 | |
131 | let mut key = vec!; |
132 | file.read_to_end .await.unwrap; |
133 | |
134 | key |
135 | ; |
136 | |
137 | let encoding_key = from_rsa_pem .unwrap; |
138 | |
139 | let claims = UserTokenMetadata |
140 | // TODO: Probably exploitable |
141 | user: data.claims.user, |
142 | generated_for: data.claims.generated_for, |
143 | exp: |
144 | + from_secs |
145 | .as_secs, |
146 | ; |
147 | |
148 | let token = encode |
149 | & new, |
150 | &claims, |
151 | &encoding_key, |
152 | |
153 | .unwrap; |
154 | |
155 | Ok |
156 | new_token: Some, |
157 | |
158 | |
159 | |
160 | |
161 | async |
162 | let key = get |
163 | .await? |
164 | .text |
165 | .await?; |
166 | |
167 | Ok |
168 | |
169 |