forked from tangled.org/core
this repo has no description

protect more routets

Changed files
+19 -7
appview
+1 -2
appview/auth/auth.go
···
clientSession.Values[appview.SessionPds] = pdsEndpoint
clientSession.Values[appview.SessionAccessJwt] = atSessionish.GetAccessJwt()
clientSession.Values[appview.SessionRefreshJwt] = atSessionish.GetRefreshJwt()
-
clientSession.Values[appview.SessionExpiry] = time.Now().Add(time.Minute * 15).Format(time.RFC3339)
+
clientSession.Values[appview.SessionExpiry] = time.Now().Add(time.Second * 5).Format(time.RFC3339)
clientSession.Values[appview.SessionAuthenticated] = true
return clientSession.Save(r, w)
}
func (a *Auth) AuthorizedClient(r *http.Request) (*xrpc.Client, error) {
clientSession, err := a.Store.Get(r, "appview-session")
-
if err != nil || clientSession.IsNew {
return nil, err
}
+16 -4
appview/state/middleware.go
···
func AuthMiddleware(s *State) Middleware {
return func(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
-
session, _ := s.auth.Store.Get(r, appview.SessionName)
+
session, err := s.auth.GetSession(r)
+
if session.IsNew || err != nil {
+
log.Printf("not logged in, redirecting")
+
http.Redirect(w, r, "/login", http.StatusTemporaryRedirect)
+
return
+
}
+
authorized, ok := session.Values[appview.SessionAuthenticated].(bool)
if !ok || !authorized {
log.Printf("not logged in, redirecting")
···
http.Redirect(w, r, "/login", http.StatusTemporaryRedirect)
return
}
-
pdsUrl := session.Values[appview.SessionPds].(string)
-
did := session.Values[appview.SessionDid].(string)
-
refreshJwt := session.Values[appview.SessionRefreshJwt].(string)
+
pdsUrl, ok1 := session.Values[appview.SessionPds].(string)
+
did, ok2 := session.Values[appview.SessionDid].(string)
+
refreshJwt, ok3 := session.Values[appview.SessionRefreshJwt].(string)
+
+
if !ok1 || !ok2 || !ok3 {
+
log.Println("invalid expiry time", err)
+
http.Redirect(w, r, "/login", http.StatusTemporaryRedirect)
+
return
+
}
if time.Now().After(expiry) {
log.Println("token expired, refreshing ...")
+2 -1
appview/state/state.go
···
// settings routes, needs auth
r.Group(func(r chi.Router) {
+
r.Use(AuthMiddleware(s))
r.With(RepoPermissionMiddleware(s, "repo:settings")).Route("/settings", func(r chi.Router) {
r.Get("/", s.RepoSettings)
r.With(RepoPermissionMiddleware(s, "repo:invite")).Put("/collaborator", s.AddCollaborator)
···
r.Get("/", s.Timeline)
-
r.Get("/logout", s.Logout)
+
r.With(AuthMiddleware(s)).Get("/logout", s.Logout)
r.Route("/login", func(r chi.Router) {
r.Get("/", s.Login)