Compare commits
	
		
			61 Commits
		
	
	
		
			v0.1.0-dev
			...
			v0.6.2-mai
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 6ec3b25e7d | |||
| 7e44d523f2 | |||
| 59d0ca0c0b | |||
| a02b15c65c | |||
| ebe29df991 | |||
| 473b4ec762 | |||
| a66ab7826c | |||
| 9da068252d | |||
| 2ba037c393 | |||
| a4c943189c | |||
| eb1e2990f9 | |||
| 99390ce8b7 | |||
| 5967ed5b13 | |||
| be4d1109a7 | |||
| 4353414c69 | |||
| c176d0fcf3 | |||
| c8b8d470dc | |||
| bcd0e607ef | |||
| 70de6b862f | |||
| 8c902b9d61 | |||
| 480a428e8b | |||
| 02697b2fd9 | |||
| d4faa7976e | |||
| ed77cab700 | |||
| 2c30abb5c6 | |||
| 1817ab01d6 | |||
| 31be156be3 | |||
| fc6b66f2e6 | |||
| eb7e394cf0 | |||
| 6dec9942cc | |||
| a855db9ecc | |||
| 17af1a00c0 | |||
| 50e735e1a9 | |||
| f6cf968f86 | |||
| 70a547ca94 | |||
| 89c89a5524 | |||
| a58b0cb40b | |||
| f601442f0e | |||
| 3424d31151 | |||
| 332e9d3378 | |||
| 2229d98ab6 | |||
| 7f5f1bae2f | |||
| d7c3443022 | |||
| 6bdc893147 | |||
| 4b8430e114 | |||
| 238fb15e6d | |||
| 5b0592f51d | |||
| 9be38542c1 | |||
| 7e189e84d8 | |||
| 79f6ebdc09 | |||
| 68a9998572 | |||
| b6787de66b | |||
| 4d3415acf2 | |||
| c9873d95d7 | |||
| f105de7c80 | |||
| 9b77a8dd78 | |||
| 88f45645b3 | |||
| dda88ce0a0 | |||
| 5893710431 | |||
| 0a678228dd | |||
| bfc14c96a7 | 
							
								
								
									
										21
									
								
								.dockerignore.yaml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										21
									
								
								.dockerignore.yaml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,21 @@ | ||||
| # Ignore build artifacts | ||||
| target/ | ||||
| pkg/ | ||||
|  | ||||
| # Ignore git directory | ||||
| .git/ | ||||
|  | ||||
| .gitea/ | ||||
|  | ||||
| # Ignore environment files (configure via docker-compose instead) | ||||
| .env* | ||||
|  | ||||
| # Ignore IDE/editor specific files | ||||
| .idea/ | ||||
| .vscode/ | ||||
|  | ||||
| # Ignore OS specific files | ||||
| *.DS_Store | ||||
|  | ||||
| # Add any other files/directories you don't need in the image | ||||
| # e.g., logs/, tmp/ | ||||
							
								
								
									
										12
									
								
								.env.docker.sample
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								.env.docker.sample
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,12 @@ | ||||
| APP_ENV=development | ||||
| BACKEND_PORT=8001 | ||||
| FRONTEND_URL=http://localhost:4200 | ||||
| RUST_LOG=debug | ||||
| ALLOWED_ORIGINS=https://soaricarus.com,https://www.soaricarus.com | ||||
| SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||
| SERVICE_PASSPHRASE=iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH | ||||
| POSTGRES_AUTH_USER=icarus_op | ||||
| POSTGRES_AUTH_PASSWORD=password | ||||
| POSTGRES_AUTH_DB=icarus_auth_db | ||||
| POSTGRES_AUTH_HOST=auth_db | ||||
| DATABASE_URL=postgresql://${POSTGRES_AUTH_USER}:${POSTGRES_AUTH_PASSWORD}@${POSTGRES_AUTH_HOST}:5432/${POSTGRES_AUTH_DB} | ||||
							
								
								
									
										12
									
								
								.env.sample
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								.env.sample
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,12 @@ | ||||
| APP_ENV=development | ||||
| BACKEND_PORT=8001 | ||||
| FRONTEND_URL=http://localhost:4200 | ||||
| RUST_LOG=debug | ||||
| ALLOWED_ORIGINS=https://soaricarus.com,https://www.soaricarus.com | ||||
| SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||
| SERVICE_PASSPHRASE=iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH | ||||
| POSTGRES_AUTH_USER=icarus_op_test | ||||
| POSTGRES_AUTH_PASSWORD=password | ||||
| POSTGRES_AUTH_DB=icarus_auth_test_db | ||||
| POSTGRES_AUTH_HOST=localhost | ||||
| DATABASE_URL=postgresql://${POSTGRES_AUTH_USER}:${POSTGRES_AUTH_PASSWORD}@${POSTGRES_AUTH_HOST}:5432/${POSTGRES_AUTH_DB} | ||||
| @@ -3,23 +3,21 @@ name: Release Tagging | ||||
| on: | ||||
|   push: | ||||
|     branches: | ||||
|       - devel | ||||
|     tags: | ||||
|       - 'v*' # Trigger on tags matching v* | ||||
|       - main | ||||
|  | ||||
| jobs: | ||||
|   release: | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - name: Checkout code | ||||
|         uses: actions/checkout@v3 | ||||
|         uses: actions/checkout@v5 | ||||
|         with: | ||||
|           fetch-depth: 0 # Important for git describe --tags | ||||
|  | ||||
|       - name: Install Rust | ||||
|         uses: actions-rs/toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.85.0 | ||||
|           toolchain: 1.90.0 | ||||
|           components: cargo | ||||
|  | ||||
|       - name: Extract Version from Cargo.toml | ||||
| @@ -29,8 +27,10 @@ jobs: | ||||
|           PROJECT_COMMIT_HASH=$(git rev-parse HEAD | cut -c 1-10) | ||||
|           BRANCH_REF="${GITHUB_REF}" | ||||
|           BRANCH_NAME=$(echo "$BRANCH_REF" | cut -d '/' -f 3) | ||||
|           PROJECT_TAG_RELEASE="v$VERSION-$BRANCH_NAME-$PROJECT_COMMIT_HASH" | ||||
|           echo "::set-output name=project_tag_release::$PROJECT_TAG_RELEASE-950" | ||||
|           PROJECT_TAG_RELEASE="v$VERSION-$BRANCH_NAME-$PROJECT_COMMIT_HASH-950" | ||||
|  | ||||
|           echo "::set-output name=project_tag_release::$PROJECT_TAG_RELEASE" | ||||
|  | ||||
|           echo "Version: $VERSION" | ||||
|           echo "Hash: $PROJECT_COMMIT_HASH" | ||||
|           echo "Branch: $BRANCH_NAME" | ||||
| @@ -51,7 +51,3 @@ jobs: | ||||
|           release_name: Release ${{ steps.version.outputs.project_tag_release }} | ||||
|           body: | | ||||
|            Release of version ${{ steps.version.outputs.project_tag_release }} | ||||
|           # draft: false | ||||
|           # prerelease: ${{ startsWith(github.ref, 'v') == false }} # prerelease if not a valid release tag | ||||
|  | ||||
|  | ||||
|   | ||||
| @@ -15,91 +15,130 @@ jobs: | ||||
|     name: Check | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.85.0 | ||||
|           toolchain: 1.90.0 | ||||
|       - run: | | ||||
|           mkdir -p ~/.ssh | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/gitlab_deploy_key | ||||
|           chmod 600 ~/.ssh/gitlab_deploy_key | ||||
|           ssh-keyscan git.kundeng.us ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLl/OZiKVDxwnyvMxa+rjKvDpKqTxH1GWuGuDPLmENGQMbTVulajZWr9x8Q1cotoJiHZkt7DA5vczcjB/4lwgWA= >> ~/.ssh/known_hosts | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||
|           chmod 600 ~/.ssh/icarus_models_deploy_key | ||||
|           ssh-keyscan ${{ vars.MYHOST }} >> ~/.ssh/known_hosts | ||||
|  | ||||
|           eval $(ssh-agent -s) | ||||
|           ssh-add -v ~/.ssh/gitlab_deploy_key | ||||
|           ssh-add -v ~/.ssh/icarus_models_deploy_key | ||||
|  | ||||
|           cargo check | ||||
|  | ||||
|   test: | ||||
|     name: Test Suite | ||||
|     runs-on: ubuntu-24.04 | ||||
|     # --- Add database service definition --- | ||||
|     services: | ||||
|       postgres: | ||||
|         image: postgres:17.5 | ||||
|         env: | ||||
|           # Use secrets for DB init, with fallbacks for flexibility | ||||
|           POSTGRES_USER: ${{ secrets.DB_TEST_USER || 'testuser' }} | ||||
|           POSTGRES_PASSWORD: ${{ secrets.DB_TEST_PASSWORD || 'testpassword' }} | ||||
|           POSTGRES_DB: ${{ secrets.DB_TEST_NAME || 'testdb' }} | ||||
|         # Options to wait until the database is ready | ||||
|         options: >- | ||||
|           --health-cmd pg_isready | ||||
|           --health-interval 10s | ||||
|           --health-timeout 5s | ||||
|           --health-retries 5 | ||||
|  | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.85.0 | ||||
|       - run: | | ||||
|           toolchain: 1.90.0 | ||||
|       # --- Add this step for explicit verification --- | ||||
|       - name: Verify Docker Environment | ||||
|         run: | | ||||
|           echo "Runner User Info:" | ||||
|           id | ||||
|           echo "Checking Docker Version:" | ||||
|           docker --version | ||||
|           echo "Checking Docker Daemon Status (info):" | ||||
|           docker info | ||||
|           echo "Checking Docker Daemon Status (ps):" | ||||
|           docker ps -a | ||||
|           echo "Docker environment check complete." | ||||
|         # NOTE: Do NOT use continue-on-error here. | ||||
|         # If Docker isn't working as expected, the job SHOULD fail here. | ||||
|       - name: Run tests | ||||
|         env: | ||||
|           # Define DATABASE_URL for tests to use | ||||
|           DATABASE_URL: postgresql://${{ secrets.DB_TEST_USER || 'testuser' }}:${{ secrets.DB_TEST_PASSWORD || 'testpassword' }}@postgres:5432/${{ secrets.DB_TEST_NAME || 'testdb' }} | ||||
|           RUST_LOG: info # Optional: configure test log level | ||||
|           SECRET_KEY: ${{ secrets.TOKEN_SECRET_KEY }} | ||||
|           # Make SSH agent available if tests fetch private dependencies | ||||
|           SSH_AUTH_SOCK: ${{ env.SSH_AUTH_SOCK }} | ||||
|         run: | | ||||
|           mkdir -p ~/.ssh | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/gitlab_deploy_key | ||||
|           chmod 600 ~/.ssh/gitlab_deploy_key | ||||
|           ssh-keyscan git.kundeng.us ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLl/OZiKVDxwnyvMxa+rjKvDpKqTxH1GWuGuDPLmENGQMbTVulajZWr9x8Q1cotoJiHZkt7DA5vczcjB/4lwgWA= >> ~/.ssh/known_hosts | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||
|           chmod 600 ~/.ssh/icarus_models_deploy_key | ||||
|           ssh-keyscan ${{ vars.MYHOST }} >> ~/.ssh/known_hosts | ||||
|  | ||||
|           eval $(ssh-agent -s) | ||||
|           ssh-add -v ~/.ssh/gitlab_deploy_key | ||||
|           ssh-add -v ~/.ssh/icarus_models_deploy_key | ||||
|  | ||||
|           cargo test | ||||
|  | ||||
|   fmt: | ||||
|     name: Rustfmt | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.85.0 | ||||
|           toolchain: 1.90.0 | ||||
|       - run: rustup component add rustfmt | ||||
|       - run: | | ||||
|           mkdir -p ~/.ssh | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/gitlab_deploy_key | ||||
|           chmod 600 ~/.ssh/gitlab_deploy_key | ||||
|           ssh-keyscan git.kundeng.us ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLl/OZiKVDxwnyvMxa+rjKvDpKqTxH1GWuGuDPLmENGQMbTVulajZWr9x8Q1cotoJiHZkt7DA5vczcjB/4lwgWA= >> ~/.ssh/known_hosts | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||
|           chmod 600 ~/.ssh/icarus_models_deploy_key | ||||
|           ssh-keyscan ${{ vars.MYHOST }} >> ~/.ssh/known_hosts | ||||
|  | ||||
|           eval $(ssh-agent -s) | ||||
|           ssh-add -v ~/.ssh/gitlab_deploy_key | ||||
|           ssh-add -v ~/.ssh/icarus_models_deploy_key | ||||
|           cargo fmt --all -- --check | ||||
|  | ||||
|   clippy: | ||||
|     name: Clippy | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.85.0 | ||||
|           toolchain: 1.90.0 | ||||
|       - run: rustup component add clippy | ||||
|       - run: | | ||||
|           mkdir -p ~/.ssh | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/gitlab_deploy_key | ||||
|           chmod 600 ~/.ssh/gitlab_deploy_key | ||||
|           ssh-keyscan git.kundeng.us ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLl/OZiKVDxwnyvMxa+rjKvDpKqTxH1GWuGuDPLmENGQMbTVulajZWr9x8Q1cotoJiHZkt7DA5vczcjB/4lwgWA= >> ~/.ssh/known_hosts | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||
|           chmod 600 ~/.ssh/icarus_models_deploy_key | ||||
|           ssh-keyscan ${{ vars.MYHOST }} >> ~/.ssh/known_hosts | ||||
|  | ||||
|           eval $(ssh-agent -s) | ||||
|           ssh-add -v ~/.ssh/gitlab_deploy_key | ||||
|           ssh-add -v ~/.ssh/icarus_models_deploy_key | ||||
|           cargo clippy -- -D warnings | ||||
|  | ||||
|   build: | ||||
|     name: build | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.85.0 | ||||
|           toolchain: 1.90.0 | ||||
|       - run: | | ||||
|           mkdir -p ~/.ssh | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/gitlab_deploy_key | ||||
|           chmod 600 ~/.ssh/gitlab_deploy_key | ||||
|           ssh-keyscan git.kundeng.us ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLl/OZiKVDxwnyvMxa+rjKvDpKqTxH1GWuGuDPLmENGQMbTVulajZWr9x8Q1cotoJiHZkt7DA5vczcjB/4lwgWA= >> ~/.ssh/known_hosts | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||
|           chmod 600 ~/.ssh/icarus_models_deploy_key | ||||
|           ssh-keyscan ${{ vars.MYHOST }} >> ~/.ssh/known_hosts | ||||
|  | ||||
|           eval $(ssh-agent -s) | ||||
|           ssh-add -v ~/.ssh/gitlab_deploy_key | ||||
|           ssh-add -v ~/.ssh/icarus_models_deploy_key | ||||
|           cargo build --release | ||||
|  | ||||
|   | ||||
							
								
								
									
										4
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										4
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							| @@ -1,2 +1,4 @@ | ||||
| /target | ||||
| Cargo.lock | ||||
| .env | ||||
| .env.local | ||||
| .env.docker | ||||
|   | ||||
							
								
								
									
										2865
									
								
								Cargo.lock
									
									
									
										generated
									
									
									
										Normal file
									
								
							
							
						
						
									
										2865
									
								
								Cargo.lock
									
									
									
										generated
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										32
									
								
								Cargo.toml
									
									
									
									
									
								
							
							
						
						
									
										32
									
								
								Cargo.toml
									
									
									
									
									
								
							| @@ -1,12 +1,30 @@ | ||||
| [package] | ||||
| name = "icarus_auth" | ||||
| version = "0.1.0" | ||||
| version = "0.6.2" | ||||
| edition = "2024" | ||||
| rust-version = "1.90" | ||||
|  | ||||
| [dependencies] | ||||
| axum = { version = "0.8.3" } | ||||
| serde = { version = "1.0.218", features = ["derive"] } | ||||
| serde_json = { version = "1.0.139" } | ||||
| tokio = { version = "1.44.1", features = ["rt-multi-thread"] } | ||||
| tracing-subscriber = "0.3.19" | ||||
| icarus-models = { git = "ssh://git@git.kundeng.us/phoenix/icarus-models.git", tag = "v0.1.14" } | ||||
| axum = { version = "0.8.6" } | ||||
| serde = { version = "1.0.228", features = ["derive"] } | ||||
| serde_json = { version = "1.0.145" } | ||||
| tokio = { version = "1.47.1", features = ["rt-multi-thread"] } | ||||
| tracing-subscriber = { version = "0.3.20" } | ||||
| tower = { version = "0.5.2", features = ["full"] } | ||||
| tower-http = { version = "0.6.6", features = ["cors"] } | ||||
| hyper = { version = "1.7.0" } | ||||
| sqlx = { version = "0.8.6", features = ["postgres", "runtime-tokio-native-tls", "time", "uuid"] } | ||||
| uuid = { version = "1.18.1", features = ["v4", "serde"] } | ||||
| argon2 = { version = "0.5.3", features = ["std"] } # Use the latest 0.5.x version | ||||
| rand = { version = "0.9.2" } | ||||
| time = { version = "0.3.41", features = ["macros", "serde"] } | ||||
| josekit = { version = "0.10.3" } | ||||
| utoipa = { version = "5.4.0", features = ["axum_extras"] } | ||||
| utoipa-swagger-ui = { version = "9.0.2", features = ["axum"] } | ||||
| icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.8.0" } | ||||
| icarus_envy = { git = "ssh://git@git.kundeng.us/phoenix/icarus_envy.git", tag = "v0.5.0" } | ||||
|  | ||||
| [dev-dependencies] | ||||
| http-body-util = { version = "0.1.3" } | ||||
| url = { version = "2.5.7" } | ||||
| once_cell = { version = "1.21.3" } # Useful for lazy initialization in tests/app setup | ||||
|   | ||||
							
								
								
									
										71
									
								
								Dockerfile
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										71
									
								
								Dockerfile
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,71 @@ | ||||
| # Stage 1: Build the application | ||||
| # Use a specific Rust version for reproducibility. Choose one that matches your development environment. | ||||
| # Using slim variant for smaller base image | ||||
| FROM rust:1.90 as builder | ||||
|  | ||||
| # Set the working directory inside the container | ||||
| WORKDIR /usr/src/app | ||||
|  | ||||
| # Install build dependencies if needed (e.g., for certain crates like sqlx with native TLS) | ||||
| # RUN apt-get update && apt-get install -y pkg-config libssl-dev | ||||
|  | ||||
| # Install build dependencies if needed (e.g., git for cloning) | ||||
| RUN apt-get update && apt-get install -y --no-install-recommends \ | ||||
|     pkg-config libssl3 \ | ||||
|     ca-certificates \ | ||||
|     openssh-client git \ | ||||
|     && rm -rf /var/lib/apt/lists/* | ||||
|  | ||||
| # << --- ADD HOST KEY HERE --- >> | ||||
| # Replace 'yourgithost.com' with the actual hostname (e.g., github.com) | ||||
| RUN mkdir -p -m 0700 ~/.ssh && \ | ||||
|     ssh-keyscan git.kundeng.us >> ~/.ssh/known_hosts | ||||
|  | ||||
| # Copy Cargo manifests | ||||
| COPY Cargo.toml Cargo.lock ./ | ||||
|  | ||||
| # Build *only* dependencies to leverage Docker cache | ||||
| # This dummy build caches dependencies as a separate layer | ||||
| RUN --mount=type=ssh mkdir src && \ | ||||
|     echo "fn main() {println!(\"if you see this, the build broke\")}" > src/main.rs && \ | ||||
|     cargo build --release --quiet && \ | ||||
|     rm -rf src target/release/deps/icarus_auth* # Clean up dummy build artifacts (replace icarus_auth) | ||||
|  | ||||
| # Copy the actual source code | ||||
| COPY src ./src | ||||
| # If you have other directories like `templates` or `static`, copy them too | ||||
| COPY .env ./.env | ||||
| COPY migrations ./migrations | ||||
|  | ||||
| # << --- SSH MOUNT ADDED HERE --- >> | ||||
| # Build *only* dependencies to leverage Docker cache | ||||
| # This dummy build caches dependencies as a separate layer | ||||
| # Mount the SSH agent socket for this command | ||||
| RUN --mount=type=ssh \ | ||||
|     cargo build --release --quiet | ||||
|  | ||||
| # Stage 2: Create the final, smaller runtime image | ||||
| # Use a minimal base image like debian-slim or even distroless for security/size | ||||
| FROM ubuntu:24.04 | ||||
|  | ||||
| # Install runtime dependencies if needed (e.g., SSL certificates) | ||||
| RUN apt-get update && apt-get install -y ca-certificates libssl-dev libssl3 && rm -rf /var/lib/apt/lists/* | ||||
|  | ||||
| # Set the working directory | ||||
| WORKDIR /usr/local/bin | ||||
|  | ||||
| # Copy the compiled binary from the builder stage | ||||
| # Replace 'icarus_auth' with the actual name of your binary (usually the crate name) | ||||
| COPY --from=builder /usr/src/app/target/release/icarus_auth . | ||||
|  | ||||
| # Copy other necessary files like .env (if used for runtime config) or static assets | ||||
| # It's generally better to configure via environment variables in Docker though | ||||
| COPY --from=builder /usr/src/app/.env . | ||||
| COPY --from=builder /usr/src/app/migrations ./migrations | ||||
|  | ||||
| # Expose the port your Axum app listens on (e.g., 3000 or 8000) | ||||
| EXPOSE 3000 | ||||
|  | ||||
| # Set the command to run your application | ||||
| # Ensure this matches the binary name copied above | ||||
| CMD ["./icarus_auth"] | ||||
							
								
								
									
										32
									
								
								README.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										32
									
								
								README.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,32 @@ | ||||
| A auth web API services for the Icarus project. | ||||
|  | ||||
|  | ||||
| # Getting Started | ||||
| The easiest way to get started is through docker. This assumes that docker is already installed | ||||
| on your system. Copy the `.env.docker.sample` as `.env`. Most of the data in the env file doesn't  | ||||
| need to be modified. The `SECRET_KEY` variable should be changed since it will be used for token | ||||
| generation. The `SECRET_PASSPHASE` should also be changed when in production mode, but make sure | ||||
| the respective `passphrase` database table record exists. | ||||
|  | ||||
| Build image | ||||
| ``` | ||||
| docker compose build | ||||
| ``` | ||||
|  | ||||
| Start images | ||||
| ``` | ||||
| docker compose up -d --force-recreate | ||||
| ``` | ||||
|  | ||||
| Bring it down | ||||
| ``` | ||||
| docker compose down -v | ||||
| ``` | ||||
|  | ||||
| Pruning | ||||
| ``` | ||||
| docker system prune -a | ||||
| ``` | ||||
|  | ||||
| To view the OpenAPI spec, run the project and access `/swagger-ui`. If running through docker, | ||||
| the url would be something like `http://localhost:8000/swagger-ui`. | ||||
							
								
								
									
										45
									
								
								docker-compose.yaml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										45
									
								
								docker-compose.yaml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,45 @@ | ||||
| version: '3.8' # Use a recent version | ||||
|  | ||||
| services: | ||||
|   # Your Rust Application Service | ||||
|   auth_api: | ||||
|     build: # Tells docker-compose to build the Dockerfile in the current directory | ||||
|       context: . | ||||
|       ssh: ["default"]  # Uses host's SSH agent | ||||
|     container_name: icarus_auth # Optional: Give the container a specific name | ||||
|     ports: | ||||
|       # Map host port 8000 to container port 3000 (adjust as needed) | ||||
|       - "8001:8001" | ||||
|     env_file: | ||||
|       - .env | ||||
|     depends_on: | ||||
|       auth_db: | ||||
|         condition: service_healthy # Wait for the DB to be healthy before starting the app | ||||
|     restart: unless-stopped # Optional: Restart policy | ||||
|  | ||||
|   # PostgreSQL Database Service | ||||
|   auth_db: | ||||
|     image: postgres:17.5-alpine # Use an official Postgres image (Alpine variant is smaller) | ||||
|     container_name: icarus_auth_db # Optional: Give the container a specific name | ||||
|     environment: | ||||
|       # These MUST match the user, password, and database name in the DATABASE_URL above | ||||
|       POSTGRES_USER: ${POSTGRES_AUTH_USER:-icarus_op} | ||||
|       POSTGRES_PASSWORD: ${POSTGRES_AUTH_PASSWORD:-password} | ||||
|       POSTGRES_DB: ${POSTGRES_AUTH_DB:-icarus_auth_db} | ||||
|     volumes: | ||||
|       # Persist database data using a named volume | ||||
|       - postgres_data:/var/lib/postgresql/data | ||||
|     ports: [] | ||||
|     healthcheck: | ||||
|         # Checks if Postgres is ready to accept connections | ||||
|         test: ["CMD-SHELL", "pg_isready -U $$POSTGRES_USER -d $$POSTGRES_DB"] | ||||
|         interval: 10s | ||||
|         timeout: 5s | ||||
|         retries: 5 | ||||
|         start_period: 10s | ||||
|     restart: always # Optional: Restart policy | ||||
|  | ||||
| # Define the named volume for data persistence | ||||
| volumes: | ||||
|   postgres_data: | ||||
|     driver: local # Use the default local driver | ||||
							
								
								
									
										28
									
								
								migrations/20250402221858_init_migrate.sql
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										28
									
								
								migrations/20250402221858_init_migrate.sql
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,28 @@ | ||||
| -- Add migration script here | ||||
| CREATE EXTENSION IF NOT EXISTS pgcrypto; | ||||
|  | ||||
| CREATE TABLE IF NOT EXISTS "user" ( | ||||
|     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||
|     username TEXT NOT NULL, | ||||
|     password TEXT NOT NULL, | ||||
|     email TEXT NOT NULL, | ||||
|     phone TEXT NOT NULL, | ||||
|     firstname TEXT NOT NULL, | ||||
|     lastname TEXT NOT NULL, | ||||
|     email_verified BOOL NOT NULL, | ||||
|     date_created TIMESTAMPTZ NOT NULL DEFAULT NOW(), | ||||
|     status TEXT NOT NULL, | ||||
|     last_login TIMESTAMPTZ NULL DEFAULT NOW(), | ||||
|     salt_id UUID NOT NULL | ||||
| ); | ||||
|  | ||||
| CREATE TABLE IF NOT EXISTS "salt" ( | ||||
|     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||
|     salt TEXT NOT NULL | ||||
| ); | ||||
|  | ||||
| CREATE TABLE IF NOT EXISTS "passphrase" ( | ||||
|     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||
|     passphrase TEXT NOT NULL, | ||||
|     date_created TIMESTAMPTZ NOT NULL DEFAULT NOW() | ||||
| ); | ||||
							
								
								
									
										2
									
								
								migrations/20250802185652_passphrase_data.sql
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										2
									
								
								migrations/20250802185652_passphrase_data.sql
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,2 @@ | ||||
| -- Add migration script here | ||||
| INSERT INTO "passphrase" (id, passphrase) VALUES('22f9c775-cce9-457a-a147-9dafbb801f61', 'iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH'); | ||||
							
								
								
									
										27
									
								
								run_migrations.txt
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										27
									
								
								run_migrations.txt
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,27 @@ | ||||
| TODO: At some point, move this somewhere that is appropriate | ||||
|  | ||||
| # Make sure role has CREATEDB | ||||
| ALTER ROLE username_that_needs_permission CREATEDB; | ||||
|  | ||||
| # Install migrations | ||||
| cargo install sqlx-cli | ||||
|  | ||||
| # Make sure to populate DATABASE_URL with correct value.  | ||||
| # By default, the DATABASE_URL found in .env file will be used | ||||
| export DATABASE_URL="postgres://icarus_op_test:password@localhost/icarus_auth_test" | ||||
|  | ||||
| # init | ||||
| sqlx migrate add init_migration | ||||
| sqlx migrate run | ||||
|  | ||||
| # Create | ||||
| sqlx database create | ||||
|  | ||||
| # Drop | ||||
| sqlx database drop | ||||
|  | ||||
| # setup | ||||
| sqlx database setup | ||||
|  | ||||
| # Reset | ||||
| sqlx database reset | ||||
							
								
								
									
										54
									
								
								src/callers/common.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										54
									
								
								src/callers/common.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,54 @@ | ||||
| pub mod response { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct TestResult { | ||||
|         pub message: String, | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub mod endpoint { | ||||
|     use super::*; | ||||
|     use axum::{Extension, Json, http::StatusCode}; | ||||
|  | ||||
|     /// Endpoint to hit the root | ||||
|     /// basic handler that responds with a static string | ||||
|     #[utoipa::path( | ||||
|         get, | ||||
|         path = super::super::endpoints::ROOT, | ||||
|         responses( | ||||
|             (status = 200, description = "Test", body = &str), | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn root() -> &'static str { | ||||
|         "Hello, World!" | ||||
|     } | ||||
|  | ||||
|     /// Endpoint to do a database ping | ||||
|     #[utoipa::path( | ||||
|         get, | ||||
|         path = super::super::endpoints::DBTEST, | ||||
|         responses( | ||||
|             (status = 200, description = "Successful ping of the db", body = super::response::TestResult), | ||||
|             (status = 400, description = "Failure in pinging the db", body = super::response::TestResult) | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn db_ping( | ||||
|         Extension(pool): Extension<sqlx::PgPool>, | ||||
|     ) -> (StatusCode, Json<response::TestResult>) { | ||||
|         match sqlx::query("SELECT 1").execute(&pool).await { | ||||
|             Ok(_) => { | ||||
|                 let tr = response::TestResult { | ||||
|                     message: String::from("This works"), | ||||
|                 }; | ||||
|                 (StatusCode::OK, Json(tr)) | ||||
|             } | ||||
|             Err(e) => ( | ||||
|                 StatusCode::BAD_REQUEST, | ||||
|                 Json(response::TestResult { | ||||
|                     message: e.to_string(), | ||||
|                 }), | ||||
|             ), | ||||
|         } | ||||
|     } | ||||
| } | ||||
							
								
								
									
										268
									
								
								src/callers/login.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										268
									
								
								src/callers/login.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,268 @@ | ||||
| pub mod request { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct Request { | ||||
|         pub username: String, | ||||
|         pub password: String, | ||||
|     } | ||||
|  | ||||
|     pub mod service_login { | ||||
|         #[derive(Debug, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||
|         pub struct Request { | ||||
|             pub passphrase: String, | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub mod refresh_token { | ||||
|         #[derive(Debug, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||
|         pub struct Request { | ||||
|             pub access_token: String, | ||||
|         } | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub mod response { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct Response { | ||||
|         pub message: String, | ||||
|         pub data: Vec<icarus_models::login_result::LoginResult>, | ||||
|     } | ||||
|  | ||||
|     pub mod service_login { | ||||
|         #[derive(Debug, Default, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||
|         pub struct Response { | ||||
|             pub message: String, | ||||
|             pub data: Vec<icarus_models::login_result::LoginResult>, | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub mod refresh_token { | ||||
|         #[derive(Debug, Default, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||
|         pub struct Response { | ||||
|             pub message: String, | ||||
|             pub data: Vec<icarus_models::login_result::LoginResult>, | ||||
|         } | ||||
|     } | ||||
| } | ||||
|  | ||||
| /// Module for login endpoints | ||||
| pub mod endpoint { | ||||
|     use axum::{Json, http::StatusCode}; | ||||
|  | ||||
|     use crate::hashing; | ||||
|     use crate::repo; | ||||
|     use crate::token_stuff; | ||||
|  | ||||
|     use super::request; | ||||
|     use super::response; | ||||
|  | ||||
|     // TODO: At some point, get the username from the DB | ||||
|     // Name of service username when returning a login result | ||||
|     pub const SERVICE_USERNAME: &str = "service"; | ||||
|  | ||||
|     async fn not_found(message: &str) -> (StatusCode, Json<response::Response>) { | ||||
|         ( | ||||
|             StatusCode::NOT_FOUND, | ||||
|             Json(response::Response { | ||||
|                 message: String::from(message), | ||||
|                 data: Vec::new(), | ||||
|             }), | ||||
|         ) | ||||
|     } | ||||
|  | ||||
|     /// Endpoint to login | ||||
|     #[utoipa::path( | ||||
|         post, | ||||
|         path = super::super::endpoints::LOGIN, | ||||
|         request_body( | ||||
|             content = request::Request, | ||||
|             description = "Data required to login", | ||||
|             content_type = "application/json" | ||||
|         ), | ||||
|         responses( | ||||
|             (status = 200, description = "Successfully logged in", body = response::Response), | ||||
|             (status = 404, description = "Could not login with credentials", body = response::Response) | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn login( | ||||
|         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||
|         Json(payload): Json<request::Request>, | ||||
|     ) -> (StatusCode, Json<response::Response>) { | ||||
|         // Check if user exists | ||||
|         match repo::user::get(&pool, &payload.username).await { | ||||
|             Ok(user) => { | ||||
|                 if hashing::verify_password(&payload.password, user.password.clone()).unwrap() { | ||||
|                     // Create token | ||||
|                     let key = icarus_envy::environment::get_secret_key().await.value; | ||||
|                     let (token_literal, duration) = | ||||
|                         token_stuff::create_token(&key, &user.id).unwrap(); | ||||
|  | ||||
|                     if token_stuff::verify_token(&key, &token_literal) { | ||||
|                         let current_time = time::OffsetDateTime::now_utc(); | ||||
|                         let _ = repo::user::update_last_login(&pool, &user, ¤t_time).await; | ||||
|  | ||||
|                         ( | ||||
|                             StatusCode::OK, | ||||
|                             Json(response::Response { | ||||
|                                 message: String::from("Successful"), | ||||
|                                 data: vec![icarus_models::login_result::LoginResult { | ||||
|                                     id: user.id, | ||||
|                                     username: user.username.clone(), | ||||
|                                     token: token_literal, | ||||
|                                     token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||
|                                     expiration: duration, | ||||
|                                 }], | ||||
|                             }), | ||||
|                         ) | ||||
|                     } else { | ||||
|                         return not_found("Could not verify password").await; | ||||
|                     } | ||||
|                 } else { | ||||
|                     return not_found("Error Hashing").await; | ||||
|                 } | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 return not_found(&err.to_string()).await; | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     /// Endpoint to login as a service user | ||||
|     #[utoipa::path( | ||||
|         post, | ||||
|         path = super::super::endpoints::SERVICE_LOGIN, | ||||
|         request_body( | ||||
|             content = request::service_login::Request, | ||||
|             description = "Data required to login as a service user", | ||||
|             content_type = "application/json" | ||||
|         ), | ||||
|         responses( | ||||
|             (status = 200, description = "Login successful", body = response::Response), | ||||
|             (status = 400, description = "Error logging in with credentials", body = response::Response) | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn service_login( | ||||
|         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||
|         axum::Json(payload): axum::Json<request::service_login::Request>, | ||||
|     ) -> ( | ||||
|         axum::http::StatusCode, | ||||
|         axum::Json<response::service_login::Response>, | ||||
|     ) { | ||||
|         let mut response = response::service_login::Response::default(); | ||||
|  | ||||
|         match repo::service::valid_passphrase(&pool, &payload.passphrase).await { | ||||
|             Ok((id, _passphrase, _date_created)) => { | ||||
|                 let key = icarus_envy::environment::get_secret_key().await.value; | ||||
|                 let (token_literal, duration) = | ||||
|                     token_stuff::create_service_token(&key, &id).unwrap(); | ||||
|  | ||||
|                 if token_stuff::verify_token(&key, &token_literal) { | ||||
|                     let login_result = icarus_models::login_result::LoginResult { | ||||
|                         id, | ||||
|                         username: String::from(SERVICE_USERNAME), | ||||
|                         token: token_literal, | ||||
|                         token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||
|                         expiration: duration, | ||||
|                     }; | ||||
|  | ||||
|                     response.data.push(login_result); | ||||
|                     response.message = String::from("Successful"); | ||||
|  | ||||
|                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||
|                 } else { | ||||
|                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||
|                 } | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 response.message = err.to_string(); | ||||
|                 (axum::http::StatusCode::BAD_REQUEST, axum::Json(response)) | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     /// Endpoint to retrieve a refresh token | ||||
|     #[utoipa::path( | ||||
|         post, | ||||
|         path = super::super::endpoints::REFRESH_TOKEN, | ||||
|         request_body( | ||||
|             content = request::refresh_token::Request, | ||||
|             description = "Data required to retrieve a refresh token", | ||||
|             content_type = "application/json" | ||||
|         ), | ||||
|         responses( | ||||
|             (status = 200, description = "Refresh token generated", body = response::Response), | ||||
|             (status = 400, description = "Error verifying token", body = response::Response), | ||||
|             (status = 404, description = "Could not validate token", body = response::Response), | ||||
|             (status = 500, description = "Error extracting token", body = response::Response) | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn refresh_token( | ||||
|         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||
|         axum::Json(payload): axum::Json<request::refresh_token::Request>, | ||||
|     ) -> ( | ||||
|         axum::http::StatusCode, | ||||
|         axum::Json<response::refresh_token::Response>, | ||||
|     ) { | ||||
|         let mut response = response::refresh_token::Response::default(); | ||||
|         let key = icarus_envy::environment::get_secret_key().await.value; | ||||
|  | ||||
|         if token_stuff::verify_token(&key, &payload.access_token) { | ||||
|             let token_type = token_stuff::get_token_type(&key, &payload.access_token).unwrap(); | ||||
|  | ||||
|             if token_stuff::is_token_type_valid(&token_type) { | ||||
|                 // Get passphrase record with id | ||||
|                 match token_stuff::extract_id_from_token(&key, &payload.access_token) { | ||||
|                     Ok(id) => match repo::service::get_passphrase(&pool, &id).await { | ||||
|                         Ok((returned_id, _, _)) => { | ||||
|                             match token_stuff::create_service_refresh_token(&key, &returned_id) { | ||||
|                                 Ok((access_token, exp_dur)) => { | ||||
|                                     let login_result = icarus_models::login_result::LoginResult { | ||||
|                                         id: returned_id, | ||||
|                                         token: access_token, | ||||
|                                         expiration: exp_dur, | ||||
|                                         token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||
|                                         username: String::from(SERVICE_USERNAME), | ||||
|                                     }; | ||||
|                                     response.message = String::from("Successful"); | ||||
|                                     response.data.push(login_result); | ||||
|  | ||||
|                                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||
|                                 } | ||||
|                                 Err(err) => { | ||||
|                                     response.message = err.to_string(); | ||||
|                                     ( | ||||
|                                         axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||
|                                         axum::Json(response), | ||||
|                                     ) | ||||
|                                 } | ||||
|                             } | ||||
|                         } | ||||
|                         Err(err) => { | ||||
|                             response.message = err.to_string(); | ||||
|                             ( | ||||
|                                 axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||
|                                 axum::Json(response), | ||||
|                             ) | ||||
|                         } | ||||
|                     }, | ||||
|                     Err(err) => { | ||||
|                         response.message = err.to_string(); | ||||
|                         ( | ||||
|                             axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||
|                             axum::Json(response), | ||||
|                         ) | ||||
|                     } | ||||
|                 } | ||||
|             } else { | ||||
|                 response.message = String::from("Invalid token type"); | ||||
|                 (axum::http::StatusCode::NOT_FOUND, axum::Json(response)) | ||||
|             } | ||||
|         } else { | ||||
|             response.message = String::from("Could not verify token"); | ||||
|             (axum::http::StatusCode::BAD_REQUEST, axum::Json(response)) | ||||
|         } | ||||
|     } | ||||
| } | ||||
							
								
								
									
										12
									
								
								src/callers/mod.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								src/callers/mod.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,12 @@ | ||||
| pub mod common; | ||||
| pub mod login; | ||||
| pub mod register; | ||||
|  | ||||
| pub mod endpoints { | ||||
|     pub const ROOT: &str = "/"; | ||||
|     pub const REGISTER: &str = "/api/v2/register"; | ||||
|     pub const DBTEST: &str = "/api/v2/test/db"; | ||||
|     pub const LOGIN: &str = "/api/v2/login"; | ||||
|     pub const SERVICE_LOGIN: &str = "/api/v2/service/login"; | ||||
|     pub const REFRESH_TOKEN: &str = "/api/v2/token/refresh"; | ||||
| } | ||||
							
								
								
									
										118
									
								
								src/callers/register.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										118
									
								
								src/callers/register.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,118 @@ | ||||
| use axum::{Json, http::StatusCode}; | ||||
|  | ||||
| use crate::hashing; | ||||
| use crate::repo; | ||||
|  | ||||
| pub mod request { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct Request { | ||||
|         #[serde(skip_serializing_if = "String::is_empty")] | ||||
|         pub username: String, | ||||
|         #[serde(skip_serializing_if = "String::is_empty")] | ||||
|         pub password: String, | ||||
|         #[serde(skip_serializing_if = "String::is_empty")] | ||||
|         pub email: String, | ||||
|         #[serde(skip_serializing_if = "String::is_empty")] | ||||
|         pub phone: String, | ||||
|         #[serde(skip_serializing_if = "String::is_empty")] | ||||
|         pub firstname: String, | ||||
|         #[serde(skip_serializing_if = "String::is_empty")] | ||||
|         pub lastname: String, | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub mod response { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct Response { | ||||
|         pub message: String, | ||||
|         pub data: Vec<icarus_models::user::User>, | ||||
|     } | ||||
| } | ||||
|  | ||||
| /// Endpoint to register a user | ||||
| #[utoipa::path( | ||||
|     post, | ||||
|     path = super::endpoints::REGISTER, | ||||
|     request_body( | ||||
|         content = request::Request, | ||||
|         description = "Data required to register", | ||||
|         content_type = "application/json" | ||||
|     ), | ||||
|     responses( | ||||
|         (status = 201, description = "User created", body = response::Response), | ||||
|         (status = 404, description = "User already exists", body = response::Response), | ||||
|         (status = 400, description = "Issue creating user", body = response::Response) | ||||
|     ) | ||||
| )] | ||||
| pub async fn register_user( | ||||
|     axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||
|     Json(payload): Json<request::Request>, | ||||
| ) -> (StatusCode, Json<response::Response>) { | ||||
|     let mut user = icarus_models::user::User { | ||||
|         username: payload.username.clone(), | ||||
|         password: payload.password.clone(), | ||||
|         email: payload.email.clone(), | ||||
|         phone: payload.phone.clone(), | ||||
|         firstname: payload.firstname.clone(), | ||||
|         lastname: payload.lastname.clone(), | ||||
|         status: String::from("Active"), | ||||
|         email_verified: true, | ||||
|         ..Default::default() | ||||
|     }; | ||||
|  | ||||
|     match repo::user::exists(&pool, &user.username).await { | ||||
|         Ok(res) => { | ||||
|             if res { | ||||
|                 ( | ||||
|                     StatusCode::BAD_REQUEST, | ||||
|                     Json(response::Response { | ||||
|                         message: String::from("Error"), | ||||
|                         data: Vec::new(), | ||||
|                     }), | ||||
|                 ) | ||||
|             } else { | ||||
|                 let salt_string = hashing::generate_salt().unwrap(); | ||||
|                 let mut salt = icarus_models::user::salt::Salt::default(); | ||||
|                 let generated_salt = salt_string; | ||||
|                 salt.salt = generated_salt.to_string(); | ||||
|                 salt.id = repo::salt::insert(&pool, &salt).await.unwrap(); | ||||
|                 user.salt_id = salt.id; | ||||
|                 let hashed_password = | ||||
|                     hashing::hash_password(&user.password, &generated_salt).unwrap(); | ||||
|                 user.password = hashed_password; | ||||
|  | ||||
|                 match repo::user::insert(&pool, &user).await { | ||||
|                     Ok((id, date_created)) => { | ||||
|                         user.id = id; | ||||
|                         user.date_created = date_created; | ||||
|                         ( | ||||
|                             StatusCode::CREATED, | ||||
|                             Json(response::Response { | ||||
|                                 message: String::from("User created"), | ||||
|                                 data: vec![user], | ||||
|                             }), | ||||
|                         ) | ||||
|                     } | ||||
|                     Err(err) => ( | ||||
|                         StatusCode::BAD_REQUEST, | ||||
|                         Json(response::Response { | ||||
|                             message: err.to_string(), | ||||
|                             data: vec![user], | ||||
|                         }), | ||||
|                     ), | ||||
|                 } | ||||
|             } | ||||
|         } | ||||
|         Err(err) => ( | ||||
|             StatusCode::BAD_REQUEST, | ||||
|             Json(response::Response { | ||||
|                 message: err.to_string(), | ||||
|                 data: vec![user], | ||||
|             }), | ||||
|         ), | ||||
|     } | ||||
| } | ||||
							
								
								
									
										10
									
								
								src/config/mod.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										10
									
								
								src/config/mod.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,10 @@ | ||||
| pub fn get_full() -> String { | ||||
|     get_address() + ":" + &get_port() | ||||
| } | ||||
| fn get_address() -> String { | ||||
|     String::from("0.0.0.0") | ||||
| } | ||||
|  | ||||
| fn get_port() -> String { | ||||
|     String::from("8001") | ||||
| } | ||||
							
								
								
									
										101
									
								
								src/hashing/mod.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										101
									
								
								src/hashing/mod.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,101 @@ | ||||
| use argon2::{ | ||||
|     Argon2, // The Argon2 algorithm struct | ||||
|     PasswordVerifier, | ||||
|     password_hash::{ | ||||
|         PasswordHasher, | ||||
|         SaltString, | ||||
|         rand_core::OsRng, // Secure random number generator | ||||
|     }, | ||||
| }; | ||||
|  | ||||
| pub fn generate_salt() -> Result<SaltString, argon2::Error> { | ||||
|     // Generate a random salt | ||||
|     // SaltString::generate uses OsRng internally for cryptographic security | ||||
|     Ok(SaltString::generate(&mut OsRng)) | ||||
| } | ||||
|  | ||||
| pub fn get_salt(s: &str) -> Result<SaltString, argon2::password_hash::Error> { | ||||
|     SaltString::from_b64(s) | ||||
| } | ||||
|  | ||||
| pub fn hash_password( | ||||
|     password: &String, | ||||
|     salt: &SaltString, | ||||
| ) -> Result<String, argon2::password_hash::Error> { | ||||
|     let password_bytes = password.as_bytes(); | ||||
|  | ||||
|     // Create an Argon2 instance with default parameters (recommended) | ||||
|     // You could customize parameters here if needed, but defaults are strong | ||||
|     let argon2 = Argon2::default(); | ||||
|  | ||||
|     // Hash the password with the salt | ||||
|     // The output is a PasswordHash string format that includes algorithm, version, | ||||
|     // parameters, salt, and the hash itself. | ||||
|     Ok(argon2.hash_password(password_bytes, salt)?.to_string()) | ||||
| } | ||||
|  | ||||
| pub fn verify_password( | ||||
|     password_attempt: &String, | ||||
|     stored_hash: String, | ||||
| ) -> Result<bool, argon2::password_hash::Error> { | ||||
|     let password_bytes = password_attempt.as_bytes(); | ||||
|  | ||||
|     // Parse the stored hash string | ||||
|     // This extracts the salt, parameters, and hash digest | ||||
|     let parsed_hash = argon2::PasswordHash::new(stored_hash.as_str())?; | ||||
|  | ||||
|     // Create an Argon2 instance (it will use the parameters from the parsed hash) | ||||
|     // Verify the password against the parsed hash | ||||
|     // This automatically uses the correct salt and parameters embedded in `parsed_hash` | ||||
|     match Argon2::default().verify_password(password_bytes, &parsed_hash) { | ||||
|         Ok(()) => Ok(true),                                       // Passwords match | ||||
|         Err(argon2::password_hash::Error::Password) => Ok(false), // Passwords don't match | ||||
|         Err(e) => Err(e), // Some other error occurred (e.g., invalid hash format) | ||||
|     } | ||||
| } | ||||
|  | ||||
| #[cfg(test)] | ||||
| mod tests { | ||||
|     use super::*; | ||||
|  | ||||
|     #[test] | ||||
|     fn test_hash_password() { | ||||
|         let some_password = String::from("somethingrandom"); | ||||
|         match hash_password(&some_password, &generate_salt().unwrap()) { | ||||
|             Ok(p) => match verify_password(&some_password, p.clone()) { | ||||
|                 Ok(res) => { | ||||
|                     assert_eq!(res, true); | ||||
|                 } | ||||
|                 Err(err) => { | ||||
|                     assert!(false, "Error: {:?}", err.to_string()); | ||||
|                 } | ||||
|             }, | ||||
|             Err(eerr) => { | ||||
|                 assert!(false, "Error: {:?}", eerr.to_string()); | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     #[test] | ||||
|     fn test_wrong_password() { | ||||
|         let some_password = String::from("somethingrandom"); | ||||
|         match hash_password(&some_password, &generate_salt().unwrap()) { | ||||
|             Ok(p) => { | ||||
|                 match verify_password(&some_password, p.clone()) { | ||||
|                     Ok(res) => { | ||||
|                         assert_eq!(res, true, "Passwords are not verified"); | ||||
|                     } | ||||
|                     Err(err) => { | ||||
|                         assert!(false, "Error: {:?}", err.to_string()); | ||||
|                     } | ||||
|                 } | ||||
|                 let wrong_password = String::from("Differentanotherlevel"); | ||||
|                 let result = verify_password(&wrong_password, p.clone()).unwrap(); | ||||
|                 assert_eq!(false, result, "Passwords should not match"); | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {:?}", err.to_string()); | ||||
|             } | ||||
|         } | ||||
|     } | ||||
| } | ||||
							
								
								
									
										36
									
								
								src/lib.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										36
									
								
								src/lib.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,36 @@ | ||||
| // TODO: Get rid of this file and place the code in more appropriate places | ||||
| pub mod callers; | ||||
| pub mod config; | ||||
| pub mod hashing; | ||||
| pub mod repo; | ||||
| pub mod token_stuff; | ||||
|  | ||||
| mod connection_settings { | ||||
|     pub const MAXCONN: u32 = 5; | ||||
| } | ||||
|  | ||||
| pub mod db { | ||||
|  | ||||
|     use sqlx::postgres::PgPoolOptions; | ||||
|  | ||||
|     use crate::connection_settings; | ||||
|  | ||||
|     pub async fn create_pool() -> Result<sqlx::PgPool, sqlx::Error> { | ||||
|         let database_url = icarus_envy::environment::get_db_url().await.value; | ||||
|         println!("Database url: {database_url}"); | ||||
|  | ||||
|         PgPoolOptions::new() | ||||
|             .max_connections(connection_settings::MAXCONN) | ||||
|             .connect(&database_url) | ||||
|             .await | ||||
|     } | ||||
|  | ||||
|     pub async fn migrations(pool: &sqlx::PgPool) { | ||||
|         // Run migrations using the sqlx::migrate! macro | ||||
|         // Assumes your migrations are in a ./migrations folder relative to Cargo.toml | ||||
|         sqlx::migrate!("./migrations") | ||||
|             .run(pool) | ||||
|             .await | ||||
|             .expect("Failed to run migrations"); | ||||
|     } | ||||
| } | ||||
							
								
								
									
										562
									
								
								src/main.rs
									
									
									
									
									
								
							
							
						
						
									
										562
									
								
								src/main.rs
									
									
									
									
									
								
							| @@ -1,41 +1,549 @@ | ||||
| use axum::{ | ||||
|     // Json, | ||||
|     Router, | ||||
|     // http::StatusCode, | ||||
|     routing::get, | ||||
|     // routing::{get, post}, | ||||
| }; | ||||
| // use serde::{Deserialize, Serialize}; | ||||
| use icarus_auth::callers; | ||||
| use icarus_auth::config; | ||||
|  | ||||
| #[tokio::main] | ||||
| async fn main() { | ||||
|     // initialize tracing | ||||
|     tracing_subscriber::fmt::init(); | ||||
|  | ||||
|     // build our application with a route | ||||
|     let app = Router::new() | ||||
|         // `GET /` goes to `root` | ||||
|         .route("/", get(root)); | ||||
|     // `POST /users` goes to `create_user` | ||||
|     // .route("/users", post(create_user)); | ||||
|     let app = init::app().await; | ||||
|  | ||||
|     // run our app with hyper, listening globally on port 3000 | ||||
|     let listener = tokio::net::TcpListener::bind(get_full()).await.unwrap(); | ||||
|     // run our app with hyper, listening globally on port 8001 | ||||
|     let url = config::get_full(); | ||||
|     let listener = tokio::net::TcpListener::bind(url).await.unwrap(); | ||||
|     axum::serve(listener, app).await.unwrap(); | ||||
| } | ||||
|  | ||||
| fn get_full() -> String { | ||||
|     get_address() + ":" + &get_port() | ||||
| } | ||||
| fn get_address() -> String { | ||||
|     String::from("0.0.0.0") | ||||
| mod init { | ||||
|     use axum::{ | ||||
|         Router, | ||||
|         routing::{get, post}, | ||||
|     }; | ||||
|     use utoipa::OpenApi; | ||||
|  | ||||
|     use crate::callers; | ||||
|     use callers::common as common_callers; | ||||
|     use callers::login as login_caller; | ||||
|     use callers::register as register_caller; | ||||
|     use login_caller::endpoint as login_endpoints; | ||||
|     use login_caller::response as login_responses; | ||||
|     use register_caller::response as register_responses; | ||||
|  | ||||
|     #[derive(utoipa::OpenApi)] | ||||
|     #[openapi( | ||||
|         paths( | ||||
|             common_callers::endpoint::db_ping, common_callers::endpoint::root, | ||||
|             register_caller::register_user, | ||||
|             login_endpoints::login, login_endpoints::service_login, login_endpoints::refresh_token | ||||
|             ), | ||||
|         components(schemas(common_callers::response::TestResult, | ||||
|                 register_responses::Response, | ||||
|             login_responses::Response, login_responses::service_login::Response, login_responses::refresh_token::Response)), | ||||
|         tags( | ||||
|             (name = "Icarus Auth API", description = "Auth API for Icarus API") | ||||
|             ) | ||||
|     )] | ||||
|     struct ApiDoc; | ||||
|  | ||||
|     mod cors { | ||||
|         pub async fn configure_cors() -> tower_http::cors::CorsLayer { | ||||
|             // Start building the CORS layer with common settings | ||||
|             let cors = tower_http::cors::CorsLayer::new() | ||||
|                 .allow_methods([ | ||||
|                     axum::http::Method::GET, | ||||
|                     axum::http::Method::POST, | ||||
|                     axum::http::Method::PUT, | ||||
|                     axum::http::Method::DELETE, | ||||
|                 ]) // Specify allowed methods:cite[2] | ||||
|                 .allow_headers([ | ||||
|                     axum::http::header::CONTENT_TYPE, | ||||
|                     axum::http::header::AUTHORIZATION, | ||||
|                 ]) // Specify allowed headers:cite[2] | ||||
|                 .allow_credentials(true) // If you need to send cookies or authentication headers:cite[2] | ||||
|                 .max_age(std::time::Duration::from_secs(3600)); // Cache the preflight response for 1 hour:cite[2] | ||||
|  | ||||
|             // Dynamically set the allowed origin based on the environment | ||||
|             match std::env::var(icarus_envy::keys::APP_ENV).as_deref() { | ||||
|                 Ok("production") => { | ||||
|                     let allowed_origins_env = icarus_envy::environment::get_allowed_origins().await; | ||||
|                     match icarus_envy::utility::delimitize(&allowed_origins_env) { | ||||
|                         Ok(alwd) => { | ||||
|                             let allowed_origins: Vec<axum::http::HeaderValue> = alwd | ||||
|                                 .into_iter() | ||||
|                                 .map(|s| s.parse::<axum::http::HeaderValue>().unwrap()) | ||||
|                                 .collect(); | ||||
|                             cors.allow_origin(allowed_origins) | ||||
|                         } | ||||
|                         Err(err) => { | ||||
|                             eprintln!( | ||||
|                                 "Could not parse out allowed origins from env: Error: {err:?}" | ||||
|                             ); | ||||
|                             std::process::exit(-1); | ||||
|                         } | ||||
|                     } | ||||
|                 } | ||||
|                 _ => { | ||||
|                     // Development (default): Allow localhost origins | ||||
|                     cors.allow_origin(vec![ | ||||
|                         "http://localhost:4200".parse().unwrap(), | ||||
|                         "http://127.0.0.1:4200".parse().unwrap(), | ||||
|                     ]) | ||||
|                 } | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn routes() -> Router { | ||||
|         // build our application with a route | ||||
|         Router::new() | ||||
|             .route( | ||||
|                 callers::endpoints::DBTEST, | ||||
|                 get(callers::common::endpoint::db_ping), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::ROOT, | ||||
|                 get(callers::common::endpoint::root), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::REGISTER, | ||||
|                 post(callers::register::register_user), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::LOGIN, | ||||
|                 post(callers::login::endpoint::login), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::SERVICE_LOGIN, | ||||
|                 post(callers::login::endpoint::service_login), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::REFRESH_TOKEN, | ||||
|                 post(callers::login::endpoint::refresh_token), | ||||
|             ) | ||||
|             .layer(cors::configure_cors().await) | ||||
|     } | ||||
|  | ||||
|     pub async fn app() -> Router { | ||||
|         let pool = icarus_auth::db::create_pool() | ||||
|             .await | ||||
|             .expect("Failed to create pool"); | ||||
|  | ||||
|         icarus_auth::db::migrations(&pool).await; | ||||
|  | ||||
|         routes() | ||||
|             .await | ||||
|             .merge( | ||||
|                 utoipa_swagger_ui::SwaggerUi::new("/swagger-ui") | ||||
|                     .url("/api-docs/openapi.json", ApiDoc::openapi()), | ||||
|             ) | ||||
|             .layer(axum::Extension(pool)) | ||||
|     } | ||||
| } | ||||
|  | ||||
| fn get_port() -> String { | ||||
|     String::from("3000") | ||||
| } | ||||
| #[cfg(test)] | ||||
| mod tests { | ||||
|     use super::*; | ||||
|  | ||||
| // basic handler that responds with a static string | ||||
| async fn root() -> &'static str { | ||||
|     "Hello, World!" | ||||
|     use axum::{ | ||||
|         body::Body, | ||||
|         http::{Request, StatusCode}, | ||||
|     }; | ||||
|     use http_body_util::BodyExt; | ||||
|     use serde_json::json; | ||||
|     use tower::ServiceExt; // for `call`, `oneshot`, and `ready` | ||||
|  | ||||
|     mod db_mgr { | ||||
|         use std::str::FromStr; | ||||
|  | ||||
|         pub const LIMIT: usize = 6; | ||||
|  | ||||
|         pub async fn get_pool() -> Result<sqlx::PgPool, sqlx::Error> { | ||||
|             let tm_db_url = icarus_envy::environment::get_db_url().await.value; | ||||
|             let tm_options = sqlx::postgres::PgConnectOptions::from_str(&tm_db_url).unwrap(); | ||||
|             sqlx::PgPool::connect_with(tm_options).await | ||||
|         } | ||||
|  | ||||
|         pub async fn generate_db_name() -> String { | ||||
|             let db_name = get_database_name().await.unwrap() | ||||
|                 + &"_" | ||||
|                 + &uuid::Uuid::new_v4().to_string()[..LIMIT]; | ||||
|             db_name | ||||
|         } | ||||
|  | ||||
|         pub async fn connect_to_db(db_name: &str) -> Result<sqlx::PgPool, sqlx::Error> { | ||||
|             let db_url = icarus_envy::environment::get_db_url().await.value; | ||||
|             let options = sqlx::postgres::PgConnectOptions::from_str(&db_url)?.database(db_name); | ||||
|             sqlx::PgPool::connect_with(options).await | ||||
|         } | ||||
|  | ||||
|         pub async fn create_database( | ||||
|             template_pool: &sqlx::PgPool, | ||||
|             db_name: &str, | ||||
|         ) -> Result<(), sqlx::Error> { | ||||
|             let create_query = format!("CREATE DATABASE {}", db_name); | ||||
|             match sqlx::query(&create_query).execute(template_pool).await { | ||||
|                 Ok(_) => Ok(()), | ||||
|                 Err(e) => Err(e), | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         // Function to drop a database | ||||
|         pub async fn drop_database( | ||||
|             template_pool: &sqlx::PgPool, | ||||
|             db_name: &str, | ||||
|         ) -> Result<(), sqlx::Error> { | ||||
|             let drop_query = format!("DROP DATABASE IF EXISTS {} WITH (FORCE)", db_name); | ||||
|             sqlx::query(&drop_query).execute(template_pool).await?; | ||||
|             Ok(()) | ||||
|         } | ||||
|  | ||||
|         pub async fn get_database_name() -> Result<String, Box<dyn std::error::Error>> { | ||||
|             let database_url = icarus_envy::environment::get_db_url().await.value; | ||||
|  | ||||
|             let parsed_url = url::Url::parse(&database_url)?; | ||||
|             if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" { | ||||
|                 match parsed_url | ||||
|                     .path_segments() | ||||
|                     .and_then(|segments| segments.last().map(|s| s.to_string())) | ||||
|                 { | ||||
|                     Some(sss) => Ok(sss), | ||||
|                     None => Err("Error parsing".into()), | ||||
|                 } | ||||
|             } else { | ||||
|                 // Handle other database types if needed | ||||
|                 Err("Error parsing".into()) | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     fn get_test_register_request() -> icarus_auth::callers::register::request::Request { | ||||
|         icarus_auth::callers::register::request::Request { | ||||
|             username: String::from("somethingsss"), | ||||
|             password: String::from("Raindown!"), | ||||
|             email: String::from("dev@null.com"), | ||||
|             phone: String::from("1234567890"), | ||||
|             firstname: String::from("Bob"), | ||||
|             lastname: String::from("Smith"), | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     fn get_test_register_payload( | ||||
|         usr: &icarus_auth::callers::register::request::Request, | ||||
|     ) -> serde_json::Value { | ||||
|         json!({ | ||||
|             "username": &usr.username, | ||||
|             "password": &usr.password, | ||||
|             "email": &usr.email, | ||||
|             "phone": &usr.phone, | ||||
|             "firstname": &usr.firstname, | ||||
|             "lastname": &usr.lastname, | ||||
|         }) | ||||
|     } | ||||
|  | ||||
|     pub mod requests { | ||||
|         use tower::ServiceExt; // for `call`, `oneshot`, and `ready` | ||||
|  | ||||
|         pub async fn register( | ||||
|             app: &axum::Router, | ||||
|             usr: &icarus_auth::callers::register::request::Request, | ||||
|         ) -> Result<axum::response::Response, std::convert::Infallible> { | ||||
|             let payload = super::get_test_register_payload(&usr); | ||||
|             let req = axum::http::Request::builder() | ||||
|                 .method(axum::http::Method::POST) | ||||
|                 .uri(crate::callers::endpoints::REGISTER) | ||||
|                 .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                 .body(axum::body::Body::from(payload.to_string())) | ||||
|                 .unwrap(); | ||||
|  | ||||
|             app.clone().oneshot(req).await | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     #[tokio::test] | ||||
|     async fn test_hello_world() { | ||||
|         let app = init::app().await; | ||||
|  | ||||
|         // `Router` implements `tower::Service<Request<Body>>` so we can | ||||
|         // call it like any tower service, no need to run an HTTP server. | ||||
|         let response = app | ||||
|             .oneshot( | ||||
|                 Request::builder() | ||||
|                     .uri(callers::endpoints::ROOT) | ||||
|                     .body(Body::empty()) | ||||
|                     .unwrap(), | ||||
|             ) | ||||
|             .await | ||||
|             .unwrap(); | ||||
|  | ||||
|         assert_eq!(response.status(), StatusCode::OK); | ||||
|  | ||||
|         let body = response.into_body().collect().await.unwrap().to_bytes(); | ||||
|         assert_eq!(&body[..], b"Hello, World!"); | ||||
|     } | ||||
|  | ||||
|     #[tokio::test] | ||||
|     async fn test_register_user() { | ||||
|         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||
|  | ||||
|         let db_name = db_mgr::generate_db_name().await; | ||||
|  | ||||
|         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||
|             Ok(_) => { | ||||
|                 println!("Success"); | ||||
|             } | ||||
|             Err(e) => { | ||||
|                 assert!(false, "Error: {:?}", e.to_string()); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||
|  | ||||
|         icarus_auth::db::migrations(&pool).await; | ||||
|  | ||||
|         let app = init::routes().await.layer(axum::Extension(pool)); | ||||
|  | ||||
|         let usr = get_test_register_request(); | ||||
|  | ||||
|         let response = requests::register(&app, &usr).await; | ||||
|  | ||||
|         match response { | ||||
|             Ok(resp) => { | ||||
|                 assert_eq!( | ||||
|                     resp.status(), | ||||
|                     StatusCode::CREATED, | ||||
|                     "Message: {:?} {:?}", | ||||
|                     resp, | ||||
|                     usr.username | ||||
|                 ); | ||||
|                 let body = axum::body::to_bytes(resp.into_body(), usize::MAX) | ||||
|                     .await | ||||
|                     .unwrap(); | ||||
|                 let parsed_body: callers::register::response::Response = | ||||
|                     serde_json::from_slice(&body).unwrap(); | ||||
|                 let returned_usr = &parsed_body.data[0]; | ||||
|  | ||||
|                 assert_eq!(false, returned_usr.id.is_nil(), "Id is not populated"); | ||||
|  | ||||
|                 assert_eq!( | ||||
|                     usr.username, returned_usr.username, | ||||
|                     "Usernames do not match" | ||||
|                 ); | ||||
|                 assert!(returned_usr.date_created.is_some(), "Date Created is empty"); | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {:?}", err.to_string()); | ||||
|             } | ||||
|         }; | ||||
|  | ||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||
|     } | ||||
|  | ||||
|     #[tokio::test] | ||||
|     async fn test_login_user() { | ||||
|         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||
|  | ||||
|         let db_name = db_mgr::generate_db_name().await; | ||||
|  | ||||
|         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||
|             Ok(_) => { | ||||
|                 println!("Success"); | ||||
|             } | ||||
|             Err(e) => { | ||||
|                 assert!(false, "Error: {:?}", e.to_string()); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||
|  | ||||
|         icarus_auth::db::migrations(&pool).await; | ||||
|  | ||||
|         let app = init::routes().await.layer(axum::Extension(pool)); | ||||
|  | ||||
|         let usr = get_test_register_request(); | ||||
|  | ||||
|         let response = requests::register(&app, &usr).await; | ||||
|  | ||||
|         match response { | ||||
|             Ok(resp) => { | ||||
|                 assert_eq!( | ||||
|                     resp.status(), | ||||
|                     StatusCode::CREATED, | ||||
|                     "Message: {:?} {:?}", | ||||
|                     resp, | ||||
|                     usr.username | ||||
|                 ); | ||||
|                 let body = axum::body::to_bytes(resp.into_body(), usize::MAX) | ||||
|                     .await | ||||
|                     .unwrap(); | ||||
|                 let parsed_body: callers::register::response::Response = | ||||
|                     serde_json::from_slice(&body).unwrap(); | ||||
|                 let returned_usr = &parsed_body.data[0]; | ||||
|  | ||||
|                 assert_eq!(false, returned_usr.id.is_nil(), "Id is not populated"); | ||||
|  | ||||
|                 assert_eq!( | ||||
|                     usr.username, returned_usr.username, | ||||
|                     "Usernames do not match" | ||||
|                 ); | ||||
|                 assert!(returned_usr.date_created.is_some(), "Date Created is empty"); | ||||
|  | ||||
|                 let login_payload = json!({ | ||||
|                     "username": &usr.username, | ||||
|                     "password": &usr.password, | ||||
|                 }); | ||||
|  | ||||
|                 match app | ||||
|                     .oneshot( | ||||
|                         Request::builder() | ||||
|                             .method(axum::http::Method::POST) | ||||
|                             .uri(callers::endpoints::LOGIN) | ||||
|                             .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                             .body(Body::from(login_payload.to_string())) | ||||
|                             .unwrap(), | ||||
|                     ) | ||||
|                     .await | ||||
|                 { | ||||
|                     Ok(resp) => { | ||||
|                         assert_eq!(StatusCode::OK, resp.status(), "Status is not right"); | ||||
|                         let body = axum::body::to_bytes(resp.into_body(), usize::MAX) | ||||
|                             .await | ||||
|                             .unwrap(); | ||||
|                         let parsed_body: callers::login::response::Response = | ||||
|                             serde_json::from_slice(&body).unwrap(); | ||||
|                         let login_result = &parsed_body.data[0]; | ||||
|                         assert!(!login_result.id.is_nil(), "Id is nil"); | ||||
|                     } | ||||
|                     Err(err) => { | ||||
|                         assert!(false, "Error: {:?}", err.to_string()); | ||||
|                     } | ||||
|                 } | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {:?}", err.to_string()); | ||||
|             } | ||||
|         }; | ||||
|  | ||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||
|     } | ||||
|  | ||||
|     #[tokio::test] | ||||
|     async fn test_service_login_user() { | ||||
|         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||
|  | ||||
|         let db_name = db_mgr::generate_db_name().await; | ||||
|  | ||||
|         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||
|             Ok(_) => { | ||||
|                 println!("Success"); | ||||
|             } | ||||
|             Err(e) => { | ||||
|                 assert!(false, "Error: {:?}", e.to_string()); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||
|  | ||||
|         icarus_auth::db::migrations(&pool).await; | ||||
|  | ||||
|         let app = init::routes().await.layer(axum::Extension(pool)); | ||||
|         let passphrase = | ||||
|             String::from("iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH"); | ||||
|         let payload = serde_json::json!({ | ||||
|             "passphrase": passphrase | ||||
|         }); | ||||
|  | ||||
|         match app | ||||
|             .oneshot( | ||||
|                 Request::builder() | ||||
|                     .method(axum::http::Method::POST) | ||||
|                     .uri(callers::endpoints::SERVICE_LOGIN) | ||||
|                     .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                     .body(Body::from(payload.to_string())) | ||||
|                     .unwrap(), | ||||
|             ) | ||||
|             .await | ||||
|         { | ||||
|             Ok(response) => { | ||||
|                 assert_eq!(StatusCode::OK, response.status(), "Status is not right"); | ||||
|                 let body = axum::body::to_bytes(response.into_body(), usize::MAX) | ||||
|                     .await | ||||
|                     .unwrap(); | ||||
|                 let parsed_body: callers::login::response::service_login::Response = | ||||
|                     serde_json::from_slice(&body).unwrap(); | ||||
|                 let _login_result = &parsed_body.data[0]; | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {err:?}"); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||
|     } | ||||
|  | ||||
|     #[tokio::test] | ||||
|     async fn test_refresh_token() { | ||||
|         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||
|  | ||||
|         let db_name = db_mgr::generate_db_name().await; | ||||
|  | ||||
|         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||
|             Ok(_) => { | ||||
|                 println!("Success"); | ||||
|             } | ||||
|             Err(e) => { | ||||
|                 assert!(false, "Error: {:?}", e.to_string()); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||
|  | ||||
|         icarus_auth::db::migrations(&pool).await; | ||||
|  | ||||
|         let app = init::routes().await.layer(axum::Extension(pool)); | ||||
|         let id = uuid::Uuid::parse_str("22f9c775-cce9-457a-a147-9dafbb801f61").unwrap(); | ||||
|         let key = icarus_envy::environment::get_secret_key().await.value; | ||||
|  | ||||
|         match icarus_auth::token_stuff::create_service_token(&key, &id) { | ||||
|             Ok((token, _expire)) => { | ||||
|                 let payload = serde_json::json!({ | ||||
|                     "access_token": token | ||||
|                 }); | ||||
|  | ||||
|                 match app | ||||
|                     .oneshot( | ||||
|                         Request::builder() | ||||
|                             .method(axum::http::Method::POST) | ||||
|                             .uri(callers::endpoints::REFRESH_TOKEN) | ||||
|                             .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                             .body(Body::from(payload.to_string())) | ||||
|                             .unwrap(), | ||||
|                     ) | ||||
|                     .await | ||||
|                 { | ||||
|                     Ok(response) => { | ||||
|                         let body = axum::body::to_bytes(response.into_body(), usize::MAX) | ||||
|                             .await | ||||
|                             .unwrap(); | ||||
|                         let parsed_body: callers::login::response::service_login::Response = | ||||
|                             serde_json::from_slice(&body).unwrap(); | ||||
|                         let login_result = &parsed_body.data[0]; | ||||
|  | ||||
|                         assert_eq!( | ||||
|                             id, login_result.id, | ||||
|                             "The Id from the response does not match {id:?} {:?}", | ||||
|                             login_result.id | ||||
|                         ); | ||||
|                     } | ||||
|                     Err(err) => { | ||||
|                         assert!(false, "Error: {err:?}"); | ||||
|                     } | ||||
|                 } | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {err:?}"); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||
|     } | ||||
| } | ||||
|   | ||||
							
								
								
									
										250
									
								
								src/repo/mod.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										250
									
								
								src/repo/mod.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,250 @@ | ||||
| pub mod user { | ||||
|     use sqlx::Row; | ||||
|  | ||||
|     #[derive(Debug, serde::Serialize, sqlx::FromRow)] | ||||
|     pub struct InsertedData { | ||||
|         pub id: uuid::Uuid, | ||||
|         pub date_created: Option<time::OffsetDateTime>, | ||||
|     } | ||||
|  | ||||
|     pub async fn get( | ||||
|         pool: &sqlx::PgPool, | ||||
|         username: &String, | ||||
|     ) -> Result<icarus_models::user::User, sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|         SELECT * FROM "user" WHERE username = $1 | ||||
|         "#, | ||||
|         ) | ||||
|         .bind(username) | ||||
|         .fetch_optional(pool) | ||||
|         .await; | ||||
|  | ||||
|         match result { | ||||
|             Ok(r) => match r { | ||||
|                 Some(r) => Ok(icarus_models::user::User { | ||||
|                     id: r.try_get("id")?, | ||||
|                     username: r.try_get("username")?, | ||||
|                     password: r.try_get("password")?, | ||||
|                     email: r.try_get("email")?, | ||||
|                     email_verified: r.try_get("email_verified")?, | ||||
|                     phone: r.try_get("phone")?, | ||||
|                     salt_id: r.try_get("salt_id")?, | ||||
|                     firstname: r.try_get("firstname")?, | ||||
|                     lastname: r.try_get("lastname")?, | ||||
|                     date_created: r.try_get("date_created")?, | ||||
|                     last_login: r.try_get("last_login")?, | ||||
|                     status: r.try_get("status")?, | ||||
|                 }), | ||||
|                 None => Err(sqlx::Error::RowNotFound), | ||||
|             }, | ||||
|             Err(e) => Err(e), | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn update_last_login( | ||||
|         pool: &sqlx::PgPool, | ||||
|         user: &icarus_models::user::User, | ||||
|         time: &time::OffsetDateTime, | ||||
|     ) -> Result<time::OffsetDateTime, sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|             UPDATE "user" SET last_login = $1 WHERE id = $2 RETURNING last_login | ||||
|             "#, | ||||
|         ) | ||||
|         .bind(time) | ||||
|         .bind(user.id) | ||||
|         .fetch_optional(pool) | ||||
|         .await | ||||
|         .map_err(|e| { | ||||
|             eprintln!("Error updating time: {e}"); | ||||
|             e | ||||
|         }); | ||||
|  | ||||
|         match result { | ||||
|             Ok(row) => match row { | ||||
|                 Some(r) => { | ||||
|                     let last_login: time::OffsetDateTime = r | ||||
|                         .try_get("last_login") | ||||
|                         .map_err(|_e| sqlx::Error::RowNotFound)?; | ||||
|                     Ok(last_login) | ||||
|                 } | ||||
|                 None => Err(sqlx::Error::RowNotFound), | ||||
|             }, | ||||
|             Err(err) => Err(err), | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn exists(pool: &sqlx::PgPool, username: &String) -> Result<bool, sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|         SELECT 1 FROM "user" WHERE username = $1 | ||||
|         "#, | ||||
|         ) | ||||
|         .bind(username) | ||||
|         .fetch_optional(pool) | ||||
|         .await; | ||||
|  | ||||
|         match result { | ||||
|             Ok(r) => Ok(r.is_some()), | ||||
|             Err(e) => Err(e), | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn insert( | ||||
|         pool: &sqlx::PgPool, | ||||
|         user: &icarus_models::user::User, | ||||
|     ) -> Result<(uuid::Uuid, std::option::Option<time::OffsetDateTime>), sqlx::Error> { | ||||
|         let row = sqlx::query( | ||||
|             r#" | ||||
|                 INSERT INTO "user" (username, password, email, phone, firstname, lastname, email_verified, status, salt_id)  | ||||
|                 VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9) | ||||
|                 RETURNING id, date_created; | ||||
|             "#) | ||||
|             .bind(&user.username) | ||||
|             .bind(&user.password) | ||||
|             .bind(&user.email) | ||||
|             .bind(&user.phone) | ||||
|             .bind(&user.firstname) | ||||
|             .bind(&user.lastname) | ||||
|             .bind(user.email_verified) | ||||
|             .bind(&user.status) | ||||
|             .bind(user.salt_id) | ||||
|         .fetch_one(pool) | ||||
|         .await | ||||
|         .map_err(|e| { | ||||
|             eprintln!("Error inserting item: {e}"); | ||||
|             e | ||||
|         })?; | ||||
|  | ||||
|         let result = InsertedData { | ||||
|             id: row.try_get("id").map_err(|_e| sqlx::Error::RowNotFound)?, | ||||
|             date_created: row | ||||
|                 .try_get("date_created") | ||||
|                 .map_err(|_e| sqlx::Error::RowNotFound)?, | ||||
|         }; | ||||
|  | ||||
|         if result.id.is_nil() && result.date_created.is_none() { | ||||
|             Err(sqlx::Error::RowNotFound) | ||||
|         } else { | ||||
|             Ok((result.id, result.date_created)) | ||||
|         } | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub mod salt { | ||||
|     use sqlx::Row; | ||||
|  | ||||
|     #[derive(Debug, serde::Serialize, sqlx::FromRow)] | ||||
|     pub struct InsertedData { | ||||
|         pub id: uuid::Uuid, | ||||
|     } | ||||
|  | ||||
|     pub async fn get( | ||||
|         pool: &sqlx::PgPool, | ||||
|         id: &uuid::Uuid, | ||||
|     ) -> Result<icarus_models::user::salt::Salt, sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|         SELECT * FROM "salt" WHERE id = $1 | ||||
|         "#, | ||||
|         ) | ||||
|         .bind(id) | ||||
|         .fetch_optional(pool) | ||||
|         .await; | ||||
|  | ||||
|         match result { | ||||
|             Ok(r) => match r { | ||||
|                 Some(r) => Ok(icarus_models::user::salt::Salt { | ||||
|                     id: r.try_get("id")?, | ||||
|                     salt: r.try_get("salt")?, | ||||
|                 }), | ||||
|                 None => Err(sqlx::Error::RowNotFound), | ||||
|             }, | ||||
|             Err(e) => Err(e), | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn insert( | ||||
|         pool: &sqlx::PgPool, | ||||
|         salt: &icarus_models::user::salt::Salt, | ||||
|     ) -> Result<uuid::Uuid, sqlx::Error> { | ||||
|         let row = sqlx::query( | ||||
|             r#" | ||||
|                 INSERT INTO "salt" (salt)  | ||||
|                 VALUES ($1) | ||||
|                 RETURNING id; | ||||
|             "#, | ||||
|         ) | ||||
|         .bind(&salt.salt) | ||||
|         .fetch_one(pool) | ||||
|         .await | ||||
|         .map_err(|e| { | ||||
|             eprintln!("Error inserting item: {e}"); | ||||
|             e | ||||
|         })?; | ||||
|  | ||||
|         let result = InsertedData { | ||||
|             id: row.try_get("id").map_err(|_e| sqlx::Error::RowNotFound)?, | ||||
|         }; | ||||
|  | ||||
|         if !result.id.is_nil() { | ||||
|             Ok(result.id) | ||||
|         } else { | ||||
|             Err(sqlx::Error::RowNotFound) | ||||
|         } | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub mod service { | ||||
|     use sqlx::Row; | ||||
|  | ||||
|     pub async fn valid_passphrase( | ||||
|         pool: &sqlx::PgPool, | ||||
|         passphrase: &String, | ||||
|     ) -> Result<(uuid::Uuid, String, time::OffsetDateTime), sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|             SELECT * FROM "passphrase" WHERE passphrase = $1 | ||||
|             "#, | ||||
|         ) | ||||
|         .bind(passphrase) | ||||
|         .fetch_one(pool) | ||||
|         .await; | ||||
|  | ||||
|         match result { | ||||
|             Ok(row) => { | ||||
|                 let id: uuid::Uuid = row.try_get("id")?; | ||||
|                 let passphrase: String = row.try_get("passphrase")?; | ||||
|                 let date_created: Option<time::OffsetDateTime> = row.try_get("date_created")?; | ||||
|  | ||||
|                 Ok((id, passphrase, date_created.unwrap())) | ||||
|             } | ||||
|             Err(err) => Err(err), | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn get_passphrase( | ||||
|         pool: &sqlx::PgPool, | ||||
|         id: &uuid::Uuid, | ||||
|     ) -> Result<(uuid::Uuid, String, time::OffsetDateTime), sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|             SELECT * FROM "passphrase" WHERE id = $1; | ||||
|             "#, | ||||
|         ) | ||||
|         .bind(id) | ||||
|         .fetch_one(pool) | ||||
|         .await; | ||||
|  | ||||
|         match result { | ||||
|             Ok(row) => { | ||||
|                 let returned_id: uuid::Uuid = row.try_get("id")?; | ||||
|                 let passphrase: String = row.try_get("passphrase")?; | ||||
|                 let date_created: time::OffsetDateTime = row.try_get("date_created")?; | ||||
|                 Ok((returned_id, passphrase, date_created)) | ||||
|             } | ||||
|             Err(err) => Err(err), | ||||
|         } | ||||
|     } | ||||
| } | ||||
							
								
								
									
										141
									
								
								src/token_stuff/mod.rs
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										141
									
								
								src/token_stuff/mod.rs
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,141 @@ | ||||
| use josekit::{ | ||||
|     self, | ||||
|     jws::alg::hmac::HmacJwsAlgorithm::Hs256, | ||||
|     jwt::{self}, | ||||
| }; | ||||
|  | ||||
| use time; | ||||
|  | ||||
| pub const KEY_ENV: &str = "SECRET_KEY"; | ||||
| pub const MESSAGE: &str = "Something random"; | ||||
| pub const ISSUER: &str = "icarus_auth"; | ||||
| pub const AUDIENCE: &str = "icarus"; | ||||
|  | ||||
| pub fn get_issued() -> time::Result<time::OffsetDateTime> { | ||||
|     Ok(time::OffsetDateTime::now_utc()) | ||||
| } | ||||
|  | ||||
| pub fn get_expiration(issued: &time::OffsetDateTime) -> Result<time::OffsetDateTime, time::Error> { | ||||
|     let duration_expire = time::Duration::hours(4); | ||||
|     Ok(*issued + duration_expire) | ||||
| } | ||||
|  | ||||
| pub fn create_token( | ||||
|     provided_key: &String, | ||||
|     id: &uuid::Uuid, | ||||
| ) -> Result<(String, i64), josekit::JoseError> { | ||||
|     let resource = icarus_models::token::TokenResource { | ||||
|         message: String::from(MESSAGE), | ||||
|         issuer: String::from(ISSUER), | ||||
|         audiences: vec![String::from(AUDIENCE)], | ||||
|         id: *id, | ||||
|     }; | ||||
|     icarus_models::token::create_token(provided_key, &resource, time::Duration::hours(4)) | ||||
| } | ||||
|  | ||||
| pub fn create_service_token( | ||||
|     provided: &String, | ||||
|     id: &uuid::Uuid, | ||||
| ) -> Result<(String, i64), josekit::JoseError> { | ||||
|     let resource = icarus_models::token::TokenResource { | ||||
|         message: String::from(SERVICE_SUBJECT), | ||||
|         issuer: String::from(ISSUER), | ||||
|         audiences: vec![String::from(AUDIENCE)], | ||||
|         id: *id, | ||||
|     }; | ||||
|     icarus_models::token::create_token(provided, &resource, time::Duration::hours(1)) | ||||
| } | ||||
|  | ||||
| pub fn create_service_refresh_token( | ||||
|     key: &String, | ||||
|     id: &uuid::Uuid, | ||||
| ) -> Result<(String, i64), josekit::JoseError> { | ||||
|     let resource = icarus_models::token::TokenResource { | ||||
|         message: String::from(SERVICE_SUBJECT), | ||||
|         issuer: String::from(ISSUER), | ||||
|         audiences: vec![String::from(AUDIENCE)], | ||||
|         id: *id, | ||||
|     }; | ||||
|     icarus_models::token::create_token(key, &resource, time::Duration::hours(4)) | ||||
| } | ||||
|  | ||||
| pub fn verify_token(key: &String, token: &String) -> bool { | ||||
|     match get_payload(key, token) { | ||||
|         Ok((payload, _header)) => match payload.subject() { | ||||
|             Some(_sub) => true, | ||||
|             None => false, | ||||
|         }, | ||||
|         Err(_err) => false, | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub fn extract_id_from_token(key: &String, token: &String) -> Result<uuid::Uuid, std::io::Error> { | ||||
|     match get_payload(key, token) { | ||||
|         Ok((payload, _header)) => match payload.claim("id") { | ||||
|             Some(id) => match uuid::Uuid::parse_str(id.as_str().unwrap()) { | ||||
|                 Ok(extracted) => Ok(extracted), | ||||
|                 Err(err) => Err(std::io::Error::other(err.to_string())), | ||||
|             }, | ||||
|             None => Err(std::io::Error::other("No claim found")), | ||||
|         }, | ||||
|         Err(err) => Err(std::io::Error::other(err.to_string())), | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub const APP_TOKEN_TYPE: &str = "Icarus_App"; | ||||
| pub const APP_SUBJECT: &str = "Something random"; | ||||
| pub const SERVICE_TOKEN_TYPE: &str = "Icarus_Service"; | ||||
| pub const SERVICE_SUBJECT: &str = "Service random"; | ||||
|  | ||||
| pub fn get_token_type(key: &String, token: &String) -> Result<String, std::io::Error> { | ||||
|     match get_payload(key, token) { | ||||
|         Ok((payload, _header)) => match payload.subject() { | ||||
|             Some(subject) => { | ||||
|                 if subject == APP_SUBJECT { | ||||
|                     Ok(String::from(APP_TOKEN_TYPE)) | ||||
|                 } else if subject == SERVICE_SUBJECT { | ||||
|                     Ok(String::from(SERVICE_TOKEN_TYPE)) | ||||
|                 } else { | ||||
|                     Err(std::io::Error::other(String::from("Invalid subject"))) | ||||
|                 } | ||||
|             } | ||||
|             None => Err(std::io::Error::other(String::from("Invalid payload"))), | ||||
|         }, | ||||
|         Err(err) => Err(std::io::Error::other(err.to_string())), | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub fn is_token_type_valid(token_type: &String) -> bool { | ||||
|     token_type == SERVICE_TOKEN_TYPE | ||||
| } | ||||
|  | ||||
| fn get_payload( | ||||
|     key: &String, | ||||
|     token: &String, | ||||
| ) -> Result<(josekit::jwt::JwtPayload, josekit::jws::JwsHeader), josekit::JoseError> { | ||||
|     let ver = Hs256.verifier_from_bytes(key.as_bytes()).unwrap(); | ||||
|     jwt::decode_with_verifier(token, &ver) | ||||
| } | ||||
|  | ||||
| #[cfg(test)] | ||||
| mod tests { | ||||
|     use super::*; | ||||
|  | ||||
|     #[test] | ||||
|     fn test_tokenize() { | ||||
|         let rt = tokio::runtime::Runtime::new().unwrap(); | ||||
|         let special_key = rt | ||||
|             .block_on(icarus_envy::environment::get_secret_key()) | ||||
|             .value; | ||||
|         let id = uuid::Uuid::new_v4(); | ||||
|         match create_token(&special_key, &id) { | ||||
|             Ok((token, _duration)) => { | ||||
|                 let result = verify_token(&special_key, &token); | ||||
|                 assert!(result, "Token not verified"); | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {:?}", err.to_string()); | ||||
|             } | ||||
|         }; | ||||
|     } | ||||
| } | ||||
		Reference in New Issue
	
	Block a user