Compare commits
	
		
			38 Commits
		
	
	
		
			v0.3.0-dev
			...
			v0.6.1-mai
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 7e44d523f2 | |||
| 59d0ca0c0b | |||
| a02b15c65c | |||
| ebe29df991 | |||
| 473b4ec762 | |||
| a66ab7826c | |||
| 9da068252d | |||
| 2ba037c393 | |||
| a4c943189c | |||
| eb1e2990f9 | |||
| 99390ce8b7 | |||
| 5967ed5b13 | |||
| be4d1109a7 | |||
| 4353414c69 | |||
| c176d0fcf3 | |||
| c8b8d470dc | |||
| bcd0e607ef | |||
| 70de6b862f | |||
| 8c902b9d61 | |||
| 480a428e8b | |||
| 02697b2fd9 | |||
| d4faa7976e | |||
| ed77cab700 | |||
| 2c30abb5c6 | |||
| 1817ab01d6 | |||
| 31be156be3 | |||
| fc6b66f2e6 | |||
| eb7e394cf0 | |||
| 6dec9942cc | |||
| a855db9ecc | |||
| 17af1a00c0 | |||
| 50e735e1a9 | |||
| f6cf968f86 | |||
| 70a547ca94 | |||
| 89c89a5524 | |||
| f601442f0e | |||
| 2229d98ab6 | |||
| 88f45645b3 | 
							
								
								
									
										21
									
								
								.dockerignore.yaml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										21
									
								
								.dockerignore.yaml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,21 @@ | ||||
| # Ignore build artifacts | ||||
| target/ | ||||
| pkg/ | ||||
|  | ||||
| # Ignore git directory | ||||
| .git/ | ||||
|  | ||||
| .gitea/ | ||||
|  | ||||
| # Ignore environment files (configure via docker-compose instead) | ||||
| .env* | ||||
|  | ||||
| # Ignore IDE/editor specific files | ||||
| .idea/ | ||||
| .vscode/ | ||||
|  | ||||
| # Ignore OS specific files | ||||
| *.DS_Store | ||||
|  | ||||
| # Add any other files/directories you don't need in the image | ||||
| # e.g., logs/, tmp/ | ||||
							
								
								
									
										12
									
								
								.env.docker.sample
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								.env.docker.sample
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,12 @@ | ||||
| APP_ENV=development | ||||
| BACKEND_PORT=8001 | ||||
| FRONTEND_URL=http://localhost:4200 | ||||
| RUST_LOG=debug | ||||
| ALLOWED_ORIGINS=https://soaricarus.com,https://www.soaricarus.com | ||||
| SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||
| SERVICE_PASSPHRASE=iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH | ||||
| POSTGRES_AUTH_USER=icarus_op | ||||
| POSTGRES_AUTH_PASSWORD=password | ||||
| POSTGRES_AUTH_DB=icarus_auth_db | ||||
| POSTGRES_AUTH_HOST=auth_db | ||||
| DATABASE_URL=postgresql://${POSTGRES_AUTH_USER}:${POSTGRES_AUTH_PASSWORD}@${POSTGRES_AUTH_HOST}:5432/${POSTGRES_AUTH_DB} | ||||
							
								
								
									
										14
									
								
								.env.sample
									
									
									
									
									
								
							
							
						
						
									
										14
									
								
								.env.sample
									
									
									
									
									
								
							| @@ -1,2 +1,12 @@ | ||||
| DATABASE_URL=postgres://username:password@localhost/database_name | ||||
| SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||
| APP_ENV=development | ||||
| BACKEND_PORT=8001 | ||||
| FRONTEND_URL=http://localhost:4200 | ||||
| RUST_LOG=debug | ||||
| ALLOWED_ORIGINS=https://soaricarus.com,https://www.soaricarus.com | ||||
| SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||
| SERVICE_PASSPHRASE=iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH | ||||
| POSTGRES_AUTH_USER=icarus_op_test | ||||
| POSTGRES_AUTH_PASSWORD=password | ||||
| POSTGRES_AUTH_DB=icarus_auth_test_db | ||||
| POSTGRES_AUTH_HOST=localhost | ||||
| DATABASE_URL=postgresql://${POSTGRES_AUTH_USER}:${POSTGRES_AUTH_PASSWORD}@${POSTGRES_AUTH_HOST}:5432/${POSTGRES_AUTH_DB} | ||||
|   | ||||
| @@ -3,23 +3,21 @@ name: Release Tagging | ||||
| on: | ||||
|   push: | ||||
|     branches: | ||||
|       - devel | ||||
|     tags: | ||||
|       - 'v*' # Trigger on tags matching v* | ||||
|       - main | ||||
|  | ||||
| jobs: | ||||
|   release: | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - name: Checkout code | ||||
|         uses: actions/checkout@v3 | ||||
|         uses: actions/checkout@v5 | ||||
|         with: | ||||
|           fetch-depth: 0 # Important for git describe --tags | ||||
|  | ||||
|       - name: Install Rust | ||||
|         uses: actions-rs/toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.86.0 | ||||
|           toolchain: 1.90.0 | ||||
|           components: cargo | ||||
|  | ||||
|       - name: Extract Version from Cargo.toml | ||||
| @@ -29,8 +27,10 @@ jobs: | ||||
|           PROJECT_COMMIT_HASH=$(git rev-parse HEAD | cut -c 1-10) | ||||
|           BRANCH_REF="${GITHUB_REF}" | ||||
|           BRANCH_NAME=$(echo "$BRANCH_REF" | cut -d '/' -f 3) | ||||
|           PROJECT_TAG_RELEASE="v$VERSION-$BRANCH_NAME-$PROJECT_COMMIT_HASH" | ||||
|           echo "::set-output name=project_tag_release::$PROJECT_TAG_RELEASE-950" | ||||
|           PROJECT_TAG_RELEASE="v$VERSION-$BRANCH_NAME-$PROJECT_COMMIT_HASH-950" | ||||
|  | ||||
|           echo "::set-output name=project_tag_release::$PROJECT_TAG_RELEASE" | ||||
|  | ||||
|           echo "Version: $VERSION" | ||||
|           echo "Hash: $PROJECT_COMMIT_HASH" | ||||
|           echo "Branch: $BRANCH_NAME" | ||||
| @@ -51,7 +51,3 @@ jobs: | ||||
|           release_name: Release ${{ steps.version.outputs.project_tag_release }} | ||||
|           body: | | ||||
|            Release of version ${{ steps.version.outputs.project_tag_release }} | ||||
|           # draft: false | ||||
|           # prerelease: ${{ startsWith(github.ref, 'v') == false }} # prerelease if not a valid release tag | ||||
|  | ||||
|  | ||||
|   | ||||
| @@ -15,10 +15,10 @@ jobs: | ||||
|     name: Check | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.86.0 | ||||
|           toolchain: 1.90.0 | ||||
|       - run: | | ||||
|           mkdir -p ~/.ssh | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||
| @@ -36,7 +36,7 @@ jobs: | ||||
|     # --- Add database service definition --- | ||||
|     services: | ||||
|       postgres: | ||||
|         image: postgres:17.4 # Or pin to a more specific version like 14.9 | ||||
|         image: postgres:17.5 | ||||
|         env: | ||||
|           # Use secrets for DB init, with fallbacks for flexibility | ||||
|           POSTGRES_USER: ${{ secrets.DB_TEST_USER || 'testuser' }} | ||||
| @@ -50,10 +50,10 @@ jobs: | ||||
|           --health-retries 5 | ||||
|  | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.86.0 | ||||
|           toolchain: 1.90.0 | ||||
|       # --- Add this step for explicit verification --- | ||||
|       - name: Verify Docker Environment | ||||
|         run: | | ||||
| @@ -91,10 +91,10 @@ jobs: | ||||
|     name: Rustfmt | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.86.0 | ||||
|           toolchain: 1.90.0 | ||||
|       - run: rustup component add rustfmt | ||||
|       - run: | | ||||
|           mkdir -p ~/.ssh | ||||
| @@ -110,10 +110,10 @@ jobs: | ||||
|     name: Clippy | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.86.0 | ||||
|           toolchain: 1.90.0 | ||||
|       - run: rustup component add clippy | ||||
|       - run: | | ||||
|           mkdir -p ~/.ssh | ||||
| @@ -129,10 +129,10 @@ jobs: | ||||
|     name: build | ||||
|     runs-on: ubuntu-24.04 | ||||
|     steps: | ||||
|       - uses: actions/checkout@v4 | ||||
|       - uses: actions/checkout@v5 | ||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||
|         with: | ||||
|           toolchain: 1.86.0 | ||||
|           toolchain: 1.90.0 | ||||
|       - run: | | ||||
|           mkdir -p ~/.ssh | ||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||
|   | ||||
							
								
								
									
										3
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							| @@ -1,3 +1,4 @@ | ||||
| /target | ||||
| Cargo.lock | ||||
| .env | ||||
| .env.local | ||||
| .env.docker | ||||
|   | ||||
							
								
								
									
										2865
									
								
								Cargo.lock
									
									
									
										generated
									
									
									
										Normal file
									
								
							
							
						
						
									
										2865
									
								
								Cargo.lock
									
									
									
										generated
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										37
									
								
								Cargo.toml
									
									
									
									
									
								
							
							
						
						
									
										37
									
								
								Cargo.toml
									
									
									
									
									
								
							| @@ -1,27 +1,30 @@ | ||||
| [package] | ||||
| name = "icarus_auth" | ||||
| version = "0.3.0" | ||||
| version = "0.6.1" | ||||
| edition = "2024" | ||||
| rust-version = "1.86" | ||||
| rust-version = "1.90" | ||||
|  | ||||
| [dependencies] | ||||
| axum = { version = "0.8.3" } | ||||
| serde = { version = "1.0.218", features = ["derive"] } | ||||
| serde_json = { version = "1.0.139" } | ||||
| tokio = { version = "1.44.1", features = ["rt-multi-thread"] } | ||||
| tracing-subscriber = { version = "0.3.19" } | ||||
| tower = { version = "0.5.2" } | ||||
| hyper = { version = "1.6.0" } | ||||
| sqlx = { version = "0.8.3", features = ["postgres", "runtime-tokio-native-tls", "time", "uuid"] } | ||||
| dotenvy = { version = "0.15.7" } | ||||
| uuid = { version = "1.16.0", features = ["v4", "serde"] } | ||||
| axum = { version = "0.8.6" } | ||||
| serde = { version = "1.0.228", features = ["derive"] } | ||||
| serde_json = { version = "1.0.145" } | ||||
| tokio = { version = "1.47.1", features = ["rt-multi-thread"] } | ||||
| tracing-subscriber = { version = "0.3.20" } | ||||
| tower = { version = "0.5.2", features = ["full"] } | ||||
| tower-http = { version = "0.6.6", features = ["cors"] } | ||||
| hyper = { version = "1.7.0" } | ||||
| sqlx = { version = "0.8.6", features = ["postgres", "runtime-tokio-native-tls", "time", "uuid"] } | ||||
| uuid = { version = "1.18.1", features = ["v4", "serde"] } | ||||
| argon2 = { version = "0.5.3", features = ["std"] } # Use the latest 0.5.x version | ||||
| rand = { version = "0.9" } | ||||
| rand = { version = "0.9.2" } | ||||
| time = { version = "0.3.41", features = ["macros", "serde"] } | ||||
| josekit = { version = "0.10.1" } | ||||
| icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.4.1" } | ||||
| josekit = { version = "0.10.3" } | ||||
| utoipa = { version = "5.4.0", features = ["axum_extras"] } | ||||
| utoipa-swagger-ui = { version = "9.0.2", features = ["axum"] } | ||||
| icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.8.0" } | ||||
| icarus_envy = { git = "ssh://git@git.kundeng.us/phoenix/icarus_envy.git", tag = "v0.5.0" } | ||||
|  | ||||
| [dev-dependencies] | ||||
| http-body-util = { version = "0.1.3" } | ||||
| url = { version = "2.5" } | ||||
| once_cell = { version = "1.19" } # Useful for lazy initialization in tests/app setup | ||||
| url = { version = "2.5.7" } | ||||
| once_cell = { version = "1.21.3" } # Useful for lazy initialization in tests/app setup | ||||
|   | ||||
							
								
								
									
										71
									
								
								Dockerfile
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										71
									
								
								Dockerfile
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,71 @@ | ||||
| # Stage 1: Build the application | ||||
| # Use a specific Rust version for reproducibility. Choose one that matches your development environment. | ||||
| # Using slim variant for smaller base image | ||||
| FROM rust:1.90 as builder | ||||
|  | ||||
| # Set the working directory inside the container | ||||
| WORKDIR /usr/src/app | ||||
|  | ||||
| # Install build dependencies if needed (e.g., for certain crates like sqlx with native TLS) | ||||
| # RUN apt-get update && apt-get install -y pkg-config libssl-dev | ||||
|  | ||||
| # Install build dependencies if needed (e.g., git for cloning) | ||||
| RUN apt-get update && apt-get install -y --no-install-recommends \ | ||||
|     pkg-config libssl3 \ | ||||
|     ca-certificates \ | ||||
|     openssh-client git \ | ||||
|     && rm -rf /var/lib/apt/lists/* | ||||
|  | ||||
| # << --- ADD HOST KEY HERE --- >> | ||||
| # Replace 'yourgithost.com' with the actual hostname (e.g., github.com) | ||||
| RUN mkdir -p -m 0700 ~/.ssh && \ | ||||
|     ssh-keyscan git.kundeng.us >> ~/.ssh/known_hosts | ||||
|  | ||||
| # Copy Cargo manifests | ||||
| COPY Cargo.toml Cargo.lock ./ | ||||
|  | ||||
| # Build *only* dependencies to leverage Docker cache | ||||
| # This dummy build caches dependencies as a separate layer | ||||
| RUN --mount=type=ssh mkdir src && \ | ||||
|     echo "fn main() {println!(\"if you see this, the build broke\")}" > src/main.rs && \ | ||||
|     cargo build --release --quiet && \ | ||||
|     rm -rf src target/release/deps/icarus_auth* # Clean up dummy build artifacts (replace icarus_auth) | ||||
|  | ||||
| # Copy the actual source code | ||||
| COPY src ./src | ||||
| # If you have other directories like `templates` or `static`, copy them too | ||||
| COPY .env ./.env | ||||
| COPY migrations ./migrations | ||||
|  | ||||
| # << --- SSH MOUNT ADDED HERE --- >> | ||||
| # Build *only* dependencies to leverage Docker cache | ||||
| # This dummy build caches dependencies as a separate layer | ||||
| # Mount the SSH agent socket for this command | ||||
| RUN --mount=type=ssh \ | ||||
|     cargo build --release --quiet | ||||
|  | ||||
| # Stage 2: Create the final, smaller runtime image | ||||
| # Use a minimal base image like debian-slim or even distroless for security/size | ||||
| FROM ubuntu:24.04 | ||||
|  | ||||
| # Install runtime dependencies if needed (e.g., SSL certificates) | ||||
| RUN apt-get update && apt-get install -y ca-certificates libssl-dev libssl3 && rm -rf /var/lib/apt/lists/* | ||||
|  | ||||
| # Set the working directory | ||||
| WORKDIR /usr/local/bin | ||||
|  | ||||
| # Copy the compiled binary from the builder stage | ||||
| # Replace 'icarus_auth' with the actual name of your binary (usually the crate name) | ||||
| COPY --from=builder /usr/src/app/target/release/icarus_auth . | ||||
|  | ||||
| # Copy other necessary files like .env (if used for runtime config) or static assets | ||||
| # It's generally better to configure via environment variables in Docker though | ||||
| COPY --from=builder /usr/src/app/.env . | ||||
| COPY --from=builder /usr/src/app/migrations ./migrations | ||||
|  | ||||
| # Expose the port your Axum app listens on (e.g., 3000 or 8000) | ||||
| EXPOSE 3000 | ||||
|  | ||||
| # Set the command to run your application | ||||
| # Ensure this matches the binary name copied above | ||||
| CMD ["./icarus_auth"] | ||||
							
								
								
									
										32
									
								
								README.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										32
									
								
								README.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,32 @@ | ||||
| A auth web API services for the Icarus project. | ||||
|  | ||||
|  | ||||
| # Getting Started | ||||
| The easiest way to get started is through docker. This assumes that docker is already installed | ||||
| on your system. Copy the `.env.docker.sample` as `.env`. Most of the data in the env file doesn't  | ||||
| need to be modified. The `SECRET_KEY` variable should be changed since it will be used for token | ||||
| generation. The `SECRET_PASSPHASE` should also be changed when in production mode, but make sure | ||||
| the respective `passphrase` database table record exists. | ||||
|  | ||||
| Build image | ||||
| ``` | ||||
| docker compose build | ||||
| ``` | ||||
|  | ||||
| Start images | ||||
| ``` | ||||
| docker compose up -d --force-recreate | ||||
| ``` | ||||
|  | ||||
| Bring it down | ||||
| ``` | ||||
| docker compose down -v | ||||
| ``` | ||||
|  | ||||
| Pruning | ||||
| ``` | ||||
| docker system prune -a | ||||
| ``` | ||||
|  | ||||
| To view the OpenAPI spec, run the project and access `/swagger-ui`. If running through docker, | ||||
| the url would be something like `http://localhost:8000/swagger-ui`. | ||||
							
								
								
									
										45
									
								
								docker-compose.yaml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										45
									
								
								docker-compose.yaml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,45 @@ | ||||
| version: '3.8' # Use a recent version | ||||
|  | ||||
| services: | ||||
|   # Your Rust Application Service | ||||
|   auth_api: | ||||
|     build: # Tells docker-compose to build the Dockerfile in the current directory | ||||
|       context: . | ||||
|       ssh: ["default"]  # Uses host's SSH agent | ||||
|     container_name: icarus_auth # Optional: Give the container a specific name | ||||
|     ports: | ||||
|       # Map host port 8000 to container port 3000 (adjust as needed) | ||||
|       - "8001:8001" | ||||
|     env_file: | ||||
|       - .env | ||||
|     depends_on: | ||||
|       auth_db: | ||||
|         condition: service_healthy # Wait for the DB to be healthy before starting the app | ||||
|     restart: unless-stopped # Optional: Restart policy | ||||
|  | ||||
|   # PostgreSQL Database Service | ||||
|   auth_db: | ||||
|     image: postgres:17.5-alpine # Use an official Postgres image (Alpine variant is smaller) | ||||
|     container_name: icarus_auth_db # Optional: Give the container a specific name | ||||
|     environment: | ||||
|       # These MUST match the user, password, and database name in the DATABASE_URL above | ||||
|       POSTGRES_USER: ${POSTGRES_AUTH_USER:-icarus_op} | ||||
|       POSTGRES_PASSWORD: ${POSTGRES_AUTH_PASSWORD:-password} | ||||
|       POSTGRES_DB: ${POSTGRES_AUTH_DB:-icarus_auth_db} | ||||
|     volumes: | ||||
|       # Persist database data using a named volume | ||||
|       - postgres_data:/var/lib/postgresql/data | ||||
|     ports: [] | ||||
|     healthcheck: | ||||
|         # Checks if Postgres is ready to accept connections | ||||
|         test: ["CMD-SHELL", "pg_isready -U $$POSTGRES_USER -d $$POSTGRES_DB"] | ||||
|         interval: 10s | ||||
|         timeout: 5s | ||||
|         retries: 5 | ||||
|         start_period: 10s | ||||
|     restart: always # Optional: Restart policy | ||||
|  | ||||
| # Define the named volume for data persistence | ||||
| volumes: | ||||
|   postgres_data: | ||||
|     driver: local # Use the default local driver | ||||
| @@ -20,3 +20,9 @@ CREATE TABLE IF NOT EXISTS "salt" ( | ||||
|     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||
|     salt TEXT NOT NULL | ||||
| ); | ||||
|  | ||||
| CREATE TABLE IF NOT EXISTS "passphrase" ( | ||||
|     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||
|     passphrase TEXT NOT NULL, | ||||
|     date_created TIMESTAMPTZ NOT NULL DEFAULT NOW() | ||||
| ); | ||||
|   | ||||
							
								
								
									
										2
									
								
								migrations/20250802185652_passphrase_data.sql
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										2
									
								
								migrations/20250802185652_passphrase_data.sql
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,2 @@ | ||||
| -- Add migration script here | ||||
| INSERT INTO "passphrase" (id, passphrase) VALUES('22f9c775-cce9-457a-a147-9dafbb801f61', 'iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH'); | ||||
| @@ -1,3 +1,5 @@ | ||||
| TODO: At some point, move this somewhere that is appropriate | ||||
|  | ||||
| # Make sure role has CREATEDB | ||||
| ALTER ROLE username_that_needs_permission CREATEDB; | ||||
|  | ||||
|   | ||||
| @@ -1,30 +1,54 @@ | ||||
| use axum::{Extension, Json, http::StatusCode}; | ||||
| pub mod response { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
| use serde::{Deserialize, Serialize}; | ||||
|  | ||||
| #[derive(Deserialize, Serialize)] | ||||
| pub struct TestResult { | ||||
|     message: String, | ||||
| } | ||||
|  | ||||
| // basic handler that responds with a static string | ||||
| pub async fn root() -> &'static str { | ||||
|     "Hello, World!" | ||||
| } | ||||
|  | ||||
| pub async fn db_ping(Extension(pool): Extension<sqlx::PgPool>) -> (StatusCode, Json<TestResult>) { | ||||
|     match sqlx::query("SELECT 1").execute(&pool).await { | ||||
|         Ok(_) => { | ||||
|             let tr = TestResult { | ||||
|                 message: String::from("This works"), | ||||
|             }; | ||||
|             (StatusCode::OK, Json(tr)) | ||||
|         } | ||||
|         Err(e) => ( | ||||
|             StatusCode::BAD_REQUEST, | ||||
|             Json(TestResult { | ||||
|                 message: e.to_string(), | ||||
|             }), | ||||
|         ), | ||||
|     #[derive(Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct TestResult { | ||||
|         pub message: String, | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub mod endpoint { | ||||
|     use super::*; | ||||
|     use axum::{Extension, Json, http::StatusCode}; | ||||
|  | ||||
|     /// Endpoint to hit the root | ||||
|     /// basic handler that responds with a static string | ||||
|     #[utoipa::path( | ||||
|         get, | ||||
|         path = super::super::endpoints::ROOT, | ||||
|         responses( | ||||
|             (status = 200, description = "Test", body = &str), | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn root() -> &'static str { | ||||
|         "Hello, World!" | ||||
|     } | ||||
|  | ||||
|     /// Endpoint to do a database ping | ||||
|     #[utoipa::path( | ||||
|         get, | ||||
|         path = super::super::endpoints::DBTEST, | ||||
|         responses( | ||||
|             (status = 200, description = "Successful ping of the db", body = super::response::TestResult), | ||||
|             (status = 400, description = "Failure in pinging the db", body = super::response::TestResult) | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn db_ping( | ||||
|         Extension(pool): Extension<sqlx::PgPool>, | ||||
|     ) -> (StatusCode, Json<response::TestResult>) { | ||||
|         match sqlx::query("SELECT 1").execute(&pool).await { | ||||
|             Ok(_) => { | ||||
|                 let tr = response::TestResult { | ||||
|                     message: String::from("This works"), | ||||
|                 }; | ||||
|                 (StatusCode::OK, Json(tr)) | ||||
|             } | ||||
|             Err(e) => ( | ||||
|                 StatusCode::BAD_REQUEST, | ||||
|                 Json(response::TestResult { | ||||
|                     message: e.to_string(), | ||||
|                 }), | ||||
|             ), | ||||
|         } | ||||
|     } | ||||
| } | ||||
|   | ||||
| @@ -1,23 +1,54 @@ | ||||
| pub mod request { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Default, Deserialize, Serialize)] | ||||
|     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct Request { | ||||
|         pub username: String, | ||||
|         pub password: String, | ||||
|     } | ||||
|  | ||||
|     pub mod service_login { | ||||
|         #[derive(Debug, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||
|         pub struct Request { | ||||
|             pub passphrase: String, | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub mod refresh_token { | ||||
|         #[derive(Debug, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||
|         pub struct Request { | ||||
|             pub access_token: String, | ||||
|         } | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub mod response { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Default, Deserialize, Serialize)] | ||||
|     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct Response { | ||||
|         pub message: String, | ||||
|         pub data: Vec<icarus_models::login_result::LoginResult>, | ||||
|     } | ||||
|  | ||||
|     pub mod service_login { | ||||
|         #[derive(Debug, Default, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||
|         pub struct Response { | ||||
|             pub message: String, | ||||
|             pub data: Vec<icarus_models::login_result::LoginResult>, | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub mod refresh_token { | ||||
|         #[derive(Debug, Default, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||
|         pub struct Response { | ||||
|             pub message: String, | ||||
|             pub data: Vec<icarus_models::login_result::LoginResult>, | ||||
|         } | ||||
|     } | ||||
| } | ||||
|  | ||||
| /// Module for login endpoints | ||||
| pub mod endpoint { | ||||
|     use axum::{Json, http::StatusCode}; | ||||
|  | ||||
| @@ -28,6 +59,10 @@ pub mod endpoint { | ||||
|     use super::request; | ||||
|     use super::response; | ||||
|  | ||||
|     // TODO: At some point, get the username from the DB | ||||
|     // Name of service username when returning a login result | ||||
|     pub const SERVICE_USERNAME: &str = "service"; | ||||
|  | ||||
|     async fn not_found(message: &str) -> (StatusCode, Json<response::Response>) { | ||||
|         ( | ||||
|             StatusCode::NOT_FOUND, | ||||
| @@ -38,6 +73,20 @@ pub mod endpoint { | ||||
|         ) | ||||
|     } | ||||
|  | ||||
|     /// Endpoint to login | ||||
|     #[utoipa::path( | ||||
|         post, | ||||
|         path = super::super::endpoints::LOGIN, | ||||
|         request_body( | ||||
|             content = request::Request, | ||||
|             description = "Data required to login", | ||||
|             content_type = "application/json" | ||||
|         ), | ||||
|         responses( | ||||
|             (status = 200, description = "Successfully logged in", body = response::Response), | ||||
|             (status = 404, description = "Could not login with credentials", body = response::Response) | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn login( | ||||
|         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||
|         Json(payload): Json<request::Request>, | ||||
| @@ -45,45 +94,34 @@ pub mod endpoint { | ||||
|         // Check if user exists | ||||
|         match repo::user::get(&pool, &payload.username).await { | ||||
|             Ok(user) => { | ||||
|                 let salt = repo::salt::get(&pool, &user.salt_id).await.unwrap(); | ||||
|                 let salt_str = hashing::get_salt(&salt.salt).unwrap(); | ||||
|                 let unhashed_password = payload.password; | ||||
|                 if hashing::verify_password(&payload.password, user.password.clone()).unwrap() { | ||||
|                     // Create token | ||||
|                     let key = icarus_envy::environment::get_secret_key().await.value; | ||||
|                     let (token_literal, duration) = | ||||
|                         token_stuff::create_token(&key, &user.id).unwrap(); | ||||
|  | ||||
|                 // Check if password is correct | ||||
|                 match hashing::hash_password(&unhashed_password, &salt_str) { | ||||
|                     Ok(hash_password) => { | ||||
|                         if hashing::verify_password(&unhashed_password, hash_password.clone()) | ||||
|                             .unwrap() | ||||
|                         { | ||||
|                             // Create token | ||||
|                             let key = token_stuff::get_key().unwrap(); | ||||
|                             let (token_literal, duration) = | ||||
|                                 token_stuff::create_token(&key).unwrap(); | ||||
|                     if token_stuff::verify_token(&key, &token_literal) { | ||||
|                         let current_time = time::OffsetDateTime::now_utc(); | ||||
|                         let _ = repo::user::update_last_login(&pool, &user, ¤t_time).await; | ||||
|  | ||||
|                             if token_stuff::verify_token(&key, &token_literal) { | ||||
|                                 ( | ||||
|                                     StatusCode::OK, | ||||
|                                     Json(response::Response { | ||||
|                                         message: String::from("Successful"), | ||||
|                                         data: vec![icarus_models::login_result::LoginResult { | ||||
|                                             id: user.id, | ||||
|                                             username: user.username, | ||||
|                                             token: token_literal, | ||||
|                                             token_type: String::from(token_stuff::TOKENTYPE), | ||||
|                                             expiration: duration, | ||||
|                                         }], | ||||
|                                     }), | ||||
|                                 ) | ||||
|                             } else { | ||||
|                                 return not_found("Could not verify password").await; | ||||
|                             } | ||||
|                         } else { | ||||
|                             return not_found("Error Hashing").await; | ||||
|                         } | ||||
|                     } | ||||
|                     Err(err) => { | ||||
|                         return not_found(&err.to_string()).await; | ||||
|                         ( | ||||
|                             StatusCode::OK, | ||||
|                             Json(response::Response { | ||||
|                                 message: String::from("Successful"), | ||||
|                                 data: vec![icarus_models::login_result::LoginResult { | ||||
|                                     id: user.id, | ||||
|                                     username: user.username.clone(), | ||||
|                                     token: token_literal, | ||||
|                                     token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||
|                                     expiration: duration, | ||||
|                                 }], | ||||
|                             }), | ||||
|                         ) | ||||
|                     } else { | ||||
|                         return not_found("Could not verify password").await; | ||||
|                     } | ||||
|                 } else { | ||||
|                     return not_found("Error Hashing").await; | ||||
|                 } | ||||
|             } | ||||
|             Err(err) => { | ||||
| @@ -91,4 +129,140 @@ pub mod endpoint { | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     /// Endpoint to login as a service user | ||||
|     #[utoipa::path( | ||||
|         post, | ||||
|         path = super::super::endpoints::SERVICE_LOGIN, | ||||
|         request_body( | ||||
|             content = request::service_login::Request, | ||||
|             description = "Data required to login as a service user", | ||||
|             content_type = "application/json" | ||||
|         ), | ||||
|         responses( | ||||
|             (status = 200, description = "Login successful", body = response::Response), | ||||
|             (status = 400, description = "Error logging in with credentials", body = response::Response) | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn service_login( | ||||
|         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||
|         axum::Json(payload): axum::Json<request::service_login::Request>, | ||||
|     ) -> ( | ||||
|         axum::http::StatusCode, | ||||
|         axum::Json<response::service_login::Response>, | ||||
|     ) { | ||||
|         let mut response = response::service_login::Response::default(); | ||||
|  | ||||
|         match repo::service::valid_passphrase(&pool, &payload.passphrase).await { | ||||
|             Ok((id, _passphrase, _date_created)) => { | ||||
|                 let key = icarus_envy::environment::get_secret_key().await.value; | ||||
|                 let (token_literal, duration) = | ||||
|                     token_stuff::create_service_token(&key, &id).unwrap(); | ||||
|  | ||||
|                 if token_stuff::verify_token(&key, &token_literal) { | ||||
|                     let login_result = icarus_models::login_result::LoginResult { | ||||
|                         id, | ||||
|                         username: String::from(SERVICE_USERNAME), | ||||
|                         token: token_literal, | ||||
|                         token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||
|                         expiration: duration, | ||||
|                     }; | ||||
|  | ||||
|                     response.data.push(login_result); | ||||
|                     response.message = String::from("Successful"); | ||||
|  | ||||
|                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||
|                 } else { | ||||
|                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||
|                 } | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 response.message = err.to_string(); | ||||
|                 (axum::http::StatusCode::BAD_REQUEST, axum::Json(response)) | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     /// Endpoint to retrieve a refresh token | ||||
|     #[utoipa::path( | ||||
|         post, | ||||
|         path = super::super::endpoints::REFRESH_TOKEN, | ||||
|         request_body( | ||||
|             content = request::refresh_token::Request, | ||||
|             description = "Data required to retrieve a refresh token", | ||||
|             content_type = "application/json" | ||||
|         ), | ||||
|         responses( | ||||
|             (status = 200, description = "Refresh token generated", body = response::Response), | ||||
|             (status = 400, description = "Error verifying token", body = response::Response), | ||||
|             (status = 404, description = "Could not validate token", body = response::Response), | ||||
|             (status = 500, description = "Error extracting token", body = response::Response) | ||||
|         ) | ||||
|     )] | ||||
|     pub async fn refresh_token( | ||||
|         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||
|         axum::Json(payload): axum::Json<request::refresh_token::Request>, | ||||
|     ) -> ( | ||||
|         axum::http::StatusCode, | ||||
|         axum::Json<response::refresh_token::Response>, | ||||
|     ) { | ||||
|         let mut response = response::refresh_token::Response::default(); | ||||
|         let key = icarus_envy::environment::get_secret_key().await.value; | ||||
|  | ||||
|         if token_stuff::verify_token(&key, &payload.access_token) { | ||||
|             let token_type = token_stuff::get_token_type(&key, &payload.access_token).unwrap(); | ||||
|  | ||||
|             if token_stuff::is_token_type_valid(&token_type) { | ||||
|                 // Get passphrase record with id | ||||
|                 match token_stuff::extract_id_from_token(&key, &payload.access_token) { | ||||
|                     Ok(id) => match repo::service::get_passphrase(&pool, &id).await { | ||||
|                         Ok((returned_id, _, _)) => { | ||||
|                             match token_stuff::create_service_refresh_token(&key, &returned_id) { | ||||
|                                 Ok((access_token, exp_dur)) => { | ||||
|                                     let login_result = icarus_models::login_result::LoginResult { | ||||
|                                         id: returned_id, | ||||
|                                         token: access_token, | ||||
|                                         expiration: exp_dur, | ||||
|                                         token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||
|                                         username: String::from(SERVICE_USERNAME), | ||||
|                                     }; | ||||
|                                     response.message = String::from("Successful"); | ||||
|                                     response.data.push(login_result); | ||||
|  | ||||
|                                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||
|                                 } | ||||
|                                 Err(err) => { | ||||
|                                     response.message = err.to_string(); | ||||
|                                     ( | ||||
|                                         axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||
|                                         axum::Json(response), | ||||
|                                     ) | ||||
|                                 } | ||||
|                             } | ||||
|                         } | ||||
|                         Err(err) => { | ||||
|                             response.message = err.to_string(); | ||||
|                             ( | ||||
|                                 axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||
|                                 axum::Json(response), | ||||
|                             ) | ||||
|                         } | ||||
|                     }, | ||||
|                     Err(err) => { | ||||
|                         response.message = err.to_string(); | ||||
|                         ( | ||||
|                             axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||
|                             axum::Json(response), | ||||
|                         ) | ||||
|                     } | ||||
|                 } | ||||
|             } else { | ||||
|                 response.message = String::from("Invalid token type"); | ||||
|                 (axum::http::StatusCode::NOT_FOUND, axum::Json(response)) | ||||
|             } | ||||
|         } else { | ||||
|             response.message = String::from("Could not verify token"); | ||||
|             (axum::http::StatusCode::BAD_REQUEST, axum::Json(response)) | ||||
|         } | ||||
|     } | ||||
| } | ||||
|   | ||||
| @@ -7,4 +7,6 @@ pub mod endpoints { | ||||
|     pub const REGISTER: &str = "/api/v2/register"; | ||||
|     pub const DBTEST: &str = "/api/v2/test/db"; | ||||
|     pub const LOGIN: &str = "/api/v2/login"; | ||||
|     pub const SERVICE_LOGIN: &str = "/api/v2/service/login"; | ||||
|     pub const REFRESH_TOKEN: &str = "/api/v2/token/refresh"; | ||||
| } | ||||
|   | ||||
| @@ -6,7 +6,7 @@ use crate::repo; | ||||
| pub mod request { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Default, Deserialize, Serialize)] | ||||
|     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct Request { | ||||
|         #[serde(skip_serializing_if = "String::is_empty")] | ||||
|         pub username: String, | ||||
| @@ -26,13 +26,28 @@ pub mod request { | ||||
| pub mod response { | ||||
|     use serde::{Deserialize, Serialize}; | ||||
|  | ||||
|     #[derive(Deserialize, Serialize)] | ||||
|     #[derive(Deserialize, Serialize, utoipa::ToSchema)] | ||||
|     pub struct Response { | ||||
|         pub message: String, | ||||
|         pub data: Vec<icarus_models::user::User>, | ||||
|     } | ||||
| } | ||||
|  | ||||
| /// Endpoint to register a user | ||||
| #[utoipa::path( | ||||
|     post, | ||||
|     path = super::endpoints::REGISTER, | ||||
|     request_body( | ||||
|         content = request::Request, | ||||
|         description = "Data required to register", | ||||
|         content_type = "application/json" | ||||
|     ), | ||||
|     responses( | ||||
|         (status = 201, description = "User created", body = response::Response), | ||||
|         (status = 404, description = "User already exists", body = response::Response), | ||||
|         (status = 400, description = "Issue creating user", body = response::Response) | ||||
|     ) | ||||
| )] | ||||
| pub async fn register_user( | ||||
|     axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||
|     Json(payload): Json<request::Request>, | ||||
|   | ||||
| @@ -6,5 +6,5 @@ fn get_address() -> String { | ||||
| } | ||||
|  | ||||
| fn get_port() -> String { | ||||
|     String::from("3000") | ||||
|     String::from("8001") | ||||
| } | ||||
|   | ||||
| @@ -11,8 +11,7 @@ use argon2::{ | ||||
| pub fn generate_salt() -> Result<SaltString, argon2::Error> { | ||||
|     // Generate a random salt | ||||
|     // SaltString::generate uses OsRng internally for cryptographic security | ||||
|     let salt = SaltString::generate(&mut OsRng); | ||||
|     Ok(salt) | ||||
|     Ok(SaltString::generate(&mut OsRng)) | ||||
| } | ||||
|  | ||||
| pub fn get_salt(s: &str) -> Result<SaltString, argon2::password_hash::Error> { | ||||
| @@ -32,9 +31,7 @@ pub fn hash_password( | ||||
|     // Hash the password with the salt | ||||
|     // The output is a PasswordHash string format that includes algorithm, version, | ||||
|     // parameters, salt, and the hash itself. | ||||
|     let password_hash = argon2.hash_password(password_bytes, salt)?.to_string(); | ||||
|  | ||||
|     Ok(password_hash) | ||||
|     Ok(argon2.hash_password(password_bytes, salt)?.to_string()) | ||||
| } | ||||
|  | ||||
| pub fn verify_password( | ||||
| @@ -48,11 +45,9 @@ pub fn verify_password( | ||||
|     let parsed_hash = argon2::PasswordHash::new(stored_hash.as_str())?; | ||||
|  | ||||
|     // Create an Argon2 instance (it will use the parameters from the parsed hash) | ||||
|     let argon2 = Argon2::default(); | ||||
|  | ||||
|     // Verify the password against the parsed hash | ||||
|     // This automatically uses the correct salt and parameters embedded in `parsed_hash` | ||||
|     match argon2.verify_password(password_bytes, &parsed_hash) { | ||||
|     match Argon2::default().verify_password(password_bytes, &parsed_hash) { | ||||
|         Ok(()) => Ok(true),                                       // Passwords match | ||||
|         Err(argon2::password_hash::Error::Password) => Ok(false), // Passwords don't match | ||||
|         Err(e) => Err(e), // Some other error occurred (e.g., invalid hash format) | ||||
| @@ -66,8 +61,7 @@ mod tests { | ||||
|     #[test] | ||||
|     fn test_hash_password() { | ||||
|         let some_password = String::from("somethingrandom"); | ||||
|         let salt = generate_salt().unwrap(); | ||||
|         match hash_password(&some_password, &salt) { | ||||
|         match hash_password(&some_password, &generate_salt().unwrap()) { | ||||
|             Ok(p) => match verify_password(&some_password, p.clone()) { | ||||
|                 Ok(res) => { | ||||
|                     assert_eq!(res, true); | ||||
| @@ -81,4 +75,27 @@ mod tests { | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     #[test] | ||||
|     fn test_wrong_password() { | ||||
|         let some_password = String::from("somethingrandom"); | ||||
|         match hash_password(&some_password, &generate_salt().unwrap()) { | ||||
|             Ok(p) => { | ||||
|                 match verify_password(&some_password, p.clone()) { | ||||
|                     Ok(res) => { | ||||
|                         assert_eq!(res, true, "Passwords are not verified"); | ||||
|                     } | ||||
|                     Err(err) => { | ||||
|                         assert!(false, "Error: {:?}", err.to_string()); | ||||
|                     } | ||||
|                 } | ||||
|                 let wrong_password = String::from("Differentanotherlevel"); | ||||
|                 let result = verify_password(&wrong_password, p.clone()).unwrap(); | ||||
|                 assert_eq!(false, result, "Passwords should not match"); | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {:?}", err.to_string()); | ||||
|             } | ||||
|         } | ||||
|     } | ||||
| } | ||||
|   | ||||
							
								
								
									
										23
									
								
								src/lib.rs
									
									
									
									
									
								
							
							
						
						
									
										23
									
								
								src/lib.rs
									
									
									
									
									
								
							| @@ -1,17 +1,10 @@ | ||||
| // TODO: Get rid of this file and place the code in more appropriate places | ||||
| pub mod callers; | ||||
| pub mod config; | ||||
| pub mod hashing; | ||||
| pub mod repo; | ||||
| pub mod token_stuff; | ||||
|  | ||||
| pub mod keys { | ||||
|     pub const DBURL: &str = "DATABASE_URL"; | ||||
|  | ||||
|     pub mod error { | ||||
|         pub const ERROR: &str = "DATABASE_URL must be set in .env"; | ||||
|     } | ||||
| } | ||||
|  | ||||
| mod connection_settings { | ||||
|     pub const MAXCONN: u32 = 5; | ||||
| } | ||||
| @@ -19,13 +12,12 @@ mod connection_settings { | ||||
| pub mod db { | ||||
|  | ||||
|     use sqlx::postgres::PgPoolOptions; | ||||
|     use std::env; | ||||
|  | ||||
|     use crate::{connection_settings, keys}; | ||||
|     use crate::connection_settings; | ||||
|  | ||||
|     pub async fn create_pool() -> Result<sqlx::PgPool, sqlx::Error> { | ||||
|         let database_url = get_db_url().await; | ||||
|         println!("Database url: {:?}", database_url); | ||||
|         let database_url = icarus_envy::environment::get_db_url().await.value; | ||||
|         println!("Database url: {database_url}"); | ||||
|  | ||||
|         PgPoolOptions::new() | ||||
|             .max_connections(connection_settings::MAXCONN) | ||||
| @@ -33,13 +25,6 @@ pub mod db { | ||||
|             .await | ||||
|     } | ||||
|  | ||||
|     async fn get_db_url() -> String { | ||||
|         #[cfg(debug_assertions)] // Example: Only load .env in debug builds | ||||
|         dotenvy::dotenv().ok(); | ||||
|  | ||||
|         env::var(keys::DBURL).expect(keys::error::ERROR) | ||||
|     } | ||||
|  | ||||
|     pub async fn migrations(pool: &sqlx::PgPool) { | ||||
|         // Run migrations using the sqlx::migrate! macro | ||||
|         // Assumes your migrations are in a ./migrations folder relative to Cargo.toml | ||||
|   | ||||
							
								
								
									
										310
									
								
								src/main.rs
									
									
									
									
									
								
							
							
						
						
									
										310
									
								
								src/main.rs
									
									
									
									
									
								
							| @@ -8,7 +8,7 @@ async fn main() { | ||||
|  | ||||
|     let app = init::app().await; | ||||
|  | ||||
|     // run our app with hyper, listening globally on port 3000 | ||||
|     // run our app with hyper, listening globally on port 8001 | ||||
|     let url = config::get_full(); | ||||
|     let listener = tokio::net::TcpListener::bind(url).await.unwrap(); | ||||
|     axum::serve(listener, app).await.unwrap(); | ||||
| @@ -19,14 +19,91 @@ mod init { | ||||
|         Router, | ||||
|         routing::{get, post}, | ||||
|     }; | ||||
|     use utoipa::OpenApi; | ||||
|  | ||||
|     use crate::callers; | ||||
|     use callers::common as common_callers; | ||||
|     use callers::login as login_caller; | ||||
|     use callers::register as register_caller; | ||||
|     use login_caller::endpoint as login_endpoints; | ||||
|     use login_caller::response as login_responses; | ||||
|     use register_caller::response as register_responses; | ||||
|  | ||||
|     #[derive(utoipa::OpenApi)] | ||||
|     #[openapi( | ||||
|         paths( | ||||
|             common_callers::endpoint::db_ping, common_callers::endpoint::root, | ||||
|             register_caller::register_user, | ||||
|             login_endpoints::login, login_endpoints::service_login, login_endpoints::refresh_token | ||||
|             ), | ||||
|         components(schemas(common_callers::response::TestResult, | ||||
|                 register_responses::Response, | ||||
|             login_responses::Response, login_responses::service_login::Response, login_responses::refresh_token::Response)), | ||||
|         tags( | ||||
|             (name = "Icarus Auth API", description = "Auth API for Icarus API") | ||||
|             ) | ||||
|     )] | ||||
|     struct ApiDoc; | ||||
|  | ||||
|     mod cors { | ||||
|         pub async fn configure_cors() -> tower_http::cors::CorsLayer { | ||||
|             // Start building the CORS layer with common settings | ||||
|             let cors = tower_http::cors::CorsLayer::new() | ||||
|                 .allow_methods([ | ||||
|                     axum::http::Method::GET, | ||||
|                     axum::http::Method::POST, | ||||
|                     axum::http::Method::PUT, | ||||
|                     axum::http::Method::DELETE, | ||||
|                 ]) // Specify allowed methods:cite[2] | ||||
|                 .allow_headers([ | ||||
|                     axum::http::header::CONTENT_TYPE, | ||||
|                     axum::http::header::AUTHORIZATION, | ||||
|                 ]) // Specify allowed headers:cite[2] | ||||
|                 .allow_credentials(true) // If you need to send cookies or authentication headers:cite[2] | ||||
|                 .max_age(std::time::Duration::from_secs(3600)); // Cache the preflight response for 1 hour:cite[2] | ||||
|  | ||||
|             // Dynamically set the allowed origin based on the environment | ||||
|             match std::env::var(icarus_envy::keys::APP_ENV).as_deref() { | ||||
|                 Ok("production") => { | ||||
|                     let allowed_origins_env = icarus_envy::environment::get_allowed_origins().await; | ||||
|                     match icarus_envy::utility::delimitize(&allowed_origins_env) { | ||||
|                         Ok(alwd) => { | ||||
|                             let allowed_origins: Vec<axum::http::HeaderValue> = alwd | ||||
|                                 .into_iter() | ||||
|                                 .map(|s| s.parse::<axum::http::HeaderValue>().unwrap()) | ||||
|                                 .collect(); | ||||
|                             cors.allow_origin(allowed_origins) | ||||
|                         } | ||||
|                         Err(err) => { | ||||
|                             eprintln!( | ||||
|                                 "Could not parse out allowed origins from env: Error: {err:?}" | ||||
|                             ); | ||||
|                             std::process::exit(-1); | ||||
|                         } | ||||
|                     } | ||||
|                 } | ||||
|                 _ => { | ||||
|                     // Development (default): Allow localhost origins | ||||
|                     cors.allow_origin(vec![ | ||||
|                         "http://localhost:4200".parse().unwrap(), | ||||
|                         "http://127.0.0.1:4200".parse().unwrap(), | ||||
|                     ]) | ||||
|                 } | ||||
|             } | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn routes() -> Router { | ||||
|         // build our application with a route | ||||
|         Router::new() | ||||
|             .route(callers::endpoints::DBTEST, get(callers::common::db_ping)) | ||||
|             .route(callers::endpoints::ROOT, get(callers::common::root)) | ||||
|             .route( | ||||
|                 callers::endpoints::DBTEST, | ||||
|                 get(callers::common::endpoint::db_ping), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::ROOT, | ||||
|                 get(callers::common::endpoint::root), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::REGISTER, | ||||
|                 post(callers::register::register_user), | ||||
| @@ -35,6 +112,15 @@ mod init { | ||||
|                 callers::endpoints::LOGIN, | ||||
|                 post(callers::login::endpoint::login), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::SERVICE_LOGIN, | ||||
|                 post(callers::login::endpoint::service_login), | ||||
|             ) | ||||
|             .route( | ||||
|                 callers::endpoints::REFRESH_TOKEN, | ||||
|                 post(callers::login::endpoint::refresh_token), | ||||
|             ) | ||||
|             .layer(cors::configure_cors().await) | ||||
|     } | ||||
|  | ||||
|     pub async fn app() -> Router { | ||||
| @@ -44,7 +130,13 @@ mod init { | ||||
|  | ||||
|         icarus_auth::db::migrations(&pool).await; | ||||
|  | ||||
|         routes().await.layer(axum::Extension(pool)) | ||||
|         routes() | ||||
|             .await | ||||
|             .merge( | ||||
|                 utoipa_swagger_ui::SwaggerUi::new("/swagger-ui") | ||||
|                     .url("/api-docs/openapi.json", ApiDoc::openapi()), | ||||
|             ) | ||||
|             .layer(axum::Extension(pool)) | ||||
|     } | ||||
| } | ||||
|  | ||||
| @@ -63,24 +155,23 @@ mod tests { | ||||
|     mod db_mgr { | ||||
|         use std::str::FromStr; | ||||
|  | ||||
|         use icarus_auth::keys; | ||||
|  | ||||
|         pub const LIMIT: usize = 6; | ||||
|  | ||||
|         pub async fn get_pool() -> Result<sqlx::PgPool, sqlx::Error> { | ||||
|             let tm_db_url = std::env::var(keys::DBURL).expect("DATABASE_URL must be present"); | ||||
|             let tm_db_url = icarus_envy::environment::get_db_url().await.value; | ||||
|             let tm_options = sqlx::postgres::PgConnectOptions::from_str(&tm_db_url).unwrap(); | ||||
|             sqlx::PgPool::connect_with(tm_options).await | ||||
|         } | ||||
|  | ||||
|         pub async fn generate_db_name() -> String { | ||||
|             let db_name = | ||||
|                 get_database_name().unwrap() + &"_" + &uuid::Uuid::new_v4().to_string()[..LIMIT]; | ||||
|             let db_name = get_database_name().await.unwrap() | ||||
|                 + &"_" | ||||
|                 + &uuid::Uuid::new_v4().to_string()[..LIMIT]; | ||||
|             db_name | ||||
|         } | ||||
|  | ||||
|         pub async fn connect_to_db(db_name: &str) -> Result<sqlx::PgPool, sqlx::Error> { | ||||
|             let db_url = std::env::var(keys::DBURL).expect("DATABASE_URL must be set for tests"); | ||||
|             let db_url = icarus_envy::environment::get_db_url().await.value; | ||||
|             let options = sqlx::postgres::PgConnectOptions::from_str(&db_url)?.database(db_name); | ||||
|             sqlx::PgPool::connect_with(options).await | ||||
|         } | ||||
| @@ -106,29 +197,21 @@ mod tests { | ||||
|             Ok(()) | ||||
|         } | ||||
|  | ||||
|         pub fn get_database_name() -> Result<String, Box<dyn std::error::Error>> { | ||||
|             dotenvy::dotenv().ok(); // Load .env file if it exists | ||||
|         pub async fn get_database_name() -> Result<String, Box<dyn std::error::Error>> { | ||||
|             let database_url = icarus_envy::environment::get_db_url().await.value; | ||||
|  | ||||
|             match std::env::var(keys::DBURL) { | ||||
|                 Ok(database_url) => { | ||||
|                     let parsed_url = url::Url::parse(&database_url)?; | ||||
|                     if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" { | ||||
|                         match parsed_url | ||||
|                             .path_segments() | ||||
|                             .and_then(|segments| segments.last().map(|s| s.to_string())) | ||||
|                         { | ||||
|                             Some(sss) => Ok(sss), | ||||
|                             None => Err("Error parsing".into()), | ||||
|                         } | ||||
|                     } else { | ||||
|                         // Handle other database types if needed | ||||
|                         Err("Error parsing".into()) | ||||
|                     } | ||||
|                 } | ||||
|                 Err(_) => { | ||||
|                     // DATABASE_URL environment variable not found | ||||
|                     Err("Error parsing".into()) | ||||
|             let parsed_url = url::Url::parse(&database_url)?; | ||||
|             if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" { | ||||
|                 match parsed_url | ||||
|                     .path_segments() | ||||
|                     .and_then(|segments| segments.last().map(|s| s.to_string())) | ||||
|                 { | ||||
|                     Some(sss) => Ok(sss), | ||||
|                     None => Err("Error parsing".into()), | ||||
|                 } | ||||
|             } else { | ||||
|                 // Handle other database types if needed | ||||
|                 Err("Error parsing".into()) | ||||
|             } | ||||
|         } | ||||
|     } | ||||
| @@ -157,6 +240,25 @@ mod tests { | ||||
|         }) | ||||
|     } | ||||
|  | ||||
|     pub mod requests { | ||||
|         use tower::ServiceExt; // for `call`, `oneshot`, and `ready` | ||||
|  | ||||
|         pub async fn register( | ||||
|             app: &axum::Router, | ||||
|             usr: &icarus_auth::callers::register::request::Request, | ||||
|         ) -> Result<axum::response::Response, std::convert::Infallible> { | ||||
|             let payload = super::get_test_register_payload(&usr); | ||||
|             let req = axum::http::Request::builder() | ||||
|                 .method(axum::http::Method::POST) | ||||
|                 .uri(crate::callers::endpoints::REGISTER) | ||||
|                 .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                 .body(axum::body::Body::from(payload.to_string())) | ||||
|                 .unwrap(); | ||||
|  | ||||
|             app.clone().oneshot(req).await | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     #[tokio::test] | ||||
|     async fn test_hello_world() { | ||||
|         let app = init::app().await; | ||||
| @@ -201,18 +303,8 @@ mod tests { | ||||
|         let app = init::routes().await.layer(axum::Extension(pool)); | ||||
|  | ||||
|         let usr = get_test_register_request(); | ||||
|         let payload = get_test_register_payload(&usr); | ||||
|  | ||||
|         let response = app | ||||
|             .oneshot( | ||||
|                 Request::builder() | ||||
|                     .method(axum::http::Method::POST) | ||||
|                     .uri(callers::endpoints::REGISTER) | ||||
|                     .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                     .body(Body::from(payload.to_string())) | ||||
|                     .unwrap(), | ||||
|             ) | ||||
|             .await; | ||||
|         let response = requests::register(&app, &usr).await; | ||||
|  | ||||
|         match response { | ||||
|             Ok(resp) => { | ||||
| @@ -268,19 +360,8 @@ mod tests { | ||||
|         let app = init::routes().await.layer(axum::Extension(pool)); | ||||
|  | ||||
|         let usr = get_test_register_request(); | ||||
|         let payload = get_test_register_payload(&usr); | ||||
|  | ||||
|         let response = app | ||||
|             .clone() | ||||
|             .oneshot( | ||||
|                 Request::builder() | ||||
|                     .method(axum::http::Method::POST) | ||||
|                     .uri(callers::endpoints::REGISTER) | ||||
|                     .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                     .body(Body::from(payload.to_string())) | ||||
|                     .unwrap(), | ||||
|             ) | ||||
|             .await; | ||||
|         let response = requests::register(&app, &usr).await; | ||||
|  | ||||
|         match response { | ||||
|             Ok(resp) => { | ||||
| @@ -344,4 +425,125 @@ mod tests { | ||||
|  | ||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||
|     } | ||||
|  | ||||
|     #[tokio::test] | ||||
|     async fn test_service_login_user() { | ||||
|         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||
|  | ||||
|         let db_name = db_mgr::generate_db_name().await; | ||||
|  | ||||
|         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||
|             Ok(_) => { | ||||
|                 println!("Success"); | ||||
|             } | ||||
|             Err(e) => { | ||||
|                 assert!(false, "Error: {:?}", e.to_string()); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||
|  | ||||
|         icarus_auth::db::migrations(&pool).await; | ||||
|  | ||||
|         let app = init::routes().await.layer(axum::Extension(pool)); | ||||
|         let passphrase = | ||||
|             String::from("iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH"); | ||||
|         let payload = serde_json::json!({ | ||||
|             "passphrase": passphrase | ||||
|         }); | ||||
|  | ||||
|         match app | ||||
|             .oneshot( | ||||
|                 Request::builder() | ||||
|                     .method(axum::http::Method::POST) | ||||
|                     .uri(callers::endpoints::SERVICE_LOGIN) | ||||
|                     .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                     .body(Body::from(payload.to_string())) | ||||
|                     .unwrap(), | ||||
|             ) | ||||
|             .await | ||||
|         { | ||||
|             Ok(response) => { | ||||
|                 assert_eq!(StatusCode::OK, response.status(), "Status is not right"); | ||||
|                 let body = axum::body::to_bytes(response.into_body(), usize::MAX) | ||||
|                     .await | ||||
|                     .unwrap(); | ||||
|                 let parsed_body: callers::login::response::service_login::Response = | ||||
|                     serde_json::from_slice(&body).unwrap(); | ||||
|                 let _login_result = &parsed_body.data[0]; | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {err:?}"); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||
|     } | ||||
|  | ||||
|     #[tokio::test] | ||||
|     async fn test_refresh_token() { | ||||
|         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||
|  | ||||
|         let db_name = db_mgr::generate_db_name().await; | ||||
|  | ||||
|         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||
|             Ok(_) => { | ||||
|                 println!("Success"); | ||||
|             } | ||||
|             Err(e) => { | ||||
|                 assert!(false, "Error: {:?}", e.to_string()); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||
|  | ||||
|         icarus_auth::db::migrations(&pool).await; | ||||
|  | ||||
|         let app = init::routes().await.layer(axum::Extension(pool)); | ||||
|         let id = uuid::Uuid::parse_str("22f9c775-cce9-457a-a147-9dafbb801f61").unwrap(); | ||||
|         let key = icarus_envy::environment::get_secret_key().await.value; | ||||
|  | ||||
|         match icarus_auth::token_stuff::create_service_token(&key, &id) { | ||||
|             Ok((token, _expire)) => { | ||||
|                 let payload = serde_json::json!({ | ||||
|                     "access_token": token | ||||
|                 }); | ||||
|  | ||||
|                 match app | ||||
|                     .oneshot( | ||||
|                         Request::builder() | ||||
|                             .method(axum::http::Method::POST) | ||||
|                             .uri(callers::endpoints::REFRESH_TOKEN) | ||||
|                             .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||
|                             .body(Body::from(payload.to_string())) | ||||
|                             .unwrap(), | ||||
|                     ) | ||||
|                     .await | ||||
|                 { | ||||
|                     Ok(response) => { | ||||
|                         let body = axum::body::to_bytes(response.into_body(), usize::MAX) | ||||
|                             .await | ||||
|                             .unwrap(); | ||||
|                         let parsed_body: callers::login::response::service_login::Response = | ||||
|                             serde_json::from_slice(&body).unwrap(); | ||||
|                         let login_result = &parsed_body.data[0]; | ||||
|  | ||||
|                         assert_eq!( | ||||
|                             id, login_result.id, | ||||
|                             "The Id from the response does not match {id:?} {:?}", | ||||
|                             login_result.id | ||||
|                         ); | ||||
|                     } | ||||
|                     Err(err) => { | ||||
|                         assert!(false, "Error: {err:?}"); | ||||
|                     } | ||||
|                 } | ||||
|             } | ||||
|             Err(err) => { | ||||
|                 assert!(false, "Error: {err:?}"); | ||||
|             } | ||||
|         } | ||||
|  | ||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||
|     } | ||||
| } | ||||
|   | ||||
| @@ -42,6 +42,39 @@ pub mod user { | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn update_last_login( | ||||
|         pool: &sqlx::PgPool, | ||||
|         user: &icarus_models::user::User, | ||||
|         time: &time::OffsetDateTime, | ||||
|     ) -> Result<time::OffsetDateTime, sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|             UPDATE "user" SET last_login = $1 WHERE id = $2 RETURNING last_login | ||||
|             "#, | ||||
|         ) | ||||
|         .bind(time) | ||||
|         .bind(user.id) | ||||
|         .fetch_optional(pool) | ||||
|         .await | ||||
|         .map_err(|e| { | ||||
|             eprintln!("Error updating time: {e}"); | ||||
|             e | ||||
|         }); | ||||
|  | ||||
|         match result { | ||||
|             Ok(row) => match row { | ||||
|                 Some(r) => { | ||||
|                     let last_login: time::OffsetDateTime = r | ||||
|                         .try_get("last_login") | ||||
|                         .map_err(|_e| sqlx::Error::RowNotFound)?; | ||||
|                     Ok(last_login) | ||||
|                 } | ||||
|                 None => Err(sqlx::Error::RowNotFound), | ||||
|             }, | ||||
|             Err(err) => Err(err), | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn exists(pool: &sqlx::PgPool, username: &String) -> Result<bool, sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
| @@ -80,7 +113,7 @@ pub mod user { | ||||
|         .fetch_one(pool) | ||||
|         .await | ||||
|         .map_err(|e| { | ||||
|             eprintln!("Error inserting item: {}", e); | ||||
|             eprintln!("Error inserting item: {e}"); | ||||
|             e | ||||
|         })?; | ||||
|  | ||||
| @@ -147,7 +180,7 @@ pub mod salt { | ||||
|         .fetch_one(pool) | ||||
|         .await | ||||
|         .map_err(|e| { | ||||
|             eprintln!("Error inserting item: {}", e); | ||||
|             eprintln!("Error inserting item: {e}"); | ||||
|             e | ||||
|         })?; | ||||
|  | ||||
| @@ -162,3 +195,56 @@ pub mod salt { | ||||
|         } | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub mod service { | ||||
|     use sqlx::Row; | ||||
|  | ||||
|     pub async fn valid_passphrase( | ||||
|         pool: &sqlx::PgPool, | ||||
|         passphrase: &String, | ||||
|     ) -> Result<(uuid::Uuid, String, time::OffsetDateTime), sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|             SELECT * FROM "passphrase" WHERE passphrase = $1 | ||||
|             "#, | ||||
|         ) | ||||
|         .bind(passphrase) | ||||
|         .fetch_one(pool) | ||||
|         .await; | ||||
|  | ||||
|         match result { | ||||
|             Ok(row) => { | ||||
|                 let id: uuid::Uuid = row.try_get("id")?; | ||||
|                 let passphrase: String = row.try_get("passphrase")?; | ||||
|                 let date_created: Option<time::OffsetDateTime> = row.try_get("date_created")?; | ||||
|  | ||||
|                 Ok((id, passphrase, date_created.unwrap())) | ||||
|             } | ||||
|             Err(err) => Err(err), | ||||
|         } | ||||
|     } | ||||
|  | ||||
|     pub async fn get_passphrase( | ||||
|         pool: &sqlx::PgPool, | ||||
|         id: &uuid::Uuid, | ||||
|     ) -> Result<(uuid::Uuid, String, time::OffsetDateTime), sqlx::Error> { | ||||
|         let result = sqlx::query( | ||||
|             r#" | ||||
|             SELECT * FROM "passphrase" WHERE id = $1; | ||||
|             "#, | ||||
|         ) | ||||
|         .bind(id) | ||||
|         .fetch_one(pool) | ||||
|         .await; | ||||
|  | ||||
|         match result { | ||||
|             Ok(row) => { | ||||
|                 let returned_id: uuid::Uuid = row.try_get("id")?; | ||||
|                 let passphrase: String = row.try_get("passphrase")?; | ||||
|                 let date_created: time::OffsetDateTime = row.try_get("date_created")?; | ||||
|                 Ok((returned_id, passphrase, date_created)) | ||||
|             } | ||||
|             Err(err) => Err(err), | ||||
|         } | ||||
|     } | ||||
| } | ||||
|   | ||||
| @@ -1,23 +1,16 @@ | ||||
| use josekit::{ | ||||
|     self, | ||||
|     jws::{JwsHeader, alg::hmac::HmacJwsAlgorithm::Hs256}, | ||||
|     jwt::{self, JwtPayload}, | ||||
|     jws::alg::hmac::HmacJwsAlgorithm::Hs256, | ||||
|     jwt::{self}, | ||||
| }; | ||||
|  | ||||
| use time; | ||||
|  | ||||
| pub const TOKENTYPE: &str = "JWT"; | ||||
| pub const KEY_ENV: &str = "SECRET_KEY"; | ||||
| pub const MESSAGE: &str = "Something random"; | ||||
| pub const ISSUER: &str = "icarus_auth"; | ||||
| pub const AUDIENCE: &str = "icarus"; | ||||
|  | ||||
| pub fn get_key() -> Result<String, dotenvy::Error> { | ||||
|     dotenvy::dotenv().ok(); | ||||
|     let key = std::env::var(KEY_ENV).expect("SECRET_KEY_NOT_FOUND"); | ||||
|     Ok(key) | ||||
| } | ||||
|  | ||||
| pub fn get_issued() -> time::Result<time::OffsetDateTime> { | ||||
|     Ok(time::OffsetDateTime::now_utc()) | ||||
| } | ||||
| @@ -27,63 +20,115 @@ pub fn get_expiration(issued: &time::OffsetDateTime) -> Result<time::OffsetDateT | ||||
|     Ok(*issued + duration_expire) | ||||
| } | ||||
|  | ||||
| mod util { | ||||
|     pub fn time_to_std_time( | ||||
|         provided_time: &time::OffsetDateTime, | ||||
|     ) -> Result<std::time::SystemTime, std::time::SystemTimeError> { | ||||
|         let converted = std::time::SystemTime::from(*provided_time); | ||||
|         Ok(converted) | ||||
|     } | ||||
| pub fn create_token( | ||||
|     provided_key: &String, | ||||
|     id: &uuid::Uuid, | ||||
| ) -> Result<(String, i64), josekit::JoseError> { | ||||
|     let resource = icarus_models::token::TokenResource { | ||||
|         message: String::from(MESSAGE), | ||||
|         issuer: String::from(ISSUER), | ||||
|         audiences: vec![String::from(AUDIENCE)], | ||||
|         id: *id, | ||||
|     }; | ||||
|     icarus_models::token::create_token(provided_key, &resource, time::Duration::hours(4)) | ||||
| } | ||||
|  | ||||
| pub fn create_token(provided_key: &String) -> Result<(String, i64), josekit::JoseError> { | ||||
|     let mut header = JwsHeader::new(); | ||||
|     header.set_token_type(TOKENTYPE); | ||||
| pub fn create_service_token( | ||||
|     provided: &String, | ||||
|     id: &uuid::Uuid, | ||||
| ) -> Result<(String, i64), josekit::JoseError> { | ||||
|     let resource = icarus_models::token::TokenResource { | ||||
|         message: String::from(SERVICE_SUBJECT), | ||||
|         issuer: String::from(ISSUER), | ||||
|         audiences: vec![String::from(AUDIENCE)], | ||||
|         id: *id, | ||||
|     }; | ||||
|     icarus_models::token::create_token(provided, &resource, time::Duration::hours(1)) | ||||
| } | ||||
|  | ||||
|     let mut payload = JwtPayload::new(); | ||||
|     payload.set_subject(MESSAGE); | ||||
|     payload.set_issuer(ISSUER); | ||||
|     payload.set_audience(vec![AUDIENCE]); | ||||
|     match get_issued() { | ||||
|         Ok(issued) => { | ||||
|             let expire = get_expiration(&issued).unwrap(); | ||||
|             payload.set_issued_at(&util::time_to_std_time(&issued).unwrap()); | ||||
|             payload.set_expires_at(&util::time_to_std_time(&expire).unwrap()); | ||||
|  | ||||
|             let key: String = if provided_key.is_empty() { | ||||
|                 get_key().unwrap() | ||||
|             } else { | ||||
|                 provided_key.to_owned() | ||||
|             }; | ||||
|  | ||||
|             let signer = Hs256.signer_from_bytes(key.as_bytes()).unwrap(); | ||||
|             Ok(( | ||||
|                 josekit::jwt::encode_with_signer(&payload, &header, &signer).unwrap(), | ||||
|                 (expire - time::OffsetDateTime::UNIX_EPOCH).whole_seconds(), | ||||
|             )) | ||||
|         } | ||||
|         Err(e) => Err(josekit::JoseError::InvalidClaim(e.into())), | ||||
|     } | ||||
| pub fn create_service_refresh_token( | ||||
|     key: &String, | ||||
|     id: &uuid::Uuid, | ||||
| ) -> Result<(String, i64), josekit::JoseError> { | ||||
|     let resource = icarus_models::token::TokenResource { | ||||
|         message: String::from(SERVICE_SUBJECT), | ||||
|         issuer: String::from(ISSUER), | ||||
|         audiences: vec![String::from(AUDIENCE)], | ||||
|         id: *id, | ||||
|     }; | ||||
|     icarus_models::token::create_token(key, &resource, time::Duration::hours(4)) | ||||
| } | ||||
|  | ||||
| pub fn verify_token(key: &String, token: &String) -> bool { | ||||
|     let ver = Hs256.verifier_from_bytes(key.as_bytes()).unwrap(); | ||||
|     let (payload, _header) = jwt::decode_with_verifier(token, &ver).unwrap(); | ||||
|     match payload.subject() { | ||||
|         Some(_sub) => true, | ||||
|         None => false, | ||||
|     match get_payload(key, token) { | ||||
|         Ok((payload, _header)) => match payload.subject() { | ||||
|             Some(_sub) => true, | ||||
|             None => false, | ||||
|         }, | ||||
|         Err(_err) => false, | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub fn extract_id_from_token(key: &String, token: &String) -> Result<uuid::Uuid, std::io::Error> { | ||||
|     match get_payload(key, token) { | ||||
|         Ok((payload, _header)) => match payload.claim("id") { | ||||
|             Some(id) => match uuid::Uuid::parse_str(id.as_str().unwrap()) { | ||||
|                 Ok(extracted) => Ok(extracted), | ||||
|                 Err(err) => Err(std::io::Error::other(err.to_string())), | ||||
|             }, | ||||
|             None => Err(std::io::Error::other("No claim found")), | ||||
|         }, | ||||
|         Err(err) => Err(std::io::Error::other(err.to_string())), | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub const APP_TOKEN_TYPE: &str = "Icarus_App"; | ||||
| pub const APP_SUBJECT: &str = "Something random"; | ||||
| pub const SERVICE_TOKEN_TYPE: &str = "Icarus_Service"; | ||||
| pub const SERVICE_SUBJECT: &str = "Service random"; | ||||
|  | ||||
| pub fn get_token_type(key: &String, token: &String) -> Result<String, std::io::Error> { | ||||
|     match get_payload(key, token) { | ||||
|         Ok((payload, _header)) => match payload.subject() { | ||||
|             Some(subject) => { | ||||
|                 if subject == APP_SUBJECT { | ||||
|                     Ok(String::from(APP_TOKEN_TYPE)) | ||||
|                 } else if subject == SERVICE_SUBJECT { | ||||
|                     Ok(String::from(SERVICE_TOKEN_TYPE)) | ||||
|                 } else { | ||||
|                     Err(std::io::Error::other(String::from("Invalid subject"))) | ||||
|                 } | ||||
|             } | ||||
|             None => Err(std::io::Error::other(String::from("Invalid payload"))), | ||||
|         }, | ||||
|         Err(err) => Err(std::io::Error::other(err.to_string())), | ||||
|     } | ||||
| } | ||||
|  | ||||
| pub fn is_token_type_valid(token_type: &String) -> bool { | ||||
|     token_type == SERVICE_TOKEN_TYPE | ||||
| } | ||||
|  | ||||
| fn get_payload( | ||||
|     key: &String, | ||||
|     token: &String, | ||||
| ) -> Result<(josekit::jwt::JwtPayload, josekit::jws::JwsHeader), josekit::JoseError> { | ||||
|     let ver = Hs256.verifier_from_bytes(key.as_bytes()).unwrap(); | ||||
|     jwt::decode_with_verifier(token, &ver) | ||||
| } | ||||
|  | ||||
| #[cfg(test)] | ||||
| mod tests { | ||||
|  | ||||
|     use super::*; | ||||
|  | ||||
|     #[test] | ||||
|     fn test_tokenize() { | ||||
|         let special_key = get_key().unwrap(); | ||||
|         match create_token(&special_key) { | ||||
|         let rt = tokio::runtime::Runtime::new().unwrap(); | ||||
|         let special_key = rt | ||||
|             .block_on(icarus_envy::environment::get_secret_key()) | ||||
|             .value; | ||||
|         let id = uuid::Uuid::new_v4(); | ||||
|         match create_token(&special_key, &id) { | ||||
|             Ok((token, _duration)) => { | ||||
|                 let result = verify_token(&special_key, &token); | ||||
|                 assert!(result, "Token not verified"); | ||||
|   | ||||
		Reference in New Issue
	
	Block a user