Compare commits
	
		
			24 Commits
		
	
	
		
			v0.3.4-dev
			...
			v0.6.1-mai
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 7e44d523f2 | |||
| 59d0ca0c0b | |||
| a02b15c65c | |||
| ebe29df991 | |||
| 473b4ec762 | |||
| a66ab7826c | |||
| 9da068252d | |||
| 2ba037c393 | |||
| a4c943189c | |||
| eb1e2990f9 | |||
| 99390ce8b7 | |||
| 5967ed5b13 | |||
| be4d1109a7 | |||
| 4353414c69 | |||
| c176d0fcf3 | |||
| c8b8d470dc | |||
| bcd0e607ef | |||
| 70de6b862f | |||
| 8c902b9d61 | |||
| 480a428e8b | |||
| 02697b2fd9 | |||
| d4faa7976e | |||
| ed77cab700 | |||
| eb7e394cf0 | 
							
								
								
									
										12
									
								
								.env.docker.sample
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								.env.docker.sample
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,12 @@ | |||||||
|  | APP_ENV=development | ||||||
|  | BACKEND_PORT=8001 | ||||||
|  | FRONTEND_URL=http://localhost:4200 | ||||||
|  | RUST_LOG=debug | ||||||
|  | ALLOWED_ORIGINS=https://soaricarus.com,https://www.soaricarus.com | ||||||
|  | SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||||
|  | SERVICE_PASSPHRASE=iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH | ||||||
|  | POSTGRES_AUTH_USER=icarus_op | ||||||
|  | POSTGRES_AUTH_PASSWORD=password | ||||||
|  | POSTGRES_AUTH_DB=icarus_auth_db | ||||||
|  | POSTGRES_AUTH_HOST=auth_db | ||||||
|  | DATABASE_URL=postgresql://${POSTGRES_AUTH_USER}:${POSTGRES_AUTH_PASSWORD}@${POSTGRES_AUTH_HOST}:5432/${POSTGRES_AUTH_DB} | ||||||
							
								
								
									
										16
									
								
								.env.sample
									
									
									
									
									
								
							
							
						
						
									
										16
									
								
								.env.sample
									
									
									
									
									
								
							| @@ -1,6 +1,12 @@ | |||||||
|  | APP_ENV=development | ||||||
|  | BACKEND_PORT=8001 | ||||||
|  | FRONTEND_URL=http://localhost:4200 | ||||||
|  | RUST_LOG=debug | ||||||
|  | ALLOWED_ORIGINS=https://soaricarus.com,https://www.soaricarus.com | ||||||
| SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||||
| POSTGRES_USER=icarus_op_test | SERVICE_PASSPHRASE=iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH | ||||||
| POSTGRES_PASSWORD=password | POSTGRES_AUTH_USER=icarus_op_test | ||||||
| POSTGRES_DB=icarus_auth_test_db | POSTGRES_AUTH_PASSWORD=password | ||||||
| POSTGRES_HOST=localhost | POSTGRES_AUTH_DB=icarus_auth_test_db | ||||||
| DATABASE_URL=postgresql://${POSTGRES_USER}:${POSTGRES_PASSWORD}@${POSTGRES_HOST}:5432/${POSTGRES_DB} | POSTGRES_AUTH_HOST=localhost | ||||||
|  | DATABASE_URL=postgresql://${POSTGRES_AUTH_USER}:${POSTGRES_AUTH_PASSWORD}@${POSTGRES_AUTH_HOST}:5432/${POSTGRES_AUTH_DB} | ||||||
|   | |||||||
| @@ -3,21 +3,21 @@ name: Release Tagging | |||||||
| on: | on: | ||||||
|   push: |   push: | ||||||
|     branches: |     branches: | ||||||
|       - devel |       - main | ||||||
|  |  | ||||||
| jobs: | jobs: | ||||||
|   release: |   release: | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - name: Checkout code |       - name: Checkout code | ||||||
|         uses: actions/checkout@v3 |         uses: actions/checkout@v5 | ||||||
|         with: |         with: | ||||||
|           fetch-depth: 0 # Important for git describe --tags |           fetch-depth: 0 # Important for git describe --tags | ||||||
|  |  | ||||||
|       - name: Install Rust |       - name: Install Rust | ||||||
|         uses: actions-rs/toolchain@v1 |         uses: actions-rs/toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|           components: cargo |           components: cargo | ||||||
|  |  | ||||||
|       - name: Extract Version from Cargo.toml |       - name: Extract Version from Cargo.toml | ||||||
| @@ -27,8 +27,10 @@ jobs: | |||||||
|           PROJECT_COMMIT_HASH=$(git rev-parse HEAD | cut -c 1-10) |           PROJECT_COMMIT_HASH=$(git rev-parse HEAD | cut -c 1-10) | ||||||
|           BRANCH_REF="${GITHUB_REF}" |           BRANCH_REF="${GITHUB_REF}" | ||||||
|           BRANCH_NAME=$(echo "$BRANCH_REF" | cut -d '/' -f 3) |           BRANCH_NAME=$(echo "$BRANCH_REF" | cut -d '/' -f 3) | ||||||
|           PROJECT_TAG_RELEASE="v$VERSION-$BRANCH_NAME-$PROJECT_COMMIT_HASH" |           PROJECT_TAG_RELEASE="v$VERSION-$BRANCH_NAME-$PROJECT_COMMIT_HASH-950" | ||||||
|           echo "::set-output name=project_tag_release::$PROJECT_TAG_RELEASE-950" |  | ||||||
|  |           echo "::set-output name=project_tag_release::$PROJECT_TAG_RELEASE" | ||||||
|  |  | ||||||
|           echo "Version: $VERSION" |           echo "Version: $VERSION" | ||||||
|           echo "Hash: $PROJECT_COMMIT_HASH" |           echo "Hash: $PROJECT_COMMIT_HASH" | ||||||
|           echo "Branch: $BRANCH_NAME" |           echo "Branch: $BRANCH_NAME" | ||||||
| @@ -49,5 +51,3 @@ jobs: | |||||||
|           release_name: Release ${{ steps.version.outputs.project_tag_release }} |           release_name: Release ${{ steps.version.outputs.project_tag_release }} | ||||||
|           body: | |           body: | | ||||||
|            Release of version ${{ steps.version.outputs.project_tag_release }} |            Release of version ${{ steps.version.outputs.project_tag_release }} | ||||||
|           # draft: false |  | ||||||
|           # prerelease: ${{ startsWith(github.ref, 'v') == false }} # prerelease if not a valid release tag |  | ||||||
| @@ -15,10 +15,10 @@ jobs: | |||||||
|     name: Check |     name: Check | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       - run: | |       - run: | | ||||||
|           mkdir -p ~/.ssh |           mkdir -p ~/.ssh | ||||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key |           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||||
| @@ -36,7 +36,7 @@ jobs: | |||||||
|     # --- Add database service definition --- |     # --- Add database service definition --- | ||||||
|     services: |     services: | ||||||
|       postgres: |       postgres: | ||||||
|         image: postgres:17.4 # Or pin to a more specific version like 14.9 |         image: postgres:17.5 | ||||||
|         env: |         env: | ||||||
|           # Use secrets for DB init, with fallbacks for flexibility |           # Use secrets for DB init, with fallbacks for flexibility | ||||||
|           POSTGRES_USER: ${{ secrets.DB_TEST_USER || 'testuser' }} |           POSTGRES_USER: ${{ secrets.DB_TEST_USER || 'testuser' }} | ||||||
| @@ -50,10 +50,10 @@ jobs: | |||||||
|           --health-retries 5 |           --health-retries 5 | ||||||
|  |  | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       # --- Add this step for explicit verification --- |       # --- Add this step for explicit verification --- | ||||||
|       - name: Verify Docker Environment |       - name: Verify Docker Environment | ||||||
|         run: | |         run: | | ||||||
| @@ -91,10 +91,10 @@ jobs: | |||||||
|     name: Rustfmt |     name: Rustfmt | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       - run: rustup component add rustfmt |       - run: rustup component add rustfmt | ||||||
|       - run: | |       - run: | | ||||||
|           mkdir -p ~/.ssh |           mkdir -p ~/.ssh | ||||||
| @@ -110,10 +110,10 @@ jobs: | |||||||
|     name: Clippy |     name: Clippy | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       - run: rustup component add clippy |       - run: rustup component add clippy | ||||||
|       - run: | |       - run: | | ||||||
|           mkdir -p ~/.ssh |           mkdir -p ~/.ssh | ||||||
| @@ -129,10 +129,10 @@ jobs: | |||||||
|     name: build |     name: build | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       - run: | |       - run: | | ||||||
|           mkdir -p ~/.ssh |           mkdir -p ~/.ssh | ||||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key |           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||||
|   | |||||||
							
								
								
									
										2
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										2
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							| @@ -1,4 +1,4 @@ | |||||||
| /target | /target | ||||||
| Cargo.lock |  | ||||||
| .env | .env | ||||||
|  | .env.local | ||||||
| .env.docker | .env.docker | ||||||
|   | |||||||
							
								
								
									
										2865
									
								
								Cargo.lock
									
									
									
										generated
									
									
									
										Normal file
									
								
							
							
						
						
									
										2865
									
								
								Cargo.lock
									
									
									
										generated
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										37
									
								
								Cargo.toml
									
									
									
									
									
								
							
							
						
						
									
										37
									
								
								Cargo.toml
									
									
									
									
									
								
							| @@ -1,27 +1,30 @@ | |||||||
| [package] | [package] | ||||||
| name = "icarus_auth" | name = "icarus_auth" | ||||||
| version = "0.3.4" | version = "0.6.1" | ||||||
| edition = "2024" | edition = "2024" | ||||||
| rust-version = "1.86" | rust-version = "1.90" | ||||||
|  |  | ||||||
| [dependencies] | [dependencies] | ||||||
| axum = { version = "0.8.3" } | axum = { version = "0.8.6" } | ||||||
| serde = { version = "1.0.218", features = ["derive"] } | serde = { version = "1.0.228", features = ["derive"] } | ||||||
| serde_json = { version = "1.0.139" } | serde_json = { version = "1.0.145" } | ||||||
| tokio = { version = "1.44.1", features = ["rt-multi-thread"] } | tokio = { version = "1.47.1", features = ["rt-multi-thread"] } | ||||||
| tracing-subscriber = { version = "0.3.19" } | tracing-subscriber = { version = "0.3.20" } | ||||||
| tower = { version = "0.5.2" } | tower = { version = "0.5.2", features = ["full"] } | ||||||
| hyper = { version = "1.6.0" } | tower-http = { version = "0.6.6", features = ["cors"] } | ||||||
| sqlx = { version = "0.8.3", features = ["postgres", "runtime-tokio-native-tls", "time", "uuid"] } | hyper = { version = "1.7.0" } | ||||||
| dotenvy = { version = "0.15.7" } | sqlx = { version = "0.8.6", features = ["postgres", "runtime-tokio-native-tls", "time", "uuid"] } | ||||||
| uuid = { version = "1.16.0", features = ["v4", "serde"] } | uuid = { version = "1.18.1", features = ["v4", "serde"] } | ||||||
| argon2 = { version = "0.5.3", features = ["std"] } # Use the latest 0.5.x version | argon2 = { version = "0.5.3", features = ["std"] } # Use the latest 0.5.x version | ||||||
| rand = { version = "0.9" } | rand = { version = "0.9.2" } | ||||||
| time = { version = "0.3.41", features = ["macros", "serde"] } | time = { version = "0.3.41", features = ["macros", "serde"] } | ||||||
| josekit = { version = "0.10.1" } | josekit = { version = "0.10.3" } | ||||||
| icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.4.1" } | utoipa = { version = "5.4.0", features = ["axum_extras"] } | ||||||
|  | utoipa-swagger-ui = { version = "9.0.2", features = ["axum"] } | ||||||
|  | icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.8.0" } | ||||||
|  | icarus_envy = { git = "ssh://git@git.kundeng.us/phoenix/icarus_envy.git", tag = "v0.5.0" } | ||||||
|  |  | ||||||
| [dev-dependencies] | [dev-dependencies] | ||||||
| http-body-util = { version = "0.1.3" } | http-body-util = { version = "0.1.3" } | ||||||
| url = { version = "2.5" } | url = { version = "2.5.7" } | ||||||
| once_cell = { version = "1.19" } # Useful for lazy initialization in tests/app setup | once_cell = { version = "1.21.3" } # Useful for lazy initialization in tests/app setup | ||||||
|   | |||||||
| @@ -1,7 +1,7 @@ | |||||||
| # Stage 1: Build the application | # Stage 1: Build the application | ||||||
| # Use a specific Rust version for reproducibility. Choose one that matches your development environment. | # Use a specific Rust version for reproducibility. Choose one that matches your development environment. | ||||||
| # Using slim variant for smaller base image | # Using slim variant for smaller base image | ||||||
| FROM rust:1.86 as builder | FROM rust:1.90 as builder | ||||||
|  |  | ||||||
| # Set the working directory inside the container | # Set the working directory inside the container | ||||||
| WORKDIR /usr/src/app | WORKDIR /usr/src/app | ||||||
|   | |||||||
							
								
								
									
										12
									
								
								README.md
									
									
									
									
									
								
							
							
						
						
									
										12
									
								
								README.md
									
									
									
									
									
								
							| @@ -1,9 +1,12 @@ | |||||||
|  | A auth web API services for the Icarus project. | ||||||
|  |  | ||||||
|  |  | ||||||
| # Getting Started | # Getting Started | ||||||
| Copy the `.env.sample` file to `.env` and ensure that the variables are populated. This project | The easiest way to get started is through docker. This assumes that docker is already installed | ||||||
| can be used with regular hosting or with docker. For the sake of getting up to speed quickly, | on your system. Copy the `.env.docker.sample` as `.env`. Most of the data in the env file doesn't  | ||||||
| Docker will be covered. Make sure docker is running and your ssh identity has been loaded. | need to be modified. The `SECRET_KEY` variable should be changed since it will be used for token | ||||||
|  | generation. The `SECRET_PASSPHASE` should also be changed when in production mode, but make sure | ||||||
|  | the respective `passphrase` database table record exists. | ||||||
|  |  | ||||||
| Build image | Build image | ||||||
| ``` | ``` | ||||||
| @@ -24,3 +27,6 @@ Pruning | |||||||
| ``` | ``` | ||||||
| docker system prune -a | docker system prune -a | ||||||
| ``` | ``` | ||||||
|  |  | ||||||
|  | To view the OpenAPI spec, run the project and access `/swagger-ui`. If running through docker, | ||||||
|  | the url would be something like `http://localhost:8000/swagger-ui`. | ||||||
|   | |||||||
| @@ -9,7 +9,7 @@ services: | |||||||
|     container_name: icarus_auth # Optional: Give the container a specific name |     container_name: icarus_auth # Optional: Give the container a specific name | ||||||
|     ports: |     ports: | ||||||
|       # Map host port 8000 to container port 3000 (adjust as needed) |       # Map host port 8000 to container port 3000 (adjust as needed) | ||||||
|       - "8000:3000" |       - "8001:8001" | ||||||
|     env_file: |     env_file: | ||||||
|       - .env |       - .env | ||||||
|     depends_on: |     depends_on: | ||||||
| @@ -19,13 +19,13 @@ services: | |||||||
|  |  | ||||||
|   # PostgreSQL Database Service |   # PostgreSQL Database Service | ||||||
|   auth_db: |   auth_db: | ||||||
|     image: postgres:17.4-alpine # Use an official Postgres image (Alpine variant is smaller) |     image: postgres:17.5-alpine # Use an official Postgres image (Alpine variant is smaller) | ||||||
|     container_name: icarus_auth_db # Optional: Give the container a specific name |     container_name: icarus_auth_db # Optional: Give the container a specific name | ||||||
|     environment: |     environment: | ||||||
|       # These MUST match the user, password, and database name in the DATABASE_URL above |       # These MUST match the user, password, and database name in the DATABASE_URL above | ||||||
|       POSTGRES_USER: ${POSTGRES_USER:-icarus_op} |       POSTGRES_USER: ${POSTGRES_AUTH_USER:-icarus_op} | ||||||
|       POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-password} |       POSTGRES_PASSWORD: ${POSTGRES_AUTH_PASSWORD:-password} | ||||||
|       POSTGRES_DB: ${POSTGRES_DB:-icarus_auth} |       POSTGRES_DB: ${POSTGRES_AUTH_DB:-icarus_auth_db} | ||||||
|     volumes: |     volumes: | ||||||
|       # Persist database data using a named volume |       # Persist database data using a named volume | ||||||
|       - postgres_data:/var/lib/postgresql/data |       - postgres_data:/var/lib/postgresql/data | ||||||
|   | |||||||
| @@ -20,3 +20,9 @@ CREATE TABLE IF NOT EXISTS "salt" ( | |||||||
|     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), |     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||||
|     salt TEXT NOT NULL |     salt TEXT NOT NULL | ||||||
| ); | ); | ||||||
|  |  | ||||||
|  | CREATE TABLE IF NOT EXISTS "passphrase" ( | ||||||
|  |     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||||
|  |     passphrase TEXT NOT NULL, | ||||||
|  |     date_created TIMESTAMPTZ NOT NULL DEFAULT NOW() | ||||||
|  | ); | ||||||
|   | |||||||
							
								
								
									
										2
									
								
								migrations/20250802185652_passphrase_data.sql
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										2
									
								
								migrations/20250802185652_passphrase_data.sql
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,2 @@ | |||||||
|  | -- Add migration script here | ||||||
|  | INSERT INTO "passphrase" (id, passphrase) VALUES('22f9c775-cce9-457a-a147-9dafbb801f61', 'iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH'); | ||||||
| @@ -1,3 +1,5 @@ | |||||||
|  | TODO: At some point, move this somewhere that is appropriate | ||||||
|  |  | ||||||
| # Make sure role has CREATEDB | # Make sure role has CREATEDB | ||||||
| ALTER ROLE username_that_needs_permission CREATEDB; | ALTER ROLE username_that_needs_permission CREATEDB; | ||||||
|  |  | ||||||
|   | |||||||
| @@ -1,7 +1,7 @@ | |||||||
| pub mod response { | pub mod response { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Deserialize, Serialize)] |     #[derive(Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct TestResult { |     pub struct TestResult { | ||||||
|         pub message: String, |         pub message: String, | ||||||
|     } |     } | ||||||
| @@ -11,11 +11,28 @@ pub mod endpoint { | |||||||
|     use super::*; |     use super::*; | ||||||
|     use axum::{Extension, Json, http::StatusCode}; |     use axum::{Extension, Json, http::StatusCode}; | ||||||
|  |  | ||||||
|     // basic handler that responds with a static string |     /// Endpoint to hit the root | ||||||
|  |     /// basic handler that responds with a static string | ||||||
|  |     #[utoipa::path( | ||||||
|  |         get, | ||||||
|  |         path = super::super::endpoints::ROOT, | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Test", body = &str), | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|     pub async fn root() -> &'static str { |     pub async fn root() -> &'static str { | ||||||
|         "Hello, World!" |         "Hello, World!" | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     /// Endpoint to do a database ping | ||||||
|  |     #[utoipa::path( | ||||||
|  |         get, | ||||||
|  |         path = super::super::endpoints::DBTEST, | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Successful ping of the db", body = super::response::TestResult), | ||||||
|  |             (status = 400, description = "Failure in pinging the db", body = super::response::TestResult) | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|     pub async fn db_ping( |     pub async fn db_ping( | ||||||
|         Extension(pool): Extension<sqlx::PgPool>, |         Extension(pool): Extension<sqlx::PgPool>, | ||||||
|     ) -> (StatusCode, Json<response::TestResult>) { |     ) -> (StatusCode, Json<response::TestResult>) { | ||||||
|   | |||||||
| @@ -1,23 +1,54 @@ | |||||||
| pub mod request { | pub mod request { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Default, Deserialize, Serialize)] |     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct Request { |     pub struct Request { | ||||||
|         pub username: String, |         pub username: String, | ||||||
|         pub password: String, |         pub password: String, | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     pub mod service_login { | ||||||
|  |         #[derive(Debug, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||||
|  |         pub struct Request { | ||||||
|  |             pub passphrase: String, | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     pub mod refresh_token { | ||||||
|  |         #[derive(Debug, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||||
|  |         pub struct Request { | ||||||
|  |             pub access_token: String, | ||||||
|  |         } | ||||||
|  |     } | ||||||
| } | } | ||||||
|  |  | ||||||
| pub mod response { | pub mod response { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Default, Deserialize, Serialize)] |     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct Response { |     pub struct Response { | ||||||
|         pub message: String, |         pub message: String, | ||||||
|         pub data: Vec<icarus_models::login_result::LoginResult>, |         pub data: Vec<icarus_models::login_result::LoginResult>, | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     pub mod service_login { | ||||||
|  |         #[derive(Debug, Default, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||||
|  |         pub struct Response { | ||||||
|  |             pub message: String, | ||||||
|  |             pub data: Vec<icarus_models::login_result::LoginResult>, | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     pub mod refresh_token { | ||||||
|  |         #[derive(Debug, Default, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||||
|  |         pub struct Response { | ||||||
|  |             pub message: String, | ||||||
|  |             pub data: Vec<icarus_models::login_result::LoginResult>, | ||||||
|  |         } | ||||||
|  |     } | ||||||
| } | } | ||||||
|  |  | ||||||
|  | /// Module for login endpoints | ||||||
| pub mod endpoint { | pub mod endpoint { | ||||||
|     use axum::{Json, http::StatusCode}; |     use axum::{Json, http::StatusCode}; | ||||||
|  |  | ||||||
| @@ -28,6 +59,10 @@ pub mod endpoint { | |||||||
|     use super::request; |     use super::request; | ||||||
|     use super::response; |     use super::response; | ||||||
|  |  | ||||||
|  |     // TODO: At some point, get the username from the DB | ||||||
|  |     // Name of service username when returning a login result | ||||||
|  |     pub const SERVICE_USERNAME: &str = "service"; | ||||||
|  |  | ||||||
|     async fn not_found(message: &str) -> (StatusCode, Json<response::Response>) { |     async fn not_found(message: &str) -> (StatusCode, Json<response::Response>) { | ||||||
|         ( |         ( | ||||||
|             StatusCode::NOT_FOUND, |             StatusCode::NOT_FOUND, | ||||||
| @@ -38,6 +73,20 @@ pub mod endpoint { | |||||||
|         ) |         ) | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     /// Endpoint to login | ||||||
|  |     #[utoipa::path( | ||||||
|  |         post, | ||||||
|  |         path = super::super::endpoints::LOGIN, | ||||||
|  |         request_body( | ||||||
|  |             content = request::Request, | ||||||
|  |             description = "Data required to login", | ||||||
|  |             content_type = "application/json" | ||||||
|  |         ), | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Successfully logged in", body = response::Response), | ||||||
|  |             (status = 404, description = "Could not login with credentials", body = response::Response) | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|     pub async fn login( |     pub async fn login( | ||||||
|         axum::Extension(pool): axum::Extension<sqlx::PgPool>, |         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||||
|         Json(payload): Json<request::Request>, |         Json(payload): Json<request::Request>, | ||||||
| @@ -47,8 +96,9 @@ pub mod endpoint { | |||||||
|             Ok(user) => { |             Ok(user) => { | ||||||
|                 if hashing::verify_password(&payload.password, user.password.clone()).unwrap() { |                 if hashing::verify_password(&payload.password, user.password.clone()).unwrap() { | ||||||
|                     // Create token |                     // Create token | ||||||
|                     let key = token_stuff::get_key().unwrap(); |                     let key = icarus_envy::environment::get_secret_key().await.value; | ||||||
|                     let (token_literal, duration) = token_stuff::create_token(&key).unwrap(); |                     let (token_literal, duration) = | ||||||
|  |                         token_stuff::create_token(&key, &user.id).unwrap(); | ||||||
|  |  | ||||||
|                     if token_stuff::verify_token(&key, &token_literal) { |                     if token_stuff::verify_token(&key, &token_literal) { | ||||||
|                         let current_time = time::OffsetDateTime::now_utc(); |                         let current_time = time::OffsetDateTime::now_utc(); | ||||||
| @@ -62,7 +112,7 @@ pub mod endpoint { | |||||||
|                                     id: user.id, |                                     id: user.id, | ||||||
|                                     username: user.username.clone(), |                                     username: user.username.clone(), | ||||||
|                                     token: token_literal, |                                     token: token_literal, | ||||||
|                                     token_type: String::from(token_stuff::TOKENTYPE), |                                     token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||||
|                                     expiration: duration, |                                     expiration: duration, | ||||||
|                                 }], |                                 }], | ||||||
|                             }), |                             }), | ||||||
| @@ -79,4 +129,140 @@ pub mod endpoint { | |||||||
|             } |             } | ||||||
|         } |         } | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     /// Endpoint to login as a service user | ||||||
|  |     #[utoipa::path( | ||||||
|  |         post, | ||||||
|  |         path = super::super::endpoints::SERVICE_LOGIN, | ||||||
|  |         request_body( | ||||||
|  |             content = request::service_login::Request, | ||||||
|  |             description = "Data required to login as a service user", | ||||||
|  |             content_type = "application/json" | ||||||
|  |         ), | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Login successful", body = response::Response), | ||||||
|  |             (status = 400, description = "Error logging in with credentials", body = response::Response) | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|  |     pub async fn service_login( | ||||||
|  |         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||||
|  |         axum::Json(payload): axum::Json<request::service_login::Request>, | ||||||
|  |     ) -> ( | ||||||
|  |         axum::http::StatusCode, | ||||||
|  |         axum::Json<response::service_login::Response>, | ||||||
|  |     ) { | ||||||
|  |         let mut response = response::service_login::Response::default(); | ||||||
|  |  | ||||||
|  |         match repo::service::valid_passphrase(&pool, &payload.passphrase).await { | ||||||
|  |             Ok((id, _passphrase, _date_created)) => { | ||||||
|  |                 let key = icarus_envy::environment::get_secret_key().await.value; | ||||||
|  |                 let (token_literal, duration) = | ||||||
|  |                     token_stuff::create_service_token(&key, &id).unwrap(); | ||||||
|  |  | ||||||
|  |                 if token_stuff::verify_token(&key, &token_literal) { | ||||||
|  |                     let login_result = icarus_models::login_result::LoginResult { | ||||||
|  |                         id, | ||||||
|  |                         username: String::from(SERVICE_USERNAME), | ||||||
|  |                         token: token_literal, | ||||||
|  |                         token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||||
|  |                         expiration: duration, | ||||||
|  |                     }; | ||||||
|  |  | ||||||
|  |                     response.data.push(login_result); | ||||||
|  |                     response.message = String::from("Successful"); | ||||||
|  |  | ||||||
|  |                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||||
|  |                 } else { | ||||||
|  |                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |             Err(err) => { | ||||||
|  |                 response.message = err.to_string(); | ||||||
|  |                 (axum::http::StatusCode::BAD_REQUEST, axum::Json(response)) | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     /// Endpoint to retrieve a refresh token | ||||||
|  |     #[utoipa::path( | ||||||
|  |         post, | ||||||
|  |         path = super::super::endpoints::REFRESH_TOKEN, | ||||||
|  |         request_body( | ||||||
|  |             content = request::refresh_token::Request, | ||||||
|  |             description = "Data required to retrieve a refresh token", | ||||||
|  |             content_type = "application/json" | ||||||
|  |         ), | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Refresh token generated", body = response::Response), | ||||||
|  |             (status = 400, description = "Error verifying token", body = response::Response), | ||||||
|  |             (status = 404, description = "Could not validate token", body = response::Response), | ||||||
|  |             (status = 500, description = "Error extracting token", body = response::Response) | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|  |     pub async fn refresh_token( | ||||||
|  |         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||||
|  |         axum::Json(payload): axum::Json<request::refresh_token::Request>, | ||||||
|  |     ) -> ( | ||||||
|  |         axum::http::StatusCode, | ||||||
|  |         axum::Json<response::refresh_token::Response>, | ||||||
|  |     ) { | ||||||
|  |         let mut response = response::refresh_token::Response::default(); | ||||||
|  |         let key = icarus_envy::environment::get_secret_key().await.value; | ||||||
|  |  | ||||||
|  |         if token_stuff::verify_token(&key, &payload.access_token) { | ||||||
|  |             let token_type = token_stuff::get_token_type(&key, &payload.access_token).unwrap(); | ||||||
|  |  | ||||||
|  |             if token_stuff::is_token_type_valid(&token_type) { | ||||||
|  |                 // Get passphrase record with id | ||||||
|  |                 match token_stuff::extract_id_from_token(&key, &payload.access_token) { | ||||||
|  |                     Ok(id) => match repo::service::get_passphrase(&pool, &id).await { | ||||||
|  |                         Ok((returned_id, _, _)) => { | ||||||
|  |                             match token_stuff::create_service_refresh_token(&key, &returned_id) { | ||||||
|  |                                 Ok((access_token, exp_dur)) => { | ||||||
|  |                                     let login_result = icarus_models::login_result::LoginResult { | ||||||
|  |                                         id: returned_id, | ||||||
|  |                                         token: access_token, | ||||||
|  |                                         expiration: exp_dur, | ||||||
|  |                                         token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||||
|  |                                         username: String::from(SERVICE_USERNAME), | ||||||
|  |                                     }; | ||||||
|  |                                     response.message = String::from("Successful"); | ||||||
|  |                                     response.data.push(login_result); | ||||||
|  |  | ||||||
|  |                                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||||
|  |                                 } | ||||||
|  |                                 Err(err) => { | ||||||
|  |                                     response.message = err.to_string(); | ||||||
|  |                                     ( | ||||||
|  |                                         axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||||
|  |                                         axum::Json(response), | ||||||
|  |                                     ) | ||||||
|  |                                 } | ||||||
|  |                             } | ||||||
|  |                         } | ||||||
|  |                         Err(err) => { | ||||||
|  |                             response.message = err.to_string(); | ||||||
|  |                             ( | ||||||
|  |                                 axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||||
|  |                                 axum::Json(response), | ||||||
|  |                             ) | ||||||
|  |                         } | ||||||
|  |                     }, | ||||||
|  |                     Err(err) => { | ||||||
|  |                         response.message = err.to_string(); | ||||||
|  |                         ( | ||||||
|  |                             axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||||
|  |                             axum::Json(response), | ||||||
|  |                         ) | ||||||
|  |                     } | ||||||
|  |                 } | ||||||
|  |             } else { | ||||||
|  |                 response.message = String::from("Invalid token type"); | ||||||
|  |                 (axum::http::StatusCode::NOT_FOUND, axum::Json(response)) | ||||||
|  |             } | ||||||
|  |         } else { | ||||||
|  |             response.message = String::from("Could not verify token"); | ||||||
|  |             (axum::http::StatusCode::BAD_REQUEST, axum::Json(response)) | ||||||
|  |         } | ||||||
|  |     } | ||||||
| } | } | ||||||
|   | |||||||
| @@ -7,4 +7,6 @@ pub mod endpoints { | |||||||
|     pub const REGISTER: &str = "/api/v2/register"; |     pub const REGISTER: &str = "/api/v2/register"; | ||||||
|     pub const DBTEST: &str = "/api/v2/test/db"; |     pub const DBTEST: &str = "/api/v2/test/db"; | ||||||
|     pub const LOGIN: &str = "/api/v2/login"; |     pub const LOGIN: &str = "/api/v2/login"; | ||||||
|  |     pub const SERVICE_LOGIN: &str = "/api/v2/service/login"; | ||||||
|  |     pub const REFRESH_TOKEN: &str = "/api/v2/token/refresh"; | ||||||
| } | } | ||||||
|   | |||||||
| @@ -6,7 +6,7 @@ use crate::repo; | |||||||
| pub mod request { | pub mod request { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Default, Deserialize, Serialize)] |     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct Request { |     pub struct Request { | ||||||
|         #[serde(skip_serializing_if = "String::is_empty")] |         #[serde(skip_serializing_if = "String::is_empty")] | ||||||
|         pub username: String, |         pub username: String, | ||||||
| @@ -26,13 +26,28 @@ pub mod request { | |||||||
| pub mod response { | pub mod response { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Deserialize, Serialize)] |     #[derive(Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct Response { |     pub struct Response { | ||||||
|         pub message: String, |         pub message: String, | ||||||
|         pub data: Vec<icarus_models::user::User>, |         pub data: Vec<icarus_models::user::User>, | ||||||
|     } |     } | ||||||
| } | } | ||||||
|  |  | ||||||
|  | /// Endpoint to register a user | ||||||
|  | #[utoipa::path( | ||||||
|  |     post, | ||||||
|  |     path = super::endpoints::REGISTER, | ||||||
|  |     request_body( | ||||||
|  |         content = request::Request, | ||||||
|  |         description = "Data required to register", | ||||||
|  |         content_type = "application/json" | ||||||
|  |     ), | ||||||
|  |     responses( | ||||||
|  |         (status = 201, description = "User created", body = response::Response), | ||||||
|  |         (status = 404, description = "User already exists", body = response::Response), | ||||||
|  |         (status = 400, description = "Issue creating user", body = response::Response) | ||||||
|  |     ) | ||||||
|  | )] | ||||||
| pub async fn register_user( | pub async fn register_user( | ||||||
|     axum::Extension(pool): axum::Extension<sqlx::PgPool>, |     axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||||
|     Json(payload): Json<request::Request>, |     Json(payload): Json<request::Request>, | ||||||
|   | |||||||
| @@ -6,5 +6,5 @@ fn get_address() -> String { | |||||||
| } | } | ||||||
|  |  | ||||||
| fn get_port() -> String { | fn get_port() -> String { | ||||||
|     String::from("3000") |     String::from("8001") | ||||||
| } | } | ||||||
|   | |||||||
							
								
								
									
										22
									
								
								src/lib.rs
									
									
									
									
									
								
							
							
						
						
									
										22
									
								
								src/lib.rs
									
									
									
									
									
								
							| @@ -1,17 +1,10 @@ | |||||||
|  | // TODO: Get rid of this file and place the code in more appropriate places | ||||||
| pub mod callers; | pub mod callers; | ||||||
| pub mod config; | pub mod config; | ||||||
| pub mod hashing; | pub mod hashing; | ||||||
| pub mod repo; | pub mod repo; | ||||||
| pub mod token_stuff; | pub mod token_stuff; | ||||||
|  |  | ||||||
| pub mod keys { |  | ||||||
|     pub const DBURL: &str = "DATABASE_URL"; |  | ||||||
|  |  | ||||||
|     pub mod error { |  | ||||||
|         pub const ERROR: &str = "DATABASE_URL must be set in .env"; |  | ||||||
|     } |  | ||||||
| } |  | ||||||
|  |  | ||||||
| mod connection_settings { | mod connection_settings { | ||||||
|     pub const MAXCONN: u32 = 5; |     pub const MAXCONN: u32 = 5; | ||||||
| } | } | ||||||
| @@ -19,13 +12,12 @@ mod connection_settings { | |||||||
| pub mod db { | pub mod db { | ||||||
|  |  | ||||||
|     use sqlx::postgres::PgPoolOptions; |     use sqlx::postgres::PgPoolOptions; | ||||||
|     use std::env; |  | ||||||
|  |  | ||||||
|     use crate::{connection_settings, keys}; |     use crate::connection_settings; | ||||||
|  |  | ||||||
|     pub async fn create_pool() -> Result<sqlx::PgPool, sqlx::Error> { |     pub async fn create_pool() -> Result<sqlx::PgPool, sqlx::Error> { | ||||||
|         let database_url = get_db_url().await; |         let database_url = icarus_envy::environment::get_db_url().await.value; | ||||||
|         println!("Database url: {:?}", database_url); |         println!("Database url: {database_url}"); | ||||||
|  |  | ||||||
|         PgPoolOptions::new() |         PgPoolOptions::new() | ||||||
|             .max_connections(connection_settings::MAXCONN) |             .max_connections(connection_settings::MAXCONN) | ||||||
| @@ -33,12 +25,6 @@ pub mod db { | |||||||
|             .await |             .await | ||||||
|     } |     } | ||||||
|  |  | ||||||
|     async fn get_db_url() -> String { |  | ||||||
|         #[cfg(debug_assertions)] // Example: Only load .env in debug builds |  | ||||||
|         dotenvy::dotenv().ok(); |  | ||||||
|         env::var(keys::DBURL).expect(keys::error::ERROR) |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     pub async fn migrations(pool: &sqlx::PgPool) { |     pub async fn migrations(pool: &sqlx::PgPool) { | ||||||
|         // Run migrations using the sqlx::migrate! macro |         // Run migrations using the sqlx::migrate! macro | ||||||
|         // Assumes your migrations are in a ./migrations folder relative to Cargo.toml |         // Assumes your migrations are in a ./migrations folder relative to Cargo.toml | ||||||
|   | |||||||
							
								
								
									
										279
									
								
								src/main.rs
									
									
									
									
									
								
							
							
						
						
									
										279
									
								
								src/main.rs
									
									
									
									
									
								
							| @@ -8,7 +8,7 @@ async fn main() { | |||||||
|  |  | ||||||
|     let app = init::app().await; |     let app = init::app().await; | ||||||
|  |  | ||||||
|     // run our app with hyper, listening globally on port 3000 |     // run our app with hyper, listening globally on port 8001 | ||||||
|     let url = config::get_full(); |     let url = config::get_full(); | ||||||
|     let listener = tokio::net::TcpListener::bind(url).await.unwrap(); |     let listener = tokio::net::TcpListener::bind(url).await.unwrap(); | ||||||
|     axum::serve(listener, app).await.unwrap(); |     axum::serve(listener, app).await.unwrap(); | ||||||
| @@ -19,8 +19,79 @@ mod init { | |||||||
|         Router, |         Router, | ||||||
|         routing::{get, post}, |         routing::{get, post}, | ||||||
|     }; |     }; | ||||||
|  |     use utoipa::OpenApi; | ||||||
|  |  | ||||||
|     use crate::callers; |     use crate::callers; | ||||||
|  |     use callers::common as common_callers; | ||||||
|  |     use callers::login as login_caller; | ||||||
|  |     use callers::register as register_caller; | ||||||
|  |     use login_caller::endpoint as login_endpoints; | ||||||
|  |     use login_caller::response as login_responses; | ||||||
|  |     use register_caller::response as register_responses; | ||||||
|  |  | ||||||
|  |     #[derive(utoipa::OpenApi)] | ||||||
|  |     #[openapi( | ||||||
|  |         paths( | ||||||
|  |             common_callers::endpoint::db_ping, common_callers::endpoint::root, | ||||||
|  |             register_caller::register_user, | ||||||
|  |             login_endpoints::login, login_endpoints::service_login, login_endpoints::refresh_token | ||||||
|  |             ), | ||||||
|  |         components(schemas(common_callers::response::TestResult, | ||||||
|  |                 register_responses::Response, | ||||||
|  |             login_responses::Response, login_responses::service_login::Response, login_responses::refresh_token::Response)), | ||||||
|  |         tags( | ||||||
|  |             (name = "Icarus Auth API", description = "Auth API for Icarus API") | ||||||
|  |             ) | ||||||
|  |     )] | ||||||
|  |     struct ApiDoc; | ||||||
|  |  | ||||||
|  |     mod cors { | ||||||
|  |         pub async fn configure_cors() -> tower_http::cors::CorsLayer { | ||||||
|  |             // Start building the CORS layer with common settings | ||||||
|  |             let cors = tower_http::cors::CorsLayer::new() | ||||||
|  |                 .allow_methods([ | ||||||
|  |                     axum::http::Method::GET, | ||||||
|  |                     axum::http::Method::POST, | ||||||
|  |                     axum::http::Method::PUT, | ||||||
|  |                     axum::http::Method::DELETE, | ||||||
|  |                 ]) // Specify allowed methods:cite[2] | ||||||
|  |                 .allow_headers([ | ||||||
|  |                     axum::http::header::CONTENT_TYPE, | ||||||
|  |                     axum::http::header::AUTHORIZATION, | ||||||
|  |                 ]) // Specify allowed headers:cite[2] | ||||||
|  |                 .allow_credentials(true) // If you need to send cookies or authentication headers:cite[2] | ||||||
|  |                 .max_age(std::time::Duration::from_secs(3600)); // Cache the preflight response for 1 hour:cite[2] | ||||||
|  |  | ||||||
|  |             // Dynamically set the allowed origin based on the environment | ||||||
|  |             match std::env::var(icarus_envy::keys::APP_ENV).as_deref() { | ||||||
|  |                 Ok("production") => { | ||||||
|  |                     let allowed_origins_env = icarus_envy::environment::get_allowed_origins().await; | ||||||
|  |                     match icarus_envy::utility::delimitize(&allowed_origins_env) { | ||||||
|  |                         Ok(alwd) => { | ||||||
|  |                             let allowed_origins: Vec<axum::http::HeaderValue> = alwd | ||||||
|  |                                 .into_iter() | ||||||
|  |                                 .map(|s| s.parse::<axum::http::HeaderValue>().unwrap()) | ||||||
|  |                                 .collect(); | ||||||
|  |                             cors.allow_origin(allowed_origins) | ||||||
|  |                         } | ||||||
|  |                         Err(err) => { | ||||||
|  |                             eprintln!( | ||||||
|  |                                 "Could not parse out allowed origins from env: Error: {err:?}" | ||||||
|  |                             ); | ||||||
|  |                             std::process::exit(-1); | ||||||
|  |                         } | ||||||
|  |                     } | ||||||
|  |                 } | ||||||
|  |                 _ => { | ||||||
|  |                     // Development (default): Allow localhost origins | ||||||
|  |                     cors.allow_origin(vec![ | ||||||
|  |                         "http://localhost:4200".parse().unwrap(), | ||||||
|  |                         "http://127.0.0.1:4200".parse().unwrap(), | ||||||
|  |                     ]) | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|     pub async fn routes() -> Router { |     pub async fn routes() -> Router { | ||||||
|         // build our application with a route |         // build our application with a route | ||||||
| @@ -41,6 +112,15 @@ mod init { | |||||||
|                 callers::endpoints::LOGIN, |                 callers::endpoints::LOGIN, | ||||||
|                 post(callers::login::endpoint::login), |                 post(callers::login::endpoint::login), | ||||||
|             ) |             ) | ||||||
|  |             .route( | ||||||
|  |                 callers::endpoints::SERVICE_LOGIN, | ||||||
|  |                 post(callers::login::endpoint::service_login), | ||||||
|  |             ) | ||||||
|  |             .route( | ||||||
|  |                 callers::endpoints::REFRESH_TOKEN, | ||||||
|  |                 post(callers::login::endpoint::refresh_token), | ||||||
|  |             ) | ||||||
|  |             .layer(cors::configure_cors().await) | ||||||
|     } |     } | ||||||
|  |  | ||||||
|     pub async fn app() -> Router { |     pub async fn app() -> Router { | ||||||
| @@ -50,7 +130,13 @@ mod init { | |||||||
|  |  | ||||||
|         icarus_auth::db::migrations(&pool).await; |         icarus_auth::db::migrations(&pool).await; | ||||||
|  |  | ||||||
|         routes().await.layer(axum::Extension(pool)) |         routes() | ||||||
|  |             .await | ||||||
|  |             .merge( | ||||||
|  |                 utoipa_swagger_ui::SwaggerUi::new("/swagger-ui") | ||||||
|  |                     .url("/api-docs/openapi.json", ApiDoc::openapi()), | ||||||
|  |             ) | ||||||
|  |             .layer(axum::Extension(pool)) | ||||||
|     } |     } | ||||||
| } | } | ||||||
|  |  | ||||||
| @@ -69,25 +155,23 @@ mod tests { | |||||||
|     mod db_mgr { |     mod db_mgr { | ||||||
|         use std::str::FromStr; |         use std::str::FromStr; | ||||||
|  |  | ||||||
|         use icarus_auth::keys; |  | ||||||
|  |  | ||||||
|         pub const LIMIT: usize = 6; |         pub const LIMIT: usize = 6; | ||||||
|  |  | ||||||
|         pub async fn get_pool() -> Result<sqlx::PgPool, sqlx::Error> { |         pub async fn get_pool() -> Result<sqlx::PgPool, sqlx::Error> { | ||||||
|             dotenvy::dotenv().ok(); // Load .env file if it exists |             let tm_db_url = icarus_envy::environment::get_db_url().await.value; | ||||||
|             let tm_db_url = std::env::var(keys::DBURL).expect("DATABASE_URL must be present"); |  | ||||||
|             let tm_options = sqlx::postgres::PgConnectOptions::from_str(&tm_db_url).unwrap(); |             let tm_options = sqlx::postgres::PgConnectOptions::from_str(&tm_db_url).unwrap(); | ||||||
|             sqlx::PgPool::connect_with(tm_options).await |             sqlx::PgPool::connect_with(tm_options).await | ||||||
|         } |         } | ||||||
|  |  | ||||||
|         pub async fn generate_db_name() -> String { |         pub async fn generate_db_name() -> String { | ||||||
|             let db_name = |             let db_name = get_database_name().await.unwrap() | ||||||
|                 get_database_name().unwrap() + &"_" + &uuid::Uuid::new_v4().to_string()[..LIMIT]; |                 + &"_" | ||||||
|  |                 + &uuid::Uuid::new_v4().to_string()[..LIMIT]; | ||||||
|             db_name |             db_name | ||||||
|         } |         } | ||||||
|  |  | ||||||
|         pub async fn connect_to_db(db_name: &str) -> Result<sqlx::PgPool, sqlx::Error> { |         pub async fn connect_to_db(db_name: &str) -> Result<sqlx::PgPool, sqlx::Error> { | ||||||
|             let db_url = std::env::var(keys::DBURL).expect("DATABASE_URL must be set for tests"); |             let db_url = icarus_envy::environment::get_db_url().await.value; | ||||||
|             let options = sqlx::postgres::PgConnectOptions::from_str(&db_url)?.database(db_name); |             let options = sqlx::postgres::PgConnectOptions::from_str(&db_url)?.database(db_name); | ||||||
|             sqlx::PgPool::connect_with(options).await |             sqlx::PgPool::connect_with(options).await | ||||||
|         } |         } | ||||||
| @@ -113,11 +197,9 @@ mod tests { | |||||||
|             Ok(()) |             Ok(()) | ||||||
|         } |         } | ||||||
|  |  | ||||||
|         pub fn get_database_name() -> Result<String, Box<dyn std::error::Error>> { |         pub async fn get_database_name() -> Result<String, Box<dyn std::error::Error>> { | ||||||
|             dotenvy::dotenv().ok(); // Load .env file if it exists |             let database_url = icarus_envy::environment::get_db_url().await.value; | ||||||
|  |  | ||||||
|             match std::env::var(keys::DBURL) { |  | ||||||
|                 Ok(database_url) => { |  | ||||||
|             let parsed_url = url::Url::parse(&database_url)?; |             let parsed_url = url::Url::parse(&database_url)?; | ||||||
|             if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" { |             if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" { | ||||||
|                 match parsed_url |                 match parsed_url | ||||||
| @@ -132,12 +214,6 @@ mod tests { | |||||||
|                 Err("Error parsing".into()) |                 Err("Error parsing".into()) | ||||||
|             } |             } | ||||||
|         } |         } | ||||||
|                 Err(_) => { |  | ||||||
|                     // DATABASE_URL environment variable not found |  | ||||||
|                     Err("Error parsing".into()) |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|         } |  | ||||||
|     } |     } | ||||||
|  |  | ||||||
|     fn get_test_register_request() -> icarus_auth::callers::register::request::Request { |     fn get_test_register_request() -> icarus_auth::callers::register::request::Request { | ||||||
| @@ -164,6 +240,25 @@ mod tests { | |||||||
|         }) |         }) | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     pub mod requests { | ||||||
|  |         use tower::ServiceExt; // for `call`, `oneshot`, and `ready` | ||||||
|  |  | ||||||
|  |         pub async fn register( | ||||||
|  |             app: &axum::Router, | ||||||
|  |             usr: &icarus_auth::callers::register::request::Request, | ||||||
|  |         ) -> Result<axum::response::Response, std::convert::Infallible> { | ||||||
|  |             let payload = super::get_test_register_payload(&usr); | ||||||
|  |             let req = axum::http::Request::builder() | ||||||
|  |                 .method(axum::http::Method::POST) | ||||||
|  |                 .uri(crate::callers::endpoints::REGISTER) | ||||||
|  |                 .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||||
|  |                 .body(axum::body::Body::from(payload.to_string())) | ||||||
|  |                 .unwrap(); | ||||||
|  |  | ||||||
|  |             app.clone().oneshot(req).await | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|     #[tokio::test] |     #[tokio::test] | ||||||
|     async fn test_hello_world() { |     async fn test_hello_world() { | ||||||
|         let app = init::app().await; |         let app = init::app().await; | ||||||
| @@ -208,18 +303,8 @@ mod tests { | |||||||
|         let app = init::routes().await.layer(axum::Extension(pool)); |         let app = init::routes().await.layer(axum::Extension(pool)); | ||||||
|  |  | ||||||
|         let usr = get_test_register_request(); |         let usr = get_test_register_request(); | ||||||
|         let payload = get_test_register_payload(&usr); |  | ||||||
|  |  | ||||||
|         let response = app |         let response = requests::register(&app, &usr).await; | ||||||
|             .oneshot( |  | ||||||
|                 Request::builder() |  | ||||||
|                     .method(axum::http::Method::POST) |  | ||||||
|                     .uri(callers::endpoints::REGISTER) |  | ||||||
|                     .header(axum::http::header::CONTENT_TYPE, "application/json") |  | ||||||
|                     .body(Body::from(payload.to_string())) |  | ||||||
|                     .unwrap(), |  | ||||||
|             ) |  | ||||||
|             .await; |  | ||||||
|  |  | ||||||
|         match response { |         match response { | ||||||
|             Ok(resp) => { |             Ok(resp) => { | ||||||
| @@ -275,19 +360,8 @@ mod tests { | |||||||
|         let app = init::routes().await.layer(axum::Extension(pool)); |         let app = init::routes().await.layer(axum::Extension(pool)); | ||||||
|  |  | ||||||
|         let usr = get_test_register_request(); |         let usr = get_test_register_request(); | ||||||
|         let payload = get_test_register_payload(&usr); |  | ||||||
|  |  | ||||||
|         let response = app |         let response = requests::register(&app, &usr).await; | ||||||
|             .clone() |  | ||||||
|             .oneshot( |  | ||||||
|                 Request::builder() |  | ||||||
|                     .method(axum::http::Method::POST) |  | ||||||
|                     .uri(callers::endpoints::REGISTER) |  | ||||||
|                     .header(axum::http::header::CONTENT_TYPE, "application/json") |  | ||||||
|                     .body(Body::from(payload.to_string())) |  | ||||||
|                     .unwrap(), |  | ||||||
|             ) |  | ||||||
|             .await; |  | ||||||
|  |  | ||||||
|         match response { |         match response { | ||||||
|             Ok(resp) => { |             Ok(resp) => { | ||||||
| @@ -351,4 +425,125 @@ mod tests { | |||||||
|  |  | ||||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; |         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     #[tokio::test] | ||||||
|  |     async fn test_service_login_user() { | ||||||
|  |         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||||
|  |  | ||||||
|  |         let db_name = db_mgr::generate_db_name().await; | ||||||
|  |  | ||||||
|  |         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||||
|  |             Ok(_) => { | ||||||
|  |                 println!("Success"); | ||||||
|  |             } | ||||||
|  |             Err(e) => { | ||||||
|  |                 assert!(false, "Error: {:?}", e.to_string()); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||||
|  |  | ||||||
|  |         icarus_auth::db::migrations(&pool).await; | ||||||
|  |  | ||||||
|  |         let app = init::routes().await.layer(axum::Extension(pool)); | ||||||
|  |         let passphrase = | ||||||
|  |             String::from("iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH"); | ||||||
|  |         let payload = serde_json::json!({ | ||||||
|  |             "passphrase": passphrase | ||||||
|  |         }); | ||||||
|  |  | ||||||
|  |         match app | ||||||
|  |             .oneshot( | ||||||
|  |                 Request::builder() | ||||||
|  |                     .method(axum::http::Method::POST) | ||||||
|  |                     .uri(callers::endpoints::SERVICE_LOGIN) | ||||||
|  |                     .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||||
|  |                     .body(Body::from(payload.to_string())) | ||||||
|  |                     .unwrap(), | ||||||
|  |             ) | ||||||
|  |             .await | ||||||
|  |         { | ||||||
|  |             Ok(response) => { | ||||||
|  |                 assert_eq!(StatusCode::OK, response.status(), "Status is not right"); | ||||||
|  |                 let body = axum::body::to_bytes(response.into_body(), usize::MAX) | ||||||
|  |                     .await | ||||||
|  |                     .unwrap(); | ||||||
|  |                 let parsed_body: callers::login::response::service_login::Response = | ||||||
|  |                     serde_json::from_slice(&body).unwrap(); | ||||||
|  |                 let _login_result = &parsed_body.data[0]; | ||||||
|  |             } | ||||||
|  |             Err(err) => { | ||||||
|  |                 assert!(false, "Error: {err:?}"); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     #[tokio::test] | ||||||
|  |     async fn test_refresh_token() { | ||||||
|  |         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||||
|  |  | ||||||
|  |         let db_name = db_mgr::generate_db_name().await; | ||||||
|  |  | ||||||
|  |         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||||
|  |             Ok(_) => { | ||||||
|  |                 println!("Success"); | ||||||
|  |             } | ||||||
|  |             Err(e) => { | ||||||
|  |                 assert!(false, "Error: {:?}", e.to_string()); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||||
|  |  | ||||||
|  |         icarus_auth::db::migrations(&pool).await; | ||||||
|  |  | ||||||
|  |         let app = init::routes().await.layer(axum::Extension(pool)); | ||||||
|  |         let id = uuid::Uuid::parse_str("22f9c775-cce9-457a-a147-9dafbb801f61").unwrap(); | ||||||
|  |         let key = icarus_envy::environment::get_secret_key().await.value; | ||||||
|  |  | ||||||
|  |         match icarus_auth::token_stuff::create_service_token(&key, &id) { | ||||||
|  |             Ok((token, _expire)) => { | ||||||
|  |                 let payload = serde_json::json!({ | ||||||
|  |                     "access_token": token | ||||||
|  |                 }); | ||||||
|  |  | ||||||
|  |                 match app | ||||||
|  |                     .oneshot( | ||||||
|  |                         Request::builder() | ||||||
|  |                             .method(axum::http::Method::POST) | ||||||
|  |                             .uri(callers::endpoints::REFRESH_TOKEN) | ||||||
|  |                             .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||||
|  |                             .body(Body::from(payload.to_string())) | ||||||
|  |                             .unwrap(), | ||||||
|  |                     ) | ||||||
|  |                     .await | ||||||
|  |                 { | ||||||
|  |                     Ok(response) => { | ||||||
|  |                         let body = axum::body::to_bytes(response.into_body(), usize::MAX) | ||||||
|  |                             .await | ||||||
|  |                             .unwrap(); | ||||||
|  |                         let parsed_body: callers::login::response::service_login::Response = | ||||||
|  |                             serde_json::from_slice(&body).unwrap(); | ||||||
|  |                         let login_result = &parsed_body.data[0]; | ||||||
|  |  | ||||||
|  |                         assert_eq!( | ||||||
|  |                             id, login_result.id, | ||||||
|  |                             "The Id from the response does not match {id:?} {:?}", | ||||||
|  |                             login_result.id | ||||||
|  |                         ); | ||||||
|  |                     } | ||||||
|  |                     Err(err) => { | ||||||
|  |                         assert!(false, "Error: {err:?}"); | ||||||
|  |                     } | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |             Err(err) => { | ||||||
|  |                 assert!(false, "Error: {err:?}"); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||||
|  |     } | ||||||
| } | } | ||||||
|   | |||||||
| @@ -57,7 +57,7 @@ pub mod user { | |||||||
|         .fetch_optional(pool) |         .fetch_optional(pool) | ||||||
|         .await |         .await | ||||||
|         .map_err(|e| { |         .map_err(|e| { | ||||||
|             eprintln!("Error updating time: {}", e); |             eprintln!("Error updating time: {e}"); | ||||||
|             e |             e | ||||||
|         }); |         }); | ||||||
|  |  | ||||||
| @@ -113,7 +113,7 @@ pub mod user { | |||||||
|         .fetch_one(pool) |         .fetch_one(pool) | ||||||
|         .await |         .await | ||||||
|         .map_err(|e| { |         .map_err(|e| { | ||||||
|             eprintln!("Error inserting item: {}", e); |             eprintln!("Error inserting item: {e}"); | ||||||
|             e |             e | ||||||
|         })?; |         })?; | ||||||
|  |  | ||||||
| @@ -180,7 +180,7 @@ pub mod salt { | |||||||
|         .fetch_one(pool) |         .fetch_one(pool) | ||||||
|         .await |         .await | ||||||
|         .map_err(|e| { |         .map_err(|e| { | ||||||
|             eprintln!("Error inserting item: {}", e); |             eprintln!("Error inserting item: {e}"); | ||||||
|             e |             e | ||||||
|         })?; |         })?; | ||||||
|  |  | ||||||
| @@ -195,3 +195,56 @@ pub mod salt { | |||||||
|         } |         } | ||||||
|     } |     } | ||||||
| } | } | ||||||
|  |  | ||||||
|  | pub mod service { | ||||||
|  |     use sqlx::Row; | ||||||
|  |  | ||||||
|  |     pub async fn valid_passphrase( | ||||||
|  |         pool: &sqlx::PgPool, | ||||||
|  |         passphrase: &String, | ||||||
|  |     ) -> Result<(uuid::Uuid, String, time::OffsetDateTime), sqlx::Error> { | ||||||
|  |         let result = sqlx::query( | ||||||
|  |             r#" | ||||||
|  |             SELECT * FROM "passphrase" WHERE passphrase = $1 | ||||||
|  |             "#, | ||||||
|  |         ) | ||||||
|  |         .bind(passphrase) | ||||||
|  |         .fetch_one(pool) | ||||||
|  |         .await; | ||||||
|  |  | ||||||
|  |         match result { | ||||||
|  |             Ok(row) => { | ||||||
|  |                 let id: uuid::Uuid = row.try_get("id")?; | ||||||
|  |                 let passphrase: String = row.try_get("passphrase")?; | ||||||
|  |                 let date_created: Option<time::OffsetDateTime> = row.try_get("date_created")?; | ||||||
|  |  | ||||||
|  |                 Ok((id, passphrase, date_created.unwrap())) | ||||||
|  |             } | ||||||
|  |             Err(err) => Err(err), | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     pub async fn get_passphrase( | ||||||
|  |         pool: &sqlx::PgPool, | ||||||
|  |         id: &uuid::Uuid, | ||||||
|  |     ) -> Result<(uuid::Uuid, String, time::OffsetDateTime), sqlx::Error> { | ||||||
|  |         let result = sqlx::query( | ||||||
|  |             r#" | ||||||
|  |             SELECT * FROM "passphrase" WHERE id = $1; | ||||||
|  |             "#, | ||||||
|  |         ) | ||||||
|  |         .bind(id) | ||||||
|  |         .fetch_one(pool) | ||||||
|  |         .await; | ||||||
|  |  | ||||||
|  |         match result { | ||||||
|  |             Ok(row) => { | ||||||
|  |                 let returned_id: uuid::Uuid = row.try_get("id")?; | ||||||
|  |                 let passphrase: String = row.try_get("passphrase")?; | ||||||
|  |                 let date_created: time::OffsetDateTime = row.try_get("date_created")?; | ||||||
|  |                 Ok((returned_id, passphrase, date_created)) | ||||||
|  |             } | ||||||
|  |             Err(err) => Err(err), | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  | } | ||||||
|   | |||||||
| @@ -1,23 +1,16 @@ | |||||||
| use josekit::{ | use josekit::{ | ||||||
|     self, |     self, | ||||||
|     jws::{JwsHeader, alg::hmac::HmacJwsAlgorithm::Hs256}, |     jws::alg::hmac::HmacJwsAlgorithm::Hs256, | ||||||
|     jwt::{self, JwtPayload}, |     jwt::{self}, | ||||||
| }; | }; | ||||||
|  |  | ||||||
| use time; | use time; | ||||||
|  |  | ||||||
| pub const TOKENTYPE: &str = "JWT"; |  | ||||||
| pub const KEY_ENV: &str = "SECRET_KEY"; | pub const KEY_ENV: &str = "SECRET_KEY"; | ||||||
| pub const MESSAGE: &str = "Something random"; | pub const MESSAGE: &str = "Something random"; | ||||||
| pub const ISSUER: &str = "icarus_auth"; | pub const ISSUER: &str = "icarus_auth"; | ||||||
| pub const AUDIENCE: &str = "icarus"; | pub const AUDIENCE: &str = "icarus"; | ||||||
|  |  | ||||||
| pub fn get_key() -> Result<String, dotenvy::Error> { |  | ||||||
|     dotenvy::dotenv().ok(); |  | ||||||
|     let key = std::env::var(KEY_ENV).expect("SECRET_KEY_NOT_FOUND"); |  | ||||||
|     Ok(key) |  | ||||||
| } |  | ||||||
|  |  | ||||||
| pub fn get_issued() -> time::Result<time::OffsetDateTime> { | pub fn get_issued() -> time::Result<time::OffsetDateTime> { | ||||||
|     Ok(time::OffsetDateTime::now_utc()) |     Ok(time::OffsetDateTime::now_utc()) | ||||||
| } | } | ||||||
| @@ -27,63 +20,115 @@ pub fn get_expiration(issued: &time::OffsetDateTime) -> Result<time::OffsetDateT | |||||||
|     Ok(*issued + duration_expire) |     Ok(*issued + duration_expire) | ||||||
| } | } | ||||||
|  |  | ||||||
| mod util { | pub fn create_token( | ||||||
|     pub fn time_to_std_time( |     provided_key: &String, | ||||||
|         provided_time: &time::OffsetDateTime, |     id: &uuid::Uuid, | ||||||
|     ) -> Result<std::time::SystemTime, std::time::SystemTimeError> { | ) -> Result<(String, i64), josekit::JoseError> { | ||||||
|         let converted = std::time::SystemTime::from(*provided_time); |     let resource = icarus_models::token::TokenResource { | ||||||
|         Ok(converted) |         message: String::from(MESSAGE), | ||||||
|     } |         issuer: String::from(ISSUER), | ||||||
|  |         audiences: vec![String::from(AUDIENCE)], | ||||||
|  |         id: *id, | ||||||
|  |     }; | ||||||
|  |     icarus_models::token::create_token(provided_key, &resource, time::Duration::hours(4)) | ||||||
| } | } | ||||||
|  |  | ||||||
| pub fn create_token(provided_key: &String) -> Result<(String, i64), josekit::JoseError> { | pub fn create_service_token( | ||||||
|     let mut header = JwsHeader::new(); |     provided: &String, | ||||||
|     header.set_token_type(TOKENTYPE); |     id: &uuid::Uuid, | ||||||
|  | ) -> Result<(String, i64), josekit::JoseError> { | ||||||
|     let mut payload = JwtPayload::new(); |     let resource = icarus_models::token::TokenResource { | ||||||
|     payload.set_subject(MESSAGE); |         message: String::from(SERVICE_SUBJECT), | ||||||
|     payload.set_issuer(ISSUER); |         issuer: String::from(ISSUER), | ||||||
|     payload.set_audience(vec![AUDIENCE]); |         audiences: vec![String::from(AUDIENCE)], | ||||||
|     match get_issued() { |         id: *id, | ||||||
|         Ok(issued) => { |  | ||||||
|             let expire = get_expiration(&issued).unwrap(); |  | ||||||
|             payload.set_issued_at(&util::time_to_std_time(&issued).unwrap()); |  | ||||||
|             payload.set_expires_at(&util::time_to_std_time(&expire).unwrap()); |  | ||||||
|  |  | ||||||
|             let key: String = if provided_key.is_empty() { |  | ||||||
|                 get_key().unwrap() |  | ||||||
|             } else { |  | ||||||
|                 provided_key.to_owned() |  | ||||||
|     }; |     }; | ||||||
|  |     icarus_models::token::create_token(provided, &resource, time::Duration::hours(1)) | ||||||
|  | } | ||||||
|  |  | ||||||
|             let signer = Hs256.signer_from_bytes(key.as_bytes()).unwrap(); | pub fn create_service_refresh_token( | ||||||
|             Ok(( |     key: &String, | ||||||
|                 josekit::jwt::encode_with_signer(&payload, &header, &signer).unwrap(), |     id: &uuid::Uuid, | ||||||
|                 (expire - time::OffsetDateTime::UNIX_EPOCH).whole_seconds(), | ) -> Result<(String, i64), josekit::JoseError> { | ||||||
|             )) |     let resource = icarus_models::token::TokenResource { | ||||||
|         } |         message: String::from(SERVICE_SUBJECT), | ||||||
|         Err(e) => Err(josekit::JoseError::InvalidClaim(e.into())), |         issuer: String::from(ISSUER), | ||||||
|     } |         audiences: vec![String::from(AUDIENCE)], | ||||||
|  |         id: *id, | ||||||
|  |     }; | ||||||
|  |     icarus_models::token::create_token(key, &resource, time::Duration::hours(4)) | ||||||
| } | } | ||||||
|  |  | ||||||
| pub fn verify_token(key: &String, token: &String) -> bool { | pub fn verify_token(key: &String, token: &String) -> bool { | ||||||
|     let ver = Hs256.verifier_from_bytes(key.as_bytes()).unwrap(); |     match get_payload(key, token) { | ||||||
|     let (payload, _header) = jwt::decode_with_verifier(token, &ver).unwrap(); |         Ok((payload, _header)) => match payload.subject() { | ||||||
|     match payload.subject() { |  | ||||||
|             Some(_sub) => true, |             Some(_sub) => true, | ||||||
|             None => false, |             None => false, | ||||||
|  |         }, | ||||||
|  |         Err(_err) => false, | ||||||
|     } |     } | ||||||
| } | } | ||||||
|  |  | ||||||
|  | pub fn extract_id_from_token(key: &String, token: &String) -> Result<uuid::Uuid, std::io::Error> { | ||||||
|  |     match get_payload(key, token) { | ||||||
|  |         Ok((payload, _header)) => match payload.claim("id") { | ||||||
|  |             Some(id) => match uuid::Uuid::parse_str(id.as_str().unwrap()) { | ||||||
|  |                 Ok(extracted) => Ok(extracted), | ||||||
|  |                 Err(err) => Err(std::io::Error::other(err.to_string())), | ||||||
|  |             }, | ||||||
|  |             None => Err(std::io::Error::other("No claim found")), | ||||||
|  |         }, | ||||||
|  |         Err(err) => Err(std::io::Error::other(err.to_string())), | ||||||
|  |     } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | pub const APP_TOKEN_TYPE: &str = "Icarus_App"; | ||||||
|  | pub const APP_SUBJECT: &str = "Something random"; | ||||||
|  | pub const SERVICE_TOKEN_TYPE: &str = "Icarus_Service"; | ||||||
|  | pub const SERVICE_SUBJECT: &str = "Service random"; | ||||||
|  |  | ||||||
|  | pub fn get_token_type(key: &String, token: &String) -> Result<String, std::io::Error> { | ||||||
|  |     match get_payload(key, token) { | ||||||
|  |         Ok((payload, _header)) => match payload.subject() { | ||||||
|  |             Some(subject) => { | ||||||
|  |                 if subject == APP_SUBJECT { | ||||||
|  |                     Ok(String::from(APP_TOKEN_TYPE)) | ||||||
|  |                 } else if subject == SERVICE_SUBJECT { | ||||||
|  |                     Ok(String::from(SERVICE_TOKEN_TYPE)) | ||||||
|  |                 } else { | ||||||
|  |                     Err(std::io::Error::other(String::from("Invalid subject"))) | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |             None => Err(std::io::Error::other(String::from("Invalid payload"))), | ||||||
|  |         }, | ||||||
|  |         Err(err) => Err(std::io::Error::other(err.to_string())), | ||||||
|  |     } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | pub fn is_token_type_valid(token_type: &String) -> bool { | ||||||
|  |     token_type == SERVICE_TOKEN_TYPE | ||||||
|  | } | ||||||
|  |  | ||||||
|  | fn get_payload( | ||||||
|  |     key: &String, | ||||||
|  |     token: &String, | ||||||
|  | ) -> Result<(josekit::jwt::JwtPayload, josekit::jws::JwsHeader), josekit::JoseError> { | ||||||
|  |     let ver = Hs256.verifier_from_bytes(key.as_bytes()).unwrap(); | ||||||
|  |     jwt::decode_with_verifier(token, &ver) | ||||||
|  | } | ||||||
|  |  | ||||||
| #[cfg(test)] | #[cfg(test)] | ||||||
| mod tests { | mod tests { | ||||||
|  |  | ||||||
|     use super::*; |     use super::*; | ||||||
|  |  | ||||||
|     #[test] |     #[test] | ||||||
|     fn test_tokenize() { |     fn test_tokenize() { | ||||||
|         let special_key = get_key().unwrap(); |         let rt = tokio::runtime::Runtime::new().unwrap(); | ||||||
|         match create_token(&special_key) { |         let special_key = rt | ||||||
|  |             .block_on(icarus_envy::environment::get_secret_key()) | ||||||
|  |             .value; | ||||||
|  |         let id = uuid::Uuid::new_v4(); | ||||||
|  |         match create_token(&special_key, &id) { | ||||||
|             Ok((token, _duration)) => { |             Ok((token, _duration)) => { | ||||||
|                 let result = verify_token(&special_key, &token); |                 let result = verify_token(&special_key, &token); | ||||||
|                 assert!(result, "Token not verified"); |                 assert!(result, "Token not verified"); | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user