2023-12-05 08:12:10 +01:00
|
|
|
import isNativeToken from "./common/is-native-token.js";
|
|
|
|
import type { CacheableLocalUser, ILocalUser } from "@/models/entities/user.js";
|
|
|
|
import { Users, AccessTokens, Apps } from "@/models/index.js";
|
2023-11-26 21:33:46 +01:00
|
|
|
import type { AccessToken } from "@/models/entities/access-token.js";
|
2023-12-05 08:12:10 +01:00
|
|
|
import { Cache } from "@/misc/cache.js";
|
2023-01-13 05:40:33 +01:00
|
|
|
import type { App } from "@/models/entities/app.js";
|
|
|
|
import {
|
|
|
|
localUserByIdCache,
|
|
|
|
localUserByNativeTokenCache,
|
|
|
|
} from "@/services/user-cache.js";
|
2022-03-25 08:27:41 +01:00
|
|
|
|
2023-07-03 04:10:33 +02:00
|
|
|
const appCache = new Cache<App>("app", 60 * 30);
|
2021-03-18 02:19:30 +01:00
|
|
|
|
2021-07-17 17:53:16 +02:00
|
|
|
export class AuthenticationError extends Error {
|
|
|
|
constructor(message: string) {
|
|
|
|
super(message);
|
2023-01-13 05:40:33 +01:00
|
|
|
this.name = "AuthenticationError";
|
2021-07-17 17:53:16 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-01-13 05:40:33 +01:00
|
|
|
export default async (
|
|
|
|
authorization: string | null | undefined,
|
|
|
|
bodyToken: string | null,
|
|
|
|
): Promise<
|
|
|
|
[CacheableLocalUser | null | undefined, AccessToken | null | undefined]
|
|
|
|
> => {
|
2022-07-18 17:41:08 +02:00
|
|
|
let token: string | null = null;
|
|
|
|
|
|
|
|
// check if there is an authorization header set
|
|
|
|
if (authorization != null) {
|
|
|
|
if (bodyToken != null) {
|
2023-01-13 05:40:33 +01:00
|
|
|
throw new AuthenticationError("using multiple authorization schemes");
|
2022-07-18 17:41:08 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// check if OAuth 2.0 Bearer tokens are being used
|
|
|
|
// Authorization schemes are case insensitive
|
2023-01-13 05:40:33 +01:00
|
|
|
if (authorization.substring(0, 7).toLowerCase() === "bearer ") {
|
2022-07-18 17:41:08 +02:00
|
|
|
token = authorization.substring(7);
|
|
|
|
} else {
|
2023-01-13 05:40:33 +01:00
|
|
|
throw new AuthenticationError("unsupported authentication scheme");
|
2022-07-18 17:41:08 +02:00
|
|
|
}
|
|
|
|
} else if (bodyToken != null) {
|
|
|
|
token = bodyToken;
|
|
|
|
} else {
|
2019-01-23 11:25:36 +01:00
|
|
|
return [null, null];
|
2017-01-05 17:28:16 +01:00
|
|
|
}
|
|
|
|
|
2017-01-06 03:07:42 +01:00
|
|
|
if (isNativeToken(token)) {
|
2023-01-13 05:40:33 +01:00
|
|
|
const user = await localUserByNativeTokenCache.fetch(
|
|
|
|
token,
|
|
|
|
() => Users.findOneBy({ token }) as Promise<ILocalUser | null>,
|
2023-07-03 04:10:33 +02:00
|
|
|
true,
|
2023-01-13 05:40:33 +01:00
|
|
|
);
|
2016-12-28 23:49:51 +01:00
|
|
|
|
2019-04-07 14:50:36 +02:00
|
|
|
if (user == null) {
|
2023-01-13 05:40:33 +01:00
|
|
|
throw new AuthenticationError("unknown token");
|
2016-12-28 23:49:51 +01:00
|
|
|
}
|
|
|
|
|
2019-01-23 11:25:36 +01:00
|
|
|
return [user, null];
|
2017-01-05 17:28:16 +01:00
|
|
|
} else {
|
2019-04-07 14:50:36 +02:00
|
|
|
const accessToken = await AccessTokens.findOne({
|
2023-01-13 05:40:33 +01:00
|
|
|
where: [
|
|
|
|
{
|
|
|
|
hash: token.toLowerCase(), // app
|
|
|
|
},
|
|
|
|
{
|
|
|
|
token: token, // miauth
|
|
|
|
},
|
|
|
|
],
|
2016-12-28 23:49:51 +01:00
|
|
|
});
|
|
|
|
|
2019-04-07 14:50:36 +02:00
|
|
|
if (accessToken == null) {
|
2023-01-13 05:40:33 +01:00
|
|
|
throw new AuthenticationError("unknown token");
|
2016-12-28 23:49:51 +01:00
|
|
|
}
|
|
|
|
|
2020-03-28 03:24:37 +01:00
|
|
|
AccessTokens.update(accessToken.id, {
|
|
|
|
lastUsedAt: new Date(),
|
|
|
|
});
|
2016-12-28 23:49:51 +01:00
|
|
|
|
2023-01-13 05:40:33 +01:00
|
|
|
const user = await localUserByIdCache.fetch(
|
|
|
|
accessToken.userId,
|
|
|
|
() =>
|
|
|
|
Users.findOneBy({
|
|
|
|
id: accessToken.userId,
|
|
|
|
}) as Promise<ILocalUser>,
|
2023-07-03 04:10:33 +02:00
|
|
|
true,
|
2023-01-13 05:40:33 +01:00
|
|
|
);
|
2016-12-28 23:49:51 +01:00
|
|
|
|
2020-03-28 03:24:37 +01:00
|
|
|
if (accessToken.appId) {
|
2023-07-03 04:10:33 +02:00
|
|
|
const app = await appCache.fetch(
|
|
|
|
accessToken.appId,
|
|
|
|
() => Apps.findOneByOrFail({ id: accessToken.appId! }),
|
|
|
|
true,
|
2023-01-13 05:40:33 +01:00
|
|
|
);
|
2020-03-28 03:24:37 +01:00
|
|
|
|
2023-01-13 05:40:33 +01:00
|
|
|
return [
|
|
|
|
user,
|
|
|
|
{
|
|
|
|
id: accessToken.id,
|
|
|
|
permission: app.permission,
|
|
|
|
} as AccessToken,
|
|
|
|
];
|
2020-03-28 03:24:37 +01:00
|
|
|
} else {
|
2020-03-28 10:07:41 +01:00
|
|
|
return [user, accessToken];
|
2020-03-28 03:24:37 +01:00
|
|
|
}
|
2016-12-28 23:49:51 +01:00
|
|
|
}
|
2019-01-23 11:25:36 +01:00
|
|
|
};
|