mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-04 07:06:36 +08:00
895788974c
Bind OAuth state payloads to the initiating session token and user ID. Verifies session token hash continuity during callback, and validates that the user ID completing the binding flow matches the user ID that initiated it.
61 lines
1.7 KiB
Go
61 lines
1.7 KiB
Go
// Copyright 2025 linux.do
|
|
// Copyright 2026 Arctel.net
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
|
|
package oauth
|
|
|
|
import (
|
|
"encoding/json"
|
|
"time"
|
|
)
|
|
|
|
// Session 用户信息字段 Key
|
|
const (
|
|
UserNameKey = "username"
|
|
UserIDKey = "user_id"
|
|
UserObjKey = "user_obj"
|
|
TokenAuthKey = "token_auth" // 标记当前请求是否通过 Access Token 鉴权
|
|
TokenAdminKey = "token_admin" // Access Token 本身是否具有管理员权限
|
|
PendingOAuthSourceIDKey = "pending_oauth_source_id"
|
|
PendingOAuthExternalIDKey = "pending_oauth_external_id"
|
|
PendingOAuthExternalUsernameKey = "pending_oauth_external_username"
|
|
PendingOAuthEmailKey = "pending_oauth_email"
|
|
SessionTokenKey = "oauth_session_token" //nolint:gosec // false positive: this is a session key, not hardcoded credentials
|
|
)
|
|
|
|
// OAuth State 缓存 Key 格式与过期时间
|
|
const (
|
|
OAuthStateCacheKeyFormat = "oauth:state:%s"
|
|
OAuthStateCacheKeyExpiration = 10 * time.Minute
|
|
)
|
|
|
|
// OAuth 授权用途常量
|
|
const (
|
|
OAuthPurposeLogin = "login"
|
|
OAuthPurposeBind = "bind"
|
|
)
|
|
|
|
type oauthStatePayload struct {
|
|
SourceName string `json:"source_name"`
|
|
Purpose string `json:"purpose"`
|
|
UserID uint64 `json:"user_id,omitempty"`
|
|
SessionHash string `json:"session_hash"`
|
|
}
|
|
|
|
func encodeOAuthStatePayload(payload oauthStatePayload) (string, error) {
|
|
data, err := json.Marshal(payload)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
return string(data), nil
|
|
}
|
|
|
|
func decodeOAuthStatePayload(value string) (oauthStatePayload, error) {
|
|
var payload oauthStatePayload
|
|
if err := json.Unmarshal([]byte(value), &payload); err != nil {
|
|
return oauthStatePayload{}, err
|
|
}
|
|
return payload, nil
|
|
}
|
|
|