mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-09-28 05:46:36 +08:00
c9fc9c0eea
Result: {"status":"keep","total_issues":8,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":8,"eslint_problems":0,"eslint_errors":0,"eslint_warnings":0,"tsc_errors":0,"measure_s":95,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_usetesting":0,"golint_test_total":0,"golint_exhaustive":0,"golint_vetx_total":0,"vitest_failed":0,"vitest_total":126}
58 lines
1.5 KiB
Go
58 lines
1.5 KiB
Go
// Copyright 2025 linux.do
|
|
// Copyright 2026 Arctel.net
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
|
|
package oauth
|
|
|
|
import (
|
|
"encoding/json"
|
|
"time"
|
|
)
|
|
|
|
// Session 用户信息字段 Key
|
|
const (
|
|
UserNameKey = "username"
|
|
UserIDKey = "user_id"
|
|
UserObjKey = "user_obj"
|
|
TokenAuthKey = "token_auth" // 标记当前请求是否通过 Access Token 鉴权
|
|
TokenAdminKey = "token_admin" // Access Token 本身是否具有管理员权限
|
|
SessionTokenKey = "oauth_session_token" //nolint:gosec // false positive: this is a session key, not hardcoded credentials
|
|
PasswordHashKey = "password_hash"
|
|
)
|
|
|
|
// OAuth State 缓存 Key 格式与过期时间
|
|
const (
|
|
OAuthStateCacheKeyFormat = "oauth:state:%s"
|
|
OAuthStateCacheKeyExpiration = 10 * time.Minute
|
|
oauthStateLimitKeyFormat = "oauth:state-limit:%s"
|
|
oauthStateLimitMax = 20
|
|
)
|
|
// OAuth 授权用途常量
|
|
const (
|
|
OAuthPurposeLogin = "login"
|
|
OAuthPurposeBind = "bind"
|
|
)
|
|
|
|
type oauthStatePayload struct {
|
|
SourceName string `json:"source_name"`
|
|
Purpose string `json:"purpose"`
|
|
UserID uint64 `json:"user_id,omitempty"`
|
|
SessionHash string `json:"session_hash"`
|
|
}
|
|
|
|
func encodeOAuthStatePayload(payload oauthStatePayload) (string, error) {
|
|
data, err := json.Marshal(payload)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
return string(data), nil
|
|
}
|
|
|
|
func decodeOAuthStatePayload(value string) (oauthStatePayload, error) {
|
|
var payload oauthStatePayload
|
|
if err := json.Unmarshal([]byte(value), &payload); err != nil {
|
|
return oauthStatePayload{}, err
|
|
}
|
|
return payload, nil
|
|
}
|