-
Notifications
You must be signed in to change notification settings - Fork 27
/
generate.go
61 lines (47 loc) · 1.53 KB
/
generate.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
package secrets
import (
"crypto/rsa"
mathrand "math/rand"
"time"
"github.com/lestrrat-go/jwx/v2/jwk"
"github.com/authgear/authgear-server/pkg/util/jwkutil"
"github.com/authgear/authgear-server/pkg/util/rand"
"github.com/authgear/authgear-server/pkg/util/uuid"
)
// Alphabet is an alphabet for secret.
// Secret is not intended to be manually entered by human.
const Alphabet = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ_"
func GenerateSecret(length int, rng *mathrand.Rand) string {
return rand.StringWithAlphabet(length, Alphabet, rng)
}
func GenerateOctetKey(createdAt time.Time, rng *mathrand.Rand) jwk.Key {
key := []byte(GenerateSecret(32, rng))
jwkKey, err := jwk.FromRaw(key)
if err != nil {
panic(err)
}
_ = jwkKey.Set(jwk.KeyIDKey, uuid.New())
_ = jwkKey.Set(jwkutil.KeyCreatedAt, float64(createdAt.Unix()))
return jwkKey
}
func GenerateOctetKeyForSig(createdAt time.Time, rng *mathrand.Rand) jwk.Key {
jwkKey := GenerateOctetKey(createdAt, rng)
_ = jwkKey.Set(jwk.KeyUsageKey, jwk.ForSignature)
_ = jwkKey.Set(jwk.AlgorithmKey, "HS256")
return jwkKey
}
func GenerateRSAKey(createdAt time.Time, rng *mathrand.Rand) jwk.Key {
privateKey, err := rsa.GenerateKey(rng, 2048)
if err != nil {
panic(err)
}
jwkKey, err := jwk.FromRaw(privateKey)
if err != nil {
panic(err)
}
_ = jwkKey.Set(jwk.KeyIDKey, uuid.New())
_ = jwkKey.Set(jwk.KeyUsageKey, jwk.ForSignature)
_ = jwkKey.Set(jwkutil.KeyCreatedAt, float64(createdAt.Unix()))
_ = jwkKey.Set(jwk.AlgorithmKey, "RS256")
return jwkKey
}