-
Notifications
You must be signed in to change notification settings - Fork 161
/
token.go
84 lines (66 loc) · 2.13 KB
/
token.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
package uaa
import (
"encoding/base64"
"encoding/json"
"strings"
bosherr "github.com/cloudfoundry/bosh-utils/errors"
)
type AccessTokenImpl struct {
type_ string
accessValue string
}
var _ AccessToken = &AccessTokenImpl{}
func (t AccessTokenImpl) Type() string { return t.type_ }
func (t AccessTokenImpl) Value() string { return t.accessValue }
func (t AccessTokenImpl) IsValid() bool { return t.type_ != "" && t.accessValue != "" }
type RefreshableAccessTokenImpl struct {
accessToken AccessToken
refreshValue string
}
var _ RefreshableAccessToken = &RefreshableAccessTokenImpl{}
func (t RefreshableAccessTokenImpl) Type() string { return t.accessToken.Type() }
func (t RefreshableAccessTokenImpl) Value() string { return t.accessToken.Value() }
func (t RefreshableAccessTokenImpl) IsValid() bool { return t.accessToken.IsValid() }
func (t RefreshableAccessTokenImpl) RefreshValue() string {
return t.refreshValue
}
type TokenInfo struct {
Username string `json:"user_name"` // e.g. "admin",
Scopes []string `json:"scope"` // e.g. ["openid","bosh.admin"]
ExpiredAt int `json:"exp"`
// ...snip...
}
func NewTokenInfoFromValue(value string) (TokenInfo, error) {
var info TokenInfo
segments := strings.Split(value, ".")
if len(segments) != 3 {
return info, bosherr.Error("Expected token value to have 3 segments")
}
bytes, err := base64.RawURLEncoding.DecodeString(segments[1])
if err != nil {
return info, bosherr.WrapError(err, "Decoding token info")
}
err = json.Unmarshal(bytes, &info)
if err != nil {
return info, bosherr.WrapError(err, "Unmarshaling token info")
}
return info, nil
}
func NewAccessToken(accessValueType, accessValue string) AccessToken {
return AccessTokenImpl{
type_: accessValueType,
accessValue: accessValue,
}
}
func NewRefreshableAccessToken(accessValueType, accessValue, refreshValue string) RefreshableAccessToken {
if len(refreshValue) == 0 {
panic("Expected non-empty refresh token value")
}
return &RefreshableAccessTokenImpl{
accessToken: AccessTokenImpl{
type_: accessValueType,
accessValue: accessValue,
},
refreshValue: refreshValue,
}
}