/
main.go
137 lines (119 loc) · 3.6 KB
/
main.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
package main
import (
"crypto/ed25519"
"crypto/x509"
"encoding/base64"
"encoding/json"
"encoding/pem"
"fmt"
"net/http"
"os"
"strings"
"time"
"github.com/gertcuykens/jwt"
)
type myHandler func(w http.ResponseWriter, r *http.Request)
func (h *myHandler) GET(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "text/plain; charset=UTF-8")
w.WriteHeader(http.StatusOK)
w.Write([]byte("OK"))
}
func newMyHandler(pk ed25519.PrivateKey) http.HandlerFunc {
var fn myHandler
fn = func(w http.ResponseWriter, r *http.Request) {
cookie, err := r.Cookie("Authorization")
if err != nil {
w.WriteHeader(http.StatusUnauthorized)
w.Write([]byte(err.Error()))
return
}
validator := []jwt.Validator{
jwt.ValidIssuer(r.Host),
jwt.ValidAudience([]string{"aud"}),
jwt.ValidNotBefore(time.Now()),
jwt.ValidIssuedAt(time.Now()),
jwt.ValidExpirationTime(time.Now()),
}
auth := jwt.Payload{
PublicKey: pk.Public().(ed25519.PublicKey),
Validator: validator,
}
err = auth.UnmarshalJSON([]byte(fmt.Sprintf(`"%s"`, cookie.Value)))
if err != nil {
w.WriteHeader(http.StatusUnauthorized)
w.Write([]byte(err.Error()))
return
}
switch {
case r.Method == http.MethodGet:
fn.GET(w, r)
default:
w.WriteHeader(http.StatusMethodNotAllowed)
w.Write([]byte("method not allowed"))
}
}
return http.HandlerFunc(fn)
}
func main() {
var pk ed25519.PrivateKey = func() ed25519.PrivateKey {
seed, err := base64.RawURLEncoding.DecodeString(os.Getenv("SEED"))
if err != nil {
panic(err)
}
return ed25519.NewKeyFromSeed(seed)
}()
x := http.NewServeMux()
x.Handle("/", newMyHandler(pk))
x.HandleFunc("/api/public", func(w http.ResponseWriter, r *http.Request) {
x509PublicKey, err := x509.MarshalPKIXPublicKey(pk.Public().(ed25519.PublicKey))
if err != nil {
w.WriteHeader(http.StatusInternalServerError)
w.Write([]byte(err.Error()))
return
}
w.Header().Set("Content-Type", "text/plain; charset=UTF-8")
w.WriteHeader(http.StatusOK)
w.Write(pem.EncodeToMemory(&pem.Block{Type: "PUBLIC KEY", Bytes: x509PublicKey}))
})
x.HandleFunc("/api/login", func(w http.ResponseWriter, r *http.Request) {
u, p, ok := r.BasicAuth()
if !ok || p != "admin" {
w.Header().Set("WWW-Authenticate", `Basic realm="`+r.Host+`"`)
http.Error(w, "unauthorized", http.StatusUnauthorized)
return
}
pl := jwt.Payload{
PrivateKey: pk,
Issuer: r.Host,
Audience: []string{"aud"},
ExpirationTime: jwt.NumericDate(time.Now().Add(1 * time.Hour)),
Subject: u,
}
v, err := json.Marshal(pl)
if err != nil {
w.WriteHeader(http.StatusBadRequest)
w.Write([]byte(err.Error()))
return
}
c := strings.Trim(string(v), `"`)
http.SetCookie(w, &http.Cookie{Path: "/", Name: "Authorization", Value: c, HttpOnly: true, SameSite: http.SameSiteStrictMode})
w.Header().Set("Content-Type", "text/plain; charset=UTF-8")
w.WriteHeader(http.StatusOK)
w.Write([]byte("OK"))
})
x.HandleFunc("/api/logout", func(w http.ResponseWriter, r *http.Request) {
http.SetCookie(w, &http.Cookie{Path: "/", Name: "Authorization", Value: "", HttpOnly: true, SameSite: http.SameSiteStrictMode, MaxAge: -1})
// w.Header().Set("Clear-Site-Data", `"cookies"`)
w.Header().Set("Content-Type", "text/plain; charset=UTF-8")
// w.Header().Set("Location", "/")
// w.WriteHeader(http.StatusSeeOther)
w.WriteHeader(http.StatusOK)
w.Write([]byte("OK"))
})
if err := http.ListenAndServeTLS(":8081", "tls/crt.pem", "tls/key.pem", x); err != nil {
panic(err)
}
// if err := http.ListenAndServe(":8081", x); err != nil {
// panic(err)
// }
}