Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
AIOSEC-1 Protect auth-server with admin token (legacy style)
- Loading branch information
1 parent
cbe2073
commit ea7b2c4
Showing
7 changed files
with
93 additions
and
15 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,68 @@ | ||
const R = require('ramda'); | ||
const logger = require('../logger'); | ||
const JWT = require('jsonwebtoken'); | ||
|
||
const { JWTSECRET, JWTAUDIENCE } = process.env; | ||
|
||
const parseBearerToken = R.compose( | ||
R.ifElse( | ||
splits => | ||
R.length(splits) === 2 && | ||
R.compose( | ||
R.toLower, | ||
R.defaultTo(''), | ||
R.head, | ||
)(splits) === 'bearer', | ||
R.nth(1), | ||
R.always(null), | ||
), | ||
R.split(' '), | ||
R.defaultTo(''), | ||
); | ||
|
||
const validateToken = async ( | ||
req, | ||
res, | ||
next, | ||
) => { | ||
const token = parseBearerToken(req.get('Authorization')); | ||
|
||
if (token == null) { | ||
logger.debug('No Bearer Token'); | ||
return res | ||
.status(401) | ||
.send({ errors: [{ message: 'Unauthorized - Bearer Token Required' }] }); | ||
} | ||
|
||
try { | ||
decoded = JWT.verify(token, JWTSECRET); | ||
|
||
if (decoded == null) { | ||
throw new Error('Decoding token resulted in "null" or "undefined".'); | ||
} | ||
|
||
const { aud } = decoded; | ||
|
||
if (JWTAUDIENCE && aud !== JWTAUDIENCE) { | ||
logger.info(`Invalid token with aud attribute: "${aud || ''}"`); | ||
throw new Error('Token audience mismatch.'); | ||
} | ||
|
||
const { role = 'none' } = decoded; | ||
|
||
if (role !== 'admin') { | ||
throw new Error('Cannot authenticate non-admin user with legacy token.'); | ||
} | ||
|
||
next(); | ||
return; | ||
} catch (e) { | ||
return res.status(403).send({ | ||
errors: [{ message: `Forbidden - Invalid Auth Token: ${e.message}` }], | ||
}); | ||
} | ||
|
||
next(); | ||
}; | ||
|
||
module.exports = validateToken; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters