Comparison

plugins/mod_tokenauth.lua @ 10669:bf81523e2ff4

mod_authtokens: Rename to mod_tokenauth for consistency with mod_saslauth
author Matthew Wild <mwild1@gmail.com>
date Wed, 26 Feb 2020 22:46:15 +0000
parent 10668:plugins/mod_authtokens.lua@25c84c0a66fd
child 10674:4459afac4d13
comparison
equal deleted inserted replaced
10668:25c84c0a66fd 10669:bf81523e2ff4
1 local id = require "util.id";
2 local jid = require "util.jid";
3 local base64 = require "util.encodings".base64;
4
5 local token_store = module:open_store("auth_tokens", "map");
6
7 function create_jid_token(actor_jid, token_jid, token_scope, token_ttl)
8 token_jid = jid.prep(token_jid);
9 if not actor_jid or token_jid ~= actor_jid and not jid.compare(token_jid, actor_jid) then
10 return nil, "not-authorized";
11 end
12
13 local token_username, token_host, token_resource = jid.split(token_jid);
14
15 if token_host ~= module.host then
16 return nil, "invalid-host";
17 end
18
19 local token_info = {
20 owner = actor_jid;
21 expires = token_ttl and (os.time() + token_ttl) or nil;
22 jid = token_jid;
23 session = {
24 username = token_username;
25 host = token_host;
26 resource = token_resource;
27
28 auth_scope = token_scope;
29 };
30 };
31
32 local token_id = id.long();
33 local token = base64.encode("1;"..token_username.."@"..token_host..";"..token_id);
34 token_store:set(token_username, token_id, token_info);
35
36 return token, token_info;
37 end
38
39 local function parse_token(encoded_token)
40 local token = base64.decode(encoded_token);
41 if not token then return nil; end
42 local token_jid, token_id = token:match("^1;([^;]+);(.+)$");
43 if not token_jid then return nil; end
44 local token_user, token_host = jid.split(token_jid);
45 return token_id, token_user, token_host;
46 end
47
48 function get_token_info(token)
49 local token_id, token_user, token_host = parse_token(token);
50 if not token_id then
51 return nil, "invalid-token-format";
52 end
53 if token_host ~= module.host then
54 return nil, "invalid-host";
55 end
56
57 local token_info, err = token_store:get(token_user, token_id);
58 if not token_info then
59 if err then
60 return nil, "internal-error";
61 end
62 return nil, "not-authorized";
63 end
64
65 if token_info.expires and token_info.expires < os.time() then
66 return nil, "not-authorized";
67 end
68
69 return token_info
70 end
71
72 function revoke_token(token)
73 local token_id, token_user, token_host = parse_token(token);
74 if not token_id then
75 return nil, "invalid-token-format";
76 end
77 if token_host ~= module.host then
78 return nil, "invalid-host";
79 end
80 return token_store:set(token_user, token_id, nil);
81 end