mirror of
https://github.com/Floriansylvain/RenewCMS.git
synced 2026-08-19 11:43:22 +02:00
First part of httpOnly JWT cookie implementation
This commit is contained in:
+15
-6
@@ -10,10 +10,12 @@ import (
|
||||
"github.com/joho/godotenv"
|
||||
)
|
||||
|
||||
var ginMode string
|
||||
var apiPort string
|
||||
var frontPort string
|
||||
var hostAddress string
|
||||
var (
|
||||
ginMode string
|
||||
apiPort string
|
||||
frontPort string
|
||||
hostAddress string
|
||||
)
|
||||
|
||||
func initEnvVariables() {
|
||||
if godotenv.Load() != nil {
|
||||
@@ -50,6 +52,12 @@ func corsMiddleware(c *gin.Context) {
|
||||
c.Next()
|
||||
}
|
||||
|
||||
func jwtProxyMiddleware(c *gin.Context) {
|
||||
jwtToken, _ := c.Cookie("jwt")
|
||||
c.Request.Header.Set("Authorization", fmt.Sprintf("Bearer %v", jwtToken))
|
||||
c.Next()
|
||||
}
|
||||
|
||||
func initArticlesRoutes(r *gin.Engine) {
|
||||
articlesRouter := r.Group("/articles")
|
||||
articlesRouter.Use(corsMiddleware, api.AuthMiddleware.MiddlewareFunc())
|
||||
@@ -63,10 +71,11 @@ func initArticlesRoutes(r *gin.Engine) {
|
||||
|
||||
func initGin() {
|
||||
r := gin.Default()
|
||||
r.Use(corsMiddleware)
|
||||
r.Use(jwtProxyMiddleware, corsMiddleware)
|
||||
|
||||
if ginMode == "release" {
|
||||
gin.SetMode(ginMode)
|
||||
api.AuthMiddleware.SecureCookie = true
|
||||
}
|
||||
|
||||
initBasicRoutes(r)
|
||||
@@ -77,6 +86,6 @@ func initGin() {
|
||||
|
||||
func main() {
|
||||
initEnvVariables()
|
||||
initJWT()
|
||||
initGin()
|
||||
initJWT()
|
||||
}
|
||||
|
||||
+18
-5
@@ -2,6 +2,7 @@ package api
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"net/http"
|
||||
"os"
|
||||
"time"
|
||||
|
||||
@@ -19,13 +20,25 @@ type User struct {
|
||||
var UsersLocation = database.Location{Database: "gohcms", Collection: "users"}
|
||||
|
||||
var AuthMiddleware, _ = jwt.New(&jwt.GinJWTMiddleware{
|
||||
Realm: "GohCMS",
|
||||
Key: []byte(os.Getenv("APP_JWT_SECRET")),
|
||||
Timeout: time.Hour,
|
||||
MaxRefresh: time.Hour,
|
||||
Authenticator: JWTAuthenticator,
|
||||
Realm: "GohCMS",
|
||||
Key: []byte(os.Getenv("APP_JWT_SECRET")),
|
||||
SendCookie: true,
|
||||
CookieHTTPOnly: true,
|
||||
CookieSameSite: http.SameSiteStrictMode,
|
||||
Timeout: time.Hour,
|
||||
MaxRefresh: time.Hour,
|
||||
LoginResponse: JWTLoginResponse,
|
||||
Authenticator: JWTAuthenticator,
|
||||
})
|
||||
|
||||
func JWTLoginResponse(c *gin.Context, code int, message string, expire time.Time) {
|
||||
if code == http.StatusOK {
|
||||
c.JSON(code, gin.H{"code": code, "message": "Successfully logged in!", "expire": expire.Format(time.RFC3339)})
|
||||
} else {
|
||||
c.JSON(code, gin.H{"code": code, "message": "Something wrong has happened."})
|
||||
}
|
||||
}
|
||||
|
||||
func JWTAuthenticator(c *gin.Context) (interface{}, error) {
|
||||
var user = User{}
|
||||
err := c.BindJSON(&user)
|
||||
|
||||
@@ -15,8 +15,8 @@ const baseURL = `http://${__APP_ENV__.APP_HOST_ADDRESS}:${__APP_ENV__.APP_API_PO
|
||||
|
||||
export async function getArticles(id: string) : Promise<Array<Article>> {
|
||||
return await fetch(`${baseURL}/articles/${id}`, {
|
||||
credentials: 'include',
|
||||
method: 'GET',
|
||||
headers: { "Authorization": `Bearer ${useAuthStore().token}` }
|
||||
})
|
||||
.then(result => result.json())
|
||||
.catch(error => {
|
||||
@@ -26,9 +26,9 @@ export async function getArticles(id: string) : Promise<Array<Article>> {
|
||||
|
||||
export async function postArticle(article: Article) : Promise<object> {
|
||||
return await fetch(`${baseURL}/articles/${article.titleID}`, {
|
||||
credentials: 'include',
|
||||
method: 'POST',
|
||||
headers: { "Authorization": `Bearer ${useAuthStore().token}` },
|
||||
body: JSON.stringify(article)
|
||||
body: JSON.stringify(article)
|
||||
})
|
||||
.then(result => result.json())
|
||||
.catch(error => {
|
||||
|
||||
@@ -19,11 +19,11 @@ function updateJWTcookies(JWTdata: jwtFormat): void {
|
||||
const cookieExpire = new Date(JWTdata.expire)
|
||||
cookieExpire.setDate(cookieExpire.getDate() + 1)
|
||||
|
||||
setCookie({
|
||||
key: 'JWTtoken',
|
||||
value: JWTdata.token,
|
||||
expire: cookieExpire.toString()
|
||||
})
|
||||
// setCookie({
|
||||
// key: 'JWTtoken',
|
||||
// value: JWTdata.token,
|
||||
// expire: cookieExpire.toString()
|
||||
// })
|
||||
setCookie({
|
||||
key: 'JWTexpire',
|
||||
value: JWTdata.expire,
|
||||
@@ -43,7 +43,7 @@ function jwtHandler(apiResponse: jwtFormat): void {
|
||||
}
|
||||
updateJWTcookies(apiResponse)
|
||||
disableErrors()
|
||||
authStore.token = apiResponse.token
|
||||
authStore.token = 'pouet'
|
||||
authStore.expire = apiResponse.expire
|
||||
isTokenOK.value = true
|
||||
}
|
||||
@@ -51,6 +51,7 @@ function jwtHandler(apiResponse: jwtFormat): void {
|
||||
function login(email: string, password: string): void {
|
||||
fetch(`http://${__APP_ENV__.APP_HOST_ADDRESS}:${__APP_ENV__.APP_API_PORT}/login/`, {
|
||||
method: "POST",
|
||||
credentials: 'include',
|
||||
body: JSON.stringify({
|
||||
email: email,
|
||||
password: password
|
||||
|
||||
Reference in New Issue
Block a user