-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathoauth.go
More file actions
104 lines (93 loc) · 2.55 KB
/
Copy pathoauth.go
File metadata and controls
104 lines (93 loc) · 2.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
// Package config manages local configuration and credential storage.
package config
import (
"encoding/json"
"errors"
"os"
"path/filepath"
"time"
)
const oauthFile = ".oauth"
// OAuthClientID is the pre-registered public OAuth client ID for the CreateOS CLI.
// Injected at build time via -ldflags="-X .../config.OAuthClientID=<id>"
var OAuthClientID = "fbcaaa58-1e30-43fe-8fba-34382ba4fe7f"
// OAuthIssuerURL is the OAuth identity server base URL
const OAuthIssuerURL = "https://id.nodeops.network"
// OAuthSession holds the OAuth tokens
type OAuthSession struct {
AccessToken string `json:"access_token"`
RefreshToken string `json:"refresh_token"`
ExpiresAt int64 `json:"expires_at"` // Unix timestamp
TokenEndpoint string `json:"token_endpoint"`
}
// oauthPath returns the path to ~/.createos/.oauth
func oauthPath() (string, error) {
dir, err := configPath()
if err != nil {
return "", err
}
return filepath.Join(dir, oauthFile), nil
}
// SaveOAuthSession writes the OAuth session to ~/.createos/.oauth
func SaveOAuthSession(session OAuthSession) error {
dir, err := configPath()
if err != nil {
return err
}
if err = os.MkdirAll(dir, 0700); err != nil {
return err
}
path, err := oauthPath()
if err != nil {
return err
}
data, err := json.Marshal(session) // #nosec G117 -- token serialization is the purpose of this function; file is stored with 0600
if err != nil {
return err
}
return os.WriteFile(path, data, 0600)
}
// LoadOAuthSession reads the OAuth session from ~/.createos/.oauth
func LoadOAuthSession() (*OAuthSession, error) {
path, err := oauthPath()
if err != nil {
return nil, err
}
data, err := os.ReadFile(path) // #nosec G304 -- path is from oauthPath() under ~/.createos/
if err != nil {
if errors.Is(err, os.ErrNotExist) {
return nil, nil
}
return nil, err
}
var session OAuthSession
if err := json.Unmarshal(data, &session); err != nil {
return nil, err
}
return &session, nil
}
// DeleteOAuthSession removes ~/.createos/.oauth
func DeleteOAuthSession() error {
path, err := oauthPath()
if err != nil {
return err
}
err = os.Remove(path)
if errors.Is(err, os.ErrNotExist) {
return nil
}
return err
}
// HasOAuthSession returns true if an OAuth session file exists
func HasOAuthSession() bool {
path, err := oauthPath()
if err != nil {
return false
}
_, err = os.Stat(path)
return err == nil
}
// IsTokenExpired returns true if the access token is expired or will expire within 60 seconds
func IsTokenExpired(session *OAuthSession) bool {
return time.Now().Unix() >= session.ExpiresAt-60
}