Add custom token support
This commit is contained in:
@@ -133,13 +133,22 @@ var errBadToken = errors.New("unrecognised token")
|
||||
|
||||
// limitsFor resolves the effective permissions for a presented secret. An empty
|
||||
// secret yields the anonymous tier.
|
||||
func (s *Server) limitsFor(secret string) (auth.Limits, error) {
|
||||
//
|
||||
// Verifying a chosen passphrase costs a deliberately slow key derivation, which
|
||||
// makes an unverified credential an amplifier: a few requests a second carrying
|
||||
// junk would keep a core busy. So a request that would need that work has to
|
||||
// pay for it out of the same budget as a failed login. The result is memoised,
|
||||
// so a real session derives once and every later request is a map lookup.
|
||||
func (s *Server) limitsFor(r *http.Request, secret string) (auth.Limits, error) {
|
||||
if secret == "" {
|
||||
return auth.Anonymous(s.cfg), nil
|
||||
}
|
||||
if err := s.tokens.MaybeReload(); err != nil {
|
||||
s.log.Error("reloading token file", "err", err)
|
||||
}
|
||||
if !s.tokens.Resolved(secret) && !s.authLimiter.allow(clientIP(r, s.cfg), s.now()) {
|
||||
return auth.Limits{}, errBadToken
|
||||
}
|
||||
t := s.tokens.Lookup(secret)
|
||||
if t == nil {
|
||||
return auth.Limits{}, errBadToken
|
||||
@@ -193,7 +202,7 @@ type page struct {
|
||||
// who is logged in and offer only the links they can use.
|
||||
func (s *Server) page(r *http.Request, title string, script bool) page {
|
||||
p := page{Base: s.cfg.BasePath, Title: title, Script: script}
|
||||
if lim, err := s.limitsFor(cookieCredential(r)); err == nil {
|
||||
if lim, err := s.limitsFor(r, cookieCredential(r)); err == nil {
|
||||
p.User, p.Admin = lim.Name, lim.Admin
|
||||
}
|
||||
return p
|
||||
|
||||
Reference in New Issue
Block a user