Encrypt cookies
This commit is contained in:
@@ -21,22 +21,40 @@ const tokenCookie = "uncensored_send_token"
|
||||
const rememberFor = 365 * 24 * time.Hour
|
||||
|
||||
// cookieCredential returns the remembered token, if any.
|
||||
func cookieCredential(r *http.Request) string {
|
||||
//
|
||||
// The cookie carries the token sealed, so this is also where an unreadable one
|
||||
// - another server's key, or the older plain format - quietly becomes "no
|
||||
// session" rather than a credential that cannot be resolved.
|
||||
func (s *Server) cookieCredential(r *http.Request) string {
|
||||
c, err := r.Cookie(tokenCookie)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
return strings.TrimSpace(c.Value)
|
||||
return s.sessions.open(strings.TrimSpace(c.Value))
|
||||
}
|
||||
|
||||
// staleSession reports a cookie that is present but will not open: sealed with
|
||||
// another server's key, or written in the plain-text format this replaced.
|
||||
// There is no session in it, and leaving it in the browser means sending a dead
|
||||
// credential on every request for a year, so the page treats it exactly as it
|
||||
// treats a revoked token: say so once, and clear it.
|
||||
func (s *Server) staleSession(r *http.Request) bool {
|
||||
c, err := r.Cookie(tokenCookie)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
value := strings.TrimSpace(c.Value)
|
||||
return value != "" && s.sessions.open(value) == ""
|
||||
}
|
||||
|
||||
// credential resolves the caller's token from an explicit header first, then
|
||||
// from the remembered cookie. Upload additionally accepts a form field, which
|
||||
// takes precedence over both.
|
||||
func credential(r *http.Request) string {
|
||||
func (s *Server) credential(r *http.Request) string {
|
||||
if t := bearer(r); t != "" {
|
||||
return t
|
||||
}
|
||||
return cookieCredential(r)
|
||||
return s.cookieCredential(r)
|
||||
}
|
||||
|
||||
// logIn stores the token in a cookie.
|
||||
@@ -48,10 +66,14 @@ func credential(r *http.Request) string {
|
||||
//
|
||||
// When persist is false the cookie carries no lifetime and the browser drops it
|
||||
// when it closes, which is the right default on a machine that is not yours.
|
||||
func (s *Server) logIn(w http.ResponseWriter, r *http.Request, token string, persist bool) {
|
||||
func (s *Server) logIn(w http.ResponseWriter, r *http.Request, token string, persist bool) error {
|
||||
sealed, err := s.sessions.seal(token)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
c := &http.Cookie{
|
||||
Name: tokenCookie,
|
||||
Value: token,
|
||||
Value: sealed,
|
||||
Path: s.cfg.BasePath,
|
||||
HttpOnly: true,
|
||||
Secure: s.isHTTPS(r),
|
||||
@@ -61,6 +83,7 @@ func (s *Server) logIn(w http.ResponseWriter, r *http.Request, token string, per
|
||||
c.MaxAge = int(rememberFor.Seconds())
|
||||
}
|
||||
http.SetCookie(w, c)
|
||||
return nil
|
||||
}
|
||||
|
||||
// forget clears a remembered token.
|
||||
|
||||
Reference in New Issue
Block a user