From b202c12caa4492a93ce87aaf38640ce634bed7ef Mon Sep 17 00:00:00 2001 From: rachel-mp4 Date: Sun, 17 Aug 2025 21:49:53 -0400 Subject: [PATCH] idk update to use new indigo/oauth --- migrations/003_newoauth.down.sql | 28 +++ migrations/003_newoauth.up.sql | 28 +++ server/cmd/main.go | 9 +- server/crypto/main.go | 15 ++ server/go.mod | 41 +--- server/go.sum | 167 +------------ server/internal/db/oauth.go | 232 +++++++++--------- server/internal/handler/lrcHandlers.go | 4 +- server/internal/handler/oauthHandlers.go | 135 ++-------- server/internal/handler/xcvrHandlers.go | 9 +- server/internal/oauth/clientmapper.go | 98 -------- server/internal/oauth/jwks.go | 20 +- server/internal/oauth/oauthclient.go | 187 ++++++-------- server/internal/oauth/service.go | 173 ++----------- server/internal/recordmanager/beep.go | 14 +- server/internal/recordmanager/channel.go | 15 +- server/internal/recordmanager/message.go | 15 +- server/internal/recordmanager/profile.go | 38 +-- .../internal/recordmanager/recordmanager.go | 52 +--- server/internal/recordmanager/session.go | 10 +- 20 files changed, 382 insertions(+), 908 deletions(-) create mode 100644 migrations/003_newoauth.down.sql create mode 100644 migrations/003_newoauth.up.sql create mode 100644 server/crypto/main.go delete mode 100644 server/internal/oauth/clientmapper.go diff --git a/migrations/003_newoauth.down.sql b/migrations/003_newoauth.down.sql new file mode 100644 index 0000000..279701f --- /dev/null +++ b/migrations/003_newoauth.down.sql @@ -0,0 +1,28 @@ +DROP TABLE IF EXISTS sessions; +DROP TABLE IF EXISTS requests; + +CREATE TABLE oauthrequests ( + id SERIAL PRIMARY KEY, + authserver_iss TEXT, + state TEXT, + did TEXT, + pds_url TEXT, + pkce_verifier TEXT, + dpop_auth_server_nonce TEXT, + dpop_private_jwk TEXT +); + +CREATE TABLE oauthsessions ( + id SERIAL PRIMARY KEY, + authserver_iss TEXT, + state TEXT, + did TEXT, + pds_url TEXT, + pkce_verifier TEXT, + dpop_auth_server_nonce TEXT, + dpop_private_jwk TEXT, + dpop_pds_nonce TEXT, + access_token TEXT, + refresh_token TEXT, + expiration TIMESTAMPTZ +); diff --git a/migrations/003_newoauth.up.sql b/migrations/003_newoauth.up.sql new file mode 100644 index 0000000..36a4ed8 --- /dev/null +++ b/migrations/003_newoauth.up.sql @@ -0,0 +1,28 @@ +DROP TABLE IF EXISTS oauthsessions; +DROP TABLE IF EXISTS oauthrequests; + +CREATE TABLE requests ( + state TEXT PRIMARY KEY, + authserver_url TEXT NOT NULL, + account_did TEXT, + scopes TEXT NOT NULL, + request_uri TEXT NOT NULL, + authserver_token_endpoint TEXT NOT NULL, + pkce_verifier TEXT NOT NULL, + dpop_authserver_nonce TEXT NOT NULL, + dpop_privatekey_multibase TEXT NOT NULL +); + +CREATE TABLE sessions ( + session_id TEXT NOT NULL PRIMARY KEY, + account_did TEXT NOT NULL, + host_url TEXT NOT NULL, + authserver_url TEXT NOT NULL, + authserver_token_endpoint TEXT NOT NULL, + scopes TEXT NOT NULL, + access_token TEXT NOT NULL, + refresh_token TEXT NOT NULL, + dpop_authserver_nonce TEXT NOT NULL, + dpop_host_nonce TEXT NOT NULL, + dpop_privatekey_multibase TEXT NOT NULL +) diff --git a/server/cmd/main.go b/server/cmd/main.go index b2ef1f8..353abd4 100644 --- a/server/cmd/main.go +++ b/server/cmd/main.go @@ -13,7 +13,6 @@ import ( "rvcx/internal/model" "rvcx/internal/oauth" "rvcx/internal/recordmanager" - "time" "github.com/joho/godotenv" ) @@ -45,13 +44,7 @@ func main() { if err != nil { panic(err) } - httpclient := &http.Client{ - Timeout: 5 * time.Second, - Transport: &http.Transport{ - IdleConnTimeout: 90 * time.Second, - }, - } - oauthclient, err := oauth.NewService(httpclient) + oauthclient, err := oauth.NewService(*store) if err != nil { logger.Println(err.Error()) panic(err) diff --git a/server/crypto/main.go b/server/crypto/main.go new file mode 100644 index 0000000..85a4999 --- /dev/null +++ b/server/crypto/main.go @@ -0,0 +1,15 @@ +package main + +import ( + "fmt" + "github.com/bluesky-social/indigo/atproto/crypto" +) + +func main() { + privateKey, err := crypto.GeneratePrivateKeyK256() + if err != nil { + panic(err) + } + clientSecretKey := privateKey.Multibase() + fmt.Println(clientSecretKey) +} diff --git a/server/go.mod b/server/go.mod index 886f8d7..d8143a2 100644 --- a/server/go.mod +++ b/server/go.mod @@ -3,15 +3,13 @@ module rvcx go 1.24.2 require ( - github.com/bluesky-social/indigo v0.0.0-20250616202859-d4516ea1d6cf + github.com/bluesky-social/indigo v0.0.0-20250813051257-8be102876fb7 github.com/bluesky-social/jetstream v0.0.0-20250414024304-d17bd81a945e github.com/gorilla/sessions v1.4.0 github.com/gorilla/websocket v1.5.3 - github.com/haileyok/atproto-oauth-golang v0.0.2 github.com/ipfs/go-cid v0.4.1 github.com/jackc/pgx/v5 v5.7.4 github.com/joho/godotenv v1.5.1 - github.com/lestrrat-go/jwx/v2 v2.0.12 github.com/rachel-mp4/lrcd v0.0.0-20250731224514-2f8d47fe368c github.com/rachel-mp4/lrcproto v0.0.0-20250720164211-c6162669b709 github.com/rivo/uniseg v0.4.7 @@ -23,42 +21,17 @@ require ( github.com/beorn7/perks v1.0.1 // indirect github.com/carlmjohnson/versioninfo v0.22.5 // indirect github.com/cespare/xxhash/v2 v2.3.0 // indirect - github.com/decred/dcrd/dcrec/secp256k1/v4 v4.2.0 // indirect - github.com/felixge/httpsnoop v1.0.4 // indirect - github.com/go-logr/logr v1.4.2 // indirect - github.com/go-logr/stdr v1.2.2 // indirect + github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect github.com/goccy/go-json v0.10.2 // indirect - github.com/gogo/protobuf v1.3.2 // indirect github.com/golang-jwt/jwt/v5 v5.2.2 // indirect - github.com/google/uuid v1.6.0 // indirect + github.com/google/go-querystring v1.1.0 // indirect github.com/gorilla/securecookie v1.1.2 // indirect - github.com/hashicorp/go-cleanhttp v0.5.2 // indirect - github.com/hashicorp/go-retryablehttp v0.7.5 // indirect - github.com/hashicorp/golang-lru v1.0.2 // indirect github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect - github.com/ipfs/bbloom v0.0.4 // indirect - github.com/ipfs/go-block-format v0.2.0 // indirect - github.com/ipfs/go-datastore v0.6.0 // indirect - github.com/ipfs/go-ipfs-blockstore v1.3.1 // indirect - github.com/ipfs/go-ipfs-ds-help v1.1.1 // indirect - github.com/ipfs/go-ipfs-util v0.0.3 // indirect - github.com/ipfs/go-ipld-cbor v0.1.0 // indirect - github.com/ipfs/go-ipld-format v0.6.0 // indirect - github.com/ipfs/go-log v1.0.5 // indirect - github.com/ipfs/go-log/v2 v2.5.1 // indirect - github.com/ipfs/go-metrics-interface v0.0.1 // indirect github.com/jackc/pgpassfile v1.0.0 // indirect github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect github.com/jackc/puddle/v2 v2.2.2 // indirect - github.com/jbenet/goprocess v0.1.4 // indirect github.com/klauspost/compress v1.17.9 // indirect github.com/klauspost/cpuid/v2 v2.2.7 // indirect - github.com/lestrrat-go/blackmagic v1.0.2 // indirect - github.com/lestrrat-go/httpcc v1.0.1 // indirect - github.com/lestrrat-go/httprc v1.0.4 // indirect - github.com/lestrrat-go/iter v1.0.2 // indirect - github.com/lestrrat-go/option v1.0.1 // indirect - github.com/mattn/go-isatty v0.0.20 // indirect github.com/minio/sha256-simd v1.0.1 // indirect github.com/mr-tron/base58 v1.2.0 // indirect github.com/multiformats/go-base32 v0.1.0 // indirect @@ -66,23 +39,19 @@ require ( github.com/multiformats/go-multibase v0.2.0 // indirect github.com/multiformats/go-multihash v0.2.3 // indirect github.com/multiformats/go-varint v0.0.7 // indirect - github.com/opentracing/opentracing-go v1.2.0 // indirect - github.com/polydawn/refmt v0.89.1-0.20221221234430-40501e09de1f // indirect + github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect github.com/prometheus/client_golang v1.19.1 // indirect github.com/prometheus/client_model v0.6.1 // indirect github.com/prometheus/common v0.54.0 // indirect github.com/prometheus/procfs v0.15.1 // indirect - github.com/segmentio/asm v1.2.0 // indirect github.com/spaolacci/murmur3 v1.1.0 // indirect + github.com/stretchr/testify v1.10.0 // indirect gitlab.com/yawning/secp256k1-voi v0.0.0-20230925100816-f2616030848b // indirect gitlab.com/yawning/tuplehash v0.0.0-20230713102510-df83abbf9a02 // indirect - go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.46.1 // indirect go.opentelemetry.io/otel v1.29.0 // indirect go.opentelemetry.io/otel/metric v1.29.0 // indirect go.opentelemetry.io/otel/trace v1.29.0 // indirect go.uber.org/atomic v1.11.0 // indirect - go.uber.org/multierr v1.11.0 // indirect - go.uber.org/zap v1.26.0 // indirect golang.org/x/crypto v0.31.0 // indirect golang.org/x/sync v0.10.0 // indirect golang.org/x/sys v0.28.0 // indirect diff --git a/server/go.sum b/server/go.sum index 27eda41..7e8647a 100644 --- a/server/go.sum +++ b/server/go.sum @@ -1,46 +1,37 @@ -github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU= -github.com/benbjohnson/clock v1.1.0/go.mod h1:J11/hYXuz8f4ySSvYwY0FKfm+ezbsZBKZxNJlLklBHA= github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM= github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw= -github.com/bluesky-social/indigo v0.0.0-20250616202859-d4516ea1d6cf h1:LFlwtY9r95lAI1yYKolCLTQnwK5VjgWO87mNsKdj3Qs= -github.com/bluesky-social/indigo v0.0.0-20250616202859-d4516ea1d6cf/go.mod h1:8FlFpF5cIq3DQG0kEHqyTkPV/5MDQoaWLcVwza5ZPJU= +github.com/bluesky-social/indigo v0.0.0-20250813051257-8be102876fb7 h1:FyoGfQFw/cTkDHdUTIYIHxfyUDgRS12K4o1mYC3ovRs= +github.com/bluesky-social/indigo v0.0.0-20250813051257-8be102876fb7/go.mod h1:n6QE1NDPFoi7PRbMUZmc2y7FibCqiVU4ePpsvhHUBR8= github.com/bluesky-social/jetstream v0.0.0-20250414024304-d17bd81a945e h1:P/O6TDHs53gwgV845uDHI+Nri889ixksRrh4bCkCdxo= github.com/bluesky-social/jetstream v0.0.0-20250414024304-d17bd81a945e/go.mod h1:WiYEeyJSdUwqoaZ71KJSpTblemUCpwJfh5oVXplK6T4= github.com/carlmjohnson/versioninfo v0.22.5 h1:O00sjOLUAFxYQjlN/bzYTuZiS0y6fWDQjMRvwtKgwwc= github.com/carlmjohnson/versioninfo v0.22.5/go.mod h1:QT9mph3wcVfISUKd0i9sZfVrPviHuSF+cUtLjm2WSf8= github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs= github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs= -github.com/cpuguy83/go-md2man/v2 v2.0.0-20190314233015-f79a8a8ca69d/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU= github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= -github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM= github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= -github.com/decred/dcrd/crypto/blake256 v1.0.1/go.mod h1:2OfgNZ5wDpcsFmHmCK5gZTPcCXqlm2ArzUIkw9czNJo= -github.com/decred/dcrd/dcrec/secp256k1/v4 v4.2.0 h1:8UrgZ3GkP4i/CLijOJx79Yu+etlyjdBU4sfcs2WYQMs= -github.com/decred/dcrd/dcrec/secp256k1/v4 v4.2.0/go.mod h1:v57UDF4pDQJcEfFUCRop3lJL149eHGSe9Jvczhzjo/0= github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg= github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U= -github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A= github.com/go-logr/logr v1.4.2 h1:6pFjapn8bFcIbiKo3XT4j/BhANplGihG6tvd+8rYgrY= github.com/go-logr/logr v1.4.2/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag= github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE= -github.com/go-yaml/yaml v2.1.0+incompatible/go.mod h1:w2MrLa16VYP0jy6N7M5kHaCkaLENm+P+Tv+MfurjSw0= github.com/goccy/go-json v0.10.2 h1:CrxCmQqYDkv1z7lO7Wbh2HN93uovUHgrECaO5ZrCXAU= github.com/goccy/go-json v0.10.2/go.mod h1:6MelG93GURQebXPDq3khkgXZkazVtN9CRI+MGFi0w8I= github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q= github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q= github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8= github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk= +github.com/google/go-cmp v0.5.2/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI= github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= +github.com/google/go-querystring v1.1.0 h1:AnCroh3fv4ZBgVIf1Iwtovgjaw/GiKJo8M8yD/fhyJ8= +github.com/google/go-querystring v1.1.0/go.mod h1:Kcdr2DB4koayq7X8pmAG4sNG59So17icRSOU623lUBU= github.com/google/gofuzz v1.2.0 h1:xRy4A+RhZaiKjJ1bPfwQ8sedCA+YS2YcCHW6ec7JMi0= github.com/google/gofuzz v1.2.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= -github.com/google/renameio v0.1.0/go.mod h1:KWCgfxg9yswjAJkECMjeO8J8rahYeXnNhOm40UhjYkI= github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= -github.com/gopherjs/gopherjs v0.0.0-20181017120253-0766667cb4d1 h1:EGx4pi6eqNxGaHF6qqu48+N2wcFQ5qg5FXgOdqsJ5d8= -github.com/gopherjs/gopherjs v0.0.0-20181017120253-0766667cb4d1/go.mod h1:wJfORRmW1u3UXTncJ5qlYoELFm8eSnnEO6hX4iZ3EWY= github.com/gorilla/securecookie v1.1.2 h1:YCIWL56dvtr73r6715mJs5ZvhtnY73hBvEF8kXD8ePA= github.com/gorilla/securecookie v1.1.2/go.mod h1:NfCASbcHqRSY+3a8tlWJwsQap2VX5pwzwo4h3eOamfo= github.com/gorilla/sessions v1.4.0 h1:kpIYOp/oi6MG/p5PgxApU8srsSw9tuFbt46Lt7auzqQ= @@ -49,8 +40,6 @@ github.com/gorilla/websocket v1.5.3 h1:saDtZ6Pbx/0u+bgYQ3q96pZgCzfhKXGPqt7kZ72aN github.com/gorilla/websocket v1.5.3/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/adAjf1fMHhE= github.com/hashicorp/go-cleanhttp v0.5.2 h1:035FKYIWjmULyFRBKPs8TBQoi0x6d9G4xc9neXJWAZQ= github.com/hashicorp/go-cleanhttp v0.5.2/go.mod h1:kO/YDlP8L1346E6Sodw+PrpBSV4/SoxCXGY6BqNFT48= -github.com/hashicorp/go-hclog v0.9.2 h1:CG6TE5H9/JXsFWJCfoIVpKFIkFe6ysEuHirp4DxCsHI= -github.com/hashicorp/go-hclog v0.9.2/go.mod h1:5CU+agLiy3J7N7QjHK5d05KxGsuXiQLrjA0H7acj2lQ= github.com/hashicorp/go-retryablehttp v0.7.5 h1:bJj+Pj19UZMIweq/iie+1u5YCdGrnxCT9yvm0e+Nd5M= github.com/hashicorp/go-retryablehttp v0.7.5/go.mod h1:Jy/gPYAdjqffZ/yFGCFV2doI5wjtH1ewM9u8iYVjtX8= github.com/hashicorp/golang-lru v1.0.2 h1:dV3g9Z/unq5DpblPpw+Oqcv4dU/1omnb4Ok8iPY6p1c= @@ -65,8 +54,6 @@ github.com/ipfs/go-cid v0.4.1 h1:A/T3qGvxi4kpKWWcPC/PgbvDA2bjVLO7n4UeVwnbs/s= github.com/ipfs/go-cid v0.4.1/go.mod h1:uQHwDeX4c6CtyrFwdqyhpNcxVewur1M7l7fNU7LKwZk= github.com/ipfs/go-datastore v0.6.0 h1:JKyz+Gvz1QEZw0LsX1IBn+JFCJQH4SJVFtM4uWU0Myk= github.com/ipfs/go-datastore v0.6.0/go.mod h1:rt5M3nNbSO/8q1t4LNkLyUwRs8HupMeN/8O4Vn9YAT8= -github.com/ipfs/go-detect-race v0.0.1 h1:qX/xay2W3E4Q1U7d9lNs1sU9nvguX0a7319XbyQ6cOk= -github.com/ipfs/go-detect-race v0.0.1/go.mod h1:8BNT7shDZPo99Q74BpGMK+4D8Mn4j46UU0LZ723meps= github.com/ipfs/go-ipfs-blockstore v1.3.1 h1:cEI9ci7V0sRNivqaOr0elDsamxXFxJMMMy7PTTDQNsQ= github.com/ipfs/go-ipfs-blockstore v1.3.1/go.mod h1:KgtZyc9fq+P2xJUiCAzbRdhhqJHvsw8u2Dlqy2MyRTE= github.com/ipfs/go-ipfs-ds-help v1.1.1 h1:B5UJOH52IbcfS56+Ul+sv8jnIV10lbjLF5eOO0C66Nw= @@ -79,7 +66,6 @@ github.com/ipfs/go-ipld-format v0.6.0 h1:VEJlA2kQ3LqFSIm5Vu6eIlSxD/Ze90xtc4Meten github.com/ipfs/go-ipld-format v0.6.0/go.mod h1:g4QVMTn3marU3qXchwjpKPKgJv+zF+OlaKMyhJ4LHPg= github.com/ipfs/go-log v1.0.5 h1:2dOuUCB1Z7uoczMWgAyDck5JLb72zHzrMnGnCNNbvY8= github.com/ipfs/go-log v1.0.5/go.mod h1:j0b8ZoR+7+R99LD9jZ6+AJsrzkPbSXbZfGakb5JPtIo= -github.com/ipfs/go-log/v2 v2.1.3/go.mod h1:/8d0SH3Su5Ooc31QlL1WysJhvyOTDCjcCZ9Axpmri6g= github.com/ipfs/go-log/v2 v2.5.1 h1:1XdUzF7048prq4aBjDQQ4SL5RxftpRGdXhNRwKSAlcY= github.com/ipfs/go-log/v2 v2.5.1/go.mod h1:prSpmC1Gpllc9UYWxDiZDreBYw7zp4Iqp1kOLU9U5UI= github.com/ipfs/go-metrics-interface v0.0.1 h1:j+cpbjYvu4R8zbleSs36gvB7jR+wsL2fGD6n0jO4kdg= @@ -92,41 +78,14 @@ github.com/jackc/pgx/v5 v5.7.4 h1:9wKznZrhWa2QiHL+NjTSPP6yjl3451BX3imWDnokYlg= github.com/jackc/pgx/v5 v5.7.4/go.mod h1:ncY89UGWxg82EykZUwSpUKEfccBGGYq1xjrOpsbsfGQ= github.com/jackc/puddle/v2 v2.2.2 h1:PR8nw+E/1w0GLuRFSmiioY6UooMp6KJv0/61nB7icHo= github.com/jackc/puddle/v2 v2.2.2/go.mod h1:vriiEXHvEE654aYKXXjOvZM39qJ0q+azkZFrfEOc3H4= -github.com/jbenet/go-cienv v0.1.0/go.mod h1:TqNnHUmJgXau0nCzC7kXWeotg3J9W34CUv5Djy1+FlA= github.com/jbenet/goprocess v0.1.4 h1:DRGOFReOMqqDNXwW70QkacFW0YN9QnwLV0Vqk+3oU0o= github.com/jbenet/goprocess v0.1.4/go.mod h1:5yspPrukOVuOLORacaBi858NqyClJPQxYZlqdZVfqY4= github.com/joho/godotenv v1.5.1 h1:7eLL/+HRGLY0ldzfGMeQkb7vMd0as4CfYvUVzLqw0N0= github.com/joho/godotenv v1.5.1/go.mod h1:f4LDr5Voq0i2e/R5DDNOoa2zzDfwtkZa6DnEwAbqwq4= -github.com/jtolds/gls v4.20.0+incompatible h1:xdiiI2gbIgH/gLH7ADydsJ1uDOEzR8yvV7C0MuV77Wo= -github.com/jtolds/gls v4.20.0+incompatible/go.mod h1:QJZ7F/aHp+rZTRtaJ1ow/lLfFfVYBRgL+9YlvaHOwJU= -github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8= -github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck= github.com/klauspost/compress v1.17.9 h1:6KIumPrER1LHsvBVuDa0r5xaG0Es51mhhB9BQB2qeMA= github.com/klauspost/compress v1.17.9/go.mod h1:Di0epgTjJY877eYKx5yC51cX2A2Vl2ibi7bDH9ttBbw= github.com/klauspost/cpuid/v2 v2.2.7 h1:ZWSB3igEs+d0qvnxR/ZBzXVmxkgt8DdzP6m9pfuVLDM= github.com/klauspost/cpuid/v2 v2.2.7/go.mod h1:Lcz8mBdAVJIBVzewtcLocK12l3Y+JytZYpaMropDUws= -github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo= -github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE= -github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= -github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ= -github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= -github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= -github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE= -github.com/lestrrat-go/blackmagic v1.0.1/go.mod h1:UrEqBzIR2U6CnzVyUtfM6oZNMt/7O7Vohk2J0OGSAtU= -github.com/lestrrat-go/blackmagic v1.0.2 h1:Cg2gVSc9h7sz9NOByczrbUvLopQmXrfFx//N+AkAr5k= -github.com/lestrrat-go/blackmagic v1.0.2/go.mod h1:UrEqBzIR2U6CnzVyUtfM6oZNMt/7O7Vohk2J0OGSAtU= -github.com/lestrrat-go/httpcc v1.0.1 h1:ydWCStUeJLkpYyjLDHihupbn2tYmZ7m22BGkcvZZrIE= -github.com/lestrrat-go/httpcc v1.0.1/go.mod h1:qiltp3Mt56+55GPVCbTdM9MlqhvzyuL6W/NMDA8vA5E= -github.com/lestrrat-go/httprc v1.0.4 h1:bAZymwoZQb+Oq8MEbyipag7iSq6YIga8Wj6GOiJGdI8= -github.com/lestrrat-go/httprc v1.0.4/go.mod h1:mwwz3JMTPBjHUkkDv/IGJ39aALInZLrhBp0X7KGUZlo= -github.com/lestrrat-go/iter v1.0.2 h1:gMXo1q4c2pHmC3dn8LzRhJfP1ceCbgSiT9lUydIzltI= -github.com/lestrrat-go/iter v1.0.2/go.mod h1:Momfcq3AnRlRjI5b5O8/G5/BvpzrhoFTZcn06fEOPt4= -github.com/lestrrat-go/jwx/v2 v2.0.12 h1:3d589+5w/b9b7S3DneICPW16AqTyYXB7VRjgluSDWeA= -github.com/lestrrat-go/jwx/v2 v2.0.12/go.mod h1:Mq4KN1mM7bp+5z/W5HS8aCNs5RKZ911G/0y2qUjAQuQ= -github.com/lestrrat-go/option v1.0.0/go.mod h1:5ZHFbivi4xwXxhxY9XHDe2FHo6/Z7WWmtT7T5nBBp3I= -github.com/lestrrat-go/option v1.0.1 h1:oAzP2fvZGQKWkvHa1/SAcFolBEca1oN+mQ7eooNBEYU= -github.com/lestrrat-go/option v1.0.1/go.mod h1:5ZHFbivi4xwXxhxY9XHDe2FHo6/Z7WWmtT7T5nBBp3I= -github.com/mattn/go-isatty v0.0.14/go.mod h1:7GGIvUiUoEMVVmxf/4nioHXj79iQHKdU27kJ6hsGG94= github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY= github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y= github.com/minio/sha256-simd v1.0.1 h1:6kaan5IFmwTNynnKKpDHe6FWHohJOHhCPchzK49dzMM= @@ -145,7 +104,6 @@ github.com/multiformats/go-varint v0.0.7 h1:sWSGR+f/eu5ABZA2ZpYKBILXTTs9JWpdEM/n github.com/multiformats/go-varint v0.0.7/go.mod h1:r8PUYw/fD/SjBCiKOoDlGF6QawOELpZAu9eioSos/OU= github.com/opentracing/opentracing-go v1.2.0 h1:uEJPy/1a5RIPAJ0Ov+OIO8OxWu77jEv+1B0VhjKrZUs= github.com/opentracing/opentracing-go v1.2.0/go.mod h1:GxEUsuufX4nBwe+T+Wl9TAgYrxe9dPLANfrWvHYVTgc= -github.com/pkg/errors v0.8.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U= github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= @@ -159,49 +117,21 @@ github.com/prometheus/common v0.54.0 h1:ZlZy0BgJhTwVZUn7dLOkwCZHUkrAqd3WYtcFCWnM github.com/prometheus/common v0.54.0/go.mod h1:/TQgMJP5CuVYveyT7n/0Ix8yLNNXy9yRSkhnLTHPDIQ= github.com/prometheus/procfs v0.15.1 h1:YagwOFzUgYfKKHX6Dr+sHT7km/hxC76UB0learggepc= github.com/prometheus/procfs v0.15.1/go.mod h1:fB45yRUv8NstnjriLhBQLuOUt+WW4BsoGhij/e3PBqk= -github.com/rachel-mp4/atproto-oauth-golang v0.0.0-20250616212213-a55a5f62b82d h1:FQ8YKfXnKmyEbKnO/blj3qWGhYdw+l3DtQCqSboJRvA= -github.com/rachel-mp4/atproto-oauth-golang v0.0.0-20250616212213-a55a5f62b82d/go.mod h1:vVRo6BPEmWOZnYk9LtXLzBPzfkY63fUaBahA+o4h55Q= github.com/rachel-mp4/lrcd v0.0.0-20250731224514-2f8d47fe368c h1:/KXAMnA+PC9ihDVI2u4BQ5BITsR+WB0anx3Zk/sLW88= github.com/rachel-mp4/lrcd v0.0.0-20250731224514-2f8d47fe368c/go.mod h1:lU5b8bC7vP56MT57i6gUYoXxHSVLyrUYMnUo7JELwSc= github.com/rachel-mp4/lrcproto v0.0.0-20250720164211-c6162669b709 h1:P//gJE0zFv9Qvfn8dvp9ZrnG0FZh2MVcAX+uOP2flRw= github.com/rachel-mp4/lrcproto v0.0.0-20250720164211-c6162669b709/go.mod h1:hQzO36tQELGbkmRnUtKeM6NMU34t79ZcTlhM+MO7pHw= github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ= github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88= -github.com/rogpeppe/go-internal v1.3.0/go.mod h1:M8bDsm7K2OlrFYOpmOWEs/qY81heoFRclV5y23lUDJ4= -github.com/rogpeppe/go-internal v1.13.1 h1:KvO1DLK/DRN07sQ1LQKScxyZJuNnedQ5/wKSR38lUII= -github.com/rogpeppe/go-internal v1.13.1/go.mod h1:uMEvuHeurkdAXX61udpOXGD/AzZDWNMNyH2VO9fmH0o= -github.com/russross/blackfriday/v2 v2.0.1/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM= -github.com/segmentio/asm v1.2.0 h1:9BQrFxC+YOHJlTlHGkTrFWf59nbL3XnCoFLTwDCI7ys= -github.com/segmentio/asm v1.2.0/go.mod h1:BqMnlJP91P8d+4ibuonYZw9mfnzI9HfxselHZr5aAcs= -github.com/shurcooL/sanitized_anchor_name v1.0.0/go.mod h1:1NzhyTcUVG4SuEtjjoZeVRXNmyL/1OwPU0+IJeTBvfc= -github.com/smartystreets/assertions v1.2.0 h1:42S6lae5dvLc7BrLu/0ugRtcFVjoJNMC/N3yZFZkDFs= -github.com/smartystreets/assertions v1.2.0/go.mod h1:tcbTF8ujkAEcZ8TElKY+i30BzYlVhC/LOxJk7iOWnoo= -github.com/smartystreets/goconvey v1.7.2 h1:9RBaZCeXEQ3UselpuwUQHltGVXvdwm6cv1hgR6gDIPg= -github.com/smartystreets/goconvey v1.7.2/go.mod h1:Vw0tHAZW6lzCRk3xgdin6fKYcG+G3Pg9vgXWeJpQFMM= github.com/spaolacci/murmur3 v1.1.0 h1:7c1g84S4BPRrfL5Xrdp6fOJ206sU9y293DDHaoy0bLI= github.com/spaolacci/murmur3 v1.1.0/go.mod h1:JwIasOWyU6f++ZhiEuf87xNszmSA2myDM2Kzu9HwQUA= github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= -github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw= -github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo= -github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs= github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= -github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4= -github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= -github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= -github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU= -github.com/stretchr/testify v1.8.4/go.mod h1:sz/lmYIOXD/1dqDmKjjqLyZ2RngseejIcXlSw2iwfAo= github.com/stretchr/testify v1.10.0 h1:Xv5erBjTwe/5IxqUQTdXv5kgmIvbHo3QQyRwhJsOfJA= github.com/stretchr/testify v1.10.0/go.mod h1:r2ic/lqez/lEtzL7wO/rwa5dbSLXVDPFyf8C91i36aY= -github.com/urfave/cli v1.22.10/go.mod h1:Gos4lmkARVdJ6EkW0WaNv/tZAAMe9V7XWyB60NtXRu0= -github.com/warpfork/go-wish v0.0.0-20220906213052-39a1cc7a02d0 h1:GDDkbFiaK8jsSDJfjId/PEGEShv6ugrt4kYsC5UIDaQ= -github.com/warpfork/go-wish v0.0.0-20220906213052-39a1cc7a02d0/go.mod h1:x6AKhvSSexNrVSrViXSHUEbICjmGXhtgABaHIySUSGw= github.com/whyrusleeping/cbor-gen v0.3.1 h1:82ioxmhEYut7LBVGhGq8xoRkXPLElVuh5mV67AFfdv0= github.com/whyrusleeping/cbor-gen v0.3.1/go.mod h1:pM99HXyEbSQHcosHc0iW7YFmwnscr+t9Te4ibko05so= -github.com/yuin/goldmark v1.1.27/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= -github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= -github.com/yuin/goldmark v1.3.5/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k= -github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= gitlab.com/yawning/secp256k1-voi v0.0.0-20230925100816-f2616030848b h1:CzigHMRySiX3drau9C6Q5CAbNIApmLdat5jPMqChvDA= gitlab.com/yawning/secp256k1-voi v0.0.0-20230925100816-f2616030848b/go.mod h1:/y/V339mxv2sZmYYR64O07VuCpdNZqCTwO8ZcouTMI8= gitlab.com/yawning/tuplehash v0.0.0-20230713102510-df83abbf9a02 h1:qwDnMxjkyLmAFgcfgTnfJrmYKWhHnci3GjDqcZp1M3Q= @@ -214,118 +144,31 @@ go.opentelemetry.io/otel/metric v1.29.0 h1:vPf/HFWTNkPu1aYeIsc98l4ktOQaL6LeSoeV2 go.opentelemetry.io/otel/metric v1.29.0/go.mod h1:auu/QWieFVWx+DmQOUMgj0F8LHWdgalxXqvp7BII/W8= go.opentelemetry.io/otel/trace v1.29.0 h1:J/8ZNK4XgR7a21DZUAsbF8pZ5Jcw1VhACmnYt39JTi4= go.opentelemetry.io/otel/trace v1.29.0/go.mod h1:eHl3w0sp3paPkYstJOmAimxhiFXPg+MMTlEh3nsQgWQ= -go.uber.org/atomic v1.6.0/go.mod h1:sABNBOSYdrvTF6hTgEIbc7YasKWGhgEQZyfxyTvoXHQ= -go.uber.org/atomic v1.7.0/go.mod h1:fEN4uk6kAWBTFdckzkM89CLk9XfWZrxpCo0nPH17wJc= go.uber.org/atomic v1.11.0 h1:ZvwS0R+56ePWxUNi+Atn9dWONBPp/AUETXlHW0DxSjE= go.uber.org/atomic v1.11.0/go.mod h1:LUxbIzbOniOlMKjJjyPfpl4v+PKK2cNJn91OQbhoJI0= -go.uber.org/goleak v1.1.11-0.20210813005559-691160354723/go.mod h1:cwTWslyiVhfpKIDGSZEM2HlOvcqm+tG4zioyIeLoqMQ= -go.uber.org/goleak v1.2.0 h1:xqgm/S+aQvhWFTtR0XK3Jvg7z8kGV8P4X14IzwN3Eqk= -go.uber.org/goleak v1.2.0/go.mod h1:XJYK+MuIchqpmGmUSAzotztawfKvYLUIgg7guXrwVUo= -go.uber.org/multierr v1.5.0/go.mod h1:FeouvMocqHpRaaGuG9EjoKcStLC43Zu/fmqdUMPcKYU= -go.uber.org/multierr v1.6.0/go.mod h1:cdWPpRnG4AhwMwsgIHip0KRBQjJy5kYEpYjJxpXp9iU= go.uber.org/multierr v1.11.0 h1:blXXJkSxSSfBVBlC76pxqeO+LN3aDfLQo+309xJstO0= go.uber.org/multierr v1.11.0/go.mod h1:20+QtiLqy0Nd6FdQB9TLXag12DsQkrbs3htMFfDN80Y= -go.uber.org/tools v0.0.0-20190618225709-2cfd321de3ee/go.mod h1:vJERXedbb3MVM5f9Ejo0C68/HhF8uaILCdgjnY+goOA= -go.uber.org/zap v1.16.0/go.mod h1:MA8QOfq0BHJwdXa996Y4dYkAqRKB8/1K1QMMZVaNZjQ= -go.uber.org/zap v1.19.1/go.mod h1:j3DNczoxDZroyBnOT1L/Q79cfUMGZxlv/9dzN7SM1rI= go.uber.org/zap v1.26.0 h1:sI7k6L95XOKS281NhVKOFCUNIvv9e0w4BF8N3u+tCRo= go.uber.org/zap v1.26.0/go.mod h1:dtElttAiwGvoJ/vj4IwHBS/gXsEu/pZ50mUIRWuG0so= -golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= -golang.org/x/crypto v0.0.0-20190510104115-cbcb75029529/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= -golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= -golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto= -golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= -golang.org/x/crypto v0.12.0/go.mod h1:NF0Gs7EO5K4qLn+Ylc+fih8BSTeIjAP05siRnAh98yw= golang.org/x/crypto v0.31.0 h1:ihbySMvVjLAeSH1IbfcRTkD/iNscyz8rGzjF/E5hV6U= golang.org/x/crypto v0.31.0/go.mod h1:kDsLvtWBEx7MV9tJOj9bnXsPbxwJQ6csT/x4KIN4Ssk= -golang.org/x/lint v0.0.0-20190930215403-16217165b5de/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc= -golang.org/x/mod v0.0.0-20190513183733-4bf6d317e70e/go.mod h1:mXi4GBBbnImb6dmsKGUJ2LatrhH/nqhxcFungHvyanc= -golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= -golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= -golang.org/x/mod v0.4.2/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= -golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= -golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= -golang.org/x/net v0.0.0-20190311183353-d8887717615a/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= -golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= -golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= -golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= -golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= -golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= -golang.org/x/net v0.0.0-20210405180319-a5a99cb37ef4/go.mod h1:p54w0d4576C0XHj96bSt6lcn1PtDYWL6XObtHCRCNQM= -golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= -golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= -golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg= -golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= -golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= -golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= -golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= -golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= -golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.10.0 h1:3NQrjDixjgGwUOCaF8w2+VYHv0Ve/vGYSbdkTa98gmQ= golang.org/x/sync v0.10.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk= -golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= -golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= -golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= -golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= -golang.org/x/sys v0.0.0-20210330210617-4fbd30eecc44/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= -golang.org/x/sys v0.0.0-20210510120138-977fb7262007/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.0.0-20210630005230-0f9fa26af87c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.0.0-20220412211240-33da011f77ad/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.11.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.28.0 h1:Fksou7UEQUWlKvIdsqzJmUmCX3cZuD2+P3XyyzwMhlA= golang.org/x/sys v0.28.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= -golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= -golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= -golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k= -golang.org/x/term v0.8.0/go.mod h1:xPskH00ivmX89bAKVGSKKtLOWNx2+17Eiy94tnKShWo= -golang.org/x/term v0.11.0/go.mod h1:zC9APTIj3jG3FdV/Ons+XE1riIZXG4aZ4GTHiPZJPIU= -golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= -golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= -golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= -golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= -golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8= -golang.org/x/text v0.12.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE= golang.org/x/text v0.21.0 h1:zyQAAkrwaneQ066sspRyJaG9VNi/YJ1NfzcGB3hZ/qo= golang.org/x/text v0.21.0/go.mod h1:4IBbMaMmOPCJ8SecivzSH54+73PCFmPWxNTLm+vZkEQ= golang.org/x/time v0.8.0 h1:9i3RxcPv3PZnitoVGMPDKZSq1xW1gK1Xy3ArNOGZfEg= golang.org/x/time v0.8.0/go.mod h1:3BpzKBy/shNhVucY/MWOyx10tF3SFh9QdLuxbVysPQM= -golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= -golang.org/x/tools v0.0.0-20190311212946-11955173bddd/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs= -golang.org/x/tools v0.0.0-20190328211700-ab21143f2384/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs= -golang.org/x/tools v0.0.0-20190621195816-6e04913cbbac/go.mod h1:/rFqwRUd4F7ZHNgwSSTFct+R/Kf4OFW1sUzUTQQTgfc= -golang.org/x/tools v0.0.0-20191029041327-9cc4af7d6b2c/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= -golang.org/x/tools v0.0.0-20191029190741-b9c20aec41a5/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= -golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= -golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE= -golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= -golang.org/x/tools v0.1.5/go.mod h1:o0xws9oXOQQZyjljx8fwUC0k7L1pTE6eaCbjGeHmOkk= -golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= -golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU= -golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= -golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= -golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028 h1:+cNy6SZtPcJQH3LJVLOSmiC7MMxXNOb3PU/VUEz+EhU= golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028/go.mod h1:NDW/Ps6MPRej6fsCIbMTohpP40sJ/P/vI1MoTEGwX90= google.golang.org/protobuf v1.36.6 h1:z1NpPI8ku2WgiWnf+t9wTPsn6eP1L7ksHUlkfLvd9xY= google.golang.org/protobuf v1.36.6/go.mod h1:jduwjTPXsFjZGTmRluh+L6NjiWu7pchiJ2/5YcXBHnY= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= -gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= -gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk= -gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q= -gopkg.in/errgo.v2 v2.1.0/go.mod h1:hNsd1EY+bozCKY1Ytp96fpM3vjJbqLJn88ws8XvfDNI= -gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= -gopkg.in/yaml.v2 v2.2.8/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -honnef.co/go/tools v0.0.1-2019.2.3/go.mod h1:a3bituU0lyd329TUQxRnasdCoJDkEUEAqEt0JzvZhAg= lukechampine.com/blake3 v1.2.1 h1:YuqqRuaqsGV71BV/nm9xlI0MKUv4QC54jQnBChWbGnI= lukechampine.com/blake3 v1.2.1/go.mod h1:0OFRp7fBtAylGVCO40o87sbupkyIGgbpv1+M1k1LM6k= diff --git a/server/internal/db/oauth.go b/server/internal/db/oauth.go index 91b5f5d..6a4f92f 100644 --- a/server/internal/db/oauth.go +++ b/server/internal/db/oauth.go @@ -4,149 +4,159 @@ import ( "context" "errors" "fmt" - "rvcx/internal/types" + "strings" + + "github.com/bluesky-social/indigo/atproto/auth/oauth" + "github.com/bluesky-social/indigo/atproto/syntax" ) -func (s *Store) StoreOAuthRequest(req *types.OAuthRequest, ctx context.Context) error { - _, err := s.pool.Exec(ctx, ` - INSERT INTO oauthrequests ( - authserver_iss, - state, - did, - pds_url, - pkce_verifier, - dpop_auth_server_nonce, - dpop_private_jwk - ) VALUES ($1, $2, $3, $4, $5, $6, $7)`, - req.AuthserverIss, - req.State, - req.Did, - req.PdsUrl, - req.PkceVerifier, - req.DpopAuthServerNonce, - req.DpopPrivKey) - return err +func (s Store) GetSession(ctx context.Context, did syntax.DID, sessionID string) (*oauth.ClientSessionData, error) { + row := s.pool.QueryRow(ctx, ` + SELECT + host_url, + authserver_url, + authserver_token_endpoint, + scopes, + access_token, + refresh_token, + dpop_authserver_nonce, + dpop_host_nonce, + dpop_privatekey_multibase + FROM sessions + WHERE did = $1 AND session_id = $2`, did.String(), sessionID) + var scope string + var csd oauth.ClientSessionData + csd.AccountDID = did + csd.SessionID = sessionID + err := row.Scan(&csd.HostURL, + &csd.AuthServerURL, + &csd.AuthServerTokenEndpoint, + &scope, + &csd.AccessToken, + &csd.RefreshToken, + &csd.DPoPAuthServerNonce, + &csd.DPoPHostNonce, + &csd.DPoPPrivateKeyMultibase, + ) + if err != nil { + return nil, errors.New("error scanning: " + err.Error()) + } + scopes := strings.Fields(scope) + csd.Scopes = scopes + return &csd, nil } -func (s *Store) StoreOAuthSession(session *types.Session, ctx context.Context) error { +func (s Store) SaveSession(ctx context.Context, sess oauth.ClientSessionData) error { + scope := strings.Join(sess.Scopes, " ") _, err := s.pool.Exec(ctx, ` - INSERT INTO oauthsessions ( - id, - authserver_iss, - state, - did, - pds_url, - pkce_verifier, - dpop_auth_server_nonce, - dpop_private_jwk, - dpop_pds_nonce, + INSERT INTO sessions ( + session_id, + account_did, + host_url, + authserver_url, + authserver_token_endpoint, + scopes, access_token, refresh_token, - expiration - ) VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11, $12)`, - session.ID, - session.AuthserverIss, - session.State, - session.Did, - session.PdsUrl, - session.PkceVerifier, - session.DpopAuthServerNonce, - session.DpopPrivKey, - session.DpopPdsNonce, - session.AccessToken, - session.RefreshToken, - session.Expiration) + dpop_authserver_nonce, + dpop_host_nonce, + dpop_privatekey_multibase + ) VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11)`, + sess.SessionID, + sess.AccountDID.String(), + sess.HostURL, + sess.AuthServerURL, + sess.AuthServerTokenEndpoint, + scope, + sess.AccessToken, + sess.RefreshToken, + sess.DPoPAuthServerNonce, + sess.DPoPHostNonce, + sess.DPoPPrivateKeyMultibase, + ) if err != nil { - return errors.New("error storing oauth session" + err.Error()) + return errors.New("failed to insert: " + err.Error()) } return nil } -func (s *Store) UpdateSession(id int, session *types.Session, ctx context.Context) error { - _, err := s.pool.Exec(ctx, `UPDATE oauthsessions - SET (dpop_auth_server_nonce, access_token, refresh_token) - VALUES ($1, $2, $3) - WHERE id = $4 - `, session.DpopAuthServerNonce, session.AccessToken, session.RefreshToken, id) +func (s Store) DeleteSession(ctx context.Context, did syntax.DID, sessionID string) error { + _, err := s.pool.Exec(ctx, `DELETE FROM sessions WHERE account_did = $1 AND session_id = $2`, did.String(), sessionID) if err != nil { - return errors.New("error updating session: " + err.Error()) + return errors.New("failed to delete: " + err.Error()) } return nil } -func (s *Store) GetOauthRequest(state string, ctx context.Context) (*types.OAuthRequest, error) { +func (s Store) GetAuthRequestInfo(ctx context.Context, state string) (*oauth.AuthRequestData, error) { row := s.pool.QueryRow(ctx, ` - SELECT - r.id, - r.authserver_iss, - r.did, - r.pds_url, - r.pkce_verifier, - r.dpop_auth_server_nonce, - r.dpop_private_jwk - FROM oauthrequests r - WHERE r.state = $1 - LIMIT 1 + SELECT + authserver_url, + account_did, + scopes, + request_uri, + authserver_token_endpoint, + pkce_verifier, + dpop_authserver_nonce, + dpop_privatekey_multibase + FROM requests + WHERE state = $1 `, state) - var req types.OAuthRequest - err := row.Scan(&req.ID, &req.AuthserverIss, &req.Did, &req.PdsUrl, &req.PkceVerifier, &req.DpopAuthServerNonce, &req.DpopPrivKey) + var ari oauth.AuthRequestData + ari.State = state + var did string + err := row.Scan( + &ari.AuthServerURL, + &did, + &ari.Scope, + &ari.AuthServerTokenEndpoint, + &ari.PKCEVerifier, + &ari.DPoPAuthServerNonce, + &ari.DPoPPrivateKeyMultibase, + ) if err != nil { - return nil, errors.New("error scanning rows while getting oauth request:" + err.Error()) + return nil, errors.New("failed to scan: " + err.Error()) } - return &req, nil -} - -func (s *Store) GetOauthSession(id int, ctx context.Context) (*types.Session, error) { - row := s.pool.QueryRow(ctx, ` - SELECT - r.authserver_iss, - r.did, - r.pds_url, - r.pkce_verifier, - r.dpop_auth_server_nonce, - r.dpop_private_jwk, - r.dpop_pds_nonce, - r.access_token, - r.refresh_token, - r.expiration - FROM oauthsessions r - WHERE r.id = $1 - `, id) - var session types.Session - err := row.Scan( - &session.AuthserverIss, - &session.Did, - &session.PdsUrl, - &session.PkceVerifier, - &session.DpopAuthServerNonce, - &session.DpopPrivKey, - &session.DpopPdsNonce, - &session.AccessToken, - &session.RefreshToken, - &session.Expiration) + sdid, err := syntax.ParseDID(did) if err != nil { - return nil, errors.New("error scanning oauthsession row: " + err.Error()) + return nil, errors.New("failed to parse did: " + err.Error()) } - session.ID = id - return &session, nil + ari.AccountDID = &sdid + return &ari, nil } -func (s *Store) DeleteOauthRequest(state string, ctx context.Context) error { +func (s Store) SaveAuthRequestInfo(ctx context.Context, info oauth.AuthRequestData) error { _, err := s.pool.Exec(ctx, ` - DELETE FROM oauthrequests r WHERE r.state = $1 - `, state) + INSERT INTO requests ( + state, + authserver_url, + account_did, + scopes, + request_uri, + authserver_token_endpoint, + pkce_verifier, + dpop_authserver_nonce, + dpop_privatekey_multibase) + VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9)`, + info.State, + info.AuthServerURL, + info.AccountDID.String(), + info.Scope, + info.AuthServerTokenEndpoint, + info.PKCEVerifier, + info.DPoPAuthServerNonce, + info.DPoPPrivateKeyMultibase, + ) if err != nil { - return errors.New("error deleting oauth request:" + err.Error()) + return errors.New("failed to insert: " + err.Error()) } return nil } -func (s *Store) DeleteOauthSession(id int, ctx context.Context) error { - _, err := s.pool.Exec(ctx, ` - DELETE FROM oauthsessions s WHERE s.id = $1 - `, id) +func (s Store) DeleteAuthRequestInfo(ctx context.Context, state string) error { + _, err := s.pool.Exec(ctx, `DELETE FROM requests WHERE state = $1`, state) if err != nil { - return errors.New("error deleting oauth request:" + err.Error()) + return errors.New("failed to delete: " + err.Error()) } return nil } diff --git a/server/internal/handler/lrcHandlers.go b/server/internal/handler/lrcHandlers.go index cd271cf..47929c2 100644 --- a/server/internal/handler/lrcHandlers.go +++ b/server/internal/handler/lrcHandlers.go @@ -32,7 +32,7 @@ func (h *Handler) postChannel(w http.ResponseWriter, r *http.Request) { return } session, _ := h.sessionStore.Get(r, "oauthsession") - id, ok := session.Values["id"].(int) + id, ok := session.Values["id"].(string) var uri, did string if !ok { did, uri, err = h.rm.PostMyChannel(r.Context(), cr) @@ -88,7 +88,7 @@ func (h *Handler) postMessage(w http.ResponseWriter, r *http.Request) { return } session, _ := h.sessionStore.Get(r, "oauthsession") - id, ok := session.Values["id"].(int) + id, ok := session.Values["id"].(string) if !ok { err = h.rm.PostMyMessage(r.Context(), pmr) } else { diff --git a/server/internal/handler/oauthHandlers.go b/server/internal/handler/oauthHandlers.go index 1d27a25..8704c21 100644 --- a/server/internal/handler/oauthHandlers.go +++ b/server/internal/handler/oauthHandlers.go @@ -1,23 +1,20 @@ package handler import ( - "context" "encoding/json" "errors" "fmt" "net/http" - "net/url" "os" "rvcx/internal/atputils" "rvcx/internal/oauth" + "strings" "github.com/gorilla/sessions" - // aog "github.com/haileyok/atproto-oauth-golang" - "github.com/haileyok/atproto-oauth-golang/helpers" ) func (h *Handler) serveJWKS(w http.ResponseWriter, r *http.Request) { - key, err := oauth.GetJWKS() + key, err := oauth.GetPrivateKey() if err != nil { h.serverError(w, err) } @@ -25,132 +22,38 @@ func (h *Handler) serveJWKS(w http.ResponseWriter, r *http.Request) { if err != nil { h.serverError(w, err) } - ro := helpers.CreateJwksResponseObject(pubKey) + ro, err := pubKey.JWK() + if err != nil { + h.serverError(w, err) + } w.Header().Set("Content-Type", "application/json") encoder := json.NewEncoder(w) encoder.Encode(ro) } -// func (h *Handler) newOAuthLogin(w http.ResponseWriter, r *http.Request) { -// err := r.ParseForm() -// if err != nil { -// h.badRequest(w, err) -// return -// } -// clientID := oauth.GetClientMetadata().ClientId -// callbackUrl := oauth.GetClientMetadata().RedirectUris[0] -// k, err := oauth.GetJWKS() -// if err != nil { -// h.serverError(w, err) -// return -// } -// cli, err := aog.NewClient(aog.ClientArgs{ -// ClientJwk: *k, -// ClientId: clientID, -// RedirectUri: callbackUrl, -// }) -// if err != nil { -// h.serverError(w, err) -// return -// } -// cli.RefreshTokenRequest -// handle := r.FormValue("handle") -// } - func (h *Handler) oauthLogin(w http.ResponseWriter, r *http.Request) { err := r.ParseForm() if err != nil { h.badRequest(w, err) return } - handle := r.FormValue("handle") - req, res, err := h.oauth.StartAuthFlow(r.Context(), handle) - if err != nil { - h.serverError(w, err) - return - } - err = h.db.StoreOAuthRequest(req, r.Context()) - if err != nil { - h.serverError(w, err) - return - } - u, _ := url.Parse(res.AuthzEndpoint) - u.RawQuery = fmt.Sprintf("client_id=%s&request_uri=%s", url.QueryEscape(oauth.GetClientMetadata().ClientId), res.RequestUri) - - session, _ := h.sessionStore.Get(r, "oauthsession") - session.Values = map[any]any{} - - session.Options = &sessions.Options{ - Path: "/", - MaxAge: 300, - HttpOnly: true, - } - session.Values["oauth_state"] = res.State - session.Values["oauth_did"] = res.DID - err = session.Save(r, w) + identifier := r.FormValue("identifier") + redirectURL, err := h.oauth.StartAuthFlow(r.Context(), identifier) if err != nil { h.serverError(w, err) return } - go func() { - err := h.db.StoreDidHandle(res.DID, handle, context.Background()) - h.logger.Deprintln("storing....") - if err != nil { - h.logger.Deprintln("failed to store did handle: " + err.Error()) - } - }() - http.Redirect(w, r, u.String(), http.StatusFound) + http.Redirect(w, r, redirectURL, http.StatusFound) } func (h *Handler) oauthCallback(w http.ResponseWriter, r *http.Request) { - resState := r.FormValue("state") - resIss := r.FormValue("iss") - resCode := r.FormValue("code") - session, err := h.sessionStore.Get(r, "oauthsession") + sessData, err := h.oauth.OauthCallback(r.Context(), r.URL.Query()) + err = h.rm.CreateInitialProfile(sessData, r.Context()) if err != nil { h.serverError(w, err) return } - if resState == "" || resIss == "" || resCode == "" { - h.badRequest(w, errors.New("did not provide one of resState, resIss, resCode")) - return - } - sessionState, ok := session.Values["oauth_state"].(string) - if !ok { - h.serverError(w, errors.New("oauth_state not found in session")) - return - } - if resState != sessionState { - h.serverError(w, errors.New("resState and sessionState do not match!")) - return - } - params := oauth.CallbackParams{ - State: resState, - Iss: resIss, - Code: resCode, - } - req, err := h.db.GetOauthRequest(resState, r.Context()) - if err != nil { - h.serverError(w, err) - return - } - OauthSession, err := h.oauth.OauthCallback(r.Context(), req, params) - if err != nil { - h.serverError(w, err) - return - } - err = h.db.DeleteOauthRequest(resState, r.Context()) - if err != nil { - h.serverError(w, err) - return - } - h.logger.Deprintf("id: %d %d", OauthSession.ID, req.ID) - err = h.db.StoreOAuthSession(OauthSession, r.Context()) - if err != nil { - h.serverError(w, err) - return - } - err = h.rm.CreateInitialProfile(req.Did, req.ID, r.Context()) + session, _ := h.sessionStore.Get(r, "oauthsession") if err != nil { h.serverError(w, err) return @@ -162,8 +65,9 @@ func (h *Handler) oauthCallback(w http.ResponseWriter, r *http.Request) { HttpOnly: true, } session.Values = map[any]any{} - session.Values["did"] = req.Did - session.Values["id"] = req.ID + session.Values["did"] = sessData.AccountDID.String() + session.Values["id"] = sessData.SessionID + session.Values["scopes"] = strings.Join(sessData.Scopes, " ") err = session.Save(r, w) if err != nil { h.serverError(w, err) @@ -226,17 +130,18 @@ func (h *Handler) handleFindDidAndHandleError(w http.ResponseWriter, err error) func (h *Handler) oauthLogout(w http.ResponseWriter, r *http.Request) { s, _ := h.sessionStore.Get(r, "oauthsession") - id, ok := s.Values["id"].(int) - if ok { + id, ok := s.Values["id"].(string) + did, bok := s.Values["did"].(string) + if ok && bok { h.logger.Deprintln("deleting session to log out!") - err := h.rm.DeleteSession(id, r.Context()) + err := h.rm.DeleteSession(did, id, r.Context()) if err != nil { h.serverError(w, errors.New("couldn't log out: "+err.Error())) return } h.logger.Deprintln("deleted session to log out!") } - s.Values = make(map[interface{}]interface{}) + s.Values = make(map[any]any) s.Options.MaxAge = -1 h.logger.Deprintln("saving cookie to log out!") err := s.Save(r, w) diff --git a/server/internal/handler/xcvrHandlers.go b/server/internal/handler/xcvrHandlers.go index 30b467c..24f4e30 100644 --- a/server/internal/handler/xcvrHandlers.go +++ b/server/internal/handler/xcvrHandlers.go @@ -21,7 +21,7 @@ func (h *Handler) postProfile(w http.ResponseWriter, r *http.Request) { return } s, _ := h.sessionStore.Get(r, "oauthsession") - id, ok := s.Values["id"].(int) + id, ok := s.Values["id"].(string) if !ok { h.badRequest(w, errors.New("must be logged in!")) return @@ -35,12 +35,13 @@ func (h *Handler) postProfile(w http.ResponseWriter, r *http.Request) { func (h *Handler) beep(w http.ResponseWriter, r *http.Request) { s, _ := h.sessionStore.Get(r, "oauthsession") - id, ok := s.Values["id"].(int) - if !ok { + id, ok := s.Values["id"].(string) + did, bok := s.Values["did"].(string) + if !ok || !bok { h.badRequest(w, errors.New("must be logged in!")) return } - err := h.rm.Beep(id, r.Context()) + err := h.rm.Beep(did, id, r.Context()) if err != nil { h.badRequest(w, err) return diff --git a/server/internal/oauth/clientmapper.go b/server/internal/oauth/clientmapper.go deleted file mode 100644 index 5f3683d..0000000 --- a/server/internal/oauth/clientmapper.go +++ /dev/null @@ -1,98 +0,0 @@ -package oauth - -import ( - "context" - "errors" - "sync" - "time" -) - -type ClientMap struct { - svc *Service - clients map[int]*OauthXRPCClient - expiry map[int]time.Time - texp map[int]time.Time - mu sync.Mutex -} - -func NewClientMap(service *Service) *ClientMap { - return &ClientMap{ - svc: service, - clients: make(map[int]*OauthXRPCClient, 10), - expiry: make(map[int]time.Time, 10), - texp: make(map[int]time.Time, 10), - mu: sync.Mutex{}, - } -} - -func (c *ClientMap) Map(id int, ctx context.Context) (cli *OauthXRPCClient, refreshed bool, err error) { - c.mu.Lock() - defer c.mu.Unlock() - cli = c.clients[id] - if cli == nil { - return - } - - texp := c.texp[id] - expiry := c.expiry[id] - if time.Now().After(expiry) { - c.Delete(id) - err = errors.New("client has expired") - return - } - if texp.Sub(time.Now()) <= 5*time.Minute { - var newexp time.Time - newexp, err = c.svc.RefreshToken(ctx, cli.session) - if err != nil { - err = errors.New("failed to refresh expired token: " + err.Error()) - return - } - refreshed = true - c.texp[id] = newexp - } - return -} - -func (c *ClientMap) Append(id int, client *OauthXRPCClient, expiration time.Time) { - c.mu.Lock() - defer c.mu.Unlock() - c.clients[id] = client - c.expiry[id] = expiration - c.texp[id] = time.Now() - -} - -func (c *ClientMap) Cleanup() { - now := time.Now() - c.mu.Lock() - defer c.mu.Unlock() - for id, client := range c.clients { - expiry, ok := c.expiry[id] - if !ok { - delete(c.expiry, id) - delete(c.clients, id) - delete(c.texp, id) - continue - } - if client == nil { - delete(c.expiry, id) - delete(c.clients, id) - delete(c.texp, id) - continue - } - if now.After(expiry) { - delete(c.expiry, id) - delete(c.clients, id) - delete(c.texp, id) - continue - } - } -} - -func (c *ClientMap) Delete(id int) { - c.mu.Lock() - defer c.mu.Unlock() - delete(c.clients, id) - delete(c.expiry, id) - delete(c.texp, id) -} diff --git a/server/internal/oauth/jwks.go b/server/internal/oauth/jwks.go index 782b854..7edb6d6 100644 --- a/server/internal/oauth/jwks.go +++ b/server/internal/oauth/jwks.go @@ -1,27 +1,15 @@ package oauth import ( + "github.com/bluesky-social/indigo/atproto/crypto" "os" - "github.com/haileyok/atproto-oauth-golang/helpers" - "github.com/lestrrat-go/jwx/v2/jwk" ) -var ( - key *jwk.Key -) - -func GetJWKS() (*jwk.Key, error) { - if key != nil { - return key, nil - } - b, err := os.ReadFile("../jwks.json") - if err != nil { - return nil, err - } - k, err := helpers.ParseJWKFromBytes(b) +func GetPrivateKey() (*crypto.PrivateKeyK256, error) { + csk := os.Getenv("CLIENT_SECRET_KEY") + key, err := crypto.ParsePrivateBytesK256([]byte(csk)) if err != nil { return nil, err } - key = &k return key, nil } diff --git a/server/internal/oauth/oauthclient.go b/server/internal/oauth/oauthclient.go index c920d58..98485ee 100644 --- a/server/internal/oauth/oauthclient.go +++ b/server/internal/oauth/oauthclient.go @@ -5,91 +5,49 @@ import ( "encoding/json" "errors" "github.com/bluesky-social/indigo/api/atproto" - "github.com/bluesky-social/indigo/api/bsky" - "github.com/bluesky-social/indigo/atproto/client" + "github.com/bluesky-social/indigo/atproto/auth/oauth" "github.com/bluesky-social/indigo/atproto/syntax" - "github.com/bluesky-social/indigo/lex/util" - "github.com/haileyok/atproto-oauth-golang" - "github.com/haileyok/atproto-oauth-golang/helpers" - "rvcx/internal/db" "rvcx/internal/lex" "rvcx/internal/log" "rvcx/internal/types" ) type OauthXRPCClient struct { - xrpc *oauth.XrpcClient session *types.Session logger *log.Logger } -func NewOauthXRPCClient(s *db.Store, l *log.Logger, session *types.Session) *OauthXRPCClient { - return &OauthXRPCClient{ - xrpc: &oauth.XrpcClient{ - OnDpopPdsNonceChanged: func(did, newNonce string) { - err := s.SetDpopPdsNonce(session.ID, newNonce) - if err != nil { - l.Println(err.Error()) - return - } - session.DpopPdsNonce = newNonce - }, - }, - session: session, - logger: l, - } -} - func (c *OauthXRPCClient) GetSession() *types.Session { return c.session } -func (c *OauthXRPCClient) getOauthSessionAuthArgs() (*oauth.XrpcAuthedRequestArgs, error) { - s := c.session - privateJwk, err := helpers.ParseJWKFromBytes([]byte(s.DpopPrivKey)) - if err != nil { - return nil, errors.New("failed to parse jwk in getoauthsessionauthargs: " + err.Error()) - } - return &oauth.XrpcAuthedRequestArgs{ - Did: s.Did, - AccessToken: s.AccessToken, - PdsUrl: s.PdsUrl, - Issuer: s.AuthserverIss, - DpopPdsNonce: s.DpopPdsNonce, - DpopPrivateJwk: privateJwk, - }, nil -} - -func (c *OauthXRPCClient) MakeBskyPost(text string, ctx context.Context) error { - authargs, err := c.getOauthSessionAuthArgs() - if err != nil { - return errors.New("failed to get oauthsessionauthargs while making post: " + err.Error()) - } - post := bsky.FeedPost{ - Text: text, - CreatedAt: syntax.DatetimeNow().String(), - } - input := atproto.RepoCreateRecord_Input{ - Collection: "app.bsky.feed.post", - Repo: authargs.Did, - Record: &util.LexiconTypeDecoder{Val: &post}, +func MakeBskyPost(cs *oauth.ClientSession, text string, ctx context.Context) error { + c := cs.APIClient() + body := map[string]any{ + "repo": *c.AccountDID, + "collection": "app.bsky.feed.post", + "record": map[string]any{ + "$type": "app.bsky.feed.post", + "text": text, + "createdAt": syntax.DatetimeNow(), + }, } - var out atproto.RepoCreateRecord_Output - err = c.xrpc.Do(ctx, authargs, "POST", "application/json", "com.atproto.repo.createRecord", nil, input, &out) + err := c.Post(ctx, "com.atproto.repo.createRecord", body, nil) if err != nil { - return errors.New("oops! failed to make post: " + err.Error()) + return errors.New("failed to tweet: " + err.Error()) } return nil } -func (c *OauthXRPCClient) CreateXCVRProfile(profile *lex.ProfileRecord, ctx context.Context) (p *lex.ProfileRecord, err error) { - authargs, err := c.getOauthSessionAuthArgs() +func CreateXCVRProfile(cs *oauth.ClientSession, profile *lex.ProfileRecord, ctx context.Context) (p *lex.ProfileRecord, err error) { + c := cs.APIClient() + nsid, err := syntax.ParseNSID("com.atproto.repo.getRecord") if err != nil { - err = errors.New("failed to get oauthsessionauthargs while making post: " + err.Error()) - return + return nil, errors.New("failed to parse: " + err.Error()) } - getOut, err := getProfileRecord(authargs.PdsUrl, authargs.Did, ctx) + var getOut atproto.RepoGetRecord_Output + err = c.Get(ctx, nsid, nil, &getOut) if err == nil { if getOut.Cid != nil { var jsonBytes []byte @@ -105,15 +63,14 @@ func (c *OauthXRPCClient) CreateXCVRProfile(profile *lex.ProfileRecord, ctx cont return &pro, nil } } - rkey := "self" - input := atproto.RepoCreateRecord_Input{ - Collection: "org.xcvr.actor.profile", - Repo: authargs.Did, - Rkey: &rkey, - Record: &util.LexiconTypeDecoder{Val: profile}, + body := map[string]any{ + "collection": "org.xcvr.actor.profile", + "repo": *c.AccountDID, + "rkey": "self", + "record": profile, } var out atproto.RepoCreateRecord_Output - err = c.xrpc.Do(ctx, authargs, "POST", "application/json", "com.atproto.repo.createRecord", nil, input, &out) + err = c.Post(ctx, "com.atproto.repo.createRecord", body, out) if err != nil { err = errors.New("oops! failed to create a profile: " + err.Error()) return @@ -121,21 +78,17 @@ func (c *OauthXRPCClient) CreateXCVRProfile(profile *lex.ProfileRecord, ctx cont return profile, nil } -func (c *OauthXRPCClient) CreateXCVRChannel(channel *lex.ChannelRecord, ctx context.Context) (uri string, cid string, err error) { - authargs, err := c.getOauthSessionAuthArgs() - if err != nil { - err = errors.New("yikers! couldn't createXCVRChannel: " + err.Error()) - return - } - input := atproto.RepoCreateRecord_Input{ - Collection: "org.xcvr.feed.channel", - Repo: authargs.Did, - Record: &util.LexiconTypeDecoder{Val: channel}, +func CreateXCVRChannel(cs *oauth.ClientSession, channel *lex.ChannelRecord, ctx context.Context) (uri string, cid string, err error) { + c := cs.APIClient() + body := map[string]any{ + "collection": "org.xcvr.actor.profile", + "repo": *c.AccountDID, + "record": channel, } var out atproto.RepoCreateRecord_Output - err = c.xrpc.Do(ctx, authargs, "POST", "application/json", "com.atproto.repo.createRecord", nil, input, &out) + err = c.Post(ctx, "com.atproto.repo.createRecord", body, out) if err != nil { - err = errors.New("that's not good! failed to create a XCVRChannel: " + err.Error()) + err = errors.New("oops! failed to create a profile: " + err.Error()) return } uri = out.Uri @@ -143,21 +96,17 @@ func (c *OauthXRPCClient) CreateXCVRChannel(channel *lex.ChannelRecord, ctx cont return } -func (c *OauthXRPCClient) CreateXCVRMessage(message *lex.MessageRecord, ctx context.Context) (uri string, cid string, err error) { - authargs, err := c.getOauthSessionAuthArgs() - if err != nil { - err = errors.New("uh oh... I couldn't make a XCVRMessage: " + err.Error()) - return - } - input := atproto.RepoCreateRecord_Input{ - Collection: "org.xcvr.lrc.message", - Repo: authargs.Did, - Record: &util.LexiconTypeDecoder{Val: message}, +func CreateXCVRMessage(cs *oauth.ClientSession, message *lex.MessageRecord, ctx context.Context) (uri string, cid string, err error) { + c := cs.APIClient() + body := map[string]any{ + "collection": "org.xcvr.actor.profile", + "repo": *c.AccountDID, + "record": message, } var out atproto.RepoCreateRecord_Output - err = c.xrpc.Do(ctx, authargs, "POST", "application/json", "com.atproto.repo.createRecord", nil, input, &out) + err = c.Post(ctx, "com.atproto.repo.createRecord", body, out) if err != nil { - err = errors.New("i've got a bad feeling aobut this... failed to create XCVRMessage: " + err.Error()) + err = errors.New("oops! failed to create a message: " + err.Error()) return } uri = out.Uri @@ -165,38 +114,40 @@ func (c *OauthXRPCClient) CreateXCVRMessage(message *lex.MessageRecord, ctx cont return } -func (c *OauthXRPCClient) UpdateXCVRProfile(profile *lex.ProfileRecord, ctx context.Context) (p *lex.ProfileRecord, err error) { - authargs, err := c.getOauthSessionAuthArgs() +func UpdateXCVRProfile(cs *oauth.ClientSession, profile *lex.ProfileRecord, ctx context.Context) (p *lex.ProfileRecord, err error) { + c := cs.APIClient() + nsid, err := syntax.ParseNSID("com.atproto.repo.getRecord") if err != nil { - err = errors.New("failed to get oauthsessionauthargs while making post: " + err.Error()) - return + return nil, errors.New("failed to parse: " + err.Error()) } - getOut, err := getProfileRecord(authargs.PdsUrl, authargs.Did, ctx) - if err != nil { - err = errors.New("messed that up! " + err.Error()) - return - } - if getOut.Cid == nil { - return c.CreateXCVRProfile(profile, ctx) + var getOut atproto.RepoGetRecord_Output + err = c.Get(ctx, nsid, nil, &getOut) + if err == nil { + if getOut.Cid != nil { + var jsonBytes []byte + jsonBytes, err = json.Marshal(getOut.Value) + if err != nil { + return + } + var pro lex.ProfileRecord + err = json.Unmarshal(jsonBytes, &pro) + if err != nil { + return + } + return &pro, nil + } } - rkey := "self" - input := atproto.RepoPutRecord_Input{ - Collection: "org.xcvr.actor.profile", - Repo: authargs.Did, - Rkey: rkey, - Record: &util.LexiconTypeDecoder{Val: profile}, - SwapRecord: getOut.Cid, + body := map[string]any{ + "collection": "org.xcvr.actor.profile", + "repo": *c.AccountDID, + "rkey": "self", + "record": profile, } - var out atproto.RepoPutRecord_Output - err = c.xrpc.Do(ctx, authargs, "POST", "application/json", "com.atproto.repo.putRecord", nil, input, &out) + var out atproto.RepoCreateRecord_Output + err = c.Post(ctx, "com.atproto.repo.createRecord", body, out) if err != nil { - err = errors.New("oops! failed to update a profile: " + err.Error()) + err = errors.New("oops! failed to create a profile: " + err.Error()) return } return profile, nil } - -func getProfileRecord(pdsUrl string, did string, ctx context.Context) (*atproto.RepoGetRecord_Output, error) { - cli := client.NewAPIClient(pdsUrl) - return atproto.RepoGetRecord(ctx, cli, "", "org.xcvr.actor.profile", did, "self") -} diff --git a/server/internal/oauth/service.go b/server/internal/oauth/service.go index 93224d2..2ab01da 100644 --- a/server/internal/oauth/service.go +++ b/server/internal/oauth/service.go @@ -2,175 +2,36 @@ package oauth import ( "context" - "encoding/json" - "errors" - "fmt" - "net/http" - "rvcx/internal/atputils" - "rvcx/internal/types" - "time" + "net/url" + "rvcx/internal/db" - atoauth "github.com/haileyok/atproto-oauth-golang" - "github.com/haileyok/atproto-oauth-golang/helpers" - "github.com/lestrrat-go/jwx/v2/jwk" + "github.com/bluesky-social/indigo/atproto/auth/oauth" + "github.com/bluesky-social/indigo/atproto/syntax" ) type Service struct { - oauth *atoauth.Client - http *http.Client - keys *jwk.Key + app *oauth.ClientApp } -func NewService(httpClient *http.Client) (*Service, error) { - key, err := GetJWKS() +func NewService(store db.Store) (*Service, error) { + config := oauth.NewPublicConfig(getClientId(), getOauthCallback(), []string{"atproto", "transition:generic"}) + key, err := GetPrivateKey() if err != nil { return nil, err } - cid := getClientId() - cbu := getOauthCallback() - cli, err := atoauth.NewClient(atoauth.ClientArgs{ - ClientJwk: *key, - ClientId: cid, - RedirectUri: cbu, - }) - if err != nil { - return nil, err - } - return &Service{ - oauth: cli, - http: httpClient, - keys: key, - }, nil + err = config.SetClientSecret(key, "secret.key.name_") + app := oauth.NewClientApp(&config, store) + return &Service{app}, nil } -type CallbackParams struct { - Iss string - State string - Code string +func (s *Service) StartAuthFlow(ctx context.Context, identifier string) (redirectURL string, err error) { + return s.app.StartAuthFlow(ctx, identifier) } -func (s *Service) StartAuthFlow(ctx context.Context, handle string) (*types.OAuthRequest, *types.OauthFlowResult, error) { - did, err := atputils.GetDidFromHandle(ctx, handle) - if err != nil { - return nil, nil, errors.New("error resolving handle:" + err.Error()) - } - dpopPrivKey, err := helpers.GenerateKey(nil) - if err != nil { - return nil, nil, errors.New("error generating key:" + err.Error()) - } - dpopPrivKeyJson, err := json.Marshal(dpopPrivKey) - if err != nil { - return nil, nil, errors.New("error marshaling privkey to json:" + err.Error()) - } - parResp, metadata, service, err := s.makeOAuthRequest(ctx, did, handle, dpopPrivKey) - if err != nil { - return nil, nil, errors.New("error making oauth request:" + err.Error()) - } - oauthReq := types.OAuthRequest{ - AuthserverIss: metadata.Issuer, - State: parResp.State, - Did: did, - PkceVerifier: parResp.PkceVerifier, - DpopAuthServerNonce: parResp.DpopAuthserverNonce, - DpopPrivKey: string(dpopPrivKeyJson), - PdsUrl: service, - } - oauthFlowResult := types.OauthFlowResult{ - AuthzEndpoint: metadata.AuthorizationEndpoint, - State: parResp.State, - DID: did, - RequestUri: parResp.RequestUri, - } - return &oauthReq, &oauthFlowResult, nil - +func (s *Service) OauthCallback(ctx context.Context, params url.Values) (sessdata *oauth.ClientSessionData, err error) { + return s.app.ProcessCallback(ctx, params) } -func (s *Service) makeOAuthRequest(ctx context.Context, did string, handle string, dpop jwk.Key) (resp *atoauth.SendParAuthResponse, meta *atoauth.OauthAuthorizationMetadata, service string, err error) { - service, err = s.resolveService(ctx, did) - if err != nil { - err = errors.New("error resolving service:" + err.Error()) - return - } - authserver, err := s.oauth.ResolvePdsAuthServer(ctx, service) - if err != nil { - err = errors.New("error resolving pds service:" + err.Error()) - return - } - meta, err = s.oauth.FetchAuthServerMetadata(ctx, authserver) - if err != nil { - err = errors.New("error fetching " + authserver + " metadata:" + err.Error()) - return - } - resp, err = s.oauth.SendParAuthRequest(ctx, authserver, meta, handle, "atproto transition:generic", dpop) - if err != nil { - err = errors.New("error sending PAR auth request to " + authserver + " h: " + handle + err.Error()) - } - return -} - -func (s *Service) resolveService(ctx context.Context, did string) (string, error) { - return atputils.GetPDSFromDid(ctx, did, s.http) -} - -// func (s *Service) resolveHandle(handle string) (string, error) { -// params := url.Values{ -// "handle": []string{handle}, -// } -// reqUrl := "https://public.api.bsky.app/xrpc/com.atproto.identity.resolveHandle?" + params.Encode() -// resp, err := s.http.Get(reqUrl) -// if err != nil { -// return "", errors.New("error making handle -> did resolution request:" + err.Error()) -// } -// defer resp.Body.Close() -// -// type did struct { -// Did string -// } -// b, err := io.ReadAll(resp.Body) -// if err != nil { -// return "", errors.New("error reading handle -> did resolution response" + err.Error()) -// } -// var resDid did -// err = json.Unmarshal(b, &resDid) -// if err != nil { -// return "", errors.New("error unmarshaling resDid:" + err.Error()) -// } -// return resDid.Did, nil -// } - -func (s *Service) OauthCallback(ctx context.Context, oauthRequest *types.OAuthRequest, params CallbackParams) (*types.Session, error) { - jwk, err := helpers.ParseJWKFromBytes([]byte(oauthRequest.DpopPrivKey)) - if err != nil { - return nil, errors.New("error parsing jwk:" + err.Error()) - } - initialTokenResp, err := s.oauth.InitialTokenRequest(ctx, params.Code, params.Iss, oauthRequest.PkceVerifier, oauthRequest.DpopAuthServerNonce, jwk) - if err != nil { - return nil, errors.New("error in initialTokenRequest:" + err.Error()) - } - if initialTokenResp.Scope != "atproto transition:generic" { - return nil, errors.New(fmt.Sprintf("incorrect scope: %s", initialTokenResp.Scope)) - } - oauthSession := types.Session{ - OAuthRequest: *oauthRequest, - AccessToken: initialTokenResp.AccessToken, - RefreshToken: initialTokenResp.RefreshToken, - Expiration: time.Now().Add(time.Duration(int(time.Second) * int(initialTokenResp.ExpiresIn))), - } - return &oauthSession, nil -} - -func (s *Service) RefreshToken(ctx context.Context, session *types.Session) (newexpiry time.Time, err error) { - jwk, err := helpers.ParseJWKFromBytes([]byte(session.DpopPrivKey)) - if err != nil { - return - } - resp, err := s.oauth.RefreshTokenRequest(ctx, session.RefreshToken, session.AuthserverIss, session.DpopAuthServerNonce, jwk) - if err != nil { - return - } - session.AccessToken = resp.AccessToken - session.DpopAuthServerNonce = resp.DpopAuthserverNonce - session.RefreshToken = resp.RefreshToken - newexpiry = time.Now().Add(1 * time.Hour) - return +func (s *Service) ResumeSession(ctx context.Context, did syntax.DID, sessionId string) (sess *oauth.ClientSession, err error) { + return s.app.ResumeSession(ctx, did, sessionId) } diff --git a/server/internal/recordmanager/beep.go b/server/internal/recordmanager/beep.go index b580842..1eaa655 100644 --- a/server/internal/recordmanager/beep.go +++ b/server/internal/recordmanager/beep.go @@ -2,13 +2,19 @@ package recordmanager import ( "context" + "errors" + "github.com/bluesky-social/indigo/atproto/syntax" + "rvcx/internal/oauth" ) -func (rm *RecordManager) Beep(id int, ctx context.Context) error { - - client, err := rm.getClient(id, ctx) +func (rm *RecordManager) Beep(id string, did string, ctx context.Context) error { + sdid, err := syntax.ParseDID(did) + if err != nil { + return errors.New("aaaa bbeeeebpp : " + err.Error()) + } + client, err := rm.service.ResumeSession(ctx, sdid, id) if err != nil { return err } - return client.MakeBskyPost("beep_", ctx) + return oauth.MakeBskyPost(client, "beep_", ctx) } diff --git a/server/internal/recordmanager/channel.go b/server/internal/recordmanager/channel.go index 81cf32e..862f503 100644 --- a/server/internal/recordmanager/channel.go +++ b/server/internal/recordmanager/channel.go @@ -6,6 +6,7 @@ import ( "github.com/bluesky-social/indigo/atproto/syntax" "rvcx/internal/atputils" "rvcx/internal/lex" + "rvcx/internal/oauth" "rvcx/internal/types" "time" ) @@ -46,8 +47,8 @@ func (rm *RecordManager) PostMyChannel(ctx context.Context, pcr *types.PostChann return rm.postchannelflow(rm.createMyChannel(), ctx, pcr) } -func (rm *RecordManager) PostChannel(id int, udid string, ctx context.Context, pcr *types.PostChannelRequest) (did string, uri string, err error) { - return rm.postchannelflow(rm.createChannel(id, udid), ctx, pcr) +func (rm *RecordManager) PostChannel(sessionId string, udid string, ctx context.Context, pcr *types.PostChannelRequest) (did string, uri string, err error) { + return rm.postchannelflow(rm.createChannel(sessionId, udid), ctx, pcr) } func (rm *RecordManager) postchannelflow(f func(*lex.ChannelRecord, *time.Time, context.Context) (*types.Channel, error), ctx context.Context, pcr *types.PostChannelRequest) (did string, uri string, err error) { @@ -92,13 +93,17 @@ func (rm *RecordManager) updateChannelmodel(c *types.Channel) error { return rm.broadcaster.UpdateChannel(c) } -func (rm *RecordManager) createChannel(id int, did string) func(*lex.ChannelRecord, *time.Time, context.Context) (*types.Channel, error) { +func (rm *RecordManager) createChannel(sessionId string, did string) func(*lex.ChannelRecord, *time.Time, context.Context) (*types.Channel, error) { return func(lcr *lex.ChannelRecord, now *time.Time, ctx context.Context) (*types.Channel, error) { - client, err := rm.getClient(id, ctx) + sdid, err := syntax.ParseDID(did) + if err != nil { + return nil, err + } + client, err := rm.service.ResumeSession(ctx, sdid, sessionId) if err != nil { return nil, errors.New("couldn't get client") } - uri, cid, err := client.CreateXCVRChannel(lcr, ctx) + uri, cid, err := oauth.CreateXCVRChannel(client, lcr, ctx) if err != nil { return nil, errors.New("something bad probs happened when posting a channel " + err.Error()) } diff --git a/server/internal/recordmanager/message.go b/server/internal/recordmanager/message.go index c617461..df18bf8 100644 --- a/server/internal/recordmanager/message.go +++ b/server/internal/recordmanager/message.go @@ -8,6 +8,7 @@ import ( "os" "rvcx/internal/atputils" "rvcx/internal/lex" + "rvcx/internal/oauth" "rvcx/internal/types" "slices" "time" @@ -68,14 +69,14 @@ func (rm *RecordManager) checkInterference(m *types.Message, did string, ctx con return nil } -func (rm *RecordManager) PostMessage(id int, udid string, ctx context.Context, pmr *types.PostMessageRequest) error { +func (rm *RecordManager) PostMessage(sessionId string, udid string, ctx context.Context, pmr *types.PostMessageRequest) error { rm.log.Deprintln("validate") lmr, now, _, _, err := rm.validateMessage(pmr, ctx) if err != nil { return errors.New("failed to validate message: " + err.Error()) } rm.log.Deprintln("create") - m, err := rm.createMessage(id, udid, lmr, now, ctx) + m, err := rm.createMessage(udid, sessionId, lmr, now, ctx) if err != nil { return errors.New("failed to create message: " + err.Error()) } @@ -154,12 +155,16 @@ func (rm *RecordManager) createMyMessage(lmr *lex.MessageRecord, now *time.Time, return message, nil } -func (rm *RecordManager) createMessage(id int, did string, lmr *lex.MessageRecord, now *time.Time, ctx context.Context) (*types.Message, error) { - client, err := rm.getClient(id, ctx) +func (rm *RecordManager) createMessage(did string, sessionID string, lmr *lex.MessageRecord, now *time.Time, ctx context.Context) (*types.Message, error) { + sdid, err := syntax.ParseDID(did) + if err != nil { + return nil, errors.New(" error: " + err.Error()) + } + client, err := rm.service.ResumeSession(ctx, sdid, sessionID) if err != nil { return nil, errors.New("failed to get client: " + err.Error()) } - uri, cid, err := client.CreateXCVRMessage(lmr, ctx) + uri, cid, err := oauth.CreateXCVRMessage(client, lmr, ctx) if err != nil { return nil, errors.New("couldn't add to user repo: " + err.Error()) } diff --git a/server/internal/recordmanager/profile.go b/server/internal/recordmanager/profile.go index aef24ed..c50dc05 100644 --- a/server/internal/recordmanager/profile.go +++ b/server/internal/recordmanager/profile.go @@ -6,7 +6,11 @@ import ( "rvcx/internal/atputils" "rvcx/internal/db" "rvcx/internal/lex" + "rvcx/internal/oauth" "rvcx/internal/types" + + atoauth "github.com/bluesky-social/indigo/atproto/auth/oauth" + "github.com/bluesky-social/indigo/atproto/syntax" ) func (rm *RecordManager) AcceptProfile(p lex.ProfileRecord, did string, ctx context.Context) error { @@ -47,21 +51,21 @@ func convertToPu(p lex.ProfileRecord, did string) *db.ProfileUpdate { } } -func (rm *RecordManager) CreateInitialProfile(did string, id int, ctx context.Context) error { +func (rm *RecordManager) CreateInitialProfile(sessData *atoauth.ClientSessionData, ctx context.Context) error { nick := "wanderer" status := "just setting up my xcvr" color := uint64(3702605) - handle, err := rm.db.ResolveDid(did, ctx) + handle, err := rm.db.ResolveDid(sessData.AccountDID.String(), ctx) if err != nil { return errors.New("i couldn't find the handle, so i couldn't create default profile record. gootbye") } - p, err := rm.createProfile(&handle, &nick, &status, &color, id, ctx) + p, err := rm.createProfile(&handle, &nick, &status, &color, sessData, ctx) if err != nil { return errors.New("AAAAA error creating profile" + err.Error()) } rm.log.Deprintln("initializing profile....") - err = rm.db.InitializeProfile(did, p.DisplayName, p.DefaultNick, p.Status, p.Color, ctx) + err = rm.db.InitializeProfile(sessData.AccountDID.String(), p.DisplayName, p.DefaultNick, p.Status, p.Color, ctx) if err != nil { return errors.New("failed to initialize profile: " + err.Error()) } @@ -69,12 +73,20 @@ func (rm *RecordManager) CreateInitialProfile(did string, id int, ctx context.Co } -func (rm *RecordManager) PostProfile(did string, id int, ctx context.Context, p *types.PostProfileRequest) error { +func (rm *RecordManager) PostProfile(did string, sessionID string, ctx context.Context, p *types.PostProfileRequest) error { + sdid, err := syntax.ParseDID(did) + if err != nil { + return errors.New("bad: " + err.Error()) + } pu, err := rm.validateProfile(did, p) if err != nil { return errors.New("couldn't validate profile: " + err.Error()) } - err = rm.updateProfile(p.DisplayName, p.DefaultNick, p.Status, p.Color, id, ctx) + cs, err := rm.service.ResumeSession(ctx, sdid, sessionID) + if err != nil { + return errors.New("couldn't resume session: " + err.Error()) + } + err = rm.updateProfile(cs, p.DisplayName, p.DefaultNick, p.Status, p.Color, ctx) if err != nil { return errors.New("couldn't create profile: " + err.Error()) } @@ -93,36 +105,32 @@ func (rm *RecordManager) storeProfile(pu *db.ProfileUpdate, ctx context.Context) return nil } -func (rm *RecordManager) updateProfile(name *string, nick *string, status *string, color *uint64, id int, ctx context.Context) error { +func (rm *RecordManager) updateProfile(cs *atoauth.ClientSession, name *string, nick *string, status *string, color *uint64, ctx context.Context) error { profilerecord := &lex.ProfileRecord{ DisplayName: name, DefaultNick: nick, Status: status, Color: color, } - client, err := rm.getClient(id, ctx) - if err != nil { - return err - } - _, err = client.UpdateXCVRProfile(profilerecord, ctx) + _, err := oauth.UpdateXCVRProfile(cs, profilerecord, ctx) if err != nil { return err } return nil } -func (rm *RecordManager) createProfile(name *string, nick *string, status *string, color *uint64, id int, ctx context.Context) (*lex.ProfileRecord, error) { +func (rm *RecordManager) createProfile(name *string, nick *string, status *string, color *uint64, sessData *atoauth.ClientSessionData, ctx context.Context) (*lex.ProfileRecord, error) { profilerecord := &lex.ProfileRecord{ DisplayName: name, DefaultNick: nick, Status: status, Color: color, } - client, err := rm.getClient(id, ctx) + client, err := rm.service.ResumeSession(ctx, sessData.AccountDID, sessData.SessionID) if err != nil { return nil, err } - p, err := client.CreateXCVRProfile(profilerecord, ctx) + p, err := oauth.CreateXCVRProfile(client, profilerecord, ctx) if err != nil { return nil, errors.New("failed to create profile: " + err.Error()) } diff --git a/server/internal/recordmanager/recordmanager.go b/server/internal/recordmanager/recordmanager.go index 1451831..055f835 100644 --- a/server/internal/recordmanager/recordmanager.go +++ b/server/internal/recordmanager/recordmanager.go @@ -1,9 +1,6 @@ package recordmanager import ( - "context" - "errors" - "fmt" "rvcx/internal/db" "rvcx/internal/log" "rvcx/internal/oauth" @@ -22,59 +19,14 @@ type RecordManager struct { log *log.Logger db *db.Store myClient *oauth.PasswordClient - clientmap *oauth.ClientMap + service *oauth.Service broadcaster LexBroadcaster } func New(log *log.Logger, db *db.Store, myClient *oauth.PasswordClient, service *oauth.Service) *RecordManager { - clientmap := oauth.NewClientMap(service) - return &RecordManager{log, db, myClient, clientmap, nil} + return &RecordManager{log, db, myClient, service, nil} } func (rm *RecordManager) SetBroadcaster(b LexBroadcaster) { rm.broadcaster = b } - -func (rm *RecordManager) getClient(id int, ctx context.Context) (*oauth.OauthXRPCClient, error) { - cli, refreshed, err := rm.clientmap.Map(id, ctx) - if cli == nil { - rm.log.Deprintln("resetting client") - cli, err = rm.resetClient(id, ctx) - if err != nil { - return nil, err - } - return cli, nil - } - - if err != nil { - return nil, errors.New("error getting client: " + err.Error()) - } - if refreshed { - rm.log.Deprintln("refreshed") - rm.db.UpdateSession(id, cli.GetSession(), ctx) - } - - return cli, nil -} - -func (rm *RecordManager) resetClient(id int, ctx context.Context) (*oauth.OauthXRPCClient, error) { - session, err := rm.db.GetOauthSession(id, ctx) - if err != nil { - return nil, errors.New(fmt.Sprintf("errpr setting up session %d: %s", id, err.Error())) - } - return rm.setupClient(session), nil -} - -func (rm *RecordManager) setupClient(session *types.Session) *oauth.OauthXRPCClient { - client := oauth.NewOauthXRPCClient(rm.db, rm.log, session) - rm.clientmap.Append(session.ID, client, session.Expiration) - rm.log.Deprintf("appended cli %d", session.ID) - if client == nil { - rm.log.Println("client nil!") - } - return client -} - -// create - oauth -// store - db -// broadcast - channels model diff --git a/server/internal/recordmanager/session.go b/server/internal/recordmanager/session.go index 5a956f8..dc6ce96 100644 --- a/server/internal/recordmanager/session.go +++ b/server/internal/recordmanager/session.go @@ -3,13 +3,17 @@ package recordmanager import ( "context" "errors" + "github.com/bluesky-social/indigo/atproto/syntax" ) -func (rm *RecordManager) DeleteSession(id int, ctx context.Context) error { - err := rm.db.DeleteOauthSession(id, ctx) +func (rm *RecordManager) DeleteSession(did string, sessionID string, ctx context.Context) error { + sdid, err := syntax.ParseDID(did) + if err != nil { + return errors.New("beep boop : " + err.Error()) + } + err = rm.db.DeleteSession(ctx, sdid, sessionID) if err != nil { return errors.New("failed to delete session: " + err.Error()) } - rm.clientmap.Delete(id) return nil } -- 2.51.2