Something went wrong. Try again.
Monorepo for Tangled tangled.org
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354import { Client, ok } from "@atcute/client";import { mainSchema as getServiceAuthSchema } from "@atcute/atproto/types/server/getServiceAuth";import { isDid, isNsid, type AtprotoAudience, type Nsid } from "@atcute/lexicons/syntax";import type { OAuthUserAgent } from "@atcute/oauth-browser-client";
export const createClient = (agent: OAuthUserAgent, proxy?: AtprotoAudience): Client => new Client({ handler: agent, proxy: proxy ?? null });
const nsidOf = (lxm: string): Nsid => { if (!isNsid(lxm)) throw new Error(`invalid nsid: ${lxm}`); return lxm;};
export interface ServiceAuthOptions { // service did for the jwt aud claim aud: string; lxm: string; // clamped to at least 60s, matching appview's service client. expiresInSeconds?: number; signal?: AbortSignal;}
// pds refuses did:web:https%3A//host as an invalid didconst hostOf = (hostOrUrl: string): string => /^[a-z][a-z0-9+.-]*:\/\//i.test(hostOrUrl) ? new URL(hostOrUrl).host : hostOrUrl.replace(/\/+$/, "");
// did:web service id, with ports percent-encoded like serviceauth didweb.export const serviceDidForHost = (hostOrUrl: string): string => `did:web:${hostOf(hostOrUrl).replace(/:/g, "%3A")}`;
export const hostForServiceDid = (did: string): string | null => { if (!isDid(did) || !did.startsWith("did:web:")) return null; const encoded = did.slice("did:web:".length); if (/%(?![0-9A-Fa-f]{2})/.test(encoded)) return null; const host = encoded.replace(/%3A/gi, ":").replace(/\.+$/, "").toLowerCase(); return host || null;};
// mint a service-auth jwt for knot/spindle xrpc calls.export const mintServiceAuth = async ( agent: OAuthUserAgent, { aud, lxm, expiresInSeconds = 60, signal }: ServiceAuthOptions): Promise<string> => { const client = createClient(agent); const exp = Math.floor(Date.now() / 1000) + Math.max(expiresInSeconds, 60); const { token } = await ok( client.call(getServiceAuthSchema, { params: { aud, exp, lxm: nsidOf(lxm) }, signal }) ); return token;};