diff --git a/shared/challenges_markdown/six/part_two.md b/shared/challenges_markdown/six/part_two.md index 58b92f6..f3a37fe 100644 --- a/shared/challenges_markdown/six/part_two.md +++ b/shared/challenges_markdown/six/part_two.md @@ -1,18 +1,25 @@ -## XRPC Service Proxying +Most atproto endpoints use something called [XRPC](https://atproto.com/specs/xrpc), you've probably seen it in something +like this URL to get a Bluesky profile of +someone [https://public.api.bsky.app/xrpc/app.bsky.actor.getProfile?actor=jcsalterego.bsky.social](https://public.api.bsky.app/xrpc/app.bsky.actor.getProfile?actor=jcsalterego.bsky.social). +In short XRPC is a way to write HTTP endpoints that can be defined by +a [lexicon schema](https://atproto.com/specs/lexicon#query-and-procedure-http-api) so you know what data is returned +from the endpoint, what type of request, parmeters, errors, etc. And since this is all defined in a lexicon schema you +can generate a client from it as well. -Now that you can create a serviceAuth JWT, let's use it in an actual XRPC request. +With XRPC you can also do something called [Service Proxying](https://atproto.com/specs/xrpc#service-proxying) which +means if you call the XRPC endpoint on your PDS while authenicated with the `atproto-proxy` header with the did and the +service like so `did:web:labeler.example.com#atproto_labeler` it looks up the service and proxies the request to the +service with a serviceAuth JWT set as the bearer. -Make an HTTP GET request to our XRPC endpoint with your JWT in the `Authorization` header: +For example, this is how Bluesky DMs work -``` -GET https://{{service_did_domain}}/xrpc/codes.advent.challenge.getDay6Code -Authorization: Bearer -``` +- On requests to the PDS for DMs there is an `atproto-proxy` header that looks like + `did:web:api.bsky.chat#bsky_chat`. +- When you call the PDS it takes the URL from the `did:web` to find a did doc at + `https://api.bsky.chat/.well-known/did.json` +- It then looks up the service `bsky_chat` in the did doc andthen proxies the web request to the `serviceEndpoint` + listed there. +- It then proxies the request to the service with the serviceAuth JWT set as the bearer. -Your JWT for this request must have: -- `iss`: Your DID -- `aud`: `{{service_did}}` -- `lxm`: `{{lxm_part_two}}` -- `exp`: A UNIX timestamp in the future - -The response will contain a JSON object with your verification code. Paste that code below. +Today's part two is for you to make a XRPC query request to the `codes.advent.challenge.getCode` XRPC endpoint to the +service `did:web:{{service_did_domain}}#advent` to get your verification code. diff --git a/web/src/main.rs b/web/src/main.rs index be3a5c8..e83f6fa 100644 --- a/web/src/main.rs +++ b/web/src/main.rs @@ -288,14 +288,14 @@ async fn main() -> Result<(), Box> { ) .route( "/day/3/upload-car", - post(handlers::custom::day_three::inspect_car) // 2MB max for default axum + post(handlers::custom::day_three::inspect_car), // 2MB max for default axum ) .route( "/day/5/{user_did}", get(handlers::custom::day_five::create_record_handler), ) .route( - "/xrpc/codes.advent.challenge.getChallengeCode", + "/xrpc/codes.advent.challenge.getCode", get(handlers::custom::day_six::xrpc_handler), ) .route( @@ -359,6 +359,9 @@ async fn home_handler(State(pool): State, session: AxumSessionStore) -> .unwrap_or(&CompletionStatus::None); if *prev_status == CompletionStatus::Both { unlocked.push(window[1]); + } else if (prev == 4 || prev == 5) && *prev_status == CompletionStatus::PartOne { + //HACK hardcoded for the workshop since we don't have a part 2 for day 4 + unlocked.push(window[1]); } else { break; } diff --git a/web/src/unlock.rs b/web/src/unlock.rs index ef81d14..572414f 100644 --- a/web/src/unlock.rs +++ b/web/src/unlock.rs @@ -63,6 +63,11 @@ pub async fn unlock( .map(|(_, s)| s) .unwrap_or(&CompletionStatus::None); + //HACK hardcoded for the workshop since we don't have a part 2 for day 4 + if (pos == 4 || pos == 5) && *prev_status == CompletionStatus::PartOne { + return next.run(request).await; + } + if *prev_status != CompletionStatus::Both { return ( http::StatusCode::FORBIDDEN,