From c2096710609335e7b79faacf49a37c9add36873d Mon Sep 17 00:00:00 2001 From: Will Date: Sun, 3 May 2026 16:07:30 +0100 Subject: [PATCH] print out the did from the request by resolving it check that the user did in the request is the same as the configured user did --- src/server.rs | 13 ++++++++++--- src/xrpc/routes.rs | 27 +++++++++++++++++++++++++-- 2 files changed, 35 insertions(+), 5 deletions(-) diff --git a/src/server.rs b/src/server.rs index d3ee88c..e4b4b40 100644 --- a/src/server.rs +++ b/src/server.rs @@ -29,6 +29,7 @@ use crate::xrpc::routes::{ pub struct ServerConfig { pub appview_did: String, pub appview_endpoint: String, + pub user_did: String, } pub async fn run_server() { @@ -41,17 +42,20 @@ pub async fn run_server() { let appview_did: String = std::env::var("APPVIEW_DID").expect("APPVIEW_DID missing"); let appview_endpoint = std::env::var("APPVIEW_HOSTNAME").expect("APPVIEW_HOSTNAME missing"); + let users_did = std::env::var("USERS_DID").expect("USERS_DID missing"); + let server_config = ServerConfig { appview_did: appview_did.clone(), appview_endpoint: appview_endpoint.clone(), + user_did: users_did, }; let service_did = Did::new_owned(appview_did).expect("APPVIEW_DID produced an invalid did:web"); let resolver = JacquardResolver::new(reqwest::Client::new(), ResolverOptions::default()); - let auth_config = ServiceAuthConfig::new(service_did, resolver); + let auth_config = ServiceAuthConfig::new(service_did, resolver.clone()); - let app_state = AppState::new(server_config, auth_config); + let app_state = AppState::new(server_config, auth_config, resolver.clone()); let app = Router::::new() .route("/", get(say_hello_text)) @@ -169,18 +173,21 @@ impl IntoResponse for XrpcErrorResponse { #[derive(Clone)] pub struct AppState { - server_config: ServerConfig, + pub server_config: ServerConfig, pub service_auth: ServiceAuthConfig, + pub resolver: JacquardResolver, } impl AppState { pub fn new( server_config: ServerConfig, service_auth: ServiceAuthConfig, + resolver: JacquardResolver, ) -> Self { Self { service_auth: service_auth, server_config: server_config, + resolver: resolver, } } } diff --git a/src/xrpc/routes.rs b/src/xrpc/routes.rs index b56e45f..e8f617b 100644 --- a/src/xrpc/routes.rs +++ b/src/xrpc/routes.rs @@ -1,6 +1,7 @@ use crate::server::AppState; use crate::server::XrpcErrorResponse; use axum::{Json, extract::State}; +use jacquard::types::string::AtIdentifier; use jacquard::xrpc::atproto::GetRecordOutput; use jacquard_api::app_bsky::actor::get_profile::GetProfileOutput; use jacquard_api::app_bsky::actor::get_profile::GetProfileRequest; @@ -12,14 +13,36 @@ use jacquard_api::app_bsky::feed::{ use jacquard_api::tools_ozone::moderation::get_record::GetRecordRequest; use jacquard_axum::ExtractXrpc; use jacquard_axum::service_auth::ExtractOptionalServiceAuth; +use jacquard_common::IntoStatic; +use jacquard_identity::resolver::IdentityResolver; use serde_json::Value; use serde_json::json; pub async fn app_bsky_actor_get_profile( - State(_): State, + State(state): State, ExtractOptionalServiceAuth(_auth): ExtractOptionalServiceAuth, - ExtractXrpc(_): ExtractXrpc, + ExtractXrpc(req): ExtractXrpc, ) -> Result>, XrpcErrorResponse> { + let did = match req.actor { + AtIdentifier::Did(did) => did.into_static(), + AtIdentifier::Handle(handle) => { + state + .resolver + .resolve_handle(&handle) + .await + .map_err(|err| { + println!("error resolving handle: {err}"); + XrpcErrorResponse::internal_server_error() + })? + } + }; + + if did.to_string() != state.server_config.user_did.to_string() { + println!("configured user did does not match request user did {did}"); + return Err(XrpcErrorResponse::internal_server_error()); + } + + println!("did is {did}"); return Err(XrpcErrorResponse::not_implemented()); } -- 2.51.2