diff --git a/.gitignore b/.gitignore index 4031274..e91c34a 100644 --- a/.gitignore +++ b/.gitignore @@ -1,5 +1,6 @@ .zig-cache/ zig-out/ +zig-pkg/ .env .env.* diff --git a/build.zig.zon b/build.zig.zon index 7b76975..b5963be 100644 --- a/build.zig.zon +++ b/build.zig.zon @@ -1,6 +1,6 @@ .{ .name = .zat, - .version = "0.3.0-alpha.6", + .version = "0.3.0-alpha.7", .fingerprint = 0x8da9db57ee82fbe4, .minimum_zig_version = "0.16.0", .dependencies = .{ diff --git a/src/internal/crypto/jwt.zig b/src/internal/crypto/jwt.zig index fd7db14..739db35 100644 --- a/src/internal/crypto/jwt.zig +++ b/src/internal/crypto/jwt.zig @@ -7,14 +7,13 @@ const std = @import("std"); const crypto = std.crypto; +const Io = std.Io; const json = @import("../xrpc/json.zig"); const multibase = @import("multibase.zig"); const multicodec = @import("multicodec.zig"); -fn timestamp() i64 { - var tv: std.c.timeval = undefined; - _ = std.c.gettimeofday(&tv, null); - return tv.sec; +fn timestamp(io: Io) i64 { + return @intCast(@divFloor(Io.Timestamp.now(io, .real).nanoseconds, std.time.ns_per_s)); } /// JWT signing algorithm @@ -145,14 +144,14 @@ pub const Jwt = struct { } /// check if the token is expired - pub fn isExpired(self: *const Jwt) bool { - const now = timestamp(); + pub fn isExpired(self: *const Jwt, io: Io) bool { + const now = timestamp(io); return now > self.payload.exp; } /// check if the token is expired with clock skew tolerance (in seconds) - pub fn isExpiredWithSkew(self: *const Jwt, skew_seconds: i64) bool { - const now = timestamp(); + pub fn isExpiredWithSkew(self: *const Jwt, io: Io, skew_seconds: i64) bool { + const now = timestamp(io); return now > (self.payload.exp + skew_seconds); } diff --git a/src/internal/oauth.zig b/src/internal/oauth.zig index bd1c3f9..cd6535d 100644 --- a/src/internal/oauth.zig +++ b/src/internal/oauth.zig @@ -7,14 +7,13 @@ const std = @import("std"); const crypto = std.crypto; +const Io = std.Io; const Allocator = std.mem.Allocator; const Keypair = @import("crypto/keypair.zig").Keypair; const jwt = @import("crypto/jwt.zig"); -fn timestamp() i64 { - var tv: std.c.timeval = undefined; - _ = std.c.gettimeofday(&tv, null); - return tv.sec; +fn timestamp(io: Io) i64 { + return @intCast(@divFloor(Io.Timestamp.now(io, .real).nanoseconds, std.time.ns_per_s)); } /// create a signed JWT from header and payload JSON strings. @@ -55,7 +54,7 @@ pub fn createDpopProof( defer allocator.free(jti); const alg = @tagName(keypair.algorithm()); - const now = timestamp(); + const now = timestamp(io); // header: {"typ":"dpop+jwt","alg":"...","jwk":{...}} const header = try std.fmt.allocPrint(allocator, @@ -99,7 +98,7 @@ pub fn createClientAssertion( defer allocator.free(kid); const alg = @tagName(keypair.algorithm()); - const now = timestamp(); + const now = timestamp(io); const header = try std.fmt.allocPrint(allocator, \\{{"typ":"JWT","alg":"{s}","kid":"{s}"}}