mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-08-28 12:02:35 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dab4940ace | ||
|
|
c7178e0a2b | ||
|
|
0261f121e8 | ||
|
|
93dc1008ee |
@@ -51,7 +51,7 @@ func (h *Handler) ParseParameters(r *http.Request) *RequestParameters {
|
|||||||
FieldFilters: make(map[string]string),
|
FieldFilters: make(map[string]string),
|
||||||
SearchFilters: make(map[string]string),
|
SearchFilters: make(map[string]string),
|
||||||
SearchOps: make(map[string]FilterOperator),
|
SearchOps: make(map[string]FilterOperator),
|
||||||
Limit: 20, // Default limit
|
Limit: 100000, // Default limit
|
||||||
Offset: 0, // Default offset
|
Offset: 0, // Default offset
|
||||||
ResponseFormat: "simple", // Default format
|
ResponseFormat: "simple", // Default format
|
||||||
ComplexAPI: false, // Default to simple API
|
ComplexAPI: false, // Default to simple API
|
||||||
|
|||||||
@@ -551,11 +551,27 @@ func (a *DatabaseAuthenticator) RefreshToken(ctx context.Context, refreshToken s
|
|||||||
return nil, fmt.Errorf("failed to parse user context: %w", err)
|
return nil, fmt.Errorf("failed to parse user context: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
return &LoginResponse{
|
// A resolvespec_refresh_token implementation that issues its own rotating
|
||||||
|
// refresh token (independent of the access/session token) returns it
|
||||||
|
// under claims.refresh_token, since UserContext has no dedicated field
|
||||||
|
// for it. Surface that into LoginResponse.RefreshToken so callers don't
|
||||||
|
// need to reach into User.Claims themselves. claims.expires_in
|
||||||
|
// (seconds) similarly overrides the default access-token ExpiresIn when
|
||||||
|
// the procedure provides a real value. Implementations that don't set
|
||||||
|
// these claims keep today's behavior unchanged (empty RefreshToken,
|
||||||
|
// 24h ExpiresIn default).
|
||||||
|
resp := &LoginResponse{
|
||||||
Token: userCtx.SessionID, // New session token from stored procedure
|
Token: userCtx.SessionID, // New session token from stored procedure
|
||||||
User: &userCtx,
|
User: &userCtx,
|
||||||
ExpiresIn: int64(24 * time.Hour.Seconds()),
|
ExpiresIn: int64(24 * time.Hour.Seconds()),
|
||||||
}, nil
|
}
|
||||||
|
if refreshToken, ok := userCtx.Claims["refresh_token"].(string); ok && refreshToken != "" {
|
||||||
|
resp.RefreshToken = refreshToken
|
||||||
|
}
|
||||||
|
if expiresIn, ok := userCtx.Claims["expires_in"].(float64); ok && expiresIn > 0 {
|
||||||
|
resp.ExpiresIn = int64(expiresIn)
|
||||||
|
}
|
||||||
|
return resp, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// JWTAuthenticator provides JWT token-based authentication
|
// JWTAuthenticator provides JWT token-based authentication
|
||||||
@@ -912,8 +928,20 @@ func (p *DatabaseRowSecurityProvider) GetRowSecurity(ctx context.Context, userRe
|
|||||||
return RowSecurity{}, ErrDirectModeUnsupported
|
return RowSecurity{}, ErrDirectModeUnsupported
|
||||||
}
|
}
|
||||||
|
|
||||||
var template string
|
// resolvespec_row_security's p_user_id is a scalar integer. GetUserRef() may
|
||||||
var hasBlock bool
|
// hand back the full *UserContext so non-DB providers can inspect claims;
|
||||||
|
// unwrap it here before it reaches the SQL args.
|
||||||
|
switch v := userRef.(type) {
|
||||||
|
case *UserContext:
|
||||||
|
if v != nil {
|
||||||
|
userRef = v.UserID
|
||||||
|
}
|
||||||
|
case UserContext:
|
||||||
|
userRef = v.UserID
|
||||||
|
}
|
||||||
|
|
||||||
|
var template sql.NullString
|
||||||
|
var hasBlock sql.NullBool
|
||||||
|
|
||||||
runQuery := func() error {
|
runQuery := func() error {
|
||||||
query := fmt.Sprintf(`SELECT p_template, p_block FROM %s($1, $2, $3)`, p.sqlNames.RowSecurity)
|
query := fmt.Sprintf(`SELECT p_template, p_block FROM %s($1, $2, $3)`, p.sqlNames.RowSecurity)
|
||||||
@@ -933,8 +961,8 @@ func (p *DatabaseRowSecurityProvider) GetRowSecurity(ctx context.Context, userRe
|
|||||||
Schema: schema,
|
Schema: schema,
|
||||||
Tablename: table,
|
Tablename: table,
|
||||||
UserID: userRef,
|
UserID: userRef,
|
||||||
Template: template,
|
Template: template.String,
|
||||||
HasBlock: hasBlock,
|
HasBlock: hasBlock.Bool,
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -793,6 +793,49 @@ func TestDatabaseAuthenticatorRefreshToken(t *testing.T) {
|
|||||||
t.Errorf("unfulfilled expectations: %v", err)
|
t.Errorf("unfulfilled expectations: %v", err)
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
|
|
||||||
|
// A resolvespec_refresh_token implementation that rotates its own
|
||||||
|
// independent refresh token (not just reusing the session/access token)
|
||||||
|
// has nowhere else to put the new refresh token and real access-token
|
||||||
|
// expiry than under UserContext.Claims, since UserContext has no
|
||||||
|
// dedicated fields for either. RefreshToken must surface those claims
|
||||||
|
// keys into LoginResponse.RefreshToken/ExpiresIn rather than silently
|
||||||
|
// dropping them (see the "successful token refresh" case above, which
|
||||||
|
// covers an implementation that has no independent refresh token at all
|
||||||
|
// and gets the 24h default instead).
|
||||||
|
t.Run("surfaces rotated refresh token and expiry from claims", func(t *testing.T) {
|
||||||
|
refreshToken := "refresh-token-abc"
|
||||||
|
|
||||||
|
sessionRows := sqlmock.NewRows([]string{"p_success", "p_error", "p_user"}).
|
||||||
|
AddRow(true, nil, `{"user_id":1,"user_name":"testuser"}`)
|
||||||
|
mock.ExpectQuery(`SELECT p_success, p_error, p_user::text FROM resolvespec_session`).
|
||||||
|
WithArgs(refreshToken, "refresh").
|
||||||
|
WillReturnRows(sessionRows)
|
||||||
|
|
||||||
|
refreshRows := sqlmock.NewRows([]string{"p_success", "p_error", "p_user"}).
|
||||||
|
AddRow(true, nil, `{"user_id":1,"user_name":"testuser","session_id":"new-access-789","claims":{"refresh_token":"new-refresh-def","expires_in":900}}`)
|
||||||
|
mock.ExpectQuery(`SELECT p_success, p_error, p_user::text FROM resolvespec_refresh_token`).
|
||||||
|
WithArgs(refreshToken, sqlmock.AnyArg()).
|
||||||
|
WillReturnRows(refreshRows)
|
||||||
|
|
||||||
|
resp, err := auth.RefreshToken(ctx, refreshToken)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("expected no error, got %v", err)
|
||||||
|
}
|
||||||
|
if resp.Token != "new-access-789" {
|
||||||
|
t.Errorf("expected token new-access-789, got %s", resp.Token)
|
||||||
|
}
|
||||||
|
if resp.RefreshToken != "new-refresh-def" {
|
||||||
|
t.Errorf("expected rotated refresh token new-refresh-def, got %q", resp.RefreshToken)
|
||||||
|
}
|
||||||
|
if resp.ExpiresIn != 900 {
|
||||||
|
t.Errorf("expected ExpiresIn 900 from claims, got %d", resp.ExpiresIn)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := mock.ExpectationsWereMet(); err != nil {
|
||||||
|
t.Errorf("unfulfilled expectations: %v", err)
|
||||||
|
}
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestDatabaseAuthenticatorReconnectsClosedDBPaths(t *testing.T) {
|
func TestDatabaseAuthenticatorReconnectsClosedDBPaths(t *testing.T) {
|
||||||
|
|||||||
Reference in New Issue
Block a user