- feat(accounts): persist device links with opaque hashed tokens, list and revoke endpoints - feat(frontend): app shell, routing and landing page with the chat-command hero - feat(frontend): Cyrillic-first fonts (Unbounded, Onest, JetBrains Mono); add i18next and motion - docs: free mod, bilingual site, one-click download, theme editor, public profiles, rich landing in plans - feat(accounts): internal gRPC AuthenticateDevice guarded by internal key - feat(frontend): ru/en i18n with typed per-feature dictionaries and language switch - feat(accounts): GET /me profile endpoint - feat(gateway): scaffold crate with config validation and health check - feat(gateway): reverse proxy to accounts and configs services - feat(gateway): resolve identity once from access JWT or device token via gRPC - feat(gateway): per-route and global rate limits with Retry-After - feat(gateway): CORS for the site origin; docs for gateway and internal contract - feat(configs): scaffold service with schema, config validation and health check - feat(configs): four config slots per account with list, get and save - feat(configs): permanent share codes with regenerate and public load-by-code - feat(accounts): GetPublicProfiles gRPC for showcase author info - style(accounts,common): apply rustfmt to existing sources - feat(configs): public showcase with publish, browse, detail and copy-to-slot - feat(backend): public profile endpoint and showcase author filter - fix(gateway): silence clippy collapsible-if and needless-ref warnings - docs(backend): configs-service implemented; Подсистема 1 backend complete - feat(mod): add Optimize module skeleton with OptimizeState holder - feat(mod): gate glass blur behind Optimize no_glass knob - feat(mod): cut MotionBlur and DoF sample counts behind lite_post knob - feat(mod): trim procedural sky noise behind lite_sky knob - feat(mod): drop fade gradients and digit rolls behind lean_hud knob - docs(todo): mark Optimize module phase 9.2 complete - refactor(mod): drop dead Renderer2D compatibility shims - refactor(mod): prune unreachable Renderer2D overload towers - refactor(mod): remove unused Renderer2D overloads and imports - docs(todo): mark Renderer2D giant-splitting done (2179 to 1597) - refactor(mod): extract shader id constants from LoVisualRenderPipelines - docs(todo): record registry wave 2026-09-25 (Renderer2D, pipelines) - refactor(mod): move Renderer2D instance state into base class - refactor(mod): extract Renderer2DRounded drawing family - refactor(mod): extract Renderer2DPath connector and chamfer family - refactor(mod): extract Renderer2DShapes circle line and texture primitives - refactor(mod): extract Renderer2DGlass and Renderer2DItem families - refactor(mod): prune Renderer2D imports after facade split - docs(todo): record Renderer2D facade inheritance split (1597 to 475) - docs: easter eggs — .env honeypot, konami troll mode, devtools banner, IDDQD config, breakable 404 block, 418 teapot - feat(mod): introduce surface style system core (SurfaceStyle, StyleSpec, StyleConfig, SurfaceRenderer) - refactor(mod): delegate HudRenderUtil liquid glass draws to SurfaceRenderer (dedupe glass constants) - refactor(mod): route bespoke glass call sites through SurfaceRenderer.plateSpec - feat(mod): add Auto option to HUD bg effects via shared HudBgStyles resolution - feat(mod): flat fallback for no-glass optimize mode and persist global HUD config - feat(mod): default HUD bg effects to Auto so the global surface style drives widgets - feat(mod): add global cycle-style hotkey with surface style notification - feat(mod): add surface style swatch strip under the global style picker - feat(gateway): reject ambiguous paths and answer .env probes with a honeypot - fix(gateway): charge failed credentials against the rate limit, allow stale ones on /auth - feat(frontend): ClickGui theme pipeline generated from the mod, live site theming - feat(frontend): landing v2 hero — voxel/particle backdrop, live ClickGui, theme strip - docs(todo): drop the FPS A/B measurement from phase 9.3, close phase 9 - feat(gateway): answer /coffee with a 418 teapot - feat(frontend): land the rest of landing v2 — HUD, module wall, showcase, FAQ, footer - feat(frontend): one-click download from GitHub releases, changelog page, release CI - feat(frontend): theme editor with live ClickGui preview, mod-compatible export and share links - fix(frontend): landing HUD playground now shows real mod widgets (fps, coordinates, module list, keybinds, ping) - style(frontend): apply ClickGui glass effect to landing HUD playground widgets - fix(frontend): prevent color field row overflow in theme editor grid - fix(frontend): never attach stale bearer token to /auth/* requests - fix(configs): unpublish/publish can no longer bypass moderation - refactor(accounts): shrink auth/handlers.rs under the 250-line cap - fix(accounts): tolerate concurrent refresh without killing every session - fix(gateway): minor hardening from the backend review - feat(configs): IDDQD easter egg config
134 lines
4.5 KiB
Rust
134 lines
4.5 KiB
Rust
use axum::http::{HeaderMap, header::AUTHORIZATION};
|
|
use jsonwebtoken::{Algorithm, DecodingKey, EncodingKey, Header, Validation, decode, encode};
|
|
use serde::{Deserialize, Serialize};
|
|
use uuid::Uuid;
|
|
|
|
/// Distinguishes token purposes so a token kind can never be replayed as
|
|
/// another. Only access tokens are JWTs today; refresh/device tokens are
|
|
/// opaque secrets. The claim stays so future kinds remain distinguishable.
|
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
|
|
#[serde(rename_all = "lowercase")]
|
|
pub enum TokenType {
|
|
Access,
|
|
}
|
|
|
|
#[derive(Debug, Serialize, Deserialize)]
|
|
pub struct Claims {
|
|
pub sub: String,
|
|
pub exp: usize,
|
|
pub token_type: TokenType,
|
|
}
|
|
|
|
fn issue(account_id: Uuid, secret: &str, token_type: TokenType, ttl_seconds: i64) -> String {
|
|
let exp = (chrono::Utc::now() + chrono::Duration::seconds(ttl_seconds)).timestamp() as usize;
|
|
let claims = Claims {
|
|
sub: account_id.to_string(),
|
|
exp,
|
|
token_type,
|
|
};
|
|
encode(
|
|
&Header::new(Algorithm::HS256),
|
|
&claims,
|
|
&EncodingKey::from_secret(secret.as_bytes()),
|
|
)
|
|
.expect("encoding a well-formed Claims struct cannot fail")
|
|
}
|
|
|
|
pub fn issue_access_token(account_id: Uuid, secret: &str) -> String {
|
|
issue(account_id, secret, TokenType::Access, 15 * 60)
|
|
}
|
|
|
|
/// Returns the claims only if the signature, expiry AND token type all match.
|
|
/// HS256 is pinned explicitly (no algorithm confusion) and expiry leeway is 0.
|
|
pub fn verify_token(token: &str, secret: &str, expected: TokenType) -> Option<Claims> {
|
|
let mut validation = Validation::new(Algorithm::HS256);
|
|
validation.leeway = 0;
|
|
validation.set_required_spec_claims(&["exp", "sub"]);
|
|
let claims = decode::<Claims>(
|
|
token,
|
|
&DecodingKey::from_secret(secret.as_bytes()),
|
|
&validation,
|
|
)
|
|
.ok()?
|
|
.claims;
|
|
(claims.token_type == expected).then_some(claims)
|
|
}
|
|
|
|
/// The raw token from `Authorization: Bearer <token>`, if the header is
|
|
/// present, valid ASCII, uses the Bearer scheme and is non-empty.
|
|
pub fn bearer_token(headers: &HeaderMap) -> Option<&str> {
|
|
let value = headers.get(AUTHORIZATION)?.to_str().ok()?;
|
|
let token = value.strip_prefix("Bearer ")?.trim();
|
|
(!token.is_empty()).then_some(token)
|
|
}
|
|
|
|
#[cfg(test)]
|
|
mod tests {
|
|
use super::*;
|
|
|
|
#[test]
|
|
fn access_token_round_trips() {
|
|
let id = Uuid::new_v4();
|
|
let token = issue_access_token(id, "test-secret");
|
|
let claims = verify_token(&token, "test-secret", TokenType::Access).expect("should decode");
|
|
assert_eq!(claims.sub, id.to_string());
|
|
assert_eq!(claims.token_type, TokenType::Access);
|
|
}
|
|
|
|
#[test]
|
|
fn wrong_secret_fails_verify() {
|
|
let token = issue_access_token(Uuid::new_v4(), "test-secret");
|
|
assert!(verify_token(&token, "other-secret", TokenType::Access).is_none());
|
|
}
|
|
|
|
#[test]
|
|
fn garbage_token_fails_verify() {
|
|
assert!(verify_token("not.a.jwt", "test-secret", TokenType::Access).is_none());
|
|
}
|
|
|
|
#[test]
|
|
fn expired_token_fails_verify() {
|
|
let token = issue(Uuid::new_v4(), "test-secret", TokenType::Access, -10);
|
|
assert!(verify_token(&token, "test-secret", TokenType::Access).is_none());
|
|
}
|
|
|
|
#[test]
|
|
fn token_signed_with_other_algorithm_is_rejected() {
|
|
let claims = Claims {
|
|
sub: Uuid::new_v4().to_string(),
|
|
exp: (chrono::Utc::now().timestamp() + 600) as usize,
|
|
token_type: TokenType::Access,
|
|
};
|
|
let hs512 = encode(
|
|
&Header::new(Algorithm::HS512),
|
|
&claims,
|
|
&EncodingKey::from_secret(b"test-secret"),
|
|
)
|
|
.unwrap();
|
|
assert!(verify_token(&hs512, "test-secret", TokenType::Access).is_none());
|
|
}
|
|
|
|
#[test]
|
|
fn bearer_token_extracts_the_token() {
|
|
let mut h = HeaderMap::new();
|
|
h.insert(AUTHORIZATION, "Bearer abc.def".parse().unwrap());
|
|
assert_eq!(bearer_token(&h), Some("abc.def"));
|
|
}
|
|
|
|
#[test]
|
|
fn bearer_token_rejects_missing_wrong_scheme_and_empty() {
|
|
let mut h = HeaderMap::new();
|
|
assert_eq!(bearer_token(&h), None);
|
|
h.insert(AUTHORIZATION, "Basic abc".parse().unwrap());
|
|
assert_eq!(bearer_token(&h), None);
|
|
h.insert(AUTHORIZATION, "Bearer ".parse().unwrap());
|
|
assert_eq!(bearer_token(&h), None);
|
|
}
|
|
|
|
#[test]
|
|
fn bearer_token_passes_opaque_value_through() {
|
|
let mut h = HeaderMap::new();
|
|
h.insert(AUTHORIZATION, "Bearer not.a.jwt".parse().unwrap());
|
|
assert_eq!(bearer_token(&h), Some("not.a.jwt"));
|
|
}
|
|
}
|