2023-08-14 07:38:37 +02:00
|
|
|
use std::sync::Arc;
|
|
|
|
|
2023-08-30 22:53:12 +02:00
|
|
|
use actix_jwt_session::*;
|
|
|
|
use actix_web::http::{Method, StatusCode};
|
2023-08-14 12:30:32 +02:00
|
|
|
use actix_web::web::{Data, Json};
|
2023-08-14 07:38:37 +02:00
|
|
|
use actix_web::HttpResponse;
|
2023-08-14 12:30:32 +02:00
|
|
|
use actix_web::{get, post};
|
2023-08-14 07:38:37 +02:00
|
|
|
use actix_web::{http::header::ContentType, test, App};
|
|
|
|
use jsonwebtoken::*;
|
|
|
|
use serde::{Deserialize, Serialize};
|
|
|
|
use uuid::Uuid;
|
|
|
|
|
|
|
|
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq)]
|
|
|
|
struct Claims {
|
|
|
|
id: Uuid,
|
2023-08-17 08:07:11 +02:00
|
|
|
subject: String,
|
2023-08-14 07:38:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
impl actix_jwt_session::Claims for Claims {
|
|
|
|
fn jti(&self) -> Uuid {
|
|
|
|
self.id
|
|
|
|
}
|
2023-08-17 08:07:11 +02:00
|
|
|
fn subject(&self) -> &str {
|
|
|
|
&self.subject
|
|
|
|
}
|
2023-08-14 07:38:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
#[tokio::test(flavor = "multi_thread")]
|
|
|
|
async fn not_authenticated() {
|
|
|
|
let redis = {
|
|
|
|
use redis_async_pool::{RedisConnectionManager, RedisPool};
|
|
|
|
RedisPool::new(
|
|
|
|
RedisConnectionManager::new(
|
|
|
|
redis::Client::open("redis://localhost:6379").expect("Fail to connect to redis"),
|
|
|
|
true,
|
|
|
|
None,
|
|
|
|
),
|
|
|
|
5,
|
|
|
|
)
|
|
|
|
};
|
|
|
|
|
2023-08-30 22:53:12 +02:00
|
|
|
let keys = JwtSigningKeys::generate(false).unwrap();
|
|
|
|
let (storage, factory) = RedisMiddlewareFactory::<Claims>::build(
|
2023-08-14 12:30:32 +02:00
|
|
|
Arc::new(keys.encoding_key),
|
2023-08-14 07:38:37 +02:00
|
|
|
Arc::new(keys.decoding_key),
|
2023-08-14 12:30:32 +02:00
|
|
|
Algorithm::EdDSA,
|
2023-08-30 22:53:12 +02:00
|
|
|
)
|
|
|
|
.with_pool(redis.clone())
|
|
|
|
.with_jwt_header(JWT_HEADER_NAME)
|
|
|
|
.with_refresh_header(REFRESH_HEADER_NAME)
|
|
|
|
.with_jwt_cookie(JWT_COOKIE_NAME)
|
|
|
|
.with_refresh_cookie(REFRESH_COOKIE_NAME)
|
|
|
|
.finish();
|
2023-08-14 07:38:37 +02:00
|
|
|
|
|
|
|
let app = App::new()
|
2023-08-30 22:53:12 +02:00
|
|
|
.app_data(Data::new(storage.clone()))
|
2023-08-14 07:38:37 +02:00
|
|
|
.wrap(factory.clone())
|
|
|
|
.app_data(Data::new(redis.clone()))
|
2023-08-30 22:53:12 +02:00
|
|
|
.app_data(Data::new(JwtTtl(Duration::days(10))))
|
|
|
|
.app_data(Data::new(RefreshTtl(Duration::days(10))))
|
2023-08-14 07:38:37 +02:00
|
|
|
.service(sign_in)
|
|
|
|
.service(sign_out)
|
|
|
|
.service(session)
|
|
|
|
.service(root);
|
|
|
|
|
|
|
|
let app = actix_web::test::init_service(app).await;
|
|
|
|
|
2023-08-14 12:30:32 +02:00
|
|
|
let res = test::call_service(
|
|
|
|
&app,
|
|
|
|
test::TestRequest::default()
|
|
|
|
.insert_header(ContentType::plaintext())
|
|
|
|
.to_request(),
|
|
|
|
)
|
|
|
|
.await;
|
2023-08-14 07:38:37 +02:00
|
|
|
assert!(res.status().is_success());
|
|
|
|
|
2023-08-14 12:30:32 +02:00
|
|
|
let res = test::call_service(
|
|
|
|
&app,
|
|
|
|
test::TestRequest::default()
|
|
|
|
.uri("/s")
|
|
|
|
.insert_header(ContentType::plaintext())
|
|
|
|
.to_request(),
|
|
|
|
)
|
|
|
|
.await;
|
|
|
|
assert_eq!(res.status(), StatusCode::UNAUTHORIZED);
|
|
|
|
|
2023-08-18 21:52:30 +02:00
|
|
|
let origina_claims = Claims {
|
|
|
|
id: Uuid::new_v4(),
|
|
|
|
subject: "foo".to_string(),
|
|
|
|
};
|
2023-08-14 12:30:32 +02:00
|
|
|
let res = test::call_service(
|
|
|
|
&app,
|
|
|
|
test::TestRequest::default()
|
|
|
|
.uri("/in")
|
|
|
|
.method(actix_web::http::Method::POST)
|
|
|
|
.insert_header(ContentType::json())
|
|
|
|
.set_json(&origina_claims)
|
|
|
|
.to_request(),
|
|
|
|
)
|
|
|
|
.await;
|
|
|
|
assert_eq!(res.status(), StatusCode::OK);
|
2023-08-30 22:53:12 +02:00
|
|
|
let auth_bearer = res
|
|
|
|
.headers()
|
|
|
|
.get(JWT_HEADER_NAME)
|
|
|
|
.unwrap()
|
|
|
|
.to_str()
|
|
|
|
.unwrap();
|
|
|
|
let refresh_bearer = res
|
|
|
|
.headers()
|
|
|
|
.get(REFRESH_HEADER_NAME)
|
|
|
|
.unwrap()
|
|
|
|
.to_str()
|
|
|
|
.unwrap();
|
|
|
|
|
|
|
|
let res = test::call_service(
|
|
|
|
&app,
|
|
|
|
test::TestRequest::default()
|
|
|
|
.uri("/s")
|
|
|
|
.method(Method::GET)
|
|
|
|
.insert_header((JWT_HEADER_NAME, auth_bearer))
|
|
|
|
.to_request(),
|
|
|
|
)
|
|
|
|
.await;
|
|
|
|
assert_eq!(res.status(), StatusCode::OK);
|
|
|
|
|
|
|
|
let res = test::call_service(
|
|
|
|
&app,
|
|
|
|
test::TestRequest::default()
|
|
|
|
.uri("/out")
|
|
|
|
.method(Method::POST)
|
|
|
|
.insert_header((JWT_HEADER_NAME, auth_bearer))
|
|
|
|
.to_request(),
|
|
|
|
)
|
|
|
|
.await;
|
|
|
|
assert_eq!(res.status(), StatusCode::OK);
|
|
|
|
|
|
|
|
let res = test::try_call_service(
|
|
|
|
&app,
|
|
|
|
test::TestRequest::default()
|
|
|
|
.uri("/s")
|
|
|
|
.method(Method::GET)
|
|
|
|
.insert_header((JWT_HEADER_NAME, auth_bearer))
|
|
|
|
.to_request(),
|
|
|
|
)
|
|
|
|
.await;
|
|
|
|
let err = res
|
|
|
|
.expect_err("Must be unauthorized")
|
|
|
|
.as_error::<actix_jwt_session::Error>()
|
|
|
|
.expect("Must be authorization error")
|
|
|
|
.clone();
|
|
|
|
assert_eq!(err, actix_jwt_session::Error::InvalidSession);
|
2023-08-14 07:38:37 +02:00
|
|
|
}
|
|
|
|
|
2023-08-14 12:30:32 +02:00
|
|
|
#[post("/in")]
|
|
|
|
async fn sign_in(
|
2023-08-30 22:53:12 +02:00
|
|
|
store: Data<SessionStorage>,
|
2023-08-14 12:30:32 +02:00
|
|
|
claims: Json<Claims>,
|
2023-08-30 22:53:12 +02:00
|
|
|
jwt_ttl: Data<JwtTtl>,
|
|
|
|
refresh_ttl: Data<RefreshTtl>,
|
2023-08-14 12:30:32 +02:00
|
|
|
) -> Result<HttpResponse, actix_web::Error> {
|
|
|
|
let claims = claims.into_inner();
|
|
|
|
let store = store.into_inner();
|
2023-08-30 22:53:12 +02:00
|
|
|
let pair = store
|
2023-08-14 12:30:32 +02:00
|
|
|
.clone()
|
2023-08-30 22:53:12 +02:00
|
|
|
.store(claims, *jwt_ttl.into_inner(), *refresh_ttl.into_inner())
|
2023-08-14 12:30:32 +02:00
|
|
|
.await
|
|
|
|
.unwrap();
|
2023-08-30 22:53:12 +02:00
|
|
|
Ok(HttpResponse::Ok()
|
|
|
|
.append_header((JWT_HEADER_NAME, pair.jwt.encode().unwrap()))
|
|
|
|
.append_header((REFRESH_HEADER_NAME, pair.refresh.encode().unwrap()))
|
|
|
|
.finish())
|
2023-08-14 07:38:37 +02:00
|
|
|
}
|
|
|
|
|
2023-08-14 12:30:32 +02:00
|
|
|
#[post("/out")]
|
2023-08-30 22:53:12 +02:00
|
|
|
async fn sign_out(store: Data<SessionStorage>, auth: Authenticated<Claims>) -> HttpResponse {
|
|
|
|
let store = store.into_inner();
|
|
|
|
store.erase::<Claims>(auth.id).await.unwrap();
|
|
|
|
HttpResponse::Ok().finish()
|
2023-08-14 07:38:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
#[get("/s")]
|
|
|
|
async fn session(auth: Authenticated<Claims>) -> HttpResponse {
|
|
|
|
HttpResponse::Ok().json(&*auth)
|
|
|
|
}
|
|
|
|
|
|
|
|
#[get("/")]
|
|
|
|
async fn root() -> HttpResponse {
|
2023-08-30 22:53:12 +02:00
|
|
|
HttpResponse::Ok().finish()
|
2023-08-14 07:38:37 +02:00
|
|
|
}
|