2019-04-05 09:57:14 +03:00
|
|
|
const concat = require('concat-stream');
|
|
|
|
const Cookies = require('cookies');
|
|
|
|
const jwt = require('jsonwebtoken');
|
|
|
|
const ignition = require('ghost-ignition');
|
|
|
|
|
|
|
|
const {
|
|
|
|
UnauthorizedError,
|
|
|
|
BadRequestError
|
|
|
|
} = ignition.errors;
|
|
|
|
|
|
|
|
const EMPTY = {};
|
|
|
|
const SIX_MONTHS_MS = 1000 * 60 * 60 * 24 * 184;
|
|
|
|
|
2019-05-06 13:23:24 +03:00
|
|
|
const withCookies = (fn, cookieConfig) => (req, res) => {
|
|
|
|
return new Promise((resolve) => {
|
|
|
|
const cookies = new Cookies(req, res, cookieConfig);
|
|
|
|
resolve(fn(req, res, {cookies}));
|
|
|
|
});
|
|
|
|
};
|
|
|
|
|
|
|
|
const withBodyAndCookies = (fn, cookieConfig) => (req, res) => {
|
2019-04-05 09:57:14 +03:00
|
|
|
return new Promise((resolve, reject) => {
|
|
|
|
const cookies = new Cookies(req, res, cookieConfig);
|
|
|
|
req.on('error', reject);
|
|
|
|
req.pipe(concat(function (buff) {
|
|
|
|
const body = buff.toString();
|
|
|
|
resolve(fn(req, res, {body, cookies}));
|
|
|
|
}));
|
|
|
|
});
|
|
|
|
};
|
|
|
|
|
|
|
|
module.exports = function create(options = EMPTY) {
|
|
|
|
if (options === EMPTY) {
|
|
|
|
throw new Error('Must pass options');
|
|
|
|
}
|
|
|
|
|
|
|
|
const {
|
|
|
|
cookieMaxAge = SIX_MONTHS_MS,
|
|
|
|
cookieSecure = true,
|
|
|
|
cookieName = 'members-ssr',
|
|
|
|
cookiePath = '/',
|
|
|
|
cookieKeys,
|
|
|
|
membersApi
|
|
|
|
} = options;
|
|
|
|
|
|
|
|
if (!membersApi) {
|
|
|
|
throw new Error('Missing option membersApi');
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!cookieKeys) {
|
|
|
|
throw new Error('Missing option cookieKeys');
|
|
|
|
}
|
|
|
|
|
|
|
|
const cookieConfig = {
|
|
|
|
keys: [].concat(cookieKeys),
|
|
|
|
secure: cookieSecure
|
|
|
|
};
|
|
|
|
|
|
|
|
const verifyJwt = token => membersApi.getPublicConfig().then(({publicKey, issuer}) => {
|
|
|
|
return new Promise((resolve, reject) => {
|
|
|
|
jwt.verify(token, publicKey, {
|
|
|
|
algorithms: ['RS512'],
|
|
|
|
issuer,
|
2019-04-11 17:08:50 +03:00
|
|
|
audience: issuer
|
2019-04-05 09:57:14 +03:00
|
|
|
}, (err, claims) => {
|
|
|
|
if (err) {
|
|
|
|
reject(new UnauthorizedError({err}));
|
|
|
|
}
|
|
|
|
resolve(claims);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2019-05-06 13:23:24 +03:00
|
|
|
const exchangeTokenForSession = withBodyAndCookies((req, res, {body, cookies}) => {
|
2019-04-05 09:57:14 +03:00
|
|
|
const token = body;
|
|
|
|
if (!body || typeof body !== 'string') {
|
2019-04-11 17:10:32 +03:00
|
|
|
return Promise.reject(new BadRequestError({
|
2019-04-05 09:57:14 +03:00
|
|
|
message: 'Expected body containing JWT'
|
2019-04-11 17:10:32 +03:00
|
|
|
}));
|
2019-04-05 09:57:14 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
return verifyJwt(token).then(() => {
|
|
|
|
cookies.set(cookieName, token, {
|
|
|
|
signed: true,
|
|
|
|
httpOnly: true,
|
|
|
|
sameSite: 'lax',
|
|
|
|
maxAge: cookieMaxAge,
|
|
|
|
path: cookiePath
|
|
|
|
});
|
|
|
|
});
|
|
|
|
}, cookieConfig);
|
|
|
|
|
2019-05-06 13:23:24 +03:00
|
|
|
const deleteSession = withCookies((req, res, {cookies}) => {
|
2019-04-11 17:10:53 +03:00
|
|
|
cookies.set(cookieName, {
|
|
|
|
signed: true,
|
|
|
|
httpOnly: true,
|
|
|
|
sameSite: 'lax',
|
|
|
|
maxAge: cookieMaxAge,
|
|
|
|
path: cookiePath
|
|
|
|
});
|
|
|
|
}, cookieConfig);
|
|
|
|
|
2019-05-06 13:23:24 +03:00
|
|
|
const getMemberDataFromSession = withCookies((req, res, {cookies}) => {
|
2019-04-10 18:02:39 +03:00
|
|
|
try {
|
|
|
|
const token = cookies.get(cookieName, {
|
|
|
|
signed: true
|
|
|
|
});
|
|
|
|
return verifyJwt(token).then((claims) => {
|
|
|
|
return membersApi.getMember(claims.sub, token);
|
|
|
|
});
|
|
|
|
} catch (e) {
|
2019-04-11 17:10:32 +03:00
|
|
|
return Promise.reject(new BadRequestError({
|
2019-04-05 09:57:14 +03:00
|
|
|
message: `Cookie ${cookieName} not found`
|
2019-04-11 17:10:32 +03:00
|
|
|
}));
|
2019-04-05 09:57:14 +03:00
|
|
|
}
|
|
|
|
}, cookieConfig);
|
|
|
|
|
|
|
|
return {
|
|
|
|
exchangeTokenForSession,
|
2019-04-11 17:10:53 +03:00
|
|
|
deleteSession,
|
2019-04-05 09:57:14 +03:00
|
|
|
getMemberDataFromSession
|
|
|
|
};
|
|
|
|
};
|