Auth finally works for testing other stuff
This commit is contained in:
+11
-40
@@ -1,73 +1,44 @@
|
|||||||
import { NextRequest, NextResponse } from "next/server";
|
import { NextRequest, NextResponse } from "next/server";
|
||||||
import {
|
|
||||||
StatusCodes,
|
|
||||||
} from 'http-status-codes';
|
|
||||||
import { narrow } from "@/types/typeUtils";
|
|
||||||
import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth";
|
import { CLIENT_AUTH_TOKENS, SERVER_AUTH_TOKENS } from "./auth";
|
||||||
import { initDb } from "../db";
|
import { StatusCodes } from "http-status-codes";
|
||||||
|
|
||||||
type Intents = 'server' | 'client';
|
|
||||||
|
|
||||||
const narrowIntents = (intents?: string | null) => narrow(intents, 'client', 'server') as Intents;
|
|
||||||
|
|
||||||
export async function GET(req: NextRequest) {
|
export async function GET(req: NextRequest) {
|
||||||
const url = new URL(req.url);
|
const url = new URL(req.url);
|
||||||
const token = url.searchParams.get('token');
|
const token = url.searchParams.get('token');
|
||||||
const intents = narrowIntents(url.searchParams.get('intents'));
|
|
||||||
|
|
||||||
if (!token)
|
if (!token)
|
||||||
return NextResponse.json({ message: "token parameter required" });
|
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.BAD_REQUEST });
|
||||||
|
|
||||||
switch (intents) {
|
|
||||||
case "server":
|
|
||||||
{
|
|
||||||
const auth = SERVER_AUTH_TOKENS[token];
|
const auth = SERVER_AUTH_TOKENS[token];
|
||||||
|
|
||||||
if (!auth)
|
if (!auth)
|
||||||
return NextResponse.json({ message: "Invalid token" });
|
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
|
||||||
|
|
||||||
const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1');
|
const ip = (req.headers.get("x-real-ip") || req.headers.get("x-forwarded-for")?.split(",")[0] || '127.0.0.1').replace('::1', '127.0.0.1');
|
||||||
|
|
||||||
if (auth.server_ip !== ip) {
|
if (auth.server_ip !== ip) {
|
||||||
return NextResponse.json({ message: "Invalid address" });
|
return NextResponse.json({ message: "Invalid address" }, { status: StatusCodes.UNAUTHORIZED });
|
||||||
}
|
}
|
||||||
|
|
||||||
delete SERVER_AUTH_TOKENS[token];
|
delete SERVER_AUTH_TOKENS[token];
|
||||||
|
|
||||||
return NextResponse.json({ message: "ok", ...auth });
|
return NextResponse.json({ message: "ok", ...auth });
|
||||||
}
|
}
|
||||||
case "client":
|
|
||||||
{
|
|
||||||
const auth = CLIENT_AUTH_TOKENS[token];
|
|
||||||
if (!auth)
|
|
||||||
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
|
|
||||||
return NextResponse.json({ message: "ok", auth });
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function POST(req: NextRequest) {
|
export async function POST(req: NextRequest) {
|
||||||
let { intents, server_ip } = await req.json();
|
let { server_ip, session_token } = await req.json();
|
||||||
|
|
||||||
intents = String(intents).split('/');
|
|
||||||
|
|
||||||
const token = crypto.randomUUID();
|
const token = crypto.randomUUID();
|
||||||
|
|
||||||
const user_id = 12;
|
const user_id = CLIENT_AUTH_TOKENS[session_token];
|
||||||
|
|
||||||
|
if (!user_id)
|
||||||
|
return NextResponse.json({ message: "Invalid token" }, { status: StatusCodes.NOT_FOUND });
|
||||||
|
|
||||||
switch (narrowIntents(intents[0])) {
|
|
||||||
case 'server':
|
|
||||||
SERVER_AUTH_TOKENS[token] = {
|
SERVER_AUTH_TOKENS[token] = {
|
||||||
user_id,
|
user_id,
|
||||||
server_ip: String(server_ip),
|
server_ip: String(server_ip),
|
||||||
};
|
};
|
||||||
return NextResponse.json({ message: "ok", token });
|
|
||||||
case 'client':
|
|
||||||
CLIENT_AUTH_TOKENS[token] = user_id;
|
|
||||||
return NextResponse.json({ message: "ok", token });
|
|
||||||
default:
|
|
||||||
return NextResponse.json({ message: 'Invalid intentions' }, { status: StatusCodes.BAD_REQUEST });
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
initDb();
|
return NextResponse.json({ message: "ok", token });
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,20 +1,8 @@
|
|||||||
import { NextRequest, NextResponse } from "next/server";
|
import { NextRequest, NextResponse } from "next/server";
|
||||||
import pool from "../db";
|
import pool, { initDb } from "../db";
|
||||||
import { StatusCodes } from "http-status-codes";
|
import { StatusCodes } from "http-status-codes";
|
||||||
import { CLIENT_AUTH_TOKENS } from "../auth/auth";
|
import { CLIENT_AUTH_TOKENS } from "../auth/auth";
|
||||||
|
|
||||||
/*
|
|
||||||
Input:
|
|
||||||
{
|
|
||||||
"name": "<Bob Smith>",
|
|
||||||
"password": "<bobsmith21>"
|
|
||||||
}
|
|
||||||
Output:
|
|
||||||
{
|
|
||||||
"message": "ok",
|
|
||||||
"token": "<crypto-uuid>",
|
|
||||||
}
|
|
||||||
*/
|
|
||||||
export async function POST(req: NextRequest) {
|
export async function POST(req: NextRequest) {
|
||||||
let { name, username, email, password } = await req.json();
|
let { name, username, email, password } = await req.json();
|
||||||
|
|
||||||
@@ -40,7 +28,7 @@ export async function POST(req: NextRequest) {
|
|||||||
const result = await pool.query("INSERT INTO users (username, email, password_hash) VALUES ($1, $2, $3) RETURNING id;", [username, email, password]);
|
const result = await pool.query("INSERT INTO users (username, email, password_hash) VALUES ($1, $2, $3) RETURNING id;", [username, email, password]);
|
||||||
const token = crypto.randomUUID();
|
const token = crypto.randomUUID();
|
||||||
|
|
||||||
CLIENT_AUTH_TOKENS[token] = result.rows[0].id;
|
CLIENT_AUTH_TOKENS[token] = parseInt(result.rows[0].id);
|
||||||
|
|
||||||
return NextResponse.json({ message: "ok", token, user_id: result.rows[0].id });
|
return NextResponse.json({ message: "ok", token, user_id: result.rows[0].id });
|
||||||
}
|
}
|
||||||
@@ -55,3 +43,5 @@ export async function DELETE(req: NextRequest) {
|
|||||||
|
|
||||||
return NextResponse.json({ message: "ok" });
|
return NextResponse.json({ message: "ok" });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
initDb();
|
||||||
+5
-1
@@ -1,8 +1,12 @@
|
|||||||
import axios from "axios";
|
import axios from "axios";
|
||||||
|
import { getUser } from "./user.js";
|
||||||
|
|
||||||
|
const session_token = await getUser();
|
||||||
|
|
||||||
const res = (await axios.post('http://localhost:3000/api/auth', {
|
const res = (await axios.post('http://localhost:3000/api/auth', {
|
||||||
intents: 'server',
|
intents: 'server',
|
||||||
server_ip: '127.0.0.1'
|
server_ip: '127.0.0.1',
|
||||||
|
session_token,
|
||||||
})).data;
|
})).data;
|
||||||
|
|
||||||
const token = res.token;
|
const token = res.token;
|
||||||
|
|||||||
+6
-2
@@ -1,12 +1,16 @@
|
|||||||
import axios from "axios";
|
import axios from "axios";
|
||||||
|
|
||||||
|
export async function getUser() {
|
||||||
console.log((await axios.delete("http://localhost:3000/api/user", {
|
console.log((await axios.delete("http://localhost:3000/api/user", {
|
||||||
data: { username: "leo" },
|
data: { username: "leo" },
|
||||||
})).data);
|
})).data);
|
||||||
|
|
||||||
console.log((await axios.post('http://localhost:3000/api/user', {
|
return ((await axios.post('http://localhost:3000/api/user', {
|
||||||
username: 'leo',
|
username: 'leo',
|
||||||
name: 'Leo',
|
name: 'Leo',
|
||||||
email: '',
|
email: '',
|
||||||
password: 'Idk123',
|
password: 'Idk123',
|
||||||
})).data);
|
})).data).token;
|
||||||
|
}
|
||||||
|
|
||||||
|
// await getUser();
|
||||||
Reference in New Issue
Block a user