2020-12-31 13:19:21 +01:00
|
|
|
package handlers
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"html/template"
|
|
|
|
"net/http"
|
|
|
|
"net/url"
|
|
|
|
|
2020-12-31 19:11:06 +01:00
|
|
|
"github.com/lestrrat-go/jwx/jwk"
|
|
|
|
|
2020-12-31 13:19:21 +01:00
|
|
|
"git.cacert.org/oidc_login/app/services"
|
|
|
|
)
|
|
|
|
|
|
|
|
type indexHandler struct {
|
|
|
|
logoutUrl string
|
|
|
|
serverAddr string
|
2020-12-31 19:11:06 +01:00
|
|
|
keySet *jwk.Set
|
2020-12-31 13:19:21 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
func (h *indexHandler) ServeHTTP(writer http.ResponseWriter, request *http.Request) {
|
|
|
|
if request.Method != http.MethodGet {
|
|
|
|
http.Error(writer, http.StatusText(http.StatusMethodNotAllowed), http.StatusMethodNotAllowed)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if request.URL.Path != "/" {
|
|
|
|
http.NotFound(writer, request)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
writer.WriteHeader(http.StatusOK)
|
|
|
|
|
|
|
|
page, err := template.New("").Parse(`
|
|
|
|
<!DOCTYPE html>
|
|
|
|
<html lang="en">
|
|
|
|
<head><title>Auth test</title></head>
|
|
|
|
<body>
|
|
|
|
<h1>Hello {{ .User }}</h1>
|
|
|
|
<p>This is an authorization protected resource</p>
|
|
|
|
<a href="{{ .LogoutURL }}">Logout</a>
|
|
|
|
</body>
|
|
|
|
</html>
|
|
|
|
`)
|
|
|
|
if err != nil {
|
|
|
|
http.Error(writer, err.Error(), http.StatusInternalServerError)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
session, err := services.GetSessionStore().Get(request, sessionName)
|
|
|
|
if err != nil {
|
|
|
|
http.Error(writer, err.Error(), http.StatusInternalServerError)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
logoutUrl, err := url.Parse(h.logoutUrl)
|
|
|
|
if err != nil {
|
|
|
|
http.Error(writer, err.Error(), http.StatusInternalServerError)
|
|
|
|
return
|
|
|
|
}
|
2020-12-31 19:11:06 +01:00
|
|
|
var idToken string
|
2020-12-31 13:19:21 +01:00
|
|
|
var ok bool
|
2020-12-31 19:11:06 +01:00
|
|
|
if idToken, ok = session.Values[sessionKeyIdToken].(string); ok {
|
2020-12-31 13:19:21 +01:00
|
|
|
logoutUrl.RawQuery = url.Values{
|
|
|
|
"id_token_hint": []string{idToken},
|
|
|
|
"post_logout_redirect_uri": []string{fmt.Sprintf("https://%s/after-logout", h.serverAddr)},
|
|
|
|
}.Encode()
|
2020-12-31 19:11:06 +01:00
|
|
|
} else {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
oidcToken, err := ParseIdToken(idToken, h.keySet)
|
|
|
|
if err != nil {
|
|
|
|
http.Error(writer, err.Error(), http.StatusInternalServerError)
|
|
|
|
return
|
2020-12-31 13:19:21 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
writer.Header().Add("Content-Type", "text/html")
|
|
|
|
err = page.Execute(writer, map[string]interface{}{
|
2020-12-31 19:11:06 +01:00
|
|
|
"User": oidcToken.Name(),
|
2020-12-31 13:19:21 +01:00
|
|
|
"LogoutURL": logoutUrl.String(),
|
|
|
|
})
|
|
|
|
if err != nil {
|
|
|
|
http.Error(writer, err.Error(), http.StatusInternalServerError)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-12-31 19:11:06 +01:00
|
|
|
func NewIndexHandler(logoutUrl string, serverAddr string, keySet *jwk.Set) *indexHandler {
|
|
|
|
return &indexHandler{logoutUrl: logoutUrl, serverAddr: serverAddr, keySet: keySet}
|
2020-12-31 13:19:21 +01:00
|
|
|
}
|