Skip to content

Commit 6a4568d

Browse files
committed
fix: use session / access_token for profile related queries or mutation
1 parent e941e48 commit 6a4568d

File tree

6 files changed

+41
-35
lines changed

6 files changed

+41
-35
lines changed

dashboard/yarn.lock

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1222,10 +1222,10 @@ error-ex@^1.3.1:
12221222
dependencies:
12231223
is-arrayish "^0.2.1"
12241224

1225-
esbuild-linux-64@0.14.9:
1225+
esbuild-darwin-arm64@0.14.9:
12261226
version "0.14.9"
1227-
resolved "https://registry.npmjs.org/esbuild-linux-64/-/esbuild-linux-64-0.14.9.tgz"
1228-
integrity sha512-WoEI+R6/PLZAxS7XagfQMFgRtLUi5cjqqU9VCfo3tnWmAXh/wt8QtUfCVVCcXVwZLS/RNvI19CtfjlrJU61nOg==
1227+
resolved "https://registry.npmjs.org/esbuild-darwin-arm64/-/esbuild-darwin-arm64-0.14.9.tgz"
1228+
integrity sha512-3ue+1T4FR5TaAu4/V1eFMG8Uwn0pgAwQZb/WwL1X78d5Cy8wOVQ67KNH1lsjU+y/9AcwMKZ9x0GGNxBB4a1Rbw==
12291229

12301230
esbuild@^0.14.9:
12311231
version "0.14.9"

server/handlers/userinfo.go

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,6 @@ func UserInfoHandler() gin.HandlerFunc {
2121
})
2222
return
2323
}
24-
2524
claims, err := token.ValidateAccessToken(gc, accessToken)
2625
if err != nil {
2726
log.Debug("Error validating access token: ", err)
@@ -30,7 +29,6 @@ func UserInfoHandler() gin.HandlerFunc {
3029
})
3130
return
3231
}
33-
3432
userID := claims["sub"].(string)
3533
user, err := db.Provider.GetUserByID(gc, userID)
3634
if err != nil {

server/resolvers/deactivate_account.go

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -21,17 +21,11 @@ func DeactivateAccountResolver(ctx context.Context) (*model.Response, error) {
2121
log.Debug("Failed to get GinContext: ", err)
2222
return res, err
2323
}
24-
accessToken, err := token.GetAccessToken(gc)
24+
userID, err := token.GetUserIDFromSessionOrAccessToken(gc)
2525
if err != nil {
26-
log.Debug("Failed to get access token: ", err)
26+
log.Debug("Failed GetUserIDFromSessionOrAccessToken: ", err)
2727
return res, err
2828
}
29-
claims, err := token.ValidateAccessToken(gc, accessToken)
30-
if err != nil {
31-
log.Debug("Failed to validate access token: ", err)
32-
return res, err
33-
}
34-
userID := claims["sub"].(string)
3529
log := log.WithFields(log.Fields{
3630
"user_id": userID,
3731
})

server/resolvers/profile.go

Lines changed: 2 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -20,21 +20,11 @@ func ProfileResolver(ctx context.Context) (*model.User, error) {
2020
log.Debug("Failed to get GinContext: ", err)
2121
return res, err
2222
}
23-
24-
accessToken, err := token.GetAccessToken(gc)
23+
userID, err := token.GetUserIDFromSessionOrAccessToken(gc)
2524
if err != nil {
26-
log.Debug("Failed to get access token: ", err)
25+
log.Debug("Failed GetUserIDFromSessionOrAccessToken: ", err)
2726
return res, err
2827
}
29-
30-
claims, err := token.ValidateAccessToken(gc, accessToken)
31-
if err != nil {
32-
log.Debug("Failed to validate access token: ", err)
33-
return res, err
34-
}
35-
36-
userID := claims["sub"].(string)
37-
3828
log := log.WithFields(log.Fields{
3929
"user_id": userID,
4030
})

server/resolvers/update_profile.go

Lines changed: 2 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -35,15 +35,9 @@ func UpdateProfileResolver(ctx context.Context, params model.UpdateProfileInput)
3535
log.Debug("Failed to get GinContext: ", err)
3636
return res, err
3737
}
38-
39-
accessToken, err := token.GetAccessToken(gc)
38+
userID, err := token.GetUserIDFromSessionOrAccessToken(gc)
4039
if err != nil {
41-
log.Debug("Failed to get access token: ", err)
42-
return res, err
43-
}
44-
claims, err := token.ValidateAccessToken(gc, accessToken)
45-
if err != nil {
46-
log.Debug("Failed to validate access token: ", err)
40+
log.Debug("Failed GetUserIDFromSessionOrAccessToken: ", err)
4741
return res, err
4842
}
4943

@@ -52,8 +46,6 @@ func UpdateProfileResolver(ctx context.Context, params model.UpdateProfileInput)
5246
log.Debug("All params are empty")
5347
return res, fmt.Errorf("please enter at least one param to update")
5448
}
55-
56-
userID := claims["sub"].(string)
5749
log := log.WithFields(log.Fields{
5850
"user_id": userID,
5951
})

server/token/auth_token.go

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ import (
1515
"github.com/robertkrimen/otto"
1616

1717
"github.com/authorizerdev/authorizer/server/constants"
18+
"github.com/authorizerdev/authorizer/server/cookie"
1819
"github.com/authorizerdev/authorizer/server/crypto"
1920
"github.com/authorizerdev/authorizer/server/db/models"
2021
"github.com/authorizerdev/authorizer/server/memorystore"
@@ -480,3 +481,34 @@ func GetIDToken(gc *gin.Context) (string, error) {
480481
token := strings.TrimPrefix(auth, "Bearer ")
481482
return token, nil
482483
}
484+
485+
// GetUserIDFromSessionOrAccessToken returns the user id from the session or access token
486+
func GetUserIDFromSessionOrAccessToken(gc *gin.Context) (string, error) {
487+
// First try to get the user id from the session
488+
isSession := true
489+
token, err := cookie.GetSession(gc)
490+
if err != nil || token == "" {
491+
log.Debug("Failed to get session token: ", err)
492+
isSession = false
493+
token, err = GetAccessToken(gc)
494+
if err != nil || token == "" {
495+
log.Debug("Failed to get access token: ", err)
496+
return "", fmt.Errorf(`unauthorized`)
497+
}
498+
}
499+
if isSession {
500+
claims, err := ValidateBrowserSession(gc, token)
501+
if err != nil {
502+
log.Debug("Failed to validate session token: ", err)
503+
return "", fmt.Errorf(`unauthorized`)
504+
}
505+
return claims.Subject, nil
506+
}
507+
// If not session, then validate the access token
508+
claims, err := ValidateAccessToken(gc, token)
509+
if err != nil {
510+
log.Debug("Failed to validate access token: ", err)
511+
return "", fmt.Errorf(`unauthorized`)
512+
}
513+
return claims["sub"].(string), nil
514+
}

0 commit comments

Comments
 (0)