fix auth middleware

This commit is contained in:
Zoe
2024-09-04 22:55:41 -05:00
parent 2ff678a5d9
commit 13218116e3
4 changed files with 33 additions and 14 deletions

15
main.go
View File

@@ -5,6 +5,7 @@ package main
import (
"context"
"database/sql"
"filething/middleware"
"filething/models"
"filething/routes"
"filething/ui"
@@ -14,7 +15,7 @@ import (
"strings"
"github.com/labstack/echo/v4"
"github.com/labstack/echo/v4/middleware"
echoMiddleware "github.com/labstack/echo/v4/middleware"
"github.com/uptrace/bun"
"github.com/uptrace/bun/dialect/pgdialect"
"github.com/uptrace/bun/driver/pgdriver"
@@ -49,9 +50,9 @@ func main() {
}
})
e.Use(middleware.Gzip())
e.Use(middleware.CORS())
e.Use(middleware.CSRFWithConfig(middleware.CSRFConfig{
e.Use(echoMiddleware.Gzip())
e.Use(echoMiddleware.CORS())
e.Use(echoMiddleware.CSRFWithConfig(echoMiddleware.CSRFConfig{
TokenLookup: "cookie:_csrf",
CookiePath: "/",
CookieSecure: true,
@@ -63,6 +64,12 @@ func main() {
{
api.POST("/login", routes.LoginHandler)
api.POST("/signup", routes.SignupHandler)
api.Use(middleware.SessionMiddleware(db))
api.GET("/user", func(c echo.Context) error {
user := c.Get("user").(*models.User)
message := fmt.Sprintf("You are %s", user.ID)
return c.JSON(http.StatusOK, map[string]string{"message": message})
})
api.GET("/hello", func(c echo.Context) error {
return c.JSON(http.StatusOK, map[string]string{"message": "Hello, World!!!"})
})

View File

@@ -4,8 +4,10 @@ import (
"context"
"database/sql"
"filething/models"
"fmt"
"net/http"
"github.com/google/uuid"
"github.com/labstack/echo/v4"
"github.com/uptrace/bun"
)
@@ -36,17 +38,25 @@ func SessionMiddleware(db *bun.DB) echo.MiddlewareFunc {
sessionToken := cookie.Value
// Query the session and user data from PostgreSQL
session := new(models.Session)
err = db.NewSelect().Model(session).Relation("User").WherePK(sessionToken).Scan(context.Background())
sessionId, err := uuid.Parse(sessionToken)
if err != nil {
return echo.NewHTTPError(http.StatusBadRequest, "Bad request")
}
session := &models.Session{
ID: sessionId,
}
err = db.NewSelect().Model(session).Relation("User").WherePK().Scan(context.Background())
if err != nil {
fmt.Println(err)
if err == sql.ErrNoRows {
return echo.NewHTTPError(http.StatusUnauthorized, "Invalid session token")
}
return echo.NewHTTPError(http.StatusInternalServerError, "Database error")
}
user := session.User
user := &session.User
// Store the user in the context
c.Set(UserContextKey, user)

View File

@@ -27,6 +27,6 @@ type User struct {
type Session struct {
bun.BaseModel `bun:"table:sessions,alias:u"`
ID uuid.UUID `bun:",pk,type:uuid,default:uuid_generate_v4()"`
UserID uuid.UUID `bun:"user_id,notnull"`
UserID uuid.UUID `bun:"user_id,notnull,type:uuid"`
User User `bun:"rel:belongs-to,join:user_id=id"`
}

View File

@@ -43,6 +43,7 @@ func LoginHandler(c echo.Context) error {
c.SetCookie(&http.Cookie{
Name: "sessionToken",
Value: session.ID.String(),
SameSite: http.SameSiteStrictMode,
Path: "/",
})
@@ -111,6 +112,7 @@ func SignupHandler(c echo.Context) error {
c.SetCookie(&http.Cookie{
Name: "sessionToken",
Value: session.ID.String(),
SameSite: http.SameSiteStrictMode,
Path: "/",
})