accounts and email
This commit is contained in:
@@ -13,6 +13,8 @@ import (
|
||||
"github.com/tim/cairnquire/apps/server/internal/auth"
|
||||
)
|
||||
|
||||
const devLogoutCookieName = "cairnquire_dev_logout"
|
||||
|
||||
func (s *Server) timeoutExceptWebSocket(timeout time.Duration) func(http.Handler) http.Handler {
|
||||
timeoutMiddleware := middleware.Timeout(timeout)
|
||||
return func(next http.Handler) http.Handler {
|
||||
@@ -99,6 +101,8 @@ func isSetupAllowedPath(path string) bool {
|
||||
return path == "/setup" ||
|
||||
path == "/api/setup" ||
|
||||
path == "/health" ||
|
||||
path == "/healthz" ||
|
||||
path == "/readyz" ||
|
||||
path == "/sw.js" ||
|
||||
strings.HasPrefix(path, "/static/")
|
||||
}
|
||||
@@ -125,7 +129,7 @@ func (s *Server) authenticateRequest(r *http.Request) (auth.Principal, bool) {
|
||||
}
|
||||
cookie, err := r.Cookie(auth.SessionCookieName)
|
||||
if err != nil || cookie.Value == "" {
|
||||
if s.devUserID == "" {
|
||||
if s.devUserID == "" || hasDevLogoutCookie(r) {
|
||||
return auth.Principal{}, false
|
||||
}
|
||||
principal, err := s.auth.PrincipalForUser(r.Context(), s.devUserID)
|
||||
@@ -138,6 +142,11 @@ func (s *Server) authenticateRequest(r *http.Request) (auth.Principal, bool) {
|
||||
return principal, true
|
||||
}
|
||||
|
||||
func hasDevLogoutCookie(r *http.Request) bool {
|
||||
cookie, err := r.Cookie(devLogoutCookieName)
|
||||
return err == nil && cookie.Value == "1"
|
||||
}
|
||||
|
||||
func requiredScopeForPath(r *http.Request) (auth.Scope, bool) {
|
||||
path := r.URL.Path
|
||||
method := r.Method
|
||||
|
||||
Reference in New Issue
Block a user