mirror of
https://git.ngram.ca/OpenJam/rc-servers
synced 2026-08-23 23:08:52 +00:00
Clippy fixes for #123
This commit is contained in:
@@ -1,9 +1,9 @@
|
|||||||
use actix_web::{get, web::{Data, Json}};
|
use actix_web::{get, web::{Data, Json}};
|
||||||
use oj_rc_core::persist::user::federation::DiscoveryMetadata;
|
use oj_rc_core::persist::user::federation::DiscoveryMetadata;
|
||||||
|
|
||||||
const OAUTH_AUTH_URL: &'static str = "authenticate/oauth2/auth";
|
const OAUTH_AUTH_URL: &str = "authenticate/oauth2/auth";
|
||||||
const OAUTH_JWKS_URL: &'static str = "authenticate/oauth2/jwks";
|
const OAUTH_JWKS_URL: &str = "authenticate/oauth2/jwks";
|
||||||
const OAUTH_TOKEN_URL: &'static str = "authenticate/oauth2/token";
|
const OAUTH_TOKEN_URL: &str = "authenticate/oauth2/token";
|
||||||
|
|
||||||
#[get("/.well-known/openid-configuration")]
|
#[get("/.well-known/openid-configuration")]
|
||||||
pub async fn get_openid_configuration(server_config: Data<oj_rc_core::persist::config::ServerConfig>) -> Json<DiscoveryMetadata> {
|
pub async fn get_openid_configuration(server_config: Data<oj_rc_core::persist::config::ServerConfig>) -> Json<DiscoveryMetadata> {
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ use actix_web::{rt, web::{Payload, Data, Path, Json}, Error, HttpRequest, HttpRe
|
|||||||
|
|
||||||
#[get("/intercom/.oj_services/{name}")]
|
#[get("/intercom/.oj_services/{name}")]
|
||||||
pub async fn services_ws(req: HttpRequest, stream: Payload, auth: Data<super::IntercomAuth>, reg: Data<super::Users>, name: Path<String>) -> Result<HttpResponse, Error> {
|
pub async fn services_ws(req: HttpRequest, stream: Payload, auth: Data<super::IntercomAuth>, reg: Data<super::Users>, name: Path<String>) -> Result<HttpResponse, Error> {
|
||||||
auth.validate(&req, &format!(".oj_services/{}", urlencoding::encode(&*name)))?;
|
auth.validate(&req, &format!(".oj_services/{}", urlencoding::encode(&name)))?;
|
||||||
let (res, mut session, _stream) = actix_ws::handle(&req, stream)?;
|
let (res, mut session, _stream) = actix_ws::handle(&req, stream)?;
|
||||||
|
|
||||||
/*let mut stream = stream
|
/*let mut stream = stream
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
use openidconnect::{OAuth2TokenResponse, TokenResponse};
|
use openidconnect::{OAuth2TokenResponse, TokenResponse};
|
||||||
use serde::{Serialize, Deserialize};
|
use serde::{Serialize, Deserialize};
|
||||||
|
|
||||||
const SOCIETY_URLS_API_ENDPOINT: &'static str = "api/v1/services.json";
|
const SOCIETY_URLS_API_ENDPOINT: &str = "api/v1/services.json";
|
||||||
const ACCESS_CODE_AAD: &'static [u8] = b"oj-access-code";
|
const ACCESS_CODE_AAD: &[u8] = b"oj-access-code";
|
||||||
|
|
||||||
pub type DiscoveryMetadata = openidconnect::core::CoreProviderMetadata;
|
pub type DiscoveryMetadata = openidconnect::core::CoreProviderMetadata;
|
||||||
pub type TokenResponsePayload = openidconnect::core::CoreTokenResponse;
|
pub type TokenResponsePayload = openidconnect::core::CoreTokenResponse;
|
||||||
@@ -72,7 +72,7 @@ impl ring::aead::NonceSequence for NonceProvider {
|
|||||||
let hash = sha2::Sha512::new()
|
let hash = sha2::Sha512::new()
|
||||||
.chain_update(self.issuer.as_bytes())
|
.chain_update(self.issuer.as_bytes())
|
||||||
.chain_update(self.secret.as_slice())
|
.chain_update(self.secret.as_slice())
|
||||||
.chain_update(&self.generated_time.to_ne_bytes())
|
.chain_update(self.generated_time.to_ne_bytes())
|
||||||
.finalize();
|
.finalize();
|
||||||
let mut nonce = Vec::from(hash.as_slice());
|
let mut nonce = Vec::from(hash.as_slice());
|
||||||
nonce.truncate(12);
|
nonce.truncate(12);
|
||||||
@@ -103,7 +103,7 @@ impl super::AccountProvider {
|
|||||||
async fn local_login_impl(&self, auth_info: super::FederatedAuthInfo, federation: &Option<crate::persist::config::Federation>) -> Result<super::UserLoginInfo, super::AuthError> {
|
async fn local_login_impl(&self, auth_info: super::FederatedAuthInfo, federation: &Option<crate::persist::config::Federation>) -> Result<super::UserLoginInfo, super::AuthError> {
|
||||||
if auth_info.display_name.is_empty() {
|
if auth_info.display_name.is_empty() {
|
||||||
return Err(super::AuthError {
|
return Err(super::AuthError {
|
||||||
message: format!("Refusing federation login with empty username"),
|
message: "Refusing federation login with empty username".to_string(),
|
||||||
code: crate::data::error_codes::AuthErrorCode::InvalidDisplayName,
|
code: crate::data::error_codes::AuthErrorCode::InvalidDisplayName,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -324,7 +324,7 @@ impl super::AccountProvider {
|
|||||||
Ok(super::UserLoginInfo {
|
Ok(super::UserLoginInfo {
|
||||||
response: libfj::robocraft::AuthenticationResponseInfo {
|
response: libfj::robocraft::AuthenticationResponseInfo {
|
||||||
token: local_token,
|
token: local_token,
|
||||||
refresh_token: refresh_token,
|
refresh_token,
|
||||||
refresh_token_expiry: "0".to_string(), // TODO (seems like this isn't actually considered by the client)
|
refresh_token_expiry: "0".to_string(), // TODO (seems like this isn't actually considered by the client)
|
||||||
},
|
},
|
||||||
is_new: false,
|
is_new: false,
|
||||||
@@ -399,20 +399,20 @@ impl super::AccountProvider {
|
|||||||
async fn remote_auth_impl(&self, auth_info: &FederatedAuthenticationPayload, challenge: &str, federation: &Option<crate::persist::config::Federation>) -> Result<String, super::AuthError> {
|
async fn remote_auth_impl(&self, auth_info: &FederatedAuthenticationPayload, challenge: &str, federation: &Option<crate::persist::config::Federation>) -> Result<String, super::AuthError> {
|
||||||
if auth_info.display_name.is_empty() {
|
if auth_info.display_name.is_empty() {
|
||||||
return Err(super::AuthError {
|
return Err(super::AuthError {
|
||||||
message: format!("Refusing federation login with empty username"),
|
message: "Refusing federation login with empty username".to_string(),
|
||||||
code: crate::data::error_codes::AuthErrorCode::InvalidDisplayName,
|
code: crate::data::error_codes::AuthErrorCode::InvalidDisplayName,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
if let Some(fedi_conf) = federation {
|
if let Some(fedi_conf) = federation {
|
||||||
if auth_info.domain_source.is_empty() {
|
if auth_info.domain_source.is_empty() {
|
||||||
return Err(super::AuthError {
|
return Err(super::AuthError {
|
||||||
message: format!("Refusing federation login with empty domain_source"),
|
message: "Refusing federation login with empty domain_source".to_string(),
|
||||||
code: crate::data::error_codes::AuthErrorCode::InvalidDisplayName,
|
code: crate::data::error_codes::AuthErrorCode::InvalidDisplayName,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
if auth_info.domain_target != *self.domain {
|
if auth_info.domain_target != *self.domain {
|
||||||
return Err(super::AuthError {
|
return Err(super::AuthError {
|
||||||
message: format!("Refusing federation login with not my domain_target"),
|
message: "Refusing federation login with not my domain_target".to_string(),
|
||||||
code: crate::data::error_codes::AuthErrorCode::InvalidDisplayName,
|
code: crate::data::error_codes::AuthErrorCode::InvalidDisplayName,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -428,12 +428,12 @@ impl super::AccountProvider {
|
|||||||
};
|
};
|
||||||
let login_info = self.login_internal(user_info, Some(auth_info.domain_source.clone())).await?;
|
let login_info = self.login_internal(user_info, Some(auth_info.domain_source.clone())).await?;
|
||||||
Ok(Self::generate_access_code(
|
Ok(Self::generate_access_code(
|
||||||
&*self.auth,
|
&self.auth,
|
||||||
challenge,
|
challenge,
|
||||||
&auth_info.display_name,
|
&auth_info.display_name,
|
||||||
&login_info.response.token,
|
&login_info.response.token,
|
||||||
&login_info.response.refresh_token,
|
&login_info.response.refresh_token,
|
||||||
&*self.secret,
|
&self.secret,
|
||||||
self.nonce_provider(),
|
self.nonce_provider(),
|
||||||
))
|
))
|
||||||
} else {
|
} else {
|
||||||
@@ -476,9 +476,7 @@ impl super::AccountProvider {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
if temp_key.len() < 32 {
|
if temp_key.len() < 32 {
|
||||||
for _ in temp_key.len()..32 {
|
temp_key.extend(std::iter::repeat_n(0, 32 - temp_key.len()));
|
||||||
temp_key.push(0);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
temp_key
|
temp_key
|
||||||
} else if secret.len() > 32 {
|
} else if secret.len() > 32 {
|
||||||
@@ -542,7 +540,7 @@ impl super::AccountProvider {
|
|||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
log::error!("Failed to decrypt secure code: {}", e);
|
log::error!("Failed to decrypt secure code: {}", e);
|
||||||
})?;
|
})?;
|
||||||
let secure_data: SecuredCodes = serde_json::from_slice(&plaintext)
|
let secure_data: SecuredCodes = serde_json::from_slice(plaintext)
|
||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
log::error!("Failed to decode JSON secure code: {}", e);
|
log::error!("Failed to decode JSON secure code: {}", e);
|
||||||
})?;
|
})?;
|
||||||
|
|||||||
Reference in New Issue
Block a user