-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathauth.go
121 lines (95 loc) · 2.4 KB
/
auth.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
package auth
import (
"encoding/base64"
"encoding/json"
"errors"
"io/ioutil"
"net/http"
"strings"
)
// Google returns Google user from the given ID token.
//
func Google(IDToken string) (*User, error) {
var err error
// validate the provided ID token
var ti *tokenInfo
if ti, err = validateIDToken(IDToken); err != nil {
return nil, err
}
// Get the user name
var name string
if name, err = extractNameFromToken(IDToken); err != nil {
return nil, err
}
user := User{
ID: ti.UserID,
Name: name,
Email: ti.Email,
}
return &user, err
}
// User represents the authenticated user.
//
type User struct {
ID string
Name string
Email string
}
type tokenInfo struct {
IssuedTo string `json:"issued_to"`
Audience string `json:"audience"`
UserID string `json:"user_id"`
ExpiresIn int64 `json:"expires_in"`
Email string `json:"email"`
EmailVerified bool `json:"email_verified"`
}
func validateIDToken(token string) (*tokenInfo, error) {
var err error
// Verification of the integrity of the ID token
var resp *http.Response
if resp, err = http.Get("https://www.googleapis.com/oauth2/v2/tokeninfo?id_token=" + token); err != nil {
return nil, err
}
if resp == nil || resp.StatusCode != http.StatusOK {
// Bad request
return nil, errors.New("Provided ID token is not valid")
}
// read the JSON token info
var body []byte
if body, err = ioutil.ReadAll(resp.Body); err != nil {
return nil, err
}
resp.Body.Close()
// decode the JSON token info
var ti *tokenInfo
json.Unmarshal(body, &ti)
return ti, err
}
func extractNameFromToken(token string) (string, error) {
parts := strings.Split(token, ".")
// token is a JWT (http://jwt.io/)
if len(parts) != 3 {
return "", errors.New("Provided token is not valid")
}
// decode the second part (claims) containing the name
var err error
var claimBytes []byte
if claimBytes, err = decodePart(parts[1]); err != nil {
return "", err
}
var claims map[string]interface{}
json.Unmarshal(claimBytes, &claims)
var name string
var ok bool
if name, ok = claims["name"].(string); !ok {
return "", errors.New("Unable to decode name from token")
}
return name, nil
}
func decodePart(p string) ([]byte, error) {
// need padding to have a multiple of four characters and avoid a base64 error
if l := len(p) % 4; l > 0 {
p += strings.Repeat("=", 4-l)
}
return base64.URLEncoding.DecodeString(p)
}