aboutsummaryrefslogtreecommitdiff
path: root/federationapi
diff options
context:
space:
mode:
authorBruce MacDonald <brucewmacdonald@gmail.com>2021-04-07 05:26:20 -0700
committerGitHub <noreply@github.com>2021-04-07 13:26:20 +0100
commitd27607af78a53bda636f14f603b02b2952d6e1d8 (patch)
treec5c5488c7395a45af24ef598308ef7f6545515ca /federationapi
parentf8d3a762c49a1dafe4e484a2440ade2bb6ba32ac (diff)
Implement OpenID module (#599) (#1812)
* Implement OpenID module (#599) - Unrelated: change Riot references to Element in client API routing Signed-off-by: Bruce MacDonald <contact@bruce-macdonald.com> * OpenID module tweaks (#599) - specify expiry is ms rather than vague ts - add OpenID token lifetime to configuration - use Go naming conventions for the path params - store plaintext token rather than hash - remove openid table sqllite mutex * Add default OpenID token lifetime (#599) * Update dendrite-config.yaml Co-authored-by: Kegsay <kegsay@gmail.com> Co-authored-by: Kegsay <kegan@matrix.org>
Diffstat (limited to 'federationapi')
-rw-r--r--federationapi/routing/openid.go65
-rw-r--r--federationapi/routing/routing.go6
2 files changed, 71 insertions, 0 deletions
diff --git a/federationapi/routing/openid.go b/federationapi/routing/openid.go
new file mode 100644
index 00000000..829dbcca
--- /dev/null
+++ b/federationapi/routing/openid.go
@@ -0,0 +1,65 @@
+// Copyright 2021 The Matrix.org Foundation C.I.C.
+//
+// Licensed under the Apache License, Version 2.0 (the "License");
+// you may not use this file except in compliance with the License.
+// You may obtain a copy of the License at
+//
+// http://www.apache.org/licenses/LICENSE-2.0
+//
+// Unless required by applicable law or agreed to in writing, software
+// distributed under the License is distributed on an "AS IS" BASIS,
+// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+// See the License for the specific language governing permissions and
+// limitations under the License.
+
+package routing
+
+import (
+ "net/http"
+ "time"
+
+ "github.com/matrix-org/dendrite/clientapi/jsonerror"
+ userapi "github.com/matrix-org/dendrite/userapi/api"
+ "github.com/matrix-org/util"
+)
+
+type openIDUserInfoResponse struct {
+ Sub string `json:"sub"`
+}
+
+// GetOpenIDUserInfo implements GET /_matrix/federation/v1/openid/userinfo
+func GetOpenIDUserInfo(
+ httpReq *http.Request,
+ userAPI userapi.UserInternalAPI,
+) util.JSONResponse {
+ token := httpReq.URL.Query().Get("access_token")
+ if len(token) == 0 {
+ return util.JSONResponse{
+ Code: http.StatusUnauthorized,
+ JSON: jsonerror.MissingArgument("access_token is missing"),
+ }
+ }
+
+ req := userapi.QueryOpenIDTokenRequest{
+ Token: token,
+ }
+
+ var openIDTokenAttrResponse userapi.QueryOpenIDTokenResponse
+ err := userAPI.QueryOpenIDToken(httpReq.Context(), &req, &openIDTokenAttrResponse)
+ if err != nil {
+ util.GetLogger(httpReq.Context()).WithError(err).Error("userAPI.QueryOpenIDToken failed")
+ }
+
+ var res interface{} = openIDUserInfoResponse{Sub: openIDTokenAttrResponse.Sub}
+ code := http.StatusOK
+ nowMS := time.Now().UnixNano() / int64(time.Millisecond)
+ if openIDTokenAttrResponse.Sub == "" || nowMS > openIDTokenAttrResponse.ExpiresAtMS {
+ code = http.StatusUnauthorized
+ res = jsonerror.UnknownToken("Access Token unknown or expired")
+ }
+
+ return util.JSONResponse{
+ Code: code,
+ JSON: res,
+ }
+}
diff --git a/federationapi/routing/routing.go b/federationapi/routing/routing.go
index ce018904..07a28c3f 100644
--- a/federationapi/routing/routing.go
+++ b/federationapi/routing/routing.go
@@ -462,4 +462,10 @@ func Setup(
return QueryDeviceKeys(httpReq, request, keyAPI, cfg.Matrix.ServerName)
},
)).Methods(http.MethodPost)
+
+ v1fedmux.Handle("/openid/userinfo",
+ httputil.MakeExternalAPI("federation_openid_userinfo", func(req *http.Request) util.JSONResponse {
+ return GetOpenIDUserInfo(req, userAPI)
+ }),
+ ).Methods(http.MethodGet)
}