2018-09-26 23:38:44 +03:00
|
|
|
// Copyright 2018 The Grin Developers
|
|
|
|
//
|
|
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
// you may not use this file except in compliance with the License.
|
|
|
|
// You may obtain a copy of the License at
|
|
|
|
//
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
//
|
|
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
// See the License for the specific language governing permissions and
|
|
|
|
// limitations under the License.
|
|
|
|
|
2018-12-08 02:59:40 +03:00
|
|
|
use crate::router::{Handler, HandlerObj, ResponseFuture};
|
2019-03-18 21:34:35 +03:00
|
|
|
use crate::web::response;
|
2018-09-26 23:38:44 +03:00
|
|
|
use futures::future::ok;
|
|
|
|
use hyper::header::{HeaderValue, AUTHORIZATION, WWW_AUTHENTICATE};
|
|
|
|
use hyper::{Body, Request, Response, StatusCode};
|
2018-10-09 16:32:53 +03:00
|
|
|
use ring::constant_time::verify_slices_are_equal;
|
2018-09-26 23:38:44 +03:00
|
|
|
|
2019-03-18 21:34:35 +03:00
|
|
|
lazy_static! {
|
|
|
|
pub static ref GRIN_BASIC_REALM: HeaderValue =
|
|
|
|
HeaderValue::from_str("Basic realm=GrinAPI").unwrap();
|
|
|
|
}
|
|
|
|
|
2018-09-26 23:38:44 +03:00
|
|
|
// Basic Authentication Middleware
|
|
|
|
pub struct BasicAuthMiddleware {
|
|
|
|
api_basic_auth: String,
|
2019-03-18 21:34:35 +03:00
|
|
|
basic_realm: &'static HeaderValue,
|
2018-09-26 23:38:44 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
impl BasicAuthMiddleware {
|
2019-03-18 21:34:35 +03:00
|
|
|
pub fn new(api_basic_auth: String, basic_realm: &'static HeaderValue) -> BasicAuthMiddleware {
|
2018-09-26 23:38:44 +03:00
|
|
|
BasicAuthMiddleware {
|
|
|
|
api_basic_auth,
|
|
|
|
basic_realm,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl Handler for BasicAuthMiddleware {
|
|
|
|
fn call(
|
|
|
|
&self,
|
|
|
|
req: Request<Body>,
|
2018-12-08 02:59:40 +03:00
|
|
|
mut handlers: Box<dyn Iterator<Item = HandlerObj>>,
|
2018-09-26 23:38:44 +03:00
|
|
|
) -> ResponseFuture {
|
2019-03-18 21:34:35 +03:00
|
|
|
let next_handler = match handlers.next() {
|
|
|
|
Some(h) => h,
|
|
|
|
None => return response(StatusCode::INTERNAL_SERVER_ERROR, "no handler found"),
|
|
|
|
};
|
2018-12-11 20:47:10 +03:00
|
|
|
if req.method().as_str() == "OPTIONS" {
|
2019-03-18 21:34:35 +03:00
|
|
|
return next_handler.call(req, handlers);
|
2018-12-11 20:47:10 +03:00
|
|
|
}
|
2018-12-08 02:59:40 +03:00
|
|
|
if req.headers().contains_key(AUTHORIZATION)
|
|
|
|
&& verify_slices_are_equal(
|
|
|
|
req.headers()[AUTHORIZATION].as_bytes(),
|
|
|
|
&self.api_basic_auth.as_bytes(),
|
|
|
|
)
|
|
|
|
.is_ok()
|
2018-09-29 10:28:25 +03:00
|
|
|
{
|
2019-03-18 21:34:35 +03:00
|
|
|
next_handler.call(req, handlers)
|
2018-09-26 23:38:44 +03:00
|
|
|
} else {
|
|
|
|
// Unauthorized 401
|
|
|
|
unauthorized_response(&self.basic_realm)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-03-18 21:34:35 +03:00
|
|
|
fn unauthorized_response(basic_realm: &HeaderValue) -> ResponseFuture {
|
2018-09-26 23:38:44 +03:00
|
|
|
let response = Response::builder()
|
|
|
|
.status(StatusCode::UNAUTHORIZED)
|
2019-03-18 21:34:35 +03:00
|
|
|
.header(WWW_AUTHENTICATE, basic_realm)
|
2018-12-08 02:59:40 +03:00
|
|
|
.body(Body::empty())
|
2018-09-26 23:38:44 +03:00
|
|
|
.unwrap();
|
|
|
|
Box::new(ok(response))
|
|
|
|
}
|