summary refs log tree commit diff
path: root/extra/admin-api/Spacebar.AdminAPI/Services/AuthenticationService.cs
diff options
context:
space:
mode:
authorRory& <root@rory.gay>2025-12-14 23:18:35 +0100
committerRory& <root@rory.gay>2025-12-14 23:18:35 +0100
commit4534d4dbf5f5071fa71c5dec4444bf4b2bbd040c (patch)
tree614304bd951f09a73155a9bd9ee192cf946e854a /extra/admin-api/Spacebar.AdminAPI/Services/AuthenticationService.cs
parentNo longer generate security_jwtSecret, switch webauthn to modern tokens, dont (diff)
downloadserver-ts-4534d4dbf5f5071fa71c5dec4444bf4b2bbd040c.tar.xz
admin api packaging
Diffstat (limited to 'extra/admin-api/Spacebar.AdminAPI/Services/AuthenticationService.cs')
-rw-r--r--extra/admin-api/Spacebar.AdminAPI/Services/AuthenticationService.cs42
1 files changed, 0 insertions, 42 deletions
diff --git a/extra/admin-api/Spacebar.AdminAPI/Services/AuthenticationService.cs b/extra/admin-api/Spacebar.AdminAPI/Services/AuthenticationService.cs
deleted file mode 100644

index d402c5b9..00000000 --- a/extra/admin-api/Spacebar.AdminAPI/Services/AuthenticationService.cs +++ /dev/null
@@ -1,42 +0,0 @@ -using System.IdentityModel.Tokens.Jwt; -using System.Security.Cryptography; -using Microsoft.IdentityModel.Tokens; -using Spacebar.Db.Contexts; -using Spacebar.Db.Models; - -namespace Spacebar.AdminAPI.Services; - -public class AuthenticationService(SpacebarDbContext db, Configuration config) { - private static Dictionary<string, User> _userCache = new(); - private static Dictionary<string, DateTime> _userCacheExpiry = new(); - - public async Task<User> GetCurrentUser(HttpRequest request) { - if (!request.Headers.ContainsKey("Authorization")) { - Console.WriteLine(string.Join(", ", request.Headers.Keys)); - throw new UnauthorizedAccessException(); - } - - var token = request.Headers["Authorization"].ToString().Split(' ').Last(); - - var handler = new JwtSecurityTokenHandler(); - var secretFile = File.ReadAllText("../../../jwt.key.pub"); - var key = ECDsa.Create(ECCurve.NamedCurves.nistP256); - key.ImportFromPem(secretFile); - - var res = await handler.ValidateTokenAsync(token, new TokenValidationParameters { - IssuerSigningKey = new ECDsaSecurityKey(key), - ValidAlgorithms = ["ES512"], - LogValidationExceptions = true, - // These are required to be false for the token to be valid as they aren't provided by the token - ValidateIssuer = false, - ValidateLifetime = false, - ValidateAudience = false, - }); - - if (!res.IsValid && !config.DisableAuthentication) { - throw new UnauthorizedAccessException(); - } - - return await db.Users.FindAsync(config.OverrideUid ?? res.ClaimsIdentity.Claims.First(x => x.Type == "id").Value) ?? throw new InvalidOperationException(); - } -} \ No newline at end of file