Add check for provider key

This commit is contained in:
kolaente 2020-10-25 16:05:24 +01:00
parent 712e8624ed
commit 2a79d5a35c
Signed by: konrad
GPG Key ID: F40E70337AB24C9B

View File

@ -21,6 +21,8 @@ import (
"code.vikunja.io/api/pkg/models" "code.vikunja.io/api/pkg/models"
"github.com/labstack/echo/v4" "github.com/labstack/echo/v4"
"net/http" "net/http"
"regexp"
"strings"
) )
type Callback struct { type Callback struct {
@ -31,12 +33,17 @@ type Callback struct {
type Provider struct { type Provider struct {
Name string `json:"name"` Name string `json:"name"`
Key string `json:"key"`
AuthURL string `json:"auth_url"` AuthURL string `json:"auth_url"`
ClientID string `json:"client_id"` ClientID string `json:"client_id"`
} }
func GetAllProviders() (providers []*Provider) { func getKeyFromName(name string) string {
reg, _ := regexp.Compile("[^a-z0-9]+")
return reg.ReplaceAllString(strings.ToLower(name), "")
}
func GetAllProviders() (providers []*Provider) {
rawProvider := config.AuthOpenIDProviders.Get().([]interface{}) rawProvider := config.AuthOpenIDProviders.Get().([]interface{})
for _, p := range rawProvider { for _, p := range rawProvider {
@ -44,6 +51,7 @@ func GetAllProviders() (providers []*Provider) {
providers = append(providers, &Provider{ providers = append(providers, &Provider{
Name: pi["name"].(string), Name: pi["name"].(string),
Key: getKeyFromName(pi["name"].(string)),
AuthURL: pi["authurl"].(string), AuthURL: pi["authurl"].(string),
ClientID: pi["clientid"].(string), ClientID: pi["clientid"].(string),
}) })
@ -52,6 +60,26 @@ func GetAllProviders() (providers []*Provider) {
return return
} }
func GetProvider(key string) *Provider {
rawProvider := config.AuthOpenIDProviders.Get().([]interface{})
for _, p := range rawProvider {
pi := p.(map[interface{}]interface{})
k := getKeyFromName(pi["name"].(string))
if k == key {
return &Provider{
Name: pi["name"].(string),
Key: k,
AuthURL: pi["authurl"].(string),
ClientID: pi["clientid"].(string),
}
}
}
return nil
}
func HandleCallback(c echo.Context) error { func HandleCallback(c echo.Context) error {
cb := &Callback{} cb := &Callback{}
if err := c.Bind(cb); err != nil { if err := c.Bind(cb); err != nil {
@ -59,7 +87,11 @@ func HandleCallback(c echo.Context) error {
} }
// Check if the provider exists // Check if the provider exists
//providerKey := c.Param("provider") providerKey := c.Param("provider")
provider := GetProvider(providerKey)
if provider == nil {
return c.JSON(http.StatusBadRequest, models.Message{Message: "Provider does not exist"})
}
// Parse the access & ID token // Parse the access & ID token