token.go 1.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960
  1. package main
  2. import (
  3. "crypto/sha256"
  4. "time"
  5. "github.com/dgrijalva/jwt-go"
  6. )
  7. func generateTokenPair(user userInfo, cockieStr string) (map[string]string, error) {
  8. //fmt.Println(user.Result.Result.UID)
  9. // Create token
  10. token := jwt.New(jwt.SigningMethodHS256)
  11. // Set claims
  12. // This is the information which frontend can use
  13. // The backend can also decode the token and get admin etc.
  14. claims := token.Claims.(jwt.MapClaims)
  15. claims["admin"] = false
  16. for _, v := range user.Result.Result.MemberofGroup {
  17. if v == "usermodifier" || v == "admins" {
  18. claims["admin"] = true
  19. }
  20. }
  21. claims["sub"] = 1
  22. claims["name"] = user.Result.Result.UID[0]
  23. claims["fullname"] = user.Result.Result.Displayname
  24. claims["IPAUid"] = user.Result.Result.Uidnumber[0]
  25. sha256 := sha256.Sum256([]byte(user.Result.Result.UID[0]))
  26. var hashChannel = make(chan []byte, 1)
  27. hashChannel <- sha256[:]
  28. claims["IPAToken"] = encrypt(<-hashChannel, cockieStr)
  29. claims["memberof"] = user.Result.Result.MemberofGroup
  30. claims["mail"] = user.Result.Result.Mail
  31. claims["exp"] = time.Now().Add(time.Minute * 15).Unix()
  32. // Generate encoded token and send it as response.
  33. // The signing string should be secret (a generated UUID works too)
  34. t, err := token.SignedString([]byte("secret"))
  35. if err != nil {
  36. return nil, err
  37. }
  38. refreshToken := jwt.New(jwt.SigningMethodHS256)
  39. rtClaims := refreshToken.Claims.(jwt.MapClaims)
  40. rtClaims["sub"] = 1
  41. rtClaims["IPAToken"] = claims["IPAToken"]
  42. rtClaims["name"] = claims["name"]
  43. rtClaims["exp"] = time.Now().Add(time.Hour * 1).Unix()
  44. rt, err := refreshToken.SignedString([]byte("secret"))
  45. if err != nil {
  46. return nil, err
  47. }
  48. return map[string]string{
  49. "access_token": t,
  50. "refresh_token": rt,
  51. }, nil
  52. }