-
-
Notifications
You must be signed in to change notification settings - Fork 762
/
Copy pathstrategy.ts
176 lines (134 loc) · 5.03 KB
/
strategy.ts
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
import {
AuthenticationRequest,
AuthenticationBaseStrategy,
AuthenticationResult,
AuthenticationParams
} from '@feathersjs/authentication'
import { Params } from '@feathersjs/feathers'
import { NotAuthenticated } from '@feathersjs/errors'
import { createDebug, _ } from '@feathersjs/commons'
import qs from 'qs'
const debug = createDebug('@feathersjs/authentication-oauth/strategy')
export interface OAuthProfile {
id?: string | number
[key: string]: any
}
export class OAuthStrategy extends AuthenticationBaseStrategy {
get configuration() {
const { entity, service, entityId, oauth } = this.authentication.configuration
const config = oauth[this.name] as any
return {
entity,
service,
entityId,
...config
}
}
get entityId(): string {
const { entityService } = this
return this.configuration.entityId || (entityService && (entityService as any).id)
}
async getEntityQuery(profile: OAuthProfile, _params: Params) {
return {
[`${this.name}Id`]: profile.sub || profile.id
}
}
async getEntityData(profile: OAuthProfile, _existingEntity: any, _params: Params) {
return {
[`${this.name}Id`]: profile.sub || profile.id
}
}
async getProfile(data: AuthenticationRequest, _params: Params) {
return data.profile
}
async getCurrentEntity(params: Params) {
const { authentication } = params
const { entity } = this.configuration
if (authentication && authentication.strategy) {
debug('getCurrentEntity with authentication', authentication)
const { strategy } = authentication
const authResult = await this.authentication.authenticate(authentication, params, strategy)
return authResult[entity]
}
return null
}
async getAllowedOrigin(params?: Params) {
const { redirect, origins = this.app.get('origins') } = this.authentication.configuration.oauth
if (Array.isArray(origins)) {
const referer = params?.headers?.referer || origins[0]
const allowedOrigin = origins.find((current) => referer.toLowerCase().startsWith(current.toLowerCase()))
if (!allowedOrigin) {
throw new NotAuthenticated(`Referer "${referer}" is not allowed.`)
}
return allowedOrigin
}
return redirect
}
async getRedirect(
data: AuthenticationResult | Error,
params?: AuthenticationParams
): Promise<string | null> {
const queryRedirect = (params && params.redirect) || ''
const redirect = await this.getAllowedOrigin(params)
if (!redirect) {
return null
}
const redirectUrl = `${redirect}${queryRedirect}`
const separator = redirectUrl.endsWith('?') ? '' : redirect.indexOf('#') !== -1 ? '?' : '#'
const authResult: AuthenticationResult = data
const query = authResult.accessToken
? { access_token: authResult.accessToken }
: { error: data.message || 'OAuth Authentication not successful' }
return `${redirectUrl}${separator}${qs.stringify(query)}`
}
async findEntity(profile: OAuthProfile, params: Params) {
const query = await this.getEntityQuery(profile, params)
debug('findEntity with query', query)
const result = await this.entityService.find({
...params,
query
})
const [entity = null] = result.data ? result.data : result
debug('findEntity returning', entity)
return entity
}
async createEntity(profile: OAuthProfile, params: Params) {
const data = await this.getEntityData(profile, null, params)
debug('createEntity with data', data)
return this.entityService.create(data, _.omit(params, 'query'))
}
async updateEntity(entity: any, profile: OAuthProfile, params: Params) {
const id = entity[this.entityId]
const data = await this.getEntityData(profile, entity, params)
debug(`updateEntity with id ${id} and data`, data)
return this.entityService.patch(id, data, _.omit(params, 'query'))
}
async getEntity(result: any, params: Params) {
const { entityService } = this
const { entityId = (entityService as any).id, entity } = this.configuration
if (!entityId || result[entityId] === undefined) {
throw new NotAuthenticated('Could not get oAuth entity')
}
if (!params.provider) {
return result
}
return entityService.get(result[entityId], {
..._.omit(params, 'query'),
[entity]: result
})
}
async authenticate(authentication: AuthenticationRequest, originalParams: AuthenticationParams) {
const entity: string = this.configuration.entity
const { provider, ...params } = originalParams
const profile = await this.getProfile(authentication, params)
const existingEntity = (await this.findEntity(profile, params)) || (await this.getCurrentEntity(params))
debug('authenticate with (existing) entity', existingEntity)
const authEntity = !existingEntity
? await this.createEntity(profile, params)
: await this.updateEntity(existingEntity, profile, params)
return {
authentication: { strategy: this.name },
[entity]: await this.getEntity(authEntity, originalParams)
}
}
}