yggdrasil/src/server/auth/refresh.rs

84 lines
3.0 KiB
Rust

/*
* Yggdrasil: Minecraft authentication server
* Copyright (C) 2023 0xf8.dev@proton.me
*
* This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
use anyhow::anyhow;
use log::debug;
use tide::{prelude::*, Request, Result};
use yggdrasil::Database;
use yggdrasil::errors::YggdrasilError;
use yggdrasil::structs::{cape::Cape, token::Token};
#[derive(Deserialize, Debug)]
struct RefreshBody {
#[serde(rename = "accessToken")]
access_token: String,
#[serde(rename = "clientToken")]
client_token: String,
#[serde(rename = "requestUser")]
pub request_user: Option<bool>,
}
pub async fn refresh(mut req: Request<Database>) -> Result {
let Ok(body) = req.body_json::<RefreshBody>().await else {
// No credentials
return Err(YggdrasilError::new_bad_request("Credentials can not be null.").into())
};
debug!("accessToken: {}", body.access_token);
debug!("clientToken: {}", body.client_token);
let Some(token) = Token::from_access_token(req.state(), body.access_token).await else {
// Token doesn't exist
return Err(YggdrasilError::new_unauthorized("Invalid token.").into())
};
// Verify token
if !token.validate_with(req.state(), body.client_token, false).await? {
return Err(YggdrasilError::new_unauthorized("Invalid token.").into())
}
// Delete old token
token.delete(req.state()).await?;
let Some(new_token) = Token::new(req.state(), token.account, token.client).await else {
return Err(YggdrasilError::new_bad_request("Couldn't create new token").into())
};
// Create response
let mut response = json!({
"accessToken": new_token.access,
"clientToken": new_token.client
});
// Give selected profile if it exists
if let Some(profile) = new_token.account.selected_profile.to_owned() {
response["selectedProfile"] = json!({
"id": profile.uuid,
"name": profile.name,
"name_history": profile.name_history,
"skin_variant": profile.skin_variant,
"capes": match profile.capes {
Some(capes) => Cape::capes_to_string(capes),
None => "".to_string()
},
"active_cape": profile.active_cape,
"attributes": profile.attributes.to_json()
});
}
// Give user if requested
if body.request_user.unwrap_or(false) { response["user"] = new_token.account.to_user() }
Ok(response.into())
}