mirror of
				https://github.com/superseriousbusiness/gotosocial.git
				synced 2025-10-31 02:12:24 -05:00 
			
		
		
		
	# Description
- tweaks the NoLLaMas proof-of-work algorithm to further granularity on time spent computing solutions
- standardizes GoToSocial cookie security directive setting in a CookiePolicy{} type
## Checklist
- [x] I/we have read the [GoToSocial contribution guidelines](https://codeberg.org/superseriousbusiness/gotosocial/src/branch/main/CONTRIBUTING.md).
- [x] I/we have discussed the proposed changes already, either in an issue on the repository, or in the Matrix chat.
- [x] I/we have not leveraged AI to create the proposed changes.
- [x] I/we have performed a self-review of added code.
- [x] I/we have written code that is legible and maintainable by others.
- [x] I/we have commented the added code, particularly in hard-to-understand areas.
- [ ] I/we have made any necessary changes to documentation.
- [ ] I/we have added tests that cover new code.
- [ ] I/we have run tests and they pass locally with the changes.
- [x] I/we have run `go fmt ./...` and `golangci-lint run`.
Co-authored-by: tobi <tobi.smethurst@protonmail.com>
Reviewed-on: https://codeberg.org/superseriousbusiness/gotosocial/pulls/4090
Co-authored-by: kim <grufwub@gmail.com>
Co-committed-by: kim <grufwub@gmail.com>
		
	
			
		
			
				
	
	
		
			82 lines
		
	
	
	
		
			2.6 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
			
		
		
	
	
			82 lines
		
	
	
	
		
			2.6 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
| // GoToSocial
 | |
| // Copyright (C) GoToSocial Authors admin@gotosocial.org
 | |
| // SPDX-License-Identifier: AGPL-3.0-or-later
 | |
| //
 | |
| // This program is free software: you can redistribute it and/or modify
 | |
| // it under the terms of the GNU Affero General Public License as published by
 | |
| // the Free Software Foundation, either version 3 of the License, or
 | |
| // (at your option) any later version.
 | |
| //
 | |
| // This program is distributed in the hope that it will be useful,
 | |
| // but WITHOUT ANY WARRANTY; without even the implied warranty of
 | |
| // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | |
| // GNU Affero General Public License for more details.
 | |
| //
 | |
| // You should have received a copy of the GNU Affero General Public License
 | |
| // along with this program.  If not, see <http://www.gnu.org/licenses/>.
 | |
| 
 | |
| package api
 | |
| 
 | |
| import (
 | |
| 	"code.superseriousbusiness.org/gotosocial/internal/api/auth"
 | |
| 	apiutil "code.superseriousbusiness.org/gotosocial/internal/api/util"
 | |
| 	"code.superseriousbusiness.org/gotosocial/internal/gtsmodel"
 | |
| 	"code.superseriousbusiness.org/gotosocial/internal/middleware"
 | |
| 	"code.superseriousbusiness.org/gotosocial/internal/oidc"
 | |
| 	"code.superseriousbusiness.org/gotosocial/internal/processing"
 | |
| 	"code.superseriousbusiness.org/gotosocial/internal/router"
 | |
| 	"code.superseriousbusiness.org/gotosocial/internal/state"
 | |
| 	"github.com/gin-gonic/gin"
 | |
| )
 | |
| 
 | |
| type Auth struct {
 | |
| 	routerSession *gtsmodel.RouterSession
 | |
| 	sessionName   string
 | |
| 	cookiePolicy  apiutil.CookiePolicy
 | |
| 
 | |
| 	auth *auth.Module
 | |
| }
 | |
| 
 | |
| // Route attaches 'auth' and 'oauth' groups to the given router.
 | |
| func (a *Auth) Route(r *router.Router, m ...gin.HandlerFunc) {
 | |
| 	// create groupings for the 'auth' and 'oauth' prefixes
 | |
| 	authGroup := r.AttachGroup("auth")
 | |
| 	oauthGroup := r.AttachGroup("oauth")
 | |
| 
 | |
| 	// instantiate + attach shared, non-global middlewares to both of these groups
 | |
| 	var (
 | |
| 		ccMiddleware = middleware.CacheControl(middleware.CacheControlConfig{
 | |
| 			Directives: []string{"private", "max-age=120"},
 | |
| 			Vary:       []string{"Accept", "Accept-Encoding"},
 | |
| 		})
 | |
| 		sessionMiddleware = middleware.Session(
 | |
| 			a.sessionName,
 | |
| 			a.routerSession.Auth,
 | |
| 			a.routerSession.Crypt,
 | |
| 			a.cookiePolicy,
 | |
| 		)
 | |
| 	)
 | |
| 	authGroup.Use(m...)
 | |
| 	oauthGroup.Use(m...)
 | |
| 	authGroup.Use(ccMiddleware, sessionMiddleware)
 | |
| 	oauthGroup.Use(ccMiddleware, sessionMiddleware)
 | |
| 
 | |
| 	a.auth.RouteAuth(authGroup.Handle)
 | |
| 	a.auth.RouteOAuth(oauthGroup.Handle)
 | |
| }
 | |
| 
 | |
| func NewAuth(
 | |
| 	state *state.State,
 | |
| 	p *processing.Processor,
 | |
| 	idp oidc.IDP,
 | |
| 	routerSession *gtsmodel.RouterSession,
 | |
| 	sessionName string,
 | |
| 	cookiePolicy apiutil.CookiePolicy,
 | |
| ) *Auth {
 | |
| 	return &Auth{
 | |
| 		routerSession: routerSession,
 | |
| 		sessionName:   sessionName,
 | |
| 		cookiePolicy:  cookiePolicy,
 | |
| 		auth:          auth.New(state, p, idp),
 | |
| 	}
 | |
| }
 |