add http method validation on each route + add pubkey tests
This commit is contained in:
@@ -217,6 +217,10 @@ impl HTTPRequest {
|
||||
}
|
||||
}
|
||||
|
||||
pub fn get_method(&self) -> String {
|
||||
self.start_line.method.clone()
|
||||
}
|
||||
|
||||
#[allow(dead_code)]
|
||||
pub fn is_valid(&self) -> bool {
|
||||
return self.start_line.is_valid();
|
||||
|
||||
+19
-6
@@ -14,7 +14,11 @@ const GET_ROUTE: &'static str = "/get/";
|
||||
const VALIDATE_ROUTE: &'static str = "/validate/";
|
||||
const PUBKEY_ROUTE: &'static str = "/pubkey/";
|
||||
|
||||
async fn handle_get(request: HTTPRequest, config: Config) -> HTTPResponse {
|
||||
async fn handle_get(request: HTTPRequest, config: Config, method: &str) -> HTTPResponse {
|
||||
if method.trim().to_lowercase() != "post" {
|
||||
return HTTPResponse::as_400();
|
||||
}
|
||||
|
||||
let mut store = FileStore::new(config.filestore_path.clone());
|
||||
match &request.body {
|
||||
Some(ref b) => {
|
||||
@@ -48,7 +52,11 @@ async fn handle_get(request: HTTPRequest, config: Config) -> HTTPResponse {
|
||||
/// validates the token by checking:
|
||||
/// * expiration time
|
||||
/// * signature
|
||||
async fn handle_validate(request: HTTPRequest, config: Config) -> HTTPResponse {
|
||||
async fn handle_validate(request: HTTPRequest, config: Config, method: &str) -> HTTPResponse {
|
||||
if request.get_method().trim().to_lowercase() != method {
|
||||
return HTTPResponse::as_400();
|
||||
}
|
||||
|
||||
let token = {
|
||||
match request.get_body_value("token") {
|
||||
Some(t) => t,
|
||||
@@ -90,7 +98,11 @@ async fn handle_validate(request: HTTPRequest, config: Config) -> HTTPResponse {
|
||||
}
|
||||
|
||||
/// returns the JWT public key in base64 encoded
|
||||
async fn handle_public_key(_request: HTTPRequest, config: Config) -> HTTPResponse {
|
||||
async fn handle_public_key(request: HTTPRequest, config: Config, method: &str) -> HTTPResponse {
|
||||
if request.get_method().trim().to_lowercase() != method {
|
||||
return HTTPResponse::as_400();
|
||||
}
|
||||
|
||||
let jwt_signer = {
|
||||
match JWTSigner::new(config).await {
|
||||
Ok(s) => s,
|
||||
@@ -114,6 +126,7 @@ async fn handle_public_key(_request: HTTPRequest, config: Config) -> HTTPRespons
|
||||
pub struct Router;
|
||||
|
||||
impl Router {
|
||||
/// routes the request to the corresponding handling method
|
||||
pub async fn route(&self, request_str: &str, addr: String, config: Config) -> HTTPResponse {
|
||||
let mut request = HTTPRequest::from(request_str);
|
||||
request.set_addr(addr);
|
||||
@@ -121,9 +134,9 @@ impl Router {
|
||||
let target = request.start_line.get_target();
|
||||
|
||||
match target.as_str() {
|
||||
GET_ROUTE => handle_get(request, config).await,
|
||||
VALIDATE_ROUTE => handle_validate(request, config).await,
|
||||
PUBKEY_ROUTE => handle_public_key(request, config).await,
|
||||
GET_ROUTE => handle_get(request, config, "post").await,
|
||||
VALIDATE_ROUTE => handle_validate(request, config, "post").await,
|
||||
PUBKEY_ROUTE => handle_public_key(request, config, "get").await,
|
||||
_ => HTTPResponse::as_404(),
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user