-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathjwt.go
More file actions
144 lines (132 loc) · 3.91 KB
/
jwt.go
File metadata and controls
144 lines (132 loc) · 3.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
package miniutils
import (
"bytes"
"encoding/json"
"errors"
"fmt"
"strings"
"time"
)
var (
ErrTokenFormat = errors.New("token is not a JWT")
ErrTokenExpired = errors.New("token is expired")
ErrTokenSign = errors.New("token sign error")
ErrTokenExp = errors.New("token lost field: exp")
)
func GetJwtBySecret(keyBytes []byte, bodyInfo map[string]interface{}) (string, error) {
headerInfo := map[string]interface{}{"typ": "JWT", "alg": "HS256"}
var sig, sstr string
var err error
if sstr, err = toJwtString(headerInfo, bodyInfo); err != nil {
return "", err
}
sig = Base64UrlEncode(GetSha256BySecret(sstr, keyBytes))
return strings.Join([]string{sstr, sig}, "."), nil
}
func toJwtString(headerInfo, bodyInfo map[string]interface{}) (string, error) {
var err error
parts := make([]string, 2)
for i := range parts {
var jsonValue []byte
if i == 0 {
jsonValue, err = json.Marshal(headerInfo)
} else {
jsonValue, err = json.Marshal(bodyInfo)
// log.Println("----jwt--toJsonString---:", string(jsonValue))
}
if err != nil {
return "", err
}
parts[i] = Base64UrlEncode(jsonValue)
}
return strings.Join(parts, "."), nil
}
type JsonWebToken struct {
secret, TokenString string
claims map[string]interface{}
}
// NewJwt init JsonWebToken by secret string
func NewJwt(secret string) *JsonWebToken {
return &JsonWebToken{secret: secret}
}
// Create JsonWebToken string
// Create(map[string]interface{}{"id": 123456789, "username": "Harvey"}, time.Second*time.Duration(3600))
func (j *JsonWebToken) Create(claims map[string]interface{}, expiresin time.Duration) (token string, err error) {
_, ok := claims["exp"]
if !ok {
claims["exp"] = time.Now().Add(expiresin).Unix()
}
token, err = GetJwtBySecret([]byte(j.secret), claims)
if err != nil {
err = fmt.Errorf("GetJwtBySecret error: %w", err)
return
}
j.TokenString = token
j.claims = claims
return
}
// JsonDecodeUseNumber 解析带数字的JSON
func JsonDecodeUseNumber(infoBytes []byte, result interface{}) error {
// err = json.Unmarshal(infoBytes, result) 时间戳 int64 转json会变 float64
// 未设置UseNumber长整型会丢失精度
decoder := json.NewDecoder(bytes.NewReader(infoBytes))
decoder.UseNumber()
// fmt.Printf("----JsonDecodeUseNumber--(%p)-(%p)-----\n", result, &result)
return decoder.Decode(result)
}
// Decode 解码JWT字符串。reads the JsonWebToken string. Return the JWT decoded data.
func (j *JsonWebToken) Decode(jwtStr string) (result map[string]interface{}, err error) {
tokenSplit := strings.Split(jwtStr, ".")
if len(tokenSplit) != 3 {
err = ErrTokenFormat
return
}
var infoBytes []byte
infoBytes, err = Base64UrlDecode(tokenSplit[1])
if err != nil {
err = fmt.Errorf("Base64UrlDecode error: %w", err)
return
}
// fmt.Printf("----Decode1--(%p)-(%p)--\n", result, &result)
// result = make(map[string]interface{})
// fmt.Printf("----Decode2---(%p)-(%p)--\n", result, &result)
err = JsonDecodeUseNumber(infoBytes, &result) // &result 传递非空指针. 不加取址符&导致空指针错误: json: Unmarshal(non-pointer map[string]interface {})
if err != nil {
err = fmt.Errorf("JsonDecodeUseNumber error: %w", err)
}
j.claims = result
return
}
// Parse 解码JWT字符串,并验证其有效性。reads the JsonWebToken string. Check the JWT decoded data and return.
func (j *JsonWebToken) Parse(jwtStr string) (result map[string]interface{}, err error) {
if j.claims != nil {
result = j.claims
} else {
result, err = j.Decode(jwtStr)
if err != nil {
return
}
}
exp, ok := result["exp"]
if ok {
expiredAt, _ := exp.(json.Number).Int64()
if expiredAt < time.Now().Unix() {
err = ErrTokenExpired
return
}
} else {
err = ErrTokenExp
return
}
var okToken string
okToken, err = GetJwtBySecret([]byte(j.secret), result)
if err != nil {
err = fmt.Errorf("GetJwtBySecret error: %w", err)
return
}
if okToken != jwtStr {
err = ErrTokenSign
return
}
return
}