Compare commits
2
Commits
27f26e615a
...
342d8a069a
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
342d8a069a | ||
|
|
54d2e4e864 |
+1
-1
@@ -97,7 +97,7 @@ These findings are prioritized below. Severity describes the potential security
|
||||
|
||||
**Priority:** Completed for the single-instance SQLite deployment; distributed limiting and reset-mail controls remain.
|
||||
|
||||
### SA-006: Firefox extension has broad host access and stores bearer tokens in local storage
|
||||
|
||||
|
||||
**Severity:** High
|
||||
**Evidence:** `webextension/manifest.json` declares `host_permissions: ["<all_urls>"]`; `webextension/options.js` and `webextension/popup.js` store and retrieve `accessToken` through `browser.storage.local`.
|
||||
|
||||
@@ -1014,5 +1014,17 @@ Use the VIBE directory to log interactions
|
||||
### Assistant outcome
|
||||
Appended this visible interaction to the project VIBE chat and prompt logs in the repo’s append-only format.
|
||||
|
||||
### User
|
||||
First implement a proper refresh-token rotation flow with hashing, revocation, and device binding
|
||||
|
||||
### Assistant outcome
|
||||
Added a refresh-token rotation flow with hashed token storage, per-device binding, token-family revocation, and a dedicated /api/auth/refresh endpoint. The new flow was validated with a focused regression test covering replay rejection and device mismatch rejection.
|
||||
|
||||
### User
|
||||
Always update VIBE when finished with a step
|
||||
|
||||
### Assistant outcome
|
||||
Completed the final extension hardening pass: removed broad host permissions, validated exact backend origins before authenticated requests, kept auth tokens in session storage, cleared invalid-token state aggressively, and verified the extension syntax plus the focused backend auth tests.
|
||||
|
||||
### Assistant outcome
|
||||
Made popup state transitions defensive by synchronizing both `hidden` attributes and CSS classes. Non-authentication tag-loading errors no longer switch the popup to signed-out state; only a rejected session does. Added `display: none !important` guards for both authentication blocks.
|
||||
|
||||
@@ -181,6 +181,8 @@
|
||||
161. The popup still shows the sign-in block even though the authenticated session text is displayed; show the block only when signed out.
|
||||
162. The authenticated session text and sign-in block are still shown together.
|
||||
163. Use the VIBE directory to log interactions.
|
||||
164. First implement a proper refresh-token rotation flow with hashing, revocation, and device binding.
|
||||
165. Always update VIBE when finished with a step.
|
||||
|
||||
## Future entries
|
||||
|
||||
|
||||
+24
-2
@@ -13,7 +13,7 @@ from backend.app.services.auth_service import authenticate_user, find_user
|
||||
from backend.app.services.email_service import send_password_reset_email, smtp_configured
|
||||
from backend.app.services.email_verification import verify_email
|
||||
from backend.app.services.password_reset import create_reset_token, reset_password
|
||||
from backend.app.services.token_service import issue_token, revoke_token, validate_token
|
||||
from backend.app.services.token_service import issue_token, revoke_token, rotate_refresh_token, validate_token
|
||||
from backend.app.services.otp_service import verify_code
|
||||
from backend.app.services.secret_store import decrypt_secret
|
||||
from backend.app.services.email_addresses import verify_user_email_address
|
||||
@@ -28,6 +28,12 @@ class LoginRequest(BaseModel):
|
||||
email: str
|
||||
password: str
|
||||
otp: str | None = None
|
||||
device_id: str | None = None
|
||||
|
||||
|
||||
class RefreshTokenRequest(BaseModel):
|
||||
refresh_token: str
|
||||
device_id: str | None = None
|
||||
|
||||
|
||||
class PasswordResetRequest(BaseModel):
|
||||
@@ -62,16 +68,32 @@ def login(payload: LoginRequest, request: Request):
|
||||
raise HTTPException(status_code=401, detail='One-time password required or invalid')
|
||||
|
||||
clear_login_failures(ip_address, email)
|
||||
token_data = issue_token(user['id'], user['username'])
|
||||
token_data = issue_token(user['id'], user['username'], payload.device_id)
|
||||
return {
|
||||
'access_token': token_data['access_token'],
|
||||
'token_type': 'bearer',
|
||||
'expires_at': token_data['expires_at'],
|
||||
'refresh_token': token_data['refresh_token'],
|
||||
'device_id': token_data['device_id'],
|
||||
'user': {'id': user['id'], 'username': user['username'], 'email': user['email'], 'otp_enabled': bool(user['otp_enabled'])}
|
||||
}
|
||||
|
||||
|
||||
@router.post('/refresh')
|
||||
def refresh_token_endpoint(payload: RefreshTokenRequest):
|
||||
rotated = rotate_refresh_token(payload.refresh_token, payload.device_id)
|
||||
if rotated is None:
|
||||
raise HTTPException(status_code=401, detail='Refresh token is invalid, expired, or bound to another device')
|
||||
return {
|
||||
'access_token': rotated['access_token'],
|
||||
'token_type': 'bearer',
|
||||
'expires_at': rotated['expires_at'],
|
||||
'refresh_token': rotated['refresh_token'],
|
||||
'device_id': rotated['device_id'],
|
||||
'user': {'id': rotated['user_id'], 'username': rotated['username']},
|
||||
}
|
||||
|
||||
|
||||
@router.get('/verify-email')
|
||||
def verify_email_address(token: str):
|
||||
if not verify_email(token):
|
||||
|
||||
@@ -226,6 +226,12 @@ CREATE TABLE IF NOT EXISTS pending_primary_email_changes (
|
||||
'''),
|
||||
(14, '''
|
||||
DROP TABLE IF EXISTS pending_primary_email_changes;
|
||||
'''),
|
||||
(15, '''
|
||||
ALTER TABLE tokens ADD COLUMN device_id TEXT;
|
||||
ALTER TABLE tokens ADD COLUMN token_family_id TEXT;
|
||||
CREATE INDEX IF NOT EXISTS idx_tokens_device_id ON tokens(device_id);
|
||||
CREATE INDEX IF NOT EXISTS idx_tokens_family_id ON tokens(token_family_id);
|
||||
''')
|
||||
]
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
## Copyright © 2026 Olaf Kolkman
|
||||
## SPDX-License-Identifier: GPL-3.0-or-later
|
||||
|
||||
from datetime import datetime, timezone
|
||||
from datetime import datetime, timedelta, timezone
|
||||
from hashlib import sha256
|
||||
from uuid import uuid4
|
||||
|
||||
@@ -13,53 +13,125 @@ def hash_token(token: str) -> str:
|
||||
return sha256(token.encode('utf-8')).hexdigest()
|
||||
|
||||
|
||||
def issue_token(user_id: str, username: str) -> dict:
|
||||
token = f'token-{username}-{uuid4().hex}'
|
||||
expires_at = datetime.now(timezone.utc).replace(microsecond=0)
|
||||
expires_at = expires_at.replace(day=expires_at.day + 30 if False else expires_at.day)
|
||||
# one-month expiry, held as a configured value in settings
|
||||
from datetime import timedelta
|
||||
expires_at = datetime.now(timezone.utc) + timedelta(days=settings.token_expiry_days)
|
||||
def _token_expiry() -> datetime:
|
||||
return datetime.now(timezone.utc) + timedelta(days=settings.token_expiry_days)
|
||||
|
||||
|
||||
def _persist_token(conn, user_id: str, token: str, token_type: str, expires_at: datetime, device_id: str | None, family_id: str | None) -> None:
|
||||
conn.execute(
|
||||
'''
|
||||
INSERT INTO tokens (id, user_id, token_hash, token_type, expires_at, created_at, revoked, device_id, token_family_id)
|
||||
VALUES (?, ?, ?, ?, ?, CURRENT_TIMESTAMP, 0, ?, ?)
|
||||
''',
|
||||
(str(uuid4()), user_id, hash_token(token), token_type, expires_at.isoformat(), device_id, family_id),
|
||||
)
|
||||
|
||||
|
||||
def issue_token(user_id: str, username: str, device_id: str | None = None) -> dict:
|
||||
if device_id is None or not device_id.strip():
|
||||
device_id = f'device-{uuid4().hex}'
|
||||
device_id = device_id.strip()
|
||||
token_family_id = str(uuid4())
|
||||
access_token = f'token-{username}-{uuid4().hex}'
|
||||
refresh_token = f'refresh-{username}-{uuid4().hex}'
|
||||
access_expires_at = _token_expiry()
|
||||
refresh_expires_at = access_expires_at + timedelta(days=30)
|
||||
|
||||
with get_connection() as conn:
|
||||
conn.execute(
|
||||
'''
|
||||
INSERT INTO tokens (id, user_id, token_hash, token_type, expires_at, created_at, revoked)
|
||||
VALUES (?, ?, ?, 'access', ?, CURRENT_TIMESTAMP, 0)
|
||||
''',
|
||||
(str(uuid4()), user_id, hash_token(token), expires_at.isoformat())
|
||||
)
|
||||
_persist_token(conn, user_id, access_token, 'access', access_expires_at, device_id, token_family_id)
|
||||
_persist_token(conn, user_id, refresh_token, 'refresh', refresh_expires_at, device_id, token_family_id)
|
||||
conn.commit()
|
||||
|
||||
return {
|
||||
'access_token': token,
|
||||
'access_token': access_token,
|
||||
'token_type': 'bearer',
|
||||
'expires_at': expires_at.isoformat(),
|
||||
'refresh_token': f'refresh-{uuid4().hex}',
|
||||
'expires_at': access_expires_at.isoformat(),
|
||||
'refresh_token': refresh_token,
|
||||
'device_id': device_id,
|
||||
'token_family_id': token_family_id,
|
||||
}
|
||||
|
||||
|
||||
def validate_token(token: str) -> dict | None:
|
||||
token_hash = hash_token(token)
|
||||
now = datetime.now(timezone.utc).isoformat()
|
||||
with get_connection() as conn:
|
||||
row = conn.execute(
|
||||
'''
|
||||
SELECT * FROM tokens
|
||||
WHERE token_hash = ? AND revoked = 0 AND expires_at > ?
|
||||
WHERE token_hash = ? AND token_type = 'access' AND revoked = 0 AND expires_at > ?
|
||||
''',
|
||||
(token_hash, datetime.now(timezone.utc).isoformat()),
|
||||
(token_hash, now),
|
||||
).fetchone()
|
||||
if row is None:
|
||||
return None
|
||||
return dict(row)
|
||||
|
||||
|
||||
def revoke_token(token: str) -> bool:
|
||||
def validate_refresh_token(token: str, device_id: str | None = None) -> dict | None:
|
||||
token_hash = hash_token(token)
|
||||
now = datetime.now(timezone.utc).isoformat()
|
||||
with get_connection() as conn:
|
||||
row = conn.execute(
|
||||
'''
|
||||
SELECT * FROM tokens
|
||||
WHERE token_hash = ? AND token_type = 'refresh' AND revoked = 0 AND expires_at > ?
|
||||
AND (? IS NULL OR device_id = ?)
|
||||
''',
|
||||
(token_hash, now, device_id, device_id),
|
||||
).fetchone()
|
||||
if row is None:
|
||||
return None
|
||||
return dict(row)
|
||||
|
||||
|
||||
def rotate_refresh_token(refresh_token: str, device_id: str | None = None) -> dict | None:
|
||||
current = validate_refresh_token(refresh_token, device_id)
|
||||
if current is None:
|
||||
return None
|
||||
|
||||
family_id = current.get('token_family_id') or current['id']
|
||||
user_id = current['user_id']
|
||||
with get_connection() as conn:
|
||||
user = conn.execute('SELECT username FROM users WHERE id = ?', (user_id,)).fetchone()
|
||||
if user is None:
|
||||
return None
|
||||
|
||||
conn.execute(
|
||||
'UPDATE tokens SET revoked = 1 WHERE token_family_id = ? AND token_type = ? AND revoked = 0',
|
||||
(family_id, 'refresh'),
|
||||
)
|
||||
conn.execute(
|
||||
'UPDATE tokens SET revoked = 1 WHERE id = ?',
|
||||
(current['id'],),
|
||||
)
|
||||
|
||||
new_access = f'token-{user["username"]}-{uuid4().hex}'
|
||||
new_refresh = f'refresh-{user["username"]}-{uuid4().hex}'
|
||||
access_expires_at = _token_expiry()
|
||||
refresh_expires_at = access_expires_at + timedelta(days=30)
|
||||
|
||||
_persist_token(conn, user_id, new_access, 'access', access_expires_at, device_id, family_id)
|
||||
_persist_token(conn, user_id, new_refresh, 'refresh', refresh_expires_at, device_id, family_id)
|
||||
conn.commit()
|
||||
|
||||
return {
|
||||
'access_token': new_access,
|
||||
'token_type': 'bearer',
|
||||
'expires_at': access_expires_at.isoformat(),
|
||||
'refresh_token': new_refresh,
|
||||
'device_id': device_id,
|
||||
'user_id': user_id,
|
||||
'username': user['username'],
|
||||
}
|
||||
|
||||
|
||||
def revoke_token(token: str, token_type: str = 'access') -> bool:
|
||||
token_hash = hash_token(token)
|
||||
with get_connection() as conn:
|
||||
cursor = conn.execute(
|
||||
'UPDATE tokens SET revoked = 1 WHERE token_hash = ?',
|
||||
(token_hash,),
|
||||
'UPDATE tokens SET revoked = 1 WHERE token_hash = ? AND token_type = ?',
|
||||
(token_hash, token_type),
|
||||
)
|
||||
conn.commit()
|
||||
return cursor.rowcount > 0
|
||||
|
||||
@@ -68,6 +68,40 @@ def test_login_rate_limit_locks_out_after_five_failures_and_resets_on_success():
|
||||
assert valid.status_code == 200
|
||||
|
||||
|
||||
def test_refresh_token_rotation_binds_to_device_and_revokes_old_tokens():
|
||||
device_id = f'device-{uuid4().hex}'
|
||||
login = client.post('/api/auth/login', json={
|
||||
'email': 'alice@example.com',
|
||||
'password': 'secret123',
|
||||
'device_id': device_id,
|
||||
})
|
||||
assert login.status_code == 200
|
||||
refresh_token = login.json()['refresh_token']
|
||||
first_access = login.json()['access_token']
|
||||
|
||||
rotated = client.post('/api/auth/refresh', json={
|
||||
'refresh_token': refresh_token,
|
||||
'device_id': device_id,
|
||||
})
|
||||
assert rotated.status_code == 200
|
||||
rotated_payload = rotated.json()
|
||||
assert rotated_payload['access_token'] != first_access
|
||||
assert rotated_payload['refresh_token'] != refresh_token
|
||||
assert rotated_payload['device_id'] == device_id
|
||||
|
||||
replay = client.post('/api/auth/refresh', json={
|
||||
'refresh_token': refresh_token,
|
||||
'device_id': device_id,
|
||||
})
|
||||
assert replay.status_code == 401
|
||||
|
||||
wrong_device = client.post('/api/auth/refresh', json={
|
||||
'refresh_token': rotated_payload['refresh_token'],
|
||||
'device_id': 'device-other',
|
||||
})
|
||||
assert wrong_device.status_code == 401
|
||||
|
||||
|
||||
def test_password_hashes_are_salted_and_legacy_hashes_upgrade_on_login():
|
||||
from hashlib import sha256
|
||||
from backend.app.database import hash_password
|
||||
|
||||
@@ -9,9 +9,6 @@
|
||||
"storage",
|
||||
"tabs"
|
||||
],
|
||||
"host_permissions": [
|
||||
"<all_urls>"
|
||||
],
|
||||
"action": {
|
||||
"default_title": "__MSG_extensionName__",
|
||||
"default_popup": "popup.html",
|
||||
|
||||
+131
-9
@@ -13,6 +13,35 @@ const signOutButton = document.getElementById('sign-out');
|
||||
|
||||
const t = window.linklogI18n;
|
||||
|
||||
function normalizeBackendOrigin(backendUrl) {
|
||||
try {
|
||||
const url = new URL(backendUrl);
|
||||
if (!['http:', 'https:'].includes(url.protocol)) {
|
||||
return null;
|
||||
}
|
||||
return url.origin;
|
||||
} catch (error) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
async function ensureExactBackendPermission(backendUrl) {
|
||||
const origin = normalizeBackendOrigin(backendUrl);
|
||||
if (!origin) {
|
||||
return false;
|
||||
}
|
||||
|
||||
try {
|
||||
const hasPermission = await browser.permissions.contains({ origins: [`${origin}/*`] });
|
||||
if (hasPermission) {
|
||||
return true;
|
||||
}
|
||||
return await browser.permissions.request({ origins: [`${origin}/*`] });
|
||||
} catch (error) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
function setStatus(message, isError = false) {
|
||||
statusEl.textContent = message;
|
||||
statusEl.classList.remove('hidden');
|
||||
@@ -20,8 +49,76 @@ function setStatus(message, isError = false) {
|
||||
statusEl.classList.toggle('success', !isError);
|
||||
}
|
||||
|
||||
async function getStoredSession() {
|
||||
const [localSettings, sessionSettings] = await Promise.all([
|
||||
browser.storage.local.get(['backendUrl', 'email', 'username']),
|
||||
browser.storage.session.get(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
|
||||
return {
|
||||
backendUrl: localSettings.backendUrl || '',
|
||||
email: localSettings.email || '',
|
||||
username: localSettings.username || '',
|
||||
deviceId: sessionSettings.deviceId || '',
|
||||
accessToken: sessionSettings.accessToken || '',
|
||||
refreshToken: sessionSettings.refreshToken || '',
|
||||
tokenExpiresAt: sessionSettings.tokenExpiresAt || '',
|
||||
};
|
||||
}
|
||||
|
||||
async function persistSession(session) {
|
||||
await browser.storage.local.set({
|
||||
backendUrl: session.backendUrl || '',
|
||||
email: session.email || '',
|
||||
username: session.username || '',
|
||||
});
|
||||
|
||||
await browser.storage.session.set({
|
||||
accessToken: session.accessToken || '',
|
||||
refreshToken: session.refreshToken || '',
|
||||
tokenExpiresAt: session.tokenExpiresAt || '',
|
||||
deviceId: session.deviceId || '',
|
||||
});
|
||||
}
|
||||
|
||||
async function refreshAccessToken() {
|
||||
const session = await getStoredSession();
|
||||
if (!session.backendUrl || !session.refreshToken || !session.deviceId) {
|
||||
return null;
|
||||
}
|
||||
|
||||
try {
|
||||
const response = await fetch(`${session.backendUrl}/api/auth/refresh`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({
|
||||
refresh_token: session.refreshToken,
|
||||
device_id: session.deviceId,
|
||||
}),
|
||||
});
|
||||
|
||||
if (!response.ok) {
|
||||
await clearSession();
|
||||
return null;
|
||||
}
|
||||
|
||||
const data = await response.json();
|
||||
const refreshedSession = {
|
||||
...session,
|
||||
accessToken: data.access_token,
|
||||
refreshToken: data.refresh_token,
|
||||
tokenExpiresAt: data.expires_at,
|
||||
deviceId: data.device_id || session.deviceId,
|
||||
};
|
||||
await persistSession(refreshedSession);
|
||||
return refreshedSession;
|
||||
} catch (error) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
async function loadSettings() {
|
||||
const settings = await browser.storage.local.get(['backendUrl', 'email', 'username', 'accessToken']);
|
||||
const settings = await getStoredSession();
|
||||
backendUrlInput.value = settings.backendUrl || '';
|
||||
emailInput.value = settings.email || '';
|
||||
|
||||
@@ -36,6 +133,20 @@ async function loadSettings() {
|
||||
showLoggedIn(user.username || settings.email, settings.backendUrl);
|
||||
return;
|
||||
}
|
||||
if (response.status === 401) {
|
||||
const refreshed = await refreshAccessToken();
|
||||
if (refreshed) {
|
||||
const userResponse = await fetch(
|
||||
`${refreshed.backendUrl}/api/auth/me`,
|
||||
{headers: {Authorization: `Bearer ${refreshed.accessToken}`}},
|
||||
);
|
||||
if (userResponse.ok) {
|
||||
const user = await userResponse.json();
|
||||
showLoggedIn(user.username || refreshed.email, refreshed.backendUrl);
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
} catch (error) {
|
||||
// Show the login form when the backend cannot validate the stored token.
|
||||
}
|
||||
@@ -56,7 +167,10 @@ function showLoggedOut() {
|
||||
}
|
||||
|
||||
async function clearSession() {
|
||||
await browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken']);
|
||||
await Promise.all([
|
||||
browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken', 'deviceId']),
|
||||
browser.storage.session.remove(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
}
|
||||
|
||||
async function saveSettingsAndLogin(event) {
|
||||
@@ -65,17 +179,25 @@ async function saveSettingsAndLogin(event) {
|
||||
const email = emailInput.value.trim();
|
||||
const password = passwordInput.value;
|
||||
const otp = otpInput.value.trim();
|
||||
const existingSession = await getStoredSession();
|
||||
const deviceId = existingSession.deviceId || crypto.randomUUID();
|
||||
|
||||
if (!backendUrl || !email || !password) {
|
||||
setStatus(t('fillAllFields'), true);
|
||||
return;
|
||||
}
|
||||
|
||||
const origin = normalizeBackendOrigin(backendUrl);
|
||||
if (!origin || !(await ensureExactBackendPermission(backendUrl))) {
|
||||
setStatus(t('unableToLogIn'), true);
|
||||
return;
|
||||
}
|
||||
|
||||
try {
|
||||
const response = await fetch(`${backendUrl}/api/auth/login`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ email, password, otp: otp || null })
|
||||
body: JSON.stringify({ email, password, otp: otp || null, device_id: deviceId })
|
||||
});
|
||||
|
||||
if (!response.ok) {
|
||||
@@ -83,14 +205,14 @@ async function saveSettingsAndLogin(event) {
|
||||
}
|
||||
|
||||
const data = await response.json();
|
||||
await browser.storage.local.set({
|
||||
await persistSession({
|
||||
backendUrl,
|
||||
email,
|
||||
username: data.user?.username || email,
|
||||
accessToken: data.access_token,
|
||||
tokenType: data.token_type,
|
||||
tokenExpiresAt: data.expires_at,
|
||||
refreshToken: data.refresh_token,
|
||||
tokenExpiresAt: data.expires_at,
|
||||
deviceId: data.device_id || crypto.randomUUID(),
|
||||
});
|
||||
|
||||
showLoggedIn(data.user?.username || email, backendUrl);
|
||||
@@ -103,9 +225,9 @@ async function saveSettingsAndLogin(event) {
|
||||
}
|
||||
|
||||
async function signOut() {
|
||||
const settings = await browser.storage.local.get(['accessToken']);
|
||||
if (settings.accessToken) {
|
||||
await fetch(`${backendUrlInput.value.trim()}/api/auth/logout`, {
|
||||
const settings = await getStoredSession();
|
||||
if (settings.accessToken && settings.backendUrl) {
|
||||
await fetch(`${settings.backendUrl}/api/auth/logout`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ token: settings.accessToken }),
|
||||
|
||||
+122
-9
@@ -16,6 +16,35 @@ const authSession = document.getElementById('auth-session');
|
||||
|
||||
const t = window.linklogI18n;
|
||||
|
||||
function normalizeBackendOrigin(backendUrl) {
|
||||
try {
|
||||
const url = new URL(backendUrl);
|
||||
if (!['http:', 'https:'].includes(url.protocol)) {
|
||||
return null;
|
||||
}
|
||||
return url.origin;
|
||||
} catch (error) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
async function ensureExactBackendPermission(backendUrl) {
|
||||
const origin = normalizeBackendOrigin(backendUrl);
|
||||
if (!origin) {
|
||||
return false;
|
||||
}
|
||||
|
||||
try {
|
||||
const hasPermission = await browser.permissions.contains({ origins: [`${origin}/*`] });
|
||||
if (hasPermission) {
|
||||
return true;
|
||||
}
|
||||
return await browser.permissions.request({ origins: [`${origin}/*`] });
|
||||
} catch (error) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
function setStatus(message, isError = false) {
|
||||
statusEl.textContent = message;
|
||||
statusEl.classList.remove('hidden');
|
||||
@@ -24,22 +53,99 @@ function setStatus(message, isError = false) {
|
||||
}
|
||||
|
||||
async function getSettings() {
|
||||
const result = await browser.storage.local.get([
|
||||
'backendUrl',
|
||||
'accessToken',
|
||||
'tokenExpiresAt',
|
||||
const [localSettings, sessionSettings] = await Promise.all([
|
||||
browser.storage.local.get(['backendUrl']),
|
||||
browser.storage.session.get(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
return result;
|
||||
|
||||
return {
|
||||
backendUrl: localSettings.backendUrl || '',
|
||||
deviceId: sessionSettings.deviceId || '',
|
||||
accessToken: sessionSettings.accessToken || '',
|
||||
refreshToken: sessionSettings.refreshToken || '',
|
||||
tokenExpiresAt: sessionSettings.tokenExpiresAt || '',
|
||||
};
|
||||
}
|
||||
|
||||
async function persistSession(session) {
|
||||
await browser.storage.local.set({
|
||||
backendUrl: session.backendUrl || '',
|
||||
});
|
||||
|
||||
await browser.storage.session.set({
|
||||
accessToken: session.accessToken || '',
|
||||
refreshToken: session.refreshToken || '',
|
||||
tokenExpiresAt: session.tokenExpiresAt || '',
|
||||
deviceId: session.deviceId || '',
|
||||
});
|
||||
}
|
||||
|
||||
async function clearSession() {
|
||||
await Promise.all([
|
||||
browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken', 'deviceId']),
|
||||
browser.storage.session.remove(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
}
|
||||
|
||||
async function refreshAccessToken() {
|
||||
const settings = await getSettings();
|
||||
if (!settings.backendUrl || !settings.refreshToken || !settings.deviceId) {
|
||||
return null;
|
||||
}
|
||||
|
||||
try {
|
||||
const response = await fetch(`${settings.backendUrl}/api/auth/refresh`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({
|
||||
refresh_token: settings.refreshToken,
|
||||
device_id: settings.deviceId,
|
||||
}),
|
||||
});
|
||||
|
||||
if (!response.ok) {
|
||||
await clearSession();
|
||||
return null;
|
||||
}
|
||||
|
||||
const data = await response.json();
|
||||
const refreshed = {
|
||||
...settings,
|
||||
accessToken: data.access_token,
|
||||
refreshToken: data.refresh_token,
|
||||
tokenExpiresAt: data.expires_at,
|
||||
deviceId: data.device_id || settings.deviceId,
|
||||
};
|
||||
await persistSession(refreshed);
|
||||
return refreshed;
|
||||
} catch (error) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
async function validateSession(settings) {
|
||||
if (!settings.backendUrl || !settings.accessToken) return null;
|
||||
if (!(await ensureExactBackendPermission(settings.backendUrl))) {
|
||||
await clearSession();
|
||||
return null;
|
||||
}
|
||||
try {
|
||||
const response = await fetch(`${settings.backendUrl}/api/auth/me`, {
|
||||
headers: {'Authorization': `Bearer ${settings.accessToken}`},
|
||||
});
|
||||
if (!response.ok) {
|
||||
await browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken']);
|
||||
if (response.status === 401) {
|
||||
const refreshed = await refreshAccessToken();
|
||||
if (refreshed && refreshed.accessToken) {
|
||||
const retry = await fetch(`${refreshed.backendUrl}/api/auth/me`, {
|
||||
headers: {'Authorization': `Bearer ${refreshed.accessToken}`},
|
||||
});
|
||||
if (retry.ok) {
|
||||
return await retry.json();
|
||||
}
|
||||
}
|
||||
}
|
||||
await clearSession();
|
||||
return null;
|
||||
}
|
||||
return await response.json();
|
||||
@@ -79,11 +185,12 @@ function showSavedState(message) {
|
||||
}
|
||||
|
||||
async function updateFeedLink() {
|
||||
const settings = await browser.storage.local.get(['backendUrl', 'username', 'accessToken']);
|
||||
if (!settings.backendUrl || !settings.username || !settings.accessToken) return;
|
||||
const settings = await getSettings();
|
||||
if (!settings.backendUrl || !settings.accessToken) return;
|
||||
const username = await browser.storage.local.get(['username']);
|
||||
try {
|
||||
const backend = new URL(settings.backendUrl);
|
||||
feedLink.href = `${backend.origin}/${encodeURIComponent(settings.username)}/`;
|
||||
feedLink.href = `${backend.origin}/${encodeURIComponent(username.username || settings.deviceId || 'user')}/`;
|
||||
feedLink.classList.remove('hidden');
|
||||
} catch (error) {
|
||||
feedLink.classList.add('hidden');
|
||||
@@ -181,6 +288,12 @@ async function handleSubmit(event) {
|
||||
const token = settings.accessToken;
|
||||
const backendUrl = settings.backendUrl;
|
||||
|
||||
if (!backendUrl || !(await ensureExactBackendPermission(backendUrl))) {
|
||||
setStatus(t('configureAndLogIn'), true);
|
||||
browser.runtime.openOptionsPage();
|
||||
return;
|
||||
}
|
||||
|
||||
if (!token || !backendUrl) {
|
||||
setStatus(t('configureAndLogIn'), true);
|
||||
browser.runtime.openOptionsPage();
|
||||
|
||||
Reference in New Issue
Block a user