From 8db0bbb874d99f7fc60efe04a84e239c2631ab64 Mon Sep 17 00:00:00 2001
From: Philippe Loctaux
Date: Sun, 19 Mar 2023 20:03:30 +0100
Subject: [PATCH] if access token expired, use refresh token, and get new
access + refresh tokens
---
.../queries/refresh_tokens/use_token.sql | 5 +
.../users/get_one_from_refresh_token.sql | 16 +
crates/database/sqlx-data.json | 88 ++++++
crates/database/src/tables/refresh_tokens.rs | 13 +
crates/database/src/tables/users.rs | 10 +
crates/ezidam/src/guards/jwt.rs | 298 +++++++++++++++++-
crates/ezidam/src/guards/jwt/admin.rs | 16 +-
crates/ezidam/src/guards/jwt/user.rs | 13 +-
crates/ezidam/src/guards/refresh_token.rs | 27 +-
crates/ezidam/src/routes/root.rs | 4 +-
crates/refresh_tokens/src/database.rs | 4 +
crates/users/src/database.rs | 9 +
12 files changed, 462 insertions(+), 41 deletions(-)
create mode 100644 crates/database/queries/refresh_tokens/use_token.sql
create mode 100644 crates/database/queries/users/get_one_from_refresh_token.sql
diff --git a/crates/database/queries/refresh_tokens/use_token.sql b/crates/database/queries/refresh_tokens/use_token.sql
new file mode 100644
index 0000000..fd70ac1
--- /dev/null
+++ b/crates/database/queries/refresh_tokens/use_token.sql
@@ -0,0 +1,5 @@
+update refresh_tokens
+
+set used_at = CURRENT_TIMESTAMP
+
+where token is ?
\ No newline at end of file
diff --git a/crates/database/queries/users/get_one_from_refresh_token.sql b/crates/database/queries/users/get_one_from_refresh_token.sql
new file mode 100644
index 0000000..1848be8
--- /dev/null
+++ b/crates/database/queries/users/get_one_from_refresh_token.sql
@@ -0,0 +1,16 @@
+select u.id,
+ u.created_at as "created_at: DateTime",
+ u.updated_at as "updated_at: DateTime",
+ u.is_admin as "is_admin: bool",
+ u.username,
+ u.name,
+ u.email,
+ u.password,
+ u.password_recover,
+ u.paper_key,
+ u.is_archived as "is_archived: bool"
+from users u
+
+ inner join refresh_tokens rt on u.id = rt.user
+
+where rt.token is ?
diff --git a/crates/database/sqlx-data.json b/crates/database/sqlx-data.json
index 1155a09..344e2e0 100644
--- a/crates/database/sqlx-data.json
+++ b/crates/database/sqlx-data.json
@@ -20,6 +20,94 @@
},
"query": "update settings\n\nset business_name = ?\n\nwhere id is 0\n"
},
+ "3c8e31ffa5cbfd4dded8a272777cb320fb51fd2e53ed25054d24e9801df0c358": {
+ "describe": {
+ "columns": [],
+ "nullable": [],
+ "parameters": {
+ "Right": 1
+ }
+ },
+ "query": "update refresh_tokens\n\nset used_at = CURRENT_TIMESTAMP\n\nwhere token is ?"
+ },
+ "4f83a1908a1980ce4bf65eadf24eed2af6c6225972ef7f9f4cf0c702264033a7": {
+ "describe": {
+ "columns": [
+ {
+ "name": "id",
+ "ordinal": 0,
+ "type_info": "Text"
+ },
+ {
+ "name": "created_at: DateTime",
+ "ordinal": 1,
+ "type_info": "Text"
+ },
+ {
+ "name": "updated_at: DateTime",
+ "ordinal": 2,
+ "type_info": "Text"
+ },
+ {
+ "name": "is_admin: bool",
+ "ordinal": 3,
+ "type_info": "Int64"
+ },
+ {
+ "name": "username",
+ "ordinal": 4,
+ "type_info": "Text"
+ },
+ {
+ "name": "name",
+ "ordinal": 5,
+ "type_info": "Text"
+ },
+ {
+ "name": "email",
+ "ordinal": 6,
+ "type_info": "Text"
+ },
+ {
+ "name": "password",
+ "ordinal": 7,
+ "type_info": "Text"
+ },
+ {
+ "name": "password_recover",
+ "ordinal": 8,
+ "type_info": "Text"
+ },
+ {
+ "name": "paper_key",
+ "ordinal": 9,
+ "type_info": "Text"
+ },
+ {
+ "name": "is_archived: bool",
+ "ordinal": 10,
+ "type_info": "Int64"
+ }
+ ],
+ "nullable": [
+ false,
+ false,
+ false,
+ false,
+ false,
+ true,
+ true,
+ true,
+ true,
+ true,
+ false
+ ],
+ "parameters": {
+ "Right": 1
+ }
+ },
+ "query": "select u.id,\n u.created_at as \"created_at: DateTime\",\n u.updated_at as \"updated_at: DateTime\",\n u.is_admin as \"is_admin: bool\",\n u.username,\n u.name,\n u.email,\n u.password,\n u.password_recover,\n u.paper_key,\n u.is_archived as \"is_archived: bool\"\nfrom users u\n\n inner join refresh_tokens rt on u.id = rt.user\n\nwhere rt.token is ?\n"
+ },
"520fe30e21f6b6c4d9a47c457675eebd144cf020e9230d154e9e4d0c8d6e01ca": {
"describe": {
"columns": [],
diff --git a/crates/database/src/tables/refresh_tokens.rs b/crates/database/src/tables/refresh_tokens.rs
index 8b76101..c17517e 100644
--- a/crates/database/src/tables/refresh_tokens.rs
+++ b/crates/database/src/tables/refresh_tokens.rs
@@ -71,4 +71,17 @@ impl RefreshTokens {
Ok((query.rows_affected() >= 1).then_some(()))
}
+
+ pub async fn use_token(
+ conn: impl SqliteExecutor<'_>,
+ token: &str,
+ ) -> Result