03ea72595d
* Initial Commit for OAuth API This builds and run and return the right error. Need to test it and then adding all users as possible client * Added mising dependency * just compile already... * Fixing template test * Imrpovements Moved db stuff in models Added some tests Added form in modpanel to add/update a client Added controllers for add/update of client * Added Forms + speed improvements Controller oauth client listing + html Controller oauth client delete + messages Messages on comment delete New ES config that disable ES if set to false. Improve load speed on local development Fix a load config bug Fix index admin & translation string sign_out broken by @ewhal * Sanitize empty strig in form array + css Multiple empty array of strings are sanitized for the oauth client create form Added some css for the form display * Upload and Create form works * Fix splitting response types * Removing required on secret when updating * fix travis error * Fix travis template test * Update dependency * Moved to jinzhu instead of azhao * randomizen secret on creation * Final touch on oath api improved display name fix grant form csrf fix login csrf on oauth * Fix gorm test * fix template test * Fixing deleted dependency issue * Make travis faster * Fix typo * Fix csrf for api calls * This shouldn't be exempt * Removing hard coded hash @ewhal Don't forget to replace the hash in tokens.go with another one * Added an example on how to use OAuth middleware * Renamed fosite utils to oauth2 utils
45 lignes
2 Kio
Go
45 lignes
2 Kio
Go
package controllers
|
|
|
|
import (
|
|
"net/http"
|
|
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/activities" // activities controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/api" // api controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/captcha" // captcha controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/databasedumps" // databasedumps controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/faq" // faq controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/feed" // feed controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/middlewares" // middlewares
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/moderator" // moderator controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/oauth" // oauth2 controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/pprof" // pprof controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/report" // report controller
|
|
"github.com/NyaaPantsu/nyaa/controllers/router"
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/search" // search controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/settings" // settings controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/static" // static files
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/torrent" // torrent controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/upload" // upload controller
|
|
_ "github.com/NyaaPantsu/nyaa/controllers/user" // user controller
|
|
"github.com/justinas/nosurf"
|
|
)
|
|
|
|
// CSRFRouter : CSRF protection for Router variable for exporting the route configuration
|
|
var CSRFRouter *nosurf.CSRFHandler
|
|
|
|
func init() {
|
|
CSRFRouter = nosurf.New(router.Get())
|
|
CSRFRouter.ExemptRegexp("/api(?:/.+)*")
|
|
CSRFRouter.ExemptRegexp("/mod(?:/.+)*")
|
|
CSRFRouter.ExemptPath("/upload")
|
|
CSRFRouter.ExemptPath("/user/login")
|
|
CSRFRouter.ExemptPath("/oauth2/token")
|
|
CSRFRouter.SetFailureHandler(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
http.Error(w, "Invalid CSRF tokens", http.StatusBadRequest)
|
|
}))
|
|
CSRFRouter.SetBaseCookie(http.Cookie{
|
|
Path: "/",
|
|
MaxAge: nosurf.MaxAge,
|
|
})
|
|
|
|
}
|