Add ApplyToContext and AuthenticateToUser helpers to the auth package, then remove the duplicated auth code spread across the MCP middleware, file server, Connect interceptor, and gRPC-Gateway middleware. - auth.ApplyToContext: single place to set claims/user into context after Authenticate() - auth.AuthenticateToUser: resolves any credential (bearer token or refresh cookie) to a *store.User - MCP middleware: replaced manual PAT DB lookup + expiry check with Authenticator.AuthenticateByPAT - File server: replaced authenticateByBearerToken/authenticateByRefreshToken with AuthenticateToUser - Connect interceptor + Gateway middleware: replaced duplicated context-setting block with ApplyToContext - MCPService now accepts secret to construct its own Authenticator
31 lines
974 B
Go
31 lines
974 B
Go
package mcp
|
|
|
|
import (
|
|
"net/http"
|
|
|
|
"github.com/labstack/echo/v5"
|
|
|
|
"github.com/usememos/memos/server/auth"
|
|
"github.com/usememos/memos/store"
|
|
)
|
|
|
|
func newAuthMiddleware(s *store.Store, secret string) echo.MiddlewareFunc {
|
|
authenticator := auth.NewAuthenticator(s, secret)
|
|
return func(next echo.HandlerFunc) echo.HandlerFunc {
|
|
return func(c *echo.Context) error {
|
|
token := auth.ExtractBearerToken(c.Request().Header.Get("Authorization"))
|
|
if token == "" {
|
|
return c.JSON(http.StatusUnauthorized, map[string]string{"message": "a personal access token is required"})
|
|
}
|
|
|
|
user, pat, err := authenticator.AuthenticateByPAT(c.Request().Context(), token)
|
|
if err != nil || user == nil {
|
|
return c.JSON(http.StatusUnauthorized, map[string]string{"message": "invalid or expired personal access token"})
|
|
}
|
|
|
|
ctx := auth.SetUserInContext(c.Request().Context(), user, pat.GetTokenId())
|
|
c.SetRequest(c.Request().WithContext(ctx))
|
|
return next(c)
|
|
}
|
|
}
|
|
}
|