Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions src/routes/image.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@ import (
"anonymousoverflow/src/types"
"fmt"
"os"
"time"

"github.com/gin-gonic/gin"
"github.com/go-resty/resty/v2"
Expand Down Expand Up @@ -45,11 +44,6 @@ func GetImage(c *gin.Context) {
return
}

if claims.Exp < time.Now().Unix() {
c.String(400, "Token expired")
return
}

// download the image
client := resty.New()
resp, err := client.R().Get(claims.ImageURL)
Expand Down
3 changes: 0 additions & 3 deletions src/types/imageProxy.go
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,5 @@ type ImageProxyClaims struct {

ImageURL string `json:"image_url"`

Iss int64 `json:"iss"`
Exp int64 `json:"exp"`

jwt.RegisteredClaims
}
7 changes: 5 additions & 2 deletions src/utils/images.go
Original file line number Diff line number Diff line change
Expand Up @@ -42,11 +42,14 @@ func ReplaceImgTags(inHtml string) string {

func generateImageProxyAuth(url string) (string, error) {
// generate a jwt with types.ImageProxyClaims
now := time.Now()
claims := types.ImageProxyClaims{
Action: "imageProxy",
ImageURL: url,
Iss: time.Now().Unix(),
Exp: time.Now().Add(time.Minute).Unix(),
RegisteredClaims: jwt.RegisteredClaims{
IssuedAt: jwt.NewNumericDate(now),
ExpiresAt: jwt.NewNumericDate(now.Add(time.Minute)),
},
}

token := jwt.NewWithClaims(jwt.SigningMethodHS512, claims)
Expand Down
51 changes: 51 additions & 0 deletions src/utils/images_test.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
package utils

import (
"anonymousoverflow/src/types"
"errors"
"testing"
"time"

"github.com/golang-jwt/jwt/v4"
)

func TestImageProxyAuth(t *testing.T) {
const secret = "image-proxy-test-secret"
const imageURL = "https://example.com/image.png"
t.Setenv("JWT_SIGNING_SECRET", secret)

authorization, err := generateImageProxyAuth(imageURL)
if err != nil {
t.Fatal(err)
}

keyFunc := func(token *jwt.Token) (interface{}, error) {
return []byte(secret), nil
}
claims := &types.ImageProxyClaims{}
token, err := jwt.ParseWithClaims(authorization, claims, keyFunc)
if err != nil || !token.Valid {
t.Fatalf("fresh token rejected: %v", err)
}
if claims.Action != "imageProxy" || claims.ImageURL != imageURL {
t.Fatalf("unexpected claims: %+v", claims)
}
if claims.IssuedAt == nil || claims.ExpiresAt == nil {
t.Fatal("missing issue time or expiry")
}
if claims.ExpiresAt.Sub(claims.IssuedAt.Time) != time.Minute {
t.Fatal("token lifetime is not one minute")
}

originalTimeFunc := jwt.TimeFunc
t.Cleanup(func() { jwt.TimeFunc = originalTimeFunc })
jwt.TimeFunc = func() time.Time { return claims.ExpiresAt.Add(time.Second) }

token, err = jwt.ParseWithClaims(authorization, &types.ImageProxyClaims{}, keyFunc)
if !errors.Is(err, jwt.ErrTokenExpired) {
t.Fatalf("expected expiry error from ParseWithClaims, got %v", err)
}
if token != nil && token.Valid {
t.Fatal("expired token is valid")
}
}