This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4,
available at

[homepage]:
diff --git a/orizentic/CONTRIBUTORS b/orizentic/CONTRIBUTORS
new file mode 100644
index 0000000..b3610d3
--- /dev/null
+++ b/orizentic/CONTRIBUTORS
@@ -0,0 +1,4 @@
* [Savanni D'Gerinel](
* [Daria Phoebe Brasea](
* [Aria Stewart]( 0000000..c76b14c --- /dev/null +++ b/orizentic/Cargo.toml @@ -0,0 +1,39 @@ +[package] +name = "orizentic" +version = "1.0.1" +authors = ["Savanni D'Gerinel "] +description = "A library for inerfacing with a JWT auth token database and a command line tool for managing it." +license = "GPL3" +documentation = "" +homepage = "" +repository = "" +categories = ["authentication", "command-line-utilities"] + +include = [ + "**/*.rs", + "Cargo.toml", + "", +] + +[build-dependencies] +version_check = "0.1.5" + +[dependencies] +chrono = { version = "0.4", features = ["serde"] } +clap = "2.33" +itertools = "0.10" +jsonwebtoken = "5" +serde = "1" +serde_derive = "1" +serde_json = "1" +thiserror = "1" +uuid = { version = "0.8", features = ["v4", "serde"] } +yaml-rust = "0.4" + +[lib] +name = "orizentic" +path = "src/" + +[[bin]] +name = "orizentic" +path = "src/" diff --git a/orizentic/LICENSE b/orizentic/LICENSE new file mode 100644 index 0000000..1704a41 --- /dev/null +++ b/orizentic/LICENSE @@ -0,0 +1,30 @@ +Copyright Savanni D'Gerinel (c) 2017 - 2019 + +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: + + * Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + + * Redistributions in binary form must reproduce the above + copyright notice, this list of conditions and the following + disclaimer in the documentation and/or other materials provided + with the distribution. + + * Neither the name of Savanni D'Gerinel nor the names of other + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. diff --git a/orizentic/ b/orizentic/ new file mode 100644 index 0000000..816c4f7 --- /dev/null +++ b/orizentic/ @@ -0,0 +1,73 @@ +# Orizentic + +[![CircleCI](]( + +[Documentation](") + +Orizentic provides a library that streamlines token-based authentication, and a CLI tool for maintaining a database of tokens. + +## Credit + +The name is a contraction of Auth(oriz)ation/Auth(entic)ation, and credit goes to [Daria Phoebe Brashear]( + +The original idea has been debated online for many years, but the push to make this useful comes from [Aria Stewart]( + +## Tokens + +Tokens are simple [JWTs]( This library simplifies the process by easily generating and checking JWTs that have only an issuer, an optional time-to-live, a resource name, a username, and a list of permissions. A typical resulting JWT would look like this: + + { iss = Savanni + , sub = health + , aud = "Savanni Desktop" + , exp = null + , nbf = null + , iat = 1499650083 + , jti = 9d57a8d8-d11e-43b2-a4d6-7b82ad043994 + , unregisteredClaims = { perms: [ "read", "write" ] } + } + +The `issuer` and `audience` (or username) are almost entirely for human readability. In this instance, I issued a token that was intended to be used on my desktop system. + +The `subject` in this case is synonymous with Resource and is a name for the resource for which access is being granted. Permissions are a simple list of freeform strings. Both of these are flexible within your application and your authorization checks will use them to verify that the token can be used for the specified purpose. + +## CLI Usage + +## Library Usage + +[orizentic - Rust]( + +There are multiple errata for the documentation: + +* There are, in fact, now [two functions]( for saving and loading a database. +* An example for how to use the library is currently here [for loading the database]( and here [as part of the AuthMiddleware for an Iron server]( I apologize for not writing this in more detail yet. + +## Language support + +This library and application is only supported for Rust. Haskell and Go support has been discontinued, but can be revived if I discover folks have an interest. The token database is compatible across tools. See readmes in the language directory for usage information. + +Future Haskell, Go, and other language versions of the library will be done through language bindings against the Rust utilities instead of through my previous clean-room re-implementations. + +## Nix installation + +If you have Nix installed on your system, or you run NixOS, create this derivation: + +orizentic.nix: + +``` +{ fetchFromGitHub }: +let src = fetchFromGitHub { + owner = "luminescent-dreams"; + repo = "orizentic"; + rev = "896140f594fe3c106662ffe2550f289bb68bc0cb"; + sha256 = "05g7b0jiyy0pv74zf89yikf65vi3jrn1da0maj0k9fxnxb2vv7a4"; + }; +in import "${src}/default.nix" {} +``` + +At this time, you must have nixpkgs-19.03 defined (and preferably pointing to the 19.03 channel). I will parameterize this and update the instructions in the future. + +I import this into my shell.nix `with import ./orizentic.nix { inherit (pkgs) fetchFromGitHub; };`. + +For a complete example, see my [shell.nix]( file. + +I have not bundled this application for any other distribution, but you should nave no trouble just building with just cargo build --release with Rust-1.33 and Cargo. diff --git a/orizentic/shell.nix b/orizentic/shell.nix new file mode 100644 index 0000000..7d40cd1 --- /dev/null +++ b/orizentic/shell.nix @@ -0,0 +1,20 @@ +let + rust_overlay = import (builtins.fetchTarball ""); + pkgs = import { overlays = [ rust_overlay ]; }; + unstable = import {}; + rust = pkgs.rust-bin.stable."1.59.0".default.override { + extensions = [ "rust-src" ]; + }; + +in pkgs.mkShell { + name = "datasphere"; + + nativeBuildInputs = [ + rust + unstable.rust-analyzer + ]; + + shellHook = '' + if [ -e ~/.nixpkgs/ ]; then . ~/.nixpkgs/; fi + ''; +} diff --git a/orizentic/src/ b/orizentic/src/ new file mode 100644 index 0000000..f465b09 --- /dev/null +++ b/orizentic/src/ @@ -0,0 +1,251 @@ +extern crate chrono; +extern crate clap; +extern crate orizentic; + +use chrono::Duration; +use clap::{App, Arg, ArgMatches, SubCommand}; +use std::env; + +use orizentic::*; + +#[derive(Debug)] +enum OrizenticErr { + ParseError(std::num::ParseIntError), +} + +// ORIZENTIC_DB +// ORIZENTIC_SECRET +// +// list +// create +// revoke +// encode +pub fn main() { + let db_path = env::var_os("ORIZENTIC_DB").map(|str| { + str.into_string() + .expect("ORIZENTIC_DB contains invalid Unicode sequences") + }); + let secret = env::var_os("ORIZENTIC_SECRET").map(|str| { + Secret( + str.into_string() + .map(|s| s.into_bytes()) + .expect("ORIZENTIC_SECRET contains invalid Unicode sequences"), + ) + }); + + let matches = App::new("orizentic cli") + .subcommand(SubCommand::with_name("list")) + .subcommand( + SubCommand::with_name("create") + .arg( + Arg::with_name("issuer") + .long("issuer") + .takes_value(true) + .required(true), + ) + .arg( + Arg::with_name("ttl") + .long("ttl") + .takes_value(true) + .required(true), + ) + .arg( + Arg::with_name("resource") + .long("resource") + .takes_value(true) + .required(true), + ) + .arg( + Arg::with_name("username") + .long("username") + .takes_value(true) + .required(true), + ) + .arg( + Arg::with_name("perms") + .long("perms") + .takes_value(true) + .required(true), + ), + ) + .subcommand( + SubCommand::with_name("revoke").arg( + Arg::with_name("id") + .long("id") + .takes_value(true) + .required(true), + ), + ) + .subcommand( + SubCommand::with_name("encode").arg( + Arg::with_name("id") + .long("id") + .takes_value(true) + .required(true), + ), + ) + .get_matches(); + + match matches.subcommand() { + ("list", _) => list_tokens(db_path), + ("create", Some(args)) => create_token(db_path, secret, args), + ("revoke", Some(args)) => revoke_token(db_path, args), + ("encode", Some(args)) => encode_token(db_path, secret, args), + (cmd, _) => { + println!("unknown subcommand: {}", cmd); + } + } +} + +fn list_tokens(db_path: Option) { + let db_path_ = db_path.expect("ORIZENTIC_DB is required for this operation"); + let claimsets = orizentic::filedb::load_claims_from_file(&db_path_); + match claimsets { + Ok(claimsets_) => { + for claimset in claimsets_ { + println!("[{}]",; + println!("Audience: {}", String::from(claimset.audience)); + match claimset.expiration { + Some(expiration) => println!( + "Expiration: {}", + expiration.format("%Y-%m-%d %H:%M:%S") + ), + None => println!("Expiration: None"), + } + println!("Issuer: {}", claimset.issuer.0); + println!( + "Issued At: {}", + claimset.issued_at.format("%Y-%m-%d %H:%M:%S") + ); + println!("Resource Name: {}", claimset.resource.0); + + let perm_val: String = itertools::Itertools::intersperse( + claimset.permissions.0.clone().into_iter(), + String::from(", "), + ) + .collect(); + println!("Permissions: {}", perm_val); + println!("") + } + } + Err(err) => { + println!("claimset failed to load: {}", err); + std::process::exit(1); + } + } +} + +fn create_token(db_path: Option, secret: Option, args: &ArgMatches) { + let db_path_ = db_path.expect("ORIZENTIC_DB is required for this operation"); + let secret_ = secret.expect("ORIZENTIC_SECRET is required for this operation"); + let issuer = args + .value_of("issuer") + .map(|x| Issuer(String::from(x))) + .expect("--issuer is a required parameter"); + let ttl: Option = args.value_of("ttl").map(|x| { + x.parse() + .and_then(|d| Ok(TTL(Duration::seconds(d)))) + .map_err(|err| OrizenticErr::ParseError(err)) + .expect("Failed to parse TTL") + }); + let resource_name = args + .value_of("resource") + .map(|x| ResourceName(String::from(x))) + .expect("--resource is a required parameter"); + let username = args + .value_of("username") + .map(|x| Username::from(x)) + .expect("--username is a required parameter"); + let perms: Permissions = args + .value_of("perms") + .map(|str| Permissions(str.split(',').map(|s| String::from(s)).collect())) + .expect("--permissions is a required parameter"); + + let claimsets = orizentic::filedb::load_claims_from_file(&db_path_); + match claimsets { + Err(err) => { + println!("claimset failed to load: {}", err); + std::process::exit(1); + } + Ok(claimsets_) => { + let new_claimset = ClaimSet::new(issuer, ttl, resource_name, username, perms); + let mut ctx = orizentic::OrizenticCtx::new(secret_, claimsets_); + ctx.add_claimset(new_claimset.clone()); + match orizentic::filedb::save_claims_to_file(&ctx.list_claimsets(), &db_path_) { + Err(err) => { + println!("Failed to write claimset to file: {:?}", err); + std::process::exit(1); + } + Ok(_) => match ctx.encode_claimset(&new_claimset) { + Ok(token) => println!("{}", token.text), + Err(err) => { + println!("token could not be encoded: {:?}", err); + std::process::exit(1); + } + }, + } + } + } +} + +fn revoke_token(db_path: Option, args: &ArgMatches) { + let db_path_ = db_path.expect("ORIZENTIC_DB is required for this operation"); + let claimsets = orizentic::filedb::load_claims_from_file(&db_path_); + + match claimsets { + Err(err) => { + println!("claimset failed to load: {}", err); + std::process::exit(1); + } + Ok(claimsets_) => { + let id = args + .value_of("id") + .map(String::from) + .expect("--id is a required parameter"); + let mut ctx = + orizentic::OrizenticCtx::new(Secret(String::from("").into_bytes()), claimsets_); + ctx.revoke_by_uuid(&id); + match orizentic::filedb::save_claims_to_file(&ctx.list_claimsets(), &db_path_) { + Err(err) => { + println!("Failed to write claimset to file: {:?}", err); + std::process::exit(1); + } + Ok(_) => {} + } + } + } +} + +fn encode_token(db_path: Option, secret: Option, args: &ArgMatches) { + let db_path_ = db_path.expect("ORIZENTIC_DB is required for this operation"); + let secret_ = secret.expect("ORIZENTIC_SECRET is required for this operation"); + let id = args + .value_of("id") + .map(String::from) + .expect("--id is a required parameter"); + + let claimsets = orizentic::filedb::load_claims_from_file(&db_path_); + match claimsets { + Err(err) => { + println!("claimset failed to load: {}", err); + std::process::exit(1); + } + Ok(claimsets_) => { + let ctx = orizentic::OrizenticCtx::new(secret_, claimsets_); + let claimset = ctx.find_claimset(&id); + match claimset { + Some(claimset_) => match ctx.encode_claimset(&claimset_) { + Ok(token) => println!("{}", token.text), + Err(err) => { + println!("token could not be encoded: {:?}", err); + std::process::exit(1); + } + }, + None => { + println!("No claimset found"); + std::process::exit(1); + } + } + } + } +} diff --git a/orizentic/src/ b/orizentic/src/ new file mode 100644 index 0000000..596458c --- /dev/null +++ b/orizentic/src/ @@ -0,0 +1,303 @@ +extern crate chrono; +extern crate jsonwebtoken as jwt; +extern crate serde; +extern crate serde_json; +extern crate uuid; +extern crate yaml_rust; + +use core::chrono::prelude::*; +use core::uuid::Uuid; +use std::collections::HashMap; +use thiserror::Error; + +/// Orizentic Errors +#[derive(Debug, Error)] +pub enum Error { + /// An underlying JWT decoding error. May be replaced with Orizentic semantic errors to better + /// encapsulate the JWT library. + #[error("JWT failed to decode: {0}")] + JWTError(jwt::errors::Error), + /// Token decoded and verified but was not present in the database. + #[error("Token not recognized")] + UnknownToken, +} + +/// ResourceName is application-defined and names a resource to which access should be controlled +#[derive(Debug, PartialEq, Clone)] +pub struct ResourceName(pub String); + +/// Permissions are application-defined descriptions of what can be done with the named resource +#[derive(Debug, PartialEq, Clone)] +pub struct Permissions(pub Vec); + +/// Issuers are typically informative, but should generally describe who or what created the token +#[derive(Debug, PartialEq, Clone)] +pub struct Issuer(pub String); + +/// Time to live is the number of seconds until a token expires. This is used for creating tokens +/// but tokens store their actual expiration time. +#[derive(Debug, PartialEq, Clone)] +pub struct TTL(pub chrono::Duration); + +/// Username, or Audience in JWT terms, should describe who or what is supposed to be using this +/// token +#[derive(Debug, PartialEq, Clone)] +pub struct Username(String); + +impl From for String { + fn from(u: Username) -> String { + u.0.clone() + } +} + +impl From<&str> for Username { + fn from(s: &str) -> Username { + Username(s.to_owned()) + } +} + +#[derive(Debug, PartialEq, Clone)] +pub struct Secret(pub Vec); + +/// A ClaimSet represents one set of permissions and claims. It is a standardized way of specifying +/// the owner, issuer, expiration time, relevant resources, and specific permissions on that +/// resource. By itself, this is only an informative data structure and so should never be trusted +/// when passed over the wire. See `VerifiedToken` and `UnverifiedToken`. +#[derive(Debug, PartialEq, Clone)] +pub struct ClaimSet { + pub id: String, + pub audience: Username, + pub expiration: Option>, + pub issuer: Issuer, + pub issued_at: DateTime, + pub resource: ResourceName, + pub permissions: Permissions, +} + +impl ClaimSet { + /// Create a new `ClaimSet`. This will return a claimset with the expiration time calculated + /// from the TTL if the TTL is provided. No expiration will be set if no TTL is provided. + pub fn new( + issuer: Issuer, + ttl: Option, + resource_name: ResourceName, + user_name: Username, + perms: Permissions, + ) -> ClaimSet { + let issued_at: DateTime = Utc::now().with_nanosecond(0).unwrap(); + let expiration = match ttl { + Some(TTL(ttl_)) => issued_at.checked_add_signed(ttl_), + None => None, + }; + ClaimSet { + id: String::from(Uuid::new_v4().to_hyphenated().to_string()), + audience: user_name, + expiration, + issuer, + issued_at, + resource: resource_name, + permissions: perms, + } + } + + pub fn to_json(&self) -> Result { + serde_json::to_string(&(ClaimSetJS::from_claimset(self))) + } + + pub fn from_json(text: &String) -> Result { + serde_json::from_str(&text).map(|x| ClaimSetJS::to_claimset(&x)) + } +} + +/// ClaimSetJS is an intermediary data structure between JWT serialization and a more usable +/// ClaimSet. +#[derive(Debug, PartialEq, Clone, Serialize, Deserialize)] +pub struct ClaimSetJS { + jti: String, + aud: String, + exp: Option, + iss: String, + iat: i64, + sub: String, + perms: Vec, +} + +impl ClaimSetJS { + pub fn from_claimset(claims: &ClaimSet) -> ClaimSetJS { + ClaimSetJS { + jti:, + aud: claims.audience.0.clone(), + exp:|t| t.timestamp()), + iss: claims.issuer.0.clone(), + iat: claims.issued_at.timestamp(), + sub: claims.resource.0.clone(), + perms: claims.permissions.0.clone(), + } + } + + pub fn to_claimset(&self) -> ClaimSet { + ClaimSet { + id: self.jti.clone(), + audience: Username(self.aud.clone()), + expiration:|t| Utc.timestamp(t, 0)), + issuer: Issuer(self.iss.clone()), + issued_at: Utc.timestamp(self.iat, 0), + resource: ResourceName(self.sub.clone()), + permissions: Permissions(self.perms.clone()), + } + } +} + +/// The Orizentic Context encapsulates a set of claims and an associated secret. This provides the +/// overall convenience of easily creating and validating tokens. Generated claimsets are stored +/// here on the theory that, even with validation, only those claims actually stored in the +/// database should be considered valid. +pub struct OrizenticCtx(Secret, HashMap); + +/// An UnverifiedToken is a combination of the JWT serialization and the decoded `ClaimSet`. As this +/// is unverified, this should only be used for information purposes, such as determining what a +/// user can do with a token even when the decoding key is absent. +#[derive(Debug)] +pub struct UnverifiedToken { + pub text: String, + pub claims: ClaimSet, +} + +impl UnverifiedToken { + /// Decode a JWT text string without verification + pub fn decode_text(text: String) -> Result { + let res = jwt::dangerous_unsafe_decode::(&text); + match res { + Ok(res_) => Ok(UnverifiedToken { + text, + claims:, + }), + Err(err) => Err(Error::JWTError(err)), + } + } +} + +/// An VerifiedToken is a combination of the JWT serialization and the decoded `ClaimSet`. This will +/// only be created by the `validate_function`, and thus will represent a token which has been +/// validated via signature, expiration time, and presence in the database. +#[derive(Debug)] +pub struct VerifiedToken { + pub text: String, + pub claims: ClaimSet, +} + +impl VerifiedToken { + /// Given a `VerifiedToken`, pass the resource name and permissions to a user-defined function. The + /// function should return true if the caller should be granted access to the resource and false, + /// otherwise. That result will be passed back to the caller. + pub fn check_authorizations bool>( + &self, + f: F, + ) -> bool { + f(&, & + } +} + +impl OrizenticCtx { + /// Create a new Orizentic Context with an initial set of claims. + pub fn new(secret: Secret, claims_lst: Vec) -> OrizenticCtx { + let mut hm = HashMap::new(); + for claimset in claims_lst { + hm.insert(, claimset); + } + OrizenticCtx(secret, hm) + } + + /// Validate a token by checking its signature, that it is not expired, and that it is still + /// present in the database. Return an error if any check fails, but return a `VerifiedToken` + /// if it all succeeds. + pub fn validate_token(&self, token: &UnverifiedToken) -> Result { + let validator = match { + Some(_) => jwt::Validation::default(), + None => jwt::Validation { + validate_exp: false, + ..jwt::Validation::default() + }, + }; + let res = jwt::decode::(&token.text, &(self.0).0, &validator); + match res { + Ok(res_) => { + let claims =; + let in_db = self.1.get(&claims.jti); + if in_db.is_some() { + Ok(VerifiedToken { + text: token.text.clone(), + claims: claims.to_claimset(), + }) + } else { + Err(Error::UnknownToken) + } + } + Err(err) => Err(Error::JWTError(err)), + } + } + + /// Given a text string, as from a web application's `Authorization` header, decode the string + /// and then validate the token. + pub fn decode_and_validate_text(&self, text: String) -> Result { + // it is necessary to first decode the token because we need the validator to know whether + // to attempt to validate the expiration. Without that check, the validator will fail any + // expiration set to None. + match UnverifiedToken::decode_text(text) { + Ok(unverified) => self.validate_token(&unverified), + Err(err) => Err(err), + } + } + + /// Add a claimset to the database. + pub fn add_claimset(&mut self, claimset: ClaimSet) { + self.1.insert(, claimset); + } + + /// Remove a claims set from the database so that all additional validation checks fail. + pub fn revoke_claimset(&mut self, claim: &ClaimSet) { + self.1.remove(&; + } + + /// Revoke a ClaimsSet given its ID, which is set in the `jti` claim of a JWT or the `id` field + /// of a `ClaimSet`. + pub fn revoke_by_uuid(&mut self, claim_id: &String) { + self.1.remove(claim_id); + } + + /// *NOT IMPLEMENTED* + pub fn replace_claimsets(&mut self, _claims_lst: Vec) { + unimplemented!() + } + + /// List all of the `ClaimSet` IDs in the database. + pub fn list_claimsets(&self) -> Vec<&ClaimSet> { + self.1.values().map(|item| item).collect() + } + + /// Find a `ClaimSet` by ID. + pub fn find_claimset(&self, claims_id: &String) -> Option<&ClaimSet> { + self.1.get(claims_id) + } + + /// Encode and sign a claimset, returning the result as a `VerifiedToken`. + pub fn encode_claimset(&self, claims: &ClaimSet) -> Result { + let in_db = self.1.get(&; + if in_db.is_some() { + let text = jwt::encode( + &jwt::Header::default(), + &ClaimSetJS::from_claimset(&claims), + &(self.0).0, + ); + match text { + Ok(text_) => Ok(VerifiedToken { + text: text_, + claims: claims.clone(), + }), + Err(err) => Err(Error::JWTError(err)), + } + } else { + Err(Error::UnknownToken) + } + } +} diff --git a/orizentic/src/ b/orizentic/src/ new file mode 100644 index 0000000..3986ac6 --- /dev/null +++ b/orizentic/src/ @@ -0,0 +1,37 @@ +extern crate serde_json; + +use core; + +use std::fs::File; +use std::path::Path; +use std::io::{Read, Error, Write}; + +pub fn save_claims_to_file(claimsets: &Vec<&core::ClaimSet>, path: &String) -> Result<(), Error> { + let path = Path::new(path); + let mut file = File::create(&path)?; + + let claimsets_js: Vec = claimsets + .into_iter() + .map(|claims| core::ClaimSetJS::from_claimset(claims)) + .collect(); + let claimset_str = serde_json::to_string(&claimsets_js)?; + file.write_fmt(format_args!("{}", claimset_str))?; + + Ok(()) +} + +pub fn load_claims_from_file(path: &String) -> Result, Error> { + let path = Path::new(path); + let mut file = File::open(&path)?; + let mut text = String::new(); + + file.read_to_string(&mut text)?; + + let claimsets_js: Vec = serde_json::from_str(&text)?; + let claimsets = claimsets_js + .into_iter() + .map(|cl_js| core::ClaimSetJS::to_claimset(&cl_js)) + .collect(); + + Ok(claimsets) +} diff --git a/orizentic/src/ b/orizentic/src/ new file mode 100644 index 0000000..fe966d1 --- /dev/null +++ b/orizentic/src/ @@ -0,0 +1,30 @@ +//! The Orizentic token management library +//! +//! This library provides a high level interface for authentication token management. It wraps +//! around the [JWT]( standard using the +//! [`jsonwebtoken`]( library for serialization and +//! validation. +//! +//! Functionality revolves around the relationship between a [ClaimSet](struct.ClaimSet.html), a +//! [VerifiedToken](struct.VerifiedToken.html), and an +//! [UnverifiedToken](struct.UnverifiedToken.html). A [ClaimSet](struct.ClaimSet.html) is +//! considered informative and stores all of the information about the permissions and resources +//! that the token bearer should have access to. [VerifiedToken](struct.VerifiedToken.html) and +//! [UnverifiedToken](struct.UnverifiedToken.html) are the result of the process of decoding a +//! string JWT, and inherently specify whether the decoding process verified the signature, +//! expiration time, and presence in the database. +//! +//! This library does not currently contain database save and load features, but those are a likely +//! upcoming feature. +//! +//! No setup is necessary when using this library to decode JWT strings. Refer to the standalone +//! [decode_text](fn.decode_text.html) function. + +#[macro_use] +extern crate serde_derive; +extern crate thiserror; + +pub use core::*; + +mod core; +pub mod filedb; diff --git a/orizentic/tests/ b/orizentic/tests/ new file mode 100644 index 0000000..da62b55 --- /dev/null +++ b/orizentic/tests/ @@ -0,0 +1,429 @@ +extern crate chrono; +extern crate orizentic; + +use orizentic::filedb::*; +use orizentic::*; +use std::fs; +use std::ops; +use std::thread; +use std::time; + +struct FileCleanup(String); + +impl FileCleanup { + fn new(path: &str) -> FileCleanup { + FileCleanup(String::from(path)) + } +} + +impl ops::Drop for FileCleanup { + fn drop(&mut self) { + fs::remove_file(&self.0).expect("failed to remove time series file"); + } +} + +#[test] +fn can_create_a_new_claimset() { + let mut ctx = OrizenticCtx::new(Secret("abcdefg".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + assert_eq!(claims.audience, Username::from("Savanni")); + match claims.expiration { + Some(ttl) => assert_eq!(ttl - claims.issued_at, chrono::Duration::seconds(3600)), + None => panic!("ttl should not be None"), + } + assert_eq!(claims.issuer, Issuer(String::from("test"))); + assert_eq!(claims.resource, ResourceName(String::from("resource-1"))); + assert_eq!( + claims.permissions, + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]) + ); + { + let tok_list = ctx.list_claimsets(); + assert_eq!(tok_list.len(), 1); + assert!(tok_list.contains(&&claims)); + } + + let claims2 = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-2")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims2.clone()); + + assert_ne!(,; + assert_eq!(claims2.resource, ResourceName(String::from("resource-2"))); + + let tok_list = ctx.list_claimsets(); + assert_eq!(tok_list.len(), 2); + assert!(tok_list.contains(&&claims)); + assert!(tok_list.contains(&&claims2)); +} + +#[test] +fn can_retrieve_claim_by_id() { + let mut ctx = OrizenticCtx::new(Secret("abcdefg".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + let claims2 = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-2")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + ctx.add_claimset(claims2.clone()); + + assert_eq!(ctx.find_claimset(&, Some(&claims)); + assert_eq!(ctx.find_claimset(&, Some(&claims2)); + + ctx.revoke_claimset(&claims); + assert_eq!(ctx.find_claimset(&, None); + assert_eq!(ctx.find_claimset(&, Some(&claims2)); +} + +#[test] +fn can_revoke_claim_by_id() { + let mut ctx = OrizenticCtx::new(Secret("abcdefg".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + let claims2 = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-2")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + + ctx.add_claimset(claims.clone()); + ctx.add_claimset(claims2.clone()); + + assert_eq!(ctx.find_claimset(&, Some(&claims)); + assert_eq!(ctx.find_claimset(&, Some(&claims2)); + + ctx.revoke_by_uuid(&; + assert_eq!(ctx.find_claimset(&, None); + assert_eq!(ctx.find_claimset(&, Some(&claims2)); +} + +#[test] +fn can_revoke_a_token() { + let mut ctx = OrizenticCtx::new(Secret("abcdefg".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + let claims2 = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-2")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + ctx.add_claimset(claims2.clone()); + + ctx.revoke_claimset(&claims); + let tok_list = ctx.list_claimsets(); + assert_eq!(tok_list.len(), 1); + assert!(!tok_list.contains(&&claims)); + assert!(tok_list.contains(&&claims2)); +} + +#[test] +fn rejects_tokens_with_an_invalid_secret() { + let mut ctx1 = OrizenticCtx::new(Secret("ctx1".to_string().into_bytes()), Vec::new()); + let ctx2 = OrizenticCtx::new(Secret("ctx2".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx1.add_claimset(claims.clone()); + let encoded_token = ctx1.encode_claimset(&claims).ok().unwrap(); + assert!(ctx2.decode_and_validate_text(encoded_token.text).is_err()); +} + +#[test] +fn rejects_tokens_that_are_absent_from_the_database() { + let mut ctx = OrizenticCtx::new(Secret("ctx".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + let encoded_token = ctx.encode_claimset(&claims).ok().unwrap(); + + ctx.revoke_claimset(&claims); + assert!(ctx.decode_and_validate_text(encoded_token.text).is_err()); +} + +#[test] +fn validates_present_tokens_with_a_valid_secret() { + let mut ctx = OrizenticCtx::new(Secret("ctx".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + let encoded_token = ctx.encode_claimset(&claims).ok().unwrap(); + assert!(ctx.decode_and_validate_text(encoded_token.text).is_ok()); +} + +#[test] +fn rejects_expired_tokens() { + let mut ctx = OrizenticCtx::new(Secret("ctx".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(1))), + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + thread::sleep(time::Duration::from_secs(2)); + let encoded_token = ctx.encode_claimset(&claims).ok().unwrap(); + assert!(ctx.decode_and_validate_text(encoded_token.text).is_err()); +} + +#[test] +fn accepts_tokens_that_have_no_expiration() { + let mut ctx = OrizenticCtx::new(Secret("ctx".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + None, + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + let encoded_token = ctx.encode_claimset(&claims).ok().unwrap(); + assert!(ctx.decode_and_validate_text(encoded_token.text).is_ok()); +} + +#[test] +fn authorizes_a_token_with_the_correct_resource_and_permissions() { + let mut ctx = OrizenticCtx::new(Secret("ctx".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + None, + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + let encoded_token = ctx.encode_claimset(&claims).ok().unwrap(); + let token = ctx + .decode_and_validate_text(encoded_token.text) + .ok() + .unwrap(); + let res = token.check_authorizations(|rn: &ResourceName, perms: &Permissions| { + *rn == ResourceName(String::from("resource-1")) && perms.0.contains(&String::from("grant")) + }); + assert!(res); +} + +#[test] +fn rejects_a_token_with_the_incorrect_permissions() { + let mut ctx = OrizenticCtx::new(Secret("ctx".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + None, + ResourceName(String::from("resource-1")), + Username::from("Savanni"), + Permissions(vec![String::from("read"), String::from("write")]), + ); + ctx.add_claimset(claims.clone()); + let encoded_token = ctx.encode_claimset(&claims).ok().unwrap(); + let token = ctx + .decode_and_validate_text(encoded_token.text) + .ok() + .unwrap(); + let res = token.check_authorizations(|rn: &ResourceName, perms: &Permissions| { + *rn == ResourceName(String::from("resource-1")) && perms.0.contains(&String::from("grant")) + }); + assert!(!res); +} + +#[test] +fn rejects_a_token_with_the_incorrect_resource_name() { + let mut ctx = OrizenticCtx::new(Secret("ctx".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + None, + ResourceName(String::from("resource-2")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + let encoded_token = ctx.encode_claimset(&claims).ok().unwrap(); + let token = ctx + .decode_and_validate_text(encoded_token.text) + .ok() + .unwrap(); + let res = token.check_authorizations(|rn: &ResourceName, perms: &Permissions| { + *rn == ResourceName(String::from("resource-1")) && perms.0.contains(&String::from("grant")) + }); + assert!(!res); +} + +#[test] +fn claims_serialize_to_json() { + let claims = ClaimSet::new( + Issuer(String::from("test")), + None, + ResourceName(String::from("resource-2")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + + let expected_jti = format!("\"jti\":\"{}\"",; + + let claim_str = claims.to_json().expect("to_json threw an error"); + //.expect(assert!(false, format!("[claims_serilazie_to_json] {}", err))); + assert!(claim_str.contains(&expected_jti)); + + let claims_ = ClaimSet::from_json(&claim_str).expect("from_json threw an error"); + assert_eq!(claims, claims_); +} + +#[test] +fn save_and_load() { + let _file_cleanup = FileCleanup::new("var/claims.db"); + let mut ctx = OrizenticCtx::new(Secret("ctx".to_string().into_bytes()), Vec::new()); + let claims = ClaimSet::new( + Issuer(String::from("test")), + None, + ResourceName(String::from("resource-2")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims.clone()); + + let claims2 = ClaimSet::new( + Issuer(String::from("test")), + Some(TTL(chrono::Duration::seconds(3600))), + ResourceName(String::from("resource-2")), + Username::from("Savanni"), + Permissions(vec![ + String::from("read"), + String::from("write"), + String::from("grant"), + ]), + ); + ctx.add_claimset(claims2.clone()); + + let res = save_claims_to_file(&ctx.list_claimsets(), &String::from("var/claims.db")); + assert!(res.is_ok()); + + let claimset = load_claims_from_file(&String::from("var/claims.db")); + match claimset { + Ok(claimset_) => { + assert!(claimset_.contains(&claims)); + assert!(claimset_.contains(&claims2)); + } + Err(err) => assert!(false, "{}", err), + } +}