Feat v0.6.9 cookie fix roadmap (#44)
Some checks failed
CI/CD / detect-changes (push) Successful in 19s
CI/CD / test-frontend (push) Successful in 27s
CI/CD / test-go-pg (push) Failing after 2m46s
CI/CD / test-sqlite (push) Successful in 3m24s
CI/CD / build-and-deploy (push) Has been skipped

Co-authored-by: Jeffrey Smith <jasafpro@gmail.com>
Co-committed-by: Jeffrey Smith <jasafpro@gmail.com>
This commit was merged in pull request #44.
This commit is contained in:
2026-04-01 09:41:59 +00:00
committed by xcaliber
parent 680ec3b897
commit 617d81e7d4
20 changed files with 866 additions and 42 deletions

View File

@@ -142,9 +142,30 @@ func parseAndValidateJWT(tokenString string, jwtSecret string) (*Claims, bool) {
return claims, true
}
// parseJWTIgnoringExpiry parses a JWT and validates the signature but
// tolerates an expired token. Used by page-auth middleware so the Go
// template can render the page shell even when the access token has
// lapsed — the Preact SDK will refresh the token client-side.
// Returns (claims, signatureValid). A tampered or unsigned token
// returns (nil, false).
func parseJWTIgnoringExpiry(tokenString string, jwtSecret string) (*Claims, bool) {
claims := &Claims{}
_, err := jwt.ParseWithClaims(tokenString, claims, func(t *jwt.Token) (interface{}, error) {
if _, ok := t.Method.(*jwt.SigningMethodHMAC); !ok {
return nil, jwt.ErrSignatureInvalid
}
return []byte(jwtSecret), nil
}, jwt.WithoutClaimsValidation())
if err != nil {
return nil, false
}
return claims, true
}
// UserIDFromCookie extracts the user ID from the arm_token cookie without
// requiring authentication. Returns "" if no valid token is found.
// Used by unauthenticated routes that want optional user context.
// Tolerates expired tokens (signature must be valid) so that user preferences
// still apply even when the access token has lapsed.
func UserIDFromCookie(c *gin.Context, jwtSecret string) string {
cookie, err := c.Cookie("arm_token")
if err != nil || cookie == "" {
@@ -152,7 +173,11 @@ func UserIDFromCookie(c *gin.Context, jwtSecret string) string {
}
claims, ok := parseAndValidateJWT(cookie, jwtSecret)
if !ok {
return ""
// Accept expired-but-signed token for optional user context
claims, ok = parseJWTIgnoringExpiry(cookie, jwtSecret)
if !ok {
return ""
}
}
return claims.UserID
}

View File

@@ -0,0 +1,82 @@
package middleware
import (
"testing"
"time"
"github.com/golang-jwt/jwt/v5"
)
const testSecret = "test-jwt-secret-key"
func makeToken(t *testing.T, userID, email string, expiresAt time.Time) string {
t.Helper()
claims := Claims{
UserID: userID,
Email: email,
RegisteredClaims: jwt.RegisteredClaims{
ExpiresAt: jwt.NewNumericDate(expiresAt),
IssuedAt: jwt.NewNumericDate(time.Now().Add(-1 * time.Hour)),
ID: "test-jti",
},
}
token := jwt.NewWithClaims(jwt.SigningMethodHS256, claims)
s, err := token.SignedString([]byte(testSecret))
if err != nil {
t.Fatal(err)
}
return s
}
func TestParseAndValidateJWT_Valid(t *testing.T) {
tok := makeToken(t, "u1", "a@b.com", time.Now().Add(15*time.Minute))
claims, ok := parseAndValidateJWT(tok, testSecret)
if !ok {
t.Fatal("expected valid token to parse")
}
if claims.UserID != "u1" {
t.Errorf("UserID = %q, want u1", claims.UserID)
}
}
func TestParseAndValidateJWT_Expired(t *testing.T) {
tok := makeToken(t, "u1", "a@b.com", time.Now().Add(-5*time.Minute))
_, ok := parseAndValidateJWT(tok, testSecret)
if ok {
t.Fatal("expected expired token to be rejected by strict parser")
}
}
func TestParseAndValidateJWT_WrongSecret(t *testing.T) {
tok := makeToken(t, "u1", "a@b.com", time.Now().Add(15*time.Minute))
_, ok := parseAndValidateJWT(tok, "wrong-secret")
if ok {
t.Fatal("expected wrong-secret token to be rejected")
}
}
func TestParseJWTIgnoringExpiry_Expired(t *testing.T) {
tok := makeToken(t, "u1", "a@b.com", time.Now().Add(-5*time.Minute))
claims, ok := parseJWTIgnoringExpiry(tok, testSecret)
if !ok {
t.Fatal("expected expired token to be accepted by lenient parser")
}
if claims.UserID != "u1" {
t.Errorf("UserID = %q, want u1", claims.UserID)
}
}
func TestParseJWTIgnoringExpiry_WrongSecret(t *testing.T) {
tok := makeToken(t, "u1", "a@b.com", time.Now().Add(-5*time.Minute))
_, ok := parseJWTIgnoringExpiry(tok, "wrong-secret")
if ok {
t.Fatal("expected tampered token to be rejected even with lenient parser")
}
}
func TestParseJWTIgnoringExpiry_GarbageToken(t *testing.T) {
_, ok := parseJWTIgnoringExpiry("not.a.jwt", testSecret)
if ok {
t.Fatal("expected garbage token to be rejected")
}
}

View File

@@ -50,10 +50,17 @@ func AuthOrRedirect(cfg *config.Config, users store.UserStore, cache *UserStatus
return
}
// Try strict validation first (token not expired).
claims, ok := parseAndValidateJWT(tokenString, cfg.JWTSecret)
if !ok {
redirectToLogin(c, loginPath)
return
// Fallback: accept an expired-but-signed token so the page
// shell can render and the Preact SDK can refresh client-side.
// A tampered/unsigned token still gets rejected.
claims, ok = parseJWTIgnoringExpiry(tokenString, cfg.JWTSecret)
if !ok {
redirectToLogin(c, loginPath)
return
}
}
if claims.UserID == "" {