mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
Signed-off-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <wpfleger@block.xyz> Signed-off-by: Will Pfleger <wpfleger@squareup.com> Signed-off-by: Will Pfleger <wpfleger96@gmail.com> Co-authored-by: npub1mn7jgtj4w2pd0g0zeuhxsa6jy6p0rewxz4kujt98my82ahfmp72sxjexk7 <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@sprout-oss.stage.blox.sqprod.co> Co-authored-by: npub1fgdl5qqnh3k3f2xkqrvt7cujalhm623x4s7fdjdj5yrtp5fzjl9qrjpucw <4a1bfa0013bc6d14a8d600d8bf6392efefbd2a26ac3c96c9b2a106b0d12297ca@sprout-oss.stage.blox.sqprod.co> Co-authored-by: npub16v54tttfqacx9ycvc3k0ut0npj564ahcuajzy6qjvh57ntmsf4uq4806j2 <d32955ad69077062930cc46cfe2df30ca9aaf6f8e76422681265e9e9af704d78@sprout-oss.stage.blox.sqprod.co> Co-authored-by: Will Pfleger <wpfleger96@gmail.com>
122 lines
3.6 KiB
Rust
122 lines
3.6 KiB
Rust
//! Invite token management for guest authentication via NIP-42 AUTH tags.
|
|
|
|
use chrono::{DateTime, Utc};
|
|
use uuid::Uuid;
|
|
|
|
use crate::error::ProxyError;
|
|
|
|
/// An invite token granting a guest access to one or more channels.
|
|
#[derive(Debug, Clone)]
|
|
pub struct InviteToken {
|
|
/// The raw token string presented by the guest during NIP-42 AUTH.
|
|
pub token: String,
|
|
/// Channels this token grants access to.
|
|
pub channel_ids: Vec<Uuid>,
|
|
/// When the token expires.
|
|
pub expires_at: DateTime<Utc>,
|
|
/// Maximum number of times the token may be used.
|
|
pub max_uses: u32,
|
|
/// Number of times the token has been used so far.
|
|
pub uses: u32,
|
|
}
|
|
|
|
impl InviteToken {
|
|
/// Create a new invite token with zero uses.
|
|
pub fn new(
|
|
token: impl Into<String>,
|
|
channel_ids: Vec<Uuid>,
|
|
expires_at: DateTime<Utc>,
|
|
max_uses: u32,
|
|
) -> Self {
|
|
Self {
|
|
token: token.into(),
|
|
channel_ids,
|
|
expires_at,
|
|
max_uses,
|
|
uses: 0,
|
|
}
|
|
}
|
|
|
|
/// Returns `Ok(())` if the token is not expired and has remaining uses.
|
|
pub fn validate(&self, now: DateTime<Utc>) -> Result<(), ProxyError> {
|
|
if now >= self.expires_at {
|
|
return Err(ProxyError::InviteExpired);
|
|
}
|
|
if self.uses >= self.max_uses {
|
|
return Err(ProxyError::InviteExhausted);
|
|
}
|
|
Ok(())
|
|
}
|
|
|
|
/// Returns `true` if the token passes validation at `now`.
|
|
pub fn is_valid(&self, now: DateTime<Utc>) -> bool {
|
|
self.validate(now).is_ok()
|
|
}
|
|
|
|
/// Increments the use counter by one (saturating).
|
|
pub fn consume(&mut self) {
|
|
self.uses = self.uses.saturating_add(1);
|
|
}
|
|
}
|
|
|
|
#[cfg(test)]
|
|
mod tests {
|
|
use super::*;
|
|
use chrono::Duration;
|
|
|
|
fn future(secs: i64) -> DateTime<Utc> {
|
|
Utc::now() + Duration::seconds(secs)
|
|
}
|
|
|
|
fn past(secs: i64) -> DateTime<Utc> {
|
|
Utc::now() - Duration::seconds(secs)
|
|
}
|
|
|
|
#[test]
|
|
fn test_invite_token_validation() {
|
|
let token = InviteToken::new("tok-valid", vec![], future(3600), 5);
|
|
assert!(token.validate(Utc::now()).is_ok());
|
|
assert!(token.is_valid(Utc::now()));
|
|
}
|
|
|
|
#[test]
|
|
fn test_invite_token_expired() {
|
|
let token = InviteToken::new("tok-expired", vec![], past(1), 5);
|
|
let err = token.validate(Utc::now()).unwrap_err();
|
|
assert!(matches!(err, ProxyError::InviteExpired));
|
|
assert!(!token.is_valid(Utc::now()));
|
|
}
|
|
|
|
#[test]
|
|
fn test_invite_token_exhausted() {
|
|
let mut token = InviteToken::new("tok-used-up", vec![], future(3600), 2);
|
|
token.uses = 2;
|
|
let err = token.validate(Utc::now()).unwrap_err();
|
|
assert!(matches!(err, ProxyError::InviteExhausted));
|
|
assert!(!token.is_valid(Utc::now()));
|
|
}
|
|
|
|
#[test]
|
|
fn test_invite_token_consume_increments_uses() {
|
|
let mut token = InviteToken::new("tok-consume", vec![], future(3600), 3);
|
|
assert_eq!(token.uses, 0);
|
|
token.consume();
|
|
assert_eq!(token.uses, 1);
|
|
token.consume();
|
|
assert_eq!(token.uses, 2);
|
|
// Still valid (uses < max_uses)
|
|
assert!(token.is_valid(Utc::now()));
|
|
token.consume();
|
|
assert!(!token.is_valid(Utc::now()));
|
|
}
|
|
|
|
#[test]
|
|
fn test_invite_token_consume_saturates_at_max() {
|
|
let mut token = InviteToken::new("tok-sat", vec![], future(3600), 1);
|
|
// Consume beyond max_uses — should not overflow
|
|
token.uses = u32::MAX;
|
|
token.consume(); // saturating_add should not panic
|
|
assert_eq!(token.uses, u32::MAX);
|
|
}
|
|
}
|