jwt.go 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133
  1. /*-
  2. * Copyright 2016 Zbigniew Mandziejewicz
  3. * Copyright 2016 Square, Inc.
  4. *
  5. * Licensed under the Apache License, Version 2.0 (the "License");
  6. * you may not use this file except in compliance with the License.
  7. * You may obtain a copy of the License at
  8. *
  9. * http://www.apache.org/licenses/LICENSE-2.0
  10. *
  11. * Unless required by applicable law or agreed to in writing, software
  12. * distributed under the License is distributed on an "AS IS" BASIS,
  13. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. * See the License for the specific language governing permissions and
  15. * limitations under the License.
  16. */
  17. package jwt
  18. import (
  19. "fmt"
  20. "gopkg.in/square/go-jose.v2"
  21. "gopkg.in/square/go-jose.v2/json"
  22. "strings"
  23. )
  24. // JSONWebToken represents a JSON Web Token (as specified in RFC7519).
  25. type JSONWebToken struct {
  26. payload func(k interface{}) ([]byte, error)
  27. unverifiedPayload func() []byte
  28. Headers []jose.Header
  29. }
  30. type NestedJSONWebToken struct {
  31. enc *jose.JSONWebEncryption
  32. Headers []jose.Header
  33. }
  34. // Claims deserializes a JSONWebToken into dest using the provided key.
  35. func (t *JSONWebToken) Claims(key interface{}, dest ...interface{}) error {
  36. b, err := t.payload(key)
  37. if err != nil {
  38. return err
  39. }
  40. for _, d := range dest {
  41. if err := json.Unmarshal(b, d); err != nil {
  42. return err
  43. }
  44. }
  45. return nil
  46. }
  47. // UnsafeClaimsWithoutVerification deserializes the claims of a
  48. // JSONWebToken into the dests. For signed JWTs, the claims are not
  49. // verified. This function won't work for encrypted JWTs.
  50. func (t *JSONWebToken) UnsafeClaimsWithoutVerification(dest ...interface{}) error {
  51. if t.unverifiedPayload == nil {
  52. return fmt.Errorf("square/go-jose: Cannot get unverified claims")
  53. }
  54. claims := t.unverifiedPayload()
  55. for _, d := range dest {
  56. if err := json.Unmarshal(claims, d); err != nil {
  57. return err
  58. }
  59. }
  60. return nil
  61. }
  62. func (t *NestedJSONWebToken) Decrypt(decryptionKey interface{}) (*JSONWebToken, error) {
  63. b, err := t.enc.Decrypt(decryptionKey)
  64. if err != nil {
  65. return nil, err
  66. }
  67. sig, err := ParseSigned(string(b))
  68. if err != nil {
  69. return nil, err
  70. }
  71. return sig, nil
  72. }
  73. // ParseSigned parses token from JWS form.
  74. func ParseSigned(s string) (*JSONWebToken, error) {
  75. sig, err := jose.ParseSigned(s)
  76. if err != nil {
  77. return nil, err
  78. }
  79. headers := make([]jose.Header, len(sig.Signatures))
  80. for i, signature := range sig.Signatures {
  81. headers[i] = signature.Header
  82. }
  83. return &JSONWebToken{
  84. payload: sig.Verify,
  85. unverifiedPayload: sig.UnsafePayloadWithoutVerification,
  86. Headers: headers,
  87. }, nil
  88. }
  89. // ParseEncrypted parses token from JWE form.
  90. func ParseEncrypted(s string) (*JSONWebToken, error) {
  91. enc, err := jose.ParseEncrypted(s)
  92. if err != nil {
  93. return nil, err
  94. }
  95. return &JSONWebToken{
  96. payload: enc.Decrypt,
  97. Headers: []jose.Header{enc.Header},
  98. }, nil
  99. }
  100. // ParseSignedAndEncrypted parses signed-then-encrypted token from JWE form.
  101. func ParseSignedAndEncrypted(s string) (*NestedJSONWebToken, error) {
  102. enc, err := jose.ParseEncrypted(s)
  103. if err != nil {
  104. return nil, err
  105. }
  106. contentType, _ := enc.Header.ExtraHeaders[jose.HeaderContentType].(string)
  107. if strings.ToUpper(contentType) != "JWT" {
  108. return nil, ErrInvalidContentType
  109. }
  110. return &NestedJSONWebToken{
  111. enc: enc,
  112. Headers: []jose.Header{enc.Header},
  113. }, nil
  114. }