jwt.go 2.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114
  1. /*-
  2. * Copyright 2016 Zbigniew Mandziejewicz
  3. * Copyright 2016 Square, Inc.
  4. *
  5. * Licensed under the Apache License, Version 2.0 (the "License");
  6. * you may not use this file except in compliance with the License.
  7. * You may obtain a copy of the License at
  8. *
  9. * http://www.apache.org/licenses/LICENSE-2.0
  10. *
  11. * Unless required by applicable law or agreed to in writing, software
  12. * distributed under the License is distributed on an "AS IS" BASIS,
  13. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. * See the License for the specific language governing permissions and
  15. * limitations under the License.
  16. */
  17. package jwt
  18. import (
  19. "gopkg.in/square/go-jose.v2"
  20. "gopkg.in/square/go-jose.v2/json"
  21. "strings"
  22. )
  23. // JSONWebToken represents a JSON Web Token (as specified in RFC7519).
  24. type JSONWebToken struct {
  25. payload func(k interface{}) ([]byte, error)
  26. Headers []jose.Header
  27. }
  28. type NestedJSONWebToken struct {
  29. enc *jose.JSONWebEncryption
  30. Headers []jose.Header
  31. }
  32. // Claims deserializes a JSONWebToken into dest using the provided key.
  33. func (t *JSONWebToken) Claims(key interface{}, dest ...interface{}) error {
  34. b, err := t.payload(key)
  35. if err != nil {
  36. return err
  37. }
  38. for _, d := range dest {
  39. if err := json.Unmarshal(b, d); err != nil {
  40. return err
  41. }
  42. }
  43. return nil
  44. }
  45. func (t *NestedJSONWebToken) Decrypt(decryptionKey interface{}) (*JSONWebToken, error) {
  46. b, err := t.enc.Decrypt(decryptionKey)
  47. if err != nil {
  48. return nil, err
  49. }
  50. sig, err := ParseSigned(string(b))
  51. if err != nil {
  52. return nil, err
  53. }
  54. return sig, nil
  55. }
  56. // ParseSigned parses token from JWS form.
  57. func ParseSigned(s string) (*JSONWebToken, error) {
  58. sig, err := jose.ParseSigned(s)
  59. if err != nil {
  60. return nil, err
  61. }
  62. headers := make([]jose.Header, len(sig.Signatures))
  63. for i, signature := range sig.Signatures {
  64. headers[i] = signature.Header
  65. }
  66. return &JSONWebToken{
  67. payload: sig.Verify,
  68. Headers: headers,
  69. }, nil
  70. }
  71. // ParseEncrypted parses token from JWE form.
  72. func ParseEncrypted(s string) (*JSONWebToken, error) {
  73. enc, err := jose.ParseEncrypted(s)
  74. if err != nil {
  75. return nil, err
  76. }
  77. return &JSONWebToken{
  78. payload: enc.Decrypt,
  79. Headers: []jose.Header{enc.Header},
  80. }, nil
  81. }
  82. // ParseSignedAndEncrypted parses signed-then-encrypted token from JWE form.
  83. func ParseSignedAndEncrypted(s string) (*NestedJSONWebToken, error) {
  84. enc, err := jose.ParseEncrypted(s)
  85. if err != nil {
  86. return nil, err
  87. }
  88. contentType, _ := enc.Header.ExtraHeaders[jose.HeaderContentType].(string)
  89. if strings.ToUpper(contentType) != "JWT" {
  90. return nil, ErrInvalidContentType
  91. }
  92. return &NestedJSONWebToken{
  93. enc: enc,
  94. Headers: []jose.Header{enc.Header},
  95. }, nil
  96. }