Abort if invalid token/data and wrap some errors

This commit is contained in:
Jan Bader 2021-12-06 21:12:32 +00:00
parent 29cee46a14
commit 16b59afc29
3 changed files with 7 additions and 4 deletions

View File

@ -19,6 +19,7 @@ func (h *Handler) getImportantData(c *gin.Context) {
budgetUUID, err := uuid.Parse(budgetID) budgetUUID, err := uuid.Parse(budgetID)
if err != nil { if err != nil {
c.Redirect(http.StatusTemporaryRedirect, "/login") c.Redirect(http.StatusTemporaryRedirect, "/login")
c.Abort()
return return
} }

View File

@ -2,6 +2,7 @@ package http
import ( import (
"context" "context"
"fmt"
"net/http" "net/http"
"time" "time"
@ -13,13 +14,13 @@ import (
func (h *Handler) verifyLogin(c *gin.Context) (budgeteer.Token, error) { func (h *Handler) verifyLogin(c *gin.Context) (budgeteer.Token, error) {
tokenString, err := c.Cookie(authCookie) tokenString, err := c.Cookie(authCookie)
if err != nil { if err != nil {
return nil, err return nil, fmt.Errorf("get cookie: %w", err)
} }
token, err := h.TokenVerifier.VerifyToken(tokenString) token, err := h.TokenVerifier.VerifyToken(tokenString)
if err != nil { if err != nil {
c.SetCookie(authCookie, "", -1, "", "", false, false) c.SetCookie(authCookie, "", -1, "", "", false, false)
return nil, err return nil, fmt.Errorf("verify token '%s': %w", tokenString, err)
} }
return token, nil return token, nil
@ -29,6 +30,7 @@ func (h *Handler) verifyLoginWithRedirect(c *gin.Context) {
token, err := h.verifyLogin(c) token, err := h.verifyLogin(c)
if err != nil { if err != nil {
c.Redirect(http.StatusTemporaryRedirect, "/login") c.Redirect(http.StatusTemporaryRedirect, "/login")
c.Abort()
return return
} }

View File

@ -54,12 +54,12 @@ func (tv *TokenVerifier) VerifyToken(tokenString string) (budgeteer.Token, error
return []byte(secret), nil return []byte(secret), nil
}) })
if err != nil { if err != nil {
return nil, err return nil, fmt.Errorf("parse jwt: %w", err)
} }
claims, err := verifyToken(token) claims, err := verifyToken(token)
if err != nil { if err != nil {
return nil, err return nil, fmt.Errorf("verify jwt: %w", err)
} }
tkn := &Token{ tkn := &Token{