2021-05-20 13:33:35 +02:00
|
|
|
package domain
|
|
|
|
|
|
|
|
import (
|
|
|
|
"encoding/base64"
|
|
|
|
"strings"
|
|
|
|
|
2022-04-27 01:01:45 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/crypto"
|
2023-12-08 16:30:55 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/zerrors"
|
2021-05-20 13:33:35 +02:00
|
|
|
)
|
|
|
|
|
|
|
|
func NewRefreshToken(userID, tokenID string, algorithm crypto.EncryptionAlgorithm) (string, error) {
|
|
|
|
return RefreshToken(userID, tokenID, tokenID, algorithm)
|
|
|
|
}
|
|
|
|
|
|
|
|
func RefreshToken(userID, tokenID, token string, algorithm crypto.EncryptionAlgorithm) (string, error) {
|
|
|
|
encrypted, err := algorithm.Encrypt([]byte(userID + ":" + tokenID + ":" + token))
|
|
|
|
if err != nil {
|
|
|
|
return "", err
|
|
|
|
}
|
|
|
|
return base64.RawURLEncoding.EncodeToString(encrypted), nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func FromRefreshToken(refreshToken string, algorithm crypto.EncryptionAlgorithm) (userID, tokenID, token string, err error) {
|
|
|
|
decoded, err := base64.RawURLEncoding.DecodeString(refreshToken)
|
|
|
|
if err != nil {
|
2024-04-09 09:42:59 +03:00
|
|
|
return "", "", "", zerrors.ThrowInvalidArgument(err, "DOMAIN-BGDhn", "Errors.User.RefreshToken.Invalid")
|
2021-05-20 13:33:35 +02:00
|
|
|
}
|
2024-08-02 11:38:37 +03:00
|
|
|
decrypted, err := algorithm.DecryptString(decoded, algorithm.EncryptionKeyID())
|
2021-05-20 13:33:35 +02:00
|
|
|
if err != nil {
|
2024-08-02 11:38:37 +03:00
|
|
|
return "", "", "", zerrors.ThrowInvalidArgument(err, "DOMAIN-rie9A", "Errors.User.RefreshToken.Invalid")
|
2021-05-20 13:33:35 +02:00
|
|
|
}
|
2024-08-02 11:38:37 +03:00
|
|
|
split := strings.Split(decrypted, ":")
|
2021-05-20 13:33:35 +02:00
|
|
|
if len(split) != 3 {
|
2024-08-02 11:38:37 +03:00
|
|
|
return "", "", "", zerrors.ThrowInvalidArgument(nil, "DOMAIN-Se8oh", "Errors.User.RefreshToken.Invalid")
|
2021-05-20 13:33:35 +02:00
|
|
|
}
|
|
|
|
return split[0], split[1], split[2], nil
|
|
|
|
}
|