AuthN: Add session client (#60894)
* add basic session client * populate UserToken in ReqContext * token rotation as a post auth hook * fixed in context handler * add session token rotation * add session token tests * use namespacedID constructor
This commit is contained in:
+7
-3
@@ -62,12 +62,16 @@ func (ctx *Context) run() {
|
||||
|
||||
// RemoteAddr returns more real IP address.
|
||||
func (ctx *Context) RemoteAddr() string {
|
||||
addr := ctx.Req.Header.Get("X-Real-IP")
|
||||
return RemoteAddr(ctx.Req)
|
||||
}
|
||||
|
||||
func RemoteAddr(req *http.Request) string {
|
||||
addr := req.Header.Get("X-Real-IP")
|
||||
|
||||
if len(addr) == 0 {
|
||||
// X-Forwarded-For may contain multiple IP addresses, separated by
|
||||
// commas.
|
||||
addr = strings.TrimSpace(strings.Split(ctx.Req.Header.Get("X-Forwarded-For"), ",")[0])
|
||||
addr = strings.TrimSpace(strings.Split(req.Header.Get("X-Forwarded-For"), ",")[0])
|
||||
}
|
||||
|
||||
// parse user inputs from headers to prevent log forgery
|
||||
@@ -79,7 +83,7 @@ func (ctx *Context) RemoteAddr() string {
|
||||
}
|
||||
|
||||
if len(addr) == 0 {
|
||||
addr = ctx.Req.RemoteAddr
|
||||
addr = req.RemoteAddr
|
||||
if i := strings.LastIndex(addr, ":"); i > -1 {
|
||||
addr = addr[:i]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user