strategy.js 2.2 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586
  1. var passport = require('passport-strategy')
  2. , siwe = require('siwe')
  3. , url = require('url')
  4. , util = require('util')
  5. , utils = require('./utils')
  6. , SessionStore = require('./store/session');
  7. function Strategy(options, verify) {
  8. if (typeof options == 'function') {
  9. verify = options;
  10. options = {};
  11. }
  12. if (!verify) { throw new TypeError('EthereumStrategy requires a verify function'); }
  13. this.name = 'ethereum';
  14. this._verify = verify;
  15. this._passReqToCallback = options.passReqToCallback;
  16. this._store = options.store || new SessionStore();
  17. }
  18. /**
  19. * Inherit from `passport.Strategy`.
  20. */
  21. util.inherits(Strategy, passport.Strategy);
  22. Strategy.prototype.authenticate = function(req, options) {
  23. //console.log(req.body);
  24. var message = req.body.message
  25. , signature = req.body.signature;
  26. if (!message) { return this.fail({ message: 'Missing message' }, 400); }
  27. if (!signature) { return this.fail({ message: 'Missing signature' }, 400); }
  28. var self = this;
  29. var siweMessage;
  30. try {
  31. var siweMessage = new siwe.SiweMessage(message);
  32. } catch(ex) {
  33. return self.fail({ message: 'Invalid message' }, 403);
  34. }
  35. var origin = utils.originalOrigin(req);
  36. if (origin !== siweMessage.uri) {
  37. return self.fail({ message: 'URI mismatch' }, 403);
  38. }
  39. var domain = url.parse(origin).host;
  40. if (domain !== siweMessage.domain) {
  41. return self.fail({ message: 'Domain mismatch' }, 403);
  42. }
  43. this._store.verify(req, siweMessage.nonce, function(err, ok, info) {
  44. if (!ok) {
  45. return self.fail(info, 403);
  46. }
  47. siweMessage.validate(signature)
  48. .then(function(message) {
  49. function verified(err, user, info) {
  50. if (err) { return self.error(err); }
  51. if (!user) { return self.fail(info); }
  52. self.success(user, info);
  53. }
  54. try {
  55. if (self._passReqToCallback) {
  56. self._verify(req, message.address, verified);
  57. } else {
  58. self._verify(message.address, verified);
  59. }
  60. } catch (ex) {
  61. return self.error(ex);
  62. }
  63. })
  64. .catch(function(err) {
  65. return self.fail({ message: 'Invalid signature' });
  66. });
  67. });
  68. };
  69. /**
  70. * Expose `Strategy`.
  71. */
  72. module.exports = Strategy;