Skip to content

Commit a8f32f4

Browse files
authored
Merge pull request #44 from auth0-samples/patch/jwt-v2
[SDK-2851] Use v2 branch of auth0/go-jwt-middleware
2 parents f054cbc + b952db7 commit a8f32f4

5 files changed

Lines changed: 126 additions & 99 deletions

File tree

01-Authorization-RS256/go.mod

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,9 +3,9 @@ module 01-Authorization-RS256
33
go 1.16
44

55
require (
6-
github.com/auth0/go-jwt-middleware v1.0.1
7-
github.com/form3tech-oss/jwt-go v3.2.5+incompatible
6+
github.com/auth0/go-jwt-middleware v1.0.1-0.20210719135851-6401fcf7191b
87
github.com/gin-contrib/cors v1.3.1
98
github.com/gin-gonic/gin v1.7.4
9+
github.com/golang-jwt/jwt v3.2.1+incompatible
1010
github.com/joho/godotenv v1.4.0
1111
)

01-Authorization-RS256/go.sum

Lines changed: 22 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,8 @@
1-
github.com/auth0/go-jwt-middleware v1.0.1 h1:/fsQ4vRr4zod1wKReUH+0A3ySRjGiT9G34kypO/EKwI=
2-
github.com/auth0/go-jwt-middleware v1.0.1/go.mod h1:YSeUX3z6+TF2H+7padiEqNJ73Zy9vXW72U//IgN0BIM=
1+
github.com/auth0/go-jwt-middleware v1.0.1-0.20210719135851-6401fcf7191b h1:pXI+CXqYUZaQvLzrQ5cxdShF7OjaYgZbK351CJc5uNQ=
2+
github.com/auth0/go-jwt-middleware v1.0.1-0.20210719135851-6401fcf7191b/go.mod h1:Tlhz43qRKMMQ4WAii9sfAuW8sPuAgQCB4yIjPgT8AH0=
33
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
44
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
55
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
6-
github.com/form3tech-oss/jwt-go v3.2.2+incompatible/go.mod h1:pbq4aXjuKjdthFRnoDwaVPLA+WlJuPGy+QneDUgJi2k=
7-
github.com/form3tech-oss/jwt-go v3.2.5+incompatible h1:/l4kBbb4/vGSsdtB5nUe8L7B9mImVMaBPw9L/0TBHU8=
8-
github.com/form3tech-oss/jwt-go v3.2.5+incompatible/go.mod h1:pbq4aXjuKjdthFRnoDwaVPLA+WlJuPGy+QneDUgJi2k=
96
github.com/gin-contrib/cors v1.3.1 h1:doAsuITavI4IOcd0Y19U4B+O0dNWihRyX//nn4sEmgA=
107
github.com/gin-contrib/cors v1.3.1/go.mod h1:jjEJ4268OPZUcU7k9Pm653S7lXUGcqMADzFA61xsmDk=
118
github.com/gin-contrib/sse v0.1.0 h1:Y/yl/+YNO8GZSjAhjMsSuLt29uWRFHdHYUb5lYOV9qE=
@@ -23,22 +20,19 @@ github.com/go-playground/universal-translator v0.17.0 h1:icxd5fm+REJzpZx7ZfpaD87
2320
github.com/go-playground/universal-translator v0.17.0/go.mod h1:UkSxE5sNxxRwHyU+Scu5vgOQjsIJAF8j9muTVoKLVtA=
2421
github.com/go-playground/validator/v10 v10.4.1 h1:pH2c5ADXtd66mxoE0Zm9SUhxE20r7aM3F26W0hOn+GE=
2522
github.com/go-playground/validator/v10 v10.4.1/go.mod h1:nlOn6nFhuKACm19sB/8EGNn9GlaMV7XkbRSipzJ0Ii4=
23+
github.com/golang-jwt/jwt v3.2.1+incompatible h1:73Z+4BJcrTC+KczS6WvTPvRGOp1WmfEP4Q1lOd9Z/+c=
24+
github.com/golang-jwt/jwt v3.2.1+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
2625
github.com/golang/protobuf v1.3.2/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=
2726
github.com/golang/protobuf v1.3.3 h1:gyjaxf+svBWX08ZjK86iN9geUJF0H6gp2IRKX6Nf6/I=
2827
github.com/golang/protobuf v1.3.3/go.mod h1:vzj43D7+SQXF/4pzW/hwtAqwc6iTitCiVSaWz5lYuqw=
28+
github.com/google/go-cmp v0.5.6 h1:BKbKCqvP6I+rmFHt06ZmyQtvB8xAkWdhFyr0ZUNZcxQ=
29+
github.com/google/go-cmp v0.5.6/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
2930
github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg=
30-
github.com/gopherjs/gopherjs v0.0.0-20181017120253-0766667cb4d1/go.mod h1:wJfORRmW1u3UXTncJ5qlYoELFm8eSnnEO6hX4iZ3EWY=
31-
github.com/gopherjs/gopherjs v0.0.0-20200217142428-fce0ec30dd00 h1:l5lAOZEym3oK3SQ2HBHWsJUfbNBiTXJDeW2QDxw9AQ0=
32-
github.com/gopherjs/gopherjs v0.0.0-20200217142428-fce0ec30dd00/go.mod h1:wJfORRmW1u3UXTncJ5qlYoELFm8eSnnEO6hX4iZ3EWY=
33-
github.com/gorilla/mux v1.7.4 h1:VuZ8uybHlWmqV03+zRzdwKL4tUnIp1MAQtp1mIFE1bc=
34-
github.com/gorilla/mux v1.7.4/go.mod h1:DVbg23sWSpFRCP0SfiEN6jmj59UnW/n46BH5rLB71So=
3531
github.com/joho/godotenv v1.4.0 h1:3l4+N6zfMWnkbPEXKng2o2/MR5mSwTrBih4ZEkkz1lg=
3632
github.com/joho/godotenv v1.4.0/go.mod h1:f4LDr5Voq0i2e/R5DDNOoa2zzDfwtkZa6DnEwAbqwq4=
3733
github.com/json-iterator/go v1.1.7/go.mod h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4=
3834
github.com/json-iterator/go v1.1.9 h1:9yzud/Ht36ygwatGx56VwCZtlI/2AD15T1X2sjSuGns=
3935
github.com/json-iterator/go v1.1.9/go.mod h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4=
40-
github.com/jtolds/gls v4.20.0+incompatible h1:xdiiI2gbIgH/gLH7ADydsJ1uDOEzR8yvV7C0MuV77Wo=
41-
github.com/jtolds/gls v4.20.0+incompatible/go.mod h1:QJZ7F/aHp+rZTRtaJ1ow/lLfFfVYBRgL+9YlvaHOwJU=
4236
github.com/kr/pretty v0.1.0 h1:L/CwN0zerZDmRFUapSPitk6f+Q3+0za1rQkzVuMiMFI=
4337
github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
4438
github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ=
@@ -54,42 +48,46 @@ github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421 h1:ZqeYNhU3OH
5448
github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=
5549
github.com/modern-go/reflect2 v0.0.0-20180701023420-4b7aa43c6742 h1:Esafd1046DLDQ0W1YjYsBW+p8U2u7vzgW2SQVmlNazg=
5650
github.com/modern-go/reflect2 v0.0.0-20180701023420-4b7aa43c6742/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
51+
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
52+
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
5753
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
5854
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
59-
github.com/smartystreets/assertions v0.0.0-20180927180507-b2de0cb4f26d/go.mod h1:OnSkiWE9lh6wB0YB77sQom3nweQdgAjqCqsofrRNTgc=
60-
github.com/smartystreets/assertions v1.1.0 h1:MkTeG1DMwsrdH7QtLXy5W+fUxWq+vmb6cLmyJ7aRtF0=
61-
github.com/smartystreets/assertions v1.1.0/go.mod h1:tcbTF8ujkAEcZ8TElKY+i30BzYlVhC/LOxJk7iOWnoo=
62-
github.com/smartystreets/goconvey v1.6.4 h1:fv0U8FUIMPNf1L9lnHLvLhgicrIVChEkdzIKYqbNC9s=
63-
github.com/smartystreets/goconvey v1.6.4/go.mod h1:syvi0/a8iFYH4r/RixwvyeAJjdLS9QV7WQ/tjFTllLA=
6455
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
6556
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
66-
github.com/stretchr/testify v1.4.0 h1:2E4SXV/wtOkTonXsotYi4li6zVWxYlZuYNCXe9XRJyk=
6757
github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4=
58+
github.com/stretchr/testify v1.7.0 h1:nwc3DEeHmmLAfoZucVR881uASk0Mfjw8xYJ99tb5CcY=
59+
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
6860
github.com/ugorji/go v1.1.7 h1:/68gy2h+1mWMrwZFeD1kQialdSzAb432dtpeJ42ovdo=
6961
github.com/ugorji/go v1.1.7/go.mod h1:kZn38zHttfInRq0xu/PH0az30d+z6vm202qpg1oXVMw=
7062
github.com/ugorji/go/codec v1.1.7 h1:2SvQaVZ1ouYrrKKwoSk2pzd4A9evlKJb9oTL+OaLUSs=
7163
github.com/ugorji/go/codec v1.1.7/go.mod h1:Ax+UKWsSmolVDwsd+7N3ZtXu+yMGCf907BLYF3GoBXY=
72-
github.com/urfave/negroni v1.0.0 h1:kIimOitoypq34K7TG7DUaJ9kq/N4Ofuwi1sjz0KipXc=
73-
github.com/urfave/negroni v1.0.0/go.mod h1:Meg73S6kFm/4PpbYdq35yYWoCZ9mS/YSx+lKnmiohz4=
7464
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
75-
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9 h1:psW17arqaxU48Z5kZ0CQnkZWQJsqcURM6tKiBApRjXI=
7665
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
77-
golang.org/x/net v0.0.0-20190311183353-d8887717615a/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
66+
golang.org/x/crypto v0.0.0-20210513164829-c07d793c2f9a h1:kr2P4QFmQr29mSLA43kwrOcgcReGTfbE9N577tCTuBc=
67+
golang.org/x/crypto v0.0.0-20210513164829-c07d793c2f9a/go.mod h1:P+XmwS30IXTQdn5tA2iutPOUgjI07+tq3H3K9MVA1s8=
7868
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
69+
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
7970
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
8071
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
8172
golang.org/x/sys v0.0.0-20190813064441-fde4db37ae7a/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
82-
golang.org/x/sys v0.0.0-20200116001909-b77594299b42 h1:vEOn+mP2zCOVzKckCZy6YsCtDblrpj/w7B9nxGNELpg=
8373
golang.org/x/sys v0.0.0-20200116001909-b77594299b42/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
74+
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68 h1:nxC68pudNYkKU6jWhgrqdreuFiOQWj1Fs7T3VrH4Pjw=
75+
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
76+
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
8477
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
8578
golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk=
79+
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
8680
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
87-
golang.org/x/tools v0.0.0-20190328211700-ab21143f2384/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs=
81+
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
8882
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
8983
gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127 h1:qIbj1fsPNlZgppZ+VLlY7N33q108Sa+fhmuc+sWQYwY=
9084
gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
9185
gopkg.in/go-playground/assert.v1 v1.2.1/go.mod h1:9RXL0bg/zibRAgZUYszZSwO/z8Y/a8bDuhia5mkpMnE=
9286
gopkg.in/go-playground/validator.v9 v9.29.1/go.mod h1:+c9/zcJMFNgbLvly1L1V+PpxWdVbfP1avr/N00E2vyQ=
87+
gopkg.in/square/go-jose.v2 v2.5.1 h1:7odma5RETjNHWJnR32wx8t+Io4djHE1PqxCFx3iiZ2w=
88+
gopkg.in/square/go-jose.v2 v2.5.1/go.mod h1:M9dMgbHiYLoDGQrXy7OpJDJWiKiU//h+vD76mk0e1AI=
9389
gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
9490
gopkg.in/yaml.v2 v2.2.8 h1:obN1ZagJSUGI0Ek/LBmuj4SNLPfIny3KsKFopxRdj10=
9591
gopkg.in/yaml.v2 v2.2.8/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
92+
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c h1:dUUwHk2QECo/6vqA44rthZ8ie2QXMNeKRTHCNY2nXvo=
93+
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=

01-Authorization-RS256/middleware/jwt.go

Lines changed: 99 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -1,73 +1,128 @@
11
package middleware
22

33
import (
4+
"context"
45
"encoding/json"
56
"errors"
7+
"fmt"
8+
"log"
69
"net/http"
710
"os"
11+
"strings"
812

913
"github.com/auth0/go-jwt-middleware"
10-
"github.com/form3tech-oss/jwt-go"
14+
"github.com/auth0/go-jwt-middleware/validate/jwt-go"
1115
"github.com/gin-gonic/gin"
16+
"github.com/golang-jwt/jwt"
1217
)
1318

19+
const signatureAlgorithm = "RS256"
20+
21+
// Ensure our CustomClaims implement the jwtgo.CustomClaims interface.
22+
var _ jwtgo.CustomClaims = &CustomClaims{}
23+
24+
// CustomClaims holds our custom claims for the *jwt.Token.
25+
type CustomClaims struct {
26+
Scope string `json:"scope"`
27+
jwt.StandardClaims
28+
}
29+
30+
// Validate our *CustomClaims.
31+
func (c CustomClaims) Validate(_ context.Context) error {
32+
expectedAudience := os.Getenv("AUTH0_AUDIENCE")
33+
if c.Audience != expectedAudience {
34+
return fmt.Errorf("token claims validation failed: unexpected audience %q", c.Audience)
35+
}
36+
37+
expectedIssuer := "https://" + os.Getenv("AUTH0_DOMAIN") + "/"
38+
if c.Issuer != expectedIssuer {
39+
return fmt.Errorf("token claims validation failed: unexpected issuer %q", c.Issuer)
40+
}
41+
42+
return nil
43+
}
44+
45+
// HasScope checks whether our claims have a specific scope.
46+
func (c CustomClaims) HasScope(expectedScope string) bool {
47+
result := strings.Split(c.Scope, " ")
48+
for i := range result {
49+
if result[i] == expectedScope {
50+
return true
51+
}
52+
}
53+
54+
return false
55+
}
56+
1457
// EnsureValidToken is a gin.HandlerFunc middleware that will check the validity of our JWT.
1558
func EnsureValidToken() gin.HandlerFunc {
16-
var jwtMiddleware = jwtmiddleware.New(jwtmiddleware.Options{
17-
ValidationKeyGetter: func(token *jwt.Token) (interface{}, error) {
18-
// Verify 'aud' claim
19-
aud := os.Getenv("AUTH0_AUDIENCE")
20-
checkAud := token.Claims.(jwt.MapClaims).VerifyAudience(aud, false)
21-
if !checkAud {
22-
return token, errors.New("invalid audience")
23-
}
24-
25-
// Verify 'iss' claim
26-
iss := "https://" + os.Getenv("AUTH0_DOMAIN") + "/"
27-
checkIss := token.Claims.(jwt.MapClaims).VerifyIssuer(iss, false)
28-
if !checkIss {
29-
return token, errors.New("invalid issuer")
30-
}
31-
32-
cert, err := getPemCert(token)
33-
if err != nil {
34-
return token, err
35-
}
36-
37-
return jwt.ParseRSAPublicKeyFromPEM([]byte(cert))
38-
},
39-
SigningMethod: jwt.SigningMethodRS256,
40-
})
59+
keyFunc := func(token *jwt.Token) (interface{}, error) {
60+
certificate, err := getPEMCertificate(token)
61+
if err != nil {
62+
return token, err
63+
}
64+
65+
return jwt.ParseRSAPublicKeyFromPEM([]byte(certificate))
66+
}
67+
68+
customClaims := func() jwtgo.CustomClaims {
69+
return &CustomClaims{}
70+
}
71+
72+
validator, err := jwtgo.New(
73+
keyFunc,
74+
signatureAlgorithm,
75+
jwtgo.WithCustomClaims(customClaims),
76+
)
77+
if err != nil {
78+
log.Fatalf("Failed to set up the jwt validator")
79+
}
80+
81+
m := jwtmiddleware.New(validator.ValidateToken)
4182

4283
return func(ctx *gin.Context) {
43-
if err := jwtMiddleware.CheckJWT(ctx.Writer, ctx.Request); err != nil {
44-
ctx.AbortWithStatus(http.StatusUnauthorized)
84+
var encounteredError = true
85+
var handler http.HandlerFunc = func(w http.ResponseWriter, r *http.Request) {
86+
encounteredError = false
87+
ctx.Request = r
88+
ctx.Next()
89+
}
90+
91+
m.CheckJWT(handler).ServeHTTP(ctx.Writer, ctx.Request)
92+
93+
if encounteredError {
94+
ctx.AbortWithStatusJSON(
95+
http.StatusUnauthorized,
96+
map[string]string{"message": "Failed to validate JWT."},
97+
)
4598
}
4699
}
47100
}
48101

49-
type Jwks struct {
50-
Keys []JSONWebKeys `json:"keys"`
51-
}
102+
type (
103+
jwks struct {
104+
Keys []jsonWebKeys `json:"keys"`
105+
}
52106

53-
type JSONWebKeys struct {
54-
Kty string `json:"kty"`
55-
Kid string `json:"kid"`
56-
Use string `json:"use"`
57-
N string `json:"n"`
58-
E string `json:"e"`
59-
X5c []string `json:"x5c"`
60-
}
107+
jsonWebKeys struct {
108+
Kty string `json:"kty"`
109+
Kid string `json:"kid"`
110+
Use string `json:"use"`
111+
N string `json:"n"`
112+
E string `json:"e"`
113+
X5c []string `json:"x5c"`
114+
}
115+
)
61116

62-
func getPemCert(token *jwt.Token) (string, error) {
63-
resp, err := http.Get("https://" + os.Getenv("AUTH0_DOMAIN") + "/.well-known/jwks.json")
117+
func getPEMCertificate(token *jwt.Token) (string, error) {
118+
response, err := http.Get("https://" + os.Getenv("AUTH0_DOMAIN") + "/.well-known/jwks.json")
64119
if err != nil {
65120
return "", err
66121
}
67-
defer resp.Body.Close()
122+
defer response.Body.Close()
68123

69-
var jwks Jwks
70-
if err = json.NewDecoder(resp.Body).Decode(&jwks); err != nil {
124+
var jwks jwks
125+
if err = json.NewDecoder(response.Body).Decode(&jwks); err != nil {
71126
return "", err
72127
}
73128

01-Authorization-RS256/router/router.go

Lines changed: 3 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,8 @@ package router
22

33
import (
44
"net/http"
5-
"strings"
65

7-
"github.com/form3tech-oss/jwt-go"
6+
"github.com/auth0/go-jwt-middleware"
87
"github.com/gin-contrib/cors"
98
"github.com/gin-gonic/gin"
109

@@ -49,10 +48,9 @@ func New() *gin.Engine {
4948
"/api/private-scoped",
5049
middleware.EnsureValidToken(),
5150
func(ctx *gin.Context) {
52-
token := ctx.Request.Context().Value("user").(*jwt.Token)
51+
claims := ctx.Request.Context().Value(jwtmiddleware.ContextKey{}).(*middleware.CustomClaims)
5352

54-
hasScope := checkScope("read:messages", token)
55-
if !hasScope {
53+
if !claims.HasScope("read:messages") {
5654
response := map[string]string{"message": "Insufficient scope."}
5755
ctx.JSON(http.StatusForbidden, response)
5856
return
@@ -67,25 +65,3 @@ func New() *gin.Engine {
6765

6866
return router
6967
}
70-
71-
func checkScope(scope string, token *jwt.Token) bool {
72-
claims, ok := token.Claims.(jwt.MapClaims)
73-
if !ok {
74-
return false
75-
}
76-
77-
const scopeKey = "scope"
78-
tokenScope, ok := claims[scopeKey].(string)
79-
if !ok {
80-
return false
81-
}
82-
83-
result := strings.Split(tokenScope, " ")
84-
for i := range result {
85-
if result[i] == scope {
86-
return true
87-
}
88-
}
89-
90-
return false
91-
}

README.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,5 @@
11
# Auth0 Golang API Samples
22

3-
> :warning: **Important security note:** This solution uses a 3rd party library with an unresolved [security issue](https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-26160). Please review the details of the vulnerability, including any of the documented mitigations, before implementing the solution.
4-
53
[![CircleCI](https://img.shields.io/circleci/project/github/auth0-samples/auth0-golang-api-samples.svg?style=flat-square)](https://circleci.com/gh/auth0-samples/auth0-golang-api-samples/tree/master)
64

75
These samples demonstrate how to create an API with Go which only permits access to resources if a valid **access token** is included. This verification is done by validating the signature and claims in a JSON Web Token (JWT) signed by Auth0.

0 commit comments

Comments
 (0)