mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-05 04:13:44 +00:00
feat(dashboard): scoped API keys with rate limits and quotas
Bearer keys (dlk_...) are checked per request against their owner's current account (ban, lock, demotion, sign out everywhere stop or narrow them at once) and their scope: permission routes need the permission in scope, read-only keys only read, level-only routes need an all-permission key, and session-only paths (sign-in, password, 2FA, key management) are never reachable with a key. Per-key rate limit and daily quota with 429 and X-RateLimit/X-Quota/Retry-After headers; usage is written in batches every minute. WebSocket subscriptions honour the scope too. Routes to list, make, rotate and revoke keys; staff with api_keys_manage can see and revoke others' keys under the rank rules. POST /api/auth/token now makes an all-permission key. Audit entries for create/rotate/revoke/denied, and actions done with a key are attributed to "user (key name)". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
#include "AuthTokenHandler.h"
|
||||
#include "ApiKeyService.h"
|
||||
#include "DashboardAuthService.h"
|
||||
#include "Game.h"
|
||||
#include "Logger.h"
|
||||
@@ -77,6 +78,13 @@ bool AuthTokenHandler::ProcessHTTPContext(HTTPContext& context, HTTPReply& reply
|
||||
const auto token = ExtractToken(context.GetHeader("Cookie"), context.GetHeader("Authorization"), source);
|
||||
if (token.empty()) return true;
|
||||
|
||||
// API keys: their scope and limits are checked here; a key over its limits is refused outright
|
||||
if (source == eTokenSource::HEADER && ApiKeyService::LooksLikeKey(token)) {
|
||||
const auto keyResult = ApiKeyService::Authenticate(token, context, reply);
|
||||
if (keyResult == ApiKeyService::eResult::INVALID) LOG_DEBUG("API key validation failed from %s", context.clientIP.c_str());
|
||||
return keyResult != ApiKeyService::eResult::REFUSED;
|
||||
}
|
||||
|
||||
const auto result = ValidateToken(token);
|
||||
if (!result.isValid) {
|
||||
LOG_DEBUG("Authentication token validation failed: %s", result.errorMessage.c_str());
|
||||
|
||||
Reference in New Issue
Block a user