mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-02 10:53:44 +00:00
The NexusDashboard-parity dashboard (dDashboardServer) and everything built on it on the experimental branch: accounts, characters, properties and moderation tools, permissions shared with in-game slash commands, economy reports, World 3D and property 3D views with client scenery, scheduled events (features, vanity changes, live events, announcements, restarts), vanity files and events, the CDClient browser, the message inspector with saved captures, chat filter tools, community challenges, live ops, the AI moderator helper, and the server-side changes they need. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
74 lines
2.3 KiB
C++
74 lines
2.3 KiB
C++
#pragma once
|
|
|
|
#include <string>
|
|
#include <ctime>
|
|
#include "json_fwd.hpp"
|
|
|
|
/**
|
|
* JWT Token utilities for dashboard authentication
|
|
* Provides secure token generation, validation, and parsing
|
|
*/
|
|
namespace JWTUtils {
|
|
/**
|
|
* JWT payload structure
|
|
*/
|
|
struct JWTPayload {
|
|
std::string username{};
|
|
uint8_t gmLevel{0};
|
|
bool rememberMe{false};
|
|
int64_t issuedAt{0};
|
|
int64_t expiresAt{0};
|
|
uint32_t accountId{0}; // 0 in tokens made without one (GenerateToken)
|
|
};
|
|
|
|
/**
|
|
* Generate a new JWT token
|
|
* @param username The username to encode in the token
|
|
* @param gmLevel The GM level of the user
|
|
* @param rememberMe If true, extends token expiration to 30 days; otherwise 24 hours
|
|
* @return Signed JWT token string
|
|
*/
|
|
std::string GenerateToken(const std::string& username, uint8_t gmLevel, bool rememberMe = false);
|
|
|
|
/**
|
|
* Generate a new JWT token with an explicit lifetime, e.g. for API clients
|
|
*/
|
|
std::string GenerateToken(const std::string& username, uint8_t gmLevel, int64_t lifetimeSeconds, bool rememberMe);
|
|
|
|
// Session and API tokens. They also carry the account ID, so a token can never sign in to a different account
|
|
// that later gets the same username. lifetimeSeconds 0: 30 days with rememberMe, else 1 day.
|
|
std::string GenerateSessionToken(uint32_t accountId, const std::string& username, uint8_t gmLevel, bool rememberMe, int64_t lifetimeSeconds = 0);
|
|
|
|
/**
|
|
* Validate and decode a JWT token
|
|
* @param token The JWT token to validate
|
|
* @param payload Output parameter for the decoded payload
|
|
* @return true if token is valid and not expired, false otherwise
|
|
*/
|
|
bool ValidateToken(const std::string& token, JWTPayload& payload);
|
|
|
|
/**
|
|
* Check if a token is expired
|
|
* @param expiresAt Expiration timestamp
|
|
* @return true if token is expired
|
|
*/
|
|
bool IsTokenExpired(int64_t expiresAt);
|
|
|
|
/**
|
|
* Set the JWT secret key (must be called once at startup)
|
|
* @param secret The secret key for signing tokens
|
|
*/
|
|
void SetSecretKey(const std::string& secret);
|
|
|
|
/**
|
|
* @return true once a secret has been configured; no tokens are issued or accepted before that
|
|
*/
|
|
bool HasSecretKey();
|
|
|
|
/**
|
|
* Generate a random hex secret suitable for SetSecretKey
|
|
* @return The secret, or an empty string if the system RNG failed
|
|
*/
|
|
std::string GenerateSecret();
|
|
}
|