mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-02 10:53:44 +00:00
Bearer keys (dlk_...) are checked per request against their owner's current account (ban, lock, demotion, sign out everywhere stop or narrow them at once) and their scope: permission routes need the permission in scope, read-only keys only read, level-only routes need an all-permission key, and session-only paths (sign-in, password, 2FA, key management) are never reachable with a key. Per-key rate limit and daily quota with 429 and X-RateLimit/X-Quota/Retry-After headers; usage is written in batches every minute. WebSocket subscriptions honour the scope too. Routes to list, make, rotate and revoke keys; staff with api_keys_manage can see and revoke others' keys under the rank rules. POST /api/auth/token now makes an all-permission key. Audit entries for create/rotate/revoke/denied, and actions done with a key are attributed to "user (key name)". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
22 lines
700 B
C++
22 lines
700 B
C++
#pragma once
|
|
|
|
#include <cstdint>
|
|
#include <string>
|
|
|
|
struct HTTPContext;
|
|
|
|
/**
|
|
* Dashboard API keys: each person makes, rotates and revokes their own keys on their account page (with a signed-in
|
|
* browser session, never with a key). A key's scope is chosen from the permissions its maker has; staff with
|
|
* api_keys_manage can see and revoke other accounts' keys, following the rank rules.
|
|
*/
|
|
namespace ApiKeyRoutes {
|
|
void RegisterRoutes();
|
|
|
|
/**
|
|
* Make a key with all of its maker's permissions (what POST /api/auth/token hands out, as the old API tokens did).
|
|
* @return The key, shown once
|
|
*/
|
|
std::string CreateFullKey(const HTTPContext& context, const std::string& name, int64_t days);
|
|
}
|