Files
DarkflameServer/dDashboardServer/auth/RequireAuthMiddleware.h
Aaron Kimbrell 3f2a9cc5b0 feat(dashboard): scoped API keys with rate limits and quotas
Bearer keys (dlk_...) are checked per request against their owner's
current account (ban, lock, demotion, sign out everywhere stop or narrow
them at once) and their scope: permission routes need the permission in
scope, read-only keys only read, level-only routes need an all-permission
key, and session-only paths (sign-in, password, 2FA, key management)
are never reachable with a key. Per-key rate limit and daily quota with
429 and X-RateLimit/X-Quota/Retry-After headers; usage is written in
batches every minute. WebSocket subscriptions honour the scope too.

Routes to list, make, rotate and revoke keys; staff with
api_keys_manage can see and revoke others' keys under the rank rules.
POST /api/auth/token now makes an all-permission key. Audit entries for
create/rotate/revoke/denied, and actions done with a key are attributed
to "user (key name)".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 22:31:03 -05:00

54 lines
2.2 KiB
C++

#ifndef __REQUIREAUTHMIDDLEWARE_H__
#define __REQUIREAUTHMIDDLEWARE_H__
#include <memory>
#include <cstdint>
#include <functional>
#include <string>
#include "IHTTPMiddleware.h"
/**
* RequireAuthMiddleware: Enforces authentication on protected routes
*
* Returns 401 Unauthorized if user is not authenticated
* Returns 403 Forbidden if user's GM level is below minimum required
*/
class RequireAuthMiddleware final : public IHTTPMiddleware {
public:
/**
* @param minGmLevel Minimum GM level required to access this route
* 0 = any authenticated user, higher numbers = GM-only
*/
explicit RequireAuthMiddleware(uint8_t minGmLevel = 0);
// The required level is looked up on every request (a permission that can be changed while running)
explicit RequireAuthMiddleware(std::function<uint8_t()> requiredLevel);
// A route guarded by a named permission: an API key must also have it in its scope
RequireAuthMiddleware(std::function<uint8_t()> requiredLevel, std::string permission);
~RequireAuthMiddleware() override = default;
bool Process(HTTPContext& context, HTTPReply& reply) override;
// Whether a GM level may use the API (requests signed in with a token in the Authorization header rather than
// the browser's cookie). Set by the dashboard from its api_access permission; unset allows everyone.
static void SetApiAccessCheck(std::function<bool(uint8_t gmLevel)> check);
// Renders the page a signed-in account gets when it may not open a page (not /api/); unset replies with JSON
static void SetForbiddenPage(std::function<void(const HTTPContext& context, HTTPReply& reply)> render);
// The route only reads, although it may be a POST (DataTables and lookups send their query as a body): read-only
// API keys may use it
void SetReadsOnly() { readsOnly = true; }
// Told when an API key is refused a route for its scope or because it is read-only (for the audit log)
static void SetApiKeyDeniedHook(std::function<void(const HTTPContext& context, const std::string& reason)> hook);
std::string GetName() const override { return "RequireAuthMiddleware"; }
private:
std::function<uint8_t()> requiredLevel;
std::string permission;
bool readsOnly{};
};
#endif // !__REQUIREAUTHMIDDLEWARE_H__