Files
DarkflameServer/dDashboardServer/auth/AuthTokenHandler.h
Aaron Kimbrell e213a7aeff feat: web dashboard and playground work
The NexusDashboard-parity dashboard (dDashboardServer) and everything built on it on the experimental branch:
accounts, characters, properties and moderation tools, permissions shared with in-game slash commands, economy
reports, World 3D and property 3D views with client scenery, scheduled events (features, vanity changes, live
events, announcements, restarts), vanity files and events, the CDClient browser, the message inspector with saved
captures, chat filter tools, community challenges, live ops, the AI moderator helper, and the server-side changes
they need.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 22:30:43 -05:00

63 lines
1.9 KiB
C++

#pragma once
#include <string>
#include <cstdint>
/**
* Centralized authentication token handler
* Consolidates token extraction and validation for HTTP routes and WebSocket connections
*/
class AuthTokenHandler {
public:
enum class eTokenSource : uint8_t {
NONE,
HEADER, // Authorization header, used by API clients
COOKIE // HttpOnly session cookie, used by the browser dashboard
};
struct TokenValidationResult {
bool isValid{false};
std::string username{};
uint32_t accountId{0};
uint8_t gmLevel{0};
std::string errorMessage{};
};
static constexpr const char* COOKIE_NAME = "dashboardToken";
/**
* Extract a named cookie value from a Cookie header
* @return The URL-decoded value, or an empty string if not present
*/
static std::string ExtractCookie(const std::string& cookieHeader, const std::string& name);
/**
* Extract token from Authorization header
* Supports "Bearer <token>" and "Token <token>"
*/
static std::string ExtractTokenFromAuthHeader(const std::string& authHeader);
/**
* Extract token from the Authorization header, falling back to the session cookie.
* Tokens are never read from the query string since URLs end up in logs and browser history.
*/
static std::string ExtractToken(const std::string& cookieHeader, const std::string& authHeader, eTokenSource& source);
/**
* Validate a token against its signature and the current state of the account in the database
*/
static TokenValidationResult ValidateToken(const std::string& token);
/**
* Process authentication for HTTP middleware use
* Populates the HTTPContext auth fields if a valid token is present; never rejects on its own
*/
static bool ProcessHTTPContext(class HTTPContext& context, class HTTPReply& reply);
/**
* Build Set-Cookie header values for the session cookie
*/
static std::string BuildSessionCookie(const std::string& token, bool rememberMe, bool secure);
static std::string BuildClearSessionCookie(bool secure);
};