import * as express from 'express'
import * as OAuthServer from 'express-oauth-server'
-import 'express-validator'
-import { OAUTH_LIFETIME } from '../initializers'
+import { OAUTH_LIFETIME } from '../initializers/constants'
import { logger } from '../helpers/logger'
+import { Socket } from 'socket.io'
+import { getAccessToken } from '../lib/oauth-model'
const oAuthServer = new OAuthServer({
useErrorHandler: true,
})
}
+function authenticateSocket (socket: Socket, next: (err?: any) => void) {
+ const accessToken = socket.handshake.query.accessToken
+
+ logger.debug('Checking socket access token %s.', accessToken)
+
+ if (!accessToken) return next(new Error('No access token provided'))
+
+ getAccessToken(accessToken)
+ .then(tokenDB => {
+ const now = new Date()
+
+ if (!tokenDB || tokenDB.accessTokenExpiresAt < now || tokenDB.refreshTokenExpiresAt < now) {
+ return next(new Error('Invalid access token.'))
+ }
+
+ socket.handshake.query.user = tokenDB.User
+
+ return next()
+ })
+}
+
function authenticatePromiseIfNeeded (req: express.Request, res: express.Response) {
return new Promise(resolve => {
// Already authenticated? (or tried to)
export {
authenticate,
+ authenticateSocket,
authenticatePromiseIfNeeded,
optionalAuthenticate,
token