-
Notifications
You must be signed in to change notification settings - Fork 0
/
login.go
57 lines (51 loc) · 1.21 KB
/
login.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
package main
import (
"fmt"
"net/http"
"net/url"
"time"
)
func handleLogin(w http.ResponseWriter, r *http.Request, ctx *context) {
valid, user := useToken(ctx.cookie, time.Now())
if !valid {
callback := fmt.Sprintf("%v/callback?%v=%v&%v=%v",
config.pathPrefix,
config.queryRole, url.QueryEscape(ctx.role),
config.queryRedirect, url.QueryEscape(ctx.redirect))
fmt.Fprint(w, loginPageStart)
fmt.Fprintf(w, unauthenticatedBody, config.botName, callback)
fmt.Fprint(w, loginPageEnd)
return
}
access, ok := config.roleBindings[ctx.role][user]
if !ok || !access {
fmt.Fprint(w, loginPageStart)
fmt.Fprintf(w, unauthorizedBody, user)
fmt.Fprint(w, loginPageEnd)
return
}
http.Redirect(w, r, ctx.redirect, http.StatusFound)
}
const loginPageStart = `
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
</head>
<body>
`
const loginPageEnd = `
</body>
</html>
`
const unauthenticatedBody = `
<script async src="https://telegram.org/js/telegram-widget.js"
data-telegram-login="%v"
data-size="large"
data-auth-url="%v">
</script>
`
const unauthorizedBody = `
You have logged in as @%v, but are not authorized to access this resource.
`