From 2bffdcdcf7e40eb432cf26c0451ea18b2292561b Mon Sep 17 00:00:00 2001 From: Zeni Kim Date: Mon, 30 Sep 2024 09:12:38 -0500 Subject: [PATCH 1/3] start cookie session --- context.go | 9 ++ cookies.go | 238 ++++++++++++++++++++++++++++++++++ core.go | 8 +- template/components/head.html | 10 +- template/components/page.html | 17 +++ 5 files changed, 275 insertions(+), 7 deletions(-) create mode 100644 cookies.go create mode 100644 template/components/page.html diff --git a/context.go b/context.go index 30c750b..cc622be 100644 --- a/context.go +++ b/context.go @@ -72,6 +72,15 @@ func (c *Context) GetHeader(key string) string { return c.Request.httpRequest.Header.Get(key) } +func (c *Context) GetCookie() (UserCookie, error) { + + user, err := GetCookie(c.Request.httpRequest) + if err != nil { + return user, err + } + return user, nil +} + func (c *Context) GetUploadedFile(name string) *UploadedFileInfo { file, fileHeader, err := c.Request.httpRequest.FormFile(name) if err != nil { diff --git a/cookies.go b/cookies.go new file mode 100644 index 0000000..87503e7 --- /dev/null +++ b/cookies.go @@ -0,0 +1,238 @@ +// Copyright (c) 2024 Zeni Kim +// Use of this source code is governed by MIT-style +// license that can be found in the LICENSE file. + +package core + +import ( + "crypto/aes" + "crypto/cipher" + + "bytes" + "crypto/rand" + "encoding/base64" + "encoding/gob" + "encoding/hex" + "errors" + "fmt" + "io" + "net/http" + "strings" +) + +var ( + ErrValueTooLong = errors.New("cookie value too long") + ErrInvalidValue = errors.New("invalid cookie value") +) + +// Declare the User type. +type UserCookie struct { + Email string + Token string +} + +var secretcookie []byte + +func GetCookie(r *http.Request) (UserCookie, error) { + + var err error + // Create a new instance of a User type. + var user UserCookie + + secretcookie, err = hex.DecodeString("13d6b4dff8f84a10851021ec8608f814570d562c92fe6b5ec4c9f595bcb3234b") + if err != nil { + return user, err + } + + gobEncodedValue, err := CookieReadEncrypted(r, "goffee", secretcookie) + if err != nil { + return user, err + } + + // Create an strings.Reader containing the gob-encoded value. + reader := strings.NewReader(gobEncodedValue) + + // Decode it into the User type. Notice that we need to pass a *pointer* to + // the Decode() target here? + if err := gob.NewDecoder(reader).Decode(&user); err != nil { + return user, err + } + + return user, nil + +} + +func SetCookie(w http.ResponseWriter, email string, token string) error { + // Initialize a User struct containing the data that we want to store in the + // cookie. + var err error + + secretcookie, err = hex.DecodeString("13d6b4dff8f84a10851021ec8608f814570d562c92fe6b5ec4c9f595bcb3234b") + if err != nil { + return err + } + + user := UserCookie{Email: email, Token: token} + + // Initialize a buffer to hold the gob-encoded data. + var buf bytes.Buffer + + // Gob-encode the user data, storing the encoded output in the buffer. + err = gob.NewEncoder(&buf).Encode(&user) + if err != nil { + return err + } + + // Call buf.String() to get the gob-encoded value as a string and set it as + // the cookie value. + cookie := http.Cookie{ + Name: "goffee", + Value: buf.String(), + Path: "/", + MaxAge: 3600, + HttpOnly: true, + Secure: true, + SameSite: http.SameSiteLaxMode, + } + + // Write an encrypted cookie containing the gob-encoded data as normal. + err = CookieWriteEncrypted(w, cookie, secretcookie) + if err != nil { + return err + } + + fmt.Printf("Cookie set %v\n", email) + + return nil +} + +func CookieWrite(w http.ResponseWriter, cookie http.Cookie) error { + // Encode the cookie value using base64. + cookie.Value = base64.URLEncoding.EncodeToString([]byte(cookie.Value)) + + // Check the total length of the cookie contents. Return the ErrValueTooLong + // error if it's more than 4096 bytes. + if len(cookie.String()) > 4096 { + return ErrValueTooLong + } + + // Write the cookie as normal. + http.SetCookie(w, &cookie) + + return nil +} + +func CookieRead(r *http.Request, name string) (string, error) { + // Read the cookie as normal. + cookie, err := r.Cookie(name) + if err != nil { + return "", err + } + + // Decode the base64-encoded cookie value. If the cookie didn't contain a + // valid base64-encoded value, this operation will fail and we return an + // ErrInvalidValue error. + value, err := base64.URLEncoding.DecodeString(cookie.Value) + if err != nil { + return "", ErrInvalidValue + } + + // Return the decoded cookie value. + return string(value), nil +} + +func CookieWriteEncrypted(w http.ResponseWriter, cookie http.Cookie, secretKey []byte) error { + // Create a new AES cipher block from the secret key. + block, err := aes.NewCipher(secretKey) + if err != nil { + return err + } + + // Wrap the cipher block in Galois Counter Mode. + aesGCM, err := cipher.NewGCM(block) + if err != nil { + return err + } + + // Create a unique nonce containing 12 random bytes. + nonce := make([]byte, aesGCM.NonceSize()) + _, err = io.ReadFull(rand.Reader, nonce) + if err != nil { + return err + } + + // Prepare the plaintext input for encryption. Because we want to + // authenticate the cookie name as well as the value, we make this plaintext + // in the format "{cookie name}:{cookie value}". We use the : character as a + // separator because it is an invalid character for cookie names and + // therefore shouldn't appear in them. + plaintext := fmt.Sprintf("%s:%s", cookie.Name, cookie.Value) + + // Encrypt the data using aesGCM.Seal(). By passing the nonce as the first + // parameter, the encrypted data will be appended to the nonce — meaning + // that the returned encryptedValue variable will be in the format + // "{nonce}{encrypted plaintext data}". + encryptedValue := aesGCM.Seal(nonce, nonce, []byte(plaintext), nil) + + // Set the cookie value to the encryptedValue. + cookie.Value = string(encryptedValue) + + // Write the cookie as normal. + return CookieWrite(w, cookie) +} + +func CookieReadEncrypted(r *http.Request, name string, secretKey []byte) (string, error) { + // Read the encrypted value from the cookie as normal. + encryptedValue, err := CookieRead(r, name) + if err != nil { + return "", err + } + + // Create a new AES cipher block from the secret key. + block, err := aes.NewCipher(secretKey) + if err != nil { + return "", err + } + + // Wrap the cipher block in Galois Counter Mode. + aesGCM, err := cipher.NewGCM(block) + if err != nil { + return "", err + } + + // Get the nonce size. + nonceSize := aesGCM.NonceSize() + + // To avoid a potential 'index out of range' panic in the next step, we + // check that the length of the encrypted value is at least the nonce + // size. + if len(encryptedValue) < nonceSize { + return "", ErrInvalidValue + } + + // Split apart the nonce from the actual encrypted data. + nonce := encryptedValue[:nonceSize] + ciphertext := encryptedValue[nonceSize:] + + // Use aesGCM.Open() to decrypt and authenticate the data. If this fails, + // return a ErrInvalidValue error. + plaintext, err := aesGCM.Open(nil, []byte(nonce), []byte(ciphertext), nil) + if err != nil { + return "", ErrInvalidValue + } + + // The plaintext value is in the format "{cookie name}:{cookie value}". We + // use strings.Cut() to split it on the first ":" character. + expectedName, value, ok := strings.Cut(string(plaintext), ":") + if !ok { + return "", ErrInvalidValue + } + + // Check that the cookie name is the expected one and hasn't been changed. + if expectedName != name { + return "", ErrInvalidValue + } + + // Return the plaintext cookie value. + return value, nil +} diff --git a/core.go b/core.go index ba208d3..59691c6 100644 --- a/core.go +++ b/core.go @@ -98,9 +98,7 @@ func (app *App) Run(router *httprouter.Router) { TemplateEnable, _ := strconv.ParseBool(TemplateEnableStr) // if enabled, if TemplateEnable { - // add public path - publicPath := os.Getenv("TEMPLATE_PUBLIC") - router.ServeFiles("/public/*filepath", http.Dir(publicPath)) + router.ServeFiles("/public/*filepath", http.Dir("storage/public")) } useHttpsStr := os.Getenv("App_USE_HTTPS") @@ -183,6 +181,7 @@ func (app *App) RegisterRoutes(routes []Route, router *httprouter.Router) *httpr func (app *App) makeHTTPRouterHandlerFunc(h Controller, ms []Hook) httprouter.Handle { return func(w http.ResponseWriter, r *http.Request, ps httprouter.Params) { + ctx := &Context{ Request: &Request{ httpRequest: r, @@ -206,11 +205,13 @@ func (app *App) makeHTTPRouterHandlerFunc(h Controller, ms []Hook) httprouter.Ha GetEventsManager: resolveEventsManager(), GetLogger: resolveLogger(), } + ctx.prepare(ctx) rhs := app.combHandlers(h, ms) app.prepareChain(rhs) app.t = 0 app.chain.execute(ctx) + for _, header := range ctx.Response.headers { w.Header().Add(header.key, header.val) } @@ -223,6 +224,7 @@ func (app *App) makeHTTPRouterHandlerFunc(h Controller, ms []Hook) httprouter.Ha } else { ct = CONTENT_TYPE_HTML } + w.Header().Add(CONTENT_TYPE, ct) if ctx.Response.statusCode != 0 { w.WriteHeader(ctx.Response.statusCode) diff --git a/template/components/head.html b/template/components/head.html index cecc5ed..68aaca8 100644 --- a/template/components/head.html +++ b/template/components/head.html @@ -1,8 +1,10 @@ {{define "head"}} - - - {{.}} | Goffee - + + + + {{.}} | Goffee + + {{end}} \ No newline at end of file diff --git a/template/components/page.html b/template/components/page.html new file mode 100644 index 0000000..636487b --- /dev/null +++ b/template/components/page.html @@ -0,0 +1,17 @@ + + + + + + + My Website + + + + +
+

Welcome to My Website

+
+ + + \ No newline at end of file From 015e85bf7b20a56381449cbf1ba1b580d3d1d360 Mon Sep 17 00:00:00 2001 From: Zeni Kim Date: Mon, 7 Oct 2024 18:10:04 -0500 Subject: [PATCH 2/3] start theme core templates --- .../components/{button.go => form_button.go} | 2 +- .../{button.html => form_button.html} | 9 +++------ template/components/form_input.go | 12 ++++++++++++ template/components/form_input.html | 15 +++++++++++++++ template/components/page.html | 17 ----------------- template/components/page_card.go | 8 ++++++++ template/components/page_card.html | 11 +++++++++++ template/components/page_footer.html | 6 ++++++ .../components/{head.html => page_head.html} | 3 ++- template/components/page_page.html | 14 ++++++++++++++ template/components/title.go | 5 ----- template/components/title.html | 5 ----- 12 files changed, 72 insertions(+), 35 deletions(-) rename template/components/{button.go => form_button.go} (83%) rename template/components/{button.html => form_button.html} (89%) create mode 100644 template/components/form_input.go create mode 100644 template/components/form_input.html delete mode 100644 template/components/page.html create mode 100644 template/components/page_card.go create mode 100644 template/components/page_card.html create mode 100644 template/components/page_footer.html rename template/components/{head.html => page_head.html} (75%) create mode 100644 template/components/page_page.html delete mode 100644 template/components/title.go delete mode 100644 template/components/title.html diff --git a/template/components/button.go b/template/components/form_button.go similarity index 83% rename from template/components/button.go rename to template/components/form_button.go index 0c52a38..2cfee00 100644 --- a/template/components/button.go +++ b/template/components/form_button.go @@ -1,6 +1,6 @@ package components -type Button struct { +type FormButton struct { Text string Link string Icon string diff --git a/template/components/button.html b/template/components/form_button.html similarity index 89% rename from template/components/button.html rename to template/components/form_button.html index 6590905..5e1d68c 100644 --- a/template/components/button.html +++ b/template/components/form_button.html @@ -1,7 +1,6 @@ -{{define "button"}} - {{if eq .Icon "gear"}} @@ -17,6 +16,4 @@ {{end}} - - {{end}} \ No newline at end of file diff --git a/template/components/form_input.go b/template/components/form_input.go new file mode 100644 index 0000000..0ce7ce4 --- /dev/null +++ b/template/components/form_input.go @@ -0,0 +1,12 @@ +package components + +type FormInput struct { + ID string + Label string + Type string + Placeholder string + Value string + Hint string + Error string + IsDisabled bool +} diff --git a/template/components/form_input.html b/template/components/form_input.html new file mode 100644 index 0000000..b79ae87 --- /dev/null +++ b/template/components/form_input.html @@ -0,0 +1,15 @@ +{{define "form_input"}} +
+ + + {{if ne .Hint ""}}{{.Hint}}{{end}} + {{if ne .Error ""}}
{{.Error}}
{{end}} +
+{{end}} \ No newline at end of file diff --git a/template/components/page.html b/template/components/page.html deleted file mode 100644 index 636487b..0000000 --- a/template/components/page.html +++ /dev/null @@ -1,17 +0,0 @@ - - - - - - - My Website - - - - -
-

Welcome to My Website

-
- - - \ No newline at end of file diff --git a/template/components/page_card.go b/template/components/page_card.go new file mode 100644 index 0000000..7f9b504 --- /dev/null +++ b/template/components/page_card.go @@ -0,0 +1,8 @@ +package components + +type PageCard struct { + CardTitle string + CardSubTitle string + CardBody string + CardLink string +} diff --git a/template/components/page_card.html b/template/components/page_card.html new file mode 100644 index 0000000..9ef8821 --- /dev/null +++ b/template/components/page_card.html @@ -0,0 +1,11 @@ +{{define "page_card"}} +
+
+ {{if .CardTitle}}
{{.CardTitle}}
{{end}} + {{if .CardSubTitle}}
{{.CardSubTitle}}
{{end}} + {{if .CardBody}}

{{.CardBody}}

{{end}} + {{block "page_card_content" .}}{{end}} + {{if .CardLink}}Card link{{end}} +
+
+{{end}} \ No newline at end of file diff --git a/template/components/page_footer.html b/template/components/page_footer.html new file mode 100644 index 0000000..20b7f38 --- /dev/null +++ b/template/components/page_footer.html @@ -0,0 +1,6 @@ +{{define "page_footer"}} +
+ +
+ +{{end}} \ No newline at end of file diff --git a/template/components/head.html b/template/components/page_head.html similarity index 75% rename from template/components/head.html rename to template/components/page_head.html index 68aaca8..e589e84 100644 --- a/template/components/head.html +++ b/template/components/page_head.html @@ -1,4 +1,4 @@ -{{define "head"}} +{{define "page_head"}} @@ -6,5 +6,6 @@ {{.}} | Goffee + {{end}} \ No newline at end of file diff --git a/template/components/page_page.html b/template/components/page_page.html new file mode 100644 index 0000000..2c83582 --- /dev/null +++ b/template/components/page_page.html @@ -0,0 +1,14 @@ + + + {{template "page_head" "Goffee"}} + +
+ {{block "page_content" .}} +
+

Use this file as base inside cup application

+
+ {{end}} + {{template "page_footer"}} +
+ + \ No newline at end of file diff --git a/template/components/title.go b/template/components/title.go deleted file mode 100644 index 0e68b6a..0000000 --- a/template/components/title.go +++ /dev/null @@ -1,5 +0,0 @@ -package components - -type Title struct { - Label string -} diff --git a/template/components/title.html b/template/components/title.html deleted file mode 100644 index eef5bf3..0000000 --- a/template/components/title.html +++ /dev/null @@ -1,5 +0,0 @@ -{{define "title"}} -
-

{{.Label}}

-
-{{end}} \ No newline at end of file From 8f17bf6a8c879a514a2029c4c8c65fce141f6aac Mon Sep 17 00:00:00 2001 From: Zeni Kim Date: Tue, 8 Oct 2024 07:58:42 -0500 Subject: [PATCH 3/3] add form components --- template/components/form_checkbox.go | 14 ++++++++++++++ template/components/form_checkbox.html | 11 +++++++++++ template/components/form_radio.go | 15 +++++++++++++++ template/components/form_radio.html | 11 +++++++++++ template/components/form_select.go | 13 +++++++++++++ template/components/form_select.html | 10 ++++++++++ template/components/form_textarea.go | 7 +++++++ template/components/form_textarea.html | 6 ++++++ 8 files changed, 87 insertions(+) create mode 100644 template/components/form_checkbox.go create mode 100644 template/components/form_checkbox.html create mode 100644 template/components/form_radio.go create mode 100644 template/components/form_radio.html create mode 100644 template/components/form_select.go create mode 100644 template/components/form_select.html create mode 100644 template/components/form_textarea.go create mode 100644 template/components/form_textarea.html diff --git a/template/components/form_checkbox.go b/template/components/form_checkbox.go new file mode 100644 index 0000000..819da82 --- /dev/null +++ b/template/components/form_checkbox.go @@ -0,0 +1,14 @@ +package components + +type FormCheckbox struct { + Label string + AllCheckbox []FormCheckboxItem +} + +type FormCheckboxItem struct { + ID string + Name string + Value string + Label string + IsChecked bool +} diff --git a/template/components/form_checkbox.html b/template/components/form_checkbox.html new file mode 100644 index 0000000..9a8d845 --- /dev/null +++ b/template/components/form_checkbox.html @@ -0,0 +1,11 @@ +{{define "form_checkbox"}} +
+ + {{range $options := .AllCheckbox}} +
+ + +
+ {{end}} +
+{{end}} \ No newline at end of file diff --git a/template/components/form_radio.go b/template/components/form_radio.go new file mode 100644 index 0000000..e8e923c --- /dev/null +++ b/template/components/form_radio.go @@ -0,0 +1,15 @@ +package components + +type FormRadio struct { + Label string + AllRadios []FormRadioItem +} + +type FormRadioItem struct { + ID string + Name string + Value string + Label string + IsDisabled bool + IsChecked bool +} diff --git a/template/components/form_radio.html b/template/components/form_radio.html new file mode 100644 index 0000000..a0c26cd --- /dev/null +++ b/template/components/form_radio.html @@ -0,0 +1,11 @@ +{{define "form_radio"}} +
+ + {{range $options := .AllRadios}} +
+ + +
+ {{end}} +
+{{end}} \ No newline at end of file diff --git a/template/components/form_select.go b/template/components/form_select.go new file mode 100644 index 0000000..db94fe3 --- /dev/null +++ b/template/components/form_select.go @@ -0,0 +1,13 @@ +package components + +type FormSelect struct { + ID string + SelectedOption FormSelectOption + Label string + AllOptions []FormSelectOption +} + +type FormSelectOption struct { + Value string + Caption string +} diff --git a/template/components/form_select.html b/template/components/form_select.html new file mode 100644 index 0000000..6317e6b --- /dev/null +++ b/template/components/form_select.html @@ -0,0 +1,10 @@ +{{define "form_select"}} +
+ + +
+{{end}} \ No newline at end of file diff --git a/template/components/form_textarea.go b/template/components/form_textarea.go new file mode 100644 index 0000000..8fbaf51 --- /dev/null +++ b/template/components/form_textarea.go @@ -0,0 +1,7 @@ +package components + +type FormTextarea struct { + ID string + Label string + AllOptions []FormSelectOption +} diff --git a/template/components/form_textarea.html b/template/components/form_textarea.html new file mode 100644 index 0000000..5372a42 --- /dev/null +++ b/template/components/form_textarea.html @@ -0,0 +1,6 @@ +{{define "form_textarea"}} +
+ + +
+{{end}} \ No newline at end of file