mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: use JWT ticket to avoid DB queries on apps (#6148)
Issue a JWT ticket on the first request with a short expiry that contains details about which workspace/agent/app combo the ticket is valid for.
This commit is contained in:
@@ -22,7 +22,9 @@ func StripCoderCookies(header string) string {
|
||||
name, _, _ := strings.Cut(part, "=")
|
||||
if name == codersdk.SessionTokenCookie ||
|
||||
name == codersdk.OAuth2StateCookie ||
|
||||
name == codersdk.OAuth2RedirectCookie {
|
||||
name == codersdk.OAuth2RedirectCookie ||
|
||||
name == codersdk.DevURLSessionTokenCookie ||
|
||||
name == codersdk.DevURLSessionTicketCookie {
|
||||
continue
|
||||
}
|
||||
cookies = append(cookies, part)
|
||||
|
||||
+3
-26
@@ -4,7 +4,6 @@ import (
|
||||
"fmt"
|
||||
"net"
|
||||
"regexp"
|
||||
"strconv"
|
||||
"strings"
|
||||
|
||||
"golang.org/x/xerrors"
|
||||
@@ -23,9 +22,7 @@ var (
|
||||
|
||||
// ApplicationURL is a parsed application URL hostname.
|
||||
type ApplicationURL struct {
|
||||
// Only one of AppSlug or Port will be set.
|
||||
AppSlug string
|
||||
Port uint16
|
||||
AppSlugOrPort string
|
||||
AgentName string
|
||||
WorkspaceName string
|
||||
Username string
|
||||
@@ -34,12 +31,7 @@ type ApplicationURL struct {
|
||||
// String returns the application URL hostname without scheme. You will likely
|
||||
// want to append a period and the base hostname.
|
||||
func (a ApplicationURL) String() string {
|
||||
appSlugOrPort := a.AppSlug
|
||||
if a.Port != 0 {
|
||||
appSlugOrPort = strconv.Itoa(int(a.Port))
|
||||
}
|
||||
|
||||
return fmt.Sprintf("%s--%s--%s--%s", appSlugOrPort, a.AgentName, a.WorkspaceName, a.Username)
|
||||
return fmt.Sprintf("%s--%s--%s--%s", a.AppSlugOrPort, a.AgentName, a.WorkspaceName, a.Username)
|
||||
}
|
||||
|
||||
// ParseSubdomainAppURL parses an ApplicationURL from the given subdomain. If
|
||||
@@ -60,29 +52,14 @@ func ParseSubdomainAppURL(subdomain string) (ApplicationURL, error) {
|
||||
}
|
||||
matchGroup := matches[0]
|
||||
|
||||
appSlug, port := AppSlugOrPort(matchGroup[appURL.SubexpIndex("AppSlug")])
|
||||
return ApplicationURL{
|
||||
AppSlug: appSlug,
|
||||
Port: port,
|
||||
AppSlugOrPort: matchGroup[appURL.SubexpIndex("AppSlug")],
|
||||
AgentName: matchGroup[appURL.SubexpIndex("AgentName")],
|
||||
WorkspaceName: matchGroup[appURL.SubexpIndex("WorkspaceName")],
|
||||
Username: matchGroup[appURL.SubexpIndex("Username")],
|
||||
}, nil
|
||||
}
|
||||
|
||||
// AppSlugOrPort takes a string and returns either the input string or a port
|
||||
// number.
|
||||
func AppSlugOrPort(val string) (string, uint16) {
|
||||
port, err := strconv.ParseUint(val, 10, 16)
|
||||
if err != nil || port == 0 {
|
||||
port = 0
|
||||
} else {
|
||||
val = ""
|
||||
}
|
||||
|
||||
return val, uint16(port)
|
||||
}
|
||||
|
||||
// HostnamesMatch returns true if the hostnames are equal, disregarding
|
||||
// capitalization, extra leading or trailing periods, and ports.
|
||||
func HostnamesMatch(a, b string) bool {
|
||||
|
||||
@@ -25,8 +25,7 @@ func TestApplicationURLString(t *testing.T) {
|
||||
{
|
||||
Name: "AppName",
|
||||
URL: httpapi.ApplicationURL{
|
||||
AppSlug: "app",
|
||||
Port: 0,
|
||||
AppSlugOrPort: "app",
|
||||
AgentName: "agent",
|
||||
WorkspaceName: "workspace",
|
||||
Username: "user",
|
||||
@@ -36,26 +35,13 @@ func TestApplicationURLString(t *testing.T) {
|
||||
{
|
||||
Name: "Port",
|
||||
URL: httpapi.ApplicationURL{
|
||||
AppSlug: "",
|
||||
Port: 8080,
|
||||
AppSlugOrPort: "8080",
|
||||
AgentName: "agent",
|
||||
WorkspaceName: "workspace",
|
||||
Username: "user",
|
||||
},
|
||||
Expected: "8080--agent--workspace--user",
|
||||
},
|
||||
{
|
||||
Name: "Both",
|
||||
URL: httpapi.ApplicationURL{
|
||||
AppSlug: "app",
|
||||
Port: 8080,
|
||||
AgentName: "agent",
|
||||
WorkspaceName: "workspace",
|
||||
Username: "user",
|
||||
},
|
||||
// Prioritizes port over app name.
|
||||
Expected: "8080--agent--workspace--user",
|
||||
},
|
||||
}
|
||||
|
||||
for _, c := range testCases {
|
||||
@@ -111,8 +97,7 @@ func TestParseSubdomainAppURL(t *testing.T) {
|
||||
Name: "AppName--Agent--Workspace--User",
|
||||
Subdomain: "app--agent--workspace--user",
|
||||
Expected: httpapi.ApplicationURL{
|
||||
AppSlug: "app",
|
||||
Port: 0,
|
||||
AppSlugOrPort: "app",
|
||||
AgentName: "agent",
|
||||
WorkspaceName: "workspace",
|
||||
Username: "user",
|
||||
@@ -122,8 +107,7 @@ func TestParseSubdomainAppURL(t *testing.T) {
|
||||
Name: "Port--Agent--Workspace--User",
|
||||
Subdomain: "8080--agent--workspace--user",
|
||||
Expected: httpapi.ApplicationURL{
|
||||
AppSlug: "",
|
||||
Port: 8080,
|
||||
AppSlugOrPort: "8080",
|
||||
AgentName: "agent",
|
||||
WorkspaceName: "workspace",
|
||||
Username: "user",
|
||||
@@ -133,8 +117,7 @@ func TestParseSubdomainAppURL(t *testing.T) {
|
||||
Name: "HyphenatedNames",
|
||||
Subdomain: "app-slug--agent-name--workspace-name--user-name",
|
||||
Expected: httpapi.ApplicationURL{
|
||||
AppSlug: "app-slug",
|
||||
Port: 0,
|
||||
AppSlugOrPort: "app-slug",
|
||||
AgentName: "agent-name",
|
||||
WorkspaceName: "workspace-name",
|
||||
Username: "user-name",
|
||||
|
||||
Reference in New Issue
Block a user