/
githubmirror
/
photoprism
Обзор
Документация
Войти
/
githubmirror
/
photoprism
Код
Запросы
0
Пакеты
0
Релизы
0
Аналитика
Безопасность
develop
pkg/authn/authtoken/parse.go
33 строки
1 KB
Michael Mayer
Downloads: Add signed tokens and file-level album selection #5733 #5743
24 июл 2026, 18:55
24 июл 2026, 18:55
1cea6cc
Код
Авторство
О чём код?
package authtoken import ( "crypto/hmac" "net/url" ) // Verify checks a bunny.net Advanced token against the message rebuilt from the request. It returns // nil when the signature matches and the token has not expired (now and expires are Unix seconds), // ErrMalformed when the token is empty, ErrExpired when the deadline has passed, and ErrSignature when // the token is forged, tampered, or signed with a different key. The comparison is constant-time. func Verify(key []byte, signaturePath string, expires int64, params url.Values, clientIP, token string, now int64) error { if token == "" { return ErrMalformed } if now > expires { return ErrExpired } want := Sign(key, signaturePath, expires, params, clientIP) if !hmac.Equal([]byte(token), []byte(want)) { return ErrSignature } return nil } // Valid reports whether token is a valid, unexpired signature for the request. func Valid(key []byte, signaturePath string, expires int64, params url.Values, clientIP, token string, now int64) bool { return Verify(key, signaturePath, expires, params, clientIP, token, now) == nil }