106 lines
2.6 KiB
Go
106 lines
2.6 KiB
Go
package auth
|
|
|
|
import (
|
|
"context"
|
|
"crypto/sha256"
|
|
"strings"
|
|
"sync"
|
|
"time"
|
|
)
|
|
|
|
// StubHashPool 是测试用假哈希池:明文加前缀,不做 argon2。
|
|
type StubHashPool struct {
|
|
mu sync.Mutex
|
|
queue int
|
|
}
|
|
|
|
func NewStubHashPool() *StubHashPool { return &StubHashPool{} }
|
|
|
|
func (p *StubHashPool) Hash(_ context.Context, _ PasswordKind, password string) (string, error) {
|
|
return "stub$" + password, nil
|
|
}
|
|
|
|
func (p *StubHashPool) Verify(_ context.Context, _ PasswordKind, password, phc string) (bool, error) {
|
|
return phc == "stub$"+password, nil
|
|
}
|
|
|
|
func (p *StubHashPool) QueueLen() int {
|
|
p.mu.Lock()
|
|
defer p.mu.Unlock()
|
|
return p.queue
|
|
}
|
|
|
|
// StubSessionTokens 假会话令牌。
|
|
type StubSessionTokens struct{}
|
|
|
|
func NewStubSessionTokens() *StubSessionTokens { return &StubSessionTokens{} }
|
|
|
|
func (s *StubSessionTokens) Issue(_ context.Context) (string, []byte, error) {
|
|
tok := "nst_stub_session_token_000000000000"
|
|
sum := sha256.Sum256([]byte(tok))
|
|
return tok, sum[:], nil
|
|
}
|
|
|
|
func (s *StubSessionTokens) HashToken(token string) []byte {
|
|
sum := sha256.Sum256([]byte(token))
|
|
return sum[:]
|
|
}
|
|
|
|
func (s *StubSessionTokens) LooksLikeSessionToken(credential string) bool {
|
|
return strings.HasPrefix(credential, "nst_")
|
|
}
|
|
|
|
// StubAPITokens 假 API 令牌。
|
|
type StubAPITokens struct{}
|
|
|
|
func NewStubAPITokens() *StubAPITokens { return &StubAPITokens{} }
|
|
|
|
func (s *StubAPITokens) Issue(_ context.Context) (string, []byte, error) {
|
|
tok := "nxm_stub_api_token_0000000000000000"
|
|
sum := sha256.Sum256([]byte(tok))
|
|
return tok, sum[:], nil
|
|
}
|
|
|
|
func (s *StubAPITokens) HashToken(token string) []byte {
|
|
sum := sha256.Sum256([]byte(token))
|
|
return sum[:]
|
|
}
|
|
|
|
func (s *StubAPITokens) LooksLikeAPIToken(credential string) bool {
|
|
return strings.HasPrefix(credential, "nxm_")
|
|
}
|
|
|
|
// StubLoginLocks 假锁定:永不锁定,记录调用便于测试。
|
|
type StubLoginLocks struct {
|
|
mu sync.Mutex
|
|
Fails []LockKey
|
|
Cleared []string
|
|
}
|
|
|
|
func NewStubLoginLocks() *StubLoginLocks { return &StubLoginLocks{} }
|
|
|
|
func (l *StubLoginLocks) Check(LockKey) (bool, time.Duration) { return false, 0 }
|
|
|
|
func (l *StubLoginLocks) Fail(key LockKey) (bool, time.Duration) {
|
|
l.mu.Lock()
|
|
defer l.mu.Unlock()
|
|
l.Fails = append(l.Fails, key)
|
|
return false, 0
|
|
}
|
|
|
|
func (l *StubLoginLocks) ClearEndpoint(endpointID string) {
|
|
l.mu.Lock()
|
|
defer l.mu.Unlock()
|
|
l.Cleared = append(l.Cleared, endpointID)
|
|
}
|
|
|
|
func (l *StubLoginLocks) Clear(LockKey) {}
|
|
|
|
// 编译期检查:假实现满足接口。
|
|
var (
|
|
_ HashPool = (*StubHashPool)(nil)
|
|
_ SessionTokens = (*StubSessionTokens)(nil)
|
|
_ APITokens = (*StubAPITokens)(nil)
|
|
_ LoginLocks = (*StubLoginLocks)(nil)
|
|
)
|