-
Notifications
You must be signed in to change notification settings - Fork 163
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Refactor JWT backend, add JS mode, allow pre parsing of token for JS …
…and local mode, allow local mode specific DB options instead of sharing with regular DB backends.
- Loading branch information
Showing
15 changed files
with
1,248 additions
and
874 deletions.
There are no files selected for viewing
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,74 @@ | ||
package js | ||
|
||
import ( | ||
"errors" | ||
"io/ioutil" | ||
"time" | ||
|
||
"github.com/robertkrimen/otto" | ||
) | ||
|
||
type Runner struct { | ||
StackDepthLimit int | ||
MsMaxDuration int64 | ||
} | ||
|
||
var Halt = errors.New("exceeded max execution time") | ||
|
||
func NewRunner(stackDepthLimit int, msMaxDuration int64) *Runner { | ||
return &Runner{ | ||
StackDepthLimit: stackDepthLimit, | ||
MsMaxDuration: msMaxDuration, | ||
} | ||
} | ||
|
||
func LoadScript(path string) (string, error) { | ||
script, err := ioutil.ReadFile(path) | ||
if err != nil { | ||
return "", err | ||
} | ||
|
||
return string(script), nil | ||
} | ||
|
||
func (o *Runner) RunScript(script string, params map[string]interface{}) (granted bool, err error) { | ||
// The VM is not thread-safe, so we need to create a new VM on every run. | ||
// TODO: This could be enhanced by having a pool of VMs. | ||
vm := otto.New() | ||
vm.SetStackDepthLimit(o.StackDepthLimit) | ||
vm.Interrupt = make(chan func(), 1) | ||
|
||
defer func() { | ||
if caught := recover(); caught != nil { | ||
if caught == Halt { | ||
granted = false | ||
err = Halt | ||
return | ||
} | ||
panic(caught) | ||
} | ||
}() | ||
|
||
go func() { | ||
time.Sleep(time.Duration(o.MsMaxDuration) * time.Millisecond) | ||
vm.Interrupt <- func() { | ||
panic(Halt) | ||
} | ||
}() | ||
|
||
for k, v := range params { | ||
vm.Set(k, v) | ||
} | ||
|
||
val, err := vm.Run(script) | ||
if err != nil { | ||
return false, err | ||
} | ||
|
||
granted, err = val.ToBoolean() | ||
if err != nil { | ||
return false, err | ||
} | ||
|
||
return | ||
} |
Oops, something went wrong.