This commit is contained in:
lbenedar
2026-03-06 15:37:31 +03:00
parent b6cdb2b860
commit 126ccfa715
5 changed files with 49 additions and 11 deletions

View File

@@ -1,6 +1,7 @@
package main
import (
"context"
"fmt"
"net/http"
@@ -20,6 +21,17 @@ func secureHeaders(next http.Handler) http.Handler {
})
}
func noSurf(next http.Handler) http.Handler {
csrfHanlder := nosurf.New(next)
csrfHanlder.SetBaseCookie(http.Cookie{
HttpOnly: true,
Path: "/",
Secure: true,
})
return csrfHanlder
}
func (app *application) logRequest(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
app.infoLog.Printf("%s - %s %s %s", r.RemoteAddr, r.Proto, r.Method, r.URL.RequestURI())
@@ -52,13 +64,24 @@ func (app *application) requireAuthentication(next http.Handler) http.Handler {
})
}
func noSurf(next http.Handler) http.Handler {
csrfHanlder := nosurf.New(next)
csrfHanlder.SetBaseCookie(http.Cookie{
HttpOnly: true,
Path: "/",
Secure: true,
})
func (app *application) authenticate(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
id := app.sessionManager.GetInt(r.Context(), "authenticatedUserID")
if id == 0 {
next.ServeHTTP(w, r)
return
}
return csrfHanlder
exists, err := app.users.Exists(id)
if err != nil {
app.serverError(w, err)
return
}
if exists {
ctx := context.WithValue(r.Context(), isAuthenticatedContextKey, true)
r = r.WithContext(ctx)
}
next.ServeHTTP(w, r)
})
}