serve: --auth and --eager-auth flags.

This commit is contained in:
fiatjaf
2026-06-20 20:23:39 -03:00
parent 483bf94ff4
commit cc879b6bf6
+40 -1
View File
@@ -64,6 +64,14 @@ var serve = &cli.Command{
Name: "blossom", Name: "blossom",
Usage: "enable blossom server", Usage: "enable blossom server",
}, },
&cli.BoolFlag{
Name: "auth",
Usage: "require AUTH for all operations",
},
&cli.BoolFlag{
Name: "eager-auth",
Usage: "send AUTH challenge immediately on connect",
},
}, },
Action: func(ctx context.Context, c *cli.Command) error { Action: func(ctx context.Context, c *cli.Command) error {
db := &slicestore.SliceStore{} db := &slicestore.SliceStore{}
@@ -116,12 +124,19 @@ var serve = &cli.Command{
totalConnections := atomic.Int32{} totalConnections := atomic.Int32{}
rl.OnConnect = func(ctx context.Context) { rl.OnConnect = func(ctx context.Context) {
totalConnections.Add(1) totalConnections.Add(1)
if c.Bool("eager-auth") {
khatru.RequestAuth(ctx)
}
go func() { go func() {
<-ctx.Done() <-ctx.Done()
totalConnections.Add(-1) totalConnections.Add(-1)
}() }()
} }
rl.OnAuth = func(ctx context.Context, pubkey nostr.PubKey) {
log(" got %s %s\n", color.GreenString("authenticated"), pubkey.Hex())
}
d := debounce.New(time.Second * 2) d := debounce.New(time.Second * 2)
var printStatus func() var printStatus func()
printStatus = func() { printStatus = func() {
@@ -228,23 +243,47 @@ var serve = &cli.Command{
// relay logging // relay logging
rl.OnRequest = func(ctx context.Context, filter nostr.Filter) (reject bool, msg string) { rl.OnRequest = func(ctx context.Context, filter nostr.Filter) (reject bool, msg string) {
if c.Bool("auth") {
if _, isAuthed := khatru.GetAuthed(ctx); !isAuthed {
return true, "auth-required: subscribe"
}
}
negentropy := "" negentropy := ""
if khatru.IsNegentropySession(ctx) { if khatru.IsNegentropySession(ctx) {
negentropy = color.HiBlueString("negentropy ") negentropy = color.HiBlueString("negentropy ")
} }
log(" got %s%s %v\n", negentropy, color.HiYellowString("request"), colors.italic(filter)) authedString := ""
if pubkey, ok := khatru.GetAuthed(ctx); ok {
authedString = fmt.Sprintf(" from %s", color.GreenString(pubkey.Hex()))
}
log(" got %s%s %v%s\n",
negentropy, color.HiYellowString("request"), colors.italic(filter), authedString)
printStatus() printStatus()
return false, "" return false, ""
} }
rl.OnCount = func(ctx context.Context, filter nostr.Filter) (reject bool, msg string) { rl.OnCount = func(ctx context.Context, filter nostr.Filter) (reject bool, msg string) {
if c.Bool("auth") {
if _, isAuthed := khatru.GetAuthed(ctx); !isAuthed {
return true, "auth-required: count"
}
}
log(" got %s %v\n", color.HiCyanString("count request"), colors.italic(filter)) log(" got %s %v\n", color.HiCyanString("count request"), colors.italic(filter))
printStatus() printStatus()
return false, "" return false, ""
} }
rl.OnEvent = func(ctx context.Context, event nostr.Event) (reject bool, msg string) { rl.OnEvent = func(ctx context.Context, event nostr.Event) (reject bool, msg string) {
if c.Bool("auth") {
if _, isAuthed := khatru.GetAuthed(ctx); !isAuthed {
return true, "auth-required: event"
}
}
log(" got %s %v\n", color.BlueString("event"), colors.italic(event)) log(" got %s %v\n", color.BlueString("event"), colors.italic(event))
printStatus() printStatus()
return false, "" return false, ""