example.go 2.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889
  1. // +build examples
  2. package main
  3. import (
  4. "encoding/hex"
  5. "fmt"
  6. "io/ioutil"
  7. "log"
  8. "net/http"
  9. "net/http/httptest"
  10. "os"
  11. "gopkg.in/jcmturner/goidentity.v3"
  12. "gopkg.in/jcmturner/gokrb5.v6/client"
  13. "gopkg.in/jcmturner/gokrb5.v6/config"
  14. "gopkg.in/jcmturner/gokrb5.v6/keytab"
  15. "gopkg.in/jcmturner/gokrb5.v6/service"
  16. "gopkg.in/jcmturner/gokrb5.v6/testdata"
  17. )
  18. func main() {
  19. s := httpServer()
  20. defer s.Close()
  21. b, _ := hex.DecodeString(testdata.TESTUSER1_KEYTAB)
  22. kt, _ := keytab.Parse(b)
  23. c, _ := config.NewConfigFromString(testdata.TEST_KRB5CONF)
  24. c.LibDefaults.NoAddresses = true
  25. cl := client.NewClientWithKeytab("testuser1", "TEST.GOKRB5", kt)
  26. cl.WithConfig(c)
  27. httpRequest(s.URL, cl)
  28. b, _ = hex.DecodeString(testdata.TESTUSER2_KEYTAB)
  29. kt, _ = keytab.Parse(b)
  30. c, _ = config.NewConfigFromString(testdata.TEST_KRB5CONF)
  31. c.LibDefaults.NoAddresses = true
  32. cl = client.NewClientWithKeytab("testuser2", "TEST.GOKRB5", kt)
  33. cl.WithConfig(c)
  34. httpRequest(s.URL, cl)
  35. }
  36. func httpRequest(url string, cl client.Client) {
  37. l := log.New(os.Stderr, "GOKRB5 Client: ", log.Ldate|log.Ltime|log.Lshortfile)
  38. err := cl.Login()
  39. if err != nil {
  40. l.Printf("Error on AS_REQ: %v\n", err)
  41. }
  42. r, _ := http.NewRequest("GET", url, nil)
  43. err = cl.SetSPNEGOHeader(r, "HTTP/host.test.gokrb5")
  44. if err != nil {
  45. l.Printf("Error setting client SPNEGO header: %v", err)
  46. }
  47. httpResp, err := http.DefaultClient.Do(r)
  48. if err != nil {
  49. l.Printf("Request error: %v\n", err)
  50. }
  51. fmt.Fprintf(os.Stdout, "Response Code: %v\n", httpResp.StatusCode)
  52. content, _ := ioutil.ReadAll(httpResp.Body)
  53. fmt.Fprintf(os.Stdout, "Response Body:\n%s\n", content)
  54. }
  55. func httpServer() *httptest.Server {
  56. l := log.New(os.Stderr, "GOKRB5 Service: ", log.Ldate|log.Ltime|log.Lshortfile)
  57. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  58. kt, _ := keytab.Parse(b)
  59. th := http.HandlerFunc(testAppHandler)
  60. c := service.NewConfig(kt)
  61. s := httptest.NewServer(service.SPNEGOKRB5Authenticate(th, c, l))
  62. return s
  63. }
  64. func testAppHandler(w http.ResponseWriter, r *http.Request) {
  65. ctx := r.Context()
  66. fmt.Fprint(w, "<html>\n<p><h1>TEST.GOKRB5 Handler</h1></p>\n")
  67. if validuser, ok := ctx.Value(service.CTXKeyAuthenticated).(bool); ok && validuser {
  68. if creds, ok := ctx.Value(service.CTXKeyCredentials).(goidentity.Identity); ok {
  69. fmt.Fprintf(w, "<ul><li>Authenticed user: %s</li>\n", creds.UserName())
  70. fmt.Fprintf(w, "<li>User's realm: %s</li></ul>\n", creds.Domain())
  71. }
  72. } else {
  73. w.WriteHeader(http.StatusUnauthorized)
  74. fmt.Fprint(w, "Authentication failed")
  75. }
  76. fmt.Fprint(w, "</html>")
  77. return
  78. }