example.go 2.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091
  1. // +build examples
  2. // Package examples provides simple examples of gokrb5 use.
  3. package main
  4. import (
  5. "encoding/hex"
  6. "fmt"
  7. "io/ioutil"
  8. "log"
  9. "net/http"
  10. "net/http/httptest"
  11. "os"
  12. "gopkg.in/jcmturner/goidentity.v3"
  13. "gopkg.in/jcmturner/gokrb5.v7/client"
  14. "gopkg.in/jcmturner/gokrb5.v7/config"
  15. "gopkg.in/jcmturner/gokrb5.v7/keytab"
  16. "gopkg.in/jcmturner/gokrb5.v7/service"
  17. "gopkg.in/jcmturner/gokrb5.v7/spnego"
  18. "gopkg.in/jcmturner/gokrb5.v7/test/testdata"
  19. )
  20. func main() {
  21. s := httpServer()
  22. defer s.Close()
  23. b, _ := hex.DecodeString(testdata.TESTUSER1_KEYTAB)
  24. kt := keytab.New()
  25. kt.Unmarshal(b)
  26. c, _ := config.NewConfigFromString(testdata.TEST_KRB5CONF)
  27. c.LibDefaults.NoAddresses = true
  28. cl := client.NewClientWithKeytab("testuser1", "TEST.GOKRB5", kt, c)
  29. httpRequest(s.URL, cl)
  30. b, _ = hex.DecodeString(testdata.TESTUSER2_KEYTAB)
  31. kt = keytab.New()
  32. kt.Unmarshal(b)
  33. c, _ = config.NewConfigFromString(testdata.TEST_KRB5CONF)
  34. c.LibDefaults.NoAddresses = true
  35. cl = client.NewClientWithKeytab("testuser2", "TEST.GOKRB5", kt, c)
  36. httpRequest(s.URL, cl)
  37. }
  38. func httpRequest(url string, cl *client.Client) {
  39. l := log.New(os.Stderr, "GOKRB5 Client: ", log.Ldate|log.Ltime|log.Lshortfile)
  40. err := cl.Login()
  41. if err != nil {
  42. l.Printf("Error on AS_REQ: %v\n", err)
  43. }
  44. r, _ := http.NewRequest("GET", url, nil)
  45. err = spnego.SetSPNEGOHeader(cl, r, "HTTP/host.test.gokrb5")
  46. if err != nil {
  47. l.Printf("Error setting client SPNEGO header: %v", err)
  48. }
  49. httpResp, err := http.DefaultClient.Do(r)
  50. if err != nil {
  51. l.Printf("Request error: %v\n", err)
  52. }
  53. fmt.Fprintf(os.Stdout, "Response Code: %v\n", httpResp.StatusCode)
  54. content, _ := ioutil.ReadAll(httpResp.Body)
  55. fmt.Fprintf(os.Stdout, "Response Body:\n%s\n", content)
  56. }
  57. func httpServer() *httptest.Server {
  58. l := log.New(os.Stderr, "GOKRB5 Service Tests: ", log.Ldate|log.Ltime|log.Lshortfile)
  59. b, _ := hex.DecodeString(testdata.HTTP_KEYTAB)
  60. kt := keytab.New()
  61. kt.Unmarshal(b)
  62. th := http.HandlerFunc(testAppHandler)
  63. s := httptest.NewServer(spnego.SPNEGOKRB5Authenticate(th, kt, service.Logger(l)))
  64. return s
  65. }
  66. func testAppHandler(w http.ResponseWriter, r *http.Request) {
  67. ctx := r.Context()
  68. fmt.Fprint(w, "<html>\n<p><h1>TEST.GOKRB5 Handler</h1></p>\n")
  69. if validuser, ok := ctx.Value(spnego.CTXKeyAuthenticated).(bool); ok && validuser {
  70. if creds, ok := ctx.Value(spnego.CTXKeyCredentials).(goidentity.Identity); ok {
  71. fmt.Fprintf(w, "<ul><li>Authenticed user: %s</li>\n", creds.UserName())
  72. fmt.Fprintf(w, "<li>User's realm: %s</li></ul>\n", creds.Domain())
  73. }
  74. } else {
  75. w.WriteHeader(http.StatusUnauthorized)
  76. fmt.Fprint(w, "Authentication failed")
  77. }
  78. fmt.Fprint(w, "</html>")
  79. return
  80. }