feat(11-03): re-authorize every Centrifugo subscribe through a namespace registry
- lighthouse: Registry of namespace authorizers (Result, Allowed, Denied), ParseChannel, ChannelID with PHP (int)-cast semantics (PHPInt, pinned by a php -r table test), FormatChannels, WithClientID/ClientID - centrifugo: ProxyHandler (constant-time X-Centrifugo-Secret, HTTP 200 generic deny, info [] on allow, presence allow/override merge, 64 KiB body cap) mounted as the ServerToServer subscribe route - README: proxy contract, registry and channel rules
This commit is contained in:
@@ -69,9 +69,11 @@ func (d *Driver) Broadcast(ctx context.Context, channels []string, event string,
|
||||
return d.client.Broadcast(ctx, channels, event, payload)
|
||||
}
|
||||
|
||||
// Routes returns GET token_path (UserAuth, TokenHandler).
|
||||
// Routes returns GET token_path (UserAuth, TokenHandler) and POST
|
||||
// subscribe_path (ServerToServer, ProxyHandler).
|
||||
func (d *Driver) Routes() []lighthouse.Route {
|
||||
return []lighthouse.Route{
|
||||
{Name: "token", Method: http.MethodGet, Path: d.cfg.TokenPath, Surface: lighthouse.UserAuth, Handler: TokenHandler(d.svc, d.issuer)},
|
||||
{Name: "subscribe", Method: http.MethodPost, Path: d.cfg.SubscribePath, Surface: lighthouse.ServerToServer, Handler: ProxyHandler(d.svc, d.cfg)},
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user