@@ -16,11 +16,20 @@ use std::env;
|
||||
use std::net::SocketAddr;
|
||||
use std::sync::Arc;
|
||||
use tower_http::cors::CorsLayer;
|
||||
use tracing_subscriber::{EnvFilter, fmt};
|
||||
|
||||
static OLLAMA_URL: Lazy<String> = Lazy::new(|| env::var("OLLAMA_URL").expect("OLLAMA_URL not set"));
|
||||
|
||||
pub fn init_tracing() {
|
||||
let filter = env::var("RUST_LOG").unwrap_or_else(|_| "info".to_string());
|
||||
|
||||
fmt().with_env_filter(EnvFilter::new(filter)).init();
|
||||
}
|
||||
|
||||
#[tokio::main]
|
||||
async fn main() {
|
||||
init_tracing();
|
||||
|
||||
#[cfg(debug_assertions)]
|
||||
{
|
||||
dotenvy::dotenv().ok();
|
||||
|
||||
@@ -10,7 +10,7 @@ pub struct Claims {
|
||||
pub preferred_username: Option<String>,
|
||||
pub exp: usize,
|
||||
pub iss: String,
|
||||
pub aud: Option<String>,
|
||||
pub aud: Option<Vec<String>>,
|
||||
pub realm_access: Option<RealmAccess>,
|
||||
}
|
||||
|
||||
@@ -47,9 +47,8 @@ pub fn validate_token(token: &str, jwks: &Value) -> Result<Claims, String> {
|
||||
|
||||
validation.set_issuer(&[ISSUER.as_str()]);
|
||||
|
||||
// Optional but recommended:
|
||||
validation.validate_exp = true;
|
||||
validation.validate_aud = false; // depends on your Keycloak config
|
||||
validation.validate_aud = false;
|
||||
|
||||
// 5. Decode & verify
|
||||
let token_data = decode::<Claims>(token, &decoding_key, &validation)
|
||||
|
||||
@@ -6,18 +6,15 @@ use crate::middlewares::auth::{
|
||||
};
|
||||
|
||||
pub async fn auth_middleware(mut request: Request, next: Next) -> Result<Response, StatusCode> {
|
||||
#[cfg(debug_assertions)]
|
||||
println!("Middleware hit");
|
||||
tracing::debug!("Middleware hit");
|
||||
|
||||
let headers = request.headers();
|
||||
|
||||
#[cfg(debug_assertions)]
|
||||
println!("Headers extracted");
|
||||
tracing::debug!("Headers extracted");
|
||||
|
||||
let auth_header = headers.get("authorization").and_then(|v| v.to_str().ok());
|
||||
|
||||
#[cfg(debug_assertions)]
|
||||
println!("Auth header: {:?}", auth_header);
|
||||
tracing::debug!("Auth header: {:?}", auth_header);
|
||||
|
||||
let auth_header = auth_header.ok_or(StatusCode::UNAUTHORIZED)?;
|
||||
|
||||
@@ -29,8 +26,7 @@ pub async fn auth_middleware(mut request: Request, next: Next) -> Result<Respons
|
||||
|
||||
match validate_token(token, &jwks) {
|
||||
Ok(claims) => {
|
||||
#[cfg(debug_assertions)]
|
||||
println!("Token valid");
|
||||
tracing::debug!("Token valid");
|
||||
|
||||
request.extensions_mut().insert(claims);
|
||||
|
||||
@@ -44,7 +40,10 @@ pub async fn auth_middleware(mut request: Request, next: Next) -> Result<Respons
|
||||
request.extensions_mut().insert(claims);
|
||||
Ok(next.run(request).await)
|
||||
}
|
||||
Err(_) => Err(StatusCode::UNAUTHORIZED),
|
||||
Err(e) => {
|
||||
eprintln!("JWT validation failed: {:?}", e);
|
||||
Err(StatusCode::UNAUTHORIZED)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user