feat: update last time used api key
This commit is contained in:
@@ -266,5 +266,4 @@ This project turns Ollama into:
|
|||||||
|
|
||||||
# TODO
|
# TODO
|
||||||
- open api doc for bearer token
|
- open api doc for bearer token
|
||||||
- endpoint for creating token
|
- db
|
||||||
- verify bearer token
|
|
||||||
|
|||||||
@@ -0,0 +1,17 @@
|
|||||||
|
use sqlx::PgPool;
|
||||||
|
use uuid::Uuid;
|
||||||
|
|
||||||
|
pub async fn update_last_access(pool: &PgPool, api_key_id: Uuid) -> Result<(), sqlx::Error> {
|
||||||
|
sqlx::query!(
|
||||||
|
r#"
|
||||||
|
UPDATE auth.api_key
|
||||||
|
SET last_used_at = now()
|
||||||
|
WHERE id = $1
|
||||||
|
"#,
|
||||||
|
api_key_id
|
||||||
|
)
|
||||||
|
.execute(pool)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
@@ -1,2 +1,3 @@
|
|||||||
|
pub mod api_key;
|
||||||
pub mod pool;
|
pub mod pool;
|
||||||
pub mod user_repository;
|
pub mod user_repository;
|
||||||
|
|||||||
@@ -3,4 +3,5 @@ use uuid::Uuid;
|
|||||||
#[derive(Clone, Debug)]
|
#[derive(Clone, Debug)]
|
||||||
pub struct ApiKeyClaims {
|
pub struct ApiKeyClaims {
|
||||||
pub sub: Uuid,
|
pub sub: Uuid,
|
||||||
|
pub api_key_id: Uuid,
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,7 +5,9 @@ use axum::{
|
|||||||
response::{IntoResponse, Response},
|
response::{IntoResponse, Response},
|
||||||
};
|
};
|
||||||
|
|
||||||
use crate::databases::postgres::user_repository::ensure_user_exists;
|
use crate::databases::postgres::{
|
||||||
|
api_key::update_last_access, user_repository::ensure_user_exists,
|
||||||
|
};
|
||||||
use crate::middlewares::auth::apikey::ApiKeyClaims;
|
use crate::middlewares::auth::apikey::ApiKeyClaims;
|
||||||
use crate::middlewares::auth::keycloak::{KeycloakClaims, get_jwks, refresh_jwks, validate_token};
|
use crate::middlewares::auth::keycloak::{KeycloakClaims, get_jwks, refresh_jwks, validate_token};
|
||||||
use crate::state::app_state::AppState;
|
use crate::state::app_state::AppState;
|
||||||
@@ -125,7 +127,7 @@ async fn try_api_key(
|
|||||||
|
|
||||||
let row = sqlx::query!(
|
let row = sqlx::query!(
|
||||||
r#"
|
r#"
|
||||||
SELECT u.id AS user_id
|
SELECT u.id AS user_id, ak.id as key_id
|
||||||
FROM auth.api_key ak
|
FROM auth.api_key ak
|
||||||
JOIN auth.user u ON u.id = ak.created_by
|
JOIN auth.user u ON u.id = ak.created_by
|
||||||
WHERE ak.key_hash = $1
|
WHERE ak.key_hash = $1
|
||||||
@@ -147,7 +149,10 @@ async fn try_api_key(
|
|||||||
state,
|
state,
|
||||||
request,
|
request,
|
||||||
next,
|
next,
|
||||||
Auth::ApiKey(ApiKeyClaims { sub: row.user_id }),
|
Auth::ApiKey(ApiKeyClaims {
|
||||||
|
sub: row.user_id,
|
||||||
|
api_key_id: row.key_id,
|
||||||
|
}),
|
||||||
)
|
)
|
||||||
.await
|
.await
|
||||||
}
|
}
|
||||||
@@ -161,12 +166,24 @@ async fn handle_auth(
|
|||||||
next: Next,
|
next: Next,
|
||||||
auth: Auth,
|
auth: Auth,
|
||||||
) -> Result<Response, StatusCode> {
|
) -> Result<Response, StatusCode> {
|
||||||
ensure_user_exists(&state.postgres, auth.user_id())
|
match &auth {
|
||||||
.await
|
Auth::Jwt(_) => {
|
||||||
.map_err(|e| {
|
ensure_user_exists(&state.postgres, auth.user_id())
|
||||||
tracing::error!("ensure_user_exists failed: {e}");
|
.await
|
||||||
StatusCode::INTERNAL_SERVER_ERROR
|
.map_err(|e| {
|
||||||
})?;
|
tracing::error!("ensure_user_exists failed: {e}");
|
||||||
|
StatusCode::INTERNAL_SERVER_ERROR
|
||||||
|
})?;
|
||||||
|
}
|
||||||
|
Auth::ApiKey(key) => {
|
||||||
|
update_last_access(&state.postgres, key.api_key_id)
|
||||||
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
tracing::error!("update_last_access failed: {e}");
|
||||||
|
StatusCode::INTERNAL_SERVER_ERROR
|
||||||
|
})?;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
request.extensions_mut().insert(auth);
|
request.extensions_mut().insert(auth);
|
||||||
Ok(next.run(request).await)
|
Ok(next.run(request).await)
|
||||||
|
|||||||
Reference in New Issue
Block a user