diff --git a/src/PostgREST/Auth.hs b/src/PostgREST/Auth.hs index 6f42eafbb..9d8f5f99c 100644 --- a/src/PostgREST/Auth.hs +++ b/src/PostgREST/Auth.hs @@ -55,9 +55,6 @@ checkPass = (. cs) . validatePassword . cs setRole :: Text -> H.Tx P.Postgres s () setRole role = H.unitEx $ B.Stmt ("set local role " <> cs (pgFmtLit role)) V.empty True -resetRole :: H.Tx P.Postgres s () -resetRole = H.unitEx [H.stmt|reset role|] - setUserId :: Text -> H.Tx P.Postgres s () setUserId uid = if uid /= "" then H.unitEx $ B.Stmt ("set local user_vars.user_id = " <> cs (pgFmtLit uid)) V.empty True @@ -90,15 +87,15 @@ signInWithJWT secret input = case maybeRole of Just (Just (String uid)) -> LoginSuccess (cs role) (cs uid) _ -> LoginFailed _ -> LoginFailed - where + where maybeRole = (Data.Map.lookup "role" <$> claims) ::Maybe (Maybe Value) maybeUserId = (Data.Map.lookup "id" <$> claims) ::Maybe (Maybe Value) claims = JWT.unregisteredClaims <$> JWT.claims <$> decoded decoded = JWT.decodeAndVerifySignature (JWT.secret secret) input - + tokenJWT :: Text -> Text -> Text -> Text tokenJWT secret uid role = JWT.encodeSigned JWT.HS256 (JWT.secret secret) claimsSet where claimsSet = JWT.def { JWT.unregisteredClaims = Data.Map.fromList [("id", String uid), ("role", String role)] - } \ No newline at end of file + } diff --git a/src/PostgREST/Main.hs b/src/PostgREST/Main.hs index e7a9d40ef..1a14c2f4d 100644 --- a/src/PostgREST/Main.hs +++ b/src/PostgREST/Main.hs @@ -73,7 +73,7 @@ main = do runSettings appSettings $ middle $ \req respond -> do body <- strictRequestBody req - resOrError <- liftIO $ H.session pool $ H.tx (Just (H.ReadUncommitted, Just True)) $ + resOrError <- liftIO $ H.session pool $ H.tx (Just (H.ReadCommitted, Just True)) $ authenticated conf (app conf body) req either (respond . errResponse) respond resOrError diff --git a/src/PostgREST/Middleware.hs b/src/PostgREST/Middleware.hs index b14bf5005..f560e8313 100644 --- a/src/PostgREST/Middleware.hs +++ b/src/PostgREST/Middleware.hs @@ -23,7 +23,7 @@ import Network.Wai.Middleware.Static (staticPolicy, only) import Network.URI (URI(..), parseURI) import PostgREST.Config (AppConfig(..), corsPolicy) -import PostgREST.Auth (LoginAttempt(..), signInRole, signInWithJWT, setRole, resetRole, setUserId, resetUserId) +import PostgREST.Auth (LoginAttempt(..), signInRole, signInWithJWT, setRole, setUserId) import PostgREST.App (contentTypeForAccept) import Codec.Binary.Base64.String (decode) @@ -62,10 +62,7 @@ authenticated conf app req = do runInRole r uid = do setUserId uid setRole r - res <- app req - resetRole - resetUserId - return res + app req redirectInsecure :: Application -> Application @@ -93,7 +90,7 @@ unsupportedAccept :: Application -> Application unsupportedAccept app req respond = do let accept = lookup hAccept $ requestHeaders req - if isNothing $ contentTypeForAccept accept + if isNothing $ contentTypeForAccept accept then respond $ responseLBS status415 [] "Unsupported Accept header, try: application/json" else app req respond diff --git a/test/SpecHelper.hs b/test/SpecHelper.hs index e24c75fb1..e5ae89db8 100644 --- a/test/SpecHelper.hs +++ b/test/SpecHelper.hs @@ -54,7 +54,7 @@ withApp perform = do perform $ middle $ \req resp -> do body <- strictRequestBody req - result <- liftIO $ H.session pool $ H.tx (Just (H.ReadUncommitted, Just True)) + result <- liftIO $ H.session pool $ H.tx (Just (H.ReadCommitted, Just True)) $ authenticated cfg (app cfg body) req either (resp . errResponse) resp result