All files / src/handlers BaseRequest.js

92.98% Statements 53/57
80% Branches 16/20
91.67% Functions 11/12
92.98% Lines 53/57
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236            1x 1x   1x         1x         1x                                   1x                     134x 134x 134x 134x                   102x 102x                   49x 49x                     53x 53x   53x 6x 47x 9x   38x     53x             7x   7x       7x 7x   7x   7x 5x 5x     7x             3x 3x   3x         3x   3x                     3x   3x   3x 3x 1x 1x                     12x   12x         12x   12x   12x 12x   12x                                                   1x                   2x 2x                                   1x    
'use strict'
 
/**
 * Dependencies
 * @ignore
 */
const crypto = require('@trust/webcrypto')
const qs = require('qs')
 
const HandledError = require('../errors/HandledError')
 
/**
 * Request Parameter Mapping
 */
const PARAMS = { 'GET': 'query', 'POST': 'body' }
 
/**
 * Response Mode Mapping
 */
const MODES = { 'query': '?', 'fragment': '#' }
 
/**
 * BaseRequest
 *
 * @class
 * Abstract class for implementing OpenID Connect request handlers.
 */
class BaseRequest {
 
  /**
   * Request Handler
   *
   * @param {HTTPRequest} req
   * @param {HTTPResponse} res
   * @param {Provider} provider
   */
  static handle (req, res, provider) {
    throw new Error('Handle must be implemented by BaseRequest subclass')
  }
 
  /**
   * Constructor
   *
   * @param {HTTPRequest} req
   * @param {HTTPResponse} res
   * @param {Provider} provider
   */
  constructor (req, res, provider) {
    this.req = req
    this.res = res
    this.provider = provider
    this.host = provider.host
  }
 
  /**
   * Get Params
   *
   * @param {BaseRequest} request
   * @returns {Object}
   */
  static getParams (request) {
    let { req } = request
    return req[PARAMS[req.method]] || {}
  }
 
  /**
   * Get Response Types
   *
   * @param {BaseRequest} request
   * @returns {Array}
   */
  static getResponseTypes (request) {
    let { params: { response_type: type } } = request
    return (typeof type === 'string') ? type.split(' ') : []
  }
 
  /**
   * Get Response Mode
   *
   * @param {BaseRequest} request
   * @returns {string}
   */
  static getResponseMode (request) {
    let mode
    let { params } = request || {}
    let { response_mode: responseMode, response_type: responseType } = params
 
    if (responseMode) {
      mode = MODES[responseMode]
    } else if (responseType === 'code' || responseType === 'none') {
      mode = '?'
    } else {
      mode = '#'
    }
 
    return mode
  }
 
  /**
   * 302 Redirect Response
   */
  redirect (data) {
    let { res, params: { redirect_uri: uri, state }, responseMode } = this
 
    Iif (state) {
      data.state = state
    }
 
    let response = qs.stringify(data)
    res.redirect(`${uri}${responseMode}${response}`)
 
    let error = new HandledError('302 Redirect')
 
    if (data.error) {
      error.error = data.error
      error.error_description = data.error_description
    }
 
    throw error
  }
 
  /**
   * 401 Unauthorized Response
   */
  unauthorized (err) {
    let { res } = this
    let { realm, error, error_description: description } = err
 
    res.set({
      'WWW-Authenticate':
      `Bearer realm=${realm}, error=${error}, error_description=${description}`
    })
 
    res.status(401).send('Unauthorized')
 
    throw new HandledError('401 Unauthorized')
  }
 
  /**
   * 403 Forbidden Response
   *
   * @param params {Object}
   * @param params.error {string}
   * @param params.error_description {string}
   */
  forbidden (params) {
    let {res} = this
 
    res.status(403).send('Forbidden')
 
    let error = new HandledError('403 Forbidden')
    error.error = params.error
    error.error_description = params.error_description
    throw error
  }
 
  /**
   * 400 Bad Request Response
   *
   * @param params {Object}
   * @param params.error {string}
   * @param params.error_description {string}
   */
  badRequest (params) {
    let {res} = this
 
    res.set({
      'Cache-Control': 'no-store',
      'Pragma': 'no-cache'
    })
 
    res.status(400).json(params)
 
    let error = new HandledError('400 Bad Request')
 
    error.error = params.error || 'invalid_request'
    error.error_description = params.error_description
 
    throw error
  }
 
  /**
   * Serves as a general purpose error handler for `.catch()` clauses in
   * Promise chains. Example usage:
   *
   *   ```
   *   return Promise.resolve(request)
   *     .then(request.validate)
   *     .then(request.stepOne)
   *     .then(request.stepTwo)  // etc.
   *     .catch(request.error.bind(request))
   *   ```
   *
   * If at any point (say, in `validate()` or `stepOne()`) the code needs to
   * break out of that promise chain intentionally, it should throw a
   * `HandledError`. For example:
   *
   *   ```
   *   throw new HandledError('400 Bad Request')
   *   ```
   *
   * @param error {HandledError|Error}
   */
  error (error) {
    Iif (!error.handled) {
      this.internalServerError(error)
    }
  }
 
  /**
   * Internal Server Error
   */
  internalServerError (err) {
    // TODO: Debug logging here
    let {res} = this
    res.status(500).send('Internal Server Error')
  }
 
 
 
  /**
   * TODO
   * This doesn't belong here.
   */
  random (byteLen) {
    let value = crypto.getRandomValues(new Uint8Array(byteLen))
    return Buffer.from(value).toString('hex')
  }
}
 
/**
 * Export
 */
module.exports = BaseRequest