PHP WebShell

Текущая директория: /opt/BitGoJS/modules/sdk-hmac/dist/src

Просмотр файла: hmac.js

"use strict";
var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {
    if (k2 === undefined) k2 = k;
    var desc = Object.getOwnPropertyDescriptor(m, k);
    if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {
      desc = { enumerable: true, get: function() { return m[k]; } };
    }
    Object.defineProperty(o, k2, desc);
}) : (function(o, m, k, k2) {
    if (k2 === undefined) k2 = k;
    o[k2] = m[k];
}));
var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {
    Object.defineProperty(o, "default", { enumerable: true, value: v });
}) : function(o, v) {
    o["default"] = v;
});
var __importStar = (this && this.__importStar) || (function () {
    var ownKeys = function(o) {
        ownKeys = Object.getOwnPropertyNames || function (o) {
            var ar = [];
            for (var k in o) if (Object.prototype.hasOwnProperty.call(o, k)) ar[ar.length] = k;
            return ar;
        };
        return ownKeys(o);
    };
    return function (mod) {
        if (mod && mod.__esModule) return mod;
        var result = {};
        if (mod != null) for (var k = ownKeys(mod), i = 0; i < k.length; i++) if (k[i] !== "default") __createBinding(result, mod, k[i]);
        __setModuleDefault(result, mod);
        return result;
    };
})();
Object.defineProperty(exports, "__esModule", { value: true });
exports.calculateHMAC = calculateHMAC;
exports.calculateHMACSubject = calculateHMACSubject;
exports.calculateRequestHMAC = calculateRequestHMAC;
exports.calculateRequestHeaders = calculateRequestHeaders;
exports.verifyResponse = verifyResponse;
const crypto_1 = require("crypto");
const urlLib = __importStar(require("url"));
const sjcl = __importStar(require("@bitgo/sjcl"));
/**
 * Calculate the HMAC for the given key and message
 * @param key {String} - the key to use for the HMAC
 * @param message {String} - the actual message to HMAC
 * @returns {*} - the result of the HMAC operation
 */
function calculateHMAC(key, message) {
    return (0, crypto_1.createHmac)('sha256', key).update(message).digest('hex');
}
/**
 * Calculate the subject string that is to be HMAC'ed for a HTTP request or response
 * @param urlPath request url, including query params
 * @param text request body text
 * @param timestamp request timestamp from `Date.now()`
 * @param statusCode Only set for HTTP responses, leave blank for requests
 * @param method request method
 * @returns {string}
 */
function calculateHMACSubject({ urlPath, text, timestamp, statusCode, method, authVersion, }) {
    const urlDetails = urlLib.parse(urlPath);
    const queryPath = urlDetails.query && urlDetails.query.length > 0 ? urlDetails.path : urlDetails.pathname;
    if (statusCode !== undefined && isFinite(statusCode) && Number.isInteger(statusCode)) {
        if (authVersion === 3) {
            return [method.toUpperCase(), timestamp, queryPath, statusCode, text].join('|');
        }
        return [timestamp, queryPath, statusCode, text].join('|');
    }
    if (authVersion === 3) {
        return [method.toUpperCase(), timestamp, '3.0', queryPath, text].join('|');
    }
    return [timestamp, queryPath, text].join('|');
}
/**
 * Calculate the HMAC for an HTTP request
 */
function calculateRequestHMAC({ url: urlPath, text, timestamp, token, method, authVersion, }) {
    const signatureSubject = calculateHMACSubject({ urlPath, text, timestamp, method, authVersion });
    // calculate the HMAC
    return calculateHMAC(token, signatureSubject);
}
/**
 * Calculate request headers with HMAC
 */
function calculateRequestHeaders({ url, text, token, method, authVersion, }) {
    const timestamp = Date.now();
    const hmac = calculateRequestHMAC({ url, text, timestamp, token, method, authVersion });
    // calculate the SHA256 hash of the token
    const hashDigest = sjcl.hash.sha256.hash(token);
    const tokenHash = sjcl.codec.hex.fromBits(hashDigest);
    return {
        hmac,
        timestamp,
        tokenHash,
    };
}
/**
 * Verify the HMAC for an HTTP response
 */
function verifyResponse({ url: urlPath, statusCode, text, timestamp, token, hmac, method, authVersion, }) {
    const signatureSubject = calculateHMACSubject({
        urlPath,
        text,
        timestamp,
        statusCode,
        method,
        authVersion,
    });
    // calculate the HMAC
    const expectedHmac = calculateHMAC(token, signatureSubject);
    // determine if the response is still within the validity window (5 minute window)
    const now = Date.now();
    const isInResponseValidityWindow = timestamp >= now - 1000 * 60 * 5 && timestamp <= now;
    // verify the HMAC and timestamp
    return {
        isValid: expectedHmac === hmac,
        expectedHmac,
        signatureSubject,
        isInResponseValidityWindow,
        verificationTime: now,
    };
}
//# sourceMappingURL=data:application/json;base64,

Выполнить команду


Для локальной разработки. Не используйте в интернете!