PHP WebShell
Текущая директория: /opt/BitGoJS/modules/sdk-hmac/dist/src
Просмотр файла: hmac.js
"use strict";
var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {
if (k2 === undefined) k2 = k;
var desc = Object.getOwnPropertyDescriptor(m, k);
if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {
desc = { enumerable: true, get: function() { return m[k]; } };
}
Object.defineProperty(o, k2, desc);
}) : (function(o, m, k, k2) {
if (k2 === undefined) k2 = k;
o[k2] = m[k];
}));
var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {
Object.defineProperty(o, "default", { enumerable: true, value: v });
}) : function(o, v) {
o["default"] = v;
});
var __importStar = (this && this.__importStar) || (function () {
var ownKeys = function(o) {
ownKeys = Object.getOwnPropertyNames || function (o) {
var ar = [];
for (var k in o) if (Object.prototype.hasOwnProperty.call(o, k)) ar[ar.length] = k;
return ar;
};
return ownKeys(o);
};
return function (mod) {
if (mod && mod.__esModule) return mod;
var result = {};
if (mod != null) for (var k = ownKeys(mod), i = 0; i < k.length; i++) if (k[i] !== "default") __createBinding(result, mod, k[i]);
__setModuleDefault(result, mod);
return result;
};
})();
Object.defineProperty(exports, "__esModule", { value: true });
exports.calculateHMAC = calculateHMAC;
exports.calculateHMACSubject = calculateHMACSubject;
exports.calculateRequestHMAC = calculateRequestHMAC;
exports.calculateRequestHeaders = calculateRequestHeaders;
exports.verifyResponse = verifyResponse;
const crypto_1 = require("crypto");
const urlLib = __importStar(require("url"));
const sjcl = __importStar(require("@bitgo/sjcl"));
/**
* Calculate the HMAC for the given key and message
* @param key {String} - the key to use for the HMAC
* @param message {String} - the actual message to HMAC
* @returns {*} - the result of the HMAC operation
*/
function calculateHMAC(key, message) {
return (0, crypto_1.createHmac)('sha256', key).update(message).digest('hex');
}
/**
* Calculate the subject string that is to be HMAC'ed for a HTTP request or response
* @param urlPath request url, including query params
* @param text request body text
* @param timestamp request timestamp from `Date.now()`
* @param statusCode Only set for HTTP responses, leave blank for requests
* @param method request method
* @returns {string}
*/
function calculateHMACSubject({ urlPath, text, timestamp, statusCode, method, authVersion, }) {
const urlDetails = urlLib.parse(urlPath);
const queryPath = urlDetails.query && urlDetails.query.length > 0 ? urlDetails.path : urlDetails.pathname;
if (statusCode !== undefined && isFinite(statusCode) && Number.isInteger(statusCode)) {
if (authVersion === 3) {
return [method.toUpperCase(), timestamp, queryPath, statusCode, text].join('|');
}
return [timestamp, queryPath, statusCode, text].join('|');
}
if (authVersion === 3) {
return [method.toUpperCase(), timestamp, '3.0', queryPath, text].join('|');
}
return [timestamp, queryPath, text].join('|');
}
/**
* Calculate the HMAC for an HTTP request
*/
function calculateRequestHMAC({ url: urlPath, text, timestamp, token, method, authVersion, }) {
const signatureSubject = calculateHMACSubject({ urlPath, text, timestamp, method, authVersion });
// calculate the HMAC
return calculateHMAC(token, signatureSubject);
}
/**
* Calculate request headers with HMAC
*/
function calculateRequestHeaders({ url, text, token, method, authVersion, }) {
const timestamp = Date.now();
const hmac = calculateRequestHMAC({ url, text, timestamp, token, method, authVersion });
// calculate the SHA256 hash of the token
const hashDigest = sjcl.hash.sha256.hash(token);
const tokenHash = sjcl.codec.hex.fromBits(hashDigest);
return {
hmac,
timestamp,
tokenHash,
};
}
/**
* Verify the HMAC for an HTTP response
*/
function verifyResponse({ url: urlPath, statusCode, text, timestamp, token, hmac, method, authVersion, }) {
const signatureSubject = calculateHMACSubject({
urlPath,
text,
timestamp,
statusCode,
method,
authVersion,
});
// calculate the HMAC
const expectedHmac = calculateHMAC(token, signatureSubject);
// determine if the response is still within the validity window (5 minute window)
const now = Date.now();
const isInResponseValidityWindow = timestamp >= now - 1000 * 60 * 5 && timestamp <= now;
// verify the HMAC and timestamp
return {
isValid: expectedHmac === hmac,
expectedHmac,
signatureSubject,
isInResponseValidityWindow,
verificationTime: now,
};
}
//# sourceMappingURL=data:application/json;base64,Выполнить команду
Для локальной разработки. Не используйте в интернете!