Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions src/Cache.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
export interface Cache<T extends NonNullable<unknown>> {
getItem(key: string): Promise<T | null>
setItem(key: string, value: T): Promise<void>
removeItem(key: string): Promise<void>
}
10 changes: 6 additions & 4 deletions src/CachingAuthorizationServerProvider.ts
Original file line number Diff line number Diff line change
@@ -1,22 +1,24 @@
import type { Cache } from "./Cache.js"
import { MemoryCache } from "./MemoryCache.js"
import type { AuthorizationServerProvider } from "./AuthorizationServerProvider.js"
import type * as oauth from "oauth4webapi"

export class CachingAuthorizationServerProvider implements AuthorizationServerProvider {
readonly #cache = new Map<string, oauth.AuthorizationServer> // TODO: Take cache from caller
readonly #cache: Cache<oauth.AuthorizationServer> = new MemoryCache // TODO: Take cache from caller
readonly #original: AuthorizationServerProvider

constructor(original: AuthorizationServerProvider) {
this.#original = original
}

async getAuthorizationServer(request: Request): Promise<oauth.AuthorizationServer> {
const cached = this.#cache.get(request.url)
if (cached !== undefined) {
const cached = await this.#cache.getItem(request.url)
if (cached !== null) {
return cached
}

const fresh = await this.#original.getAuthorizationServer(request)
this.#cache.set(request.url, fresh)
await this.#cache.setItem(request.url, fresh)
return fresh
}
}
10 changes: 6 additions & 4 deletions src/CachingClientProvider.ts
Original file line number Diff line number Diff line change
@@ -1,22 +1,24 @@
import type { Cache } from "./Cache.js"
import { MemoryCache } from "./MemoryCache.js"
import type { ClientProvider } from "./ClientProvider.js"
import type * as oauth from "oauth4webapi"

export class CachingClientProvider implements ClientProvider {
readonly #cache = new Map<string, oauth.Client> // TODO: Take cache from caller
readonly #cache: Cache<oauth.Client> = new MemoryCache // TODO: Take cache from caller
readonly #original: ClientProvider

constructor(original: ClientProvider) {
this.#original = original
}

async getClient(as: oauth.AuthorizationServer, redirectUri: string, signal: AbortSignal): Promise<oauth.Client> {
const cached = this.#cache.get(as.issuer)
if (cached !== undefined) {
const cached = await this.#cache.getItem(as.issuer)
if (cached !== null) {
return cached
}

const fresh = await this.#original.getClient(as, redirectUri, signal)
this.#cache.set(as.issuer, fresh)
await this.#cache.setItem(as.issuer, fresh)
return fresh
}
}
10 changes: 6 additions & 4 deletions src/CachingIssuerProvider.ts
Original file line number Diff line number Diff line change
@@ -1,21 +1,23 @@
import type { Cache } from "./Cache.js"
import { MemoryCache } from "./MemoryCache.js"
import { IssuerProvider } from "./IssuerProvider.js"

export class CachingIssuerProvider implements IssuerProvider {
readonly #cache = new Map<string, URL> // TODO: Take cache from caller
readonly #cache: Cache<URL> = new MemoryCache // TODO: Take cache from caller
readonly #original: IssuerProvider

constructor(original: IssuerProvider) {
this.#original = original
}

async getIssuer(request: Request): Promise<URL> {
const cached = this.#cache.get(request.url)
if (cached !== undefined) {
const cached = await this.#cache.getItem(request.url)
if (cached !== null) {
return cached
}

const fresh = await this.#original.getIssuer(request)
this.#cache.set(request.url, fresh)
await this.#cache.setItem(request.url, fresh)
return fresh
}
}
14 changes: 8 additions & 6 deletions src/DPoPTokenProvider.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ import type { TokenProvider } from "./TokenProvider.js"
import type { AuthorizationServerProvider } from "./AuthorizationServerProvider.js"
import { ClientProvider } from "./ClientProvider.js"
import { supportsOfflineAccess } from "./supportsOfflineAccess.js"
import type { Cache } from "./Cache.js"
import { MemoryCache } from "./MemoryCache.js"

type CacheEntry = {
created: number,
Expand All @@ -20,7 +22,7 @@ export class DPoPTokenProvider implements TokenProvider {

// TODO: Take cache from caller
// TODO: Once cache is externalized, document that it should not be shared between clients (which would lead to impersonation)
readonly #cache = new Map<string, CacheEntry>
readonly #cache: Cache<CacheEntry> = new MemoryCache
readonly #asProvider: AuthorizationServerProvider
readonly #clientProvider: ClientProvider

Expand Down Expand Up @@ -52,23 +54,23 @@ export class DPoPTokenProvider implements TokenProvider {

private async getCachedToken(request: Request): Promise<CacheEntry> {
// TODO: More robust key via callback to support complex caching scenarios
const cached = this.#cache.get(request.url)
const cached = await this.#cache.getItem(request.url)

// TODO: Support actively refreshing the token
if (cached !== undefined) {
if (cached !== null) {
if (!isExpired(cached)) {
return cached
}

const refreshed = await this.refreshToken(cached, request)
if (refreshed !== undefined) {
this.#cache.set(request.url, refreshed)
await this.#cache.setItem(request.url, refreshed)
return refreshed
}
}

const fresh = await this.obtainToken(request)
this.#cache.set(request.url, fresh)
await this.#cache.setItem(request.url, fresh)

return fresh
}
Expand Down Expand Up @@ -155,7 +157,7 @@ export class DPoPTokenProvider implements TokenProvider {
const tokenResponse = await oauth.refreshTokenGrantRequest(cached.authorizationServer, cached.client, this.getClientAuth(cached.authorizationServer.issuer, cached.client), cached.tokenResult.refresh_token, options)
tokenResult = await oauth.processRefreshTokenResponse(cached.authorizationServer, cached.client, tokenResponse)
} catch (e) {
this.#cache.delete(request.url)
await this.#cache.removeItem(request.url)

if (e instanceof oauth.ResponseBodyError && e.error === "invalid_grant") {
console.debug("Access token could not be refreshed")
Expand Down
17 changes: 17 additions & 0 deletions src/MemoryCache.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
import type { Cache } from "./Cache.js"

export class MemoryCache<T extends NonNullable<unknown>> implements Cache<T> {
readonly #values = new Map<string, T>

async getItem(key: string): Promise<T | null> {
return this.#values.get(key) ?? null
}

async setItem(key: string, value: T): Promise<void> {
this.#values.set(key, value)
}

async removeItem(key: string): Promise<void> {
this.#values.delete(key)
}
}
Loading