-
Notifications
You must be signed in to change notification settings - Fork 2
/
index.js
105 lines (90 loc) · 2.14 KB
/
index.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
var AWS = require('aws-sdk');
var jwt = require('jsonwebtoken');
function KmsJwt(options)
{
options = options || { awsConfig: {}, keyArn: null, signingKey: null };
this.signingKey = options.signingKey;
this.keyArn = options.keyArn;
this.publicKey = null;
this.kms = new AWS.KMS(options.awsConfig);
}
KmsJwt.prototype.createSigningKey = function(publicKey, callback)
{
try
{
var params = {
Plaintext: publicKey,
KeyId: this.keyArn
};
this.kms.encrypt(params,function(err, data){
var result = null;
if (!err && data.CiphertextBlob)
{
result = data.CiphertextBlob.toString('base64');
}
callback(err,result);
});
}
catch(e)
{
callback(e,null);
}
};
KmsJwt.prototype.retrievePublicKey = function(token, callback)
{
try
{
var self = this;
this.kms.decrypt({ CiphertextBlob : new Buffer(this.signingKey, 'base64') },function(err,data){
if (!err)
{
self.publicKey = data.Plaintext.toString();
}
callback(err,data);
});
}
catch(e)
{
callback(e,null);
}
};
KmsJwt.prototype.verify = function(token, callback)
{
var self = this;
var verifyToken = function(token,callback) {
try
{
var decoded = jwt.verify(token, self.publicKey);
if (decoded.hasOwnProperty('exp') && decoded.exp < Date.now()/1000)
{
callback("JWT token expired", decoded);
}
else
{
callback(null, decoded);
}
}
catch (e)
{
callback(e.message,null);
}
};
if (!this.publicKey)
{
this.retrievePublicKey(token,function(err, data){
if (err)
{
callback(err,null);
}
else
{
verifyToken(token,callback);
}
});
}
else
{
verifyToken(token,callback);
}
};
module.exports = KmsJwt;