Three browser-facing endpoints now require a kind-27235 HTTP auth event
(NIP-98) proving the caller controls the pubkey:
- GET /subscription/email — pubkey extracted from auth header instead
of query param; returns subscription for the authed pubkey.
- PUT /subscription/email — pubkey extracted from auth header instead
of trusting a client-supplied body field.
- DELETE /subscription/:key — verifies auth pubkey matches subscription
owner (returns 403 if mismatch).
Server-side: decode base64 'Nostr <b64>' Authorization header, JSON.parse,
check kind === 27235, verifyEvent (nostr-tools/pure), then check u /
method / payload tags against the request URL / method / body.
README updated to reflect 'implemented' auth (not 'planned').
Integration test updated to generate NIP-98 auth headers via a new helper
script (script/nip98-auth-header.mjs).
34 lines
No EOL
1 KiB
JavaScript
34 lines
No EOL
1 KiB
JavaScript
#!/usr/bin/env node
|
|
// Generates a NIP-98 Authorization header value ("Nostr <base64>") for
|
|
// testing purposes.
|
|
//
|
|
// Usage:
|
|
// node script/nip98-auth-header.mjs <secret-hex> <url> <method> [body]
|
|
//
|
|
// Example:
|
|
// export AUTH=$(node script/nip98-auth-header.mjs \
|
|
// "$SECRET" "$BASE_URL/subscription/email" PUT '{"email":"a@b.com","frequency":"daily"}')
|
|
// curl -H "Authorization: $AUTH" ...
|
|
|
|
import { makeHttpAuth, makeHttpAuthHeader } from '@welshman/util'
|
|
import { Nip01Signer } from '@welshman/signer'
|
|
|
|
const [, , secret, url, method, body] = process.argv
|
|
|
|
if (!secret || !url) {
|
|
console.error('Usage: node script/nip98-auth-header.mjs <secret-hex> <url> <method> [body]')
|
|
process.exit(1)
|
|
}
|
|
|
|
const signer = Nip01Signer.fromSecret(secret)
|
|
|
|
// Create the unsigned auth event template
|
|
const event = await makeHttpAuth(url, method || 'GET', body || undefined)
|
|
|
|
// Stamp (created_at, pubkey, id) and sign
|
|
const signed = await signer.sign(event)
|
|
|
|
// Encode as "Nostr <base64>"
|
|
const header = makeHttpAuthHeader(signed)
|
|
|
|
console.log(header) |