Blind authentication (#675)

* auth server

* cleaning up

* auth ledger class

* class variables -> instance variables

* annotations

* add models and api route

* custom amount and api prefix

* add auth db

* blind auth token working

* jwt working

* clean up

* JWT works

* using openid connect server

* use oauth server with password flow

* new realm

* add keycloak docker

* hopefully not garbage

* auth works

* auth kinda working

* fix cli

* auth works for send and receive

* pass auth_db to Wallet

* auth in info

* refactor

* fix supported

* cache mint info

* fix settings and endpoints

* add description to .env.example

* track changes for openid connect client

* store mint in db

* store credentials

* clean up v1_api.py

* load mint info into auth wallet

* fix first login

* authenticate if refresh token fails

* clear auth also middleware

* use regex

* add cli command

* pw works

* persist keyset amounts

* add errors.py

* do not start auth server if disabled in config

* upadte poetry

* disvoery url

* fix test

* support device code flow

* adopt latest spec changes

* fix code flow

* mint max bat dynamic

* mypy ignore

* fix test

* do not serialize amount in authproof

* all auth flows working

* fix tests

* submodule

* refactor

* test

* dont sleep

* test

* add wallet auth tests

* test differently

* test only keycloak for now

* fix creds

* daemon

* fix test

* install everything

* install jinja

* delete wallet for every test

* auth: use global rate limiter

* test auth rate limit

* keycloak hostname

* move keycloak test data

* reactivate all tests

* add readme

* load proofs

* remove unused code

* remove unused code

* implement change suggestions by ok300

* add error codes

* test errors
This commit is contained in:
callebtc
2025-01-29 22:48:51 -06:00
committed by GitHub
parent b67ffd8705
commit a0ef44dba0
58 changed files with 8188 additions and 701 deletions

View File

@@ -38,6 +38,11 @@ class MintInfoContact(BaseModel):
info: str
class MintInfoProtectedEndpoint(BaseModel):
method: str
path: str
class GetInfoResponse(BaseModel):
name: Optional[str] = None
pubkey: Optional[str] = None
@@ -57,7 +62,7 @@ class GetInfoResponse(BaseModel):
# BEGIN DEPRECATED: NUT-06 contact field change
# NUT-06 PR: https://github.com/cashubtc/nuts/pull/117
@root_validator(pre=True)
def preprocess_deprecated_contact_field(cls, values):
def preprocess_deprecated_contact_field(cls, values: dict):
if "contact" in values and values["contact"]:
if isinstance(values["contact"][0], list):
values["contact"] = [
@@ -346,3 +351,16 @@ class PostRestoreResponse(BaseModel):
def __init__(self, **data):
super().__init__(**data)
self.promises = self.signatures
# ------- API: BLIND AUTH -------
class PostAuthBlindMintRequest(BaseModel):
outputs: List[BlindedMessage] = Field(
...,
max_items=settings.mint_max_request_length,
description="Blinded messages for creating blind auth tokens.",
)
class PostAuthBlindMintResponse(BaseModel):
signatures: List[BlindedSignature] = []