aboutsummaryrefslogtreecommitdiffstats
path: root/internal/auth/csrf.go
diff options
context:
space:
mode:
authorgramanas <grm@eyesin.space>2026-09-12 11:24:17 +0300
committergramanas <grm@eyesin.space>2026-09-12 11:24:17 +0300
commit3eb04b1a2bdf9e53231fe862cfd76327371a9741 (patch)
treeb38b2d82a47233fd8e0bb18c59e4a8f3dd2412d7 /internal/auth/csrf.go
downloadblogspace-3eb04b1a2bdf9e53231fe862cfd76327371a9741.tar.gz
blogspace-3eb04b1a2bdf9e53231fe862cfd76327371a9741.tar.bz2
blogspace-3eb04b1a2bdf9e53231fe862cfd76327371a9741.zip
Initial multi-tenant blog host
Go + Postgres application serving a management dashboard on the base domain and one public blog per subdomain. Markdown posts organised in pages, form-based theme customisation, image uploads stored in Postgres, JWT cookie sessions with CSRF, superadmin user management, RSS feeds. Docker/compose deployment and a Makefile-driven dev environment with seed data. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/auth/csrf.go')
-rw-r--r--internal/auth/csrf.go20
1 files changed, 20 insertions, 0 deletions
diff --git a/internal/auth/csrf.go b/internal/auth/csrf.go
new file mode 100644
index 0000000..da34309
--- /dev/null
+++ b/internal/auth/csrf.go
@@ -0,0 +1,20 @@
+package auth
+
+import (
+ "crypto/hmac"
+ "crypto/sha256"
+ "encoding/hex"
+ "fmt"
+)
+
+// CSRFToken derives a per-user token from the secret; it changes whenever the
+// user's token_version changes (password reset, disable) and needs no storage.
+func CSRFToken(secret []byte, userID int64, tokenVersion int) string {
+ m := hmac.New(sha256.New, secret)
+ fmt.Fprintf(m, "csrf:%d:%d", userID, tokenVersion)
+ return hex.EncodeToString(m.Sum(nil))
+}
+
+func CheckCSRF(secret []byte, userID int64, tokenVersion int, got string) bool {
+ return hmac.Equal([]byte(CSRFToken(secret, userID, tokenVersion)), []byte(got))
+}