package main import ( "crypto/subtle" "net/http" "strings" ) const bearerPrefix = "Bearer " // withAuth guards a handler with a constant-time bearer-token check. func withAuth(token string, next http.Handler) http.Handler { want := []byte(token) return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { h := r.Header.Get("Authorization") if !strings.HasPrefix(h, bearerPrefix) { http.Error(w, "unauthorized", http.StatusUnauthorized) return } got := []byte(strings.TrimPrefix(h, bearerPrefix)) if subtle.ConstantTimeCompare(got, want) != 1 { http.Error(w, "unauthorized", http.StatusUnauthorized) return } next.ServeHTTP(w, r) }) } // withCORS reflects the request Origin only when it is in allowed, answers // preflight OPTIONS with 204, and passes everything else through. It wraps the // auth middleware so preflight (which carries no Authorization header) is never // rejected by auth. func withCORS(allowed []string, next http.Handler) http.Handler { set := make(map[string]struct{}, len(allowed)) for _, o := range allowed { set[o] = struct{}{} } return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { origin := r.Header.Get("Origin") if _, ok := set[origin]; ok && origin != "" { w.Header().Set("Access-Control-Allow-Origin", origin) w.Header().Add("Vary", "Origin") w.Header().Set("Access-Control-Allow-Methods", "GET,PUT,DELETE,OPTIONS") w.Header().Set("Access-Control-Allow-Headers", "Authorization,Content-Type") w.Header().Set("Access-Control-Max-Age", "86400") } if r.Method == http.MethodOptions { w.WriteHeader(http.StatusNoContent) return } next.ServeHTTP(w, r) }) }