use super::{Caller, Peer, Request, Response, rest_error};
pub(super) fn sign_in_required() -> Response {
rest_error(
401,
"unauthorized",
"sign in: send an API token as Authorization: Bearer (isb token create)",
)
.header("WWW-Authenticate", "Bearer")
}
pub fn origin(req: &Request, caller: &Caller, mcp: bool) -> crate::audit::Origin {
let surface = match (&req.peer, mcp, caller) {
(Peer::Unix { .. }, _, _) => "cli",
(_, true, _) => "mcp",
(_, false, Caller::User { principal })
if matches!(principal.kind, crate::auth::PrincipalKind::Session { .. }) =>
{
"web"
}
_ => "rest",
};
let sane = |s: &&str| {
!s.is_empty()
&& s.len() <= 64
&& s.bytes()
.all(|b| b.is_ascii_alphanumeric() || matches!(b, b'-' | b'_' | b'.' | b':'))
};
let request_id = req
.header("x-request-id")
.filter(sane)
.or_else(|| req.header("cf-ray").filter(sane))
.map(String::from)
.unwrap_or_else(new_request_id);
crate::audit::Origin {
surface: surface.into(),
ip: crate::auth::http::client_ip(req),
user_agent: req.header("user-agent").map(String::from),
request_id: Some(request_id),
}
}
fn new_request_id() -> String {
use ring::rand::SecureRandom;
let mut b = [0u8; 8];
let _ = ring::rand::SystemRandom::new().fill(&mut b);
b.iter().map(|x| format!("{x:02x}")).collect()
}