mirror of
https://github.com/wahyd4/ruby-sdk.git
synced 2026-08-09 04:46:10 +10:00
添加Auth.generate_uptoken()方法,厘清上传授权凭证签发算法。
This commit is contained in:
@@ -8,6 +8,113 @@ require 'qiniu/exceptions'
|
||||
|
||||
module Qiniu
|
||||
module Auth
|
||||
class << self
|
||||
def calculate_deadline(expires_in, deadline = nil)
|
||||
### 授权期计算
|
||||
if expires_in.is_a?(Integer) && expires_in > 0 then
|
||||
# 指定相对时间,单位:秒
|
||||
return Time.now.to_i + expires_in
|
||||
elsif deadline.is_a?(Integer) then
|
||||
# 指定绝对时间,常用于调试和单元测试
|
||||
return deadline
|
||||
end
|
||||
|
||||
# 默认授权期1小时
|
||||
return Time.now.to_i + 3600
|
||||
end # calculate_deadline
|
||||
end # class << self
|
||||
|
||||
class PutPolicy
|
||||
private
|
||||
def initialize(bucket, key = nil, expires_in = 3600, deadline = nil)
|
||||
### 设定scope参数(必填项目)
|
||||
self.scope!(bucket, key)
|
||||
|
||||
### 设定deadline参数(必填项目)
|
||||
@expires_in = expires_in
|
||||
@deadline = Auth.calculate_deadline(expires_in, deadline)
|
||||
end # initialize
|
||||
|
||||
PARAMS = {
|
||||
:scope => "scope" ,
|
||||
:save_key => "saveKey" ,
|
||||
:end_user => "endUser" ,
|
||||
:return_url => "returnUrl" ,
|
||||
:return_body => "returnBody" ,
|
||||
:callback_url => "callbackUrl" ,
|
||||
:callback_body => "callbackBody" ,
|
||||
:persistent_ops => "persistentOps" ,
|
||||
:persistent_notify_url => "persistentNotifyUrl" ,
|
||||
:transform => "transform" ,
|
||||
|
||||
:deadline => "deadline" ,
|
||||
:insert_only => "insertOnly" ,
|
||||
:fsize_limit => "fsizeLimit" ,
|
||||
:detect_mime => "detectMime" ,
|
||||
:mime_limit => "mimeLimit" ,
|
||||
:fop_timeout => "fopTimeout"
|
||||
}
|
||||
|
||||
public
|
||||
attr_reader :bucket, :key
|
||||
|
||||
def scope!(bucket, key = nil)
|
||||
@bucket = bucket
|
||||
@key = key
|
||||
|
||||
if key.nil? then
|
||||
# 新增语义,文件已存在则失败
|
||||
@scope = bucket
|
||||
else
|
||||
# 覆盖语义,文件已存在则直接覆盖
|
||||
@scope = "#{bucket}:#{key}"
|
||||
end
|
||||
end # scope!
|
||||
|
||||
def expires_in!(seconds)
|
||||
if !seconds.nil? then
|
||||
return @expires_in
|
||||
end
|
||||
|
||||
@epires_in = seconds
|
||||
@deadline = Auth.calculate_deadline(seconds)
|
||||
|
||||
return @expires_in
|
||||
end # expires_in!
|
||||
|
||||
def allow_mime_list! (list)
|
||||
@mime_limit = list
|
||||
end # allow_mime_list!
|
||||
|
||||
def deny_mime_list! (list)
|
||||
@mime_limit = "!#{list}"
|
||||
end # deny_mime_list!
|
||||
|
||||
def insert_only!
|
||||
@insert_only = 1
|
||||
end # insert_only!
|
||||
|
||||
def detect_mime!
|
||||
@detect_mime = 1
|
||||
end # detect_mime!
|
||||
|
||||
def to_json
|
||||
args = {}
|
||||
|
||||
PARAMS.each_pair do |key, fld|
|
||||
val = self.public_send(key)
|
||||
if !val.nil? then
|
||||
args[fld] = val
|
||||
end
|
||||
end
|
||||
|
||||
return args.to_json
|
||||
end # to_json
|
||||
|
||||
PARAMS.each_pair do |key, fld|
|
||||
attr_accessor key
|
||||
end
|
||||
end # class PutPolicy
|
||||
|
||||
class << self
|
||||
|
||||
@@ -101,6 +208,21 @@ module Qiniu
|
||||
return acctoken
|
||||
end # generate_acctoken
|
||||
|
||||
def generate_uptoken(put_policy)
|
||||
### 提取AK/SK信息
|
||||
access_key = Config.settings[:access_key]
|
||||
secret_key = Config.settings[:secret_key]
|
||||
|
||||
### 生成待签名字符串
|
||||
encoded_put_policy = Utils.urlsafe_base64_encode(put_policy.to_json)
|
||||
|
||||
### 生成数字签名
|
||||
sign = HMAC::SHA1.new(secret_key).update(encoded_put_policy).digest
|
||||
encoded_sign = Utils.urlsafe_base64_encode(sign)
|
||||
|
||||
### 生成上传授权凭证
|
||||
uptoken = "#{access_key}:#{encoded_sign}:#{encoded_put_policy}"
|
||||
end # generate_uptoken
|
||||
end # class << self
|
||||
|
||||
end # module Auth
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
# -*- encoding: utf-8 -*-
|
||||
# vim: sw=2 ts=2
|
||||
|
||||
module Qiniu
|
||||
module Storage
|
||||
@@ -61,6 +62,27 @@ module Qiniu
|
||||
Utils.http_request url, post_data
|
||||
end # upload_with_token_2
|
||||
|
||||
### 授权举例
|
||||
# put_policy.bucket | put_policy.key | key | 语义 | 授权
|
||||
# :---------------- | :------------- | :------ | :--- | :---
|
||||
# trivial_bucket | <nil> | <nil> | 新增 | 允许,最终key为1)使用put_policy.save_key生成的值或2)资源内容的Hash值
|
||||
# trivial_bucket | <nil> | foo.txt | 新增 | 允许
|
||||
# trivial_bucket | <nil> | bar.jpg | 新增 | 允许
|
||||
# trivial_bucket | foo.txt | <nil> | 覆盖 | 允许,由SDK将put_policy.key赋值给key实现
|
||||
# trivial_bucket | foo.txt | foo.txt | 覆盖 | 允许
|
||||
# trivial_bucket | foo.txt | bar.jpg | 覆盖 | 禁止,put_policy.key与key不一致
|
||||
def upload_with_put_policy(put_policy,
|
||||
local_file,
|
||||
key = nil,
|
||||
x_vars = nil)
|
||||
uptoken = Auth.generate_uptoken(put_policy)
|
||||
if key.nil? then
|
||||
key = put_policy.key
|
||||
end
|
||||
|
||||
return upload_with_token_2(uptoken, local_file, key, x_vars)
|
||||
end # upload_with_put_policy
|
||||
|
||||
private
|
||||
def _generate_action_params(local_file,
|
||||
bucket,
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
# -*- encoding: utf-8 -*-
|
||||
# vim: sw=2 ts=2
|
||||
|
||||
require 'spec_helper'
|
||||
require 'qiniu/auth'
|
||||
@@ -126,6 +127,49 @@ module Qiniu
|
||||
end
|
||||
end
|
||||
|
||||
context ".upload_with_put_policy" do
|
||||
it "should works" do
|
||||
pp = Qiniu::Auth::PutPolicy.new(@bucket, @key)
|
||||
pp.end_user = "why404@gmail.com"
|
||||
puts 'put_policy=' + pp.to_json
|
||||
|
||||
code, data, raw_headers = Qiniu::Storage.upload_with_put_policy(
|
||||
pp,
|
||||
__FILE__,
|
||||
@key + '-not-equal'
|
||||
)
|
||||
code.should_not == 200
|
||||
puts data.inspect
|
||||
puts raw_headers.inspect
|
||||
|
||||
code, data, raw_headers = Qiniu::Storage.upload_with_put_policy(
|
||||
pp,
|
||||
__FILE__,
|
||||
@key
|
||||
)
|
||||
|
||||
code.should == 200
|
||||
puts data.inspect
|
||||
puts raw_headers.inspect
|
||||
end
|
||||
end # .upload_with_put_policy
|
||||
|
||||
context ".stat" do
|
||||
it "should exists" do
|
||||
code, data = Qiniu::Storage.stat(@bucket, @key)
|
||||
puts data.inspect
|
||||
code.should == 200
|
||||
end
|
||||
end
|
||||
|
||||
context ".delete" do
|
||||
it "should works" do
|
||||
code, data = Qiniu::Storage.delete(@bucket, @key)
|
||||
puts data.inspect
|
||||
code.should == 200
|
||||
end
|
||||
end
|
||||
|
||||
### 测试断点续上传
|
||||
context ".resumable_upload_with_token" do
|
||||
it "should works" do
|
||||
|
||||
Reference in New Issue
Block a user