6 Commits
Author SHA1 Message Date
sugoidogo 7e723b13ed remove extra comma 2025-10-25 08:04:02 -07:00
sugoidogo 31dd75f2f7 add docker build 2025-10-25 07:59:03 -07:00
sugoidogo 59f15b7e60 remove compiler output from git 2025-10-25 07:50:44 -07:00
sugoidogo d925b1ec19 update wrangler config and source maps 2025-10-25 07:41:20 -07:00
sugoidogo ee9eb17898 switch to dedicated source maps 2025-10-25 07:39:28 -07:00
sugoidogo db9828a518 refactor: typescript 2025-10-25 07:36:08 -07:00
19 changed files with 12074 additions and 1832 deletions
+102
View File
@@ -0,0 +1,102 @@
name: Docker
# This workflow uses actions that are not certified by GitHub.
# They are provided by a third-party and are governed by
# separate terms of service, privacy policy, and support
# documentation.
on:
push:
# Publish semver tags as releases.
tags: [ '*.*.*' ]
env:
# Use docker.io for Docker Hub if empty
REGISTRY: ghcr.io
# github.repository as <account>/<repo>
IMAGE_NAME: ${{ github.repository }}
jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
# This is used to complete the identity challenge
# with sigstore/fulcio when running outside of PRs.
id-token: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Install Worker Dependencies
run: npm install
- name: Compile Worker
run: npx selflare compile
- name: Generate Dockerfile
run: npx selflare docker
# Install the cosign tool except on PR
# https://github.com/sigstore/cosign-installer
- name: Install cosign
if: github.event_name != 'pull_request'
uses: sigstore/cosign-installer@59acb6260d9c0ba8f4a2f9d9b48431a222b68e20 #v3.5.0
with:
cosign-release: 'v2.2.4'
# Set up BuildKit Docker container builder to be able to build
# multi-platform images and export cache
# https://github.com/docker/setup-buildx-action
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3.0.0
# Login against a Docker registry except on PR
# https://github.com/docker/login-action
- name: Log into registry ${{ env.REGISTRY }}
if: github.event_name != 'pull_request'
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
# Extract metadata (tags, labels) for Docker
# https://github.com/docker/metadata-action
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@96383f45573cb7f253c731d3b3ab81c87ef81934 # v5.0.0
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
# Build and push Docker image with Buildx (don't push on PR)
# https://github.com/docker/build-push-action
- name: Build and push Docker image
id: build-and-push
uses: docker/build-push-action@0565240e2d4ab88bba5387d719585280857ece09 # v5.0.0
with:
context: .
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
# Sign the resulting Docker image digest except on PRs.
# This will only write to the public Rekor transparency log when the Docker
# repository is public to avoid leaking data. If you would like to publish
# transparency data even for private images, pass --force to cosign below.
# https://github.com/sigstore/cosign
- name: Sign the published Docker image
if: ${{ github.event_name != 'pull_request' }}
env:
# https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-an-intermediate-environment-variable
TAGS: ${{ steps.meta.outputs.tags }}
DIGEST: ${{ steps.build-and-push.outputs.digest }}
# This step uses the identity token to provision an ephemeral certificate
# against the sigstore community Fulcio instance.
run: echo "${TAGS}" | xargs -I {} cosign sign --yes {}@${DIGEST}
+15 -9
View File
@@ -92,14 +92,6 @@ web_modules/
.yarn-integrity .yarn-integrity
# dotenv environment variable files
.env
.env.development.local
.env.test.local
.env.production.local
.env.local
# parcel-bundler cache (https://parceljs.org/) # parcel-bundler cache (https://parceljs.org/)
.cache .cache
@@ -168,5 +160,19 @@ dist
# wrangler project # wrangler project
.dev.vars .dev.vars*
!.dev.vars.example
.env*
!.env.example
.wrangler/ .wrangler/
# selflare project
worker.capnp
docker-compose.yml
Dockerfile
# typescript output
static/*.js
static/*.js.map
+5
View File
@@ -0,0 +1,5 @@
{
"files.associations": {
"wrangler.json": "jsonc"
}
}
+2092 -357
View File
File diff suppressed because it is too large Load Diff
+9 -4
View File
@@ -1,12 +1,17 @@
{ {
"name": "twitch-cloud-ebs", "name": "twitch-cloud-ebs",
"version": "1.0.0", "version": "0.0.0",
"private": true,
"scripts": { "scripts": {
"deploy": "wrangler deploy", "deploy": "wrangler deploy",
"dev": "wrangler dev --ip=0.0.0.0" "dev": "wrangler dev",
"cf-typegen": "wrangler types"
}, },
"devDependencies": { "devDependencies": {
"@twurple/auth": "^7.2.1", "@sugoidogo/selflare": "^1.1.3",
"wrangler": "^3.60.3" "@twurple/auth": "^7.4.0",
"fetch-retry": "^6.0.0",
"typescript": "^5.5.2",
"wrangler": "^4.43.0"
} }
} }
-244
View File
@@ -1,244 +0,0 @@
//import * as ebs from '@twurple/ebs-helper'
/** @type {URL} */
let url = null
let validation = null
let headers = new Headers({
'access-control-allow-methods':'GET,HEAD,PUT,POST,DELETE,OPTIONS',
'access-control-allow-origin': '*',
'access-control-allow-headers': 'content-type, client-id, authorization',
'access-control-allow-private-network': 'true',
'cache-control': 'no-cache,private',
})
/**
* create a Response object with preset headers
* @param {BodyInit} body
* @param {ResponseInit} init
*/
function newResponse(body = undefined, init = undefined) {
if (!init) {
init = {}
}
if (!init.headers) {
init.headers = {}
}
Object.assign(init.headers, Object.fromEntries(headers))
if (!body && init.status && init.status >= 400) {
body = JSON.stringify({ status: init.status, message: init.statusText }) + '\n'
}
return new Response(body, init)
}
/**
*
* @param {Request} request
* @param {*} env
*/
async function validate(request, env) {
const authorization =
request.headers.get('authorization') ||
url.searchParams.get('authorization') || ''
const [type, helixToken, token] = authorization.split(' ')
if (type.toLowerCase() !== 'extension') {
let response = await fetch('https://id.twitch.tv/oauth2/validate', {
headers: { authorization: authorization },
})
if (!response.ok) {
return response
}
response = await response.json()
response.secret = env[response.client_id]
if (!response.secret) {
return newResponse(null, { status: 403, statusText: 'unauthorized client' })
}
return newResponse(JSON.stringify(response))
}
try {
const client_id = jwt.decode(helixToken).client_id
const secret = env[client_id]
if (!secret) {
throw new Error('unrecognized client id')
}
const validation = jwt.verify(token, Buffer.from(secret, 'base64'))
validation.client_id = client_id
validation.secret = secret
return newResponse(JSON.stringify(validation))
} catch (error) {
return newResponse(error.message, { status: 400 })
}
}
/**
*
* @param {Request} request
* @param {*} env
* @returns
*/
async function oauth2(request, env) {
if (url.pathname !== '/oauth2/token') {
return newResponse(null, { status: 404 })
}
if (!request.headers.get('content-type').includes('form')){
return newResponse(null, { status: 400, statusText:'content type must be form data' })
}
const requestBody = await request.formData()
if (!requestBody.has('client_id')) {
return newResponse('missing client_id', { status: 401, statusText: 'missing client_id' })
}
const client_secret = await env[requestBody.get('client_id')]
if (!client_secret) {
return newResponse(null, { status: 403,statusText:'unauthorized client' })
}
requestBody.append('client_secret', client_secret)
return fetch('https://id.twitch.tv/oauth2/token', {
method: 'POST',
body: requestBody
})
}
/**
*
* @param {Request} request
* @param {*} env
*/
async function storage(request, env) {
if (!validation.user_id) {
return newResponse(null, { status: 403, statusText: 'storage api requires user access token' })
}
const clientPath = validation.user_id + '/' + validation.client_id + '/'
const requestPath = url.pathname.replaceAll('/..', '')
const objectName = (clientPath + requestPath).replaceAll('//', '/')
console.debug(objectName)
if (request.method === 'GET') {
if (objectName.endsWith('/')){
const options = {
prefix: objectName,
cursor: url.searchParams.get("cursor") ?? undefined
}
const listing = await env.storage.list(options)
if (listing.truncated) {
headers.append('cursor', listing.cursor)
}
const list=new Set()
for(const object of listing.objects){
list.add(object.key.slice(objectName.length).split('/')[0])
}
headers.append('content-type', 'application/json')
return newResponse(JSON.stringify([...list]))
}
const object = await env.storage.get(objectName, {
range: request.headers,
onlyIf: request.headers,
})
if (object === null) {
return newResponse(null, {status:404})
}
object.writeHttpMetadata(headers)
headers.set('etag', object.httpEtag)
if (object.range) {
headers.set("content-range", `bytes ${object.range.offset}-${object.range.end ?? object.size - 1}/${object.size}`)
}
const status = object.body ? (request.headers.get("range") !== null ? 206 : 200) : 304
return newResponse(object.body, { status: status })
}
if (request.method === 'HEAD') {
const object = await env.storage.head(objectName)
if (object === null) {
return newResponse(null, { status: 404 })
}
const headers = new Headers()
object.writeHttpMetadata(headers)
headers.set('etag', object.httpEtag)
return newResponse(null, { headers: headers })
}
if (request.method === 'PUT' || request.method == 'POST') {
const object = await env.storage.put(objectName, request.body, {
httpMetadata: request.headers,
})
return newResponse(null, {
headers: {
'etag': object.httpEtag,
}
})
}
if (request.method === 'DELETE') {
await env.storage.delete(objectName)
return newResponse()
}
return newResponse(`Unsupported method`, {
status: 400
})
}
/**
*
* @param {Request} request
* @param {*} env
*/
async function ebs(request, env) {
//TODO
}
async function serve_static(request, env) {
/** @type {Response} */
let response = await env.static.fetch(request)
if (!response.ok) {
return response
}
response = await response.text()
if(url.pathname.endsWith('js')){
headers.set('content-type','text/javascript')
}
return newResponse(response)
}
export default {
/**
*
* @param {Request} request
* @param {*} env
*/
async fetch(request, env) {
if(request.method==='OPTIONS'){
return newResponse()
}
url = new URL(request.url)
if (env.serve_static) {
const response = await serve_static(url, env)
if (response.ok) {
return response
}
}
if (url.pathname.startsWith('/oauth2')) {
return oauth2(request, env)
}
validation = await validate(request, env)
if (!validation.ok) {
return validation
}
validation = await validation.json()
if (url.pathname.startsWith('/ebs')) {
return ebs(request, env)
}
if (env.storage) {
return storage(request, env)
}
return newResponse(null,{status:404})
},
};
+205
View File
@@ -0,0 +1,205 @@
//import * as ebs from '@twurple/ebs-helper'
/** @type {URL} */
let url: URL
let validation: any
let headers: Headers
/**
* create a Response object with preset headers
*/
function newResponse(body?: BodyInit, init?: ResponseInit) {
if (!init) {
init = {}
}
if (!init.headers) {
init.headers = {}
}
Object.assign(init.headers, Object.fromEntries(headers))
if (!body && init.status && init.status >= 400) {
body = JSON.stringify({ status: init.status, message: init.statusText }) + '\n'
}
return new Response(body, init)
}
async function validate(request: Request, env: Env) {
const authorization =
request.headers.get('authorization') ||
url.searchParams.get('authorization') || ''
const [type, helixToken, token] = authorization.split(' ')
let response: any = await fetch('https://id.twitch.tv/oauth2/validate', {
headers: { authorization: authorization },
})
if (!response.ok) {
return response
}
response = await response.json()
response.secret = await env.client_secrets.get(response.client_id)
if (!response.secret) {
return newResponse(undefined, { status: 403, statusText: 'unauthorized client' })
}
return newResponse(JSON.stringify(response))
}
async function oauth2(request: Request, env: Env) {
if (url.pathname !== '/oauth2/token') {
return newResponse(undefined, { status: 404 })
}
if (!request.headers.get('content-type')!.includes('form')) {
return newResponse(undefined, { status: 400, statusText: 'content type must be form data' })
}
const requestBody = await request.formData()
if (!requestBody.has('client_id')) {
return newResponse('missing client_id', { status: 401, statusText: 'missing client_id' })
}
const client_secret = await env.client_secrets.get(requestBody.get('client_id') as string)!
if (!client_secret) {
return newResponse(undefined, { status: 403, statusText: 'unauthorized client' })
}
requestBody.append('client_secret', client_secret)
return fetch('https://id.twitch.tv/oauth2/token', {
method: 'POST',
body: requestBody
})
}
async function storage(request: Request, env: Env) {
if (!validation.user_id) {
return newResponse(undefined, { status: 403, statusText: 'storage api requires user access token' })
}
const clientPath = validation.user_id + '/' + validation.client_id + '/'
const requestPath = url.pathname.replaceAll('/..', '')
const objectName = (clientPath + requestPath).replaceAll('//', '/')
console.debug(objectName)
if (request.method === 'GET') {
if (objectName.endsWith('/')) {
const options = {
prefix: objectName,
cursor: url.searchParams.get("cursor") ?? undefined
}
const listing = await env.storage.list(options)
if (listing.truncated) {
headers.append('cursor', listing.cursor)
}
const list = new Set()
for (const object of listing.objects) {
list.add(object.key.slice(objectName.length).split('/')[0])
}
headers.append('content-type', 'application/json')
return newResponse(JSON.stringify([...list]))
}
const object = await env.storage.get(objectName, {
range: request.headers,
onlyIf: request.headers,
})
if (object === null) {
return newResponse(undefined, { status: 404 })
}
object.writeHttpMetadata(headers)
headers.set('etag', object.httpEtag)
/* this came from a cloudflare example in javascript,
* but I can't find documentation on R2Range, so can't fix this.
if (object.range) {
headers.set("content-range", `bytes ${object.range.offset}-${object.range.end ?? object.size - 1}/${object.size}`)
}
*/
let responseBody: ReadableStream | undefined = undefined
if ('body' in object) {
responseBody = object.body
}
const status = responseBody ? (request.headers.get("range") !== null ? 206 : 200) : 304
return newResponse(responseBody, { status: status })
}
if (request.method === 'HEAD') {
const object = await env.storage.head(objectName)
if (object === null) {
return newResponse(undefined, { status: 404 })
}
const headers = new Headers()
object.writeHttpMetadata(headers)
headers.set('etag', object.httpEtag)
return newResponse(undefined, { headers: headers })
}
if (request.method === 'PUT' || request.method == 'POST') {
const object = await env.storage.put(objectName, request.body, {
httpMetadata: request.headers,
})
return newResponse(undefined, {
headers: {
'etag': object.httpEtag,
}
})
}
if (request.method === 'DELETE') {
await env.storage.delete(objectName)
return newResponse()
}
return newResponse(`Unsupported method`, {
status: 400
})
}
async function serve_static(request: Request, env: Env) {
if (url.pathname.endsWith('.mjs')) {
headers.append('Location', url.href.replace('.mjs', '.js'))
return newResponse(undefined, { status: 308 })
}
return newResponse(undefined, { status: 404 })
}
export default {
async fetch(request: Request, env: Env) {
url = new URL(request.url)
const host = request.headers.get('host')
if (host) {
url.host = host
}
const proto = request.headers.get('x-forwarded-proto')
if (proto) {
url.protocol = proto
}
headers = new Headers({
'access-control-allow-methods': 'GET,HEAD,PUT,POST,DELETE,OPTIONS',
'access-control-allow-origin': '*',
'access-control-allow-headers': 'content-type, client-id, authorization',
'access-control-allow-private-network': 'true',
'cache-control': 'no-cache,private',
})
if (request.method === 'OPTIONS') {
return newResponse()
}
{
const response = await serve_static(request, env)
if (response.status < 400) {
return response
}
}
if (url.pathname.startsWith('/oauth2')) {
return oauth2(request, env)
}
validation = await validate(request, env)
if (!validation.ok) {
return validation
}
validation = await validation.json()
if (env.storage) {
return storage(request, env)
}
return newResponse(undefined, { status: 404 })
},
};
-120
View File
@@ -1,120 +0,0 @@
import * as TwitchAuth from "./TwitchAuth.mjs";
function getTwurpleProxy(token){
return new Proxy(token,{
get(target, name, receiver){
return target[name.toString().replace(/[A-Z]/g, letter => `_${letter.toLowerCase()}`)]
}
})
}
/**
* @param {import("./TwitchAuth.mjs").TwitchToken} token
* @param {...string} scopes
*/
function hasScopes(token,...scopes){
if(!token){
return false
}
if(!scopes){
return true
}
for(const scope of scopes){
if(!token.scope.includes(scope)){
return false
}
}
return true
}
export default class SugoiAuthProvider {
/** @type {TwitchToken} */
#token;
/** @type {String} */
clientId;
constructor(client_id){
this.clientId=client_id
}
#setToken=(token)=>{
this.#token=token
return token
}
/**
* get a new token
* @param {String[]} scopes
* @returns {Promise<import("./TwitchAuth.mjs").TwitchToken>}
*/
async addUser(...scopes){
this.#token=TwitchAuth.getUserToken(this.clientId,...scopes).then(getTwurpleProxy).then(this.#setToken)
return this.#token
}
/**
* use an existing token
* @param {import("./TwitchAuth.mjs").TwitchToken} token
* @returns {import("./TwitchAuth.mjs").TwitchToken}
*/
async addUserForToken(token){
if(token.refresh_token){
this.#token=TwitchAuth.refreshToken(token.refresh_token).then(getTwurpleProxy).then(this.#setToken)
return this.#token
}
this.#token=TwitchAuth.validateToken(token.access_token).then(getTwurpleProxy).then(this.#setToken)
return this.#token
}
removeUser(){
this.#token=null
}
/**
* @param {String|Number} user
* @param {String[][]} scopeSets
* @returns {Promise<import("./TwitchAuth.mjs").TwitchToken | null>}
*/
async getAccessTokenForUser(user,...scopeSets){
if((!scopeSets[0]) && (this.#token)){
return this.#token
}
for(const scopes of scopeSets){
if(hasScopes(this.#token,...scopes)){
return this.#token
}
}
this.#token=TwitchAuth.getUserTokenPassive(this.clientId,...(scopeSets[0]||[])).then(getTwurpleProxy).then(this.#setToken)
return this.#token
}
/**
* @param {String|Number} user
* @returns {Promise<import("./TwitchAuth.mjs").TwitchToken>}
*/
getAnyAccessToken(user){
return this.#token || TwitchAuth.getAppToken(this.clientId)
}
/**
* @param {String|Number} user
* @returns {String[]}
*/
getCurrentScopesForUser(user){
if(!this.#token || this.#token instanceof Promise){
return []
}
return this.#token.scope
}
/**
* @param {String|Number} user
* @returns {Promise<import("./TwitchAuth.mjs").TwitchToken>}
*/
async refreshAccessTokenForUser(user){
this.#token=TwitchAuth.refreshToken(this.#token.refresh_token).then(this.#setToken)
return this.#token
}
}
+2
View File
@@ -0,0 +1,2 @@
/*
access-control-allow-origin: *
-63
View File
@@ -1,63 +0,0 @@
import * as TwitchAuth from './TwitchAuth.mjs'
/** @type {import('./TwitchAuth.mjs').TwitchToken} */
let token=null;
export function request_auth(client_id,scope,redirect_uri=location.origin+location.pathname){
return TwitchAuth.requestAuthCode(client_id,...scope.split(' '))
}
export function get_url_params(){
return Object.fromEntries(new URLSearchParams(location.search))
}
export async function fetch_tokens(client_id,code,redirect_uri=location.origin+location.path){
client_id=client_id
token=await TwitchAuth.exchangeCode(client_id,code)
token.client_id=client_id
return token
}
export function get_headers(tokens){
return {
'Authorization':'Bearer '+tokens.access_token,
'Client-ID':tokens.client_id
}
}
export async function validate_tokens(tokens){
const validation=await TwitchAuth.validateToken(tokens.access_token)
Object.assign(tokens,validation)
tokens.scope=validation.scopes
tokens.auth_headers=get_headers(tokens)
token=tokens
return token
}
export function set_local_tokens(client_id,tokens){
token=tokens
return token
}
export function get_local_tokens(client_id){
return token
}
export async function refresh_tokens(client_id,refresh_token){
token=await TwitchAuth.refreshToken(client_id,refresh_token)
return token
}
export function set_refresh_timeout(client_id,tokens){
return setTimeout(()=>{
TwitchAuth.refreshToken(client_id,tokens.refresh_token)
.then(new_tokens=>Object.assign(tokens,new_tokens))
},tokens.expires_in*999)
}
export async function get_tokens(client_id,scope='',redirect_uri=location.origin+location.pathname,auth_return=false){
token=await TwitchAuth.getUserToken(client_id,...scope.split(' ')).then(validate_tokens)
set_refresh_timeout(client_id,token)
return token
}
export default get_tokens
+89
View File
@@ -0,0 +1,89 @@
import * as TwitchAuth from "./TwitchAuth.ts";
import { AccessTokenMaybeWithUserId, AuthProvider, AccessToken, AccessTokenWithUserId } from "@twurple/auth";
type Token = TwitchAuth.TwitchToken & AccessTokenMaybeWithUserId
function getTwurpleProxy(token: TwitchAuth.TwitchToken): Token {
return new Proxy(token, {
get(target, name, receiver) {
return target[name.toString().replace(/[A-Z]/g, letter => `_${letter.toLowerCase()}`)]
}
}) as Token
}
function hasScopes(token: Token, ...scopes: string[]) {
if (!token) {
return false
}
if (!scopes) {
return true
}
for (const scope of scopes) {
if (!token.scope.includes(scope)) {
return false
}
}
return true
}
export default class SugoiAuthProvider implements AuthProvider {
#token: Token
clientId: string;
constructor(client_id: string) {
this.clientId = client_id
}
#setToken = (token: Token) => {
this.#token = token
return token
}
async addUser(...scopes: string[]) {
this.#token = await TwitchAuth.getUserToken(this.clientId, ...scopes).then(getTwurpleProxy).then(this.#setToken)
return this.#token
}
async addUserForToken(token: TwitchAuth.TwitchToken) {
if (token.refresh_token) {
this.#token = await TwitchAuth.refreshToken(this.clientId, token.refresh_token).then(getTwurpleProxy).then(this.#setToken)
return this.#token
}
this.#token = await TwitchAuth.validateToken(token.access_token).then(getTwurpleProxy).then(this.#setToken)
return this.#token
}
removeUser() {
this.#token = null
}
async getAccessTokenForUser(user: string | number, ...scopeSets: string[][]) {
if ((!scopeSets[0]) && (this.#token)) {
return this.#token as AccessTokenWithUserId
}
for (const scopes of scopeSets) {
if (hasScopes(this.#token, ...scopes)) {
return this.#token as AccessTokenWithUserId
}
}
this.#token = await TwitchAuth.getUserTokenPassive(this.clientId, ...(scopeSets[0] || [])).then(getTwurpleProxy).then(this.#setToken)
return this.#token as AccessTokenWithUserId
}
async getAnyAccessToken(user: string | number) {
return this.#token || TwitchAuth.getAppToken(this.clientId).then(getTwurpleProxy)
}
getCurrentScopesForUser(user: string | number) {
if (!this.#token || this.#token instanceof Promise) {
return []
}
return this.#token.scope
}
async refreshAccessTokenForUser(user: string | number) {
this.#token = await TwitchAuth.refreshToken(this.clientId, this.#token.refresh_token).then(this.#setToken)
return this.#token as AccessTokenWithUserId
}
}
@@ -1,27 +1,25 @@
import fetch_retry from 'https://cdn.jsdelivr.net/npm/fetch-retry/+esm' import fetch_retry from 'fetch-retry'
const fetch = fetch_retry(globalThis.fetch, { const fetch = fetch_retry(globalThis.fetch, {
retries: 10, retries: 10,
retryDelay: attempts => attempts * 1000 retryDelay: attempts => attempts * 1000
}) })
/** export interface TwitchToken {
* @typedef {Object} TwitchToken access_token: string
* @property {String} access_token expires_in: number
* @property {Number} expires_in obtainment_timestamp: number
* @property {Number} obtainment_timestamp token_type: string
* @property {String} token_type user_id?: number
* @property {Number} [user_id] scope?: Array<string>
* @property {Array<String>} [scope] refresh_token?: string
* @property {String} [refresh_token] login?: string
* @property {String} [login] client_id?: string
* @property {String} [client_id] }
*/
/** export interface AuthCode {
* @typedef {Object} AuthCode code: string
* @property {String} code scope: string
* @property {String} scope }
*/
const redirect_uri = location.origin + location.pathname const redirect_uri = location.origin + location.pathname
const proxy_uri = new URL('/oauth2/token', import.meta.url) const proxy_uri = new URL('/oauth2/token', import.meta.url)
@@ -31,17 +29,17 @@ const proxy_uri = new URL('/oauth2/token', import.meta.url)
* @param {TwitchToken} token * @param {TwitchToken} token
* @returns {TwitchToken} * @returns {TwitchToken}
*/ */
function stamp(token) { function stamp(token: TwitchToken): TwitchToken {
token.obtainment_timestamp = Date.now() token.obtainment_timestamp = Date.now()
return token return token
} }
/** /**
* https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#client-credentials-grant-flow * https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#client-credentials-grant-flow
* @param {String} client_id * @param {string} client_id
* @returns {Promise<TwitchToken>} * @returns {Promise<TwitchToken>}
*/ */
export function getAppToken(client_id) { export function getAppToken(client_id: string): Promise<TwitchToken> {
const searchParams = new URLSearchParams({ const searchParams = new URLSearchParams({
client_id: client_id, client_id: client_id,
grant_type: 'client_credentials' grant_type: 'client_credentials'
@@ -61,11 +59,11 @@ export function getAppToken(client_id) {
/** /**
* https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#implicit-grant-flow * https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#implicit-grant-flow
* @param {String} client_id * @param {string} client_id
* @param {Array<String>|String} scopes * @param {Array<string>|string} scopes
* @returns {Promise<AuthCode>} * @returns {Promise<AuthCode>}
*/ */
export function requestAccessToken(client_id, ...scopes) { export function requestAccessToken(client_id: string, ...scopes: Array<string>) {
console.debug('requesting access token') console.debug('requesting access token')
const url = new URL('https://id.twitch.tv/oauth2/authorize') const url = new URL('https://id.twitch.tv/oauth2/authorize')
url.searchParams.append('response_type', 'token') url.searchParams.append('response_type', 'token')
@@ -76,11 +74,11 @@ export function requestAccessToken(client_id, ...scopes) {
/** /**
* https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#get-the-user-to-authorize-your-app * https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#get-the-user-to-authorize-your-app
* @param {String} client_id * @param {string} client_id
* @param {Array<String>|String} scopes * @param {Array<string>|string} scopes
* @returns {Promise<AuthCode>} * @returns {Promise<AuthCode>}
*/ */
export function requestAuthCode(client_id, ...scopes) { export function requestAuthCode(client_id: string, ...scopes: Array<string>): Promise<any> {
console.debug('requesting authorization code') console.debug('requesting authorization code')
const url = new URL('https://id.twitch.tv/oauth2/authorize') const url = new URL('https://id.twitch.tv/oauth2/authorize')
url.searchParams.append('response_type', 'code') url.searchParams.append('response_type', 'code')
@@ -92,11 +90,11 @@ export function requestAuthCode(client_id, ...scopes) {
/** /**
* https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#use-the-authorization-code-to-get-a-token * https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#use-the-authorization-code-to-get-a-token
* @param {String} client_id * @param {string} client_id
* @param {String} code * @param {string} code
* @returns {Promise<TwitchToken>} * @returns {Promise<TwitchToken>}
*/ */
export function exchangeCode(client_id, code) { export function exchangeCode(client_id: string, code: string): Promise<TwitchToken> {
console.debug('exchanging authorization code') console.debug('exchanging authorization code')
const searchParams = new URLSearchParams({ const searchParams = new URLSearchParams({
client_id: client_id, client_id: client_id,
@@ -118,10 +116,10 @@ export function exchangeCode(client_id, code) {
/** /**
* https://dev.twitch.tv/docs/authentication/validate-tokens/#how-to-validate-a-token * https://dev.twitch.tv/docs/authentication/validate-tokens/#how-to-validate-a-token
* @param {String} access_token * @param {string} access_token
* @returns {TwitchToken} * @returns {TwitchToken}
*/ */
export function validateToken(access_token) { export async function validateToken(access_token: string): Promise<TwitchToken> {
console.debug('validating token') console.debug('validating token')
return fetch('https://id.twitch.tv/oauth2/validate', { return fetch('https://id.twitch.tv/oauth2/validate', {
headers: { authorization: 'OAuth ' + access_token } headers: { authorization: 'OAuth ' + access_token }
@@ -130,7 +128,7 @@ export function validateToken(access_token) {
throw new Error(await response.text()) throw new Error(await response.text())
} }
/** @type {TwitchToken} */ /** @type {TwitchToken} */
const token = await response.json() const token: any = await response.json()
token.access_token = access_token token.access_token = access_token
token.scope = token.scopes token.scope = token.scopes
delete token.scopes delete token.scopes
@@ -141,11 +139,11 @@ export function validateToken(access_token) {
/** /**
* https://dev.twitch.tv/docs/authentication/refresh-tokens/#how-to-use-a-refresh-token * https://dev.twitch.tv/docs/authentication/refresh-tokens/#how-to-use-a-refresh-token
* @param {String} client_id * @param {string} client_id
* @param {String} refresh_token * @param {string} refresh_token
* @returns {Promise<TwitchToken>} * @returns {Promise<TwitchToken>}
*/ */
export function refreshToken(client_id, refresh_token) { export function refreshToken(client_id: string, refresh_token: string): Promise<TwitchToken> {
console.debug('refreshing token') console.debug('refreshing token')
const searchParams = new URLSearchParams({ const searchParams = new URLSearchParams({
client_id: client_id, client_id: client_id,
@@ -169,10 +167,10 @@ export function refreshToken(client_id, refresh_token) {
* refresh token, access token, or error message, in that order, * refresh token, access token, or error message, in that order,
* and if it finds none of those, starts the auth code grant flow. * and if it finds none of those, starts the auth code grant flow.
* https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#authorization-code-grant-flow * https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#authorization-code-grant-flow
* @param {String} client_id * @param {string} client_id
* @returns {TwitchToken} * @returns {TwitchToken}
*/ */
export async function getUserToken(client_id, ...scopes) { export async function getUserToken(client_id: string, ...scopes): Promise<TwitchToken> {
const token=await getUserTokenPassive(client_id, ...scopes) const token=await getUserTokenPassive(client_id, ...scopes)
if(!token){ if(!token){
return requestAuthCode(client_id, ...scopes) return requestAuthCode(client_id, ...scopes)
@@ -184,10 +182,10 @@ export async function getUserToken(client_id, ...scopes) {
* This function checks the url search parameters and hash for an auth code, * This function checks the url search parameters and hash for an auth code,
* refresh token, access token, or error message, in that order. * refresh token, access token, or error message, in that order.
* https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#authorization-code-grant-flow * https://dev.twitch.tv/docs/authentication/getting-tokens-oauth/#authorization-code-grant-flow
* @param {String} client_id * @param {string} client_id
* @returns {TwitchToken} * @returns {TwitchToken}
*/ */
export function getUserTokenPassive(client_id, ...scopes){ export async function getUserTokenPassive(client_id: string, ...scopes): Promise<TwitchToken>{
console.debug('scopes requested:',...scopes) console.debug('scopes requested:',...scopes)
const params = new URLSearchParams(location.search + '&' + location.hash.substring(1)) const params = new URLSearchParams(location.search + '&' + location.hash.substring(1))
if (params.has('code')) { if (params.has('code')) {
@@ -8,12 +8,9 @@
export default class WebStorage { export default class WebStorage {
#origin = new URL(import.meta.url).origin #origin = new URL(import.meta.url).origin
/** @type {import('@twurple/auth').AuthProvider} */ #auth_provider: import('@twurple/auth').AuthProvider = null;
#auth_provider = null; #cache: Cache = null
/** @type {Cache} */ #fetch: typeof globalThis.fetch = null
#cache = null
/** @type {fetch} */
#fetch = null
/** /**
* Creates a fetch request wrapper that returns cached responses when the server can't be reached. * Creates a fetch request wrapper that returns cached responses when the server can't be reached.
@@ -23,10 +20,10 @@ export default class WebStorage {
* @param {import('@twurple/auth').AuthProvider} auth_provider used to add the authentication header to requests for web storage * @param {import('@twurple/auth').AuthProvider} auth_provider used to add the authentication header to requests for web storage
* @param {fetch} fetch defaults to `globalThis.fetch`, allows you to further customize fetch behavior via chaining, for example with `fetch-retry` * @param {fetch} fetch defaults to `globalThis.fetch`, allows you to further customize fetch behavior via chaining, for example with `fetch-retry`
*/ */
constructor(auth_provider, fetch = (resource,options)=>{return globalThis.fetch(resource,options)}) { constructor(auth_provider: import('@twurple/auth').AuthProvider, fetch: typeof globalThis.fetch = (resource,options)=>{return globalThis.fetch(resource,options)}) {
this.#fetch = fetch this.#fetch = fetch
this.#auth_provider = auth_provider this.#auth_provider = auth_provider
auth_provider.getAccessTokenForUser() auth_provider.getAccessTokenForUser(undefined)
.then(token => caches.open(token.userId + '/' + auth_provider.clientId)) .then(token => caches.open(token.userId + '/' + auth_provider.clientId))
.then(cache => this.#cache = cache) .then(cache => this.#cache = cache)
} }
@@ -36,10 +33,10 @@ export default class WebStorage {
* @param {String | URL} resource * @param {String | URL} resource
* @param {RequestInit} options * @param {RequestInit} options
*/ */
async fetch(resource, options={}) { async fetch(resource: string | URL, options: RequestInit={}) {
resource = new URL(resource, this.#origin) resource = new URL(resource, this.#origin)
if (resource.origin == this.#origin) { if (resource.origin == this.#origin) {
const token = await this.#auth_provider.getAccessTokenForUser() const token = await this.#auth_provider.getAccessTokenForUser(undefined)
if (!options.headers) { if (!options.headers) {
options.headers = {} options.headers = {}
} }
+72
View File
@@ -0,0 +1,72 @@
import * as TwitchAuth from './TwitchAuth.ts'
interface AuthHeaders {
'Authorization': string,
'Client-ID': string
}
interface Token extends TwitchAuth.TwitchToken {
auth_headers: AuthHeaders
}
let token: Token=null;
export function request_auth(client_id: string,scope: string,redirect_uri=location.origin+location.pathname){
return TwitchAuth.requestAuthCode(client_id,...scope.split(' '))
}
export function get_url_params(){
return Object.fromEntries(new URLSearchParams(location.search))
}
export async function fetch_tokens(client_id: string,code: string,redirect_uri=location.origin+location.pathname): Promise<Token>{
client_id=client_id
token=await TwitchAuth.exchangeCode(client_id,code) as Token
token.client_id=client_id
return token
}
export function get_headers(tokens: Token): AuthHeaders{
return {
'Authorization':'Bearer '+tokens.access_token,
'Client-ID':tokens.client_id
}
}
export async function validate_tokens(tokens: Token): Promise<Token>{
const validation=await TwitchAuth.validateToken(tokens.access_token)
Object.assign(tokens,validation)
tokens.scope=validation.scope
tokens.auth_headers=get_headers(tokens)
token=tokens
return token
}
export function set_local_tokens(client_id: string,tokens: Token){
token=tokens
return token
}
export function get_local_tokens(client_id: string){
return token
}
export async function refresh_tokens(client_id: string,refresh_token: string){
token=await TwitchAuth.refreshToken(client_id,refresh_token) as Token
return token
}
export function set_refresh_timeout(client_id: string,tokens: Token){
return setTimeout(()=>{
TwitchAuth.refreshToken(client_id,tokens.refresh_token)
.then(new_tokens=>Object.assign(tokens,new_tokens))
},tokens.expires_in*999)
}
export async function get_tokens(client_id: string,scope='',redirect_uri=location.origin+location.pathname,auth_return=false){
token=await TwitchAuth.getUserToken(client_id,...scope.split(' ')).then(validate_tokens)
set_refresh_timeout(client_id,token)
return token
}
export default get_tokens
+9
View File
@@ -0,0 +1,9 @@
{
"compilerOptions": {
"target": "es2020",
"module": "es2020",
"moduleResolution": "node",
"allowImportingTsExtensions": true,
"noEmit": true,
}
}
+45
View File
@@ -0,0 +1,45 @@
{
"compilerOptions": {
/* Visit https://aka.ms/tsconfig.json to read more about this file */
/* Set the JavaScript language version for emitted JavaScript and include compatible library declarations. */
"target": "es2021",
/* Specify a set of bundled library declaration files that describe the target runtime environment. */
"lib": ["es2021"],
/* Specify what JSX code is generated. */
"jsx": "react-jsx",
/* Specify what module code is generated. */
"module": "es2022",
/* Specify how TypeScript looks up a file from a given module specifier. */
"moduleResolution": "Bundler",
/* Enable importing .json files */
"resolveJsonModule": true,
/* Allow JavaScript files to be a part of your program. Use the `checkJS` option to get errors from these files. */
"allowJs": true,
/* Enable error reporting in type-checked JavaScript files. */
"checkJs": false,
/* Disable emitting files from a compilation. */
"noEmit": true,
/* Ensure that each file can be safely transpiled without relying on other imports. */
"isolatedModules": true,
/* Allow 'import x from y' when a module doesn't have a default export. */
"allowSyntheticDefaultImports": true,
/* Ensure that casing is correct in imports. */
"forceConsistentCasingInFileNames": true,
/* Enable all strict type-checking options. */
"strict": true,
/* Skip type checking all .d.ts files. */
"skipLibCheck": true,
"types": [
"./worker-configuration.d.ts"
]
},
"exclude": ["test"],
"include": ["worker-configuration.d.ts", "src/**/*.ts"]
}
+8400
View File
File diff suppressed because it is too large Load Diff
+40
View File
@@ -0,0 +1,40 @@
/**
* For more details on how to configure Wrangler, refer to:
* https://developers.cloudflare.com/workers/wrangler/configuration/
*/
{
"$schema": "node_modules/wrangler/config-schema.json",
"name": "twitch-cloud-ebs",
"main": "src/index.ts",
"compatibility_date": "2025-10-14",
"workers_dev": false,
"preview_urls": false,
"compatibility_flags": [
"global_fetch_strictly_public"
],
"assets": {
"directory": "./static"
},
"observability": {
"enabled": true
},
"placement": {
"mode": "smart"
},
"kv_namespaces": [
{
"binding": "client_secrets",
"id": "bacfae340a2d45428ba085a00773ba99"
}
],
"r2_buckets": [
{
"binding": "storage",
"bucket_name": "sugoi-web-services",
"jurisdiction": "eu"
}
],
"build": {
"command": "esbuild static_src/*.ts --outdir=static --bundle --format=esm --minify --sourcemap --target=es2020"
}
}
-41
View File
@@ -1,41 +0,0 @@
#:schema node_modules/wrangler/config-schema.json
name = "twitch-cloud-ebs"
main = "src/index.js"
compatibility_date = "2025-01-09"
[route]
pattern="ebs.sugoidogo.com"
custom_domain=true
# Workers Logs
# Docs: https://developers.cloudflare.com/workers/observability/logs/workers-logs/
[observability]
enabled = true
# Workers Assets
# Docs: https://developers.cloudflare.com/workers/static-assets/binding/
[assets]
directory = "./static/"
binding = "static"
experimental_serve_directly = false
# Variable bindings. These are arbitrary, plaintext strings (similar to environment variables)
# Docs:
# - https://developers.cloudflare.com/workers/wrangler/configuration/#environment-variables
# Use secrets to store sensitive data.
# - https://developers.cloudflare.com/workers/configuration/secrets/
[vars]
serve_static = true
# Automatically place your workloads in an optimal location to minimize latency.
# Docs: https://developers.cloudflare.com/workers/configuration/smart-placement/#smart-placement
# [placement]
# mode = "smart"
# Bind an R2 Bucket. Use R2 to store arbitrarily large blobs of data, such as files.
# Docs: https://developers.cloudflare.com/workers/wrangler/configuration/#r2-buckets
[[r2_buckets]]
binding = "storage"
bucket_name = "sugoi-web-services"
preview_bucket_name = "sugoi-web-services-testing"
jurisdiction = "eu"