import type { NextFunction, Request, Response } from 'express' import jwt, { type JwtPayload } from 'jsonwebtoken' export type OsintClaims = JwtPayload & { role?: string; isAdmin?: boolean; name?:string; preferred_username?:string } declare global { namespace Express { interface Request { authClaims?: OsintClaims } } } export function authenticateJwt(req: Request, _res: Response, next: NextFunction) { const authorization = req.headers.authorization const token = req.cookies?.auth_token || (authorization?.startsWith('Bearer ') ? authorization.slice(7) : undefined) const secret = process.env.JWT_SECRET if (token && secret) { try { const decoded = jwt.verify(token, secret) if (typeof decoded !== 'string') req.authClaims = decoded as OsintClaims } catch { /* An absent, expired, or invalid cookie is an anonymous session. */ } } next() } export function hasAdminClaim(req: Request) { return req.authClaims?.role === 'admin' || req.authClaims?.isAdmin === true } /** * Identity for a player's game state. Real players arrive with a JWT issued by * glitch.university (verified through the key-exchange handoff); until that lands, * an absent token resolves to a single fixed development user so the game is * playable locally with no identity provider. Only this fallback branch changes * when the external handoff is wired — the `user_id` column stays the same. */ export const DEVELOPMENT_TEST_USER_ID = 'osint-test-player' export function resolveUserId(req: Request): string { const sub = req.authClaims?.sub return typeof sub === 'string' && sub.length > 0 ? sub : DEVELOPMENT_TEST_USER_ID } export function resolvePlayerName(req: Request): string { const candidate = req.authClaims?.name || req.authClaims?.preferred_username || req.authClaims?.sub return typeof candidate === 'string' && candidate.trim() ? candidate.trim().slice(0,300) : 'Player' } export function requireAdmin(req: Request, res: Response, next: NextFunction) { if (!hasAdminClaim(req)) return res.status(403).json({ error: 'Administrator claim required' }) next() } // Mint a player token (path A: GUPI is the issuer for now). Verification is // issuer-agnostic — a glitch.university token with the same sub verifies identically. export function signPlayerToken(user: { id: string; displayName: string }) { if (!process.env.JWT_SECRET) throw new Error('JWT_SECRET is required') return jwt.sign({ sub: user.id, name: user.displayName, role: 'player' }, process.env.JWT_SECRET, { expiresIn: '30d' }) } export function createDevelopmentAdminToken() { if (process.env.NODE_ENV === 'production') throw new Error('Development sessions are disabled in production') if (!process.env.JWT_SECRET) throw new Error('JWT_SECRET is required') return jwt.sign({ sub: 'osint-local-admin', role: 'admin', isAdmin: true }, process.env.JWT_SECRET, { expiresIn: '7d' }) }