Build Packages / Create release (push) Successful in 24s
Build Packages / build:viewer:macos-arm64:nocuda (push) Successful in 3m29s
Build Packages / build:rugnux:macos-arm64:nocuda (push) Successful in 2m43s
Build Packages / build:rugnux:linux-aarch64:cuda (push) Successful in 8m27s
Build Packages / build:rugnux:linux-x86_64:cuda (push) Successful in 9m53s
Build Packages / build:viewer:linux-x86_64:nocuda (push) Successful in 9m58s
Build Packages / build:viewer:linux-x86_64:cuda (push) Successful in 11m22s
Build Packages / build:jfjoch:rocky8:nocuda (push) Successful in 13m39s
Build Packages / build:viewer:windows-x86_64:nocuda (push) Successful in 18m37s
Build Packages / build:jfjoch:rocky9:nocuda (push) Successful in 16m32s
Build Packages / build:viewer:windows-x86_64:cuda (push) Successful in 24m11s
Build Packages / HDF5 consumer tests (DIALS, XDS) (push) Successful in 25m30s
Build Packages / build:jfjoch:ubuntu2404:nocuda (push) Successful in 19m3s
Build Packages / build:jfjoch:ubuntu2204:nocuda (push) Successful in 20m23s
Build Packages / build:jfjoch:rocky8:cuda-sls9 (push) Successful in 19m41s
Build Packages / Generate python client (push) Successful in 50s
Build Packages / Build documentation (push) Successful in 1m16s
Build Packages / build:jfjoch:rocky9:cuda-sls9 (push) Successful in 21m0s
Build Packages / build:jfjoch:rocky8:cuda (push) Successful in 18m38s
Build Packages / build:rugnux:windows-x86_64:cuda (push) Successful in 14m33s
Build Packages / build:jfjoch:rocky9:cuda (push) Successful in 17m55s
Build Packages / build:jfjoch:ubuntu2204:cuda (push) Successful in 20m50s
Build Packages / build:jfjoch:ubuntu2404:cuda (push) Successful in 18m38s
Build Packages / Unit tests (push) Successful in 1h46m14s
* jfjoch_broker: Optional per-dataset authentication - statistics, images and plots can require a bearer token, which jfjoch_viewer supports. * jfjoch_viewer: Dark mode and a theme-matched colour scheme, a magnifier panel, and simpler contrast and background controls. * Rugnux: Multiple performance improvements on GPU and CPU (CPU-only processing up to 40% faster, faster image decoding on ARM), with unchanged results. * Rugnux: `--model` rigid-body refinement runs on the GPU, and the model-validation check is faster and more reliable. * Rugnux: Improved scaling and merging - error model, outlier rejection, absorption correction and French-Wilson amplitudes now agree more closely with XDS and ctruncate. * Rugnux: Improved integration - radial background on powder and ice rings, crowded rotation data keep their reflections, and CPU-only builds integrate large unit cells as GPU builds do. * Rugnux: More robust detector geometry - measured beam centre, X-ray bandwidth and goniometer rate, and geometry refinement accepted only on significant evidence. * Rugnux: Merged files are written in the standard setting, or in the setting of a reference MTZ, structure-factor mmCIF or model, with its free-R flags. * Rugnux: Richer report - ice and powder rings, further lattices, superstructure candidates and mosaicity, with warnings worded as prompts to check. * Rugnux: Clear error messages when a data set needs more GPU or host memory than is available. Reviewed-on: #83 Co-authored-by: Filip Leonarski <filip.leonarski@psi.ch>
60 lines
2.0 KiB
C++
60 lines
2.0 KiB
C++
// SPDX-FileCopyrightText: 2026 Filip Leonarski, Paul Scherrer Institute <filip.leonarski@psi.ch>
|
|
// SPDX-License-Identifier: GPL-3.0-only
|
|
|
|
#include "BearerTokens.h"
|
|
|
|
#include <cctype>
|
|
|
|
namespace {
|
|
// Every byte is examined even after the first mismatch, so the comparison time does not
|
|
// reveal how long the matching prefix was.
|
|
bool ConstantTimeEqual(const std::string &a, const std::string &b) {
|
|
if (a.size() != b.size())
|
|
return false;
|
|
volatile unsigned char diff = 0;
|
|
for (size_t i = 0; i < a.size(); i++)
|
|
diff |= static_cast<unsigned char>(a[i] ^ b[i]);
|
|
return diff == 0;
|
|
}
|
|
|
|
// RFC 6750: the scheme name is case-insensitive and is followed by one or more spaces and the
|
|
// token. Returns the token, or nothing when the header is not a bearer credential.
|
|
std::optional<std::string> BearerToken(const std::string &header) {
|
|
if (header.size() < 7)
|
|
return std::nullopt;
|
|
std::string scheme = header.substr(0, 6);
|
|
for (auto &c: scheme)
|
|
c = static_cast<char>(std::tolower(static_cast<unsigned char>(c)));
|
|
if (scheme != "bearer" || header[6] != ' ')
|
|
return std::nullopt;
|
|
size_t start = header.find_first_not_of(' ', 6);
|
|
if (start == std::string::npos)
|
|
return std::nullopt;
|
|
size_t end = header.find_last_not_of(" \t\r\n");
|
|
return header.substr(start, end - start + 1);
|
|
}
|
|
}
|
|
|
|
void BearerTokens::Replace(std::vector<std::string> input) {
|
|
std::unique_lock ul(m);
|
|
tokens.clear();
|
|
for (auto &t: input)
|
|
if (!t.empty())
|
|
tokens.push_back(std::move(t));
|
|
}
|
|
|
|
bool BearerTokens::Accept(const std::optional<std::string> &authorization) const {
|
|
std::unique_lock ul(m);
|
|
if (tokens.empty())
|
|
return true;
|
|
if (!authorization)
|
|
return false;
|
|
auto presented = BearerToken(*authorization);
|
|
if (!presented)
|
|
return false;
|
|
for (const auto &t: tokens)
|
|
if (ConstantTimeEqual(t, *presented))
|
|
return true;
|
|
return false;
|
|
}
|