view mod_measure_storage/mod_measure_storage.lua @ 5616:59d5fc50f602

mod_http_oauth2: Implement refresh token rotation Makes refresh tokens one-time-use, handing out a new refresh token with each access token. Thus if a refresh token is stolen and used by an attacker, the next time the legitimate client tries to use the previous refresh token, it will not work and the attack will be noticed. If the attacker does not use the refresh token, it becomes invalid after the legitimate client uses it. This behavior is recommended by draft-ietf-oauth-security-topics
author Kim Alvefur <zash@zash.se>
date Sun, 23 Jul 2023 02:56:08 +0200
parents 04ae5b45e6c7
children
line wrap: on
line source

module:set_global()

local function return_args_after_calling(f, ...)
	f();
	return ...
end

local function time_method(module, store_name, store_type, method_name, method_function)
	local opt_use_tags = module:get_option_boolean("measure_storage_tagged_metric", false);

	local metric_name, metric_tags;
	if opt_use_tags then
		metric_name, metric_tags = "storage_operation", ("store_name:%s,store_type:%s,store_operation:%s"):format(store_name, store_type, method_name);
	else
		metric_name = store_name.."_"..store_type.."_"..method_name;
	end
	local measure_operation_started = module:measure(metric_name, "times", metric_tags);

	return function (...)
		module:log("debug", "Measuring storage operation %s (%s)", metric_name, metric_tags or "no tags");
		local measure_operation_complete = measure_operation_started();
		return return_args_after_calling(measure_operation_complete, method_function(...));
	end;
end

local function wrap_store(module, store_name, store_type, store)
	local new_store = setmetatable({}, {
		__index = function (t, method_name)
			local original_method = store[method_name];
			if type(original_method) ~= "function" then
				if original_method then
					rawset(t, method_name, original_method);
				end
				return original_method;
			end
			local timed_method = time_method(module, store_name, store_type, method_name, original_method);
			rawset(t, method_name, timed_method);
			return timed_method;
		end;
	});
	return new_store;
end

local function hook_event(module)
	module:hook("store-opened", function(event)
		event.store = wrap_store(module, event.store_name, event.store_type or "keyval", event.store);
	end);
end

function module.load()
	hook_event(module);
end

function module.add_host(module)
	hook_event(module);
end