credential.go 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136
  1. package ccm
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "io"
  6. "net/http"
  7. "os"
  8. "os/user"
  9. "path/filepath"
  10. "time"
  11. E "github.com/sagernet/sing/common/exceptions"
  12. )
  13. const (
  14. oauth2ClientID = "9d1c250a-e61b-44d9-88ed-5944d1962f5e"
  15. oauth2TokenURL = "https://console.anthropic.com/v1/oauth/token"
  16. claudeAPIBaseURL = "https://api.anthropic.com"
  17. tokenRefreshBufferMs = 60000
  18. anthropicBetaOAuthValue = "oauth-2025-04-20"
  19. )
  20. func getRealUser() (*user.User, error) {
  21. if sudoUser := os.Getenv("SUDO_USER"); sudoUser != "" {
  22. sudoUserInfo, err := user.Lookup(sudoUser)
  23. if err == nil {
  24. return sudoUserInfo, nil
  25. }
  26. }
  27. return user.Current()
  28. }
  29. func getDefaultCredentialsPath() (string, error) {
  30. userInfo, err := getRealUser()
  31. if err != nil {
  32. return "", err
  33. }
  34. return filepath.Join(userInfo.HomeDir, ".claude", ".credentials.json"), nil
  35. }
  36. func readCredentialsFromFile(path string) (*oauthCredentials, error) {
  37. data, err := os.ReadFile(path)
  38. if err != nil {
  39. return nil, err
  40. }
  41. var credentialsContainer struct {
  42. ClaudeAIAuth *oauthCredentials `json:"claudeAiOauth,omitempty"`
  43. }
  44. err = json.Unmarshal(data, &credentialsContainer)
  45. if err != nil {
  46. return nil, err
  47. }
  48. if credentialsContainer.ClaudeAIAuth == nil {
  49. return nil, E.New("claudeAiOauth field not found in credentials")
  50. }
  51. return credentialsContainer.ClaudeAIAuth, nil
  52. }
  53. func writeCredentialsToFile(oauthCredentials *oauthCredentials, path string) error {
  54. data, err := json.MarshalIndent(map[string]any{
  55. "claudeAiOauth": oauthCredentials,
  56. }, "", " ")
  57. if err != nil {
  58. return err
  59. }
  60. return os.WriteFile(path, data, 0o600)
  61. }
  62. type oauthCredentials struct {
  63. AccessToken string `json:"accessToken"`
  64. RefreshToken string `json:"refreshToken"`
  65. ExpiresAt int64 `json:"expiresAt"`
  66. Scopes []string `json:"scopes,omitempty"`
  67. SubscriptionType string `json:"subscriptionType,omitempty"`
  68. IsMax bool `json:"isMax,omitempty"`
  69. }
  70. func (c *oauthCredentials) needsRefresh() bool {
  71. if c.ExpiresAt == 0 {
  72. return false
  73. }
  74. return time.Now().UnixMilli() >= c.ExpiresAt-tokenRefreshBufferMs
  75. }
  76. func refreshToken(httpClient *http.Client, credentials *oauthCredentials) (*oauthCredentials, error) {
  77. if credentials.RefreshToken == "" {
  78. return nil, E.New("refresh token is empty")
  79. }
  80. requestBody, err := json.Marshal(map[string]string{
  81. "grant_type": "refresh_token",
  82. "refresh_token": credentials.RefreshToken,
  83. "client_id": oauth2ClientID,
  84. })
  85. if err != nil {
  86. return nil, E.Cause(err, "marshal request")
  87. }
  88. request, err := http.NewRequest("POST", oauth2TokenURL, bytes.NewReader(requestBody))
  89. if err != nil {
  90. return nil, err
  91. }
  92. request.Header.Set("Content-Type", "application/json")
  93. request.Header.Set("Accept", "application/json")
  94. response, err := httpClient.Do(request)
  95. if err != nil {
  96. return nil, err
  97. }
  98. defer response.Body.Close()
  99. if response.StatusCode != http.StatusOK {
  100. body, _ := io.ReadAll(response.Body)
  101. return nil, E.New("refresh failed: ", response.Status, " ", string(body))
  102. }
  103. var tokenResponse struct {
  104. AccessToken string `json:"access_token"`
  105. RefreshToken string `json:"refresh_token"`
  106. ExpiresIn int `json:"expires_in"`
  107. }
  108. err = json.NewDecoder(response.Body).Decode(&tokenResponse)
  109. if err != nil {
  110. return nil, E.Cause(err, "decode response")
  111. }
  112. newCredentials := *credentials
  113. newCredentials.AccessToken = tokenResponse.AccessToken
  114. if tokenResponse.RefreshToken != "" {
  115. newCredentials.RefreshToken = tokenResponse.RefreshToken
  116. }
  117. newCredentials.ExpiresAt = time.Now().UnixMilli() + int64(tokenResponse.ExpiresIn)*1000
  118. return &newCredentials, nil
  119. }