credential.go 3.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139
  1. package ccm
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "io"
  6. "net/http"
  7. "os"
  8. "os/user"
  9. "path/filepath"
  10. "time"
  11. E "github.com/sagernet/sing/common/exceptions"
  12. )
  13. const (
  14. oauth2ClientID = "9d1c250a-e61b-44d9-88ed-5944d1962f5e"
  15. oauth2TokenURL = "https://console.anthropic.com/v1/oauth/token"
  16. claudeAPIBaseURL = "https://api.anthropic.com"
  17. tokenRefreshBufferMs = 60000
  18. anthropicBetaOAuthValue = "oauth-2025-04-20"
  19. )
  20. func getRealUser() (*user.User, error) {
  21. if sudoUser := os.Getenv("SUDO_USER"); sudoUser != "" {
  22. sudoUserInfo, err := user.Lookup(sudoUser)
  23. if err == nil {
  24. return sudoUserInfo, nil
  25. }
  26. }
  27. return user.Current()
  28. }
  29. func getDefaultCredentialsPath() (string, error) {
  30. if configDir := os.Getenv("CLAUDE_CONFIG_DIR"); configDir != "" {
  31. return filepath.Join(configDir, ".credentials.json"), nil
  32. }
  33. userInfo, err := getRealUser()
  34. if err != nil {
  35. return "", err
  36. }
  37. return filepath.Join(userInfo.HomeDir, ".claude", ".credentials.json"), nil
  38. }
  39. func readCredentialsFromFile(path string) (*oauthCredentials, error) {
  40. data, err := os.ReadFile(path)
  41. if err != nil {
  42. return nil, err
  43. }
  44. var credentialsContainer struct {
  45. ClaudeAIAuth *oauthCredentials `json:"claudeAiOauth,omitempty"`
  46. }
  47. err = json.Unmarshal(data, &credentialsContainer)
  48. if err != nil {
  49. return nil, err
  50. }
  51. if credentialsContainer.ClaudeAIAuth == nil {
  52. return nil, E.New("claudeAiOauth field not found in credentials")
  53. }
  54. return credentialsContainer.ClaudeAIAuth, nil
  55. }
  56. func writeCredentialsToFile(oauthCredentials *oauthCredentials, path string) error {
  57. data, err := json.MarshalIndent(map[string]any{
  58. "claudeAiOauth": oauthCredentials,
  59. }, "", " ")
  60. if err != nil {
  61. return err
  62. }
  63. return os.WriteFile(path, data, 0o600)
  64. }
  65. type oauthCredentials struct {
  66. AccessToken string `json:"accessToken"`
  67. RefreshToken string `json:"refreshToken"`
  68. ExpiresAt int64 `json:"expiresAt"`
  69. Scopes []string `json:"scopes,omitempty"`
  70. SubscriptionType string `json:"subscriptionType,omitempty"`
  71. IsMax bool `json:"isMax,omitempty"`
  72. }
  73. func (c *oauthCredentials) needsRefresh() bool {
  74. if c.ExpiresAt == 0 {
  75. return false
  76. }
  77. return time.Now().UnixMilli() >= c.ExpiresAt-tokenRefreshBufferMs
  78. }
  79. func refreshToken(httpClient *http.Client, credentials *oauthCredentials) (*oauthCredentials, error) {
  80. if credentials.RefreshToken == "" {
  81. return nil, E.New("refresh token is empty")
  82. }
  83. requestBody, err := json.Marshal(map[string]string{
  84. "grant_type": "refresh_token",
  85. "refresh_token": credentials.RefreshToken,
  86. "client_id": oauth2ClientID,
  87. })
  88. if err != nil {
  89. return nil, E.Cause(err, "marshal request")
  90. }
  91. request, err := http.NewRequest("POST", oauth2TokenURL, bytes.NewReader(requestBody))
  92. if err != nil {
  93. return nil, err
  94. }
  95. request.Header.Set("Content-Type", "application/json")
  96. request.Header.Set("Accept", "application/json")
  97. response, err := httpClient.Do(request)
  98. if err != nil {
  99. return nil, err
  100. }
  101. defer response.Body.Close()
  102. if response.StatusCode != http.StatusOK {
  103. body, _ := io.ReadAll(response.Body)
  104. return nil, E.New("refresh failed: ", response.Status, " ", string(body))
  105. }
  106. var tokenResponse struct {
  107. AccessToken string `json:"access_token"`
  108. RefreshToken string `json:"refresh_token"`
  109. ExpiresIn int `json:"expires_in"`
  110. }
  111. err = json.NewDecoder(response.Body).Decode(&tokenResponse)
  112. if err != nil {
  113. return nil, E.Cause(err, "decode response")
  114. }
  115. newCredentials := *credentials
  116. newCredentials.AccessToken = tokenResponse.AccessToken
  117. if tokenResponse.RefreshToken != "" {
  118. newCredentials.RefreshToken = tokenResponse.RefreshToken
  119. }
  120. newCredentials.ExpiresAt = time.Now().UnixMilli() + int64(tokenResponse.ExpiresIn)*1000
  121. return &newCredentials, nil
  122. }