credential.go 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173
  1. package ocm
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "io"
  6. "net/http"
  7. "os"
  8. "os/user"
  9. "path/filepath"
  10. "time"
  11. E "github.com/sagernet/sing/common/exceptions"
  12. )
  13. const (
  14. oauth2ClientID = "app_EMoamEEZ73f0CkXaXp7hrann"
  15. oauth2TokenURL = "https://auth.openai.com/oauth/token"
  16. openaiAPIBaseURL = "https://api.openai.com"
  17. chatGPTBackendURL = "https://chatgpt.com/backend-api/codex"
  18. tokenRefreshIntervalDays = 8
  19. )
  20. func getRealUser() (*user.User, error) {
  21. if sudoUser := os.Getenv("SUDO_USER"); sudoUser != "" {
  22. sudoUserInfo, err := user.Lookup(sudoUser)
  23. if err == nil {
  24. return sudoUserInfo, nil
  25. }
  26. }
  27. return user.Current()
  28. }
  29. func getDefaultCredentialsPath() (string, error) {
  30. if codexHome := os.Getenv("CODEX_HOME"); codexHome != "" {
  31. return filepath.Join(codexHome, "auth.json"), nil
  32. }
  33. userInfo, err := getRealUser()
  34. if err != nil {
  35. return "", err
  36. }
  37. return filepath.Join(userInfo.HomeDir, ".codex", "auth.json"), nil
  38. }
  39. func readCredentialsFromFile(path string) (*oauthCredentials, error) {
  40. data, err := os.ReadFile(path)
  41. if err != nil {
  42. return nil, err
  43. }
  44. var credentials oauthCredentials
  45. err = json.Unmarshal(data, &credentials)
  46. if err != nil {
  47. return nil, err
  48. }
  49. return &credentials, nil
  50. }
  51. func writeCredentialsToFile(credentials *oauthCredentials, path string) error {
  52. data, err := json.MarshalIndent(credentials, "", " ")
  53. if err != nil {
  54. return err
  55. }
  56. return os.WriteFile(path, data, 0o600)
  57. }
  58. type oauthCredentials struct {
  59. APIKey string `json:"OPENAI_API_KEY,omitempty"`
  60. Tokens *tokenData `json:"tokens,omitempty"`
  61. LastRefresh *time.Time `json:"last_refresh,omitempty"`
  62. }
  63. type tokenData struct {
  64. IDToken string `json:"id_token,omitempty"`
  65. AccessToken string `json:"access_token"`
  66. RefreshToken string `json:"refresh_token"`
  67. AccountID string `json:"account_id,omitempty"`
  68. }
  69. func (c *oauthCredentials) isAPIKeyMode() bool {
  70. return c.APIKey != ""
  71. }
  72. func (c *oauthCredentials) getAccessToken() string {
  73. if c.APIKey != "" {
  74. return c.APIKey
  75. }
  76. if c.Tokens != nil {
  77. return c.Tokens.AccessToken
  78. }
  79. return ""
  80. }
  81. func (c *oauthCredentials) getAccountID() string {
  82. if c.Tokens != nil {
  83. return c.Tokens.AccountID
  84. }
  85. return ""
  86. }
  87. func (c *oauthCredentials) needsRefresh() bool {
  88. if c.APIKey != "" {
  89. return false
  90. }
  91. if c.Tokens == nil || c.Tokens.RefreshToken == "" {
  92. return false
  93. }
  94. if c.LastRefresh == nil {
  95. return true
  96. }
  97. return time.Since(*c.LastRefresh) >= time.Duration(tokenRefreshIntervalDays)*24*time.Hour
  98. }
  99. func refreshToken(httpClient *http.Client, credentials *oauthCredentials) (*oauthCredentials, error) {
  100. if credentials.Tokens == nil || credentials.Tokens.RefreshToken == "" {
  101. return nil, E.New("refresh token is empty")
  102. }
  103. requestBody, err := json.Marshal(map[string]string{
  104. "grant_type": "refresh_token",
  105. "refresh_token": credentials.Tokens.RefreshToken,
  106. "client_id": oauth2ClientID,
  107. "scope": "openid profile email",
  108. })
  109. if err != nil {
  110. return nil, E.Cause(err, "marshal request")
  111. }
  112. request, err := http.NewRequest("POST", oauth2TokenURL, bytes.NewReader(requestBody))
  113. if err != nil {
  114. return nil, err
  115. }
  116. request.Header.Set("Content-Type", "application/json")
  117. request.Header.Set("Accept", "application/json")
  118. response, err := httpClient.Do(request)
  119. if err != nil {
  120. return nil, err
  121. }
  122. defer response.Body.Close()
  123. if response.StatusCode != http.StatusOK {
  124. body, _ := io.ReadAll(response.Body)
  125. return nil, E.New("refresh failed: ", response.Status, " ", string(body))
  126. }
  127. var tokenResponse struct {
  128. IDToken string `json:"id_token"`
  129. AccessToken string `json:"access_token"`
  130. RefreshToken string `json:"refresh_token"`
  131. }
  132. err = json.NewDecoder(response.Body).Decode(&tokenResponse)
  133. if err != nil {
  134. return nil, E.Cause(err, "decode response")
  135. }
  136. newCredentials := *credentials
  137. if newCredentials.Tokens == nil {
  138. newCredentials.Tokens = &tokenData{}
  139. }
  140. if tokenResponse.IDToken != "" {
  141. newCredentials.Tokens.IDToken = tokenResponse.IDToken
  142. }
  143. if tokenResponse.AccessToken != "" {
  144. newCredentials.Tokens.AccessToken = tokenResponse.AccessToken
  145. }
  146. if tokenResponse.RefreshToken != "" {
  147. newCredentials.Tokens.RefreshToken = tokenResponse.RefreshToken
  148. }
  149. now := time.Now()
  150. newCredentials.LastRefresh = &now
  151. return &newCredentials, nil
  152. }