upleb.uk

Public git repos — served from a NIP-34 GRASP relay at git.upleb.uk

summaryrefslogtreecommitdiff
path: root/98.md
diff options
context:
space:
mode:
Diffstat (limited to '98.md')
-rw-r--r--98.md63
1 files changed, 63 insertions, 0 deletions
diff --git a/98.md b/98.md
new file mode 100644
index 0000000..be425b2
--- /dev/null
+++ b/98.md
@@ -0,0 +1,63 @@
1NIP-98
2======
3
4HTTP Auth
5---------
6
7`draft` `optional`
8
9This NIP defines an ephemeral event used to authorize requests to HTTP servers using nostr events.
10
11This is useful for HTTP services which are built for Nostr and deal with Nostr user accounts.
12
13## Nostr event
14
15A `kind 27235` (In reference to [RFC 7235](https://www.rfc-editor.org/rfc/rfc7235)) event is used.
16
17The `content` SHOULD be empty.
18
19The following tags MUST be included.
20
21* `u` - absolute URL
22* `method` - HTTP Request Method
23
24Example event:
25```json
26{
27 "id": "fe964e758903360f28d8424d092da8494ed207cba823110be3a57dfe4b578734",
28 "pubkey": "63fe6318dc58583cfe16810f86dd09e18bfd76aabc24a0081ce2856f330504ed",
29 "content": "",
30 "kind": 27235,
31 "created_at": 1682327852,
32 "tags": [
33 ["u", "https://api.snort.social/api/v1/n5sp/list"],
34 ["method", "GET"]
35 ],
36 "sig": "5ed9d8ec958bc854f997bdc24ac337d005af372324747efe4a00e24f4c30437ff4dd8308684bed467d9d6be3e5a517bb43b1732cc7d33949a3aaf86705c22184"
37}
38```
39
40Servers MUST perform the following checks in order to validate the event:
411. The `kind` MUST be `27235`.
422. The `created_at` timestamp MUST be within a reasonable time window (suggestion 60 seconds).
433. The `u` tag MUST be exactly the same as the absolute request URL (including query parameters).
444. The `method` tag MUST be the same HTTP method used for the requested resource.
45
46When the request contains a body (as in POST/PUT/PATCH methods) clients SHOULD include a SHA256 hash of the request body in a `payload` tag as hex (`["payload", "<sha256-hex>"]`), servers MAY check this to validate that the requested payload is authorized.
47
48If one of the checks was to fail the server SHOULD respond with a 401 Unauthorized response code.
49
50Servers MAY perform additional implementation-specific validation checks.
51
52## Request Flow
53
54Using the `Authorization` HTTP header, the `kind 27235` event MUST be `base64` encoded and use the Authorization scheme `Nostr`
55
56Example HTTP Authorization header:
57```
58Authorization: Nostr
59eyJpZCI6ImZlOTY0ZTc1ODkwMzM2MGYyOGQ4NDI0ZDA5MmRhODQ5NGVkMjA3Y2JhODIzMTEwYmUzYTU3ZGZlNGI1Nzg3MzQiLCJwdWJrZXkiOiI2M2ZlNjMxOGRjNTg1ODNjZmUxNjgxMGY4NmRkMDllMThiZmQ3NmFhYmMyNGEwMDgxY2UyODU2ZjMzMDUwNGVkIiwiY29udGVudCI6IiIsImtpbmQiOjI3MjM1LCJjcmVhdGVkX2F0IjoxNjgyMzI3ODUyLCJ0YWdzIjpbWyJ1IiwiaHR0cHM6Ly9hcGkuc25vcnQuc29jaWFsL2FwaS92MS9uNXNwL2xpc3QiXSxbIm1ldGhvZCIsIkdFVCJdXSwic2lnIjoiNWVkOWQ4ZWM5NThiYzg1NGY5OTdiZGMyNGFjMzM3ZDAwNWFmMzcyMzI0NzQ3ZWZlNGEwMGUyNGY0YzMwNDM3ZmY0ZGQ4MzA4Njg0YmVkNDY3ZDlkNmJlM2U1YTUxN2JiNDNiMTczMmNjN2QzMzk0OWEzYWFmODY3MDVjMjIxODQifQ
60```
61
62## Reference Implementations
63- C# ASP.NET `AuthenticationHandler` [NostrAuth.cs](https://gist.github.com/v0l/74346ae530896115bfe2504c8cd018d3)