package password import ( "clapclap/internal/apperr" "github.com/gin-gonic/gin" ) type Authenticator struct { getUserID func(c *gin.Context) error getHashedPassword func(c *gin.Context) (string, error) getExpectedHash func(c *gin.Context) (string, error) compare func(string, string) error } func (a *Authenticator) Authenticate(c *gin.Context) { err := a.getUserID(c) if err != nil { apperr.AbortWithError(c, apperr.NewUnauthorizedError(err, "Invalid identifier")) return } hashed, err := a.getHashedPassword(c) if err != nil { apperr.AbortWithError(c, apperr.NewUnauthorizedError(err, "Failed to read password")) return } expected, err := a.getExpectedHash(c) if err != nil { apperr.AbortWithError(c, apperr.NewUnauthorizedError(err, "Account not found or password not set")) return } err = a.compare(hashed, expected) if err != nil { apperr.AbortWithError(c, apperr.NewUnauthorizedError(err, "Incorrect password")) return } // if we reached this point, we must have a valid userID in the context c.Next() }