mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-01 12:31:59 +00:00
chore(security): apply golangci-lint fixes to lookup and security packages
This commit is contained in:
@@ -2,6 +2,7 @@ package security
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
)
|
||||
|
||||
|
||||
@@ -159,11 +159,3 @@ func (ks *DatabaseKeyStore) validateKeyLoad(ctx context.Context, hash, cacheKey
|
||||
func keystoreCacheKey(hash string) string {
|
||||
return "keystore:validate:" + hash
|
||||
}
|
||||
|
||||
// nullStringOr returns s.String if valid, otherwise the fallback.
|
||||
func nullStringOr(s sql.NullString, fallback string) string {
|
||||
if s.Valid && s.String != "" {
|
||||
return s.String
|
||||
}
|
||||
return fallback
|
||||
}
|
||||
|
||||
@@ -261,7 +261,7 @@ func (r *passkeyRouter) Store(ctx context.Context, rec lookup.PasskeyCredentialR
|
||||
return st.Store(ctx, rec)
|
||||
}
|
||||
|
||||
func (r *passkeyRouter) Get(ctx context.Context, credentialID string) (int, uint32, error) {
|
||||
func (r *passkeyRouter) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
|
||||
st, err := pick[lookup.PasskeyStore](r.c, ctx, lookup.OpPasskeyGet, r.c.procs.PasskeyGetCredential, r.proc, r.direct)
|
||||
if err != nil {
|
||||
return 0, 0, err
|
||||
|
||||
@@ -499,7 +499,7 @@ func (s *suite) seed(t *testing.T, table string, cols []string, vals ...any) {
|
||||
}
|
||||
args[i] = v
|
||||
}
|
||||
q := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)", table, strings.Join(cols, ", "), strings.Join(ph, ", "))
|
||||
q := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)", table, strings.Join(cols, ", "), strings.Join(ph, ", ")) //nolint:gosec // test seeding with fixed table names
|
||||
if _, err := s.DB.ExecContext(ctx, q, args...); err != nil {
|
||||
t.Fatalf("seed %s: %v", table, err)
|
||||
}
|
||||
@@ -526,8 +526,8 @@ func (s *suite) policy(t *testing.T) {
|
||||
t.Fatalf("column rules (user + group, exact table, active only): %d %v %+v", len(rules), err, rules)
|
||||
}
|
||||
paths := map[string]bool{}
|
||||
for _, r := range rules {
|
||||
paths[strings.Join(r.Path, ".")] = true
|
||||
for i := range rules {
|
||||
paths[strings.Join(rules[i].Path, ".")] = true
|
||||
}
|
||||
if !paths["email"] || !paths["profile.ssn"] {
|
||||
t.Fatalf("paths: %v", paths)
|
||||
|
||||
@@ -429,9 +429,9 @@ func (b *Base) Insert(e lookup.Entity) *Insert { return &Insert{b: b, e: e} }
|
||||
// Set adds assignments.
|
||||
func (i *Insert) Set(as ...Assignment) *Insert { i.sets = append(i.sets, as...); return i }
|
||||
|
||||
func (i *Insert) colsAndArgs() ([]string, []any) {
|
||||
cols := make([]string, len(i.sets))
|
||||
args := make([]any, len(i.sets))
|
||||
func (i *Insert) colsAndArgs() (cols []string, args []any) {
|
||||
cols = make([]string, len(i.sets))
|
||||
args = make([]any, len(i.sets))
|
||||
for n, a := range i.sets {
|
||||
cols[n] = i.b.colName(a.Col)
|
||||
args[n] = i.b.arg(a.Val)
|
||||
|
||||
@@ -68,10 +68,9 @@ func (p *Passkey) Store(ctx context.Context, rec lookup.PasskeyCredentialRecord)
|
||||
}
|
||||
|
||||
// Get implements lookup.PasskeyStore.
|
||||
func (p *Passkey) Get(ctx context.Context, credentialID string) (int, uint32, error) {
|
||||
var userID int
|
||||
func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
|
||||
var count int64
|
||||
err := p.do(func(q Querier) error {
|
||||
err = p.do(func(q Querier) error {
|
||||
return p.From(lookup.EntityUserPasskeyCredentials).Cols(lookup.PasskeyUserID, lookup.PasskeySignCount).
|
||||
Where(Eq(lookup.PasskeyCredentialID, credentialID)).QueryRow(ctx, q, &userID, &count)
|
||||
})
|
||||
|
||||
@@ -44,7 +44,7 @@ const (
|
||||
OpSession Op = "session"
|
||||
OpTouchSession Op = "touch_session"
|
||||
OpRefresh Op = "refresh"
|
||||
OpLoginAPIKey Op = "login_api_key"
|
||||
OpLoginAPIKey Op = "login_api_key" //nolint:gosec // operation name, not a credential
|
||||
OpJWTLogin Op = "jwt_login"
|
||||
OpJWTLogout Op = "jwt_logout"
|
||||
OpResetRequest Op = "reset_request"
|
||||
@@ -64,8 +64,8 @@ const (
|
||||
|
||||
OpOAuthGetOrCreateUser Op = "oauth_get_or_create_user"
|
||||
OpOAuthCreateSession Op = "oauth_create_session"
|
||||
OpOAuthGetRefreshToken Op = "oauth_get_refresh_token"
|
||||
OpOAuthUpdateRefreshToken Op = "oauth_update_refresh_token"
|
||||
OpOAuthGetRefreshToken Op = "oauth_get_refresh_token" //nolint:gosec // operation name, not a credential
|
||||
OpOAuthUpdateRefreshToken Op = "oauth_update_refresh_token" //nolint:gosec // operation name, not a credential
|
||||
OpOAuthGetUser Op = "oauth_get_user"
|
||||
|
||||
OpPasskeyStore Op = "passkey_store"
|
||||
@@ -74,7 +74,7 @@ const (
|
||||
OpPasskeyList Op = "passkey_list"
|
||||
OpPasskeyDelete Op = "passkey_delete"
|
||||
OpPasskeyRename Op = "passkey_rename"
|
||||
OpPasskeyByUsername Op = "passkey_by_username"
|
||||
OpPasskeyByUsername Op = "passkey_by_username" //nolint:gosec // operation name, not a credential
|
||||
OpPasskeyLogin Op = "passkey_login"
|
||||
|
||||
OpTOTPEnable Op = "totp_enable"
|
||||
|
||||
@@ -38,7 +38,7 @@ func normalizeTimes(raw []byte) []byte {
|
||||
func fixTimes(m map[string]any) {
|
||||
for k, v := range m {
|
||||
s, ok := v.(string)
|
||||
if !ok || !(strings.HasSuffix(k, "_at") || k == "expiry") {
|
||||
if !ok || (!strings.HasSuffix(k, "_at") && k != "expiry") {
|
||||
continue
|
||||
}
|
||||
if _, err := time.Parse(time.RFC3339Nano, s); err == nil {
|
||||
|
||||
@@ -68,7 +68,7 @@ func (p *Passkey) Store(ctx context.Context, rec lookup.PasskeyCredentialRecord)
|
||||
}
|
||||
|
||||
// Get implements lookup.PasskeyStore.
|
||||
func (p *Passkey) Get(ctx context.Context, credentialID string) (int, uint32, error) {
|
||||
func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
|
||||
raw, err := decodeCredentialID(credentialID)
|
||||
if err != nil {
|
||||
return 0, 0, err
|
||||
|
||||
@@ -22,7 +22,7 @@ const (
|
||||
EntityUserSessions Entity = "user_sessions"
|
||||
EntityTokenBlacklist Entity = "token_blacklist"
|
||||
EntityUserTOTPBackupCodes Entity = "user_totp_backup_codes"
|
||||
EntityUserPasskeyCredentials Entity = "user_passkey_credentials"
|
||||
EntityUserPasskeyCredentials Entity = "user_passkey_credentials" //nolint:gosec // table name, not a credential
|
||||
EntityUserPasswordResets Entity = "user_password_resets"
|
||||
EntityOAuthClients Entity = "oauth_clients"
|
||||
EntityOAuthCodes Entity = "oauth_codes"
|
||||
|
||||
@@ -3,10 +3,11 @@ package providers
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
)
|
||||
|
||||
// KeyStoreAuthenticator implements the Authenticator interface using a KeyStore.
|
||||
|
||||
@@ -7,10 +7,11 @@ import (
|
||||
"encoding/base64"
|
||||
"encoding/hex"
|
||||
"fmt"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
"sync"
|
||||
"sync/atomic"
|
||||
"time"
|
||||
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
)
|
||||
|
||||
// ConfigKeyStore is an in-memory keystore backed by a static slice of UserKey values.
|
||||
|
||||
@@ -3,8 +3,9 @@ package totp
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
"net/http"
|
||||
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
)
|
||||
|
||||
// BaseAuthenticator is the subset of security.Authenticator that Authenticator wraps.
|
||||
|
||||
@@ -4,8 +4,9 @@ import (
|
||||
"crypto/sha256"
|
||||
"encoding/hex"
|
||||
"fmt"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
"sync"
|
||||
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
)
|
||||
|
||||
// MemoryProvider is an in-memory implementation of AuthProvider for testing/examples
|
||||
|
||||
@@ -9,12 +9,13 @@ import (
|
||||
"encoding/base32"
|
||||
"encoding/binary"
|
||||
"fmt"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
"hash"
|
||||
"math"
|
||||
"net/url"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
)
|
||||
|
||||
// AuthProvider defines interface for 2FA operations
|
||||
|
||||
@@ -6,6 +6,7 @@ import (
|
||||
"database/sql"
|
||||
"encoding/hex"
|
||||
"fmt"
|
||||
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/lookup"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/totp"
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user