chore(security): apply golangci-lint fixes to lookup and security packages

This commit is contained in:
Hein
2026-10-01 13:21:00 +02:00
parent c9fa8c60f2
commit 2516fcb13d
16 changed files with 29 additions and 31 deletions
+1
View File
@@ -2,6 +2,7 @@ package security
import (
"context"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
)
-8
View File
@@ -159,11 +159,3 @@ func (ks *DatabaseKeyStore) validateKeyLoad(ctx context.Context, hash, cacheKey
func keystoreCacheKey(hash string) string {
return "keystore:validate:" + hash
}
// nullStringOr returns s.String if valid, otherwise the fallback.
func nullStringOr(s sql.NullString, fallback string) string {
if s.Valid && s.String != "" {
return s.String
}
return fallback
}
+1 -1
View File
@@ -261,7 +261,7 @@ func (r *passkeyRouter) Store(ctx context.Context, rec lookup.PasskeyCredentialR
return st.Store(ctx, rec)
}
func (r *passkeyRouter) Get(ctx context.Context, credentialID string) (int, uint32, error) {
func (r *passkeyRouter) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
st, err := pick[lookup.PasskeyStore](r.c, ctx, lookup.OpPasskeyGet, r.c.procs.PasskeyGetCredential, r.proc, r.direct)
if err != nil {
return 0, 0, err
@@ -499,7 +499,7 @@ func (s *suite) seed(t *testing.T, table string, cols []string, vals ...any) {
}
args[i] = v
}
q := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)", table, strings.Join(cols, ", "), strings.Join(ph, ", "))
q := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)", table, strings.Join(cols, ", "), strings.Join(ph, ", ")) //nolint:gosec // test seeding with fixed table names
if _, err := s.DB.ExecContext(ctx, q, args...); err != nil {
t.Fatalf("seed %s: %v", table, err)
}
@@ -526,8 +526,8 @@ func (s *suite) policy(t *testing.T) {
t.Fatalf("column rules (user + group, exact table, active only): %d %v %+v", len(rules), err, rules)
}
paths := map[string]bool{}
for _, r := range rules {
paths[strings.Join(r.Path, ".")] = true
for i := range rules {
paths[strings.Join(rules[i].Path, ".")] = true
}
if !paths["email"] || !paths["profile.ssn"] {
t.Fatalf("paths: %v", paths)
+3 -3
View File
@@ -429,9 +429,9 @@ func (b *Base) Insert(e lookup.Entity) *Insert { return &Insert{b: b, e: e} }
// Set adds assignments.
func (i *Insert) Set(as ...Assignment) *Insert { i.sets = append(i.sets, as...); return i }
func (i *Insert) colsAndArgs() ([]string, []any) {
cols := make([]string, len(i.sets))
args := make([]any, len(i.sets))
func (i *Insert) colsAndArgs() (cols []string, args []any) {
cols = make([]string, len(i.sets))
args = make([]any, len(i.sets))
for n, a := range i.sets {
cols[n] = i.b.colName(a.Col)
args[n] = i.b.arg(a.Val)
+2 -3
View File
@@ -68,10 +68,9 @@ func (p *Passkey) Store(ctx context.Context, rec lookup.PasskeyCredentialRecord)
}
// Get implements lookup.PasskeyStore.
func (p *Passkey) Get(ctx context.Context, credentialID string) (int, uint32, error) {
var userID int
func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
var count int64
err := p.do(func(q Querier) error {
err = p.do(func(q Querier) error {
return p.From(lookup.EntityUserPasskeyCredentials).Cols(lookup.PasskeyUserID, lookup.PasskeySignCount).
Where(Eq(lookup.PasskeyCredentialID, credentialID)).QueryRow(ctx, q, &userID, &count)
})
+4 -4
View File
@@ -44,7 +44,7 @@ const (
OpSession Op = "session"
OpTouchSession Op = "touch_session"
OpRefresh Op = "refresh"
OpLoginAPIKey Op = "login_api_key"
OpLoginAPIKey Op = "login_api_key" //nolint:gosec // operation name, not a credential
OpJWTLogin Op = "jwt_login"
OpJWTLogout Op = "jwt_logout"
OpResetRequest Op = "reset_request"
@@ -64,8 +64,8 @@ const (
OpOAuthGetOrCreateUser Op = "oauth_get_or_create_user"
OpOAuthCreateSession Op = "oauth_create_session"
OpOAuthGetRefreshToken Op = "oauth_get_refresh_token"
OpOAuthUpdateRefreshToken Op = "oauth_update_refresh_token"
OpOAuthGetRefreshToken Op = "oauth_get_refresh_token" //nolint:gosec // operation name, not a credential
OpOAuthUpdateRefreshToken Op = "oauth_update_refresh_token" //nolint:gosec // operation name, not a credential
OpOAuthGetUser Op = "oauth_get_user"
OpPasskeyStore Op = "passkey_store"
@@ -74,7 +74,7 @@ const (
OpPasskeyList Op = "passkey_list"
OpPasskeyDelete Op = "passkey_delete"
OpPasskeyRename Op = "passkey_rename"
OpPasskeyByUsername Op = "passkey_by_username"
OpPasskeyByUsername Op = "passkey_by_username" //nolint:gosec // operation name, not a credential
OpPasskeyLogin Op = "passkey_login"
OpTOTPEnable Op = "totp_enable"
+1 -1
View File
@@ -38,7 +38,7 @@ func normalizeTimes(raw []byte) []byte {
func fixTimes(m map[string]any) {
for k, v := range m {
s, ok := v.(string)
if !ok || !(strings.HasSuffix(k, "_at") || k == "expiry") {
if !ok || (!strings.HasSuffix(k, "_at") && k != "expiry") {
continue
}
if _, err := time.Parse(time.RFC3339Nano, s); err == nil {
+1 -1
View File
@@ -68,7 +68,7 @@ func (p *Passkey) Store(ctx context.Context, rec lookup.PasskeyCredentialRecord)
}
// Get implements lookup.PasskeyStore.
func (p *Passkey) Get(ctx context.Context, credentialID string) (int, uint32, error) {
func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
raw, err := decodeCredentialID(credentialID)
if err != nil {
return 0, 0, err
+1 -1
View File
@@ -22,7 +22,7 @@ const (
EntityUserSessions Entity = "user_sessions"
EntityTokenBlacklist Entity = "token_blacklist"
EntityUserTOTPBackupCodes Entity = "user_totp_backup_codes"
EntityUserPasskeyCredentials Entity = "user_passkey_credentials"
EntityUserPasskeyCredentials Entity = "user_passkey_credentials" //nolint:gosec // table name, not a credential
EntityUserPasswordResets Entity = "user_password_resets"
EntityOAuthClients Entity = "oauth_clients"
EntityOAuthCodes Entity = "oauth_codes"
@@ -3,10 +3,11 @@ package providers
import (
"context"
"fmt"
"github.com/bitechdev/ResolveSpec/pkg/security"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
"net/http"
"strings"
"github.com/bitechdev/ResolveSpec/pkg/security"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
)
// KeyStoreAuthenticator implements the Authenticator interface using a KeyStore.
+2 -1
View File
@@ -7,10 +7,11 @@ import (
"encoding/base64"
"encoding/hex"
"fmt"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
"sync"
"sync/atomic"
"time"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
)
// ConfigKeyStore is an in-memory keystore backed by a static slice of UserKey values.
+2 -1
View File
@@ -3,8 +3,9 @@ package totp
import (
"context"
"fmt"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
"net/http"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
)
// BaseAuthenticator is the subset of security.Authenticator that Authenticator wraps.
+2 -1
View File
@@ -4,8 +4,9 @@ import (
"crypto/sha256"
"encoding/hex"
"fmt"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
"sync"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
)
// MemoryProvider is an in-memory implementation of AuthProvider for testing/examples
+2 -1
View File
@@ -9,12 +9,13 @@ import (
"encoding/base32"
"encoding/binary"
"fmt"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
"hash"
"math"
"net/url"
"strings"
"time"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
)
// AuthProvider defines interface for 2FA operations
+1
View File
@@ -6,6 +6,7 @@ import (
"database/sql"
"encoding/hex"
"fmt"
"github.com/bitechdev/ResolveSpec/pkg/security/lookup"
"github.com/bitechdev/ResolveSpec/pkg/security/totp"
)