mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-06 13:26:28 +00:00
chore(security): apply golangci-lint fixes to lookup and security packages
This commit is contained in:
@@ -2,6 +2,7 @@ package security
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
@@ -159,11 +159,3 @@ func (ks *DatabaseKeyStore) validateKeyLoad(ctx context.Context, hash, cacheKey
|
|||||||
func keystoreCacheKey(hash string) string {
|
func keystoreCacheKey(hash string) string {
|
||||||
return "keystore:validate:" + hash
|
return "keystore:validate:" + hash
|
||||||
}
|
}
|
||||||
|
|
||||||
// nullStringOr returns s.String if valid, otherwise the fallback.
|
|
||||||
func nullStringOr(s sql.NullString, fallback string) string {
|
|
||||||
if s.Valid && s.String != "" {
|
|
||||||
return s.String
|
|
||||||
}
|
|
||||||
return fallback
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -261,7 +261,7 @@ func (r *passkeyRouter) Store(ctx context.Context, rec lookup.PasskeyCredentialR
|
|||||||
return st.Store(ctx, rec)
|
return st.Store(ctx, rec)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (r *passkeyRouter) Get(ctx context.Context, credentialID string) (int, uint32, error) {
|
func (r *passkeyRouter) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
|
||||||
st, err := pick[lookup.PasskeyStore](r.c, ctx, lookup.OpPasskeyGet, r.c.procs.PasskeyGetCredential, r.proc, r.direct)
|
st, err := pick[lookup.PasskeyStore](r.c, ctx, lookup.OpPasskeyGet, r.c.procs.PasskeyGetCredential, r.proc, r.direct)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return 0, 0, err
|
return 0, 0, err
|
||||||
|
|||||||
@@ -499,7 +499,7 @@ func (s *suite) seed(t *testing.T, table string, cols []string, vals ...any) {
|
|||||||
}
|
}
|
||||||
args[i] = v
|
args[i] = v
|
||||||
}
|
}
|
||||||
q := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)", table, strings.Join(cols, ", "), strings.Join(ph, ", "))
|
q := fmt.Sprintf("INSERT INTO %s (%s) VALUES (%s)", table, strings.Join(cols, ", "), strings.Join(ph, ", ")) //nolint:gosec // test seeding with fixed table names
|
||||||
if _, err := s.DB.ExecContext(ctx, q, args...); err != nil {
|
if _, err := s.DB.ExecContext(ctx, q, args...); err != nil {
|
||||||
t.Fatalf("seed %s: %v", table, err)
|
t.Fatalf("seed %s: %v", table, err)
|
||||||
}
|
}
|
||||||
@@ -526,8 +526,8 @@ func (s *suite) policy(t *testing.T) {
|
|||||||
t.Fatalf("column rules (user + group, exact table, active only): %d %v %+v", len(rules), err, rules)
|
t.Fatalf("column rules (user + group, exact table, active only): %d %v %+v", len(rules), err, rules)
|
||||||
}
|
}
|
||||||
paths := map[string]bool{}
|
paths := map[string]bool{}
|
||||||
for _, r := range rules {
|
for i := range rules {
|
||||||
paths[strings.Join(r.Path, ".")] = true
|
paths[strings.Join(rules[i].Path, ".")] = true
|
||||||
}
|
}
|
||||||
if !paths["email"] || !paths["profile.ssn"] {
|
if !paths["email"] || !paths["profile.ssn"] {
|
||||||
t.Fatalf("paths: %v", paths)
|
t.Fatalf("paths: %v", paths)
|
||||||
|
|||||||
@@ -429,9 +429,9 @@ func (b *Base) Insert(e lookup.Entity) *Insert { return &Insert{b: b, e: e} }
|
|||||||
// Set adds assignments.
|
// Set adds assignments.
|
||||||
func (i *Insert) Set(as ...Assignment) *Insert { i.sets = append(i.sets, as...); return i }
|
func (i *Insert) Set(as ...Assignment) *Insert { i.sets = append(i.sets, as...); return i }
|
||||||
|
|
||||||
func (i *Insert) colsAndArgs() ([]string, []any) {
|
func (i *Insert) colsAndArgs() (cols []string, args []any) {
|
||||||
cols := make([]string, len(i.sets))
|
cols = make([]string, len(i.sets))
|
||||||
args := make([]any, len(i.sets))
|
args = make([]any, len(i.sets))
|
||||||
for n, a := range i.sets {
|
for n, a := range i.sets {
|
||||||
cols[n] = i.b.colName(a.Col)
|
cols[n] = i.b.colName(a.Col)
|
||||||
args[n] = i.b.arg(a.Val)
|
args[n] = i.b.arg(a.Val)
|
||||||
|
|||||||
@@ -68,10 +68,9 @@ func (p *Passkey) Store(ctx context.Context, rec lookup.PasskeyCredentialRecord)
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Get implements lookup.PasskeyStore.
|
// Get implements lookup.PasskeyStore.
|
||||||
func (p *Passkey) Get(ctx context.Context, credentialID string) (int, uint32, error) {
|
func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
|
||||||
var userID int
|
|
||||||
var count int64
|
var count int64
|
||||||
err := p.do(func(q Querier) error {
|
err = p.do(func(q Querier) error {
|
||||||
return p.From(lookup.EntityUserPasskeyCredentials).Cols(lookup.PasskeyUserID, lookup.PasskeySignCount).
|
return p.From(lookup.EntityUserPasskeyCredentials).Cols(lookup.PasskeyUserID, lookup.PasskeySignCount).
|
||||||
Where(Eq(lookup.PasskeyCredentialID, credentialID)).QueryRow(ctx, q, &userID, &count)
|
Where(Eq(lookup.PasskeyCredentialID, credentialID)).QueryRow(ctx, q, &userID, &count)
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ const (
|
|||||||
OpSession Op = "session"
|
OpSession Op = "session"
|
||||||
OpTouchSession Op = "touch_session"
|
OpTouchSession Op = "touch_session"
|
||||||
OpRefresh Op = "refresh"
|
OpRefresh Op = "refresh"
|
||||||
OpLoginAPIKey Op = "login_api_key"
|
OpLoginAPIKey Op = "login_api_key" //nolint:gosec // operation name, not a credential
|
||||||
OpJWTLogin Op = "jwt_login"
|
OpJWTLogin Op = "jwt_login"
|
||||||
OpJWTLogout Op = "jwt_logout"
|
OpJWTLogout Op = "jwt_logout"
|
||||||
OpResetRequest Op = "reset_request"
|
OpResetRequest Op = "reset_request"
|
||||||
@@ -64,8 +64,8 @@ const (
|
|||||||
|
|
||||||
OpOAuthGetOrCreateUser Op = "oauth_get_or_create_user"
|
OpOAuthGetOrCreateUser Op = "oauth_get_or_create_user"
|
||||||
OpOAuthCreateSession Op = "oauth_create_session"
|
OpOAuthCreateSession Op = "oauth_create_session"
|
||||||
OpOAuthGetRefreshToken Op = "oauth_get_refresh_token"
|
OpOAuthGetRefreshToken Op = "oauth_get_refresh_token" //nolint:gosec // operation name, not a credential
|
||||||
OpOAuthUpdateRefreshToken Op = "oauth_update_refresh_token"
|
OpOAuthUpdateRefreshToken Op = "oauth_update_refresh_token" //nolint:gosec // operation name, not a credential
|
||||||
OpOAuthGetUser Op = "oauth_get_user"
|
OpOAuthGetUser Op = "oauth_get_user"
|
||||||
|
|
||||||
OpPasskeyStore Op = "passkey_store"
|
OpPasskeyStore Op = "passkey_store"
|
||||||
@@ -74,7 +74,7 @@ const (
|
|||||||
OpPasskeyList Op = "passkey_list"
|
OpPasskeyList Op = "passkey_list"
|
||||||
OpPasskeyDelete Op = "passkey_delete"
|
OpPasskeyDelete Op = "passkey_delete"
|
||||||
OpPasskeyRename Op = "passkey_rename"
|
OpPasskeyRename Op = "passkey_rename"
|
||||||
OpPasskeyByUsername Op = "passkey_by_username"
|
OpPasskeyByUsername Op = "passkey_by_username" //nolint:gosec // operation name, not a credential
|
||||||
OpPasskeyLogin Op = "passkey_login"
|
OpPasskeyLogin Op = "passkey_login"
|
||||||
|
|
||||||
OpTOTPEnable Op = "totp_enable"
|
OpTOTPEnable Op = "totp_enable"
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ func normalizeTimes(raw []byte) []byte {
|
|||||||
func fixTimes(m map[string]any) {
|
func fixTimes(m map[string]any) {
|
||||||
for k, v := range m {
|
for k, v := range m {
|
||||||
s, ok := v.(string)
|
s, ok := v.(string)
|
||||||
if !ok || !(strings.HasSuffix(k, "_at") || k == "expiry") {
|
if !ok || (!strings.HasSuffix(k, "_at") && k != "expiry") {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
if _, err := time.Parse(time.RFC3339Nano, s); err == nil {
|
if _, err := time.Parse(time.RFC3339Nano, s); err == nil {
|
||||||
|
|||||||
@@ -68,7 +68,7 @@ func (p *Passkey) Store(ctx context.Context, rec lookup.PasskeyCredentialRecord)
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Get implements lookup.PasskeyStore.
|
// Get implements lookup.PasskeyStore.
|
||||||
func (p *Passkey) Get(ctx context.Context, credentialID string) (int, uint32, error) {
|
func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error) {
|
||||||
raw, err := decodeCredentialID(credentialID)
|
raw, err := decodeCredentialID(credentialID)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return 0, 0, err
|
return 0, 0, err
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ const (
|
|||||||
EntityUserSessions Entity = "user_sessions"
|
EntityUserSessions Entity = "user_sessions"
|
||||||
EntityTokenBlacklist Entity = "token_blacklist"
|
EntityTokenBlacklist Entity = "token_blacklist"
|
||||||
EntityUserTOTPBackupCodes Entity = "user_totp_backup_codes"
|
EntityUserTOTPBackupCodes Entity = "user_totp_backup_codes"
|
||||||
EntityUserPasskeyCredentials Entity = "user_passkey_credentials"
|
EntityUserPasskeyCredentials Entity = "user_passkey_credentials" //nolint:gosec // table name, not a credential
|
||||||
EntityUserPasswordResets Entity = "user_password_resets"
|
EntityUserPasswordResets Entity = "user_password_resets"
|
||||||
EntityOAuthClients Entity = "oauth_clients"
|
EntityOAuthClients Entity = "oauth_clients"
|
||||||
EntityOAuthCodes Entity = "oauth_codes"
|
EntityOAuthCodes Entity = "oauth_codes"
|
||||||
|
|||||||
@@ -3,10 +3,11 @@ package providers
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security"
|
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
"github.com/bitechdev/ResolveSpec/pkg/security"
|
||||||
|
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||||
)
|
)
|
||||||
|
|
||||||
// KeyStoreAuthenticator implements the Authenticator interface using a KeyStore.
|
// KeyStoreAuthenticator implements the Authenticator interface using a KeyStore.
|
||||||
|
|||||||
@@ -7,10 +7,11 @@ import (
|
|||||||
"encoding/base64"
|
"encoding/base64"
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
"fmt"
|
"fmt"
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
|
||||||
"sync"
|
"sync"
|
||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||||
)
|
)
|
||||||
|
|
||||||
// ConfigKeyStore is an in-memory keystore backed by a static slice of UserKey values.
|
// ConfigKeyStore is an in-memory keystore backed by a static slice of UserKey values.
|
||||||
|
|||||||
@@ -3,8 +3,9 @@ package totp
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
|
||||||
"net/http"
|
"net/http"
|
||||||
|
|
||||||
|
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||||
)
|
)
|
||||||
|
|
||||||
// BaseAuthenticator is the subset of security.Authenticator that Authenticator wraps.
|
// BaseAuthenticator is the subset of security.Authenticator that Authenticator wraps.
|
||||||
|
|||||||
@@ -4,8 +4,9 @@ import (
|
|||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
"fmt"
|
"fmt"
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
|
||||||
"sync"
|
"sync"
|
||||||
|
|
||||||
|
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||||
)
|
)
|
||||||
|
|
||||||
// MemoryProvider is an in-memory implementation of AuthProvider for testing/examples
|
// MemoryProvider is an in-memory implementation of AuthProvider for testing/examples
|
||||||
|
|||||||
@@ -9,12 +9,13 @@ import (
|
|||||||
"encoding/base32"
|
"encoding/base32"
|
||||||
"encoding/binary"
|
"encoding/binary"
|
||||||
"fmt"
|
"fmt"
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
|
||||||
"hash"
|
"hash"
|
||||||
"math"
|
"math"
|
||||||
"net/url"
|
"net/url"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||||
)
|
)
|
||||||
|
|
||||||
// AuthProvider defines interface for 2FA operations
|
// AuthProvider defines interface for 2FA operations
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ import (
|
|||||||
"database/sql"
|
"database/sql"
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security/lookup"
|
"github.com/bitechdev/ResolveSpec/pkg/security/lookup"
|
||||||
"github.com/bitechdev/ResolveSpec/pkg/security/totp"
|
"github.com/bitechdev/ResolveSpec/pkg/security/totp"
|
||||||
)
|
)
|
||||||
|
|||||||
Reference in New Issue
Block a user