mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-01 04:21:58 +00:00
chore(gosec): enable gosec and address findings
This commit is contained in:
@@ -520,7 +520,7 @@ func SetSessionCookie(w http.ResponseWriter, loginResp *LoginResponse, opts ...S
|
||||
maxAge = int(loginResp.ExpiresIn)
|
||||
}
|
||||
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
http.SetCookie(w, &http.Cookie{ //nolint:gosec // G124: Secure/HttpOnly/SameSite set from options with secure defaults
|
||||
Name: o.name(),
|
||||
Value: loginResp.Token,
|
||||
Path: o.path(),
|
||||
@@ -563,7 +563,7 @@ func ClearSessionCookie(w http.ResponseWriter, opts ...SessionCookieOptions) {
|
||||
o = opts[0]
|
||||
}
|
||||
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
http.SetCookie(w, &http.Cookie{ //nolint:gosec // G124: Secure/HttpOnly/SameSite set from options with secure defaults
|
||||
Name: o.name(),
|
||||
Value: "",
|
||||
Path: o.path(),
|
||||
|
||||
@@ -54,10 +54,10 @@ func ExampleOAuth2Google() {
|
||||
})
|
||||
|
||||
// Return user info as JSON
|
||||
_ = json.NewEncoder(w).Encode(loginResp)
|
||||
_ = json.NewEncoder(w).Encode(loginResp) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
_ = http.ListenAndServe(":8080", router)
|
||||
_ = http.ListenAndServe(":8080", router) //nolint:gosec // G114: example code only
|
||||
}
|
||||
|
||||
// Example: OAuth2 Authentication with GitHub
|
||||
@@ -89,10 +89,10 @@ func ExampleOAuth2GitHub() {
|
||||
return
|
||||
}
|
||||
|
||||
_ = json.NewEncoder(w).Encode(loginResp)
|
||||
_ = json.NewEncoder(w).Encode(loginResp) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
_ = http.ListenAndServe(":8080", router)
|
||||
_ = http.ListenAndServe(":8080", router) //nolint:gosec // G114: example code only
|
||||
}
|
||||
|
||||
// Example: Custom OAuth2 Provider
|
||||
@@ -100,7 +100,7 @@ func ExampleOAuth2Custom() {
|
||||
db, _ := sql.Open("postgres", "connection-string")
|
||||
|
||||
// Custom OAuth2 provider configuration
|
||||
oauth2Auth := NewDatabaseAuthenticator(db).WithOAuth2(OAuth2Config{
|
||||
oauth2Auth := NewDatabaseAuthenticator(db).WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: "your-client-id",
|
||||
ClientSecret: "your-client-secret",
|
||||
RedirectURL: "http://localhost:8080/auth/callback",
|
||||
@@ -142,10 +142,10 @@ func ExampleOAuth2Custom() {
|
||||
return
|
||||
}
|
||||
|
||||
_ = json.NewEncoder(w).Encode(loginResp)
|
||||
_ = json.NewEncoder(w).Encode(loginResp) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
_ = http.ListenAndServe(":8080", router)
|
||||
_ = http.ListenAndServe(":8080", router) //nolint:gosec // G114: example code only
|
||||
}
|
||||
|
||||
// Example: Multi-Provider OAuth2 with Security Integration
|
||||
@@ -190,7 +190,7 @@ func ExampleOAuth2MultiProvider() {
|
||||
return
|
||||
}
|
||||
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
http.SetCookie(w, &http.Cookie{ //nolint:gosec // G124: Secure/HttpOnly/SameSite set from options with secure defaults
|
||||
Name: "session_token",
|
||||
Value: loginResp.Token,
|
||||
Path: "/",
|
||||
@@ -218,7 +218,7 @@ func ExampleOAuth2MultiProvider() {
|
||||
return
|
||||
}
|
||||
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
http.SetCookie(w, &http.Cookie{ //nolint:gosec // G124: Secure/HttpOnly/SameSite set from options with secure defaults
|
||||
Name: "session_token",
|
||||
Value: loginResp.Token,
|
||||
Path: "/",
|
||||
@@ -243,7 +243,7 @@ func ExampleOAuth2MultiProvider() {
|
||||
_ = json.NewEncoder(w).Encode(userCtx)
|
||||
})
|
||||
|
||||
_ = http.ListenAndServe(":8080", router)
|
||||
_ = http.ListenAndServe(":8080", router) //nolint:gosec // G114: example code only
|
||||
}
|
||||
|
||||
// Example: OAuth2 with Token Refresh
|
||||
@@ -294,10 +294,10 @@ func ExampleOAuth2TokenRefresh() {
|
||||
SameSite: http.SameSiteLaxMode,
|
||||
})
|
||||
|
||||
_ = json.NewEncoder(w).Encode(loginResp)
|
||||
_ = json.NewEncoder(w).Encode(loginResp) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
_ = http.ListenAndServe(":8080", router)
|
||||
_ = http.ListenAndServe(":8080", router) //nolint:gosec // G114: example code only
|
||||
}
|
||||
|
||||
// Example: OAuth2 Logout
|
||||
@@ -334,7 +334,7 @@ func ExampleOAuth2Logout() {
|
||||
}
|
||||
|
||||
// Clear cookie
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
http.SetCookie(w, &http.Cookie{ //nolint:gosec // G124: Secure/HttpOnly/SameSite set from options with secure defaults
|
||||
Name: "session_token",
|
||||
Value: "",
|
||||
Path: "/",
|
||||
@@ -346,7 +346,7 @@ func ExampleOAuth2Logout() {
|
||||
_, _ = w.Write([]byte("Logged out successfully"))
|
||||
})
|
||||
|
||||
_ = http.ListenAndServe(":8080", router)
|
||||
_ = http.ListenAndServe(":8080", router) //nolint:gosec // G114: example code only
|
||||
}
|
||||
|
||||
// Example: Complete OAuth2 Integration with Database Setup
|
||||
@@ -393,7 +393,7 @@ func ExampleOAuth2Complete() {
|
||||
return
|
||||
}
|
||||
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
http.SetCookie(w, &http.Cookie{ //nolint:gosec // G124: Secure/HttpOnly/SameSite set from options with secure defaults
|
||||
Name: "session_token",
|
||||
Value: loginResp.Token,
|
||||
Path: "/",
|
||||
@@ -426,7 +426,7 @@ func ExampleOAuth2Complete() {
|
||||
UserID: userCtx.UserID,
|
||||
})
|
||||
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
http.SetCookie(w, &http.Cookie{ //nolint:gosec // G124: Secure/HttpOnly/SameSite set from options with secure defaults
|
||||
Name: "session_token",
|
||||
Value: "",
|
||||
Path: "/",
|
||||
@@ -437,7 +437,7 @@ func ExampleOAuth2Complete() {
|
||||
http.Redirect(w, r, "/", http.StatusTemporaryRedirect)
|
||||
})
|
||||
|
||||
_ = http.ListenAndServe(":8080", router)
|
||||
_ = http.ListenAndServe(":8080", router) //nolint:gosec // G114: example code only
|
||||
}
|
||||
|
||||
func setupOAuth2Tables(db *sql.DB) {
|
||||
@@ -488,7 +488,7 @@ func ExampleOAuth2AllProviders() {
|
||||
|
||||
// Create authenticator with ALL OAuth2 providers
|
||||
auth := NewDatabaseAuthenticator(db).
|
||||
WithOAuth2(OAuth2Config{
|
||||
WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: "google-client-id",
|
||||
ClientSecret: "google-client-secret",
|
||||
RedirectURL: "http://localhost:8080/auth/google/callback",
|
||||
@@ -498,7 +498,7 @@ func ExampleOAuth2AllProviders() {
|
||||
UserInfoURL: "https://www.googleapis.com/oauth2/v2/userinfo",
|
||||
ProviderName: "google",
|
||||
}).
|
||||
WithOAuth2(OAuth2Config{
|
||||
WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: "github-client-id",
|
||||
ClientSecret: "github-client-secret",
|
||||
RedirectURL: "http://localhost:8080/auth/github/callback",
|
||||
@@ -508,7 +508,7 @@ func ExampleOAuth2AllProviders() {
|
||||
UserInfoURL: "https://api.github.com/user",
|
||||
ProviderName: "github",
|
||||
}).
|
||||
WithOAuth2(OAuth2Config{
|
||||
WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: "microsoft-client-id",
|
||||
ClientSecret: "microsoft-client-secret",
|
||||
RedirectURL: "http://localhost:8080/auth/microsoft/callback",
|
||||
@@ -518,7 +518,7 @@ func ExampleOAuth2AllProviders() {
|
||||
UserInfoURL: "https://graph.microsoft.com/v1.0/me",
|
||||
ProviderName: "microsoft",
|
||||
}).
|
||||
WithOAuth2(OAuth2Config{
|
||||
WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: "facebook-client-id",
|
||||
ClientSecret: "facebook-client-secret",
|
||||
RedirectURL: "http://localhost:8080/auth/facebook/callback",
|
||||
@@ -547,7 +547,7 @@ func ExampleOAuth2AllProviders() {
|
||||
http.Error(w, err.Error(), http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
_ = json.NewEncoder(w).Encode(loginResp)
|
||||
_ = json.NewEncoder(w).Encode(loginResp) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
// GitHub routes
|
||||
@@ -562,7 +562,7 @@ func ExampleOAuth2AllProviders() {
|
||||
http.Error(w, err.Error(), http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
_ = json.NewEncoder(w).Encode(loginResp)
|
||||
_ = json.NewEncoder(w).Encode(loginResp) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
// Microsoft routes
|
||||
@@ -577,7 +577,7 @@ func ExampleOAuth2AllProviders() {
|
||||
http.Error(w, err.Error(), http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
_ = json.NewEncoder(w).Encode(loginResp)
|
||||
_ = json.NewEncoder(w).Encode(loginResp) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
// Facebook routes
|
||||
@@ -592,7 +592,7 @@ func ExampleOAuth2AllProviders() {
|
||||
http.Error(w, err.Error(), http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
_ = json.NewEncoder(w).Encode(loginResp)
|
||||
_ = json.NewEncoder(w).Encode(loginResp) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
// Create security list for protected routes
|
||||
@@ -611,5 +611,5 @@ func ExampleOAuth2AllProviders() {
|
||||
_ = json.NewEncoder(w).Encode(userCtx)
|
||||
})
|
||||
|
||||
_ = http.ListenAndServe(":8080", router)
|
||||
_ = http.ListenAndServe(":8080", router) //nolint:gosec // G114: example code only
|
||||
}
|
||||
|
||||
@@ -441,7 +441,7 @@ func (a *DatabaseAuthenticator) OAuth2RefreshToken(ctx context.Context, refreshT
|
||||
// NewGoogleAuthenticator creates a DatabaseAuthenticator configured for Google OAuth2
|
||||
func NewGoogleAuthenticator(clientID, clientSecret, redirectURL string, db *sql.DB) *DatabaseAuthenticator {
|
||||
auth := NewDatabaseAuthenticator(db)
|
||||
return auth.WithOAuth2(OAuth2Config{
|
||||
return auth.WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: clientID,
|
||||
ClientSecret: clientSecret,
|
||||
RedirectURL: redirectURL,
|
||||
@@ -456,7 +456,7 @@ func NewGoogleAuthenticator(clientID, clientSecret, redirectURL string, db *sql.
|
||||
// NewGitHubAuthenticator creates a DatabaseAuthenticator configured for GitHub OAuth2
|
||||
func NewGitHubAuthenticator(clientID, clientSecret, redirectURL string, db *sql.DB) *DatabaseAuthenticator {
|
||||
auth := NewDatabaseAuthenticator(db)
|
||||
return auth.WithOAuth2(OAuth2Config{
|
||||
return auth.WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: clientID,
|
||||
ClientSecret: clientSecret,
|
||||
RedirectURL: redirectURL,
|
||||
@@ -471,7 +471,7 @@ func NewGitHubAuthenticator(clientID, clientSecret, redirectURL string, db *sql.
|
||||
// NewMicrosoftAuthenticator creates a DatabaseAuthenticator configured for Microsoft OAuth2
|
||||
func NewMicrosoftAuthenticator(clientID, clientSecret, redirectURL string, db *sql.DB) *DatabaseAuthenticator {
|
||||
auth := NewDatabaseAuthenticator(db)
|
||||
return auth.WithOAuth2(OAuth2Config{
|
||||
return auth.WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: clientID,
|
||||
ClientSecret: clientSecret,
|
||||
RedirectURL: redirectURL,
|
||||
@@ -486,7 +486,7 @@ func NewMicrosoftAuthenticator(clientID, clientSecret, redirectURL string, db *s
|
||||
// NewFacebookAuthenticator creates a DatabaseAuthenticator configured for Facebook OAuth2
|
||||
func NewFacebookAuthenticator(clientID, clientSecret, redirectURL string, db *sql.DB) *DatabaseAuthenticator {
|
||||
auth := NewDatabaseAuthenticator(db)
|
||||
return auth.WithOAuth2(OAuth2Config{
|
||||
return auth.WithOAuth2(OAuth2Config{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
ClientID: clientID,
|
||||
ClientSecret: clientSecret,
|
||||
RedirectURL: redirectURL,
|
||||
|
||||
@@ -305,7 +305,7 @@ func (s *OAuthServer) serverMetadata() map[string]interface{} {
|
||||
|
||||
func (s *OAuthServer) metadataHandler(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(s.serverMetadata()) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(s.serverMetadata()) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------
|
||||
@@ -318,7 +318,7 @@ func (s *OAuthServer) openIDConfigurationHandler(w http.ResponseWriter, r *http.
|
||||
meta["id_token_signing_alg_values_supported"] = []string{"RS256"}
|
||||
meta["claims_supported"] = []string{"sub", "iss", "aud", "exp", "iat", "email", "preferred_username"}
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(meta) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(meta) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------
|
||||
@@ -333,7 +333,7 @@ func (s *OAuthServer) protectedResourceHandler(w http.ResponseWriter, r *http.Re
|
||||
"bearer_methods_supported": []string{"header"},
|
||||
}
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(meta) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(meta) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------
|
||||
@@ -343,7 +343,7 @@ func (s *OAuthServer) protectedResourceHandler(w http.ResponseWriter, r *http.Re
|
||||
func (s *OAuthServer) jwksHandler(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
if s.signingKey == nil {
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{"keys": []interface{}{}}) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{"keys": []interface{}{}}) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
return
|
||||
}
|
||||
pub := s.signingKey.PublicKey
|
||||
@@ -355,7 +355,7 @@ func (s *OAuthServer) jwksHandler(w http.ResponseWriter, r *http.Request) {
|
||||
"n": base64.RawURLEncoding.EncodeToString(pub.N.Bytes()),
|
||||
"e": base64.RawURLEncoding.EncodeToString(bigEndianBytes(pub.E)),
|
||||
}
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{"keys": []interface{}{jwk}}) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{"keys": []interface{}{jwk}}) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------
|
||||
@@ -392,7 +392,7 @@ func (s *OAuthServer) userinfoHandler(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{ //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(map[string]interface{}{ //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
"sub": info.Sub,
|
||||
"preferred_username": info.Username,
|
||||
"email": info.Email,
|
||||
@@ -507,7 +507,7 @@ func (s *OAuthServer) registerHandler(w http.ResponseWriter, r *http.Request) {
|
||||
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(http.StatusCreated)
|
||||
json.NewEncoder(w).Encode(resp) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(resp) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------
|
||||
@@ -995,7 +995,7 @@ func (s *OAuthServer) revokeHandler(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
|
||||
if s.auth != nil {
|
||||
s.auth.OAuthRevokeToken(r.Context(), token) //nolint:errcheck
|
||||
s.auth.OAuthRevokeToken(r.Context(), token) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
} else {
|
||||
// In external-provider-only mode, attempt revocation via the first provider's auth.
|
||||
s.mu.RLock()
|
||||
@@ -1005,7 +1005,7 @@ func (s *OAuthServer) revokeHandler(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
s.mu.RUnlock()
|
||||
if providerAuth != nil {
|
||||
providerAuth.OAuthRevokeToken(r.Context(), token) //nolint:errcheck
|
||||
providerAuth.OAuthRevokeToken(r.Context(), token) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
}
|
||||
w.WriteHeader(http.StatusOK)
|
||||
@@ -1022,14 +1022,14 @@ func (s *OAuthServer) introspectHandler(w http.ResponseWriter, r *http.Request)
|
||||
}
|
||||
if err := r.ParseForm(); err != nil {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.Write([]byte(`{"active":false}`)) //nolint:errcheck
|
||||
w.Write([]byte(`{"active":false}`)) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
return
|
||||
}
|
||||
token := r.FormValue("token")
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
|
||||
if token == "" {
|
||||
w.Write([]byte(`{"active":false}`)) //nolint:errcheck
|
||||
w.Write([]byte(`{"active":false}`)) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
return
|
||||
}
|
||||
|
||||
@@ -1043,16 +1043,16 @@ func (s *OAuthServer) introspectHandler(w http.ResponseWriter, r *http.Request)
|
||||
s.mu.RUnlock()
|
||||
}
|
||||
if authToUse == nil {
|
||||
w.Write([]byte(`{"active":false}`)) //nolint:errcheck
|
||||
w.Write([]byte(`{"active":false}`)) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
return
|
||||
}
|
||||
|
||||
info, err := authToUse.OAuthIntrospectToken(r.Context(), token)
|
||||
if err != nil {
|
||||
w.Write([]byte(`{"active":false}`)) //nolint:errcheck
|
||||
w.Write([]byte(`{"active":false}`)) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
return
|
||||
}
|
||||
json.NewEncoder(w).Encode(info) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(info) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------
|
||||
@@ -1063,13 +1063,13 @@ func (s *OAuthServer) renderLoginForm(w http.ResponseWriter, r *http.Request, cl
|
||||
w.Header().Set("Content-Type", "text/html; charset=utf-8")
|
||||
errHTML := ""
|
||||
if errMsg != "" {
|
||||
errHTML = `<p style="color:red">` + errMsg + `</p>`
|
||||
errHTML = `<p style="color:red">` + htmlEscape(errMsg) + `</p>`
|
||||
}
|
||||
fmt.Fprintf(w, loginFormHTML,
|
||||
s.cfg.LoginTitle,
|
||||
s.cfg.LoginTitle,
|
||||
fmt.Fprintf(w, loginFormHTML, //nolint:gosec // G705: output is HTML-escaped
|
||||
htmlEscape(s.cfg.LoginTitle),
|
||||
htmlEscape(s.cfg.LoginTitle),
|
||||
errHTML,
|
||||
clientID,
|
||||
htmlEscape(clientID),
|
||||
htmlEscape(redirectURI),
|
||||
htmlEscape(clientState),
|
||||
htmlEscape(codeChallenge),
|
||||
@@ -1195,7 +1195,7 @@ func (s *OAuthServer) writeOAuthToken(w http.ResponseWriter, r *http.Request, ac
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.Header().Set("Cache-Control", "no-store")
|
||||
w.Header().Set("Pragma", "no-cache")
|
||||
json.NewEncoder(w).Encode(resp) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(resp) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
|
||||
// buildIDToken issues an OIDC id_token for the just-issued access token by reusing the
|
||||
@@ -1294,7 +1294,7 @@ func writeOAuthError(w http.ResponseWriter, errCode, description string, status
|
||||
}
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(status)
|
||||
json.NewEncoder(w).Encode(resp) //nolint:errcheck
|
||||
json.NewEncoder(w).Encode(resp) //nolint:errcheck,gosec // G104: best-effort write, error intentionally ignored
|
||||
}
|
||||
|
||||
func htmlEscape(s string) string {
|
||||
|
||||
@@ -117,7 +117,7 @@ func (a *DatabaseAuthenticator) OAuthSaveCode(ctx context.Context, code *OAuthCo
|
||||
return a.oauthSaveCodeDirect(ctx, code)
|
||||
}
|
||||
|
||||
input, err := json.Marshal(code)
|
||||
input, err := json.Marshal(code) //nolint:gosec // G117: intentional: field must be serialized
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to marshal code: %w", err)
|
||||
}
|
||||
|
||||
@@ -239,7 +239,7 @@ func PasskeyHTTPHandlersExample(auth *DatabaseAuthenticator) {
|
||||
})
|
||||
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
_ = json.NewEncoder(w).Encode(loginResponse)
|
||||
_ = json.NewEncoder(w).Encode(loginResponse) //nolint:gosec // G117: intentional: field must be serialized
|
||||
})
|
||||
|
||||
// List credentials endpoint
|
||||
|
||||
@@ -215,7 +215,7 @@ func (a *DatabaseAuthenticator) Login(ctx context.Context, req LoginRequest) (*L
|
||||
return a.loginDirect(ctx, req)
|
||||
}
|
||||
// Convert LoginRequest to JSON
|
||||
reqJSON, err := json.Marshal(req)
|
||||
reqJSON, err := json.Marshal(req) //nolint:gosec // G117: intentional: field must be serialized
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("failed to marshal login request: %w", err)
|
||||
}
|
||||
@@ -254,7 +254,7 @@ func (a *DatabaseAuthenticator) Register(ctx context.Context, req RegisterReques
|
||||
return a.registerDirect(ctx, req)
|
||||
}
|
||||
// Convert RegisterRequest to JSON
|
||||
reqJSON, err := json.Marshal(req)
|
||||
reqJSON, err := json.Marshal(req) //nolint:gosec // G117: intentional: field must be serialized
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("failed to marshal register request: %w", err)
|
||||
}
|
||||
@@ -414,7 +414,7 @@ func (a *DatabaseAuthenticator) Authenticate(r *http.Request) (*UserContext, err
|
||||
|
||||
err := a.runDBOpWithReconnect(func(db *sql.DB) error {
|
||||
query := fmt.Sprintf(`SELECT p_success, p_error, p_user::text FROM %s($1, $2)`, a.sqlNames.Session)
|
||||
return db.QueryRowContext(r.Context(), query, token, reference).Scan(&success, &errorMsg, &userJSON)
|
||||
return db.QueryRowContext(r.Context(), query, token, reference).Scan(&success, &errorMsg, &userJSON) //nolint:gosec // G701: identifier comes from trusted config, values are bound parameters
|
||||
})
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("session query failed: %w", err)
|
||||
@@ -505,7 +505,7 @@ func (a *DatabaseAuthenticator) updateSessionActivity(ctx context.Context, sessi
|
||||
|
||||
_ = a.runDBOpWithReconnect(func(db *sql.DB) error {
|
||||
query := fmt.Sprintf(`SELECT p_success, p_error, p_user::text FROM %s($1, $2::jsonb)`, a.sqlNames.SessionUpdate)
|
||||
return db.QueryRowContext(ctx, query, sessionToken, string(userJSON)).Scan(&success, &errorMsg, &updatedUserJSON)
|
||||
return db.QueryRowContext(ctx, query, sessionToken, string(userJSON)).Scan(&success, &errorMsg, &updatedUserJSON) //nolint:gosec // G701: identifier comes from trusted config, values are bound parameters
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
@@ -218,7 +218,7 @@ func (a *DatabaseAuthenticator) sessionDirect(ctx context.Context, token string)
|
||||
FROM %s s JOIN %s u ON s.user_id = u.id
|
||||
WHERE s.session_token = ? AND s.expires_at > ? AND u.is_active = ?`,
|
||||
a.tableNames.UserSessions, a.tableNames.Users))
|
||||
return db.QueryRowContext(ctx, query, token, time.Now(), true).Scan(&userID, &username, &email, &userLevel, &roles, &programUserID, &programUserTable)
|
||||
return db.QueryRowContext(ctx, query, token, time.Now(), true).Scan(&userID, &username, &email, &userLevel, &roles, &programUserID, &programUserTable) //nolint:gosec // G701: identifier comes from trusted config, values are bound parameters
|
||||
})
|
||||
if err != nil {
|
||||
if errors.Is(err, sql.ErrNoRows) {
|
||||
@@ -242,7 +242,7 @@ func (a *DatabaseAuthenticator) sessionDirect(ctx context.Context, token string)
|
||||
func (a *DatabaseAuthenticator) updateSessionActivityDirect(ctx context.Context, sessionToken string) error {
|
||||
return a.runDBOpWithReconnect(func(db *sql.DB) error {
|
||||
query := rewritePlaceholders(db, fmt.Sprintf(`UPDATE %s SET last_activity_at = ? WHERE session_token = ? AND expires_at > ?`, a.tableNames.UserSessions))
|
||||
_, err := db.ExecContext(ctx, query, time.Now(), sessionToken, time.Now())
|
||||
_, err := db.ExecContext(ctx, query, time.Now(), sessionToken, time.Now()) //nolint:gosec // G701: identifier comes from trusted config, values are bound parameters
|
||||
return err
|
||||
})
|
||||
}
|
||||
|
||||
@@ -69,7 +69,7 @@ type SQLNames struct {
|
||||
|
||||
// DefaultSQLNames returns an SQLNames with all default resolvespec_* values.
|
||||
func DefaultSQLNames() *SQLNames {
|
||||
return &SQLNames{
|
||||
return &SQLNames{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
Login: "resolvespec_login",
|
||||
Register: "resolvespec_register",
|
||||
Logout: "resolvespec_logout",
|
||||
|
||||
@@ -31,7 +31,7 @@ type TableNames struct {
|
||||
|
||||
// DefaultTableNames returns a TableNames with all default table names.
|
||||
func DefaultTableNames() *TableNames {
|
||||
return &TableNames{
|
||||
return &TableNames{ //nolint:gosec // G101: false positive: identifier/example, not a credential
|
||||
Users: "users",
|
||||
UserSessions: "user_sessions",
|
||||
TokenBlacklist: "token_blacklist",
|
||||
|
||||
@@ -3,7 +3,7 @@ package security
|
||||
import (
|
||||
"crypto/hmac"
|
||||
"crypto/rand"
|
||||
"crypto/sha1"
|
||||
"crypto/sha1" //nolint:gosec // G505: SHA-1 is required by RFC 6238/4226 HMAC-TOTP
|
||||
"crypto/sha256"
|
||||
"crypto/sha512"
|
||||
"encoding/base32"
|
||||
@@ -117,7 +117,7 @@ func (t *TOTPGenerator) GenerateCode(secret string, timestamp time.Time) (string
|
||||
}
|
||||
|
||||
// Calculate counter (time steps since Unix epoch)
|
||||
counter := uint64(timestamp.Unix()) / uint64(t.config.Period)
|
||||
counter := uint64(timestamp.Unix()) / uint64(t.config.Period) //nolint:gosec // G115: value range bounded by caller/type, conversion intentional
|
||||
|
||||
// Generate HMAC
|
||||
h := t.getHashFunc()
|
||||
|
||||
Reference in New Issue
Block a user