Adds internal/web/oidc.DexAuth, the production web.Auth impl behind the seam (ADR-011, docs/ui-spec.md §6). Standard Authorization Code flow against Dex: - Routes() mounts /auth/login (state+nonce, redirect to authorize), /auth/callback (code exchange, ID-token verify, nonce check, allowlist: sub must equal Config.AllowedSubject else 403, set session, redirect /), /auth/logout (clear session). - Middleware redirects unauthenticated requests to /auth/login, slides the session expiry on each authenticated request; /healthz and /auth/* bypass. - CurrentUser resolves the principal from the session cookie. - Sessions: server-side in-memory store (single Stage-0 replica) keyed by an HMAC-SHA256 (HS256) signed, HttpOnly, Secure, SameSite=Lax cookie with a short TTL + sliding refresh. State->nonce pending map is one-time + expiring (replay/CSRF defense). Tokens are never logged. Constructor New(ctx, Config, ...Option); the six-field Config (Issuer, ClientID, ClientSecret, RedirectURL, SessionSecret, AllowedSubject) is what cmd/tapir wires from TAPIR_OIDC_*/TAPIR_DEX_*/TAPIR_SESSION_SECRET/ TAPIR_ALLOWED_SUBJECT. Options (clock, TTL, insecure cookies) are test-only. Tests use a fake OIDC issuer via httptest (discovery + JWKS + token endpoint signing an RS256 ID token) — no live Dex: login 302s to authorize; callback for the allowlisted sub sets a session and 302s to /; non-allowlisted sub 403; middleware redirects unauthenticated and passes authenticated; logout clears; plus expiry, tampered-cookie, and unknown-state cases. Deps (per ADR-006 / ui-spec §6): adds github.com/coreos/go-oidc/v3 — the homelab-standard OIDC lib, small, handles discovery + JWKS + ID-token verification; pairs with the already-present golang.org/x/oauth2. go-jose/v4 (transitive via go-oidc) is used directly only in tests to sign the fake issuer's tokens. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
29 lines
1023 B
AMPL
29 lines
1023 B
AMPL
module gitea.d-ma.be/mathias/tapir
|
|
|
|
go 1.25.0
|
|
|
|
require (
|
|
github.com/coreos/go-oidc/v3 v3.18.0
|
|
github.com/fergusstrange/embedded-postgres v1.34.0
|
|
github.com/go-jose/go-jose/v4 v4.1.4
|
|
github.com/golang-migrate/migrate/v4 v4.19.1
|
|
github.com/jackc/pgx/v5 v5.9.2
|
|
github.com/stretchr/testify v1.11.1
|
|
golang.org/x/oauth2 v0.36.0
|
|
)
|
|
|
|
require (
|
|
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
|
|
github.com/jackc/pgerrcode v0.0.0-20220416144525-469b46aa5efa // indirect
|
|
github.com/jackc/pgpassfile v1.0.0 // indirect
|
|
github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
|
|
github.com/jackc/puddle/v2 v2.2.2 // indirect
|
|
github.com/lib/pq v1.10.9 // indirect
|
|
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
|
|
github.com/rogpeppe/go-internal v1.15.0 // indirect
|
|
github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 // indirect
|
|
golang.org/x/sync v0.18.0 // indirect
|
|
golang.org/x/text v0.31.0 // indirect
|
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
|
)
|