Harden compliance portal auth and TLS
Align console references and OAuth branding with the compliance-page model, and fix certificate cache eviction, portal OAuth handlers, and magic-link edge cases left after the trust-center rename. Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
@@ -29,38 +29,26 @@ const (
|
||||
)
|
||||
|
||||
func CIMDClientIDURL(portalBaseURL string) (string, error) {
|
||||
parsed, err := url.Parse(portalBaseURL)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
parsed.Path = CIMDMetadataPath
|
||||
parsed.RawQuery = ""
|
||||
parsed.Fragment = ""
|
||||
|
||||
return parsed.String(), nil
|
||||
return portalEndpointURL(portalBaseURL, CIMDMetadataPath)
|
||||
}
|
||||
|
||||
func OAuthCallbackURL(portalBaseURL string) (string, error) {
|
||||
parsed, err := url.Parse(portalBaseURL)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
parsed.Path = OAuthCallbackPath
|
||||
parsed.RawQuery = ""
|
||||
parsed.Fragment = ""
|
||||
|
||||
return parsed.String(), nil
|
||||
return portalEndpointURL(portalBaseURL, OAuthCallbackPath)
|
||||
}
|
||||
|
||||
func PortalRootURL(rawURL string) (string, error) {
|
||||
parsed, err := url.Parse(rawURL)
|
||||
return portalEndpointURL(rawURL, "")
|
||||
}
|
||||
|
||||
// portalEndpointURL replaces the path on a portal base URL and clears
|
||||
// query/fragment. Shared by CIMD, OAuth callback, and brand asset URLs.
|
||||
func portalEndpointURL(portalBaseURL string, path string) (string, error) {
|
||||
parsed, err := url.Parse(portalBaseURL)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("cannot parse portal URL: %w", err)
|
||||
}
|
||||
|
||||
parsed.Path = ""
|
||||
parsed.Path = path
|
||||
parsed.RawQuery = ""
|
||||
parsed.Fragment = ""
|
||||
|
||||
|
||||
Reference in New Issue
Block a user