Harden compliance portal auth and TLS

Align console references and OAuth branding with the
compliance-page model, and fix certificate cache eviction,
portal OAuth handlers, and magic-link edge cases left after
the trust-center rename.

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-07-20 09:59:25 +02:00
parent b03acbd029
commit 43ce3a7c53
51 changed files with 626 additions and 458 deletions

View File

@@ -62,7 +62,6 @@ type (
magicLinkTokenValidity time.Duration
sessionDuration time.Duration
bucket string
encryptionKey cipher.EncryptionKey
trustCenterBaseDomain string
certManager *certmanager.Service
certificate *x509.Certificate
@@ -150,6 +149,10 @@ func NewService(
return nil, fmt.Errorf("oauth2 scope registry is required")
}
if cfg.CertManager == nil {
return nil, fmt.Errorf("cert manager is required")
}
svc := &Service{
pg: pgClient,
fm: fm,
@@ -163,7 +166,6 @@ func NewService(
magicLinkTokenValidity: cfg.MagicLinkTokenValidity,
sessionDuration: cfg.SessionDuration,
bucket: cfg.Bucket,
encryptionKey: cfg.EncryptionKey,
trustCenterBaseDomain: cfg.TrustCenterBaseDomain,
certManager: cfg.CertManager,
certificate: cfg.Certificate,