Harden compliance portal auth and TLS

Align console references and OAuth branding with the
compliance-page model, and fix certificate cache eviction,
portal OAuth handlers, and magic-link edge cases left after
the trust-center rename.

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-07-20 09:59:25 +02:00
parent b03acbd029
commit 43ce3a7c53
51 changed files with 626 additions and 458 deletions

View File

@@ -46,6 +46,8 @@ func Make(s string) string {
}
func MakeWithEntropy(s string) string {
const maxDNSLabel = 63
base := Make(s)
suffix := rand.MustHexString(4)
@@ -53,5 +55,18 @@ func MakeWithEntropy(s string) string {
return suffix
}
// DNS labels are capped at 63 octets. Keep the entropy suffix and
// truncate the name-derived prefix so hostnames stay provisionable.
maxBase := maxDNSLabel - 1 - len(suffix)
if maxBase < 1 {
return suffix
}
if len(base) > maxBase {
base = strings.Trim(base[:maxBase], "-")
if base == "" {
return suffix
}
}
return base + "-" + suffix
}

View File

@@ -21,6 +21,7 @@
package slug
import (
"strings"
"testing"
"github.com/stretchr/testify/assert"
@@ -91,4 +92,15 @@ func TestMakeWithEntropy(t *testing.T) {
assert.NotEqual(t, first, second, "MakeWithEntropy should produce distinct slugs")
},
)
t.Run(
"long names stay within dns label length",
func(t *testing.T) {
t.Parallel()
got := MakeWithEntropy(strings.Repeat("Very Long Organization Name ", 10))
assert.LessOrEqual(t, len(got), 63)
assert.Regexp(t, `^[a-z0-9-]+-[0-9a-f]{8}$`, got)
},
)
}