Remove useless encryption key injections
Signed-off-by: Émile Ré <emile@getprobo.com>
This commit is contained in:
@@ -22,23 +22,19 @@ import (
|
|||||||
"go.gearno.de/kit/log"
|
"go.gearno.de/kit/log"
|
||||||
"go.gearno.de/kit/pg"
|
"go.gearno.de/kit/pg"
|
||||||
"go.probo.inc/probo/pkg/coredata"
|
"go.probo.inc/probo/pkg/coredata"
|
||||||
"go.probo.inc/probo/pkg/crypto/cipher"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type ACMEChallengeHandler struct {
|
type ACMEChallengeHandler struct {
|
||||||
pg *pg.Client
|
pg *pg.Client
|
||||||
encryptionKey cipher.EncryptionKey
|
|
||||||
logger *log.Logger
|
logger *log.Logger
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewACMEChallengeHandler(
|
func NewACMEChallengeHandler(
|
||||||
pg *pg.Client,
|
pg *pg.Client,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
logger *log.Logger,
|
logger *log.Logger,
|
||||||
) *ACMEChallengeHandler {
|
) *ACMEChallengeHandler {
|
||||||
return &ACMEChallengeHandler{
|
return &ACMEChallengeHandler{
|
||||||
pg: pg,
|
pg: pg,
|
||||||
encryptionKey: encryptionKey,
|
|
||||||
logger: logger.Named("certmanager.acme-challenge-handler"),
|
logger: logger.Named("certmanager.acme-challenge-handler"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -82,7 +78,7 @@ func (h *ACMEChallengeHandler) getKeyAuthForToken(ctx context.Context, token str
|
|||||||
ctx,
|
ctx,
|
||||||
func(conn pg.Conn) error {
|
func(conn pg.Conn) error {
|
||||||
domain := &coredata.CustomDomain{}
|
domain := &coredata.CustomDomain{}
|
||||||
if err := domain.LoadByHTTPChallengeToken(ctx, conn, coredata.NewNoScope(), h.encryptionKey, token); err != nil {
|
if err := domain.LoadByHTTPChallengeToken(ctx, conn, coredata.NewNoScope(), token); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -53,7 +53,7 @@ func (w *CacheStore) WarmCache(ctx context.Context) error {
|
|||||||
ctx,
|
ctx,
|
||||||
func(conn pg.Conn) error {
|
func(conn pg.Conn) error {
|
||||||
domains := coredata.CustomDomains{}
|
domains := coredata.CustomDomains{}
|
||||||
if err := domains.LoadActiveCertificates(ctx, conn, coredata.NewNoScope(), w.encryptionKey); err != nil {
|
if err := domains.LoadActiveCertificates(ctx, conn, coredata.NewNoScope()); err != nil {
|
||||||
return fmt.Errorf("cannot load active certificates: %w", err)
|
return fmt.Errorf("cannot load active certificates: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -95,7 +95,7 @@ func (w *CacheStore) WarmCache(ctx context.Context) error {
|
|||||||
|
|
||||||
func (w *CacheStore) warmDomain(ctx context.Context, conn pg.Conn, domain *coredata.CustomDomain) error {
|
func (w *CacheStore) warmDomain(ctx context.Context, conn pg.Conn, domain *coredata.CustomDomain) error {
|
||||||
var loadedDomain coredata.CustomDomain
|
var loadedDomain coredata.CustomDomain
|
||||||
if err := loadedDomain.LoadByID(ctx, conn, coredata.NewNoScope(), w.encryptionKey, domain.ID); err != nil {
|
if err := loadedDomain.LoadByID(ctx, conn, coredata.NewNoScope(), domain.ID); err != nil {
|
||||||
return fmt.Errorf("cannot load domain with decrypted values: %w", err)
|
return fmt.Errorf("cannot load domain with decrypted values: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -162,7 +162,7 @@ func (w *CacheStore) WarmSingleDomain(ctx context.Context, domainName string) er
|
|||||||
ctx,
|
ctx,
|
||||||
func(conn pg.Conn) error {
|
func(conn pg.Conn) error {
|
||||||
var domain coredata.CustomDomain
|
var domain coredata.CustomDomain
|
||||||
if err := domain.LoadByDomain(ctx, conn, coredata.NewNoScope(), w.encryptionKey, domainName); err != nil {
|
if err := domain.LoadByDomain(ctx, conn, coredata.NewNoScope(), domainName); err != nil {
|
||||||
return fmt.Errorf("cannot load domain: %w", err)
|
return fmt.Errorf("cannot load domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -224,7 +224,7 @@ func (p *Provisioner) resetStaleDomain(
|
|||||||
domain *coredata.CustomDomain,
|
domain *coredata.CustomDomain,
|
||||||
) error {
|
) error {
|
||||||
fullDomain := &coredata.CustomDomain{}
|
fullDomain := &coredata.CustomDomain{}
|
||||||
if err := fullDomain.LoadByIDForUpdateSkipLocked(ctx, tx, coredata.NewNoScope(), p.encryptionKey, domain.ID); err != nil {
|
if err := fullDomain.LoadByIDForUpdateSkipLocked(ctx, tx, coredata.NewNoScope(), domain.ID); err != nil {
|
||||||
if errors.Is(err, coredata.ErrResourceNotFound) {
|
if errors.Is(err, coredata.ErrResourceNotFound) {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
@@ -260,7 +260,7 @@ func (p *Provisioner) resetStaleDomain(
|
|||||||
fullDomain.SSLLastAttemptAt = nil
|
fullDomain.SSLLastAttemptAt = nil
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := fullDomain.Update(ctx, tx, coredata.NewNoScope(), p.encryptionKey); err != nil {
|
if err := fullDomain.Update(ctx, tx, coredata.NewNoScope()); err != nil {
|
||||||
return fmt.Errorf("cannot update stale domain: %w", err)
|
return fmt.Errorf("cannot update stale domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -273,7 +273,7 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
domainID gid.GID,
|
domainID gid.GID,
|
||||||
) error {
|
) error {
|
||||||
domain := &coredata.CustomDomain{}
|
domain := &coredata.CustomDomain{}
|
||||||
if err := domain.LoadByIDForUpdateSkipLocked(ctx, tx, coredata.NewNoScope(), p.encryptionKey, domainID); err != nil {
|
if err := domain.LoadByIDForUpdateSkipLocked(ctx, tx, coredata.NewNoScope(), domainID); err != nil {
|
||||||
if errors.Is(err, coredata.ErrResourceNotFound) {
|
if errors.Is(err, coredata.ErrResourceNotFound) {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
@@ -312,7 +312,7 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
domain.HTTPOrderURL = &challenge.OrderURL
|
domain.HTTPOrderURL = &challenge.OrderURL
|
||||||
domain.SSLStatus = coredata.CustomDomainSSLStatusProvisioning
|
domain.SSLStatus = coredata.CustomDomainSSLStatusProvisioning
|
||||||
|
|
||||||
if err := domain.Update(ctx, tx, coredata.NewNoScope(), p.encryptionKey); err != nil {
|
if err := domain.Update(ctx, tx, coredata.NewNoScope()); err != nil {
|
||||||
return fmt.Errorf("cannot update domain with challenge: %w", err)
|
return fmt.Errorf("cannot update domain with challenge: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -362,7 +362,7 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
domain.HTTPOrderURL = nil
|
domain.HTTPOrderURL = nil
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := domain.Update(ctx, tx, coredata.NewNoScope(), p.encryptionKey); err != nil {
|
if err := domain.Update(ctx, tx, coredata.NewNoScope()); err != nil {
|
||||||
return fmt.Errorf("cannot update domain: %w", err)
|
return fmt.Errorf("cannot update domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -393,7 +393,7 @@ func (p *Provisioner) provisionDomainCertificate(
|
|||||||
domain.HTTPChallengeURL = nil
|
domain.HTTPChallengeURL = nil
|
||||||
domain.HTTPOrderURL = nil
|
domain.HTTPOrderURL = nil
|
||||||
|
|
||||||
if err := domain.Update(ctx, tx, coredata.NewNoScope(), p.encryptionKey); err != nil {
|
if err := domain.Update(ctx, tx, coredata.NewNoScope()); err != nil {
|
||||||
return fmt.Errorf("cannot update domain: %w", err)
|
return fmt.Errorf("cannot update domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -130,7 +130,7 @@ func (r *Renewer) checkAndRenew(ctx context.Context) error {
|
|||||||
|
|
||||||
func (r *Renewer) renewDomain(ctx context.Context, tx pg.Conn, domainID gid.GID) error {
|
func (r *Renewer) renewDomain(ctx context.Context, tx pg.Conn, domainID gid.GID) error {
|
||||||
domain := &coredata.CustomDomain{}
|
domain := &coredata.CustomDomain{}
|
||||||
if err := domain.LoadByIDForUpdateSkipLocked(ctx, tx, coredata.NewNoScope(), r.encryptionKey, domainID); err != nil {
|
if err := domain.LoadByIDForUpdateSkipLocked(ctx, tx, coredata.NewNoScope(), domainID); err != nil {
|
||||||
if errors.Is(err, coredata.ErrResourceNotFound) {
|
if errors.Is(err, coredata.ErrResourceNotFound) {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
@@ -149,7 +149,7 @@ func (r *Renewer) renewDomain(ctx context.Context, tx pg.Conn, domainID gid.GID)
|
|||||||
}
|
}
|
||||||
|
|
||||||
domain.SSLStatus = coredata.CustomDomainSSLStatusRenewing
|
domain.SSLStatus = coredata.CustomDomainSSLStatusRenewing
|
||||||
if err := domain.Update(ctx, tx, coredata.NewNoScope(), r.encryptionKey); err != nil {
|
if err := domain.Update(ctx, tx, coredata.NewNoScope()); err != nil {
|
||||||
return fmt.Errorf("cannot update domain status: %w", err)
|
return fmt.Errorf("cannot update domain status: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -116,7 +116,7 @@ func (s *Selector) loadFromDatabase(domain string) (*tls.Certificate, error) {
|
|||||||
|
|
||||||
func (s *Selector) rebuildCacheEntry(ctx context.Context, conn pg.Conn, domain string) error {
|
func (s *Selector) rebuildCacheEntry(ctx context.Context, conn pg.Conn, domain string) error {
|
||||||
var customDomain coredata.CustomDomain
|
var customDomain coredata.CustomDomain
|
||||||
if err := customDomain.LoadByDomain(ctx, conn, coredata.NewNoScope(), s.encryptionKey, domain); err != nil {
|
if err := customDomain.LoadByDomain(ctx, conn, coredata.NewNoScope(), domain); err != nil {
|
||||||
return fmt.Errorf("cannot load domain: %w", err)
|
return fmt.Errorf("cannot load domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -153,7 +153,6 @@ func (cd *CustomDomain) LoadByID(
|
|||||||
ctx context.Context,
|
ctx context.Context,
|
||||||
conn pg.Conn,
|
conn pg.Conn,
|
||||||
scope Scoper,
|
scope Scoper,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
domainID gid.GID,
|
domainID gid.GID,
|
||||||
) error {
|
) error {
|
||||||
q := `
|
q := `
|
||||||
@@ -210,7 +209,6 @@ func (cd *CustomDomain) LoadByIDForUpdateSkipLocked(
|
|||||||
ctx context.Context,
|
ctx context.Context,
|
||||||
conn pg.Conn,
|
conn pg.Conn,
|
||||||
scope Scoper,
|
scope Scoper,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
domainID gid.GID,
|
domainID gid.GID,
|
||||||
) error {
|
) error {
|
||||||
q := `
|
q := `
|
||||||
@@ -267,7 +265,6 @@ func (cd *CustomDomain) LoadByDomain(
|
|||||||
ctx context.Context,
|
ctx context.Context,
|
||||||
conn pg.Conn,
|
conn pg.Conn,
|
||||||
scope Scoper,
|
scope Scoper,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
domain string,
|
domain string,
|
||||||
) error {
|
) error {
|
||||||
q := `
|
q := `
|
||||||
@@ -324,7 +321,6 @@ func (cd *CustomDomain) LoadByOrganizationID(
|
|||||||
ctx context.Context,
|
ctx context.Context,
|
||||||
conn pg.Conn,
|
conn pg.Conn,
|
||||||
scope Scoper,
|
scope Scoper,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
organizationID gid.GID,
|
organizationID gid.GID,
|
||||||
) error {
|
) error {
|
||||||
q := `
|
q := `
|
||||||
@@ -468,7 +464,6 @@ func (cd *CustomDomain) Update(
|
|||||||
ctx context.Context,
|
ctx context.Context,
|
||||||
conn pg.Conn,
|
conn pg.Conn,
|
||||||
scope Scoper,
|
scope Scoper,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
) error {
|
) error {
|
||||||
var encryptedKey []byte
|
var encryptedKey []byte
|
||||||
if len(cd.EncryptedSSLPrivateKey) > 0 {
|
if len(cd.EncryptedSSLPrivateKey) > 0 {
|
||||||
@@ -554,7 +549,6 @@ func (cd *CustomDomain) LoadByHTTPChallengeToken(
|
|||||||
ctx context.Context,
|
ctx context.Context,
|
||||||
conn pg.Conn,
|
conn pg.Conn,
|
||||||
scope Scoper,
|
scope Scoper,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
token string,
|
token string,
|
||||||
) error {
|
) error {
|
||||||
q := `
|
q := `
|
||||||
@@ -714,7 +708,6 @@ func (domains *CustomDomains) LoadActiveCertificates(
|
|||||||
ctx context.Context,
|
ctx context.Context,
|
||||||
conn pg.Conn,
|
conn pg.Conn,
|
||||||
scope Scoper,
|
scope Scoper,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
) error {
|
) error {
|
||||||
q := `
|
q := `
|
||||||
SELECT
|
SELECT
|
||||||
|
|||||||
@@ -114,7 +114,7 @@ func (s *CompliancePageService) EmailPresenterConfig(ctx context.Context, compli
|
|||||||
}
|
}
|
||||||
|
|
||||||
customDomain = &coredata.CustomDomain{}
|
customDomain = &coredata.CustomDomain{}
|
||||||
if err := customDomain.LoadByOrganizationID(ctx, conn, scope, s.encryptionKey, organization.ID); err != nil {
|
if err := customDomain.LoadByOrganizationID(ctx, conn, scope, organization.ID); err != nil {
|
||||||
if !errors.Is(err, coredata.ErrResourceNotFound) {
|
if !errors.Is(err, coredata.ErrResourceNotFound) {
|
||||||
return fmt.Errorf("cannot load custom domain: %w", err)
|
return fmt.Errorf("cannot load custom domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1900,35 +1900,6 @@ func (s OrganizationService) GetSCIMBridgeByID(ctx context.Context, bridgeID gid
|
|||||||
return bridge, nil
|
return bridge, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s OrganizationService) GetConnectorByID(ctx context.Context, connectorID gid.GID) (*coredata.Connector, error) {
|
|
||||||
var (
|
|
||||||
scope = coredata.NewScopeFromObjectID(connectorID)
|
|
||||||
connector = &coredata.Connector{}
|
|
||||||
)
|
|
||||||
|
|
||||||
err := s.pg.WithConn(
|
|
||||||
ctx,
|
|
||||||
func(conn pg.Conn) error {
|
|
||||||
err := connector.LoadByID(ctx, conn, scope, connectorID, s.encryptionKey)
|
|
||||||
if err != nil {
|
|
||||||
if err == coredata.ErrResourceNotFound {
|
|
||||||
return NewConnectorNotFoundError(connectorID)
|
|
||||||
}
|
|
||||||
|
|
||||||
return fmt.Errorf("cannot load connector: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
},
|
|
||||||
)
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
return connector, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// GetConnectorMetadataByID returns connector metadata without decrypting the connection.
|
// GetConnectorMetadataByID returns connector metadata without decrypting the connection.
|
||||||
// Use this when you only need provider, organization, or other metadata fields.
|
// Use this when you only need provider, organization, or other metadata fields.
|
||||||
func (s OrganizationService) GetConnectorMetadataByID(ctx context.Context, connectorID gid.GID) (*coredata.Connector, error) {
|
func (s OrganizationService) GetConnectorMetadataByID(ctx context.Context, connectorID gid.GID) (*coredata.Connector, error) {
|
||||||
|
|||||||
@@ -31,14 +31,12 @@ import (
|
|||||||
"go.gearno.de/kit/pg"
|
"go.gearno.de/kit/pg"
|
||||||
"go.probo.inc/probo/pkg/baseurl"
|
"go.probo.inc/probo/pkg/baseurl"
|
||||||
"go.probo.inc/probo/pkg/coredata"
|
"go.probo.inc/probo/pkg/coredata"
|
||||||
"go.probo.inc/probo/pkg/crypto/cipher"
|
|
||||||
"go.probo.inc/probo/pkg/gid"
|
"go.probo.inc/probo/pkg/gid"
|
||||||
)
|
)
|
||||||
|
|
||||||
type (
|
type (
|
||||||
Service struct {
|
Service struct {
|
||||||
pg *pg.Client
|
pg *pg.Client
|
||||||
encryptionKey cipher.EncryptionKey
|
|
||||||
baseURL string
|
baseURL string
|
||||||
certificate *x509.Certificate
|
certificate *x509.Certificate
|
||||||
privateKey *rsa.PrivateKey
|
privateKey *rsa.PrivateKey
|
||||||
@@ -57,7 +55,6 @@ type (
|
|||||||
|
|
||||||
func NewService(
|
func NewService(
|
||||||
pg *pg.Client,
|
pg *pg.Client,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
baseURL string,
|
baseURL string,
|
||||||
certificate *x509.Certificate,
|
certificate *x509.Certificate,
|
||||||
privateKey *rsa.PrivateKey,
|
privateKey *rsa.PrivateKey,
|
||||||
@@ -65,7 +62,6 @@ func NewService(
|
|||||||
) (*Service, error) {
|
) (*Service, error) {
|
||||||
return &Service{
|
return &Service{
|
||||||
pg: pg,
|
pg: pg,
|
||||||
encryptionKey: encryptionKey,
|
|
||||||
baseURL: baseURL,
|
baseURL: baseURL,
|
||||||
certificate: certificate,
|
certificate: certificate,
|
||||||
privateKey: privateKey,
|
privateKey: privateKey,
|
||||||
|
|||||||
@@ -28,7 +28,6 @@ type (
|
|||||||
pg *pg.Client
|
pg *pg.Client
|
||||||
fm *filemanager.Service
|
fm *filemanager.Service
|
||||||
hp *passwdhash.Profile
|
hp *passwdhash.Profile
|
||||||
encryptionKey cipher.EncryptionKey
|
|
||||||
baseURL string
|
baseURL string
|
||||||
tokenSecret string
|
tokenSecret string
|
||||||
disableSignup bool
|
disableSignup bool
|
||||||
@@ -127,7 +126,7 @@ func NewService(
|
|||||||
svc.Authorizer = NewAuthorizer(pgClient)
|
svc.Authorizer = NewAuthorizer(pgClient)
|
||||||
svc.Authorizer.RegisterPolicySet(IAMPolicySet())
|
svc.Authorizer.RegisterPolicySet(IAMPolicySet())
|
||||||
|
|
||||||
samlService, err := saml.NewService(svc.pg, svc.encryptionKey, svc.baseURL, svc.certificate, svc.privateKey, cfg.Logger)
|
samlService, err := saml.NewService(svc.pg, svc.baseURL, svc.certificate, svc.privateKey, cfg.Logger)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("cannot create SAML service: %w", err)
|
return nil, fmt.Errorf("cannot create SAML service: %w", err)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -122,7 +122,7 @@ func (s *CustomDomainService) DeleteCustomDomain(
|
|||||||
}
|
}
|
||||||
|
|
||||||
domain := &coredata.CustomDomain{}
|
domain := &coredata.CustomDomain{}
|
||||||
if err := domain.LoadByID(ctx, tx, s.svc.scope, s.encryptionKey, *org.CustomDomainID); err != nil {
|
if err := domain.LoadByID(ctx, tx, s.svc.scope, *org.CustomDomainID); err != nil {
|
||||||
return fmt.Errorf("cannot load domain: %w", err)
|
return fmt.Errorf("cannot load domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -159,7 +159,7 @@ func (s *CustomDomainService) GetOrganizationCustomDomain(
|
|||||||
}
|
}
|
||||||
|
|
||||||
domain = &coredata.CustomDomain{}
|
domain = &coredata.CustomDomain{}
|
||||||
if err := domain.LoadByID(ctx, conn, s.svc.scope, s.encryptionKey, *org.CustomDomainID); err != nil {
|
if err := domain.LoadByID(ctx, conn, s.svc.scope, *org.CustomDomainID); err != nil {
|
||||||
return fmt.Errorf("cannot load custom domain: %w", err)
|
return fmt.Errorf("cannot load custom domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -399,7 +399,7 @@ func (s *Service) LoadOrganizationByDomain(ctx context.Context, domain string) (
|
|||||||
ctx,
|
ctx,
|
||||||
func(conn pg.Conn) error {
|
func(conn pg.Conn) error {
|
||||||
var customDomain coredata.CustomDomain
|
var customDomain coredata.CustomDomain
|
||||||
if err := customDomain.LoadByDomain(ctx, conn, coredata.NewNoScope(), s.encryptionKey, domain); err != nil {
|
if err := customDomain.LoadByDomain(ctx, conn, coredata.NewNoScope(), domain); err != nil {
|
||||||
return fmt.Errorf("cannot load custom domain: %w", err)
|
return fmt.Errorf("cannot load custom domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -617,7 +617,7 @@ func (s *TrustCenterService) EmailPresenterConfig(ctx context.Context, complianc
|
|||||||
}
|
}
|
||||||
|
|
||||||
customDomain = &coredata.CustomDomain{}
|
customDomain = &coredata.CustomDomain{}
|
||||||
if err := customDomain.LoadByOrganizationID(ctx, conn, scope, s.svc.encryptionKey, organization.ID); err != nil {
|
if err := customDomain.LoadByOrganizationID(ctx, conn, scope, organization.ID); err != nil {
|
||||||
if !errors.Is(err, coredata.ErrResourceNotFound) {
|
if !errors.Is(err, coredata.ErrResourceNotFound) {
|
||||||
return fmt.Errorf("cannot load custom domain: %w", err)
|
return fmt.Errorf("cannot load custom domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -422,7 +422,6 @@ func (impl *Implm) Run(
|
|||||||
pgClient,
|
pgClient,
|
||||||
impl.cfg.GetSlackSigningSecret(),
|
impl.cfg.GetSlackSigningSecret(),
|
||||||
baseURL.String(),
|
baseURL.String(),
|
||||||
encryptionKey,
|
|
||||||
impl.cfg.Auth.Cookie.Secret,
|
impl.cfg.Auth.Cookie.Secret,
|
||||||
l.Named("slack"),
|
l.Named("slack"),
|
||||||
)
|
)
|
||||||
@@ -462,7 +461,6 @@ func (impl *Implm) Run(
|
|||||||
s3Client,
|
s3Client,
|
||||||
impl.cfg.AWS.Bucket,
|
impl.cfg.AWS.Bucket,
|
||||||
baseURL.String(),
|
baseURL.String(),
|
||||||
encryptionKey,
|
|
||||||
impl.cfg.GetSlackSigningSecret(),
|
impl.cfg.GetSlackSigningSecret(),
|
||||||
iamService,
|
iamService,
|
||||||
esignService,
|
esignService,
|
||||||
@@ -817,7 +815,6 @@ func (impl *Implm) runTrustCenterServer(
|
|||||||
|
|
||||||
httpACMEHandler := certmanager.NewACMEChallengeHandler(
|
httpACMEHandler := certmanager.NewACMEChallengeHandler(
|
||||||
pgClient,
|
pgClient,
|
||||||
encryptionKey,
|
|
||||||
l.Named("http_acme_handler"),
|
l.Named("http_acme_handler"),
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -863,7 +860,6 @@ func (impl *Implm) runTrustCenterServer(
|
|||||||
|
|
||||||
acmeHandler := certmanager.NewACMEChallengeHandler(
|
acmeHandler := certmanager.NewACMEChallengeHandler(
|
||||||
pgClient,
|
pgClient,
|
||||||
encryptionKey,
|
|
||||||
l.Named("acme_handler"),
|
l.Named("acme_handler"),
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ import (
|
|||||||
"go.gearno.de/kit/log"
|
"go.gearno.de/kit/log"
|
||||||
"go.gearno.de/kit/pg"
|
"go.gearno.de/kit/pg"
|
||||||
"go.probo.inc/probo/pkg/coredata"
|
"go.probo.inc/probo/pkg/coredata"
|
||||||
"go.probo.inc/probo/pkg/crypto/cipher"
|
|
||||||
"go.probo.inc/probo/pkg/gid"
|
"go.probo.inc/probo/pkg/gid"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -16,7 +15,6 @@ type Service struct {
|
|||||||
logger *log.Logger
|
logger *log.Logger
|
||||||
slackSigningSecret string
|
slackSigningSecret string
|
||||||
baseURL string
|
baseURL string
|
||||||
encryptionKey cipher.EncryptionKey
|
|
||||||
tokenSecret string
|
tokenSecret string
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -25,7 +23,6 @@ type TenantService struct {
|
|||||||
scope coredata.Scoper
|
scope coredata.Scoper
|
||||||
logger *log.Logger
|
logger *log.Logger
|
||||||
baseURL string
|
baseURL string
|
||||||
encryptionKey cipher.EncryptionKey
|
|
||||||
tokenSecret string
|
tokenSecret string
|
||||||
SlackMessages *SlackMessageService
|
SlackMessages *SlackMessageService
|
||||||
}
|
}
|
||||||
@@ -34,7 +31,6 @@ func NewService(
|
|||||||
pg *pg.Client,
|
pg *pg.Client,
|
||||||
slackSigningSecret string,
|
slackSigningSecret string,
|
||||||
baseURL string,
|
baseURL string,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
tokenSecret string,
|
tokenSecret string,
|
||||||
logger *log.Logger,
|
logger *log.Logger,
|
||||||
) *Service {
|
) *Service {
|
||||||
@@ -43,7 +39,6 @@ func NewService(
|
|||||||
logger: logger,
|
logger: logger,
|
||||||
slackSigningSecret: slackSigningSecret,
|
slackSigningSecret: slackSigningSecret,
|
||||||
baseURL: baseURL,
|
baseURL: baseURL,
|
||||||
encryptionKey: encryptionKey,
|
|
||||||
tokenSecret: tokenSecret,
|
tokenSecret: tokenSecret,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -54,7 +49,6 @@ func (s *Service) WithTenant(tenantID gid.TenantID) *TenantService {
|
|||||||
scope: coredata.NewScope(tenantID),
|
scope: coredata.NewScope(tenantID),
|
||||||
logger: s.logger,
|
logger: s.logger,
|
||||||
baseURL: s.baseURL,
|
baseURL: s.baseURL,
|
||||||
encryptionKey: s.encryptionKey,
|
|
||||||
tokenSecret: s.tokenSecret,
|
tokenSecret: s.tokenSecret,
|
||||||
}
|
}
|
||||||
tenantService.SlackMessages = &SlackMessageService{svc: tenantService}
|
tenantService.SlackMessages = &SlackMessageService{svc: tenantService}
|
||||||
|
|||||||
@@ -79,7 +79,7 @@ func (s OrganizationService) GetOrganizationCustomDomain(
|
|||||||
}
|
}
|
||||||
|
|
||||||
domain = &coredata.CustomDomain{}
|
domain = &coredata.CustomDomain{}
|
||||||
if err := domain.LoadByID(ctx, conn, s.svc.scope, s.svc.encryptionKey, *org.CustomDomainID); err != nil {
|
if err := domain.LoadByID(ctx, conn, s.svc.scope, *org.CustomDomainID); err != nil {
|
||||||
return fmt.Errorf("cannot load custom domain: %w", err)
|
return fmt.Errorf("cannot load custom domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -24,7 +24,6 @@ import (
|
|||||||
"go.gearno.de/kit/pg"
|
"go.gearno.de/kit/pg"
|
||||||
"go.probo.inc/probo/packages/emails"
|
"go.probo.inc/probo/packages/emails"
|
||||||
"go.probo.inc/probo/pkg/coredata"
|
"go.probo.inc/probo/pkg/coredata"
|
||||||
"go.probo.inc/probo/pkg/crypto/cipher"
|
|
||||||
"go.probo.inc/probo/pkg/esign"
|
"go.probo.inc/probo/pkg/esign"
|
||||||
"go.probo.inc/probo/pkg/filemanager"
|
"go.probo.inc/probo/pkg/filemanager"
|
||||||
"go.probo.inc/probo/pkg/gid"
|
"go.probo.inc/probo/pkg/gid"
|
||||||
@@ -40,7 +39,6 @@ type (
|
|||||||
s3 *s3.Client
|
s3 *s3.Client
|
||||||
bucket string
|
bucket string
|
||||||
proboSvc *probo.Service
|
proboSvc *probo.Service
|
||||||
encryptionKey cipher.EncryptionKey
|
|
||||||
slackSigningSecret string
|
slackSigningSecret string
|
||||||
baseURL string
|
baseURL string
|
||||||
iam *iam.Service
|
iam *iam.Service
|
||||||
@@ -57,7 +55,6 @@ type (
|
|||||||
bucket string
|
bucket string
|
||||||
scope coredata.Scoper
|
scope coredata.Scoper
|
||||||
proboSvc *probo.Service
|
proboSvc *probo.Service
|
||||||
encryptionKey cipher.EncryptionKey
|
|
||||||
baseURL string
|
baseURL string
|
||||||
iam *iam.Service
|
iam *iam.Service
|
||||||
esign *esign.Service
|
esign *esign.Service
|
||||||
@@ -84,7 +81,6 @@ func NewService(
|
|||||||
s3Client *s3.Client,
|
s3Client *s3.Client,
|
||||||
bucket string,
|
bucket string,
|
||||||
baseURL string,
|
baseURL string,
|
||||||
encryptionKey cipher.EncryptionKey,
|
|
||||||
slackSigningSecret string,
|
slackSigningSecret string,
|
||||||
iam *iam.Service,
|
iam *iam.Service,
|
||||||
esignSvc *esign.Service,
|
esignSvc *esign.Service,
|
||||||
@@ -97,7 +93,6 @@ func NewService(
|
|||||||
pg: pgClient,
|
pg: pgClient,
|
||||||
s3: s3Client,
|
s3: s3Client,
|
||||||
bucket: bucket,
|
bucket: bucket,
|
||||||
encryptionKey: encryptionKey,
|
|
||||||
slackSigningSecret: slackSigningSecret,
|
slackSigningSecret: slackSigningSecret,
|
||||||
baseURL: baseURL,
|
baseURL: baseURL,
|
||||||
iam: iam,
|
iam: iam,
|
||||||
@@ -116,7 +111,6 @@ func (s *Service) WithTenant(tenantID gid.TenantID) *TenantService {
|
|||||||
bucket: s.bucket,
|
bucket: s.bucket,
|
||||||
scope: coredata.NewScope(tenantID),
|
scope: coredata.NewScope(tenantID),
|
||||||
proboSvc: s.proboSvc,
|
proboSvc: s.proboSvc,
|
||||||
encryptionKey: s.encryptionKey,
|
|
||||||
baseURL: s.baseURL,
|
baseURL: s.baseURL,
|
||||||
iam: s.iam,
|
iam: s.iam,
|
||||||
esign: s.esign,
|
esign: s.esign,
|
||||||
@@ -204,7 +198,7 @@ func (s *Service) GetByDomainName(ctx context.Context, domain string) (*coredata
|
|||||||
ctx,
|
ctx,
|
||||||
func(conn pg.Conn) error {
|
func(conn pg.Conn) error {
|
||||||
var customDomain coredata.CustomDomain
|
var customDomain coredata.CustomDomain
|
||||||
if err := customDomain.LoadByDomain(ctx, conn, coredata.NewNoScope(), s.encryptionKey, domain); err != nil {
|
if err := customDomain.LoadByDomain(ctx, conn, coredata.NewNoScope(), domain); err != nil {
|
||||||
if errors.Is(err, coredata.ErrResourceNotFound) {
|
if errors.Is(err, coredata.ErrResourceNotFound) {
|
||||||
return ErrPageNotFound
|
return ErrPageNotFound
|
||||||
}
|
}
|
||||||
@@ -247,7 +241,7 @@ func (s *Service) GetCustomDomainByOrganizationID(ctx context.Context, organizat
|
|||||||
err := s.pg.WithConn(
|
err := s.pg.WithConn(
|
||||||
ctx,
|
ctx,
|
||||||
func(conn pg.Conn) error {
|
func(conn pg.Conn) error {
|
||||||
return customDomain.LoadByOrganizationID(ctx, conn, coredata.NewNoScope(), s.encryptionKey, organizationID)
|
return customDomain.LoadByOrganizationID(ctx, conn, coredata.NewNoScope(), organizationID)
|
||||||
},
|
},
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
@@ -274,7 +274,7 @@ func (s *TrustCenterService) EmailPresenterConfig(ctx context.Context, complianc
|
|||||||
}
|
}
|
||||||
|
|
||||||
customDomain = &coredata.CustomDomain{}
|
customDomain = &coredata.CustomDomain{}
|
||||||
if err := customDomain.LoadByOrganizationID(ctx, conn, scope, s.svc.encryptionKey, organization.ID); err != nil {
|
if err := customDomain.LoadByOrganizationID(ctx, conn, scope, organization.ID); err != nil {
|
||||||
if !errors.Is(err, coredata.ErrResourceNotFound) {
|
if !errors.Is(err, coredata.ErrResourceNotFound) {
|
||||||
return fmt.Errorf("cannot load custom domain: %w", err)
|
return fmt.Errorf("cannot load custom domain: %w", err)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user