Inline OAuth2 signing key in config
The OAuth2/OIDC server accepted its signing key via a file path (key-file), while every other PEM key in the probod config (SAML private key, ACME account key) is embedded inline. Switch the field to a private-key string so the convention is uniform. The signing key is operator-supplied material that must outlive any process restart, so the bootstrap builder now treats OAUTH2_SERVER_SIGNING_KEY as required and refuses to start without one; silently minting a fresh key per boot would break token validation across rollouts. The OAUTH2_SERVER_* env vars otherwise flow through builder.Build like the existing SAML block so the new OAuth2Server section is populated end-to-end. Rework the e2e harness to render its config via bootstrap at test setup, which removes the static e2e/console/testdata/config.yaml and the previously generated test-only PEM file. A per-run RSA key is minted via bootstrap.GenerateOAuth2SigningKey (kept public for test tooling) and injected through the builder env map. CI now passes ACME_ROOT_CA inline instead of mutating a YAML on disk. Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
@@ -26,9 +26,10 @@ import (
|
||||
type EnvGetter func(key string) string
|
||||
|
||||
type Builder struct {
|
||||
getEnv EnvGetter
|
||||
samlCertificate string
|
||||
samlPrivateKey string
|
||||
getEnv EnvGetter
|
||||
samlCertificate string
|
||||
samlPrivateKey string
|
||||
oauth2SigningKey string
|
||||
}
|
||||
|
||||
func NewBuilder(getEnv EnvGetter) *Builder {
|
||||
@@ -48,6 +49,8 @@ func (b *Builder) Build() (*probod.FullConfig, error) {
|
||||
return nil, fmt.Errorf("cannot get SAML credentials: %w", err)
|
||||
}
|
||||
|
||||
oauth2SigningKey := b.getOAuth2SigningKey()
|
||||
|
||||
pgCACertBundle := b.getPgCACertBundle()
|
||||
|
||||
cfg := &probod.FullConfig{
|
||||
@@ -120,6 +123,17 @@ func (b *Builder) Build() (*probod.FullConfig, error) {
|
||||
ClientSecret: b.getEnv("AUTH_MICROSOFT_CLIENT_SECRET"),
|
||||
Enabled: b.getEnv("AUTH_MICROSOFT_CLIENT_ID") != "" && b.getEnv("AUTH_MICROSOFT_CLIENT_SECRET") != "",
|
||||
},
|
||||
OAuth2Server: probod.OAuth2ServerConfig{
|
||||
SigningKeys: []probod.OAuth2SigningKeyConfig{{
|
||||
PrivateKey: oauth2SigningKey,
|
||||
KID: b.getEnvOrDefault("OAUTH2_SERVER_SIGNING_KEY_KID", "default"),
|
||||
Active: true,
|
||||
}},
|
||||
AccessTokenDuration: b.getEnvIntOrDefault("OAUTH2_SERVER_ACCESS_TOKEN_DURATION", 3600),
|
||||
RefreshTokenDuration: b.getEnvIntOrDefault("OAUTH2_SERVER_REFRESH_TOKEN_DURATION", 2592000),
|
||||
AuthorizationCodeDuration: b.getEnvIntOrDefault("OAUTH2_SERVER_AUTHORIZATION_CODE_DURATION", 600),
|
||||
DeviceCodeDuration: b.getEnvIntOrDefault("OAUTH2_SERVER_DEVICE_CODE_DURATION", 600),
|
||||
},
|
||||
},
|
||||
TrustCenter: probod.TrustCenterConfig{
|
||||
HTTPAddr: b.getEnvOrDefault("TRUST_CENTER_HTTP_ADDR", ":80"),
|
||||
@@ -323,6 +337,10 @@ func (b *Builder) validateRequired() error {
|
||||
}
|
||||
}
|
||||
|
||||
if b.oauth2SigningKey == "" && b.getEnv("OAUTH2_SERVER_SIGNING_KEY") == "" {
|
||||
missing = append(missing, "OAUTH2_SERVER_SIGNING_KEY")
|
||||
}
|
||||
|
||||
if slackClientID := b.getEnv("CONNECTOR_SLACK_CLIENT_ID"); slackClientID != "" {
|
||||
slackRequired := []string{
|
||||
"CONNECTOR_SLACK_CLIENT_SECRET",
|
||||
@@ -388,6 +406,13 @@ func (b *Builder) getSAMLCredentials() (cert, key string, err error) {
|
||||
return cert, key, nil
|
||||
}
|
||||
|
||||
func (b *Builder) getOAuth2SigningKey() string {
|
||||
if b.oauth2SigningKey != "" {
|
||||
return b.oauth2SigningKey
|
||||
}
|
||||
return b.getEnv("OAUTH2_SERVER_SIGNING_KEY")
|
||||
}
|
||||
|
||||
func (b *Builder) getPgCACertBundle() string {
|
||||
if path := b.getEnv("PG_CA_BUNDLE_PATH"); path != "" {
|
||||
data, err := os.ReadFile(path)
|
||||
|
||||
Reference in New Issue
Block a user