Inline OAuth2 signing key in config
The OAuth2/OIDC server accepted its signing key via a file path (key-file), while every other PEM key in the probod config (SAML private key, ACME account key) is embedded inline. Switch the field to a private-key string so the convention is uniform. The signing key is operator-supplied material that must outlive any process restart, so the bootstrap builder now treats OAUTH2_SERVER_SIGNING_KEY as required and refuses to start without one; silently minting a fresh key per boot would break token validation across rollouts. The OAUTH2_SERVER_* env vars otherwise flow through builder.Build like the existing SAML block so the new OAuth2Server section is populated end-to-end. Rework the e2e harness to render its config via bootstrap at test setup, which removes the static e2e/console/testdata/config.yaml and the previously generated test-only PEM file. A per-run RSA key is minted via bootstrap.GenerateOAuth2SigningKey (kept public for test tooling) and injected through the builder env map. CI now passes ACME_ROOT_CA inline instead of mutating a YAML on disk. Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
@@ -41,9 +41,9 @@ type OAuth2ServerConfig struct {
|
||||
}
|
||||
|
||||
type OAuth2SigningKeyConfig struct {
|
||||
KeyFile string `json:"key-file"`
|
||||
KID string `json:"kid"`
|
||||
Active bool `json:"active"`
|
||||
PrivateKey string `json:"private-key"`
|
||||
KID string `json:"kid"`
|
||||
Active bool `json:"active"`
|
||||
}
|
||||
|
||||
type CookieConfig struct {
|
||||
|
||||
@@ -25,7 +25,6 @@ import (
|
||||
"fmt"
|
||||
"net"
|
||||
"net/http"
|
||||
"os"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
@@ -389,12 +388,7 @@ func (impl *Implm) Run(
|
||||
var oauth2SigningKeys oauth2server.SigningKeys
|
||||
var hasActive bool
|
||||
for _, keyCfg := range impl.cfg.Auth.OAuth2Server.SigningKeys {
|
||||
keyPEM, err := os.ReadFile(keyCfg.KeyFile)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot read OAuth2 server signing key file: %w", err)
|
||||
}
|
||||
|
||||
signer, err := pemutil.DecodePrivateKey(keyPEM)
|
||||
signer, err := pemutil.DecodePrivateKey([]byte(keyCfg.PrivateKey))
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot decode OAuth2 server signing key: %w", err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user