Chore: Update authlib (#110880)
* Chore: Update authlib * exclude incompatible version of github.com/grafana/gomemcache * Update go-jose to v4 * fix jose imports * remove jose v3 from go.mod * fix tests * fix serialize * fix failing live tests * add v1 of ES256 testkeys. Port tests to use ES256 instead of HS256 * accept more signature algs for okta and azuread * azure social graph token sig * accept more signature algs for oauth refresh and jwt auth * update workspace * add a static signer for inproc * rebase and fix ext_jwt * fix jwt tests * apply alex patch on gomemcache * update linting * fix ext_jwt panic * update workspaces --------- Co-authored-by: Jo Garnier <git@jguer.space>
This commit is contained in:
co-authored by
Jo Garnier
parent
172febd690
commit
294fd943c0
@@ -6,7 +6,8 @@ import (
|
||||
"fmt"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
jose "github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/prometheus/client_golang/prometheus"
|
||||
"go.opentelemetry.io/otel/trace"
|
||||
"golang.org/x/sync/singleflight"
|
||||
@@ -170,7 +171,7 @@ func (s *Service) SyncIDToken(ctx context.Context, identity *authn.Identity, _ *
|
||||
}
|
||||
|
||||
func (s *Service) extractTokenClaims(token string) (*authnlib.Claims[authnlib.IDTokenClaims], error) {
|
||||
parsed, err := jwt.ParseSigned(token)
|
||||
parsed, err := jwt.ParseSigned(token, []jose.SignatureAlgorithm{jose.ES256})
|
||||
if err != nil {
|
||||
s.metrics.failedTokenSigningCounter.Inc()
|
||||
return nil, err
|
||||
|
||||
@@ -2,14 +2,19 @@ package idimpl
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/ecdsa"
|
||||
"crypto/x509"
|
||||
"encoding/pem"
|
||||
"fmt"
|
||||
"testing"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
claims "github.com/grafana/authlib/types"
|
||||
|
||||
"github.com/grafana/grafana/pkg/infra/remotecache"
|
||||
"github.com/grafana/grafana/pkg/infra/tracing"
|
||||
"github.com/grafana/grafana/pkg/services/auth"
|
||||
@@ -35,14 +40,38 @@ func Test_ProvideService(t *testing.T) {
|
||||
})
|
||||
}
|
||||
|
||||
var testKey = decodePrivateKey([]byte(`
|
||||
-----BEGIN EC PRIVATE KEY-----
|
||||
MHcCAQEEID6lXWsmcv/UWn9SptjOThsy88cifgGIBj2Lu0M9I8tQoAoGCCqGSM49
|
||||
AwEHoUQDQgAEsf6eNnNMNhl+q7jXsbdUf3ADPh248uoFUSSV9oBzgptyokHCjJz6
|
||||
n6PKDm2W7i3S2+dAs5M5f3s7d8KiLjGZdQ==
|
||||
-----END EC PRIVATE KEY-----
|
||||
`))
|
||||
|
||||
func decodePrivateKey(data []byte) *ecdsa.PrivateKey {
|
||||
block, _ := pem.Decode(data)
|
||||
if block == nil {
|
||||
panic("should include PEM block")
|
||||
}
|
||||
|
||||
privateKey, err := x509.ParseECPrivateKey(block.Bytes)
|
||||
if err != nil {
|
||||
panic(fmt.Sprintf("should be able to parse ec private key: %v", err))
|
||||
}
|
||||
if privateKey.Curve.Params().Name != "P-256" {
|
||||
panic("should be valid private key")
|
||||
}
|
||||
|
||||
return privateKey
|
||||
}
|
||||
|
||||
func TestService_SignIdentity(t *testing.T) {
|
||||
signer := &idtest.FakeSigner{
|
||||
SignIDTokenFn: func(_ context.Context, claims *auth.IDClaims) (string, error) {
|
||||
key := []byte("key")
|
||||
s, err := jose.NewSigner(jose.SigningKey{Algorithm: jose.HS256, Key: key}, nil)
|
||||
s, err := jose.NewSigner(jose.SigningKey{Algorithm: jose.ES256, Key: testKey}, nil)
|
||||
require.NoError(t, err)
|
||||
|
||||
token, err := jwt.Signed(s).Claims(claims.Claims).Claims(claims.Rest).CompactSerialize()
|
||||
token, err := jwt.Signed(s).Claims(claims.Claims).Claims(claims.Rest).Serialize()
|
||||
require.NoError(t, err)
|
||||
|
||||
return token, nil
|
||||
@@ -73,7 +102,7 @@ func TestService_SignIdentity(t *testing.T) {
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
parsed, err := jwt.ParseSigned(token)
|
||||
parsed, err := jwt.ParseSigned(token, []jose.SignatureAlgorithm{jose.ES256})
|
||||
require.NoError(t, err)
|
||||
|
||||
gotClaims := &auth.IDClaims{}
|
||||
|
||||
@@ -3,8 +3,8 @@ package idimpl
|
||||
import (
|
||||
"context"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
|
||||
"github.com/grafana/grafana/pkg/services/auth"
|
||||
"github.com/grafana/grafana/pkg/services/signingkeys"
|
||||
@@ -33,7 +33,7 @@ func (s *LocalSigner) SignIDToken(ctx context.Context, claims *auth.IDClaims) (s
|
||||
|
||||
builder := jwt.Signed(signer).Claims(&claims.Rest).Claims(claims.Claims)
|
||||
|
||||
token, err := builder.CompactSerialize()
|
||||
token, err := builder.Serialize()
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
@@ -6,7 +6,8 @@ import (
|
||||
"errors"
|
||||
"strings"
|
||||
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
jose "github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
|
||||
"github.com/grafana/grafana/pkg/infra/log"
|
||||
"github.com/grafana/grafana/pkg/infra/remotecache"
|
||||
@@ -69,7 +70,8 @@ func (s *AuthService) Verify(ctx context.Context, strToken string) (map[string]a
|
||||
s.log.Debug("Parsing JSON Web Token")
|
||||
|
||||
strToken = sanitizeJWT(strToken)
|
||||
token, err := jwt.ParseSigned(strToken)
|
||||
token, err := jwt.ParseSigned(strToken, []jose.SignatureAlgorithm{jose.EdDSA, jose.HS256, jose.HS384,
|
||||
jose.HS512, jose.RS512, jose.RS256, jose.ES256, jose.ES384, jose.ES512, jose.PS256, jose.PS384, jose.PS512})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -106,7 +108,8 @@ func (s *AuthService) Verify(ctx context.Context, strToken string) (map[string]a
|
||||
// HasSubClaim checks if the provided JWT token contains a non-empty "sub" claim.
|
||||
// Returns true if it contains, otherwise returns false.
|
||||
func HasSubClaim(jwtToken string) bool {
|
||||
parsed, err := jwt.ParseSigned(sanitizeJWT(jwtToken))
|
||||
parsed, err := jwt.ParseSigned(sanitizeJWT(jwtToken), []jose.SignatureAlgorithm{jose.EdDSA, jose.HS256, jose.HS384,
|
||||
jose.HS512, jose.RS512, jose.RS256, jose.ES256, jose.ES384, jose.ES512, jose.PS256, jose.PS384, jose.PS512})
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
@@ -13,8 +13,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
jose "github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
jose "github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/madflojo/testcerts"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
@@ -454,10 +454,10 @@ func TestIntegrationClaimValidation(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
_, err = sc.authJWTSvc.Verify(sc.ctx, sign(t, key, jwt.Claims{Audience: []string{"foo"}}, nil))
|
||||
require.Error(t, err)
|
||||
require.NoError(t, err)
|
||||
|
||||
_, err = sc.authJWTSvc.Verify(sc.ctx, sign(t, key, jwt.Claims{Audience: []string{"bar", "baz"}}, nil))
|
||||
require.Error(t, err)
|
||||
require.NoError(t, err)
|
||||
|
||||
_, err = sc.authJWTSvc.Verify(sc.ctx, sign(t, key, jwt.Claims{Audience: []string{"baz"}}, nil))
|
||||
require.Error(t, err)
|
||||
|
||||
@@ -18,7 +18,7 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
jose "github.com/go-jose/go-jose/v3"
|
||||
jose "github.com/go-jose/go-jose/v4"
|
||||
|
||||
"github.com/grafana/grafana/pkg/infra/log"
|
||||
"github.com/grafana/grafana/pkg/infra/remotecache"
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
"encoding/pem"
|
||||
"fmt"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
)
|
||||
|
||||
var rsaKeys [3]*rsa.PrivateKey
|
||||
|
||||
@@ -3,8 +3,8 @@ package jwt
|
||||
import (
|
||||
"testing"
|
||||
|
||||
jose "github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
jose "github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
@@ -16,9 +16,9 @@ func sign(t *testing.T, key any, claims any, opts *jose.SignerOptions) string {
|
||||
if opts == nil {
|
||||
opts = &jose.SignerOptions{}
|
||||
}
|
||||
sig, err := jose.NewSigner(jose.SigningKey{Algorithm: jose.PS512, Key: key}, (opts).WithType("JWT"))
|
||||
sig, err := jose.NewSigner(jose.SigningKey{Algorithm: jose.RS256, Key: key}, (opts).WithType("JWT"))
|
||||
require.NoError(t, err)
|
||||
token, err := jwt.Signed(sig).Claims(claims).CompactSerialize()
|
||||
token, err := jwt.Signed(sig).Claims(claims).Serialize()
|
||||
require.NoError(t, err)
|
||||
return token
|
||||
}
|
||||
@@ -40,7 +40,7 @@ func signNone(t *testing.T, claims any) string {
|
||||
|
||||
sig, err := jose.NewSigner(jose.SigningKey{Algorithm: "none", Key: noneSigner{}}, (&jose.SignerOptions{}).WithType("JWT"))
|
||||
require.NoError(t, err)
|
||||
token, err := jwt.Signed(sig).Claims(claims).CompactSerialize()
|
||||
token, err := jwt.Signed(sig).Claims(claims).Serialize()
|
||||
require.NoError(t, err)
|
||||
return token
|
||||
}
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
"reflect"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
)
|
||||
|
||||
func (s *AuthService) initClaimExpectations() error {
|
||||
@@ -35,13 +35,13 @@ func (s *AuthService) initClaimExpectations() error {
|
||||
case []any:
|
||||
for _, val := range value {
|
||||
if v, ok := val.(string); ok {
|
||||
s.expectRegistered.Audience = append(s.expectRegistered.Audience, v)
|
||||
s.expectRegistered.AnyAudience = append(s.expectRegistered.AnyAudience, v)
|
||||
} else {
|
||||
return fmt.Errorf("%q expectation contains value with invalid type %T, string expected", key, val)
|
||||
}
|
||||
}
|
||||
case string:
|
||||
s.expectRegistered.Audience = []string{value}
|
||||
s.expectRegistered.AnyAudience = []string{value}
|
||||
default:
|
||||
return fmt.Errorf("%q expectation has invalid type %T, array or string expected", key, value)
|
||||
}
|
||||
|
||||
@@ -6,7 +6,8 @@ import (
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
jose "github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"go.opentelemetry.io/otel/trace"
|
||||
|
||||
authlib "github.com/grafana/authlib/authn"
|
||||
@@ -215,7 +216,7 @@ func (s *ExtendedJWT) Test(ctx context.Context, r *authn.Request) bool {
|
||||
return false
|
||||
}
|
||||
|
||||
parsedToken, err := jwt.ParseSigned(rawToken)
|
||||
parsedToken, err := jwt.ParseSigned(rawToken, []jose.SignatureAlgorithm{jose.ES256})
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
@@ -2,15 +2,16 @@ package clients
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/ecdsa"
|
||||
"crypto/elliptic"
|
||||
"crypto/rand"
|
||||
"crypto/rsa"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
@@ -127,7 +128,8 @@ var (
|
||||
},
|
||||
}
|
||||
|
||||
pk, _ = rsa.GenerateKey(rand.Reader, 4096)
|
||||
// generate ES256 key
|
||||
pk, _ = ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
|
||||
)
|
||||
|
||||
var _ authnlib.Verifier[authnlib.IDTokenClaims] = &mockIDVerifier{}
|
||||
@@ -173,12 +175,12 @@ func TestExtendedJWT_Test(t *testing.T) {
|
||||
},
|
||||
{
|
||||
name: "should return true when Authorization header contains Bearer prefix",
|
||||
authHeaderFunc: func() string { return "Bearer " + generateToken(validAccessTokenClaims, pk, jose.RS256) },
|
||||
authHeaderFunc: func() string { return "Bearer " + generateToken(t, validAccessTokenClaims, pk, jose.ES256) },
|
||||
want: true,
|
||||
},
|
||||
{
|
||||
name: "should return true when Authorization header only contains the token",
|
||||
authHeaderFunc: func() string { return generateToken(validAccessTokenClaims, pk, jose.RS256) },
|
||||
authHeaderFunc: func() string { return generateToken(t, validAccessTokenClaims, pk, jose.ES256) },
|
||||
want: true,
|
||||
},
|
||||
{
|
||||
@@ -485,7 +487,7 @@ func TestExtendedJWT_Authenticate(t *testing.T) {
|
||||
|
||||
validHTTPReq := &http.Request{
|
||||
Header: map[string][]string{
|
||||
"X-Access-Token": {generateToken(*tc.accessToken, pk, jose.RS256)},
|
||||
"X-Access-Token": {generateToken(t, *tc.accessToken, pk, jose.ES256)},
|
||||
},
|
||||
}
|
||||
|
||||
@@ -493,7 +495,7 @@ func TestExtendedJWT_Authenticate(t *testing.T) {
|
||||
if tc.idToken != nil {
|
||||
env.s.accessTokenVerifier = &mockVerifier{Claims: *tc.accessToken}
|
||||
env.s.idTokenVerifier = &mockIDVerifier{Claims: *tc.idToken}
|
||||
validHTTPReq.Header.Add(ExtJWTAuthorizationHeaderName, generateIDToken(*tc.idToken, pk, jose.RS256))
|
||||
validHTTPReq.Header.Add(ExtJWTAuthorizationHeaderName, generateIDToken(t, *tc.idToken, pk, jose.ES256))
|
||||
}
|
||||
|
||||
id, err := env.s.Authenticate(context.Background(), &authn.Request{
|
||||
@@ -674,14 +676,14 @@ func TestVerifyRFC9068TokenFailureScenarios(t *testing.T) {
|
||||
for _, tc := range testCases {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
if tc.alg == "" {
|
||||
tc.alg = jose.RS256
|
||||
tc.alg = jose.ES256
|
||||
}
|
||||
|
||||
var tokenToTest string
|
||||
if tc.generateWrongTyp {
|
||||
tokenToTest = generateIDToken(*tc.idPayload, pk, tc.alg)
|
||||
tokenToTest = generateIDToken(t, *tc.idPayload, pk, tc.alg)
|
||||
} else {
|
||||
tokenToTest = generateToken(*tc.payload, pk, tc.alg)
|
||||
tokenToTest = generateToken(t, *tc.payload, pk, tc.alg)
|
||||
}
|
||||
_, err := env.s.accessTokenVerifier.Verify(context.Background(), tokenToTest)
|
||||
require.Error(t, err)
|
||||
@@ -711,24 +713,40 @@ type testEnv struct {
|
||||
s *ExtendedJWT
|
||||
}
|
||||
|
||||
func generateToken(payload accessTokenClaims, signingKey any, alg jose.SignatureAlgorithm) string {
|
||||
signer, _ := jose.NewSigner(jose.SigningKey{Algorithm: alg, Key: signingKey}, &jose.SignerOptions{
|
||||
func generateToken(t *testing.T, payload accessTokenClaims, signingKey any, alg jose.SignatureAlgorithm) string {
|
||||
signer, err := jose.NewSigner(jose.SigningKey{Algorithm: alg, Key: signingKey}, &jose.SignerOptions{
|
||||
ExtraHeaders: map[jose.HeaderKey]any{
|
||||
jose.HeaderType: authnlib.TokenTypeAccess,
|
||||
"kid": "default",
|
||||
}})
|
||||
if err != nil {
|
||||
// For incompatible algorithm/key combinations (like RS384 with ECDSA key),
|
||||
// return invalid token to test verification failure
|
||||
if alg == jose.RS384 {
|
||||
return "invalid.token"
|
||||
}
|
||||
require.NoError(t, err)
|
||||
}
|
||||
|
||||
result, _ := jwt.Signed(signer).Claims(payload).CompactSerialize()
|
||||
result, err := jwt.Signed(signer).Claims(payload).Serialize()
|
||||
require.NoError(t, err)
|
||||
return result
|
||||
}
|
||||
|
||||
func generateIDToken(payload idTokenClaims, signingKey any, alg jose.SignatureAlgorithm) string {
|
||||
signer, _ := jose.NewSigner(jose.SigningKey{Algorithm: alg, Key: signingKey}, &jose.SignerOptions{
|
||||
func generateIDToken(t *testing.T, payload idTokenClaims, signingKey any, alg jose.SignatureAlgorithm) string {
|
||||
signer, err := jose.NewSigner(jose.SigningKey{Algorithm: alg, Key: signingKey}, &jose.SignerOptions{
|
||||
ExtraHeaders: map[jose.HeaderKey]any{
|
||||
jose.HeaderType: authnlib.TokenTypeID,
|
||||
"kid": "default",
|
||||
}})
|
||||
if err != nil {
|
||||
if alg == jose.RS384 {
|
||||
return "invalid.token"
|
||||
}
|
||||
require.NoError(t, err)
|
||||
}
|
||||
|
||||
result, _ := jwt.Signed(signer).Claims(payload).CompactSerialize()
|
||||
result, err := jwt.Signed(signer).Claims(payload).Serialize()
|
||||
require.NoError(t, err)
|
||||
return result
|
||||
}
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"golang.org/x/sync/singleflight"
|
||||
|
||||
@@ -2,16 +2,21 @@ package live
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/ecdsa"
|
||||
"crypto/x509"
|
||||
"encoding/pem"
|
||||
"fmt"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"github.com/centrifugal/centrifuge"
|
||||
|
||||
"github.com/grafana/grafana/pkg/api/routing"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
"github.com/grafana/grafana/pkg/infra/db"
|
||||
@@ -379,9 +384,35 @@ func newDummyTransport(name string) *dummyTransport {
|
||||
return &dummyTransport{name: name}
|
||||
}
|
||||
|
||||
// There is a duplication of this function in the identity package. pkg/apimachinery/identity/requester_test.go.
|
||||
// If you need to copy it, place it as a test helper function in the identity package.
|
||||
var testKey = decodePrivateKey([]byte(`
|
||||
-----BEGIN EC PRIVATE KEY-----
|
||||
MHcCAQEEID6lXWsmcv/UWn9SptjOThsy88cifgGIBj2Lu0M9I8tQoAoGCCqGSM49
|
||||
AwEHoUQDQgAEsf6eNnNMNhl+q7jXsbdUf3ADPh248uoFUSSV9oBzgptyokHCjJz6
|
||||
n6PKDm2W7i3S2+dAs5M5f3s7d8KiLjGZdQ==
|
||||
-----END EC PRIVATE KEY-----
|
||||
`))
|
||||
|
||||
func decodePrivateKey(data []byte) *ecdsa.PrivateKey {
|
||||
block, _ := pem.Decode(data)
|
||||
if block == nil {
|
||||
panic("should include PEM block")
|
||||
}
|
||||
|
||||
privateKey, err := x509.ParseECPrivateKey(block.Bytes)
|
||||
if err != nil {
|
||||
panic(fmt.Sprintf("should be able to parse ec private key: %v", err))
|
||||
}
|
||||
if privateKey.Curve.Params().Name != "P-256" {
|
||||
panic("should be valid private key")
|
||||
}
|
||||
|
||||
return privateKey
|
||||
}
|
||||
|
||||
func createToken(t *testing.T, exp *time.Time) string {
|
||||
key := []byte("test-secret-key")
|
||||
signer, err := jose.NewSigner(jose.SigningKey{Algorithm: jose.HS256, Key: key}, nil)
|
||||
signer, err := jose.NewSigner(jose.SigningKey{Algorithm: jose.ES256, Key: testKey}, nil)
|
||||
require.NoError(t, err)
|
||||
|
||||
claims := struct {
|
||||
@@ -396,7 +427,7 @@ func createToken(t *testing.T, exp *time.Time) string {
|
||||
claims.Expiry = jwt.NewNumericDate(*exp)
|
||||
}
|
||||
|
||||
token, err := jwt.Signed(signer).Claims(claims).CompactSerialize()
|
||||
token, err := jwt.Signed(signer).Claims(claims).Serialize()
|
||||
require.NoError(t, err)
|
||||
return token
|
||||
}
|
||||
|
||||
@@ -7,13 +7,15 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
jose "github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/prometheus/client_golang/prometheus"
|
||||
"go.opentelemetry.io/otel/attribute"
|
||||
"go.opentelemetry.io/otel/trace"
|
||||
"golang.org/x/oauth2"
|
||||
|
||||
claims "github.com/grafana/authlib/types"
|
||||
|
||||
"github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
"github.com/grafana/grafana/pkg/infra/log"
|
||||
"github.com/grafana/grafana/pkg/infra/serverlock"
|
||||
@@ -577,7 +579,8 @@ func GetIDTokenExpiry(token *oauth2.Token) (time.Time, error) {
|
||||
return time.Time{}, nil
|
||||
}
|
||||
|
||||
parsedToken, err := jwt.ParseSigned(idToken)
|
||||
parsedToken, err := jwt.ParseSigned(idToken, []jose.SignatureAlgorithm{jose.EdDSA, jose.HS256, jose.HS384,
|
||||
jose.HS512, jose.RS512, jose.RS256, jose.ES256, jose.ES384, jose.ES512, jose.PS256, jose.PS384, jose.PS512})
|
||||
if err != nil {
|
||||
return time.Time{}, fmt.Errorf("error parsing id token: %w", err)
|
||||
}
|
||||
|
||||
@@ -12,7 +12,7 @@ import (
|
||||
"crypto"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
@@ -15,7 +15,7 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
|
||||
"github.com/grafana/grafana/pkg/api/response"
|
||||
"github.com/grafana/grafana/pkg/api/routing"
|
||||
|
||||
@@ -12,7 +12,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
|
||||
@@ -4,7 +4,7 @@ import (
|
||||
"context"
|
||||
"crypto"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
)
|
||||
|
||||
type FakeSigningKeysService struct {
|
||||
|
||||
@@ -4,7 +4,8 @@ import (
|
||||
"context"
|
||||
"crypto"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
|
||||
"github.com/grafana/grafana/pkg/services/signingkeys"
|
||||
)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user