Chore: Update authlib (#110880)
* Chore: Update authlib * exclude incompatible version of github.com/grafana/gomemcache * Update go-jose to v4 * fix jose imports * remove jose v3 from go.mod * fix tests * fix serialize * fix failing live tests * add v1 of ES256 testkeys. Port tests to use ES256 instead of HS256 * accept more signature algs for okta and azuread * azure social graph token sig * accept more signature algs for oauth refresh and jwt auth * update workspace * add a static signer for inproc * rebase and fix ext_jwt * fix jwt tests * apply alex patch on gomemcache * update linting * fix ext_jwt panic * update workspaces --------- Co-authored-by: Jo Garnier <git@jguer.space>
This commit is contained in:
co-authored by
Jo Garnier
parent
172febd690
commit
294fd943c0
@@ -2,16 +2,21 @@ package live
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/ecdsa"
|
||||
"crypto/x509"
|
||||
"encoding/pem"
|
||||
"fmt"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-jose/go-jose/v3"
|
||||
"github.com/go-jose/go-jose/v3/jwt"
|
||||
"github.com/go-jose/go-jose/v4"
|
||||
"github.com/go-jose/go-jose/v4/jwt"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"github.com/centrifugal/centrifuge"
|
||||
|
||||
"github.com/grafana/grafana/pkg/api/routing"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
"github.com/grafana/grafana/pkg/infra/db"
|
||||
@@ -379,9 +384,35 @@ func newDummyTransport(name string) *dummyTransport {
|
||||
return &dummyTransport{name: name}
|
||||
}
|
||||
|
||||
// There is a duplication of this function in the identity package. pkg/apimachinery/identity/requester_test.go.
|
||||
// If you need to copy it, place it as a test helper function in the identity package.
|
||||
var testKey = decodePrivateKey([]byte(`
|
||||
-----BEGIN EC PRIVATE KEY-----
|
||||
MHcCAQEEID6lXWsmcv/UWn9SptjOThsy88cifgGIBj2Lu0M9I8tQoAoGCCqGSM49
|
||||
AwEHoUQDQgAEsf6eNnNMNhl+q7jXsbdUf3ADPh248uoFUSSV9oBzgptyokHCjJz6
|
||||
n6PKDm2W7i3S2+dAs5M5f3s7d8KiLjGZdQ==
|
||||
-----END EC PRIVATE KEY-----
|
||||
`))
|
||||
|
||||
func decodePrivateKey(data []byte) *ecdsa.PrivateKey {
|
||||
block, _ := pem.Decode(data)
|
||||
if block == nil {
|
||||
panic("should include PEM block")
|
||||
}
|
||||
|
||||
privateKey, err := x509.ParseECPrivateKey(block.Bytes)
|
||||
if err != nil {
|
||||
panic(fmt.Sprintf("should be able to parse ec private key: %v", err))
|
||||
}
|
||||
if privateKey.Curve.Params().Name != "P-256" {
|
||||
panic("should be valid private key")
|
||||
}
|
||||
|
||||
return privateKey
|
||||
}
|
||||
|
||||
func createToken(t *testing.T, exp *time.Time) string {
|
||||
key := []byte("test-secret-key")
|
||||
signer, err := jose.NewSigner(jose.SigningKey{Algorithm: jose.HS256, Key: key}, nil)
|
||||
signer, err := jose.NewSigner(jose.SigningKey{Algorithm: jose.ES256, Key: testKey}, nil)
|
||||
require.NoError(t, err)
|
||||
|
||||
claims := struct {
|
||||
@@ -396,7 +427,7 @@ func createToken(t *testing.T, exp *time.Time) string {
|
||||
claims.Expiry = jwt.NewNumericDate(*exp)
|
||||
}
|
||||
|
||||
token, err := jwt.Signed(signer).Claims(claims).CompactSerialize()
|
||||
token, err := jwt.Signed(signer).Claims(claims).Serialize()
|
||||
require.NoError(t, err)
|
||||
return token
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user