Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 11 additions & 2 deletions backend/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -34,15 +34,16 @@ require (
github.com/getarcaneapp/arcane/cli/v2 v2.9.0
github.com/getarcaneapp/arcane/types/v2 v2.9.0
github.com/go-git/go-git/v5 v5.19.2
github.com/go-jose/go-jose/v4 v4.1.4
github.com/go-webauthn/webauthn v0.18.0
github.com/gofrs/flock v0.13.1
github.com/golang-jwt/jwt/v5 v5.3.1
github.com/google/go-containerregistry v0.22.0
github.com/google/uuid v1.6.0
github.com/jinzhu/copier v0.4.0
github.com/jwx-go/jwkfetch/v4 v4.0.4
github.com/klauspost/compress v1.19.2
github.com/labstack/echo/v5 v5.3.1
github.com/lestrrat-go/httprc/v3 v3.0.6
github.com/lestrrat-go/jwx/v4 v4.4.0
github.com/libtnb/sqlite v1.2.2
github.com/lmittmann/tint v1.2.0
github.com/moby/buildkit v0.32.2
Expand Down Expand Up @@ -160,11 +161,13 @@ require (
github.com/fxamacker/cbor/v2 v2.9.3 // indirect
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
github.com/go-git/go-billy/v5 v5.9.0 // indirect
github.com/go-jose/go-jose/v4 v4.1.4 // indirect
github.com/go-logr/logr v1.4.4 // indirect
github.com/go-logr/stdr v1.2.2 // indirect
github.com/go-ole/go-ole v1.3.0 // indirect
github.com/go-viper/mapstructure/v2 v2.5.0 // indirect
github.com/go-webauthn/x v0.3.0 // indirect
github.com/golang-jwt/jwt/v5 v5.3.1 // indirect
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
github.com/google/go-cmp v0.7.0 // indirect
github.com/google/go-tpm v0.9.8 // indirect
Expand Down Expand Up @@ -195,6 +198,11 @@ require (
github.com/knqyf263/go-rpm-version v0.0.0-20220614171824-631e686d1075 // indirect
github.com/labstack/echo/v4 v4.15.4 // indirect
github.com/labstack/gommon v0.5.0 // indirect
github.com/lestrrat-go/blackmagic v1.0.4 // indirect
github.com/lestrrat-go/dsig v1.4.0 // indirect
github.com/lestrrat-go/httpcc v1.0.1 // indirect
github.com/lestrrat-go/option/v2 v2.0.0 // indirect
github.com/lestrrat-go/option/v3 v3.0.0-alpha1 // indirect
github.com/lucasb-eyer/go-colorful v1.4.1 // indirect
github.com/lufia/plan9stats v0.0.0-20260330125221-c963978e514e // indirect
github.com/mattn/go-colorable v0.1.15 // indirect
Expand Down Expand Up @@ -266,6 +274,7 @@ require (
github.com/tonistiigi/units v0.0.0-20180711220420-6950e57a87ea // indirect
github.com/tonistiigi/vt100 v0.0.0-20240514184818-90bafcd6abab // indirect
github.com/valyala/bytebufferpool v1.0.0 // indirect
github.com/valyala/fastjson v1.6.10 // indirect
github.com/valyala/fasttemplate v1.2.2 // indirect
github.com/vito/midterm v0.1.4 // indirect
github.com/vito/progrock v0.10.1 // indirect
Expand Down
18 changes: 18 additions & 0 deletions backend/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -485,6 +485,8 @@ github.com/jonboulle/clockwork v0.5.0 h1:Hyh9A8u51kptdkR+cqRpT1EebBwTn1oK9YfGYbd
github.com/jonboulle/clockwork v0.5.0/go.mod h1:3mZlmanh0g2NDKO5TWZVJAfofYk64M7XN3SzBPjZF60=
github.com/jstemmer/go-junit-report v0.0.0-20190106144839-af01ea7f8024/go.mod h1:6v2b51hI/fHJwM22ozAgKL4VKDeJcHhJFhtBdhmNjmU=
github.com/jstemmer/go-junit-report v0.9.1/go.mod h1:Brl9GWCQeLvo8nXZwPNNblvFj/XSXhF0NWZEnDohbsk=
github.com/jwx-go/jwkfetch/v4 v4.0.4 h1:fKgCdegz9WTnBAemDCj1QzPZYIuobg9k2qo+HZkXgmA=
github.com/jwx-go/jwkfetch/v4 v4.0.4/go.mod h1:dTGEkaGuxg9vcCR1F2Dk+TnwmXcZpeUGahNWKtbcKu8=
github.com/kevinburke/ssh_config v1.6.0 h1:J1FBfmuVosPHf5GRdltRLhPJtJpTlMdKTBjRgTaQBFY=
github.com/kevinburke/ssh_config v1.6.0/go.mod h1:q2RIzfka+BXARoNexmF9gkxEX7DmvbW9P4hIVx2Kg4M=
github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck=
Expand All @@ -511,6 +513,20 @@ github.com/labstack/echo/v5 v5.3.1 h1:75maCxkQVGualckLc/5s/ihgpH1a1Dc6AuGWNVNs6b
github.com/labstack/echo/v5 v5.3.1/go.mod h1:4iEGNQiPPZnkfYpNR/L6fINd3NLiGWUD5+eBotFALas=
github.com/labstack/gommon v0.5.0 h1:6VSQ2NOzsnEJ5W6+84E0RbcaDDmgB6NIAzWCczTEe6c=
github.com/labstack/gommon v0.5.0/go.mod h1:Rzlg7HHy1maLfzBYGg9NZcVuz1sA68HHhLjhcEllYE0=
github.com/lestrrat-go/blackmagic v1.0.4 h1:IwQibdnf8l2KoO+qC3uT4OaTWsW7tuRQXy9TRN9QanA=
github.com/lestrrat-go/blackmagic v1.0.4/go.mod h1:6AWFyKNNj0zEXQYfTMPfZrAXUWUfTIZ5ECEUEJaijtw=
github.com/lestrrat-go/dsig v1.4.0 h1:g7LUjK8cT74A5DzBXJI5HzsJuLhoYN0Wzj4nuOMIrH8=
github.com/lestrrat-go/dsig v1.4.0/go.mod h1:I8Nddg/vN2cUl/h8N7SRRApLnNNeyZPIqLYpvpOtGGo=
github.com/lestrrat-go/httpcc v1.0.1 h1:ydWCStUeJLkpYyjLDHihupbn2tYmZ7m22BGkcvZZrIE=
github.com/lestrrat-go/httpcc v1.0.1/go.mod h1:qiltp3Mt56+55GPVCbTdM9MlqhvzyuL6W/NMDA8vA5E=
github.com/lestrrat-go/httprc/v3 v3.0.6 h1:4FpLQ18KK/ypPbVU3NLWJNRvH3kcYiqKqWfKGqNWxxI=
github.com/lestrrat-go/httprc/v3 v3.0.6/go.mod h1:mSMtkZW92Z98M5YoNNztbRGxbXHql7tSitCvaxvo9l0=
github.com/lestrrat-go/jwx/v4 v4.4.0 h1:CzoK8+u++WF7vVEmxx9fB8VaheeXWZ698F6HZbrl6SI=
github.com/lestrrat-go/jwx/v4 v4.4.0/go.mod h1:65utsGK/iSrjgGfu6iqj/TAvSfia6SSXkRpjHcKcTyg=
github.com/lestrrat-go/option/v2 v2.0.0 h1:XxrcaJESE1fokHy3FpaQ/cXW8ZsIdWcdFzzLOcID3Ss=
github.com/lestrrat-go/option/v2 v2.0.0/go.mod h1:oSySsmzMoR0iRzCDCaUfsCzxQHUEuhOViQObyy7S6Vg=
github.com/lestrrat-go/option/v3 v3.0.0-alpha1 h1:dvdzLwm/Ba5CJUF3jQP7w/iNYSLfy7yyh9XXNa1WjxI=
github.com/lestrrat-go/option/v3 v3.0.0-alpha1/go.mod h1:5KSg20dfsKkNJtjDmaQRLZVXuUrzuCCcz/gbDK0pfKk=
github.com/libtnb/sqlite v1.2.2 h1:Ku5hAPP5B3A4kQcDn4Z3qyNMafKzuAbnFZX4oD9wR4I=
github.com/libtnb/sqlite v1.2.2/go.mod h1:JkAuxM7HHo0tc7dQENjIGpp/yIfrLX5nKr5ME9wuvmI=
github.com/lmittmann/tint v1.2.0 h1:AogHRHy8HUJUnNJBHJlYa+fR4YY8mko2cnCp67xn9JY=
Expand Down Expand Up @@ -763,6 +779,8 @@ github.com/ulikunitz/xz v0.5.15 h1:9DNdB5s+SgV3bQ2ApL10xRc35ck0DuIX/isZvIk+ubY=
github.com/ulikunitz/xz v0.5.15/go.mod h1:nbz6k7qbPmH4IRqmfOplQw/tblSgqTqBwxkY0oWt/14=
github.com/valyala/bytebufferpool v1.0.0 h1:GqA5TC/0021Y/b9FG4Oi9Mr3q7XYx6KllzawFIhcdPw=
github.com/valyala/bytebufferpool v1.0.0/go.mod h1:6bBcMArwyJ5K/AmCkWv1jt77kVWyCJ6HpOuEn7z0Csc=
github.com/valyala/fastjson v1.6.10 h1:/yjJg8jaVQdYR3arGxPE2X5z89xrlhS0eGXdv+ADTh4=
github.com/valyala/fastjson v1.6.10/go.mod h1:e6FubmQouUNP73jtMLmcbxS6ydWIpOfhz34TSfO3JaE=
github.com/valyala/fasttemplate v1.2.2 h1:lxLXG0uE3Qnshl9QyaK6XJxMXlQZELvChBOCmQD0Loo=
github.com/valyala/fasttemplate v1.2.2/go.mod h1:KHLXt3tVN2HBp8eijSv/kGJopbvo7S+qRAEEKiv+SiQ=
github.com/vbatts/tar-split v0.12.3 h1:Cd46rkGXI3Td4yrVNwU8ripbxFaQbmesqhjBUUYAJSw=
Expand Down
19 changes: 6 additions & 13 deletions backend/internal/auth/huma_middleware_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,7 @@ import (
"github.com/getarcaneapp/arcane/backend/v2/internal/user"
"github.com/getarcaneapp/arcane/backend/v2/pkg/authz"
"github.com/getarcaneapp/arcane/backend/v2/pkg/utils"
"github.com/getarcaneapp/arcane/backend/v2/pkg/utils/mldsajose"
authtypes "github.com/getarcaneapp/arcane/types/v2/auth"
"github.com/golang-jwt/jwt/v5"
"github.com/labstack/echo/v5"
"github.com/libtnb/sqlite"
"github.com/stretchr/testify/require"
Expand Down Expand Up @@ -281,7 +279,7 @@ func TestNewHumaMiddleware_OpportunisticAuthOnPublicRoute(t *testing.T) {
session, _, err := sessionSvc.CreateSession(context.Background(), "u-logout", exp, authtypes.SessionMeta{})
require.NoError(t, err)

claims := jwt.MapClaims{
claims := map[string]any{
"jti": "u-logout",
"sub": "access",
"iat": time.Now().Unix(),
Expand All @@ -291,8 +289,7 @@ func TestNewHumaMiddleware_OpportunisticAuthOnPublicRoute(t *testing.T) {
"username": "logouttest",
"roles": []string{"user"},
}
token, err := jwt.NewWithClaims(mldsajose.SigningMethodMLDSA87, claims).SignedString(signingKey)
require.NoError(t, err)
token := signJWXTokenInternal(t, signingKey, claims)

router := echo.New()
apiGroup := router.Group("/api")
Expand Down Expand Up @@ -371,7 +368,7 @@ func TestNewHumaMiddleware_VersionMismatchIsRecoverable(t *testing.T) {

// An empty appVersion omits the claim, which passes the version check (no pin).
mintToken := func(appVersion string) string {
claims := jwt.MapClaims{
claims := map[string]any{
"jti": "u-ver",
"sub": "access",
"iat": time.Now().Unix(),
Expand All @@ -383,9 +380,7 @@ func TestNewHumaMiddleware_VersionMismatchIsRecoverable(t *testing.T) {
if appVersion != "" {
claims["app_version"] = appVersion
}
token, signErr := jwt.NewWithClaims(mldsajose.SigningMethodMLDSA87, claims).SignedString(signingKey)
require.NoError(t, signErr)
return token
return signJWXTokenInternal(t, signingKey, claims)
}

router := echo.New()
Expand Down Expand Up @@ -498,7 +493,7 @@ func mintHumaMiddlewareTestTokenInternal(t *testing.T, userSvc *user.UserService
session, _, err := sessionSvc.CreateSession(context.Background(), userID, exp, authtypes.SessionMeta{})
require.NoError(t, err)

claims := jwt.MapClaims{
claims := map[string]any{
"jti": userID,
"sub": "access",
"iat": time.Now().Unix(),
Expand All @@ -507,9 +502,7 @@ func mintHumaMiddlewareTestTokenInternal(t *testing.T, userSvc *user.UserService
"user_id": userID,
"username": userID,
}
token, err := jwt.NewWithClaims(mldsajose.SigningMethodMLDSA87, claims).SignedString(signingKey)
require.NoError(t, err)
return token
return signJWXTokenInternal(t, signingKey, claims)
}

func (r staticPermissionResolverInternal) ResolvePermissions(_ context.Context, _ *common.User) (*authz.PermissionSet, error) {
Expand Down
Loading
Loading