Implement KeyCape service-token issuance
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 47s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 47s
This commit is contained in:
parent
519f0772d2
commit
e877d2752d
10 changed files with 348 additions and 43 deletions
|
|
@ -41,9 +41,22 @@ func ValidateConfig(cfg *Config) []string {
|
|||
prefix = fmt.Sprintf("clients[%d]", i)
|
||||
errs = append(errs, prefix+": clientId must not be empty")
|
||||
}
|
||||
if len(c.RedirectURIs) == 0 {
|
||||
hasAuthorizationCode := contains(c.GrantTypes, "authorization_code")
|
||||
hasClientCredentials := contains(c.GrantTypes, "client_credentials")
|
||||
if (hasAuthorizationCode || !hasClientCredentials) && len(c.RedirectURIs) == 0 {
|
||||
errs = append(errs, prefix+": redirect_uri: at least one redirectUri must be registered")
|
||||
}
|
||||
if hasClientCredentials {
|
||||
if c.ClientType != "confidential" {
|
||||
errs = append(errs, prefix+": client_credentials requires clientType confidential")
|
||||
}
|
||||
if !strings.HasPrefix(c.SecretRef, "env:") {
|
||||
errs = append(errs, prefix+": client_credentials requires an env: secretRef")
|
||||
}
|
||||
if c.ServiceSubject == "" || c.Tenant == "" {
|
||||
errs = append(errs, prefix+": client_credentials requires serviceSubject and tenant")
|
||||
}
|
||||
}
|
||||
// Warn about wildcard redirect URIs (they are blocked at runtime anyway).
|
||||
for _, uri := range c.RedirectURIs {
|
||||
if strings.ContainsAny(uri, "*?") {
|
||||
|
|
@ -59,3 +72,12 @@ func ValidateConfig(cfg *Config) []string {
|
|||
|
||||
return errs
|
||||
}
|
||||
|
||||
func contains(values []string, wanted string) bool {
|
||||
for _, value := range values {
|
||||
if value == wanted {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue