auth: grant scoped access to anon internal auth
Internal auth is granted access to everything, whereas anonymous
internal auth is pretty restricted. This is mostly to avoid accidentally
hitting resolvers that require a logged-in user, however. Given that all
anon internal use cases are hard-coded and tested, this seems like a
pretty low risk. Allowing this will have the huge benefit of making much
more information available to anon internal queries, which will unlock
removing a bunch of awkward work-arounds we put in place.
Note, however, that this is also a work-around. It saves us from adding
yet more work-arounds to the GQL schema, and in the meantime a redesign
of the schema (especially the directives) is being worked on.
auth/middleware: fix user_type on new users
auth/middleware: convert user types to uppercase
server: use routing groups
Instead of hardcoding some exceptions in the auth middleware, use a
different routing group for routes that do not require auth. Makes the
auth middleware more generic and also removes a lot of unneccessary
middleware processing from routes that don't need it.
For now, the added group is not accessible from outside the module, but
if the need arises, this might be an option.
auth: add auth.IPAddress
With support for X-Forwarded-For
auth/middleware: set WWW-Authenticate header field
See RFC 6750 section 3.
client: rename Execute to Do
583d0b1bcb08 ("client/graphql: handle GraphQL errors") changed
Execute behavior by wrapping the result into a struct with "data"
and "errors" fields. This is a breaking change, but it's hard to
spot when upgrading core-go because it won't cause a compilation
error.
Rename Execute to Do to break the build and force callers to update
accordingly.
auth: add RequireMiddleware
Same as Middleware, but requires auth for all requests. Will be
useful to drop hacks from pages.sr.ht.
Drop gqlparser v1 dependency
Only use v2 throughout the repository.
auth: make DecodeGrants return an error
We'll use this function to validate grants passed in via
builds.sr.ht manifests.
auth: add AuthContext.Access
Same logic as server.Access, but lower-level. Useful to check for
a permission not covered by the GraphQL schema @access directives
(such as builds.sr.ht secrets).
auth: add /query/external/* to anonymous whitelist
auth/middleware: make auth scheme case-insensitive
According to RFC 7235 section 2.1, the auth scheme is
case-insensitive.
auth: fix invalid json tag in InternalAuth
auth: Use canonical user IDs
When adding users to the database, use the canonical user ID from
meta.sr.ht.
auth: Use canonical user IDs
When adding users to the database, use the canonical user ID from
meta.sr.ht.
Fix (some) user PGP key lookups from meta.sr.ht
The authForUsername() function uses a closure that is almost identical
to the LookupUser() function, but is missing the handling for the PGP
key if called from meta.sr.ht. This causes at least the email
notifications for new OAuth2 tokens to be sent unencrypted. This commit
fixes that (and reduces code duplication) by calling LookupUser()
instead.
This requires the context for the tests to have a value for the calling
service, so add that to the mock.
auth: fix nil reference in auth method check