Skip to content

Commit ac5d65a

Browse files
authored
Merge pull request #217 from ARGOeu/devel
Version 1.4.0
2 parents 8e62504 + 6d6f9c3 commit ac5d65a

18 files changed

+8465
-14959
lines changed

Jenkinsfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
pipeline {
22
agent {
33
docker {
4-
image 'argo.registry:5000/epel-7-go1.19'
4+
image 'argo.registry:5000/epel-7-go1.21'
55
args '-u jenkins:jenkins'
66
}
77
}
@@ -60,7 +60,7 @@ pipeline {
6060
}
6161
agent {
6262
docker {
63-
image 'node:buster'
63+
image 'node:18-buster'
6464
}
6565
}
6666
steps {

LICENSE

Lines changed: 162 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,171 @@
1-
Copyright (c) 2018 GRNET S.A.
1+
Apache License
2+
Version 2.0, January 2004
3+
http://www.apache.org/licenses/
4+
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
5+
1. Definitions.
6+
"License" shall mean the terms and conditions for use, reproduction,
7+
and distribution as defined by Sections 1 through 9 of this document.
8+
"Licensor" shall mean the copyright owner or entity authorized by
9+
the copyright owner that is granting the License.
10+
"Legal Entity" shall mean the union of the acting entity and all
11+
other entities that control, are controlled by, or are under common
12+
control with that entity. For the purposes of this definition,
13+
"control" means (i) the power, direct or indirect, to cause the
14+
direction or management of such entity, whether by contract or
15+
otherwise, or (ii) ownership of fifty percent (50%) or more of the
16+
outstanding shares, or (iii) beneficial ownership of such entity.
17+
"You" (or "Your") shall mean an individual or Legal Entity
18+
exercising permissions granted by this License.
19+
"Source" form shall mean the preferred form for making modifications,
20+
including but not limited to software source code, documentation
21+
source, and configuration files.
22+
"Object" form shall mean any form resulting from mechanical
23+
transformation or translation of a Source form, including but
24+
not limited to compiled object code, generated documentation,
25+
and conversions to other media types.
26+
"Work" shall mean the work of authorship, whether in Source or
27+
Object form, made available under the License, as indicated by a
28+
copyright notice that is included in or attached to the work
29+
(an example is provided in the Appendix below).
30+
"Derivative Works" shall mean any work, whether in Source or Object
31+
form, that is based on (or derived from) the Work and for which the
32+
editorial revisions, annotations, elaborations, or other modifications
33+
represent, as a whole, an original work of authorship. For the purposes
34+
of this License, Derivative Works shall not include works that remain
35+
separable from, or merely link (or bind by name) to the interfaces of,
36+
the Work and Derivative Works thereof.
37+
"Contribution" shall mean any work of authorship, including
38+
the original version of the Work and any modifications or additions
39+
to that Work or Derivative Works thereof, that is intentionally
40+
submitted to Licensor for inclusion in the Work by the copyright owner
41+
or by an individual or Legal Entity authorized to submit on behalf of
42+
the copyright owner. For the purposes of this definition, "submitted"
43+
means any form of electronic, verbal, or written communication sent
44+
to the Licensor or its representatives, including but not limited to
45+
communication on electronic mailing lists, source code control systems,
46+
and issue tracking systems that are managed by, or on behalf of, the
47+
Licensor for the purpose of discussing and improving the Work, but
48+
excluding communication that is conspicuously marked or otherwise
49+
designated in writing by the copyright owner as "Not a Contribution."
50+
"Contributor" shall mean Licensor and any individual or Legal Entity
51+
on behalf of whom a Contribution has been received by Licensor and
52+
subsequently incorporated within the Work.
53+
2. Grant of Copyright License. Subject to the terms and conditions of
54+
this License, each Contributor hereby grants to You a perpetual,
55+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
56+
copyright license to reproduce, prepare Derivative Works of,
57+
publicly display, publicly perform, sublicense, and distribute the
58+
Work and such Derivative Works in Source or Object form.
59+
3. Grant of Patent License. Subject to the terms and conditions of
60+
this License, each Contributor hereby grants to You a perpetual,
61+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
62+
(except as stated in this section) patent license to make, have made,
63+
use, offer to sell, sell, import, and otherwise transfer the Work,
64+
where such license applies only to those patent claims licensable
65+
by such Contributor that are necessarily infringed by their
66+
Contribution(s) alone or by combination of their Contribution(s)
67+
with the Work to which such Contribution(s) was submitted. If You
68+
institute patent litigation against any entity (including a
69+
cross-claim or counterclaim in a lawsuit) alleging that the Work
70+
or a Contribution incorporated within the Work constitutes direct
71+
or contributory patent infringement, then any patent licenses
72+
granted to You under this License for that Work shall terminate
73+
as of the date such litigation is filed.
74+
4. Redistribution. You may reproduce and distribute copies of the
75+
Work or Derivative Works thereof in any medium, with or without
76+
modifications, and in Source or Object form, provided that You
77+
meet the following conditions:
78+
(a) You must give any other recipients of the Work or
79+
Derivative Works a copy of this License; and
80+
(b) You must cause any modified files to carry prominent notices
81+
stating that You changed the files; and
82+
(c) You must retain, in the Source form of any Derivative Works
83+
that You distribute, all copyright, patent, trademark, and
84+
attribution notices from the Source form of the Work,
85+
excluding those notices that do not pertain to any part of
86+
the Derivative Works; and
87+
(d) If the Work includes a "NOTICE" text file as part of its
88+
distribution, then any Derivative Works that You distribute must
89+
include a readable copy of the attribution notices contained
90+
within such NOTICE file, excluding those notices that do not
91+
pertain to any part of the Derivative Works, in at least one
92+
of the following places: within a NOTICE text file distributed
93+
as part of the Derivative Works; within the Source form or
94+
documentation, if provided along with the Derivative Works; or,
95+
within a display generated by the Derivative Works, if and
96+
wherever such third-party notices normally appear. The contents
97+
of the NOTICE file are for informational purposes only and
98+
do not modify the License. You may add Your own attribution
99+
notices within Derivative Works that You distribute, alongside
100+
or as an addendum to the NOTICE text from the Work, provided
101+
that such additional attribution notices cannot be construed
102+
as modifying the License.
103+
You may add Your own copyright statement to Your modifications and
104+
may provide additional or different license terms and conditions
105+
for use, reproduction, or distribution of Your modifications, or
106+
for any such Derivative Works as a whole, provided Your use,
107+
reproduction, and distribution of the Work otherwise complies with
108+
the conditions stated in this License.
109+
5. Submission of Contributions. Unless You explicitly state otherwise,
110+
any Contribution intentionally submitted for inclusion in the Work
111+
by You to the Licensor shall be under the terms and conditions of
112+
this License, without any additional terms or conditions.
113+
Notwithstanding the above, nothing herein shall supersede or modify
114+
the terms of any separate license agreement you may have executed
115+
with Licensor regarding such Contributions.
116+
6. Trademarks. This License does not grant permission to use the trade
117+
names, trademarks, service marks, or product names of the Licensor,
118+
except as required for reasonable and customary use in describing the
119+
origin of the Work and reproducing the content of the NOTICE file.
120+
7. Disclaimer of Warranty. Unless required by applicable law or
121+
agreed to in writing, Licensor provides the Work (and each
122+
Contributor provides its Contributions) on an "AS IS" BASIS,
123+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
124+
implied, including, without limitation, any warranties or conditions
125+
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
126+
PARTICULAR PURPOSE. You are solely responsible for determining the
127+
appropriateness of using or redistributing the Work and assume any
128+
risks associated with Your exercise of permissions under this License.
129+
8. Limitation of Liability. In no event and under no legal theory,
130+
whether in tort (including negligence), contract, or otherwise,
131+
unless required by applicable law (such as deliberate and grossly
132+
negligent acts) or agreed to in writing, shall any Contributor be
133+
liable to You for damages, including any direct, indirect, special,
134+
incidental, or consequential damages of any character arising as a
135+
result of this License or out of the use or inability to use the
136+
Work (including but not limited to damages for loss of goodwill,
137+
work stoppage, computer failure or malfunction, or any and all
138+
other commercial damages or losses), even if such Contributor
139+
has been advised of the possibility of such damages.
140+
9. Accepting Warranty or Additional Liability. While redistributing
141+
the Work or Derivative Works thereof, You may choose to offer,
142+
and charge a fee for, acceptance of support, warranty, indemnity,
143+
or other liability obligations and/or rights consistent with this
144+
License. However, in accepting such obligations, You may act only
145+
on Your own behalf and on Your sole responsibility, not on behalf
146+
of any other Contributor, and only if You agree to indemnify,
147+
defend, and hold each Contributor harmless for any liability
148+
incurred by, or claims asserted against, such Contributor by reason
149+
of your accepting any such warranty or additional liability.
150+
END OF TERMS AND CONDITIONS
151+
APPENDIX: How to apply the Apache License to your work.
152+
To apply the Apache License to your work, attach the following
153+
boilerplate notice, with the fields enclosed by brackets "[]"
154+
replaced with your own identifying information. (Don't include
155+
the brackets!) The text should be enclosed in the appropriate
156+
comment syntax for the file format. We also recommend that a
157+
file or class name and description of purpose be included on the
158+
same "printed page" as the copyright notice for easier
159+
identification within third-party archives.
160+
161+
Copyright 2018 National Infrastructures for Research and Technology - GRNET S.A.
2162

3163
Licensed under the Apache License, Version 2.0 (the "License");
4164
you may not use this file except in compliance with the License.
5165
You may obtain a copy of the License at
6-
7166
http://www.apache.org/licenses/LICENSE-2.0
8-
9167
Unless required by applicable law or agreed to in writing, software
10168
distributed under the License is distributed on an "AS IS" BASIS,
11169
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12170
See the License for the specific language governing permissions and
13-
limitations under the License.
171+
limitations under the License.

README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ Before you start, you need to issue a valid certificate.
1818

1919
## Set Up
2020

21-
1. Install Golang 1.19
21+
1. Install Golang 1.21
2222
2. Create a new work space:
2323

2424
`mkdir ~/go-workspace`
@@ -58,7 +58,7 @@ Before you start, you need to issue a valid certificate.
5858
Inside the project's folder issue the command:
5959
`go test ./... -tags integration`
6060

61-
9. Install mongoDB
61+
9. Install mongoDB 6.
6262

6363
## Configuration
6464

argo-api-authn.spec

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33

44
Name: argo-api-authn
55
Summary: ARGO Authentication API. Map X509, OICD to token.
6-
Version: 1.3.0
6+
Version: 1.4.0
77
Release: 1%{?dist}
88
License: ASL 2.0
99
Buildroot: %{_tmppath}/%{name}-buildroot
@@ -60,6 +60,8 @@ go install -buildmode=pie -ldflags "-s -w -linkmode=external -extldflags '-z rel
6060
%attr(0644,root,root) /usr/lib/systemd/system/argo-api-authn.service
6161

6262
%changelog
63+
* Mon May 27 2024 Agelos Tsalapatis <agelos.tsal@gmail.com> - 1.3.0-1%{?dist}
64+
- Release of argo-api-authn version 1.4.0
6365
* Wed Jan 24 2024 Agelos Tsalapatis <agelos.tsal@gmail.com> - 1.3.0-1%{?dist}
6466
- Release of argo-api-authn version 1.3.0
6567
* Tue Dec 19 2023 Agelos Tsalapatis <agelos.tsal@gmail.com> - 1.2.0-1%{?dist}

auth/revoke.go

Lines changed: 17 additions & 63 deletions
Original file line numberDiff line numberDiff line change
@@ -134,7 +134,8 @@ func CRLCheckRevokedCert(ctx context.Context, cert *x509.Certificate) error {
134134
}
135135

136136
// SynchronizedCheckInCRL checks if a serial number exists within the serial numbers of other revoked certificates
137-
func SynchronizedCheckInCRL(doneChan <-chan bool, errChan chan<- error, revokedCerts []pkix.RevokedCertificate, serialNumber *big.Int, wg *sync.WaitGroup) {
137+
func SynchronizedCheckInCRL(doneChan <-chan bool, errChan chan<- error, revokedCerts []pkix.RevokedCertificate,
138+
serialNumber *big.Int, wg *sync.WaitGroup) {
138139

139140
loop:
140141
for _, cert := range revokedCerts {
@@ -156,66 +157,6 @@ loop:
156157
defer wg.Done()
157158
}
158159

159-
// FetchCRLV2 fetches the CRL using the V2 x509 version
160-
func FetchCRLV2(ctx context.Context, url string) ([]pkix.RevokedCertificate, error) {
161-
162-
var err error
163-
var resp *http.Response
164-
var crlBytes []byte
165-
166-
var crtList = &x509.RevocationList{}
167-
168-
// initialize the client and perform a get request to grab the crl
169-
client := &http.Client{Timeout: time.Duration(30 * time.Second)}
170-
if resp, err = client.Get(url); err != nil {
171-
log.WithFields(
172-
log.Fields{
173-
"trace_id": ctx.Value("trace_id"),
174-
"type": "backend_log",
175-
"backend_service": "crl",
176-
"backend_hosts": url,
177-
"details": err.Error(),
178-
},
179-
).Error("CRL Request error")
180-
err = utils.APIGenericInternalError(fmt.Sprintf("Could not access CRL %v", url))
181-
return []pkix.RevokedCertificate{}, err
182-
}
183-
184-
// read the response
185-
if crlBytes, err = io.ReadAll(resp.Body); err != nil {
186-
log.WithFields(
187-
log.Fields{
188-
"trace_id": ctx.Value("trace_id"),
189-
"type": "backend_log",
190-
"backend_service": "crl",
191-
"backend_hosts": url,
192-
"details": err.Error(),
193-
},
194-
).Error("Unable to read CRL data")
195-
err = utils.APIGenericInternalError("Unable to read CRL Data")
196-
return []pkix.RevokedCertificate{}, err
197-
}
198-
199-
defer resp.Body.Close()
200-
201-
// create the crl from the byte slice
202-
if crtList, err = x509.ParseRevocationList(crlBytes); err != nil {
203-
log.WithFields(
204-
log.Fields{
205-
"trace_id": ctx.Value("trace_id"),
206-
"type": "backend_log",
207-
"backend_service": "crl",
208-
"backend_hosts": url,
209-
"details": err.Error(),
210-
},
211-
).Error("Unable to parse CRL data")
212-
err = utils.APIGenericInternalError("Unable to parse CRL Data")
213-
return []pkix.RevokedCertificate{}, err
214-
}
215-
216-
return crtList.RevokedCertificates, err
217-
}
218-
219160
// FetchCRL fetches the CRL
220161
func FetchCRL(ctx context.Context, url string) ([]pkix.RevokedCertificate, error) {
221162

@@ -256,8 +197,21 @@ func FetchCRL(ctx context.Context, url string) ([]pkix.RevokedCertificate, error
256197
return []pkix.RevokedCertificate{}, err
257198
}
258199

259-
defer resp.Body.Close()
260-
200+
defer func(Body io.ReadCloser) {
201+
err := Body.Close()
202+
if err != nil {
203+
log.WithFields(
204+
log.Fields{
205+
"trace_id": ctx.Value("trace_id"),
206+
"type": "backend_log",
207+
"backend_service": "crl",
208+
"backend_hosts": url,
209+
"details": err.Error(),
210+
},
211+
).Error("Could not close response body")
212+
}
213+
}(resp.Body)
214+
261215
// create the crl from the byte slice
262216
if crtList, err = x509.ParseCRL(crlBytes); err != nil {
263217
log.WithFields(

auth/revoke_test.go

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ import (
44
"context"
55
"crypto/x509"
66
"encoding/pem"
7-
"io/ioutil"
7+
"io"
88
"testing"
99

1010
LOGGER "github.com/sirupsen/logrus"
@@ -141,7 +141,14 @@ func (suite *RevokeTestSuite) TestCRLCheckRevokedCert() {
141141
suite.Equal("Internal Error: Could not access CRL https://unknown/unknown", err4.Error())
142142
}
143143

144+
func (suite *RevokeTestSuite) TestFetchCRL() {
145+
// test cases about consuming various CRL
146+
crlUrl := "http://www.gridcanada.ca/ca/bffbd7d0.r0"
147+
_, err := FetchCRL(context.Background(), crlUrl)
148+
suite.Nil(err)
149+
}
150+
144151
func TestRevokeTestSuite(t *testing.T) {
145-
LOGGER.SetOutput(ioutil.Discard)
152+
LOGGER.SetOutput(io.Discard)
146153
suite.Run(t, new(RevokeTestSuite))
147154
}

authmethods/authmethods_test.go

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,6 @@ import (
77
"github.com/ARGOeu/argo-api-authn/stores"
88
"github.com/stretchr/testify/suite"
99
"io"
10-
"io/ioutil"
1110
"testing"
1211
)
1312

@@ -21,7 +20,7 @@ func ConvertAuthMethodToReadCloser(am AuthMethod) io.ReadCloser {
2120

2221
reader := bytes.NewReader(bb)
2322

24-
return ioutil.NopCloser(reader)
23+
return io.NopCloser(reader)
2524

2625
}
2726

0 commit comments

Comments
 (0)