Dominik Schmidt
44dba933b7
refactor(config): keep the re-export a function, pin env expansion in the test
2026-10-08 16:27:59 +02:00
Dominik Schmidt
87fb14eb5d
refactor(config): extract BindSourcesToStructs into pkg/config/binder
...
New leaf package (only gookit + pkg/config/defaults) so callers can bind a
yaml config file without importing the aggregate service config. pkg/config
keeps a backward-compatible re-export.
2026-10-08 16:27:59 +02:00
Florian Schade
371e84ba68
Merge pull request #3658 from opencloud-eu/cli-additions
...
feat: add more cli options to unified roles
2026-10-08 12:44:38 +02:00
Andre Duffeck
ba98b1d942
Merge pull request #3674 from aduffeck/guest-id-canonical-ascii
...
Use the stored guest id when returning an invite permission
2026-10-08 11:55:22 +02:00
Viktor Scharf
a71eefa966
fix: translation makefile path ( #3678 )
2026-10-08 10:19:14 +02:00
André Duffeck
50a004b04f
Bump reva
2026-10-07 16:22:23 +02:00
Andre Duffeck
b5988200a3
Merge pull request #3671 from aduffeck/derive-guest-session-secret
...
Derive the guest session key from OC_JWT_SECRET
2026-10-07 15:47:37 +02:00
André Duffeck
08edebc66c
Use the stored guest id when returning an invite permission
...
The share provider now stores the guest's mail address in its canonical
form, so build the returned identity from the created share instead of
the request.
2026-10-07 12:45:13 +02:00
Viktor Scharf
3134526824
api-test: extend search tests ( #3634 )
...
* api-test: extend search tests
* adjust tets
2026-10-07 10:07:27 +02:00
André Duffeck
e4afd03bd0
Use HKDF instead of plain hmac to derive the session cookie secret
2026-10-07 10:06:57 +02:00
Andre Duffeck
c71e186720
Merge pull request #3596 from opencloud-eu/dependabot/go_modules/github.com/onsi/ginkgo/v2-2.33.0
...
build(deps): bump github.com/onsi/ginkgo/v2 from 2.32.1 to 2.33.0
2026-10-07 10:06:39 +02:00
dependabot[bot]
b45592b8e1
build(deps): bump github.com/onsi/ginkgo/v2 from 2.32.1 to 2.33.0
...
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo ) from 2.32.1 to 2.33.0.
- [Release notes](https://github.com/onsi/ginkgo/releases )
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/onsi/ginkgo/compare/v2.32.1...v2.33.0 )
---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
dependency-version: 2.33.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-10-07 07:21:33 +00:00
Jörn Friedrich Dreyer
fbb0aff156
Merge pull request #3599 from opencloud-eu/dependabot/go_modules/github.com/open-policy-agent/opa-1.20.2
...
build(deps): bump github.com/open-policy-agent/opa from 1.19.1 to 1.21.1
2026-10-07 09:19:01 +02:00
André Duffeck
10b93edded
Derive the guest session key from OC_JWT_SECRET
...
Replace AUTH_GUEST_SESSION_JWT_SECRET with a key derived via
HMAC-SHA256 from the reva JWT secret. Guest session tokens and reva
access tokens remain unforgeable across each other without a second
secret to configure.
2026-10-07 08:46:53 +02:00
dependabot[bot]
3f7d649ca7
build(deps): bump github.com/open-policy-agent/opa from 1.19.1 to 1.21.1
...
Bumps [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa ) from 1.19.1 to 1.21.1.
- [Release notes](https://github.com/open-policy-agent/opa/releases )
- [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md )
- [Commits](https://github.com/open-policy-agent/opa/compare/v1.19.1...v1.21.1 )
---
updated-dependencies:
- dependency-name: github.com/open-policy-agent/opa
dependency-version: 1.20.2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-10-06 13:46:22 +00:00
Andre Duffeck
1df2eb21d4
Merge pull request #3668 from aduffeck/send-guestlink-emails
...
Send guestlink emails
2026-10-06 15:43:15 +02:00
André Duffeck
3858d7ec50
Bump reva to pull in the new capability
2026-10-06 13:25:09 +02:00
Andre Duffeck
22dfa5b65e
Merge pull request #3618 from rhafer/proxy-guestauth-middleware
...
guestlinks: implement auth-middleware for Guestlink cookies
2026-10-06 13:05:43 +02:00
André Duffeck
ec7f3f68a4
Add email notifications when a guest link has been created
2026-10-06 12:46:01 +02:00
André Duffeck
27a0195146
Set the guest_link capability according to the config
2026-10-06 12:46:01 +02:00
André Duffeck
3a555257fb
Align env var names, fix port conflict
2026-10-06 11:28:16 +02:00
André Duffeck
88e45f8961
Stream auth failure bodies through encoders
2026-10-06 10:22:41 +02:00
André Duffeck
7f7da7f583
Use subtle to compare the hash
2026-10-06 09:52:02 +02:00
André Duffeck
934232e838
Limit body size on unauthenticated redeem endpoint
2026-10-06 09:52:02 +02:00
André Duffeck
e8c78f496d
Do not leak information about tokens in errors
2026-10-06 09:52:02 +02:00
André Duffeck
adc8a51657
Don't use the same secret for signing sessions and reva tokens
2026-10-06 09:52:02 +02:00
André Duffeck
713b9c5095
Only enable guest_link auth when the feature is enabled
2026-10-06 09:52:02 +02:00
Alex
d761a484da
feat(web): use the OpenCloud brand colors for the primary color role ( #3631 )
2026-10-06 09:50:25 +02:00
Ralf Haferkamp
fbb6ac602c
proxy: add guestlink auth middleware
2026-10-06 09:47:00 +02:00
Ralf Haferkamp
98cdbd077d
refactor(proxy): return typed authentication results from authenticators
...
Replace the boolean authenticator result with a typed AuthenticationResult
containing AuthenticationState (NotApplicable, Failed, Succeeded, Error)
to distinguish between non-applicability, rejected credentials, and
dependency failures.
All existing authentication behavior remains observably unchanged.
2026-10-06 09:47:00 +02:00
Ralf Haferkamp
246d49ee18
guestlinks: Setup guestlinks authprovider
...
This starts the guestlinks authprovider as part of the auth-guest
service and wires it into the authregistry.
2026-10-06 09:47:00 +02:00
Andre Duffeck
6ff4794ca8
Merge pull request #3609 from maki5/feat/guestauth_service
...
feat(guestlinks)!: auth-guest service
2026-10-06 09:23:22 +02:00
André Duffeck
aeb11b07ce
Adapt to renamed env var about guest links
2026-10-06 08:56:58 +02:00
Alex Ababii
c1dc12deee
feat(guestauth): upd readme with guest links flow diagram
2026-10-06 08:08:28 +02:00
Alex Ababii
2c898250a9
feat(guestauth): upd file manager lock, addtional filetrs for shareExpired and shareRemoved events, common config loading fix
2026-10-06 08:08:28 +02:00
Alex Ababii
c5879ca1b2
feat(guestauth): renaming guest ivitations to guest links for consistency with libre-graph-api
2026-10-06 08:08:28 +02:00
Alex Ababii
a1a8221f68
feat(guestauth): global flag to disable the guest links feature
2026-10-06 08:08:26 +02:00
Alex Ababii
340851de70
feat(guestauth): updated redeem endpoint response and dependencies
2026-10-06 08:07:44 +02:00
Alex Ababii
e17a9a3ae9
feat(guestauth): aligned readme
2026-10-06 08:07:44 +02:00
Alex Ababii
d0847093bf
feat(guestauth): prefix for cookie
2026-10-06 08:07:44 +02:00
Alex Ababii
cbf3ee8c0b
feat(guestauth): guestauth service rename to auth-guest
2026-10-06 08:07:44 +02:00
Alex Ababii
f86e339233
feat(guestauth): grantee email in GuestTokenCreated event
2026-10-06 08:07:44 +02:00
Alex Ababii
cf77e47ce4
feat(guestauth): used file lock instead of mutex in file strorage implementation
2026-10-06 08:07:43 +02:00
Alex Ababii
eac68b9354
feat(guestauth): upd redeem response error format
2026-10-06 08:07:43 +02:00
Alex Ababii
9088273778
feat(guestauth): upd token record expiry proporety value on add
2026-10-06 08:07:43 +02:00
Alex Ababii
b920654815
feat(guetauth): upd the redeem route
2026-10-06 08:07:43 +02:00
Alex Ababii
e5c3be7c67
feat(guestauth): moved SecretHash to a method instead of field in struct
2026-10-06 08:07:43 +02:00
Alex Ababii
b4aa47c029
feat(guestauth): renamed Storage interface and dependencies to Manager
2026-10-06 08:07:43 +02:00
Alex Ababii
2106f60fd8
feat(guestauth): upd version tags for env vars
2026-10-06 08:07:43 +02:00
Alex Ababii
fdf52e4eaf
feat(guestauth): upd service readme
2026-10-06 08:07:43 +02:00