Commit Graph
24000 Commits
Author SHA1 Message Date
Dominik Schmidt 44dba933b7 refactor(config): keep the re-export a function, pin env expansion in the test 2026-10-08 16:27:59 +02:00
Dominik Schmidt 87fb14eb5d refactor(config): extract BindSourcesToStructs into pkg/config/binder
New leaf package (only gookit + pkg/config/defaults) so callers can bind a
yaml config file without importing the aggregate service config. pkg/config
keeps a backward-compatible re-export.
2026-10-08 16:27:59 +02:00
Florian Schade 371e84ba68 Merge pull request #3658 from opencloud-eu/cli-additions
feat: add more cli options to unified roles
2026-10-08 12:44:38 +02:00
Andre Duffeck ba98b1d942 Merge pull request #3674 from aduffeck/guest-id-canonical-ascii
Use the stored guest id when returning an invite permission
2026-10-08 11:55:22 +02:00
Viktor Scharf a71eefa966 fix: translation makefile path (#3678) 2026-10-08 10:19:14 +02:00
André Duffeck 50a004b04f Bump reva 2026-10-07 16:22:23 +02:00
Andre Duffeck b5988200a3 Merge pull request #3671 from aduffeck/derive-guest-session-secret
Derive the guest session key from OC_JWT_SECRET
2026-10-07 15:47:37 +02:00
André Duffeck 08edebc66c Use the stored guest id when returning an invite permission
The share provider now stores the guest's mail address in its canonical
form, so build the returned identity from the created share instead of
the request.
2026-10-07 12:45:13 +02:00
Viktor Scharf 3134526824 api-test: extend search tests (#3634)
* api-test: extend search tests

* adjust tets
2026-10-07 10:07:27 +02:00
André Duffeck e4afd03bd0 Use HKDF instead of plain hmac to derive the session cookie secret 2026-10-07 10:06:57 +02:00
Andre Duffeck c71e186720 Merge pull request #3596 from opencloud-eu/dependabot/go_modules/github.com/onsi/ginkgo/v2-2.33.0
build(deps): bump github.com/onsi/ginkgo/v2 from 2.32.1 to 2.33.0
2026-10-07 10:06:39 +02:00
dependabot[bot] b45592b8e1 build(deps): bump github.com/onsi/ginkgo/v2 from 2.32.1 to 2.33.0
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.32.1 to 2.33.0.
- [Release notes](https://github.com/onsi/ginkgo/releases)
- [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md)
- [Commits](https://github.com/onsi/ginkgo/compare/v2.32.1...v2.33.0)

---
updated-dependencies:
- dependency-name: github.com/onsi/ginkgo/v2
  dependency-version: 2.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-10-07 07:21:33 +00:00
Jörn Friedrich Dreyer fbb0aff156 Merge pull request #3599 from opencloud-eu/dependabot/go_modules/github.com/open-policy-agent/opa-1.20.2
build(deps): bump github.com/open-policy-agent/opa from 1.19.1 to 1.21.1
2026-10-07 09:19:01 +02:00
André Duffeck 10b93edded Derive the guest session key from OC_JWT_SECRET
Replace AUTH_GUEST_SESSION_JWT_SECRET with a key derived via
HMAC-SHA256 from the reva JWT secret. Guest session tokens and reva
access tokens remain unforgeable across each other without a second
secret to configure.
2026-10-07 08:46:53 +02:00
dependabot[bot] 3f7d649ca7 build(deps): bump github.com/open-policy-agent/opa from 1.19.1 to 1.21.1
Bumps [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) from 1.19.1 to 1.21.1.
- [Release notes](https://github.com/open-policy-agent/opa/releases)
- [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-policy-agent/opa/compare/v1.19.1...v1.21.1)

---
updated-dependencies:
- dependency-name: github.com/open-policy-agent/opa
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-10-06 13:46:22 +00:00
Andre Duffeck 1df2eb21d4 Merge pull request #3668 from aduffeck/send-guestlink-emails
Send guestlink emails
2026-10-06 15:43:15 +02:00
André Duffeck 3858d7ec50 Bump reva to pull in the new capability 2026-10-06 13:25:09 +02:00
Andre Duffeck 22dfa5b65e Merge pull request #3618 from rhafer/proxy-guestauth-middleware
guestlinks: implement auth-middleware for Guestlink cookies
2026-10-06 13:05:43 +02:00
André Duffeck ec7f3f68a4 Add email notifications when a guest link has been created 2026-10-06 12:46:01 +02:00
André Duffeck 27a0195146 Set the guest_link capability according to the config 2026-10-06 12:46:01 +02:00
André Duffeck 3a555257fb Align env var names, fix port conflict 2026-10-06 11:28:16 +02:00
André Duffeck 88e45f8961 Stream auth failure bodies through encoders 2026-10-06 10:22:41 +02:00
André Duffeck 7f7da7f583 Use subtle to compare the hash 2026-10-06 09:52:02 +02:00
André Duffeck 934232e838 Limit body size on unauthenticated redeem endpoint 2026-10-06 09:52:02 +02:00
André Duffeck e8c78f496d Do not leak information about tokens in errors 2026-10-06 09:52:02 +02:00
André Duffeck adc8a51657 Don't use the same secret for signing sessions and reva tokens 2026-10-06 09:52:02 +02:00
André Duffeck 713b9c5095 Only enable guest_link auth when the feature is enabled 2026-10-06 09:52:02 +02:00
Alex d761a484da feat(web): use the OpenCloud brand colors for the primary color role (#3631) 2026-10-06 09:50:25 +02:00
Ralf Haferkamp fbb6ac602c proxy: add guestlink auth middleware 2026-10-06 09:47:00 +02:00
Ralf Haferkamp 98cdbd077d refactor(proxy): return typed authentication results from authenticators
Replace the boolean authenticator result with a typed AuthenticationResult
containing AuthenticationState (NotApplicable, Failed, Succeeded, Error)
to distinguish between non-applicability, rejected credentials, and
dependency failures.

All existing authentication behavior remains observably unchanged.
2026-10-06 09:47:00 +02:00
Ralf Haferkamp 246d49ee18 guestlinks: Setup guestlinks authprovider
This starts the guestlinks authprovider as part of the auth-guest
service and wires it into the authregistry.
2026-10-06 09:47:00 +02:00
Andre Duffeck 6ff4794ca8 Merge pull request #3609 from maki5/feat/guestauth_service
feat(guestlinks)!: auth-guest service
2026-10-06 09:23:22 +02:00
André Duffeck aeb11b07ce Adapt to renamed env var about guest links 2026-10-06 08:56:58 +02:00
Alex Ababii c1dc12deee feat(guestauth): upd readme with guest links flow diagram 2026-10-06 08:08:28 +02:00
Alex Ababii 2c898250a9 feat(guestauth): upd file manager lock, addtional filetrs for shareExpired and shareRemoved events, common config loading fix 2026-10-06 08:08:28 +02:00
Alex Ababii c5879ca1b2 feat(guestauth): renaming guest ivitations to guest links for consistency with libre-graph-api 2026-10-06 08:08:28 +02:00
Alex Ababii a1a8221f68 feat(guestauth): global flag to disable the guest links feature 2026-10-06 08:08:26 +02:00
Alex Ababii 340851de70 feat(guestauth): updated redeem endpoint response and dependencies 2026-10-06 08:07:44 +02:00
Alex Ababii e17a9a3ae9 feat(guestauth): aligned readme 2026-10-06 08:07:44 +02:00
Alex Ababii d0847093bf feat(guestauth): prefix for cookie 2026-10-06 08:07:44 +02:00
Alex Ababii cbf3ee8c0b feat(guestauth): guestauth service rename to auth-guest 2026-10-06 08:07:44 +02:00
Alex Ababii f86e339233 feat(guestauth): grantee email in GuestTokenCreated event 2026-10-06 08:07:44 +02:00
Alex Ababii cf77e47ce4 feat(guestauth): used file lock instead of mutex in file strorage implementation 2026-10-06 08:07:43 +02:00
Alex Ababii eac68b9354 feat(guestauth): upd redeem response error format 2026-10-06 08:07:43 +02:00
Alex Ababii 9088273778 feat(guestauth): upd token record expiry proporety value on add 2026-10-06 08:07:43 +02:00
Alex Ababii b920654815 feat(guetauth): upd the redeem route 2026-10-06 08:07:43 +02:00
Alex Ababii e5c3be7c67 feat(guestauth): moved SecretHash to a method instead of field in struct 2026-10-06 08:07:43 +02:00
Alex Ababii b4aa47c029 feat(guestauth): renamed Storage interface and dependencies to Manager 2026-10-06 08:07:43 +02:00
Alex Ababii 2106f60fd8 feat(guestauth): upd version tags for env vars 2026-10-06 08:07:43 +02:00
Alex Ababii fdf52e4eaf feat(guestauth): upd service readme 2026-10-06 08:07:43 +02:00