Benedikt Kulmann
709543234f
chore: set introduction version to 7.5.0 for new env vars
2026-08-25 12:53:03 +02:00
Jörn Friedrich Dreyer
0776a479da
send all /data throught middleware
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-08-21 07:34:46 +02:00
Jörn Friedrich Dreyer
a93ec92789
rewrite more /data urls
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-08-21 07:34:46 +02:00
Jörn Friedrich Dreyer
c0d5380017
drop unused datagateway service and gateway config
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-08-21 07:34:46 +02:00
Jörn Friedrich Dreyer
a74661618e
refactor datagateway into proxy middleware
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-08-21 07:34:46 +02:00
Florian Schade
8b922127b8
feat: move the collaboration mentioning api to graph
2026-08-17 15:44:04 +02:00
Alex
b2cf7a965f
fix(csp): allow blob: in style-src for EPUB reader iframe ( #3300 )
2026-08-13 13:16:04 +02:00
Jörn Friedrich Dreyer
8478b5daa1
allow tuning the proxies http client
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-08-13 11:54:42 +02:00
Jörn Friedrich Dreyer
6f5f993ada
Merge pull request #3288 from fschade/feat-modernize-opa
...
perf(policies): reuse the compiled rego query across evaluations
2026-08-12 17:58:13 +02:00
Florian Schade
1e7cfaf92d
refactor(policies): read the rego policies once at startup
2026-08-12 17:01:49 +02:00
Florian Schade
cd7f8f91b6
fix: oidc middleware claim race
2026-08-11 11:39:50 +02:00
Dominik Schmidt
51dd107767
feat: add announcement banner
2026-07-29 00:39:59 +02:00
Viktor Scharf
5accb6056b
set 7.3.0 version placeholder ( #3132 )
2026-07-14 18:12:24 +02:00
Elias Schneider
4734c57f2b
fix(proxy): honor access token cache ttl
2026-07-14 17:49:40 +02:00
André Duffeck
1ea634e6e3
Do not try to create personal spaces for lightweight or service users
...
This fixes error logs like
RR error when calling Createhome error="gateway: grpc failed with code CODE_INVALID_ARGUMENT" line=github.com/opencloud-eu/opencloud/services/proxy/pkg/middleware/create_home.go:87 service=proxy
e.g. during internal requests to the data provider.
2026-06-19 11:05:44 +02:00
Jörn Friedrich Dreyer
81fd00043e
Merge pull request #2063 from opencloud-eu/nats-tls-options
...
add tls support for all nats connections
2026-06-16 13:21:22 +02:00
Florian Schade
f1208cfa32
enhancement: make collaboration mention functionality public
2026-06-11 09:28:37 +02:00
Florian Schade
159785a3b5
enhancement: make collaboration font management functionality public
2026-06-11 09:28:37 +02:00
Jörn Friedrich Dreyer
77fd4fca69
add tls support for all nats connections
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-06-10 17:04:18 +02:00
Florian Schade
457284885b
fix: remove unnecessary error log it the oidc access token verify method is set to none
2026-05-20 15:11:03 +02:00
Jörn Friedrich Dreyer
5d7bfc9033
delete unused constants
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-05-13 10:54:00 +02:00
Jörn Friedrich Dreyer
fb4112dc68
update generated code
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-05-13 10:52:44 +02:00
Florian Schade
d0e3f14539
chore: remove loop var references
2026-04-23 17:11:55 +02:00
Florian Schade
288e67cc39
chore: replace interface with any
2026-04-23 09:31:11 +02:00
Viktor Scharf
f8b28b12e9
combine version placeholder check steps [ 🎉 release]. set 6.1.0. version for upcoming release ( #2626 )
...
* 🎉 release: combine version placeholder check steps
* set 6.1.0 version
2026-04-20 10:43:22 +02:00
Ralf Haferkamp
d9f39773e7
proxy: add memory cache for tenant id mapping
...
This is to reduce the number of "proxy->gateway->users->ldap" roundtrips
for the tenant id mapping.
The cache currently has a non-configurable ttl of 10 min.
Related: #2310
2026-04-09 17:46:50 +02:00
Ralf Haferkamp
a931e53c26
proxy: Allow mapping from an external tenant id to the internal id
...
When the tenant id coming in via the OIDC claims doesn't match the
tenant id on the provisioned user, a mapping can be configured and
resolved via the reva TenantAPI service (now started as part of the
"users" service).
Closes : #2310
2026-04-09 17:46:50 +02:00
Ralf Haferkamp
33f45fa965
feat(multi-tenancy): verify tenant via OIDC claim
...
When multi-tenancy is enable we now allow to specify an OIDC claim
against which the tenantid of the user resolved via CS3 apis is matched.
Partial: #2310
2026-04-02 16:10:53 +02:00
Michael Barz
f0836c54fb
feat: add userid to spans ( #2536 )
2026-03-30 10:32:24 +02:00
Florian Schade
c7fd33c919
fix: send the backchannel logout event only if a session exists
2026-02-27 11:16:53 +01:00
Florian Schade
b69b9cd569
fix: simplify subject.session key parsing
2026-02-25 14:02:09 +01:00
Florian Schade
e8ecbd7af1
refactor: make the logout mode private
2026-02-25 14:02:09 +01:00
Florian Schade
fd614eacf1
fix: use base64 record keys to prevent separator clashes with subjects or sessionIds that contain a dot
2026-02-25 14:02:09 +01:00
Florian Schade
910298aa05
chore: change naming
2026-02-25 14:02:09 +01:00
Florian Schade
7350050a05
test: add more backchannellogout tests
2026-02-25 14:02:09 +01:00
Florian Schade
f72e3f1e32
chore: cleanup backchannel logout pr for review
2026-02-25 14:02:09 +01:00
Florian Schade
0c62c45494
enhancement: document idp side-effects
2026-02-25 14:02:09 +01:00
Florian Schade
f6553498f6
enhancement: finalize backchannel logout
2026-02-25 14:02:09 +01:00
6a0fd89475
refactor deletion
...
Co-authored-by: Jörn Dreyer <j.dreyer@opencloud.eu >
Co-authored-by: Michael Barz <m.barz@opencloud.eu >
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-02-25 14:02:09 +01:00
Christian Richter
cb38aaab16
create mapping in cache for subject => sessionid
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-02-25 14:02:09 +01:00
Christian Richter
762062bfa3
add mapping to backchannel logout for subject => sessionid
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-02-25 14:02:09 +01:00
Christian Richter and Michael Barz
291265afb0
add additional validation to logout token
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
Co-authored-by: Michael Barz <m.barz@opencloud.eu >
2026-02-25 14:02:09 +01:00
Ralf Haferkamp
6dde2839df
fix(oidc_auth): Fix userinfo cache expiration logic
...
When the userinfo claims store in the usercache is found to be expired,
do not return an error but ignore the cached entry and force a
re-verification of the access token (either via parsing the JWT again or
via a UserInfo lookup).
This is required for setups with non-JWT access tokes where the expiry
date set in the cached claims does not reflect the actual token expiry,
but just the CacheTTL.
Fixes : #1493
2026-02-19 13:17:17 +01:00
Ralf Haferkamp
0639304e96
docs(proxy): Clarify PROXY_OIDC_USERINFO_CACHE_TTL value
...
Try to make it more precise when that value is actually relevant.
Closes : #2252
2026-02-03 15:36:37 +01:00
Christian Richter
b51c4af8d9
remove logger from proxytest
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 14:50:44 +01:00
Christian Richter
21975d75eb
consolidate log config in proxy
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2026-01-08 13:16:55 +01:00
Jörn Friedrich Dreyer
84dce9a236
correctly handle paths ending in /
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-01-07 15:04:34 +01:00
Jörn Friedrich Dreyer
38eb7fb21b
use clean urls for routing
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-01-07 15:04:34 +01:00
Jörn Friedrich Dreyer
c99342318f
merge ocdav into frontend
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-01-07 15:04:34 +01:00
Christian Richter
0372869b8b
refactor remaining code from urfave/cli
...
Signed-off-by: Christian Richter <c.richter@opencloud.eu >
2025-12-15 16:40:27 +01:00