Skip to content

Commit

Permalink
Merge pull request #88 from caos/basic-auth
Browse files Browse the repository at this point in the history
fix: encoding of basic auth header values
  • Loading branch information
hifabienne committed Mar 5, 2021
2 parents 527dd7b + 8f6e2c5 commit 84e5159
Show file tree
Hide file tree
Showing 4 changed files with 22 additions and 4 deletions.
4 changes: 2 additions & 2 deletions pkg/client/rs/resource_server.go
Expand Up @@ -37,11 +37,11 @@ func (r *resourceServer) AuthFn() (interface{}, error) {
return r.authFn()
}

func NewResourceServerClientCredentials(issuer, clientID, clientSecret string, option Option) (ResourceServer, error) {
func NewResourceServerClientCredentials(issuer, clientID, clientSecret string, option ...Option) (ResourceServer, error) {
authorizer := func() (interface{}, error) {
return utils.AuthorizeBasic(clientID, clientSecret), nil
}
return newResourceServer(issuer, authorizer, option)
return newResourceServer(issuer, authorizer, option...)
}
func NewResourceServerJWTProfile(issuer, clientID, keyID string, key []byte, options ...Option) (ResourceServer, error) {
signer, err := client.NewSignerFromPrivateKeyByte(key, keyID)
Expand Down
11 changes: 10 additions & 1 deletion pkg/op/signer.go
Expand Up @@ -51,9 +51,18 @@ func (s *tokenSigner) refreshSigningKey(ctx context.Context, keyCh <-chan jose.S
return
case key := <-keyCh:
s.alg = key.Algorithm
if key.Algorithm == "" || key.Key == nil {
s.signer = nil
logging.Log("OP-DAvt4").Warn("signer has no key")
continue
}
var err error
s.signer, err = jose.NewSigner(key, &jose.SignerOptions{})
logging.Log("OP-pf32aw").OnError(err).Error("error creating signer")
if err != nil {
logging.Log("OP-pf32aw").WithError(err).Error("error creating signer")
continue
}
logging.Log("OP-agRf2").Info("signer exchanged signing key")
}
}
}
Expand Down
9 changes: 9 additions & 0 deletions pkg/op/token_intospection.go
Expand Up @@ -3,6 +3,7 @@ package op
import (
"errors"
"net/http"
"net/url"

"github.com/caos/oidc/pkg/oidc"
"github.com/caos/oidc/pkg/utils"
Expand Down Expand Up @@ -68,6 +69,14 @@ func ParseTokenIntrospectionRequest(r *http.Request, introspector Introspector)
}
clientID, clientSecret, ok := r.BasicAuth()
if ok {
clientID, err = url.QueryUnescape(clientID)
if err != nil {
return "", "", errors.New("invalid basic auth header")
}
clientSecret, err = url.QueryUnescape(clientSecret)
if err != nil {
return "", "", errors.New("invalid basic auth header")
}
if err := introspector.Storage().AuthorizeClientIDSecret(r.Context(), clientID, clientSecret); err != nil {
return "", "", err
}
Expand Down
2 changes: 1 addition & 1 deletion pkg/utils/http.go
Expand Up @@ -30,7 +30,7 @@ type RequestAuthorization func(*http.Request)

func AuthorizeBasic(user, password string) RequestAuthorization {
return func(req *http.Request) {
req.SetBasicAuth(user, password)
req.SetBasicAuth(url.QueryEscape(user), url.QueryEscape(password))
}
}

Expand Down

0 comments on commit 84e5159

Please sign in to comment.