zitadel/internal/api/grpc/server/middleware
Stefan Benz 7caa43ab23
feat: action v2 signing (#8779)
# Which Problems Are Solved

The action v2 messages were didn't contain anything providing security
for the sent content.

# How the Problems Are Solved

Each Target now has a SigningKey, which can also be newly generated
through the API and returned at creation and through the Get-Endpoints.
There is now a HTTP header "Zitadel-Signature", which is generated with
the SigningKey and Payload, and also contains a timestamp to check with
a tolerance if the message took to long to sent.

# Additional Changes

The functionality to create and check the signature is provided in the
pkg/actions package, and can be reused in the SDK.

# Additional Context

Closes #7924

---------

Co-authored-by: Livio Spring <livio.a@gmail.com>
2024-11-28 10:06:52 +00:00
..
access_interceptor.go feat: trusted (instance) domains (#8369) 2024-07-31 18:00:38 +03:00
activity_interceptor.go feat: api v2beta to api v2 (#8283) 2024-07-26 22:39:55 +02:00
auth_interceptor_test.go refactor: rename package errors to zerrors (#7039) 2023-12-08 15:30:55 +01:00
auth_interceptor.go fix: add organizationID query for user v2 ListUsers and clean up depeprecated attribute (#7593) 2024-03-21 08:07:00 +00:00
cache_interceptor.go chore(v2): move to new org (#3499) 2022-04-26 23:01:45 +00:00
call_interceptor.go perf: query data AS OF SYSTEM TIME (#5231) 2023-02-27 22:36:43 +01:00
error_interceptor_test.go fix: translation (#647) 2020-08-28 09:44:43 +02:00
error_interceptor.go refactor: rename package errors to zerrors (#7039) 2023-12-08 15:30:55 +01:00
execution_interceptor_test.go feat: action v2 signing (#8779) 2024-11-28 10:06:52 +00:00
execution_interceptor.go feat(v3alpha): write actions (#8225) 2024-07-31 14:42:12 +02:00
instance_interceptor_test.go feat(v3alpha): read actions (#8357) 2024-08-12 22:32:01 +02:00
instance_interceptor.go feat(v3alpha): read actions (#8357) 2024-08-12 22:32:01 +02:00
limits_interceptor.go feat: block instances (#7129) 2024-01-17 10:16:48 +00:00
metrics_interceptor.go chore(v2): move to new org (#3499) 2022-04-26 23:01:45 +00:00
mock_test.go refactor: rename package errors to zerrors (#7039) 2023-12-08 15:30:55 +01:00
quota_interceptor.go refactor: rename package errors to zerrors (#7039) 2023-12-08 15:30:55 +01:00
service_interceptor.go feat: add new api services (#5619) 2023-04-11 15:37:42 +02:00
tracing.go refactor(fmt): run gci on complete project (#7557) 2024-04-03 10:43:43 +00:00
translation_interceptor.go feat: restrict languages (#6931) 2023-12-05 11:12:01 +00:00
translator.go refactor: rename package errors to zerrors (#7039) 2023-12-08 15:30:55 +01:00
validation_interceptor.go refactor(fmt): run gci on complete project (#7557) 2024-04-03 10:43:43 +00:00