mirror of
https://github.com/zitadel/zitadel.git
synced 2025-01-11 09:43:40 +00:00
744185449e
* introspect * testingapplication key * date * client keys * fix client keys * fix client keys * access tokens only for users * AuthMethodPrivateKeyJWT * client keys * set introspection info correctly * managae apis * update oidc pkg * cleanup * merge msater * set current sequence in migration * set current sequence in migration * set current sequence in migration * Apply suggestions from code review Co-authored-by: Fabi <38692350+fgerschwiler@users.noreply.github.com> * DeleteAuthNKeysByObjectID * ensure authn keys uptodate * update oidc version * merge master * merge master Co-authored-by: Fabi <38692350+fgerschwiler@users.noreply.github.com>
63 lines
1.6 KiB
Go
63 lines
1.6 KiB
Go
package model
|
|
|
|
import (
|
|
"fmt"
|
|
"strings"
|
|
|
|
"github.com/caos/logging"
|
|
|
|
"github.com/caos/zitadel/internal/crypto"
|
|
"github.com/caos/zitadel/internal/errors"
|
|
es_models "github.com/caos/zitadel/internal/eventstore/models"
|
|
"github.com/caos/zitadel/internal/id"
|
|
)
|
|
|
|
type APIConfig struct {
|
|
es_models.ObjectRoot
|
|
AppID string
|
|
ClientID string
|
|
ClientSecret *crypto.CryptoValue
|
|
ClientSecretString string
|
|
AuthMethodType APIAuthMethodType
|
|
ClientKeys []*ClientKey
|
|
}
|
|
|
|
type APIAuthMethodType int32
|
|
|
|
const (
|
|
APIAuthMethodTypeBasic APIAuthMethodType = iota
|
|
APIAuthMethodTypePrivateKeyJWT
|
|
)
|
|
|
|
func (c *APIConfig) IsValid() bool {
|
|
return true
|
|
}
|
|
|
|
//ClientID random_number@projectname (eg. 495894098234@zitadel)
|
|
func (c *APIConfig) GenerateNewClientID(idGenerator id.Generator, project *Project) error {
|
|
rndID, err := idGenerator.Next()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
c.ClientID = fmt.Sprintf("%v@%v", rndID, strings.ReplaceAll(strings.ToLower(project.Name), " ", "_"))
|
|
return nil
|
|
}
|
|
|
|
func (c *APIConfig) GenerateClientSecretIfNeeded(generator crypto.Generator) (string, error) {
|
|
if c.AuthMethodType == APIAuthMethodTypeBasic {
|
|
return c.GenerateNewClientSecret(generator)
|
|
}
|
|
return "", nil
|
|
}
|
|
|
|
func (c *APIConfig) GenerateNewClientSecret(generator crypto.Generator) (string, error) {
|
|
cryptoValue, stringSecret, err := crypto.NewCode(generator)
|
|
if err != nil {
|
|
logging.Log("MODEL-ADvd2").OnError(err).Error("unable to create client secret")
|
|
return "", errors.ThrowInternal(err, "MODEL-dsvr43", "Errors.Project.CouldNotGenerateClientSecret")
|
|
}
|
|
c.ClientSecret = cryptoValue
|
|
return stringSecret, nil
|
|
}
|