Commit graph

2484 commits

Author SHA1 Message Date
Max
285ca7b5ed
Merge pull request #1028 from trheyi/main
Enhance OAuth token management with PKCE support and refactor tests
2025-07-22 12:56:33 +08:00
Max
7e8d4a9ba9 Enhance OAuth token management with PKCE support and refactor tests
- Updated OAuth token handling to include PKCE (Proof Key for Code Exchange) parameters, improving security for authorization code grants.
- Refactored token management tests to incorporate PKCE code verifier and challenge, ensuring compliance with OAuth 2.1 standards.
- Enhanced refresh token handling to validate requested scopes against originally granted scopes, improving security and compliance.
- Updated various methods to support optional scope parameters, streamlining token management and validation processes.
- Improved test coverage for token introspection and exchange scenarios, ensuring robust validation of token handling logic.
2025-07-22 12:55:44 +08:00
Max
a09ddd70ac
Merge pull request #1027 from trheyi/main
Implement JWKS endpoint and enhance OAuth tests
2025-07-21 20:08:28 +08:00
Max
41c44cb726 Implement JWKS endpoint and enhance OAuth tests
- Added the JWKS endpoint to return JSON Web Key Set in compliance with RFC 7517, including necessary security headers.
- Refactored the JWKS generation logic to retrieve signing certificates and construct the JWK from the RSA public key.
- Introduced comprehensive tests for the JWKS endpoint, validating response format, compliance, and security headers.
- Updated go.mod to include the MongoDB driver as a required dependency.
2025-07-21 20:07:46 +08:00
Max
966e0cfd00 Enhance OAuth test setup with reusable certificate management
- Introduced global test certificate paths to avoid redundant certificate generation across tests, improving efficiency.
- Implemented a function to create temporary certificates once for all tests, ensuring consistent usage of signing certificates.
- Updated test configurations to utilize the new certificate management, enhancing clarity and maintainability.
- Added cleanup functionality for global test certificates to ensure proper resource management after tests.
2025-07-21 19:44:00 +08:00
Max
e1428551ba Refactor OAuth token management tests and remove deprecated methods
- Removed outdated token management tests from the user provider, including tests for storing, revoking, and retrieving tokens.
- Updated the user provider interface to reflect the removal of token management methods, ensuring cleaner code and improved maintainability.
- Streamlined the test suite by focusing on relevant user management functionalities, enhancing overall test clarity and effectiveness.
2025-07-21 18:59:26 +08:00
Max
8d1174d566 Refactor hello world endpoints and add OAuth protection
- Renamed existing hello world endpoints to public and added a new protected endpoint with OAuth guard.
- Updated test cases to reflect the new endpoint structure and added tests for protected endpoint access with and without valid tokens.
- Enhanced response handling for public and protected endpoints to ensure consistent output and proper status codes.
2025-07-21 18:49:20 +08:00
Max
55931bb59b Add OAuth token revocation and introspection tests
- Implemented comprehensive tests for the OAuth token revocation and introspection endpoints, ensuring correct handling of valid, invalid, and missing token scenarios.
- Enhanced the oauthRevoke and oauthIntrospect methods to comply with RFC specifications, returning appropriate status codes and responses.
- Introduced a utility function for obtaining access tokens directly in tests, streamlining the testing process for OAuth endpoints.
- Improved error handling and logging for better debugging and verification during tests.
2025-07-21 17:57:34 +08:00
Max
8bce24a00b
Merge pull request #1026 from trheyi/main
Add OAuth token handling and enhance grant type support
2025-07-21 17:41:10 +08:00
Max
2b171c3540 Refactor OAuth token handling and enhance grant type support
- Consolidated token grant handling into a unified method for authorization code, client credentials, and device code grants, improving code organization and reducing duplication.
- Introduced new methods for handling token exchange and refresh token grants, ensuring compliance with relevant RFCs.
- Enhanced error handling and validation for client credentials and grant types, improving robustness and security.
- Updated tests to utilize real authorization codes and ensure comprehensive coverage of the new functionality.
2025-07-21 17:40:08 +08:00
Max
e4a02d6b9c Add OAuth authorization tests and improve error handling 2025-07-21 16:21:40 +08:00
Max
b1996594a2
Merge pull request #1025 from trheyi/main
Enhance OAuth functionality with registration tests and response impr…
2025-07-21 16:08:18 +08:00
Max
e936407452 Enhance OAuth functionality with registration tests and response improvements
- Added a comprehensive test for the OAuth client registration endpoint, ensuring proper handling of valid requests and responses.
- Updated the response handling methods to comply with RFC standards, including a new method for direct OAuth responses.
- Refactored existing response methods to improve security header management and streamline response generation.
- Enhanced test logging for better debugging and verification of response data during OAuth registration tests.
2025-07-21 16:07:40 +08:00
Max
437d15af10
Merge pull request #1024 from trheyi/main
Implement OAuth endpoint logic and enhance test setup
2025-07-21 15:35:23 +08:00
Max
517a4cf5b0 Implement OAuth endpoint logic and enhance test setup
- Added core functionality for OAuth authorization, token handling, and user info retrieval, including error handling and response generation.
- Introduced helper functions for managing different grant types, improving code organization and clarity.
- Enhanced the test setup with a new Prepare function to initialize the OpenAPI test environment and a Clean function for proper resource management.
- Updated tests to ensure the OpenAPI server is correctly loaded and operational during testing.
2025-07-21 15:34:13 +08:00
Max
35dd8b5017
Merge pull request #1023 from trheyi/main
Refactor OAuth endpoint structure and add well-known handlers
2025-07-20 19:11:46 +08:00
Max
458391f5b4 Refactor OAuth endpoint structure and add well-known handlers
- Removed OAuth discovery and metadata endpoints from the attachOAuth function to streamline the code.
- Introduced a new method to handle well-known endpoints, improving organization and clarity in the OAuth implementation.
- Updated the Attach method to include the new well-known handlers, ensuring proper routing for OAuth-related metadata.
2025-07-20 19:11:16 +08:00
Max
915eaa79fc
Merge pull request #1022 from trheyi/main
Add OAuth documentation for versioned paths and discovery endpoints
2025-07-20 19:06:09 +08:00
Max
6256e131b3 Add OAuth documentation for versioned paths and discovery endpoints
- Added notes in the OAuth handler to clarify the requirements for using versioned paths, including the placement of discovery endpoints and server metadata.
- Emphasized the importance of mounting discovery endpoints at the root level for proper MCP client configuration and OAuth functionality.
2025-07-20 19:05:41 +08:00
Max
dfb4ff31dd
Merge pull request #1021 from trheyi/main
Add OpenAPI support and enhance configuration handling
2025-07-20 18:53:04 +08:00
Max
b96a400869 Add OpenAPI support and enhance configuration handling
- Integrated OpenAPI loading functionality into the engine's Load and Reload processes, allowing for better API management.
- Updated the OpenAPI configuration to set a default BaseURL and ensure it does not have a trailing slash.
- Implemented the Attach method to connect the OpenAPI server to the Gin router, facilitating API endpoint management.
- Removed the obsolete hello package to streamline the OpenAPI module.
2025-07-20 18:52:30 +08:00
Max
097129571a
Merge pull request #1020 from trheyi/main
Implement JSON marshaling and unmarshaling for configuration with dur…
2025-07-20 17:49:22 +08:00
Max
0fff602c93 Implement JSON marshaling and unmarshaling for configuration with duration parsing
- Enhanced the Config struct to support JSON marshaling and unmarshaling with human-readable duration strings for various OAuth settings.
- Introduced temporary structures to facilitate the conversion of string duration fields to time.Duration types during JSON operations.
- Added utility functions for parsing and formatting duration strings, ensuring accurate handling of time-related configurations.
- Updated tests to validate the correct parsing and formatting of duration fields in the configuration.
2025-07-20 17:49:01 +08:00
Max
deb38c576d
Merge pull request #1019 from trheyi/main
Enhance test for Load function by adding data store cleanup
2025-07-20 12:03:54 +08:00
Max
fa58bf42dc Enhance test for Load function by adding data store cleanup
- Implemented a cleanup step in the TestLoad function to remove the data store created during tests, ensuring a clean test environment.
- Added error handling for the Load function to improve robustness and provide feedback in case of failures.
2025-07-20 12:03:25 +08:00
Max
200ad70cc0
Merge pull request #1018 from trheyi/main
Update OAuth store management and enhance cache configurations
2025-07-20 11:48:39 +08:00
Max
5d3c03db1f Update OAuth store management and enhance cache configurations
- Added support for a new OAuth data store in the system store management, allowing for better organization and retrieval of OAuth-related data.
- Updated the OAuth cache store configuration to increase the cache size from 4096 to 8192, improving performance and storage capacity.
- Enhanced test utilities to include the new OAuth store, ensuring comprehensive testing coverage for the updated store management features.
2025-07-20 11:47:57 +08:00
Max
91ab642377
Merge pull request #1017 from trheyi/main
Implement system store management and enhance store loading functiona…
2025-07-20 11:23:52 +08:00
Max
8523170992 Implement system store management and enhance store loading functionality
- Introduced a new system store management feature, allowing for the loading of predefined system stores such as cache and OAuth client stores.
- Added a `loadSystemStores` function to handle the loading of system stores with variable replacement for configuration paths.
- Enhanced the `Load` function to include the loading of system stores, improving the overall store management process.
- Updated test utilities to support loading system stores for testing, ensuring comprehensive coverage and functionality.
- Refactored the `replaceVars` function to facilitate variable replacement in JSON strings, enhancing flexibility in store configurations.
2025-07-20 11:23:00 +08:00
Max
8dff8f1a09
Merge pull request #1016 from trheyi/main
Enhance OAuth configuration types with optional defaults
2025-07-18 17:05:39 +08:00
Max
72b732348d Enhance OAuth configuration types with optional defaults
- Updated the SigningConfig, TokenConfig, SecurityConfig, and ClientConfig structures to include optional default values for various fields, improving clarity and usability.
- Added comments to specify default values and optionality for each configuration parameter, enhancing documentation within the code.
- This change aims to streamline the configuration process for OAuth service implementations.
2025-07-18 17:05:13 +08:00
Max
a356858a1f
Merge pull request #1015 from trheyi/main
Add user and security tests
2025-07-18 15:51:39 +08:00
Max
ef07622e7e Add user and security tests 2025-07-18 15:48:50 +08:00
Max
0bad7e20c6
Merge pull request #1014 from trheyi/main
Refactor token exchange implementation in OAuth service
2025-07-18 15:31:33 +08:00
Max
2610036082 Refactor token exchange implementation in OAuth service
- Updated the TokenExchange method to utilize a new generateExchangedToken function for improved token generation.
- Enhanced error handling to return a descriptive error response if token generation fails.
- Added a new generateExchangedToken function to encapsulate the logic for creating exchanged tokens, improving code organization and maintainability.
2025-07-18 15:30:52 +08:00
Max
8dedbb1c2b
Merge pull request #1013 from trheyi/main
Refactor dynamic client registration tests in OAuth service
2025-07-18 15:13:42 +08:00
Max
b959768016 Refactor dynamic client registration tests in OAuth service
- Updated test cases to improve coverage for dynamic client registration scenarios.
- Enhanced error handling tests for various client registration edge cases, ensuring robustness in validation processes.
- Streamlined test setup for consistency across different testing environments.
2025-07-18 15:13:08 +08:00
Max
7590daad90
Merge pull request #1012 from trheyi/main
Add tests for dynamic client registration validation in OAuth service
2025-07-18 15:00:03 +08:00
Max
9fd0d4713a Add tests for dynamic client registration validation in OAuth service
- Implemented tests to verify error handling for disallowed redirect URI hosts and schemes during dynamic client registration.
- Updated test clients to use localhost for redirect URIs, ensuring consistency in testing environment.
2025-07-18 14:58:29 +08:00
Max
6cf7070370
Merge pull request #1011 from trheyi/main
Enhance client creation and dynamic registration in OAuth service
2025-07-18 14:52:03 +08:00
Max
944c3e1b8e Enhance client creation and dynamic registration in OAuth service
- Added default values for grant types, response types, application type, and token endpoint auth method during dynamic client registration.
- Implemented nil checks for client information in the CreateClient and UpdateClient methods to ensure robust error handling and validation.
2025-07-18 14:51:34 +08:00
Max
7ec0978ce0
Merge pull request #1010 from trheyi/main
Refactor OAuth service to improve client registration and user manage…
2025-07-18 14:32:13 +08:00
Max
d3874b28ad Refactor OAuth service to improve client registration and user management
- Enhanced dynamic client registration by refining client ID and secret generation methods.
- Improved validation processes for client registration requests and authorization flows.
- Streamlined user management integration with the updated user model, ensuring compatibility and efficiency.
- Updated token management features to support new client and user interactions, enhancing overall service functionality.
2025-07-18 14:28:44 +08:00
Max
16c9783b98
Merge pull request #1009 from trheyi/main
Implement dynamic client registration and enhance OAuth service funct…
2025-07-18 12:11:51 +08:00
Max
58eb00f8f2 Implement dynamic client registration and enhance OAuth service functionality
- Added dynamic client registration support in the OAuth service, implementing RFC 7591 for automatic client registration.
- Introduced methods for generating client IDs and secrets, validating registration requests, and creating client information.
- Enhanced authorization flow by validating client requests, redirect URIs, and response types.
- Implemented token management features, including token introspection, token exchange, and refresh token handling.
- Improved security with state parameter generation and validation, as well as code challenge methods for PKCE.
- Updated endpoint discovery and server metadata retrieval to include new features and capabilities.
2025-07-18 12:11:21 +08:00
Max
ad0bbb0a27
Merge pull request #1008 from trheyi/main
Add user model integration and enhance OAuth user provider
2025-07-18 11:32:12 +08:00
Max
fb20eb54c5 Add user model integration and enhance OAuth user provider
- Introduced a new user model `yao/models/user.mod.yao` to support user management functionalities.
- Updated the OAuth service to utilize the new `DefaultUser` provider, enhancing user authentication and management capabilities.
- Refactored user retrieval methods to align with the new user model structure, ensuring compatibility and improved functionality.
- Added token management methods to the user provider interface, streamlining token handling processes.
- Enhanced test utilities to include the new user model for comprehensive testing coverage.
2025-07-18 11:31:39 +08:00
Max
7636455d08
Merge pull request #1007 from trheyi/main
Remove deprecated OAuth interfaces and types
2025-07-17 17:23:30 +08:00
Max
e19aa4b8df Remove deprecated OAuth interfaces and types
- Deleted the OAuth interface and related types that were previously defined in the `interfaces.go` and `types.go` files, streamlining the codebase.
- Updated the `oauth.go` file to integrate user and client providers directly, enhancing the service's functionality and reducing complexity.
- Refactored the user information retrieval method to utilize the new user provider structure, ensuring compatibility with the updated architecture.
2025-07-17 17:19:22 +08:00
Max
93823b87d9
Merge pull request #1006 from trheyi/main
Add OAuth service implementation with configuration and validation
2025-07-17 12:05:13 +08:00