Implements gateway-level JWT validation for SQS requests: - Validates JWT signature against Authentik JWKS - Verifies claims: iss, aud, exp, nbf (with 60s skew) - Checks 'permissions' claim for sqs:read/sqs:write/wildcard - Returns 403 with error details on validation failure - JWKS caching with 15min TTL and auto-refresh on key rotation Architecture: - SQS: Gateway validates JWT (kmsvc code unverified) - MinIO, Temporal: Native JWT support (pass-through) - Memory, IAM: Service-owned JWT validation Integration tests added: - Reject requests without Authorization header (403) - Accept requests with valid JWT from Authentik - Pass through Authorization header unchanged for other services Uses github.com/MicahParks/keyfunc/v2 for JWKS handling: - Automatic refresh every 15 minutes - On-demand refresh if kid not found - Handles RS256 signatures
35 lines
1.2 KiB
AMPL
35 lines
1.2 KiB
AMPL
module forgejo.riotpiao.com/rock/homelab-frontend
|
|
|
|
go 1.26.0
|
|
|
|
require (
|
|
github.com/MicahParks/keyfunc/v2 v2.1.0
|
|
github.com/golang-jwt/jwt/v5 v5.3.1
|
|
go.temporal.io/api v1.63.5
|
|
go.temporal.io/sdk v1.48.0
|
|
google.golang.org/grpc v1.83.2
|
|
google.golang.org/protobuf v1.36.11
|
|
gopkg.in/yaml.v3 v3.0.1
|
|
)
|
|
|
|
require (
|
|
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a // indirect
|
|
github.com/gogo/protobuf v1.3.2 // indirect
|
|
github.com/golang/mock v1.6.0 // indirect
|
|
github.com/google/uuid v1.6.0 // indirect
|
|
github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.2 // indirect
|
|
github.com/grpc-ecosystem/grpc-gateway/v2 v2.22.0 // indirect
|
|
github.com/nexus-rpc/nexus-proto-annotations v0.1.0 // indirect
|
|
github.com/nexus-rpc/sdk-go v0.7.0 // indirect
|
|
github.com/robfig/cron v1.2.0 // indirect
|
|
github.com/stretchr/objx v0.5.3 // indirect
|
|
github.com/stretchr/testify v1.12.0 // indirect
|
|
golang.org/x/net v0.58.0 // indirect
|
|
golang.org/x/sync v0.22.0 // indirect
|
|
golang.org/x/sys v0.47.0 // indirect
|
|
golang.org/x/text v0.41.0 // indirect
|
|
golang.org/x/time v0.3.0 // indirect
|
|
google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa // indirect
|
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa // indirect
|
|
)
|