Compare commits
base: unkin/artifactapi:8ced48901ff174848c13e4bf7cdce651803e82db
unkin/artifactapi:master
unkin/artifactapi:benvin/auth-design-doc
unkin/artifactapi:benvin/yaml_updates
unkin/artifactapi:benvin/develop
unkin/artifactapi:v3.11.1
unkin/artifactapi:v3.11.0
unkin/artifactapi:v3.10.1
unkin/artifactapi:v3.10.0
unkin/artifactapi:v3.9.1
unkin/artifactapi:v3.9.0
unkin/artifactapi:v3.8.0
unkin/artifactapi:v3.7.7
unkin/artifactapi:v3.7.6
unkin/artifactapi:v3.7.5
unkin/artifactapi:v3.7.4
unkin/artifactapi:v3.7.3
unkin/artifactapi:v3.7.2
unkin/artifactapi:v3.7.1
unkin/artifactapi:v3.7.0
unkin/artifactapi:v3.6.5
unkin/artifactapi:v3.6.4
unkin/artifactapi:v3.6.3
unkin/artifactapi:v3.6.2
unkin/artifactapi:v3.6.1
unkin/artifactapi:v3.6.0
unkin/artifactapi:v3.5.0
unkin/artifactapi:v3.4.0
unkin/artifactapi:v3.3.0
unkin/artifactapi:v3.2.0
unkin/artifactapi:v3.1.0
unkin/artifactapi:v3.0.0
unkin/artifactapi:v2.7.3
unkin/artifactapi:v2.7.2
unkin/artifactapi:v2.7.1
unkin/artifactapi:v2.7.0
unkin/artifactapi:v2.6.0
unkin/artifactapi:v2.5.0
unkin/artifactapi:v2.4.0
unkin/artifactapi:v2.3.0
unkin/artifactapi:v2.2.1
unkin/artifactapi:v2.2.0
unkin/artifactapi:v2.1.3
unkin/artifactapi:v2.1.2
unkin/artifactapi:v2.1.1
unkin/artifactapi:v2.1.0
unkin/artifactapi:v2.0.4
..
compare: unkin/artifactapi:v3.8.0
unkin/artifactapi:master
unkin/artifactapi:benvin/auth-design-doc
unkin/artifactapi:benvin/yaml_updates
unkin/artifactapi:benvin/develop
unkin/artifactapi:v3.11.1
unkin/artifactapi:v3.11.0
unkin/artifactapi:v3.10.1
unkin/artifactapi:v3.10.0
unkin/artifactapi:v3.9.1
unkin/artifactapi:v3.9.0
unkin/artifactapi:v3.8.0
unkin/artifactapi:v3.7.7
unkin/artifactapi:v3.7.6
unkin/artifactapi:v3.7.5
unkin/artifactapi:v3.7.4
unkin/artifactapi:v3.7.3
unkin/artifactapi:v3.7.2
unkin/artifactapi:v3.7.1
unkin/artifactapi:v3.7.0
unkin/artifactapi:v3.6.5
unkin/artifactapi:v3.6.4
unkin/artifactapi:v3.6.3
unkin/artifactapi:v3.6.2
unkin/artifactapi:v3.6.1
unkin/artifactapi:v3.6.0
unkin/artifactapi:v3.5.0
unkin/artifactapi:v3.4.0
unkin/artifactapi:v3.3.0
unkin/artifactapi:v3.2.0
unkin/artifactapi:v3.1.0
unkin/artifactapi:v3.0.0
unkin/artifactapi:v2.7.3
unkin/artifactapi:v2.7.2
unkin/artifactapi:v2.7.1
unkin/artifactapi:v2.7.0
unkin/artifactapi:v2.6.0
unkin/artifactapi:v2.5.0
unkin/artifactapi:v2.4.0
unkin/artifactapi:v2.3.0
unkin/artifactapi:v2.2.1
unkin/artifactapi:v2.2.0
unkin/artifactapi:v2.1.3
unkin/artifactapi:v2.1.2
unkin/artifactapi:v2.1.1
unkin/artifactapi:v2.1.0
unkin/artifactapi:v2.0.4
1 Commits
8ced48901f
..
v3.8.0
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
109ba2ce27 |
feat: server-level GitHub machine credential for authenticated requests (#109)
ci/woodpecker/tag/docker Pipeline was successful
## Why Anonymous GitHub is capped at 60 requests/hour and cannot read private repositories. A machine credential usable by a free (non-enterprise) account is needed to lift the request budget to ~5000/hr and to read private-repo release assets. Builds on the background syncer (#108, now merged to `master`); this diff is the auth changes only. ## How - Add `internal/githubauth`: a process-wide GitHub credential delivered via env/secret, applied by default to every outbound GitHub request (releases scan, ranged asset-header GETs, and the generic-github byte proxy for private assets). - Support two modes: - **PAT** — `GITHUB_TOKEN` sent as `Authorization: Bearer <token>`. - **GitHub App** — `GITHUB_APP_ID` + `GITHUB_APP_INSTALLATION_ID` + private key (`GITHUB_APP_PRIVATE_KEY` inline PEM or `GITHUB_APP_PRIVATE_KEY_PATH`). Mint a short-lived RS256 JWT with stdlib `crypto/rsa` (no new dependency), exchange it at `POST /app/installations/{id}/access_tokens` for a ~1h installation token, cache it, and single-flight a refresh a few minutes before expiry. - Inject at the two GitHub call paths: the rpm github provider header builder (releases + ranged fetches) and the generic provider `AuthHeaders` (byte proxy, github.com hosts only; the pre-signed `objects.githubusercontent.com` redirect deliberately gets no Authorization). - Honor precedence: a remote's own `username`/`password` overrides the server credential; no credential configured stays anonymous (current behavior). - Fail closed at startup on partial App configuration (e.g. App id without a private key); a token-and-App conflict is also rejected. - Never persist the credential to the DB, return it from an API, or log it (token-exchange failures never echo the response body). - Read config via the existing `getenv` convention; document PAT vs App setup, the free-account fine-grained PAT scopes (Contents:read + Metadata:read), precedence, and the rate-limit implication. ## Rate limit Authenticated requests share the syncer's single global limiter — no second limiter is added. A token raises the effective GitHub ceiling (~5000/hr vs ~60/hr), so the limiter defaults stay safe. ## Tests `internal/githubauth` and `internal/provider/{rpm,generic}`: - PAT attaches the correct `Authorization` header to releases + asset-header requests. - App mints a valid RS256 JWT (verified against the app public key), exchanges it at a mocked endpoint, reuses the cached token without re-exchanging, refreshes near expiry, and single-flights concurrent callers. - Per-remote credential overrides the server credential (rpm + generic). - No credential → no `Authorization` header, requests still succeed anonymously. - ETag/304 flow still works with auth attached. - The credential does not appear in a remote's serialized JSON. - Config validation: no-config is anonymous; partial App config and token/App conflict both error. Verified fail-before/pass-after for the injection tests. `gofmt -l`, `go build ./...`, `go vet ./...`, `go test ./...` all clean (26 packages). Reviewed-on: #109 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net> |