mirror of
https://github.com/git-pkgs/proxy.git
synced 2026-08-23 12:24:57 -04:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
272e6d9040 |
||
|
|
c1f09e7921 |
||
|
|
17446b419f |
||
|
|
5cdbc89ed4 |
||
|
|
1a814c7e1f |
||
|
|
12ad4ecefc |
||
|
|
f0e6e11e8c |
||
|
|
088027cac3 |
||
|
|
49a68f1d81 |
||
|
|
e4fbf3f277 |
||
|
|
879e89efca |
||
|
|
87bf742237 |
||
|
|
78b29e5a21 |
||
|
|
3e534690d7 |
||
|
|
41c033a1e8 |
||
|
|
849500de1e |
||
|
|
ed540053fa |
||
|
|
6fcc57c994 |
||
|
|
538a15d9f8 |
||
|
|
bbea63f046 |
||
|
|
a17bdc7c89 |
||
|
|
30e4052615 |
||
|
|
4fa903e01e |
||
|
|
14f80ced34 |
||
|
|
d0f93196a3 |
71 changed files with 5740 additions and 1797 deletions
5
.github/workflows/ci.yml
vendored
5
.github/workflows/ci.yml
vendored
|
|
@ -13,7 +13,6 @@ jobs:
|
||||||
strategy:
|
strategy:
|
||||||
matrix:
|
matrix:
|
||||||
os: [ubuntu-latest, macos-latest, windows-latest]
|
os: [ubuntu-latest, macos-latest, windows-latest]
|
||||||
go-version: ['1.25']
|
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
|
|
@ -24,7 +23,7 @@ jobs:
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||||
with:
|
with:
|
||||||
go-version: ${{ matrix.go-version }}
|
go-version-file: go.mod
|
||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
run: go build -v ./...
|
run: go build -v ./...
|
||||||
|
|
@ -42,7 +41,7 @@ jobs:
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||||
with:
|
with:
|
||||||
go-version: '1.25'
|
go-version-file: go.mod
|
||||||
|
|
||||||
- name: golangci-lint
|
- name: golangci-lint
|
||||||
run: go tool golangci-lint run ./...
|
run: go tool golangci-lint run ./...
|
||||||
|
|
|
||||||
2
.github/workflows/swagger.yml
vendored
2
.github/workflows/swagger.yml
vendored
|
|
@ -19,7 +19,7 @@ jobs:
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||||
with:
|
with:
|
||||||
go-version: '1.25'
|
go-version-file: go.mod
|
||||||
|
|
||||||
- name: Install swag
|
- name: Install swag
|
||||||
run: go install github.com/swaggo/swag/cmd/swag@latest
|
run: go install github.com/swaggo/swag/cmd/swag@latest
|
||||||
|
|
|
||||||
2
.github/workflows/zizmor.yml
vendored
2
.github/workflows/zizmor.yml
vendored
|
|
@ -26,4 +26,4 @@ jobs:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Run zizmor
|
- name: Run zizmor
|
||||||
uses: zizmorcore/zizmor-action@6fc4b006235f201fdab3722e17240ab420d580e5 # v0.6.1
|
uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
|
||||||
|
|
|
||||||
|
|
@ -39,7 +39,7 @@ proxy/
|
||||||
│ │ └── queries.go # CRUD operations
|
│ │ └── queries.go # CRUD operations
|
||||||
│ ├── storage/ # Artifact file storage
|
│ ├── storage/ # Artifact file storage
|
||||||
│ │ ├── storage.go # Storage interface
|
│ │ ├── storage.go # Storage interface
|
||||||
│ │ └── filesystem.go # Local filesystem impl
|
│ │ └── blob.go # gocloud.dev/blob backends (file, S3, Azure)
|
||||||
│ ├── upstream/ # Upstream registry clients
|
│ ├── upstream/ # Upstream registry clients
|
||||||
│ │ ├── fetcher.go # HTTP artifact fetching
|
│ │ ├── fetcher.go # HTTP artifact fetching
|
||||||
│ │ └── resolver.go # Download URL resolution
|
│ │ └── resolver.go # Download URL resolution
|
||||||
|
|
@ -72,7 +72,7 @@ Key types:
|
||||||
|
|
||||||
### `internal/storage`
|
### `internal/storage`
|
||||||
|
|
||||||
Artifact file storage abstraction. Currently implements local filesystem storage. Designed to allow future backends (S3, GCS).
|
Artifact file storage abstraction backed by `gocloud.dev/blob`. Supports local filesystem (`file://`), S3 (`s3://`), and Azure (`azblob://`) URLs.
|
||||||
|
|
||||||
Interface:
|
Interface:
|
||||||
```go
|
```go
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,4 @@
|
||||||
FROM --platform=$BUILDPLATFORM golang:1.26.5-alpine AS builder
|
FROM --platform=$BUILDPLATFORM golang:1.26.6-alpine AS builder
|
||||||
|
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
|
|
||||||
|
|
|
||||||
50
README.md
50
README.md
|
|
@ -362,6 +362,39 @@ Or pull images directly:
|
||||||
docker pull localhost:8080/library/nginx:latest
|
docker pull localhost:8080/library/nginx:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Helm
|
||||||
|
|
||||||
|
Configure each HTTP chart repository with a name, then add the matching proxy
|
||||||
|
URL to Helm:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
upstream:
|
||||||
|
helm:
|
||||||
|
bitnami: "https://charts.bitnami.com/bitnami"
|
||||||
|
```
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm repo add bitnami http://localhost:8080/helm/bitnami
|
||||||
|
helm repo update
|
||||||
|
helm pull bitnami/nginx
|
||||||
|
```
|
||||||
|
|
||||||
|
The proxy caches `index.yaml` using the normal metadata-cache settings and
|
||||||
|
caches chart archives after verifying their SHA-256 digest from the index.
|
||||||
|
|
||||||
|
For charts stored in an OCI registry, configure a named OCI upstream and add
|
||||||
|
the reserved `upstream/{name}` prefix to the chart reference:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
upstream:
|
||||||
|
oci:
|
||||||
|
ghcr: "https://ghcr.io"
|
||||||
|
```
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm pull oci://localhost:8080/upstream/ghcr/owner/charts/mychart --version 1.0.0 --plain-http
|
||||||
|
```
|
||||||
|
|
||||||
### Debian / APT
|
### Debian / APT
|
||||||
|
|
||||||
Configure APT to use the proxy in `/etc/apt/sources.list.d/proxy.list`:
|
Configure APT to use the proxy in `/etc/apt/sources.list.d/proxy.list`:
|
||||||
|
|
@ -376,6 +409,13 @@ Replace your existing sources.list entries, then:
|
||||||
sudo apt update
|
sudo apt update
|
||||||
```
|
```
|
||||||
|
|
||||||
|
The upstream defaults to `http://deb.debian.org/debian`. To proxy a different APT repository (e.g. Ubuntu), set `upstream.debian` in the config file or `PROXY_UPSTREAM_DEBIAN` in the environment:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
upstream:
|
||||||
|
debian: "http://archive.ubuntu.com/ubuntu"
|
||||||
|
```
|
||||||
|
|
||||||
### RPM / Yum / DNF
|
### RPM / Yum / DNF
|
||||||
|
|
||||||
Configure yum/dnf to use the proxy in `/etc/yum.repos.d/proxy.repo`:
|
Configure yum/dnf to use the proxy in `/etc/yum.repos.d/proxy.repo`:
|
||||||
|
|
@ -416,6 +456,7 @@ The proxy can be configured via:
|
||||||
-database-url string PostgreSQL connection URL
|
-database-url string PostgreSQL connection URL
|
||||||
-log-level string Log level: debug, info, warn, error (default "info")
|
-log-level string Log level: debug, info, warn, error (default "info")
|
||||||
-log-format string Log format: text, json (default "text")
|
-log-format string Log format: text, json (default "text")
|
||||||
|
-access-log string Path to the JSONL access log
|
||||||
-version Print version and exit
|
-version Print version and exit
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
@ -431,6 +472,7 @@ PROXY_DATABASE_PATH=./cache/proxy.db
|
||||||
PROXY_DATABASE_URL=postgres://user:pass@localhost/proxy?sslmode=disable
|
PROXY_DATABASE_URL=postgres://user:pass@localhost/proxy?sslmode=disable
|
||||||
PROXY_LOG_LEVEL=info
|
PROXY_LOG_LEVEL=info
|
||||||
PROXY_LOG_FORMAT=text
|
PROXY_LOG_FORMAT=text
|
||||||
|
PROXY_ACCESS_LOG_PATH=/var/log/proxy/access.jsonl
|
||||||
```
|
```
|
||||||
|
|
||||||
### Configuration File
|
### Configuration File
|
||||||
|
|
@ -451,6 +493,9 @@ log:
|
||||||
level: "info"
|
level: "info"
|
||||||
format: "text"
|
format: "text"
|
||||||
|
|
||||||
|
access_log:
|
||||||
|
path: "/var/log/proxy/access.jsonl" # Optional JSONL activity log
|
||||||
|
|
||||||
# Optional: override upstream URLs
|
# Optional: override upstream URLs
|
||||||
upstream:
|
upstream:
|
||||||
npm: "https://registry.npmjs.org"
|
npm: "https://registry.npmjs.org"
|
||||||
|
|
@ -624,6 +669,7 @@ Recently cached:
|
||||||
| `GET /conda/*` | Conda/Anaconda protocol |
|
| `GET /conda/*` | Conda/Anaconda protocol |
|
||||||
| `GET /cran/*` | CRAN (R) protocol |
|
| `GET /cran/*` | CRAN (R) protocol |
|
||||||
| `GET /julia/*` | Julia Pkg server protocol |
|
| `GET /julia/*` | Julia Pkg server protocol |
|
||||||
|
| `GET /helm/{repository}/*` | HTTP Helm chart repository protocol |
|
||||||
| `GET /v2/*` | OCI/Docker registry protocol |
|
| `GET /v2/*` | OCI/Docker registry protocol |
|
||||||
| `GET /debian/*` | Debian/APT repository protocol |
|
| `GET /debian/*` | Debian/APT repository protocol |
|
||||||
| `GET /rpm/*` | RPM/Yum repository protocol |
|
| `GET /rpm/*` | RPM/Yum repository protocol |
|
||||||
|
|
@ -837,6 +883,8 @@ The proxy exposes Prometheus metrics at `GET /metrics`. All metric names are pre
|
||||||
|
|
||||||
| Metric | Type | Labels | Description |
|
| Metric | Type | Labels | Description |
|
||||||
|--------|------|--------|-------------|
|
|--------|------|--------|-------------|
|
||||||
|
| `proxy_requests_total` | counter | `ecosystem`, `status` | Proxy responses by package ecosystem and HTTP status |
|
||||||
|
| `proxy_request_duration_seconds` | histogram | `ecosystem`, `status` | Proxy request duration |
|
||||||
| `proxy_cache_hits_total` | counter | `ecosystem` | Cache hits |
|
| `proxy_cache_hits_total` | counter | `ecosystem` | Cache hits |
|
||||||
| `proxy_cache_misses_total` | counter | `ecosystem` | Cache misses |
|
| `proxy_cache_misses_total` | counter | `ecosystem` | Cache misses |
|
||||||
| `proxy_cache_size_bytes` | gauge | | Total size of cached artifacts |
|
| `proxy_cache_size_bytes` | gauge | | Total size of cached artifacts |
|
||||||
|
|
@ -1017,7 +1065,7 @@ The proxy will recreate the database on next start.
|
||||||
|
|
||||||
Requirements:
|
Requirements:
|
||||||
|
|
||||||
- Go 1.25 or later
|
- Go (the project version is declared in `go.mod`)
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
git clone https://github.com/git-pkgs/proxy.git
|
git clone https://github.com/git-pkgs/proxy.git
|
||||||
|
|
|
||||||
|
|
@ -40,6 +40,8 @@
|
||||||
// Log level: debug, info, warn, error (default "info")
|
// Log level: debug, info, warn, error (default "info")
|
||||||
// -log-format string
|
// -log-format string
|
||||||
// Log format: text, json (default "text")
|
// Log format: text, json (default "text")
|
||||||
|
// -access-log string
|
||||||
|
// Path to the JSONL access log (disabled by default)
|
||||||
//
|
//
|
||||||
// Stats Flags:
|
// Stats Flags:
|
||||||
//
|
//
|
||||||
|
|
@ -72,6 +74,7 @@
|
||||||
// PROXY_DATABASE_URL - PostgreSQL connection URL
|
// PROXY_DATABASE_URL - PostgreSQL connection URL
|
||||||
// PROXY_LOG_LEVEL - Log level
|
// PROXY_LOG_LEVEL - Log level
|
||||||
// PROXY_LOG_FORMAT - Log format
|
// PROXY_LOG_FORMAT - Log format
|
||||||
|
// PROXY_ACCESS_LOG_PATH - JSONL access log path
|
||||||
// PROXY_UPSTREAM_MAVEN - Maven repository upstream URL
|
// PROXY_UPSTREAM_MAVEN - Maven repository upstream URL
|
||||||
// PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL - Gradle Plugin Portal upstream URL
|
// PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL - Gradle Plugin Portal upstream URL
|
||||||
// PROXY_GRADLE_BUILD_CACHE_READ_ONLY - Disable Gradle PUT uploads
|
// PROXY_GRADLE_BUILD_CACHE_READ_ONLY - Disable Gradle PUT uploads
|
||||||
|
|
@ -184,6 +187,7 @@ func runServe() {
|
||||||
databaseURL := fs.String("database-url", "", "PostgreSQL connection URL")
|
databaseURL := fs.String("database-url", "", "PostgreSQL connection URL")
|
||||||
logLevel := fs.String("log-level", "", "Log level: debug, info, warn, error")
|
logLevel := fs.String("log-level", "", "Log level: debug, info, warn, error")
|
||||||
logFormat := fs.String("log-format", "", "Log format: text, json")
|
logFormat := fs.String("log-format", "", "Log format: text, json")
|
||||||
|
accessLogPath := fs.String("access-log", "", "Path to the JSONL access log")
|
||||||
version := fs.Bool("version", false, "Print version and exit")
|
version := fs.Bool("version", false, "Print version and exit")
|
||||||
|
|
||||||
fs.Usage = func() {
|
fs.Usage = func() {
|
||||||
|
|
@ -201,6 +205,7 @@ func runServe() {
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_DATABASE_URL PostgreSQL connection URL\n")
|
fmt.Fprintf(os.Stderr, " PROXY_DATABASE_URL PostgreSQL connection URL\n")
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_LOG_LEVEL Log level\n")
|
fmt.Fprintf(os.Stderr, " PROXY_LOG_LEVEL Log level\n")
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_LOG_FORMAT Log format\n")
|
fmt.Fprintf(os.Stderr, " PROXY_LOG_FORMAT Log format\n")
|
||||||
|
fmt.Fprintf(os.Stderr, " PROXY_ACCESS_LOG_PATH JSONL access log path\n")
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_MAVEN Maven repository upstream URL\n")
|
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_MAVEN Maven repository upstream URL\n")
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL Gradle Plugin Portal upstream URL\n")
|
fmt.Fprintf(os.Stderr, " PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL Gradle Plugin Portal upstream URL\n")
|
||||||
fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_READ_ONLY Disable Gradle PUT uploads\n")
|
fmt.Fprintf(os.Stderr, " PROXY_GRADLE_BUILD_CACHE_READ_ONLY Disable Gradle PUT uploads\n")
|
||||||
|
|
@ -256,6 +261,9 @@ func runServe() {
|
||||||
if *logFormat != "" {
|
if *logFormat != "" {
|
||||||
cfg.Log.Format = *logFormat
|
cfg.Log.Format = *logFormat
|
||||||
}
|
}
|
||||||
|
if *accessLogPath != "" {
|
||||||
|
cfg.AccessLog.Path = *accessLogPath
|
||||||
|
}
|
||||||
|
|
||||||
// Validate configuration
|
// Validate configuration
|
||||||
if err := cfg.Validate(); err != nil {
|
if err := cfg.Validate(); err != nil {
|
||||||
|
|
@ -267,7 +275,10 @@ func runServe() {
|
||||||
logger := setupLogger(cfg.Log.Level, cfg.Log.Format)
|
logger := setupLogger(cfg.Log.Level, cfg.Log.Format)
|
||||||
|
|
||||||
// Create and start server
|
// Create and start server
|
||||||
srv, err := server.New(cfg, logger)
|
srv, err := server.New(cfg, logger, server.BuildInfo{
|
||||||
|
Version: Version,
|
||||||
|
Commit: Commit,
|
||||||
|
})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
logger.Error("failed to create server", "error", err)
|
logger.Error("failed to create server", "error", err)
|
||||||
os.Exit(1)
|
os.Exit(1)
|
||||||
|
|
|
||||||
|
|
@ -78,6 +78,10 @@ log:
|
||||||
# Log format: "text" or "json"
|
# Log format: "text" or "json"
|
||||||
format: "text"
|
format: "text"
|
||||||
|
|
||||||
|
# JSONL access log. Leave path empty to disable it.
|
||||||
|
access_log:
|
||||||
|
path: ""
|
||||||
|
|
||||||
# Upstream registry URLs and authentication
|
# Upstream registry URLs and authentication
|
||||||
upstream:
|
upstream:
|
||||||
# npm registry URL
|
# npm registry URL
|
||||||
|
|
@ -95,8 +99,21 @@ upstream:
|
||||||
# Cargo crate download URL
|
# Cargo crate download URL
|
||||||
cargo_download: "https://static.crates.io/crates"
|
cargo_download: "https://static.crates.io/crates"
|
||||||
|
|
||||||
|
# Debian/APT repository URL (used by /debian endpoint)
|
||||||
|
debian: "http://deb.debian.org/debian"
|
||||||
|
|
||||||
|
# Named HTTP Helm chart repositories (used by /helm/{name}/)
|
||||||
|
# helm:
|
||||||
|
# bitnami: "https://charts.bitnami.com/bitnami"
|
||||||
|
|
||||||
|
# Named OCI registries. Use the upstream/{name}/ repository prefix, e.g.
|
||||||
|
# oci://proxy.example.com/upstream/ghcr/owner/chart.
|
||||||
|
# oci:
|
||||||
|
# ghcr: "https://ghcr.io"
|
||||||
|
|
||||||
# Authentication for upstream registries
|
# Authentication for upstream registries
|
||||||
# Keys are URL prefixes matched against request URLs.
|
# Keys are absolute URL scopes. Scheme, host, effective port, and path
|
||||||
|
# segment boundaries must match; the longest matching scope wins.
|
||||||
# Values can reference environment variables using ${VAR_NAME} syntax.
|
# Values can reference environment variables using ${VAR_NAME} syntax.
|
||||||
#
|
#
|
||||||
# Supported auth types:
|
# Supported auth types:
|
||||||
|
|
|
||||||
|
|
@ -240,6 +240,8 @@ Fetches artifacts from upstream registries.
|
||||||
- Exponential backoff retry on 429 (rate limit) and 5xx errors
|
- Exponential backoff retry on 429 (rate limit) and 5xx errors
|
||||||
- Returns streaming reader (doesn't load into memory)
|
- Returns streaming reader (doesn't load into memory)
|
||||||
- Configurable user-agent
|
- Configurable user-agent
|
||||||
|
- Shares an authentication-aware transport with metadata requests so URL-scoped credentials apply consistently
|
||||||
|
- Discovers and caches scoped OCI Bearer tokens from registry challenges
|
||||||
|
|
||||||
**Resolver:**
|
**Resolver:**
|
||||||
- Determines download URL for a package/version
|
- Determines download URL for a package/version
|
||||||
|
|
@ -351,6 +353,7 @@ Eviction can be implemented as:
|
||||||
- Fresh data - new versions visible immediately
|
- Fresh data - new versions visible immediately
|
||||||
- Metadata is small, upstream fetch is fast
|
- Metadata is small, upstream fetch is fast
|
||||||
- Set `cache_metadata: true` or use the mirror command to enable metadata caching for offline use via the `metadata_cache` table
|
- Set `cache_metadata: true` or use the mirror command to enable metadata caching for offline use via the `metadata_cache` table
|
||||||
|
- OCI manifests are the exception: they are cached automatically so previously fetched images remain pullable when the registry or token service is unavailable
|
||||||
|
|
||||||
**Why stream artifacts?**
|
**Why stream artifacts?**
|
||||||
- Memory efficient - don't load large files into RAM
|
- Memory efficient - don't load large files into RAM
|
||||||
|
|
|
||||||
|
|
@ -108,6 +108,30 @@ log:
|
||||||
| `log.level` | `PROXY_LOG_LEVEL` | `-log-level` | `debug`, `info`, `warn`, `error` |
|
| `log.level` | `PROXY_LOG_LEVEL` | `-log-level` | `debug`, `info`, `warn`, `error` |
|
||||||
| `log.format` | `PROXY_LOG_FORMAT` | `-log-format` | `text`, `json` |
|
| `log.format` | `PROXY_LOG_FORMAT` | `-log-format` | `text`, `json` |
|
||||||
|
|
||||||
|
## Access Log
|
||||||
|
|
||||||
|
The optional access log records client requests and each HTTP exchange with an upstream registry. It is always written as JSONL, with one JSON object per line. Records for the same client request share a `request_id`.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
access_log:
|
||||||
|
path: "/var/log/proxy/access.jsonl"
|
||||||
|
```
|
||||||
|
|
||||||
|
| Config | Environment | Flag | Description |
|
||||||
|
|--------|-------------|------|-------------|
|
||||||
|
| `access_log.path` | `PROXY_ACCESS_LOG_PATH` | `-access-log` | File to append JSONL records to; empty disables the log |
|
||||||
|
|
||||||
|
The parent directory must exist and be writable when the proxy starts. A newly created log file is readable and writable only by the proxy process owner.
|
||||||
|
|
||||||
|
A request that receives a rate limit response from an upstream can produce records like these:
|
||||||
|
|
||||||
|
```json
|
||||||
|
{"time":"2026-08-16T12:00:00Z","event":"upstream","request_id":"host/example-000001","method":"GET","url":"https://registry.example/packages/example","status_code":429,"duration_ms":42}
|
||||||
|
{"time":"2026-08-16T12:00:00Z","event":"request","request_id":"host/example-000001","method":"GET","path":"/npm/example","status_code":502,"duration_ms":43,"remote_addr":"192.0.2.10:41234"}
|
||||||
|
```
|
||||||
|
|
||||||
|
Upstream retries and OCI authentication calls are separate `upstream` records, so the log preserves every status returned over the wire. Network failures have an `error` field and no `status_code`. URL credentials, query strings, and fragments are omitted from both upstream URLs and client paths.
|
||||||
|
|
||||||
## Upstream Registries
|
## Upstream Registries
|
||||||
|
|
||||||
Override default upstream registry URLs:
|
Override default upstream registry URLs:
|
||||||
|
|
@ -119,11 +143,33 @@ upstream:
|
||||||
gradle_plugin_portal: "https://plugins.gradle.org/m2"
|
gradle_plugin_portal: "https://plugins.gradle.org/m2"
|
||||||
cargo: "https://index.crates.io"
|
cargo: "https://index.crates.io"
|
||||||
cargo_download: "https://static.crates.io/crates"
|
cargo_download: "https://static.crates.io/crates"
|
||||||
|
|
||||||
|
# Named HTTP Helm chart repositories, served at /helm/{name}/.
|
||||||
|
helm:
|
||||||
|
bitnami: "https://charts.bitnami.com/bitnami"
|
||||||
|
|
||||||
|
# Named OCI registries. Select one with the repository prefix
|
||||||
|
# upstream/{name}/, e.g. oci://proxy.example.com/upstream/ghcr/owner/chart.
|
||||||
|
oci:
|
||||||
|
ghcr: "https://ghcr.io"
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Helm HTTP repositories are read-only. The proxy fetches and rewrites each
|
||||||
|
repository's `index.yaml` so chart archives are downloaded through the proxy.
|
||||||
|
Chart archives are retained only when their SHA-256 digest matches the digest
|
||||||
|
listed in the index. Relative and absolute chart URLs are both supported.
|
||||||
|
|
||||||
|
Named OCI registries preserve the existing unprefixed Docker Hub mirror. A
|
||||||
|
reference such as `oci://proxy.example.com/upstream/ghcr/owner/chart` is sent
|
||||||
|
to the registry configured as `ghcr` with `owner/chart` as its repository.
|
||||||
|
When the proxy uses plain HTTP (for example `localhost:8080`), pass
|
||||||
|
`--plain-http` to Helm OCI commands.
|
||||||
|
|
||||||
## Authentication
|
## Authentication
|
||||||
|
|
||||||
Configure authentication for private upstream registries. Auth is matched by URL prefix, and credentials can reference environment variables using `${VAR_NAME}` syntax.
|
Configure authentication for private upstream registries. The same authentication-aware client is used for metadata and artifact downloads, and credentials can reference environment variables using `${VAR_NAME}` syntax.
|
||||||
|
|
||||||
|
OCI registries that return a Bearer challenge from a `/v2/{repository}/…` endpoint are handled automatically. The proxy discovers the token realm from `WWW-Authenticate`, applies any configured credentials for the token URL, and reuses the scoped token until shortly before it expires.
|
||||||
|
|
||||||
### Bearer Token
|
### Bearer Token
|
||||||
|
|
||||||
|
|
@ -172,7 +218,7 @@ upstream:
|
||||||
|
|
||||||
### URL Matching
|
### URL Matching
|
||||||
|
|
||||||
Auth configs are matched by URL prefix. The longest matching prefix wins, so you can configure different credentials for different paths:
|
Auth keys must be absolute URLs. Matching compares the scheme, host, effective port, and path-segment prefix, preventing credentials for `registry.example.com` from being sent to a lookalike host such as `registry.example.com.evil.test`. The longest matching scope wins, so you can configure different credentials for different paths:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
upstream:
|
upstream:
|
||||||
|
|
@ -246,6 +292,8 @@ Note: Hex cooldown requires disabling registry signature verification since the
|
||||||
|
|
||||||
By default the proxy fetches metadata fresh from upstream on every request. Enable `cache_metadata` to store metadata responses in the database and storage backend for offline fallback. When upstream is unreachable, the proxy serves the last cached copy. ETag-based revalidation avoids re-downloading unchanged metadata.
|
By default the proxy fetches metadata fresh from upstream on every request. Enable `cache_metadata` to store metadata responses in the database and storage backend for offline fallback. When upstream is unreachable, the proxy serves the last cached copy. ETag-based revalidation avoids re-downloading unchanged metadata.
|
||||||
|
|
||||||
|
OCI manifests are always cached because cached image blobs cannot be pulled without their manifests. Digest-addressed manifests are immutable and served directly from cache. Tag-addressed manifests follow `metadata_ttl`, revalidate when stale, and fall back to the last cached response when the registry is unavailable.
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
cache_metadata: true
|
cache_metadata: true
|
||||||
```
|
```
|
||||||
|
|
|
||||||
189
go.mod
189
go.mod
|
|
@ -1,73 +1,79 @@
|
||||||
module github.com/git-pkgs/proxy
|
module github.com/git-pkgs/proxy
|
||||||
|
|
||||||
go 1.25.6
|
go 1.26.0
|
||||||
|
|
||||||
|
toolchain go1.26.6
|
||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/BurntSushi/toml v1.6.0
|
github.com/BurntSushi/toml v1.6.0
|
||||||
github.com/CycloneDX/cyclonedx-go v0.11.0
|
github.com/CycloneDX/cyclonedx-go v0.11.0
|
||||||
github.com/git-pkgs/archives v0.4.0
|
github.com/git-pkgs/archives v0.5.1
|
||||||
github.com/git-pkgs/cooldown v0.1.1
|
github.com/git-pkgs/cooldown v0.1.1
|
||||||
github.com/git-pkgs/enrichment v0.6.4
|
github.com/git-pkgs/enrichment v0.6.5
|
||||||
github.com/git-pkgs/magic v0.1.0
|
github.com/git-pkgs/integrity v0.1.1
|
||||||
github.com/git-pkgs/purl v0.1.15
|
github.com/git-pkgs/magic v0.2.0
|
||||||
github.com/git-pkgs/registries v0.6.4
|
github.com/git-pkgs/purl v0.1.17
|
||||||
github.com/git-pkgs/spdx v0.1.4
|
github.com/git-pkgs/registries v0.8.1
|
||||||
github.com/git-pkgs/vers v0.3.0
|
github.com/git-pkgs/spdx v0.3.1
|
||||||
github.com/git-pkgs/vulns v0.2.1
|
github.com/git-pkgs/vers v0.3.1
|
||||||
|
github.com/git-pkgs/vulns v0.2.2
|
||||||
github.com/go-chi/chi/v5 v5.3.1
|
github.com/go-chi/chi/v5 v5.3.1
|
||||||
github.com/jmoiron/sqlx v1.4.0
|
github.com/jmoiron/sqlx v1.4.0
|
||||||
github.com/lib/pq v1.12.3
|
github.com/lib/pq v1.12.3
|
||||||
github.com/prometheus/client_golang v1.24.0
|
github.com/prometheus/client_golang v1.24.1
|
||||||
github.com/prometheus/client_model v0.6.2
|
github.com/prometheus/client_model v0.6.2
|
||||||
github.com/spdx/tools-golang v0.5.7
|
github.com/spdx/tools-golang v0.5.7
|
||||||
github.com/swaggo/swag v1.16.6
|
github.com/swaggo/swag v1.16.6
|
||||||
gocloud.dev v0.46.0
|
gocloud.dev v0.46.0
|
||||||
golang.org/x/sync v0.22.0
|
golang.org/x/sync v0.22.0
|
||||||
google.golang.org/protobuf v1.36.11
|
google.golang.org/protobuf v1.36.12
|
||||||
gopkg.in/yaml.v3 v3.0.1
|
gopkg.in/yaml.v3 v3.0.1
|
||||||
modernc.org/sqlite v1.55.0
|
modernc.org/sqlite v1.56.0
|
||||||
)
|
)
|
||||||
|
|
||||||
require (
|
require (
|
||||||
4d63.com/gocheckcompilerdirectives v1.3.0 // indirect
|
4d63.com/gocheckcompilerdirectives v1.4.0 // indirect
|
||||||
4d63.com/gochecknoglobals v0.2.2 // indirect
|
4d63.com/gochecknoglobals v0.2.2 // indirect
|
||||||
cloud.google.com/go/auth v0.18.2 // indirect
|
charm.land/lipgloss/v2 v2.0.6 // indirect
|
||||||
|
cloud.google.com/go/auth v0.21.0 // indirect
|
||||||
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
|
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
|
||||||
cloud.google.com/go/compute/metadata v0.9.0 // indirect
|
cloud.google.com/go/compute/metadata v0.9.0 // indirect
|
||||||
codeberg.org/chavacava/garif v0.2.0 // indirect
|
codeberg.org/chavacava/garif v0.2.0 // indirect
|
||||||
codeberg.org/polyfloyd/go-errorlint v1.9.0 // indirect
|
codeberg.org/polyfloyd/go-errorlint v1.9.0 // indirect
|
||||||
dev.gaijin.team/go/exhaustruct/v4 v4.0.0 // indirect
|
dev.gaijin.team/go/exhaustruct/v4 v4.0.0 // indirect
|
||||||
dev.gaijin.team/go/golib v0.6.0 // indirect
|
dev.gaijin.team/go/exhaustruct/v5 v5.0.3 // indirect
|
||||||
|
dev.gaijin.team/go/golib v0.8.1 // indirect
|
||||||
github.com/4meepo/tagalign v1.4.3 // indirect
|
github.com/4meepo/tagalign v1.4.3 // indirect
|
||||||
github.com/Abirdcfly/dupword v0.1.7 // indirect
|
github.com/Abirdcfly/dupword v0.1.8 // indirect
|
||||||
github.com/AdminBenni/iota-mixing v1.0.0 // indirect
|
github.com/AdminBenni/iota-mixing v1.0.0 // indirect
|
||||||
github.com/AlwxSin/noinlineerr v1.0.5 // indirect
|
github.com/AlwxSin/noinlineerr v1.0.6 // indirect
|
||||||
github.com/Antonboom/errname v1.1.1 // indirect
|
github.com/Antonboom/errname v1.1.2 // indirect
|
||||||
github.com/Antonboom/nilnil v1.1.1 // indirect
|
github.com/Antonboom/nilnil v1.1.2 // indirect
|
||||||
github.com/Antonboom/testifylint v1.6.4 // indirect
|
github.com/Antonboom/testifylint v1.6.4 // indirect
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 // indirect
|
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 // indirect
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 // indirect
|
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 // indirect
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
|
github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4 // indirect
|
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4 // indirect
|
||||||
github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 // indirect
|
github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 // indirect
|
||||||
|
github.com/ClickHouse/clickhouse-go-linter v1.2.1 // indirect
|
||||||
github.com/Djarvur/go-err113 v0.1.1 // indirect
|
github.com/Djarvur/go-err113 v0.1.1 // indirect
|
||||||
github.com/KyleBanks/depth v1.2.1 // indirect
|
github.com/KyleBanks/depth v1.2.1 // indirect
|
||||||
github.com/Masterminds/semver/v3 v3.4.0 // indirect
|
github.com/Masterminds/semver/v3 v3.5.0 // indirect
|
||||||
github.com/MirrexOne/unqueryvet v1.5.3 // indirect
|
github.com/MirrexOne/unqueryvet v1.5.4 // indirect
|
||||||
github.com/OpenPeeDeeP/depguard/v2 v2.2.1 // indirect
|
github.com/OpenPeeDeeP/depguard/v2 v2.2.1 // indirect
|
||||||
github.com/PuerkitoBio/purell v1.1.1 // indirect
|
github.com/PuerkitoBio/purell v1.1.1 // indirect
|
||||||
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
|
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
|
||||||
github.com/alecthomas/chroma/v2 v2.23.1 // indirect
|
github.com/alecthomas/chroma/v2 v2.27.0 // indirect
|
||||||
github.com/alecthomas/go-check-sumtype v0.3.1 // indirect
|
github.com/alecthomas/go-check-sumtype v0.3.1 // indirect
|
||||||
github.com/alexkohler/nakedret/v2 v2.0.6 // indirect
|
github.com/alexkohler/nakedret/v2 v2.0.6 // indirect
|
||||||
github.com/alexkohler/prealloc v1.0.2 // indirect
|
github.com/alexkohler/prealloc v1.1.0 // indirect
|
||||||
github.com/alfatraining/structtag v1.0.0 // indirect
|
github.com/alfatraining/structtag v1.0.0 // indirect
|
||||||
github.com/alingse/asasalint v0.0.11 // indirect
|
github.com/alingse/asasalint v0.0.11 // indirect
|
||||||
github.com/alingse/nilnesserr v0.2.0 // indirect
|
github.com/alingse/nilnesserr v0.2.0 // indirect
|
||||||
github.com/anchore/go-struct-converter v0.1.0 // indirect
|
github.com/anchore/go-struct-converter v0.1.0 // indirect
|
||||||
github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect
|
github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect
|
||||||
github.com/ashanbrown/forbidigo/v2 v2.3.0 // indirect
|
github.com/ashanbrown/forbidigo/v2 v2.3.1 // indirect
|
||||||
github.com/ashanbrown/makezero/v2 v2.1.0 // indirect
|
github.com/ashanbrown/makezero/v2 v2.2.1 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2 v1.41.9 // indirect
|
github.com/aws/aws-sdk-go-v2 v1.41.9 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 // indirect
|
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/config v1.32.20 // indirect
|
github.com/aws/aws-sdk-go-v2/config v1.32.20 // indirect
|
||||||
|
|
@ -87,48 +93,49 @@ require (
|
||||||
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.2 // indirect
|
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.36.2 // indirect
|
||||||
github.com/aws/aws-sdk-go-v2/service/sts v1.42.3 // indirect
|
github.com/aws/aws-sdk-go-v2/service/sts v1.42.3 // indirect
|
||||||
github.com/aws/smithy-go v1.26.0 // indirect
|
github.com/aws/smithy-go v1.26.0 // indirect
|
||||||
github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
|
|
||||||
github.com/beorn7/perks v1.0.1 // indirect
|
github.com/beorn7/perks v1.0.1 // indirect
|
||||||
github.com/bkielbasa/cyclop v1.2.3 // indirect
|
github.com/bkielbasa/cyclop v1.2.3 // indirect
|
||||||
github.com/blizzy78/varnamelen v0.8.0 // indirect
|
github.com/blizzy78/varnamelen v0.8.0 // indirect
|
||||||
github.com/bombsimon/wsl/v4 v4.7.0 // indirect
|
github.com/bombsimon/wsl/v4 v4.7.0 // indirect
|
||||||
github.com/bombsimon/wsl/v5 v5.6.0 // indirect
|
github.com/bombsimon/wsl/v5 v5.9.0 // indirect
|
||||||
github.com/breml/bidichk v0.3.3 // indirect
|
github.com/breml/bidichk v0.3.3 // indirect
|
||||||
github.com/breml/errchkjson v0.4.1 // indirect
|
github.com/breml/errchkjson v0.4.1 // indirect
|
||||||
github.com/butuzov/ireturn v0.4.0 // indirect
|
github.com/butuzov/ireturn v0.4.1 // indirect
|
||||||
github.com/butuzov/mirror v1.3.0 // indirect
|
github.com/butuzov/mirror v1.3.3 // indirect
|
||||||
github.com/catenacyber/perfsprint v0.10.1 // indirect
|
github.com/catenacyber/perfsprint v0.10.1 // indirect
|
||||||
github.com/ccojocar/zxcvbn-go v1.0.4 // indirect
|
github.com/ccojocar/zxcvbn-go v1.0.4 // indirect
|
||||||
github.com/cenk/backoff v2.2.1+incompatible // indirect
|
github.com/cenk/backoff v2.2.1+incompatible // indirect
|
||||||
github.com/cespare/xxhash/v2 v2.3.0 // indirect
|
github.com/cespare/xxhash/v2 v2.3.0 // indirect
|
||||||
github.com/charithe/durationcheck v0.0.11 // indirect
|
github.com/charithe/durationcheck v0.0.11 // indirect
|
||||||
github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc // indirect
|
github.com/charmbracelet/colorprofile v0.4.3 // indirect
|
||||||
github.com/charmbracelet/lipgloss v1.1.0 // indirect
|
github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 // indirect
|
||||||
github.com/charmbracelet/x/ansi v0.10.1 // indirect
|
github.com/charmbracelet/x/ansi v0.11.8 // indirect
|
||||||
github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd // indirect
|
github.com/charmbracelet/x/term v0.2.2 // indirect
|
||||||
github.com/charmbracelet/x/term v0.2.1 // indirect
|
github.com/charmbracelet/x/termios v0.1.1 // indirect
|
||||||
|
github.com/charmbracelet/x/windows v0.2.2 // indirect
|
||||||
github.com/ckaznocha/intrange v0.3.1 // indirect
|
github.com/ckaznocha/intrange v0.3.1 // indirect
|
||||||
|
github.com/clipperhouse/displaywidth v0.11.0 // indirect
|
||||||
|
github.com/clipperhouse/uax29/v2 v2.7.0 // indirect
|
||||||
github.com/cpuguy83/go-md2man/v2 v2.0.6 // indirect
|
github.com/cpuguy83/go-md2man/v2 v2.0.6 // indirect
|
||||||
github.com/curioswitch/go-reassign v0.3.0 // indirect
|
github.com/curioswitch/go-reassign v0.3.0 // indirect
|
||||||
github.com/daixiang0/gci v0.13.7 // indirect
|
github.com/daixiang0/gci v0.13.7 // indirect
|
||||||
github.com/dave/dst v0.27.3 // indirect
|
github.com/dave/dst v0.27.3 // indirect
|
||||||
github.com/davecgh/go-spew v1.1.1 // indirect
|
|
||||||
github.com/denis-tingaikin/go-header v0.5.0 // indirect
|
github.com/denis-tingaikin/go-header v0.5.0 // indirect
|
||||||
github.com/dlclark/regexp2 v1.11.5 // indirect
|
github.com/dlclark/regexp2/v2 v2.2.1 // indirect
|
||||||
github.com/dustin/go-humanize v1.0.1 // indirect
|
github.com/dustin/go-humanize v1.0.1 // indirect
|
||||||
github.com/ecosyste-ms/ecosystems-go v0.4.0 // indirect
|
github.com/ecosyste-ms/ecosystems-go v0.4.0 // indirect
|
||||||
github.com/ettle/strcase v0.2.0 // indirect
|
github.com/ettle/strcase v0.2.0 // indirect
|
||||||
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a // indirect
|
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a // indirect
|
||||||
github.com/fatih/color v1.18.0 // indirect
|
github.com/fatih/color v1.19.0 // indirect
|
||||||
github.com/fatih/structtag v1.2.0 // indirect
|
github.com/fatih/structtag v1.2.0 // indirect
|
||||||
github.com/firefart/nonamedreturns v1.0.6 // indirect
|
github.com/firefart/nonamedreturns v1.0.8 // indirect
|
||||||
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
||||||
github.com/fzipp/gocyclo v0.6.0 // indirect
|
github.com/fzipp/gocyclo v0.6.0 // indirect
|
||||||
github.com/ghostiam/protogetter v0.3.20 // indirect
|
github.com/ghostiam/protogetter v0.3.21 // indirect
|
||||||
github.com/git-pkgs/packageurl-go v0.3.1 // indirect
|
github.com/git-pkgs/packageurl-go v0.3.1 // indirect
|
||||||
github.com/git-pkgs/pom v0.1.5 // indirect
|
github.com/git-pkgs/pom v0.1.5 // indirect
|
||||||
github.com/github/go-spdx/v2 v2.7.0 // indirect
|
github.com/github/go-spdx/v2 v2.7.0 // indirect
|
||||||
github.com/go-critic/go-critic v0.14.3 // indirect
|
github.com/go-critic/go-critic v0.14.4 // indirect
|
||||||
github.com/go-logr/logr v1.4.3 // indirect
|
github.com/go-logr/logr v1.4.3 // indirect
|
||||||
github.com/go-logr/stdr v1.2.2 // indirect
|
github.com/go-logr/stdr v1.2.2 // indirect
|
||||||
github.com/go-openapi/jsonpointer v0.19.5 // indirect
|
github.com/go-openapi/jsonpointer v0.19.5 // indirect
|
||||||
|
|
@ -149,108 +156,108 @@ require (
|
||||||
github.com/gofrs/flock v0.13.0 // indirect
|
github.com/gofrs/flock v0.13.0 // indirect
|
||||||
github.com/golang-jwt/jwt/v5 v5.3.1 // indirect
|
github.com/golang-jwt/jwt/v5 v5.3.1 // indirect
|
||||||
github.com/golangci/asciicheck v0.5.0 // indirect
|
github.com/golangci/asciicheck v0.5.0 // indirect
|
||||||
github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 // indirect
|
github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 // indirect
|
||||||
github.com/golangci/go-printf-func-name v0.1.1 // indirect
|
github.com/golangci/go-printf-func-name v0.1.1 // indirect
|
||||||
github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d // indirect
|
github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 // indirect
|
||||||
github.com/golangci/golangci-lint/v2 v2.10.1 // indirect
|
github.com/golangci/golangci-lint/v2 v2.13.1 // indirect
|
||||||
github.com/golangci/golines v0.15.0 // indirect
|
github.com/golangci/golines v0.15.0 // indirect
|
||||||
github.com/golangci/misspell v0.8.0 // indirect
|
github.com/golangci/misspell v0.8.0 // indirect
|
||||||
github.com/golangci/plugin-module-register v0.1.2 // indirect
|
github.com/golangci/plugin-module-register v0.1.2 // indirect
|
||||||
github.com/golangci/revgrep v0.8.0 // indirect
|
github.com/golangci/revgrep v0.8.0 // indirect
|
||||||
|
github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba // indirect
|
||||||
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e // indirect
|
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e // indirect
|
||||||
github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e // indirect
|
github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e // indirect
|
||||||
github.com/google/go-cmp v0.7.0 // indirect
|
github.com/google/go-cmp v0.7.0 // indirect
|
||||||
github.com/google/s2a-go v0.1.9 // indirect
|
github.com/google/s2a-go v0.1.9 // indirect
|
||||||
github.com/google/uuid v1.6.0 // indirect
|
github.com/google/uuid v1.6.0 // indirect
|
||||||
github.com/google/wire v0.7.0 // indirect
|
github.com/google/wire v0.7.0 // indirect
|
||||||
github.com/googleapis/enterprise-certificate-proxy v0.3.14 // indirect
|
github.com/googleapis/enterprise-certificate-proxy v0.3.18 // indirect
|
||||||
github.com/googleapis/gax-go/v2 v2.19.0 // indirect
|
github.com/googleapis/gax-go/v2 v2.23.0 // indirect
|
||||||
github.com/gordonklaus/ineffassign v0.2.0 // indirect
|
github.com/gordonklaus/ineffassign v0.2.0 // indirect
|
||||||
github.com/gostaticanalysis/analysisutil v0.7.1 // indirect
|
github.com/gostaticanalysis/analysisutil v0.7.1 // indirect
|
||||||
github.com/gostaticanalysis/comment v1.5.0 // indirect
|
github.com/gostaticanalysis/comment v1.5.0 // indirect
|
||||||
github.com/gostaticanalysis/forcetypeassert v0.2.0 // indirect
|
github.com/gostaticanalysis/forcetypeassert v0.2.0 // indirect
|
||||||
github.com/gostaticanalysis/nilerr v0.1.2 // indirect
|
github.com/gostaticanalysis/nilerr v0.1.2 // indirect
|
||||||
github.com/hashicorp/go-immutable-radix/v2 v2.1.0 // indirect
|
github.com/hashicorp/go-immutable-radix/v2 v2.1.0 // indirect
|
||||||
github.com/hashicorp/go-version v1.8.0 // indirect
|
github.com/hashicorp/go-version v1.9.0 // indirect
|
||||||
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
|
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
|
||||||
github.com/hashicorp/hcl v1.0.0 // indirect
|
github.com/hashicorp/hcl v1.0.0 // indirect
|
||||||
github.com/hexops/gotextdiff v1.0.3 // indirect
|
github.com/hexops/gotextdiff v1.0.3 // indirect
|
||||||
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
||||||
github.com/jgautheron/goconst v1.8.2 // indirect
|
github.com/jgautheron/goconst v1.11.0 // indirect
|
||||||
github.com/jingyugao/rowserrcheck v1.1.1 // indirect
|
|
||||||
github.com/jjti/go-spancheck v0.6.5 // indirect
|
github.com/jjti/go-spancheck v0.6.5 // indirect
|
||||||
github.com/josharian/intern v1.0.0 // indirect
|
github.com/josharian/intern v1.0.0 // indirect
|
||||||
github.com/julz/importas v0.2.0 // indirect
|
github.com/julz/importas v0.2.0 // indirect
|
||||||
github.com/karamaru-alpha/copyloopvar v1.2.2 // indirect
|
github.com/karamaru-alpha/copyloopvar v1.2.2 // indirect
|
||||||
github.com/kisielk/errcheck v1.9.0 // indirect
|
github.com/kisielk/errcheck v1.20.0 // indirect
|
||||||
github.com/kkHAIKE/contextcheck v1.1.6 // indirect
|
github.com/kkHAIKE/contextcheck v1.1.6 // indirect
|
||||||
github.com/kulti/thelper v0.7.1 // indirect
|
github.com/kulti/thelper v0.7.1 // indirect
|
||||||
github.com/kunwardeep/paralleltest v1.0.15 // indirect
|
github.com/kunwardeep/paralleltest v1.0.15 // indirect
|
||||||
github.com/kylelemons/godebug v1.1.0 // indirect
|
github.com/kylelemons/godebug v1.1.0 // indirect
|
||||||
github.com/lasiar/canonicalheader v1.1.2 // indirect
|
github.com/lasiar/canonicalheader v1.1.2 // indirect
|
||||||
github.com/ldez/exptostd v0.4.5 // indirect
|
github.com/ldez/exptostd v0.4.5 // indirect
|
||||||
github.com/ldez/gomoddirectives v0.8.0 // indirect
|
github.com/ldez/gomoddirectives v0.9.0 // indirect
|
||||||
github.com/ldez/grignotin v0.10.1 // indirect
|
github.com/ldez/grignotin v0.10.1 // indirect
|
||||||
github.com/ldez/structtags v0.6.1 // indirect
|
github.com/ldez/structtags v0.6.1 // indirect
|
||||||
github.com/ldez/tagliatelle v0.7.2 // indirect
|
github.com/ldez/tagliatelle v0.7.2 // indirect
|
||||||
github.com/ldez/usetesting v0.5.0 // indirect
|
github.com/ldez/usetesting v0.5.0 // indirect
|
||||||
github.com/leonklingele/grouper v1.1.2 // indirect
|
github.com/leonklingele/grouper v1.1.2 // indirect
|
||||||
github.com/lucasb-eyer/go-colorful v1.2.0 // indirect
|
github.com/lucasb-eyer/go-colorful v1.4.1 // indirect
|
||||||
github.com/macabu/inamedparam v0.2.0 // indirect
|
github.com/macabu/inamedparam v0.2.0 // indirect
|
||||||
github.com/magiconair/properties v1.8.6 // indirect
|
github.com/magiconair/properties v1.8.6 // indirect
|
||||||
github.com/mailru/easyjson v0.7.7 // indirect
|
github.com/mailru/easyjson v0.7.7 // indirect
|
||||||
github.com/manuelarte/embeddedstructfieldcheck v0.4.0 // indirect
|
github.com/manuelarte/embeddedstructfieldcheck v0.4.0 // indirect
|
||||||
github.com/manuelarte/funcorder v0.5.0 // indirect
|
github.com/manuelarte/funcorder v0.6.0 // indirect
|
||||||
github.com/maratori/testableexamples v1.0.1 // indirect
|
github.com/maratori/testableexamples v1.0.1 // indirect
|
||||||
github.com/maratori/testpackage v1.1.2 // indirect
|
github.com/maratori/testpackage v1.1.2 // indirect
|
||||||
github.com/matoous/godox v1.1.0 // indirect
|
github.com/matoous/godox v1.1.0 // indirect
|
||||||
github.com/mattn/go-colorable v0.1.14 // indirect
|
github.com/mattn/go-colorable v0.1.15 // indirect
|
||||||
github.com/mattn/go-isatty v0.0.20 // indirect
|
github.com/mattn/go-isatty v0.0.24 // indirect
|
||||||
github.com/mattn/go-runewidth v0.0.16 // indirect
|
github.com/mattn/go-runewidth v0.0.24 // indirect
|
||||||
github.com/mgechev/revive v1.14.0 // indirect
|
github.com/mgechev/revive v1.15.0 // indirect
|
||||||
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
||||||
github.com/mitchellh/mapstructure v1.5.0 // indirect
|
github.com/mitchellh/mapstructure v1.5.0 // indirect
|
||||||
github.com/moricho/tparallel v0.3.2 // indirect
|
github.com/moricho/tparallel v0.3.2 // indirect
|
||||||
github.com/muesli/termenv v0.16.0 // indirect
|
github.com/muesli/cancelreader v0.2.2 // indirect
|
||||||
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
|
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
|
||||||
github.com/nakabonne/nestif v0.3.1 // indirect
|
github.com/nakabonne/nestif v0.3.1 // indirect
|
||||||
github.com/ncruces/go-strftime v1.0.0 // indirect
|
github.com/ncruces/go-strftime v1.0.0 // indirect
|
||||||
github.com/nishanths/exhaustive v0.12.0 // indirect
|
github.com/nishanths/exhaustive v0.12.0 // indirect
|
||||||
github.com/nishanths/predeclared v0.2.2 // indirect
|
github.com/nishanths/predeclared v0.2.2 // indirect
|
||||||
github.com/nunnatsa/ginkgolinter v0.23.0 // indirect
|
github.com/nunnatsa/ginkgolinter v0.24.0 // indirect
|
||||||
github.com/oapi-codegen/nullable v1.1.0 // indirect
|
github.com/oapi-codegen/nullable v1.2.0 // indirect
|
||||||
github.com/oapi-codegen/runtime v1.6.0 // indirect
|
github.com/oapi-codegen/runtime v1.6.0 // indirect
|
||||||
github.com/package-url/packageurl-go v0.1.6 // indirect
|
github.com/package-url/packageurl-go v0.1.6 // indirect
|
||||||
github.com/pandatix/go-cvss v0.6.2 // indirect
|
github.com/pandatix/go-cvss v0.6.2 // indirect
|
||||||
github.com/pelletier/go-toml v1.9.5 // indirect
|
github.com/pelletier/go-toml v1.9.5 // indirect
|
||||||
github.com/pelletier/go-toml/v2 v2.2.4 // indirect
|
github.com/pelletier/go-toml/v2 v2.4.3 // indirect
|
||||||
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
|
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
|
||||||
github.com/pmezard/go-difflib v1.0.0 // indirect
|
github.com/prometheus/common v0.70.1 // indirect
|
||||||
github.com/prometheus/common v0.70.0 // indirect
|
|
||||||
github.com/prometheus/procfs v0.21.1 // indirect
|
github.com/prometheus/procfs v0.21.1 // indirect
|
||||||
github.com/quasilyte/go-ruleguard v0.4.5 // indirect
|
github.com/quasilyte/go-ruleguard v0.4.5 // indirect
|
||||||
github.com/quasilyte/go-ruleguard/dsl v0.3.23 // indirect
|
github.com/quasilyte/go-ruleguard/dsl v0.3.23 // indirect
|
||||||
github.com/quasilyte/gogrep v0.5.0 // indirect
|
github.com/quasilyte/gogrep v0.5.0 // indirect
|
||||||
github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 // indirect
|
github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 // indirect
|
||||||
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 // indirect
|
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 // indirect
|
||||||
github.com/raeperd/recvcheck v0.2.0 // indirect
|
github.com/raeperd/recvcheck v0.3.0 // indirect
|
||||||
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
|
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
|
||||||
github.com/rivo/uniseg v0.4.7 // indirect
|
github.com/rivo/uniseg v0.4.7 // indirect
|
||||||
github.com/rogpeppe/go-internal v1.14.1 // indirect
|
github.com/rogpeppe/go-internal v1.16.0 // indirect
|
||||||
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 // indirect
|
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 // indirect
|
||||||
github.com/rubyist/circuitbreaker v2.2.1+incompatible // indirect
|
github.com/rubyist/circuitbreaker v2.2.1+incompatible // indirect
|
||||||
github.com/russross/blackfriday/v2 v2.1.0 // indirect
|
github.com/russross/blackfriday/v2 v2.1.0 // indirect
|
||||||
github.com/ryancurrah/gomodguard v1.4.1 // indirect
|
github.com/ryancurrah/gomodguard v1.4.1 // indirect
|
||||||
github.com/ryanrolds/sqlclosecheck v0.5.1 // indirect
|
github.com/ryancurrah/gomodguard/v2 v2.1.3 // indirect
|
||||||
|
github.com/ryanrolds/sqlclosecheck v0.6.0 // indirect
|
||||||
github.com/sanposhiho/wastedassign/v2 v2.1.0 // indirect
|
github.com/sanposhiho/wastedassign/v2 v2.1.0 // indirect
|
||||||
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect
|
github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 // indirect
|
||||||
github.com/sashamelentyev/interfacebloat v1.1.0 // indirect
|
github.com/sashamelentyev/interfacebloat v1.1.0 // indirect
|
||||||
github.com/sashamelentyev/usestdlibvars v1.29.0 // indirect
|
github.com/sashamelentyev/usestdlibvars v1.29.0 // indirect
|
||||||
github.com/securego/gosec/v2 v2.23.0 // indirect
|
github.com/securego/gosec/v2 v2.28.0 // indirect
|
||||||
github.com/sirupsen/logrus v1.9.4 // indirect
|
github.com/sirupsen/logrus v1.10.1 // indirect
|
||||||
github.com/sivchari/containedctx v1.0.3 // indirect
|
github.com/sivchari/containedctx v1.0.3 // indirect
|
||||||
github.com/sonatard/noctx v0.4.0 // indirect
|
github.com/sonatard/noctx v0.5.1 // indirect
|
||||||
github.com/sourcegraph/go-diff v0.7.0 // indirect
|
github.com/sourcegraph/go-diff v0.8.0 // indirect
|
||||||
github.com/spf13/afero v1.15.0 // indirect
|
github.com/spf13/afero v1.15.0 // indirect
|
||||||
github.com/spf13/cast v1.5.0 // indirect
|
github.com/spf13/cast v1.5.0 // indirect
|
||||||
github.com/spf13/cobra v1.10.2 // indirect
|
github.com/spf13/cobra v1.10.2 // indirect
|
||||||
|
|
@ -259,11 +266,11 @@ require (
|
||||||
github.com/spf13/viper v1.12.0 // indirect
|
github.com/spf13/viper v1.12.0 // indirect
|
||||||
github.com/ssgreg/nlreturn/v2 v2.2.1 // indirect
|
github.com/ssgreg/nlreturn/v2 v2.2.1 // indirect
|
||||||
github.com/stbenjam/no-sprintf-host-port v0.3.1 // indirect
|
github.com/stbenjam/no-sprintf-host-port v0.3.1 // indirect
|
||||||
github.com/stretchr/objx v0.5.2 // indirect
|
github.com/stretchr/objx v0.5.3 // indirect
|
||||||
github.com/stretchr/testify v1.11.1 // indirect
|
github.com/stretchr/testify v1.12.1 // indirect
|
||||||
github.com/subosito/gotenv v1.4.1 // indirect
|
github.com/subosito/gotenv v1.4.1 // indirect
|
||||||
github.com/tetafro/godot v1.5.4 // indirect
|
github.com/tetafro/godot v1.5.6 // indirect
|
||||||
github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 // indirect
|
github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 // indirect
|
||||||
github.com/timonwong/loggercheck v0.11.0 // indirect
|
github.com/timonwong/loggercheck v0.11.0 // indirect
|
||||||
github.com/tomarrell/wrapcheck/v2 v2.12.0 // indirect
|
github.com/tomarrell/wrapcheck/v2 v2.12.0 // indirect
|
||||||
github.com/tommy-muehle/go-mnd/v2 v2.5.1 // indirect
|
github.com/tommy-muehle/go-mnd/v2 v2.5.1 // indirect
|
||||||
|
|
@ -271,8 +278,8 @@ require (
|
||||||
github.com/ultraware/funlen v0.2.0 // indirect
|
github.com/ultraware/funlen v0.2.0 // indirect
|
||||||
github.com/ultraware/whitespace v0.2.0 // indirect
|
github.com/ultraware/whitespace v0.2.0 // indirect
|
||||||
github.com/urfave/cli/v2 v2.3.0 // indirect
|
github.com/urfave/cli/v2 v2.3.0 // indirect
|
||||||
github.com/uudashr/gocognit v1.2.0 // indirect
|
github.com/uudashr/gocognit v1.2.1 // indirect
|
||||||
github.com/uudashr/iface v1.4.1 // indirect
|
github.com/uudashr/iface v1.5.0 // indirect
|
||||||
github.com/xen0n/gosmopolitan v1.3.0 // indirect
|
github.com/xen0n/gosmopolitan v1.3.0 // indirect
|
||||||
github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
|
github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
|
||||||
github.com/yagipy/maintidx v1.0.0 // indirect
|
github.com/yagipy/maintidx v1.0.0 // indirect
|
||||||
|
|
@ -280,9 +287,9 @@ require (
|
||||||
github.com/ykadowak/zerologlint v0.1.5 // indirect
|
github.com/ykadowak/zerologlint v0.1.5 // indirect
|
||||||
gitlab.com/bosi/decorder v0.4.2 // indirect
|
gitlab.com/bosi/decorder v0.4.2 // indirect
|
||||||
go-simpler.org/musttag v0.14.0 // indirect
|
go-simpler.org/musttag v0.14.0 // indirect
|
||||||
go-simpler.org/sloglint v0.11.1 // indirect
|
go-simpler.org/sloglint v0.12.0 // indirect
|
||||||
go.augendre.info/arangolint v0.4.0 // indirect
|
go.augendre.info/arangolint v0.4.0 // indirect
|
||||||
go.augendre.info/fatcontext v0.9.0 // indirect
|
go.augendre.info/fatcontext v0.10.0 // indirect
|
||||||
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
|
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
|
||||||
go.opentelemetry.io/otel v1.44.0 // indirect
|
go.opentelemetry.io/otel v1.44.0 // indirect
|
||||||
go.opentelemetry.io/otel/metric v1.44.0 // indirect
|
go.opentelemetry.io/otel/metric v1.44.0 // indirect
|
||||||
|
|
@ -292,28 +299,28 @@ require (
|
||||||
go.uber.org/multierr v1.11.0 // indirect
|
go.uber.org/multierr v1.11.0 // indirect
|
||||||
go.uber.org/zap v1.27.1 // indirect
|
go.uber.org/zap v1.27.1 // indirect
|
||||||
go.yaml.in/yaml/v2 v2.4.4 // indirect
|
go.yaml.in/yaml/v2 v2.4.4 // indirect
|
||||||
go.yaml.in/yaml/v3 v3.0.4 // indirect
|
go.yaml.in/yaml/v3 v3.0.5 // indirect
|
||||||
golang.org/x/crypto v0.53.0 // indirect
|
golang.org/x/crypto v0.55.0 // indirect
|
||||||
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa // indirect
|
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa // indirect
|
||||||
golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 // indirect
|
golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f // indirect
|
||||||
golang.org/x/mod v0.37.0 // indirect
|
golang.org/x/mod v0.40.0 // indirect
|
||||||
golang.org/x/net v0.56.0 // indirect
|
golang.org/x/net v0.58.0 // indirect
|
||||||
golang.org/x/oauth2 v0.36.0 // indirect
|
golang.org/x/oauth2 v0.36.0 // indirect
|
||||||
golang.org/x/sys v0.47.0 // indirect
|
golang.org/x/sys v0.47.0 // indirect
|
||||||
golang.org/x/text v0.38.0 // indirect
|
golang.org/x/text v0.41.0 // indirect
|
||||||
golang.org/x/tools v0.47.0 // indirect
|
golang.org/x/tools v0.49.0 // indirect
|
||||||
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
|
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
|
||||||
google.golang.org/api v0.272.0 // indirect
|
google.golang.org/api v0.288.0 // indirect
|
||||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478 // indirect
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 // indirect
|
||||||
google.golang.org/grpc v1.82.1 // indirect
|
google.golang.org/grpc v1.82.1 // indirect
|
||||||
gopkg.in/ini.v1 v1.67.0 // indirect
|
gopkg.in/ini.v1 v1.67.0 // indirect
|
||||||
gopkg.in/yaml.v2 v2.4.0 // indirect
|
gopkg.in/yaml.v2 v2.4.0 // indirect
|
||||||
honnef.co/go/tools v0.7.0 // indirect
|
honnef.co/go/tools v0.8.0 // indirect
|
||||||
modernc.org/libc v1.74.1 // indirect
|
modernc.org/libc v1.74.4 // indirect
|
||||||
modernc.org/mathutil v1.7.1 // indirect
|
modernc.org/mathutil v1.7.1 // indirect
|
||||||
modernc.org/memory v1.11.0 // indirect
|
modernc.org/memory v1.11.0 // indirect
|
||||||
mvdan.cc/gofumpt v0.9.2 // indirect
|
mvdan.cc/gofumpt v0.11.0 // indirect
|
||||||
mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 // indirect
|
mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 // indirect
|
||||||
sigs.k8s.io/yaml v1.6.0 // indirect
|
sigs.k8s.io/yaml v1.6.0 // indirect
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
|
||||||
442
go.sum
442
go.sum
|
|
@ -1,13 +1,15 @@
|
||||||
4d63.com/gocheckcompilerdirectives v1.3.0 h1:Ew5y5CtcAAQeTVKUVFrE7EwHMrTO6BggtEj8BZSjZ3A=
|
4d63.com/gocheckcompilerdirectives v1.4.0 h1:ZLq62rbGWVmQhiZ8kuNVIT/M09xCSTdJz9K3xOdT/CY=
|
||||||
4d63.com/gocheckcompilerdirectives v1.3.0/go.mod h1:ofsJ4zx2QAuIP/NO/NAh1ig6R1Fb18/GI7RVMwz7kAY=
|
4d63.com/gocheckcompilerdirectives v1.4.0/go.mod h1:9ZOAiMOjqC/nRwci2fcUXVHUNLG/cH6r6rhUh+jTFtQ=
|
||||||
4d63.com/gochecknoglobals v0.2.2 h1:H1vdnwnMaZdQW/N+NrkT1SZMTBmcwHe9Vq8lJcYYTtU=
|
4d63.com/gochecknoglobals v0.2.2 h1:H1vdnwnMaZdQW/N+NrkT1SZMTBmcwHe9Vq8lJcYYTtU=
|
||||||
4d63.com/gochecknoglobals v0.2.2/go.mod h1:lLxwTQjL5eIesRbvnzIP3jZtG140FnTdz+AlMa+ogt0=
|
4d63.com/gochecknoglobals v0.2.2/go.mod h1:lLxwTQjL5eIesRbvnzIP3jZtG140FnTdz+AlMa+ogt0=
|
||||||
cel.dev/expr v0.25.1 h1:1KrZg61W6TWSxuNZ37Xy49ps13NUovb66QLprthtwi4=
|
cel.dev/expr v0.25.1 h1:1KrZg61W6TWSxuNZ37Xy49ps13NUovb66QLprthtwi4=
|
||||||
cel.dev/expr v0.25.1/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4=
|
cel.dev/expr v0.25.1/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4=
|
||||||
|
charm.land/lipgloss/v2 v2.0.6 h1:EaGKeuA8FvF+v2BT5VmZd2LoYLaMZJXA5n34th8nCIQ=
|
||||||
|
charm.land/lipgloss/v2 v2.0.6/go.mod h1:ipDDJNSGa1hlwDtSfW1s2/xR8Vdhbut4PXh2zEKZd0Q=
|
||||||
cloud.google.com/go v0.123.0 h1:2NAUJwPR47q+E35uaJeYoNhuNEM9kM8SjgRgdeOJUSE=
|
cloud.google.com/go v0.123.0 h1:2NAUJwPR47q+E35uaJeYoNhuNEM9kM8SjgRgdeOJUSE=
|
||||||
cloud.google.com/go v0.123.0/go.mod h1:xBoMV08QcqUGuPW65Qfm1o9Y4zKZBpGS+7bImXLTAZU=
|
cloud.google.com/go v0.123.0/go.mod h1:xBoMV08QcqUGuPW65Qfm1o9Y4zKZBpGS+7bImXLTAZU=
|
||||||
cloud.google.com/go/auth v0.18.2 h1:+Nbt5Ev0xEqxlNjd6c+yYUeosQ5TtEUaNcN/3FozlaM=
|
cloud.google.com/go/auth v0.21.0 h1:g/QwYfYb2Ai6HH8oomAOyBaIHLbscZ4+T/F/f5JZHkE=
|
||||||
cloud.google.com/go/auth v0.18.2/go.mod h1:xD+oY7gcahcu7G2SG2DsBerfFxgPAJz17zz2joOFF3M=
|
cloud.google.com/go/auth v0.21.0/go.mod h1:M9o2Oz+YI2jAfxewJgb1vyI3vceHF+eohmxyzmrl+9s=
|
||||||
cloud.google.com/go/auth/oauth2adapt v0.2.8 h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc=
|
cloud.google.com/go/auth/oauth2adapt v0.2.8 h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc=
|
||||||
cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c=
|
cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c=
|
||||||
cloud.google.com/go/compute/metadata v0.9.0 h1:pDUj4QMoPejqq20dK0Pg2N4yG9zIkYGdBtwLoEkH9Zs=
|
cloud.google.com/go/compute/metadata v0.9.0 h1:pDUj4QMoPejqq20dK0Pg2N4yG9zIkYGdBtwLoEkH9Zs=
|
||||||
|
|
@ -24,23 +26,25 @@ codeberg.org/polyfloyd/go-errorlint v1.9.0 h1:VkdEEmA1VBpH6ecQoMR4LdphVI3fA4RrCh
|
||||||
codeberg.org/polyfloyd/go-errorlint v1.9.0/go.mod h1:GPRRu2LzVijNn4YkrZYJfatQIdS+TrcK8rL5Xs24qw8=
|
codeberg.org/polyfloyd/go-errorlint v1.9.0/go.mod h1:GPRRu2LzVijNn4YkrZYJfatQIdS+TrcK8rL5Xs24qw8=
|
||||||
dev.gaijin.team/go/exhaustruct/v4 v4.0.0 h1:873r7aNneqoBB3IaFIzhvt2RFYTuHgmMjoKfwODoI1Y=
|
dev.gaijin.team/go/exhaustruct/v4 v4.0.0 h1:873r7aNneqoBB3IaFIzhvt2RFYTuHgmMjoKfwODoI1Y=
|
||||||
dev.gaijin.team/go/exhaustruct/v4 v4.0.0/go.mod h1:aZ/k2o4Y05aMJtiux15x8iXaumE88YdiB0Ai4fXOzPI=
|
dev.gaijin.team/go/exhaustruct/v4 v4.0.0/go.mod h1:aZ/k2o4Y05aMJtiux15x8iXaumE88YdiB0Ai4fXOzPI=
|
||||||
dev.gaijin.team/go/golib v0.6.0 h1:v6nnznFTs4bppib/NyU1PQxobwDHwCXXl15P7DV5Zgo=
|
dev.gaijin.team/go/exhaustruct/v5 v5.0.3 h1:yOeA7DNjlT8y4yfmN6nWWYYggA13N523YAj9/TXbuTM=
|
||||||
dev.gaijin.team/go/golib v0.6.0/go.mod h1:uY1mShx8Z/aNHWDyAkZTkX+uCi5PdX7KsG1eDQa2AVE=
|
dev.gaijin.team/go/exhaustruct/v5 v5.0.3/go.mod h1:KwtBsX8nHHH1YxhxkpiBq6bfsmw5WnazWpNvJPHgY9Y=
|
||||||
|
dev.gaijin.team/go/golib v0.8.1 h1:JYju4x9BSo+QD/AYeHULVDcvEhiFg8wOi6pT0IaZF5E=
|
||||||
|
dev.gaijin.team/go/golib v0.8.1/go.mod h1:c5fu7t1RSGMxSQgcUYO1sODbzsYnOCXJLmHeNG1Eb+0=
|
||||||
filippo.io/edwards25519 v1.1.0/go.mod h1:BxyFTGdWcka3PhytdK4V28tE5sGfRvvvRV7EaN4VDT4=
|
filippo.io/edwards25519 v1.1.0/go.mod h1:BxyFTGdWcka3PhytdK4V28tE5sGfRvvvRV7EaN4VDT4=
|
||||||
filippo.io/edwards25519 v1.2.0 h1:crnVqOiS4jqYleHd9vaKZ+HKtHfllngJIiOpNpoJsjo=
|
filippo.io/edwards25519 v1.2.0 h1:crnVqOiS4jqYleHd9vaKZ+HKtHfllngJIiOpNpoJsjo=
|
||||||
filippo.io/edwards25519 v1.2.0/go.mod h1:xzAOLCNug/yB62zG1bQ8uziwrIqIuxhctzJT18Q77mc=
|
filippo.io/edwards25519 v1.2.0/go.mod h1:xzAOLCNug/yB62zG1bQ8uziwrIqIuxhctzJT18Q77mc=
|
||||||
github.com/4meepo/tagalign v1.4.3 h1:Bnu7jGWwbfpAie2vyl63Zup5KuRv21olsPIha53BJr8=
|
github.com/4meepo/tagalign v1.4.3 h1:Bnu7jGWwbfpAie2vyl63Zup5KuRv21olsPIha53BJr8=
|
||||||
github.com/4meepo/tagalign v1.4.3/go.mod h1:00WwRjiuSbrRJnSVeGWPLp2epS5Q/l4UEy0apLLS37c=
|
github.com/4meepo/tagalign v1.4.3/go.mod h1:00WwRjiuSbrRJnSVeGWPLp2epS5Q/l4UEy0apLLS37c=
|
||||||
github.com/Abirdcfly/dupword v0.1.7 h1:2j8sInznrje4I0CMisSL6ipEBkeJUJAmK1/lfoNGWrQ=
|
github.com/Abirdcfly/dupword v0.1.8 h1:SrhcUuGsROBuChFxHALRYzyyPODWn9zwghmzPvD9Cd8=
|
||||||
github.com/Abirdcfly/dupword v0.1.7/go.mod h1:K0DkBeOebJ4VyOICFdppB23Q0YMOgVafM0zYW0n9lF4=
|
github.com/Abirdcfly/dupword v0.1.8/go.mod h1:XZrhVnI7YGpsTiWZANSQaBJ4QpL/Tq5vIEdKJJAs9WI=
|
||||||
github.com/AdminBenni/iota-mixing v1.0.0 h1:Os6lpjG2dp/AE5fYBPAA1zfa2qMdCAWwPMCgpwKq7wo=
|
github.com/AdminBenni/iota-mixing v1.0.0 h1:Os6lpjG2dp/AE5fYBPAA1zfa2qMdCAWwPMCgpwKq7wo=
|
||||||
github.com/AdminBenni/iota-mixing v1.0.0/go.mod h1:i4+tpAaB+qMVIV9OK3m4/DAynOd5bQFaOu+2AhtBCNY=
|
github.com/AdminBenni/iota-mixing v1.0.0/go.mod h1:i4+tpAaB+qMVIV9OK3m4/DAynOd5bQFaOu+2AhtBCNY=
|
||||||
github.com/AlwxSin/noinlineerr v1.0.5 h1:RUjt63wk1AYWTXtVXbSqemlbVTb23JOSRiNsshj7TbY=
|
github.com/AlwxSin/noinlineerr v1.0.6 h1:KAvuxunTe9QxvqrFB7nZTdb/7Wzas4AvifslTnG0Ld8=
|
||||||
github.com/AlwxSin/noinlineerr v1.0.5/go.mod h1:+QgkkoYrMH7RHvcdxdlI7vYYEdgeoFOVjU9sUhw/rQc=
|
github.com/AlwxSin/noinlineerr v1.0.6/go.mod h1:+QgkkoYrMH7RHvcdxdlI7vYYEdgeoFOVjU9sUhw/rQc=
|
||||||
github.com/Antonboom/errname v1.1.1 h1:bllB7mlIbTVzO9jmSWVWLjxTEbGBVQ1Ff/ClQgtPw9Q=
|
github.com/Antonboom/errname v1.1.2 h1:dxwONZJua3VB8Xh/VaCjqAcqF645sWWv7xj26zy7tdQ=
|
||||||
github.com/Antonboom/errname v1.1.1/go.mod h1:gjhe24xoxXp0ScLtHzjiXp0Exi1RFLKJb0bVBtWKCWQ=
|
github.com/Antonboom/errname v1.1.2/go.mod h1:YeZIpgLMxT+SNkruGgYkLhzq/9vs3fsolTZegKaKDZI=
|
||||||
github.com/Antonboom/nilnil v1.1.1 h1:9Mdr6BYd8WHCDngQnNVV0b554xyisFioEKi30sksufQ=
|
github.com/Antonboom/nilnil v1.1.2 h1:aNlFuJhaEseXe4fHO3xbjXlSeEiQVYa2lEkWD2s2hAY=
|
||||||
github.com/Antonboom/nilnil v1.1.1/go.mod h1:yCyAmSw3doopbOWhJlVci+HuyNRuHJKIv6V2oYQa8II=
|
github.com/Antonboom/nilnil v1.1.2/go.mod h1:0ynwvphOLmAuMwTNDyBnDZmSwZoDpcFXmUHmzoHH2WA=
|
||||||
github.com/Antonboom/testifylint v1.6.4 h1:gs9fUEy+egzxkEbq9P4cpcMB6/G0DYdMeiFS87UiqmQ=
|
github.com/Antonboom/testifylint v1.6.4 h1:gs9fUEy+egzxkEbq9P4cpcMB6/G0DYdMeiFS87UiqmQ=
|
||||||
github.com/Antonboom/testifylint v1.6.4/go.mod h1:YO33FROXX2OoUfwjz8g+gUxQXio5i9qpVy7nXGbxDD4=
|
github.com/Antonboom/testifylint v1.6.4/go.mod h1:YO33FROXX2OoUfwjz8g+gUxQXio5i9qpVy7nXGbxDD4=
|
||||||
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 h1:fou+2+WFTib47nS+nz/ozhEBnvU96bKHy6LjRsY4E28=
|
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 h1:fou+2+WFTib47nS+nz/ozhEBnvU96bKHy6LjRsY4E28=
|
||||||
|
|
@ -62,6 +66,8 @@ github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0/go.mod h1:HKpQ
|
||||||
github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU=
|
github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU=
|
||||||
github.com/BurntSushi/toml v1.6.0 h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk=
|
github.com/BurntSushi/toml v1.6.0 h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk=
|
||||||
github.com/BurntSushi/toml v1.6.0/go.mod h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho=
|
github.com/BurntSushi/toml v1.6.0/go.mod h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho=
|
||||||
|
github.com/ClickHouse/clickhouse-go-linter v1.2.1 h1:zGEKIyd5YL08ieWG/LOUmlau2DxbxPVOfAeo+4Jz3ck=
|
||||||
|
github.com/ClickHouse/clickhouse-go-linter v1.2.1/go.mod h1:pLorS7ffPTfuUV9M0SJgfHA/h/WQPQUk2FWG9x74cQ4=
|
||||||
github.com/CycloneDX/cyclonedx-go v0.11.0 h1:GokP8FiRC+foiuwWhSSLpSD5H4hSWtGnR3wo7apkBFI=
|
github.com/CycloneDX/cyclonedx-go v0.11.0 h1:GokP8FiRC+foiuwWhSSLpSD5H4hSWtGnR3wo7apkBFI=
|
||||||
github.com/CycloneDX/cyclonedx-go v0.11.0/go.mod h1:vUvbCXQsEm48OI6oOlanxstwNByXjCZ2wuleUlwGEO8=
|
github.com/CycloneDX/cyclonedx-go v0.11.0/go.mod h1:vUvbCXQsEm48OI6oOlanxstwNByXjCZ2wuleUlwGEO8=
|
||||||
github.com/Djarvur/go-err113 v0.1.1 h1:eHfopDqXRwAi+YmCUas75ZE0+hoBHJ2GQNLYRSxao4g=
|
github.com/Djarvur/go-err113 v0.1.1 h1:eHfopDqXRwAi+YmCUas75ZE0+hoBHJ2GQNLYRSxao4g=
|
||||||
|
|
@ -74,10 +80,10 @@ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapp
|
||||||
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0/go.mod h1:Mf6O40IAyB9zR/1J8nGDDPirZQQPbYJni8Yisy7NTMc=
|
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0/go.mod h1:Mf6O40IAyB9zR/1J8nGDDPirZQQPbYJni8Yisy7NTMc=
|
||||||
github.com/KyleBanks/depth v1.2.1 h1:5h8fQADFrWtarTdtDudMmGsC7GPbOAu6RVB3ffsVFHc=
|
github.com/KyleBanks/depth v1.2.1 h1:5h8fQADFrWtarTdtDudMmGsC7GPbOAu6RVB3ffsVFHc=
|
||||||
github.com/KyleBanks/depth v1.2.1/go.mod h1:jzSb9d0L43HxTQfT+oSA1EEp2q+ne2uh6XgeJcm8brE=
|
github.com/KyleBanks/depth v1.2.1/go.mod h1:jzSb9d0L43HxTQfT+oSA1EEp2q+ne2uh6XgeJcm8brE=
|
||||||
github.com/Masterminds/semver/v3 v3.4.0 h1:Zog+i5UMtVoCU8oKka5P7i9q9HgrJeGzI9SA1Xbatp0=
|
github.com/Masterminds/semver/v3 v3.5.0 h1:kQceYJfbupGfZOKZQg0kou0DgAKhzDg2NZPAwZ/2OOE=
|
||||||
github.com/Masterminds/semver/v3 v3.4.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM=
|
github.com/Masterminds/semver/v3 v3.5.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM=
|
||||||
github.com/MirrexOne/unqueryvet v1.5.3 h1:LpT3rsH+IY3cQddWF9bg4C7jsbASdGnrOSofY8IPEiw=
|
github.com/MirrexOne/unqueryvet v1.5.4 h1:38QOxShO7JmMWT+eCdDMbcUgGCOeJphVkzzRgyLJgsQ=
|
||||||
github.com/MirrexOne/unqueryvet v1.5.3/go.mod h1:fs9Zq6eh1LRIhsDIsxf9PONVUjYdFHdtkHIgZdJnyPU=
|
github.com/MirrexOne/unqueryvet v1.5.4/go.mod h1:fs9Zq6eh1LRIhsDIsxf9PONVUjYdFHdtkHIgZdJnyPU=
|
||||||
github.com/OpenPeeDeeP/depguard/v2 v2.2.1 h1:vckeWVESWp6Qog7UZSARNqfu/cZqvki8zsuj3piCMx4=
|
github.com/OpenPeeDeeP/depguard/v2 v2.2.1 h1:vckeWVESWp6Qog7UZSARNqfu/cZqvki8zsuj3piCMx4=
|
||||||
github.com/OpenPeeDeeP/depguard/v2 v2.2.1/go.mod h1:q4DKzC4UcVaAvcfd41CZh0PWpGgzrVxUYBlgKNGquUo=
|
github.com/OpenPeeDeeP/depguard/v2 v2.2.1/go.mod h1:q4DKzC4UcVaAvcfd41CZh0PWpGgzrVxUYBlgKNGquUo=
|
||||||
github.com/PuerkitoBio/purell v1.1.1 h1:WEQqlqaGbrPkxLJWfBwQmfEAE1Z7ONdDLqrN38tNFfI=
|
github.com/PuerkitoBio/purell v1.1.1 h1:WEQqlqaGbrPkxLJWfBwQmfEAE1Z7ONdDLqrN38tNFfI=
|
||||||
|
|
@ -87,16 +93,16 @@ github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578/go.mod h1:uGdko
|
||||||
github.com/RaveNoX/go-jsoncommentstrip v1.0.0/go.mod h1:78ihd09MekBnJnxpICcwzCMzGrKSKYe4AqU6PDYYpjk=
|
github.com/RaveNoX/go-jsoncommentstrip v1.0.0/go.mod h1:78ihd09MekBnJnxpICcwzCMzGrKSKYe4AqU6PDYYpjk=
|
||||||
github.com/alecthomas/assert/v2 v2.11.0 h1:2Q9r3ki8+JYXvGsDyBXwH3LcJ+WK5D0gc5E8vS6K3D0=
|
github.com/alecthomas/assert/v2 v2.11.0 h1:2Q9r3ki8+JYXvGsDyBXwH3LcJ+WK5D0gc5E8vS6K3D0=
|
||||||
github.com/alecthomas/assert/v2 v2.11.0/go.mod h1:Bze95FyfUr7x34QZrjL+XP+0qgp/zg8yS+TtBj1WA3k=
|
github.com/alecthomas/assert/v2 v2.11.0/go.mod h1:Bze95FyfUr7x34QZrjL+XP+0qgp/zg8yS+TtBj1WA3k=
|
||||||
github.com/alecthomas/chroma/v2 v2.23.1 h1:nv2AVZdTyClGbVQkIzlDm/rnhk1E9bU9nXwmZ/Vk/iY=
|
github.com/alecthomas/chroma/v2 v2.27.0 h1:FodwmyOBgJULFYmDqibcp9pvfDLWdtPRh9v/r5BXYZs=
|
||||||
github.com/alecthomas/chroma/v2 v2.23.1/go.mod h1:NqVhfBR0lte5Ouh3DcthuUCTUpDC9cxBOfyMbMQPs3o=
|
github.com/alecthomas/chroma/v2 v2.27.0/go.mod h1:NjJ3ciIgrqBNeIkWZ4e46nseoLDslxU1LmfCoL+wcY8=
|
||||||
github.com/alecthomas/go-check-sumtype v0.3.1 h1:u9aUvbGINJxLVXiFvHUlPEaD7VDULsrxJb4Aq31NLkU=
|
github.com/alecthomas/go-check-sumtype v0.3.1 h1:u9aUvbGINJxLVXiFvHUlPEaD7VDULsrxJb4Aq31NLkU=
|
||||||
github.com/alecthomas/go-check-sumtype v0.3.1/go.mod h1:A8TSiN3UPRw3laIgWEUOHHLPa6/r9MtoigdlP5h3K/E=
|
github.com/alecthomas/go-check-sumtype v0.3.1/go.mod h1:A8TSiN3UPRw3laIgWEUOHHLPa6/r9MtoigdlP5h3K/E=
|
||||||
github.com/alecthomas/repr v0.5.2 h1:SU73FTI9D1P5UNtvseffFSGmdNci/O6RsqzeXJtP0Qs=
|
github.com/alecthomas/repr v0.5.2 h1:SU73FTI9D1P5UNtvseffFSGmdNci/O6RsqzeXJtP0Qs=
|
||||||
github.com/alecthomas/repr v0.5.2/go.mod h1:Fr0507jx4eOXV7AlPV6AVZLYrLIuIeSOWtW57eE/O/4=
|
github.com/alecthomas/repr v0.5.2/go.mod h1:Fr0507jx4eOXV7AlPV6AVZLYrLIuIeSOWtW57eE/O/4=
|
||||||
github.com/alexkohler/nakedret/v2 v2.0.6 h1:ME3Qef1/KIKr3kWX3nti3hhgNxw6aqN5pZmQiFSsuzQ=
|
github.com/alexkohler/nakedret/v2 v2.0.6 h1:ME3Qef1/KIKr3kWX3nti3hhgNxw6aqN5pZmQiFSsuzQ=
|
||||||
github.com/alexkohler/nakedret/v2 v2.0.6/go.mod h1:l3RKju/IzOMQHmsEvXwkqMDzHHvurNQfAgE1eVmT40Q=
|
github.com/alexkohler/nakedret/v2 v2.0.6/go.mod h1:l3RKju/IzOMQHmsEvXwkqMDzHHvurNQfAgE1eVmT40Q=
|
||||||
github.com/alexkohler/prealloc v1.0.2 h1:MPo8cIkGkZytq7WNH9UHv3DIX1mPz1RatPXnZb0zHWQ=
|
github.com/alexkohler/prealloc v1.1.0 h1:cKGRBqlXw5iyQGLYhrXrDlcHxugXpTq4tQ5c91wkf8M=
|
||||||
github.com/alexkohler/prealloc v1.0.2/go.mod h1:fT39Jge3bQrfA7nPMDngUfvUbQGQeJyGQnR+913SCig=
|
github.com/alexkohler/prealloc v1.1.0/go.mod h1:fT39Jge3bQrfA7nPMDngUfvUbQGQeJyGQnR+913SCig=
|
||||||
github.com/alfatraining/structtag v1.0.0 h1:2qmcUqNcCoyVJ0up879K614L9PazjBSFruTB0GOFjCc=
|
github.com/alfatraining/structtag v1.0.0 h1:2qmcUqNcCoyVJ0up879K614L9PazjBSFruTB0GOFjCc=
|
||||||
github.com/alfatraining/structtag v1.0.0/go.mod h1:p3Xi5SwzTi+Ryj64DqjLWz7XurHxbGsq6y3ubePJPus=
|
github.com/alfatraining/structtag v1.0.0/go.mod h1:p3Xi5SwzTi+Ryj64DqjLWz7XurHxbGsq6y3ubePJPus=
|
||||||
github.com/alingse/asasalint v0.0.11 h1:SFwnQXJ49Kx/1GghOFz1XGqHYKp21Kq1nHad/0WQRnw=
|
github.com/alingse/asasalint v0.0.11 h1:SFwnQXJ49Kx/1GghOFz1XGqHYKp21Kq1nHad/0WQRnw=
|
||||||
|
|
@ -107,10 +113,10 @@ github.com/anchore/go-struct-converter v0.1.0 h1:2rDRssAl6mgKBSLNiVCMADgZRhoqtw9
|
||||||
github.com/anchore/go-struct-converter v0.1.0/go.mod h1:rYqSE9HbjzpHTI74vwPvae4ZVYZd1lue2ta6xHPdblA=
|
github.com/anchore/go-struct-converter v0.1.0/go.mod h1:rYqSE9HbjzpHTI74vwPvae4ZVYZd1lue2ta6xHPdblA=
|
||||||
github.com/apapsch/go-jsonmerge/v2 v2.0.0 h1:axGnT1gRIfimI7gJifB699GoE/oq+F2MU7Dml6nw9rQ=
|
github.com/apapsch/go-jsonmerge/v2 v2.0.0 h1:axGnT1gRIfimI7gJifB699GoE/oq+F2MU7Dml6nw9rQ=
|
||||||
github.com/apapsch/go-jsonmerge/v2 v2.0.0/go.mod h1:lvDnEdqiQrp0O42VQGgmlKpxL1AP2+08jFMw88y4klk=
|
github.com/apapsch/go-jsonmerge/v2 v2.0.0/go.mod h1:lvDnEdqiQrp0O42VQGgmlKpxL1AP2+08jFMw88y4klk=
|
||||||
github.com/ashanbrown/forbidigo/v2 v2.3.0 h1:OZZDOchCgsX5gvToVtEBoV2UWbFfI6RKQTir2UZzSxo=
|
github.com/ashanbrown/forbidigo/v2 v2.3.1 h1:KAZijvQ7zeIBKbhikT4jCm0TLYXC4u78bTiLh/8JROI=
|
||||||
github.com/ashanbrown/forbidigo/v2 v2.3.0/go.mod h1:5p6VmsG5/1xx3E785W9fouMxIOkvY2rRV9nMdWadd6c=
|
github.com/ashanbrown/forbidigo/v2 v2.3.1/go.mod h1:2QDkLTzU6TV937eFROamXrW92M3paehdae4HCDCOZCM=
|
||||||
github.com/ashanbrown/makezero/v2 v2.1.0 h1:snuKYMbqosNokUKm+R6/+vOPs8yVAi46La7Ck6QYSaE=
|
github.com/ashanbrown/makezero/v2 v2.2.1 h1:A7uU8dgB1PA9aelTxHMfHIQ8Qev8AB3JLxJUBUsejqM=
|
||||||
github.com/ashanbrown/makezero/v2 v2.1.0/go.mod h1:aEGT/9q3S8DHeE57C88z2a6xydvgx8J5hgXIGWgo0MY=
|
github.com/ashanbrown/makezero/v2 v2.2.1/go.mod h1:aEGT/9q3S8DHeE57C88z2a6xydvgx8J5hgXIGWgo0MY=
|
||||||
github.com/aws/aws-sdk-go-v2 v1.41.9 h1:/rYeyO2+HrMztAmxAq9++XJtFMqSIpSsNA0yDGALYq4=
|
github.com/aws/aws-sdk-go-v2 v1.41.9 h1:/rYeyO2+HrMztAmxAq9++XJtFMqSIpSsNA0yDGALYq4=
|
||||||
github.com/aws/aws-sdk-go-v2 v1.41.9/go.mod h1:+HsoOEX80qAVUitj1A2DhCNTjmb3edVyuDypb6LNEeo=
|
github.com/aws/aws-sdk-go-v2 v1.41.9/go.mod h1:+HsoOEX80qAVUitj1A2DhCNTjmb3edVyuDypb6LNEeo=
|
||||||
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 h1:h5+3VT69KUBK24grGuuA5saDJTj2IIjLb9au668Fo5I=
|
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.11 h1:h5+3VT69KUBK24grGuuA5saDJTj2IIjLb9au668Fo5I=
|
||||||
|
|
@ -149,8 +155,6 @@ github.com/aws/aws-sdk-go-v2/service/sts v1.42.3 h1:ErklX/7uhSbkAAeyQD/Y1OoQ9hO3
|
||||||
github.com/aws/aws-sdk-go-v2/service/sts v1.42.3/go.mod h1:ULe4HCzfKPiR6R3HEurE3b1upEkuk8AkMrOKtaOxKO8=
|
github.com/aws/aws-sdk-go-v2/service/sts v1.42.3/go.mod h1:ULe4HCzfKPiR6R3HEurE3b1upEkuk8AkMrOKtaOxKO8=
|
||||||
github.com/aws/smithy-go v1.26.0 h1:9ouqbi+NyKP7fV3Te7UElCwdAb6Y8uk7LGwPE5tVe/s=
|
github.com/aws/smithy-go v1.26.0 h1:9ouqbi+NyKP7fV3Te7UElCwdAb6Y8uk7LGwPE5tVe/s=
|
||||||
github.com/aws/smithy-go v1.26.0/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
|
github.com/aws/smithy-go v1.26.0/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
|
||||||
github.com/aymanbagabas/go-osc52/v2 v2.0.1 h1:HwpRHbFMcZLEVr42D4p7XBqjyuxQH5SMiErDT4WkJ2k=
|
|
||||||
github.com/aymanbagabas/go-osc52/v2 v2.0.1/go.mod h1:uYgXzlJ7ZpABp8OJ+exZzJJhRNQ2ASbcXHWsFqH8hp8=
|
|
||||||
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
|
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
|
||||||
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
|
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
|
||||||
github.com/bkielbasa/cyclop v1.2.3 h1:faIVMIGDIANuGPWH031CZJTi2ymOQBULs9H21HSMa5w=
|
github.com/bkielbasa/cyclop v1.2.3 h1:faIVMIGDIANuGPWH031CZJTi2ymOQBULs9H21HSMa5w=
|
||||||
|
|
@ -160,18 +164,18 @@ github.com/blizzy78/varnamelen v0.8.0/go.mod h1:V9TzQZ4fLJ1DSrjVDfl89H7aMnTvKkAp
|
||||||
github.com/bmatcuk/doublestar v1.1.1/go.mod h1:UD6OnuiIn0yFxxA2le/rnRU1G4RaI4UvFv1sNto9p6w=
|
github.com/bmatcuk/doublestar v1.1.1/go.mod h1:UD6OnuiIn0yFxxA2le/rnRU1G4RaI4UvFv1sNto9p6w=
|
||||||
github.com/bombsimon/wsl/v4 v4.7.0 h1:1Ilm9JBPRczjyUs6hvOPKvd7VL1Q++PL8M0SXBDf+jQ=
|
github.com/bombsimon/wsl/v4 v4.7.0 h1:1Ilm9JBPRczjyUs6hvOPKvd7VL1Q++PL8M0SXBDf+jQ=
|
||||||
github.com/bombsimon/wsl/v4 v4.7.0/go.mod h1:uV/+6BkffuzSAVYD+yGyld1AChO7/EuLrCF/8xTiapg=
|
github.com/bombsimon/wsl/v4 v4.7.0/go.mod h1:uV/+6BkffuzSAVYD+yGyld1AChO7/EuLrCF/8xTiapg=
|
||||||
github.com/bombsimon/wsl/v5 v5.6.0 h1:4z+/sBqC5vUmSp1O0mS+czxwH9+LKXtCWtHH9rZGQL8=
|
github.com/bombsimon/wsl/v5 v5.9.0 h1:WCrgZ7RQnZO5oEwbVTlYgBdU3wL294kR1BSWV8vTfsU=
|
||||||
github.com/bombsimon/wsl/v5 v5.6.0/go.mod h1:Uqt2EfrMj2NV8UGoN1f1Y3m0NpUVCsUdrNCdet+8LvU=
|
github.com/bombsimon/wsl/v5 v5.9.0/go.mod h1:kjo4HiAV5FDkHC8/uzJq9mBffEEd6WT/nvN7DoMovDM=
|
||||||
github.com/bradleyjkemp/cupaloy/v2 v2.8.0 h1:any4BmKE+jGIaMpnU8YgH/I2LPiLBufr6oMMlVBbn9M=
|
github.com/bradleyjkemp/cupaloy/v2 v2.8.0 h1:any4BmKE+jGIaMpnU8YgH/I2LPiLBufr6oMMlVBbn9M=
|
||||||
github.com/bradleyjkemp/cupaloy/v2 v2.8.0/go.mod h1:bm7JXdkRd4BHJk9HpwqAI8BoAY1lps46Enkdqw6aRX0=
|
github.com/bradleyjkemp/cupaloy/v2 v2.8.0/go.mod h1:bm7JXdkRd4BHJk9HpwqAI8BoAY1lps46Enkdqw6aRX0=
|
||||||
github.com/breml/bidichk v0.3.3 h1:WSM67ztRusf1sMoqH6/c4OBCUlRVTKq+CbSeo0R17sE=
|
github.com/breml/bidichk v0.3.3 h1:WSM67ztRusf1sMoqH6/c4OBCUlRVTKq+CbSeo0R17sE=
|
||||||
github.com/breml/bidichk v0.3.3/go.mod h1:ISbsut8OnjB367j5NseXEGGgO/th206dVa427kR8YTE=
|
github.com/breml/bidichk v0.3.3/go.mod h1:ISbsut8OnjB367j5NseXEGGgO/th206dVa427kR8YTE=
|
||||||
github.com/breml/errchkjson v0.4.1 h1:keFSS8D7A2T0haP9kzZTi7o26r7kE3vymjZNeNDRDwg=
|
github.com/breml/errchkjson v0.4.1 h1:keFSS8D7A2T0haP9kzZTi7o26r7kE3vymjZNeNDRDwg=
|
||||||
github.com/breml/errchkjson v0.4.1/go.mod h1:a23OvR6Qvcl7DG/Z4o0el6BRAjKnaReoPQFciAl9U3s=
|
github.com/breml/errchkjson v0.4.1/go.mod h1:a23OvR6Qvcl7DG/Z4o0el6BRAjKnaReoPQFciAl9U3s=
|
||||||
github.com/butuzov/ireturn v0.4.0 h1:+s76bF/PfeKEdbG8b54aCocxXmi0wvYdOVsWxVO7n8E=
|
github.com/butuzov/ireturn v0.4.1 h1:vWb3NO4t77iku/sjCQ/2pHTQeOmxEhjIriJqRLg1Y+I=
|
||||||
github.com/butuzov/ireturn v0.4.0/go.mod h1:ghI0FrCmap8pDWZwfPisFD1vEc56VKH4NpQUxDHta70=
|
github.com/butuzov/ireturn v0.4.1/go.mod h1:q+DXKzTDV5guNuXLnIab9fKXizTn2miZHLhxH7V/GB4=
|
||||||
github.com/butuzov/mirror v1.3.0 h1:HdWCXzmwlQHdVhwvsfBb2Au0r3HyINry3bDWLYXiKoc=
|
github.com/butuzov/mirror v1.3.3 h1:v0RsWBhfFc1RQqE/f3sHpSttKDtodFn0gFmtYyD4/hA=
|
||||||
github.com/butuzov/mirror v1.3.0/go.mod h1:AEij0Z8YMALaq4yQj9CPPVYOyJQyiexpQEQgihajRfI=
|
github.com/butuzov/mirror v1.3.3/go.mod h1:h9BzzwYnTiHO0GzgvaTqIg7VSsOUhdIv51cHFFBmX1w=
|
||||||
github.com/catenacyber/perfsprint v0.10.1 h1:u7Riei30bk46XsG8nknMhKLXG9BcXz3+3tl/WpKm0PQ=
|
github.com/catenacyber/perfsprint v0.10.1 h1:u7Riei30bk46XsG8nknMhKLXG9BcXz3+3tl/WpKm0PQ=
|
||||||
github.com/catenacyber/perfsprint v0.10.1/go.mod h1:DJTGsi/Zufpuus6XPGJyKOTMELe347o6akPvWG9Zcsc=
|
github.com/catenacyber/perfsprint v0.10.1/go.mod h1:DJTGsi/Zufpuus6XPGJyKOTMELe347o6akPvWG9Zcsc=
|
||||||
github.com/ccojocar/zxcvbn-go v1.0.4 h1:FWnCIRMXPj43ukfX000kvBZvV6raSxakYr1nzyNrUcc=
|
github.com/ccojocar/zxcvbn-go v1.0.4 h1:FWnCIRMXPj43ukfX000kvBZvV6raSxakYr1nzyNrUcc=
|
||||||
|
|
@ -182,18 +186,24 @@ github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UF
|
||||||
github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
|
github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
|
||||||
github.com/charithe/durationcheck v0.0.11 h1:g1/EX1eIiKS57NTWsYtHDZ/APfeXKhye1DidBcABctk=
|
github.com/charithe/durationcheck v0.0.11 h1:g1/EX1eIiKS57NTWsYtHDZ/APfeXKhye1DidBcABctk=
|
||||||
github.com/charithe/durationcheck v0.0.11/go.mod h1:x5iZaixRNl8ctbM+3B2RrPG5t856TxRyVQEnbIEM2X4=
|
github.com/charithe/durationcheck v0.0.11/go.mod h1:x5iZaixRNl8ctbM+3B2RrPG5t856TxRyVQEnbIEM2X4=
|
||||||
github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc h1:4pZI35227imm7yK2bGPcfpFEmuY1gc2YSTShr4iJBfs=
|
github.com/charmbracelet/colorprofile v0.4.3 h1:QPa1IWkYI+AOB+fE+mg/5/4HRMZcaXex9t5KX76i20Q=
|
||||||
github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc/go.mod h1:X4/0JoqgTIPSFcRA/P6INZzIuyqdFY5rm8tb41s9okk=
|
github.com/charmbracelet/colorprofile v0.4.3/go.mod h1:/zT4BhpD5aGFpqQQqw7a+VtHCzu+zrQtt1zhMt9mR4Q=
|
||||||
github.com/charmbracelet/lipgloss v1.1.0 h1:vYXsiLHVkK7fp74RkV7b2kq9+zDLoEU4MZoFqR/noCY=
|
github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886 h1:rdnVWKgJpTVXKuKuJyxDJ+NFJdUaUqGvyGy61OcvlbA=
|
||||||
github.com/charmbracelet/lipgloss v1.1.0/go.mod h1:/6Q8FR2o+kj8rz4Dq0zQc3vYf7X+B0binUUBwA0aL30=
|
github.com/charmbracelet/ultraviolet v0.0.0-20260811164956-006e29f97886/go.mod h1:nAw0d9PhFp1qdzi2xhQU5YOu5sVpDIHWlaW2Uz/bCro=
|
||||||
github.com/charmbracelet/x/ansi v0.10.1 h1:rL3Koar5XvX0pHGfovN03f5cxLbCF2YvLeyz7D2jVDQ=
|
github.com/charmbracelet/x/ansi v0.11.8 h1:JMFwp0CgDC2+jcOB162HH5k7I3FVbgFSMMYg7dSPBQQ=
|
||||||
github.com/charmbracelet/x/ansi v0.10.1/go.mod h1:3RQDQ6lDnROptfpWuUVIUG64bD2g2BgntdxH0Ya5TeE=
|
github.com/charmbracelet/x/ansi v0.11.8/go.mod h1:ZNN+3mXny/516oTQPLMPIBeSINvNJJQ8uQXDgbeJxY0=
|
||||||
github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd h1:vy0GVL4jeHEwG5YOXDmi86oYw2yuYUGqz6a8sLwg0X8=
|
github.com/charmbracelet/x/term v0.2.2 h1:xVRT/S2ZcKdhhOuSP4t5cLi5o+JxklsoEObBSgfgZRk=
|
||||||
github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd/go.mod h1:xe0nKWGd3eJgtqZRaN9RjMtK7xUYchjzPr7q6kcvCCs=
|
github.com/charmbracelet/x/term v0.2.2/go.mod h1:kF8CY5RddLWrsgVwpw4kAa6TESp6EB5y3uxGLeCqzAI=
|
||||||
github.com/charmbracelet/x/term v0.2.1 h1:AQeHeLZ1OqSXhrAWpYUtZyX1T3zVxfpZuEQMIQaGIAQ=
|
github.com/charmbracelet/x/termios v0.1.1 h1:o3Q2bT8eqzGnGPOYheoYS8eEleT5ZVNYNy8JawjaNZY=
|
||||||
github.com/charmbracelet/x/term v0.2.1/go.mod h1:oQ4enTYFV7QN4m0i9mzHrViD7TQKvNEEkHUMCmsxdUg=
|
github.com/charmbracelet/x/termios v0.1.1/go.mod h1:rB7fnv1TgOPOyyKRJ9o+AsTU/vK5WHJ2ivHeut/Pcwo=
|
||||||
|
github.com/charmbracelet/x/windows v0.2.2 h1:IofanmuvaxnKHuV04sC0eBy/smG6kIKrWG2/jYn2GuM=
|
||||||
|
github.com/charmbracelet/x/windows v0.2.2/go.mod h1:/8XtdKZzedat74NQFn0NGlGL4soHB0YQZrETF96h75k=
|
||||||
github.com/ckaznocha/intrange v0.3.1 h1:j1onQyXvHUsPWujDH6WIjhyH26gkRt/txNlV7LspvJs=
|
github.com/ckaznocha/intrange v0.3.1 h1:j1onQyXvHUsPWujDH6WIjhyH26gkRt/txNlV7LspvJs=
|
||||||
github.com/ckaznocha/intrange v0.3.1/go.mod h1:QVepyz1AkUoFQkpEqksSYpNpUo3c5W7nWh/s6SHIJJk=
|
github.com/ckaznocha/intrange v0.3.1/go.mod h1:QVepyz1AkUoFQkpEqksSYpNpUo3c5W7nWh/s6SHIJJk=
|
||||||
|
github.com/clipperhouse/displaywidth v0.11.0 h1:lBc6kY44VFw+TDx4I8opi/EtL9m20WSEFgwIwO+UVM8=
|
||||||
|
github.com/clipperhouse/displaywidth v0.11.0/go.mod h1:bkrFNkf81G8HyVqmKGxsPufD3JhNl3dSqnGhOoSD/o0=
|
||||||
|
github.com/clipperhouse/uax29/v2 v2.7.0 h1:+gs4oBZ2gPfVrKPthwbMzWZDaAFPGYK72F0NJv2v7Vk=
|
||||||
|
github.com/clipperhouse/uax29/v2 v2.7.0/go.mod h1:EFJ2TJMRUaplDxHKj1qAEhCtQPW2tJSwu5BF98AuoVM=
|
||||||
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 h1:aBangftG7EVZoUb69Os8IaYg++6uMOdKK83QtkkvJik=
|
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 h1:aBangftG7EVZoUb69Os8IaYg++6uMOdKK83QtkkvJik=
|
||||||
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2/go.mod h1:qwXFYgsP6T7XnJtbKlf1HP8AjxZZyzxMmc+Lq5GjlU4=
|
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2/go.mod h1:qwXFYgsP6T7XnJtbKlf1HP8AjxZZyzxMmc+Lq5GjlU4=
|
||||||
github.com/cpuguy83/go-md2man/v2 v2.0.0-20190314233015-f79a8a8ca69d/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU=
|
github.com/cpuguy83/go-md2man/v2 v2.0.0-20190314233015-f79a8a8ca69d/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU=
|
||||||
|
|
@ -209,12 +219,15 @@ github.com/dave/dst v0.27.3/go.mod h1:jHh6EOibnHgcUW3WjKHisiooEkYwqpHLBSX1iOBhEy
|
||||||
github.com/dave/jennifer v1.7.1 h1:B4jJJDHelWcDhlRQxWeo0Npa/pYKBLrirAQoTN45txo=
|
github.com/dave/jennifer v1.7.1 h1:B4jJJDHelWcDhlRQxWeo0Npa/pYKBLrirAQoTN45txo=
|
||||||
github.com/dave/jennifer v1.7.1/go.mod h1:nXbxhEmQfOZhWml3D1cDK5M1FLnMSozpbFN/m3RmGZc=
|
github.com/dave/jennifer v1.7.1/go.mod h1:nXbxhEmQfOZhWml3D1cDK5M1FLnMSozpbFN/m3RmGZc=
|
||||||
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||||
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
|
||||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||||
|
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM=
|
||||||
|
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||||
github.com/denis-tingaikin/go-header v0.5.0 h1:SRdnP5ZKvcO9KKRP1KJrhFR3RrlGuD+42t4429eC9k8=
|
github.com/denis-tingaikin/go-header v0.5.0 h1:SRdnP5ZKvcO9KKRP1KJrhFR3RrlGuD+42t4429eC9k8=
|
||||||
github.com/denis-tingaikin/go-header v0.5.0/go.mod h1:mMenU5bWrok6Wl2UsZjy+1okegmwQ3UgWl4V1D8gjlY=
|
github.com/denis-tingaikin/go-header v0.5.0/go.mod h1:mMenU5bWrok6Wl2UsZjy+1okegmwQ3UgWl4V1D8gjlY=
|
||||||
github.com/dlclark/regexp2 v1.11.5 h1:Q/sSnsKerHeCkc/jSTNq1oCm7KiVgUMZRDUoRu0JQZQ=
|
github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz8=
|
||||||
github.com/dlclark/regexp2 v1.11.5/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
|
github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
|
||||||
|
github.com/dlclark/regexp2/v2 v2.2.1 h1:mf4KkFUj0gJuarK8P+LgiS+Lit7m9N1yAwEfPbee7R0=
|
||||||
|
github.com/dlclark/regexp2/v2 v2.2.1/go.mod h1:avUrQvPaLz2DrFNHJF0taWAFFX2C1GMSSoeiqFjcBmU=
|
||||||
github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY=
|
github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY=
|
||||||
github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto=
|
github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto=
|
||||||
github.com/ecosyste-ms/ecosystems-go v0.4.0 h1:5A+zF+XWT8sYYYjlc2/tI1SmiDGzbHLyT9CapVc5dGA=
|
github.com/ecosyste-ms/ecosystems-go v0.4.0 h1:5A+zF+XWT8sYYYjlc2/tI1SmiDGzbHLyT9CapVc5dGA=
|
||||||
|
|
@ -228,50 +241,52 @@ github.com/ettle/strcase v0.2.0 h1:fGNiVF21fHXpX1niBgk0aROov1LagYsOwV/xqKDKR/Q=
|
||||||
github.com/ettle/strcase v0.2.0/go.mod h1:DajmHElDSaX76ITe3/VHVyMin4LWSJN5Z909Wp+ED1A=
|
github.com/ettle/strcase v0.2.0/go.mod h1:DajmHElDSaX76ITe3/VHVyMin4LWSJN5Z909Wp+ED1A=
|
||||||
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a h1:yDWHCSQ40h88yih2JAcL6Ls/kVkSE8GFACTGVnMPruw=
|
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a h1:yDWHCSQ40h88yih2JAcL6Ls/kVkSE8GFACTGVnMPruw=
|
||||||
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a/go.mod h1:7Ga40egUymuWXxAe151lTNnCv97MddSOVsjpPPkityA=
|
github.com/facebookgo/clock v0.0.0-20150410010913-600d898af40a/go.mod h1:7Ga40egUymuWXxAe151lTNnCv97MddSOVsjpPPkityA=
|
||||||
github.com/fatih/color v1.18.0 h1:S8gINlzdQ840/4pfAwic/ZE0djQEH3wM94VfqLTZcOM=
|
github.com/fatih/color v1.19.0 h1:Zp3PiM21/9Ld6FzSKyL5c/BULoe/ONr9KlbYVOfG8+w=
|
||||||
github.com/fatih/color v1.18.0/go.mod h1:4FelSpRwEGDpQ12mAdzqdOukCy4u8WUtOY6lkT/6HfU=
|
github.com/fatih/color v1.19.0/go.mod h1:zNk67I0ZUT1bEGsSGyCZYZNrHuTkJJB+r6Q9VuMi0LE=
|
||||||
github.com/fatih/structtag v1.2.0 h1:/OdNE99OxoI/PqaW/SuSK9uxxT3f/tcSZgon/ssNSx4=
|
github.com/fatih/structtag v1.2.0 h1:/OdNE99OxoI/PqaW/SuSK9uxxT3f/tcSZgon/ssNSx4=
|
||||||
github.com/fatih/structtag v1.2.0/go.mod h1:mBJUNpUnHmRKrKlQQlmCrh5PuhftFbNv8Ys4/aAZl94=
|
github.com/fatih/structtag v1.2.0/go.mod h1:mBJUNpUnHmRKrKlQQlmCrh5PuhftFbNv8Ys4/aAZl94=
|
||||||
github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg=
|
github.com/felixge/httpsnoop v1.1.0 h1:3YtUj32ZZkqZtt3sZZsClsymw/QDuVfpNhoA31zeORc=
|
||||||
github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U=
|
github.com/felixge/httpsnoop v1.1.0/go.mod h1:Zqxgdd+1Rkcz8euOqdr7lqgCRJztwr5hp9vDSi5UZCE=
|
||||||
github.com/firefart/nonamedreturns v1.0.6 h1:vmiBcKV/3EqKY3ZiPxCINmpS431OcE1S47AQUwhrg8E=
|
github.com/firefart/nonamedreturns v1.0.8 h1:iB32Dl17zJl1zlVEj/WlUWgx0HiRyQ85OUw1WHa4/II=
|
||||||
github.com/firefart/nonamedreturns v1.0.6/go.mod h1:R8NisJnSIpvPWheCq0mNRXJok6D8h7fagJTF8EMEwCo=
|
github.com/firefart/nonamedreturns v1.0.8/go.mod h1:vxFNvm5AfP/8rgAKFzYmnqx0yp1HjrYsErZ9pHPTznA=
|
||||||
github.com/frankban/quicktest v1.14.3 h1:FJKSZTDHjyhriyC81FLQ0LY93eSai0ZyR/ZIkd3ZUKE=
|
github.com/frankban/quicktest v1.14.3 h1:FJKSZTDHjyhriyC81FLQ0LY93eSai0ZyR/ZIkd3ZUKE=
|
||||||
github.com/frankban/quicktest v1.14.3/go.mod h1:mgiwOwqx65TmIk1wJ6Q7wvnVMocbUorkibMOrVTHZps=
|
github.com/frankban/quicktest v1.14.3/go.mod h1:mgiwOwqx65TmIk1wJ6Q7wvnVMocbUorkibMOrVTHZps=
|
||||||
github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k=
|
github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k=
|
||||||
github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0=
|
github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0=
|
||||||
github.com/fzipp/gocyclo v0.6.0 h1:lsblElZG7d3ALtGMx9fmxeTKZaLLpU8mET09yN4BBLo=
|
github.com/fzipp/gocyclo v0.6.0 h1:lsblElZG7d3ALtGMx9fmxeTKZaLLpU8mET09yN4BBLo=
|
||||||
github.com/fzipp/gocyclo v0.6.0/go.mod h1:rXPyn8fnlpa0R2csP/31uerbiVBugk5whMdlyaLkLoA=
|
github.com/fzipp/gocyclo v0.6.0/go.mod h1:rXPyn8fnlpa0R2csP/31uerbiVBugk5whMdlyaLkLoA=
|
||||||
github.com/ghostiam/protogetter v0.3.20 h1:oW7OPFit2FxZOpmMRPP9FffU4uUpfeE/rEdE1f+MzD0=
|
github.com/ghostiam/protogetter v0.3.21 h1:EeWTGvL/Eyosp653hiWb6Byx4b69iJC4/E+za7vQHoI=
|
||||||
github.com/ghostiam/protogetter v0.3.20/go.mod h1:FjIu5Yfs6FT391m+Fjp3fbAYJ6rkL/J6ySpZBfnODuI=
|
github.com/ghostiam/protogetter v0.3.21/go.mod h1:iAKSpyoHwYzay+OpjoWgwzRtPFthEfuUvmlomTThck0=
|
||||||
github.com/git-pkgs/archives v0.4.0 h1:KNmmIsLiSH27lUdT27EfUkQXFaLgXV5KezE81iyOIgo=
|
github.com/git-pkgs/archives v0.5.1 h1:qwu/vsoerQZF1iysRtfcxpy1KIUSJJSpXJ5JNxzNoQw=
|
||||||
github.com/git-pkgs/archives v0.4.0/go.mod h1:tfio0OIuPKEBKHs/UCL5XBUvYmKpnvtnba2iDlfSd6g=
|
github.com/git-pkgs/archives v0.5.1/go.mod h1:AKpkxnts49R9uAt1mL2ULYcHrmYujCDVu24IsFvW9so=
|
||||||
github.com/git-pkgs/cooldown v0.1.1 h1:9OqqzCB8gANz/y44SmqGD0Jp8Qtu81D1sCbKl6Ehg7w=
|
github.com/git-pkgs/cooldown v0.1.1 h1:9OqqzCB8gANz/y44SmqGD0Jp8Qtu81D1sCbKl6Ehg7w=
|
||||||
github.com/git-pkgs/cooldown v0.1.1/go.mod h1:v7APuK/UouTiu8mWQZbdDmj7DfxxkGUeuhjaRB5gv9E=
|
github.com/git-pkgs/cooldown v0.1.1/go.mod h1:v7APuK/UouTiu8mWQZbdDmj7DfxxkGUeuhjaRB5gv9E=
|
||||||
github.com/git-pkgs/enrichment v0.6.4 h1:mGrfenttwmcUfPXRkWpB0wBJiiGj55ltniUh66Pq4bU=
|
github.com/git-pkgs/enrichment v0.6.5 h1:U0SPzWVGoK4R8TwojCTASBRTEV+QSs0IitdLmzI/g/k=
|
||||||
github.com/git-pkgs/enrichment v0.6.4/go.mod h1:zz1vPUak/w8Jhajll0KDRN2MjKaEYeCzQTxumWnVhqY=
|
github.com/git-pkgs/enrichment v0.6.5/go.mod h1:Vt2PLMvWPOio9DLyC8Gdhh1yxsHwcRcG+L2Kkc9+kak=
|
||||||
github.com/git-pkgs/magic v0.1.0 h1:xLrqq7CMXB9g5bJnmJyKw17Rvlh0GFiEmO6e5RFsoeY=
|
github.com/git-pkgs/integrity v0.1.1 h1:nHQ7SktOiGM1dOb5BFnkdtttG/6FCgE6r5ru6QnsGts=
|
||||||
github.com/git-pkgs/magic v0.1.0/go.mod h1:3ndidt+yvFaI1M0aEkkzkOlFnLPkeVQASIUojazcxCI=
|
github.com/git-pkgs/integrity v0.1.1/go.mod h1:hxu24lcd230377hCF28JQW7sGcCbuNLqo/0ULeb+F1Q=
|
||||||
|
github.com/git-pkgs/magic v0.2.0 h1:c7HqVxnP8c88EaVMH0/KraDFVTcmiXckRiSvNZEnvMQ=
|
||||||
|
github.com/git-pkgs/magic v0.2.0/go.mod h1:3ndidt+yvFaI1M0aEkkzkOlFnLPkeVQASIUojazcxCI=
|
||||||
github.com/git-pkgs/packageurl-go v0.3.1 h1:WM3RBABQZLaRBxgKyYughc3cVBE8KyQxbSC6Jt5ak7M=
|
github.com/git-pkgs/packageurl-go v0.3.1 h1:WM3RBABQZLaRBxgKyYughc3cVBE8KyQxbSC6Jt5ak7M=
|
||||||
github.com/git-pkgs/packageurl-go v0.3.1/go.mod h1:rcIxiG37BlQLB6FZfgdj9Fm7yjhRQd3l+5o7J0QPAk4=
|
github.com/git-pkgs/packageurl-go v0.3.1/go.mod h1:rcIxiG37BlQLB6FZfgdj9Fm7yjhRQd3l+5o7J0QPAk4=
|
||||||
github.com/git-pkgs/pom v0.1.5 h1:TGT8Az2OMxGWsXnSagtUMGzZm7Oax8HrSCteA+mi0qY=
|
github.com/git-pkgs/pom v0.1.5 h1:TGT8Az2OMxGWsXnSagtUMGzZm7Oax8HrSCteA+mi0qY=
|
||||||
github.com/git-pkgs/pom v0.1.5/go.mod h1:ufdMBe1lKzqOeP9IUb9NPZ458xKV8E8NvuyBMxOfwIk=
|
github.com/git-pkgs/pom v0.1.5/go.mod h1:ufdMBe1lKzqOeP9IUb9NPZ458xKV8E8NvuyBMxOfwIk=
|
||||||
github.com/git-pkgs/purl v0.1.15 h1:iQ3clh0Cw41rkM0rf24B7ShnN9Z+UtLMAFlNDUs+Qd4=
|
github.com/git-pkgs/purl v0.1.17 h1:oRSd8tqllTLl74Wa4WnuqU500hXd9OdUnImOEswQUVE=
|
||||||
github.com/git-pkgs/purl v0.1.15/go.mod h1:PqCLVBDeZrZgHysR803/AntMELgIr2LFZVNCcwLH2m0=
|
github.com/git-pkgs/purl v0.1.17/go.mod h1:7u7ora8tQdrkS7Auclr5v8dCJdjN4ej6AbrvYZi2b7k=
|
||||||
github.com/git-pkgs/registries v0.6.4 h1:Kq/KlStjaQyE83UXT/tKuzCrIzc4keGeBjtroMqgoHA=
|
github.com/git-pkgs/registries v0.8.1 h1:Yf2FFdARQ1HcdtZfWBYa5OZFwZHzhFYStiz7qbTDDUU=
|
||||||
github.com/git-pkgs/registries v0.6.4/go.mod h1:YkGHbxHIe2Ha/ROH6zNkS5PJUUoa9g0Ti/s2XhZnrak=
|
github.com/git-pkgs/registries v0.8.1/go.mod h1:5dc3V7rOhAI5755L/bDtjtYV4D5XV4J/4ZtyIXSEs0U=
|
||||||
github.com/git-pkgs/spdx v0.1.4 h1:eQ0waEV3uUeItpWAOvdN1K1rL9hTgsU7fF74r1mDXMs=
|
github.com/git-pkgs/spdx v0.3.1 h1:58JPY5X9pYpXvnzzZIgehItlBykeOOw52pNc4OBcS+c=
|
||||||
github.com/git-pkgs/spdx v0.1.4/go.mod h1:cqRoZcvl530s/W+oGNvwjt4ODN8T1W6D/20MUZEFdto=
|
github.com/git-pkgs/spdx v0.3.1/go.mod h1:cqRoZcvl530s/W+oGNvwjt4ODN8T1W6D/20MUZEFdto=
|
||||||
github.com/git-pkgs/vers v0.3.0 h1:xM4LLUCRmqzdDfe+/pVQUx4SRyFXRVth6tOsJ14wMKU=
|
github.com/git-pkgs/vers v0.3.1 h1:jy/ht2wIRJI5zQrccm6GTeYr+hGFwe2z8LV1HOr4Wco=
|
||||||
github.com/git-pkgs/vers v0.3.0/go.mod h1:biTbSQK1qdbrsxDEKnqe3Jzclxz8vW6uDcwKjfUGcOo=
|
github.com/git-pkgs/vers v0.3.1/go.mod h1:biTbSQK1qdbrsxDEKnqe3Jzclxz8vW6uDcwKjfUGcOo=
|
||||||
github.com/git-pkgs/vulns v0.2.1 h1:tWGhOfPVDZwkM2Y9vRkMpMR+gjtlu2jhERS5JeNBoKQ=
|
github.com/git-pkgs/vulns v0.2.2 h1:4z6fE/Yqf34PTVSv1WsN09hMznjPa9t+1fHDIywZI3g=
|
||||||
github.com/git-pkgs/vulns v0.2.1/go.mod h1:/0gHKHQR5SWttZVEMqgOvCXssKFwAtbac/PfkhBax9o=
|
github.com/git-pkgs/vulns v0.2.2/go.mod h1:cQkJfI2WyW53Seg55Su0gjOSFE5ImSZ0XbHXeb33gfs=
|
||||||
github.com/github/go-spdx/v2 v2.7.0 h1:GzfXx4wFdlilARxmFRXW/mgUy3A4vSqZocCMFV6XFdQ=
|
github.com/github/go-spdx/v2 v2.7.0 h1:GzfXx4wFdlilARxmFRXW/mgUy3A4vSqZocCMFV6XFdQ=
|
||||||
github.com/github/go-spdx/v2 v2.7.0/go.mod h1:Ftc45YYG1WzpzwEPKRVm9Jv8vDqOrN4gWoCkK+bHer0=
|
github.com/github/go-spdx/v2 v2.7.0/go.mod h1:Ftc45YYG1WzpzwEPKRVm9Jv8vDqOrN4gWoCkK+bHer0=
|
||||||
github.com/go-chi/chi/v5 v5.3.1 h1:3j4HZLGZQ3JpMCrPJF/Jl3mYJfWLKBfNJ6quurUGCf8=
|
github.com/go-chi/chi/v5 v5.3.1 h1:3j4HZLGZQ3JpMCrPJF/Jl3mYJfWLKBfNJ6quurUGCf8=
|
||||||
github.com/go-chi/chi/v5 v5.3.1/go.mod h1:R+tYY2hNuVUUjxoPtqUdgBqevM9s9njzkTLutVsOCto=
|
github.com/go-chi/chi/v5 v5.3.1/go.mod h1:R+tYY2hNuVUUjxoPtqUdgBqevM9s9njzkTLutVsOCto=
|
||||||
github.com/go-critic/go-critic v0.14.3 h1:5R1qH2iFeo4I/RJU8vTezdqs08Egi4u5p6vOESA0pog=
|
github.com/go-critic/go-critic v0.14.4 h1:dSX4C3pWSeuMVxvQh6yG8U0ReSf3YOmKi4nwX5q7n/8=
|
||||||
github.com/go-critic/go-critic v0.14.3/go.mod h1:xwntfW6SYAd7h1OqDzmN6hBX/JxsEKl5up/Y2bsxgVQ=
|
github.com/go-critic/go-critic v0.14.4/go.mod h1:xwntfW6SYAd7h1OqDzmN6hBX/JxsEKl5up/Y2bsxgVQ=
|
||||||
github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA=
|
github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA=
|
||||||
github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
|
github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
|
||||||
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
|
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
|
||||||
|
|
@ -289,8 +304,8 @@ github.com/go-openapi/spec v0.20.4/go.mod h1:faYFR1CvsJZ0mNsmsphTMSoRrNV3TEDoAM7
|
||||||
github.com/go-openapi/swag v0.19.5/go.mod h1:POnQmlKehdgb5mhVOsnJFsivZCEZ/vjK9gh66Z9tfKk=
|
github.com/go-openapi/swag v0.19.5/go.mod h1:POnQmlKehdgb5mhVOsnJFsivZCEZ/vjK9gh66Z9tfKk=
|
||||||
github.com/go-openapi/swag v0.19.15 h1:D2NRCBzS9/pEY3gP9Nl8aDqGUcPFrwG2p+CNFrLyrCM=
|
github.com/go-openapi/swag v0.19.15 h1:D2NRCBzS9/pEY3gP9Nl8aDqGUcPFrwG2p+CNFrLyrCM=
|
||||||
github.com/go-openapi/swag v0.19.15/go.mod h1:QYRuS/SOXUCsnplDa677K7+DxSOj6IPNl/eQntq43wQ=
|
github.com/go-openapi/swag v0.19.15/go.mod h1:QYRuS/SOXUCsnplDa677K7+DxSOj6IPNl/eQntq43wQ=
|
||||||
github.com/go-quicktest/qt v1.101.0 h1:O1K29Txy5P2OK0dGo59b7b0LR6wKfIhttaAhHUyn7eI=
|
github.com/go-quicktest/qt v1.102.0 h1:HSQxCeh5YZH3EL3W39ixjtyaEhcWSXQHtHnMBzSs474=
|
||||||
github.com/go-quicktest/qt v1.101.0/go.mod h1:14Bz/f7NwaXPtdYEgzsx46kqSxVwTbzVZsDC26tQJow=
|
github.com/go-quicktest/qt v1.102.0/go.mod h1:p4lGIVX+8Wa6ZPNDvqcxq36XpUDLh42FLetFU7odllI=
|
||||||
github.com/go-sql-driver/mysql v1.8.1/go.mod h1:wEBSXgmK//2ZFJyE+qWnIsVGmvmEKlqwuVSjsCm7DZg=
|
github.com/go-sql-driver/mysql v1.8.1/go.mod h1:wEBSXgmK//2ZFJyE+qWnIsVGmvmEKlqwuVSjsCm7DZg=
|
||||||
github.com/go-sql-driver/mysql v1.9.3 h1:U/N249h2WzJ3Ukj8SowVFjdtZKfu9vlLZxjPXV1aweo=
|
github.com/go-sql-driver/mysql v1.9.3 h1:U/N249h2WzJ3Ukj8SowVFjdtZKfu9vlLZxjPXV1aweo=
|
||||||
github.com/go-sql-driver/mysql v1.9.3/go.mod h1:qn46aNg1333BRMNU69Lq93t8du/dwxI64Gl8i5p1WMU=
|
github.com/go-sql-driver/mysql v1.9.3/go.mod h1:qn46aNg1333BRMNU69Lq93t8du/dwxI64Gl8i5p1WMU=
|
||||||
|
|
@ -331,14 +346,14 @@ github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek
|
||||||
github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps=
|
github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps=
|
||||||
github.com/golangci/asciicheck v0.5.0 h1:jczN/BorERZwK8oiFBOGvlGPknhvq0bjnysTj4nUfo0=
|
github.com/golangci/asciicheck v0.5.0 h1:jczN/BorERZwK8oiFBOGvlGPknhvq0bjnysTj4nUfo0=
|
||||||
github.com/golangci/asciicheck v0.5.0/go.mod h1:5RMNAInbNFw2krqN6ibBxN/zfRFa9S6tA1nPdM0l8qQ=
|
github.com/golangci/asciicheck v0.5.0/go.mod h1:5RMNAInbNFw2krqN6ibBxN/zfRFa9S6tA1nPdM0l8qQ=
|
||||||
github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32 h1:WUvBfQL6EW/40l6OmeSBYQJNSif4O11+bmWEz+C7FYw=
|
github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202 h1:CbTB8KpqnViI6lIXxp03Oclc4VFHi3K4BWC1TacsZ+A=
|
||||||
github.com/golangci/dupl v0.0.0-20250308024227-f665c8d69b32/go.mod h1:NUw9Zr2Sy7+HxzdjIULge71wI6yEg1lWQr7Evcu8K0E=
|
github.com/golangci/dupl v0.0.0-20260401084720-c99c5cf5c202/go.mod h1:NUw9Zr2Sy7+HxzdjIULge71wI6yEg1lWQr7Evcu8K0E=
|
||||||
github.com/golangci/go-printf-func-name v0.1.1 h1:hIYTFJqAGp1iwoIfsNTpoq1xZAarogrvjO9AfiW3B4U=
|
github.com/golangci/go-printf-func-name v0.1.1 h1:hIYTFJqAGp1iwoIfsNTpoq1xZAarogrvjO9AfiW3B4U=
|
||||||
github.com/golangci/go-printf-func-name v0.1.1/go.mod h1:Es64MpWEZbh0UBtTAICOZiB+miW53w/K9Or/4QogJss=
|
github.com/golangci/go-printf-func-name v0.1.1/go.mod h1:Es64MpWEZbh0UBtTAICOZiB+miW53w/K9Or/4QogJss=
|
||||||
github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d h1:viFft9sS/dxoYY0aiOTsLKO2aZQAPT4nlQCsimGcSGE=
|
github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792 h1:WL8YKrt3UbOBqSRU7GpP5BTtQTMWtVtj+mfPijgZeIg=
|
||||||
github.com/golangci/gofmt v0.0.0-20250106114630-d62b90e6713d/go.mod h1:ivJ9QDg0XucIkmwhzCDsqcnxxlDStoTl89jDMIoNxKY=
|
github.com/golangci/gofmt v0.0.0-20260820135601-e84e05053792/go.mod h1:te5hX0dW4C5r6YbXs+6ysNr8Q5UTmdIqGbb+mlFiYmA=
|
||||||
github.com/golangci/golangci-lint/v2 v2.10.1 h1:flhw5Px6ojbLyEFzXvJn5B2HEdkkRlkhE1SnmCbQBiE=
|
github.com/golangci/golangci-lint/v2 v2.13.1 h1:RuM4OcluM4xFQcGuRE6R7jA33pqxK/W1EsBxpugdZjg=
|
||||||
github.com/golangci/golangci-lint/v2 v2.10.1/go.mod h1:dBsrOk6zj0vDhlTv+IiJGqkDokR24IVTS7W3EVfPTQY=
|
github.com/golangci/golangci-lint/v2 v2.13.1/go.mod h1:HwX7mDzqHbcSxlhrTygjX1GJbAfQ3sJAqOx41qQlhDE=
|
||||||
github.com/golangci/golines v0.15.0 h1:Qnph25g8Y1c5fdo1X7GaRDGgnMHgnxh4Gk4VfPTtRx0=
|
github.com/golangci/golines v0.15.0 h1:Qnph25g8Y1c5fdo1X7GaRDGgnMHgnxh4Gk4VfPTtRx0=
|
||||||
github.com/golangci/golines v0.15.0/go.mod h1:AZjXd23tbHMpowhtnGlj9KCNsysj72aeZVVHnVcZx10=
|
github.com/golangci/golines v0.15.0/go.mod h1:AZjXd23tbHMpowhtnGlj9KCNsysj72aeZVVHnVcZx10=
|
||||||
github.com/golangci/misspell v0.8.0 h1:qvxQhiE2/5z+BVRo1kwYA8yGz+lOlu5Jfvtx2b04Jbg=
|
github.com/golangci/misspell v0.8.0 h1:qvxQhiE2/5z+BVRo1kwYA8yGz+lOlu5Jfvtx2b04Jbg=
|
||||||
|
|
@ -347,6 +362,8 @@ github.com/golangci/plugin-module-register v0.1.2 h1:e5WM6PO6NIAEcij3B053CohVp3H
|
||||||
github.com/golangci/plugin-module-register v0.1.2/go.mod h1:1+QGTsKBvAIvPvoY/os+G5eoqxWn70HYDm2uvUyGuVw=
|
github.com/golangci/plugin-module-register v0.1.2/go.mod h1:1+QGTsKBvAIvPvoY/os+G5eoqxWn70HYDm2uvUyGuVw=
|
||||||
github.com/golangci/revgrep v0.8.0 h1:EZBctwbVd0aMeRnNUsFogoyayvKHyxlV3CdUA46FX2s=
|
github.com/golangci/revgrep v0.8.0 h1:EZBctwbVd0aMeRnNUsFogoyayvKHyxlV3CdUA46FX2s=
|
||||||
github.com/golangci/revgrep v0.8.0/go.mod h1:U4R/s9dlXZsg8uJmaR1GrloUr14D7qDl8gi2iPXJH8k=
|
github.com/golangci/revgrep v0.8.0/go.mod h1:U4R/s9dlXZsg8uJmaR1GrloUr14D7qDl8gi2iPXJH8k=
|
||||||
|
github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba h1:lqtcnSMDuuJdu/LrKWi5RJzpSNLOJXYe/nzQutTI5kg=
|
||||||
|
github.com/golangci/rowserrcheck v0.0.0-20260419091836-c5f79b8a11ba/go.mod h1:sCBNcpRmhJCtbFGz49+IM3ETTFf7QdJ30AeYCd43NKk=
|
||||||
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e h1:ai0EfmVYE2bRA5htgAG9r7s3tHsfjIhN98WshBTJ9jM=
|
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e h1:ai0EfmVYE2bRA5htgAG9r7s3tHsfjIhN98WshBTJ9jM=
|
||||||
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e/go.mod h1:Vrn4B5oR9qRwM+f54koyeH3yzphlecwERs0el27Fr/s=
|
github.com/golangci/swaggoswag v0.0.0-20250504205917-77f2aca3143e/go.mod h1:Vrn4B5oR9qRwM+f54koyeH3yzphlecwERs0el27Fr/s=
|
||||||
github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e h1:gD6P7NEo7Eqtt0ssnqSJNNndxe69DOQ24A5h7+i3KpM=
|
github.com/golangci/unconvert v0.0.0-20250410112200-a129a6e6413e h1:gD6P7NEo7Eqtt0ssnqSJNNndxe69DOQ24A5h7+i3KpM=
|
||||||
|
|
@ -362,18 +379,18 @@ github.com/google/go-replayers/httpreplay v1.2.0 h1:VM1wEyyjaoU53BwrOnaf9VhAyQQE
|
||||||
github.com/google/go-replayers/httpreplay v1.2.0/go.mod h1:WahEFFZZ7a1P4VM1qEeHy+tME4bwyqPcwWbNlUI1Mcg=
|
github.com/google/go-replayers/httpreplay v1.2.0/go.mod h1:WahEFFZZ7a1P4VM1qEeHy+tME4bwyqPcwWbNlUI1Mcg=
|
||||||
github.com/google/martian/v3 v3.3.3 h1:DIhPTQrbPkgs2yJYdXU/eNACCG5DVQjySNRNlflZ9Fc=
|
github.com/google/martian/v3 v3.3.3 h1:DIhPTQrbPkgs2yJYdXU/eNACCG5DVQjySNRNlflZ9Fc=
|
||||||
github.com/google/martian/v3 v3.3.3/go.mod h1:iEPrYcgCF7jA9OtScMFQyAlZZ4YXTKEtJ1E6RWzmBA0=
|
github.com/google/martian/v3 v3.3.3/go.mod h1:iEPrYcgCF7jA9OtScMFQyAlZZ4YXTKEtJ1E6RWzmBA0=
|
||||||
github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83 h1:z2ogiKUYzX5Is6zr/vP9vJGqPwcdqsWjOt+V8J7+bTc=
|
github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 h1:LMLX+LgTNWpfvCBdFebv6EsYotImrt/Ppc5cXIriCSo=
|
||||||
github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83/go.mod h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI=
|
github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3/go.mod h1:jl5iWTm0/hd5PjEYEOuwAJ57L/CibdZfrqZ5XA5GrCk=
|
||||||
github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0=
|
github.com/google/s2a-go v0.1.9 h1:LGD7gtMgezd8a/Xak7mEWL0PjoTQFvpRudN895yqKW0=
|
||||||
github.com/google/s2a-go v0.1.9/go.mod h1:YA0Ei2ZQL3acow2O62kdp9UlnvMmU7kA6Eutn0dXayM=
|
github.com/google/s2a-go v0.1.9/go.mod h1:YA0Ei2ZQL3acow2O62kdp9UlnvMmU7kA6Eutn0dXayM=
|
||||||
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
|
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
|
||||||
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
|
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
|
||||||
github.com/google/wire v0.7.0 h1:JxUKI6+CVBgCO2WToKy/nQk0sS+amI9z9EjVmdaocj4=
|
github.com/google/wire v0.7.0 h1:JxUKI6+CVBgCO2WToKy/nQk0sS+amI9z9EjVmdaocj4=
|
||||||
github.com/google/wire v0.7.0/go.mod h1:n6YbUQD9cPKTnHXEBN2DXlOp/mVADhVErcMFb0v3J18=
|
github.com/google/wire v0.7.0/go.mod h1:n6YbUQD9cPKTnHXEBN2DXlOp/mVADhVErcMFb0v3J18=
|
||||||
github.com/googleapis/enterprise-certificate-proxy v0.3.14 h1:yh8ncqsbUY4shRD5dA6RlzjJaT4hi3kII+zYw8wmLb8=
|
github.com/googleapis/enterprise-certificate-proxy v0.3.18 h1:hvVi34VucdrV1IIsiWuqYM8kutw/92MxNEFxCJZEh0k=
|
||||||
github.com/googleapis/enterprise-certificate-proxy v0.3.14/go.mod h1:vqVt9yG9480NtzREnTlmGSBmFrA+bzb0yl0TxoBQXOg=
|
github.com/googleapis/enterprise-certificate-proxy v0.3.18/go.mod h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k=
|
||||||
github.com/googleapis/gax-go/v2 v2.19.0 h1:fYQaUOiGwll0cGj7jmHT/0nPlcrZDFPrZRhTsoCr8hE=
|
github.com/googleapis/gax-go/v2 v2.23.0 h1:Tchl7qkvE7Ip3y+ztvNufYFvkfqTe7NfLTYGIdJRLuE=
|
||||||
github.com/googleapis/gax-go/v2 v2.19.0/go.mod h1:w2ROXVdfGEVFXzmlciUU4EdjHgWvB5h2n6x/8XSTTJA=
|
github.com/googleapis/gax-go/v2 v2.23.0/go.mod h1:rBQKOVJCdb8IFEzg+FCwlt1LP/xMDGuqUXhUG+XMXEg=
|
||||||
github.com/gordonklaus/ineffassign v0.2.0 h1:Uths4KnmwxNJNzq87fwQQDDnbNb7De00VOk9Nu0TySs=
|
github.com/gordonklaus/ineffassign v0.2.0 h1:Uths4KnmwxNJNzq87fwQQDDnbNb7De00VOk9Nu0TySs=
|
||||||
github.com/gordonklaus/ineffassign v0.2.0/go.mod h1:TIpymnagPSexySzs7F9FnO1XFTy8IT3a59vmZp5Y9Lw=
|
github.com/gordonklaus/ineffassign v0.2.0/go.mod h1:TIpymnagPSexySzs7F9FnO1XFTy8IT3a59vmZp5Y9Lw=
|
||||||
github.com/gostaticanalysis/analysisutil v0.7.1 h1:ZMCjoue3DtDWQ5WyU16YbjbQEQ3VuzwxALrpYd+HeKk=
|
github.com/gostaticanalysis/analysisutil v0.7.1 h1:ZMCjoue3DtDWQ5WyU16YbjbQEQ3VuzwxALrpYd+HeKk=
|
||||||
|
|
@ -393,8 +410,8 @@ github.com/hashicorp/go-immutable-radix/v2 v2.1.0/go.mod h1:hgdqLXA4f6NIjRVisM1T
|
||||||
github.com/hashicorp/go-uuid v1.0.3 h1:2gKiV6YVmrJ1i2CKKa9obLvRieoRGviZFL26PcT/Co8=
|
github.com/hashicorp/go-uuid v1.0.3 h1:2gKiV6YVmrJ1i2CKKa9obLvRieoRGviZFL26PcT/Co8=
|
||||||
github.com/hashicorp/go-uuid v1.0.3/go.mod h1:6SBZvOh/SIDV7/2o3Jml5SYk/TvGqwFJ/bN7x4byOro=
|
github.com/hashicorp/go-uuid v1.0.3/go.mod h1:6SBZvOh/SIDV7/2o3Jml5SYk/TvGqwFJ/bN7x4byOro=
|
||||||
github.com/hashicorp/go-version v1.2.1/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA=
|
github.com/hashicorp/go-version v1.2.1/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA=
|
||||||
github.com/hashicorp/go-version v1.8.0 h1:KAkNb1HAiZd1ukkxDFGmokVZe1Xy9HG6NUp+bPle2i4=
|
github.com/hashicorp/go-version v1.9.0 h1:CeOIz6k+LoN3qX9Z0tyQrPtiB1DFYRPfCIBtaXPSCnA=
|
||||||
github.com/hashicorp/go-version v1.8.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA=
|
github.com/hashicorp/go-version v1.9.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA=
|
||||||
github.com/hashicorp/golang-lru/v2 v2.0.7 h1:a+bsQ5rvGLjzHuww6tVxozPZFVghXaHOwFs4luLUK2k=
|
github.com/hashicorp/golang-lru/v2 v2.0.7 h1:a+bsQ5rvGLjzHuww6tVxozPZFVghXaHOwFs4luLUK2k=
|
||||||
github.com/hashicorp/golang-lru/v2 v2.0.7/go.mod h1:QeFd9opnmA6QUJc5vARoKUSoFhyfM2/ZepoAG6RGpeM=
|
github.com/hashicorp/golang-lru/v2 v2.0.7/go.mod h1:QeFd9opnmA6QUJc5vARoKUSoFhyfM2/ZepoAG6RGpeM=
|
||||||
github.com/hashicorp/hcl v1.0.0 h1:0Anlzjpi4vEasTeNFn2mLJgTSwt0+6sfsiTG8qcWGx4=
|
github.com/hashicorp/hcl v1.0.0 h1:0Anlzjpi4vEasTeNFn2mLJgTSwt0+6sfsiTG8qcWGx4=
|
||||||
|
|
@ -403,10 +420,8 @@ github.com/hexops/gotextdiff v1.0.3 h1:gitA9+qJrrTCsiCl7+kh75nPqQt1cx4ZkudSTLoUq
|
||||||
github.com/hexops/gotextdiff v1.0.3/go.mod h1:pSWU5MAI3yDq+fZBTazCSJysOMbxWL1BSow5/V2vxeg=
|
github.com/hexops/gotextdiff v1.0.3/go.mod h1:pSWU5MAI3yDq+fZBTazCSJysOMbxWL1BSow5/V2vxeg=
|
||||||
github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8=
|
github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8=
|
||||||
github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
|
github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
|
||||||
github.com/jgautheron/goconst v1.8.2 h1:y0XF7X8CikZ93fSNT6WBTb/NElBu9IjaY7CCYQrCMX4=
|
github.com/jgautheron/goconst v1.11.0 h1:KgN90z5qXt5f0Uzf3cWXev3hfMMFUyNeKdpkSBRvLDk=
|
||||||
github.com/jgautheron/goconst v1.8.2/go.mod h1:A0oxgBCHy55NQn6sYpO7UdnA9p+h7cPtoOZUmvNIako=
|
github.com/jgautheron/goconst v1.11.0/go.mod h1:0p+wv1lFOiUr0IlNNT1nrm6+8DB8u2sU6KHGzFRXHDc=
|
||||||
github.com/jingyugao/rowserrcheck v1.1.1 h1:zibz55j/MJtLsjP1OF4bSdgXxwL1b+Vn7Tjzq7gFzUs=
|
|
||||||
github.com/jingyugao/rowserrcheck v1.1.1/go.mod h1:4yvlZSDb3IyDTUZJUmpZfm2Hwok+Dtp+nu2qOq+er9c=
|
|
||||||
github.com/jjti/go-spancheck v0.6.5 h1:lmi7pKxa37oKYIMScialXUK6hP3iY5F1gu+mLBPgYB8=
|
github.com/jjti/go-spancheck v0.6.5 h1:lmi7pKxa37oKYIMScialXUK6hP3iY5F1gu+mLBPgYB8=
|
||||||
github.com/jjti/go-spancheck v0.6.5/go.mod h1:aEogkeatBrbYsyW6y5TgDfihCulDYciL1B7rG2vSsrU=
|
github.com/jjti/go-spancheck v0.6.5/go.mod h1:aEogkeatBrbYsyW6y5TgDfihCulDYciL1B7rG2vSsrU=
|
||||||
github.com/jmoiron/sqlx v1.4.0 h1:1PLqN7S1UYp5t4SrVVnt4nUVNemrDAtxlulVe+Qgm3o=
|
github.com/jmoiron/sqlx v1.4.0 h1:1PLqN7S1UYp5t4SrVVnt4nUVNemrDAtxlulVe+Qgm3o=
|
||||||
|
|
@ -420,12 +435,12 @@ github.com/karamaru-alpha/copyloopvar v1.2.2 h1:yfNQvP9YaGQR7VaWLYcfZUlRP2eo2vhE
|
||||||
github.com/karamaru-alpha/copyloopvar v1.2.2/go.mod h1:oY4rGZqZ879JkJMtX3RRkcXRkmUvH0x35ykgaKgsgJY=
|
github.com/karamaru-alpha/copyloopvar v1.2.2/go.mod h1:oY4rGZqZ879JkJMtX3RRkcXRkmUvH0x35ykgaKgsgJY=
|
||||||
github.com/keybase/go-keychain v0.0.1 h1:way+bWYa6lDppZoZcgMbYsvC7GxljxrskdNInRtuthU=
|
github.com/keybase/go-keychain v0.0.1 h1:way+bWYa6lDppZoZcgMbYsvC7GxljxrskdNInRtuthU=
|
||||||
github.com/keybase/go-keychain v0.0.1/go.mod h1:PdEILRW3i9D8JcdM+FmY6RwkHGnhHxXwkPPMeUgOK1k=
|
github.com/keybase/go-keychain v0.0.1/go.mod h1:PdEILRW3i9D8JcdM+FmY6RwkHGnhHxXwkPPMeUgOK1k=
|
||||||
github.com/kisielk/errcheck v1.9.0 h1:9xt1zI9EBfcYBvdU1nVrzMzzUPUtPKs9bVSIM3TAb3M=
|
github.com/kisielk/errcheck v1.20.0 h1:9rwHBNKzd4wkDWcROy3DvFGNqEPlkxBg305rvk7HabI=
|
||||||
github.com/kisielk/errcheck v1.9.0/go.mod h1:kQxWMMVZgIkDq7U8xtG/n2juOjbLgZtedi0D+/VL/i8=
|
github.com/kisielk/errcheck v1.20.0/go.mod h1:O+f80MKNwX8Oor2jwgpeQ9An7uJm+hRSgT+h22knRJU=
|
||||||
github.com/kkHAIKE/contextcheck v1.1.6 h1:7HIyRcnyzxL9Lz06NGhiKvenXq7Zw6Q0UQu/ttjfJCE=
|
github.com/kkHAIKE/contextcheck v1.1.6 h1:7HIyRcnyzxL9Lz06NGhiKvenXq7Zw6Q0UQu/ttjfJCE=
|
||||||
github.com/kkHAIKE/contextcheck v1.1.6/go.mod h1:3dDbMRNBFaq8HFXWC1JyvDSPm43CmE6IuHam8Wr0rkg=
|
github.com/kkHAIKE/contextcheck v1.1.6/go.mod h1:3dDbMRNBFaq8HFXWC1JyvDSPm43CmE6IuHam8Wr0rkg=
|
||||||
github.com/klauspost/compress v1.19.0 h1:sXLILfc9jV2QYWkzFOPWStmcUVH2RHEB1JCdY2oVvCQ=
|
github.com/klauspost/compress v1.19.1 h1:VsB4HPswih7mmZ8WleSFQ75c/Ui1M4trX5oAsJnhSlk=
|
||||||
github.com/klauspost/compress v1.19.0/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
|
github.com/klauspost/compress v1.19.1/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
|
||||||
github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
|
github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
|
||||||
github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
|
github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
|
||||||
github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
|
github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
|
||||||
|
|
@ -443,8 +458,8 @@ github.com/lasiar/canonicalheader v1.1.2 h1:vZ5uqwvDbyJCnMhmFYimgMZnJMjwljN5VGY0
|
||||||
github.com/lasiar/canonicalheader v1.1.2/go.mod h1:qJCeLFS0G/QlLQ506T+Fk/fWMa2VmBUiEI2cuMK4djI=
|
github.com/lasiar/canonicalheader v1.1.2/go.mod h1:qJCeLFS0G/QlLQ506T+Fk/fWMa2VmBUiEI2cuMK4djI=
|
||||||
github.com/ldez/exptostd v0.4.5 h1:kv2ZGUVI6VwRfp/+bcQ6Nbx0ghFWcGIKInkG/oFn1aQ=
|
github.com/ldez/exptostd v0.4.5 h1:kv2ZGUVI6VwRfp/+bcQ6Nbx0ghFWcGIKInkG/oFn1aQ=
|
||||||
github.com/ldez/exptostd v0.4.5/go.mod h1:QRjHRMXJrCTIm9WxVNH6VW7oN7KrGSht69bIRwvdFsM=
|
github.com/ldez/exptostd v0.4.5/go.mod h1:QRjHRMXJrCTIm9WxVNH6VW7oN7KrGSht69bIRwvdFsM=
|
||||||
github.com/ldez/gomoddirectives v0.8.0 h1:JqIuTtgvFC2RdH1s357vrE23WJF2cpDCPFgA/TWDGpk=
|
github.com/ldez/gomoddirectives v0.9.0 h1:2YV/EX7nVlWL4jySusYTzBKHuE3D2fgcRsQuMa3yIoo=
|
||||||
github.com/ldez/gomoddirectives v0.8.0/go.mod h1:jutzamvZR4XYJLr0d5Honycp4Gy6GEg2mS9+2YX3F1Q=
|
github.com/ldez/gomoddirectives v0.9.0/go.mod h1:DdZzfm9MdXCjn2/UGYXCFfo+tzrp2Ib4iD2Q0kIJkwE=
|
||||||
github.com/ldez/grignotin v0.10.1 h1:keYi9rYsgbvqAZGI1liek5c+jv9UUjbvdj3Tbn5fn4o=
|
github.com/ldez/grignotin v0.10.1 h1:keYi9rYsgbvqAZGI1liek5c+jv9UUjbvdj3Tbn5fn4o=
|
||||||
github.com/ldez/grignotin v0.10.1/go.mod h1:UlDbXFCARrXbWGNGP3S5vsysNXAPhnSuBufpTEbwOas=
|
github.com/ldez/grignotin v0.10.1/go.mod h1:UlDbXFCARrXbWGNGP3S5vsysNXAPhnSuBufpTEbwOas=
|
||||||
github.com/ldez/structtags v0.6.1 h1:bUooFLbXx41tW8SvkfwfFkkjPYvFFs59AAMgVg6DUBk=
|
github.com/ldez/structtags v0.6.1 h1:bUooFLbXx41tW8SvkfwfFkkjPYvFFs59AAMgVg6DUBk=
|
||||||
|
|
@ -458,8 +473,8 @@ github.com/leonklingele/grouper v1.1.2/go.mod h1:6D0M/HVkhs2yRKRFZUoGjeDy7EZTfFB
|
||||||
github.com/lib/pq v1.10.9/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o=
|
github.com/lib/pq v1.10.9/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o=
|
||||||
github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ=
|
github.com/lib/pq v1.12.3 h1:tTWxr2YLKwIvK90ZXEw8GP7UFHtcbTtty8zsI+YjrfQ=
|
||||||
github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA=
|
github.com/lib/pq v1.12.3/go.mod h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA=
|
||||||
github.com/lucasb-eyer/go-colorful v1.2.0 h1:1nnpGOrhyZZuNyfu1QjKiUICQ74+3FNCN69Aj6K7nkY=
|
github.com/lucasb-eyer/go-colorful v1.4.1 h1:1EO+WB73+EH8EVbzlrG3KLAfEypQWVHIBqlTf+2hNss=
|
||||||
github.com/lucasb-eyer/go-colorful v1.2.0/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0=
|
github.com/lucasb-eyer/go-colorful v1.4.1/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0=
|
||||||
github.com/macabu/inamedparam v0.2.0 h1:VyPYpOc10nkhI2qeNUdh3Zket4fcZjEWe35poddBCpE=
|
github.com/macabu/inamedparam v0.2.0 h1:VyPYpOc10nkhI2qeNUdh3Zket4fcZjEWe35poddBCpE=
|
||||||
github.com/macabu/inamedparam v0.2.0/go.mod h1:+Pee9/YfGe5LJ62pYXqB89lJ+0k5bsR8Wgz/C0Zlq3U=
|
github.com/macabu/inamedparam v0.2.0/go.mod h1:+Pee9/YfGe5LJ62pYXqB89lJ+0k5bsR8Wgz/C0Zlq3U=
|
||||||
github.com/magiconair/properties v1.8.6 h1:5ibWZ6iY0NctNGWo87LalDlEZ6R41TqbbDamhfG/Qzo=
|
github.com/magiconair/properties v1.8.6 h1:5ibWZ6iY0NctNGWo87LalDlEZ6R41TqbbDamhfG/Qzo=
|
||||||
|
|
@ -471,8 +486,8 @@ github.com/mailru/easyjson v0.7.7 h1:UGYAvKxe3sBsEDzO8ZeWOSlIQfWFlxbzLZe7hwFURr0
|
||||||
github.com/mailru/easyjson v0.7.7/go.mod h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc=
|
github.com/mailru/easyjson v0.7.7/go.mod h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc=
|
||||||
github.com/manuelarte/embeddedstructfieldcheck v0.4.0 h1:3mAIyaGRtjK6EO9E73JlXLtiy7ha80b2ZVGyacxgfww=
|
github.com/manuelarte/embeddedstructfieldcheck v0.4.0 h1:3mAIyaGRtjK6EO9E73JlXLtiy7ha80b2ZVGyacxgfww=
|
||||||
github.com/manuelarte/embeddedstructfieldcheck v0.4.0/go.mod h1:z8dFSyXqp+fC6NLDSljRJeNQJJDWnY7RoWFzV3PC6UM=
|
github.com/manuelarte/embeddedstructfieldcheck v0.4.0/go.mod h1:z8dFSyXqp+fC6NLDSljRJeNQJJDWnY7RoWFzV3PC6UM=
|
||||||
github.com/manuelarte/funcorder v0.5.0 h1:llMuHXXbg7tD0i/LNw8vGnkDTHFpTnWqKPI85Rknc+8=
|
github.com/manuelarte/funcorder v0.6.0 h1:0hBngc4fa1IgNiI65A7sFGkMvoMCc878RjqB5V7rWP0=
|
||||||
github.com/manuelarte/funcorder v0.5.0/go.mod h1:Yt3CiUQthSBMBxjShjdXMexmzpP8YGvGLjrxJNkO2hA=
|
github.com/manuelarte/funcorder v0.6.0/go.mod h1:id3NDhXdQBmeqXH7eVC6Z89xS6JxvZ8kF9xUxpArU/g=
|
||||||
github.com/maratori/testableexamples v1.0.1 h1:HfOQXs+XgfeRBJ+Wz0XfH+FHnoY9TVqL6Fcevpzy4q8=
|
github.com/maratori/testableexamples v1.0.1 h1:HfOQXs+XgfeRBJ+Wz0XfH+FHnoY9TVqL6Fcevpzy4q8=
|
||||||
github.com/maratori/testableexamples v1.0.1/go.mod h1:XE2F/nQs7B9N08JgyRmdGjYVGqxWwClLPCGSQhXQSrQ=
|
github.com/maratori/testableexamples v1.0.1/go.mod h1:XE2F/nQs7B9N08JgyRmdGjYVGqxWwClLPCGSQhXQSrQ=
|
||||||
github.com/maratori/testpackage v1.1.2 h1:ffDSh+AgqluCLMXhM19f/cpvQAKygKAJXFl9aUjmbqs=
|
github.com/maratori/testpackage v1.1.2 h1:ffDSh+AgqluCLMXhM19f/cpvQAKygKAJXFl9aUjmbqs=
|
||||||
|
|
@ -481,24 +496,24 @@ github.com/matoous/godox v1.1.0 h1:W5mqwbyWrwZv6OQ5Z1a/DHGMOvXYCBP3+Ht7KMoJhq4=
|
||||||
github.com/matoous/godox v1.1.0/go.mod h1:jgE/3fUXiTurkdHOLT5WEkThTSuE7yxHv5iWPa80afs=
|
github.com/matoous/godox v1.1.0/go.mod h1:jgE/3fUXiTurkdHOLT5WEkThTSuE7yxHv5iWPa80afs=
|
||||||
github.com/matryer/is v1.4.0 h1:sosSmIWwkYITGrxZ25ULNDeKiMNzFSr4V/eqBQP0PeE=
|
github.com/matryer/is v1.4.0 h1:sosSmIWwkYITGrxZ25ULNDeKiMNzFSr4V/eqBQP0PeE=
|
||||||
github.com/matryer/is v1.4.0/go.mod h1:8I/i5uYgLzgsgEloJE1U6xx5HkBQpAZvepWuujKwMRU=
|
github.com/matryer/is v1.4.0/go.mod h1:8I/i5uYgLzgsgEloJE1U6xx5HkBQpAZvepWuujKwMRU=
|
||||||
github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHPsaIE=
|
github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy0/jY=
|
||||||
github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
|
github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8=
|
||||||
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
|
github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI=
|
||||||
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
|
github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A=
|
||||||
github.com/mattn/go-runewidth v0.0.16 h1:E5ScNMtiwvlvB5paMFdw9p4kSQzbXFikJ5SQO6TULQc=
|
github.com/mattn/go-runewidth v0.0.24 h1:cpokDiIn0MGnhdHwuWnJBITySJ20QyNGnY2kR/ay2DU=
|
||||||
github.com/mattn/go-runewidth v0.0.16/go.mod h1:Jdepj2loyihRzMpdS35Xk/zdY8IAYHsh153qUoGf23w=
|
github.com/mattn/go-runewidth v0.0.24/go.mod h1:XBkDxAl56ILZc9knddidhrOlY5R/pDhgLpndooCuJAs=
|
||||||
github.com/mattn/go-sqlite3 v1.14.22 h1:2gZY6PC6kBnID23Tichd1K+Z0oS6nE/XwU+Vz/5o4kU=
|
github.com/mattn/go-sqlite3 v1.14.22 h1:2gZY6PC6kBnID23Tichd1K+Z0oS6nE/XwU+Vz/5o4kU=
|
||||||
github.com/mattn/go-sqlite3 v1.14.22/go.mod h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y=
|
github.com/mattn/go-sqlite3 v1.14.22/go.mod h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y=
|
||||||
github.com/mgechev/revive v1.14.0 h1:CC2Ulb3kV7JFYt+izwORoS3VT/+Plb8BvslI/l1yZsc=
|
github.com/mgechev/revive v1.15.0 h1:vJ0HzSBzfNyPbHKolgiFjHxLek9KUijhqh42yGoqZ8Q=
|
||||||
github.com/mgechev/revive v1.14.0/go.mod h1:MvnujelCZBZCaoDv5B3foPo6WWgULSSFxvfxp7GsPfo=
|
github.com/mgechev/revive v1.15.0/go.mod h1:LlAKO3QQe9OJ0pVZzI2GPa8CbXGZ/9lNpCGvK4T/a8A=
|
||||||
github.com/mitchellh/go-homedir v1.1.0 h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG+4E0Y=
|
github.com/mitchellh/go-homedir v1.1.0 h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG+4E0Y=
|
||||||
github.com/mitchellh/go-homedir v1.1.0/go.mod h1:SfyaCUpYCn1Vlf4IUYiD9fPX4A5wJrkLzIz1N1q0pr0=
|
github.com/mitchellh/go-homedir v1.1.0/go.mod h1:SfyaCUpYCn1Vlf4IUYiD9fPX4A5wJrkLzIz1N1q0pr0=
|
||||||
github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY=
|
github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY=
|
||||||
github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
|
github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
|
||||||
github.com/moricho/tparallel v0.3.2 h1:odr8aZVFA3NZrNybggMkYO3rgPRcqjeQUlBBFVxKHTI=
|
github.com/moricho/tparallel v0.3.2 h1:odr8aZVFA3NZrNybggMkYO3rgPRcqjeQUlBBFVxKHTI=
|
||||||
github.com/moricho/tparallel v0.3.2/go.mod h1:OQ+K3b4Ln3l2TZveGCywybl68glfLEwFGqvnjok8b+U=
|
github.com/moricho/tparallel v0.3.2/go.mod h1:OQ+K3b4Ln3l2TZveGCywybl68glfLEwFGqvnjok8b+U=
|
||||||
github.com/muesli/termenv v0.16.0 h1:S5AlUN9dENB57rsbnkPyfdGuWIlkmzJjbFf0Tf5FWUc=
|
github.com/muesli/cancelreader v0.2.2 h1:3I4Kt4BQjOR54NavqnDogx/MIoWBFa0StPA8ELUXHmA=
|
||||||
github.com/muesli/termenv v0.16.0/go.mod h1:ZRfOIKPFDYQoDFF4Olj7/QJbW60Ol/kL1pU3VfY/Cnk=
|
github.com/muesli/cancelreader v0.2.2/go.mod h1:3XuTXfFS2VjM+HTLZY9Ak0l6eUKfijIfMUZ4EgX0QYo=
|
||||||
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA=
|
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA=
|
||||||
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ=
|
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ=
|
||||||
github.com/nakabonne/nestif v0.3.1 h1:wm28nZjhQY5HyYPx+weN3Q65k6ilSBxDb8v5S81B81U=
|
github.com/nakabonne/nestif v0.3.1 h1:wm28nZjhQY5HyYPx+weN3Q65k6ilSBxDb8v5S81B81U=
|
||||||
|
|
@ -510,16 +525,16 @@ github.com/nishanths/exhaustive v0.12.0 h1:vIY9sALmw6T/yxiASewa4TQcFsVYZQQRUQJhK
|
||||||
github.com/nishanths/exhaustive v0.12.0/go.mod h1:mEZ95wPIZW+x8kC4TgC+9YCUgiST7ecevsVDTgc2obs=
|
github.com/nishanths/exhaustive v0.12.0/go.mod h1:mEZ95wPIZW+x8kC4TgC+9YCUgiST7ecevsVDTgc2obs=
|
||||||
github.com/nishanths/predeclared v0.2.2 h1:V2EPdZPliZymNAn79T8RkNApBjMmVKh5XRpLm/w98Vk=
|
github.com/nishanths/predeclared v0.2.2 h1:V2EPdZPliZymNAn79T8RkNApBjMmVKh5XRpLm/w98Vk=
|
||||||
github.com/nishanths/predeclared v0.2.2/go.mod h1:RROzoN6TnGQupbC+lqggsOlcgysk3LMK/HI84Mp280c=
|
github.com/nishanths/predeclared v0.2.2/go.mod h1:RROzoN6TnGQupbC+lqggsOlcgysk3LMK/HI84Mp280c=
|
||||||
github.com/nunnatsa/ginkgolinter v0.23.0 h1:x3o4DGYOWbBMP/VdNQKgSj+25aJKx2Pe6lHr8gBcgf8=
|
github.com/nunnatsa/ginkgolinter v0.24.0 h1:Mp0EagluLFP98JatP6nqp/gGEoljNG97uf9AcxcBVy8=
|
||||||
github.com/nunnatsa/ginkgolinter v0.23.0/go.mod h1:9qN1+0akwXEccwV1CAcCDfcoBlWXHB+ML9884pL4SZ4=
|
github.com/nunnatsa/ginkgolinter v0.24.0/go.mod h1:2ZMRuzX6+3XXyY6UZOwb6n+MCocVGbkIsDBC4vuWz5c=
|
||||||
github.com/oapi-codegen/nullable v1.1.0 h1:eAh8JVc5430VtYVnq00Hrbpag9PFRGWLjxR1/3KntMs=
|
github.com/oapi-codegen/nullable v1.2.0 h1:VflFkDW980KhBPiFF7nWSyjg+r4Obqj8lXipV0UkP5w=
|
||||||
github.com/oapi-codegen/nullable v1.1.0/go.mod h1:KUZ3vUzkmEKY90ksAmit2+5juDIhIZhfDl+0PwOQlFY=
|
github.com/oapi-codegen/nullable v1.2.0/go.mod h1:KUZ3vUzkmEKY90ksAmit2+5juDIhIZhfDl+0PwOQlFY=
|
||||||
github.com/oapi-codegen/runtime v1.6.0 h1:7Xx+GlueD6nRuyKoCPzL434Jfi3BetbiJOrzCHp/VPU=
|
github.com/oapi-codegen/runtime v1.6.0 h1:7Xx+GlueD6nRuyKoCPzL434Jfi3BetbiJOrzCHp/VPU=
|
||||||
github.com/oapi-codegen/runtime v1.6.0/go.mod h1:GwV7hC2hviaMzj+ITfHVRESK5J2W/GefVwIND/bMGvU=
|
github.com/oapi-codegen/runtime v1.6.0/go.mod h1:GwV7hC2hviaMzj+ITfHVRESK5J2W/GefVwIND/bMGvU=
|
||||||
github.com/onsi/ginkgo/v2 v2.28.1 h1:S4hj+HbZp40fNKuLUQOYLDgZLwNUVn19N3Atb98NCyI=
|
github.com/onsi/ginkgo/v2 v2.32.0 h1:Hw7s2pVrQo/8Yz5N77qdnpHaoc+c6cC9WIV1Jce+J6E=
|
||||||
github.com/onsi/ginkgo/v2 v2.28.1/go.mod h1:CLtbVInNckU3/+gC8LzkGUb9oF+e8W8TdUsxPwvdOgE=
|
github.com/onsi/ginkgo/v2 v2.32.0/go.mod h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44=
|
||||||
github.com/onsi/gomega v1.39.1 h1:1IJLAad4zjPn2PsnhH70V4DKRFlrCzGBNrNaru+Vf28=
|
github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
|
||||||
github.com/onsi/gomega v1.39.1/go.mod h1:hL6yVALoTOxeWudERyfppUcZXjMwIMLnuSfruD2lcfg=
|
github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
|
||||||
github.com/otiai10/copy v1.2.0/go.mod h1:rrF5dJ5F0t/EWSYODDu4j9/vEeYHMkc8jt0zJChqQWw=
|
github.com/otiai10/copy v1.2.0/go.mod h1:rrF5dJ5F0t/EWSYODDu4j9/vEeYHMkc8jt0zJChqQWw=
|
||||||
github.com/otiai10/copy v1.14.0 h1:dCI/t1iTdYGtkvCuBG2BgR6KZa83PTclw4U5n2wAllU=
|
github.com/otiai10/copy v1.14.0 h1:dCI/t1iTdYGtkvCuBG2BgR6KZa83PTclw4U5n2wAllU=
|
||||||
github.com/otiai10/copy v1.14.0/go.mod h1:ECfuL02W+/FkTWZWgQqXPWZgW9oeKCSQ5qVfSc4qc4w=
|
github.com/otiai10/copy v1.14.0/go.mod h1:ECfuL02W+/FkTWZWgQqXPWZgW9oeKCSQ5qVfSc4qc4w=
|
||||||
|
|
@ -533,22 +548,23 @@ github.com/pandatix/go-cvss v0.6.2 h1:TFiHlzUkT67s6UkelHmK6s1INKVUG7nlKYiWWDTITG
|
||||||
github.com/pandatix/go-cvss v0.6.2/go.mod h1:jDXYlQBZrc8nvrMUVVvTG8PhmuShOnKrxP53nOFkt8Q=
|
github.com/pandatix/go-cvss v0.6.2/go.mod h1:jDXYlQBZrc8nvrMUVVvTG8PhmuShOnKrxP53nOFkt8Q=
|
||||||
github.com/pelletier/go-toml v1.9.5 h1:4yBQzkHv+7BHq2PQUZF3Mx0IYxG7LsP222s7Agd3ve8=
|
github.com/pelletier/go-toml v1.9.5 h1:4yBQzkHv+7BHq2PQUZF3Mx0IYxG7LsP222s7Agd3ve8=
|
||||||
github.com/pelletier/go-toml v1.9.5/go.mod h1:u1nR/EPcESfeI/szUZKdtJ0xRNbUoANCkoOuaOx1Y+c=
|
github.com/pelletier/go-toml v1.9.5/go.mod h1:u1nR/EPcESfeI/szUZKdtJ0xRNbUoANCkoOuaOx1Y+c=
|
||||||
github.com/pelletier/go-toml/v2 v2.2.4 h1:mye9XuhQ6gvn5h28+VilKrrPoQVanw5PMw/TB0t5Ec4=
|
github.com/pelletier/go-toml/v2 v2.4.3 h1:GTRvJQutkOSftxIFD5xw9aepkYNuPWmVJpffdDPYVpY=
|
||||||
github.com/pelletier/go-toml/v2 v2.2.4/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY=
|
github.com/pelletier/go-toml/v2 v2.4.3/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY=
|
||||||
github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea h1:sKwxy1H95npauwu8vtF95vG/syrL0p8fSZo/XlDg5gk=
|
github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea h1:sKwxy1H95npauwu8vtF95vG/syrL0p8fSZo/XlDg5gk=
|
||||||
github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea/go.mod h1:1VcHEd3ro4QMoHfiNl/j7Jkln9+KQuorp0PItHMJYNg=
|
github.com/peterbourgon/g2s v0.0.0-20170223122336-d4e7ad98afea/go.mod h1:1VcHEd3ro4QMoHfiNl/j7Jkln9+KQuorp0PItHMJYNg=
|
||||||
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c h1:+mdjkGKdHQG3305AYmdv1U2eRNDiU2ErMBj1gwrq8eQ=
|
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c h1:+mdjkGKdHQG3305AYmdv1U2eRNDiU2ErMBj1gwrq8eQ=
|
||||||
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c/go.mod h1:7rwL4CYBLnjLxUqIJNnCWiEdr3bn6IUYi15bNlnbCCU=
|
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c/go.mod h1:7rwL4CYBLnjLxUqIJNnCWiEdr3bn6IUYi15bNlnbCCU=
|
||||||
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 h1:GFCKgmp0tecUJ0sJuv4pzYCqS9+RGSn52M3FUwPs+uo=
|
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 h1:GFCKgmp0tecUJ0sJuv4pzYCqS9+RGSn52M3FUwPs+uo=
|
||||||
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10/go.mod h1:t/avpk3KcrXxUnYOhZhMXJlSEyie6gQbtLq5NM3loB8=
|
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10/go.mod h1:t/avpk3KcrXxUnYOhZhMXJlSEyie6gQbtLq5NM3loB8=
|
||||||
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
|
|
||||||
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||||
github.com/prometheus/client_golang v1.24.0 h1:5XStIklKuAtJSNpdD3s8XJj/Yv78IQmE1kbNk87JrAI=
|
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U=
|
||||||
github.com/prometheus/client_golang v1.24.0/go.mod h1:QcsNdotprC2nS4BTM2ucbcqxd2CeXTEa9jW7zHO9iDE=
|
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||||
|
github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU=
|
||||||
|
github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE=
|
||||||
github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
|
github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
|
||||||
github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
|
github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
|
||||||
github.com/prometheus/common v0.70.0 h1:bcpru3tWPVnxGnETLgOV5jbp/JRXgYEyv65CuBLAMMI=
|
github.com/prometheus/common v0.70.1 h1:1HvjP4D5oL3t8RsPlwxA9onvvStjtIHYE5XuuwOi/PY=
|
||||||
github.com/prometheus/common v0.70.0/go.mod h1:S/SFasQmgGiYH6C81LKCtYa8QACgthGg5zxL2udV7SY=
|
github.com/prometheus/common v0.70.1/go.mod h1:VdFUQDMZK3VLkurFUVhia6uys/0suUp86TJz5qbJRhc=
|
||||||
github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI=
|
github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI=
|
||||||
github.com/prometheus/procfs v0.21.1/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY=
|
github.com/prometheus/procfs v0.21.1/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY=
|
||||||
github.com/quasilyte/go-ruleguard v0.4.5 h1:AGY0tiOT5hJX9BTdx/xBdoCubQUAE2grkqY2lSwvZcA=
|
github.com/quasilyte/go-ruleguard v0.4.5 h1:AGY0tiOT5hJX9BTdx/xBdoCubQUAE2grkqY2lSwvZcA=
|
||||||
|
|
@ -561,15 +577,14 @@ github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727 h1:TCg2WBOl
|
||||||
github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727/go.mod h1:rlzQ04UMyJXu/aOvhd8qT+hvDrFpiwqp8MRXDY9szc0=
|
github.com/quasilyte/regex/syntax v0.0.0-20210819130434-b3f0c404a727/go.mod h1:rlzQ04UMyJXu/aOvhd8qT+hvDrFpiwqp8MRXDY9szc0=
|
||||||
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 h1:M8mH9eK4OUR4lu7Gd+PU1fV2/qnDNfzT635KRSObncs=
|
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567 h1:M8mH9eK4OUR4lu7Gd+PU1fV2/qnDNfzT635KRSObncs=
|
||||||
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567/go.mod h1:DWNGW8A4Y+GyBgPuaQJuWiy0XYftx4Xm/y5Jqk9I6VQ=
|
github.com/quasilyte/stdinfo v0.0.0-20220114132959-f7386bf02567/go.mod h1:DWNGW8A4Y+GyBgPuaQJuWiy0XYftx4Xm/y5Jqk9I6VQ=
|
||||||
github.com/raeperd/recvcheck v0.2.0 h1:GnU+NsbiCqdC2XX5+vMZzP+jAJC5fht7rcVTAhX74UI=
|
github.com/raeperd/recvcheck v0.3.0 h1:PM+XYvyxIj3bo+kobJfFTdTuU3Lmfu96mKDbyHDbRt8=
|
||||||
github.com/raeperd/recvcheck v0.2.0/go.mod h1:n04eYkwIR0JbgD73wT8wL4JjPC3wm0nFtzBnWNocnYU=
|
github.com/raeperd/recvcheck v0.3.0/go.mod h1:PZNwG+HztFYMH2ZPq0Hu3QgkV2yiA6VrtNz9c1fXWJo=
|
||||||
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE=
|
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE=
|
||||||
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo=
|
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo=
|
||||||
github.com/rivo/uniseg v0.2.0/go.mod h1:J6wj4VEh+S6ZtnVlnTBMWIodfgj8LQOQFoIToxlJtxc=
|
|
||||||
github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ=
|
github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ=
|
||||||
github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88=
|
github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88=
|
||||||
github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ=
|
github.com/rogpeppe/go-internal v1.16.0 h1:O9DK+vNMDVGLr2BeZqmpLeMjiMNkuXfcqntWbZV6S5g=
|
||||||
github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc=
|
github.com/rogpeppe/go-internal v1.16.0/go.mod h1:DrUVZyrJU+txYW5/1kwtXQSMFio52ZOxX7yM1VHvnxs=
|
||||||
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 h1:18kd+8ZUlt/ARXhljq+14TwAoKa61q6dX8jtwOf6DH8=
|
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529 h1:18kd+8ZUlt/ARXhljq+14TwAoKa61q6dX8jtwOf6DH8=
|
||||||
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529/go.mod h1:qe5TWALJ8/a1Lqznoc5BDHpYX/8HU60Hm2AwRmqzxqA=
|
github.com/rs/dnscache v0.0.0-20230804202142-fc85eb664529/go.mod h1:qe5TWALJ8/a1Lqznoc5BDHpYX/8HU60Hm2AwRmqzxqA=
|
||||||
github.com/rubyist/circuitbreaker v2.2.1+incompatible h1:KUKd/pV8Geg77+8LNDwdow6rVCAYOp8+kHUyFvL6Mhk=
|
github.com/rubyist/circuitbreaker v2.2.1+incompatible h1:KUKd/pV8Geg77+8LNDwdow6rVCAYOp8+kHUyFvL6Mhk=
|
||||||
|
|
@ -579,31 +594,31 @@ github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf
|
||||||
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
|
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
|
||||||
github.com/ryancurrah/gomodguard v1.4.1 h1:eWC8eUMNZ/wM/PWuZBv7JxxqT5fiIKSIyTvjb7Elr+g=
|
github.com/ryancurrah/gomodguard v1.4.1 h1:eWC8eUMNZ/wM/PWuZBv7JxxqT5fiIKSIyTvjb7Elr+g=
|
||||||
github.com/ryancurrah/gomodguard v1.4.1/go.mod h1:qnMJwV1hX9m+YJseXEBhd2s90+1Xn6x9dLz11ualI1I=
|
github.com/ryancurrah/gomodguard v1.4.1/go.mod h1:qnMJwV1hX9m+YJseXEBhd2s90+1Xn6x9dLz11ualI1I=
|
||||||
github.com/ryanrolds/sqlclosecheck v0.5.1 h1:dibWW826u0P8jNLsLN+En7+RqWWTYrjCB9fJfSfdyCU=
|
github.com/ryancurrah/gomodguard/v2 v2.1.3 h1:E7sz3PJwE9Ba1reVxSpF6XLCPJZ74Kfw/LabTNM4GIA=
|
||||||
github.com/ryanrolds/sqlclosecheck v0.5.1/go.mod h1:2g3dUjoS6AL4huFdv6wn55WpLIDjY7ZgUR4J8HOO/XQ=
|
github.com/ryancurrah/gomodguard/v2 v2.1.3/go.mod h1:CQicdLGatWMxLX53JzoBjYlsNZhHbmLv2AVa0s2aivU=
|
||||||
|
github.com/ryanrolds/sqlclosecheck v0.6.0 h1:pEyL9okISdg1F1SEpJNlrEotkTGerv5BMk7U4AG0eVg=
|
||||||
|
github.com/ryanrolds/sqlclosecheck v0.6.0/go.mod h1:xyX16hsDaCMXHrMJ3JMzGf5OpDfHTOTTQrT7HOFUmeU=
|
||||||
github.com/sanposhiho/wastedassign/v2 v2.1.0 h1:crurBF7fJKIORrV85u9UUpePDYGWnwvv3+A96WvwXT0=
|
github.com/sanposhiho/wastedassign/v2 v2.1.0 h1:crurBF7fJKIORrV85u9UUpePDYGWnwvv3+A96WvwXT0=
|
||||||
github.com/sanposhiho/wastedassign/v2 v2.1.0/go.mod h1:+oSmSC+9bQ+VUAxA66nBb0Z7N8CK7mscKTDYC6aIek4=
|
github.com/sanposhiho/wastedassign/v2 v2.1.0/go.mod h1:+oSmSC+9bQ+VUAxA66nBb0Z7N8CK7mscKTDYC6aIek4=
|
||||||
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 h1:KRzFb2m7YtdldCEkzs6KqmJw4nqEVZGK7IN2kJkjTuQ=
|
github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 h1:1EYB5IzjZawrrnELUi78f9fPu57HuXjmddZPjrls/28=
|
||||||
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
|
github.com/santhosh-tekuri/jsonschema/v6 v6.0.3/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
|
||||||
github.com/sashamelentyev/interfacebloat v1.1.0 h1:xdRdJp0irL086OyW1H/RTZTr1h/tMEOsumirXcOJqAw=
|
github.com/sashamelentyev/interfacebloat v1.1.0 h1:xdRdJp0irL086OyW1H/RTZTr1h/tMEOsumirXcOJqAw=
|
||||||
github.com/sashamelentyev/interfacebloat v1.1.0/go.mod h1:+Y9yU5YdTkrNvoX0xHc84dxiN1iBi9+G8zZIhPVoNjQ=
|
github.com/sashamelentyev/interfacebloat v1.1.0/go.mod h1:+Y9yU5YdTkrNvoX0xHc84dxiN1iBi9+G8zZIhPVoNjQ=
|
||||||
github.com/sashamelentyev/usestdlibvars v1.29.0 h1:8J0MoRrw4/NAXtjQqTHrbW9NN+3iMf7Knkq057v4XOQ=
|
github.com/sashamelentyev/usestdlibvars v1.29.0 h1:8J0MoRrw4/NAXtjQqTHrbW9NN+3iMf7Knkq057v4XOQ=
|
||||||
github.com/sashamelentyev/usestdlibvars v1.29.0/go.mod h1:8PpnjHMk5VdeWlVb4wCdrB8PNbLqZ3wBZTZWkrpZZL8=
|
github.com/sashamelentyev/usestdlibvars v1.29.0/go.mod h1:8PpnjHMk5VdeWlVb4wCdrB8PNbLqZ3wBZTZWkrpZZL8=
|
||||||
github.com/securego/gosec/v2 v2.23.0 h1:h4TtF64qFzvnkqvsHC/knT7YC5fqyOCItlVR8+ptEBo=
|
github.com/securego/gosec/v2 v2.28.0 h1:ZsSdiDb0AtTpLFVol5z91gbMei9ZiLEPG/pZjZujp7c=
|
||||||
github.com/securego/gosec/v2 v2.23.0/go.mod h1:qRHEgXLFuYUDkI2T7W7NJAmOkxVhkR0x9xyHOIcMNZ0=
|
github.com/securego/gosec/v2 v2.28.0/go.mod h1:lb4/9AHe+lJy/kjWmWRWWsEipvbwGKuxf+tY1Pmjdnk=
|
||||||
github.com/sergi/go-diff v1.2.0 h1:XU+rvMAioB0UC3q1MFrIQy4Vo5/4VsRDQQXHsEya6xQ=
|
github.com/sergi/go-diff v1.2.0 h1:XU+rvMAioB0UC3q1MFrIQy4Vo5/4VsRDQQXHsEya6xQ=
|
||||||
github.com/sergi/go-diff v1.2.0/go.mod h1:STckp+ISIX8hZLjrqAeVduY0gWCT9IjLuqbuNXdaHfM=
|
github.com/sergi/go-diff v1.2.0/go.mod h1:STckp+ISIX8hZLjrqAeVduY0gWCT9IjLuqbuNXdaHfM=
|
||||||
github.com/shurcooL/go v0.0.0-20180423040247-9e1955d9fb6e/go.mod h1:TDJrrUr11Vxrven61rcy3hJMUqaf/CLWYhHNPmT14Lk=
|
|
||||||
github.com/shurcooL/go-goon v0.0.0-20170922171312-37c2f522c041/go.mod h1:N5mDOmsrJOB+vfqUK+7DmDyjhSLIIBnXo9lvZJj3MWQ=
|
|
||||||
github.com/shurcooL/sanitized_anchor_name v1.0.0/go.mod h1:1NzhyTcUVG4SuEtjjoZeVRXNmyL/1OwPU0+IJeTBvfc=
|
github.com/shurcooL/sanitized_anchor_name v1.0.0/go.mod h1:1NzhyTcUVG4SuEtjjoZeVRXNmyL/1OwPU0+IJeTBvfc=
|
||||||
github.com/sirupsen/logrus v1.9.4 h1:TsZE7l11zFCLZnZ+teH4Umoq5BhEIfIzfRDZ1Uzql2w=
|
github.com/sirupsen/logrus v1.10.1 h1:xi4336Zh11WpU14fXR6I67V3yaTPQYwRx2WEtHbRg4Q=
|
||||||
github.com/sirupsen/logrus v1.9.4/go.mod h1:ftWc9WdOfJ0a92nsE2jF5u5ZwH8Bv2zdeOC42RjbV2g=
|
github.com/sirupsen/logrus v1.10.1/go.mod h1:vsQHnG7xzNsxk3NrwboUiWPnIC3dmbjcGPykD7+tiHk=
|
||||||
github.com/sivchari/containedctx v1.0.3 h1:x+etemjbsh2fB5ewm5FeLNi5bUjK0V8n0RB+Wwfd0XE=
|
github.com/sivchari/containedctx v1.0.3 h1:x+etemjbsh2fB5ewm5FeLNi5bUjK0V8n0RB+Wwfd0XE=
|
||||||
github.com/sivchari/containedctx v1.0.3/go.mod h1:c1RDvCbnJLtH4lLcYD/GqwiBSSf4F5Qk0xld2rBqzJ4=
|
github.com/sivchari/containedctx v1.0.3/go.mod h1:c1RDvCbnJLtH4lLcYD/GqwiBSSf4F5Qk0xld2rBqzJ4=
|
||||||
github.com/sonatard/noctx v0.4.0 h1:7MC/5Gg4SQ4lhLYR6mvOP6mQVSxCrdyiExo7atBs27o=
|
github.com/sonatard/noctx v0.5.1 h1:wklWg9c9ZYugOAk7qG4yP4PBrlQsmSLPTvW1K4PRQMs=
|
||||||
github.com/sonatard/noctx v0.4.0/go.mod h1:64XdbzFb18XL4LporKXp8poqZtPKbCrqQ402CV+kJas=
|
github.com/sonatard/noctx v0.5.1/go.mod h1:64XdbzFb18XL4LporKXp8poqZtPKbCrqQ402CV+kJas=
|
||||||
github.com/sourcegraph/go-diff v0.7.0 h1:9uLlrd5T46OXs5qpp8L/MTltk0zikUGi0sNNyCpA8G0=
|
github.com/sourcegraph/go-diff v0.8.0 h1:ipIyu4cTsLbIrln4l0qtHA3r0a7gyK4ntKjtQytHhvY=
|
||||||
github.com/sourcegraph/go-diff v0.7.0/go.mod h1:iBszgVvyxdc8SFZ7gm69go2KDdt3ag071iBaWPF6cjs=
|
github.com/sourcegraph/go-diff v0.8.0/go.mod h1:hWlcO7Al+UZStZAP8rBumHpCK5ZHQ5BXsMls8p4+F5E=
|
||||||
github.com/spdx/tools-golang v0.5.7 h1:+sWcKGnhwp3vLdMqPcLdA6QK679vd86cK9hQWH3AwCg=
|
github.com/spdx/tools-golang v0.5.7 h1:+sWcKGnhwp3vLdMqPcLdA6QK679vd86cK9hQWH3AwCg=
|
||||||
github.com/spdx/tools-golang v0.5.7/go.mod h1:jg7w0LOpoNAw6OxKEzCoqPC2GCTj45LyTlVmXubDsYw=
|
github.com/spdx/tools-golang v0.5.7/go.mod h1:jg7w0LOpoNAw6OxKEzCoqPC2GCTj45LyTlVmXubDsYw=
|
||||||
github.com/spf13/afero v1.15.0 h1:b/YBCLWAJdFWJTN9cLhiXXcD7mzKn9Dm86dNnfyQw1I=
|
github.com/spf13/afero v1.15.0 h1:b/YBCLWAJdFWJTN9cLhiXXcD7mzKn9Dm86dNnfyQw1I=
|
||||||
|
|
@ -628,14 +643,14 @@ github.com/ssgreg/nlreturn/v2 v2.2.1/go.mod h1:E/iiPB78hV7Szg2YfRgyIrk1AD6JVMTRk
|
||||||
github.com/stbenjam/no-sprintf-host-port v0.3.1 h1:AyX7+dxI4IdLBPtDbsGAyqiTSLpCP9hWRrXQDU4Cm/g=
|
github.com/stbenjam/no-sprintf-host-port v0.3.1 h1:AyX7+dxI4IdLBPtDbsGAyqiTSLpCP9hWRrXQDU4Cm/g=
|
||||||
github.com/stbenjam/no-sprintf-host-port v0.3.1/go.mod h1:ODbZesTCHMVKthBHskvUUexdcNHAQRXk9NpSsL8p/HQ=
|
github.com/stbenjam/no-sprintf-host-port v0.3.1/go.mod h1:ODbZesTCHMVKthBHskvUUexdcNHAQRXk9NpSsL8p/HQ=
|
||||||
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
||||||
github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY=
|
github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4=
|
||||||
github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA=
|
github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0=
|
||||||
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
|
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
|
||||||
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
|
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
|
||||||
github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4=
|
github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4=
|
||||||
github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
||||||
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
|
github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
|
||||||
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
|
github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
|
||||||
github.com/subosito/gotenv v1.4.1 h1:jyEFiXpy21Wm81FBN71l9VoMMV8H8jG+qIK3GCpY6Qs=
|
github.com/subosito/gotenv v1.4.1 h1:jyEFiXpy21Wm81FBN71l9VoMMV8H8jG+qIK3GCpY6Qs=
|
||||||
github.com/subosito/gotenv v1.4.1/go.mod h1:ayKnFf/c6rvx/2iiLrJUk1e6plDbT3edrFNGqEflhK0=
|
github.com/subosito/gotenv v1.4.1/go.mod h1:ayKnFf/c6rvx/2iiLrJUk1e6plDbT3edrFNGqEflhK0=
|
||||||
github.com/swaggo/swag v1.16.6 h1:qBNcx53ZaX+M5dxVyTrgQ0PJ/ACK+NzhwcbieTt+9yI=
|
github.com/swaggo/swag v1.16.6 h1:qBNcx53ZaX+M5dxVyTrgQ0PJ/ACK+NzhwcbieTt+9yI=
|
||||||
|
|
@ -646,10 +661,10 @@ github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3 h1:f+jULpR
|
||||||
github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3/go.mod h1:ON8b8w4BN/kE1EOhwT0o+d62W65a6aPw1nouo9LMgyY=
|
github.com/tenntenn/text/transform v0.0.0-20200319021203-7eef512accb3/go.mod h1:ON8b8w4BN/kE1EOhwT0o+d62W65a6aPw1nouo9LMgyY=
|
||||||
github.com/terminalstatic/go-xsd-validate v0.1.6 h1:TenYeQ3eY631qNi1/cTmLH/s2slHPRKTTHT+XSHkepo=
|
github.com/terminalstatic/go-xsd-validate v0.1.6 h1:TenYeQ3eY631qNi1/cTmLH/s2slHPRKTTHT+XSHkepo=
|
||||||
github.com/terminalstatic/go-xsd-validate v0.1.6/go.mod h1:18lsvYFofBflqCrvo1umpABZ99+GneNTw2kEEc8UPJw=
|
github.com/terminalstatic/go-xsd-validate v0.1.6/go.mod h1:18lsvYFofBflqCrvo1umpABZ99+GneNTw2kEEc8UPJw=
|
||||||
github.com/tetafro/godot v1.5.4 h1:u1ww+gqpRLiIA16yF2PV1CV1n/X3zhyezbNXC3E14Sg=
|
github.com/tetafro/godot v1.5.6 h1:IEkrFCwXaYHlOn4mGzGS3F3dkP6m9t0jpwqBFPIkKiA=
|
||||||
github.com/tetafro/godot v1.5.4/go.mod h1:eOkMrVQurDui411nBY2FA05EYH01r14LuWY/NrVDVcU=
|
github.com/tetafro/godot v1.5.6/go.mod h1:eOkMrVQurDui411nBY2FA05EYH01r14LuWY/NrVDVcU=
|
||||||
github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67 h1:9LPGD+jzxMlnk5r6+hJnar67cgpDIz/iyD+rfl5r2Vk=
|
github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4 h1:SiHe5XLTn9sFWJ5pBwJ5FN/4j34q9ZlOAD//kMoMYp0=
|
||||||
github.com/timakin/bodyclose v0.0.0-20241222091800-1db5c5ca4d67/go.mod h1:mkjARE7Yr8qU23YcGMSALbIxTQ9r9QBVahQOBRfU460=
|
github.com/timakin/bodyclose v0.0.0-20260129054331-73d1f95b84b4/go.mod h1:sDHLK7rb/59v/ZxZ7KtymgcoxuUMxjXq8gtu9VMOK8M=
|
||||||
github.com/timonwong/loggercheck v0.11.0 h1:jdaMpYBl+Uq9mWPXv1r8jc5fC3gyXx4/WGwTnnNKn4M=
|
github.com/timonwong/loggercheck v0.11.0 h1:jdaMpYBl+Uq9mWPXv1r8jc5fC3gyXx4/WGwTnnNKn4M=
|
||||||
github.com/timonwong/loggercheck v0.11.0/go.mod h1:HEAWU8djynujaAVX7QI65Myb8qgfcZ1uKbdpg3ZzKl8=
|
github.com/timonwong/loggercheck v0.11.0/go.mod h1:HEAWU8djynujaAVX7QI65Myb8qgfcZ1uKbdpg3ZzKl8=
|
||||||
github.com/tomarrell/wrapcheck/v2 v2.12.0 h1:H/qQ1aNWz/eeIhxKAFvkfIA+N7YDvq6TWVFL27Of9is=
|
github.com/tomarrell/wrapcheck/v2 v2.12.0 h1:H/qQ1aNWz/eeIhxKAFvkfIA+N7YDvq6TWVFL27Of9is=
|
||||||
|
|
@ -664,10 +679,10 @@ github.com/ultraware/whitespace v0.2.0 h1:TYowo2m9Nfj1baEQBjuHzvMRbp19i+RCcRYrSW
|
||||||
github.com/ultraware/whitespace v0.2.0/go.mod h1:XcP1RLD81eV4BW8UhQlpaR+SDc2givTvyI8a586WjW8=
|
github.com/ultraware/whitespace v0.2.0/go.mod h1:XcP1RLD81eV4BW8UhQlpaR+SDc2givTvyI8a586WjW8=
|
||||||
github.com/urfave/cli/v2 v2.3.0 h1:qph92Y649prgesehzOrQjdWyxFOp/QVM+6imKHad91M=
|
github.com/urfave/cli/v2 v2.3.0 h1:qph92Y649prgesehzOrQjdWyxFOp/QVM+6imKHad91M=
|
||||||
github.com/urfave/cli/v2 v2.3.0/go.mod h1:LJmUH05zAU44vOAcrfzZQKsZbVcdbOG8rtL3/XcUArI=
|
github.com/urfave/cli/v2 v2.3.0/go.mod h1:LJmUH05zAU44vOAcrfzZQKsZbVcdbOG8rtL3/XcUArI=
|
||||||
github.com/uudashr/gocognit v1.2.0 h1:3BU9aMr1xbhPlvJLSydKwdLN3tEUUrzPSSM8S4hDYRA=
|
github.com/uudashr/gocognit v1.2.1 h1:CSJynt5txTnORn/DkhiB4mZjwPuifyASC8/6Q0I/QS4=
|
||||||
github.com/uudashr/gocognit v1.2.0/go.mod h1:k/DdKPI6XBZO1q7HgoV2juESI2/Ofj9AcHPZhBBdrTU=
|
github.com/uudashr/gocognit v1.2.1/go.mod h1:acaubQc6xYlXFEMb9nWX2dYBzJ/bIjEkc1zzvyIZg5Q=
|
||||||
github.com/uudashr/iface v1.4.1 h1:J16Xl1wyNX9ofhpHmQ9h9gk5rnv2A6lX/2+APLTo0zU=
|
github.com/uudashr/iface v1.5.0 h1:PgdMt4uAettGG8K/Kbamc4B9FABgUgnS3TLbl6fnjEk=
|
||||||
github.com/uudashr/iface v1.4.1/go.mod h1:pbeBPlbuU2qkNDn0mmfrxP2X+wjPMIQAy+r1MBXSXtg=
|
github.com/uudashr/iface v1.5.0/go.mod h1:pbeBPlbuU2qkNDn0mmfrxP2X+wjPMIQAy+r1MBXSXtg=
|
||||||
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f h1:J9EGpcZtP0E/raorCMxlFGSTBrsSlaDGf3jU/qvAE2c=
|
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f h1:J9EGpcZtP0E/raorCMxlFGSTBrsSlaDGf3jU/qvAE2c=
|
||||||
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f/go.mod h1:N2zxlSyiKSe5eX1tZViRH5QA0qijqEDrYZiPEAiq3wU=
|
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f/go.mod h1:N2zxlSyiKSe5eX1tZViRH5QA0qijqEDrYZiPEAiq3wU=
|
||||||
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 h1:EzJWgHovont7NscjpAxXsDA8S8BMYve8Y5+7cuRE7R0=
|
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 h1:EzJWgHovont7NscjpAxXsDA8S8BMYve8Y5+7cuRE7R0=
|
||||||
|
|
@ -687,7 +702,6 @@ github.com/ykadowak/zerologlint v0.1.5/go.mod h1:KaUskqF3e/v59oPmdq1U1DnKcuHokl2
|
||||||
github.com/yuin/goldmark v1.1.25/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
github.com/yuin/goldmark v1.1.25/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||||
github.com/yuin/goldmark v1.1.32/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
github.com/yuin/goldmark v1.1.32/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||||
github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||||
github.com/yuin/goldmark v1.3.5/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k=
|
|
||||||
github.com/yuin/goldmark v1.4.1/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k=
|
github.com/yuin/goldmark v1.4.1/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k=
|
||||||
github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY=
|
github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY=
|
||||||
gitlab.com/bosi/decorder v0.4.2 h1:qbQaV3zgwnBZ4zPMhGLW4KZe7A7NwxEhJx39R3shffo=
|
gitlab.com/bosi/decorder v0.4.2 h1:qbQaV3zgwnBZ4zPMhGLW4KZe7A7NwxEhJx39R3shffo=
|
||||||
|
|
@ -696,20 +710,20 @@ go-simpler.org/assert v0.9.0 h1:PfpmcSvL7yAnWyChSjOz6Sp6m9j5lyK8Ok9pEL31YkQ=
|
||||||
go-simpler.org/assert v0.9.0/go.mod h1:74Eqh5eI6vCK6Y5l3PI8ZYFXG4Sa+tkr70OIPJAUr28=
|
go-simpler.org/assert v0.9.0/go.mod h1:74Eqh5eI6vCK6Y5l3PI8ZYFXG4Sa+tkr70OIPJAUr28=
|
||||||
go-simpler.org/musttag v0.14.0 h1:XGySZATqQYSEV3/YTy+iX+aofbZZllJaqwFWs+RTtSo=
|
go-simpler.org/musttag v0.14.0 h1:XGySZATqQYSEV3/YTy+iX+aofbZZllJaqwFWs+RTtSo=
|
||||||
go-simpler.org/musttag v0.14.0/go.mod h1:uP8EymctQjJ4Z1kUnjX0u2l60WfUdQxCwSNKzE1JEOE=
|
go-simpler.org/musttag v0.14.0/go.mod h1:uP8EymctQjJ4Z1kUnjX0u2l60WfUdQxCwSNKzE1JEOE=
|
||||||
go-simpler.org/sloglint v0.11.1 h1:xRbPepLT/MHPTCA6TS/wNfZrDzkGvCCqUv4Bdwc3H7s=
|
go-simpler.org/sloglint v0.12.0 h1:UzWDlLWNE5FLqsvyq3tWYHuQMbqrervOhT8qPl4Mmw4=
|
||||||
go-simpler.org/sloglint v0.11.1/go.mod h1:2PowwiCOK8mjiF+0KGifVOT8ZsCNiFzvfyJeJOIt8MQ=
|
go-simpler.org/sloglint v0.12.0/go.mod h1:jBjjC2bm8rYrs88oTRlFX497kWjJsyZWYoNaXkGRI6I=
|
||||||
go.augendre.info/arangolint v0.4.0 h1:xSCZjRoS93nXazBSg5d0OGCi9APPLNMmmLrC995tR50=
|
go.augendre.info/arangolint v0.4.0 h1:xSCZjRoS93nXazBSg5d0OGCi9APPLNMmmLrC995tR50=
|
||||||
go.augendre.info/arangolint v0.4.0/go.mod h1:l+f/b4plABuFISuKnTGD4RioXiCCgghv2xqst/xOvAA=
|
go.augendre.info/arangolint v0.4.0/go.mod h1:l+f/b4plABuFISuKnTGD4RioXiCCgghv2xqst/xOvAA=
|
||||||
go.augendre.info/fatcontext v0.9.0 h1:Gt5jGD4Zcj8CDMVzjOJITlSb9cEch54hjRRlN3qDojE=
|
go.augendre.info/fatcontext v0.10.0 h1:HhFopmivh8U1+AU7f0kuwUeg2eiIns7YsGQOMHwSJ90=
|
||||||
go.augendre.info/fatcontext v0.9.0/go.mod h1:L94brOAT1OOUNue6ph/2HnwxoNlds9aXDF2FcUntbNw=
|
go.augendre.info/fatcontext v0.10.0/go.mod h1:pqpGvA9GlrXy+aXkp8L2dKz12Zp4g2FhzcAtwToU+2w=
|
||||||
go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64=
|
go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64=
|
||||||
go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y=
|
go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y=
|
||||||
go.opentelemetry.io/contrib/detectors/gcp v1.43.0 h1:62yY3dT7/ShwOxzA0RsKRgshBmfElKI4d/Myu2OxDFU=
|
go.opentelemetry.io/contrib/detectors/gcp v1.43.0 h1:62yY3dT7/ShwOxzA0RsKRgshBmfElKI4d/Myu2OxDFU=
|
||||||
go.opentelemetry.io/contrib/detectors/gcp v1.43.0/go.mod h1:RyaZMFY7yi1kAs45S6mbFGz8O8rqB0dTY14uzvG4LCs=
|
go.opentelemetry.io/contrib/detectors/gcp v1.43.0/go.mod h1:RyaZMFY7yi1kAs45S6mbFGz8O8rqB0dTY14uzvG4LCs=
|
||||||
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0 h1:yI1/OhfEPy7J9eoa6Sj051C7n5dvpj0QX8g4sRchg04=
|
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0 h1:yI1/OhfEPy7J9eoa6Sj051C7n5dvpj0QX8g4sRchg04=
|
||||||
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0/go.mod h1:NoUCKYWK+3ecatC4HjkRktREheMeEtrXoQxrqYFeHSc=
|
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0/go.mod h1:NoUCKYWK+3ecatC4HjkRktREheMeEtrXoQxrqYFeHSc=
|
||||||
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0 h1:OyrsyzuttWTSur2qN/Lm0m2a8yqyIjUVBZcxFPuXq2o=
|
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo=
|
||||||
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0/go.mod h1:C2NGBr+kAB4bk3xtMXfZ94gqFDtg/GkI7e9zqGh5Beg=
|
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI=
|
||||||
go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU=
|
go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU=
|
||||||
go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc=
|
go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc=
|
||||||
go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc=
|
go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc=
|
||||||
|
|
@ -730,51 +744,43 @@ go.uber.org/zap v1.27.1 h1:08RqriUEv8+ArZRYSTXy1LeBScaMpVSTBhCeaZYfMYc=
|
||||||
go.uber.org/zap v1.27.1/go.mod h1:GB2qFLM7cTU87MWRP2mPIjqfIDnGu+VIO4V/SdhGo2E=
|
go.uber.org/zap v1.27.1/go.mod h1:GB2qFLM7cTU87MWRP2mPIjqfIDnGu+VIO4V/SdhGo2E=
|
||||||
go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ=
|
go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ=
|
||||||
go.yaml.in/yaml/v2 v2.4.4/go.mod h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ=
|
go.yaml.in/yaml/v2 v2.4.4/go.mod h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ=
|
||||||
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
|
|
||||||
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
|
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
|
||||||
|
go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
|
||||||
|
go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg=
|
||||||
gocloud.dev v0.46.0 h1:niIuZwSjMtBx8K+ITB2s5kZullB13PGOS2ZoQPZxQ4Q=
|
gocloud.dev v0.46.0 h1:niIuZwSjMtBx8K+ITB2s5kZullB13PGOS2ZoQPZxQ4Q=
|
||||||
gocloud.dev v0.46.0/go.mod h1:ACQe+2qO+hEO+pdcvvsM+RB63r8TyGD1W3ESCLFyzvM=
|
gocloud.dev v0.46.0/go.mod h1:ACQe+2qO+hEO+pdcvvsM+RB63r8TyGD1W3ESCLFyzvM=
|
||||||
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
|
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
|
||||||
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
|
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
|
||||||
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
|
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
|
||||||
golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
|
golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
|
||||||
golang.org/x/crypto v0.13.0/go.mod h1:y6Z2r+Rw4iayiXXAIxJIDAJ1zMW4yaTpebo8fPOliYc=
|
golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
|
||||||
golang.org/x/crypto v0.14.0/go.mod h1:MVFd36DqK4CsrnJYDkBA3VC4m2GkXAM0PvzMCn4JQf4=
|
golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
|
||||||
golang.org/x/crypto v0.53.0 h1:QZ4Muo8THX6CizN2vPPd5fBGHyogrdK9fG4wLPFUsto=
|
|
||||||
golang.org/x/crypto v0.53.0/go.mod h1:DNLU434OwVakk9PzuwV8w62mAJpRJL3vsgcfp4Qnsio=
|
|
||||||
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa h1:Zt3DZoOFFYkKhDT3v7Lm9FDMEV06GpzjG2jrqW+QTE0=
|
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa h1:Zt3DZoOFFYkKhDT3v7Lm9FDMEV06GpzjG2jrqW+QTE0=
|
||||||
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa/go.mod h1:K79w1Vqn7PoiZn+TkNpx3BUWUQksGO3JcVX6qIjytmA=
|
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa/go.mod h1:K79w1Vqn7PoiZn+TkNpx3BUWUQksGO3JcVX6qIjytmA=
|
||||||
golang.org/x/exp/typeparams v0.0.0-20220428152302-39d4317da171/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk=
|
golang.org/x/exp/typeparams v0.0.0-20220428152302-39d4317da171/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk=
|
||||||
golang.org/x/exp/typeparams v0.0.0-20230203172020-98cc5a0785f9/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk=
|
golang.org/x/exp/typeparams v0.0.0-20230203172020-98cc5a0785f9/go.mod h1:AbB0pIl9nAr9wVwH+Z2ZpaocVmF5I4GyWCDIsVjR0bk=
|
||||||
golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358 h1:qWFG1Dj7TBjOjOvhEOkmyGPVoquqUKnIU0lEVLp8xyk=
|
golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f h1:+lI8cDJ4uceLipg2f1ODay7fEuLkk0BIHXd6PB8icxo=
|
||||||
golang.org/x/exp/typeparams v0.0.0-20260209203927-2842357ff358/go.mod h1:4Mzdyp/6jzw9auFDJ3OMF5qksa7UvPnzKqTVGcb04ms=
|
golang.org/x/exp/typeparams v0.0.0-20260811152304-ee035b5b010f/go.mod h1:PqrXSW65cXDZH0k4IeUbhmg/bcAZDbzNz3byBpKCsXo=
|
||||||
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||||
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||||
golang.org/x/mod v0.4.1/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
golang.org/x/mod v0.4.1/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||||
golang.org/x/mod v0.4.2/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
|
||||||
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3/go.mod h1:3p9vT2HGsQu2K1YbXdKPJLVgG5VJdoTa1poYQBtP1AY=
|
golang.org/x/mod v0.6.0-dev.0.20220106191415-9b9b3d81d5e3/go.mod h1:3p9vT2HGsQu2K1YbXdKPJLVgG5VJdoTa1poYQBtP1AY=
|
||||||
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
|
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
|
||||||
golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
|
golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
|
||||||
golang.org/x/mod v0.12.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
|
golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs=
|
||||||
golang.org/x/mod v0.13.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
|
golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE=
|
||||||
golang.org/x/mod v0.37.0 h1:vF1DjpVEshcIqoEaauuHebaLk1O1forxjxBaVn884JQ=
|
|
||||||
golang.org/x/mod v0.37.0/go.mod h1:m8S8VeM9r4dzDwjrKO0a1sZP3YjeMamRRlD+fmR2Q/0=
|
|
||||||
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
|
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
|
||||||
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
||||||
golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
||||||
golang.org/x/net v0.0.0-20200625001655-4c5254603344/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA=
|
golang.org/x/net v0.0.0-20200625001655-4c5254603344/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA=
|
||||||
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
|
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
|
||||||
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
|
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
|
||||||
golang.org/x/net v0.0.0-20210405180319-a5a99cb37ef4/go.mod h1:p54w0d4576C0XHj96bSt6lcn1PtDYWL6XObtHCRCNQM=
|
|
||||||
golang.org/x/net v0.0.0-20210421230115-4e50805a0758/go.mod h1:72T/g9IO56b78aLF+1Kcs5dz7/ng1VjMUvfKvpfy+jM=
|
golang.org/x/net v0.0.0-20210421230115-4e50805a0758/go.mod h1:72T/g9IO56b78aLF+1Kcs5dz7/ng1VjMUvfKvpfy+jM=
|
||||||
golang.org/x/net v0.0.0-20211015210444-4f30a5c0130f/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
|
golang.org/x/net v0.0.0-20211015210444-4f30a5c0130f/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
|
||||||
golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c=
|
golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c=
|
||||||
golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
|
golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
|
||||||
golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg=
|
golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=
|
||||||
golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk=
|
golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU=
|
||||||
golang.org/x/net v0.16.0/go.mod h1:NxSsAGuq816PNPmqtQdLE42eU2Fs7NoRIZrHJAlaCOE=
|
|
||||||
golang.org/x/net v0.56.0 h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=
|
|
||||||
golang.org/x/net v0.56.0/go.mod h1:D3Ku6r+V6JROoZK144D2XfMHFcMq/0zSfLelVTCFKec=
|
|
||||||
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
|
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
|
||||||
golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
|
golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
|
||||||
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
|
|
@ -784,8 +790,6 @@ golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJ
|
||||||
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
golang.org/x/sync v0.3.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y=
|
|
||||||
golang.org/x/sync v0.4.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y=
|
|
||||||
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
|
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
|
||||||
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
|
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
|
||||||
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||||
|
|
@ -794,10 +798,8 @@ golang.org/x/sys v0.0.0-20200323222414-85ca7c5b95cd/go.mod h1:h1NjWce9XRLGQEsW7w
|
||||||
golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||||
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||||
golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||||
golang.org/x/sys v0.0.0-20210330210617-4fbd30eecc44/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
|
||||||
golang.org/x/sys v0.0.0-20210420072515-93ed5bcd2bfe/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.0.0-20210420072515-93ed5bcd2bfe/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||||
golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||||
golang.org/x/sys v0.0.0-20210510120138-977fb7262007/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
|
||||||
golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||||
golang.org/x/sys v0.0.0-20211019181941-9d821ace8654/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
golang.org/x/sys v0.0.0-20211019181941-9d821ace8654/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||||
golang.org/x/sys v0.0.0-20211105183446-c75c47738b0c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
golang.org/x/sys v0.0.0-20211105183446-c75c47738b0c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||||
|
|
@ -805,28 +807,19 @@ golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBc
|
||||||
golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||||
golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||||
golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||||
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
|
||||||
golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
|
||||||
golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
|
||||||
golang.org/x/sys v0.13.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
|
||||||
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
|
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
|
||||||
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
|
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
|
||||||
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
|
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
|
||||||
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
|
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
|
||||||
golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k=
|
golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k=
|
||||||
golang.org/x/term v0.8.0/go.mod h1:xPskH00ivmX89bAKVGSKKtLOWNx2+17Eiy94tnKShWo=
|
|
||||||
golang.org/x/term v0.12.0/go.mod h1:owVbMEjm3cBLCHdkQu9b1opXd4ETQWc3BhuQGKgXgvU=
|
|
||||||
golang.org/x/term v0.13.0/go.mod h1:LTmsnFJwVN6bCy1rVCoS+qHT1HhALEFxKncY3WNNh4U=
|
|
||||||
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
||||||
golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk=
|
golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk=
|
||||||
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
|
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
|
||||||
golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
|
golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
|
||||||
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
|
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
|
||||||
golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
|
golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
|
||||||
golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8=
|
golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
|
||||||
golang.org/x/text v0.13.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE=
|
golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
|
||||||
golang.org/x/text v0.38.0 h1:sXmwo9DwP3OK9EZ7PqAdaooSGozfl/3a6/xJcbzPRhE=
|
|
||||||
golang.org/x/text v0.38.0/go.mod h1:YXZt3QhHUKYT53r2lLKFIVi6Ao1jdzrTR/KQ09qyxF4=
|
|
||||||
golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
|
golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
|
||||||
golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno=
|
golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno=
|
||||||
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
|
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
|
||||||
|
|
@ -835,14 +828,11 @@ golang.org/x/tools v0.0.0-20200329025819-fd4102a86c65/go.mod h1:Sl4aGygMT6LrqrWc
|
||||||
golang.org/x/tools v0.0.0-20200724022722-7017fd6b1305/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA=
|
golang.org/x/tools v0.0.0-20200724022722-7017fd6b1305/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA=
|
||||||
golang.org/x/tools v0.1.1-0.20210205202024-ef80cdb6ec6d/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU=
|
golang.org/x/tools v0.1.1-0.20210205202024-ef80cdb6ec6d/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU=
|
||||||
golang.org/x/tools v0.1.1-0.20210302220138-2ac05c832e1a/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU=
|
golang.org/x/tools v0.1.1-0.20210302220138-2ac05c832e1a/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU=
|
||||||
golang.org/x/tools v0.1.1/go.mod h1:o0xws9oXOQQZyjljx8fwUC0k7L1pTE6eaCbjGeHmOkk=
|
|
||||||
golang.org/x/tools v0.1.10/go.mod h1:Uh6Zz+xoGYZom868N8YTex3t7RhtHDBrE8Gzo9bV56E=
|
golang.org/x/tools v0.1.10/go.mod h1:Uh6Zz+xoGYZom868N8YTex3t7RhtHDBrE8Gzo9bV56E=
|
||||||
golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc=
|
golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc=
|
||||||
golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU=
|
golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU=
|
||||||
golang.org/x/tools v0.13.0/go.mod h1:HvlwmtVNQAhOuCjW7xxvovg8wbNq7LwfXh/k7wXUl58=
|
golang.org/x/tools v0.49.0 h1:3NI7VXzL9+1WZD52Dx2ttoPwD5DWrFGpl9mFZDlmisI=
|
||||||
golang.org/x/tools v0.14.0/go.mod h1:uYBEerGOWcJyEORxN+Ek8+TT266gXkNlHdJBwexUsBg=
|
golang.org/x/tools v0.49.0/go.mod h1:SJNXV9DBKT0UbdttsQjbfJlAE/q+y36++zo3uL3N0Oo=
|
||||||
golang.org/x/tools v0.47.0 h1:7Kn5x/d1svx/PzryTsqeoZN4TZwqeH5pGWjefhLi/1Q=
|
|
||||||
golang.org/x/tools v0.47.0/go.mod h1:dFHnyTvFWY212G+h7ZY4Vsp/K3U4/7W9TyVaAul8uCA=
|
|
||||||
golang.org/x/tools/go/expect v0.1.1-deprecated h1:jpBZDwmgPhXsKZC6WhL20P4b/wmnpsEAGHaNy0n/rJM=
|
golang.org/x/tools/go/expect v0.1.1-deprecated h1:jpBZDwmgPhXsKZC6WhL20P4b/wmnpsEAGHaNy0n/rJM=
|
||||||
golang.org/x/tools/go/expect v0.1.1-deprecated/go.mod h1:eihoPOH+FgIqa3FpoTwguz/bVUSGBlGQU67vpBeOrBY=
|
golang.org/x/tools/go/expect v0.1.1-deprecated/go.mod h1:eihoPOH+FgIqa3FpoTwguz/bVUSGBlGQU67vpBeOrBY=
|
||||||
golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated h1:1h2MnaIAIXISqTFKdENegdpAgUXz6NrPEsbIeWaBRvM=
|
golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated h1:1h2MnaIAIXISqTFKdENegdpAgUXz6NrPEsbIeWaBRvM=
|
||||||
|
|
@ -855,18 +845,18 @@ golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da h1:noIWHXmPHxILtqtCOPIhS
|
||||||
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da/go.mod h1:NDW/Ps6MPRej6fsCIbMTohpP40sJ/P/vI1MoTEGwX90=
|
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da/go.mod h1:NDW/Ps6MPRej6fsCIbMTohpP40sJ/P/vI1MoTEGwX90=
|
||||||
gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4=
|
gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4=
|
||||||
gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E=
|
gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E=
|
||||||
google.golang.org/api v0.272.0 h1:eLUQZGnAS3OHn31URRf9sAmRk3w2JjMx37d2k8AjJmA=
|
google.golang.org/api v0.288.0 h1:glhO/J88obKP5I269W3hB73dvBKrjU56ZfmNlNXpgTU=
|
||||||
google.golang.org/api v0.272.0/go.mod h1:wKjowi5LNJc5qarNvDCvNQBn3rVK8nSy6jg2SwRwzIA=
|
google.golang.org/api v0.288.0/go.mod h1:lM2kYRzYUCBY91P9h6VF1PYmvhxii3O5hji37qRvIcY=
|
||||||
google.golang.org/genproto v0.0.0-20260316180232-0b37fe3546d5 h1:JNfk58HZ8lfmXbYK2vx/UvsqIL59TzByCxPIX4TDmsE=
|
google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 h1:XzmzkmB14QhVhgnawEVsOn6OFsnpyxNPRY9QV01dNB0=
|
||||||
google.golang.org/genproto v0.0.0-20260316180232-0b37fe3546d5/go.mod h1:x5julN69+ED4PcFk/XWayw35O0lf/nGa4aNgODCmNmw=
|
google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7/go.mod h1:L43LFes82YgSonw6iTXTxXUX1OlULt4AQtkik4ULL/I=
|
||||||
google.golang.org/genproto/googleapis/api v0.0.0-20260414002931-afd174a4e478 h1:yQugLulqltosq0B/f8l4w9VryjV+N/5gcW0jQ3N8Qec=
|
google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 h1:jQ9p21COKWjP3VwuFrNRiiOTMh3mPpN45R7SLrH/HUU=
|
||||||
google.golang.org/genproto/googleapis/api v0.0.0-20260414002931-afd174a4e478/go.mod h1:C6ADNqOxbgdUUeRTU+LCHDPB9ttAMCTff6auwCVa4uc=
|
google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7/go.mod h1:KqHwBx2upmfa1XSi1WuRvC+2VGCLtooKkfmyvRbUmqA=
|
||||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478 h1:RmoJA1ujG+/lRGNfUnOMfhCy5EipVMyvUE+KNbPbTlw=
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 h1:qEHAMpSaUhtD0p3NbEEI83HwNGFxEwaSJ1G9PLnCBZE=
|
||||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
|
||||||
google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=
|
google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=
|
||||||
google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA=
|
google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA=
|
||||||
google.golang.org/protobuf v1.36.11 h1:fV6ZwhNocDyBLK0dj+fg8ektcVegBBuEolpbTQyBNVE=
|
google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc=
|
||||||
google.golang.org/protobuf v1.36.11/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
|
google.golang.org/protobuf v1.36.12/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
|
||||||
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||||
gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||||
gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||||
|
|
@ -882,10 +872,10 @@ gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C
|
||||||
gopkg.in/yaml.v3 v3.0.0-20200615113413-eeeca48fe776/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
gopkg.in/yaml.v3 v3.0.0-20200615113413-eeeca48fe776/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
||||||
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
|
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
|
||||||
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
||||||
honnef.co/go/tools v0.7.0 h1:w6WUp1VbkqPEgLz4rkBzH/CSU6HkoqNLp6GstyTx3lU=
|
honnef.co/go/tools v0.8.0 h1:UacpzPr7D6i5BAjTkA7sNVcx4kIbhAZcQ4zYtKiXx68=
|
||||||
honnef.co/go/tools v0.7.0/go.mod h1:pm29oPxeP3P82ISxZDgIYeOaf9ta6Pi0EWvCFoLG2vc=
|
honnef.co/go/tools v0.8.0/go.mod h1:XA+OnlRA9EDh/ukGvXMNSZNKGwFQJ+5dER0ioUkOxks=
|
||||||
modernc.org/cc/v4 v4.29.0 h1:CXgwL8cvxmyzBQZzbSl/6xFtMCryb6u8IOqDci39cgc=
|
modernc.org/cc/v4 v4.29.1 h1:MKgdCV3WykTSPqpVrnxdEDS0HEd2FHpKZDzxzU5LyeI=
|
||||||
modernc.org/cc/v4 v4.29.0/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
|
modernc.org/cc/v4 v4.29.1/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
|
||||||
modernc.org/ccgo/v4 v4.34.6 h1:sBgfIwyN0TQ9C5hwIeuqyeAKyMWnbvj2fvpF4L11uzU=
|
modernc.org/ccgo/v4 v4.34.6 h1:sBgfIwyN0TQ9C5hwIeuqyeAKyMWnbvj2fvpF4L11uzU=
|
||||||
modernc.org/ccgo/v4 v4.34.6/go.mod h1:SZ8YcN9NG7XVsQYdm6jYBvi8PQP1qi+kqB6OhjqI3Fk=
|
modernc.org/ccgo/v4 v4.34.6/go.mod h1:SZ8YcN9NG7XVsQYdm6jYBvi8PQP1qi+kqB6OhjqI3Fk=
|
||||||
modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM=
|
modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM=
|
||||||
|
|
@ -896,8 +886,8 @@ modernc.org/gc/v3 v3.1.4 h1:2g65LGVSmFQrXeITAw97x7hCRvZFcyE1uDP+7Vng7JI=
|
||||||
modernc.org/gc/v3 v3.1.4/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
|
modernc.org/gc/v3 v3.1.4/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
|
||||||
modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks=
|
modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks=
|
||||||
modernc.org/goabi0 v0.2.0/go.mod h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI=
|
modernc.org/goabi0 v0.2.0/go.mod h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI=
|
||||||
modernc.org/libc v1.74.1 h1:bdR4VTKFMC4966QSNZ05XLGI/VwzVa2kTUX51Dm0riQ=
|
modernc.org/libc v1.74.4 h1:fX1Omw4o2/1C2iRkkIsrQTasJQldLhRmuPreXLoWs9k=
|
||||||
modernc.org/libc v1.74.1/go.mod h1:uH4t5bOx3G3g9Xcmj10YKlTcVISlRDwv8VoQJG9n8Os=
|
modernc.org/libc v1.74.4/go.mod h1:eeQAS9W3sZeKYMFubydxJpII9ybHWshk+7or7bLG9co=
|
||||||
modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU=
|
modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU=
|
||||||
modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg=
|
modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg=
|
||||||
modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI=
|
modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI=
|
||||||
|
|
@ -906,15 +896,15 @@ modernc.org/opt v0.2.0 h1:tGyef5ApycA7FSEOMraay9SaTk5zmbx7Tu+cJs4QKZg=
|
||||||
modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns=
|
modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns=
|
||||||
modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w=
|
modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w=
|
||||||
modernc.org/sortutil v1.2.1/go.mod h1:7ZI3a3REbai7gzCLcotuw9AC4VZVpYMjDzETGsSMqJE=
|
modernc.org/sortutil v1.2.1/go.mod h1:7ZI3a3REbai7gzCLcotuw9AC4VZVpYMjDzETGsSMqJE=
|
||||||
modernc.org/sqlite v1.55.0 h1:hIFh0MCH0rGinQ/4KYb5/UbCkRkb+UP+OkLCVWa5MTM=
|
modernc.org/sqlite v1.56.0 h1:/D8e2RfFqoy/Zc6PuC76U28zFwmI/sYx1Kjm4yEn9e0=
|
||||||
modernc.org/sqlite v1.55.0/go.mod h1:4ntCLuNmnH8+GNqjka1wNg7KJd5/Hi5FYp8K+XQ7GZw=
|
modernc.org/sqlite v1.56.0/go.mod h1:yCJ2cmAaIkHQ25oXWrF8H4O1lIfPYPR26yCEDj2P3pQ=
|
||||||
modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0=
|
modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0=
|
||||||
modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A=
|
modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A=
|
||||||
modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y=
|
modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y=
|
||||||
modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM=
|
modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM=
|
||||||
mvdan.cc/gofumpt v0.9.2 h1:zsEMWL8SVKGHNztrx6uZrXdp7AX8r421Vvp23sz7ik4=
|
mvdan.cc/gofumpt v0.11.0 h1:0H01XB95PnN2QgCSR9ELdZyTlJqNZ7181B0BTMh5VZc=
|
||||||
mvdan.cc/gofumpt v0.9.2/go.mod h1:iB7Hn+ai8lPvofHd9ZFGVg2GOr8sBUw1QUWjNbmIL/s=
|
mvdan.cc/gofumpt v0.11.0/go.mod h1:BeT5wCsOJt6J9zT2MZIOGszjUHzFkn1/l9g6xAzqsXo=
|
||||||
mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15 h1:ssMzja7PDPJV8FStj7hq9IKiuiKhgz9ErWw+m68e7DI=
|
mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673 h1:dEE6li4OPIE54oojY2qaayFS1fSp17G14si0gXRxl0U=
|
||||||
mvdan.cc/unparam v0.0.0-20251027182757-5beb8c8f8f15/go.mod h1:4M5MMXl2kW6fivUT6yRGpLLPNfuGtU2Z0cPvFquGDYU=
|
mvdan.cc/unparam v0.0.0-20260818115549-3f964bcb5673/go.mod h1:62roFV3D3nYOWIXv3PfGO4UYEKAotz2WgLywT87ONd8=
|
||||||
sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs=
|
sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs=
|
||||||
sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4=
|
sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4=
|
||||||
|
|
|
||||||
109
internal/accesslog/accesslog.go
Normal file
109
internal/accesslog/accesslog.go
Normal file
|
|
@ -0,0 +1,109 @@
|
||||||
|
// Package accesslog writes proxy activity as JSON Lines.
|
||||||
|
package accesslog
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"net/url"
|
||||||
|
"os"
|
||||||
|
"sync"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
accessLogFileMode os.FileMode = 0o600
|
||||||
|
|
||||||
|
// EventRequest identifies the response sent by the proxy to a client.
|
||||||
|
EventRequest = "request"
|
||||||
|
// EventUpstream identifies one HTTP exchange with an upstream service.
|
||||||
|
EventUpstream = "upstream"
|
||||||
|
)
|
||||||
|
|
||||||
|
type requestIDKey struct{}
|
||||||
|
|
||||||
|
// Entry is one proxy activity record.
|
||||||
|
type Entry struct {
|
||||||
|
Time time.Time `json:"time"`
|
||||||
|
Event string `json:"event"`
|
||||||
|
RequestID string `json:"request_id,omitempty"`
|
||||||
|
Method string `json:"method"`
|
||||||
|
Path string `json:"path,omitempty"`
|
||||||
|
URL string `json:"url,omitempty"`
|
||||||
|
StatusCode int `json:"status_code,omitempty"`
|
||||||
|
DurationMS int64 `json:"duration_ms"`
|
||||||
|
RemoteAddr string `json:"remote_addr,omitempty"`
|
||||||
|
Error string `json:"error,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// Logger appends complete JSON objects to a file, one per line.
|
||||||
|
type Logger struct {
|
||||||
|
mu sync.Mutex
|
||||||
|
file *os.File
|
||||||
|
encoder *json.Encoder
|
||||||
|
}
|
||||||
|
|
||||||
|
// Open opens path for append, creating it with owner-only permissions when needed.
|
||||||
|
func Open(path string) (*Logger, error) {
|
||||||
|
file, err := os.OpenFile(path, os.O_APPEND|os.O_CREATE|os.O_WRONLY, accessLogFileMode)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("opening access log: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
return &Logger{
|
||||||
|
file: file,
|
||||||
|
encoder: json.NewEncoder(file),
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// Write appends an entry to the log.
|
||||||
|
func (l *Logger) Write(entry Entry) error {
|
||||||
|
if entry.Time.IsZero() {
|
||||||
|
entry.Time = time.Now().UTC()
|
||||||
|
}
|
||||||
|
|
||||||
|
l.mu.Lock()
|
||||||
|
defer l.mu.Unlock()
|
||||||
|
|
||||||
|
if err := l.encoder.Encode(entry); err != nil {
|
||||||
|
return fmt.Errorf("writing access log: %w", err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// Close closes the log file after any active writer finishes.
|
||||||
|
func (l *Logger) Close() error {
|
||||||
|
l.mu.Lock()
|
||||||
|
defer l.mu.Unlock()
|
||||||
|
|
||||||
|
if err := l.file.Close(); err != nil {
|
||||||
|
return fmt.Errorf("closing access log: %w", err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// WithRequestID stores a proxy request ID in ctx.
|
||||||
|
func WithRequestID(ctx context.Context, requestID string) context.Context {
|
||||||
|
return context.WithValue(ctx, requestIDKey{}, requestID)
|
||||||
|
}
|
||||||
|
|
||||||
|
// RequestID returns the proxy request ID stored in ctx.
|
||||||
|
func RequestID(ctx context.Context) string {
|
||||||
|
requestID, _ := ctx.Value(requestIDKey{}).(string)
|
||||||
|
return requestID
|
||||||
|
}
|
||||||
|
|
||||||
|
// URLWithoutSecrets returns a URL without user information, query values, or fragments.
|
||||||
|
func URLWithoutSecrets(value *url.URL) string {
|
||||||
|
if value == nil {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
|
clean := *value
|
||||||
|
clean.User = nil
|
||||||
|
clean.RawQuery = ""
|
||||||
|
clean.ForceQuery = false
|
||||||
|
clean.Fragment = ""
|
||||||
|
clean.RawFragment = ""
|
||||||
|
return clean.String()
|
||||||
|
}
|
||||||
91
internal/accesslog/accesslog_test.go
Normal file
91
internal/accesslog/accesslog_test.go
Normal file
|
|
@ -0,0 +1,91 @@
|
||||||
|
package accesslog
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bufio"
|
||||||
|
"context"
|
||||||
|
"encoding/json"
|
||||||
|
"net/url"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"sync"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestLoggerWritesJSONLines(t *testing.T) {
|
||||||
|
path := filepath.Join(t.TempDir(), "access.jsonl")
|
||||||
|
logger, err := Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
const entries = 20
|
||||||
|
var wg sync.WaitGroup
|
||||||
|
for range entries {
|
||||||
|
wg.Add(1)
|
||||||
|
go func() {
|
||||||
|
defer wg.Done()
|
||||||
|
if err := logger.Write(Entry{
|
||||||
|
Event: EventUpstream,
|
||||||
|
RequestID: "request-id",
|
||||||
|
Method: "GET",
|
||||||
|
URL: "https://registry.example/packages/example",
|
||||||
|
StatusCode: 429,
|
||||||
|
}); err != nil {
|
||||||
|
t.Errorf("Write: %v", err)
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
}
|
||||||
|
wg.Wait()
|
||||||
|
|
||||||
|
if err := logger.Close(); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
file, err := os.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
defer func() { _ = file.Close() }()
|
||||||
|
|
||||||
|
scanner := bufio.NewScanner(file)
|
||||||
|
count := 0
|
||||||
|
for scanner.Scan() {
|
||||||
|
var entry Entry
|
||||||
|
if err := json.Unmarshal(scanner.Bytes(), &entry); err != nil {
|
||||||
|
t.Fatalf("line %d is not JSON: %v", count+1, err)
|
||||||
|
}
|
||||||
|
if entry.Time.IsZero() {
|
||||||
|
t.Errorf("line %d has no time", count+1)
|
||||||
|
}
|
||||||
|
if entry.StatusCode != 429 {
|
||||||
|
t.Errorf("line %d status_code = %d, want 429", count+1, entry.StatusCode)
|
||||||
|
}
|
||||||
|
count++
|
||||||
|
}
|
||||||
|
if err := scanner.Err(); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if count != entries {
|
||||||
|
t.Errorf("lines = %d, want %d", count, entries)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRequestID(t *testing.T) {
|
||||||
|
ctx := WithRequestID(context.Background(), "abc-123")
|
||||||
|
if got := RequestID(ctx); got != "abc-123" {
|
||||||
|
t.Errorf("RequestID = %q, want %q", got, "abc-123")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestURLWithoutSecrets(t *testing.T) {
|
||||||
|
value, err := url.Parse("https://user:password@registry.example/package.tgz?token=secret#fragment")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
got := URLWithoutSecrets(value)
|
||||||
|
want := "https://registry.example/package.tgz"
|
||||||
|
if got != want {
|
||||||
|
t.Errorf("URLWithoutSecrets = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
@ -91,6 +91,9 @@ type Config struct {
|
||||||
// Log configures logging.
|
// Log configures logging.
|
||||||
Log LogConfig `json:"log" yaml:"log"`
|
Log LogConfig `json:"log" yaml:"log"`
|
||||||
|
|
||||||
|
// AccessLog configures the JSONL activity log.
|
||||||
|
AccessLog AccessLogConfig `json:"access_log" yaml:"access_log"`
|
||||||
|
|
||||||
// Upstream configures upstream registry URLs (optional overrides).
|
// Upstream configures upstream registry URLs (optional overrides).
|
||||||
Upstream UpstreamConfig `json:"upstream" yaml:"upstream"`
|
Upstream UpstreamConfig `json:"upstream" yaml:"upstream"`
|
||||||
|
|
||||||
|
|
@ -280,6 +283,12 @@ type LogConfig struct {
|
||||||
Format string `json:"format" yaml:"format"`
|
Format string `json:"format" yaml:"format"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// AccessLogConfig configures the JSONL activity log.
|
||||||
|
type AccessLogConfig struct {
|
||||||
|
// Path is the file to append activity records to. Empty disables the access log.
|
||||||
|
Path string `json:"path" yaml:"path"`
|
||||||
|
}
|
||||||
|
|
||||||
// UpstreamConfig configures upstream registry URLs and authentication.
|
// UpstreamConfig configures upstream registry URLs and authentication.
|
||||||
// Leave empty to use defaults.
|
// Leave empty to use defaults.
|
||||||
type UpstreamConfig struct {
|
type UpstreamConfig struct {
|
||||||
|
|
@ -309,24 +318,40 @@ type UpstreamConfig struct {
|
||||||
// Default: http://deb.debian.org/debian
|
// Default: http://deb.debian.org/debian
|
||||||
Debian string `json:"debian" yaml:"debian"`
|
Debian string `json:"debian" yaml:"debian"`
|
||||||
|
|
||||||
|
// Helm maps repository names to HTTP Helm chart repository URLs.
|
||||||
|
// Requests use /helm/{name}/index.yaml and chart URLs in the index are
|
||||||
|
// rewritten to the same named proxy endpoint.
|
||||||
|
Helm map[string]string `json:"helm" yaml:"helm"`
|
||||||
|
|
||||||
|
// OCI maps names to OCI registry URLs. Requests to a named registry use
|
||||||
|
// the repository prefix upstream/{name}/, for example
|
||||||
|
// oci://proxy.example.com/upstream/ghcr/owner/chart.
|
||||||
|
OCI map[string]string `json:"oci" yaml:"oci"`
|
||||||
|
|
||||||
// Auth configures authentication for upstream registries.
|
// Auth configures authentication for upstream registries.
|
||||||
// Keys are URL prefixes that are matched against request URLs.
|
// Keys are absolute URL scopes matched by scheme, host, effective port,
|
||||||
|
// and path-segment prefix.
|
||||||
// Example: "https://npm.pkg.github.com" matches all requests to that host.
|
// Example: "https://npm.pkg.github.com" matches all requests to that host.
|
||||||
Auth map[string]AuthConfig `json:"auth" yaml:"auth"`
|
Auth map[string]AuthConfig `json:"auth" yaml:"auth"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// AuthForURL returns the auth config that matches the given URL.
|
// AuthForURL returns the auth config that matches the given URL.
|
||||||
// Matches are based on URL prefix - the longest matching prefix wins.
|
// The longest matching URL scope wins.
|
||||||
func (u *UpstreamConfig) AuthForURL(url string) *AuthConfig {
|
func (u *UpstreamConfig) AuthForURL(url string) *AuthConfig {
|
||||||
if u.Auth == nil {
|
if u.Auth == nil {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
target, err := parseAuthURL(url)
|
||||||
|
if err != nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
var bestMatch *AuthConfig
|
var bestMatch *AuthConfig
|
||||||
var bestLen int
|
var bestLen int
|
||||||
|
|
||||||
for pattern, auth := range u.Auth {
|
for pattern, auth := range u.Auth {
|
||||||
if strings.HasPrefix(url, pattern) && len(pattern) > bestLen {
|
configured, err := parseAuthURL(pattern)
|
||||||
|
if err == nil && authURLMatches(configured, target) && len(pattern) > bestLen {
|
||||||
a := auth // copy to avoid loop variable capture
|
a := auth // copy to avoid loop variable capture
|
||||||
bestMatch = &a
|
bestMatch = &a
|
||||||
bestLen = len(pattern)
|
bestLen = len(pattern)
|
||||||
|
|
@ -336,6 +361,73 @@ func (u *UpstreamConfig) AuthForURL(url string) *AuthConfig {
|
||||||
return bestMatch
|
return bestMatch
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Validate checks upstream authentication URL scopes.
|
||||||
|
func (u *UpstreamConfig) Validate() error {
|
||||||
|
for pattern := range u.Auth {
|
||||||
|
if _, err := parseAuthURL(pattern); err != nil {
|
||||||
|
return fmt.Errorf("invalid upstream.auth URL %q: %w", pattern, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if err := validateNamedUpstreams("upstream.helm", u.Helm); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if err := validateNamedUpstreams("upstream.oci", u.OCI); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func validateNamedUpstreams(field string, upstreams map[string]string) error {
|
||||||
|
for name, upstreamURL := range upstreams {
|
||||||
|
if name == "" || name == "." || name == ".." || strings.ContainsAny(name, `/\\`) {
|
||||||
|
return fmt.Errorf("invalid %s name %q", field, name)
|
||||||
|
}
|
||||||
|
if err := validateAbsoluteURL(field+"."+name, upstreamURL); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseAuthURL(value string) (*url.URL, error) {
|
||||||
|
parsed, err := url.Parse(value)
|
||||||
|
if err != nil || !parsed.IsAbs() || parsed.Hostname() == "" || parsed.Opaque != "" {
|
||||||
|
return nil, fmt.Errorf("invalid authentication URL")
|
||||||
|
}
|
||||||
|
return parsed, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func authURLMatches(configured, target *url.URL) bool {
|
||||||
|
if !strings.EqualFold(configured.Scheme, target.Scheme) ||
|
||||||
|
!strings.EqualFold(configured.Hostname(), target.Hostname()) ||
|
||||||
|
authURLPort(configured) != authURLPort(target) {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
if configured.RawQuery != "" && configured.RawQuery != target.RawQuery {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
configuredPath := strings.TrimSuffix(configured.EscapedPath(), "/")
|
||||||
|
if configuredPath == "" {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
targetPath := strings.TrimSuffix(target.EscapedPath(), "/")
|
||||||
|
return targetPath == configuredPath || strings.HasPrefix(targetPath, configuredPath+"/")
|
||||||
|
}
|
||||||
|
|
||||||
|
func authURLPort(value *url.URL) string {
|
||||||
|
if port := value.Port(); port != "" {
|
||||||
|
return port
|
||||||
|
}
|
||||||
|
if strings.EqualFold(value.Scheme, "https") {
|
||||||
|
return "443"
|
||||||
|
}
|
||||||
|
if strings.EqualFold(value.Scheme, "http") {
|
||||||
|
return "80"
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
// AuthConfig configures authentication for an upstream registry.
|
// AuthConfig configures authentication for an upstream registry.
|
||||||
type AuthConfig struct {
|
type AuthConfig struct {
|
||||||
// Type is the authentication type: "bearer", "basic", or "header".
|
// Type is the authentication type: "bearer", "basic", or "header".
|
||||||
|
|
@ -453,6 +545,7 @@ func setEnvBool(dst *bool, key string) {
|
||||||
// - PROXY_DATABASE_PATH
|
// - PROXY_DATABASE_PATH
|
||||||
// - PROXY_LOG_LEVEL
|
// - PROXY_LOG_LEVEL
|
||||||
// - PROXY_LOG_FORMAT
|
// - PROXY_LOG_FORMAT
|
||||||
|
// - PROXY_ACCESS_LOG_PATH
|
||||||
// - PROXY_HEALTH_STORAGE_PROBE_INTERVAL
|
// - PROXY_HEALTH_STORAGE_PROBE_INTERVAL
|
||||||
func (c *Config) LoadFromEnv() {
|
func (c *Config) LoadFromEnv() {
|
||||||
setEnvString(&c.Listen, "PROXY_LISTEN")
|
setEnvString(&c.Listen, "PROXY_LISTEN")
|
||||||
|
|
@ -469,6 +562,7 @@ func (c *Config) LoadFromEnv() {
|
||||||
setEnvString(&c.Database.URL, "PROXY_DATABASE_URL")
|
setEnvString(&c.Database.URL, "PROXY_DATABASE_URL")
|
||||||
setEnvString(&c.Log.Level, "PROXY_LOG_LEVEL")
|
setEnvString(&c.Log.Level, "PROXY_LOG_LEVEL")
|
||||||
setEnvString(&c.Log.Format, "PROXY_LOG_FORMAT")
|
setEnvString(&c.Log.Format, "PROXY_LOG_FORMAT")
|
||||||
|
setEnvString(&c.AccessLog.Path, "PROXY_ACCESS_LOG_PATH")
|
||||||
setEnvString(&c.Upstream.Maven, "PROXY_UPSTREAM_MAVEN")
|
setEnvString(&c.Upstream.Maven, "PROXY_UPSTREAM_MAVEN")
|
||||||
setEnvString(&c.Upstream.GradlePluginPortal, "PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL")
|
setEnvString(&c.Upstream.GradlePluginPortal, "PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL")
|
||||||
setEnvString(&c.Upstream.Debian, "PROXY_UPSTREAM_DEBIAN")
|
setEnvString(&c.Upstream.Debian, "PROXY_UPSTREAM_DEBIAN")
|
||||||
|
|
@ -577,15 +671,19 @@ func (c *Config) Validate() error {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
return c.validateComponents()
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c *Config) validateComponents() error {
|
||||||
|
if err := c.Upstream.Validate(); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
if err := c.Health.Validate(); err != nil {
|
if err := c.Health.Validate(); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := c.Gradle.BuildCache.Validate(); err != nil {
|
return c.Gradle.BuildCache.Validate()
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Validate checks the /health configuration. An unset interval is allowed
|
// Validate checks the /health configuration. An unset interval is allowed
|
||||||
|
|
@ -830,8 +928,7 @@ func ParseSize(s string) (int64, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, s2 := range suffixes {
|
for _, s2 := range suffixes {
|
||||||
if strings.HasSuffix(s, s2.suffix) {
|
if numStr, ok := strings.CutSuffix(s, s2.suffix); ok {
|
||||||
numStr := strings.TrimSuffix(s, s2.suffix)
|
|
||||||
num, err := strconv.ParseFloat(numStr, 64)
|
num, err := strconv.ParseFloat(numStr, 64)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return 0, fmt.Errorf("invalid number %q", numStr)
|
return 0, fmt.Errorf("invalid number %q", numStr)
|
||||||
|
|
|
||||||
|
|
@ -3,6 +3,7 @@ package config
|
||||||
import (
|
import (
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
|
|
@ -25,6 +26,9 @@ func TestDefault(t *testing.T) {
|
||||||
if cfg.Database.Path == "" {
|
if cfg.Database.Path == "" {
|
||||||
t.Error("Database.Path should not be empty")
|
t.Error("Database.Path should not be empty")
|
||||||
}
|
}
|
||||||
|
if cfg.AccessLog.Path != "" {
|
||||||
|
t.Errorf("AccessLog.Path = %q, want disabled by default", cfg.AccessLog.Path)
|
||||||
|
}
|
||||||
if cfg.Gradle.BuildCache.MaxUploadSize != "100MB" {
|
if cfg.Gradle.BuildCache.MaxUploadSize != "100MB" {
|
||||||
t.Errorf("Gradle.BuildCache.MaxUploadSize = %q, want %q", cfg.Gradle.BuildCache.MaxUploadSize, "100MB")
|
t.Errorf("Gradle.BuildCache.MaxUploadSize = %q, want %q", cfg.Gradle.BuildCache.MaxUploadSize, "100MB")
|
||||||
}
|
}
|
||||||
|
|
@ -211,6 +215,8 @@ database:
|
||||||
log:
|
log:
|
||||||
level: "debug"
|
level: "debug"
|
||||||
format: "json"
|
format: "json"
|
||||||
|
access_log:
|
||||||
|
path: "/var/log/proxy/access.jsonl"
|
||||||
`
|
`
|
||||||
if err := os.WriteFile(path, []byte(content), 0644); err != nil {
|
if err := os.WriteFile(path, []byte(content), 0644); err != nil {
|
||||||
t.Fatalf("writing config file: %v", err)
|
t.Fatalf("writing config file: %v", err)
|
||||||
|
|
@ -239,6 +245,9 @@ log:
|
||||||
if cfg.Log.Format != "json" {
|
if cfg.Log.Format != "json" {
|
||||||
t.Errorf("Log.Format = %q, want %q", cfg.Log.Format, "json")
|
t.Errorf("Log.Format = %q, want %q", cfg.Log.Format, "json")
|
||||||
}
|
}
|
||||||
|
if cfg.AccessLog.Path != "/var/log/proxy/access.jsonl" {
|
||||||
|
t.Errorf("AccessLog.Path = %q, want %q", cfg.AccessLog.Path, "/var/log/proxy/access.jsonl")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestLoadJSON(t *testing.T) {
|
func TestLoadJSON(t *testing.T) {
|
||||||
|
|
@ -274,6 +283,7 @@ func TestLoadFromEnv(t *testing.T) {
|
||||||
t.Setenv("PROXY_UI_URL", "https://ui.env.example.com/ui")
|
t.Setenv("PROXY_UI_URL", "https://ui.env.example.com/ui")
|
||||||
t.Setenv("PROXY_STORAGE_PATH", "/env/cache")
|
t.Setenv("PROXY_STORAGE_PATH", "/env/cache")
|
||||||
t.Setenv("PROXY_LOG_LEVEL", testLevelDebug)
|
t.Setenv("PROXY_LOG_LEVEL", testLevelDebug)
|
||||||
|
t.Setenv("PROXY_ACCESS_LOG_PATH", "/tmp/proxy-access.jsonl")
|
||||||
t.Setenv("PROXY_UPSTREAM_MAVEN", "https://maven.example.com/repository/maven-public")
|
t.Setenv("PROXY_UPSTREAM_MAVEN", "https://maven.example.com/repository/maven-public")
|
||||||
t.Setenv("PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL", "https://plugins.example.com/m2")
|
t.Setenv("PROXY_UPSTREAM_GRADLE_PLUGIN_PORTAL", "https://plugins.example.com/m2")
|
||||||
t.Setenv("PROXY_UPSTREAM_DEBIAN", "http://archive.ubuntu.com/ubuntu")
|
t.Setenv("PROXY_UPSTREAM_DEBIAN", "http://archive.ubuntu.com/ubuntu")
|
||||||
|
|
@ -300,6 +310,9 @@ func TestLoadFromEnv(t *testing.T) {
|
||||||
if cfg.Log.Level != testLevelDebug {
|
if cfg.Log.Level != testLevelDebug {
|
||||||
t.Errorf("Log.Level = %q, want %q", cfg.Log.Level, testLevelDebug)
|
t.Errorf("Log.Level = %q, want %q", cfg.Log.Level, testLevelDebug)
|
||||||
}
|
}
|
||||||
|
if cfg.AccessLog.Path != "/tmp/proxy-access.jsonl" {
|
||||||
|
t.Errorf("AccessLog.Path = %q, want %q", cfg.AccessLog.Path, "/tmp/proxy-access.jsonl")
|
||||||
|
}
|
||||||
if cfg.Upstream.Maven != "https://maven.example.com/repository/maven-public" {
|
if cfg.Upstream.Maven != "https://maven.example.com/repository/maven-public" {
|
||||||
t.Errorf("Upstream.Maven = %q, want %q", cfg.Upstream.Maven, "https://maven.example.com/repository/maven-public")
|
t.Errorf("Upstream.Maven = %q, want %q", cfg.Upstream.Maven, "https://maven.example.com/repository/maven-public")
|
||||||
}
|
}
|
||||||
|
|
@ -795,3 +808,114 @@ func TestDatabaseConfigString(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestUpstreamAuthForURLMatchesURLComponents(t *testing.T) {
|
||||||
|
registryAuth := AuthConfig{Type: "bearer", Token: "registry-token"}
|
||||||
|
privateAuth := AuthConfig{Type: "bearer", Token: "private-token"}
|
||||||
|
config := UpstreamConfig{Auth: map[string]AuthConfig{
|
||||||
|
"https://registry.example.com": registryAuth,
|
||||||
|
"https://registry.example.com/private": privateAuth,
|
||||||
|
}}
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
url string
|
||||||
|
wantToken string
|
||||||
|
}{
|
||||||
|
{name: "registry root", url: "https://registry.example.com/package", wantToken: "registry-token"},
|
||||||
|
{name: "host is case insensitive", url: "https://REGISTRY.EXAMPLE.COM/package", wantToken: "registry-token"},
|
||||||
|
{name: "longest path match", url: "https://registry.example.com/private/package", wantToken: "private-token"},
|
||||||
|
{name: "exact path match", url: "https://registry.example.com/private", wantToken: "private-token"},
|
||||||
|
{name: "path segment boundary", url: "https://registry.example.com/private-other/package", wantToken: "registry-token"},
|
||||||
|
{name: "lookalike host rejected", url: "https://registry.example.com.evil.test/package"},
|
||||||
|
{name: "different scheme rejected", url: "http://registry.example.com/package"},
|
||||||
|
{name: "different port rejected", url: "https://registry.example.com:8443/package"},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
auth := config.AuthForURL(tt.url)
|
||||||
|
if tt.wantToken == "" {
|
||||||
|
if auth != nil {
|
||||||
|
t.Fatalf("AuthForURL() = %+v, want nil", auth)
|
||||||
|
}
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if auth == nil {
|
||||||
|
t.Fatal("AuthForURL() = nil, want authentication")
|
||||||
|
}
|
||||||
|
if auth.Token != tt.wantToken {
|
||||||
|
t.Errorf("token = %q, want %q", auth.Token, tt.wantToken)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestValidateUpstreamAuthURLs(t *testing.T) {
|
||||||
|
t.Run("valid absolute URL", func(t *testing.T) {
|
||||||
|
cfg := Default()
|
||||||
|
cfg.Upstream.Auth = map[string]AuthConfig{
|
||||||
|
"https://registry.example.com/private": {Type: "bearer", Token: "token"},
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := cfg.Validate(); err != nil {
|
||||||
|
t.Fatalf("Validate() error = %v", err)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
t.Run("invalid URL", func(t *testing.T) {
|
||||||
|
cfg := Default()
|
||||||
|
cfg.Upstream.Auth = map[string]AuthConfig{
|
||||||
|
"registry.example.com": {Type: "bearer", Token: "token"},
|
||||||
|
}
|
||||||
|
|
||||||
|
err := cfg.Validate()
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Validate() error = nil, want invalid upstream.auth URL error")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "upstream.auth") || !strings.Contains(err.Error(), "registry.example.com") {
|
||||||
|
t.Errorf("Validate() error = %q, want field and URL", err)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestValidateNamedUpstreams(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
modify func(*Config)
|
||||||
|
wantErr bool
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "valid Helm and OCI upstreams",
|
||||||
|
modify: func(cfg *Config) {
|
||||||
|
cfg.Upstream.Helm = map[string]string{"bitnami": "https://charts.bitnami.com/bitnami"}
|
||||||
|
cfg.Upstream.OCI = map[string]string{"ghcr": "https://ghcr.io"}
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Helm upstream name contains path separator",
|
||||||
|
modify: func(cfg *Config) {
|
||||||
|
cfg.Upstream.Helm = map[string]string{"team/charts": "https://charts.example.com"}
|
||||||
|
},
|
||||||
|
wantErr: true,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "OCI upstream URL is not absolute",
|
||||||
|
modify: func(cfg *Config) {
|
||||||
|
cfg.Upstream.OCI = map[string]string{"private": "registry.example.com"}
|
||||||
|
},
|
||||||
|
wantErr: true,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
cfg := Default()
|
||||||
|
tt.modify(cfg)
|
||||||
|
err := cfg.Validate()
|
||||||
|
if (err != nil) != tt.wantErr {
|
||||||
|
t.Errorf("Validate() error = %v, wantErr %t", err, tt.wantErr)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
||||||
|
|
@ -8,6 +8,11 @@ import (
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
testContentHash = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
|
||||||
|
testIntegrity = "sha512-z4PhNX7vuL3xVChQ1m2AB9Yg5AULVxXcg/SpIdNs6c5H0NE8XYXysP+DGNKHfuwvY7kxvUdBeoGlODJ6+SfaPg=="
|
||||||
|
)
|
||||||
|
|
||||||
func TestCreateAndOpen(t *testing.T) {
|
func TestCreateAndOpen(t *testing.T) {
|
||||||
dir := t.TempDir()
|
dir := t.TempDir()
|
||||||
dbPath := filepath.Join(dir, "test.db")
|
dbPath := filepath.Join(dir, "test.db")
|
||||||
|
|
@ -132,7 +137,7 @@ func TestVersionCRUD(t *testing.T) {
|
||||||
v := &Version{
|
v := &Version{
|
||||||
PURL: "pkg:npm/lodash@4.17.21",
|
PURL: "pkg:npm/lodash@4.17.21",
|
||||||
PackagePURL: "pkg:npm/lodash",
|
PackagePURL: "pkg:npm/lodash",
|
||||||
Integrity: sql.NullString{String: "sha512-abc123", Valid: true},
|
Integrity: sql.NullString{String: testIntegrity, Valid: true},
|
||||||
}
|
}
|
||||||
|
|
||||||
err = db.UpsertVersion(v)
|
err = db.UpsertVersion(v)
|
||||||
|
|
@ -200,7 +205,7 @@ func TestArtifactCRUD(t *testing.T) {
|
||||||
t.Error("expected artifact to not be cached yet")
|
t.Error("expected artifact to not be cached yet")
|
||||||
}
|
}
|
||||||
|
|
||||||
err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", "sha256-abc", 12345, "application/gzip")
|
err = db.MarkArtifactCached(versionPURL, "lodash-4.17.21.tgz", "/cache/npm/lodash-4.17.21.tgz", testContentHash, 12345, "application/gzip")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatalf("MarkArtifactCached failed: %v", err)
|
t.Fatalf("MarkArtifactCached failed: %v", err)
|
||||||
}
|
}
|
||||||
|
|
@ -239,6 +244,86 @@ func TestArtifactCRUD(t *testing.T) {
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestGetCachedArtifact(t *testing.T) {
|
||||||
|
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
||||||
|
const (
|
||||||
|
packagePURL = "pkg:npm/lodash"
|
||||||
|
versionPURL = "pkg:npm/lodash@4.17.21"
|
||||||
|
filename = "lodash-4.17.21.tgz"
|
||||||
|
)
|
||||||
|
seedCachedArtifactTestData(t, db, packagePURL, versionPURL, filename)
|
||||||
|
|
||||||
|
cached, err := db.GetCachedArtifact(packagePURL, versionPURL, filename)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetCachedArtifact before cache failed: %v", err)
|
||||||
|
}
|
||||||
|
if cached != nil {
|
||||||
|
t.Fatalf("expected no cached artifact, got %+v", cached)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := db.MarkArtifactCached(versionPURL, filename, "/cache/npm/"+filename,
|
||||||
|
testContentHash, 12345, "application/gzip"); err != nil {
|
||||||
|
t.Fatalf("MarkArtifactCached failed: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
cached, err = db.GetCachedArtifact(packagePURL, versionPURL, filename)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetCachedArtifact failed: %v", err)
|
||||||
|
}
|
||||||
|
if cached == nil {
|
||||||
|
t.Fatal("expected cached artifact, got nil")
|
||||||
|
}
|
||||||
|
if cached.Ecosystem != "npm" {
|
||||||
|
t.Errorf("expected npm ecosystem, got %q", cached.Ecosystem)
|
||||||
|
}
|
||||||
|
if cached.StoragePath != "/cache/npm/"+filename {
|
||||||
|
t.Errorf("expected cached storage path, got %q", cached.StoragePath)
|
||||||
|
}
|
||||||
|
if cached.ContentHash.String != testContentHash {
|
||||||
|
t.Errorf("expected cached content hash, got %q", cached.ContentHash.String)
|
||||||
|
}
|
||||||
|
if cached.Size.Int64 != 12345 {
|
||||||
|
t.Errorf("expected cached size 12345, got %d", cached.Size.Int64)
|
||||||
|
}
|
||||||
|
if cached.ContentType.String != "application/gzip" {
|
||||||
|
t.Errorf("expected cached content type, got %q", cached.ContentType.String)
|
||||||
|
}
|
||||||
|
if cached.Integrity.String != testIntegrity {
|
||||||
|
t.Errorf("expected cached integrity, got %q", cached.Integrity.String)
|
||||||
|
}
|
||||||
|
|
||||||
|
cached, err = db.GetCachedArtifact("pkg:npm/other", versionPURL, filename)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetCachedArtifact with wrong package failed: %v", err)
|
||||||
|
}
|
||||||
|
if cached != nil {
|
||||||
|
t.Fatalf("expected package mismatch to miss cache, got %+v", cached)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
func seedCachedArtifactTestData(t *testing.T, db *DB, packagePURL, versionPURL, filename string) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
if err := db.UpsertPackage(&Package{PURL: packagePURL, Ecosystem: "npm", Name: "lodash"}); err != nil {
|
||||||
|
t.Fatalf("UpsertPackage failed: %v", err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertVersion(&Version{
|
||||||
|
PURL: versionPURL,
|
||||||
|
PackagePURL: packagePURL,
|
||||||
|
Integrity: sql.NullString{String: testIntegrity, Valid: true},
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("UpsertVersion failed: %v", err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertArtifact(&Artifact{
|
||||||
|
VersionPURL: versionPURL,
|
||||||
|
Filename: filename,
|
||||||
|
UpstreamURL: "https://registry.npmjs.org/lodash/-/" + filename,
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("UpsertArtifact failed: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestCacheManagement(t *testing.T) {
|
func TestCacheManagement(t *testing.T) {
|
||||||
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
||||||
pkg := &Package{
|
pkg := &Package{
|
||||||
|
|
|
||||||
|
|
@ -30,6 +30,10 @@ func TestUpsertAndGetMetadataCache(t *testing.T) {
|
||||||
StoragePath: "_metadata/npm/lodash/metadata",
|
StoragePath: "_metadata/npm/lodash/metadata",
|
||||||
ETag: sql.NullString{String: `"abc123"`, Valid: true},
|
ETag: sql.NullString{String: `"abc123"`, Valid: true},
|
||||||
ContentType: sql.NullString{String: "application/json", Valid: true},
|
ContentType: sql.NullString{String: "application/json", Valid: true},
|
||||||
|
ContentDigest: sql.NullString{
|
||||||
|
String: "sha256:0123456789abcdef",
|
||||||
|
Valid: true,
|
||||||
|
},
|
||||||
Size: sql.NullInt64{Int64: 1024, Valid: true},
|
Size: sql.NullInt64{Int64: 1024, Valid: true},
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
||||||
}
|
}
|
||||||
|
|
@ -62,6 +66,9 @@ func TestUpsertAndGetMetadataCache(t *testing.T) {
|
||||||
if !got.ContentType.Valid || got.ContentType.String != "application/json" {
|
if !got.ContentType.Valid || got.ContentType.String != "application/json" {
|
||||||
t.Errorf("content_type = %v, want %q", got.ContentType, "application/json")
|
t.Errorf("content_type = %v, want %q", got.ContentType, "application/json")
|
||||||
}
|
}
|
||||||
|
if !got.ContentDigest.Valid || got.ContentDigest.String != "sha256:0123456789abcdef" {
|
||||||
|
t.Errorf("content_digest = %v, want %q", got.ContentDigest, "sha256:0123456789abcdef")
|
||||||
|
}
|
||||||
if !got.Size.Valid || got.Size.Int64 != 1024 {
|
if !got.Size.Valid || got.Size.Int64 != 1024 {
|
||||||
t.Errorf("size = %v, want 1024", got.Size)
|
t.Errorf("size = %v, want 1024", got.Size)
|
||||||
}
|
}
|
||||||
|
|
@ -178,3 +185,47 @@ func TestMetadataCacheTableCreatedByMigration(t *testing.T) {
|
||||||
t.Error("metadata_cache table should exist after migration")
|
t.Error("metadata_cache table should exist after migration")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestMetadataCacheContentDigestMigrationPreservesExistingRows(t *testing.T) {
|
||||||
|
dbPath := filepath.Join(t.TempDir(), "test.db")
|
||||||
|
db, err := Create(dbPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Create failed: %v", err)
|
||||||
|
}
|
||||||
|
defer func() { _ = db.Close() }()
|
||||||
|
|
||||||
|
if _, err := db.Exec("ALTER TABLE metadata_cache DROP COLUMN content_digest"); err != nil {
|
||||||
|
t.Fatalf("dropping content_digest: %v", err)
|
||||||
|
}
|
||||||
|
if _, err := db.Exec("DELETE FROM migrations WHERE name = ?", "006_add_metadata_content_digest"); err != nil {
|
||||||
|
t.Fatalf("resetting digest migration: %v", err)
|
||||||
|
}
|
||||||
|
if _, err := db.Exec(`
|
||||||
|
INSERT INTO metadata_cache (ecosystem, name, storage_path, content_type, size, fetched_at, created_at, updated_at)
|
||||||
|
VALUES (?, ?, ?, ?, ?, ?, ?, ?)
|
||||||
|
`, "oci-manifest", "cache-key", "_metadata/oci-manifest/cache-key/metadata", "application/json", 2, time.Now(), time.Now(), time.Now()); err != nil {
|
||||||
|
t.Fatalf("inserting legacy cache row: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := db.MigrateSchema(); err != nil {
|
||||||
|
t.Fatalf("MigrateSchema() error = %v", err)
|
||||||
|
}
|
||||||
|
hasDigest, err := db.HasColumn("metadata_cache", "content_digest")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("HasColumn() error = %v", err)
|
||||||
|
}
|
||||||
|
if !hasDigest {
|
||||||
|
t.Fatal("metadata_cache.content_digest was not added")
|
||||||
|
}
|
||||||
|
|
||||||
|
entry, err := db.GetMetadataCache("oci-manifest", "cache-key")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetMetadataCache() error = %v", err)
|
||||||
|
}
|
||||||
|
if entry == nil || entry.StoragePath != "_metadata/oci-manifest/cache-key/metadata" {
|
||||||
|
t.Fatalf("existing metadata cache row was not preserved: %#v", entry)
|
||||||
|
}
|
||||||
|
if entry.ContentDigest.Valid {
|
||||||
|
t.Errorf("legacy content digest = %q, want NULL", entry.ContentDigest.String)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
||||||
|
|
@ -191,6 +191,28 @@ func (db *DB) GetArtifact(versionPURL, filename string) (*Artifact, error) {
|
||||||
return &a, nil
|
return &a, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// GetCachedArtifact returns the fields needed to serve a cached artifact.
|
||||||
|
func (db *DB) GetCachedArtifact(packagePURL, versionPURL, filename string) (*CachedArtifact, error) {
|
||||||
|
var artifact CachedArtifact
|
||||||
|
query := db.Rebind(`
|
||||||
|
SELECT packages.ecosystem, artifacts.storage_path, artifacts.content_hash, artifacts.size,
|
||||||
|
artifacts.content_type, versions.integrity
|
||||||
|
FROM artifacts
|
||||||
|
JOIN versions ON versions.purl = artifacts.version_purl
|
||||||
|
JOIN packages ON packages.purl = versions.package_purl
|
||||||
|
WHERE packages.purl = ? AND artifacts.version_purl = ? AND artifacts.filename = ?
|
||||||
|
AND artifacts.storage_path IS NOT NULL AND artifacts.fetched_at IS NOT NULL
|
||||||
|
`)
|
||||||
|
err := db.Get(&artifact, query, packagePURL, versionPURL, filename)
|
||||||
|
if err == sql.ErrNoRows {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return &artifact, nil
|
||||||
|
}
|
||||||
|
|
||||||
func (db *DB) GetArtifactByPath(storagePath string) (*Artifact, error) {
|
func (db *DB) GetArtifactByPath(storagePath string) (*Artifact, error) {
|
||||||
var a Artifact
|
var a Artifact
|
||||||
query := db.Rebind(`
|
query := db.Rebind(`
|
||||||
|
|
@ -445,9 +467,12 @@ func (db *DB) GetMostPopularPackages(limit int) ([]PopularPackage, error) {
|
||||||
type RecentPackage struct {
|
type RecentPackage struct {
|
||||||
Ecosystem string `db:"ecosystem"`
|
Ecosystem string `db:"ecosystem"`
|
||||||
Name string `db:"name"`
|
Name string `db:"name"`
|
||||||
Version string `db:"version"`
|
VersionPURL string `db:"version_purl"`
|
||||||
CachedAt time.Time `db:"fetched_at"`
|
CachedAt time.Time `db:"fetched_at"`
|
||||||
Size int64 `db:"size"`
|
Size int64 `db:"size"`
|
||||||
|
// Version is derived from VersionPURL rather than selected, so that the
|
||||||
|
// PURL percent-encoding is decoded (e.g. "%2B" back to "+").
|
||||||
|
Version string `db:"-"`
|
||||||
}
|
}
|
||||||
|
|
||||||
func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
|
func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
|
||||||
|
|
@ -461,10 +486,10 @@ func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
var packages []RecentPackage
|
var packages []RecentPackage
|
||||||
// We need to extract version from the purl since there's no separate version column
|
// There is no separate version column, so the full version PURL is selected
|
||||||
|
// and the version is decoded from it in Go.
|
||||||
query := db.Rebind(`
|
query := db.Rebind(`
|
||||||
SELECT p.ecosystem, p.name,
|
SELECT p.ecosystem, p.name, v.purl as version_purl,
|
||||||
SUBSTR(v.purl, INSTR(v.purl, '@') + 1) as version,
|
|
||||||
a.fetched_at, COALESCE(a.size, 0) as size
|
a.fetched_at, COALESCE(a.size, 0) as size
|
||||||
FROM artifacts a
|
FROM artifacts a
|
||||||
JOIN versions v ON v.purl = a.version_purl
|
JOIN versions v ON v.purl = a.version_purl
|
||||||
|
|
@ -474,25 +499,13 @@ func (db *DB) GetRecentlyCachedPackages(limit int) ([]RecentPackage, error) {
|
||||||
LIMIT ?
|
LIMIT ?
|
||||||
`)
|
`)
|
||||||
|
|
||||||
// For postgres, use different string function
|
|
||||||
if db.dialect == DialectPostgres {
|
|
||||||
query = db.Rebind(`
|
|
||||||
SELECT p.ecosystem, p.name,
|
|
||||||
SUBSTRING(v.purl FROM POSITION('@' IN v.purl) + 1) as version,
|
|
||||||
a.fetched_at, COALESCE(a.size, 0) as size
|
|
||||||
FROM artifacts a
|
|
||||||
JOIN versions v ON v.purl = a.version_purl
|
|
||||||
JOIN packages p ON p.purl = v.package_purl
|
|
||||||
WHERE a.storage_path IS NOT NULL AND a.fetched_at IS NOT NULL
|
|
||||||
ORDER BY a.fetched_at DESC
|
|
||||||
LIMIT ?
|
|
||||||
`)
|
|
||||||
}
|
|
||||||
|
|
||||||
err = db.Select(&packages, query, limit)
|
err = db.Select(&packages, query, limit)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
for i := range packages {
|
||||||
|
packages[i].Version = VersionFromPURL(packages[i].VersionPURL)
|
||||||
|
}
|
||||||
return packages, nil
|
return packages, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -894,7 +907,7 @@ func (db *DB) GetMetadataCache(ecosystem, name string) (*MetadataCacheEntry, err
|
||||||
var entry MetadataCacheEntry
|
var entry MetadataCacheEntry
|
||||||
query := db.Rebind(`
|
query := db.Rebind(`
|
||||||
SELECT id, ecosystem, name, storage_path, etag, content_type,
|
SELECT id, ecosystem, name, storage_path, etag, content_type,
|
||||||
size, last_modified, fetched_at, created_at, updated_at
|
content_digest, size, last_modified, fetched_at, created_at, updated_at
|
||||||
FROM metadata_cache WHERE ecosystem = ? AND name = ?
|
FROM metadata_cache WHERE ecosystem = ? AND name = ?
|
||||||
`)
|
`)
|
||||||
err := db.Get(&entry, query, ecosystem, name)
|
err := db.Get(&entry, query, ecosystem, name)
|
||||||
|
|
@ -914,12 +927,13 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error {
|
||||||
if db.dialect == DialectPostgres {
|
if db.dialect == DialectPostgres {
|
||||||
query = `
|
query = `
|
||||||
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type,
|
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type,
|
||||||
size, last_modified, fetched_at, created_at, updated_at)
|
content_digest, size, last_modified, fetched_at, created_at, updated_at)
|
||||||
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10)
|
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10, $11)
|
||||||
ON CONFLICT(ecosystem, name) DO UPDATE SET
|
ON CONFLICT(ecosystem, name) DO UPDATE SET
|
||||||
storage_path = EXCLUDED.storage_path,
|
storage_path = EXCLUDED.storage_path,
|
||||||
etag = EXCLUDED.etag,
|
etag = EXCLUDED.etag,
|
||||||
content_type = EXCLUDED.content_type,
|
content_type = EXCLUDED.content_type,
|
||||||
|
content_digest = EXCLUDED.content_digest,
|
||||||
size = EXCLUDED.size,
|
size = EXCLUDED.size,
|
||||||
last_modified = EXCLUDED.last_modified,
|
last_modified = EXCLUDED.last_modified,
|
||||||
fetched_at = EXCLUDED.fetched_at,
|
fetched_at = EXCLUDED.fetched_at,
|
||||||
|
|
@ -928,12 +942,13 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error {
|
||||||
} else {
|
} else {
|
||||||
query = `
|
query = `
|
||||||
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type,
|
INSERT INTO metadata_cache (ecosystem, name, storage_path, etag, content_type,
|
||||||
size, last_modified, fetched_at, created_at, updated_at)
|
content_digest, size, last_modified, fetched_at, created_at, updated_at)
|
||||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
|
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
|
||||||
ON CONFLICT(ecosystem, name) DO UPDATE SET
|
ON CONFLICT(ecosystem, name) DO UPDATE SET
|
||||||
storage_path = excluded.storage_path,
|
storage_path = excluded.storage_path,
|
||||||
etag = excluded.etag,
|
etag = excluded.etag,
|
||||||
content_type = excluded.content_type,
|
content_type = excluded.content_type,
|
||||||
|
content_digest = excluded.content_digest,
|
||||||
size = excluded.size,
|
size = excluded.size,
|
||||||
last_modified = excluded.last_modified,
|
last_modified = excluded.last_modified,
|
||||||
fetched_at = excluded.fetched_at,
|
fetched_at = excluded.fetched_at,
|
||||||
|
|
@ -943,7 +958,7 @@ func (db *DB) UpsertMetadataCache(entry *MetadataCacheEntry) error {
|
||||||
|
|
||||||
_, err := db.Exec(query,
|
_, err := db.Exec(query,
|
||||||
entry.Ecosystem, entry.Name, entry.StoragePath, entry.ETag,
|
entry.Ecosystem, entry.Name, entry.StoragePath, entry.ETag,
|
||||||
entry.ContentType, entry.Size, entry.LastModified, entry.FetchedAt, now, now,
|
entry.ContentType, entry.ContentDigest, entry.Size, entry.LastModified, entry.FetchedAt, now, now,
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("upserting metadata cache: %w", err)
|
return fmt.Errorf("upserting metadata cache: %w", err)
|
||||||
|
|
|
||||||
|
|
@ -102,6 +102,7 @@ CREATE TABLE IF NOT EXISTS metadata_cache (
|
||||||
storage_path TEXT NOT NULL,
|
storage_path TEXT NOT NULL,
|
||||||
etag TEXT,
|
etag TEXT,
|
||||||
content_type TEXT,
|
content_type TEXT,
|
||||||
|
content_digest TEXT,
|
||||||
size INTEGER,
|
size INTEGER,
|
||||||
last_modified DATETIME,
|
last_modified DATETIME,
|
||||||
fetched_at DATETIME,
|
fetched_at DATETIME,
|
||||||
|
|
@ -202,6 +203,7 @@ CREATE TABLE IF NOT EXISTS metadata_cache (
|
||||||
storage_path TEXT NOT NULL,
|
storage_path TEXT NOT NULL,
|
||||||
etag TEXT,
|
etag TEXT,
|
||||||
content_type TEXT,
|
content_type TEXT,
|
||||||
|
content_digest TEXT,
|
||||||
size BIGINT,
|
size BIGINT,
|
||||||
last_modified TIMESTAMP,
|
last_modified TIMESTAMP,
|
||||||
fetched_at TIMESTAMP,
|
fetched_at TIMESTAMP,
|
||||||
|
|
@ -359,6 +361,7 @@ var migrations = []migration{
|
||||||
{"003_ensure_artifacts_table", migrateEnsureArtifactsTable},
|
{"003_ensure_artifacts_table", migrateEnsureArtifactsTable},
|
||||||
{"004_ensure_vulnerabilities_table", migrateEnsureVulnerabilitiesTable},
|
{"004_ensure_vulnerabilities_table", migrateEnsureVulnerabilitiesTable},
|
||||||
{"005_ensure_metadata_cache_table", migrateEnsureMetadataCacheTable},
|
{"005_ensure_metadata_cache_table", migrateEnsureMetadataCacheTable},
|
||||||
|
{"006_add_metadata_content_digest", migrateAddMetadataContentDigest},
|
||||||
}
|
}
|
||||||
|
|
||||||
// isTableNotFound returns true if the error indicates a missing table.
|
// isTableNotFound returns true if the error indicates a missing table.
|
||||||
|
|
@ -581,6 +584,20 @@ func migrateEnsureMetadataCacheTable(db *DB) error {
|
||||||
return db.EnsureMetadataCacheTable()
|
return db.EnsureMetadataCacheTable()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func migrateAddMetadataContentDigest(db *DB) error {
|
||||||
|
hasColumn, err := db.HasColumn("metadata_cache", "content_digest")
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("checking metadata_cache content_digest column: %w", err)
|
||||||
|
}
|
||||||
|
if hasColumn {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
if _, err := db.Exec("ALTER TABLE metadata_cache ADD COLUMN content_digest TEXT"); err != nil {
|
||||||
|
return fmt.Errorf("adding metadata_cache content_digest column: %w", err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
// EnsureMetadataCacheTable creates the metadata_cache table if it doesn't exist.
|
// EnsureMetadataCacheTable creates the metadata_cache table if it doesn't exist.
|
||||||
func (db *DB) EnsureMetadataCacheTable() error {
|
func (db *DB) EnsureMetadataCacheTable() error {
|
||||||
has, err := db.HasTable("metadata_cache")
|
has, err := db.HasTable("metadata_cache")
|
||||||
|
|
@ -601,6 +618,7 @@ func (db *DB) EnsureMetadataCacheTable() error {
|
||||||
storage_path TEXT NOT NULL,
|
storage_path TEXT NOT NULL,
|
||||||
etag TEXT,
|
etag TEXT,
|
||||||
content_type TEXT,
|
content_type TEXT,
|
||||||
|
content_digest TEXT,
|
||||||
size BIGINT,
|
size BIGINT,
|
||||||
last_modified TIMESTAMP,
|
last_modified TIMESTAMP,
|
||||||
fetched_at TIMESTAMP,
|
fetched_at TIMESTAMP,
|
||||||
|
|
@ -618,6 +636,7 @@ func (db *DB) EnsureMetadataCacheTable() error {
|
||||||
storage_path TEXT NOT NULL,
|
storage_path TEXT NOT NULL,
|
||||||
etag TEXT,
|
etag TEXT,
|
||||||
content_type TEXT,
|
content_type TEXT,
|
||||||
|
content_digest TEXT,
|
||||||
size INTEGER,
|
size INTEGER,
|
||||||
last_modified DATETIME,
|
last_modified DATETIME,
|
||||||
fetched_at DATETIME,
|
fetched_at DATETIME,
|
||||||
|
|
|
||||||
|
|
@ -2,6 +2,7 @@ package database
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"database/sql"
|
"database/sql"
|
||||||
|
"net/url"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
|
|
@ -47,11 +48,80 @@ type Version struct {
|
||||||
// Version extracts the version string from the PURL.
|
// Version extracts the version string from the PURL.
|
||||||
// e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21"
|
// e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21"
|
||||||
func (v *Version) Version() string {
|
func (v *Version) Version() string {
|
||||||
if idx := strings.LastIndex(v.PURL, "@"); idx >= 0 {
|
return VersionFromPURL(v.PURL)
|
||||||
return v.PURL[idx+1:]
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// EscapedVersion returns the version escaped for use as a single URL path
|
||||||
|
// segment.
|
||||||
|
//
|
||||||
|
// Version returns decoded text, which is what should be shown to a user but is
|
||||||
|
// not safe to drop into a link: html/template preserves reserved characters and
|
||||||
|
// existing escapes in a URL, so "release/1" would split into two path segments,
|
||||||
|
// "v1?build" would start a query string, and a literal "%2B" would be read back
|
||||||
|
// as "+". Escaping here and decoding in splitWildcardPath round-trips the value,
|
||||||
|
// so the link resolves to the version that was stored.
|
||||||
|
func (v *Version) EscapedVersion() string {
|
||||||
|
return url.PathEscape(v.Version())
|
||||||
|
}
|
||||||
|
|
||||||
|
// DisplayPURL returns the PURL with its path components percent-decoded, for
|
||||||
|
// showing in the UI. The stored PURL keeps the canonical encoding (which is
|
||||||
|
// what the API and all lookups use); this is only a readable rendering, so that
|
||||||
|
// a version like "7.91+dfsg1-2ubuntu0.1" is not shown as "7.91%2Bdfsg1-2ubuntu0.1"
|
||||||
|
// and an npm scope is shown as "@babel" rather than "%40babel". Qualifiers and
|
||||||
|
// subpath keep their encoding, since decoding those would be ambiguous.
|
||||||
|
func (v *Version) DisplayPURL() string {
|
||||||
|
base, suffix := v.PURL, ""
|
||||||
|
if i := strings.IndexAny(base, "?#"); i >= 0 {
|
||||||
|
base, suffix = base[:i], base[i:]
|
||||||
|
}
|
||||||
|
|
||||||
|
name, version := base, ""
|
||||||
|
if idx := strings.LastIndex(base, "@"); idx >= 0 {
|
||||||
|
name, version = base[:idx], "@"+decodePURLComponent(base[idx+1:])
|
||||||
|
}
|
||||||
|
|
||||||
|
parts := strings.Split(name, "/")
|
||||||
|
for i, part := range parts {
|
||||||
|
parts[i] = decodePURLComponent(part)
|
||||||
|
}
|
||||||
|
return strings.Join(parts, "/") + version + suffix
|
||||||
|
}
|
||||||
|
|
||||||
|
// VersionFromPURL extracts the decoded version string from a PURL.
|
||||||
|
//
|
||||||
|
// PURL percent-encodes characters that are not safe in a path component, so a
|
||||||
|
// Debian version like "7.91+dfsg1-2ubuntu0.1" is stored as
|
||||||
|
// "pkg:deb/nmap@7.91%2Bdfsg1-2ubuntu0.1". The raw substring after "@" is
|
||||||
|
// therefore not the version: it must be percent-decoded before being displayed
|
||||||
|
// or used to build a URL, otherwise "%2B" leaks into the UI and round-tripping
|
||||||
|
// the value back into a PURL double-encodes it.
|
||||||
|
//
|
||||||
|
// e.g., "pkg:npm/lodash@4.17.21" -> "4.17.21"
|
||||||
|
func VersionFromPURL(p string) string {
|
||||||
|
// Qualifiers ("?key=value") and subpath ("#path") follow the version.
|
||||||
|
if i := strings.IndexAny(p, "?#"); i >= 0 {
|
||||||
|
p = p[:i]
|
||||||
|
}
|
||||||
|
idx := strings.LastIndex(p, "@")
|
||||||
|
if idx < 0 {
|
||||||
return ""
|
return ""
|
||||||
}
|
}
|
||||||
|
return decodePURLComponent(p[idx+1:])
|
||||||
|
}
|
||||||
|
|
||||||
|
// decodePURLComponent percent-decodes a single PURL path component, returning
|
||||||
|
// the input unchanged if it is not valid percent-encoding.
|
||||||
|
func decodePURLComponent(s string) string {
|
||||||
|
if !strings.Contains(s, "%") {
|
||||||
|
return s
|
||||||
|
}
|
||||||
|
decoded, err := url.PathUnescape(s)
|
||||||
|
if err != nil {
|
||||||
|
return s
|
||||||
|
}
|
||||||
|
return decoded
|
||||||
|
}
|
||||||
|
|
||||||
// Artifact represents a cached artifact in the database.
|
// Artifact represents a cached artifact in the database.
|
||||||
// This table is proxy-specific and not part of git-pkgs.
|
// This table is proxy-specific and not part of git-pkgs.
|
||||||
|
|
@ -76,6 +146,16 @@ func (a *Artifact) IsCached() bool {
|
||||||
return a.StoragePath.Valid && a.FetchedAt.Valid
|
return a.StoragePath.Valid && a.FetchedAt.Valid
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// CachedArtifact contains the fields needed to serve a cached artifact.
|
||||||
|
type CachedArtifact struct {
|
||||||
|
Ecosystem string `db:"ecosystem"`
|
||||||
|
StoragePath string `db:"storage_path"`
|
||||||
|
ContentHash sql.NullString `db:"content_hash"`
|
||||||
|
Size sql.NullInt64 `db:"size"`
|
||||||
|
ContentType sql.NullString `db:"content_type"`
|
||||||
|
Integrity sql.NullString `db:"integrity"`
|
||||||
|
}
|
||||||
|
|
||||||
// MetadataCacheEntry represents a cached metadata blob for offline serving.
|
// MetadataCacheEntry represents a cached metadata blob for offline serving.
|
||||||
type MetadataCacheEntry struct {
|
type MetadataCacheEntry struct {
|
||||||
ID int64 `db:"id" json:"id"`
|
ID int64 `db:"id" json:"id"`
|
||||||
|
|
@ -84,6 +164,7 @@ type MetadataCacheEntry struct {
|
||||||
StoragePath string `db:"storage_path" json:"storage_path"`
|
StoragePath string `db:"storage_path" json:"storage_path"`
|
||||||
ETag sql.NullString `db:"etag" json:"etag,omitempty"`
|
ETag sql.NullString `db:"etag" json:"etag,omitempty"`
|
||||||
ContentType sql.NullString `db:"content_type" json:"content_type,omitempty"`
|
ContentType sql.NullString `db:"content_type" json:"content_type,omitempty"`
|
||||||
|
ContentDigest sql.NullString `db:"content_digest" json:"content_digest,omitempty"`
|
||||||
Size sql.NullInt64 `db:"size" json:"size,omitempty"`
|
Size sql.NullInt64 `db:"size" json:"size,omitempty"`
|
||||||
LastModified sql.NullTime `db:"last_modified" json:"last_modified,omitempty"`
|
LastModified sql.NullTime `db:"last_modified" json:"last_modified,omitempty"`
|
||||||
FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"`
|
FetchedAt sql.NullTime `db:"fetched_at" json:"fetched_at,omitempty"`
|
||||||
|
|
|
||||||
159
internal/database/version_purl_test.go
Normal file
159
internal/database/version_purl_test.go
Normal file
|
|
@ -0,0 +1,159 @@
|
||||||
|
package database
|
||||||
|
|
||||||
|
import (
|
||||||
|
"database/sql"
|
||||||
|
"net/url"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestVersionFromPURL(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
purl string
|
||||||
|
want string
|
||||||
|
}{
|
||||||
|
{"simple", "pkg:npm/lodash@4.17.21", "4.17.21"},
|
||||||
|
{"namespaced", "pkg:composer/symfony/console@6.0.0", "6.0.0"},
|
||||||
|
// Debian/Ubuntu versions routinely contain "+", which PURL encodes.
|
||||||
|
{"encoded plus", "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"},
|
||||||
|
{"encoded epoch", "pkg:deb/curl@1%3A7.81.0-1", "1:7.81.0-1"},
|
||||||
|
{"encoded plus with qualifier", "pkg:deb/nmap@7.91%2Bdfsg1?repository_url=http%3A%2F%2Fexample.com", "7.91+dfsg1"},
|
||||||
|
{"tilde is not encoded", "pkg:deb/foo@1.0~rc1", "1.0~rc1"},
|
||||||
|
{"no version", "pkg:npm/lodash", ""},
|
||||||
|
{"invalid escape passed through", "pkg:npm/lodash@1.0%zz", "1.0%zz"},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
if got := VersionFromPURL(tt.purl); got != tt.want {
|
||||||
|
t.Errorf("VersionFromPURL(%q) = %q, want %q", tt.purl, got, tt.want)
|
||||||
|
}
|
||||||
|
v := &Version{PURL: tt.purl}
|
||||||
|
if got := v.Version(); got != tt.want {
|
||||||
|
t.Errorf("Version.Version() for %q = %q, want %q", tt.purl, got, tt.want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestVersionEscapedVersion checks the value the templates put in a URL. It
|
||||||
|
// must survive the round trip back through the router: escaping here and
|
||||||
|
// decoding per path segment on the way in has to yield the original version.
|
||||||
|
func TestVersionEscapedVersion(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
purl string
|
||||||
|
want string
|
||||||
|
}{
|
||||||
|
{"simple", "pkg:npm/lodash@4.17.21", "4.17.21"},
|
||||||
|
// "+" is legal in a path segment, so it stays literal and the UI keeps
|
||||||
|
// showing the version the way Debian writes it.
|
||||||
|
{"plus stays literal", "pkg:deb/nmap@7.91%2Bdfsg1-2ubuntu0.1", "7.91+dfsg1-2ubuntu0.1"},
|
||||||
|
// A slash would otherwise split the version into two path segments.
|
||||||
|
{"slash", "pkg:golang/example@release%2F1", "release%2F1"},
|
||||||
|
// A question mark would otherwise start the query string.
|
||||||
|
{"question mark", "pkg:npm/example@v1%3Fbuild", "v1%3Fbuild"},
|
||||||
|
// A version containing a literal "%2B" is stored double-encoded; the
|
||||||
|
// link must re-encode it or it decodes back to "+" instead.
|
||||||
|
{"literal percent escape", "pkg:npm/example@1.0%252B", "1.0%252B"},
|
||||||
|
{"space", "pkg:npm/example@1.0%20beta", "1.0%20beta"},
|
||||||
|
{"no version", "pkg:npm/lodash", ""},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
v := &Version{PURL: tt.purl}
|
||||||
|
got := v.EscapedVersion()
|
||||||
|
if got != tt.want {
|
||||||
|
t.Errorf("EscapedVersion() for %q = %q, want %q", tt.purl, got, tt.want)
|
||||||
|
}
|
||||||
|
// The router decodes each path segment, which must give back the
|
||||||
|
// version the page displays.
|
||||||
|
decoded, err := url.PathUnescape(got)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("PathUnescape(%q) failed: %v", got, err)
|
||||||
|
}
|
||||||
|
if decoded != v.Version() {
|
||||||
|
t.Errorf("round trip for %q = %q, want %q", tt.purl, decoded, v.Version())
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestVersionDisplayPURL(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
purl string
|
||||||
|
want string
|
||||||
|
}{
|
||||||
|
{"simple", "pkg:npm/lodash@4.17.21", "pkg:npm/lodash@4.17.21"},
|
||||||
|
{
|
||||||
|
"encoded plus",
|
||||||
|
"pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1",
|
||||||
|
"pkg:deb/nmap@7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"qualifier preserved",
|
||||||
|
"pkg:deb/nmap@7.91%2Bdfsg1?repository_url=http%3A%2F%2Fexample.com",
|
||||||
|
"pkg:deb/nmap@7.91+dfsg1?repository_url=http%3A%2F%2Fexample.com",
|
||||||
|
},
|
||||||
|
// The namespace is encoded too: MakePURLString("npm", "@babel/core", …)
|
||||||
|
// produces "pkg:npm/%40babel/core@…".
|
||||||
|
{"encoded npm scope", "pkg:npm/%40babel/core@7.0.0", "pkg:npm/@babel/core@7.0.0"},
|
||||||
|
{"encoded scope without version", "pkg:npm/%40babel/core", "pkg:npm/@babel/core"},
|
||||||
|
{"no version", "pkg:npm/lodash", "pkg:npm/lodash"},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
v := &Version{PURL: tt.purl}
|
||||||
|
if got := v.DisplayPURL(); got != tt.want {
|
||||||
|
t.Errorf("DisplayPURL() for %q = %q, want %q", tt.purl, got, tt.want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestGetRecentlyCachedPackagesDecodesVersion guards the dashboard's "recently
|
||||||
|
// cached" list, which derives the version from the version PURL.
|
||||||
|
func TestGetRecentlyCachedPackagesDecodesVersion(t *testing.T) {
|
||||||
|
runWithBothDatabases(t, func(t *testing.T, db *DB) {
|
||||||
|
const versionPURL = "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1"
|
||||||
|
|
||||||
|
if err := db.UpsertPackage(&Package{
|
||||||
|
PURL: "pkg:deb/nmap", Ecosystem: "deb", Name: "nmap",
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("UpsertPackage failed: %v", err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertVersion(&Version{
|
||||||
|
PURL: versionPURL, PackagePURL: "pkg:deb/nmap",
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("UpsertVersion failed: %v", err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertArtifact(&Artifact{
|
||||||
|
VersionPURL: versionPURL,
|
||||||
|
Filename: "nmap_7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1_amd64.deb",
|
||||||
|
UpstreamURL: "http://archive.ubuntu.com/ubuntu/pool/universe/n/nmap/nmap.deb",
|
||||||
|
StoragePath: sql.NullString{String: "/cache/nmap.deb", Valid: true},
|
||||||
|
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("UpsertArtifact failed: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
recent, err := db.GetRecentlyCachedPackages(10)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetRecentlyCachedPackages failed: %v", err)
|
||||||
|
}
|
||||||
|
if len(recent) != 1 {
|
||||||
|
t.Fatalf("expected 1 recent package, got %d", len(recent))
|
||||||
|
}
|
||||||
|
const want = "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"
|
||||||
|
if recent[0].Version != want {
|
||||||
|
t.Errorf("Version = %q, want %q", recent[0].Version, want)
|
||||||
|
}
|
||||||
|
if recent[0].VersionPURL != versionPURL {
|
||||||
|
t.Errorf("VersionPURL = %q, want %q", recent[0].VersionPURL, versionPURL)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
@ -201,43 +201,6 @@ func (s *Service) CheckVulnerabilities(ctx context.Context, ecosystem, name, ver
|
||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// BulkCheckVulnerabilities queries vulnerabilities for multiple package versions.
|
|
||||||
func (s *Service) BulkCheckVulnerabilities(ctx context.Context, packages []struct{ Ecosystem, Name, Version string }) (map[string][]VulnInfo, error) {
|
|
||||||
purls := make([]*purl.PURL, len(packages))
|
|
||||||
for i, pkg := range packages {
|
|
||||||
purls[i] = purl.MakePURL(pkg.Ecosystem, pkg.Name, pkg.Version)
|
|
||||||
}
|
|
||||||
|
|
||||||
vulnResults, err := s.vulnSource.QueryBatch(ctx, purls)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
result := make(map[string][]VulnInfo, len(packages))
|
|
||||||
for i, vulnList := range vulnResults {
|
|
||||||
pkg := packages[i]
|
|
||||||
key := purl.MakePURLString(pkg.Ecosystem, pkg.Name, pkg.Version)
|
|
||||||
|
|
||||||
var infos []VulnInfo
|
|
||||||
for _, v := range vulnList {
|
|
||||||
info := VulnInfo{
|
|
||||||
ID: v.ID,
|
|
||||||
Summary: v.Summary,
|
|
||||||
Severity: v.SeverityLevel(),
|
|
||||||
CVSSScore: v.CVSSScore(),
|
|
||||||
FixedVersion: v.FixedVersion(pkg.Ecosystem, pkg.Name),
|
|
||||||
}
|
|
||||||
for _, ref := range v.References {
|
|
||||||
info.References = append(info.References, ref.URL)
|
|
||||||
}
|
|
||||||
infos = append(infos, info)
|
|
||||||
}
|
|
||||||
result[key] = infos
|
|
||||||
}
|
|
||||||
|
|
||||||
return result, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// IsOutdated checks if a version is older than the latest version.
|
// IsOutdated checks if a version is older than the latest version.
|
||||||
func (s *Service) IsOutdated(currentVersion, latestVersion string) bool {
|
func (s *Service) IsOutdated(currentVersion, latestVersion string) bool {
|
||||||
if latestVersion == "" || currentVersion == "" {
|
if latestVersion == "" || currentVersion == "" {
|
||||||
|
|
@ -288,19 +251,6 @@ func (s *Service) CategorizeLicense(license string) LicenseCategory {
|
||||||
return LicenseUnknown
|
return LicenseUnknown
|
||||||
}
|
}
|
||||||
|
|
||||||
// NormalizeLicense normalizes a license string to SPDX format.
|
|
||||||
func (s *Service) NormalizeLicense(license string) string {
|
|
||||||
if license == "" {
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
|
|
||||||
if normalized, err := spdx.NormalizeExpressionLax(license); err == nil {
|
|
||||||
return normalized
|
|
||||||
}
|
|
||||||
|
|
||||||
return license
|
|
||||||
}
|
|
||||||
|
|
||||||
// EnrichmentResult contains all enrichment data for a package version.
|
// EnrichmentResult contains all enrichment data for a package version.
|
||||||
type EnrichmentResult struct {
|
type EnrichmentResult struct {
|
||||||
Package *PackageInfo
|
Package *PackageInfo
|
||||||
|
|
|
||||||
|
|
@ -74,25 +74,3 @@ func TestCategorizeLicense(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestNormalizeLicense(t *testing.T) {
|
|
||||||
logger := slog.New(slog.NewTextHandler(os.Stdout, nil))
|
|
||||||
svc := New(logger)
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
input string
|
|
||||||
expected string
|
|
||||||
}{
|
|
||||||
{"MIT", "MIT"},
|
|
||||||
{"Apache 2", "Apache-2.0"},
|
|
||||||
{"Apache-2.0", "Apache-2.0"},
|
|
||||||
{"", ""},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tc := range tests {
|
|
||||||
result := svc.NormalizeLicense(tc.input)
|
|
||||||
if result != tc.expected {
|
|
||||||
t.Errorf("NormalizeLicense(%q) = %q, want %q", tc.input, result, tc.expected)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -12,10 +12,10 @@ import (
|
||||||
|
|
||||||
const (
|
const (
|
||||||
dockerHubRegistry = "https://registry-1.docker.io"
|
dockerHubRegistry = "https://registry-1.docker.io"
|
||||||
dockerHubAuth = "https://auth.docker.io"
|
|
||||||
blobMatchCount = 3 // full match + name + digest
|
blobMatchCount = 3 // full match + name + digest
|
||||||
manifestMatchCount = 3 // full match + name + reference
|
manifestMatchCount = 3 // full match + name + reference
|
||||||
tagsListMatchCount = 2 // full match + name
|
tagsListMatchCount = 2 // full match + name
|
||||||
|
registrySelectorParts = 3 // upstream + name + repository
|
||||||
)
|
)
|
||||||
|
|
||||||
// ContainerHandler handles OCI/Docker container registry protocol requests.
|
// ContainerHandler handles OCI/Docker container registry protocol requests.
|
||||||
|
|
@ -24,18 +24,27 @@ const (
|
||||||
type ContainerHandler struct {
|
type ContainerHandler struct {
|
||||||
proxy *Proxy
|
proxy *Proxy
|
||||||
registryURL string
|
registryURL string
|
||||||
authURL string
|
|
||||||
proxyURL string
|
proxyURL string
|
||||||
|
namedRegistries map[string]string
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewContainerHandler creates a new container registry protocol handler.
|
// NewContainerHandler creates a new container registry protocol handler.
|
||||||
func NewContainerHandler(proxy *Proxy, proxyURL string) *ContainerHandler {
|
// Named registries are selected with the repository prefix
|
||||||
return &ContainerHandler{
|
// upstream/{name}/, leaving unprefixed requests compatible with the Docker Hub
|
||||||
|
// mirror behavior.
|
||||||
|
func NewContainerHandler(proxy *Proxy, proxyURL string, namedRegistries ...map[string]string) *ContainerHandler {
|
||||||
|
h := &ContainerHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
registryURL: dockerHubRegistry,
|
registryURL: dockerHubRegistry,
|
||||||
authURL: dockerHubAuth,
|
|
||||||
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
}
|
}
|
||||||
|
if len(namedRegistries) > 0 {
|
||||||
|
h.namedRegistries = make(map[string]string, len(namedRegistries[0]))
|
||||||
|
for name, registryURL := range namedRegistries[0] {
|
||||||
|
h.namedRegistries[name] = strings.TrimSuffix(registryURL, "/")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return h
|
||||||
}
|
}
|
||||||
|
|
||||||
// Routes returns the HTTP handler for container registry requests.
|
// Routes returns the HTTP handler for container registry requests.
|
||||||
|
|
@ -88,33 +97,46 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
h.proxy.Logger.Info("container blob request", "name", name, "digest", digest)
|
registryURL, upstreamName, cacheName, ok := h.registryForName(name)
|
||||||
|
if !ok {
|
||||||
|
h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
// Get auth token for upstream
|
h.proxy.Logger.Info("container blob request", "name", upstreamName, "digest", digest)
|
||||||
token, err := h.getAuthToken(r.Context(), name, "pull")
|
|
||||||
|
filename := digest
|
||||||
|
cached, err := h.proxy.GetCachedArtifact(r.Context(), "oci", cacheName, digest, filename)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.proxy.Logger.Error("failed to get auth token", "error", err)
|
h.proxy.Logger.Error("failed to check blob cache", "error", err)
|
||||||
h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
|
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to check blob cache")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if cached != nil {
|
||||||
|
w.Header().Set("Docker-Content-Digest", digest)
|
||||||
|
if cached.ContentType != "" {
|
||||||
|
w.Header().Set("Content-Type", cached.ContentType)
|
||||||
|
} else {
|
||||||
|
w.Header().Set("Content-Type", "application/octet-stream")
|
||||||
|
}
|
||||||
|
serveArtifact(w, r.Method, cached)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// For HEAD requests, just proxy to upstream
|
// For HEAD requests, just proxy to upstream
|
||||||
if r.Method == http.MethodHead {
|
if r.Method == http.MethodHead {
|
||||||
h.proxyBlobHead(w, r, name, digest, token)
|
h.proxyBlobHead(w, r, registryURL, upstreamName, digest)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// Try to get from cache, or fetch from upstream with auth
|
// Try to get from cache, or fetch from the authentication-aware upstream client.
|
||||||
filename := digest
|
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
||||||
headers := http.Header{"Authorization": {"Bearer " + token}}
|
|
||||||
result, err := h.proxy.GetOrFetchArtifactFromURLWithHeaders(
|
|
||||||
r.Context(),
|
r.Context(),
|
||||||
"oci",
|
"oci",
|
||||||
name,
|
cacheName,
|
||||||
digest, // use digest as version
|
digest, // use digest as version
|
||||||
filename,
|
filename,
|
||||||
fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest),
|
fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, upstreamName, digest),
|
||||||
headers,
|
|
||||||
)
|
)
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -128,12 +150,15 @@ func (h *ContainerHandler) handleBlobDownload(w http.ResponseWriter, r *http.Req
|
||||||
}
|
}
|
||||||
|
|
||||||
w.Header().Set("Docker-Content-Digest", digest)
|
w.Header().Set("Docker-Content-Digest", digest)
|
||||||
|
if result.ContentType != "" {
|
||||||
|
w.Header().Set("Content-Type", result.ContentType)
|
||||||
|
} else {
|
||||||
w.Header().Set("Content-Type", "application/octet-stream")
|
w.Header().Set("Content-Type", "application/octet-stream")
|
||||||
|
}
|
||||||
ServeArtifact(w, result)
|
ServeArtifact(w, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleManifest proxies manifest requests to upstream.
|
// handleManifest serves immutable manifests from cache and revalidates mutable tags.
|
||||||
// Manifests change when tags are updated, so we proxy these directly.
|
|
||||||
// Path format: {name}/manifests/{reference}
|
// Path format: {name}/manifests/{reference}
|
||||||
func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request, path string) {
|
func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request, path string) {
|
||||||
if r.Method != http.MethodGet && r.Method != http.MethodHead {
|
if r.Method != http.MethodGet && r.Method != http.MethodHead {
|
||||||
|
|
@ -147,58 +172,14 @@ func (h *ContainerHandler) handleManifest(w http.ResponseWriter, r *http.Request
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
h.proxy.Logger.Info("container manifest request", "name", name, "reference", reference)
|
registryURL, upstreamName, _, ok := h.registryForName(name)
|
||||||
|
if !ok {
|
||||||
// Get auth token
|
h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
|
||||||
token, err := h.getAuthToken(r.Context(), name, "pull")
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Error("failed to get auth token", "error", err)
|
|
||||||
h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// Proxy to upstream
|
h.proxy.Logger.Info("container manifest request", "name", upstreamName, "reference", reference)
|
||||||
upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", h.registryURL, name, reference)
|
h.serveManifest(w, r, registryURL, upstreamName, reference)
|
||||||
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
req.Header.Set("Authorization", "Bearer "+token)
|
|
||||||
|
|
||||||
// Forward Accept header for content negotiation
|
|
||||||
if accept := r.Header.Get("Accept"); accept != "" {
|
|
||||||
req.Header.Set("Accept", accept)
|
|
||||||
} else {
|
|
||||||
// Default accept headers for manifests
|
|
||||||
req.Header.Set("Accept", strings.Join([]string{
|
|
||||||
"application/vnd.oci.image.manifest.v1+json",
|
|
||||||
"application/vnd.oci.image.index.v1+json",
|
|
||||||
"application/vnd.docker.distribution.manifest.v2+json",
|
|
||||||
"application/vnd.docker.distribution.manifest.list.v2+json",
|
|
||||||
"application/vnd.docker.distribution.manifest.v1+prettyjws",
|
|
||||||
}, ", "))
|
|
||||||
}
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
h.proxy.Logger.Error("failed to fetch manifest", "error", err)
|
|
||||||
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
|
||||||
return
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
// Copy relevant headers
|
|
||||||
for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest", "ETag"} {
|
|
||||||
if v := resp.Header.Get(header); v != "" {
|
|
||||||
w.Header().Set(header, v)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
w.WriteHeader(resp.StatusCode)
|
|
||||||
_, _ = io.Copy(w, resp.Body)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleTagsList proxies tag list requests to upstream.
|
// handleTagsList proxies tag list requests to upstream.
|
||||||
|
|
@ -214,14 +195,13 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// Get auth token
|
registryURL, upstreamName, _, ok := h.registryForName(name)
|
||||||
token, err := h.getAuthToken(r.Context(), name, "pull")
|
if !ok {
|
||||||
if err != nil {
|
h.containerError(w, http.StatusNotFound, "NAME_UNKNOWN", "unknown upstream registry")
|
||||||
h.containerError(w, http.StatusUnauthorized, "UNAUTHORIZED", "failed to authenticate")
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", h.registryURL, name)
|
upstreamURL := fmt.Sprintf("%s/v2/%s/tags/list", registryURL, upstreamName)
|
||||||
if r.URL.RawQuery != "" {
|
if r.URL.RawQuery != "" {
|
||||||
upstreamURL += "?" + r.URL.RawQuery
|
upstreamURL += "?" + r.URL.RawQuery
|
||||||
}
|
}
|
||||||
|
|
@ -232,8 +212,6 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
req.Header.Set("Authorization", "Bearer "+token)
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
resp, err := h.proxy.HTTPClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
||||||
|
|
@ -246,46 +224,9 @@ func (h *ContainerHandler) handleTagsList(w http.ResponseWriter, r *http.Request
|
||||||
_, _ = io.Copy(w, resp.Body)
|
_, _ = io.Copy(w, resp.Body)
|
||||||
}
|
}
|
||||||
|
|
||||||
// getAuthToken gets a bearer token for the specified repository.
|
|
||||||
// Docker Hub requires auth even for public images.
|
|
||||||
func (h *ContainerHandler) getAuthToken(_ interface{ Done() <-chan struct{} }, repository, action string) (string, error) {
|
|
||||||
// For Docker Hub: https://auth.docker.io/token?service=registry.docker.io&scope=repository:{repo}:pull
|
|
||||||
authURL := fmt.Sprintf("%s/token?service=registry.docker.io&scope=repository:%s:%s",
|
|
||||||
h.authURL, repository, action)
|
|
||||||
|
|
||||||
req, err := http.NewRequest(http.MethodGet, authURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
return "", fmt.Errorf("auth failed with status %d", resp.StatusCode)
|
|
||||||
}
|
|
||||||
|
|
||||||
var tokenResp struct {
|
|
||||||
Token string `json:"token"`
|
|
||||||
AccessToken string `json:"access_token"`
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := json.NewDecoder(resp.Body).Decode(&tokenResp); err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
if tokenResp.Token != "" {
|
|
||||||
return tokenResp.Token, nil
|
|
||||||
}
|
|
||||||
return tokenResp.AccessToken, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// proxyBlobHead handles HEAD requests for blobs.
|
// proxyBlobHead handles HEAD requests for blobs.
|
||||||
func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, name, digest, token string) {
|
func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request, registryURL, name, digest string) {
|
||||||
upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", h.registryURL, name, digest)
|
upstreamURL := fmt.Sprintf("%s/v2/%s/blobs/%s", registryURL, name, digest)
|
||||||
|
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodHead, upstreamURL, nil)
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodHead, upstreamURL, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -293,8 +234,6 @@ func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request,
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
req.Header.Set("Authorization", "Bearer "+token)
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
resp, err := h.proxy.HTTPClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
||||||
|
|
@ -311,6 +250,24 @@ func (h *ContainerHandler) proxyBlobHead(w http.ResponseWriter, r *http.Request,
|
||||||
w.WriteHeader(resp.StatusCode)
|
w.WriteHeader(resp.StatusCode)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// registryForName resolves a client-visible OCI repository name to an upstream
|
||||||
|
// registry and its repository name. Named upstreams use upstream/{name}/ as a
|
||||||
|
// reserved prefix; all other names continue to target Docker Hub.
|
||||||
|
func (h *ContainerHandler) registryForName(name string) (registryURL, upstreamName, cacheName string, ok bool) {
|
||||||
|
parts := strings.SplitN(name, "/", registrySelectorParts)
|
||||||
|
if len(parts) >= 2 && parts[0] == "upstream" {
|
||||||
|
if len(parts) != registrySelectorParts || parts[2] == "" {
|
||||||
|
return "", "", "", false
|
||||||
|
}
|
||||||
|
registryURL, ok = h.namedRegistries[parts[1]]
|
||||||
|
if !ok || registryURL == "" {
|
||||||
|
return "", "", "", false
|
||||||
|
}
|
||||||
|
return registryURL, parts[2], name, true
|
||||||
|
}
|
||||||
|
return h.registryURL, name, name, true
|
||||||
|
}
|
||||||
|
|
||||||
// containerError writes an OCI-compliant error response.
|
// containerError writes an OCI-compliant error response.
|
||||||
func (h *ContainerHandler) containerError(w http.ResponseWriter, status int, code, message string) {
|
func (h *ContainerHandler) containerError(w http.ResponseWriter, status int, code, message string) {
|
||||||
w.Header().Set("Content-Type", "application/json")
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
|
|
||||||
251
internal/handler/container_manifest.go
Normal file
251
internal/handler/container_manifest.go
Normal file
|
|
@ -0,0 +1,251 @@
|
||||||
|
package handler
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"crypto/sha256"
|
||||||
|
"database/sql"
|
||||||
|
"encoding/hex"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
|
"net/http"
|
||||||
|
"regexp"
|
||||||
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/git-pkgs/proxy/internal/database"
|
||||||
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
containerManifestCacheEcosystem = "oci-manifest"
|
||||||
|
containerStaleWarning = `110 - "Response is Stale"`
|
||||||
|
)
|
||||||
|
|
||||||
|
var manifestDigestReferencePattern = regexp.MustCompile(`^[a-z0-9]+:[a-f0-9]+$`)
|
||||||
|
|
||||||
|
type cachedContainerManifest struct {
|
||||||
|
body []byte
|
||||||
|
contentType string
|
||||||
|
contentDigest string
|
||||||
|
etag string
|
||||||
|
size int64
|
||||||
|
fetchedAt time.Time
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *ContainerHandler) serveManifest(w http.ResponseWriter, r *http.Request, registryURL, name, reference string) {
|
||||||
|
accept := containerManifestAccept(r)
|
||||||
|
cacheKey := h.containerManifestCacheKey(registryURL, name, reference, accept)
|
||||||
|
cached, err := h.loadContainerManifest(r.Context(), cacheKey)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Warn("failed to read cached container manifest", "error", err)
|
||||||
|
cached = nil
|
||||||
|
}
|
||||||
|
|
||||||
|
immutable := manifestDigestReferencePattern.MatchString(reference)
|
||||||
|
if cached != nil && (immutable || h.containerManifestFresh(cached)) {
|
||||||
|
writeContainerManifest(w, r.Method, cached, false)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
upstreamURL := fmt.Sprintf("%s/v2/%s/manifests/%s", registryURL, name, reference)
|
||||||
|
req, err := http.NewRequestWithContext(r.Context(), r.Method, upstreamURL, nil)
|
||||||
|
if err != nil {
|
||||||
|
h.containerError(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create request")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
req.Header.Set("Accept", accept)
|
||||||
|
if cached != nil && cached.etag != "" {
|
||||||
|
req.Header.Set("If-None-Match", cached.etag)
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := h.proxy.HTTPClient.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
h.serveStaleManifestOrError(w, r, cached, err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
if resp.StatusCode == http.StatusNotModified && cached != nil {
|
||||||
|
cached.fetchedAt = time.Now()
|
||||||
|
if err := h.storeContainerManifest(r.Context(), cacheKey, cached); err != nil {
|
||||||
|
h.proxy.Logger.Warn("failed to refresh cached container manifest", "error", err)
|
||||||
|
}
|
||||||
|
writeContainerManifest(w, r.Method, cached, false)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if resp.StatusCode != http.StatusOK {
|
||||||
|
if cached != nil && shouldServeStaleManifest(resp.StatusCode) {
|
||||||
|
writeContainerManifest(w, r.Method, cached, true)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
copyContainerManifestHeaders(w.Header(), resp.Header)
|
||||||
|
w.WriteHeader(resp.StatusCode)
|
||||||
|
_, _ = io.Copy(w, resp.Body)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
if r.Method == http.MethodHead {
|
||||||
|
copyContainerManifestHeaders(w.Header(), resp.Header)
|
||||||
|
w.WriteHeader(http.StatusOK)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
body, err := h.proxy.ReadMetadata(resp.Body)
|
||||||
|
if err != nil {
|
||||||
|
h.serveStaleManifestOrError(w, r, cached, fmt.Errorf("reading manifest: %w", err))
|
||||||
|
return
|
||||||
|
}
|
||||||
|
manifest := &cachedContainerManifest{
|
||||||
|
body: body,
|
||||||
|
contentType: resp.Header.Get("Content-Type"),
|
||||||
|
contentDigest: resp.Header.Get("Docker-Content-Digest"),
|
||||||
|
etag: resp.Header.Get("ETag"),
|
||||||
|
size: int64(len(body)),
|
||||||
|
fetchedAt: time.Now(),
|
||||||
|
}
|
||||||
|
if manifest.contentDigest == "" {
|
||||||
|
manifest.contentDigest = sha256Digest(body)
|
||||||
|
}
|
||||||
|
if err := h.storeContainerManifest(r.Context(), cacheKey, manifest); err != nil {
|
||||||
|
h.proxy.Logger.Warn("failed to cache container manifest", "error", err)
|
||||||
|
}
|
||||||
|
if manifest.contentDigest != reference && manifestDigestReferencePattern.MatchString(manifest.contentDigest) {
|
||||||
|
digestKey := h.containerManifestCacheKey(registryURL, name, manifest.contentDigest, accept)
|
||||||
|
if err := h.storeContainerManifest(r.Context(), digestKey, manifest); err != nil {
|
||||||
|
h.proxy.Logger.Warn("failed to cache container manifest by digest", "error", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
writeContainerManifest(w, r.Method, manifest, false)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *ContainerHandler) serveStaleManifestOrError(w http.ResponseWriter, r *http.Request, cached *cachedContainerManifest, err error) {
|
||||||
|
if cached != nil {
|
||||||
|
h.proxy.Logger.Warn("upstream manifest fetch failed, serving stale cache", "error", err)
|
||||||
|
writeContainerManifest(w, r.Method, cached, true)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
h.proxy.Logger.Error("failed to fetch manifest", "error", err)
|
||||||
|
h.containerError(w, http.StatusBadGateway, "INTERNAL_ERROR", "failed to fetch from upstream")
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *ContainerHandler) containerManifestFresh(manifest *cachedContainerManifest) bool {
|
||||||
|
return h.proxy.MetadataTTL > 0 && !manifest.fetchedAt.IsZero() && time.Since(manifest.fetchedAt) < h.proxy.MetadataTTL
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *ContainerHandler) containerManifestCacheKey(registryURL, name, reference, accept string) string {
|
||||||
|
identity := strings.Join([]string{registryURL, name, reference, accept}, "\x00")
|
||||||
|
sum := sha256.Sum256([]byte(identity))
|
||||||
|
return hex.EncodeToString(sum[:])
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *ContainerHandler) loadContainerManifest(ctx context.Context, cacheKey string) (*cachedContainerManifest, error) {
|
||||||
|
if h.proxy.DB == nil || h.proxy.Storage == nil {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
entry, err := h.proxy.DB.GetMetadataCache(containerManifestCacheEcosystem, cacheKey)
|
||||||
|
if err != nil || entry == nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
reader, err := h.proxy.Storage.Open(ctx, entry.StoragePath)
|
||||||
|
if err != nil {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
defer func() { _ = reader.Close() }()
|
||||||
|
body, err := h.proxy.ReadMetadata(reader)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
manifest := &cachedContainerManifest{body: body, size: int64(len(body))}
|
||||||
|
if entry.ContentType.Valid {
|
||||||
|
manifest.contentType = entry.ContentType.String
|
||||||
|
}
|
||||||
|
if entry.ContentDigest.Valid {
|
||||||
|
manifest.contentDigest = entry.ContentDigest.String
|
||||||
|
} else {
|
||||||
|
manifest.contentDigest = sha256Digest(body)
|
||||||
|
}
|
||||||
|
if entry.ETag.Valid {
|
||||||
|
manifest.etag = entry.ETag.String
|
||||||
|
}
|
||||||
|
if entry.Size.Valid {
|
||||||
|
manifest.size = entry.Size.Int64
|
||||||
|
}
|
||||||
|
if entry.FetchedAt.Valid {
|
||||||
|
manifest.fetchedAt = entry.FetchedAt.Time
|
||||||
|
}
|
||||||
|
return manifest, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *ContainerHandler) storeContainerManifest(ctx context.Context, cacheKey string, manifest *cachedContainerManifest) error {
|
||||||
|
if h.proxy.DB == nil || h.proxy.Storage == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
storagePath := metadataStoragePath(containerManifestCacheEcosystem, cacheKey)
|
||||||
|
size, _, err := h.proxy.Storage.Store(ctx, storagePath, bytes.NewReader(manifest.body))
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("storing manifest: %w", err)
|
||||||
|
}
|
||||||
|
manifest.size = size
|
||||||
|
return h.proxy.DB.UpsertMetadataCache(&database.MetadataCacheEntry{
|
||||||
|
Ecosystem: containerManifestCacheEcosystem,
|
||||||
|
Name: cacheKey,
|
||||||
|
StoragePath: storagePath,
|
||||||
|
ETag: sql.NullString{String: manifest.etag, Valid: manifest.etag != ""},
|
||||||
|
ContentType: sql.NullString{String: manifest.contentType, Valid: manifest.contentType != ""},
|
||||||
|
ContentDigest: sql.NullString{String: manifest.contentDigest, Valid: manifest.contentDigest != ""},
|
||||||
|
Size: sql.NullInt64{Int64: size, Valid: true},
|
||||||
|
FetchedAt: sql.NullTime{Time: manifest.fetchedAt, Valid: !manifest.fetchedAt.IsZero()},
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
func writeContainerManifest(w http.ResponseWriter, method string, manifest *cachedContainerManifest, stale bool) {
|
||||||
|
if manifest.contentType != "" {
|
||||||
|
w.Header().Set("Content-Type", manifest.contentType)
|
||||||
|
}
|
||||||
|
w.Header().Set("Content-Length", strconv.FormatInt(manifest.size, 10))
|
||||||
|
if manifest.contentDigest != "" {
|
||||||
|
w.Header().Set("Docker-Content-Digest", manifest.contentDigest)
|
||||||
|
}
|
||||||
|
if manifest.etag != "" {
|
||||||
|
w.Header().Set("ETag", manifest.etag)
|
||||||
|
}
|
||||||
|
if stale {
|
||||||
|
w.Header().Set("Warning", containerStaleWarning)
|
||||||
|
}
|
||||||
|
w.WriteHeader(http.StatusOK)
|
||||||
|
if method != http.MethodHead {
|
||||||
|
_, _ = w.Write(manifest.body)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func containerManifestAccept(r *http.Request) string {
|
||||||
|
if accept := r.Header.Get("Accept"); accept != "" {
|
||||||
|
return accept
|
||||||
|
}
|
||||||
|
return strings.Join([]string{
|
||||||
|
"application/vnd.oci.image.manifest.v1+json",
|
||||||
|
"application/vnd.oci.image.index.v1+json",
|
||||||
|
"application/vnd.docker.distribution.manifest.v2+json",
|
||||||
|
"application/vnd.docker.distribution.manifest.list.v2+json",
|
||||||
|
"application/vnd.docker.distribution.manifest.v1+prettyjws",
|
||||||
|
}, ", ")
|
||||||
|
}
|
||||||
|
|
||||||
|
func copyContainerManifestHeaders(destination, source http.Header) {
|
||||||
|
for _, header := range []string{"Content-Type", "Content-Length", "Docker-Content-Digest", "ETag", "WWW-Authenticate"} {
|
||||||
|
if value := source.Get(header); value != "" {
|
||||||
|
destination.Set(header, value)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func shouldServeStaleManifest(status int) bool {
|
||||||
|
return status == http.StatusTooManyRequests || status >= http.StatusInternalServerError
|
||||||
|
}
|
||||||
|
|
||||||
|
func sha256Digest(body []byte) string {
|
||||||
|
digest := sha256.Sum256(body)
|
||||||
|
return "sha256:" + hex.EncodeToString(digest[:])
|
||||||
|
}
|
||||||
|
|
@ -1,16 +1,15 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
|
||||||
"context"
|
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"io"
|
"io"
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
|
"strconv"
|
||||||
"testing"
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient"
|
||||||
"github.com/git-pkgs/registries/fetch"
|
"github.com/git-pkgs/registries/fetch"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -135,90 +134,568 @@ func TestContainerHandler_parseTagsListPath(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestContainerHandler_BlobDownload_CachesWithAuth(t *testing.T) {
|
func TestContainerHandler_NamedOCIRegistryServesHelmArtifacts(t *testing.T) {
|
||||||
// Set up a mock auth server that returns a token
|
digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
|
||||||
authServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
manifest := `{"schemaVersion":2,"config":{"mediaType":"application/vnd.cncf.helm.config.v1+json"},"layers":[{"mediaType":"application/vnd.cncf.helm.chart.content.v1.tar+gzip","digest":"` + digest + `"}]}`
|
||||||
w.Header().Set("Content-Type", "application/json")
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
_ = json.NewEncoder(w).Encode(map[string]string{"token": "test-token-123"})
|
switch r.URL.Path {
|
||||||
|
case "/v2/owner/demo/manifests/1.0.0":
|
||||||
|
w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
|
||||||
|
w.Header().Set("Docker-Content-Digest", digest)
|
||||||
|
_, _ = io.WriteString(w, manifest)
|
||||||
|
case "/v2/owner/demo/blobs/" + digest:
|
||||||
|
w.Header().Set("Content-Type", "application/vnd.cncf.helm.chart.content.v1.tar+gzip")
|
||||||
|
_, _ = io.WriteString(w, "chart archive")
|
||||||
|
default:
|
||||||
|
http.NotFound(w, r)
|
||||||
|
}
|
||||||
}))
|
}))
|
||||||
defer authServer.Close()
|
defer upstream.Close()
|
||||||
|
|
||||||
// Set up mock fetcher that captures headers
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
var capturedHeaders http.Header
|
proxy.HTTPClient = upstream.Client()
|
||||||
mf := &mockFetcherWithHeaders{
|
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
||||||
fetchFn: func(_ context.Context, _ string, headers http.Header) (*fetch.Artifact, error) {
|
proxy.Fetcher = fetcher
|
||||||
capturedHeaders = headers
|
t.Cleanup(func() { _ = fetcher.Close() })
|
||||||
return &fetch.Artifact{
|
h := NewContainerHandler(proxy, "http://proxy.example", map[string]string{"ghcr": upstream.URL})
|
||||||
Body: io.NopCloser(bytes.NewReader([]byte("blob-content"))),
|
|
||||||
Size: 12,
|
manifestResponse := httptest.NewRecorder()
|
||||||
ContentType: "application/octet-stream",
|
h.Routes().ServeHTTP(manifestResponse,
|
||||||
}, nil
|
httptest.NewRequest(http.MethodGet, "/upstream/ghcr/owner/demo/manifests/1.0.0", nil))
|
||||||
},
|
if manifestResponse.Code != http.StatusOK {
|
||||||
|
t.Fatalf("manifest status = %d, want 200: %s", manifestResponse.Code, manifestResponse.Body.String())
|
||||||
|
}
|
||||||
|
if got := manifestResponse.Header().Get("Content-Type"); got != "application/vnd.oci.image.manifest.v1+json" {
|
||||||
|
t.Errorf("manifest Content-Type = %q", got)
|
||||||
}
|
}
|
||||||
|
|
||||||
dir := t.TempDir()
|
blobResponse := httptest.NewRecorder()
|
||||||
db, err := database.Create(dir + "/test.db")
|
h.Routes().ServeHTTP(blobResponse,
|
||||||
if err != nil {
|
httptest.NewRequest(http.MethodGet, "/upstream/ghcr/owner/demo/blobs/"+digest, nil))
|
||||||
t.Fatalf("failed to create test database: %v", err)
|
if blobResponse.Code != http.StatusOK {
|
||||||
|
t.Fatalf("blob status = %d, want 200: %s", blobResponse.Code, blobResponse.Body.String())
|
||||||
|
}
|
||||||
|
if got := blobResponse.Header().Get("Content-Type"); got != "application/vnd.cncf.helm.chart.content.v1.tar+gzip" {
|
||||||
|
t.Errorf("blob Content-Type = %q", got)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
t.Cleanup(func() { _ = db.Close() })
|
|
||||||
|
|
||||||
store := newMockStorage()
|
func TestContainerHandler_BlobDownload_DiscoversBearerChallenge(t *testing.T) {
|
||||||
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
|
||||||
proxy := &Proxy{
|
registryRequests := 0
|
||||||
DB: db,
|
tokenRequests := 0
|
||||||
Storage: store,
|
var upstream *httptest.Server
|
||||||
Fetcher: mf,
|
upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
Logger: logger,
|
switch r.URL.Path {
|
||||||
HTTPClient: &http.Client{},
|
case "/token":
|
||||||
|
tokenRequests++
|
||||||
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
_ = json.NewEncoder(w).Encode(map[string]any{
|
||||||
|
"token": "discovered-token",
|
||||||
|
"expires_in": 3600,
|
||||||
|
})
|
||||||
|
case "/v2/library/nginx/blobs/" + digest:
|
||||||
|
registryRequests++
|
||||||
|
if r.Header.Get("Authorization") != "Bearer discovered-token" {
|
||||||
|
w.Header().Set("WWW-Authenticate", `Bearer realm="`+upstream.URL+`/token",service="registry.test",scope="repository:library/nginx:pull"`)
|
||||||
|
http.Error(w, "authentication required", http.StatusUnauthorized)
|
||||||
|
return
|
||||||
}
|
}
|
||||||
|
w.Header().Set("Content-Type", "application/octet-stream")
|
||||||
|
_, _ = io.WriteString(w, "upstream blob")
|
||||||
|
default:
|
||||||
|
http.NotFound(w, r)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
|
authTransport := upstreamhttp.NewTransport(http.DefaultTransport, nil)
|
||||||
|
client := &http.Client{Transport: authTransport}
|
||||||
|
artifactFetcher := fetch.NewFetcher(
|
||||||
|
fetch.WithHTTPClient(client),
|
||||||
|
fetch.WithMaxRetries(0),
|
||||||
|
)
|
||||||
|
t.Cleanup(func() { _ = artifactFetcher.Close() })
|
||||||
|
proxy.Fetcher = artifactFetcher
|
||||||
|
proxy.HTTPClient = client
|
||||||
|
|
||||||
h := &ContainerHandler{
|
h := &ContainerHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
registryURL: "https://registry-1.docker.io",
|
registryURL: upstream.URL,
|
||||||
authURL: authServer.URL,
|
|
||||||
proxyURL: "http://localhost:8080",
|
proxyURL: "http://localhost:8080",
|
||||||
}
|
}
|
||||||
|
|
||||||
handler := h.Routes()
|
for range 2 {
|
||||||
req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd", nil)
|
req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/"+digest, nil)
|
||||||
w := httptest.NewRecorder()
|
w := httptest.NewRecorder()
|
||||||
handler.ServeHTTP(w, req)
|
h.Routes().ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
||||||
|
}
|
||||||
|
if got := w.Body.String(); got != "upstream blob" {
|
||||||
|
t.Errorf("body = %q, want %q", got, "upstream blob")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if tokenRequests != 1 {
|
||||||
|
t.Errorf("token requests = %d, want 1", tokenRequests)
|
||||||
|
}
|
||||||
|
if registryRequests != 2 {
|
||||||
|
t.Errorf("registry requests = %d, want 2", registryRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestContainerHandler_CachedImagePullSurvivesRegistryAndTokenOutages(t *testing.T) {
|
||||||
|
digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
|
||||||
|
manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}`
|
||||||
|
blob := "cached image blob"
|
||||||
|
registryAvailable := true
|
||||||
|
tokenAvailable := true
|
||||||
|
registryRequests := 0
|
||||||
|
tokenRequests := 0
|
||||||
|
|
||||||
|
tokenServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
tokenRequests++
|
||||||
|
if !tokenAvailable {
|
||||||
|
http.Error(w, "token service unavailable", http.StatusServiceUnavailable)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
_ = json.NewEncoder(w).Encode(map[string]any{
|
||||||
|
"token": "discovered-token",
|
||||||
|
"expires_in": 3600,
|
||||||
|
})
|
||||||
|
}))
|
||||||
|
defer tokenServer.Close()
|
||||||
|
|
||||||
|
registryServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
registryRequests++
|
||||||
|
if !registryAvailable {
|
||||||
|
http.Error(w, "registry unavailable", http.StatusServiceUnavailable)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if r.Header.Get("Authorization") != "Bearer discovered-token" {
|
||||||
|
w.Header().Set("WWW-Authenticate", `Bearer realm="`+tokenServer.URL+`",service="registry.test",scope="repository:library/nginx:pull"`)
|
||||||
|
http.Error(w, "authentication required", http.StatusUnauthorized)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
switch r.URL.Path {
|
||||||
|
case "/v2/library/nginx/manifests/latest":
|
||||||
|
w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
|
||||||
|
w.Header().Set("Docker-Content-Digest", digest)
|
||||||
|
_, _ = io.WriteString(w, manifest)
|
||||||
|
case "/v2/library/nginx/blobs/" + digest:
|
||||||
|
w.Header().Set("Content-Type", "application/octet-stream")
|
||||||
|
_, _ = io.WriteString(w, blob)
|
||||||
|
default:
|
||||||
|
http.NotFound(w, r)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer registryServer.Close()
|
||||||
|
|
||||||
|
warmProxy, db, store, _ := setupTestProxy(t)
|
||||||
|
warmClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, nil)}
|
||||||
|
warmFetcher := fetch.NewFetcher(
|
||||||
|
fetch.WithHTTPClient(warmClient),
|
||||||
|
fetch.WithMaxRetries(0),
|
||||||
|
)
|
||||||
|
t.Cleanup(func() { _ = warmFetcher.Close() })
|
||||||
|
warmProxy.Fetcher = warmFetcher
|
||||||
|
warmProxy.HTTPClient = warmClient
|
||||||
|
warmProxy.MetadataTTL = time.Hour
|
||||||
|
warmHandler := (&ContainerHandler{
|
||||||
|
proxy: warmProxy,
|
||||||
|
registryURL: registryServer.URL,
|
||||||
|
proxyURL: "http://localhost:8080",
|
||||||
|
}).Routes()
|
||||||
|
|
||||||
|
for _, request := range []struct {
|
||||||
|
path string
|
||||||
|
body string
|
||||||
|
}{
|
||||||
|
{path: "/library/nginx/manifests/latest", body: manifest},
|
||||||
|
{path: "/library/nginx/blobs/" + digest, body: blob},
|
||||||
|
} {
|
||||||
|
response := httptest.NewRecorder()
|
||||||
|
warmHandler.ServeHTTP(response, httptest.NewRequest(http.MethodGet, request.path, nil))
|
||||||
|
if response.Code != http.StatusOK {
|
||||||
|
t.Fatalf("warming %s: status = %d, want %d; body: %s", request.path, response.Code, http.StatusOK, response.Body.String())
|
||||||
|
}
|
||||||
|
if got := response.Body.String(); got != request.body {
|
||||||
|
t.Fatalf("warming %s: body = %q, want %q", request.path, got, request.body)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
warmRegistryRequests := registryRequests
|
||||||
|
warmTokenRequests := tokenRequests
|
||||||
|
registryAvailable = false
|
||||||
|
tokenAvailable = false
|
||||||
|
|
||||||
|
offlineClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport, nil)}
|
||||||
|
offlineFetcher := fetch.NewFetcher(
|
||||||
|
fetch.WithHTTPClient(offlineClient),
|
||||||
|
fetch.WithMaxRetries(0),
|
||||||
|
)
|
||||||
|
t.Cleanup(func() { _ = offlineFetcher.Close() })
|
||||||
|
offlineProxy := NewProxy(db, store, offlineFetcher, fetch.NewResolver(), warmProxy.Logger)
|
||||||
|
offlineProxy.HTTPClient = offlineClient
|
||||||
|
offlineProxy.MetadataTTL = time.Hour
|
||||||
|
offlineHandler := (&ContainerHandler{
|
||||||
|
proxy: offlineProxy,
|
||||||
|
registryURL: registryServer.URL,
|
||||||
|
proxyURL: "http://localhost:8080",
|
||||||
|
}).Routes()
|
||||||
|
|
||||||
|
for _, request := range []struct {
|
||||||
|
name string
|
||||||
|
path string
|
||||||
|
body string
|
||||||
|
}{
|
||||||
|
{name: "tag manifest", path: "/library/nginx/manifests/latest", body: manifest},
|
||||||
|
{name: "digest manifest", path: "/library/nginx/manifests/" + digest, body: manifest},
|
||||||
|
{name: "blob", path: "/library/nginx/blobs/" + digest, body: blob},
|
||||||
|
} {
|
||||||
|
t.Run(request.name, func(t *testing.T) {
|
||||||
|
response := httptest.NewRecorder()
|
||||||
|
offlineHandler.ServeHTTP(response, httptest.NewRequest(http.MethodGet, request.path, nil))
|
||||||
|
if response.Code != http.StatusOK {
|
||||||
|
t.Fatalf("status = %d, want %d; body: %s", response.Code, http.StatusOK, response.Body.String())
|
||||||
|
}
|
||||||
|
if got := response.Body.String(); got != request.body {
|
||||||
|
t.Errorf("body = %q, want %q", got, request.body)
|
||||||
|
}
|
||||||
|
if got := response.Header().Get("Docker-Content-Digest"); got != digest {
|
||||||
|
t.Errorf("Docker-Content-Digest = %q, want %q", got, digest)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
if registryRequests != warmRegistryRequests {
|
||||||
|
t.Errorf("offline registry requests = %d, want 0", registryRequests-warmRegistryRequests)
|
||||||
|
}
|
||||||
|
if tokenRequests != warmTokenRequests {
|
||||||
|
t.Errorf("offline token requests = %d, want 0", tokenRequests-warmTokenRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestContainerHandler_BlobDownload_CacheHitSkipsAuth(t *testing.T) {
|
||||||
|
proxy, db, store, fetcher := setupTestProxy(t)
|
||||||
|
digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
|
||||||
|
seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob")
|
||||||
|
|
||||||
|
upstreamRequests := 0
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
upstreamRequests++
|
||||||
|
http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
h := &ContainerHandler{
|
||||||
|
proxy: proxy,
|
||||||
|
registryURL: upstream.URL,
|
||||||
|
proxyURL: "http://localhost:8080",
|
||||||
|
}
|
||||||
|
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/library/nginx/blobs/"+digest, nil)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(w, req)
|
||||||
|
|
||||||
if w.Code != http.StatusOK {
|
if w.Code != http.StatusOK {
|
||||||
t.Errorf("got status %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
||||||
}
|
}
|
||||||
|
if got := w.Body.String(); got != "cached blob" {
|
||||||
// Verify auth header was passed to the fetcher
|
t.Errorf("body = %q, want %q", got, "cached blob")
|
||||||
if capturedHeaders == nil {
|
|
||||||
t.Fatal("expected headers to be passed to fetcher, got nil")
|
|
||||||
}
|
}
|
||||||
auth := capturedHeaders.Get("Authorization")
|
if upstreamRequests != 0 {
|
||||||
if auth != "Bearer test-token-123" {
|
t.Errorf("upstream requests = %d, want 0", upstreamRequests)
|
||||||
t.Errorf("Authorization = %q, want %q", auth, "Bearer test-token-123")
|
|
||||||
}
|
}
|
||||||
|
if fetcher.fetchCalled {
|
||||||
// Verify response headers
|
t.Error("fetcher should not be called on cache hit")
|
||||||
if got := w.Header().Get("Docker-Content-Digest"); got != "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd" {
|
|
||||||
t.Errorf("Docker-Content-Digest = %q, want digest", got)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// mockFetcherWithHeaders captures headers passed to FetchWithHeaders.
|
func TestContainerHandler_BlobHead_CacheHitSkipsUpstreamAndAuth(t *testing.T) {
|
||||||
type mockFetcherWithHeaders struct {
|
proxy, db, store, fetcher := setupTestProxy(t)
|
||||||
fetchFn func(ctx context.Context, url string, headers http.Header) (*fetch.Artifact, error)
|
digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
|
||||||
|
seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob")
|
||||||
|
|
||||||
|
upstreamRequests := 0
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
upstreamRequests++
|
||||||
|
http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
|
||||||
|
h := &ContainerHandler{
|
||||||
|
proxy: proxy,
|
||||||
|
registryURL: upstream.URL,
|
||||||
|
proxyURL: "http://localhost:8080",
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *mockFetcherWithHeaders) Fetch(ctx context.Context, url string) (*fetch.Artifact, error) {
|
req := httptest.NewRequest(http.MethodHead, "/library/nginx/blobs/"+digest, nil)
|
||||||
return f.FetchWithHeaders(ctx, url, nil)
|
w := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(w, req)
|
||||||
|
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Fatalf("status = %d, want %d; body: %s", w.Code, http.StatusOK, w.Body.String())
|
||||||
|
}
|
||||||
|
if got := w.Header().Get("Docker-Content-Digest"); got != digest {
|
||||||
|
t.Errorf("Docker-Content-Digest = %q, want %q", got, digest)
|
||||||
|
}
|
||||||
|
if got := w.Header().Get("Content-Length"); got != "11" {
|
||||||
|
t.Errorf("Content-Length = %q, want %q", got, "11")
|
||||||
|
}
|
||||||
|
if w.Body.Len() != 0 {
|
||||||
|
t.Errorf("HEAD response body length = %d, want 0", w.Body.Len())
|
||||||
|
}
|
||||||
|
if upstreamRequests != 0 {
|
||||||
|
t.Errorf("upstream requests = %d, want 0", upstreamRequests)
|
||||||
|
}
|
||||||
|
if fetcher.fetchCalled {
|
||||||
|
t.Error("fetcher should not be called on cache hit")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *mockFetcherWithHeaders) FetchWithHeaders(ctx context.Context, url string, headers http.Header) (*fetch.Artifact, error) {
|
func TestContainerHandler_BlobHead_DirectServeRedirects(t *testing.T) {
|
||||||
return f.fetchFn(ctx, url, headers)
|
proxy, db, store, fetcher := setupTestProxy(t)
|
||||||
|
digest := "sha256:abc123def456abc123def456abc123def456abc123def456abc123def456abcd"
|
||||||
|
seedPackage(t, db, store, "oci", "library/nginx", digest, digest, "cached blob")
|
||||||
|
store.signedURL = "https://storage.example.test/cached-blob?signature=test"
|
||||||
|
proxy.DirectServe = true
|
||||||
|
|
||||||
|
h := &ContainerHandler{
|
||||||
|
proxy: proxy,
|
||||||
|
registryURL: "https://registry.example.test",
|
||||||
|
proxyURL: "http://localhost:8080",
|
||||||
}
|
}
|
||||||
|
|
||||||
func (f *mockFetcherWithHeaders) Head(_ context.Context, _ string) (int64, string, error) {
|
req := httptest.NewRequest(http.MethodHead, "/library/nginx/blobs/"+digest, nil)
|
||||||
return 0, "", nil
|
w := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(w, req)
|
||||||
|
|
||||||
|
if w.Code != http.StatusFound {
|
||||||
|
t.Fatalf("status = %d, want %d", w.Code, http.StatusFound)
|
||||||
|
}
|
||||||
|
if got := w.Header().Get("Location"); got != store.signedURL {
|
||||||
|
t.Errorf("Location = %q, want %q", got, store.signedURL)
|
||||||
|
}
|
||||||
|
wantETag := `"` + sha256Hex("cached blob") + `"`
|
||||||
|
if got := w.Header().Get("ETag"); got != wantETag {
|
||||||
|
t.Errorf("ETag = %q, want %q", got, wantETag)
|
||||||
|
}
|
||||||
|
if w.Body.Len() != 0 {
|
||||||
|
t.Errorf("HEAD response body length = %d, want 0", w.Body.Len())
|
||||||
|
}
|
||||||
|
if fetcher.fetchCalled {
|
||||||
|
t.Error("fetcher should not be called on cache hit")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestContainerHandler_ManifestByDigest_CacheHitSkipsUpstream(t *testing.T) {
|
||||||
|
digest := "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
|
||||||
|
manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}`
|
||||||
|
upstreamAvailable := true
|
||||||
|
upstreamRequests := 0
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
upstreamRequests++
|
||||||
|
if !upstreamAvailable {
|
||||||
|
http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if r.URL.Path != "/v2/library/nginx/manifests/"+digest {
|
||||||
|
http.NotFound(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
|
||||||
|
w.Header().Set("Docker-Content-Digest", digest)
|
||||||
|
w.Header().Set("ETag", `"manifest-etag"`)
|
||||||
|
if r.Method != http.MethodHead {
|
||||||
|
_, _ = io.WriteString(w, manifest)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"}
|
||||||
|
|
||||||
|
first := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil))
|
||||||
|
if first.Code != http.StatusOK {
|
||||||
|
t.Fatalf("initial status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String())
|
||||||
|
}
|
||||||
|
if first.Body.String() != manifest {
|
||||||
|
t.Fatalf("initial body = %q, want %q", first.Body.String(), manifest)
|
||||||
|
}
|
||||||
|
|
||||||
|
upstreamAvailable = false
|
||||||
|
second := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(second, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil))
|
||||||
|
if second.Code != http.StatusOK {
|
||||||
|
t.Fatalf("cached status = %d, want %d; body: %s", second.Code, http.StatusOK, second.Body.String())
|
||||||
|
}
|
||||||
|
if second.Body.String() != manifest {
|
||||||
|
t.Errorf("cached body = %q, want %q", second.Body.String(), manifest)
|
||||||
|
}
|
||||||
|
if got := second.Header().Get("Docker-Content-Digest"); got != digest {
|
||||||
|
t.Errorf("cached Docker-Content-Digest = %q, want %q", got, digest)
|
||||||
|
}
|
||||||
|
|
||||||
|
head := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(head, httptest.NewRequest(http.MethodHead, "/library/nginx/manifests/"+digest, nil))
|
||||||
|
if head.Code != http.StatusOK {
|
||||||
|
t.Fatalf("cached HEAD status = %d, want %d", head.Code, http.StatusOK)
|
||||||
|
}
|
||||||
|
wantLength := strconv.Itoa(len(manifest))
|
||||||
|
if got := head.Header().Get("Content-Length"); got != wantLength {
|
||||||
|
t.Errorf("cached HEAD Content-Length = %q, want %q", got, wantLength)
|
||||||
|
}
|
||||||
|
if head.Body.Len() != 0 {
|
||||||
|
t.Errorf("cached HEAD body length = %d, want 0", head.Body.Len())
|
||||||
|
}
|
||||||
|
if upstreamRequests != 1 {
|
||||||
|
t.Errorf("upstream requests = %d, want 1", upstreamRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestContainerHandler_ManifestByTag_UsesStaleCacheOnUpstreamFailure(t *testing.T) {
|
||||||
|
digest := "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
|
||||||
|
manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.index.v1+json"}`
|
||||||
|
upstreamAvailable := true
|
||||||
|
upstreamRequests := 0
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
upstreamRequests++
|
||||||
|
if !upstreamAvailable {
|
||||||
|
http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
w.Header().Set("Content-Type", "application/vnd.oci.image.index.v1+json")
|
||||||
|
w.Header().Set("Docker-Content-Digest", digest)
|
||||||
|
_, _ = io.WriteString(w, manifest)
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
proxy.MetadataTTL = 0
|
||||||
|
h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"}
|
||||||
|
|
||||||
|
first := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil))
|
||||||
|
if first.Code != http.StatusOK {
|
||||||
|
t.Fatalf("initial status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String())
|
||||||
|
}
|
||||||
|
|
||||||
|
upstreamAvailable = false
|
||||||
|
second := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(second, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil))
|
||||||
|
if second.Code != http.StatusOK {
|
||||||
|
t.Fatalf("stale status = %d, want %d; body: %s", second.Code, http.StatusOK, second.Body.String())
|
||||||
|
}
|
||||||
|
if second.Body.String() != manifest {
|
||||||
|
t.Errorf("stale body = %q, want %q", second.Body.String(), manifest)
|
||||||
|
}
|
||||||
|
if got := second.Header().Get("Warning"); got != `110 - "Response is Stale"` {
|
||||||
|
t.Errorf("Warning = %q, want stale warning", got)
|
||||||
|
}
|
||||||
|
if got := second.Header().Get("Docker-Content-Digest"); got != digest {
|
||||||
|
t.Errorf("stale Docker-Content-Digest = %q, want %q", got, digest)
|
||||||
|
}
|
||||||
|
if upstreamRequests != 2 {
|
||||||
|
t.Errorf("upstream requests = %d, want 2", upstreamRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestContainerHandler_ManifestByTag_CachesDigestAlias(t *testing.T) {
|
||||||
|
digest := "sha256:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc"
|
||||||
|
manifest := `{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json"}`
|
||||||
|
upstreamAvailable := true
|
||||||
|
upstreamRequests := 0
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
upstreamRequests++
|
||||||
|
if !upstreamAvailable {
|
||||||
|
http.Error(w, "upstream unavailable", http.StatusServiceUnavailable)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if r.URL.Path != "/v2/library/nginx/manifests/latest" {
|
||||||
|
http.NotFound(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
|
||||||
|
w.Header().Set("Docker-Content-Digest", digest)
|
||||||
|
_, _ = io.WriteString(w, manifest)
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"}
|
||||||
|
|
||||||
|
first := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil))
|
||||||
|
if first.Code != http.StatusOK {
|
||||||
|
t.Fatalf("tag status = %d, want %d; body: %s", first.Code, http.StatusOK, first.Body.String())
|
||||||
|
}
|
||||||
|
|
||||||
|
upstreamAvailable = false
|
||||||
|
byDigest := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(byDigest, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/"+digest, nil))
|
||||||
|
if byDigest.Code != http.StatusOK {
|
||||||
|
t.Fatalf("digest status = %d, want %d; body: %s", byDigest.Code, http.StatusOK, byDigest.Body.String())
|
||||||
|
}
|
||||||
|
if byDigest.Body.String() != manifest {
|
||||||
|
t.Errorf("digest body = %q, want %q", byDigest.Body.String(), manifest)
|
||||||
|
}
|
||||||
|
if got := byDigest.Header().Get("Docker-Content-Digest"); got != digest {
|
||||||
|
t.Errorf("Docker-Content-Digest = %q, want %q", got, digest)
|
||||||
|
}
|
||||||
|
if upstreamRequests != 1 {
|
||||||
|
t.Errorf("upstream requests = %d, want 1", upstreamRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestContainerHandler_ManifestByTag_StaleHeadChecksUpstream(t *testing.T) {
|
||||||
|
oldDigest := "sha256:dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"
|
||||||
|
newDigest := "sha256:eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
|
||||||
|
currentDigest := oldDigest
|
||||||
|
upstreamRequests := 0
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
upstreamRequests++
|
||||||
|
w.Header().Set("Content-Type", "application/vnd.oci.image.manifest.v1+json")
|
||||||
|
w.Header().Set("Docker-Content-Digest", currentDigest)
|
||||||
|
w.Header().Set("ETag", `"`+currentDigest+`"`)
|
||||||
|
if r.Method != http.MethodHead {
|
||||||
|
_, _ = io.WriteString(w, `{"schemaVersion":2}`)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
proxy.MetadataTTL = 0
|
||||||
|
h := &ContainerHandler{proxy: proxy, registryURL: upstream.URL, proxyURL: "http://localhost:8080"}
|
||||||
|
|
||||||
|
first := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(first, httptest.NewRequest(http.MethodGet, "/library/nginx/manifests/latest", nil))
|
||||||
|
if first.Code != http.StatusOK {
|
||||||
|
t.Fatalf("initial status = %d, want %d", first.Code, http.StatusOK)
|
||||||
|
}
|
||||||
|
|
||||||
|
currentDigest = newDigest
|
||||||
|
head := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(head, httptest.NewRequest(http.MethodHead, "/library/nginx/manifests/latest", nil))
|
||||||
|
if head.Code != http.StatusOK {
|
||||||
|
t.Fatalf("HEAD status = %d, want %d", head.Code, http.StatusOK)
|
||||||
|
}
|
||||||
|
if got := head.Header().Get("Docker-Content-Digest"); got != newDigest {
|
||||||
|
t.Errorf("Docker-Content-Digest = %q, want %q", got, newDigest)
|
||||||
|
}
|
||||||
|
if upstreamRequests != 2 {
|
||||||
|
t.Errorf("upstream requests = %d, want 2", upstreamRequests)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestContainerHandler_Routes_VersionCheck(t *testing.T) {
|
func TestContainerHandler_Routes_VersionCheck(t *testing.T) {
|
||||||
|
|
|
||||||
|
|
@ -12,6 +12,11 @@ func TestDebianHandler_parsePoolPath(t *testing.T) {
|
||||||
{"pool/main/libn/libncurses/libncurses6_6.2-1_amd64.deb", "libncurses6", "6.2-1", "amd64"},
|
{"pool/main/libn/libncurses/libncurses6_6.2-1_amd64.deb", "libncurses6", "6.2-1", "amd64"},
|
||||||
{"pool/contrib/v/virtualbox/virtualbox_6.1.38-1_amd64.deb", "virtualbox", "6.1.38-1", "amd64"},
|
{"pool/contrib/v/virtualbox/virtualbox_6.1.38-1_amd64.deb", "virtualbox", "6.1.38-1", "amd64"},
|
||||||
{"pool/main/g/git/git_2.39.2-1_arm64.deb", "git", "2.39.2-1", "arm64"},
|
{"pool/main/g/git/git_2.39.2-1_arm64.deb", "git", "2.39.2-1", "arm64"},
|
||||||
|
{
|
||||||
|
"pool/universe/n/nmap/nmap_7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1_amd64.deb",
|
||||||
|
"nmap", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1", "amd64",
|
||||||
|
},
|
||||||
|
{"pool/main/o/openssl/openssl_3.0.2-0ubuntu1.15~build1_amd64.deb", "openssl", "3.0.2-0ubuntu1.15~build1", "amd64"},
|
||||||
{"invalid/path", "", "", ""},
|
{"invalid/path", "", "", ""},
|
||||||
{"pool/main/n/nginx/nginx.deb", "", "", ""},
|
{"pool/main/n/nginx/nginx.deb", "", "", ""},
|
||||||
})
|
})
|
||||||
|
|
|
||||||
|
|
@ -49,7 +49,7 @@ func seedPackageWithPURL(t *testing.T, db *database.DB, store *mockStorage, ecos
|
||||||
Filename: filename,
|
Filename: filename,
|
||||||
UpstreamURL: "https://example.com/" + filename,
|
UpstreamURL: "https://example.com/" + filename,
|
||||||
StoragePath: sql.NullString{String: storagePath, Valid: true},
|
StoragePath: sql.NullString{String: storagePath, Valid: true},
|
||||||
ContentHash: sql.NullString{String: "abc123", Valid: true},
|
ContentHash: sql.NullString{String: sha256Hex(content), Valid: true},
|
||||||
Size: sql.NullInt64{Int64: int64(len(content)), Valid: true},
|
Size: sql.NullInt64{Int64: int64(len(content)), Valid: true},
|
||||||
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
|
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
||||||
|
|
|
||||||
|
|
@ -13,6 +13,7 @@ import (
|
||||||
"net/url"
|
"net/url"
|
||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
|
"sync"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/git-pkgs/cooldown"
|
"github.com/git-pkgs/cooldown"
|
||||||
|
|
@ -48,12 +49,19 @@ func hasDotDotSegment(path string) bool {
|
||||||
|
|
||||||
const defaultHTTPTimeout = 30 * time.Second
|
const defaultHTTPTimeout = 30 * time.Second
|
||||||
|
|
||||||
|
const artifactCopyBufferSize = 32 << 10
|
||||||
|
|
||||||
|
var artifactCopyBufferPool = sync.Pool{ //nolint:gochecknoglobals // shared across artifact responses
|
||||||
|
New: func() any {
|
||||||
|
buffer := make([]byte, artifactCopyBufferSize)
|
||||||
|
return &buffer
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
// canonicalPackagePURL returns a versionless PURL in canonical form so cooldown
|
// canonicalPackagePURL returns a versionless PURL in canonical form so cooldown
|
||||||
// lookups match keys produced by config.CooldownConfig.NormalizedPackages.
|
// lookups match keys produced by config.CooldownConfig.NormalizedPackages.
|
||||||
func canonicalPackagePURL(ecosystem, name string) string {
|
func canonicalPackagePURL(ecosystem, name string) string {
|
||||||
p := purl.MakePURL(ecosystem, name, "")
|
return purl.MakePURLString(ecosystem, name, "")
|
||||||
_ = p.Normalize()
|
|
||||||
return p.String()
|
|
||||||
}
|
}
|
||||||
|
|
||||||
const contentTypeJSON = "application/json"
|
const contentTypeJSON = "application/json"
|
||||||
|
|
@ -136,41 +144,59 @@ type CacheResult struct {
|
||||||
|
|
||||||
// GetOrFetchArtifact retrieves an artifact from cache or fetches from upstream.
|
// GetOrFetchArtifact retrieves an artifact from cache or fetches from upstream.
|
||||||
func (p *Proxy) GetOrFetchArtifact(ctx context.Context, ecosystem, name, version, filename string) (*CacheResult, error) {
|
func (p *Proxy) GetOrFetchArtifact(ctx context.Context, ecosystem, name, version, filename string) (*CacheResult, error) {
|
||||||
pkgPURL := purl.MakePURLString(ecosystem, name, "")
|
if cached, err := p.GetCachedArtifact(ctx, ecosystem, name, version, filename); err != nil {
|
||||||
versionPURL := purl.MakePURLString(ecosystem, name, version)
|
|
||||||
|
|
||||||
if cached, err := p.checkCache(ctx, pkgPURL, versionPURL, filename); err != nil {
|
|
||||||
return nil, err
|
return nil, err
|
||||||
} else if cached != nil {
|
} else if cached != nil {
|
||||||
return cached, nil
|
return cached, nil
|
||||||
}
|
}
|
||||||
|
metrics.RecordCacheMiss(ecosystem)
|
||||||
|
|
||||||
|
pkgPURL := purl.MakePURLString(ecosystem, name, "")
|
||||||
|
versionPURL := purl.MakePURLString(ecosystem, name, version)
|
||||||
return p.fetchAndCache(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL)
|
return p.fetchAndCache(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// GetCachedArtifact retrieves an artifact from cache without contacting an upstream.
|
||||||
|
// It returns nil when no usable cache entry exists.
|
||||||
|
func (p *Proxy) GetCachedArtifact(ctx context.Context, ecosystem, name, version, filename string) (*CacheResult, error) {
|
||||||
|
pkgPURL := purl.MakePURLString(ecosystem, name, "")
|
||||||
|
versionPURL := purl.MakePURLString(ecosystem, name, version)
|
||||||
|
return p.checkCache(ctx, pkgPURL, versionPURL, filename)
|
||||||
|
}
|
||||||
|
|
||||||
|
// ClearCachedArtifact removes both an artifact cache record and its stored
|
||||||
|
// bytes after an external integrity check fails.
|
||||||
|
func (p *Proxy) ClearCachedArtifact(ctx context.Context, ecosystem, name, version, filename string) error {
|
||||||
|
if p.DB == nil || p.Storage == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
pkgPURL := purl.MakePURLString(ecosystem, name, "")
|
||||||
|
versionPURL := purl.MakePURLString(ecosystem, name, version)
|
||||||
|
cached, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("looking up cached artifact: %w", err)
|
||||||
|
}
|
||||||
|
if cached == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
if err := p.Storage.Delete(ctx, cached.StoragePath); err != nil {
|
||||||
|
return fmt.Errorf("deleting cached artifact: %w", err)
|
||||||
|
}
|
||||||
|
return p.DB.ClearArtifactCache(versionPURL, filename)
|
||||||
|
}
|
||||||
|
|
||||||
// checkCache looks up an artifact in the cache. Returns nil if not cached.
|
// checkCache looks up an artifact in the cache. Returns nil if not cached.
|
||||||
func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename string) (*CacheResult, error) {
|
func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename string) (*CacheResult, error) {
|
||||||
pkg, err := p.DB.GetPackageByPURL(pkgPURL)
|
artifact, err := p.DB.GetCachedArtifact(pkgPURL, versionPURL, filename)
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("checking package cache: %w", err)
|
|
||||||
}
|
|
||||||
if pkg == nil {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
ver, err := p.DB.GetVersionByPURL(versionPURL)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("checking version cache: %w", err)
|
|
||||||
}
|
|
||||||
if ver == nil {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
artifact, err := p.DB.GetArtifact(versionPURL, filename)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("checking artifact cache: %w", err)
|
return nil, fmt.Errorf("checking artifact cache: %w", err)
|
||||||
}
|
}
|
||||||
if artifact == nil || !artifact.IsCached() {
|
if artifact == nil {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
checks, err := newIntegrityChecks(artifact.ContentHash.String, artifact.Integrity.String)
|
||||||
|
if err != nil {
|
||||||
|
p.rejectUnusableCacheRecord(artifact, versionPURL, filename, err)
|
||||||
return nil, nil
|
return nil, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -182,39 +208,44 @@ func (p *Proxy) checkCache(ctx context.Context, pkgPURL, versionPURL, filename s
|
||||||
}
|
}
|
||||||
|
|
||||||
if p.DirectServe {
|
if p.DirectServe {
|
||||||
signed, err := p.Storage.SignedURL(ctx, artifact.StoragePath.String, p.DirectServeTTL)
|
signed, err := p.Storage.SignedURL(ctx, artifact.StoragePath, p.DirectServeTTL)
|
||||||
if err == nil {
|
if err == nil {
|
||||||
result.RedirectURL = rewriteSignedURLHost(signed, p.DirectServeBaseURL)
|
result.RedirectURL = rewriteSignedURLHost(signed, p.DirectServeBaseURL)
|
||||||
p.recordCacheHit(pkgPURL, versionPURL, filename)
|
p.recordCacheHit(artifact.Ecosystem, versionPURL, filename)
|
||||||
return result, nil
|
return result, nil
|
||||||
}
|
}
|
||||||
if !errors.Is(err, storage.ErrSignedURLUnsupported) {
|
if !errors.Is(err, storage.ErrSignedURLUnsupported) {
|
||||||
p.Logger.Warn("failed to sign storage URL, falling back to streaming",
|
p.Logger.Warn("failed to sign storage URL, falling back to streaming",
|
||||||
"path", artifact.StoragePath.String, "error", err)
|
"path", artifact.StoragePath, "error", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
start := time.Now()
|
start := time.Now()
|
||||||
reader, err := p.Storage.Open(ctx, artifact.StoragePath.String)
|
reader, err := p.Storage.Open(ctx, artifact.StoragePath)
|
||||||
metrics.RecordStorageOperation("read", time.Since(start))
|
metrics.RecordStorageOperation("read", time.Since(start))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
metrics.RecordStorageError("read")
|
metrics.RecordStorageError("read")
|
||||||
p.Logger.Warn("cached artifact missing from storage, will refetch",
|
p.Logger.Warn("cached artifact missing from storage, will refetch",
|
||||||
"path", artifact.StoragePath.String, "error", err)
|
"path", artifact.StoragePath, "error", err)
|
||||||
return nil, nil
|
return nil, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
result.Reader = newVerifyingReader(reader, artifact.ContentHash.String, ver.Integrity.String,
|
result.Reader, err = checks.wrap(reader,
|
||||||
func(reason string) {
|
func(reason string) {
|
||||||
p.Logger.Error("cached artifact failed integrity check",
|
p.Logger.Error("cached artifact failed integrity check",
|
||||||
"purl", versionPURL, "filename", filename,
|
"purl", versionPURL, "filename", filename,
|
||||||
"path", artifact.StoragePath.String, "reason", reason)
|
"path", artifact.StoragePath, "reason", reason)
|
||||||
metrics.RecordIntegrityFailure(pkg.Ecosystem)
|
metrics.RecordIntegrityFailure(purl.NormalizeEcosystem(artifact.Ecosystem))
|
||||||
if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil {
|
if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil {
|
||||||
p.Logger.Warn("failed to clear corrupt artifact from cache", "error", err)
|
p.Logger.Warn("failed to clear corrupt artifact from cache", "error", err)
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
p.recordCacheHit(pkgPURL, versionPURL, filename)
|
if err != nil {
|
||||||
|
_ = reader.Close()
|
||||||
|
p.rejectUnusableCacheRecord(artifact, versionPURL, filename, err)
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
p.recordCacheHit(artifact.Ecosystem, versionPURL, filename)
|
||||||
return result, nil
|
return result, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -238,17 +269,22 @@ func rewriteSignedURLHost(signed, baseURL string) string {
|
||||||
return s.String()
|
return s.String()
|
||||||
}
|
}
|
||||||
|
|
||||||
func (p *Proxy) recordCacheHit(pkgPURL, versionPURL, filename string) {
|
func (p *Proxy) recordCacheHit(ecosystem, versionPURL, filename string) {
|
||||||
_ = p.DB.RecordArtifactHit(versionPURL, filename)
|
_ = p.DB.RecordArtifactHit(versionPURL, filename)
|
||||||
if parsed, err := purl.Parse(pkgPURL); err == nil {
|
metrics.RecordCacheHit(ecosystem)
|
||||||
metrics.RecordCacheHit(purl.PURLTypeToEcosystem(parsed.Type))
|
}
|
||||||
|
|
||||||
|
func (p *Proxy) rejectUnusableCacheRecord(artifact *database.CachedArtifact, versionPURL, filename string, cause error) {
|
||||||
|
p.Logger.Warn("cached artifact has unusable integrity metadata",
|
||||||
|
"purl", versionPURL, "filename", filename,
|
||||||
|
"path", artifact.StoragePath, "error", cause)
|
||||||
|
metrics.RecordIntegrityFailure(purl.NormalizeEcosystem(artifact.Ecosystem))
|
||||||
|
if err := p.DB.ClearArtifactCache(versionPURL, filename); err != nil {
|
||||||
|
p.Logger.Warn("failed to clear unusable artifact from cache", "error", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (p *Proxy) fetchAndCache(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL string) (*CacheResult, error) {
|
func (p *Proxy) fetchAndCache(ctx context.Context, ecosystem, name, version, filename, pkgPURL, versionPURL string) (*CacheResult, error) {
|
||||||
// Record cache miss
|
|
||||||
metrics.RecordCacheMiss(ecosystem)
|
|
||||||
|
|
||||||
// Resolve download URL
|
// Resolve download URL
|
||||||
info, err := p.Resolver.Resolve(ctx, ecosystem, name, version)
|
info, err := p.Resolver.Resolve(ctx, ecosystem, name, version)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -363,29 +399,40 @@ func (p *Proxy) updateCacheDB(ecosystem, name, filename, pkgPURL, versionPURL, u
|
||||||
|
|
||||||
// ServeArtifact writes a CacheResult to an HTTP response.
|
// ServeArtifact writes a CacheResult to an HTTP response.
|
||||||
func ServeArtifact(w http.ResponseWriter, result *CacheResult) {
|
func ServeArtifact(w http.ResponseWriter, result *CacheResult) {
|
||||||
|
serveArtifact(w, http.MethodGet, result)
|
||||||
|
}
|
||||||
|
|
||||||
|
func serveArtifact(w http.ResponseWriter, method string, result *CacheResult) {
|
||||||
if result.RedirectURL != "" {
|
if result.RedirectURL != "" {
|
||||||
if result.Hash != "" {
|
if result.Hash != "" {
|
||||||
w.Header().Set("ETag", fmt.Sprintf(`"%s"`, result.Hash))
|
w.Header().Set("ETag", `"`+result.Hash+`"`)
|
||||||
}
|
}
|
||||||
w.Header().Set("Location", result.RedirectURL)
|
w.Header().Set("Location", result.RedirectURL)
|
||||||
w.WriteHeader(http.StatusFound)
|
w.WriteHeader(http.StatusFound)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if result.Reader != nil {
|
||||||
defer func() { _ = result.Reader.Close() }()
|
defer func() { _ = result.Reader.Close() }()
|
||||||
|
}
|
||||||
|
|
||||||
if result.ContentType != "" {
|
if result.ContentType != "" {
|
||||||
w.Header().Set("Content-Type", result.ContentType)
|
w.Header().Set("Content-Type", result.ContentType)
|
||||||
}
|
}
|
||||||
if result.Size > 0 {
|
if result.Size > 0 || (method == http.MethodHead && result.Size == 0) {
|
||||||
w.Header().Set("Content-Length", fmt.Sprintf("%d", result.Size))
|
w.Header().Set("Content-Length", strconv.FormatInt(result.Size, 10))
|
||||||
}
|
}
|
||||||
if result.Hash != "" {
|
if result.Hash != "" {
|
||||||
w.Header().Set("ETag", fmt.Sprintf(`"%s"`, result.Hash))
|
w.Header().Set("ETag", `"`+result.Hash+`"`)
|
||||||
}
|
}
|
||||||
|
|
||||||
w.WriteHeader(http.StatusOK)
|
w.WriteHeader(http.StatusOK)
|
||||||
_, _ = io.Copy(w, result.Reader)
|
if method != http.MethodHead && result.Reader != nil {
|
||||||
|
buffer := artifactCopyBufferPool.Get().(*[]byte)
|
||||||
|
defer artifactCopyBufferPool.Put(buffer)
|
||||||
|
// Hide optional ReaderFrom methods so io.CopyBuffer uses the pooled buffer.
|
||||||
|
_, _ = io.CopyBuffer(struct{ io.Writer }{w}, result.Reader, *buffer)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// ProxyUpstream forwards a request to an upstream URL without caching.
|
// ProxyUpstream forwards a request to an upstream URL without caching.
|
||||||
|
|
@ -511,12 +558,14 @@ func (p *Proxy) FetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, u
|
||||||
if entry.ContentType.Valid {
|
if entry.ContentType.Valid {
|
||||||
ct = entry.ContentType.String
|
ct = entry.ContentType.String
|
||||||
}
|
}
|
||||||
|
metrics.RecordCacheHit(ecosystem)
|
||||||
return data, ct, nil
|
return data, ct, nil
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
// Cache file missing/unreadable, fall through to upstream
|
// Cache file missing/unreadable, fall through to upstream
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
p.recordMetadataCacheMiss(ecosystem)
|
||||||
|
|
||||||
accept := contentTypeJSON
|
accept := contentTypeJSON
|
||||||
if len(acceptHeaders) > 0 && acceptHeaders[0] != "" {
|
if len(acceptHeaders) > 0 && acceptHeaders[0] != "" {
|
||||||
|
|
@ -564,6 +613,12 @@ func (p *Proxy) FetchOrCacheMetadata(ctx context.Context, ecosystem, cacheKey, u
|
||||||
return data, ct, nil
|
return data, ct, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (p *Proxy) recordMetadataCacheMiss(ecosystem string) {
|
||||||
|
if p.CacheMetadata {
|
||||||
|
metrics.RecordCacheMiss(ecosystem)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// fetchUpstreamMetadata fetches metadata from upstream, using ETag for conditional revalidation.
|
// fetchUpstreamMetadata fetches metadata from upstream, using ETag for conditional revalidation.
|
||||||
// Returns the body, content type, ETag, upstream Last-Modified time, and any error.
|
// Returns the body, content type, ETag, upstream Last-Modified time, and any error.
|
||||||
func (p *Proxy) fetchUpstreamMetadata(ctx context.Context, upstreamURL string, entry *database.MetadataCacheEntry, accept string) ([]byte, string, string, time.Time, error) {
|
func (p *Proxy) fetchUpstreamMetadata(ctx context.Context, upstreamURL string, entry *database.MetadataCacheEntry, accept string) ([]byte, string, string, time.Time, error) {
|
||||||
|
|
@ -807,18 +862,17 @@ func (p *Proxy) GetOrFetchArtifactFromURL(ctx context.Context, ecosystem, name,
|
||||||
}
|
}
|
||||||
|
|
||||||
// GetOrFetchArtifactFromURLWithHeaders retrieves an artifact from cache or fetches from a URL
|
// GetOrFetchArtifactFromURLWithHeaders retrieves an artifact from cache or fetches from a URL
|
||||||
// with additional HTTP headers. This is needed for registries that require authentication
|
// with additional request-specific HTTP headers.
|
||||||
// (e.g. Docker Hub requires a Bearer token even for public images).
|
|
||||||
func (p *Proxy) GetOrFetchArtifactFromURLWithHeaders(ctx context.Context, ecosystem, name, version, filename, downloadURL string, headers http.Header) (*CacheResult, error) {
|
func (p *Proxy) GetOrFetchArtifactFromURLWithHeaders(ctx context.Context, ecosystem, name, version, filename, downloadURL string, headers http.Header) (*CacheResult, error) {
|
||||||
pkgPURL := purl.MakePURLString(ecosystem, name, "")
|
if cached, err := p.GetCachedArtifact(ctx, ecosystem, name, version, filename); err != nil {
|
||||||
versionPURL := purl.MakePURLString(ecosystem, name, version)
|
|
||||||
|
|
||||||
if cached, err := p.checkCache(ctx, pkgPURL, versionPURL, filename); err != nil {
|
|
||||||
return nil, err
|
return nil, err
|
||||||
} else if cached != nil {
|
} else if cached != nil {
|
||||||
return cached, nil
|
return cached, nil
|
||||||
}
|
}
|
||||||
|
metrics.RecordCacheMiss(ecosystem)
|
||||||
|
|
||||||
|
pkgPURL := purl.MakePURLString(ecosystem, name, "")
|
||||||
|
versionPURL := purl.MakePURLString(ecosystem, name, version)
|
||||||
return p.fetchAndCacheFromURL(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL, headers)
|
return p.fetchAndCacheFromURL(ctx, ecosystem, name, version, filename, pkgPURL, versionPURL, downloadURL, headers)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
300
internal/handler/handler_bench_test.go
Normal file
300
internal/handler/handler_bench_test.go
Normal file
|
|
@ -0,0 +1,300 @@
|
||||||
|
package handler
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"crypto/sha256"
|
||||||
|
"database/sql"
|
||||||
|
"encoding/hex"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
|
"log/slog"
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/git-pkgs/proxy/internal/database"
|
||||||
|
"github.com/git-pkgs/proxy/internal/storage"
|
||||||
|
"github.com/git-pkgs/purl"
|
||||||
|
"github.com/git-pkgs/registries/fetch"
|
||||||
|
)
|
||||||
|
|
||||||
|
const benchmarkArtifactSize = 64 << 10
|
||||||
|
|
||||||
|
const benchmarkMetadataSize = 1 << 20
|
||||||
|
|
||||||
|
type benchmarkResponseWriter struct {
|
||||||
|
header http.Header
|
||||||
|
}
|
||||||
|
|
||||||
|
func (w *benchmarkResponseWriter) Header() http.Header {
|
||||||
|
return w.header
|
||||||
|
}
|
||||||
|
|
||||||
|
func (w *benchmarkResponseWriter) Write(p []byte) (int, error) {
|
||||||
|
return len(p), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (w *benchmarkResponseWriter) WriteHeader(_ int) {}
|
||||||
|
|
||||||
|
func benchmarkCachedProxy(b *testing.B) (*Proxy, *mockStorage) {
|
||||||
|
b.Helper()
|
||||||
|
|
||||||
|
proxy, db, store, _ := setupTestProxy(b)
|
||||||
|
content := strings.Repeat("x", benchmarkArtifactSize)
|
||||||
|
seedPackage(b, db, store, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz", content)
|
||||||
|
|
||||||
|
artifact, err := db.GetArtifact("pkg:npm/lodash@4.17.21", "lodash-4.17.21.tgz")
|
||||||
|
if err != nil {
|
||||||
|
b.Fatalf("get seeded artifact: %v", err)
|
||||||
|
}
|
||||||
|
sum := sha256.Sum256([]byte(content))
|
||||||
|
artifact.ContentHash.String = hex.EncodeToString(sum[:])
|
||||||
|
if err := db.UpsertArtifact(artifact); err != nil {
|
||||||
|
b.Fatalf("update seeded artifact hash: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
return proxy, store
|
||||||
|
}
|
||||||
|
|
||||||
|
func BenchmarkArtifactCacheHit(b *testing.B) {
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
b.Run("stream-64KiB", func(b *testing.B) {
|
||||||
|
proxy, _ := benchmarkCachedProxy(b)
|
||||||
|
w := &benchmarkResponseWriter{header: make(http.Header)}
|
||||||
|
b.SetBytes(benchmarkArtifactSize)
|
||||||
|
b.ReportAllocs()
|
||||||
|
b.ResetTimer()
|
||||||
|
|
||||||
|
for b.Loop() {
|
||||||
|
result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
|
||||||
|
if err != nil {
|
||||||
|
b.Fatal(err)
|
||||||
|
}
|
||||||
|
ServeArtifact(w, result)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
b.Run("direct-serve", func(b *testing.B) {
|
||||||
|
proxy, store := benchmarkCachedProxy(b)
|
||||||
|
proxy.DirectServe = true
|
||||||
|
store.signedURL = "https://storage.example/npm/lodash-4.17.21.tgz?signature=abc"
|
||||||
|
w := &benchmarkResponseWriter{header: make(http.Header)}
|
||||||
|
b.ReportAllocs()
|
||||||
|
b.ResetTimer()
|
||||||
|
|
||||||
|
for b.Loop() {
|
||||||
|
result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
|
||||||
|
if err != nil {
|
||||||
|
b.Fatal(err)
|
||||||
|
}
|
||||||
|
ServeArtifact(w, result)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
func BenchmarkArtifactCacheHitParallel(b *testing.B) {
|
||||||
|
proxy, _ := benchmarkCachedProxy(b)
|
||||||
|
ctx := context.Background()
|
||||||
|
b.SetBytes(benchmarkArtifactSize)
|
||||||
|
b.ReportAllocs()
|
||||||
|
b.ResetTimer()
|
||||||
|
|
||||||
|
b.RunParallel(func(pb *testing.PB) {
|
||||||
|
w := &benchmarkResponseWriter{header: make(http.Header)}
|
||||||
|
for pb.Next() {
|
||||||
|
result, err := proxy.GetOrFetchArtifact(ctx, "npm", "lodash", "4.17.21", "lodash-4.17.21.tgz")
|
||||||
|
if err != nil {
|
||||||
|
b.Error(err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
ServeArtifact(w, result)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
func BenchmarkReadMetadata(b *testing.B) {
|
||||||
|
payload := bytes.Repeat([]byte("x"), benchmarkMetadataSize)
|
||||||
|
proxy := &Proxy{MetadataMaxSize: benchmarkMetadataSize}
|
||||||
|
b.SetBytes(benchmarkMetadataSize)
|
||||||
|
b.ReportAllocs()
|
||||||
|
|
||||||
|
var data []byte
|
||||||
|
for b.Loop() {
|
||||||
|
var err error
|
||||||
|
data, err = proxy.ReadMetadata(bytes.NewReader(payload))
|
||||||
|
if err != nil {
|
||||||
|
b.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(data) != len(payload) {
|
||||||
|
b.Fatalf("metadata size = %d, want %d", len(data), len(payload))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func BenchmarkArtifactPURLConstruction(b *testing.B) {
|
||||||
|
for _, tc := range []struct {
|
||||||
|
name string
|
||||||
|
ecosystem string
|
||||||
|
packageID string
|
||||||
|
}{
|
||||||
|
{"npm", "npm", "lodash"},
|
||||||
|
{"scoped-npm", "npm", "@scope/package"},
|
||||||
|
{"go", "golang", "github.com/git-pkgs/proxy"},
|
||||||
|
} {
|
||||||
|
b.Run(tc.name, func(b *testing.B) {
|
||||||
|
b.ReportAllocs()
|
||||||
|
var packagePURL, versionPURL string
|
||||||
|
for b.Loop() {
|
||||||
|
packagePURL = purl.MakePURLString(tc.ecosystem, tc.packageID, "")
|
||||||
|
versionPURL = purl.MakePURLString(tc.ecosystem, tc.packageID, "1.2.3")
|
||||||
|
}
|
||||||
|
if packagePURL == "" || versionPURL == "" {
|
||||||
|
b.Fatal("empty PURL")
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
type benchmarkNPMServer struct {
|
||||||
|
client *http.Client
|
||||||
|
requestURL string
|
||||||
|
db *database.DB
|
||||||
|
versionPURL string
|
||||||
|
filename string
|
||||||
|
}
|
||||||
|
|
||||||
|
func newBenchmarkNPMServer(b *testing.B) *benchmarkNPMServer {
|
||||||
|
b.Helper()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
dir := b.TempDir()
|
||||||
|
db, err := database.Create(filepath.Join(dir, "benchmark.db"))
|
||||||
|
if err != nil {
|
||||||
|
b.Fatalf("create database: %v", err)
|
||||||
|
}
|
||||||
|
b.Cleanup(func() { _ = db.Close() })
|
||||||
|
|
||||||
|
store, err := storage.OpenBucket(ctx, "file://"+filepath.Join(dir, "cache"))
|
||||||
|
if err != nil {
|
||||||
|
b.Fatalf("open storage: %v", err)
|
||||||
|
}
|
||||||
|
b.Cleanup(func() { _ = store.Close() })
|
||||||
|
|
||||||
|
content := bytes.Repeat([]byte("x"), benchmarkArtifactSize)
|
||||||
|
storagePath := storage.ArtifactPath("npm", "", "lodash", "4.17.21", "lodash-4.17.21.tgz")
|
||||||
|
size, hash, err := store.Store(ctx, storagePath, bytes.NewReader(content))
|
||||||
|
if err != nil {
|
||||||
|
b.Fatalf("store artifact: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
pkg := &database.Package{PURL: "pkg:npm/lodash", Ecosystem: "npm", Name: "lodash"}
|
||||||
|
if err := db.UpsertPackage(pkg); err != nil {
|
||||||
|
b.Fatalf("seed package: %v", err)
|
||||||
|
}
|
||||||
|
version := &database.Version{PURL: "pkg:npm/lodash@4.17.21", PackagePURL: pkg.PURL}
|
||||||
|
if err := db.UpsertVersion(version); err != nil {
|
||||||
|
b.Fatalf("seed version: %v", err)
|
||||||
|
}
|
||||||
|
artifact := &database.Artifact{
|
||||||
|
VersionPURL: version.PURL,
|
||||||
|
Filename: "lodash-4.17.21.tgz",
|
||||||
|
UpstreamURL: "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz",
|
||||||
|
StoragePath: sql.NullString{String: storagePath, Valid: true},
|
||||||
|
ContentHash: sql.NullString{String: hash, Valid: true},
|
||||||
|
Size: sql.NullInt64{Int64: size, Valid: true},
|
||||||
|
ContentType: sql.NullString{String: "application/gzip", Valid: true},
|
||||||
|
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
||||||
|
}
|
||||||
|
if err := db.UpsertArtifact(artifact); err != nil {
|
||||||
|
b.Fatalf("seed artifact: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
proxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), logger)
|
||||||
|
handler := NewNPMHandler(proxy, "http://proxy.example", "https://registry.npmjs.org")
|
||||||
|
server := httptest.NewServer(handler.Routes())
|
||||||
|
b.Cleanup(server.Close)
|
||||||
|
client := server.Client()
|
||||||
|
return &benchmarkNPMServer{
|
||||||
|
client: client,
|
||||||
|
requestURL: server.URL + "/lodash/-/lodash-4.17.21.tgz",
|
||||||
|
db: db,
|
||||||
|
versionPURL: version.PURL,
|
||||||
|
filename: artifact.Filename,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *benchmarkNPMServer) request() error {
|
||||||
|
resp, err := s.client.Get(s.requestURL)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("GET cached artifact: %w", err)
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
if resp.StatusCode != http.StatusOK {
|
||||||
|
return fmt.Errorf("GET cached artifact status = %d, want %d", resp.StatusCode, http.StatusOK)
|
||||||
|
}
|
||||||
|
n, err := io.Copy(io.Discard, resp.Body)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("read cached artifact: %w", err)
|
||||||
|
}
|
||||||
|
if n != benchmarkArtifactSize {
|
||||||
|
return fmt.Errorf("cached artifact size = %d, want %d", n, benchmarkArtifactSize)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *benchmarkNPMServer) hitCount(b *testing.B) int64 {
|
||||||
|
b.Helper()
|
||||||
|
artifact, err := s.db.GetArtifact(s.versionPURL, s.filename)
|
||||||
|
if err != nil {
|
||||||
|
b.Fatalf("get artifact hit count: %v", err)
|
||||||
|
}
|
||||||
|
return artifact.HitCount
|
||||||
|
}
|
||||||
|
|
||||||
|
func benchmarkNPMArtifactCacheHitHTTP(b *testing.B, parallel bool) {
|
||||||
|
server := newBenchmarkNPMServer(b)
|
||||||
|
if err := server.request(); err != nil {
|
||||||
|
b.Fatal(err)
|
||||||
|
}
|
||||||
|
startHits := server.hitCount(b)
|
||||||
|
|
||||||
|
b.SetBytes(benchmarkArtifactSize)
|
||||||
|
b.ReportAllocs()
|
||||||
|
b.ResetTimer()
|
||||||
|
if parallel {
|
||||||
|
b.RunParallel(func(pb *testing.PB) {
|
||||||
|
for pb.Next() {
|
||||||
|
if err := server.request(); err != nil {
|
||||||
|
b.Error(err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
} else {
|
||||||
|
for b.Loop() {
|
||||||
|
if err := server.request(); err != nil {
|
||||||
|
b.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
b.StopTimer()
|
||||||
|
|
||||||
|
if hitCount := server.hitCount(b) - startHits; hitCount != int64(b.N) {
|
||||||
|
b.Fatalf("new artifact hits = %d, want %d", hitCount, b.N)
|
||||||
|
}
|
||||||
|
b.ReportMetric(float64(b.N)/b.Elapsed().Seconds(), "requests/s")
|
||||||
|
}
|
||||||
|
|
||||||
|
func BenchmarkNPMArtifactCacheHitHTTP(b *testing.B) {
|
||||||
|
benchmarkNPMArtifactCacheHitHTTP(b, false)
|
||||||
|
}
|
||||||
|
|
||||||
|
func BenchmarkNPMArtifactCacheHitHTTPParallel(b *testing.B) {
|
||||||
|
benchmarkNPMArtifactCacheHitHTTP(b, true)
|
||||||
|
}
|
||||||
|
|
@ -5,7 +5,6 @@ import (
|
||||||
"context"
|
"context"
|
||||||
"database/sql"
|
"database/sql"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
|
||||||
"io"
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
|
|
@ -16,8 +15,11 @@ import (
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/config"
|
"github.com/git-pkgs/proxy/internal/config"
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
"github.com/git-pkgs/proxy/internal/database"
|
||||||
|
"github.com/git-pkgs/proxy/internal/metrics"
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
"github.com/git-pkgs/proxy/internal/storage"
|
||||||
|
"github.com/git-pkgs/purl"
|
||||||
"github.com/git-pkgs/registries/fetch"
|
"github.com/git-pkgs/registries/fetch"
|
||||||
|
"github.com/prometheus/client_golang/prometheus/testutil"
|
||||||
)
|
)
|
||||||
|
|
||||||
// mockStorage implements storage.Storage for testing.
|
// mockStorage implements storage.Storage for testing.
|
||||||
|
|
@ -42,7 +44,7 @@ func (s *mockStorage) Store(_ context.Context, path string, r io.Reader) (int64,
|
||||||
return 0, "", err
|
return 0, "", err
|
||||||
}
|
}
|
||||||
s.files[path] = data
|
s.files[path] = data
|
||||||
return int64(len(data)), "fakehash123", nil
|
return int64(len(data)), sha256Hex(string(data)), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *mockStorage) Open(_ context.Context, path string) (io.ReadCloser, error) {
|
func (s *mockStorage) Open(_ context.Context, path string) (io.ReadCloser, error) {
|
||||||
|
|
@ -128,7 +130,7 @@ func (f *mockFetcher) Head(_ context.Context, _ string) (int64, string, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
// setupTestProxy creates a Proxy with a real DB (SQLite in temp dir) and mock storage/fetcher.
|
// setupTestProxy creates a Proxy with a real DB (SQLite in temp dir) and mock storage/fetcher.
|
||||||
func setupTestProxy(t *testing.T) (*Proxy, *database.DB, *mockStorage, *mockFetcher) {
|
func setupTestProxy(t testing.TB) (*Proxy, *database.DB, *mockStorage, *mockFetcher) {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
dir := t.TempDir()
|
dir := t.TempDir()
|
||||||
|
|
@ -148,11 +150,11 @@ func setupTestProxy(t *testing.T) (*Proxy, *database.DB, *mockStorage, *mockFetc
|
||||||
}
|
}
|
||||||
|
|
||||||
// seedPackage creates a package, version, and cached artifact in the test DB and storage.
|
// seedPackage creates a package, version, and cached artifact in the test DB and storage.
|
||||||
func seedPackage(t *testing.T, db *database.DB, store *mockStorage, ecosystem, name, version, filename, content string) {
|
func seedPackage(t testing.TB, db *database.DB, store *mockStorage, ecosystem, name, version, filename, content string) {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
pkg := &database.Package{
|
pkg := &database.Package{
|
||||||
PURL: fmt.Sprintf("pkg:%s/%s", ecosystem, name),
|
PURL: purl.MakePURLString(ecosystem, name, ""),
|
||||||
Ecosystem: ecosystem,
|
Ecosystem: ecosystem,
|
||||||
Name: name,
|
Name: name,
|
||||||
}
|
}
|
||||||
|
|
@ -160,7 +162,7 @@ func seedPackage(t *testing.T, db *database.DB, store *mockStorage, ecosystem, n
|
||||||
t.Fatalf("failed to upsert package: %v", err)
|
t.Fatalf("failed to upsert package: %v", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
versionPURL := fmt.Sprintf("pkg:%s/%s@%s", ecosystem, name, version)
|
versionPURL := purl.MakePURLString(ecosystem, name, version)
|
||||||
ver := &database.Version{
|
ver := &database.Version{
|
||||||
PURL: versionPURL,
|
PURL: versionPURL,
|
||||||
PackagePURL: pkg.PURL,
|
PackagePURL: pkg.PURL,
|
||||||
|
|
@ -177,7 +179,7 @@ func seedPackage(t *testing.T, db *database.DB, store *mockStorage, ecosystem, n
|
||||||
Filename: filename,
|
Filename: filename,
|
||||||
UpstreamURL: "https://example.com/" + filename,
|
UpstreamURL: "https://example.com/" + filename,
|
||||||
StoragePath: sql.NullString{String: storagePath, Valid: true},
|
StoragePath: sql.NullString{String: storagePath, Valid: true},
|
||||||
ContentHash: sql.NullString{String: "abc123", Valid: true},
|
ContentHash: sql.NullString{String: sha256Hex(content), Valid: true},
|
||||||
Size: sql.NullInt64{Int64: int64(len(content)), Valid: true},
|
Size: sql.NullInt64{Int64: int64(len(content)), Valid: true},
|
||||||
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
|
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
||||||
|
|
@ -266,13 +268,80 @@ func TestGetOrFetchArtifact_CacheHit(t *testing.T) {
|
||||||
if result.ContentType != "application/octet-stream" {
|
if result.ContentType != "application/octet-stream" {
|
||||||
t.Errorf("got content type %q, want %q", result.ContentType, "application/octet-stream")
|
t.Errorf("got content type %q, want %q", result.ContentType, "application/octet-stream")
|
||||||
}
|
}
|
||||||
if result.Hash != "abc123" {
|
if result.Hash != sha256Hex("cached content") {
|
||||||
t.Errorf("got hash %q, want %q", result.Hash, "abc123")
|
t.Errorf("got hash %q, want %q", result.Hash, sha256Hex("cached content"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestGetCachedArtifactRejectsMalformedIntegrityMetadata(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
malformedHash string
|
||||||
|
malformedIntegrity string
|
||||||
|
}{
|
||||||
|
{name: "content hash", malformedHash: "abc123"},
|
||||||
|
{name: "native integrity", malformedIntegrity: "sha512-abc123"},
|
||||||
|
}
|
||||||
|
for _, test := range tests {
|
||||||
|
t.Run(test.name, func(t *testing.T) {
|
||||||
|
assertMalformedCacheRejected(t, test.malformedHash, test.malformedIntegrity)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func assertMalformedCacheRejected(t *testing.T, malformedHash, malformedIntegrity string) {
|
||||||
|
t.Helper()
|
||||||
|
proxy, db, store, _ := setupTestProxy(t)
|
||||||
|
const (
|
||||||
|
packageName = "broken"
|
||||||
|
version = "1.0.0"
|
||||||
|
filename = "broken-1.0.0.tgz"
|
||||||
|
)
|
||||||
|
seedPackage(t, db, store, "npm", packageName, version, filename, "cached content")
|
||||||
|
versionPURL := purl.MakePURLString("npm", packageName, version)
|
||||||
|
|
||||||
|
if malformedHash != "" {
|
||||||
|
artifact, err := db.GetArtifact(versionPURL, filename)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
artifact.ContentHash = sql.NullString{String: malformedHash, Valid: true}
|
||||||
|
if err := db.UpsertArtifact(artifact); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if malformedIntegrity != "" {
|
||||||
|
versionRecord := &database.Version{
|
||||||
|
PURL: versionPURL,
|
||||||
|
PackagePURL: purl.MakePURLString("npm", packageName, ""),
|
||||||
|
Integrity: sql.NullString{String: malformedIntegrity, Valid: true},
|
||||||
|
}
|
||||||
|
if err := db.UpsertVersion(versionRecord); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
proxy.DirectServe = true
|
||||||
|
store.signedURL = "https://cache.example/broken"
|
||||||
|
result, err := proxy.GetCachedArtifact(context.Background(), "npm", packageName, version, filename)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetCachedArtifact: %v", err)
|
||||||
|
}
|
||||||
|
if result != nil {
|
||||||
|
t.Errorf("GetCachedArtifact = %+v, want nil", result)
|
||||||
|
}
|
||||||
|
artifact, err := db.GetArtifact(versionPURL, filename)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if artifact.StoragePath.Valid {
|
||||||
|
t.Error("unusable cache record retained its storage path")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) {
|
func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) {
|
||||||
proxy, _, _, fetcher := setupTestProxy(t)
|
proxy, _, _, fetcher := setupTestProxy(t)
|
||||||
|
missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("npm"))
|
||||||
|
|
||||||
// The resolver will fail because "nonexistent" isn't a real package,
|
// The resolver will fail because "nonexistent" isn't a real package,
|
||||||
// but we're testing that it tries to fetch (doesn't return from cache).
|
// but we're testing that it tries to fetch (doesn't return from cache).
|
||||||
|
|
@ -282,6 +351,10 @@ func TestGetOrFetchArtifact_CacheMiss_NoPackage(t *testing.T) {
|
||||||
if err == nil {
|
if err == nil {
|
||||||
t.Fatal("expected error for uncached package")
|
t.Fatal("expected error for uncached package")
|
||||||
}
|
}
|
||||||
|
missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("npm"))
|
||||||
|
if diff := missesAfter - missesBefore; diff != 1 {
|
||||||
|
t.Errorf("cache misses delta = %.0f, want 1", diff)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) {
|
func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) {
|
||||||
|
|
@ -297,7 +370,7 @@ func TestGetOrFetchArtifactFromURL_CacheMiss_StorageMissing(t *testing.T) {
|
||||||
Filename: "missing-1.0.0.tgz",
|
Filename: "missing-1.0.0.tgz",
|
||||||
UpstreamURL: "https://example.com/missing.tgz",
|
UpstreamURL: "https://example.com/missing.tgz",
|
||||||
StoragePath: sql.NullString{String: "nonexistent/path.tgz", Valid: true},
|
StoragePath: sql.NullString{String: "nonexistent/path.tgz", Valid: true},
|
||||||
ContentHash: sql.NullString{String: "hash", Valid: true},
|
ContentHash: sql.NullString{String: sha256Hex("missing content"), Valid: true},
|
||||||
Size: sql.NullInt64{Int64: 100, Valid: true},
|
Size: sql.NullInt64{Int64: 100, Valid: true},
|
||||||
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
|
ContentType: sql.NullString{String: "application/octet-stream", Valid: true},
|
||||||
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
||||||
|
|
@ -540,6 +613,7 @@ func TestServeArtifact_Stream(t *testing.T) {
|
||||||
func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) {
|
func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) {
|
||||||
proxy, db, store, fetcher := setupTestProxy(t)
|
proxy, db, store, fetcher := setupTestProxy(t)
|
||||||
seedPackage(t, db, store, "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "pypi content")
|
seedPackage(t, db, store, "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "pypi content")
|
||||||
|
missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi"))
|
||||||
|
|
||||||
result, err := proxy.GetOrFetchArtifactFromURL(context.Background(), "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "https://pypi.org/files/requests-2.28.0.tar.gz")
|
result, err := proxy.GetOrFetchArtifactFromURL(context.Background(), "pypi", "requests", "2.28.0", "requests-2.28.0.tar.gz", "https://pypi.org/files/requests-2.28.0.tar.gz")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -553,10 +627,15 @@ func TestGetOrFetchArtifactFromURL_CacheHit(t *testing.T) {
|
||||||
if fetcher.fetchCalled {
|
if fetcher.fetchCalled {
|
||||||
t.Error("fetcher should not be called on cache hit")
|
t.Error("fetcher should not be called on cache hit")
|
||||||
}
|
}
|
||||||
|
missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi"))
|
||||||
|
if diff := missesAfter - missesBefore; diff != 0 {
|
||||||
|
t.Errorf("cache misses delta = %.0f, want 0", diff)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) {
|
func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) {
|
||||||
proxy, _, store, fetcher := setupTestProxy(t)
|
proxy, _, store, fetcher := setupTestProxy(t)
|
||||||
|
missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi"))
|
||||||
|
|
||||||
fetcher.artifact = &fetch.Artifact{
|
fetcher.artifact = &fetch.Artifact{
|
||||||
Body: io.NopCloser(strings.NewReader("fetched content")),
|
Body: io.NopCloser(strings.NewReader("fetched content")),
|
||||||
|
|
@ -589,6 +668,10 @@ func TestGetOrFetchArtifactFromURL_CacheMiss(t *testing.T) {
|
||||||
if _, ok := store.files[storagePath]; !ok {
|
if _, ok := store.files[storagePath]; !ok {
|
||||||
t.Error("artifact was not stored in storage")
|
t.Error("artifact was not stored in storage")
|
||||||
}
|
}
|
||||||
|
missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("pypi"))
|
||||||
|
if diff := missesAfter - missesBefore; diff != 1 {
|
||||||
|
t.Errorf("cache misses delta = %.0f, want 1", diff)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGetOrFetchArtifactFromURL_FetchError(t *testing.T) {
|
func TestGetOrFetchArtifactFromURL_FetchError(t *testing.T) {
|
||||||
|
|
@ -878,6 +961,8 @@ func TestProxyCached_NoValidators_OmitsHeaders(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) {
|
func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) {
|
||||||
|
hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test"))
|
||||||
|
missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test"))
|
||||||
upstreamHits := 0
|
upstreamHits := 0
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
upstreamHits++
|
upstreamHits++
|
||||||
|
|
@ -904,6 +989,12 @@ func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) {
|
||||||
if upstreamHits != 1 {
|
if upstreamHits != 1 {
|
||||||
t.Fatalf("expected 1 upstream hit, got %d", upstreamHits)
|
t.Fatalf("expected 1 upstream hit, got %d", upstreamHits)
|
||||||
}
|
}
|
||||||
|
if diff := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - missesBefore; diff != 1 {
|
||||||
|
t.Errorf("cache misses delta after first request = %.0f, want 1", diff)
|
||||||
|
}
|
||||||
|
if diff := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - hitsBefore; diff != 0 {
|
||||||
|
t.Errorf("cache hits delta after first request = %.0f, want 0", diff)
|
||||||
|
}
|
||||||
|
|
||||||
// Second request within TTL should serve from cache without hitting upstream
|
// Second request within TTL should serve from cache without hitting upstream
|
||||||
body, _, err = proxy.FetchOrCacheMetadata(ctx, "test", "ttl-pkg", upstream.URL+"/pkg")
|
body, _, err = proxy.FetchOrCacheMetadata(ctx, "test", "ttl-pkg", upstream.URL+"/pkg")
|
||||||
|
|
@ -916,9 +1007,16 @@ func TestFetchOrCacheMetadata_TTL_ServesFreshFromCache(t *testing.T) {
|
||||||
if upstreamHits != 1 {
|
if upstreamHits != 1 {
|
||||||
t.Errorf("expected upstream to still be hit only once, got %d", upstreamHits)
|
t.Errorf("expected upstream to still be hit only once, got %d", upstreamHits)
|
||||||
}
|
}
|
||||||
|
if diff := testutil.ToFloat64(metrics.CacheHits.WithLabelValues("test")) - hitsBefore; diff != 1 {
|
||||||
|
t.Errorf("cache hits delta after second request = %.0f, want 1", diff)
|
||||||
|
}
|
||||||
|
if diff := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test")) - missesBefore; diff != 1 {
|
||||||
|
t.Errorf("cache misses delta after second request = %.0f, want 1", diff)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) {
|
func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) {
|
||||||
|
missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test"))
|
||||||
upstreamHits := 0
|
upstreamHits := 0
|
||||||
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
upstreamHits++
|
upstreamHits++
|
||||||
|
|
@ -947,6 +1045,40 @@ func TestFetchOrCacheMetadata_TTL_Zero_AlwaysRevalidates(t *testing.T) {
|
||||||
if upstreamHits != 2 {
|
if upstreamHits != 2 {
|
||||||
t.Errorf("expected 2 upstream hits with TTL=0, got %d", upstreamHits)
|
t.Errorf("expected 2 upstream hits with TTL=0, got %d", upstreamHits)
|
||||||
}
|
}
|
||||||
|
missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues("test"))
|
||||||
|
if diff := missesAfter - missesBefore; diff != 2 {
|
||||||
|
t.Errorf("cache misses delta = %.0f, want 2", diff)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchOrCacheMetadata_CacheDisabledDoesNotRecordMetrics(t *testing.T) {
|
||||||
|
const ecosystem = "metadata-disabled"
|
||||||
|
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
_, _ = w.Write([]byte(`{"v":1}`))
|
||||||
|
}))
|
||||||
|
t.Cleanup(upstream.Close)
|
||||||
|
|
||||||
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
|
||||||
|
hitsBefore := testutil.ToFloat64(metrics.CacheHits.WithLabelValues(ecosystem))
|
||||||
|
missesBefore := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues(ecosystem))
|
||||||
|
|
||||||
|
_, _, err := proxy.FetchOrCacheMetadata(context.Background(), ecosystem, "pkg", upstream.URL+"/pkg")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("fetch metadata: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
hitsAfter := testutil.ToFloat64(metrics.CacheHits.WithLabelValues(ecosystem))
|
||||||
|
missesAfter := testutil.ToFloat64(metrics.CacheMisses.WithLabelValues(ecosystem))
|
||||||
|
if diff := hitsAfter - hitsBefore; diff != 0 {
|
||||||
|
t.Errorf("cache hits delta = %.0f, want 0", diff)
|
||||||
|
}
|
||||||
|
if diff := missesAfter - missesBefore; diff != 0 {
|
||||||
|
t.Errorf("cache misses delta = %.0f, want 0", diff)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestProxyCached_StaleWarningHeader(t *testing.T) {
|
func TestProxyCached_StaleWarningHeader(t *testing.T) {
|
||||||
|
|
|
||||||
364
internal/handler/helm.go
Normal file
364
internal/handler/helm.go
Normal file
|
|
@ -0,0 +1,364 @@
|
||||||
|
package handler
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/sha256"
|
||||||
|
"encoding/hex"
|
||||||
|
"errors"
|
||||||
|
"fmt"
|
||||||
|
"net/http"
|
||||||
|
"net/url"
|
||||||
|
"path"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"gopkg.in/yaml.v3"
|
||||||
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
helmMetadataEcosystem = "helm"
|
||||||
|
helmIndexFilename = "index.yaml"
|
||||||
|
sha256HexLength = 64
|
||||||
|
)
|
||||||
|
|
||||||
|
// HelmHandler serves read-only HTTP Helm chart repositories. Each configured
|
||||||
|
// repository is mounted at /helm/{repository}/.
|
||||||
|
type HelmHandler struct {
|
||||||
|
proxy *Proxy
|
||||||
|
proxyURL string
|
||||||
|
repositories map[string]string
|
||||||
|
}
|
||||||
|
|
||||||
|
// NewHelmHandler creates a Helm chart repository protocol handler.
|
||||||
|
func NewHelmHandler(proxy *Proxy, proxyURL string, repositories map[string]string) *HelmHandler {
|
||||||
|
h := &HelmHandler{
|
||||||
|
proxyURL: strings.TrimSuffix(proxyURL, "/"),
|
||||||
|
repositories: make(map[string]string, len(repositories)),
|
||||||
|
proxy: proxy,
|
||||||
|
}
|
||||||
|
for name, repositoryURL := range repositories {
|
||||||
|
h.repositories[name] = strings.TrimSuffix(repositoryURL, "/")
|
||||||
|
}
|
||||||
|
return h
|
||||||
|
}
|
||||||
|
|
||||||
|
// Routes returns the HTTP handler for Helm chart repository requests.
|
||||||
|
func (h *HelmHandler) Routes() http.Handler {
|
||||||
|
mux := http.NewServeMux()
|
||||||
|
mux.HandleFunc("GET /{repository}/index.yaml", h.handleIndex)
|
||||||
|
mux.HandleFunc("GET /{repository}/charts/{digest}/{filename}", h.handleChart)
|
||||||
|
return mux
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) handleIndex(w http.ResponseWriter, r *http.Request) {
|
||||||
|
repository, upstreamURL, ok := h.repositoryForRequest(r)
|
||||||
|
if !ok {
|
||||||
|
http.NotFound(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
body, contentType, err := h.fetchIndex(r, repository, upstreamURL)
|
||||||
|
if err != nil {
|
||||||
|
h.serveIndexError(w, err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
rewritten, err := h.rewriteIndex(repository, upstreamURL, body)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Warn("failed to rewrite Helm index", "repository", repository, "error", err)
|
||||||
|
http.Error(w, "invalid Helm repository index", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
h.proxy.writeMetadataCachedResponse(w, r, helmMetadataEcosystem, h.indexCacheKey(repository, upstreamURL), rewritten, contentType)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) handleChart(w http.ResponseWriter, r *http.Request) {
|
||||||
|
repository, upstreamURL, ok := h.repositoryForRequest(r)
|
||||||
|
if !ok {
|
||||||
|
http.NotFound(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
digest, ok := normalizeHelmDigest(r.PathValue("digest"))
|
||||||
|
filename := r.PathValue("filename")
|
||||||
|
if !ok || filename == "" || strings.Contains(filename, "/") || containsPathTraversal(filename) {
|
||||||
|
http.Error(w, "invalid chart request", http.StatusBadRequest)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
cached, err := h.proxy.GetCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Error("failed to check Helm chart cache", "error", err)
|
||||||
|
http.Error(w, "failed to check chart cache", http.StatusInternalServerError)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if cached != nil {
|
||||||
|
h.serveChart(w, r, repository, digest, filename, cached)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
body, _, err := h.fetchIndex(r, repository, upstreamURL)
|
||||||
|
if err != nil {
|
||||||
|
h.serveIndexError(w, err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
downloadURL, err := h.findChartDownload(upstreamURL, body, digest, filename)
|
||||||
|
if err != nil {
|
||||||
|
if errors.Is(err, errHelmChartNotFound) {
|
||||||
|
http.NotFound(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
h.proxy.Logger.Warn("failed to read Helm index", "repository", repository, "error", err)
|
||||||
|
http.Error(w, "invalid Helm repository index", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
result, err := h.proxy.GetOrFetchArtifactFromURL(
|
||||||
|
r.Context(), helmMetadataEcosystem, repository, digest, filename, downloadURL)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.serveArtifactError(w, err, "failed to fetch chart")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
h.serveChart(w, r, repository, digest, filename, result)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) serveChart(w http.ResponseWriter, r *http.Request, repository, digest, filename string, result *CacheResult) {
|
||||||
|
if !strings.EqualFold(result.Hash, digest) {
|
||||||
|
if result.Reader != nil {
|
||||||
|
_ = result.Reader.Close()
|
||||||
|
}
|
||||||
|
if clearErr := h.proxy.ClearCachedArtifact(r.Context(), helmMetadataEcosystem, repository, digest, filename); clearErr != nil {
|
||||||
|
h.proxy.Logger.Warn("failed to clear Helm chart with invalid digest", "error", clearErr)
|
||||||
|
}
|
||||||
|
http.Error(w, "chart digest verification failed", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
if result.ContentType == "" {
|
||||||
|
w.Header().Set("Content-Type", "application/gzip")
|
||||||
|
}
|
||||||
|
ServeArtifact(w, result)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) repositoryForRequest(r *http.Request) (name, upstreamURL string, ok bool) {
|
||||||
|
name = r.PathValue("repository")
|
||||||
|
upstreamURL, ok = h.repositories[name]
|
||||||
|
return name, upstreamURL, ok
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) fetchIndex(r *http.Request, repository, upstreamURL string) ([]byte, string, error) {
|
||||||
|
return h.proxy.FetchOrCacheMetadata(
|
||||||
|
r.Context(),
|
||||||
|
helmMetadataEcosystem,
|
||||||
|
h.indexCacheKey(repository, upstreamURL),
|
||||||
|
upstreamURL+"/"+helmIndexFilename,
|
||||||
|
"application/x-yaml, text/yaml;q=0.9, */*;q=0.1",
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) indexCacheKey(repository, upstreamURL string) string {
|
||||||
|
identity := repository + "\x00" + upstreamURL
|
||||||
|
digest := sha256.Sum256([]byte(identity))
|
||||||
|
return hex.EncodeToString(digest[:])
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) serveIndexError(w http.ResponseWriter, err error) {
|
||||||
|
if errors.Is(err, ErrUpstreamNotFound) {
|
||||||
|
http.Error(w, "Helm repository not found", http.StatusNotFound)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
h.proxy.Logger.Error("failed to fetch Helm index", "error", err)
|
||||||
|
http.Error(w, "failed to fetch Helm repository index", http.StatusBadGateway)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) rewriteIndex(repository, upstreamURL string, body []byte) ([]byte, error) {
|
||||||
|
document, entries, err := parseHelmIndex(body)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
for i := 0; i < len(entries.Content); i += 2 {
|
||||||
|
chartName := entries.Content[i].Value
|
||||||
|
releases := entries.Content[i+1]
|
||||||
|
if releases.Kind != yaml.SequenceNode {
|
||||||
|
return nil, fmt.Errorf("chart %q releases must be a sequence", chartName)
|
||||||
|
}
|
||||||
|
|
||||||
|
filtered := make([]*yaml.Node, 0, len(releases.Content))
|
||||||
|
for _, release := range releases.Content {
|
||||||
|
chart, err := h.parseChartRelease(chartName, upstreamURL, release)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if h.chartOnCooldown(chartName, chart.created) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
for _, download := range chart.downloads {
|
||||||
|
download.node.Value = h.chartProxyURL(repository, chart.digest, download.filename)
|
||||||
|
}
|
||||||
|
filtered = append(filtered, release)
|
||||||
|
}
|
||||||
|
releases.Content = filtered
|
||||||
|
}
|
||||||
|
|
||||||
|
return yaml.Marshal(document)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) findChartDownload(upstreamURL string, body []byte, digest, filename string) (string, error) {
|
||||||
|
_, entries, err := parseHelmIndex(body)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
for i := 0; i < len(entries.Content); i += 2 {
|
||||||
|
chartName := entries.Content[i].Value
|
||||||
|
releases := entries.Content[i+1]
|
||||||
|
if releases.Kind != yaml.SequenceNode {
|
||||||
|
return "", fmt.Errorf("chart %q releases must be a sequence", chartName)
|
||||||
|
}
|
||||||
|
for _, release := range releases.Content {
|
||||||
|
chart, err := h.parseChartRelease(chartName, upstreamURL, release)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
if chart.digest != digest || h.chartOnCooldown(chartName, chart.created) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
for _, download := range chart.downloads {
|
||||||
|
if download.filename == filename {
|
||||||
|
return download.url, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return "", errHelmChartNotFound
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) chartOnCooldown(chartName string, created time.Time) bool {
|
||||||
|
return !created.IsZero() && h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() &&
|
||||||
|
!h.proxy.Cooldown.IsAllowed(helmMetadataEcosystem, canonicalPackagePURL(helmMetadataEcosystem, chartName), created)
|
||||||
|
}
|
||||||
|
|
||||||
|
type helmChartDownload struct {
|
||||||
|
node *yaml.Node
|
||||||
|
url string
|
||||||
|
filename string
|
||||||
|
}
|
||||||
|
|
||||||
|
type helmChartRelease struct {
|
||||||
|
created time.Time
|
||||||
|
digest string
|
||||||
|
downloads []helmChartDownload
|
||||||
|
}
|
||||||
|
|
||||||
|
var errHelmChartNotFound = errors.New("chart not found in Helm index")
|
||||||
|
|
||||||
|
func (h *HelmHandler) parseChartRelease(chartName, upstreamURL string, release *yaml.Node) (helmChartRelease, error) {
|
||||||
|
digestNode := helmMappingValue(release, "digest")
|
||||||
|
urlsNode := helmMappingValue(release, "urls")
|
||||||
|
if digestNode == nil || urlsNode == nil || urlsNode.Kind != yaml.SequenceNode || len(urlsNode.Content) == 0 {
|
||||||
|
return helmChartRelease{}, fmt.Errorf("chart %q has no digest or URLs", chartName)
|
||||||
|
}
|
||||||
|
digest, ok := normalizeHelmDigest(digestNode.Value)
|
||||||
|
if !ok {
|
||||||
|
return helmChartRelease{}, fmt.Errorf("chart %q has invalid digest", chartName)
|
||||||
|
}
|
||||||
|
|
||||||
|
baseURL, err := url.Parse(upstreamURL + "/" + helmIndexFilename)
|
||||||
|
if err != nil {
|
||||||
|
return helmChartRelease{}, fmt.Errorf("parsing Helm repository URL: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
chart := helmChartRelease{digest: digest}
|
||||||
|
if createdNode := helmMappingValue(release, "created"); createdNode != nil && createdNode.Value != "" {
|
||||||
|
chart.created, err = time.Parse(time.RFC3339Nano, createdNode.Value)
|
||||||
|
if err != nil {
|
||||||
|
return helmChartRelease{}, fmt.Errorf("chart %q has invalid creation time: %w", chartName, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, urlNode := range urlsNode.Content {
|
||||||
|
if urlNode.Kind != yaml.ScalarNode {
|
||||||
|
return helmChartRelease{}, fmt.Errorf("chart %q has invalid URL", chartName)
|
||||||
|
}
|
||||||
|
reference, err := url.Parse(urlNode.Value)
|
||||||
|
if err != nil {
|
||||||
|
return helmChartRelease{}, fmt.Errorf("parsing chart %q URL: %w", chartName, err)
|
||||||
|
}
|
||||||
|
downloadURL := baseURL.ResolveReference(reference)
|
||||||
|
if (downloadURL.Scheme != "http" && downloadURL.Scheme != "https") || downloadURL.Host == "" {
|
||||||
|
return helmChartRelease{}, fmt.Errorf("chart %q URL must be HTTP(S)", chartName)
|
||||||
|
}
|
||||||
|
filename := path.Base(downloadURL.Path)
|
||||||
|
if filename == "." || filename == "/" || filename == "" || !strings.HasSuffix(filename, ".tgz") {
|
||||||
|
return helmChartRelease{}, fmt.Errorf("chart %q URL must point to a .tgz file", chartName)
|
||||||
|
}
|
||||||
|
chart.downloads = append(chart.downloads, helmChartDownload{
|
||||||
|
node: urlNode,
|
||||||
|
url: downloadURL.String(),
|
||||||
|
filename: filename,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
return chart, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HelmHandler) chartProxyURL(repository, digest, filename string) string {
|
||||||
|
return fmt.Sprintf("%s/helm/%s/charts/%s/%s", h.proxyURL,
|
||||||
|
url.PathEscape(repository), digest, url.PathEscape(filename))
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseHelmIndex(body []byte) (*yaml.Node, *yaml.Node, error) {
|
||||||
|
var document yaml.Node
|
||||||
|
if err := yaml.Unmarshal(body, &document); err != nil {
|
||||||
|
return nil, nil, fmt.Errorf("parsing Helm index: %w", err)
|
||||||
|
}
|
||||||
|
entries, err := helmIndexEntries(&document)
|
||||||
|
if err != nil {
|
||||||
|
return nil, nil, err
|
||||||
|
}
|
||||||
|
return &document, entries, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func helmIndexEntries(document *yaml.Node) (*yaml.Node, error) {
|
||||||
|
if document == nil {
|
||||||
|
return nil, errors.New("helm index is empty")
|
||||||
|
}
|
||||||
|
if len(document.Content) != 1 || document.Content[0].Kind != yaml.MappingNode {
|
||||||
|
return nil, errors.New("helm index must be a mapping")
|
||||||
|
}
|
||||||
|
entries := helmMappingValue(document.Content[0], "entries")
|
||||||
|
if entries == nil || entries.Kind != yaml.MappingNode {
|
||||||
|
return nil, errors.New("helm index has no entries mapping")
|
||||||
|
}
|
||||||
|
if len(entries.Content)%2 != 0 {
|
||||||
|
return nil, errors.New("helm index entries mapping has an incomplete key-value pair")
|
||||||
|
}
|
||||||
|
return entries, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func helmMappingValue(mapping *yaml.Node, key string) *yaml.Node {
|
||||||
|
if mapping == nil || mapping.Kind != yaml.MappingNode {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
for i := 0; i+1 < len(mapping.Content); i += 2 {
|
||||||
|
if mapping.Content[i].Value == key {
|
||||||
|
return mapping.Content[i+1]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func normalizeHelmDigest(value string) (string, bool) {
|
||||||
|
digest := strings.TrimPrefix(strings.ToLower(value), "sha256:")
|
||||||
|
if len(digest) != sha256HexLength {
|
||||||
|
return "", false
|
||||||
|
}
|
||||||
|
for _, char := range digest {
|
||||||
|
if (char < '0' || char > '9') && (char < 'a' || char > 'f') {
|
||||||
|
return "", false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return digest, true
|
||||||
|
}
|
||||||
337
internal/handler/helm_test.go
Normal file
337
internal/handler/helm_test.go
Normal file
|
|
@ -0,0 +1,337 @@
|
||||||
|
package handler
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/sha256"
|
||||||
|
"encoding/hex"
|
||||||
|
"fmt"
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"strings"
|
||||||
|
"sync/atomic"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/git-pkgs/cooldown"
|
||||||
|
upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient"
|
||||||
|
"github.com/git-pkgs/proxy/internal/storage"
|
||||||
|
"github.com/git-pkgs/registries/fetch"
|
||||||
|
"gopkg.in/yaml.v3"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestHelmHandler_RewritesIndexAndCachesChart(t *testing.T) {
|
||||||
|
chart := []byte("a Helm chart")
|
||||||
|
digest := helmSHA256Hex(chart)
|
||||||
|
var available atomic.Bool
|
||||||
|
available.Store(true)
|
||||||
|
var indexRequests atomic.Int32
|
||||||
|
var chartRequests atomic.Int32
|
||||||
|
|
||||||
|
var upstream *httptest.Server
|
||||||
|
upstream = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if !available.Load() {
|
||||||
|
http.Error(w, "unavailable", http.StatusServiceUnavailable)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
switch r.URL.Path {
|
||||||
|
case "/charts/index.yaml":
|
||||||
|
indexRequests.Add(1)
|
||||||
|
w.Header().Set("Content-Type", "application/x-yaml")
|
||||||
|
_, _ = fmt.Fprintf(w, `apiVersion: v1
|
||||||
|
entries:
|
||||||
|
demo:
|
||||||
|
- annotations:
|
||||||
|
example.com/retained: "true"
|
||||||
|
created: 2020-01-02T03:04:05Z
|
||||||
|
digest: %s
|
||||||
|
name: demo
|
||||||
|
urls:
|
||||||
|
- demo-1.0.0.tgz
|
||||||
|
- %s/charts/mirror/demo-1.0.0.tgz
|
||||||
|
version: 1.0.0
|
||||||
|
generated: 2020-01-02T03:04:05Z
|
||||||
|
`, digest, upstream.URL)
|
||||||
|
case "/charts/demo-1.0.0.tgz", "/charts/mirror/demo-1.0.0.tgz":
|
||||||
|
chartRequests.Add(1)
|
||||||
|
w.Header().Set("Content-Type", "application/gzip")
|
||||||
|
_, _ = w.Write(chart)
|
||||||
|
default:
|
||||||
|
http.NotFound(w, r)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
|
proxy.CacheMetadata = true
|
||||||
|
proxy.MetadataTTL = time.Hour
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
||||||
|
proxy.Fetcher = fetcher
|
||||||
|
t.Cleanup(func() { _ = fetcher.Close() })
|
||||||
|
|
||||||
|
h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": upstream.URL + "/charts"})
|
||||||
|
|
||||||
|
indexResponse := serveHelmRequest(h, "/stable/index.yaml")
|
||||||
|
if indexResponse.Code != http.StatusOK {
|
||||||
|
t.Fatalf("index status = %d, want 200: %s", indexResponse.Code, indexResponse.Body.String())
|
||||||
|
}
|
||||||
|
if got := indexResponse.Header().Get("Content-Type"); got != "application/x-yaml" {
|
||||||
|
t.Errorf("index Content-Type = %q, want application/x-yaml", got)
|
||||||
|
}
|
||||||
|
if strings.Contains(indexResponse.Body.String(), upstream.URL) {
|
||||||
|
t.Errorf("rewritten index contains upstream URL: %s", indexResponse.Body.String())
|
||||||
|
}
|
||||||
|
if !strings.Contains(indexResponse.Body.String(), "example.com/retained") {
|
||||||
|
t.Errorf("rewritten index lost an unrelated field: %s", indexResponse.Body.String())
|
||||||
|
}
|
||||||
|
|
||||||
|
var index map[string]any
|
||||||
|
if err := yaml.Unmarshal(indexResponse.Body.Bytes(), &index); err != nil {
|
||||||
|
t.Fatalf("parse rewritten index: %v", err)
|
||||||
|
}
|
||||||
|
entries := index["entries"].(map[string]any)
|
||||||
|
release := entries["demo"].([]any)[0].(map[string]any)
|
||||||
|
urls := release["urls"].([]any)
|
||||||
|
wantURL := "http://proxy.example/helm/stable/charts/" + digest + "/demo-1.0.0.tgz"
|
||||||
|
for _, rawURL := range urls {
|
||||||
|
if rawURL != wantURL {
|
||||||
|
t.Errorf("rewritten URL = %q, want %q", rawURL, wantURL)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
firstChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz")
|
||||||
|
if firstChart.Code != http.StatusOK {
|
||||||
|
t.Fatalf("chart status = %d, want 200: %s", firstChart.Code, firstChart.Body.String())
|
||||||
|
}
|
||||||
|
if got := firstChart.Body.String(); got != string(chart) {
|
||||||
|
t.Errorf("chart body = %q, want %q", got, chart)
|
||||||
|
}
|
||||||
|
if got := firstChart.Header().Get("Content-Type"); got != "application/gzip" {
|
||||||
|
t.Errorf("chart Content-Type = %q, want application/gzip", got)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Artifact cache availability must not depend on metadata caching or a
|
||||||
|
// reachable index upstream.
|
||||||
|
proxy.CacheMetadata = false
|
||||||
|
available.Store(false)
|
||||||
|
cachedChart := serveHelmRequest(h, "/stable/charts/"+digest+"/demo-1.0.0.tgz")
|
||||||
|
if cachedChart.Code != http.StatusOK {
|
||||||
|
t.Fatalf("cached chart status = %d, want 200: %s", cachedChart.Code, cachedChart.Body.String())
|
||||||
|
}
|
||||||
|
if got := cachedChart.Body.String(); got != string(chart) {
|
||||||
|
t.Errorf("cached chart body = %q, want %q", got, chart)
|
||||||
|
}
|
||||||
|
if got := indexRequests.Load(); got != 1 {
|
||||||
|
t.Errorf("index requests = %d, want 1", got)
|
||||||
|
}
|
||||||
|
if got := chartRequests.Load(); got != 1 {
|
||||||
|
t.Errorf("chart requests = %d, want 1", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestHelmHandler_RejectsChartDigestMismatch(t *testing.T) {
|
||||||
|
chart := []byte("tampered chart")
|
||||||
|
digest := helmSHA256Hex([]byte("expected chart"))
|
||||||
|
requests := 0
|
||||||
|
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
switch r.URL.Path {
|
||||||
|
case "/index.yaml":
|
||||||
|
_, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest)
|
||||||
|
case "/demo.tgz":
|
||||||
|
requests++
|
||||||
|
_, _ = w.Write(chart)
|
||||||
|
default:
|
||||||
|
http.NotFound(w, r)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, store, _ := setupTestProxy(t)
|
||||||
|
proxy.CacheMetadata = true
|
||||||
|
proxy.MetadataTTL = time.Hour
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(upstream.Client()), fetch.WithMaxRetries(0))
|
||||||
|
proxy.Fetcher = fetcher
|
||||||
|
t.Cleanup(func() { _ = fetcher.Close() })
|
||||||
|
h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": upstream.URL})
|
||||||
|
|
||||||
|
for range 2 {
|
||||||
|
response := serveHelmRequest(h, "/test/charts/"+digest+"/demo.tgz")
|
||||||
|
if response.Code != http.StatusBadGateway {
|
||||||
|
t.Errorf("status = %d, want 502: %s", response.Code, response.Body.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if requests != 2 {
|
||||||
|
t.Errorf("chart requests = %d, want 2 after invalid cache entry is cleared", requests)
|
||||||
|
}
|
||||||
|
storagePath := storage.ArtifactPath(helmMetadataEcosystem, "", "test", digest, "demo.tgz")
|
||||||
|
if exists, err := store.Exists(t.Context(), storagePath); err != nil {
|
||||||
|
t.Fatalf("checking rejected chart storage: %v", err)
|
||||||
|
} else if exists {
|
||||||
|
t.Errorf("rejected chart remains in storage at %q", storagePath)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestHelmHandler_IndexCacheChangesWithUpstreamURL(t *testing.T) {
|
||||||
|
firstDigest := strings.Repeat("a", sha256HexLength)
|
||||||
|
secondDigest := strings.Repeat("b", sha256HexLength)
|
||||||
|
firstRequests := 0
|
||||||
|
secondRequests := 0
|
||||||
|
first := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
firstRequests++
|
||||||
|
_, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", firstDigest)
|
||||||
|
}))
|
||||||
|
defer first.Close()
|
||||||
|
second := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
secondRequests++
|
||||||
|
_, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", secondDigest)
|
||||||
|
}))
|
||||||
|
defer second.Close()
|
||||||
|
|
||||||
|
proxy, db, store, _ := setupTestProxy(t)
|
||||||
|
proxy.CacheMetadata = true
|
||||||
|
proxy.MetadataTTL = time.Hour
|
||||||
|
proxy.HTTPClient = first.Client()
|
||||||
|
firstHandler := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"stable": first.URL})
|
||||||
|
if response := serveHelmRequest(firstHandler, "/stable/index.yaml"); response.Code != http.StatusOK {
|
||||||
|
t.Fatalf("first index status = %d, want 200: %s", response.Code, response.Body.String())
|
||||||
|
}
|
||||||
|
|
||||||
|
// Model a restarted server with the same database and storage but a changed
|
||||||
|
// repository URL. Its cache key must not reuse the previous index or ETag.
|
||||||
|
restartedProxy := NewProxy(db, store, &mockFetcher{}, fetch.NewResolver(), nil)
|
||||||
|
restartedProxy.CacheMetadata = true
|
||||||
|
restartedProxy.MetadataTTL = time.Hour
|
||||||
|
restartedProxy.HTTPClient = second.Client()
|
||||||
|
secondHandler := NewHelmHandler(restartedProxy, "http://proxy.example", map[string]string{"stable": second.URL})
|
||||||
|
response := serveHelmRequest(secondHandler, "/stable/index.yaml")
|
||||||
|
if response.Code != http.StatusOK {
|
||||||
|
t.Fatalf("second index status = %d, want 200: %s", response.Code, response.Body.String())
|
||||||
|
}
|
||||||
|
if !strings.Contains(response.Body.String(), secondDigest) {
|
||||||
|
t.Errorf("second index did not use the new upstream: %s", response.Body.String())
|
||||||
|
}
|
||||||
|
if firstRequests != 1 {
|
||||||
|
t.Errorf("first upstream requests = %d, want 1", firstRequests)
|
||||||
|
}
|
||||||
|
if secondRequests != 1 {
|
||||||
|
t.Errorf("second upstream requests = %d, want 1", secondRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestHelmHandler_UsesConfiguredUpstreamAuthentication(t *testing.T) {
|
||||||
|
chart := []byte("private Helm chart")
|
||||||
|
digest := helmSHA256Hex(chart)
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.Header.Get("Authorization") != "Bearer private-token" {
|
||||||
|
http.Error(w, "unauthorized", http.StatusUnauthorized)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
switch r.URL.Path {
|
||||||
|
case "/index.yaml":
|
||||||
|
_, _ = fmt.Fprintf(w, "apiVersion: v1\nentries:\n demo:\n - digest: %s\n urls: [demo.tgz]\n", digest)
|
||||||
|
case "/demo.tgz":
|
||||||
|
_, _ = w.Write(chart)
|
||||||
|
default:
|
||||||
|
http.NotFound(w, r)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, _ := setupTestProxy(t)
|
||||||
|
proxy.CacheMetadata = true
|
||||||
|
proxy.MetadataTTL = time.Hour
|
||||||
|
authClient := &http.Client{Transport: upstreamhttp.NewTransport(http.DefaultTransport,
|
||||||
|
upstreamhttp.AuthFunc(func(string) (string, string) {
|
||||||
|
return "Authorization", "Bearer private-token"
|
||||||
|
}))}
|
||||||
|
proxy.HTTPClient = authClient
|
||||||
|
fetcher := fetch.NewFetcher(fetch.WithHTTPClient(authClient), fetch.WithMaxRetries(0))
|
||||||
|
proxy.Fetcher = fetcher
|
||||||
|
t.Cleanup(func() { _ = fetcher.Close() })
|
||||||
|
h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"private": upstream.URL})
|
||||||
|
|
||||||
|
response := serveHelmRequest(h, "/private/charts/"+digest+"/demo.tgz")
|
||||||
|
if response.Code != http.StatusOK {
|
||||||
|
t.Fatalf("status = %d, want 200: %s", response.Code, response.Body.String())
|
||||||
|
}
|
||||||
|
if got := response.Body.String(); got != string(chart) {
|
||||||
|
t.Errorf("body = %q, want %q", got, chart)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestHelmHandler_FiltersNewChartsFromIndex(t *testing.T) {
|
||||||
|
oldDigest := strings.Repeat("a", 64)
|
||||||
|
newDigest := strings.Repeat("b", 64)
|
||||||
|
proxy := &Proxy{Cooldown: &cooldown.Config{Default: "3d"}}
|
||||||
|
h := NewHelmHandler(proxy, "http://proxy.example", map[string]string{"test": "https://charts.example"})
|
||||||
|
|
||||||
|
body := fmt.Sprintf(`apiVersion: v1
|
||||||
|
entries:
|
||||||
|
demo:
|
||||||
|
- created: %s
|
||||||
|
digest: %s
|
||||||
|
urls: [demo-old.tgz]
|
||||||
|
- created: %s
|
||||||
|
digest: %s
|
||||||
|
urls: [demo-new.tgz]
|
||||||
|
`, time.Now().Add(-10*24*time.Hour).Format(time.RFC3339), oldDigest,
|
||||||
|
time.Now().Add(-time.Hour).Format(time.RFC3339), newDigest)
|
||||||
|
|
||||||
|
rewritten, err := h.rewriteIndex("test", "https://charts.example", []byte(body))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("rewriteIndex() error = %v", err)
|
||||||
|
}
|
||||||
|
if strings.Contains(string(rewritten), newDigest) {
|
||||||
|
t.Errorf("rewritten index includes a chart still in cooldown: %s", rewritten)
|
||||||
|
}
|
||||||
|
if !strings.Contains(string(rewritten), oldDigest) {
|
||||||
|
t.Errorf("rewritten index omitted an old chart: %s", rewritten)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNormalizeHelmDigest(t *testing.T) {
|
||||||
|
digest := strings.Repeat("a", 64)
|
||||||
|
for _, input := range []string{digest, "sha256:" + digest, "SHA256:" + strings.ToUpper(digest)} {
|
||||||
|
if got, ok := normalizeHelmDigest(input); !ok || got != digest {
|
||||||
|
t.Errorf("normalizeHelmDigest(%q) = %q, %t; want %q, true", input, got, ok, digest)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if _, ok := normalizeHelmDigest("bad"); ok {
|
||||||
|
t.Error("normalizeHelmDigest accepted an invalid digest")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestHelmIndexEntriesRejectsIncompleteMapping(t *testing.T) {
|
||||||
|
entries := &yaml.Node{
|
||||||
|
Kind: yaml.MappingNode,
|
||||||
|
Content: []*yaml.Node{
|
||||||
|
{Kind: yaml.ScalarNode, Value: "demo"},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
document := &yaml.Node{
|
||||||
|
Kind: yaml.DocumentNode,
|
||||||
|
Content: []*yaml.Node{{
|
||||||
|
Kind: yaml.MappingNode,
|
||||||
|
Content: []*yaml.Node{
|
||||||
|
{Kind: yaml.ScalarNode, Value: "entries"},
|
||||||
|
entries,
|
||||||
|
},
|
||||||
|
}},
|
||||||
|
}
|
||||||
|
|
||||||
|
if _, err := helmIndexEntries(document); err == nil {
|
||||||
|
t.Fatal("helmIndexEntries() error = nil, want incomplete mapping error")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func serveHelmRequest(h *HelmHandler, target string) *httptest.ResponseRecorder {
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.Routes().ServeHTTP(w, httptest.NewRequest(http.MethodGet, target, nil))
|
||||||
|
return w
|
||||||
|
}
|
||||||
|
|
||||||
|
func helmSHA256Hex(data []byte) string {
|
||||||
|
digest := sha256.Sum256(data)
|
||||||
|
return hex.EncodeToString(digest[:])
|
||||||
|
}
|
||||||
|
|
@ -1,140 +1,100 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"crypto/sha256"
|
|
||||||
"crypto/sha512"
|
|
||||||
"crypto/subtle"
|
|
||||||
"encoding/base64"
|
|
||||||
"encoding/hex"
|
|
||||||
"fmt"
|
"fmt"
|
||||||
"hash"
|
|
||||||
"io"
|
"io"
|
||||||
"strings"
|
|
||||||
|
"github.com/git-pkgs/integrity"
|
||||||
)
|
)
|
||||||
|
|
||||||
// parseSRI parses a Subresource Integrity string (e.g. "sha512-abc==") into
|
type integrityChecks struct {
|
||||||
// an algorithm name and raw digest bytes. Returns ok=false for empty,
|
contentHash integrity.SRI
|
||||||
// malformed, or unsupported entries. Only the first hash in a multi-hash
|
native integrity.SRI
|
||||||
// SRI string is considered.
|
algorithms []integrity.Algorithm
|
||||||
func parseSRI(s string) (algo string, digest []byte, ok bool) {
|
|
||||||
s = strings.TrimSpace(s)
|
|
||||||
if s == "" {
|
|
||||||
return "", nil, false
|
|
||||||
}
|
}
|
||||||
if i := strings.IndexByte(s, ' '); i >= 0 {
|
|
||||||
s = s[:i]
|
func newIntegrityChecks(contentHash, native string) (integrityChecks, error) {
|
||||||
}
|
checks := integrityChecks{}
|
||||||
algo, b64, found := strings.Cut(s, "-")
|
|
||||||
if !found {
|
if contentHash != "" {
|
||||||
return "", nil, false
|
digest, err := integrity.ParseHex(integrity.SHA256, contentHash)
|
||||||
}
|
|
||||||
d, err := base64.StdEncoding.DecodeString(b64)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", nil, false
|
return integrityChecks{}, fmt.Errorf("parse content_hash: %w", err)
|
||||||
}
|
}
|
||||||
switch algo {
|
checks.contentHash = integrity.SRI{digest}
|
||||||
case "sha256", "sha384", "sha512":
|
checks.algorithms = append(checks.algorithms, integrity.SHA256)
|
||||||
return algo, d, true
|
}
|
||||||
default:
|
|
||||||
return "", nil, false
|
if native != "" {
|
||||||
|
digests, err := integrity.ParseSRI(native)
|
||||||
|
if err != nil {
|
||||||
|
return integrityChecks{}, fmt.Errorf("parse integrity: %w", err)
|
||||||
|
}
|
||||||
|
checks.native = digests
|
||||||
|
for _, digest := range digests {
|
||||||
|
checks.algorithms = append(checks.algorithms, digest.Algorithm())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func newSRIHash(algo string) hash.Hash {
|
return checks, nil
|
||||||
switch algo {
|
|
||||||
case "sha256":
|
|
||||||
return sha256.New()
|
|
||||||
case "sha384":
|
|
||||||
return sha512.New384()
|
|
||||||
case "sha512":
|
|
||||||
return sha512.New()
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// verifyingReader wraps an io.ReadCloser and computes SHA256 (and optionally
|
func (c integrityChecks) wrap(source io.ReadCloser, onMismatch func(string)) (io.ReadCloser, error) {
|
||||||
// a second SRI hash) as bytes are read. When the underlying reader reaches
|
if len(c.algorithms) == 0 {
|
||||||
// EOF it compares the digests against the expected values and calls
|
return source, nil
|
||||||
// onMismatch for each failure. Verification is skipped if the stream was
|
}
|
||||||
// not fully consumed (e.g. client disconnect) to avoid false positives.
|
reader, err := integrity.NewReader(source, c.algorithms...)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("create integrity reader: %w", err)
|
||||||
|
}
|
||||||
|
return &verifyingReader{
|
||||||
|
source: source,
|
||||||
|
reader: reader,
|
||||||
|
checks: c,
|
||||||
|
onMismatch: onMismatch,
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// verifyingReader forwards Close to its source and reports completed digest
|
||||||
|
// mismatches after its shared integrity reader observes EOF.
|
||||||
type verifyingReader struct {
|
type verifyingReader struct {
|
||||||
r io.ReadCloser
|
source io.ReadCloser
|
||||||
sha256 hash.Hash
|
reader *integrity.Reader
|
||||||
wantSHA256 string
|
checks integrityChecks
|
||||||
sri hash.Hash
|
|
||||||
sriAlgo string
|
|
||||||
wantSRI []byte
|
|
||||||
onMismatch func(reason string)
|
onMismatch func(reason string)
|
||||||
eof bool
|
|
||||||
verified bool
|
verified bool
|
||||||
}
|
}
|
||||||
|
|
||||||
func newVerifyingReader(r io.ReadCloser, contentHash, sri string, onMismatch func(string)) io.ReadCloser {
|
func (r *verifyingReader) Read(p []byte) (int, error) {
|
||||||
if contentHash == "" && sri == "" {
|
n, err := r.reader.Read(p)
|
||||||
return r
|
|
||||||
}
|
|
||||||
v := &verifyingReader{
|
|
||||||
r: r,
|
|
||||||
onMismatch: onMismatch,
|
|
||||||
}
|
|
||||||
if contentHash != "" {
|
|
||||||
v.sha256 = sha256.New()
|
|
||||||
v.wantSHA256 = contentHash
|
|
||||||
}
|
|
||||||
if algo, digest, ok := parseSRI(sri); ok {
|
|
||||||
v.sri = newSRIHash(algo)
|
|
||||||
v.sriAlgo = algo
|
|
||||||
v.wantSRI = digest
|
|
||||||
}
|
|
||||||
if v.sha256 == nil && v.sri == nil {
|
|
||||||
return r
|
|
||||||
}
|
|
||||||
return v
|
|
||||||
}
|
|
||||||
|
|
||||||
func (v *verifyingReader) Read(p []byte) (int, error) {
|
|
||||||
n, err := v.r.Read(p)
|
|
||||||
if n > 0 {
|
|
||||||
if v.sha256 != nil {
|
|
||||||
v.sha256.Write(p[:n])
|
|
||||||
}
|
|
||||||
if v.sri != nil {
|
|
||||||
v.sri.Write(p[:n])
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if err == io.EOF {
|
if err == io.EOF {
|
||||||
v.eof = true
|
r.verify()
|
||||||
v.verify()
|
|
||||||
}
|
}
|
||||||
return n, err
|
return n, err
|
||||||
}
|
}
|
||||||
|
|
||||||
func (v *verifyingReader) Close() error {
|
func (r *verifyingReader) Close() error {
|
||||||
if v.eof {
|
return r.source.Close()
|
||||||
v.verify()
|
|
||||||
}
|
|
||||||
return v.r.Close()
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (v *verifyingReader) verify() {
|
func (r *verifyingReader) verify() {
|
||||||
if v.verified {
|
if r.verified {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
r.verified = true
|
||||||
|
result := r.reader.Result()
|
||||||
|
if !result.Complete {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
v.verified = true
|
|
||||||
|
|
||||||
if v.sha256 != nil {
|
if len(r.checks.contentHash) > 0 {
|
||||||
got := hex.EncodeToString(v.sha256.Sum(nil))
|
if err := result.Verify(r.checks.contentHash); err != nil {
|
||||||
if subtle.ConstantTimeCompare([]byte(got), []byte(v.wantSHA256)) != 1 {
|
r.onMismatch("content_hash: " + err.Error())
|
||||||
v.onMismatch(fmt.Sprintf("content_hash mismatch: stored=%s computed=%s", v.wantSHA256, got))
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if v.sri != nil {
|
if len(r.checks.native) > 0 {
|
||||||
got := v.sri.Sum(nil)
|
if err := result.Verify(r.checks.native); err != nil {
|
||||||
if subtle.ConstantTimeCompare(got, v.wantSRI) != 1 {
|
r.onMismatch("integrity: " + err.Error())
|
||||||
v.onMismatch(fmt.Sprintf("integrity mismatch: %s expected=%s computed=%s",
|
|
||||||
v.sriAlgo,
|
|
||||||
base64.StdEncoding.EncodeToString(v.wantSRI),
|
|
||||||
base64.StdEncoding.EncodeToString(got)))
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -5,6 +5,7 @@ import (
|
||||||
"crypto/sha512"
|
"crypto/sha512"
|
||||||
"encoding/base64"
|
"encoding/base64"
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
|
"errors"
|
||||||
"io"
|
"io"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
@ -15,42 +16,68 @@ func sha256Hex(data string) string {
|
||||||
return hex.EncodeToString(sum[:])
|
return hex.EncodeToString(sum[:])
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func sha256SRI(data string) string {
|
||||||
|
sum := sha256.Sum256([]byte(data))
|
||||||
|
return "sha256-" + base64.StdEncoding.EncodeToString(sum[:])
|
||||||
|
}
|
||||||
|
|
||||||
|
func sha384SRI(data string) string {
|
||||||
|
sum := sha512.Sum384([]byte(data))
|
||||||
|
return "sha384-" + base64.StdEncoding.EncodeToString(sum[:])
|
||||||
|
}
|
||||||
|
|
||||||
func sha512SRI(data string) string {
|
func sha512SRI(data string) string {
|
||||||
sum := sha512.Sum512([]byte(data))
|
sum := sha512.Sum512([]byte(data))
|
||||||
return "sha512-" + base64.StdEncoding.EncodeToString(sum[:])
|
return "sha512-" + base64.StdEncoding.EncodeToString(sum[:])
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestParseSRI(t *testing.T) {
|
func wrapIntegrityReader(t *testing.T, source io.ReadCloser, contentHash, native string, onMismatch func(string)) io.ReadCloser {
|
||||||
tests := []struct {
|
t.Helper()
|
||||||
name string
|
checks, err := newIntegrityChecks(contentHash, native)
|
||||||
input string
|
if err != nil {
|
||||||
algo string
|
t.Fatalf("newIntegrityChecks: %v", err)
|
||||||
ok bool
|
}
|
||||||
}{
|
reader, err := checks.wrap(source, onMismatch)
|
||||||
{"sha512", sha512SRI("hello"), "sha512", true},
|
if err != nil {
|
||||||
{"sha256", "sha256-" + base64.StdEncoding.EncodeToString([]byte("0123456789012345678901234567890123456789")), "sha256", true},
|
t.Fatalf("wrap: %v", err)
|
||||||
{"empty", "", "", false},
|
}
|
||||||
{"no dash", "sha512abc", "", false},
|
return reader
|
||||||
{"bad base64", "sha512-not!base64", "", false},
|
|
||||||
{"unsupported algo", "md5-" + base64.StdEncoding.EncodeToString([]byte("x")), "", false},
|
|
||||||
{"multi hash takes first", sha512SRI("a") + " " + sha512SRI("b"), "sha512", true},
|
|
||||||
{"whitespace", " " + sha512SRI("x") + " ", "sha512", true},
|
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range tests {
|
func TestNewIntegrityChecksCollectsAlgorithms(t *testing.T) {
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
checks, err := newIntegrityChecks(
|
||||||
algo, digest, ok := parseSRI(tt.input)
|
sha256Hex("hello"),
|
||||||
if ok != tt.ok {
|
strings.Join([]string{sha256SRI("first"), sha512SRI("second"), sha384SRI("third"), sha512SRI("alternative")}, " "),
|
||||||
t.Fatalf("ok = %v, want %v", ok, tt.ok)
|
)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
if !tt.ok {
|
if len(checks.algorithms) != 5 {
|
||||||
return
|
t.Fatalf("algorithms = %v, want 5 entries", checks.algorithms)
|
||||||
}
|
}
|
||||||
if algo != tt.algo {
|
if len(checks.native) != 4 {
|
||||||
t.Errorf("algo = %q, want %q", algo, tt.algo)
|
t.Errorf("native digests = %d, want 4", len(checks.native))
|
||||||
}
|
}
|
||||||
if len(digest) == 0 {
|
}
|
||||||
t.Error("digest is empty")
|
|
||||||
|
func TestNewIntegrityChecksRejectsMalformedMetadata(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
contentHash string
|
||||||
|
native string
|
||||||
|
}{
|
||||||
|
{name: "short content hash", contentHash: "abc123"},
|
||||||
|
{name: "non-hex content hash", contentHash: strings.Repeat("z", sha256.Size*2)},
|
||||||
|
{name: "missing SRI separator", native: "sha512"},
|
||||||
|
{name: "malformed SRI base64", native: "sha512-not!base64"},
|
||||||
|
{name: "wrong SRI length", native: "sha512-" + base64.StdEncoding.EncodeToString([]byte("short"))},
|
||||||
|
{name: "unsupported SRI algorithm", native: "md5-1B2M2Y8AsgTpgAmY7PhCfg=="},
|
||||||
|
{name: "invalid SRI alternative", native: sha512SRI("valid") + " sha384-nope"},
|
||||||
|
}
|
||||||
|
for _, test := range tests {
|
||||||
|
t.Run(test.name, func(t *testing.T) {
|
||||||
|
if _, err := newIntegrityChecks(test.contentHash, test.native); err == nil {
|
||||||
|
t.Fatal("newIntegrityChecks returned nil error")
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
@ -67,69 +94,156 @@ func TestVerifyingReader(t *testing.T) {
|
||||||
sri string
|
sri string
|
||||||
wantCalls int
|
wantCalls int
|
||||||
}{
|
}{
|
||||||
{"both match", goodSHA, goodSRI, 0},
|
{name: "both match", hash: goodSHA, sri: goodSRI},
|
||||||
{"sha256 only match", goodSHA, "", 0},
|
{name: "SHA-256 only match", hash: goodSHA},
|
||||||
{"sri only match", "", goodSRI, 0},
|
{name: "SRI only match", sri: goodSRI},
|
||||||
{"sha256 mismatch", sha256Hex("other"), "", 1},
|
{name: "SHA-256 mismatch", hash: sha256Hex("other"), wantCalls: 1},
|
||||||
{"sri mismatch", "", sha512SRI("other"), 1},
|
{name: "SRI mismatch", sri: sha512SRI("other"), wantCalls: 1},
|
||||||
{"both mismatch", sha256Hex("other"), sha512SRI("other"), 2},
|
{name: "both mismatch", hash: sha256Hex("other"), sri: sha512SRI("other"), wantCalls: 2},
|
||||||
{"no checks", "", "", 0},
|
{name: "no checks"},
|
||||||
{"unparseable sri ignored", goodSHA, "garbage", 0},
|
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range tests {
|
for _, test := range tests {
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
t.Run(test.name, func(t *testing.T) {
|
||||||
var calls []string
|
var calls []string
|
||||||
r := newVerifyingReader(io.NopCloser(strings.NewReader(data)), tt.hash, tt.sri,
|
reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), test.hash, test.sri,
|
||||||
func(reason string) { calls = append(calls, reason) })
|
func(reason string) { calls = append(calls, reason) })
|
||||||
|
|
||||||
got, err := io.ReadAll(r)
|
got, err := io.ReadAll(reader)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatalf("ReadAll: %v", err)
|
t.Fatalf("ReadAll: %v", err)
|
||||||
}
|
}
|
||||||
if string(got) != data {
|
if string(got) != data {
|
||||||
t.Errorf("data corrupted: got %q", got)
|
t.Errorf("data corrupted: got %q", got)
|
||||||
}
|
}
|
||||||
if err := r.Close(); err != nil {
|
if err := reader.Close(); err != nil {
|
||||||
t.Fatalf("Close: %v", err)
|
t.Fatalf("Close: %v", err)
|
||||||
}
|
}
|
||||||
|
if len(calls) != test.wantCalls {
|
||||||
if len(calls) != tt.wantCalls {
|
t.Errorf("onMismatch called %d times, want %d: %v", len(calls), test.wantCalls, calls)
|
||||||
t.Errorf("onMismatch called %d times, want %d: %v", len(calls), tt.wantCalls, calls)
|
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestVerifyingReaderPassthrough(t *testing.T) {
|
func TestVerifyingReaderUsesStrongestNativeAlgorithm(t *testing.T) {
|
||||||
src := io.NopCloser(strings.NewReader("x"))
|
const data = "artifact"
|
||||||
r := newVerifyingReader(src, "", "", func(string) { t.Fatal("should not be called") })
|
tests := []struct {
|
||||||
if r != src {
|
name string
|
||||||
t.Error("expected passthrough when no hashes provided")
|
native string
|
||||||
|
wantCalls int
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "weaker match does not override stronger mismatch",
|
||||||
|
native: sha256SRI(data) + " " + sha512SRI("other"),
|
||||||
|
wantCalls: 1,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "stronger match ignores weaker mismatch",
|
||||||
|
native: sha256SRI("other") + " " + sha512SRI(data),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "same algorithm alternative matches",
|
||||||
|
native: sha512SRI("other") + " " + sha512SRI(data),
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
for _, test := range tests {
|
||||||
|
t.Run(test.name, func(t *testing.T) {
|
||||||
|
var calls int
|
||||||
|
reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), "", test.native, func(string) { calls++ })
|
||||||
|
if _, err := io.Copy(io.Discard, reader); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if calls != test.wantCalls {
|
||||||
|
t.Errorf("onMismatch called %d times, want %d", calls, test.wantCalls)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestVerifyingReaderMismatchMessages(t *testing.T) {
|
||||||
|
const data = "actual"
|
||||||
|
wantHash := sha256Hex("expected")
|
||||||
|
wantSRI := sha512SRI("expected")
|
||||||
|
var reasons []string
|
||||||
|
reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader(data)), wantHash, wantSRI,
|
||||||
|
func(reason string) { reasons = append(reasons, reason) })
|
||||||
|
if _, err := io.Copy(io.Discard, reader); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if len(reasons) != 2 {
|
||||||
|
t.Fatalf("reasons = %v, want two", reasons)
|
||||||
|
}
|
||||||
|
wantContentReason := "content_hash: integrity mismatch: expected " + sha256SRI("expected") + ", calculated " + sha256SRI(data)
|
||||||
|
if reasons[0] != wantContentReason {
|
||||||
|
t.Errorf("content reason = %q, want %q", reasons[0], wantContentReason)
|
||||||
|
}
|
||||||
|
wantNativeReason := "integrity: integrity mismatch: expected " + wantSRI + ", calculated " + sha512SRI(data)
|
||||||
|
if reasons[1] != wantNativeReason {
|
||||||
|
t.Errorf("native reason = %q, want %q", reasons[1], wantNativeReason)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestVerifyingReaderPassthrough(t *testing.T) {
|
||||||
|
source := io.NopCloser(strings.NewReader("x"))
|
||||||
|
reader := wrapIntegrityReader(t, source, "", "", func(string) { t.Fatal("should not be called") })
|
||||||
|
if reader != source {
|
||||||
|
t.Error("expected passthrough when no hashes were provided")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
type closeTrackingReader struct {
|
||||||
|
io.Reader
|
||||||
|
closed bool
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *closeTrackingReader) Close() error {
|
||||||
|
r.closed = true
|
||||||
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestVerifyingReaderPartialRead(t *testing.T) {
|
func TestVerifyingReaderPartialRead(t *testing.T) {
|
||||||
|
source := &closeTrackingReader{Reader: strings.NewReader("hello world")}
|
||||||
var calls int
|
var calls int
|
||||||
r := newVerifyingReader(io.NopCloser(strings.NewReader("hello world")),
|
reader := wrapIntegrityReader(t, source, sha256Hex("other"), "", func(string) { calls++ })
|
||||||
sha256Hex("hello world"), "", func(string) { calls++ })
|
|
||||||
|
|
||||||
buf := make([]byte, 5)
|
buffer := make([]byte, 5)
|
||||||
_, _ = r.Read(buf)
|
_, _ = reader.Read(buffer)
|
||||||
_ = r.Close()
|
_ = reader.Close()
|
||||||
|
|
||||||
if calls != 0 {
|
if calls != 0 {
|
||||||
t.Errorf("onMismatch called %d times for partial read, want 0", calls)
|
t.Errorf("onMismatch called %d times for partial read, want 0", calls)
|
||||||
}
|
}
|
||||||
|
if !source.closed {
|
||||||
|
t.Error("Close was not forwarded to the source")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestVerifyingReaderNonEOFError(t *testing.T) {
|
||||||
|
var calls int
|
||||||
|
reader := wrapIntegrityReader(t, io.NopCloser(errorFixtureReader{}), sha256Hex("data"), "", func(string) { calls++ })
|
||||||
|
if _, err := io.ReadAll(reader); !errors.Is(err, errIntegrityReadFixture) {
|
||||||
|
t.Fatalf("ReadAll error = %v", err)
|
||||||
|
}
|
||||||
|
if calls != 0 {
|
||||||
|
t.Errorf("onMismatch called %d times after non-EOF error", calls)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
var errIntegrityReadFixture = errors.New("integrity read fixture")
|
||||||
|
|
||||||
|
type errorFixtureReader struct{}
|
||||||
|
|
||||||
|
func (errorFixtureReader) Read(p []byte) (int, error) {
|
||||||
|
return copy(p, "data"), errIntegrityReadFixture
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestVerifyingReaderVerifyOnce(t *testing.T) {
|
func TestVerifyingReaderVerifyOnce(t *testing.T) {
|
||||||
var calls int
|
var calls int
|
||||||
r := newVerifyingReader(io.NopCloser(strings.NewReader("x")), sha256Hex("y"), "",
|
reader := wrapIntegrityReader(t, io.NopCloser(strings.NewReader("x")), sha256Hex("y"), "", func(string) { calls++ })
|
||||||
func(string) { calls++ })
|
_, _ = io.ReadAll(reader)
|
||||||
_, _ = io.ReadAll(r)
|
_ = reader.Close()
|
||||||
_ = r.Close()
|
_ = reader.Close()
|
||||||
_ = r.Close()
|
|
||||||
if calls != 1 {
|
if calls != 1 {
|
||||||
t.Errorf("onMismatch called %d times, want 1", calls)
|
t.Errorf("onMismatch called %d times, want 1", calls)
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,7 +1,6 @@
|
||||||
package handler
|
package handler
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
@ -117,23 +116,12 @@ func TestComposerDownloadUpstreamNotFoundReturns404(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestContainerBlobUpstreamNotFoundReturns404(t *testing.T) {
|
func TestContainerBlobUpstreamNotFoundReturns404(t *testing.T) {
|
||||||
authServer := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
proxy, _, _, fetcher := setupTestProxy(t)
|
||||||
w.Header().Set("Content-Type", "application/json")
|
fetcher.fetchErr = fetch.ErrNotFound
|
||||||
_, _ = w.Write([]byte(`{"token": "test-token-123"}`))
|
|
||||||
}))
|
|
||||||
defer authServer.Close()
|
|
||||||
|
|
||||||
proxy, _, _, _ := setupTestProxy(t)
|
|
||||||
proxy.Fetcher = &mockFetcherWithHeaders{
|
|
||||||
fetchFn: func(_ context.Context, _ string, _ http.Header) (*fetch.Artifact, error) {
|
|
||||||
return nil, fetch.ErrNotFound
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
h := &ContainerHandler{
|
h := &ContainerHandler{
|
||||||
proxy: proxy,
|
proxy: proxy,
|
||||||
registryURL: "https://registry-1.docker.io",
|
registryURL: "https://registry-1.docker.io",
|
||||||
authURL: authServer.URL,
|
|
||||||
proxyURL: "http://localhost:8080",
|
proxyURL: "http://localhost:8080",
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -13,7 +13,7 @@ import (
|
||||||
|
|
||||||
const (
|
const (
|
||||||
npmUpstream = "https://registry.npmjs.org"
|
npmUpstream = "https://registry.npmjs.org"
|
||||||
npmAbbreviatedCT = "application/vnd.npm.install-v1+json"
|
npmAcceptDefault = "application/vnd.npm.install-v1+json;q=1.0, application/json;q=0.8"
|
||||||
scopedParts = 2 // scope + name in scoped packages
|
scopedParts = 2 // scope + name in scoped packages
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -71,9 +71,12 @@ func (h *NPMHandler) handlePackageMetadata(w http.ResponseWriter, r *http.Reques
|
||||||
|
|
||||||
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName))
|
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName))
|
||||||
|
|
||||||
// Use abbreviated metadata when cooldown is disabled — it's much smaller
|
// Prefer the smaller abbreviated packument format but include application/json
|
||||||
// (e.g. drizzle-orm: 4MB vs 92MB) but lacks the time map needed for cooldown.
|
// as a fallback so upstreams that reject the abbreviated type (e.g. JFrog
|
||||||
accept := npmAbbreviatedCT
|
// Artifactory, which returns 406) can still respond with full metadata.
|
||||||
|
// When cooldown is enabled we must use full metadata exclusively because the
|
||||||
|
// abbreviated format omits the "time" map required for version age filtering.
|
||||||
|
accept := npmAcceptDefault
|
||||||
if h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() {
|
if h.proxy.Cooldown != nil && h.proxy.Cooldown.Enabled() {
|
||||||
accept = contentTypeJSON
|
accept = contentTypeJSON
|
||||||
}
|
}
|
||||||
|
|
@ -265,6 +268,13 @@ func (h *NPMHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
h.proxy.Logger.Info("npm download request",
|
h.proxy.Logger.Info("npm download request",
|
||||||
"package", packageName, "version", version, "filename", filename)
|
"package", packageName, "version", version, "filename", filename)
|
||||||
|
|
||||||
|
if h.versionInCooldown(r, packageName, version) {
|
||||||
|
h.proxy.Logger.Info("cooldown: withholding npm tarball",
|
||||||
|
"package", packageName, "version", version)
|
||||||
|
JSONError(w, http.StatusNotFound, "version not found")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
downloadURL := fmt.Sprintf(
|
downloadURL := fmt.Sprintf(
|
||||||
"%s/%s/-/%s",
|
"%s/%s/-/%s",
|
||||||
h.upstreamURL,
|
h.upstreamURL,
|
||||||
|
|
@ -287,6 +297,50 @@ func (h *NPMHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
ServeArtifact(w, result)
|
ServeArtifact(w, result)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// versionInCooldown reports whether a version is still inside the cooldown
|
||||||
|
// window. Filtering the packument is not enough on its own: tarball URLs are
|
||||||
|
// predictable and lockfiles record them directly, so `npm ci` reaches the
|
||||||
|
// download path without ever requesting metadata.
|
||||||
|
//
|
||||||
|
// The packument is served from the metadata cache, so this normally costs no
|
||||||
|
// extra upstream request. A version with no usable publish time is allowed
|
||||||
|
// through, matching how applyCooldownFiltering treats it.
|
||||||
|
func (h *NPMHandler) versionInCooldown(r *http.Request, packageName, version string) bool {
|
||||||
|
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
upstreamURL := fmt.Sprintf("%s/%s", h.upstreamURL, url.PathEscape(packageName))
|
||||||
|
|
||||||
|
body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "npm", packageName, upstreamURL, contentTypeJSON)
|
||||||
|
if err != nil {
|
||||||
|
h.proxy.Logger.Warn("cooldown: could not fetch npm metadata for download check",
|
||||||
|
"package", packageName, "version", version, "error", err)
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
var metadata struct {
|
||||||
|
Time map[string]string `json:"time"`
|
||||||
|
}
|
||||||
|
if err := json.Unmarshal(body, &metadata); err != nil {
|
||||||
|
h.proxy.Logger.Warn("cooldown: could not parse npm metadata for download check",
|
||||||
|
"package", packageName, "version", version, "error", err)
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
published, ok := metadata.Time[version]
|
||||||
|
if !ok {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
publishedAt, err := time.Parse(time.RFC3339, published)
|
||||||
|
if err != nil {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
return !h.proxy.Cooldown.IsAllowed("npm", canonicalPackagePURL("npm", packageName), publishedAt)
|
||||||
|
}
|
||||||
|
|
||||||
func escapeNPMDownloadPackage(packageName string) string {
|
func escapeNPMDownloadPackage(packageName string) string {
|
||||||
scope, name, scoped := strings.Cut(packageName, "/")
|
scope, name, scoped := strings.Cut(packageName, "/")
|
||||||
if scoped && strings.HasPrefix(scope, "@") && len(scope) > 1 && name != "" && !strings.Contains(name, "/") {
|
if scoped && strings.HasPrefix(scope, "@") && len(scope) > 1 && name != "" && !strings.Contains(name, "/") {
|
||||||
|
|
|
||||||
|
|
@ -396,7 +396,7 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) {
|
||||||
}))
|
}))
|
||||||
defer upstream.Close()
|
defer upstream.Close()
|
||||||
|
|
||||||
t.Run("no cooldown uses abbreviated metadata", func(t *testing.T) {
|
t.Run("no cooldown uses combined accept header", func(t *testing.T) {
|
||||||
h := &NPMHandler{
|
h := &NPMHandler{
|
||||||
proxy: testProxy(),
|
proxy: testProxy(),
|
||||||
upstreamURL: upstream.URL,
|
upstreamURL: upstream.URL,
|
||||||
|
|
@ -407,12 +407,12 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) {
|
||||||
w := httptest.NewRecorder()
|
w := httptest.NewRecorder()
|
||||||
h.handlePackageMetadata(w, req)
|
h.handlePackageMetadata(w, req)
|
||||||
|
|
||||||
if gotAccept != npmAbbreviatedCT {
|
if gotAccept != npmAcceptDefault {
|
||||||
t.Errorf("Accept = %q, want abbreviated metadata header", gotAccept)
|
t.Errorf("Accept = %q, want %q", gotAccept, npmAcceptDefault)
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
|
|
||||||
t.Run("cooldown enabled uses full metadata", func(t *testing.T) {
|
t.Run("cooldown enabled uses full metadata only", func(t *testing.T) {
|
||||||
proxy := testProxy()
|
proxy := testProxy()
|
||||||
proxy.Cooldown = &cooldown.Config{Default: "3d"}
|
proxy.Cooldown = &cooldown.Config{Default: "3d"}
|
||||||
|
|
||||||
|
|
@ -426,8 +426,8 @@ func TestNPMHandlerUsesAbbreviatedMetadata(t *testing.T) {
|
||||||
w := httptest.NewRecorder()
|
w := httptest.NewRecorder()
|
||||||
h.handlePackageMetadata(w, req)
|
h.handlePackageMetadata(w, req)
|
||||||
|
|
||||||
if gotAccept == npmAbbreviatedCT {
|
if gotAccept != contentTypeJSON {
|
||||||
t.Error("cooldown enabled should use full metadata, not abbreviated")
|
t.Errorf("Accept = %q, want %q (cooldown requires full metadata)", gotAccept, contentTypeJSON)
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
@ -454,3 +454,81 @@ func TestNPMHandlerMetadataNotFound(t *testing.T) {
|
||||||
t.Errorf("status = %d, want %d", w.Code, http.StatusNotFound)
|
t.Errorf("status = %d, want %d", w.Code, http.StatusNotFound)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestNPMDownloadCooldown(t *testing.T) {
|
||||||
|
now := time.Now()
|
||||||
|
packument := `{
|
||||||
|
"name": "leftpad",
|
||||||
|
"dist-tags": {"latest": "2.0.0"},
|
||||||
|
"time": {
|
||||||
|
"1.0.0": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `",
|
||||||
|
"2.0.0": "` + now.Add(-1*time.Hour).Format(time.RFC3339) + `"
|
||||||
|
},
|
||||||
|
"versions": {"1.0.0": {}, "2.0.0": {}}
|
||||||
|
}`
|
||||||
|
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
w.Header().Set("Content-Type", contentTypeJSON)
|
||||||
|
_, _ = io.WriteString(w, packument)
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
version string
|
||||||
|
wantStatus int
|
||||||
|
}{
|
||||||
|
{"published before the window serves the tarball", testVersion100, http.StatusOK},
|
||||||
|
{"published inside the window is withheld", "2.0.0", http.StatusNotFound},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
proxy, _, _, fetcher := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
proxy.Cooldown = &cooldown.Config{Default: "7d"}
|
||||||
|
fetcher.artifact = &fetch.Artifact{
|
||||||
|
Body: io.NopCloser(strings.NewReader("tarball data")),
|
||||||
|
ContentType: "application/octet-stream",
|
||||||
|
}
|
||||||
|
|
||||||
|
h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL)
|
||||||
|
srv := httptest.NewServer(h.Routes())
|
||||||
|
defer srv.Close()
|
||||||
|
|
||||||
|
resp, err := http.Get(srv.URL + "/leftpad/-/leftpad-" + tt.version + ".tgz")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("request failed: %v", err)
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
if resp.StatusCode != tt.wantStatus {
|
||||||
|
t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus)
|
||||||
|
}
|
||||||
|
if tt.wantStatus == http.StatusNotFound && fetcher.fetchCalled {
|
||||||
|
t.Error("fetched a version that is still inside the cooldown window")
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNPMDownloadCooldownDisabled(t *testing.T) {
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
t.Error("metadata must not be fetched when cooldown is disabled")
|
||||||
|
w.WriteHeader(http.StatusInternalServerError)
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, fetcher := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
fetcher.artifact = &fetch.Artifact{
|
||||||
|
Body: io.NopCloser(strings.NewReader("tarball data")),
|
||||||
|
ContentType: "application/octet-stream",
|
||||||
|
}
|
||||||
|
|
||||||
|
h := NewNPMHandler(proxy, "http://proxy.test", upstream.URL)
|
||||||
|
|
||||||
|
if h.versionInCooldown(httptest.NewRequest(http.MethodGet, "/", nil), "leftpad", testVersion100) {
|
||||||
|
t.Error("versionInCooldown = true, want false when cooldown is not configured")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
||||||
|
|
@ -110,24 +110,14 @@ func (h *PyPIHandler) handleSimplePackage(w http.ResponseWriter, r *http.Request
|
||||||
// that should be filtered out due to cooldown.
|
// that should be filtered out due to cooldown.
|
||||||
func (h *PyPIHandler) fetchFilteredVersions(r *http.Request, name string) map[string]bool {
|
func (h *PyPIHandler) fetchFilteredVersions(r *http.Request, name string) map[string]bool {
|
||||||
jsonURL := fmt.Sprintf("%s/pypi/%s/json", h.upstreamURL, name)
|
jsonURL := fmt.Sprintf("%s/pypi/%s/json", h.upstreamURL, name)
|
||||||
req, err := http.NewRequestWithContext(r.Context(), http.MethodGet, jsonURL, nil)
|
|
||||||
if err != nil {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
req.Header.Set("Accept", "application/json")
|
|
||||||
|
|
||||||
resp, err := h.proxy.HTTPClient.Do(req)
|
body, _, err := h.proxy.FetchOrCacheMetadata(r.Context(), "pypi", name+"/json", jsonURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
defer func() { _ = resp.Body.Close() }()
|
|
||||||
|
|
||||||
if resp.StatusCode != http.StatusOK {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var metadata map[string]any
|
var metadata map[string]any
|
||||||
if err := json.NewDecoder(resp.Body).Decode(&metadata); err != nil {
|
if err := json.Unmarshal(body, &metadata); err != nil {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -311,6 +301,21 @@ func (h *PyPIHandler) shouldFilterRelease(packagePURL string, files any) bool {
|
||||||
return !publishedAt.IsZero() && !h.proxy.Cooldown.IsAllowed("pypi", packagePURL, publishedAt)
|
return !publishedAt.IsZero() && !h.proxy.Cooldown.IsAllowed("pypi", packagePURL, publishedAt)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// versionInCooldown reports whether a version is still inside the cooldown
|
||||||
|
// window. Filtering the simple index is not enough on its own: file URLs are
|
||||||
|
// recorded in lockfiles and requirements pins, so pip can reach the download
|
||||||
|
// path without ever reading the index.
|
||||||
|
//
|
||||||
|
// A release whose upload time cannot be determined is allowed through, matching
|
||||||
|
// how fetchFilteredVersions treats it.
|
||||||
|
func (h *PyPIHandler) versionInCooldown(r *http.Request, name, version string) bool {
|
||||||
|
if h.proxy.Cooldown == nil || !h.proxy.Cooldown.Enabled() {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
return h.fetchFilteredVersions(r, name)[version]
|
||||||
|
}
|
||||||
|
|
||||||
// rewriteFileEntries rewrites URLs in a list of file entries.
|
// rewriteFileEntries rewrites URLs in a list of file entries.
|
||||||
func (h *PyPIHandler) rewriteFileEntries(files any) {
|
func (h *PyPIHandler) rewriteFileEntries(files any) {
|
||||||
filesArr, ok := files.([]any)
|
filesArr, ok := files.([]any)
|
||||||
|
|
@ -417,6 +422,13 @@ func (h *PyPIHandler) handleDownload(w http.ResponseWriter, r *http.Request) {
|
||||||
filename := parts[len(parts)-1]
|
filename := parts[len(parts)-1]
|
||||||
name, version := h.parseFilename(filename)
|
name, version := h.parseFilename(filename)
|
||||||
|
|
||||||
|
if name != "" && h.versionInCooldown(r, name, version) {
|
||||||
|
h.proxy.Logger.Info("cooldown: withholding pypi file",
|
||||||
|
"name", name, "version", version, "filename", filename)
|
||||||
|
http.Error(w, "not found", http.StatusNotFound)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
if name == "" {
|
if name == "" {
|
||||||
// Can't determine name/version, use hash as identifier
|
// Can't determine name/version, use hash as identifier
|
||||||
name = fmt.Sprintf("_hash_%s", hashPath(path))
|
name = fmt.Sprintf("_hash_%s", hashPath(path))
|
||||||
|
|
|
||||||
|
|
@ -7,6 +7,7 @@ import (
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"strings"
|
"strings"
|
||||||
|
"sync/atomic"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
|
@ -236,3 +237,116 @@ func TestPyPIHandler_DownloadCacheMiss(t *testing.T) {
|
||||||
t.Error("expected fetcher to be called on cache miss")
|
t.Error("expected fetcher to be called on cache miss")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestPyPIDownloadCooldown(t *testing.T) {
|
||||||
|
now := time.Now()
|
||||||
|
releases := `{"releases": {
|
||||||
|
"1.0.0": [{"upload_time_iso_8601": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `"}],
|
||||||
|
"2.0.0": [{"upload_time_iso_8601": "` + now.Add(-1*time.Hour).Format(time.RFC3339) + `"}]
|
||||||
|
}}`
|
||||||
|
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
w.Header().Set("Content-Type", contentTypeJSON)
|
||||||
|
_, _ = io.WriteString(w, releases)
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
filename string
|
||||||
|
wantStatus int
|
||||||
|
}{
|
||||||
|
{"published before the window serves the file", "newpkg-1.0.0.tar.gz", http.StatusOK},
|
||||||
|
{"published inside the window is withheld", "newpkg-2.0.0.tar.gz", http.StatusNotFound},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
proxy, _, _, fetcher := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
proxy.Cooldown = &cooldown.Config{Default: "7d"}
|
||||||
|
fetcher.artifact = &fetch.Artifact{
|
||||||
|
Body: io.NopCloser(strings.NewReader("sdist data")),
|
||||||
|
ContentType: "application/octet-stream",
|
||||||
|
}
|
||||||
|
|
||||||
|
h := &PyPIHandler{
|
||||||
|
proxy: proxy,
|
||||||
|
upstreamURL: upstream.URL,
|
||||||
|
proxyURL: "http://localhost",
|
||||||
|
}
|
||||||
|
srv := httptest.NewServer(h.Routes())
|
||||||
|
defer srv.Close()
|
||||||
|
|
||||||
|
resp, err := http.Get(srv.URL + "/packages/packages/ab/cd/ef0123456789/" + tt.filename)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("request failed: %v", err)
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
if resp.StatusCode != tt.wantStatus {
|
||||||
|
t.Errorf("status = %d, want %d", resp.StatusCode, tt.wantStatus)
|
||||||
|
}
|
||||||
|
if tt.wantStatus == http.StatusNotFound && fetcher.fetchCalled {
|
||||||
|
t.Error("fetched a version that is still inside the cooldown window")
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPyPIDownloadCooldownMetadataCache ensures that repeated downloads that
|
||||||
|
// trigger cooldown filtering reuse the cached PyPI JSON metadata instead of
|
||||||
|
// fetching it from upstream once per download.
|
||||||
|
func TestPyPIDownloadCooldownMetadataCache(t *testing.T) {
|
||||||
|
now := time.Now()
|
||||||
|
releases := `{"releases": {
|
||||||
|
"1.0.0": [{"upload_time_iso_8601": "` + now.Add(-30*24*time.Hour).Format(time.RFC3339) + `"}],
|
||||||
|
"2.0.0": [{"upload_time_iso_8601": "` + now.Add(-1*time.Hour).Format(time.RFC3339) + `"}]
|
||||||
|
}}`
|
||||||
|
|
||||||
|
var metadataRequests atomic.Int64
|
||||||
|
upstream := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.URL.Path == "/pypi/newpkg/json" {
|
||||||
|
metadataRequests.Add(1)
|
||||||
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
_, _ = io.WriteString(w, releases)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
w.Header().Set("Content-Type", "application/octet-stream")
|
||||||
|
_, _ = io.WriteString(w, "package data")
|
||||||
|
}))
|
||||||
|
defer upstream.Close()
|
||||||
|
|
||||||
|
proxy, _, _, fetcher := setupTestProxy(t)
|
||||||
|
proxy.HTTPClient = upstream.Client()
|
||||||
|
proxy.CacheMetadata = true
|
||||||
|
proxy.MetadataTTL = time.Hour
|
||||||
|
proxy.Cooldown = &cooldown.Config{Default: "7d"}
|
||||||
|
fetcher.artifact = &fetch.Artifact{
|
||||||
|
Body: io.NopCloser(strings.NewReader("package data")),
|
||||||
|
ContentType: "application/octet-stream",
|
||||||
|
}
|
||||||
|
|
||||||
|
h := &PyPIHandler{
|
||||||
|
proxy: proxy,
|
||||||
|
upstreamURL: upstream.URL,
|
||||||
|
proxyURL: "http://localhost",
|
||||||
|
}
|
||||||
|
srv := httptest.NewServer(h.Routes())
|
||||||
|
defer srv.Close()
|
||||||
|
|
||||||
|
// Two downloads of the same package: one outside the cooldown window
|
||||||
|
// (served) and one inside (withheld). Both go through the download path
|
||||||
|
// that resolves filtered versions.
|
||||||
|
for _, filename := range []string{"newpkg-1.0.0.tar.gz", "newpkg-2.0.0.tar.gz"} {
|
||||||
|
resp, err := http.Get(srv.URL + "/packages/packages/ab/cd/ef0123456789/" + filename)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("request failed: %v", err)
|
||||||
|
}
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
}
|
||||||
|
|
||||||
|
if got := metadataRequests.Load(); got != 1 {
|
||||||
|
t.Errorf("upstream metadata JSON requests = %d, want 1 (repeated downloads should reuse the cached metadata)", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
||||||
74
internal/httpclient/access_log.go
Normal file
74
internal/httpclient/access_log.go
Normal file
|
|
@ -0,0 +1,74 @@
|
||||||
|
package httpclient
|
||||||
|
|
||||||
|
import (
|
||||||
|
"log/slog"
|
||||||
|
"net/http"
|
||||||
|
"net/url"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/git-pkgs/proxy/internal/accesslog"
|
||||||
|
)
|
||||||
|
|
||||||
|
type accessLogTransport struct {
|
||||||
|
base http.RoundTripper
|
||||||
|
accessLog *accesslog.Logger
|
||||||
|
logger *slog.Logger
|
||||||
|
}
|
||||||
|
|
||||||
|
// NewAccessLogTransport records each upstream HTTP exchange around base.
|
||||||
|
func NewAccessLogTransport(base http.RoundTripper, log *accesslog.Logger, logger *slog.Logger) http.RoundTripper {
|
||||||
|
if base == nil {
|
||||||
|
base = http.DefaultTransport
|
||||||
|
}
|
||||||
|
if logger == nil {
|
||||||
|
logger = slog.Default()
|
||||||
|
}
|
||||||
|
if log == nil {
|
||||||
|
return base
|
||||||
|
}
|
||||||
|
return &accessLogTransport{
|
||||||
|
base: base,
|
||||||
|
accessLog: log,
|
||||||
|
logger: logger,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *accessLogTransport) RoundTrip(req *http.Request) (*http.Response, error) {
|
||||||
|
start := time.Now()
|
||||||
|
resp, err := t.base.RoundTrip(req)
|
||||||
|
|
||||||
|
entry := accesslog.Entry{
|
||||||
|
Event: accesslog.EventUpstream,
|
||||||
|
RequestID: accesslog.RequestID(req.Context()),
|
||||||
|
Method: req.Method,
|
||||||
|
URL: accesslog.URLWithoutSecrets(req.URL),
|
||||||
|
DurationMS: time.Since(start).Milliseconds(),
|
||||||
|
}
|
||||||
|
if resp != nil {
|
||||||
|
entry.StatusCode = resp.StatusCode
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
entry.Error = errorWithoutSecrets(err, req.URL)
|
||||||
|
}
|
||||||
|
if writeErr := t.accessLog.Write(entry); writeErr != nil {
|
||||||
|
t.logger.Error("failed to write access log", "error", writeErr)
|
||||||
|
}
|
||||||
|
|
||||||
|
return resp, err
|
||||||
|
}
|
||||||
|
|
||||||
|
func errorWithoutSecrets(err error, requestURL *url.URL) string {
|
||||||
|
message := err.Error()
|
||||||
|
if requestURL == nil {
|
||||||
|
return message
|
||||||
|
}
|
||||||
|
|
||||||
|
cleanURL := accesslog.URLWithoutSecrets(requestURL)
|
||||||
|
for _, value := range []string{requestURL.String(), requestURL.Redacted()} {
|
||||||
|
if value != "" {
|
||||||
|
message = strings.ReplaceAll(message, value, cleanURL)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return message
|
||||||
|
}
|
||||||
121
internal/httpclient/access_log_test.go
Normal file
121
internal/httpclient/access_log_test.go
Normal file
|
|
@ -0,0 +1,121 @@
|
||||||
|
package httpclient
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bufio"
|
||||||
|
"encoding/json"
|
||||||
|
"errors"
|
||||||
|
"io"
|
||||||
|
"log/slog"
|
||||||
|
"net/http"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/git-pkgs/proxy/internal/accesslog"
|
||||||
|
)
|
||||||
|
|
||||||
|
type roundTripFunc func(*http.Request) (*http.Response, error)
|
||||||
|
|
||||||
|
func (f roundTripFunc) RoundTrip(req *http.Request) (*http.Response, error) {
|
||||||
|
return f(req)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAccessLogTransportRecordsUpstreamStatus(t *testing.T) {
|
||||||
|
path := filepath.Join(t.TempDir(), "access.jsonl")
|
||||||
|
accessLogger, err := accesslog.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
base := roundTripFunc(func(req *http.Request) (*http.Response, error) {
|
||||||
|
return &http.Response{
|
||||||
|
StatusCode: http.StatusTooManyRequests,
|
||||||
|
Body: io.NopCloser(strings.NewReader("rate limited")),
|
||||||
|
Request: req,
|
||||||
|
}, nil
|
||||||
|
})
|
||||||
|
client := &http.Client{Transport: NewAccessLogTransport(base, accessLogger, slog.Default())}
|
||||||
|
req, err := http.NewRequest(http.MethodGet, "https://user:password@registry.example/package.tgz?token=secret", nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
req = req.WithContext(accesslog.WithRequestID(req.Context(), "request-123"))
|
||||||
|
|
||||||
|
resp, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
if err := accessLogger.Close(); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
entry := readAccessLogEntry(t, path)
|
||||||
|
if entry.Event != accesslog.EventUpstream {
|
||||||
|
t.Errorf("event = %q, want %q", entry.Event, accesslog.EventUpstream)
|
||||||
|
}
|
||||||
|
if entry.RequestID != "request-123" {
|
||||||
|
t.Errorf("request_id = %q, want %q", entry.RequestID, "request-123")
|
||||||
|
}
|
||||||
|
if entry.StatusCode != http.StatusTooManyRequests {
|
||||||
|
t.Errorf("status_code = %d, want %d", entry.StatusCode, http.StatusTooManyRequests)
|
||||||
|
}
|
||||||
|
if entry.URL != "https://registry.example/package.tgz" {
|
||||||
|
t.Errorf("url = %q, want URL without credentials or query", entry.URL)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAccessLogTransportRecordsUpstreamError(t *testing.T) {
|
||||||
|
path := filepath.Join(t.TempDir(), "access.jsonl")
|
||||||
|
accessLogger, err := accesslog.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
wantErr := errors.New("GET https://user:password@registry.example/package.tgz?token=secret: connection refused")
|
||||||
|
base := roundTripFunc(func(*http.Request) (*http.Response, error) {
|
||||||
|
return nil, wantErr
|
||||||
|
})
|
||||||
|
client := &http.Client{Transport: NewAccessLogTransport(base, accessLogger, slog.Default())}
|
||||||
|
|
||||||
|
_, err = client.Get("https://user:password@registry.example/package.tgz?token=secret")
|
||||||
|
if !errors.Is(err, wantErr) {
|
||||||
|
t.Fatalf("GET error = %v, want %v", err, wantErr)
|
||||||
|
}
|
||||||
|
if err := accessLogger.Close(); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
entry := readAccessLogEntry(t, path)
|
||||||
|
if entry.StatusCode != 0 {
|
||||||
|
t.Errorf("status_code = %d, want 0", entry.StatusCode)
|
||||||
|
}
|
||||||
|
if strings.Contains(entry.Error, "password") || strings.Contains(entry.Error, "secret") {
|
||||||
|
t.Errorf("error contains URL credentials or query: %q", entry.Error)
|
||||||
|
}
|
||||||
|
if !strings.Contains(entry.Error, "connection refused") {
|
||||||
|
t.Errorf("error = %q, want connection failure", entry.Error)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func readAccessLogEntry(t *testing.T, path string) accesslog.Entry {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
file, err := os.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
defer func() { _ = file.Close() }()
|
||||||
|
|
||||||
|
scanner := bufio.NewScanner(file)
|
||||||
|
if !scanner.Scan() {
|
||||||
|
t.Fatalf("access log is empty: %v", scanner.Err())
|
||||||
|
}
|
||||||
|
|
||||||
|
var entry accesslog.Entry
|
||||||
|
if err := json.Unmarshal(scanner.Bytes(), &entry); err != nil {
|
||||||
|
t.Fatalf("decoding access log: %v", err)
|
||||||
|
}
|
||||||
|
return entry
|
||||||
|
}
|
||||||
433
internal/httpclient/transport.go
Normal file
433
internal/httpclient/transport.go
Normal file
|
|
@ -0,0 +1,433 @@
|
||||||
|
// Package httpclient provides authentication-aware HTTP transports for upstream requests.
|
||||||
|
package httpclient
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
|
"net/http"
|
||||||
|
"net/url"
|
||||||
|
"strings"
|
||||||
|
"sync"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
defaultTokenLifetime = 60 * time.Second
|
||||||
|
tokenExpirySkew = 5 * time.Second
|
||||||
|
maxTokenResponseSize = 1 << 20
|
||||||
|
shortTokenSkewDivisor = 10
|
||||||
|
)
|
||||||
|
|
||||||
|
// AuthFunc returns a configured authentication header for a URL.
|
||||||
|
type AuthFunc func(url string) (headerName, headerValue string)
|
||||||
|
|
||||||
|
// Transport adds configured authentication and follows OCI Bearer challenges.
|
||||||
|
type Transport struct {
|
||||||
|
base http.RoundTripper
|
||||||
|
authForURL AuthFunc
|
||||||
|
|
||||||
|
mu sync.Mutex
|
||||||
|
tokens map[string]cachedToken
|
||||||
|
challenges map[string]bearerChallenge
|
||||||
|
}
|
||||||
|
|
||||||
|
type cachedToken struct {
|
||||||
|
value string
|
||||||
|
expiresAt time.Time
|
||||||
|
}
|
||||||
|
|
||||||
|
type bearerChallenge struct {
|
||||||
|
realm string
|
||||||
|
service string
|
||||||
|
scopes []string
|
||||||
|
}
|
||||||
|
|
||||||
|
type tokenResponse struct {
|
||||||
|
Token string `json:"token"`
|
||||||
|
AccessToken string `json:"access_token"`
|
||||||
|
ExpiresIn int64 `json:"expires_in"`
|
||||||
|
IssuedAt string `json:"issued_at"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// NewTransport creates an authentication-aware transport around base.
|
||||||
|
func NewTransport(base http.RoundTripper, authForURL AuthFunc) *Transport {
|
||||||
|
if base == nil {
|
||||||
|
base = http.DefaultTransport
|
||||||
|
}
|
||||||
|
return &Transport{
|
||||||
|
base: base,
|
||||||
|
authForURL: authForURL,
|
||||||
|
tokens: make(map[string]cachedToken),
|
||||||
|
challenges: make(map[string]bearerChallenge),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// RoundTrip implements http.RoundTripper.
|
||||||
|
func (t *Transport) RoundTrip(req *http.Request) (*http.Response, error) {
|
||||||
|
hasExplicitAuthorization := req.Header.Get("Authorization") != ""
|
||||||
|
outbound := cloneRequest(req)
|
||||||
|
t.applyAuthentication(outbound, hasExplicitAuthorization)
|
||||||
|
|
||||||
|
resp, err := t.base.RoundTrip(outbound)
|
||||||
|
if err != nil || resp.StatusCode != http.StatusUnauthorized {
|
||||||
|
return resp, err
|
||||||
|
}
|
||||||
|
if hasExplicitAuthorization {
|
||||||
|
return resp, nil
|
||||||
|
}
|
||||||
|
if registryProtectionSpace(req.URL) == "" {
|
||||||
|
return resp, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
challenge, ok := parseBearerChallenge(resp.Header.Values("WWW-Authenticate"))
|
||||||
|
if !ok || !canReplay(req) {
|
||||||
|
return resp, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
drainAndClose(resp.Body)
|
||||||
|
token, err := t.token(req.Context(), challenge)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("registry authentication: %w", err)
|
||||||
|
}
|
||||||
|
t.rememberChallenge(req.URL, challenge)
|
||||||
|
|
||||||
|
retry, err := cloneRequestForRetry(req)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
t.applyConfiguredAuthentication(retry)
|
||||||
|
retry.Header.Set("Authorization", "Bearer "+token)
|
||||||
|
return t.base.RoundTrip(retry)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *Transport) applyAuthentication(req *http.Request, hasExplicitAuthorization bool) {
|
||||||
|
t.applyConfiguredAuthentication(req)
|
||||||
|
if hasExplicitAuthorization {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if token := t.cachedTokenForRequest(req.URL); token != "" {
|
||||||
|
req.Header.Set("Authorization", "Bearer "+token)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *Transport) applyConfiguredAuthentication(req *http.Request) {
|
||||||
|
if t.authForURL == nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
name, value := t.authForURL(req.URL.String())
|
||||||
|
if name != "" && value != "" && req.Header.Get(name) == "" {
|
||||||
|
req.Header.Set(name, value)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *Transport) token(ctx context.Context, challenge bearerChallenge) (string, error) {
|
||||||
|
key := challenge.key()
|
||||||
|
if token := t.cachedToken(key); token != "" {
|
||||||
|
return token, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
token, expiresAt, err := t.fetchToken(ctx, challenge)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
t.cacheToken(key, cachedToken{value: token, expiresAt: expiresAt})
|
||||||
|
return token, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *Transport) cacheToken(key string, token cachedToken) {
|
||||||
|
now := time.Now()
|
||||||
|
t.mu.Lock()
|
||||||
|
defer t.mu.Unlock()
|
||||||
|
|
||||||
|
for cachedKey, cached := range t.tokens {
|
||||||
|
if !now.Before(cached.expiresAt) {
|
||||||
|
delete(t.tokens, cachedKey)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
t.tokens[key] = token
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *Transport) fetchToken(ctx context.Context, challenge bearerChallenge) (string, time.Time, error) {
|
||||||
|
tokenURL, err := url.Parse(challenge.realm)
|
||||||
|
if err != nil || !tokenURL.IsAbs() || (tokenURL.Scheme != "https" && tokenURL.Scheme != "http") {
|
||||||
|
return "", time.Time{}, fmt.Errorf("invalid token realm %q", challenge.realm)
|
||||||
|
}
|
||||||
|
|
||||||
|
query := tokenURL.Query()
|
||||||
|
if challenge.service != "" {
|
||||||
|
query.Set("service", challenge.service)
|
||||||
|
}
|
||||||
|
for _, scope := range challenge.scopes {
|
||||||
|
query.Add("scope", scope)
|
||||||
|
}
|
||||||
|
query.Set("client_id", "git-pkgs-proxy")
|
||||||
|
tokenURL.RawQuery = query.Encode()
|
||||||
|
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, tokenURL.String(), nil)
|
||||||
|
if err != nil {
|
||||||
|
return "", time.Time{}, err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := &http.Client{Transport: configuredTransport{parent: t}}
|
||||||
|
resp, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return "", time.Time{}, fmt.Errorf("requesting token: %w", err)
|
||||||
|
}
|
||||||
|
defer func() { _ = resp.Body.Close() }()
|
||||||
|
|
||||||
|
if resp.StatusCode < http.StatusOK || resp.StatusCode >= http.StatusMultipleChoices {
|
||||||
|
body, _ := io.ReadAll(io.LimitReader(resp.Body, maxTokenResponseSize))
|
||||||
|
return "", time.Time{}, fmt.Errorf("token service returned %d: %s", resp.StatusCode, strings.TrimSpace(string(body)))
|
||||||
|
}
|
||||||
|
|
||||||
|
var payload tokenResponse
|
||||||
|
if err := json.NewDecoder(io.LimitReader(resp.Body, maxTokenResponseSize)).Decode(&payload); err != nil {
|
||||||
|
return "", time.Time{}, fmt.Errorf("decoding token response: %w", err)
|
||||||
|
}
|
||||||
|
token := payload.Token
|
||||||
|
if token == "" {
|
||||||
|
token = payload.AccessToken
|
||||||
|
}
|
||||||
|
if token == "" {
|
||||||
|
return "", time.Time{}, fmt.Errorf("token response did not contain a token")
|
||||||
|
}
|
||||||
|
|
||||||
|
issuedAt := time.Now()
|
||||||
|
if payload.IssuedAt != "" {
|
||||||
|
if parsed, parseErr := time.Parse(time.RFC3339, payload.IssuedAt); parseErr == nil {
|
||||||
|
issuedAt = parsed
|
||||||
|
}
|
||||||
|
}
|
||||||
|
lifetime := time.Duration(payload.ExpiresIn) * time.Second
|
||||||
|
if lifetime <= 0 {
|
||||||
|
lifetime = defaultTokenLifetime
|
||||||
|
}
|
||||||
|
expiresAt := issuedAt.Add(lifetime).Add(-expirySkew(lifetime))
|
||||||
|
return token, expiresAt, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
type configuredTransport struct {
|
||||||
|
parent *Transport
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t configuredTransport) RoundTrip(req *http.Request) (*http.Response, error) {
|
||||||
|
outbound := cloneRequest(req)
|
||||||
|
t.parent.applyConfiguredAuthentication(outbound)
|
||||||
|
return t.parent.base.RoundTrip(outbound)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *Transport) cachedTokenForRequest(requestURL *url.URL) string {
|
||||||
|
space := registryProtectionSpace(requestURL)
|
||||||
|
if space == "" {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
|
t.mu.Lock()
|
||||||
|
challenge, ok := t.challenges[space]
|
||||||
|
t.mu.Unlock()
|
||||||
|
if !ok {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
return t.cachedToken(challenge.key())
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *Transport) cachedToken(key string) string {
|
||||||
|
now := time.Now()
|
||||||
|
t.mu.Lock()
|
||||||
|
defer t.mu.Unlock()
|
||||||
|
|
||||||
|
token, ok := t.tokens[key]
|
||||||
|
if !ok {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
if !now.Before(token.expiresAt) {
|
||||||
|
delete(t.tokens, key)
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
return token.value
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *Transport) rememberChallenge(requestURL *url.URL, challenge bearerChallenge) {
|
||||||
|
space := registryProtectionSpace(requestURL)
|
||||||
|
if space == "" {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
t.mu.Lock()
|
||||||
|
t.challenges[space] = challenge
|
||||||
|
t.mu.Unlock()
|
||||||
|
}
|
||||||
|
|
||||||
|
func (c bearerChallenge) key() string {
|
||||||
|
return c.realm + "\x00" + c.service + "\x00" + strings.Join(c.scopes, "\x00")
|
||||||
|
}
|
||||||
|
|
||||||
|
func registryProtectionSpace(u *url.URL) string {
|
||||||
|
const registryPrefix = "/v2/"
|
||||||
|
if u == nil || !strings.HasPrefix(u.Path, registryPrefix) {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
rest := strings.TrimPrefix(u.Path, registryPrefix)
|
||||||
|
end := len(rest)
|
||||||
|
for _, marker := range []string{"/blobs/", "/manifests/", "/tags/", "/referrers/"} {
|
||||||
|
if index := strings.Index(rest, marker); index >= 0 && index < end {
|
||||||
|
end = index
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if end == len(rest) || end == 0 {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
return u.Scheme + "://" + u.Host + registryPrefix + rest[:end]
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseBearerChallenge(values []string) (bearerChallenge, bool) {
|
||||||
|
for _, value := range values {
|
||||||
|
params, ok := bearerParameters(value)
|
||||||
|
if !ok || params["realm"] == "" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
challenge := bearerChallenge{
|
||||||
|
realm: params["realm"],
|
||||||
|
service: params["service"],
|
||||||
|
}
|
||||||
|
if scope := params["scope"]; scope != "" {
|
||||||
|
challenge.scopes = append(challenge.scopes, scope)
|
||||||
|
}
|
||||||
|
return challenge, true
|
||||||
|
}
|
||||||
|
return bearerChallenge{}, false
|
||||||
|
}
|
||||||
|
|
||||||
|
func bearerParameters(value string) (map[string]string, bool) {
|
||||||
|
start := findAuthScheme(value, "Bearer")
|
||||||
|
if start < 0 {
|
||||||
|
return nil, false
|
||||||
|
}
|
||||||
|
rest := value[start+len("Bearer"):]
|
||||||
|
params := make(map[string]string)
|
||||||
|
for {
|
||||||
|
rest = strings.TrimLeft(rest, " \t,")
|
||||||
|
if rest == "" {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
|
||||||
|
keyEnd := strings.IndexAny(rest, "= \t,")
|
||||||
|
if keyEnd <= 0 {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
key := strings.ToLower(rest[:keyEnd])
|
||||||
|
rest = strings.TrimLeft(rest[keyEnd:], " \t")
|
||||||
|
if rest == "" || rest[0] != '=' {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
rest = strings.TrimLeft(rest[1:], " \t")
|
||||||
|
|
||||||
|
parsed, remaining, ok := parseAuthValue(rest)
|
||||||
|
if !ok {
|
||||||
|
return nil, false
|
||||||
|
}
|
||||||
|
params[key] = parsed
|
||||||
|
rest = remaining
|
||||||
|
}
|
||||||
|
return params, true
|
||||||
|
}
|
||||||
|
|
||||||
|
func findAuthScheme(value, scheme string) int {
|
||||||
|
inQuote := false
|
||||||
|
escaped := false
|
||||||
|
for index := 0; index+len(scheme) <= len(value); index++ {
|
||||||
|
char := value[index]
|
||||||
|
if escaped {
|
||||||
|
escaped = false
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if char == '\\' && inQuote {
|
||||||
|
escaped = true
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if char == '"' {
|
||||||
|
inQuote = !inQuote
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if inQuote || !strings.EqualFold(value[index:index+len(scheme)], scheme) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
beforeOK := index == 0 || value[index-1] == ',' || value[index-1] == ' ' || value[index-1] == '\t'
|
||||||
|
after := index + len(scheme)
|
||||||
|
afterOK := after < len(value) && (value[after] == ' ' || value[after] == '\t')
|
||||||
|
if beforeOK && afterOK {
|
||||||
|
return index
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return -1
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseAuthValue(value string) (parsed, remaining string, ok bool) {
|
||||||
|
if value == "" {
|
||||||
|
return "", "", false
|
||||||
|
}
|
||||||
|
if value[0] != '"' {
|
||||||
|
end := strings.IndexAny(value, " \t,")
|
||||||
|
if end < 0 {
|
||||||
|
return value, "", true
|
||||||
|
}
|
||||||
|
return value[:end], value[end:], end > 0
|
||||||
|
}
|
||||||
|
|
||||||
|
var builder strings.Builder
|
||||||
|
escaped := false
|
||||||
|
for index := 1; index < len(value); index++ {
|
||||||
|
char := value[index]
|
||||||
|
if escaped {
|
||||||
|
builder.WriteByte(char)
|
||||||
|
escaped = false
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if char == '\\' {
|
||||||
|
escaped = true
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if char == '"' {
|
||||||
|
return builder.String(), value[index+1:], true
|
||||||
|
}
|
||||||
|
builder.WriteByte(char)
|
||||||
|
}
|
||||||
|
return "", "", false
|
||||||
|
}
|
||||||
|
|
||||||
|
func cloneRequest(req *http.Request) *http.Request {
|
||||||
|
clone := req.Clone(req.Context())
|
||||||
|
clone.Header = req.Header.Clone()
|
||||||
|
return clone
|
||||||
|
}
|
||||||
|
|
||||||
|
func canReplay(req *http.Request) bool {
|
||||||
|
return req.Body == nil || req.GetBody != nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func cloneRequestForRetry(req *http.Request) (*http.Request, error) {
|
||||||
|
clone := cloneRequest(req)
|
||||||
|
if req.Body == nil {
|
||||||
|
return clone, nil
|
||||||
|
}
|
||||||
|
body, err := req.GetBody()
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("replaying authenticated request: %w", err)
|
||||||
|
}
|
||||||
|
clone.Body = body
|
||||||
|
return clone, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func expirySkew(lifetime time.Duration) time.Duration {
|
||||||
|
if lifetime < tokenExpirySkew*2 {
|
||||||
|
return lifetime / shortTokenSkewDivisor
|
||||||
|
}
|
||||||
|
return tokenExpirySkew
|
||||||
|
}
|
||||||
|
|
||||||
|
func drainAndClose(body io.ReadCloser) {
|
||||||
|
_, _ = io.Copy(io.Discard, io.LimitReader(body, maxTokenResponseSize))
|
||||||
|
_ = body.Close()
|
||||||
|
}
|
||||||
251
internal/httpclient/transport_test.go
Normal file
251
internal/httpclient/transport_test.go
Normal file
|
|
@ -0,0 +1,251 @@
|
||||||
|
package httpclient
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"io"
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestTransportFollowsBearerChallengeAndCachesToken(t *testing.T) {
|
||||||
|
var registryRequests int
|
||||||
|
var tokenRequests int
|
||||||
|
var server *httptest.Server
|
||||||
|
|
||||||
|
server = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
switch r.URL.Path {
|
||||||
|
case "/token":
|
||||||
|
tokenRequests++
|
||||||
|
if got := r.URL.Query().Get("service"); got != "registry.test" {
|
||||||
|
t.Errorf("service = %q, want %q", got, "registry.test")
|
||||||
|
}
|
||||||
|
if got := r.URL.Query().Get("scope"); got != "repository:library/test:pull" {
|
||||||
|
t.Errorf("scope = %q, want %q", got, "repository:library/test:pull")
|
||||||
|
}
|
||||||
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
_, _ = io.WriteString(w, `{"token":"registry-token","expires_in":3600}`)
|
||||||
|
case "/v2/library/test/blobs/sha256:first", "/v2/library/test/blobs/sha256:second":
|
||||||
|
registryRequests++
|
||||||
|
if r.Header.Get("Authorization") != "Bearer registry-token" {
|
||||||
|
w.Header().Set("WWW-Authenticate", `Bearer realm="`+server.URL+`/token",service="registry.test",scope="repository:library/test:pull"`)
|
||||||
|
http.Error(w, "authentication required", http.StatusUnauthorized)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
_, _ = io.WriteString(w, "blob")
|
||||||
|
default:
|
||||||
|
http.NotFound(w, r)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer server.Close()
|
||||||
|
|
||||||
|
client := &http.Client{Transport: NewTransport(http.DefaultTransport, nil)}
|
||||||
|
for _, digest := range []string{"sha256:first", "sha256:second"} {
|
||||||
|
resp, err := client.Get(server.URL + "/v2/library/test/blobs/" + digest)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET %s: %v", digest, err)
|
||||||
|
}
|
||||||
|
body, readErr := io.ReadAll(resp.Body)
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
if readErr != nil {
|
||||||
|
t.Fatalf("read %s response: %v", digest, readErr)
|
||||||
|
}
|
||||||
|
if resp.StatusCode != http.StatusOK {
|
||||||
|
t.Fatalf("GET %s status = %d, want %d", digest, resp.StatusCode, http.StatusOK)
|
||||||
|
}
|
||||||
|
if string(body) != "blob" {
|
||||||
|
t.Errorf("GET %s body = %q, want %q", digest, body, "blob")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if tokenRequests != 1 {
|
||||||
|
t.Errorf("token requests = %d, want 1", tokenRequests)
|
||||||
|
}
|
||||||
|
if registryRequests != 3 {
|
||||||
|
t.Errorf("registry requests = %d, want 3", registryRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTransportAddsConfiguredAuthentication(t *testing.T) {
|
||||||
|
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if got := r.Header.Get("X-Registry-Token"); got != "configured-token" {
|
||||||
|
t.Errorf("X-Registry-Token = %q, want %q", got, "configured-token")
|
||||||
|
}
|
||||||
|
w.WriteHeader(http.StatusNoContent)
|
||||||
|
}))
|
||||||
|
defer server.Close()
|
||||||
|
|
||||||
|
authForURL := func(url string) (string, string) {
|
||||||
|
if strings.HasPrefix(url, server.URL) {
|
||||||
|
return "X-Registry-Token", "configured-token"
|
||||||
|
}
|
||||||
|
return "", ""
|
||||||
|
}
|
||||||
|
client := &http.Client{Transport: NewTransport(http.DefaultTransport, authForURL)}
|
||||||
|
|
||||||
|
resp, err := client.Get(server.URL + "/metadata")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET metadata: %v", err)
|
||||||
|
}
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
if resp.StatusCode != http.StatusNoContent {
|
||||||
|
t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusNoContent)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTransportPreservesExplicitAuthentication(t *testing.T) {
|
||||||
|
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if got := r.Header.Get("Authorization"); got != "Bearer explicit-token" {
|
||||||
|
t.Errorf("Authorization = %q, want %q", got, "Bearer explicit-token")
|
||||||
|
}
|
||||||
|
w.WriteHeader(http.StatusNoContent)
|
||||||
|
}))
|
||||||
|
defer server.Close()
|
||||||
|
|
||||||
|
authForURL := func(string) (string, string) {
|
||||||
|
return "Authorization", "Bearer configured-token"
|
||||||
|
}
|
||||||
|
client := &http.Client{Transport: NewTransport(http.DefaultTransport, authForURL)}
|
||||||
|
req, err := http.NewRequest(http.MethodGet, server.URL+"/artifact", nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
req.Header.Set("Authorization", "Bearer explicit-token")
|
||||||
|
|
||||||
|
resp, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET artifact: %v", err)
|
||||||
|
}
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
if resp.StatusCode != http.StatusNoContent {
|
||||||
|
t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusNoContent)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTransportDoesNotReplaceExplicitAuthenticationAfterBearerChallenge(t *testing.T) {
|
||||||
|
var registryRequests int
|
||||||
|
var tokenRequests int
|
||||||
|
var server *httptest.Server
|
||||||
|
|
||||||
|
server = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
switch r.URL.Path {
|
||||||
|
case "/token":
|
||||||
|
tokenRequests++
|
||||||
|
_, _ = io.WriteString(w, `{"token":"registry-token"}`)
|
||||||
|
case "/v2/library/test/blobs/sha256:test":
|
||||||
|
registryRequests++
|
||||||
|
if got := r.Header.Get("Authorization"); got != "Bearer explicit-token" {
|
||||||
|
t.Errorf("Authorization = %q, want %q", got, "Bearer explicit-token")
|
||||||
|
}
|
||||||
|
w.Header().Set("WWW-Authenticate", `Bearer realm="`+server.URL+`/token"`)
|
||||||
|
http.Error(w, "authentication required", http.StatusUnauthorized)
|
||||||
|
default:
|
||||||
|
http.NotFound(w, r)
|
||||||
|
}
|
||||||
|
}))
|
||||||
|
defer server.Close()
|
||||||
|
|
||||||
|
client := &http.Client{Transport: NewTransport(http.DefaultTransport, nil)}
|
||||||
|
req, err := http.NewRequest(http.MethodGet, server.URL+"/v2/library/test/blobs/sha256:test", nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
req.Header.Set("Authorization", "Bearer explicit-token")
|
||||||
|
|
||||||
|
resp, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET blob: %v", err)
|
||||||
|
}
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
if resp.StatusCode != http.StatusUnauthorized {
|
||||||
|
t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusUnauthorized)
|
||||||
|
}
|
||||||
|
if registryRequests != 1 {
|
||||||
|
t.Errorf("registry requests = %d, want 1", registryRequests)
|
||||||
|
}
|
||||||
|
if tokenRequests != 0 {
|
||||||
|
t.Errorf("token requests = %d, want 0", tokenRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTransportDoesNotForwardConfiguredAuthenticationOnTokenRedirect(t *testing.T) {
|
||||||
|
destination := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if got := r.Header.Get("X-Registry-Token"); got != "" {
|
||||||
|
t.Errorf("redirected X-Registry-Token = %q, want empty", got)
|
||||||
|
}
|
||||||
|
_, _ = io.WriteString(w, `{"token":"registry-token"}`)
|
||||||
|
}))
|
||||||
|
defer destination.Close()
|
||||||
|
|
||||||
|
source := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if got := r.Header.Get("X-Registry-Token"); got != "configured-token" {
|
||||||
|
t.Errorf("source X-Registry-Token = %q, want %q", got, "configured-token")
|
||||||
|
}
|
||||||
|
http.Redirect(w, r, destination.URL+"/token", http.StatusFound)
|
||||||
|
}))
|
||||||
|
defer source.Close()
|
||||||
|
|
||||||
|
authForURL := func(rawURL string) (string, string) {
|
||||||
|
if strings.HasPrefix(rawURL, source.URL) {
|
||||||
|
return "X-Registry-Token", "configured-token"
|
||||||
|
}
|
||||||
|
return "", ""
|
||||||
|
}
|
||||||
|
transport := NewTransport(http.DefaultTransport, authForURL)
|
||||||
|
token, _, err := transport.fetchToken(context.Background(), bearerChallenge{realm: source.URL + "/token"})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("fetchToken: %v", err)
|
||||||
|
}
|
||||||
|
if token != "registry-token" {
|
||||||
|
t.Errorf("token = %q, want %q", token, "registry-token")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTransportPrunesExpiredTokens(t *testing.T) {
|
||||||
|
transport := NewTransport(http.DefaultTransport, nil)
|
||||||
|
transport.tokens["expired-unused"] = cachedToken{
|
||||||
|
value: "expired-token",
|
||||||
|
expiresAt: time.Now().Add(-time.Minute),
|
||||||
|
}
|
||||||
|
transport.cacheToken("current", cachedToken{
|
||||||
|
value: "current-token",
|
||||||
|
expiresAt: time.Now().Add(time.Minute),
|
||||||
|
})
|
||||||
|
|
||||||
|
if got := transport.cachedToken("current"); got != "current-token" {
|
||||||
|
t.Errorf("cachedToken(current) = %q, want %q", got, "current-token")
|
||||||
|
}
|
||||||
|
if _, ok := transport.tokens["expired-unused"]; ok {
|
||||||
|
t.Error("expired unused token was not pruned")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTransportDoesNotFollowBearerChallengeOutsideOCIRegistry(t *testing.T) {
|
||||||
|
tokenRequests := 0
|
||||||
|
var server *httptest.Server
|
||||||
|
server = httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.URL.Path == "/token" {
|
||||||
|
tokenRequests++
|
||||||
|
_, _ = io.WriteString(w, `{"token":"unexpected"}`)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
w.Header().Set("WWW-Authenticate", `Bearer realm="`+server.URL+`/token"`)
|
||||||
|
http.Error(w, "authentication required", http.StatusUnauthorized)
|
||||||
|
}))
|
||||||
|
defer server.Close()
|
||||||
|
|
||||||
|
client := &http.Client{Transport: NewTransport(http.DefaultTransport, nil)}
|
||||||
|
resp, err := client.Get(server.URL + "/api/packages")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET API: %v", err)
|
||||||
|
}
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
if resp.StatusCode != http.StatusUnauthorized {
|
||||||
|
t.Errorf("status = %d, want %d", resp.StatusCode, http.StatusUnauthorized)
|
||||||
|
}
|
||||||
|
if tokenRequests != 0 {
|
||||||
|
t.Errorf("token requests = %d, want 0", tokenRequests)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
@ -6,6 +6,7 @@ import (
|
||||||
"strconv"
|
"strconv"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
"github.com/git-pkgs/purl"
|
||||||
"github.com/prometheus/client_golang/prometheus"
|
"github.com/prometheus/client_golang/prometheus"
|
||||||
"github.com/prometheus/client_golang/prometheus/promhttp"
|
"github.com/prometheus/client_golang/prometheus/promhttp"
|
||||||
)
|
)
|
||||||
|
|
@ -173,12 +174,12 @@ func RecordRequest(ecosystem string, status int, duration time.Duration) {
|
||||||
|
|
||||||
// RecordCacheHit increments cache hit counter.
|
// RecordCacheHit increments cache hit counter.
|
||||||
func RecordCacheHit(ecosystem string) {
|
func RecordCacheHit(ecosystem string) {
|
||||||
CacheHits.WithLabelValues(ecosystem).Inc()
|
CacheHits.WithLabelValues(purl.NormalizeEcosystem(ecosystem)).Inc()
|
||||||
}
|
}
|
||||||
|
|
||||||
// RecordCacheMiss increments cache miss counter.
|
// RecordCacheMiss increments cache miss counter.
|
||||||
func RecordCacheMiss(ecosystem string) {
|
func RecordCacheMiss(ecosystem string) {
|
||||||
CacheMisses.WithLabelValues(ecosystem).Inc()
|
CacheMisses.WithLabelValues(purl.NormalizeEcosystem(ecosystem)).Inc()
|
||||||
}
|
}
|
||||||
|
|
||||||
// RecordUpstreamFetch tracks upstream fetch duration.
|
// RecordUpstreamFetch tracks upstream fetch duration.
|
||||||
|
|
|
||||||
|
|
@ -6,6 +6,7 @@ import (
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/prometheus/client_golang/prometheus"
|
"github.com/prometheus/client_golang/prometheus"
|
||||||
|
"github.com/prometheus/client_golang/prometheus/testutil"
|
||||||
dto "github.com/prometheus/client_model/go"
|
dto "github.com/prometheus/client_model/go"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -191,22 +192,45 @@ func TestMetricsEndpointOutput(t *testing.T) {
|
||||||
|
|
||||||
func TestMetricsLabeling(t *testing.T) {
|
func TestMetricsLabeling(t *testing.T) {
|
||||||
// Test that different ecosystems are properly labeled
|
// Test that different ecosystems are properly labeled
|
||||||
ecosystems := []string{"npm", "pypi", "cargo", "gem"}
|
ecosystems := []struct {
|
||||||
|
input string
|
||||||
|
label string
|
||||||
|
}{
|
||||||
|
{input: "npm", label: "npm"},
|
||||||
|
{input: "pypi", label: "pypi"},
|
||||||
|
{input: "cargo", label: "cargo"},
|
||||||
|
{input: "gem", label: "rubygems"},
|
||||||
|
}
|
||||||
|
|
||||||
for _, eco := range ecosystems {
|
for _, eco := range ecosystems {
|
||||||
RecordRequest(eco, 200, 10*time.Millisecond)
|
RecordRequest(eco.input, 200, 10*time.Millisecond)
|
||||||
RecordCacheHit(eco)
|
RecordCacheHit(eco.input)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Verify each ecosystem has metrics
|
// Verify each ecosystem has metrics
|
||||||
for _, eco := range ecosystems {
|
for _, eco := range ecosystems {
|
||||||
val := getMetricValue(t, CacheHits, eco)
|
val := getMetricValue(t, CacheHits, eco.label)
|
||||||
if val == 0 {
|
if val == 0 {
|
||||||
t.Errorf("no cache hits recorded for %s", eco)
|
t.Errorf("no cache hits recorded for %s", eco.label)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestCacheMetricLabelsAreNormalized(t *testing.T) {
|
||||||
|
rubyHitsBefore := testutil.ToFloat64(CacheHits.WithLabelValues("rubygems"))
|
||||||
|
composerMissesBefore := testutil.ToFloat64(CacheMisses.WithLabelValues("packagist"))
|
||||||
|
|
||||||
|
RecordCacheHit("gem")
|
||||||
|
RecordCacheMiss("composer")
|
||||||
|
|
||||||
|
if diff := testutil.ToFloat64(CacheHits.WithLabelValues("rubygems")) - rubyHitsBefore; diff != 1 {
|
||||||
|
t.Errorf("rubygems cache hits delta = %.0f, want 1", diff)
|
||||||
|
}
|
||||||
|
if diff := testutil.ToFloat64(CacheMisses.WithLabelValues("packagist")) - composerMissesBefore; diff != 1 {
|
||||||
|
t.Errorf("packagist cache misses delta = %.0f, want 1", diff)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestMetricNames(t *testing.T) {
|
func TestMetricNames(t *testing.T) {
|
||||||
// Verify metric names follow Prometheus naming conventions
|
// Verify metric names follow Prometheus naming conventions
|
||||||
expectedMetrics := []string{
|
expectedMetrics := []string{
|
||||||
|
|
|
||||||
|
|
@ -1,16 +0,0 @@
|
||||||
package mirror
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"fmt"
|
|
||||||
)
|
|
||||||
|
|
||||||
// RegistrySource enumerates all packages in a registry for full mirroring.
|
|
||||||
// Registry enumeration is not yet implemented for any ecosystem.
|
|
||||||
type RegistrySource struct {
|
|
||||||
Ecosystem string
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *RegistrySource) Enumerate(_ context.Context, _ func(PackageVersion) error) error {
|
|
||||||
return fmt.Errorf("registry enumeration is not yet implemented for ecosystem %q", s.Ecosystem)
|
|
||||||
}
|
|
||||||
|
|
@ -1,46 +0,0 @@
|
||||||
package mirror
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"testing"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestRegistrySourceUnsupported(t *testing.T) {
|
|
||||||
source := &RegistrySource{Ecosystem: "golang"}
|
|
||||||
err := source.Enumerate(context.Background(), func(pv PackageVersion) error {
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err == nil {
|
|
||||||
t.Fatal("expected error for unsupported ecosystem")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRegistrySourceNPMNotImplemented(t *testing.T) {
|
|
||||||
source := &RegistrySource{Ecosystem: "npm"}
|
|
||||||
err := source.Enumerate(context.Background(), func(pv PackageVersion) error {
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err == nil {
|
|
||||||
t.Fatal("expected not-implemented error")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRegistrySourcePyPINotImplemented(t *testing.T) {
|
|
||||||
source := &RegistrySource{Ecosystem: "pypi"}
|
|
||||||
err := source.Enumerate(context.Background(), func(pv PackageVersion) error {
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err == nil {
|
|
||||||
t.Fatal("expected not-implemented error")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRegistrySourceCargoNotImplemented(t *testing.T) {
|
|
||||||
source := &RegistrySource{Ecosystem: "cargo"}
|
|
||||||
err := source.Enumerate(context.Background(), func(pv PackageVersion) error {
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err == nil {
|
|
||||||
t.Fatal("expected not-implemented error")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
@ -139,12 +139,11 @@ type BulkResponse struct {
|
||||||
// Resolves namespaced package names (Composer vendor/name, npm @scope/name) from the path.
|
// Resolves namespaced package names (Composer vendor/name, npm @scope/name) from the path.
|
||||||
func (h *APIHandler) HandlePackagePath(w http.ResponseWriter, r *http.Request) {
|
func (h *APIHandler) HandlePackagePath(w http.ResponseWriter, r *http.Request) {
|
||||||
ecosystem := chi.URLParam(r, "ecosystem")
|
ecosystem := chi.URLParam(r, "ecosystem")
|
||||||
wildcard := chi.URLParam(r, "*")
|
segments, err := packagePathSegments(r)
|
||||||
if err := validatePackagePath(wildcard); err != nil {
|
if err != nil {
|
||||||
badRequest(w, err.Error())
|
badRequest(w, err.Error())
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
segments := splitWildcardPath(wildcard)
|
|
||||||
|
|
||||||
if ecosystem == "" || len(segments) == 0 {
|
if ecosystem == "" || len(segments) == 0 {
|
||||||
badRequest(w, "ecosystem and name are required")
|
badRequest(w, "ecosystem and name are required")
|
||||||
|
|
@ -277,12 +276,11 @@ func (h *APIHandler) getVersion(w http.ResponseWriter, r *http.Request, ecosyste
|
||||||
// Supports both {name} and {name}/{version} paths with namespaced package names.
|
// Supports both {name} and {name}/{version} paths with namespaced package names.
|
||||||
func (h *APIHandler) HandleVulnsPath(w http.ResponseWriter, r *http.Request) {
|
func (h *APIHandler) HandleVulnsPath(w http.ResponseWriter, r *http.Request) {
|
||||||
ecosystem := chi.URLParam(r, "ecosystem")
|
ecosystem := chi.URLParam(r, "ecosystem")
|
||||||
wildcard := chi.URLParam(r, "*")
|
segments, err := packagePathSegments(r)
|
||||||
if err := validatePackagePath(wildcard); err != nil {
|
if err != nil {
|
||||||
badRequest(w, err.Error())
|
badRequest(w, err.Error())
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
segments := splitWildcardPath(wildcard)
|
|
||||||
|
|
||||||
if ecosystem == "" || len(segments) == 0 {
|
if ecosystem == "" || len(segments) == 0 {
|
||||||
badRequest(w, "ecosystem and name are required")
|
badRequest(w, "ecosystem and name are required")
|
||||||
|
|
|
||||||
|
|
@ -147,12 +147,11 @@ type BrowseFileInfo struct {
|
||||||
// {name}/{version}/file/{path} -> browse file
|
// {name}/{version}/file/{path} -> browse file
|
||||||
func (s *Server) handleBrowsePath(w http.ResponseWriter, r *http.Request) {
|
func (s *Server) handleBrowsePath(w http.ResponseWriter, r *http.Request) {
|
||||||
ecosystem := chi.URLParam(r, "ecosystem")
|
ecosystem := chi.URLParam(r, "ecosystem")
|
||||||
wildcard := chi.URLParam(r, "*")
|
segments, err := packagePathSegments(r)
|
||||||
if err := validatePackagePath(wildcard); err != nil {
|
if err != nil {
|
||||||
badRequest(w, err.Error())
|
badRequest(w, err.Error())
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
segments := splitWildcardPath(wildcard)
|
|
||||||
|
|
||||||
if ecosystem == "" || len(segments) < 2 {
|
if ecosystem == "" || len(segments) < 2 {
|
||||||
badRequest(w, "ecosystem, name, and version required")
|
badRequest(w, "ecosystem, name, and version required")
|
||||||
|
|
@ -203,12 +202,11 @@ func (s *Server) handleBrowsePath(w http.ResponseWriter, r *http.Request) {
|
||||||
// Supported paths: {name}/{fromVersion}/{toVersion}
|
// Supported paths: {name}/{fromVersion}/{toVersion}
|
||||||
func (s *Server) handleComparePath(w http.ResponseWriter, r *http.Request) {
|
func (s *Server) handleComparePath(w http.ResponseWriter, r *http.Request) {
|
||||||
ecosystem := chi.URLParam(r, "ecosystem")
|
ecosystem := chi.URLParam(r, "ecosystem")
|
||||||
wildcard := chi.URLParam(r, "*")
|
segments, err := packagePathSegments(r)
|
||||||
if err := validatePackagePath(wildcard); err != nil {
|
if err != nil {
|
||||||
badRequest(w, err.Error())
|
badRequest(w, err.Error())
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
segments := splitWildcardPath(wildcard)
|
|
||||||
|
|
||||||
if ecosystem == "" || len(segments) < 3 {
|
if ecosystem == "" || len(segments) < 3 {
|
||||||
badRequest(w, "ecosystem, name, fromVersion, and toVersion required")
|
badRequest(w, "ecosystem, name, fromVersion, and toVersion required")
|
||||||
|
|
@ -506,11 +504,16 @@ func isLikelyText(filename string) bool {
|
||||||
}
|
}
|
||||||
|
|
||||||
// BrowseSourceData contains data for the browse source page.
|
// BrowseSourceData contains data for the browse source page.
|
||||||
|
//
|
||||||
|
// Version is the decoded version, for display. EscapedVersion is the same value
|
||||||
|
// escaped as a single URL path segment and is what the links and the browse API
|
||||||
|
// calls must use; see database.Version.EscapedVersion.
|
||||||
type BrowseSourceData struct {
|
type BrowseSourceData struct {
|
||||||
Layout
|
Layout
|
||||||
Ecosystem string
|
Ecosystem string
|
||||||
PackageName string
|
PackageName string
|
||||||
Version string
|
Version string
|
||||||
|
EscapedVersion string
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleBrowseSource is now showBrowseSource in server.go, dispatched via handlePackagePath.
|
// handleBrowseSource is now showBrowseSource in server.go, dispatched via handlePackagePath.
|
||||||
|
|
@ -601,12 +604,17 @@ func (s *Server) compareDiff(w http.ResponseWriter, r *http.Request, ecosystem,
|
||||||
}
|
}
|
||||||
|
|
||||||
// ComparePageData contains data for the version comparison page.
|
// ComparePageData contains data for the version comparison page.
|
||||||
|
//
|
||||||
|
// FromVersion and ToVersion are decoded, for display; the Escaped variants are
|
||||||
|
// the path-segment form used to build the compare API URL.
|
||||||
type ComparePageData struct {
|
type ComparePageData struct {
|
||||||
Layout
|
Layout
|
||||||
Ecosystem string
|
Ecosystem string
|
||||||
PackageName string
|
PackageName string
|
||||||
FromVersion string
|
FromVersion string
|
||||||
ToVersion string
|
ToVersion string
|
||||||
|
EscapedFromVersion string
|
||||||
|
EscapedToVersion string
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleComparePage is now showComparePage in server.go, dispatched via handlePackagePath.
|
// handleComparePage is now showComparePage in server.go, dispatched via handlePackagePath.
|
||||||
|
|
|
||||||
|
|
@ -430,6 +430,10 @@ func TestHandleBrowseSourcePage(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if !strings.Contains(body, "proxy test-version (test-commit)") {
|
||||||
|
t.Error("browse source footer should contain proxy build information, not the package version")
|
||||||
|
}
|
||||||
|
|
||||||
// Check that the escapeHTML function is present for XSS protection
|
// Check that the escapeHTML function is present for XSS protection
|
||||||
if !strings.Contains(body, "function escapeHTML(str)") {
|
if !strings.Contains(body, "function escapeHTML(str)") {
|
||||||
t.Error("browse source page missing escapeHTML function for XSS protection")
|
t.Error("browse source page missing escapeHTML function for XSS protection")
|
||||||
|
|
@ -450,8 +454,10 @@ func TestHandleBrowseSourcePage(t *testing.T) {
|
||||||
if !strings.Contains(body, "const packageName = 'test-browse'") {
|
if !strings.Contains(body, "const packageName = 'test-browse'") {
|
||||||
t.Error("browse source page missing packageName variable")
|
t.Error("browse source page missing packageName variable")
|
||||||
}
|
}
|
||||||
if !strings.Contains(body, "const version = '1.0.0'") {
|
// The version reaches the browse API as one path segment, so the page holds
|
||||||
t.Error("browse source page missing version variable")
|
// its escaped form.
|
||||||
|
if !strings.Contains(body, "const versionPath = '1.0.0'") {
|
||||||
|
t.Error("browse source page missing versionPath variable")
|
||||||
}
|
}
|
||||||
|
|
||||||
// Verify content type
|
// Verify content type
|
||||||
|
|
@ -617,12 +623,13 @@ func TestHandleComparePage(t *testing.T) {
|
||||||
|
|
||||||
body := w.Body.String()
|
body := w.Body.String()
|
||||||
|
|
||||||
// Check that versions are set correctly in JavaScript
|
// Check that versions are set correctly in JavaScript. The compare API takes
|
||||||
if !strings.Contains(body, "const fromVersion = '1.0.0'") {
|
// each version as a path segment, so the page holds their escaped forms.
|
||||||
t.Error("page should set fromVersion")
|
if !strings.Contains(body, "const fromVersionPath = '1.0.0'") {
|
||||||
|
t.Error("page should set fromVersionPath")
|
||||||
}
|
}
|
||||||
if !strings.Contains(body, "const toVersion = '2.0.0'") {
|
if !strings.Contains(body, "const toVersionPath = '2.0.0'") {
|
||||||
t.Error("page should set toVersion")
|
t.Error("page should set toVersionPath")
|
||||||
}
|
}
|
||||||
|
|
||||||
// Test invalid format (missing separator)
|
// Test invalid format (missing separator)
|
||||||
|
|
|
||||||
|
|
@ -15,7 +15,7 @@ import (
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
"github.com/git-pkgs/proxy/internal/storage"
|
||||||
)
|
)
|
||||||
|
|
||||||
func setupEvictionTest(t *testing.T) (*database.DB, *storage.Filesystem) {
|
func setupEvictionTest(t *testing.T) (*database.DB, *storage.Blob) {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
tempDir := t.TempDir()
|
tempDir := t.TempDir()
|
||||||
|
|
@ -27,7 +27,7 @@ func setupEvictionTest(t *testing.T) (*database.DB, *storage.Filesystem) {
|
||||||
t.Fatalf("failed to create database: %v", err)
|
t.Fatalf("failed to create database: %v", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
store, err := storage.NewFilesystem(storagePath)
|
store, err := storage.OpenBucket(context.Background(), "file://"+storagePath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
_ = db.Close()
|
_ = db.Close()
|
||||||
t.Fatalf("failed to create storage: %v", err)
|
t.Fatalf("failed to create storage: %v", err)
|
||||||
|
|
@ -243,7 +243,7 @@ func TestStartEvictionLoop_UnlimitedSkips(t *testing.T) {
|
||||||
}
|
}
|
||||||
defer func() { _ = db.Close() }()
|
defer func() { _ = db.Close() }()
|
||||||
|
|
||||||
store, err := storage.NewFilesystem(storagePath)
|
store, err := storage.OpenBucket(context.Background(), "file://"+storagePath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatalf("failed to create storage: %v", err)
|
t.Fatalf("failed to create storage: %v", err)
|
||||||
}
|
}
|
||||||
|
|
@ -280,7 +280,7 @@ func defaultTestConfig(storagePath, dbPath string) *config.Config {
|
||||||
return &config.Config{
|
return &config.Config{
|
||||||
Listen: ":8080",
|
Listen: ":8080",
|
||||||
BaseURL: "http://localhost:8080",
|
BaseURL: "http://localhost:8080",
|
||||||
Storage: config.StorageConfig{Path: storagePath, MaxSize: ""},
|
Storage: config.StorageConfig{URL: "file://" + storagePath, MaxSize: ""},
|
||||||
Database: config.DatabaseConfig{
|
Database: config.DatabaseConfig{
|
||||||
Driver: "sqlite",
|
Driver: "sqlite",
|
||||||
Path: dbPath,
|
Path: dbPath,
|
||||||
|
|
|
||||||
|
|
@ -2,17 +2,24 @@ package server
|
||||||
|
|
||||||
import "net/http"
|
import "net/http"
|
||||||
|
|
||||||
// Layout carries per-request fields consumed by the shared base template
|
// BuildInfo identifies the running proxy binary.
|
||||||
// (canonical URL, og:url). It is embedded in every page data struct so that
|
type BuildInfo struct {
|
||||||
// templates can reference {{.UIBaseURL}} and {{.CanonicalPath}} alongside the
|
Version string
|
||||||
// page's own fields.
|
Commit string
|
||||||
|
}
|
||||||
|
|
||||||
|
// Layout carries shared fields consumed by the base template. It is embedded
|
||||||
|
// in every page data struct so templates can access canonical URL and build
|
||||||
|
// information alongside the page's own fields.
|
||||||
type Layout struct {
|
type Layout struct {
|
||||||
|
BuildInfo BuildInfo
|
||||||
UIBaseURL string
|
UIBaseURL string
|
||||||
CanonicalPath string
|
CanonicalPath string
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *Server) layoutFor(r *http.Request) Layout {
|
func (s *Server) layoutFor(r *http.Request) Layout {
|
||||||
return Layout{
|
return Layout{
|
||||||
|
BuildInfo: s.buildInfo,
|
||||||
UIBaseURL: s.cfg.UIBaseURL,
|
UIBaseURL: s.cfg.UIBaseURL,
|
||||||
CanonicalPath: r.URL.Path,
|
CanonicalPath: r.URL.Path,
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -3,16 +3,15 @@ package server
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"net/http"
|
"net/http"
|
||||||
|
"strings"
|
||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
"github.com/git-pkgs/proxy/internal/accesslog"
|
||||||
|
"github.com/git-pkgs/proxy/internal/metrics"
|
||||||
"github.com/go-chi/chi/v5/middleware"
|
"github.com/go-chi/chi/v5/middleware"
|
||||||
)
|
)
|
||||||
|
|
||||||
type contextKey string
|
|
||||||
|
|
||||||
const requestIDKey contextKey = "request_id"
|
|
||||||
|
|
||||||
var requestCounter atomic.Uint64
|
var requestCounter atomic.Uint64
|
||||||
|
|
||||||
// RequestIDMiddleware adds a sequential request ID to the context and response headers.
|
// RequestIDMiddleware adds a sequential request ID to the context and response headers.
|
||||||
|
|
@ -23,7 +22,7 @@ func RequestIDMiddleware(next http.Handler) http.Handler {
|
||||||
requestID := middleware.GetReqID(r.Context())
|
requestID := middleware.GetReqID(r.Context())
|
||||||
|
|
||||||
// Store formatted ID in context
|
// Store formatted ID in context
|
||||||
ctx := context.WithValue(r.Context(), requestIDKey, requestID)
|
ctx := accesslog.WithRequestID(r.Context(), requestID)
|
||||||
|
|
||||||
// Add to response header for client tracking
|
// Add to response header for client tracking
|
||||||
w.Header().Set("X-Request-ID", requestID)
|
w.Header().Set("X-Request-ID", requestID)
|
||||||
|
|
@ -34,10 +33,7 @@ func RequestIDMiddleware(next http.Handler) http.Handler {
|
||||||
|
|
||||||
// GetRequestID retrieves the request ID from context.
|
// GetRequestID retrieves the request ID from context.
|
||||||
func GetRequestID(ctx context.Context) string {
|
func GetRequestID(ctx context.Context) string {
|
||||||
if id, ok := ctx.Value(requestIDKey).(string); ok {
|
return accesslog.RequestID(ctx)
|
||||||
return id
|
|
||||||
}
|
|
||||||
return ""
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// LoggerMiddleware logs HTTP requests with request ID correlation.
|
// LoggerMiddleware logs HTTP requests with request ID correlation.
|
||||||
|
|
@ -48,27 +44,51 @@ func (s *Server) LoggerMiddleware(next http.Handler) http.Handler {
|
||||||
|
|
||||||
rw := &responseWriter{ResponseWriter: w, status: http.StatusOK}
|
rw := &responseWriter{ResponseWriter: w, status: http.StatusOK}
|
||||||
next.ServeHTTP(rw, r)
|
next.ServeHTTP(rw, r)
|
||||||
|
duration := time.Since(start)
|
||||||
|
|
||||||
s.logger.Info("request",
|
s.logger.Info("request",
|
||||||
"request_id", requestID,
|
"request_id", requestID,
|
||||||
"method", r.Method,
|
"method", r.Method,
|
||||||
"path", r.URL.Path,
|
"path", r.URL.Path,
|
||||||
"status", rw.status,
|
"status", rw.status,
|
||||||
"duration", time.Since(start),
|
"duration", duration,
|
||||||
"remote", r.RemoteAddr)
|
"remote", r.RemoteAddr)
|
||||||
|
|
||||||
|
if r.URL.Path != "/metrics" {
|
||||||
|
metrics.RecordRequest(requestEcosystem(r.URL.Path), rw.status, duration)
|
||||||
|
}
|
||||||
|
|
||||||
|
if s.accessLog != nil {
|
||||||
|
if err := s.accessLog.Write(accesslog.Entry{
|
||||||
|
Event: accesslog.EventRequest,
|
||||||
|
RequestID: requestID,
|
||||||
|
Method: r.Method,
|
||||||
|
Path: r.URL.EscapedPath(),
|
||||||
|
StatusCode: rw.status,
|
||||||
|
DurationMS: duration.Milliseconds(),
|
||||||
|
RemoteAddr: r.RemoteAddr,
|
||||||
|
}); err != nil {
|
||||||
|
s.logger.Error("failed to write access log", "error", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
// ActiveRequestsMiddleware tracks the number of active requests using Prometheus metrics.
|
func requestEcosystem(path string) string {
|
||||||
func ActiveRequestsMiddleware(next http.Handler) http.Handler {
|
segment, _, _ := strings.Cut(strings.TrimPrefix(path, "/"), "/")
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
switch segment {
|
||||||
// Don't track metrics endpoint itself
|
case "npm", "cargo", "hex", "pub", "pypi", "maven", "gradle", "nuget",
|
||||||
if r.URL.Path == "/metrics" {
|
"conan", "conda", "cran", "julia", "debian", "rpm":
|
||||||
next.ServeHTTP(w, r)
|
return segment
|
||||||
return
|
case "gem":
|
||||||
|
return "rubygems"
|
||||||
|
case "go":
|
||||||
|
return "golang"
|
||||||
|
case "composer":
|
||||||
|
return "packagist"
|
||||||
|
case "v2":
|
||||||
|
return "oci"
|
||||||
|
default:
|
||||||
|
return "other"
|
||||||
}
|
}
|
||||||
|
|
||||||
// Implemented in server.go where metrics package is imported
|
|
||||||
next.ServeHTTP(w, r)
|
|
||||||
})
|
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -2,13 +2,21 @@ package server
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"encoding/json"
|
||||||
"io"
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
|
"github.com/git-pkgs/proxy/internal/accesslog"
|
||||||
|
"github.com/git-pkgs/proxy/internal/metrics"
|
||||||
"github.com/go-chi/chi/v5/middleware"
|
"github.com/go-chi/chi/v5/middleware"
|
||||||
|
"github.com/prometheus/client_golang/prometheus"
|
||||||
|
"github.com/prometheus/client_golang/prometheus/testutil"
|
||||||
|
dto "github.com/prometheus/client_model/go"
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestRequestIDMiddleware(t *testing.T) {
|
func TestRequestIDMiddleware(t *testing.T) {
|
||||||
|
|
@ -45,7 +53,7 @@ func TestGetRequestID(t *testing.T) {
|
||||||
}{
|
}{
|
||||||
{
|
{
|
||||||
name: "with request ID",
|
name: "with request ID",
|
||||||
ctx: context.WithValue(context.Background(), requestIDKey, "test-123"),
|
ctx: accesslog.WithRequestID(context.Background(), "test-123"),
|
||||||
expected: "test-123",
|
expected: "test-123",
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|
@ -65,36 +73,6 @@ func TestGetRequestID(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestActiveRequestsMiddleware(t *testing.T) {
|
|
||||||
handler := ActiveRequestsMiddleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
}))
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/test", nil)
|
|
||||||
rec := httptest.NewRecorder()
|
|
||||||
|
|
||||||
handler.ServeHTTP(rec, req)
|
|
||||||
|
|
||||||
if rec.Code != http.StatusOK {
|
|
||||||
t.Errorf("expected status 200, got %d", rec.Code)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestActiveRequestsMiddleware_SkipsMetricsEndpoint(t *testing.T) {
|
|
||||||
handler := ActiveRequestsMiddleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
}))
|
|
||||||
|
|
||||||
req := httptest.NewRequest(http.MethodGet, "/metrics", nil)
|
|
||||||
rec := httptest.NewRecorder()
|
|
||||||
|
|
||||||
handler.ServeHTTP(rec, req)
|
|
||||||
|
|
||||||
if rec.Code != http.StatusOK {
|
|
||||||
t.Errorf("expected status 200, got %d", rec.Code)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestLoggerMiddleware(t *testing.T) {
|
func TestLoggerMiddleware(t *testing.T) {
|
||||||
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
s := &Server{logger: logger}
|
s := &Server{logger: logger}
|
||||||
|
|
@ -121,6 +99,133 @@ func TestLoggerMiddleware(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestLoggerMiddlewareRecordsRequestMetrics(t *testing.T) {
|
||||||
|
before := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("rubygems", "404"))
|
||||||
|
durationMetric := metrics.RequestDuration.WithLabelValues("rubygems", "404")
|
||||||
|
beforeDurationCount := histogramSampleCount(t, durationMetric)
|
||||||
|
|
||||||
|
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
s := &Server{logger: logger}
|
||||||
|
handler := s.LoggerMiddleware(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
w.WriteHeader(http.StatusNotFound)
|
||||||
|
}))
|
||||||
|
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/gem/downloads/missing.gem", nil)
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
handler.ServeHTTP(rec, req)
|
||||||
|
|
||||||
|
after := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("rubygems", "404"))
|
||||||
|
if got := after - before; got != 1 {
|
||||||
|
t.Errorf("request counter delta = %.0f, want 1", got)
|
||||||
|
}
|
||||||
|
afterDurationCount := histogramSampleCount(t, durationMetric)
|
||||||
|
if got := afterDurationCount - beforeDurationCount; got != 1 {
|
||||||
|
t.Errorf("request duration sample delta = %d, want 1", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func histogramSampleCount(t *testing.T, observer prometheus.Observer) uint64 {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
metric, ok := observer.(prometheus.Metric)
|
||||||
|
if !ok {
|
||||||
|
t.Fatal("histogram observer does not implement prometheus.Metric")
|
||||||
|
}
|
||||||
|
|
||||||
|
var value dto.Metric
|
||||||
|
if err := metric.Write(&value); err != nil {
|
||||||
|
t.Fatalf("writing histogram metric: %v", err)
|
||||||
|
}
|
||||||
|
return value.GetHistogram().GetSampleCount()
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLoggerMiddlewareSkipsMetricsEndpointMetrics(t *testing.T) {
|
||||||
|
before := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("other", "200"))
|
||||||
|
|
||||||
|
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
s := &Server{logger: logger}
|
||||||
|
handler := s.LoggerMiddleware(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
w.WriteHeader(http.StatusOK)
|
||||||
|
}))
|
||||||
|
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/metrics", nil)
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
handler.ServeHTTP(rec, req)
|
||||||
|
|
||||||
|
after := testutil.ToFloat64(metrics.RequestsTotal.WithLabelValues("other", "200"))
|
||||||
|
if got := after - before; got != 0 {
|
||||||
|
t.Errorf("request counter delta = %.0f, want 0", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRequestEcosystem(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
path string
|
||||||
|
want string
|
||||||
|
}{
|
||||||
|
{path: "/npm/lodash", want: "npm"},
|
||||||
|
{path: "/gem/downloads/rails.gem", want: "rubygems"},
|
||||||
|
{path: "/go/example.com/module/@v/list", want: "golang"},
|
||||||
|
{path: "/composer/vendor/package", want: "packagist"},
|
||||||
|
{path: "/v2/library/alpine/manifests/latest", want: "oci"},
|
||||||
|
{path: "/ui/", want: "other"},
|
||||||
|
{path: "/api/package/npm/lodash", want: "other"},
|
||||||
|
{path: "/", want: "other"},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.path, func(t *testing.T) {
|
||||||
|
if got := requestEcosystem(tt.path); got != tt.want {
|
||||||
|
t.Errorf("requestEcosystem(%q) = %q, want %q", tt.path, got, tt.want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLoggerMiddlewareWritesAccessLog(t *testing.T) {
|
||||||
|
path := filepath.Join(t.TempDir(), "access.jsonl")
|
||||||
|
activityLog, err := accesslog.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
s := &Server{logger: logger, accessLog: activityLog}
|
||||||
|
next := http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||||
|
w.WriteHeader(http.StatusNotFound)
|
||||||
|
})
|
||||||
|
handler := middleware.RequestID(RequestIDMiddleware(s.LoggerMiddleware(next)))
|
||||||
|
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/packages/example?token=secret", nil)
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
handler.ServeHTTP(rec, req)
|
||||||
|
|
||||||
|
if err := activityLog.Close(); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
data, err := os.ReadFile(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
var entry accesslog.Entry
|
||||||
|
if err := json.Unmarshal(data, &entry); err != nil {
|
||||||
|
t.Fatalf("decoding access log: %v", err)
|
||||||
|
}
|
||||||
|
if entry.Event != accesslog.EventRequest {
|
||||||
|
t.Errorf("event = %q, want %q", entry.Event, accesslog.EventRequest)
|
||||||
|
}
|
||||||
|
if entry.RequestID == "" {
|
||||||
|
t.Error("request_id is empty")
|
||||||
|
}
|
||||||
|
if entry.Path != "/packages/example" {
|
||||||
|
t.Errorf("path = %q, want query string omitted", entry.Path)
|
||||||
|
}
|
||||||
|
if entry.StatusCode != http.StatusNotFound {
|
||||||
|
t.Errorf("status_code = %d, want %d", entry.StatusCode, http.StatusNotFound)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestResponseWriter_WriteHeader(t *testing.T) {
|
func TestResponseWriter_WriteHeader(t *testing.T) {
|
||||||
tests := []struct {
|
tests := []struct {
|
||||||
name string
|
name string
|
||||||
|
|
|
||||||
|
|
@ -2,10 +2,13 @@ package server
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"net/http"
|
||||||
|
"net/url"
|
||||||
"strings"
|
"strings"
|
||||||
"unicode"
|
"unicode"
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
"github.com/git-pkgs/proxy/internal/database"
|
||||||
|
"github.com/go-chi/chi/v5"
|
||||||
)
|
)
|
||||||
|
|
||||||
// maxPackagePathLen bounds the wildcard portion of package routes (name plus
|
// maxPackagePathLen bounds the wildcard portion of package routes (name plus
|
||||||
|
|
@ -13,17 +16,62 @@ import (
|
||||||
// longer, so 512 leaves room without admitting pathological inputs.
|
// longer, so 512 leaves room without admitting pathological inputs.
|
||||||
const maxPackagePathLen = 512
|
const maxPackagePathLen = 512
|
||||||
|
|
||||||
|
// packagePathSegments validates the wildcard portion of a package route and
|
||||||
|
// splits it into decoded path segments.
|
||||||
|
func packagePathSegments(r *http.Request) ([]string, error) {
|
||||||
|
wildcard := chi.URLParam(r, "*")
|
||||||
|
encoded := wildcardIsEncoded(r)
|
||||||
|
if err := validatePackagePath(wildcard, encoded); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
return splitWildcardPath(wildcard, encoded), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// wildcardIsEncoded reports whether the chi wildcard for this request is still
|
||||||
|
// percent-encoded.
|
||||||
|
//
|
||||||
|
// chi routes on r.URL.RawPath when it is set and on r.URL.Path otherwise, and
|
||||||
|
// net/url only sets RawPath when the request's escaping differs from the
|
||||||
|
// canonical encoding of the decoded path. A version such as "release%2F1" is
|
||||||
|
// therefore routed raw, while "1.0%252B" (a version whose text contains a
|
||||||
|
// literal "%2B") encodes canonically and arrives already decoded once. The
|
||||||
|
// distinction decides whether the segments still need decoding: decoding the
|
||||||
|
// second case again would turn it into "1.0+" and resolve a different version.
|
||||||
|
func wildcardIsEncoded(r *http.Request) bool {
|
||||||
|
return r.URL.RawPath != ""
|
||||||
|
}
|
||||||
|
|
||||||
// validatePackagePath rejects wildcard package paths that cannot be valid in
|
// validatePackagePath rejects wildcard package paths that cannot be valid in
|
||||||
// any supported ecosystem. It is a coarse filter applied before database or
|
// any supported ecosystem. It is a coarse filter applied before database or
|
||||||
// enrichment lookups; ecosystem-specific name rules are layered on top.
|
// enrichment lookups; ecosystem-specific name rules are layered on top.
|
||||||
func validatePackagePath(path string) error {
|
//
|
||||||
|
// encoded has the meaning described on wildcardIsEncoded.
|
||||||
|
func validatePackagePath(path string, encoded bool) error {
|
||||||
if path == "" {
|
if path == "" {
|
||||||
return fmt.Errorf("package name required")
|
return fmt.Errorf("package name required")
|
||||||
}
|
}
|
||||||
if len(path) > maxPackagePathLen {
|
if len(path) > maxPackagePathLen {
|
||||||
return fmt.Errorf("package path exceeds %d bytes", maxPackagePathLen)
|
return fmt.Errorf("package path exceeds %d bytes", maxPackagePathLen)
|
||||||
}
|
}
|
||||||
for _, r := range path {
|
// Validate the decoded segments: the handlers work with decoded values, so
|
||||||
|
// an escape such as "%00" or "%2E%2E" must not slip past these checks.
|
||||||
|
for _, seg := range splitWildcardPath(path, encoded) {
|
||||||
|
// Each segment is checked both as the handlers see it and decoded once
|
||||||
|
// more: a segment can reach a handler with escapes intact, and the
|
||||||
|
// upstream registry is then the one that decodes them.
|
||||||
|
for _, value := range []string{seg, decodePathSegment(seg)} {
|
||||||
|
// A decoded segment can itself contain slashes (from "%2F"), and
|
||||||
|
// the segments are later rejoined into a package name that
|
||||||
|
// registries interpolate straight into an upstream URL. Check every
|
||||||
|
// path element, not just the segment as a whole, or
|
||||||
|
// "a%2F..%2F..%2Fb" traverses.
|
||||||
|
for _, elem := range strings.Split(value, "/") {
|
||||||
|
if elem == ".." {
|
||||||
|
return fmt.Errorf("package path contains parent directory segment")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for _, r := range value {
|
||||||
if r == 0 {
|
if r == 0 {
|
||||||
return fmt.Errorf("package path contains null byte")
|
return fmt.Errorf("package path contains null byte")
|
||||||
}
|
}
|
||||||
|
|
@ -31,6 +79,8 @@ func validatePackagePath(path string) error {
|
||||||
return fmt.Errorf("package path contains control character %#U", r)
|
return fmt.Errorf("package path contains control character %#U", r)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -60,10 +110,37 @@ func resolvePackageName(db *database.DB, ecosystem string, segments []string) (n
|
||||||
|
|
||||||
// splitWildcardPath splits a chi wildcard path value into segments,
|
// splitWildcardPath splits a chi wildcard path value into segments,
|
||||||
// trimming any leading/trailing slashes.
|
// trimming any leading/trailing slashes.
|
||||||
func splitWildcardPath(path string) []string {
|
//
|
||||||
|
// When encoded is set the value is still percent-encoded (see
|
||||||
|
// wildcardIsEncoded), so each segment is decoded after splitting. Splitting
|
||||||
|
// first keeps an encoded "%2F" inside a name from being mistaken for a
|
||||||
|
// separator. Decoding matters for versions such as "1.0%2Bbuild1", which must
|
||||||
|
// reach the handlers as "1.0+build1" so that rebuilding the PURL yields the
|
||||||
|
// value that was stored rather than a double-encoded one.
|
||||||
|
func splitWildcardPath(path string, encoded bool) []string {
|
||||||
path = strings.Trim(path, "/")
|
path = strings.Trim(path, "/")
|
||||||
if path == "" {
|
if path == "" {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
return strings.Split(path, "/")
|
segments := strings.Split(path, "/")
|
||||||
|
if !encoded {
|
||||||
|
return segments
|
||||||
|
}
|
||||||
|
for i, seg := range segments {
|
||||||
|
segments[i] = decodePathSegment(seg)
|
||||||
|
}
|
||||||
|
return segments
|
||||||
|
}
|
||||||
|
|
||||||
|
// decodePathSegment percent-decodes a single URL path segment, returning it
|
||||||
|
// unchanged if it is not valid percent-encoding.
|
||||||
|
func decodePathSegment(seg string) string {
|
||||||
|
if !strings.Contains(seg, "%") {
|
||||||
|
return seg
|
||||||
|
}
|
||||||
|
decoded, err := url.PathUnescape(seg)
|
||||||
|
if err != nil {
|
||||||
|
return seg
|
||||||
|
}
|
||||||
|
return decoded
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,12 +1,15 @@
|
||||||
package server
|
package server
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
"github.com/git-pkgs/proxy/internal/database"
|
||||||
|
"github.com/go-chi/chi/v5"
|
||||||
)
|
)
|
||||||
|
|
||||||
func newTestDB(t *testing.T) (*database.DB, func()) {
|
func newTestDB(t *testing.T) (*database.DB, func()) {
|
||||||
|
|
@ -96,25 +99,43 @@ func TestResolvePackageName(t *testing.T) {
|
||||||
func TestSplitWildcardPath(t *testing.T) {
|
func TestSplitWildcardPath(t *testing.T) {
|
||||||
tests := []struct {
|
tests := []struct {
|
||||||
input string
|
input string
|
||||||
|
encoded bool
|
||||||
want []string
|
want []string
|
||||||
}{
|
}{
|
||||||
{"lodash", []string{"lodash"}},
|
{"lodash", false, []string{"lodash"}},
|
||||||
{"lodash/4.17.21", []string{"lodash", "4.17.21"}},
|
{"lodash/4.17.21", false, []string{"lodash", "4.17.21"}},
|
||||||
{"monolog/monolog", []string{"monolog", "monolog"}},
|
{"monolog/monolog", false, []string{"monolog", "monolog"}},
|
||||||
{"symfony/console/6.0.0/browse", []string{"symfony", "console", "6.0.0", "browse"}},
|
{"symfony/console/6.0.0/browse", false, []string{"symfony", "console", "6.0.0", "browse"}},
|
||||||
{"", nil},
|
{"", false, nil},
|
||||||
{"/", nil},
|
{"/", false, nil},
|
||||||
|
// chi routes on the raw path when it differs from the canonical
|
||||||
|
// encoding of the decoded path, so segments arrive percent-encoded and
|
||||||
|
// must be decoded.
|
||||||
|
{
|
||||||
|
"nmap/7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1", true,
|
||||||
|
[]string{"nmap", "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"},
|
||||||
|
},
|
||||||
|
{"%40babel/core/7.0.0", true, []string{"@babel", "core", "7.0.0"}},
|
||||||
|
// An encoded separator stays inside its segment rather than splitting.
|
||||||
|
{"vendor%2Fname/1.0.0", true, []string{"vendor/name", "1.0.0"}},
|
||||||
|
// Invalid escapes are passed through untouched.
|
||||||
|
{"lodash/1.0%zz", true, []string{"lodash", "1.0%zz"}},
|
||||||
|
// When chi routed on the already-decoded path, an escape that survived
|
||||||
|
// is part of the value: a version whose text is "1.0%2B" reaches here
|
||||||
|
// as "1.0%2B" and decoding it again would yield "1.0+".
|
||||||
|
{"nmap/1.0%2B", false, []string{"nmap", "1.0%2B"}},
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range tests {
|
for _, tt := range tests {
|
||||||
got := splitWildcardPath(tt.input)
|
got := splitWildcardPath(tt.input, tt.encoded)
|
||||||
if len(got) != len(tt.want) {
|
if len(got) != len(tt.want) {
|
||||||
t.Errorf("splitWildcardPath(%q) = %v, want %v", tt.input, got, tt.want)
|
t.Errorf("splitWildcardPath(%q, %v) = %v, want %v", tt.input, tt.encoded, got, tt.want)
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
for i := range got {
|
for i := range got {
|
||||||
if got[i] != tt.want[i] {
|
if got[i] != tt.want[i] {
|
||||||
t.Errorf("splitWildcardPath(%q)[%d] = %q, want %q", tt.input, i, got[i], tt.want[i])
|
t.Errorf("splitWildcardPath(%q, %v)[%d] = %q, want %q",
|
||||||
|
tt.input, tt.encoded, i, got[i], tt.want[i])
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -132,8 +153,19 @@ func TestValidatePackagePath(t *testing.T) {
|
||||||
{"composer namespaced", "symfony/console/6.0.0", false},
|
{"composer namespaced", "symfony/console/6.0.0", false},
|
||||||
{"maven coordinates", "org.apache.commons/commons-lang3/3.12.0", false},
|
{"maven coordinates", "org.apache.commons/commons-lang3/3.12.0", false},
|
||||||
{"unicode", "café/1.0.0", false},
|
{"unicode", "café/1.0.0", false},
|
||||||
|
{"encoded plus in version", "nmap/7.91%2Bdfsg1-2ubuntu0.1", false},
|
||||||
{"empty", "", true},
|
{"empty", "", true},
|
||||||
{"null byte", "lodash\x00/4.17.21", true},
|
{"null byte", "lodash\x00/4.17.21", true},
|
||||||
|
{"encoded null byte", "lodash/%00", true},
|
||||||
|
{"encoded newline", "lodash/1.0%0A", true},
|
||||||
|
{"parent segment", "lodash/../4.17.21", true},
|
||||||
|
{"encoded parent segment", "lodash/%2E%2E/4.17.21", true},
|
||||||
|
// A decoded segment can contain slashes, so traversal can hide inside
|
||||||
|
// one segment. Registries interpolate the resolved name straight into
|
||||||
|
// an upstream URL, and Go sends dot-segments verbatim.
|
||||||
|
{"traversal inside one segment", "pkg%2F..%2F..%2Fadmin", true},
|
||||||
|
{"traversal via encoded dots and slash", "pkg%2f%2e%2e%2fadmin", true},
|
||||||
|
{"encoded slash alone is allowed", "vendor%2Fname/1.0.0", false},
|
||||||
{"null byte suffix", "lodash\x00", true},
|
{"null byte suffix", "lodash\x00", true},
|
||||||
{"newline", "lodash\n4.17.21", true},
|
{"newline", "lodash\n4.17.21", true},
|
||||||
{"carriage return", "lodash\r", true},
|
{"carriage return", "lodash\r", true},
|
||||||
|
|
@ -145,9 +177,64 @@ func TestValidatePackagePath(t *testing.T) {
|
||||||
|
|
||||||
for _, tt := range tests {
|
for _, tt := range tests {
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
err := validatePackagePath(tt.path)
|
// The verdict must not depend on whether chi routed on the raw or
|
||||||
|
// on the already-decoded path: an escape that reaches a handler
|
||||||
|
// undecoded is decoded by the upstream registry instead, so it is
|
||||||
|
// rejected either way.
|
||||||
|
for _, encoded := range []bool{false, true} {
|
||||||
|
err := validatePackagePath(tt.path, encoded)
|
||||||
if (err != nil) != tt.wantErr {
|
if (err != nil) != tt.wantErr {
|
||||||
t.Errorf("validatePackagePath(%q) error = %v, wantErr %v", tt.path, err, tt.wantErr)
|
t.Errorf("validatePackagePath(%q, %v) error = %v, wantErr %v",
|
||||||
|
tt.path, encoded, err, tt.wantErr)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestPackagePathSegments drives the real router, which is what decides whether
|
||||||
|
// the wildcard still carries percent-encoding. Go decodes the request path
|
||||||
|
// itself unless the escaping is non-canonical, so the same version can arrive
|
||||||
|
// either way and only one of the two forms may be decoded again.
|
||||||
|
func TestPackagePathSegments(t *testing.T) {
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
target string
|
||||||
|
want []string
|
||||||
|
}{
|
||||||
|
{"plain", "/pkg/npm/lodash/4.17.21", []string{"lodash", "4.17.21"}},
|
||||||
|
{"encoded plus", "/pkg/deb/nmap/7.91%2Bdfsg1-2ubuntu0.1", []string{"nmap", "7.91+dfsg1-2ubuntu0.1"}},
|
||||||
|
{"decoded plus", "/pkg/deb/nmap/7.91+dfsg1-2ubuntu0.1", []string{"nmap", "7.91+dfsg1-2ubuntu0.1"}},
|
||||||
|
// An encoded slash is one segment, not a separator.
|
||||||
|
{"encoded slash", "/pkg/composer/vendor%2Fname/1.0.0", []string{"vendor/name", "1.0.0"}},
|
||||||
|
{"question mark", "/pkg/npm/example/v1%3Fbuild", []string{"example", "v1?build"}},
|
||||||
|
// "1.0%252B" is the escaped form of the version "1.0%2B"; net/url
|
||||||
|
// already decoded it once, so it must not be decoded again.
|
||||||
|
{"literal percent escape", "/pkg/npm/example/1.0%252B", []string{"example", "1.0%2B"}},
|
||||||
|
{"browse suffix", "/pkg/deb/nmap/7.91%2Bdfsg1/browse", []string{"nmap", "7.91+dfsg1", "browse"}},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
var got []string
|
||||||
|
var gotErr error
|
||||||
|
|
||||||
|
router := chi.NewRouter()
|
||||||
|
router.Get("/pkg/{ecosystem}/*", func(_ http.ResponseWriter, r *http.Request) {
|
||||||
|
got, gotErr = packagePathSegments(r)
|
||||||
|
})
|
||||||
|
router.ServeHTTP(httptest.NewRecorder(), httptest.NewRequest("GET", tt.target, nil))
|
||||||
|
|
||||||
|
if gotErr != nil {
|
||||||
|
t.Fatalf("packagePathSegments(%q) failed: %v", tt.target, gotErr)
|
||||||
|
}
|
||||||
|
if len(got) != len(tt.want) {
|
||||||
|
t.Fatalf("segments for %q = %v, want %v", tt.target, got, tt.want)
|
||||||
|
}
|
||||||
|
for i := range got {
|
||||||
|
if got[i] != tt.want[i] {
|
||||||
|
t.Errorf("segments for %q [%d] = %q, want %q", tt.target, i, got[i], tt.want[i])
|
||||||
|
}
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -54,21 +54,25 @@ import (
|
||||||
"fmt"
|
"fmt"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
|
"net/url"
|
||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
swaggerdoc "github.com/git-pkgs/proxy/docs/swagger"
|
|
||||||
"github.com/git-pkgs/proxy/internal/config"
|
|
||||||
"github.com/git-pkgs/cooldown"
|
"github.com/git-pkgs/cooldown"
|
||||||
|
swaggerdoc "github.com/git-pkgs/proxy/docs/swagger"
|
||||||
|
"github.com/git-pkgs/proxy/internal/accesslog"
|
||||||
|
"github.com/git-pkgs/proxy/internal/config"
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
"github.com/git-pkgs/proxy/internal/database"
|
||||||
"github.com/git-pkgs/proxy/internal/enrichment"
|
"github.com/git-pkgs/proxy/internal/enrichment"
|
||||||
"github.com/git-pkgs/proxy/internal/handler"
|
"github.com/git-pkgs/proxy/internal/handler"
|
||||||
|
upstreamhttp "github.com/git-pkgs/proxy/internal/httpclient"
|
||||||
"github.com/git-pkgs/proxy/internal/metrics"
|
"github.com/git-pkgs/proxy/internal/metrics"
|
||||||
"github.com/git-pkgs/proxy/internal/mirror"
|
"github.com/git-pkgs/proxy/internal/mirror"
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
"github.com/git-pkgs/proxy/internal/storage"
|
||||||
"github.com/git-pkgs/purl"
|
"github.com/git-pkgs/purl"
|
||||||
"github.com/git-pkgs/registries/fetch"
|
"github.com/git-pkgs/registries/fetch"
|
||||||
|
"github.com/git-pkgs/registries/safehttp"
|
||||||
"github.com/git-pkgs/spdx"
|
"github.com/git-pkgs/spdx"
|
||||||
"github.com/go-chi/chi/v5"
|
"github.com/go-chi/chi/v5"
|
||||||
"github.com/go-chi/chi/v5/middleware"
|
"github.com/go-chi/chi/v5/middleware"
|
||||||
|
|
@ -88,14 +92,31 @@ type Server struct {
|
||||||
db *database.DB
|
db *database.DB
|
||||||
storage storage.Storage
|
storage storage.Storage
|
||||||
logger *slog.Logger
|
logger *slog.Logger
|
||||||
|
buildInfo BuildInfo
|
||||||
http *http.Server
|
http *http.Server
|
||||||
templates *Templates
|
templates *Templates
|
||||||
cancel context.CancelFunc
|
cancel context.CancelFunc
|
||||||
healthCache *healthCache
|
healthCache *healthCache
|
||||||
|
accessLog *accesslog.Logger
|
||||||
}
|
}
|
||||||
|
|
||||||
// New creates a new Server with the given configuration.
|
// New creates a new Server with the given configuration.
|
||||||
func New(cfg *config.Config, logger *slog.Logger) (*Server, error) {
|
func New(cfg *config.Config, logger *slog.Logger, buildInfo BuildInfo) (*Server, error) {
|
||||||
|
var activityLog *accesslog.Logger
|
||||||
|
if cfg.AccessLog.Path != "" {
|
||||||
|
var err error
|
||||||
|
activityLog, err = accesslog.Open(cfg.AccessLog.Path)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("initializing access log: %w", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
closeAccessLog := true
|
||||||
|
defer func() {
|
||||||
|
if closeAccessLog && activityLog != nil {
|
||||||
|
_ = activityLog.Close()
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
|
||||||
// Initialize database
|
// Initialize database
|
||||||
var db *database.DB
|
var db *database.DB
|
||||||
var err error
|
var err error
|
||||||
|
|
@ -144,20 +165,38 @@ func New(cfg *config.Config, logger *slog.Logger) (*Server, error) {
|
||||||
return nil, fmt.Errorf("initializing health cache: %w", err)
|
return nil, fmt.Errorf("initializing health cache: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
return &Server{
|
server := &Server{
|
||||||
cfg: cfg,
|
cfg: cfg,
|
||||||
db: db,
|
db: db,
|
||||||
storage: store,
|
storage: store,
|
||||||
logger: logger,
|
logger: logger,
|
||||||
|
buildInfo: buildInfo,
|
||||||
templates: &Templates{},
|
templates: &Templates{},
|
||||||
healthCache: hc,
|
healthCache: hc,
|
||||||
}, nil
|
accessLog: activityLog,
|
||||||
|
}
|
||||||
|
closeAccessLog = false
|
||||||
|
return server, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// Start starts the HTTP server.
|
// Start starts the HTTP server.
|
||||||
func (s *Server) Start() error {
|
func (s *Server) Start() error {
|
||||||
// Create shared components with circuit breaker
|
// Use one authentication-aware transport for metadata and artifacts so
|
||||||
baseFetcher := fetch.NewFetcher(fetch.WithAuthFunc(s.authForURL))
|
// configured credentials and cached OCI challenges apply consistently.
|
||||||
|
safeClient := safehttp.New(nil, safehttp.Options{})
|
||||||
|
baseTransport := safeClient.Transport
|
||||||
|
if s.accessLog != nil {
|
||||||
|
baseTransport = upstreamhttp.NewAccessLogTransport(baseTransport, s.accessLog, s.logger)
|
||||||
|
}
|
||||||
|
authTransport := upstreamhttp.NewTransport(baseTransport, upstreamhttp.AuthFunc(s.authForURL))
|
||||||
|
metadataClient := *safeClient
|
||||||
|
metadataClient.Timeout = s.cfg.ParseHTTPTimeout()
|
||||||
|
metadataClient.Transport = authTransport
|
||||||
|
artifactClient := metadataClient
|
||||||
|
artifactClient.Timeout = serverWriteTimeout
|
||||||
|
|
||||||
|
// Create shared components with circuit breaker.
|
||||||
|
baseFetcher := fetch.NewFetcher(fetch.WithHTTPClient(&artifactClient))
|
||||||
fetcher := fetch.NewCircuitBreakerFetcher(baseFetcher)
|
fetcher := fetch.NewCircuitBreakerFetcher(baseFetcher)
|
||||||
resolver := fetch.NewResolver()
|
resolver := fetch.NewResolver()
|
||||||
cd := &cooldown.Config{
|
cd := &cooldown.Config{
|
||||||
|
|
@ -166,7 +205,7 @@ func (s *Server) Start() error {
|
||||||
Packages: s.cfg.Cooldown.NormalizedPackages(),
|
Packages: s.cfg.Cooldown.NormalizedPackages(),
|
||||||
}
|
}
|
||||||
proxy := handler.NewProxy(s.db, s.storage, fetcher, resolver, s.logger)
|
proxy := handler.NewProxy(s.db, s.storage, fetcher, resolver, s.logger)
|
||||||
proxy.HTTPClient.Timeout = s.cfg.ParseHTTPTimeout()
|
proxy.HTTPClient = &metadataClient
|
||||||
proxy.AuthForURL = s.authForURL
|
proxy.AuthForURL = s.authForURL
|
||||||
proxy.Cooldown = cd
|
proxy.Cooldown = cd
|
||||||
proxy.CacheMetadata = s.cfg.CacheMetadata
|
proxy.CacheMetadata = s.cfg.CacheMetadata
|
||||||
|
|
@ -222,7 +261,8 @@ func (s *Server) Start() error {
|
||||||
condaHandler := handler.NewCondaHandler(proxy, s.cfg.BaseURL)
|
condaHandler := handler.NewCondaHandler(proxy, s.cfg.BaseURL)
|
||||||
cranHandler := handler.NewCRANHandler(proxy, s.cfg.BaseURL)
|
cranHandler := handler.NewCRANHandler(proxy, s.cfg.BaseURL)
|
||||||
juliaHandler := handler.NewJuliaHandler(proxy, s.cfg.BaseURL)
|
juliaHandler := handler.NewJuliaHandler(proxy, s.cfg.BaseURL)
|
||||||
containerHandler := handler.NewContainerHandler(proxy, s.cfg.BaseURL)
|
containerHandler := handler.NewContainerHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.OCI)
|
||||||
|
helmHandler := handler.NewHelmHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.Helm)
|
||||||
debianHandler := handler.NewDebianHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.Debian)
|
debianHandler := handler.NewDebianHandler(proxy, s.cfg.BaseURL, s.cfg.Upstream.Debian)
|
||||||
rpmHandler := handler.NewRPMHandler(proxy, s.cfg.BaseURL)
|
rpmHandler := handler.NewRPMHandler(proxy, s.cfg.BaseURL)
|
||||||
|
|
||||||
|
|
@ -242,6 +282,7 @@ func (s *Server) Start() error {
|
||||||
r.Mount("/cran", http.StripPrefix("/cran", cranHandler.Routes()))
|
r.Mount("/cran", http.StripPrefix("/cran", cranHandler.Routes()))
|
||||||
r.Mount("/julia", http.StripPrefix("/julia", juliaHandler.Routes()))
|
r.Mount("/julia", http.StripPrefix("/julia", juliaHandler.Routes()))
|
||||||
r.Mount("/v2", http.StripPrefix("/v2", containerHandler.Routes()))
|
r.Mount("/v2", http.StripPrefix("/v2", containerHandler.Routes()))
|
||||||
|
r.Mount("/helm", http.StripPrefix("/helm", helmHandler.Routes()))
|
||||||
r.Mount("/debian", http.StripPrefix("/debian", debianHandler.Routes()))
|
r.Mount("/debian", http.StripPrefix("/debian", debianHandler.Routes()))
|
||||||
r.Mount("/rpm", http.StripPrefix("/rpm", rpmHandler.Routes()))
|
r.Mount("/rpm", http.StripPrefix("/rpm", rpmHandler.Routes()))
|
||||||
|
|
||||||
|
|
@ -360,6 +401,12 @@ func (s *Server) Shutdown(ctx context.Context) error {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if s.accessLog != nil {
|
||||||
|
if err := s.accessLog.Close(); err != nil {
|
||||||
|
errs = append(errs, fmt.Errorf("access log close: %w", err))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if s.db != nil {
|
if s.db != nil {
|
||||||
if err := s.db.Close(); err != nil {
|
if err := s.db.Close(); err != nil {
|
||||||
errs = append(errs, fmt.Errorf("database close: %w", err))
|
errs = append(errs, fmt.Errorf("database close: %w", err))
|
||||||
|
|
@ -668,12 +715,11 @@ func (s *Server) handlePackagesList(w http.ResponseWriter, r *http.Request) {
|
||||||
// {name}/compare/{v1}...{v2} -> compare versions
|
// {name}/compare/{v1}...{v2} -> compare versions
|
||||||
func (s *Server) handlePackagePath(w http.ResponseWriter, r *http.Request) {
|
func (s *Server) handlePackagePath(w http.ResponseWriter, r *http.Request) {
|
||||||
ecosystem := chi.URLParam(r, "ecosystem")
|
ecosystem := chi.URLParam(r, "ecosystem")
|
||||||
wildcard := chi.URLParam(r, "*")
|
segments, err := packagePathSegments(r)
|
||||||
if err := validatePackagePath(wildcard); err != nil {
|
if err != nil {
|
||||||
http.Error(w, err.Error(), http.StatusBadRequest)
|
http.Error(w, err.Error(), http.StatusBadRequest)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
segments := splitWildcardPath(wildcard)
|
|
||||||
|
|
||||||
if ecosystem == "" || len(segments) == 0 {
|
if ecosystem == "" || len(segments) == 0 {
|
||||||
http.Error(w, "ecosystem and package name required", http.StatusBadRequest)
|
http.Error(w, "ecosystem and package name required", http.StatusBadRequest)
|
||||||
|
|
@ -817,6 +863,7 @@ func (s *Server) showBrowseSource(w http.ResponseWriter, r *http.Request, ecosys
|
||||||
Ecosystem: ecosystem,
|
Ecosystem: ecosystem,
|
||||||
PackageName: name,
|
PackageName: name,
|
||||||
Version: version,
|
Version: version,
|
||||||
|
EscapedVersion: url.PathEscape(version),
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := s.templates.Render(w, "browse_source", data); err != nil {
|
if err := s.templates.Render(w, "browse_source", data); err != nil {
|
||||||
|
|
@ -839,6 +886,8 @@ func (s *Server) showComparePage(w http.ResponseWriter, r *http.Request, ecosyst
|
||||||
PackageName: name,
|
PackageName: name,
|
||||||
FromVersion: parts[0],
|
FromVersion: parts[0],
|
||||||
ToVersion: parts[1],
|
ToVersion: parts[1],
|
||||||
|
EscapedFromVersion: url.PathEscape(parts[0]),
|
||||||
|
EscapedToVersion: url.PathEscape(parts[1]),
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := s.templates.Render(w, "compare_versions", data); err != nil {
|
if err := s.templates.Render(w, "compare_versions", data); err != nil {
|
||||||
|
|
|
||||||
|
|
@ -1,15 +1,20 @@
|
||||||
package server
|
package server
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"database/sql"
|
"database/sql"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"html"
|
||||||
"io"
|
"io"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
|
"net/url"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
|
"regexp"
|
||||||
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
|
|
@ -18,6 +23,7 @@ import (
|
||||||
"github.com/git-pkgs/proxy/internal/database"
|
"github.com/git-pkgs/proxy/internal/database"
|
||||||
"github.com/git-pkgs/proxy/internal/handler"
|
"github.com/git-pkgs/proxy/internal/handler"
|
||||||
"github.com/git-pkgs/proxy/internal/storage"
|
"github.com/git-pkgs/proxy/internal/storage"
|
||||||
|
"github.com/git-pkgs/purl"
|
||||||
"github.com/git-pkgs/registries/fetch"
|
"github.com/git-pkgs/registries/fetch"
|
||||||
"github.com/go-chi/chi/v5"
|
"github.com/go-chi/chi/v5"
|
||||||
)
|
)
|
||||||
|
|
@ -46,7 +52,7 @@ func newTestServer(t *testing.T) *testServer {
|
||||||
t.Fatalf("failed to create database: %v", err)
|
t.Fatalf("failed to create database: %v", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
store, err := storage.NewFilesystem(storagePath)
|
store, err := storage.OpenBucket(context.Background(), "file://"+storagePath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
_ = db.Close()
|
_ = db.Close()
|
||||||
_ = os.RemoveAll(tempDir)
|
_ = os.RemoveAll(tempDir)
|
||||||
|
|
@ -60,7 +66,7 @@ func newTestServer(t *testing.T) *testServer {
|
||||||
|
|
||||||
cfg := &config.Config{
|
cfg := &config.Config{
|
||||||
BaseURL: "http://localhost:8080",
|
BaseURL: "http://localhost:8080",
|
||||||
Storage: config.StorageConfig{Path: storagePath},
|
Storage: config.StorageConfig{URL: "file://" + storagePath},
|
||||||
Database: config.DatabaseConfig{Path: dbPath},
|
Database: config.DatabaseConfig{Path: dbPath},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -99,6 +105,7 @@ func newTestServer(t *testing.T) *testServer {
|
||||||
db: db,
|
db: db,
|
||||||
storage: store,
|
storage: store,
|
||||||
logger: logger,
|
logger: logger,
|
||||||
|
buildInfo: BuildInfo{Version: "test-version", Commit: "test-commit"},
|
||||||
templates: &Templates{},
|
templates: &Templates{},
|
||||||
healthCache: hc,
|
healthCache: hc,
|
||||||
}
|
}
|
||||||
|
|
@ -308,6 +315,9 @@ func TestDashboard(t *testing.T) {
|
||||||
if !strings.Contains(body, "Cached Artifacts") {
|
if !strings.Contains(body, "Cached Artifacts") {
|
||||||
t.Error("dashboard should contain stats")
|
t.Error("dashboard should contain stats")
|
||||||
}
|
}
|
||||||
|
if !strings.Contains(body, "proxy test-version (test-commit)") {
|
||||||
|
t.Error("dashboard footer should contain build information")
|
||||||
|
}
|
||||||
if !strings.Contains(body, "Popular Packages") {
|
if !strings.Contains(body, "Popular Packages") {
|
||||||
t.Error("dashboard should contain popular packages section")
|
t.Error("dashboard should contain popular packages section")
|
||||||
}
|
}
|
||||||
|
|
@ -593,6 +603,9 @@ func TestVersionShowWithHitCount(t *testing.T) {
|
||||||
if !strings.Contains(body, "42 cache hits") {
|
if !strings.Contains(body, "42 cache hits") {
|
||||||
t.Error("expected page to show hit count")
|
t.Error("expected page to show hit count")
|
||||||
}
|
}
|
||||||
|
if !strings.Contains(body, "proxy test-version (test-commit)") {
|
||||||
|
t.Error("version show footer should contain proxy build information, not the package version")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestSearchWithNullValues(t *testing.T) {
|
func TestSearchWithNullValues(t *testing.T) {
|
||||||
|
|
@ -764,6 +777,236 @@ func TestVersionShowPage_NotFoundServer(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TestVersionShowPage_PlusInVersion covers Debian/Ubuntu style versions such as
|
||||||
|
// nmap's "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1". PURL percent-encodes "+" as
|
||||||
|
// "%2B", so the UI must show the decoded version and resolve both the decoded
|
||||||
|
// and the still-encoded form of the URL back to the same version.
|
||||||
|
func TestVersionShowPage_PlusInVersion(t *testing.T) {
|
||||||
|
ts := newTestServer(t)
|
||||||
|
defer ts.close()
|
||||||
|
|
||||||
|
const version = "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1"
|
||||||
|
const versionPURL = "pkg:deb/nmap@7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1"
|
||||||
|
|
||||||
|
pkg := &database.Package{PURL: "pkg:deb/nmap", Ecosystem: "deb", Name: "nmap"}
|
||||||
|
if err := ts.db.UpsertPackage(pkg); err != nil {
|
||||||
|
t.Fatalf("failed to upsert package: %v", err)
|
||||||
|
}
|
||||||
|
if err := ts.db.UpsertVersion(&database.Version{
|
||||||
|
PURL: versionPURL, PackagePURL: pkg.PURL,
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("failed to upsert version: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// The package page must link to and display the decoded version.
|
||||||
|
req := httptest.NewRequest("GET", "/ui/package/deb/nmap", nil)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
ts.handler.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Fatalf("package page: expected status 200, got %d", w.Code)
|
||||||
|
}
|
||||||
|
body := w.Body.String()
|
||||||
|
if strings.Contains(body, "%2B") {
|
||||||
|
t.Error("package page leaks PURL percent-encoding into the UI")
|
||||||
|
}
|
||||||
|
// html/template renders "+" as the "+" entity inside attributes and text.
|
||||||
|
if !strings.Contains(body, "7.91+dfsg1+really7.80+dfsg1-2ubuntu0.1") {
|
||||||
|
t.Error("expected package page to show the decoded version")
|
||||||
|
}
|
||||||
|
|
||||||
|
// Both the decoded and the encoded URL must reach the version page.
|
||||||
|
for _, path := range []string{
|
||||||
|
"/ui/package/deb/nmap/" + version,
|
||||||
|
"/ui/package/deb/nmap/7.91%2Bdfsg1%2Breally7.80%2Bdfsg1-2ubuntu0.1",
|
||||||
|
} {
|
||||||
|
req := httptest.NewRequest("GET", path, nil)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
ts.handler.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Errorf("GET %s: expected status 200, got %d", path, w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestVersionURLEscaping covers versions whose characters are significant in a
|
||||||
|
// URL path: "/" splits off another path segment, "?" starts a query string, and
|
||||||
|
// a literal "%xx" is read back as the character it encodes. The pages show the
|
||||||
|
// decoded version but must build every link from a separately escaped value,
|
||||||
|
// and those links have to resolve back to the same version.
|
||||||
|
func TestVersionURLEscaping(t *testing.T) {
|
||||||
|
// A second version is needed for the compare controls to be rendered.
|
||||||
|
const otherVersion = "1.0.0"
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
version string
|
||||||
|
}{
|
||||||
|
{"slash", "release/1"},
|
||||||
|
{"question mark", "v1?build"},
|
||||||
|
{"literal percent escape", "1.0%2B"},
|
||||||
|
{"plus", "7.91+dfsg1-2ubuntu0.1"},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
ts := newTestServer(t)
|
||||||
|
defer ts.close()
|
||||||
|
seedEscapingVersions(t, ts.db, tt.version, otherVersion)
|
||||||
|
|
||||||
|
// The package page links to the escaped version.
|
||||||
|
escaped := url.PathEscape(tt.version)
|
||||||
|
versionPath := "/ui/package/deb/nmap/" + escaped
|
||||||
|
packagePage := ts.getOK(t, "/ui/package/deb/nmap")
|
||||||
|
if !containsValue(attrValues(packagePage, "href"), versionPath) {
|
||||||
|
t.Fatalf("package page has no link to %q; hrefs: %v",
|
||||||
|
versionPath, attrValues(packagePage, "href"))
|
||||||
|
}
|
||||||
|
|
||||||
|
ts.checkVersionAndBrowsePages(t, versionPath, tt.version, escaped)
|
||||||
|
ts.checkComparePage(t, packagePage, tt.version, escaped, otherVersion)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// seedEscapingVersions stores a Debian package with the given versions, each
|
||||||
|
// with a cached artifact so that the version page offers its browse link.
|
||||||
|
func seedEscapingVersions(t *testing.T, db *database.DB, versions ...string) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
pkg := &database.Package{PURL: "pkg:deb/nmap", Ecosystem: "deb", Name: "nmap"}
|
||||||
|
if err := db.UpsertPackage(pkg); err != nil {
|
||||||
|
t.Fatalf("failed to upsert package: %v", err)
|
||||||
|
}
|
||||||
|
for _, v := range versions {
|
||||||
|
versionPURL := purl.MakePURLString("deb", "nmap", v)
|
||||||
|
if err := db.UpsertVersion(&database.Version{
|
||||||
|
PURL: versionPURL, PackagePURL: pkg.PURL,
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("failed to upsert version %q: %v", v, err)
|
||||||
|
}
|
||||||
|
if err := db.UpsertArtifact(&database.Artifact{
|
||||||
|
VersionPURL: versionPURL,
|
||||||
|
Filename: "nmap.deb",
|
||||||
|
UpstreamURL: "http://archive.ubuntu.com/ubuntu/pool/universe/n/nmap/nmap.deb",
|
||||||
|
StoragePath: sql.NullString{String: "/cache/nmap.deb", Valid: true},
|
||||||
|
FetchedAt: sql.NullTime{Time: time.Now(), Valid: true},
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("failed to upsert artifact for %q: %v", v, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// checkVersionAndBrowsePages follows a version link from the package page and
|
||||||
|
// then the browse link from the version page, checking that both resolve to the
|
||||||
|
// stored version and display it decoded.
|
||||||
|
func (ts *testServer) checkVersionAndBrowsePages(t *testing.T, versionPath, version, escaped string) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
versionPage := ts.getOK(t, versionPath)
|
||||||
|
wantPURL := "pkg:deb/nmap@" + version
|
||||||
|
if !strings.Contains(html.UnescapeString(versionPage), wantPURL) {
|
||||||
|
t.Errorf("version page does not show %q", wantPURL)
|
||||||
|
}
|
||||||
|
|
||||||
|
browsePath := versionPath + "/browse"
|
||||||
|
if !containsValue(attrValues(versionPage, "href"), browsePath) {
|
||||||
|
t.Fatalf("version page has no browse link to %q; hrefs: %v",
|
||||||
|
browsePath, attrValues(versionPage, "href"))
|
||||||
|
}
|
||||||
|
|
||||||
|
browsePage := ts.getOK(t, browsePath)
|
||||||
|
if !strings.Contains(html.UnescapeString(browsePage), "nmap@"+version) {
|
||||||
|
t.Errorf("browse page does not show the decoded version %q", version)
|
||||||
|
}
|
||||||
|
// The browse API is called with the escaped version, not with the text shown
|
||||||
|
// in the heading.
|
||||||
|
if got := jsConstant(t, browsePage, "versionPath"); got != escaped {
|
||||||
|
t.Errorf("browse page passes %q to the browse API, want %q", got, escaped)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// checkComparePage builds the compare URL the way the package page's script
|
||||||
|
// does, from the values its checkboxes carry, and checks the page it reaches.
|
||||||
|
func (ts *testServer) checkComparePage(t *testing.T, packagePage, version, escaped, otherVersion string) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
selectable := attrValues(packagePage, "data-version-path")
|
||||||
|
if !containsValue(selectable, escaped) {
|
||||||
|
t.Fatalf("package page compare data holds %v, want %q", selectable, escaped)
|
||||||
|
}
|
||||||
|
|
||||||
|
comparePage := ts.getOK(t, "/ui/package/deb/nmap/compare/"+escaped+"..."+otherVersion)
|
||||||
|
decoded := html.UnescapeString(comparePage)
|
||||||
|
for _, want := range []string{version, otherVersion} {
|
||||||
|
if !strings.Contains(decoded, want) {
|
||||||
|
t.Errorf("compare page does not show version %q", want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if got := jsConstant(t, comparePage, "fromVersionPath"); got != escaped {
|
||||||
|
t.Errorf("compare page passes %q to the compare API, want %q", got, escaped)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// getOK performs a GET against the server and fails the test unless it returns
|
||||||
|
// 200, returning the response body.
|
||||||
|
func (ts *testServer) getOK(t *testing.T, path string) string {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
req := httptest.NewRequest("GET", path, nil)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
ts.handler.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Fatalf("GET %s: expected status 200, got %d", path, w.Code)
|
||||||
|
}
|
||||||
|
|
||||||
|
return w.Body.String()
|
||||||
|
}
|
||||||
|
|
||||||
|
// attrValues returns the value of every occurrence of an HTML attribute in a
|
||||||
|
// rendered page, with HTML entities resolved so that values can be compared
|
||||||
|
// against the raw strings they were built from.
|
||||||
|
func attrValues(body, attr string) []string {
|
||||||
|
re := regexp.MustCompile(regexp.QuoteMeta(attr) + `="([^"]*)"`)
|
||||||
|
|
||||||
|
var values []string
|
||||||
|
for _, match := range re.FindAllStringSubmatch(body, -1) {
|
||||||
|
values = append(values, html.UnescapeString(match[1]))
|
||||||
|
}
|
||||||
|
|
||||||
|
return values
|
||||||
|
}
|
||||||
|
|
||||||
|
// jsConstant returns the value of a single-quoted JavaScript string constant in
|
||||||
|
// a rendered page. html/template escapes characters that are significant in
|
||||||
|
// JavaScript, rendering "+" as "\\u002b" for instance, so the escapes are
|
||||||
|
// resolved to recover the value the page actually uses.
|
||||||
|
func jsConstant(t *testing.T, body, name string) string {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
re := regexp.MustCompile(`const ` + regexp.QuoteMeta(name) + ` = '([^']*)'`)
|
||||||
|
match := re.FindStringSubmatch(body)
|
||||||
|
if match == nil {
|
||||||
|
t.Fatalf("page does not declare the constant %q", name)
|
||||||
|
}
|
||||||
|
|
||||||
|
unescaped, err := strconv.Unquote(`"` + match[1] + `"`)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("cannot unescape %q: %v", match[1], err)
|
||||||
|
}
|
||||||
|
|
||||||
|
return unescaped
|
||||||
|
}
|
||||||
|
|
||||||
|
func containsValue(values []string, want string) bool {
|
||||||
|
for _, v := range values {
|
||||||
|
if v == want {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
func TestPackageShowPage_WithLicense(t *testing.T) {
|
func TestPackageShowPage_WithLicense(t *testing.T) {
|
||||||
ts := newTestServer(t)
|
ts := newTestServer(t)
|
||||||
defer ts.close()
|
defer ts.close()
|
||||||
|
|
@ -1092,10 +1335,14 @@ func TestNewServer_StorageConnectivityCheck(t *testing.T) {
|
||||||
|
|
||||||
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
|
||||||
srv, err := New(cfg, logger)
|
buildInfo := BuildInfo{Version: "test-version", Commit: "test-commit"}
|
||||||
|
srv, err := New(cfg, logger, buildInfo)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatalf("New() failed: %v", err)
|
t.Fatalf("New() failed: %v", err)
|
||||||
}
|
}
|
||||||
|
if srv.buildInfo != buildInfo {
|
||||||
|
t.Errorf("build info = %#v, want %#v", srv.buildInfo, buildInfo)
|
||||||
|
}
|
||||||
|
|
||||||
// On Windows, OpenBucket normalises to file:///C:/path; on Unix the
|
// On Windows, OpenBucket normalises to file:///C:/path; on Unix the
|
||||||
// absolute path already starts with /, so file:// + /path == file:///path.
|
// absolute path already starts with /, so file:// + /path == file:///path.
|
||||||
|
|
@ -1109,6 +1356,27 @@ func TestNewServer_StorageConnectivityCheck(t *testing.T) {
|
||||||
_ = srv.db.Close()
|
_ = srv.db.Close()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestNewServer_InvalidAccessLogFailsBeforeDatabaseInit(t *testing.T) {
|
||||||
|
tempDir := t.TempDir()
|
||||||
|
dbPath := filepath.Join(tempDir, "test.db")
|
||||||
|
cfg := &config.Config{
|
||||||
|
Storage: config.StorageConfig{URL: "file://" + filepath.Join(tempDir, "artifacts")},
|
||||||
|
Database: config.DatabaseConfig{Path: dbPath},
|
||||||
|
AccessLog: config.AccessLogConfig{Path: filepath.Join(tempDir, "missing", "access.jsonl")},
|
||||||
|
}
|
||||||
|
|
||||||
|
logger := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
if _, err := New(cfg, logger, BuildInfo{}); err == nil {
|
||||||
|
t.Fatal("New() succeeded with invalid access log path")
|
||||||
|
} else if !strings.Contains(err.Error(), "initializing access log") {
|
||||||
|
t.Fatalf("New() error = %v, want access log initialization error", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if _, err := os.Stat(dbPath); !os.IsNotExist(err) {
|
||||||
|
t.Errorf("database initialized before access log validation: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestStatsEndpoint_StorageURL(t *testing.T) {
|
func TestStatsEndpoint_StorageURL(t *testing.T) {
|
||||||
ts := newTestServer(t)
|
ts := newTestServer(t)
|
||||||
defer ts.close()
|
defer ts.close()
|
||||||
|
|
|
||||||
|
|
@ -12,6 +12,11 @@
|
||||||
<i data-lucide="github" class="w-4 h-4"></i><span>github.com/git-pkgs/proxy</span>
|
<i data-lucide="github" class="w-4 h-4"></i><span>github.com/git-pkgs/proxy</span>
|
||||||
</a>
|
</a>
|
||||||
</p>
|
</p>
|
||||||
|
{{if .BuildInfo.Version}}
|
||||||
|
<p class="text-xs text-gray-500 dark:text-gray-500 mt-2">
|
||||||
|
proxy {{.BuildInfo.Version}}{{if .BuildInfo.Commit}} ({{.BuildInfo.Commit}}){{end}}
|
||||||
|
</p>
|
||||||
|
{{end}}
|
||||||
</div>
|
</div>
|
||||||
<div>
|
<div>
|
||||||
<h3 class="text-sm font-semibold text-gray-900 dark:text-gray-100 mb-3">Resources</h3>
|
<h3 class="text-sm font-semibold text-gray-900 dark:text-gray-100 mb-3">Resources</h3>
|
||||||
|
|
|
||||||
|
|
@ -7,7 +7,7 @@
|
||||||
<span class="mx-2">/</span>
|
<span class="mx-2">/</span>
|
||||||
<a href="/ui/package/{{.Ecosystem}}/{{.PackageName}}" class="hover:text-gray-900 dark:hover:text-gray-100">{{.PackageName}}</a>
|
<a href="/ui/package/{{.Ecosystem}}/{{.PackageName}}" class="hover:text-gray-900 dark:hover:text-gray-100">{{.PackageName}}</a>
|
||||||
<span class="mx-2">/</span>
|
<span class="mx-2">/</span>
|
||||||
<a href="/ui/package/{{.Ecosystem}}/{{.PackageName}}/{{.Version}}" class="hover:text-gray-900 dark:hover:text-gray-100">{{.Version}}</a>
|
<a href="/ui/package/{{.Ecosystem}}/{{.PackageName}}/{{.EscapedVersion}}" class="hover:text-gray-900 dark:hover:text-gray-100">{{.Version}}</a>
|
||||||
<span class="mx-2">/</span>
|
<span class="mx-2">/</span>
|
||||||
<span>Browse Source</span>
|
<span>Browse Source</span>
|
||||||
</nav>
|
</nav>
|
||||||
|
|
@ -51,7 +51,10 @@
|
||||||
<script>
|
<script>
|
||||||
const ecosystem = '{{.Ecosystem}}';
|
const ecosystem = '{{.Ecosystem}}';
|
||||||
const packageName = '{{.PackageName}}';
|
const packageName = '{{.PackageName}}';
|
||||||
const version = '{{.Version}}';
|
// The browse API takes the version as one path segment, so the escaped form is
|
||||||
|
// used here: a version such as "release/1" or "v1?build" would otherwise change
|
||||||
|
// the request path rather than travel inside it.
|
||||||
|
const versionPath = '{{.EscapedVersion}}';
|
||||||
let currentPath = '';
|
let currentPath = '';
|
||||||
|
|
||||||
// Escape a string for safe interpolation into HTML attributes and content.
|
// Escape a string for safe interpolation into HTML attributes and content.
|
||||||
|
|
@ -65,7 +68,7 @@ function escapeHTML(str) {
|
||||||
// Load file tree for a directory
|
// Load file tree for a directory
|
||||||
async function loadFileTree(path = '') {
|
async function loadFileTree(path = '') {
|
||||||
try {
|
try {
|
||||||
const url = `/ui/api/browse/${ecosystem}/${packageName}/${version}?path=${encodeURIComponent(path)}`;
|
const url = `/ui/api/browse/${ecosystem}/${packageName}/${versionPath}?path=${encodeURIComponent(path)}`;
|
||||||
const response = await fetch(url);
|
const response = await fetch(url);
|
||||||
if (!response.ok) throw new Error('Failed to load directory');
|
if (!response.ok) throw new Error('Failed to load directory');
|
||||||
|
|
||||||
|
|
@ -137,7 +140,7 @@ function renderFileTree(files, basePath) {
|
||||||
// Load and display file content
|
// Load and display file content
|
||||||
async function loadFile(path) {
|
async function loadFile(path) {
|
||||||
try {
|
try {
|
||||||
const url = `/ui/api/browse/${ecosystem}/${packageName}/${version}/file/${path}`;
|
const url = `/ui/api/browse/${ecosystem}/${packageName}/${versionPath}/file/${path}`;
|
||||||
const response = await fetch(url);
|
const response = await fetch(url);
|
||||||
if (!response.ok) throw new Error('Failed to load file');
|
if (!response.ok) throw new Error('Failed to load file');
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -74,12 +74,14 @@
|
||||||
<script>
|
<script>
|
||||||
const ecosystem = '{{.Ecosystem}}';
|
const ecosystem = '{{.Ecosystem}}';
|
||||||
const packageName = '{{.PackageName}}';
|
const packageName = '{{.PackageName}}';
|
||||||
const fromVersion = '{{.FromVersion}}';
|
// Each version is one path segment of the compare API URL, so the escaped form
|
||||||
const toVersion = '{{.ToVersion}}';
|
// is used rather than the decoded text shown in the heading above.
|
||||||
|
const fromVersionPath = '{{.EscapedFromVersion}}';
|
||||||
|
const toVersionPath = '{{.EscapedToVersion}}';
|
||||||
|
|
||||||
async function loadDiff() {
|
async function loadDiff() {
|
||||||
try {
|
try {
|
||||||
const url = `/ui/api/compare/${ecosystem}/${packageName}/${fromVersion}/${toVersion}`;
|
const url = `/ui/api/compare/${ecosystem}/${packageName}/${fromVersionPath}/${toVersionPath}`;
|
||||||
const response = await fetch(url);
|
const response = await fetch(url);
|
||||||
|
|
||||||
if (!response.ok) {
|
if (!response.ok) {
|
||||||
|
|
|
||||||
|
|
@ -63,8 +63,8 @@
|
||||||
{{range .Versions}}
|
{{range .Versions}}
|
||||||
<div class="px-6 py-3 flex items-center justify-between version-row">
|
<div class="px-6 py-3 flex items-center justify-between version-row">
|
||||||
<div class="flex items-center gap-3">
|
<div class="flex items-center gap-3">
|
||||||
<input type="checkbox" class="version-checkbox hidden" data-version="{{.Version}}" />
|
<input type="checkbox" class="version-checkbox hidden" data-version-path="{{.EscapedVersion}}" />
|
||||||
<a href="/ui/package/{{$.Package.Ecosystem}}/{{$.Package.Name}}/{{.Version}}" class="font-mono text-sm hover:text-blue-600 dark:hover:text-blue-400">{{.PURL}}</a>
|
<a href="/ui/package/{{$.Package.Ecosystem}}/{{$.Package.Name}}/{{.EscapedVersion}}" class="font-mono text-sm hover:text-blue-600 dark:hover:text-blue-400">{{.DisplayPURL}}</a>
|
||||||
{{if .Yanked}}<span class="ml-2 inline-flex items-center px-2 py-0.5 rounded text-xs font-medium bg-red-100 text-red-700 dark:bg-red-900 dark:text-red-300">yanked</span>{{end}}
|
{{if .Yanked}}<span class="ml-2 inline-flex items-center px-2 py-0.5 rounded text-xs font-medium bg-red-100 text-red-700 dark:bg-red-900 dark:text-red-300">yanked</span>{{end}}
|
||||||
</div>
|
</div>
|
||||||
{{if .PublishedAt.Valid}}<span class="text-sm text-gray-500 dark:text-gray-400">{{.PublishedAt.Time.Format "2006-01-02"}}</span>{{end}}
|
{{if .PublishedAt.Valid}}<span class="text-sm text-gray-500 dark:text-gray-400">{{.PublishedAt.Time.Format "2006-01-02"}}</span>{{end}}
|
||||||
|
|
@ -120,9 +120,11 @@ document.addEventListener('change', function(e) {
|
||||||
const checked = document.querySelectorAll('.version-checkbox:checked');
|
const checked = document.querySelectorAll('.version-checkbox:checked');
|
||||||
|
|
||||||
if (checked.length === 2) {
|
if (checked.length === 2) {
|
||||||
// Navigate to compare page
|
// Navigate to compare page. The checkboxes carry the version
|
||||||
const v1 = checked[0].dataset.version;
|
// already escaped as a path segment, so a version containing "/",
|
||||||
const v2 = checked[1].dataset.version;
|
// "?" or a literal "%" does not break out of the segment.
|
||||||
|
const v1 = checked[0].dataset.versionPath;
|
||||||
|
const v2 = checked[1].dataset.versionPath;
|
||||||
window.location.href = `/ui/package/${ecosystem}/${packageName}/compare/${v1}...${v2}`;
|
window.location.href = `/ui/package/${ecosystem}/${packageName}/compare/${v1}...${v2}`;
|
||||||
} else if (checked.length > 2) {
|
} else if (checked.length > 2) {
|
||||||
// Uncheck the oldest selection
|
// Uncheck the oldest selection
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,4 @@
|
||||||
{{define "title"}}{{.Package.Name}}@{{.Version.PURL}} - git-pkgs proxy{{end}}
|
{{define "title"}}{{.Version.DisplayPURL}} - git-pkgs proxy{{end}}
|
||||||
|
|
||||||
{{define "content"}}
|
{{define "content"}}
|
||||||
<div class="mb-6">
|
<div class="mb-6">
|
||||||
|
|
@ -9,7 +9,7 @@
|
||||||
</nav>
|
</nav>
|
||||||
<div class="flex items-center gap-3 mb-2">
|
<div class="flex items-center gap-3 mb-2">
|
||||||
{{template "ecosystem_badge" .Package.Ecosystem}}
|
{{template "ecosystem_badge" .Package.Ecosystem}}
|
||||||
<h1 class="text-3xl font-bold font-mono">{{.Version.PURL}}</h1>
|
<h1 class="text-3xl font-bold font-mono">{{.Version.DisplayPURL}}</h1>
|
||||||
{{if .IsOutdated}}
|
{{if .IsOutdated}}
|
||||||
<span class="inline-flex items-center px-2 py-1 rounded text-sm font-medium bg-amber-100 text-amber-700 dark:bg-amber-900 dark:text-amber-300">outdated</span>
|
<span class="inline-flex items-center px-2 py-1 rounded text-sm font-medium bg-amber-100 text-amber-700 dark:bg-amber-900 dark:text-amber-300">outdated</span>
|
||||||
{{end}}
|
{{end}}
|
||||||
|
|
@ -22,7 +22,7 @@
|
||||||
{{end}}
|
{{end}}
|
||||||
{{if .HasCachedArtifact}}
|
{{if .HasCachedArtifact}}
|
||||||
<div class="mt-4">
|
<div class="mt-4">
|
||||||
<a href="/ui/package/{{.Package.Ecosystem}}/{{.Package.Name}}/{{.Version.Version}}/browse"
|
<a href="/ui/package/{{.Package.Ecosystem}}/{{.Package.Name}}/{{.Version.EscapedVersion}}/browse"
|
||||||
class="inline-flex items-center px-4 py-2 bg-blue-600 text-white rounded-lg hover:bg-blue-700 transition-colors">
|
class="inline-flex items-center px-4 py-2 bg-blue-600 text-white rounded-lg hover:bg-blue-700 transition-colors">
|
||||||
<svg class="w-4 h-4 mr-2" fill="none" stroke="currentColor" viewBox="0 0 24 24">
|
<svg class="w-4 h-4 mr-2" fill="none" stroke="currentColor" viewBox="0 0 24 24">
|
||||||
<path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M3 7v10a2 2 0 002 2h14a2 2 0 002-2V9a2 2 0 00-2-2h-6l-2-2H5a2 2 0 00-2 2z"></path>
|
<path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M3 7v10a2 2 0 002 2h14a2 2 0 002-2V9a2 2 0 00-2-2h-6l-2-2H5a2 2 0 00-2 2z"></path>
|
||||||
|
|
|
||||||
|
|
@ -186,6 +186,64 @@ func TestRenderEmitsCanonicalAndOG(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestFooterUsesBuildInfoWhenPageDefinesVersion(t *testing.T) {
|
||||||
|
templates := &Templates{}
|
||||||
|
buildInfo := BuildInfo{Version: "proxy-build-1.2.3", Commit: "abc123def"}
|
||||||
|
wantFooter := "proxy proxy-build-1.2.3 (abc123def)"
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
page string
|
||||||
|
data any
|
||||||
|
shadow string
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "version show page",
|
||||||
|
page: "version_show",
|
||||||
|
data: VersionShowData{
|
||||||
|
Layout: Layout{BuildInfo: buildInfo},
|
||||||
|
Package: &database.Package{
|
||||||
|
PURL: "pkg:npm/lodash",
|
||||||
|
Ecosystem: "npm",
|
||||||
|
Name: "lodash",
|
||||||
|
},
|
||||||
|
Version: &database.Version{
|
||||||
|
PURL: "pkg:npm/lodash@9.9.9",
|
||||||
|
PackagePURL: "pkg:npm/lodash",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
shadow: "9.9.9",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "browse source page",
|
||||||
|
page: "browse_source",
|
||||||
|
data: BrowseSourceData{
|
||||||
|
Layout: Layout{BuildInfo: buildInfo},
|
||||||
|
Ecosystem: "npm",
|
||||||
|
PackageName: "lodash",
|
||||||
|
Version: "9.9.9",
|
||||||
|
},
|
||||||
|
shadow: "9.9.9",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
if err := templates.Render(w, tt.page, tt.data); err != nil {
|
||||||
|
t.Fatalf("Render(%q) failed: %v", tt.page, err)
|
||||||
|
}
|
||||||
|
body := w.Body.String()
|
||||||
|
if !strings.Contains(body, wantFooter) {
|
||||||
|
t.Errorf("footer missing build info %q", wantFooter)
|
||||||
|
}
|
||||||
|
if strings.Contains(body, "proxy "+tt.shadow) {
|
||||||
|
t.Errorf("footer used page Version %q instead of BuildInfo", tt.shadow)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestRenderOmitsCanonicalWhenUIBaseURLUnset(t *testing.T) {
|
func TestRenderOmitsCanonicalWhenUIBaseURLUnset(t *testing.T) {
|
||||||
templates := &Templates{}
|
templates := &Templates{}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,277 +0,0 @@
|
||||||
package storage
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
fsys "io/fs"
|
|
||||||
"os"
|
|
||||||
"path/filepath"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Filesystem implements Storage using the local filesystem.
|
|
||||||
type Filesystem struct {
|
|
||||||
root string
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewFilesystem creates a new filesystem storage rooted at the given directory.
|
|
||||||
// The directory will be created if it does not exist.
|
|
||||||
func NewFilesystem(root string) (*Filesystem, error) {
|
|
||||||
absRoot, err := filepath.Abs(root)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("resolving root path: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := os.MkdirAll(absRoot, dirPermissions); err != nil {
|
|
||||||
return nil, fmt.Errorf("creating root directory: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return &Filesystem{root: absRoot}, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) fullPath(path string) (string, error) {
|
|
||||||
localPath, err := cleanStoragePath(path)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
return filepath.Join(fs.root, localPath), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) prefixPath(prefix string) (string, error) {
|
|
||||||
if prefix == "" {
|
|
||||||
return fs.root, nil
|
|
||||||
}
|
|
||||||
return fs.fullPath(prefix)
|
|
||||||
}
|
|
||||||
|
|
||||||
func cleanStoragePath(path string) (string, error) {
|
|
||||||
if path == "." || strings.Contains(path, `\`) || !filepath.IsLocal(path) {
|
|
||||||
return "", fmt.Errorf("%w: invalid storage path", ErrNotFound)
|
|
||||||
}
|
|
||||||
|
|
||||||
localPath, err := filepath.Localize(path)
|
|
||||||
if err != nil || localPath == "." || !filepath.IsLocal(localPath) {
|
|
||||||
return "", fmt.Errorf("%w: invalid storage path", ErrNotFound)
|
|
||||||
}
|
|
||||||
|
|
||||||
return localPath, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) Store(ctx context.Context, path string, r io.Reader) (int64, string, error) {
|
|
||||||
fullPath, err := fs.fullPath(path)
|
|
||||||
if err != nil {
|
|
||||||
return 0, "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
dir := filepath.Dir(fullPath)
|
|
||||||
if err := os.MkdirAll(dir, dirPermissions); err != nil {
|
|
||||||
return 0, "", fmt.Errorf("creating directory: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Write to temp file first for atomic operation
|
|
||||||
tmpFile, err := os.CreateTemp(dir, ".tmp-*")
|
|
||||||
if err != nil {
|
|
||||||
return 0, "", fmt.Errorf("creating temp file: %w", err)
|
|
||||||
}
|
|
||||||
tmpPath := tmpFile.Name()
|
|
||||||
|
|
||||||
// Clean up temp file on error
|
|
||||||
success := false
|
|
||||||
defer func() {
|
|
||||||
if !success {
|
|
||||||
_ = tmpFile.Close()
|
|
||||||
_ = os.Remove(tmpPath)
|
|
||||||
}
|
|
||||||
}()
|
|
||||||
|
|
||||||
// Write content and compute hash
|
|
||||||
h := sha256.New()
|
|
||||||
w := io.MultiWriter(tmpFile, h)
|
|
||||||
|
|
||||||
size, err := io.Copy(w, r)
|
|
||||||
if err != nil {
|
|
||||||
return 0, "", fmt.Errorf("writing content: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := tmpFile.Close(); err != nil {
|
|
||||||
return 0, "", fmt.Errorf("closing temp file: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Atomic rename
|
|
||||||
if err := os.Rename(tmpPath, fullPath); err != nil {
|
|
||||||
return 0, "", fmt.Errorf("renaming temp file: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
success = true
|
|
||||||
hash := hex.EncodeToString(h.Sum(nil))
|
|
||||||
return size, hash, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) Open(ctx context.Context, path string) (io.ReadCloser, error) {
|
|
||||||
fullPath, err := fs.fullPath(path)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
f, err := os.Open(fullPath)
|
|
||||||
if err != nil {
|
|
||||||
if os.IsNotExist(err) {
|
|
||||||
return nil, ErrNotFound
|
|
||||||
}
|
|
||||||
return nil, fmt.Errorf("opening file: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return f, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) Exists(ctx context.Context, path string) (bool, error) {
|
|
||||||
fullPath, err := fs.fullPath(path)
|
|
||||||
if err != nil {
|
|
||||||
return false, err
|
|
||||||
}
|
|
||||||
|
|
||||||
_, err = os.Stat(fullPath)
|
|
||||||
if err != nil {
|
|
||||||
if os.IsNotExist(err) {
|
|
||||||
return false, nil
|
|
||||||
}
|
|
||||||
return false, fmt.Errorf("checking file: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return true, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) Delete(ctx context.Context, path string) error {
|
|
||||||
fullPath, err := fs.fullPath(path)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
err = os.Remove(fullPath)
|
|
||||||
if err != nil && !os.IsNotExist(err) {
|
|
||||||
return fmt.Errorf("removing file: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Try to clean up empty parent directories
|
|
||||||
dir := filepath.Dir(fullPath)
|
|
||||||
for dir != fs.root {
|
|
||||||
if err := os.Remove(dir); err != nil {
|
|
||||||
break // Directory not empty or other error
|
|
||||||
}
|
|
||||||
dir = filepath.Dir(dir)
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) SignedURL(_ context.Context, _ string, _ time.Duration) (string, error) {
|
|
||||||
return "", ErrSignedURLUnsupported
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) Size(ctx context.Context, path string) (int64, error) {
|
|
||||||
fullPath, err := fs.fullPath(path)
|
|
||||||
if err != nil {
|
|
||||||
return 0, err
|
|
||||||
}
|
|
||||||
|
|
||||||
info, err := os.Stat(fullPath)
|
|
||||||
if err != nil {
|
|
||||||
if os.IsNotExist(err) {
|
|
||||||
return 0, ErrNotFound
|
|
||||||
}
|
|
||||||
return 0, fmt.Errorf("stat file: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return info.Size(), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) UsedSpace(ctx context.Context) (int64, error) {
|
|
||||||
var total int64
|
|
||||||
|
|
||||||
err := filepath.Walk(fs.root, func(path string, info os.FileInfo, err error) error {
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if !info.IsDir() {
|
|
||||||
total += info.Size()
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
return 0, fmt.Errorf("walking directory: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return total, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// ListPrefix returns object metadata for paths under a prefix.
|
|
||||||
func (fs *Filesystem) ListPrefix(ctx context.Context, prefix string) ([]ObjectInfo, error) {
|
|
||||||
searchRoot, err := fs.prefixPath(prefix)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
if _, err := os.Stat(searchRoot); err != nil {
|
|
||||||
if os.IsNotExist(err) {
|
|
||||||
return []ObjectInfo{}, nil
|
|
||||||
}
|
|
||||||
return nil, fmt.Errorf("stat prefix: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
objects := make([]ObjectInfo, 0)
|
|
||||||
err = filepath.WalkDir(searchRoot, func(path string, entry fsys.DirEntry, err error) error {
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if entry.IsDir() {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
info, err := entry.Info()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
relPath, err := filepath.Rel(fs.root, path)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
objects = append(objects, ObjectInfo{
|
|
||||||
Path: filepath.ToSlash(relPath),
|
|
||||||
Size: info.Size(),
|
|
||||||
ModTime: info.ModTime(),
|
|
||||||
})
|
|
||||||
|
|
||||||
return nil
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("walking prefix: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return objects, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// Root returns the root directory of the storage.
|
|
||||||
func (fs *Filesystem) Root() string {
|
|
||||||
return fs.root
|
|
||||||
}
|
|
||||||
|
|
||||||
// FullPath returns the full filesystem path for a storage path.
|
|
||||||
// Useful for serving files directly or debugging.
|
|
||||||
// Returns an error if the resulting path would escape the storage root.
|
|
||||||
func (fs *Filesystem) FullPath(path string) (string, error) {
|
|
||||||
return fs.fullPath(path)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) URL() string {
|
|
||||||
return "file://" + filepath.ToSlash(fs.root)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (fs *Filesystem) Close() error {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
@ -1,331 +0,0 @@
|
||||||
package storage
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"errors"
|
|
||||||
"io"
|
|
||||||
"os"
|
|
||||||
"path/filepath"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestNewFilesystem(t *testing.T) {
|
|
||||||
dir := t.TempDir()
|
|
||||||
root := filepath.Join(dir, "cache")
|
|
||||||
|
|
||||||
fs, err := NewFilesystem(root)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("NewFilesystem failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if _, err := os.Stat(root); err != nil {
|
|
||||||
t.Errorf("root directory not created: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if fs.Root() != root {
|
|
||||||
t.Errorf("Root() = %q, want %q", fs.Root(), root)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemStore(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
content := "test content for storage"
|
|
||||||
|
|
||||||
size, hash, err := fs.Store(ctx, "npm/lodash/4.17.21/lodash.tgz", strings.NewReader(content))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Store failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if size != int64(len(content)) {
|
|
||||||
t.Errorf("size = %d, want %d", size, len(content))
|
|
||||||
}
|
|
||||||
|
|
||||||
h := sha256.Sum256([]byte(content))
|
|
||||||
wantHash := hex.EncodeToString(h[:])
|
|
||||||
if hash != wantHash {
|
|
||||||
t.Errorf("hash = %s, want %s", hash, wantHash)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Verify file exists on disk
|
|
||||||
fullPath, err := fs.FullPath("npm/lodash/4.17.21/lodash.tgz")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("FullPath failed: %v", err)
|
|
||||||
}
|
|
||||||
data, err := os.ReadFile(fullPath)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("reading stored file: %v", err)
|
|
||||||
}
|
|
||||||
if string(data) != content {
|
|
||||||
t.Errorf("stored content = %q, want %q", string(data), content)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemStoreAtomic(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
// Store initial content
|
|
||||||
_, _, err := fs.Store(ctx, "test/file.txt", strings.NewReader("initial"))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("initial Store failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Overwrite with new content
|
|
||||||
_, _, err = fs.Store(ctx, "test/file.txt", strings.NewReader("updated"))
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("update Store failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Verify updated content
|
|
||||||
r, err := fs.Open(ctx, "test/file.txt")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Open failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = r.Close() }()
|
|
||||||
|
|
||||||
data, _ := io.ReadAll(r)
|
|
||||||
if string(data) != "updated" {
|
|
||||||
t.Errorf("content = %q, want %q", string(data), "updated")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemOpen(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
content := "readable content"
|
|
||||||
|
|
||||||
_, _, _ = fs.Store(ctx, "test/read.txt", strings.NewReader(content))
|
|
||||||
|
|
||||||
r, err := fs.Open(ctx, "test/read.txt")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Open failed: %v", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = r.Close() }()
|
|
||||||
|
|
||||||
data, err := io.ReadAll(r)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("ReadAll failed: %v", err)
|
|
||||||
}
|
|
||||||
if string(data) != content {
|
|
||||||
t.Errorf("content = %q, want %q", string(data), content)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemOpenNotFound(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
_, err := fs.Open(ctx, "does/not/exist.txt")
|
|
||||||
if !errors.Is(err, ErrNotFound) {
|
|
||||||
t.Errorf("Open non-existent = %v, want ErrNotFound", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemExists(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
exists, err := fs.Exists(ctx, "test/exists.txt")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Exists failed: %v", err)
|
|
||||||
}
|
|
||||||
if exists {
|
|
||||||
t.Error("Exists returned true for non-existent file")
|
|
||||||
}
|
|
||||||
|
|
||||||
_, _, _ = fs.Store(ctx, "test/exists.txt", strings.NewReader("content"))
|
|
||||||
|
|
||||||
exists, err = fs.Exists(ctx, "test/exists.txt")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Exists after store failed: %v", err)
|
|
||||||
}
|
|
||||||
if !exists {
|
|
||||||
t.Error("Exists returned false for existing file")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemDelete(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
_, _, _ = fs.Store(ctx, "test/delete/nested/file.txt", strings.NewReader("content"))
|
|
||||||
|
|
||||||
err := fs.Delete(ctx, "test/delete/nested/file.txt")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Delete failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
exists, _ := fs.Exists(ctx, "test/delete/nested/file.txt")
|
|
||||||
if exists {
|
|
||||||
t.Error("file still exists after delete")
|
|
||||||
}
|
|
||||||
|
|
||||||
// Empty parent directories should be cleaned up
|
|
||||||
nestedDir, err := fs.FullPath("test/delete/nested")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("FullPath failed: %v", err)
|
|
||||||
}
|
|
||||||
if _, err := os.Stat(nestedDir); !os.IsNotExist(err) {
|
|
||||||
t.Error("empty nested directory not cleaned up")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemDeleteNotFound(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
// Delete non-existent file should not error
|
|
||||||
err := fs.Delete(ctx, "does/not/exist.txt")
|
|
||||||
if err != nil {
|
|
||||||
t.Errorf("Delete non-existent = %v, want nil", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemSize(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
content := "size test content"
|
|
||||||
|
|
||||||
_, _, _ = fs.Store(ctx, "test/size.txt", strings.NewReader(content))
|
|
||||||
|
|
||||||
size, err := fs.Size(ctx, "test/size.txt")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("Size failed: %v", err)
|
|
||||||
}
|
|
||||||
if size != int64(len(content)) {
|
|
||||||
t.Errorf("Size = %d, want %d", size, len(content))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemSizeNotFound(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
_, err := fs.Size(ctx, "does/not/exist.txt")
|
|
||||||
if !errors.Is(err, ErrNotFound) {
|
|
||||||
t.Errorf("Size non-existent = %v, want ErrNotFound", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemUsedSpace(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
// Empty storage
|
|
||||||
used, err := fs.UsedSpace(ctx)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("UsedSpace failed: %v", err)
|
|
||||||
}
|
|
||||||
if used != 0 {
|
|
||||||
t.Errorf("UsedSpace empty = %d, want 0", used)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Add some files
|
|
||||||
_, _, _ = fs.Store(ctx, "a.txt", strings.NewReader("aaaa")) // 4 bytes
|
|
||||||
_, _, _ = fs.Store(ctx, "b.txt", strings.NewReader("bbbbbb")) // 6 bytes
|
|
||||||
_, _, _ = fs.Store(ctx, "c/d.txt", strings.NewReader("ccccc")) // 5 bytes
|
|
||||||
|
|
||||||
used, err = fs.UsedSpace(ctx)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("UsedSpace failed: %v", err)
|
|
||||||
}
|
|
||||||
if used != 15 {
|
|
||||||
t.Errorf("UsedSpace = %d, want 15", used)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemLargeFile(t *testing.T) {
|
|
||||||
assertLargeFileRoundTrip(t, createTestFilesystem(t))
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemRejectsInvalidPaths(t *testing.T) {
|
|
||||||
tmp := t.TempDir()
|
|
||||||
fs, err := NewFilesystem(tmp)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
for _, p := range []string{
|
|
||||||
"",
|
|
||||||
".",
|
|
||||||
"../etc/passwd",
|
|
||||||
"../../etc/passwd",
|
|
||||||
"a/../../etc/passwd",
|
|
||||||
"/etc/passwd",
|
|
||||||
"test//file.txt",
|
|
||||||
"test/./file.txt",
|
|
||||||
"test/../file.txt",
|
|
||||||
`test\..\file.txt`,
|
|
||||||
} {
|
|
||||||
name := p
|
|
||||||
if name == "" {
|
|
||||||
name = "empty"
|
|
||||||
}
|
|
||||||
|
|
||||||
t.Run(name, func(t *testing.T) {
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
if _, err := fs.FullPath(p); !errors.Is(err, ErrNotFound) {
|
|
||||||
t.Errorf("FullPath(%q) = %v, want ErrNotFound", p, err)
|
|
||||||
}
|
|
||||||
if _, err := fs.Open(ctx, p); err == nil {
|
|
||||||
t.Errorf("Open(%q) should reject invalid path", p)
|
|
||||||
}
|
|
||||||
if _, _, err := fs.Store(ctx, p, strings.NewReader("x")); err == nil {
|
|
||||||
t.Errorf("Store(%q) should reject invalid path", p)
|
|
||||||
}
|
|
||||||
if _, err := fs.Exists(ctx, p); err == nil {
|
|
||||||
t.Errorf("Exists(%q) should reject invalid path", p)
|
|
||||||
}
|
|
||||||
if err := fs.Delete(ctx, p); err == nil {
|
|
||||||
t.Errorf("Delete(%q) should reject invalid path", p)
|
|
||||||
}
|
|
||||||
if _, err := fs.Size(ctx, p); err == nil {
|
|
||||||
t.Errorf("Size(%q) should reject invalid path", p)
|
|
||||||
}
|
|
||||||
if _, err := fs.ListPrefix(ctx, p); p != "" && err == nil {
|
|
||||||
t.Errorf("ListPrefix(%q) should reject invalid path", p)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemListPrefixAllowsEmptyPrefix(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
ctx := context.Background()
|
|
||||||
|
|
||||||
_, _, _ = fs.Store(ctx, "a.txt", strings.NewReader("aaaa"))
|
|
||||||
_, _, _ = fs.Store(ctx, "c/d.txt", strings.NewReader("ccccc"))
|
|
||||||
|
|
||||||
objects, err := fs.ListPrefix(ctx, "")
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("ListPrefix empty prefix failed: %v", err)
|
|
||||||
}
|
|
||||||
if len(objects) != 2 {
|
|
||||||
t.Fatalf("ListPrefix empty prefix returned %d objects, want 2", len(objects))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestFilesystemSignedURLUnsupported(t *testing.T) {
|
|
||||||
fs := createTestFilesystem(t)
|
|
||||||
|
|
||||||
_, err := fs.SignedURL(context.Background(), "test/file.txt", time.Minute)
|
|
||||||
if !errors.Is(err, ErrSignedURLUnsupported) {
|
|
||||||
t.Errorf("SignedURL = %v, want ErrSignedURLUnsupported", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func createTestFilesystem(t *testing.T) *Filesystem {
|
|
||||||
t.Helper()
|
|
||||||
dir := t.TempDir()
|
|
||||||
|
|
||||||
fs, err := NewFilesystem(dir)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("NewFilesystem failed: %v", err)
|
|
||||||
}
|
|
||||||
return fs
|
|
||||||
}
|
|
||||||
|
|
@ -11,8 +11,6 @@ package storage
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/hex"
|
|
||||||
"errors"
|
"errors"
|
||||||
"io"
|
"io"
|
||||||
"time"
|
"time"
|
||||||
|
|
@ -80,42 +78,3 @@ func ArtifactPath(ecosystem, namespace, name, version, filename string) string {
|
||||||
}
|
}
|
||||||
return ecosystem + "/" + name + "/" + version + "/" + filename
|
return ecosystem + "/" + name + "/" + version + "/" + filename
|
||||||
}
|
}
|
||||||
|
|
||||||
// HashingReader wraps a reader and computes SHA256 hash as content is read.
|
|
||||||
type HashingReader struct {
|
|
||||||
r io.Reader
|
|
||||||
hash []byte
|
|
||||||
h interface{ Sum([]byte) []byte }
|
|
||||||
size int64
|
|
||||||
done bool
|
|
||||||
}
|
|
||||||
|
|
||||||
func NewHashingReader(r io.Reader) *HashingReader {
|
|
||||||
h := sha256.New()
|
|
||||||
return &HashingReader{
|
|
||||||
r: io.TeeReader(r, h),
|
|
||||||
h: h,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (hr *HashingReader) Read(p []byte) (n int, err error) {
|
|
||||||
n, err = hr.r.Read(p)
|
|
||||||
hr.size += int64(n)
|
|
||||||
if err == io.EOF {
|
|
||||||
hr.done = true
|
|
||||||
hr.hash = hr.h.Sum(nil)
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
func (hr *HashingReader) Sum() string {
|
|
||||||
if !hr.done {
|
|
||||||
hr.hash = hr.h.Sum(nil)
|
|
||||||
hr.done = true
|
|
||||||
}
|
|
||||||
return hex.EncodeToString(hr.hash)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (hr *HashingReader) Size() int64 {
|
|
||||||
return hr.size
|
|
||||||
}
|
|
||||||
|
|
|
||||||
|
|
@ -6,7 +6,6 @@ import (
|
||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
"io"
|
"io"
|
||||||
"strings"
|
|
||||||
"testing"
|
"testing"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -35,30 +34,6 @@ func TestArtifactPath(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestHashingReader(t *testing.T) {
|
|
||||||
content := "hello world"
|
|
||||||
r := NewHashingReader(strings.NewReader(content))
|
|
||||||
|
|
||||||
data, err := io.ReadAll(r)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("ReadAll failed: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if string(data) != content {
|
|
||||||
t.Errorf("got content %q, want %q", string(data), content)
|
|
||||||
}
|
|
||||||
|
|
||||||
if r.Size() != int64(len(content)) {
|
|
||||||
t.Errorf("got size %d, want %d", r.Size(), len(content))
|
|
||||||
}
|
|
||||||
|
|
||||||
h := sha256.Sum256([]byte(content))
|
|
||||||
wantHash := hex.EncodeToString(h[:])
|
|
||||||
if r.Sum() != wantHash {
|
|
||||||
t.Errorf("got hash %s, want %s", r.Sum(), wantHash)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// assertLargeFileRoundTrip stores a 1MB file in the given storage, verifies size and
|
// assertLargeFileRoundTrip stores a 1MB file in the given storage, verifies size and
|
||||||
// hash, then reads it back and confirms the content matches.
|
// hash, then reads it back and confirms the content matches.
|
||||||
func assertLargeFileRoundTrip(t *testing.T, s Storage) {
|
func assertLargeFileRoundTrip(t *testing.T, s Storage) {
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue