Skip to content

guestlinks: implement auth-middleware for Guestlink cookies - #3618

Merged
aduffeck merged 10 commits into
opencloud-eu:mainfrom
rhafer:proxy-guestauth-middleware
Oct 6, 2026
Merged

aduffeck merged 10 commits into
opencloud-eu:mainfrom
rhafer:proxy-guestauth-middleware

Conversation

@rhafer

@rhafer rhafer commented Sep 29, 2026

Copy link
Copy Markdown
Member

This is currently based on #3609. Needs to be rebased once that on is merged. Until that I'll keep this in draft state.

Needs: opencloud-eu/reva#822

This adds the reva guestlinks authprovider service to the auth-guest service.

Also it adds new a authentication middleware for the Cookies issued by the auth-guest that utilizes the above auth-provider for signing a reva token.

Beware: Currently this gives too broad access (e.g. the authenticated user is able to use graph/v1.0/users?$seach=...)

@codacy-production

codacy-production Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 148 complexity

Metric Results
Complexity 148

View in Codacy

🟢 Coverage 63.38% diff coverage · +0.16% coverage variation

Metric Results
Coverage variation ✅ +0.16% coverage variation (-1.00%)
Diff coverage ✅ 63.38% diff coverage

View coverage diff in Codacy

Coverage variation details
Coverable lines Covered lines Coverage
Common ancestor commit (6ff4794) 90725 22141 24.40%
Head commit (3a55525) 91096 (+371) 22381 (+240) 24.57% (+0.16%)

Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: <coverage of head commit> - <coverage of common ancestor commit>

Diff coverage details
Coverable lines Covered lines Diff coverage
Pull request (#3618) 426 270 63.38%

Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: <covered lines added or modified>/<coverable lines added or modified> * 100%

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@rhafer
rhafer force-pushed the proxy-guestauth-middleware branch 4 times, most recently from 2b476ab to a6c3f13 Compare October 1, 2026 16:13
@aduffeck

aduffeck commented Oct 5, 2026

Copy link
Copy Markdown
Member

Just for the record: the comment in the description about giving too broad access is no longer true. The guest_link_auth middleware is now limited to these path prefixes:

		"/graph/v1beta1/me/drive/sharedWithMe",
		"/dav/",
		"/remote.php/dav/",
		"/webdav/",
		"/remote.php/webdav/"

rhafer and others added 8 commits October 6, 2026 09:47
This starts the guestlinks authprovider as part of the auth-guest
service and wires it into the authregistry.
Replace the boolean authenticator result with a typed AuthenticationResult
containing AuthenticationState (NotApplicable, Failed, Succeeded, Error)
to distinguish between non-applicability, rejected credentials, and
dependency failures.

All existing authentication behavior remains observably unchanged.
@aduffeck
aduffeck force-pushed the proxy-guestauth-middleware branch from 14a04ab to 7f7da7f Compare October 6, 2026 08:06
@aduffeck
aduffeck marked this pull request as ready for review October 6, 2026 09:41
@aduffeck
aduffeck enabled auto-merge October 6, 2026 10:05
@aduffeck
aduffeck merged commit 22dfa5b into opencloud-eu:main Oct 6, 2026
68 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

guestlinks: proxy middleware to validate guestlink cookies for authentication

2 participants