Skip to content

Add "guestlinks" authmanager - #822

Merged
rhafer merged 6 commits into
opencloud-eu:mainfrom
rhafer:cookie-auth
Oct 1, 2026
Merged

rhafer merged 6 commits into
opencloud-eu:mainfrom
rhafer:cookie-auth

Conversation

@rhafer

@rhafer rhafer commented Sep 24, 2026

Copy link
Copy Markdown
Member

This add a new authmanager allowing to sign reva tokes for the upcoming guestlinks implemenation (needed for: opencloud-eu/opencloud#3070)

It also streamlines the errtypes <-> statuscode mapping. I can put that into a separate PR if desired.

@rhafer rhafer self-assigned this Sep 24, 2026
@rhafer
rhafer force-pushed the cookie-auth branch 2 times, most recently from 230b272 to 6959f58 Compare September 28, 2026 12:34
@rhafer
rhafer requested a review from aduffeck September 29, 2026 06:47
@rhafer

rhafer commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Streamlined the expected JWT claims with the related opencloud PR (opencloud-eu/opencloud#3609)

rhafer added 2 commits October 1, 2026 15:06
Add an opt-in StatusInnerErrorProvider interface (pkg/rgrpc/status) so
auth manager errors can attach details to rpc.Status.InnerError. Only
errors implementing (or wrapping) the interface contribute details;
nothing is serialized automatically.

- authprovider service: attach InnerError when the auth error provides one.
- gateway Authenticate: also pass CODE_UNAVAILABLE through unchanged
  (alongside existing UNAUTHENTICATED/PERMISSION_DENIED/NOT_FOUND),
  preserving Message, Trace and InnerError.

This is needed groundwork the upcoming guestlinks auth manager. It needs
to be able to return additional details when used authentication token
is expired.
@rhafer
rhafer force-pushed the cookie-auth branch 3 times, most recently from 4ad6938 to cd19a6d Compare October 1, 2026 13:35
rhafer added 4 commits October 1, 2026 15:53
Add a new "guestlinks" Reva authentication manager that validates
OpenCloud guest-link session JWTs.

Related: opencloud-eu/opencloud#3070
Consistently map the `InvalidCredentials` error to the `Unauthenticated`
Status, like the other mappers already do (e.g. from/to HTTP Status code or the one
via the `IsInvalidCredentials` interface).
Make errtype marker interfaces implement error, then use them
consistently when converting errors to RPC statuses.
@rhafer
rhafer merged commit 392feb6 into opencloud-eu:main Oct 1, 2026
18 of 19 checks passed
@openclouders openclouders mentioned this pull request Oct 1, 2026
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants