- Notifications
You must be signed in to change notification settings - Fork370
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
refactor: split HMAC SHA strategy#813
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters
BREAKING CHANGES: Going forward, the `HMACSHAStrategy` requires a `BaseHMACSHAStrategy`. Here is how to upgrade it:```patchvar hmacshaStrategy = HMACSHAStrategy{-Enigma: &hmac.HMACStrategy{Config: &fosite.Config{GlobalSecret: []byte("foobarfoobarfoobarfoobarfoobarfoobarfoobarfoobar")}},-Config: &fosite.Config{-AccessTokenLifespan: time.Hour * 24,-AuthorizeCodeLifespan: time.Hour * 24,+BaseHMACSHAStrategy: &BaseHMACSHAStrategy{+Enigma: &hmac.HMACStrategy{Config: &fosite.Config{GlobalSecret: []byte("foobarfoobarfoobarfoobarfoobarfoobarfoobarfoobar")}},+Config: &fosite.Config{+AccessTokenLifespan: time.Hour * 24,+AuthorizeCodeLifespan: time.Hour * 24,+},},}```
aeneasr added a commit that referenced this pull requestJul 10, 2024
6 tasks
aeneasr added a commit that referenced this pull requestJul 16, 2024
This PR addresses improvements to the OAuth2 package, making it easier to inject custom strategies. As part of this change, the HMAC strategy has been split into a prefixed and unprefixed strategy. Due to this, the instantiation of `HMACSHAStrategy` has changed.This patch addresses improvements over#813 which has been reverted and fixed here.BREAKING CHANGES: Going forward, please instantiate the HMACSHAStrategy using `oauth2.NewHMACSHAStrategy()`:```patch-var hmacshaStrategy = oauth2.HMACSHAStrategy{-Enigma: &hmac.HMACStrategy{Config: &fosite.Config{GlobalSecret: []byte("foobarfoobarfoobarfoobarfoobarfoobarfoobarfoobar")}},-Config: &fosite.Config{-AccessTokenLifespan: time.Hour * 24,-AuthorizeCodeLifespan: time.Hour * 24,-},-}+var hmacshaStrategy = oauth2.NewHMACSHAStrategy(+&hmac.HMACStrategy{Config: &fosite.Config{GlobalSecret: []byte("foobarfoobarfoobarfoobarfoobarfoobarfoobarfoobar")}},+&fosite.Config{+AccessTokenLifespan: time.Hour * 24,+AuthorizeCodeLifespan: time.Hour * 24,+},+)```
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
BREAKING CHANGES: Going forward, the
HMACSHAStrategy
requires aBaseHMACSHAStrategy
. Here is how to upgrade it:Checklist
[ ] I have referenced an issue containing the design document if my change introduces a new feature.If this pull request addresses a security vulnerability,
I confirm that I got approval (please contactsecurity@ory.sh) from the maintainers to push the changes.
[ ] I have added tests that prove my fix is effective or that my feature works.Further comments