Robert Vollmert
2b8ffc8e61
src: update for changed map type in aeson-2
...
This means that we're now using Data.Map.Strict instead of
Data.HashMap.Strict for JSON objects in general, and specifically
for claims maps and CSV rows.
This addresses certain hash flooding vulnerabilities, but may
have performance downsides.
Compare e.g. https://frasertweedale.github.io/blog-fp/posts/2021-10-12-aeson-hash-flooding-protection.html
2022-06-13 13:25:54 +02:00
Robert Vollmert
5e6987b1d8
src: consistently import HashMap as HM, Map as M
...
With both HashMap and Map imported as M in different modules,
linter rules prevented ever importing both modules in one place.
2022-06-13 13:16:50 +02:00
Wolfgang Walther
c3ade07ad6
feat: Make db-anon-role optional
...
Without db-anon-role, PostgREST will block any anonymous access without hitting the database.
Resolves #1689 , Ref #1823
2022-01-22 15:59:26 +01:00
3c17f97c87
refactor: Make JWT authorization a middleware
...
This follows the style of wai-middleware-auth package and
makes the JWT parsing a middleware.
Co-authored-by: Wolfgang Walther <walther@technowledgy.de >
2022-01-07 20:26:33 +01:00
Remo Rechkemmer and GitHub
f99fd6cbad
refactor: Split up Types.hs and logically organize modules ( #1793 )
2021-04-11 18:28:01 +02:00
Remo Rechkemmer and GitHub
e6973f966b
refactor: App.hs and related changes ( #1725 )
...
* Use ExceptT to avoid 'staircasing' case analysis in App.hs
* Split large function in App.hs into individual handler functions
* Adapt API of Auth.hs, OpenApi.hs etc. to simplify the use of those modules in App.hs
* Split optional rollback functionality into Middleware
* Unify SimpleError and ApiRequestError into one Error type, so it can be used across modules
2021-02-23 22:41:48 +01:00
steve-chavez
17af56adb1
refactor: config validation inside readAppConfig
...
Remove Either from configJwtRoleClaimKey/configServerUnixSocketMode
and remove whenLefts.
2021-01-22 15:56:08 -05:00
Wolfgang Walther and Wolfgang Walther
6dd126461e
cov: Remove unused code
2021-01-14 16:40:29 +01:00
steve-chavez
0ff05edd16
refactor: move parseSecret out of App.postgrest
...
parseSecret only needs to be computed once, after the config is read.
2020-07-13 11:30:16 -05:00
steve-chavez
55b4f4fbe7
Fix expired JWTs starting an empty transaction
...
Fixes https://github.com/PostgREST/postgrest/issues/1094 .
Expired JWTs were doing an empty BEGIN/COMMIT in the db.
2020-07-03 17:23:10 -05:00
Robert Vollmert and Steve Chavez
3da5a2875e
Update to protolude 0.3.0
...
The good part is that protolude 0.3.0 builds with GHC 8.10.
The bad part is that this change is a bit painful:
- the default `toS` has changed to no longer convert to and from ByteString
- similarly, `show` no longer outputs ByteString
The changes here are pretty much minimal to keep things compiling; I didn't
see a nice way to work with the new ConvertText class, even though `toUtf8`
seems like it might help if used besides `toS` at just the right spots.
2020-04-23 14:14:21 -05:00
Xavier Francisco and Steve Chávez
28b3d6cafd
Update stylish haskell config; apply all; add CI config ( #1299 )
...
* Update config default; Copy non-defaults
* Update .stylish-haskell config version to match pgrst
* Apply stylish haskell to all files
* CircleCI config
* Remove redundant import.
What is used from Network.HTTP.Types.Headers is also exported by Network.HTTP.Types.
* Grouped imports
* Show un-styled files on CircleCI failure
* Fix styling imports
* Apply adhoc standard correctly
2019-05-23 10:44:34 -05:00
Russell Davies and Steve Chávez
473ac70789
Add support for parsing JSON Web Key Sets
2018-11-13 13:58:17 -05:00
steve-chavez
dadfe965b9
Do hlint 2.1 hints
2018-11-06 11:54:10 -05:00
Steve Chávez and GitHub
0a1d83ce8f
Fix JWTIssuedAtFuture for valid iat claim ( #1166 )
...
* Add test for ensuring "iat" works with time cache
2018-08-16 12:29:32 -05:00
steve-chavez
f033c2c4b5
Add role-claim-key config value
2018-04-30 11:31:06 -05:00
steve-chavez
5c87fe2704
Add getCurrentTime cache for jwt validation
2018-04-30 11:31:06 -05:00
Ruslan Talpa and GitHub
e4183780a9
Fix #1016
2017-12-12 15:31:39 +02:00
Pi3r and Joe Nelson
2b5ae34c5a
Update jose to 0.6 ( #997 )
2017-10-15 10:49:25 -04:00
Elliot Murphy and Joe Nelson
3ccae4bb8b
Allow configurable audience claim ( #975 )
2017-09-26 07:29:20 -07:00
Joe Nelson and GitHub
0ed4215a0d
Support asymmetric JWK ( #919 )
2017-08-09 08:42:00 -05:00
Ruslan Talpa and Joe Nelson
5fffbbe381
Make HTTP headers available as GUCs #800 ( #849 )
2017-04-10 19:23:48 -05:00
Joe Nelson
c6cd8145eb
Set request.jwt.claim.*
2016-10-17 22:32:36 -07:00
Joe Nelson
62ed9e2c4d
Do not require jwt secret, but die on auth without it
2016-09-24 21:28:08 -07:00
Joe Nelson
fb5fce026d
Issue http 401 for expired jwt
...
Fixes #512
2016-09-24 21:28:08 -07:00
Diogo Biazus and Joe Nelson
6f737056a2
Protolude completion in library and executable ( #697 )
2016-08-21 15:10:19 -07:00
Diogo Biazus
0e172b8030
Port Auth to prolude
2016-06-29 09:25:57 -04:00
Jacky Hu
cf4e157de7
Provide a swagger2 spec for the dynamic API
...
Related issue: #144
2016-06-18 10:18:43 +08:00
Joe Nelson
c7d863c998
Merge pull request #605 from diogob/microlens
...
Replace lens dependency for microlens
2016-05-21 11:48:07 -07:00
Diogo Biazus
b68fcd2522
Replace lens dependency for microlens
2016-05-21 13:31:39 -04:00
Diogo Biazus
abd81c998b
jwtClaims should always return Left for invalid JWT
2016-05-21 13:18:45 -04:00
Joe Nelson
18e3c30ad8
Return proper 401/403 when access denied
...
Fixes #584
2016-05-15 00:56:47 -07:00
Joe Nelson
eae5857d0e
Set role only once, and set it before other GUC vars ( #560 )
...
* Set role only once, and set it before other GUC vars
Fixes #559
* Unify role/claim logic in claimsToSQL
Suggested by @diogob
2016-04-15 07:30:36 -07:00
Joe Nelson
358254639a
Merge @ruslantalpa's fk improved detection
2016-03-12 12:42:57 -08:00
Joe Nelson
f67e195f76
Expose all claims via sql postgrest.claims
2016-03-11 20:51:22 -08:00
Joe Nelson
508d722fb2
Allow SQL functions to generate registered JWT claims
2016-03-10 21:58:43 -08:00
Ruslan Talpa
40eec0b2ff
code beautify using stylish-haskell
2016-02-29 14:53:41 +02:00
Joe Nelson
cbb2ba7d42
Appease hlint
2016-01-24 18:09:20 -08:00
Joe Nelson
6122bc4108
Middleware compiles
2016-01-24 18:09:18 -08:00
Joe Nelson
87c946ef52
Treat JWT as a Secret, not String
2015-11-19 09:58:41 -08:00
Diogo Biazus
f47d5e52f4
Moves all PgQuery module to QueryBuilder
2015-11-14 22:54:55 -05:00
calebmer
62cb8e0453
Cleanup JWT expires
2015-11-11 08:34:50 -05:00
calebmer
aab2f0d1f1
Ensure JWT expires
2015-11-05 17:04:54 -05:00
Diogo Biazus
2c1236652e
Fixes hlint suggestions
2015-11-01 16:49:21 -05:00
Ruslan Talpa
cd3a149aa4
Merge remote-tracking branch 'begriffs/v3' into v3
2015-10-24 21:25:01 +03:00
Joe Nelson
7692693aae
Enforce GHC >= 7.10 and fix Stack warnings
2015-10-23 10:33:27 -07:00
Ruslan Talpa
f5fb78ec99
version changed to 3, circle ci to use ghc 7.10.1, stricter import/export in PgQuery and remove of dead code
2015-10-23 12:23:46 +03:00
Diogo Biazus
d000a6c61a
Eliminates SET role duplication and changes Auth module interface
2015-10-22 00:08:02 -04:00
Diogo Biazus
250a4dcfb2
Adds back import to make GHC 7.8 happy
2015-10-20 19:51:25 -04:00
Diogo Biazus
6e55017f96
Cleans and adds haddock comments
2015-10-20 19:48:54 -04:00