From 8a1c0963553e435ea909c824f14cef82c17d8f60 Mon Sep 17 00:00:00 2001 From: Algis Dumbris Date: Fri, 13 Mar 2026 11:59:37 +0200 Subject: [PATCH] feat: implement human auth with OAuth 2.1 (fosite) Add complete auth subsystem with OAuth 2.1 authorization server using ory/fosite, local user accounts with bcrypt password hashing, session management, and HTTP handlers for the Web UI. Components: - User store with bcrypt hashing (configurable cost, default 12), CRUD, validation (username 3-64 chars alphanumeric+underscore, password 8-72 bytes) - Session store with secure random IDs, configurable lifetime (default 24h), expiration cleanup, and per-user invalidation - OAuth client store with client_id/secret generation and bcrypt verification - Fosite storage adapter implementing CoreStorage, TokenRevocationStorage, and PKCERequestStorage backed by SQLite - OAuth provider configured with authorization code (PKCE S256 mandatory), client credentials, refresh token rotation, and token introspection - HTTP handlers: POST /auth/register, POST /auth/login, POST /auth/logout, GET /auth/me, PUT /auth/password, GET /oauth/authorize, POST /oauth/token, POST /oauth/introspect - Middleware: RequireSession (cookie), RequireBearer (access token), RequireAuth (either), RequireAdmin (role check) - Structured auth event logging (login, token issuance, session lifecycle) - Schema migration 002_auth.sql extending users, oauth_clients, oauth_tokens tables and adding sessions, oauth_authorization_codes tables - Initial admin user auto-created on first run with random password printed to stdout - All tests pass with CGO_ENABLED=0, zero external runtime dependencies Co-Authored-By: Claude Opus 4.6 --- cmd/synapbus/main.go | 67 +++ go.mod | 66 +++ go.sum | 827 ++++++++++++++++++++++++++- internal/auth/client_store.go | 214 +++++++ internal/auth/config.go | 53 ++ internal/auth/doc.go | 5 + internal/auth/errors.go | 38 ++ internal/auth/fosite_store.go | 496 ++++++++++++++++ internal/auth/handlers.go | 390 +++++++++++++ internal/auth/handlers_test.go | 333 +++++++++++ internal/auth/logging.go | 63 ++ internal/auth/middleware.go | 168 ++++++ internal/auth/oauth_test.go | 260 +++++++++ internal/auth/provider.go | 63 ++ internal/auth/session_store.go | 132 +++++ internal/auth/session_store_test.go | 171 ++++++ internal/auth/types.go | 104 ++++ internal/auth/user_store.go | 217 +++++++ internal/auth/user_store_test.go | 289 ++++++++++ internal/storage/schema/002_auth.sql | 51 ++ 20 files changed, 3999 insertions(+), 8 deletions(-) create mode 100644 internal/auth/client_store.go create mode 100644 internal/auth/config.go create mode 100644 internal/auth/doc.go create mode 100644 internal/auth/errors.go create mode 100644 internal/auth/fosite_store.go create mode 100644 internal/auth/handlers.go create mode 100644 internal/auth/handlers_test.go create mode 100644 internal/auth/logging.go create mode 100644 internal/auth/middleware.go create mode 100644 internal/auth/oauth_test.go create mode 100644 internal/auth/provider.go create mode 100644 internal/auth/session_store.go create mode 100644 internal/auth/session_store_test.go create mode 100644 internal/auth/types.go create mode 100644 internal/auth/user_store.go create mode 100644 internal/auth/user_store_test.go create mode 100644 internal/storage/schema/002_auth.sql diff --git a/cmd/synapbus/main.go b/cmd/synapbus/main.go index f16cccd..00529b7 100644 --- a/cmd/synapbus/main.go +++ b/cmd/synapbus/main.go @@ -2,6 +2,8 @@ package main import ( "context" + "crypto/rand" + "encoding/hex" "fmt" "log/slog" "net/http" @@ -14,6 +16,7 @@ import ( "github.com/spf13/cobra" "github.com/smart-mcp-proxy/synapbus/internal/agents" + "github.com/smart-mcp-proxy/synapbus/internal/auth" mcpserver "github.com/smart-mcp-proxy/synapbus/internal/mcp" "github.com/smart-mcp-proxy/synapbus/internal/messaging" "github.com/smart-mcp-proxy/synapbus/internal/storage" @@ -90,6 +93,46 @@ func runServe(cmd *cobra.Command, args []string) error { agentStore := agents.NewSQLiteAgentStore(db.DB) agentService := agents.NewAgentService(agentStore, tracer) + // Initialize auth subsystem + authSecret := make([]byte, 32) + if _, err := rand.Read(authSecret); err != nil { + return fmt.Errorf("generate auth secret: %w", err) + } + + authCfg := auth.DefaultConfig() + authCfg.Secret = authSecret + authCfg.DevMode = true + authCfg.IssuerURL = fmt.Sprintf("http://localhost:%d", port) + + userStore := auth.NewSQLiteUserStore(db.DB, authCfg.BcryptCost) + sessionStore := auth.NewSQLiteSessionStore(db.DB) + clientStore := auth.NewSQLiteClientStore(db.DB, authCfg.BcryptCost) + fositeStore := auth.NewFositeStore(db.DB, authCfg.BcryptCost) + oauthProvider := auth.NewOAuthProvider(authCfg, fositeStore) + authHandlers := auth.NewHandlers(userStore, sessionStore, clientStore, oauthProvider, authCfg) + + // Create initial admin user if no users exist + userCount, err := userStore.CountUsers(ctx) + if err != nil { + return fmt.Errorf("count users: %w", err) + } + if userCount == 0 { + adminPassword := generateRandomPassword() + if _, err := userStore.CreateUser(ctx, "admin", adminPassword, "Admin"); err != nil { + return fmt.Errorf("create admin user: %w", err) + } + slog.Info("initial admin user created", + "username", "admin", + "password", adminPassword, + ) + fmt.Printf("\n========================================\n") + fmt.Printf(" Initial admin account created\n") + fmt.Printf(" Username: admin\n") + fmt.Printf(" Password: %s\n", adminPassword) + fmt.Printf(" (Change this password after first login)\n") + fmt.Printf("========================================\n\n") + } + // Create MCP server mcpSrv := mcpserver.NewMCPServer(msgService, agentService) startTime := time.Now() @@ -100,6 +143,23 @@ func runServe(cmd *cobra.Command, args []string) error { // Health endpoint (no auth) r.Get("/health", mcpserver.NewHealthHandler(mcpSrv.ConnectionManager(), "0.1.0", startTime)) + // Auth endpoints (public) + r.Post("/auth/register", authHandlers.HandleRegister) + r.Post("/auth/login", authHandlers.HandleLogin) + + // OAuth endpoints + r.Get("/oauth/authorize", authHandlers.HandleAuthorize) + r.Post("/oauth/token", authHandlers.HandleToken) + r.Post("/oauth/introspect", authHandlers.HandleIntrospect) + + // Protected auth endpoints + r.Group(func(r chi.Router) { + r.Use(auth.RequireSession(userStore, sessionStore)) + r.Post("/auth/logout", authHandlers.HandleLogout) + r.Get("/auth/me", authHandlers.HandleMe) + r.Put("/auth/password", authHandlers.HandleChangePassword) + }) + // MCP SSE endpoint r.Mount("/mcp", mcpSrv.SSEHandler()) @@ -144,3 +204,10 @@ func runServe(cmd *cobra.Command, args []string) error { slog.Info("SynapBus stopped") return nil } + +// generateRandomPassword creates a cryptographically random password. +func generateRandomPassword() string { + b := make([]byte, 16) + rand.Read(b) + return hex.EncodeToString(b) +} diff --git a/go.mod b/go.mod index 45671c6..760ebcc 100644 --- a/go.mod +++ b/go.mod @@ -5,28 +5,94 @@ go 1.25.0 require ( github.com/go-chi/chi/v5 v5.2.5 github.com/mark3labs/mcp-go v0.45.0 + github.com/ory/fosite v0.49.0 github.com/spf13/cobra v1.10.2 golang.org/x/crypto v0.49.0 modernc.org/sqlite v1.46.1 ) require ( + github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect github.com/bahlo/generic-list-go v0.2.0 // indirect github.com/buger/jsonparser v1.1.1 // indirect + github.com/cenkalti/backoff/v4 v4.3.0 // indirect + github.com/cespare/xxhash/v2 v2.3.0 // indirect + github.com/cristalhq/jwt/v4 v4.0.2 // indirect + github.com/davecgh/go-spew v1.1.1 // indirect + github.com/dgraph-io/ristretto v1.0.0 // indirect github.com/dustin/go-humanize v1.0.1 // indirect + github.com/felixge/httpsnoop v1.0.4 // indirect + github.com/fsnotify/fsnotify v1.6.0 // indirect + github.com/go-jose/go-jose/v3 v3.0.3 // indirect + github.com/go-logr/logr v1.3.0 // indirect + github.com/go-logr/stdr v1.2.2 // indirect + github.com/gobuffalo/pop/v6 v6.1.1 // indirect + github.com/gogo/protobuf v1.3.2 // indirect + github.com/golang/mock v1.6.0 // indirect + github.com/golang/protobuf v1.5.3 // indirect github.com/google/uuid v1.6.0 // indirect + github.com/gorilla/websocket v1.5.0 // indirect + github.com/grpc-ecosystem/grpc-gateway/v2 v2.18.1 // indirect + github.com/hashicorp/go-cleanhttp v0.5.2 // indirect + github.com/hashicorp/go-retryablehttp v0.7.7 // indirect + github.com/hashicorp/hcl v1.0.0 // indirect github.com/inconshreveable/mousetrap v1.1.0 // indirect github.com/invopop/jsonschema v0.13.0 // indirect + github.com/magiconair/properties v1.8.7 // indirect github.com/mailru/easyjson v0.7.7 // indirect github.com/mattn/go-isatty v0.0.20 // indirect + github.com/mattn/goveralls v0.0.12 // indirect + github.com/mitchellh/mapstructure v1.5.0 // indirect + github.com/mohae/deepcopy v0.0.0-20170929034955-c48cc78d4826 // indirect github.com/ncruces/go-strftime v1.0.0 // indirect + github.com/openzipkin/zipkin-go v0.4.2 // indirect + github.com/ory/go-acc v0.2.9-0.20230103102148-6b1c9a70dbbe // indirect + github.com/ory/go-convenience v0.1.0 // indirect + github.com/ory/x v0.0.665 // indirect + github.com/pelletier/go-toml/v2 v2.0.9 // indirect + github.com/pkg/errors v0.9.1 // indirect + github.com/pmezard/go-difflib v1.0.0 // indirect github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect + github.com/seatgeek/logrus-gelf-formatter v0.0.0-20210414080842-5b05eb8ff761 // indirect + github.com/sirupsen/logrus v1.9.3 // indirect + github.com/spf13/afero v1.9.5 // indirect github.com/spf13/cast v1.7.1 // indirect + github.com/spf13/jwalterweatherman v1.1.0 // indirect github.com/spf13/pflag v1.0.9 // indirect + github.com/spf13/viper v1.16.0 // indirect + github.com/stretchr/testify v1.9.0 // indirect + github.com/subosito/gotenv v1.4.2 // indirect github.com/wk8/go-ordered-map/v2 v2.1.8 // indirect github.com/yosida95/uritemplate/v3 v3.0.2 // indirect + go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace v0.46.1 // indirect + go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.46.1 // indirect + go.opentelemetry.io/contrib/propagators/b3 v1.21.0 // indirect + go.opentelemetry.io/contrib/propagators/jaeger v1.21.1 // indirect + go.opentelemetry.io/contrib/samplers/jaegerremote v0.15.1 // indirect + go.opentelemetry.io/otel v1.21.0 // indirect + go.opentelemetry.io/otel/exporters/jaeger v1.17.0 // indirect + go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.21.0 // indirect + go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.21.0 // indirect + go.opentelemetry.io/otel/exporters/zipkin v1.21.0 // indirect + go.opentelemetry.io/otel/metric v1.21.0 // indirect + go.opentelemetry.io/otel/sdk v1.21.0 // indirect + go.opentelemetry.io/otel/trace v1.21.0 // indirect + go.opentelemetry.io/proto/otlp v1.0.0 // indirect golang.org/x/exp v0.0.0-20251023183803-a4bb9ffd2546 // indirect + golang.org/x/mod v0.33.0 // indirect + golang.org/x/net v0.51.0 // indirect + golang.org/x/oauth2 v0.14.0 // indirect + golang.org/x/sync v0.20.0 // indirect golang.org/x/sys v0.42.0 // indirect + golang.org/x/text v0.35.0 // indirect + golang.org/x/tools v0.42.0 // indirect + google.golang.org/appengine v1.6.8 // indirect + google.golang.org/genproto v0.0.0-20231106174013-bbf56f31fb17 // indirect + google.golang.org/genproto/googleapis/api v0.0.0-20231106174013-bbf56f31fb17 // indirect + google.golang.org/genproto/googleapis/rpc v0.0.0-20231106174013-bbf56f31fb17 // indirect + google.golang.org/grpc v1.59.0 // indirect + google.golang.org/protobuf v1.33.0 // indirect + gopkg.in/ini.v1 v1.67.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect modernc.org/libc v1.67.6 // indirect modernc.org/mathutil v1.7.1 // indirect diff --git a/go.sum b/go.sum index 8823752..e2a4492 100644 --- a/go.sum +++ b/go.sum @@ -1,78 +1,886 @@ +cloud.google.com/go v0.26.0/go.mod h1:aQUYkXzVsufM+DwF1aE+0xfcU+56JwCaLick0ClmMTw= +cloud.google.com/go v0.34.0/go.mod h1:aQUYkXzVsufM+DwF1aE+0xfcU+56JwCaLick0ClmMTw= +cloud.google.com/go v0.38.0/go.mod h1:990N+gfupTy94rShfmMCWGDn0LpTmnzTp2qbd1dvSRU= +cloud.google.com/go v0.44.1/go.mod h1:iSa0KzasP4Uvy3f1mN/7PiObzGgflwredwwASm/v6AU= +cloud.google.com/go v0.44.2/go.mod h1:60680Gw3Yr4ikxnPRS/oxxkBccT6SA1yMk63TGekxKY= +cloud.google.com/go v0.44.3/go.mod h1:60680Gw3Yr4ikxnPRS/oxxkBccT6SA1yMk63TGekxKY= +cloud.google.com/go v0.45.1/go.mod h1:RpBamKRgapWJb87xiFSdk4g1CME7QZg3uwTez+TSTjc= +cloud.google.com/go v0.46.3/go.mod h1:a6bKKbmY7er1mI7TEI4lsAkts/mkhTSZK8w33B4RAg0= +cloud.google.com/go v0.50.0/go.mod h1:r9sluTvynVuxRIOHXQEHMFffphuXHOMZMycpNR5e6To= +cloud.google.com/go v0.52.0/go.mod h1:pXajvRH/6o3+F9jDHZWQ5PbGhn+o8w9qiu/CffaVdO4= +cloud.google.com/go v0.53.0/go.mod h1:fp/UouUEsRkN6ryDKNW/Upv/JBKnv6WDthjR6+vze6M= +cloud.google.com/go v0.54.0/go.mod h1:1rq2OEkV3YMf6n/9ZvGWI3GWw0VoqH/1x2nd8Is/bPc= +cloud.google.com/go v0.56.0/go.mod h1:jr7tqZxxKOVYizybht9+26Z/gUq7tiRzu+ACVAMbKVk= +cloud.google.com/go v0.57.0/go.mod h1:oXiQ6Rzq3RAkkY7N6t3TcE6jE+CIBBbA36lwQ1JyzZs= +cloud.google.com/go v0.62.0/go.mod h1:jmCYTdRCQuc1PHIIJ/maLInMho30T/Y0M4hTdTShOYc= +cloud.google.com/go v0.65.0/go.mod h1:O5N8zS7uWy9vkA9vayVHs65eM1ubvY4h553ofrNHObY= +cloud.google.com/go v0.72.0/go.mod h1:M+5Vjvlc2wnp6tjzE102Dw08nGShTscUx2nZMufOKPI= +cloud.google.com/go v0.74.0/go.mod h1:VV1xSbzvo+9QJOxLDaJfTjx5e+MePCpCWwvftOeQmWk= +cloud.google.com/go v0.75.0/go.mod h1:VGuuCn7PG0dwsd5XPVm2Mm3wlh3EL55/79EKB6hlPTY= +cloud.google.com/go/bigquery v1.0.1/go.mod h1:i/xbL2UlR5RvWAURpBYZTtm/cXjCha9lbfbpx4poX+o= +cloud.google.com/go/bigquery v1.3.0/go.mod h1:PjpwJnslEMmckchkHFfq+HTD2DmtT67aNFKH1/VBDHE= +cloud.google.com/go/bigquery v1.4.0/go.mod h1:S8dzgnTigyfTmLBfrtrhyYhwRxG72rYxvftPBK2Dvzc= +cloud.google.com/go/bigquery v1.5.0/go.mod h1:snEHRnqQbz117VIFhE8bmtwIDY80NLUZUMb4Nv6dBIg= +cloud.google.com/go/bigquery v1.7.0/go.mod h1://okPTzCYNXSlb24MZs83e2Do+h+VXtc4gLoIoXIAPc= +cloud.google.com/go/bigquery v1.8.0/go.mod h1:J5hqkt3O0uAFnINi6JXValWIb1v0goeZM77hZzJN/fQ= +cloud.google.com/go/datastore v1.0.0/go.mod h1:LXYbyblFSglQ5pkeyhO+Qmw7ukd3C+pD7TKLgZqpHYE= +cloud.google.com/go/datastore v1.1.0/go.mod h1:umbIZjpQpHh4hmRpGhH4tLFup+FVzqBi1b3c64qFpCk= +cloud.google.com/go/pubsub v1.0.1/go.mod h1:R0Gpsv3s54REJCy4fxDixWD93lHJMoZTyQ2kNxGRt3I= +cloud.google.com/go/pubsub v1.1.0/go.mod h1:EwwdRX2sKPjnvnqCa270oGRyludottCI76h+R3AArQw= +cloud.google.com/go/pubsub v1.2.0/go.mod h1:jhfEVHT8odbXTkndysNHCcx0awwzvfOlguIAii9o8iA= +cloud.google.com/go/pubsub v1.3.1/go.mod h1:i+ucay31+CNRpDW4Lu78I4xXG+O1r/MAHgjpRVR+TSU= +cloud.google.com/go/storage v1.0.0/go.mod h1:IhtSnM/ZTZV8YYJWCY8RULGVqBDmpoyjwiyrjsg+URw= +cloud.google.com/go/storage v1.5.0/go.mod h1:tpKbwo567HUNpVclU5sGELwQWBDZ8gh0ZeosJ0Rtdos= +cloud.google.com/go/storage v1.6.0/go.mod h1:N7U0C8pVQ/+NIKOBQyamJIeKQKkZ+mxpohlUTyfDhBk= +cloud.google.com/go/storage v1.8.0/go.mod h1:Wv1Oy7z6Yz3DshWRJFhqM/UCfaWIRTdp0RXyy7KQOVs= +cloud.google.com/go/storage v1.10.0/go.mod h1:FLPqc6j+Ki4BU591ie1oL6qBQGu2Bl/tZ9ullr3+Kg0= +cloud.google.com/go/storage v1.14.0/go.mod h1:GrKmX003DSIwi9o29oFT7YDnHYwZoctc3fOKtUw0Xmo= +dmitri.shuralyov.com/gpu/mtl v0.0.0-20190408044501-666a987793e9/go.mod h1:H6x//7gZCb22OMCxBHrMx7a5I7Hp++hsVxbQ4BYO7hU= +github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU= +github.com/BurntSushi/xgb v0.0.0-20160522181843-27f122750802/go.mod h1:IVnqGOEym/WlBOVXweHU+Q+/VP0lqqI8lqeDx9IjBqo= +github.com/Masterminds/semver/v3 v3.1.1/go.mod h1:VPu/7SZ7ePZ3QOrcuXROw5FAcLl4a0cBrbBpGY/8hQs= +github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 h1:DklsrG3dyBCFEj5IhUbnKptjxatkF07cF2ak3yi77so= +github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2/go.mod h1:WaHUgvxTVq04UNunO+XhnAqY/wQc+bxr74GqbsZ/Jqw= +github.com/aymerick/douceur v0.2.0/go.mod h1:wlT5vV2O3h55X9m7iVYN0TBM0NH/MmbLnd30/FjWUq4= github.com/bahlo/generic-list-go v0.2.0 h1:5sz/EEAK+ls5wF+NeqDpk5+iNdMDXrh3z3nPnH1Wvgk= github.com/bahlo/generic-list-go v0.2.0/go.mod h1:2KvAjgMlE5NNynlg/5iLrrCCZ2+5xWbdbCW3pNTGyYg= github.com/buger/jsonparser v1.1.1 h1:2PnMjfWD7wBILjqQbt530v576A/cAbQvEW9gGIpYMUs= github.com/buger/jsonparser v1.1.1/go.mod h1:6RYKKt7H4d4+iWqouImQ9R2FZql3VbhNgx27UK13J/0= +github.com/cenkalti/backoff/v4 v4.3.0 h1:MyRJ/UdXutAwSAT+s3wNd7MfTIcy71VQueUuFK343L8= +github.com/cenkalti/backoff/v4 v4.3.0/go.mod h1:Y3VNntkOUPxTVeUxJ/G5vcM//AlwfmyYozVcomhLiZE= +github.com/census-instrumentation/opencensus-proto v0.2.1/go.mod h1:f6KPmirojxKA12rnyqOA5BBL4O983OfeGPqjHWSTneU= +github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs= +github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs= +github.com/chzyer/logex v1.1.10/go.mod h1:+Ywpsq7O8HXn0nuIou7OrIPyXbp3wmkHB+jjWRnGsAI= +github.com/chzyer/readline v0.0.0-20180603132655-2972be24d48e/go.mod h1:nSuG5e5PlCu98SY8svDHJxuZscDgtXS6KTTbou5AhLI= +github.com/chzyer/test v0.0.0-20180213035817-a1ea475d72b1/go.mod h1:Q3SI9o4m/ZMnBNeIyt5eFwwo7qiLfzFZmjNmxjkiQlU= +github.com/client9/misspell v0.3.4/go.mod h1:qj6jICC3Q7zFZvVWo7KLAzC3yx5G7kyvSDkc90ppPyw= +github.com/cncf/udpa/go v0.0.0-20191209042840-269d4d468f6f/go.mod h1:M8M6+tZqaGXZJjfX53e64911xZQV5JYwmTeXPW+k8Sc= +github.com/cncf/udpa/go v0.0.0-20200629203442-efcf912fb354/go.mod h1:WmhPx2Nbnhtbo57+VJT5O0JRkEi1Wbu0z5j0R8u5Hbk= +github.com/cncf/udpa/go v0.0.0-20201120205902-5459f2c99403/go.mod h1:WmhPx2Nbnhtbo57+VJT5O0JRkEi1Wbu0z5j0R8u5Hbk= +github.com/cockroachdb/apd v1.1.0/go.mod h1:8Sl8LxpKi29FqWXR16WEFZRNSz3SoPzUzeMeY4+DwBQ= +github.com/coreos/go-systemd v0.0.0-20190321100706-95778dfbb74e/go.mod h1:F5haX7vjVVG0kc13fIWeqUViNPyEJxv/OmvnBo0Yme4= +github.com/coreos/go-systemd v0.0.0-20190719114852-fd7a80b32e1f/go.mod h1:F5haX7vjVVG0kc13fIWeqUViNPyEJxv/OmvnBo0Yme4= +github.com/cpuguy83/go-md2man/v2 v2.0.2/go.mod h1:tgQtvFlXSQOSOSIRvRPT7W67SCa46tRHOmNcaadrF8o= github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g= +github.com/creack/pty v1.1.7/go.mod h1:lj5s0c3V2DBrqTV7llrYr5NG6My20zk30Fl46Y7DoTY= +github.com/cristalhq/jwt/v4 v4.0.2 h1:g/AD3h0VicDamtlM70GWGElp8kssQEv+5wYd7L9WOhU= +github.com/cristalhq/jwt/v4 v4.0.2/go.mod h1:HnYraSNKDRag1DZP92rYHyrjyQHnVEHPNqesmzs+miQ= +github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/dgraph-io/ristretto v1.0.0 h1:SYG07bONKMlFDUYu5pEu3DGAh8c2OFNzKm6G9J4Si84= +github.com/dgraph-io/ristretto v1.0.0/go.mod h1:jTi2FiYEhQ1NsMmA7DeBykizjOuY88NhKBkepyu1jPc= +github.com/dgryski/go-farm v0.0.0-20200201041132-a6ae2369ad13 h1:fAjc9m62+UWV/WAFKLNi6ZS0675eEUC9y3AlwSbQu1Y= +github.com/dgryski/go-farm v0.0.0-20200201041132-a6ae2369ad13/go.mod h1:SqUrOPUnsFjfmXRMNPybcSiG0BgUW2AuFH8PAnS2iTw= github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY= github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto= +github.com/envoyproxy/go-control-plane v0.9.0/go.mod h1:YTl/9mNaCwkRvm6d1a2C3ymFceY/DCBVvsKhRF0iEA4= +github.com/envoyproxy/go-control-plane v0.9.1-0.20191026205805-5f8ba28d4473/go.mod h1:YTl/9mNaCwkRvm6d1a2C3ymFceY/DCBVvsKhRF0iEA4= +github.com/envoyproxy/go-control-plane v0.9.4/go.mod h1:6rpuAdCZL397s3pYoYcLgu1mIlRU8Am5FuJP05cCM98= +github.com/envoyproxy/go-control-plane v0.9.7/go.mod h1:cwu0lG7PUMfa9snN8LXBig5ynNVH9qI8YYLbd1fK2po= +github.com/envoyproxy/go-control-plane v0.9.9-0.20201210154907-fd9021fe5dad/go.mod h1:cXg6YxExXjJnVBQHBLXeUAgxn2UodCpnH306RInaBQk= +github.com/envoyproxy/protoc-gen-validate v0.1.0/go.mod h1:iSmxcyjqTsJpI2R4NaDN7+kN2VEUnK/pcBlmesArF7c= +github.com/fatih/color v1.13.0/go.mod h1:kLAiJbzzSOZDVNGyDpeOxJ47H46qBXwg5ILebYFFOfk= +github.com/fatih/color v1.16.0 h1:zmkK9Ngbjj+K0yRhTVONQh1p/HknKYSlNT+vZCzyokM= +github.com/fatih/color v1.16.0/go.mod h1:fL2Sau1YI5c0pdGEVCbKQbLXB6edEj1ZgiY4NijnWvE= +github.com/fatih/structs v1.1.0/go.mod h1:9NiDSp5zOcgEDl+j00MP/WkGVPOlPRLejGD8Ga6PJ7M= +github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg= +github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U= github.com/frankban/quicktest v1.14.6 h1:7Xjx+VpznH+oBnejlPUj8oUpdxnVs4f8XU8WnHkI4W8= github.com/frankban/quicktest v1.14.6/go.mod h1:4ptaffx2x8+WTWXmUCuVU6aPUX1/Mz7zb5vbUoiM6w0= +github.com/fsnotify/fsnotify v1.6.0 h1:n+5WquG0fcWoWp6xPWfHdbskMCQaFnG6PfBrh1Ky4HY= +github.com/fsnotify/fsnotify v1.6.0/go.mod h1:sl3t1tCWJFWoRz9R8WJCbQihKKwmorjAbSClcnxKAGw= github.com/go-chi/chi/v5 v5.2.5 h1:Eg4myHZBjyvJmAFjFvWgrqDTXFyOzjj7YIm3L3mu6Ug= github.com/go-chi/chi/v5 v5.2.5/go.mod h1:X7Gx4mteadT3eDOMTsXzmI4/rwUpOwBHLpAfupzFJP0= +github.com/go-gl/glfw v0.0.0-20190409004039-e6da0acd62b1/go.mod h1:vR7hzQXu2zJy9AVAgeJqvqgH9Q5CA+iKCZ2gyEVpxRU= +github.com/go-gl/glfw/v3.3/glfw v0.0.0-20191125211704-12ad95a8df72/go.mod h1:tQ2UAYgL5IevRw8kRxooKSPJfGvJ9fJQFa0TUsXzTg8= +github.com/go-gl/glfw/v3.3/glfw v0.0.0-20200222043503-6f7a984d4dc4/go.mod h1:tQ2UAYgL5IevRw8kRxooKSPJfGvJ9fJQFa0TUsXzTg8= +github.com/go-jose/go-jose/v3 v3.0.3 h1:fFKWeig/irsp7XD2zBxvnmA/XaRWp5V3CBsZXJF7G7k= +github.com/go-jose/go-jose/v3 v3.0.3/go.mod h1:5b+7YgP7ZICgJDBdfjZaIt+H/9L9T/YQrVfLAMboGkQ= +github.com/go-kit/log v0.1.0/go.mod h1:zbhenjAZHb184qTLMA9ZjW7ThYL0H2mk7Q6pNt4vbaY= +github.com/go-logfmt/logfmt v0.5.0/go.mod h1:wCYkCAKZfumFQihp8CzCvQ3paCTfi41vtzG1KdI/P7A= +github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A= +github.com/go-logr/logr v1.3.0 h1:2y3SDp0ZXuc6/cjLSZ+Q3ir+QB9T/iG5yYRXqsagWSY= +github.com/go-logr/logr v1.3.0/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= +github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag= +github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE= +github.com/go-sql-driver/mysql v1.6.0/go.mod h1:DCzpHaOWr8IXmIStZouvnhqoel9Qv2LBy8hT2VhHyBg= +github.com/go-sql-driver/mysql v1.7.0/go.mod h1:OXbVy3sEdcQ2Doequ6Z5BW6fXNQTmx+9S1MCJN5yJMI= +github.com/go-stack/stack v1.8.0/go.mod h1:v0f6uXyyMGvRgIKkXu+yp6POWl0qKG85gN/melR3HDY= +github.com/gobuffalo/attrs v1.0.3/go.mod h1:KvDJCE0avbufqS0Bw3UV7RQynESY0jjod+572ctX4t8= +github.com/gobuffalo/envy v1.10.2/go.mod h1:qGAGwdvDsaEtPhfBzb3o0SfDea8ByGn9j8bKmVft9z8= +github.com/gobuffalo/fizz v1.14.4/go.mod h1:9/2fGNXNeIFOXEEgTPJwiK63e44RjG+Nc4hfMm1ArGM= +github.com/gobuffalo/flect v0.3.0/go.mod h1:5pf3aGnsvqvCj50AVni7mJJF8ICxGZ8HomberC3pXLE= +github.com/gobuffalo/flect v1.0.0/go.mod h1:l9V6xSb4BlXwsxEMj3FVEub2nkdQjWhPvD8XTTlHPQc= +github.com/gobuffalo/genny/v2 v2.1.0/go.mod h1:4yoTNk4bYuP3BMM6uQKYPvtP6WsXFGm2w2EFYZdRls8= +github.com/gobuffalo/github_flavored_markdown v1.1.3/go.mod h1:IzgO5xS6hqkDmUh91BW/+Qxo/qYnvfzoz3A7uLkg77I= +github.com/gobuffalo/helpers v0.6.7/go.mod h1:j0u1iC1VqlCaJEEVkZN8Ia3TEzfj/zoXANqyJExTMTA= +github.com/gobuffalo/logger v1.0.7/go.mod h1:u40u6Bq3VVvaMcy5sRBclD8SXhBYPS0Qk95ubt+1xJM= +github.com/gobuffalo/nulls v0.4.2/go.mod h1:EElw2zmBYafU2R9W4Ii1ByIj177wA/pc0JdjtD0EsH8= +github.com/gobuffalo/packd v1.0.2/go.mod h1:sUc61tDqGMXON80zpKGp92lDb86Km28jfvX7IAyxFT8= +github.com/gobuffalo/plush/v4 v4.1.16/go.mod h1:6t7swVsarJ8qSLw1qyAH/KbrcSTwdun2ASEQkOznakg= +github.com/gobuffalo/plush/v4 v4.1.18/go.mod h1:xi2tJIhFI4UdzIL8sxZtzGYOd2xbBpcFbLZlIPGGZhU= +github.com/gobuffalo/pop/v6 v6.1.1 h1:eUDBaZcb0gYrmFnKwpuTEUA7t5ZHqNfvS4POqJYXDZY= +github.com/gobuffalo/pop/v6 v6.1.1/go.mod h1:1n7jAmI1i7fxuXPZjZb0VBPQDbksRtCoFnrDV5IsvaI= +github.com/gobuffalo/tags/v3 v3.1.4/go.mod h1:ArRNo3ErlHO8BtdA0REaZxijuWnWzF6PUXngmMXd2I0= +github.com/gobuffalo/validate/v3 v3.3.3/go.mod h1:YC7FsbJ/9hW/VjQdmXPvFqvRis4vrRYFxr69WiNZw6g= +github.com/gofrs/uuid v4.0.0+incompatible/go.mod h1:b2aQJv3Z4Fp6yNu3cdSllBxTCLRxnplIgP/c0N/04lM= +github.com/gofrs/uuid v4.2.0+incompatible/go.mod h1:b2aQJv3Z4Fp6yNu3cdSllBxTCLRxnplIgP/c0N/04lM= +github.com/gofrs/uuid v4.3.1+incompatible/go.mod h1:b2aQJv3Z4Fp6yNu3cdSllBxTCLRxnplIgP/c0N/04lM= +github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q= +github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q= +github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q= +github.com/golang/groupcache v0.0.0-20190702054246-869f871628b6/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc= +github.com/golang/groupcache v0.0.0-20191227052852-215e87163ea7/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc= +github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc= +github.com/golang/mock v1.1.1/go.mod h1:oTYuIxOrZwtPieC+H1uAHpcLFnEyAGVDL/k47Jfbm0A= +github.com/golang/mock v1.2.0/go.mod h1:oTYuIxOrZwtPieC+H1uAHpcLFnEyAGVDL/k47Jfbm0A= +github.com/golang/mock v1.3.1/go.mod h1:sBzyDLLjw3U8JLTeZvSv8jJB+tU5PVekmnlKIyFUx0Y= +github.com/golang/mock v1.4.0/go.mod h1:UOMv5ysSaYNkG+OFQykRIcU/QvvxJf3p21QfJ2Bt3cw= +github.com/golang/mock v1.4.1/go.mod h1:UOMv5ysSaYNkG+OFQykRIcU/QvvxJf3p21QfJ2Bt3cw= +github.com/golang/mock v1.4.3/go.mod h1:UOMv5ysSaYNkG+OFQykRIcU/QvvxJf3p21QfJ2Bt3cw= +github.com/golang/mock v1.4.4/go.mod h1:l3mdAwkq5BuhzHwde/uurv3sEJeZMXNpwsxVWU71h+4= +github.com/golang/mock v1.6.0 h1:ErTB+efbowRARo13NNdxyJji2egdxLGQhRaY+DUumQc= +github.com/golang/mock v1.6.0/go.mod h1:p6yTPP+5HYm5mzsMV8JkE6ZKdX+/wYM6Hr+LicevLPs= +github.com/golang/protobuf v1.2.0/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U= +github.com/golang/protobuf v1.3.1/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U= +github.com/golang/protobuf v1.3.2/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U= +github.com/golang/protobuf v1.3.3/go.mod h1:vzj43D7+SQXF/4pzW/hwtAqwc6iTitCiVSaWz5lYuqw= +github.com/golang/protobuf v1.3.4/go.mod h1:vzj43D7+SQXF/4pzW/hwtAqwc6iTitCiVSaWz5lYuqw= +github.com/golang/protobuf v1.3.5/go.mod h1:6O5/vntMXwX2lRkT1hjjk0nAC1IDOTvTlVgjlRvqsdk= +github.com/golang/protobuf v1.4.0-rc.1/go.mod h1:ceaxUfeHdC40wWswd/P6IGgMaK3YpKi5j83Wpe3EHw8= +github.com/golang/protobuf v1.4.0-rc.1.0.20200221234624-67d41d38c208/go.mod h1:xKAWHe0F5eneWXFV3EuXVDTCmh+JuBKY0li0aMyXATA= +github.com/golang/protobuf v1.4.0-rc.2/go.mod h1:LlEzMj4AhA7rCAGe4KMBDvJI+AwstrUpVNzEA03Pprs= +github.com/golang/protobuf v1.4.0-rc.4.0.20200313231945-b860323f09d0/go.mod h1:WU3c8KckQ9AFe+yFwt9sWVRKCVIyN9cPHBJSNnbL67w= +github.com/golang/protobuf v1.4.0/go.mod h1:jodUvKwWbYaEsadDk5Fwe5c77LiNKVO9IDvqG2KuDX0= +github.com/golang/protobuf v1.4.1/go.mod h1:U8fpvMrcmy5pZrNK1lt4xCsGvpyWQ/VVv6QDs8UjoX8= +github.com/golang/protobuf v1.4.2/go.mod h1:oDoupMAO8OvCJWAcko0GGGIgR6R6ocIYbsSw735rRwI= +github.com/golang/protobuf v1.4.3/go.mod h1:oDoupMAO8OvCJWAcko0GGGIgR6R6ocIYbsSw735rRwI= +github.com/golang/protobuf v1.5.0/go.mod h1:FsONVRAS9T7sI+LIUmWTfcYkHO4aIWwzhcaSAoJOfIk= +github.com/golang/protobuf v1.5.2/go.mod h1:XVQd3VNwM+JqD3oG2Ue2ip4fOMUkwXdXDdiuN0vRsmY= +github.com/golang/protobuf v1.5.3 h1:KhyjKVUg7Usr/dYsdSqoFveMYd5ko72D+zANwlG1mmg= +github.com/golang/protobuf v1.5.3/go.mod h1:XVQd3VNwM+JqD3oG2Ue2ip4fOMUkwXdXDdiuN0vRsmY= +github.com/google/btree v0.0.0-20180813153112-4030bb1f1f0c/go.mod h1:lNA+9X1NB3Zf8V7Ke586lFgjr2dZNuvo3lPJSGZ5JPQ= +github.com/google/btree v1.0.0/go.mod h1:lNA+9X1NB3Zf8V7Ke586lFgjr2dZNuvo3lPJSGZ5JPQ= +github.com/google/go-cmp v0.2.0/go.mod h1:oXzfMopK8JAjlY9xF4vHSVASa0yLyX7SntLO5aqRK0M= +github.com/google/go-cmp v0.3.0/go.mod h1:8QqcDgzrUqlUb/G2PQTWiueGozuR1884gddMywk6iLU= +github.com/google/go-cmp v0.3.1/go.mod h1:8QqcDgzrUqlUb/G2PQTWiueGozuR1884gddMywk6iLU= +github.com/google/go-cmp v0.4.0/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= +github.com/google/go-cmp v0.4.1/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= +github.com/google/go-cmp v0.5.0/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= +github.com/google/go-cmp v0.5.1/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= +github.com/google/go-cmp v0.5.2/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= +github.com/google/go-cmp v0.5.4/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= +github.com/google/go-cmp v0.5.5/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE= +github.com/google/go-cmp v0.5.9/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI= github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= +github.com/google/martian v2.1.0+incompatible/go.mod h1:9I4somxYTbIHy5NJKHRl3wXiIaQGbYVAs8BPL6v8lEs= +github.com/google/martian/v3 v3.0.0/go.mod h1:y5Zk1BBys9G+gd6Jrk0W3cC1+ELVxBWuIGO+w/tUAp0= +github.com/google/martian/v3 v3.1.0/go.mod h1:y5Zk1BBys9G+gd6Jrk0W3cC1+ELVxBWuIGO+w/tUAp0= +github.com/google/pprof v0.0.0-20181206194817-3ea8567a2e57/go.mod h1:zfwlbNMJ+OItoe0UupaVj+oy1omPYYDuagoSzA8v9mc= +github.com/google/pprof v0.0.0-20190515194954-54271f7e092f/go.mod h1:zfwlbNMJ+OItoe0UupaVj+oy1omPYYDuagoSzA8v9mc= +github.com/google/pprof v0.0.0-20191218002539-d4f498aebedc/go.mod h1:ZgVRPoUq/hfqzAqh7sHMqb3I9Rq5C59dIz2SbBwJ4eM= +github.com/google/pprof v0.0.0-20200212024743-f11f1df84d12/go.mod h1:ZgVRPoUq/hfqzAqh7sHMqb3I9Rq5C59dIz2SbBwJ4eM= +github.com/google/pprof v0.0.0-20200229191704-1ebb73c60ed3/go.mod h1:ZgVRPoUq/hfqzAqh7sHMqb3I9Rq5C59dIz2SbBwJ4eM= +github.com/google/pprof v0.0.0-20200430221834-fc25d7d30c6d/go.mod h1:ZgVRPoUq/hfqzAqh7sHMqb3I9Rq5C59dIz2SbBwJ4eM= +github.com/google/pprof v0.0.0-20200708004538-1a94d8640e99/go.mod h1:ZgVRPoUq/hfqzAqh7sHMqb3I9Rq5C59dIz2SbBwJ4eM= +github.com/google/pprof v0.0.0-20201023163331-3e6fc7fc9c4c/go.mod h1:kpwsk12EmLew5upagYY7GY0pfYCcupk39gWOCRROcvE= +github.com/google/pprof v0.0.0-20201203190320-1bf35d6f28c2/go.mod h1:kpwsk12EmLew5upagYY7GY0pfYCcupk39gWOCRROcvE= +github.com/google/pprof v0.0.0-20201218002935-b9804c9f04c2/go.mod h1:kpwsk12EmLew5upagYY7GY0pfYCcupk39gWOCRROcvE= github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e h1:ijClszYn+mADRFY17kjQEVQ1XRhq2/JR1M3sGqeJoxs= github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e/go.mod h1:boTsfXsheKC2y+lKOCMpSfarhxDeIzfZG1jqGcPl3cA= +github.com/google/renameio v0.1.0/go.mod h1:KWCgfxg9yswjAJkECMjeO8J8rahYeXnNhOm40UhjYkI= +github.com/google/uuid v1.1.2/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= +github.com/googleapis/gax-go/v2 v2.0.4/go.mod h1:0Wqv26UfaUD9n4G6kQubkQ+KchISgw+vpHVxEJEs9eg= +github.com/googleapis/gax-go/v2 v2.0.5/go.mod h1:DWXyrwAJ9X0FpwwEdw+IPEYBICEFu5mhpdKc/us6bOk= +github.com/googleapis/google-cloud-go-testing v0.0.0-20200911160855-bcd43fbb19e8/go.mod h1:dvDLG8qkwmyD9a/MJJN3XJcT3xFxOKAvTZGvuZmac9g= +github.com/gorilla/css v1.0.0/go.mod h1:Dn721qIggHpt4+EFCcTLTU/vk5ySda2ReITrtgBl60c= +github.com/gorilla/websocket v1.5.0 h1:PPwGk2jz7EePpoHN/+ClbZu8SPxiqlu12wZP/3sWmnc= +github.com/gorilla/websocket v1.5.0/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/adAjf1fMHhE= +github.com/grpc-ecosystem/grpc-gateway/v2 v2.18.1 h1:6UKoz5ujsI55KNpsJH3UwCq3T8kKbZwNZBNPuTTje8U= +github.com/grpc-ecosystem/grpc-gateway/v2 v2.18.1/go.mod h1:YvJ2f6MplWDhfxiUC3KpyTy76kYUZA4W3pTv/wdKQ9Y= +github.com/hashicorp/go-cleanhttp v0.5.2 h1:035FKYIWjmULyFRBKPs8TBQoi0x6d9G4xc9neXJWAZQ= +github.com/hashicorp/go-cleanhttp v0.5.2/go.mod h1:kO/YDlP8L1346E6Sodw+PrpBSV4/SoxCXGY6BqNFT48= +github.com/hashicorp/go-hclog v1.6.3 h1:Qr2kF+eVWjTiYmU7Y31tYlP1h0q/X3Nl3tPGdaB11/k= +github.com/hashicorp/go-hclog v1.6.3/go.mod h1:W4Qnvbt70Wk/zYJryRzDRU/4r0kIg0PVHBcfoyhpF5M= +github.com/hashicorp/go-retryablehttp v0.7.7 h1:C8hUCYzor8PIfXHa4UrZkU4VvK8o9ISHxT2Q8+VepXU= +github.com/hashicorp/go-retryablehttp v0.7.7/go.mod h1:pkQpWZeYWskR+D1tR2O5OcBFOxfA7DoAO6xtkuQnHTk= +github.com/hashicorp/golang-lru v0.5.0/go.mod h1:/m3WP610KZHVQ1SGc6re/UDhFvYD7pJ4Ao+sR/qLZy8= +github.com/hashicorp/golang-lru v0.5.1/go.mod h1:/m3WP610KZHVQ1SGc6re/UDhFvYD7pJ4Ao+sR/qLZy8= +github.com/hashicorp/golang-lru v0.5.4 h1:YDjusn29QI/Das2iO9M0BHnIbxPeyuCHsjMW+lJfyTc= github.com/hashicorp/golang-lru/v2 v2.0.7 h1:a+bsQ5rvGLjzHuww6tVxozPZFVghXaHOwFs4luLUK2k= github.com/hashicorp/golang-lru/v2 v2.0.7/go.mod h1:QeFd9opnmA6QUJc5vARoKUSoFhyfM2/ZepoAG6RGpeM= +github.com/hashicorp/hcl v1.0.0 h1:0Anlzjpi4vEasTeNFn2mLJgTSwt0+6sfsiTG8qcWGx4= +github.com/hashicorp/hcl v1.0.0/go.mod h1:E5yfLk+7swimpb2L/Alb/PJmXilQ/rhwaUYs4T20WEQ= +github.com/ianlancetaylor/demangle v0.0.0-20181102032728-5e5cf60278f6/go.mod h1:aSSvb/t6k1mPoxDqO4vJh6VOCGPwU4O0C2/Eqndh1Sc= +github.com/ianlancetaylor/demangle v0.0.0-20200824232613-28f6c0f3b639/go.mod h1:aSSvb/t6k1mPoxDqO4vJh6VOCGPwU4O0C2/Eqndh1Sc= +github.com/inconshreveable/mousetrap v1.0.1/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8= github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= github.com/invopop/jsonschema v0.13.0 h1:KvpoAJWEjR3uD9Kbm2HWJmqsEaHt8lBUpd0qHcIi21E= github.com/invopop/jsonschema v0.13.0/go.mod h1:ffZ5Km5SWWRAIN6wbDXItl95euhFz2uON45H2qjYt+0= +github.com/jackc/chunkreader v1.0.0/go.mod h1:RT6O25fNZIuasFJRyZ4R/Y2BbhasbmZXF9QQ7T3kePo= +github.com/jackc/chunkreader/v2 v2.0.0/go.mod h1:odVSm741yZoC3dpHEUXIqA9tQRhFrgOHwnPIn9lDKlk= +github.com/jackc/chunkreader/v2 v2.0.1/go.mod h1:odVSm741yZoC3dpHEUXIqA9tQRhFrgOHwnPIn9lDKlk= +github.com/jackc/pgconn v0.0.0-20190420214824-7e0022ef6ba3/go.mod h1:jkELnwuX+w9qN5YIfX0fl88Ehu4XC3keFuOJJk9pcnA= +github.com/jackc/pgconn v0.0.0-20190824142844-760dd75542eb/go.mod h1:lLjNuW/+OfW9/pnVKPazfWOgNfH2aPem8YQ7ilXGvJE= +github.com/jackc/pgconn v0.0.0-20190831204454-2fabfa3c18b7/go.mod h1:ZJKsE/KZfsUgOEh9hBm+xYTstcNHg7UPMVJqRfQxq4s= +github.com/jackc/pgconn v1.8.0/go.mod h1:1C2Pb36bGIP9QHGBYCjnyhqu7Rv3sGshaQUvmfGIB/o= +github.com/jackc/pgconn v1.9.0/go.mod h1:YctiPyvzfU11JFxoXokUOOKQXQmDMoJL9vJzHH8/2JY= +github.com/jackc/pgconn v1.9.1-0.20210724152538-d89c8390a530/go.mod h1:4z2w8XhRbP1hYxkpTuBjTS3ne3J48K83+u0zoyvg2pI= +github.com/jackc/pgconn v1.13.0/go.mod h1:AnowpAqO4CMIIJNZl2VJp+KrkAZciAkhEl0W0JIobpI= +github.com/jackc/pgio v1.0.0/go.mod h1:oP+2QK2wFfUWgr+gxjoBH9KGBb31Eio69xUb0w5bYf8= +github.com/jackc/pgmock v0.0.0-20190831213851-13a1b77aafa2/go.mod h1:fGZlG77KXmcq05nJLRkk0+p82V8B8Dw8KN2/V9c/OAE= +github.com/jackc/pgmock v0.0.0-20201204152224-4fe30f7445fd/go.mod h1:hrBW0Enj2AZTNpt/7Y5rr2xe/9Mn757Wtb2xeBzPv2c= +github.com/jackc/pgmock v0.0.0-20210724152146-4ad1a8207f65/go.mod h1:5R2h2EEX+qri8jOWMbJCtaPWkrrNc7OHwsp2TCqp7ak= +github.com/jackc/pgpassfile v1.0.0/go.mod h1:CEx0iS5ambNFdcRtxPj5JhEz+xB6uRky5eyVu/W2HEg= +github.com/jackc/pgproto3 v1.1.0/go.mod h1:eR5FA3leWg7p9aeAqi37XOTgTIbkABlvcPB3E5rlc78= +github.com/jackc/pgproto3/v2 v2.0.0-alpha1.0.20190420180111-c116219b62db/go.mod h1:bhq50y+xrl9n5mRYyCBFKkpRVTLYJVWeCc+mEAI3yXA= +github.com/jackc/pgproto3/v2 v2.0.0-alpha1.0.20190609003834-432c2951c711/go.mod h1:uH0AWtUmuShn0bcesswc4aBTWGvw0cAxIJp+6OB//Wg= +github.com/jackc/pgproto3/v2 v2.0.0-rc3/go.mod h1:ryONWYqW6dqSg1Lw6vXNMXoBJhpzvWKnT95C46ckYeM= +github.com/jackc/pgproto3/v2 v2.0.0-rc3.0.20190831210041-4c03ce451f29/go.mod h1:ryONWYqW6dqSg1Lw6vXNMXoBJhpzvWKnT95C46ckYeM= +github.com/jackc/pgproto3/v2 v2.0.6/go.mod h1:WfJCnwN3HIg9Ish/j3sgWXnAfK8A9Y0bwXYU5xKaEdA= +github.com/jackc/pgproto3/v2 v2.1.1/go.mod h1:WfJCnwN3HIg9Ish/j3sgWXnAfK8A9Y0bwXYU5xKaEdA= +github.com/jackc/pgproto3/v2 v2.3.1/go.mod h1:WfJCnwN3HIg9Ish/j3sgWXnAfK8A9Y0bwXYU5xKaEdA= +github.com/jackc/pgservicefile v0.0.0-20200714003250-2b9c44734f2b/go.mod h1:vsD4gTJCa9TptPL8sPkXrLZ+hDuNrZCnj29CQpr4X1E= +github.com/jackc/pgtype v0.0.0-20190421001408-4ed0de4755e0/go.mod h1:hdSHsc1V01CGwFsrv11mJRHWJ6aifDLfdV3aVjFF0zg= +github.com/jackc/pgtype v0.0.0-20190824184912-ab885b375b90/go.mod h1:KcahbBH1nCMSo2DXpzsoWOAfFkdEtEJpPbVLq8eE+mc= +github.com/jackc/pgtype v0.0.0-20190828014616-a8802b16cc59/go.mod h1:MWlu30kVJrUS8lot6TQqcg7mtthZ9T0EoIBFiJcmcyw= +github.com/jackc/pgtype v1.8.1-0.20210724151600-32e20a603178/go.mod h1:C516IlIV9NKqfsMCXTdChteoXmwgUceqaLfjg2e3NlM= +github.com/jackc/pgtype v1.12.0/go.mod h1:LUMuVrfsFfdKGLw+AFFVv6KtHOFMwRgDDzBt76IqCA4= +github.com/jackc/pgx/v4 v4.0.0-20190420224344-cc3461e65d96/go.mod h1:mdxmSJJuR08CZQyj1PVQBHy9XOp5p8/SHH6a0psbY9Y= +github.com/jackc/pgx/v4 v4.0.0-20190421002000-1b8f0016e912/go.mod h1:no/Y67Jkk/9WuGR0JG/JseM9irFbnEPbuWV2EELPNuM= +github.com/jackc/pgx/v4 v4.0.0-pre1.0.20190824185557-6972a5742186/go.mod h1:X+GQnOEnf1dqHGpw7JmHqHc1NxDoalibchSk9/RWuDc= +github.com/jackc/pgx/v4 v4.12.1-0.20210724153913-640aa07df17c/go.mod h1:1QD0+tgSXP7iUjYm9C1NxKhny7lq6ee99u/z+IHFcgs= +github.com/jackc/pgx/v4 v4.17.2/go.mod h1:lcxIZN44yMIrWI78a5CpucdD14hX0SBDbNRvjDBItsw= +github.com/jackc/puddle v0.0.0-20190413234325-e4ced69a3a2b/go.mod h1:m4B5Dj62Y0fbyuIc15OsIqK0+JU8nkqQjsgx7dvjSWk= +github.com/jackc/puddle v0.0.0-20190608224051-11cab39313c9/go.mod h1:m4B5Dj62Y0fbyuIc15OsIqK0+JU8nkqQjsgx7dvjSWk= +github.com/jackc/puddle v1.1.3/go.mod h1:m4B5Dj62Y0fbyuIc15OsIqK0+JU8nkqQjsgx7dvjSWk= +github.com/jackc/puddle v1.3.0/go.mod h1:m4B5Dj62Y0fbyuIc15OsIqK0+JU8nkqQjsgx7dvjSWk= +github.com/jandelgado/gcov2lcov v1.0.5 h1:rkBt40h0CVK4oCb8Dps950gvfd1rYvQ8+cWa346lVU0= +github.com/jandelgado/gcov2lcov v1.0.5/go.mod h1:NnSxK6TMlg1oGDBfGelGbjgorT5/L3cchlbtgFYZSss= +github.com/jmoiron/sqlx v1.3.5/go.mod h1:nRVWtLre0KfCLJvgxzCsLVMogSvQ1zNJtpYr2Ccp0mQ= +github.com/joho/godotenv v1.4.0/go.mod h1:f4LDr5Voq0i2e/R5DDNOoa2zzDfwtkZa6DnEwAbqwq4= github.com/josharian/intern v1.0.0/go.mod h1:5DoeVV0s6jJacbCEi61lwdGj/aVlrQvzHFFd8Hwg//Y= +github.com/jstemmer/go-junit-report v0.0.0-20190106144839-af01ea7f8024/go.mod h1:6v2b51hI/fHJwM22ozAgKL4VKDeJcHhJFhtBdhmNjmU= +github.com/jstemmer/go-junit-report v0.9.1/go.mod h1:Brl9GWCQeLvo8nXZwPNNblvFj/XSXhF0NWZEnDohbsk= +github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51/go.mod h1:CzGEWj7cYgsdH8dAjBGEr58BoE7ScuLd+fwFZ44+/x8= +github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8= +github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck= +github.com/knadh/koanf/maps v0.1.1 h1:G5TjmUh2D7G2YWf5SQQqSiHRJEjaicvU0KpypqB3NIs= +github.com/knadh/koanf/maps v0.1.1/go.mod h1:npD/QZY3V6ghQDdcQzl1W4ICNVTkohC8E73eI2xW4yI= +github.com/knadh/koanf/parsers/json v0.1.0 h1:dzSZl5pf5bBcW0Acnu20Djleto19T0CfHcvZ14NJ6fU= +github.com/knadh/koanf/parsers/json v0.1.0/go.mod h1:ll2/MlXcZ2BfXD6YJcjVFzhG9P0TdJ207aIBKQhV2hY= +github.com/knadh/koanf/providers/rawbytes v0.1.0 h1:dpzgu2KO6uf6oCb4aP05KDmKmAmI51k5pe8RYKQ0qME= +github.com/knadh/koanf/providers/rawbytes v0.1.0/go.mod h1:mMTB1/IcJ/yE++A2iEZbY1MLygX7vttU+C+S/YmPu9c= +github.com/knadh/koanf/v2 v2.0.1 h1:1dYGITt1I23x8cfx8ZnldtezdyaZtfAuRtIFOiRzK7g= +github.com/knadh/koanf/v2 v2.0.1/go.mod h1:ZeiIlIDXTE7w1lMT6UVcNiRAS2/rCeLn/GdLNvY1Dus= +github.com/konsorten/go-windows-terminal-sequences v1.0.1/go.mod h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ= +github.com/konsorten/go-windows-terminal-sequences v1.0.2/go.mod h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ= +github.com/kr/fs v0.1.0/go.mod h1:FFnZGqtBN9Gxj7eW1uZ42v5BccTP0vu6NEaFoC2HwRg= +github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo= github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE= github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= +github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ= +github.com/kr/pty v1.1.8/go.mod h1:O1sed60cT9XZ5uDucP5qwvh+TE3NnUj51EiZO/lmSfw= +github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE= +github.com/lib/pq v1.0.0/go.mod h1:5WUZQaWbwv1U+lTReE5YruASi9Al49XbQIvNi/34Woo= +github.com/lib/pq v1.1.0/go.mod h1:5WUZQaWbwv1U+lTReE5YruASi9Al49XbQIvNi/34Woo= +github.com/lib/pq v1.2.0/go.mod h1:5WUZQaWbwv1U+lTReE5YruASi9Al49XbQIvNi/34Woo= +github.com/lib/pq v1.10.2/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o= +github.com/lib/pq v1.10.7/go.mod h1:AlVN5x4E4T544tWzH6hKfbfQvm3HdbOxrmggDNAPY9o= +github.com/luna-duclos/instrumentedsql v1.1.3/go.mod h1:9J1njvFds+zN7y85EDhN9XNQLANWwZt2ULeIC8yMNYs= +github.com/magiconair/properties v1.8.7 h1:IeQXZAiQcpL9mgcAe1Nu6cX9LLw6ExEHKjN0VQdvPDY= +github.com/magiconair/properties v1.8.7/go.mod h1:Dhd985XPs7jluiymwWYZ0G4Z61jb3vdS329zhj2hYo0= github.com/mailru/easyjson v0.7.7 h1:UGYAvKxe3sBsEDzO8ZeWOSlIQfWFlxbzLZe7hwFURr0= github.com/mailru/easyjson v0.7.7/go.mod h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc= github.com/mark3labs/mcp-go v0.45.0 h1:s0S8qR/9fWaQ3pHxz7pm1uQ0DrswoSnRIxKIjbiQtkc= github.com/mark3labs/mcp-go v0.45.0/go.mod h1:YnJfOL382MIWDx1kMY+2zsRHU/q78dBg9aFb8W6Thdw= +github.com/mattn/go-colorable v0.1.1/go.mod h1:FuOcm+DKB9mbwrcAfNl7/TZVBZ6rcnceauSikq3lYCQ= +github.com/mattn/go-colorable v0.1.6/go.mod h1:u6P/XSegPjTcexA+o6vUJrdnUu04hMope9wVRipJSqc= +github.com/mattn/go-colorable v0.1.9/go.mod h1:u6P/XSegPjTcexA+o6vUJrdnUu04hMope9wVRipJSqc= +github.com/mattn/go-colorable v0.1.13 h1:fFA4WZxdEF4tXPZVKMLwD8oUnCTTo08duU7wxecdEvA= +github.com/mattn/go-colorable v0.1.13/go.mod h1:7S9/ev0klgBDR4GtXTXX8a3vIGJpMovkB8vQcUbaXHg= +github.com/mattn/go-isatty v0.0.5/go.mod h1:Iq45c/XA43vh69/j3iqttzPXn0bhXyGjM0Hdxcsrc5s= +github.com/mattn/go-isatty v0.0.7/go.mod h1:Iq45c/XA43vh69/j3iqttzPXn0bhXyGjM0Hdxcsrc5s= +github.com/mattn/go-isatty v0.0.12/go.mod h1:cbi8OIDigv2wuxKPP5vlRcQ1OAZbq2CE4Kysco4FUpU= +github.com/mattn/go-isatty v0.0.14/go.mod h1:7GGIvUiUoEMVVmxf/4nioHXj79iQHKdU27kJ6hsGG94= github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY= github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y= +github.com/mattn/go-sqlite3 v1.14.6/go.mod h1:NyWgC/yNuGj7Q9rpYnZvas74GogHl5/Z4A/KQRfk6bU= +github.com/mattn/go-sqlite3 v1.14.15/go.mod h1:2eHXhiwb8IkHr+BDWZGa96P6+rkvnG63S2DGjv9HUNg= +github.com/mattn/go-sqlite3 v1.14.16/go.mod h1:2eHXhiwb8IkHr+BDWZGa96P6+rkvnG63S2DGjv9HUNg= +github.com/mattn/goveralls v0.0.12 h1:PEEeF0k1SsTjOBQ8FOmrOAoCu4ytuMaWCnWe94zxbCg= +github.com/mattn/goveralls v0.0.12/go.mod h1:44ImGEUfmqH8bBtaMrYKsM65LXfNLWmwaxFGjZwgMSQ= +github.com/microcosm-cc/bluemonday v1.0.20/go.mod h1:yfBmMi8mxvaZut3Yytv+jTXRY8mxyjJ0/kQBTElld50= +github.com/mitchellh/copystructure v1.2.0 h1:vpKXTN4ewci03Vljg/q9QvCGUDttBOGBIa15WveJJGw= +github.com/mitchellh/copystructure v1.2.0/go.mod h1:qLl+cE2AmVv+CoeAwDPye/v+N2HKCj9FbZEVFJRxO9s= +github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY= +github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo= +github.com/mitchellh/reflectwalk v1.0.2 h1:G2LzWKi524PWgd3mLHV8Y5k7s6XUvT0Gef6zxSIeXaQ= +github.com/mitchellh/reflectwalk v1.0.2/go.mod h1:mSTlrgnPZtwu0c4WaC2kGObEpuNDbx0jmZXqmk4esnw= +github.com/mohae/deepcopy v0.0.0-20170929034955-c48cc78d4826 h1:RWengNIwukTxcDr9M+97sNutRR1RKhG96O6jWumTTnw= +github.com/mohae/deepcopy v0.0.0-20170929034955-c48cc78d4826/go.mod h1:TaXosZuwdSHYgviHp1DAtfrULt5eUgsSMsZf+YrPgl8= github.com/ncruces/go-strftime v1.0.0 h1:HMFp8mLCTPp341M/ZnA4qaf7ZlsbTc+miZjCLOFAw7w= github.com/ncruces/go-strftime v1.0.0/go.mod h1:Fwc5htZGVVkseilnfgOVb9mKy6w1naJmn9CehxcKcls= +github.com/nyaruka/phonenumbers v1.1.6 h1:DcueYq7QrOArAprAYNoQfDgp0KetO4LqtnBtQC6Wyes= +github.com/nyaruka/phonenumbers v1.1.6/go.mod h1:yShPJHDSH3aTKzCbXyVxNpbl2kA+F+Ne5Pun/MvFRos= +github.com/oleiade/reflections v1.0.1 h1:D1XO3LVEYroYskEsoSiGItp9RUxG6jWnCVvrqH0HHQM= +github.com/oleiade/reflections v1.0.1/go.mod h1:rdFxbxq4QXVZWj0F+e9jqjDkc7dbp97vkRixKo2JR60= +github.com/openzipkin/zipkin-go v0.4.2 h1:zjqfqHjUpPmB3c1GlCvvgsM1G4LkvqQbBDueDOCg/jA= +github.com/openzipkin/zipkin-go v0.4.2/go.mod h1:ZeVkFjuuBiSy13y8vpSDCjMi9GoI3hPpCJSBx/EYFhY= +github.com/ory/fosite v0.49.0 h1:KNqO7RVt/1X8F08/UI0Y+GRvcpscCWgjqvpLBQPRovo= +github.com/ory/fosite v0.49.0/go.mod h1:FAn7IY+I6DjT1r29wMouPeRYq63DWUuBj++96uOS4mE= +github.com/ory/go-acc v0.2.9-0.20230103102148-6b1c9a70dbbe h1:rvu4obdvqR0fkSIJ8IfgzKOWwZ5kOT2UNfLq81Qk7rc= +github.com/ory/go-acc v0.2.9-0.20230103102148-6b1c9a70dbbe/go.mod h1:z4n3u6as84LbV4YmgjHhnwtccQqzf4cZlSk9f1FhygI= +github.com/ory/go-convenience v0.1.0 h1:zouLKfF2GoSGnJwGq+PE/nJAE6dj2Zj5QlTgmMTsTS8= +github.com/ory/go-convenience v0.1.0/go.mod h1:uEY/a60PL5c12nYz4V5cHY03IBmwIAEm8TWB0yn9KNs= +github.com/ory/herodot v0.10.2 h1:gGvNMHgAwWzdP/eo+roSiT5CGssygHSjDU7MSQNlJ4E= +github.com/ory/herodot v0.10.2/go.mod h1:MMNmY6MG1uB6fnXYFaHoqdV23DTWctlPsmRCeq/2+wc= +github.com/ory/jsonschema/v3 v3.0.8 h1:Ssdb3eJ4lDZ/+XnGkvQS/te0p+EkolqwTsDOCxr/FmU= +github.com/ory/jsonschema/v3 v3.0.8/go.mod h1:ZPzqjDkwd3QTnb2Z6PAS+OTvBE2x5i6m25wCGx54W/0= +github.com/ory/x v0.0.665 h1:61vv0ObCDSX1vOQYbxBeqDiv4YiPmMT91lYxDaaKX08= +github.com/ory/x v0.0.665/go.mod h1:7SCTki3N0De3ZpqlxhxU/94ZrOCfNEnXwVtd0xVt+L8= +github.com/pelletier/go-toml/v2 v2.0.9 h1:uH2qQXheeefCCkuBBSLi7jCiSmj3VRh2+Goq2N7Xxu0= +github.com/pelletier/go-toml/v2 v2.0.9/go.mod h1:tJU2Z3ZkXwnxa4DPO899bsyIoywizdUvyaeZurnPPDc= +github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e/go.mod h1:pJLUxLENpZxwdsKMEsNbx1VGcRFpLqf3715MtcvvzbA= +github.com/pkg/errors v0.8.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= +github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4= +github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= +github.com/pkg/sftp v1.13.1/go.mod h1:3HaPG6Dq1ILlpPZRO0HVMrsydcdLt6HRDccSgb87qRg= github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= +github.com/prometheus/client_model v0.0.0-20190812154241-14fe0d1b01d4/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA= github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE= github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo= -github.com/rogpeppe/go-internal v1.9.0 h1:73kH8U+JUqXU8lRuOHeVHaa/SZPifC7BkcraZVejAe8= +github.com/rogpeppe/go-internal v1.3.0/go.mod h1:M8bDsm7K2OlrFYOpmOWEs/qY81heoFRclV5y23lUDJ4= github.com/rogpeppe/go-internal v1.9.0/go.mod h1:WtVeX8xhTBvf0smdhujwtBcq4Qrzq/fJaraNFVN+nFs= +github.com/rogpeppe/go-internal v1.10.0 h1:TMyTOH3F/DB16zRVcYyreMH6GnZZrwQVAoYjRBZyWFQ= +github.com/rogpeppe/go-internal v1.10.0/go.mod h1:UQnix2H7Ngw/k4C5ijL5+65zddjncjaFoBhdsK/akog= +github.com/rs/xid v1.2.1/go.mod h1:+uKXf+4Djp6Md1KODXJxgGQPKngRmWyn10oCKFzNHOQ= +github.com/rs/zerolog v1.13.0/go.mod h1:YbFCdg8HfsridGWAh22vktObvhZbQsZXe4/zB0OKkWU= +github.com/rs/zerolog v1.15.0/go.mod h1:xYTKnLHcpfU2225ny5qZjxnj9NvkumZYjJHlAThCjNc= github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM= +github.com/satori/go.uuid v1.2.0/go.mod h1:dA0hQrYB0VpLJoorglMZABFdXlWrHn1NEOzdhQKdks0= +github.com/seatgeek/logrus-gelf-formatter v0.0.0-20210414080842-5b05eb8ff761 h1:0b8DF5kR0PhRoRXDiEEdzrgBc8UqVY4JWLkQJCRsLME= +github.com/seatgeek/logrus-gelf-formatter v0.0.0-20210414080842-5b05eb8ff761/go.mod h1:/THDZYi7F/BsVEcYzYPqdcWFQ+1C2InkawTKfLOAnzg= +github.com/sergi/go-diff v1.2.0/go.mod h1:STckp+ISIX8hZLjrqAeVduY0gWCT9IjLuqbuNXdaHfM= +github.com/shopspring/decimal v0.0.0-20180709203117-cd690d0c9e24/go.mod h1:M+9NzErvs504Cn4c5DxATwIqPbtswREoFCre64PpcG4= +github.com/shopspring/decimal v1.2.0/go.mod h1:DKyhrW/HYNuLGql+MJL6WCR6knT2jwCFRcu2hWCYk4o= +github.com/sirupsen/logrus v1.4.1/go.mod h1:ni0Sbl8bgC9z8RoU9G6nDWqqs/fq4eDPysMBDgk/93Q= +github.com/sirupsen/logrus v1.4.2/go.mod h1:tLMulIdttU9McNUspp0xgXVQah82FyeX6MwdIuYE2rE= +github.com/sirupsen/logrus v1.9.0/go.mod h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ= +github.com/sirupsen/logrus v1.9.3 h1:dueUQJ1C2q9oE3F7wvmSGAaVtTmUizReu6fjN8uqzbQ= +github.com/sirupsen/logrus v1.9.3/go.mod h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ= +github.com/sourcegraph/annotate v0.0.0-20160123013949-f4cad6c6324d/go.mod h1:UdhH50NIW0fCiwBSr0co2m7BnFLdv4fQTgdqdJTHFeE= +github.com/sourcegraph/syntaxhighlight v0.0.0-20170531221838-bd320f5d308e/go.mod h1:HuIsMU8RRBOtsCgI77wP899iHVBQpCmg4ErYMZB+2IA= +github.com/spf13/afero v1.9.5 h1:stMpOSZFs//0Lv29HduCmli3GUfpFoF3Y1Q/aXj/wVM= +github.com/spf13/afero v1.9.5/go.mod h1:UBogFpq8E9Hx+xc5CNTTEpTnuHVmXDwZcZcE1eb/UhQ= github.com/spf13/cast v1.7.1 h1:cuNEagBQEHWN1FnbGEjCXL2szYEXqfJPbP2HNUaca9Y= github.com/spf13/cast v1.7.1/go.mod h1:ancEpBxwJDODSW/UG4rDrAqiKolqNNh2DX3mk86cAdo= +github.com/spf13/cobra v1.6.1/go.mod h1:IOw/AERYS7UzyrGinqmz6HLUo219MORXGxhbaJUqzrY= github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU= github.com/spf13/cobra v1.10.2/go.mod h1:7C1pvHqHw5A4vrJfjNwvOdzYu0Gml16OCs2GRiTUUS4= +github.com/spf13/jwalterweatherman v1.1.0 h1:ue6voC5bR5F8YxI5S67j9i582FU4Qvo2bmqnqMYADFk= +github.com/spf13/jwalterweatherman v1.1.0/go.mod h1:aNWZUN0dPAAO/Ljvb5BEdw96iTZ0EXowPYD95IqWIGo= +github.com/spf13/pflag v1.0.5/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= github.com/spf13/pflag v1.0.9 h1:9exaQaMOCwffKiiiYk6/BndUBv+iRViNW+4lEMi0PvY= github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= +github.com/spf13/viper v1.16.0 h1:rGGH0XDZhdUOryiDWjmIvUSWpbNqisK8Wk0Vyefw8hc= +github.com/spf13/viper v1.16.0/go.mod h1:yg78JgCJcbrQOvV9YLXgkLaZqUidkY9K+Dd1FofRzQg= +github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= +github.com/stretchr/objx v0.1.1/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= +github.com/stretchr/objx v0.2.0/go.mod h1:qt09Ya8vawLte6SNmTgCsAVtYtaKzEcn8ATUoHMkEqE= +github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw= +github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo= +github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY= +github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA= +github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs= +github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= +github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4= +github.com/stretchr/testify v1.5.1/go.mod h1:5W2xD1RspED5o8YsWQXVCued0rvSQ+mT+I5cxcmMvtA= +github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= +github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= +github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU= +github.com/stretchr/testify v1.8.1/go.mod h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4= +github.com/stretchr/testify v1.8.4/go.mod h1:sz/lmYIOXD/1dqDmKjjqLyZ2RngseejIcXlSw2iwfAo= github.com/stretchr/testify v1.9.0 h1:HtqpIVDClZ4nwg75+f6Lvsy/wHu+3BoSGCbBAcpTsTg= github.com/stretchr/testify v1.9.0/go.mod h1:r2ic/lqez/lEtzL7wO/rwa5dbSLXVDPFyf8C91i36aY= +github.com/subosito/gotenv v1.4.2 h1:X1TuBLAMDFbaTAChgCBLu3DU3UPyELpnF2jjJ2cz/S8= +github.com/subosito/gotenv v1.4.2/go.mod h1:ayKnFf/c6rvx/2iiLrJUk1e6plDbT3edrFNGqEflhK0= +github.com/tidwall/gjson v1.14.3 h1:9jvXn7olKEHU1S9vwoMGliaT8jq1vJ7IH/n9zD9Dnlw= +github.com/tidwall/gjson v1.14.3/go.mod h1:/wbyibRr2FHMks5tjHJ5F8dMZh3AcwJEMf5vlfC0lxk= +github.com/tidwall/match v1.1.1 h1:+Ho715JplO36QYgwN9PGYNhgZvoUSc9X2c80KVTi+GA= +github.com/tidwall/match v1.1.1/go.mod h1:eRSPERbgtNPcGhD8UCthc6PmLEQXEWd3PRB5JTxsfmM= +github.com/tidwall/pretty v1.2.1 h1:qjsOFOWWQl+N3RsoF5/ssm1pHmJJwhjlSbZ51I6wMl4= +github.com/tidwall/pretty v1.2.1/go.mod h1:ITEVvHYasfjBbM0u2Pg8T2nJnzm8xPwvNhhsoaGGjNU= +github.com/tidwall/sjson v1.2.5 h1:kLy8mja+1c9jlljvWTlSazM7cKDRfJuR/bOJhcY5NcY= +github.com/tidwall/sjson v1.2.5/go.mod h1:Fvgq9kS/6ociJEDnK0Fk1cpYF4FIW6ZF7LAe+6jwd28= +github.com/urfave/negroni v1.0.0 h1:kIimOitoypq34K7TG7DUaJ9kq/N4Ofuwi1sjz0KipXc= +github.com/urfave/negroni v1.0.0/go.mod h1:Meg73S6kFm/4PpbYdq35yYWoCZ9mS/YSx+lKnmiohz4= github.com/wk8/go-ordered-map/v2 v2.1.8 h1:5h/BUHu93oj4gIdvHHHGsScSTMijfx5PeYkE/fJgbpc= github.com/wk8/go-ordered-map/v2 v2.1.8/go.mod h1:5nJHM5DyteebpVlHnWMV0rPz6Zp7+xBAnxjb1X5vnTw= github.com/yosida95/uritemplate/v3 v3.0.2 h1:Ed3Oyj9yrmi9087+NczuL5BwkIc4wvTb5zIM+UJPGz4= github.com/yosida95/uritemplate/v3 v3.0.2/go.mod h1:ILOh0sOhIJR3+L/8afwt/kE++YT040gmv5BQTMR2HP4= +github.com/yuin/goldmark v1.1.25/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= +github.com/yuin/goldmark v1.1.27/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= +github.com/yuin/goldmark v1.1.32/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= +github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= +github.com/yuin/goldmark v1.3.5/go.mod h1:mwnBkeHKe2W/ZEtQ+71ViKU8L12m81fl3OWwC1Zlc8k= +github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= +github.com/zenazn/goji v0.9.0/go.mod h1:7S9M489iMyHBNxwZnk9/EHS098H4/F6TATF2mIxtB1Q= +go.opencensus.io v0.21.0/go.mod h1:mSImk1erAIZhrmZN+AvHh14ztQfjbGwt4TtuofqLduU= +go.opencensus.io v0.22.0/go.mod h1:+kGneAE2xo2IficOXnaByMWTGM9T73dGwxeWcUqIpI8= +go.opencensus.io v0.22.2/go.mod h1:yxeiOL68Rb0Xd1ddK5vPZ/oVn4vY4Ynel7k9FzqtOIw= +go.opencensus.io v0.22.3/go.mod h1:yxeiOL68Rb0Xd1ddK5vPZ/oVn4vY4Ynel7k9FzqtOIw= +go.opencensus.io v0.22.4/go.mod h1:yxeiOL68Rb0Xd1ddK5vPZ/oVn4vY4Ynel7k9FzqtOIw= +go.opencensus.io v0.22.5/go.mod h1:5pWMHQbX5EPX2/62yrJeAkowc+lfs/XD7Uxpq3pI6kk= +go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace v0.46.1 h1:gbhw/u49SS3gkPWiYweQNJGm/uJN5GkI/FrosxSHT7A= +go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace v0.46.1/go.mod h1:GnOaBaFQ2we3b9AGWJpsBa7v1S5RlQzlC3O7dRMxZhM= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.46.1 h1:aFJWCqJMNjENlcleuuOkGAPH82y0yULBScfXcIEdS24= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.46.1/go.mod h1:sEGXWArGqc3tVa+ekntsN65DmVbVeW+7lTKTjZF3/Fo= +go.opentelemetry.io/contrib/propagators/b3 v1.21.0 h1:uGdgDPNzwQWRwCXJgw/7h29JaRqcq9B87Iv4hJDKAZw= +go.opentelemetry.io/contrib/propagators/b3 v1.21.0/go.mod h1:D9GQXvVGT2pzyTfp1QBOnD1rzKEWzKjjwu5q2mslCUI= +go.opentelemetry.io/contrib/propagators/jaeger v1.21.1 h1:f4beMGDKiVzg9IcX7/VuWVy+oGdjx3dNJ72YehmtY5k= +go.opentelemetry.io/contrib/propagators/jaeger v1.21.1/go.mod h1:U9jhkEl8d1LL+QXY7q3kneJWJugiN3kZJV2OWz3hkBY= +go.opentelemetry.io/contrib/samplers/jaegerremote v0.15.1 h1:Qb+5A+JbIjXwO7l4HkRUhgIn4Bzz0GNS2q+qdmSx+0c= +go.opentelemetry.io/contrib/samplers/jaegerremote v0.15.1/go.mod h1:G4vNCm7fRk0kjZ6pGNLo5SpLxAUvOfSrcaegnT8TPck= +go.opentelemetry.io/otel v1.21.0 h1:hzLeKBZEL7Okw2mGzZ0cc4k/A7Fta0uoPgaJCr8fsFc= +go.opentelemetry.io/otel v1.21.0/go.mod h1:QZzNPQPm1zLX4gZK4cMi+71eaorMSGT3A4znnUvNNEo= +go.opentelemetry.io/otel/exporters/jaeger v1.17.0 h1:D7UpUy2Xc2wsi1Ras6V40q806WM07rqoCWzXu7Sqy+4= +go.opentelemetry.io/otel/exporters/jaeger v1.17.0/go.mod h1:nPCqOnEH9rNLKqH/+rrUjiMzHJdV1BlpKcTwRTyKkKI= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.21.0 h1:cl5P5/GIfFh4t6xyruOgJP5QiA1pw4fYYdv6nc6CBWw= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.21.0/go.mod h1:zgBdWWAu7oEEMC06MMKc5NLbA/1YDXV1sMpSqEeLQLg= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.21.0 h1:digkEZCJWobwBqMwC0cwCq8/wkkRy/OowZg5OArWZrM= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.21.0/go.mod h1:/OpE/y70qVkndM0TrxT4KBoN3RsFZP0QaofcfYrj76I= +go.opentelemetry.io/otel/exporters/zipkin v1.21.0 h1:D+Gv6lSfrFBWmQYyxKjDd0Zuld9SRXpIrEsKZvE4DO4= +go.opentelemetry.io/otel/exporters/zipkin v1.21.0/go.mod h1:83oMKR6DzmHisFOW3I+yIMGZUTjxiWaiBI8M8+TU5zE= +go.opentelemetry.io/otel/metric v1.21.0 h1:tlYWfeo+Bocx5kLEloTjbcDwBuELRrIFxwdQ36PlJu4= +go.opentelemetry.io/otel/metric v1.21.0/go.mod h1:o1p3CA8nNHW8j5yuQLdc1eeqEaPfzug24uvsyIEJRWM= +go.opentelemetry.io/otel/sdk v1.21.0 h1:FTt8qirL1EysG6sTQRZ5TokkU8d0ugCj8htOgThZXQ8= +go.opentelemetry.io/otel/sdk v1.21.0/go.mod h1:Nna6Yv7PWTdgJHVRD9hIYywQBRx7pbox6nwBnZIxl/E= +go.opentelemetry.io/otel/trace v1.21.0 h1:WD9i5gzvoUPuXIXH24ZNBudiarZDKuekPqi/E8fpfLc= +go.opentelemetry.io/otel/trace v1.21.0/go.mod h1:LGbsEB0f9LGjN+OZaQQ26sohbOmiMR+BaslueVtS/qQ= +go.opentelemetry.io/proto/otlp v1.0.0 h1:T0TX0tmXU8a3CbNXzEKGeU5mIVOdf0oykP+u2lIVU/I= +go.opentelemetry.io/proto/otlp v1.0.0/go.mod h1:Sy6pihPLfYHkr3NkUbEhGHFhINUSI/v80hjKIs5JXpM= +go.uber.org/atomic v1.3.2/go.mod h1:gD2HeocX3+yG+ygLZcrzQJaqmWj9AIm7n08wl/qW/PE= +go.uber.org/atomic v1.4.0/go.mod h1:gD2HeocX3+yG+ygLZcrzQJaqmWj9AIm7n08wl/qW/PE= +go.uber.org/atomic v1.5.0/go.mod h1:sABNBOSYdrvTF6hTgEIbc7YasKWGhgEQZyfxyTvoXHQ= +go.uber.org/atomic v1.6.0/go.mod h1:sABNBOSYdrvTF6hTgEIbc7YasKWGhgEQZyfxyTvoXHQ= +go.uber.org/multierr v1.1.0/go.mod h1:wR5kodmAFQ0UK8QlbwjlSNy0Z68gJhDJUG5sjR94q/0= +go.uber.org/multierr v1.3.0/go.mod h1:VgVr7evmIr6uPjLBxg28wmKNXyqE9akIJ5XnfpiKl+4= +go.uber.org/multierr v1.5.0/go.mod h1:FeouvMocqHpRaaGuG9EjoKcStLC43Zu/fmqdUMPcKYU= +go.uber.org/tools v0.0.0-20190618225709-2cfd321de3ee/go.mod h1:vJERXedbb3MVM5f9Ejo0C68/HhF8uaILCdgjnY+goOA= +go.uber.org/zap v1.9.1/go.mod h1:vwi/ZaCAaUcBkycHslxD9B2zi4UTXhF60s6SWpuDF0Q= +go.uber.org/zap v1.10.0/go.mod h1:vwi/ZaCAaUcBkycHslxD9B2zi4UTXhF60s6SWpuDF0Q= +go.uber.org/zap v1.13.0/go.mod h1:zwrFLgMcdUuIBviXEYEH1YKNaOBnKXsx2IPda5bBwHM= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= +golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= +golang.org/x/crypto v0.0.0-20190411191339-88737f569e3a/go.mod h1:WFFai1msRO1wXaEeE5yQxYXgSfI8pQAWXbQop6sCtWE= +golang.org/x/crypto v0.0.0-20190510104115-cbcb75029529/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= +golang.org/x/crypto v0.0.0-20190605123033-f99c8df09eb5/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= +golang.org/x/crypto v0.0.0-20190820162420-60c769a6c586/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= +golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= +golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto= +golang.org/x/crypto v0.0.0-20201203163018-be400aefbc4c/go.mod h1:jdWPYTVW3xRLrWPugEBEK3UY2ZEsg3UU495nc5E+M+I= +golang.org/x/crypto v0.0.0-20210421170649-83a5a9bb288b/go.mod h1:T9bdIzuCu7OtxOm1hfPfRQxPLYneinmdGuTeoZ9dtd4= +golang.org/x/crypto v0.0.0-20210616213533-5ff15b29337e/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= +golang.org/x/crypto v0.0.0-20210711020723-a769d52b0f97/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= +golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= +golang.org/x/crypto v0.0.0-20220722155217-630584e8d5aa/go.mod h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4= +golang.org/x/crypto v0.19.0/go.mod h1:Iy9bg/ha4yyC70EfRS8jz+B6ybOBKMaSxLj6P6oBDfU= golang.org/x/crypto v0.49.0 h1:+Ng2ULVvLHnJ/ZFEq4KdcDd/cfjrrjjNSXNzxg0Y4U4= golang.org/x/crypto v0.49.0/go.mod h1:ErX4dUh2UM+CFYiXZRTcMpEcN8b/1gxEuv3nODoYtCA= +golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= +golang.org/x/exp v0.0.0-20190306152737-a1d7652674e8/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= +golang.org/x/exp v0.0.0-20190510132918-efd6b22b2522/go.mod h1:ZjyILWgesfNpC6sMxTJOJm9Kp84zZh5NQWvqDGG3Qr8= +golang.org/x/exp v0.0.0-20190829153037-c13cbed26979/go.mod h1:86+5VVa7VpoJ4kLfm080zCjGlMRFzhUhsZKEZO7MGek= +golang.org/x/exp v0.0.0-20191030013958-a1ab85dbe136/go.mod h1:JXzH8nQsPlswgeRAPE3MuO9GYsAcnJvJ4vnMwN/5qkY= +golang.org/x/exp v0.0.0-20191129062945-2f5052295587/go.mod h1:2RIsYlXP63K8oxa1u096TMicItID8zy7Y6sNkU49FU4= +golang.org/x/exp v0.0.0-20191227195350-da58074b4299/go.mod h1:2RIsYlXP63K8oxa1u096TMicItID8zy7Y6sNkU49FU4= +golang.org/x/exp v0.0.0-20200119233911-0405dc783f0a/go.mod h1:2RIsYlXP63K8oxa1u096TMicItID8zy7Y6sNkU49FU4= +golang.org/x/exp v0.0.0-20200207192155-f17229e696bd/go.mod h1:J/WKrq2StrnmMY6+EHIKF9dgMWnmCNThgcyBT1FY9mM= +golang.org/x/exp v0.0.0-20200224162631-6cc2880d07d6/go.mod h1:3jZMyOhIsHpP37uCMkUooju7aAi5cS1Q23tOzKc+0MU= golang.org/x/exp v0.0.0-20251023183803-a4bb9ffd2546 h1:mgKeJMpvi0yx/sU5GsxQ7p6s2wtOnGAHZWCHUM4KGzY= golang.org/x/exp v0.0.0-20251023183803-a4bb9ffd2546/go.mod h1:j/pmGrbnkbPtQfxEe5D0VQhZC6qKbfKifgD0oM7sR70= -golang.org/x/mod v0.29.0 h1:HV8lRxZC4l2cr3Zq1LvtOsi/ThTgWnUk/y64QSs8GwA= -golang.org/x/mod v0.29.0/go.mod h1:NyhrlYXJ2H4eJiRy/WDBO6HMqZQ6q9nk4JzS3NuCK+w= -golang.org/x/sync v0.17.0 h1:l60nONMj9l5drqw6jlhIELNv9I0A4OFgRsG9k2oT9Ug= -golang.org/x/sync v0.17.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI= +golang.org/x/image v0.0.0-20190227222117-0694c2d4d067/go.mod h1:kZ7UVZpmo3dzQBMxlp+ypCbDeSB+sBbTgSJuh5dn5js= +golang.org/x/image v0.0.0-20190802002840-cff245a6509b/go.mod h1:FeLwcggjj3mMvU+oOTbSwawSJRM1uh48EjtB4UJZlP0= +golang.org/x/lint v0.0.0-20181026193005-c67002cb31c3/go.mod h1:UVdnD1Gm6xHRNCYTkRU2/jEulfH38KcIWyp/GAMgvoE= +golang.org/x/lint v0.0.0-20190227174305-5b3e6a55c961/go.mod h1:wehouNa3lNwaWXcvxsM5YxQ5yQlVC4a0KAMCusXpPoU= +golang.org/x/lint v0.0.0-20190301231843-5614ed5bae6f/go.mod h1:UVdnD1Gm6xHRNCYTkRU2/jEulfH38KcIWyp/GAMgvoE= +golang.org/x/lint v0.0.0-20190313153728-d0100b6bd8b3/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc= +golang.org/x/lint v0.0.0-20190409202823-959b441ac422/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc= +golang.org/x/lint v0.0.0-20190909230951-414d861bb4ac/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc= +golang.org/x/lint v0.0.0-20190930215403-16217165b5de/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc= +golang.org/x/lint v0.0.0-20191125180803-fdd1cda4f05f/go.mod h1:5qLYkcX4OjUUV8bRuDixDT3tpyyb+LUpUlRWLxfhWrs= +golang.org/x/lint v0.0.0-20200130185559-910be7a94367/go.mod h1:3xt1FjdF8hUf6vQPIChWIBhFzV8gjjsPE/fR3IyQdNY= +golang.org/x/lint v0.0.0-20200302205851-738671d3881b/go.mod h1:3xt1FjdF8hUf6vQPIChWIBhFzV8gjjsPE/fR3IyQdNY= +golang.org/x/lint v0.0.0-20201208152925-83fdc39ff7b5/go.mod h1:3xt1FjdF8hUf6vQPIChWIBhFzV8gjjsPE/fR3IyQdNY= +golang.org/x/mobile v0.0.0-20190312151609-d3739f865fa6/go.mod h1:z+o9i4GpDbdi3rU15maQ/Ox0txvL9dWGYEHz965HBQE= +golang.org/x/mobile v0.0.0-20190719004257-d2bd2a29d028/go.mod h1:E/iHnbuqvinMTCcRqshq8CkpyQDoeVncDDYHnLhea+o= +golang.org/x/mod v0.0.0-20190513183733-4bf6d317e70e/go.mod h1:mXi4GBBbnImb6dmsKGUJ2LatrhH/nqhxcFungHvyanc= +golang.org/x/mod v0.1.0/go.mod h1:0QHyrYULN0/3qlju5TqG8bIK38QM8yzMo5ekMj3DlcY= +golang.org/x/mod v0.1.1-0.20191105210325-c90efee705ee/go.mod h1:QqPTAvyqsEbceGzBzNggFXnrqF1CaUcvgkdR5Ot7KZg= +golang.org/x/mod v0.1.1-0.20191107180719-034126e5016b/go.mod h1:QqPTAvyqsEbceGzBzNggFXnrqF1CaUcvgkdR5Ot7KZg= +golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= +golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= +golang.org/x/mod v0.4.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= +golang.org/x/mod v0.4.1/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= +golang.org/x/mod v0.4.2/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= +golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= +golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= +golang.org/x/mod v0.10.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= +golang.org/x/mod v0.33.0 h1:tHFzIWbBifEmbwtGz65eaWyGiGZatSrT9prnU8DbVL8= +golang.org/x/mod v0.33.0/go.mod h1:swjeQEj+6r7fODbD2cqrnje9PnziFuw4bmLbBZFrQ5w= +golang.org/x/net v0.0.0-20180724234803-3673e40ba225/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= +golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= +golang.org/x/net v0.0.0-20190108225652-1e06a53dbb7e/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= +golang.org/x/net v0.0.0-20190213061140-3a22650c66bd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= +golang.org/x/net v0.0.0-20190311183353-d8887717615a/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= +golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= +golang.org/x/net v0.0.0-20190501004415-9ce7a6920f09/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= +golang.org/x/net v0.0.0-20190503192946-f4e77d36d62c/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= +golang.org/x/net v0.0.0-20190603091049-60506f45cf65/go.mod h1:HSz+uSET+XFnRR8LxR5pz3Of3rY3CfYBVs4xY44aLks= +golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20190628185345-da137c7871d7/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20190724013045-ca1201d0de80/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20190813141303-74dc4d7220e7/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20191209160850-c0dbc17a3553/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20200114155413-6afb5195e5aa/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20200202094626-16171245cfb2/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20200222125558-5a598a2470a0/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20200301022130-244492dfa37a/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20200324143707-d3edc9973b7e/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A= +golang.org/x/net v0.0.0-20200501053045-e0ff5e5a1de5/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A= +golang.org/x/net v0.0.0-20200506145744-7e3656a0809f/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A= +golang.org/x/net v0.0.0-20200513185701-a91f0712d120/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A= +golang.org/x/net v0.0.0-20200520182314-0ba52f642ac2/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A= +golang.org/x/net v0.0.0-20200625001655-4c5254603344/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA= +golang.org/x/net v0.0.0-20200707034311-ab3426394381/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA= +golang.org/x/net v0.0.0-20200822124328-c89045814202/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA= +golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= +golang.org/x/net v0.0.0-20201031054903-ff519b6c9102/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= +golang.org/x/net v0.0.0-20201209123823-ac852fbbde11/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= +golang.org/x/net v0.0.0-20201224014010-6772e930b67b/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= +golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= +golang.org/x/net v0.0.0-20210405180319-a5a99cb37ef4/go.mod h1:p54w0d4576C0XHj96bSt6lcn1PtDYWL6XObtHCRCNQM= +golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y= +golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= +golang.org/x/net v0.0.0-20220826154423-83b083e8dc8b/go.mod h1:YDH+HFinaLZZlnHAfSS6ZXJJ9M9t4Dl22yv3iI2vPwk= +golang.org/x/net v0.0.0-20221002022538-bcab6841153b/go.mod h1:YDH+HFinaLZZlnHAfSS6ZXJJ9M9t4Dl22yv3iI2vPwk= +golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= +golang.org/x/net v0.9.0/go.mod h1:d48xBJpPfHeWQsugry2m+kC02ZBRGRgulfHnEXEuWns= +golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg= +golang.org/x/net v0.51.0 h1:94R/GTO7mt3/4wIKpcR5gkGmRLOuE/2hNGeWq/GBIFo= +golang.org/x/net v0.51.0/go.mod h1:aamm+2QF5ogm02fjy5Bb7CQ0WMt1/WVM7FtyaTLlA9Y= +golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U= +golang.org/x/oauth2 v0.0.0-20190226205417-e64efc72b421/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw= +golang.org/x/oauth2 v0.0.0-20190604053449-0f29369cfe45/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw= +golang.org/x/oauth2 v0.0.0-20191202225959-858c2ad4c8b6/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw= +golang.org/x/oauth2 v0.0.0-20200107190931-bf48bf16ab8d/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw= +golang.org/x/oauth2 v0.0.0-20200902213428-5d25da1a8d43/go.mod h1:KelEdhl1UZF7XfJ4dDtk6s++YSgaE7mD/BuKKDLBl4A= +golang.org/x/oauth2 v0.0.0-20201109201403-9fd604954f58/go.mod h1:KelEdhl1UZF7XfJ4dDtk6s++YSgaE7mD/BuKKDLBl4A= +golang.org/x/oauth2 v0.0.0-20201208152858-08078c50e5b5/go.mod h1:KelEdhl1UZF7XfJ4dDtk6s++YSgaE7mD/BuKKDLBl4A= +golang.org/x/oauth2 v0.0.0-20210218202405-ba52d332ba99/go.mod h1:KelEdhl1UZF7XfJ4dDtk6s++YSgaE7mD/BuKKDLBl4A= +golang.org/x/oauth2 v0.14.0 h1:P0Vrf/2538nmC0H+pEQ3MNFRRnVR7RlqyVw+bvm26z0= +golang.org/x/oauth2 v0.14.0/go.mod h1:lAtNWgaWfL4cm7j2OV8TxGi9Qb7ECORx8DktCY74OwM= +golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20181221193216-37e7f081c4d4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20190227155943-e225da77a7e6/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20200317015054-43a5402ce75a/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20200625203802-6e8e738ad208/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20201207232520-09787c993a3a/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20210220032951-036812b2e83c/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20220929204114-8fcdb60fdcc0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4= +golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= +golang.org/x/sys v0.0.0-20180830151530-49385e6e1522/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20180905080454-ebe1bf3edb33/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20190222072716-a9d3bda3a223/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20190312061237-fead79001313/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190403152447-81d4e9dc473e/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190422165155-953cdadca894/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190502145724-3ef323f4f1fd/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190507160741-ecd444e8653b/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190606165138-5da285871e9c/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190624142023-c5567b49c5d0/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190726091711-fc99dfbffb4e/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20190813064441-fde4db37ae7a/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20191001151750-bb3f8db39f24/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20191026070338-33540a1f6037/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20191204072324-ce4227a45e2e/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20191228213918-04cbcbbfeed8/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200113162924-86b910548bc1/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200116001909-b77594299b42/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200122134326-e047566fdf82/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200202164722-d101bd2416d5/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200212091648-12a6c2dcc1e4/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200223170610-d5e6a3e2c0ae/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200302150141-5c8b2ff67527/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200323222414-85ca7c5b95cd/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200331124033-c3d80250170d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200501052902-10377860bb8e/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200511232937-7e40ca221e25/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200515095857-1151b9dac4a9/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200523222454-059865788121/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200803210538-64077c9b5642/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200905004654-be1d3432aa8f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20201201145000-ef89a241ccb3/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210104204734-6f8348627aad/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210119212857-b64e53b001e4/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210225134936-a50acf3fe073/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210330210617-4fbd30eecc44/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210423185535-09eb48e85fd7/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210510120138-977fb7262007/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20210630005230-0f9fa26af87c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20220728004956-3c1f35247d10/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20220908164124-27713097b956/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.7.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.17.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= golang.org/x/sys v0.42.0 h1:omrd2nAlyT5ESRdCLYdm3+fMfNFE/+Rf4bDIQImRJeo= golang.org/x/sys v0.42.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= -golang.org/x/tools v0.38.0 h1:Hx2Xv8hISq8Lm16jvBZ2VQf+RLmbd7wVUsALibYI/IQ= -golang.org/x/tools v0.38.0/go.mod h1:yEsQ/d/YK8cjh0L6rZlY8tgtlKiBNTL14pGDJPJpYQs= -gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM= +golang.org/x/telemetry v0.0.0-20260209163413-e7419c687ee4 h1:bTLqdHv7xrGlFbvf5/TXNxy/iUwwdkjhqQTJDjW7aj0= +golang.org/x/telemetry v0.0.0-20260209163413-e7419c687ee4/go.mod h1:g5NllXBEermZrmR51cJDQxmJUHUOfRAaNyWBM+R+548= +golang.org/x/term v0.0.0-20201117132131-f5c789dd3221/go.mod h1:Nr5EML6q2oocZ2LXRh80K7BxOlk5/8JxuGnuhpl+muw= +golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= +golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= +golang.org/x/term v0.0.0-20220722155259-a9ba230a4035/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= +golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k= +golang.org/x/term v0.7.0/go.mod h1:P32HKFT3hSsZrRxla30E9HqToFYAQPCMs/zFMBUFqPY= +golang.org/x/term v0.8.0/go.mod h1:xPskH00ivmX89bAKVGSKKtLOWNx2+17Eiy94tnKShWo= +golang.org/x/term v0.17.0/go.mod h1:lLRBjIVuehSbZlaOtGMbcMncT+aqLLLmKrsjNrUguwk= +golang.org/x/text v0.0.0-20170915032832-14c0d48ead0c/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= +golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= +golang.org/x/text v0.3.1-0.20180807135948-17ff2d5776d2/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= +golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk= +golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= +golang.org/x/text v0.3.4/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= +golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= +golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= +golang.org/x/text v0.3.8/go.mod h1:E6s5w1FMmriuDzIBO73fBruAKo1PCIq6d2Q6DHfQ8WQ= +golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= +golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8= +golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU= +golang.org/x/text v0.35.0 h1:JOVx6vVDFokkpaq1AEptVzLTpDe9KGpj5tR4/X+ybL8= +golang.org/x/text v0.35.0/go.mod h1:khi/HExzZJ2pGnjenulevKNX1W67CUy0AsXcNubPGCA= +golang.org/x/time v0.0.0-20181108054448-85acf8d2951c/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= +golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= +golang.org/x/time v0.0.0-20191024005414-555d28b269f0/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= +golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= +golang.org/x/tools v0.0.0-20190114222345-bf090417da8b/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= +golang.org/x/tools v0.0.0-20190226205152-f727befe758c/go.mod h1:9Yl7xja0Znq3iFh3HoIrodX9oNMXvdceNzlUR8zjMvY= +golang.org/x/tools v0.0.0-20190311212946-11955173bddd/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs= +golang.org/x/tools v0.0.0-20190312151545-0bb0c0a6e846/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs= +golang.org/x/tools v0.0.0-20190312170243-e65039ee4138/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs= +golang.org/x/tools v0.0.0-20190425150028-36563e24a262/go.mod h1:RgjU9mgBXZiqYHBnxXauZ1Gv1EHHAz9KjViQ78xBX0Q= +golang.org/x/tools v0.0.0-20190425163242-31fd60d6bfdc/go.mod h1:RgjU9mgBXZiqYHBnxXauZ1Gv1EHHAz9KjViQ78xBX0Q= +golang.org/x/tools v0.0.0-20190506145303-2d16b83fe98c/go.mod h1:RgjU9mgBXZiqYHBnxXauZ1Gv1EHHAz9KjViQ78xBX0Q= +golang.org/x/tools v0.0.0-20190524140312-2c0ae7006135/go.mod h1:RgjU9mgBXZiqYHBnxXauZ1Gv1EHHAz9KjViQ78xBX0Q= +golang.org/x/tools v0.0.0-20190606124116-d0a3d012864b/go.mod h1:/rFqwRUd4F7ZHNgwSSTFct+R/Kf4OFW1sUzUTQQTgfc= +golang.org/x/tools v0.0.0-20190621195816-6e04913cbbac/go.mod h1:/rFqwRUd4F7ZHNgwSSTFct+R/Kf4OFW1sUzUTQQTgfc= +golang.org/x/tools v0.0.0-20190628153133-6cdbf07be9d0/go.mod h1:/rFqwRUd4F7ZHNgwSSTFct+R/Kf4OFW1sUzUTQQTgfc= +golang.org/x/tools v0.0.0-20190816200558-6889da9d5479/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20190823170909-c4a336ef6a2f/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20190911174233-4f2ddba30aff/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191012152004-8de300cfc20a/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191029041327-9cc4af7d6b2c/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191029190741-b9c20aec41a5/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191113191852-77e3bb0ad9e7/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191115202509-3a792d9c32b2/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191125144606-a911d9008d1f/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191130070609-6e064ea0cf2d/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20191216173652-a0e659d51361/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20191227053925-7b8e75db28f4/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200103221440-774c71fcf114/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200117161641-43d50277825c/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200122220014-bf1340f18c4a/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200130002326-2f3ba24bd6e7/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200204074204-1cc6d1ef6c74/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200207183749-b753a1ba74fa/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200212150539-ea181f53ac56/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200224181240-023911ca70b2/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200227222343-706bc42d1f0d/go.mod h1:TB2adYChydJhpapKDTa4BR/hXlZSLoq2Wpct/0txZ28= +golang.org/x/tools v0.0.0-20200304193943-95d2e580d8eb/go.mod h1:o4KQGtdN14AW+yjsvvwRTJJuXz8XRtIHtEnmAXLyFUw= +golang.org/x/tools v0.0.0-20200312045724-11d5b4c81c7d/go.mod h1:o4KQGtdN14AW+yjsvvwRTJJuXz8XRtIHtEnmAXLyFUw= +golang.org/x/tools v0.0.0-20200331025713-a30bf2db82d4/go.mod h1:Sl4aGygMT6LrqrWclx+PTx3U+LnKx/seiNR+3G19Ar8= +golang.org/x/tools v0.0.0-20200501065659-ab2804fb9c9d/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE= +golang.org/x/tools v0.0.0-20200512131952-2bc93b1c0c88/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE= +golang.org/x/tools v0.0.0-20200515010526-7d3b6ebf133d/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE= +golang.org/x/tools v0.0.0-20200618134242-20370b0cb4b2/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE= +golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE= +golang.org/x/tools v0.0.0-20200729194436-6467de6f59a7/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA= +golang.org/x/tools v0.0.0-20200804011535-6c149bb5ef0d/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA= +golang.org/x/tools v0.0.0-20200825202427-b303f430e36d/go.mod h1:njjCfa9FT2d7l9Bc6FUM5FLjQPp3cFF28FI3qnDFljA= +golang.org/x/tools v0.0.0-20200904185747-39188db58858/go.mod h1:Cj7w3i3Rnn0Xh82ur9kSqwfTHTeVxaDqrfMjpcNT6bE= +golang.org/x/tools v0.0.0-20201110124207-079ba7bd75cd/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= +golang.org/x/tools v0.0.0-20201201161351-ac6f37ff4c2a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= +golang.org/x/tools v0.0.0-20201208233053-a543418bbed2/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= +golang.org/x/tools v0.0.0-20210105154028-b0ab187a4818/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= +golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= +golang.org/x/tools v0.0.0-20210108195828-e2f9c7f1fc8e/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= +golang.org/x/tools v0.1.0/go.mod h1:xkSsbof2nBLbhDlRMhhhyNLN/zl3eTqcnHD5viDpcZ0= +golang.org/x/tools v0.1.1/go.mod h1:o0xws9oXOQQZyjljx8fwUC0k7L1pTE6eaCbjGeHmOkk= +golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= +golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU= +golang.org/x/tools v0.8.0/go.mod h1:JxBZ99ISMI5ViVkT1tr6tdNmXeTrcpVSD3vZ1RsRdN4= +golang.org/x/tools v0.42.0 h1:uNgphsn75Tdz5Ji2q36v/nsFSfR/9BRFvqhGBaJGd5k= +golang.org/x/tools v0.42.0/go.mod h1:Ma6lCIwGZvHK6XtgbswSoWroEkhugApmsXyrUmBhfr0= +golang.org/x/xerrors v0.0.0-20190410155217-1f06c39b4373/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.org/x/xerrors v0.0.0-20190513163551-3ee3066db522/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +google.golang.org/api v0.4.0/go.mod h1:8k5glujaEP+g9n7WNsDg8QP6cUVNI86fCNMcbazEtwE= +google.golang.org/api v0.7.0/go.mod h1:WtwebWUNSVBH/HAw79HIFXZNqEvBhG+Ra+ax0hx3E3M= +google.golang.org/api v0.8.0/go.mod h1:o4eAsZoiT+ibD93RtjEohWalFOjRDx6CVaqeizhEnKg= +google.golang.org/api v0.9.0/go.mod h1:o4eAsZoiT+ibD93RtjEohWalFOjRDx6CVaqeizhEnKg= +google.golang.org/api v0.13.0/go.mod h1:iLdEw5Ide6rF15KTC1Kkl0iskquN2gFfn9o9XIsbkAI= +google.golang.org/api v0.14.0/go.mod h1:iLdEw5Ide6rF15KTC1Kkl0iskquN2gFfn9o9XIsbkAI= +google.golang.org/api v0.15.0/go.mod h1:iLdEw5Ide6rF15KTC1Kkl0iskquN2gFfn9o9XIsbkAI= +google.golang.org/api v0.17.0/go.mod h1:BwFmGc8tA3vsd7r/7kR8DY7iEEGSU04BFxCo5jP/sfE= +google.golang.org/api v0.18.0/go.mod h1:BwFmGc8tA3vsd7r/7kR8DY7iEEGSU04BFxCo5jP/sfE= +google.golang.org/api v0.19.0/go.mod h1:BwFmGc8tA3vsd7r/7kR8DY7iEEGSU04BFxCo5jP/sfE= +google.golang.org/api v0.20.0/go.mod h1:BwFmGc8tA3vsd7r/7kR8DY7iEEGSU04BFxCo5jP/sfE= +google.golang.org/api v0.22.0/go.mod h1:BwFmGc8tA3vsd7r/7kR8DY7iEEGSU04BFxCo5jP/sfE= +google.golang.org/api v0.24.0/go.mod h1:lIXQywCXRcnZPGlsd8NbLnOjtAoL6em04bJ9+z0MncE= +google.golang.org/api v0.28.0/go.mod h1:lIXQywCXRcnZPGlsd8NbLnOjtAoL6em04bJ9+z0MncE= +google.golang.org/api v0.29.0/go.mod h1:Lcubydp8VUV7KeIHD9z2Bys/sm/vGKnG1UHuDBSrHWM= +google.golang.org/api v0.30.0/go.mod h1:QGmEvQ87FHZNiUVJkT14jQNYJ4ZJjdRF23ZXz5138Fc= +google.golang.org/api v0.35.0/go.mod h1:/XrVsuzM0rZmrsbjJutiuftIzeuTQcEeaYcSk/mQ1dg= +google.golang.org/api v0.36.0/go.mod h1:+z5ficQTmoYpPn8LCUNVpK5I7hwkpjbcgqA7I34qYtE= +google.golang.org/api v0.40.0/go.mod h1:fYKFpnQN0DsDSKRVRcQSDQNtqWPfM9i+zNPxepjRCQ8= +google.golang.org/appengine v1.1.0/go.mod h1:EbEs0AVv82hx2wNQdGPgUI5lhzA/G0D9YwlJXL52JkM= +google.golang.org/appengine v1.4.0/go.mod h1:xpcJRLb0r/rnEns0DIKYYv+WjYCduHsrkT7/EB5XEv4= +google.golang.org/appengine v1.5.0/go.mod h1:xpcJRLb0r/rnEns0DIKYYv+WjYCduHsrkT7/EB5XEv4= +google.golang.org/appengine v1.6.1/go.mod h1:i06prIuMbXzDqacNJfV5OdTW448YApPu5ww/cMBSeb0= +google.golang.org/appengine v1.6.5/go.mod h1:8WjMMxjGQR8xUklV/ARdw2HLXBOI7O7uCIDZVag1xfc= +google.golang.org/appengine v1.6.6/go.mod h1:8WjMMxjGQR8xUklV/ARdw2HLXBOI7O7uCIDZVag1xfc= +google.golang.org/appengine v1.6.7/go.mod h1:8WjMMxjGQR8xUklV/ARdw2HLXBOI7O7uCIDZVag1xfc= +google.golang.org/appengine v1.6.8 h1:IhEN5q69dyKagZPYMSdIjS2HqprW324FRQZJcGqPAsM= +google.golang.org/appengine v1.6.8/go.mod h1:1jJ3jBArFh5pcgW8gCtRJnepW8FzD1V44FJffLiz/Ds= +google.golang.org/genproto v0.0.0-20180817151627-c66870c02cf8/go.mod h1:JiN7NxoALGmiZfu7CAH4rXhgtRTLTxftemlI0sWmxmc= +google.golang.org/genproto v0.0.0-20190307195333-5fe7a883aa19/go.mod h1:VzzqZJRnGkLBvHegQrXjBqPurQTc5/KpmUdxsrq26oE= +google.golang.org/genproto v0.0.0-20190418145605-e7d98fc518a7/go.mod h1:VzzqZJRnGkLBvHegQrXjBqPurQTc5/KpmUdxsrq26oE= +google.golang.org/genproto v0.0.0-20190425155659-357c62f0e4bb/go.mod h1:VzzqZJRnGkLBvHegQrXjBqPurQTc5/KpmUdxsrq26oE= +google.golang.org/genproto v0.0.0-20190502173448-54afdca5d873/go.mod h1:VzzqZJRnGkLBvHegQrXjBqPurQTc5/KpmUdxsrq26oE= +google.golang.org/genproto v0.0.0-20190801165951-fa694d86fc64/go.mod h1:DMBHOl98Agz4BDEuKkezgsaosCRResVns1a3J2ZsMNc= +google.golang.org/genproto v0.0.0-20190819201941-24fa4b261c55/go.mod h1:DMBHOl98Agz4BDEuKkezgsaosCRResVns1a3J2ZsMNc= +google.golang.org/genproto v0.0.0-20190911173649-1774047e7e51/go.mod h1:IbNlFCBrqXvoKpeg0TB2l7cyZUmoaFKYIwrEpbDKLA8= +google.golang.org/genproto v0.0.0-20191108220845-16a3f7862a1a/go.mod h1:n3cpQtvxv34hfy77yVDNjmbRyujviMdxYliBSkLhpCc= +google.golang.org/genproto v0.0.0-20191115194625-c23dd37a84c9/go.mod h1:n3cpQtvxv34hfy77yVDNjmbRyujviMdxYliBSkLhpCc= +google.golang.org/genproto v0.0.0-20191216164720-4f79533eabd1/go.mod h1:n3cpQtvxv34hfy77yVDNjmbRyujviMdxYliBSkLhpCc= +google.golang.org/genproto v0.0.0-20191230161307-f3c370f40bfb/go.mod h1:n3cpQtvxv34hfy77yVDNjmbRyujviMdxYliBSkLhpCc= +google.golang.org/genproto v0.0.0-20200115191322-ca5a22157cba/go.mod h1:n3cpQtvxv34hfy77yVDNjmbRyujviMdxYliBSkLhpCc= +google.golang.org/genproto v0.0.0-20200122232147-0452cf42e150/go.mod h1:n3cpQtvxv34hfy77yVDNjmbRyujviMdxYliBSkLhpCc= +google.golang.org/genproto v0.0.0-20200204135345-fa8e72b47b90/go.mod h1:GmwEX6Z4W5gMy59cAlVYjN9JhxgbQH6Gn+gFDQe2lzA= +google.golang.org/genproto v0.0.0-20200212174721-66ed5ce911ce/go.mod h1:55QSHmfGQM9UVYDPBsyGGes0y52j32PQ3BqQfXhyH3c= +google.golang.org/genproto v0.0.0-20200224152610-e50cd9704f63/go.mod h1:55QSHmfGQM9UVYDPBsyGGes0y52j32PQ3BqQfXhyH3c= +google.golang.org/genproto v0.0.0-20200228133532-8c2c7df3a383/go.mod h1:55QSHmfGQM9UVYDPBsyGGes0y52j32PQ3BqQfXhyH3c= +google.golang.org/genproto v0.0.0-20200305110556-506484158171/go.mod h1:55QSHmfGQM9UVYDPBsyGGes0y52j32PQ3BqQfXhyH3c= +google.golang.org/genproto v0.0.0-20200312145019-da6875a35672/go.mod h1:55QSHmfGQM9UVYDPBsyGGes0y52j32PQ3BqQfXhyH3c= +google.golang.org/genproto v0.0.0-20200331122359-1ee6d9798940/go.mod h1:55QSHmfGQM9UVYDPBsyGGes0y52j32PQ3BqQfXhyH3c= +google.golang.org/genproto v0.0.0-20200430143042-b979b6f78d84/go.mod h1:55QSHmfGQM9UVYDPBsyGGes0y52j32PQ3BqQfXhyH3c= +google.golang.org/genproto v0.0.0-20200511104702-f5ebc3bea380/go.mod h1:55QSHmfGQM9UVYDPBsyGGes0y52j32PQ3BqQfXhyH3c= +google.golang.org/genproto v0.0.0-20200515170657-fc4c6c6a6587/go.mod h1:YsZOwe1myG/8QRHRsmBRE1LrgQY60beZKjly0O1fX9U= +google.golang.org/genproto v0.0.0-20200526211855-cb27e3aa2013/go.mod h1:NbSheEEYHJ7i3ixzK3sjbqSGDJWnxyFXZblF3eUsNvo= +google.golang.org/genproto v0.0.0-20200618031413-b414f8b61790/go.mod h1:jDfRM7FcilCzHH/e9qn6dsT145K34l5v+OpcnNgKAAA= +google.golang.org/genproto v0.0.0-20200729003335-053ba62fc06f/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20200804131852-c06518451d9c/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20200825200019-8632dd797987/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20200904004341-0bd0a958aa1d/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20201109203340-2640f1f9cdfb/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20201201144952-b05cb90ed32e/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20201210142538-e3217bee35cc/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20201214200347-8c77b98c765d/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20210108203827-ffc7fda8c3d7/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20210226172003-ab064af71705/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= +google.golang.org/genproto v0.0.0-20231106174013-bbf56f31fb17 h1:wpZ8pe2x1Q3f2KyT5f8oP/fa9rHAKgFPr/HZdNuS+PQ= +google.golang.org/genproto v0.0.0-20231106174013-bbf56f31fb17/go.mod h1:J7XzRzVy1+IPwWHZUzoD0IccYZIrXILAQpc+Qy9CMhY= +google.golang.org/genproto/googleapis/api v0.0.0-20231106174013-bbf56f31fb17 h1:JpwMPBpFN3uKhdaekDpiNlImDdkUAyiJ6ez/uxGaUSo= +google.golang.org/genproto/googleapis/api v0.0.0-20231106174013-bbf56f31fb17/go.mod h1:0xJLfVdJqpAPl8tDg1ujOCGzx6LFLttXT5NhllGOXY4= +google.golang.org/genproto/googleapis/rpc v0.0.0-20231106174013-bbf56f31fb17 h1:Jyp0Hsi0bmHXG6k9eATXoYtjd6e2UzZ1SCn/wIupY14= +google.golang.org/genproto/googleapis/rpc v0.0.0-20231106174013-bbf56f31fb17/go.mod h1:oQ5rr10WTTMvP4A36n8JpR1OrO1BEiV4f78CneXZxkA= +google.golang.org/grpc v1.19.0/go.mod h1:mqu4LbDTu4XGKhr4mRzUsmM4RtVoemTSY81AxZiDr8c= +google.golang.org/grpc v1.20.1/go.mod h1:10oTOabMzJvdu6/UiuZezV6QK5dSlG84ov/aaiqXj38= +google.golang.org/grpc v1.21.1/go.mod h1:oYelfM1adQP15Ek0mdvEgi9Df8B9CZIaU1084ijfRaM= +google.golang.org/grpc v1.23.0/go.mod h1:Y5yQAOtifL1yxbo5wqy6BxZv8vAUGQwXBOALyacEbxg= +google.golang.org/grpc v1.25.1/go.mod h1:c3i+UQWmh7LiEpx4sFZnkU36qjEYZ0imhYfXVyQciAY= +google.golang.org/grpc v1.26.0/go.mod h1:qbnxyOmOxrQa7FizSgH+ReBfzJrCY1pSN7KXBS8abTk= +google.golang.org/grpc v1.27.0/go.mod h1:qbnxyOmOxrQa7FizSgH+ReBfzJrCY1pSN7KXBS8abTk= +google.golang.org/grpc v1.27.1/go.mod h1:qbnxyOmOxrQa7FizSgH+ReBfzJrCY1pSN7KXBS8abTk= +google.golang.org/grpc v1.28.0/go.mod h1:rpkK4SK4GF4Ach/+MFLZUBavHOvF2JJB5uozKKal+60= +google.golang.org/grpc v1.29.1/go.mod h1:itym6AZVZYACWQqET3MqgPpjcuV5QH3BxFS3IjizoKk= +google.golang.org/grpc v1.30.0/go.mod h1:N36X2cJ7JwdamYAgDz+s+rVMFjt3numwzf/HckM8pak= +google.golang.org/grpc v1.31.0/go.mod h1:N36X2cJ7JwdamYAgDz+s+rVMFjt3numwzf/HckM8pak= +google.golang.org/grpc v1.31.1/go.mod h1:N36X2cJ7JwdamYAgDz+s+rVMFjt3numwzf/HckM8pak= +google.golang.org/grpc v1.33.2/go.mod h1:JMHMWHQWaTccqQQlmk3MJZS+GWXOdAesneDmEnv2fbc= +google.golang.org/grpc v1.34.0/go.mod h1:WotjhfgOW/POjDeRt8vscBtXq+2VjORFy659qA51WJ8= +google.golang.org/grpc v1.35.0/go.mod h1:qjiiYl8FncCW8feJPdyg3v6XW24KsRHe+dy9BAGRRjU= +google.golang.org/grpc v1.59.0 h1:Z5Iec2pjwb+LEOqzpB2MR12/eKFhDPhuqW91O+4bwUk= +google.golang.org/grpc v1.59.0/go.mod h1:aUPDwccQo6OTjy7Hct4AfBPD1GptF4fyUjIkQ9YtF98= +google.golang.org/protobuf v0.0.0-20200109180630-ec00e32a8dfd/go.mod h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8= +google.golang.org/protobuf v0.0.0-20200221191635-4d8936d0db64/go.mod h1:kwYJMbMJ01Woi6D6+Kah6886xMZcty6N08ah7+eCXa0= +google.golang.org/protobuf v0.0.0-20200228230310-ab0ca4ff8a60/go.mod h1:cfTl7dwQJ+fmap5saPgwCLgHXTUD7jkjRqWcaiX5VyM= +google.golang.org/protobuf v1.20.1-0.20200309200217-e05f789c0967/go.mod h1:A+miEFZTKqfCUM6K7xSMQL9OKL/b6hQv+e19PK+JZNE= +google.golang.org/protobuf v1.21.0/go.mod h1:47Nbq4nVaFHyn7ilMalzfO3qCViNmqZ2kzikPIcrTAo= +google.golang.org/protobuf v1.22.0/go.mod h1:EGpADcykh3NcUnDUJcl1+ZksZNG86OlYog2l/sGQquU= +google.golang.org/protobuf v1.23.0/go.mod h1:EGpADcykh3NcUnDUJcl1+ZksZNG86OlYog2l/sGQquU= +google.golang.org/protobuf v1.23.1-0.20200526195155-81db48ad09cc/go.mod h1:EGpADcykh3NcUnDUJcl1+ZksZNG86OlYog2l/sGQquU= +google.golang.org/protobuf v1.24.0/go.mod h1:r/3tXBNzIEhYS9I1OUVjXDlt8tc493IdKGjtUeSXeh4= +google.golang.org/protobuf v1.25.0/go.mod h1:9JNX74DMeImyA3h4bdi1ymwjUzf21/xIlbajtzgsN7c= +google.golang.org/protobuf v1.26.0-rc.1/go.mod h1:jlhhOSvTdKEhbULTjvd4ARK9grFBp09yW+WbY/TyQbw= +google.golang.org/protobuf v1.26.0/go.mod h1:9q0QmTI4eRPtz6boOQmLYwt+qCgq0jsYwAQnmE0givc= +google.golang.org/protobuf v1.33.0 h1:uNO2rsAINq/JlFpSdYEKIZ0uKD/R9cpdv0T+yoGwGmI= +google.golang.org/protobuf v1.33.0/go.mod h1:c6P6GXX6sHbq/GpV6MGZEdwhWPcYBgnhAHhKbcUYpos= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= +gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= +gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= +gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk= +gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q= +gopkg.in/errgo.v2 v2.1.0/go.mod h1:hNsd1EY+bozCKY1Ytp96fpM3vjJbqLJn88ws8XvfDNI= +gopkg.in/inconshreveable/log15.v2 v2.0.0-20180818164646-67afb5ed74ec/go.mod h1:aPpfJ7XW+gOuirDoZ8gHhLh3kZ1B08FtV2bbmy7Jv3s= +gopkg.in/ini.v1 v1.67.0 h1:Dgnx+6+nfE+IfzjUEISNeydPJh9AXNNsWbGP9KzCsOA= +gopkg.in/ini.v1 v1.67.0/go.mod h1:pNLf8WUiyNEtQjuu5G5vTm06TEv9tsIgeAvK8hOrP4k= +gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= +gopkg.in/yaml.v2 v2.2.4/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= +gopkg.in/yaml.v2 v2.4.0/go.mod h1:RDklbk79AGWmwhnvt/jBztapEOGDOx6ZbXqjP6csGnQ= +gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= +honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= +honnef.co/go/tools v0.0.0-20190106161140-3f1c8253044a/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= +honnef.co/go/tools v0.0.0-20190418001031-e561f6794a2a/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= +honnef.co/go/tools v0.0.0-20190523083050-ea95bdfd59fc/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= +honnef.co/go/tools v0.0.1-2019.2.3/go.mod h1:a3bituU0lyd329TUQxRnasdCoJDkEUEAqEt0JzvZhAg= +honnef.co/go/tools v0.0.1-2020.1.3/go.mod h1:X/FiERA/W4tHapMX5mGpAtMSVEeEUOyHaw9vFzvIQ3k= +honnef.co/go/tools v0.0.1-2020.1.4/go.mod h1:X/FiERA/W4tHapMX5mGpAtMSVEeEUOyHaw9vFzvIQ3k= modernc.org/cc/v4 v4.27.1 h1:9W30zRlYrefrDV2JE2O8VDtJ1yPGownxciz5rrbQZis= modernc.org/cc/v4 v4.27.1/go.mod h1:uVtb5OGqUKpoLWhqwNQo/8LwvoiEBLvZXIQ/SmO6mL0= modernc.org/ccgo/v4 v4.30.1 h1:4r4U1J6Fhj98NKfSjnPUN7Ze2c6MnAdL0hWw6+LrJpc= @@ -101,3 +909,6 @@ modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0= modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A= modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y= modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM= +rsc.io/binaryregexp v0.2.0/go.mod h1:qTv7/COck+e2FymRvadv62gMdZztPaShugOCi3I+8D8= +rsc.io/quote/v3 v3.1.0/go.mod h1:yEA65RcK8LyAZtP9Kv3t0HmxON59tX3rD+tICJqUlj0= +rsc.io/sampler v1.3.0/go.mod h1:T1hPZKmBbMNahiBKFy5HrXp6adAjACjK9JXDnKaTXpA= diff --git a/internal/auth/client_store.go b/internal/auth/client_store.go new file mode 100644 index 0000000..c0fc5a0 --- /dev/null +++ b/internal/auth/client_store.go @@ -0,0 +1,214 @@ +package auth + +import ( + "context" + "crypto/rand" + "database/sql" + "encoding/hex" + "encoding/json" + "fmt" + "strings" + "time" + + "golang.org/x/crypto/bcrypt" +) + +// ClientStore defines the storage interface for OAuth client operations. +type ClientStore interface { + CreateClient(ctx context.Context, name string, redirectURIs, grantTypes, scopes []string, ownerID int64) (*OAuthClient, string, error) + GetClient(ctx context.Context, clientID string) (*OAuthClient, error) + ListClientsByOwner(ctx context.Context, ownerID int64) ([]*OAuthClient, error) + VerifyClientSecret(ctx context.Context, clientID, secret string) (*OAuthClient, error) +} + +// SQLiteClientStore implements ClientStore using SQLite. +type SQLiteClientStore struct { + db *sql.DB + bcryptCost int +} + +// NewSQLiteClientStore creates a new SQLite-backed client store. +func NewSQLiteClientStore(db *sql.DB, bcryptCost int) *SQLiteClientStore { + if bcryptCost < 10 { + bcryptCost = 12 + } + return &SQLiteClientStore{db: db, bcryptCost: bcryptCost} +} + +// CreateClient registers a new OAuth client, generating client_id and client_secret. +// Returns the client and the raw secret (shown once). +func (s *SQLiteClientStore) CreateClient(ctx context.Context, name string, redirectURIs, grantTypes, scopes []string, ownerID int64) (*OAuthClient, string, error) { + clientID, err := generateClientID() + if err != nil { + return nil, "", fmt.Errorf("generate client_id: %w", err) + } + + secret, err := generateClientSecret() + if err != nil { + return nil, "", fmt.Errorf("generate client_secret: %w", err) + } + + hash, err := bcrypt.GenerateFromPassword([]byte(secret), s.bcryptCost) + if err != nil { + return nil, "", fmt.Errorf("hash secret: %w", err) + } + + if redirectURIs == nil { + redirectURIs = []string{} + } + if grantTypes == nil { + grantTypes = []string{"client_credentials"} + } + if scopes == nil { + scopes = []string{} + } + + redirectURIsJSON, _ := json.Marshal(redirectURIs) + grantTypesJSON, _ := json.Marshal(grantTypes) + scopesJSON, _ := json.Marshal(scopes) + + _, err = s.db.ExecContext(ctx, + `INSERT INTO oauth_clients (id, secret_hash, name, redirect_uris, grant_types, scopes, owner_id, created_at) + VALUES (?, ?, ?, ?, ?, ?, ?, CURRENT_TIMESTAMP)`, + clientID, string(hash), name, string(redirectURIsJSON), string(grantTypesJSON), string(scopesJSON), ownerID, + ) + if err != nil { + return nil, "", fmt.Errorf("insert client: %w", err) + } + + client := &OAuthClient{ + ID: clientID, + SecretHash: string(hash), + Name: name, + RedirectURIs: redirectURIs, + GrantTypes: grantTypes, + Scopes: scopes, + OwnerID: ownerID, + CreatedAt: time.Now(), + } + + return client, secret, nil +} + +// GetClient retrieves an OAuth client by its ID. +func (s *SQLiteClientStore) GetClient(ctx context.Context, clientID string) (*OAuthClient, error) { + var redirectURIsJSON, grantTypesJSON, scopesJSON string + var ownerID sql.NullInt64 + client := &OAuthClient{} + + err := s.db.QueryRowContext(ctx, + `SELECT id, secret_hash, name, redirect_uris, grant_types, scopes, owner_id, created_at + FROM oauth_clients WHERE id = ?`, clientID, + ).Scan(&client.ID, &client.SecretHash, &client.Name, + &redirectURIsJSON, &grantTypesJSON, &scopesJSON, &ownerID, &client.CreatedAt) + if err != nil { + if err == sql.ErrNoRows { + return nil, ErrClientNotFound + } + return nil, fmt.Errorf("query client: %w", err) + } + + json.Unmarshal([]byte(redirectURIsJSON), &client.RedirectURIs) + json.Unmarshal([]byte(grantTypesJSON), &client.GrantTypes) + json.Unmarshal([]byte(scopesJSON), &client.Scopes) + if ownerID.Valid { + client.OwnerID = ownerID.Int64 + } + + if client.RedirectURIs == nil { + client.RedirectURIs = []string{} + } + if client.GrantTypes == nil { + client.GrantTypes = []string{} + } + if client.Scopes == nil { + client.Scopes = []string{} + } + + return client, nil +} + +// ListClientsByOwner returns all OAuth clients owned by the given user. +func (s *SQLiteClientStore) ListClientsByOwner(ctx context.Context, ownerID int64) ([]*OAuthClient, error) { + rows, err := s.db.QueryContext(ctx, + `SELECT id, secret_hash, name, redirect_uris, grant_types, scopes, owner_id, created_at + FROM oauth_clients WHERE owner_id = ? ORDER BY name`, ownerID, + ) + if err != nil { + return nil, fmt.Errorf("query clients: %w", err) + } + defer rows.Close() + + var clients []*OAuthClient + for rows.Next() { + var redirectURIsJSON, grantTypesJSON, scopesJSON string + var oid sql.NullInt64 + c := &OAuthClient{} + if err := rows.Scan(&c.ID, &c.SecretHash, &c.Name, + &redirectURIsJSON, &grantTypesJSON, &scopesJSON, &oid, &c.CreatedAt); err != nil { + return nil, fmt.Errorf("scan client: %w", err) + } + json.Unmarshal([]byte(redirectURIsJSON), &c.RedirectURIs) + json.Unmarshal([]byte(grantTypesJSON), &c.GrantTypes) + json.Unmarshal([]byte(scopesJSON), &c.Scopes) + if oid.Valid { + c.OwnerID = oid.Int64 + } + if c.RedirectURIs == nil { + c.RedirectURIs = []string{} + } + if c.GrantTypes == nil { + c.GrantTypes = []string{} + } + if c.Scopes == nil { + c.Scopes = []string{} + } + clients = append(clients, c) + } + if clients == nil { + clients = []*OAuthClient{} + } + return clients, rows.Err() +} + +// VerifyClientSecret checks a client_id/secret combination. +func (s *SQLiteClientStore) VerifyClientSecret(ctx context.Context, clientID, secret string) (*OAuthClient, error) { + client, err := s.GetClient(ctx, clientID) + if err != nil { + return nil, err + } + + if err := bcrypt.CompareHashAndPassword([]byte(client.SecretHash), []byte(secret)); err != nil { + return nil, ErrInvalidPassword + } + + return client, nil +} + +// generateClientID creates a random client identifier. +func generateClientID() (string, error) { + b := make([]byte, 16) + if _, err := rand.Read(b); err != nil { + return "", err + } + return "synapbus_" + hex.EncodeToString(b), nil +} + +// generateClientSecret creates a random client secret. +func generateClientSecret() (string, error) { + b := make([]byte, 32) + if _, err := rand.Read(b); err != nil { + return "", err + } + return "sbs_" + hex.EncodeToString(b), nil +} + +// HasGrantType checks if the client supports the given grant type. +func (c *OAuthClient) HasGrantType(grantType string) bool { + for _, gt := range c.GrantTypes { + if strings.EqualFold(gt, grantType) { + return true + } + } + return false +} diff --git a/internal/auth/config.go b/internal/auth/config.go new file mode 100644 index 0000000..7f6e6c8 --- /dev/null +++ b/internal/auth/config.go @@ -0,0 +1,53 @@ +package auth + +import "time" + +// Config holds configuration for the auth subsystem. +type Config struct { + // BcryptCost is the bcrypt hashing cost. Minimum 10, default 12. + BcryptCost int + + // AccessTokenTTL is the lifetime of access tokens. Default 1 hour. + AccessTokenTTL time.Duration + + // RefreshTokenLifetime is the absolute lifetime of refresh tokens. Default 30 days. + RefreshTokenLifetime time.Duration + + // SessionLifetime is the lifetime of Web UI sessions. Default 24 hours. + SessionLifetime time.Duration + + // IssuerURL is the OAuth issuer URL (e.g., http://localhost:8080). + IssuerURL string + + // DevMode allows HTTP without TLS. When true, a warning is logged. + DevMode bool + + // Secret is the system secret used for HMAC signing of tokens. + // Must be at least 32 bytes. + Secret []byte +} + +// DefaultConfig returns a Config with sensible defaults. +func DefaultConfig() Config { + return Config{ + BcryptCost: 12, + AccessTokenTTL: 1 * time.Hour, + RefreshTokenLifetime: 30 * 24 * time.Hour, + SessionLifetime: 24 * time.Hour, + DevMode: true, + } +} + +// Validate checks that the config values are within acceptable ranges. +func (c Config) Validate() error { + if c.BcryptCost < 10 { + return ErrBcryptCostTooLow + } + if c.BcryptCost > 31 { + return ErrBcryptCostTooHigh + } + if len(c.Secret) < 32 { + return ErrSecretTooShort + } + return nil +} diff --git a/internal/auth/doc.go b/internal/auth/doc.go new file mode 100644 index 0000000..3d9c853 --- /dev/null +++ b/internal/auth/doc.go @@ -0,0 +1,5 @@ +// Package auth provides OAuth 2.1 authorization, user management, and session +// handling for SynapBus. It embeds an OAuth 2.1 authorization server using +// ory/fosite with support for authorization code (PKCE S256), client credentials, +// and refresh token rotation grants. +package auth diff --git a/internal/auth/errors.go b/internal/auth/errors.go new file mode 100644 index 0000000..050c15b --- /dev/null +++ b/internal/auth/errors.go @@ -0,0 +1,38 @@ +package auth + +import "errors" + +// Sentinel errors for the auth package. +var ( + // User errors + ErrUserNotFound = errors.New("user not found") + ErrDuplicateUsername = errors.New("username already exists") + ErrInvalidUsername = errors.New("username must be 3-64 characters, alphanumeric and underscore only") + ErrPasswordTooShort = errors.New("password must be at least 8 characters") + ErrPasswordTooLong = errors.New("password must be at most 72 bytes (bcrypt limit)") + ErrInvalidPassword = errors.New("invalid password") + + // Session errors + ErrSessionNotFound = errors.New("session not found") + ErrSessionExpired = errors.New("session expired") + + // OAuth client errors + ErrClientNotFound = errors.New("client not found") + + // Token errors + ErrTokenNotFound = errors.New("token not found") + ErrTokenExpired = errors.New("token expired") + ErrTokenConsumed = errors.New("token already consumed") + ErrTokenInvalid = errors.New("invalid token") + ErrCodeNotFound = errors.New("authorization code not found") + ErrCodeExpired = errors.New("authorization code expired") + ErrCodeUsed = errors.New("authorization code already used") + ErrPKCERequired = errors.New("PKCE code_challenge is required") + ErrPKCEPlainNotAllowed = errors.New("code_challenge_method 'plain' is not allowed, use S256") + ErrPKCEVerifierMismatch = errors.New("code_verifier does not match code_challenge") + + // Config errors + ErrBcryptCostTooLow = errors.New("bcrypt cost must be at least 10") + ErrBcryptCostTooHigh = errors.New("bcrypt cost must be at most 31") + ErrSecretTooShort = errors.New("system secret must be at least 32 bytes") +) diff --git a/internal/auth/fosite_store.go b/internal/auth/fosite_store.go new file mode 100644 index 0000000..ea3d916 --- /dev/null +++ b/internal/auth/fosite_store.go @@ -0,0 +1,496 @@ +package auth + +import ( + "context" + "crypto/rand" + "crypto/sha256" + "database/sql" + "encoding/json" + "fmt" + "log/slog" + "net/url" + "strings" + "time" + + "github.com/ory/fosite" +) + +// FositeStore implements fosite's storage interfaces backed by SQLite. +// It implements: +// - fosite.Storage (ClientManager + ClientAssertionJWT) +// - oauth2.CoreStorage (AuthorizeCodeStorage + AccessTokenStorage + RefreshTokenStorage) +// - oauth2.TokenRevocationStorage +// - pkce.PKCERequestStorage +type FositeStore struct { + db *sql.DB + bcryptCost int + logger *slog.Logger +} + +// NewFositeStore creates a new fosite storage adapter. +func NewFositeStore(db *sql.DB, bcryptCost int) *FositeStore { + return &FositeStore{ + db: db, + bcryptCost: bcryptCost, + logger: slog.Default().With("component", "fosite-store"), + } +} + +// fositeSession implements fosite.Session for token storage. +type fositeSession struct { + UserID int64 `json:"user_id"` + Username string `json:"username"` + Subject string `json:"subject"` + ExpiresAtMap map[fosite.TokenType]time.Time `json:"expires_at_map"` +} + +// SetExpiresAt implements fosite.Session. +func (s *fositeSession) SetExpiresAt(key fosite.TokenType, exp time.Time) { + if s.ExpiresAtMap == nil { + s.ExpiresAtMap = make(map[fosite.TokenType]time.Time) + } + s.ExpiresAtMap[key] = exp +} + +// GetExpiresAt implements fosite.Session. +func (s *fositeSession) GetExpiresAt(key fosite.TokenType) time.Time { + if s.ExpiresAtMap == nil { + return time.Time{} + } + return s.ExpiresAtMap[key] +} + +// GetUsername implements fosite.Session. +func (s *fositeSession) GetUsername() string { + return s.Username +} + +// GetSubject implements fosite.Session. +func (s *fositeSession) GetSubject() string { + return s.Subject +} + +// Clone implements fosite.Session. +func (s *fositeSession) Clone() fosite.Session { + expiresAtMap := make(map[fosite.TokenType]time.Time) + for k, v := range s.ExpiresAtMap { + expiresAtMap[k] = v + } + return &fositeSession{ + UserID: s.UserID, + Username: s.Username, + Subject: s.Subject, + ExpiresAtMap: expiresAtMap, + } +} + +// --- fosite.ClientManager --- + +// GetClient implements fosite.Storage (ClientManager). +func (s *FositeStore) GetClient(ctx context.Context, id string) (fosite.Client, error) { + var secretHash, name, redirectURIsJSON, grantTypesJSON, scopesJSON string + var ownerID sql.NullInt64 + + err := s.db.QueryRowContext(ctx, + `SELECT id, secret_hash, name, redirect_uris, grant_types, scopes, owner_id + FROM oauth_clients WHERE id = ?`, id, + ).Scan(&id, &secretHash, &name, &redirectURIsJSON, &grantTypesJSON, &scopesJSON, &ownerID) + if err != nil { + if err == sql.ErrNoRows { + return nil, fosite.ErrNotFound + } + s.logger.Error("get client failed", "error", err) + return nil, fosite.ErrServerError + } + + var redirectURIs, grantTypes, scopes []string + json.Unmarshal([]byte(redirectURIsJSON), &redirectURIs) + json.Unmarshal([]byte(grantTypesJSON), &grantTypes) + json.Unmarshal([]byte(scopesJSON), &scopes) + + return &fositeClient{ + id: id, + secretHash: []byte(secretHash), + name: name, + redirectURIs: redirectURIs, + grantTypes: grantTypes, + scopes: scopes, + }, nil +} + +// ClientAssertionJWTValid implements fosite.Storage. +func (s *FositeStore) ClientAssertionJWTValid(ctx context.Context, jti string) error { + return fosite.ErrNotFound +} + +// SetClientAssertionJWT implements fosite.Storage. +func (s *FositeStore) SetClientAssertionJWT(ctx context.Context, jti string, exp time.Time) error { + return nil +} + +// --- oauth2.AuthorizeCodeStorage --- + +// CreateAuthorizeCodeSession stores an authorization code. +func (s *FositeStore) CreateAuthorizeCodeSession(ctx context.Context, code string, request fosite.Requester) error { + sess := s.extractSession(request) + sessJSON, _ := json.Marshal(sess) + scopes := strings.Join(request.GetRequestedScopes(), " ") + client := request.GetClient() + + form := request.GetRequestForm() + codeChallenge := form.Get("code_challenge") + codeChallengeMethod := form.Get("code_challenge_method") + + _, err := s.db.ExecContext(ctx, + `INSERT INTO oauth_authorization_codes (code, client_id, user_id, redirect_uri, scopes, + code_challenge, code_challenge_method, session_data, expires_at, created_at, used) + VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, CURRENT_TIMESTAMP, 0)`, + code, client.GetID(), sess.UserID, + form.Get("redirect_uri"), + scopes, codeChallenge, codeChallengeMethod, + string(sessJSON), + request.GetSession().GetExpiresAt(fosite.AuthorizeCode), + ) + if err != nil { + s.logger.Error("create auth code session failed", "error", err) + return fosite.ErrServerError + } + return nil +} + +// GetAuthorizeCodeSession retrieves an authorization code session. +func (s *FositeStore) GetAuthorizeCodeSession(ctx context.Context, code string, session fosite.Session) (fosite.Requester, error) { + var clientID string + var userID int64 + var redirectURI, scopes, sessData, codeChallenge, codeChallengeMethod string + var expiresAt time.Time + var used int + + err := s.db.QueryRowContext(ctx, + `SELECT client_id, user_id, redirect_uri, scopes, code_challenge, + code_challenge_method, session_data, expires_at, used + FROM oauth_authorization_codes WHERE code = ?`, code, + ).Scan(&clientID, &userID, &redirectURI, &scopes, &codeChallenge, + &codeChallengeMethod, &sessData, &expiresAt, &used) + if err != nil { + if err == sql.ErrNoRows { + return nil, fosite.ErrNotFound + } + s.logger.Error("get auth code session failed", "error", err) + return nil, fosite.ErrServerError + } + + if used != 0 { + return nil, fosite.ErrInvalidatedAuthorizeCode + } + + var sess fositeSession + json.Unmarshal([]byte(sessData), &sess) + + client, err := s.GetClient(ctx, clientID) + if err != nil { + return nil, err + } + + scopesList := splitScopes(scopes) + form := url.Values{} + form.Set("redirect_uri", redirectURI) + form.Set("code_challenge", codeChallenge) + form.Set("code_challenge_method", codeChallengeMethod) + + req := &fosite.Request{ + ID: uuid(), + Client: client, + RequestedScope: scopesList, + GrantedScope: scopesList, + Session: &sess, + Form: form, + RequestedAt: time.Now(), + RequestedAudience: []string{}, + GrantedAudience: []string{}, + } + + return req, nil +} + +// InvalidateAuthorizeCodeSession marks an authorization code as used. +func (s *FositeStore) InvalidateAuthorizeCodeSession(ctx context.Context, code string) error { + _, err := s.db.ExecContext(ctx, + "UPDATE oauth_authorization_codes SET used = 1 WHERE code = ?", code, + ) + if err != nil { + s.logger.Error("invalidate auth code failed", "error", err) + return fosite.ErrServerError + } + return nil +} + +// --- oauth2.AccessTokenStorage --- + +// CreateAccessTokenSession stores an access token. +func (s *FositeStore) CreateAccessTokenSession(ctx context.Context, signature string, request fosite.Requester) error { + return s.createTokenSession(ctx, signature, TokenTypeAccess, request) +} + +// GetAccessTokenSession retrieves an access token session. +func (s *FositeStore) GetAccessTokenSession(ctx context.Context, signature string, session fosite.Session) (fosite.Requester, error) { + return s.getTokenSession(ctx, signature, TokenTypeAccess) +} + +// DeleteAccessTokenSession removes an access token. +func (s *FositeStore) DeleteAccessTokenSession(ctx context.Context, signature string) error { + return s.deleteTokenSession(ctx, signature) +} + +// --- oauth2.RefreshTokenStorage --- + +// CreateRefreshTokenSession stores a refresh token. +// accessSignature links this refresh token to the corresponding access token. +func (s *FositeStore) CreateRefreshTokenSession(ctx context.Context, signature string, accessSignature string, request fosite.Requester) error { + sess := s.extractSession(request) + sessJSON, _ := json.Marshal(sess) + scopes := strings.Join(request.GetGrantedScopes(), " ") + client := request.GetClient() + + var userID interface{} + if sess.UserID > 0 { + userID = sess.UserID + } else { + userID = nil + } + + _, err := s.db.ExecContext(ctx, + `INSERT INTO oauth_tokens (signature, client_id, user_id, access_token_hash, refresh_token_hash, + scope, token_type, session_data, expires_at, created_at, consumed, parent_signature) + VALUES (?, ?, ?, ?, '', ?, ?, ?, ?, CURRENT_TIMESTAMP, 0, ?)`, + signature, client.GetID(), userID, + hashSignature(signature), scopes, TokenTypeRefresh, string(sessJSON), + request.GetSession().GetExpiresAt(fosite.RefreshToken), + accessSignature, + ) + if err != nil { + s.logger.Error("create refresh token session failed", "error", err) + return fosite.ErrServerError + } + return nil +} + +// GetRefreshTokenSession retrieves a refresh token session. +func (s *FositeStore) GetRefreshTokenSession(ctx context.Context, signature string, session fosite.Session) (fosite.Requester, error) { + return s.getTokenSession(ctx, signature, TokenTypeRefresh) +} + +// DeleteRefreshTokenSession removes a refresh token. +func (s *FositeStore) DeleteRefreshTokenSession(ctx context.Context, signature string) error { + return s.deleteTokenSession(ctx, signature) +} + +// RotateRefreshToken rotates a refresh token by consuming the old one and linking to the new one. +func (s *FositeStore) RotateRefreshToken(ctx context.Context, requestID string, refreshTokenSignature string) error { + // Mark the old refresh token as consumed + _, err := s.db.ExecContext(ctx, + "UPDATE oauth_tokens SET consumed = 1 WHERE signature = ? AND token_type = 'refresh'", + refreshTokenSignature, + ) + if err != nil { + s.logger.Error("rotate refresh token failed", "error", err) + return fosite.ErrServerError + } + return nil +} + +// --- oauth2.TokenRevocationStorage --- +// Note: TokenRevocationStorage embeds RefreshTokenStorage and AccessTokenStorage, +// both of which are already implemented above. + +// RevokeRefreshToken revokes a refresh token by request ID. +func (s *FositeStore) RevokeRefreshToken(ctx context.Context, requestID string) error { + // Revoke all refresh tokens for this request + _, err := s.db.ExecContext(ctx, + "UPDATE oauth_tokens SET consumed = 1 WHERE token_type = 'refresh' AND signature = ?", + requestID, + ) + return err +} + +// RevokeAccessToken revokes an access token by request ID. +func (s *FositeStore) RevokeAccessToken(ctx context.Context, requestID string) error { + _, err := s.db.ExecContext(ctx, + "DELETE FROM oauth_tokens WHERE signature = ? AND token_type = 'access'", requestID, + ) + return err +} + +// --- pkce.PKCERequestStorage --- + +// CreatePKCERequestSession stores PKCE data for an authorization code. +func (s *FositeStore) CreatePKCERequestSession(ctx context.Context, signature string, request fosite.Requester) error { + // PKCE data is stored as part of the authorization code session + return nil +} + +// GetPKCERequestSession retrieves PKCE data for an authorization code. +func (s *FositeStore) GetPKCERequestSession(ctx context.Context, signature string, session fosite.Session) (fosite.Requester, error) { + return s.GetAuthorizeCodeSession(ctx, signature, session) +} + +// DeletePKCERequestSession removes PKCE data for an authorization code. +func (s *FositeStore) DeletePKCERequestSession(ctx context.Context, signature string) error { + return nil +} + +// --- Internal helpers --- + +func (s *FositeStore) createTokenSession(ctx context.Context, signature, tokenType string, request fosite.Requester) error { + sess := s.extractSession(request) + sessJSON, _ := json.Marshal(sess) + scopes := strings.Join(request.GetGrantedScopes(), " ") + client := request.GetClient() + + expiresAt := request.GetSession().GetExpiresAt(fosite.AccessToken) + if tokenType == TokenTypeRefresh { + expiresAt = request.GetSession().GetExpiresAt(fosite.RefreshToken) + } + + // user_id can be NULL for client_credentials grants (no user involved) + var userID interface{} + if sess.UserID > 0 { + userID = sess.UserID + } else { + userID = nil + } + + _, err := s.db.ExecContext(ctx, + `INSERT INTO oauth_tokens (signature, client_id, user_id, access_token_hash, refresh_token_hash, + scope, token_type, session_data, expires_at, created_at, consumed, parent_signature) + VALUES (?, ?, ?, ?, '', ?, ?, ?, ?, CURRENT_TIMESTAMP, 0, '')`, + signature, client.GetID(), userID, + hashSignature(signature), scopes, tokenType, string(sessJSON), + expiresAt, + ) + if err != nil { + s.logger.Error("create token session failed", "token_type", tokenType, "error", err) + return fosite.ErrServerError + } + return nil +} + +func (s *FositeStore) getTokenSession(ctx context.Context, signature, tokenType string) (fosite.Requester, error) { + var clientID string + var userID sql.NullInt64 + var scopes, sessData string + var expiresAt time.Time + var consumed int + + err := s.db.QueryRowContext(ctx, + `SELECT client_id, user_id, scope, session_data, expires_at, consumed + FROM oauth_tokens WHERE signature = ? AND token_type = ?`, + signature, tokenType, + ).Scan(&clientID, &userID, &scopes, &sessData, &expiresAt, &consumed) + if err != nil { + if err == sql.ErrNoRows { + return nil, fosite.ErrNotFound + } + s.logger.Error("get token session failed", "error", err) + return nil, fosite.ErrServerError + } + + if consumed != 0 { + // Token was consumed (refresh token rotation) + // Revoke entire token family + s.revokeTokenFamily(ctx, signature) + return nil, fosite.ErrInactiveToken + } + + var sess fositeSession + json.Unmarshal([]byte(sessData), &sess) + + client, err := s.GetClient(ctx, clientID) + if err != nil { + return nil, err + } + + scopesList := splitScopes(scopes) + req := &fosite.Request{ + ID: uuid(), + Client: client, + RequestedScope: scopesList, + GrantedScope: scopesList, + Session: &sess, + Form: url.Values{}, + RequestedAt: time.Now(), + RequestedAudience: []string{}, + GrantedAudience: []string{}, + } + + return req, nil +} + +func (s *FositeStore) deleteTokenSession(ctx context.Context, signature string) error { + _, err := s.db.ExecContext(ctx, + "DELETE FROM oauth_tokens WHERE signature = ?", signature, + ) + return err +} + +// revokeTokenFamily revokes all tokens in a refresh token chain. +func (s *FositeStore) revokeTokenFamily(ctx context.Context, signature string) { + _, err := s.db.ExecContext(ctx, + `UPDATE oauth_tokens SET consumed = 1 WHERE client_id IN ( + SELECT client_id FROM oauth_tokens WHERE signature = ? + )`, signature, + ) + if err != nil { + s.logger.Error("revoke token family failed", "signature", signature, "error", err) + } +} + +func (s *FositeStore) extractSession(request fosite.Requester) *fositeSession { + if sess, ok := request.GetSession().(*fositeSession); ok { + return sess + } + return &fositeSession{} +} + +func hashSignature(sig string) string { + h := sha256.Sum256([]byte(sig)) + return fmt.Sprintf("%x", h) +} + +func splitScopes(scopes string) fosite.Arguments { + if scopes == "" { + return fosite.Arguments{} + } + return fosite.Arguments(strings.Split(scopes, " ")) +} + +func uuid() string { + b := make([]byte, 16) + rand.Read(b) + return fmt.Sprintf("%x-%x-%x-%x-%x", b[0:4], b[4:6], b[6:8], b[8:10], b[10:]) +} + +// --- fositeClient implements fosite.Client --- + +type fositeClient struct { + id string + secretHash []byte + name string + redirectURIs []string + grantTypes []string + scopes []string +} + +func (c *fositeClient) GetID() string { return c.id } +func (c *fositeClient) GetHashedSecret() []byte { return c.secretHash } +func (c *fositeClient) GetRedirectURIs() []string { return c.redirectURIs } +func (c *fositeClient) GetGrantTypes() fosite.Arguments { return fosite.Arguments(c.grantTypes) } +func (c *fositeClient) GetResponseTypes() fosite.Arguments { return fosite.Arguments{"code"} } +func (c *fositeClient) GetScopes() fosite.Arguments { return fosite.Arguments(c.scopes) } +func (c *fositeClient) IsPublic() bool { return false } +func (c *fositeClient) GetAudience() fosite.Arguments { return fosite.Arguments{} } + +// GetResponseModes implements fosite.ResponseModeClient. +func (c *fositeClient) GetResponseModes() []fosite.ResponseModeType { + return []fosite.ResponseModeType{fosite.ResponseModeQuery} +} diff --git a/internal/auth/handlers.go b/internal/auth/handlers.go new file mode 100644 index 0000000..aea3b45 --- /dev/null +++ b/internal/auth/handlers.go @@ -0,0 +1,390 @@ +package auth + +import ( + "encoding/json" + "log/slog" + "net/http" + "strings" + "time" + + "github.com/ory/fosite" +) + +// Handlers holds the HTTP handlers for the auth subsystem. +type Handlers struct { + userStore UserStore + sessionStore SessionStore + clientStore ClientStore + provider fosite.OAuth2Provider + config Config + logger *slog.Logger +} + +// NewHandlers creates a new set of auth HTTP handlers. +func NewHandlers( + userStore UserStore, + sessionStore SessionStore, + clientStore ClientStore, + provider fosite.OAuth2Provider, + config Config, +) *Handlers { + return &Handlers{ + userStore: userStore, + sessionStore: sessionStore, + clientStore: clientStore, + provider: provider, + config: config, + logger: slog.Default().With("component", "auth"), + } +} + +// HandleRegister handles POST /auth/register. +func (h *Handlers) HandleRegister(w http.ResponseWriter, r *http.Request) { + if r.Method != http.MethodPost { + writeError(w, http.StatusMethodNotAllowed, "method_not_allowed", "POST required") + return + } + + var req struct { + Username string `json:"username"` + Password string `json:"password"` + DisplayName string `json:"display_name"` + } + + if err := json.NewDecoder(r.Body).Decode(&req); err != nil { + writeError(w, http.StatusBadRequest, "invalid_request", "Invalid JSON body") + return + } + + user, err := h.userStore.CreateUser(r.Context(), req.Username, req.Password, req.DisplayName) + if err != nil { + switch err { + case ErrDuplicateUsername: + writeError(w, http.StatusConflict, "duplicate_username", "Username already exists") + case ErrInvalidUsername: + writeError(w, http.StatusBadRequest, "invalid_username", err.Error()) + case ErrPasswordTooShort: + writeError(w, http.StatusBadRequest, "invalid_password", err.Error()) + case ErrPasswordTooLong: + writeError(w, http.StatusBadRequest, "invalid_password", err.Error()) + default: + h.logger.Error("create user failed", "error", err) + writeError(w, http.StatusInternalServerError, "server_error", "Failed to create user") + } + return + } + + LogAuthEvent(r.Context(), h.logger, AuthEvent{ + Type: EventUserCreated, + UserID: user.ID, + Username: user.Username, + RemoteIP: remoteIP(r), + }) + + w.Header().Set("Content-Type", "application/json") + w.WriteHeader(http.StatusCreated) + json.NewEncoder(w).Encode(user) +} + +// HandleLogin handles POST /auth/login. +func (h *Handlers) HandleLogin(w http.ResponseWriter, r *http.Request) { + if r.Method != http.MethodPost { + writeError(w, http.StatusMethodNotAllowed, "method_not_allowed", "POST required") + return + } + + var req struct { + Username string `json:"username"` + Password string `json:"password"` + } + + if err := json.NewDecoder(r.Body).Decode(&req); err != nil { + writeError(w, http.StatusBadRequest, "invalid_request", "Invalid JSON body") + return + } + + user, err := h.userStore.VerifyPassword(r.Context(), req.Username, req.Password) + if err != nil { + LogAuthEvent(r.Context(), h.logger, AuthEvent{ + Type: EventLoginFailure, + Username: req.Username, + RemoteIP: remoteIP(r), + }) + writeError(w, http.StatusUnauthorized, "invalid_credentials", "Invalid username or password") + return + } + + session, err := h.sessionStore.CreateSession(r.Context(), user.ID, h.config.SessionLifetime) + if err != nil { + h.logger.Error("create session failed", "error", err) + writeError(w, http.StatusInternalServerError, "server_error", "Failed to create session") + return + } + + // Set session cookie + http.SetCookie(w, &http.Cookie{ + Name: SessionCookieName, + Value: session.SessionID, + Path: "/", + HttpOnly: true, + Secure: !h.config.DevMode, + SameSite: http.SameSiteLaxMode, + MaxAge: int(h.config.SessionLifetime.Seconds()), + }) + + LogAuthEvent(r.Context(), h.logger, AuthEvent{ + Type: EventLoginSuccess, + UserID: user.ID, + Username: user.Username, + RemoteIP: remoteIP(r), + }) + + LogAuthEvent(r.Context(), h.logger, AuthEvent{ + Type: EventSessionCreated, + UserID: user.ID, + Username: user.Username, + RemoteIP: remoteIP(r), + }) + + w.Header().Set("Content-Type", "application/json") + json.NewEncoder(w).Encode(user) +} + +// HandleLogout handles POST /auth/logout. +func (h *Handlers) HandleLogout(w http.ResponseWriter, r *http.Request) { + if r.Method != http.MethodPost { + writeError(w, http.StatusMethodNotAllowed, "method_not_allowed", "POST required") + return + } + + cookie, err := r.Cookie(SessionCookieName) + if err == nil && cookie.Value != "" { + h.sessionStore.DeleteSession(r.Context(), cookie.Value) + + user, ok := UserFromContext(r.Context()) + if ok { + LogAuthEvent(r.Context(), h.logger, AuthEvent{ + Type: EventSessionDestroyed, + UserID: user.ID, + Username: user.Username, + RemoteIP: remoteIP(r), + }) + } + } + + // Clear cookie + http.SetCookie(w, &http.Cookie{ + Name: SessionCookieName, + Value: "", + Path: "/", + HttpOnly: true, + Secure: !h.config.DevMode, + SameSite: http.SameSiteLaxMode, + MaxAge: -1, + }) + + w.WriteHeader(http.StatusOK) + w.Write([]byte(`{"status":"logged_out"}`)) +} + +// HandleMe handles GET /auth/me. +func (h *Handlers) HandleMe(w http.ResponseWriter, r *http.Request) { + if r.Method != http.MethodGet { + writeError(w, http.StatusMethodNotAllowed, "method_not_allowed", "GET required") + return + } + + user, ok := UserFromContext(r.Context()) + if !ok { + writeError(w, http.StatusUnauthorized, "unauthorized", "Not authenticated") + return + } + + w.Header().Set("Content-Type", "application/json") + json.NewEncoder(w).Encode(user) +} + +// HandleChangePassword handles PUT /auth/password. +func (h *Handlers) HandleChangePassword(w http.ResponseWriter, r *http.Request) { + if r.Method != http.MethodPut { + writeError(w, http.StatusMethodNotAllowed, "method_not_allowed", "PUT required") + return + } + + user, ok := UserFromContext(r.Context()) + if !ok { + writeError(w, http.StatusUnauthorized, "unauthorized", "Not authenticated") + return + } + + var req struct { + CurrentPassword string `json:"current_password"` + NewPassword string `json:"new_password"` + } + + if err := json.NewDecoder(r.Body).Decode(&req); err != nil { + writeError(w, http.StatusBadRequest, "invalid_request", "Invalid JSON body") + return + } + + // Verify current password + if _, err := h.userStore.VerifyPassword(r.Context(), user.Username, req.CurrentPassword); err != nil { + writeError(w, http.StatusForbidden, "invalid_password", "Current password is incorrect") + return + } + + // Update password + if err := h.userStore.UpdatePassword(r.Context(), user.ID, req.NewPassword); err != nil { + switch err { + case ErrPasswordTooShort: + writeError(w, http.StatusBadRequest, "invalid_password", err.Error()) + case ErrPasswordTooLong: + writeError(w, http.StatusBadRequest, "invalid_password", err.Error()) + default: + h.logger.Error("update password failed", "error", err) + writeError(w, http.StatusInternalServerError, "server_error", "Failed to update password") + } + return + } + + // Invalidate all sessions except current + if sessionID, ok := SessionIDFromContext(r.Context()); ok { + h.sessionStore.DeleteSessionsByUserExcept(r.Context(), user.ID, sessionID) + } + + LogAuthEvent(r.Context(), h.logger, AuthEvent{ + Type: EventPasswordChanged, + UserID: user.ID, + Username: user.Username, + RemoteIP: remoteIP(r), + }) + + w.WriteHeader(http.StatusOK) + w.Write([]byte(`{"status":"password_changed"}`)) +} + +// HandleAuthorize handles GET /oauth/authorize. +func (h *Handlers) HandleAuthorize(w http.ResponseWriter, r *http.Request) { + ctx := r.Context() + + ar, err := h.provider.NewAuthorizeRequest(ctx, r) + if err != nil { + h.logger.Debug("authorize request failed", "error", err) + h.provider.WriteAuthorizeError(ctx, w, ar, err) + return + } + + // Check if user is authenticated via session + user, ok := UserFromContext(ctx) + if !ok { + // User needs to log in first + // In a real implementation, this would redirect to a login page + writeError(w, http.StatusUnauthorized, "login_required", "Please log in first") + return + } + + // Create session for fosite + sess := NewSession(user) + response, err := h.provider.NewAuthorizeResponse(ctx, ar, sess) + if err != nil { + h.logger.Debug("authorize response failed", "error", err) + h.provider.WriteAuthorizeError(ctx, w, ar, err) + return + } + + h.provider.WriteAuthorizeResponse(ctx, w, ar, response) +} + +// HandleToken handles POST /oauth/token. +func (h *Handlers) HandleToken(w http.ResponseWriter, r *http.Request) { + ctx := r.Context() + sess := &fositeSession{} + + ar, err := h.provider.NewAccessRequest(ctx, r, sess) + if err != nil { + h.logger.Debug("access request failed", "error", err) + h.provider.WriteAccessError(ctx, w, ar, err) + return + } + + // Grant requested scopes + for _, scope := range ar.GetRequestedScopes() { + ar.GrantScope(scope) + } + + response, err := h.provider.NewAccessResponse(ctx, ar) + if err != nil { + h.logger.Debug("access response failed", "error", err) + h.provider.WriteAccessError(ctx, w, ar, err) + return + } + + grantType := r.FormValue("grant_type") + LogAuthEvent(ctx, h.logger, AuthEvent{ + Type: EventTokenIssued, + ClientID: ar.GetClient().GetID(), + RemoteIP: remoteIP(r), + Details: map[string]any{ + "grant_type": grantType, + }, + }) + + if grantType == "refresh_token" { + LogAuthEvent(ctx, h.logger, AuthEvent{ + Type: EventTokenRefreshed, + ClientID: ar.GetClient().GetID(), + RemoteIP: remoteIP(r), + }) + } + + h.provider.WriteAccessResponse(ctx, w, ar, response) +} + +// HandleIntrospect handles POST /oauth/introspect. +func (h *Handlers) HandleIntrospect(w http.ResponseWriter, r *http.Request) { + if r.Method != http.MethodPost { + writeError(w, http.StatusMethodNotAllowed, "method_not_allowed", "POST required") + return + } + + ctx := r.Context() + sess := &fositeSession{} + + ir, err := h.provider.NewIntrospectionRequest(ctx, r, sess) + if err != nil { + h.logger.Debug("introspection request failed", "error", err) + w.Header().Set("Content-Type", "application/json") + json.NewEncoder(w).Encode(IntrospectionResponse{Active: false}) + return + } + + resp := IntrospectionResponse{ + Active: ir.IsActive(), + ClientID: ir.GetAccessRequester().GetClient().GetID(), + TokenType: "bearer", + } + + if sess, ok := ir.GetAccessRequester().GetSession().(*fositeSession); ok { + resp.Username = sess.Username + resp.Subject = sess.Subject + if exp := sess.GetExpiresAt(fosite.AccessToken); !exp.IsZero() { + resp.ExpiresAt = exp.Unix() + } + } + + resp.Scope = strings.Join(ir.GetAccessRequester().GetGrantedScopes(), " ") + resp.IssuedAt = time.Now().Unix() // approximate + + w.Header().Set("Content-Type", "application/json") + json.NewEncoder(w).Encode(resp) +} + +// writeError writes a JSON error response. +func writeError(w http.ResponseWriter, status int, errCode, description string) { + w.Header().Set("Content-Type", "application/json") + w.WriteHeader(status) + json.NewEncoder(w).Encode(ErrorResponse{ + Error: errCode, + Description: description, + }) +} diff --git a/internal/auth/handlers_test.go b/internal/auth/handlers_test.go new file mode 100644 index 0000000..c83b6a6 --- /dev/null +++ b/internal/auth/handlers_test.go @@ -0,0 +1,333 @@ +package auth + +import ( + "bytes" + "context" + "database/sql" + "encoding/json" + "net/http" + "net/http/httptest" + "testing" + "time" +) + +func setupHandlers(t *testing.T) (*Handlers, *sql.DB) { + t.Helper() + db := newTestDB(t) + + cfg := DefaultConfig() + cfg.BcryptCost = 10 // faster for tests + cfg.Secret = make([]byte, 32) + for i := range cfg.Secret { + cfg.Secret[i] = byte(i) + } + + userStore := NewSQLiteUserStore(db, cfg.BcryptCost) + sessionStore := NewSQLiteSessionStore(db) + clientStore := NewSQLiteClientStore(db, cfg.BcryptCost) + fositeStore := NewFositeStore(db, cfg.BcryptCost) + provider := NewOAuthProvider(cfg, fositeStore) + handlers := NewHandlers(userStore, sessionStore, clientStore, provider, cfg) + + return handlers, db +} + +func TestHandlers_Register(t *testing.T) { + h, _ := setupHandlers(t) + + t.Run("successful registration", func(t *testing.T) { + body := `{"username":"newuser","password":"password123","display_name":"New User"}` + req := httptest.NewRequest(http.MethodPost, "/auth/register", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + rr := httptest.NewRecorder() + + h.HandleRegister(rr, req) + + if rr.Code != http.StatusCreated { + t.Errorf("status = %d, want %d. Body: %s", rr.Code, http.StatusCreated, rr.Body.String()) + } + + var user User + if err := json.NewDecoder(rr.Body).Decode(&user); err != nil { + t.Fatalf("decode response: %v", err) + } + if user.Username != "newuser" { + t.Errorf("Username = %q, want %q", user.Username, "newuser") + } + if user.DisplayName != "New User" { + t.Errorf("DisplayName = %q, want %q", user.DisplayName, "New User") + } + }) + + t.Run("duplicate username returns 409", func(t *testing.T) { + body := `{"username":"newuser","password":"password123"}` + req := httptest.NewRequest(http.MethodPost, "/auth/register", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + rr := httptest.NewRecorder() + + h.HandleRegister(rr, req) + + if rr.Code != http.StatusConflict { + t.Errorf("status = %d, want %d", rr.Code, http.StatusConflict) + } + }) + + t.Run("short password returns 400", func(t *testing.T) { + body := `{"username":"shortpw","password":"short"}` + req := httptest.NewRequest(http.MethodPost, "/auth/register", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + rr := httptest.NewRecorder() + + h.HandleRegister(rr, req) + + if rr.Code != http.StatusBadRequest { + t.Errorf("status = %d, want %d", rr.Code, http.StatusBadRequest) + } + }) + + t.Run("invalid username returns 400", func(t *testing.T) { + body := `{"username":"ab","password":"password123"}` + req := httptest.NewRequest(http.MethodPost, "/auth/register", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + rr := httptest.NewRecorder() + + h.HandleRegister(rr, req) + + if rr.Code != http.StatusBadRequest { + t.Errorf("status = %d, want %d", rr.Code, http.StatusBadRequest) + } + }) + + t.Run("invalid JSON returns 400", func(t *testing.T) { + req := httptest.NewRequest(http.MethodPost, "/auth/register", bytes.NewBufferString("{invalid")) + req.Header.Set("Content-Type", "application/json") + rr := httptest.NewRecorder() + + h.HandleRegister(rr, req) + + if rr.Code != http.StatusBadRequest { + t.Errorf("status = %d, want %d", rr.Code, http.StatusBadRequest) + } + }) +} + +func TestHandlers_Login(t *testing.T) { + h, db := setupHandlers(t) + ctx := context.Background() + + // Create a test user + userStore := NewSQLiteUserStore(db, 10) + userStore.CreateUser(ctx, "loginuser", "password123", "Login User") + + t.Run("successful login", func(t *testing.T) { + body := `{"username":"loginuser","password":"password123"}` + req := httptest.NewRequest(http.MethodPost, "/auth/login", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + rr := httptest.NewRecorder() + + h.HandleLogin(rr, req) + + if rr.Code != http.StatusOK { + t.Errorf("status = %d, want %d. Body: %s", rr.Code, http.StatusOK, rr.Body.String()) + } + + // Check session cookie + cookies := rr.Result().Cookies() + var sessionCookie *http.Cookie + for _, c := range cookies { + if c.Name == SessionCookieName { + sessionCookie = c + break + } + } + if sessionCookie == nil { + t.Fatal("session cookie not set") + } + if !sessionCookie.HttpOnly { + t.Error("session cookie should be HttpOnly") + } + if sessionCookie.SameSite != http.SameSiteLaxMode { + t.Error("session cookie should be SameSite=Lax") + } + }) + + t.Run("wrong password returns 401", func(t *testing.T) { + body := `{"username":"loginuser","password":"wrongpassword"}` + req := httptest.NewRequest(http.MethodPost, "/auth/login", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + rr := httptest.NewRecorder() + + h.HandleLogin(rr, req) + + if rr.Code != http.StatusUnauthorized { + t.Errorf("status = %d, want %d", rr.Code, http.StatusUnauthorized) + } + }) + + t.Run("non-existent user returns 401", func(t *testing.T) { + body := `{"username":"nobody","password":"password123"}` + req := httptest.NewRequest(http.MethodPost, "/auth/login", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + rr := httptest.NewRecorder() + + h.HandleLogin(rr, req) + + if rr.Code != http.StatusUnauthorized { + t.Errorf("status = %d, want %d", rr.Code, http.StatusUnauthorized) + } + }) +} + +func TestHandlers_Logout(t *testing.T) { + h, db := setupHandlers(t) + ctx := context.Background() + + userStore := NewSQLiteUserStore(db, 10) + sessStore := NewSQLiteSessionStore(db) + + user, _ := userStore.CreateUser(ctx, "logoutuser", "password123", "") + session, _ := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + + req := httptest.NewRequest(http.MethodPost, "/auth/logout", nil) + req.AddCookie(&http.Cookie{Name: SessionCookieName, Value: session.SessionID}) + // Add user to context (normally done by middleware) + req = req.WithContext(ContextWithUser(req.Context(), user)) + rr := httptest.NewRecorder() + + h.HandleLogout(rr, req) + + if rr.Code != http.StatusOK { + t.Errorf("status = %d, want %d", rr.Code, http.StatusOK) + } + + // Cookie should be cleared + cookies := rr.Result().Cookies() + for _, c := range cookies { + if c.Name == SessionCookieName && c.MaxAge != -1 { + t.Error("session cookie should be cleared (MaxAge = -1)") + } + } + + // Session should be deleted + _, err := sessStore.GetSession(ctx, session.SessionID) + if err != ErrSessionNotFound { + t.Errorf("session should be deleted after logout") + } +} + +func TestHandlers_Me(t *testing.T) { + h, db := setupHandlers(t) + ctx := context.Background() + + userStore := NewSQLiteUserStore(db, 10) + user, _ := userStore.CreateUser(ctx, "meuser", "password123", "Me User") + + t.Run("authenticated", func(t *testing.T) { + req := httptest.NewRequest(http.MethodGet, "/auth/me", nil) + req = req.WithContext(ContextWithUser(req.Context(), user)) + rr := httptest.NewRecorder() + + h.HandleMe(rr, req) + + if rr.Code != http.StatusOK { + t.Errorf("status = %d, want %d", rr.Code, http.StatusOK) + } + + var resp User + json.NewDecoder(rr.Body).Decode(&resp) + if resp.Username != "meuser" { + t.Errorf("Username = %q, want %q", resp.Username, "meuser") + } + }) + + t.Run("unauthenticated", func(t *testing.T) { + req := httptest.NewRequest(http.MethodGet, "/auth/me", nil) + rr := httptest.NewRecorder() + + h.HandleMe(rr, req) + + if rr.Code != http.StatusUnauthorized { + t.Errorf("status = %d, want %d", rr.Code, http.StatusUnauthorized) + } + }) +} + +func TestHandlers_ChangePassword(t *testing.T) { + h, db := setupHandlers(t) + ctx := context.Background() + + userStore := NewSQLiteUserStore(db, 10) + sessStore := NewSQLiteSessionStore(db) + + user, _ := userStore.CreateUser(ctx, "chpwuser", "oldpassword1", "") + session, _ := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + // Create another session that should be invalidated + sess2, _ := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + + t.Run("successful password change", func(t *testing.T) { + body := `{"current_password":"oldpassword1","new_password":"newpassword1"}` + req := httptest.NewRequest(http.MethodPut, "/auth/password", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + req = req.WithContext(ContextWithUser(req.Context(), user)) + req = req.WithContext(ContextWithSessionID(req.Context(), session.SessionID)) + rr := httptest.NewRecorder() + + h.HandleChangePassword(rr, req) + + if rr.Code != http.StatusOK { + t.Errorf("status = %d, want %d. Body: %s", rr.Code, http.StatusOK, rr.Body.String()) + } + + // Verify old password no longer works + _, err := userStore.VerifyPassword(ctx, "chpwuser", "oldpassword1") + if err != ErrInvalidPassword { + t.Error("old password should not work") + } + + // Verify new password works + _, err = userStore.VerifyPassword(ctx, "chpwuser", "newpassword1") + if err != nil { + t.Errorf("new password should work: %v", err) + } + + // Other sessions should be invalidated + _, err = sessStore.GetSession(ctx, sess2.SessionID) + if err != ErrSessionNotFound { + t.Error("other sessions should be invalidated after password change") + } + + // Current session should still exist + _, err = sessStore.GetSession(ctx, session.SessionID) + if err != nil { + t.Errorf("current session should still exist: %v", err) + } + }) + + t.Run("wrong current password returns 403", func(t *testing.T) { + body := `{"current_password":"wrongpassword","new_password":"newpassword2"}` + req := httptest.NewRequest(http.MethodPut, "/auth/password", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + req = req.WithContext(ContextWithUser(req.Context(), user)) + rr := httptest.NewRecorder() + + h.HandleChangePassword(rr, req) + + if rr.Code != http.StatusForbidden { + t.Errorf("status = %d, want %d", rr.Code, http.StatusForbidden) + } + }) + + t.Run("short new password returns 400", func(t *testing.T) { + body := `{"current_password":"newpassword1","new_password":"short"}` + req := httptest.NewRequest(http.MethodPut, "/auth/password", bytes.NewBufferString(body)) + req.Header.Set("Content-Type", "application/json") + req = req.WithContext(ContextWithUser(req.Context(), user)) + rr := httptest.NewRecorder() + + h.HandleChangePassword(rr, req) + + if rr.Code != http.StatusBadRequest { + t.Errorf("status = %d, want %d", rr.Code, http.StatusBadRequest) + } + }) +} diff --git a/internal/auth/logging.go b/internal/auth/logging.go new file mode 100644 index 0000000..95fb237 --- /dev/null +++ b/internal/auth/logging.go @@ -0,0 +1,63 @@ +package auth + +import ( + "context" + "log/slog" + "net/http" +) + +// Auth event type constants. +const ( + EventLoginSuccess = "login_success" + EventLoginFailure = "login_failure" + EventTokenIssued = "token_issued" + EventTokenRefreshed = "token_refreshed" + EventTokenRevoked = "token_revoked" + EventSessionCreated = "session_created" + EventSessionDestroyed = "session_destroyed" + EventUserCreated = "user_created" + EventPasswordChanged = "password_changed" +) + +// AuthEvent represents a structured auth event for logging. +type AuthEvent struct { + Type string + UserID int64 + Username string + ClientID string + RemoteIP string + Details map[string]any +} + +// LogAuthEvent logs an authentication event with structured fields. +func LogAuthEvent(ctx context.Context, logger *slog.Logger, event AuthEvent) { + attrs := []any{ + "event", event.Type, + } + + if event.UserID > 0 { + attrs = append(attrs, "user_id", event.UserID) + } + if event.Username != "" { + attrs = append(attrs, "username", event.Username) + } + if event.ClientID != "" { + attrs = append(attrs, "client_id", event.ClientID) + } + if event.RemoteIP != "" { + attrs = append(attrs, "remote_ip", event.RemoteIP) + } + for k, v := range event.Details { + attrs = append(attrs, k, v) + } + + logger.InfoContext(ctx, "auth event", attrs...) +} + +// remoteIP extracts the remote IP from an HTTP request. +func remoteIP(r *http.Request) string { + if forwarded := r.Header.Get("X-Forwarded-For"); forwarded != "" { + return forwarded + } + return r.RemoteAddr +} diff --git a/internal/auth/middleware.go b/internal/auth/middleware.go new file mode 100644 index 0000000..1ece61d --- /dev/null +++ b/internal/auth/middleware.go @@ -0,0 +1,168 @@ +package auth + +import ( + "context" + "log/slog" + "net/http" + "strings" + + "github.com/ory/fosite" +) + +type contextKey string + +const ( + userContextKey contextKey = "auth_user" + clientContextKey contextKey = "auth_client" + sessionContextKey contextKey = "auth_session_id" +) + +// UserFromContext extracts the authenticated user from the context. +func UserFromContext(ctx context.Context) (*User, bool) { + user, ok := ctx.Value(userContextKey).(*User) + return user, ok +} + +// ContextWithUser returns a new context with the user set. +func ContextWithUser(ctx context.Context, user *User) context.Context { + return context.WithValue(ctx, userContextKey, user) +} + +// SessionIDFromContext extracts the session ID from the context. +func SessionIDFromContext(ctx context.Context) (string, bool) { + sid, ok := ctx.Value(sessionContextKey).(string) + return sid, ok +} + +// ContextWithSessionID returns a new context with the session ID set. +func ContextWithSessionID(ctx context.Context, sessionID string) context.Context { + return context.WithValue(ctx, sessionContextKey, sessionID) +} + +// ClientFromContext extracts the authenticated client identity from the context. +func ClientFromContext(ctx context.Context) (string, bool) { + cid, ok := ctx.Value(clientContextKey).(string) + return cid, ok +} + +// ContextWithClient returns a new context with the client ID set. +func ContextWithClient(ctx context.Context, clientID string) context.Context { + return context.WithValue(ctx, clientContextKey, clientID) +} + +// SessionCookieName is the name of the session cookie. +const SessionCookieName = "synapbus_session" + +// RequireSession creates middleware that checks for a valid session cookie. +// If valid, it injects the user into the context. If not, returns 401. +func RequireSession(userStore UserStore, sessionStore SessionStore) func(http.Handler) http.Handler { + return func(next http.Handler) http.Handler { + return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + cookie, err := r.Cookie(SessionCookieName) + if err != nil || cookie.Value == "" { + http.Error(w, `{"error":"unauthorized","message":"No session cookie"}`, http.StatusUnauthorized) + return + } + + session, err := sessionStore.GetSession(r.Context(), cookie.Value) + if err != nil { + slog.Debug("session lookup failed", "error", err) + http.Error(w, `{"error":"unauthorized","message":"Invalid or expired session"}`, http.StatusUnauthorized) + return + } + + user, err := userStore.GetUserByID(r.Context(), session.UserID) + if err != nil { + slog.Error("user lookup failed for session", "user_id", session.UserID, "error", err) + http.Error(w, `{"error":"unauthorized","message":"User not found"}`, http.StatusUnauthorized) + return + } + + ctx := ContextWithUser(r.Context(), user) + ctx = ContextWithSessionID(ctx, session.SessionID) + next.ServeHTTP(w, r.WithContext(ctx)) + }) + } +} + +// RequireBearer creates middleware that validates an OAuth access token. +// If valid, it injects the user/client identity into the context. +func RequireBearer(provider fosite.OAuth2Provider, userStore UserStore) func(http.Handler) http.Handler { + return func(next http.Handler) http.Handler { + return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + authHeader := r.Header.Get("Authorization") + if authHeader == "" { + http.Error(w, `{"error":"unauthorized","message":"Missing Authorization header"}`, http.StatusUnauthorized) + return + } + + parts := strings.SplitN(authHeader, " ", 2) + if len(parts) != 2 || !strings.EqualFold(parts[0], "Bearer") { + http.Error(w, `{"error":"unauthorized","message":"Invalid Authorization header format"}`, http.StatusUnauthorized) + return + } + + token := parts[1] + _ = token + + // Use fosite introspection + _, ar, err := provider.IntrospectToken(r.Context(), parts[1], fosite.AccessToken, new(fositeSession)) + if err != nil { + slog.Debug("bearer token validation failed", "error", err) + w.Header().Set("WWW-Authenticate", `Bearer error="invalid_token"`) + http.Error(w, `{"error":"unauthorized","message":"Invalid or expired token"}`, http.StatusUnauthorized) + return + } + + ctx := r.Context() + ctx = ContextWithClient(ctx, ar.GetClient().GetID()) + + // If the token has a user session, load the user + if sess, ok := ar.GetSession().(*fositeSession); ok && sess.UserID > 0 { + user, err := userStore.GetUserByID(ctx, sess.UserID) + if err == nil { + ctx = ContextWithUser(ctx, user) + } + } + + next.ServeHTTP(w, r.WithContext(ctx)) + }) + } +} + +// RequireAuth creates middleware that accepts either a session cookie or bearer token. +func RequireAuth(userStore UserStore, sessionStore SessionStore, provider fosite.OAuth2Provider) func(http.Handler) http.Handler { + sessionMW := RequireSession(userStore, sessionStore) + bearerMW := RequireBearer(provider, userStore) + + return func(next http.Handler) http.Handler { + return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + // Check for bearer token first + if r.Header.Get("Authorization") != "" { + bearerMW(next).ServeHTTP(w, r) + return + } + // Fall back to session cookie + sessionMW(next).ServeHTTP(w, r) + }) + } +} + +// RequireAdmin creates middleware that requires the user to have admin role. +// Must be used after RequireSession or RequireAuth. +func RequireAdmin() func(http.Handler) http.Handler { + return func(next http.Handler) http.Handler { + return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + user, ok := UserFromContext(r.Context()) + if !ok { + http.Error(w, `{"error":"unauthorized","message":"Authentication required"}`, http.StatusUnauthorized) + return + } + if user.Role != RoleAdmin { + http.Error(w, `{"error":"forbidden","message":"Admin access required"}`, http.StatusForbidden) + return + } + next.ServeHTTP(w, r) + }) + } +} diff --git a/internal/auth/oauth_test.go b/internal/auth/oauth_test.go new file mode 100644 index 0000000..15d1df7 --- /dev/null +++ b/internal/auth/oauth_test.go @@ -0,0 +1,260 @@ +package auth + +import ( + "context" + "encoding/json" + "net/http" + "net/http/httptest" + "net/url" + "strings" + "testing" +) + +func setupOAuth(t *testing.T) (*Handlers, *SQLiteUserStore, *SQLiteClientStore, *SQLiteSessionStore) { + t.Helper() + db := newTestDB(t) + + cfg := DefaultConfig() + cfg.BcryptCost = 10 + cfg.DevMode = true + cfg.Secret = make([]byte, 32) + for i := range cfg.Secret { + cfg.Secret[i] = byte(i) + } + + userStore := NewSQLiteUserStore(db, cfg.BcryptCost) + sessionStore := NewSQLiteSessionStore(db) + clientStore := NewSQLiteClientStore(db, cfg.BcryptCost) + fositeStore := NewFositeStore(db, cfg.BcryptCost) + provider := NewOAuthProvider(cfg, fositeStore) + handlers := NewHandlers(userStore, sessionStore, clientStore, provider, cfg) + + return handlers, userStore, clientStore, sessionStore +} + +func TestOAuth_ClientCredentials(t *testing.T) { + h, userStore, clientStore, _ := setupOAuth(t) + ctx := context.Background() + + // Create owner user and client + user, _ := userStore.CreateUser(ctx, "oauthowner", "password123", "") + client, secret, err := clientStore.CreateClient(ctx, "test-client", + []string{}, []string{"client_credentials"}, []string{"read", "write"}, user.ID) + if err != nil { + t.Fatalf("CreateClient: %v", err) + } + + t.Run("valid client credentials", func(t *testing.T) { + form := url.Values{} + form.Set("grant_type", "client_credentials") + form.Set("scope", "read write") + + req := httptest.NewRequest(http.MethodPost, "/oauth/token", strings.NewReader(form.Encode())) + req.Header.Set("Content-Type", "application/x-www-form-urlencoded") + req.SetBasicAuth(client.ID, secret) + rr := httptest.NewRecorder() + + h.HandleToken(rr, req) + + if rr.Code != http.StatusOK { + t.Errorf("status = %d, want %d. Body: %s", rr.Code, http.StatusOK, rr.Body.String()) + return + } + + var resp map[string]interface{} + if err := json.NewDecoder(rr.Body).Decode(&resp); err != nil { + t.Fatalf("decode response: %v", err) + } + + if resp["access_token"] == nil || resp["access_token"] == "" { + t.Error("expected access_token in response") + } + if resp["token_type"] != "bearer" { + t.Errorf("token_type = %v, want bearer", resp["token_type"]) + } + if resp["expires_in"] == nil { + t.Error("expected expires_in in response") + } + }) + + t.Run("invalid client secret", func(t *testing.T) { + form := url.Values{} + form.Set("grant_type", "client_credentials") + + req := httptest.NewRequest(http.MethodPost, "/oauth/token", strings.NewReader(form.Encode())) + req.Header.Set("Content-Type", "application/x-www-form-urlencoded") + req.SetBasicAuth(client.ID, "wrong-secret") + rr := httptest.NewRecorder() + + h.HandleToken(rr, req) + + if rr.Code == http.StatusOK { + t.Error("expected non-200 for invalid secret") + } + }) + + t.Run("unknown client", func(t *testing.T) { + form := url.Values{} + form.Set("grant_type", "client_credentials") + + req := httptest.NewRequest(http.MethodPost, "/oauth/token", strings.NewReader(form.Encode())) + req.Header.Set("Content-Type", "application/x-www-form-urlencoded") + req.SetBasicAuth("nonexistent-client", "secret") + rr := httptest.NewRecorder() + + h.HandleToken(rr, req) + + if rr.Code == http.StatusOK { + t.Error("expected non-200 for unknown client") + } + }) +} + +func TestOAuth_TokenIntrospection(t *testing.T) { + h, userStore, clientStore, _ := setupOAuth(t) + ctx := context.Background() + + user, _ := userStore.CreateUser(ctx, "introowner", "password123", "") + client, secret, _ := clientStore.CreateClient(ctx, "intro-client", + []string{}, []string{"client_credentials"}, []string{"read"}, user.ID) + + // First, get a token + form := url.Values{} + form.Set("grant_type", "client_credentials") + form.Set("scope", "read") + + req := httptest.NewRequest(http.MethodPost, "/oauth/token", strings.NewReader(form.Encode())) + req.Header.Set("Content-Type", "application/x-www-form-urlencoded") + req.SetBasicAuth(client.ID, secret) + rr := httptest.NewRecorder() + + h.HandleToken(rr, req) + + if rr.Code != http.StatusOK { + t.Fatalf("token request failed: %d %s", rr.Code, rr.Body.String()) + } + + var tokenResp map[string]interface{} + json.NewDecoder(rr.Body).Decode(&tokenResp) + accessToken := tokenResp["access_token"].(string) + + t.Run("valid token introspection", func(t *testing.T) { + form := url.Values{} + form.Set("token", accessToken) + + req := httptest.NewRequest(http.MethodPost, "/oauth/introspect", strings.NewReader(form.Encode())) + req.Header.Set("Content-Type", "application/x-www-form-urlencoded") + req.SetBasicAuth(client.ID, secret) + rr := httptest.NewRecorder() + + h.HandleIntrospect(rr, req) + + if rr.Code != http.StatusOK { + t.Errorf("status = %d, want %d. Body: %s", rr.Code, http.StatusOK, rr.Body.String()) + return + } + + var resp IntrospectionResponse + json.NewDecoder(rr.Body).Decode(&resp) + + if !resp.Active { + t.Error("token should be active") + } + if resp.ClientID != client.ID { + t.Errorf("client_id = %q, want %q", resp.ClientID, client.ID) + } + }) + + t.Run("invalid token introspection", func(t *testing.T) { + form := url.Values{} + form.Set("token", "invalid-token-value") + + req := httptest.NewRequest(http.MethodPost, "/oauth/introspect", strings.NewReader(form.Encode())) + req.Header.Set("Content-Type", "application/x-www-form-urlencoded") + req.SetBasicAuth(client.ID, secret) + rr := httptest.NewRecorder() + + h.HandleIntrospect(rr, req) + + var resp IntrospectionResponse + json.NewDecoder(rr.Body).Decode(&resp) + + if resp.Active { + t.Error("invalid token should not be active") + } + }) +} + +func TestOAuth_ClientStore(t *testing.T) { + db := newTestDB(t) + userStore := NewSQLiteUserStore(db, 10) + clientStore := NewSQLiteClientStore(db, 10) + ctx := context.Background() + + user, _ := userStore.CreateUser(ctx, "clientowner", "password123", "") + + t.Run("create and get client", func(t *testing.T) { + client, secret, err := clientStore.CreateClient(ctx, "test-app", + []string{"http://localhost:3000/callback"}, + []string{"authorization_code", "client_credentials"}, + []string{"read", "write"}, + user.ID, + ) + if err != nil { + t.Fatalf("CreateClient: %v", err) + } + if client.ID == "" { + t.Error("client ID should not be empty") + } + if secret == "" { + t.Error("client secret should not be empty") + } + if client.Name != "test-app" { + t.Errorf("Name = %q, want %q", client.Name, "test-app") + } + + // Get client + got, err := clientStore.GetClient(ctx, client.ID) + if err != nil { + t.Fatalf("GetClient: %v", err) + } + if got.Name != "test-app" { + t.Errorf("Name = %q, want %q", got.Name, "test-app") + } + if len(got.RedirectURIs) != 1 { + t.Errorf("RedirectURIs length = %d, want 1", len(got.RedirectURIs)) + } + }) + + t.Run("verify client secret", func(t *testing.T) { + client, secret, _ := clientStore.CreateClient(ctx, "verify-app", + nil, nil, nil, user.ID) + + _, err := clientStore.VerifyClientSecret(ctx, client.ID, secret) + if err != nil { + t.Errorf("VerifyClientSecret should succeed: %v", err) + } + + _, err = clientStore.VerifyClientSecret(ctx, client.ID, "wrong-secret") + if err == nil { + t.Error("VerifyClientSecret should fail with wrong secret") + } + }) + + t.Run("list clients by owner", func(t *testing.T) { + clients, err := clientStore.ListClientsByOwner(ctx, user.ID) + if err != nil { + t.Fatalf("ListClientsByOwner: %v", err) + } + if len(clients) < 1 { + t.Error("should have at least 1 client") + } + }) + + t.Run("non-existent client", func(t *testing.T) { + _, err := clientStore.GetClient(ctx, "nonexistent-id") + if err != ErrClientNotFound { + t.Errorf("expected ErrClientNotFound, got %v", err) + } + }) +} diff --git a/internal/auth/provider.go b/internal/auth/provider.go new file mode 100644 index 0000000..1060400 --- /dev/null +++ b/internal/auth/provider.go @@ -0,0 +1,63 @@ +package auth + +import ( + "crypto/rand" + "time" + + "github.com/ory/fosite" + "github.com/ory/fosite/compose" + "github.com/ory/fosite/token/hmac" +) + +// NewOAuthProvider creates a configured fosite OAuth 2.1 provider. +// It supports authorization code with PKCE (S256 only), client credentials, and refresh token rotation. +func NewOAuthProvider(cfg Config, store *FositeStore) fosite.OAuth2Provider { + secret := cfg.Secret + if len(secret) < 32 { + // Generate a random secret if not configured + secret = make([]byte, 32) + rand.Read(secret) + } + + config := &fosite.Config{ + AccessTokenLifespan: cfg.AccessTokenTTL, + RefreshTokenLifespan: cfg.RefreshTokenLifetime, + AuthorizeCodeLifespan: 10 * time.Minute, + GlobalSecret: secret, + SendDebugMessagesToClients: cfg.DevMode, + EnforcePKCE: true, + EnforcePKCEForPublicClients: true, + EnablePKCEPlainChallengeMethod: false, + TokenURL: cfg.IssuerURL + "/oauth/token", + HashCost: cfg.BcryptCost, + } + + // HMACSHAStrategy for token generation + hmacStrategy := &hmac.HMACStrategy{ + Config: config, + } + + _ = hmacStrategy + + return compose.Compose( + config, + store, + &compose.CommonStrategy{ + CoreStrategy: compose.NewOAuth2HMACStrategy(config), + }, + compose.OAuth2AuthorizeExplicitFactory, + compose.OAuth2ClientCredentialsGrantFactory, + compose.OAuth2RefreshTokenGrantFactory, + compose.OAuth2PKCEFactory, + compose.OAuth2TokenIntrospectionFactory, + ) +} + +// NewSession creates a new fosite session for a user. +func NewSession(user *User) fosite.Session { + return &fositeSession{ + UserID: user.ID, + Username: user.Username, + Subject: user.Username, + } +} diff --git a/internal/auth/session_store.go b/internal/auth/session_store.go new file mode 100644 index 0000000..de69c64 --- /dev/null +++ b/internal/auth/session_store.go @@ -0,0 +1,132 @@ +package auth + +import ( + "context" + "crypto/rand" + "database/sql" + "encoding/hex" + "fmt" + "time" +) + +// SessionStore defines the storage interface for session operations. +type SessionStore interface { + CreateSession(ctx context.Context, userID int64, lifetime time.Duration) (*Session, error) + GetSession(ctx context.Context, sessionID string) (*Session, error) + DeleteSession(ctx context.Context, sessionID string) error + DeleteSessionsByUser(ctx context.Context, userID int64) error + DeleteSessionsByUserExcept(ctx context.Context, userID int64, exceptSessionID string) error + CleanupExpired(ctx context.Context) (int64, error) +} + +// SQLiteSessionStore implements SessionStore using SQLite. +type SQLiteSessionStore struct { + db *sql.DB +} + +// NewSQLiteSessionStore creates a new SQLite-backed session store. +func NewSQLiteSessionStore(db *sql.DB) *SQLiteSessionStore { + return &SQLiteSessionStore{db: db} +} + +// CreateSession creates a new session with a cryptographically random session ID. +func (s *SQLiteSessionStore) CreateSession(ctx context.Context, userID int64, lifetime time.Duration) (*Session, error) { + sessionID, err := generateSessionID() + if err != nil { + return nil, fmt.Errorf("generate session id: %w", err) + } + + now := time.Now() + expiresAt := now.Add(lifetime) + + _, err = s.db.ExecContext(ctx, + `INSERT INTO sessions (session_id, user_id, created_at, expires_at, last_active_at) + VALUES (?, ?, ?, ?, ?)`, + sessionID, userID, now, expiresAt, now, + ) + if err != nil { + return nil, fmt.Errorf("insert session: %w", err) + } + + return &Session{ + SessionID: sessionID, + UserID: userID, + CreatedAt: now, + ExpiresAt: expiresAt, + LastActiveAt: now, + }, nil +} + +// GetSession retrieves a session by its ID. Returns ErrSessionExpired if the session has expired. +func (s *SQLiteSessionStore) GetSession(ctx context.Context, sessionID string) (*Session, error) { + session := &Session{} + err := s.db.QueryRowContext(ctx, + `SELECT session_id, user_id, created_at, expires_at, last_active_at + FROM sessions WHERE session_id = ?`, sessionID, + ).Scan(&session.SessionID, &session.UserID, &session.CreatedAt, + &session.ExpiresAt, &session.LastActiveAt) + if err != nil { + if err == sql.ErrNoRows { + return nil, ErrSessionNotFound + } + return nil, fmt.Errorf("query session: %w", err) + } + + if time.Now().After(session.ExpiresAt) { + // Clean up the expired session + s.DeleteSession(ctx, sessionID) + return nil, ErrSessionExpired + } + + // Update last_active_at + s.db.ExecContext(ctx, + `UPDATE sessions SET last_active_at = CURRENT_TIMESTAMP WHERE session_id = ?`, + sessionID, + ) + + return session, nil +} + +// DeleteSession removes a session. +func (s *SQLiteSessionStore) DeleteSession(ctx context.Context, sessionID string) error { + _, err := s.db.ExecContext(ctx, + "DELETE FROM sessions WHERE session_id = ?", sessionID, + ) + return err +} + +// DeleteSessionsByUser removes all sessions for a user. +func (s *SQLiteSessionStore) DeleteSessionsByUser(ctx context.Context, userID int64) error { + _, err := s.db.ExecContext(ctx, + "DELETE FROM sessions WHERE user_id = ?", userID, + ) + return err +} + +// DeleteSessionsByUserExcept removes all sessions for a user except the specified one. +func (s *SQLiteSessionStore) DeleteSessionsByUserExcept(ctx context.Context, userID int64, exceptSessionID string) error { + _, err := s.db.ExecContext(ctx, + "DELETE FROM sessions WHERE user_id = ? AND session_id != ?", userID, exceptSessionID, + ) + return err +} + +// CleanupExpired removes all expired sessions and returns the count removed. +func (s *SQLiteSessionStore) CleanupExpired(ctx context.Context) (int64, error) { + result, err := s.db.ExecContext(ctx, + "DELETE FROM sessions WHERE expires_at < ?", time.Now(), + ) + if err != nil { + return 0, err + } + return result.RowsAffected() +} + +// generateSessionID creates a cryptographically random session identifier. +func generateSessionID() (string, error) { + b := make([]byte, 32) + if _, err := rand.Read(b); err != nil { + return "", err + } + return hex.EncodeToString(b), nil +} diff --git a/internal/auth/session_store_test.go b/internal/auth/session_store_test.go new file mode 100644 index 0000000..8df4ae9 --- /dev/null +++ b/internal/auth/session_store_test.go @@ -0,0 +1,171 @@ +package auth + +import ( + "context" + "testing" + "time" +) + +func TestSessionStore_CreateAndGet(t *testing.T) { + db := newTestDB(t) + userStore := NewSQLiteUserStore(db, 10) + sessStore := NewSQLiteSessionStore(db) + ctx := context.Background() + + user, err := userStore.CreateUser(ctx, "sessuser", "password123", "") + if err != nil { + t.Fatalf("CreateUser: %v", err) + } + + session, err := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + if err != nil { + t.Fatalf("CreateSession: %v", err) + } + + if session.SessionID == "" { + t.Error("SessionID should not be empty") + } + if session.UserID != user.ID { + t.Errorf("UserID = %d, want %d", session.UserID, user.ID) + } + + // Get session + got, err := sessStore.GetSession(ctx, session.SessionID) + if err != nil { + t.Fatalf("GetSession: %v", err) + } + if got.UserID != user.ID { + t.Errorf("UserID = %d, want %d", got.UserID, user.ID) + } +} + +func TestSessionStore_NotFound(t *testing.T) { + db := newTestDB(t) + sessStore := NewSQLiteSessionStore(db) + ctx := context.Background() + + _, err := sessStore.GetSession(ctx, "nonexistent-session-id") + if err != ErrSessionNotFound { + t.Errorf("expected ErrSessionNotFound, got %v", err) + } +} + +func TestSessionStore_Expired(t *testing.T) { + db := newTestDB(t) + userStore := NewSQLiteUserStore(db, 10) + sessStore := NewSQLiteSessionStore(db) + ctx := context.Background() + + user, _ := userStore.CreateUser(ctx, "expuser", "password123", "") + + // Create a session with very short lifetime + session, err := sessStore.CreateSession(ctx, user.ID, 1*time.Millisecond) + if err != nil { + t.Fatalf("CreateSession: %v", err) + } + + // Wait for expiry + time.Sleep(10 * time.Millisecond) + + _, err = sessStore.GetSession(ctx, session.SessionID) + if err != ErrSessionExpired { + t.Errorf("expected ErrSessionExpired, got %v", err) + } +} + +func TestSessionStore_Delete(t *testing.T) { + db := newTestDB(t) + userStore := NewSQLiteUserStore(db, 10) + sessStore := NewSQLiteSessionStore(db) + ctx := context.Background() + + user, _ := userStore.CreateUser(ctx, "deluser", "password123", "") + + session, _ := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + + if err := sessStore.DeleteSession(ctx, session.SessionID); err != nil { + t.Fatalf("DeleteSession: %v", err) + } + + _, err := sessStore.GetSession(ctx, session.SessionID) + if err != ErrSessionNotFound { + t.Errorf("expected ErrSessionNotFound after delete, got %v", err) + } +} + +func TestSessionStore_DeleteByUser(t *testing.T) { + db := newTestDB(t) + userStore := NewSQLiteUserStore(db, 10) + sessStore := NewSQLiteSessionStore(db) + ctx := context.Background() + + user, _ := userStore.CreateUser(ctx, "delbyuser", "password123", "") + + sess1, _ := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + sess2, _ := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + + if err := sessStore.DeleteSessionsByUser(ctx, user.ID); err != nil { + t.Fatalf("DeleteSessionsByUser: %v", err) + } + + _, err := sessStore.GetSession(ctx, sess1.SessionID) + if err != ErrSessionNotFound { + t.Errorf("session 1 should be deleted") + } + _, err = sessStore.GetSession(ctx, sess2.SessionID) + if err != ErrSessionNotFound { + t.Errorf("session 2 should be deleted") + } +} + +func TestSessionStore_DeleteByUserExcept(t *testing.T) { + db := newTestDB(t) + userStore := NewSQLiteUserStore(db, 10) + sessStore := NewSQLiteSessionStore(db) + ctx := context.Background() + + user, _ := userStore.CreateUser(ctx, "exceptuser", "password123", "") + + sess1, _ := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + sess2, _ := sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + + if err := sessStore.DeleteSessionsByUserExcept(ctx, user.ID, sess1.SessionID); err != nil { + t.Fatalf("DeleteSessionsByUserExcept: %v", err) + } + + // Session 1 should still exist + _, err := sessStore.GetSession(ctx, sess1.SessionID) + if err != nil { + t.Errorf("session 1 should still exist: %v", err) + } + + // Session 2 should be deleted + _, err = sessStore.GetSession(ctx, sess2.SessionID) + if err != ErrSessionNotFound { + t.Errorf("session 2 should be deleted") + } +} + +func TestSessionStore_CleanupExpired(t *testing.T) { + db := newTestDB(t) + userStore := NewSQLiteUserStore(db, 10) + sessStore := NewSQLiteSessionStore(db) + ctx := context.Background() + + user, _ := userStore.CreateUser(ctx, "cleanuser", "password123", "") + + // Create an expired session + sessStore.CreateSession(ctx, user.ID, 1*time.Millisecond) + time.Sleep(10 * time.Millisecond) + + // Create a valid session + sessStore.CreateSession(ctx, user.ID, 24*time.Hour) + + removed, err := sessStore.CleanupExpired(ctx) + if err != nil { + t.Fatalf("CleanupExpired: %v", err) + } + if removed != 1 { + t.Errorf("removed = %d, want 1", removed) + } +} diff --git a/internal/auth/types.go b/internal/auth/types.go new file mode 100644 index 0000000..d10d4bd --- /dev/null +++ b/internal/auth/types.go @@ -0,0 +1,104 @@ +package auth + +import "time" + +// User represents a human account in SynapBus. +type User struct { + ID int64 `json:"id"` + Username string `json:"username"` + PasswordHash string `json:"-"` + DisplayName string `json:"display_name"` + Role string `json:"role"` + CreatedAt time.Time `json:"created_at"` + UpdatedAt time.Time `json:"updated_at"` +} + +// User role constants. +const ( + RoleUser = "user" + RoleAdmin = "admin" +) + +// Session represents a Web UI session linking a browser cookie to a user. +type Session struct { + SessionID string `json:"session_id"` + UserID int64 `json:"user_id"` + CreatedAt time.Time `json:"created_at"` + ExpiresAt time.Time `json:"expires_at"` + LastActiveAt time.Time `json:"last_active_at"` +} + +// OAuthClient represents a registered OAuth 2.1 client. +type OAuthClient struct { + ID string `json:"id"` + SecretHash string `json:"-"` + Name string `json:"name"` + RedirectURIs []string `json:"redirect_uris"` + GrantTypes []string `json:"grant_types"` + Scopes []string `json:"scopes"` + OwnerID int64 `json:"owner_id"` + CreatedAt time.Time `json:"created_at"` +} + +// AuthorizationCode represents an OAuth authorization code. +type AuthorizationCode struct { + Code string `json:"code"` + ClientID string `json:"client_id"` + UserID int64 `json:"user_id"` + RedirectURI string `json:"redirect_uri"` + Scopes string `json:"scopes"` + CodeChallenge string `json:"code_challenge"` + CodeChallengeMethod string `json:"code_challenge_method"` + SessionData string `json:"session_data"` + ExpiresAt time.Time `json:"expires_at"` + CreatedAt time.Time `json:"created_at"` + Used bool `json:"used"` +} + +// OAuthToken represents an issued access or refresh token. +type OAuthToken struct { + ID int64 `json:"id"` + Signature string `json:"signature"` + ClientID string `json:"client_id"` + UserID int64 `json:"user_id"` + Scopes string `json:"scopes"` + TokenType string `json:"token_type"` // "access" or "refresh" + SessionData string `json:"session_data"` + ExpiresAt time.Time `json:"expires_at"` + CreatedAt time.Time `json:"created_at"` + Consumed bool `json:"consumed"` + ParentSignature string `json:"parent_signature"` +} + +// Token type constants. +const ( + TokenTypeAccess = "access" + TokenTypeRefresh = "refresh" +) + +// TokenResponse is the JSON response for OAuth token endpoint. +type TokenResponse struct { + AccessToken string `json:"access_token"` + TokenType string `json:"token_type"` + ExpiresIn int `json:"expires_in"` + RefreshToken string `json:"refresh_token,omitempty"` + Scope string `json:"scope,omitempty"` +} + +// IntrospectionResponse is the JSON response for token introspection (RFC 7662). +type IntrospectionResponse struct { + Active bool `json:"active"` + Scope string `json:"scope,omitempty"` + ClientID string `json:"client_id,omitempty"` + Username string `json:"username,omitempty"` + TokenType string `json:"token_type,omitempty"` + ExpiresAt int64 `json:"exp,omitempty"` + IssuedAt int64 `json:"iat,omitempty"` + Subject string `json:"sub,omitempty"` +} + +// ErrorResponse is a JSON error response. +type ErrorResponse struct { + Error string `json:"error"` + Description string `json:"error_description,omitempty"` +} diff --git a/internal/auth/user_store.go b/internal/auth/user_store.go new file mode 100644 index 0000000..0a49a97 --- /dev/null +++ b/internal/auth/user_store.go @@ -0,0 +1,217 @@ +package auth + +import ( + "context" + "database/sql" + "fmt" + "regexp" + "strings" + "time" + + "golang.org/x/crypto/bcrypt" +) + +var usernameRegex = regexp.MustCompile(`^[a-zA-Z0-9_]{3,64}$`) + +// UserStore defines the storage interface for user operations. +type UserStore interface { + CreateUser(ctx context.Context, username, password, displayName string) (*User, error) + GetUserByID(ctx context.Context, id int64) (*User, error) + GetUserByUsername(ctx context.Context, username string) (*User, error) + UpdatePassword(ctx context.Context, userID int64, newPassword string) error + ListUsers(ctx context.Context) ([]*User, error) + CountUsers(ctx context.Context) (int, error) + VerifyPassword(ctx context.Context, username, password string) (*User, error) +} + +// SQLiteUserStore implements UserStore using SQLite. +type SQLiteUserStore struct { + db *sql.DB + bcryptCost int +} + +// NewSQLiteUserStore creates a new SQLite-backed user store. +func NewSQLiteUserStore(db *sql.DB, bcryptCost int) *SQLiteUserStore { + if bcryptCost < 10 { + bcryptCost = 12 + } + return &SQLiteUserStore{db: db, bcryptCost: bcryptCost} +} + +// CreateUser creates a new user with a bcrypt-hashed password. +func (s *SQLiteUserStore) CreateUser(ctx context.Context, username, password, displayName string) (*User, error) { + if !usernameRegex.MatchString(username) { + return nil, ErrInvalidUsername + } + + if len(password) < 8 { + return nil, ErrPasswordTooShort + } + if len(password) > 72 { + return nil, ErrPasswordTooLong + } + + hash, err := bcrypt.GenerateFromPassword([]byte(password), s.bcryptCost) + if err != nil { + return nil, fmt.Errorf("hash password: %w", err) + } + + // Determine role: first user is admin + count, err := s.CountUsers(ctx) + if err != nil { + return nil, fmt.Errorf("count users: %w", err) + } + + role := RoleUser + if count == 0 { + role = RoleAdmin + } + + if displayName == "" { + displayName = username + } + + result, err := s.db.ExecContext(ctx, + `INSERT INTO users (username, password_hash, display_name, role, created_at, updated_at) + VALUES (?, ?, ?, ?, CURRENT_TIMESTAMP, CURRENT_TIMESTAMP)`, + username, string(hash), displayName, role, + ) + if err != nil { + if strings.Contains(err.Error(), "UNIQUE constraint") { + return nil, ErrDuplicateUsername + } + return nil, fmt.Errorf("insert user: %w", err) + } + + id, err := result.LastInsertId() + if err != nil { + return nil, fmt.Errorf("get user id: %w", err) + } + + return &User{ + ID: id, + Username: username, + DisplayName: displayName, + Role: role, + CreatedAt: time.Now(), + UpdatedAt: time.Now(), + }, nil +} + +// GetUserByID retrieves a user by their ID. +func (s *SQLiteUserStore) GetUserByID(ctx context.Context, id int64) (*User, error) { + user := &User{} + err := s.db.QueryRowContext(ctx, + `SELECT id, username, password_hash, display_name, role, created_at, updated_at + FROM users WHERE id = ?`, id, + ).Scan(&user.ID, &user.Username, &user.PasswordHash, &user.DisplayName, + &user.Role, &user.CreatedAt, &user.UpdatedAt) + if err != nil { + if err == sql.ErrNoRows { + return nil, ErrUserNotFound + } + return nil, fmt.Errorf("query user: %w", err) + } + return user, nil +} + +// GetUserByUsername retrieves a user by their username. +func (s *SQLiteUserStore) GetUserByUsername(ctx context.Context, username string) (*User, error) { + user := &User{} + err := s.db.QueryRowContext(ctx, + `SELECT id, username, password_hash, display_name, role, created_at, updated_at + FROM users WHERE username = ?`, username, + ).Scan(&user.ID, &user.Username, &user.PasswordHash, &user.DisplayName, + &user.Role, &user.CreatedAt, &user.UpdatedAt) + if err != nil { + if err == sql.ErrNoRows { + return nil, ErrUserNotFound + } + return nil, fmt.Errorf("query user: %w", err) + } + return user, nil +} + +// UpdatePassword changes a user's password. +func (s *SQLiteUserStore) UpdatePassword(ctx context.Context, userID int64, newPassword string) error { + if len(newPassword) < 8 { + return ErrPasswordTooShort + } + if len(newPassword) > 72 { + return ErrPasswordTooLong + } + + hash, err := bcrypt.GenerateFromPassword([]byte(newPassword), s.bcryptCost) + if err != nil { + return fmt.Errorf("hash password: %w", err) + } + + result, err := s.db.ExecContext(ctx, + `UPDATE users SET password_hash = ?, updated_at = CURRENT_TIMESTAMP WHERE id = ?`, + string(hash), userID, + ) + if err != nil { + return fmt.Errorf("update password: %w", err) + } + + rows, err := result.RowsAffected() + if err != nil { + return fmt.Errorf("check rows affected: %w", err) + } + if rows == 0 { + return ErrUserNotFound + } + return nil +} + +// ListUsers returns all users. +func (s *SQLiteUserStore) ListUsers(ctx context.Context) ([]*User, error) { + rows, err := s.db.QueryContext(ctx, + `SELECT id, username, password_hash, display_name, role, created_at, updated_at + FROM users ORDER BY id`, + ) + if err != nil { + return nil, fmt.Errorf("query users: %w", err) + } + defer rows.Close() + + var users []*User + for rows.Next() { + u := &User{} + if err := rows.Scan(&u.ID, &u.Username, &u.PasswordHash, &u.DisplayName, + &u.Role, &u.CreatedAt, &u.UpdatedAt); err != nil { + return nil, fmt.Errorf("scan user: %w", err) + } + users = append(users, u) + } + if users == nil { + users = []*User{} + } + return users, rows.Err() +} + +// CountUsers returns the number of registered users. +func (s *SQLiteUserStore) CountUsers(ctx context.Context) (int, error) { + var count int + err := s.db.QueryRowContext(ctx, "SELECT COUNT(*) FROM users").Scan(&count) + return count, err +} + +// VerifyPassword checks a username/password combination and returns the user if valid. +func (s *SQLiteUserStore) VerifyPassword(ctx context.Context, username, password string) (*User, error) { + user, err := s.GetUserByUsername(ctx, username) + if err != nil { + // Do a dummy bcrypt comparison to prevent timing attacks + bcrypt.CompareHashAndPassword( + []byte("$2a$12$dummyhashvaluefortimingatttack0000000000000000000"), + []byte(password), + ) + return nil, ErrInvalidPassword + } + + if err := bcrypt.CompareHashAndPassword([]byte(user.PasswordHash), []byte(password)); err != nil { + return nil, ErrInvalidPassword + } + + return user, nil +} diff --git a/internal/auth/user_store_test.go b/internal/auth/user_store_test.go new file mode 100644 index 0000000..166310c --- /dev/null +++ b/internal/auth/user_store_test.go @@ -0,0 +1,289 @@ +package auth + +import ( + "context" + "database/sql" + "fmt" + "testing" + + _ "modernc.org/sqlite" + + "github.com/smart-mcp-proxy/synapbus/internal/storage" + "golang.org/x/crypto/bcrypt" +) + +func newTestDB(t *testing.T) *sql.DB { + t.Helper() + dsn := fmt.Sprintf("file:%s?mode=memory&cache=shared", t.Name()) + db, err := sql.Open("sqlite", dsn) + if err != nil { + t.Fatalf("open database: %v", err) + } + t.Cleanup(func() { db.Close() }) + + if _, err := db.Exec("PRAGMA foreign_keys=ON"); err != nil { + t.Fatalf("enable foreign keys: %v", err) + } + + ctx := context.Background() + if err := storage.RunMigrations(ctx, db); err != nil { + t.Fatalf("run migrations: %v", err) + } + + return db +} + +func TestUserStore_CreateUser(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) // use cost 10 for test speed + ctx := context.Background() + + t.Run("valid user", func(t *testing.T) { + user, err := store.CreateUser(ctx, "testuser", "password123", "Test User") + if err != nil { + t.Fatalf("CreateUser: %v", err) + } + if user.ID == 0 { + t.Error("expected non-zero user ID") + } + if user.Username != "testuser" { + t.Errorf("Username = %q, want %q", user.Username, "testuser") + } + if user.DisplayName != "Test User" { + t.Errorf("DisplayName = %q, want %q", user.DisplayName, "Test User") + } + // First user should be admin + if user.Role != RoleAdmin { + t.Errorf("Role = %q, want %q (first user should be admin)", user.Role, RoleAdmin) + } + }) + + t.Run("second user is regular", func(t *testing.T) { + user, err := store.CreateUser(ctx, "testuser2", "password123", "Test User 2") + if err != nil { + t.Fatalf("CreateUser: %v", err) + } + if user.Role != RoleUser { + t.Errorf("Role = %q, want %q (second user should be regular)", user.Role, RoleUser) + } + }) + + t.Run("bcrypt cost >= 10", func(t *testing.T) { + user, err := store.GetUserByUsername(ctx, "testuser") + if err != nil { + t.Fatalf("GetUserByUsername: %v", err) + } + cost, err := bcrypt.Cost([]byte(user.PasswordHash)) + if err != nil { + t.Fatalf("bcrypt.Cost: %v", err) + } + if cost < 10 { + t.Errorf("bcrypt cost = %d, want >= 10", cost) + } + }) +} + +func TestUserStore_DuplicateUsername(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) + ctx := context.Background() + + if _, err := store.CreateUser(ctx, "dupuser", "password123", ""); err != nil { + t.Fatalf("CreateUser: %v", err) + } + + _, err := store.CreateUser(ctx, "dupuser", "password456", "") + if err != ErrDuplicateUsername { + t.Errorf("expected ErrDuplicateUsername, got %v", err) + } +} + +func TestUserStore_InvalidUsername(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) + ctx := context.Background() + + tests := []struct { + name string + username string + }{ + {"too short", "ab"}, + {"has spaces", "hello world"}, + {"has special chars", "user@name"}, + {"has dash", "user-name"}, + {"empty", ""}, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + _, err := store.CreateUser(ctx, tt.username, "password123", "") + if err != ErrInvalidUsername { + t.Errorf("expected ErrInvalidUsername for %q, got %v", tt.username, err) + } + }) + } +} + +func TestUserStore_PasswordValidation(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) + ctx := context.Background() + + t.Run("too short", func(t *testing.T) { + _, err := store.CreateUser(ctx, "shortpw", "short", "") + if err != ErrPasswordTooShort { + t.Errorf("expected ErrPasswordTooShort, got %v", err) + } + }) + + t.Run("too long", func(t *testing.T) { + longPW := make([]byte, 73) + for i := range longPW { + longPW[i] = 'a' + } + _, err := store.CreateUser(ctx, "longpw", string(longPW), "") + if err != ErrPasswordTooLong { + t.Errorf("expected ErrPasswordTooLong, got %v", err) + } + }) +} + +func TestUserStore_GetByID(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) + ctx := context.Background() + + user, err := store.CreateUser(ctx, "getbyid", "password123", "Get By ID") + if err != nil { + t.Fatalf("CreateUser: %v", err) + } + + got, err := store.GetUserByID(ctx, user.ID) + if err != nil { + t.Fatalf("GetUserByID: %v", err) + } + if got.Username != "getbyid" { + t.Errorf("Username = %q, want %q", got.Username, "getbyid") + } + + // Non-existent user + _, err = store.GetUserByID(ctx, 99999) + if err != ErrUserNotFound { + t.Errorf("expected ErrUserNotFound, got %v", err) + } +} + +func TestUserStore_VerifyPassword(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) + ctx := context.Background() + + store.CreateUser(ctx, "verifypw", "correctpassword", "") + + t.Run("correct password", func(t *testing.T) { + user, err := store.VerifyPassword(ctx, "verifypw", "correctpassword") + if err != nil { + t.Fatalf("VerifyPassword: %v", err) + } + if user.Username != "verifypw" { + t.Errorf("Username = %q, want %q", user.Username, "verifypw") + } + }) + + t.Run("wrong password", func(t *testing.T) { + _, err := store.VerifyPassword(ctx, "verifypw", "wrongpassword") + if err != ErrInvalidPassword { + t.Errorf("expected ErrInvalidPassword, got %v", err) + } + }) + + t.Run("non-existent user", func(t *testing.T) { + _, err := store.VerifyPassword(ctx, "nonexistent", "password") + if err != ErrInvalidPassword { + t.Errorf("expected ErrInvalidPassword, got %v", err) + } + }) +} + +func TestUserStore_UpdatePassword(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) + ctx := context.Background() + + user, _ := store.CreateUser(ctx, "updatepw", "oldpassword1", "") + + t.Run("successful update", func(t *testing.T) { + err := store.UpdatePassword(ctx, user.ID, "newpassword1") + if err != nil { + t.Fatalf("UpdatePassword: %v", err) + } + + // Old password should fail + _, err = store.VerifyPassword(ctx, "updatepw", "oldpassword1") + if err != ErrInvalidPassword { + t.Error("old password should not work after update") + } + + // New password should work + _, err = store.VerifyPassword(ctx, "updatepw", "newpassword1") + if err != nil { + t.Errorf("new password should work: %v", err) + } + }) + + t.Run("too short new password", func(t *testing.T) { + err := store.UpdatePassword(ctx, user.ID, "short") + if err != ErrPasswordTooShort { + t.Errorf("expected ErrPasswordTooShort, got %v", err) + } + }) + + t.Run("non-existent user", func(t *testing.T) { + err := store.UpdatePassword(ctx, 99999, "password123") + if err != ErrUserNotFound { + t.Errorf("expected ErrUserNotFound, got %v", err) + } + }) +} + +func TestUserStore_ListUsers(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) + ctx := context.Background() + + for i := 0; i < 3; i++ { + store.CreateUser(ctx, fmt.Sprintf("listuser%d", i), "password123", "") + } + + users, err := store.ListUsers(ctx) + if err != nil { + t.Fatalf("ListUsers: %v", err) + } + if len(users) != 3 { + t.Errorf("got %d users, want 3", len(users)) + } +} + +func TestUserStore_CountUsers(t *testing.T) { + db := newTestDB(t) + store := NewSQLiteUserStore(db, 10) + ctx := context.Background() + + count, err := store.CountUsers(ctx) + if err != nil { + t.Fatalf("CountUsers: %v", err) + } + if count != 0 { + t.Errorf("initial count = %d, want 0", count) + } + + store.CreateUser(ctx, "countuser", "password123", "") + + count, err = store.CountUsers(ctx) + if err != nil { + t.Fatalf("CountUsers: %v", err) + } + if count != 1 { + t.Errorf("count after create = %d, want 1", count) + } +} diff --git a/internal/storage/schema/002_auth.sql b/internal/storage/schema/002_auth.sql new file mode 100644 index 0000000..8b1a527 --- /dev/null +++ b/internal/storage/schema/002_auth.sql @@ -0,0 +1,51 @@ +-- Auth schema extensions for OAuth 2.1 +-- Adds role to users, extends oauth_clients, creates session and auth code tables + +-- Add role column to users table +ALTER TABLE users ADD COLUMN role TEXT NOT NULL DEFAULT 'user' CHECK (role IN ('user', 'admin')); + +-- Add scopes and owner_id columns to oauth_clients +ALTER TABLE oauth_clients ADD COLUMN scopes TEXT NOT NULL DEFAULT '[]'; +ALTER TABLE oauth_clients ADD COLUMN owner_id INTEGER REFERENCES users(id); + +-- Web UI sessions +CREATE TABLE IF NOT EXISTS sessions ( + session_id TEXT PRIMARY KEY, + user_id INTEGER NOT NULL REFERENCES users(id), + created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, + expires_at TIMESTAMP NOT NULL, + last_active_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP +); + +CREATE INDEX idx_sessions_user ON sessions(user_id); +CREATE INDEX idx_sessions_expires ON sessions(expires_at); + +-- OAuth authorization codes +CREATE TABLE IF NOT EXISTS oauth_authorization_codes ( + code TEXT PRIMARY KEY, + client_id TEXT NOT NULL, + user_id INTEGER NOT NULL REFERENCES users(id), + redirect_uri TEXT NOT NULL, + scopes TEXT NOT NULL DEFAULT '', + code_challenge TEXT NOT NULL DEFAULT '', + code_challenge_method TEXT NOT NULL DEFAULT '', + session_data TEXT NOT NULL DEFAULT '{}', + expires_at TIMESTAMP NOT NULL, + created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, + used INTEGER NOT NULL DEFAULT 0 +); + +CREATE INDEX idx_oauth_auth_codes_client ON oauth_authorization_codes(client_id); + +-- Extend oauth_tokens: add token_type, session_data, consumed, parent_signature +ALTER TABLE oauth_tokens ADD COLUMN token_type TEXT NOT NULL DEFAULT 'access'; +ALTER TABLE oauth_tokens ADD COLUMN session_data TEXT NOT NULL DEFAULT '{}'; +ALTER TABLE oauth_tokens ADD COLUMN consumed INTEGER NOT NULL DEFAULT 0; +ALTER TABLE oauth_tokens ADD COLUMN parent_signature TEXT; +ALTER TABLE oauth_tokens ADD COLUMN signature TEXT; + +CREATE INDEX idx_oauth_tokens_signature ON oauth_tokens(signature); +CREATE INDEX idx_oauth_tokens_type ON oauth_tokens(token_type); +CREATE INDEX idx_oauth_tokens_parent ON oauth_tokens(parent_signature); + +INSERT INTO schema_migrations (version) VALUES (2);