mirror of
https://github.com/shankar0123/certctl.git
synced 2026-06-07 18:01:37 +00:00
Unify API auth + RFC-compliant CRL/OCSP (M-002 + M-003 + M-006, auto-closes M-001)
Closes the remaining P1 gaps from coverage-gap-audit.md (M-001/M-002/M-003/M-006)
on top of the C-001/C-002 ownership + agent-FK contract fixes landed in
a53a4b8. The work lands as a single commit spanning server, docs, tests,
and the React client.
M-002 — Named API keys with per-key actor propagation
* Migration 000014 adds the 'api_keys' table (id, name, hash,
principal, role, created_at, last_used_at, disabled_at) so every
credential carries an identifiable principal instead of the
opaque 'anonymous'/'api-key' sentinel.
* Auth middleware now rotates through configured keys, performs
constant-time hash comparison, stamps 'last_used_at', and emits
an actor struct via contextWithActor(). The audit middleware,
bulk-revocation handler, approval handlers, and MCP tool layer
now read the principal off the context and persist it on every
audit_events row.
* Regression coverage:
- internal/api/middleware/audit_test.go — actor propagation,
principal redaction for disabled keys, anonymous fallback for
unauthenticated endpoints.
- internal/api/handler/bulk_revocation_handler_test.go,
job_handler_test.go — principal-on-audit assertions.
M-003 — Authorization gates (Phase B)
* Approval handler rejects self-approval / self-rejection with 403
when the actor principal equals the job's requested_by field.
* Bulk revocation is gated behind the 'admin' role; operators and
viewers receive 403.
* Regression coverage:
- internal/service/job_test.go — TestApproveJob_NotSelf,
TestRejectJob_NotSelf.
- internal/api/handler/bulk_revocation_handler_test.go —
TestBulkRevoke_RequiresAdmin, TestBulkRevoke_AdminSucceeds.
M-006 — RFC-compliant CRL/OCSP on the unauthenticated .well-known mux
* Per RFC 8615, relying parties cannot reasonably be asked to
authenticate against the issuing certctl instance to retrieve
revocation material. CRL and OCSP move off the authenticated
'/api/v1/crl*' and '/api/v1/ocsp/*' paths onto:
GET /.well-known/pki/crl/{issuer_id}
Content-Type: application/pkix-crl (RFC 5280 §5)
GET /.well-known/pki/ocsp/{issuer_id}/{serial}
Content-Type: application/ocsp-response (RFC 6960)
* Non-standard JSON CRL shape is removed; only DER is served.
* Short-lived certificate exemption (profile TTL < 1h → skip
CRL/OCSP) is preserved; the response simply omits the serial.
* Routes are registered on the unauthenticated 'finalHandler' mux
in cmd/server/main.go alongside EST ('/.well-known/est/*') and
SCEP ('/scep'). Legacy authenticated paths return 404.
* Regression coverage:
- internal/api/handler/certificate_handler_test.go — content
type, DER parseability, 404 for unknown issuer.
- internal/api/handler/adversarial_path_test.go — unauthenticated
access asserted for CRL, OCSP, EST, SCEP.
- internal/api/router/router_test.go — route-table assertion
that '.well-known/pki/*', '.well-known/est/*', and '/scep' are
mounted on the unauthenticated branch.
M-001 — Auto-closed by M-002
EST and SCEP were already registered on the unauthenticated
'finalHandler' mux; the router comment at
internal/api/router/router.go:247 now matches reality. The
adversarial-path tests above lock the behavior in.
Verification (all gates green):
* go vet ./... — clean
* go build ./... — ok
* go test -short ./... (55+ packages) — all pass
* web/ : npm test (225 Vitest tests) — all pass
* web/ : npx tsc --noEmit — clean
* grep sweep for '/api/v1/(crl|ocsp)' — 13 surviving hits,
all intentional M-006 tombstone/relocation comments.
Documentation:
* coverage-gap-audit.md — status flips M-001/M-002/M-003/M-006 →
Fixed, with per-finding resolution paragraphs citing regression
test IDs. (Audit file lives outside this repo; see cowork root.)
* CLAUDE.md Project Status line updated with the auth-unification
closure note.
* docs/features.md, docs/architecture.md, docs/quickstart.md,
docs/concepts.md, docs/connectors.md, docs/test-env.md,
docs/testing-guide.md, docs/compliance-*.md, docs/demo-advanced.md
— refreshed for the new '.well-known/pki/*' namespace and named
API keys.
* api/openapi.yaml — documents the new unauthenticated endpoints
and removes the legacy '/api/v1/crl*' + '/api/v1/ocsp/*' paths.
.gitignore: adds '/.gocache/' and '/.gomodcache/' for the session-
scoped Go caches so they never enter the tree.
This commit is contained in:
@@ -195,16 +195,11 @@ type metricsResponse struct {
|
||||
Uptime float64 `json:"uptime_seconds"`
|
||||
}
|
||||
|
||||
// crlResponse for the CRL endpoint.
|
||||
type crlResponse struct {
|
||||
Version int `json:"version"`
|
||||
Total int `json:"total"`
|
||||
Entries []struct {
|
||||
Serial string `json:"serial_number"`
|
||||
Reason string `json:"reason"`
|
||||
RevokedAt string `json:"revoked_at"`
|
||||
} `json:"entries"`
|
||||
}
|
||||
// M-006: The non-standard JSON CRL endpoint (`GET /api/v1/crl`) was removed.
|
||||
// RFC 5280 §5 defines only the DER wire format, which is now served
|
||||
// unauthenticated at `/.well-known/pki/crl/{issuer_id}` per RFC 8615.
|
||||
// The `crlResponse` Go struct that used to decode the JSON envelope is gone;
|
||||
// Phase 7 parses the DER bytes directly via `x509.ParseRevocationList`.
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// PostgreSQL test helper
|
||||
@@ -728,18 +723,41 @@ func TestIntegrationSuite(t *testing.T) {
|
||||
t.Fatalf("revocation response unexpected: %s", body)
|
||||
}
|
||||
|
||||
// Check CRL
|
||||
t.Run("CRL", func(t *testing.T) {
|
||||
resp, err := c.Get("/api/v1/crl")
|
||||
// Check DER CRL served unauthenticated under /.well-known/pki/ per
|
||||
// RFC 5280 §5 + RFC 8615 (M-006). Use a plain http.Get — no Bearer
|
||||
// token — to prove the endpoint is reachable by relying parties that
|
||||
// have no certctl API credentials.
|
||||
t.Run("CRL_DER_Unauthenticated", func(t *testing.T) {
|
||||
resp, err := http.Get(serverURL + "/.well-known/pki/crl/iss-local")
|
||||
if err != nil {
|
||||
t.Fatalf("GET CRL: %v", err)
|
||||
t.Fatalf("GET DER CRL: %v", err)
|
||||
}
|
||||
var crl crlResponse
|
||||
if err := decodeJSON(resp, &crl); err != nil {
|
||||
t.Fatalf("decode CRL: %v", err)
|
||||
defer resp.Body.Close()
|
||||
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
body, _ := io.ReadAll(resp.Body)
|
||||
t.Fatalf("unexpected status: got %d, want 200 (body=%s)", resp.StatusCode, string(body))
|
||||
}
|
||||
if crl.Total < 1 {
|
||||
t.Fatalf("CRL total: got %d, want >= 1", crl.Total)
|
||||
if ct := resp.Header.Get("Content-Type"); ct != "application/pkix-crl" {
|
||||
t.Errorf("Content-Type: got %q, want %q", ct, "application/pkix-crl")
|
||||
}
|
||||
|
||||
body, err := io.ReadAll(resp.Body)
|
||||
if err != nil {
|
||||
t.Fatalf("read CRL body: %v", err)
|
||||
}
|
||||
if len(body) == 0 {
|
||||
t.Fatal("CRL body empty")
|
||||
}
|
||||
|
||||
// Parse the DER bytes as an X.509 CRL (RFC 5280) and verify the
|
||||
// just-revoked certificate is listed.
|
||||
crl, err := x509.ParseRevocationList(body)
|
||||
if err != nil {
|
||||
t.Fatalf("parse DER CRL: %v", err)
|
||||
}
|
||||
if len(crl.RevokedCertificateEntries) < 1 {
|
||||
t.Fatalf("CRL entries: got %d, want >= 1", len(crl.RevokedCertificateEntries))
|
||||
}
|
||||
})
|
||||
|
||||
|
||||
+31
-6
@@ -26,6 +26,7 @@
|
||||
package integration_test
|
||||
|
||||
import (
|
||||
"crypto/x509"
|
||||
"database/sql"
|
||||
"encoding/json"
|
||||
"io"
|
||||
@@ -596,13 +597,37 @@ func TestQA(t *testing.T) {
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("CRL_JSON", func(t *testing.T) {
|
||||
code, body := c.bodyStr(t, "GET", "/api/v1/crl", "")
|
||||
if code != 200 {
|
||||
t.Fatalf("CRL = %d", code)
|
||||
// M-006: The non-standard JSON CRL endpoint was removed. RFC 5280 §5
|
||||
// defines only the DER wire format, now served unauthenticated at
|
||||
// `/.well-known/pki/crl/{issuer_id}` per RFC 8615. Use a plain
|
||||
// http.Get — no Bearer — to prove the endpoint is reachable by
|
||||
// relying parties with no API credentials.
|
||||
t.Run("CRL_DER_Unauthenticated", func(t *testing.T) {
|
||||
resp, err := http.Get(qaServerURL + "/.well-known/pki/crl/iss-local")
|
||||
if err != nil {
|
||||
t.Fatalf("GET DER CRL: %v", err)
|
||||
}
|
||||
if !strings.Contains(body, "entries") {
|
||||
t.Fatalf("CRL response missing entries field")
|
||||
defer resp.Body.Close()
|
||||
if resp.StatusCode != 200 {
|
||||
b, _ := io.ReadAll(resp.Body)
|
||||
t.Fatalf("CRL = %d (body=%s)", resp.StatusCode, string(b))
|
||||
}
|
||||
if ct := resp.Header.Get("Content-Type"); ct != "application/pkix-crl" {
|
||||
t.Errorf("Content-Type: got %q, want %q", ct, "application/pkix-crl")
|
||||
}
|
||||
body, err := io.ReadAll(resp.Body)
|
||||
if err != nil {
|
||||
t.Fatalf("read CRL body: %v", err)
|
||||
}
|
||||
if len(body) == 0 {
|
||||
t.Fatal("CRL body empty")
|
||||
}
|
||||
crl, err := x509.ParseRevocationList(body)
|
||||
if err != nil {
|
||||
t.Fatalf("parse DER CRL: %v", err)
|
||||
}
|
||||
if len(crl.RevokedCertificateEntries) < 1 {
|
||||
t.Fatalf("CRL entries: got %d, want >= 1", len(crl.RevokedCertificateEntries))
|
||||
}
|
||||
})
|
||||
})
|
||||
|
||||
+15
-6
@@ -608,13 +608,22 @@ else
|
||||
fail "Revocation failed" "$REVOKE_RESP"
|
||||
fi
|
||||
|
||||
info "Checking CRL..."
|
||||
CRL_RESP=$(api_get "/api/v1/crl" 2>/dev/null || echo '{"total":0}')
|
||||
CRL_TOTAL=$(echo "$CRL_RESP" | python3 -c "import sys,json; print(json.load(sys.stdin).get('total',0))" 2>/dev/null || echo 0)
|
||||
if [ "$CRL_TOTAL" -ge 1 ]; then
|
||||
pass "CRL contains $CRL_TOTAL revoked certificate(s)"
|
||||
info "Checking DER CRL under /.well-known/pki (RFC 5280 §5, RFC 8615)..."
|
||||
# The JSON CRL endpoint (`GET /api/v1/crl`) was removed in M-006. RFC 5280
|
||||
# defines only the DER wire format, now served unauthenticated at
|
||||
# `/.well-known/pki/crl/{issuer_id}`. Fetch without the Bearer header to
|
||||
# prove the endpoint is reachable by relying parties with no API key.
|
||||
CRL_TMP=$(mktemp)
|
||||
CRL_HEADERS=$(mktemp)
|
||||
CRL_HTTP_CODE=$(curl -s -o "$CRL_TMP" -D "$CRL_HEADERS" -w "%{http_code}" "${API_URL}/.well-known/pki/crl/iss-local" 2>/dev/null || echo "000")
|
||||
CRL_SIZE=$(wc -c < "$CRL_TMP" | tr -d ' ')
|
||||
CRL_CONTENT_TYPE=$(awk 'tolower($1)=="content-type:" { sub(/\r$/,"",$2); print tolower($2) }' "$CRL_HEADERS" | head -n1)
|
||||
rm -f "$CRL_TMP" "$CRL_HEADERS"
|
||||
|
||||
if [ "$CRL_HTTP_CODE" = "200" ] && [ "$CRL_CONTENT_TYPE" = "application/pkix-crl" ] && [ "$CRL_SIZE" -gt 0 ]; then
|
||||
pass "DER CRL served unauthenticated (HTTP 200, Content-Type application/pkix-crl, ${CRL_SIZE} bytes)"
|
||||
else
|
||||
fail "CRL empty after revocation"
|
||||
fail "DER CRL fetch failed: HTTP=$CRL_HTTP_CODE Content-Type=$CRL_CONTENT_TYPE size=$CRL_SIZE"
|
||||
fi
|
||||
|
||||
CERT_STATUS=$(api_get "/api/v1/certificates/mc-local-test" | python3 -c "import sys,json; print(json.load(sys.stdin).get('status',''))" 2>/dev/null || echo "unknown")
|
||||
|
||||
Reference in New Issue
Block a user