mirror of
https://github.com/shankar0123/certctl.git
synced 2026-06-07 16:11:29 +00:00
1b4de3fb2d
Closes L-009 + L-010 + L-011 + L-013 + L-020 + L-021 from
comprehensive-audit-2026-04-25. L-004 deferred — recon found NO
rotation infrastructure exists at all; building it from scratch is
a feature project, not a Bundle-E mechanical sweep.
L-009 — ZeroSSL EAB URL configurable
Audit's 'no timeout' claim was wrong: ari.go:329 has 15s timeout.
internal/connector/issuer/acme/acme.go: zeroSSLEABEndpoint now
lazily reads CERTCTL_ZEROSSL_EAB_URL from env at package init;
defaults to ZeroSSL public endpoint. Pre-existing test override
path preserved.
L-010 — Verified-already-clean
grep -rn 'mock\.Anything' --include='*_test.go' . returned 0.
certctl uses hand-rolled struct mocks (mockJobRepo, mockAuditRepo,
etc.) with explicit method bodies; no testify-style mocks anywhere.
L-011 — IPv6 bracket-aware dialing pinned
Every production net.Dial / DialTimeout site audited:
cmd/agent/main.go:293 — intentional IPv4 literal '8.8.8.8:80'
verify.go / tlsprobe / network_scan — net.Dialer (no string addr)
email.go — net.JoinHostPort (bracket-aware)
ssh.go — addr derives from JoinHostPort upstream
ssrf.go — net.Dialer
internal/connector/notifier/email/email_ipv6_test.go (NEW):
TestJoinHostPort_IPv6BracketsRoundTrip pins IPv4/IPv6/zone variants;
TestSMTPDialerUsesJoinHostPort source-greps email.go and fails CI
if a future refactor swaps in 'host:port' concatenation.
L-013 — Verified-already-clean (monotonic-safe)
Only one site uses now.Sub: middleware.go:393 in tokenBucket.allow().
Both 'now' and tb.lastRefill come from time.Now() which carries
monotonic-clock readings per Go's time package contract;
intra-process now.Sub is monotonic-safe by construction. Doc
comment block added above the call to make the invariant explicit.
L-020 (CWE-563) — ineffassign sweep, 8 unique sites
certificate.go:135 — sortDir initial value dropped (set
unconditionally below by SortDesc branch).
certificate.go:169,175 — argCount post-increments dropped (var
not read past the LIMIT/OFFSET formatting).
agent_group.go, profile.go — page/perPage truly vestigial,
replaced with _ = page; _ = perPage.
issuer.go:633, owner.go:131, target.go:267, team.go:131 — same
treatment for the audit-flagged second-function ListXxx clamps.
First-function List() in issuer/owner/target/team KEEPS its
clamp because page/perPage is used for in-memory slice
pagination — ineffassign correctly didn't flag those.
Build + tests green post-sweep.
L-021 — Transitive CVE bump
go get golang.org/x/crypto@v0.45.0 golang.org/x/net@v0.47.0
(crypto required net@0.47.0). go-text@v0.31.0 transitively
bumped.
Per tool-output govulncheck-verbose: x/net@v0.45.0 fixes
GO-2026-4441 + GO-2026-4440; x/crypto@v0.45.0 fixes
GO-2025-4134 + GO-2025-4135 + GO-2025-4116 — all 5 advisories
cleared. Bundle B's ISV grep guard + Bundle D's release-time
govulncheck step are the going-forward monitor + bump pass.
L-004 — Deferred to dedicated bundle
Recon: zero hits for RotateAPIKey / rotated_at / key_status
anywhere in source. API keys configured via
CERTCTL_API_KEYS_NAMED env var; rotation is operator-managed
(edit env + restart). Building rotation infrastructure from
scratch is a feature project, not a mechanical sweep.
Documented in audit-report.md with scope-pivot note.
Audit deliverables:
audit-report.md: score 46/55 -> 52/55 closed
(Low 14/19 -> 19/19 — 100% Low closed except L-004 deferred)
findings.yaml: 6 status flips
certctl/CHANGELOG.md: Bundle E section
Verification:
go test -count=1 -short ./internal/service ./internal/connector/issuer/acme
./internal/connector/notifier/email green
go vet on changed packages clean
189 lines
5.1 KiB
Go
189 lines
5.1 KiB
Go
package service
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"log/slog"
|
|
"time"
|
|
|
|
"github.com/shankar0123/certctl/internal/domain"
|
|
"github.com/shankar0123/certctl/internal/repository"
|
|
)
|
|
|
|
// OwnerService provides business logic for certificate owner management.
|
|
type OwnerService struct {
|
|
ownerRepo repository.OwnerRepository
|
|
auditService *AuditService
|
|
}
|
|
|
|
// NewOwnerService creates a new owner service.
|
|
func NewOwnerService(
|
|
ownerRepo repository.OwnerRepository,
|
|
auditService *AuditService,
|
|
) *OwnerService {
|
|
return &OwnerService{
|
|
ownerRepo: ownerRepo,
|
|
auditService: auditService,
|
|
}
|
|
}
|
|
|
|
// List returns a paginated list of owners.
|
|
func (s *OwnerService) List(ctx context.Context, page, perPage int) ([]*domain.Owner, int64, error) {
|
|
if page < 1 {
|
|
page = 1
|
|
}
|
|
if perPage < 1 {
|
|
perPage = 50
|
|
}
|
|
|
|
owners, err := s.ownerRepo.List(ctx)
|
|
if err != nil {
|
|
return nil, 0, fmt.Errorf("failed to list owners: %w", err)
|
|
}
|
|
total := int64(len(owners))
|
|
start := (page - 1) * perPage
|
|
if start >= int(total) {
|
|
return nil, total, nil
|
|
}
|
|
end := start + perPage
|
|
if end > int(total) {
|
|
end = int(total)
|
|
}
|
|
return owners[start:end], total, nil
|
|
}
|
|
|
|
// Get retrieves an owner by ID.
|
|
func (s *OwnerService) Get(ctx context.Context, id string) (*domain.Owner, error) {
|
|
owner, err := s.ownerRepo.Get(ctx, id)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to get owner %s: %w", id, err)
|
|
}
|
|
return owner, nil
|
|
}
|
|
|
|
// Create validates and stores a new owner.
|
|
func (s *OwnerService) Create(ctx context.Context, owner *domain.Owner, actor string) error {
|
|
if owner.Name == "" {
|
|
return fmt.Errorf("owner name is required")
|
|
}
|
|
|
|
if owner.ID == "" {
|
|
owner.ID = generateID("owner")
|
|
}
|
|
now := time.Now()
|
|
if owner.CreatedAt.IsZero() {
|
|
owner.CreatedAt = now
|
|
}
|
|
if owner.UpdatedAt.IsZero() {
|
|
owner.UpdatedAt = now
|
|
}
|
|
if err := s.ownerRepo.Create(ctx, owner); err != nil {
|
|
return fmt.Errorf("failed to create owner: %w", err)
|
|
}
|
|
|
|
if s.auditService != nil {
|
|
if auditErr := s.auditService.RecordEvent(ctx, actor, domain.ActorTypeUser, "create_owner", "owner", owner.ID, nil); auditErr != nil {
|
|
slog.Error("failed to record audit event", "error", auditErr)
|
|
}
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// Update modifies an existing owner.
|
|
func (s *OwnerService) Update(ctx context.Context, id string, owner *domain.Owner, actor string) error {
|
|
if owner.Name == "" {
|
|
return fmt.Errorf("owner name is required")
|
|
}
|
|
|
|
owner.ID = id
|
|
if err := s.ownerRepo.Update(ctx, owner); err != nil {
|
|
return fmt.Errorf("failed to update owner %s: %w", id, err)
|
|
}
|
|
|
|
if s.auditService != nil {
|
|
if auditErr := s.auditService.RecordEvent(ctx, actor, domain.ActorTypeUser, "update_owner", "owner", id, nil); auditErr != nil {
|
|
slog.Error("failed to record audit event", "error", auditErr)
|
|
}
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// Delete removes an owner.
|
|
func (s *OwnerService) Delete(ctx context.Context, id string, actor string) error {
|
|
if err := s.ownerRepo.Delete(ctx, id); err != nil {
|
|
return fmt.Errorf("failed to delete owner %s: %w", id, err)
|
|
}
|
|
|
|
if s.auditService != nil {
|
|
if auditErr := s.auditService.RecordEvent(ctx, actor, domain.ActorTypeUser, "delete_owner", "owner", id, nil); auditErr != nil {
|
|
slog.Error("failed to record audit event", "error", auditErr)
|
|
}
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// ListOwners returns paginated owners (handler interface method).
|
|
func (s *OwnerService) ListOwners(ctx context.Context, page, perPage int) ([]domain.Owner, int64, error) {
|
|
// Bundle E / Audit L-020: page/perPage are unused; the underlying repo
|
|
// List() does not yet take pagination params. Marked explicitly so
|
|
// ineffassign sees no dead store and future maintainers see the
|
|
// vestigial params rather than a misleading default-applied clamp.
|
|
_ = page
|
|
_ = perPage
|
|
|
|
owners, err := s.ownerRepo.List(ctx)
|
|
if err != nil {
|
|
return nil, 0, fmt.Errorf("failed to list owners: %w", err)
|
|
}
|
|
total := int64(len(owners))
|
|
|
|
var result []domain.Owner
|
|
for _, o := range owners {
|
|
if o != nil {
|
|
result = append(result, *o)
|
|
}
|
|
}
|
|
|
|
return result, total, nil
|
|
}
|
|
|
|
// GetOwner returns a single owner (handler interface method).
|
|
func (s *OwnerService) GetOwner(ctx context.Context, id string) (*domain.Owner, error) {
|
|
return s.ownerRepo.Get(ctx, id)
|
|
}
|
|
|
|
// CreateOwner creates a new owner (handler interface method).
|
|
func (s *OwnerService) CreateOwner(ctx context.Context, owner domain.Owner) (*domain.Owner, error) {
|
|
if owner.ID == "" {
|
|
owner.ID = generateID("owner")
|
|
}
|
|
now := time.Now()
|
|
if owner.CreatedAt.IsZero() {
|
|
owner.CreatedAt = now
|
|
}
|
|
if owner.UpdatedAt.IsZero() {
|
|
owner.UpdatedAt = now
|
|
}
|
|
if err := s.ownerRepo.Create(ctx, &owner); err != nil {
|
|
return nil, fmt.Errorf("failed to create owner: %w", err)
|
|
}
|
|
return &owner, nil
|
|
}
|
|
|
|
// UpdateOwner modifies an owner (handler interface method).
|
|
func (s *OwnerService) UpdateOwner(ctx context.Context, id string, owner domain.Owner) (*domain.Owner, error) {
|
|
owner.ID = id
|
|
if err := s.ownerRepo.Update(ctx, &owner); err != nil {
|
|
return nil, fmt.Errorf("failed to update owner: %w", err)
|
|
}
|
|
return &owner, nil
|
|
}
|
|
|
|
// DeleteOwner removes an owner (handler interface method).
|
|
func (s *OwnerService) DeleteOwner(ctx context.Context, id string) error {
|
|
return s.ownerRepo.Delete(ctx, id)
|
|
}
|