fix(09): WR-10 keep cabana's own backend guard when it is activated twice on one application

This commit is contained in:
Jakub Zych
2026-10-01 21:31:46 +02:00
parent 299d220b51
commit 2d96adf775
5 changed files with 40 additions and 2 deletions

View File

@@ -78,6 +78,7 @@ func Login(secret string) (string, error) {
| `bouncer.Registry` | Named guard registry; `bouncer.NewRegistry` creates one. |
| `bouncer.Registry.Register` | Registers a guard under a name on behalf of a plugin; duplicate names fail. |
| `bouncer.Registry.Middleware` | Returns HTTP middleware for a registered guard; unknown names fail. |
| `bouncer.Registry.Owner` | The plugin ID that registered a named guard. |
| `bouncer.NewJWTGuard` | Frontend JWT guard reading the bearer header and optional cookies. |
| `bouncer.NewBackendJWTGuard` | Admin JWT guard that requires the backend audience. |
| `bouncer.Middleware` | Standalone middleware that validates a bearer token and loads the user. |

View File

@@ -54,6 +54,16 @@ func (reg *Registry) Register(pluginID, name string, g any) error {
return nil
}
// Owner returns the plugin ID that registered the guard name. The second
// result is false when no guard has that name.
func (reg *Registry) Owner(name string) (string, bool) {
if reg == nil {
return "", false
}
ng, ok := reg.guards[name]
return ng.pluginID, ok
}
// Middleware derives an http middleware from a registered guard. Unknown
// names fail (fail boot, mirrors surf.RegisterMiddleware's contract).
// On Authenticate/AuthenticateCredential success: WithUser (+WithCredential

View File

@@ -289,3 +289,20 @@ func TestRegisterAcceptsValidGuards(t *testing.T) {
t.Fatal(err)
}
}
func TestRegistryOwner(t *testing.T) {
reg := NewRegistry()
if _, ok := reg.Owner("backend"); ok {
t.Fatal("an unregistered guard reported an owner")
}
if err := reg.Register("acme.owner", "backend", NewBackendJWTGuard("test-secret-for-registry-owner", nil, nil, nil)); err != nil {
t.Fatal(err)
}
if owner, ok := reg.Owner("backend"); !ok || owner != "acme.owner" {
t.Fatalf("Owner = %q, %v; want acme.owner", owner, ok)
}
var nilReg *Registry
if _, ok := nilReg.Owner("backend"); ok {
t.Fatal("a nil registry reported an owner")
}
}