feat(11-03): re-authorize every Centrifugo subscribe through a namespace registry

- lighthouse: Registry of namespace authorizers (Result, Allowed, Denied),
  ParseChannel, ChannelID with PHP (int)-cast semantics (PHPInt, pinned by
  a php -r table test), FormatChannels, WithClientID/ClientID
- centrifugo: ProxyHandler (constant-time X-Centrifugo-Secret, HTTP 200
  generic deny, info [] on allow, presence allow/override merge, 64 KiB
  body cap) mounted as the ServerToServer subscribe route
- README: proxy contract, registry and channel rules
This commit is contained in:
Jakub Zych
2026-09-30 12:29:09 +02:00
parent cada7a4442
commit 79fd705680
8 changed files with 699 additions and 11 deletions

View File

@@ -33,6 +33,7 @@ const (
type Service struct {
app *backpack.App
driver Driver
registry *Registry
log *slog.Logger
namespace string
queue string
@@ -85,10 +86,11 @@ func From(app *backpack.App) (*Service, error) {
func newService(app *backpack.App) *Service {
svc := &Service{
app: app,
log: loggerFromApp(app),
queue: DefaultQueue,
timeout: DefaultTimeout,
app: app,
registry: NewRegistry(),
log: loggerFromApp(app),
queue: DefaultQueue,
timeout: DefaultTimeout,
}
if app == nil || app.Config == nil {
return svc
@@ -112,6 +114,15 @@ func (s *Service) Driver() Driver {
return s.driver
}
// Registry returns the channel-namespace authorizer registry that the
// driver's subscribe authorization consults.
func (s *Service) Registry() *Registry {
if s == nil {
return nil
}
return s.registry
}
// Logger returns the app logger the service and its driver log through.
func (s *Service) Logger() *slog.Logger {
if s == nil || s.log == nil {