Commit Graph
100 Commits
Author SHA1 Message Date
Jan Larwig f7ae0ae81e test: update traefik setup and use in-memory for all dex instances instead of etcd
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 10:38:26 +02:00
Jan Larwig c4043233cf ci: hardening by replacing all tags using immutable commit hashes (#3507)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:31:56 +02:00
Jan Larwig d707a36a4c test: fix expected error message wording
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:23:29 +02:00
Jan Larwig 304077498d ci: use go tool for running golangci-lint
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:23:29 +02:00
Jan Larwig 09979d458a docs: update slack reference for CNCF
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-09 13:50:16 +02:00
Jan Larwig 61151b4869 Merge pull request #3447 from oauth2-proxy/chore/bump-go-to-1.26-and-migrate-of-reverse-proxy-handling
chore(dep): bump go to 1.26 and migrate of reverse proxy handling
2026-06-09 12:20:57 +02:00
Jan Larwig 0de18825f6 chore(deps): bump Go to 1.26 and migrate upstream reverse proxies to Rewrite
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-08 14:12:56 +02:00
Jan Larwig 9a14186a26 chore(goconsts): use proper constants for http methods
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-08 12:54:58 +02:00
Jan Larwig 65037b086c change affiliation 2026-04-17 10:56:42 +02:00
Jan Larwig bdfde725c6 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:29:01 +02:00
Jan Larwig cc0e0335ea Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:24:51 +02:00
Jan Larwig aff369dfa3 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:22:56 +02:00
Jan Larwig 43596a7bab Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:20:36 +02:00
Jan LarwigandChristopher Schrewing 0337a95fc6 Merge commit from fork
* fix: clear session cookie at beginning of signinpage handler

Co-authored-by: Christopher Schrewing <christopher.schrewing@weidmueller.com>
Signed-off-by: Michael Bella <michael.bella@weidmueller.com>
Signed-off-by: Jan Larwig <jan@larwig.com>

* test: clear session cookie at beginning of signinpage handler

Signed-off-by: Jan Larwig <jan@larwig.com>

* doc: changelog entry for GHSA-f24x-5g9q-753f

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Michael Bella <michael.bella@weidmueller.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: Christopher Schrewing <christopher.schrewing@weidmueller.com>
2026-04-13 18:17:50 +02:00
Jan Larwig 26de082a78 chore(deps): update gomod dependencies (#3411)
-       github.com/coreos/go-oidc/v3 v3.17.0
+       github.com/coreos/go-oidc/v3 v3.18.0

-       github.com/go-jose/go-jose/v3 v3.0.4
+       github.com/go-jose/go-jose/v3 v3.0.5

-       github.com/go-viper/mapstructure/v2 v2.4.0
+       github.com/go-viper/mapstructure/v2 v2.5.0

-       golang.org/x/crypto v0.49.0
+       golang.org/x/crypto v0.50.0

-       golang.org/x/net v0.52.0
+       golang.org/x/net v0.53.0

-       google.golang.org/api v0.272.0
+       google.golang.org/api v0.275.0

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-12 14:21:47 +02:00
Jan Larwig da9123f740 doc: fix config validation formatting (#3386)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-03-23 16:05:54 +01:00
Jan Larwig 7bc4b5e5df doc: fix changelog for v7.15.0 2026-03-23 15:54:46 +01:00
Jan LarwigandSimon Engmann 46be69c276 fix: propagate errors during route building (#3383)
* Propagate errors during route building

This fixes cases such as invalid paths being silently discarded after
creation by throwing a visible error in such cases.
Due to the way gorilla/mux's fluent API is designed, it is necessary to
manually call `.GetError()` to check for errors while building routes.

Signed-off-by: Simon Engmann <simon.engmann@sovity.de>

* Add test for route building error propagation

Signed-off-by: Simon Engmann <simon.engmann@sovity.de>

* Add route building error propagation to changelog

Signed-off-by: Simon Engmann <simon.engmann@sovity.de>

---------

Signed-off-by: Simon Engmann <simon.engmann@sovity.de>
Co-authored-by: Simon Engmann <simon.engmann@sovity.de>
2026-03-23 11:25:20 +01:00
Jan Larwig 5ca3012652 doc: update PR template with additional checklist items 2026-03-23 10:36:19 +01:00
Jan Larwig 0ecc35ea41 chore(deps): update gomod and golangci/golangci-lint to v2.11.4 (#3382)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-03-23 09:38:12 +01:00
Jan LarwigandTristan 9ae0b325a6 feat: add support for setting a unix binding's socket file mode (#3376)
fix: linter issues and set default unix socket permissions to 0660

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: Tristan <tristan@mangadex.org>
2026-03-19 00:08:50 +08:00
Jan Larwig 274d7dec46 ci: harden workflows; add trivy scanning; (#3372)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-03-17 21:07:53 +08:00
Jan Larwig 788f3d0e1d ci: ensure we always use the latest patch version of golang (#3350)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-02-26 14:48:35 +01:00
Jan Larwig 06f1234b69 ci: ensure we always use the latest patch version of golang (#3349)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-02-26 14:43:52 +01:00
Jan Larwig e7724f3a74 ci: ensure release branches originate from the local repository and reduce residual risk of command injection (#3337)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-02-12 21:18:45 +01:00
Jan Larwig d5ea33bea7 ci: avoid running qlty coverage report for PRs (#3316)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-18 01:05:54 +01:00
Jan Larwig 7bf586c898 Merge pull request #3313 from oauth2-proxy/release/v7.14.1
release v7.14.1
2026-01-17 16:22:29 +01:00
Jan Larwig 8f52b14eda doc: changelog entry for v7.14.1
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 16:15:54 +01:00
Jan Larwig 56b5c08596 Merge pull request #3312 from oauth2-proxy/chore/gomod
chore(deps): update go1.25.6 and dependencies
2026-01-17 16:07:31 +01:00
Jan Larwig 5020c33124 ci: fix qlty coverage upload
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 16:01:19 +01:00
Jan Larwig cc0b48d5ec ci: fix linter warnings for preallocation
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 16:01:14 +01:00
Jan Larwig 844e4e3b0c chore(deps): upgrade to go1.25.6; upgrade all go dependencies
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 15:25:59 +01:00
Jan Larwig 707e6c4a1c Merge pull request #3308 from oauth2-proxy/release/v7.14.0
release v7.14.0
2026-01-17 11:15:40 +01:00
Jan Larwig 1f29953b7b docs: add todo for revamping the usage / naming of PassHostHeader
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 11:06:24 +01:00
Jan Larwig 3bc1a5373a doc: extend the alpha config changelog notice
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 11:06:24 +01:00
Jan Larwig a360cb3875 docs: backport integrations split to v7.14.x & v7.13.x
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 11:06:19 +01:00
Jan Larwig f46dcc77a8 doc: cncf onboarding and sponsor update
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 11:04:43 +01:00
Jan Larwig 34c2712c99 doc: add changelog and migration guide for v7.14.0 alpha config changes
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-01-17 11:04:42 +01:00
Jan Larwig 699f367115 chore(deps): upgrade gomod and bump to golang v1.25.5 (#3292)
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-12-24 11:30:23 +01:00
Jan Larwig e27921ee80 Merge pull request #2628 from tuunit/use-mapstructures-for-parsing-and-merging
structured config #1: introduce mapstructure decoder for yaml parsing
2025-11-28 18:14:11 +01:00
Jan Larwig aee540a277 doc: fix mapstructure configuration comments
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-28 17:20:15 +01:00
Jan Larwig 15041dd116 feat: migrate google used organization id and header normalization booleans to pointers
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:39:01 +01:00
Jan Larwig 0eec65e230 refactor: ptr.Ptr to ptr.To
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:59 +01:00
Jan Larwig 137decb1ec adapting unit tests and fixing minor issues introduced with the derefing
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:57 +01:00
Jan Larwig 638fba417f deref everything but now with default constants
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:56 +01:00
Jan Larwig ceb9a387b1 deref everything... but why?
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:54 +01:00
Jan Larwig 527c72f23f feat: add ensure defaults to all migrated structs
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:52 +01:00
Jan Larwig 51b1fd0510 chore(deps): replace with forked official yaml library
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:51 +01:00
Jan Larwig 9d70e04262 feat: migrate all alpha config booleans to pointers
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:49 +01:00
Jan Larwig 50414356e8 return nil directly
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:47 +01:00
Jan Larwig 955ab6b41b fix test setup and add local image build make target
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:46 +01:00
Jan Larwig 48bd2d7d38 fix merge problems and test cases
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:44 +01:00
Jan Larwig 810f629ee8 revert: secrets as []byte instead of string
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:42 +01:00
Jan Larwig aaf1889b97 fix alpha config
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:40 +01:00
Jan Larwig 18fc898129 resolve cipher deprecation and update mapstructures v2
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:29 +01:00
tuunit 4c0dd28f12 fix alpha config example
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:26 +01:00
tuunit c186d40675 use official upstream yaml library v3
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:22 +01:00
tuunit 6720d8da60 add duration test
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:18 +01:00
Jan Larwig 676f56a35e apply review suggestions
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:38:03 +01:00
tuunit 7c20001045 introduce mapstructure decoder for yaml parsing
remove color output in tests for better readability in github actions

bugfix: remove google as default provider for alpha options

fix conversion flow for toml to yaml

revert ginkgo color deactivation

revert claim- and secret source back to pointers

regenerate alpha config

Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-16 22:37:37 +01:00
Jan Larwig fcf4e7947b fix: hmacauth dependency licensing issue (#3253)
* fix: upstream licensing issue by adopting hmacauth library and changing asserting library for its test cases

Signed-off-by: Jan Larwig <jan@larwig.com>

* fix: golang code quality and linting issues for hmacauth

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-09 20:14:54 +01:00
Jan Larwig f3f30fa976 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-08 12:52:31 +01:00
Jan Larwig 5993067505 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-11-08 12:42:45 +01:00
Jan Larwig 8f687e4d0c chore(deps): upgrade to latest go1.25.3 (#3244)
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-10-28 09:54:10 +01:00
Jan Larwig 5082db0bec Merge pull request #3169 from oauth2-proxy/release/v7.12.0
release v7.12.0
2025-08-19 08:50:29 +02:00
Jan Larwig 7294eebce1 add changelog entry for v7.12.0
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-08-19 08:42:24 +02:00
Jan Larwig 744b31a2c6 chore(dep): upgrade to latest golang 1.24.6 (#3166)
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-08-18 14:27:19 +02:00
Jan Larwig 9667bce094 feat(e2e): add workflow to trigger e2e test suite through PR comments (#3153)
* feat(e2e): add workflow to trigger e2e test suite through PR comments

* add empty line
2025-08-12 08:11:00 +02:00
Jan Larwig 9ffafad4b2 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-07-30 19:46:58 +02:00
b57c82181d feat(cookie) csrf per request limit (#3134)
* Allow setting maximum number of csrf cookies, deleting the oldest if necessary

* Add a test for multiple CSRF cookies to remove the old cookie

* Add docs/changelog

* If limit is <=0 do not clear

Signed-off-by: test <bert@transtrend.com>

* Better docs

Co-authored-by: Jan Larwig <jan@larwig.com>

* direct check of option value

Co-authored-by: Jan Larwig <jan@larwig.com>

* direct use of option value

Co-authored-by: Jan Larwig <jan@larwig.com>

* sort based on clock compare vs time compare

Co-authored-by: Jan Larwig <jan@larwig.com>

* clock.Clock does not implement Compare, fix csrf cookie extraction after rename

Signed-off-by: Bert Helderman <bert@transtrend.com>

* Linter fix

* add method signature documentation and slight formatting

Signed-off-by: Jan Larwig <jan@larwig.com>

* fix: test case for csrf cookie limit and flag

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Bert Helderman <bert@transtrend.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: test <bert@transtrend.com>
Co-authored-by: bh-tt <71650427+bh-tt@users.noreply.github.com>
2025-07-20 16:44:42 +02:00
Jan Larwig e25f9ec9d7 add changelog entry
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-07-17 10:01:37 +02:00
Jan Larwig c8c160da79 Create FUNDING.yml 2025-07-11 09:58:16 +02:00
Jan Larwig 14d5355655 docs: add note about version obfuscation to footer option (#3051)
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-05-03 21:44:30 +02:00
Jan Larwig 367183d7b8 chore(build): refactoring makefile for better usability and introducing a default help target (#2930) 2025-04-27 20:09:52 +02:00
Jan Larwig 46554b5bff chore(deps): update golang dependencies and pin to latest golang v1.23.x release (#3011)
Signed-off-by: Jan Larwig <jan@larwig.com>
2025-03-25 20:22:56 +01:00
Jan Larwig a01abbd9b2 Merge pull request #2957 from oauth2-proxy/renovate/golangci-golangci-lint-1.x
chore(deps): update dependency golangci/golangci-lint to v1.64.7
2025-03-12 08:55:55 +01:00
Jan Larwig 089c0eaae1 Merge pull request #2956 from oauth2-proxy/renovate/alpine-3.x
chore(deps): update alpine docker tag to v3.21.3
2025-03-12 08:51:45 +01:00
Jan Larwig 0364f1b32f doc: add entra id to issue templates 2025-01-29 14:58:53 +01:00
Jan Larwig 67f3da232a fix(test): syntax violation of json with one too many closing curly brackets 2025-01-20 20:45:45 +01:00
Jan Larwig 3cf74c21f8 doc: update changelog 2025-01-20 20:45:45 +01:00
Jan Larwig 9b32699c26 chore(deps): update all go depedencies 2025-01-20 20:45:45 +01:00
Jan Larwig 58527ec6c9 chore(build): retrieve go version from go.mod as single point of truth 2025-01-20 20:45:45 +01:00
Jan Larwig 0edecd381e update release highlights 2025-01-15 12:22:44 +01:00
Jan Larwig a29eda3a6d Merge branch 'master' into fix/missing-version-during-docker-built 2025-01-15 09:08:42 +01:00
Jan Larwig f1a5011108 fix: setting missing version during docker built 2025-01-14 16:29:26 +01:00
tuunit 8dd2cbec4d fix: systemd socket support build handling for windows 2025-01-13 16:41:33 +01:00
tuunit ae5b5dc45f doc: update release v7.8.0 changelog 2025-01-13 16:41:33 +01:00
Jan LarwigandJoel Speed 9945b68a06 doc: readme overhaul and azure sponsorship (#2826)
* new readme structure

* add adopters file

* add microsoft sponsorship

* add reference to adopter file

* add gopher slack invite link

* slightly rephrase nightly image section

* add sponsor request for action

* better formatting for contributor wall

* add longer wait time for stale PRs and issues and allow for exemption through bug and high-priority labels

* apply review suggestion

Co-authored-by: Joel Speed <Joel.speed@hotmail.co.uk>

---------

Co-authored-by: Joel Speed <Joel.speed@hotmail.co.uk>
2024-10-27 12:12:46 +00:00
tuunit 4bd920b208 add changelog entry 2024-10-06 21:55:45 +02:00
tuunit bae168f06a better handling of default transport modification 2024-10-06 21:43:38 +02:00
tuunit 8fd7312a90 fix: self signed certificate handling 2024-10-05 17:29:37 +02:00
tuunit 07230ead91 fix(ci): testing full release cycle before release branches can be merged 2024-10-02 16:03:13 +02:00
tuunit 1dd4a412b0 add new loop var linter for go1.22 and remove unnecessary exportloopref linter 2024-10-01 11:15:48 +02:00
tuunit 3c7dadcbd2 add v7.7.0 release highlights 2024-10-01 11:15:48 +02:00
tuunit 6e32bd6e38 fix missing 'changes since' section logic 2024-10-01 11:15:47 +02:00
tuunit f0fe33e032 enforce go 1.22.7 2024-10-01 11:15:47 +02:00
tuunit 715995843c fix golangci-lint version in pipelines 2024-10-01 11:15:47 +02:00
tuunit ad3ee0f66c update relase pipeline 2024-09-25 10:34:28 +02:00
tuunit 41c8d5bfce chore(deps): update all golang dependencies 2024-09-23 16:38:40 +02:00
Jan Larwig e22b8d0eca doc: update maintainer emails (#2748) 2024-08-20 18:56:11 +02:00