summaryrefslogtreecommitdiff
path: root/vendor
diff options
context:
space:
mode:
authorgy95 <1015105054@qq.com>2023-01-17 10:51:00 +0800
committergy95 <1015105054@qq.com>2023-01-17 16:18:21 +0800
commit355ec8f862f1db88b49716130e639d0ea43f5aae (patch)
treed90aab1d80947caaab82dae70674157f7aa66dbc /vendor
parentbump kind version to 1.12.0 (diff)
downloadkubeedge-355ec8f862f1db88b49716130e639d0ea43f5aae.tar.gz
fix conformance e2e compile error
Signed-off-by: gy95 <1015105054@qq.com>
Diffstat (limited to 'vendor')
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/.gitignore1
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/.travis.yml14
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/asymmetric.go4
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/cipher/ecdh_es.go28
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/crypter.go14
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/encoding.go14
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/jwk.go184
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/jws.go95
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/jwt/claims.go30
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/jwt/errors.go5
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/jwt/jwt.go39
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/jwt/validation.go20
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/opaque.go61
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/shared.go21
-rw-r--r--vendor/gopkg.in/square/go-jose.v2/signing.go74
-rw-r--r--vendor/modules.txt3
16 files changed, 98 insertions, 509 deletions
diff --git a/vendor/gopkg.in/square/go-jose.v2/.gitignore b/vendor/gopkg.in/square/go-jose.v2/.gitignore
index 95a851586..5b4d73b68 100644
--- a/vendor/gopkg.in/square/go-jose.v2/.gitignore
+++ b/vendor/gopkg.in/square/go-jose.v2/.gitignore
@@ -5,4 +5,3 @@
*.pem
*.cov
jose-util/jose-util
-jose-util.t.err \ No newline at end of file
diff --git a/vendor/gopkg.in/square/go-jose.v2/.travis.yml b/vendor/gopkg.in/square/go-jose.v2/.travis.yml
index ae69862df..a84e99f7d 100644
--- a/vendor/gopkg.in/square/go-jose.v2/.travis.yml
+++ b/vendor/gopkg.in/square/go-jose.v2/.travis.yml
@@ -8,9 +8,12 @@ matrix:
- go: tip
go:
-- '1.11.x'
-- '1.12.x'
-- tip
+- '1.5.x'
+- '1.6.x'
+- '1.7.x'
+- '1.8.x'
+- '1.9.x'
+- '1.10.x'
go_import_path: gopkg.in/square/go-jose.v2
@@ -26,8 +29,6 @@ before_install:
- go get github.com/wadey/gocovmerge
- go get github.com/mattn/goveralls
- go get github.com/stretchr/testify/assert
-- go get github.com/stretchr/testify/require
-- go get github.com/google/go-cmp/cmp
- go get golang.org/x/tools/cmd/cover || true
- go get code.google.com/p/go.tools/cmd/cover || true
- pip install cram --user
@@ -37,9 +38,10 @@ script:
- go test ./cipher -v -covermode=count -coverprofile=cipher/profile.cov
- go test ./jwt -v -covermode=count -coverprofile=jwt/profile.cov
- go test ./json -v # no coverage for forked encoding/json package
-- cd jose-util && go build && PATH=$PWD:$PATH cram -v jose-util.t # cram tests jose-util
+- cd jose-util && go build && PATH=$PWD:$PATH cram -v jose-util.t
- cd ..
after_success:
- gocovmerge *.cov */*.cov > merged.coverprofile
- $HOME/gopath/bin/goveralls -coverprofile merged.coverprofile -service=travis-ci
+
diff --git a/vendor/gopkg.in/square/go-jose.v2/asymmetric.go b/vendor/gopkg.in/square/go-jose.v2/asymmetric.go
index b69aa0369..67935561b 100644
--- a/vendor/gopkg.in/square/go-jose.v2/asymmetric.go
+++ b/vendor/gopkg.in/square/go-jose.v2/asymmetric.go
@@ -29,7 +29,7 @@ import (
"math/big"
"golang.org/x/crypto/ed25519"
- josecipher "gopkg.in/square/go-jose.v2/cipher"
+ "gopkg.in/square/go-jose.v2/cipher"
"gopkg.in/square/go-jose.v2/json"
)
@@ -288,7 +288,7 @@ func (ctx rsaDecrypterSigner) signPayload(payload []byte, alg SignatureAlgorithm
out, err = rsa.SignPKCS1v15(RandReader, ctx.privateKey, hash, hashed)
case PS256, PS384, PS512:
out, err = rsa.SignPSS(RandReader, ctx.privateKey, hash, hashed, &rsa.PSSOptions{
- SaltLength: rsa.PSSSaltLengthEqualsHash,
+ SaltLength: rsa.PSSSaltLengthAuto,
})
}
diff --git a/vendor/gopkg.in/square/go-jose.v2/cipher/ecdh_es.go b/vendor/gopkg.in/square/go-jose.v2/cipher/ecdh_es.go
index 093c64674..c128e327f 100644
--- a/vendor/gopkg.in/square/go-jose.v2/cipher/ecdh_es.go
+++ b/vendor/gopkg.in/square/go-jose.v2/cipher/ecdh_es.go
@@ -17,10 +17,8 @@
package josecipher
import (
- "bytes"
"crypto"
"crypto/ecdsa"
- "crypto/elliptic"
"encoding/binary"
)
@@ -46,38 +44,16 @@ func DeriveECDHES(alg string, apuData, apvData []byte, priv *ecdsa.PrivateKey, p
panic("public key not on same curve as private key")
}
- z, _ := priv.Curve.ScalarMult(pub.X, pub.Y, priv.D.Bytes())
- zBytes := z.Bytes()
+ z, _ := priv.PublicKey.Curve.ScalarMult(pub.X, pub.Y, priv.D.Bytes())
+ reader := NewConcatKDF(crypto.SHA256, z.Bytes(), algID, ptyUInfo, ptyVInfo, supPubInfo, []byte{})
- // Note that calling z.Bytes() on a big.Int may strip leading zero bytes from
- // the returned byte array. This can lead to a problem where zBytes will be
- // shorter than expected which breaks the key derivation. Therefore we must pad
- // to the full length of the expected coordinate here before calling the KDF.
- octSize := dSize(priv.Curve)
- if len(zBytes) != octSize {
- zBytes = append(bytes.Repeat([]byte{0}, octSize-len(zBytes)), zBytes...)
- }
-
- reader := NewConcatKDF(crypto.SHA256, zBytes, algID, ptyUInfo, ptyVInfo, supPubInfo, []byte{})
key := make([]byte, size)
// Read on the KDF will never fail
_, _ = reader.Read(key)
-
return key
}
-// dSize returns the size in octets for a coordinate on a elliptic curve.
-func dSize(curve elliptic.Curve) int {
- order := curve.Params().P
- bitLen := order.BitLen()
- size := bitLen / 8
- if bitLen%8 != 0 {
- size++
- }
- return size
-}
-
func lengthPrefixed(data []byte) []byte {
out := make([]byte, len(data)+4)
binary.BigEndian.PutUint32(out, uint32(len(data)))
diff --git a/vendor/gopkg.in/square/go-jose.v2/crypter.go b/vendor/gopkg.in/square/go-jose.v2/crypter.go
index d24cabf6b..c45c71206 100644
--- a/vendor/gopkg.in/square/go-jose.v2/crypter.go
+++ b/vendor/gopkg.in/square/go-jose.v2/crypter.go
@@ -141,8 +141,6 @@ func NewEncrypter(enc ContentEncryption, rcpt Recipient, opts *EncrypterOptions)
keyID, rawKey = encryptionKey.KeyID, encryptionKey.Key
case *JSONWebKey:
keyID, rawKey = encryptionKey.KeyID, encryptionKey.Key
- case OpaqueKeyEncrypter:
- keyID, rawKey = encryptionKey.KeyID(), encryptionKey
default:
rawKey = encryptionKey
}
@@ -269,11 +267,9 @@ func makeJWERecipient(alg KeyAlgorithm, encryptionKey interface{}) (recipientKey
recipient, err := makeJWERecipient(alg, encryptionKey.Key)
recipient.keyID = encryptionKey.KeyID
return recipient, err
+ default:
+ return recipientKeyInfo{}, ErrUnsupportedKeyType
}
- if encrypter, ok := encryptionKey.(OpaqueKeyEncrypter); ok {
- return newOpaqueKeyEncrypter(alg, encrypter)
- }
- return recipientKeyInfo{}, ErrUnsupportedKeyType
}
// newDecrypter creates an appropriate decrypter based on the key type
@@ -299,11 +295,9 @@ func newDecrypter(decryptionKey interface{}) (keyDecrypter, error) {
return newDecrypter(decryptionKey.Key)
case *JSONWebKey:
return newDecrypter(decryptionKey.Key)
+ default:
+ return nil, ErrUnsupportedKeyType
}
- if okd, ok := decryptionKey.(OpaqueKeyDecrypter); ok {
- return &opaqueKeyDecrypter{decrypter: okd}, nil
- }
- return nil, ErrUnsupportedKeyType
}
// Implementation of encrypt method producing a JWE object.
diff --git a/vendor/gopkg.in/square/go-jose.v2/encoding.go b/vendor/gopkg.in/square/go-jose.v2/encoding.go
index 70f7385c4..b9687c647 100644
--- a/vendor/gopkg.in/square/go-jose.v2/encoding.go
+++ b/vendor/gopkg.in/square/go-jose.v2/encoding.go
@@ -23,12 +23,13 @@ import (
"encoding/binary"
"io"
"math/big"
- "strings"
- "unicode"
+ "regexp"
"gopkg.in/square/go-jose.v2/json"
)
+var stripWhitespaceRegex = regexp.MustCompile("\\s")
+
// Helper function to serialize known-good objects.
// Precondition: value is not a nil pointer.
func mustSerializeJSON(value interface{}) []byte {
@@ -55,14 +56,7 @@ func mustSerializeJSON(value interface{}) []byte {
// Strip all newlines and whitespace
func stripWhitespace(data string) string {
- buf := strings.Builder{}
- buf.Grow(len(data))
- for _, r := range data {
- if !unicode.IsSpace(r) {
- buf.WriteRune(r)
- }
- }
- return buf.String()
+ return stripWhitespaceRegex.ReplaceAllString(data, "")
}
// Perform compression based on algorithm
diff --git a/vendor/gopkg.in/square/go-jose.v2/jwk.go b/vendor/gopkg.in/square/go-jose.v2/jwk.go
index 2dc6aec4b..fb585b115 100644
--- a/vendor/gopkg.in/square/go-jose.v2/jwk.go
+++ b/vendor/gopkg.in/square/go-jose.v2/jwk.go
@@ -17,20 +17,15 @@
package jose
import (
- "bytes"
"crypto"
"crypto/ecdsa"
"crypto/elliptic"
"crypto/rsa"
- "crypto/sha1"
- "crypto/sha256"
"crypto/x509"
"encoding/base64"
- "encoding/hex"
"errors"
"fmt"
"math/big"
- "net/url"
"reflect"
"strings"
@@ -62,31 +57,16 @@ type rawJSONWebKey struct {
Dq *byteBuffer `json:"dq,omitempty"`
Qi *byteBuffer `json:"qi,omitempty"`
// Certificates
- X5c []string `json:"x5c,omitempty"`
- X5u *url.URL `json:"x5u,omitempty"`
- X5tSHA1 string `json:"x5t,omitempty"`
- X5tSHA256 string `json:"x5t#S256,omitempty"`
+ X5c []string `json:"x5c,omitempty"`
}
// JSONWebKey represents a public or private key in JWK format.
type JSONWebKey struct {
- // Cryptographic key, can be a symmetric or asymmetric key.
- Key interface{}
- // Key identifier, parsed from `kid` header.
- KeyID string
- // Key algorithm, parsed from `alg` header.
- Algorithm string
- // Key use, parsed from `use` header.
- Use string
-
- // X.509 certificate chain, parsed from `x5c` header.
+ Key interface{}
Certificates []*x509.Certificate
- // X.509 certificate URL, parsed from `x5u` header.
- CertificatesURL *url.URL
- // X.509 certificate thumbprint (SHA-1), parsed from `x5t` header.
- CertificateThumbprintSHA1 []byte
- // X.509 certificate thumbprint (SHA-256), parsed from `x5t#S256` header.
- CertificateThumbprintSHA256 []byte
+ KeyID string
+ Algorithm string
+ Use string
}
// MarshalJSON serializes the given key to its JSON representation.
@@ -125,39 +105,6 @@ func (k JSONWebKey) MarshalJSON() ([]byte, error) {
raw.X5c = append(raw.X5c, base64.StdEncoding.EncodeToString(cert.Raw))
}
- x5tSHA1Len := len(k.CertificateThumbprintSHA1)
- x5tSHA256Len := len(k.CertificateThumbprintSHA256)
- if x5tSHA1Len > 0 {
- if x5tSHA1Len != sha1.Size {
- return nil, fmt.Errorf("square/go-jose: invalid SHA-1 thumbprint (must be %d bytes, not %d)", sha1.Size, x5tSHA1Len)
- }
- raw.X5tSHA1 = base64.RawURLEncoding.EncodeToString(k.CertificateThumbprintSHA1)
- }
- if x5tSHA256Len > 0 {
- if x5tSHA256Len != sha256.Size {
- return nil, fmt.Errorf("square/go-jose: invalid SHA-256 thumbprint (must be %d bytes, not %d)", sha256.Size, x5tSHA256Len)
- }
- raw.X5tSHA256 = base64.RawURLEncoding.EncodeToString(k.CertificateThumbprintSHA256)
- }
-
- // If cert chain is attached (as opposed to being behind a URL), check the
- // keys thumbprints to make sure they match what is expected. This is to
- // ensure we don't accidentally produce a JWK with semantically inconsistent
- // data in the headers.
- if len(k.Certificates) > 0 {
- expectedSHA1 := sha1.Sum(k.Certificates[0].Raw)
- expectedSHA256 := sha256.Sum256(k.Certificates[0].Raw)
-
- if len(k.CertificateThumbprintSHA1) > 0 && !bytes.Equal(k.CertificateThumbprintSHA1, expectedSHA1[:]) {
- return nil, errors.New("square/go-jose: invalid SHA-1 thumbprint, does not match cert chain")
- }
- if len(k.CertificateThumbprintSHA256) > 0 && !bytes.Equal(k.CertificateThumbprintSHA256, expectedSHA256[:]) {
- return nil, errors.New("square/go-jose: invalid or SHA-256 thumbprint, does not match cert chain")
- }
- }
-
- raw.X5u = k.CertificatesURL
-
return json.Marshal(raw)
}
@@ -169,61 +116,28 @@ func (k *JSONWebKey) UnmarshalJSON(data []byte) (err error) {
return err
}
- certs, err := parseCertificateChain(raw.X5c)
- if err != nil {
- return fmt.Errorf("square/go-jose: failed to unmarshal x5c field: %s", err)
- }
-
var key interface{}
- var certPub interface{}
- var keyPub interface{}
-
- if len(certs) > 0 {
- // We need to check that leaf public key matches the key embedded in this
- // JWK, as required by the standard (see RFC 7517, Section 4.7). Otherwise
- // the JWK parsed could be semantically invalid. Technically, should also
- // check key usage fields and other extensions on the cert here, but the
- // standard doesn't exactly explain how they're supposed to map from the
- // JWK representation to the X.509 extensions.
- certPub = certs[0].PublicKey
- }
-
switch raw.Kty {
case "EC":
if raw.D != nil {
key, err = raw.ecPrivateKey()
- if err == nil {
- keyPub = key.(*ecdsa.PrivateKey).Public()
- }
} else {
key, err = raw.ecPublicKey()
- keyPub = key
}
case "RSA":
if raw.D != nil {
key, err = raw.rsaPrivateKey()
- if err == nil {
- keyPub = key.(*rsa.PrivateKey).Public()
- }
} else {
key, err = raw.rsaPublicKey()
- keyPub = key
}
case "oct":
- if certPub != nil {
- return errors.New("square/go-jose: invalid JWK, found 'oct' (symmetric) key with cert chain")
- }
key, err = raw.symmetricKey()
case "OKP":
if raw.Crv == "Ed25519" && raw.X != nil {
if raw.D != nil {
key, err = raw.edPrivateKey()
- if err == nil {
- keyPub = key.(ed25519.PrivateKey).Public()
- }
} else {
key, err = raw.edPublicKey()
- keyPub = key
}
} else {
err = fmt.Errorf("square/go-jose: unknown curve %s'", raw.Crv)
@@ -232,78 +146,12 @@ func (k *JSONWebKey) UnmarshalJSON(data []byte) (err error) {
err = fmt.Errorf("square/go-jose: unknown json web key type '%s'", raw.Kty)
}
- if err != nil {
- return
- }
-
- if certPub != nil && keyPub != nil {
- if !reflect.DeepEqual(certPub, keyPub) {
- return errors.New("square/go-jose: invalid JWK, public keys in key and x5c fields to not match")
- }
- }
-
- *k = JSONWebKey{Key: key, KeyID: raw.Kid, Algorithm: raw.Alg, Use: raw.Use, Certificates: certs}
-
- k.CertificatesURL = raw.X5u
-
- // x5t parameters are base64url-encoded SHA thumbprints
- // See RFC 7517, Section 4.8, https://tools.ietf.org/html/rfc7517#section-4.8
- x5tSHA1bytes, err := base64.RawURLEncoding.DecodeString(raw.X5tSHA1)
- if err != nil {
- return errors.New("square/go-jose: invalid JWK, x5t header has invalid encoding")
- }
-
- // RFC 7517, Section 4.8 is ambiguous as to whether the digest output should be byte or hex,
- // for this reason, after base64 decoding, if the size is sha1.Size it's likely that the value is a byte encoded
- // checksum so we skip this. Otherwise if the checksum was hex encoded we expect a 40 byte sized array so we'll
- // try to hex decode it. When Marshalling this value we'll always use a base64 encoded version of byte format checksum.
- if len(x5tSHA1bytes) == 2*sha1.Size {
- hx, err := hex.DecodeString(string(x5tSHA1bytes))
- if err != nil {
- return fmt.Errorf("square/go-jose: invalid JWK, unable to hex decode x5t: %v", err)
-
- }
- x5tSHA1bytes = hx
- }
-
- k.CertificateThumbprintSHA1 = x5tSHA1bytes
-
- x5tSHA256bytes, err := base64.RawURLEncoding.DecodeString(raw.X5tSHA256)
- if err != nil {
- return errors.New("square/go-jose: invalid JWK, x5t#S256 header has invalid encoding")
- }
+ if err == nil {
+ *k = JSONWebKey{Key: key, KeyID: raw.Kid, Algorithm: raw.Alg, Use: raw.Use}
- if len(x5tSHA256bytes) == 2*sha256.Size {
- hx256, err := hex.DecodeString(string(x5tSHA256bytes))
+ k.Certificates, err = parseCertificateChain(raw.X5c)
if err != nil {
- return fmt.Errorf("square/go-jose: invalid JWK, unable to hex decode x5t#S256: %v", err)
- }
- x5tSHA256bytes = hx256
- }
-
- k.CertificateThumbprintSHA256 = x5tSHA256bytes
-
- x5tSHA1Len := len(k.CertificateThumbprintSHA1)
- x5tSHA256Len := len(k.CertificateThumbprintSHA256)
- if x5tSHA1Len > 0 && x5tSHA1Len != sha1.Size {
- return errors.New("square/go-jose: invalid JWK, x5t header is of incorrect size")
- }
- if x5tSHA256Len > 0 && x5tSHA256Len != sha256.Size {
- return errors.New("square/go-jose: invalid JWK, x5t#S256 header is of incorrect size")
- }
-
- // If certificate chain *and* thumbprints are set, verify correctness.
- if len(k.Certificates) > 0 {
- leaf := k.Certificates[0]
- sha1sum := sha1.Sum(leaf.Raw)
- sha256sum := sha256.Sum256(leaf.Raw)
-
- if len(k.CertificateThumbprintSHA1) > 0 && !bytes.Equal(sha1sum[:], k.CertificateThumbprintSHA1) {
- return errors.New("square/go-jose: invalid JWK, x5c thumbprint does not match x5t value")
- }
-
- if len(k.CertificateThumbprintSHA256) > 0 && !bytes.Equal(sha256sum[:], k.CertificateThumbprintSHA256) {
- return errors.New("square/go-jose: invalid JWK, x5c thumbprint does not match x5t#S256 value")
+ return fmt.Errorf("failed to unmarshal x5c field: %s", err)
}
}
@@ -382,7 +230,7 @@ func (k *JSONWebKey) Thumbprint(hash crypto.Hash) ([]byte, error) {
case *rsa.PrivateKey:
input, err = rsaThumbprintInput(key.N, key.E)
case ed25519.PrivateKey:
- input, err = edThumbprintInput(ed25519.PublicKey(key[32:]))
+ input, err = edThumbprintInput(ed25519.PublicKey(key[0:32]))
default:
return nil, fmt.Errorf("square/go-jose: unknown key type '%s'", reflect.TypeOf(key))
}
@@ -509,11 +357,11 @@ func (key rawJSONWebKey) ecPublicKey() (*ecdsa.PublicKey, error) {
// the curve specified in the "crv" parameter.
// https://tools.ietf.org/html/rfc7518#section-6.2.1.2
if curveSize(curve) != len(key.X.data) {
- return nil, fmt.Errorf("square/go-jose: invalid EC public key, wrong length for x")
+ return nil, fmt.Errorf("square/go-jose: invalid EC private key, wrong length for x")
}
if curveSize(curve) != len(key.Y.data) {
- return nil, fmt.Errorf("square/go-jose: invalid EC public key, wrong length for y")
+ return nil, fmt.Errorf("square/go-jose: invalid EC private key, wrong length for y")
}
x := key.X.bigInt()
@@ -573,8 +421,8 @@ func (key rawJSONWebKey) edPrivateKey() (ed25519.PrivateKey, error) {
}
privateKey := make([]byte, ed25519.PrivateKeySize)
- copy(privateKey[0:32], key.D.bytes())
- copy(privateKey[32:], key.X.bytes())
+ copy(privateKey[0:32], key.X.bytes())
+ copy(privateKey[32:], key.D.bytes())
rv := ed25519.PrivateKey(privateKey)
return rv, nil
}
@@ -635,9 +483,9 @@ func (key rawJSONWebKey) rsaPrivateKey() (*rsa.PrivateKey, error) {
}
func fromEdPrivateKey(ed ed25519.PrivateKey) (*rawJSONWebKey, error) {
- raw := fromEdPublicKey(ed25519.PublicKey(ed[32:]))
+ raw := fromEdPublicKey(ed25519.PublicKey(ed[0:32]))
- raw.D = newBuffer(ed[0:32])
+ raw.D = newBuffer(ed[32:])
return raw, nil
}
diff --git a/vendor/gopkg.in/square/go-jose.v2/jws.go b/vendor/gopkg.in/square/go-jose.v2/jws.go
index 7e261f937..8b59b6ab2 100644
--- a/vendor/gopkg.in/square/go-jose.v2/jws.go
+++ b/vendor/gopkg.in/square/go-jose.v2/jws.go
@@ -17,7 +17,6 @@
package jose
import (
- "bytes"
"encoding/base64"
"errors"
"fmt"
@@ -76,21 +75,13 @@ type Signature struct {
}
// ParseSigned parses a signed message in compact or full serialization format.
-func ParseSigned(signature string) (*JSONWebSignature, error) {
- signature = stripWhitespace(signature)
- if strings.HasPrefix(signature, "{") {
- return parseSignedFull(signature)
+func ParseSigned(input string) (*JSONWebSignature, error) {
+ input = stripWhitespace(input)
+ if strings.HasPrefix(input, "{") {
+ return parseSignedFull(input)
}
- return parseSignedCompact(signature, nil)
-}
-
-// ParseDetached parses a signed message in compact serialization format with detached payload.
-func ParseDetached(signature string, payload []byte) (*JSONWebSignature, error) {
- if payload == nil {
- return nil, errors.New("square/go-jose: nil payload")
- }
- return parseSignedCompact(stripWhitespace(signature), payload)
+ return parseSignedCompact(input)
}
// Get a header value
@@ -102,39 +93,20 @@ func (sig Signature) mergedHeaders() rawHeader {
}
// Compute data to be signed
-func (obj JSONWebSignature) computeAuthData(payload []byte, signature *Signature) ([]byte, error) {
- var authData bytes.Buffer
-
- protectedHeader := new(rawHeader)
+func (obj JSONWebSignature) computeAuthData(payload []byte, signature *Signature) []byte {
+ var serializedProtected string
if signature.original != nil && signature.original.Protected != nil {
- if err := json.Unmarshal(signature.original.Protected.bytes(), protectedHeader); err != nil {
- return nil, err
- }
- authData.WriteString(signature.original.Protected.base64())
+ serializedProtected = signature.original.Protected.base64()
} else if signature.protected != nil {
- protectedHeader = signature.protected
- authData.WriteString(base64.RawURLEncoding.EncodeToString(mustSerializeJSON(protectedHeader)))
- }
-
- needsBase64 := true
-
- if protectedHeader != nil {
- var err error
- if needsBase64, err = protectedHeader.getB64(); err != nil {
- needsBase64 = true
- }
- }
-
- authData.WriteByte('.')
-
- if needsBase64 {
- authData.WriteString(base64.RawURLEncoding.EncodeToString(payload))
+ serializedProtected = base64.RawURLEncoding.EncodeToString(mustSerializeJSON(signature.protected))
} else {
- authData.Write(payload)
+ serializedProtected = ""
}
- return authData.Bytes(), nil
+ return []byte(fmt.Sprintf("%s.%s",
+ serializedProtected,
+ base64.RawURLEncoding.EncodeToString(payload)))
}
// parseSignedFull parses a message in full format.
@@ -274,26 +246,20 @@ func (parsed *rawJSONWebSignature) sanitized() (*JSONWebSignature, error) {
}
// parseSignedCompact parses a message in compact format.
-func parseSignedCompact(input string, payload []byte) (*JSONWebSignature, error) {
+func parseSignedCompact(input string) (*JSONWebSignature, error) {
parts := strings.Split(input, ".")
if len(parts) != 3 {
return nil, fmt.Errorf("square/go-jose: compact JWS format must have three parts")
}
- if parts[1] != "" && payload != nil {
- return nil, fmt.Errorf("square/go-jose: payload is not detached")
- }
-
rawProtected, err := base64.RawURLEncoding.DecodeString(parts[0])
if err != nil {
return nil, err
}
- if payload == nil {
- payload, err = base64.RawURLEncoding.DecodeString(parts[1])
- if err != nil {
- return nil, err
- }
+ payload, err := base64.RawURLEncoding.DecodeString(parts[1])
+ if err != nil {
+ return nil, err
}
signature, err := base64.RawURLEncoding.DecodeString(parts[2])
@@ -309,30 +275,19 @@ func parseSignedCompact(input string, payload []byte) (*JSONWebSignature, error)
return raw.sanitized()
}
-func (obj JSONWebSignature) compactSerialize(detached bool) (string, error) {
+// CompactSerialize serializes an object using the compact serialization format.
+func (obj JSONWebSignature) CompactSerialize() (string, error) {
if len(obj.Signatures) != 1 || obj.Signatures[0].header != nil || obj.Signatures[0].protected == nil {
return "", ErrNotSupported
}
- serializedProtected := base64.RawURLEncoding.EncodeToString(mustSerializeJSON(obj.Signatures[0].protected))
- payload := ""
- signature := base64.RawURLEncoding.EncodeToString(obj.Signatures[0].Signature)
-
- if !detached {
- payload = base64.RawURLEncoding.EncodeToString(obj.payload)
- }
-
- return fmt.Sprintf("%s.%s.%s", serializedProtected, payload, signature), nil
-}
-
-// CompactSerialize serializes an object using the compact serialization format.
-func (obj JSONWebSignature) CompactSerialize() (string, error) {
- return obj.compactSerialize(false)
-}
+ serializedProtected := mustSerializeJSON(obj.Signatures[0].protected)
-// DetachedCompactSerialize serializes an object using the compact serialization format with detached payload.
-func (obj JSONWebSignature) DetachedCompactSerialize() (string, error) {
- return obj.compactSerialize(true)
+ return fmt.Sprintf(
+ "%s.%s.%s",
+ base64.RawURLEncoding.EncodeToString(serializedProtected),
+ base64.RawURLEncoding.EncodeToString(obj.payload),
+ base64.RawURLEncoding.EncodeToString(obj.Signatures[0].Signature)), nil
}
// FullSerialize serializes an object using the full JSON serialization format.
diff --git a/vendor/gopkg.in/square/go-jose.v2/jwt/claims.go b/vendor/gopkg.in/square/go-jose.v2/jwt/claims.go
index 30fbe1cdc..31274b006 100644
--- a/vendor/gopkg.in/square/go-jose.v2/jwt/claims.go
+++ b/vendor/gopkg.in/square/go-jose.v2/jwt/claims.go
@@ -26,13 +26,13 @@ import (
// Claims represents public claim values (as specified in RFC 7519).
type Claims struct {
- Issuer string `json:"iss,omitempty"`
- Subject string `json:"sub,omitempty"`
- Audience Audience `json:"aud,omitempty"`
- Expiry *NumericDate `json:"exp,omitempty"`
- NotBefore *NumericDate `json:"nbf,omitempty"`
- IssuedAt *NumericDate `json:"iat,omitempty"`
- ID string `json:"jti,omitempty"`
+ Issuer string `json:"iss,omitempty"`
+ Subject string `json:"sub,omitempty"`
+ Audience Audience `json:"aud,omitempty"`
+ Expiry NumericDate `json:"exp,omitempty"`
+ NotBefore NumericDate `json:"nbf,omitempty"`
+ IssuedAt NumericDate `json:"iat,omitempty"`
+ ID string `json:"jti,omitempty"`
}
// NumericDate represents date and time as the number of seconds since the
@@ -41,17 +41,16 @@ type Claims struct {
type NumericDate int64
// NewNumericDate constructs NumericDate from time.Time value.
-func NewNumericDate(t time.Time) *NumericDate {
+func NewNumericDate(t time.Time) NumericDate {
if t.IsZero() {
- return nil
+ return NumericDate(0)
}
// While RFC 7519 technically states that NumericDate values may be
// non-integer values, we don't bother serializing timestamps in
// claims with sub-second accurancy and just round to the nearest
// second instead. Not convined sub-second accuracy is useful here.
- out := NumericDate(t.Unix())
- return &out
+ return NumericDate(t.Unix())
}
// MarshalJSON serializes the given NumericDate into its JSON representation.
@@ -73,14 +72,11 @@ func (n *NumericDate) UnmarshalJSON(b []byte) error {
}
// Time returns time.Time representation of NumericDate.
-func (n *NumericDate) Time() time.Time {
- if n == nil {
- return time.Time{}
- }
- return time.Unix(int64(*n), 0)
+func (n NumericDate) Time() time.Time {
+ return time.Unix(int64(n), 0)
}
-// Audience represents the recipients that the token is intended for.
+// Audience represents the recipents that the token is intended for.
type Audience []string
// UnmarshalJSON reads an audience from its JSON representation.
diff --git a/vendor/gopkg.in/square/go-jose.v2/jwt/errors.go b/vendor/gopkg.in/square/go-jose.v2/jwt/errors.go
index 09f76ae4b..6507dfb28 100644
--- a/vendor/gopkg.in/square/go-jose.v2/jwt/errors.go
+++ b/vendor/gopkg.in/square/go-jose.v2/jwt/errors.go
@@ -46,8 +46,5 @@ var ErrNotValidYet = errors.New("square/go-jose/jwt: validation failed, token no
// ErrExpired indicates that token is used after expiry time indicated in exp claim.
var ErrExpired = errors.New("square/go-jose/jwt: validation failed, token is expired (exp)")
-// ErrIssuedInTheFuture indicates that the iat field is in the future.
-var ErrIssuedInTheFuture = errors.New("square/go-jose/jwt: validation field, token issued in the future (iat)")
-
-// ErrInvalidContentType indicates that token requires JWT cty header.
+// ErrInvalidContentType indicated that token requires JWT cty header.
var ErrInvalidContentType = errors.New("square/go-jose/jwt: expected content type to be JWT (cty header)")
diff --git a/vendor/gopkg.in/square/go-jose.v2/jwt/jwt.go b/vendor/gopkg.in/square/go-jose.v2/jwt/jwt.go
index aa13d4f0e..4ce9779a7 100644
--- a/vendor/gopkg.in/square/go-jose.v2/jwt/jwt.go
+++ b/vendor/gopkg.in/square/go-jose.v2/jwt/jwt.go
@@ -19,10 +19,9 @@ package jwt
import (
"fmt"
- "strings"
-
- jose "gopkg.in/square/go-jose.v2"
+ "gopkg.in/square/go-jose.v2"
"gopkg.in/square/go-jose.v2/json"
+ "strings"
)
// JSONWebToken represents a JSON Web Token (as specified in RFC7519).
@@ -39,9 +38,7 @@ type NestedJSONWebToken struct {
// Claims deserializes a JSONWebToken into dest using the provided key.
func (t *JSONWebToken) Claims(key interface{}, dest ...interface{}) error {
- payloadKey := tryJWKS(t.Headers, key)
-
- b, err := t.payload(payloadKey)
+ b, err := t.payload(key)
if err != nil {
return err
}
@@ -72,9 +69,7 @@ func (t *JSONWebToken) UnsafeClaimsWithoutVerification(dest ...interface{}) erro
}
func (t *NestedJSONWebToken) Decrypt(decryptionKey interface{}) (*JSONWebToken, error) {
- key := tryJWKS(t.Headers, decryptionKey)
-
- b, err := t.enc.Decrypt(key)
+ b, err := t.enc.Decrypt(decryptionKey)
if err != nil {
return nil, err
}
@@ -135,29 +130,3 @@ func ParseSignedAndEncrypted(s string) (*NestedJSONWebToken, error) {
Headers: []jose.Header{enc.Header},
}, nil
}
-
-func tryJWKS(headers []jose.Header, key interface{}) interface{} {
- jwks, ok := key.(*jose.JSONWebKeySet)
- if !ok {
- return key
- }
-
- var kid string
- for _, header := range headers {
- if header.KeyID != "" {
- kid = header.KeyID
- break
- }
- }
-
- if kid == "" {
- return key
- }
-
- keys := jwks.Key(kid)
- if len(keys) == 0 {
- return key
- }
-
- return keys[0].Key
-}
diff --git a/vendor/gopkg.in/square/go-jose.v2/jwt/validation.go b/vendor/gopkg.in/square/go-jose.v2/jwt/validation.go
index 6f3ff4e80..d638811d3 100644
--- a/vendor/gopkg.in/square/go-jose.v2/jwt/validation.go
+++ b/vendor/gopkg.in/square/go-jose.v2/jwt/validation.go
@@ -35,7 +35,7 @@ type Expected struct {
Audience Audience
// ID matches the "jti" claim exactly.
ID string
- // Time matches the "exp", "nbf" and "iat" claims with leeway.
+ // Time matches the "exp" and "nbf" claims with leeway.
Time time.Time
}
@@ -94,20 +94,12 @@ func (c Claims) ValidateWithLeeway(e Expected, leeway time.Duration) error {
}
}
- if !e.Time.IsZero() {
- if c.NotBefore != nil && e.Time.Add(leeway).Before(c.NotBefore.Time()) {
- return ErrNotValidYet
- }
-
- if c.Expiry != nil && e.Time.Add(-leeway).After(c.Expiry.Time()) {
- return ErrExpired
- }
+ if !e.Time.IsZero() && e.Time.Add(leeway).Before(c.NotBefore.Time()) {
+ return ErrNotValidYet
+ }
- // IssuedAt is optional but cannot be in the future. This is not required by the RFC, but
- // something is misconfigured if this happens and we should not trust it.
- if c.IssuedAt != nil && e.Time.Add(leeway).Before(c.IssuedAt.Time()) {
- return ErrIssuedInTheFuture
- }
+ if !e.Time.IsZero() && e.Time.Add(-leeway).After(c.Expiry.Time()) {
+ return ErrExpired
}
return nil
diff --git a/vendor/gopkg.in/square/go-jose.v2/opaque.go b/vendor/gopkg.in/square/go-jose.v2/opaque.go
index df747f992..4a8bd8f32 100644
--- a/vendor/gopkg.in/square/go-jose.v2/opaque.go
+++ b/vendor/gopkg.in/square/go-jose.v2/opaque.go
@@ -81,64 +81,3 @@ type opaqueVerifier struct {
func (o *opaqueVerifier) verifyPayload(payload []byte, signature []byte, alg SignatureAlgorithm) error {
return o.verifier.VerifyPayload(payload, signature, alg)
}
-
-// OpaqueKeyEncrypter is an interface that supports encrypting keys with an opaque key.
-type OpaqueKeyEncrypter interface {
- // KeyID returns the kid
- KeyID() string
- // Algs returns a list of supported key encryption algorithms.
- Algs() []KeyAlgorithm
- // encryptKey encrypts the CEK using the given algorithm.
- encryptKey(cek []byte, alg KeyAlgorithm) (recipientInfo, error)
-}
-
-type opaqueKeyEncrypter struct {
- encrypter OpaqueKeyEncrypter
-}
-
-func newOpaqueKeyEncrypter(alg KeyAlgorithm, encrypter OpaqueKeyEncrypter) (recipientKeyInfo, error) {
- var algSupported bool
- for _, salg := range encrypter.Algs() {
- if alg == salg {
- algSupported = true
- break
- }
- }
- if !algSupported {
- return recipientKeyInfo{}, ErrUnsupportedAlgorithm
- }
-
- return recipientKeyInfo{
- keyID: encrypter.KeyID(),
- keyAlg: alg,
- keyEncrypter: &opaqueKeyEncrypter{
- encrypter: encrypter,
- },
- }, nil
-}
-
-func (oke *opaqueKeyEncrypter) encryptKey(cek []byte, alg KeyAlgorithm) (recipientInfo, error) {
- return oke.encrypter.encryptKey(cek, alg)
-}
-
-//OpaqueKeyDecrypter is an interface that supports decrypting keys with an opaque key.
-type OpaqueKeyDecrypter interface {
- DecryptKey(encryptedKey []byte, header Header) ([]byte, error)
-}
-
-type opaqueKeyDecrypter struct {
- decrypter OpaqueKeyDecrypter
-}
-
-func (okd *opaqueKeyDecrypter) decryptKey(headers rawHeader, recipient *recipientInfo, generator keyGenerator) ([]byte, error) {
- mergedHeaders := rawHeader{}
- mergedHeaders.merge(&headers)
- mergedHeaders.merge(recipient.header)
-
- header, err := mergedHeaders.sanitized()
- if err != nil {
- return nil, err
- }
-
- return okd.decrypter.DecryptKey(recipient.encryptedKey, header)
-}
diff --git a/vendor/gopkg.in/square/go-jose.v2/shared.go b/vendor/gopkg.in/square/go-jose.v2/shared.go
index f8438641f..b0a6255ec 100644
--- a/vendor/gopkg.in/square/go-jose.v2/shared.go
+++ b/vendor/gopkg.in/square/go-jose.v2/shared.go
@@ -153,18 +153,12 @@ const (
headerJWK = "jwk" // *JSONWebKey
headerKeyID = "kid" // string
headerNonce = "nonce" // string
- headerB64 = "b64" // bool
headerP2C = "p2c" // *byteBuffer (int)
headerP2S = "p2s" // *byteBuffer ([]byte)
)
-// supportedCritical is the set of supported extensions that are understood and processed.
-var supportedCritical = map[string]bool{
- headerB64: true,
-}
-
// rawHeader represents the JOSE header for JWE/JWS objects (used for parsing).
//
// The decoding of the constituent items is deferred because we want to marshal
@@ -355,21 +349,6 @@ func (parsed rawHeader) getP2S() (*byteBuffer, error) {
return parsed.getByteBuffer(headerP2S)
}
-// getB64 extracts parsed "b64" from the raw JSON, defaulting to true.
-func (parsed rawHeader) getB64() (bool, error) {
- v := parsed[headerB64]
- if v == nil {
- return true, nil
- }
-
- var b64 bool
- err := json.Unmarshal(*v, &b64)
- if err != nil {
- return true, err
- }
- return b64, nil
-}
-
// sanitized produces a cleaned-up header object from the raw JSON.
func (parsed rawHeader) sanitized() (h Header, err error) {
for k, v := range parsed {
diff --git a/vendor/gopkg.in/square/go-jose.v2/signing.go b/vendor/gopkg.in/square/go-jose.v2/signing.go
index bad820cea..be6cf0481 100644
--- a/vendor/gopkg.in/square/go-jose.v2/signing.go
+++ b/vendor/gopkg.in/square/go-jose.v2/signing.go
@@ -17,7 +17,6 @@
package jose
import (
- "bytes"
"crypto/ecdsa"
"crypto/rsa"
"encoding/base64"
@@ -78,27 +77,6 @@ func (so *SignerOptions) WithType(typ ContentType) *SignerOptions {
return so.WithHeader(HeaderType, typ)
}
-// WithCritical adds the given names to the critical ("crit") header and returns
-// the updated SignerOptions.
-func (so *SignerOptions) WithCritical(names ...string) *SignerOptions {
- if so.ExtraHeaders[headerCritical] == nil {
- so.WithHeader(headerCritical, make([]string, 0, len(names)))
- }
- crit := so.ExtraHeaders[headerCritical].([]string)
- so.ExtraHeaders[headerCritical] = append(crit, names...)
- return so
-}
-
-// WithBase64 adds a base64url-encode payload ("b64") header and returns the updated
-// SignerOptions. When the "b64" value is "false", the payload is not base64 encoded.
-func (so *SignerOptions) WithBase64(b64 bool) *SignerOptions {
- if !b64 {
- so.WithHeader(headerB64, b64)
- so.WithCritical(headerB64)
- }
- return so
-}
-
type payloadSigner interface {
signPayload(payload []byte, alg SignatureAlgorithm) (Signature, error)
}
@@ -255,10 +233,7 @@ func (ctx *genericSigner) Sign(payload []byte) (*JSONWebSignature, error) {
if ctx.embedJWK {
protected[headerJWK] = recipient.publicKey()
} else {
- keyID := recipient.publicKey().KeyID
- if keyID != "" {
- protected[headerKeyID] = keyID
- }
+ protected[headerKeyID] = recipient.publicKey().KeyID
}
}
@@ -275,26 +250,12 @@ func (ctx *genericSigner) Sign(payload []byte) (*JSONWebSignature, error) {
}
serializedProtected := mustSerializeJSON(protected)
- needsBase64 := true
-
- if b64, ok := protected[headerB64]; ok {
- if needsBase64, ok = b64.(bool); !ok {
- return nil, errors.New("square/go-jose: Invalid b64 header parameter")
- }
- }
-
- var input bytes.Buffer
- input.WriteString(base64.RawURLEncoding.EncodeToString(serializedProtected))
- input.WriteByte('.')
+ input := []byte(fmt.Sprintf("%s.%s",
+ base64.RawURLEncoding.EncodeToString(serializedProtected),
+ base64.RawURLEncoding.EncodeToString(payload)))
- if needsBase64 {
- input.WriteString(base64.RawURLEncoding.EncodeToString(payload))
- } else {
- input.Write(payload)
- }
-
- signatureInfo, err := recipient.signer.signPayload(input.Bytes(), recipient.sigAlg)
+ signatureInfo, err := recipient.signer.signPayload(input, recipient.sigAlg)
if err != nil {
return nil, err
}
@@ -363,18 +324,12 @@ func (obj JSONWebSignature) DetachedVerify(payload []byte, verificationKey inter
if err != nil {
return err
}
-
- for _, name := range critical {
- if !supportedCritical[name] {
- return ErrCryptoFailure
- }
- }
-
- input, err := obj.computeAuthData(payload, &signature)
- if err != nil {
+ if len(critical) > 0 {
+ // Unsupported crit header
return ErrCryptoFailure
}
+ input := obj.computeAuthData(payload, &signature)
alg := headers.getSignatureAlgorithm()
err = verifier.verifyPayload(input, signature.Signature, alg)
if err == nil {
@@ -411,25 +366,18 @@ func (obj JSONWebSignature) DetachedVerifyMulti(payload []byte, verificationKey
return -1, Signature{}, err
}
-outer:
for i, signature := range obj.Signatures {
headers := signature.mergedHeaders()
critical, err := headers.getCritical()
if err != nil {
continue
}
-
- for _, name := range critical {
- if !supportedCritical[name] {
- continue outer
- }
- }
-
- input, err := obj.computeAuthData(payload, &signature)
- if err != nil {
+ if len(critical) > 0 {
+ // Unsupported crit header
continue
}
+ input := obj.computeAuthData(payload, &signature)
alg := headers.getSignatureAlgorithm()
err = verifier.verifyPayload(input, signature.Signature, alg)
if err == nil {
diff --git a/vendor/modules.txt b/vendor/modules.txt
index a638e29c4..5adaf93b7 100644
--- a/vendor/modules.txt
+++ b/vendor/modules.txt
@@ -1301,7 +1301,7 @@ gopkg.in/inf.v0
# gopkg.in/natefinch/lumberjack.v2 v2.0.0
## explicit
gopkg.in/natefinch/lumberjack.v2
-# gopkg.in/square/go-jose.v2 v2.5.1
+# gopkg.in/square/go-jose.v2 v2.5.1 => gopkg.in/square/go-jose.v2 v2.2.2
## explicit
gopkg.in/square/go-jose.v2
gopkg.in/square/go-jose.v2/cipher
@@ -2648,6 +2648,7 @@ sigs.k8s.io/yaml
# go.etcd.io/etcd/pkg/v3 => go.etcd.io/etcd/pkg/v3 v3.5.0
# go.etcd.io/etcd/raft/v3 => go.etcd.io/etcd/raft/v3 v3.5.0
# go.etcd.io/etcd/server/v3 => go.etcd.io/etcd/server/v3 v3.5.0
+# gopkg.in/square/go-jose.v2 => gopkg.in/square/go-jose.v2 v2.2.2
# k8s.io/api => github.com/kubeedge/kubernetes/staging/src/k8s.io/api v1.23.15-kubeedge1
# k8s.io/apiextensions-apiserver => github.com/kubeedge/kubernetes/staging/src/k8s.io/apiextensions-apiserver v1.23.15-kubeedge1
# k8s.io/apimachinery => github.com/kubeedge/kubernetes/staging/src/k8s.io/apimachinery v1.23.15-kubeedge1