style: collapse nested if-let in JWT secret config (clippy)
This commit is contained in:
+26
-29
@@ -604,30 +604,31 @@ impl AppConfig {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Auth configuration
|
// Auth configuration
|
||||||
if let Ok(jwt_secret) = env::var("OXICLOUD_JWT_SECRET") {
|
if let Some(jwt_secret) = env::var("OXICLOUD_JWT_SECRET")
|
||||||
if !jwt_secret.is_empty() {
|
.ok()
|
||||||
// SECURITY: Validate JWT secret minimum entropy (RFC 7518 §3.2
|
.filter(|s| !s.is_empty())
|
||||||
// recommends ≥256 bits for HS256). Panic on dangerously short
|
{
|
||||||
// secrets, warn on sub-optimal ones.
|
// SECURITY: Validate JWT secret minimum entropy (RFC 7518 §3.2
|
||||||
let len = jwt_secret.len();
|
// recommends ≥256 bits for HS256). Panic on dangerously short
|
||||||
if config.features.enable_auth && len < 16 {
|
// secrets, warn on sub-optimal ones.
|
||||||
panic!(
|
let len = jwt_secret.len();
|
||||||
"FATAL: OXICLOUD_JWT_SECRET is dangerously short ({} bytes). \
|
if config.features.enable_auth && len < 16 {
|
||||||
Minimum: 32 bytes (256 bits) for HS256. \
|
panic!(
|
||||||
Generate a secure secret with: openssl rand -hex 32",
|
"FATAL: OXICLOUD_JWT_SECRET is dangerously short ({} bytes). \
|
||||||
len
|
Minimum: 32 bytes (256 bits) for HS256. \
|
||||||
);
|
Generate a secure secret with: openssl rand -hex 32",
|
||||||
} else if config.features.enable_auth && len < 32 {
|
len
|
||||||
tracing::warn!("==========================================================");
|
);
|
||||||
tracing::warn!(
|
} else if config.features.enable_auth && len < 32 {
|
||||||
"OXICLOUD_JWT_SECRET is only {} bytes — recommended minimum is 32 (256 bits).",
|
tracing::warn!("==========================================================");
|
||||||
len
|
tracing::warn!(
|
||||||
);
|
"OXICLOUD_JWT_SECRET is only {} bytes — recommended minimum is 32 (256 bits).",
|
||||||
tracing::warn!("Generate a stronger secret with: openssl rand -hex 32");
|
len
|
||||||
tracing::warn!("==========================================================");
|
);
|
||||||
}
|
tracing::warn!("Generate a stronger secret with: openssl rand -hex 32");
|
||||||
config.auth.jwt_secret = jwt_secret;
|
tracing::warn!("==========================================================");
|
||||||
}
|
}
|
||||||
|
config.auth.jwt_secret = jwt_secret;
|
||||||
}
|
}
|
||||||
|
|
||||||
// SECURITY: Auto-persist JWT secret to storage so it survives restarts.
|
// SECURITY: Auto-persist JWT secret to storage so it survives restarts.
|
||||||
@@ -642,10 +643,7 @@ impl AppConfig {
|
|||||||
let persisted = persisted.trim().to_string();
|
let persisted = persisted.trim().to_string();
|
||||||
if persisted.len() >= 32 {
|
if persisted.len() >= 32 {
|
||||||
config.auth.jwt_secret = persisted;
|
config.auth.jwt_secret = persisted;
|
||||||
tracing::info!(
|
tracing::info!("JWT secret loaded from {}", secret_file.display());
|
||||||
"JWT secret loaded from {}",
|
|
||||||
secret_file.display()
|
|
||||||
);
|
|
||||||
} else {
|
} else {
|
||||||
tracing::warn!(
|
tracing::warn!(
|
||||||
"Persisted JWT secret too short ({}B), regenerating",
|
"Persisted JWT secret too short ({}B), regenerating",
|
||||||
@@ -664,8 +662,7 @@ impl AppConfig {
|
|||||||
use rand_core::{OsRng, RngCore};
|
use rand_core::{OsRng, RngCore};
|
||||||
let mut key = [0u8; 32];
|
let mut key = [0u8; 32];
|
||||||
OsRng.fill_bytes(&mut key);
|
OsRng.fill_bytes(&mut key);
|
||||||
let generated_secret: String =
|
let generated_secret: String = key.iter().map(|b| format!("{:02x}", b)).collect();
|
||||||
key.iter().map(|b| format!("{:02x}", b)).collect();
|
|
||||||
|
|
||||||
// Persist to storage volume so it survives container restarts
|
// Persist to storage volume so it survives container restarts
|
||||||
if let Err(e) = std::fs::write(&secret_file, &generated_secret) {
|
if let Err(e) = std::fs::write(&secret_file, &generated_secret) {
|
||||||
|
|||||||
@@ -612,7 +612,6 @@ impl AppServiceFactory {
|
|||||||
path_resolver: None,
|
path_resolver: None,
|
||||||
webdav_lock_store:
|
webdav_lock_store:
|
||||||
crate::infrastructure::services::webdav_lock_service::create_webdav_lock_store(),
|
crate::infrastructure::services::webdav_lock_service::create_webdav_lock_store(),
|
||||||
|
|
||||||
};
|
};
|
||||||
|
|
||||||
// 9b. Wire admin settings service when auth is available
|
// 9b. Wire admin settings service when auth is available
|
||||||
@@ -893,7 +892,6 @@ pub struct AppState {
|
|||||||
Option<Arc<crate::infrastructure::services::path_resolver_service::PathResolverService>>,
|
Option<Arc<crate::infrastructure::services::path_resolver_service::PathResolverService>>,
|
||||||
pub webdav_lock_store:
|
pub webdav_lock_store:
|
||||||
Arc<crate::infrastructure::services::webdav_lock_service::WebDavLockStore>,
|
Arc<crate::infrastructure::services::webdav_lock_service::WebDavLockStore>,
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// All AppState construction is done via struct literal in build_app_state().
|
// All AppState construction is done via struct literal in build_app_state().
|
||||||
|
|||||||
Reference in New Issue
Block a user