pomerium/authorize/evaluator
Kenneth Jenkins 9d4d31cb4f
authorize: implement client certificate CRL check (#4439)
Update isValidClientCertificate() to also consult the configured
certificate revocation lists. Update existing test cases and add a new
unit test to exercise the revocation support. Restore the skipped
integration test case.

Generate new test certificates and CRLs using a new `go run`-able source
file.
2023-08-03 15:59:11 -07:00
..
opa authorize: remove JWT timestamp format workaround (#4321) 2023-06-30 11:54:46 -07:00
config.go authorize: implement client certificate CRL check (#4439) 2023-08-03 15:59:11 -07:00
evaluator.go authorize: implement client certificate CRL check (#4439) 2023-08-03 15:59:11 -07:00
evaluator_test.go authorize: implement client certificate CRL check (#4439) 2023-08-03 15:59:11 -07:00
functions.go authorize: implement client certificate CRL check (#4439) 2023-08-03 15:59:11 -07:00
functions_test.go authorize: implement client certificate CRL check (#4439) 2023-08-03 15:59:11 -07:00
gen-test-certs.go authorize: implement client certificate CRL check (#4439) 2023-08-03 15:59:11 -07:00
google_cloud_serverless.go config: remove source, remove deadcode, fix linting issues (#4118) 2023-04-21 17:25:11 -06:00
google_cloud_serverless_test.go authorize: move headers and jwt signing to rego (#1856) 2021-02-08 10:53:21 -07:00
headers_evaluator.go config: add support for $pomerium.id_token and $pomerium.access_token in set_request_headers (#4219) 2023-06-01 16:00:02 -06:00
headers_evaluator_test.go authorize: remove JWT timestamp format workaround (#4321) 2023-06-30 11:54:46 -07:00
policy_evaluator.go authorize: omit client cert rule when not needed (#4386) 2023-07-24 15:27:57 -07:00
policy_evaluator_test.go authorize: add "client-certificate-required" reason (#4389) 2023-07-25 10:03:51 -07:00