Skip to content

Commit 20a980b

Browse files
authored
Merge branch 'master' into dependabot/go_modules/google.golang.org/grpc-1.79.2
2 parents 155b8eb + 01c8796 commit 20a980b

File tree

27 files changed

+53
-53
lines changed

27 files changed

+53
-53
lines changed

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ You can use `step-ca` to:
2929

3030
As you design your PKI, if you need any of the following, [consider our commerical CA](http://smallstep.com):
3131
- Multiple certificate authorities
32-
- Active revocation (CRL, OSCP)
32+
- Active revocation (CRL, OCSP)
3333
- Turnkey high-volume, high availability CA
3434
- An API for seamless IaC management of your PKI
3535
- Integrated support for SCEP & NDES, for migrating from legacy Active Directory Certificate Services deployments

acme/challenge.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -531,7 +531,7 @@ func validateWireOIDCClaims(o *wireprovisioner.OIDCOptions, token *oidc.IDToken,
531531

532532
type wireDpopPayload struct {
533533
// AccessToken is the token generated by wire-server
534-
AccessToken string `json:"access_token"` //nolint:gosec // field name required by Wire protocol
534+
AccessToken string `json:"access_token"`
535535
}
536536

537537
func wireDPOP01Validate(ctx context.Context, ch *Challenge, db WireDB, accountJWK *jose.JSONWebKey, payload []byte) error {
@@ -1618,7 +1618,7 @@ func uitoa(val uint) string {
16181618
val = v
16191619
}
16201620
// val < 10
1621-
buf[i] = byte('0' + val) //nolint:gosec // val is always 0-9 here
1621+
buf[i] = byte('0' + val)
16221622
return string(buf[i:])
16231623
}
16241624

api/crl.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,6 @@ func CRL(w http.ResponseWriter, r *http.Request) {
4141
} else {
4242
w.Header().Add("Content-Type", "application/pkix-crl")
4343
w.Header().Add("Content-Disposition", "attachment; filename=\"crl.der\"")
44-
w.Write(crlInfo.Data) //nolint:gosec // writing CRL binary data
44+
w.Write(crlInfo.Data)
4545
}
4646
}

authority/admin/db/nosql/provisioner.go

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,16 +29,16 @@ type dbProvisioner struct {
2929

3030
type dbBasicAuth struct {
3131
Username string `json:"username"`
32-
Password string `json:"password"` //nolint:gosec // field name for database storage
32+
Password string `json:"password"`
3333
}
3434

3535
type dbWebhook struct {
3636
Name string `json:"name"`
3737
ID string `json:"id"`
3838
URL string `json:"url"`
3939
Kind string `json:"kind"`
40-
Secret string `json:"secret"` //nolint:gosec // field name for database storage
41-
BearerToken string `json:"bearerToken,omitempty"` //nolint:gosec // field name for database storage
40+
Secret string `json:"secret"`
41+
BearerToken string `json:"bearerToken,omitempty"`
4242
BasicAuth *dbBasicAuth `json:"basicAuth,omitempty"`
4343
DisableTLSClientAuth bool `json:"disableTLSClientAuth,omitempty"`
4444
CertType string `json:"certType,omitempty"`

authority/config/config.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -79,7 +79,7 @@ type Config struct {
7979
Monitoring json.RawMessage `json:"monitoring,omitempty"`
8080
AuthorityConfig *AuthConfig `json:"authority,omitempty"`
8181
TLS *TLSOptions `json:"tls,omitempty"`
82-
Password string `json:"password,omitempty"` //nolint:gosec // field name for CA configuration
82+
Password string `json:"password,omitempty"`
8383
Templates *templates.Templates `json:"templates,omitempty"`
8484
CommonName string `json:"commonName,omitempty"`
8585
CRL *CRLConfig `json:"crl,omitempty"`
@@ -263,7 +263,7 @@ func (c *Config) Save(filename string) error {
263263
var b bytes.Buffer
264264
enc := json.NewEncoder(&b)
265265
enc.SetIndent("", "\t")
266-
if err := enc.Encode(c); err != nil {
266+
if err := enc.Encode(c); err != nil { //nolint:gosec // config struct contains password field by design
267267
return fmt.Errorf("error encoding configuration: %w", err)
268268
}
269269
if err := os.WriteFile(filename, b.Bytes(), 0600); err != nil {

authority/provisioner/aws.go

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -469,7 +469,7 @@ func (p *AWS) readURLv1(url string) (*http.Response, error) {
469469
if err != nil {
470470
return nil, err
471471
}
472-
resp, err := client.Do(req) //nolint:gosec // request to AWS metadata service
472+
resp, err := client.Do(req)
473473
if err != nil {
474474
return nil, err
475475
}
@@ -485,7 +485,7 @@ func (p *AWS) readURLv2(url string) (*http.Response, error) {
485485
return nil, err
486486
}
487487
req.Header.Set(awsMetadataTokenTTLHeader, p.config.tokenTTL)
488-
resp, err := client.Do(req) //nolint:gosec // request to AWS metadata service
488+
resp, err := client.Do(req)
489489
if err != nil {
490490
return nil, err
491491
}
@@ -504,7 +504,7 @@ func (p *AWS) readURLv2(url string) (*http.Response, error) {
504504
return nil, err
505505
}
506506
req.Header.Set(awsMetadataTokenHeader, string(token))
507-
resp, err = client.Do(req) //nolint:gosec // request to AWS metadata service
507+
resp, err = client.Do(req)
508508
if err != nil {
509509
return nil, err
510510
}

authority/provisioner/azure.go

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -66,8 +66,8 @@ func newAzureConfig(tenantID string) *azureConfig {
6666
}
6767

6868
type azureIdentityToken struct {
69-
AccessToken string `json:"access_token"` //nolint:gosec // field name required by Azure API
70-
RefreshToken string `json:"refresh_token"` //nolint:gosec // field name required by Azure API
69+
AccessToken string `json:"access_token"`
70+
RefreshToken string `json:"refresh_token"`
7171
ClientID string `json:"client_id"`
7272
ExpiresIn int64 `json:"expires_in,string"`
7373
ExpiresOn int64 `json:"expires_on,string"`
@@ -212,7 +212,7 @@ func (p *Azure) GetIdentityToken(subject, caURL string) (string, error) {
212212
query.Add("api-version", azureIdentityTokenAPIVersion)
213213
req.URL.RawQuery = query.Encode()
214214

215-
resp, err := http.DefaultClient.Do(req) //nolint:gosec // request to Azure metadata service
215+
resp, err := http.DefaultClient.Do(req)
216216
if err != nil {
217217
return "", errors.Wrap(err, "error getting identity token, are you in a Azure VM?")
218218
}
@@ -510,7 +510,7 @@ func (p *Azure) getAzureEnvironment() (string, error) {
510510
query.Add("api-version", "2021-02-01")
511511
req.URL.RawQuery = query.Encode()
512512

513-
resp, err := http.DefaultClient.Do(req) //nolint:gosec // request to Azure metadata service
513+
resp, err := http.DefaultClient.Do(req)
514514
if err != nil {
515515
return "", errors.Wrap(err, "error getting azure instance environment, are you in a Azure VM?")
516516
}

authority/provisioner/gcp.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -199,7 +199,7 @@ func (p *GCP) GetIdentityToken(subject, caURL string) (string, error) {
199199
return "", errors.Wrap(err, "error creating identity request")
200200
}
201201
req.Header.Set("Metadata-Flavor", "Google")
202-
resp, err := http.DefaultClient.Do(req) //nolint:gosec // request to GCP metadata service
202+
resp, err := http.DefaultClient.Do(req)
203203
if err != nil {
204204
return "", errors.Wrap(err, "error doing identity request, are you in a GCP VM?")
205205
}

authority/provisioner/k8sSA.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ const (
3636
type k8sSAPayload struct {
3737
jose.Claims
3838
Namespace string `json:"kubernetes.io/serviceaccount/namespace,omitempty"`
39-
SecretName string `json:"kubernetes.io/serviceaccount/secret.name,omitempty"` //nolint:gosec // field name required by Kubernetes API
39+
SecretName string `json:"kubernetes.io/serviceaccount/secret.name,omitempty"`
4040
ServiceAccountName string `json:"kubernetes.io/serviceaccount/service-account.name,omitempty"`
4141
ServiceAccountUID string `json:"kubernetes.io/serviceaccount/service-account.uid,omitempty"`
4242
}

authority/provisioner/oidc.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -84,7 +84,7 @@ type OIDC struct {
8484
Type string `json:"type"`
8585
Name string `json:"name"`
8686
ClientID string `json:"clientID"`
87-
ClientSecret string `json:"clientSecret"` //nolint:gosec // field name required by OIDC configuration
87+
ClientSecret string `json:"clientSecret"`
8888
ConfigurationEndpoint string `json:"configurationEndpoint"`
8989
TenantID string `json:"tenantID,omitempty"`
9090
Admins []string `json:"admins,omitempty"`

0 commit comments

Comments
 (0)