mirror of
https://github.com/open-policy-agent/opa.git
synced 2026-08-12 19:32:48 -06:00
e43ef0a979
Earlier this evening I tried to run the Go [modernize](https://pkg.go.dev/golang.org/x/tools/gopls/internal/analysis/modernize) analyzer on OPA. That didn't go as planned: - https://github.com/golang/go/issues/73661 - https://github.com/golang/go/issues/73663 While we wait for that to be fixed, I figured an old-fashioned search-and-replace across the repo may work for at least the `interface{}` to `any` conversion. That should help make it easier to see the other fixes as applied by the modernize tool once it has had those issues resolved. Signed-off-by: Anders Eknert <anders@styra.com>
34 lines
798 B
Go
34 lines
798 B
Go
package verify
|
|
|
|
import (
|
|
"crypto/hmac"
|
|
"errors"
|
|
"fmt"
|
|
|
|
"github.com/open-policy-agent/opa/internal/jwx/jwa"
|
|
"github.com/open-policy-agent/opa/internal/jwx/jws/sign"
|
|
)
|
|
|
|
func newHMAC(alg jwa.SignatureAlgorithm) (*HMACVerifier, error) {
|
|
|
|
s, err := sign.New(alg)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to generate HMAC signer: %w", err)
|
|
}
|
|
return &HMACVerifier{signer: s}, nil
|
|
}
|
|
|
|
// Verify checks whether the signature for a given input and key is correct
|
|
func (v HMACVerifier) Verify(signingInput, signature []byte, key any) (err error) {
|
|
|
|
expected, err := v.signer.Sign(signingInput, key)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to generated signature: %w", err)
|
|
}
|
|
|
|
if !hmac.Equal(signature, expected) {
|
|
return errors.New("failed to match hmac signature")
|
|
}
|
|
return nil
|
|
}
|