HOG v2.1.1¶
A patch release: two fixes to behaviour introduced in v2.1.0, and the repository metadata that the v2.1.0 module rename broke.
Fixes¶
bearer.signingAlgs was ignored unless a dedicated key set was in use.
The accepted algorithms were applied only when the verifier was built against
bearer.jwksURL or a discovered jwks_access_token_uri. On the ordinary path,
where the provider advertises neither, go-oidc filled the list from the
discovery document and an explicit signingAlgs had no effect. It is now
applied on both paths, so restricting the algorithms always restricts them.
forwardIdentity without an issuer is now refused at startup. A route
could set forwardIdentity: true while the gateway configured no
identity.assertion.issue. Nothing minted the header and nothing stripped it,
so a client-supplied X-Hog-Identity reached the backend unchanged. A
downstream HOG rejected it for want of a valid signature, but a backend that
trusted the header would not have. That configuration now fails to build, with
an error naming the route.
The example configuration shipped a real signing seed. The identity
assertion's key used a working 32-byte Ed25519 seed as the fallback of
${ASSERTION_SEED:-…}, so copying the example verbatim signed assertions with
a key published in this repository. The fallback is now all zero bytes, which
is unmistakably a placeholder, and the comment says so.
The documentation image¶
The hog-docs image never built. Its Dockerfile runs the documentation build
in strict mode from a source copy with no .git, where the git-history dates
plugin warns on every page, and strict mode turns a warning into a failure.
The plugin is now switched off for that build alone, so link and navigation
checking stays strict while the image builds. This is why the v2.1.0 release
run reported a failure.
Repository metadata¶
The v2.1.0 rename to github.com/paulopiriquito/hog/v2 also rewrote plain
repository URLs, which never carry the module's major-version suffix. The
README badges and release link, the documentation site's repository and
edit links, one quickstart link, and the org.opencontainers.image.source
label baked into every published image pointed at a path that does not exist.
All are corrected here.
Upgrade notes¶
Nothing to change in your configuration, unless you set forwardIdentity
without identity.assertion.issue, which never did what it appeared to do and
now reports the problem instead of forwarding a client-supplied header.