Skip to content

HOG v2.1.1

A patch release: two fixes to behaviour introduced in v2.1.0, and the repository metadata that the v2.1.0 module rename broke.

Fixes

bearer.signingAlgs was ignored unless a dedicated key set was in use. The accepted algorithms were applied only when the verifier was built against bearer.jwksURL or a discovered jwks_access_token_uri. On the ordinary path, where the provider advertises neither, go-oidc filled the list from the discovery document and an explicit signingAlgs had no effect. It is now applied on both paths, so restricting the algorithms always restricts them.

forwardIdentity without an issuer is now refused at startup. A route could set forwardIdentity: true while the gateway configured no identity.assertion.issue. Nothing minted the header and nothing stripped it, so a client-supplied X-Hog-Identity reached the backend unchanged. A downstream HOG rejected it for want of a valid signature, but a backend that trusted the header would not have. That configuration now fails to build, with an error naming the route.

The example configuration shipped a real signing seed. The identity assertion's key used a working 32-byte Ed25519 seed as the fallback of ${ASSERTION_SEED:-…}, so copying the example verbatim signed assertions with a key published in this repository. The fallback is now all zero bytes, which is unmistakably a placeholder, and the comment says so.

The documentation image

The hog-docs image never built. Its Dockerfile runs the documentation build in strict mode from a source copy with no .git, where the git-history dates plugin warns on every page, and strict mode turns a warning into a failure. The plugin is now switched off for that build alone, so link and navigation checking stays strict while the image builds. This is why the v2.1.0 release run reported a failure.

Repository metadata

The v2.1.0 rename to github.com/paulopiriquito/hog/v2 also rewrote plain repository URLs, which never carry the module's major-version suffix. The README badges and release link, the documentation site's repository and edit links, one quickstart link, and the org.opencontainers.image.source label baked into every published image pointed at a path that does not exist. All are corrected here.

Upgrade notes

Nothing to change in your configuration, unless you set forwardIdentity without identity.assertion.issue, which never did what it appeared to do and now reports the problem instead of forwarding a client-supplied header.

go get github.com/paulopiriquito/hog/v2@v2.1.1