mirror of
https://tangled.org/evan.jarrett.net/at-container-registry
synced 2026-10-01 14:35:36 +00:00
oauth working
This commit is contained in:
@@ -5,6 +5,7 @@ import (
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"strings"
|
||||
"sync"
|
||||
|
||||
"github.com/distribution/distribution/v3"
|
||||
registrymw "github.com/distribution/distribution/v3/registry/middleware/registry"
|
||||
@@ -35,6 +36,7 @@ type NamespaceResolver struct {
|
||||
distribution.Namespace
|
||||
resolver *atproto.Resolver
|
||||
defaultStorageEndpoint string
|
||||
repositories sync.Map // Cache of RoutingRepository instances by key (did:reponame)
|
||||
}
|
||||
|
||||
// initATProtoResolver initializes the name resolution middleware
|
||||
@@ -115,11 +117,10 @@ func (nr *NamespaceResolver) Repository(ctx context.Context, name reference.Name
|
||||
|
||||
if globalRefresher != nil {
|
||||
// Try OAuth flow first
|
||||
accessToken, dpopKey, err := globalRefresher.GetAccessToken(ctx, did)
|
||||
accessToken, dpopKey, dpopTransport, err := globalRefresher.GetAccessToken(ctx, did)
|
||||
if err == nil {
|
||||
// OAuth token available - create client with DPoP support
|
||||
fmt.Printf("DEBUG [registry/middleware]: Using OAuth access token for DID=%s\n", did)
|
||||
dpopTransport := oauth.NewDPoPTransport(nil, dpopKey)
|
||||
// OAuth token available - use cached DPoP transport (preserves nonce)
|
||||
fmt.Printf("DEBUG [registry/middleware]: Using OAuth access token for DID=%s (length=%d, first_20=%q)\n", did, len(accessToken), accessToken[:min(20, len(accessToken))])
|
||||
atprotoClient = atproto.NewClientWithDPoP(pdsEndpoint, did, accessToken, dpopKey, dpopTransport)
|
||||
} else {
|
||||
fmt.Printf("DEBUG [registry/middleware]: OAuth refresh failed for DID=%s: %v, falling back to Basic Auth\n", did, err)
|
||||
@@ -143,13 +144,25 @@ func (nr *NamespaceResolver) Repository(ctx context.Context, name reference.Name
|
||||
// Example: "evan.jarrett.net/debian" -> store as "debian"
|
||||
repositoryName := imageName
|
||||
|
||||
fmt.Printf("DEBUG [registry/middleware]: Creating RoutingRepository for image=%s (ATProto repo name)\n", repositoryName)
|
||||
// Cache key is DID + repository name
|
||||
cacheKey := did + ":" + repositoryName
|
||||
|
||||
// Check cache first
|
||||
if cached, ok := nr.repositories.Load(cacheKey); ok {
|
||||
fmt.Printf("DEBUG [registry/middleware]: Using cached RoutingRepository for %s\n", cacheKey)
|
||||
return cached.(*storage.RoutingRepository), nil
|
||||
}
|
||||
|
||||
fmt.Printf("DEBUG [registry/middleware]: Creating new RoutingRepository for image=%s (ATProto repo name)\n", repositoryName)
|
||||
|
||||
// Create routing repository - routes manifests to ATProto, blobs to hold service
|
||||
// The registry is stateless - no local storage is used
|
||||
// Pass storage endpoint and DID as parameters (can't use context as it gets lost)
|
||||
routingRepo := storage.NewRoutingRepository(repo, atprotoClient, repositoryName, storageEndpoint, did)
|
||||
|
||||
// Cache the repository
|
||||
nr.repositories.Store(cacheKey, routingRepo)
|
||||
|
||||
return routingRepo, nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user