33337a67563d468c494af3afb9eb4d71394cde34

Author
TheEdgeOfRage <git@theedgeofrage.com>
Committer
TheEdgeOfRage <git@theedgeofrage.com>
Date

Message

Remove authentication

Diff

 1diff --git a/main.go b/main.go
 2index ea5999c270f5783ca89240832e883f393b52adea..65f4f6b9115da07aebd211e966f2031ab1d1b3b3 100644
 3--- a/main.go
 4+++ b/main.go
 5@@ -2,7 +2,6 @@ package main
 6 
 7 import (
 8 	"context"
 9-	"crypto/subtle"
10 	"encoding/json"
11 	"errors"
12 	"fmt"
13@@ -23,7 +22,6 @@ var commitSHA = regexp.MustCompile(`^[0-9a-f]{40}([0-9a-f]{24})?$`)
14 type config struct {
15 	registry        string
16 	buildkitAddress string
17-	token           []byte
18 }
19 
20 type buildRequest struct {
21@@ -43,7 +41,7 @@ func main() {
22 	jobs := make(chan buildRequest, 100)
23 	go runWorker(config, jobs)
24 
25-	http.HandleFunc("POST /build", buildHandler(config, jobs))
26+	http.HandleFunc("POST /build", buildHandler(jobs))
27 	slog.Info("worker started", "address", ":8080", "registry", config.registry, "buildkit_address", config.buildkitAddress)
28 	if err := http.ListenAndServe(":8080", nil); err != nil {
29 		slog.Error("serve HTTP", "error", err)
30@@ -52,20 +50,6 @@ func main() {
31 }
32 
33 func loadConfig() (config, error) {
34-	tokenFile, err := requiredEnvironment("CI_TOKEN_FILE")
35-	if err != nil {
36-		return config{}, err
37-	}
38-
39-	token, err := os.ReadFile(tokenFile)
40-	if err != nil {
41-		return config{}, fmt.Errorf("read CI token: %w", err)
42-	}
43-	token = trimTrailingNewline(token)
44-	if len(token) == 0 {
45-		return config{}, errors.New("CI token is empty")
46-	}
47-
48 	registry, err := requiredEnvironment("REGISTRY")
49 	if err != nil {
50 		return config{}, err
51@@ -79,7 +63,6 @@ func loadConfig() (config, error) {
52 	return config{
53 		registry:        registry,
54 		buildkitAddress: buildkitAddress,
55-		token:           token,
56 	}, nil
57 }
58 
59@@ -96,24 +79,8 @@ func validRepository(repository string) bool {
60 	return repository != "." && !filepath.IsAbs(repository) && cleaned == repository && cleaned != ".."
61 }
62 
63-func trimTrailingNewline(value []byte) []byte {
64-	for len(value) > 0 && (value[len(value)-1] == '\n' || value[len(value)-1] == '\r') {
65-		value = value[:len(value)-1]
66-	}
67-	return value
68-}
69-
70-func buildHandler(config config, jobs chan<- buildRequest) http.HandlerFunc {
71+func buildHandler(jobs chan<- buildRequest) http.HandlerFunc {
72 	return func(writer http.ResponseWriter, request *http.Request) {
73-		if subtle.ConstantTimeCompare(
74-			[]byte(request.Header.Get("Authorization")),
75-			append([]byte("Bearer "), config.token...),
76-		) != 1 {
77-			slog.Warn("build request rejected", "reason", "unauthorized", "remote_address", request.RemoteAddr)
78-			http.Error(writer, "unauthorized", http.StatusUnauthorized)
79-			return
80-		}
81-
82 		request.Body = http.MaxBytesReader(writer, request.Body, maxRequestBodySize)
83 		defer func() {
84 			if err := request.Body.Close(); err != nil {