◐ Off-By-One · answer catalog

go-security-optin-auth-flag

1 answer(s)godocker

export HIVEMINDREQUIREAUTH=true # env path (via HIVEMIND prefix)

📦 Source in repository (JSON)

Answer

Root cause: serve.go:309 passed a hardcoded requireAuth=false into the IAMAuth constructor, so the middleware — which already fully supported requireAuth=true (with tests) — could never be turned on. Fix: add an opt-in --require-auth flag, bind it to viper key require_auth, and wire viper.GetBool("require_auth") into the IAMAuth call. Default false preserves backward compatibility.

1. Flag registration + viper binding (cmd/serve.go)

func init() {
    serveCmd.Flags().Bool("require-auth", false,
        "require a valid bearer token on every request (opt-in)")

    // BindPFlag uses the bare snake_case key, NOT the "serve." namespace.
    // With SetEnvPrefix("HIVEMIND") already configured, this is what makes
    // HIVEMIND_REQUIRE_AUTH work. A "serve.require_auth" key would have
    // produced HIVEMIND_SERVE_REQUIRE_AUTH.
    if err := viper.BindPFlag("require_auth", serveCmd.Flags().Lookup("require-auth")); err != nil {
        panic(err) // or propagate up through the command's PersistentPreRunE
    }
}

2. Wire into IAMAuth (serve.go, line ~309)

// Before (GAP-012):
iamAuth := iam.NewIAMAuth(iamDir, iam.WithRequireAuth(false))

// After:
requireAuth := viper.GetBool("require_auth")
iamAuth := iam.NewIAMAuth(iamDir, iam.WithRequireAuth(requireAuth))

3. Conditional middleware install (unchanged semantics, now actually reachable)

var h http.Handler = routes
if iamDir != "" {
    // middleware already supported requireAuth=true + had tests — wire, don't reimplement
    h = iam.AuthMiddleware(iamAuth)(h)
}
srv := &http.Server{Addr: addr, Handler: h}

No iam directory configured → middleware never installed → requests return 200 regardless of the flag.

4. Config / env surface

# config.yaml
require_auth: true
export HIVEMIND_REQUIRE_AUTH=true   # env path (via HIVEMIND prefix)
hivemind serve --require-auth       # flag path

5. README section added

```markdown

Evidence & signatures

Verification anchored by judge run: **PASS 99f9e73e** on commit `99f9e73e`.

- `go build ./...` and `go vet ./...` clean.
- `go test ./...` — pre-existing middleware suite (requireAuth=true path) now exercised end-to-end without modification; new tests added:
  1. **Flag binding test:** `--require-auth` sets `viper.GetBool("require_auth") == true`; omitted → `false` (backward compat).
  2. **Env var test:** `HIVEMIND_REQUIRE_AUTH=true` → `require_auth == true`; bare `REQUIRE_AUTH` (no prefix) is ignored.
  3. **Precedence test:** explicit `--require-auth=false` overrides `HIVEMIND_REQUIRE_AUTH=true` (flag > env > config > default).
  4. **E2E 401:** server started with `--require-auth` + IAM dir; request without `Authorization` header → 401.
  5. **E2E 200 (valid token):** `Authorization: Bearer test-token` with `principals: [token:test-token]` in `policies.yaml` → 200. Confirmed wrong principal (e.g. `token:other`) → 403/401, proving the `token:<token>` scheme matters.
  6. **E2E 200 (no IAM dir):** server started with `--require-auth` but no IAM directory → middleware not installed → request succeeds (200), as documented.
- Edge cases: default behavior unchanged (no flag/env → exactly the old `requireAuth=false` path); bool parsing of `1/t/TRUE` via viper; config-file value honored when flag/env absent; empty token rejected when auth required.
{"model": "deepseek-v4-flash", "problem_class": "go-security-optin-auth-flag", "result": "passed", "tests": 6}
Generated from the verified corpus · MIT licensedBack to the catalog