diff --git a/packages/cre-sdk/scripts/src/fix-imports.ts b/packages/cre-sdk/scripts/src/fix-imports.ts index f983f602..1d0d2aa5 100644 --- a/packages/cre-sdk/scripts/src/fix-imports.ts +++ b/packages/cre-sdk/scripts/src/fix-imports.ts @@ -17,7 +17,7 @@ const fixImports = async () => { const content = await readFile(file, 'utf-8') // Replace @cre/* imports with relative paths - const fixedContent = content.replace(/@cre\/([^'"]*)/g, (_, path) => { + const fixedContent = content.replace(/@cre\/([A-Za-z0-9/_.\-]+)/g, (_, path) => { // Convert @cre/sdk/utils to relative path from current file const currentDir = dirname(file) const targetPath = join(process.cwd(), 'dist', path) diff --git a/packages/cre-sdk/src/generated/capabilities/networking/confidentialhttp/v1alpha/client_pb.ts b/packages/cre-sdk/src/generated/capabilities/networking/confidentialhttp/v1alpha/client_pb.ts index 473f7b89..b02ba68b 100644 --- a/packages/cre-sdk/src/generated/capabilities/networking/confidentialhttp/v1alpha/client_pb.ts +++ b/packages/cre-sdk/src/generated/capabilities/networking/confidentialhttp/v1alpha/client_pb.ts @@ -2,85 +2,131 @@ // @generated from file capabilities/networking/confidentialhttp/v1alpha/client.proto (package capabilities.networking.confidentialhttp.v1alpha, syntax proto3) /* eslint-disable */ -import type { Message } from '@bufbuild/protobuf' -import type { GenFile, GenMessage, GenService } from '@bufbuild/protobuf/codegenv2' -import { fileDesc, messageDesc, serviceDesc } from '@bufbuild/protobuf/codegenv2' -import type { Duration, DurationJson } from '@bufbuild/protobuf/wkt' -import { file_google_protobuf_duration } from '@bufbuild/protobuf/wkt' -import { file_tools_generator_v1alpha_cre_metadata } from '../../../../tools/generator/v1alpha/cre_metadata_pb' +import type { GenEnum, GenFile, GenMessage, GenService } from "@bufbuild/protobuf/codegenv2"; +import { enumDesc, fileDesc, messageDesc, serviceDesc } from "@bufbuild/protobuf/codegenv2"; +import type { Duration, DurationJson } from "@bufbuild/protobuf/wkt"; +import { file_google_protobuf_duration } from "@bufbuild/protobuf/wkt"; +import { file_tools_generator_v1alpha_cre_metadata } from "../../../../tools/generator/v1alpha/cre_metadata_pb"; +import type { Message } from "@bufbuild/protobuf"; /** * Describes the file capabilities/networking/confidentialhttp/v1alpha/client.proto. */ -export const file_capabilities_networking_confidentialhttp_v1alpha_client: GenFile = - /*@__PURE__*/ - fileDesc( - 'Cj1jYXBhYmlsaXRpZXMvbmV0d29ya2luZy9jb25maWRlbnRpYWxodHRwL3YxYWxwaGEvY2xpZW50LnByb3RvEjBjYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEiUAoQU2VjcmV0SWRlbnRpZmllchILCgNrZXkYASABKAkSEQoJbmFtZXNwYWNlGAIgASgJEhIKBW93bmVyGAMgASgJSACIAQFCCAoGX293bmVyIh4KDEhlYWRlclZhbHVlcxIOCgZ2YWx1ZXMYASADKAki1wQKC0hUVFBSZXF1ZXN0EgsKA3VybBgBIAEoCRIOCgZtZXRob2QYAiABKAkSFQoLYm9keV9zdHJpbmcYAyABKAlIABIUCgpib2R5X2J5dGVzGAggASgMSAASZgoNbXVsdGlfaGVhZGVycxgEIAMoCzJPLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5IVFRQUmVxdWVzdC5NdWx0aUhlYWRlcnNFbnRyeRJ3ChZ0ZW1wbGF0ZV9wdWJsaWNfdmFsdWVzGAUgAygLMlcuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLkhUVFBSZXF1ZXN0LlRlbXBsYXRlUHVibGljVmFsdWVzRW50cnkSHwoXY3VzdG9tX3Jvb3RfY2FfY2VydF9wZW0YBiABKAwSKgoHdGltZW91dBgHIAEoCzIZLmdvb2dsZS5wcm90b2J1Zi5EdXJhdGlvbhIWCg5lbmNyeXB0X291dHB1dBgJIAEoCBpzChFNdWx0aUhlYWRlcnNFbnRyeRILCgNrZXkYASABKAkSTQoFdmFsdWUYAiABKAsyPi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuSGVhZGVyVmFsdWVzOgI4ARo7ChlUZW1wbGF0ZVB1YmxpY1ZhbHVlc0VudHJ5EgsKA2tleRgBIAEoCRINCgV2YWx1ZRgCIAEoCToCOAFCBgoEYm9keSKPAgoMSFRUUFJlc3BvbnNlEhMKC3N0YXR1c19jb2RlGAEgASgNEgwKBGJvZHkYAiABKAwSZwoNbXVsdGlfaGVhZGVycxgDIAMoCzJQLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5IVFRQUmVzcG9uc2UuTXVsdGlIZWFkZXJzRW50cnkacwoRTXVsdGlIZWFkZXJzRW50cnkSCwoDa2V5GAEgASgJEk0KBXZhbHVlGAIgASgLMj4uY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLkhlYWRlclZhbHVlczoCOAEiyAEKF0NvbmZpZGVudGlhbEhUVFBSZXF1ZXN0El0KEXZhdWx0X2Rvbl9zZWNyZXRzGAEgAygLMkIuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLlNlY3JldElkZW50aWZpZXISTgoHcmVxdWVzdBgCIAEoCzI9LmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5IVFRQUmVxdWVzdDLKAQoGQ2xpZW50EpgBCgtTZW5kUmVxdWVzdBJJLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5Db25maWRlbnRpYWxIVFRQUmVxdWVzdBo+LmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5IVFRQUmVzcG9uc2UaJYK1GCEIARIdY29uZmlkZW50aWFsLWh0dHBAMS4wLjAtYWxwaGFCpgIKNGNvbS5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGFCC0NsaWVudFByb3RvUAGiAgNDTkOqAjBDYXBhYmlsaXRpZXMuTmV0d29ya2luZy5Db25maWRlbnRpYWxodHRwLlYxYWxwaGHKAjBDYXBhYmlsaXRpZXNcTmV0d29ya2luZ1xDb25maWRlbnRpYWxodHRwXFYxYWxwaGHiAjxDYXBhYmlsaXRpZXNcTmV0d29ya2luZ1xDb25maWRlbnRpYWxodHRwXFYxYWxwaGFcR1BCTWV0YWRhdGHqAjNDYXBhYmlsaXRpZXM6Ok5ldHdvcmtpbmc6OkNvbmZpZGVudGlhbGh0dHA6OlYxYWxwaGFiBnByb3RvMw', - [file_google_protobuf_duration, file_tools_generator_v1alpha_cre_metadata], - ) +export const file_capabilities_networking_confidentialhttp_v1alpha_client: GenFile = /*@__PURE__*/ + fileDesc("Cj1jYXBhYmlsaXRpZXMvbmV0d29ya2luZy9jb25maWRlbnRpYWxodHRwL3YxYWxwaGEvY2xpZW50LnByb3RvEjBjYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEiUAoQU2VjcmV0SWRlbnRpZmllchILCgNrZXkYASABKAkSEQoJbmFtZXNwYWNlGAIgASgJEhIKBW93bmVyGAMgASgJSACIAQFCCAoGX293bmVyIoABCg5TdHJpbmdPclNlY3JldBIPCgVwbGFpbhgBIAEoCUgAElQKBnNlY3JldBgCIAEoCzJCLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5TZWNyZXRJZGVudGlmaWVySABCBwoFdmFsdWUiHgoMSGVhZGVyVmFsdWVzEg4KBnZhbHVlcxgBIAMoCSKvBQoLSFRUUFJlcXVlc3QSCwoDdXJsGAEgASgJEg4KBm1ldGhvZBgCIAEoCRIVCgtib2R5X3N0cmluZxgDIAEoCUgAEhQKCmJvZHlfYnl0ZXMYCCABKAxIABJmCg1tdWx0aV9oZWFkZXJzGAQgAygLMk8uY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLkhUVFBSZXF1ZXN0Lk11bHRpSGVhZGVyc0VudHJ5EncKFnRlbXBsYXRlX3B1YmxpY192YWx1ZXMYBSADKAsyVy5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuSFRUUFJlcXVlc3QuVGVtcGxhdGVQdWJsaWNWYWx1ZXNFbnRyeRIfChdjdXN0b21fcm9vdF9jYV9jZXJ0X3BlbRgGIAEoDBIqCgd0aW1lb3V0GAcgASgLMhkuZ29vZ2xlLnByb3RvYnVmLkR1cmF0aW9uEhYKDmVuY3J5cHRfb3V0cHV0GAkgASgIEk0KBG10bHMYCiABKAsyOi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuTXRsc0F1dGhIAYgBARpzChFNdWx0aUhlYWRlcnNFbnRyeRILCgNrZXkYASABKAkSTQoFdmFsdWUYAiABKAsyPi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuSGVhZGVyVmFsdWVzOgI4ARo7ChlUZW1wbGF0ZVB1YmxpY1ZhbHVlc0VudHJ5EgsKA2tleRgBIAEoCRINCgV2YWx1ZRgCIAEoCToCOAFCBgoEYm9keUIHCgVfbXRscyKPAgoMSFRUUFJlc3BvbnNlEhMKC3N0YXR1c19jb2RlGAEgASgNEgwKBGJvZHkYAiABKAwSZwoNbXVsdGlfaGVhZGVycxgDIAMoCzJQLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5IVFRQUmVzcG9uc2UuTXVsdGlIZWFkZXJzRW50cnkacwoRTXVsdGlIZWFkZXJzRW50cnkSCwoDa2V5GAEgASgJEk0KBXZhbHVlGAIgASgLMj4uY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLkhlYWRlclZhbHVlczoCOAEi+gIKF0NvbmZpZGVudGlhbEhUVFBSZXF1ZXN0El0KEXZhdWx0X2Rvbl9zZWNyZXRzGAEgAygLMkIuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLlNlY3JldElkZW50aWZpZXISTgoHcmVxdWVzdBgCIAEoCzI9LmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5IVFRQUmVxdWVzdBJPCgRhdXRoGAMgASgLMjwuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLkF1dGhDb25maWdIAIgBARJNCgRtdGxzGAQgASgLMjouY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLk10bHNBdXRoSAGIAQFCBwoFX2F1dGhCBwoFX210bHMikAIKCE10bHNBdXRoElcKC2NsaWVudF9jZXJ0GAEgASgLMkIuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLlNlY3JldElkZW50aWZpZXISVgoKY2xpZW50X2tleRgCIAEoCzJCLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5TZWNyZXRJZGVudGlmaWVyElMKB2NhX2NlcnQYAyABKAsyQi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuU2VjcmV0SWRlbnRpZmllciKhAwoKQXV0aENvbmZpZxJPCgdhcGlfa2V5GAEgASgLMjwuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLkFwaUtleUF1dGhIABJMCgViYXNpYxgCIAEoCzI7LmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5CYXNpY0F1dGhIABJOCgZiZWFyZXIYAyABKAsyPC5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuQmVhcmVyQXV0aEgAEkoKBGhtYWMYBCABKAsyOi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuSG1hY0F1dGhIABJOCgZvYXV0aDIYBSABKAsyPC5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuT0F1dGgyQXV0aEgAQggKBm1ldGhvZCKLAQoKQXBpS2V5QXV0aBITCgtoZWFkZXJfbmFtZRgBIAEoCRJSCgZzZWNyZXQYAiABKAsyQi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuU2VjcmV0SWRlbnRpZmllchIUCgx2YWx1ZV9wcmVmaXgYAyABKAkitQEKCUJhc2ljQXV0aBJSCgh1c2VybmFtZRgBIAEoCzJALmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5TdHJpbmdPclNlY3JldBJUCghwYXNzd29yZBgCIAEoCzJCLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5TZWNyZXRJZGVudGlmaWVyIooBCgpCZWFyZXJBdXRoElEKBXRva2VuGAEgASgLMkIuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLlNlY3JldElkZW50aWZpZXISEwoLaGVhZGVyX25hbWUYAiABKAkSFAoMdmFsdWVfcHJlZml4GAMgASgJIocCCghIbWFjQXV0aBJOCgZzaGEyNTYYASABKAsyPC5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuSG1hY1NoYTI1NkgAElAKCmF3c19zaWdfdjQYAiABKAsyOi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuQXdzU2lnVjRIABJOCgZjdXN0b20YAyABKAsyPC5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuSG1hY0N1c3RvbUgAQgkKB3ZhcmlhbnQivQEKCkhtYWNTaGEyNTYSUgoGc2VjcmV0GAEgASgLMkIuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLlNlY3JldElkZW50aWZpZXISGAoQc2lnbmF0dXJlX2hlYWRlchgCIAEoCRIYChB0aW1lc3RhbXBfaGVhZGVyGAMgASgJEhUKDWluY2x1ZGVfcXVlcnkYBCABKAgSEAoIZW5jb2RpbmcYBSABKAki8AIKCEF3c1NpZ1Y0ElcKDWFjY2Vzc19rZXlfaWQYASABKAsyQC5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuU3RyaW5nT3JTZWNyZXQSXQoRc2VjcmV0X2FjY2Vzc19rZXkYAiABKAsyQi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuU2VjcmV0SWRlbnRpZmllchJZCg1zZXNzaW9uX3Rva2VuGAMgASgLMkIuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLlNlY3JldElkZW50aWZpZXISDgoGcmVnaW9uGAQgASgJEg8KB3NlcnZpY2UYBSABKAkSFgoOc2lnbmVkX2hlYWRlcnMYBiADKAkSGAoQdW5zaWduZWRfcGF5bG9hZBgHIAEoCCLtAgoKSG1hY0N1c3RvbRJSCgZzZWNyZXQYASABKAsyQi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuU2VjcmV0SWRlbnRpZmllchIaChJjYW5vbmljYWxfdGVtcGxhdGUYAiABKAkSTwoEaGFzaBgDIAEoDjJBLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5IbWFjQ3VzdG9tLkhhc2gSGAoQc2lnbmF0dXJlX2hlYWRlchgEIAEoCRIYChBzaWduYXR1cmVfcHJlZml4GAUgASgJEhgKEHRpbWVzdGFtcF9oZWFkZXIYBiABKAkSFAoMbm9uY2VfaGVhZGVyGAcgASgJEhAKCGVuY29kaW5nGAggASgJIigKBEhhc2gSDwoLSEFTSF9TSEEyNTYQABIPCgtIQVNIX1NIQTUxMhABIt8BCgpPQXV0aDJBdXRoEmcKEmNsaWVudF9jcmVkZW50aWFscxgBIAEoCzJJLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5PQXV0aDJDbGllbnRDcmVkZW50aWFsc0gAEl0KDXJlZnJlc2hfdG9rZW4YAiABKAsyRC5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuT0F1dGgyUmVmcmVzaFRva2VuSABCCQoHdmFyaWFudCLAAwoXT0F1dGgyQ2xpZW50Q3JlZGVudGlhbHMSEQoJdG9rZW5fdXJsGAEgASgJElMKCWNsaWVudF9pZBgCIAEoCzJALmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5TdHJpbmdPclNlY3JldBJZCg1jbGllbnRfc2VjcmV0GAMgASgLMkIuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLlNlY3JldElkZW50aWZpZXISDgoGc2NvcGVzGAQgAygJEhAKCGF1ZGllbmNlGAUgASgJEhoKEmNsaWVudF9hdXRoX21ldGhvZBgGIAEoCRJwCgxleHRyYV9wYXJhbXMYByADKAsyWi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuT0F1dGgyQ2xpZW50Q3JlZGVudGlhbHMuRXh0cmFQYXJhbXNFbnRyeRoyChBFeHRyYVBhcmFtc0VudHJ5EgsKA2tleRgBIAEoCRINCgV2YWx1ZRgCIAEoCToCOAEi4wMKEk9BdXRoMlJlZnJlc2hUb2tlbhIRCgl0b2tlbl91cmwYASABKAkSWQoNcmVmcmVzaF90b2tlbhgCIAEoCzJCLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5TZWNyZXRJZGVudGlmaWVyElMKCWNsaWVudF9pZBgDIAEoCzJALmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5TdHJpbmdPclNlY3JldBJZCg1jbGllbnRfc2VjcmV0GAQgASgLMkIuY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhLlNlY3JldElkZW50aWZpZXISDgoGc2NvcGVzGAUgAygJEmsKDGV4dHJhX3BhcmFtcxgGIAMoCzJVLmNhcGFiaWxpdGllcy5uZXR3b3JraW5nLmNvbmZpZGVudGlhbGh0dHAudjFhbHBoYS5PQXV0aDJSZWZyZXNoVG9rZW4uRXh0cmFQYXJhbXNFbnRyeRoyChBFeHRyYVBhcmFtc0VudHJ5EgsKA2tleRgBIAEoCRINCgV2YWx1ZRgCIAEoCToCOAEyygEKBkNsaWVudBKYAQoLU2VuZFJlcXVlc3QSSS5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuQ29uZmlkZW50aWFsSFRUUFJlcXVlc3QaPi5jYXBhYmlsaXRpZXMubmV0d29ya2luZy5jb25maWRlbnRpYWxodHRwLnYxYWxwaGEuSFRUUFJlc3BvbnNlGiWCtRghCAESHWNvbmZpZGVudGlhbC1odHRwQDEuMC4wLWFscGhhQqYCCjRjb20uY2FwYWJpbGl0aWVzLm5ldHdvcmtpbmcuY29uZmlkZW50aWFsaHR0cC52MWFscGhhQgtDbGllbnRQcm90b1ABogIDQ05DqgIwQ2FwYWJpbGl0aWVzLk5ldHdvcmtpbmcuQ29uZmlkZW50aWFsaHR0cC5WMWFscGhhygIwQ2FwYWJpbGl0aWVzXE5ldHdvcmtpbmdcQ29uZmlkZW50aWFsaHR0cFxWMWFscGhh4gI8Q2FwYWJpbGl0aWVzXE5ldHdvcmtpbmdcQ29uZmlkZW50aWFsaHR0cFxWMWFscGhhXEdQQk1ldGFkYXRh6gIzQ2FwYWJpbGl0aWVzOjpOZXR3b3JraW5nOjpDb25maWRlbnRpYWxodHRwOjpWMWFscGhhYgZwcm90bzM", [file_google_protobuf_duration, file_tools_generator_v1alpha_cre_metadata]); /** * @generated from message capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier */ -export type SecretIdentifier = - Message<'capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier'> & { - /** - * @generated from field: string key = 1; - */ - key: string +export type SecretIdentifier = Message<"capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier"> & { + /** + * @generated from field: string key = 1; + */ + key: string; - /** - * @generated from field: string namespace = 2; - */ - namespace: string + /** + * @generated from field: string namespace = 2; + */ + namespace: string; - /** - * @generated from field: optional string owner = 3; - */ - owner?: string - } + /** + * @generated from field: optional string owner = 3; + */ + owner?: string; +}; /** * @generated from message capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier */ export type SecretIdentifierJson = { - /** - * @generated from field: string key = 1; - */ - key?: string - - /** - * @generated from field: string namespace = 2; - */ - namespace?: string - - /** - * @generated from field: optional string owner = 3; - */ - owner?: string -} + /** + * @generated from field: string key = 1; + */ + key?: string; + + /** + * @generated from field: string namespace = 2; + */ + namespace?: string; + + /** + * @generated from field: optional string owner = 3; + */ + owner?: string; +}; /** * Describes the message capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier. * Use `create(SecretIdentifierSchema)` to create a new message. */ -export const SecretIdentifierSchema: GenMessage< - SecretIdentifier, - { jsonType: SecretIdentifierJson } -> = /*@__PURE__*/ messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 0) +export const SecretIdentifierSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 0); + +/** + * StringOrSecret allows a field to carry either a plain string value + * (used directly) or a SecretIdentifier (resolved from the vault at + * signing time). Use this for fields that aren't necessarily secret, + * e.g. a username or client_id. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.StringOrSecret + */ +export type StringOrSecret = Message<"capabilities.networking.confidentialhttp.v1alpha.StringOrSecret"> & { + /** + * @generated from oneof capabilities.networking.confidentialhttp.v1alpha.StringOrSecret.value + */ + value: { + /** + * @generated from field: string plain = 1; + */ + value: string; + case: "plain"; + } | { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret = 2; + */ + value: SecretIdentifier; + case: "secret"; + } | { case: undefined; value?: undefined }; +}; + +/** + * StringOrSecret allows a field to carry either a plain string value + * (used directly) or a SecretIdentifier (resolved from the vault at + * signing time). Use this for fields that aren't necessarily secret, + * e.g. a username or client_id. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.StringOrSecret + */ +export type StringOrSecretJson = { + /** + * @generated from field: string plain = 1; + */ + plain?: string; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret = 2; + */ + secret?: SecretIdentifierJson; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.StringOrSecret. + * Use `create(StringOrSecretSchema)` to create a new message. + */ +export const StringOrSecretSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 1); /** * HeaderValues represents multiple values for a single header key. * * @generated from message capabilities.networking.confidentialhttp.v1alpha.HeaderValues */ -export type HeaderValues = - Message<'capabilities.networking.confidentialhttp.v1alpha.HeaderValues'> & { - /** - * @generated from field: repeated string values = 1; - */ - values: string[] - } +export type HeaderValues = Message<"capabilities.networking.confidentialhttp.v1alpha.HeaderValues"> & { + /** + * @generated from field: repeated string values = 1; + */ + values: string[]; +}; /** * HeaderValues represents multiple values for a single header key. @@ -88,103 +134,106 @@ export type HeaderValues = * @generated from message capabilities.networking.confidentialhttp.v1alpha.HeaderValues */ export type HeaderValuesJson = { - /** - * @generated from field: repeated string values = 1; - */ - values?: string[] -} + /** + * @generated from field: repeated string values = 1; + */ + values?: string[]; +}; /** * Describes the message capabilities.networking.confidentialhttp.v1alpha.HeaderValues. * Use `create(HeaderValuesSchema)` to create a new message. */ -export const HeaderValuesSchema: GenMessage = - /*@__PURE__*/ - messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 1) +export const HeaderValuesSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 2); /** * HTTPRequest contains the HTTP fields used to make a request from the enclave. * * @generated from message capabilities.networking.confidentialhttp.v1alpha.HTTPRequest */ -export type HTTPRequest = - Message<'capabilities.networking.confidentialhttp.v1alpha.HTTPRequest'> & { - /** - * url is the endpoint to which the request is sent. - * - * @generated from field: string url = 1; - */ - url: string - - /** - * method is the HTTP method (GET, POST, PUT, DELETE, etc.). - * - * @generated from field: string method = 2; - */ - method: string - - /** - * body is the request body - either a string template or raw bytes. - * - * @generated from oneof capabilities.networking.confidentialhttp.v1alpha.HTTPRequest.body - */ - body: - | { - /** - * @generated from field: string body_string = 3; - */ - value: string - case: 'bodyString' - } - | { - /** - * @generated from field: bytes body_bytes = 8; - */ - value: Uint8Array - case: 'bodyBytes' - } - | { case: undefined; value?: undefined } - - /** - * multi_headers are the request headers as name-value pairs. - * Supports multiple values per header key. - * - * @generated from field: map multi_headers = 4; - */ - multiHeaders: { [key: string]: HeaderValues } - - /** - * template_public_values are public values used to fill in request body and header templates. - * - * @generated from field: map template_public_values = 5; - */ - templatePublicValues: { [key: string]: string } - - /** - * custom_root_ca_cert_pem is an optional custom root CA certificate (PEM format) - * for verifying the external server's TLS certificate. - * - * @generated from field: bytes custom_root_ca_cert_pem = 6; - */ - customRootCaCertPem: Uint8Array - - /** - * timeout is the request timeout duration. - * - * @generated from field: google.protobuf.Duration timeout = 7; - */ - timeout?: Duration - - /** - * encrypt_output controls whether the enclave response should be encrypted. - * If true, the response will be AES-GCM encrypted using the - * "san_marino_aes_gcm_encryption_key" secret. - * Default is false (response returned unencrypted). - * - * @generated from field: bool encrypt_output = 9; - */ - encryptOutput: boolean - } +export type HTTPRequest = Message<"capabilities.networking.confidentialhttp.v1alpha.HTTPRequest"> & { + /** + * url is the endpoint to which the request is sent. + * + * @generated from field: string url = 1; + */ + url: string; + + /** + * method is the HTTP method (GET, POST, PUT, DELETE, etc.). + * + * @generated from field: string method = 2; + */ + method: string; + + /** + * body is the request body - either a string template or raw bytes. + * + * @generated from oneof capabilities.networking.confidentialhttp.v1alpha.HTTPRequest.body + */ + body: { + /** + * @generated from field: string body_string = 3; + */ + value: string; + case: "bodyString"; + } | { + /** + * @generated from field: bytes body_bytes = 8; + */ + value: Uint8Array; + case: "bodyBytes"; + } | { case: undefined; value?: undefined }; + + /** + * multi_headers are the request headers as name-value pairs. + * Supports multiple values per header key. + * + * @generated from field: map multi_headers = 4; + */ + multiHeaders: { [key: string]: HeaderValues }; + + /** + * template_public_values are public values used to fill in request body and header templates. + * + * @generated from field: map template_public_values = 5; + */ + templatePublicValues: { [key: string]: string }; + + /** + * custom_root_ca_cert_pem is an optional custom root CA certificate (PEM format) + * for verifying the external server's TLS certificate. + * + * @generated from field: bytes custom_root_ca_cert_pem = 6; + */ + customRootCaCertPem: Uint8Array; + + /** + * timeout is the request timeout duration. + * + * @generated from field: google.protobuf.Duration timeout = 7; + */ + timeout?: Duration; + + /** + * encrypt_output controls whether the enclave response should be encrypted. + * If true, the response will be AES-GCM encrypted using the + * "san_marino_aes_gcm_encryption_key" secret. + * Default is false (response returned unencrypted). + * + * @generated from field: bool encrypt_output = 9; + */ + encryptOutput: boolean; + + /** + * mtls, when set, configures mutual TLS for this request. Serialized here + * (on HTTPRequest) so it is included in GetInput() and reaches the enclave. + * + * @generated from field: optional capabilities.networking.confidentialhttp.v1alpha.MtlsAuth mtls = 10; + */ + mtls?: MtlsAuth; +}; /** * HTTPRequest contains the HTTP fields used to make a request from the enclave. @@ -192,108 +241,114 @@ export type HTTPRequest = * @generated from message capabilities.networking.confidentialhttp.v1alpha.HTTPRequest */ export type HTTPRequestJson = { - /** - * url is the endpoint to which the request is sent. - * - * @generated from field: string url = 1; - */ - url?: string - - /** - * method is the HTTP method (GET, POST, PUT, DELETE, etc.). - * - * @generated from field: string method = 2; - */ - method?: string - - /** - * @generated from field: string body_string = 3; - */ - bodyString?: string - - /** - * @generated from field: bytes body_bytes = 8; - */ - bodyBytes?: string - - /** - * multi_headers are the request headers as name-value pairs. - * Supports multiple values per header key. - * - * @generated from field: map multi_headers = 4; - */ - multiHeaders?: { [key: string]: HeaderValuesJson } - - /** - * template_public_values are public values used to fill in request body and header templates. - * - * @generated from field: map template_public_values = 5; - */ - templatePublicValues?: { [key: string]: string } - - /** - * custom_root_ca_cert_pem is an optional custom root CA certificate (PEM format) - * for verifying the external server's TLS certificate. - * - * @generated from field: bytes custom_root_ca_cert_pem = 6; - */ - customRootCaCertPem?: string - - /** - * timeout is the request timeout duration. - * - * @generated from field: google.protobuf.Duration timeout = 7; - */ - timeout?: DurationJson - - /** - * encrypt_output controls whether the enclave response should be encrypted. - * If true, the response will be AES-GCM encrypted using the - * "san_marino_aes_gcm_encryption_key" secret. - * Default is false (response returned unencrypted). - * - * @generated from field: bool encrypt_output = 9; - */ - encryptOutput?: boolean -} + /** + * url is the endpoint to which the request is sent. + * + * @generated from field: string url = 1; + */ + url?: string; + + /** + * method is the HTTP method (GET, POST, PUT, DELETE, etc.). + * + * @generated from field: string method = 2; + */ + method?: string; + + /** + * @generated from field: string body_string = 3; + */ + bodyString?: string; + + /** + * @generated from field: bytes body_bytes = 8; + */ + bodyBytes?: string; + + /** + * multi_headers are the request headers as name-value pairs. + * Supports multiple values per header key. + * + * @generated from field: map multi_headers = 4; + */ + multiHeaders?: { [key: string]: HeaderValuesJson }; + + /** + * template_public_values are public values used to fill in request body and header templates. + * + * @generated from field: map template_public_values = 5; + */ + templatePublicValues?: { [key: string]: string }; + + /** + * custom_root_ca_cert_pem is an optional custom root CA certificate (PEM format) + * for verifying the external server's TLS certificate. + * + * @generated from field: bytes custom_root_ca_cert_pem = 6; + */ + customRootCaCertPem?: string; + + /** + * timeout is the request timeout duration. + * + * @generated from field: google.protobuf.Duration timeout = 7; + */ + timeout?: DurationJson; + + /** + * encrypt_output controls whether the enclave response should be encrypted. + * If true, the response will be AES-GCM encrypted using the + * "san_marino_aes_gcm_encryption_key" secret. + * Default is false (response returned unencrypted). + * + * @generated from field: bool encrypt_output = 9; + */ + encryptOutput?: boolean; + + /** + * mtls, when set, configures mutual TLS for this request. Serialized here + * (on HTTPRequest) so it is included in GetInput() and reaches the enclave. + * + * @generated from field: optional capabilities.networking.confidentialhttp.v1alpha.MtlsAuth mtls = 10; + */ + mtls?: MtlsAuthJson; +}; /** * Describes the message capabilities.networking.confidentialhttp.v1alpha.HTTPRequest. * Use `create(HTTPRequestSchema)` to create a new message. */ -export const HTTPRequestSchema: GenMessage = - /*@__PURE__*/ - messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 2) +export const HTTPRequestSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 3); /** * HTTPResponse contains the HTTP response from the enclave. * * @generated from message capabilities.networking.confidentialhttp.v1alpha.HTTPResponse */ -export type HTTPResponse = - Message<'capabilities.networking.confidentialhttp.v1alpha.HTTPResponse'> & { - /** - * status_code is the HTTP status code. - * - * @generated from field: uint32 status_code = 1; - */ - statusCode: number - - /** - * body is the response body. - * - * @generated from field: bytes body = 2; - */ - body: Uint8Array - - /** - * multi_headers are the response headers. - * Supports multiple values per header key. - * - * @generated from field: map multi_headers = 3; - */ - multiHeaders: { [key: string]: HeaderValues } - } +export type HTTPResponse = Message<"capabilities.networking.confidentialhttp.v1alpha.HTTPResponse"> & { + /** + * status_code is the HTTP status code. + * + * @generated from field: uint32 status_code = 1; + */ + statusCode: number; + + /** + * body is the response body. + * + * @generated from field: bytes body = 2; + */ + body: Uint8Array; + + /** + * multi_headers are the response headers. + * Supports multiple values per header key. + * + * @generated from field: map multi_headers = 3; + */ + multiHeaders: { [key: string]: HeaderValues }; +}; /** * HTTPResponse contains the HTTP response from the enclave. @@ -301,36 +356,35 @@ export type HTTPResponse = * @generated from message capabilities.networking.confidentialhttp.v1alpha.HTTPResponse */ export type HTTPResponseJson = { - /** - * status_code is the HTTP status code. - * - * @generated from field: uint32 status_code = 1; - */ - statusCode?: number - - /** - * body is the response body. - * - * @generated from field: bytes body = 2; - */ - body?: string - - /** - * multi_headers are the response headers. - * Supports multiple values per header key. - * - * @generated from field: map multi_headers = 3; - */ - multiHeaders?: { [key: string]: HeaderValuesJson } -} + /** + * status_code is the HTTP status code. + * + * @generated from field: uint32 status_code = 1; + */ + statusCode?: number; + + /** + * body is the response body. + * + * @generated from field: bytes body = 2; + */ + body?: string; + + /** + * multi_headers are the response headers. + * Supports multiple values per header key. + * + * @generated from field: map multi_headers = 3; + */ + multiHeaders?: { [key: string]: HeaderValuesJson }; +}; /** * Describes the message capabilities.networking.confidentialhttp.v1alpha.HTTPResponse. * Use `create(HTTPResponseSchema)` to create a new message. */ -export const HTTPResponseSchema: GenMessage = - /*@__PURE__*/ - messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 3) +export const HTTPResponseSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 4); /** * ConfidentialHTTPRequest is the input provided to the confidential HTTP capability. @@ -338,18 +392,37 @@ export const HTTPResponseSchema: GenMessage & { - /** - * @generated from field: repeated capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier vault_don_secrets = 1; - */ - vaultDonSecrets: SecretIdentifier[] +export type ConfidentialHTTPRequest = Message<"capabilities.networking.confidentialhttp.v1alpha.ConfidentialHTTPRequest"> & { + /** + * @generated from field: repeated capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier vault_don_secrets = 1; + */ + vaultDonSecrets: SecretIdentifier[]; - /** - * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HTTPRequest request = 2; - */ - request?: HTTPRequest - } + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HTTPRequest request = 2; + */ + request?: HTTPRequest; + + /** + * auth, when set, instructs the enclave to sign the outbound request using + * the specified method. Every SecretIdentifier referenced inside AuthConfig + * must also appear in vault_don_secrets (enforced by the capability validator). + * When auth is nil, the request is sent with only the headers/body the + * caller provided — preserving the legacy "{{.SECRET_NAME}}" header-template + * behavior. + * + * @generated from field: optional capabilities.networking.confidentialhttp.v1alpha.AuthConfig auth = 3; + */ + auth?: AuthConfig; + + /** + * mtls, when set, configures mutual TLS for the outbound request. mTLS is + * a transport-level mechanism and operates independently of auth. + * + * @generated from field: optional capabilities.networking.confidentialhttp.v1alpha.MtlsAuth mtls = 4; + */ + mtls?: MtlsAuth; +}; /** * ConfidentialHTTPRequest is the input provided to the confidential HTTP capability. @@ -358,36 +431,1129 @@ export type ConfidentialHTTPRequest = * @generated from message capabilities.networking.confidentialhttp.v1alpha.ConfidentialHTTPRequest */ export type ConfidentialHTTPRequestJson = { - /** - * @generated from field: repeated capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier vault_don_secrets = 1; - */ - vaultDonSecrets?: SecretIdentifierJson[] - - /** - * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HTTPRequest request = 2; - */ - request?: HTTPRequestJson -} + /** + * @generated from field: repeated capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier vault_don_secrets = 1; + */ + vaultDonSecrets?: SecretIdentifierJson[]; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HTTPRequest request = 2; + */ + request?: HTTPRequestJson; + + /** + * auth, when set, instructs the enclave to sign the outbound request using + * the specified method. Every SecretIdentifier referenced inside AuthConfig + * must also appear in vault_don_secrets (enforced by the capability validator). + * When auth is nil, the request is sent with only the headers/body the + * caller provided — preserving the legacy "{{.SECRET_NAME}}" header-template + * behavior. + * + * @generated from field: optional capabilities.networking.confidentialhttp.v1alpha.AuthConfig auth = 3; + */ + auth?: AuthConfigJson; + + /** + * mtls, when set, configures mutual TLS for the outbound request. mTLS is + * a transport-level mechanism and operates independently of auth. + * + * @generated from field: optional capabilities.networking.confidentialhttp.v1alpha.MtlsAuth mtls = 4; + */ + mtls?: MtlsAuthJson; +}; /** * Describes the message capabilities.networking.confidentialhttp.v1alpha.ConfidentialHTTPRequest. * Use `create(ConfidentialHTTPRequestSchema)` to create a new message. */ -export const ConfidentialHTTPRequestSchema: GenMessage< - ConfidentialHTTPRequest, - { jsonType: ConfidentialHTTPRequestJson } -> = /*@__PURE__*/ messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 4) +export const ConfidentialHTTPRequestSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 5); + +/** + * MtlsAuth configures mutual TLS for the outbound request. The client + * certificate and private key are resolved from VaultDON at execution time. + * Every SecretIdentifier referenced inside MtlsAuth must also appear in + * vault_don_secrets (enforced by the capability validator). + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.MtlsAuth + */ +export type MtlsAuth = Message<"capabilities.networking.confidentialhttp.v1alpha.MtlsAuth"> & { + /** + * required; PEM-encoded client certificate + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier client_cert = 1; + */ + clientCert?: SecretIdentifier; + + /** + * required; PEM-encoded private key + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier client_key = 2; + */ + clientKey?: SecretIdentifier; + + /** + * optional; PEM-encoded CA bundle for server verification + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier ca_cert = 3; + */ + caCert?: SecretIdentifier; +}; + +/** + * MtlsAuth configures mutual TLS for the outbound request. The client + * certificate and private key are resolved from VaultDON at execution time. + * Every SecretIdentifier referenced inside MtlsAuth must also appear in + * vault_don_secrets (enforced by the capability validator). + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.MtlsAuth + */ +export type MtlsAuthJson = { + /** + * required; PEM-encoded client certificate + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier client_cert = 1; + */ + clientCert?: SecretIdentifierJson; + + /** + * required; PEM-encoded private key + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier client_key = 2; + */ + clientKey?: SecretIdentifierJson; + + /** + * optional; PEM-encoded CA bundle for server verification + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier ca_cert = 3; + */ + caCert?: SecretIdentifierJson; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.MtlsAuth. + * Use `create(MtlsAuthSchema)` to create a new message. + */ +export const MtlsAuthSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 6); + +/** + * AuthConfig selects one of the supported request-signing methods. + * Each variant carries the method-specific parameters and references + * the secrets it needs. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.AuthConfig + */ +export type AuthConfig = Message<"capabilities.networking.confidentialhttp.v1alpha.AuthConfig"> & { + /** + * @generated from oneof capabilities.networking.confidentialhttp.v1alpha.AuthConfig.method + */ + method: { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.ApiKeyAuth api_key = 1; + */ + value: ApiKeyAuth; + case: "apiKey"; + } | { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.BasicAuth basic = 2; + */ + value: BasicAuth; + case: "basic"; + } | { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.BearerAuth bearer = 3; + */ + value: BearerAuth; + case: "bearer"; + } | { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HmacAuth hmac = 4; + */ + value: HmacAuth; + case: "hmac"; + } | { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.OAuth2Auth oauth2 = 5; + */ + value: OAuth2Auth; + case: "oauth2"; + } | { case: undefined; value?: undefined }; +}; + +/** + * AuthConfig selects one of the supported request-signing methods. + * Each variant carries the method-specific parameters and references + * the secrets it needs. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.AuthConfig + */ +export type AuthConfigJson = { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.ApiKeyAuth api_key = 1; + */ + apiKey?: ApiKeyAuthJson; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.BasicAuth basic = 2; + */ + basic?: BasicAuthJson; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.BearerAuth bearer = 3; + */ + bearer?: BearerAuthJson; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HmacAuth hmac = 4; + */ + hmac?: HmacAuthJson; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.OAuth2Auth oauth2 = 5; + */ + oauth2?: OAuth2AuthJson; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.AuthConfig. + * Use `create(AuthConfigSchema)` to create a new message. + */ +export const AuthConfigSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 7); + +/** + * ApiKeyAuth attaches a secret value to a chosen header. + * Renders as: : + * Example (header_name="x-api-key"): + * x-api-key: + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.ApiKeyAuth + */ +export type ApiKeyAuth = Message<"capabilities.networking.confidentialhttp.v1alpha.ApiKeyAuth"> & { + /** + * required, e.g. "x-api-key", "Authorization" + * + * @generated from field: string header_name = 1; + */ + headerName: string; + + /** + * required; the API key value + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret = 2; + */ + secret?: SecretIdentifier; + + /** + * optional, e.g. "ApiKey ", "Token " + * + * @generated from field: string value_prefix = 3; + */ + valuePrefix: string; +}; + +/** + * ApiKeyAuth attaches a secret value to a chosen header. + * Renders as: : + * Example (header_name="x-api-key"): + * x-api-key: + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.ApiKeyAuth + */ +export type ApiKeyAuthJson = { + /** + * required, e.g. "x-api-key", "Authorization" + * + * @generated from field: string header_name = 1; + */ + headerName?: string; + + /** + * required; the API key value + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret = 2; + */ + secret?: SecretIdentifierJson; + + /** + * optional, e.g. "ApiKey ", "Token " + * + * @generated from field: string value_prefix = 3; + */ + valuePrefix?: string; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.ApiKeyAuth. + * Use `create(ApiKeyAuthSchema)` to create a new message. + */ +export const ApiKeyAuthSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 8); + +/** + * BasicAuth renders: Authorization: Basic base64(username ":" password). + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.BasicAuth + */ +export type BasicAuth = Message<"capabilities.networking.confidentialhttp.v1alpha.BasicAuth"> & { + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.StringOrSecret username = 1; + */ + username?: StringOrSecret; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier password = 2; + */ + password?: SecretIdentifier; +}; + +/** + * BasicAuth renders: Authorization: Basic base64(username ":" password). + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.BasicAuth + */ +export type BasicAuthJson = { + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.StringOrSecret username = 1; + */ + username?: StringOrSecretJson; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier password = 2; + */ + password?: SecretIdentifierJson; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.BasicAuth. + * Use `create(BasicAuthSchema)` to create a new message. + */ +export const BasicAuthSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 9); + +/** + * BearerAuth attaches a pre-issued long-lived token. + * Default behavior: Authorization: Bearer + * header_name and value_prefix allow rare overrides (e.g. GitHub's + * "Authorization: token "). + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.BearerAuth + */ +export type BearerAuth = Message<"capabilities.networking.confidentialhttp.v1alpha.BearerAuth"> & { + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier token = 1; + */ + token?: SecretIdentifier; + + /** + * optional override, default "Authorization" + * + * @generated from field: string header_name = 2; + */ + headerName: string; + + /** + * optional override, default "Bearer " + * + * @generated from field: string value_prefix = 3; + */ + valuePrefix: string; +}; + +/** + * BearerAuth attaches a pre-issued long-lived token. + * Default behavior: Authorization: Bearer + * header_name and value_prefix allow rare overrides (e.g. GitHub's + * "Authorization: token "). + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.BearerAuth + */ +export type BearerAuthJson = { + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier token = 1; + */ + token?: SecretIdentifierJson; + + /** + * optional override, default "Authorization" + * + * @generated from field: string header_name = 2; + */ + headerName?: string; + + /** + * optional override, default "Bearer " + * + * @generated from field: string value_prefix = 3; + */ + valuePrefix?: string; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.BearerAuth. + * Use `create(BearerAuthSchema)` to create a new message. + */ +export const BearerAuthSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 10); + +/** + * HmacAuth groups all HMAC-family signing variants. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.HmacAuth + */ +export type HmacAuth = Message<"capabilities.networking.confidentialhttp.v1alpha.HmacAuth"> & { + /** + * @generated from oneof capabilities.networking.confidentialhttp.v1alpha.HmacAuth.variant + */ + variant: { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HmacSha256 sha256 = 1; + */ + value: HmacSha256; + case: "sha256"; + } | { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.AwsSigV4 aws_sig_v4 = 2; + */ + value: AwsSigV4; + case: "awsSigV4"; + } | { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HmacCustom custom = 3; + */ + value: HmacCustom; + case: "custom"; + } | { case: undefined; value?: undefined }; +}; + +/** + * HmacAuth groups all HMAC-family signing variants. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.HmacAuth + */ +export type HmacAuthJson = { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HmacSha256 sha256 = 1; + */ + sha256?: HmacSha256Json; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.AwsSigV4 aws_sig_v4 = 2; + */ + awsSigV4?: AwsSigV4Json; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HmacCustom custom = 3; + */ + custom?: HmacCustomJson; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.HmacAuth. + * Use `create(HmacAuthSchema)` to create a new message. + */ +export const HmacAuthSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 11); + +/** + * HmacSha256 implements a generic canonical-string HMAC-SHA256 signature. + * Canonical string: method "\n" url "\n" sha256(body) "\n" timestamp + * Signature is attached via signature_header, timestamp via timestamp_header. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.HmacSha256 + */ +export type HmacSha256 = Message<"capabilities.networking.confidentialhttp.v1alpha.HmacSha256"> & { + /** + * required; the shared signing secret + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret = 1; + */ + secret?: SecretIdentifier; + + /** + * default "X-Signature" + * + * @generated from field: string signature_header = 2; + */ + signatureHeader: string; + + /** + * default "X-Timestamp" + * + * @generated from field: string timestamp_header = 3; + */ + timestampHeader: string; + + /** + * if true, include the query string in the canonical url + * + * @generated from field: bool include_query = 4; + */ + includeQuery: boolean; + + /** + * "hex" (default) or "base64" + * + * @generated from field: string encoding = 5; + */ + encoding: string; +}; + +/** + * HmacSha256 implements a generic canonical-string HMAC-SHA256 signature. + * Canonical string: method "\n" url "\n" sha256(body) "\n" timestamp + * Signature is attached via signature_header, timestamp via timestamp_header. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.HmacSha256 + */ +export type HmacSha256Json = { + /** + * required; the shared signing secret + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret = 1; + */ + secret?: SecretIdentifierJson; + + /** + * default "X-Signature" + * + * @generated from field: string signature_header = 2; + */ + signatureHeader?: string; + + /** + * default "X-Timestamp" + * + * @generated from field: string timestamp_header = 3; + */ + timestampHeader?: string; + + /** + * if true, include the query string in the canonical url + * + * @generated from field: bool include_query = 4; + */ + includeQuery?: boolean; + + /** + * "hex" (default) or "base64" + * + * @generated from field: string encoding = 5; + */ + encoding?: string; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.HmacSha256. + * Use `create(HmacSha256Schema)` to create a new message. + */ +export const HmacSha256Schema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 12); + +/** + * AwsSigV4 implements AWS Signature Version 4. + * Uses github.com/aws/aws-sdk-go-v2/aws/signer/v4 under the hood. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.AwsSigV4 + */ +export type AwsSigV4 = Message<"capabilities.networking.confidentialhttp.v1alpha.AwsSigV4"> & { + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.StringOrSecret access_key_id = 1; + */ + accessKeyId?: StringOrSecret; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret_access_key = 2; + */ + secretAccessKey?: SecretIdentifier; + + /** + * optional (for STS temporary credentials) + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier session_token = 3; + */ + sessionToken?: SecretIdentifier; + + /** + * required, e.g. "us-east-1" + * + * @generated from field: string region = 4; + */ + region: string; + + /** + * required, e.g. "execute-api", "s3" + * + * @generated from field: string service = 5; + */ + service: string; + + /** + * Signed headers (comma-separated lowercase). Optional; defaults to + * "host;x-amz-date" plus "x-amz-security-token" if session_token is set. + * + * @generated from field: repeated string signed_headers = 6; + */ + signedHeaders: string[]; + + /** + * If true, uses X-Amz-Content-Sha256: UNSIGNED-PAYLOAD (useful for large S3 + * uploads). Default false. + * + * @generated from field: bool unsigned_payload = 7; + */ + unsignedPayload: boolean; +}; + +/** + * AwsSigV4 implements AWS Signature Version 4. + * Uses github.com/aws/aws-sdk-go-v2/aws/signer/v4 under the hood. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.AwsSigV4 + */ +export type AwsSigV4Json = { + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.StringOrSecret access_key_id = 1; + */ + accessKeyId?: StringOrSecretJson; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret_access_key = 2; + */ + secretAccessKey?: SecretIdentifierJson; + + /** + * optional (for STS temporary credentials) + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier session_token = 3; + */ + sessionToken?: SecretIdentifierJson; + + /** + * required, e.g. "us-east-1" + * + * @generated from field: string region = 4; + */ + region?: string; + + /** + * required, e.g. "execute-api", "s3" + * + * @generated from field: string service = 5; + */ + service?: string; + + /** + * Signed headers (comma-separated lowercase). Optional; defaults to + * "host;x-amz-date" plus "x-amz-security-token" if session_token is set. + * + * @generated from field: repeated string signed_headers = 6; + */ + signedHeaders?: string[]; + + /** + * If true, uses X-Amz-Content-Sha256: UNSIGNED-PAYLOAD (useful for large S3 + * uploads). Default false. + * + * @generated from field: bool unsigned_payload = 7; + */ + unsignedPayload?: boolean; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.AwsSigV4. + * Use `create(AwsSigV4Schema)` to create a new message. + */ +export const AwsSigV4Schema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 13); + +/** + * HmacCustom lets workflow authors specify the canonical string via a + * Go text/template string. Available template vars: + * {{.method}} {{.url}} {{.path}} {{.query}} {{.body}} {{.body_sha256}} + * {{.timestamp}} {{.nonce}} {{header "X-Foo"}} + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.HmacCustom + */ +export type HmacCustom = Message<"capabilities.networking.confidentialhttp.v1alpha.HmacCustom"> & { + /** + * required; the signing secret + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret = 1; + */ + secret?: SecretIdentifier; + + /** + * required + * + * @generated from field: string canonical_template = 2; + */ + canonicalTemplate: string; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HmacCustom.Hash hash = 3; + */ + hash: HmacCustom_Hash; + + /** + * required + * + * @generated from field: string signature_header = 4; + */ + signatureHeader: string; + + /** + * e.g. "HMAC-SHA256 " + * + * @generated from field: string signature_prefix = 5; + */ + signaturePrefix: string; + + /** + * optional; if set, timestamp header injected + * + * @generated from field: string timestamp_header = 6; + */ + timestampHeader: string; + + /** + * optional; if set, random nonce header injected + * + * @generated from field: string nonce_header = 7; + */ + nonceHeader: string; + + /** + * "hex" (default) or "base64" + * + * @generated from field: string encoding = 8; + */ + encoding: string; +}; + +/** + * HmacCustom lets workflow authors specify the canonical string via a + * Go text/template string. Available template vars: + * {{.method}} {{.url}} {{.path}} {{.query}} {{.body}} {{.body_sha256}} + * {{.timestamp}} {{.nonce}} {{header "X-Foo"}} + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.HmacCustom + */ +export type HmacCustomJson = { + /** + * required; the signing secret + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier secret = 1; + */ + secret?: SecretIdentifierJson; + + /** + * required + * + * @generated from field: string canonical_template = 2; + */ + canonicalTemplate?: string; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.HmacCustom.Hash hash = 3; + */ + hash?: HmacCustom_HashJson; + + /** + * required + * + * @generated from field: string signature_header = 4; + */ + signatureHeader?: string; + + /** + * e.g. "HMAC-SHA256 " + * + * @generated from field: string signature_prefix = 5; + */ + signaturePrefix?: string; + + /** + * optional; if set, timestamp header injected + * + * @generated from field: string timestamp_header = 6; + */ + timestampHeader?: string; + + /** + * optional; if set, random nonce header injected + * + * @generated from field: string nonce_header = 7; + */ + nonceHeader?: string; + + /** + * "hex" (default) or "base64" + * + * @generated from field: string encoding = 8; + */ + encoding?: string; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.HmacCustom. + * Use `create(HmacCustomSchema)` to create a new message. + */ +export const HmacCustomSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 14); + +/** + * @generated from enum capabilities.networking.confidentialhttp.v1alpha.HmacCustom.Hash + */ +export enum HmacCustom_Hash { + /** + * @generated from enum value: HASH_SHA256 = 0; + */ + SHA256 = 0, + + /** + * @generated from enum value: HASH_SHA512 = 1; + */ + SHA512 = 1, +} + +/** + * @generated from enum capabilities.networking.confidentialhttp.v1alpha.HmacCustom.Hash + */ +export type HmacCustom_HashJson = "HASH_SHA256" | "HASH_SHA512"; + +/** + * Describes the enum capabilities.networking.confidentialhttp.v1alpha.HmacCustom.Hash. + */ +export const HmacCustom_HashSchema: GenEnum = /*@__PURE__*/ + enumDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 14, 0); + +/** + * OAuth2Auth groups headless OAuth 2.0 flows. + * Interactive flows (Authorization Code, PKCE, Device Code) are NOT supported — + * they require browser consent that a headless TEE cannot perform. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.OAuth2Auth + */ +export type OAuth2Auth = Message<"capabilities.networking.confidentialhttp.v1alpha.OAuth2Auth"> & { + /** + * @generated from oneof capabilities.networking.confidentialhttp.v1alpha.OAuth2Auth.variant + */ + variant: { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.OAuth2ClientCredentials client_credentials = 1; + */ + value: OAuth2ClientCredentials; + case: "clientCredentials"; + } | { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.OAuth2RefreshToken refresh_token = 2; + */ + value: OAuth2RefreshToken; + case: "refreshToken"; + } | { case: undefined; value?: undefined }; +}; + +/** + * OAuth2Auth groups headless OAuth 2.0 flows. + * Interactive flows (Authorization Code, PKCE, Device Code) are NOT supported — + * they require browser consent that a headless TEE cannot perform. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.OAuth2Auth + */ +export type OAuth2AuthJson = { + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.OAuth2ClientCredentials client_credentials = 1; + */ + clientCredentials?: OAuth2ClientCredentialsJson; + + /** + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.OAuth2RefreshToken refresh_token = 2; + */ + refreshToken?: OAuth2RefreshTokenJson; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.OAuth2Auth. + * Use `create(OAuth2AuthSchema)` to create a new message. + */ +export const OAuth2AuthSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 15); + +/** + * OAuth2ClientCredentials: machine-to-machine grant. + * The enclave POSTs to token_url with client_id/client_secret, caches the + * resulting access_token per (workflow_owner, token_url, client_id, scopes), + * and attaches "Authorization: Bearer " to the outbound request. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.OAuth2ClientCredentials + */ +export type OAuth2ClientCredentials = Message<"capabilities.networking.confidentialhttp.v1alpha.OAuth2ClientCredentials"> & { + /** + * required, must be https:// + * + * @generated from field: string token_url = 1; + */ + tokenUrl: string; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.StringOrSecret client_id = 2; + */ + clientId?: StringOrSecret; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier client_secret = 3; + */ + clientSecret?: SecretIdentifier; + + /** + * optional + * + * @generated from field: repeated string scopes = 4; + */ + scopes: string[]; + + /** + * optional (Auth0-style) + * + * @generated from field: string audience = 5; + */ + audience: string; + + /** + * "basic_auth" (default) or "request_body" — where to put client creds + * on the token request. + * + * @generated from field: string client_auth_method = 6; + */ + clientAuthMethod: string; + + /** + * Extra form params to send with the token request. + * + * @generated from field: map extra_params = 7; + */ + extraParams: { [key: string]: string }; +}; + +/** + * OAuth2ClientCredentials: machine-to-machine grant. + * The enclave POSTs to token_url with client_id/client_secret, caches the + * resulting access_token per (workflow_owner, token_url, client_id, scopes), + * and attaches "Authorization: Bearer " to the outbound request. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.OAuth2ClientCredentials + */ +export type OAuth2ClientCredentialsJson = { + /** + * required, must be https:// + * + * @generated from field: string token_url = 1; + */ + tokenUrl?: string; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.StringOrSecret client_id = 2; + */ + clientId?: StringOrSecretJson; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier client_secret = 3; + */ + clientSecret?: SecretIdentifierJson; + + /** + * optional + * + * @generated from field: repeated string scopes = 4; + */ + scopes?: string[]; + + /** + * optional (Auth0-style) + * + * @generated from field: string audience = 5; + */ + audience?: string; + + /** + * "basic_auth" (default) or "request_body" — where to put client creds + * on the token request. + * + * @generated from field: string client_auth_method = 6; + */ + clientAuthMethod?: string; + + /** + * Extra form params to send with the token request. + * + * @generated from field: map extra_params = 7; + */ + extraParams?: { [key: string]: string }; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.OAuth2ClientCredentials. + * Use `create(OAuth2ClientCredentialsSchema)` to create a new message. + */ +export const OAuth2ClientCredentialsSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 16); + +/** + * OAuth2RefreshToken: the workflow stores a long-lived refresh_token in Vault + * (obtained out-of-band during an interactive consent). The enclave exchanges + * it for an access_token on cache miss. + * + * Important: if the IdP rotates refresh tokens on each exchange, the enclave + * cannot persist the new refresh_token back to Vault. Disable refresh-token + * rotation at the IdP, or prefer client_credentials where possible. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.OAuth2RefreshToken + */ +export type OAuth2RefreshToken = Message<"capabilities.networking.confidentialhttp.v1alpha.OAuth2RefreshToken"> & { + /** + * required, must be https:// + * + * @generated from field: string token_url = 1; + */ + tokenUrl: string; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier refresh_token = 2; + */ + refreshToken?: SecretIdentifier; + + /** + * optional + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.StringOrSecret client_id = 3; + */ + clientId?: StringOrSecret; + + /** + * optional when present + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier client_secret = 4; + */ + clientSecret?: SecretIdentifier; + + /** + * optional + * + * @generated from field: repeated string scopes = 5; + */ + scopes: string[]; + + /** + * @generated from field: map extra_params = 6; + */ + extraParams: { [key: string]: string }; +}; + +/** + * OAuth2RefreshToken: the workflow stores a long-lived refresh_token in Vault + * (obtained out-of-band during an interactive consent). The enclave exchanges + * it for an access_token on cache miss. + * + * Important: if the IdP rotates refresh tokens on each exchange, the enclave + * cannot persist the new refresh_token back to Vault. Disable refresh-token + * rotation at the IdP, or prefer client_credentials where possible. + * + * @generated from message capabilities.networking.confidentialhttp.v1alpha.OAuth2RefreshToken + */ +export type OAuth2RefreshTokenJson = { + /** + * required, must be https:// + * + * @generated from field: string token_url = 1; + */ + tokenUrl?: string; + + /** + * required + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier refresh_token = 2; + */ + refreshToken?: SecretIdentifierJson; + + /** + * optional + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.StringOrSecret client_id = 3; + */ + clientId?: StringOrSecretJson; + + /** + * optional when present + * + * @generated from field: capabilities.networking.confidentialhttp.v1alpha.SecretIdentifier client_secret = 4; + */ + clientSecret?: SecretIdentifierJson; + + /** + * optional + * + * @generated from field: repeated string scopes = 5; + */ + scopes?: string[]; + + /** + * @generated from field: map extra_params = 6; + */ + extraParams?: { [key: string]: string }; +}; + +/** + * Describes the message capabilities.networking.confidentialhttp.v1alpha.OAuth2RefreshToken. + * Use `create(OAuth2RefreshTokenSchema)` to create a new message. + */ +export const OAuth2RefreshTokenSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 17); /** * @generated from service capabilities.networking.confidentialhttp.v1alpha.Client */ export const Client: GenService<{ - /** - * @generated from rpc capabilities.networking.confidentialhttp.v1alpha.Client.SendRequest - */ - sendRequest: { - methodKind: 'unary' - input: typeof ConfidentialHTTPRequestSchema - output: typeof HTTPResponseSchema - } -}> = /*@__PURE__*/ serviceDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 0) + /** + * @generated from rpc capabilities.networking.confidentialhttp.v1alpha.Client.SendRequest + */ + sendRequest: { + methodKind: "unary"; + input: typeof ConfidentialHTTPRequestSchema; + output: typeof HTTPResponseSchema; + }, +}> = /*@__PURE__*/ + serviceDesc(file_capabilities_networking_confidentialhttp_v1alpha_client, 0); + diff --git a/packages/cre-sdk/src/generated/tools/generator/v1alpha/cre_metadata_pb.ts b/packages/cre-sdk/src/generated/tools/generator/v1alpha/cre_metadata_pb.ts index dfafc07f..89c672a3 100644 --- a/packages/cre-sdk/src/generated/tools/generator/v1alpha/cre_metadata_pb.ts +++ b/packages/cre-sdk/src/generated/tools/generator/v1alpha/cre_metadata_pb.ts @@ -16,7 +16,7 @@ import { file_sdk_v1alpha_sdk } from '../../../sdk/v1alpha/sdk_pb' export const file_tools_generator_v1alpha_cre_metadata: GenFile = /*@__PURE__*/ fileDesc( - 'Cip0b29scy9nZW5lcmF0b3IvdjFhbHBoYS9jcmVfbWV0YWRhdGEucHJvdG8SF3Rvb2xzLmdlbmVyYXRvci52MWFscGhhIoQBCgtTdHJpbmdMYWJlbBJECghkZWZhdWx0cxgBIAMoCzIyLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLlN0cmluZ0xhYmVsLkRlZmF1bHRzRW50cnkaLwoNRGVmYXVsdHNFbnRyeRILCgNrZXkYASABKAkSDQoFdmFsdWUYAiABKAk6AjgBIogBCgtVaW50NjRMYWJlbBJECghkZWZhdWx0cxgBIAMoCzIyLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLlVpbnQ2NExhYmVsLkRlZmF1bHRzRW50cnkaMwoNRGVmYXVsdHNFbnRyeRILCgNrZXkYASABKAkSEQoFdmFsdWUYAiABKARCAjAAOgI4ASKEAQoLVWludDMyTGFiZWwSRAoIZGVmYXVsdHMYASADKAsyMi50b29scy5nZW5lcmF0b3IudjFhbHBoYS5VaW50MzJMYWJlbC5EZWZhdWx0c0VudHJ5Gi8KDURlZmF1bHRzRW50cnkSCwoDa2V5GAEgASgJEg0KBXZhbHVlGAIgASgNOgI4ASKGAQoKSW50NjRMYWJlbBJDCghkZWZhdWx0cxgBIAMoCzIxLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLkludDY0TGFiZWwuRGVmYXVsdHNFbnRyeRozCg1EZWZhdWx0c0VudHJ5EgsKA2tleRgBIAEoCRIRCgV2YWx1ZRgCIAEoA0ICMAA6AjgBIoIBCgpJbnQzMkxhYmVsEkMKCGRlZmF1bHRzGAEgAygLMjEudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuSW50MzJMYWJlbC5EZWZhdWx0c0VudHJ5Gi8KDURlZmF1bHRzRW50cnkSCwoDa2V5GAEgASgJEg0KBXZhbHVlGAIgASgFOgI4ASLBAgoFTGFiZWwSPAoMc3RyaW5nX2xhYmVsGAEgASgLMiQudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuU3RyaW5nTGFiZWxIABI8Cgx1aW50NjRfbGFiZWwYAiABKAsyJC50b29scy5nZW5lcmF0b3IudjFhbHBoYS5VaW50NjRMYWJlbEgAEjoKC2ludDY0X2xhYmVsGAMgASgLMiMudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuSW50NjRMYWJlbEgAEjwKDHVpbnQzMl9sYWJlbBgEIAEoCzIkLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLlVpbnQzMkxhYmVsSAASOgoLaW50MzJfbGFiZWwYBSABKAsyIy50b29scy5nZW5lcmF0b3IudjFhbHBoYS5JbnQzMkxhYmVsSABCBgoEa2luZCLkAQoSQ2FwYWJpbGl0eU1ldGFkYXRhEh8KBG1vZGUYASABKA4yES5zZGsudjFhbHBoYS5Nb2RlEhUKDWNhcGFiaWxpdHlfaWQYAiABKAkSRwoGbGFiZWxzGAMgAygLMjcudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuQ2FwYWJpbGl0eU1ldGFkYXRhLkxhYmVsc0VudHJ5Gk0KC0xhYmVsc0VudHJ5EgsKA2tleRgBIAEoCRItCgV2YWx1ZRgCIAEoCzIeLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLkxhYmVsOgI4ASI2ChhDYXBhYmlsaXR5TWV0aG9kTWV0YWRhdGESGgoSbWFwX3RvX3VudHlwZWRfYXBpGAEgASgIOm4KCmNhcGFiaWxpdHkSHy5nb29nbGUucHJvdG9idWYuU2VydmljZU9wdGlvbnMY0IYDIAEoCzIrLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLkNhcGFiaWxpdHlNZXRhZGF0YVIKY2FwYWJpbGl0eTprCgZtZXRob2QSHi5nb29nbGUucHJvdG9idWYuTWV0aG9kT3B0aW9ucxjRhgMgASgLMjEudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuQ2FwYWJpbGl0eU1ldGhvZE1ldGFkYXRhUgZtZXRob2RCrwEKG2NvbS50b29scy5nZW5lcmF0b3IudjFhbHBoYUIQQ3JlTWV0YWRhdGFQcm90b1ABogIDVEdYqgIXVG9vbHMuR2VuZXJhdG9yLlYxYWxwaGHKAhhUb29sc1xHZW5lcmF0b3JfXFYxYWxwaGHiAiRUb29sc1xHZW5lcmF0b3JfXFYxYWxwaGFcR1BCTWV0YWRhdGHqAhlUb29sczo6R2VuZXJhdG9yOjpWMWFscGhhYgZwcm90bzM', + 'Cip0b29scy9nZW5lcmF0b3IvdjFhbHBoYS9jcmVfbWV0YWRhdGEucHJvdG8SF3Rvb2xzLmdlbmVyYXRvci52MWFscGhhIoQBCgtTdHJpbmdMYWJlbBJECghkZWZhdWx0cxgBIAMoCzIyLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLlN0cmluZ0xhYmVsLkRlZmF1bHRzRW50cnkaLwoNRGVmYXVsdHNFbnRyeRILCgNrZXkYASABKAkSDQoFdmFsdWUYAiABKAk6AjgBIogBCgtVaW50NjRMYWJlbBJECghkZWZhdWx0cxgBIAMoCzIyLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLlVpbnQ2NExhYmVsLkRlZmF1bHRzRW50cnkaMwoNRGVmYXVsdHNFbnRyeRILCgNrZXkYASABKAkSEQoFdmFsdWUYAiABKARCAjAAOgI4ASKEAQoLVWludDMyTGFiZWwSRAoIZGVmYXVsdHMYASADKAsyMi50b29scy5nZW5lcmF0b3IudjFhbHBoYS5VaW50MzJMYWJlbC5EZWZhdWx0c0VudHJ5Gi8KDURlZmF1bHRzRW50cnkSCwoDa2V5GAEgASgJEg0KBXZhbHVlGAIgASgNOgI4ASKGAQoKSW50NjRMYWJlbBJDCghkZWZhdWx0cxgBIAMoCzIxLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLkludDY0TGFiZWwuRGVmYXVsdHNFbnRyeRozCg1EZWZhdWx0c0VudHJ5EgsKA2tleRgBIAEoCRIRCgV2YWx1ZRgCIAEoA0ICMAA6AjgBIoIBCgpJbnQzMkxhYmVsEkMKCGRlZmF1bHRzGAEgAygLMjEudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuSW50MzJMYWJlbC5EZWZhdWx0c0VudHJ5Gi8KDURlZmF1bHRzRW50cnkSCwoDa2V5GAEgASgJEg0KBXZhbHVlGAIgASgFOgI4ASLTAgoFTGFiZWwSEAoIb3B0aW9uYWwYBiABKAgSPAoMc3RyaW5nX2xhYmVsGAEgASgLMiQudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuU3RyaW5nTGFiZWxIABI8Cgx1aW50NjRfbGFiZWwYAiABKAsyJC50b29scy5nZW5lcmF0b3IudjFhbHBoYS5VaW50NjRMYWJlbEgAEjoKC2ludDY0X2xhYmVsGAMgASgLMiMudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuSW50NjRMYWJlbEgAEjwKDHVpbnQzMl9sYWJlbBgEIAEoCzIkLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLlVpbnQzMkxhYmVsSAASOgoLaW50MzJfbGFiZWwYBSABKAsyIy50b29scy5nZW5lcmF0b3IudjFhbHBoYS5JbnQzMkxhYmVsSABCBgoEa2luZCLkAQoSQ2FwYWJpbGl0eU1ldGFkYXRhEh8KBG1vZGUYASABKA4yES5zZGsudjFhbHBoYS5Nb2RlEhUKDWNhcGFiaWxpdHlfaWQYAiABKAkSRwoGbGFiZWxzGAMgAygLMjcudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuQ2FwYWJpbGl0eU1ldGFkYXRhLkxhYmVsc0VudHJ5Gk0KC0xhYmVsc0VudHJ5EgsKA2tleRgBIAEoCRItCgV2YWx1ZRgCIAEoCzIeLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLkxhYmVsOgI4ASI2ChhDYXBhYmlsaXR5TWV0aG9kTWV0YWRhdGESGgoSbWFwX3RvX3VudHlwZWRfYXBpGAEgASgIOm4KCmNhcGFiaWxpdHkSHy5nb29nbGUucHJvdG9idWYuU2VydmljZU9wdGlvbnMY0IYDIAEoCzIrLnRvb2xzLmdlbmVyYXRvci52MWFscGhhLkNhcGFiaWxpdHlNZXRhZGF0YVIKY2FwYWJpbGl0eTprCgZtZXRob2QSHi5nb29nbGUucHJvdG9idWYuTWV0aG9kT3B0aW9ucxjRhgMgASgLMjEudG9vbHMuZ2VuZXJhdG9yLnYxYWxwaGEuQ2FwYWJpbGl0eU1ldGhvZE1ldGFkYXRhUgZtZXRob2RCrwEKG2NvbS50b29scy5nZW5lcmF0b3IudjFhbHBoYUIQQ3JlTWV0YWRhdGFQcm90b1ABogIDVEdYqgIXVG9vbHMuR2VuZXJhdG9yLlYxYWxwaGHKAhhUb29sc1xHZW5lcmF0b3JfXFYxYWxwaGHiAiRUb29sc1xHZW5lcmF0b3JfXFYxYWxwaGFcR1BCTWV0YWRhdGHqAhlUb29sczo6R2VuZXJhdG9yOjpWMWFscGhhYgZwcm90bzM', [file_google_protobuf_descriptor, file_sdk_v1alpha_sdk], ) @@ -164,6 +164,13 @@ export const Int32LabelSchema: GenMessage & { + /** + * When true, the label is not required and will only be included in the capability ID when set. + * + * @generated from field: bool optional = 6; + */ + optional: boolean + /** * @generated from oneof tools.generator.v1alpha.Label.kind */ @@ -210,6 +217,13 @@ export type Label = Message<'tools.generator.v1alpha.Label'> & { * @generated from message tools.generator.v1alpha.Label */ export type LabelJson = { + /** + * When true, the label is not required and will only be included in the capability ID when set. + * + * @generated from field: bool optional = 6; + */ + optional?: boolean + /** * @generated from field: tools.generator.v1alpha.StringLabel string_label = 1; */ diff --git a/packages/cre-sdk/src/sdk/cre/__tests__/confidentialhttp.test.ts b/packages/cre-sdk/src/sdk/cre/__tests__/confidentialhttp.test.ts new file mode 100644 index 00000000..a103904b --- /dev/null +++ b/packages/cre-sdk/src/sdk/cre/__tests__/confidentialhttp.test.ts @@ -0,0 +1,135 @@ +import { describe, expect, test } from 'bun:test' +import { buildAuthConfig } from '@cre/sdk/cre/confidentialhttp' + +describe('buildAuthConfig', () => { + test('apiKey variant', () => { + const a = buildAuthConfig({ + kind: 'apiKey', + headerName: 'x-api-key', + secret: { key: 'cg' }, + }) + expect(a.apiKey?.headerName).toBe('x-api-key') + expect(a.apiKey?.secret?.key).toBe('cg') + expect(a.apiKey?.valuePrefix).toBe('') + }) + + test('apiKey with valuePrefix', () => { + const a = buildAuthConfig({ + kind: 'apiKey', + headerName: 'Authorization', + secret: { key: 'tok' }, + valuePrefix: 'ApiKey ', + }) + expect(a.apiKey?.valuePrefix).toBe('ApiKey ') + }) + + test('basic variant', () => { + const a = buildAuthConfig({ + kind: 'basic', + username: { key: 'u' }, + password: { key: 'p' }, + }) + expect(a.basic?.username?.secret?.key).toBe('u') + expect(a.basic?.password?.key).toBe('p') + }) + + test('basic with plain username', () => { + const a = buildAuthConfig({ + kind: 'basic', + username: 'public-user', + password: { key: 'p' }, + }) + expect(a.basic?.username?.plain).toBe('public-user') + expect(a.basic?.password?.key).toBe('p') + }) + + test('bearer with overrides', () => { + const a = buildAuthConfig({ + kind: 'bearer', + token: { key: 'pat' }, + headerName: 'Authorization', + valuePrefix: 'token ', + }) + expect(a.bearer?.token?.key).toBe('pat') + expect(a.bearer?.headerName).toBe('Authorization') + expect(a.bearer?.valuePrefix).toBe('token ') + }) + + test('hmacSha256', () => { + const a = buildAuthConfig({ + kind: 'hmacSha256', + secret: { key: 'k' }, + signatureHeader: 'X-Sig', + encoding: 'base64', + includeQuery: true, + }) + expect(a.hmac?.sha256?.signatureHeader).toBe('X-Sig') + expect(a.hmac?.sha256?.includeQuery).toBe(true) + expect(a.hmac?.sha256?.encoding).toBe('base64') + }) + + test('awsSigV4 with all options', () => { + const a = buildAuthConfig({ + kind: 'awsSigV4', + accessKeyId: { key: 'ak' }, + secretAccessKey: { key: 'sk' }, + sessionToken: { key: 'st' }, + region: 'us-east-1', + service: 's3', + signedHeaders: ['host', 'x-amz-date'], + unsignedPayload: true, + }) + const v = a.hmac?.awsSigV4 + expect(v?.accessKeyId?.secret?.key).toBe('ak') + expect(v?.secretAccessKey?.key).toBe('sk') + expect(v?.sessionToken?.key).toBe('st') + expect(v?.signedHeaders?.length).toBe(2) + expect(v?.unsignedPayload).toBe(true) + }) + + test('hmacCustom sha512', () => { + const a = buildAuthConfig({ + kind: 'hmacCustom', + secret: { key: 'k' }, + canonicalTemplate: '{{.method}}', + hash: 'sha512', + signatureHeader: 'X-Sig', + signaturePrefix: 'HMAC-SHA512 ', + }) + expect(a.hmac?.custom?.hash).toBe('HASH_SHA512') + expect(a.hmac?.custom?.signaturePrefix).toBe('HMAC-SHA512 ') + }) + + test('oauth2 clientCredentials', () => { + const a = buildAuthConfig({ + kind: 'oauth2ClientCredentials', + tokenUrl: 'https://idp/token', + clientId: { key: 'cid' }, + clientSecret: { key: 'csec' }, + scopes: ['read', 'write'], + audience: 'aud', + clientAuthMethod: 'requestBody', + extraParams: { foo: 'bar' }, + }) + const v = a.oauth2?.clientCredentials + expect(v?.tokenUrl).toBe('https://idp/token') + expect(v?.scopes).toEqual(['read', 'write']) + expect(v?.clientAuthMethod).toBe('request_body') + expect(v?.extraParams?.foo).toBe('bar') + }) + + test('oauth2 refreshToken', () => { + const a = buildAuthConfig({ + kind: 'oauth2RefreshToken', + tokenUrl: 'https://idp/token', + refreshToken: { key: 'rt' }, + clientId: { key: 'cid' }, + clientSecret: { key: 'csec' }, + scopes: ['read'], + }) + const v = a.oauth2?.refreshToken + expect(v?.refreshToken?.key).toBe('rt') + expect(v?.clientId?.secret?.key).toBe('cid') + expect(v?.clientSecret?.key).toBe('csec') + }) +}) diff --git a/packages/cre-sdk/src/sdk/cre/confidentialhttp.ts b/packages/cre-sdk/src/sdk/cre/confidentialhttp.ts new file mode 100644 index 00000000..3b22a9b8 --- /dev/null +++ b/packages/cre-sdk/src/sdk/cre/confidentialhttp.ts @@ -0,0 +1,312 @@ +// Ergonomic helpers for the confidentialHTTP capability's AuthConfig. +// +// Building the AuthConfig oneof variants by hand is verbose; these helpers +// let workflow authors describe the signing method via a discriminated union +// and produce the matching proto-JSON structure that fits straight into a +// ConfidentialHTTPRequestJson.auth field. +// +// Every SecretIdentifier referenced inside an AuthConfigInput must also +// appear in vaultDonSecrets (the capability validator enforces this). + +import type { + ApiKeyAuthJson, + AuthConfigJson, + AwsSigV4Json, + BasicAuthJson, + BearerAuthJson, + HmacAuthJson, + HmacCustomJson, + HmacSha256Json, + MtlsAuthJson, + OAuth2AuthJson, + OAuth2ClientCredentialsJson, + OAuth2RefreshTokenJson, + SecretIdentifierJson, + StringOrSecretJson, +} from '@cre/generated/capabilities/networking/confidentialhttp/v1alpha/client_pb' + +// ----------------------------------------------------------------------------- +// Input types +// ----------------------------------------------------------------------------- + +/** A reference to a Vault DON secret. */ +export type SecretRef = { + key: string + namespace?: string + owner?: string +} + +/** A field that may carry either a plain string or a Vault secret. */ +export type StringOrSecretInput = string | SecretRef + +export type AuthConfigInput = + | ApiKeyAuthInput + | BasicAuthInput + | BearerAuthInput + | HmacSha256Input + | AwsSigV4Input + | HmacCustomInput + | OAuth2ClientCredentialsInput + | OAuth2RefreshTokenInput + +/** Mutual TLS config for transport-level client authentication. */ +export type MtlsInput = { + /** Vault secret key for the PEM-encoded client certificate. */ + clientCert: SecretRef + /** Vault secret key for the PEM-encoded client private key. */ + clientKey: SecretRef + /** Optional Vault secret key for a PEM-encoded CA bundle (server verification). */ + caCert?: SecretRef +} + +export type ApiKeyAuthInput = { + kind: 'apiKey' + /** Header name, e.g. "x-api-key" or "Authorization". */ + headerName: string + /** Vault secret carrying the API key value. */ + secret: SecretRef + /** Optional prefix, e.g. "ApiKey " or "Token ". Default: empty. */ + valuePrefix?: string +} + +export type BasicAuthInput = { + kind: 'basic' + username: StringOrSecretInput + password: SecretRef +} + +export type BearerAuthInput = { + kind: 'bearer' + token: SecretRef + /** Default "Authorization". */ + headerName?: string + /** Default "Bearer ". */ + valuePrefix?: string +} + +export type HmacSha256Input = { + kind: 'hmacSha256' + secret: SecretRef + /** Default "X-Signature". */ + signatureHeader?: string + /** Default "X-Timestamp". */ + timestampHeader?: string + includeQuery?: boolean + /** "hex" (default) or "base64". */ + encoding?: 'hex' | 'base64' +} + +export type AwsSigV4Input = { + kind: 'awsSigV4' + accessKeyId: StringOrSecretInput + secretAccessKey: SecretRef + sessionToken?: SecretRef + region: string + service: string + signedHeaders?: string[] + unsignedPayload?: boolean +} + +export type HmacCustomInput = { + kind: 'hmacCustom' + secret: SecretRef + canonicalTemplate: string + hash: 'sha256' | 'sha512' + encoding?: 'hex' | 'base64' + signatureHeader: string + signaturePrefix?: string + timestampHeader?: string + nonceHeader?: string +} + +export type OAuth2ClientCredentialsInput = { + kind: 'oauth2ClientCredentials' + tokenUrl: string + clientId: StringOrSecretInput + clientSecret: SecretRef + scopes?: string[] + audience?: string + clientAuthMethod?: 'basicAuth' | 'requestBody' + extraParams?: Record +} + +export type OAuth2RefreshTokenInput = { + kind: 'oauth2RefreshToken' + tokenUrl: string + refreshToken: SecretRef + clientId?: StringOrSecretInput + clientSecret?: SecretRef + scopes?: string[] + extraParams?: Record +} + +// ----------------------------------------------------------------------------- +// Conversion helpers +// ----------------------------------------------------------------------------- + +function toSecretIdentifierJson(ref: SecretRef): SecretIdentifierJson { + const out: SecretIdentifierJson = { key: ref.key } + if (ref.namespace !== undefined) out.namespace = ref.namespace + if (ref.owner !== undefined) out.owner = ref.owner + return out +} + +function toStringOrSecretJson(value: StringOrSecretInput): StringOrSecretJson { + if (typeof value === 'string') { + return { plain: value } + } + return { secret: toSecretIdentifierJson(value) } +} + +// ----------------------------------------------------------------------------- +// buildAuthConfig — factory that converts the union into an AuthConfigJson. +// ----------------------------------------------------------------------------- + +/** + * Convert a workflow-author-friendly AuthConfigInput into the proto-JSON + * AuthConfig expected by `ConfidentialHTTPRequestJson.auth`. + * + * @example + * const auth = buildAuthConfig({ + * kind: 'apiKey', + * headerName: 'x-api-key', + * secret: { key: 'coingecko_api_key' }, + * }) + * client.sendRequest(runtime, { request, vaultDonSecrets, auth }) + */ +export function buildAuthConfig(input: AuthConfigInput): AuthConfigJson { + switch (input.kind) { + case 'apiKey': + return { apiKey: apiKeyJson(input) } + case 'basic': + return { basic: basicJson(input) } + case 'bearer': + return { bearer: bearerJson(input) } + case 'hmacSha256': + return { hmac: { sha256: hmacSha256Json(input) } satisfies HmacAuthJson } + case 'awsSigV4': + return { hmac: { awsSigV4: awsSigV4Json(input) } satisfies HmacAuthJson } + case 'hmacCustom': + return { hmac: { custom: hmacCustomJson(input) } satisfies HmacAuthJson } + case 'oauth2ClientCredentials': + return { + oauth2: { clientCredentials: oauth2ClientCredentialsJson(input) } satisfies OAuth2AuthJson, + } + case 'oauth2RefreshToken': + return { oauth2: { refreshToken: oauth2RefreshTokenJson(input) } satisfies OAuth2AuthJson } + } +} + +function apiKeyJson(i: ApiKeyAuthInput): ApiKeyAuthJson { + return { + headerName: i.headerName, + secret: toSecretIdentifierJson(i.secret), + valuePrefix: i.valuePrefix ?? '', + } +} + +function basicJson(i: BasicAuthInput): BasicAuthJson { + return { + username: toStringOrSecretJson(i.username), + password: toSecretIdentifierJson(i.password), + } +} + +function bearerJson(i: BearerAuthInput): BearerAuthJson { + return { + token: toSecretIdentifierJson(i.token), + headerName: i.headerName ?? '', + valuePrefix: i.valuePrefix ?? '', + } +} + +function hmacSha256Json(i: HmacSha256Input): HmacSha256Json { + return { + secret: toSecretIdentifierJson(i.secret), + signatureHeader: i.signatureHeader ?? '', + timestampHeader: i.timestampHeader ?? '', + includeQuery: i.includeQuery ?? false, + encoding: i.encoding ?? '', + } +} + +function awsSigV4Json(i: AwsSigV4Input): AwsSigV4Json { + const out: AwsSigV4Json = { + accessKeyId: toStringOrSecretJson(i.accessKeyId), + secretAccessKey: toSecretIdentifierJson(i.secretAccessKey), + region: i.region, + service: i.service, + signedHeaders: i.signedHeaders ?? [], + unsignedPayload: i.unsignedPayload ?? false, + } + if (i.sessionToken) out.sessionToken = toSecretIdentifierJson(i.sessionToken) + return out +} + +function hmacCustomJson(i: HmacCustomInput): HmacCustomJson { + return { + secret: toSecretIdentifierJson(i.secret), + canonicalTemplate: i.canonicalTemplate, + hash: i.hash === 'sha512' ? 'HASH_SHA512' : 'HASH_SHA256', + encoding: i.encoding ?? '', + signatureHeader: i.signatureHeader, + signaturePrefix: i.signaturePrefix ?? '', + timestampHeader: i.timestampHeader ?? '', + nonceHeader: i.nonceHeader ?? '', + } +} + +function oauth2ClientCredentialsJson( + i: OAuth2ClientCredentialsInput, +): OAuth2ClientCredentialsJson { + return { + tokenUrl: i.tokenUrl, + clientId: toStringOrSecretJson(i.clientId), + clientSecret: toSecretIdentifierJson(i.clientSecret), + scopes: i.scopes ?? [], + audience: i.audience ?? '', + clientAuthMethod: + i.clientAuthMethod === 'requestBody' + ? 'request_body' + : i.clientAuthMethod === 'basicAuth' + ? 'basic_auth' + : '', + extraParams: i.extraParams ?? {}, + } +} + +function oauth2RefreshTokenJson(i: OAuth2RefreshTokenInput): OAuth2RefreshTokenJson { + const out: OAuth2RefreshTokenJson = { + tokenUrl: i.tokenUrl, + refreshToken: toSecretIdentifierJson(i.refreshToken), + scopes: i.scopes ?? [], + extraParams: i.extraParams ?? {}, + } + if (i.clientId !== undefined) out.clientId = toStringOrSecretJson(i.clientId) + if (i.clientSecret !== undefined) out.clientSecret = toSecretIdentifierJson(i.clientSecret) + return out +} + +/** + * Convert a MtlsInput into the proto-JSON MtlsAuth expected by + * `HTTPRequestJson.mtls`. The returned object should be set on + * `request.mtls` (the inner HTTPRequest, not ConfidentialHTTPRequest). + * All referenced secrets must appear in `vaultDonSecrets`. + * + * @example + * const mtls = buildMtlsConfig({ + * clientCert: { key: 'my-cert', namespace: 'my-ns' }, + * clientKey: { key: 'my-key', namespace: 'my-ns' }, + * }) + * client.sendRequest(runtime, { request: { ...req, mtls }, vaultDonSecrets }) + */ +export function buildMtlsConfig(input: MtlsInput): MtlsAuthJson { + const out: MtlsAuthJson = { + clientCert: toSecretIdentifierJson(input.clientCert), + clientKey: toSecretIdentifierJson(input.clientKey), + } + if (input.caCert !== undefined) { + out.caCert = toSecretIdentifierJson(input.caCert) + } + return out +} diff --git a/packages/cre-sdk/src/sdk/cre/index.ts b/packages/cre-sdk/src/sdk/cre/index.ts index 270e8ede..d863c353 100644 --- a/packages/cre-sdk/src/sdk/cre/index.ts +++ b/packages/cre-sdk/src/sdk/cre/index.ts @@ -29,6 +29,20 @@ export { } from '@cre/generated-sdk/capabilities/blockchain/evm/v1alpha/client_sdk_gen' // Confidential HTTP Capability export { ClientCapability as ConfidentialHTTPClient } from '@cre/generated-sdk/capabilities/networking/confidentialhttp/v1alpha/client_sdk_gen' +export { + type AuthConfigInput, + type ApiKeyAuthInput, + type BasicAuthInput, + type BearerAuthInput, + type HmacSha256Input, + type AwsSigV4Input, + type HmacCustomInput, + type OAuth2ClientCredentialsInput, + type OAuth2RefreshTokenInput, + type MtlsInput, + buildAuthConfig, + buildMtlsConfig, +} from '@cre/sdk/cre/confidentialhttp' // HTTP Capability export { ClientCapability as HTTPClient, diff --git a/submodules/chainlink-protos b/submodules/chainlink-protos index faea187e..a13ce582 160000 --- a/submodules/chainlink-protos +++ b/submodules/chainlink-protos @@ -1 +1 @@ -Subproject commit faea187e6997e00852cad8046c09b7b2d0f1e128 +Subproject commit a13ce582498c0aae9a1441a5361ab1453179fe3d