Add Access Gate for Required Groups on ExApp HTTP traffic.

AppAPI cannot restrict ExApps by Nextcloud group; enforce any-of membership in-library with Wrap/Check, deploy-env helpers, and positive-only cache.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Konrad Neitzel
2026-08-27 17:10:58 +02:00
co-authored by Cursor
parent 7921694782
commit 3980263146
6 changed files with 651 additions and 8 deletions
+51
View File
@@ -0,0 +1,51 @@
package gonexapp
import (
"strconv"
"strings"
"time"
)
// EnvRequiredGroups is the conventional deploy env name for Required Groups.
const EnvRequiredGroups = "REQUIRED_GROUPS"
// EnvRequiredGroupsCacheSeconds is the conventional deploy env name for Access Gate cache TTL.
const EnvRequiredGroupsCacheSeconds = "REQUIRED_GROUPS_CACHE_SECONDS"
// DefaultCacheSeconds is used when REQUIRED_GROUPS_CACHE_SECONDS is unset or invalid.
const DefaultCacheSeconds = 60
// ParseRequiredGroups splits a comma-separated Required Groups env value.
func ParseRequiredGroups(s string) []string {
parts := strings.Split(s, ",")
out := make([]string, 0, len(parts))
for _, p := range parts {
p = strings.TrimSpace(p)
if p == "" {
continue
}
out = append(out, p)
}
return out
}
// ResolveRequiredGroups applies env override rules: unset uses codeDefault;
// set (including empty) replaces the default.
func ResolveRequiredGroups(envValue string, envSet bool, codeDefault []string) []string {
if !envSet {
return append([]string(nil), codeDefault...)
}
return ParseRequiredGroups(envValue)
}
// ParseCacheSeconds parses REQUIRED_GROUPS_CACHE_SECONDS. Unset or invalid → defaultSec seconds; "0" → no cache.
func ParseCacheSeconds(s string, defaultSec int) time.Duration {
if strings.TrimSpace(s) == "" {
return time.Duration(defaultSec) * time.Second
}
n, err := strconv.Atoi(strings.TrimSpace(s))
if err != nil || n < 0 {
return time.Duration(defaultSec) * time.Second
}
return time.Duration(n) * time.Second
}