Remove unused auth.restTokenPrivateKey setting
Support for auth token based REST API was removed in change I404c834e5 which went into Gerrit version 2.6, but the initialisation of the auth.restTokenPrivateKey setting seems to have been missed. Remove it. Change-Id: Iff4f6f9a1c302dfd9e2b7fe52f2ddbebe06d9967
This commit is contained in:
@@ -3888,7 +3888,6 @@ Sample `etc/secure.config`:
|
||||
----
|
||||
[auth]
|
||||
registerEmailPrivateKey = 2zHNrXE2bsoylzUqDxZp0H1cqUmjgWb6
|
||||
restTokenPrivateKey = 7e40PzCjlUKOnXATvcBNXH6oyiu+r0dFk2c=
|
||||
|
||||
[database]
|
||||
username = webuser
|
||||
|
@@ -61,9 +61,6 @@ class InitAuth implements InitStep {
|
||||
if (auth.getSecure("registerEmailPrivateKey") == null) {
|
||||
auth.setSecure("registerEmailPrivateKey", SignedToken.generateRandomKey());
|
||||
}
|
||||
if (auth.getSecure("restTokenPrivateKey") == null) {
|
||||
auth.setSecure("restTokenPrivateKey", SignedToken.generateRandomKey());
|
||||
}
|
||||
|
||||
initSignedPush();
|
||||
}
|
||||
|
@@ -60,7 +60,6 @@ public class AuthConfig {
|
||||
private final String cookiePath;
|
||||
private final boolean cookieSecure;
|
||||
private final SignedToken emailReg;
|
||||
private final SignedToken restToken;
|
||||
|
||||
@Inject
|
||||
AuthConfig(@GerritServerConfig final Config cfg)
|
||||
@@ -103,15 +102,6 @@ public class AuthConfig {
|
||||
} else {
|
||||
emailReg = null;
|
||||
}
|
||||
|
||||
key = cfg.getString("auth", null, "restTokenPrivateKey");
|
||||
if (key != null && !key.isEmpty()) {
|
||||
int age = (int) ConfigUtil.getTimeUnit(cfg,
|
||||
"auth", null, "maxRestTokenAge", 60, TimeUnit.SECONDS);
|
||||
restToken = new SignedToken(age, key);
|
||||
} else {
|
||||
restToken = null;
|
||||
}
|
||||
}
|
||||
|
||||
private static List<OpenIdProviderPattern> toPatterns(Config cfg, String name) {
|
||||
@@ -196,10 +186,6 @@ public class AuthConfig {
|
||||
return emailReg;
|
||||
}
|
||||
|
||||
public SignedToken getRestToken() {
|
||||
return restToken;
|
||||
}
|
||||
|
||||
/** OpenID identities which the server permits for authentication. */
|
||||
public List<OpenIdProviderPattern> getAllowedOpenIDs() {
|
||||
return allowedOpenIDs;
|
||||
|
Reference in New Issue
Block a user