|
7 | 7 | "encoding/json" |
8 | 8 | "net/http" |
9 | 9 |
|
| 10 | + "golang.org/x/sync/errgroup" |
| 11 | + |
10 | 12 | "github.com/ory/x/httprouterx" |
11 | 13 |
|
12 | 14 | "github.com/gofrs/uuid" |
@@ -89,25 +91,34 @@ func (h *Handler) SetRoutes(admin *httprouterx.RouterAdmin, public *httprouterx. |
89 | 91 | // 200: jsonWebKeySet |
90 | 92 | // default: errorOAuth2 |
91 | 93 | func (h *Handler) discoverJsonWebKeys(w http.ResponseWriter, r *http.Request) { |
92 | | - var jwks jose.JSONWebKeySet |
93 | | - |
94 | | - ctx := r.Context() |
95 | | - for _, set := range stringslice.Unique(h.r.Config().WellKnownKeys(ctx)) { |
96 | | - keys, err := h.r.KeyManager().GetKeySet(ctx, set) |
97 | | - if errors.Is(err, x.ErrNotFound) { |
98 | | - h.r.Logger().Warnf("JSON Web Key Set \"%s\" does not exist yet, generating new key pair...", set) |
99 | | - keys, err = h.r.KeyManager().GenerateAndPersistKeySet(ctx, set, uuid.Must(uuid.NewV4()).String(), string(jose.RS256), "sig") |
100 | | - if err != nil { |
101 | | - h.r.Writer().WriteError(w, r, err) |
102 | | - return |
| 94 | + eg, ctx := errgroup.WithContext(r.Context()) |
| 95 | + wellKnownKeys := stringslice.Unique(h.r.Config().WellKnownKeys(ctx)) |
| 96 | + keys := make(chan *jose.JSONWebKeySet, len(wellKnownKeys)) |
| 97 | + for _, set := range wellKnownKeys { |
| 98 | + set := set |
| 99 | + eg.Go(func() error { |
| 100 | + k, err := h.r.KeyManager().GetKeySet(ctx, set) |
| 101 | + if errors.Is(err, x.ErrNotFound) { |
| 102 | + h.r.Logger().Warnf("JSON Web Key Set %q does not exist yet, generating new key pair...", set) |
| 103 | + k, err = h.r.KeyManager().GenerateAndPersistKeySet(ctx, set, uuid.Must(uuid.NewV4()).String(), string(jose.RS256), "sig") |
| 104 | + if err != nil { |
| 105 | + return err |
| 106 | + } |
| 107 | + } else if err != nil { |
| 108 | + return err |
103 | 109 | } |
104 | | - } else if err != nil { |
105 | | - h.r.Writer().WriteError(w, r, err) |
106 | | - return |
107 | | - } |
108 | | - |
109 | | - keys = ExcludePrivateKeys(keys) |
110 | | - jwks.Keys = append(jwks.Keys, keys.Keys...) |
| 110 | + keys <- ExcludePrivateKeys(k) |
| 111 | + return nil |
| 112 | + }) |
| 113 | + } |
| 114 | + if err := eg.Wait(); err != nil { |
| 115 | + h.r.Writer().WriteError(w, r, err) |
| 116 | + return |
| 117 | + } |
| 118 | + close(keys) |
| 119 | + var jwks jose.JSONWebKeySet |
| 120 | + for k := range keys { |
| 121 | + jwks.Keys = append(jwks.Keys, k.Keys...) |
111 | 122 | } |
112 | 123 |
|
113 | 124 | h.r.Writer().Write(w, r, &jwks) |
|
0 commit comments