From 0d55dcc7490f2cfddd6168c3c73478dee9fb2e9c Mon Sep 17 00:00:00 2001 From: Erik Larsson Date: Fri, 26 Mar 2021 10:19:19 +0100 Subject: [PATCH 1/4] fix: use timestamp with timezone for signing_keys Signed-off-by: Erik Larsson --- .changeset/hungry-jars-knock.md | 5 +++ .../migrations/20210326100300_timestamptz.js | 40 +++++++++++++++++++ 2 files changed, 45 insertions(+) create mode 100644 .changeset/hungry-jars-knock.md create mode 100644 plugins/auth-backend/migrations/20210326100300_timestamptz.js diff --git a/.changeset/hungry-jars-knock.md b/.changeset/hungry-jars-knock.md new file mode 100644 index 0000000000..ae41888b52 --- /dev/null +++ b/.changeset/hungry-jars-knock.md @@ -0,0 +1,5 @@ +--- +'@backstage/plugin-auth-backend': minor +--- + +Fixes timezone bug for auth signing keys diff --git a/plugins/auth-backend/migrations/20210326100300_timestamptz.js b/plugins/auth-backend/migrations/20210326100300_timestamptz.js new file mode 100644 index 0000000000..e23644cfa1 --- /dev/null +++ b/plugins/auth-backend/migrations/20210326100300_timestamptz.js @@ -0,0 +1,40 @@ +/* + * Copyright 2020 Spotify AB + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +// @ts-check + +/** + * @param {import('knex').Knex} knex + */ +exports.up = function (knex, Promise) { + return knex.schema.alterTable('signing_keys', function (t) { + t.timestamp('created_at', { useTz: true, precision: 0 }) + .notNullable() + .defaultTo(knex.fn.now()) + .comment('The creation time of the key') + .alter(); + }); +}; + +exports.down = function (knex, Promise) { + return knex.schema.alterTable('signing_keys', function (t) { + t.timestamp('created_at', { useTz: false, precision: 0 }) + .notNullable() + .defaultTo(knex.fn.now()) + .comment('The creation time of the key') + .alter(); + }); +}; From bd7018e6ab0b82d7a19fbd830f84406ee2aa31ad Mon Sep 17 00:00:00 2001 From: Erik Larsson Date: Fri, 26 Mar 2021 10:24:31 +0100 Subject: [PATCH 2/4] fix linting Signed-off-by: Erik Larsson --- .../auth-backend/migrations/20210326100300_timestamptz.js | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/plugins/auth-backend/migrations/20210326100300_timestamptz.js b/plugins/auth-backend/migrations/20210326100300_timestamptz.js index e23644cfa1..2e8fa1bc7c 100644 --- a/plugins/auth-backend/migrations/20210326100300_timestamptz.js +++ b/plugins/auth-backend/migrations/20210326100300_timestamptz.js @@ -19,7 +19,7 @@ /** * @param {import('knex').Knex} knex */ -exports.up = function (knex, Promise) { +exports.up = async function up(knex) { return knex.schema.alterTable('signing_keys', function (t) { t.timestamp('created_at', { useTz: true, precision: 0 }) .notNullable() @@ -29,7 +29,10 @@ exports.up = function (knex, Promise) { }); }; -exports.down = function (knex, Promise) { +/** + * @param {import('knex').Knex} knex + */ +exports.down = async function down(knex) { return knex.schema.alterTable('signing_keys', function (t) { t.timestamp('created_at', { useTz: false, precision: 0 }) .notNullable() From a25efcc643f515185fbdb479e25c43910268cba3 Mon Sep 17 00:00:00 2001 From: Erik Larsson Date: Fri, 26 Mar 2021 11:36:49 +0100 Subject: [PATCH 3/4] skip sqllite Signed-off-by: Erik Larsson --- .../migrations/20210326100300_timestamptz.js | 36 +++++++++++-------- 1 file changed, 22 insertions(+), 14 deletions(-) diff --git a/plugins/auth-backend/migrations/20210326100300_timestamptz.js b/plugins/auth-backend/migrations/20210326100300_timestamptz.js index 2e8fa1bc7c..d326a32211 100644 --- a/plugins/auth-backend/migrations/20210326100300_timestamptz.js +++ b/plugins/auth-backend/migrations/20210326100300_timestamptz.js @@ -20,24 +20,32 @@ * @param {import('knex').Knex} knex */ exports.up = async function up(knex) { - return knex.schema.alterTable('signing_keys', function (t) { - t.timestamp('created_at', { useTz: true, precision: 0 }) - .notNullable() - .defaultTo(knex.fn.now()) - .comment('The creation time of the key') - .alter(); - }); + // Sqlite does not support alter column. + if (knex.client.config.client !== 'sqlite3') { + await knex.schema.alterTable('signing_keys', table => { + table + .timestamp('created_at', { useTz: true, precision: 0 }) + .notNullable() + .defaultTo(knex.fn.now()) + .comment('The creation time of the key') + .alter(); + }); + } }; /** * @param {import('knex').Knex} knex */ exports.down = async function down(knex) { - return knex.schema.alterTable('signing_keys', function (t) { - t.timestamp('created_at', { useTz: false, precision: 0 }) - .notNullable() - .defaultTo(knex.fn.now()) - .comment('The creation time of the key') - .alter(); - }); + // Sqlite does not support alter column. + if (knex.client.config.client !== 'sqlite3') { + await knex.schema.alterTable('signing_keys', table => { + table + .timestamp('created_at', { useTz: false, precision: 0 }) + .notNullable() + .defaultTo(knex.fn.now()) + .comment('The creation time of the key') + .alter(); + }); + } }; From e2abcd8cc38218bcc4c89d0ad1399518bfcee1a8 Mon Sep 17 00:00:00 2001 From: Erik Larsson Date: Fri, 26 Mar 2021 23:04:33 +0100 Subject: [PATCH 4/4] patch Signed-off-by: Erik Larsson --- .changeset/hungry-jars-knock.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.changeset/hungry-jars-knock.md b/.changeset/hungry-jars-knock.md index ae41888b52..733a2ccd17 100644 --- a/.changeset/hungry-jars-knock.md +++ b/.changeset/hungry-jars-knock.md @@ -1,5 +1,5 @@ --- -'@backstage/plugin-auth-backend': minor +'@backstage/plugin-auth-backend': patch --- Fixes timezone bug for auth signing keys