Skip to content

Commit c1c6c87

Browse files
committed
registry: encode credentials with moby's authconfig package
EncodedAuth now delegates the X-Registry-Auth wire encoding to moby/api/pkg/authconfig (same module, already required) instead of hand-rolling the JSON+base64url pair, and push.go reuses it instead of its own copy. The CLI and moby AuthConfig structs are field-for-field identical, so a direct type conversion bridges them. The explicit GetAuthConfigKey normalization drops out of EncodedAuth: docker/cli's configfile.GetAuthConfig normalizes the Docker Hub domain itself. It remains for the OCI resolver, whose credential callback receives the network host actually contacted (registry-1.docker.io), which the configfile does not map. Signed-off-by: Nicolas De Loof <nicolas.deloof@gmail.com>
1 parent 17ee7d7 commit c1c6c87

2 files changed

Lines changed: 13 additions & 19 deletions

File tree

‎internal/registry/registry.go‎

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,10 @@
1717
package registry
1818

1919
import (
20-
"encoding/base64"
21-
"encoding/json"
22-
2320
"github.com/distribution/reference"
2421
clitypes "github.com/docker/cli/cli/config/types"
22+
"github.com/moby/moby/api/pkg/authconfig"
23+
registrytypes "github.com/moby/moby/api/types/registry"
2524
)
2625

2726
const (
@@ -44,6 +43,11 @@ const (
4443

4544
// GetAuthConfigKey special-cases using the full index address of the official
4645
// index as the AuthConfig key, and uses the (host)name[:port] for private indexes.
46+
//
47+
// It differs from the docker CLI configfile's own normalization by also
48+
// mapping the registry host (registry-1.docker.io): OCI resolvers hand the
49+
// credential callback the network host actually contacted, not the reference
50+
// domain.
4751
func GetAuthConfigKey(indexName string) string {
4852
if indexName == IndexName || indexName == IndexHostname || indexName == DefaultRegistryHost {
4953
return IndexServer
@@ -59,16 +63,12 @@ type AuthProvider interface {
5963

6064
// EncodedAuth returns the credentials for the registry hosting the given
6165
// image reference, base64-encoded as expected by the Docker API's
62-
// X-Registry-Auth header.
66+
// X-Registry-Auth header. The configfile normalizes the Docker Hub domain to
67+
// its canonical credentials key itself.
6368
func EncodedAuth(ref reference.Named, cfg AuthProvider) (string, error) {
64-
authConfig, err := cfg.GetAuthConfig(GetAuthConfigKey(reference.Domain(ref)))
65-
if err != nil {
66-
return "", err
67-
}
68-
69-
buf, err := json.Marshal(authConfig)
69+
auth, err := cfg.GetAuthConfig(reference.Domain(ref))
7070
if err != nil {
7171
return "", err
7272
}
73-
return base64.URLEncoding.EncodeToString(buf), nil
73+
return authconfig.Encode(registrytypes.AuthConfig(auth))
7474
}

‎pkg/compose/push.go‎

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,6 @@ package compose
1818

1919
import (
2020
"context"
21-
"encoding/base64"
2221
"encoding/json"
2322
"errors"
2423
"fmt"
@@ -92,18 +91,13 @@ func (s *composeService) pushServiceImage(ctx context.Context, tag string, quiet
9291
return err
9392
}
9493

95-
authConfig, err := s.configFile().GetAuthConfig(registry.GetAuthConfigKey(reference.Domain(ref)))
96-
if err != nil {
97-
return err
98-
}
99-
100-
buf, err := json.Marshal(authConfig)
94+
encodedAuth, err := registry.EncodedAuth(ref, s.configFile())
10195
if err != nil {
10296
return err
10397
}
10498

10599
stream, err := s.apiClient().ImagePush(ctx, tag, client.ImagePushOptions{
106-
RegistryAuth: base64.URLEncoding.EncodeToString(buf),
100+
RegistryAuth: encodedAuth,
107101
})
108102
if err != nil {
109103
return err

0 commit comments

Comments
 (0)