{"id":13542554,"url":"https://github.com/mozilla-services/autograph-edge","last_synced_at":"2025-04-11T13:51:13.482Z","repository":{"id":34378269,"uuid":"135722141","full_name":"mozilla-services/autograph-edge","owner":"mozilla-services","description":"Public endpoint of the Autograph signing service","archived":false,"fork":false,"pushed_at":"2025-03-13T20:02:34.000Z","size":492,"stargazers_count":5,"open_issues_count":7,"forks_count":3,"subscribers_count":12,"default_branch":"main","last_synced_at":"2025-03-25T10:04:32.368Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://hub.docker.com/r/mozilla/autographedge/","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mozilla-services.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-06-01T13:39:22.000Z","updated_at":"2025-03-13T19:04:07.000Z","dependencies_parsed_at":"2024-01-16T15:52:33.445Z","dependency_job_id":"d8fcadb3-0315-4764-95b4-747b44e02dc1","html_url":"https://github.com/mozilla-services/autograph-edge","commit_stats":null,"previous_names":[],"tags_count":47,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mozilla-services%2Fautograph-edge","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mozilla-services%2Fautograph-edge/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mozilla-services%2Fautograph-edge/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mozilla-services%2Fautograph-edge/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mozilla-services","download_url":"https://codeload.github.com/mozilla-services/autograph-edge/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248411940,"owners_count":21099028,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T10:01:10.568Z","updated_at":"2025-04-11T13:51:13.462Z","avatar_url":"https://github.com/mozilla-services.png","language":"Go","funding_links":[],"categories":["Go","others"],"sub_categories":[],"readme":"[![CircleCI](https://circleci.com/gh/mozilla-services/autograph-edge.svg?style=svg)](https://circleci.com/gh/mozilla-services/autograph-edge)\n\n[![Coverage Status](https://coveralls.io/repos/github/mozilla-services/autograph-edge/badge.svg?branch=main)](https://coveralls.io/github/mozilla-services/autograph-edge?branch=main)\n\nAutograph edge\n==============\n\nThis is a small webapp that provides a public endpoint to autograph,\nwithout exposing the entire service to the internet. It only supports XPI and\nAPK signing, and provides fine grained access control to only give clients the\nability to sign a given apk or xpi.\n\nClient are expected to use curl - or similar - to interact with the webapp. An\nunsigned file is submitted to the `/sign/` endpoint along with an authorization\nclient_token. The HTTP response contains the signed file.\n\n```bash\ncurl -F \"input=@/tmp/unsigned.apk\" -o /tmp/signed.apk \\\n    -H \"Authorization: \u003csecret token\u003e\" \\\n    https://autograph-edge.example.com/sign\n```\n\nConfiguration\n-------------\n\n\nThe yaml file `autograph-edge.yaml` the location of the autograph server in\n`url` and a list of authorizations.\n\n```yaml\nauthorizations:\n    - client_token: c4180d2963fffdcd1cd5a1a343225288b964d8934b809a7d76941ccf67cc8547\n      addonid: myaddon@allizom.org\n      user: alice\n      key: fs5wgcer9qj819kfptdlp8gm227ewxnzvsuj9ztycsx08hfhzu\n      signer: extensions-ecdsa\n```\n\nEach authorization has a `client_token` that clients send in their `Authorization` HTTP\nheaders.\n\nThe authorization also has a `user`, `key` and `signer` that are used to call\nautograph (therefore these configuration items must come from the autograph\nconfig).\n\nIf the authorization is for an add-on, it must also contain an `addonid`, which\nis the ID of the add-on being signed. It can also include the optional params:\n\n* `addonpkcs7digest`, a string of the PKCS7 digest algorithm to use\n  (`\"SHA1\"` or `\"SHA256\"`). Defaults to `\"SHA1\"`.\n* `addoncosealgorithms`, an array of strings for COSE Algorithms to\n  sign the addon with. Defaults to an empty list [].\n\nThe sample configuration file in this repository can get you started.\n\n\nNote that the client_token must be longer than 60 characters. You should use `openssl\nrand -hex 32` to generate it.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmozilla-services%2Fautograph-edge","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmozilla-services%2Fautograph-edge","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmozilla-services%2Fautograph-edge/lists"}