From 152cb47692b2139a04e29451e577b1ce0aea3995 Mon Sep 17 00:00:00 2001 From: Karl Persson Date: Wed, 27 Mar 2024 15:22:13 +0100 Subject: [PATCH] AuthN: Add IsAuthenticatedBy to identity interface and replace checks (#85262) Add IsAuthenticatedBy to identity interface and replace checks --- pkg/api/login.go | 2 +- pkg/services/auth/identity/requester.go | 2 ++ pkg/services/authn/identity.go | 9 +++++++++ pkg/services/contexthandler/contexthandler.go | 2 +- pkg/services/sqlstore/permissions/dashboard.go | 2 +- pkg/services/user/identity.go | 9 +++++++++ 6 files changed, 23 insertions(+), 3 deletions(-) diff --git a/pkg/api/login.go b/pkg/api/login.go index 71a7251242b..8e5d570044d 100644 --- a/pkg/api/login.go +++ b/pkg/api/login.go @@ -129,7 +129,7 @@ func (hs *HTTPServer) LoginView(c *contextmodel.ReqContext) { // LDAP users authenticated by auth proxy are also assigned login token but their auth module is LDAP if hs.Cfg.AuthProxy.Enabled && hs.Cfg.AuthProxy.EnableLoginToken && - (c.SignedInUser.AuthenticatedBy == loginservice.AuthProxyAuthModule || c.SignedInUser.AuthenticatedBy == loginservice.LDAPAuthModule) { + c.SignedInUser.IsAuthenticatedBy(loginservice.AuthProxyAuthModule, loginservice.LDAPAuthModule) { user := &user.User{ID: c.SignedInUser.UserID, Email: c.SignedInUser.Email, Login: c.SignedInUser.Login} err := hs.loginUserWithUser(user, c) if err != nil { diff --git a/pkg/services/auth/identity/requester.go b/pkg/services/auth/identity/requester.go index dadc5e5f9fa..a33544a70d2 100644 --- a/pkg/services/auth/identity/requester.go +++ b/pkg/services/auth/identity/requester.go @@ -50,6 +50,8 @@ type Requester interface { // DEPRECATED: GetOrgName returns the name of the active organization. // Retrieve the organization name from the organization service instead of using this method. GetOrgName() string + // IsAuthenticatedBy returns true if entity was authenticated by any of supplied providers. + IsAuthenticatedBy(providers ...string) bool // IsNil returns true if the identity is nil // FIXME: remove this method once all services are using an interface diff --git a/pkg/services/authn/identity.go b/pkg/services/authn/identity.go index 5cd067fc65f..5eeb636980a 100644 --- a/pkg/services/authn/identity.go +++ b/pkg/services/authn/identity.go @@ -197,6 +197,15 @@ func (i *Identity) HasUniqueId() bool { return namespace == NamespaceUser || namespace == NamespaceServiceAccount || namespace == NamespaceAPIKey } +func (i *Identity) IsAuthenticatedBy(providers ...string) bool { + for _, p := range providers { + if i.AuthenticatedBy == p { + return true + } + } + return false +} + func (i *Identity) IsNil() bool { return i == nil } diff --git a/pkg/services/contexthandler/contexthandler.go b/pkg/services/contexthandler/contexthandler.go index 02ff630fc66..2437f38aa8b 100644 --- a/pkg/services/contexthandler/contexthandler.go +++ b/pkg/services/contexthandler/contexthandler.go @@ -120,7 +120,7 @@ func (h *ContextHandler) Middleware(next http.Handler) http.Handler { reqContext.UserToken = identity.SessionToken reqContext.IsSignedIn = !reqContext.SignedInUser.IsAnonymous reqContext.AllowAnonymous = reqContext.SignedInUser.IsAnonymous - reqContext.IsRenderCall = identity.GetAuthenticatedBy() == login.RenderModule + reqContext.IsRenderCall = identity.IsAuthenticatedBy(login.RenderModule) } reqContext.Logger = reqContext.Logger.New("userId", reqContext.UserID, "orgId", reqContext.OrgID, "uname", reqContext.Login) diff --git a/pkg/services/sqlstore/permissions/dashboard.go b/pkg/services/sqlstore/permissions/dashboard.go index a91f2ff9103..38f8ad92a60 100644 --- a/pkg/services/sqlstore/permissions/dashboard.go +++ b/pkg/services/sqlstore/permissions/dashboard.go @@ -141,7 +141,7 @@ func (f *accessControlDashboardPermissionFilter) buildClauses() { // useSelfContainedPermissions is true if the user's permissions are stored and set from the JWT token // currently it's used for the extended JWT module (when the user is authenticated via a JWT token generated by Grafana) - useSelfContainedPermissions := f.user.GetAuthenticatedBy() == login.ExtendedJWTModule + useSelfContainedPermissions := f.user.IsAuthenticatedBy(login.ExtendedJWTModule) if len(f.dashboardActions) > 0 { toCheck := actionsToCheck(f.dashboardActions, f.user.GetPermissions(), dashWildcards, folderWildcards) diff --git a/pkg/services/user/identity.go b/pkg/services/user/identity.go index 4b2825f817f..af7894c3a7c 100644 --- a/pkg/services/user/identity.go +++ b/pkg/services/user/identity.go @@ -217,6 +217,15 @@ func (u *SignedInUser) GetNamespacedID() (string, string) { return parts[0], parts[1] } +func (u *SignedInUser) IsAuthenticatedBy(providers ...string) bool { + for _, p := range providers { + if u.AuthenticatedBy == p { + return true + } + } + return false +} + // FIXME: remove this method once all services are using an interface func (u *SignedInUser) IsNil() bool { return u == nil