AuthN: Perform login with authn.Service (#61466)
* AuthN: Create password client wrapper and use that on in basic auth client * AuthN: fix basic auth client test * AuthN: Add tests for form authentication * API: Inject authn service * Login: If authnService feature flag is enabled use authn login * Login: Handle token creation errors
This commit is contained in:
@@ -65,18 +65,23 @@ func ProvideService(
|
||||
}
|
||||
|
||||
var passwordClients []authn.PasswordClient
|
||||
|
||||
if !s.cfg.DisableLogin {
|
||||
passwordClients = append(passwordClients, clients.ProvideGrafana(userService))
|
||||
}
|
||||
|
||||
if s.cfg.LDAPEnabled {
|
||||
passwordClients = append(passwordClients, clients.ProvideLDAP(cfg))
|
||||
}
|
||||
|
||||
// only configure basic auth client if it is enabled, and we have at least one password client enabled
|
||||
if s.cfg.BasicAuthEnabled && len(passwordClients) > 0 {
|
||||
s.clients[authn.ClientBasic] = clients.ProvideBasic(loginAttempts, passwordClients...)
|
||||
// if we have password clients configure check if basic auth or form auth is enabled
|
||||
if len(passwordClients) > 0 {
|
||||
passwordClient := clients.ProvidePassword(loginAttempts, passwordClients...)
|
||||
if s.cfg.BasicAuthEnabled {
|
||||
s.clients[authn.ClientBasic] = clients.ProvideBasic(passwordClient)
|
||||
}
|
||||
// FIXME (kalleep): Remove the global variable and stick it into cfg
|
||||
if !setting.DisableLoginForm {
|
||||
s.clients[authn.ClientForm] = clients.ProvideForm(passwordClient)
|
||||
}
|
||||
}
|
||||
|
||||
if s.cfg.JWTAuthEnabled {
|
||||
@@ -128,6 +133,8 @@ func (s *Service) Authenticate(ctx context.Context, client string, r *authn.Requ
|
||||
return nil, true, err
|
||||
}
|
||||
|
||||
// FIXME (kalleep): Handle disabled identities
|
||||
|
||||
for _, hook := range s.postAuthHooks {
|
||||
if err := hook(ctx, identity, r); err != nil {
|
||||
s.log.FromContext(ctx).Warn("post auth hook failed", "error", err, "id", identity)
|
||||
|
||||
Reference in New Issue
Block a user