Auth: Add authed device tagging (#72442)
* add authed device tagging * fix config * implement feedback * implement feedback * add reverse untag behavior * remove duplicate stat * Update pkg/services/anonymous/anonimpl/impl.go
This commit is contained in:
@@ -3,6 +3,7 @@ package anonimpl
|
||||
import (
|
||||
"context"
|
||||
"encoding/hex"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"hash/fnv"
|
||||
"net/http"
|
||||
@@ -14,28 +15,30 @@ import (
|
||||
"github.com/grafana/grafana/pkg/infra/network"
|
||||
"github.com/grafana/grafana/pkg/infra/remotecache"
|
||||
"github.com/grafana/grafana/pkg/infra/usagestats"
|
||||
"github.com/grafana/grafana/pkg/services/anonymous"
|
||||
"github.com/grafana/grafana/pkg/web"
|
||||
)
|
||||
|
||||
const thirtyDays = 30 * 24 * time.Hour
|
||||
const anonCachePrefix = "anon-session"
|
||||
|
||||
type Device struct {
|
||||
ip string
|
||||
userAgent string
|
||||
Kind anonymous.DeviceKind `json:"kind"`
|
||||
IP string `json:"ip"`
|
||||
UserAgent string `json:"user_agent"`
|
||||
LastSeen time.Time `json:"last_seen"`
|
||||
}
|
||||
|
||||
func (a *Device) Key() (string, error) {
|
||||
key := strings.Builder{}
|
||||
key.WriteString(a.ip)
|
||||
key.WriteString(a.userAgent)
|
||||
key.WriteString(a.IP)
|
||||
key.WriteString(a.UserAgent)
|
||||
|
||||
hash := fnv.New128a()
|
||||
if _, err := hash.Write([]byte(key.String())); err != nil {
|
||||
return "", fmt.Errorf("failed to write to hash: %w", err)
|
||||
}
|
||||
|
||||
return strings.Join([]string{anonCachePrefix, hex.EncodeToString(hash.Sum(nil))}, ":"), nil
|
||||
return strings.Join([]string{string(a.Kind), hex.EncodeToString(hash.Sum(nil))}, ":"), nil
|
||||
}
|
||||
|
||||
type AnonDeviceService struct {
|
||||
@@ -57,17 +60,36 @@ func ProvideAnonymousDeviceService(remoteCache remotecache.CacheStorage, usageSt
|
||||
}
|
||||
|
||||
func (a *AnonDeviceService) usageStatFn(ctx context.Context) (map[string]interface{}, error) {
|
||||
sessionCount, err := a.remoteCache.Count(ctx, anonCachePrefix)
|
||||
anonDeviceCount, err := a.remoteCache.Count(ctx, string(anonymous.AnonDevice))
|
||||
if err != nil {
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
authedDeviceCount, err := a.remoteCache.Count(ctx, string(anonymous.AuthedDevice))
|
||||
if err != nil {
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
return map[string]interface{}{
|
||||
"stats.anonymous.session.count": sessionCount,
|
||||
"stats.anonymous.session.count": anonDeviceCount, // keep session for legacy data
|
||||
"stats.users.device.count": authedDeviceCount,
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (a *AnonDeviceService) TagDevice(ctx context.Context, httpReq *http.Request) error {
|
||||
func (a *AnonDeviceService) untagDevice(ctx context.Context, device *Device) error {
|
||||
key, err := device.Key()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if err := a.remoteCache.Delete(ctx, key); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (a *AnonDeviceService) TagDevice(ctx context.Context, httpReq *http.Request, kind anonymous.DeviceKind) error {
|
||||
addr := web.RemoteAddr(httpReq)
|
||||
ip, err := network.GetIPFromAddress(addr)
|
||||
if err != nil {
|
||||
@@ -80,12 +102,14 @@ func (a *AnonDeviceService) TagDevice(ctx context.Context, httpReq *http.Request
|
||||
clientIPStr = ""
|
||||
}
|
||||
|
||||
anonDevice := &Device{
|
||||
ip: clientIPStr,
|
||||
userAgent: httpReq.UserAgent(),
|
||||
taggedDevice := &Device{
|
||||
Kind: kind,
|
||||
IP: clientIPStr,
|
||||
UserAgent: httpReq.UserAgent(),
|
||||
LastSeen: time.Now().UTC(),
|
||||
}
|
||||
|
||||
key, err := anonDevice.Key()
|
||||
key, err := taggedDevice.Key()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -96,5 +120,27 @@ func (a *AnonDeviceService) TagDevice(ctx context.Context, httpReq *http.Request
|
||||
|
||||
a.localCache.SetDefault(key, struct{}{})
|
||||
|
||||
return a.remoteCache.Set(ctx, key, []byte(key), thirtyDays)
|
||||
deviceJSON, err := json.Marshal(taggedDevice)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if err := a.remoteCache.Set(ctx, key, deviceJSON, thirtyDays); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// remove existing tag when device switches to another kind
|
||||
untagKind := anonymous.AnonDevice
|
||||
if kind == anonymous.AnonDevice {
|
||||
untagKind = anonymous.AuthedDevice
|
||||
}
|
||||
if err := a.untagDevice(ctx, &Device{
|
||||
Kind: untagKind,
|
||||
IP: taggedDevice.IP,
|
||||
UserAgent: taggedDevice.UserAgent,
|
||||
}); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -2,14 +2,17 @@ package anonimpl
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"github.com/grafana/grafana/pkg/infra/remotecache"
|
||||
"github.com/grafana/grafana/pkg/infra/usagestats"
|
||||
"github.com/grafana/grafana/pkg/services/anonymous"
|
||||
)
|
||||
|
||||
func TestAnonDeviceKey(t *testing.T) {
|
||||
@@ -21,24 +24,27 @@ func TestAnonDeviceKey(t *testing.T) {
|
||||
{
|
||||
name: "should hash correctly",
|
||||
session: &Device{
|
||||
ip: "10.10.10.10",
|
||||
userAgent: "test",
|
||||
Kind: anonymous.AnonDevice,
|
||||
IP: "10.10.10.10",
|
||||
UserAgent: "test",
|
||||
},
|
||||
expected: "anon-session:ad9f5c6bf504a9fa77c37a3a6658c0cd",
|
||||
},
|
||||
{
|
||||
name: "should hash correctly with different ip",
|
||||
session: &Device{
|
||||
ip: "10.10.10.1",
|
||||
userAgent: "test",
|
||||
Kind: anonymous.AnonDevice,
|
||||
IP: "10.10.10.1",
|
||||
UserAgent: "test",
|
||||
},
|
||||
expected: "anon-session:580605320245e8289e0b301074a027c3",
|
||||
},
|
||||
{
|
||||
name: "should hash correctly with different user agent",
|
||||
session: &Device{
|
||||
ip: "10.10.10.1",
|
||||
userAgent: "test2",
|
||||
Kind: anonymous.AnonDevice,
|
||||
IP: "10.10.10.1",
|
||||
UserAgent: "test2",
|
||||
},
|
||||
expected: "anon-session:5fdd04b0bd04a9fa77c4243f8111258b",
|
||||
},
|
||||
@@ -58,75 +64,149 @@ func TestAnonDeviceKey(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestIntegrationAnonDeviceService_tag(t *testing.T) {
|
||||
func TestIntegrationDeviceService_tag(t *testing.T) {
|
||||
type tagReq struct {
|
||||
httpReq *http.Request
|
||||
kind anonymous.DeviceKind
|
||||
}
|
||||
testCases := []struct {
|
||||
name string
|
||||
req []*http.Request
|
||||
expectedCount int64
|
||||
name string
|
||||
req []tagReq
|
||||
expectedAnonCount int64
|
||||
expectedAuthedCount int64
|
||||
expectedDevice *Device
|
||||
}{
|
||||
{
|
||||
name: "no requests",
|
||||
req: []*http.Request{},
|
||||
expectedCount: 0,
|
||||
name: "no requests",
|
||||
req: []tagReq{{httpReq: &http.Request{}, kind: anonymous.AnonDevice}},
|
||||
expectedAnonCount: 0,
|
||||
expectedAuthedCount: 0,
|
||||
},
|
||||
{
|
||||
name: "missing info should not tag",
|
||||
req: []*http.Request{
|
||||
{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
},
|
||||
req: []tagReq{{httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
},
|
||||
},
|
||||
expectedCount: 0,
|
||||
kind: anonymous.AnonDevice,
|
||||
}},
|
||||
expectedAnonCount: 0,
|
||||
expectedAuthedCount: 0,
|
||||
},
|
||||
{
|
||||
name: "should tag once",
|
||||
req: []*http.Request{
|
||||
{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
req: []tagReq{{httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
expectedCount: 1,
|
||||
kind: anonymous.AnonDevice,
|
||||
},
|
||||
},
|
||||
expectedAnonCount: 1,
|
||||
expectedAuthedCount: 0,
|
||||
expectedDevice: &Device{
|
||||
Kind: anonymous.AnonDevice,
|
||||
IP: "10.30.30.1",
|
||||
UserAgent: "test"},
|
||||
},
|
||||
{
|
||||
name: "repeat request should not tag",
|
||||
req: []*http.Request{
|
||||
{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
req: []tagReq{{httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
expectedCount: 1,
|
||||
kind: anonymous.AnonDevice,
|
||||
}, {httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
kind: anonymous.AnonDevice,
|
||||
},
|
||||
},
|
||||
expectedAnonCount: 1,
|
||||
expectedAuthedCount: 0,
|
||||
}, {
|
||||
name: "authed request should untag anon",
|
||||
req: []tagReq{{httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
kind: anonymous.AnonDevice,
|
||||
}, {httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
kind: anonymous.AuthedDevice,
|
||||
},
|
||||
},
|
||||
expectedAnonCount: 0,
|
||||
expectedAuthedCount: 1,
|
||||
}, {
|
||||
name: "anon request should untag authed",
|
||||
req: []tagReq{{httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
kind: anonymous.AuthedDevice,
|
||||
}, {httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
kind: anonymous.AnonDevice,
|
||||
},
|
||||
},
|
||||
expectedAnonCount: 1,
|
||||
expectedAuthedCount: 0,
|
||||
},
|
||||
{
|
||||
name: "tag 2 different requests",
|
||||
req: []*http.Request{
|
||||
{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.2"},
|
||||
},
|
||||
name: "tag 4 different requests",
|
||||
req: []tagReq{{httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.1"},
|
||||
},
|
||||
},
|
||||
expectedCount: 2,
|
||||
kind: anonymous.AnonDevice,
|
||||
}, {httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.2"},
|
||||
},
|
||||
},
|
||||
kind: anonymous.AnonDevice,
|
||||
}, {httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.3"},
|
||||
},
|
||||
},
|
||||
kind: anonymous.AuthedDevice,
|
||||
}, {httpReq: &http.Request{
|
||||
Header: http.Header{
|
||||
"User-Agent": []string{"test"},
|
||||
"X-Forwarded-For": []string{"10.30.30.4"},
|
||||
},
|
||||
},
|
||||
kind: anonymous.AuthedDevice,
|
||||
},
|
||||
},
|
||||
expectedAnonCount: 2,
|
||||
expectedAuthedCount: 2,
|
||||
},
|
||||
}
|
||||
|
||||
@@ -137,14 +217,32 @@ func TestIntegrationAnonDeviceService_tag(t *testing.T) {
|
||||
anonService := ProvideAnonymousDeviceService(fakeStore, &usagestats.UsageStatsMock{})
|
||||
|
||||
for _, req := range tc.req {
|
||||
err := anonService.TagDevice(context.Background(), req)
|
||||
err := anonService.TagDevice(context.Background(), req.httpReq, req.kind)
|
||||
require.NoError(t, err)
|
||||
}
|
||||
|
||||
stats, err := anonService.usageStatFn(context.Background())
|
||||
require.NoError(t, err)
|
||||
|
||||
assert.Equal(t, tc.expectedCount, stats["stats.anonymous.session.count"].(int64))
|
||||
assert.Equal(t, tc.expectedAnonCount, stats["stats.anonymous.session.count"].(int64))
|
||||
assert.Equal(t, tc.expectedAuthedCount, stats["stats.users.device.count"].(int64))
|
||||
|
||||
if tc.expectedDevice != nil {
|
||||
key, err := tc.expectedDevice.Key()
|
||||
require.NoError(t, err)
|
||||
|
||||
k, err := fakeStore.Get(context.Background(), key)
|
||||
require.NoError(t, err)
|
||||
|
||||
gotDevice := &Device{}
|
||||
err = json.Unmarshal(k, gotDevice)
|
||||
require.NoError(t, err)
|
||||
|
||||
assert.NotNil(t, gotDevice.LastSeen)
|
||||
gotDevice.LastSeen = time.Time{}
|
||||
|
||||
assert.Equal(t, tc.expectedDevice, gotDevice)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -162,8 +260,10 @@ func TestIntegrationAnonDeviceService_localCacheSafety(t *testing.T) {
|
||||
}
|
||||
|
||||
anonDevice := &Device{
|
||||
ip: "10.30.30.2",
|
||||
userAgent: "test",
|
||||
Kind: anonymous.AnonDevice,
|
||||
IP: "10.30.30.2",
|
||||
UserAgent: "test",
|
||||
LastSeen: time.Now().UTC(),
|
||||
}
|
||||
|
||||
key, err := anonDevice.Key()
|
||||
@@ -171,7 +271,7 @@ func TestIntegrationAnonDeviceService_localCacheSafety(t *testing.T) {
|
||||
|
||||
anonService.localCache.SetDefault(key, true)
|
||||
|
||||
err = anonService.TagDevice(context.Background(), req)
|
||||
err = anonService.TagDevice(context.Background(), req, anonymous.AnonDevice)
|
||||
require.NoError(t, err)
|
||||
|
||||
stats, err := anonService.usageStatFn(context.Background())
|
||||
|
||||
@@ -3,11 +3,13 @@ package anontest
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
|
||||
"github.com/grafana/grafana/pkg/services/anonymous"
|
||||
)
|
||||
|
||||
type FakeAnonymousSessionService struct {
|
||||
}
|
||||
|
||||
func (f *FakeAnonymousSessionService) TagDevice(ctx context.Context, httpReq *http.Request) error {
|
||||
func (f *FakeAnonymousSessionService) TagDevice(ctx context.Context, httpReq *http.Request, kind anonymous.DeviceKind) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -5,6 +5,13 @@ import (
|
||||
"net/http"
|
||||
)
|
||||
|
||||
type DeviceKind string
|
||||
|
||||
const (
|
||||
AnonDevice DeviceKind = "anon-session"
|
||||
AuthedDevice DeviceKind = "authed-session"
|
||||
)
|
||||
|
||||
type Service interface {
|
||||
TagDevice(context.Context, *http.Request) error
|
||||
TagDevice(context.Context, *http.Request, DeviceKind) error
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user