SSO: Add LDAP fallback strategy for SSO settings service (#88905)

* add root and client certificate value fields for LDAP

* update error messages for connection error

* add LDAP fallback strategy for SSO settings service

* fix params for sso service provider

* fix params for sso service provider

* sort imports

* sort imports

* replace json.Number with int64 in config map

* remove type assertions
This commit is contained in:
Mihai Doarna
2024-06-11 10:22:53 +03:00
committed by GitHub
parent d4b0ac5973
commit 3d40caf819
8 changed files with 318 additions and 38 deletions
@@ -18,6 +18,7 @@ import (
ac "github.com/grafana/grafana/pkg/services/accesscontrol"
"github.com/grafana/grafana/pkg/services/auth/identity"
"github.com/grafana/grafana/pkg/services/featuremgmt"
"github.com/grafana/grafana/pkg/services/ldap/service"
"github.com/grafana/grafana/pkg/services/licensing"
"github.com/grafana/grafana/pkg/services/secrets"
"github.com/grafana/grafana/pkg/services/ssosettings"
@@ -47,9 +48,10 @@ type Service struct {
func ProvideService(cfg *setting.Cfg, sqlStore db.DB, ac ac.AccessControl,
routeRegister routing.RouteRegister, features featuremgmt.FeatureToggles,
secrets secrets.Service, usageStats usagestats.Service, registerer prometheus.Registerer,
settingsProvider setting.Provider, licensing licensing.Licensing) *Service {
settingsProvider setting.Provider, licensing licensing.Licensing, ldap service.LDAP) *Service {
fbStrategies := []ssosettings.FallbackStrategy{
strategies.NewOAuthStrategy(cfg),
strategies.NewLDAPStrategy(cfg, ldap),
}
configurableProviders := make(map[string]bool)
@@ -22,6 +22,7 @@ import (
"github.com/grafana/grafana/pkg/services/accesscontrol"
"github.com/grafana/grafana/pkg/services/accesscontrol/acimpl"
"github.com/grafana/grafana/pkg/services/featuremgmt"
"github.com/grafana/grafana/pkg/services/ldap/service"
"github.com/grafana/grafana/pkg/services/licensing/licensingtest"
secretsFakes "github.com/grafana/grafana/pkg/services/secrets/fakes"
"github.com/grafana/grafana/pkg/services/ssosettings"
@@ -1555,7 +1556,7 @@ func Test_ProviderService(t *testing.T) {
"azuread",
"okta",
},
strategiesLength: 1,
strategiesLength: 2,
},
{
name: "should return all fallback strategies and it should return all OAuth providers but not SAML because the licensing feature is enabled but the configurable provider is not setup",
@@ -1569,7 +1570,7 @@ func Test_ProviderService(t *testing.T) {
"azuread",
"okta",
},
strategiesLength: 2,
strategiesLength: 3,
},
{
name: "should return all fallback strategies and it should return all OAuth providers and SAML because the licensing feature is enabled and the provider is setup",
@@ -1585,7 +1586,7 @@ func Test_ProviderService(t *testing.T) {
"okta",
"saml",
},
strategiesLength: 2,
strategiesLength: 3,
},
}
for _, tc := range tests {
@@ -1647,6 +1648,7 @@ func setupTestEnv(t *testing.T, isLicensingEnabled, keepFallbackStratergies, sam
prometheus.NewRegistry(),
&setting.OSSImpl{Cfg: cfg},
licensing,
service.ProvideService(cfg),
)
// overriding values for exposed fields