Auth: Introduce authn.SSOClientConfig to get client config from SSOSettings service (#94618)
* wip * possible solution * Separate interface for SSO settings clients * Rename interface * Fix tests * Rename * Change GetClientConfig to comma ok idiom
This commit is contained in:
@@ -27,9 +27,11 @@ var (
|
||||
errAPIKeyOrgMismatch = errutil.Unauthorized("api-key.organization-mismatch", errutil.WithPublicMessage("API key does not belong to the requested organization"))
|
||||
)
|
||||
|
||||
var _ authn.HookClient = new(APIKey)
|
||||
var _ authn.ContextAwareClient = new(APIKey)
|
||||
var _ authn.IdentityResolverClient = new(APIKey)
|
||||
var (
|
||||
_ authn.HookClient = new(APIKey)
|
||||
_ authn.ContextAwareClient = new(APIKey)
|
||||
_ authn.IdentityResolverClient = new(APIKey)
|
||||
)
|
||||
|
||||
const (
|
||||
metaKeyID = "keyID"
|
||||
|
||||
@@ -150,7 +150,8 @@ func (s *ExtendedJWT) authenticateAsUser(
|
||||
RestrictedActions: accessTokenClaims.Rest.DelegatedPermissions,
|
||||
},
|
||||
FetchSyncedUser: true,
|
||||
}}, nil
|
||||
},
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (s *ExtendedJWT) authenticateAsService(accessTokenClaims authlib.Claims[authlib.AccessTokenClaims]) (*authn.Identity, error) {
|
||||
|
||||
@@ -8,9 +8,7 @@ import (
|
||||
"github.com/grafana/grafana/pkg/web"
|
||||
)
|
||||
|
||||
var (
|
||||
errBadForm = errutil.BadRequest("form-auth.invalid", errutil.WithPublicMessage("bad login data"))
|
||||
)
|
||||
var errBadForm = errutil.BadRequest("form-auth.invalid", errutil.WithPublicMessage("bad login data"))
|
||||
|
||||
var _ authn.Client = new(Form)
|
||||
|
||||
|
||||
@@ -73,7 +73,8 @@ func (s *JWT) Authenticate(ctx context.Context, r *authn.Request) (*authn.Identi
|
||||
SyncOrgRoles: !s.cfg.JWTAuth.SkipOrgRoleSync,
|
||||
AllowSignUp: s.cfg.JWTAuth.AutoSignUp,
|
||||
SyncTeams: s.cfg.JWTAuth.GroupsAttributePath != "",
|
||||
}}
|
||||
},
|
||||
}
|
||||
|
||||
if key := s.cfg.JWTAuth.UsernameClaim; key != "" {
|
||||
id.Login, _ = claims[key].(string)
|
||||
@@ -117,7 +118,6 @@ func (s *JWT) Authenticate(ctx context.Context, r *authn.Request) (*authn.Identi
|
||||
|
||||
return role, &grafanaAdmin, nil
|
||||
})
|
||||
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
@@ -60,8 +60,11 @@ func fromSocialErr(err *connectors.SocialError) error {
|
||||
return errutil.Unauthorized("auth.oauth.userinfo.failed", errutil.WithPublicMessage(err.Error())).Errorf("%w", err)
|
||||
}
|
||||
|
||||
var _ authn.LogoutClient = new(OAuth)
|
||||
var _ authn.RedirectClient = new(OAuth)
|
||||
var (
|
||||
_ authn.LogoutClient = new(OAuth)
|
||||
_ authn.RedirectClient = new(OAuth)
|
||||
_ authn.SSOSettingsAwareClient = new(OAuth)
|
||||
)
|
||||
|
||||
func ProvideOAuth(
|
||||
name string, cfg *setting.Cfg, oauthService oauthtoken.OAuthTokenService,
|
||||
@@ -203,6 +206,15 @@ func (c *OAuth) IsEnabled() bool {
|
||||
return provider.Enabled
|
||||
}
|
||||
|
||||
func (c *OAuth) GetConfig() authn.SSOClientConfig {
|
||||
provider := c.socialService.GetOAuthInfoProvider(c.providerName)
|
||||
if provider == nil {
|
||||
return nil
|
||||
}
|
||||
|
||||
return provider
|
||||
}
|
||||
|
||||
func (c *OAuth) RedirectURL(ctx context.Context, r *authn.Request) (*authn.Redirect, error) {
|
||||
var opts []oauth2.AuthCodeOption
|
||||
|
||||
@@ -274,7 +286,7 @@ func (c *OAuth) Logout(ctx context.Context, user identity.Requester) (*authn.Red
|
||||
return nil, false
|
||||
}
|
||||
|
||||
if isOICDLogout(redirectURL) && token != nil && token.Valid() {
|
||||
if isOIDCLogout(redirectURL) && token != nil && token.Valid() {
|
||||
if idToken, ok := token.Extra("id_token").(string); ok {
|
||||
redirectURL = withIDTokenHint(redirectURL, idToken)
|
||||
}
|
||||
@@ -346,7 +358,7 @@ func withIDTokenHint(redirectURL string, idToken string) string {
|
||||
return u.String()
|
||||
}
|
||||
|
||||
func isOICDLogout(redirectUrl string) bool {
|
||||
func isOIDCLogout(redirectUrl string) bool {
|
||||
if redirectUrl == "" {
|
||||
return false
|
||||
}
|
||||
|
||||
@@ -13,9 +13,7 @@ import (
|
||||
"github.com/grafana/grafana/pkg/services/rendering"
|
||||
)
|
||||
|
||||
var (
|
||||
errInvalidRenderKey = errutil.Unauthorized("render-auth.invalid-key", errutil.WithPublicMessage("Invalid Render Key"))
|
||||
)
|
||||
var errInvalidRenderKey = errutil.Unauthorized("render-auth.invalid-key", errutil.WithPublicMessage("Invalid Render Key"))
|
||||
|
||||
const (
|
||||
renderCookieName = "renderKey"
|
||||
|
||||
Reference in New Issue
Block a user