JWT Authentication: Add support for specifying groups in auth.jwt for teamsync (#82175)
* merge JSON search logic * document public methods * improve test coverage * use separate JWT setting struct * correct use of cfg.JWTAuth * add group tests * fix DynMap typing * add settings to default ini * add groups option to devenv path * fix test * lint * revert jwt-proxy change * remove redundant check * fix parallel test
This commit is contained in:
@@ -1,4 +1,112 @@
|
||||
package util
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
|
||||
"github.com/jmespath/go-jmespath"
|
||||
|
||||
"github.com/grafana/grafana/pkg/util/errutil"
|
||||
)
|
||||
|
||||
// DynMap defines a dynamic map interface.
|
||||
type DynMap map[string]any
|
||||
|
||||
var (
|
||||
// ErrEmptyJSON is an error for empty attribute in JSON.
|
||||
ErrEmptyJSON = errutil.NewBase(errutil.StatusBadRequest,
|
||||
"json-missing-body", errutil.WithPublicMessage("Empty JSON provided"))
|
||||
|
||||
// ErrNoAttributePathSpecified is an error for no attribute path specified.
|
||||
ErrNoAttributePathSpecified = errutil.NewBase(errutil.StatusBadRequest,
|
||||
"json-no-attribute-path-specified", errutil.WithPublicMessage("No attribute path specified"))
|
||||
|
||||
// ErrFailedToUnmarshalJSON is an error for failure in unmarshalling JSON.
|
||||
ErrFailedToUnmarshalJSON = errutil.NewBase(errutil.StatusBadRequest,
|
||||
"json-failed-to-unmarshal", errutil.WithPublicMessage("Failed to unmarshal JSON"))
|
||||
|
||||
// ErrFailedToSearchJSON is an error for failure in searching JSON.
|
||||
ErrFailedToSearchJSON = errutil.NewBase(errutil.StatusBadRequest,
|
||||
"json-failed-to-search", errutil.WithPublicMessage("Failed to search JSON with provided path"))
|
||||
)
|
||||
|
||||
// SearchJSONForStringSliceAttr searches for a slice attribute in a JSON object and returns a string slice.
|
||||
// The attributePath parameter is a string that specifies the path to the attribute.
|
||||
// The data parameter is the JSON object that we're searching. It can be a byte slice or a go type.
|
||||
func SearchJSONForStringSliceAttr(attributePath string, data any) ([]string, error) {
|
||||
val, err := searchJSONForAttr(attributePath, data)
|
||||
if err != nil {
|
||||
return []string{}, err
|
||||
}
|
||||
|
||||
ifArr, ok := val.([]any)
|
||||
if !ok {
|
||||
return []string{}, nil
|
||||
}
|
||||
|
||||
result := []string{}
|
||||
for _, v := range ifArr {
|
||||
if strVal, ok := v.(string); ok {
|
||||
result = append(result, strVal)
|
||||
}
|
||||
}
|
||||
|
||||
return result, nil
|
||||
}
|
||||
|
||||
// SearchJSONForStringAttr searches for a specific attribute in a JSON object and returns a string.
|
||||
// The attributePath parameter is a string that specifies the path to the attribute.
|
||||
// The data parameter is the JSON object that we're searching. It can be a byte slice or a go type.
|
||||
func SearchJSONForStringAttr(attributePath string, data any) (string, error) {
|
||||
val, err := searchJSONForAttr(attributePath, data)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
strVal, ok := val.(string)
|
||||
if ok {
|
||||
return strVal, nil
|
||||
}
|
||||
|
||||
return "", nil
|
||||
}
|
||||
|
||||
// searchJSONForAttr searches for a specific attribute in a JSON object.
|
||||
// The attributePath parameter is a string that specifies the path to the attribute.
|
||||
// The data parameter is the JSON object that we're searching.
|
||||
// The function returns the value of the attribute and an error if one occurred.
|
||||
func searchJSONForAttr(attributePath string, data any) (any, error) {
|
||||
// If no attribute path is specified, return an error
|
||||
if attributePath == "" {
|
||||
return "", ErrNoAttributePathSpecified.Errorf("attribute path: %q", attributePath)
|
||||
}
|
||||
|
||||
// If the data is nil, return an error
|
||||
if data == nil {
|
||||
return "", ErrEmptyJSON.Errorf("empty json, attribute path: %q", attributePath)
|
||||
}
|
||||
|
||||
// Copy the data to a new variable
|
||||
var jsonData = data
|
||||
|
||||
// If the data is a byte slice, try to unmarshal it into a JSON object
|
||||
if dataBytes, ok := data.([]byte); ok {
|
||||
// If the byte slice is empty, return an error
|
||||
if len(dataBytes) == 0 {
|
||||
return "", ErrEmptyJSON.Errorf("empty json, attribute path: %q", attributePath)
|
||||
}
|
||||
|
||||
// Try to unmarshal the byte slice
|
||||
if err := json.Unmarshal(dataBytes, &jsonData); err != nil {
|
||||
return "", ErrFailedToUnmarshalJSON.Errorf("%v: %w", "failed to unmarshal user info JSON response", err)
|
||||
}
|
||||
}
|
||||
|
||||
// Search for the attribute in the JSON object
|
||||
value, err := jmespath.Search(attributePath, jsonData)
|
||||
if err != nil {
|
||||
return "", ErrFailedToSearchJSON.Errorf("failed to search user info JSON response with provided path: %q: %w", attributePath, err)
|
||||
}
|
||||
|
||||
// Return the value and nil error
|
||||
return value, nil
|
||||
}
|
||||
|
||||
@@ -0,0 +1,155 @@
|
||||
package util_test
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"github.com/grafana/grafana/pkg/util"
|
||||
)
|
||||
|
||||
func TestSearchJSONForGroups(t *testing.T) {
|
||||
t.Parallel()
|
||||
tests := []struct {
|
||||
Name string
|
||||
searchObject any
|
||||
GroupsAttributePath string
|
||||
ExpectedResult []string
|
||||
ExpectedError error
|
||||
}{
|
||||
{
|
||||
Name: "Given an invalid user info JSON response",
|
||||
searchObject: []byte("{"),
|
||||
GroupsAttributePath: "attributes.groups",
|
||||
ExpectedResult: []string{},
|
||||
ExpectedError: util.ErrFailedToUnmarshalJSON,
|
||||
},
|
||||
{
|
||||
Name: "Given an empty user info JSON response and empty JMES path",
|
||||
searchObject: []byte{},
|
||||
GroupsAttributePath: "",
|
||||
ExpectedResult: []string{},
|
||||
ExpectedError: util.ErrNoAttributePathSpecified,
|
||||
},
|
||||
{
|
||||
Name: "Given an empty user info JSON response and valid JMES path",
|
||||
searchObject: []byte{},
|
||||
GroupsAttributePath: "attributes.groups",
|
||||
ExpectedResult: []string{},
|
||||
ExpectedError: util.ErrEmptyJSON,
|
||||
},
|
||||
{
|
||||
Name: "Given a nil JSON and valid JMES path",
|
||||
searchObject: []byte{},
|
||||
GroupsAttributePath: "attributes.groups",
|
||||
ExpectedResult: []string{},
|
||||
ExpectedError: util.ErrEmptyJSON,
|
||||
},
|
||||
{
|
||||
Name: "Given a simple user info JSON response and valid JMES path",
|
||||
searchObject: []byte(`{
|
||||
"attributes": {
|
||||
"groups": ["foo", "bar"]
|
||||
}
|
||||
}`),
|
||||
GroupsAttributePath: "attributes.groups[]",
|
||||
ExpectedResult: []string{"foo", "bar"},
|
||||
},
|
||||
{
|
||||
Name: "Given a simple object and valid JMES path",
|
||||
searchObject: map[string]any{
|
||||
"attributes": map[string]any{
|
||||
"groups": []string{"foo", "bar"},
|
||||
},
|
||||
},
|
||||
GroupsAttributePath: "attributes.groups[]",
|
||||
ExpectedResult: []string{"foo", "bar"},
|
||||
},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
test := test
|
||||
t.Run(test.Name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
actualResult, err := util.SearchJSONForStringSliceAttr(
|
||||
test.GroupsAttributePath, test.searchObject)
|
||||
if test.ExpectedError == nil {
|
||||
require.NoError(t, err)
|
||||
} else {
|
||||
require.ErrorIs(t, err, test.ExpectedError)
|
||||
}
|
||||
require.Equal(t, test.ExpectedResult, actualResult)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestSearchJSONForEmail(t *testing.T) {
|
||||
t.Parallel()
|
||||
tests := []struct {
|
||||
Name string
|
||||
UserInfoJSONResponse any
|
||||
EmailAttributePath string
|
||||
ExpectedResult string
|
||||
ExpectedError error
|
||||
}{
|
||||
{
|
||||
Name: "Given a simple user info JSON response and valid JMES path",
|
||||
UserInfoJSONResponse: []byte(`{
|
||||
"attributes": {
|
||||
"email": "grafana@localhost"
|
||||
}
|
||||
}`),
|
||||
EmailAttributePath: "attributes.email",
|
||||
ExpectedResult: "grafana@localhost",
|
||||
},
|
||||
{
|
||||
Name: "Given a simple object and valid JMES path",
|
||||
UserInfoJSONResponse: map[string]any{
|
||||
"attributes": map[string]any{
|
||||
"email": "grafana@localhost",
|
||||
},
|
||||
},
|
||||
EmailAttributePath: "attributes.email",
|
||||
ExpectedResult: "grafana@localhost",
|
||||
},
|
||||
{
|
||||
Name: "Given a user info JSON response with e-mails array and valid JMES path",
|
||||
UserInfoJSONResponse: []byte(`{
|
||||
"attributes": {
|
||||
"emails": ["grafana@localhost", "admin@localhost"]
|
||||
}
|
||||
}`),
|
||||
EmailAttributePath: "attributes.emails[0]",
|
||||
ExpectedResult: "grafana@localhost",
|
||||
},
|
||||
{
|
||||
Name: "Given a nested user info JSON response and valid JMES path",
|
||||
UserInfoJSONResponse: []byte(`{
|
||||
"identities": [
|
||||
{
|
||||
"userId": "grafana@localhost"
|
||||
},
|
||||
{
|
||||
"userId": "admin@localhost"
|
||||
}
|
||||
]
|
||||
}`),
|
||||
EmailAttributePath: "identities[0].userId",
|
||||
ExpectedResult: "grafana@localhost",
|
||||
},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
test := test
|
||||
t.Run(test.Name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
actualResult, err := util.SearchJSONForStringAttr(test.EmailAttributePath, test.UserInfoJSONResponse)
|
||||
if test.ExpectedError != nil {
|
||||
require.NoError(t, err)
|
||||
} else {
|
||||
require.ErrorIs(t, err, test.ExpectedError)
|
||||
}
|
||||
require.Equal(t, test.ExpectedResult, actualResult)
|
||||
})
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user