Authlib: Update authz client to use zookies (#111291)

* Authlib: Update authz client to use zookies

* fix zookie return

* fix linter
This commit is contained in:
Alexander Zobnin
2025-09-18 16:24:22 +02:00
committed by GitHub
parent 0aa5dee86a
commit 72d212c5f9
28 changed files with 89 additions and 81 deletions
+6 -5
View File
@@ -6,6 +6,7 @@ import (
"fmt"
claims "github.com/grafana/authlib/types"
"github.com/grafana/grafana/pkg/apimachinery/identity"
"github.com/grafana/grafana/pkg/apimachinery/utils"
)
@@ -142,24 +143,24 @@ func (c *LegacyAccessClient) Check(ctx context.Context, id claims.AuthInfo, req
return claims.CheckResponse{Allowed: allowed}, nil
}
func (c *LegacyAccessClient) Compile(ctx context.Context, id claims.AuthInfo, req claims.ListRequest) (claims.ItemChecker, error) {
func (c *LegacyAccessClient) Compile(ctx context.Context, id claims.AuthInfo, req claims.ListRequest) (claims.ItemChecker, claims.Zookie, error) {
ident, ok := id.(identity.Requester)
if !ok {
return nil, errors.New("expected identity.Requester for legacy access control")
return nil, claims.NoopZookie{}, errors.New("expected identity.Requester for legacy access control")
}
opts, ok := c.opts[req.Resource]
if !ok {
return nil, fmt.Errorf("unsupported resource: %s", req.Resource)
return nil, claims.NoopZookie{}, fmt.Errorf("unsupported resource: %s", req.Resource)
}
action, ok := opts.Mapping[utils.VerbList]
if !ok {
return nil, fmt.Errorf("missing action for %s %s", utils.VerbList, req.Resource)
return nil, claims.NoopZookie{}, fmt.Errorf("missing action for %s %s", utils.VerbList, req.Resource)
}
check := Checker(ident, action)
return func(name, _ string) bool {
return check(fmt.Sprintf("%s:%s:%s", opts.Resource, opts.Attr, name))
}, nil
}, claims.NoopZookie{}, nil
}
+1 -1
View File
@@ -43,7 +43,7 @@ func (c *Client) Check(ctx context.Context, id authlib.AuthInfo, req authlib.Che
return c.authzlibclient.Check(ctx, id, req)
}
func (c *Client) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, error) {
func (c *Client) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, authlib.Zookie, error) {
ctx, span := tracer.Start(ctx, "authlib.zanzana.client.Compile")
defer span.End()
+3 -2
View File
@@ -4,6 +4,7 @@ import (
"context"
authlib "github.com/grafana/authlib/types"
authzextv1 "github.com/grafana/grafana/pkg/services/authz/proto/v1"
)
@@ -19,8 +20,8 @@ func (nc *NoopClient) Check(ctx context.Context, id authlib.AuthInfo, req authli
return authlib.CheckResponse{}, nil
}
func (nc *NoopClient) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, error) {
return nil, nil
func (nc *NoopClient) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, authlib.Zookie, error) {
return nil, authlib.NoopZookie{}, nil
}
func (nc NoopClient) Read(ctx context.Context, req *authzextv1.ReadRequest) (*authzextv1.ReadResponse, error) {
@@ -9,6 +9,8 @@ import (
"github.com/grafana/grafana/pkg/infra/log"
)
var _ authlib.AccessClient = (*ShadowClient)(nil)
type ShadowClient struct {
logger log.Logger
accessClient authlib.AccessClient
@@ -67,7 +69,7 @@ func (c *ShadowClient) Check(ctx context.Context, id authlib.AuthInfo, req authl
return res, err
}
func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, error) {
func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, authlib.Zookie, error) {
zanzanaItemCheckerChan := make(chan authlib.ItemChecker, 1)
go func() {
if c.zanzanaClient == nil {
@@ -76,7 +78,7 @@ func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req aut
}
timer := prometheus.NewTimer(c.metrics.compileSeconds.WithLabelValues("zanzana"))
itemChecker, err := c.zanzanaClient.Compile(ctx, id, req)
itemChecker, _, err := c.zanzanaClient.Compile(ctx, id, req)
timer.ObserveDuration()
if err != nil {
c.logger.Warn("Failed to compile zanzana item checker", "error", err)
@@ -85,10 +87,10 @@ func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req aut
}()
timer := prometheus.NewTimer(c.metrics.compileSeconds.WithLabelValues("rbac"))
rbacItemChecker, err := c.accessClient.Compile(ctx, id, req)
rbacItemChecker, _, err := c.accessClient.Compile(ctx, id, req)
timer.ObserveDuration()
if err != nil {
return nil, err
return nil, authlib.NoopZookie{}, err
}
zanzanaItemChecker := <-zanzanaItemCheckerChan
@@ -107,5 +109,5 @@ func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req aut
return rbacRes
}
return shadowItemChecker, err
return shadowItemChecker, authlib.NoopZookie{}, err
}