Authlib: Update authz client to use zookies (#111291)
* Authlib: Update authz client to use zookies * fix zookie return * fix linter
This commit is contained in:
@@ -6,6 +6,7 @@ import (
|
||||
"fmt"
|
||||
|
||||
claims "github.com/grafana/authlib/types"
|
||||
|
||||
"github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/utils"
|
||||
)
|
||||
@@ -142,24 +143,24 @@ func (c *LegacyAccessClient) Check(ctx context.Context, id claims.AuthInfo, req
|
||||
return claims.CheckResponse{Allowed: allowed}, nil
|
||||
}
|
||||
|
||||
func (c *LegacyAccessClient) Compile(ctx context.Context, id claims.AuthInfo, req claims.ListRequest) (claims.ItemChecker, error) {
|
||||
func (c *LegacyAccessClient) Compile(ctx context.Context, id claims.AuthInfo, req claims.ListRequest) (claims.ItemChecker, claims.Zookie, error) {
|
||||
ident, ok := id.(identity.Requester)
|
||||
if !ok {
|
||||
return nil, errors.New("expected identity.Requester for legacy access control")
|
||||
return nil, claims.NoopZookie{}, errors.New("expected identity.Requester for legacy access control")
|
||||
}
|
||||
|
||||
opts, ok := c.opts[req.Resource]
|
||||
if !ok {
|
||||
return nil, fmt.Errorf("unsupported resource: %s", req.Resource)
|
||||
return nil, claims.NoopZookie{}, fmt.Errorf("unsupported resource: %s", req.Resource)
|
||||
}
|
||||
|
||||
action, ok := opts.Mapping[utils.VerbList]
|
||||
if !ok {
|
||||
return nil, fmt.Errorf("missing action for %s %s", utils.VerbList, req.Resource)
|
||||
return nil, claims.NoopZookie{}, fmt.Errorf("missing action for %s %s", utils.VerbList, req.Resource)
|
||||
}
|
||||
|
||||
check := Checker(ident, action)
|
||||
return func(name, _ string) bool {
|
||||
return check(fmt.Sprintf("%s:%s:%s", opts.Resource, opts.Attr, name))
|
||||
}, nil
|
||||
}, claims.NoopZookie{}, nil
|
||||
}
|
||||
|
||||
@@ -43,7 +43,7 @@ func (c *Client) Check(ctx context.Context, id authlib.AuthInfo, req authlib.Che
|
||||
return c.authzlibclient.Check(ctx, id, req)
|
||||
}
|
||||
|
||||
func (c *Client) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, error) {
|
||||
func (c *Client) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, authlib.Zookie, error) {
|
||||
ctx, span := tracer.Start(ctx, "authlib.zanzana.client.Compile")
|
||||
defer span.End()
|
||||
|
||||
|
||||
@@ -4,6 +4,7 @@ import (
|
||||
"context"
|
||||
|
||||
authlib "github.com/grafana/authlib/types"
|
||||
|
||||
authzextv1 "github.com/grafana/grafana/pkg/services/authz/proto/v1"
|
||||
)
|
||||
|
||||
@@ -19,8 +20,8 @@ func (nc *NoopClient) Check(ctx context.Context, id authlib.AuthInfo, req authli
|
||||
return authlib.CheckResponse{}, nil
|
||||
}
|
||||
|
||||
func (nc *NoopClient) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, error) {
|
||||
return nil, nil
|
||||
func (nc *NoopClient) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, authlib.Zookie, error) {
|
||||
return nil, authlib.NoopZookie{}, nil
|
||||
}
|
||||
|
||||
func (nc NoopClient) Read(ctx context.Context, req *authzextv1.ReadRequest) (*authzextv1.ReadResponse, error) {
|
||||
|
||||
@@ -9,6 +9,8 @@ import (
|
||||
"github.com/grafana/grafana/pkg/infra/log"
|
||||
)
|
||||
|
||||
var _ authlib.AccessClient = (*ShadowClient)(nil)
|
||||
|
||||
type ShadowClient struct {
|
||||
logger log.Logger
|
||||
accessClient authlib.AccessClient
|
||||
@@ -67,7 +69,7 @@ func (c *ShadowClient) Check(ctx context.Context, id authlib.AuthInfo, req authl
|
||||
return res, err
|
||||
}
|
||||
|
||||
func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, error) {
|
||||
func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req authlib.ListRequest) (authlib.ItemChecker, authlib.Zookie, error) {
|
||||
zanzanaItemCheckerChan := make(chan authlib.ItemChecker, 1)
|
||||
go func() {
|
||||
if c.zanzanaClient == nil {
|
||||
@@ -76,7 +78,7 @@ func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req aut
|
||||
}
|
||||
|
||||
timer := prometheus.NewTimer(c.metrics.compileSeconds.WithLabelValues("zanzana"))
|
||||
itemChecker, err := c.zanzanaClient.Compile(ctx, id, req)
|
||||
itemChecker, _, err := c.zanzanaClient.Compile(ctx, id, req)
|
||||
timer.ObserveDuration()
|
||||
if err != nil {
|
||||
c.logger.Warn("Failed to compile zanzana item checker", "error", err)
|
||||
@@ -85,10 +87,10 @@ func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req aut
|
||||
}()
|
||||
|
||||
timer := prometheus.NewTimer(c.metrics.compileSeconds.WithLabelValues("rbac"))
|
||||
rbacItemChecker, err := c.accessClient.Compile(ctx, id, req)
|
||||
rbacItemChecker, _, err := c.accessClient.Compile(ctx, id, req)
|
||||
timer.ObserveDuration()
|
||||
if err != nil {
|
||||
return nil, err
|
||||
return nil, authlib.NoopZookie{}, err
|
||||
}
|
||||
|
||||
zanzanaItemChecker := <-zanzanaItemCheckerChan
|
||||
@@ -107,5 +109,5 @@ func (c *ShadowClient) Compile(ctx context.Context, id authlib.AuthInfo, req aut
|
||||
return rbacRes
|
||||
}
|
||||
|
||||
return shadowItemChecker, err
|
||||
return shadowItemChecker, authlib.NoopZookie{}, err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user