Cfg: Deduplicate DefaultOrgID code (#93588)
Cfg: Expose DefaultOrgID function
This commit is contained in:
@@ -101,7 +101,7 @@ func (s *ExtendedJWT) authenticateAsUser(
|
||||
accessTokenClaims authlib.Claims[authlib.AccessTokenClaims],
|
||||
) (*authn.Identity, error) {
|
||||
// Only allow id tokens signed for namespace configured for this instance.
|
||||
if allowedNamespace := s.namespaceMapper(s.getDefaultOrgID()); !claims.NamespaceMatches(authlib.NewIdentityClaims(idTokenClaims), allowedNamespace) {
|
||||
if allowedNamespace := s.namespaceMapper(s.cfg.DefaultOrgID()); !claims.NamespaceMatches(authlib.NewIdentityClaims(idTokenClaims), allowedNamespace) {
|
||||
return nil, errExtJWTDisallowedNamespaceClaim.Errorf("unexpected id token namespace: %s", idTokenClaims.Rest.Namespace)
|
||||
}
|
||||
|
||||
@@ -138,7 +138,7 @@ func (s *ExtendedJWT) authenticateAsUser(
|
||||
return &authn.Identity{
|
||||
ID: id,
|
||||
Type: t,
|
||||
OrgID: s.getDefaultOrgID(),
|
||||
OrgID: s.cfg.DefaultOrgID(),
|
||||
AccessTokenClaims: &accessTokenClaims,
|
||||
IDTokenClaims: &idTokenClaims,
|
||||
AuthenticatedBy: login.ExtendedJWTModule,
|
||||
@@ -155,7 +155,7 @@ func (s *ExtendedJWT) authenticateAsUser(
|
||||
|
||||
func (s *ExtendedJWT) authenticateAsService(accessTokenClaims authlib.Claims[authlib.AccessTokenClaims]) (*authn.Identity, error) {
|
||||
// Allow access tokens with that has a wildcard namespace or a namespace matching this instance.
|
||||
if allowedNamespace := s.namespaceMapper(s.getDefaultOrgID()); !claims.NamespaceMatches(authlib.NewAccessClaims(accessTokenClaims), allowedNamespace) {
|
||||
if allowedNamespace := s.namespaceMapper(s.cfg.DefaultOrgID()); !claims.NamespaceMatches(authlib.NewAccessClaims(accessTokenClaims), allowedNamespace) {
|
||||
return nil, errExtJWTDisallowedNamespaceClaim.Errorf("unexpected access token namespace: %s", accessTokenClaims.Rest.Namespace)
|
||||
}
|
||||
|
||||
@@ -186,7 +186,7 @@ func (s *ExtendedJWT) authenticateAsService(accessTokenClaims authlib.Claims[aut
|
||||
ID: id,
|
||||
UID: id,
|
||||
Type: t,
|
||||
OrgID: s.getDefaultOrgID(),
|
||||
OrgID: s.cfg.DefaultOrgID(),
|
||||
AccessTokenClaims: &accessTokenClaims,
|
||||
IDTokenClaims: nil,
|
||||
AuthenticatedBy: login.ExtendedJWTModule,
|
||||
@@ -247,11 +247,3 @@ func (s *ExtendedJWT) retrieveAuthorizationToken(httpRequest *http.Request) stri
|
||||
// Strip the 'Bearer' prefix if it exists.
|
||||
return strings.TrimPrefix(jwtToken, "Bearer ")
|
||||
}
|
||||
|
||||
func (s *ExtendedJWT) getDefaultOrgID() int64 {
|
||||
orgID := int64(1)
|
||||
if s.cfg.AutoAssignOrg && s.cfg.AutoAssignOrgId > 0 {
|
||||
orgID = int64(s.cfg.AutoAssignOrgId)
|
||||
}
|
||||
return orgID
|
||||
}
|
||||
|
||||
@@ -20,11 +20,7 @@ func getRoles(cfg *setting.Cfg, extract roleExtractor) (map[int64]org.RoleType,
|
||||
return orgRoles, nil, nil
|
||||
}
|
||||
|
||||
orgID := int64(1)
|
||||
if cfg.AutoAssignOrg && cfg.AutoAssignOrgId > 0 {
|
||||
orgID = int64(cfg.AutoAssignOrgId)
|
||||
}
|
||||
orgRoles[orgID] = role
|
||||
orgRoles[cfg.DefaultOrgID()] = role
|
||||
|
||||
return orgRoles, isGrafanaAdmin, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user