[v9.3.x] Auth: Fix catch both both ErrInvalidAPIKey for context with APIKey (#62206)
Auth: Fix catch both both ErrInvalidAPIKey for context with APIKey (#62193)
* fix: capture both ErrInvalidAPIKey
* rename of variable
(cherry picked from commit c5cb5be3cc)
Co-authored-by: Eric Leijonmarck <eric.leijonmarck@gmail.com>
This commit is contained in:
co-authored by
Eric Leijonmarck
parent
4da046bde5
commit
7ee08a5c50
@@ -285,13 +285,13 @@ func (h *ContextHandler) initContextWithAPIKey(reqContext *models.ReqContext) bo
|
|||||||
*reqContext.Req = *reqContext.Req.WithContext(ctx)
|
*reqContext.Req = *reqContext.Req.WithContext(ctx)
|
||||||
|
|
||||||
var (
|
var (
|
||||||
apikey *apikey.APIKey
|
apiKey *apikey.APIKey
|
||||||
errKey error
|
errKey error
|
||||||
)
|
)
|
||||||
if strings.HasPrefix(keyString, apikeygenprefix.GrafanaPrefix) {
|
if strings.HasPrefix(keyString, apikeygenprefix.GrafanaPrefix) {
|
||||||
apikey, errKey = h.getPrefixedAPIKey(reqContext.Req.Context(), keyString) // decode prefixed key
|
apiKey, errKey = h.getPrefixedAPIKey(reqContext.Req.Context(), keyString) // decode prefixed key
|
||||||
} else {
|
} else {
|
||||||
apikey, errKey = h.getAPIKey(reqContext.Req.Context(), keyString) // decode legacy api key
|
apiKey, errKey = h.getAPIKey(reqContext.Req.Context(), keyString) // decode legacy api key
|
||||||
}
|
}
|
||||||
|
|
||||||
if errKey != nil {
|
if errKey != nil {
|
||||||
@@ -299,6 +299,11 @@ func (h *ContextHandler) initContextWithAPIKey(reqContext *models.ReqContext) bo
|
|||||||
if errors.Is(errKey, apikeygen.ErrInvalidApiKey) {
|
if errors.Is(errKey, apikeygen.ErrInvalidApiKey) {
|
||||||
status = http.StatusUnauthorized
|
status = http.StatusUnauthorized
|
||||||
}
|
}
|
||||||
|
// this is when the getPrefixAPIKey return error form the apikey package instead of the apikeygen
|
||||||
|
// when called in the sqlx store methods
|
||||||
|
if errors.Is(errKey, apikey.ErrInvalid) {
|
||||||
|
status = http.StatusUnauthorized
|
||||||
|
}
|
||||||
reqContext.JsonApiErr(status, InvalidAPIKey, errKey)
|
reqContext.JsonApiErr(status, InvalidAPIKey, errKey)
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
@@ -308,12 +313,12 @@ func (h *ContextHandler) initContextWithAPIKey(reqContext *models.ReqContext) bo
|
|||||||
if getTime == nil {
|
if getTime == nil {
|
||||||
getTime = time.Now
|
getTime = time.Now
|
||||||
}
|
}
|
||||||
if apikey.Expires != nil && *apikey.Expires <= getTime().Unix() {
|
if apiKey.Expires != nil && *apiKey.Expires <= getTime().Unix() {
|
||||||
reqContext.JsonApiErr(http.StatusUnauthorized, "Expired API key", nil)
|
reqContext.JsonApiErr(http.StatusUnauthorized, "Expired API key", nil)
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
if apikey.IsRevoked != nil && *apikey.IsRevoked {
|
if apiKey.IsRevoked != nil && *apiKey.IsRevoked {
|
||||||
reqContext.JsonApiErr(http.StatusUnauthorized, "Revoked token", nil)
|
reqContext.JsonApiErr(http.StatusUnauthorized, "Revoked token", nil)
|
||||||
|
|
||||||
return true
|
return true
|
||||||
@@ -329,15 +334,15 @@ func (h *ContextHandler) initContextWithAPIKey(reqContext *models.ReqContext) bo
|
|||||||
if err := h.apiKeyService.UpdateAPIKeyLastUsedDate(context.Background(), id); err != nil {
|
if err := h.apiKeyService.UpdateAPIKeyLastUsedDate(context.Background(), id); err != nil {
|
||||||
reqContext.Logger.Warn("failed to update last use date for api key", "id", id)
|
reqContext.Logger.Warn("failed to update last use date for api key", "id", id)
|
||||||
}
|
}
|
||||||
}(apikey.Id)
|
}(apiKey.Id)
|
||||||
|
|
||||||
if apikey.ServiceAccountId == nil || *apikey.ServiceAccountId < 1 { //There is no service account attached to the apikey
|
if apiKey.ServiceAccountId == nil || *apiKey.ServiceAccountId < 1 { //There is no service account attached to the apikey
|
||||||
// Use the old APIkey method. This provides backwards compatibility.
|
// Use the old APIkey method. This provides backwards compatibility.
|
||||||
// will probably have to be supported for a long time.
|
// will probably have to be supported for a long time.
|
||||||
reqContext.SignedInUser = &user.SignedInUser{}
|
reqContext.SignedInUser = &user.SignedInUser{}
|
||||||
reqContext.OrgRole = apikey.Role
|
reqContext.OrgRole = apiKey.Role
|
||||||
reqContext.ApiKeyID = apikey.Id
|
reqContext.ApiKeyID = apiKey.Id
|
||||||
reqContext.OrgID = apikey.OrgId
|
reqContext.OrgID = apiKey.OrgId
|
||||||
reqContext.IsSignedIn = true
|
reqContext.IsSignedIn = true
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
@@ -345,7 +350,7 @@ func (h *ContextHandler) initContextWithAPIKey(reqContext *models.ReqContext) bo
|
|||||||
//There is a service account attached to the API key
|
//There is a service account attached to the API key
|
||||||
|
|
||||||
//Use service account linked to API key as the signed in user
|
//Use service account linked to API key as the signed in user
|
||||||
querySignedInUser := user.GetSignedInUserQuery{UserID: *apikey.ServiceAccountId, OrgID: apikey.OrgId}
|
querySignedInUser := user.GetSignedInUserQuery{UserID: *apiKey.ServiceAccountId, OrgID: apiKey.OrgId}
|
||||||
querySignedInUserResult, err := h.userService.GetSignedInUserWithCacheCtx(reqContext.Req.Context(), &querySignedInUser)
|
querySignedInUserResult, err := h.userService.GetSignedInUserWithCacheCtx(reqContext.Req.Context(), &querySignedInUser)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
reqContext.Logger.Error(
|
reqContext.Logger.Error(
|
||||||
|
|||||||
Reference in New Issue
Block a user