Identity: Remove typed id (#91801)
* Refactor identity struct to store type in separate field * Update ResolveIdentity to take string representation of typedID * Add IsIdentityType to requester interface * Use IsIdentityType from interface * Remove usage of TypedID * Remote typedID struct * fix GetInternalID
This commit is contained in:
@@ -8,7 +8,6 @@ import (
|
||||
|
||||
"github.com/grafana/authlib/claims"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/errutil"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
"github.com/grafana/grafana/pkg/infra/log"
|
||||
"github.com/grafana/grafana/pkg/services/anonymous"
|
||||
"github.com/grafana/grafana/pkg/services/anonymous/anonimpl/anonstore"
|
||||
@@ -74,7 +73,7 @@ func (a *Anonymous) IdentityType() claims.IdentityType {
|
||||
return claims.TypeAnonymous
|
||||
}
|
||||
|
||||
func (a *Anonymous) ResolveIdentity(ctx context.Context, orgID int64, namespaceID identity.TypedID) (*authn.Identity, error) {
|
||||
func (a *Anonymous) ResolveIdentity(ctx context.Context, orgID int64, typ claims.IdentityType, id string) (*authn.Identity, error) {
|
||||
o, err := a.orgService.GetByName(ctx, &org.GetOrgByNameQuery{Name: a.cfg.AnonymousOrgName})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
@@ -85,7 +84,7 @@ func (a *Anonymous) ResolveIdentity(ctx context.Context, orgID int64, namespaceI
|
||||
}
|
||||
|
||||
// Anonymous identities should always have the same namespace id.
|
||||
if namespaceID != identity.AnonymousTypedID {
|
||||
if !claims.IsIdentityType(typ, claims.TypeAnonymous) || id != "0" {
|
||||
return nil, errInvalidID
|
||||
}
|
||||
|
||||
@@ -110,7 +109,8 @@ func (a *Anonymous) Priority() uint {
|
||||
|
||||
func (a *Anonymous) newAnonymousIdentity(o *org.Org) *authn.Identity {
|
||||
return &authn.Identity{
|
||||
ID: identity.AnonymousTypedID,
|
||||
ID: "0",
|
||||
Type: claims.TypeAnonymous,
|
||||
OrgID: o.ID,
|
||||
OrgName: o.Name,
|
||||
OrgRoles: map[int64]org.RoleType{o.ID: org.RoleType(a.cfg.AnonymousOrgRole)},
|
||||
|
||||
@@ -8,7 +8,7 @@ import (
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
"github.com/grafana/authlib/claims"
|
||||
"github.com/grafana/grafana/pkg/infra/log"
|
||||
"github.com/grafana/grafana/pkg/services/anonymous/anontest"
|
||||
"github.com/grafana/grafana/pkg/services/authn"
|
||||
@@ -60,7 +60,7 @@ func TestAnonymous_Authenticate(t *testing.T) {
|
||||
} else {
|
||||
require.Nil(t, err)
|
||||
|
||||
assert.Equal(t, identity.AnonymousTypedID, user.ID)
|
||||
assert.Equal(t, "anonymous:0", user.GetID())
|
||||
assert.Equal(t, tt.org.ID, user.OrgID)
|
||||
assert.Equal(t, tt.org.Name, user.OrgName)
|
||||
assert.Equal(t, tt.cfg.AnonymousOrgRole, string(user.GetOrgRole()))
|
||||
@@ -74,7 +74,8 @@ func TestAnonymous_ResolveIdentity(t *testing.T) {
|
||||
desc string
|
||||
cfg *setting.Cfg
|
||||
orgID int64
|
||||
namespaceID identity.TypedID
|
||||
typ claims.IdentityType
|
||||
id string
|
||||
org *org.Org
|
||||
orgErr error
|
||||
expectedErr error
|
||||
@@ -88,7 +89,8 @@ func TestAnonymous_ResolveIdentity(t *testing.T) {
|
||||
AnonymousOrgName: "some org",
|
||||
},
|
||||
orgID: 1,
|
||||
namespaceID: identity.AnonymousTypedID,
|
||||
typ: claims.TypeAnonymous,
|
||||
id: "0",
|
||||
expectedErr: errInvalidOrg,
|
||||
},
|
||||
{
|
||||
@@ -98,7 +100,8 @@ func TestAnonymous_ResolveIdentity(t *testing.T) {
|
||||
AnonymousOrgName: "some org",
|
||||
},
|
||||
orgID: 1,
|
||||
namespaceID: identity.MustParseTypedID("anonymous:1"),
|
||||
typ: claims.TypeAnonymous,
|
||||
id: "1",
|
||||
expectedErr: errInvalidID,
|
||||
},
|
||||
{
|
||||
@@ -107,8 +110,9 @@ func TestAnonymous_ResolveIdentity(t *testing.T) {
|
||||
cfg: &setting.Cfg{
|
||||
AnonymousOrgName: "some org",
|
||||
},
|
||||
orgID: 1,
|
||||
namespaceID: identity.AnonymousTypedID,
|
||||
orgID: 1,
|
||||
typ: claims.TypeAnonymous,
|
||||
id: "0",
|
||||
},
|
||||
}
|
||||
|
||||
@@ -121,7 +125,7 @@ func TestAnonymous_ResolveIdentity(t *testing.T) {
|
||||
anonDeviceService: anontest.NewFakeService(),
|
||||
}
|
||||
|
||||
identity, err := c.ResolveIdentity(context.Background(), tt.orgID, tt.namespaceID)
|
||||
identity, err := c.ResolveIdentity(context.Background(), tt.orgID, tt.typ, tt.id)
|
||||
if tt.expectedErr != nil {
|
||||
assert.ErrorIs(t, err, tt.expectedErr)
|
||||
assert.Nil(t, identity)
|
||||
|
||||
Reference in New Issue
Block a user