AuthN: Set uid during authentication (#87797)

* Identity: Remove GetNamespacedUID and use GetUID instead

* Authn: Set uid for users and service accounts
This commit is contained in:
Karl Persson
2024-05-14 14:13:50 +02:00
committed by GitHub
parent 6836bfe1ea
commit 9977258d04
9 changed files with 70 additions and 86 deletions
+10 -1
View File
@@ -364,7 +364,7 @@ func (s *UserSync) lookupByOneOf(ctx context.Context, params login.UserLookupPar
var err error
// If not found, try to find the user by email address
if usr == nil && params.Email != nil && *params.Email != "" {
if params.Email != nil && *params.Email != "" {
usr, err = s.userService.GetByEmail(ctx, &user.GetUserByEmailQuery{Email: *params.Email})
if err != nil && !errors.Is(err, user.ErrUserNotFound) {
return nil, err
@@ -390,6 +390,7 @@ func (s *UserSync) lookupByOneOf(ctx context.Context, params login.UserLookupPar
// This is used to update the identity with the latest user information.
func syncUserToIdentity(usr *user.User, id *authn.Identity) {
id.ID = authn.NewNamespaceID(authn.NamespaceUser, usr.ID)
id.UID = authn.NewNamespaceIDString(authn.NamespaceUser, usr.UID)
id.Login = usr.Login
id.Email = usr.Email
id.Name = usr.Name
@@ -399,6 +400,14 @@ func syncUserToIdentity(usr *user.User, id *authn.Identity) {
// syncSignedInUserToIdentity syncs a user to an identity.
func syncSignedInUserToIdentity(usr *user.SignedInUser, identity *authn.Identity) {
var ns authn.Namespace
if identity.ID.IsNamespace(authn.NamespaceServiceAccount) {
ns = authn.NamespaceServiceAccount
} else {
ns = authn.NamespaceUser
}
identity.UID = authn.NewNamespaceIDString(ns, usr.UserUID)
identity.Name = usr.Name
identity.Login = usr.Login
identity.Email = usr.Email
@@ -47,6 +47,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
userService := &usertest.FakeUserService{ExpectedUser: &user.User{
ID: 1,
UID: "1",
Login: "test",
Name: "test",
Email: "test",
@@ -54,6 +55,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
userServiceMod := &usertest.FakeUserService{ExpectedUser: &user.User{
ID: 3,
UID: "3",
Login: "test",
Name: "test",
Email: "test",
@@ -63,6 +65,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
userServiceEmailMod := &usertest.FakeUserService{ExpectedUser: &user.User{
ID: 3,
UID: "3",
Login: "test",
Name: "test",
Email: "test@test.com",
@@ -76,6 +79,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
CreateFn: func(ctx context.Context, cmd *user.CreateUserCommand) (*user.User, error) {
return &user.User{
ID: 2,
UID: "2",
Login: cmd.Login,
Name: cmd.Name,
Email: cmd.Email,
@@ -159,6 +163,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
wantErr: false,
wantID: &authn.Identity{
ID: authn.MustParseNamespaceID("user:1"),
UID: authn.MustParseNamespaceID("user:1"),
Login: "test",
Name: "test",
Email: "test",
@@ -197,6 +202,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
wantErr: false,
wantID: &authn.Identity{
ID: authn.MustParseNamespaceID("user:1"),
UID: authn.MustParseNamespaceID("user:1"),
Login: "test",
Name: "test",
Email: "test",
@@ -237,6 +243,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
wantErr: false,
wantID: &authn.Identity{
ID: authn.MustParseNamespaceID("user:1"),
UID: authn.MustParseNamespaceID("user:1"),
AuthID: "2032",
AuthenticatedBy: "oauth",
Login: "test",
@@ -308,6 +315,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
wantErr: false,
wantID: &authn.Identity{
ID: authn.MustParseNamespaceID("user:2"),
UID: authn.MustParseNamespaceID("user:2"),
Login: "test_create",
Name: "test_create",
Email: "test_create",
@@ -353,6 +361,7 @@ func TestUserSync_SyncUserHook(t *testing.T) {
wantErr: false,
wantID: &authn.Identity{
ID: authn.MustParseNamespaceID("user:3"),
UID: authn.MustParseNamespaceID("user:3"),
Login: "test_mod",
Name: "test_mod",
Email: "test_mod",
@@ -397,8 +406,9 @@ func TestUserSync_SyncUserHook(t *testing.T) {
wantErr: false,
wantID: &authn.Identity{
ID: authn.MustParseNamespaceID("user:3"),
Login: "test",
UID: authn.MustParseNamespaceID("user:3"),
Name: "test",
Login: "test",
Email: "test_mod@test.com",
IsDisabled: false,
EmailVerified: false,