[authn] use authlib client+interceptors for in-proc mode (#93124)
* Add authlib gRPC authenticators for in-proc mode * implement `StaticRequester` signing in the unified resource client - [x] when the `claims.AuthInfo` value type is `identity.StaticRequester`, and there's no ID token set, create an internal token and sign it with symmetrical key. This is a workaround for `go-jose` not offering the possibility to create an unsigned token. - [x] update `IDClaimsWrapper` to support the scenario above - [x] Switch to using `claims.From()` in `dashboardSqlAccess.SaveDashboard()` --------- Co-authored-by: gamab <gabriel.mabille@grafana.com>
This commit is contained in:
co-authored by
gamab
parent
db97da3465
commit
a8b07b0c81
@@ -33,6 +33,7 @@ import (
|
||||
"github.com/grafana/grafana/pkg/services/accesscontrol/ossaccesscontrol"
|
||||
"github.com/grafana/grafana/pkg/services/accesscontrol/resourcepermissions"
|
||||
"github.com/grafana/grafana/pkg/services/apiserver/endpoints/request"
|
||||
"github.com/grafana/grafana/pkg/services/auth/idtest"
|
||||
"github.com/grafana/grafana/pkg/services/datasources"
|
||||
"github.com/grafana/grafana/pkg/services/featuremgmt"
|
||||
"github.com/grafana/grafana/pkg/services/org"
|
||||
@@ -509,6 +510,11 @@ func (c *K8sTestHelper) CreateUser(name string, orgName string, basicRole org.Ro
|
||||
require.Equal(c.t, orgId, s.OrgID)
|
||||
require.Equal(c.t, basicRole, s.OrgRole) // make sure the role was set properly
|
||||
|
||||
idToken, idClaims, err := idtest.CreateInternalToken(s, []byte("secret"))
|
||||
require.NoError(c.t, err)
|
||||
s.IDToken = idToken
|
||||
s.IDTokenClaims = idClaims
|
||||
|
||||
usr := User{
|
||||
Identity: s,
|
||||
password: name,
|
||||
|
||||
Reference in New Issue
Block a user