[v10.1.x] AuthProxy: Fix user retrieval through cache (#73824)
AuthProxy: Fix user retrieval through cache (#73802)
* AuthProxy: Change auth proxy sync cache key
(cherry picked from commit 5d14b6ba19)
Co-authored-by: Karl Persson <kalle.persson@grafana.com>
This commit is contained in:
co-authored by
Karl Persson
parent
75923bf476
commit
b124a2de3f
@@ -2,12 +2,12 @@ package clients
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"encoding/binary"
|
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
"fmt"
|
"fmt"
|
||||||
"hash/fnv"
|
"hash/fnv"
|
||||||
"net"
|
"net"
|
||||||
"path"
|
"path"
|
||||||
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
@@ -26,7 +26,7 @@ const (
|
|||||||
proxyFieldLogin = "Login"
|
proxyFieldLogin = "Login"
|
||||||
proxyFieldRole = "Role"
|
proxyFieldRole = "Role"
|
||||||
proxyFieldGroups = "Groups"
|
proxyFieldGroups = "Groups"
|
||||||
proxyCachePrefix = "auth-proxy-sync-ttl"
|
proxyCachePrefix = "authn-proxy-sync-ttl"
|
||||||
)
|
)
|
||||||
|
|
||||||
var proxyFields = [...]string{proxyFieldName, proxyFieldEmail, proxyFieldLogin, proxyFieldRole, proxyFieldGroups}
|
var proxyFields = [...]string{proxyFieldName, proxyFieldEmail, proxyFieldLogin, proxyFieldRole, proxyFieldGroups}
|
||||||
@@ -85,22 +85,25 @@ func (c *Proxy) Authenticate(ctx context.Context, r *authn.Request) (*authn.Iden
|
|||||||
// See if we have cached the user id, in that case we can fetch the signed-in user and skip sync.
|
// See if we have cached the user id, in that case we can fetch the signed-in user and skip sync.
|
||||||
// Error here means that we could not find anything in cache, so we can proceed as usual
|
// Error here means that we could not find anything in cache, so we can proceed as usual
|
||||||
if entry, err := c.cache.Get(ctx, cacheKey); err == nil {
|
if entry, err := c.cache.Get(ctx, cacheKey); err == nil {
|
||||||
uid := int64(binary.LittleEndian.Uint64(entry))
|
uid, err := strconv.ParseInt(string(entry), 10, 64)
|
||||||
|
|
||||||
usr, err := c.userSrv.GetSignedInUserWithCacheCtx(ctx, &user.GetSignedInUserQuery{
|
|
||||||
UserID: uid,
|
|
||||||
OrgID: r.OrgID,
|
|
||||||
})
|
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
c.log.FromContext(ctx).Warn("Could not resolved cached user", "error", err, "userId", string(entry))
|
c.log.FromContext(ctx).Warn("failed to parse user id from cache", "error", err, "userId", string(entry))
|
||||||
}
|
} else {
|
||||||
|
usr, err := c.userSrv.GetSignedInUserWithCacheCtx(ctx, &user.GetSignedInUserQuery{
|
||||||
|
UserID: uid,
|
||||||
|
OrgID: r.OrgID,
|
||||||
|
})
|
||||||
|
|
||||||
// if we for some reason cannot find the user we proceed with the normal flow, authenticate with ProxyClient
|
if err != nil {
|
||||||
// and perform syncs
|
c.log.FromContext(ctx).Warn("Could not resolved cached user", "error", err, "userId", string(entry))
|
||||||
if usr != nil {
|
}
|
||||||
c.log.FromContext(ctx).Debug("User was loaded from cache, skip syncs", "userId", usr.UserID)
|
|
||||||
return authn.IdentityFromSignedInUser(authn.NamespacedID(authn.NamespaceUser, usr.UserID), usr, authn.ClientParams{SyncPermissions: true}, login.AuthProxyAuthModule), nil
|
// if we for some reason cannot find the user we proceed with the normal flow, authenticate with ProxyClient
|
||||||
|
// and perform syncs
|
||||||
|
if usr != nil {
|
||||||
|
c.log.FromContext(ctx).Debug("User was loaded from cache, skip syncs", "userId", usr.UserID)
|
||||||
|
return authn.IdentityFromSignedInUser(authn.NamespacedID(authn.NamespaceUser, usr.UserID), usr, authn.ClientParams{SyncPermissions: true}, login.AuthProxyAuthModule), nil
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -137,8 +140,7 @@ func (c *Proxy) Hook(ctx context.Context, identity *authn.Identity, r *authn.Req
|
|||||||
}
|
}
|
||||||
|
|
||||||
c.log.FromContext(ctx).Debug("Cache proxy user", "userId", id)
|
c.log.FromContext(ctx).Debug("Cache proxy user", "userId", id)
|
||||||
bytes := make([]byte, 8)
|
bytes := []byte(strconv.FormatInt(id, 10))
|
||||||
binary.LittleEndian.PutUint64(bytes, uint64(id))
|
|
||||||
if err := c.cache.Set(ctx, identity.ClientParams.CacheAuthProxyKey, bytes, time.Duration(c.cfg.AuthProxySyncTTL)*time.Minute); err != nil {
|
if err := c.cache.Set(ctx, identity.ClientParams.CacheAuthProxyKey, bytes, time.Duration(c.cfg.AuthProxySyncTTL)*time.Minute); err != nil {
|
||||||
c.log.Warn("failed to cache proxy user", "error", err, "userId", id)
|
c.log.Warn("failed to cache proxy user", "error", err, "userId", id)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user