Auth: Implement Token URL JWT Auth (#52662)
* Auth: check of auth_token in url and resolve user if present * check if auth_token is passed in url * Auth: Pass auth_token for request if present in path * no need to decode token in index * temp * use loadURLToken and set authorization header * cache token in memory and strip it from url * Use loadURLToken * Keep token in url * strip sensitive query strings from url used by context logger * adapt login by url to jwt token * add jwt iframe devenv * add jwt iframe devenv instructions * add access note * add test for cleaning request * ensure jwt token is not carried into handlers * do not reshuffle queries, might be important * add correct db dump location * prefer set token instead of cached token Co-authored-by: Ieva <ieva.vasiljeva@grafana.com> Co-authored-by: Karl Persson <kalle.persson@grafana.com> Co-authored-by: Ieva <ieva.vasiljeva@grafana.com>
This commit is contained in:
@@ -493,6 +493,36 @@ func TestMiddlewareContext(t *testing.T) {
|
||||
sc.exec()
|
||||
})
|
||||
|
||||
middlewareScenario(t, "Request body should not be read in default context handler, but query should be altered - jwt", func(t *testing.T, sc *scenarioContext) {
|
||||
sc.fakeReq("POST", "/?targetOrgId=123&auth_token=token")
|
||||
body := "key=value"
|
||||
sc.req.Body = io.NopCloser(strings.NewReader(body))
|
||||
|
||||
sc.handlerFunc = func(c *models.ReqContext) {
|
||||
t.Log("Handler called")
|
||||
defer func() {
|
||||
err := c.Req.Body.Close()
|
||||
require.NoError(t, err)
|
||||
}()
|
||||
|
||||
require.Equal(t, "", c.Req.URL.Query().Get("auth_token"))
|
||||
|
||||
bodyAfterHandler, e := io.ReadAll(c.Req.Body)
|
||||
require.NoError(t, e)
|
||||
require.Equal(t, body, string(bodyAfterHandler))
|
||||
}
|
||||
|
||||
sc.req.Header.Set(sc.cfg.AuthProxyHeaderName, hdrName)
|
||||
sc.req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
|
||||
sc.req.Header.Set("Content-Length", strconv.Itoa(len(body)))
|
||||
sc.m.Post("/", sc.defaultHandler)
|
||||
sc.exec()
|
||||
}, func(cfg *setting.Cfg) {
|
||||
cfg.JWTAuthEnabled = true
|
||||
cfg.JWTAuthURLLogin = true
|
||||
cfg.JWTAuthHeaderName = "X-WEBAUTH-TOKEN"
|
||||
})
|
||||
|
||||
middlewareScenario(t, "Should get an existing user from header", func(t *testing.T, sc *scenarioContext) {
|
||||
const userID int64 = 12
|
||||
const orgID int64 = 2
|
||||
|
||||
Reference in New Issue
Block a user