Access control: allow using targetOrgId parameter to set organization ID for a request (#41761)

* read target org ID in context handler

* simplify test

* add test for request body not being read in ctx handler

* linting fix
This commit is contained in:
Ieva
2021-11-17 16:11:56 +01:00
committed by GitHub
parent d623285fcc
commit c426f5673b
2 changed files with 68 additions and 0 deletions
@@ -4,6 +4,7 @@ package contexthandler
import (
"context"
"errors"
"net/url"
"strconv"
"strings"
"time"
@@ -105,6 +106,19 @@ func (h *ContextHandler) Middleware(mContext *web.Context) {
}
}
queryParameters, err := url.ParseQuery(reqContext.Req.URL.RawQuery)
if err != nil {
reqContext.Logger.Error("Failed to parse query parameters", "error", err)
}
if queryParameters.Has("targetOrgId") {
targetOrg, err := strconv.ParseInt(queryParameters.Get("targetOrgId"), 10, 64)
if err == nil {
orgID = targetOrg
} else {
reqContext.Logger.Error("Invalid target organization ID", "error", err)
}
}
// the order in which these are tested are important
// look for api key in Authorization header first
// then init session and look for userId in session