Merge pull request #15506 from ioito/automated-cherry-pick-of-#15505-upstream-release-3.10

Automated cherry pick of #15505: fix(cloudid): huawei saml user name
This commit is contained in:
Zexi Li
2022-12-07 22:35:48 +08:00
committed by GitHub
2 changed files with 18 additions and 16 deletions
+13 -12
View File
@@ -1874,51 +1874,52 @@ func (self *SCloudaccount) SyncCloudroles(ctx context.Context, userCred mcclient
return result
}
func (self *SCloudaccount) GetUserCloudgroups(userCred mcclient.TokenCredential) ([]string, error) {
ret := []string{}
func (self *SCloudaccount) GetUserCloudgroups(userCred mcclient.TokenCredential) ([]string, []string, error) {
userNames, groupNames := []string{}, []string{}
q := SamluserManager.Query().Equals("owner_id", userCred.GetUserId()).Equals("cloudaccount_id", self.Id)
users := []SSamluser{}
err := db.FetchModelObjects(SamluserManager, q, &users)
if err != nil {
return nil, errors.Wrapf(err, "db.FetchModelObjects")
return nil, nil, errors.Wrapf(err, "db.FetchModelObjects")
}
if len(users) == 0 {
return nil, fmt.Errorf("no available saml user for %s %s", userCred.GetUserName(), userCred.GetUserId())
return nil, nil, fmt.Errorf("no available saml user for %s %s", userCred.GetUserName(), userCred.GetUserId())
}
groupIds := []string{}
for i := range users {
userNames = append(userNames, users[i].Name)
groupIds = append(groupIds, users[i].CloudgroupId)
}
q = CloudgroupManager.Query().In("id", groupIds)
groups := []SCloudgroup{}
err = db.FetchModelObjects(CloudgroupManager, q, &groups)
if err != nil {
return nil, errors.Wrapf(err, "db.FetchModelObjects")
return nil, nil, errors.Wrapf(err, "db.FetchModelObjects")
}
if len(groups) == 0 {
return ret, fmt.Errorf("no available cloudgroup for %s %s", userCred.GetUserName(), userCred.GetUserId())
return userNames, groupNames, fmt.Errorf("no available cloudgroup for %s %s", userCred.GetUserName(), userCred.GetUserId())
}
for i := range groups {
cache, err := CloudgroupcacheManager.Register(&groups[i], self)
if err != nil {
return []string{}, errors.Wrapf(err, "group cache Register")
return userNames, groupNames, errors.Wrapf(err, "group cache Register")
}
if len(cache.ExternalId) > 0 {
ret = append(ret, cache.Name)
groupNames = append(groupNames, cache.Name)
} else {
s := auth.GetAdminSession(context.TODO(), options.Options.Region)
_, err = cache.GetOrCreateICloudgroup(context.TODO(), s.GetToken())
if err != nil {
return []string{}, errors.Wrapf(err, "GetOrCreateICloudgroup")
return userNames, groupNames, errors.Wrapf(err, "GetOrCreateICloudgroup")
}
cache, err := CloudgroupcacheManager.Register(&groups[i], self)
if err != nil {
return []string{}, errors.Wrapf(err, "group cache Register")
return userNames, groupNames, errors.Wrapf(err, "group cache Register")
}
ret = append(ret, cache.Name)
groupNames = append(groupNames, cache.Name)
}
}
return ret, nil
return userNames, groupNames, nil
}
func (self *SCloudaccount) InviteAzureUser(ctx context.Context, userCred mcclient.TokenCredential, domain string) (string, error) {
+5 -4
View File
@@ -19,6 +19,7 @@ import (
"database/sql"
"fmt"
"net/url"
"strings"
"yunion.io/x/pkg/errors"
@@ -68,7 +69,7 @@ func (d *SHuaweiSAMLDriver) GetIdpInitiatedLoginData(ctx context.Context, userCr
if len(idpId) == 0 {
return data, httperrors.NewInputParameterError("saml auth url %s missing idp", uri)
}
groups, err := account.GetUserCloudgroups(userCred)
users, groups, err := account.GetUserCloudgroups(userCred)
if err != nil {
return data, httperrors.NewGeneralError(errors.Wrapf(err, "GetUserCloudgroups"))
}
@@ -77,7 +78,7 @@ func (d *SHuaweiSAMLDriver) GetIdpInitiatedLoginData(ctx context.Context, userCr
data.NameIdFormat = samlutils.NAME_ID_FORMAT_TRANSIENT
data.AudienceRestriction = sp.GetEntityId()
for k, v := range map[string][]string{
"User": {userCred.GetUserName()},
"User": {strings.Join(users, ",")},
"Groups": groups,
} {
data.Attributes = append(data.Attributes, samlutils.SSAMLResponseAttribute{
@@ -126,7 +127,7 @@ func (d *SHuaweiSAMLDriver) GetSpInitiatedLoginData(ctx context.Context, userCre
return data, httperrors.NewResourceNotReadyError("SAMLProvider for account %s not ready", account.Id)
}
groups, err := account.GetUserCloudgroups(userCred)
users, groups, err := account.GetUserCloudgroups(userCred)
if err != nil {
return data, httperrors.NewGeneralError(errors.Wrapf(err, "GetUserCloudgroups"))
}
@@ -135,7 +136,7 @@ func (d *SHuaweiSAMLDriver) GetSpInitiatedLoginData(ctx context.Context, userCre
data.NameIdFormat = samlutils.NAME_ID_FORMAT_TRANSIENT
data.AudienceRestriction = sp.GetEntityId()
for k, v := range map[string][]string{
"User": {userCred.GetUserName()},
"User": {strings.Join(users, ",")},
"Groups": groups,
} {
data.Attributes = append(data.Attributes, samlutils.SSAMLResponseAttribute{