fix(region): vendor update (#19826)

This commit is contained in:
屈轩
2024-03-29 10:37:57 +08:00
committed by GitHub
parent 52eb6d1048
commit 796c2dad86
14 changed files with 303 additions and 299 deletions
+1 -1
View File
@@ -89,7 +89,7 @@ require (
k8s.io/cluster-bootstrap v0.19.3
k8s.io/cri-api v0.22.17
moul.io/http2curl/v2 v2.3.0
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240321094619-9614dc43aa9b
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240328114957-5bdec2c9d919
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32
yunion.io/x/jsonutils v1.0.1-0.20240203102553-4096f103b401
yunion.io/x/log v1.0.1-0.20240305175729-7cf2d6cd5a91
+2 -2
View File
@@ -1210,8 +1210,8 @@ sigs.k8s.io/structured-merge-diff/v4 v4.0.1/go.mod h1:bJZC9H9iH24zzfZ/41RGcq60oK
sigs.k8s.io/yaml v1.1.0/go.mod h1:UJmg0vDUVViEyp3mgSv9WPwZCDxu4rQW1olrI1uml+o=
sigs.k8s.io/yaml v1.2.0 h1:kr/MCeFWJWTwyaHoR9c8EjH9OumOmoF9YGiZd7lFm/Q=
sigs.k8s.io/yaml v1.2.0/go.mod h1:yfXDCHCao9+ENCvLSE62v9VSji2MKu5jeNfTrofGhJc=
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240321094619-9614dc43aa9b h1:M6R0Rp/zOJEAREMTVzuiPXEf6e25Ozh71JbZ4UuphyE=
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240321094619-9614dc43aa9b/go.mod h1:dsUESXIbXJ+/ywbNClhldOrbPOiBi2udrgOnB/ffoWk=
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240328114957-5bdec2c9d919 h1:mFqAWZNc6oUttUhvqxYpXUtdTV5LiZPdhfp5X3hx+ds=
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240328114957-5bdec2c9d919/go.mod h1:dsUESXIbXJ+/ywbNClhldOrbPOiBi2udrgOnB/ffoWk=
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32 h1:v7POYkQwo1XzOxBoIoRVr/k0V9Y5JyjpshlIFa9raug=
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32/go.mod h1:Uxuou9WQIeJXNpy7t2fPLL0BYLvLiMvGQwY7Qc6aSws=
yunion.io/x/jsonutils v0.0.0-20190625054549-a964e1e8a051/go.mod h1:4N0/RVzsYL3kH3WE/H1BjUQdFiWu50JGCFQuuy+Z634=
-120
View File
@@ -1,120 +0,0 @@
// Copyright 2014 The Go Authors. All rights reserved.
// Use of this source code is governed by a BSD-style
// license that can be found in the LICENSE file.
// Package clientcredentials implements the OAuth2.0 "client credentials" token flow,
// also known as the "two-legged OAuth 2.0".
//
// This should be used when the client is acting on its own behalf or when the client
// is the resource owner. It may also be used when requesting access to protected
// resources based on an authorization previously arranged with the authorization
// server.
//
// See https://tools.ietf.org/html/rfc6749#section-4.4
package clientcredentials // import "golang.org/x/oauth2/clientcredentials"
import (
"context"
"fmt"
"net/http"
"net/url"
"strings"
"golang.org/x/oauth2"
"golang.org/x/oauth2/internal"
)
// Config describes a 2-legged OAuth2 flow, with both the
// client application information and the server's endpoint URLs.
type Config struct {
// ClientID is the application's ID.
ClientID string
// ClientSecret is the application's secret.
ClientSecret string
// TokenURL is the resource server's token endpoint
// URL. This is a constant specific to each server.
TokenURL string
// Scope specifies optional requested permissions.
Scopes []string
// EndpointParams specifies additional parameters for requests to the token endpoint.
EndpointParams url.Values
// AuthStyle optionally specifies how the endpoint wants the
// client ID & client secret sent. The zero value means to
// auto-detect.
AuthStyle oauth2.AuthStyle
}
// Token uses client credentials to retrieve a token.
//
// The provided context optionally controls which HTTP client is used. See the oauth2.HTTPClient variable.
func (c *Config) Token(ctx context.Context) (*oauth2.Token, error) {
return c.TokenSource(ctx).Token()
}
// Client returns an HTTP client using the provided token.
// The token will auto-refresh as necessary.
//
// The provided context optionally controls which HTTP client
// is returned. See the oauth2.HTTPClient variable.
//
// The returned Client and its Transport should not be modified.
func (c *Config) Client(ctx context.Context) *http.Client {
return oauth2.NewClient(ctx, c.TokenSource(ctx))
}
// TokenSource returns a TokenSource that returns t until t expires,
// automatically refreshing it as necessary using the provided context and the
// client ID and client secret.
//
// Most users will use Config.Client instead.
func (c *Config) TokenSource(ctx context.Context) oauth2.TokenSource {
source := &tokenSource{
ctx: ctx,
conf: c,
}
return oauth2.ReuseTokenSource(nil, source)
}
type tokenSource struct {
ctx context.Context
conf *Config
}
// Token refreshes the token by using a new client credentials request.
// tokens received this way do not include a refresh token
func (c *tokenSource) Token() (*oauth2.Token, error) {
v := url.Values{
"grant_type": {"client_credentials"},
}
if len(c.conf.Scopes) > 0 {
v.Set("scope", strings.Join(c.conf.Scopes, " "))
}
for k, p := range c.conf.EndpointParams {
// Allow grant_type to be overridden to allow interoperability with
// non-compliant implementations.
if _, ok := v[k]; ok && k != "grant_type" {
return nil, fmt.Errorf("oauth2: cannot overwrite parameter %q", k)
}
v[k] = p
}
tk, err := internal.RetrieveToken(c.ctx, c.conf.ClientID, c.conf.ClientSecret, c.conf.TokenURL, v, internal.AuthStyle(c.conf.AuthStyle))
if err != nil {
if rErr, ok := err.(*internal.RetrieveError); ok {
return nil, (*oauth2.RetrieveError)(rErr)
}
return nil, err
}
t := &oauth2.Token{
AccessToken: tk.AccessToken,
TokenType: tk.TokenType,
RefreshToken: tk.RefreshToken,
Expiry: tk.Expiry,
}
return t.WithExtra(tk.Raw), nil
}
+1 -2
View File
@@ -1083,7 +1083,6 @@ golang.org/x/net/trace
## explicit; go 1.11
golang.org/x/oauth2
golang.org/x/oauth2/authhandler
golang.org/x/oauth2/clientcredentials
golang.org/x/oauth2/google
golang.org/x/oauth2/google/internal/externalaccount
golang.org/x/oauth2/internal
@@ -1477,7 +1476,7 @@ sigs.k8s.io/structured-merge-diff/v4/value
# sigs.k8s.io/yaml v1.2.0
## explicit; go 1.12
sigs.k8s.io/yaml
# yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240321094619-9614dc43aa9b
# yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240328114957-5bdec2c9d919
## explicit; go 1.18
yunion.io/x/cloudmux/pkg/apis
yunion.io/x/cloudmux/pkg/apis/billing
+7 -117
View File
@@ -41,7 +41,6 @@ import (
azureenv "github.com/Azure/go-autorest/autorest/azure"
"github.com/Azure/go-autorest/autorest/azure/auth"
"github.com/pkg/errors"
"golang.org/x/oauth2/clientcredentials"
"yunion.io/x/jsonutils"
"yunion.io/x/log"
@@ -64,7 +63,6 @@ const (
type TAzureResource string
var (
GraphResource = TAzureResource("graph")
DefaultResource = TAzureResource("default")
LoganalyticsResource = TAzureResource("loganalytics")
)
@@ -79,6 +77,9 @@ type SAzureClient struct {
clientCache map[TAzureResource]*azureAuthClient
lock sync.Mutex
tokenLock sync.Mutex
tokenMap map[string]*Token
httpClient *http.Client
ressourceGroups []SResourceGroup
@@ -89,6 +90,8 @@ type SAzureClient struct {
debug bool
ctx context.Context
workspaces []SLoganalyticsWorkspace
}
@@ -135,6 +138,8 @@ func NewAzureClient(cfg *AzureClientConfig) (*SAzureClient, error) {
AzureClientConfig: cfg,
debug: cfg.debug,
clientCache: map[TAzureResource]*azureAuthClient{},
tokenMap: map[string]*Token{},
ctx: context.Background(),
}
var err error
client.subscriptions, err = client.ListSubscriptions()
@@ -184,13 +189,6 @@ func (self *SAzureClient) getClient(resource TAzureResource) (*azureAuthClient,
client.Sender = httpClient
switch resource {
case GraphResource:
ret.domain = env.GraphEndpoint
conf.Resource = env.GraphEndpoint
if self.envName == "AzureChinaCloud" {
ret.domain = "https://graph.chinacloudapi.cn/"
conf.Resource = "https://graph.chinacloudapi.cn/"
}
case LoganalyticsResource:
ret.domain = env.ResourceIdentifiers.OperationalInsights
conf.Resource = env.ResourceIdentifiers.OperationalInsights
@@ -223,10 +221,6 @@ func (self *SAzureClient) getDefaultClient() (*azureAuthClient, error) {
return self.getClient(DefaultResource)
}
func (self *SAzureClient) getGraphClient() (*azureAuthClient, error) {
return self.getClient(GraphResource)
}
func (self *SAzureClient) getLoganalyticsClient() (*azureAuthClient, error) {
return self.getClient(LoganalyticsResource)
}
@@ -290,18 +284,6 @@ func (self *SAzureClient) ljsonRequest(method, path string, body jsonutils.JSONO
return jsonRequest(cli.client, method, cli.domain, path, body, params, self.debug)
}
func (self *SAzureClient) gjsonRequest(method, path string, body jsonutils.JSONObject, params url.Values) (jsonutils.JSONObject, error) {
cli, err := self.getGraphClient()
if err != nil {
return nil, errors.Wrapf(err, "gjsonRequest")
}
if params == nil {
params = url.Values{}
}
params.Set("api-version", "1.6")
return jsonRequest(cli.client, method, cli.domain, path, body, params, self.debug)
}
func (self *SAzureClient) put(path string, body jsonutils.JSONObject) (jsonutils.JSONObject, error) {
params := url.Values{}
params.Set("api-version", self._apiVersion(path, params))
@@ -346,55 +328,6 @@ func (self *SAzureClient) get(resourceId string, params url.Values, retVal inter
return self._get(resourceId, params, retVal, true)
}
func (self *SAzureClient) gcreate(resource string, body jsonutils.JSONObject, retVal interface{}) error {
path := resource
result, err := self.msGraphRequest("POST", path, body)
if err != nil {
return errors.Wrapf(err, "msGraphRequest")
}
if gotypes.IsNil(result) {
return fmt.Errorf("empty response")
}
if retVal != nil {
return result.Unmarshal(retVal)
}
return nil
}
func (self *SAzureClient) gpatch(resource string, body jsonutils.JSONObject) (jsonutils.JSONObject, error) {
return self.gjsonRequest("PATCH", resource, body, nil)
}
func (self *SAzureClient) glist(resource string, params url.Values, retVal interface{}) error {
if params == nil {
params = url.Values{}
}
err := self._glist(resource, params, retVal)
if err != nil {
return errors.Wrapf(err, "_glist(%s)", resource)
}
return nil
}
func (self *SAzureClient) _glist(resource string, params url.Values, retVal interface{}) error {
path := resource
if len(params) > 0 {
path = fmt.Sprintf("%s?%s", path, params.Encode())
}
body, err := self.msGraphRequest("GET", path, nil)
if err != nil {
return err
}
if gotypes.IsNil(body) {
return fmt.Errorf("empty response")
}
err = body.Unmarshal(retVal, "value")
if err != nil {
return errors.Wrapf(err, "body.Unmarshal")
}
return nil
}
func (self *SAzureClient) list(resource string, params url.Values, retVal interface{}) error {
if params == nil {
params = url.Values{}
@@ -602,18 +535,6 @@ func (self *SAzureClient) del(resourceId string) error {
return err
}
func (self *SAzureClient) GDelete(resourceId string) error {
return self.gdel(resourceId)
}
func (self *SAzureClient) gdel(resourceId string) error {
_, err := self.msGraphRequest("DELETE", resourceId, nil)
if err != nil {
return errors.Wrapf(err, "gdel(%s)", resourceId)
}
return nil
}
func (self *SAzureClient) perform(resourceId string, action string, body jsonutils.JSONObject) (jsonutils.JSONObject, error) {
path := fmt.Sprintf("%s/%s", resourceId, action)
return self.post(path, body)
@@ -1128,34 +1049,3 @@ func (self *SAzureClient) SetTags(resourceId string, tags map[string]string) (js
}
return self.patch(path, jsonutils.Marshal(input))
}
func (self *SAzureClient) msGraphClient() *http.Client {
conf := clientcredentials.Config{
ClientID: self.clientId,
ClientSecret: self.clientSecret,
TokenURL: fmt.Sprintf("https://login.microsoftonline.com/%s/oauth2/v2.0/token", self.tenantId),
Scopes: []string{"https://graph.microsoft.com/.default"},
}
if self.envName == "AzureChinaCloud" {
conf.TokenURL = fmt.Sprintf("https://login.partner.microsoftonline.cn/%s/oauth2/v2.0/token", self.tenantId)
conf.Scopes = []string{"https://microsoftgraph.chinacloudapi.cn/.default"}
}
return conf.Client(context.TODO())
}
func (self *SAzureClient) msGraphRequest(method string, resource string, body jsonutils.JSONObject) (jsonutils.JSONObject, error) {
client := self.msGraphClient()
url := fmt.Sprintf("https://graph.microsoft.com/v1.0/%s", resource)
if self.envName == "AzureChinaCloud" {
url = fmt.Sprintf("https://microsoftgraph.chinacloudapi.cn/v1.0/%s", resource)
}
req := httputils.NewJsonRequest(httputils.THttpMethod(method), url, body)
ae := AzureResponseError{}
cli := httputils.NewJsonClient(client)
_, body, err := cli.Send(context.TODO(), req, &ae, self.debug)
if err != nil {
return nil, err
}
return body, nil
}
+192
View File
@@ -0,0 +1,192 @@
package azure
import (
"fmt"
"io"
"net/http"
"net/url"
"strings"
"time"
"yunion.io/x/cloudmux/pkg/cloudprovider"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/httputils"
)
const (
ENV_NAME_CHINA = "AzureChinaCloud"
ENV_NAME_GLOBAL = "AzurePublicCloud"
SERVICE_MANAGEMENT = "management"
SERVICE_GRAPH = "graph"
SERVICE_AAD = "aad"
)
var azServices = map[string]map[string]string{
SERVICE_GRAPH: {
ENV_NAME_GLOBAL: "https://graph.microsoft.com/v1.0",
ENV_NAME_CHINA: "https://microsoftgraph.chinacloudapi.cn/v1.0",
},
SERVICE_MANAGEMENT: {
ENV_NAME_GLOBAL: "https://management.azure.com",
ENV_NAME_CHINA: "https://management.chinacloudapi.cn",
},
SERVICE_AAD: {
ENV_NAME_GLOBAL: "https://login.microsoftonline.com",
ENV_NAME_CHINA: "https://login.chinacloudapi.cn",
},
}
type Token struct {
TokenType string
ExpiresIn int64
ExtExpiresIn int64
ExpiresOn int64
NotBefore int64
Resource string
AccessToken string
}
func (t Token) Token() string {
return fmt.Sprintf("%s %s", t.TokenType, t.AccessToken)
}
func (t Token) isExpire() bool {
expire := time.Unix(t.NotBefore, 0)
return expire.Before(time.Now())
}
func (self *SAzureClient) client() *http.Client {
if self.httpClient != nil {
return self.httpClient
}
httpClient := self.cpcfg.AdaptiveTimeoutHttpClient()
transport, _ := httpClient.Transport.(*http.Transport)
httpClient.Transport = cloudprovider.GetCheckTransport(transport, func(req *http.Request) (func(resp *http.Response) error, error) {
if self.cpcfg.ReadOnly {
if req.Method == "GET" || (req.Method == "POST" && strings.HasSuffix(req.URL.Path, "oauth2/token")) {
return nil, nil
}
return nil, errors.Wrapf(cloudprovider.ErrAccountReadOnly, "%s %s", req.Method, req.URL.Path)
}
return nil, nil
})
self.httpClient = httpClient
return self.httpClient
}
func (self *SAzureClient) auth(resource string) (string, error) {
self.tokenLock.Lock()
defer self.tokenLock.Unlock()
if token, ok := self.tokenMap[resource]; ok && !token.isExpire() {
return token.Token(), nil
}
data := url.Values{}
data.Set("client_id", self.clientId)
data.Set("client_secret", self.clientSecret)
data.Set("grant_type", "client_credentials")
data.Set("resource", resource)
domain := azServices[SERVICE_AAD][self.envName]
url := fmt.Sprintf("%s/%s/oauth2/token?api-version=1.0", domain, self.tenantId)
client := self.client()
resp, err := client.PostForm(url, data)
if err != nil {
return "", errors.Wrapf(err, "auth")
}
defer resp.Body.Close()
body, err := io.ReadAll(resp.Body)
if err != nil {
return "", errors.Wrapf(err, "read body")
}
obj, err := jsonutils.Parse(body)
if err != nil {
return "", errors.Wrapf(err, "parse body %s", string(body))
}
if obj.Contains("error") {
return "", errors.Errorf(string(body))
}
token := &Token{}
err = obj.Unmarshal(token)
if err != nil {
return "", errors.Wrapf(err, "unmarshal token")
}
self.tokenMap[resource] = token
return token.Token(), nil
}
func (self *SAzureClient) Do(req *http.Request) (*http.Response, error) {
resource := fmt.Sprintf("https://%s", req.Host)
token, err := self.auth(resource)
if err != nil {
return nil, errors.Wrapf(err, "auth")
}
req.Header.Set("Authorization", token)
return self.client().Do(req)
}
func (self *SAzureClient) list_v2(resource, apiVersion string, params url.Values) (jsonutils.JSONObject, error) {
return self._list_v2(SERVICE_MANAGEMENT, resource, apiVersion, params)
}
func (self *SAzureClient) _list_v2(service string, resource, apiVersion string, params url.Values) (jsonutils.JSONObject, error) {
if params == nil {
params = url.Values{}
}
if len(apiVersion) > 0 {
params.Set("api-version", apiVersion)
}
domain := azServices[service][self.envName]
url := fmt.Sprintf("%s/%s", domain, resource)
if len(params) > 0 {
url += fmt.Sprintf("?%s", params.Encode())
}
_, resp, err := httputils.JSONRequest(self, self.ctx, httputils.GET, url, nil, nil, self.debug)
return resp, err
}
func (self *SAzureClient) post_v2(resource, apiVersion string, body map[string]interface{}) (jsonutils.JSONObject, error) {
return self._post_v2("", resource, apiVersion, body)
}
func (self *SAzureClient) _post_v2(service string, resource, apiVersion string, body map[string]interface{}) (jsonutils.JSONObject, error) {
domain := azServices[service][self.envName]
url := fmt.Sprintf("%s/%s", domain, resource)
if len(apiVersion) > 0 {
url += fmt.Sprintf("?api-version=%s", apiVersion)
}
_, resp, err := httputils.JSONRequest(self, self.ctx, httputils.POST, url, nil, jsonutils.Marshal(body), self.debug)
return resp, err
}
func (self *SAzureClient) delete_v2(resource, apiVersion string, body map[string]interface{}) (jsonutils.JSONObject, error) {
return self._delete_v2("", resource, apiVersion)
}
func (self *SAzureClient) _delete_v2(service string, resource, apiVersion string) (jsonutils.JSONObject, error) {
domain := azServices[service][self.envName]
url := fmt.Sprintf("%s/%s", domain, resource)
if len(apiVersion) > 0 {
url += fmt.Sprintf("?api-version=%s", apiVersion)
}
_, resp, err := httputils.JSONRequest(self, self.ctx, httputils.DELETE, url, nil, nil, self.debug)
return resp, err
}
func (self *SAzureClient) patch_v2(resource, apiVersion string, body map[string]interface{}) (jsonutils.JSONObject, error) {
return self._patch_v2("", resource, apiVersion, body)
}
func (self *SAzureClient) _patch_v2(service string, resource, apiVersion string, body map[string]interface{}) (jsonutils.JSONObject, error) {
domain := azServices[service][self.envName]
url := fmt.Sprintf("%s/%s", domain, resource)
if len(apiVersion) > 0 {
url += fmt.Sprintf("?api-version=%s", apiVersion)
}
_, resp, err := httputils.JSONRequest(self, self.ctx, httputils.PATCH, url, nil, jsonutils.Marshal(body), self.debug)
return resp, err
}
+30 -15
View File
@@ -19,7 +19,6 @@ import (
"net/url"
"strings"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/pinyinutils"
@@ -121,7 +120,8 @@ func (group *SCloudgroup) DetachSystemPolicy(policyId string) error {
return errors.Wrapf(err, "GetRule(%s)", assignment.Properties.RoleDefinitionId)
}
if role.Properties.RoleName == policyId {
return group.client.gdel(assignment.Id)
_, err := group.client._delete_v2(SERVICE_GRAPH, assignment.Id, "")
return err
}
}
return nil
@@ -136,12 +136,16 @@ func (group *SCloudgroup) Delete() error {
}
func (self *SAzureClient) GetCloudgroups(name string) ([]SCloudgroup, error) {
groups := []SCloudgroup{}
params := url.Values{}
if len(name) > 0 {
params.Set("$filter", fmt.Sprintf("displayName eq '%s'", name))
}
err := self.glist("groups", params, &groups)
resp, err := self._list_v2(SERVICE_GRAPH, "groups", "", params)
if err != nil {
return nil, err
}
groups := []SCloudgroup{}
err = resp.Unmarshal(&groups, "value")
if err != nil {
return nil, err
}
@@ -177,9 +181,13 @@ func (self *SAzureClient) GetICloudgroupByName(name string) (cloudprovider.IClou
}
func (self *SAzureClient) ListGroupMemebers(id string) ([]SClouduser, error) {
users := []SClouduser{}
resource := fmt.Sprintf("groups/%s/members", id)
err := self.glist(resource, nil, &users)
resp, err := self._list_v2(SERVICE_GRAPH, resource, "", nil)
if err != nil {
return nil, err
}
users := []SClouduser{}
err = resp.Unmarshal(&users, "value")
if err != nil {
return nil, err
}
@@ -187,7 +195,8 @@ func (self *SAzureClient) ListGroupMemebers(id string) ([]SClouduser, error) {
}
func (self *SAzureClient) DeleteGroup(id string) error {
return self.gdel(fmt.Sprintf("groups/%s", id))
_, err := self._delete_v2(SERVICE_GRAPH, "groups/"+id, "")
return err
}
func (self *SAzureClient) CreateGroup(name, desc string) (*SCloudgroup, error) {
@@ -200,12 +209,16 @@ func (self *SAzureClient) CreateGroup(name, desc string) (*SCloudgroup, error) {
if len(desc) > 0 {
params["Description"] = desc
}
group := SCloudgroup{client: self}
err := self.gcreate("groups", jsonutils.Marshal(params), &group)
resp, err := self._post_v2(SERVICE_GRAPH, "groups", "", params)
if err != nil {
return nil, errors.Wrap(err, "Create")
return nil, err
}
return &group, nil
group := &SCloudgroup{client: self}
err = resp.Unmarshal(group)
if err != nil {
return nil, err
}
return group, nil
}
func (self *SAzureClient) RemoveGroupUser(id, userName string) error {
@@ -213,7 +226,9 @@ func (self *SAzureClient) RemoveGroupUser(id, userName string) error {
if err != nil {
return errors.Wrapf(err, "GetCloudusers(%s)", userName)
}
return self.gdel(fmt.Sprintf("/groups/%s/members/%s/$ref", id, user.Id))
resource := fmt.Sprintf("/groups/%s/members/%s/$ref", id, user.Id)
_, err = self._delete_v2(SERVICE_GRAPH, resource, "")
return err
}
func (self *SAzureClient) CreateICloudgroup(name, desc string) (cloudprovider.ICloudgroup, error) {
@@ -230,14 +245,14 @@ func (self *SAzureClient) AddGroupUser(id, userName string) error {
if err != nil {
return errors.Wrapf(err, "GetCloudusers(%s)", userName)
}
resource := fmt.Sprintf("groups/%s/members/$ref", id)
params := map[string]string{
params := map[string]interface{}{
"@odata.id": fmt.Sprintf("https://graph.microsoft.com/v1.0/directoryObjects/%s", user.Id),
}
if self.envName == "AzureChinaCloud" {
params["@odata.id"] = fmt.Sprintf("https://microsoftgraph.chinacloudapi.cn/v1.0/directoryObjects/%s", user.Id)
}
err = self.gcreate(resource, jsonutils.Marshal(params), nil)
resource := fmt.Sprintf("groups/%s/members/$ref", id)
_, err = self._post_v2(SERVICE_GRAPH, resource, "", params)
if err != nil && !strings.Contains(err.Error(), "One or more added object references already exist for the following modified properties") {
return err
}
+31 -31
View File
@@ -19,9 +19,7 @@ import (
"net/url"
"time"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/httputils"
"yunion.io/x/cloudmux/pkg/cloudprovider"
"yunion.io/x/cloudmux/pkg/multicloud"
@@ -162,7 +160,8 @@ func (user *SClouduser) DetachSystemPolicy(policyId string) error {
return errors.Wrapf(err, "GetRule(%s)", assignment.Properties.RoleDefinitionId)
}
if role.Properties.RoleName == policyId {
return user.client.gdel(assignment.Id)
_, err := user.client._delete_v2(SERVICE_GRAPH, assignment.Id, "")
return err
}
}
return nil
@@ -200,20 +199,27 @@ func (user *SClouduser) GetICloudgroups() ([]cloudprovider.ICloudgroup, error) {
func (self *SAzureClient) GetUserGroups(userId string) ([]SCloudgroup, error) {
resource := fmt.Sprintf("users/%s/memberOf", userId)
resp, err := self._list_v2(SERVICE_GRAPH, resource, "", nil)
if err != nil {
return nil, err
}
groups := []SCloudgroup{}
err := self.glist(resource, url.Values{}, &groups)
err = resp.Unmarshal(&groups, "value")
if err != nil {
return nil, err
}
return groups, err
}
func (self *SAzureClient) ResetClouduserPassword(id, password string) error {
body := jsonutils.Marshal(map[string]interface{}{
body := map[string]interface{}{
"passwordPolicies": "DisablePasswordExpiration, DisableStrongPassword",
"passwordProfile": map[string]interface{}{
"password": password,
},
})
}
resource := fmt.Sprintf("%s/users/%s", self.tenantId, id)
_, err := self.gpatch(resource, body)
_, err := self._patch_v2(SERVICE_GRAPH, resource, "", body)
return err
}
@@ -233,8 +239,11 @@ func (self *SAzureClient) GetClouduser(name string) (*SClouduser, error) {
func (self *SAzureClient) GetCloudusers() ([]SClouduser, error) {
users := []SClouduser{}
params := url.Values{}
err := self.glist("users", params, &users)
resp, err := self._list_v2(SERVICE_GRAPH, "users", "", url.Values{})
if err != nil {
return nil, err
}
err = resp.Unmarshal(&users, "value")
if err != nil {
return nil, err
}
@@ -242,14 +251,14 @@ func (self *SAzureClient) GetCloudusers() ([]SClouduser, error) {
}
func (self *SAzureClient) DeleteClouduser(id string) error {
_, err := self.msGraphRequest(string(httputils.DELETE), "users/"+id, nil)
_, err := self._delete_v2(SERVICE_GRAPH, "users/"+id, "")
return err
}
func (self *SAzureClient) GetICloudusers() ([]cloudprovider.IClouduser, error) {
users, err := self.ListGraphUsers()
users, err := self.GetCloudusers()
if err != nil {
return nil, errors.Wrap(err, "ListGraphUsers")
return nil, errors.Wrap(err, "GetCloudusers")
}
ret := []cloudprovider.IClouduser{}
for i := range users {
@@ -293,9 +302,13 @@ type SDomain struct {
func (self *SAzureClient) GetDomains() ([]SDomain, error) {
domains := []SDomain{}
err := self.glist("domains", nil, &domains)
resp, err := self._list_v2(SERVICE_GRAPH, "domains", "", nil)
if err != nil {
return nil, errors.Wrap(err, "glist")
return nil, errors.Wrap(err, "list domains")
}
err = resp.Unmarshal(&domains, "value")
if err != nil {
return nil, err
}
return domains, nil
}
@@ -332,27 +345,14 @@ func (self *SAzureClient) CreateClouduser(name, password string) (*SClouduser, e
return nil, errors.Wrap(err, "GetDefaultDomain")
}
params["userPrincipalName"] = fmt.Sprintf("%s@%s", name, domain)
user := SClouduser{client: self}
resp, err := self.msGraphRequest(string(httputils.POST), "users", jsonutils.Marshal(params))
user := &SClouduser{client: self}
resp, err := self._post_v2(SERVICE_GRAPH, "users", "", params)
if err != nil {
return nil, errors.Wrap(err, "Create")
}
err = resp.Unmarshal(&user)
err = resp.Unmarshal(user)
if err != nil {
return nil, err
}
return &user, nil
}
func (self *SAzureClient) ListGraphUsers() ([]SClouduser, error) {
resp, err := self.msGraphRequest("GET", "users", nil)
if err != nil {
return nil, errors.Wrapf(err, "msGraphRequest.users")
}
users := []SClouduser{}
err = resp.Unmarshal(&users, "value")
if err != nil {
return nil, errors.Wrapf(err, "resp.Unmarshal")
}
return users, nil
return user, nil
}
+9 -1
View File
@@ -95,6 +95,14 @@ func (cli *SAzureClient) ListServicePrincipal(appId string) ([]SServicePrincipal
if len(appId) > 0 {
params.Set("$filter", fmt.Sprintf(`appId eq '%s'`, cli.clientId))
}
resp, err := cli._list_v2(SERVICE_GRAPH, "servicePrincipals", "", params)
if err != nil {
return nil, err
}
result := []SServicePrincipal{}
return result, cli.glist("servicePrincipals", params, &result)
err = resp.Unmarshal(&result, "value")
if err != nil {
return nil, err
}
return result, nil
}
+13 -8
View File
@@ -79,25 +79,30 @@ func (self *SAMLProvider) GetAuthUrl(apiServer string) string {
}
func (self *SAzureClient) ListSAMLProviders() ([]SAMLProvider, error) {
_, err := self.msGraphRequest("GET", "identityProviders", nil)
resp, err := self._list_v2(SERVICE_GRAPH, "identityProviders", "", nil)
if err != nil {
return nil, err
}
return []SAMLProvider{}, nil
ret := []SAMLProvider{}
err = resp.Unmarshal(&ret, "value")
if err != nil {
return nil, err
}
return ret, nil
}
func (self *SAzureClient) InviteUser(email string) (*SClouduser, error) {
body := jsonutils.Marshal(map[string]string{
body := map[string]interface{}{
"invitedUserEmailAddress": email,
"inviteRedirectUrl": fmt.Sprintf("https://portal.azure.com/%s?login_hint=%s", self.tenantId, email),
})
resp, err := self.msGraphRequest("POST", "invitations", body)
}
resp, err := self._post_v2(SERVICE_GRAPH, "invitations", "", body)
if err != nil {
return nil, errors.Wrapf(err, "msGraphRequest.invitations")
return nil, errors.Wrapf(err, "invitations")
}
inviteUrl, _ := resp.GetString("inviteRedeemUrl")
err = cloudprovider.Wait(time.Second*2, time.Minute, func() (bool, error) {
users, err := self.ListGraphUsers()
users, err := self.GetCloudusers()
if err != nil {
return false, errors.Wrapf(err, "GetCloudusers")
}
@@ -112,7 +117,7 @@ func (self *SAzureClient) InviteUser(email string) (*SClouduser, error) {
if err != nil {
return nil, errors.Wrapf(cloudprovider.ErrNotFound, "after invite %s", email)
}
users, err := self.ListGraphUsers()
users, err := self.GetCloudusers()
if err != nil {
return nil, errors.Wrapf(err, "GetCloudusers")
}
+4
View File
@@ -328,6 +328,10 @@ func (self *SNutanixClient) get(res string, id string, params url.Values, retVal
return nil
}
func (cli *SNutanixClient) GetCloudRegionExternalIdPrefix() string {
return fmt.Sprintf("%s/%s/", CLOUD_PROVIDER_NUTANIX, cli.cpcfg.Id)
}
func (self *SNutanixClient) GetSubAccounts() ([]cloudprovider.SSubAccount, error) {
subAccount := cloudprovider.SSubAccount{
Id: self.GetAccountId(),
@@ -143,6 +143,10 @@ type SNutanixProvider struct {
client *nutanix.SNutanixClient
}
func (self *SNutanixProvider) GetCloudRegionExternalIdPrefix() string {
return self.client.GetCloudRegionExternalIdPrefix()
}
func (self *SNutanixProvider) GetSysInfo() (jsonutils.JSONObject, error) {
return jsonutils.NewDict(), nil
}
@@ -143,6 +143,10 @@ type SProxmoxProvider struct {
client *proxmox.SProxmoxClient
}
func (self *SProxmoxProvider) GetCloudRegionExternalIdPrefix() string {
return self.client.GetCloudRegionExternalIdPrefix()
}
func (self *SProxmoxProvider) GetSysInfo() (jsonutils.JSONObject, error) {
return jsonutils.NewDict(), nil
}
+5 -2
View File
@@ -20,7 +20,6 @@ import (
"crypto/tls"
"fmt"
"io"
"io/ioutil"
"mime/multipart"
"net/http"
"net/url"
@@ -341,7 +340,7 @@ func (cli *SProxmoxClient) upload(node, storageName, filename string, reader io.
}
defer resp.Body.Close()
data, err := ioutil.ReadAll(resp.Body)
data, err := io.ReadAll(resp.Body)
if err != nil {
return nil, err
}
@@ -369,6 +368,10 @@ func (cli *SProxmoxClient) upload(node, storageName, filename string, reader io.
return nil, errors.Wrapf(cloudprovider.ErrNotFound, "after upload")
}
func (cli *SProxmoxClient) GetCloudRegionExternalIdPrefix() string {
return fmt.Sprintf("%s/%s/", CLOUD_PROVIDER_PROXMOX, cli.cpcfg.Id)
}
func (self *SProxmoxClient) GetSubAccounts() ([]cloudprovider.SSubAccount, error) {
subAccount := cloudprovider.SSubAccount{}
subAccount.Id = self.host