mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: rename git_auth to external_auth in our schema (#9935)
* chore: rename `git_auth` to `external_auth` in our schema We're changing Git auth to be external auth. It will support any OAuth2 or OIDC provider. To split up the larger change I want to contribute the schema changes first, and I'll add the feature itself in another PR. * Fix names * Fix outdated view * Rename some additional places * Fix sort order * Fix template versions auth route * Fix types * Fix dbauthz
This commit is contained in:
@@ -48,8 +48,8 @@ import (
|
||||
const DefaultAcquireJobLongPollDur = time.Second * 5
|
||||
|
||||
type Options struct {
|
||||
OIDCConfig httpmw.OAuth2Config
|
||||
GitAuthConfigs []*gitauth.Config
|
||||
OIDCConfig httpmw.OAuth2Config
|
||||
ExternalAuthConfigs []*gitauth.Config
|
||||
// TimeNowFn is only used in tests
|
||||
TimeNowFn func() time.Time
|
||||
|
||||
@@ -62,7 +62,7 @@ type server struct {
|
||||
ID uuid.UUID
|
||||
Logger slog.Logger
|
||||
Provisioners []database.ProvisionerType
|
||||
GitAuthConfigs []*gitauth.Config
|
||||
ExternalAuthConfigs []*gitauth.Config
|
||||
Tags Tags
|
||||
Database database.Store
|
||||
Pubsub pubsub.Pubsub
|
||||
@@ -157,7 +157,7 @@ func NewServer(
|
||||
ID: id,
|
||||
Logger: logger,
|
||||
Provisioners: provisioners,
|
||||
GitAuthConfigs: options.GitAuthConfigs,
|
||||
ExternalAuthConfigs: options.ExternalAuthConfigs,
|
||||
Tags: tags,
|
||||
Database: db,
|
||||
Pubsub: ps,
|
||||
@@ -404,9 +404,9 @@ func (s *server) acquireProtoJob(ctx context.Context, job database.ProvisionerJo
|
||||
return nil, failJob(fmt.Sprintf("get workspace build parameters: %s", err))
|
||||
}
|
||||
|
||||
gitAuthProviders := []*sdkproto.GitAuthProvider{}
|
||||
for _, p := range templateVersion.GitAuthProviders {
|
||||
link, err := s.Database.GetGitAuthLink(ctx, database.GetGitAuthLinkParams{
|
||||
externalAuthProviders := []*sdkproto.ExternalAuthProvider{}
|
||||
for _, p := range templateVersion.ExternalAuthProviders {
|
||||
link, err := s.Database.GetExternalAuthLink(ctx, database.GetExternalAuthLinkParams{
|
||||
ProviderID: p,
|
||||
UserID: owner.ID,
|
||||
})
|
||||
@@ -414,10 +414,10 @@ func (s *server) acquireProtoJob(ctx context.Context, job database.ProvisionerJo
|
||||
continue
|
||||
}
|
||||
if err != nil {
|
||||
return nil, failJob(fmt.Sprintf("acquire git auth link: %s", err))
|
||||
return nil, failJob(fmt.Sprintf("acquire external auth link: %s", err))
|
||||
}
|
||||
var config *gitauth.Config
|
||||
for _, c := range s.GitAuthConfigs {
|
||||
for _, c := range s.ExternalAuthConfigs {
|
||||
if c.ID != p {
|
||||
continue
|
||||
}
|
||||
@@ -426,8 +426,8 @@ func (s *server) acquireProtoJob(ctx context.Context, job database.ProvisionerJo
|
||||
}
|
||||
// We weren't able to find a matching config for the ID!
|
||||
if config == nil {
|
||||
s.Logger.Warn(ctx, "workspace build job is missing git provider",
|
||||
slog.F("git_provider_id", p),
|
||||
s.Logger.Warn(ctx, "workspace build job is missing external auth provider",
|
||||
slog.F("provider_id", p),
|
||||
slog.F("template_version_id", templateVersion.ID),
|
||||
slog.F("workspace_id", workspaceBuild.WorkspaceID))
|
||||
continue
|
||||
@@ -435,12 +435,12 @@ func (s *server) acquireProtoJob(ctx context.Context, job database.ProvisionerJo
|
||||
|
||||
link, valid, err := config.RefreshToken(ctx, s.Database, link)
|
||||
if err != nil {
|
||||
return nil, failJob(fmt.Sprintf("refresh git auth link %q: %s", p, err))
|
||||
return nil, failJob(fmt.Sprintf("refresh external auth link %q: %s", p, err))
|
||||
}
|
||||
if !valid {
|
||||
continue
|
||||
}
|
||||
gitAuthProviders = append(gitAuthProviders, &sdkproto.GitAuthProvider{
|
||||
externalAuthProviders = append(externalAuthProviders, &sdkproto.ExternalAuthProvider{
|
||||
Id: p,
|
||||
AccessToken: link.OAuthAccessToken,
|
||||
})
|
||||
@@ -448,12 +448,12 @@ func (s *server) acquireProtoJob(ctx context.Context, job database.ProvisionerJo
|
||||
|
||||
protoJob.Type = &proto.AcquiredJob_WorkspaceBuild_{
|
||||
WorkspaceBuild: &proto.AcquiredJob_WorkspaceBuild{
|
||||
WorkspaceBuildId: workspaceBuild.ID.String(),
|
||||
WorkspaceName: workspace.Name,
|
||||
State: workspaceBuild.ProvisionerState,
|
||||
RichParameterValues: convertRichParameterValues(workspaceBuildParameters),
|
||||
VariableValues: asVariableValues(templateVariables),
|
||||
GitAuthProviders: gitAuthProviders,
|
||||
WorkspaceBuildId: workspaceBuild.ID.String(),
|
||||
WorkspaceName: workspace.Name,
|
||||
State: workspaceBuild.ProvisionerState,
|
||||
RichParameterValues: convertRichParameterValues(workspaceBuildParameters),
|
||||
VariableValues: asVariableValues(templateVariables),
|
||||
ExternalAuthProviders: externalAuthProviders,
|
||||
Metadata: &sdkproto.Metadata{
|
||||
CoderUrl: s.AccessURL.String(),
|
||||
WorkspaceTransition: transition,
|
||||
@@ -1028,30 +1028,30 @@ func (s *server) CompleteJob(ctx context.Context, completed *proto.CompletedJob)
|
||||
|
||||
var completedError sql.NullString
|
||||
|
||||
for _, gitAuthProvider := range jobType.TemplateImport.GitAuthProviders {
|
||||
for _, externalAuthProvider := range jobType.TemplateImport.ExternalAuthProviders {
|
||||
contains := false
|
||||
for _, configuredProvider := range s.GitAuthConfigs {
|
||||
if configuredProvider.ID == gitAuthProvider {
|
||||
for _, configuredProvider := range s.ExternalAuthConfigs {
|
||||
if configuredProvider.ID == externalAuthProvider {
|
||||
contains = true
|
||||
break
|
||||
}
|
||||
}
|
||||
if !contains {
|
||||
completedError = sql.NullString{
|
||||
String: fmt.Sprintf("git auth provider %q is not configured", gitAuthProvider),
|
||||
String: fmt.Sprintf("external auth provider %q is not configured", externalAuthProvider),
|
||||
Valid: true,
|
||||
}
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
err = s.Database.UpdateTemplateVersionGitAuthProvidersByJobID(ctx, database.UpdateTemplateVersionGitAuthProvidersByJobIDParams{
|
||||
JobID: jobID,
|
||||
GitAuthProviders: jobType.TemplateImport.GitAuthProviders,
|
||||
UpdatedAt: dbtime.Now(),
|
||||
err = s.Database.UpdateTemplateVersionExternalAuthProvidersByJobID(ctx, database.UpdateTemplateVersionExternalAuthProvidersByJobIDParams{
|
||||
JobID: jobID,
|
||||
ExternalAuthProviders: jobType.TemplateImport.ExternalAuthProviders,
|
||||
UpdatedAt: dbtime.Now(),
|
||||
})
|
||||
if err != nil {
|
||||
return nil, xerrors.Errorf("update template version git auth providers: %w", err)
|
||||
return nil, xerrors.Errorf("update template version external auth providers: %w", err)
|
||||
}
|
||||
|
||||
err = s.Database.UpdateProvisionerJobWithCompleteByID(ctx, database.UpdateProvisionerJobWithCompleteByIDParams{
|
||||
|
||||
@@ -143,7 +143,7 @@ func TestAcquireJob(t *testing.T) {
|
||||
gitAuthProvider := "github"
|
||||
srv, db, ps := setup(t, false, &overrides{
|
||||
deploymentValues: dv,
|
||||
gitAuthConfigs: []*gitauth.Config{{
|
||||
externalAuthConfigs: []*gitauth.Config{{
|
||||
ID: gitAuthProvider,
|
||||
OAuth2Config: &testutil.OAuth2Config{},
|
||||
}},
|
||||
@@ -158,7 +158,7 @@ func TestAcquireJob(t *testing.T) {
|
||||
OAuthExpiry: dbtime.Now().Add(time.Hour),
|
||||
OAuthAccessToken: "access-token",
|
||||
})
|
||||
dbgen.GitAuthLink(t, db, database.GitAuthLink{
|
||||
dbgen.ExternalAuthLink(t, db, database.ExternalAuthLink{
|
||||
ProviderID: gitAuthProvider,
|
||||
UserID: user.ID,
|
||||
})
|
||||
@@ -175,10 +175,10 @@ func TestAcquireJob(t *testing.T) {
|
||||
},
|
||||
JobID: uuid.New(),
|
||||
})
|
||||
err := db.UpdateTemplateVersionGitAuthProvidersByJobID(ctx, database.UpdateTemplateVersionGitAuthProvidersByJobIDParams{
|
||||
JobID: version.JobID,
|
||||
GitAuthProviders: []string{gitAuthProvider},
|
||||
UpdatedAt: dbtime.Now(),
|
||||
err := db.UpdateTemplateVersionExternalAuthProvidersByJobID(ctx, database.UpdateTemplateVersionExternalAuthProvidersByJobIDParams{
|
||||
JobID: version.JobID,
|
||||
ExternalAuthProviders: []string{gitAuthProvider},
|
||||
UpdatedAt: dbtime.Now(),
|
||||
})
|
||||
require.NoError(t, err)
|
||||
// Import version job
|
||||
@@ -288,7 +288,7 @@ func TestAcquireJob(t *testing.T) {
|
||||
Value: "second_value",
|
||||
},
|
||||
},
|
||||
GitAuthProviders: []*sdkproto.GitAuthProvider{{
|
||||
ExternalAuthProviders: []*sdkproto.ExternalAuthProvider{{
|
||||
Id: gitAuthProvider,
|
||||
AccessToken: "access_token",
|
||||
}},
|
||||
@@ -923,8 +923,8 @@ func TestCompleteJob(t *testing.T) {
|
||||
Name: "hello",
|
||||
Type: "aws_instance",
|
||||
}},
|
||||
StopResources: []*sdkproto.Resource{},
|
||||
GitAuthProviders: []string{"github"},
|
||||
StopResources: []*sdkproto.Resource{},
|
||||
ExternalAuthProviders: []string{"github"},
|
||||
},
|
||||
},
|
||||
})
|
||||
@@ -933,7 +933,7 @@ func TestCompleteJob(t *testing.T) {
|
||||
completeJob()
|
||||
job, err = db.GetProvisionerJobByID(ctx, job.ID)
|
||||
require.NoError(t, err)
|
||||
require.Contains(t, job.Error.String, `git auth provider "github" is not configured`)
|
||||
require.Contains(t, job.Error.String, `external auth provider "github" is not configured`)
|
||||
})
|
||||
|
||||
t.Run("TemplateImport_WithGitAuth", func(t *testing.T) {
|
||||
@@ -941,7 +941,7 @@ func TestCompleteJob(t *testing.T) {
|
||||
srvID := uuid.New()
|
||||
srv, db, _ := setup(t, false, &overrides{
|
||||
id: &srvID,
|
||||
gitAuthConfigs: []*gitauth.Config{{
|
||||
externalAuthConfigs: []*gitauth.Config{{
|
||||
ID: "github",
|
||||
}},
|
||||
})
|
||||
@@ -977,8 +977,8 @@ func TestCompleteJob(t *testing.T) {
|
||||
Name: "hello",
|
||||
Type: "aws_instance",
|
||||
}},
|
||||
StopResources: []*sdkproto.Resource{},
|
||||
GitAuthProviders: []string{"github"},
|
||||
StopResources: []*sdkproto.Resource{},
|
||||
ExternalAuthProviders: []string{"github"},
|
||||
},
|
||||
},
|
||||
})
|
||||
@@ -1675,7 +1675,7 @@ func TestInsertWorkspaceResource(t *testing.T) {
|
||||
|
||||
type overrides struct {
|
||||
deploymentValues *codersdk.DeploymentValues
|
||||
gitAuthConfigs []*gitauth.Config
|
||||
externalAuthConfigs []*gitauth.Config
|
||||
id *uuid.UUID
|
||||
templateScheduleStore *atomic.Pointer[schedule.TemplateScheduleStore]
|
||||
userQuietHoursScheduleStore *atomic.Pointer[schedule.UserQuietHoursScheduleStore]
|
||||
@@ -1691,7 +1691,7 @@ func setup(t *testing.T, ignoreLogErrors bool, ov *overrides) (proto.DRPCProvisi
|
||||
db := dbfake.New()
|
||||
ps := pubsub.NewInMemory()
|
||||
deploymentValues := &codersdk.DeploymentValues{}
|
||||
var gitAuthConfigs []*gitauth.Config
|
||||
var externalAuthConfigs []*gitauth.Config
|
||||
srvID := uuid.New()
|
||||
tss := testTemplateScheduleStore()
|
||||
uqhss := testUserQuietHoursScheduleStore()
|
||||
@@ -1701,8 +1701,8 @@ func setup(t *testing.T, ignoreLogErrors bool, ov *overrides) (proto.DRPCProvisi
|
||||
if ov.deploymentValues != nil {
|
||||
deploymentValues = ov.deploymentValues
|
||||
}
|
||||
if ov.gitAuthConfigs != nil {
|
||||
gitAuthConfigs = ov.gitAuthConfigs
|
||||
if ov.externalAuthConfigs != nil {
|
||||
externalAuthConfigs = ov.externalAuthConfigs
|
||||
}
|
||||
if ov.id != nil {
|
||||
srvID = *ov.id
|
||||
@@ -1748,7 +1748,7 @@ func setup(t *testing.T, ignoreLogErrors bool, ov *overrides) (proto.DRPCProvisi
|
||||
uqhss,
|
||||
deploymentValues,
|
||||
provisionerdserver.Options{
|
||||
GitAuthConfigs: gitAuthConfigs,
|
||||
ExternalAuthConfigs: externalAuthConfigs,
|
||||
TimeNowFn: timeNowFn,
|
||||
OIDCConfig: &oauth2.Config{},
|
||||
AcquireJobLongPollDur: pollDur,
|
||||
|
||||
Reference in New Issue
Block a user