mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: merge authorization contexts (#12816)
* chore: merge authorization contexts Instead of 2 auth contexts from apikey and dbauthz, merge them to just use dbauthz. It is annoying to have two. * fixup authorization reference
This commit is contained in:
+17
-17
@@ -19,15 +19,15 @@ import (
|
||||
// This is faster than calling Authorize() on each object.
|
||||
func AuthorizeFilter[O rbac.Objecter](h *HTTPAuthorizer, r *http.Request, action rbac.Action, objects []O) ([]O, error) {
|
||||
roles := httpmw.UserAuthorization(r)
|
||||
objects, err := rbac.Filter(r.Context(), h.Authorizer, roles.Actor, action, objects)
|
||||
objects, err := rbac.Filter(r.Context(), h.Authorizer, roles, action, objects)
|
||||
if err != nil {
|
||||
// Log the error as Filter should not be erroring.
|
||||
h.Logger.Error(r.Context(), "authorization filter failed",
|
||||
slog.Error(err),
|
||||
slog.F("user_id", roles.Actor.ID),
|
||||
slog.F("username", roles.ActorName),
|
||||
slog.F("roles", roles.Actor.SafeRoleNames()),
|
||||
slog.F("scope", roles.Actor.SafeScopeName()),
|
||||
slog.F("user_id", roles.ID),
|
||||
slog.F("username", roles),
|
||||
slog.F("roles", roles.SafeRoleNames()),
|
||||
slog.F("scope", roles.SafeScopeName()),
|
||||
slog.F("route", r.URL.Path),
|
||||
slog.F("action", action),
|
||||
)
|
||||
@@ -65,7 +65,7 @@ func (api *API) Authorize(r *http.Request, action rbac.Action, object rbac.Objec
|
||||
// }
|
||||
func (h *HTTPAuthorizer) Authorize(r *http.Request, action rbac.Action, object rbac.Objecter) bool {
|
||||
roles := httpmw.UserAuthorization(r)
|
||||
err := h.Authorizer.Authorize(r.Context(), roles.Actor, action, object.RBACObject())
|
||||
err := h.Authorizer.Authorize(r.Context(), roles, action, object.RBACObject())
|
||||
if err != nil {
|
||||
// Log the errors for debugging
|
||||
internalError := new(rbac.UnauthorizedError)
|
||||
@@ -76,10 +76,10 @@ func (h *HTTPAuthorizer) Authorize(r *http.Request, action rbac.Action, object r
|
||||
// Log information for debugging. This will be very helpful
|
||||
// in the early days
|
||||
logger.Warn(r.Context(), "requester is not authorized to access the object",
|
||||
slog.F("roles", roles.Actor.SafeRoleNames()),
|
||||
slog.F("actor_id", roles.Actor.ID),
|
||||
slog.F("actor_name", roles.ActorName),
|
||||
slog.F("scope", roles.Actor.SafeScopeName()),
|
||||
slog.F("roles", roles.SafeRoleNames()),
|
||||
slog.F("actor_id", roles.ID),
|
||||
slog.F("actor_name", roles),
|
||||
slog.F("scope", roles.SafeScopeName()),
|
||||
slog.F("route", r.URL.Path),
|
||||
slog.F("action", action),
|
||||
slog.F("object", object),
|
||||
@@ -97,7 +97,7 @@ func (h *HTTPAuthorizer) Authorize(r *http.Request, action rbac.Action, object r
|
||||
// Note the authorization is only for the given action and object type.
|
||||
func (h *HTTPAuthorizer) AuthorizeSQLFilter(r *http.Request, action rbac.Action, objectType string) (rbac.PreparedAuthorized, error) {
|
||||
roles := httpmw.UserAuthorization(r)
|
||||
prepared, err := h.Authorizer.Prepare(r.Context(), roles.Actor, action, objectType)
|
||||
prepared, err := h.Authorizer.Prepare(r.Context(), roles, action, objectType)
|
||||
if err != nil {
|
||||
return nil, xerrors.Errorf("prepare filter: %w", err)
|
||||
}
|
||||
@@ -128,10 +128,10 @@ func (api *API) checkAuthorization(rw http.ResponseWriter, r *http.Request) {
|
||||
|
||||
api.Logger.Debug(ctx, "check-auth",
|
||||
slog.F("my_id", httpmw.APIKey(r).UserID),
|
||||
slog.F("got_id", auth.Actor.ID),
|
||||
slog.F("name", auth.ActorName),
|
||||
slog.F("roles", auth.Actor.SafeRoleNames()),
|
||||
slog.F("scope", auth.Actor.SafeScopeName()),
|
||||
slog.F("got_id", auth.ID),
|
||||
slog.F("name", auth),
|
||||
slog.F("roles", auth.SafeRoleNames()),
|
||||
slog.F("scope", auth.SafeScopeName()),
|
||||
)
|
||||
|
||||
response := make(codersdk.AuthorizationResponse)
|
||||
@@ -171,7 +171,7 @@ func (api *API) checkAuthorization(rw http.ResponseWriter, r *http.Request) {
|
||||
Type: v.Object.ResourceType.String(),
|
||||
}
|
||||
if obj.Owner == "me" {
|
||||
obj.Owner = auth.Actor.ID
|
||||
obj.Owner = auth.ID
|
||||
}
|
||||
|
||||
// If a resource ID is specified, fetch that specific resource.
|
||||
@@ -219,7 +219,7 @@ func (api *API) checkAuthorization(rw http.ResponseWriter, r *http.Request) {
|
||||
obj = dbObj.RBACObject()
|
||||
}
|
||||
|
||||
err := api.Authorizer.Authorize(ctx, auth.Actor, rbac.Action(v.Action), obj)
|
||||
err := api.Authorizer.Authorize(ctx, auth, rbac.Action(v.Action), obj)
|
||||
response[k] = err == nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user