mirror of
https://github.com/gravitational/teleport.git
synced 2026-08-31 02:28:23 +08:00
8858cee029
* add config field in cluster auth preference * extend ClusterConfiguration to support checking auth preference in AtomicWrite * stable UNIX users storage * auth API and auth-side business logic * move server implementation to a subpackage * Use proto3 and the default (open) API * remove type alias for ClusterConfiguration * Move new AuthPreference validation into a Validate method * Check the StableUnixUserConfig before use * use Config instead of Params * Don't rely on error types for the retry logic * Fix TestStableUNIXUsersBasic * Use free functions for Validate * make grpc * black-box testing that includes authz
54 lines
2.3 KiB
Go
54 lines
2.3 KiB
Go
// Teleport
|
|
// Copyright (C) 2025 Gravitational, Inc.
|
|
//
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU Affero General Public License as published by
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
// (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU Affero General Public License for more details.
|
|
//
|
|
// You should have received a copy of the GNU Affero General Public License
|
|
// along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
package services
|
|
|
|
import (
|
|
"context"
|
|
|
|
"github.com/gravitational/teleport/lib/backend"
|
|
)
|
|
|
|
// StableUNIXUsersInternal is the (auth-only) storage service to interact with
|
|
// stable UNIX users.
|
|
type StableUNIXUsersInternal interface {
|
|
// ListStableUNIXUsers returns a page of username/UID pairs. The returned
|
|
// next page token is empty when fetching the last page in the list;
|
|
// otherwise it can be passed to ListStableUNIXUsers to fetch the next page.
|
|
ListStableUNIXUsers(ctx context.Context, pageSize int, pageToken string) (_ []StableUNIXUser, nextPageToken string, _ error)
|
|
|
|
// GetUIDForUsername returns the stable UID associated with the given
|
|
// username, if one exists, or a NotFound.
|
|
GetUIDForUsername(context.Context, string) (int32, error)
|
|
// SearchFreeUID returns the first available UID in the range between first
|
|
// and last (included). If no stored UIDs are within the range, it returns
|
|
// first. If no UIDs are available in the range, the returned bool will be
|
|
// false.
|
|
SearchFreeUID(ctx context.Context, first, last int32) (int32, bool, error)
|
|
|
|
// AppendCreateStableUNIXUser appends some atomic write actions to the given
|
|
// slice that will create a username/UID pair for a stable UNIX user. The
|
|
// backend to which the actions are applied should be the same backend used
|
|
// by the StableUNIXUsersInternal.
|
|
AppendCreateStableUNIXUser(actions []backend.ConditionalAction, username string, uid int32) ([]backend.ConditionalAction, error)
|
|
}
|
|
|
|
// StableUNIXUser is a username/UID pair representing a stable UNIX user.
|
|
type StableUNIXUser struct {
|
|
Username string
|
|
UID int32
|
|
}
|