2023-02-17 16:06:41 +03:00
|
|
|
package store
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"encoding/json"
|
|
|
|
"fmt"
|
|
|
|
"strings"
|
2023-09-17 17:55:13 +03:00
|
|
|
|
|
|
|
"github.com/pkg/errors"
|
2023-02-17 16:06:41 +03:00
|
|
|
)
|
|
|
|
|
2023-02-18 06:29:12 +03:00
|
|
|
type IdentityProviderType string
|
2023-02-17 16:06:41 +03:00
|
|
|
|
|
|
|
const (
|
2023-07-02 13:56:25 +03:00
|
|
|
IdentityProviderOAuth2Type IdentityProviderType = "OAUTH2"
|
2023-02-17 16:06:41 +03:00
|
|
|
)
|
|
|
|
|
2023-07-02 13:56:25 +03:00
|
|
|
func (t IdentityProviderType) String() string {
|
|
|
|
return string(t)
|
|
|
|
}
|
|
|
|
|
2023-02-18 13:31:03 +03:00
|
|
|
type IdentityProviderConfig struct {
|
|
|
|
OAuth2Config *IdentityProviderOAuth2Config
|
|
|
|
}
|
2023-02-17 16:06:41 +03:00
|
|
|
|
|
|
|
type IdentityProviderOAuth2Config struct {
|
|
|
|
ClientID string `json:"clientId"`
|
|
|
|
ClientSecret string `json:"clientSecret"`
|
|
|
|
AuthURL string `json:"authUrl"`
|
|
|
|
TokenURL string `json:"tokenUrl"`
|
|
|
|
UserInfoURL string `json:"userInfoUrl"`
|
|
|
|
Scopes []string `json:"scopes"`
|
|
|
|
FieldMapping *FieldMapping `json:"fieldMapping"`
|
|
|
|
}
|
|
|
|
|
|
|
|
type FieldMapping struct {
|
2023-02-18 06:29:12 +03:00
|
|
|
Identifier string `json:"identifier"`
|
|
|
|
DisplayName string `json:"displayName"`
|
|
|
|
Email string `json:"email"`
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
type IdentityProvider struct {
|
2023-08-04 16:55:07 +03:00
|
|
|
ID int32
|
2023-02-17 16:06:41 +03:00
|
|
|
Name string
|
2023-02-18 06:29:12 +03:00
|
|
|
Type IdentityProviderType
|
2023-02-17 16:06:41 +03:00
|
|
|
IdentifierFilter string
|
|
|
|
Config *IdentityProviderConfig
|
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
type FindIdentityProvider struct {
|
2023-08-04 16:55:07 +03:00
|
|
|
ID *int32
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
type UpdateIdentityProvider struct {
|
2023-08-04 16:55:07 +03:00
|
|
|
ID int32
|
2023-02-18 06:29:12 +03:00
|
|
|
Type IdentityProviderType
|
2023-02-17 16:06:41 +03:00
|
|
|
Name *string
|
|
|
|
IdentifierFilter *string
|
|
|
|
Config *IdentityProviderConfig
|
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
type DeleteIdentityProvider struct {
|
2023-08-04 16:55:07 +03:00
|
|
|
ID int32
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
func (s *Store) CreateIdentityProvider(ctx context.Context, create *IdentityProvider) (*IdentityProvider, error) {
|
2023-02-17 16:06:41 +03:00
|
|
|
var configBytes []byte
|
2023-07-02 13:56:25 +03:00
|
|
|
if create.Type == IdentityProviderOAuth2Type {
|
2023-07-20 18:15:56 +03:00
|
|
|
bytes, err := json.Marshal(create.Config.OAuth2Config)
|
2023-02-17 16:06:41 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2023-07-20 18:15:56 +03:00
|
|
|
configBytes = bytes
|
2023-02-17 16:06:41 +03:00
|
|
|
} else {
|
2023-09-17 17:55:13 +03:00
|
|
|
return nil, errors.Errorf("unsupported idp type %s", string(create.Type))
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
2023-06-26 18:46:01 +03:00
|
|
|
|
2023-07-20 18:15:56 +03:00
|
|
|
stmt := `
|
2023-02-17 16:06:41 +03:00
|
|
|
INSERT INTO idp (
|
|
|
|
name,
|
|
|
|
type,
|
|
|
|
identifier_filter,
|
|
|
|
config
|
|
|
|
)
|
|
|
|
VALUES (?, ?, ?, ?)
|
|
|
|
RETURNING id
|
|
|
|
`
|
2023-07-20 18:15:56 +03:00
|
|
|
if err := s.db.QueryRowContext(
|
2023-02-17 16:06:41 +03:00
|
|
|
ctx,
|
2023-07-20 18:15:56 +03:00
|
|
|
stmt,
|
2023-02-17 16:06:41 +03:00
|
|
|
create.Name,
|
|
|
|
create.Type,
|
|
|
|
create.IdentifierFilter,
|
|
|
|
string(configBytes),
|
|
|
|
).Scan(
|
|
|
|
&create.ID,
|
|
|
|
); err != nil {
|
2023-06-26 18:46:01 +03:00
|
|
|
return nil, err
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
2023-06-26 18:46:01 +03:00
|
|
|
|
|
|
|
identityProvider := create
|
|
|
|
s.idpCache.Store(identityProvider.ID, identityProvider)
|
|
|
|
return identityProvider, nil
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
func (s *Store) ListIdentityProviders(ctx context.Context, find *FindIdentityProvider) ([]*IdentityProvider, error) {
|
2023-07-20 18:15:56 +03:00
|
|
|
where, args := []string{"1 = 1"}, []any{}
|
|
|
|
if v := find.ID; v != nil {
|
|
|
|
where, args = append(where, fmt.Sprintf("id = $%d", len(args)+1)), append(args, *v)
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-07-20 18:15:56 +03:00
|
|
|
rows, err := s.db.QueryContext(ctx, `
|
|
|
|
SELECT
|
|
|
|
id,
|
|
|
|
name,
|
|
|
|
type,
|
|
|
|
identifier_filter,
|
|
|
|
config
|
|
|
|
FROM idp
|
|
|
|
WHERE `+strings.Join(where, " AND ")+` ORDER BY id ASC`,
|
|
|
|
args...,
|
|
|
|
)
|
2023-02-17 16:06:41 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2023-07-20 18:15:56 +03:00
|
|
|
defer rows.Close()
|
|
|
|
|
|
|
|
var identityProviders []*IdentityProvider
|
|
|
|
for rows.Next() {
|
|
|
|
var identityProvider IdentityProvider
|
|
|
|
var identityProviderConfig string
|
|
|
|
if err := rows.Scan(
|
|
|
|
&identityProvider.ID,
|
|
|
|
&identityProvider.Name,
|
|
|
|
&identityProvider.Type,
|
|
|
|
&identityProvider.IdentifierFilter,
|
|
|
|
&identityProviderConfig,
|
|
|
|
); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
if identityProvider.Type == IdentityProviderOAuth2Type {
|
|
|
|
oauth2Config := &IdentityProviderOAuth2Config{}
|
|
|
|
if err := json.Unmarshal([]byte(identityProviderConfig), oauth2Config); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
identityProvider.Config = &IdentityProviderConfig{
|
|
|
|
OAuth2Config: oauth2Config,
|
|
|
|
}
|
|
|
|
} else {
|
2023-09-17 17:55:13 +03:00
|
|
|
return nil, errors.Errorf("unsupported idp type %s", string(identityProvider.Type))
|
2023-07-20 18:15:56 +03:00
|
|
|
}
|
|
|
|
identityProviders = append(identityProviders, &identityProvider)
|
|
|
|
}
|
2023-02-17 16:06:41 +03:00
|
|
|
|
2023-07-20 18:15:56 +03:00
|
|
|
if err := rows.Err(); err != nil {
|
2023-07-06 16:56:42 +03:00
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2023-07-20 18:15:56 +03:00
|
|
|
for _, item := range identityProviders {
|
2023-02-18 13:41:52 +03:00
|
|
|
s.idpCache.Store(item.ID, item)
|
|
|
|
}
|
2023-07-20 18:15:56 +03:00
|
|
|
return identityProviders, nil
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
func (s *Store) GetIdentityProvider(ctx context.Context, find *FindIdentityProvider) (*IdentityProvider, error) {
|
2023-02-18 13:41:52 +03:00
|
|
|
if find.ID != nil {
|
|
|
|
if cache, ok := s.idpCache.Load(*find.ID); ok {
|
2023-06-26 18:46:01 +03:00
|
|
|
return cache.(*IdentityProvider), nil
|
2023-02-18 13:41:52 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-07-20 18:15:56 +03:00
|
|
|
list, err := s.ListIdentityProviders(ctx, find)
|
2023-02-17 16:06:41 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
if len(list) == 0 {
|
2023-06-26 18:46:01 +03:00
|
|
|
return nil, nil
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
identityProvider := list[0]
|
|
|
|
s.idpCache.Store(identityProvider.ID, identityProvider)
|
|
|
|
return identityProvider, nil
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
func (s *Store) UpdateIdentityProvider(ctx context.Context, update *UpdateIdentityProvider) (*IdentityProvider, error) {
|
2023-03-18 17:34:22 +03:00
|
|
|
set, args := []string{}, []any{}
|
2023-02-17 16:06:41 +03:00
|
|
|
if v := update.Name; v != nil {
|
|
|
|
set, args = append(set, "name = ?"), append(args, *v)
|
|
|
|
}
|
|
|
|
if v := update.IdentifierFilter; v != nil {
|
|
|
|
set, args = append(set, "identifier_filter = ?"), append(args, *v)
|
|
|
|
}
|
|
|
|
if v := update.Config; v != nil {
|
|
|
|
var configBytes []byte
|
2023-07-02 13:56:25 +03:00
|
|
|
if update.Type == IdentityProviderOAuth2Type {
|
2023-07-20 18:15:56 +03:00
|
|
|
bytes, err := json.Marshal(update.Config.OAuth2Config)
|
2023-02-17 16:06:41 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2023-07-20 18:15:56 +03:00
|
|
|
configBytes = bytes
|
2023-02-17 16:06:41 +03:00
|
|
|
} else {
|
2023-09-17 17:55:13 +03:00
|
|
|
return nil, errors.Errorf("unsupported idp type %s", string(update.Type))
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
set, args = append(set, "config = ?"), append(args, string(configBytes))
|
|
|
|
}
|
|
|
|
args = append(args, update.ID)
|
|
|
|
|
2023-07-20 18:15:56 +03:00
|
|
|
stmt := `
|
2023-02-17 16:06:41 +03:00
|
|
|
UPDATE idp
|
|
|
|
SET ` + strings.Join(set, ", ") + `
|
|
|
|
WHERE id = ?
|
|
|
|
RETURNING id, name, type, identifier_filter, config
|
|
|
|
`
|
2023-06-26 18:46:01 +03:00
|
|
|
var identityProvider IdentityProvider
|
2023-02-17 16:06:41 +03:00
|
|
|
var identityProviderConfig string
|
2023-07-20 18:15:56 +03:00
|
|
|
if err := s.db.QueryRowContext(ctx, stmt, args...).Scan(
|
2023-06-26 18:46:01 +03:00
|
|
|
&identityProvider.ID,
|
|
|
|
&identityProvider.Name,
|
|
|
|
&identityProvider.Type,
|
|
|
|
&identityProvider.IdentifierFilter,
|
2023-02-17 16:06:41 +03:00
|
|
|
&identityProviderConfig,
|
|
|
|
); err != nil {
|
2023-06-26 18:46:01 +03:00
|
|
|
return nil, err
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
2023-06-26 18:46:01 +03:00
|
|
|
|
2023-07-02 13:56:25 +03:00
|
|
|
if identityProvider.Type == IdentityProviderOAuth2Type {
|
2023-02-18 13:31:03 +03:00
|
|
|
oauth2Config := &IdentityProviderOAuth2Config{}
|
|
|
|
if err := json.Unmarshal([]byte(identityProviderConfig), oauth2Config); err != nil {
|
2023-02-17 16:06:41 +03:00
|
|
|
return nil, err
|
|
|
|
}
|
2023-06-26 18:46:01 +03:00
|
|
|
identityProvider.Config = &IdentityProviderConfig{
|
2023-02-18 13:31:03 +03:00
|
|
|
OAuth2Config: oauth2Config,
|
|
|
|
}
|
2023-02-17 16:06:41 +03:00
|
|
|
} else {
|
2023-09-17 17:55:13 +03:00
|
|
|
return nil, errors.Errorf("unsupported idp type %s", string(identityProvider.Type))
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
2023-06-26 18:46:01 +03:00
|
|
|
|
|
|
|
s.idpCache.Store(identityProvider.ID, identityProvider)
|
|
|
|
return &identityProvider, nil
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
|
|
|
|
2023-06-26 18:46:01 +03:00
|
|
|
func (s *Store) DeleteIdentityProvider(ctx context.Context, delete *DeleteIdentityProvider) error {
|
2023-03-18 17:34:22 +03:00
|
|
|
where, args := []string{"id = ?"}, []any{delete.ID}
|
2023-02-17 16:06:41 +03:00
|
|
|
stmt := `DELETE FROM idp WHERE ` + strings.Join(where, " AND ")
|
2023-07-20 18:15:56 +03:00
|
|
|
result, err := s.db.ExecContext(ctx, stmt, args...)
|
2023-02-17 16:06:41 +03:00
|
|
|
if err != nil {
|
2023-06-26 18:46:01 +03:00
|
|
|
return err
|
2023-02-17 16:06:41 +03:00
|
|
|
}
|
2023-06-26 18:46:01 +03:00
|
|
|
if _, err = result.RowsAffected(); err != nil {
|
2023-02-17 16:06:41 +03:00
|
|
|
return err
|
|
|
|
}
|
2023-02-18 13:41:52 +03:00
|
|
|
s.idpCache.Delete(delete.ID)
|
2023-02-17 16:06:41 +03:00
|
|
|
return nil
|
|
|
|
}
|