2021-01-04 13:52:13 +00:00
|
|
|
package command
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
2021-05-20 11:33:35 +00:00
|
|
|
"time"
|
|
|
|
|
2021-03-01 07:48:50 +00:00
|
|
|
"github.com/caos/zitadel/internal/api/authz"
|
2021-03-25 16:26:21 +00:00
|
|
|
authz_repo "github.com/caos/zitadel/internal/authz/repository/eventsourcing"
|
2021-02-24 10:17:39 +00:00
|
|
|
"github.com/caos/zitadel/internal/config/types"
|
2021-03-01 07:48:50 +00:00
|
|
|
"github.com/caos/zitadel/internal/domain"
|
2021-02-23 14:13:04 +00:00
|
|
|
"github.com/caos/zitadel/internal/eventstore"
|
2021-01-04 13:52:13 +00:00
|
|
|
|
2021-01-18 10:24:15 +00:00
|
|
|
"github.com/caos/zitadel/internal/api/http"
|
2021-01-04 13:52:13 +00:00
|
|
|
sd "github.com/caos/zitadel/internal/config/systemdefaults"
|
|
|
|
"github.com/caos/zitadel/internal/crypto"
|
|
|
|
"github.com/caos/zitadel/internal/id"
|
2021-02-23 14:13:04 +00:00
|
|
|
iam_repo "github.com/caos/zitadel/internal/repository/iam"
|
2021-05-20 11:33:35 +00:00
|
|
|
"github.com/caos/zitadel/internal/repository/keypair"
|
2021-02-23 14:13:04 +00:00
|
|
|
"github.com/caos/zitadel/internal/repository/org"
|
|
|
|
proj_repo "github.com/caos/zitadel/internal/repository/project"
|
|
|
|
usr_repo "github.com/caos/zitadel/internal/repository/user"
|
|
|
|
usr_grant_repo "github.com/caos/zitadel/internal/repository/usergrant"
|
2021-01-04 13:52:13 +00:00
|
|
|
"github.com/caos/zitadel/internal/telemetry/tracing"
|
2021-01-18 10:24:15 +00:00
|
|
|
webauthn_helper "github.com/caos/zitadel/internal/webauthn"
|
2021-01-04 13:52:13 +00:00
|
|
|
)
|
|
|
|
|
2021-02-24 10:17:39 +00:00
|
|
|
type Commands struct {
|
2021-03-01 07:48:50 +00:00
|
|
|
eventstore *eventstore.Eventstore
|
|
|
|
idGenerator id.Generator
|
|
|
|
iamDomain string
|
|
|
|
zitadelRoles []authz.RoleMapping
|
2021-01-04 13:52:13 +00:00
|
|
|
|
2021-03-19 10:12:56 +00:00
|
|
|
idpConfigSecretCrypto crypto.EncryptionAlgorithm
|
2021-01-04 13:52:13 +00:00
|
|
|
|
2021-01-18 10:24:15 +00:00
|
|
|
userPasswordAlg crypto.HashAlgorithm
|
|
|
|
initializeUserCode crypto.Generator
|
|
|
|
emailVerificationCode crypto.Generator
|
|
|
|
phoneVerificationCode crypto.Generator
|
|
|
|
passwordVerificationCode crypto.Generator
|
|
|
|
machineKeyAlg crypto.EncryptionAlgorithm
|
|
|
|
machineKeySize int
|
2021-02-22 11:27:47 +00:00
|
|
|
applicationKeySize int
|
2021-01-18 10:24:15 +00:00
|
|
|
applicationSecretGenerator crypto.Generator
|
2021-03-19 10:12:56 +00:00
|
|
|
domainVerificationAlg crypto.EncryptionAlgorithm
|
2021-01-18 10:24:15 +00:00
|
|
|
domainVerificationGenerator crypto.Generator
|
|
|
|
domainVerificationValidator func(domain, token, verifier string, checkType http.CheckType) error
|
2021-03-01 07:48:50 +00:00
|
|
|
multifactors domain.MultifactorConfigs
|
2021-02-12 15:51:12 +00:00
|
|
|
|
2021-02-22 11:27:47 +00:00
|
|
|
webauthn *webauthn_helper.WebAuthN
|
2021-02-12 15:51:12 +00:00
|
|
|
keySize int
|
|
|
|
keyAlgorithm crypto.EncryptionAlgorithm
|
|
|
|
privateKeyLifetime time.Duration
|
|
|
|
publicKeyLifetime time.Duration
|
2021-03-25 16:26:21 +00:00
|
|
|
tokenVerifier *authz.TokenVerifier
|
2021-01-04 13:52:13 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
type Config struct {
|
2021-02-24 10:17:39 +00:00
|
|
|
Eventstore types.SQLUser
|
2021-01-04 13:52:13 +00:00
|
|
|
}
|
|
|
|
|
2021-03-25 16:26:21 +00:00
|
|
|
func StartCommands(eventstore *eventstore.Eventstore, defaults sd.SystemDefaults, authZConfig authz.Config, authZRepo *authz_repo.EsRepository) (repo *Commands, err error) {
|
2021-02-24 10:17:39 +00:00
|
|
|
repo = &Commands{
|
|
|
|
eventstore: eventstore,
|
2021-02-12 15:51:12 +00:00
|
|
|
idGenerator: id.SonyFlakeGenerator,
|
2021-02-24 10:17:39 +00:00
|
|
|
iamDomain: defaults.Domain,
|
2021-03-01 07:48:50 +00:00
|
|
|
zitadelRoles: authZConfig.RolePermissionMappings,
|
2021-02-24 10:17:39 +00:00
|
|
|
keySize: defaults.KeyConfig.Size,
|
|
|
|
privateKeyLifetime: defaults.KeyConfig.PrivateKeyLifetime.Duration,
|
|
|
|
publicKeyLifetime: defaults.KeyConfig.PublicKeyLifetime.Duration,
|
2021-01-04 13:52:13 +00:00
|
|
|
}
|
|
|
|
iam_repo.RegisterEventMappers(repo.eventstore)
|
2021-01-18 10:24:15 +00:00
|
|
|
org.RegisterEventMappers(repo.eventstore)
|
2021-01-15 08:32:59 +00:00
|
|
|
usr_repo.RegisterEventMappers(repo.eventstore)
|
2021-01-22 12:31:52 +00:00
|
|
|
usr_grant_repo.RegisterEventMappers(repo.eventstore)
|
|
|
|
proj_repo.RegisterEventMappers(repo.eventstore)
|
2021-02-12 15:51:12 +00:00
|
|
|
keypair.RegisterEventMappers(repo.eventstore)
|
2021-01-04 13:52:13 +00:00
|
|
|
|
2021-02-24 10:17:39 +00:00
|
|
|
repo.idpConfigSecretCrypto, err = crypto.NewAESCrypto(defaults.IDPConfigVerificationKey)
|
2021-01-04 13:52:13 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2021-02-24 10:17:39 +00:00
|
|
|
userEncryptionAlgorithm, err := crypto.NewAESCrypto(defaults.UserVerificationKey)
|
2021-01-04 13:52:13 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2021-02-24 10:17:39 +00:00
|
|
|
repo.initializeUserCode = crypto.NewEncryptionGenerator(defaults.SecretGenerators.InitializeUserCode, userEncryptionAlgorithm)
|
|
|
|
repo.emailVerificationCode = crypto.NewEncryptionGenerator(defaults.SecretGenerators.EmailVerificationCode, userEncryptionAlgorithm)
|
|
|
|
repo.phoneVerificationCode = crypto.NewEncryptionGenerator(defaults.SecretGenerators.PhoneVerificationCode, userEncryptionAlgorithm)
|
|
|
|
repo.passwordVerificationCode = crypto.NewEncryptionGenerator(defaults.SecretGenerators.PasswordVerificationCode, userEncryptionAlgorithm)
|
|
|
|
repo.userPasswordAlg = crypto.NewBCrypt(defaults.SecretGenerators.PasswordSaltCost)
|
2021-01-12 11:59:51 +00:00
|
|
|
repo.machineKeyAlg = userEncryptionAlgorithm
|
2021-02-24 10:17:39 +00:00
|
|
|
repo.machineKeySize = int(defaults.SecretGenerators.MachineKeySize)
|
|
|
|
repo.applicationKeySize = int(defaults.SecretGenerators.ApplicationKeySize)
|
2021-01-12 11:59:51 +00:00
|
|
|
|
2021-02-24 10:17:39 +00:00
|
|
|
aesOTPCrypto, err := crypto.NewAESCrypto(defaults.Multifactors.OTP.VerificationKey)
|
2021-01-15 08:32:59 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2021-03-01 07:48:50 +00:00
|
|
|
repo.multifactors = domain.MultifactorConfigs{
|
|
|
|
OTP: domain.OTPConfig{
|
2021-01-15 08:32:59 +00:00
|
|
|
CryptoMFA: aesOTPCrypto,
|
2021-02-24 10:17:39 +00:00
|
|
|
Issuer: defaults.Multifactors.OTP.Issuer,
|
2021-01-15 08:32:59 +00:00
|
|
|
},
|
|
|
|
}
|
2021-02-24 10:17:39 +00:00
|
|
|
passwordAlg := crypto.NewBCrypt(defaults.SecretGenerators.PasswordSaltCost)
|
|
|
|
repo.applicationSecretGenerator = crypto.NewHashGenerator(defaults.SecretGenerators.ClientSecretGenerator, passwordAlg)
|
2021-01-18 10:24:15 +00:00
|
|
|
|
2021-02-24 10:17:39 +00:00
|
|
|
repo.domainVerificationAlg, err = crypto.NewAESCrypto(defaults.DomainVerification.VerificationKey)
|
2021-01-18 10:24:15 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2021-02-24 10:17:39 +00:00
|
|
|
repo.domainVerificationGenerator = crypto.NewEncryptionGenerator(defaults.DomainVerification.VerificationGenerator, repo.domainVerificationAlg)
|
2021-01-18 10:24:15 +00:00
|
|
|
repo.domainVerificationValidator = http.ValidateDomain
|
2021-02-24 10:17:39 +00:00
|
|
|
web, err := webauthn_helper.StartServer(defaults.WebAuthN)
|
2021-01-15 08:32:59 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
repo.webauthn = web
|
2021-02-12 15:51:12 +00:00
|
|
|
|
2021-02-24 10:17:39 +00:00
|
|
|
keyAlgorithm, err := crypto.NewAESCrypto(defaults.KeyConfig.EncryptionConfig)
|
2021-02-12 15:51:12 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
repo.keyAlgorithm = keyAlgorithm
|
2021-03-25 16:26:21 +00:00
|
|
|
|
|
|
|
repo.tokenVerifier = authz.Start(authZRepo)
|
2021-01-04 13:52:13 +00:00
|
|
|
return repo, nil
|
|
|
|
}
|
|
|
|
|
2021-02-24 10:17:39 +00:00
|
|
|
func (c *Commands) getIAMWriteModel(ctx context.Context) (_ *IAMWriteModel, err error) {
|
2021-01-04 13:52:13 +00:00
|
|
|
ctx, span := tracing.NewSpan(ctx)
|
|
|
|
defer func() { span.EndWithError(err) }()
|
|
|
|
|
2021-01-12 11:59:51 +00:00
|
|
|
writeModel := NewIAMWriteModel()
|
2021-02-24 10:17:39 +00:00
|
|
|
err = c.eventstore.FilterToQueryReducer(ctx, writeModel)
|
2021-01-04 13:52:13 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
return writeModel, nil
|
|
|
|
}
|
2021-02-18 13:48:27 +00:00
|
|
|
|
|
|
|
func AppendAndReduce(object interface {
|
|
|
|
AppendEvents(...eventstore.EventReader)
|
|
|
|
Reduce() error
|
|
|
|
}, events ...eventstore.EventReader) error {
|
|
|
|
object.AppendEvents(events...)
|
|
|
|
return object.Reduce()
|
|
|
|
}
|