2020-03-24 13:15:01 +00:00
|
|
|
package middleware
|
2020-03-23 06:01:59 +00:00
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
2020-07-08 11:56:37 +00:00
|
|
|
|
2020-03-23 06:01:59 +00:00
|
|
|
"google.golang.org/grpc"
|
|
|
|
"google.golang.org/grpc/codes"
|
|
|
|
"google.golang.org/grpc/status"
|
|
|
|
|
2020-07-08 11:56:37 +00:00
|
|
|
"github.com/caos/zitadel/internal/api/authz"
|
2020-03-24 13:15:01 +00:00
|
|
|
grpc_util "github.com/caos/zitadel/internal/api/grpc"
|
2020-07-08 11:56:37 +00:00
|
|
|
"github.com/caos/zitadel/internal/api/http"
|
2020-12-02 07:50:59 +00:00
|
|
|
"github.com/caos/zitadel/internal/telemetry/tracing"
|
2020-03-23 06:01:59 +00:00
|
|
|
)
|
|
|
|
|
2020-07-08 11:56:37 +00:00
|
|
|
func AuthorizationInterceptor(verifier *authz.TokenVerifier, authConfig authz.Config) grpc.UnaryServerInterceptor {
|
2020-03-23 06:01:59 +00:00
|
|
|
return func(ctx context.Context, req interface{}, info *grpc.UnaryServerInfo, handler grpc.UnaryHandler) (interface{}, error) {
|
2020-07-08 11:56:37 +00:00
|
|
|
return authorize(ctx, req, info, handler, verifier, authConfig)
|
|
|
|
}
|
|
|
|
}
|
2020-03-23 06:01:59 +00:00
|
|
|
|
2020-10-21 08:18:34 +00:00
|
|
|
func authorize(ctx context.Context, req interface{}, info *grpc.UnaryServerInfo, handler grpc.UnaryHandler, verifier *authz.TokenVerifier, authConfig authz.Config) (_ interface{}, err error) {
|
2020-07-08 11:56:37 +00:00
|
|
|
authOpt, needsToken := verifier.CheckAuthMethod(info.FullMethod)
|
|
|
|
if !needsToken {
|
2020-03-23 06:01:59 +00:00
|
|
|
return handler(ctx, req)
|
|
|
|
}
|
2020-07-08 11:56:37 +00:00
|
|
|
|
2020-11-20 06:57:39 +00:00
|
|
|
ctx, span := tracing.NewServerInterceptorSpan(ctx)
|
|
|
|
defer func() { span.EndWithError(err) }()
|
|
|
|
|
2020-07-08 11:56:37 +00:00
|
|
|
authToken := grpc_util.GetAuthorizationHeader(ctx)
|
|
|
|
if authToken == "" {
|
|
|
|
return nil, status.Error(codes.Unauthenticated, "auth header missing")
|
|
|
|
}
|
|
|
|
|
|
|
|
orgID := grpc_util.GetHeader(ctx, http.ZitadelOrgID)
|
|
|
|
|
2020-10-21 08:18:34 +00:00
|
|
|
ctx, err = authz.CheckUserAuthorization(ctx, req, authToken, orgID, verifier, authConfig, authOpt, info.FullMethod)
|
2020-07-08 11:56:37 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2020-10-21 08:18:34 +00:00
|
|
|
span.End()
|
2020-07-08 11:56:37 +00:00
|
|
|
return handler(ctx, req)
|
2020-03-23 06:01:59 +00:00
|
|
|
}
|