2021-01-04 14:52:13 +01:00
|
|
|
package command
|
|
|
|
|
|
|
|
import (
|
2022-10-17 21:19:15 +02:00
|
|
|
"context"
|
2022-09-12 17:18:08 +01:00
|
|
|
"net/http"
|
2021-05-20 13:33:35 +02:00
|
|
|
"time"
|
|
|
|
|
2022-04-27 01:01:45 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/api/authz"
|
2022-09-12 17:18:08 +01:00
|
|
|
api_http "github.com/zitadel/zitadel/internal/api/http"
|
2022-10-17 21:19:15 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/command/preparation"
|
2022-04-27 01:01:45 +02:00
|
|
|
sd "github.com/zitadel/zitadel/internal/config/systemdefaults"
|
|
|
|
"github.com/zitadel/zitadel/internal/crypto"
|
|
|
|
"github.com/zitadel/zitadel/internal/domain"
|
2022-04-28 10:30:41 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/errors"
|
2022-04-27 01:01:45 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/eventstore"
|
|
|
|
"github.com/zitadel/zitadel/internal/id"
|
|
|
|
"github.com/zitadel/zitadel/internal/repository/action"
|
2023-05-24 20:29:58 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/repository/idpintent"
|
2022-04-27 01:01:45 +02:00
|
|
|
instance_repo "github.com/zitadel/zitadel/internal/repository/instance"
|
|
|
|
"github.com/zitadel/zitadel/internal/repository/keypair"
|
|
|
|
"github.com/zitadel/zitadel/internal/repository/org"
|
|
|
|
proj_repo "github.com/zitadel/zitadel/internal/repository/project"
|
2023-02-15 02:52:11 +01:00
|
|
|
"github.com/zitadel/zitadel/internal/repository/quota"
|
2023-05-05 17:34:53 +02:00
|
|
|
"github.com/zitadel/zitadel/internal/repository/session"
|
2022-04-27 01:01:45 +02:00
|
|
|
usr_repo "github.com/zitadel/zitadel/internal/repository/user"
|
|
|
|
usr_grant_repo "github.com/zitadel/zitadel/internal/repository/usergrant"
|
|
|
|
"github.com/zitadel/zitadel/internal/static"
|
|
|
|
webauthn_helper "github.com/zitadel/zitadel/internal/webauthn"
|
2021-01-04 14:52:13 +01:00
|
|
|
)
|
|
|
|
|
2021-02-24 11:17:39 +01:00
|
|
|
type Commands struct {
|
2022-09-12 17:18:08 +01:00
|
|
|
httpClient *http.Client
|
|
|
|
|
2023-05-05 17:34:53 +02:00
|
|
|
checkPermission domain.PermissionCheck
|
2023-06-05 18:43:51 +02:00
|
|
|
newEmailCode func(ctx context.Context, filter preparation.FilterToQueryReducer, codeAlg crypto.EncryptionAlgorithm) (*CryptoCodeWithExpiry, error)
|
2023-04-25 09:02:29 +02:00
|
|
|
|
2022-04-25 11:16:36 +02:00
|
|
|
eventstore *eventstore.Eventstore
|
|
|
|
static static.Storage
|
|
|
|
idGenerator id.Generator
|
|
|
|
zitadelRoles []authz.RoleMapping
|
2022-04-28 10:30:41 +02:00
|
|
|
externalDomain string
|
2022-04-25 11:16:36 +02:00
|
|
|
externalSecure bool
|
|
|
|
externalPort uint16
|
2021-01-04 14:52:13 +01:00
|
|
|
|
2022-04-20 16:59:37 +02:00
|
|
|
idpConfigEncryption crypto.EncryptionAlgorithm
|
|
|
|
smtpEncryption crypto.EncryptionAlgorithm
|
|
|
|
smsEncryption crypto.EncryptionAlgorithm
|
|
|
|
userEncryption crypto.EncryptionAlgorithm
|
2021-01-18 11:24:15 +01:00
|
|
|
userPasswordAlg crypto.HashAlgorithm
|
|
|
|
machineKeySize int
|
2021-02-22 12:27:47 +01:00
|
|
|
applicationKeySize int
|
2021-03-19 11:12:56 +01:00
|
|
|
domainVerificationAlg crypto.EncryptionAlgorithm
|
2021-01-18 11:24:15 +01:00
|
|
|
domainVerificationGenerator crypto.Generator
|
2022-09-12 17:18:08 +01:00
|
|
|
domainVerificationValidator func(domain, token, verifier string, checkType api_http.CheckType) error
|
2023-05-05 17:34:53 +02:00
|
|
|
sessionTokenCreator func(sessionID string) (id string, token string, err error)
|
|
|
|
sessionTokenVerifier func(ctx context.Context, sessionToken, sessionID, tokenID string) (err error)
|
2021-02-12 16:51:12 +01:00
|
|
|
|
2022-09-12 17:18:08 +01:00
|
|
|
multifactors domain.MultifactorConfigs
|
|
|
|
webauthnConfig *webauthn_helper.Config
|
|
|
|
keySize int
|
|
|
|
keyAlgorithm crypto.EncryptionAlgorithm
|
|
|
|
certificateAlgorithm crypto.EncryptionAlgorithm
|
|
|
|
certKeySize int
|
|
|
|
privateKeyLifetime time.Duration
|
|
|
|
publicKeyLifetime time.Duration
|
|
|
|
certificateLifetime time.Duration
|
2021-01-04 14:52:13 +01:00
|
|
|
}
|
|
|
|
|
2023-04-25 09:02:29 +02:00
|
|
|
func StartCommands(
|
|
|
|
es *eventstore.Eventstore,
|
2022-02-16 16:49:17 +01:00
|
|
|
defaults sd.SystemDefaults,
|
2022-04-20 16:59:37 +02:00
|
|
|
zitadelRoles []authz.RoleMapping,
|
2022-02-16 16:49:17 +01:00
|
|
|
staticStore static.Storage,
|
2022-04-25 10:01:17 +02:00
|
|
|
webAuthN *webauthn_helper.Config,
|
2022-04-28 10:30:41 +02:00
|
|
|
externalDomain string,
|
2022-04-25 11:16:36 +02:00
|
|
|
externalSecure bool,
|
|
|
|
externalPort uint16,
|
2023-05-05 17:34:53 +02:00
|
|
|
idpConfigEncryption, otpEncryption, smtpEncryption, smsEncryption, userEncryption, domainVerificationEncryption, oidcEncryption, samlEncryption crypto.EncryptionAlgorithm,
|
2022-09-12 17:18:08 +01:00
|
|
|
httpClient *http.Client,
|
2023-05-05 17:34:53 +02:00
|
|
|
permissionCheck domain.PermissionCheck,
|
|
|
|
sessionTokenVerifier func(ctx context.Context, sessionToken string, sessionID string, tokenID string) (err error),
|
2022-02-16 16:49:17 +01:00
|
|
|
) (repo *Commands, err error) {
|
2022-04-28 10:30:41 +02:00
|
|
|
if externalDomain == "" {
|
2022-05-12 09:34:46 +02:00
|
|
|
return nil, errors.ThrowInvalidArgument(nil, "COMMAND-Df21s", "no external domain specified")
|
2022-04-28 10:30:41 +02:00
|
|
|
}
|
2023-05-05 17:34:53 +02:00
|
|
|
idGenerator := id.SonyFlakeGenerator()
|
|
|
|
// reuse the oidcEncryption to be able to handle both tokens in the interceptor later on
|
|
|
|
sessionAlg := oidcEncryption
|
2021-02-24 11:17:39 +01:00
|
|
|
repo = &Commands{
|
2022-03-14 07:55:09 +01:00
|
|
|
eventstore: es,
|
|
|
|
static: staticStore,
|
2023-05-05 17:34:53 +02:00
|
|
|
idGenerator: idGenerator,
|
2022-04-20 16:59:37 +02:00
|
|
|
zitadelRoles: zitadelRoles,
|
2022-04-28 10:30:41 +02:00
|
|
|
externalDomain: externalDomain,
|
2022-04-25 11:16:36 +02:00
|
|
|
externalSecure: externalSecure,
|
|
|
|
externalPort: externalPort,
|
2022-03-14 07:55:09 +01:00
|
|
|
keySize: defaults.KeyConfig.Size,
|
2022-09-12 17:18:08 +01:00
|
|
|
certKeySize: defaults.KeyConfig.CertificateSize,
|
2022-03-14 07:55:09 +01:00
|
|
|
privateKeyLifetime: defaults.KeyConfig.PrivateKeyLifetime,
|
|
|
|
publicKeyLifetime: defaults.KeyConfig.PublicKeyLifetime,
|
2022-09-12 17:18:08 +01:00
|
|
|
certificateLifetime: defaults.KeyConfig.CertificateLifetime,
|
2022-04-20 16:59:37 +02:00
|
|
|
idpConfigEncryption: idpConfigEncryption,
|
|
|
|
smtpEncryption: smtpEncryption,
|
|
|
|
smsEncryption: smsEncryption,
|
|
|
|
userEncryption: userEncryption,
|
2022-03-14 07:55:09 +01:00
|
|
|
domainVerificationAlg: domainVerificationEncryption,
|
|
|
|
keyAlgorithm: oidcEncryption,
|
2022-09-12 17:18:08 +01:00
|
|
|
certificateAlgorithm: samlEncryption,
|
2022-04-25 10:01:17 +02:00
|
|
|
webauthnConfig: webAuthN,
|
2022-09-12 17:18:08 +01:00
|
|
|
httpClient: httpClient,
|
2023-05-05 17:34:53 +02:00
|
|
|
checkPermission: permissionCheck,
|
2023-06-05 18:43:51 +02:00
|
|
|
newEmailCode: newEmailCode,
|
2023-05-05 17:34:53 +02:00
|
|
|
sessionTokenCreator: sessionTokenCreator(idGenerator, sessionAlg),
|
|
|
|
sessionTokenVerifier: sessionTokenVerifier,
|
2021-01-04 14:52:13 +01:00
|
|
|
}
|
2022-04-12 16:20:17 +02:00
|
|
|
|
2022-03-28 10:05:09 +02:00
|
|
|
instance_repo.RegisterEventMappers(repo.eventstore)
|
2021-01-18 11:24:15 +01:00
|
|
|
org.RegisterEventMappers(repo.eventstore)
|
2021-01-15 09:32:59 +01:00
|
|
|
usr_repo.RegisterEventMappers(repo.eventstore)
|
2021-01-22 13:31:52 +01:00
|
|
|
usr_grant_repo.RegisterEventMappers(repo.eventstore)
|
|
|
|
proj_repo.RegisterEventMappers(repo.eventstore)
|
2021-02-12 16:51:12 +01:00
|
|
|
keypair.RegisterEventMappers(repo.eventstore)
|
2021-09-27 13:43:49 +02:00
|
|
|
action.RegisterEventMappers(repo.eventstore)
|
2023-02-15 02:52:11 +01:00
|
|
|
quota.RegisterEventMappers(repo.eventstore)
|
2023-05-05 17:34:53 +02:00
|
|
|
session.RegisterEventMappers(repo.eventstore)
|
2023-05-24 20:29:58 +02:00
|
|
|
idpintent.RegisterEventMappers(repo.eventstore)
|
2021-01-04 14:52:13 +01:00
|
|
|
|
2021-02-24 11:17:39 +01:00
|
|
|
repo.userPasswordAlg = crypto.NewBCrypt(defaults.SecretGenerators.PasswordSaltCost)
|
|
|
|
repo.machineKeySize = int(defaults.SecretGenerators.MachineKeySize)
|
|
|
|
repo.applicationKeySize = int(defaults.SecretGenerators.ApplicationKeySize)
|
2021-01-12 12:59:51 +01:00
|
|
|
|
2021-03-01 08:48:50 +01:00
|
|
|
repo.multifactors = domain.MultifactorConfigs{
|
|
|
|
OTP: domain.OTPConfig{
|
2022-03-14 07:55:09 +01:00
|
|
|
CryptoMFA: otpEncryption,
|
2021-02-24 11:17:39 +01:00
|
|
|
Issuer: defaults.Multifactors.OTP.Issuer,
|
2021-01-15 09:32:59 +01:00
|
|
|
},
|
|
|
|
}
|
2021-01-18 11:24:15 +01:00
|
|
|
|
2021-02-24 11:17:39 +01:00
|
|
|
repo.domainVerificationGenerator = crypto.NewEncryptionGenerator(defaults.DomainVerification.VerificationGenerator, repo.domainVerificationAlg)
|
2022-09-12 17:18:08 +01:00
|
|
|
repo.domainVerificationValidator = api_http.ValidateDomain
|
2021-01-04 14:52:13 +01:00
|
|
|
return repo, nil
|
|
|
|
}
|
|
|
|
|
2023-06-05 23:30:10 +02:00
|
|
|
type AppendReducer interface {
|
2022-01-03 09:19:07 +01:00
|
|
|
AppendEvents(...eventstore.Event)
|
2023-02-15 02:52:11 +01:00
|
|
|
// TODO: Why is it allowed to return an error here?
|
2021-02-18 14:48:27 +01:00
|
|
|
Reduce() error
|
2023-06-05 23:30:10 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func (c *Commands) pushAppendAndReduce(ctx context.Context, object AppendReducer, cmds ...eventstore.Command) error {
|
|
|
|
events, err := c.eventstore.Push(ctx, cmds...)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return AppendAndReduce(object, events...)
|
|
|
|
}
|
|
|
|
|
|
|
|
func AppendAndReduce(object AppendReducer, events ...eventstore.Event) error {
|
2021-02-18 14:48:27 +01:00
|
|
|
object.AppendEvents(events...)
|
|
|
|
return object.Reduce()
|
|
|
|
}
|
2022-10-17 21:19:15 +02:00
|
|
|
|
|
|
|
func queryAndReduce(ctx context.Context, filter preparation.FilterToQueryReducer, wm eventstore.QueryReducer) error {
|
|
|
|
events, err := filter(ctx, wm.Query())
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if len(events) == 0 {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
wm.AppendEvents(events...)
|
|
|
|
return wm.Reduce()
|
|
|
|
}
|
|
|
|
|
|
|
|
type existsWriteModel interface {
|
|
|
|
Exists() bool
|
|
|
|
eventstore.QueryReducer
|
|
|
|
}
|
|
|
|
|
|
|
|
func exists(ctx context.Context, filter preparation.FilterToQueryReducer, wm existsWriteModel) (bool, error) {
|
|
|
|
err := queryAndReduce(ctx, filter, wm)
|
|
|
|
if err != nil {
|
|
|
|
return false, err
|
|
|
|
}
|
|
|
|
return wm.Exists(), nil
|
|
|
|
}
|