2023-01-04 23:10:43 +08:00
|
|
|
package clients
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
2024-04-11 16:25:29 +08:00
|
|
|
"errors"
|
2023-01-04 23:10:43 +08:00
|
|
|
"net/url"
|
2024-08-13 16:18:28 +08:00
|
|
|
"strconv"
|
2023-03-23 21:39:04 +08:00
|
|
|
"time"
|
2023-01-04 23:10:43 +08:00
|
|
|
|
2025-07-10 21:41:00 +08:00
|
|
|
"go.opentelemetry.io/otel/trace"
|
|
|
|
|
2025-01-21 17:06:55 +08:00
|
|
|
claims "github.com/grafana/authlib/types"
|
2023-01-04 23:10:43 +08:00
|
|
|
"github.com/grafana/grafana/pkg/infra/log"
|
|
|
|
"github.com/grafana/grafana/pkg/services/auth"
|
|
|
|
"github.com/grafana/grafana/pkg/services/authn"
|
2024-04-11 16:25:29 +08:00
|
|
|
"github.com/grafana/grafana/pkg/services/login"
|
|
|
|
"github.com/grafana/grafana/pkg/services/user"
|
2023-03-03 21:17:09 +08:00
|
|
|
"github.com/grafana/grafana/pkg/setting"
|
2023-01-04 23:10:43 +08:00
|
|
|
)
|
|
|
|
|
2023-01-26 17:50:44 +08:00
|
|
|
var _ authn.ContextAwareClient = new(Session)
|
2023-01-04 23:10:43 +08:00
|
|
|
|
2025-07-10 21:41:00 +08:00
|
|
|
func ProvideSession(cfg *setting.Cfg, sessionService auth.UserTokenService,
|
|
|
|
authInfoService login.AuthInfoService, tracer trace.Tracer) *Session {
|
2023-01-04 23:10:43 +08:00
|
|
|
return &Session{
|
2024-04-11 16:25:29 +08:00
|
|
|
cfg: cfg,
|
|
|
|
log: log.New(authn.ClientSession),
|
|
|
|
sessionService: sessionService,
|
|
|
|
authInfoService: authInfoService,
|
2025-07-10 21:41:00 +08:00
|
|
|
tracer: tracer,
|
2023-01-04 23:10:43 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
type Session struct {
|
2024-04-11 16:25:29 +08:00
|
|
|
cfg *setting.Cfg
|
|
|
|
log log.Logger
|
|
|
|
sessionService auth.UserTokenService
|
|
|
|
authInfoService login.AuthInfoService
|
2025-07-10 21:41:00 +08:00
|
|
|
tracer trace.Tracer
|
2023-01-04 23:10:43 +08:00
|
|
|
}
|
|
|
|
|
2023-01-26 17:50:44 +08:00
|
|
|
func (s *Session) Name() string {
|
|
|
|
return authn.ClientSession
|
2023-01-04 23:10:43 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
func (s *Session) Authenticate(ctx context.Context, r *authn.Request) (*authn.Identity, error) {
|
2023-03-03 21:17:09 +08:00
|
|
|
unescapedCookie, err := r.HTTPRequest.Cookie(s.cfg.LoginCookieName)
|
2023-01-04 23:10:43 +08:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
rawSessionToken, err := url.QueryUnescape(unescapedCookie.Value)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
token, err := s.sessionService.LookupToken(ctx, rawSessionToken)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2024-02-16 22:03:37 +08:00
|
|
|
if token.NeedsRotation(time.Duration(s.cfg.TokenRotationIntervalMinutes) * time.Minute) {
|
|
|
|
return nil, authn.ErrTokenNeedsRotation.Errorf("token needs to be rotated")
|
2023-01-04 23:10:43 +08:00
|
|
|
}
|
|
|
|
|
2024-04-11 16:25:29 +08:00
|
|
|
ident := &authn.Identity{
|
2024-08-13 16:18:28 +08:00
|
|
|
ID: strconv.FormatInt(token.UserId, 10),
|
|
|
|
Type: claims.TypeUser,
|
2023-03-23 21:39:04 +08:00
|
|
|
SessionToken: token,
|
|
|
|
ClientParams: authn.ClientParams{
|
|
|
|
FetchSyncedUser: true,
|
|
|
|
SyncPermissions: true,
|
|
|
|
},
|
2024-04-11 16:25:29 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
info, err := s.authInfoService.GetAuthInfo(ctx, &login.GetAuthInfoQuery{UserId: token.UserId})
|
|
|
|
if err != nil {
|
|
|
|
if !errors.Is(err, user.ErrUserNotFound) {
|
|
|
|
s.log.FromContext(ctx).Error("Failed to fetch auth info", "err", err)
|
|
|
|
}
|
|
|
|
return ident, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
ident.AuthID = info.AuthId
|
|
|
|
ident.AuthenticatedBy = info.AuthModule
|
|
|
|
return ident, nil
|
2023-01-04 23:10:43 +08:00
|
|
|
}
|
|
|
|
|
2024-04-15 16:54:50 +08:00
|
|
|
func (s *Session) IsEnabled() bool {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
2023-01-26 17:50:44 +08:00
|
|
|
func (s *Session) Test(ctx context.Context, r *authn.Request) bool {
|
2023-03-03 21:17:09 +08:00
|
|
|
if s.cfg.LoginCookieName == "" {
|
2023-01-26 17:50:44 +08:00
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2023-03-03 21:17:09 +08:00
|
|
|
if _, err := r.HTTPRequest.Cookie(s.cfg.LoginCookieName); err != nil {
|
2023-01-26 17:50:44 +08:00
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *Session) Priority() uint {
|
|
|
|
return 60
|
|
|
|
}
|