| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | // Copyright (c) 2015-2022 MinIO, Inc.
 | 
					
						
							|  |  |  | //
 | 
					
						
							|  |  |  | // This file is part of MinIO Object Storage stack
 | 
					
						
							|  |  |  | //
 | 
					
						
							|  |  |  | // This program is free software: you can redistribute it and/or modify
 | 
					
						
							|  |  |  | // it under the terms of the GNU Affero General Public License as published by
 | 
					
						
							|  |  |  | // the Free Software Foundation, either version 3 of the License, or
 | 
					
						
							|  |  |  | // (at your option) any later version.
 | 
					
						
							|  |  |  | //
 | 
					
						
							|  |  |  | // This program is distributed in the hope that it will be useful
 | 
					
						
							|  |  |  | // but WITHOUT ANY WARRANTY; without even the implied warranty of
 | 
					
						
							|  |  |  | // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | 
					
						
							|  |  |  | // GNU Affero General Public License for more details.
 | 
					
						
							|  |  |  | //
 | 
					
						
							|  |  |  | // You should have received a copy of the GNU Affero General Public License
 | 
					
						
							|  |  |  | // along with this program.  If not, see <http://www.gnu.org/licenses/>.
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | package cmd | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | import ( | 
					
						
							|  |  |  | 	"context" | 
					
						
							|  |  |  | 	"encoding/json" | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	"errors" | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	"fmt" | 
					
						
							|  |  |  | 	"io" | 
					
						
							|  |  |  | 	"net/http" | 
					
						
							|  |  |  | 	"strings" | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-06-20 08:53:08 +08:00
										 |  |  | 	"github.com/minio/madmin-go/v3" | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	"github.com/minio/minio-go/v7/pkg/set" | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	"github.com/minio/minio/internal/config" | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	cfgldap "github.com/minio/minio/internal/config/identity/ldap" | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	"github.com/minio/minio/internal/config/identity/openid" | 
					
						
							|  |  |  | 	"github.com/minio/minio/internal/logger" | 
					
						
							| 
									
										
										
										
											2023-01-23 19:12:47 +08:00
										 |  |  | 	"github.com/minio/mux" | 
					
						
							| 
									
										
										
										
											2023-09-05 03:57:37 +08:00
										 |  |  | 	"github.com/minio/pkg/v2/ldap" | 
					
						
							| 
									
										
										
										
											2023-09-15 05:50:16 +08:00
										 |  |  | 	"github.com/minio/pkg/v2/policy" | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | ) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-07-11 07:59:44 +08:00
										 |  |  | func addOrUpdateIDPHandler(ctx context.Context, w http.ResponseWriter, r *http.Request, isUpdate bool) { | 
					
						
							| 
									
										
										
										
											2023-09-15 05:50:16 +08:00
										 |  |  | 	objectAPI, cred := validateAdminReq(ctx, w, r, policy.ConfigUpdateAdminAction) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	if objectAPI == nil { | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	if r.ContentLength > maxEConfigJSONSize || r.ContentLength == -1 { | 
					
						
							|  |  |  | 		// More than maxConfigSize bytes were available
 | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigTooLarge), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	// Ensure body content type is opaque to ensure that request body has not
 | 
					
						
							|  |  |  | 	// been interpreted as form data.
 | 
					
						
							|  |  |  | 	contentType := r.Header.Get("Content-Type") | 
					
						
							|  |  |  | 	if contentType != "application/octet-stream" { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrBadRequest), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	password := cred.SecretKey | 
					
						
							|  |  |  | 	reqBytes, err := madmin.DecryptData(password, io.LimitReader(r.Body, r.ContentLength)) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							| 
									
										
										
										
											2024-02-02 08:13:57 +08:00
										 |  |  | 		logger.LogIf(ctx, err, logger.ErrorKind) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigBadJSON), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	idpCfgType := mux.Vars(r)["type"] | 
					
						
							|  |  |  | 	if !madmin.ValidIDPConfigTypes.Contains(idpCfgType) { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigInvalidIDPType), r.URL) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	var subSys string | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	switch idpCfgType { | 
					
						
							|  |  |  | 	case madmin.OpenidIDPCfg: | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 		subSys = madmin.IdentityOpenIDSubSys | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	case madmin.LDAPIDPCfg: | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 		subSys = madmin.IdentityLDAPSubSys | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	cfgName := mux.Vars(r)["name"] | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	cfgTarget := madmin.Default | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	if cfgName != "" { | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 		cfgTarget = cfgName | 
					
						
							|  |  |  | 		if idpCfgType == madmin.LDAPIDPCfg && cfgName != madmin.Default { | 
					
						
							|  |  |  | 			// LDAP does not support multiple configurations. So cfgName must be
 | 
					
						
							|  |  |  | 			// empty or `madmin.Default`.
 | 
					
						
							| 
									
										
										
										
											2023-03-17 02:58:59 +08:00
										 |  |  | 			writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigLDAPNonDefaultConfigName), r.URL) | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 			return | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	// Check that this is a valid Create vs Update API call.
 | 
					
						
							|  |  |  | 	s := globalServerConfig.Clone() | 
					
						
							|  |  |  | 	if apiErrCode := handleCreateUpdateValidation(s, subSys, cfgTarget, isUpdate); apiErrCode != ErrNone { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(apiErrCode), r.URL) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	cfgData := "" | 
					
						
							|  |  |  | 	{ | 
					
						
							|  |  |  | 		tgtSuffix := "" | 
					
						
							|  |  |  | 		if cfgTarget != madmin.Default { | 
					
						
							|  |  |  | 			tgtSuffix = config.SubSystemSeparator + cfgTarget | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		cfgData = subSys + tgtSuffix + config.KvSpaceSeparator + string(reqBytes) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-12-20 03:10:14 +08:00
										 |  |  | 	cfg, err := readServerConfig(ctx, objectAPI, nil) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	dynamic, err := cfg.ReadConfig(strings.NewReader(cfgData)) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// IDP config is not dynamic. Sanity check.
 | 
					
						
							|  |  |  | 	if dynamic { | 
					
						
							| 
									
										
										
										
											2023-10-12 00:06:40 +08:00
										 |  |  | 		writeCustomErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrInternalError), "", r.URL) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-05-25 13:57:37 +08:00
										 |  |  | 	if err = validateConfig(ctx, cfg, subSys); err != nil { | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 		var validationErr ldap.Validation | 
					
						
							|  |  |  | 		if errors.As(err, &validationErr) { | 
					
						
							|  |  |  | 			// If we got an LDAP validation error, we need to send appropriate
 | 
					
						
							|  |  |  | 			// error message back to client (likely mc).
 | 
					
						
							|  |  |  | 			writeCustomErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigLDAPValidation), | 
					
						
							|  |  |  | 				validationErr.FormatError(), r.URL) | 
					
						
							|  |  |  | 			return | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		writeCustomErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigBadJSON), err.Error(), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// Update the actual server config on disk.
 | 
					
						
							|  |  |  | 	if err = saveServerConfig(ctx, objectAPI, cfg); err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// Write to the config input KV to history.
 | 
					
						
							|  |  |  | 	if err = saveServerConfigHistory(ctx, objectAPI, []byte(cfgData)); err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	writeSuccessResponseHeadersOnly(w) | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | func handleCreateUpdateValidation(s config.Config, subSys, cfgTarget string, isUpdate bool) APIErrorCode { | 
					
						
							|  |  |  | 	if cfgTarget != madmin.Default { | 
					
						
							|  |  |  | 		// This cannot give an error at this point.
 | 
					
						
							|  |  |  | 		subSysTargets, _ := s.GetAvailableTargets(subSys) | 
					
						
							|  |  |  | 		subSysTargetsSet := set.CreateStringSet(subSysTargets...) | 
					
						
							|  |  |  | 		if isUpdate && !subSysTargetsSet.Contains(cfgTarget) { | 
					
						
							|  |  |  | 			return ErrAdminConfigIDPCfgNameDoesNotExist | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		if !isUpdate && subSysTargetsSet.Contains(cfgTarget) { | 
					
						
							|  |  |  | 			return ErrAdminConfigIDPCfgNameAlreadyExists | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		return ErrNone | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// For the default configuration name, since it will always be an available
 | 
					
						
							|  |  |  | 	// target, we need to check if a configuration value has been set previously
 | 
					
						
							|  |  |  | 	// to figure out if this is a valid create or update API call.
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// This cannot really error (FIXME: improve the type for GetConfigInfo)
 | 
					
						
							|  |  |  | 	var cfgInfos []madmin.IDPCfgInfo | 
					
						
							|  |  |  | 	switch subSys { | 
					
						
							|  |  |  | 	case madmin.IdentityOpenIDSubSys: | 
					
						
							| 
									
										
										
										
											2023-02-26 13:01:37 +08:00
										 |  |  | 		cfgInfos, _ = globalIAMSys.OpenIDConfig.GetConfigInfo(s, cfgTarget) | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	case madmin.IdentityLDAPSubSys: | 
					
						
							| 
									
										
										
										
											2023-02-25 10:37:22 +08:00
										 |  |  | 		cfgInfos, _ = globalIAMSys.LDAPConfig.GetConfigInfo(s, cfgTarget) | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	if len(cfgInfos) > 0 && !isUpdate { | 
					
						
							|  |  |  | 		return ErrAdminConfigIDPCfgNameAlreadyExists | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	if len(cfgInfos) == 0 && isUpdate { | 
					
						
							|  |  |  | 		return ErrAdminConfigIDPCfgNameDoesNotExist | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	return ErrNone | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | // AddIdentityProviderCfg: adds a new IDP config for openid/ldap.
 | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | //
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | // PUT <admin-prefix>/idp-cfg/openid/dex1 -> create named config `dex1`
 | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | //
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | // PUT <admin-prefix>/idp-cfg/openid/_ -> create (default) named config `_`
 | 
					
						
							|  |  |  | func (a adminAPIHandlers) AddIdentityProviderCfg(w http.ResponseWriter, r *http.Request) { | 
					
						
							| 
									
										
										
										
											2023-07-14 05:52:21 +08:00
										 |  |  | 	ctx := r.Context() | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-07-11 07:59:44 +08:00
										 |  |  | 	addOrUpdateIDPHandler(ctx, w, r, false) | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | } | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | // UpdateIdentityProviderCfg: updates an existing IDP config for openid/ldap.
 | 
					
						
							|  |  |  | //
 | 
					
						
							| 
									
										
										
										
											2023-06-30 14:38:26 +08:00
										 |  |  | // POST <admin-prefix>/idp-cfg/openid/dex1 -> update named config `dex1`
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | //
 | 
					
						
							| 
									
										
										
										
											2023-06-30 14:38:26 +08:00
										 |  |  | // POST <admin-prefix>/idp-cfg/openid/_ -> update (default) named config `_`
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | func (a adminAPIHandlers) UpdateIdentityProviderCfg(w http.ResponseWriter, r *http.Request) { | 
					
						
							| 
									
										
										
										
											2023-07-14 05:52:21 +08:00
										 |  |  | 	ctx := r.Context() | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-07-11 07:59:44 +08:00
										 |  |  | 	addOrUpdateIDPHandler(ctx, w, r, true) | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | // ListIdentityProviderCfg:
 | 
					
						
							|  |  |  | //
 | 
					
						
							|  |  |  | // GET <admin-prefix>/idp-cfg/openid -> lists openid provider configs.
 | 
					
						
							|  |  |  | func (a adminAPIHandlers) ListIdentityProviderCfg(w http.ResponseWriter, r *http.Request) { | 
					
						
							| 
									
										
										
										
											2023-07-14 05:52:21 +08:00
										 |  |  | 	ctx := r.Context() | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-09-15 05:50:16 +08:00
										 |  |  | 	objectAPI, cred := validateAdminReq(ctx, w, r, policy.ConfigUpdateAdminAction) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	if objectAPI == nil { | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	password := cred.SecretKey | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	idpCfgType := mux.Vars(r)["type"] | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	if !madmin.ValidIDPConfigTypes.Contains(idpCfgType) { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigInvalidIDPType), r.URL) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	var cfgList []madmin.IDPListItem | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	var err error | 
					
						
							|  |  |  | 	switch idpCfgType { | 
					
						
							|  |  |  | 	case madmin.OpenidIDPCfg: | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 		cfg := globalServerConfig.Clone() | 
					
						
							| 
									
										
										
										
											2023-02-26 13:01:37 +08:00
										 |  |  | 		cfgList, err = globalIAMSys.OpenIDConfig.GetConfigList(cfg) | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	case madmin.LDAPIDPCfg: | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 		cfg := globalServerConfig.Clone() | 
					
						
							| 
									
										
										
										
											2023-02-25 10:37:22 +08:00
										 |  |  | 		cfgList, err = globalIAMSys.LDAPConfig.GetConfigList(cfg) | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	default: | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrNotImplemented), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	if err != nil { | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	data, err := json.Marshal(cfgList) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	econfigData, err := madmin.EncryptData(password, data) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	writeSuccessResponseJSON(w, econfigData) | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | // GetIdentityProviderCfg:
 | 
					
						
							|  |  |  | //
 | 
					
						
							|  |  |  | // GET <admin-prefix>/idp-cfg/openid/dex_test
 | 
					
						
							|  |  |  | func (a adminAPIHandlers) GetIdentityProviderCfg(w http.ResponseWriter, r *http.Request) { | 
					
						
							| 
									
										
										
										
											2023-07-14 05:52:21 +08:00
										 |  |  | 	ctx := r.Context() | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-09-15 05:50:16 +08:00
										 |  |  | 	objectAPI, cred := validateAdminReq(ctx, w, r, policy.ConfigUpdateAdminAction) | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	if objectAPI == nil { | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	idpCfgType := mux.Vars(r)["type"] | 
					
						
							|  |  |  | 	cfgName := mux.Vars(r)["name"] | 
					
						
							|  |  |  | 	password := cred.SecretKey | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	if !madmin.ValidIDPConfigTypes.Contains(idpCfgType) { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigInvalidIDPType), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	cfg := globalServerConfig.Clone() | 
					
						
							|  |  |  | 	var cfgInfos []madmin.IDPCfgInfo | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	var err error | 
					
						
							|  |  |  | 	switch idpCfgType { | 
					
						
							|  |  |  | 	case madmin.OpenidIDPCfg: | 
					
						
							| 
									
										
										
										
											2023-02-26 13:01:37 +08:00
										 |  |  | 		cfgInfos, err = globalIAMSys.OpenIDConfig.GetConfigInfo(cfg, cfgName) | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	case madmin.LDAPIDPCfg: | 
					
						
							| 
									
										
										
										
											2023-02-25 10:37:22 +08:00
										 |  |  | 		cfgInfos, err = globalIAMSys.LDAPConfig.GetConfigInfo(cfg, cfgName) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 		if errors.Is(err, openid.ErrProviderConfigNotFound) || errors.Is(err, cfgldap.ErrProviderConfigNotFound) { | 
					
						
							|  |  |  | 			writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminNoSuchConfigTarget), r.URL) | 
					
						
							|  |  |  | 			return | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | 	res := madmin.IDPConfig{ | 
					
						
							|  |  |  | 		Type: idpCfgType, | 
					
						
							|  |  |  | 		Name: cfgName, | 
					
						
							|  |  |  | 		Info: cfgInfos, | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	data, err := json.Marshal(res) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	econfigData, err := madmin.EncryptData(password, data) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	writeSuccessResponseJSON(w, econfigData) | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | // DeleteIdentityProviderCfg:
 | 
					
						
							|  |  |  | //
 | 
					
						
							| 
									
										
										
										
											2022-11-01 05:52:26 +08:00
										 |  |  | // DELETE <admin-prefix>/idp-cfg/openid/dex_test
 | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | func (a adminAPIHandlers) DeleteIdentityProviderCfg(w http.ResponseWriter, r *http.Request) { | 
					
						
							| 
									
										
										
										
											2023-07-14 05:52:21 +08:00
										 |  |  | 	ctx := r.Context() | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-09-15 05:50:16 +08:00
										 |  |  | 	objectAPI, _ := validateAdminReq(ctx, w, r, policy.ConfigUpdateAdminAction) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	if objectAPI == nil { | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	idpCfgType := mux.Vars(r)["type"] | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	cfgName := mux.Vars(r)["name"] | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	if !madmin.ValidIDPConfigTypes.Contains(idpCfgType) { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigInvalidIDPType), r.URL) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	cfgCopy := globalServerConfig.Clone() | 
					
						
							|  |  |  | 	var subSys string | 
					
						
							|  |  |  | 	switch idpCfgType { | 
					
						
							|  |  |  | 	case madmin.OpenidIDPCfg: | 
					
						
							|  |  |  | 		subSys = config.IdentityOpenIDSubSys | 
					
						
							| 
									
										
										
										
											2023-02-26 13:01:37 +08:00
										 |  |  | 		cfgInfos, err := globalIAMSys.OpenIDConfig.GetConfigInfo(cfgCopy, cfgName) | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 		if err != nil { | 
					
						
							|  |  |  | 			if errors.Is(err, openid.ErrProviderConfigNotFound) { | 
					
						
							|  |  |  | 				writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminNoSuchConfigTarget), r.URL) | 
					
						
							|  |  |  | 				return | 
					
						
							|  |  |  | 			} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 			writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 			return | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 		hasEnv := false | 
					
						
							|  |  |  | 		for _, ci := range cfgInfos { | 
					
						
							|  |  |  | 			if ci.IsCfg && ci.IsEnv { | 
					
						
							|  |  |  | 				hasEnv = true | 
					
						
							|  |  |  | 				break | 
					
						
							|  |  |  | 			} | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 		if hasEnv { | 
					
						
							|  |  |  | 			writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigEnvOverridden), r.URL) | 
					
						
							|  |  |  | 			return | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 	case madmin.LDAPIDPCfg: | 
					
						
							|  |  |  | 		subSys = config.IdentityLDAPSubSys | 
					
						
							| 
									
										
										
										
											2023-02-25 10:37:22 +08:00
										 |  |  | 		cfgInfos, err := globalIAMSys.LDAPConfig.GetConfigInfo(cfgCopy, cfgName) | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 		if err != nil { | 
					
						
							|  |  |  | 			if errors.Is(err, openid.ErrProviderConfigNotFound) { | 
					
						
							|  |  |  | 				writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminNoSuchConfigTarget), r.URL) | 
					
						
							|  |  |  | 				return | 
					
						
							|  |  |  | 			} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 			writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 			return | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 		hasEnv := false | 
					
						
							|  |  |  | 		for _, ci := range cfgInfos { | 
					
						
							|  |  |  | 			if ci.IsCfg && ci.IsEnv { | 
					
						
							|  |  |  | 				hasEnv = true | 
					
						
							|  |  |  | 				break | 
					
						
							|  |  |  | 			} | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 		if hasEnv { | 
					
						
							|  |  |  | 			writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigEnvOverridden), r.URL) | 
					
						
							|  |  |  | 			return | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	default: | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrNotImplemented), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-12-20 03:10:14 +08:00
										 |  |  | 	cfg, err := readServerConfig(ctx, objectAPI, nil) | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-20 02:00:10 +08:00
										 |  |  | 	cfgKey := fmt.Sprintf("%s:%s", subSys, cfgName) | 
					
						
							|  |  |  | 	if cfgName == madmin.Default { | 
					
						
							|  |  |  | 		cfgKey = subSys | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	if err = cfg.DelKVS(cfgKey); err != nil { | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2023-05-25 13:57:37 +08:00
										 |  |  | 	if err = validateConfig(ctx, cfg, subSys); err != nil { | 
					
						
							| 
									
										
										
										
											2023-05-11 00:37:30 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 		var validationErr ldap.Validation | 
					
						
							|  |  |  | 		if errors.As(err, &validationErr) { | 
					
						
							|  |  |  | 			// If we got an LDAP validation error, we need to send appropriate
 | 
					
						
							|  |  |  | 			// error message back to client (likely mc).
 | 
					
						
							|  |  |  | 			writeCustomErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigLDAPValidation), | 
					
						
							|  |  |  | 				validationErr.FormatError(), r.URL) | 
					
						
							|  |  |  | 			return | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-07-06 09:18:04 +08:00
										 |  |  | 		writeCustomErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAdminConfigBadJSON), err.Error(), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	if err = saveServerConfig(ctx, objectAPI, cfg); err != nil { | 
					
						
							|  |  |  | 		writeErrorResponseJSON(ctx, w, toAdminAPIErr(ctx, err), r.URL) | 
					
						
							|  |  |  | 		return | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	dynamic := config.SubSystemsDynamic.Contains(subSys) | 
					
						
							|  |  |  | 	if dynamic { | 
					
						
							|  |  |  | 		applyDynamic(ctx, objectAPI, cfg, subSys, r, w) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | } |