generic_oauth.go 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265
  1. package social
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "fmt"
  6. "net/http"
  7. "net/mail"
  8. "github.com/grafana/grafana/pkg/models"
  9. "golang.org/x/oauth2"
  10. )
  11. type GenericOAuth struct {
  12. *oauth2.Config
  13. allowedDomains []string
  14. allowedOrganizations []string
  15. apiUrl string
  16. allowSignup bool
  17. teamIds []int
  18. }
  19. func (s *GenericOAuth) Type() int {
  20. return int(models.GENERIC)
  21. }
  22. func (s *GenericOAuth) IsEmailAllowed(email string) bool {
  23. return isEmailAllowed(email, s.allowedDomains)
  24. }
  25. func (s *GenericOAuth) IsSignupAllowed() bool {
  26. return s.allowSignup
  27. }
  28. func (s *GenericOAuth) IsTeamMember(client *http.Client) bool {
  29. if len(s.teamIds) == 0 {
  30. return true
  31. }
  32. teamMemberships, err := s.FetchTeamMemberships(client)
  33. if err != nil {
  34. return false
  35. }
  36. for _, teamId := range s.teamIds {
  37. for _, membershipId := range teamMemberships {
  38. if teamId == membershipId {
  39. return true
  40. }
  41. }
  42. }
  43. return false
  44. }
  45. func (s *GenericOAuth) IsOrganizationMember(client *http.Client) bool {
  46. if len(s.allowedOrganizations) == 0 {
  47. return true
  48. }
  49. organizations, err := s.FetchOrganizations(client)
  50. if err != nil {
  51. return false
  52. }
  53. for _, allowedOrganization := range s.allowedOrganizations {
  54. for _, organization := range organizations {
  55. if organization == allowedOrganization {
  56. return true
  57. }
  58. }
  59. }
  60. return false
  61. }
  62. func (s *GenericOAuth) FetchPrivateEmail(client *http.Client) (string, error) {
  63. type Record struct {
  64. Email string `json:"email"`
  65. Primary bool `json:"primary"`
  66. IsPrimary bool `json:"is_primary"`
  67. Verified bool `json:"verified"`
  68. IsConfirmed bool `json:"is_confirmed"`
  69. }
  70. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/emails"))
  71. if err != nil {
  72. return "", fmt.Errorf("Error getting email address: %s", err)
  73. }
  74. var records []Record
  75. err = json.Unmarshal(response.Body, &records)
  76. if err != nil {
  77. var data struct {
  78. Values []Record `json:"values"`
  79. }
  80. err = json.Unmarshal(response.Body, &data)
  81. if err != nil {
  82. return "", fmt.Errorf("Error getting email address: %s", err)
  83. }
  84. records = data.Values
  85. }
  86. var email = ""
  87. for _, record := range records {
  88. if record.Primary || record.IsPrimary {
  89. email = record.Email
  90. break
  91. }
  92. }
  93. return email, nil
  94. }
  95. func (s *GenericOAuth) FetchTeamMemberships(client *http.Client) ([]int, error) {
  96. type Record struct {
  97. Id int `json:"id"`
  98. }
  99. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/teams"))
  100. if err != nil {
  101. return nil, fmt.Errorf("Error getting team memberships: %s", err)
  102. }
  103. var records []Record
  104. err = json.Unmarshal(response.Body, &records)
  105. if err != nil {
  106. return nil, fmt.Errorf("Error getting team memberships: %s", err)
  107. }
  108. var ids = make([]int, len(records))
  109. for i, record := range records {
  110. ids[i] = record.Id
  111. }
  112. return ids, nil
  113. }
  114. func (s *GenericOAuth) FetchOrganizations(client *http.Client) ([]string, error) {
  115. type Record struct {
  116. Login string `json:"login"`
  117. }
  118. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/orgs"))
  119. if err != nil {
  120. return nil, fmt.Errorf("Error getting organizations: %s", err)
  121. }
  122. var records []Record
  123. err = json.Unmarshal(response.Body, &records)
  124. if err != nil {
  125. return nil, fmt.Errorf("Error getting organizations: %s", err)
  126. }
  127. var logins = make([]string, len(records))
  128. for i, record := range records {
  129. logins[i] = record.Login
  130. }
  131. return logins, nil
  132. }
  133. type UserInfoJson struct {
  134. Name string `json:"name"`
  135. DisplayName string `json:"display_name"`
  136. Login string `json:"login"`
  137. Username string `json:"username"`
  138. Email string `json:"email"`
  139. Upn string `json:"upn"`
  140. Attributes map[string][]string `json:"attributes"`
  141. }
  142. func (s *GenericOAuth) UserInfo(client *http.Client) (*BasicUserInfo, error) {
  143. var data UserInfoJson
  144. response, err := HttpGet(client, s.apiUrl)
  145. if err != nil {
  146. return nil, fmt.Errorf("Error getting user info: %s", err)
  147. }
  148. err = json.Unmarshal(response.Body, &data)
  149. if err != nil {
  150. return nil, fmt.Errorf("Error getting user info: %s", err)
  151. }
  152. name, err := s.extractName(data)
  153. if err != nil {
  154. return nil, err
  155. }
  156. email, err := s.extractEmail(data, client)
  157. if err != nil {
  158. return nil, err
  159. }
  160. login, err := s.extractLogin(data, email)
  161. if err != nil {
  162. return nil, err
  163. }
  164. userInfo := &BasicUserInfo{
  165. Name: name,
  166. Login: login,
  167. Email: email,
  168. }
  169. if !s.IsTeamMember(client) {
  170. return nil, errors.New("User not a member of one of the required teams")
  171. }
  172. if !s.IsOrganizationMember(client) {
  173. return nil, errors.New("User not a member of one of the required organizations")
  174. }
  175. return userInfo, nil
  176. }
  177. func (s *GenericOAuth) extractEmail(data UserInfoJson, client *http.Client) (string, error) {
  178. if data.Email != "" {
  179. return data.Email, nil
  180. }
  181. if data.Attributes["email:primary"] != nil {
  182. return data.Attributes["email:primary"][0], nil
  183. }
  184. if data.Upn != "" {
  185. emailAddr, emailErr := mail.ParseAddress(data.Upn)
  186. if emailErr == nil {
  187. return emailAddr.Address, nil
  188. }
  189. }
  190. return s.FetchPrivateEmail(client)
  191. }
  192. func (s *GenericOAuth) extractLogin(data UserInfoJson, email string) (string, error) {
  193. if data.Login != "" {
  194. return data.Login, nil
  195. }
  196. if data.Username != "" {
  197. return data.Username, nil
  198. }
  199. return email, nil
  200. }
  201. func (s *GenericOAuth) extractName(data UserInfoJson) (string, error) {
  202. if data.Name != "" {
  203. return data.Name, nil
  204. }
  205. if data.DisplayName != "" {
  206. return data.DisplayName, nil
  207. }
  208. return "", nil
  209. }