generic_oauth.go 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303
  1. package social
  2. import (
  3. "encoding/base64"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "net/http"
  8. "net/mail"
  9. "regexp"
  10. "github.com/grafana/grafana/pkg/models"
  11. "golang.org/x/oauth2"
  12. )
  13. type SocialGenericOAuth struct {
  14. *SocialBase
  15. allowedDomains []string
  16. allowedOrganizations []string
  17. apiUrl string
  18. allowSignup bool
  19. teamIds []int
  20. }
  21. func (s *SocialGenericOAuth) Type() int {
  22. return int(models.GENERIC)
  23. }
  24. func (s *SocialGenericOAuth) IsEmailAllowed(email string) bool {
  25. return isEmailAllowed(email, s.allowedDomains)
  26. }
  27. func (s *SocialGenericOAuth) IsSignupAllowed() bool {
  28. return s.allowSignup
  29. }
  30. func (s *SocialGenericOAuth) IsTeamMember(client *http.Client) bool {
  31. if len(s.teamIds) == 0 {
  32. return true
  33. }
  34. teamMemberships, err := s.FetchTeamMemberships(client)
  35. if err != nil {
  36. return false
  37. }
  38. for _, teamId := range s.teamIds {
  39. for _, membershipId := range teamMemberships {
  40. if teamId == membershipId {
  41. return true
  42. }
  43. }
  44. }
  45. return false
  46. }
  47. func (s *SocialGenericOAuth) IsOrganizationMember(client *http.Client) bool {
  48. if len(s.allowedOrganizations) == 0 {
  49. return true
  50. }
  51. organizations, err := s.FetchOrganizations(client)
  52. if err != nil {
  53. return false
  54. }
  55. for _, allowedOrganization := range s.allowedOrganizations {
  56. for _, organization := range organizations {
  57. if organization == allowedOrganization {
  58. return true
  59. }
  60. }
  61. }
  62. return false
  63. }
  64. func (s *SocialGenericOAuth) FetchPrivateEmail(client *http.Client) (string, error) {
  65. type Record struct {
  66. Email string `json:"email"`
  67. Primary bool `json:"primary"`
  68. IsPrimary bool `json:"is_primary"`
  69. Verified bool `json:"verified"`
  70. IsConfirmed bool `json:"is_confirmed"`
  71. }
  72. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/emails"))
  73. if err != nil {
  74. return "", fmt.Errorf("Error getting email address: %s", err)
  75. }
  76. var records []Record
  77. err = json.Unmarshal(response.Body, &records)
  78. if err != nil {
  79. var data struct {
  80. Values []Record `json:"values"`
  81. }
  82. err = json.Unmarshal(response.Body, &data)
  83. if err != nil {
  84. return "", fmt.Errorf("Error getting email address: %s", err)
  85. }
  86. records = data.Values
  87. }
  88. var email = ""
  89. for _, record := range records {
  90. if record.Primary || record.IsPrimary {
  91. email = record.Email
  92. break
  93. }
  94. }
  95. return email, nil
  96. }
  97. func (s *SocialGenericOAuth) FetchTeamMemberships(client *http.Client) ([]int, error) {
  98. type Record struct {
  99. Id int `json:"id"`
  100. }
  101. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/teams"))
  102. if err != nil {
  103. return nil, fmt.Errorf("Error getting team memberships: %s", err)
  104. }
  105. var records []Record
  106. err = json.Unmarshal(response.Body, &records)
  107. if err != nil {
  108. return nil, fmt.Errorf("Error getting team memberships: %s", err)
  109. }
  110. var ids = make([]int, len(records))
  111. for i, record := range records {
  112. ids[i] = record.Id
  113. }
  114. return ids, nil
  115. }
  116. func (s *SocialGenericOAuth) FetchOrganizations(client *http.Client) ([]string, error) {
  117. type Record struct {
  118. Login string `json:"login"`
  119. }
  120. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/orgs"))
  121. if err != nil {
  122. return nil, fmt.Errorf("Error getting organizations: %s", err)
  123. }
  124. var records []Record
  125. err = json.Unmarshal(response.Body, &records)
  126. if err != nil {
  127. return nil, fmt.Errorf("Error getting organizations: %s", err)
  128. }
  129. var logins = make([]string, len(records))
  130. for i, record := range records {
  131. logins[i] = record.Login
  132. }
  133. return logins, nil
  134. }
  135. type UserInfoJson struct {
  136. Name string `json:"name"`
  137. DisplayName string `json:"display_name"`
  138. Login string `json:"login"`
  139. Username string `json:"username"`
  140. Email string `json:"email"`
  141. Upn string `json:"upn"`
  142. Attributes map[string][]string `json:"attributes"`
  143. }
  144. func (s *SocialGenericOAuth) UserInfo(client *http.Client, token *oauth2.Token) (*BasicUserInfo, error) {
  145. var data UserInfoJson
  146. var err error
  147. if !s.extractToken(&data, token) {
  148. response, err := HttpGet(client, s.apiUrl)
  149. if err != nil {
  150. return nil, fmt.Errorf("Error getting user info: %s", err)
  151. }
  152. err = json.Unmarshal(response.Body, &data)
  153. if err != nil {
  154. return nil, fmt.Errorf("Error decoding user info JSON: %s", err)
  155. }
  156. }
  157. name := s.extractName(&data)
  158. email := s.extractEmail(&data)
  159. if email == "" {
  160. email, err = s.FetchPrivateEmail(client)
  161. if err != nil {
  162. return nil, err
  163. }
  164. }
  165. login := s.extractLogin(&data, email)
  166. userInfo := &BasicUserInfo{
  167. Name: name,
  168. Login: login,
  169. Email: email,
  170. }
  171. if !s.IsTeamMember(client) {
  172. return nil, errors.New("User not a member of one of the required teams")
  173. }
  174. if !s.IsOrganizationMember(client) {
  175. return nil, errors.New("User not a member of one of the required organizations")
  176. }
  177. return userInfo, nil
  178. }
  179. func (s *SocialGenericOAuth) extractToken(data *UserInfoJson, token *oauth2.Token) bool {
  180. idToken := token.Extra("id_token")
  181. if idToken == nil {
  182. s.log.Debug("No id_token found", "token", token)
  183. return false
  184. }
  185. jwtRegexp := regexp.MustCompile("^([-_a-zA-Z0-9]+)[.]([-_a-zA-Z0-9]+)[.]([-_a-zA-Z0-9]+)$")
  186. matched := jwtRegexp.FindStringSubmatch(idToken.(string))
  187. if matched == nil {
  188. s.log.Debug("id_token is not in JWT format", "id_token", idToken.(string))
  189. return false
  190. }
  191. payload, err := base64.RawURLEncoding.DecodeString(matched[2])
  192. if err != nil {
  193. s.log.Error("Error base64 decoding id_token", "raw_payload", matched[2], "err", err)
  194. return false
  195. }
  196. err = json.Unmarshal(payload, data)
  197. if err != nil {
  198. s.log.Error("Error decoding id_token JSON", "payload", string(payload), "err", err)
  199. return false
  200. }
  201. email := s.extractEmail(data)
  202. if email == "" {
  203. s.log.Debug("No email found in id_token", "json", string(payload), "data", data)
  204. return false
  205. }
  206. s.log.Debug("Received id_token", "json", string(payload), "data", data)
  207. return true
  208. }
  209. func (s *SocialGenericOAuth) extractEmail(data *UserInfoJson) string {
  210. if data.Email != "" {
  211. return data.Email
  212. }
  213. if data.Attributes["email:primary"] != nil {
  214. return data.Attributes["email:primary"][0]
  215. }
  216. if data.Upn != "" {
  217. emailAddr, emailErr := mail.ParseAddress(data.Upn)
  218. if emailErr == nil {
  219. return emailAddr.Address
  220. }
  221. }
  222. return ""
  223. }
  224. func (s *SocialGenericOAuth) extractLogin(data *UserInfoJson, email string) string {
  225. if data.Login != "" {
  226. return data.Login
  227. }
  228. if data.Username != "" {
  229. return data.Username
  230. }
  231. return email
  232. }
  233. func (s *SocialGenericOAuth) extractName(data *UserInfoJson) string {
  234. if data.Name != "" {
  235. return data.Name
  236. }
  237. if data.DisplayName != "" {
  238. return data.DisplayName
  239. }
  240. return ""
  241. }