social.go 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197
  1. package social
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "strconv"
  6. "strings"
  7. "github.com/grafana/grafana/pkg/models"
  8. "github.com/grafana/grafana/pkg/setting"
  9. "golang.org/x/net/context"
  10. "golang.org/x/oauth2"
  11. )
  12. type BasicUserInfo struct {
  13. Identity string
  14. Name string
  15. Email string
  16. Login string
  17. Company string
  18. }
  19. type SocialConnector interface {
  20. Type() int
  21. UserInfo(token *oauth2.Token) (*BasicUserInfo, error)
  22. IsEmailAllowed(email string) bool
  23. IsSignupAllowed() bool
  24. AuthCodeURL(state string, opts ...oauth2.AuthCodeOption) string
  25. Exchange(ctx context.Context, code string) (*oauth2.Token, error)
  26. }
  27. var (
  28. SocialBaseUrl = "/login/"
  29. SocialMap = make(map[string]SocialConnector)
  30. )
  31. func NewOAuthService() {
  32. setting.OAuthService = &setting.OAuther{}
  33. setting.OAuthService.OAuthInfos = make(map[string]*setting.OAuthInfo)
  34. allOauthes := []string{"github", "google"}
  35. for _, name := range allOauthes {
  36. sec := setting.Cfg.Section("auth." + name)
  37. info := &setting.OAuthInfo{
  38. ClientId: sec.Key("client_id").String(),
  39. ClientSecret: sec.Key("client_secret").String(),
  40. Scopes: sec.Key("scopes").Strings(" "),
  41. AuthUrl: sec.Key("auth_url").String(),
  42. TokenUrl: sec.Key("token_url").String(),
  43. ApiUrl: sec.Key("api_url").String(),
  44. Enabled: sec.Key("enabled").MustBool(),
  45. AllowedDomains: sec.Key("allowed_domains").Strings(" "),
  46. AllowSignup: sec.Key("allow_sign_up").MustBool(),
  47. }
  48. if !info.Enabled {
  49. continue
  50. }
  51. setting.OAuthService.OAuthInfos[name] = info
  52. config := oauth2.Config{
  53. ClientID: info.ClientId,
  54. ClientSecret: info.ClientSecret,
  55. Endpoint: oauth2.Endpoint{
  56. AuthURL: info.AuthUrl,
  57. TokenURL: info.TokenUrl,
  58. },
  59. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  60. Scopes: info.Scopes,
  61. }
  62. // GitHub.
  63. if name == "github" {
  64. setting.OAuthService.GitHub = true
  65. SocialMap["github"] = &SocialGithub{Config: &config, allowedDomains: info.AllowedDomains, ApiUrl: info.ApiUrl, allowSignup: info.AllowSignup}
  66. }
  67. // Google.
  68. if name == "google" {
  69. setting.OAuthService.Google = true
  70. SocialMap["google"] = &SocialGoogle{Config: &config, allowedDomains: info.AllowedDomains, ApiUrl: info.ApiUrl, allowSignup: info.AllowSignup}
  71. }
  72. }
  73. }
  74. func isEmailAllowed(email string, allowedDomains []string) bool {
  75. if len(allowedDomains) == 0 {
  76. return true
  77. }
  78. valid := false
  79. for _, domain := range allowedDomains {
  80. emailSuffix := fmt.Sprintf("@%s", domain)
  81. valid = valid || strings.HasSuffix(email, emailSuffix)
  82. }
  83. return valid
  84. }
  85. type SocialGithub struct {
  86. *oauth2.Config
  87. allowedDomains []string
  88. ApiUrl string
  89. allowSignup bool
  90. }
  91. func (s *SocialGithub) Type() int {
  92. return int(models.GITHUB)
  93. }
  94. func (s *SocialGithub) IsEmailAllowed(email string) bool {
  95. return isEmailAllowed(email, s.allowedDomains)
  96. }
  97. func (s *SocialGithub) IsSignupAllowed() bool {
  98. return s.allowSignup
  99. }
  100. func (s *SocialGithub) UserInfo(token *oauth2.Token) (*BasicUserInfo, error) {
  101. var data struct {
  102. Id int `json:"id"`
  103. Name string `json:"login"`
  104. Email string `json:"email"`
  105. }
  106. var err error
  107. client := s.Client(oauth2.NoContext, token)
  108. r, err := client.Get(s.ApiUrl)
  109. if err != nil {
  110. return nil, err
  111. }
  112. defer r.Body.Close()
  113. if err = json.NewDecoder(r.Body).Decode(&data); err != nil {
  114. return nil, err
  115. }
  116. return &BasicUserInfo{
  117. Identity: strconv.Itoa(data.Id),
  118. Name: data.Name,
  119. Email: data.Email,
  120. }, nil
  121. }
  122. // ________ .__
  123. // / _____/ ____ ____ ____ | | ____
  124. // / \ ___ / _ \ / _ \ / ___\| | _/ __ \
  125. // \ \_\ ( <_> | <_> ) /_/ > |_\ ___/
  126. // \______ /\____/ \____/\___ /|____/\___ >
  127. // \/ /_____/ \/
  128. type SocialGoogle struct {
  129. *oauth2.Config
  130. allowedDomains []string
  131. ApiUrl string
  132. allowSignup bool
  133. }
  134. func (s *SocialGoogle) Type() int {
  135. return int(models.GOOGLE)
  136. }
  137. func (s *SocialGoogle) IsEmailAllowed(email string) bool {
  138. return isEmailAllowed(email, s.allowedDomains)
  139. }
  140. func (s *SocialGoogle) IsSignupAllowed() bool {
  141. return s.allowSignup
  142. }
  143. func (s *SocialGoogle) UserInfo(token *oauth2.Token) (*BasicUserInfo, error) {
  144. var data struct {
  145. Id string `json:"id"`
  146. Name string `json:"name"`
  147. Email string `json:"email"`
  148. }
  149. var err error
  150. client := s.Client(oauth2.NoContext, token)
  151. r, err := client.Get(s.ApiUrl)
  152. if err != nil {
  153. return nil, err
  154. }
  155. defer r.Body.Close()
  156. if err = json.NewDecoder(r.Body).Decode(&data); err != nil {
  157. return nil, err
  158. }
  159. return &BasicUserInfo{
  160. Identity: data.Id,
  161. Name: data.Name,
  162. Email: data.Email,
  163. }, nil
  164. }