social.go 4.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170
  1. package social
  2. import (
  3. "net/http"
  4. "strings"
  5. "context"
  6. "golang.org/x/oauth2"
  7. "github.com/grafana/grafana/pkg/log"
  8. "github.com/grafana/grafana/pkg/setting"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. type BasicUserInfo struct {
  12. Id string
  13. Name string
  14. Email string
  15. Login string
  16. Company string
  17. Role string
  18. }
  19. type SocialConnector interface {
  20. Type() int
  21. UserInfo(client *http.Client, token *oauth2.Token) (*BasicUserInfo, error)
  22. IsEmailAllowed(email string) bool
  23. IsSignupAllowed() bool
  24. AuthCodeURL(state string, opts ...oauth2.AuthCodeOption) string
  25. Exchange(ctx context.Context, code string) (*oauth2.Token, error)
  26. Client(ctx context.Context, t *oauth2.Token) *http.Client
  27. }
  28. type SocialBase struct {
  29. *oauth2.Config
  30. log log.Logger
  31. }
  32. type Error struct {
  33. s string
  34. }
  35. func (e *Error) Error() string {
  36. return e.s
  37. }
  38. var (
  39. SocialBaseUrl = "/login/"
  40. SocialMap = make(map[string]SocialConnector)
  41. )
  42. func NewOAuthService() {
  43. setting.OAuthService = &setting.OAuther{}
  44. setting.OAuthService.OAuthInfos = make(map[string]*setting.OAuthInfo)
  45. allOauthes := []string{"github", "google", "generic_oauth", "grafananet", "grafana_com"}
  46. for _, name := range allOauthes {
  47. sec := setting.Cfg.Section("auth." + name)
  48. info := &setting.OAuthInfo{
  49. ClientId: sec.Key("client_id").String(),
  50. ClientSecret: sec.Key("client_secret").String(),
  51. Scopes: util.SplitString(sec.Key("scopes").String()),
  52. AuthUrl: sec.Key("auth_url").String(),
  53. TokenUrl: sec.Key("token_url").String(),
  54. ApiUrl: sec.Key("api_url").String(),
  55. Enabled: sec.Key("enabled").MustBool(),
  56. AllowedDomains: util.SplitString(sec.Key("allowed_domains").String()),
  57. HostedDomain: sec.Key("hosted_domain").String(),
  58. AllowSignup: sec.Key("allow_sign_up").MustBool(),
  59. Name: sec.Key("name").MustString(name),
  60. TlsClientCert: sec.Key("tls_client_cert").String(),
  61. TlsClientKey: sec.Key("tls_client_key").String(),
  62. TlsClientCa: sec.Key("tls_client_ca").String(),
  63. TlsSkipVerify: sec.Key("tls_skip_verify_insecure").MustBool(),
  64. }
  65. if !info.Enabled {
  66. continue
  67. }
  68. if name == "grafananet" {
  69. name = "grafana_com"
  70. }
  71. setting.OAuthService.OAuthInfos[name] = info
  72. config := oauth2.Config{
  73. ClientID: info.ClientId,
  74. ClientSecret: info.ClientSecret,
  75. Endpoint: oauth2.Endpoint{
  76. AuthURL: info.AuthUrl,
  77. TokenURL: info.TokenUrl,
  78. },
  79. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  80. Scopes: info.Scopes,
  81. }
  82. logger := log.New("oauth." + name)
  83. // GitHub.
  84. if name == "github" {
  85. SocialMap["github"] = &SocialGithub{
  86. SocialBase: &SocialBase{
  87. Config: &config,
  88. log: logger,
  89. },
  90. allowedDomains: info.AllowedDomains,
  91. apiUrl: info.ApiUrl,
  92. allowSignup: info.AllowSignup,
  93. teamIds: sec.Key("team_ids").Ints(","),
  94. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  95. }
  96. }
  97. // Google.
  98. if name == "google" {
  99. SocialMap["google"] = &SocialGoogle{
  100. SocialBase: &SocialBase{
  101. Config: &config,
  102. log: logger,
  103. },
  104. allowedDomains: info.AllowedDomains,
  105. hostedDomain: info.HostedDomain,
  106. apiUrl: info.ApiUrl,
  107. allowSignup: info.AllowSignup,
  108. }
  109. }
  110. // Generic - Uses the same scheme as Github.
  111. if name == "generic_oauth" {
  112. SocialMap["generic_oauth"] = &SocialGenericOAuth{
  113. SocialBase: &SocialBase{
  114. Config: &config,
  115. log: logger,
  116. },
  117. allowedDomains: info.AllowedDomains,
  118. apiUrl: info.ApiUrl,
  119. allowSignup: info.AllowSignup,
  120. teamIds: sec.Key("team_ids").Ints(","),
  121. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  122. }
  123. }
  124. if name == "grafana_com" {
  125. config = oauth2.Config{
  126. ClientID: info.ClientId,
  127. ClientSecret: info.ClientSecret,
  128. Endpoint: oauth2.Endpoint{
  129. AuthURL: setting.GrafanaComUrl + "/oauth2/authorize",
  130. TokenURL: setting.GrafanaComUrl + "/api/oauth2/token",
  131. },
  132. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  133. Scopes: info.Scopes,
  134. }
  135. SocialMap["grafana_com"] = &SocialGrafanaCom{
  136. SocialBase: &SocialBase{
  137. Config: &config,
  138. log: logger,
  139. },
  140. url: setting.GrafanaComUrl,
  141. allowSignup: info.AllowSignup,
  142. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  143. }
  144. }
  145. }
  146. }