generic_oauth.go 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305
  1. package social
  2. import (
  3. "encoding/base64"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "net/http"
  8. "net/mail"
  9. "regexp"
  10. "github.com/grafana/grafana/pkg/models"
  11. "golang.org/x/oauth2"
  12. )
  13. type SocialGenericOAuth struct {
  14. *SocialBase
  15. allowedDomains []string
  16. allowedOrganizations []string
  17. apiUrl string
  18. allowSignup bool
  19. emailAttributeName string
  20. teamIds []int
  21. }
  22. func (s *SocialGenericOAuth) Type() int {
  23. return int(models.GENERIC)
  24. }
  25. func (s *SocialGenericOAuth) IsEmailAllowed(email string) bool {
  26. return isEmailAllowed(email, s.allowedDomains)
  27. }
  28. func (s *SocialGenericOAuth) IsSignupAllowed() bool {
  29. return s.allowSignup
  30. }
  31. func (s *SocialGenericOAuth) IsTeamMember(client *http.Client) bool {
  32. if len(s.teamIds) == 0 {
  33. return true
  34. }
  35. teamMemberships, err := s.FetchTeamMemberships(client)
  36. if err != nil {
  37. return false
  38. }
  39. for _, teamId := range s.teamIds {
  40. for _, membershipId := range teamMemberships {
  41. if teamId == membershipId {
  42. return true
  43. }
  44. }
  45. }
  46. return false
  47. }
  48. func (s *SocialGenericOAuth) IsOrganizationMember(client *http.Client) bool {
  49. if len(s.allowedOrganizations) == 0 {
  50. return true
  51. }
  52. organizations, err := s.FetchOrganizations(client)
  53. if err != nil {
  54. return false
  55. }
  56. for _, allowedOrganization := range s.allowedOrganizations {
  57. for _, organization := range organizations {
  58. if organization == allowedOrganization {
  59. return true
  60. }
  61. }
  62. }
  63. return false
  64. }
  65. func (s *SocialGenericOAuth) FetchPrivateEmail(client *http.Client) (string, error) {
  66. type Record struct {
  67. Email string `json:"email"`
  68. Primary bool `json:"primary"`
  69. IsPrimary bool `json:"is_primary"`
  70. Verified bool `json:"verified"`
  71. IsConfirmed bool `json:"is_confirmed"`
  72. }
  73. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/emails"))
  74. if err != nil {
  75. return "", fmt.Errorf("Error getting email address: %s", err)
  76. }
  77. var records []Record
  78. err = json.Unmarshal(response.Body, &records)
  79. if err != nil {
  80. var data struct {
  81. Values []Record `json:"values"`
  82. }
  83. err = json.Unmarshal(response.Body, &data)
  84. if err != nil {
  85. return "", fmt.Errorf("Error getting email address: %s", err)
  86. }
  87. records = data.Values
  88. }
  89. var email = ""
  90. for _, record := range records {
  91. if record.Primary || record.IsPrimary {
  92. email = record.Email
  93. break
  94. }
  95. }
  96. return email, nil
  97. }
  98. func (s *SocialGenericOAuth) FetchTeamMemberships(client *http.Client) ([]int, error) {
  99. type Record struct {
  100. Id int `json:"id"`
  101. }
  102. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/teams"))
  103. if err != nil {
  104. return nil, fmt.Errorf("Error getting team memberships: %s", err)
  105. }
  106. var records []Record
  107. err = json.Unmarshal(response.Body, &records)
  108. if err != nil {
  109. return nil, fmt.Errorf("Error getting team memberships: %s", err)
  110. }
  111. var ids = make([]int, len(records))
  112. for i, record := range records {
  113. ids[i] = record.Id
  114. }
  115. return ids, nil
  116. }
  117. func (s *SocialGenericOAuth) FetchOrganizations(client *http.Client) ([]string, error) {
  118. type Record struct {
  119. Login string `json:"login"`
  120. }
  121. response, err := HttpGet(client, fmt.Sprintf(s.apiUrl+"/orgs"))
  122. if err != nil {
  123. return nil, fmt.Errorf("Error getting organizations: %s", err)
  124. }
  125. var records []Record
  126. err = json.Unmarshal(response.Body, &records)
  127. if err != nil {
  128. return nil, fmt.Errorf("Error getting organizations: %s", err)
  129. }
  130. var logins = make([]string, len(records))
  131. for i, record := range records {
  132. logins[i] = record.Login
  133. }
  134. return logins, nil
  135. }
  136. type UserInfoJson struct {
  137. Name string `json:"name"`
  138. DisplayName string `json:"display_name"`
  139. Login string `json:"login"`
  140. Username string `json:"username"`
  141. Email string `json:"email"`
  142. Upn string `json:"upn"`
  143. Attributes map[string][]string `json:"attributes"`
  144. }
  145. func (s *SocialGenericOAuth) UserInfo(client *http.Client, token *oauth2.Token) (*BasicUserInfo, error) {
  146. var data UserInfoJson
  147. var err error
  148. if !s.extractToken(&data, token) {
  149. response, err := HttpGet(client, s.apiUrl)
  150. if err != nil {
  151. return nil, fmt.Errorf("Error getting user info: %s", err)
  152. }
  153. err = json.Unmarshal(response.Body, &data)
  154. if err != nil {
  155. return nil, fmt.Errorf("Error decoding user info JSON: %s", err)
  156. }
  157. }
  158. name := s.extractName(&data)
  159. email := s.extractEmail(&data)
  160. if email == "" {
  161. email, err = s.FetchPrivateEmail(client)
  162. if err != nil {
  163. return nil, err
  164. }
  165. }
  166. login := s.extractLogin(&data, email)
  167. userInfo := &BasicUserInfo{
  168. Name: name,
  169. Login: login,
  170. Email: email,
  171. }
  172. if !s.IsTeamMember(client) {
  173. return nil, errors.New("User not a member of one of the required teams")
  174. }
  175. if !s.IsOrganizationMember(client) {
  176. return nil, errors.New("User not a member of one of the required organizations")
  177. }
  178. return userInfo, nil
  179. }
  180. func (s *SocialGenericOAuth) extractToken(data *UserInfoJson, token *oauth2.Token) bool {
  181. idToken := token.Extra("id_token")
  182. if idToken == nil {
  183. s.log.Debug("No id_token found", "token", token)
  184. return false
  185. }
  186. jwtRegexp := regexp.MustCompile("^([-_a-zA-Z0-9]+)[.]([-_a-zA-Z0-9]+)[.]([-_a-zA-Z0-9]+)$")
  187. matched := jwtRegexp.FindStringSubmatch(idToken.(string))
  188. if matched == nil {
  189. s.log.Debug("id_token is not in JWT format", "id_token", idToken.(string))
  190. return false
  191. }
  192. payload, err := base64.RawURLEncoding.DecodeString(matched[2])
  193. if err != nil {
  194. s.log.Error("Error base64 decoding id_token", "raw_payload", matched[2], "err", err)
  195. return false
  196. }
  197. err = json.Unmarshal(payload, data)
  198. if err != nil {
  199. s.log.Error("Error decoding id_token JSON", "payload", string(payload), "err", err)
  200. return false
  201. }
  202. email := s.extractEmail(data)
  203. if email == "" {
  204. s.log.Debug("No email found in id_token", "json", string(payload), "data", data)
  205. return false
  206. }
  207. s.log.Debug("Received id_token", "json", string(payload), "data", data)
  208. return true
  209. }
  210. func (s *SocialGenericOAuth) extractEmail(data *UserInfoJson) string {
  211. if data.Email != "" {
  212. return data.Email
  213. }
  214. emails, ok := data.Attributes[s.emailAttributeName]
  215. if ok && len(emails) != 0 {
  216. return emails[0]
  217. }
  218. if data.Upn != "" {
  219. emailAddr, emailErr := mail.ParseAddress(data.Upn)
  220. if emailErr == nil {
  221. return emailAddr.Address
  222. }
  223. }
  224. return ""
  225. }
  226. func (s *SocialGenericOAuth) extractLogin(data *UserInfoJson, email string) string {
  227. if data.Login != "" {
  228. return data.Login
  229. }
  230. if data.Username != "" {
  231. return data.Username
  232. }
  233. return email
  234. }
  235. func (s *SocialGenericOAuth) extractName(data *UserInfoJson) string {
  236. if data.Name != "" {
  237. return data.Name
  238. }
  239. if data.DisplayName != "" {
  240. return data.DisplayName
  241. }
  242. return ""
  243. }