social.go 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148
  1. package social
  2. import (
  3. "net/http"
  4. "strings"
  5. "golang.org/x/net/context"
  6. "golang.org/x/oauth2"
  7. "github.com/grafana/grafana/pkg/setting"
  8. "github.com/grafana/grafana/pkg/util"
  9. )
  10. type BasicUserInfo struct {
  11. Name string
  12. Email string
  13. Login string
  14. Company string
  15. Role string
  16. }
  17. type SocialConnector interface {
  18. Type() int
  19. UserInfo(client *http.Client) (*BasicUserInfo, error)
  20. IsEmailAllowed(email string) bool
  21. IsSignupAllowed() bool
  22. AuthCodeURL(state string, opts ...oauth2.AuthCodeOption) string
  23. Exchange(ctx context.Context, code string) (*oauth2.Token, error)
  24. Client(ctx context.Context, t *oauth2.Token) *http.Client
  25. }
  26. type Error struct {
  27. s string
  28. }
  29. func (e *Error) Error() string {
  30. return e.s
  31. }
  32. var (
  33. SocialBaseUrl = "/login/"
  34. SocialMap = make(map[string]SocialConnector)
  35. )
  36. func NewOAuthService() {
  37. setting.OAuthService = &setting.OAuther{}
  38. setting.OAuthService.OAuthInfos = make(map[string]*setting.OAuthInfo)
  39. allOauthes := []string{"github", "google", "generic_oauth", "grafananet", "grafana_com"}
  40. for _, name := range allOauthes {
  41. sec := setting.Cfg.Section("auth." + name)
  42. info := &setting.OAuthInfo{
  43. ClientId: sec.Key("client_id").String(),
  44. ClientSecret: sec.Key("client_secret").String(),
  45. Scopes: util.SplitString(sec.Key("scopes").String()),
  46. AuthUrl: sec.Key("auth_url").String(),
  47. TokenUrl: sec.Key("token_url").String(),
  48. ApiUrl: sec.Key("api_url").String(),
  49. Enabled: sec.Key("enabled").MustBool(),
  50. AllowedDomains: util.SplitString(sec.Key("allowed_domains").String()),
  51. HostedDomain: sec.Key("hosted_domain").String(),
  52. AllowSignup: sec.Key("allow_sign_up").MustBool(),
  53. Name: sec.Key("name").MustString(name),
  54. TlsClientCert: sec.Key("tls_client_cert").String(),
  55. TlsClientKey: sec.Key("tls_client_key").String(),
  56. TlsClientCa: sec.Key("tls_client_ca").String(),
  57. TlsSkipVerify: sec.Key("tls_skip_verify_insecure").MustBool(),
  58. }
  59. if !info.Enabled {
  60. continue
  61. }
  62. if name == "grafananet" {
  63. name = "grafana_com"
  64. }
  65. setting.OAuthService.OAuthInfos[name] = info
  66. config := oauth2.Config{
  67. ClientID: info.ClientId,
  68. ClientSecret: info.ClientSecret,
  69. Endpoint: oauth2.Endpoint{
  70. AuthURL: info.AuthUrl,
  71. TokenURL: info.TokenUrl,
  72. },
  73. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  74. Scopes: info.Scopes,
  75. }
  76. // GitHub.
  77. if name == "github" {
  78. SocialMap["github"] = &SocialGithub{
  79. Config: &config,
  80. allowedDomains: info.AllowedDomains,
  81. apiUrl: info.ApiUrl,
  82. allowSignup: info.AllowSignup,
  83. teamIds: sec.Key("team_ids").Ints(","),
  84. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  85. }
  86. }
  87. // Google.
  88. if name == "google" {
  89. SocialMap["google"] = &SocialGoogle{
  90. Config: &config,
  91. allowedDomains: info.AllowedDomains,
  92. hostedDomain: info.HostedDomain,
  93. apiUrl: info.ApiUrl,
  94. allowSignup: info.AllowSignup,
  95. }
  96. }
  97. // Generic - Uses the same scheme as Github.
  98. if name == "generic_oauth" {
  99. SocialMap["generic_oauth"] = &GenericOAuth{
  100. Config: &config,
  101. allowedDomains: info.AllowedDomains,
  102. apiUrl: info.ApiUrl,
  103. allowSignup: info.AllowSignup,
  104. teamIds: sec.Key("team_ids").Ints(","),
  105. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  106. }
  107. }
  108. if name == "grafana_com" {
  109. config = oauth2.Config{
  110. ClientID: info.ClientId,
  111. ClientSecret: info.ClientSecret,
  112. Endpoint: oauth2.Endpoint{
  113. AuthURL: setting.GrafanaComUrl + "/oauth2/authorize",
  114. TokenURL: setting.GrafanaComUrl + "/api/oauth2/token",
  115. },
  116. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  117. Scopes: info.Scopes,
  118. }
  119. SocialMap["grafana_com"] = &SocialGrafanaCom{
  120. Config: &config,
  121. url: setting.GrafanaComUrl,
  122. allowSignup: info.AllowSignup,
  123. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  124. }
  125. }
  126. }
  127. }