social.go 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212
  1. package social
  2. import (
  3. "net/http"
  4. "strings"
  5. "context"
  6. "golang.org/x/oauth2"
  7. "github.com/grafana/grafana/pkg/log"
  8. "github.com/grafana/grafana/pkg/setting"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. type BasicUserInfo struct {
  12. Id string
  13. Name string
  14. Email string
  15. Login string
  16. Company string
  17. Role string
  18. }
  19. type SocialConnector interface {
  20. Type() int
  21. UserInfo(client *http.Client, token *oauth2.Token) (*BasicUserInfo, error)
  22. IsEmailAllowed(email string) bool
  23. IsSignupAllowed() bool
  24. AuthCodeURL(state string, opts ...oauth2.AuthCodeOption) string
  25. Exchange(ctx context.Context, code string) (*oauth2.Token, error)
  26. Client(ctx context.Context, t *oauth2.Token) *http.Client
  27. }
  28. type SocialBase struct {
  29. *oauth2.Config
  30. log log.Logger
  31. }
  32. type Error struct {
  33. s string
  34. }
  35. func (e *Error) Error() string {
  36. return e.s
  37. }
  38. const (
  39. grafanaCom = "grafana_com"
  40. )
  41. var (
  42. SocialBaseUrl = "/login/"
  43. SocialMap = make(map[string]SocialConnector)
  44. allOauthes = []string{"github", "gitlab", "google", "generic_oauth", "grafananet", grafanaCom}
  45. )
  46. func NewOAuthService() {
  47. setting.OAuthService = &setting.OAuther{}
  48. setting.OAuthService.OAuthInfos = make(map[string]*setting.OAuthInfo)
  49. for _, name := range allOauthes {
  50. sec := setting.Raw.Section("auth." + name)
  51. info := &setting.OAuthInfo{
  52. ClientId: sec.Key("client_id").String(),
  53. ClientSecret: sec.Key("client_secret").String(),
  54. Scopes: util.SplitString(sec.Key("scopes").String()),
  55. AuthUrl: sec.Key("auth_url").String(),
  56. TokenUrl: sec.Key("token_url").String(),
  57. ApiUrl: sec.Key("api_url").String(),
  58. Enabled: sec.Key("enabled").MustBool(),
  59. EmailAttributeName: sec.Key("email_attribute_name").String(),
  60. AllowedDomains: util.SplitString(sec.Key("allowed_domains").String()),
  61. HostedDomain: sec.Key("hosted_domain").String(),
  62. AllowSignup: sec.Key("allow_sign_up").MustBool(),
  63. Name: sec.Key("name").MustString(name),
  64. TlsClientCert: sec.Key("tls_client_cert").String(),
  65. TlsClientKey: sec.Key("tls_client_key").String(),
  66. TlsClientCa: sec.Key("tls_client_ca").String(),
  67. TlsSkipVerify: sec.Key("tls_skip_verify_insecure").MustBool(),
  68. }
  69. if !info.Enabled {
  70. continue
  71. }
  72. if name == "grafananet" {
  73. name = grafanaCom
  74. }
  75. setting.OAuthService.OAuthInfos[name] = info
  76. config := oauth2.Config{
  77. ClientID: info.ClientId,
  78. ClientSecret: info.ClientSecret,
  79. Endpoint: oauth2.Endpoint{
  80. AuthURL: info.AuthUrl,
  81. TokenURL: info.TokenUrl,
  82. },
  83. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  84. Scopes: info.Scopes,
  85. }
  86. logger := log.New("oauth." + name)
  87. // GitHub.
  88. if name == "github" {
  89. SocialMap["github"] = &SocialGithub{
  90. SocialBase: &SocialBase{
  91. Config: &config,
  92. log: logger,
  93. },
  94. allowedDomains: info.AllowedDomains,
  95. apiUrl: info.ApiUrl,
  96. allowSignup: info.AllowSignup,
  97. teamIds: sec.Key("team_ids").Ints(","),
  98. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  99. }
  100. }
  101. // GitLab.
  102. if name == "gitlab" {
  103. SocialMap["gitlab"] = &SocialGitlab{
  104. SocialBase: &SocialBase{
  105. Config: &config,
  106. log: logger,
  107. },
  108. allowedDomains: info.AllowedDomains,
  109. apiUrl: info.ApiUrl,
  110. allowSignup: info.AllowSignup,
  111. allowedGroups: util.SplitString(sec.Key("allowed_groups").String()),
  112. }
  113. }
  114. // Google.
  115. if name == "google" {
  116. SocialMap["google"] = &SocialGoogle{
  117. SocialBase: &SocialBase{
  118. Config: &config,
  119. log: logger,
  120. },
  121. allowedDomains: info.AllowedDomains,
  122. hostedDomain: info.HostedDomain,
  123. apiUrl: info.ApiUrl,
  124. allowSignup: info.AllowSignup,
  125. }
  126. }
  127. // Generic - Uses the same scheme as Github.
  128. if name == "generic_oauth" {
  129. SocialMap["generic_oauth"] = &SocialGenericOAuth{
  130. SocialBase: &SocialBase{
  131. Config: &config,
  132. log: logger,
  133. },
  134. allowedDomains: info.AllowedDomains,
  135. apiUrl: info.ApiUrl,
  136. allowSignup: info.AllowSignup,
  137. emailAttributeName: info.EmailAttributeName,
  138. teamIds: sec.Key("team_ids").Ints(","),
  139. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  140. }
  141. }
  142. if name == grafanaCom {
  143. config = oauth2.Config{
  144. ClientID: info.ClientId,
  145. ClientSecret: info.ClientSecret,
  146. Endpoint: oauth2.Endpoint{
  147. AuthURL: setting.GrafanaComUrl + "/oauth2/authorize",
  148. TokenURL: setting.GrafanaComUrl + "/api/oauth2/token",
  149. },
  150. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  151. Scopes: info.Scopes,
  152. }
  153. SocialMap[grafanaCom] = &SocialGrafanaCom{
  154. SocialBase: &SocialBase{
  155. Config: &config,
  156. log: logger,
  157. },
  158. url: setting.GrafanaComUrl,
  159. allowSignup: info.AllowSignup,
  160. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  161. }
  162. }
  163. }
  164. }
  165. // GetOAuthProviders returns available oauth providers and if they're enabled or not
  166. var GetOAuthProviders = func(cfg *setting.Cfg) map[string]bool {
  167. result := map[string]bool{}
  168. if cfg == nil || cfg.Raw == nil {
  169. return result
  170. }
  171. for _, name := range allOauthes {
  172. if name == "grafananet" {
  173. name = grafanaCom
  174. }
  175. sec := cfg.Raw.Section("auth." + name)
  176. if sec == nil {
  177. continue
  178. }
  179. result[name] = sec.Key("enabled").MustBool()
  180. }
  181. return result
  182. }