social.go 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219
  1. package social
  2. import (
  3. "net/http"
  4. "strings"
  5. "context"
  6. "golang.org/x/oauth2"
  7. "github.com/grafana/grafana/pkg/log"
  8. "github.com/grafana/grafana/pkg/setting"
  9. "github.com/grafana/grafana/pkg/util"
  10. )
  11. type BasicUserInfo struct {
  12. Id string
  13. Name string
  14. Email string
  15. Login string
  16. Company string
  17. Role string
  18. }
  19. type SocialConnector interface {
  20. Type() int
  21. UserInfo(client *http.Client, token *oauth2.Token) (*BasicUserInfo, error)
  22. IsEmailAllowed(email string) bool
  23. IsSignupAllowed() bool
  24. AuthCodeURL(state string, opts ...oauth2.AuthCodeOption) string
  25. Exchange(ctx context.Context, code string) (*oauth2.Token, error)
  26. Client(ctx context.Context, t *oauth2.Token) *http.Client
  27. TokenSource(ctx context.Context, t *oauth2.Token) oauth2.TokenSource
  28. }
  29. type SocialBase struct {
  30. *oauth2.Config
  31. log log.Logger
  32. }
  33. type Error struct {
  34. s string
  35. }
  36. func (e *Error) Error() string {
  37. return e.s
  38. }
  39. const (
  40. grafanaCom = "grafana_com"
  41. )
  42. var (
  43. SocialBaseUrl = "/login/"
  44. SocialMap = make(map[string]SocialConnector)
  45. allOauthes = []string{"github", "gitlab", "google", "generic_oauth", "grafananet", grafanaCom}
  46. )
  47. func NewOAuthService() {
  48. setting.OAuthService = &setting.OAuther{}
  49. setting.OAuthService.OAuthInfos = make(map[string]*setting.OAuthInfo)
  50. for _, name := range allOauthes {
  51. sec := setting.Raw.Section("auth." + name)
  52. info := &setting.OAuthInfo{
  53. ClientId: sec.Key("client_id").String(),
  54. ClientSecret: sec.Key("client_secret").String(),
  55. Scopes: util.SplitString(sec.Key("scopes").String()),
  56. AuthUrl: sec.Key("auth_url").String(),
  57. TokenUrl: sec.Key("token_url").String(),
  58. ApiUrl: sec.Key("api_url").String(),
  59. Enabled: sec.Key("enabled").MustBool(),
  60. EmailAttributeName: sec.Key("email_attribute_name").String(),
  61. AllowedDomains: util.SplitString(sec.Key("allowed_domains").String()),
  62. HostedDomain: sec.Key("hosted_domain").String(),
  63. AllowSignup: sec.Key("allow_sign_up").MustBool(),
  64. Name: sec.Key("name").MustString(name),
  65. TlsClientCert: sec.Key("tls_client_cert").String(),
  66. TlsClientKey: sec.Key("tls_client_key").String(),
  67. TlsClientCa: sec.Key("tls_client_ca").String(),
  68. TlsSkipVerify: sec.Key("tls_skip_verify_insecure").MustBool(),
  69. SendClientCredentialsViaPost: sec.Key("send_client_credentials_via_post").MustBool(),
  70. }
  71. if !info.Enabled {
  72. continue
  73. }
  74. // handle the clients that do not properly support Basic auth headers and require passing client_id/client_secret via POST payload
  75. if info.SendClientCredentialsViaPost {
  76. oauth2.RegisterBrokenAuthHeaderProvider(info.TokenUrl)
  77. }
  78. if name == "grafananet" {
  79. name = grafanaCom
  80. }
  81. setting.OAuthService.OAuthInfos[name] = info
  82. config := oauth2.Config{
  83. ClientID: info.ClientId,
  84. ClientSecret: info.ClientSecret,
  85. Endpoint: oauth2.Endpoint{
  86. AuthURL: info.AuthUrl,
  87. TokenURL: info.TokenUrl,
  88. },
  89. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  90. Scopes: info.Scopes,
  91. }
  92. logger := log.New("oauth." + name)
  93. // GitHub.
  94. if name == "github" {
  95. SocialMap["github"] = &SocialGithub{
  96. SocialBase: &SocialBase{
  97. Config: &config,
  98. log: logger,
  99. },
  100. allowedDomains: info.AllowedDomains,
  101. apiUrl: info.ApiUrl,
  102. allowSignup: info.AllowSignup,
  103. teamIds: sec.Key("team_ids").Ints(","),
  104. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  105. }
  106. }
  107. // GitLab.
  108. if name == "gitlab" {
  109. SocialMap["gitlab"] = &SocialGitlab{
  110. SocialBase: &SocialBase{
  111. Config: &config,
  112. log: logger,
  113. },
  114. allowedDomains: info.AllowedDomains,
  115. apiUrl: info.ApiUrl,
  116. allowSignup: info.AllowSignup,
  117. allowedGroups: util.SplitString(sec.Key("allowed_groups").String()),
  118. }
  119. }
  120. // Google.
  121. if name == "google" {
  122. SocialMap["google"] = &SocialGoogle{
  123. SocialBase: &SocialBase{
  124. Config: &config,
  125. log: logger,
  126. },
  127. allowedDomains: info.AllowedDomains,
  128. hostedDomain: info.HostedDomain,
  129. apiUrl: info.ApiUrl,
  130. allowSignup: info.AllowSignup,
  131. }
  132. }
  133. // Generic - Uses the same scheme as Github.
  134. if name == "generic_oauth" {
  135. SocialMap["generic_oauth"] = &SocialGenericOAuth{
  136. SocialBase: &SocialBase{
  137. Config: &config,
  138. log: logger,
  139. },
  140. allowedDomains: info.AllowedDomains,
  141. apiUrl: info.ApiUrl,
  142. allowSignup: info.AllowSignup,
  143. emailAttributeName: info.EmailAttributeName,
  144. teamIds: sec.Key("team_ids").Ints(","),
  145. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  146. }
  147. }
  148. if name == grafanaCom {
  149. config = oauth2.Config{
  150. ClientID: info.ClientId,
  151. ClientSecret: info.ClientSecret,
  152. Endpoint: oauth2.Endpoint{
  153. AuthURL: setting.GrafanaComUrl + "/oauth2/authorize",
  154. TokenURL: setting.GrafanaComUrl + "/api/oauth2/token",
  155. },
  156. RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
  157. Scopes: info.Scopes,
  158. }
  159. SocialMap[grafanaCom] = &SocialGrafanaCom{
  160. SocialBase: &SocialBase{
  161. Config: &config,
  162. log: logger,
  163. },
  164. url: setting.GrafanaComUrl,
  165. allowSignup: info.AllowSignup,
  166. allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
  167. }
  168. }
  169. }
  170. }
  171. // GetOAuthProviders returns available oauth providers and if they're enabled or not
  172. var GetOAuthProviders = func(cfg *setting.Cfg) map[string]bool {
  173. result := map[string]bool{}
  174. if cfg == nil || cfg.Raw == nil {
  175. return result
  176. }
  177. for _, name := range allOauthes {
  178. if name == "grafananet" {
  179. name = grafanaCom
  180. }
  181. sec := cfg.Raw.Section("auth." + name)
  182. if sec == nil {
  183. continue
  184. }
  185. result[name] = sec.Key("enabled").MustBool()
  186. }
  187. return result
  188. }