Rewrite identity and access management

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2025-12-03 19:23:15 +01:00
parent 4ed3f5a067
commit 74fc3b8cd1
201 changed files with 32895 additions and 23649 deletions

View File

@@ -0,0 +1,71 @@
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package gqlutils
import (
"context"
"net/http"
"github.com/99designs/gqlgen/graphql"
"github.com/99designs/gqlgen/graphql/handler"
"github.com/99designs/gqlgen/graphql/handler/extension"
"github.com/99designs/gqlgen/graphql/handler/transport"
"go.gearno.de/kit/log"
)
type Handler struct {
gqlhandler *handler.Server
}
var (
mb int64 = 1024 * 1024
postTransport = transport.POST{}
optionsTransport = transport.Options{}
multipartTransport = transport.MultipartForm{
MaxMemory: 32 * mb,
MaxUploadSize: 50 * mb,
}
introspectionExtension = extension.Introspection{}
)
func NewHandler[S graphql.ExecutableSchema](executableSchema S, logger *log.Logger) *Handler {
handler := handler.New(executableSchema)
handler.AddTransport(postTransport)
handler.AddTransport(optionsTransport)
handler.AddTransport(multipartTransport)
handler.Use(introspectionExtension)
handler.Use(NewTracingExtension(logger))
handler.SetRecoverFunc(RecoverFunc)
return &Handler{gqlhandler: handler}
}
func (gqlh *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
gqlh.gqlhandler.ServeHTTP(w, r)
}
func (gqlh *Handler) Use(extension graphql.HandlerExtension) {
gqlh.gqlhandler.Use(extension)
}
func (gqlh *Handler) AroundOperations(f func(ctx context.Context, next graphql.OperationHandler) graphql.ResponseHandler) {
gqlh.gqlhandler.AroundOperations(f)
}

View File

@@ -22,8 +22,7 @@ import (
"github.com/vektah/gqlparser/v2/gqlerror"
"go.gearno.de/kit/httpserver"
"go.gearno.de/kit/log"
"go.probo.inc/probo/pkg/auth"
"go.probo.inc/probo/pkg/authz"
"go.probo.inc/probo/pkg/iam"
"go.probo.inc/probo/pkg/validator"
)
@@ -32,24 +31,25 @@ func RecoverFunc(ctx context.Context, err any) error {
return gqlErr
}
var errSAMLRequired auth.ErrSAMLAuthRequired
if errors.As(asError(err), &errSAMLRequired) {
return AuthenticationRequired(map[string]any{
"requiresSaml": true,
"redirectUrl": errSAMLRequired.RedirectURL,
"samlConfigId": errSAMLRequired.ConfigID.String(),
"organizationId": errSAMLRequired.OrganizationID.String(),
})
}
// TODO: multi session here
// var errSAMLRequired iam.ErrSAMLAuthRequired
// if errors.As(asError(err), &errSAMLRequired) {
// return AuthenticationRequired(map[string]any{
// "requiresSaml": true,
// "redirectUrl": errSAMLRequired.RedirectURL,
// "samlConfigId": errSAMLRequired.ConfigID.String(),
// "organizationId": errSAMLRequired.OrganizationID.String(),
// })
// }
var errPasswordRequired auth.ErrPasswordAuthRequired
if errors.As(asError(err), &errPasswordRequired) {
return AuthenticationRequired(map[string]any{
"requiresSaml": false,
"redirectUrl": errPasswordRequired.RedirectURL,
"organizationId": errPasswordRequired.OrganizationID.String(),
})
}
// var errPasswordRequired iam.ErrPasswordAuthRequired
// if errors.As(asError(err), &errPasswordRequired) {
// return AuthenticationRequired(map[string]any{
// "requiresSaml": false,
// "redirectUrl": errPasswordRequired.RedirectURL,
// "organizationId": errPasswordRequired.OrganizationID.String(),
// })
// }
var errValidations validator.ValidationErrors
if errors.As(asError(err), &errValidations) {
@@ -72,12 +72,12 @@ func RecoverFunc(ctx context.Context, err any) error {
return gqlErrors
}
var tenantAccessErr *authz.TenantAccessError
var tenantAccessErr *iam.TenantAccessError
if errTyped, ok := err.(error); ok && errors.As(errTyped, &tenantAccessErr) {
return Unauthorized()
}
var permissionDeniedErr *authz.PermissionDeniedError
var permissionDeniedErr *iam.ErrInsufficientPermissions
if errTyped, ok := err.(error); ok && errors.As(errTyped, &permissionDeniedErr) {
return Forbidden(permissionDeniedErr)
}