@@ -441,7 +441,7 @@ func validateTenantAccess(ctx context.Context, tenantID gid.TenantID) {
|
||||
access, _ := ctx.Value(userTenantContextKey).(*userTenantAccess)
|
||||
|
||||
if access == nil {
|
||||
panic(fmt.Errorf("tenant not found"))
|
||||
panic(&authz.TenantAccessError{Message: "tenant not found"})
|
||||
}
|
||||
|
||||
if !slices.Contains(access.tenantIDs, tenantID) {
|
||||
@@ -451,6 +451,6 @@ func validateTenantAccess(ctx context.Context, tenantID gid.TenantID) {
|
||||
}
|
||||
}
|
||||
|
||||
panic(fmt.Errorf("access denied to tenant"))
|
||||
panic(&authz.TenantAccessError{Message: "tenant not found"})
|
||||
}
|
||||
}
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
69
pkg/server/graphql/errors.go
Normal file
69
pkg/server/graphql/errors.go
Normal file
@@ -0,0 +1,69 @@
|
||||
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
|
||||
//
|
||||
// Permission to use, copy, modify, and/or distribute this software for any
|
||||
// purpose with or without fee is hereby granted, provided that the above
|
||||
// copyright notice and this permission notice appear in all copies.
|
||||
//
|
||||
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
// PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
package graphql
|
||||
|
||||
import (
|
||||
"maps"
|
||||
|
||||
"github.com/vektah/gqlparser/v2/gqlerror"
|
||||
)
|
||||
|
||||
func Unauthorized() *gqlerror.Error {
|
||||
return &gqlerror.Error{
|
||||
Message: "not authorized",
|
||||
Extensions: map[string]any{
|
||||
"code": "UNAUTHORIZED",
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func AuthenticationRequired(details map[string]any) *gqlerror.Error {
|
||||
extensions := map[string]any{
|
||||
"code": "AUTHENTICATION_REQUIRED",
|
||||
}
|
||||
maps.Copy(extensions, details)
|
||||
|
||||
return &gqlerror.Error{
|
||||
Message: "Additional authentication required to access this organization",
|
||||
Extensions: extensions,
|
||||
}
|
||||
}
|
||||
|
||||
func NotFound(err error) *gqlerror.Error {
|
||||
return &gqlerror.Error{
|
||||
Message: err.Error(),
|
||||
Extensions: map[string]any{
|
||||
"code": "NOT_FOUND",
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func Conflict(err error) *gqlerror.Error {
|
||||
return &gqlerror.Error{
|
||||
Message: err.Error(),
|
||||
Extensions: map[string]any{
|
||||
"code": "CONFLICT",
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func Invalid(err error) *gqlerror.Error {
|
||||
return &gqlerror.Error{
|
||||
Message: err.Error(),
|
||||
Extensions: map[string]any{
|
||||
"code": "INVALID",
|
||||
},
|
||||
}
|
||||
}
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
"runtime/debug"
|
||||
|
||||
"github.com/getprobo/probo/pkg/auth"
|
||||
"github.com/getprobo/probo/pkg/authz"
|
||||
"github.com/vektah/gqlparser/v2/gqlerror"
|
||||
"go.gearno.de/kit/httpserver"
|
||||
"go.gearno.de/kit/log"
|
||||
@@ -32,29 +33,26 @@ func RecoverFunc(ctx context.Context, err any) error {
|
||||
|
||||
var errSAMLRequired auth.ErrSAMLAuthRequired
|
||||
if errors.As(asError(err), &errSAMLRequired) {
|
||||
return &gqlerror.Error{
|
||||
Message: "Additional authentication required to access this organization",
|
||||
Extensions: map[string]any{
|
||||
"code": "AUTHENTICATION_REQUIRED",
|
||||
"requiresSaml": true,
|
||||
"redirectUrl": errSAMLRequired.RedirectURL,
|
||||
"samlConfigId": errSAMLRequired.ConfigID.String(),
|
||||
"organizationId": errSAMLRequired.OrganizationID.String(),
|
||||
},
|
||||
}
|
||||
return AuthenticationRequired(map[string]any{
|
||||
"requiresSaml": true,
|
||||
"redirectUrl": errSAMLRequired.RedirectURL,
|
||||
"samlConfigId": errSAMLRequired.ConfigID.String(),
|
||||
"organizationId": errSAMLRequired.OrganizationID.String(),
|
||||
})
|
||||
}
|
||||
|
||||
var errPasswordRequired auth.ErrPasswordAuthRequired
|
||||
if errors.As(asError(err), &errPasswordRequired) {
|
||||
return &gqlerror.Error{
|
||||
Message: "Additional authentication required to access this organization",
|
||||
Extensions: map[string]any{
|
||||
"code": "AUTHENTICATION_REQUIRED",
|
||||
"requiresSaml": false,
|
||||
"redirectUrl": errPasswordRequired.RedirectURL,
|
||||
"organizationId": errPasswordRequired.OrganizationID.String(),
|
||||
},
|
||||
}
|
||||
return AuthenticationRequired(map[string]any{
|
||||
"requiresSaml": false,
|
||||
"redirectUrl": errPasswordRequired.RedirectURL,
|
||||
"organizationId": errPasswordRequired.OrganizationID.String(),
|
||||
})
|
||||
}
|
||||
|
||||
var tenantAccessErr *authz.TenantAccessError
|
||||
if errTyped, ok := err.(error); ok && errors.As(errTyped, &tenantAccessErr) {
|
||||
return Unauthorized()
|
||||
}
|
||||
|
||||
logger := httpserver.LoggerFromContext(ctx)
|
||||
|
||||
Reference in New Issue
Block a user