Catch assumption needed errors
Signed-off-by: Émile Ré <emile@getprobo.com>
This commit is contained in:
@@ -72,6 +72,11 @@ func NewAuthorizeFunc(
|
||||
}
|
||||
|
||||
if err := svc.Authorizer.Authorize(ctx, params); err != nil {
|
||||
var errAssumptionNeeded *iam.ErrAssumptionNeeded
|
||||
if errors.As(err, &errAssumptionNeeded) {
|
||||
return gqlutils.NotAssuming(ctx, err)
|
||||
}
|
||||
|
||||
var errInsufficientPermissions *iam.ErrInsufficientPermissions
|
||||
if errors.As(err, &errInsufficientPermissions) {
|
||||
return gqlutils.Forbidden(ctx, err)
|
||||
|
||||
@@ -52,6 +52,20 @@ func Unauthenticatedf(ctx context.Context, format string, a ...any) *gqlerror.Er
|
||||
return Unauthenticated(ctx, fmt.Errorf(format, a...))
|
||||
}
|
||||
|
||||
func NotAssuming(ctx context.Context, err error) *gqlerror.Error {
|
||||
return &gqlerror.Error{
|
||||
Message: err.Error(),
|
||||
Path: graphql.GetPath(ctx),
|
||||
Extensions: map[string]any{
|
||||
"code": "NOT_ASSUMING",
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func NotAssumingf(ctx context.Context, format string, a ...any) *gqlerror.Error {
|
||||
return NotAssuming(ctx, fmt.Errorf(format, a...))
|
||||
}
|
||||
|
||||
func Forbidden(ctx context.Context, err error) *gqlerror.Error {
|
||||
return &gqlerror.Error{
|
||||
Message: err.Error(),
|
||||
|
||||
Reference in New Issue
Block a user