// Copyright (c) 2026 Probo Inc . // // Permission is hereby granted, free of charge, to any person obtaining a copy // of this software and associated documentation files (the "Software"), to deal // in the Software without restriction, including without limitation the rights // to use, copy, modify, merge, publish, distribute, sublicense, and/or sell // copies of the Software, and to permit persons to whom the Software is // furnished to do so, subject to the following conditions: // // The above copyright notice and this permission notice shall be included in // all copies or substantial portions of the Software. // // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, // OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE // SOFTWARE. package dataloader import ( "context" "errors" "go.gearno.de/kit/log" "go.probo.inc/probo/pkg/coredata" "go.probo.inc/probo/pkg/gid" "go.probo.inc/probo/pkg/iam" "go.probo.inc/probo/pkg/server/api/authz" "go.probo.inc/probo/pkg/server/gqlutils" ) // NewAuthorizeFunc returns an authz.AuthorizeFunc that batches authorize // calls through the per-request dataloader. Parallel field resolvers within // the same request collapse into a single iam.Authorizer.AuthorizeMulti // call. Requires the dataloader middleware to have populated Loaders in // context. func NewAuthorizeFunc(logger *log.Logger) authz.AuthorizeFunc { return func( ctx context.Context, objectID gid.GID, action iam.Action, options ...authz.AuthorizeFuncOption, ) (*coredata.Scope, error) { loaders := FromContext(ctx) applied := iam.AuthorizeParams{ ResourceAttributes: make(map[string]string), } for _, opt := range options { opt(&applied) } result, err := loaders.Authorize.Load( ctx, AuthorizeKey{ ResourceID: objectID, Action: action, ResourceAttributes: EncodeAuthorizeKeyAttributes(applied.ResourceAttributes), DryRun: applied.DryRun, SkipAssumptionCheck: applied.SkipAssumptionCheck, }, ) if err != nil { if _, ok := errors.AsType[*iam.ErrAssumptionRequired](err); ok { return nil, gqlutils.AssumptionRequired(ctx, err) } if _, ok := errors.AsType[*iam.ErrInsufficientPermissions](err); ok { return nil, gqlutils.Forbidden(ctx, err) } if _, ok := errors.AsType[*iam.ErrInsufficientOAuth2Scope](err); ok { return nil, gqlutils.Forbidden(ctx, err) } if errors.Is(err, coredata.ErrResourceNotFound) { return nil, gqlutils.NotFoundf(ctx, "resource not found") } logger.ErrorCtx(ctx, "cannot authorize", log.Error(err)) return nil, gqlutils.Internal(ctx) } return result.Scope, nil } }