mirror of
https://github.com/featurebasedb/featurebase.git
synced 2026-10-06 19:07:50 +00:00
added more authz functionality
This commit is contained in:
parent
44b855d50b
commit
f05f1d0de2
3 changed files with 151 additions and 4 deletions
|
|
@ -91,7 +91,7 @@ func (p *GroupPermissions) GetPermissions(groups []Group, index string) (permiss
|
|||
if perm, ok := p.Permissions[group.GroupID][index]; ok {
|
||||
allPermissions[perm] = true
|
||||
} else {
|
||||
return "", fmt.Errorf("User %s is NOT allowed access to index %s", group.UserID, index)
|
||||
return "", fmt.Errorf("User %s does not have permission to index %s", group.UserID, index)
|
||||
}
|
||||
} else {
|
||||
groupsDenied = append(groupsDenied, group.GroupID)
|
||||
|
|
@ -99,7 +99,7 @@ func (p *GroupPermissions) GetPermissions(groups []Group, index string) (permiss
|
|||
}
|
||||
|
||||
if len(groupsDenied) == len(groups) {
|
||||
return "", fmt.Errorf("group(s) %s are NOT allowed access to FeatureBase", groupsDenied)
|
||||
return "", fmt.Errorf("group(s) %s does not have permission to FeatureBase", groupsDenied)
|
||||
}
|
||||
|
||||
if allPermissions["admin"] {
|
||||
|
|
@ -112,3 +112,30 @@ func (p *GroupPermissions) GetPermissions(groups []Group, index string) (permiss
|
|||
return "", fmt.Errorf("no permissions found")
|
||||
}
|
||||
}
|
||||
|
||||
func (p *GroupPermissions) IsAdmin(groups []Group) bool {
|
||||
for _, group := range groups {
|
||||
if _, ok := p.Permissions[group.GroupID]; ok {
|
||||
for _, permission := range p.Permissions[group.GroupID] {
|
||||
if permission == "admin" {
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func (p *GroupPermissions) GetAuthorizedIndexList(groups []Group, desiredPermission string) (indexList []string) {
|
||||
|
||||
for _, group := range groups {
|
||||
if _, ok := p.Permissions[group.GroupID]; ok {
|
||||
for index, permission := range p.Permissions[group.GroupID] {
|
||||
if permission == desiredPermission {
|
||||
indexList = append(indexList, index)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return indexList
|
||||
}
|
||||
|
|
@ -23,6 +23,7 @@ import (
|
|||
)
|
||||
|
||||
func TestAuth_ReadPermissionsFile(t *testing.T) {
|
||||
|
||||
singleInput := `"dca35310-ecda-4f23-86cd-876aee55906b":
|
||||
"test": "read"`
|
||||
|
||||
|
|
@ -67,6 +68,7 @@ func TestAuth_ReadPermissionsFile(t *testing.T) {
|
|||
}
|
||||
|
||||
func TestAuth_GetPermissions(t *testing.T) {
|
||||
|
||||
// initializes different example of permissions file in yaml
|
||||
permissions1 := `"dca35310-ecda-4f23-86cd-876aee55906b":
|
||||
"test": "read"`
|
||||
|
|
@ -112,14 +114,14 @@ func TestAuth_GetPermissions(t *testing.T) {
|
|||
groupsList3,
|
||||
"test1",
|
||||
"",
|
||||
"NOT allowed access to index",
|
||||
"does not have permission to index",
|
||||
},
|
||||
{
|
||||
permissions2,
|
||||
groupsList2,
|
||||
"test",
|
||||
"",
|
||||
"NOT allowed access to FeatureBase",
|
||||
"does not have permission to FeatureBase",
|
||||
},
|
||||
{
|
||||
permissions1,
|
||||
|
|
@ -176,3 +178,90 @@ func TestAuth_GetPermissions(t *testing.T) {
|
|||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestAuth_IsAdmin(t *testing.T) {
|
||||
|
||||
group := []authz.Group{
|
||||
{"user-is", "dca35310-ecda-4f23-86cd-876aee55906b", "group-name"},
|
||||
}
|
||||
|
||||
groupPermissions1 := map[string]map[string]string{
|
||||
"dca35310-ecda-4f23-86cd-876aee55906b": {"test": "admin"},
|
||||
}
|
||||
|
||||
groupPermissions2 := map[string]map[string]string{
|
||||
"dca35310-ecda-4f23-86cd-876aee55906b": {"test": "read"},
|
||||
}
|
||||
|
||||
tests := []struct {
|
||||
groups []authz.Group
|
||||
groupPermissions map[string]map[string]string
|
||||
output bool
|
||||
}{
|
||||
{
|
||||
group, groupPermissions1, true,
|
||||
},
|
||||
{
|
||||
group, groupPermissions2, false,
|
||||
},
|
||||
}
|
||||
|
||||
for i, test := range tests {
|
||||
t.Run(fmt.Sprintf("%d", i), func(t *testing.T) {
|
||||
p := authz.GroupPermissions{test.groupPermissions}
|
||||
resp := p.IsAdmin(test.groups)
|
||||
if resp != test.output {
|
||||
t.Errorf("expected %t, but got %t", test.output, resp)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestAuth_GetAuthorizedIndexList(t *testing.T) {
|
||||
|
||||
group := []authz.Group{
|
||||
{"user-is", "dca35310-ecda-4f23-86cd-876aee55906b", "group-name"},
|
||||
}
|
||||
|
||||
p := authz.GroupPermissions{map[string]map[string]string{
|
||||
"dca35310-ecda-4f23-86cd-876aee55906b": {
|
||||
"test1": "admin",
|
||||
"test2": "read",
|
||||
"test3": "read",
|
||||
},
|
||||
}}
|
||||
|
||||
tests := []struct {
|
||||
groups []authz.Group
|
||||
permission string
|
||||
output []string
|
||||
}{
|
||||
{
|
||||
group,
|
||||
"read",
|
||||
[]string{"test2", "test3"},
|
||||
},
|
||||
{
|
||||
group,
|
||||
"admin",
|
||||
[]string{"test1"},
|
||||
},
|
||||
{
|
||||
group,
|
||||
"write",
|
||||
nil,
|
||||
},
|
||||
}
|
||||
|
||||
for i, test := range tests {
|
||||
t.Run(fmt.Sprintf("%d", i), func(t *testing.T) {
|
||||
|
||||
indexList := p.GetAuthorizedIndexList(test.groups, test.permission)
|
||||
|
||||
if !reflect.DeepEqual(indexList, test.output) {
|
||||
t.Errorf("expected %s, but got %s", test.output, indexList)
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
}
|
||||
|
|
@ -237,6 +237,37 @@ func (m *Command) Start() (err error) {
|
|||
if err = p.ReadPermissionsFile(permsFile); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
groups := []authz.Group{
|
||||
{
|
||||
UserID: "user-id",
|
||||
GroupID: "dca35310-ecda-4f23-86cd-876aee55906b",
|
||||
GroupName: "group-name",
|
||||
},
|
||||
// {
|
||||
// UserID: "user-id",
|
||||
// GroupID: "dca35310-ecda-4f23-86cd-876aee559900",
|
||||
// GroupName: "group-name",
|
||||
// },
|
||||
}
|
||||
|
||||
index := "test"
|
||||
|
||||
perm, err := p.GetPermissions(groups, index)
|
||||
fmt.Printf("\nuser has %s access to index %s\n", perm, index)
|
||||
if err != nil {
|
||||
fmt.Printf("\np: %s, err: %s\n", perm, err.Error())
|
||||
}
|
||||
|
||||
adminAccess := p.IsAdmin(groups)
|
||||
fmt.Printf("\nAdminAccess: %t\n", adminAccess)
|
||||
|
||||
accessList := []string{"read", "write", "admin"}
|
||||
for _, a := range accessList {
|
||||
indexList := p.GetAuthorizedIndexList(groups, a)
|
||||
fmt.Printf("\nPermission requested: %s, Index List: %s\n", a, indexList)
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
// Initialize server.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue