2014-10-07 15:54:38 -04:00
|
|
|
package social
|
|
|
|
|
|
|
|
|
|
import (
|
2016-10-11 02:51:44 -04:00
|
|
|
"net/http"
|
2014-10-07 15:54:38 -04:00
|
|
|
"strings"
|
|
|
|
|
|
2018-01-16 12:32:42 +01:00
|
|
|
"context"
|
|
|
|
|
|
2014-12-30 10:10:13 +01:00
|
|
|
"golang.org/x/oauth2"
|
2016-10-11 02:51:44 -04:00
|
|
|
|
2018-01-18 17:17:51 -05:00
|
|
|
"github.com/grafana/grafana/pkg/log"
|
2016-10-11 02:51:44 -04:00
|
|
|
"github.com/grafana/grafana/pkg/setting"
|
2017-04-25 03:14:29 -04:00
|
|
|
"github.com/grafana/grafana/pkg/util"
|
2014-10-07 15:54:38 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
|
|
type BasicUserInfo struct {
|
2016-12-14 12:15:35 +09:00
|
|
|
Name string
|
|
|
|
|
Email string
|
|
|
|
|
Login string
|
|
|
|
|
Company string
|
|
|
|
|
Role string
|
2014-10-07 15:54:38 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
type SocialConnector interface {
|
|
|
|
|
Type() int
|
2018-01-18 17:17:51 -05:00
|
|
|
UserInfo(client *http.Client, token *oauth2.Token) (*BasicUserInfo, error)
|
2015-04-06 14:16:22 +02:00
|
|
|
IsEmailAllowed(email string) bool
|
2015-04-09 17:15:19 -08:00
|
|
|
IsSignupAllowed() bool
|
2014-10-07 15:54:38 -04:00
|
|
|
|
2014-12-30 10:10:13 +01:00
|
|
|
AuthCodeURL(state string, opts ...oauth2.AuthCodeOption) string
|
2015-04-04 09:50:25 +02:00
|
|
|
Exchange(ctx context.Context, code string) (*oauth2.Token, error)
|
2016-10-11 02:51:44 -04:00
|
|
|
Client(ctx context.Context, t *oauth2.Token) *http.Client
|
2014-10-07 15:54:38 -04:00
|
|
|
}
|
|
|
|
|
|
2018-01-18 17:17:51 -05:00
|
|
|
type SocialBase struct {
|
|
|
|
|
*oauth2.Config
|
|
|
|
|
log log.Logger
|
|
|
|
|
}
|
|
|
|
|
|
2017-02-01 16:32:51 +03:00
|
|
|
type Error struct {
|
|
|
|
|
s string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func (e *Error) Error() string {
|
|
|
|
|
return e.s
|
|
|
|
|
}
|
|
|
|
|
|
2014-10-07 15:54:38 -04:00
|
|
|
var (
|
2014-10-07 17:56:37 -04:00
|
|
|
SocialBaseUrl = "/login/"
|
2014-10-07 15:54:38 -04:00
|
|
|
SocialMap = make(map[string]SocialConnector)
|
|
|
|
|
)
|
|
|
|
|
|
2014-10-07 17:56:37 -04:00
|
|
|
func NewOAuthService() {
|
2014-10-07 15:54:38 -04:00
|
|
|
setting.OAuthService = &setting.OAuther{}
|
|
|
|
|
setting.OAuthService.OAuthInfos = make(map[string]*setting.OAuthInfo)
|
|
|
|
|
|
2017-05-22 14:56:50 +02:00
|
|
|
allOauthes := []string{"github", "google", "generic_oauth", "grafananet", "grafana_com"}
|
2014-10-07 15:54:38 -04:00
|
|
|
|
|
|
|
|
for _, name := range allOauthes {
|
2015-01-27 10:09:54 +01:00
|
|
|
sec := setting.Cfg.Section("auth." + name)
|
2014-10-07 15:54:38 -04:00
|
|
|
info := &setting.OAuthInfo{
|
2015-04-06 14:16:22 +02:00
|
|
|
ClientId: sec.Key("client_id").String(),
|
|
|
|
|
ClientSecret: sec.Key("client_secret").String(),
|
2017-04-25 03:14:29 -04:00
|
|
|
Scopes: util.SplitString(sec.Key("scopes").String()),
|
2015-04-06 14:16:22 +02:00
|
|
|
AuthUrl: sec.Key("auth_url").String(),
|
|
|
|
|
TokenUrl: sec.Key("token_url").String(),
|
2015-04-15 10:31:56 +02:00
|
|
|
ApiUrl: sec.Key("api_url").String(),
|
2015-04-06 14:16:22 +02:00
|
|
|
Enabled: sec.Key("enabled").MustBool(),
|
2017-04-25 03:14:29 -04:00
|
|
|
AllowedDomains: util.SplitString(sec.Key("allowed_domains").String()),
|
2016-10-28 03:00:47 -07:00
|
|
|
HostedDomain: sec.Key("hosted_domain").String(),
|
2015-04-09 17:15:19 -08:00
|
|
|
AllowSignup: sec.Key("allow_sign_up").MustBool(),
|
2016-09-28 15:10:50 +02:00
|
|
|
Name: sec.Key("name").MustString(name),
|
2016-10-11 02:51:44 -04:00
|
|
|
TlsClientCert: sec.Key("tls_client_cert").String(),
|
|
|
|
|
TlsClientKey: sec.Key("tls_client_key").String(),
|
|
|
|
|
TlsClientCa: sec.Key("tls_client_ca").String(),
|
2017-09-28 11:10:59 +01:00
|
|
|
TlsSkipVerify: sec.Key("tls_skip_verify_insecure").MustBool(),
|
2014-10-07 17:56:37 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if !info.Enabled {
|
|
|
|
|
continue
|
2014-10-07 15:54:38 -04:00
|
|
|
}
|
|
|
|
|
|
2017-05-22 14:56:50 +02:00
|
|
|
if name == "grafananet" {
|
|
|
|
|
name = "grafana_com"
|
|
|
|
|
}
|
|
|
|
|
|
2014-10-07 15:54:38 -04:00
|
|
|
setting.OAuthService.OAuthInfos[name] = info
|
2016-10-11 02:51:44 -04:00
|
|
|
|
2014-12-30 10:10:13 +01:00
|
|
|
config := oauth2.Config{
|
|
|
|
|
ClientID: info.ClientId,
|
|
|
|
|
ClientSecret: info.ClientSecret,
|
|
|
|
|
Endpoint: oauth2.Endpoint{
|
|
|
|
|
AuthURL: info.AuthUrl,
|
|
|
|
|
TokenURL: info.TokenUrl,
|
|
|
|
|
},
|
|
|
|
|
RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
|
|
|
|
|
Scopes: info.Scopes,
|
2014-10-07 15:54:38 -04:00
|
|
|
}
|
|
|
|
|
|
2018-01-23 13:03:44 +01:00
|
|
|
logger := log.New("oauth." + name)
|
2018-01-18 17:17:51 -05:00
|
|
|
|
2014-10-07 17:56:37 -04:00
|
|
|
// GitHub.
|
|
|
|
|
if name == "github" {
|
2015-04-29 09:49:22 +02:00
|
|
|
SocialMap["github"] = &SocialGithub{
|
2018-01-18 19:17:05 -05:00
|
|
|
SocialBase: &SocialBase{
|
|
|
|
|
Config: &config,
|
|
|
|
|
log: logger,
|
2018-01-18 17:17:51 -05:00
|
|
|
},
|
2015-05-23 17:06:51 +03:00
|
|
|
allowedDomains: info.AllowedDomains,
|
|
|
|
|
apiUrl: info.ApiUrl,
|
|
|
|
|
allowSignup: info.AllowSignup,
|
2016-09-28 15:10:50 +02:00
|
|
|
teamIds: sec.Key("team_ids").Ints(","),
|
2017-04-25 03:14:29 -04:00
|
|
|
allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
|
2015-04-29 09:49:22 +02:00
|
|
|
}
|
2014-10-07 17:56:37 -04:00
|
|
|
}
|
2014-10-07 15:54:38 -04:00
|
|
|
|
2014-10-07 17:56:37 -04:00
|
|
|
// Google.
|
|
|
|
|
if name == "google" {
|
2015-04-29 09:49:22 +02:00
|
|
|
SocialMap["google"] = &SocialGoogle{
|
2018-01-18 19:17:05 -05:00
|
|
|
SocialBase: &SocialBase{
|
|
|
|
|
Config: &config,
|
|
|
|
|
log: logger,
|
2018-01-18 17:17:51 -05:00
|
|
|
},
|
2016-12-14 12:15:35 +09:00
|
|
|
allowedDomains: info.AllowedDomains,
|
|
|
|
|
hostedDomain: info.HostedDomain,
|
|
|
|
|
apiUrl: info.ApiUrl,
|
|
|
|
|
allowSignup: info.AllowSignup,
|
2015-04-29 09:49:22 +02:00
|
|
|
}
|
2014-10-07 17:56:37 -04:00
|
|
|
}
|
2016-04-12 17:54:45 -07:00
|
|
|
|
|
|
|
|
// Generic - Uses the same scheme as Github.
|
2016-05-18 13:37:04 -07:00
|
|
|
if name == "generic_oauth" {
|
2018-01-18 17:17:51 -05:00
|
|
|
SocialMap["generic_oauth"] = &SocialGenericOAuth{
|
2018-01-18 19:17:05 -05:00
|
|
|
SocialBase: &SocialBase{
|
|
|
|
|
Config: &config,
|
|
|
|
|
log: logger,
|
2018-01-18 17:17:51 -05:00
|
|
|
},
|
2016-04-12 17:54:45 -07:00
|
|
|
allowedDomains: info.AllowedDomains,
|
|
|
|
|
apiUrl: info.ApiUrl,
|
|
|
|
|
allowSignup: info.AllowSignup,
|
2016-09-28 15:10:50 +02:00
|
|
|
teamIds: sec.Key("team_ids").Ints(","),
|
2017-04-25 03:14:29 -04:00
|
|
|
allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
|
2016-04-12 17:54:45 -07:00
|
|
|
}
|
|
|
|
|
}
|
2016-09-19 16:48:07 -04:00
|
|
|
|
2017-05-22 14:56:50 +02:00
|
|
|
if name == "grafana_com" {
|
2016-10-11 02:51:44 -04:00
|
|
|
config = oauth2.Config{
|
2016-09-19 16:48:07 -04:00
|
|
|
ClientID: info.ClientId,
|
|
|
|
|
ClientSecret: info.ClientSecret,
|
2016-12-14 12:15:35 +09:00
|
|
|
Endpoint: oauth2.Endpoint{
|
2017-05-22 14:56:50 +02:00
|
|
|
AuthURL: setting.GrafanaComUrl + "/oauth2/authorize",
|
|
|
|
|
TokenURL: setting.GrafanaComUrl + "/api/oauth2/token",
|
2016-09-19 16:48:07 -04:00
|
|
|
},
|
2016-12-14 12:15:35 +09:00
|
|
|
RedirectURL: strings.TrimSuffix(setting.AppUrl, "/") + SocialBaseUrl + name,
|
|
|
|
|
Scopes: info.Scopes,
|
2016-09-19 16:48:07 -04:00
|
|
|
}
|
|
|
|
|
|
2017-05-22 14:56:50 +02:00
|
|
|
SocialMap["grafana_com"] = &SocialGrafanaCom{
|
2018-01-18 19:17:05 -05:00
|
|
|
SocialBase: &SocialBase{
|
|
|
|
|
Config: &config,
|
|
|
|
|
log: logger,
|
2018-01-18 17:17:51 -05:00
|
|
|
},
|
2017-05-22 14:56:50 +02:00
|
|
|
url: setting.GrafanaComUrl,
|
2016-09-19 16:48:07 -04:00
|
|
|
allowSignup: info.AllowSignup,
|
2017-04-25 03:14:29 -04:00
|
|
|
allowedOrganizations: util.SplitString(sec.Key("allowed_organizations").String()),
|
2016-09-19 16:48:07 -04:00
|
|
|
}
|
|
|
|
|
}
|
2014-10-07 15:54:38 -04:00
|
|
|
}
|
|
|
|
|
}
|