From 476838d59aaeec781af724513cd17b5c76c97436 Mon Sep 17 00:00:00 2001 From: James Read Date: Sun, 24 Nov 2024 16:22:24 -0500 Subject: [PATCH] bugfix: Local users now work with a single usergroup (#486) --- internal/config/config.go | 2 +- internal/grpcapi/grpcApi.go | 3 +-- internal/httpservers/restapi_auth_local.go | 29 +++++++++++++++++----- 3 files changed, 25 insertions(+), 9 deletions(-) diff --git a/internal/config/config.go b/internal/config/config.go index 9538621..fa1f673 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -147,8 +147,8 @@ type AuthLocalUsersConfig struct { type LocalUser struct { Username string + Usergroup string Password string - Groups []string } type OAuth2Provider struct { diff --git a/internal/grpcapi/grpcApi.go b/internal/grpcapi/grpcApi.go index 940a89d..e0820b8 100644 --- a/internal/grpcapi/grpcApi.go +++ b/internal/grpcapi/grpcApi.go @@ -114,8 +114,7 @@ func (api *oliveTinAPI) LocalUserLogin(ctx ctx.Context, req *pb.LocalUserLoginRe match := checkUserPassword(cfg, req.Username, req.Password) if match { - header := metadata.Pairs("set-user", req.Username) - grpc.SendHeader(ctx, header) + grpc.SendHeader(ctx, metadata.Pairs("set-username", req.Username)) log.WithFields(log.Fields{ "username": req.Username, diff --git a/internal/httpservers/restapi_auth_local.go b/internal/httpservers/restapi_auth_local.go index f597541..8422a29 100644 --- a/internal/httpservers/restapi_auth_local.go +++ b/internal/httpservers/restapi_auth_local.go @@ -5,11 +5,12 @@ import ( "net/http" "github.com/google/uuid" + "github.com/OliveTin/OliveTin/internal/config" log "github.com/sirupsen/logrus" ) var ( - localUserSessions = make(map[string]string) // sid -> username, used for local user sessions + localUserSessions = make(map[string]*config.LocalUser) ) func parseLocalUserCookie(req *http.Request) (string, string, string) { @@ -21,7 +22,7 @@ func parseLocalUserCookie(req *http.Request) (string, string, string) { cookieValue := cookie.Value - username, ok := localUserSessions[cookieValue] + user, ok := localUserSessions[cookieValue] if !ok { log.WithFields(log.Fields{ @@ -31,15 +32,31 @@ func parseLocalUserCookie(req *http.Request) (string, string, string) { return "", "", "" } - return username, "", cookie.Value + return user.Username, user.Usergroup, cookie.Value +} + +func findUserByUsername(searchUsername string) *config.LocalUser { + for _, user := range cfg.AuthLocalUsers.Users { + if user.Username == searchUsername { + return user + } + } + + return nil } func forwardResponseHandlerLoginLocalUser(md metadata.MD, w http.ResponseWriter) error { - setUser := getMetadataKeyOrEmpty(md, "set-user") + setUsername := getMetadataKeyOrEmpty(md, "set-username") + + if setUsername != "" { + user := findUserByUsername(setUsername) + + if user == nil { + return nil + } - if setUser != "" { sid := uuid.NewString() - localUserSessions[sid] = setUser + localUserSessions[sid] = user http.SetCookie( w,