Skip to content

Commit 4e6f2be

Browse files
committed
add permission checks to api endpoints
This adds permission checks to api endpoints. The following permissions-api policy actions are now required: - iam_issuer_create - iam_issuer_update - iam_issuer_delete - iam_issuer_get - iam_oauthclient_create - iam_oauthclient_delete - iam_oauthclient_get Signed-off-by: Mike Mason <[email protected]>
1 parent 5765bbc commit 4e6f2be

File tree

13 files changed

+385
-78
lines changed

13 files changed

+385
-78
lines changed

README.md

+11
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,18 @@ $ openssl genpkey -out privkey.pem -algorithm RSA -pkeyopt rsa_keygen_bits:4096
7070

7171
Update the config file and/or Docker Compose volume mounts accordingly.
7272

73+
If the permissions config has been defined, the actor will need access to the following actions to make the corresponding api calls. See [Permissions-API][permissionsapi] for more details on updating your policy.
74+
75+
* iam_issuer_create
76+
* iam_issuer_update
77+
* iam_issuer_delete
78+
* iam_issuer_get
79+
* iam_oauthclient_create
80+
* iam_oauthclient_delete
81+
* iam_oauthclient_get
82+
7383
[pkcs8]: https://en.wikipedia.org/wiki/PKCS_8
84+
[permissionsapi]: https://github.com/infratographer/permissions-api
7485

7586
## Development
7687

chart/identity-api/templates/configMap.yaml

+4
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,10 @@ data:
3636
{{- end }}
3737
storage:
3838
type: crdb
39+
permissions:
40+
url: {{ .permissions.url | quote }}
41+
ignoreNoResponders: {{ .permissions.ignoreNoResponders }}
42+
defaultAllow: {{ .permissions.defaultAllow }}
3943
audit:
4044
enabled: {{ .audit.enabled }}
4145
path: /app-audit/audit.log

chart/identity-api/values.yaml

+12
Original file line numberDiff line numberDiff line change
@@ -76,6 +76,18 @@ config:
7676
path: "/keys/default.pem"
7777
algorithm: RS256
7878

79+
permissions:
80+
# url should point to a permissions-api authorization API route, such as https://example.com/api/v1/allow.
81+
# If not set, all permissions checks will be denied by default. To override this behavior, set defaultAllow
82+
# to true.
83+
url: ""
84+
85+
# ignoreNoResponders will ignore no responder errors when auth relationship requests are published.
86+
ignoreNoResponders: false
87+
88+
# defaultAllow if set to true, will allow all permissions checks when URL is not set.
89+
defaultAllow: false
90+
7991
audit:
8092
enabled: false
8193
component: identity-api

cmd/serve.go

+9-1
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ import (
1212
"github.com/ory/fosite/compose"
1313
"github.com/spf13/cobra"
1414
"github.com/spf13/viper"
15+
"go.infratographer.com/permissions-api/pkg/permissions"
1516
"go.infratographer.com/x/crdbx"
1617
"go.infratographer.com/x/echojwtx"
1718
"go.infratographer.com/x/echox"
@@ -72,6 +73,13 @@ func serve(ctx context.Context) {
7273
defer auditCloseFn() //nolint:errcheck // Not needed to check returned error.
7374
}
7475

76+
perms, err := permissions.New(config.Config.Permissions,
77+
permissions.WithLogger(logger),
78+
)
79+
if err != nil {
80+
logger.Fatal("failed to initialize permissions", zap.Error(err))
81+
}
82+
7583
storageEngine, err := storage.NewEngine(config.Config.CRDB)
7684
if err != nil {
7785
logger.Fatalf("error initializing storage: %s", err)
@@ -105,7 +113,7 @@ func serve(ctx context.Context) {
105113
oauth2.NewClientCredentialsHandlerFactory,
106114
)
107115

108-
apiHandler, err := httpsrv.NewAPIHandler(storageEngine, auditMiddleware)
116+
apiHandler, err := httpsrv.NewAPIHandler(storageEngine, auditMiddleware, perms.Middleware())
109117
if err != nil {
110118
logger.Fatal("error initializing API server: %s", err)
111119
}

go.mod

+47-32
Original file line numberDiff line numberDiff line change
@@ -4,25 +4,25 @@ go 1.20
44

55
require (
66
github.com/MicahParks/keyfunc/v2 v2.1.0
7-
github.com/cockroachdb/cockroach-go/v2 v2.3.5
7+
github.com/cockroachdb/cockroach-go/v2 v2.3.6
88
github.com/deepmap/oapi-codegen v1.13.4
99
github.com/getkin/kin-openapi v0.118.0
1010
github.com/google/cel-go v0.18.0
1111
github.com/labstack/echo-jwt/v4 v4.2.0
12-
github.com/labstack/echo/v4 v4.11.1
12+
github.com/labstack/echo/v4 v4.11.4
1313
github.com/metal-toolbox/auditevent v0.8.0
1414
github.com/ory/fosite v0.44.0
1515
github.com/ory/x v0.0.589
1616
github.com/pressly/goose/v3 v3.15.0
17-
github.com/spf13/cobra v1.7.0
17+
github.com/spf13/cobra v1.8.0
1818
github.com/spf13/pflag v1.0.5
19-
github.com/spf13/viper v1.16.0
19+
github.com/spf13/viper v1.18.2
2020
github.com/stretchr/testify v1.8.4
21-
go.infratographer.com/x v0.3.8
21+
go.infratographer.com/x v0.3.9
2222
go.opentelemetry.io/otel v1.16.0
2323
go.opentelemetry.io/otel/trace v1.16.0
24-
go.uber.org/zap v1.25.0
25-
google.golang.org/genproto/googleapis/api v0.0.0-20230913181813-007df8e322eb
24+
go.uber.org/zap v1.26.0
25+
google.golang.org/genproto/googleapis/api v0.0.0-20231106174013-bbf56f31fb17
2626
google.golang.org/protobuf v1.31.0
2727
gopkg.in/square/go-jose.v2 v2.6.0
2828
gopkg.in/yaml.v3 v3.0.1
@@ -33,20 +33,24 @@ require (
3333
github.com/antlr/antlr4/runtime/Go/antlr/v4 v4.0.0-20230305170008-8188dc5388df // indirect
3434
github.com/apapsch/go-jsonmerge/v2 v2.0.0 // indirect
3535
github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d // indirect
36+
github.com/authzed/authzed-go v0.10.1 // indirect
37+
github.com/authzed/grpcutil v0.0.0-20240123194739-2ea1e3d2d98b // indirect
3638
github.com/beorn7/perks v1.0.1 // indirect
3739
github.com/bytedance/sonic v1.10.0-rc3 // indirect
3840
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
41+
github.com/certifi/gocertifi v0.0.0-20210507211836-431795d63e8d // indirect
3942
github.com/cespare/xxhash/v2 v2.2.0 // indirect
4043
github.com/chenzhuoyu/base64x v0.0.0-20230717121745-296ad89f973d // indirect
4144
github.com/chenzhuoyu/iasm v0.9.0 // indirect
4245
github.com/cristalhq/jwt/v4 v4.0.2 // indirect
4346
github.com/dave/jennifer v1.4.0 // indirect
44-
github.com/davecgh/go-spew v1.1.1 // indirect
47+
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
4548
github.com/dgraph-io/ristretto v0.1.1 // indirect
4649
github.com/dustin/go-humanize v1.0.1 // indirect
4750
github.com/ecordell/optgen v0.0.6 // indirect
51+
github.com/envoyproxy/protoc-gen-validate v1.0.2 // indirect
4852
github.com/felixge/httpsnoop v1.0.3 // indirect
49-
github.com/fsnotify/fsnotify v1.6.0 // indirect
53+
github.com/fsnotify/fsnotify v1.7.0 // indirect
5054
github.com/gabriel-vasile/mimetype v1.4.2 // indirect
5155
github.com/gin-contrib/sse v0.1.0 // indirect
5256
github.com/gin-gonic/gin v1.9.1 // indirect
@@ -62,13 +66,14 @@ require (
6266
github.com/gofrs/flock v0.8.1 // indirect
6367
github.com/golang-jwt/jwt v3.2.2+incompatible // indirect
6468
github.com/golang-jwt/jwt/v5 v5.0.0 // indirect
65-
github.com/golang/glog v1.1.0 // indirect
69+
github.com/golang/glog v1.1.2 // indirect
6670
github.com/golang/mock v1.6.0 // indirect
6771
github.com/golang/protobuf v1.5.3 // indirect
68-
github.com/google/uuid v1.3.1 // indirect
72+
github.com/google/uuid v1.4.0 // indirect
6973
github.com/gorilla/mux v1.8.0 // indirect
7074
github.com/gorilla/websocket v1.5.0 // indirect
71-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.14.0 // indirect
75+
github.com/grpc-ecosystem/go-grpc-middleware v1.4.0 // indirect
76+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.18.0 // indirect
7277
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
7378
github.com/hashicorp/go-retryablehttp v0.7.1 // indirect
7479
github.com/hashicorp/hcl v1.0.0 // indirect
@@ -85,42 +90,52 @@ require (
8590
github.com/jaevor/go-nanoid v1.3.0 // indirect
8691
github.com/josharian/intern v1.0.0 // indirect
8792
github.com/json-iterator/go v1.1.12 // indirect
93+
github.com/jzelinskie/stringz v0.0.2 // indirect
94+
github.com/klauspost/compress v1.17.2 // indirect
8895
github.com/klauspost/cpuid/v2 v2.2.5 // indirect
8996
github.com/labstack/echo-contrib v0.15.0 // indirect
90-
github.com/labstack/gommon v0.4.0 // indirect
97+
github.com/labstack/gommon v0.4.2 // indirect
9198
github.com/leodido/go-urn v1.2.4 // indirect
9299
github.com/lib/pq v1.10.9 // indirect
93100
github.com/magiconair/properties v1.8.7 // indirect
94101
github.com/mailru/easyjson v0.7.7 // indirect
95102
github.com/mattn/go-colorable v0.1.13 // indirect
96-
github.com/mattn/go-isatty v0.0.19 // indirect
103+
github.com/mattn/go-isatty v0.0.20 // indirect
97104
github.com/mattn/goveralls v0.0.6 // indirect
98105
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
99106
github.com/mitchellh/mapstructure v1.5.0 // indirect
100107
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
101108
github.com/modern-go/reflect2 v1.0.2 // indirect
102109
github.com/mohae/deepcopy v0.0.0-20170929034955-c48cc78d4826 // indirect
110+
github.com/nats-io/nats.go v1.31.0 // indirect
111+
github.com/nats-io/nkeys v0.4.6 // indirect
112+
github.com/nats-io/nuid v1.0.1 // indirect
103113
github.com/ory/go-acc v0.2.9-0.20230103102148-6b1c9a70dbbe // indirect
104114
github.com/ory/go-convenience v0.1.0 // indirect
105115
github.com/pborman/uuid v1.2.1 // indirect
106-
github.com/pelletier/go-toml/v2 v2.0.9 // indirect
116+
github.com/pelletier/go-toml/v2 v2.1.0 // indirect
107117
github.com/perimeterx/marshmallow v1.1.5 // indirect
108118
github.com/pkg/errors v0.9.1 // indirect
109-
github.com/pmezard/go-difflib v1.0.0 // indirect
119+
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
110120
github.com/prometheus/client_golang v1.15.0 // indirect
111121
github.com/prometheus/client_model v0.3.0 // indirect
112122
github.com/prometheus/common v0.42.0 // indirect
113123
github.com/prometheus/procfs v0.11.0 // indirect
114-
github.com/spf13/afero v1.9.5 // indirect
115-
github.com/spf13/cast v1.5.1 // indirect
124+
github.com/sagikazarmark/locafero v0.4.0 // indirect
125+
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
126+
github.com/sourcegraph/conc v0.3.0 // indirect
127+
github.com/spf13/afero v1.11.0 // indirect
128+
github.com/spf13/cast v1.6.0 // indirect
116129
github.com/spf13/jwalterweatherman v1.1.0 // indirect
117130
github.com/stoewer/go-strcase v1.2.0 // indirect
118-
github.com/subosito/gotenv v1.4.2 // indirect
131+
github.com/subosito/gotenv v1.6.0 // indirect
119132
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
120133
github.com/ugorji/go/codec v1.2.11 // indirect
121134
github.com/valyala/bytebufferpool v1.0.0 // indirect
122135
github.com/valyala/fasttemplate v1.2.2 // indirect
136+
go.infratographer.com/permissions-api v0.3.2 // indirect
123137
go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho v0.42.0 // indirect
138+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.42.0 // indirect
124139
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.42.0 // indirect
125140
go.opentelemetry.io/otel/exporters/jaeger v1.16.0 // indirect
126141
go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.16.0 // indirect
@@ -131,20 +146,20 @@ require (
131146
go.opentelemetry.io/otel/metric v1.16.0 // indirect
132147
go.opentelemetry.io/otel/sdk v1.16.0 // indirect
133148
go.opentelemetry.io/proto/otlp v0.19.0 // indirect
134-
go.uber.org/multierr v1.10.0 // indirect
149+
go.uber.org/multierr v1.11.0 // indirect
135150
golang.org/x/arch v0.4.0 // indirect
136-
golang.org/x/crypto v0.12.0 // indirect
137-
golang.org/x/exp v0.0.0-20230817173708-d852ddb80c63 // indirect
151+
golang.org/x/crypto v0.17.0 // indirect
152+
golang.org/x/exp v0.0.0-20230905200255-921286631fa9 // indirect
138153
golang.org/x/mod v0.12.0 // indirect
139-
golang.org/x/net v0.14.0 // indirect
140-
golang.org/x/oauth2 v0.10.0 // indirect
141-
golang.org/x/sys v0.11.0 // indirect
142-
golang.org/x/text v0.12.0 // indirect
143-
golang.org/x/time v0.3.0 // indirect
144-
golang.org/x/tools v0.12.1-0.20230815132531-74c255bcf846 // indirect
145-
google.golang.org/appengine v1.6.7 // indirect
146-
google.golang.org/genproto v0.0.0-20230803162519-f966b187b2e5 // indirect
147-
google.golang.org/genproto/googleapis/rpc v0.0.0-20230803162519-f966b187b2e5 // indirect
148-
google.golang.org/grpc v1.57.0 // indirect
154+
golang.org/x/net v0.19.0 // indirect
155+
golang.org/x/oauth2 v0.15.0 // indirect
156+
golang.org/x/sys v0.15.0 // indirect
157+
golang.org/x/text v0.14.0 // indirect
158+
golang.org/x/time v0.5.0 // indirect
159+
golang.org/x/tools v0.13.0 // indirect
160+
google.golang.org/appengine v1.6.8 // indirect
161+
google.golang.org/genproto v0.0.0-20231106174013-bbf56f31fb17 // indirect
162+
google.golang.org/genproto/googleapis/rpc v0.0.0-20231120223509-83a465c0220f // indirect
163+
google.golang.org/grpc v1.60.1 // indirect
149164
gopkg.in/ini.v1 v1.67.0 // indirect
150165
)

0 commit comments

Comments
 (0)