[MM-63421] add openID Authorization API-compliant PDP interface (#30462)

Этот коммит содержится в:
Ibrahim Serdar Acikgoz
2025-04-02 11:04:27 +02:00
коммит произвёл GitHub
родитель f8e16780ef
Коммит 3eb854c58d
5 изменённых файлов: 133 добавлений и 0 удалений

Просмотреть файл

@@ -37,3 +37,9 @@ var metricsInterfaceFn func(*PlatformService, string, string) einterfaces.Metric
func RegisterMetricsInterface(f func(*PlatformService, string, string) einterfaces.MetricsInterface) {
metricsInterfaceFn = f
}
var pdpInterface func(*PlatformService) einterfaces.PolicyDecisionPointInterface
func RegisterPdpInterface(f func(*PlatformService) einterfaces.PolicyDecisionPointInterface) {
pdpInterface = f
}

Просмотреть файл

@@ -111,6 +111,8 @@ type PlatformService struct {
// This is a test mode setting used to enable Redis
// without a license.
forceEnableRedis bool
pdpService einterfaces.PolicyDecisionPointInterface
}
type HookRunner interface {
@@ -474,6 +476,10 @@ func (ps *PlatformService) initEnterprise() {
if licenseInterface != nil {
ps.licenseManager = licenseInterface(ps)
}
if pdpInterface != nil {
ps.pdpService = pdpInterface(ps)
}
}
func (ps *PlatformService) TotalWebsocketConnections() int {

Просмотреть файл

@@ -0,0 +1,62 @@
// Code generated by mockery v2.42.2. DO NOT EDIT.
// Regenerate this file using `make einterfaces-mocks`.
package mocks
import (
model "github.com/mattermost/mattermost/server/public/model"
request "github.com/mattermost/mattermost/server/public/shared/request"
mock "github.com/stretchr/testify/mock"
)
// PolicyDecisionPointInterface is an autogenerated mock type for the PolicyDecisionPointInterface type
type PolicyDecisionPointInterface struct {
mock.Mock
}
// AccessEvaluation provides a mock function with given fields: rctx, accessRequest
func (_m *PolicyDecisionPointInterface) AccessEvaluation(rctx request.CTX, accessRequest model.AccessRequest) (*model.AccessDecision, *model.AppError) {
ret := _m.Called(rctx, accessRequest)
if len(ret) == 0 {
panic("no return value specified for AccessEvaluation")
}
var r0 *model.AccessDecision
var r1 *model.AppError
if rf, ok := ret.Get(0).(func(request.CTX, model.AccessRequest) (*model.AccessDecision, *model.AppError)); ok {
return rf(rctx, accessRequest)
}
if rf, ok := ret.Get(0).(func(request.CTX, model.AccessRequest) *model.AccessDecision); ok {
r0 = rf(rctx, accessRequest)
} else {
if ret.Get(0) != nil {
r0 = ret.Get(0).(*model.AccessDecision)
}
}
if rf, ok := ret.Get(1).(func(request.CTX, model.AccessRequest) *model.AppError); ok {
r1 = rf(rctx, accessRequest)
} else {
if ret.Get(1) != nil {
r1 = ret.Get(1).(*model.AppError)
}
}
return r0, r1
}
// NewPolicyDecisionPointInterface creates a new instance of PolicyDecisionPointInterface. It also registers a testing interface on the mock and a cleanup function to assert the mocks expectations.
// The first argument is typically a *testing.T value.
func NewPolicyDecisionPointInterface(t interface {
mock.TestingT
Cleanup(func())
}) *PolicyDecisionPointInterface {
mock := &PolicyDecisionPointInterface{}
mock.Mock.Test(t)
t.Cleanup(func() { mock.AssertExpectations(t) })
return mock
}

16
server/einterfaces/pdp.go Обычный файл
Просмотреть файл

@@ -0,0 +1,16 @@
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
package einterfaces
import (
"github.com/mattermost/mattermost/server/public/model"
"github.com/mattermost/mattermost/server/public/shared/request"
)
// PolicyDecisionPointInterface is the service that evaluates access requests
// using the OpenID Auth API spec. It determines whether a subject can perform
// an action on a resource based on the resource policy.
type PolicyDecisionPointInterface interface {
AccessEvaluation(rctx request.CTX, accessRequest model.AccessRequest) (*model.AccessDecision, *model.AppError)
}

43
server/public/model/access_request.go Обычный файл
Просмотреть файл

@@ -0,0 +1,43 @@
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
package model
// Subject represents the user or a virtual entity for which the Authorization
// API is called.
type Subject struct {
// ID is the unique identifier of the Subject.
// it can be a user ID, bot ID, etc and it is scoped to the Type.
ID string `json:"id"`
// Type specifies the type of the Subject, eg. user, bot, etc.
Type string `json:"type"`
// Properties are the key-value pairs assicuated with the subject.
// An attribute may be single-valued or multi-valued and can be a primitive type
// (string, boolean, number) or a complex type like a JSON object or array.
Properties map[string]any `json:"properties"`
}
// Resource is the target of an access request.
type Resource struct {
// ID is the unique identifier of the Resource.
// It can be a channel ID, post ID, etc and it is scoped to the Type.
ID string `json:"id"`
// Type specifies the type of the Resource, eg. channel, post, etc.
Type string `json:"type"`
}
// AccessRequest represents the input to the Policy Decision Point (PDP).
// It contains the Subject, Resource, Action and optional Context attributes.
type AccessRequest struct {
Subject Subject `json:"subject"`
Resource Resource `json:"resource"`
Action string `json:"action"`
Context map[string]any `json:"context,omitempty"`
}
// The PDP evaluates the request and returns an AccessDecision.
// The Decision field is a boolean indicating whether the request is allowed or not.
type AccessDecision struct {
Decision bool `json:"decision"`
Context map[string]any `json:"context,omitempty"`
}