feat(server): activate projected authentication safely
This commit is contained in:
@@ -19,6 +19,9 @@ import (
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/service"
|
||||
)
|
||||
|
||||
var publishProjectedCanonical = authconfig.PublishProjectedCanonical
|
||||
var requireRuntimeAuthProjectionReady = authconfig.RequireRuntimeAuthProjectionReady
|
||||
|
||||
// Result records the completed setup phases. DescriptorPath always identifies the descriptor
|
||||
// selected by this invocation, including an idempotent rerun.
|
||||
type Result struct {
|
||||
@@ -85,7 +88,7 @@ func Run(ctx context.Context, runner compose.Runner, request Request, input io.R
|
||||
func configureAuthentication(ctx context.Context, installation config.Installation, request Request, input io.Reader, output io.Writer) error {
|
||||
directory := installation.AuthenticationDirectory()
|
||||
if _, _, err := authconfig.Load(directory); err == nil {
|
||||
return nil
|
||||
return publishConfiguredAuthentication(ctx, installation)
|
||||
}
|
||||
if _, err := os.Lstat(filepath.Join(directory, "auth.yaml")); !errors.Is(err, os.ErrNotExist) {
|
||||
return errors.New("setup authentication configuration is invalid")
|
||||
@@ -100,6 +103,25 @@ func configureAuthentication(ctx context.Context, installation config.Installati
|
||||
if _, _, err := authconfig.Load(directory); err != nil {
|
||||
return errors.New("setup authentication configuration is invalid")
|
||||
}
|
||||
return publishConfiguredAuthentication(ctx, installation)
|
||||
}
|
||||
|
||||
func publishConfiguredAuthentication(ctx context.Context, installation config.Installation) error {
|
||||
projection := installation.RuntimeAuthProjection()
|
||||
if projection == nil {
|
||||
return nil
|
||||
}
|
||||
status, err := publishProjectedCanonical(ctx, installation.AuthenticationDirectory(), authconfig.ProjectionSpec{
|
||||
RuntimeRoot: projection.Directory,
|
||||
UID: projection.UID,
|
||||
GID: projection.GID,
|
||||
})
|
||||
if err != nil || status.State != "ready" || !status.Equal {
|
||||
return errors.New("setup authentication runtime projection could not be published")
|
||||
}
|
||||
if err := requireRuntimeAuthProjectionReady(installation); err != nil {
|
||||
return errors.New("setup authentication runtime projection could not be verified")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user