feat(auth): add local and OIDC management to tht
This commit is contained in:
@@ -50,6 +50,9 @@ type generatedDescriptor struct {
|
||||
Branch string `yaml:"branch"`
|
||||
Access string `yaml:"access"`
|
||||
} `yaml:"workspaceRepository"`
|
||||
Authentication struct {
|
||||
ConfigDirectory string `yaml:"configDirectory"`
|
||||
} `yaml:"authentication"`
|
||||
Overrides []string `yaml:"overrides"`
|
||||
}
|
||||
|
||||
@@ -74,6 +77,9 @@ func EnsureFiles(request Request, input io.Reader, output io.Writer) (FilesResul
|
||||
}
|
||||
descriptorPath := filepath.Join(directory, descriptorName)
|
||||
environmentPath := filepath.Join(directory, environmentName)
|
||||
if err := safeio.EnsurePrivateDirectory(filepath.Join(directory, "auth")); err != nil {
|
||||
return FilesResult{}, errors.New("authentication directory is unavailable or unsafe")
|
||||
}
|
||||
result := FilesResult{DescriptorPath: descriptorPath, EnvironmentPath: environmentPath}
|
||||
|
||||
descriptor, environment, err := render(root, descriptorPath, values)
|
||||
@@ -298,6 +304,7 @@ func installationDirectory(root, id string) (string, error) {
|
||||
func render(root, descriptorPath string, value answers) ([]byte, []byte, error) {
|
||||
descriptor := generatedDescriptor{Profile: value.profile, ProjectDirectory: root, EnvFile: filepath.Join(filepath.Dir(descriptorPath), environmentName)}
|
||||
descriptor.Workspace.Remote, descriptor.Workspace.Branch, descriptor.Workspace.Access = value.workspaceRemote, value.workspaceBranch, value.workspaceAccess
|
||||
descriptor.Authentication.ConfigDirectory = filepath.Join(filepath.Dir(descriptorPath), "auth")
|
||||
descriptor.Overrides = []string{filepath.Join(root, "deploy", "compose.git-"+value.workspaceAccess+".yaml")}
|
||||
descriptorBytes, err := yaml.Marshal(descriptor)
|
||||
if err != nil {
|
||||
@@ -308,6 +315,7 @@ func render(root, descriptorPath string, value answers) ([]byte, []byte, error)
|
||||
"THT_WORKSPACE_GIT_REMOTE=" + dotenvValue(value.workspaceRemote),
|
||||
"THT_WORKSPACE_GIT_BRANCH=" + dotenvValue(value.workspaceBranch),
|
||||
"THT_WORKSPACE_INSTALLATION_ID=" + dotenvValue(value.installationID),
|
||||
"THT_AUTH_CONFIG_ROOT=" + dotenvValue(descriptor.Authentication.ConfigDirectory),
|
||||
"THT_SECRETS_FILE=" + dotenvValue(value.secretsFile),
|
||||
"PI_AUTH_FILE=" + dotenvValue(value.piAuthFile),
|
||||
"THOTH_HTTP_PORT=8080", "THOTH_CORE_HTTP_PORT=8787", "MAX_PI_PROCESSES=4",
|
||||
|
||||
@@ -11,6 +11,7 @@ import (
|
||||
"testing"
|
||||
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/config"
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/safeio"
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/testsupport"
|
||||
)
|
||||
|
||||
@@ -48,6 +49,13 @@ func TestEnsureFilesCreatesDiscoverableConfigurationInProjectWithSpaces(t *testi
|
||||
t.Errorf("generated file %s has permissions %o, want owner-only", path, info.Mode().Perm())
|
||||
}
|
||||
}
|
||||
installation, err := config.Load(result.DescriptorPath)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := safeio.ValidatePrivateDirectory(installation.AuthenticationDirectory()); err != nil {
|
||||
t.Fatalf("authentication directory is not private: %v", err)
|
||||
}
|
||||
|
||||
descriptor, err := os.ReadFile(result.DescriptorPath)
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user