mirror of
https://gitlab.com/fabinfra/fabaccess/bffh.git
synced 2024-11-22 14:57:56 +01:00
Make Users DB a global resource
This commit is contained in:
parent
4ff0abd161
commit
2e9c7fbc19
@ -1,34 +1,33 @@
|
|||||||
use std::sync::Arc;
|
use std::sync::Arc;
|
||||||
use crate::authorization::permissions::Permission;
|
use crate::authorization::permissions::Permission;
|
||||||
use crate::authorization::roles::Role;
|
use crate::authorization::roles::Role;
|
||||||
|
use crate::Users;
|
||||||
use crate::users::User;
|
use crate::users::User;
|
||||||
|
|
||||||
pub mod permissions;
|
pub mod permissions;
|
||||||
pub mod roles;
|
pub mod roles;
|
||||||
|
|
||||||
struct Inner {
|
struct Inner {
|
||||||
|
users: Users,
|
||||||
}
|
}
|
||||||
impl Inner {
|
impl Inner {
|
||||||
pub fn new() -> Self {
|
pub fn new(users: Users) -> Self {
|
||||||
Self {}
|
Self { users }
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Clone)]
|
#[derive(Clone)]
|
||||||
pub struct AuthorizationHandle {
|
pub struct AuthorizationHandle {
|
||||||
inner: Arc<Inner>,
|
users: Users,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl AuthorizationHandle {
|
impl AuthorizationHandle {
|
||||||
pub fn new() -> Self {
|
pub fn new(users: Users) -> Self {
|
||||||
Self {
|
Self { users }
|
||||||
inner: Arc::new(Inner::new())
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn get_user_roles(&self, uid: impl AsRef<str>) -> Option<impl IntoIterator<Item=Role>> {
|
pub fn get_user_roles(&self, uid: impl AsRef<str>) -> Option<impl IntoIterator<Item=Role>> {
|
||||||
unimplemented!();
|
let user = self.users.get_user(uid.as_ref())?;
|
||||||
Some([])
|
Some([])
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -94,15 +94,13 @@ impl Resource {
|
|||||||
}
|
}
|
||||||
|
|
||||||
fn set_state(&self, state: MachineState) {
|
fn set_state(&self, state: MachineState) {
|
||||||
|
self.inner.set_state(state)
|
||||||
}
|
}
|
||||||
|
|
||||||
fn set_status(&self, state: Status) {
|
fn set_status(&self, state: Status) {
|
||||||
unimplemented!()
|
let old = self.inner.get_state();
|
||||||
}
|
let new = MachineState { state, .. old };
|
||||||
|
self.set_state(new);
|
||||||
fn set_previous_user(&self, user: User) {
|
|
||||||
unimplemented!()
|
|
||||||
}
|
}
|
||||||
|
|
||||||
pub async fn try_update(&self, session: SessionHandle, new: Status) {
|
pub async fn try_update(&self, session: SessionHandle, new: Status) {
|
||||||
@ -168,7 +166,7 @@ impl Resource {
|
|||||||
}
|
}
|
||||||
|
|
||||||
pub async fn force_set(&self, new: Status) {
|
pub async fn force_set(&self, new: Status) {
|
||||||
unimplemented!()
|
self.set_status(new);
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn visible(&self, session: &SessionHandle) -> bool {
|
pub fn visible(&self, session: &SessionHandle) -> bool {
|
||||||
|
@ -14,20 +14,22 @@
|
|||||||
* along with this program. If not, see <https://www.gnu.org/licenses/>.
|
* along with this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use std::collections::HashMap;
|
use anyhow::Context;
|
||||||
|
use lmdb::Environment;
|
||||||
|
use once_cell::sync::OnceCell;
|
||||||
use rkyv::{Archive, Deserialize, Infallible, Serialize};
|
use rkyv::{Archive, Deserialize, Infallible, Serialize};
|
||||||
|
use std::collections::HashMap;
|
||||||
use std::ops::Deref;
|
use std::ops::Deref;
|
||||||
use std::path::Path;
|
use std::path::Path;
|
||||||
use std::sync::Arc;
|
use std::sync::Arc;
|
||||||
use anyhow::Context;
|
|
||||||
use lmdb::Environment;
|
|
||||||
|
|
||||||
pub mod db;
|
pub mod db;
|
||||||
|
|
||||||
pub use crate::authentication::db::PassDB;
|
pub use crate::authentication::db::PassDB;
|
||||||
use crate::authorization::roles::{Role, RoleIdentifier};
|
use crate::authorization::roles::{Role, RoleIdentifier};
|
||||||
use crate::UserDB;
|
use crate::db::LMDBorrow;
|
||||||
use crate::users::db::UserData;
|
use crate::users::db::UserData;
|
||||||
|
use crate::UserDB;
|
||||||
|
|
||||||
#[derive(
|
#[derive(
|
||||||
Clone,
|
Clone,
|
||||||
@ -53,28 +55,37 @@ impl User {
|
|||||||
pub fn get_username(&self) -> &str {
|
pub fn get_username(&self) -> &str {
|
||||||
self.id.as_str()
|
self.id.as_str()
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn get_roles(&self) -> impl IntoIterator<Item=Role> {
|
|
||||||
unimplemented!();
|
|
||||||
[]
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
pub struct Inner {
|
static USERDB: OnceCell<UserDB> = OnceCell::new();
|
||||||
userdb: UserDB,
|
|
||||||
//passdb: PassDB,
|
|
||||||
}
|
|
||||||
|
|
||||||
#[derive(Clone)]
|
#[derive(Copy, Clone)]
|
||||||
|
#[repr(transparent)]
|
||||||
pub struct Users {
|
pub struct Users {
|
||||||
inner: Arc<Inner>
|
userdb: &'static UserDB,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Users {
|
impl Users {
|
||||||
pub fn new(env: Arc<Environment>) -> anyhow::Result<Self> {
|
pub fn new(env: Arc<Environment>) -> anyhow::Result<Self> {
|
||||||
let userdb = unsafe { UserDB::create(env.clone()).unwrap() };
|
let span = tracing::debug_span!("users", ?env, "Creating Users handle");
|
||||||
//let passdb = unsafe { PassDB::create(env).unwrap() };
|
let _guard = span.enter();
|
||||||
Ok(Self { inner: Arc::new(Inner { userdb }) })
|
|
||||||
|
let userdb = USERDB
|
||||||
|
.get_or_try_init(|| {
|
||||||
|
tracing::debug!("Global resource not yet initialized, initializing…");
|
||||||
|
unsafe { UserDB::create(env.clone()) }
|
||||||
|
})
|
||||||
|
.context("Failed to open userdb")?;
|
||||||
|
|
||||||
|
Ok(Self { userdb })
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn get_user(&self, uid: &str) -> Option<db::User> {
|
||||||
|
tracing::trace!(uid, "Looking up user");
|
||||||
|
self.userdb
|
||||||
|
.get(uid)
|
||||||
|
.unwrap()
|
||||||
|
.map(|user| Deserialize::<db::User, _>::deserialize(user.deref(), &mut Infallible).unwrap())
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn load_file<P: AsRef<Path>>(&self, path: P) -> anyhow::Result<()> {
|
pub fn load_file<P: AsRef<Path>>(&self, path: P) -> anyhow::Result<()> {
|
||||||
@ -82,20 +93,25 @@ impl Users {
|
|||||||
let mut map: HashMap<String, UserData> = toml::from_slice(&f)?;
|
let mut map: HashMap<String, UserData> = toml::from_slice(&f)?;
|
||||||
|
|
||||||
for (uid, mut userdata) in map {
|
for (uid, mut userdata) in map {
|
||||||
userdata.passwd = userdata.passwd.map(|pw| if !pw.starts_with("$argon2") {
|
userdata.passwd = userdata.passwd.map(|pw| {
|
||||||
let config = argon2::Config::default();
|
if !pw.starts_with("$argon2") {
|
||||||
let salt: [u8; 16] = rand::random();
|
let config = argon2::Config::default();
|
||||||
let hash = argon2::hash_encoded(pw.as_bytes(), &salt, &config)
|
let salt: [u8; 16] = rand::random();
|
||||||
.expect(&format!("Failed to hash password for {}: ", uid));
|
let hash = argon2::hash_encoded(pw.as_bytes(), &salt, &config)
|
||||||
tracing::debug!("Hashed pw for {} to {}", uid, hash);
|
.expect(&format!("Failed to hash password for {}: ", uid));
|
||||||
|
tracing::debug!("Hashed pw for {} to {}", uid, hash);
|
||||||
|
|
||||||
hash
|
hash
|
||||||
} else {
|
} else {
|
||||||
pw
|
pw
|
||||||
|
}
|
||||||
});
|
});
|
||||||
let user = db::User { id: uid.clone(), userdata };
|
let user = db::User {
|
||||||
|
id: uid.clone(),
|
||||||
|
userdata,
|
||||||
|
};
|
||||||
tracing::trace!(%uid, ?user, "Storing user object");
|
tracing::trace!(%uid, ?user, "Storing user object");
|
||||||
self.inner.userdb.put(uid.as_str(), &user);
|
self.userdb.put(uid.as_str(), &user);
|
||||||
}
|
}
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
|
Loading…
Reference in New Issue
Block a user