Make Users DB a global resource

This commit is contained in:
Nadja Reitzenstein 2022-03-15 16:28:11 +01:00
parent 4ff0abd161
commit 2e9c7fbc19
3 changed files with 59 additions and 46 deletions

View File

@ -1,34 +1,33 @@
use std::sync::Arc; use std::sync::Arc;
use crate::authorization::permissions::Permission; use crate::authorization::permissions::Permission;
use crate::authorization::roles::Role; use crate::authorization::roles::Role;
use crate::Users;
use crate::users::User; use crate::users::User;
pub mod permissions; pub mod permissions;
pub mod roles; pub mod roles;
struct Inner { struct Inner {
users: Users,
} }
impl Inner { impl Inner {
pub fn new() -> Self { pub fn new(users: Users) -> Self {
Self {} Self { users }
} }
} }
#[derive(Clone)] #[derive(Clone)]
pub struct AuthorizationHandle { pub struct AuthorizationHandle {
inner: Arc<Inner>, users: Users,
} }
impl AuthorizationHandle { impl AuthorizationHandle {
pub fn new() -> Self { pub fn new(users: Users) -> Self {
Self { Self { users }
inner: Arc::new(Inner::new())
}
} }
pub fn get_user_roles(&self, uid: impl AsRef<str>) -> Option<impl IntoIterator<Item=Role>> { pub fn get_user_roles(&self, uid: impl AsRef<str>) -> Option<impl IntoIterator<Item=Role>> {
unimplemented!(); let user = self.users.get_user(uid.as_ref())?;
Some([]) Some([])
} }

View File

@ -94,15 +94,13 @@ impl Resource {
} }
fn set_state(&self, state: MachineState) { fn set_state(&self, state: MachineState) {
self.inner.set_state(state)
} }
fn set_status(&self, state: Status) { fn set_status(&self, state: Status) {
unimplemented!() let old = self.inner.get_state();
} let new = MachineState { state, .. old };
self.set_state(new);
fn set_previous_user(&self, user: User) {
unimplemented!()
} }
pub async fn try_update(&self, session: SessionHandle, new: Status) { pub async fn try_update(&self, session: SessionHandle, new: Status) {
@ -168,7 +166,7 @@ impl Resource {
} }
pub async fn force_set(&self, new: Status) { pub async fn force_set(&self, new: Status) {
unimplemented!() self.set_status(new);
} }
pub fn visible(&self, session: &SessionHandle) -> bool { pub fn visible(&self, session: &SessionHandle) -> bool {

View File

@ -14,20 +14,22 @@
* along with this program. If not, see <https://www.gnu.org/licenses/>. * along with this program. If not, see <https://www.gnu.org/licenses/>.
*/ */
use std::collections::HashMap; use anyhow::Context;
use lmdb::Environment;
use once_cell::sync::OnceCell;
use rkyv::{Archive, Deserialize, Infallible, Serialize}; use rkyv::{Archive, Deserialize, Infallible, Serialize};
use std::collections::HashMap;
use std::ops::Deref; use std::ops::Deref;
use std::path::Path; use std::path::Path;
use std::sync::Arc; use std::sync::Arc;
use anyhow::Context;
use lmdb::Environment;
pub mod db; pub mod db;
pub use crate::authentication::db::PassDB; pub use crate::authentication::db::PassDB;
use crate::authorization::roles::{Role, RoleIdentifier}; use crate::authorization::roles::{Role, RoleIdentifier};
use crate::UserDB; use crate::db::LMDBorrow;
use crate::users::db::UserData; use crate::users::db::UserData;
use crate::UserDB;
#[derive( #[derive(
Clone, Clone,
@ -53,28 +55,37 @@ impl User {
pub fn get_username(&self) -> &str { pub fn get_username(&self) -> &str {
self.id.as_str() self.id.as_str()
} }
pub fn get_roles(&self) -> impl IntoIterator<Item=Role> {
unimplemented!();
[]
}
} }
pub struct Inner { static USERDB: OnceCell<UserDB> = OnceCell::new();
userdb: UserDB,
//passdb: PassDB,
}
#[derive(Clone)] #[derive(Copy, Clone)]
#[repr(transparent)]
pub struct Users { pub struct Users {
inner: Arc<Inner> userdb: &'static UserDB,
} }
impl Users { impl Users {
pub fn new(env: Arc<Environment>) -> anyhow::Result<Self> { pub fn new(env: Arc<Environment>) -> anyhow::Result<Self> {
let userdb = unsafe { UserDB::create(env.clone()).unwrap() }; let span = tracing::debug_span!("users", ?env, "Creating Users handle");
//let passdb = unsafe { PassDB::create(env).unwrap() }; let _guard = span.enter();
Ok(Self { inner: Arc::new(Inner { userdb }) })
let userdb = USERDB
.get_or_try_init(|| {
tracing::debug!("Global resource not yet initialized, initializing…");
unsafe { UserDB::create(env.clone()) }
})
.context("Failed to open userdb")?;
Ok(Self { userdb })
}
pub fn get_user(&self, uid: &str) -> Option<db::User> {
tracing::trace!(uid, "Looking up user");
self.userdb
.get(uid)
.unwrap()
.map(|user| Deserialize::<db::User, _>::deserialize(user.deref(), &mut Infallible).unwrap())
} }
pub fn load_file<P: AsRef<Path>>(&self, path: P) -> anyhow::Result<()> { pub fn load_file<P: AsRef<Path>>(&self, path: P) -> anyhow::Result<()> {
@ -82,20 +93,25 @@ impl Users {
let mut map: HashMap<String, UserData> = toml::from_slice(&f)?; let mut map: HashMap<String, UserData> = toml::from_slice(&f)?;
for (uid, mut userdata) in map { for (uid, mut userdata) in map {
userdata.passwd = userdata.passwd.map(|pw| if !pw.starts_with("$argon2") { userdata.passwd = userdata.passwd.map(|pw| {
let config = argon2::Config::default(); if !pw.starts_with("$argon2") {
let salt: [u8; 16] = rand::random(); let config = argon2::Config::default();
let hash = argon2::hash_encoded(pw.as_bytes(), &salt, &config) let salt: [u8; 16] = rand::random();
.expect(&format!("Failed to hash password for {}: ", uid)); let hash = argon2::hash_encoded(pw.as_bytes(), &salt, &config)
tracing::debug!("Hashed pw for {} to {}", uid, hash); .expect(&format!("Failed to hash password for {}: ", uid));
tracing::debug!("Hashed pw for {} to {}", uid, hash);
hash hash
} else { } else {
pw pw
}
}); });
let user = db::User { id: uid.clone(), userdata }; let user = db::User {
id: uid.clone(),
userdata,
};
tracing::trace!(%uid, ?user, "Storing user object"); tracing::trace!(%uid, ?user, "Storing user object");
self.inner.userdb.put(uid.as_str(), &user); self.userdb.put(uid.as_str(), &user);
} }
Ok(()) Ok(())