2019-11-16 20:48:24 +02:00
|
|
|
package wrapper
|
2015-12-21 01:50:16 +02:00
|
|
|
|
|
|
|
import (
|
2018-03-03 13:53:52 +02:00
|
|
|
"context"
|
2020-02-07 22:58:03 +02:00
|
|
|
"strings"
|
2018-03-03 13:53:52 +02:00
|
|
|
|
2020-02-10 10:26:28 +02:00
|
|
|
"github.com/micro/go-micro/v2/auth"
|
2020-01-30 13:39:00 +02:00
|
|
|
"github.com/micro/go-micro/v2/client"
|
|
|
|
"github.com/micro/go-micro/v2/debug/stats"
|
|
|
|
"github.com/micro/go-micro/v2/debug/trace"
|
2020-02-10 10:26:28 +02:00
|
|
|
"github.com/micro/go-micro/v2/errors"
|
2020-01-30 13:39:00 +02:00
|
|
|
"github.com/micro/go-micro/v2/metadata"
|
|
|
|
"github.com/micro/go-micro/v2/server"
|
2015-12-21 01:50:16 +02:00
|
|
|
)
|
|
|
|
|
2015-12-23 02:02:42 +02:00
|
|
|
type clientWrapper struct {
|
2015-12-21 01:50:16 +02:00
|
|
|
client.Client
|
2020-02-26 00:15:44 +02:00
|
|
|
|
|
|
|
// Auth interface
|
|
|
|
auth func() auth.Auth
|
|
|
|
// headers to inject
|
2016-01-28 19:55:28 +02:00
|
|
|
headers metadata.Metadata
|
2015-12-21 01:50:16 +02:00
|
|
|
}
|
|
|
|
|
2020-01-24 23:58:29 +02:00
|
|
|
type traceWrapper struct {
|
|
|
|
client.Client
|
|
|
|
|
|
|
|
name string
|
2020-01-29 17:45:11 +02:00
|
|
|
trace trace.Tracer
|
2020-01-24 23:58:29 +02:00
|
|
|
}
|
|
|
|
|
2019-11-16 20:48:24 +02:00
|
|
|
var (
|
|
|
|
HeaderPrefix = "Micro-"
|
|
|
|
)
|
|
|
|
|
2016-04-15 17:45:59 +02:00
|
|
|
func (c *clientWrapper) setHeaders(ctx context.Context) context.Context {
|
2020-04-08 11:50:19 +02:00
|
|
|
// don't overwrite keys
|
|
|
|
return metadata.MergeContext(ctx, c.headers, false)
|
2016-04-15 17:45:59 +02:00
|
|
|
}
|
|
|
|
|
2015-12-23 02:02:42 +02:00
|
|
|
func (c *clientWrapper) Call(ctx context.Context, req client.Request, rsp interface{}, opts ...client.CallOption) error {
|
2016-04-15 17:45:59 +02:00
|
|
|
ctx = c.setHeaders(ctx)
|
2015-12-21 01:50:16 +02:00
|
|
|
return c.Client.Call(ctx, req, rsp, opts...)
|
|
|
|
}
|
|
|
|
|
2018-04-14 19:15:09 +02:00
|
|
|
func (c *clientWrapper) Stream(ctx context.Context, req client.Request, opts ...client.CallOption) (client.Stream, error) {
|
2016-04-15 17:45:59 +02:00
|
|
|
ctx = c.setHeaders(ctx)
|
2015-12-21 01:50:16 +02:00
|
|
|
return c.Client.Stream(ctx, req, opts...)
|
|
|
|
}
|
|
|
|
|
2018-04-14 19:15:09 +02:00
|
|
|
func (c *clientWrapper) Publish(ctx context.Context, p client.Message, opts ...client.PublishOption) error {
|
2016-04-15 17:45:59 +02:00
|
|
|
ctx = c.setHeaders(ctx)
|
2015-12-21 01:50:16 +02:00
|
|
|
return c.Client.Publish(ctx, p, opts...)
|
|
|
|
}
|
2019-11-16 20:48:24 +02:00
|
|
|
|
2020-01-24 23:58:29 +02:00
|
|
|
func (c *traceWrapper) Call(ctx context.Context, req client.Request, rsp interface{}, opts ...client.CallOption) error {
|
|
|
|
newCtx, s := c.trace.Start(ctx, req.Service()+"."+req.Endpoint())
|
|
|
|
|
2020-02-12 12:57:17 +02:00
|
|
|
s.Type = trace.SpanTypeRequestOutbound
|
2020-01-24 23:58:29 +02:00
|
|
|
err := c.Client.Call(newCtx, req, rsp, opts...)
|
|
|
|
if err != nil {
|
|
|
|
s.Metadata["error"] = err.Error()
|
|
|
|
}
|
|
|
|
|
|
|
|
// finish the trace
|
|
|
|
c.trace.Finish(s)
|
|
|
|
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-02-26 00:15:44 +02:00
|
|
|
// FromService wraps a client to inject service and auth metadata
|
|
|
|
func FromService(name string, c client.Client, fn func() auth.Auth) client.Client {
|
2019-11-16 20:48:24 +02:00
|
|
|
return &clientWrapper{
|
2019-11-16 20:52:27 +02:00
|
|
|
c,
|
2020-02-26 00:15:44 +02:00
|
|
|
fn,
|
2019-11-16 20:52:27 +02:00
|
|
|
metadata.Metadata{
|
|
|
|
HeaderPrefix + "From-Service": name,
|
|
|
|
},
|
|
|
|
}
|
2019-11-16 20:48:24 +02:00
|
|
|
}
|
2019-12-18 20:36:42 +02:00
|
|
|
|
|
|
|
// HandlerStats wraps a server handler to generate request/error stats
|
|
|
|
func HandlerStats(stats stats.Stats) server.HandlerWrapper {
|
|
|
|
// return a handler wrapper
|
|
|
|
return func(h server.HandlerFunc) server.HandlerFunc {
|
|
|
|
// return a function that returns a function
|
|
|
|
return func(ctx context.Context, req server.Request, rsp interface{}) error {
|
|
|
|
// execute the handler
|
|
|
|
err := h(ctx, req, rsp)
|
|
|
|
// record the stats
|
|
|
|
stats.Record(err)
|
|
|
|
// return the error
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2020-01-24 23:58:29 +02:00
|
|
|
|
|
|
|
// TraceCall is a call tracing wrapper
|
2020-01-29 17:45:11 +02:00
|
|
|
func TraceCall(name string, t trace.Tracer, c client.Client) client.Client {
|
2020-01-24 23:58:29 +02:00
|
|
|
return &traceWrapper{
|
|
|
|
name: name,
|
|
|
|
trace: t,
|
|
|
|
Client: c,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// TraceHandler wraps a server handler to perform tracing
|
2020-01-29 17:45:11 +02:00
|
|
|
func TraceHandler(t trace.Tracer) server.HandlerWrapper {
|
2020-01-24 23:58:29 +02:00
|
|
|
// return a handler wrapper
|
|
|
|
return func(h server.HandlerFunc) server.HandlerFunc {
|
|
|
|
// return a function that returns a function
|
|
|
|
return func(ctx context.Context, req server.Request, rsp interface{}) error {
|
2020-02-07 22:58:03 +02:00
|
|
|
// don't store traces for debug
|
|
|
|
if strings.HasPrefix(req.Endpoint(), "Debug.") {
|
|
|
|
return h(ctx, req, rsp)
|
|
|
|
}
|
|
|
|
|
2020-01-24 23:58:29 +02:00
|
|
|
// get the span
|
|
|
|
newCtx, s := t.Start(ctx, req.Service()+"."+req.Endpoint())
|
2020-02-12 12:57:17 +02:00
|
|
|
s.Type = trace.SpanTypeRequestInbound
|
2020-01-24 23:58:29 +02:00
|
|
|
|
|
|
|
err := h(newCtx, req, rsp)
|
|
|
|
if err != nil {
|
|
|
|
s.Metadata["error"] = err.Error()
|
|
|
|
}
|
|
|
|
|
|
|
|
// finish
|
|
|
|
t.Finish(s)
|
|
|
|
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2020-02-10 10:26:28 +02:00
|
|
|
|
|
|
|
// AuthHandler wraps a server handler to perform auth
|
2020-03-25 22:59:37 +02:00
|
|
|
func AuthHandler(fn func() auth.Auth) server.HandlerWrapper {
|
2020-02-10 10:26:28 +02:00
|
|
|
return func(h server.HandlerFunc) server.HandlerFunc {
|
|
|
|
return func(ctx context.Context, req server.Request, rsp interface{}) error {
|
|
|
|
// get the auth.Auth interface
|
|
|
|
a := fn()
|
|
|
|
|
2020-02-13 16:07:14 +02:00
|
|
|
// Check for debug endpoints which should be excluded from auth
|
|
|
|
if strings.HasPrefix(req.Endpoint(), "Debug.") {
|
|
|
|
return h(ctx, req, rsp)
|
2020-02-10 10:26:28 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Extract the token if present. Note: if noop is being used
|
|
|
|
// then the token can be blank without erroring
|
|
|
|
var token string
|
|
|
|
if header, ok := metadata.Get(ctx, "Authorization"); ok {
|
|
|
|
// Ensure the correct scheme is being used
|
2020-03-25 13:20:53 +02:00
|
|
|
if !strings.HasPrefix(header, auth.BearerScheme) {
|
2020-04-02 19:41:06 +02:00
|
|
|
return errors.Unauthorized(req.Service(), "invalid authorization header. expected Bearer schema")
|
2020-02-10 10:26:28 +02:00
|
|
|
}
|
|
|
|
|
2020-03-25 13:20:53 +02:00
|
|
|
token = header[len(auth.BearerScheme):]
|
2020-02-10 10:26:28 +02:00
|
|
|
}
|
|
|
|
|
2020-03-25 11:35:29 +02:00
|
|
|
// Inspect the token and get the account
|
2020-03-23 18:19:30 +02:00
|
|
|
account, err := a.Inspect(token)
|
|
|
|
if err != nil {
|
2020-04-14 10:14:07 +02:00
|
|
|
account = &auth.Account{Namespace: a.Options().Namespace}
|
2020-04-02 19:41:06 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// construct the resource
|
|
|
|
res := &auth.Resource{
|
2020-04-07 17:24:51 +02:00
|
|
|
Type: "service",
|
|
|
|
Name: req.Service(),
|
|
|
|
Endpoint: req.Endpoint(),
|
2020-03-25 11:35:29 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Verify the caller has access to the resource
|
2020-04-02 19:41:06 +02:00
|
|
|
err = a.Verify(account, res)
|
2020-03-25 12:31:33 +02:00
|
|
|
if err != nil && len(account.ID) > 0 {
|
2020-04-02 19:41:06 +02:00
|
|
|
return errors.Forbidden(req.Service(), "Forbidden call made to %v:%v by %v", req.Service(), req.Endpoint(), account.ID)
|
2020-03-25 12:31:33 +02:00
|
|
|
} else if err != nil {
|
2020-04-02 19:41:06 +02:00
|
|
|
return errors.Unauthorized(req.Service(), "Unauthorised call made to %v:%v", req.Service(), req.Endpoint())
|
2020-03-04 11:54:52 +02:00
|
|
|
}
|
|
|
|
|
2020-03-23 18:19:30 +02:00
|
|
|
// There is an account, set it in the context
|
|
|
|
ctx, err = auth.ContextWithAccount(ctx, account)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2020-02-10 10:26:28 +02:00
|
|
|
}
|
|
|
|
|
2020-03-04 11:54:52 +02:00
|
|
|
// The user is authorised, allow the call
|
2020-02-10 10:26:28 +02:00
|
|
|
return h(ctx, req, rsp)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|