Skip to content
Snippets Groups Projects
Select Git revision
  • e492790b5182cd46291ffd02cb17129eee2a46fb
  • master default protected
  • feature/PRXS-3383-CollectionsSort
  • refactor/PRXS-3053-Files
  • feature/PRXS-3143-3235-ReferenceOptions
  • feature/PRXS-3421-ImplementNewRefAPI
  • feature/PRXS-3143-LimitReferenceFields
  • feature/PRXS-3234-FeaturePruneIdents
  • feature/3149-LocaleCodeAsID-Feature
  • PRXS-3421-RecursiveReferences
  • feature/3109-SerializeFeature
  • release/0.33
  • feature/3109-RecoverySchema
  • feature/3109-feature
  • fix/PRXS-3369-ValidateFields
  • refactor/PRXS-3306-MovePkgGroup1
  • refactor/6-pkg-refactor-expr
  • fix/PRXS-3360-TemplateBuilderPatch
  • feature/3293-MongoV2
  • feature/3272-GoVersionUp
  • feature/PRXS-3218-HideTemplateActions
  • v0.33.1
  • v0.32.0
  • v0.31.1
  • v0.31.0
  • v0.30.0
  • v0.29.0
  • v0.28.0
  • v0.27.0-alpha.1+16
  • v0.27.0-alpha.1+15
  • v0.27.0-alpha.1+14
  • v0.27.0-alpha.1+13
  • v0.27.0-alpha.1+12
  • v0.27.0-alpha.1+11
  • v0.27.0-alpha.1+10
  • v0.27.0-alpha.1+9
  • v0.27.0-alpha.1+8
  • v0.27.0-alpha.1+7
  • v0.27.0-alpha.1+6
  • v0.27.0-alpha.1+5
  • v0.27.0-alpha.1+4
41 results

telemetry_middleware.go

Blame
  • auth.go 3.91 KiB
    package perxis
    
    import (
    	"context"
    	"runtime"
    	"strings"
    
    	"git.perx.ru/perxis/perxis-go/pkg/errors"
    )
    
    var (
    	ErrAccessDenied = errors.New("access denied")
    )
    
    type Principal interface {
    	GetID() string
    }
    
    // Authenticator интерфейс для аутентификации
    type Authenticator interface {
    	// Authenticate аутентификация
    	Authenticate(ctx context.Context) (Principal, error)
    }
    
    type Authorization struct {
    	Authorizer Authorizer
    }
    
    // Authorizer интерфейс для авторизации
    type Authorizer interface {
    	Authorize(principal Principal, action string, resource any) (*Authorization, error)
    }
    
    var (
    	authorizer    Authorizer
    	authenticator Authenticator
    )
    
    func SetAuthorizer(a Authorizer) {
    	authorizer = a
    }
    
    func SetAuthenticator(a Authenticator) {
    	authenticator = a
    }
    
    func Authenticate(ctx context.Context) (Principal, error) {
    	if authenticator == nil {
    		return nil, nil
    	}
    	return authenticator.Authenticate(ctx)
    }
    
    func Authorize(principal Principal, action string, resource any) (*Authorization, error) {
    	if authorizer == nil {
    		return nil, nil
    	}
    	return authorizer.Authorize(principal, action, resource)
    }
    
    func AuthorizeContext(ctx context.Context, action string, resource any) (*Authorization, error) {
    	principal, err := Authenticate(ctx)
    	if err != nil {
    		return nil, err
    	}
    	return Authorize(principal, action, resource)
    }
    
    func IsAllowed(ctx context.Context, res any) (*Authorization, error) {
    	pc, _, _, _ := runtime.Caller(1)