Files
paralus/server/cluster_authz.go
nirav-rafay c66bdc25cd restructure rcloud-base as a single base controller (#37)
* restructure rcloud-base as a single base controller
* updated master.rest
* moved sentry from internal to pkg as it is used by relay
* removing unused rpc and it's dependencies
* Fix usermgmt tests
* Don't redefine variables in rest file
Co-authored-by: Abin Simon <abin.simon@rafay.co>
2022-03-03 17:59:06 +05:30

43 lines
1.4 KiB
Go

package server
import (
"context"
sentryrpc "github.com/RafaySystems/rcloud-base/proto/rpc/sentry"
"github.com/RafaySystems/rcloud-base/pkg/sentry/authz"
"github.com/RafaySystems/rcloud-base/pkg/service"
)
type clusterAuthzServer struct {
bs service.BootstrapService
aps service.AccountPermissionService
gps service.GroupPermissionService
krs service.KubeconfigRevocationService
kcs service.KubectlClusterSettingsService
kss service.KubeconfigSettingService
//apn models.AccountProjectNamespaceService
}
// GetUserAuthorization return authorization profile of user for a given cluster
func (s *clusterAuthzServer) GetUserAuthorization(ctx context.Context, req *sentryrpc.GetUserAuthorizationRequest) (*sentryrpc.GetUserAuthorizationResponse, error) {
resp, err := authz.GetAuthorization(ctx, req, s.bs, s.aps, s.gps, s.krs, s.kcs, s.kss)
if err != nil {
_log.Errorw("error getting auth profile", "req", req, "error", err.Error())
return nil, err
}
return resp, nil
}
// NewClusterAuthzServer returns New ClusterAuthzServer
func NewClusterAuthzServer(bs service.BootstrapService, aps service.AccountPermissionService, gps service.GroupPermissionService, krs service.KubeconfigRevocationService, kcs service.KubectlClusterSettingsService, kss service.KubeconfigSettingService) sentryrpc.ClusterAuthorizationServer {
return &clusterAuthzServer{
bs: bs,
aps: aps,
gps: gps,
krs: krs,
kcs: kcs,
kss: kss,
}
}