mirror of
https://github.com/openziti/ziti.git
synced 2026-10-08 22:01:15 +00:00
623681db87
- as updates to API Sessions can now happen later than the last time they were active, updatedAt is no longer the correct representation of the last activity an API Session had - move all logic that used updatedAt to lastActivityAt - add migration to set lastActivityAt
85 lines
2.3 KiB
Go
85 lines
2.3 KiB
Go
/*
|
|
Copyright NetFoundry, Inc.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
https://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package policy
|
|
|
|
import (
|
|
"fmt"
|
|
"github.com/michaelquigley/pfxlog"
|
|
"github.com/openziti/edge/controller/env"
|
|
"github.com/openziti/edge/runner"
|
|
"time"
|
|
)
|
|
|
|
const (
|
|
maxIterations = 1000
|
|
maxDeletePerIteration = 500
|
|
)
|
|
|
|
type ApiSessionEnforcer struct {
|
|
appEnv *env.AppEnv
|
|
sessionTimeout time.Duration
|
|
*runner.BaseOperation
|
|
}
|
|
|
|
func NewSessionEnforcer(appEnv *env.AppEnv, frequency time.Duration, sessionTimeout time.Duration) *ApiSessionEnforcer {
|
|
if sessionTimeout < 60*time.Second {
|
|
pfxlog.Logger().Panic("sessionTimeout can not be less than 60 seconds")
|
|
}
|
|
|
|
pfxlog.Logger().
|
|
WithField("sessionTimeout", sessionTimeout.String()).
|
|
WithField("frequency", frequency.String()).
|
|
Info("session enforcer configured")
|
|
|
|
return &ApiSessionEnforcer{
|
|
appEnv: appEnv,
|
|
sessionTimeout: sessionTimeout,
|
|
BaseOperation: runner.NewBaseOperation("ApiSessionEnforcer", frequency),
|
|
}
|
|
}
|
|
|
|
func (s *ApiSessionEnforcer) Run() error {
|
|
oldest := time.Now().Add(s.sessionTimeout * -1)
|
|
query := fmt.Sprintf("lastActivityAt < datetime(%s) limit %d", oldest.UTC().Format(time.RFC3339), maxDeletePerIteration)
|
|
|
|
for i := 0; i < maxIterations; i++ {
|
|
ids := make([]string, 0, maxDeletePerIteration)
|
|
err := s.appEnv.GetHandlers().ApiSession.StreamIds(query, func(id string, err error) error {
|
|
if lastActivityAt, hasUnflushedValue := s.appEnv.GetHandlers().ApiSession.HeartbeatCollector.LastAccessedAt(id); !hasUnflushedValue || lastActivityAt.Before(oldest) {
|
|
ids = append(ids, id)
|
|
}
|
|
|
|
return nil
|
|
})
|
|
|
|
if err != nil {
|
|
pfxlog.Logger().Errorf("encountered error querying for API sessions to remove: %v", err)
|
|
break
|
|
}
|
|
|
|
if len(ids) == 0 {
|
|
break
|
|
}
|
|
|
|
for _, id := range ids {
|
|
_ = s.appEnv.GetHandlers().ApiSession.Delete(id)
|
|
}
|
|
}
|
|
|
|
return nil
|
|
}
|