mirror of
https://github.com/openziti/ziti.git
synced 2026-09-18 08:35:24 +00:00
623681db87
- as updates to API Sessions can now happen later than the last time they were active, updatedAt is no longer the correct representation of the last activity an API Session had - move all logic that used updatedAt to lastActivityAt - add migration to set lastActivityAt
84 lines
2.4 KiB
Go
84 lines
2.4 KiB
Go
/*
|
|
Copyright NetFoundry, Inc.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
https://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package persistence
|
|
|
|
import (
|
|
"fmt"
|
|
"github.com/openziti/foundation/storage/boltz"
|
|
"github.com/openziti/foundation/util/errorz"
|
|
"github.com/openziti/foundation/util/stringz"
|
|
"github.com/pkg/errors"
|
|
"strings"
|
|
)
|
|
|
|
const (
|
|
RolePrefix = "#"
|
|
EntityPrefix = "@"
|
|
AllRole = "#all"
|
|
)
|
|
|
|
func validateRolesAndIds(field string, values []string) error {
|
|
if len(values) > 1 && stringz.Contains(values, AllRole) {
|
|
return errorz.NewFieldError(fmt.Sprintf("if using %v, it should be the only role specified", AllRole), field, values)
|
|
}
|
|
|
|
var invalidKeys []string
|
|
for _, entry := range values {
|
|
if !strings.HasPrefix(entry, RolePrefix) && !strings.HasPrefix(entry, EntityPrefix) {
|
|
invalidKeys = append(invalidKeys, entry)
|
|
}
|
|
}
|
|
if len(invalidKeys) > 0 {
|
|
return errorz.NewFieldError("role entries must prefixed with # (to indicate role attributes) or @ (to indicate a name or id)", field, invalidKeys)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func splitRolesAndIds(values []string) ([]string, []string, error) {
|
|
var roles []string
|
|
var ids []string
|
|
for _, entry := range values {
|
|
if strings.HasPrefix(entry, RolePrefix) {
|
|
entry = strings.TrimPrefix(entry, RolePrefix)
|
|
roles = append(roles, entry)
|
|
} else if strings.HasPrefix(entry, EntityPrefix) {
|
|
entry = strings.TrimPrefix(entry, EntityPrefix)
|
|
ids = append(ids, entry)
|
|
} else {
|
|
return nil, nil, errors.Errorf("'%v' is neither role attribute (prefixed with %v) or an entity id or name (prefixed with %v)",
|
|
entry, RolePrefix, EntityPrefix)
|
|
}
|
|
}
|
|
return roles, ids, nil
|
|
}
|
|
|
|
func FieldValuesToIds(new []boltz.FieldTypeAndValue) []string {
|
|
var entityRoles []string
|
|
for _, fv := range new {
|
|
entityRoles = append(entityRoles, string(fv.Value))
|
|
}
|
|
return entityRoles
|
|
}
|
|
|
|
func roleRef(val string) string {
|
|
return RolePrefix + val
|
|
}
|
|
|
|
func entityRef(val string) string {
|
|
return EntityPrefix + val
|
|
}
|