mirror of
https://github.com/openziti/ziti.git
synced 2026-09-10 08:45:41 +00:00
25dda7f994
fixes #3437 adds error response for token update if API Session IDs do not match - updates all token updates to add structured errors - added an upfront API Session ID check on token updates in order to provide an error adds fix for #3444 ensure api session types are checked to avoid nil ref Identities may have mixed authentication modes if the credentials are being shared. While not recommended, it is possible. This can cause situations where API Session are not of a uniform type. During token updates for OIDC, legacy API Sessions must be ignored. - ignores legacy API Sessions during token update for a specific identity - adds error messages for unlikely scenarios that indicate systemic failures
141 lines
3.1 KiB
Go
141 lines
3.1 KiB
Go
/*
|
|
Copyright NetFoundry Inc.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
https://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package handler_edge_ctrl
|
|
|
|
import "github.com/openziti/sdk-golang/ziti/edge"
|
|
|
|
type controllerError interface {
|
|
error
|
|
ErrorCode() uint32
|
|
}
|
|
|
|
func internalError(err error) controllerError {
|
|
if err == nil {
|
|
return nil
|
|
}
|
|
return internalErrorWrapper{error: err}
|
|
}
|
|
|
|
type internalErrorWrapper struct {
|
|
error
|
|
}
|
|
|
|
func (internalErrorWrapper) ErrorCode() uint32 {
|
|
return edge.ErrorCodeInternal
|
|
}
|
|
|
|
type InvalidApiSessionError struct{}
|
|
|
|
func (InvalidApiSessionError) Error() string {
|
|
return "invalid api session"
|
|
}
|
|
|
|
func (self InvalidApiSessionError) ErrorCode() uint32 {
|
|
return edge.ErrorCodeInvalidApiSession
|
|
}
|
|
|
|
type InvalidSessionError struct{}
|
|
|
|
func (InvalidSessionError) Error() string {
|
|
return "invalid session"
|
|
}
|
|
|
|
func (self InvalidSessionError) ErrorCode() uint32 {
|
|
return edge.ErrorCodeInvalidSession
|
|
}
|
|
|
|
type WrongSessionTypeError struct{}
|
|
|
|
func (WrongSessionTypeError) Error() string {
|
|
return "incorrect session type"
|
|
}
|
|
|
|
func (self WrongSessionTypeError) ErrorCode() uint32 {
|
|
return edge.ErrorCodeWrongSessionType
|
|
}
|
|
|
|
type InvalidEdgeRouterForSessionError struct{}
|
|
|
|
func (InvalidEdgeRouterForSessionError) Error() string {
|
|
return "invalid edge router for session"
|
|
}
|
|
|
|
func (self InvalidEdgeRouterForSessionError) ErrorCode() uint32 {
|
|
return edge.ErrorCodeInvalidEdgeRouterForSession
|
|
}
|
|
|
|
type InvalidServiceError struct{}
|
|
|
|
func (InvalidServiceError) Error() string {
|
|
return "invalid service"
|
|
}
|
|
|
|
func (self InvalidServiceError) ErrorCode() uint32 {
|
|
return edge.ErrorCodeInvalidService
|
|
}
|
|
|
|
type TunnelingNotEnabledError struct{}
|
|
|
|
func (TunnelingNotEnabledError) Error() string {
|
|
return "tunneling not enabled"
|
|
}
|
|
|
|
func (self TunnelingNotEnabledError) ErrorCode() uint32 {
|
|
return edge.ErrorCodeTunnelingNotEnabled
|
|
}
|
|
|
|
func invalidTerminator(msg string) controllerError {
|
|
return &genericControllerError{
|
|
msg: msg,
|
|
errorCode: edge.ErrorCodeInvalidTerminator,
|
|
}
|
|
}
|
|
|
|
func invalidCost(msg string) controllerError {
|
|
return &genericControllerError{
|
|
msg: msg,
|
|
errorCode: edge.ErrorCodeInvalidCost,
|
|
}
|
|
}
|
|
|
|
func invalidPrecedence(msg string) controllerError {
|
|
return &genericControllerError{
|
|
msg: msg,
|
|
errorCode: edge.ErrorCodeInvalidPrecedence,
|
|
}
|
|
}
|
|
|
|
func encryptionDataMissing(msg string) controllerError {
|
|
return &genericControllerError{
|
|
msg: msg,
|
|
errorCode: edge.ErrorCodeEncryptionDataMissing,
|
|
}
|
|
}
|
|
|
|
type genericControllerError struct {
|
|
msg string
|
|
errorCode uint32
|
|
}
|
|
|
|
func (self *genericControllerError) Error() string {
|
|
return self.msg
|
|
}
|
|
|
|
func (self *genericControllerError) ErrorCode() uint32 {
|
|
return self.errorCode
|
|
}
|