OLD | NEW |
1 // Copyright 2015 The Chromium Authors. All rights reserved. | 1 // Copyright 2015 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 package services | 5 package services |
6 | 6 |
7 import ( | 7 import ( |
8 "github.com/golang/protobuf/proto" | 8 "github.com/golang/protobuf/proto" |
9 "github.com/luci/luci-go/appengine/logdog/coordinator" | 9 "github.com/luci/luci-go/appengine/logdog/coordinator" |
10 "github.com/luci/luci-go/appengine/logdog/coordinator/endpoints" | 10 "github.com/luci/luci-go/appengine/logdog/coordinator/endpoints" |
11 "github.com/luci/luci-go/common/api/logdog_coordinator/services/v1" | 11 "github.com/luci/luci-go/common/api/logdog_coordinator/services/v1" |
12 "github.com/luci/luci-go/common/config" | 12 "github.com/luci/luci-go/common/config" |
13 "github.com/luci/luci-go/common/grpcutil" | 13 "github.com/luci/luci-go/common/grpcutil" |
14 log "github.com/luci/luci-go/common/logging" | 14 log "github.com/luci/luci-go/common/logging" |
15 "golang.org/x/net/context" | 15 "golang.org/x/net/context" |
16 ) | 16 ) |
17 | 17 |
18 // server is a Cloud Endpoint service supporting privileged support services. | 18 // server is a service supporting privileged support services. |
19 // | 19 // |
20 // This endpoint is restricted to LogDog support service accounts. | 20 // This endpoint is restricted to LogDog support service accounts. |
21 type server struct{} | 21 type server struct{} |
22 | 22 |
23 // New creates a new authenticating ServicesServer instance. | 23 // New creates a new authenticating ServicesServer instance. |
24 func New() logdog.ServicesServer { | 24 func New() logdog.ServicesServer { |
25 return &logdog.DecoratedServices{ | 25 return &logdog.DecoratedServices{ |
26 Service: &server{}, | 26 Service: &server{}, |
27 Prelude: func(c context.Context, methodName string, req proto.Me
ssage) (context.Context, error) { | 27 Prelude: func(c context.Context, methodName string, req proto.Me
ssage) (context.Context, error) { |
28 // Only service users may access this endpoint. | 28 // Only service users may access this endpoint. |
29 if err := coordinator.IsServiceUser(c); err != nil { | 29 if err := coordinator.IsServiceUser(c); err != nil { |
30 log.Fields{ | 30 log.Fields{ |
31 log.ErrorKey: err, | 31 log.ErrorKey: err, |
32 }.Errorf(c, "Failed to authenticate user as a se
rvice.") | 32 }.Errorf(c, "Failed to authenticate user as a se
rvice.") |
33 if !coordinator.IsMembershipError(err) { | 33 if !coordinator.IsMembershipError(err) { |
34 // Not a membership error. Something wen
t wrong on the server's end. | 34 // Not a membership error. Something wen
t wrong on the server's end. |
35 return nil, grpcutil.Internal | 35 return nil, grpcutil.Internal |
36 } | 36 } |
37 return nil, grpcutil.PermissionDenied | 37 return nil, grpcutil.PermissionDenied |
38 } | 38 } |
39 | 39 |
40 // Enter a datastore namespace based on the message type
. | 40 // Enter a datastore namespace based on the message type
. |
41 // | 41 // |
42 // We use a type switch here because this is a shared de
corator. | 42 // We use a type switch here because this is a shared de
corator. |
43 if pbm, ok := req.(endpoints.ProjectBoundMessage); ok { | 43 if pbm, ok := req.(endpoints.ProjectBoundMessage); ok { |
44 project := config.ProjectName(pbm.GetMessageProj
ect()) | 44 project := config.ProjectName(pbm.GetMessageProj
ect()) |
45 log.Fields{ | 45 log.Fields{ |
46 "project": project, | 46 "project": project, |
47 }.Debugf(c, "Request is entering project namespa
ce.") | 47 }.Debugf(c, "Request is entering project namespa
ce.") |
48 » » » » if err := coordinator.WithProjectNamespaceNoAuth
(&c, project); err != nil { | 48 » » » » if err := coordinator.WithProjectNamespace(&c, p
roject, coordinator.NamespaceAccessNoAuth); err != nil { |
49 return nil, grpcutil.Internal | 49 return nil, grpcutil.Internal |
50 } | 50 } |
51 } | 51 } |
52 | 52 |
53 return c, nil | 53 return c, nil |
54 }, | 54 }, |
55 } | 55 } |
56 } | 56 } |
OLD | NEW |