Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(77)

Side by Side Diff: tokenserver/appengine/delegation/rpc_import_delegation_configs.go

Issue 2413683004: token-server: Delegation config import, validation and evaluation. (Closed)
Patch Set: rebase Created 4 years, 2 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
(Empty)
1 // Copyright 2016 The LUCI Authors. All rights reserved.
2 // Use of this source code is governed under the Apache License, Version 2.0
3 // that can be found in the LICENSE file.
4
5 package delegation
6
7 import (
8 "time"
9
10 "github.com/golang/protobuf/proto"
11 "golang.org/x/net/context"
12 "google.golang.org/grpc"
13 "google.golang.org/grpc/codes"
14
15 ds "github.com/luci/gae/service/datastore"
16 "github.com/luci/gae/service/info"
17
18 "github.com/luci/luci-go/common/config"
19 "github.com/luci/luci-go/common/logging"
20 "github.com/luci/luci-go/common/proto/google"
21
22 "github.com/luci/luci-go/tokenserver/api/admin/v1"
23 )
24
25 const delegationCfg = "delegation.cfg"
26
27 // ImportDelegationConfigsRPC implements Admin.ImportDelegationConfigs method.
28 type ImportDelegationConfigsRPC struct {
29 }
30
31 // ImportDelegationConfigs fetches configs from from luci-config right now.
32 func (r *ImportDelegationConfigsRPC) ImportDelegationConfigs(c context.Context, _ *google.Empty) (*admin.ImportedConfigs, error) {
33 cfg, err := fetchConfigFile(c, delegationCfg)
34 if err != nil {
35 return nil, grpc.Errorf(codes.Internal, "can't read config file - %s", err)
36 }
37 logging.Infof(c, "Importing %q at rev %s", delegationCfg, cfg.Revision)
38
39 // This is returned on successful import.
40 successResp := &admin.ImportedConfigs{
41 ImportedConfigs: []*admin.ImportedConfigs_ConfigFile{
42 {
43 Name: delegationCfg,
44 Revision: cfg.Revision,
45 },
46 },
47 }
48
49 // Already have this revision in the datastore?
50 existing, err := FetchDelegationConfig(c)
51 if err != nil {
52 return nil, grpc.Errorf(codes.Internal, "can't read existing con fig - %s", err)
53 }
54 if existing.Revision == cfg.Revision {
55 logging.Infof(c, "Up-to-date at rev %s", cfg.Revision)
56 return successResp, nil
57 }
58
59 // Convert to binary proto, to be stored in the datastore.
60 msg := &admin.DelegationPermissions{}
61 if err = proto.UnmarshalText(cfg.Content, msg); err != nil {
62 return nil, grpc.Errorf(codes.InvalidArgument, "can't parse conf ig file - %s", err)
63 }
64 blob, err := proto.Marshal(msg)
nodir 2016/10/13 22:03:52 do it after validation?
Vadim Sh. 2016/10/27 04:12:00 Done.
65 if err != nil {
66 return nil, grpc.Errorf(codes.Internal, "can't serialize proto - %s", err)
67 }
68
69 // Validate the new config before storing.
70 if merr := ValidateConfig(msg); len(merr) != 0 {
71 logging.Errorf(c, "The config at rev %s is invalid: %s", cfg.Rev ision, merr)
72 for _, err := range merr {
73 logging.Errorf(c, "%s", err)
74 }
75 return nil, grpc.Errorf(codes.InvalidArgument, "validation error - %s", merr)
76 }
77
78 // Success!
79 imported := DelegationConfig{
80 Revision: cfg.Revision,
81 Config: blob,
82 ParsedConfig: msg,
83 }
84 if err := ds.Put(c, &imported); err != nil {
85 return nil, grpc.Errorf(codes.Internal, "failed to store the con fig - %s", err)
86 }
87
88 logging.Infof(c, "Updated delegation config %s => %s", existing.Revision , imported.Revision)
89 return successResp, nil
90 }
91
92 // fetchConfigFile fetches a file from this services' config set.
93 func fetchConfigFile(c context.Context, path string) (*config.Config, error) {
94 configSet := "services/" + info.AppID(c)
95 logging.Infof(c, "Reading %q from config set %q", path, configSet)
96 c, _ = context.WithTimeout(c, 30*time.Second) // URL fetch deadline
97 return config.GetConfig(c, configSet, path, false)
98 }
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698