create.go 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149
  1. package project_role
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "fmt"
  6. "net/http"
  7. "github.com/porter-dev/porter/api/server/handlers"
  8. "github.com/porter-dev/porter/api/server/shared"
  9. "github.com/porter-dev/porter/api/server/shared/apierrors"
  10. "github.com/porter-dev/porter/api/server/shared/config"
  11. "github.com/porter-dev/porter/api/types"
  12. "github.com/porter-dev/porter/internal/encryption"
  13. "github.com/porter-dev/porter/internal/models"
  14. "github.com/porter-dev/porter/internal/repository"
  15. "gorm.io/gorm"
  16. )
  17. type CreateProjectRoleHandler struct {
  18. handlers.PorterHandlerReadWriter
  19. }
  20. func NewCreateProjectRoleHandler(
  21. config *config.Config,
  22. decoderValidator shared.RequestDecoderValidator,
  23. writer shared.ResultWriter,
  24. ) *CreateProjectRoleHandler {
  25. return &CreateProjectRoleHandler{
  26. PorterHandlerReadWriter: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  27. }
  28. }
  29. func (c *CreateProjectRoleHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  30. project, _ := r.Context().Value(types.ProjectScope).(*models.Project)
  31. user, _ := r.Context().Value(types.UserScope).(*models.User)
  32. request := &types.CreateProjectRoleRequest{}
  33. if ok := c.DecodeAndValidate(w, r, request); !ok {
  34. return
  35. }
  36. if request.Name == string(types.RoleAdmin) ||
  37. request.Name == string(types.RoleDeveloper) ||
  38. request.Name == string(types.RoleViewer) {
  39. c.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(
  40. fmt.Errorf("default role names admin, developer, viewer are not allowed"), http.StatusConflict,
  41. ))
  42. return
  43. }
  44. uid, err := encryption.GenerateRandomBytes(16)
  45. if err != nil {
  46. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  47. return
  48. }
  49. policyBytes, err := json.Marshal([]*types.PolicyDocument{request.Policy})
  50. if err != nil {
  51. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  52. return
  53. }
  54. policy, err := c.Repo().Policy().CreatePolicy(&models.Policy{
  55. UniqueID: uid,
  56. ProjectID: project.ID,
  57. CreatedByUserID: user.ID,
  58. Name: fmt.Sprintf("%s-project-role-policy", request.Name),
  59. PolicyBytes: policyBytes,
  60. })
  61. if err != nil {
  62. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  63. return
  64. }
  65. uid, err = encryption.GenerateRandomBytes(16)
  66. if err != nil {
  67. // we need to delete the policy we just created
  68. c.Repo().Policy().DeletePolicy(policy)
  69. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  70. return
  71. }
  72. role, err := c.Repo().ProjectRole().CreateProjectRole(&models.ProjectRole{
  73. UniqueID: uid,
  74. ProjectID: project.ID,
  75. PolicyUID: policy.UniqueID,
  76. Name: request.Name,
  77. })
  78. if err != nil {
  79. // we need to delete the policy we just created
  80. c.Repo().Policy().DeletePolicy(policy)
  81. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  82. return
  83. }
  84. if len(request.Users) > 0 {
  85. for _, u := range request.Users {
  86. err := validateUserForProjectRole(c.Repo(), u, project.ID)
  87. if err != nil {
  88. c.HandleAPIError(w, r, err)
  89. return
  90. }
  91. }
  92. err = c.Repo().ProjectRole().UpdateUsersInProjectRole(project.ID, role.UniqueID, request.Users)
  93. if err != nil {
  94. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  95. return
  96. }
  97. }
  98. w.WriteHeader(http.StatusCreated)
  99. }
  100. func validateUserForProjectRole(repo repository.Repository, userID, projectID uint) apierrors.RequestError {
  101. // check for valid user
  102. _, err := repo.User().ReadUser(userID)
  103. if err != nil && errors.Is(err, gorm.ErrRecordNotFound) {
  104. return apierrors.NewErrNotFound(fmt.Errorf("user with id %d does not exist", userID))
  105. } else if err != nil {
  106. return apierrors.NewErrInternal(err)
  107. }
  108. // a user needs to have been a collaborator with at least one role already in a project to be added to a new role
  109. roles, err := repo.ProjectRole().ListAllRolesForUser(projectID, userID)
  110. if err != nil {
  111. return apierrors.NewErrInternal(err)
  112. }
  113. if len(roles) == 0 {
  114. return apierrors.NewErrPassThroughToClient(fmt.Errorf("user is not a collaborator in this project"),
  115. http.StatusBadRequest)
  116. }
  117. return nil
  118. }