create.go 2.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105
  1. package project_role
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "net/http"
  6. "github.com/porter-dev/porter/api/server/handlers"
  7. "github.com/porter-dev/porter/api/server/shared"
  8. "github.com/porter-dev/porter/api/server/shared/apierrors"
  9. "github.com/porter-dev/porter/api/server/shared/config"
  10. "github.com/porter-dev/porter/api/types"
  11. "github.com/porter-dev/porter/internal/encryption"
  12. "github.com/porter-dev/porter/internal/models"
  13. )
  14. type CreateProjectRoleHandler struct {
  15. handlers.PorterHandlerReadWriter
  16. }
  17. func NewCreateProjectRoleHandler(
  18. config *config.Config,
  19. decoderValidator shared.RequestDecoderValidator,
  20. writer shared.ResultWriter,
  21. ) *CreateProjectRoleHandler {
  22. return &CreateProjectRoleHandler{
  23. PorterHandlerReadWriter: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  24. }
  25. }
  26. func (c *CreateProjectRoleHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  27. project, _ := r.Context().Value(types.ProjectScope).(*models.Project)
  28. user, _ := r.Context().Value(types.UserScope).(*models.User)
  29. request := &types.CreateProjectRoleRequest{}
  30. if ok := c.DecodeAndValidate(w, r, request); !ok {
  31. return
  32. }
  33. uid, err := encryption.GenerateRandomBytes(16)
  34. if err != nil {
  35. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  36. return
  37. }
  38. policyBytes, err := json.Marshal([]*types.PolicyDocument{request.Policy})
  39. if err != nil {
  40. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  41. return
  42. }
  43. policy, err := c.Repo().Policy().CreatePolicy(&models.Policy{
  44. UniqueID: uid,
  45. ProjectID: project.ID,
  46. CreatedByUserID: user.ID,
  47. Name: fmt.Sprintf("%s-project-role-policy", request.Name),
  48. PolicyBytes: policyBytes,
  49. })
  50. if err != nil {
  51. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  52. return
  53. }
  54. uid, err = encryption.GenerateRandomBytes(16)
  55. if err != nil {
  56. // we need to delete the policy we just created
  57. c.Repo().Policy().DeletePolicy(policy)
  58. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  59. return
  60. }
  61. role, err := c.Repo().ProjectRole().CreateProjectRole(&models.ProjectRole{
  62. UniqueID: uid,
  63. ProjectID: project.ID,
  64. PolicyUID: policy.UniqueID,
  65. Name: request.Name,
  66. })
  67. if err != nil {
  68. // we need to delete the policy we just created
  69. c.Repo().Policy().DeletePolicy(policy)
  70. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  71. return
  72. }
  73. err = c.Repo().ProjectRole().UpdateUsersInProjectRole(project.ID, role.UniqueID, request.Users)
  74. if err != nil {
  75. // we need to delete the policy and project role we just created
  76. c.Repo().Policy().DeletePolicy(policy)
  77. c.Repo().ProjectRole().DeleteProjectRole(role)
  78. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  79. return
  80. }
  81. w.WriteHeader(http.StatusCreated)
  82. }