812c0b34ea
* feat(ldap): simplify ldap configuration refactor(auth): move ldap settings to a component feat(ldap): add username style autofill feat(ldap): customs for ad feat(app): introduce box selector refactor(auth-settings): use box selector feat(ldap): style changes refactor(ldap): move connectivity check button to a component refactor(settings): move ldap security settings to a component refactor(ldap): move user search to component refactor(ldap): move group search to component style(ldap): remove comment refactor(auth-settings): move auto-user-toggle to component feat(ldap): provide methods to search for users and groups refactor(ldap): move group/user settings into component refactor(ldap): provide labels for components refactor(ldap): separate custom and ad settings fix(ldap): search for users feat(ldap): search users feat(ldap): complete password if missing feat(ldap): search for users feat(ldap): show a list of users feat(ldap): get user uid feat(ldap): search groups without password feat(groups): show group results feat(ldap): add display types feat(ldap): search for groups refactor(ldap): clean code fix(ldap): sort users table fix(ldap): show settings by type feat(ldap): parse values from basedn feat(ldap): parse values feat(app): emit on change event from box-selector feat(ldap): user search filter feat(ldap): search username attribute feat(ldap): remove format around search filter feat(ldap): ad group search refactor(ldap): move dn builder to component feat(ldap): use base dn builder for group search feat(ldap): search for ad groups refactor(ldap): replace domain root object feat(ldap): openldap settings refactor(ldap): delete empty controllers feat(ldap): remove warning on wrong group filter feat(ldap): clear username and pass if not AD feat(ldap): clear basedn when switch from openldap to ad feat(ldap): clear ldap settings when switich from ldap to ad feat(ldap): set dn only if there are values feat(ldap): support more cases of domains feat(ldap): parse openldap domain correctly refactor(ldap): move server type check feat(ldap): move entries feat(ldap): show username format style(ldap): remove comments feat(ldap): clear group filter when no groups refactor(ldap): replace generic payload feat(ldap): allow the user to test login feat(ldap): add test login to custom and open ldap settings feat(ldap): style fixes fix(ldap): style fix fix(ldap): style fixes refactor(ldap): move components to module feat(ldap): add group entries feat(ldap): add borders around each group entry feat(ldap): parse user filter feat(ldap): add/remove group feat(ldap): set ad anonymous mode to false feat(ldap): add group name feat(ldap): fix parentheses feat(ldap): separate between each search config fix(ldap): fix parsing of group dn feat(ldap): style fixes feat(ldap): remove of change of filter refactor(ldap): remove user display style feat(ldap): rename group entries field refactor(auth): move auto user provision refactor(ldap): refactor box selector feat(ldap): move ad settings to be a global setting style(ldap): remove comments feat(ldap): add auto user toggle refactor(auth/ad): rename ad component fix(auth/ad): fix the use of a certificate refactor(ldap): rename components fix(ldap): show user and group search fix(ldap): design group settings feat(ldap): search users and groups feat(ldap): add margins refactor(ldap): separate ldap and ad settings refactor(auth): use central check for auth method feat(ldap): clear margins feat(ldap): add port if missing feat(ldap): fix ad name fix(ldap): rename fields feat(ldap): add domain root field feat(auth/ad): remove domain root field feat(ldap): rename base dn to root domain feat(ldap/openldap): get suffix feat(ldap/open): change base filter fix(ldap): align feat(db): introduce migration for ldap server type refactor(ldap): move service to ldap module refactor(ldap): sync between client and server constants fix(ldap): use post for check style(ldap): fix handler comments fix(ldap): check for errors style(ldap): fix tyop fix(ldap): check equality style(ldap): add comments fix(ldap): allow anonymous mode fix(ldap): show errors on search users feat(lasp): use custom settings for each server fix(ldap): supply default group filter fix(ldap): show domain suffix in new settings fix(ldap): replace icon with text refactor(components): remove box-selector-wrapper * fix(ldap): enable test when form is valid * fix(ldap): add port if missing
246 lines
8.2 KiB
Go
246 lines
8.2 KiB
Go
package settings
|
|
|
|
import (
|
|
"errors"
|
|
"net/http"
|
|
"time"
|
|
|
|
"github.com/asaskevich/govalidator"
|
|
httperror "github.com/portainer/libhttp/error"
|
|
"github.com/portainer/libhttp/request"
|
|
"github.com/portainer/libhttp/response"
|
|
portainer "github.com/portainer/portainer/api"
|
|
"github.com/portainer/portainer/api/filesystem"
|
|
)
|
|
|
|
type settingsUpdatePayload struct {
|
|
LogoURL *string
|
|
BlackListedLabels []portainer.Pair
|
|
AuthenticationMethod *int
|
|
LDAPSettings *portainer.LDAPSettings
|
|
OAuthSettings *portainer.OAuthSettings
|
|
AllowBindMountsForRegularUsers *bool
|
|
AllowPrivilegedModeForRegularUsers *bool
|
|
AllowHostNamespaceForRegularUsers *bool
|
|
AllowVolumeBrowserForRegularUsers *bool
|
|
AllowDeviceMappingForRegularUsers *bool
|
|
AllowStackManagementForRegularUsers *bool
|
|
AllowContainerCapabilitiesForRegularUsers *bool
|
|
EnableHostManagementFeatures *bool
|
|
SnapshotInterval *string
|
|
TemplatesURL *string
|
|
EdgeAgentCheckinInterval *int
|
|
EnableEdgeComputeFeatures *bool
|
|
UserSessionTimeout *string
|
|
EnableTelemetry *bool
|
|
}
|
|
|
|
func (payload *settingsUpdatePayload) Validate(r *http.Request) error {
|
|
if payload.AuthenticationMethod != nil && *payload.AuthenticationMethod != 1 && *payload.AuthenticationMethod != 2 && *payload.AuthenticationMethod != 3 {
|
|
return errors.New("Invalid authentication method value. Value must be one of: 1 (internal), 2 (LDAP/AD) or 3 (OAuth)")
|
|
}
|
|
if payload.LogoURL != nil && *payload.LogoURL != "" && !govalidator.IsURL(*payload.LogoURL) {
|
|
return errors.New("Invalid logo URL. Must correspond to a valid URL format")
|
|
}
|
|
if payload.TemplatesURL != nil && *payload.TemplatesURL != "" && !govalidator.IsURL(*payload.TemplatesURL) {
|
|
return errors.New("Invalid external templates URL. Must correspond to a valid URL format")
|
|
}
|
|
if payload.UserSessionTimeout != nil {
|
|
_, err := time.ParseDuration(*payload.UserSessionTimeout)
|
|
if err != nil {
|
|
return errors.New("Invalid user session timeout")
|
|
}
|
|
}
|
|
|
|
if payload.AuthenticationMethod != nil && *payload.AuthenticationMethod == 2 {
|
|
if payload.LDAPSettings == nil {
|
|
return errors.New("Invalid LDAP Configuration")
|
|
}
|
|
if len(payload.LDAPSettings.URLs) == 0 {
|
|
return errors.New("Invalid LDAP URLs. At least one URL is required")
|
|
}
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// PUT request on /api/settings
|
|
func (handler *Handler) settingsUpdate(w http.ResponseWriter, r *http.Request) *httperror.HandlerError {
|
|
var payload settingsUpdatePayload
|
|
err := request.DecodeAndValidateJSONPayload(r, &payload)
|
|
if err != nil {
|
|
return &httperror.HandlerError{http.StatusBadRequest, "Invalid request payload", err}
|
|
}
|
|
|
|
settings, err := handler.DataStore.Settings().Settings()
|
|
if err != nil {
|
|
return &httperror.HandlerError{http.StatusInternalServerError, "Unable to retrieve the settings from the database", err}
|
|
}
|
|
|
|
if payload.AuthenticationMethod != nil {
|
|
settings.AuthenticationMethod = portainer.AuthenticationMethod(*payload.AuthenticationMethod)
|
|
}
|
|
|
|
if payload.LogoURL != nil {
|
|
settings.LogoURL = *payload.LogoURL
|
|
}
|
|
|
|
if payload.TemplatesURL != nil {
|
|
settings.TemplatesURL = *payload.TemplatesURL
|
|
}
|
|
|
|
if payload.BlackListedLabels != nil {
|
|
settings.BlackListedLabels = payload.BlackListedLabels
|
|
}
|
|
|
|
if payload.LDAPSettings != nil {
|
|
ldapReaderDN := settings.LDAPSettings.ReaderDN
|
|
ldapPassword := settings.LDAPSettings.Password
|
|
|
|
if payload.LDAPSettings.ReaderDN != "" {
|
|
ldapReaderDN = payload.LDAPSettings.ReaderDN
|
|
}
|
|
|
|
if payload.LDAPSettings.Password != "" {
|
|
ldapPassword = payload.LDAPSettings.Password
|
|
}
|
|
|
|
if payload.LDAPSettings.AnonymousMode {
|
|
ldapReaderDN = ""
|
|
ldapPassword = ""
|
|
}
|
|
|
|
settings.LDAPSettings = *payload.LDAPSettings
|
|
settings.LDAPSettings.ReaderDN = ldapReaderDN
|
|
settings.LDAPSettings.Password = ldapPassword
|
|
}
|
|
|
|
if payload.OAuthSettings != nil {
|
|
clientSecret := payload.OAuthSettings.ClientSecret
|
|
if clientSecret == "" {
|
|
clientSecret = settings.OAuthSettings.ClientSecret
|
|
}
|
|
settings.OAuthSettings = *payload.OAuthSettings
|
|
settings.OAuthSettings.ClientSecret = clientSecret
|
|
}
|
|
|
|
if payload.AllowBindMountsForRegularUsers != nil {
|
|
settings.AllowBindMountsForRegularUsers = *payload.AllowBindMountsForRegularUsers
|
|
}
|
|
|
|
if payload.AllowPrivilegedModeForRegularUsers != nil {
|
|
settings.AllowPrivilegedModeForRegularUsers = *payload.AllowPrivilegedModeForRegularUsers
|
|
}
|
|
|
|
updateAuthorizations := false
|
|
if payload.AllowVolumeBrowserForRegularUsers != nil {
|
|
settings.AllowVolumeBrowserForRegularUsers = *payload.AllowVolumeBrowserForRegularUsers
|
|
updateAuthorizations = true
|
|
}
|
|
|
|
if payload.EnableHostManagementFeatures != nil {
|
|
settings.EnableHostManagementFeatures = *payload.EnableHostManagementFeatures
|
|
}
|
|
|
|
if payload.EnableEdgeComputeFeatures != nil {
|
|
settings.EnableEdgeComputeFeatures = *payload.EnableEdgeComputeFeatures
|
|
}
|
|
|
|
if payload.AllowHostNamespaceForRegularUsers != nil {
|
|
settings.AllowHostNamespaceForRegularUsers = *payload.AllowHostNamespaceForRegularUsers
|
|
}
|
|
|
|
if payload.AllowStackManagementForRegularUsers != nil {
|
|
settings.AllowStackManagementForRegularUsers = *payload.AllowStackManagementForRegularUsers
|
|
}
|
|
|
|
if payload.AllowContainerCapabilitiesForRegularUsers != nil {
|
|
settings.AllowContainerCapabilitiesForRegularUsers = *payload.AllowContainerCapabilitiesForRegularUsers
|
|
}
|
|
|
|
if payload.SnapshotInterval != nil && *payload.SnapshotInterval != settings.SnapshotInterval {
|
|
err := handler.updateSnapshotInterval(settings, *payload.SnapshotInterval)
|
|
if err != nil {
|
|
return &httperror.HandlerError{http.StatusInternalServerError, "Unable to update snapshot interval", err}
|
|
}
|
|
}
|
|
|
|
if payload.EdgeAgentCheckinInterval != nil {
|
|
settings.EdgeAgentCheckinInterval = *payload.EdgeAgentCheckinInterval
|
|
}
|
|
|
|
if payload.UserSessionTimeout != nil {
|
|
settings.UserSessionTimeout = *payload.UserSessionTimeout
|
|
|
|
userSessionDuration, _ := time.ParseDuration(*payload.UserSessionTimeout)
|
|
|
|
handler.JWTService.SetUserSessionDuration(userSessionDuration)
|
|
}
|
|
|
|
if payload.AllowDeviceMappingForRegularUsers != nil {
|
|
settings.AllowDeviceMappingForRegularUsers = *payload.AllowDeviceMappingForRegularUsers
|
|
}
|
|
|
|
if payload.EnableTelemetry != nil {
|
|
settings.EnableTelemetry = *payload.EnableTelemetry
|
|
}
|
|
|
|
tlsError := handler.updateTLS(settings)
|
|
if tlsError != nil {
|
|
return tlsError
|
|
}
|
|
|
|
err = handler.DataStore.Settings().UpdateSettings(settings)
|
|
if err != nil {
|
|
return &httperror.HandlerError{http.StatusInternalServerError, "Unable to persist settings changes inside the database", err}
|
|
}
|
|
|
|
if updateAuthorizations {
|
|
err := handler.updateVolumeBrowserSetting(settings)
|
|
if err != nil {
|
|
return &httperror.HandlerError{http.StatusInternalServerError, "Unable to update RBAC authorizations", err}
|
|
}
|
|
}
|
|
|
|
return response.JSON(w, settings)
|
|
}
|
|
|
|
func (handler *Handler) updateVolumeBrowserSetting(settings *portainer.Settings) error {
|
|
err := handler.AuthorizationService.UpdateVolumeBrowsingAuthorizations(settings.AllowVolumeBrowserForRegularUsers)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
err = handler.AuthorizationService.UpdateUsersAuthorizations()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
func (handler *Handler) updateSnapshotInterval(settings *portainer.Settings, snapshotInterval string) error {
|
|
settings.SnapshotInterval = snapshotInterval
|
|
|
|
err := handler.SnapshotService.SetSnapshotInterval(snapshotInterval)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
func (handler *Handler) updateTLS(settings *portainer.Settings) *httperror.HandlerError {
|
|
if (settings.LDAPSettings.TLSConfig.TLS || settings.LDAPSettings.StartTLS) && !settings.LDAPSettings.TLSConfig.TLSSkipVerify {
|
|
caCertPath, _ := handler.FileService.GetPathForTLSFile(filesystem.LDAPStorePath, portainer.TLSFileCA)
|
|
settings.LDAPSettings.TLSConfig.TLSCACertPath = caCertPath
|
|
} else {
|
|
settings.LDAPSettings.TLSConfig.TLSCACertPath = ""
|
|
err := handler.FileService.DeleteTLSFiles(filesystem.LDAPStorePath)
|
|
if err != nil {
|
|
return &httperror.HandlerError{http.StatusInternalServerError, "Unable to remove TLS files from disk", err}
|
|
}
|
|
}
|
|
return nil
|
|
}
|