-
Notifications
You must be signed in to change notification settings - Fork 3.1k
/
claims.go
115 lines (90 loc) · 2.78 KB
/
claims.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
package types
import (
"encoding/json"
"fmt"
"net/http"
"github.com/go-jose/go-jose/v3/jwt"
)
type Claims struct {
jwt.Claims
Groups []string `json:"groups,omitempty"`
Email string `json:"email,omitempty"`
EmailVerified bool `json:"-"`
Name string `json:"name,omitempty"`
ServiceAccountName string `json:"service_account_name,omitempty"`
ServiceAccountNamespace string `json:"service_account_namespace,omitempty"`
PreferredUsername string `json:"preferred_username,omitempty"`
RawClaim map[string]interface{} `json:"-"`
}
type UserInfo struct {
Groups []string `json:"groups"`
}
type HttpClient interface {
Do(req *http.Request) (*http.Response, error)
}
var httpClient HttpClient
func init() {
httpClient = &http.Client{}
}
// UnmarshalJSON is a custom Unmarshal that overwrites
// json.Unmarshal to mash every claim into a custom map
func (c *Claims) UnmarshalJSON(data []byte) error {
type claimAlias Claims
var localClaim claimAlias = claimAlias(*c)
// Populate the claims struct as much as possible
err := json.Unmarshal(data, &localClaim)
if err != nil {
return err
}
// Populate the raw data struct
err = json.Unmarshal(data, &localClaim.RawClaim)
if err != nil {
return err
}
if localClaim.RawClaim["email_verified"] == true || localClaim.RawClaim["email_verified"] == "true" {
localClaim.EmailVerified = true
}
*c = Claims(localClaim)
return nil
}
// GetCustomGroup is responsible for extracting groups based on the
// provided custom claim key
func (c *Claims) GetCustomGroup(customKeyName string) ([]string, error) {
groups, ok := c.RawClaim[customKeyName]
if !ok {
return nil, fmt.Errorf("no claim found for key: %v", customKeyName)
}
sliceInterface, ok := groups.([]interface{})
if !ok {
return nil, fmt.Errorf("expected an array, got %v", groups)
}
newSlice := []string{}
for _, a := range sliceInterface {
val, ok := a.(string)
if !ok {
return nil, fmt.Errorf("group name %v was not a string", a)
}
newSlice = append(newSlice, val)
}
return newSlice, nil
}
func (c *Claims) GetUserInfoGroups(accessToken, issuer, userInfoPath string) ([]string, error) {
url := fmt.Sprintf("%s%s", issuer, userInfoPath)
request, err := http.NewRequest("GET", url, nil)
if err != nil {
return nil, err
}
bearer := fmt.Sprintf("Bearer %s", accessToken)
request.Header.Set("Authorization", bearer)
response, err := httpClient.Do(request)
if err != nil {
return nil, err
}
userInfo := UserInfo{}
defer response.Body.Close()
err = json.NewDecoder(response.Body).Decode(&userInfo)
if err != nil {
return nil, err
}
return userInfo.Groups, nil
}