/
autoapproval.go
76 lines (56 loc) · 1.54 KB
/
autoapproval.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
package autoapproval
import (
"encoding/json"
"errors"
"fmt"
"github.com/aws/aws-sdk-go/aws"
"github.com/aws/aws-sdk-go/aws/session"
"github.com/aws/aws-sdk-go/service/lambda"
"github.com/common-fate/common-fate/pkg/identity"
"github.com/common-fate/common-fate/pkg/rule"
)
type Status string
const (
AUTO_APPROVED Status = "AUTO_APPROVED"
REQUIRES_APPROVAL Status = "REQUIRES_APPROVAL"
)
type ResponseBody struct {
Decision Status `json:"decision"`
Justification string `json:"justification,omitempty"`
}
type RequestBody struct {
User identity.User `json:"user"`
Rule rule.AccessRule `json:"rule"`
}
type Service struct {
}
func (s Service) Autoapprove(user identity.User, rule rule.AccessRule, lambdaArn string) (bool, error) {
sess, err := session.NewSession()
if err != nil {
return false, err
}
req := RequestBody{User: user, Rule: rule}
payload, err := json.Marshal(req)
if err != nil {
return false, err
}
params := &lambda.InvokeInput{
FunctionName: aws.String(lambdaArn), // Lambda arn
Payload: payload,
InvocationType: aws.String("RequestResponse"), // Get synchronous output
}
svc := lambda.New(sess)
resp, err := svc.Invoke(params)
if err != nil {
fmt.Println("Error happened when Invoke lambda ", err)
}
var output ResponseBody
err = json.Unmarshal(resp.Payload, &output)
if err != nil {
return false, err
}
if resp.FunctionError != nil {
return false, errors.New("Error happened when calling lambda: " + *resp.FunctionError)
}
return output.Decision == AUTO_APPROVED, nil
}