Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions lib/Exceptions/LookupServerConfigurationException.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
<?php

declare(strict_types=1);

/**
* SPDX-FileCopyrightText: 2026 Nextcloud GmbH and Nextcloud contributors
* SPDX-License-Identifier: AGPL-3.0-or-later
*/

namespace OCA\GlobalSiteSelector\Exceptions;

use Exception;

class LookupServerConfigurationException extends Exception {
}
11 changes: 9 additions & 2 deletions lib/GlobalSiteSelector.php
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@

namespace OCA\GlobalSiteSelector;

use OCA\GlobalSiteSelector\Exceptions\LookupServerConfigurationException;
use OCA\GlobalSiteSelector\Exceptions\MasterUrlException;
use OCP\IConfig;

Expand Down Expand Up @@ -77,9 +78,15 @@ public function getMasterUrl(): string {

/**
* get lookup server URL
*
* @throws LookupServerConfigurationException
*/
public function getLookupServerUrl(): string {
// TODO: returns exception if non-existant
return $this->config->getSystemValueString('lookup_server', '');
$lus = $this->config->getSystemValueString('lookup_server', '');
if ($lus === '') {
throw new LookupServerConfigurationException();
}

return rtrim($lus, '/');
}
}
25 changes: 11 additions & 14 deletions lib/Lookup.php
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@
namespace OCA\GlobalSiteSelector;

use JsonException;
use OCA\GlobalSiteSelector\Exceptions\LookupServerConfigurationException;
use OCP\Federation\ICloudIdManager;
use OCP\Http\Client\IClientService;
use OCP\IConfig;
Expand All @@ -26,7 +27,6 @@ public function __construct(
private readonly GlobalSiteSelector $gss,
private readonly IConfig $config,
) {
$this->lookupServerUrl = $this->config->getSystemValueString('lookup_server', '');
}

/**
Expand All @@ -39,15 +39,6 @@ public function __construct(
public function search(string &$uid, bool $matchUid = false): string {
$location = '';

// admin need to specify a lookup server with GSS capabilities
if (empty($this->lookupServerUrl)) {
$this->logger->error(
'Can not lookup user, no lookup server registered',
['app' => 'globalsiteselector']
);
return $location;
}

try {
$body = $this->queryLookupServer($uid, $matchUid);
if (($body['federationId'] ?? '') !== '') {
Expand All @@ -56,6 +47,9 @@ public function search(string &$uid, bool $matchUid = false): string {
} else {
$this->logger->debug('search: federationId not set for ' . $uid . ' ' . json_encode($body));
}
} catch (LookupServerConfigurationException) {
$this->logger->debug('Can not lookup user, no lookup server registered');
return '';
} catch (\InvalidArgumentException) {
// Nothing to do, assuming we have not found anything
}
Expand All @@ -67,16 +61,15 @@ public function search(string &$uid, bool $matchUid = false): string {
/**
* query lookup server and return result
*
* @param $uid
*
* @throws LookupServerConfigurationException
* @throws \Exception
*/
protected function queryLookupServer(string $uid, bool $matchUid = false): mixed {
$this->sanitizeUid($uid);
$this->logger->debug('queryLookupServer: asking lookup server for: ' . $uid . ' (matchUid: ' . json_encode($matchUid) . ')');
$client = $this->clientService->newClient();
$response = $client->get(
$this->lookupServerUrl . '/users',
$this->gss->getLookupServerUrl() . '/users',
$this->configureClient(
[
'query' => [
Expand Down Expand Up @@ -150,7 +143,11 @@ private function getUserLocation_Sanitize(string $address, string &$uid): string
*/
public function getInstances(): array {
$client = $this->clientService->newClient();
$response = $client->get($this->lookupServerUrl . '/gs/instances', $this->configureClient(['body' => json_encode(['authKey' => $this->gss->getJwtKey()])]));
try {
$response = $client->get($this->gss->getLookupServerUrl() . '/gs/instances', $this->configureClient(['body' => json_encode(['authKey' => $this->gss->getJwtKey()])]));
} catch (LookupServerConfigurationException $e) {
return [];
}

try {
return json_decode($response->getBody(), true, flags: JSON_THROW_ON_ERROR);
Expand Down
16 changes: 9 additions & 7 deletions lib/Service/SlaveService.php
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@
use Exception;
use OCA\GlobalSiteSelector\AppInfo\Application;
use OCA\GlobalSiteSelector\Exceptions\ConfigurationException;
use OCA\GlobalSiteSelector\Exceptions\LookupServerConfigurationException;
use OCA\GlobalSiteSelector\GlobalSiteSelector;
use OCA\GlobalSiteSelector\Lookup;
use OCP\Accounts\IAccountManager;
Expand All @@ -24,7 +25,6 @@
class SlaveService {
private const CACHE_DISPLAY_NAME = 'gss/displayName';
private const CACHE_DISPLAY_NAME_TTL = 3600;
private readonly string $lookupServer;
private readonly string $operationMode;
private readonly string $authKey;
private readonly ICache $cacheDisplayName;
Expand All @@ -37,10 +37,9 @@ public function __construct(
private readonly IAccountManager $accountManager,
private readonly IConfig $config,
private readonly Lookup $lookup,
GlobalSiteSelector $gss,
private readonly GlobalSiteSelector $gss,
ICacheFactory $cacheFactory,
) {
$this->lookupServer = rtrim($gss->getLookupServerUrl(), '/');
$this->operationMode = $gss->getMode();
$this->authKey = $gss->getJwtKey();

Expand Down Expand Up @@ -159,9 +158,11 @@ protected function postLookup(string $path, array $data): void {
$httpClient = $this->clientService->newClient();
try {
$httpClient->post(
$this->lookupServer . $path,
$this->gss->getLookupServerUrl() . $path,
$this->lookup->configureClient(['body' => json_encode($dataBatch)])
);
} catch (LookupServerConfigurationException) {
$this->logger->debug('lookup server not configured');
} catch (Exception $e) {
$this->logger->warning(
'Could not send user to lookup server',
Expand All @@ -182,9 +183,11 @@ protected function getLookup(string $path, array $data): string {
$httpClient = $this->clientService->newClient();
try {
$response = $httpClient->get(
$this->lookupServer . $path,
$this->gss->getLookupServerUrl() . $path,
$this->lookup->configureClient(['body' => json_encode($dataBatch)])
);
} catch (LookupServerConfigurationException) {
$this->logger->debug('lookup server not configured');
} catch (Exception $e) {
$this->logger->warning(
'Could not get data from lookup server',
Expand All @@ -201,8 +204,7 @@ protected function getLookup(string $path, array $data): string {
* @throws ConfigurationException
*/
protected function checkConfiguration(): void {
if (empty($this->lookupServer)
|| empty($this->operationMode)
if (empty($this->operationMode)
|| empty($this->authKey)
) {
$this->logger->error('app not configured correctly');
Expand Down
24 changes: 9 additions & 15 deletions lib/Slave.php
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@

use Exception;
use OCA\GlobalSiteSelector\AppInfo\Application;
use OCA\GlobalSiteSelector\Exceptions\LookupServerConfigurationException;
use OCA\GlobalSiteSelector\Service\SlaveService;
use OCA\GlobalSiteSelector\Vendor\Firebase\JWT\JWT;
use OCP\Http\Client\IClientService;
Expand All @@ -20,7 +21,6 @@
class Slave {
public const SAML_IDP = 'saml_idp';
public const OIDC_PROVIDER_ID = 'oidc_provider_id';
private string $lookupServer;
private readonly string $operationMode;
private readonly string $authKey;
private static array $toRemove = []; // remember users which should be removed
Expand All @@ -34,11 +34,8 @@ public function __construct(
private readonly LoggerInterface $logger,
private readonly IConfig $config,
) {
$this->lookupServer = $this->gss->getLookupServerUrl();
$this->operationMode = $this->gss->getMode();
$this->authKey = $this->gss->getJwtKey();
$this->lookupServer = rtrim($this->lookupServer, '/');
$this->lookupServer .= '/gs/users';
}

public function createUser(array $params): void {
Expand Down Expand Up @@ -178,9 +175,11 @@ protected function addUsers(array $users): void {
$httpClient = $this->clientService->newClient();
try {
$httpClient->post(
$this->lookupServer,
$this->gss->getLookupServerUrl() . '/gs/users',
$this->lookup->configureClient(['body' => json_encode($dataBatch)])
);
} catch (LookupServerConfigurationException) {
$this->logger->debug('no lookup server configured to update');
} catch (Exception $e) {
$this->logger->warning(
'Could not send user to lookup server',
Expand Down Expand Up @@ -209,9 +208,11 @@ protected function removeUsers(array $users): void {
$httpClient = $this->clientService->newClient();
try {
$httpClient->delete(
$this->lookupServer,
$this->gss->getLookupServerUrl() . '/gs/users',
$this->lookup->configureClient(['body' => json_encode($dataBatch)])
);
} catch (LookupServerConfigurationException) {
$this->logger->debug('no lookup server configured to update');
} catch (Exception $e) {
$this->logger->warning(
'Could not remove user from the lookup server',
Expand All @@ -228,17 +229,10 @@ protected function checkConfiguration(): bool {
return false;
}

if (empty($this->lookupServer)
|| empty($this->operationMode)
if (empty($this->operationMode)
|| empty($this->authKey)
) {
$this->logger->error(
'global site selector app not configured correctly',
[
'app' => Application::APP_ID,
]
);

$this->logger->error('global site selector app not configured correctly');
return false;
}

Expand Down
Loading