Skip to content

Commit 26deb80

Browse files
committed
feat: implement path block and user block
Fixes #313
1 parent 598abc5 commit 26deb80

2 files changed

Lines changed: 29 additions & 10 deletions

File tree

‎internal/controller/proxy_controller.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,7 +112,7 @@ func (controller *ProxyController) proxyHandler(c *gin.Context) {
112112
return
113113
}
114114

115-
authEnabled, err := controller.Auth.IsAuthEnabled(uri, labels.Path.Allow)
115+
authEnabled, err := controller.Auth.IsAuthEnabled(uri, labels.Path)
116116

117117
if err != nil {
118118
log.Error().Err(err).Msg("Failed to check if auth is enabled for resource")

‎internal/service/auth_service.go‎

Lines changed: 28 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -289,6 +289,13 @@ func (auth *AuthService) IsResourceAllowed(c *gin.Context, context config.UserCo
289289
return utils.CheckFilter(labels.OAuth.Whitelist, context.Email)
290290
}
291291

292+
if labels.Users.Block != "" {
293+
log.Debug().Msg("Checking blocked users")
294+
if utils.CheckFilter(labels.Users.Block, context.Username) {
295+
return false
296+
}
297+
}
298+
292299
log.Debug().Msg("Checking users")
293300
return utils.CheckFilter(labels.Users.Allow, context.Username)
294301
}
@@ -316,19 +323,31 @@ func (auth *AuthService) IsInOAuthGroup(c *gin.Context, context config.UserConte
316323
return false
317324
}
318325

319-
func (auth *AuthService) IsAuthEnabled(uri string, pathAllow string) (bool, error) {
320-
if pathAllow == "" {
321-
return true, nil
322-
}
326+
func (auth *AuthService) IsAuthEnabled(uri string, path config.PathLabels) (bool, error) {
327+
// Check for block list
328+
if path.Block != "" {
329+
regex, err := regexp.Compile(path.Block)
323330

324-
regex, err := regexp.Compile(pathAllow)
331+
if err != nil {
332+
return true, err
333+
}
325334

326-
if err != nil {
327-
return true, err
335+
if !regex.MatchString(uri) {
336+
return false, nil
337+
}
328338
}
329339

330-
if regex.MatchString(uri) {
331-
return false, nil
340+
// Check for allow list
341+
if path.Allow != "" {
342+
regex, err := regexp.Compile(path.Allow)
343+
344+
if err != nil {
345+
return true, err
346+
}
347+
348+
if regex.MatchString(uri) {
349+
return false, nil
350+
}
332351
}
333352

334353
return true, nil

0 commit comments

Comments
 (0)