Skip to content

Commit f5ac7ef

Browse files
committed
refactor: mode label decoder to separate package
1 parent b024d5f commit f5ac7ef

7 files changed

Lines changed: 120 additions & 42 deletions

File tree

‎internal/config/config.go‎

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -126,51 +126,51 @@ type RedirectQuery struct {
126126

127127
// Labels
128128

129-
type Labels struct {
130-
Apps map[string]AppLabels
129+
type Apps struct {
130+
Apps map[string]App
131131
}
132132

133-
type AppLabels struct {
134-
Config ConfigLabels
135-
Users UsersLabels
136-
OAuth OAuthLabels
137-
IP IPLabels
138-
Response ResponseLabels
139-
Path PathLabels
133+
type App struct {
134+
Config AppConfig
135+
Users AppUsers
136+
OAuth AppOAuth
137+
IP AppIP
138+
Response AppResponse
139+
Path AppPath
140140
}
141141

142-
type ConfigLabels struct {
142+
type AppConfig struct {
143143
Domain string
144144
}
145145

146-
type UsersLabels struct {
146+
type AppUsers struct {
147147
Allow string
148148
Block string
149149
}
150150

151-
type OAuthLabels struct {
151+
type AppOAuth struct {
152152
Whitelist string
153153
Groups string
154154
}
155155

156-
type IPLabels struct {
156+
type AppIP struct {
157157
Allow []string
158158
Block []string
159159
Bypass []string
160160
}
161161

162-
type ResponseLabels struct {
162+
type AppResponse struct {
163163
Headers []string
164-
BasicAuth BasicAuthLabels
164+
BasicAuth AppBasicAuth
165165
}
166166

167-
type BasicAuthLabels struct {
167+
type AppBasicAuth struct {
168168
Username string
169169
Password string
170170
PasswordFile string
171171
}
172172

173-
type PathLabels struct {
173+
type AppPath struct {
174174
Allow string
175175
Block string
176176
}

‎internal/controller/proxy_controller.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -251,7 +251,7 @@ func (controller *ProxyController) proxyHandler(c *gin.Context) {
251251
c.Redirect(http.StatusTemporaryRedirect, fmt.Sprintf("%s/login?%s", controller.config.AppURL, queries.Encode()))
252252
}
253253

254-
func (controller *ProxyController) setHeaders(c *gin.Context, labels config.AppLabels) {
254+
func (controller *ProxyController) setHeaders(c *gin.Context, labels config.App) {
255255
c.Header("Authorization", c.Request.Header.Get("Authorization"))
256256

257257
headers := utils.ParseHeaders(labels.Response.Headers)

‎internal/service/auth_service.go‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -285,7 +285,7 @@ func (auth *AuthService) UserAuthConfigured() bool {
285285
return len(auth.config.Users) > 0 || auth.ldap != nil
286286
}
287287

288-
func (auth *AuthService) IsResourceAllowed(c *gin.Context, context config.UserContext, labels config.AppLabels) bool {
288+
func (auth *AuthService) IsResourceAllowed(c *gin.Context, context config.UserContext, labels config.App) bool {
289289
if context.OAuth {
290290
log.Debug().Msg("Checking OAuth whitelist")
291291
return utils.CheckFilter(labels.OAuth.Whitelist, context.Email)
@@ -322,7 +322,7 @@ func (auth *AuthService) IsInOAuthGroup(c *gin.Context, context config.UserConte
322322
return false
323323
}
324324

325-
func (auth *AuthService) IsAuthEnabled(uri string, path config.PathLabels) (bool, error) {
325+
func (auth *AuthService) IsAuthEnabled(uri string, path config.AppPath) (bool, error) {
326326
// Check for block list
327327
if path.Block != "" {
328328
regex, err := regexp.Compile(path.Block)
@@ -364,7 +364,7 @@ func (auth *AuthService) GetBasicAuth(c *gin.Context) *config.User {
364364
}
365365
}
366366

367-
func (auth *AuthService) CheckIP(labels config.IPLabels, ip string) bool {
367+
func (auth *AuthService) CheckIP(labels config.AppIP, ip string) bool {
368368
for _, blocked := range labels.Block {
369369
res, err := utils.FilterIP(blocked, ip)
370370
if err != nil {
@@ -398,7 +398,7 @@ func (auth *AuthService) CheckIP(labels config.IPLabels, ip string) bool {
398398
return true
399399
}
400400

401-
func (auth *AuthService) IsBypassedIP(labels config.IPLabels, ip string) bool {
401+
func (auth *AuthService) IsBypassedIP(labels config.AppIP, ip string) bool {
402402
for _, bypassed := range labels.Bypass {
403403
res, err := utils.FilterIP(bypassed, ip)
404404
if err != nil {

‎internal/service/docker_service.go‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ import (
44
"context"
55
"strings"
66
"tinyauth/internal/config"
7-
"tinyauth/internal/utils"
7+
"tinyauth/internal/utils/decoders"
88

99
container "github.com/docker/docker/api/types/container"
1010
"github.com/docker/docker/client"
@@ -55,17 +55,17 @@ func (docker *DockerService) DockerConnected() bool {
5555
return err == nil
5656
}
5757

58-
func (docker *DockerService) GetLabels(appDomain string) (config.AppLabels, error) {
58+
func (docker *DockerService) GetLabels(appDomain string) (config.App, error) {
5959
isConnected := docker.DockerConnected()
6060

6161
if !isConnected {
6262
log.Debug().Msg("Docker not connected, returning empty labels")
63-
return config.AppLabels{}, nil
63+
return config.App{}, nil
6464
}
6565

6666
containers, err := docker.GetContainers()
6767
if err != nil {
68-
return config.AppLabels{}, err
68+
return config.App{}, err
6969
}
7070

7171
for _, ctr := range containers {
@@ -75,7 +75,7 @@ func (docker *DockerService) GetLabels(appDomain string) (config.AppLabels, erro
7575
continue
7676
}
7777

78-
labels, err := utils.GetLabels(inspect.Config.Labels)
78+
labels, err := decoders.DecodeLabels(inspect.Config.Labels)
7979
if err != nil {
8080
log.Warn().Str("id", ctr.ID).Err(err).Msg("Error getting container labels, skipping")
8181
continue
@@ -95,5 +95,5 @@ func (docker *DockerService) GetLabels(appDomain string) (config.AppLabels, erro
9595
}
9696

9797
log.Debug().Msg("No matching container found, returning empty labels")
98-
return config.AppLabels{}, nil
98+
return config.App{}, nil
9999
}
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
package decoders
2+
3+
import (
4+
"tinyauth/internal/config"
5+
6+
"github.com/traefik/paerser/parser"
7+
)
8+
9+
func DecodeLabels(labels map[string]string) (config.Apps, error) {
10+
var appLabels config.Apps
11+
12+
err := parser.Decode(labels, &appLabels, "tinyauth", "tinyauth.apps")
13+
14+
if err != nil {
15+
return config.Apps{}, err
16+
}
17+
18+
return appLabels, nil
19+
}
Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
package decoders_test
2+
3+
import (
4+
"reflect"
5+
"testing"
6+
"tinyauth/internal/config"
7+
"tinyauth/internal/utils/decoders"
8+
)
9+
10+
func TestDecodeLabels(t *testing.T) {
11+
// Variables
12+
expected := config.Apps{
13+
Apps: map[string]config.App{
14+
"foo": {
15+
Config: config.AppConfig{
16+
Domain: "example.com",
17+
},
18+
Users: config.AppUsers{
19+
Allow: "user1,user2",
20+
Block: "user3",
21+
},
22+
OAuth: config.AppOAuth{
23+
Whitelist: "somebody@example.com",
24+
Groups: "group3",
25+
},
26+
IP: config.AppIP{
27+
Allow: []string{"10.71.0.1/24", "10.71.0.2"},
28+
Block: []string{"10.10.10.10", "10.0.0.0/24"},
29+
Bypass: []string{"192.168.1.1"},
30+
},
31+
Response: config.AppResponse{
32+
Headers: []string{"X-Foo=Bar", "X-Baz=Qux"},
33+
BasicAuth: config.AppBasicAuth{
34+
Username: "admin",
35+
Password: "password",
36+
PasswordFile: "/path/to/passwordfile",
37+
},
38+
},
39+
Path: config.AppPath{
40+
Allow: "/public",
41+
Block: "/private",
42+
},
43+
},
44+
},
45+
}
46+
test := map[string]string{
47+
"tinyauth.apps.foo.config.domain": "example.com",
48+
"tinyauth.apps.foo.users.allow": "user1,user2",
49+
"tinyauth.apps.foo.users.block": "user3",
50+
"tinyauth.apps.foo.oauth.whitelist": "somebody@example.com",
51+
"tinyauth.apps.foo.oauth.groups": "group3",
52+
"tinyauth.apps.foo.ip.allow": "10.71.0.1/24,10.71.0.2",
53+
"tinyauth.apps.foo.ip.block": "10.10.10.10,10.0.0.0/24",
54+
"tinyauth.apps.foo.ip.bypass": "192.168.1.1",
55+
"tinyauth.apps.foo.response.headers": "X-Foo=Bar,X-Baz=Qux",
56+
"tinyauth.apps.foo.response.basicauth.username": "admin",
57+
"tinyauth.apps.foo.response.basicauth.password": "password",
58+
"tinyauth.apps.foo.response.basicauth.passwordfile": "/path/to/passwordfile",
59+
"tinyauth.apps.foo.path.allow": "/public",
60+
"tinyauth.apps.foo.path.block": "/private",
61+
}
62+
63+
// Test
64+
result, err := decoders.DecodeLabels(test)
65+
66+
if err != nil {
67+
t.Fatalf("Unexpected error: %v", err)
68+
}
69+
70+
if reflect.DeepEqual(expected, result) == false {
71+
t.Fatalf("Expected %v but got %v", expected, result)
72+
}
73+
}

‎internal/utils/label_utils.go‎

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -3,22 +3,8 @@ package utils
33
import (
44
"net/http"
55
"strings"
6-
"tinyauth/internal/config"
7-
8-
"github.com/traefik/paerser/parser"
96
)
107

11-
func GetLabels(labels map[string]string) (config.Labels, error) {
12-
var labelsParsed config.Labels
13-
14-
err := parser.Decode(labels, &labelsParsed, "tinyauth", "tinyauth.apps")
15-
if err != nil {
16-
return config.Labels{}, err
17-
}
18-
19-
return labelsParsed, nil
20-
}
21-
228
func ParseHeaders(headers []string) map[string]string {
239
headerMap := make(map[string]string)
2410
for _, header := range headers {

0 commit comments

Comments
 (0)