2014-08-06 00:05:59 +00:00
|
|
|
package consul
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
2014-08-08 23:00:32 +00:00
|
|
|
"time"
|
|
|
|
|
2014-08-06 00:05:59 +00:00
|
|
|
"github.com/armon/go-metrics"
|
2014-08-08 23:00:32 +00:00
|
|
|
"github.com/hashicorp/consul/acl"
|
2014-08-06 00:05:59 +00:00
|
|
|
"github.com/hashicorp/consul/consul/structs"
|
2016-01-29 19:42:34 +00:00
|
|
|
"github.com/hashicorp/go-uuid"
|
2014-08-06 00:05:59 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// ACL endpoint is used to manipulate ACLs
|
|
|
|
type ACL struct {
|
|
|
|
srv *Server
|
|
|
|
}
|
|
|
|
|
2016-08-03 05:04:11 +00:00
|
|
|
// aclApplyInternal is used to apply an ACL request after it has been vetted that
|
|
|
|
// this is a valid operation. It is used when users are updating ACLs, in which
|
|
|
|
// case we check their token to make sure they have management privileges. It is
|
|
|
|
// also used for ACL replication. We want to run the replicated ACLs through the
|
|
|
|
// same checks on the change itself. If an operation needs to generate an ID,
|
|
|
|
// routine will fill in an ID with the args as part of the request.
|
|
|
|
func aclApplyInternal(srv *Server, args *structs.ACLRequest, reply *string) error {
|
2014-08-06 17:30:47 +00:00
|
|
|
switch args.Op {
|
|
|
|
case structs.ACLSet:
|
|
|
|
// Verify the ACL type
|
|
|
|
switch args.ACL.Type {
|
|
|
|
case structs.ACLTypeClient:
|
|
|
|
case structs.ACLTypeManagement:
|
|
|
|
default:
|
|
|
|
return fmt.Errorf("Invalid ACL Type")
|
|
|
|
}
|
|
|
|
|
2014-08-22 21:55:09 +00:00
|
|
|
// Verify this is not a root ACL
|
|
|
|
if acl.RootACL(args.ACL.ID) != nil {
|
|
|
|
return fmt.Errorf("%s: Cannot modify root ACL", permissionDenied)
|
|
|
|
}
|
|
|
|
|
2014-08-08 23:00:32 +00:00
|
|
|
// Validate the rules compile
|
|
|
|
_, err := acl.Parse(args.ACL.Rules)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("ACL rule compilation failed: %v", err)
|
|
|
|
}
|
2014-08-06 00:05:59 +00:00
|
|
|
|
2015-05-06 02:19:45 +00:00
|
|
|
// If no ID is provided, generate a new ID. This must
|
2014-10-09 19:23:32 +00:00
|
|
|
// be done prior to appending to the raft log, because the ID is not
|
|
|
|
// deterministic. Once the entry is in the log, the state update MUST
|
|
|
|
// be deterministic or the followers will not converge.
|
2015-05-06 02:19:45 +00:00
|
|
|
if args.ACL.ID == "" {
|
2016-08-03 05:04:11 +00:00
|
|
|
state := srv.fsm.State()
|
2014-10-09 19:23:32 +00:00
|
|
|
for {
|
2016-01-29 19:42:34 +00:00
|
|
|
if args.ACL.ID, err = uuid.GenerateUUID(); err != nil {
|
2016-08-03 05:04:11 +00:00
|
|
|
srv.logger.Printf("[ERR] consul.acl: UUID generation failed: %v", err)
|
2016-01-29 19:42:34 +00:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2015-10-14 02:18:43 +00:00
|
|
|
_, acl, err := state.ACLGet(args.ACL.ID)
|
2014-10-09 19:23:32 +00:00
|
|
|
if err != nil {
|
2016-08-03 05:04:11 +00:00
|
|
|
srv.logger.Printf("[ERR] consul.acl: ACL lookup failed: %v", err)
|
2014-10-09 19:23:32 +00:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
if acl == nil {
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-08-06 17:30:47 +00:00
|
|
|
case structs.ACLDelete:
|
|
|
|
if args.ACL.ID == "" {
|
|
|
|
return fmt.Errorf("Missing ACL ID")
|
2014-08-22 21:55:09 +00:00
|
|
|
} else if args.ACL.ID == anonymousToken {
|
|
|
|
return fmt.Errorf("%s: Cannot delete anonymous token", permissionDenied)
|
2014-08-06 17:30:47 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
default:
|
|
|
|
return fmt.Errorf("Invalid ACL Operation")
|
2014-08-06 00:05:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Apply the update
|
2016-08-03 05:04:11 +00:00
|
|
|
resp, err := srv.raftApply(structs.ACLRequestType, args)
|
2014-08-06 00:05:59 +00:00
|
|
|
if err != nil {
|
2016-08-03 05:04:11 +00:00
|
|
|
srv.logger.Printf("[ERR] consul.acl: Apply failed: %v", err)
|
2014-08-06 00:05:59 +00:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
if respErr, ok := resp.(error); ok {
|
|
|
|
return respErr
|
|
|
|
}
|
|
|
|
|
2016-08-03 05:04:11 +00:00
|
|
|
// Check if the return type is a string
|
|
|
|
if respString, ok := resp.(string); ok {
|
|
|
|
*reply = respString
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Apply is used to apply a modifying request to the data store. This should
|
|
|
|
// only be used for operations that modify the data
|
|
|
|
func (a *ACL) Apply(args *structs.ACLRequest, reply *string) error {
|
|
|
|
if done, err := a.srv.forward("ACL.Apply", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
defer metrics.MeasureSince([]string{"consul", "acl", "apply"}, time.Now())
|
|
|
|
|
|
|
|
// Verify we are allowed to serve this request
|
|
|
|
if a.srv.config.ACLDatacenter != a.srv.config.Datacenter {
|
|
|
|
return fmt.Errorf(aclDisabled)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Verify token is permitted to modify ACLs
|
|
|
|
if acl, err := a.srv.resolveToken(args.Token); err != nil {
|
|
|
|
return err
|
|
|
|
} else if acl == nil || !acl.ACLModify() {
|
|
|
|
return permissionDeniedErr
|
|
|
|
}
|
|
|
|
|
|
|
|
// Do the apply now that this update is vetted.
|
|
|
|
if err := aclApplyInternal(a.srv, args, reply); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2014-08-18 22:23:02 +00:00
|
|
|
// Clear the cache if applicable
|
|
|
|
if args.ACL.ID != "" {
|
|
|
|
a.srv.aclAuthCache.ClearACL(args.ACL.ID)
|
|
|
|
}
|
|
|
|
|
2014-08-06 00:05:59 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get is used to retrieve a single ACL
|
|
|
|
func (a *ACL) Get(args *structs.ACLSpecificRequest,
|
|
|
|
reply *structs.IndexedACLs) error {
|
|
|
|
if done, err := a.srv.forward("ACL.Get", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2014-08-12 22:32:44 +00:00
|
|
|
// Verify we are allowed to serve this request
|
|
|
|
if a.srv.config.ACLDatacenter != a.srv.config.Datacenter {
|
|
|
|
return fmt.Errorf(aclDisabled)
|
|
|
|
}
|
|
|
|
|
2014-08-06 00:05:59 +00:00
|
|
|
// Get the local state
|
2015-10-13 05:21:39 +00:00
|
|
|
state := a.srv.fsm.State()
|
|
|
|
return a.srv.blockingRPC(&args.QueryOptions,
|
2014-08-06 00:05:59 +00:00
|
|
|
&reply.QueryMeta,
|
2015-10-13 03:12:13 +00:00
|
|
|
state.GetQueryWatch("ACLGet"),
|
2014-08-06 00:05:59 +00:00
|
|
|
func() error {
|
2015-10-14 02:18:43 +00:00
|
|
|
index, acl, err := state.ACLGet(args.ACL)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
reply.Index = index
|
2014-08-06 00:05:59 +00:00
|
|
|
if acl != nil {
|
|
|
|
reply.ACLs = structs.ACLs{acl}
|
2015-01-13 20:02:30 +00:00
|
|
|
} else {
|
|
|
|
reply.ACLs = nil
|
2014-08-06 00:05:59 +00:00
|
|
|
}
|
2015-10-14 02:18:43 +00:00
|
|
|
return nil
|
2014-08-06 00:05:59 +00:00
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2016-08-04 00:01:32 +00:00
|
|
|
// makeACLETag returns an ETag for the given parent and policy.
|
|
|
|
func makeACLETag(parent string, policy *acl.Policy) string {
|
|
|
|
return fmt.Sprintf("%s:%s", parent, policy.ID)
|
|
|
|
}
|
|
|
|
|
2014-08-08 22:32:43 +00:00
|
|
|
// GetPolicy is used to retrieve a compiled policy object with a TTL. Does not
|
|
|
|
// support a blocking query.
|
2014-08-08 23:55:47 +00:00
|
|
|
func (a *ACL) GetPolicy(args *structs.ACLPolicyRequest, reply *structs.ACLPolicy) error {
|
2014-08-08 22:32:43 +00:00
|
|
|
if done, err := a.srv.forward("ACL.GetPolicy", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2014-08-12 22:32:44 +00:00
|
|
|
// Verify we are allowed to serve this request
|
|
|
|
if a.srv.config.ACLDatacenter != a.srv.config.Datacenter {
|
|
|
|
return fmt.Errorf(aclDisabled)
|
|
|
|
}
|
|
|
|
|
2014-08-08 22:32:43 +00:00
|
|
|
// Get the policy via the cache
|
2014-08-12 17:54:56 +00:00
|
|
|
parent, policy, err := a.srv.aclAuthCache.GetACLPolicy(args.ACL)
|
2014-08-08 22:32:43 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2014-08-08 23:55:47 +00:00
|
|
|
// Generate an ETag
|
2014-08-08 22:52:52 +00:00
|
|
|
conf := a.srv.config
|
2016-08-04 00:01:32 +00:00
|
|
|
etag := makeACLETag(parent, policy)
|
2014-08-08 23:55:47 +00:00
|
|
|
|
|
|
|
// Setup the response
|
|
|
|
reply.ETag = etag
|
2014-08-08 22:52:52 +00:00
|
|
|
reply.TTL = conf.ACLTTL
|
2014-08-08 22:32:43 +00:00
|
|
|
a.srv.setQueryMeta(&reply.QueryMeta)
|
2014-08-08 23:55:47 +00:00
|
|
|
|
|
|
|
// Only send the policy on an Etag mis-match
|
|
|
|
if args.ETag != etag {
|
2014-08-12 17:54:56 +00:00
|
|
|
reply.Parent = parent
|
2014-08-08 23:55:47 +00:00
|
|
|
reply.Policy = policy
|
|
|
|
}
|
2014-08-08 22:32:43 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2014-08-06 00:05:59 +00:00
|
|
|
// List is used to list all the ACLs
|
|
|
|
func (a *ACL) List(args *structs.DCSpecificRequest,
|
|
|
|
reply *structs.IndexedACLs) error {
|
|
|
|
if done, err := a.srv.forward("ACL.List", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2014-08-12 22:32:44 +00:00
|
|
|
// Verify we are allowed to serve this request
|
|
|
|
if a.srv.config.ACLDatacenter != a.srv.config.Datacenter {
|
|
|
|
return fmt.Errorf(aclDisabled)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Verify token is permitted to list ACLs
|
|
|
|
if acl, err := a.srv.resolveToken(args.Token); err != nil {
|
|
|
|
return err
|
|
|
|
} else if acl == nil || !acl.ACLList() {
|
|
|
|
return permissionDeniedErr
|
|
|
|
}
|
|
|
|
|
2014-08-06 00:05:59 +00:00
|
|
|
// Get the local state
|
2015-10-13 05:21:39 +00:00
|
|
|
state := a.srv.fsm.State()
|
|
|
|
return a.srv.blockingRPC(&args.QueryOptions,
|
2014-08-06 00:05:59 +00:00
|
|
|
&reply.QueryMeta,
|
2015-10-13 03:12:13 +00:00
|
|
|
state.GetQueryWatch("ACLList"),
|
2014-08-06 00:05:59 +00:00
|
|
|
func() error {
|
2015-10-14 02:18:43 +00:00
|
|
|
index, acls, err := state.ACLList()
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
reply.Index, reply.ACLs = index, acls
|
|
|
|
return nil
|
2014-08-06 00:05:59 +00:00
|
|
|
})
|
|
|
|
}
|
2016-08-05 04:32:36 +00:00
|
|
|
|
|
|
|
// ReplicationStatus is used to retrieve the current ACL replication status.
|
|
|
|
func (a *ACL) ReplicationStatus(args *structs.DCSpecificRequest,
|
|
|
|
reply *structs.ACLReplicationStatus) error {
|
|
|
|
// This must be sent to the leader, so we fix the args since we are
|
|
|
|
// re-using a structure where we don't support all the options.
|
|
|
|
args.RequireConsistent = true
|
|
|
|
args.AllowStale = false
|
|
|
|
if done, err := a.srv.forward("ACL.ReplicationStatus", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// There's no ACL token required here since this doesn't leak any
|
|
|
|
// sensitive information, and we don't want people to have to use
|
|
|
|
// management tokens if they are querying this via a health check.
|
|
|
|
|
|
|
|
// Poll the latest status.
|
|
|
|
a.srv.aclReplicationStatusLock.RLock()
|
|
|
|
*reply = a.srv.aclReplicationStatus
|
|
|
|
a.srv.aclReplicationStatusLock.RUnlock()
|
|
|
|
return nil
|
|
|
|
}
|