auth.go 1.9 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364
  1. // Copyright 2020 guylewin, guy@lewin.co.il
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package auth
  15. import (
  16. "fmt"
  17. v1 "github.com/fatedier/frp/pkg/config/v1"
  18. "github.com/fatedier/frp/pkg/msg"
  19. )
  20. type Setter interface {
  21. SetLogin(*msg.Login) error
  22. SetPing(*msg.Ping) error
  23. SetNewWorkConn(*msg.NewWorkConn) error
  24. }
  25. func NewAuthSetter(cfg v1.AuthClientConfig) (authProvider Setter, err error) {
  26. switch cfg.Method {
  27. case v1.AuthMethodToken:
  28. authProvider = NewTokenAuth(cfg.AdditionalScopes, cfg.Token)
  29. case v1.AuthMethodOIDC:
  30. if cfg.OIDC.TokenSource != nil {
  31. authProvider = NewOidcTokenSourceAuthSetter(cfg.AdditionalScopes, cfg.OIDC.TokenSource)
  32. } else {
  33. authProvider, err = NewOidcAuthSetter(cfg.AdditionalScopes, cfg.OIDC)
  34. if err != nil {
  35. return nil, err
  36. }
  37. }
  38. default:
  39. return nil, fmt.Errorf("unsupported auth method: %s", cfg.Method)
  40. }
  41. return authProvider, nil
  42. }
  43. type Verifier interface {
  44. VerifyLogin(*msg.Login) error
  45. VerifyPing(*msg.Ping) error
  46. VerifyNewWorkConn(*msg.NewWorkConn) error
  47. }
  48. func NewAuthVerifier(cfg v1.AuthServerConfig) (authVerifier Verifier) {
  49. switch cfg.Method {
  50. case v1.AuthMethodToken:
  51. authVerifier = NewTokenAuth(cfg.AdditionalScopes, cfg.Token)
  52. case v1.AuthMethodOIDC:
  53. tokenVerifier := NewTokenVerifier(cfg.OIDC)
  54. authVerifier = NewOidcAuthVerifier(cfg.AdditionalScopes, tokenVerifier)
  55. }
  56. return authVerifier
  57. }