tokencache.go 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209
  1. // Copyright 2019 Yunion
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package models
  15. import (
  16. "context"
  17. "fmt"
  18. "sort"
  19. "strings"
  20. "time"
  21. "yunion.io/x/log"
  22. "yunion.io/x/pkg/errors"
  23. "yunion.io/x/pkg/util/timeutils"
  24. "yunion.io/x/sqlchemy"
  25. api "yunion.io/x/onecloud/pkg/apis/identity"
  26. "yunion.io/x/onecloud/pkg/cloudcommon/db"
  27. "yunion.io/x/onecloud/pkg/keystone/cache"
  28. "yunion.io/x/onecloud/pkg/mcclient"
  29. "yunion.io/x/onecloud/pkg/util/logclient"
  30. )
  31. var TokenCacheManager *STokenCacheManager
  32. func init() {
  33. TokenCacheManager = &STokenCacheManager{
  34. SStandaloneAnonResourceBaseManager: db.NewStandaloneAnonResourceBaseManager(
  35. STokenCache{},
  36. "token_cache_tbl",
  37. "token_cache",
  38. "token_caches",
  39. ),
  40. }
  41. TokenCacheManager.SetVirtualObject(TokenCacheManager)
  42. TokenCacheManager.TableSpec().AddIndex(false, "deleted", "valid")
  43. }
  44. type STokenCache struct {
  45. db.SStandaloneAnonResourceBase
  46. // Token string `width:"700" charset:"ascii" nullable:"false" primary:"true"`
  47. ExpiredAt time.Time `nullable:"false"`
  48. Valid bool
  49. Method string `width:"32" charset:"ascii"`
  50. AuditIds string `width:"512" charset:"utf8" index:"true"`
  51. UserId string `width:"128" charset:"ascii" nullable:"false"`
  52. ProjectId string `width:"128" charset:"ascii" nullable:"true"`
  53. DomainId string `width:"128" charset:"ascii" nullable:"true"`
  54. Source string `width:"16" charset:"ascii"`
  55. Ip string `width:"64" charset:"ascii"`
  56. }
  57. type STokenCacheManager struct {
  58. db.SStandaloneAnonResourceBaseManager
  59. }
  60. func joinAuditIds(ids []string) string {
  61. sort.Strings(ids)
  62. return strings.Join(ids, ",")
  63. }
  64. func (manager *STokenCacheManager) Save(ctx context.Context, tokenStr string, expiredAt time.Time, method string, auditIds []string, userId, projId, domainId, source, ip string) error {
  65. return manager.insert(ctx, tokenStr, expiredAt, true, method, auditIds, userId, projId, domainId, source, ip)
  66. }
  67. func (manager *STokenCacheManager) Invalidate(ctx context.Context, userCred mcclient.TokenCredential, tokenStr string) error {
  68. token, err := manager.FetchToken(tokenStr)
  69. if err != nil {
  70. return errors.Wrap(err, "FetchToken")
  71. }
  72. err = token.invalidate(ctx, userCred)
  73. if err != nil {
  74. return errors.Wrap(err, "token.invalidate")
  75. }
  76. return nil
  77. }
  78. func (manager *STokenCacheManager) BatchInvalidateByUserId(ctx context.Context, userCred mcclient.TokenCredential, uid string) error {
  79. return manager.batchInvalidateInternal(ctx, userCred, func(q *sqlchemy.SQuery) *sqlchemy.SQuery {
  80. q = q.Equals("user_id", uid)
  81. return q
  82. })
  83. }
  84. func (manager *STokenCacheManager) BatchInvalidate(ctx context.Context, userCred mcclient.TokenCredential, method string, auditIds []string) error {
  85. return manager.batchInvalidateInternal(ctx, userCred, func(q *sqlchemy.SQuery) *sqlchemy.SQuery {
  86. q = q.Equals("method", method).Equals("audit_ids", joinAuditIds(auditIds))
  87. return q
  88. })
  89. }
  90. func (manager *STokenCacheManager) batchInvalidateInternal(ctx context.Context, userCred mcclient.TokenCredential, filter func(q *sqlchemy.SQuery) *sqlchemy.SQuery) error {
  91. q := manager.Query().IsTrue("valid")
  92. q = filter(q)
  93. tokens := make([]STokenCache, 0)
  94. err := db.FetchModelObjects(manager, q, &tokens)
  95. if err != nil {
  96. return errors.Wrap(err, "FetchModelObjects")
  97. }
  98. if len(tokens) == 0 {
  99. return nil
  100. }
  101. errs := make([]error, 0)
  102. for i := range tokens {
  103. token := tokens[i]
  104. err := token.invalidate(ctx, userCred)
  105. if err != nil {
  106. errs = append(errs, errors.Wrapf(err, "batchInvalidateInternal token %s", token.Id))
  107. }
  108. }
  109. if len(errs) > 0 {
  110. return errors.NewAggregate(errs)
  111. }
  112. return nil
  113. }
  114. func (manager *STokenCacheManager) insert(ctx context.Context, token string, expiredAt time.Time, valid bool, method string, auditIds []string, userId, projectId, domainId, source, ip string) error {
  115. val := STokenCache{
  116. SStandaloneAnonResourceBase: db.SStandaloneAnonResourceBase{
  117. Id: token,
  118. },
  119. ExpiredAt: expiredAt,
  120. Valid: valid,
  121. Method: method,
  122. AuditIds: joinAuditIds(auditIds),
  123. UserId: userId,
  124. ProjectId: projectId,
  125. DomainId: domainId,
  126. Source: source,
  127. Ip: ip,
  128. }
  129. val.SetModelManager(manager, &val)
  130. err := manager.TableSpec().InsertOrUpdate(ctx, &val)
  131. return errors.Wrap(err, "InsertOrUpdate")
  132. }
  133. func (manager *STokenCacheManager) FetchToken(tokenStr string) (*STokenCache, error) {
  134. obj, err := manager.FetchById(tokenStr)
  135. if err != nil {
  136. return nil, errors.Wrap(err, "FetchById")
  137. }
  138. return obj.(*STokenCache), nil
  139. }
  140. func (manager *STokenCacheManager) removeObsolete() error {
  141. sql := fmt.Sprintf("DELETE FROM %s WHERE expired_at < ?", manager.TableSpec().Name())
  142. db := sqlchemy.GetDBWithName(manager.TableSpec().GetDBName())
  143. now := timeutils.UtcNow()
  144. _, err := db.Exec(sql, now.Add(-24*time.Hour))
  145. return errors.Wrap(err, "Exec Delete")
  146. }
  147. func RemoveObsoleteInvalidTokens(ctx context.Context, userCred mcclient.TokenCredential, start bool) {
  148. err := TokenCacheManager.removeObsolete()
  149. if err != nil {
  150. log.Errorf("RemoveObsoleteInvalidTokens fail %s", err)
  151. }
  152. }
  153. func (manager *STokenCacheManager) FetchInvalidTokens() ([]string, error) {
  154. q := manager.Query("id").IsFalse("valid")
  155. tokens := make([]STokenCache, 0)
  156. err := db.FetchModelObjects(manager, q, &tokens)
  157. if err != nil {
  158. return nil, errors.Wrap(err, "FetchModelObjects")
  159. }
  160. ret := make([]string, len(tokens))
  161. for i := range tokens {
  162. ret[i] = tokens[i].Id
  163. }
  164. return ret, nil
  165. }
  166. func (token *STokenCache) invalidate(ctx context.Context, userCred mcclient.TokenCredential) error {
  167. err := TokenCacheManager.BatchInvalidate(ctx, userCred, api.AUTH_METHOD_TOKEN, []string{token.Id})
  168. if err != nil {
  169. return errors.Wrapf(err, "BatchInvalidate subtoken %s", token.Id)
  170. }
  171. _, err = db.Update(token, func() error {
  172. token.Valid = false
  173. return nil
  174. })
  175. if err != nil {
  176. return errors.Wrap(err, "update")
  177. }
  178. cache.Remove(token.Id)
  179. logclient.AddActionLogWithContext(ctx, token, logclient.ACT_DELETE, token.GetShortDesc(ctx), userCred, true)
  180. return nil
  181. }