cas.go 1.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051
  1. // Copyright 2019 Yunion
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package mcclient
  15. import (
  16. api "yunion.io/x/onecloud/pkg/apis/identity"
  17. "yunion.io/x/onecloud/pkg/httperrors"
  18. )
  19. func (this *Client) AuthenticateCAS(idpId string, ticket, redurectUri string, projectId, projectName, projectDomain string, cliIp string) (TokenCredential, error) {
  20. aCtx := SAuthContext{
  21. // CAS auth must comes from Web
  22. Source: AuthSourceWeb,
  23. Ip: cliIp,
  24. }
  25. return this.authenticateCASWithContext(idpId, ticket, redurectUri, projectId, projectName, projectDomain, aCtx)
  26. }
  27. func (this *Client) authenticateCASWithContext(idpId string, ticket, redirectUri string, projectId, projectName, projectDomain string, aCtx SAuthContext) (TokenCredential, error) {
  28. if this.AuthVersion() != "v3" {
  29. return nil, httperrors.ErrNotSupported
  30. }
  31. input := SAuthenticationInputV3{}
  32. input.Auth.Identity.Id = idpId
  33. input.Auth.Identity.Methods = []string{api.AUTH_METHOD_CAS}
  34. input.Auth.Identity.CASTicket.Id = ticket
  35. input.Auth.Identity.CASTicket.Service = redirectUri
  36. if len(projectId) > 0 {
  37. input.Auth.Scope.Project.Id = projectId
  38. }
  39. if len(projectName) > 0 {
  40. input.Auth.Scope.Project.Name = projectName
  41. if len(projectDomain) > 0 {
  42. input.Auth.Scope.Project.Domain.Name = projectDomain
  43. }
  44. }
  45. input.Auth.Context = aCtx
  46. return this._authV3Input(input)
  47. }