oauth2.go 1.7 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950
  1. // Copyright 2019 Yunion
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package mcclient
  15. import (
  16. api "yunion.io/x/onecloud/pkg/apis/identity"
  17. "yunion.io/x/onecloud/pkg/httperrors"
  18. )
  19. func (this *Client) AuthenticateOAuth2(idpId, code string, projectId, projectName, projectDomain string, cliIp string) (TokenCredential, error) {
  20. aCtx := SAuthContext{
  21. // OAuth2 auth must comes from Web
  22. Source: AuthSourceWeb,
  23. Ip: cliIp,
  24. }
  25. return this.authenticateOAuth2WithContext(idpId, code, projectId, projectName, projectDomain, aCtx)
  26. }
  27. func (this *Client) authenticateOAuth2WithContext(idpId, code string, projectId, projectName, projectDomain string, aCtx SAuthContext) (TokenCredential, error) {
  28. if this.AuthVersion() != "v3" {
  29. return nil, httperrors.ErrNotSupported
  30. }
  31. input := SAuthenticationInputV3{}
  32. input.Auth.Identity.Methods = []string{api.AUTH_METHOD_OAuth2}
  33. input.Auth.Identity.Id = idpId
  34. input.Auth.Identity.OAuth2.Code = code
  35. if len(projectId) > 0 {
  36. input.Auth.Scope.Project.Id = projectId
  37. }
  38. if len(projectName) > 0 {
  39. input.Auth.Scope.Project.Name = projectName
  40. if len(projectDomain) > 0 {
  41. input.Auth.Scope.Project.Domain.Name = projectDomain
  42. }
  43. }
  44. input.Auth.Context = aCtx
  45. return this._authV3Input(input)
  46. }