assume.go 1.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142
  1. // Copyright 2019 Yunion
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package mcclient
  15. import (
  16. api "yunion.io/x/onecloud/pkg/apis/identity"
  17. "yunion.io/x/onecloud/pkg/httperrors"
  18. )
  19. func (client *Client) AuthenticateAssume(token string, userId, projectId string, cliIp string) (TokenCredential, error) {
  20. aCtx := SAuthContext{
  21. // Assume auth must comes from API
  22. Source: AuthSourceAPI,
  23. Ip: cliIp,
  24. }
  25. return client.authenticateAssumeWithContext(token, userId, projectId, aCtx)
  26. }
  27. func (client *Client) authenticateAssumeWithContext(token string, userId, projectId string, aCtx SAuthContext) (TokenCredential, error) {
  28. if client.AuthVersion() != "v3" {
  29. return nil, httperrors.ErrNotSupported
  30. }
  31. input := SAuthenticationInputV3{}
  32. input.Auth.Identity.Token.Id = token
  33. input.Auth.Identity.Methods = []string{api.AUTH_METHOD_ASSUME}
  34. input.Auth.Identity.Assume.User.Id = userId
  35. input.Auth.Scope.Project.Id = projectId
  36. input.Auth.Context = aCtx
  37. return client._authV3Input(input)
  38. }