-
Notifications
You must be signed in to change notification settings - Fork 2
Features and code reorganization to support the KBase Lakehouse #243
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
9102d2e
21f813e
847525c
2da7097
84cecd8
b314752
f5a1828
d42563b
c726d3c
fb66930
33c13c2
de13941
39f2bec
fa723ca
aa11b2f
e65b1c2
5d1d52a
c9c7a9c
2aa7dc3
889dece
dd23b56
4a76621
f6bff15
42b95ab
241610a
e57b79d
f8fbad6
10e2730
b3dfb55
8cdd7ec
90c198b
0fedd83
3e7cdef
d8e5098
955a551
d4395f8
ebbd669
5c181ae
8ae5bfd
65a1ea4
368ace0
d9d3f66
db262a7
15e40d4
b142c4d
7bc0727
c59d8c3
34c864f
8ad8346
4fb0ba8
6359493
a1cb94d
cf9300a
c4bc14e
9fea9b7
a73d28d
9551a4e
9213e32
29f738a
a2a1b1c
0eda402
5a5d4f4
404cb98
7aa5324
31ec0d2
3937d46
2a66b56
f523e3b
8b351db
ac28d7b
64c0915
df69b12
759e32f
045d863
b8ebe52
52bd522
204e90b
964a8f4
df70635
e3977ec
9242a4e
6f36e16
e8fb69d
8e3ad8c
901896c
0f4fbff
aa84441
9adc4cf
33182c2
d790073
c9d8967
70d7e8f
c5dfd90
fe64493
c4fd773
9792079
cff0f17
358d2e7
beb2e99
6ef3553
a88bcda
df8b54b
7a727f5
20a882d
9b55be5
4f58f94
3b17352
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -143,11 +143,12 @@ func (a *Authenticator) readAccessTokenFile() error { | |
| } | ||
|
|
||
| userRecords[token] = User{ | ||
| Name: record[0], | ||
| Email: record[1], | ||
| Orcid: record[2], | ||
| Organization: record[3], | ||
| IsSuper: isSuper, | ||
| Name: record[0], | ||
| Email: record[1], | ||
| Orcid: record[2], | ||
| Organization: record[3], | ||
| IsSuper: isSuper, | ||
| ConnectionCredentials: make(map[string]Credential), | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The file-based access-token auth path always creates
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This is intentional. The KBase auth process is specific to KBase users with tokens, after all--there's no way for someone without a KBase dev token to access the MMS (right?). |
||
| } | ||
| } | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,85 @@ | ||
| // Copyright (c) 2023 The KBase Project and its Contributors | ||
| // Copyright (c) 2023 Cohere Consulting, LLC | ||
| // | ||
| // Permission is hereby granted, free of charge, to any person obtaining a copy of | ||
| // this software and associated documentation files (the "Software"), to deal in | ||
| // the Software without restriction, including without limitation the rights to | ||
| // use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies | ||
| // of the Software, and to permit persons to whom the Software is furnished to do | ||
| // so, subject to the following conditions: | ||
| // | ||
| // The above copyright notice and this permission notice shall be included in all | ||
| // copies or substantial portions of the Software. | ||
| // | ||
| // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR | ||
| // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, | ||
| // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE | ||
| // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER | ||
| // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, | ||
| // OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE | ||
| // SOFTWARE. | ||
|
|
||
| package auth | ||
|
|
||
| import ( | ||
| "encoding/json" | ||
| "fmt" | ||
| "io" | ||
| "net/http" | ||
| "time" | ||
| ) | ||
|
|
||
| // The Minio Management Service (MMS) provide authentication information for a user | ||
| // given a valid KBase token for that user | ||
|
|
||
| type MMSRecord struct { | ||
| Username string `json:"username"` | ||
| S3AccessKey string `json:"s3_access_key"` | ||
| S3SecretKey string `json:"s3_secret_key"` | ||
| PolarisClientId string `json:"polaris_client_id"` | ||
| PolarisClientSecret string `json:"polaris_client_secret"` | ||
| } | ||
|
|
||
| type MMS struct { | ||
| Client http.Client | ||
| } | ||
|
|
||
| func NewMMS() MMS { | ||
| return MMS{ | ||
| Client: http.Client{ | ||
| Timeout: 5 * time.Second, | ||
| }, | ||
| } | ||
| } | ||
|
|
||
| // retrieves the MMS record associated with the given access token | ||
| func (mms MMS) FetchRecord(accessToken string) (MMSRecord, error) { | ||
|
jeff-cohere marked this conversation as resolved.
|
||
| resource := fmt.Sprintf("%s:%d", kbaseMMSUrl, kbaseMMSPort) + "/credentials/" | ||
| request, err := http.NewRequest(http.MethodGet, resource, http.NoBody) | ||
| if err != nil { | ||
| return MMSRecord{}, err | ||
| } | ||
| request.Header.Add("Authorization", fmt.Sprintf("Bearer %s", accessToken)) | ||
| resp, err := mms.Client.Do(request) | ||
| if err != nil { | ||
| return MMSRecord{}, err | ||
| } | ||
| defer resp.Body.Close() | ||
| if resp.StatusCode < http.StatusOK || resp.StatusCode >= http.StatusMultipleChoices { | ||
| return MMSRecord{}, fmt.Errorf("MMS returned HTTP %d", resp.StatusCode) | ||
| } | ||
|
|
||
| body, err := io.ReadAll(resp.Body) | ||
| if err != nil { | ||
| return MMSRecord{}, err | ||
| } | ||
|
|
||
| var record MMSRecord | ||
| err = json.Unmarshal(body, &record) | ||
| return record, err | ||
| } | ||
|
|
||
| const ( | ||
| kbaseMMSUrl = "http://mms.dev" | ||
| kbaseMMSPort = 8000 | ||
| ) | ||
Uh oh!
There was an error while loading. Please reload this page.