diff options
| author | mo khan <mo@mokhan.ca> | 2025-07-15 16:37:08 -0600 |
|---|---|---|
| committer | mo khan <mo@mokhan.ca> | 2025-07-17 16:30:22 -0600 |
| commit | 45df4d0d9b577fecee798d672695fe24ff57fb1b (patch) | |
| tree | 1b99bf645035b58e0d6db08c7a83521f41f7a75b /vendor/github.com/authzed/grpcutil | |
| parent | f94f79608393d4ab127db63cc41668445ef6b243 (diff) | |
feat: migrate from Cedar to SpiceDB authorization system
This is a major architectural change that replaces the Cedar policy-based
authorization system with SpiceDB's relation-based authorization.
Key changes:
- Migrate from Rust to Go implementation
- Replace Cedar policies with SpiceDB schema and relationships
- Switch from envoy `ext_authz` with Cedar to SpiceDB permission checks
- Update build system and dependencies for Go ecosystem
- Maintain Envoy integration for external authorization
This change enables more flexible permission modeling through SpiceDB's
Google Zanzibar inspired relation-based system, supporting complex
hierarchical permissions that were difficult to express in Cedar.
Breaking change: Existing Cedar policies and Rust-based configuration
will no longer work and need to be migrated to SpiceDB schema.
Diffstat (limited to 'vendor/github.com/authzed/grpcutil')
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/.golangci.yaml | 37 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/.yamllint | 10 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/DCO | 37 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/LICENSE | 201 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/README.md | 5 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/buf.gen.yaml | 12 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/dial_opts.go | 149 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/middleware.go | 118 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/reflection.go | 51 | ||||
| -rw-r--r-- | vendor/github.com/authzed/grpcutil/util.go | 18 |
10 files changed, 638 insertions, 0 deletions
diff --git a/vendor/github.com/authzed/grpcutil/.golangci.yaml b/vendor/github.com/authzed/grpcutil/.golangci.yaml new file mode 100644 index 00000000..f1461b4d --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/.golangci.yaml @@ -0,0 +1,37 @@ +--- +run: + timeout: '5m' +output: + sort-results: true +linters-settings: + goimports: + local-prefixes: 'github.com/authzed/grpcutil' +linters: + enable: + - 'bidichk' + - 'bodyclose' + - 'errcheck' + - 'errname' + - 'errorlint' + - 'gofumpt' + - 'goimports' + - 'goprintffuncname' + - 'gosec' + - 'gosimple' + - 'govet' + - 'importas' + - 'ineffassign' + - 'makezero' + - 'prealloc' + - 'predeclared' + - 'promlinter' + - 'revive' + - 'rowserrcheck' + - 'staticcheck' + - 'stylecheck' + - 'tenv' + - 'typecheck' + - 'unconvert' + - 'unused' + - 'wastedassign' + - 'whitespace' diff --git a/vendor/github.com/authzed/grpcutil/.yamllint b/vendor/github.com/authzed/grpcutil/.yamllint new file mode 100644 index 00000000..9c1e7e32 --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/.yamllint @@ -0,0 +1,10 @@ +# vim: ft=yaml +--- +yaml-files: + - "*.yaml" + - "*.yml" + - ".yamllint" +extends: "default" +rules: + quoted-strings: "enable" + line-length: "disable" diff --git a/vendor/github.com/authzed/grpcutil/DCO b/vendor/github.com/authzed/grpcutil/DCO new file mode 100644 index 00000000..8201f992 --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/DCO @@ -0,0 +1,37 @@ +Developer Certificate of Origin +Version 1.1 + +Copyright (C) 2004, 2006 The Linux Foundation and its contributors. +1 Letterman Drive +Suite D4700 +San Francisco, CA, 94129 + +Everyone is permitted to copy and distribute verbatim copies of this +license document, but changing it is not allowed. + + +Developer's Certificate of Origin 1.1 + +By making a contribution to this project, I certify that: + +(a) The contribution was created in whole or in part by me and I + have the right to submit it under the open source license + indicated in the file; or + +(b) The contribution is based upon previous work that, to the best + of my knowledge, is covered under an appropriate open source + license and I have the right under that license to submit that + work with modifications, whether created in whole or in part + by me, under the same open source license (unless I am + permitted to submit under a different license), as indicated + in the file; or + +(c) The contribution was provided directly to me by some other + person who certified (a), (b) or (c) and I have not modified + it. + +(d) I understand and agree that this project and the contribution + are public and that a record of the contribution (including all + personal information I submit with it, including my sign-off) is + maintained indefinitely and may be redistributed consistent with + this project or the open source license(s) involved. diff --git a/vendor/github.com/authzed/grpcutil/LICENSE b/vendor/github.com/authzed/grpcutil/LICENSE new file mode 100644 index 00000000..261eeb9e --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/LICENSE @@ -0,0 +1,201 @@ + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/vendor/github.com/authzed/grpcutil/README.md b/vendor/github.com/authzed/grpcutil/README.md new file mode 100644 index 00000000..f0b37669 --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/README.md @@ -0,0 +1,5 @@ +# grpcutil + +[](https://godoc.org/github.com/authzed/grpcutil) + +grpcutil implements various utilities to simplify common gRPC APIs. diff --git a/vendor/github.com/authzed/grpcutil/buf.gen.yaml b/vendor/github.com/authzed/grpcutil/buf.gen.yaml new file mode 100644 index 00000000..729faeaf --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/buf.gen.yaml @@ -0,0 +1,12 @@ +#!/usr/bin/env -S go run github.com/bufbuild/buf/cmd/buf generate -o internal/testpb internal/testpb/test.proto --template +--- +version: "v1" +plugins: + - name: 'go' + path: ["go", "run", "google.golang.org/protobuf/cmd/protoc-gen-go"] + out: '.' + opt: 'paths=source_relative' + - name: 'go-grpc' + out: '.' + path: ["go", "run", "google.golang.org/grpc/cmd/protoc-gen-go-grpc"] + opt: 'paths=source_relative' diff --git a/vendor/github.com/authzed/grpcutil/dial_opts.go b/vendor/github.com/authzed/grpcutil/dial_opts.go new file mode 100644 index 00000000..68369d40 --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/dial_opts.go @@ -0,0 +1,149 @@ +// Package grpcutil implements various utilities to simplify common gRPC APIs. +package grpcutil + +import ( + "context" + "crypto/tls" + "crypto/x509" + "errors" + "fmt" + "io/fs" + "os" + + "github.com/certifi/gocertifi" + "google.golang.org/grpc" + "google.golang.org/grpc/credentials" +) + +type verification int + +const ( + // SkipVerifyCA is a constant that improves the readability of functions + // with the insecureSkipVerify parameter. + SkipVerifyCA verification = iota + + // VerifyCA is a constant that improves the readability of functions + // with the insecureSkipVerify parameter. + VerifyCA +) + +func (v verification) asInsecureSkipVerify() bool { + switch v { + case SkipVerifyCA: + return true + case VerifyCA: + return false + default: + panic("unknown verification") + } +} + +// WithSystemCerts returns a grpc.DialOption that uses the system-provided +// certificate authority chain to verify the connection. +// +// If one cannot be found, this falls back to using a vendored version of +// Mozilla's collection of root certificate authorities. +func WithSystemCerts(v verification) (grpc.DialOption, error) { + certPool, err := x509.SystemCertPool() + if err != nil { + // Fall back to Mozilla collection of root CAs. + certPool, err = gocertifi.CACerts() + if err != nil { + // This library promises that this should never occur. + return nil, fmt.Errorf("gocertifi returned an error: %w", err) + } + } + + return grpc.WithTransportCredentials(credentials.NewTLS(&tls.Config{ + RootCAs: certPool, + InsecureSkipVerify: v.asInsecureSkipVerify(), // nolint + })), nil +} + +func forEachFileContents(dirPath string, fn func(contents []byte)) error { + dirFS := os.DirFS(dirPath) + return fs.WalkDir(dirFS, ".", func(path string, d fs.DirEntry, err error) error { + if !d.IsDir() { + contents, err := fs.ReadFile(dirFS, d.Name()) + if err != nil { + return err + } + fn(contents) + } + return nil + }) +} + +// WithCustomCerts returns a grpc.DialOption for requiring TLS that is +// authenticated using a certificate authority chain provided as a path on disk. +// +// If the path is a directory, all files are loaded. +func WithCustomCerts(v verification, certPaths ...string) (grpc.DialOption, error) { + var caFiles [][]byte + for _, certPath := range certPaths { + fi, err := os.Stat(certPath) + if err != nil { + return nil, fmt.Errorf("failed to find certificate: %w", err) + } + + if fi.IsDir() { + if err = forEachFileContents(certPath, func(contents []byte) { + caFiles = append(caFiles, contents) + }); err != nil { + return nil, err + } + } else { + contents, err := os.ReadFile(certPath) + if err != nil { + return nil, err + } + caFiles = append(caFiles, contents) + } + } + + return WithCustomCertBytes(v, caFiles...) +} + +// WithCustomCertBytes returns a grpc.DialOption for requiring TLS that is +// authenticated using a certificate authority chain provided in bytes. +func WithCustomCertBytes(v verification, certsContents ...[]byte) (grpc.DialOption, error) { + certPool := x509.NewCertPool() + for _, certContents := range certsContents { + if ok := certPool.AppendCertsFromPEM(certContents); !ok { + return nil, errors.New("failed to append certs from CA PEM") + } + } + + return grpc.WithTransportCredentials(credentials.NewTLS(&tls.Config{ + RootCAs: certPool, + InsecureSkipVerify: v.asInsecureSkipVerify(), // nolint:gosec + })), nil +} + +type secureMetadataCreds map[string]string + +func (c secureMetadataCreds) RequireTransportSecurity() bool { return true } +func (c secureMetadataCreds) GetRequestMetadata(context.Context, ...string) (map[string]string, error) { + return c, nil +} + +// WithBearerToken returns a grpc.DialOption that adds a standard HTTP Bearer +// token to all requests sent from a client. +func WithBearerToken(token string) grpc.DialOption { + return grpc.WithPerRPCCredentials(secureMetadataCreds{"authorization": "Bearer " + token}) +} + +type insecureMetadataCreds map[string]string + +func (c insecureMetadataCreds) RequireTransportSecurity() bool { return false } +func (c insecureMetadataCreds) GetRequestMetadata(_ context.Context, _ ...string) (map[string]string, error) { + return c, nil +} + +// WithInsecureBearerToken returns a grpc.DialOption that adds a standard HTTP +// Bearer token to all requests sent from an insecure client. +// +// Must be used in conjunction with `insecure.NewCredentials()`. +func WithInsecureBearerToken(token string) grpc.DialOption { + return grpc.WithPerRPCCredentials(insecureMetadataCreds{"authorization": "Bearer " + token}) +} diff --git a/vendor/github.com/authzed/grpcutil/middleware.go b/vendor/github.com/authzed/grpcutil/middleware.go new file mode 100644 index 00000000..052367af --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/middleware.go @@ -0,0 +1,118 @@ +package grpcutil + +import ( + "context" + "fmt" + "strings" + + grpcmw "github.com/grpc-ecosystem/go-grpc-middleware" + grpc_auth "github.com/grpc-ecosystem/go-grpc-middleware/auth" + grpcvalidate "github.com/grpc-ecosystem/go-grpc-middleware/validator" + "google.golang.org/grpc" + "google.golang.org/grpc/health" + healthpb "google.golang.org/grpc/health/grpc_health_v1" +) + +// IgnoreAuthMixin is a struct that can be embedded to make a gRPC handler +// ignore any auth requirements set by the gRPC community auth middleware. +type IgnoreAuthMixin struct{} + +var _ grpc_auth.ServiceAuthFuncOverride = (*IgnoreAuthMixin)(nil) + +// AuthFuncOverride implements the grpc_auth.ServiceAuthFuncOverride by +// performing a no-op. +func (m IgnoreAuthMixin) AuthFuncOverride(ctx context.Context, _ string) (context.Context, error) { + return ctx, nil +} + +// AuthlessHealthServer implements a gRPC health endpoint that will ignore any auth +// requirements set by github.com/grpc-ecosystem/go-grpc-middleware/auth. +type AuthlessHealthServer struct { + *health.Server + IgnoreAuthMixin +} + +// NewAuthlessHealthServer returns a new gRPC health server that ignores auth +// middleware. +func NewAuthlessHealthServer() *AuthlessHealthServer { + return &AuthlessHealthServer{Server: health.NewServer()} +} + +// SetServicesHealthy sets the service to SERVING +func (s *AuthlessHealthServer) SetServicesHealthy(svcDesc ...*grpc.ServiceDesc) { + for _, d := range svcDesc { + s.SetServingStatus( + d.ServiceName, + healthpb.HealthCheckResponse_SERVING, + ) + } +} + +// DefaultUnaryMiddleware is a recommended set of middleware that should each gracefully no-op if the middleware is not +// applicable. +var DefaultUnaryMiddleware = []grpc.UnaryServerInterceptor{grpcvalidate.UnaryServerInterceptor()} + +// WrapMethods wraps all non-streaming endpoints with the given list of interceptors. +// It returns a copy of the ServiceDesc with the new wrapped methods. +func WrapMethods(svcDesc grpc.ServiceDesc, interceptors ...grpc.UnaryServerInterceptor) (wrapped *grpc.ServiceDesc) { + chain := grpcmw.ChainUnaryServer(interceptors...) + for i, m := range svcDesc.Methods { + handler := m.Handler + wrapped := grpc.MethodDesc{ + MethodName: m.MethodName, + Handler: func(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) { + if interceptor == nil { + interceptor = NoopUnaryInterceptor + } + return handler(srv, ctx, dec, grpcmw.ChainUnaryServer(interceptor, chain)) + }, + } + svcDesc.Methods[i] = wrapped + } + return &svcDesc +} + +// WrapStreams wraps all streaming endpoints with the given list of interceptors. +// It returns a copy of the ServiceDesc with the new wrapped methods. +func WrapStreams(svcDesc grpc.ServiceDesc, interceptors ...grpc.StreamServerInterceptor) (wrapped *grpc.ServiceDesc) { + chain := grpcmw.ChainStreamServer(interceptors...) + for i, s := range svcDesc.Streams { + handler := s.Handler + info := &grpc.StreamServerInfo{ + FullMethod: fmt.Sprintf("/%s/%s", svcDesc.ServiceName, s.StreamName), + IsClientStream: s.ClientStreams, + IsServerStream: s.ServerStreams, + } + wrapped := grpc.StreamDesc{ + StreamName: s.StreamName, + ClientStreams: s.ClientStreams, + ServerStreams: s.ServerStreams, + Handler: func(srv interface{}, stream grpc.ServerStream) error { + return chain(srv, stream, info, handler) + }, + } + svcDesc.Streams[i] = wrapped + } + return &svcDesc +} + +// NoopUnaryInterceptor is a gRPC middleware that does not do anything. +func NoopUnaryInterceptor(ctx context.Context, req interface{}, _ *grpc.UnaryServerInfo, handler grpc.UnaryHandler) (resp interface{}, err error) { + return handler(ctx, req) +} + +// SplitMethodName is used to split service name and method name from the +// method string passed into Interceptors. +// +// This function is vendored from: +// https://github.com/grpc-ecosystem/go-grpc-prometheus/blob/82c243799c991a7d5859215fba44a81834a52a71/util.go#L31-L37 +// +// Copyright 2016 Michal Witkowski. All Rights Reserved. +// Apache 2.0 Licensed +func SplitMethodName(fullMethodName string) (string, string) { + fullMethodName = strings.TrimPrefix(fullMethodName, "/") // remove leading slash + if i := strings.Index(fullMethodName, "/"); i >= 0 { + return fullMethodName[:i], fullMethodName[i+1:] + } + return "unknown", "unknown" +} diff --git a/vendor/github.com/authzed/grpcutil/reflection.go b/vendor/github.com/authzed/grpcutil/reflection.go new file mode 100644 index 00000000..092b5680 --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/reflection.go @@ -0,0 +1,51 @@ +package grpcutil + +import ( + "google.golang.org/grpc" + "google.golang.org/grpc/reflection" + rpbv1 "google.golang.org/grpc/reflection/grpc_reflection_v1" + "google.golang.org/grpc/reflection/grpc_reflection_v1alpha" +) + +// NewAuthlessReflectionInterceptor creates a proxy GRPCServer which automatically converts +// ServerReflectionServer instances to ones that skip grpc auth middleware. +// +// change: +// reflection.Register(srv) +// to: +// reflection.Register(grpcutil.NewAuthlessReflectionInterceptor(srv)) +func NewAuthlessReflectionInterceptor(srv reflection.GRPCServer) reflection.GRPCServer { + return interceptingRegistrar{srv} +} + +type interceptingRegistrar struct { + delegate reflection.GRPCServer +} + +func (ir interceptingRegistrar) GetServiceInfo() map[string]grpc.ServiceInfo { + return ir.delegate.GetServiceInfo() +} + +func (ir interceptingRegistrar) RegisterService(desc *grpc.ServiceDesc, impl interface{}) { + reflectionSrvv1, ok := impl.(rpbv1.ServerReflectionServer) + if ok { + ir.delegate.RegisterService(desc, &authlessReflectionV1{ServerReflectionServer: reflectionSrvv1}) + } + + reflectionSrvv1alpha, ok := impl.(grpc_reflection_v1alpha.ServerReflectionServer) + if ok { + ir.delegate.RegisterService(desc, &authlessReflectionV1Alpha{ServerReflectionServer: reflectionSrvv1alpha}) + } +} + +type authlessReflectionV1 struct { + IgnoreAuthMixin + + rpbv1.ServerReflectionServer +} + +type authlessReflectionV1Alpha struct { + IgnoreAuthMixin + + grpc_reflection_v1alpha.ServerReflectionServer +} diff --git a/vendor/github.com/authzed/grpcutil/util.go b/vendor/github.com/authzed/grpcutil/util.go new file mode 100644 index 00000000..65bb3bd5 --- /dev/null +++ b/vendor/github.com/authzed/grpcutil/util.go @@ -0,0 +1,18 @@ +package grpcutil + +import ( + "testing" + + "github.com/stretchr/testify/require" + "google.golang.org/grpc/codes" + "google.golang.org/grpc/status" +) + +// RequireStatus asserts that an error is a gRPC error and returns the expected +// status code. +func RequireStatus(t *testing.T, expected codes.Code, err error) { + require.Error(t, err) + errStatus, ok := status.FromError(err) + require.True(t, ok) + require.Equal(t, expected, errStatus.Code()) +} |
