XRootD
Loading...
Searching...
No Matches
XrdMacaroons.cc
Go to the documentation of this file.
3
4#include "XrdOuc/XrdOucEnv.hh"
7#include "XrdOuc/XrdOucEnv.hh"
12#include "XrdVersion.hh"
13
14#include <stdexcept>
15#include <dlfcn.h>
16
20
21// Trick to access compiled version and directly call for the default object
22// is taken from xrootd-scitokens.
23static XrdVERSIONINFODEF(compiledVer, XrdAccTest, XrdVNUMBER, XrdVERSION);
25 const char *cfn,
26 const char *parm,
27 XrdVersionInfo &myVer);
28
30
31extern "C" {
32
33XrdEXPORT
35 const char *config,
36 const char *params,
37 XrdOucEnv * /*not used*/,
38 XrdAccAuthorize * chain_authz)
39{
40 try
41 {
42 auto new_authz = new Macaroons::Authz(log, config, chain_authz);
43 SciTokensHelper = new_authz;
44 return new_authz;
45 }
46 catch (std::runtime_error &e)
47 {
48 XrdSysError err(log, "macaroons");
49 err.Emsg("Config", "Configuration of Macaroon authorization handler failed", e.what());
50 return nullptr;
51 }
52}
53
54XrdEXPORT
56 const char *config,
57 const char *parms)
58{
59 XrdAccAuthorize *chain_authz = nullptr;
60 XrdSysError err(log, "macaroons");
61
62 if (parms && parms[0]) {
63 XrdOucString parms_str(parms);
64 XrdOucString chained_lib;
65 int from = parms_str.tokenize(chained_lib, 0, ' ');
66 const char *chained_parms = nullptr;
67 err.Emsg("Config", "Will chain library", chained_lib.c_str());
68 if (from > 0)
69 {
70 parms_str.erasefromstart(from);
71 if (parms_str.length())
72 {
73 err.Emsg("Config", "Will chain parameters", parms_str.c_str());
74 chained_parms = parms_str.c_str();
75 }
76 }
77 char resolvePath[2048];
78 bool usedAltPath{true};
79 if (!XrdOucPinPath(chained_lib.c_str(), usedAltPath, resolvePath, 2048)) {
80 err.Emsg("Config", "Failed to locate appropriately versioned chained auth library:", parms);
81 return nullptr;
82 }
83 void *handle_base = dlopen(resolvePath, RTLD_LOCAL|RTLD_NOW);
84 if (handle_base == nullptr) {
85 err.Emsg("Config", "Failed to base plugin ", resolvePath, dlerror());
86 return nullptr;
87 }
88
89 XrdAccAuthorize *(*ep)(XrdSysLogger *, const char *, const char *);
90 ep = (XrdAccAuthorize *(*)(XrdSysLogger *, const char *, const char *))
91 (dlsym(handle_base, "XrdAccAuthorizeObject"));
92 if (!ep)
93 {
94 dlclose(handle_base);
95 err.Emsg("Config", "Unable to chain second authlib after macaroons", parms);
96 return nullptr;
97 }
98
99 chain_authz = (*ep)(log, config, chained_parms);
100
101 if (chain_authz == nullptr) {
102 dlclose(handle_base);
103 err.Emsg("Config", "Unable to chain second authlib after macaroons "
104 "which returned nullptr");
105 return nullptr;
106 }
107 }
108 else
109 {
110 chain_authz = XrdAccDefaultAuthorizeObject(log, config, parms, compiledVer);
111 }
112 try
113 {
114 auto new_authz = new Macaroons::Authz(log, config, chain_authz);
115 SciTokensHelper = new_authz;
116 return new_authz;
117 }
118 catch (const std::runtime_error &e)
119 {
120 err.Emsg("Config", "Configuration of Macaroon authorization handler failed", e.what());
121 return nullptr;
122 }
123}
124
125
126XrdEXPORT
128 XrdSysError *log, const char * config,
129 const char * parms, XrdOucEnv *env)
130{
131 void *authz_raw = env->GetPtr("XrdAccAuthorize*");
132 XrdAccAuthorize *def_authz = static_cast<XrdAccAuthorize *>(authz_raw);
133
134 log->Emsg("Initialize", "Creating new Macaroon handler object");
135 try
136 {
137 return new Macaroons::Handler(log, config, env, def_authz);
138 }
139 catch (std::runtime_error &e)
140 {
141 log->Emsg("Config", "Generation of Macaroon handler failed", e.what());
142 return nullptr;
143 }
144}
145
146
147}
XrdVERSIONINFO(XrdClGetPlugIn, XrdClGetPlugIn) extern "C"
XrdAccAuthorize * XrdAccDefaultAuthorizeObject(XrdSysLogger *lp, const char *cfn, const char *parm, XrdVersionInfo &urVer)
XrdHttpExtHandler * XrdHttpGetExtHandler(XrdHttpExtHandlerArgs)
static XrdVERSIONINFODEF(compiledVer, XrdAccTest, XrdVNUMBER, XrdVERSION)
XrdEXPORT XrdAccAuthorize * XrdAccAuthorizeObject(XrdSysLogger *log, const char *config, const char *parms)
XrdEXPORT XrdAccAuthorize * XrdAccAuthorizeObjAdd(XrdSysLogger *log, const char *config, const char *params, XrdOucEnv *, XrdAccAuthorize *chain_authz)
XrdEXPORT XrdSciTokensHelper * SciTokensHelper
int XrdOucPinPath(const char *piPath, bool &noAltP, char *buff, int blen)
void * GetPtr(const char *varname)
Definition XrdOucEnv.cc:263
int erasefromstart(int sz=0)
int length() const
int tokenize(XrdOucString &tok, int from, char del=':')
const char * c_str() const
int Emsg(const char *esfx, int ecode, const char *text1, const char *text2=0)