|
1 | 1 | package proxy
|
2 | 2 |
|
3 | 3 | import (
|
| 4 | + apierrors "k8s.io/apimachinery/pkg/api/errors" |
4 | 5 | metainternal "k8s.io/apimachinery/pkg/apis/meta/internalversion"
|
5 | 6 | metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
6 | 7 | "k8s.io/apimachinery/pkg/runtime"
|
7 | 8 | apirequest "k8s.io/apiserver/pkg/endpoints/request"
|
8 | 9 | "k8s.io/apiserver/pkg/registry/rest"
|
| 10 | + "k8s.io/kubernetes/pkg/api" |
| 11 | + "k8s.io/kubernetes/pkg/apis/rbac" |
| 12 | + "k8s.io/kubernetes/pkg/client/clientset_generated/internalclientset/typed/rbac/internalversion" |
9 | 13 |
|
10 |
| - authorizationapi "github.com/openshift/origin/pkg/authorization/apis/authorization" |
11 |
| - clusterpolicybindingregistry "github.com/openshift/origin/pkg/authorization/registry/clusterpolicybinding" |
12 |
| - "github.com/openshift/origin/pkg/authorization/registry/clusterrolebinding" |
13 |
| - rolebindingregistry "github.com/openshift/origin/pkg/authorization/registry/rolebinding" |
14 |
| - rolebindingstorage "github.com/openshift/origin/pkg/authorization/registry/rolebinding/policybased" |
15 |
| - "github.com/openshift/origin/pkg/authorization/rulevalidation" |
| 14 | + authzapi "github.com/openshift/origin/pkg/authorization/apis/authorization" |
16 | 15 | )
|
17 | 16 |
|
18 |
| -type ClusterRoleBindingStorage struct { |
19 |
| - roleBindingStorage rolebindingstorage.VirtualStorage |
| 17 | +func rbacToClusterRoleBinding(in *rbac.ClusterRoleBinding) (authzapi.ClusterRoleBinding, error) { |
| 18 | + var out authzapi.ClusterRoleBinding |
| 19 | + err := authzapi.Convert_rbac_ClusterRoleBinding_To_authorization_ClusterRoleBinding(in, &out, nil) |
| 20 | + return out, err |
20 | 21 | }
|
21 | 22 |
|
22 |
| -func NewClusterRoleBindingStorage(clusterBindingRegistry clusterpolicybindingregistry.Registry, liveRuleResolver, cachedRuleResolver rulevalidation.AuthorizationRuleResolver) clusterrolebinding.Storage { |
23 |
| - return &ClusterRoleBindingStorage{ |
24 |
| - roleBindingStorage: rolebindingstorage.VirtualStorage{ |
25 |
| - BindingRegistry: clusterpolicybindingregistry.NewSimulatedRegistry(clusterBindingRegistry), |
| 23 | +func rbacFromClusterRoleBinding(in *authzapi.ClusterRoleBinding) (rbac.ClusterRoleBinding, error) { |
| 24 | + var out rbac.ClusterRoleBinding |
| 25 | + err := authzapi.Convert_authorization_ClusterRoleBinding_To_rbac_ClusterRoleBinding(in, &out, nil) |
| 26 | + return out, err |
| 27 | +} |
26 | 28 |
|
27 |
| - RuleResolver: liveRuleResolver, |
28 |
| - CachedRuleResolver: cachedRuleResolver, |
| 29 | +type ClusterRoleBindingStorage struct { |
| 30 | + client internalversion.ClusterRoleBindingInterface |
| 31 | +} |
29 | 32 |
|
30 |
| - CreateStrategy: rolebindingregistry.ClusterStrategy, |
31 |
| - UpdateStrategy: rolebindingregistry.ClusterStrategy, |
32 |
| - Resource: authorizationapi.Resource("clusterrolebinding"), |
33 |
| - }, |
34 |
| - } |
| 33 | +func NewREST(client internalversion.ClusterRoleBindingInterface) *ClusterRoleBindingStorage { |
| 34 | + return &ClusterRoleBindingStorage{client} |
35 | 35 | }
|
36 | 36 |
|
37 | 37 | func (s *ClusterRoleBindingStorage) New() runtime.Object {
|
38 |
| - return &authorizationapi.ClusterRoleBinding{} |
| 38 | + return &authzapi.ClusterRoleBinding{} |
39 | 39 | }
|
40 | 40 | func (s *ClusterRoleBindingStorage) NewList() runtime.Object {
|
41 |
| - return &authorizationapi.ClusterRoleBindingList{} |
| 41 | + return &authzapi.ClusterRoleBindingList{} |
42 | 42 | }
|
43 | 43 |
|
44 | 44 | func (s *ClusterRoleBindingStorage) List(ctx apirequest.Context, options *metainternal.ListOptions) (runtime.Object, error) {
|
45 |
| - ret, err := s.roleBindingStorage.List(ctx, options) |
46 |
| - if ret == nil { |
| 45 | + optv1 := metav1.ListOptions{} |
| 46 | + if err := metainternal.Convert_internalversion_ListOptions_To_v1_ListOptions(options, &optv1, nil); err != nil { |
47 | 47 | return nil, err
|
48 | 48 | }
|
49 |
| - return authorizationapi.ToClusterRoleBindingList(ret.(*authorizationapi.RoleBindingList)), err |
| 49 | + roles, err := s.client.List(optv1) |
| 50 | + if roles == nil { |
| 51 | + return nil, err |
| 52 | + } |
| 53 | + ret := &authzapi.ClusterRoleBindingList{} |
| 54 | + for _, curr := range roles.Items { |
| 55 | + role, err := rbacToClusterRoleBinding(&curr) |
| 56 | + if err != nil { |
| 57 | + return nil, err |
| 58 | + } |
| 59 | + ret.Items = append(ret.Items, role) |
| 60 | + } |
| 61 | + return ret, err |
50 | 62 | }
|
51 | 63 |
|
52 | 64 | func (s *ClusterRoleBindingStorage) Get(ctx apirequest.Context, name string, options *metav1.GetOptions) (runtime.Object, error) {
|
53 |
| - ret, err := s.roleBindingStorage.Get(ctx, name, options) |
54 |
| - if ret == nil { |
| 65 | + ret, err := s.client.Get(name, *options) |
| 66 | + if err != nil { |
55 | 67 | return nil, err
|
56 | 68 | }
|
57 |
| - |
58 |
| - return authorizationapi.ToClusterRoleBinding(ret.(*authorizationapi.RoleBinding)), err |
| 69 | + role, err := rbacToClusterRoleBinding(ret) |
| 70 | + if err != nil { |
| 71 | + return nil, err |
| 72 | + } |
| 73 | + return &role, err |
59 | 74 | }
|
| 75 | + |
60 | 76 | func (s *ClusterRoleBindingStorage) Delete(ctx apirequest.Context, name string, options *metav1.DeleteOptions) (runtime.Object, bool, error) {
|
61 |
| - ret, immediate, err := s.roleBindingStorage.Delete(ctx, name, options) |
62 |
| - if ret == nil { |
63 |
| - return nil, immediate, err |
| 77 | + if err := s.client.Delete(name, options); err != nil { |
| 78 | + return nil, false, err |
64 | 79 | }
|
65 | 80 |
|
66 |
| - return ret.(*metav1.Status), false, err |
| 81 | + return &metav1.Status{Status: metav1.StatusSuccess}, true, nil |
67 | 82 | }
|
68 | 83 |
|
69 | 84 | func (s *ClusterRoleBindingStorage) Create(ctx apirequest.Context, obj runtime.Object) (runtime.Object, error) {
|
70 |
| - clusterObj := obj.(*authorizationapi.ClusterRoleBinding) |
71 |
| - convertedObj := authorizationapi.ToRoleBinding(clusterObj) |
| 85 | + clusterObj := obj.(*authzapi.ClusterRoleBinding) |
| 86 | + convertedObj, err := rbacFromClusterRoleBinding(clusterObj) |
72 | 87 |
|
73 |
| - ret, err := s.roleBindingStorage.Create(ctx, convertedObj) |
74 |
| - if ret == nil { |
| 88 | + ret, err := s.client.Create(&convertedObj) |
| 89 | + if err != nil { |
75 | 90 | return nil, err
|
76 | 91 | }
|
77 |
| - |
78 |
| - return authorizationapi.ToClusterRoleBinding(ret.(*authorizationapi.RoleBinding)), err |
79 |
| -} |
80 |
| - |
81 |
| -type convertingObjectInfo struct { |
82 |
| - rest.UpdatedObjectInfo |
83 |
| -} |
84 |
| - |
85 |
| -func (i convertingObjectInfo) UpdatedObject(ctx apirequest.Context, old runtime.Object) (runtime.Object, error) { |
86 |
| - oldObj := old.(*authorizationapi.RoleBinding) |
87 |
| - convertedOldObj := authorizationapi.ToClusterRoleBinding(oldObj) |
88 |
| - obj, err := i.UpdatedObjectInfo.UpdatedObject(ctx, convertedOldObj) |
| 92 | + role, err := rbacToClusterRoleBinding(ret) |
89 | 93 | if err != nil {
|
90 | 94 | return nil, err
|
91 | 95 | }
|
92 |
| - clusterObj := obj.(*authorizationapi.ClusterRoleBinding) |
93 |
| - convertedObj := authorizationapi.ToRoleBinding(clusterObj) |
94 |
| - return convertedObj, nil |
| 96 | + return &role, err |
95 | 97 | }
|
96 | 98 |
|
97 | 99 | func (s *ClusterRoleBindingStorage) Update(ctx apirequest.Context, name string, objInfo rest.UpdatedObjectInfo) (runtime.Object, bool, error) {
|
98 |
| - ret, created, err := s.roleBindingStorage.Update(ctx, name, convertingObjectInfo{objInfo}) |
99 |
| - if ret == nil { |
100 |
| - return nil, created, err |
| 100 | + old, err := s.client.Get(name, metav1.GetOptions{}) |
| 101 | + if err != nil { |
| 102 | + if apierrors.IsNotFound(err) { |
| 103 | + err = apierrors.NewNotFound(rbac.Resource("clusterrolebinding"), name) |
| 104 | + } |
| 105 | + return nil, false, err |
| 106 | + } |
| 107 | + |
| 108 | + oldRoleBinding, err := rbacToClusterRoleBinding(old) |
| 109 | + if err != nil { |
| 110 | + return nil, false, err |
| 111 | + } |
| 112 | + |
| 113 | + obj, err := objInfo.UpdatedObject(ctx, &oldRoleBinding) |
| 114 | + if err != nil { |
| 115 | + return nil, false, err |
| 116 | + } |
| 117 | + |
| 118 | + updatedRoleBinding, err := rbacFromClusterRoleBinding(obj.(*authzapi.ClusterRoleBinding)) |
| 119 | + if err != nil { |
| 120 | + return nil, false, err |
101 | 121 | }
|
102 | 122 |
|
103 |
| - return authorizationapi.ToClusterRoleBinding(ret.(*authorizationapi.RoleBinding)), created, err |
| 123 | + ret, err := s.client.Update(&updatedRoleBinding) |
| 124 | + if err != nil { |
| 125 | + return nil, false, err |
| 126 | + } |
| 127 | + |
| 128 | + role, err := rbacToClusterRoleBinding(ret) |
| 129 | + if err != nil { |
| 130 | + return nil, false, err |
| 131 | + } |
| 132 | + return &role, false, err |
104 | 133 | }
|
105 | 134 |
|
106 |
| -func (m *ClusterRoleBindingStorage) CreateClusterRoleBindingWithEscalation(ctx apirequest.Context, obj *authorizationapi.ClusterRoleBinding) (*authorizationapi.ClusterRoleBinding, error) { |
107 |
| - in := authorizationapi.ToRoleBinding(obj) |
108 |
| - ret, err := m.roleBindingStorage.CreateRoleBindingWithEscalation(ctx, in) |
109 |
| - return authorizationapi.ToClusterRoleBinding(ret), err |
| 135 | +// FIXME: what's escalation exactly ? |
| 136 | +func (m *ClusterRoleBindingStorage) CreateClusterRoleBindingWithEscalation(ctx apirequest.Context, obj *authzapi.ClusterRoleBinding) (*authzapi.ClusterRoleBinding, error) { |
| 137 | + ret, err := m.Create(ctx, obj) |
| 138 | + if err != nil { |
| 139 | + return nil, err |
| 140 | + } |
| 141 | + return ret.(*authzapi.ClusterRoleBinding), err |
110 | 142 | }
|
111 | 143 |
|
112 |
| -func (m *ClusterRoleBindingStorage) UpdateClusterRoleBindingWithEscalation(ctx apirequest.Context, obj *authorizationapi.ClusterRoleBinding) (*authorizationapi.ClusterRoleBinding, bool, error) { |
113 |
| - in := authorizationapi.ToRoleBinding(obj) |
114 |
| - ret, created, err := m.roleBindingStorage.UpdateRoleBindingWithEscalation(ctx, in) |
115 |
| - return authorizationapi.ToClusterRoleBinding(ret), created, err |
| 144 | +func (m *ClusterRoleBindingStorage) UpdateClusterRoleBindingWithEscalation(ctx apirequest.Context, obj *authzapi.ClusterRoleBinding) (*authzapi.ClusterRoleBinding, bool, error) { |
| 145 | + ret, ignored, err := m.Update(ctx, obj.Name, rest.DefaultUpdatedObjectInfo(obj, api.Scheme)) |
| 146 | + if err != nil { |
| 147 | + return nil, false, err |
| 148 | + } |
| 149 | + return ret.(*authzapi.ClusterRoleBinding), ignored, err |
116 | 150 | }
|
0 commit comments