Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ edition = "2021"
license = "MIT"
name = "pg_doorman"
rust-version = "1.87.0"
version = "3.11.1"
version = "3.11.2"

[profile.release]
codegen-units = 1
Expand Down
14 changes: 14 additions & 0 deletions documentation/en/src/changelog.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,19 @@
# Changelog

### 3.11.2

#### Talos routes `s2i|`-prefixed clients through a service pool

For `user=talos`, the pool-user selection now also understands
`s2i|`-prefixed `clientId`s. In addition to `clientId`, `srv-<clientId>`
and the max token role (`owner`, `read_write`, `read_only`), pg_doorman
checks a pool user named `srv-<service-name>` where `service-name` is
the part of the `clientId` after the `|` separator. For a `clientId` of
`s2i|test-service` the pool user checked is `srv-test-service`.

Selection order: `clientId`, `srv-<clientId>`, `srv-<service-name>`
(for `s2i|`-prefixed `clientId`), then the max token role.

### 3.11.1

#### Pool-level `sync_server_parameters` override
Expand Down
46 changes: 43 additions & 3 deletions src/auth/talos.rs
Original file line number Diff line number Diff line change
Expand Up @@ -117,10 +117,18 @@ pub fn resolve_talos_user(
source: TalosUserSource::Personal,
};
}
let service_name = format!("srv-{client_id}");
if pool_exists(pool_name, &service_name) {
let service_name_by_client_id = format!("srv-{client_id}");
if pool_exists(pool_name, &service_name_by_client_id) {
return TalosResolution {
username: service_name,
username: service_name_by_client_id,
source: TalosUserSource::ServicePool,
};
}
let parsed_service_name = client_id.split("|").nth(1).unwrap_or(client_id);
let service_account = format!("srv-{parsed_service_name}");
if pool_exists(pool_name, &service_account) {
return TalosResolution {
username: service_account,
source: TalosUserSource::ServicePool,
};
}
Expand Down Expand Up @@ -615,6 +623,38 @@ mod tests {
assert_eq!(resolved.username, "srv-billing-api");
}

#[test]
fn resolve_service_pool_from_prefixed_client_id() {
let resolved =
resolve_talos_user("billing_db", "s2i|test-service", Role::Owner, |db, user| {
db == "billing_db" && user == "srv-test-service"
});
assert_eq!(resolved.source, TalosUserSource::ServicePool);
assert_eq!(resolved.username, "srv-test-service");
}

#[test]
fn resolve_service_pool_from_prefixed_client_id_respects_max_role() {
let resolved = resolve_talos_user(
"billing_db",
"s2i|test-service",
Role::ReadWrite,
|db, user| db == "billing_db" && user == "srv-test-service",
);
assert_eq!(resolved.source, TalosUserSource::ServicePool);
assert_eq!(resolved.username, "srv-test-service");
}

#[test]
fn resolve_falls_back_to_max_role_when_service_account_missing() {
let resolved =
resolve_talos_user("billing_db", "s2i|test-service", Role::ReadWrite, |_, _| {
false
});
assert_eq!(resolved.source, TalosUserSource::MaxRole);
assert_eq!(resolved.username, "read_write");
}

#[test]
fn resolve_falls_through_to_max_role() {
let resolved = resolve_talos_user("billing_db", "billing-api", Role::Owner, |_, _| false);
Expand Down
Loading