2026-04-09 00:10:38 +08:00
|
|
|
use super::super::internal;
|
|
|
|
|
use crate::admin_api;
|
2026-05-07 23:48:29 +08:00
|
|
|
use crate::audit::attach_admin_audit_event;
|
|
|
|
|
use crate::control::{
|
|
|
|
|
validate_management_token_admin_route_permission, GatewayPublicRequestContext,
|
|
|
|
|
};
|
2026-04-05 20:23:16 +08:00
|
|
|
use crate::{AppState, GatewayError};
|
2026-04-04 01:40:24 +08:00
|
|
|
use axum::body::{Body, Bytes};
|
2026-05-07 23:48:29 +08:00
|
|
|
use axum::http::{self, Response};
|
|
|
|
|
use axum::response::IntoResponse;
|
|
|
|
|
use axum::Json;
|
|
|
|
|
use serde_json::json;
|
|
|
|
|
use tracing::warn;
|
2026-04-03 14:59:58 +08:00
|
|
|
|
|
|
|
|
pub(super) async fn maybe_build_local_internal_proxy_response(
|
2026-03-31 19:19:04 +08:00
|
|
|
state: &AppState,
|
|
|
|
|
request_context: &GatewayPublicRequestContext,
|
|
|
|
|
remote_addr: &std::net::SocketAddr,
|
2026-04-04 01:40:24 +08:00
|
|
|
request_body: Option<&Bytes>,
|
2026-03-31 19:19:04 +08:00
|
|
|
) -> Result<Option<Response<Body>>, GatewayError> {
|
2026-04-04 01:40:24 +08:00
|
|
|
internal::maybe_build_local_internal_proxy_response_impl(
|
2026-03-31 19:19:04 +08:00
|
|
|
state,
|
|
|
|
|
request_context,
|
|
|
|
|
remote_addr,
|
|
|
|
|
request_body,
|
|
|
|
|
)
|
2026-04-04 01:40:24 +08:00
|
|
|
.await
|
2026-03-31 19:19:04 +08:00
|
|
|
}
|
|
|
|
|
|
2026-04-03 14:59:58 +08:00
|
|
|
pub(super) async fn maybe_build_local_admin_proxy_response(
|
2026-03-31 19:19:04 +08:00
|
|
|
state: &AppState,
|
|
|
|
|
request_context: &GatewayPublicRequestContext,
|
2026-04-04 01:40:24 +08:00
|
|
|
request_body: Option<&Bytes>,
|
2026-03-31 19:19:04 +08:00
|
|
|
) -> Result<Option<Response<Body>>, GatewayError> {
|
|
|
|
|
let Some(decision) = request_context.control_decision.as_ref() else {
|
|
|
|
|
return Ok(None);
|
|
|
|
|
};
|
|
|
|
|
if decision.route_class.as_deref() != Some("admin_proxy") {
|
|
|
|
|
return Ok(None);
|
|
|
|
|
}
|
|
|
|
|
if decision.admin_principal.is_none() {
|
|
|
|
|
return Ok(None);
|
|
|
|
|
}
|
2026-05-07 23:48:29 +08:00
|
|
|
if let Some(response) = maybe_build_management_token_permission_denied_response(request_context)
|
|
|
|
|
{
|
|
|
|
|
return Ok(Some(response));
|
|
|
|
|
}
|
2026-03-31 19:19:04 +08:00
|
|
|
|
2026-04-09 00:10:38 +08:00
|
|
|
admin_api::maybe_build_local_admin_response(admin_api::AdminRouteRequest::new(
|
2026-04-07 02:50:19 +08:00
|
|
|
state,
|
|
|
|
|
request_context,
|
|
|
|
|
request_body,
|
2026-04-09 00:10:38 +08:00
|
|
|
))
|
|
|
|
|
.await
|
2026-03-31 19:19:04 +08:00
|
|
|
}
|
2026-05-07 23:48:29 +08:00
|
|
|
|
|
|
|
|
fn maybe_build_management_token_permission_denied_response(
|
|
|
|
|
request_context: &GatewayPublicRequestContext,
|
|
|
|
|
) -> Option<Response<Body>> {
|
|
|
|
|
let decision = request_context.control_decision.as_ref()?;
|
|
|
|
|
let admin_principal = decision.admin_principal.as_ref()?;
|
|
|
|
|
let token_id = admin_principal.management_token_id.as_deref()?;
|
|
|
|
|
let denied = validate_management_token_admin_route_permission(
|
|
|
|
|
&request_context.request_method,
|
|
|
|
|
decision,
|
|
|
|
|
admin_principal.management_token_permissions.as_deref(),
|
|
|
|
|
)
|
|
|
|
|
.err()?;
|
|
|
|
|
|
|
|
|
|
warn!(
|
|
|
|
|
trace_id = %request_context.trace_id,
|
|
|
|
|
admin_management_token_id = %token_id,
|
|
|
|
|
route_family = decision.route_family.as_deref().unwrap_or("unknown"),
|
|
|
|
|
route_kind = decision.route_kind.as_deref().unwrap_or("unknown"),
|
|
|
|
|
required_permission = %denied.required_permission,
|
|
|
|
|
"management token permission denied"
|
|
|
|
|
);
|
|
|
|
|
|
|
|
|
|
let mut response = (
|
|
|
|
|
http::StatusCode::FORBIDDEN,
|
|
|
|
|
Json(json!({
|
|
|
|
|
"detail": "management token permission denied",
|
|
|
|
|
"required_permission": denied.required_permission,
|
|
|
|
|
"route_family": decision.route_family.as_deref(),
|
|
|
|
|
"route_kind": decision.route_kind.as_deref(),
|
|
|
|
|
"request_path": request_context.request_path,
|
|
|
|
|
})),
|
|
|
|
|
)
|
|
|
|
|
.into_response();
|
|
|
|
|
attach_admin_audit_event(
|
|
|
|
|
&mut response,
|
|
|
|
|
"admin_management_token_permission_denied",
|
|
|
|
|
"permission_denied",
|
|
|
|
|
"management_token_permission",
|
|
|
|
|
token_id,
|
|
|
|
|
);
|
|
|
|
|
Some(response)
|
|
|
|
|
}
|