-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Fix spicedb throwing on invalid arguments #20269
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -58,6 +58,15 @@ import { ApplicationError, ErrorCodes } from "@gitpod/gitpod-protocol/lib/messag | |
| import { ContextService } from "../workspace/context-service"; | ||
| import { UserService } from "../user/user-service"; | ||
| import { ContextParser } from "../workspace/context-parser-service"; | ||
| import { workspaceIDRegex } from "@gitpod/gitpod-protocol/lib/util/gitpod-host-url"; | ||
|
|
||
| const isWorkspaceId = (workspaceId?: string) => { | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This kind of method should ideally be part of |
||
| if (!workspaceId) { | ||
| return false; | ||
| } | ||
|
|
||
| return workspaceIDRegex.test(workspaceId); | ||
| }; | ||
|
|
||
| @injectable() | ||
| export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceInterface> { | ||
|
|
@@ -68,8 +77,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| @inject(ContextParser) private contextParser: ContextParser; | ||
|
|
||
| async getWorkspace(req: GetWorkspaceRequest, _: HandlerContext): Promise<GetWorkspaceResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| const info = await this.workspaceService.getWorkspace(ctxUserId(), req.workspaceId); | ||
| const response = new GetWorkspaceResponse(); | ||
|
|
@@ -198,8 +207,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
|
|
||
| async startWorkspace(req: StartWorkspaceRequest): Promise<StartWorkspaceResponse> { | ||
| // We rely on FGA to do the permission checking | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| const user = await this.userService.findUserById(ctxUserId(), ctxUserId()); | ||
| const { workspace, latestInstance: instance } = await this.workspaceService.getWorkspace( | ||
|
|
@@ -227,8 +236,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| req: GetWorkspaceDefaultImageRequest, | ||
| _: HandlerContext, | ||
| ): Promise<GetWorkspaceDefaultImageResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| const result = await this.workspaceService.getWorkspaceDefaultImage(ctxUserId(), req.workspaceId); | ||
| const response = new GetWorkspaceDefaultImageResponse({ | ||
|
|
@@ -246,8 +255,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| } | ||
|
|
||
| async sendHeartBeat(req: SendHeartBeatRequest, _: HandlerContext): Promise<SendHeartBeatResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| const info = await this.workspaceService.getWorkspace(ctxUserId(), req.workspaceId); | ||
| if (!info.latestInstance?.id || info.latestInstance.status.phase !== "running") { | ||
|
|
@@ -265,8 +274,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| req: GetWorkspaceOwnerTokenRequest, | ||
| _: HandlerContext, | ||
| ): Promise<GetWorkspaceOwnerTokenResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| const ownerToken = await this.workspaceService.getOwnerToken(ctxUserId(), req.workspaceId); | ||
| const response = new GetWorkspaceOwnerTokenResponse(); | ||
|
|
@@ -278,8 +287,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| req: GetWorkspaceEditorCredentialsRequest, | ||
| _: HandlerContext, | ||
| ): Promise<GetWorkspaceEditorCredentialsResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| const credentials = await this.workspaceService.getIDECredentials(ctxUserId(), req.workspaceId); | ||
| const response = new GetWorkspaceEditorCredentialsResponse(); | ||
|
|
@@ -288,8 +297,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| } | ||
|
|
||
| async updateWorkspace(req: UpdateWorkspaceRequest): Promise<UpdateWorkspaceResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| if (req.spec?.timeout?.inactivity?.seconds || (req.spec?.sshPublicKeys && req.spec?.sshPublicKeys.length > 0)) { | ||
| throw new ApplicationError(ErrorCodes.UNIMPLEMENTED, "not implemented"); | ||
|
|
@@ -363,17 +372,17 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| } | ||
|
|
||
| async stopWorkspace(req: StopWorkspaceRequest): Promise<StopWorkspaceResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| await this.workspaceService.stopWorkspace(ctxUserId(), req.workspaceId, "stopped via API"); | ||
| const response = new StopWorkspaceResponse(); | ||
| return response; | ||
| } | ||
|
|
||
| async deleteWorkspace(req: DeleteWorkspaceRequest): Promise<DeleteWorkspaceResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| await this.workspaceService.deleteWorkspace(ctxUserId(), req.workspaceId, "user"); | ||
| const response = new DeleteWorkspaceResponse(); | ||
|
|
@@ -389,8 +398,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| } | ||
|
|
||
| async createWorkspaceSnapshot(req: CreateWorkspaceSnapshotRequest): Promise<CreateWorkspaceSnapshotResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| const snapshot = await this.workspaceService.takeSnapshot(ctxUserId(), { | ||
| workspaceId: req.workspaceId, | ||
|
|
@@ -410,8 +419,8 @@ export class WorkspaceServiceAPI implements ServiceImpl<typeof WorkspaceServiceI | |
| } | ||
|
|
||
| async updateWorkspacePort(req: UpdateWorkspacePortRequest): Promise<UpdateWorkspacePortResponse> { | ||
| if (!req.workspaceId) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "workspaceId is required"); | ||
| if (!isWorkspaceId(req.workspaceId)) { | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🧡 |
||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "a valid workspaceId is required"); | ||
| } | ||
| if (!req.port) { | ||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, "port is required"); | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -15,6 +15,7 @@ import { base64decode } from "@jmondi/oauth2-server"; | |
| import { DecodedZedToken } from "@gitpod/spicedb-impl/lib/impl/v1/impl.pb"; | ||
| import { ctxTryGetCache, ctxTrySetCache } from "../util/request-context"; | ||
| import { ApplicationError, ErrorCodes } from "@gitpod/gitpod-protocol/lib/messaging/error"; | ||
| import { isGrpcError } from "@gitpod/gitpod-protocol/lib/util/grpc"; | ||
|
|
||
| async function tryThree<T>(errMessage: string, code: (attempt: number) => Promise<T>): Promise<T> { | ||
| let attempt = 0; | ||
|
|
@@ -104,6 +105,9 @@ export class SpiceDBAuthorizer { | |
| const permitted = response.permissionship === v1.CheckPermissionResponse_Permissionship.HAS_PERMISSION; | ||
| return { permitted, checkedAt: response.checkedAt?.token }; | ||
| } catch (err) { | ||
| if (isGrpcError(err) && err.code === grpc.status.INVALID_ARGUMENT) { | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Please add a comment on the "why"/context 🙏 |
||
| throw new ApplicationError(ErrorCodes.BAD_REQUEST, `Invalid request for permission check: ${err}`); | ||
| } | ||
| error = err; | ||
| log.error("[spicedb] Failed to perform authorization check.", err, { | ||
| request: new TrustedValue(req), | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🫧 I wonder where this regex comes from... it hopefully is identical with this one?
@filiptronicek Could you check whether we can easily unify something here? 🤔 The code I cited should be the source of truth.