2023-03-13 15:14:18 +01:00
|
|
|
package http
|
|
|
|
|
|
|
|
import (
|
|
|
|
"encoding/json"
|
|
|
|
"net/http"
|
2023-06-07 08:57:43 +02:00
|
|
|
"strconv"
|
2023-03-13 15:14:18 +01:00
|
|
|
|
|
|
|
"github.com/gorilla/mux"
|
|
|
|
"github.com/rs/xid"
|
|
|
|
|
|
|
|
"github.com/netbirdio/netbird/management/server"
|
|
|
|
"github.com/netbirdio/netbird/management/server/http/api"
|
|
|
|
"github.com/netbirdio/netbird/management/server/http/util"
|
|
|
|
"github.com/netbirdio/netbird/management/server/jwtclaims"
|
|
|
|
"github.com/netbirdio/netbird/management/server/status"
|
|
|
|
)
|
|
|
|
|
|
|
|
// Policies is a handler that returns policy of the account
|
|
|
|
type Policies struct {
|
|
|
|
accountManager server.AccountManager
|
|
|
|
claimsExtractor *jwtclaims.ClaimsExtractor
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewPoliciesHandler creates a new Policies handler
|
|
|
|
func NewPoliciesHandler(accountManager server.AccountManager, authCfg AuthCfg) *Policies {
|
|
|
|
return &Policies{
|
|
|
|
accountManager: accountManager,
|
|
|
|
claimsExtractor: jwtclaims.NewClaimsExtractor(
|
|
|
|
jwtclaims.WithAudience(authCfg.Audience),
|
|
|
|
jwtclaims.WithUserIDClaim(authCfg.UserIDClaim),
|
|
|
|
),
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// GetAllPolicies list for the account
|
|
|
|
func (h *Policies) GetAllPolicies(w http.ResponseWriter, r *http.Request) {
|
|
|
|
claims := h.claimsExtractor.FromRequestContext(r)
|
2024-07-03 11:33:02 +02:00
|
|
|
account, user, err := h.accountManager.GetAccountFromToken(r.Context(), claims)
|
2023-03-13 15:14:18 +01:00
|
|
|
if err != nil {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
accountPolicies, err := h.accountManager.ListPolicies(r.Context(), account.Id, user.Id)
|
2023-03-13 15:14:18 +01:00
|
|
|
if err != nil {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-05-29 16:00:18 +02:00
|
|
|
policies := []*api.Policy{}
|
|
|
|
for _, policy := range accountPolicies {
|
|
|
|
resp := toPolicyResponse(account, policy)
|
|
|
|
if len(resp.Rules) == 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.Internal, "no rules in the policy"), w)
|
2023-05-29 16:00:18 +02:00
|
|
|
return
|
|
|
|
}
|
|
|
|
policies = append(policies, resp)
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteJSONObject(r.Context(), w, policies)
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// UpdatePolicy handles update to a policy identified by a given ID
|
|
|
|
func (h *Policies) UpdatePolicy(w http.ResponseWriter, r *http.Request) {
|
|
|
|
claims := h.claimsExtractor.FromRequestContext(r)
|
2024-07-03 11:33:02 +02:00
|
|
|
account, user, err := h.accountManager.GetAccountFromToken(r.Context(), claims)
|
2023-03-13 15:14:18 +01:00
|
|
|
if err != nil {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
vars := mux.Vars(r)
|
2023-05-03 00:15:25 +02:00
|
|
|
policyID := vars["policyId"]
|
2023-03-13 15:14:18 +01:00
|
|
|
if len(policyID) == 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "invalid policy ID"), w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
policyIdx := -1
|
|
|
|
for i, policy := range account.Policies {
|
|
|
|
if policy.ID == policyID {
|
|
|
|
policyIdx = i
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if policyIdx < 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.NotFound, "couldn't find policy id %s", policyID), w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-05-29 16:00:18 +02:00
|
|
|
h.savePolicy(w, r, account, user, policyID)
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// CreatePolicy handles policy creation request
|
|
|
|
func (h *Policies) CreatePolicy(w http.ResponseWriter, r *http.Request) {
|
|
|
|
claims := h.claimsExtractor.FromRequestContext(r)
|
2024-07-03 11:33:02 +02:00
|
|
|
account, user, err := h.accountManager.GetAccountFromToken(r.Context(), claims)
|
2023-03-13 15:14:18 +01:00
|
|
|
if err != nil {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-05-29 16:00:18 +02:00
|
|
|
h.savePolicy(w, r, account, user, "")
|
|
|
|
}
|
|
|
|
|
|
|
|
// savePolicy handles policy creation and update
|
|
|
|
func (h *Policies) savePolicy(
|
|
|
|
w http.ResponseWriter,
|
|
|
|
r *http.Request,
|
|
|
|
account *server.Account,
|
|
|
|
user *server.User,
|
|
|
|
policyID string,
|
|
|
|
) {
|
|
|
|
var req api.PutApiPoliciesPolicyIdJSONRequestBody
|
|
|
|
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
2023-03-13 15:14:18 +01:00
|
|
|
util.WriteErrorResponse("couldn't parse JSON request", http.StatusBadRequest, w)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if req.Name == "" {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "policy name shouldn't be empty"), w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-05-29 16:00:18 +02:00
|
|
|
if len(req.Rules) == 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "policy rules shouldn't be empty"), w)
|
2023-05-29 16:00:18 +02:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if policyID == "" {
|
|
|
|
policyID = xid.New().String()
|
|
|
|
}
|
|
|
|
|
|
|
|
policy := server.Policy{
|
|
|
|
ID: policyID,
|
2023-03-13 15:14:18 +01:00
|
|
|
Name: req.Name,
|
|
|
|
Enabled: req.Enabled,
|
|
|
|
Description: req.Description,
|
|
|
|
}
|
2024-07-03 11:33:02 +02:00
|
|
|
for _, rule := range req.Rules {
|
2023-05-29 16:00:18 +02:00
|
|
|
pr := server.PolicyRule{
|
2024-07-03 11:33:02 +02:00
|
|
|
ID: policyID, // TODO: when policy can contain multiple rules, need refactor
|
|
|
|
Name: rule.Name,
|
|
|
|
Destinations: groupMinimumsToStrings(account, rule.Destinations),
|
|
|
|
Sources: groupMinimumsToStrings(account, rule.Sources),
|
|
|
|
Bidirectional: rule.Bidirectional,
|
2023-05-29 16:00:18 +02:00
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
pr.Enabled = rule.Enabled
|
|
|
|
if rule.Description != nil {
|
|
|
|
pr.Description = *rule.Description
|
2023-05-29 16:00:18 +02:00
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
switch rule.Action {
|
2023-05-29 16:00:18 +02:00
|
|
|
case api.PolicyRuleUpdateActionAccept:
|
|
|
|
pr.Action = server.PolicyTrafficActionAccept
|
|
|
|
case api.PolicyRuleUpdateActionDrop:
|
|
|
|
pr.Action = server.PolicyTrafficActionDrop
|
|
|
|
default:
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "unknown action type"), w)
|
2023-05-29 16:00:18 +02:00
|
|
|
return
|
|
|
|
}
|
2023-03-13 15:14:18 +01:00
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
switch rule.Protocol {
|
2023-05-29 16:00:18 +02:00
|
|
|
case api.PolicyRuleUpdateProtocolAll:
|
|
|
|
pr.Protocol = server.PolicyRuleProtocolALL
|
|
|
|
case api.PolicyRuleUpdateProtocolTcp:
|
|
|
|
pr.Protocol = server.PolicyRuleProtocolTCP
|
|
|
|
case api.PolicyRuleUpdateProtocolUdp:
|
|
|
|
pr.Protocol = server.PolicyRuleProtocolUDP
|
|
|
|
case api.PolicyRuleUpdateProtocolIcmp:
|
|
|
|
pr.Protocol = server.PolicyRuleProtocolICMP
|
|
|
|
default:
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "unknown protocol type: %v", rule.Protocol), w)
|
2023-05-29 16:00:18 +02:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
if rule.Ports != nil && len(*rule.Ports) != 0 {
|
|
|
|
for _, v := range *rule.Ports {
|
2023-06-07 08:57:43 +02:00
|
|
|
if port, err := strconv.Atoi(v); err != nil || port < 1 || port > 65535 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "valid port value is in 1..65535 range"), w)
|
2023-06-07 08:57:43 +02:00
|
|
|
return
|
|
|
|
}
|
|
|
|
pr.Ports = append(pr.Ports, v)
|
|
|
|
}
|
2023-05-29 16:00:18 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// validate policy object
|
|
|
|
switch pr.Protocol {
|
|
|
|
case server.PolicyRuleProtocolALL, server.PolicyRuleProtocolICMP:
|
|
|
|
if len(pr.Ports) != 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "for ALL or ICMP protocol ports is not allowed"), w)
|
2023-05-29 16:00:18 +02:00
|
|
|
return
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
2023-05-29 16:00:18 +02:00
|
|
|
if !pr.Bidirectional {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "for ALL or ICMP protocol type flow can be only bi-directional"), w)
|
2023-05-29 16:00:18 +02:00
|
|
|
return
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
2023-05-29 16:00:18 +02:00
|
|
|
case server.PolicyRuleProtocolTCP, server.PolicyRuleProtocolUDP:
|
|
|
|
if !pr.Bidirectional && len(pr.Ports) == 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "for ALL or ICMP protocol type flow can be only bi-directional"), w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
2023-05-29 16:00:18 +02:00
|
|
|
|
|
|
|
policy.Rules = append(policy.Rules, &pr)
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
2023-05-29 16:00:18 +02:00
|
|
|
|
2024-02-20 09:59:56 +01:00
|
|
|
if req.SourcePostureChecks != nil {
|
|
|
|
policy.SourcePostureChecks = sourcePostureChecksToStrings(account, *req.SourcePostureChecks)
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
if err := h.accountManager.SavePolicy(r.Context(), account.Id, user.Id, &policy); err != nil {
|
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-05-29 16:00:18 +02:00
|
|
|
resp := toPolicyResponse(account, &policy)
|
|
|
|
if len(resp.Rules) == 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.Internal, "no rules in the policy"), w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteJSONObject(r.Context(), w, resp)
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// DeletePolicy handles policy deletion request
|
|
|
|
func (h *Policies) DeletePolicy(w http.ResponseWriter, r *http.Request) {
|
|
|
|
claims := h.claimsExtractor.FromRequestContext(r)
|
2024-07-03 11:33:02 +02:00
|
|
|
account, user, err := h.accountManager.GetAccountFromToken(r.Context(), claims)
|
2023-03-13 15:14:18 +01:00
|
|
|
if err != nil {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
aID := account.Id
|
|
|
|
|
|
|
|
vars := mux.Vars(r)
|
2023-05-03 00:15:25 +02:00
|
|
|
policyID := vars["policyId"]
|
2023-03-13 15:14:18 +01:00
|
|
|
if len(policyID) == 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "invalid policy ID"), w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
if err = h.accountManager.DeletePolicy(r.Context(), aID, policyID, user.Id); err != nil {
|
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteJSONObject(r.Context(), w, emptyObject{})
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// GetPolicy handles a group Get request identified by ID
|
|
|
|
func (h *Policies) GetPolicy(w http.ResponseWriter, r *http.Request) {
|
|
|
|
claims := h.claimsExtractor.FromRequestContext(r)
|
2024-07-03 11:33:02 +02:00
|
|
|
account, user, err := h.accountManager.GetAccountFromToken(r.Context(), claims)
|
2023-03-13 15:14:18 +01:00
|
|
|
if err != nil {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
switch r.Method {
|
|
|
|
case http.MethodGet:
|
|
|
|
vars := mux.Vars(r)
|
2023-05-03 00:15:25 +02:00
|
|
|
policyID := vars["policyId"]
|
2023-03-13 15:14:18 +01:00
|
|
|
if len(policyID) == 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.InvalidArgument, "invalid policy ID"), w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
policy, err := h.accountManager.GetPolicy(r.Context(), account.Id, policyID, user.Id)
|
2023-03-13 15:14:18 +01:00
|
|
|
if err != nil {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), err, w)
|
2023-03-13 15:14:18 +01:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2023-05-29 16:00:18 +02:00
|
|
|
resp := toPolicyResponse(account, policy)
|
|
|
|
if len(resp.Rules) == 0 {
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.Internal, "no rules in the policy"), w)
|
2023-05-29 16:00:18 +02:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteJSONObject(r.Context(), w, resp)
|
2023-03-13 15:14:18 +01:00
|
|
|
default:
|
2024-07-03 11:33:02 +02:00
|
|
|
util.WriteError(r.Context(), status.Errorf(status.NotFound, "method not found"), w)
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func toPolicyResponse(account *server.Account, policy *server.Policy) *api.Policy {
|
|
|
|
cache := make(map[string]api.GroupMinimum)
|
|
|
|
ap := &api.Policy{
|
2024-02-20 09:59:56 +01:00
|
|
|
Id: &policy.ID,
|
|
|
|
Name: policy.Name,
|
|
|
|
Description: policy.Description,
|
|
|
|
Enabled: policy.Enabled,
|
|
|
|
SourcePostureChecks: policy.SourcePostureChecks,
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
|
|
|
for _, r := range policy.Rules {
|
2023-12-04 13:34:06 +01:00
|
|
|
rID := r.ID
|
|
|
|
rDescription := r.Description
|
2023-03-13 15:14:18 +01:00
|
|
|
rule := api.PolicyRule{
|
2023-12-04 13:34:06 +01:00
|
|
|
Id: &rID,
|
2023-05-29 16:00:18 +02:00
|
|
|
Name: r.Name,
|
|
|
|
Enabled: r.Enabled,
|
2023-12-04 13:34:06 +01:00
|
|
|
Description: &rDescription,
|
2023-05-29 16:00:18 +02:00
|
|
|
Bidirectional: r.Bidirectional,
|
|
|
|
Protocol: api.PolicyRuleProtocol(r.Protocol),
|
|
|
|
Action: api.PolicyRuleAction(r.Action),
|
|
|
|
}
|
|
|
|
if len(r.Ports) != 0 {
|
2023-11-27 16:40:02 +01:00
|
|
|
portsCopy := r.Ports
|
2023-05-29 16:00:18 +02:00
|
|
|
rule.Ports = &portsCopy
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
|
|
|
for _, gid := range r.Sources {
|
|
|
|
_, ok := cache[gid]
|
|
|
|
if ok {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if group, ok := account.Groups[gid]; ok {
|
|
|
|
minimum := api.GroupMinimum{
|
|
|
|
Id: group.ID,
|
|
|
|
Name: group.Name,
|
|
|
|
PeersCount: len(group.Peers),
|
|
|
|
}
|
|
|
|
rule.Sources = append(rule.Sources, minimum)
|
|
|
|
cache[gid] = minimum
|
|
|
|
}
|
|
|
|
}
|
|
|
|
for _, gid := range r.Destinations {
|
|
|
|
cachedMinimum, ok := cache[gid]
|
|
|
|
if ok {
|
|
|
|
rule.Destinations = append(rule.Destinations, cachedMinimum)
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if group, ok := account.Groups[gid]; ok {
|
|
|
|
minimum := api.GroupMinimum{
|
|
|
|
Id: group.ID,
|
|
|
|
Name: group.Name,
|
|
|
|
PeersCount: len(group.Peers),
|
|
|
|
}
|
|
|
|
rule.Destinations = append(rule.Destinations, minimum)
|
|
|
|
cache[gid] = minimum
|
|
|
|
}
|
|
|
|
}
|
|
|
|
ap.Rules = append(ap.Rules, rule)
|
|
|
|
}
|
|
|
|
return ap
|
|
|
|
}
|
|
|
|
|
2023-05-29 16:00:18 +02:00
|
|
|
func groupMinimumsToStrings(account *server.Account, gm []string) []string {
|
2023-03-13 15:14:18 +01:00
|
|
|
result := make([]string, 0, len(gm))
|
2023-05-29 16:00:18 +02:00
|
|
|
for _, g := range gm {
|
|
|
|
if _, ok := account.Groups[g]; !ok {
|
2023-03-13 15:14:18 +01:00
|
|
|
continue
|
|
|
|
}
|
2023-05-29 16:00:18 +02:00
|
|
|
result = append(result, g)
|
2023-03-13 15:14:18 +01:00
|
|
|
}
|
|
|
|
return result
|
|
|
|
}
|
2024-02-20 09:59:56 +01:00
|
|
|
|
|
|
|
func sourcePostureChecksToStrings(account *server.Account, postureChecksIds []string) []string {
|
|
|
|
result := make([]string, 0, len(postureChecksIds))
|
|
|
|
for _, id := range postureChecksIds {
|
|
|
|
for _, postureCheck := range account.PostureChecks {
|
|
|
|
if id == postureCheck.ID {
|
|
|
|
result = append(result, id)
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
return result
|
|
|
|
}
|