Welcome to mirror list, hosted at ThFree Co, Russian Federation.

gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGitLab Bot <gitlab-bot@gitlab.com>2021-10-20 11:43:02 +0300
committerGitLab Bot <gitlab-bot@gitlab.com>2021-10-20 11:43:02 +0300
commitd9ab72d6080f594d0b3cae15f14b3ef2c6c638cb (patch)
tree2341ef426af70ad1e289c38036737e04b0aa5007 /lib/gitlab/auth
parentd6e514dd13db8947884cd58fe2a9c2a063400a9b (diff)
Add latest changes from gitlab-org/gitlab@14-4-stable-eev14.4.0-rc42
Diffstat (limited to 'lib/gitlab/auth')
-rw-r--r--lib/gitlab/auth/request_authenticator.rb25
1 files changed, 24 insertions, 1 deletions
diff --git a/lib/gitlab/auth/request_authenticator.rb b/lib/gitlab/auth/request_authenticator.rb
index 08214bbd449..1a9259a4f0e 100644
--- a/lib/gitlab/auth/request_authenticator.rb
+++ b/lib/gitlab/auth/request_authenticator.rb
@@ -30,7 +30,8 @@ module Gitlab
end
def find_sessionless_user(request_format)
- find_user_from_web_access_token(request_format, scopes: [:api, :read_api]) ||
+ find_user_from_dependency_proxy_token ||
+ find_user_from_web_access_token(request_format, scopes: [:api, :read_api]) ||
find_user_from_feed_token(request_format) ||
find_user_from_static_object_token(request_format) ||
find_user_from_basic_auth_job ||
@@ -82,6 +83,28 @@ module Gitlab
basic_auth_personal_access_token: api_request? || git_request?
}
end
+
+ def find_user_from_dependency_proxy_token
+ return unless dependency_proxy_request?
+
+ token, _ = ActionController::HttpAuthentication::Token.token_and_options(current_request)
+
+ return unless token
+
+ user_or_deploy_token = ::DependencyProxy::AuthTokenService.user_or_deploy_token_from_jwt(token)
+
+ # Do not return deploy tokens
+ # See https://gitlab.com/gitlab-org/gitlab/-/issues/342481
+ return unless user_or_deploy_token.is_a?(::User)
+
+ user_or_deploy_token
+ rescue ActiveRecord::RecordNotFound
+ nil # invalid id used return no user
+ end
+
+ def dependency_proxy_request?
+ Gitlab::PathRegex.dependency_proxy_route_regex.match?(current_request.path)
+ end
end
end
end