github.com/greenpau/go-authcrunch@v1.1.4/pkg/authn/gatekeeper.go (about)

     1  // Copyright 2024 Paul Greenberg greenpau@outlook.com
     2  //
     3  // Licensed under the Apache License, Version 2.0 (the "License");
     4  // you may not use this file except in compliance with the License.
     5  // You may obtain a copy of the License at
     6  //
     7  //     http://www.apache.org/licenses/LICENSE-2.0
     8  //
     9  // Unless required by applicable law or agreed to in writing, software
    10  // distributed under the License is distributed on an "AS IS" BASIS,
    11  // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    12  // See the License for the specific language governing permissions and
    13  // limitations under the License.
    14  
    15  package authn
    16  
    17  import (
    18  	"fmt"
    19  	"slices"
    20  
    21  	"github.com/greenpau/go-authcrunch/pkg/authn/enums/role"
    22  	"github.com/greenpau/go-authcrunch/pkg/user"
    23  )
    24  
    25  func (p *Portal) authorizedRole(usr *user.User, authorizedRoles []role.Kind, authenticated bool) error {
    26  	if !authenticated {
    27  		if slices.Contains(authorizedRoles, role.Anonymous) {
    28  			return nil
    29  		}
    30  		return fmt.Errorf("user is not authenticated")
    31  	}
    32  
    33  	if slices.Contains(authorizedRoles, role.User) {
    34  		for roleName := range p.config.PortalUserRoles {
    35  			if usr.HasRole(roleName) {
    36  				return nil
    37  			}
    38  		}
    39  		for _, roleNamePattern := range p.config.userRolePatterns {
    40  			if usr.HasRolePattern(roleNamePattern) {
    41  				return nil
    42  			}
    43  		}
    44  	}
    45  
    46  	if slices.Contains(authorizedRoles, role.Admin) {
    47  		for roleName := range p.config.PortalAdminRoles {
    48  			if usr.HasRole(roleName) {
    49  				return nil
    50  			}
    51  		}
    52  		for _, roleNamePattern := range p.config.adminRolePatterns {
    53  			if usr.HasRolePattern(roleNamePattern) {
    54  				return nil
    55  			}
    56  		}
    57  	}
    58  
    59  	return fmt.Errorf("user is not authorized")
    60  }