5232fcb808
R-023: Zero-trust enforcement operationally wired. ACL enforcement (C-45 staged rollout): - acl.Check wired into all 5 daemon handlers (dispatch/jobs/nodes/tasks) - health endpoints exempt (liveness probes not gated) - ACL log-only mode default (config acl.enforce=false); enforce after bootstrap ACL verified - sshpush auth: ORCA_OIDC_TOKEN validated against JWKS before apply - txn apply: Authorize hook validates OIDC token before running pull - acl.json mode 0600 (was 0644) - flock on acl.json for concurrent grant/revoke - bootstrap ACL: init grants cluster-admin to orca-admins group + SVID Audit actor identity: - currentActor reads OIDC sub from credentials.json (was hardcoded "cli") - threaded through all audit.Record calls via context WebAuthn registration auth: - BeginRegistration/FinishRegistration require authenticated session - fail-closed 401 when no authFunc configured New files: internal/daemon/acl.go, internal/cli/authactor.go, internal/engine/actor.go, internal/identity/authtoken.go, internal/sshpush/auth.go, internal/txn/auth_test.go ---ci--- project: orca phase: 4 milestone: v0.13 status: complete requirements: covered: [153] ---/ci---
77 lines
1.8 KiB
Go
77 lines
1.8 KiB
Go
package daemon
|
|
|
|
import (
|
|
"context"
|
|
"log/slog"
|
|
"net/http"
|
|
"strconv"
|
|
"time"
|
|
|
|
"git.cloudinit.dev/coreci/orca/internal/acl"
|
|
"git.cloudinit.dev/coreci/orca/internal/model"
|
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
|
)
|
|
|
|
// handleTasksCollection handles /v1/tasks (GET only).
|
|
// Optional query param: ?job_id=<id> to filter by job.
|
|
// Optional: ?limit=<n> (default 100, max 1000).
|
|
func (s *Server) handleTasksCollection(w http.ResponseWriter, r *http.Request) {
|
|
if r.Method != http.MethodGet {
|
|
writeError(w, http.StatusMethodNotAllowed, "method not allowed")
|
|
return
|
|
}
|
|
ctx, cancel := context.WithTimeout(r.Context(), 5*time.Second)
|
|
defer cancel()
|
|
|
|
// P04 ACL enforcement (C-44). Task list is a cluster-wide read.
|
|
ns := "_defaults"
|
|
if s.acl != nil {
|
|
if id, ok := s.acl.Check(r, ns, acl.PermRead); !ok {
|
|
deny(w, id, ns, acl.PermRead)
|
|
return
|
|
}
|
|
}
|
|
|
|
jobID := r.URL.Query().Get("job_id")
|
|
if jobID != "" {
|
|
if err := validateID(jobID); err != nil {
|
|
writeError(w, http.StatusBadRequest, err.Error())
|
|
return
|
|
}
|
|
}
|
|
|
|
limit := 100
|
|
if v := r.URL.Query().Get("limit"); v != "" {
|
|
n, err := strconv.Atoi(v)
|
|
if err != nil || n <= 0 {
|
|
writeError(w, http.StatusBadRequest, "invalid limit")
|
|
return
|
|
}
|
|
if n > 1000 {
|
|
n = 1000
|
|
}
|
|
limit = n
|
|
}
|
|
|
|
repo := store.NewTaskRepo(s.db)
|
|
var tasks []*model.Task
|
|
var err error
|
|
if jobID != "" {
|
|
tasks, err = repo.ListByJob(ctx, jobID)
|
|
} else {
|
|
tasks, err = repo.ListRecent(ctx, limit)
|
|
}
|
|
if err != nil {
|
|
s.log.Error("list tasks",
|
|
slog.String("component", "daemon"),
|
|
slog.String("job_id", jobID),
|
|
slog.String("error", err.Error()))
|
|
writeError(w, http.StatusInternalServerError, "failed to list tasks")
|
|
return
|
|
}
|
|
if tasks == nil {
|
|
tasks = []*model.Task{}
|
|
}
|
|
writeJSON(w, http.StatusOK, map[string]any{"tasks": tasks, "count": len(tasks)})
|
|
}
|