diff --git a/lib/cartodb/api/auth_api.js b/lib/cartodb/api/auth_api.js index bacccda7..8782f907 100644 --- a/lib/cartodb/api/auth_api.js +++ b/lib/cartodb/api/auth_api.js @@ -70,7 +70,7 @@ AuthApi.prototype.authorizedByAPIKey = function(user, res, callback) { this.metadataBackend.getApikey(user, apikeyToken, (err, apikey) => { if (err) { - if (err.message && -1 !== err.message.indexOf('name not found')) { + if (isNameNotFoundError(err)) { err.http_status = 404; } @@ -79,15 +79,8 @@ AuthApi.prototype.authorizedByAPIKey = function(user, res, callback) { //Remove this block when Auth fallback is not used anymore // AUTH_FALLBACK - if (!apikey.databaseRole && apikey.user_id && global.environment.postgres_auth_user) { - apikey.databaseRole = _.template(global.environment.postgres_auth_user, apikey); - } - - //Remove this block when Auth fallback is not used anymore - // AUTH_FALLBACK - if (!apikey.databasePassword && global.environment.postgres.password) { - apikey.databasePassword = global.environment.postgres.password; - } + apikey.databaseRole = composeUserDatabase(apikey); + apikey.databasePassword = composeDatabasePassword(apikey); if ( !isValidApiKey(apikey)) { const error = new Error('Unauthorized'); @@ -98,7 +91,7 @@ AuthApi.prototype.authorizedByAPIKey = function(user, res, callback) { return callback(error); } - if (apikeyUsername && (apikeyUsername !== res.locals.user)) { + if (!usernameMatches(apikeyUsername, res.locals.user)) { const error = new Error('Forbidden'); error.type = 'auth'; error.subtype = 'api-key-username-mismatch'; @@ -120,6 +113,46 @@ AuthApi.prototype.authorizedByAPIKey = function(user, res, callback) { }); }; +//Remove this block when Auth fallback is not used anymore +// AUTH_FALLBACK +function composeUserDatabase (apikey) { + if (shouldComposeUserDatabase(apikey)) { + return _.template(global.environment.postgres_auth_user, apikey); + } + + return apikey.databaseRole; +} + +//Remove this block when Auth fallback is not used anymore +// AUTH_FALLBACK +function composeDatabasePassword (apikey) { + if (shouldComposeDatabasePassword(apikey)) { + return global.environment.postgres.password; + } + + return apikey.databasePassword; +} + +//Remove this block when Auth fallback is not used anymore +// AUTH_FALLBACK +function shouldComposeDatabasePassword (apikey) { + return !apikey.databasePassword && global.environment.postgres.password; +} + +//Remove this block when Auth fallback is not used anymore +// AUTH_FALLBACK +function shouldComposeUserDatabase(apikey) { + return !apikey.databaseRole && apikey.user_id && global.environment.postgres_auth_user; +} + +function isNameNotFoundError (err) { + return err.message && -1 !== err.message.indexOf('name not found'); +} + +function usernameMatches (apikeyUsername, requestUsername) { + return !(apikeyUsername && (apikeyUsername !== requestUsername)); +} + /** * Check access authorization * diff --git a/lib/cartodb/backends/pg_connection.js b/lib/cartodb/backends/pg_connection.js index 71ec2928..290fb6ef 100644 --- a/lib/cartodb/backends/pg_connection.js +++ b/lib/cartodb/backends/pg_connection.js @@ -22,7 +22,7 @@ PgConnection.prototype.setDBAuth = function(username, params, apikeyType, callba if (apikeyType === 'master') { this.metadataBackend.getMasterApikey(username, (err, apikey) => { if (err) { - if (err.message && -1 !== err.message.indexOf('name not found')) { + if (isNameNotFoundError(err)) { err.http_status = 404; } return callback(err); @@ -42,7 +42,7 @@ PgConnection.prototype.setDBAuth = function(username, params, apikeyType, callba } else if (apikeyType === 'regular') { //Actually it can be any type of api key this.metadataBackend.getApikey(username, params.api_key, (err, apikey) => { if (err) { - if (err.message && -1 !== err.message.indexOf('name not found')) { + if (isNameNotFoundError(err)) { err.http_status = 404; } return callback(err); @@ -75,7 +75,7 @@ PgConnection.prototype.setDBAuth = function(username, params, apikeyType, callba } else if (apikeyType === 'default') { this.metadataBackend.getApikey(username, 'default_public', (err, apikey) => { if (err) { - if (err.message && -1 !== err.message.indexOf('name not found')) { + if (isNameNotFoundError(err)) { err.http_status = 404; } return callback(err); @@ -97,6 +97,11 @@ PgConnection.prototype.setDBAuth = function(username, params, apikeyType, callba } }; +function isNameNotFoundError (err) { + return err.message && -1 !== err.message.indexOf('name not found'); +} + + // Set db connection parameters to those for the given username // // @param dbowner cartodb username of database owner,