summaryrefslogtreecommitdiff
path: root/web/src/actions/user.js
blob: 9b3261c9fe5c40da5503af624aec1cbe0c566fbe (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
// Copyright 2020 Red Hat, Inc
//
// Licensed under the Apache License, Version 2.0 (the "License"); you may
// not use this file except in compliance with the License. You may obtain
// a copy of the License at
//
//      http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
// WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
// License for the specific language governing permissions and limitations
// under the License.


import * as API from '../api'
import { USER_ACL_FAIL, USER_ACL_REQUEST, USER_ACL_SUCCESS } from './auth'

export const USER_LOGGED_IN = 'USER_LOGGED_IN'
export const USER_LOGGED_OUT = 'USER_LOGGED_OUT'

// Access tokens are not necessary JWTs (Google OAUTH uses a custom format)
// check the access token, if it isn't a JWT, use the ID token

export function getToken(user) {
  try {
    JSON.parse(atob(user.access_token.split('.')[1]))
    return user.access_token
  } catch (e) {
    return user.id_token
  }
}

export const fetchUserACLRequest = (tenant) => ({
  type: USER_ACL_REQUEST,
  tenant: tenant,
})

export const userLoggedIn = (user) => (dispatch) => {
  dispatch({
    type: USER_LOGGED_IN,
    user: user,
    token: getToken(user),
  })
}

export const userLoggedOut = () => (dispatch) => {
  dispatch({
    type: USER_LOGGED_OUT,
  })
}

const fetchUserACLSuccess = (json) => ({
  type: USER_ACL_SUCCESS,
  isAdmin: json.zuul.admin,
  scope: json.zuul.scope,
})

const fetchUserACLFail = error => ({
  type: USER_ACL_FAIL,
  error
})

export const fetchUserACL = (tenant, user) => (dispatch) => {
  dispatch(fetchUserACLRequest(tenant))
  let apiPrefix = 'tenant/' + tenant + '/'
  return API.fetchUserAuthorizations(apiPrefix, user.token)
    .then(response => dispatch(fetchUserACLSuccess(response.data)))
    .catch(error => {
      dispatch(fetchUserACLFail(error))
    })
}