request_context.py 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259
  1. from dataclasses import dataclass
  2. from datetime import datetime
  3. from time import perf_counter
  4. from uuid import uuid4
  5. import httpx
  6. from fastapi import Request, Response
  7. from starlette.responses import JSONResponse
  8. from starlette.middleware.base import BaseHTTPMiddleware, RequestResponseEndpoint
  9. from core_shared.security import build_internal_service_headers
  10. from app.bootstrap.settings import ApiGatewaySettings
  11. from app.domain.repositories import ApiKeyRepository
  12. from app.infrastructure.api_keys import hash_api_key
  13. REQUEST_ID_HEADER = "x-request-id"
  14. TENANT_ID_HEADER = "x-tenant-id"
  15. DEFAULT_TENANT_ID = "public"
  16. @dataclass
  17. class GatewayRequestContext:
  18. request_id: str
  19. tenant_id: str
  20. started_perf_counter: float
  21. api_key_id: str | None = None
  22. user_id: str | None = None
  23. target_service: str | None = None
  24. target_url: str | None = None
  25. class GatewayRequestContextMiddleware(BaseHTTPMiddleware):
  26. async def dispatch(
  27. self,
  28. request: Request,
  29. call_next: RequestResponseEndpoint,
  30. ) -> Response:
  31. request_id = request.headers.get(REQUEST_ID_HEADER) or str(uuid4())
  32. tenant_id = resolve_tenant_id(request)
  33. request.state.gateway_context = GatewayRequestContext(
  34. request_id=request_id,
  35. tenant_id=tenant_id,
  36. started_perf_counter=perf_counter(),
  37. )
  38. auth_response = authenticate_gateway_request(request)
  39. if auth_response is not None:
  40. from app.infrastructure.audit import persist_gateway_audit
  41. persist_gateway_audit(
  42. request=request,
  43. session_factory=request.app.state.session_factory,
  44. status_code=auth_response.status_code,
  45. error_message=None,
  46. )
  47. context = get_gateway_request_context(request)
  48. auth_response.headers[REQUEST_ID_HEADER] = request_id
  49. auth_response.headers[TENANT_ID_HEADER] = context.tenant_id
  50. return auth_response
  51. try:
  52. response = await call_next(request)
  53. except Exception as exc:
  54. from app.infrastructure.audit import persist_gateway_audit
  55. persist_gateway_audit(
  56. request=request,
  57. session_factory=request.app.state.session_factory,
  58. status_code=500,
  59. error_message=str(exc),
  60. )
  61. raise
  62. from app.infrastructure.audit import persist_gateway_audit
  63. persist_gateway_audit(
  64. request=request,
  65. session_factory=request.app.state.session_factory,
  66. status_code=response.status_code,
  67. )
  68. context = get_gateway_request_context(request)
  69. response.headers[REQUEST_ID_HEADER] = request_id
  70. response.headers[TENANT_ID_HEADER] = context.tenant_id
  71. return response
  72. def resolve_tenant_id(request: Request) -> str:
  73. header_tenant_id = request.headers.get(TENANT_ID_HEADER)
  74. if header_tenant_id:
  75. return header_tenant_id
  76. query_tenant_id = request.query_params.get("tenant_id")
  77. if query_tenant_id:
  78. return query_tenant_id
  79. return DEFAULT_TENANT_ID
  80. def get_gateway_request_context(request: Request) -> GatewayRequestContext:
  81. context = getattr(request.state, "gateway_context", None)
  82. if isinstance(context, GatewayRequestContext):
  83. return context
  84. return GatewayRequestContext(
  85. request_id=str(uuid4()),
  86. tenant_id=DEFAULT_TENANT_ID,
  87. started_perf_counter=perf_counter(),
  88. )
  89. def authenticate_gateway_request(request: Request) -> Response | None:
  90. settings = ApiGatewaySettings()
  91. if not settings.auth_required:
  92. return None
  93. if not request.url.path.startswith("/gateway/"):
  94. return None
  95. if request.url.path in {"/gateway/services/health"}:
  96. return None
  97. if is_initial_api_key_bootstrap_request(request):
  98. return None
  99. api_key = request.headers.get(settings.api_key_header_name)
  100. if not api_key:
  101. return JSONResponse(
  102. status_code=401,
  103. content={"detail": "missing api key"},
  104. )
  105. db = request.app.state.session_factory()
  106. try:
  107. entity = ApiKeyRepository(db).get_active_by_hash(key_hash=hash_api_key(api_key))
  108. if entity is None:
  109. return JSONResponse(
  110. status_code=401,
  111. content={"detail": "invalid api key"},
  112. )
  113. if entity.expires_time is not None and entity.expires_time <= datetime.utcnow():
  114. return JSONResponse(
  115. status_code=401,
  116. content={"detail": "api key expired"},
  117. )
  118. context = get_gateway_request_context(request)
  119. requested_tenant_id = resolve_tenant_id(request)
  120. if requested_tenant_id not in {DEFAULT_TENANT_ID, entity.tenant_id}:
  121. return JSONResponse(
  122. status_code=403,
  123. content={"detail": "api key tenant mismatch"},
  124. )
  125. context.tenant_id = entity.tenant_id
  126. context.api_key_id = entity.id
  127. context.user_id = request.headers.get(settings.user_id_header_name)
  128. permission = derive_gateway_permission(request)
  129. if permission is not None and not api_key_scope_allows(
  130. scopes=entity.scopes,
  131. permission=permission,
  132. ):
  133. return JSONResponse(
  134. status_code=403,
  135. content={"detail": "api key scope denied", "permission": permission},
  136. )
  137. if settings.authz_required:
  138. if context.user_id is None:
  139. return JSONResponse(
  140. status_code=401,
  141. content={"detail": "missing user id"},
  142. )
  143. authz_response = check_auth_service_permission(
  144. settings=settings,
  145. tenant_id=entity.tenant_id,
  146. user_id=context.user_id,
  147. permission=permission or "gateway:access",
  148. )
  149. if authz_response is not None:
  150. return authz_response
  151. ApiKeyRepository(db).touch_last_used_time(api_key_id=entity.id)
  152. finally:
  153. db.close()
  154. return None
  155. def is_initial_api_key_bootstrap_request(request: Request) -> bool:
  156. if request.method.upper() != "POST" or request.url.path != "/gateway/api-keys":
  157. return False
  158. db = request.app.state.session_factory()
  159. try:
  160. return not ApiKeyRepository(db).has_any()
  161. finally:
  162. db.close()
  163. def derive_gateway_permission(request: Request) -> str | None:
  164. if not request.url.path.startswith("/gateway/"):
  165. return None
  166. path_parts = [part for part in request.url.path.split("/") if part]
  167. if len(path_parts) < 2:
  168. return "gateway:access"
  169. if path_parts[1] in {"services", "api-keys", "audits"}:
  170. resource = path_parts[1]
  171. else:
  172. resource = path_parts[1].replace("_", "-")
  173. action = "read" if request.method.upper() in {"GET", "HEAD", "OPTIONS"} else "write"
  174. return f"gateway:{resource}:{action}"
  175. def api_key_scope_allows(*, scopes: str | None, permission: str) -> bool:
  176. if scopes is None or not scopes.strip():
  177. return True
  178. scope_values = parse_scope_values(scopes)
  179. if "*" in scope_values or permission in scope_values:
  180. return True
  181. resource_prefix = permission.rsplit(":", 1)[0]
  182. return f"{resource_prefix}:*" in scope_values
  183. def parse_scope_values(scopes: str) -> set[str]:
  184. normalized = scopes.replace(",", " ").replace("\n", " ")
  185. return {item.strip() for item in normalized.split(" ") if item.strip()}
  186. def check_auth_service_permission(
  187. *,
  188. settings: ApiGatewaySettings,
  189. tenant_id: str,
  190. user_id: str,
  191. permission: str,
  192. ) -> Response | None:
  193. try:
  194. with httpx.Client(timeout=settings.authz_timeout_seconds) as client:
  195. response = client.post(
  196. f"{settings.auth_service_url.rstrip('/')}/auth/permissions/check",
  197. headers=build_internal_service_headers(settings),
  198. json={
  199. "tenant_id": tenant_id,
  200. "user_id": user_id,
  201. "permission": permission,
  202. },
  203. )
  204. response.raise_for_status()
  205. payload = response.json()
  206. except (httpx.HTTPError, ValueError) as exc:
  207. return JSONResponse(
  208. status_code=503,
  209. content={"detail": "auth service permission check failed", "error": str(exc)},
  210. )
  211. allowed = payload.get("allowed")
  212. if allowed is True:
  213. return None
  214. reason = payload.get("reason")
  215. return JSONResponse(
  216. status_code=403,
  217. content={
  218. "detail": "permission denied",
  219. "permission": permission,
  220. "reason": reason if isinstance(reason, str) else "denied",
  221. },
  222. )