mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-31 12:01:29 +02:00
[client] UI refactor (#6069)
Refactor UI --------- Co-authored-by: Eduard Gert <kontakt@eduardgert.de> Co-authored-by: braginini <bangvalo@gmail.com> Co-authored-by: Pascal Fischer <32096965+pascal-fischer@users.noreply.github.com> Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: riccardom <riccardomanfrin@gmail.com>
This commit is contained in:
116
client/ui/authsession/service.go
Normal file
116
client/ui/authsession/service.go
Normal file
@@ -0,0 +1,116 @@
|
||||
//go:build !android && !ios && !freebsd && !js
|
||||
|
||||
package authsession
|
||||
|
||||
import (
|
||||
"context"
|
||||
"time"
|
||||
|
||||
"google.golang.org/grpc/codes"
|
||||
gstatus "google.golang.org/grpc/status"
|
||||
|
||||
"github.com/netbirdio/netbird/client/proto"
|
||||
)
|
||||
|
||||
type ExtendStartParams struct {
|
||||
// Hint is the OIDC login_hint, typically the user's email.
|
||||
Hint string `json:"hint"`
|
||||
}
|
||||
|
||||
type ExtendStartResult struct {
|
||||
VerificationURI string `json:"verificationUri"`
|
||||
VerificationURIComplete string `json:"verificationUriComplete"`
|
||||
UserCode string `json:"userCode"`
|
||||
DeviceCode string `json:"deviceCode"`
|
||||
ExpiresIn int64 `json:"expiresIn"`
|
||||
}
|
||||
|
||||
type ExtendWaitParams struct {
|
||||
DeviceCode string `json:"deviceCode"`
|
||||
UserCode string `json:"userCode"`
|
||||
}
|
||||
|
||||
// ExtendResult: ExpiresAt is nil when the peer is ineligible for extension.
|
||||
// Preempted means a newer WaitExtend took over the IdP poll — a no-op, not a failure.
|
||||
type ExtendResult struct {
|
||||
ExpiresAt *time.Time `json:"sessionExpiresAt,omitempty"`
|
||||
Preempted bool `json:"preempted,omitempty"`
|
||||
}
|
||||
|
||||
// DaemonConn duplicates services.DaemonConn to avoid an import cycle.
|
||||
type DaemonConn interface {
|
||||
Client() (proto.DaemonServiceClient, error)
|
||||
}
|
||||
|
||||
// Session bundles the session-auth daemon RPCs the UI drives.
|
||||
type Session struct {
|
||||
conn DaemonConn
|
||||
}
|
||||
|
||||
func NewSession(conn DaemonConn) *Session {
|
||||
return &Session{conn: conn}
|
||||
}
|
||||
|
||||
// RequestExtend starts the SSO session-extension flow on the daemon.
|
||||
func (s *Session) RequestExtend(ctx context.Context, p ExtendStartParams) (ExtendStartResult, error) {
|
||||
cli, err := s.conn.Client()
|
||||
if err != nil {
|
||||
return ExtendStartResult{}, err
|
||||
}
|
||||
|
||||
req := &proto.RequestExtendAuthSessionRequest{}
|
||||
if p.Hint != "" {
|
||||
h := p.Hint
|
||||
req.Hint = &h
|
||||
}
|
||||
|
||||
resp, err := cli.RequestExtendAuthSession(ctx, req)
|
||||
if err != nil {
|
||||
return ExtendStartResult{}, err
|
||||
}
|
||||
|
||||
return ExtendStartResult{
|
||||
VerificationURI: resp.GetVerificationURI(),
|
||||
VerificationURIComplete: resp.GetVerificationURIComplete(),
|
||||
UserCode: resp.GetUserCode(),
|
||||
DeviceCode: resp.GetDeviceCode(),
|
||||
ExpiresIn: resp.GetExpiresIn(),
|
||||
}, nil
|
||||
}
|
||||
|
||||
// WaitExtend blocks until the user completes the SSO flow started by RequestExtend.
|
||||
func (s *Session) WaitExtend(ctx context.Context, p ExtendWaitParams) (ExtendResult, error) {
|
||||
cli, err := s.conn.Client()
|
||||
if err != nil {
|
||||
return ExtendResult{}, err
|
||||
}
|
||||
|
||||
resp, err := cli.WaitExtendAuthSession(ctx, &proto.WaitExtendAuthSessionRequest{
|
||||
DeviceCode: p.DeviceCode,
|
||||
UserCode: p.UserCode,
|
||||
})
|
||||
if err != nil {
|
||||
if st, ok := gstatus.FromError(err); ok && st.Code() == codes.Canceled {
|
||||
return ExtendResult{Preempted: true}, nil
|
||||
}
|
||||
return ExtendResult{}, err
|
||||
}
|
||||
|
||||
out := ExtendResult{}
|
||||
if ts := resp.GetSessionExpiresAt(); ts.IsValid() && !ts.AsTime().IsZero() {
|
||||
t := ts.AsTime().UTC()
|
||||
out.ExpiresAt = &t
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// DismissWarning suppresses the daemon's T-FinalWarningLead fallback dialog for
|
||||
// the current deadline. Best-effort: a stale call is silently swallowed daemon-side.
|
||||
func (s *Session) DismissWarning(ctx context.Context) error {
|
||||
cli, err := s.conn.Client()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, err = cli.DismissSessionWarning(ctx, &proto.DismissSessionWarningRequest{})
|
||||
return err
|
||||
}
|
||||
64
client/ui/authsession/warning.go
Normal file
64
client/ui/authsession/warning.go
Normal file
@@ -0,0 +1,64 @@
|
||||
//go:build !android && !ios && !freebsd && !js
|
||||
|
||||
// Package authsession holds the UI-side domain logic for the SSO
|
||||
// session-extend feature. The Wails facades in client/ui/services/session*.go
|
||||
// are thin adapters over these types.
|
||||
package authsession
|
||||
|
||||
import (
|
||||
"time"
|
||||
|
||||
"github.com/netbirdio/netbird/client/internal/auth/sessionwatch"
|
||||
)
|
||||
|
||||
// Re-exported from sessionwatch so UI-side consumers don't import the
|
||||
// daemon-internal package directly.
|
||||
const (
|
||||
MetaWarning = sessionwatch.MetaSessionWarning
|
||||
MetaFinal = sessionwatch.MetaSessionFinal
|
||||
MetaExpiresAt = sessionwatch.MetaSessionExpiresAt
|
||||
MetaLeadMinutes = sessionwatch.MetaSessionLeadMinutes
|
||||
MetaDeadlineRejected = sessionwatch.MetaSessionDeadlineRejected
|
||||
)
|
||||
|
||||
// Warning is the typed payload emitted on the session-warning Wails events.
|
||||
type Warning struct {
|
||||
// Absolute UTC deadline; best-effort, stays zero when metadata is
|
||||
// missing or malformed (e.g. an older daemon) and the UI falls back
|
||||
// to the Status snapshot.
|
||||
ExpiresAt time.Time `json:"sessionExpiresAt"`
|
||||
// Configured lead time, so the UI need not hardcode the constant.
|
||||
LeadMinutes int `json:"leadMinutes"`
|
||||
// True on the final-warning fallback event.
|
||||
Final bool `json:"final"`
|
||||
}
|
||||
|
||||
// WarningFromMetadata parses SystemEvent metadata into a Warning, or returns
|
||||
// (nil, false) when the event is not a session-warning. A field that fails to
|
||||
// parse stays zero; the event is still surfaced.
|
||||
func WarningFromMetadata(meta map[string]string) (*Warning, bool) {
|
||||
if meta == nil || meta[MetaWarning] != "true" {
|
||||
return nil, false
|
||||
}
|
||||
|
||||
out := &Warning{
|
||||
Final: meta[MetaFinal] == "true",
|
||||
}
|
||||
if raw := meta[MetaExpiresAt]; raw != "" {
|
||||
if t, err := sessionwatch.ParseExpiresAt(raw); err == nil {
|
||||
out.ExpiresAt = t
|
||||
}
|
||||
}
|
||||
if raw := meta[MetaLeadMinutes]; raw != "" {
|
||||
if n, err := sessionwatch.ParseLeadMinutes(raw); err == nil {
|
||||
out.LeadMinutes = n
|
||||
}
|
||||
}
|
||||
return out, true
|
||||
}
|
||||
|
||||
// ParseExpiresAt re-exports sessionwatch.ParseExpiresAt so UI-side call sites
|
||||
// don't import the daemon-internal package.
|
||||
func ParseExpiresAt(s string) (time.Time, error) {
|
||||
return sessionwatch.ParseExpiresAt(s)
|
||||
}
|
||||
82
client/ui/authsession/warning_test.go
Normal file
82
client/ui/authsession/warning_test.go
Normal file
@@ -0,0 +1,82 @@
|
||||
//go:build !android && !ios && !freebsd && !js
|
||||
|
||||
package authsession
|
||||
|
||||
import (
|
||||
"testing"
|
||||
"time"
|
||||
)
|
||||
|
||||
func TestWarningFromMetadata_NotASessionWarning(t *testing.T) {
|
||||
cases := []struct {
|
||||
name string
|
||||
meta map[string]string
|
||||
}{
|
||||
{"nil metadata", nil},
|
||||
{"empty map", map[string]string{}},
|
||||
{"unrelated event", map[string]string{"new_version_available": "0.65.0"}},
|
||||
{"flag not 'true'", map[string]string{"session_warning": "1"}},
|
||||
}
|
||||
for _, tc := range cases {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
if w, ok := WarningFromMetadata(tc.meta); ok {
|
||||
t.Fatalf("expected (nil, false), got (%+v, %v)", w, ok)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestWarningFromMetadata_FullPayload(t *testing.T) {
|
||||
ts := "2026-05-18T13:30:00Z"
|
||||
meta := map[string]string{
|
||||
"session_warning": "true",
|
||||
"session_expires_at": ts,
|
||||
"lead_minutes": "10",
|
||||
}
|
||||
|
||||
got, ok := WarningFromMetadata(meta)
|
||||
if !ok {
|
||||
t.Fatalf("expected the warning to be recognised, got ok=false")
|
||||
}
|
||||
want, _ := time.Parse(time.RFC3339, ts)
|
||||
if !got.ExpiresAt.Equal(want.UTC()) {
|
||||
t.Errorf("ExpiresAt = %v, want %v", got.ExpiresAt, want.UTC())
|
||||
}
|
||||
if got.LeadMinutes != 10 {
|
||||
t.Errorf("LeadMinutes = %d, want 10", got.LeadMinutes)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWarningFromMetadata_BadFieldsStillEmits(t *testing.T) {
|
||||
// Older or buggy daemon: the flag is set but the timestamp/lead are
|
||||
// missing or malformed. The UI should still get a warning so it can
|
||||
// at least surface "session expires soon"; field zero-values are fine.
|
||||
meta := map[string]string{
|
||||
"session_warning": "true",
|
||||
"session_expires_at": "not-a-timestamp",
|
||||
"lead_minutes": "abc",
|
||||
}
|
||||
|
||||
got, ok := WarningFromMetadata(meta)
|
||||
if !ok {
|
||||
t.Fatalf("warning should still be recognised even with malformed fields")
|
||||
}
|
||||
if !got.ExpiresAt.IsZero() {
|
||||
t.Errorf("malformed timestamp should leave field zero, got %v", got.ExpiresAt)
|
||||
}
|
||||
if got.LeadMinutes != 0 {
|
||||
t.Errorf("malformed lead_minutes should leave field 0, got %d", got.LeadMinutes)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWarningFromMetadata_MissingFieldsStillEmits(t *testing.T) {
|
||||
// Only the flag is present (e.g. future-trimmed event). Still emit.
|
||||
meta := map[string]string{"session_warning": "true"}
|
||||
got, ok := WarningFromMetadata(meta)
|
||||
if !ok {
|
||||
t.Fatalf("warning should still be recognised when only flag is present")
|
||||
}
|
||||
if got.ExpiresAt.IsZero() != true || got.LeadMinutes != 0 {
|
||||
t.Errorf("missing fields should be zero-valued, got %+v", got)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user