drone/internal/api/handler/serviceaccount/delete.go
Johannes Batzill 8c2f900c80 Principals, ServiceAccounts, Tokens and auth.Sessions (#15)
This change introduces the concept of a principal (abstraction of call identity), and adds a new service account type principal. Also adds support for different tokens (session, PAT, SAT, OAuth2) and adds auth.Session which is being used to capture information about the caller and call method.
2022-09-25 23:44:51 -07:00

49 lines
1.4 KiB
Go

// Copyright 2021 Harness Inc. All rights reserved.
// Use of this source code is governed by the Polyform Free Trial License
// that can be found in the LICENSE.md file for this repository.
package serviceaccount
import (
"net/http"
"github.com/harness/gitness/internal/api/guard"
"github.com/harness/gitness/internal/api/render"
"github.com/harness/gitness/internal/api/request"
"github.com/harness/gitness/internal/store"
"github.com/harness/gitness/types/enum"
"github.com/rs/zerolog/hlog"
)
/*
* Deletes a service account.
*/
func HandleDelete(guard *guard.Guard, saStore store.ServiceAccountStore, tokenStore store.TokenStore) http.HandlerFunc {
return guard.ServiceAccount(
enum.PermissionServiceAccountDelete,
func(w http.ResponseWriter, r *http.Request) {
ctx := r.Context()
log := hlog.FromRequest(r)
sa, _ := request.ServiceAccountFrom(ctx)
// delete all tokens (okay if we fail after - user intends to delete service account anyway)
err := tokenStore.DeleteForPrincipal(ctx, sa.ID)
if err != nil {
log.Error().Err(err).Msg("Failed to delete tokens for service account.")
render.UserfiedErrorOrInternal(w, err)
return
}
err = saStore.Delete(ctx, sa.ID)
if err != nil {
log.Error().Err(err).Msg("Failed to delete the service account.")
render.UserfiedErrorOrInternal(w, err)
return
}
w.WriteHeader(http.StatusNoContent)
})
}