You can not select more than 25 topics Topics must start with a chinese character,a letter or number, can include dashes ('-') and can be up to 35 characters long.

alts_util.h 1.9 kB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354
  1. /*
  2. *
  3. * Copyright 2019 gRPC authors.
  4. *
  5. * Licensed under the Apache License, Version 2.0 (the "License");
  6. * you may not use this file except in compliance with the License.
  7. * You may obtain a copy of the License at
  8. *
  9. * http://www.apache.org/licenses/LICENSE-2.0
  10. *
  11. * Unless required by applicable law or agreed to in writing, software
  12. * distributed under the License is distributed on an "AS IS" BASIS,
  13. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. * See the License for the specific language governing permissions and
  15. * limitations under the License.
  16. *
  17. */
  18. #ifndef GRPCPP_SECURITY_ALTS_UTIL_H
  19. #define GRPCPP_SECURITY_ALTS_UTIL_H
  20. #include <memory>
  21. #include <grpc/grpc_security_constants.h>
  22. #include <grpcpp/impl/codegen/status.h>
  23. #include <grpcpp/security/alts_context.h>
  24. #include <grpcpp/security/auth_context.h>
  25. struct grpc_gcp_AltsContext;
  26. namespace grpc
  27. {
  28. namespace experimental
  29. {
  30. // GetAltsContextFromAuthContext helps to get the AltsContext from AuthContext.
  31. // If ALTS is not the transport security protocol used to establish the
  32. // connection, this function will return nullptr.
  33. std::unique_ptr<AltsContext> GetAltsContextFromAuthContext(
  34. const std::shared_ptr<const AuthContext>& auth_context
  35. );
  36. // This utility function performs ALTS client authorization check on server
  37. // side, i.e., checks if the client identity matches one of the expected service
  38. // accounts. It returns OK if client is authorized and an error otherwise.
  39. grpc::Status AltsClientAuthzCheck(
  40. const std::shared_ptr<const AuthContext>& auth_context,
  41. const std::vector<std::string>& expected_service_accounts
  42. );
  43. } // namespace experimental
  44. } // namespace grpc
  45. #endif // GRPCPP_SECURITY_ALTS_UTIL_H