Skip to content

Commit

Permalink
feat: Check resource provider when allowlist enabled
Browse files Browse the repository at this point in the history
  • Loading branch information
bgins committed Jan 9, 2025
1 parent 7ac5bc0 commit 49c54a3
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions pkg/solver/server.go
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ import (
corehttp "net/http"
"os"
"path/filepath"
"slices"
"time"

"github.com/go-chi/httprate"
Expand Down Expand Up @@ -299,6 +300,19 @@ func (solverServer *solverServer) addResourceOffer(resourceOffer data.ResourceOf
versionHeader, _ := http.GetVersionFromHeaders(req)
log.Debug().Msgf("resource provider adding offer with version header %s", versionHeader)

if solverServer.options.AccessControl.EnableResourceProviderAllowlist {
allowedProviders, err := solverServer.store.GetAllowedResourceProviders()
if err != nil {
log.Error().Err(err).Msgf("Unable to load resource provider allowlist: %s", err)
return nil, err
}

if !slices.Contains(allowedProviders, resourceOffer.ResourceProvider) {
log.Debug().Msgf("resource provider not in allowlist %s", resourceOffer.ResourceProvider)
return nil, fmt.Errorf("resource provider not allowed to post resource offer %s", resourceOffer.ResourceProvider)
}
}

signerAddress, err := http.CheckSignature(req)
if err != nil {
log.Error().Err(err).Msgf("error checking signature")
Expand Down

0 comments on commit 49c54a3

Please sign in to comment.