mirror of
https://github.com/dadosfera/maestro.git
synced 2026-09-07 07:54:47 +00:00
Compare commits
9
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5d8e908339 | ||
|
|
3b48dd1613 | ||
|
|
bac74c9577 | ||
|
|
19d748ae09 | ||
|
|
4db865371f | ||
|
|
0aa9c065a5 | ||
|
|
cb98099a91 | ||
|
|
17de31f1a6 | ||
|
|
9e597fadba |
@@ -4,6 +4,8 @@ charts:
|
||||
values:
|
||||
- ../maestro/values.yaml
|
||||
set:
|
||||
- name: app_name
|
||||
value: maestro
|
||||
- name: maestro.duc_url
|
||||
value: duc.dadosfera.ai
|
||||
- name: hostname
|
||||
@@ -20,3 +22,32 @@ charts:
|
||||
value: c0afdcce-c5be-40d0-9d1d-2d271121f14a
|
||||
- name: replicaCount
|
||||
value: 2
|
||||
|
||||
- name: unimed
|
||||
chart: ../maestro
|
||||
values:
|
||||
- ../maestro/values.yaml
|
||||
set:
|
||||
- name: app_name
|
||||
value: maestro-unimed
|
||||
- name: maestro.duc_url
|
||||
value: duc.dadosfera.ai
|
||||
- name: hostname
|
||||
value: maestro.dadosfera.ai
|
||||
- name: maestro.pi_factory_url
|
||||
value: pi-factory.dadosfera.ai
|
||||
- name: maestro.in_factory_url
|
||||
value: in-factory.dadosfera.ai
|
||||
- name: maestro.tr_factory_url
|
||||
value: in-factory.dadosfera.ai
|
||||
- name: maestro.open_customer_id
|
||||
value: b3e3dfe5-b992-4586-a73c-c0b0c00f615d
|
||||
- name: maestro.open_group_id
|
||||
value: c0afdcce-c5be-40d0-9d1d-2d271121f14a
|
||||
# Customer id
|
||||
- name: maestro.dedicated_proxy
|
||||
value: dea2c27f-0973-4588-a2e0-9e31b64c7ffd
|
||||
- name: replicaCount
|
||||
value: 1
|
||||
- name: restricted-ip
|
||||
value: "177.52.172.0/24"
|
||||
|
||||
+3
-1
@@ -47,4 +47,6 @@ charts:
|
||||
- name: maestro.dedicated_proxy
|
||||
value: 14d52fd4-d83d-4cdd-be34-bf11cc28b3bd
|
||||
- name: replicaCount
|
||||
value: 1
|
||||
value: 1
|
||||
- name: maestro.restricted_ip
|
||||
value: "57.151.113.140/30"
|
||||
@@ -100,6 +100,8 @@ spec:
|
||||
value: {{ .Values.maestro.open_customer_id }}
|
||||
- name: OPEN_GROUP_ID
|
||||
value: {{ .Values.maestro.open_group_id }}
|
||||
- name: DEDICATED_PROXY
|
||||
value: {{ .Values.maestro.dedicated_proxy }}
|
||||
- name: JWT_PRIVATE_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
|
||||
@@ -11,7 +11,11 @@ metadata:
|
||||
generation: 1
|
||||
labels:
|
||||
app: {{ .Values.app_name }}
|
||||
{{- if .Values.maestro.dedicated_proxy}}
|
||||
name: open-data-{{ .Values.app_name }}
|
||||
{{- else }}
|
||||
name: open-data
|
||||
{{- end }}
|
||||
namespace: applications
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
|
||||
@@ -3,9 +3,15 @@ kind: Ingress
|
||||
metadata:
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/proxy-body-size: "0"
|
||||
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/proxy-connect-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/server-snippet: |
|
||||
underscores_in_headers on;
|
||||
ignore_invalid_headers on;
|
||||
{{- if .Values.maestro.restricted_ip}}
|
||||
nginx.ingress.kubernetes.io/whitelist-source-range: {{ .Values.maestro.restricted_ip }}
|
||||
{{- end }}
|
||||
|
||||
generation: 1
|
||||
labels:
|
||||
|
||||
@@ -44,6 +44,7 @@ maestro:
|
||||
open_customer_id: f239718a-a271-4ef9-ae7e-02a2f0f3aa6e
|
||||
open_group_id: 401573bb-334f-44b2-b30e-88d4cea31ae9
|
||||
dedicated_proxy: ""
|
||||
restricted_ip: ""
|
||||
autoscaling:
|
||||
enabled: false
|
||||
minReplicas: 1
|
||||
|
||||
@@ -4,6 +4,7 @@ import {
|
||||
OnApplicationBootstrap,
|
||||
ExecutionContext,
|
||||
Inject,
|
||||
ForbiddenException,
|
||||
} from '@nestjs/common';
|
||||
import { Reflector } from '@nestjs/core';
|
||||
import assert from 'assert';
|
||||
@@ -113,6 +114,18 @@ export class AuthenticationGuard
|
||||
return false;
|
||||
}
|
||||
|
||||
// Bloquear outros customer de usar o maestor dedicado
|
||||
const DEDICATED_PROXY = process.env.DEDICATED_PROXY || '';
|
||||
if (DEDICATED_PROXY !== '' && DEDICATED_PROXY !== accessTokenPayload.customer_id) {
|
||||
throw new ErrorBuilder(ErrorCodes.AUTH.FORBIDDEN);
|
||||
}
|
||||
|
||||
// Bloquear o customer de acesso o maestro publico
|
||||
// const hasNetworkPolicyModule = accessTokenPayload.customer_modules.includes('network-policy');
|
||||
// if (hasNetworkPolicyModule && DEDICATED_PROXY === '') {
|
||||
// throw new ForbiddenException();
|
||||
// }
|
||||
|
||||
request.accessTokenPayload = accessTokenPayload;
|
||||
request.user = {
|
||||
user_id: accessTokenPayload.user_id,
|
||||
|
||||
@@ -54,14 +54,22 @@ export class AuthClientService implements OnModuleInit {
|
||||
return lastValueFrom(this.authService.AuthSnowflakeSignIn(input));
|
||||
}
|
||||
|
||||
checkDedicatedProxy(customerId: string) {
|
||||
checkDedicatedProxy({
|
||||
customer
|
||||
}: AuthSignInResponse) {
|
||||
const DEDICATED_PROXY = process.env.DEDICATED_PROXY || '';
|
||||
this.logger.info('SignIn - Setting customer ID for dedicated proxy: ' + DEDICATED_PROXY);
|
||||
if (DEDICATED_PROXY !== '') {
|
||||
this.logger.info('Customer ID: ' + customerId);
|
||||
if (DEDICATED_PROXY !== customerId) {
|
||||
throw new ForbiddenException();
|
||||
}
|
||||
this.logger.info('Customer ID: ' + customer.id);
|
||||
|
||||
if (DEDICATED_PROXY !== '' && DEDICATED_PROXY !== customer.id) {
|
||||
throw new ForbiddenException();
|
||||
}
|
||||
|
||||
// Bloquear o customer de acesso o maestro publico
|
||||
this.logger.info('Check if customer have network policy: ' + customer.modules);
|
||||
const hasNetworkPolicyModule = customer.modules.includes('network-policy');
|
||||
if (hasNetworkPolicyModule && DEDICATED_PROXY === '') {
|
||||
throw new ForbiddenException();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -85,7 +93,7 @@ export class AuthClientService implements OnModuleInit {
|
||||
}
|
||||
|
||||
if (result.customer) {
|
||||
this.checkDedicatedProxy(result.customer.id);
|
||||
this.checkDedicatedProxy(result);
|
||||
}
|
||||
|
||||
return result
|
||||
|
||||
@@ -22,7 +22,7 @@ export class PDFParser<T> implements Parser<T> {
|
||||
const html = await this.htmlParser.parse(data);
|
||||
await page.setContent(html, {
|
||||
waitUntil: 'networkidle0',
|
||||
timeout: 30000,
|
||||
timeout: 90000,
|
||||
});
|
||||
|
||||
// Configurações adicionais para garantir um PDF válido
|
||||
@@ -43,7 +43,7 @@ export class PDFParser<T> implements Parser<T> {
|
||||
pageRanges: '',
|
||||
tagged: true,
|
||||
outline: false,
|
||||
timeout: 30000,
|
||||
timeout: 90000,
|
||||
});
|
||||
|
||||
await browser.close();
|
||||
|
||||
Reference in New Issue
Block a user