mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
misc: implemented review comments
This commit is contained in:
@@ -78,7 +78,7 @@ export const registerAdminRouter = async (server: FastifyZodProvider) => {
|
|||||||
});
|
});
|
||||||
},
|
},
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const config = await server.services.superAdmin.updateServerCfg(req.body);
|
const config = await server.services.superAdmin.updateServerCfg(req.body, req.permission.id);
|
||||||
return { config };
|
return { config };
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ import { AuthMethod } from "../auth/auth-type";
|
|||||||
import { TOrgServiceFactory } from "../org/org-service";
|
import { TOrgServiceFactory } from "../org/org-service";
|
||||||
import { TUserDALFactory } from "../user/user-dal";
|
import { TUserDALFactory } from "../user/user-dal";
|
||||||
import { TSuperAdminDALFactory } from "./super-admin-dal";
|
import { TSuperAdminDALFactory } from "./super-admin-dal";
|
||||||
import { TAdminSignUpDTO } from "./super-admin-types";
|
import { LoginMethod, TAdminSignUpDTO } from "./super-admin-types";
|
||||||
|
|
||||||
type TSuperAdminServiceFactoryDep = {
|
type TSuperAdminServiceFactoryDep = {
|
||||||
serverCfgDAL: TSuperAdminDALFactory;
|
serverCfgDAL: TSuperAdminDALFactory;
|
||||||
@@ -79,7 +79,38 @@ export const superAdminServiceFactory = ({
|
|||||||
return newCfg;
|
return newCfg;
|
||||||
};
|
};
|
||||||
|
|
||||||
const updateServerCfg = async (data: TSuperAdminUpdate) => {
|
const updateServerCfg = async (data: TSuperAdminUpdate, userId: string) => {
|
||||||
|
if (data.enabledLoginMethods) {
|
||||||
|
const superAdminUser = await userDAL.findById(userId);
|
||||||
|
const loginMethodToAuthMethod = {
|
||||||
|
[LoginMethod.EMAIL]: [AuthMethod.EMAIL],
|
||||||
|
[LoginMethod.GOOGLE]: [AuthMethod.GOOGLE],
|
||||||
|
[LoginMethod.GITLAB]: [AuthMethod.GITLAB],
|
||||||
|
[LoginMethod.GITHUB]: [AuthMethod.GITHUB],
|
||||||
|
[LoginMethod.LDAP]: [AuthMethod.LDAP],
|
||||||
|
[LoginMethod.OIDC]: [AuthMethod.OIDC],
|
||||||
|
[LoginMethod.SAML]: [
|
||||||
|
AuthMethod.AZURE_SAML,
|
||||||
|
AuthMethod.GOOGLE_SAML,
|
||||||
|
AuthMethod.JUMPCLOUD_SAML,
|
||||||
|
AuthMethod.KEYCLOAK_SAML,
|
||||||
|
AuthMethod.OKTA_SAML
|
||||||
|
]
|
||||||
|
};
|
||||||
|
|
||||||
|
if (
|
||||||
|
!data.enabledLoginMethods.some((loginMethod) =>
|
||||||
|
loginMethodToAuthMethod[loginMethod as LoginMethod].some(
|
||||||
|
(authMethod) => superAdminUser.authMethods?.includes(authMethod)
|
||||||
|
)
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message:
|
||||||
|
"Admin has insufficient authentication methods for update operation to complete without getting locked out."
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
const updatedServerCfg = await serverCfgDAL.updateById(ADMIN_CONFIG_DB_UUID, data);
|
const updatedServerCfg = await serverCfgDAL.updateById(ADMIN_CONFIG_DB_UUID, data);
|
||||||
|
|
||||||
await keyStore.setItemWithExpiry(ADMIN_CONFIG_KEY, ADMIN_CONFIG_KEY_EXP, JSON.stringify(updatedServerCfg));
|
await keyStore.setItemWithExpiry(ADMIN_CONFIG_KEY, ADMIN_CONFIG_KEY_EXP, JSON.stringify(updatedServerCfg));
|
||||||
@@ -167,7 +198,7 @@ export const superAdminServiceFactory = ({
|
|||||||
orgName: initialOrganizationName
|
orgName: initialOrganizationName
|
||||||
});
|
});
|
||||||
|
|
||||||
await updateServerCfg({ initialized: true });
|
await updateServerCfg({ initialized: true }, userInfo.user.id);
|
||||||
const token = await authService.generateUserTokens({
|
const token = await authService.generateUserTokens({
|
||||||
user: userInfo.user,
|
user: userInfo.user,
|
||||||
authMethod: AuthMethod.EMAIL,
|
authMethod: AuthMethod.EMAIL,
|
||||||
|
|||||||
@@ -337,7 +337,11 @@ export const InitialStep = ({ setStep, email, setEmail, password, setPassword }:
|
|||||||
</>
|
</>
|
||||||
)}
|
)}
|
||||||
{!isLoading && loginError && <Error text={t("login.error-login") ?? ""} />}
|
{!isLoading && loginError && <Error text={t("login.error-login") ?? ""} />}
|
||||||
{config.allowSignUp ? (
|
{config.allowSignUp &&
|
||||||
|
(shouldDisplayLoginMethod(LoginMethod.EMAIL) ||
|
||||||
|
shouldDisplayLoginMethod(LoginMethod.GOOGLE) ||
|
||||||
|
shouldDisplayLoginMethod(LoginMethod.GITHUB) ||
|
||||||
|
shouldDisplayLoginMethod(LoginMethod.GITLAB)) ? (
|
||||||
<div className="mt-6 flex flex-row text-sm text-bunker-400">
|
<div className="mt-6 flex flex-row text-sm text-bunker-400">
|
||||||
<Link href="/signup">
|
<Link href="/signup">
|
||||||
<span className="cursor-pointer duration-200 hover:text-bunker-200 hover:underline hover:decoration-primary-700 hover:underline-offset-4">
|
<span className="cursor-pointer duration-200 hover:text-bunker-200 hover:underline hover:decoration-primary-700 hover:underline-offset-4">
|
||||||
|
|||||||
Reference in New Issue
Block a user