misc: added check for ldap group

This commit is contained in:
Sheen Capadngan
2024-07-01 18:12:16 +08:00
parent 0bb2b2887b
commit 0b8f6878fe

View File

@@ -53,7 +53,7 @@ import {
TTestLdapConnectionDTO, TTestLdapConnectionDTO,
TUpdateLdapCfgDTO TUpdateLdapCfgDTO
} from "./ldap-config-types"; } from "./ldap-config-types";
import { testLDAPConfig } from "./ldap-fns"; import { searchGroups, testLDAPConfig } from "./ldap-fns";
import { TLdapGroupMapDALFactory } from "./ldap-group-map-dal"; import { TLdapGroupMapDALFactory } from "./ldap-group-map-dal";
type TLdapConfigServiceFactoryDep = { type TLdapConfigServiceFactoryDep = {
@@ -286,7 +286,7 @@ export const ldapConfigServiceFactory = ({
return ldapConfig; return ldapConfig;
}; };
const getLdapCfg = async (filter: { orgId: string; isActive?: boolean }) => { const getLdapCfg = async (filter: { orgId: string; isActive?: boolean; id?: string }) => {
const ldapConfig = await ldapConfigDAL.findOne(filter); const ldapConfig = await ldapConfigDAL.findOne(filter);
if (!ldapConfig) throw new BadRequestError({ message: "Failed to find organization LDAP data" }); if (!ldapConfig) throw new BadRequestError({ message: "Failed to find organization LDAP data" });
@@ -716,11 +716,25 @@ export const ldapConfigServiceFactory = ({
message: "Failed to create LDAP group map due to plan restriction. Upgrade plan to create LDAP group map." message: "Failed to create LDAP group map due to plan restriction. Upgrade plan to create LDAP group map."
}); });
const ldapConfig = await ldapConfigDAL.findOne({ const ldapConfig = await getLdapCfg({
id: ldapConfigId, orgId,
orgId id: ldapConfigId
}); });
if (!ldapConfig) throw new BadRequestError({ message: "Failed to find organization LDAP data" });
if (!ldapConfig.groupSearchBase) {
throw new BadRequestError({
message: "Configure a group search base in your LDAP configuration in order to proceed."
});
}
const groupSearchFilter = `(cn=${ldapGroupCN})`;
const groups = await searchGroups(ldapConfig, groupSearchFilter, ldapConfig.groupSearchBase);
if (!groups.some((g) => g.cn === ldapGroupCN)) {
throw new BadRequestError({
message: "Failed to find LDAP Group CN"
});
}
const group = await groupDAL.findOne({ slug: groupSlug, orgId }); const group = await groupDAL.findOne({ slug: groupSlug, orgId });
if (!group) throw new BadRequestError({ message: "Failed to find group" }); if (!group) throw new BadRequestError({ message: "Failed to find group" });