misc: addressed feedback

This commit is contained in:
Sheen Capadngan
2025-04-17 04:00:02 +08:00
parent fc2e5d18b7
commit 1137247e69
14 changed files with 29 additions and 29 deletions
@@ -3,17 +3,17 @@ import { Knex } from "knex";
import { TableName } from "../schemas"; import { TableName } from "../schemas";
export async function up(knex: Knex): Promise<void> { export async function up(knex: Knex): Promise<void> {
if (!(await knex.schema.hasColumn(TableName.Organization, "enableBypassOrgAuth"))) { if (!(await knex.schema.hasColumn(TableName.Organization, "bypassOrgAuthEnabled"))) {
await knex.schema.alterTable(TableName.Organization, (t) => { await knex.schema.alterTable(TableName.Organization, (t) => {
t.boolean("enableBypassOrgAuth").defaultTo(false).notNullable(); t.boolean("bypassOrgAuthEnabled").defaultTo(false).notNullable();
}); });
} }
} }
export async function down(knex: Knex): Promise<void> { export async function down(knex: Knex): Promise<void> {
if (await knex.schema.hasColumn(TableName.Organization, "enableBypassOrgAuth")) { if (await knex.schema.hasColumn(TableName.Organization, "bypassOrgAuthEnabled")) {
await knex.schema.alterTable(TableName.Organization, (t) => { await knex.schema.alterTable(TableName.Organization, (t) => {
t.dropColumn("enableBypassOrgAuth"); t.dropColumn("bypassOrgAuthEnabled");
}); });
} }
} }
+1 -1
View File
@@ -27,7 +27,7 @@ export const OrganizationsSchema = z.object({
shouldUseNewPrivilegeSystem: z.boolean().default(true), shouldUseNewPrivilegeSystem: z.boolean().default(true),
privilegeUpgradeInitiatedByUsername: z.string().nullable().optional(), privilegeUpgradeInitiatedByUsername: z.string().nullable().optional(),
privilegeUpgradeInitiatedAt: z.date().nullable().optional(), privilegeUpgradeInitiatedAt: z.date().nullable().optional(),
enableBypassOrgAuth: z.boolean().default(false) bypassOrgAuthEnabled: z.boolean().default(false)
}); });
export type TOrganizations = z.infer<typeof OrganizationsSchema>; export type TOrganizations = z.infer<typeof OrganizationsSchema>;
@@ -54,7 +54,7 @@ export const permissionDALFactory = (db: TDbClient) => {
db.ref("slug").withSchema(TableName.OrgRoles).withSchema(TableName.OrgRoles).as("customRoleSlug"), db.ref("slug").withSchema(TableName.OrgRoles).withSchema(TableName.OrgRoles).as("customRoleSlug"),
db.ref("permissions").withSchema(TableName.OrgRoles), db.ref("permissions").withSchema(TableName.OrgRoles),
db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"), db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"),
db.ref("enableBypassOrgAuth").withSchema(TableName.Organization).as("enableBypassOrgAuth"), db.ref("bypassOrgAuthEnabled").withSchema(TableName.Organization).as("bypassOrgAuthEnabled"),
db.ref("groupId").withSchema("userGroups"), db.ref("groupId").withSchema("userGroups"),
db.ref("groupOrgId").withSchema("userGroups"), db.ref("groupOrgId").withSchema("userGroups"),
db.ref("groupName").withSchema("userGroups"), db.ref("groupName").withSchema("userGroups"),
@@ -73,7 +73,7 @@ export const permissionDALFactory = (db: TDbClient) => {
OrgMembershipsSchema.extend({ OrgMembershipsSchema.extend({
permissions: z.unknown(), permissions: z.unknown(),
orgAuthEnforced: z.boolean().optional().nullable(), orgAuthEnforced: z.boolean().optional().nullable(),
enableBypassOrgAuth: z.boolean(), bypassOrgAuthEnabled: z.boolean(),
customRoleSlug: z.string().optional().nullable(), customRoleSlug: z.string().optional().nullable(),
shouldUseNewPrivilegeSystem: z.boolean() shouldUseNewPrivilegeSystem: z.boolean()
}).parse(el), }).parse(el),
@@ -678,7 +678,7 @@ export const permissionDALFactory = (db: TDbClient) => {
db.ref("key").withSchema(TableName.IdentityMetadata).as("metadataKey"), db.ref("key").withSchema(TableName.IdentityMetadata).as("metadataKey"),
db.ref("value").withSchema(TableName.IdentityMetadata).as("metadataValue"), db.ref("value").withSchema(TableName.IdentityMetadata).as("metadataValue"),
db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"), db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"),
db.ref("enableBypassOrgAuth").withSchema(TableName.Organization).as("enableBypassOrgAuth"), db.ref("bypassOrgAuthEnabled").withSchema(TableName.Organization).as("bypassOrgAuthEnabled"),
db.ref("role").withSchema(TableName.OrgMembership).as("orgRole"), db.ref("role").withSchema(TableName.OrgMembership).as("orgRole"),
db.ref("orgId").withSchema(TableName.Project), db.ref("orgId").withSchema(TableName.Project),
db.ref("type").withSchema(TableName.Project).as("projectType"), db.ref("type").withSchema(TableName.Project).as("projectType"),
@@ -702,7 +702,7 @@ export const permissionDALFactory = (db: TDbClient) => {
membershipUpdatedAt, membershipUpdatedAt,
projectType, projectType,
shouldUseNewPrivilegeSystem, shouldUseNewPrivilegeSystem,
enableBypassOrgAuth bypassOrgAuthEnabled
}) => ({ }) => ({
orgId, orgId,
orgAuthEnforced, orgAuthEnforced,
@@ -715,7 +715,7 @@ export const permissionDALFactory = (db: TDbClient) => {
createdAt: membershipCreatedAt || groupMembershipCreatedAt, createdAt: membershipCreatedAt || groupMembershipCreatedAt,
updatedAt: membershipUpdatedAt || groupMembershipUpdatedAt, updatedAt: membershipUpdatedAt || groupMembershipUpdatedAt,
shouldUseNewPrivilegeSystem, shouldUseNewPrivilegeSystem,
enableBypassOrgAuth bypassOrgAuthEnabled
}), }),
childrenMapper: [ childrenMapper: [
{ {
@@ -121,7 +121,7 @@ function isAuthMethodSaml(actorAuthMethod: ActorAuthMethod) {
function validateOrgSSO( function validateOrgSSO(
actorAuthMethod: ActorAuthMethod, actorAuthMethod: ActorAuthMethod,
isOrgSsoEnforced: TOrganizations["authEnforced"], isOrgSsoEnforced: TOrganizations["authEnforced"],
isOrgSsoBypassEnabled: TOrganizations["enableBypassOrgAuth"], isOrgSsoBypassEnabled: TOrganizations["bypassOrgAuthEnabled"],
orgRole: OrgMembershipRole orgRole: OrgMembershipRole
) { ) {
if (actorAuthMethod === undefined) { if (actorAuthMethod === undefined) {
@@ -142,7 +142,7 @@ export const permissionServiceFactory = ({
validateOrgSSO( validateOrgSSO(
authMethod, authMethod,
membership.orgAuthEnforced, membership.orgAuthEnforced,
membership.enableBypassOrgAuth, membership.bypassOrgAuthEnabled,
membership.role as OrgMembershipRole membership.role as OrgMembershipRole
); );
@@ -234,7 +234,7 @@ export const permissionServiceFactory = ({
validateOrgSSO( validateOrgSSO(
authMethod, authMethod,
userProjectPermission.orgAuthEnforced, userProjectPermission.orgAuthEnforced,
userProjectPermission.enableBypassOrgAuth, userProjectPermission.bypassOrgAuthEnabled,
userProjectPermission.orgRole userProjectPermission.orgRole
); );
@@ -261,7 +261,7 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
enforceMfa: z.boolean().optional(), enforceMfa: z.boolean().optional(),
selectedMfaMethod: z.nativeEnum(MfaMethod).optional(), selectedMfaMethod: z.nativeEnum(MfaMethod).optional(),
allowSecretSharingOutsideOrganization: z.boolean().optional(), allowSecretSharingOutsideOrganization: z.boolean().optional(),
enableBypassOrgAuth: z.boolean().optional() bypassOrgAuthEnabled: z.boolean().optional()
}), }),
response: { response: {
200: z.object({ 200: z.object({
+1 -1
View File
@@ -17,5 +17,5 @@ export const sanitizedOrganizationSchema = OrganizationsSchema.pick({
shouldUseNewPrivilegeSystem: true, shouldUseNewPrivilegeSystem: true,
privilegeUpgradeInitiatedByUsername: true, privilegeUpgradeInitiatedByUsername: true,
privilegeUpgradeInitiatedAt: true, privilegeUpgradeInitiatedAt: true,
enableBypassOrgAuth: true bypassOrgAuthEnabled: true
}); });
+2 -2
View File
@@ -350,7 +350,7 @@ export const orgServiceFactory = ({
enforceMfa, enforceMfa,
selectedMfaMethod, selectedMfaMethod,
allowSecretSharingOutsideOrganization, allowSecretSharingOutsideOrganization,
enableBypassOrgAuth bypassOrgAuthEnabled
} }
}: TUpdateOrgDTO) => { }: TUpdateOrgDTO) => {
const appCfg = getConfig(); const appCfg = getConfig();
@@ -431,7 +431,7 @@ export const orgServiceFactory = ({
enforceMfa, enforceMfa,
selectedMfaMethod, selectedMfaMethod,
allowSecretSharingOutsideOrganization, allowSecretSharingOutsideOrganization,
enableBypassOrgAuth bypassOrgAuthEnabled
}); });
if (!org) throw new NotFoundError({ message: `Organization with ID '${orgId}' not found` }); if (!org) throw new NotFoundError({ message: `Organization with ID '${orgId}' not found` });
return org; return org;
+1 -1
View File
@@ -73,7 +73,7 @@ export type TUpdateOrgDTO = {
enforceMfa: boolean; enforceMfa: boolean;
selectedMfaMethod: MfaMethod; selectedMfaMethod: MfaMethod;
allowSecretSharingOutsideOrganization: boolean; allowSecretSharingOutsideOrganization: boolean;
enableBypassOrgAuth: boolean; bypassOrgAuthEnabled: boolean;
}>; }>;
} & TOrgPermission; } & TOrgPermission;
@@ -111,7 +111,7 @@ export const useUpdateOrg = () => {
enforceMfa, enforceMfa,
selectedMfaMethod, selectedMfaMethod,
allowSecretSharingOutsideOrganization, allowSecretSharingOutsideOrganization,
enableBypassOrgAuth bypassOrgAuthEnabled
}) => { }) => {
return apiRequest.patch(`/api/v1/organization/${orgId}`, { return apiRequest.patch(`/api/v1/organization/${orgId}`, {
name, name,
@@ -122,7 +122,7 @@ export const useUpdateOrg = () => {
enforceMfa, enforceMfa,
selectedMfaMethod, selectedMfaMethod,
allowSecretSharingOutsideOrganization, allowSecretSharingOutsideOrganization,
enableBypassOrgAuth bypassOrgAuthEnabled
}); });
}, },
onSuccess: () => { onSuccess: () => {
+2 -2
View File
@@ -9,7 +9,7 @@ export type Organization = {
createAt: string; createAt: string;
updatedAt: string; updatedAt: string;
authEnforced: boolean; authEnforced: boolean;
enableBypassOrgAuth: boolean; bypassOrgAuthEnabled: boolean;
orgAuthMethod: string; orgAuthMethod: string;
scimEnabled: boolean; scimEnabled: boolean;
slug: string; slug: string;
@@ -31,7 +31,7 @@ export type UpdateOrgDTO = {
enforceMfa?: boolean; enforceMfa?: boolean;
selectedMfaMethod?: MfaMethod; selectedMfaMethod?: MfaMethod;
allowSecretSharingOutsideOrganization?: boolean; allowSecretSharingOutsideOrganization?: boolean;
enableBypassOrgAuth?: boolean; bypassOrgAuthEnabled?: boolean;
}; };
export type BillingDetails = { export type BillingDetails = {
@@ -71,7 +71,7 @@ export const SelectOrganizationPage = () => {
const handleSelectOrganization = useCallback( const handleSelectOrganization = useCallback(
async (organization: Organization) => { async (organization: Organization) => {
const canBypassOrgAuth = const canBypassOrgAuth =
organization.enableBypassOrgAuth && organization.bypassOrgAuthEnabled &&
organization.userRole === OrgMembershipRole.Admin && organization.userRole === OrgMembershipRole.Admin &&
isAdminLogin; isAdminLogin;
@@ -65,7 +65,7 @@ export const OrgGeneralAuthSection = () => {
await mutateAsync({ await mutateAsync({
orgId: currentOrg?.id, orgId: currentOrg?.id,
enableBypassOrgAuth: value bypassOrgAuthEnabled: value
}); });
createNotification({ createNotification({
@@ -129,7 +129,7 @@ export const OrgGeneralAuthSection = () => {
level. level.
</span> </span>
<p className="mt-4"> <p className="mt-4">
In case of a lockout, admins can use the admin login portal in{" "} In case of a lockout, admins can use the admin login portal at{" "}
<a <a
target="_blank" target="_blank"
rel="noopener noreferrer" rel="noopener noreferrer"
@@ -153,7 +153,7 @@ export const OrgGeneralAuthSection = () => {
{(isAllowed) => ( {(isAllowed) => (
<Switch <Switch
id="allow-admin-bypass" id="allow-admin-bypass"
isChecked={currentOrg?.enableBypassOrgAuth ?? false} isChecked={currentOrg?.bypassOrgAuthEnabled ?? false}
onCheckedChange={(value) => handleEnableBypassOrgAuthToggle(value)} onCheckedChange={(value) => handleEnableBypassOrgAuthToggle(value)}
isDisabled={!isAllowed} isDisabled={!isAllowed}
/> />
@@ -92,7 +92,7 @@ export const OrgOIDCSection = (): JSX.Element => {
await updateOrg({ await updateOrg({
orgId: currentOrg?.id, orgId: currentOrg?.id,
enableBypassOrgAuth: value bypassOrgAuthEnabled: value
}); });
createNotification({ createNotification({
@@ -212,7 +212,7 @@ export const OrgOIDCSection = (): JSX.Element => {
level. level.
</span> </span>
<p className="mt-4"> <p className="mt-4">
In case of a lockout, admins can use the admin login portal in{" "} In case of a lockout, admins can use the admin login portal at{" "}
<a <a
target="_blank" target="_blank"
rel="noopener noreferrer" rel="noopener noreferrer"
@@ -236,7 +236,7 @@ export const OrgOIDCSection = (): JSX.Element => {
{(isAllowed) => ( {(isAllowed) => (
<Switch <Switch
id="allow-admin-bypass" id="allow-admin-bypass"
isChecked={currentOrg?.enableBypassOrgAuth ?? false} isChecked={currentOrg?.bypassOrgAuthEnabled ?? false}
onCheckedChange={(value) => handleEnableBypassOrgAuthToggle(value)} onCheckedChange={(value) => handleEnableBypassOrgAuthToggle(value)}
isDisabled={!isAllowed} isDisabled={!isAllowed}
/> />