mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 07:26:45 +00:00
misc: add oidc saml handling for login check
This commit is contained in:
@@ -608,6 +608,7 @@ export const registerRoutes = async (
|
|||||||
});
|
});
|
||||||
const superAdminService = superAdminServiceFactory({
|
const superAdminService = superAdminServiceFactory({
|
||||||
userDAL,
|
userDAL,
|
||||||
|
userAliasDAL,
|
||||||
authService: loginService,
|
authService: loginService,
|
||||||
serverCfgDAL: superAdminDAL,
|
serverCfgDAL: superAdminDAL,
|
||||||
kmsRootConfigDAL,
|
kmsRootConfigDAL,
|
||||||
|
|||||||
@@ -16,12 +16,15 @@ import { TKmsServiceFactory } from "../kms/kms-service";
|
|||||||
import { RootKeyEncryptionStrategy } from "../kms/kms-types";
|
import { RootKeyEncryptionStrategy } from "../kms/kms-types";
|
||||||
import { TOrgServiceFactory } from "../org/org-service";
|
import { TOrgServiceFactory } from "../org/org-service";
|
||||||
import { TUserDALFactory } from "../user/user-dal";
|
import { TUserDALFactory } from "../user/user-dal";
|
||||||
|
import { TUserAliasDALFactory } from "../user-alias/user-alias-dal";
|
||||||
|
import { UserAliasType } from "../user-alias/user-alias-types";
|
||||||
import { TSuperAdminDALFactory } from "./super-admin-dal";
|
import { TSuperAdminDALFactory } from "./super-admin-dal";
|
||||||
import { LoginMethod, TAdminGetUsersDTO, TAdminSignUpDTO } from "./super-admin-types";
|
import { LoginMethod, TAdminGetUsersDTO, TAdminSignUpDTO } from "./super-admin-types";
|
||||||
|
|
||||||
type TSuperAdminServiceFactoryDep = {
|
type TSuperAdminServiceFactoryDep = {
|
||||||
serverCfgDAL: TSuperAdminDALFactory;
|
serverCfgDAL: TSuperAdminDALFactory;
|
||||||
userDAL: TUserDALFactory;
|
userDAL: TUserDALFactory;
|
||||||
|
userAliasDAL: Pick<TUserAliasDALFactory, "findOne">;
|
||||||
authService: Pick<TAuthLoginFactory, "generateUserTokens">;
|
authService: Pick<TAuthLoginFactory, "generateUserTokens">;
|
||||||
kmsService: Pick<TKmsServiceFactory, "encryptWithRootKey" | "decryptWithRootKey" | "updateEncryptionStrategy">;
|
kmsService: Pick<TKmsServiceFactory, "encryptWithRootKey" | "decryptWithRootKey" | "updateEncryptionStrategy">;
|
||||||
kmsRootConfigDAL: TKmsRootConfigDALFactory;
|
kmsRootConfigDAL: TKmsRootConfigDALFactory;
|
||||||
@@ -48,6 +51,7 @@ const ADMIN_CONFIG_DB_UUID = "00000000-0000-0000-0000-000000000000";
|
|||||||
export const superAdminServiceFactory = ({
|
export const superAdminServiceFactory = ({
|
||||||
serverCfgDAL,
|
serverCfgDAL,
|
||||||
userDAL,
|
userDAL,
|
||||||
|
userAliasDAL,
|
||||||
authService,
|
authService,
|
||||||
orgService,
|
orgService,
|
||||||
keyStore,
|
keyStore,
|
||||||
@@ -104,29 +108,43 @@ export const superAdminServiceFactory = ({
|
|||||||
|
|
||||||
if (data.enabledLoginMethods) {
|
if (data.enabledLoginMethods) {
|
||||||
const superAdminUser = await userDAL.findById(userId);
|
const superAdminUser = await userDAL.findById(userId);
|
||||||
|
const isSamlConfiguredForUser = Boolean(
|
||||||
|
await userAliasDAL.findOne({
|
||||||
|
userId,
|
||||||
|
aliasType: UserAliasType.SAML
|
||||||
|
})
|
||||||
|
);
|
||||||
|
|
||||||
|
const isUserSamlAccessEnabled = isSamlConfiguredForUser && data.enabledLoginMethods.includes(LoginMethod.SAML);
|
||||||
|
const isOidcConfiguredForUser = Boolean(
|
||||||
|
await userAliasDAL.findOne({
|
||||||
|
userId,
|
||||||
|
aliasType: UserAliasType.OIDC
|
||||||
|
})
|
||||||
|
);
|
||||||
|
|
||||||
|
const isUserOidcAccessEnabled = isOidcConfiguredForUser && data.enabledLoginMethods.includes(LoginMethod.OIDC);
|
||||||
|
|
||||||
const loginMethodToAuthMethod = {
|
const loginMethodToAuthMethod = {
|
||||||
[LoginMethod.EMAIL]: [AuthMethod.EMAIL],
|
[LoginMethod.EMAIL]: [AuthMethod.EMAIL],
|
||||||
[LoginMethod.GOOGLE]: [AuthMethod.GOOGLE],
|
[LoginMethod.GOOGLE]: [AuthMethod.GOOGLE],
|
||||||
[LoginMethod.GITLAB]: [AuthMethod.GITLAB],
|
[LoginMethod.GITLAB]: [AuthMethod.GITLAB],
|
||||||
[LoginMethod.GITHUB]: [AuthMethod.GITHUB],
|
[LoginMethod.GITHUB]: [AuthMethod.GITHUB],
|
||||||
[LoginMethod.LDAP]: [AuthMethod.LDAP],
|
[LoginMethod.LDAP]: [AuthMethod.LDAP],
|
||||||
[LoginMethod.OIDC]: [AuthMethod.OIDC],
|
[LoginMethod.SAML]: [],
|
||||||
[LoginMethod.SAML]: [
|
[LoginMethod.OIDC]: []
|
||||||
AuthMethod.AZURE_SAML,
|
|
||||||
AuthMethod.GOOGLE_SAML,
|
|
||||||
AuthMethod.JUMPCLOUD_SAML,
|
|
||||||
AuthMethod.KEYCLOAK_SAML,
|
|
||||||
AuthMethod.OKTA_SAML
|
|
||||||
]
|
|
||||||
};
|
};
|
||||||
|
|
||||||
if (
|
const canServerAdminAccessAfterApply =
|
||||||
!data.enabledLoginMethods.some((loginMethod) =>
|
data.enabledLoginMethods.some((loginMethod) =>
|
||||||
loginMethodToAuthMethod[loginMethod as LoginMethod].some(
|
loginMethodToAuthMethod[loginMethod as LoginMethod].some(
|
||||||
(authMethod) => superAdminUser.authMethods?.includes(authMethod)
|
(authMethod) => superAdminUser.authMethods?.includes(authMethod)
|
||||||
)
|
)
|
||||||
)
|
) ||
|
||||||
) {
|
isUserSamlAccessEnabled ||
|
||||||
|
isUserOidcAccessEnabled;
|
||||||
|
|
||||||
|
if (!canServerAdminAccessAfterApply) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "You must configure at least one auth method to prevent account lockout"
|
message: "You must configure at least one auth method to prevent account lockout"
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user