mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
fix: review changes
This commit is contained in:
@@ -355,15 +355,13 @@ export const licenseServiceFactory = ({
|
||||
projectId,
|
||||
refreshCache
|
||||
}: TOrgPlanDTO) => {
|
||||
const isChildOrg = rootOrgId !== actorOrgId;
|
||||
|
||||
await permissionService.getOrgPermission({
|
||||
actorId,
|
||||
actor,
|
||||
orgId,
|
||||
actorOrgId,
|
||||
actorAuthMethod,
|
||||
scope: isChildOrg ? OrganizationActionScope.ChildOrganization : OrganizationActionScope.ParentOrganization
|
||||
scope: OrganizationActionScope.Any
|
||||
});
|
||||
if (refreshCache) {
|
||||
await refreshPlan(rootOrgId);
|
||||
|
||||
@@ -170,7 +170,7 @@ export const IDENTITIES = {
|
||||
}
|
||||
} as const;
|
||||
|
||||
const IDENTITY_AUTH_SUB_ORGANIZATION_NAME = "sub-organization slug to scope the token to";
|
||||
const IDENTITY_AUTH_SUB_ORGANIZATION_NAME = "sub-organization name to scope the token to";
|
||||
|
||||
export const UNIVERSAL_AUTH = {
|
||||
LOGIN: {
|
||||
@@ -612,7 +612,7 @@ export const TOKEN_AUTH = {
|
||||
CREATE_TOKEN: {
|
||||
identityId: "The ID of the machine identity to create the token for.",
|
||||
name: "The name of the token to create.",
|
||||
subOrganizationName: "The sub organization slug to scope the token to."
|
||||
subOrganizationName: "The sub organization name to scope the token to."
|
||||
},
|
||||
UPDATE_TOKEN: {
|
||||
tokenId: "The ID of the token to update metadata for.",
|
||||
|
||||
@@ -92,28 +92,15 @@ export const registerAuthRoutes = async (server: FastifyZodProvider) => {
|
||||
let expiresIn: string | number = appCfg.JWT_AUTH_LIFETIME;
|
||||
|
||||
if (decodedToken.organizationId) {
|
||||
if (decodedToken.subOrganizationId) {
|
||||
const subOrg = await server.services.org.findOrganizationById({
|
||||
userId: decodedToken.userId,
|
||||
orgId: decodedToken.subOrganizationId,
|
||||
actorAuthMethod: decodedToken.authMethod,
|
||||
actorOrgId: decodedToken.subOrganizationId,
|
||||
rootOrgId: decodedToken.organizationId
|
||||
});
|
||||
if (subOrg && subOrg.userTokenExpiration) {
|
||||
expiresIn = getMinExpiresIn(appCfg.JWT_AUTH_LIFETIME, subOrg.userTokenExpiration);
|
||||
}
|
||||
} else {
|
||||
const org = await server.services.org.findOrganizationById({
|
||||
userId: decodedToken.userId,
|
||||
orgId: decodedToken.organizationId,
|
||||
actorAuthMethod: decodedToken.authMethod,
|
||||
actorOrgId: decodedToken.organizationId,
|
||||
rootOrgId: decodedToken.organizationId
|
||||
});
|
||||
if (org && org.userTokenExpiration) {
|
||||
expiresIn = getMinExpiresIn(appCfg.JWT_AUTH_LIFETIME, org.userTokenExpiration);
|
||||
}
|
||||
const org = await server.services.org.findOrganizationById({
|
||||
userId: decodedToken.userId,
|
||||
orgId: decodedToken.subOrganizationId ? decodedToken.subOrganizationId : decodedToken.organizationId,
|
||||
actorAuthMethod: decodedToken.authMethod,
|
||||
actorOrgId: decodedToken.subOrganizationId ? decodedToken.subOrganizationId : decodedToken.organizationId,
|
||||
rootOrgId: decodedToken.organizationId
|
||||
});
|
||||
if (org && org.userTokenExpiration) {
|
||||
expiresIn = getMinExpiresIn(appCfg.JWT_AUTH_LIFETIME, org.userTokenExpiration);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -5,6 +5,7 @@ import { IdentityAlicloudAuthsSchema } from "@app/db/schemas";
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ALICLOUD_AUTH, ApiDocsTags } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -38,7 +39,7 @@ export const registerIdentityAliCloudAuthRouter = async (server: FastifyZodProvi
|
||||
message: "AccessKeyId must be alphanumeric"
|
||||
})
|
||||
.describe(ALICLOUD_AUTH.LOGIN.AccessKeyId),
|
||||
subOrganizationName: z.string().trim().optional().describe(ALICLOUD_AUTH.LOGIN.subOrganizationName),
|
||||
subOrganizationName: slugSchema().optional().describe(ALICLOUD_AUTH.LOGIN.subOrganizationName),
|
||||
SignatureMethod: z.enum(["HMAC-SHA1"]).describe(ALICLOUD_AUTH.LOGIN.SignatureMethod),
|
||||
Timestamp: z
|
||||
.string()
|
||||
@@ -75,10 +76,7 @@ export const registerIdentityAliCloudAuthRouter = async (server: FastifyZodProvi
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { identityAliCloudAuth, accessToken, identityAccessToken, identity } =
|
||||
await server.services.identityAliCloudAuth.login({
|
||||
...req.body,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
});
|
||||
await server.services.identityAliCloudAuth.login(req.body);
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
|
||||
@@ -4,6 +4,7 @@ import { IdentityAwsAuthsSchema } from "@app/db/schemas";
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, AWS_AUTH } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -29,7 +30,7 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
|
||||
iamHttpRequestMethod: z.string().default("POST").describe(AWS_AUTH.LOGIN.iamHttpRequestMethod),
|
||||
iamRequestBody: z.string().describe(AWS_AUTH.LOGIN.iamRequestBody),
|
||||
iamRequestHeaders: z.string().describe(AWS_AUTH.LOGIN.iamRequestHeaders),
|
||||
subOrganizationName: z.string().trim().optional().describe(AWS_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(AWS_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -42,10 +43,7 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider)
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { identityAwsAuth, accessToken, identityAccessToken, identity } =
|
||||
await server.services.identityAwsAuth.login({
|
||||
...req.body,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
});
|
||||
await server.services.identityAwsAuth.login(req.body);
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
|
||||
@@ -4,6 +4,7 @@ import { IdentityAzureAuthsSchema } from "@app/db/schemas";
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, AZURE_AUTH } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -24,7 +25,7 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider
|
||||
body: z.object({
|
||||
identityId: z.string().trim().describe(AZURE_AUTH.LOGIN.identityId),
|
||||
jwt: z.string(),
|
||||
subOrganizationName: z.string().trim().optional().describe(AZURE_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(AZURE_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
|
||||
@@ -4,6 +4,7 @@ import { IdentityGcpAuthsSchema } from "@app/db/schemas";
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, GCP_AUTH } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -24,7 +25,7 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
|
||||
body: z.object({
|
||||
identityId: z.string().trim().describe(GCP_AUTH.LOGIN.identityId),
|
||||
jwt: z.string(),
|
||||
subOrganizationName: z.string().trim().optional().describe(GCP_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(GCP_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -37,10 +38,7 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider)
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { identityGcpAuth, accessToken, identityAccessToken, identity } =
|
||||
await server.services.identityGcpAuth.login({
|
||||
...req.body,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
});
|
||||
await server.services.identityGcpAuth.login(req.body);
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
|
||||
@@ -4,6 +4,7 @@ import { IdentityJwtAuthsSchema } from "@app/db/schemas";
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, JWT_AUTH } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -100,7 +101,7 @@ export const registerIdentityJwtAuthRouter = async (server: FastifyZodProvider)
|
||||
body: z.object({
|
||||
identityId: z.string().trim().describe(JWT_AUTH.LOGIN.identityId),
|
||||
jwt: z.string().trim(),
|
||||
subOrganizationName: z.string().trim().optional().describe(JWT_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(JWT_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -113,11 +114,7 @@ export const registerIdentityJwtAuthRouter = async (server: FastifyZodProvider)
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { identityJwtAuth, accessToken, identityAccessToken, identity } =
|
||||
await server.services.identityJwtAuth.login({
|
||||
identityId: req.body.identityId,
|
||||
jwt: req.body.jwt,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
});
|
||||
await server.services.identityJwtAuth.login(req.body);
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
|
||||
@@ -5,6 +5,7 @@ import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, KUBERNETES_AUTH } from "@app/lib/api-docs";
|
||||
import { CharacterType, characterValidator } from "@app/lib/validator/validate-string";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -45,7 +46,7 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
|
||||
body: z.object({
|
||||
identityId: z.string().trim().describe(KUBERNETES_AUTH.LOGIN.identityId),
|
||||
jwt: z.string().trim(),
|
||||
subOrganizationName: z.string().trim().optional().describe(KUBERNETES_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(KUBERNETES_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -58,11 +59,7 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { identityKubernetesAuth, accessToken, identityAccessToken, identity } =
|
||||
await server.services.identityKubernetesAuth.login({
|
||||
identityId: req.body.identityId,
|
||||
jwt: req.body.jwt,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
});
|
||||
await server.services.identityKubernetesAuth.login(req.body);
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
|
||||
@@ -21,6 +21,7 @@ import { getConfig } from "@app/lib/config/env";
|
||||
import { UnauthorizedError } from "@app/lib/errors";
|
||||
import { logger } from "@app/lib/logger";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -125,7 +126,7 @@ export const registerIdentityLdapAuthRouter = async (server: FastifyZodProvider)
|
||||
identityId: z.string().trim().describe(LDAP_AUTH.LOGIN.identityId),
|
||||
username: z.string().describe(LDAP_AUTH.LOGIN.username),
|
||||
password: z.string().describe(LDAP_AUTH.LOGIN.password),
|
||||
subOrganizationName: z.string().trim().optional().describe(LDAP_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(LDAP_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
|
||||
@@ -4,6 +4,7 @@ import { IdentityOciAuthsSchema } from "@app/db/schemas";
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, OCI_AUTH } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -41,7 +42,7 @@ export const registerIdentityOciAuthRouter = async (server: FastifyZodProvider)
|
||||
}
|
||||
})
|
||||
.describe(OCI_AUTH.LOGIN.headers),
|
||||
subOrganizationName: z.string().trim().optional().describe(OCI_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(OCI_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -54,10 +55,7 @@ export const registerIdentityOciAuthRouter = async (server: FastifyZodProvider)
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { identityOciAuth, accessToken, identityAccessToken, identity } =
|
||||
await server.services.identityOciAuth.login({
|
||||
...req.body,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
});
|
||||
await server.services.identityOciAuth.login(req.body);
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
|
||||
@@ -4,6 +4,7 @@ import { IdentityOidcAuthsSchema } from "@app/db/schemas";
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, OIDC_AUTH } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -48,7 +49,7 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
|
||||
body: z.object({
|
||||
identityId: z.string().trim().describe(OIDC_AUTH.LOGIN.identityId),
|
||||
jwt: z.string().trim(),
|
||||
subOrganizationName: z.string().trim().optional().describe(OIDC_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(OIDC_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -61,11 +62,7 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider)
|
||||
},
|
||||
handler: async (req) => {
|
||||
const { identityOidcAuth, accessToken, identityAccessToken, identity, oidcTokenData } =
|
||||
await server.services.identityOidcAuth.login({
|
||||
identityId: req.body.identityId,
|
||||
jwt: req.body.jwt,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
});
|
||||
await server.services.identityOidcAuth.login(req.body);
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
...req.auditLogInfo,
|
||||
|
||||
@@ -7,6 +7,7 @@ import { getConfig } from "@app/lib/config/env";
|
||||
import { crypto } from "@app/lib/crypto/cryptography";
|
||||
import { BadRequestError } from "@app/lib/errors";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -47,7 +48,7 @@ export const registerIdentityTlsCertAuthRouter = async (server: FastifyZodProvid
|
||||
description: "Login with TLS Certificate Auth for machine identity",
|
||||
body: z.object({
|
||||
identityId: z.string().trim().describe(TLS_CERT_AUTH.LOGIN.identityId),
|
||||
subOrganizationName: z.string().trim().optional().describe(TLS_CERT_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(TLS_CERT_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -67,9 +68,8 @@ export const registerIdentityTlsCertAuthRouter = async (server: FastifyZodProvid
|
||||
|
||||
const { identityTlsCertAuth, accessToken, identityAccessToken, identity } =
|
||||
await server.services.identityTlsCertAuth.login({
|
||||
identityId: req.body.identityId,
|
||||
clientCertificate: clientCertificate as string,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
...req.body,
|
||||
clientCertificate: clientCertificate as string
|
||||
});
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
|
||||
@@ -4,6 +4,7 @@ import { IdentityAccessTokensSchema, IdentityTokenAuthsSchema } from "@app/db/sc
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, TOKEN_AUTH } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -308,7 +309,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
|
||||
}),
|
||||
body: z.object({
|
||||
name: z.string().optional().describe(TOKEN_AUTH.CREATE_TOKEN.name),
|
||||
subOrganizationName: z.string().trim().optional().describe(TOKEN_AUTH.CREATE_TOKEN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(TOKEN_AUTH.CREATE_TOKEN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -329,8 +330,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider
|
||||
actorOrgId: req.permission.orgId,
|
||||
identityId: req.params.identityId,
|
||||
isActorSuperAdmin: isSuperAdmin(req.auth),
|
||||
...req.body,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
...req.body
|
||||
});
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
|
||||
@@ -4,6 +4,7 @@ import { IdentityUaClientSecretsSchema, IdentityUniversalAuthsSchema } from "@ap
|
||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { ApiDocsTags, UNIVERSAL_AUTH } from "@app/lib/api-docs";
|
||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { slugSchema } from "@app/server/lib/schemas";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||
@@ -36,7 +37,7 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => {
|
||||
body: z.object({
|
||||
clientId: z.string().trim().describe(UNIVERSAL_AUTH.LOGIN.clientId),
|
||||
clientSecret: z.string().trim().describe(UNIVERSAL_AUTH.LOGIN.clientSecret),
|
||||
subOrganizationName: z.string().trim().optional().describe(UNIVERSAL_AUTH.LOGIN.subOrganizationName)
|
||||
subOrganizationName: slugSchema().optional().describe(UNIVERSAL_AUTH.LOGIN.subOrganizationName)
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
@@ -57,10 +58,8 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => {
|
||||
accessTokenTTL,
|
||||
accessTokenMaxTTL
|
||||
} = await server.services.identityUa.login({
|
||||
clientId: req.body.clientId,
|
||||
clientSecret: req.body.clientSecret,
|
||||
ip: req.realIp,
|
||||
subOrganizationName: req.body.subOrganizationName
|
||||
...req.body,
|
||||
ip: req.realIp
|
||||
});
|
||||
|
||||
await server.services.auditLog.createAuditLog({
|
||||
|
||||
@@ -543,7 +543,6 @@ export const authLoginServiceFactory = ({
|
||||
|
||||
const isSubOrganization = Boolean(selectedOrg.rootOrgId && selectedOrg.id !== selectedOrg.rootOrgId);
|
||||
|
||||
let rootOrg = selectedOrg;
|
||||
let membershipRole;
|
||||
|
||||
if (isSubOrganization) {
|
||||
@@ -553,13 +552,6 @@ export const authLoginServiceFactory = ({
|
||||
});
|
||||
}
|
||||
|
||||
rootOrg = await orgDAL.findById(selectedOrg.rootOrgId);
|
||||
if (!rootOrg) {
|
||||
throw new BadRequestError({
|
||||
message: "Invalid root organization"
|
||||
});
|
||||
}
|
||||
|
||||
// Check user membership in the sub-organization
|
||||
const orgMembership = await membershipUserDAL.findOne({
|
||||
actorUserId: user.id,
|
||||
@@ -577,7 +569,7 @@ export const authLoginServiceFactory = ({
|
||||
// Check user membership in the root organization
|
||||
const rootOrgMembership = await membershipUserDAL.findOne({
|
||||
actorUserId: user.id,
|
||||
scopeOrgId: rootOrg.id,
|
||||
scopeOrgId: selectedOrg.rootOrgId,
|
||||
scope: AccessScope.Organization,
|
||||
status: OrgMembershipStatus.Accepted
|
||||
});
|
||||
@@ -665,7 +657,7 @@ export const authLoginServiceFactory = ({
|
||||
user,
|
||||
userAgent,
|
||||
ip: ipAddress,
|
||||
organizationId: isSubOrganization ? rootOrg.id : organizationId,
|
||||
organizationId: isSubOrganization ? selectedOrg.rootOrgId || "" : organizationId,
|
||||
subOrganizationId: isSubOrganization ? organizationId : undefined,
|
||||
isMfaVerified: decodedToken.isMfaVerified,
|
||||
mfaMethod: decodedToken.mfaMethod
|
||||
@@ -755,7 +747,7 @@ export const authLoginServiceFactory = ({
|
||||
metadata: {
|
||||
organizationId,
|
||||
organizationName: selectedOrg.name,
|
||||
rootOrganizationId: rootOrg.id
|
||||
rootOrganizationId: selectedOrg.rootOrgId || ""
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
@@ -210,11 +210,9 @@ export const identityAccessTokenServiceFactory = ({
|
||||
|
||||
const identityOrgDetails = await orgDAL.findOne({ id: scopeOrgId });
|
||||
|
||||
const isSubOrg = !!(identityOrgDetails.rootOrgId || identityOrgDetails.parentOrgId);
|
||||
const isSubOrg = Boolean(identityOrgDetails.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg
|
||||
? identityOrgDetails.rootOrgId || identityOrgDetails.parentOrgId || identityOrgDetails.id
|
||||
: identityOrgDetails.id;
|
||||
const rootOrgId = isSubOrg ? identityOrgDetails.rootOrgId || identityOrgDetails.id : identityOrgDetails.id;
|
||||
|
||||
// Verify identity membership in the organization
|
||||
const identityOrgMembership = await membershipIdentityDAL.findOne({
|
||||
|
||||
@@ -80,7 +80,7 @@ export const identityAliCloudAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -119,7 +119,7 @@ export const identityAwsAuthServiceFactory = ({
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -75,7 +75,7 @@ export const identityAzureAuthServiceFactory = ({
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -72,7 +72,7 @@ export const identityGcpAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -86,7 +86,7 @@ export const identityJwtAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -198,7 +198,7 @@ export const identityKubernetesAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -167,7 +167,7 @@ export const identityLdapAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -76,7 +76,7 @@ export const identityOciAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -87,7 +87,7 @@ export const identityOidcAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -85,7 +85,7 @@ export const identityTlsCertAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -505,7 +505,7 @@ export const identityTokenAuthServiceFactory = ({
|
||||
if (!identity) throw new UnauthorizedError({ message: "Identity not found" });
|
||||
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id;
|
||||
|
||||
|
||||
@@ -91,7 +91,7 @@ export const identityUaServiceFactory = ({
|
||||
|
||||
const identity = await identityDAL.findById(identityUa.identityId);
|
||||
const org = await orgDAL.findById(identity.orgId);
|
||||
const isSubOrg = !!(org.rootOrgId || org.parentOrgId);
|
||||
const isSubOrg = Boolean(org.rootOrgId);
|
||||
|
||||
const rootOrgId = isSubOrg ? org.rootOrgId || "" : org.id;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user