From 327ebfeb34d899d3c9db97b9166eb14c0a8c4474 Mon Sep 17 00:00:00 2001 From: Piyush Gupta Date: Wed, 3 Dec 2025 13:32:18 +0530 Subject: [PATCH] fix: review changes --- .../ee/services/license/license-service.ts | 4 +-- backend/src/lib/api-docs/constants.ts | 4 +-- backend/src/server/routes/v1/auth-router.ts | 31 ++++++------------- .../v1/identity-alicloud-auth-router.ts | 8 ++--- .../routes/v1/identity-aws-iam-auth-router.ts | 8 ++--- .../routes/v1/identity-azure-auth-router.ts | 3 +- .../routes/v1/identity-gcp-auth-router.ts | 8 ++--- .../routes/v1/identity-jwt-auth-router.ts | 9 ++---- .../v1/identity-kubernetes-auth-router.ts | 9 ++---- .../routes/v1/identity-ldap-auth-router.ts | 3 +- .../routes/v1/identity-oci-auth-router.ts | 8 ++--- .../routes/v1/identity-oidc-auth-router.ts | 9 ++---- .../v1/identity-tls-cert-auth-router.ts | 8 ++--- .../routes/v1/identity-token-auth-router.ts | 6 ++-- .../v1/identity-universal-auth-router.ts | 9 +++--- .../src/services/auth/auth-login-service.ts | 14 ++------- .../identity-access-token-service.ts | 6 ++-- .../identity-alicloud-auth-service.ts | 2 +- .../identity-aws-auth-service.ts | 2 +- .../identity-azure-auth-service.ts | 2 +- .../identity-gcp-auth-service.ts | 2 +- .../identity-jwt-auth-service.ts | 2 +- .../identity-kubernetes-auth-service.ts | 2 +- .../identity-ldap-auth-service.ts | 2 +- .../identity-oci-auth-service.ts | 2 +- .../identity-oidc-auth-service.ts | 2 +- .../identity-tls-cert-auth-service.ts | 2 +- .../identity-token-auth-service.ts | 2 +- .../identity-ua/identity-ua-service.ts | 2 +- 29 files changed, 65 insertions(+), 106 deletions(-) diff --git a/backend/src/ee/services/license/license-service.ts b/backend/src/ee/services/license/license-service.ts index 2113b4c00..c8e311621 100644 --- a/backend/src/ee/services/license/license-service.ts +++ b/backend/src/ee/services/license/license-service.ts @@ -355,15 +355,13 @@ export const licenseServiceFactory = ({ projectId, refreshCache }: TOrgPlanDTO) => { - const isChildOrg = rootOrgId !== actorOrgId; - await permissionService.getOrgPermission({ actorId, actor, orgId, actorOrgId, actorAuthMethod, - scope: isChildOrg ? OrganizationActionScope.ChildOrganization : OrganizationActionScope.ParentOrganization + scope: OrganizationActionScope.Any }); if (refreshCache) { await refreshPlan(rootOrgId); diff --git a/backend/src/lib/api-docs/constants.ts b/backend/src/lib/api-docs/constants.ts index 554eeb635..4cf6160c7 100644 --- a/backend/src/lib/api-docs/constants.ts +++ b/backend/src/lib/api-docs/constants.ts @@ -170,7 +170,7 @@ export const IDENTITIES = { } } as const; -const IDENTITY_AUTH_SUB_ORGANIZATION_NAME = "sub-organization slug to scope the token to"; +const IDENTITY_AUTH_SUB_ORGANIZATION_NAME = "sub-organization name to scope the token to"; export const UNIVERSAL_AUTH = { LOGIN: { @@ -612,7 +612,7 @@ export const TOKEN_AUTH = { CREATE_TOKEN: { identityId: "The ID of the machine identity to create the token for.", name: "The name of the token to create.", - subOrganizationName: "The sub organization slug to scope the token to." + subOrganizationName: "The sub organization name to scope the token to." }, UPDATE_TOKEN: { tokenId: "The ID of the token to update metadata for.", diff --git a/backend/src/server/routes/v1/auth-router.ts b/backend/src/server/routes/v1/auth-router.ts index 16290f1e3..bedc519da 100644 --- a/backend/src/server/routes/v1/auth-router.ts +++ b/backend/src/server/routes/v1/auth-router.ts @@ -92,28 +92,15 @@ export const registerAuthRoutes = async (server: FastifyZodProvider) => { let expiresIn: string | number = appCfg.JWT_AUTH_LIFETIME; if (decodedToken.organizationId) { - if (decodedToken.subOrganizationId) { - const subOrg = await server.services.org.findOrganizationById({ - userId: decodedToken.userId, - orgId: decodedToken.subOrganizationId, - actorAuthMethod: decodedToken.authMethod, - actorOrgId: decodedToken.subOrganizationId, - rootOrgId: decodedToken.organizationId - }); - if (subOrg && subOrg.userTokenExpiration) { - expiresIn = getMinExpiresIn(appCfg.JWT_AUTH_LIFETIME, subOrg.userTokenExpiration); - } - } else { - const org = await server.services.org.findOrganizationById({ - userId: decodedToken.userId, - orgId: decodedToken.organizationId, - actorAuthMethod: decodedToken.authMethod, - actorOrgId: decodedToken.organizationId, - rootOrgId: decodedToken.organizationId - }); - if (org && org.userTokenExpiration) { - expiresIn = getMinExpiresIn(appCfg.JWT_AUTH_LIFETIME, org.userTokenExpiration); - } + const org = await server.services.org.findOrganizationById({ + userId: decodedToken.userId, + orgId: decodedToken.subOrganizationId ? decodedToken.subOrganizationId : decodedToken.organizationId, + actorAuthMethod: decodedToken.authMethod, + actorOrgId: decodedToken.subOrganizationId ? decodedToken.subOrganizationId : decodedToken.organizationId, + rootOrgId: decodedToken.organizationId + }); + if (org && org.userTokenExpiration) { + expiresIn = getMinExpiresIn(appCfg.JWT_AUTH_LIFETIME, org.userTokenExpiration); } } diff --git a/backend/src/server/routes/v1/identity-alicloud-auth-router.ts b/backend/src/server/routes/v1/identity-alicloud-auth-router.ts index 70eb9bea6..817cde667 100644 --- a/backend/src/server/routes/v1/identity-alicloud-auth-router.ts +++ b/backend/src/server/routes/v1/identity-alicloud-auth-router.ts @@ -5,6 +5,7 @@ import { IdentityAlicloudAuthsSchema } from "@app/db/schemas"; import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ALICLOUD_AUTH, ApiDocsTags } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -38,7 +39,7 @@ export const registerIdentityAliCloudAuthRouter = async (server: FastifyZodProvi message: "AccessKeyId must be alphanumeric" }) .describe(ALICLOUD_AUTH.LOGIN.AccessKeyId), - subOrganizationName: z.string().trim().optional().describe(ALICLOUD_AUTH.LOGIN.subOrganizationName), + subOrganizationName: slugSchema().optional().describe(ALICLOUD_AUTH.LOGIN.subOrganizationName), SignatureMethod: z.enum(["HMAC-SHA1"]).describe(ALICLOUD_AUTH.LOGIN.SignatureMethod), Timestamp: z .string() @@ -75,10 +76,7 @@ export const registerIdentityAliCloudAuthRouter = async (server: FastifyZodProvi }, handler: async (req) => { const { identityAliCloudAuth, accessToken, identityAccessToken, identity } = - await server.services.identityAliCloudAuth.login({ - ...req.body, - subOrganizationName: req.body.subOrganizationName - }); + await server.services.identityAliCloudAuth.login(req.body); await server.services.auditLog.createAuditLog({ ...req.auditLogInfo, diff --git a/backend/src/server/routes/v1/identity-aws-iam-auth-router.ts b/backend/src/server/routes/v1/identity-aws-iam-auth-router.ts index 152dd0311..d9d9cab40 100644 --- a/backend/src/server/routes/v1/identity-aws-iam-auth-router.ts +++ b/backend/src/server/routes/v1/identity-aws-iam-auth-router.ts @@ -4,6 +4,7 @@ import { IdentityAwsAuthsSchema } from "@app/db/schemas"; import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, AWS_AUTH } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -29,7 +30,7 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider) iamHttpRequestMethod: z.string().default("POST").describe(AWS_AUTH.LOGIN.iamHttpRequestMethod), iamRequestBody: z.string().describe(AWS_AUTH.LOGIN.iamRequestBody), iamRequestHeaders: z.string().describe(AWS_AUTH.LOGIN.iamRequestHeaders), - subOrganizationName: z.string().trim().optional().describe(AWS_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(AWS_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ @@ -42,10 +43,7 @@ export const registerIdentityAwsAuthRouter = async (server: FastifyZodProvider) }, handler: async (req) => { const { identityAwsAuth, accessToken, identityAccessToken, identity } = - await server.services.identityAwsAuth.login({ - ...req.body, - subOrganizationName: req.body.subOrganizationName - }); + await server.services.identityAwsAuth.login(req.body); await server.services.auditLog.createAuditLog({ ...req.auditLogInfo, diff --git a/backend/src/server/routes/v1/identity-azure-auth-router.ts b/backend/src/server/routes/v1/identity-azure-auth-router.ts index e4277777e..e8dd4341d 100644 --- a/backend/src/server/routes/v1/identity-azure-auth-router.ts +++ b/backend/src/server/routes/v1/identity-azure-auth-router.ts @@ -4,6 +4,7 @@ import { IdentityAzureAuthsSchema } from "@app/db/schemas"; import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, AZURE_AUTH } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -24,7 +25,7 @@ export const registerIdentityAzureAuthRouter = async (server: FastifyZodProvider body: z.object({ identityId: z.string().trim().describe(AZURE_AUTH.LOGIN.identityId), jwt: z.string(), - subOrganizationName: z.string().trim().optional().describe(AZURE_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(AZURE_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ diff --git a/backend/src/server/routes/v1/identity-gcp-auth-router.ts b/backend/src/server/routes/v1/identity-gcp-auth-router.ts index 71f43224e..9f6d284bd 100644 --- a/backend/src/server/routes/v1/identity-gcp-auth-router.ts +++ b/backend/src/server/routes/v1/identity-gcp-auth-router.ts @@ -4,6 +4,7 @@ import { IdentityGcpAuthsSchema } from "@app/db/schemas"; import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, GCP_AUTH } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -24,7 +25,7 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider) body: z.object({ identityId: z.string().trim().describe(GCP_AUTH.LOGIN.identityId), jwt: z.string(), - subOrganizationName: z.string().trim().optional().describe(GCP_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(GCP_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ @@ -37,10 +38,7 @@ export const registerIdentityGcpAuthRouter = async (server: FastifyZodProvider) }, handler: async (req) => { const { identityGcpAuth, accessToken, identityAccessToken, identity } = - await server.services.identityGcpAuth.login({ - ...req.body, - subOrganizationName: req.body.subOrganizationName - }); + await server.services.identityGcpAuth.login(req.body); await server.services.auditLog.createAuditLog({ ...req.auditLogInfo, diff --git a/backend/src/server/routes/v1/identity-jwt-auth-router.ts b/backend/src/server/routes/v1/identity-jwt-auth-router.ts index 3cf79bcfc..a9d0b90c6 100644 --- a/backend/src/server/routes/v1/identity-jwt-auth-router.ts +++ b/backend/src/server/routes/v1/identity-jwt-auth-router.ts @@ -4,6 +4,7 @@ import { IdentityJwtAuthsSchema } from "@app/db/schemas"; import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, JWT_AUTH } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -100,7 +101,7 @@ export const registerIdentityJwtAuthRouter = async (server: FastifyZodProvider) body: z.object({ identityId: z.string().trim().describe(JWT_AUTH.LOGIN.identityId), jwt: z.string().trim(), - subOrganizationName: z.string().trim().optional().describe(JWT_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(JWT_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ @@ -113,11 +114,7 @@ export const registerIdentityJwtAuthRouter = async (server: FastifyZodProvider) }, handler: async (req) => { const { identityJwtAuth, accessToken, identityAccessToken, identity } = - await server.services.identityJwtAuth.login({ - identityId: req.body.identityId, - jwt: req.body.jwt, - subOrganizationName: req.body.subOrganizationName - }); + await server.services.identityJwtAuth.login(req.body); await server.services.auditLog.createAuditLog({ ...req.auditLogInfo, diff --git a/backend/src/server/routes/v1/identity-kubernetes-auth-router.ts b/backend/src/server/routes/v1/identity-kubernetes-auth-router.ts index 9c7b80798..29edf363a 100644 --- a/backend/src/server/routes/v1/identity-kubernetes-auth-router.ts +++ b/backend/src/server/routes/v1/identity-kubernetes-auth-router.ts @@ -5,6 +5,7 @@ import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, KUBERNETES_AUTH } from "@app/lib/api-docs"; import { CharacterType, characterValidator } from "@app/lib/validator/validate-string"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -45,7 +46,7 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide body: z.object({ identityId: z.string().trim().describe(KUBERNETES_AUTH.LOGIN.identityId), jwt: z.string().trim(), - subOrganizationName: z.string().trim().optional().describe(KUBERNETES_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(KUBERNETES_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ @@ -58,11 +59,7 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide }, handler: async (req) => { const { identityKubernetesAuth, accessToken, identityAccessToken, identity } = - await server.services.identityKubernetesAuth.login({ - identityId: req.body.identityId, - jwt: req.body.jwt, - subOrganizationName: req.body.subOrganizationName - }); + await server.services.identityKubernetesAuth.login(req.body); await server.services.auditLog.createAuditLog({ ...req.auditLogInfo, diff --git a/backend/src/server/routes/v1/identity-ldap-auth-router.ts b/backend/src/server/routes/v1/identity-ldap-auth-router.ts index 8cf41d0fc..ec5360345 100644 --- a/backend/src/server/routes/v1/identity-ldap-auth-router.ts +++ b/backend/src/server/routes/v1/identity-ldap-auth-router.ts @@ -21,6 +21,7 @@ import { getConfig } from "@app/lib/config/env"; import { UnauthorizedError } from "@app/lib/errors"; import { logger } from "@app/lib/logger"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -125,7 +126,7 @@ export const registerIdentityLdapAuthRouter = async (server: FastifyZodProvider) identityId: z.string().trim().describe(LDAP_AUTH.LOGIN.identityId), username: z.string().describe(LDAP_AUTH.LOGIN.username), password: z.string().describe(LDAP_AUTH.LOGIN.password), - subOrganizationName: z.string().trim().optional().describe(LDAP_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(LDAP_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ diff --git a/backend/src/server/routes/v1/identity-oci-auth-router.ts b/backend/src/server/routes/v1/identity-oci-auth-router.ts index a243c1a0d..cffba6f41 100644 --- a/backend/src/server/routes/v1/identity-oci-auth-router.ts +++ b/backend/src/server/routes/v1/identity-oci-auth-router.ts @@ -4,6 +4,7 @@ import { IdentityOciAuthsSchema } from "@app/db/schemas"; import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, OCI_AUTH } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -41,7 +42,7 @@ export const registerIdentityOciAuthRouter = async (server: FastifyZodProvider) } }) .describe(OCI_AUTH.LOGIN.headers), - subOrganizationName: z.string().trim().optional().describe(OCI_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(OCI_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ @@ -54,10 +55,7 @@ export const registerIdentityOciAuthRouter = async (server: FastifyZodProvider) }, handler: async (req) => { const { identityOciAuth, accessToken, identityAccessToken, identity } = - await server.services.identityOciAuth.login({ - ...req.body, - subOrganizationName: req.body.subOrganizationName - }); + await server.services.identityOciAuth.login(req.body); await server.services.auditLog.createAuditLog({ ...req.auditLogInfo, diff --git a/backend/src/server/routes/v1/identity-oidc-auth-router.ts b/backend/src/server/routes/v1/identity-oidc-auth-router.ts index 6fb66d2af..9b49a65f0 100644 --- a/backend/src/server/routes/v1/identity-oidc-auth-router.ts +++ b/backend/src/server/routes/v1/identity-oidc-auth-router.ts @@ -4,6 +4,7 @@ import { IdentityOidcAuthsSchema } from "@app/db/schemas"; import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, OIDC_AUTH } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -48,7 +49,7 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider) body: z.object({ identityId: z.string().trim().describe(OIDC_AUTH.LOGIN.identityId), jwt: z.string().trim(), - subOrganizationName: z.string().trim().optional().describe(OIDC_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(OIDC_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ @@ -61,11 +62,7 @@ export const registerIdentityOidcAuthRouter = async (server: FastifyZodProvider) }, handler: async (req) => { const { identityOidcAuth, accessToken, identityAccessToken, identity, oidcTokenData } = - await server.services.identityOidcAuth.login({ - identityId: req.body.identityId, - jwt: req.body.jwt, - subOrganizationName: req.body.subOrganizationName - }); + await server.services.identityOidcAuth.login(req.body); await server.services.auditLog.createAuditLog({ ...req.auditLogInfo, diff --git a/backend/src/server/routes/v1/identity-tls-cert-auth-router.ts b/backend/src/server/routes/v1/identity-tls-cert-auth-router.ts index 9cf97f44c..2a6faf896 100644 --- a/backend/src/server/routes/v1/identity-tls-cert-auth-router.ts +++ b/backend/src/server/routes/v1/identity-tls-cert-auth-router.ts @@ -7,6 +7,7 @@ import { getConfig } from "@app/lib/config/env"; import { crypto } from "@app/lib/crypto/cryptography"; import { BadRequestError } from "@app/lib/errors"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -47,7 +48,7 @@ export const registerIdentityTlsCertAuthRouter = async (server: FastifyZodProvid description: "Login with TLS Certificate Auth for machine identity", body: z.object({ identityId: z.string().trim().describe(TLS_CERT_AUTH.LOGIN.identityId), - subOrganizationName: z.string().trim().optional().describe(TLS_CERT_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(TLS_CERT_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ @@ -67,9 +68,8 @@ export const registerIdentityTlsCertAuthRouter = async (server: FastifyZodProvid const { identityTlsCertAuth, accessToken, identityAccessToken, identity } = await server.services.identityTlsCertAuth.login({ - identityId: req.body.identityId, - clientCertificate: clientCertificate as string, - subOrganizationName: req.body.subOrganizationName + ...req.body, + clientCertificate: clientCertificate as string }); await server.services.auditLog.createAuditLog({ diff --git a/backend/src/server/routes/v1/identity-token-auth-router.ts b/backend/src/server/routes/v1/identity-token-auth-router.ts index e14d440fb..e6ad10acc 100644 --- a/backend/src/server/routes/v1/identity-token-auth-router.ts +++ b/backend/src/server/routes/v1/identity-token-auth-router.ts @@ -4,6 +4,7 @@ import { IdentityAccessTokensSchema, IdentityTokenAuthsSchema } from "@app/db/sc import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, TOKEN_AUTH } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -308,7 +309,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider }), body: z.object({ name: z.string().optional().describe(TOKEN_AUTH.CREATE_TOKEN.name), - subOrganizationName: z.string().trim().optional().describe(TOKEN_AUTH.CREATE_TOKEN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(TOKEN_AUTH.CREATE_TOKEN.subOrganizationName) }), response: { 200: z.object({ @@ -329,8 +330,7 @@ export const registerIdentityTokenAuthRouter = async (server: FastifyZodProvider actorOrgId: req.permission.orgId, identityId: req.params.identityId, isActorSuperAdmin: isSuperAdmin(req.auth), - ...req.body, - subOrganizationName: req.body.subOrganizationName + ...req.body }); await server.services.auditLog.createAuditLog({ diff --git a/backend/src/server/routes/v1/identity-universal-auth-router.ts b/backend/src/server/routes/v1/identity-universal-auth-router.ts index 2e779a6c0..64a6cfebe 100644 --- a/backend/src/server/routes/v1/identity-universal-auth-router.ts +++ b/backend/src/server/routes/v1/identity-universal-auth-router.ts @@ -4,6 +4,7 @@ import { IdentityUaClientSecretsSchema, IdentityUniversalAuthsSchema } from "@ap import { EventType } from "@app/ee/services/audit-log/audit-log-types"; import { ApiDocsTags, UNIVERSAL_AUTH } from "@app/lib/api-docs"; import { readLimit, writeLimit } from "@app/server/config/rateLimiter"; +import { slugSchema } from "@app/server/lib/schemas"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { AuthMode } from "@app/services/auth/auth-type"; import { TIdentityTrustedIp } from "@app/services/identity/identity-types"; @@ -36,7 +37,7 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => { body: z.object({ clientId: z.string().trim().describe(UNIVERSAL_AUTH.LOGIN.clientId), clientSecret: z.string().trim().describe(UNIVERSAL_AUTH.LOGIN.clientSecret), - subOrganizationName: z.string().trim().optional().describe(UNIVERSAL_AUTH.LOGIN.subOrganizationName) + subOrganizationName: slugSchema().optional().describe(UNIVERSAL_AUTH.LOGIN.subOrganizationName) }), response: { 200: z.object({ @@ -57,10 +58,8 @@ export const registerIdentityUaRouter = async (server: FastifyZodProvider) => { accessTokenTTL, accessTokenMaxTTL } = await server.services.identityUa.login({ - clientId: req.body.clientId, - clientSecret: req.body.clientSecret, - ip: req.realIp, - subOrganizationName: req.body.subOrganizationName + ...req.body, + ip: req.realIp }); await server.services.auditLog.createAuditLog({ diff --git a/backend/src/services/auth/auth-login-service.ts b/backend/src/services/auth/auth-login-service.ts index 78bf44253..b2d6281cc 100644 --- a/backend/src/services/auth/auth-login-service.ts +++ b/backend/src/services/auth/auth-login-service.ts @@ -543,7 +543,6 @@ export const authLoginServiceFactory = ({ const isSubOrganization = Boolean(selectedOrg.rootOrgId && selectedOrg.id !== selectedOrg.rootOrgId); - let rootOrg = selectedOrg; let membershipRole; if (isSubOrganization) { @@ -553,13 +552,6 @@ export const authLoginServiceFactory = ({ }); } - rootOrg = await orgDAL.findById(selectedOrg.rootOrgId); - if (!rootOrg) { - throw new BadRequestError({ - message: "Invalid root organization" - }); - } - // Check user membership in the sub-organization const orgMembership = await membershipUserDAL.findOne({ actorUserId: user.id, @@ -577,7 +569,7 @@ export const authLoginServiceFactory = ({ // Check user membership in the root organization const rootOrgMembership = await membershipUserDAL.findOne({ actorUserId: user.id, - scopeOrgId: rootOrg.id, + scopeOrgId: selectedOrg.rootOrgId, scope: AccessScope.Organization, status: OrgMembershipStatus.Accepted }); @@ -665,7 +657,7 @@ export const authLoginServiceFactory = ({ user, userAgent, ip: ipAddress, - organizationId: isSubOrganization ? rootOrg.id : organizationId, + organizationId: isSubOrganization ? selectedOrg.rootOrgId || "" : organizationId, subOrganizationId: isSubOrganization ? organizationId : undefined, isMfaVerified: decodedToken.isMfaVerified, mfaMethod: decodedToken.mfaMethod @@ -755,7 +747,7 @@ export const authLoginServiceFactory = ({ metadata: { organizationId, organizationName: selectedOrg.name, - rootOrganizationId: rootOrg.id + rootOrganizationId: selectedOrg.rootOrgId || "" } } }); diff --git a/backend/src/services/identity-access-token/identity-access-token-service.ts b/backend/src/services/identity-access-token/identity-access-token-service.ts index cf39b38c9..ab4d7ef5d 100644 --- a/backend/src/services/identity-access-token/identity-access-token-service.ts +++ b/backend/src/services/identity-access-token/identity-access-token-service.ts @@ -210,11 +210,9 @@ export const identityAccessTokenServiceFactory = ({ const identityOrgDetails = await orgDAL.findOne({ id: scopeOrgId }); - const isSubOrg = !!(identityOrgDetails.rootOrgId || identityOrgDetails.parentOrgId); + const isSubOrg = Boolean(identityOrgDetails.rootOrgId); - const rootOrgId = isSubOrg - ? identityOrgDetails.rootOrgId || identityOrgDetails.parentOrgId || identityOrgDetails.id - : identityOrgDetails.id; + const rootOrgId = isSubOrg ? identityOrgDetails.rootOrgId || identityOrgDetails.id : identityOrgDetails.id; // Verify identity membership in the organization const identityOrgMembership = await membershipIdentityDAL.findOne({ diff --git a/backend/src/services/identity-alicloud-auth/identity-alicloud-auth-service.ts b/backend/src/services/identity-alicloud-auth/identity-alicloud-auth-service.ts index 866f68aa1..4790067ff 100644 --- a/backend/src/services/identity-alicloud-auth/identity-alicloud-auth-service.ts +++ b/backend/src/services/identity-alicloud-auth/identity-alicloud-auth-service.ts @@ -80,7 +80,7 @@ export const identityAliCloudAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-aws-auth/identity-aws-auth-service.ts b/backend/src/services/identity-aws-auth/identity-aws-auth-service.ts index f17d61616..a06ec4838 100644 --- a/backend/src/services/identity-aws-auth/identity-aws-auth-service.ts +++ b/backend/src/services/identity-aws-auth/identity-aws-auth-service.ts @@ -119,7 +119,7 @@ export const identityAwsAuthServiceFactory = ({ const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-azure-auth/identity-azure-auth-service.ts b/backend/src/services/identity-azure-auth/identity-azure-auth-service.ts index 345cb20d1..92ad82fd7 100644 --- a/backend/src/services/identity-azure-auth/identity-azure-auth-service.ts +++ b/backend/src/services/identity-azure-auth/identity-azure-auth-service.ts @@ -75,7 +75,7 @@ export const identityAzureAuthServiceFactory = ({ const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-gcp-auth/identity-gcp-auth-service.ts b/backend/src/services/identity-gcp-auth/identity-gcp-auth-service.ts index eac756730..797103de1 100644 --- a/backend/src/services/identity-gcp-auth/identity-gcp-auth-service.ts +++ b/backend/src/services/identity-gcp-auth/identity-gcp-auth-service.ts @@ -72,7 +72,7 @@ export const identityGcpAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-jwt-auth/identity-jwt-auth-service.ts b/backend/src/services/identity-jwt-auth/identity-jwt-auth-service.ts index 8e413f331..c6b309c5c 100644 --- a/backend/src/services/identity-jwt-auth/identity-jwt-auth-service.ts +++ b/backend/src/services/identity-jwt-auth/identity-jwt-auth-service.ts @@ -86,7 +86,7 @@ export const identityJwtAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-kubernetes-auth/identity-kubernetes-auth-service.ts b/backend/src/services/identity-kubernetes-auth/identity-kubernetes-auth-service.ts index 2ed1d5140..1f4ec1e11 100644 --- a/backend/src/services/identity-kubernetes-auth/identity-kubernetes-auth-service.ts +++ b/backend/src/services/identity-kubernetes-auth/identity-kubernetes-auth-service.ts @@ -198,7 +198,7 @@ export const identityKubernetesAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-ldap-auth/identity-ldap-auth-service.ts b/backend/src/services/identity-ldap-auth/identity-ldap-auth-service.ts index befc308e5..f84f95839 100644 --- a/backend/src/services/identity-ldap-auth/identity-ldap-auth-service.ts +++ b/backend/src/services/identity-ldap-auth/identity-ldap-auth-service.ts @@ -167,7 +167,7 @@ export const identityLdapAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-oci-auth/identity-oci-auth-service.ts b/backend/src/services/identity-oci-auth/identity-oci-auth-service.ts index 131f64263..3daa9c754 100644 --- a/backend/src/services/identity-oci-auth/identity-oci-auth-service.ts +++ b/backend/src/services/identity-oci-auth/identity-oci-auth-service.ts @@ -76,7 +76,7 @@ export const identityOciAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-oidc-auth/identity-oidc-auth-service.ts b/backend/src/services/identity-oidc-auth/identity-oidc-auth-service.ts index e41f9b311..d47bca36d 100644 --- a/backend/src/services/identity-oidc-auth/identity-oidc-auth-service.ts +++ b/backend/src/services/identity-oidc-auth/identity-oidc-auth-service.ts @@ -87,7 +87,7 @@ export const identityOidcAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-tls-cert-auth/identity-tls-cert-auth-service.ts b/backend/src/services/identity-tls-cert-auth/identity-tls-cert-auth-service.ts index a8604917f..88d40fd8e 100644 --- a/backend/src/services/identity-tls-cert-auth/identity-tls-cert-auth-service.ts +++ b/backend/src/services/identity-tls-cert-auth/identity-tls-cert-auth-service.ts @@ -85,7 +85,7 @@ export const identityTlsCertAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-token-auth/identity-token-auth-service.ts b/backend/src/services/identity-token-auth/identity-token-auth-service.ts index 586c38f20..ff7dd9dfb 100644 --- a/backend/src/services/identity-token-auth/identity-token-auth-service.ts +++ b/backend/src/services/identity-token-auth/identity-token-auth-service.ts @@ -505,7 +505,7 @@ export const identityTokenAuthServiceFactory = ({ if (!identity) throw new UnauthorizedError({ message: "Identity not found" }); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || org.id : org.id; diff --git a/backend/src/services/identity-ua/identity-ua-service.ts b/backend/src/services/identity-ua/identity-ua-service.ts index 29b515d06..4ff1f6203 100644 --- a/backend/src/services/identity-ua/identity-ua-service.ts +++ b/backend/src/services/identity-ua/identity-ua-service.ts @@ -91,7 +91,7 @@ export const identityUaServiceFactory = ({ const identity = await identityDAL.findById(identityUa.identityId); const org = await orgDAL.findById(identity.orgId); - const isSubOrg = !!(org.rootOrgId || org.parentOrgId); + const isSubOrg = Boolean(org.rootOrgId); const rootOrgId = isSubOrg ? org.rootOrgId || "" : org.id;