Merge pull request #4446 from Infisical/fix/selectOrgSamlEnforced

Check token source before throwing an error for auth enforced scenarios
This commit is contained in:
carlosmonastyrski
2025-08-31 13:49:09 -03:00
committed by GitHub
@@ -453,10 +453,14 @@ export const authLoginServiceFactory = ({
const selectedOrg = await orgDAL.findById(organizationId); const selectedOrg = await orgDAL.findById(organizationId);
// Check if authEnforced is true, if that's the case, throw an error // Check if authEnforced is true and the current auth method is not an enforced method
if (selectedOrg.authEnforced) { if (
selectedOrg.authEnforced &&
!isAuthMethodSaml(decodedToken.authMethod) &&
decodedToken.authMethod !== AuthMethod.OIDC
) {
throw new BadRequestError({ throw new BadRequestError({
message: "Authentication is required by your organization before you can log in." message: "Login with the auth method required by your organization."
}); });
} }