From 3e230555fbee64d64c93ce4774abc04e98e5427e Mon Sep 17 00:00:00 2001 From: Sheen Capadngan Date: Thu, 20 Jun 2024 13:59:50 +0800 Subject: [PATCH] misc: added oifc checks to signup --- backend/src/ee/services/oidc/oidc-config-service.ts | 7 ++++++- backend/src/services/auth/auth-login-service.ts | 3 ++- backend/src/services/auth/auth-signup-service.ts | 5 ++++- 3 files changed, 12 insertions(+), 3 deletions(-) diff --git a/backend/src/ee/services/oidc/oidc-config-service.ts b/backend/src/ee/services/oidc/oidc-config-service.ts index 81f71ed7e..b983492bc 100644 --- a/backend/src/ee/services/oidc/oidc-config-service.ts +++ b/backend/src/ee/services/oidc/oidc-config-service.ts @@ -41,7 +41,10 @@ import { } from "./oidc-config-types"; type TOidcConfigServiceFactoryDep = { - userDAL: Pick; + userDAL: Pick< + TUserDALFactory, + "create" | "findOne" | "transaction" | "updateById" | "findById" | "findUserEncKeyByUserId" + >; userAliasDAL: Pick; orgDAL: Pick< TOrgDALFactory, @@ -276,6 +279,7 @@ export const oidcConfigServiceFactory = ({ await licenseService.updateSubscriptionOrgMemberCount(organization.id); + const userEnc = await userDAL.findUserEncKeyByUserId(user.id); const isUserCompleted = Boolean(user.isAccepted); const providerAuthToken = jwt.sign( { @@ -288,6 +292,7 @@ export const oidcConfigServiceFactory = ({ organizationName: organization.name, organizationId: organization.id, organizationSlug: organization.slug, + hasExchangedPrivateKey: Boolean(userEnc?.serverEncryptedPrivateKey), authMethod: AuthMethod.OIDC, authType: UserAliasType.OIDC, isUserCompleted, diff --git a/backend/src/services/auth/auth-login-service.ts b/backend/src/services/auth/auth-login-service.ts index 3a85b6996..995ba9b22 100644 --- a/backend/src/services/auth/auth-login-service.ts +++ b/backend/src/services/auth/auth-login-service.ts @@ -574,7 +574,8 @@ export const authLoginServiceFactory = ({ const { authMethod, userName } = decodedProviderToken; if (!userName) throw new BadRequestError({ message: "Missing user name" }); const organizationId = - (isAuthMethodSaml(authMethod) || authMethod === AuthMethod.LDAP) && decodedProviderToken.orgId + (isAuthMethodSaml(authMethod) || [AuthMethod.LDAP, AuthMethod.OIDC].includes(authMethod)) && + decodedProviderToken.orgId ? decodedProviderToken.orgId : undefined; diff --git a/backend/src/services/auth/auth-signup-service.ts b/backend/src/services/auth/auth-signup-service.ts index 8cf2c9d34..8cb22542b 100644 --- a/backend/src/services/auth/auth-signup-service.ts +++ b/backend/src/services/auth/auth-signup-service.ts @@ -192,7 +192,10 @@ export const authSignupServiceFactory = ({ tx ); // If it's SAML Auth and the organization ID is present, we should check if the user has a pending invite for this org, and accept it - if ((isAuthMethodSaml(authMethod) || authMethod === AuthMethod.LDAP) && organizationId) { + if ( + (isAuthMethodSaml(authMethod) || [AuthMethod.LDAP, AuthMethod.OIDC].includes(authMethod as AuthMethod)) && + organizationId + ) { const [pendingOrgMembership] = await orgDAL.findMembership({ [`${TableName.OrgMembership}.userId` as "userId"]: user.id, status: OrgMembershipStatus.Invited,