mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 00:26:40 +00:00
misc: added oifc checks to signup
This commit is contained in:
@@ -41,7 +41,10 @@ import {
|
|||||||
} from "./oidc-config-types";
|
} from "./oidc-config-types";
|
||||||
|
|
||||||
type TOidcConfigServiceFactoryDep = {
|
type TOidcConfigServiceFactoryDep = {
|
||||||
userDAL: Pick<TUserDALFactory, "create" | "findOne" | "transaction" | "updateById" | "findById">;
|
userDAL: Pick<
|
||||||
|
TUserDALFactory,
|
||||||
|
"create" | "findOne" | "transaction" | "updateById" | "findById" | "findUserEncKeyByUserId"
|
||||||
|
>;
|
||||||
userAliasDAL: Pick<TUserAliasDALFactory, "create" | "findOne">;
|
userAliasDAL: Pick<TUserAliasDALFactory, "create" | "findOne">;
|
||||||
orgDAL: Pick<
|
orgDAL: Pick<
|
||||||
TOrgDALFactory,
|
TOrgDALFactory,
|
||||||
@@ -276,6 +279,7 @@ export const oidcConfigServiceFactory = ({
|
|||||||
|
|
||||||
await licenseService.updateSubscriptionOrgMemberCount(organization.id);
|
await licenseService.updateSubscriptionOrgMemberCount(organization.id);
|
||||||
|
|
||||||
|
const userEnc = await userDAL.findUserEncKeyByUserId(user.id);
|
||||||
const isUserCompleted = Boolean(user.isAccepted);
|
const isUserCompleted = Boolean(user.isAccepted);
|
||||||
const providerAuthToken = jwt.sign(
|
const providerAuthToken = jwt.sign(
|
||||||
{
|
{
|
||||||
@@ -288,6 +292,7 @@ export const oidcConfigServiceFactory = ({
|
|||||||
organizationName: organization.name,
|
organizationName: organization.name,
|
||||||
organizationId: organization.id,
|
organizationId: organization.id,
|
||||||
organizationSlug: organization.slug,
|
organizationSlug: organization.slug,
|
||||||
|
hasExchangedPrivateKey: Boolean(userEnc?.serverEncryptedPrivateKey),
|
||||||
authMethod: AuthMethod.OIDC,
|
authMethod: AuthMethod.OIDC,
|
||||||
authType: UserAliasType.OIDC,
|
authType: UserAliasType.OIDC,
|
||||||
isUserCompleted,
|
isUserCompleted,
|
||||||
|
|||||||
@@ -574,7 +574,8 @@ export const authLoginServiceFactory = ({
|
|||||||
const { authMethod, userName } = decodedProviderToken;
|
const { authMethod, userName } = decodedProviderToken;
|
||||||
if (!userName) throw new BadRequestError({ message: "Missing user name" });
|
if (!userName) throw new BadRequestError({ message: "Missing user name" });
|
||||||
const organizationId =
|
const organizationId =
|
||||||
(isAuthMethodSaml(authMethod) || authMethod === AuthMethod.LDAP) && decodedProviderToken.orgId
|
(isAuthMethodSaml(authMethod) || [AuthMethod.LDAP, AuthMethod.OIDC].includes(authMethod)) &&
|
||||||
|
decodedProviderToken.orgId
|
||||||
? decodedProviderToken.orgId
|
? decodedProviderToken.orgId
|
||||||
: undefined;
|
: undefined;
|
||||||
|
|
||||||
|
|||||||
@@ -192,7 +192,10 @@ export const authSignupServiceFactory = ({
|
|||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
// If it's SAML Auth and the organization ID is present, we should check if the user has a pending invite for this org, and accept it
|
// If it's SAML Auth and the organization ID is present, we should check if the user has a pending invite for this org, and accept it
|
||||||
if ((isAuthMethodSaml(authMethod) || authMethod === AuthMethod.LDAP) && organizationId) {
|
if (
|
||||||
|
(isAuthMethodSaml(authMethod) || [AuthMethod.LDAP, AuthMethod.OIDC].includes(authMethod as AuthMethod)) &&
|
||||||
|
organizationId
|
||||||
|
) {
|
||||||
const [pendingOrgMembership] = await orgDAL.findMembership({
|
const [pendingOrgMembership] = await orgDAL.findMembership({
|
||||||
[`${TableName.OrgMembership}.userId` as "userId"]: user.id,
|
[`${TableName.OrgMembership}.userId` as "userId"]: user.id,
|
||||||
status: OrgMembershipStatus.Invited,
|
status: OrgMembershipStatus.Invited,
|
||||||
|
|||||||
Reference in New Issue
Block a user