mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 19:26:19 +00:00
Improve user alias check logic and header usage on resend code
This commit is contained in:
@@ -423,6 +423,7 @@ export const samlConfigServiceFactory = ({
|
|||||||
organizationSlug: organization.slug,
|
organizationSlug: organization.slug,
|
||||||
authMethod: authProvider,
|
authMethod: authProvider,
|
||||||
hasExchangedPrivateKey: true,
|
hasExchangedPrivateKey: true,
|
||||||
|
aliasId: userAlias.id,
|
||||||
authType: UserAliasType.SAML,
|
authType: UserAliasType.SAML,
|
||||||
isUserCompleted,
|
isUserCompleted,
|
||||||
...(relayState
|
...(relayState
|
||||||
|
|||||||
@@ -20,15 +20,12 @@ export const registerUserRouter = async (server: FastifyZodProvider) => {
|
|||||||
headers: z.object({
|
headers: z.object({
|
||||||
referer: z.string().trim()
|
referer: z.string().trim()
|
||||||
}),
|
}),
|
||||||
body: z.object({
|
|
||||||
username: z.string().trim()
|
|
||||||
}),
|
|
||||||
response: {
|
response: {
|
||||||
200: z.object({})
|
200: z.object({})
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
await server.services.user.sendEmailVerificationCode(req.body.username, req.headers.referer);
|
await server.services.user.sendEmailVerificationCode(req.headers.referer);
|
||||||
return {};
|
return {};
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -54,18 +54,22 @@ export const userServiceFactory = ({
|
|||||||
permissionService,
|
permissionService,
|
||||||
userAliasDAL
|
userAliasDAL
|
||||||
}: TUserServiceFactoryDep) => {
|
}: TUserServiceFactoryDep) => {
|
||||||
const sendEmailVerificationCode = async (username: string, referer: string) => {
|
const sendEmailVerificationCode = async (referer: string) => {
|
||||||
|
const url = new URL(referer);
|
||||||
|
const refererToken = url.searchParams.get("token");
|
||||||
|
if (!refererToken)
|
||||||
|
throw new BadRequestError({ name: "Failed to send email verification code due to no token on referer" });
|
||||||
|
const { authType, aliasId, username } = crypto.jwt().decode(refererToken) as {
|
||||||
|
authType: string;
|
||||||
|
aliasId: string;
|
||||||
|
username: string;
|
||||||
|
};
|
||||||
// akhilmhdh: case sensitive email resolution
|
// akhilmhdh: case sensitive email resolution
|
||||||
const users = await userDAL.findUserByUsername(username);
|
const users = await userDAL.findUserByUsername(username);
|
||||||
const user = users?.length > 1 ? users.find((el) => el.username === username) : users?.[0];
|
const user = users?.length > 1 ? users.find((el) => el.username === username) : users?.[0];
|
||||||
if (!user) throw new NotFoundError({ name: `User with username '${username}' not found` });
|
if (!user) throw new NotFoundError({ name: `User with username '${username}' not found` });
|
||||||
let { isEmailVerified } = user;
|
let { isEmailVerified } = user;
|
||||||
const url = new URL(referer);
|
const userAlias = await userAliasDAL.findOne({ userId: user.id, aliasType: authType, id: aliasId });
|
||||||
const refererToken = url.searchParams.get("token");
|
|
||||||
if (!refererToken)
|
|
||||||
throw new BadRequestError({ name: "Failed to send email verification code due to no token on referer" });
|
|
||||||
const { authType } = crypto.jwt().decode(refererToken) as { authType: string };
|
|
||||||
const userAlias = await userAliasDAL.findOne({ userId: user.id, aliasType: authType });
|
|
||||||
if (userAlias) {
|
if (userAlias) {
|
||||||
isEmailVerified = userAlias.isEmailVerified;
|
isEmailVerified = userAlias.isEmailVerified;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user