Upgrade passport/saml to 5.0

This addresses the breaking changes in 5.0 listed here https://github.com/node-saml/node-saml/blob/v5.0.0/CHANGELOG.md#-major-changes

Todo: test with existing saml workflow
This commit is contained in:
Maidul Islam
2025-03-14 21:16:42 -04:00
parent f461eaa432
commit 6426b85c1e
3 changed files with 37 additions and 25 deletions
+29 -17
View File
@@ -22,7 +22,7 @@ import { SanitizedSamlConfigSchema } from "@app/server/routes/sanitizedSchema/di
import { AuthMode } from "@app/services/auth/auth-type"; import { AuthMode } from "@app/services/auth/auth-type";
type TSAMLConfig = { type TSAMLConfig = {
callbackUrl: string; callbackUrl: string;
entryPoint: string; entryPoint: string;
issuer: string; issuer: string;
cert: string; cert: string;
@@ -302,15 +302,21 @@ export const registerSamlRouter = async (server: FastifyZodProvider) => {
} }
}, },
handler: async (req) => { handler: async (req) => {
const saml = await server.services.saml.createSamlCfg({ const { isActive, authProvider, issuer, entryPoint, cert } = req.body;
actor: req.permission.type, const { permission } = req;
actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, return server.services.saml.createSamlCfg({
actorOrgId: req.permission.orgId, isActive,
orgId: req.body.organizationId, authProvider,
...req.body issuer,
entryPoint,
idpCert: cert,
actor: permission.type,
actorId: permission.id,
actorAuthMethod: permission.authMethod,
actorOrgId: permission.orgId,
orgId: req.body.organizationId
}); });
return saml;
} }
}); });
@@ -337,15 +343,21 @@ export const registerSamlRouter = async (server: FastifyZodProvider) => {
} }
}, },
handler: async (req) => { handler: async (req) => {
const saml = await server.services.saml.updateSamlCfg({ const { isActive, authProvider, issuer, entryPoint, cert } = req.body;
actor: req.permission.type, const { permission } = req;
actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, return server.services.saml.updateSamlCfg({
actorOrgId: req.permission.orgId, isActive,
orgId: req.body.organizationId, authProvider,
...req.body issuer,
entryPoint,
idpCert: cert,
actor: permission.type,
actorId: permission.id,
actorAuthMethod: permission.authMethod,
actorOrgId: permission.orgId,
orgId: req.body.organizationId
}); });
return saml;
} }
}); });
}; };
@@ -63,7 +63,7 @@ export const samlConfigServiceFactory = ({
kmsService kmsService
}: TSamlConfigServiceFactoryDep) => { }: TSamlConfigServiceFactoryDep) => {
const createSamlCfg = async ({ const createSamlCfg = async ({
cert, idpCert,
actor, actor,
actorAuthMethod, actorAuthMethod,
actorOrgId, actorOrgId,
@@ -93,9 +93,9 @@ export const samlConfigServiceFactory = ({
orgId, orgId,
authProvider, authProvider,
isActive, isActive,
encryptedSamlIssuer: encryptor({ plainText: Buffer.from(issuer) }).cipherTextBlob, encryptedSamlCertificate: encryptor({ plainText: Buffer.from(idpCert) }).cipherTextBlob,
encryptedSamlEntryPoint: encryptor({ plainText: Buffer.from(entryPoint) }).cipherTextBlob, encryptedSamlEntryPoint: encryptor({ plainText: Buffer.from(entryPoint) }).cipherTextBlob,
encryptedSamlCertificate: encryptor({ plainText: Buffer.from(cert) }).cipherTextBlob encryptedSamlIssuer: encryptor({ plainText: Buffer.from(issuer) }).cipherTextBlob
}); });
return samlConfig; return samlConfig;
@@ -106,7 +106,7 @@ export const samlConfigServiceFactory = ({
actor, actor,
actorOrgId, actorOrgId,
actorAuthMethod, actorAuthMethod,
cert, idpCert,
actorId, actorId,
issuer, issuer,
isActive, isActive,
@@ -136,8 +136,8 @@ export const samlConfigServiceFactory = ({
updateQuery.encryptedSamlIssuer = encryptor({ plainText: Buffer.from(issuer) }).cipherTextBlob; updateQuery.encryptedSamlIssuer = encryptor({ plainText: Buffer.from(issuer) }).cipherTextBlob;
} }
if (cert !== undefined) { if (idpCert !== undefined) {
updateQuery.encryptedSamlCertificate = encryptor({ plainText: Buffer.from(cert) }).cipherTextBlob; updateQuery.encryptedSamlCertificate = encryptor({ plainText: Buffer.from(idpCert) }).cipherTextBlob;
} }
const [ssoConfig] = await samlConfigDAL.update({ orgId }, updateQuery); const [ssoConfig] = await samlConfigDAL.update({ orgId }, updateQuery);
@@ -15,7 +15,7 @@ export type TCreateSamlCfgDTO = {
isActive: boolean; isActive: boolean;
entryPoint: string; entryPoint: string;
issuer: string; issuer: string;
cert: string; idpCert: string;
} & TOrgPermission; } & TOrgPermission;
export type TUpdateSamlCfgDTO = Partial<{ export type TUpdateSamlCfgDTO = Partial<{
@@ -23,7 +23,7 @@ export type TUpdateSamlCfgDTO = Partial<{
isActive: boolean; isActive: boolean;
entryPoint: string; entryPoint: string;
issuer: string; issuer: string;
cert: string; idpCert: string;
}> & }> &
TOrgPermission; TOrgPermission;