mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 15:27:27 +00:00
Merge pull request #4460 from Infisical/fix/selectOrganizationAdminBypass
Fix blocking issue for auth admin bypass on selectOrganization
This commit is contained in:
@@ -453,23 +453,24 @@ export const authLoginServiceFactory = ({
|
|||||||
|
|
||||||
const selectedOrg = await orgDAL.findById(organizationId);
|
const selectedOrg = await orgDAL.findById(organizationId);
|
||||||
|
|
||||||
|
if (!selectedOrgMembership) {
|
||||||
|
throw new ForbiddenRequestError({
|
||||||
|
message: `User does not have access to the organization named ${selectedOrg?.name}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// Check if authEnforced is true and the current auth method is not an enforced method
|
// Check if authEnforced is true and the current auth method is not an enforced method
|
||||||
if (
|
if (
|
||||||
selectedOrg.authEnforced &&
|
selectedOrg.authEnforced &&
|
||||||
!isAuthMethodSaml(decodedToken.authMethod) &&
|
!isAuthMethodSaml(decodedToken.authMethod) &&
|
||||||
decodedToken.authMethod !== AuthMethod.OIDC
|
decodedToken.authMethod !== AuthMethod.OIDC &&
|
||||||
|
!(selectedOrg.bypassOrgAuthEnabled && selectedOrgMembership.userRole === OrgMembershipRole.Admin)
|
||||||
) {
|
) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Login with the auth method required by your organization."
|
message: "Login with the auth method required by your organization."
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!selectedOrgMembership) {
|
|
||||||
throw new ForbiddenRequestError({
|
|
||||||
message: `User does not have access to the organization named ${selectedOrg?.name}`
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
if (selectedOrg.googleSsoAuthEnforced && decodedToken.authMethod !== AuthMethod.GOOGLE) {
|
if (selectedOrg.googleSsoAuthEnforced && decodedToken.authMethod !== AuthMethod.GOOGLE) {
|
||||||
const canBypass = selectedOrg.bypassOrgAuthEnabled && selectedOrgMembership.userRole === OrgMembershipRole.Admin;
|
const canBypass = selectedOrg.bypassOrgAuthEnabled && selectedOrgMembership.userRole === OrgMembershipRole.Admin;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user