mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 13:27:46 +00:00
Improve handleSelectOrganization logic for SSO enforcement
This commit is contained in:
@@ -88,29 +88,24 @@ export const SelectOrganizationSection = () => {
|
|||||||
// org has an org-level auth method enabled (e.g. SAML)
|
// org has an org-level auth method enabled (e.g. SAML)
|
||||||
// -> logout + redirect to SAML SSO
|
// -> logout + redirect to SAML SSO
|
||||||
let url = "";
|
let url = "";
|
||||||
if (organization.orgAuthMethod === AuthMethod.OIDC) {
|
if (organization.googleSsoAuthEnforced) {
|
||||||
|
if (authToken.authMethod !== AuthMethod.GOOGLE) {
|
||||||
|
url = `/api/v1/sso/redirect/google?org_slug=${organization.slug}`;
|
||||||
|
|
||||||
|
if (callbackPort) {
|
||||||
|
url += `&callback_port=${callbackPort}`;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} else if (organization.orgAuthMethod === AuthMethod.OIDC) {
|
||||||
url = `/api/v1/sso/oidc/login?orgSlug=${organization.slug}${
|
url = `/api/v1/sso/oidc/login?orgSlug=${organization.slug}${
|
||||||
callbackPort ? `&callbackPort=${callbackPort}` : ""
|
callbackPort ? `&callbackPort=${callbackPort}` : ""
|
||||||
}`;
|
}`;
|
||||||
} else if (
|
} else if (organization.orgAuthMethod === AuthMethod.SAML) {
|
||||||
organization.orgAuthMethod === AuthMethod.SAML &&
|
|
||||||
// if google sso is enforced, we don't want to redirect to saml
|
|
||||||
!organization.googleSsoAuthEnforced
|
|
||||||
) {
|
|
||||||
url = `/api/v1/sso/redirect/saml2/organizations/${organization.slug}`;
|
url = `/api/v1/sso/redirect/saml2/organizations/${organization.slug}`;
|
||||||
|
|
||||||
if (callbackPort) {
|
if (callbackPort) {
|
||||||
url += `?callback_port=${callbackPort}`;
|
url += `?callback_port=${callbackPort}`;
|
||||||
}
|
}
|
||||||
} else if (
|
|
||||||
organization.googleSsoAuthEnforced &&
|
|
||||||
authToken.authMethod !== AuthMethod.GOOGLE
|
|
||||||
) {
|
|
||||||
url = `/api/v1/sso/redirect/google?org_slug=${organization.slug}`;
|
|
||||||
|
|
||||||
if (callbackPort) {
|
|
||||||
url += `&callback_port=${callbackPort}`;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// we are conditionally checking if the url is set because it may not be set if google SSO is enforced, but the user is already logged in with google SSO
|
// we are conditionally checking if the url is set because it may not be set if google SSO is enforced, but the user is already logged in with google SSO
|
||||||
|
|||||||
Reference in New Issue
Block a user