mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 13:27:46 +00:00
Feat: Scoped JWT to organization
This commit is contained in:
@@ -1,6 +1,7 @@
|
|||||||
import jwt from "jsonwebtoken";
|
import jwt from "jsonwebtoken";
|
||||||
|
|
||||||
import { TUsers, UserDeviceSchema } from "@app/db/schemas";
|
import { TUsers, UserDeviceSchema } from "@app/db/schemas";
|
||||||
|
import { isAuthMethodSaml } from "@app/ee/services/permission/permission-fns";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { generateSrpServerKey, srpCheckClientProof } from "@app/lib/crypto";
|
import { generateSrpServerKey, srpCheckClientProof } from "@app/lib/crypto";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
@@ -89,7 +90,7 @@ export const authLoginServiceFactory = ({ userDAL, tokenService, smtpService }:
|
|||||||
user: TUsers;
|
user: TUsers;
|
||||||
ip: string;
|
ip: string;
|
||||||
userAgent: string;
|
userAgent: string;
|
||||||
organizationId?: string;
|
organizationId: string | undefined;
|
||||||
authMethod: AuthMethod;
|
authMethod: AuthMethod;
|
||||||
}) => {
|
}) => {
|
||||||
const cfg = getConfig();
|
const cfg = getConfig();
|
||||||
@@ -178,9 +179,15 @@ export const authLoginServiceFactory = ({ userDAL, tokenService, smtpService }:
|
|||||||
// let authMethod = (providerAuthToken as AuthMethod) || AuthMethod.EMAIL;
|
// let authMethod = (providerAuthToken as AuthMethod) || AuthMethod.EMAIL;
|
||||||
|
|
||||||
let authMethod = AuthMethod.EMAIL;
|
let authMethod = AuthMethod.EMAIL;
|
||||||
|
let organizationId: string | undefined;
|
||||||
|
|
||||||
if (providerAuthToken) {
|
if (providerAuthToken) {
|
||||||
authMethod = validateProviderAuthToken(providerAuthToken, email).authMethod;
|
const decodedProviderToken = validateProviderAuthToken(providerAuthToken, email);
|
||||||
|
|
||||||
|
authMethod = decodedProviderToken.authMethod;
|
||||||
|
if (isAuthMethodSaml(authMethod) && decodedProviderToken.orgId) {
|
||||||
|
organizationId = decodedProviderToken.orgId;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!userEnc.serverPrivateKey || !userEnc.clientPublicKey) throw new Error("Failed to authenticate. Try again?");
|
if (!userEnc.serverPrivateKey || !userEnc.clientPublicKey) throw new Error("Failed to authenticate. Try again?");
|
||||||
@@ -226,7 +233,8 @@ export const authLoginServiceFactory = ({ userDAL, tokenService, smtpService }:
|
|||||||
},
|
},
|
||||||
ip,
|
ip,
|
||||||
userAgent,
|
userAgent,
|
||||||
authMethod
|
authMethod,
|
||||||
|
organizationId
|
||||||
});
|
});
|
||||||
|
|
||||||
return { token, isMfaEnabled: false, user: userEnc } as const;
|
return { token, isMfaEnabled: false, user: userEnc } as const;
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ export enum AuthMethod {
|
|||||||
OKTA_SAML = "okta-saml",
|
OKTA_SAML = "okta-saml",
|
||||||
AZURE_SAML = "azure-saml",
|
AZURE_SAML = "azure-saml",
|
||||||
JUMPCLOUD_SAML = "jumpcloud-saml",
|
JUMPCLOUD_SAML = "jumpcloud-saml",
|
||||||
|
GOOGLE_SAML = "google-saml",
|
||||||
LDAP = "ldap"
|
LDAP = "ldap"
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -38,6 +39,8 @@ export enum ActorType { // would extend to AWS, Azure, ...
|
|||||||
SCIM_CLIENT = "scimClient"
|
SCIM_CLIENT = "scimClient"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export type ActorAuthMethod = AuthMethod | null;
|
||||||
|
|
||||||
export type AuthModeJwtTokenPayload = {
|
export type AuthModeJwtTokenPayload = {
|
||||||
authTokenType: AuthTokenType.ACCESS_TOKEN;
|
authTokenType: AuthTokenType.ACCESS_TOKEN;
|
||||||
authMethod: AuthMethod;
|
authMethod: AuthMethod;
|
||||||
|
|||||||
Reference in New Issue
Block a user