mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 11:27:07 +00:00
misc: made bypass opt-in
This commit is contained in:
@@ -0,0 +1,19 @@
|
|||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
|
import { TableName } from "../schemas";
|
||||||
|
|
||||||
|
export async function up(knex: Knex): Promise<void> {
|
||||||
|
if (!(await knex.schema.hasColumn(TableName.Organization, "enableBypassOrgAuth"))) {
|
||||||
|
await knex.schema.alterTable(TableName.Organization, (t) => {
|
||||||
|
t.boolean("enableBypassOrgAuth").defaultTo(false).notNullable();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function down(knex: Knex): Promise<void> {
|
||||||
|
if (await knex.schema.hasColumn(TableName.Organization, "enableBypassOrgAuth")) {
|
||||||
|
await knex.schema.alterTable(TableName.Organization, (t) => {
|
||||||
|
t.dropColumn("enableBypassOrgAuth");
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -26,7 +26,8 @@ export const OrganizationsSchema = z.object({
|
|||||||
allowSecretSharingOutsideOrganization: z.boolean().default(true).nullable().optional(),
|
allowSecretSharingOutsideOrganization: z.boolean().default(true).nullable().optional(),
|
||||||
shouldUseNewPrivilegeSystem: z.boolean().default(true),
|
shouldUseNewPrivilegeSystem: z.boolean().default(true),
|
||||||
privilegeUpgradeInitiatedByUsername: z.string().nullable().optional(),
|
privilegeUpgradeInitiatedByUsername: z.string().nullable().optional(),
|
||||||
privilegeUpgradeInitiatedAt: z.date().nullable().optional()
|
privilegeUpgradeInitiatedAt: z.date().nullable().optional(),
|
||||||
|
enableBypassOrgAuth: z.boolean().default(false)
|
||||||
});
|
});
|
||||||
|
|
||||||
export type TOrganizations = z.infer<typeof OrganizationsSchema>;
|
export type TOrganizations = z.infer<typeof OrganizationsSchema>;
|
||||||
|
|||||||
@@ -54,6 +54,7 @@ export const permissionDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("slug").withSchema(TableName.OrgRoles).withSchema(TableName.OrgRoles).as("customRoleSlug"),
|
db.ref("slug").withSchema(TableName.OrgRoles).withSchema(TableName.OrgRoles).as("customRoleSlug"),
|
||||||
db.ref("permissions").withSchema(TableName.OrgRoles),
|
db.ref("permissions").withSchema(TableName.OrgRoles),
|
||||||
db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"),
|
db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"),
|
||||||
|
db.ref("enableBypassOrgAuth").withSchema(TableName.Organization).as("enableBypassOrgAuth"),
|
||||||
db.ref("groupId").withSchema("userGroups"),
|
db.ref("groupId").withSchema("userGroups"),
|
||||||
db.ref("groupOrgId").withSchema("userGroups"),
|
db.ref("groupOrgId").withSchema("userGroups"),
|
||||||
db.ref("groupName").withSchema("userGroups"),
|
db.ref("groupName").withSchema("userGroups"),
|
||||||
@@ -72,6 +73,7 @@ export const permissionDALFactory = (db: TDbClient) => {
|
|||||||
OrgMembershipsSchema.extend({
|
OrgMembershipsSchema.extend({
|
||||||
permissions: z.unknown(),
|
permissions: z.unknown(),
|
||||||
orgAuthEnforced: z.boolean().optional().nullable(),
|
orgAuthEnforced: z.boolean().optional().nullable(),
|
||||||
|
enableBypassOrgAuth: z.boolean(),
|
||||||
customRoleSlug: z.string().optional().nullable(),
|
customRoleSlug: z.string().optional().nullable(),
|
||||||
shouldUseNewPrivilegeSystem: z.boolean()
|
shouldUseNewPrivilegeSystem: z.boolean()
|
||||||
}).parse(el),
|
}).parse(el),
|
||||||
@@ -676,6 +678,7 @@ export const permissionDALFactory = (db: TDbClient) => {
|
|||||||
db.ref("key").withSchema(TableName.IdentityMetadata).as("metadataKey"),
|
db.ref("key").withSchema(TableName.IdentityMetadata).as("metadataKey"),
|
||||||
db.ref("value").withSchema(TableName.IdentityMetadata).as("metadataValue"),
|
db.ref("value").withSchema(TableName.IdentityMetadata).as("metadataValue"),
|
||||||
db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"),
|
db.ref("authEnforced").withSchema(TableName.Organization).as("orgAuthEnforced"),
|
||||||
|
db.ref("enableBypassOrgAuth").withSchema(TableName.Organization).as("enableBypassOrgAuth"),
|
||||||
db.ref("role").withSchema(TableName.OrgMembership).as("orgRole"),
|
db.ref("role").withSchema(TableName.OrgMembership).as("orgRole"),
|
||||||
db.ref("orgId").withSchema(TableName.Project),
|
db.ref("orgId").withSchema(TableName.Project),
|
||||||
db.ref("type").withSchema(TableName.Project).as("projectType"),
|
db.ref("type").withSchema(TableName.Project).as("projectType"),
|
||||||
@@ -698,7 +701,8 @@ export const permissionDALFactory = (db: TDbClient) => {
|
|||||||
groupMembershipUpdatedAt,
|
groupMembershipUpdatedAt,
|
||||||
membershipUpdatedAt,
|
membershipUpdatedAt,
|
||||||
projectType,
|
projectType,
|
||||||
shouldUseNewPrivilegeSystem
|
shouldUseNewPrivilegeSystem,
|
||||||
|
enableBypassOrgAuth
|
||||||
}) => ({
|
}) => ({
|
||||||
orgId,
|
orgId,
|
||||||
orgAuthEnforced,
|
orgAuthEnforced,
|
||||||
@@ -710,7 +714,8 @@ export const permissionDALFactory = (db: TDbClient) => {
|
|||||||
id: membershipId || groupMembershipId,
|
id: membershipId || groupMembershipId,
|
||||||
createdAt: membershipCreatedAt || groupMembershipCreatedAt,
|
createdAt: membershipCreatedAt || groupMembershipCreatedAt,
|
||||||
updatedAt: membershipUpdatedAt || groupMembershipUpdatedAt,
|
updatedAt: membershipUpdatedAt || groupMembershipUpdatedAt,
|
||||||
shouldUseNewPrivilegeSystem
|
shouldUseNewPrivilegeSystem,
|
||||||
|
enableBypassOrgAuth
|
||||||
}),
|
}),
|
||||||
childrenMapper: [
|
childrenMapper: [
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -121,14 +121,18 @@ function isAuthMethodSaml(actorAuthMethod: ActorAuthMethod) {
|
|||||||
function validateOrgSSO(
|
function validateOrgSSO(
|
||||||
actorAuthMethod: ActorAuthMethod,
|
actorAuthMethod: ActorAuthMethod,
|
||||||
isOrgSsoEnforced: TOrganizations["authEnforced"],
|
isOrgSsoEnforced: TOrganizations["authEnforced"],
|
||||||
|
isOrgSsoBypassEnabled: TOrganizations["enableBypassOrgAuth"],
|
||||||
orgRole: OrgMembershipRole
|
orgRole: OrgMembershipRole
|
||||||
) {
|
) {
|
||||||
if (actorAuthMethod === undefined) {
|
if (actorAuthMethod === undefined) {
|
||||||
throw new UnauthorizedError({ name: "No auth method defined" });
|
throw new UnauthorizedError({ name: "No auth method defined" });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (isOrgSsoEnforced && isOrgSsoBypassEnabled && orgRole === OrgMembershipRole.Admin) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
if (
|
if (
|
||||||
orgRole !== OrgMembershipRole.Admin &&
|
|
||||||
isOrgSsoEnforced &&
|
isOrgSsoEnforced &&
|
||||||
actorAuthMethod !== null &&
|
actorAuthMethod !== null &&
|
||||||
!isAuthMethodSaml(actorAuthMethod) &&
|
!isAuthMethodSaml(actorAuthMethod) &&
|
||||||
|
|||||||
@@ -139,7 +139,12 @@ export const permissionServiceFactory = ({
|
|||||||
throw new ForbiddenRequestError({ name: "You are not logged into this organization" });
|
throw new ForbiddenRequestError({ name: "You are not logged into this organization" });
|
||||||
}
|
}
|
||||||
|
|
||||||
validateOrgSSO(authMethod, membership.orgAuthEnforced, membership.role as OrgMembershipRole);
|
validateOrgSSO(
|
||||||
|
authMethod,
|
||||||
|
membership.orgAuthEnforced,
|
||||||
|
membership.enableBypassOrgAuth,
|
||||||
|
membership.role as OrgMembershipRole
|
||||||
|
);
|
||||||
|
|
||||||
const finalPolicyRoles = [{ role: membership.role, permissions: membership.permissions }].concat(
|
const finalPolicyRoles = [{ role: membership.role, permissions: membership.permissions }].concat(
|
||||||
membership?.groups?.map(({ role, customRolePermission }) => ({
|
membership?.groups?.map(({ role, customRolePermission }) => ({
|
||||||
@@ -226,7 +231,12 @@ export const permissionServiceFactory = ({
|
|||||||
throw new ForbiddenRequestError({ name: "You are not logged into this organization" });
|
throw new ForbiddenRequestError({ name: "You are not logged into this organization" });
|
||||||
}
|
}
|
||||||
|
|
||||||
validateOrgSSO(authMethod, userProjectPermission.orgAuthEnforced, userProjectPermission.orgRole);
|
validateOrgSSO(
|
||||||
|
authMethod,
|
||||||
|
userProjectPermission.orgAuthEnforced,
|
||||||
|
userProjectPermission.enableBypassOrgAuth,
|
||||||
|
userProjectPermission.orgRole
|
||||||
|
);
|
||||||
|
|
||||||
if (actionProjectType !== ActionProjectType.Any && actionProjectType !== userProjectPermission.projectType) {
|
if (actionProjectType !== ActionProjectType.Any && actionProjectType !== userProjectPermission.projectType) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
|
|||||||
@@ -260,7 +260,8 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
|
|||||||
defaultMembershipRoleSlug: slugSchema({ max: 64, field: "Default Membership Role" }).optional(),
|
defaultMembershipRoleSlug: slugSchema({ max: 64, field: "Default Membership Role" }).optional(),
|
||||||
enforceMfa: z.boolean().optional(),
|
enforceMfa: z.boolean().optional(),
|
||||||
selectedMfaMethod: z.nativeEnum(MfaMethod).optional(),
|
selectedMfaMethod: z.nativeEnum(MfaMethod).optional(),
|
||||||
allowSecretSharingOutsideOrganization: z.boolean().optional()
|
allowSecretSharingOutsideOrganization: z.boolean().optional(),
|
||||||
|
enableBypassOrgAuth: z.boolean().optional()
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
|
|||||||
@@ -16,5 +16,6 @@ export const sanitizedOrganizationSchema = OrganizationsSchema.pick({
|
|||||||
allowSecretSharingOutsideOrganization: true,
|
allowSecretSharingOutsideOrganization: true,
|
||||||
shouldUseNewPrivilegeSystem: true,
|
shouldUseNewPrivilegeSystem: true,
|
||||||
privilegeUpgradeInitiatedByUsername: true,
|
privilegeUpgradeInitiatedByUsername: true,
|
||||||
privilegeUpgradeInitiatedAt: true
|
privilegeUpgradeInitiatedAt: true,
|
||||||
|
enableBypassOrgAuth: true
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -349,7 +349,8 @@ export const orgServiceFactory = ({
|
|||||||
defaultMembershipRoleSlug,
|
defaultMembershipRoleSlug,
|
||||||
enforceMfa,
|
enforceMfa,
|
||||||
selectedMfaMethod,
|
selectedMfaMethod,
|
||||||
allowSecretSharingOutsideOrganization
|
allowSecretSharingOutsideOrganization,
|
||||||
|
enableBypassOrgAuth
|
||||||
}
|
}
|
||||||
}: TUpdateOrgDTO) => {
|
}: TUpdateOrgDTO) => {
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
@@ -429,7 +430,8 @@ export const orgServiceFactory = ({
|
|||||||
defaultMembershipRole,
|
defaultMembershipRole,
|
||||||
enforceMfa,
|
enforceMfa,
|
||||||
selectedMfaMethod,
|
selectedMfaMethod,
|
||||||
allowSecretSharingOutsideOrganization
|
allowSecretSharingOutsideOrganization,
|
||||||
|
enableBypassOrgAuth
|
||||||
});
|
});
|
||||||
if (!org) throw new NotFoundError({ message: `Organization with ID '${orgId}' not found` });
|
if (!org) throw new NotFoundError({ message: `Organization with ID '${orgId}' not found` });
|
||||||
return org;
|
return org;
|
||||||
|
|||||||
@@ -73,6 +73,7 @@ export type TUpdateOrgDTO = {
|
|||||||
enforceMfa: boolean;
|
enforceMfa: boolean;
|
||||||
selectedMfaMethod: MfaMethod;
|
selectedMfaMethod: MfaMethod;
|
||||||
allowSecretSharingOutsideOrganization: boolean;
|
allowSecretSharingOutsideOrganization: boolean;
|
||||||
|
enableBypassOrgAuth: boolean;
|
||||||
}>;
|
}>;
|
||||||
} & TOrgPermission;
|
} & TOrgPermission;
|
||||||
|
|
||||||
|
|||||||
@@ -110,7 +110,8 @@ export const useUpdateOrg = () => {
|
|||||||
defaultMembershipRoleSlug,
|
defaultMembershipRoleSlug,
|
||||||
enforceMfa,
|
enforceMfa,
|
||||||
selectedMfaMethod,
|
selectedMfaMethod,
|
||||||
allowSecretSharingOutsideOrganization
|
allowSecretSharingOutsideOrganization,
|
||||||
|
enableBypassOrgAuth
|
||||||
}) => {
|
}) => {
|
||||||
return apiRequest.patch(`/api/v1/organization/${orgId}`, {
|
return apiRequest.patch(`/api/v1/organization/${orgId}`, {
|
||||||
name,
|
name,
|
||||||
@@ -120,7 +121,8 @@ export const useUpdateOrg = () => {
|
|||||||
defaultMembershipRoleSlug,
|
defaultMembershipRoleSlug,
|
||||||
enforceMfa,
|
enforceMfa,
|
||||||
selectedMfaMethod,
|
selectedMfaMethod,
|
||||||
allowSecretSharingOutsideOrganization
|
allowSecretSharingOutsideOrganization,
|
||||||
|
enableBypassOrgAuth
|
||||||
});
|
});
|
||||||
},
|
},
|
||||||
onSuccess: () => {
|
onSuccess: () => {
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ export type Organization = {
|
|||||||
createAt: string;
|
createAt: string;
|
||||||
updatedAt: string;
|
updatedAt: string;
|
||||||
authEnforced: boolean;
|
authEnforced: boolean;
|
||||||
|
enableBypassOrgAuth: boolean;
|
||||||
orgAuthMethod: string;
|
orgAuthMethod: string;
|
||||||
scimEnabled: boolean;
|
scimEnabled: boolean;
|
||||||
slug: string;
|
slug: string;
|
||||||
@@ -30,6 +31,7 @@ export type UpdateOrgDTO = {
|
|||||||
enforceMfa?: boolean;
|
enforceMfa?: boolean;
|
||||||
selectedMfaMethod?: MfaMethod;
|
selectedMfaMethod?: MfaMethod;
|
||||||
allowSecretSharingOutsideOrganization?: boolean;
|
allowSecretSharingOutsideOrganization?: boolean;
|
||||||
|
enableBypassOrgAuth?: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type BillingDetails = {
|
export type BillingDetails = {
|
||||||
|
|||||||
@@ -69,7 +69,10 @@ export const SelectOrganizationPage = () => {
|
|||||||
|
|
||||||
const handleSelectOrganization = useCallback(
|
const handleSelectOrganization = useCallback(
|
||||||
async (organization: Organization) => {
|
async (organization: Organization) => {
|
||||||
if (organization.authEnforced && organization.userRole !== OrgMembershipRole.Admin) {
|
const canBypassOrgAuth =
|
||||||
|
organization.enableBypassOrgAuth && organization.userRole === OrgMembershipRole.Admin;
|
||||||
|
|
||||||
|
if (organization.authEnforced && !canBypassOrgAuth) {
|
||||||
// org has an org-level auth method enabled (e.g. SAML)
|
// org has an org-level auth method enabled (e.g. SAML)
|
||||||
// -> logout + redirect to SAML SSO
|
// -> logout + redirect to SAML SSO
|
||||||
await logout.mutateAsync();
|
await logout.mutateAsync();
|
||||||
|
|||||||
+58
-30
@@ -55,6 +55,28 @@ export const OrgGeneralAuthSection = () => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const handleEnableBypassOrgAuthToggle = async (value: boolean) => {
|
||||||
|
try {
|
||||||
|
if (!currentOrg?.id) return;
|
||||||
|
if (!subscription?.oidcSSO) {
|
||||||
|
handlePopUpOpen("upgradePlan");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
await mutateAsync({
|
||||||
|
orgId: currentOrg?.id,
|
||||||
|
enableBypassOrgAuth: value
|
||||||
|
});
|
||||||
|
|
||||||
|
createNotification({
|
||||||
|
text: `Successfully ${value ? "enabled" : "disabled"} admin bypassing of org-level auth`,
|
||||||
|
type: "success"
|
||||||
|
});
|
||||||
|
} catch (err) {
|
||||||
|
console.error(err);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<>
|
<>
|
||||||
{/* <div className="py-4">
|
{/* <div className="py-4">
|
||||||
@@ -77,35 +99,6 @@ export const OrgGeneralAuthSection = () => {
|
|||||||
<div className="mb-2 flex justify-between">
|
<div className="mb-2 flex justify-between">
|
||||||
<div className="flex items-center gap-1">
|
<div className="flex items-center gap-1">
|
||||||
<span className="text-md text-mineshaft-100">Enforce SAML SSO</span>
|
<span className="text-md text-mineshaft-100">Enforce SAML SSO</span>
|
||||||
<Tooltip
|
|
||||||
className="max-w-lg"
|
|
||||||
content={
|
|
||||||
<div>
|
|
||||||
<span>
|
|
||||||
Login enforcement is only applied to non-admin users in order to prevent total
|
|
||||||
lockout from the organization when the SAML provider is unavailable.
|
|
||||||
</span>
|
|
||||||
|
|
||||||
<p className="mt-4">
|
|
||||||
In case of a lockout, use the admin login portal{" "}
|
|
||||||
<a
|
|
||||||
target="_blank"
|
|
||||||
rel="noopener noreferrer"
|
|
||||||
className="underline underline-offset-2 hover:text-mineshaft-300"
|
|
||||||
href={`${window.location.origin}/admin/login`}
|
|
||||||
>
|
|
||||||
here.
|
|
||||||
</a>
|
|
||||||
</p>
|
|
||||||
</div>
|
|
||||||
}
|
|
||||||
>
|
|
||||||
<FontAwesomeIcon
|
|
||||||
icon={faInfoCircle}
|
|
||||||
size="sm"
|
|
||||||
className="mt-0.5 inline-block text-mineshaft-400"
|
|
||||||
/>
|
|
||||||
</Tooltip>
|
|
||||||
</div>
|
</div>
|
||||||
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
@@ -119,9 +112,44 @@ export const OrgGeneralAuthSection = () => {
|
|||||||
</OrgPermissionCan>
|
</OrgPermissionCan>
|
||||||
</div>
|
</div>
|
||||||
<p className="text-sm text-mineshaft-300">
|
<p className="text-sm text-mineshaft-300">
|
||||||
Enforce non-admin users to authenticate via SAML to access this organization
|
Enforce users to authenticate via SAML to access this organization
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
{currentOrg?.authEnforced && (
|
||||||
|
<div className="py-4">
|
||||||
|
<div className="mb-2 flex justify-between">
|
||||||
|
<div className="flex items-center gap-1">
|
||||||
|
<span className="text-md text-mineshaft-100">Enable Admin SSO Bypass</span>
|
||||||
|
<Tooltip
|
||||||
|
className="max-w-lg"
|
||||||
|
content="When this is enabled, we strongly recommend enforcing MFA at the organization level."
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon
|
||||||
|
icon={faInfoCircle}
|
||||||
|
size="sm"
|
||||||
|
className="mt-0.5 inline-block text-mineshaft-400"
|
||||||
|
/>
|
||||||
|
</Tooltip>
|
||||||
|
</div>
|
||||||
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
||||||
|
{(isAllowed) => (
|
||||||
|
<Switch
|
||||||
|
id="allow-admin-bypass"
|
||||||
|
isChecked={currentOrg?.enableBypassOrgAuth ?? false}
|
||||||
|
onCheckedChange={(value) => handleEnableBypassOrgAuthToggle(value)}
|
||||||
|
isDisabled={!isAllowed}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
</OrgPermissionCan>
|
||||||
|
</div>
|
||||||
|
<p className="text-sm text-mineshaft-300">
|
||||||
|
<span>
|
||||||
|
Allow organization admins to bypass OIDC enforcement when SSO is unavailable,
|
||||||
|
misconfigured, or inaccessible.
|
||||||
|
</span>
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
<UpgradePlanModal
|
<UpgradePlanModal
|
||||||
isOpen={popUp.upgradePlan.isOpen}
|
isOpen={popUp.upgradePlan.isOpen}
|
||||||
onOpenChange={(isOpen) => handlePopUpToggle("upgradePlan", isOpen)}
|
onOpenChange={(isOpen) => handlePopUpToggle("upgradePlan", isOpen)}
|
||||||
|
|||||||
+58
-30
@@ -82,6 +82,28 @@ export const OrgOIDCSection = (): JSX.Element => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const handleEnableBypassOrgAuthToggle = async (value: boolean) => {
|
||||||
|
try {
|
||||||
|
if (!currentOrg?.id) return;
|
||||||
|
if (!subscription?.oidcSSO) {
|
||||||
|
handlePopUpOpen("upgradePlan");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
await updateOrg({
|
||||||
|
orgId: currentOrg?.id,
|
||||||
|
enableBypassOrgAuth: value
|
||||||
|
});
|
||||||
|
|
||||||
|
createNotification({
|
||||||
|
text: `Successfully ${value ? "enabled" : "disabled"} admin bypassing of org-level auth`,
|
||||||
|
type: "success"
|
||||||
|
});
|
||||||
|
} catch (err) {
|
||||||
|
console.error(err);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
const handleOIDCGroupManagement = async (value: boolean) => {
|
const handleOIDCGroupManagement = async (value: boolean) => {
|
||||||
try {
|
try {
|
||||||
if (!currentOrg?.id) return;
|
if (!currentOrg?.id) return;
|
||||||
@@ -160,35 +182,6 @@ export const OrgOIDCSection = (): JSX.Element => {
|
|||||||
<div className="mb-2 flex justify-between">
|
<div className="mb-2 flex justify-between">
|
||||||
<div className="flex items-center gap-1">
|
<div className="flex items-center gap-1">
|
||||||
<span className="text-md text-mineshaft-100">Enforce OIDC SSO</span>
|
<span className="text-md text-mineshaft-100">Enforce OIDC SSO</span>
|
||||||
<Tooltip
|
|
||||||
className="max-w-lg"
|
|
||||||
content={
|
|
||||||
<div>
|
|
||||||
<span>
|
|
||||||
Login enforcement is only applied to non-admin users in order to prevent total
|
|
||||||
lockout from the organization when the OIDC provider is unavailable.
|
|
||||||
</span>
|
|
||||||
|
|
||||||
<p className="mt-4">
|
|
||||||
In case of a lockout, use the admin login portal{" "}
|
|
||||||
<a
|
|
||||||
target="_blank"
|
|
||||||
rel="noopener noreferrer"
|
|
||||||
className="underline underline-offset-2 hover:text-mineshaft-300"
|
|
||||||
href={`${window.location.origin}/admin/login`}
|
|
||||||
>
|
|
||||||
here.
|
|
||||||
</a>
|
|
||||||
</p>
|
|
||||||
</div>
|
|
||||||
}
|
|
||||||
>
|
|
||||||
<FontAwesomeIcon
|
|
||||||
icon={faInfoCircle}
|
|
||||||
size="sm"
|
|
||||||
className="mt-0.5 inline-block text-mineshaft-400"
|
|
||||||
/>
|
|
||||||
</Tooltip>
|
|
||||||
</div>
|
</div>
|
||||||
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
@@ -202,9 +195,44 @@ export const OrgOIDCSection = (): JSX.Element => {
|
|||||||
</OrgPermissionCan>
|
</OrgPermissionCan>
|
||||||
</div>
|
</div>
|
||||||
<p className="text-sm text-mineshaft-300">
|
<p className="text-sm text-mineshaft-300">
|
||||||
<span>Enforce non-admin users to authenticate via OIDC to access this organization.</span>
|
<span>Enforce users to authenticate via OIDC to access this organization.</span>
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
{currentOrg?.authEnforced && (
|
||||||
|
<div className="py-4">
|
||||||
|
<div className="mb-2 flex justify-between">
|
||||||
|
<div className="flex items-center gap-1">
|
||||||
|
<span className="text-md text-mineshaft-100">Enable Admin SSO Bypass</span>
|
||||||
|
<Tooltip
|
||||||
|
className="max-w-lg"
|
||||||
|
content="When this is enabled, we strongly recommend enforcing MFA at the organization level."
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon
|
||||||
|
icon={faInfoCircle}
|
||||||
|
size="sm"
|
||||||
|
className="mt-0.5 inline-block text-mineshaft-400"
|
||||||
|
/>
|
||||||
|
</Tooltip>
|
||||||
|
</div>
|
||||||
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
||||||
|
{(isAllowed) => (
|
||||||
|
<Switch
|
||||||
|
id="allow-admin-bypass"
|
||||||
|
isChecked={currentOrg?.enableBypassOrgAuth ?? false}
|
||||||
|
onCheckedChange={(value) => handleEnableBypassOrgAuthToggle(value)}
|
||||||
|
isDisabled={!isAllowed}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
</OrgPermissionCan>
|
||||||
|
</div>
|
||||||
|
<p className="text-sm text-mineshaft-300">
|
||||||
|
<span>
|
||||||
|
Allow organization admins to bypass OIDC enforcement when SSO is unavailable,
|
||||||
|
misconfigured, or inaccessible.
|
||||||
|
</span>
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
<div className="py-4">
|
<div className="py-4">
|
||||||
<div className="mb-2 flex justify-between">
|
<div className="mb-2 flex justify-between">
|
||||||
<div className="text-md flex items-center text-mineshaft-100">
|
<div className="text-md flex items-center text-mineshaft-100">
|
||||||
|
|||||||
Reference in New Issue
Block a user