mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 10:27:26 +00:00
Feat: Scoped JWT to organization, SAML helper functions
This commit is contained in:
@@ -0,0 +1,22 @@
|
|||||||
|
import { UnauthorizedError } from "@app/lib/errors";
|
||||||
|
import { ActorAuthMethod, AuthMethod } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
|
function isAuthMethodSaml(actorAuthMethod: ActorAuthMethod) {
|
||||||
|
if (!actorAuthMethod) return false;
|
||||||
|
|
||||||
|
return [AuthMethod.AZURE_SAML, AuthMethod.OKTA_SAML, AuthMethod.JUMPCLOUD_SAML, AuthMethod.GOOGLE_SAML].includes(
|
||||||
|
actorAuthMethod
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
function validateOrgSAML(actorAuthMethod: ActorAuthMethod, isSamlEnforced?: boolean | null) {
|
||||||
|
if (actorAuthMethod === undefined) {
|
||||||
|
throw new UnauthorizedError({ name: "No auth method defined" });
|
||||||
|
}
|
||||||
|
|
||||||
|
if (isSamlEnforced && actorAuthMethod !== null && !isAuthMethodSaml(actorAuthMethod)) {
|
||||||
|
throw new UnauthorizedError({ name: "Cannot access org-scoped resource" });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export { isAuthMethodSaml, validateOrgSAML };
|
||||||
Reference in New Issue
Block a user