mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 21:27:10 +00:00
Add TRUST_SAML_EMAILS and TRUST_LDAP_EMAILS opts
This commit is contained in:
@@ -437,7 +437,7 @@ export const ldapConfigServiceFactory = ({
|
|||||||
{
|
{
|
||||||
username: uniqueUsername,
|
username: uniqueUsername,
|
||||||
email: emails[0],
|
email: emails[0],
|
||||||
isEmailVerified: false,
|
isEmailVerified: appCfg.TRUST_LDAP_EMAILS,
|
||||||
firstName,
|
firstName,
|
||||||
lastName,
|
lastName,
|
||||||
authMethods: [],
|
authMethods: [],
|
||||||
@@ -557,7 +557,7 @@ export const ldapConfigServiceFactory = ({
|
|||||||
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
||||||
userId: user.id,
|
userId: user.id,
|
||||||
username: user.username,
|
username: user.username,
|
||||||
...(user.email && { email: user.email }),
|
...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
|
||||||
firstName,
|
firstName,
|
||||||
lastName,
|
lastName,
|
||||||
organizationName: organization.name,
|
organizationName: organization.name,
|
||||||
|
|||||||
@@ -374,7 +374,7 @@ export const samlConfigServiceFactory = ({
|
|||||||
{
|
{
|
||||||
username: uniqueUsername,
|
username: uniqueUsername,
|
||||||
email,
|
email,
|
||||||
isEmailVerified: false,
|
isEmailVerified: appCfg.TRUST_SAML_EMAILS,
|
||||||
firstName,
|
firstName,
|
||||||
lastName,
|
lastName,
|
||||||
authMethods: [],
|
authMethods: [],
|
||||||
@@ -414,7 +414,7 @@ export const samlConfigServiceFactory = ({
|
|||||||
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
||||||
userId: user.id,
|
userId: user.id,
|
||||||
username: user.username,
|
username: user.username,
|
||||||
...(user.email && { email: user.email }),
|
...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
|
||||||
firstName,
|
firstName,
|
||||||
lastName,
|
lastName,
|
||||||
organizationName: organization.name,
|
organizationName: organization.name,
|
||||||
|
|||||||
@@ -98,6 +98,9 @@ const envSchema = z
|
|||||||
CLIENT_ID_GITLAB: zpStr(z.string().optional()),
|
CLIENT_ID_GITLAB: zpStr(z.string().optional()),
|
||||||
CLIENT_SECRET_GITLAB: zpStr(z.string().optional()),
|
CLIENT_SECRET_GITLAB: zpStr(z.string().optional()),
|
||||||
URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)),
|
URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)),
|
||||||
|
// email verification
|
||||||
|
TRUST_SAML_EMAILS: zodStrBool.default("false"),
|
||||||
|
TRUST_LDAP_EMAILS: zodStrBool.default("false"),
|
||||||
// SECRET-SCANNING
|
// SECRET-SCANNING
|
||||||
SECRET_SCANNING_WEBHOOK_PROXY: zpStr(z.string().optional()),
|
SECRET_SCANNING_WEBHOOK_PROXY: zpStr(z.string().optional()),
|
||||||
SECRET_SCANNING_WEBHOOK_SECRET: zpStr(z.string().optional()),
|
SECRET_SCANNING_WEBHOOK_SECRET: zpStr(z.string().optional()),
|
||||||
|
|||||||
@@ -361,6 +361,7 @@ export const authLoginServiceFactory = ({
|
|||||||
user = await userDAL.create({
|
user = await userDAL.create({
|
||||||
username: email,
|
username: email,
|
||||||
email,
|
email,
|
||||||
|
isEmailVerified: true,
|
||||||
firstName,
|
firstName,
|
||||||
lastName,
|
lastName,
|
||||||
authMethods: [authMethod],
|
authMethods: [authMethod],
|
||||||
@@ -374,6 +375,8 @@ export const authLoginServiceFactory = ({
|
|||||||
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
||||||
userId: user.id,
|
userId: user.id,
|
||||||
username: user.username,
|
username: user.username,
|
||||||
|
email: user.email,
|
||||||
|
isEmailVerified: user.isEmailVerified,
|
||||||
firstName: user.firstName,
|
firstName: user.firstName,
|
||||||
lastName: user.lastName,
|
lastName: user.lastName,
|
||||||
authMethod,
|
authMethod,
|
||||||
|
|||||||
@@ -135,11 +135,6 @@ export const authSignupServiceFactory = ({
|
|||||||
userAgent,
|
userAgent,
|
||||||
authorization
|
authorization
|
||||||
}: TCompleteAccountSignupDTO) => {
|
}: TCompleteAccountSignupDTO) => {
|
||||||
console.log("completeEmailAccountSignup args: ", {
|
|
||||||
email,
|
|
||||||
firstName,
|
|
||||||
lastName
|
|
||||||
});
|
|
||||||
const user = await userDAL.findOne({ username: email });
|
const user = await userDAL.findOne({ username: email });
|
||||||
if (!user || (user && user.isAccepted)) {
|
if (!user || (user && user.isAccepted)) {
|
||||||
throw new Error("Failed to complete account for complete user");
|
throw new Error("Failed to complete account for complete user");
|
||||||
|
|||||||
@@ -3,26 +3,30 @@ title: "Configurations"
|
|||||||
description: "Read how to configure environment variables for self-hosted Infisical."
|
description: "Read how to configure environment variables for self-hosted Infisical."
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
||||||
Infisical accepts all configurations via environment variables. For a minimal self-hosted instance, at least `ENCRYPTION_KEY`, `AUTH_SECRET`, `DB_CONNECTION_URI` and `REDIS_URL` must be defined.
|
Infisical accepts all configurations via environment variables. For a minimal self-hosted instance, at least `ENCRYPTION_KEY`, `AUTH_SECRET`, `DB_CONNECTION_URI` and `REDIS_URL` must be defined.
|
||||||
However, you can configure additional settings to activate more features as needed.
|
However, you can configure additional settings to activate more features as needed.
|
||||||
|
|
||||||
## General platform
|
## General platform
|
||||||
|
|
||||||
Used to configure platform-specific security and operational settings
|
Used to configure platform-specific security and operational settings
|
||||||
|
|
||||||
<ParamField query="ENCRYPTION_KEY" type="string" default="none" required>
|
<ParamField query="ENCRYPTION_KEY" type="string" default="none" required>
|
||||||
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex 16`
|
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex
|
||||||
|
16`
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField query="AUTH_SECRET" type="string" default="none" required>
|
<ParamField query="AUTH_SECRET" type="string" default="none" required>
|
||||||
Must be a random 32 byte base64 string. Can be generated with `openssl rand -base64 32`
|
Must be a random 32 byte base64 string. Can be generated with `openssl rand
|
||||||
|
-base64 32`
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField query="SITE_URL" type="string" default="none" optional>
|
<ParamField query="SITE_URL" type="string" default="none" optional>
|
||||||
Must be an absolute URL including the protocol (e.g. https://app.infisical.com).
|
Must be an absolute URL including the protocol (e.g.
|
||||||
|
https://app.infisical.com).
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
## Data Layer
|
## Data Layer
|
||||||
|
|
||||||
The platform utilizes Postgres to persist all of its data and Redis for caching and backgroud tasks
|
The platform utilizes Postgres to persist all of its data and Redis for caching and backgroud tasks
|
||||||
|
|
||||||
<ParamField query="DB_CONNECTION_URI" type="string" default="" required>
|
<ParamField query="DB_CONNECTION_URI" type="string" default="" required>
|
||||||
@@ -39,9 +43,8 @@ The platform utilizes Postgres to persist all of its data and Redis for caching
|
|||||||
Redis connection string.
|
Redis connection string.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
## Email service
|
## Email service
|
||||||
|
|
||||||
Without email configuration, Infisical's core functions like sign-up/login and secret operations work, but this disables multi-factor authentication, email invites for projects, alerts for suspicious logins, and all other email-dependent features.
|
Without email configuration, Infisical's core functions like sign-up/login and secret operations work, but this disables multi-factor authentication, email invites for projects, alerts for suspicious logins, and all other email-dependent features.
|
||||||
|
|
||||||
<Accordion title="Generic Configuration">
|
<Accordion title="Generic Configuration">
|
||||||
@@ -49,22 +52,33 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
|||||||
Hostname to connect to for establishing SMTP connections
|
Hostname to connect to for establishing SMTP connections
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<ParamField query="SMTP_USERNAME" type="string" default="none" optional>
|
<ParamField query="SMTP_USERNAME" type="string" default="none" optional>
|
||||||
Credential to connect to host (e.g. [email protected])
|
Credential to connect to host (e.g. [email protected])
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<ParamField query="SMTP_PASSWORD" type="string" default="none" optional>
|
<ParamField query="SMTP_PASSWORD" type="string" default="none" optional>
|
||||||
Credential to connect to host
|
Credential to connect to host
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<ParamField query="SMTP_PORT" type="string" default="587" optional>
|
<ParamField query="SMTP_PORT" type="string" default="587" optional>
|
||||||
Port to connect to for establishing SMTP connections
|
Port to connect to for establishing SMTP connections
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<ParamField query="SMTP_SECURE" type="string" default="none" optional>
|
<ParamField query="SMTP_SECURE" type="string" default="none" optional>
|
||||||
If true, use TLS when connecting to host. If false, TLS will be used if STARTTLS is supported
|
If true, use TLS when connecting to host. If false, TLS will be used if
|
||||||
|
STARTTLS is supported
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<ParamField query="SMTP_FROM_ADDRESS" type="string" default="none" optional>
|
<ParamField query="SMTP_FROM_ADDRESS" type="string" default="none" optional>
|
||||||
Email address to be used for sending emails
|
Email address to be used for sending emails
|
||||||
</ParamField>
|
</ParamField>
|
||||||
@@ -118,6 +132,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
|||||||
[email protected] # your email address being used to send out emails
|
[email protected] # your email address being used to send out emails
|
||||||
SMTP_FROM_NAME=Infisical
|
SMTP_FROM_NAME=Infisical
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="AWS SES">
|
<Accordion title="AWS SES">
|
||||||
@@ -149,6 +164,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
|||||||
SMTP_FROM_NAME=Infisical
|
SMTP_FROM_NAME=Infisical
|
||||||
```
|
```
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
@@ -176,6 +192,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
|||||||
SMTP_FROM_NAME=Infisical
|
SMTP_FROM_NAME=Infisical
|
||||||
```
|
```
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
The `SMTP_FROM_ADDRESS` environment variable should be an email for an
|
The `SMTP_FROM_ADDRESS` environment variable should be an email for an
|
||||||
authenticated domain under Configuration > Domain Management in SocketLabs.
|
authenticated domain under Configuration > Domain Management in SocketLabs.
|
||||||
@@ -215,9 +233,11 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
|||||||
[email protected] # your email address being used to send out emails
|
[email protected] # your email address being used to send out emails
|
||||||
SMTP_FROM_NAME=Infisical
|
SMTP_FROM_NAME=Infisical
|
||||||
```
|
```
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
Remember that you will need to restart Infisical for this to work properly.
|
Remember that you will need to restart Infisical for this to work properly.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Gmail">
|
<Accordion title="Gmail">
|
||||||
@@ -261,6 +281,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
|||||||
[email protected]
|
[email protected]
|
||||||
SMTP_FROM_NAME=Infisical
|
SMTP_FROM_NAME=Infisical
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Zoho Mail">
|
<Accordion title="Zoho Mail">
|
||||||
@@ -278,6 +299,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
|||||||
SMTP_FROM_NAME=Infisical
|
SMTP_FROM_NAME=Infisical
|
||||||
```
|
```
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
You can use either your personal Zoho email address like `[email protected]` or
|
You can use either your personal Zoho email address like `[email protected]` or
|
||||||
a domain-based email address like `[email protected]`. If using a
|
a domain-based email address like `[email protected]`. If using a
|
||||||
@@ -290,11 +313,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
|||||||
</Info>
|
</Info>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
## Authentication
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
## SSO based login
|
|
||||||
By default, users can only login via email/password based login method.
|
By default, users can only login via email/password based login method.
|
||||||
To login into Infisical with OAuth providers such as Google, configure the associated variables.
|
To login into Infisical with OAuth providers such as Google, configure the associated variables.
|
||||||
|
|
||||||
@@ -335,33 +355,49 @@ To login into Infisical with OAuth providers such as Google, configure the assoc
|
|||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Okta SAML">
|
<Accordion title="Okta SAML">
|
||||||
Requires enterprise license. Please contact [email protected] to get more information.
|
Requires enterprise license. Please contact [email protected] to get more
|
||||||
|
information.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Azure SAML">
|
<Accordion title="Azure SAML">
|
||||||
Requires enterprise license. Please contact [email protected] to get more information.
|
Requires enterprise license. Please contact [email protected] to get more
|
||||||
|
information.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="JumpCloud SAML">
|
<Accordion title="JumpCloud SAML">
|
||||||
Requires enterprise license. Please contact [email protected] to get more information.
|
Requires enterprise license. Please contact [email protected] to get more
|
||||||
|
information.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string">
|
<ParamField query="TRUST_SAML_EMAILS" type="boolean" default="false" optional>
|
||||||
Configure SAML organization slug to automatically redirect all users of your Infisical instance to the identity provider.
|
Whether or not to trust emails from external SAML identity providers. If set
|
||||||
|
to `false` then users will be prompted to verify their email address upon
|
||||||
|
first login.
|
||||||
|
</ParamField>
|
||||||
|
<ParamField query="TRUST_LDAP_EMAILS" type="string" default="false" optional>
|
||||||
|
Whether or not to trust emails from external LDAP servers. If set to `false`
|
||||||
|
then users will be prompted to verify their email address upon first login.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string">
|
||||||
|
Configure SAML organization slug to automatically redirect all users of your
|
||||||
|
Infisical instance to the identity provider.
|
||||||
|
</ParamField>
|
||||||
|
|
||||||
## Native secret integrations
|
## Native secret integrations
|
||||||
|
|
||||||
To help you sync secrets from Infisical to services such as Github and Gitlab, Infisical provides native integrations out of the box.
|
To help you sync secrets from Infisical to services such as Github and Gitlab, Infisical provides native integrations out of the box.
|
||||||
|
|
||||||
<Accordion title="Heroku">
|
<Accordion title="Heroku">
|
||||||
<ParamField query="CLIENT_ID_HEROKU" type="string" default="none" optional>
|
<ParamField query="CLIENT_ID_HEROKU" type="string" default="none" optional>
|
||||||
OAuth2 client ID for Heroku integration
|
OAuth2 client ID for Heroku integration
|
||||||
</ParamField>
|
</ParamField>
|
||||||
<ParamField query="CLIENT_SECRET_HEROKU" type="string" default="none" optional>
|
<ParamField
|
||||||
|
query="CLIENT_SECRET_HEROKU"
|
||||||
|
type="string"
|
||||||
|
default="none"
|
||||||
|
optional
|
||||||
|
>
|
||||||
OAuth2 client secret for Heroku integration
|
OAuth2 client secret for Heroku integration
|
||||||
</ParamField>
|
</ParamField>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
@@ -371,6 +407,8 @@ To help you sync secrets from Infisical to services such as Github and Gitlab, I
|
|||||||
OAuth2 client ID for Vercel integration
|
OAuth2 client ID for Vercel integration
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
|
{" "}
|
||||||
|
|
||||||
<ParamField query="CLIENT_SECRET_VERCEL" type="string" default="none" optional>
|
<ParamField query="CLIENT_SECRET_VERCEL" type="string" default="none" optional>
|
||||||
OAuth2 client secret for Vercel integration
|
OAuth2 client secret for Vercel integration
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|||||||
-2
@@ -149,8 +149,6 @@ export const OrgMembersTable = ({ handlePopUpOpen, setCompleteInviteLink }: Prop
|
|||||||
[members, searchMemberFilter]
|
[members, searchMemberFilter]
|
||||||
);
|
);
|
||||||
|
|
||||||
console.log("filterdUser: ", filterdUser);
|
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div>
|
<div>
|
||||||
<Input
|
<Input
|
||||||
|
|||||||
@@ -16,8 +16,16 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
|
|||||||
const [step, setStep] = useState(0);
|
const [step, setStep] = useState(0);
|
||||||
const [password, setPassword] = useState("");
|
const [password, setPassword] = useState("");
|
||||||
|
|
||||||
const { username, email, organizationName, organizationSlug, firstName, lastName, authType } =
|
const {
|
||||||
jwt_decode(providerAuthToken) as any;
|
username,
|
||||||
|
email,
|
||||||
|
organizationName,
|
||||||
|
organizationSlug,
|
||||||
|
firstName,
|
||||||
|
lastName,
|
||||||
|
authType,
|
||||||
|
isEmailVerified
|
||||||
|
} = jwt_decode(providerAuthToken) as any;
|
||||||
|
|
||||||
const renderView = () => {
|
const renderView = () => {
|
||||||
switch (step) {
|
switch (step) {
|
||||||
@@ -25,7 +33,7 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
|
|||||||
return (
|
return (
|
||||||
<UserInfoSSOStep
|
<UserInfoSSOStep
|
||||||
username={username}
|
username={username}
|
||||||
email={email}
|
isEmailVerified={isEmailVerified}
|
||||||
name={`${firstName} ${lastName}`}
|
name={`${firstName} ${lastName}`}
|
||||||
providerOrganizationName={organizationName}
|
providerOrganizationName={organizationName}
|
||||||
password={password}
|
password={password}
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ const client = new jsrp.client();
|
|||||||
type Props = {
|
type Props = {
|
||||||
setStep: (step: number) => void;
|
setStep: (step: number) => void;
|
||||||
username: string;
|
username: string;
|
||||||
email?: string;
|
isEmailVerified?: boolean;
|
||||||
password: string;
|
password: string;
|
||||||
setPassword: (value: string) => void;
|
setPassword: (value: string) => void;
|
||||||
name: string;
|
name: string;
|
||||||
@@ -60,7 +60,7 @@ type Errors = {
|
|||||||
*/
|
*/
|
||||||
export const UserInfoSSOStep = ({
|
export const UserInfoSSOStep = ({
|
||||||
username,
|
username,
|
||||||
email,
|
isEmailVerified,
|
||||||
name,
|
name,
|
||||||
providerOrganizationName,
|
providerOrganizationName,
|
||||||
password,
|
password,
|
||||||
@@ -204,13 +204,13 @@ export const UserInfoSSOStep = ({
|
|||||||
localStorage.setItem("orgData.id", orgId);
|
localStorage.setItem("orgData.id", orgId);
|
||||||
localStorage.setItem("projectData.id", project.id);
|
localStorage.setItem("projectData.id", project.id);
|
||||||
|
|
||||||
if (email) {
|
if (isEmailVerified) {
|
||||||
|
// move to backup PDF step
|
||||||
|
setStep(3);
|
||||||
|
} else {
|
||||||
// move to verify email
|
// move to verify email
|
||||||
await sendEmailVerificationCode();
|
await sendEmailVerificationCode();
|
||||||
setStep(1);
|
setStep(1);
|
||||||
} else {
|
|
||||||
// move to backup PDF step
|
|
||||||
setStep(3);
|
|
||||||
}
|
}
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
setIsLoading(false);
|
setIsLoading(false);
|
||||||
|
|||||||
Reference in New Issue
Block a user