Add TRUST_SAML_EMAILS and TRUST_LDAP_EMAILS opts

This commit is contained in:
Tuan Dang
2024-04-26 22:30:07 -07:00
parent 858a35812a
commit 80da2a19aa
9 changed files with 204 additions and 159 deletions
@@ -437,7 +437,7 @@ export const ldapConfigServiceFactory = ({
{ {
username: uniqueUsername, username: uniqueUsername,
email: emails[0], email: emails[0],
isEmailVerified: false, isEmailVerified: appCfg.TRUST_LDAP_EMAILS,
firstName, firstName,
lastName, lastName,
authMethods: [], authMethods: [],
@@ -557,7 +557,7 @@ export const ldapConfigServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN, authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id, userId: user.id,
username: user.username, username: user.username,
...(user.email && { email: user.email }), ...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
firstName, firstName,
lastName, lastName,
organizationName: organization.name, organizationName: organization.name,
@@ -374,7 +374,7 @@ export const samlConfigServiceFactory = ({
{ {
username: uniqueUsername, username: uniqueUsername,
email, email,
isEmailVerified: false, isEmailVerified: appCfg.TRUST_SAML_EMAILS,
firstName, firstName,
lastName, lastName,
authMethods: [], authMethods: [],
@@ -414,7 +414,7 @@ export const samlConfigServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN, authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id, userId: user.id,
username: user.username, username: user.username,
...(user.email && { email: user.email }), ...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
firstName, firstName,
lastName, lastName,
organizationName: organization.name, organizationName: organization.name,
+3
View File
@@ -98,6 +98,9 @@ const envSchema = z
CLIENT_ID_GITLAB: zpStr(z.string().optional()), CLIENT_ID_GITLAB: zpStr(z.string().optional()),
CLIENT_SECRET_GITLAB: zpStr(z.string().optional()), CLIENT_SECRET_GITLAB: zpStr(z.string().optional()),
URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)), URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)),
// email verification
TRUST_SAML_EMAILS: zodStrBool.default("false"),
TRUST_LDAP_EMAILS: zodStrBool.default("false"),
// SECRET-SCANNING // SECRET-SCANNING
SECRET_SCANNING_WEBHOOK_PROXY: zpStr(z.string().optional()), SECRET_SCANNING_WEBHOOK_PROXY: zpStr(z.string().optional()),
SECRET_SCANNING_WEBHOOK_SECRET: zpStr(z.string().optional()), SECRET_SCANNING_WEBHOOK_SECRET: zpStr(z.string().optional()),
@@ -361,6 +361,7 @@ export const authLoginServiceFactory = ({
user = await userDAL.create({ user = await userDAL.create({
username: email, username: email,
email, email,
isEmailVerified: true,
firstName, firstName,
lastName, lastName,
authMethods: [authMethod], authMethods: [authMethod],
@@ -374,6 +375,8 @@ export const authLoginServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN, authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id, userId: user.id,
username: user.username, username: user.username,
email: user.email,
isEmailVerified: user.isEmailVerified,
firstName: user.firstName, firstName: user.firstName,
lastName: user.lastName, lastName: user.lastName,
authMethod, authMethod,
@@ -135,11 +135,6 @@ export const authSignupServiceFactory = ({
userAgent, userAgent,
authorization authorization
}: TCompleteAccountSignupDTO) => { }: TCompleteAccountSignupDTO) => {
console.log("completeEmailAccountSignup args: ", {
email,
firstName,
lastName
});
const user = await userDAL.findOne({ username: email }); const user = await userDAL.findOne({ username: email });
if (!user || (user && user.isAccepted)) { if (!user || (user && user.isAccepted)) {
throw new Error("Failed to complete account for complete user"); throw new Error("Failed to complete account for complete user");
+58 -20
View File
@@ -3,26 +3,30 @@ title: "Configurations"
description: "Read how to configure environment variables for self-hosted Infisical." description: "Read how to configure environment variables for self-hosted Infisical."
--- ---
Infisical accepts all configurations via environment variables. For a minimal self-hosted instance, at least `ENCRYPTION_KEY`, `AUTH_SECRET`, `DB_CONNECTION_URI` and `REDIS_URL` must be defined. Infisical accepts all configurations via environment variables. For a minimal self-hosted instance, at least `ENCRYPTION_KEY`, `AUTH_SECRET`, `DB_CONNECTION_URI` and `REDIS_URL` must be defined.
However, you can configure additional settings to activate more features as needed. However, you can configure additional settings to activate more features as needed.
## General platform ## General platform
Used to configure platform-specific security and operational settings Used to configure platform-specific security and operational settings
<ParamField query="ENCRYPTION_KEY" type="string" default="none" required> <ParamField query="ENCRYPTION_KEY" type="string" default="none" required>
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex 16` Must be a random 16 byte hex string. Can be generated with `openssl rand -hex
16`
</ParamField> </ParamField>
<ParamField query="AUTH_SECRET" type="string" default="none" required> <ParamField query="AUTH_SECRET" type="string" default="none" required>
Must be a random 32 byte base64 string. Can be generated with `openssl rand -base64 32` Must be a random 32 byte base64 string. Can be generated with `openssl rand
-base64 32`
</ParamField> </ParamField>
<ParamField query="SITE_URL" type="string" default="none" optional> <ParamField query="SITE_URL" type="string" default="none" optional>
Must be an absolute URL including the protocol (e.g. https://app.infisical.com). Must be an absolute URL including the protocol (e.g.
https://app.infisical.com).
</ParamField> </ParamField>
## Data Layer ## Data Layer
The platform utilizes Postgres to persist all of its data and Redis for caching and backgroud tasks The platform utilizes Postgres to persist all of its data and Redis for caching and backgroud tasks
<ParamField query="DB_CONNECTION_URI" type="string" default="" required> <ParamField query="DB_CONNECTION_URI" type="string" default="" required>
@@ -39,9 +43,8 @@ The platform utilizes Postgres to persist all of its data and Redis for caching
Redis connection string. Redis connection string.
</ParamField> </ParamField>
## Email service ## Email service
Without email configuration, Infisical's core functions like sign-up/login and secret operations work, but this disables multi-factor authentication, email invites for projects, alerts for suspicious logins, and all other email-dependent features. Without email configuration, Infisical's core functions like sign-up/login and secret operations work, but this disables multi-factor authentication, email invites for projects, alerts for suspicious logins, and all other email-dependent features.
<Accordion title="Generic Configuration"> <Accordion title="Generic Configuration">
@@ -49,22 +52,33 @@ Without email configuration, Infisical's core functions like sign-up/login and s
Hostname to connect to for establishing SMTP connections Hostname to connect to for establishing SMTP connections
</ParamField> </ParamField>
{" "}
<ParamField query="SMTP_USERNAME" type="string" default="none" optional> <ParamField query="SMTP_USERNAME" type="string" default="none" optional>
Credential to connect to host (e.g. [email protected]) Credential to connect to host (e.g. [email protected])
</ParamField> </ParamField>
{" "}
<ParamField query="SMTP_PASSWORD" type="string" default="none" optional> <ParamField query="SMTP_PASSWORD" type="string" default="none" optional>
Credential to connect to host Credential to connect to host
</ParamField> </ParamField>
{" "}
<ParamField query="SMTP_PORT" type="string" default="587" optional> <ParamField query="SMTP_PORT" type="string" default="587" optional>
Port to connect to for establishing SMTP connections Port to connect to for establishing SMTP connections
</ParamField> </ParamField>
{" "}
<ParamField query="SMTP_SECURE" type="string" default="none" optional> <ParamField query="SMTP_SECURE" type="string" default="none" optional>
If true, use TLS when connecting to host. If false, TLS will be used if STARTTLS is supported If true, use TLS when connecting to host. If false, TLS will be used if
STARTTLS is supported
</ParamField> </ParamField>
{" "}
<ParamField query="SMTP_FROM_ADDRESS" type="string" default="none" optional> <ParamField query="SMTP_FROM_ADDRESS" type="string" default="none" optional>
Email address to be used for sending emails Email address to be used for sending emails
</ParamField> </ParamField>
@@ -118,6 +132,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
[email protected] # your email address being used to send out emails [email protected] # your email address being used to send out emails
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
</Accordion> </Accordion>
<Accordion title="AWS SES"> <Accordion title="AWS SES">
@@ -149,6 +164,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
</Step> </Step>
</Steps> </Steps>
<Info> <Info>
@@ -176,6 +192,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
{" "}
<Note> <Note>
The `SMTP_FROM_ADDRESS` environment variable should be an email for an The `SMTP_FROM_ADDRESS` environment variable should be an email for an
authenticated domain under Configuration > Domain Management in SocketLabs. authenticated domain under Configuration > Domain Management in SocketLabs.
@@ -215,9 +233,11 @@ Without email configuration, Infisical's core functions like sign-up/login and s
[email protected] # your email address being used to send out emails [email protected] # your email address being used to send out emails
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
<Info> <Info>
Remember that you will need to restart Infisical for this to work properly. Remember that you will need to restart Infisical for this to work properly.
</Info> </Info>
</Accordion> </Accordion>
<Accordion title="Gmail"> <Accordion title="Gmail">
@@ -261,6 +281,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
[email protected] [email protected]
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
</Accordion> </Accordion>
<Accordion title="Zoho Mail"> <Accordion title="Zoho Mail">
@@ -278,6 +299,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
{" "}
<Note> <Note>
You can use either your personal Zoho email address like `[email protected]` or You can use either your personal Zoho email address like `[email protected]` or
a domain-based email address like `[email protected]`. If using a a domain-based email address like `[email protected]`. If using a
@@ -290,11 +313,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
</Info> </Info>
</Accordion> </Accordion>
## Authentication
## SSO based login
By default, users can only login via email/password based login method. By default, users can only login via email/password based login method.
To login into Infisical with OAuth providers such as Google, configure the associated variables. To login into Infisical with OAuth providers such as Google, configure the associated variables.
@@ -335,33 +355,49 @@ To login into Infisical with OAuth providers such as Google, configure the assoc
</Accordion> </Accordion>
<Accordion title="Okta SAML"> <Accordion title="Okta SAML">
Requires enterprise license. Please contact [email protected] to get more information. Requires enterprise license. Please contact [email protected] to get more
information.
</Accordion> </Accordion>
<Accordion title="Azure SAML"> <Accordion title="Azure SAML">
Requires enterprise license. Please contact [email protected] to get more information. Requires enterprise license. Please contact [email protected] to get more
information.
</Accordion> </Accordion>
<Accordion title="JumpCloud SAML"> <Accordion title="JumpCloud SAML">
Requires enterprise license. Please contact [email protected] to get more information. Requires enterprise license. Please contact [email protected] to get more
information.
</Accordion> </Accordion>
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string"> <ParamField query="TRUST_SAML_EMAILS" type="boolean" default="false" optional>
Configure SAML organization slug to automatically redirect all users of your Infisical instance to the identity provider. Whether or not to trust emails from external SAML identity providers. If set
to `false` then users will be prompted to verify their email address upon
first login.
</ParamField>
<ParamField query="TRUST_LDAP_EMAILS" type="string" default="false" optional>
Whether or not to trust emails from external LDAP servers. If set to `false`
then users will be prompted to verify their email address upon first login.
</ParamField> </ParamField>
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string">
Configure SAML organization slug to automatically redirect all users of your
Infisical instance to the identity provider.
</ParamField>
## Native secret integrations ## Native secret integrations
To help you sync secrets from Infisical to services such as Github and Gitlab, Infisical provides native integrations out of the box. To help you sync secrets from Infisical to services such as Github and Gitlab, Infisical provides native integrations out of the box.
<Accordion title="Heroku"> <Accordion title="Heroku">
<ParamField query="CLIENT_ID_HEROKU" type="string" default="none" optional> <ParamField query="CLIENT_ID_HEROKU" type="string" default="none" optional>
OAuth2 client ID for Heroku integration OAuth2 client ID for Heroku integration
</ParamField> </ParamField>
<ParamField query="CLIENT_SECRET_HEROKU" type="string" default="none" optional> <ParamField
query="CLIENT_SECRET_HEROKU"
type="string"
default="none"
optional
>
OAuth2 client secret for Heroku integration OAuth2 client secret for Heroku integration
</ParamField> </ParamField>
</Accordion> </Accordion>
@@ -371,6 +407,8 @@ To help you sync secrets from Infisical to services such as Github and Gitlab, I
OAuth2 client ID for Vercel integration OAuth2 client ID for Vercel integration
</ParamField> </ParamField>
{" "}
<ParamField query="CLIENT_SECRET_VERCEL" type="string" default="none" optional> <ParamField query="CLIENT_SECRET_VERCEL" type="string" default="none" optional>
OAuth2 client secret for Vercel integration OAuth2 client secret for Vercel integration
</ParamField> </ParamField>
@@ -149,8 +149,6 @@ export const OrgMembersTable = ({ handlePopUpOpen, setCompleteInviteLink }: Prop
[members, searchMemberFilter] [members, searchMemberFilter]
); );
console.log("filterdUser: ", filterdUser);
return ( return (
<div> <div>
<Input <Input
+11 -3
View File
@@ -16,8 +16,16 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
const [step, setStep] = useState(0); const [step, setStep] = useState(0);
const [password, setPassword] = useState(""); const [password, setPassword] = useState("");
const { username, email, organizationName, organizationSlug, firstName, lastName, authType } = const {
jwt_decode(providerAuthToken) as any; username,
email,
organizationName,
organizationSlug,
firstName,
lastName,
authType,
isEmailVerified
} = jwt_decode(providerAuthToken) as any;
const renderView = () => { const renderView = () => {
switch (step) { switch (step) {
@@ -25,7 +33,7 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
return ( return (
<UserInfoSSOStep <UserInfoSSOStep
username={username} username={username}
email={email} isEmailVerified={isEmailVerified}
name={`${firstName} ${lastName}`} name={`${firstName} ${lastName}`}
providerOrganizationName={organizationName} providerOrganizationName={organizationName}
password={password} password={password}
@@ -26,7 +26,7 @@ const client = new jsrp.client();
type Props = { type Props = {
setStep: (step: number) => void; setStep: (step: number) => void;
username: string; username: string;
email?: string; isEmailVerified?: boolean;
password: string; password: string;
setPassword: (value: string) => void; setPassword: (value: string) => void;
name: string; name: string;
@@ -60,7 +60,7 @@ type Errors = {
*/ */
export const UserInfoSSOStep = ({ export const UserInfoSSOStep = ({
username, username,
email, isEmailVerified,
name, name,
providerOrganizationName, providerOrganizationName,
password, password,
@@ -204,13 +204,13 @@ export const UserInfoSSOStep = ({
localStorage.setItem("orgData.id", orgId); localStorage.setItem("orgData.id", orgId);
localStorage.setItem("projectData.id", project.id); localStorage.setItem("projectData.id", project.id);
if (email) { if (isEmailVerified) {
// move to backup PDF step
setStep(3);
} else {
// move to verify email // move to verify email
await sendEmailVerificationCode(); await sendEmailVerificationCode();
setStep(1); setStep(1);
} else {
// move to backup PDF step
setStep(3);
} }
} catch (error) { } catch (error) {
setIsLoading(false); setIsLoading(false);