Add TRUST_SAML_EMAILS and TRUST_LDAP_EMAILS opts

This commit is contained in:
Tuan Dang
2024-04-26 22:30:07 -07:00
parent 858a35812a
commit 80da2a19aa
9 changed files with 204 additions and 159 deletions

View File

@@ -437,7 +437,7 @@ export const ldapConfigServiceFactory = ({
{ {
username: uniqueUsername, username: uniqueUsername,
email: emails[0], email: emails[0],
isEmailVerified: false, isEmailVerified: appCfg.TRUST_LDAP_EMAILS,
firstName, firstName,
lastName, lastName,
authMethods: [], authMethods: [],
@@ -557,7 +557,7 @@ export const ldapConfigServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN, authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id, userId: user.id,
username: user.username, username: user.username,
...(user.email && { email: user.email }), ...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
firstName, firstName,
lastName, lastName,
organizationName: organization.name, organizationName: organization.name,

View File

@@ -374,7 +374,7 @@ export const samlConfigServiceFactory = ({
{ {
username: uniqueUsername, username: uniqueUsername,
email, email,
isEmailVerified: false, isEmailVerified: appCfg.TRUST_SAML_EMAILS,
firstName, firstName,
lastName, lastName,
authMethods: [], authMethods: [],
@@ -414,7 +414,7 @@ export const samlConfigServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN, authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id, userId: user.id,
username: user.username, username: user.username,
...(user.email && { email: user.email }), ...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
firstName, firstName,
lastName, lastName,
organizationName: organization.name, organizationName: organization.name,

View File

@@ -98,6 +98,9 @@ const envSchema = z
CLIENT_ID_GITLAB: zpStr(z.string().optional()), CLIENT_ID_GITLAB: zpStr(z.string().optional()),
CLIENT_SECRET_GITLAB: zpStr(z.string().optional()), CLIENT_SECRET_GITLAB: zpStr(z.string().optional()),
URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)), URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)),
// email verification
TRUST_SAML_EMAILS: zodStrBool.default("false"),
TRUST_LDAP_EMAILS: zodStrBool.default("false"),
// SECRET-SCANNING // SECRET-SCANNING
SECRET_SCANNING_WEBHOOK_PROXY: zpStr(z.string().optional()), SECRET_SCANNING_WEBHOOK_PROXY: zpStr(z.string().optional()),
SECRET_SCANNING_WEBHOOK_SECRET: zpStr(z.string().optional()), SECRET_SCANNING_WEBHOOK_SECRET: zpStr(z.string().optional()),

View File

@@ -361,6 +361,7 @@ export const authLoginServiceFactory = ({
user = await userDAL.create({ user = await userDAL.create({
username: email, username: email,
email, email,
isEmailVerified: true,
firstName, firstName,
lastName, lastName,
authMethods: [authMethod], authMethods: [authMethod],
@@ -374,6 +375,8 @@ export const authLoginServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN, authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id, userId: user.id,
username: user.username, username: user.username,
email: user.email,
isEmailVerified: user.isEmailVerified,
firstName: user.firstName, firstName: user.firstName,
lastName: user.lastName, lastName: user.lastName,
authMethod, authMethod,

View File

@@ -135,11 +135,6 @@ export const authSignupServiceFactory = ({
userAgent, userAgent,
authorization authorization
}: TCompleteAccountSignupDTO) => { }: TCompleteAccountSignupDTO) => {
console.log("completeEmailAccountSignup args: ", {
email,
firstName,
lastName
});
const user = await userDAL.findOne({ username: email }); const user = await userDAL.findOne({ username: email });
if (!user || (user && user.isAccepted)) { if (!user || (user && user.isAccepted)) {
throw new Error("Failed to complete account for complete user"); throw new Error("Failed to complete account for complete user");

View File

@@ -3,26 +3,30 @@ title: "Configurations"
description: "Read how to configure environment variables for self-hosted Infisical." description: "Read how to configure environment variables for self-hosted Infisical."
--- ---
Infisical accepts all configurations via environment variables. For a minimal self-hosted instance, at least `ENCRYPTION_KEY`, `AUTH_SECRET`, `DB_CONNECTION_URI` and `REDIS_URL` must be defined. Infisical accepts all configurations via environment variables. For a minimal self-hosted instance, at least `ENCRYPTION_KEY`, `AUTH_SECRET`, `DB_CONNECTION_URI` and `REDIS_URL` must be defined.
However, you can configure additional settings to activate more features as needed. However, you can configure additional settings to activate more features as needed.
## General platform ## General platform
Used to configure platform-specific security and operational settings Used to configure platform-specific security and operational settings
<ParamField query="ENCRYPTION_KEY" type="string" default="none" required> <ParamField query="ENCRYPTION_KEY" type="string" default="none" required>
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex 16` Must be a random 16 byte hex string. Can be generated with `openssl rand -hex
16`
</ParamField> </ParamField>
<ParamField query="AUTH_SECRET" type="string" default="none" required> <ParamField query="AUTH_SECRET" type="string" default="none" required>
Must be a random 32 byte base64 string. Can be generated with `openssl rand -base64 32` Must be a random 32 byte base64 string. Can be generated with `openssl rand
-base64 32`
</ParamField> </ParamField>
<ParamField query="SITE_URL" type="string" default="none" optional> <ParamField query="SITE_URL" type="string" default="none" optional>
Must be an absolute URL including the protocol (e.g. https://app.infisical.com). Must be an absolute URL including the protocol (e.g.
https://app.infisical.com).
</ParamField> </ParamField>
## Data Layer ## Data Layer
The platform utilizes Postgres to persist all of its data and Redis for caching and backgroud tasks The platform utilizes Postgres to persist all of its data and Redis for caching and backgroud tasks
<ParamField query="DB_CONNECTION_URI" type="string" default="" required> <ParamField query="DB_CONNECTION_URI" type="string" default="" required>
@@ -39,9 +43,8 @@ The platform utilizes Postgres to persist all of its data and Redis for caching
Redis connection string. Redis connection string.
</ParamField> </ParamField>
## Email service ## Email service
Without email configuration, Infisical's core functions like sign-up/login and secret operations work, but this disables multi-factor authentication, email invites for projects, alerts for suspicious logins, and all other email-dependent features. Without email configuration, Infisical's core functions like sign-up/login and secret operations work, but this disables multi-factor authentication, email invites for projects, alerts for suspicious logins, and all other email-dependent features.
<Accordion title="Generic Configuration"> <Accordion title="Generic Configuration">
@@ -49,25 +52,36 @@ Without email configuration, Infisical's core functions like sign-up/login and s
Hostname to connect to for establishing SMTP connections Hostname to connect to for establishing SMTP connections
</ParamField> </ParamField>
<ParamField query="SMTP_USERNAME" type="string" default="none" optional> {" "}
Credential to connect to host (e.g. team@infisical.com)
</ParamField>
<ParamField query="SMTP_PASSWORD" type="string" default="none" optional> <ParamField query="SMTP_USERNAME" type="string" default="none" optional>
Credential to connect to host Credential to connect to host (e.g. team@infisical.com)
</ParamField> </ParamField>
<ParamField query="SMTP_PORT" type="string" default="587" optional> {" "}
Port to connect to for establishing SMTP connections
</ParamField>
<ParamField query="SMTP_SECURE" type="string" default="none" optional> <ParamField query="SMTP_PASSWORD" type="string" default="none" optional>
If true, use TLS when connecting to host. If false, TLS will be used if STARTTLS is supported Credential to connect to host
</ParamField> </ParamField>
<ParamField query="SMTP_FROM_ADDRESS" type="string" default="none" optional> {" "}
Email address to be used for sending emails
</ParamField> <ParamField query="SMTP_PORT" type="string" default="587" optional>
Port to connect to for establishing SMTP connections
</ParamField>
{" "}
<ParamField query="SMTP_SECURE" type="string" default="none" optional>
If true, use TLS when connecting to host. If false, TLS will be used if
STARTTLS is supported
</ParamField>
{" "}
<ParamField query="SMTP_FROM_ADDRESS" type="string" default="none" optional>
Email address to be used for sending emails
</ParamField>
<ParamField query="SMTP_FROM_NAME" type="string" default="none" optional> <ParamField query="SMTP_FROM_NAME" type="string" default="none" optional>
Name label to be used in From field (e.g. Team) Name label to be used in From field (e.g. Team)
@@ -76,25 +90,25 @@ Without email configuration, Infisical's core functions like sign-up/login and s
<Accordion title="Twilio SendGrid"> <Accordion title="Twilio SendGrid">
1. Create an account and configure [SendGrid](https://sendgrid.com) to send emails. 1. Create an account and configure [SendGrid](https://sendgrid.com) to send emails.
2. Create a SendGrid API Key under Settings > [API Keys](https://app.sendgrid.com/settings/api_keys) 2. Create a SendGrid API Key under Settings > [API Keys](https://app.sendgrid.com/settings/api_keys)
3. Set a name for your API Key, we recommend using "Infisical," and select the "Restricted Key" option. You will need to enable the "Mail Send" permission as shown below: 3. Set a name for your API Key, we recommend using "Infisical," and select the "Restricted Key" option. You will need to enable the "Mail Send" permission as shown below:
![creating sendgrid api key](../../images/self-hosting/configuration/email/email-sendgrid-create-key.png) ![creating sendgrid api key](../../images/self-hosting/configuration/email/email-sendgrid-create-key.png)
![setting sendgrid api key restriction](../../images/self-hosting/configuration/email/email-sendgrid-restrictions.png) ![setting sendgrid api key restriction](../../images/self-hosting/configuration/email/email-sendgrid-restrictions.png)
4. With the API Key, you can now set your SMTP environment variables: 4. With the API Key, you can now set your SMTP environment variables:
``` ```
SMTP_HOST=smtp.sendgrid.net SMTP_HOST=smtp.sendgrid.net
SMTP_USERNAME=apikey SMTP_USERNAME=apikey
SMTP_PASSWORD=SG.rqFsfjxYPiqE1lqZTgD_lz7x8IVLx # your SendGrid API Key from step above SMTP_PASSWORD=SG.rqFsfjxYPiqE1lqZTgD_lz7x8IVLx # your SendGrid API Key from step above
SMTP_PORT=587 SMTP_PORT=587
SMTP_SECURE=true SMTP_SECURE=true
SMTP_FROM_ADDRESS=hey@example.com # your email address being used to send out emails SMTP_FROM_ADDRESS=hey@example.com # your email address being used to send out emails
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
<Info> <Info>
Remember that you will need to restart Infisical for this to work properly. Remember that you will need to restart Infisical for this to work properly.
@@ -105,19 +119,20 @@ Without email configuration, Infisical's core functions like sign-up/login and s
1. Create an account and configure [Mailgun](https://www.mailgun.com) to send emails. 1. Create an account and configure [Mailgun](https://www.mailgun.com) to send emails.
2. Obtain your Mailgun credentials in Sending > Overview > SMTP 2. Obtain your Mailgun credentials in Sending > Overview > SMTP
![obtain mailhog api key estriction](../../images/self-hosting/configuration/email/email-mailhog-credentials.png) ![obtain mailhog api key estriction](../../images/self-hosting/configuration/email/email-mailhog-credentials.png)
3. With your Mailgun credentials, you can now set up your SMTP environment variables: 3. With your Mailgun credentials, you can now set up your SMTP environment variables:
```
SMTP_HOST=smtp.mailgun.org # obtained from credentials page
SMTP_USERNAME=postmaster@example.mailgun.org # obtained from credentials page
SMTP_PASSWORD=password # obtained from credentials page
SMTP_PORT=587
SMTP_SECURE=true
SMTP_FROM_ADDRESS=hey@example.com # your email address being used to send out emails
SMTP_FROM_NAME=Infisical
```
```
SMTP_HOST=smtp.mailgun.org # obtained from credentials page
SMTP_USERNAME=postmaster@example.mailgun.org # obtained from credentials page
SMTP_PASSWORD=password # obtained from credentials page
SMTP_PORT=587
SMTP_SECURE=true
SMTP_FROM_ADDRESS=hey@example.com # your email address being used to send out emails
SMTP_FROM_NAME=Infisical
```
</Accordion> </Accordion>
<Accordion title="AWS SES"> <Accordion title="AWS SES">
@@ -149,6 +164,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
</Step> </Step>
</Steps> </Steps>
<Info> <Info>
@@ -160,30 +176,32 @@ Without email configuration, Infisical's core functions like sign-up/login and s
1. Create an account and configure [SocketLabs](https://www.socketlabs.com/) to send emails. 1. Create an account and configure [SocketLabs](https://www.socketlabs.com/) to send emails.
2. From the dashboard, navigate to SMTP Credentials > SMTP & APIs > SMTP Credentials to obtain your SocketLabs SMTP credentials. 2. From the dashboard, navigate to SMTP Credentials > SMTP & APIs > SMTP Credentials to obtain your SocketLabs SMTP credentials.
![opening SocketLabs dashboard](../../images/self-hosting/configuration/email/email-socketlabs-dashboard.png) ![opening SocketLabs dashboard](../../images/self-hosting/configuration/email/email-socketlabs-dashboard.png)
![obtaining SocketLabs credentials](../../images/self-hosting/configuration/email/email-socketlabs-credentials.png) ![obtaining SocketLabs credentials](../../images/self-hosting/configuration/email/email-socketlabs-credentials.png)
3. With your SocketLabs SMTP credentials, you can now set up your SMTP environment variables: 3. With your SocketLabs SMTP credentials, you can now set up your SMTP environment variables:
``` ```
SMTP_HOST=smtp.socketlabs.com SMTP_HOST=smtp.socketlabs.com
SMTP_USERNAME=username # obtained from your credentials SMTP_USERNAME=username # obtained from your credentials
SMTP_PASSWORD=password # obtained from your credentials SMTP_PASSWORD=password # obtained from your credentials
SMTP_PORT=587 SMTP_PORT=587
SMTP_SECURE=true SMTP_SECURE=true
SMTP_FROM_ADDRESS=hey@example.com # your email address being used to send out emails SMTP_FROM_ADDRESS=hey@example.com # your email address being used to send out emails
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
<Note> {" "}
The `SMTP_FROM_ADDRESS` environment variable should be an email for an
authenticated domain under Configuration > Domain Management in SocketLabs.
For example, if you're using SocketLabs in sandbox mode, then you may use an
email like `team@sandbox.socketlabs.dev`.
</Note>
![SocketLabs domain management](../../images/self-hosting/configuration/email/email-socketlabs-domains.png) <Note>
The `SMTP_FROM_ADDRESS` environment variable should be an email for an
authenticated domain under Configuration > Domain Management in SocketLabs.
For example, if you're using SocketLabs in sandbox mode, then you may use an
email like `team@sandbox.socketlabs.dev`.
</Note>
![SocketLabs domain management](../../images/self-hosting/configuration/email/email-socketlabs-domains.png)
<Info> <Info>
Remember that you will need to restart Infisical for this to work properly. Remember that you will need to restart Infisical for this to work properly.
@@ -194,55 +212,57 @@ Without email configuration, Infisical's core functions like sign-up/login and s
1. Create an account on [Resend](https://resend.com). 1. Create an account on [Resend](https://resend.com).
2. Add a [Domain](https://resend.com/domains). 2. Add a [Domain](https://resend.com/domains).
![adding resend domain](../../images/self-hosting/configuration/email/email-resend-create-domain.png) ![adding resend domain](../../images/self-hosting/configuration/email/email-resend-create-domain.png)
3. Create an [API Key](https://resend.com/api-keys). 3. Create an [API Key](https://resend.com/api-keys).
![creating resend api key](../../images/self-hosting/configuration/email/email-resend-create-key.png) ![creating resend api key](../../images/self-hosting/configuration/email/email-resend-create-key.png)
4. Go to the [SMTP page](https://resend.com/settings/smtp) and copy the values. 4. Go to the [SMTP page](https://resend.com/settings/smtp) and copy the values.
![go to resend smtp settings](../../images/self-hosting/configuration/email/email-resend-smtp-settings.png) ![go to resend smtp settings](../../images/self-hosting/configuration/email/email-resend-smtp-settings.png)
5. With the API Key, you can now set your SMTP environment variables variables: 5. With the API Key, you can now set your SMTP environment variables variables:
```
SMTP_HOST=smtp.resend.com
SMTP_USERNAME=resend
SMTP_PASSWORD=YOUR_API_KEY
SMTP_PORT=587
SMTP_SECURE=true
SMTP_FROM_ADDRESS=hey@example.com # your email address being used to send out emails
SMTP_FROM_NAME=Infisical
```
```
SMTP_HOST=smtp.resend.com
SMTP_USERNAME=resend
SMTP_PASSWORD=YOUR_API_KEY
SMTP_PORT=587
SMTP_SECURE=true
SMTP_FROM_ADDRESS=hey@example.com # your email address being used to send out emails
SMTP_FROM_NAME=Infisical
```
<Info> <Info>
Remember that you will need to restart Infisical for this to work properly. Remember that you will need to restart Infisical for this to work properly.
</Info> </Info>
</Accordion> </Accordion>
<Accordion title="Gmail"> <Accordion title="Gmail">
Create an account and enable "less secure app access" in Gmail Account Settings > Security. This will allow Create an account and enable "less secure app access" in Gmail Account Settings > Security. This will allow
applications like Infisical to authenticate with Gmail via your username and password. applications like Infisical to authenticate with Gmail via your username and password.
![Gmail secure app access](../../images/self-hosting/configuration/email/email-gmail-app-access.png) ![Gmail secure app access](../../images/self-hosting/configuration/email/email-gmail-app-access.png)
With your Gmail username and password, you can set your SMTP environment variables: With your Gmail username and password, you can set your SMTP environment variables:
``` ```
SMTP_HOST=smtp.gmail.com SMTP_HOST=smtp.gmail.com
SMTP_USERNAME=hey@gmail.com # your email SMTP_USERNAME=hey@gmail.com # your email
SMTP_PASSWORD=password # your password SMTP_PASSWORD=password # your password
SMTP_PORT=587 SMTP_PORT=587
SMTP_SECURE=true SMTP_SECURE=true
SMTP_FROM_ADDRESS=hey@gmail.com SMTP_FROM_ADDRESS=hey@gmail.com
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
<Warning> <Warning>
As per the [notice](https://support.google.com/accounts/answer/6010255?hl=en) by Google, you should note that using Gmail credentials for SMTP configuration As per the [notice](https://support.google.com/accounts/answer/6010255?hl=en) by Google, you should note that using Gmail credentials for SMTP configuration
will only work for Google Workspace or Google Cloud Identity customers as of May 30, 2022. will only work for Google Workspace or Google Cloud Identity customers as of May 30, 2022.
Put differently, the SMTP configuration is only possible with business (not personal) Gmail credentials. Put differently, the SMTP configuration is only possible with business (not personal) Gmail credentials.
</Warning> </Warning>
</Accordion> </Accordion>
@@ -250,51 +270,51 @@ Without email configuration, Infisical's core functions like sign-up/login and s
<Accordion title="Office365"> <Accordion title="Office365">
1. Create an account and configure [Office365](https://www.office.com/) to send emails. 1. Create an account and configure [Office365](https://www.office.com/) to send emails.
2. With your login credentials, you can now set up your SMTP environment variables: 2. With your login credentials, you can now set up your SMTP environment variables:
```
SMTP_HOST=smtp.office365.com
SMTP_USERNAME=username@yourdomain.com # your username
SMTP_PASSWORD=password # your password
SMTP_PORT=587
SMTP_SECURE=true
SMTP_FROM_ADDRESS=username@yourdomain.com
SMTP_FROM_NAME=Infisical
```
```
SMTP_HOST=smtp.office365.com
SMTP_USERNAME=username@yourdomain.com # your username
SMTP_PASSWORD=password # your password
SMTP_PORT=587
SMTP_SECURE=true
SMTP_FROM_ADDRESS=username@yourdomain.com
SMTP_FROM_NAME=Infisical
```
</Accordion> </Accordion>
<Accordion title="Zoho Mail"> <Accordion title="Zoho Mail">
1. Create an account and configure [Zoho Mail](https://www.zoho.com/mail/) to send emails. 1. Create an account and configure [Zoho Mail](https://www.zoho.com/mail/) to send emails.
2. With your email credentials, you can now set up your SMTP environment variables: 2. With your email credentials, you can now set up your SMTP environment variables:
``` ```
SMTP_HOST=smtp.zoho.com SMTP_HOST=smtp.zoho.com
SMTP_USERNAME=username # your email SMTP_USERNAME=username # your email
SMTP_PASSWORD=password # your password SMTP_PASSWORD=password # your password
SMTP_PORT=587 SMTP_PORT=587
SMTP_SECURE=true SMTP_SECURE=true
SMTP_FROM_ADDRESS=hey@example.com # your personal Zoho email or domain-based email linked to Zoho Mail SMTP_FROM_ADDRESS=hey@example.com # your personal Zoho email or domain-based email linked to Zoho Mail
SMTP_FROM_NAME=Infisical SMTP_FROM_NAME=Infisical
``` ```
<Note> {" "}
You can use either your personal Zoho email address like `you@zohomail.com` or
a domain-based email address like `you@yourdomain.com`. If using a <Note>
domain-based email address, then please make sure that you've configured and You can use either your personal Zoho email address like `you@zohomail.com` or
verified it with Zoho Mail. a domain-based email address like `you@yourdomain.com`. If using a
</Note> domain-based email address, then please make sure that you've configured and
verified it with Zoho Mail.
</Note>
<Info> <Info>
Remember that you will need to restart Infisical for this to work properly. Remember that you will need to restart Infisical for this to work properly.
</Info> </Info>
</Accordion> </Accordion>
## Authentication
## SSO based login
By default, users can only login via email/password based login method. By default, users can only login via email/password based login method.
To login into Infisical with OAuth providers such as Google, configure the associated variables. To login into Infisical with OAuth providers such as Google, configure the associated variables.
@@ -335,33 +355,49 @@ To login into Infisical with OAuth providers such as Google, configure the assoc
</Accordion> </Accordion>
<Accordion title="Okta SAML"> <Accordion title="Okta SAML">
Requires enterprise license. Please contact team@infisical.com to get more information. Requires enterprise license. Please contact team@infisical.com to get more
information.
</Accordion> </Accordion>
<Accordion title="Azure SAML"> <Accordion title="Azure SAML">
Requires enterprise license. Please contact team@infisical.com to get more information. Requires enterprise license. Please contact team@infisical.com to get more
information.
</Accordion> </Accordion>
<Accordion title="JumpCloud SAML"> <Accordion title="JumpCloud SAML">
Requires enterprise license. Please contact team@infisical.com to get more information. Requires enterprise license. Please contact team@infisical.com to get more
information.
</Accordion> </Accordion>
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string"> <ParamField query="TRUST_SAML_EMAILS" type="boolean" default="false" optional>
Configure SAML organization slug to automatically redirect all users of your Infisical instance to the identity provider. Whether or not to trust emails from external SAML identity providers. If set
to `false` then users will be prompted to verify their email address upon
first login.
</ParamField>
<ParamField query="TRUST_LDAP_EMAILS" type="string" default="false" optional>
Whether or not to trust emails from external LDAP servers. If set to `false`
then users will be prompted to verify their email address upon first login.
</ParamField> </ParamField>
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string">
Configure SAML organization slug to automatically redirect all users of your
Infisical instance to the identity provider.
</ParamField>
## Native secret integrations ## Native secret integrations
To help you sync secrets from Infisical to services such as Github and Gitlab, Infisical provides native integrations out of the box. To help you sync secrets from Infisical to services such as Github and Gitlab, Infisical provides native integrations out of the box.
<Accordion title="Heroku"> <Accordion title="Heroku">
<ParamField query="CLIENT_ID_HEROKU" type="string" default="none" optional> <ParamField query="CLIENT_ID_HEROKU" type="string" default="none" optional>
OAuth2 client ID for Heroku integration OAuth2 client ID for Heroku integration
</ParamField> </ParamField>
<ParamField query="CLIENT_SECRET_HEROKU" type="string" default="none" optional> <ParamField
query="CLIENT_SECRET_HEROKU"
type="string"
default="none"
optional
>
OAuth2 client secret for Heroku integration OAuth2 client secret for Heroku integration
</ParamField> </ParamField>
</Accordion> </Accordion>
@@ -371,9 +407,11 @@ To help you sync secrets from Infisical to services such as Github and Gitlab, I
OAuth2 client ID for Vercel integration OAuth2 client ID for Vercel integration
</ParamField> </ParamField>
<ParamField query="CLIENT_SECRET_VERCEL" type="string" default="none" optional> {" "}
OAuth2 client secret for Vercel integration
</ParamField> <ParamField query="CLIENT_SECRET_VERCEL" type="string" default="none" optional>
OAuth2 client secret for Vercel integration
</ParamField>
<ParamField query="CLIENT_SLUG_VERCEL" type="string" default="none" optional> <ParamField query="CLIENT_SLUG_VERCEL" type="string" default="none" optional>
OAuth2 slug for Vercel integration OAuth2 slug for Vercel integration

View File

@@ -149,8 +149,6 @@ export const OrgMembersTable = ({ handlePopUpOpen, setCompleteInviteLink }: Prop
[members, searchMemberFilter] [members, searchMemberFilter]
); );
console.log("filterdUser: ", filterdUser);
return ( return (
<div> <div>
<Input <Input

View File

@@ -16,8 +16,16 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
const [step, setStep] = useState(0); const [step, setStep] = useState(0);
const [password, setPassword] = useState(""); const [password, setPassword] = useState("");
const { username, email, organizationName, organizationSlug, firstName, lastName, authType } = const {
jwt_decode(providerAuthToken) as any; username,
email,
organizationName,
organizationSlug,
firstName,
lastName,
authType,
isEmailVerified
} = jwt_decode(providerAuthToken) as any;
const renderView = () => { const renderView = () => {
switch (step) { switch (step) {
@@ -25,7 +33,7 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
return ( return (
<UserInfoSSOStep <UserInfoSSOStep
username={username} username={username}
email={email} isEmailVerified={isEmailVerified}
name={`${firstName} ${lastName}`} name={`${firstName} ${lastName}`}
providerOrganizationName={organizationName} providerOrganizationName={organizationName}
password={password} password={password}

View File

@@ -26,7 +26,7 @@ const client = new jsrp.client();
type Props = { type Props = {
setStep: (step: number) => void; setStep: (step: number) => void;
username: string; username: string;
email?: string; isEmailVerified?: boolean;
password: string; password: string;
setPassword: (value: string) => void; setPassword: (value: string) => void;
name: string; name: string;
@@ -60,7 +60,7 @@ type Errors = {
*/ */
export const UserInfoSSOStep = ({ export const UserInfoSSOStep = ({
username, username,
email, isEmailVerified,
name, name,
providerOrganizationName, providerOrganizationName,
password, password,
@@ -204,13 +204,13 @@ export const UserInfoSSOStep = ({
localStorage.setItem("orgData.id", orgId); localStorage.setItem("orgData.id", orgId);
localStorage.setItem("projectData.id", project.id); localStorage.setItem("projectData.id", project.id);
if (email) { if (isEmailVerified) {
// move to backup PDF step
setStep(3);
} else {
// move to verify email // move to verify email
await sendEmailVerificationCode(); await sendEmailVerificationCode();
setStep(1); setStep(1);
} else {
// move to backup PDF step
setStep(3);
} }
} catch (error) { } catch (error) {
setIsLoading(false); setIsLoading(false);