Add TRUST_SAML_EMAILS and TRUST_LDAP_EMAILS opts

This commit is contained in:
Tuan Dang
2024-04-26 22:30:07 -07:00
parent 858a35812a
commit 80da2a19aa
9 changed files with 204 additions and 159 deletions
@@ -437,7 +437,7 @@ export const ldapConfigServiceFactory = ({
{
username: uniqueUsername,
email: emails[0],
isEmailVerified: false,
isEmailVerified: appCfg.TRUST_LDAP_EMAILS,
firstName,
lastName,
authMethods: [],
@@ -557,7 +557,7 @@ export const ldapConfigServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id,
username: user.username,
...(user.email && { email: user.email }),
...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
firstName,
lastName,
organizationName: organization.name,
@@ -374,7 +374,7 @@ export const samlConfigServiceFactory = ({
{
username: uniqueUsername,
email,
isEmailVerified: false,
isEmailVerified: appCfg.TRUST_SAML_EMAILS,
firstName,
lastName,
authMethods: [],
@@ -414,7 +414,7 @@ export const samlConfigServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id,
username: user.username,
...(user.email && { email: user.email }),
...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
firstName,
lastName,
organizationName: organization.name,
+3
View File
@@ -98,6 +98,9 @@ const envSchema = z
CLIENT_ID_GITLAB: zpStr(z.string().optional()),
CLIENT_SECRET_GITLAB: zpStr(z.string().optional()),
URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)),
// email verification
TRUST_SAML_EMAILS: zodStrBool.default("false"),
TRUST_LDAP_EMAILS: zodStrBool.default("false"),
// SECRET-SCANNING
SECRET_SCANNING_WEBHOOK_PROXY: zpStr(z.string().optional()),
SECRET_SCANNING_WEBHOOK_SECRET: zpStr(z.string().optional()),
@@ -361,6 +361,7 @@ export const authLoginServiceFactory = ({
user = await userDAL.create({
username: email,
email,
isEmailVerified: true,
firstName,
lastName,
authMethods: [authMethod],
@@ -374,6 +375,8 @@ export const authLoginServiceFactory = ({
authTokenType: AuthTokenType.PROVIDER_TOKEN,
userId: user.id,
username: user.username,
email: user.email,
isEmailVerified: user.isEmailVerified,
firstName: user.firstName,
lastName: user.lastName,
authMethod,
@@ -135,11 +135,6 @@ export const authSignupServiceFactory = ({
userAgent,
authorization
}: TCompleteAccountSignupDTO) => {
console.log("completeEmailAccountSignup args: ", {
email,
firstName,
lastName
});
const user = await userDAL.findOne({ username: email });
if (!user || (user && user.isAccepted)) {
throw new Error("Failed to complete account for complete user");
+58 -20
View File
@@ -3,26 +3,30 @@ title: "Configurations"
description: "Read how to configure environment variables for self-hosted Infisical."
---
Infisical accepts all configurations via environment variables. For a minimal self-hosted instance, at least `ENCRYPTION_KEY`, `AUTH_SECRET`, `DB_CONNECTION_URI` and `REDIS_URL` must be defined.
However, you can configure additional settings to activate more features as needed.
## General platform
Used to configure platform-specific security and operational settings
<ParamField query="ENCRYPTION_KEY" type="string" default="none" required>
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex 16`
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex
16`
</ParamField>
<ParamField query="AUTH_SECRET" type="string" default="none" required>
Must be a random 32 byte base64 string. Can be generated with `openssl rand -base64 32`
Must be a random 32 byte base64 string. Can be generated with `openssl rand
-base64 32`
</ParamField>
<ParamField query="SITE_URL" type="string" default="none" optional>
Must be an absolute URL including the protocol (e.g. https://app.infisical.com).
Must be an absolute URL including the protocol (e.g.
https://app.infisical.com).
</ParamField>
## Data Layer
The platform utilizes Postgres to persist all of its data and Redis for caching and backgroud tasks
<ParamField query="DB_CONNECTION_URI" type="string" default="" required>
@@ -39,9 +43,8 @@ The platform utilizes Postgres to persist all of its data and Redis for caching
Redis connection string.
</ParamField>
## Email service
Without email configuration, Infisical's core functions like sign-up/login and secret operations work, but this disables multi-factor authentication, email invites for projects, alerts for suspicious logins, and all other email-dependent features.
<Accordion title="Generic Configuration">
@@ -49,22 +52,33 @@ Without email configuration, Infisical's core functions like sign-up/login and s
Hostname to connect to for establishing SMTP connections
</ParamField>
{" "}
<ParamField query="SMTP_USERNAME" type="string" default="none" optional>
Credential to connect to host (e.g. [email protected])
</ParamField>
{" "}
<ParamField query="SMTP_PASSWORD" type="string" default="none" optional>
Credential to connect to host
</ParamField>
{" "}
<ParamField query="SMTP_PORT" type="string" default="587" optional>
Port to connect to for establishing SMTP connections
</ParamField>
{" "}
<ParamField query="SMTP_SECURE" type="string" default="none" optional>
If true, use TLS when connecting to host. If false, TLS will be used if STARTTLS is supported
If true, use TLS when connecting to host. If false, TLS will be used if
STARTTLS is supported
</ParamField>
{" "}
<ParamField query="SMTP_FROM_ADDRESS" type="string" default="none" optional>
Email address to be used for sending emails
</ParamField>
@@ -118,6 +132,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
[email protected] # your email address being used to send out emails
SMTP_FROM_NAME=Infisical
```
</Accordion>
<Accordion title="AWS SES">
@@ -149,6 +164,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
SMTP_FROM_NAME=Infisical
```
</Step>
</Steps>
<Info>
@@ -176,6 +192,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
SMTP_FROM_NAME=Infisical
```
{" "}
<Note>
The `SMTP_FROM_ADDRESS` environment variable should be an email for an
authenticated domain under Configuration > Domain Management in SocketLabs.
@@ -215,9 +233,11 @@ Without email configuration, Infisical's core functions like sign-up/login and s
[email protected] # your email address being used to send out emails
SMTP_FROM_NAME=Infisical
```
<Info>
Remember that you will need to restart Infisical for this to work properly.
</Info>
</Accordion>
<Accordion title="Gmail">
@@ -261,6 +281,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
[email protected]
SMTP_FROM_NAME=Infisical
```
</Accordion>
<Accordion title="Zoho Mail">
@@ -278,6 +299,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
SMTP_FROM_NAME=Infisical
```
{" "}
<Note>
You can use either your personal Zoho email address like `[email protected]` or
a domain-based email address like `[email protected]`. If using a
@@ -290,11 +313,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
</Info>
</Accordion>
## Authentication
## SSO based login
By default, users can only login via email/password based login method.
To login into Infisical with OAuth providers such as Google, configure the associated variables.
@@ -335,33 +355,49 @@ To login into Infisical with OAuth providers such as Google, configure the assoc
</Accordion>
<Accordion title="Okta SAML">
Requires enterprise license. Please contact [email protected] to get more information.
Requires enterprise license. Please contact [email protected] to get more
information.
</Accordion>
<Accordion title="Azure SAML">
Requires enterprise license. Please contact [email protected] to get more information.
Requires enterprise license. Please contact [email protected] to get more
information.
</Accordion>
<Accordion title="JumpCloud SAML">
Requires enterprise license. Please contact [email protected] to get more information.
Requires enterprise license. Please contact [email protected] to get more
information.
</Accordion>
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string">
Configure SAML organization slug to automatically redirect all users of your Infisical instance to the identity provider.
<ParamField query="TRUST_SAML_EMAILS" type="boolean" default="false" optional>
Whether or not to trust emails from external SAML identity providers. If set
to `false` then users will be prompted to verify their email address upon
first login.
</ParamField>
<ParamField query="TRUST_LDAP_EMAILS" type="string" default="false" optional>
Whether or not to trust emails from external LDAP servers. If set to `false`
then users will be prompted to verify their email address upon first login.
</ParamField>
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string">
Configure SAML organization slug to automatically redirect all users of your
Infisical instance to the identity provider.
</ParamField>
## Native secret integrations
To help you sync secrets from Infisical to services such as Github and Gitlab, Infisical provides native integrations out of the box.
<Accordion title="Heroku">
<ParamField query="CLIENT_ID_HEROKU" type="string" default="none" optional>
OAuth2 client ID for Heroku integration
</ParamField>
<ParamField query="CLIENT_SECRET_HEROKU" type="string" default="none" optional>
<ParamField
query="CLIENT_SECRET_HEROKU"
type="string"
default="none"
optional
>
OAuth2 client secret for Heroku integration
</ParamField>
</Accordion>
@@ -371,6 +407,8 @@ To help you sync secrets from Infisical to services such as Github and Gitlab, I
OAuth2 client ID for Vercel integration
</ParamField>
{" "}
<ParamField query="CLIENT_SECRET_VERCEL" type="string" default="none" optional>
OAuth2 client secret for Vercel integration
</ParamField>
@@ -149,8 +149,6 @@ export const OrgMembersTable = ({ handlePopUpOpen, setCompleteInviteLink }: Prop
[members, searchMemberFilter]
);
console.log("filterdUser: ", filterdUser);
return (
<div>
<Input
+11 -3
View File
@@ -16,8 +16,16 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
const [step, setStep] = useState(0);
const [password, setPassword] = useState("");
const { username, email, organizationName, organizationSlug, firstName, lastName, authType } =
jwt_decode(providerAuthToken) as any;
const {
username,
email,
organizationName,
organizationSlug,
firstName,
lastName,
authType,
isEmailVerified
} = jwt_decode(providerAuthToken) as any;
const renderView = () => {
switch (step) {
@@ -25,7 +33,7 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
return (
<UserInfoSSOStep
username={username}
email={email}
isEmailVerified={isEmailVerified}
name={`${firstName} ${lastName}`}
providerOrganizationName={organizationName}
password={password}
@@ -26,7 +26,7 @@ const client = new jsrp.client();
type Props = {
setStep: (step: number) => void;
username: string;
email?: string;
isEmailVerified?: boolean;
password: string;
setPassword: (value: string) => void;
name: string;
@@ -60,7 +60,7 @@ type Errors = {
*/
export const UserInfoSSOStep = ({
username,
email,
isEmailVerified,
name,
providerOrganizationName,
password,
@@ -204,13 +204,13 @@ export const UserInfoSSOStep = ({
localStorage.setItem("orgData.id", orgId);
localStorage.setItem("projectData.id", project.id);
if (email) {
if (isEmailVerified) {
// move to backup PDF step
setStep(3);
} else {
// move to verify email
await sendEmailVerificationCode();
setStep(1);
} else {
// move to backup PDF step
setStep(3);
}
} catch (error) {
setIsLoading(false);