mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 03:28:15 +00:00
Add TRUST_SAML_EMAILS and TRUST_LDAP_EMAILS opts
This commit is contained in:
@@ -437,7 +437,7 @@ export const ldapConfigServiceFactory = ({
|
||||
{
|
||||
username: uniqueUsername,
|
||||
email: emails[0],
|
||||
isEmailVerified: false,
|
||||
isEmailVerified: appCfg.TRUST_LDAP_EMAILS,
|
||||
firstName,
|
||||
lastName,
|
||||
authMethods: [],
|
||||
@@ -557,7 +557,7 @@ export const ldapConfigServiceFactory = ({
|
||||
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
||||
userId: user.id,
|
||||
username: user.username,
|
||||
...(user.email && { email: user.email }),
|
||||
...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
|
||||
firstName,
|
||||
lastName,
|
||||
organizationName: organization.name,
|
||||
|
||||
@@ -374,7 +374,7 @@ export const samlConfigServiceFactory = ({
|
||||
{
|
||||
username: uniqueUsername,
|
||||
email,
|
||||
isEmailVerified: false,
|
||||
isEmailVerified: appCfg.TRUST_SAML_EMAILS,
|
||||
firstName,
|
||||
lastName,
|
||||
authMethods: [],
|
||||
@@ -414,7 +414,7 @@ export const samlConfigServiceFactory = ({
|
||||
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
||||
userId: user.id,
|
||||
username: user.username,
|
||||
...(user.email && { email: user.email }),
|
||||
...(user.email && { email: user.email, isEmailVerified: user.isEmailVerified }),
|
||||
firstName,
|
||||
lastName,
|
||||
organizationName: organization.name,
|
||||
|
||||
@@ -98,6 +98,9 @@ const envSchema = z
|
||||
CLIENT_ID_GITLAB: zpStr(z.string().optional()),
|
||||
CLIENT_SECRET_GITLAB: zpStr(z.string().optional()),
|
||||
URL_GITLAB_URL: zpStr(z.string().optional().default(GITLAB_URL)),
|
||||
// email verification
|
||||
TRUST_SAML_EMAILS: zodStrBool.default("false"),
|
||||
TRUST_LDAP_EMAILS: zodStrBool.default("false"),
|
||||
// SECRET-SCANNING
|
||||
SECRET_SCANNING_WEBHOOK_PROXY: zpStr(z.string().optional()),
|
||||
SECRET_SCANNING_WEBHOOK_SECRET: zpStr(z.string().optional()),
|
||||
|
||||
@@ -361,6 +361,7 @@ export const authLoginServiceFactory = ({
|
||||
user = await userDAL.create({
|
||||
username: email,
|
||||
email,
|
||||
isEmailVerified: true,
|
||||
firstName,
|
||||
lastName,
|
||||
authMethods: [authMethod],
|
||||
@@ -374,6 +375,8 @@ export const authLoginServiceFactory = ({
|
||||
authTokenType: AuthTokenType.PROVIDER_TOKEN,
|
||||
userId: user.id,
|
||||
username: user.username,
|
||||
email: user.email,
|
||||
isEmailVerified: user.isEmailVerified,
|
||||
firstName: user.firstName,
|
||||
lastName: user.lastName,
|
||||
authMethod,
|
||||
|
||||
@@ -135,11 +135,6 @@ export const authSignupServiceFactory = ({
|
||||
userAgent,
|
||||
authorization
|
||||
}: TCompleteAccountSignupDTO) => {
|
||||
console.log("completeEmailAccountSignup args: ", {
|
||||
email,
|
||||
firstName,
|
||||
lastName
|
||||
});
|
||||
const user = await userDAL.findOne({ username: email });
|
||||
if (!user || (user && user.isAccepted)) {
|
||||
throw new Error("Failed to complete account for complete user");
|
||||
|
||||
@@ -3,26 +3,30 @@ title: "Configurations"
|
||||
description: "Read how to configure environment variables for self-hosted Infisical."
|
||||
---
|
||||
|
||||
|
||||
Infisical accepts all configurations via environment variables. For a minimal self-hosted instance, at least `ENCRYPTION_KEY`, `AUTH_SECRET`, `DB_CONNECTION_URI` and `REDIS_URL` must be defined.
|
||||
However, you can configure additional settings to activate more features as needed.
|
||||
|
||||
## General platform
|
||||
|
||||
Used to configure platform-specific security and operational settings
|
||||
|
||||
<ParamField query="ENCRYPTION_KEY" type="string" default="none" required>
|
||||
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex 16`
|
||||
Must be a random 16 byte hex string. Can be generated with `openssl rand -hex
|
||||
16`
|
||||
</ParamField>
|
||||
|
||||
<ParamField query="AUTH_SECRET" type="string" default="none" required>
|
||||
Must be a random 32 byte base64 string. Can be generated with `openssl rand -base64 32`
|
||||
Must be a random 32 byte base64 string. Can be generated with `openssl rand
|
||||
-base64 32`
|
||||
</ParamField>
|
||||
|
||||
<ParamField query="SITE_URL" type="string" default="none" optional>
|
||||
Must be an absolute URL including the protocol (e.g. https://app.infisical.com).
|
||||
Must be an absolute URL including the protocol (e.g.
|
||||
https://app.infisical.com).
|
||||
</ParamField>
|
||||
|
||||
## Data Layer
|
||||
|
||||
The platform utilizes Postgres to persist all of its data and Redis for caching and backgroud tasks
|
||||
|
||||
<ParamField query="DB_CONNECTION_URI" type="string" default="" required>
|
||||
@@ -39,9 +43,8 @@ The platform utilizes Postgres to persist all of its data and Redis for caching
|
||||
Redis connection string.
|
||||
</ParamField>
|
||||
|
||||
|
||||
|
||||
## Email service
|
||||
|
||||
Without email configuration, Infisical's core functions like sign-up/login and secret operations work, but this disables multi-factor authentication, email invites for projects, alerts for suspicious logins, and all other email-dependent features.
|
||||
|
||||
<Accordion title="Generic Configuration">
|
||||
@@ -49,22 +52,33 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
||||
Hostname to connect to for establishing SMTP connections
|
||||
</ParamField>
|
||||
|
||||
{" "}
|
||||
|
||||
<ParamField query="SMTP_USERNAME" type="string" default="none" optional>
|
||||
Credential to connect to host (e.g. [email protected])
|
||||
</ParamField>
|
||||
|
||||
{" "}
|
||||
|
||||
<ParamField query="SMTP_PASSWORD" type="string" default="none" optional>
|
||||
Credential to connect to host
|
||||
</ParamField>
|
||||
|
||||
{" "}
|
||||
|
||||
<ParamField query="SMTP_PORT" type="string" default="587" optional>
|
||||
Port to connect to for establishing SMTP connections
|
||||
</ParamField>
|
||||
|
||||
{" "}
|
||||
|
||||
<ParamField query="SMTP_SECURE" type="string" default="none" optional>
|
||||
If true, use TLS when connecting to host. If false, TLS will be used if STARTTLS is supported
|
||||
If true, use TLS when connecting to host. If false, TLS will be used if
|
||||
STARTTLS is supported
|
||||
</ParamField>
|
||||
|
||||
{" "}
|
||||
|
||||
<ParamField query="SMTP_FROM_ADDRESS" type="string" default="none" optional>
|
||||
Email address to be used for sending emails
|
||||
</ParamField>
|
||||
@@ -118,6 +132,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
||||
[email protected] # your email address being used to send out emails
|
||||
SMTP_FROM_NAME=Infisical
|
||||
```
|
||||
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="AWS SES">
|
||||
@@ -149,6 +164,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
||||
SMTP_FROM_NAME=Infisical
|
||||
```
|
||||
</Step>
|
||||
|
||||
</Steps>
|
||||
|
||||
<Info>
|
||||
@@ -176,6 +192,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
||||
SMTP_FROM_NAME=Infisical
|
||||
```
|
||||
|
||||
{" "}
|
||||
|
||||
<Note>
|
||||
The `SMTP_FROM_ADDRESS` environment variable should be an email for an
|
||||
authenticated domain under Configuration > Domain Management in SocketLabs.
|
||||
@@ -215,9 +233,11 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
||||
[email protected] # your email address being used to send out emails
|
||||
SMTP_FROM_NAME=Infisical
|
||||
```
|
||||
|
||||
<Info>
|
||||
Remember that you will need to restart Infisical for this to work properly.
|
||||
</Info>
|
||||
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Gmail">
|
||||
@@ -261,6 +281,7 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
||||
[email protected]
|
||||
SMTP_FROM_NAME=Infisical
|
||||
```
|
||||
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Zoho Mail">
|
||||
@@ -278,6 +299,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
||||
SMTP_FROM_NAME=Infisical
|
||||
```
|
||||
|
||||
{" "}
|
||||
|
||||
<Note>
|
||||
You can use either your personal Zoho email address like `[email protected]` or
|
||||
a domain-based email address like `[email protected]`. If using a
|
||||
@@ -290,11 +313,8 @@ Without email configuration, Infisical's core functions like sign-up/login and s
|
||||
</Info>
|
||||
</Accordion>
|
||||
|
||||
## Authentication
|
||||
|
||||
|
||||
|
||||
|
||||
## SSO based login
|
||||
By default, users can only login via email/password based login method.
|
||||
To login into Infisical with OAuth providers such as Google, configure the associated variables.
|
||||
|
||||
@@ -335,33 +355,49 @@ To login into Infisical with OAuth providers such as Google, configure the assoc
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Okta SAML">
|
||||
Requires enterprise license. Please contact [email protected] to get more information.
|
||||
Requires enterprise license. Please contact [email protected] to get more
|
||||
information.
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Azure SAML">
|
||||
Requires enterprise license. Please contact [email protected] to get more information.
|
||||
Requires enterprise license. Please contact [email protected] to get more
|
||||
information.
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="JumpCloud SAML">
|
||||
Requires enterprise license. Please contact [email protected] to get more information.
|
||||
Requires enterprise license. Please contact [email protected] to get more
|
||||
information.
|
||||
</Accordion>
|
||||
|
||||
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string">
|
||||
Configure SAML organization slug to automatically redirect all users of your Infisical instance to the identity provider.
|
||||
<ParamField query="TRUST_SAML_EMAILS" type="boolean" default="false" optional>
|
||||
Whether or not to trust emails from external SAML identity providers. If set
|
||||
to `false` then users will be prompted to verify their email address upon
|
||||
first login.
|
||||
</ParamField>
|
||||
<ParamField query="TRUST_LDAP_EMAILS" type="string" default="false" optional>
|
||||
Whether or not to trust emails from external LDAP servers. If set to `false`
|
||||
then users will be prompted to verify their email address upon first login.
|
||||
</ParamField>
|
||||
|
||||
|
||||
|
||||
|
||||
<ParamField query="NEXT_PUBLIC_SAML_ORG_SLUG" type="string">
|
||||
Configure SAML organization slug to automatically redirect all users of your
|
||||
Infisical instance to the identity provider.
|
||||
</ParamField>
|
||||
|
||||
## Native secret integrations
|
||||
|
||||
To help you sync secrets from Infisical to services such as Github and Gitlab, Infisical provides native integrations out of the box.
|
||||
|
||||
<Accordion title="Heroku">
|
||||
<ParamField query="CLIENT_ID_HEROKU" type="string" default="none" optional>
|
||||
OAuth2 client ID for Heroku integration
|
||||
</ParamField>
|
||||
<ParamField query="CLIENT_SECRET_HEROKU" type="string" default="none" optional>
|
||||
<ParamField
|
||||
query="CLIENT_SECRET_HEROKU"
|
||||
type="string"
|
||||
default="none"
|
||||
optional
|
||||
>
|
||||
OAuth2 client secret for Heroku integration
|
||||
</ParamField>
|
||||
</Accordion>
|
||||
@@ -371,6 +407,8 @@ To help you sync secrets from Infisical to services such as Github and Gitlab, I
|
||||
OAuth2 client ID for Vercel integration
|
||||
</ParamField>
|
||||
|
||||
{" "}
|
||||
|
||||
<ParamField query="CLIENT_SECRET_VERCEL" type="string" default="none" optional>
|
||||
OAuth2 client secret for Vercel integration
|
||||
</ParamField>
|
||||
|
||||
-2
@@ -149,8 +149,6 @@ export const OrgMembersTable = ({ handlePopUpOpen, setCompleteInviteLink }: Prop
|
||||
[members, searchMemberFilter]
|
||||
);
|
||||
|
||||
console.log("filterdUser: ", filterdUser);
|
||||
|
||||
return (
|
||||
<div>
|
||||
<Input
|
||||
|
||||
@@ -16,8 +16,16 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
|
||||
const [step, setStep] = useState(0);
|
||||
const [password, setPassword] = useState("");
|
||||
|
||||
const { username, email, organizationName, organizationSlug, firstName, lastName, authType } =
|
||||
jwt_decode(providerAuthToken) as any;
|
||||
const {
|
||||
username,
|
||||
email,
|
||||
organizationName,
|
||||
organizationSlug,
|
||||
firstName,
|
||||
lastName,
|
||||
authType,
|
||||
isEmailVerified
|
||||
} = jwt_decode(providerAuthToken) as any;
|
||||
|
||||
const renderView = () => {
|
||||
switch (step) {
|
||||
@@ -25,7 +33,7 @@ export const SignupSSO = ({ providerAuthToken }: Props) => {
|
||||
return (
|
||||
<UserInfoSSOStep
|
||||
username={username}
|
||||
email={email}
|
||||
isEmailVerified={isEmailVerified}
|
||||
name={`${firstName} ${lastName}`}
|
||||
providerOrganizationName={organizationName}
|
||||
password={password}
|
||||
|
||||
@@ -26,7 +26,7 @@ const client = new jsrp.client();
|
||||
type Props = {
|
||||
setStep: (step: number) => void;
|
||||
username: string;
|
||||
email?: string;
|
||||
isEmailVerified?: boolean;
|
||||
password: string;
|
||||
setPassword: (value: string) => void;
|
||||
name: string;
|
||||
@@ -60,7 +60,7 @@ type Errors = {
|
||||
*/
|
||||
export const UserInfoSSOStep = ({
|
||||
username,
|
||||
email,
|
||||
isEmailVerified,
|
||||
name,
|
||||
providerOrganizationName,
|
||||
password,
|
||||
@@ -204,13 +204,13 @@ export const UserInfoSSOStep = ({
|
||||
localStorage.setItem("orgData.id", orgId);
|
||||
localStorage.setItem("projectData.id", project.id);
|
||||
|
||||
if (email) {
|
||||
if (isEmailVerified) {
|
||||
// move to backup PDF step
|
||||
setStep(3);
|
||||
} else {
|
||||
// move to verify email
|
||||
await sendEmailVerificationCode();
|
||||
setStep(1);
|
||||
} else {
|
||||
// move to backup PDF step
|
||||
setStep(3);
|
||||
}
|
||||
} catch (error) {
|
||||
setIsLoading(false);
|
||||
|
||||
Reference in New Issue
Block a user