mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 16:26:37 +00:00
feat: added support for login via cli
This commit is contained in:
@@ -45,14 +45,20 @@ export const registerOidcRouter = async (server: FastifyZodProvider) => {
|
|||||||
method: "GET",
|
method: "GET",
|
||||||
schema: {
|
schema: {
|
||||||
querystring: z.object({
|
querystring: z.object({
|
||||||
orgSlug: z.string().trim()
|
orgSlug: z.string().trim(),
|
||||||
|
callbackPort: z.string().trim().optional()
|
||||||
})
|
})
|
||||||
},
|
},
|
||||||
handler: async (req, res) => {
|
handler: async (req, res) => {
|
||||||
// get params, save to session
|
// get params, save to session
|
||||||
const { orgSlug } = req.query;
|
const { orgSlug, callbackPort } = req.query;
|
||||||
req.session.set<any>("oidcOrgSlug", orgSlug);
|
req.session.set<any>("oidcOrgSlug", orgSlug);
|
||||||
const oidcStrategy = await server.services.oidc.getOrgAuthStrategy(orgSlug);
|
|
||||||
|
if (callbackPort) {
|
||||||
|
req.session.set<any>("callbackPort", callbackPort);
|
||||||
|
}
|
||||||
|
|
||||||
|
const oidcStrategy = await server.services.oidc.getOrgAuthStrategy(orgSlug, callbackPort);
|
||||||
(
|
(
|
||||||
passport.authenticate(oidcStrategy as Strategy, {
|
passport.authenticate(oidcStrategy as Strategy, {
|
||||||
scope: "profile email openid"
|
scope: "profile email openid"
|
||||||
@@ -67,7 +73,9 @@ export const registerOidcRouter = async (server: FastifyZodProvider) => {
|
|||||||
method: "GET",
|
method: "GET",
|
||||||
handler: async (req, res) => {
|
handler: async (req, res) => {
|
||||||
const oidcOrgSlug = req.session.get<any>("oidcOrgSlug");
|
const oidcOrgSlug = req.session.get<any>("oidcOrgSlug");
|
||||||
const oidcStrategy = await server.services.oidc.getOrgAuthStrategy(oidcOrgSlug);
|
const callbackPort = req.session.get<any>("callbackPort");
|
||||||
|
const oidcStrategy = await server.services.oidc.getOrgAuthStrategy(oidcOrgSlug, callbackPort);
|
||||||
|
|
||||||
await (
|
await (
|
||||||
passport.authenticate(oidcStrategy as Strategy, {
|
passport.authenticate(oidcStrategy as Strategy, {
|
||||||
failureRedirect: "/api/v1/sso/oidc/login/error",
|
failureRedirect: "/api/v1/sso/oidc/login/error",
|
||||||
@@ -76,6 +84,8 @@ export const registerOidcRouter = async (server: FastifyZodProvider) => {
|
|||||||
}) as any
|
}) as any
|
||||||
)(req, res);
|
)(req, res);
|
||||||
|
|
||||||
|
await req.session.destroy();
|
||||||
|
|
||||||
if (req.passportUser.isUserCompleted) {
|
if (req.passportUser.isUserCompleted) {
|
||||||
return res.redirect(
|
return res.redirect(
|
||||||
`http://localhost:8080/login/sso?token=${encodeURIComponent(req.passportUser.providerAuthToken)}`
|
`http://localhost:8080/login/sso?token=${encodeURIComponent(req.passportUser.providerAuthToken)}`
|
||||||
@@ -92,7 +102,9 @@ export const registerOidcRouter = async (server: FastifyZodProvider) => {
|
|||||||
server.route({
|
server.route({
|
||||||
url: "/login/error",
|
url: "/login/error",
|
||||||
method: "GET",
|
method: "GET",
|
||||||
handler: (req, res) => {
|
handler: async (req, res) => {
|
||||||
|
await req.session.destroy();
|
||||||
|
|
||||||
return res.status(500).send({
|
return res.status(500).send({
|
||||||
error: "Authentication error",
|
error: "Authentication error",
|
||||||
details: req.query
|
details: req.query
|
||||||
|
|||||||
@@ -63,7 +63,7 @@ export const oidcConfigServiceFactory = ({
|
|||||||
smtpService,
|
smtpService,
|
||||||
oidcConfigDAL
|
oidcConfigDAL
|
||||||
}: TOidcConfigServiceFactoryDep) => {
|
}: TOidcConfigServiceFactoryDep) => {
|
||||||
const oidcLogin = async ({ externalId, email, firstName, lastName, orgId }: TOidcLoginDTO) => {
|
const oidcLogin = async ({ externalId, email, firstName, lastName, orgId, callbackPort }: TOidcLoginDTO) => {
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
const userAlias = await userAliasDAL.findOne({
|
const userAlias = await userAliasDAL.findOne({
|
||||||
externalId,
|
externalId,
|
||||||
@@ -188,7 +188,8 @@ export const oidcConfigServiceFactory = ({
|
|||||||
organizationSlug: organization.slug,
|
organizationSlug: organization.slug,
|
||||||
authMethod: AuthMethod.OIDC,
|
authMethod: AuthMethod.OIDC,
|
||||||
authType: UserAliasType.OIDC,
|
authType: UserAliasType.OIDC,
|
||||||
isUserCompleted
|
isUserCompleted,
|
||||||
|
...(callbackPort && { callbackPort })
|
||||||
},
|
},
|
||||||
appCfg.AUTH_SECRET,
|
appCfg.AUTH_SECRET,
|
||||||
{
|
{
|
||||||
@@ -491,7 +492,7 @@ export const oidcConfigServiceFactory = ({
|
|||||||
return oidcCfg;
|
return oidcCfg;
|
||||||
};
|
};
|
||||||
|
|
||||||
const getOrgAuthStrategy = async (orgSlug: string) => {
|
const getOrgAuthStrategy = async (orgSlug: string, callbackPort?: string) => {
|
||||||
const appCfg = getConfig();
|
const appCfg = getConfig();
|
||||||
|
|
||||||
const org = await orgDAL.findOne({
|
const org = await orgDAL.findOne({
|
||||||
@@ -542,7 +543,8 @@ export const oidcConfigServiceFactory = ({
|
|||||||
externalId: claims.sub,
|
externalId: claims.sub,
|
||||||
firstName: claims.given_name ?? "",
|
firstName: claims.given_name ?? "",
|
||||||
lastName: claims.family_name ?? "",
|
lastName: claims.family_name ?? "",
|
||||||
orgId: org.id
|
orgId: org.id,
|
||||||
|
callbackPort
|
||||||
})
|
})
|
||||||
.then(({ isUserCompleted, providerAuthToken }) => {
|
.then(({ isUserCompleted, providerAuthToken }) => {
|
||||||
cb(null, { isUserCompleted, providerAuthToken });
|
cb(null, { isUserCompleted, providerAuthToken });
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ export type TOidcLoginDTO = {
|
|||||||
firstName: string;
|
firstName: string;
|
||||||
lastName?: string;
|
lastName?: string;
|
||||||
orgId: string;
|
orgId: string;
|
||||||
|
callbackPort?: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TGetOidcCfgDTO =
|
export type TGetOidcCfgDTO =
|
||||||
|
|||||||
@@ -24,8 +24,11 @@ export const SSOStep = ({ setStep, type }: Props) => {
|
|||||||
}`
|
}`
|
||||||
);
|
);
|
||||||
} else {
|
} else {
|
||||||
// TODO: Sheen - Add callback support for CLI login
|
window.open(
|
||||||
window.open(`/api/v1/sso/oidc/login?orgSlug=${ssoIdentifier}`);
|
`/api/v1/sso/oidc/login?orgSlug=${ssoIdentifier}${
|
||||||
|
callbackPort ? `&callbackPort=${callbackPort}` : ""
|
||||||
|
}`
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
window.close();
|
window.close();
|
||||||
|
|||||||
Reference in New Issue
Block a user