diff --git a/backend/src/controllers/v1/signupController.ts b/backend/src/controllers/v1/signupController.ts index b545320a6..ce464e214 100644 --- a/backend/src/controllers/v1/signupController.ts +++ b/backend/src/controllers/v1/signupController.ts @@ -1,5 +1,5 @@ import { Request, Response } from "express"; -import { User } from "../../models"; +import { AuthMethod, User } from "../../models"; import { checkEmailVerification, sendEmailVerification } from "../../helpers/signup"; import { createToken } from "../../helpers/auth"; import { BadRequestError } from "../../utils/errors"; @@ -81,7 +81,8 @@ export const verifyEmailSignup = async (req: Request, res: Response) => { if (!user) { user = await new User({ - email + email, + authMethods: [AuthMethod.EMAIL] }).save(); } diff --git a/backend/src/controllers/v3/signupController.ts b/backend/src/controllers/v3/signupController.ts index 12f225c4e..f17384189 100644 --- a/backend/src/controllers/v3/signupController.ts +++ b/backend/src/controllers/v3/signupController.ts @@ -117,7 +117,17 @@ export const completeAccountSignup = async (req: Request, res: Response) => { if (!user) throw new Error("Failed to complete account for non-existent user"); // ensure user is non-null - if (!user.authMethods?.includes(AuthMethod.OKTA_SAML)) { + const hasSamlEnabled = user.authMethods + .some( + (authMethod: AuthMethod) => + [ + AuthMethod.OKTA_SAML, + AuthMethod.AZURE_SAML, + AuthMethod.JUMPCLOUD_SAML + ].includes(authMethod) + ); + + if (!hasSamlEnabled) { // TODO: modify this part // initialize default organization and workspace await initializeDefaultOrg({ organizationName, diff --git a/backend/src/helpers/auth.ts b/backend/src/helpers/auth.ts index e15283c75..f24c54859 100644 --- a/backend/src/helpers/auth.ts +++ b/backend/src/helpers/auth.ts @@ -408,7 +408,7 @@ export const validateProviderAuthToken = async ({ ); if ( - !user.authMethods.includes(decodedToken.authProvider) || + !user.authMethods.includes(decodedToken.authMethod) || decodedToken.email !== email ) { throw new Error("Invalid authentication credentials.")