Add orgId to reuse login1/login2 logic for LDAP 2nd step login

This commit is contained in:
Tuan Dang
2024-02-26 10:41:44 -08:00
parent 1c088b3a58
commit 9ba4b939a4
8 changed files with 40 additions and 10 deletions
@@ -370,16 +370,21 @@ export const ldapConfigServiceFactory = ({
orgId, orgId,
firstName, firstName,
lastName, lastName,
authMethods: [AuthMethod.EMAIL], authMethods: [AuthMethod.LDAP],
isGhost: false isGhost: false
}, },
tx tx
); );
await orgDAL.createMembership({ await orgDAL.createMembership(
{
userId: newUser.id,
orgId, orgId,
role: OrgMembershipRole.Member, role: OrgMembershipRole.Member,
status: OrgMembershipStatus.Invited status: OrgMembershipStatus.Invited
}); },
tx
);
return newUser; return newUser;
}); });
} }
@@ -13,6 +13,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
schema: { schema: {
body: z.object({ body: z.object({
email: z.string().trim(), email: z.string().trim(),
orgId: z.string().optional(),
providerAuthToken: z.string().trim().optional(), providerAuthToken: z.string().trim().optional(),
clientPublicKey: z.string().trim() clientPublicKey: z.string().trim()
}), }),
@@ -26,6 +27,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
handler: async (req) => { handler: async (req) => {
const { serverPublicKey, salt } = await server.services.login.loginGenServerPublicKey({ const { serverPublicKey, salt } = await server.services.login.loginGenServerPublicKey({
email: req.body.email, email: req.body.email,
userOrgId: req.body.orgId,
clientPublicKey: req.body.clientPublicKey, clientPublicKey: req.body.clientPublicKey,
providerAuthToken: req.body.providerAuthToken providerAuthToken: req.body.providerAuthToken
}); });
@@ -43,6 +45,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
schema: { schema: {
body: z.object({ body: z.object({
email: z.string().trim(), email: z.string().trim(),
orgId: z.string().optional(),
providerAuthToken: z.string().trim().optional(), providerAuthToken: z.string().trim().optional(),
clientProof: z.string().trim() clientProof: z.string().trim()
}), }),
@@ -71,6 +74,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
const data = await server.services.login.loginExchangeClientProof({ const data = await server.services.login.loginExchangeClientProof({
email: req.body.email, email: req.body.email,
userOrgId: req.body.orgId,
ip: req.realIp, ip: req.realIp,
userAgent, userAgent,
providerAuthToken: req.body.providerAuthToken, providerAuthToken: req.body.providerAuthToken,
@@ -130,10 +130,14 @@ export const authLoginServiceFactory = ({ userDAL, tokenService, smtpService }:
*/ */
const loginGenServerPublicKey = async ({ const loginGenServerPublicKey = async ({
email, email,
userOrgId,
providerAuthToken, providerAuthToken,
clientPublicKey clientPublicKey
}: TLoginGenServerPublicKeyDTO) => { }: TLoginGenServerPublicKeyDTO) => {
const userEnc = await userDAL.findUserEncKeyByUsername(email); const userEnc = await userDAL.findUserEncKeyByUsername({
username: email,
orgId: userOrgId
});
if (!userEnc || (userEnc && !userEnc.isAccepted)) { if (!userEnc || (userEnc && !userEnc.isAccepted)) {
throw new Error("Failed to find user"); throw new Error("Failed to find user");
} }
@@ -155,12 +159,16 @@ export const authLoginServiceFactory = ({ userDAL, tokenService, smtpService }:
*/ */
const loginExchangeClientProof = async ({ const loginExchangeClientProof = async ({
email, email,
userOrgId,
clientProof, clientProof,
providerAuthToken, providerAuthToken,
ip, ip,
userAgent userAgent
}: TLoginClientProofDTO) => { }: TLoginClientProofDTO) => {
const userEnc = await userDAL.findUserEncKeyByUsername(email); const userEnc = await userDAL.findUserEncKeyByUsername({
username: email,
orgId: userOrgId
});
if (!userEnc) throw new Error("Failed to find user"); if (!userEnc) throw new Error("Failed to find user");
const cfg = getConfig(); const cfg = getConfig();
@@ -2,12 +2,14 @@ import { AuthMethod } from "./auth-type";
export type TLoginGenServerPublicKeyDTO = { export type TLoginGenServerPublicKeyDTO = {
email: string; email: string;
userOrgId?: string;
clientPublicKey: string; clientPublicKey: string;
providerAuthToken?: string; providerAuthToken?: string;
}; };
export type TLoginClientProofDTO = { export type TLoginClientProofDTO = {
email: string; email: string;
userOrgId?: string;
clientProof: string; clientProof: string;
providerAuthToken?: string; providerAuthToken?: string;
ip: string; ip: string;
+6 -2
View File
@@ -20,10 +20,14 @@ export const userDALFactory = (db: TDbClient) => {
// USER ENCRYPTION FUNCTIONS // USER ENCRYPTION FUNCTIONS
// ------------------------- // -------------------------
const findUserEncKeyByUsername = async (username: string) => { const findUserEncKeyByUsername = async ({ username, orgId }: { username: string; orgId?: string }) => {
try { try {
return await db(TableName.Users) return await db(TableName.Users)
.where({ username, isGhost: false }) .where({
username,
...(orgId ? { orgId } : { orgId: null }),
isGhost: false
})
.join(TableName.UserEncryptionKey, `${TableName.Users}.id`, `${TableName.UserEncryptionKey}.userId`) .join(TableName.UserEncryptionKey, `${TableName.Users}.id`, `${TableName.UserEncryptionKey}.userId`)
.first(); .first();
} catch (error) { } catch (error) {
@@ -21,10 +21,12 @@ interface IsLoginSuccessful {
*/ */
const attemptLogin = async ({ const attemptLogin = async ({
email, email,
orgId,
password, password,
providerAuthToken providerAuthToken
}: { }: {
email: string; email: string;
orgId?: string;
password: string; password: string;
providerAuthToken?: string; providerAuthToken?: string;
}): Promise<IsLoginSuccessful> => { }): Promise<IsLoginSuccessful> => {
@@ -38,6 +40,7 @@ const attemptLogin = async ({
const { serverPublicKey, salt } = await login1({ const { serverPublicKey, salt } = await login1({
email, email,
orgId,
clientPublicKey, clientPublicKey,
providerAuthToken providerAuthToken
}); });
@@ -59,6 +62,7 @@ const attemptLogin = async ({
tag tag
} = await login2({ } = await login2({
email, email,
orgId,
clientProof, clientProof,
providerAuthToken providerAuthToken
}); });
+2
View File
@@ -25,12 +25,14 @@ export type VerifyMfaTokenRes = {
export type Login1DTO = { export type Login1DTO = {
email: string; email: string;
orgId?: string;
clientPublicKey: string; clientPublicKey: string;
providerAuthToken?: string; providerAuthToken?: string;
} }
export type Login2DTO = { export type Login2DTO = {
email: string; email: string;
orgId?: string;
clientProof: string; clientProof: string;
providerAuthToken?: string; providerAuthToken?: string;
} }
@@ -78,6 +78,7 @@ export const PasswordStep = ({
} else { } else {
const loginAttempt = await attemptLogin({ const loginAttempt = await attemptLogin({
email, email,
orgId: organizationId,
password, password,
providerAuthToken, providerAuthToken,
}); });