Revert license overwrites, fix type errors, add error handling to email function

This commit is contained in:
x
2025-04-22 14:58:17 -04:00
parent a32b590dc5
commit a838f84601
5 changed files with 26 additions and 24 deletions

View File

@@ -25,11 +25,11 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
customRateLimits: false,
customAlerts: false,
secretAccessInsights: false,
auditLogs: true,
auditLogsRetentionDays: 3,
auditLogs: false,
auditLogsRetentionDays: 0,
auditLogStreams: false,
auditLogStreamLimit: 3,
samlSSO: true,
samlSSO: false,
hsm: false,
oidcSSO: false,
scim: false,

View File

@@ -454,18 +454,22 @@ export const authLoginServiceFactory = ({
const orgAdmins = await orgDAL.findOrgMembersByRole(organizationId, OrgMembershipRole.Admin);
const adminEmails = orgAdmins.map((admin) => admin.user?.email).filter(Boolean) as string[];
if (adminEmails.length > 0) {
await smtpService.sendMail({
recipients: adminEmails,
subjectLine: "Security Alert: Admin SSO Bypass",
substitutions: {
email: user.email,
timestamp: new Date().toISOString(),
ip: ipAddress,
userAgent
},
template: SmtpTemplates.OrgAdminBreakglassAccess
});
try {
if (adminEmails.length > 0) {
await smtpService.sendMail({
recipients: adminEmails,
subjectLine: "Security Alert: Admin SSO Bypass",
substitutions: {
email: user.email,
timestamp: new Date().toISOString(),
ip: ipAddress,
userAgent
},
template: SmtpTemplates.OrgAdminBreakglassAccess
});
}
} catch (error) {
logger.error(error, `Failed to send SSO bypass notification emails for user ${user.email}`);
}
}

View File

@@ -68,18 +68,15 @@ const awsRegionFromHeader = (authorizationHeader: string): string | null => {
return null;
};
function isValidAwsRegion(region: (string | null)): boolean {
const validRegionPattern = new RE2('^[a-z0-9-]+$');
if (typeof region !== 'string' || region.length === 0 || region.length > 20) {
function isValidAwsRegion(region: string | null): boolean {
const validRegionPattern = new RE2("^[a-z0-9-]+$");
if (typeof region !== "string" || region.length === 0 || region.length > 20) {
return false;
}
return validRegionPattern.test(region);
}
export const identityAwsAuthServiceFactory = ({
identityAccessTokenDAL,
identityAwsAuthDAL,
@@ -100,7 +97,7 @@ export const identityAwsAuthServiceFactory = ({
const region = headers.Authorization ? awsRegionFromHeader(headers.Authorization) : null;
if (!isValidAwsRegion(region)) {
throw new BadRequestError({message: "Invalid AWS region"});
throw new BadRequestError({ message: "Invalid AWS region" });
}
const url = region ? `https://sts.${region}.amazonaws.com` : identityAwsAuth.stsEndpoint;

View File

@@ -44,7 +44,7 @@ export enum SmtpTemplates {
SecretRotationFailed = "secretRotationFailed.handlebars",
ProjectAccessRequest = "projectAccess.handlebars",
OrgAdminProjectDirectAccess = "orgAdminProjectGrantAccess.handlebars",
OrgAdminBreakglassAccess = "OrgAdminBreakglassAccess.handlebars",
OrgAdminBreakglassAccess = "orgAdminBreakglassAccess.handlebars",
ServiceTokenExpired = "serviceTokenExpired.handlebars"
}

View File

@@ -84,6 +84,7 @@ export const eventToNameMap: { [K in EventType]: string } = {
[EventType.ADD_PKI_COLLECTION_ITEM]: "Add PKI collection item",
[EventType.DELETE_PKI_COLLECTION_ITEM]: "Delete PKI collection item",
[EventType.ORG_ADMIN_ACCESS_PROJECT]: "Org admin accessed project",
[EventType.ORG_ADMIN_BYPASS_SSO]: "Org admin bypassed SSO enforcement",
[EventType.CREATE_CERTIFICATE_TEMPLATE]: "Create certificate template",
[EventType.UPDATE_CERTIFICATE_TEMPLATE]: "Update certificate template",
[EventType.DELETE_CERTIFICATE_TEMPLATE]: "Delete certificate template",