diff --git a/backend/src/ee/services/license/license-fns.ts b/backend/src/ee/services/license/license-fns.ts index f6d0d0410..3f4af174b 100644 --- a/backend/src/ee/services/license/license-fns.ts +++ b/backend/src/ee/services/license/license-fns.ts @@ -25,11 +25,11 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({ customRateLimits: false, customAlerts: false, secretAccessInsights: false, - auditLogs: true, - auditLogsRetentionDays: 3, + auditLogs: false, + auditLogsRetentionDays: 0, auditLogStreams: false, auditLogStreamLimit: 3, - samlSSO: true, + samlSSO: false, hsm: false, oidcSSO: false, scim: false, diff --git a/backend/src/services/auth/auth-login-service.ts b/backend/src/services/auth/auth-login-service.ts index 6af512773..e0d964017 100644 --- a/backend/src/services/auth/auth-login-service.ts +++ b/backend/src/services/auth/auth-login-service.ts @@ -454,18 +454,22 @@ export const authLoginServiceFactory = ({ const orgAdmins = await orgDAL.findOrgMembersByRole(organizationId, OrgMembershipRole.Admin); const adminEmails = orgAdmins.map((admin) => admin.user?.email).filter(Boolean) as string[]; - if (adminEmails.length > 0) { - await smtpService.sendMail({ - recipients: adminEmails, - subjectLine: "Security Alert: Admin SSO Bypass", - substitutions: { - email: user.email, - timestamp: new Date().toISOString(), - ip: ipAddress, - userAgent - }, - template: SmtpTemplates.OrgAdminBreakglassAccess - }); + try { + if (adminEmails.length > 0) { + await smtpService.sendMail({ + recipients: adminEmails, + subjectLine: "Security Alert: Admin SSO Bypass", + substitutions: { + email: user.email, + timestamp: new Date().toISOString(), + ip: ipAddress, + userAgent + }, + template: SmtpTemplates.OrgAdminBreakglassAccess + }); + } + } catch (error) { + logger.error(error, `Failed to send SSO bypass notification emails for user ${user.email}`); } } diff --git a/backend/src/services/identity-aws-auth/identity-aws-auth-service.ts b/backend/src/services/identity-aws-auth/identity-aws-auth-service.ts index 0849a7523..fe7b24783 100644 --- a/backend/src/services/identity-aws-auth/identity-aws-auth-service.ts +++ b/backend/src/services/identity-aws-auth/identity-aws-auth-service.ts @@ -68,18 +68,15 @@ const awsRegionFromHeader = (authorizationHeader: string): string | null => { return null; }; - - -function isValidAwsRegion(region: (string | null)): boolean { - const validRegionPattern = new RE2('^[a-z0-9-]+$'); - if (typeof region !== 'string' || region.length === 0 || region.length > 20) { +function isValidAwsRegion(region: string | null): boolean { + const validRegionPattern = new RE2("^[a-z0-9-]+$"); + if (typeof region !== "string" || region.length === 0 || region.length > 20) { return false; } - + return validRegionPattern.test(region); } - export const identityAwsAuthServiceFactory = ({ identityAccessTokenDAL, identityAwsAuthDAL, @@ -100,7 +97,7 @@ export const identityAwsAuthServiceFactory = ({ const region = headers.Authorization ? awsRegionFromHeader(headers.Authorization) : null; if (!isValidAwsRegion(region)) { - throw new BadRequestError({message: "Invalid AWS region"}); + throw new BadRequestError({ message: "Invalid AWS region" }); } const url = region ? `https://sts.${region}.amazonaws.com` : identityAwsAuth.stsEndpoint; diff --git a/backend/src/services/smtp/smtp-service.ts b/backend/src/services/smtp/smtp-service.ts index 0e028968d..550e1bb07 100644 --- a/backend/src/services/smtp/smtp-service.ts +++ b/backend/src/services/smtp/smtp-service.ts @@ -44,7 +44,7 @@ export enum SmtpTemplates { SecretRotationFailed = "secretRotationFailed.handlebars", ProjectAccessRequest = "projectAccess.handlebars", OrgAdminProjectDirectAccess = "orgAdminProjectGrantAccess.handlebars", - OrgAdminBreakglassAccess = "OrgAdminBreakglassAccess.handlebars", + OrgAdminBreakglassAccess = "orgAdminBreakglassAccess.handlebars", ServiceTokenExpired = "serviceTokenExpired.handlebars" } diff --git a/frontend/src/hooks/api/auditLogs/constants.tsx b/frontend/src/hooks/api/auditLogs/constants.tsx index 159e840ec..229f822da 100644 --- a/frontend/src/hooks/api/auditLogs/constants.tsx +++ b/frontend/src/hooks/api/auditLogs/constants.tsx @@ -84,6 +84,7 @@ export const eventToNameMap: { [K in EventType]: string } = { [EventType.ADD_PKI_COLLECTION_ITEM]: "Add PKI collection item", [EventType.DELETE_PKI_COLLECTION_ITEM]: "Delete PKI collection item", [EventType.ORG_ADMIN_ACCESS_PROJECT]: "Org admin accessed project", + [EventType.ORG_ADMIN_BYPASS_SSO]: "Org admin bypassed SSO enforcement", [EventType.CREATE_CERTIFICATE_TEMPLATE]: "Create certificate template", [EventType.UPDATE_CERTIFICATE_TEMPLATE]: "Update certificate template", [EventType.DELETE_CERTIFICATE_TEMPLATE]: "Delete certificate template",