Revert license overwrites, fix type errors, add error handling to email function

This commit is contained in:
x
2025-04-22 14:58:17 -04:00
parent a32b590dc5
commit a838f84601
5 changed files with 26 additions and 24 deletions
@@ -25,11 +25,11 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
customRateLimits: false, customRateLimits: false,
customAlerts: false, customAlerts: false,
secretAccessInsights: false, secretAccessInsights: false,
auditLogs: true, auditLogs: false,
auditLogsRetentionDays: 3, auditLogsRetentionDays: 0,
auditLogStreams: false, auditLogStreams: false,
auditLogStreamLimit: 3, auditLogStreamLimit: 3,
samlSSO: true, samlSSO: false,
hsm: false, hsm: false,
oidcSSO: false, oidcSSO: false,
scim: false, scim: false,
+16 -12
View File
@@ -454,18 +454,22 @@ export const authLoginServiceFactory = ({
const orgAdmins = await orgDAL.findOrgMembersByRole(organizationId, OrgMembershipRole.Admin); const orgAdmins = await orgDAL.findOrgMembersByRole(organizationId, OrgMembershipRole.Admin);
const adminEmails = orgAdmins.map((admin) => admin.user?.email).filter(Boolean) as string[]; const adminEmails = orgAdmins.map((admin) => admin.user?.email).filter(Boolean) as string[];
if (adminEmails.length > 0) { try {
await smtpService.sendMail({ if (adminEmails.length > 0) {
recipients: adminEmails, await smtpService.sendMail({
subjectLine: "Security Alert: Admin SSO Bypass", recipients: adminEmails,
substitutions: { subjectLine: "Security Alert: Admin SSO Bypass",
email: user.email, substitutions: {
timestamp: new Date().toISOString(), email: user.email,
ip: ipAddress, timestamp: new Date().toISOString(),
userAgent ip: ipAddress,
}, userAgent
template: SmtpTemplates.OrgAdminBreakglassAccess },
}); template: SmtpTemplates.OrgAdminBreakglassAccess
});
}
} catch (error) {
logger.error(error, `Failed to send SSO bypass notification emails for user ${user.email}`);
} }
} }
@@ -68,18 +68,15 @@ const awsRegionFromHeader = (authorizationHeader: string): string | null => {
return null; return null;
}; };
function isValidAwsRegion(region: string | null): boolean {
const validRegionPattern = new RE2("^[a-z0-9-]+$");
function isValidAwsRegion(region: (string | null)): boolean { if (typeof region !== "string" || region.length === 0 || region.length > 20) {
const validRegionPattern = new RE2('^[a-z0-9-]+$');
if (typeof region !== 'string' || region.length === 0 || region.length > 20) {
return false; return false;
} }
return validRegionPattern.test(region); return validRegionPattern.test(region);
} }
export const identityAwsAuthServiceFactory = ({ export const identityAwsAuthServiceFactory = ({
identityAccessTokenDAL, identityAccessTokenDAL,
identityAwsAuthDAL, identityAwsAuthDAL,
@@ -100,7 +97,7 @@ export const identityAwsAuthServiceFactory = ({
const region = headers.Authorization ? awsRegionFromHeader(headers.Authorization) : null; const region = headers.Authorization ? awsRegionFromHeader(headers.Authorization) : null;
if (!isValidAwsRegion(region)) { if (!isValidAwsRegion(region)) {
throw new BadRequestError({message: "Invalid AWS region"}); throw new BadRequestError({ message: "Invalid AWS region" });
} }
const url = region ? `https://sts.${region}.amazonaws.com` : identityAwsAuth.stsEndpoint; const url = region ? `https://sts.${region}.amazonaws.com` : identityAwsAuth.stsEndpoint;
+1 -1
View File
@@ -44,7 +44,7 @@ export enum SmtpTemplates {
SecretRotationFailed = "secretRotationFailed.handlebars", SecretRotationFailed = "secretRotationFailed.handlebars",
ProjectAccessRequest = "projectAccess.handlebars", ProjectAccessRequest = "projectAccess.handlebars",
OrgAdminProjectDirectAccess = "orgAdminProjectGrantAccess.handlebars", OrgAdminProjectDirectAccess = "orgAdminProjectGrantAccess.handlebars",
OrgAdminBreakglassAccess = "OrgAdminBreakglassAccess.handlebars", OrgAdminBreakglassAccess = "orgAdminBreakglassAccess.handlebars",
ServiceTokenExpired = "serviceTokenExpired.handlebars" ServiceTokenExpired = "serviceTokenExpired.handlebars"
} }
@@ -84,6 +84,7 @@ export const eventToNameMap: { [K in EventType]: string } = {
[EventType.ADD_PKI_COLLECTION_ITEM]: "Add PKI collection item", [EventType.ADD_PKI_COLLECTION_ITEM]: "Add PKI collection item",
[EventType.DELETE_PKI_COLLECTION_ITEM]: "Delete PKI collection item", [EventType.DELETE_PKI_COLLECTION_ITEM]: "Delete PKI collection item",
[EventType.ORG_ADMIN_ACCESS_PROJECT]: "Org admin accessed project", [EventType.ORG_ADMIN_ACCESS_PROJECT]: "Org admin accessed project",
[EventType.ORG_ADMIN_BYPASS_SSO]: "Org admin bypassed SSO enforcement",
[EventType.CREATE_CERTIFICATE_TEMPLATE]: "Create certificate template", [EventType.CREATE_CERTIFICATE_TEMPLATE]: "Create certificate template",
[EventType.UPDATE_CERTIFICATE_TEMPLATE]: "Update certificate template", [EventType.UPDATE_CERTIFICATE_TEMPLATE]: "Update certificate template",
[EventType.DELETE_CERTIFICATE_TEMPLATE]: "Delete certificate template", [EventType.DELETE_CERTIFICATE_TEMPLATE]: "Delete certificate template",