mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 14:27:30 +00:00
Refactor ldap filter validation
This commit is contained in:
@@ -54,13 +54,18 @@ export const registerLdapRouter = async (server: FastifyZodProvider) => {
|
|||||||
try {
|
try {
|
||||||
const ldapConfig = (req as unknown as FastifyRequest).ldapConfig as TLDAPConfig;
|
const ldapConfig = (req as unknown as FastifyRequest).ldapConfig as TLDAPConfig;
|
||||||
|
|
||||||
const groupFilter = "(|(memberUid={{.Username}})(member={{.UserDN}})(uniqueMember={{.UserDN}}))";
|
let groups: { dn: string; cn: string }[] | undefined;
|
||||||
const groupSearchFilter = (ldapConfig.groupSearchFilter || groupFilter)
|
if (ldapConfig.groupSearchBase) {
|
||||||
.replace(/{{\.Username}}/g, user.uid)
|
const groupFilter = "(|(memberUid={{.Username}})(member={{.UserDN}})(uniqueMember={{.UserDN}}))";
|
||||||
.replace(/{{\.UserDN}}/g, user.dn);
|
const groupSearchFilter = (ldapConfig.groupSearchFilter || groupFilter)
|
||||||
|
.replace(/{{\.Username}}/g, user.uid)
|
||||||
|
.replace(/{{\.UserDN}}/g, user.dn);
|
||||||
|
|
||||||
if (!isValidLdapFilter(groupSearchFilter)) {
|
if (!isValidLdapFilter(groupSearchFilter)) {
|
||||||
throw new Error("Generated LDAP search filter is invalid.");
|
throw new Error("Generated LDAP search filter is invalid.");
|
||||||
|
}
|
||||||
|
|
||||||
|
groups = await searchGroups(ldapConfig, groupSearchFilter, ldapConfig.groupSearchBase);
|
||||||
}
|
}
|
||||||
|
|
||||||
const { isUserCompleted, providerAuthToken } = await server.services.ldap.ldapLogin({
|
const { isUserCompleted, providerAuthToken } = await server.services.ldap.ldapLogin({
|
||||||
@@ -70,9 +75,7 @@ export const registerLdapRouter = async (server: FastifyZodProvider) => {
|
|||||||
firstName: user.givenName ?? user.cn ?? "",
|
firstName: user.givenName ?? user.cn ?? "",
|
||||||
lastName: user.sn ?? "",
|
lastName: user.sn ?? "",
|
||||||
emails: user.mail ? [user.mail] : [],
|
emails: user.mail ? [user.mail] : [],
|
||||||
groups: ldapConfig.groupSearchBase
|
groups,
|
||||||
? await searchGroups(ldapConfig, groupSearchFilter, ldapConfig.groupSearchBase)
|
|
||||||
: undefined,
|
|
||||||
relayState: ((req as unknown as FastifyRequest).body as { RelayState?: string }).RelayState,
|
relayState: ((req as unknown as FastifyRequest).body as { RelayState?: string }).RelayState,
|
||||||
orgId: (req as unknown as FastifyRequest).ldapConfig.organization
|
orgId: (req as unknown as FastifyRequest).ldapConfig.organization
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -40,7 +40,7 @@ import {
|
|||||||
TTestLdapConnectionDTO,
|
TTestLdapConnectionDTO,
|
||||||
TUpdateLdapCfgDTO
|
TUpdateLdapCfgDTO
|
||||||
} from "./ldap-config-types";
|
} from "./ldap-config-types";
|
||||||
import { isValidLdapFilter, testLDAPConfig } from "./ldap-fns";
|
import { testLDAPConfig } from "./ldap-fns";
|
||||||
import { TLdapGroupMapDALFactory } from "./ldap-group-map-dal";
|
import { TLdapGroupMapDALFactory } from "./ldap-group-map-dal";
|
||||||
|
|
||||||
type TLdapConfigServiceFactoryDep = {
|
type TLdapConfigServiceFactoryDep = {
|
||||||
@@ -113,18 +113,6 @@ export const ldapConfigServiceFactory = ({
|
|||||||
"Failed to create LDAP configuration due to plan restriction. Upgrade plan to create LDAP configuration."
|
"Failed to create LDAP configuration due to plan restriction. Upgrade plan to create LDAP configuration."
|
||||||
});
|
});
|
||||||
|
|
||||||
const isSearchFilterValid = isValidLdapFilter(searchFilter);
|
|
||||||
if (!isSearchFilterValid)
|
|
||||||
throw new BadRequestError({
|
|
||||||
message: "Failed to create LDAP configuration due to invalid search filter."
|
|
||||||
});
|
|
||||||
|
|
||||||
const isGroupSearchFilterValid = isValidLdapFilter(groupSearchFilter);
|
|
||||||
if (!isGroupSearchFilterValid)
|
|
||||||
throw new BadRequestError({
|
|
||||||
message: "Failed to create LDAP configuration due to invalid group search filter."
|
|
||||||
});
|
|
||||||
|
|
||||||
const orgBot = await orgBotDAL.transaction(async (tx) => {
|
const orgBot = await orgBotDAL.transaction(async (tx) => {
|
||||||
const doc = await orgBotDAL.findOne({ orgId }, tx);
|
const doc = await orgBotDAL.findOne({ orgId }, tx);
|
||||||
if (doc) return doc;
|
if (doc) return doc;
|
||||||
@@ -225,22 +213,6 @@ export const ldapConfigServiceFactory = ({
|
|||||||
"Failed to update LDAP configuration due to plan restriction. Upgrade plan to update LDAP configuration."
|
"Failed to update LDAP configuration due to plan restriction. Upgrade plan to update LDAP configuration."
|
||||||
});
|
});
|
||||||
|
|
||||||
if (searchFilter) {
|
|
||||||
const isSearchFilterValid = isValidLdapFilter(searchFilter);
|
|
||||||
if (!isSearchFilterValid)
|
|
||||||
throw new BadRequestError({
|
|
||||||
message: "Failed to update LDAP configuration due to invalid search filter."
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
if (groupSearchFilter) {
|
|
||||||
const isGroupSearchFilterValid = isValidLdapFilter(groupSearchFilter);
|
|
||||||
if (!isGroupSearchFilterValid)
|
|
||||||
throw new BadRequestError({
|
|
||||||
message: "Failed to update LDAP configuration due to invalid group search filter."
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
const updateQuery: TLdapConfigsUpdate = {
|
const updateQuery: TLdapConfigsUpdate = {
|
||||||
isActive,
|
isActive,
|
||||||
url,
|
url,
|
||||||
|
|||||||
Reference in New Issue
Block a user