mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 21:27:10 +00:00
Updated membership logic for SAML auth
This commit is contained in:
@@ -106,7 +106,6 @@ export const login1 = async (req: Request, res: Response) => {
|
|||||||
*/
|
*/
|
||||||
export const login2 = async (req: Request, res: Response) => {
|
export const login2 = async (req: Request, res: Response) => {
|
||||||
try {
|
try {
|
||||||
|
|
||||||
if (!req.headers["user-agent"]) throw InternalServerError({ message: "User-Agent header is required" });
|
if (!req.headers["user-agent"]) throw InternalServerError({ message: "User-Agent header is required" });
|
||||||
|
|
||||||
const { email, clientProof, providerAuthToken } = req.body;
|
const { email, clientProof, providerAuthToken } = req.body;
|
||||||
@@ -189,7 +188,7 @@ export const login2 = async (req: Request, res: Response) => {
|
|||||||
ip: req.realIP,
|
ip: req.realIP,
|
||||||
userAgent: req.headers["user-agent"] ?? "",
|
userAgent: req.headers["user-agent"] ?? "",
|
||||||
});
|
});
|
||||||
|
|
||||||
// store (refresh) token in httpOnly cookie
|
// store (refresh) token in httpOnly cookie
|
||||||
res.cookie("jid", tokens.refreshToken, {
|
res.cookie("jid", tokens.refreshToken, {
|
||||||
httpOnly: true,
|
httpOnly: true,
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ import { EELicenseService } from "../../services";
|
|||||||
*/
|
*/
|
||||||
export const redirectSSO = async (req: Request, res: Response) => {
|
export const redirectSSO = async (req: Request, res: Response) => {
|
||||||
if (req.isUserCompleted) {
|
if (req.isUserCompleted) {
|
||||||
return res.redirect(`${await getSiteURL()}/login/sso?token=${encodeURIComponent(req.providerAuthToken)}`);
|
return res.redirect(`${await getSiteURL()}/login/sso?token=${encodeURIComponent(req.providerAuthToken)}`);
|
||||||
}
|
}
|
||||||
|
|
||||||
return res.redirect(`${await getSiteURL()}/signup/sso?token=${encodeURIComponent(req.providerAuthToken)}`);
|
return res.redirect(`${await getSiteURL()}/signup/sso?token=${encodeURIComponent(req.providerAuthToken)}`);
|
||||||
|
|||||||
+40
-11
@@ -19,7 +19,7 @@ import {
|
|||||||
} from "../config";
|
} from "../config";
|
||||||
import { getSSOConfigHelper } from "../ee/helpers/organizations";
|
import { getSSOConfigHelper } from "../ee/helpers/organizations";
|
||||||
import { InternalServerError, OrganizationNotFoundError } from "./errors";
|
import { InternalServerError, OrganizationNotFoundError } from "./errors";
|
||||||
import { INVITED, MEMBER } from "../variables";
|
import { ACCEPTED, INVITED, MEMBER } from "../variables";
|
||||||
import { getSiteURL } from "../config";
|
import { getSiteURL } from "../config";
|
||||||
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-var-requires
|
// eslint-disable-next-line @typescript-eslint/no-var-requires
|
||||||
@@ -152,7 +152,7 @@ const initializePassport = async () => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const samlConfig: ISAMLConfig = ({
|
const samlConfig: ISAMLConfig = ({
|
||||||
path: `/api/v1/sso/saml2/${ssoIdentifier}`,
|
path: `${await getSiteURL()}/api/v1/sso/saml2/${ssoIdentifier}`,
|
||||||
callbackURL: `${await getSiteURL()}/api/v1/sso/saml2${ssoIdentifier}`,
|
callbackURL: `${await getSiteURL()}/api/v1/sso/saml2${ssoIdentifier}`,
|
||||||
entryPoint: ssoConfig.entryPoint,
|
entryPoint: ssoConfig.entryPoint,
|
||||||
issuer: ssoConfig.issuer,
|
issuer: ssoConfig.issuer,
|
||||||
@@ -165,7 +165,7 @@ const initializePassport = async () => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
req.ssoConfig = ssoConfig;
|
req.ssoConfig = ssoConfig;
|
||||||
|
|
||||||
done(null, samlConfig);
|
done(null, samlConfig);
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
@@ -184,15 +184,44 @@ const initializePassport = async () => {
|
|||||||
email
|
email
|
||||||
}).select("+publicKey");
|
}).select("+publicKey");
|
||||||
|
|
||||||
if (user && user.authProvider !== AuthProvider.OKTA_SAML) {
|
if (user) {
|
||||||
done(InternalServerError());
|
if (!user.authProvider || user.authProvider === AuthProvider.EMAIL || user.authProvider === AuthProvider.GOOGLE) {
|
||||||
}
|
await User.findByIdAndUpdate(
|
||||||
|
user._id,
|
||||||
if (!user) {
|
{
|
||||||
|
authProvider: req.ssoConfig.authProvider
|
||||||
|
},
|
||||||
|
{
|
||||||
|
new: true
|
||||||
|
}
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
let membershipOrg = await MembershipOrg.findOne(
|
||||||
|
{
|
||||||
|
user: user._id,
|
||||||
|
organization: organization._id
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!membershipOrg) {
|
||||||
|
membershipOrg = await new MembershipOrg({
|
||||||
|
inviteEmail: email,
|
||||||
|
user: user._id,
|
||||||
|
organization: organization._id,
|
||||||
|
role: MEMBER,
|
||||||
|
status: ACCEPTED
|
||||||
|
}).save();
|
||||||
|
}
|
||||||
|
|
||||||
|
if (membershipOrg.status === INVITED) {
|
||||||
|
membershipOrg.status = ACCEPTED;
|
||||||
|
await membershipOrg.save();
|
||||||
|
}
|
||||||
|
} else {
|
||||||
user = await new User({
|
user = await new User({
|
||||||
email,
|
email,
|
||||||
authProvider: AuthProvider.OKTA_SAML,
|
authProvider: req.ssoConfig.authProvider,
|
||||||
authId: profile.id,
|
|
||||||
firstName,
|
firstName,
|
||||||
lastName
|
lastName
|
||||||
}).save();
|
}).save();
|
||||||
@@ -200,7 +229,7 @@ const initializePassport = async () => {
|
|||||||
await new MembershipOrg({
|
await new MembershipOrg({
|
||||||
inviteEmail: email,
|
inviteEmail: email,
|
||||||
user: user._id,
|
user: user._id,
|
||||||
organization: organization?._id,
|
organization: organization._id,
|
||||||
role: MEMBER,
|
role: MEMBER,
|
||||||
status: INVITED
|
status: INVITED
|
||||||
}).save();
|
}).save();
|
||||||
|
|||||||
@@ -125,6 +125,7 @@ const attemptLogin = async (
|
|||||||
// because this function is about logging the user in
|
// because this function is about logging the user in
|
||||||
// and not initializing the login details
|
// and not initializing the login details
|
||||||
const userOrgs = await getOrganizations();
|
const userOrgs = await getOrganizations();
|
||||||
|
|
||||||
const orgId = userOrgs[0]._id;
|
const orgId = userOrgs[0]._id;
|
||||||
localStorage.setItem("orgData.id", orgId);
|
localStorage.setItem("orgData.id", orgId);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user