feat: added enforceMfa toggle for orgs

This commit is contained in:
Sheen Capadngan
2024-10-17 03:02:26 +08:00
parent 9192c5caa2
commit bd1ed2614e
12 changed files with 119 additions and 7 deletions
@@ -0,0 +1,19 @@
import { Knex } from "knex";
import { TableName } from "../schemas";
export async function up(knex: Knex): Promise<void> {
if (!(await knex.schema.hasColumn(TableName.Organization, "enforceMfa"))) {
await knex.schema.alterTable(TableName.Organization, (tb) => {
tb.boolean("enforceMfa").defaultTo(false).notNullable();
});
}
}
export async function down(knex: Knex): Promise<void> {
if (await knex.schema.hasColumn(TableName.Organization, "enforceMfa")) {
await knex.schema.alterTable(TableName.Organization, (t) => {
t.dropColumn("enforceMfa");
});
}
}
+2 -1
View File
@@ -20,7 +20,8 @@ export const OrganizationsSchema = z.object({
scimEnabled: z.boolean().default(false).nullable().optional(), scimEnabled: z.boolean().default(false).nullable().optional(),
kmsDefaultKeyId: z.string().uuid().nullable().optional(), kmsDefaultKeyId: z.string().uuid().nullable().optional(),
kmsEncryptedDataKey: zodBuffer.nullable().optional(), kmsEncryptedDataKey: zodBuffer.nullable().optional(),
defaultMembershipRole: z.string().default("member") defaultMembershipRole: z.string().default("member"),
enforceMfa: z.boolean().default(false)
}); });
export type TOrganizations = z.infer<typeof OrganizationsSchema>; export type TOrganizations = z.infer<typeof OrganizationsSchema>;
@@ -46,7 +46,8 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
writeLimit: 200, writeLimit: 200,
secretsLimit: 40 secretsLimit: 40
}, },
pkiEst: false pkiEst: false,
enforceMfa: false
}); });
export const setupLicenseRequestWithStore = (baseURL: string, refreshUrl: string, licenseKey: string) => { export const setupLicenseRequestWithStore = (baseURL: string, refreshUrl: string, licenseKey: string) => {
@@ -64,6 +64,7 @@ export type TFeatureSet = {
secretsLimit: number; secretsLimit: number;
}; };
pkiEst: boolean; pkiEst: boolean;
enforceMfa: boolean;
}; };
export type TOrgPlansTableDTO = { export type TOrgPlansTableDTO = {
@@ -226,7 +226,8 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
.refine((v) => slugify(v) === v, { .refine((v) => slugify(v) === v, {
message: "Membership role must be a valid slug" message: "Membership role must be a valid slug"
}) })
.optional() .optional(),
enforceMfa: z.boolean().optional()
}), }),
response: { response: {
200: z.object({ 200: z.object({
+3 -2
View File
@@ -268,7 +268,7 @@ export const orgServiceFactory = ({
actorOrgId, actorOrgId,
actorAuthMethod, actorAuthMethod,
orgId, orgId,
data: { name, slug, authEnforced, scimEnabled, defaultMembershipRoleSlug } data: { name, slug, authEnforced, scimEnabled, defaultMembershipRoleSlug, enforceMfa }
}: TUpdateOrgDTO) => { }: TUpdateOrgDTO) => {
const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId); const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId);
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings); ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
@@ -317,7 +317,8 @@ export const orgServiceFactory = ({
slug: slug ? slugify(slug) : undefined, slug: slug ? slugify(slug) : undefined,
authEnforced, authEnforced,
scimEnabled, scimEnabled,
defaultMembershipRole defaultMembershipRole,
enforceMfa
}); });
if (!org) throw new NotFoundError({ message: "Organization not found" }); if (!org) throw new NotFoundError({ message: "Organization not found" });
return org; return org;
+1
View File
@@ -64,6 +64,7 @@ export type TUpdateOrgDTO = {
authEnforced: boolean; authEnforced: boolean;
scimEnabled: boolean; scimEnabled: boolean;
defaultMembershipRoleSlug: string; defaultMembershipRoleSlug: string;
enforceMfa: boolean;
}>; }>;
} & TOrgPermission; } & TOrgPermission;
@@ -82,13 +82,22 @@ export const useCreateOrg = (options: { invalidate: boolean } = { invalidate: tr
export const useUpdateOrg = () => { export const useUpdateOrg = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation<{}, {}, UpdateOrgDTO>({ return useMutation<{}, {}, UpdateOrgDTO>({
mutationFn: ({ name, authEnforced, scimEnabled, slug, orgId, defaultMembershipRoleSlug }) => { mutationFn: ({
name,
authEnforced,
scimEnabled,
slug,
orgId,
defaultMembershipRoleSlug,
enforceMfa
}) => {
return apiRequest.patch(`/api/v1/organization/${orgId}`, { return apiRequest.patch(`/api/v1/organization/${orgId}`, {
name, name,
authEnforced, authEnforced,
scimEnabled, scimEnabled,
slug, slug,
defaultMembershipRoleSlug defaultMembershipRoleSlug,
enforceMfa
}); });
}, },
onSuccess: () => { onSuccess: () => {
@@ -11,6 +11,7 @@ export type Organization = {
scimEnabled: boolean; scimEnabled: boolean;
slug: string; slug: string;
defaultMembershipRole: string; defaultMembershipRole: string;
enforceMfa: boolean;
}; };
export type UpdateOrgDTO = { export type UpdateOrgDTO = {
@@ -20,6 +21,7 @@ export type UpdateOrgDTO = {
scimEnabled?: boolean; scimEnabled?: boolean;
slug?: string; slug?: string;
defaultMembershipRoleSlug?: string; defaultMembershipRoleSlug?: string;
enforceMfa?: boolean;
}; };
export type BillingDetails = { export type BillingDetails = {
@@ -42,4 +42,5 @@ export type SubscriptionPlan = {
instanceUserManagement: boolean; instanceUserManagement: boolean;
externalKms: boolean; externalKms: boolean;
pkiEst: boolean; pkiEst: boolean;
enforceMfa: boolean;
}; };
@@ -16,6 +16,7 @@ import { LoginMethod } from "@app/hooks/api/admin/types";
import { LDAPModal } from "./LDAPModal"; import { LDAPModal } from "./LDAPModal";
import { OIDCModal } from "./OIDCModal"; import { OIDCModal } from "./OIDCModal";
import { OrgGeneralAuthSection } from "./OrgGeneralAuthSection"; import { OrgGeneralAuthSection } from "./OrgGeneralAuthSection";
import { OrgGenericAuthSection } from "./OrgGenericAuthSection";
import { OrgLDAPSection } from "./OrgLDAPSection"; import { OrgLDAPSection } from "./OrgLDAPSection";
import { OrgOIDCSection } from "./OrgOIDCSection"; import { OrgOIDCSection } from "./OrgOIDCSection";
import { OrgScimSection } from "./OrgSCIMSection"; import { OrgScimSection } from "./OrgSCIMSection";
@@ -161,6 +162,7 @@ export const OrgAuthTab = withPermission(
return ( return (
<> <>
<OrgGenericAuthSection />
{shouldShowCreateIdentityProviderView ? ( {shouldShowCreateIdentityProviderView ? (
createIdentityProviderView createIdentityProviderView
) : ( ) : (
@@ -0,0 +1,73 @@
import { createNotification } from "@app/components/notifications";
import { OrgPermissionCan } from "@app/components/permissions";
import { Switch, UpgradePlanModal } from "@app/components/v2";
import {
OrgPermissionActions,
OrgPermissionSubjects,
useOrganization,
useSubscription
} from "@app/context";
import { useUpdateOrg } from "@app/hooks/api";
import { usePopUp } from "@app/hooks/usePopUp";
export const OrgGenericAuthSection = () => {
const { currentOrg } = useOrganization();
const { subscription } = useSubscription();
const { popUp, handlePopUpOpen, handlePopUpToggle } = usePopUp(["upgradePlan"] as const);
const { mutateAsync } = useUpdateOrg();
const handleEnforceMfaToggle = async (value: boolean) => {
try {
if (!currentOrg?.id) return;
if (!subscription?.enforceMfa) {
handlePopUpOpen("upgradePlan");
return;
}
await mutateAsync({
orgId: currentOrg?.id,
enforceMfa: value
});
createNotification({
text: `Successfully ${value ? "enforced" : "un-enforced"} MFA`,
type: "success"
});
} catch (err) {
console.error(err);
createNotification({
text: (err as { response: { data: { message: string } } }).response.data.message,
type: "error"
});
}
};
return (
<div className="mb-4 rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-6">
<div className="py-4">
<div className="mb-2 flex justify-between">
<h3 className="text-md text-mineshaft-100">Enforce Multi-factor Authentication</h3>
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
{(isAllowed) => (
<Switch
id="enforce-org-mfa"
onCheckedChange={(value) => handleEnforceMfaToggle(value)}
isChecked={currentOrg?.enforceMfa ?? false}
isDisabled={!isAllowed}
/>
)}
</OrgPermissionCan>
</div>
<p className="text-sm text-mineshaft-300">
Enforce members to authenticate with MFA in order to access the organization
</p>
</div>
<UpgradePlanModal
isOpen={popUp.upgradePlan.isOpen}
onOpenChange={(isOpen) => handlePopUpToggle("upgradePlan", isOpen)}
text="You can enforce user MFA if you switch to Infisical's Pro plan."
/>
</div>
);
};