mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 16:27:46 +00:00
feat: added enforceMfa toggle for orgs
This commit is contained in:
@@ -0,0 +1,19 @@
|
|||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
|
import { TableName } from "../schemas";
|
||||||
|
|
||||||
|
export async function up(knex: Knex): Promise<void> {
|
||||||
|
if (!(await knex.schema.hasColumn(TableName.Organization, "enforceMfa"))) {
|
||||||
|
await knex.schema.alterTable(TableName.Organization, (tb) => {
|
||||||
|
tb.boolean("enforceMfa").defaultTo(false).notNullable();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function down(knex: Knex): Promise<void> {
|
||||||
|
if (await knex.schema.hasColumn(TableName.Organization, "enforceMfa")) {
|
||||||
|
await knex.schema.alterTable(TableName.Organization, (t) => {
|
||||||
|
t.dropColumn("enforceMfa");
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -20,7 +20,8 @@ export const OrganizationsSchema = z.object({
|
|||||||
scimEnabled: z.boolean().default(false).nullable().optional(),
|
scimEnabled: z.boolean().default(false).nullable().optional(),
|
||||||
kmsDefaultKeyId: z.string().uuid().nullable().optional(),
|
kmsDefaultKeyId: z.string().uuid().nullable().optional(),
|
||||||
kmsEncryptedDataKey: zodBuffer.nullable().optional(),
|
kmsEncryptedDataKey: zodBuffer.nullable().optional(),
|
||||||
defaultMembershipRole: z.string().default("member")
|
defaultMembershipRole: z.string().default("member"),
|
||||||
|
enforceMfa: z.boolean().default(false)
|
||||||
});
|
});
|
||||||
|
|
||||||
export type TOrganizations = z.infer<typeof OrganizationsSchema>;
|
export type TOrganizations = z.infer<typeof OrganizationsSchema>;
|
||||||
|
|||||||
@@ -46,7 +46,8 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
|
|||||||
writeLimit: 200,
|
writeLimit: 200,
|
||||||
secretsLimit: 40
|
secretsLimit: 40
|
||||||
},
|
},
|
||||||
pkiEst: false
|
pkiEst: false,
|
||||||
|
enforceMfa: false
|
||||||
});
|
});
|
||||||
|
|
||||||
export const setupLicenseRequestWithStore = (baseURL: string, refreshUrl: string, licenseKey: string) => {
|
export const setupLicenseRequestWithStore = (baseURL: string, refreshUrl: string, licenseKey: string) => {
|
||||||
|
|||||||
@@ -64,6 +64,7 @@ export type TFeatureSet = {
|
|||||||
secretsLimit: number;
|
secretsLimit: number;
|
||||||
};
|
};
|
||||||
pkiEst: boolean;
|
pkiEst: boolean;
|
||||||
|
enforceMfa: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TOrgPlansTableDTO = {
|
export type TOrgPlansTableDTO = {
|
||||||
|
|||||||
@@ -226,7 +226,8 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
|
|||||||
.refine((v) => slugify(v) === v, {
|
.refine((v) => slugify(v) === v, {
|
||||||
message: "Membership role must be a valid slug"
|
message: "Membership role must be a valid slug"
|
||||||
})
|
})
|
||||||
.optional()
|
.optional(),
|
||||||
|
enforceMfa: z.boolean().optional()
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.object({
|
200: z.object({
|
||||||
|
|||||||
@@ -268,7 +268,7 @@ export const orgServiceFactory = ({
|
|||||||
actorOrgId,
|
actorOrgId,
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
orgId,
|
orgId,
|
||||||
data: { name, slug, authEnforced, scimEnabled, defaultMembershipRoleSlug }
|
data: { name, slug, authEnforced, scimEnabled, defaultMembershipRoleSlug, enforceMfa }
|
||||||
}: TUpdateOrgDTO) => {
|
}: TUpdateOrgDTO) => {
|
||||||
const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId);
|
const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings);
|
||||||
@@ -317,7 +317,8 @@ export const orgServiceFactory = ({
|
|||||||
slug: slug ? slugify(slug) : undefined,
|
slug: slug ? slugify(slug) : undefined,
|
||||||
authEnforced,
|
authEnforced,
|
||||||
scimEnabled,
|
scimEnabled,
|
||||||
defaultMembershipRole
|
defaultMembershipRole,
|
||||||
|
enforceMfa
|
||||||
});
|
});
|
||||||
if (!org) throw new NotFoundError({ message: "Organization not found" });
|
if (!org) throw new NotFoundError({ message: "Organization not found" });
|
||||||
return org;
|
return org;
|
||||||
|
|||||||
@@ -64,6 +64,7 @@ export type TUpdateOrgDTO = {
|
|||||||
authEnforced: boolean;
|
authEnforced: boolean;
|
||||||
scimEnabled: boolean;
|
scimEnabled: boolean;
|
||||||
defaultMembershipRoleSlug: string;
|
defaultMembershipRoleSlug: string;
|
||||||
|
enforceMfa: boolean;
|
||||||
}>;
|
}>;
|
||||||
} & TOrgPermission;
|
} & TOrgPermission;
|
||||||
|
|
||||||
|
|||||||
@@ -82,13 +82,22 @@ export const useCreateOrg = (options: { invalidate: boolean } = { invalidate: tr
|
|||||||
export const useUpdateOrg = () => {
|
export const useUpdateOrg = () => {
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
return useMutation<{}, {}, UpdateOrgDTO>({
|
return useMutation<{}, {}, UpdateOrgDTO>({
|
||||||
mutationFn: ({ name, authEnforced, scimEnabled, slug, orgId, defaultMembershipRoleSlug }) => {
|
mutationFn: ({
|
||||||
|
name,
|
||||||
|
authEnforced,
|
||||||
|
scimEnabled,
|
||||||
|
slug,
|
||||||
|
orgId,
|
||||||
|
defaultMembershipRoleSlug,
|
||||||
|
enforceMfa
|
||||||
|
}) => {
|
||||||
return apiRequest.patch(`/api/v1/organization/${orgId}`, {
|
return apiRequest.patch(`/api/v1/organization/${orgId}`, {
|
||||||
name,
|
name,
|
||||||
authEnforced,
|
authEnforced,
|
||||||
scimEnabled,
|
scimEnabled,
|
||||||
slug,
|
slug,
|
||||||
defaultMembershipRoleSlug
|
defaultMembershipRoleSlug,
|
||||||
|
enforceMfa
|
||||||
});
|
});
|
||||||
},
|
},
|
||||||
onSuccess: () => {
|
onSuccess: () => {
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ export type Organization = {
|
|||||||
scimEnabled: boolean;
|
scimEnabled: boolean;
|
||||||
slug: string;
|
slug: string;
|
||||||
defaultMembershipRole: string;
|
defaultMembershipRole: string;
|
||||||
|
enforceMfa: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type UpdateOrgDTO = {
|
export type UpdateOrgDTO = {
|
||||||
@@ -20,6 +21,7 @@ export type UpdateOrgDTO = {
|
|||||||
scimEnabled?: boolean;
|
scimEnabled?: boolean;
|
||||||
slug?: string;
|
slug?: string;
|
||||||
defaultMembershipRoleSlug?: string;
|
defaultMembershipRoleSlug?: string;
|
||||||
|
enforceMfa?: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type BillingDetails = {
|
export type BillingDetails = {
|
||||||
|
|||||||
@@ -42,4 +42,5 @@ export type SubscriptionPlan = {
|
|||||||
instanceUserManagement: boolean;
|
instanceUserManagement: boolean;
|
||||||
externalKms: boolean;
|
externalKms: boolean;
|
||||||
pkiEst: boolean;
|
pkiEst: boolean;
|
||||||
|
enforceMfa: boolean;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ import { LoginMethod } from "@app/hooks/api/admin/types";
|
|||||||
import { LDAPModal } from "./LDAPModal";
|
import { LDAPModal } from "./LDAPModal";
|
||||||
import { OIDCModal } from "./OIDCModal";
|
import { OIDCModal } from "./OIDCModal";
|
||||||
import { OrgGeneralAuthSection } from "./OrgGeneralAuthSection";
|
import { OrgGeneralAuthSection } from "./OrgGeneralAuthSection";
|
||||||
|
import { OrgGenericAuthSection } from "./OrgGenericAuthSection";
|
||||||
import { OrgLDAPSection } from "./OrgLDAPSection";
|
import { OrgLDAPSection } from "./OrgLDAPSection";
|
||||||
import { OrgOIDCSection } from "./OrgOIDCSection";
|
import { OrgOIDCSection } from "./OrgOIDCSection";
|
||||||
import { OrgScimSection } from "./OrgSCIMSection";
|
import { OrgScimSection } from "./OrgSCIMSection";
|
||||||
@@ -161,6 +162,7 @@ export const OrgAuthTab = withPermission(
|
|||||||
|
|
||||||
return (
|
return (
|
||||||
<>
|
<>
|
||||||
|
<OrgGenericAuthSection />
|
||||||
{shouldShowCreateIdentityProviderView ? (
|
{shouldShowCreateIdentityProviderView ? (
|
||||||
createIdentityProviderView
|
createIdentityProviderView
|
||||||
) : (
|
) : (
|
||||||
|
|||||||
+73
@@ -0,0 +1,73 @@
|
|||||||
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
|
import { Switch, UpgradePlanModal } from "@app/components/v2";
|
||||||
|
import {
|
||||||
|
OrgPermissionActions,
|
||||||
|
OrgPermissionSubjects,
|
||||||
|
useOrganization,
|
||||||
|
useSubscription
|
||||||
|
} from "@app/context";
|
||||||
|
import { useUpdateOrg } from "@app/hooks/api";
|
||||||
|
import { usePopUp } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
|
export const OrgGenericAuthSection = () => {
|
||||||
|
const { currentOrg } = useOrganization();
|
||||||
|
const { subscription } = useSubscription();
|
||||||
|
const { popUp, handlePopUpOpen, handlePopUpToggle } = usePopUp(["upgradePlan"] as const);
|
||||||
|
|
||||||
|
const { mutateAsync } = useUpdateOrg();
|
||||||
|
|
||||||
|
const handleEnforceMfaToggle = async (value: boolean) => {
|
||||||
|
try {
|
||||||
|
if (!currentOrg?.id) return;
|
||||||
|
if (!subscription?.enforceMfa) {
|
||||||
|
handlePopUpOpen("upgradePlan");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
await mutateAsync({
|
||||||
|
orgId: currentOrg?.id,
|
||||||
|
enforceMfa: value
|
||||||
|
});
|
||||||
|
|
||||||
|
createNotification({
|
||||||
|
text: `Successfully ${value ? "enforced" : "un-enforced"} MFA`,
|
||||||
|
type: "success"
|
||||||
|
});
|
||||||
|
} catch (err) {
|
||||||
|
console.error(err);
|
||||||
|
createNotification({
|
||||||
|
text: (err as { response: { data: { message: string } } }).response.data.message,
|
||||||
|
type: "error"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
return (
|
||||||
|
<div className="mb-4 rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-6">
|
||||||
|
<div className="py-4">
|
||||||
|
<div className="mb-2 flex justify-between">
|
||||||
|
<h3 className="text-md text-mineshaft-100">Enforce Multi-factor Authentication</h3>
|
||||||
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Sso}>
|
||||||
|
{(isAllowed) => (
|
||||||
|
<Switch
|
||||||
|
id="enforce-org-mfa"
|
||||||
|
onCheckedChange={(value) => handleEnforceMfaToggle(value)}
|
||||||
|
isChecked={currentOrg?.enforceMfa ?? false}
|
||||||
|
isDisabled={!isAllowed}
|
||||||
|
/>
|
||||||
|
)}
|
||||||
|
</OrgPermissionCan>
|
||||||
|
</div>
|
||||||
|
<p className="text-sm text-mineshaft-300">
|
||||||
|
Enforce members to authenticate with MFA in order to access the organization
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
<UpgradePlanModal
|
||||||
|
isOpen={popUp.upgradePlan.isOpen}
|
||||||
|
onOpenChange={(isOpen) => handlePopUpToggle("upgradePlan", isOpen)}
|
||||||
|
text="You can enforce user MFA if you switch to Infisical's Pro plan."
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
};
|
||||||
Reference in New Issue
Block a user